Article URL: https://www.usenix.org/publications/loginonline/data-only-attacks-are-easier-you-think Comments URL: https://news.ycombinator.com/item?id=49811429 Points: 4 # Comments: 0
EXCLUSIVE: GM CEO Mary Barra to attend Trump's state dinner for Xi, sources say Β Β Reuters
When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract clauses, and documenting incident escalation workflows. Now in its second year, the harder part of DORA is
Moscow oil refinery output halted after Sunday drone attack, sources say Β Β Reuters
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer just technical. It is
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSecΒ said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May'sΒ supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from
The new program expands Vectra AI's partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes.

Russia's Yaroslavl refinery shuts processing after a drone attack, sources say Β Β Reuters
A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.

Nvidia CEO to attend Trump dinner for Xi, source says Β Β Reuters
From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.

"Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.

Iran and US hit tankers in biggest wave of attacks on shipping since war began Β Β Reuters
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.

Researchers and OpenAI disagree on whether an earlier incident involving DseWiki, which the company did not disclose, was a βhack."

Frontier AI models have already demonstrated they can autonomously β and in some cases, inadvertently β conduct end-to-end compromises, but researchers warn the situation will become more urgent very soon.

DEFCON.social is open! From the first DEF CON announcement over 30 years ago inviting all to attend our first gathering: "We cordially invite all hackers/phreaks, techno-rats, programmers, writers, activists, lawyers, philosophers, politicians, security officials, cyberpunks and all network sysops and users to attend." That's still our core audience, but we welcome artists, musicians, infosec, privacy professionals, journalists, and everyone genuinely curious about how things work. Name: DEFCON.social URL: https://defcon.social/ Support Site: https://www.defcon.social/ Location: USA Languagesβ¦

Lockbit is by far this summerβs most prolific ransomware group, trailed by two offshoots of the Conti group.

CISA is warning that Palo Alto Networksβ PAN-OS is under active attack and needs to be patched ASAP.
