Normal view
-
ZDNet | security RSS
- Samsung Galaxy S26 Ultra vs. iPhone 17 Pro Max: I use both phones daily, and this one's better
Samsung Galaxy S26 Ultra vs. iPhone 17 Pro Max: I use both phones daily, and this one's better
DigiCert: Misissued code signing certificates
-
ZDNet | security RSS
- 60Hz vs. 120Hz vs. 165Hz: I've tested dozens of TVs, and here's what's best for your home
60Hz vs. 120Hz vs. 165Hz: I've tested dozens of TVs, and here's what's best for your home
Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware
Why this 16-inch gaming laptop is a smarter buy than a desktop in 2026
-
ZDNet | security RSS
- These 5 critical Windows Defender settings are off by default - turn them on ASAP
These 5 critical Windows Defender settings are off by default - turn them on ASAP
-
/r/netsec - Information Security News & Discussion
- Major AI Clients Shipping With Broken OAuth Implementations
Major AI Clients Shipping With Broken OAuth Implementations
The majority of widely used AI clients like:
- Claude Code
- Claude Desktop
- Cursor
- LibreChat
- Amazon Q CLI
have not implemented the critical refresh-token flow of the OAuth standard.
This is forcing developers to issue long lived tokens creating a serious security regression in an already solved problem.
This write up includes a matrix table of 14 major clients with notes linking to feature requests, pull requests, and multiple forum discussions.
It is not all gloom and doom though!
There is a work-around solution that security conscious users are using as a stop-gap also discussed, along with a best practices guide for developers implementing their own MCP OAuth Solution.
The plan is to update this reference on a monthly basis to track if there is any movement on this open requests.
[link] [comments]
Attackers are cashing in on fresh 'CopyFail' Linux flaw
Researchers dropped a reliable root exploit and it didnβt sit idle for long
CISA is warning that a newly-disclosed Linux kernel bug dubbed "CopyFail" is already being exploited, just days after researchers dropped a working root-level exploit.β¦
-
ZDNet | security RSS
- This critical Linux vulnerability is putting millions of systems at risk - how to protect yours
This critical Linux vulnerability is putting millions of systems at risk - how to protect yours
China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions
-
The Register - Security
- Real estate giant confirms vishing incident as ShinyHunters and Qilin both come knocking
Real estate giant confirms vishing incident as ShinyHunters and Qilin both come knocking
Cushman & Wakefield activated incident response protocols after serial extortionists issued separate threats
Real estate giant Cushman & Wakefield has confirmed a data breach after two cybercrime groups, ShinyHunters and Qilin, separately claimed responsibility for attacks on the company.β¦
-
/r/netsec - Information Security News & Discussion
- Popular DAEMON Tools software infected β supply chain attack ongoing since April 8, 2026
-
/r/netsec - Information Security News & Discussion
- HN Security - Extending Burp Suite for fun and profit β The Montoya way β Part 10
-
ZDNet | security RSS
- I'm backing up my Samsung Messages before it's too late - 2 free and easy methods
I'm backing up my Samsung Messages before it's too late - 2 free and easy methods
ShinyHunters claims dump puts 119K Vimeo emails in the wild
Vimeo points finger at analytics supplier Anodot, says no logins or card data were touched
More than 119,000 Vimeo users's email addresses were extracted in a breach traced to a third-party analytics vendor, according to Have I Been Pwned.β¦
-
ZDNet | security RSS
- Bose's new home theater system is optimized for your various TV setups - but can it beat Sony?
Bose's new home theater system is optimized for your various TV setups - but can it beat Sony?
-
The Hacker News
- The Back Door Attackers Know About β and Most Security Teams Still Havenβt Closed
The Back Door Attackers Know About β and Most Security Teams Still Havenβt Closed
MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks