News & Updates
The latest announcements, product releases, and platform updates.
Uber's Product Chief on Expansion into Hotels, Robotaxis, and Strategic Focus
Uber's Chief Product Officer Sachin Kansal discusses the company's expansion into hotels, boat rentals, and AI-driven features, while clarifying its strategic focus.
Google and Microsoft Remove ModHeader Extension Over Hidden Data Collection
Google and Microsoft have removed the ModHeader browser extension after researchers discovered a hidden browsing-history collector inside it.
CrashStealer: New macOS Malware Targets Sensitive Data with Sophisticated Techniques
A newly discovered macOS malware, CrashStealer, steals sensitive data, bypasses Gatekeeper, and uses advanced encryption techniques.
Silver Fox Group Deploys New MODBEACON RAT Using gRPC Streaming
The China-linked Silver Fox group has introduced MODBEACON, a new Rust-based remote access trojan using gRPC streaming for encrypted communications.
Unpatched XRING Flaw in XQUIC Allows Remote Server Crashes
A critical flaw in Alibaba's XQUIC library allows remote clients to crash servers with legal HTTP/3 traffic. No patch is available.
Three Critical Vulnerabilities in OpenClaw AI Assistant Patched
OpenClaw AI assistant patched three high-severity flaws enabling credential theft, privilege escalation, and arbitrary code execution.
Laser Attack Resets Tangem Wallet Passwords, Researchers Warn
Researchers demonstrate a laser attack on Tangem crypto wallet cards, allowing attackers to reset passwords and gain control.
Critical Zimbra Flaw Could Allow Arbitrary Code Execution via Crafted Emails
Zimbra warns of a critical stored XSS vulnerability in its Classic Web Client that could lead to arbitrary code execution through crafted emails.
Compromised jscrambler 8.14.0 npm Release Contains Malicious Infostealer
Version 8.14.0 of the jscrambler npm package was released with a malicious preinstall hook that deploys an infostealer targeting developer secrets.
Progress Software Orders Shutdown of ShareFile Servers Amid Security Threat
Progress Software has instructed ShareFile customers to shut down Windows servers running Storage Zone Controllers due to a credible security threat.
Injective Labs GitHub Compromise Exposes Cryptocurrency Wallets to Theft
Unknown threat actors compromised Injective Labs’ GitHub repository, publishing a malicious npm package to steal cryptocurrency wallet keys.
npm 12 Disables Install Scripts by Default, Deprecates Granular Access Tokens
GitHub releases npm 12 with install scripts disabled by default and deprecates granular access tokens to enhance security.
OpenAI Launches GPT-5.6 and ChatGPT Work After Government Approval
OpenAI's GPT-5.6 and ChatGPT Work are now publicly available after receiving government approval, aiming to set new standards in AI capabilities.
GhostApproval Flaw in AI Coding Assistants Puts Developers at Risk
Researchers at Wiz uncover a symlink flaw in popular AI coding assistants that could allow attackers to take control of a developer's computer.
OnlyFans Creators' DMCA Requests Expose Hacked Government Websites
Adult content creators' DMCA takedown requests inadvertently reveal widespread hacking of government and university websites.