home.social

#security_cyberattacksandhacks — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #security_cyberattacksandhacks, aggregated by home.social.

fetched live
  1. Feed: All Latest | The AI Era Is Creating a Bug Hunting Arms Race by Lily Hay Newman

    AI generated summary, Read the full article for complete information.

    The article explains how the rise of autonomous AI models is reshaping the bug‑hunting ecosystem, turning vulnerability discovery and exploit creation into a fast‑moving arms race. As AI tools enable both attackers and researchers to identify and weaponize software flaws at unprecedented speed, bug‑bounty programs are being inundated with high‑volume submissions, forcing companies like Google, Apple, and Curl to adjust payout structures and, in some cases, suspend programs due to low‑quality “AI‑generated” reports. This surge is compressing the traditional 90‑day disclosure timeline, pressuring organizations to release patches more quickly while also highlighting the limitations of patch‑centric defenses. Experts argue that, beyond faster fixes, the industry needs fundamentally more resilient architectures that render many bugs irrelevant, as reliance on patching alone cannot keep pace with AI‑driven vulnerability discovery.

    Read more: wired.com/story/the-ai-era-is-

    #Apple #Google #HackerOne #security_cyberattacksandhacks #security_securitynews #JosephThacker

  2. Feed: All Latest | The AI Era Is Creating a Bug Hunting Arms Race by Lily Hay Newman

    AI generated summary, Read the full article for complete information.

    The article explains how the rise of autonomous AI models is reshaping the bug‑hunting ecosystem, turning vulnerability discovery and exploit creation into a fast‑moving arms race. As AI tools enable both attackers and researchers to identify and weaponize software flaws at unprecedented speed, bug‑bounty programs are being inundated with high‑volume submissions, forcing companies like Google, Apple, and Curl to adjust payout structures and, in some cases, suspend programs due to low‑quality “AI‑generated” reports. This surge is compressing the traditional 90‑day disclosure timeline, pressuring organizations to release patches more quickly while also highlighting the limitations of patch‑centric defenses. Experts argue that, beyond faster fixes, the industry needs fundamentally more resilient architectures that render many bugs irrelevant, as reliance on patching alone cannot keep pace with AI‑driven vulnerability discovery.

    Read more: wired.com/story/the-ai-era-is-

    #Apple #Google #HackerOne #security_cyberattacksandhacks #security_securitynews #JosephThacker

  3. Feed: All Latest | The AI Era Is Creating a Bug Hunting Arms Race by Lily Hay Newman

    AI generated summary, Read the full article for complete information.

    The article explains how the rise of autonomous AI models is reshaping the bug‑hunting ecosystem, turning vulnerability discovery and exploit creation into a fast‑moving arms race. As AI tools enable both attackers and researchers to identify and weaponize software flaws at unprecedented speed, bug‑bounty programs are being inundated with high‑volume submissions, forcing companies like Google, Apple, and Curl to adjust payout structures and, in some cases, suspend programs due to low‑quality “AI‑generated” reports. This surge is compressing the traditional 90‑day disclosure timeline, pressuring organizations to release patches more quickly while also highlighting the limitations of patch‑centric defenses. Experts argue that, beyond faster fixes, the industry needs fundamentally more resilient architectures that render many bugs irrelevant, as reliance on patching alone cannot keep pace with AI‑driven vulnerability discovery.

    Read more: wired.com/story/the-ai-era-is-

    #Apple #Google #HackerOne #security_cyberattacksandhacks #security_securitynews #JosephThacker

  4. Feed: All Latest | The AI Era Is Creating a Bug Hunting Arms Race by Lily Hay Newman

    AI generated summary, Read the full article for complete information.

    The article explains how the rise of autonomous AI models is reshaping the bug‑hunting ecosystem, turning vulnerability discovery and exploit creation into a fast‑moving arms race. As AI tools enable both attackers and researchers to identify and weaponize software flaws at unprecedented speed, bug‑bounty programs are being inundated with high‑volume submissions, forcing companies like Google, Apple, and Curl to adjust payout structures and, in some cases, suspend programs due to low‑quality “AI‑generated” reports. This surge is compressing the traditional 90‑day disclosure timeline, pressuring organizations to release patches more quickly while also highlighting the limitations of patch‑centric defenses. Experts argue that, beyond faster fixes, the industry needs fundamentally more resilient architectures that render many bugs irrelevant, as reliance on patching alone cannot keep pace with AI‑driven vulnerability discovery.

    Read more: wired.com/story/the-ai-era-is-

    #Apple #Google #HackerOne #security_cyberattacksandhacks #security_securitynews #JosephThacker

  5. Feed: All Latest | Foxconn Ransomware Attack Shows Nothing Is Safe Forever by Lily Hay Newman

    AI generated summary, Read the full article for complete information.

    Foxconn, the electronics manufacturer best known for building Apple iPhones, recently suffered a ransomware attack by the Nitrogen group, which claims to have stolen 8 TB of data—including schematics and project details for customers such as Dell, Google, Apple, and Nvidia. While Foxconn confirmed that some North American factories experienced a cyber‑attack and are now resuming normal production, it has not verified the attackers’ claims. The breach underscores the growing trend of ransomware groups targeting supply‑chain giants that store both their own and their clients’ intellectual property. Nitrogen, linked to the ALPHV/BlackCat family, listed Foxconn on its breach site; its ransomware is based on “Conti 2” code and suffers a design flaw that prevents decryption even if the attackers wish to restore systems. Foxconn has faced multiple extortion attempts in the past, including high‑profile incidents in 2020, 2022, and 2024, highlighting the persistent risk of large‑scale data theft and disruption across the tech industry.

    Read more: wired.com/story/foxconn-ransom

    #Foxconn #Nitrogen #Apple #LockBit #security_cyberattacksandhacks #AllanLiska

  6. Feed: All Latest | Foxconn Ransomware Attack Shows Nothing Is Safe Forever by Lily Hay Newman

    AI generated summary, Read the full article for complete information.

    Foxconn, the electronics manufacturer best known for building Apple iPhones, recently suffered a ransomware attack by the Nitrogen group, which claims to have stolen 8 TB of data—including schematics and project details for customers such as Dell, Google, Apple, and Nvidia. While Foxconn confirmed that some North American factories experienced a cyber‑attack and are now resuming normal production, it has not verified the attackers’ claims. The breach underscores the growing trend of ransomware groups targeting supply‑chain giants that store both their own and their clients’ intellectual property. Nitrogen, linked to the ALPHV/BlackCat family, listed Foxconn on its breach site; its ransomware is based on “Conti 2” code and suffers a design flaw that prevents decryption even if the attackers wish to restore systems. Foxconn has faced multiple extortion attempts in the past, including high‑profile incidents in 2020, 2022, and 2024, highlighting the persistent risk of large‑scale data theft and disruption across the tech industry.

    Read more: wired.com/story/foxconn-ransom

    #Foxconn #Nitrogen #Apple #LockBit #security_cyberattacksandhacks #AllanLiska

  7. Feed: All Latest | Foxconn Ransomware Attack Shows Nothing Is Safe Forever by Lily Hay Newman

    AI generated summary, Read the full article for complete information.

    Foxconn, the electronics manufacturer best known for building Apple iPhones, recently suffered a ransomware attack by the Nitrogen group, which claims to have stolen 8 TB of data—including schematics and project details for customers such as Dell, Google, Apple, and Nvidia. While Foxconn confirmed that some North American factories experienced a cyber‑attack and are now resuming normal production, it has not verified the attackers’ claims. The breach underscores the growing trend of ransomware groups targeting supply‑chain giants that store both their own and their clients’ intellectual property. Nitrogen, linked to the ALPHV/BlackCat family, listed Foxconn on its breach site; its ransomware is based on “Conti 2” code and suffers a design flaw that prevents decryption even if the attackers wish to restore systems. Foxconn has faced multiple extortion attempts in the past, including high‑profile incidents in 2020, 2022, and 2024, highlighting the persistent risk of large‑scale data theft and disruption across the tech industry.

    Read more: wired.com/story/foxconn-ransom

    #Foxconn #Nitrogen #Apple #LockBit #security_cyberattacksandhacks #AllanLiska

  8. Feed: All Latest | Foxconn Ransomware Attack Shows Nothing Is Safe Forever by Lily Hay Newman

    AI generated summary, Read the full article for complete information.

    Foxconn, the electronics manufacturer best known for building Apple iPhones, recently suffered a ransomware attack by the Nitrogen group, which claims to have stolen 8 TB of data—including schematics and project details for customers such as Dell, Google, Apple, and Nvidia. While Foxconn confirmed that some North American factories experienced a cyber‑attack and are now resuming normal production, it has not verified the attackers’ claims. The breach underscores the growing trend of ransomware groups targeting supply‑chain giants that store both their own and their clients’ intellectual property. Nitrogen, linked to the ALPHV/BlackCat family, listed Foxconn on its breach site; its ransomware is based on “Conti 2” code and suffers a design flaw that prevents decryption even if the attackers wish to restore systems. Foxconn has faced multiple extortion attempts in the past, including high‑profile incidents in 2020, 2022, and 2024, highlighting the persistent risk of large‑scale data theft and disruption across the tech industry.

    Read more: wired.com/story/foxconn-ransom

    #Foxconn #Nitrogen #Apple #LockBit #security_cyberattacksandhacks #AllanLiska

  9. Feed: All Latest | Dangerous New Linux Exploit Gives Attackers Root Access to Countless Computers by Dan Goodin, Ars Technica

    AI generated summary, Read the full article for complete information.

    A newly disclosed Linux kernel vulnerability, dubbed CopyFail (CVE‑2026‑31431), enables a local privilege‑escalation that lets an unprivileged attacker obtain root on virtually any Linux distribution with a single, unmodified script. Released by security firm Theori after a brief private disclosure, the flaw resides in the kernel’s crypto API where an AEAD template copy operation overwrites adjacent memory, allowing the attacker to elevate privileges, break out of containers, compromise multi‑tenant systems, and hijack CI/CD pipelines. Although patches were quickly issued for several kernel versions (7.0, 6.19.12, 6.18.12, 6.12.85, 6.6.137, 6.1.170, 5.15.204, and 5.10.254), many distributions had not yet applied them, leaving countless desktops, servers, and cloud environments exposed. Experts warn that the exploit’s reliability surpasses earlier high‑profile kernel bugs like Dirty Pipe and Dirty Cow, and they urge all Linux users to verify that their systems incorporate the relevant fixes or follow vendor mitigation guidance.

    Read more: wired.com/story/dangerous-new-

    #Theori #Ubuntu #Amazon #SUSE #Debian #RedHat #Fedora #ArchLinux #Kubernetes #Linux #copyfail #security #security_cyberattacksandhacks #security_securitynews

  10. Feed: All Latest | Dangerous New Linux Exploit Gives Attackers Root Access to Countless Computers by Dan Goodin, Ars Technica

    AI generated summary, Read the full article for complete information.

    A newly disclosed Linux kernel vulnerability, dubbed CopyFail (CVE‑2026‑31431), enables a local privilege‑escalation that lets an unprivileged attacker obtain root on virtually any Linux distribution with a single, unmodified script. Released by security firm Theori after a brief private disclosure, the flaw resides in the kernel’s crypto API where an AEAD template copy operation overwrites adjacent memory, allowing the attacker to elevate privileges, break out of containers, compromise multi‑tenant systems, and hijack CI/CD pipelines. Although patches were quickly issued for several kernel versions (7.0, 6.19.12, 6.18.12, 6.12.85, 6.6.137, 6.1.170, 5.15.204, and 5.10.254), many distributions had not yet applied them, leaving countless desktops, servers, and cloud environments exposed. Experts warn that the exploit’s reliability surpasses earlier high‑profile kernel bugs like Dirty Pipe and Dirty Cow, and they urge all Linux users to verify that their systems incorporate the relevant fixes or follow vendor mitigation guidance.

    Read more: wired.com/story/dangerous-new-

    #Theori #Ubuntu #Amazon #SUSE #Debian #RedHat #Fedora #ArchLinux #Kubernetes #Linux #copyfail #security #security_cyberattacksandhacks #security_securitynews