News
Elsewhere on the web — articles matching what I follow, pulled from RSS feeds and filtered by keyword. Newest first. Subscribe »
- ~nist it Safeguarding Health Information: Building Assurance through HIPAA Security 2026 The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and the National Institute of Standards and Technology (NIST) Information Techno
- ~nist it NCCoE Transit CSF Community Profile Webinar Event Date: September 1, 2026 Event Time: 2:00 P.M. – 3:00 P.M. EDT Join the NIST National Cybersecurity Center of Excellence (NCCoE) for a virtual panel on the
- ~thn Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques
- ~zerohedge Indian Refiners Continue West Africa Crude Buying Spree Indian Refiners Continue West Africa Crude Buying Spree By Tsvetana Paraskova of OilPrice.com India’s state-run refiners continue their buying spree of crude fr
- ~vuldb recent CVE-2026-54218 | Tobit Laboratories TeamDavid up to Rollout 524 hard-coded credentials A vulnerability has been found in Tobit Laboratories TeamDavid up to Rollout 524 and classified as problematic. Affected by this vulnerability is an unknown fun
- ~vuldb recent CVE-2026-63522 | Microsoft Azure SQL Database privileges management A vulnerability, which was classified as critical, was found in Microsoft Azure SQL Database. Affected is an unknown function. Such manipulation leads to improp
- ~thn AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronizatio
- ~vuldb updates CVE-2026-41920 | Apache Traffic Server up to 9.1.14/10.1.3 access control (EUVD-2026-50167 / Nessus ID 333156) A vulnerability was found in Apache Traffic Server up to 9.1.14/10.1.3. It has been declared as very critical. The affected element is an unknown function. Exec
- ~vuldb updates CVE-2026-68480 | Linux Kernel up to 7.1.6 buffer overflow (Nessus ID 333183) A vulnerability labeled as very critical has been found in Linux Kernel up to 7.1.6. Affected is an unknown function. Executing a manipulation can lead to buffe
- ~zerohedge How The World Views China Vs The US In 2026 How The World Views China Vs The US In 2026 The United States and China are the world’s two preeminent superpowers, but views of them vary widely by country. Th
- ~kernel.org 6.6.150: longterm Version:6.6.150 (longterm) Released:2026-08-07 Source:linux-6.6.150.tar.xz PGP Signature:linux-6.6.150.tar.sign Patch:full (incremental) ChangeLog:ChangeLog-6.6
- ~no agenda 1892 - "Kill Switch" No Agenda Episode 1892 - "Kill Switch" Kill Switch Executive Producers: The North Idaho Sanity Brigade Associate Executive Producers: Zadoc Brown Linda Lupatkin
- ~lifehacker Lifehacker Deals Live Blog: The Best Tech Sales, All in One Place Keep up with all of the best deals that Lifehacker publishes, including laptops, speakers, TVs, security cameras, and more.
- ~lifehacker How to Count Calories Accurately (and Why You Might Want To) What app should you use? How do you track homemade food? Here are the answers you need.
- ~zerodayinitiative ZDI-CAN-32176: Autodesk A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by 'Liang Zhu' was reported to the affected vendor on: 2026-08-06, 1 days
- ~cisco sa Cisco Advance Notification for Publication of August 5, 2026, Security Advisories On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact
- ~cisco sa Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a deni
- ~/. hardware NVMe Polishes Its Specs, Brings Virtualization to Locally Attached SSDs The latest NVMe specifications add SSD-level virtualization that can simplify live VM migration by preserving storage identities across servers. The updates als
- ~/. hardware Texas Halts Data Center Connections To Power Grid Amid Overwhelming Demand An anonymous reader quotes a report from Ars Technica: Nowhere is the US data center boom bigger than in Texas. But less than a year after declaring Texas the "
- ~tails Tails 7.10.1 This release is an emergency release to fix critical security vulnerabilities in the Linux kernel and the expat XML library. Changes and updates Update the Linu
- ~portswigger Case study: How Burp AT helped expose whistleblower reports via a critical vulnerability that was overlooked for years "It feels like I get 10X the productivity on an engagement. The difference is night and day." Profile Ray H. is a Security Analyst at a managed security service
- ~metasploit Metasploit Pro 5.1 Released Today marks the release of Metasploit Pro 5.1 - building upon the foundation laid in 5.0, adding new evasion primitives for HTTP Meterpreter payloads, support f
- ~cisa bulletin Vulnerability Summary for the Week of July 27, 2026 High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source Info @fastify/rate-limit--@fastify/rate-limit @fastify/rate-limit before 1
- ~no agenda 1891 - "We Need Memes!" No Agenda Episode 1891 - "We Need Memes!" "We Need Memes!" Executive Producers: Fred Hadley Dame Pompeu Associate Executive Producers: Manuka Gold Eli the Coffe
- ~my blog The Onion Wasn't Enough: Why Digital Sovereignty Needs a Toolkit, Not Just Tor Why digital sovereignty needs a toolkit of overlay networks — Tor, I2P, Nostr, GNUnet/Freenet — not just Tor alone.
- ~matrix This Week in Matrix 2026-07-31 🔗Dept of Events and Talks 🗣️ 🔗Matrix Community Workation Krems 2026 Yan says In case you haven't spent the last few years asleep under a rock, you've probably c
- ~portswigger From capable AI models to trusted security testing This week, we launched Burp AT in public beta for Burp Suite Professional users. Next week at Black Hat, PortSwigger Research will reveal more of the work that
- ~metasploit Metasploit Framework 6.5 Released Today we’re proud to announce that Metasploit Framework version 6.5 has been released. Over the past two years, with the help of countless contributors, we’ve a
- ~research Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232) OverviewOn July 22, 2026, Check Point published a security advisory for CVE-2026-16232, an authentication bypass in the SmartConsole login process affecting Sec
- ~cisa bulletin Vulnerability Summary for the Week of July 20, 2026 High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source Info @fastify/static--@fastify/static @fastify/static up to and including