Data and security

Auto Added by WPeMatico

Anthropic’s Claude Mythos found 10,000 critical vulnerabilities in one month. The patches can’t keep up.

Anthropic disclosed on Friday that Project Glasswing, its restricted cybersecurity initiative, has uncovered more than 10,000 high- or critical-severity vulnerability candidates across some of the most systemically important software in the world since the programme went live one month ago. Of those, 1,726 have been validated as true positives. 1,094 are confirmed high- or critical-severity […]

This story continues at The Next Web

Anthropic’s Claude Mythos found 10,000 critical vulnerabilities in one month. The patches can’t keep up. Read More »

GitHub confirms hackers stole thousands of internal code repositories after employee installed a poisoned VS Code extension

  It is an unsettling irony when the world’s largest code-hosting platform becomes the victim of its own ecosystem. GitHub confirmed on Tuesday that a threat actor exfiltrated approximately 3,800 internal repositories after compromising an employee’s device through a poisoned Visual Studio Code extension, marking one of the most significant breaches the Microsoft-owned company has ever […]

This story continues at The Next Web

GitHub confirms hackers stole thousands of internal code repositories after employee installed a poisoned VS Code extension Read More »

QIZ Security teams up with Google Cloud to help enterprises brace for the quantum cryptography threat

  The race to protect sensitive data from future quantum computers just gained fresh momentum. QIZ Security, a cryptographic posture management startup, has announced a collaboration with Google Cloud designed to help enterprises accelerate their migration to quantum-resistant cryptography, a shift that regulators and technologists increasingly regard as urgent. The partnership combines QIZ’s platform, which […]

This story continues at The Next Web

QIZ Security teams up with Google Cloud to help enterprises brace for the quantum cryptography threat Read More »

Cropin scales global AgTech analytics with Sisense-powered intelligence

When it comes to feeding the planet, the old ways of farming are running up against hard limits. Climate volatility, supply-chain disruption, and the sheer complexity of managing crops across dozens of countries have made data-driven agriculture not just a nice-to-have but an operational imperative. Cropin, the India-headquartered SaaS AgTech company, is leaning into that […]

This story continues at The Next Web

Cropin scales global AgTech analytics with Sisense-powered intelligence Read More »

Hackers stole fingerprints and medical data from 1.8 million people in NYC’s largest public hospital breach

  New York City Health and Hospitals, the largest public healthcare system in the United States, has disclosed that hackers stole personal data, medical records, and biometric information, including fingerprints, in a breach affecting at least 1.8 million people. The organisation reported the figure to the US Department of Health and Human Services, making the […]

This story continues at The Next Web

Hackers stole fingerprints and medical data from 1.8 million people in NYC’s largest public hospital breach Read More »

Grafana Labs refuses ransom after hackers steal already-open-source code

The hackers exfiltrated a codebase that was already open source, then demanded payment to keep it from being released. Grafana said no, and cited the FBI’s standing advice. It is the second high-profile extortion case in seven days. Grafana Labs, the open-source monitoring and visualisation company, disclosed on Monday that hackers had broken into its […]

This story continues at The Next Web

Grafana Labs refuses ransom after hackers steal already-open-source code Read More »

A student with a laptop and a radio stopped four high-speed trains. The crypto keys hadn’t been changed in 19 years.

At 23:23 on 5 April, a 23-year-old university student in Taichung transmitted a falsified General Alarm signal into the Taiwan High Speed Rail Corporation’s internal radio system. Four trains travelling at up to 300 km/h received the highest-priority emergency alert and switched to manual braking. The entire high-speed rail network was disrupted for 48 minutes. […]

This story continues at The Next Web

A student with a laptop and a radio stopped four high-speed trains. The crypto keys hadn’t been changed in 19 years. Read More »

Four OpenClaw flaws let attackers steal data, escalate privileges, and plant backdoors through the agent’s own sandbox

Cybersecurity researchers at Cyera have disclosed four vulnerabilities in OpenClaw that, when chained together, allow an attacker to steal sensitive data, escalate privileges, and establish persistent control over a compromised host. The flaws, collectively dubbed “Claw Chain,” affect OpenClaw’s OpenShell managed sandbox backend and its MCP loopback runtime. All four have been patched in OpenClaw […]

This story continues at The Next Web

Four OpenClaw flaws let attackers steal data, escalate privileges, and plant backdoors through the agent’s own sandbox Read More »

Snap, YouTube, and TikTok settle school addiction lawsuit, leaving Meta to face trial alone

Snap, Google’s YouTube, and ByteDance’s TikTok have reached settlements in the first lawsuit brought by a public school district over claims that social media addiction has disrupted learning and forced schools to spend heavily on combating a youth mental health crisis. The settlements, filed on Friday in federal court in Oakland, California, leave Meta Platforms […]

This story continues at The Next Web

Snap, YouTube, and TikTok settle school addiction lawsuit, leaving Meta to face trial alone Read More »

Google found the first AI-generated zero-day exploit. It stopped the attack before it started.

  Google has identified the first zero-day exploit it believes was developed with artificial intelligence. The criminal threat actor that built it planned to use it in a mass exploitation event. Google’s Threat Intelligence Group discovered the vulnerability before it was deployed, worked with the affected vendor to patch it, and disrupted the operation. The […]

This story continues at The Next Web

Google found the first AI-generated zero-day exploit. It stopped the attack before it started. Read More »

Shopping Cart