REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
64 reports · page 2 of 2
ars_security · tlp:amber · 5/19/2026, 6:27:08 PM
In stunning display of stupid, secret CISA credentials found in public GitHub repo SSH keys, plaintext passwords, other sensitive data had been up since November 2025. Security researcher Brian Krebs brings us the news that America's Cybersecurity & Infrastructure Agency (CISA) has had a large store of plaintext passwords, SSH private keys, tokens, and "other sensitive CISA assets" exposed in a public GitHub repo since at least November 2025. The now-offline public repo…
Read original ↗https://arstechnica.com/information-technology/2026/05/in-stunning-display-of-stupid-secret-cisa-credentials-found-in-public-github-repoars_security · tlp:amber · 5/18/2026, 1:23:34 PM
Bug bounty businesses bombarded with AI slop "Never-ending" AI slop strains corporate hacking reward schemes. Companies that pay hackers to find flaws in their software are being inundated with low-quality reports generated by AI, forcing some to suspend the programs altogether. Businesses that run “bug bounty” schemes have long relied on independent security researchers to spot vulnerabilities. But the rise of AI tools is now overwhelming them with spurious submissions. Bu…
ars_security · tlp:amber · 5/14/2026, 6:32:01 PM
Zero-day exploit completely defeats default Windows 11 BitLocker protections It's not entirely clear how the exploit works. Microsoft says it's investigating. A zero-day exploit circulating online allows people with physical access to a Windows 11 system to bypass default BitLocker protections and gain complete access to an encrypted drive within seconds. The exploit, named YellowKey, was published earlier this week by a researcher who goes by the alias Nightmare-Eclipse. I…
Read original ↗https://arstechnica.com/security/2026/05/zero-day-exploit-completely-defeats-default-windows-11-bitlocker-protectionsars_security · tlp:amber · 5/11/2026, 10:28:19 PM
Linux bitten by second severe vulnerability in as many weeks Production-version patches are coming online and should be installed pronto. Linux users have been bitten by yet another vulnerability that gives containers and untrusted users the ability to gain root access, marking the second time in as many weeks that a severe threat has caught defenders off guard. The threat, known as Dirty Frag, allows low-privilege users, including those using virtual machines, to gain root…
Read original ↗https://arstechnica.com/security/2026/05/linux-bitten-by-second-severe-vulnerability-in-as-many-weeksars_security · tlp:amber · 5/8/2026, 6:33:48 PM
Chaos erupts as cyberattack disrupts learning platform Canvas amid finals Across the country, schools and colleges postpone year-end tests. Chaos erupted at schools and colleges throughout the US on Thursday as a cyberattack disrupted online learning platform Canvas just as students were due to take final exams. Canvas parent company Instructure said that as of Friday morning, the platform was back online. Instructure said it temporarily took Canvas offline on Thursday afte…
Read original ↗https://arstechnica.com/security/2026/05/chaos-erupts-as-cyberattack-disrupts-learning-platform-canvas-amid-finalsars_security · tlp:amber · 5/7/2026, 7:18:16 PM
Mozilla says 271 vulnerabilities found by Mythos have "almost no false positives" The developer of Firefox says it has "completely bought in" on AI-assisted bug discovery. The disbelief was palpable when Mozilla’s CTO last month declared that AI-assisted vulnerability detection meant “ zero-days are numbered ” and “defenders finally have a chance to win, decisively.” After all, it looked like part of an all-too-familiar pattern: Cherry-pick a handful of impressive AI-achiev…
Read original ↗https://arstechnica.com/information-technology/2026/05/mozilla-says-271-vulnerabilities-found-by-mythos-have-almost-no-false-positivesars_security · tlp:amber · 5/5/2026, 7:46:15 PM
Widely used Daemon Tools disk app backdoored in monthlong supply-chain attack Daemon Tools users: It's time to check your machines for stealthy infections, stat. Daemon Tools, a widely used app for mounting disk images, has been backdoored in a monthlong compromise that has pushed malicious updates from the servers of its developer, researchers said Tuesday. Kaspersky, the security firm reporting the supply-chain attack, said it began on April 8 and remained active as of th…
Read original ↗https://arstechnica.com/security/2026/05/widely-used-daemon-tools-disk-app-backdoored-in-monthlong-supply-chain-attackars_security · tlp:amber · 5/1/2026, 7:12:26 PM
Ubuntu infrastructure has been down for more than a day The outage has hampered communication concerning a critical vulnerability that gives root. Servers operated by Ubuntu and its parent company Canonical were knocked offline on Thursday morning and have remained down ever since, a situation that’s preventing the OS provider from communicating normally following the botched disclosure of a major vulnerability. Attempts to connect to most Ubuntu and Canonical webpages and …
Read original ↗https://arstechnica.com/security/2026/05/ubuntu-infrastructure-has-been-down-for-more-than-a-dayars_security · tlp:amber · 5/1/2026, 3:32:27 PM
GPT-5.5 matches heavily hyped Mythos Preview in new cybersecurity tests New results suggest Mythos' cyber threat isn't "a breakthrough specific to one model." Last month, Anthropic made a big deal about the supposedly outsize cybersecurity threat represented by its Mythos Preview model, leading the company to restrict the initial release to “critical industry partners.” But new research from the UK's AI Security Institute (AISI) suggests that OpenAI's GPT-5.5, which launche…
Read original ↗https://arstechnica.com/ai/2026/05/amid-mythos-hyped-cybersecurity-prowess-researchers-find-gpt-5-5-is-just-as-goodars_security · tlp:amber · 4/30/2026, 8:20:48 PM
The most severe Linux threat to surface in years catches the world flat-footed CopyFail threatens multi-tenant servers, CI/CD work flows, Kubernetes containers, and more. Publicly released exploit code for an effectively unpatched vulnerability that gives root access to virtually all releases of Linux is setting off alarm bells as defenders scramble to ward off severe compromises inside data centers and on personal devices. The vulnerability and exploit code that exploits i…
Read original ↗https://arstechnica.com/security/2026/04/as-the-most-severe-linux-threat-in-years-surfaces-the-world-scramblesars_security · tlp:amber · 4/29/2026, 11:00:24 AM
Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden Security firms find themselves especially exposed. It has been a bad six weeks for security firm Checkmarx. Over the past 40 days, it has been the victim of at least one supply-chain attack that delivered malware to customers on two separate occasions. Now it has been hit by a ransomware attack from prolific fame-seeking hackers. The streak of misfortunes started on March 19 with the supply-…
Read original ↗https://arstechnica.com/information-technology/2026/04/why-a-recent-supply-chain-attack-singled-out-security-firms-checkmarx-and-bitwardenars_security · tlp:amber · 4/27/2026, 9:04:03 PM
Open source package with 1 million monthly downloads stole user credentials If you're one of millions using element-data, it's time to check for compromise. Open source software with more than 1 million monthly downloads was compromised after a threat actor exploited a vulnerability in the developers’ account workflow that gave access to its signing keys and other sensitive information. On Friday, unknown attackers exploited the vulnerability to push a new version of elemen…
Read original ↗https://arstechnica.com/security/2026/04/open-source-package-with-1-million-monthly-downloads-stole-user-credentialsars_security · tlp:amber · 4/24/2026, 7:00:39 PM
Why are top university websites serving porn? It comes down to shoddy housekeeping. Hundreds of subdomains from dozens of universities have been hijacked by scammers. Websites for some of the world’s most prestigious universities are serving explicit porn and malicious content after scammers exploited the shoddy record-keeping of the site administrators, a researcher found recently. The sites included berkeley.edu, columbia.edu, and washu.edu, the official domains for the U…
Read original ↗https://arstechnica.com/security/2026/04/why-are-top-university-websites-serving-porn-it-comes-down-to-shoddy-housekeepingars_security · tlp:amber · 4/23/2026, 8:41:23 PM
In a first, a ransomware family is confirmed to be quantum-safe Technically speaking, there's no practical benefit to use PQC. So why is it being used? A relatively new ransomware family is using a novel approach to hype the strength of the encryption used to scramble files—making, or at least claiming, that it is protected against attacks by quantum computers. Kyber, as the ransomware is called, has been around since at least last September and quickly attracted attention …
Read original ↗https://arstechnica.com/security/2026/04/now-even-ransomware-is-using-post-quantum-cryptographyars_security · tlp:amber · 4/22/2026, 10:07:54 PM
Crypto scam lures ships into Strait of Hormuz, falsely promising safe passage Ship attacked by Iran after possibly falling for safe passage crypto scam. Crypto scammers are targeting the thousands of ships stranded near the Strait of Hormuz—and at least one ship that faced Iranian gunfire may have been tricked into believing it had paid Iran for safe passage. The first warning of such a crypto scam came from the Greek maritime risk management company MARISKS on April 20, ac…
Read original ↗https://arstechnica.com/security/2026/04/crypto-scam-lures-ships-into-strait-of-hormuz-falsely-promising-safe-passagears_security · tlp:amber · 4/22/2026, 7:32:56 PM
Microsoft issues emergency update for macOS and Linux ASP.NET threat When authentication fails, things can go very, very wrong. Microsoft released an emergency patch for its ASP.NET Core to fix a high-severity vulnerability that allows unauthenticated attackers to gain SYSTEM privileges on devices that use the Web development framework to run Linux or macOS apps. The software maker said Tuesday evening that the vulnerability, tracked as CVE-2026-40372, affects versions 10.0…
Read original ↗https://arstechnica.com/security/2026/04/microsoft-issues-emergency-update-for-macos-and-linux-asp-net-threatars_security · tlp:amber · 4/21/2026, 9:40:41 PM
Mozilla: Anthropic's Mythos found 271 security vulnerabilities in Firefox 150 CTO says new AI model is "every bit as capable" as world's best security researchers. Earlier this month, Anthropic said its Mythos Preview model was so good at finding cybersecurity vulnerabilities that the company was limiting its initial release to "a limited group of critical industry partners." Since then, debate has raged over whether the model presages an era of turbocharged AI-aided hackin…
Read original ↗https://arstechnica.com/ai/2026/04/mozilla-anthropics-mythos-found-271-zero-day-vulnerabilities-in-firefox-150ars_security · tlp:amber · 4/21/2026, 12:35:20 PM
Contrary to popular superstition, AES 128 is just fine in a post-quantum world A stubborn misconception is hampering the already hard work of quantum readiness. With growing focus on the existential threat quantum computing poses to some of the most crucial and widely used forms of encryption, cryptography engineer Filippo Valsorda wants to make one thing absolutely clear: Contrary to popular mythology that refuses to die, AES 128 is perfectly fine in a post-quantum world. …
Read original ↗https://arstechnica.com/security/2026/04/contrary-to-popular-superstition-aes-128-is-just-fine-in-a-post-quantum-worldars_security · tlp:amber · 4/17/2026, 9:28:35 PM
US-sanctioned currency exchange says $15 million heist done by "unfriendly states" Grinex says needed hacking resources "available exclusively to... unfriendly states." Grinex, a US-sanctioned cryptocurrency exchange registered in Kyrgyzstan, said it’s halting operations after experiencing a $13 million heist carried out by “western special services” hackers. Researchers from TRM, which has confirmed the theft, put the value of stolen assets at $15 million after discovering…
Read original ↗https://arstechnica.com/security/2026/04/russia-friendly-exchange-says-western-special-service-behind-15-million-cyberattackars_security · tlp:amber · 4/17/2026, 11:00:50 AM
Recent advances push Big Tech closer to the Q-Day danger zone Here's which players are winning the race to transition to post-quantum crypto. Sometime around 2010, sophisticated malware known as Flame hijacked the mechanism that Microsoft used to distribute updates to millions of Windows computers around the world. The malware—reportedly jointly developed by the US and Israel—pushed a malicious update throughout an infected network belonging to the Iranian government. The l…
Read original ↗https://arstechnica.com/security/2026/04/while-some-big-tech-players-accelerate-pqc-readiness-others-stay-the-coursears_security · tlp:amber · 4/15/2026, 8:36:28 PM
"TotalRecall Reloaded" tool finds a side entrance to Windows 11's Recall database "The vault is solid. The delivery truck is not." Two years ago, Microsoft launched its first wave of “Copilot+” Windows PCs with a handful of exclusive features that could take advantage of the neural processing unit (NPU) hardware being built into newer laptop processors. These NPUs could enable AI and machine learning features that could run locally rather than in someone’s cloud, theoretica…
Read original ↗https://arstechnica.com/gadgets/2026/04/totalrecall-reloaded-tool-finds-a-side-entrance-to-windows-11s-recall-databasears_security · tlp:amber · 4/14/2026, 7:11:25 PM
UK gov's Mythos AI tests help separate cybersecurity threat from hype New model is the first AI system to complete a difficult multistep infiltration challenge. Last week, Anthropic announced it was restricting the initial release of its Mythos Preview model to "a limited group of critical industry partners," giving them time to prepare for a model that it said is "strikingly capable at computer security tasks." Now, the UK government's AI Security Institute (AISI) has publ…
Read original ↗https://arstechnica.com/ai/2026/04/uk-govs-mythos-ai-tests-help-separate-cybersecurity-threat-from-hypears_security · tlp:amber · 4/8/2026, 8:49:11 PM
Iran-linked hackers disrupt operations at US critical infrastructure sites As the US and Israel's war has ramped up, so too have hacks on US industrial sites. Hackers working on behalf of the Iranian government are disrupting operations at multiple US critical infrastructure sites, likely in response to the country's ongoing war with the US, a half-dozen government agencies are warning. In an advisory published Tuesday, the FBI, Cybersecurity and Infrastructure Security Age…
Read original ↗https://arstechnica.com/security/2026/04/iran-linked-hackers-disrupt-operations-at-us-critical-infrastructure-sitesars_security · tlp:amber · 4/8/2026, 11:00:08 AM
Thousands of consumer routers hacked by Russia's military End-of-life routers in homes and small offices hacked in 120 countries. The Russian military is once again hacking home and small office routers in widespread operations that send unwitting users to sites that harvest passwords and credential tokens for use in espionage campaigns, researchers said Tuesday. An estimated 18,000 to 40,000 consumer routers, mostly those made by MikroTik and TP-Link, located in 120 countr…
Read original ↗https://arstechnica.com/security/2026/04/russias-military-hacks-thousands-of-consumer-routers-to-steal-credentials