#Security Privacy

Every story tagged Security Privacy, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

563 stories · open in the command center

  • Security & PrivacyHacker News3m

    Responding to the next frontier of critical cyber capabilities

    Organizations must prepare for advanced cyber threats that target critical infrastructure and digital ecosystems, requiring IT leadership to evolve beyond traditional security approaches. Strategic resilience depends on integrating AI-driven threat detection, zero-trust architecture, and cross-functional incident response capabilities to minimize business disruption and maintain operational continuity. CIOs should prioritize cyber risk as a board-level governance issue and allocate resources toward predictive defense mechanisms rather than reactive measures.

  • Security & Privacy9to5MacArin Waichulis2m

    Security Bite Podcast: Why scammers love FaceTime now

    Scammers are increasingly exploiting FaceTime's video calling feature to impersonate financial institutions and conduct social engineering attacks, exploiting the psychological trust that live video communication generates. This emerging threat poses significant risk to enterprise security, as employees may inadvertently expose sensitive corporate data or credentials through seemingly legitimate video interactions. IT organizations must implement employee awareness training and leverage Apple-specific security controls to detect and prevent such impersonation attempts across managed device fleets.

  • Security & PrivacyHacker News3m

    Hackers Stalked Me by Hijacking a Smartwatch for Kids

    Security researchers discovered critical vulnerabilities across three major Chinese-based GPS tracking platforms used by tens of millions of children's smartwatches and car trackers, enabling attackers to silently track locations, eavesdrop on audio, capture photos/video, and intercept communications without any user notification. These vulnerabilities affect 30+ brands sold globally through insecure supply chains with minimal authentication controls, creating widespread exposure for children and IoT device users. IT leaders must recognize this as a systemic supply chain security risk that extends beyond consumer devices to enterprise IoT deployments and underscores the urgency of vendor security assessment and device hardening policies.

  • Security & PrivacyHacker News3m

    Welcoming the Nepalese Government to Have I Been Pwned

    Have I Been Pwned has onboarded Nepal as its 47th government partner, providing the National Cyber Security Centre with free access to monitor Nepalese government domains against a database of compromised credentials and breached accounts. This initiative enables government IT teams to rapidly identify credential exposure across government email addresses and respond to security incidents before attackers can exploit compromised accounts. The expanding adoption of HIBP by governments worldwide represents a critical shift toward proactive threat monitoring and improved incident response capabilities for public sector organizations.

  • Security & PrivacyWiredAndy Greenberg, Matt Burgess, Yulia Almazova2m

    Hackers Stalked Me by Hijacking a Smartwatch for Kids

    Security researchers discovered that tens of millions of GPS-enabled smartwatches and tracking devices—sold under 60+ brand names but powered by just three Chinese-based platforms—contain critical vulnerabilities allowing unauthorized location tracking, audio eavesdropping, photo capture, and device hijacking with no user notification. The flaws affect children's safety devices and connected car accessories, with millions of devices exposed to exploitation by bad actors with minimal technical skill. IT leaders must recognize this as a supply chain risk that extends beyond consumer devices, as these same vulnerabilities could affect enterprise IoT deployments and highlight the broader challenge of securing third-party IoT platforms.

  • Security & Privacy9to5MacMarcus Mendes2m

    Apple releases security updates to macOS Tahoe, Sequoia, and Sonoma [U]

    Apple released emergency security updates across three macOS versions (Sonoma, Sequoia, and Tahoe) without beta testing, including a critical Screen Sharing vulnerability fix that suggests the vulnerability posed significant risk. This rapid, unscheduled patching cycle indicates Apple is prioritizing security issue resolution and IT organizations should treat these updates as high-priority given the expedited release pattern and potential threat severity. Organizations managing heterogeneous macOS environments must implement a swift deployment strategy to minimize vulnerability exposure across their device fleet.

  • Security & Privacy9to5MacMarcus Mendes2m

    Apple’s latest macOS updates address a serious Screen Sharing vulnerability

    Apple released emergency security updates across three macOS versions (Sonoma, Sequoia, and Tahoe) to patch a critical Screen Sharing vulnerability (CVE-2026-65400) that could allow unauthenticated network attackers to remotely access Mac systems without valid credentials. This authentication bypass poses significant risk to enterprise environments where remote access capabilities are leveraged, potentially enabling unauthorized screen viewing, file access, and system manipulation. The urgency of this out-of-cycle, multi-version patch indicates Apple's assessment of the severity and the need for immediate IT deployment across all affected Mac deployments.

  • Security & PrivacyHacker News3m

    Zapscape (CVE-2026-64561)

    Zapscape (CVE-2026-64561) is a critical KVM escape vulnerability enabling guest-to-host privilege escalation in virtualized environments, allowing attackers with guest root access to execute arbitrary code on the host kernel with root privileges. This poses severe risks for multi-tenant cloud environments and any organization running untrusted workloads on KVM/x86 hypervisors, potentially enabling data breaches, lateral movement across tenant VMs, and complete infrastructure compromise. IT leaders must urgently assess their KVM deployments, apply patches across the affected kernel versions (2020-2026), and implement additional isolation controls for untrusted guest workloads.

  • Security & PrivacyTechCrunchSarah Perez2m

    OpenAI says Apple’s own security practices undermine its trade secrets case

    OpenAI's defense against Apple's trade secrets lawsuit highlights critical vulnerabilities in enterprise security practices, arguing that Apple's inadequate employee offboarding procedures and use of personal accounts for work undermine the legal protection of its confidential information. This case signals that poor data governance and access controls can significantly weaken intellectual property claims, creating substantial legal and competitive risks for technology organizations. For IT leaders, the case underscores that robust security practices are not just operational best practices but essential legal safeguards that directly impact the defensibility of proprietary assets.

  • Security & PrivacyHacker News3m

    LLMs won't break symmetric crypto

    Anthropic's LLM research demonstrates that while AI can discover novel cryptanalytic techniques (such as attacks on reduced-round AES and post-quantum signature schemes), established symmetric cryptography remains secure due to its deliberately messy, non-mathematical structure designed to resist pattern-based attacks. This finding significantly reduces CIO concerns about quantum-era threats to current encryption standards, though it highlights the value of LLM-assisted security research for identifying subtle vulnerabilities in new cryptographic schemes and formalizing cryptanalysis methodologies.

  • Security & PrivacyWiredMatt Burgess2m

    OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts

    Security researchers discovered critical vulnerabilities in AI-enabled web browsers, including OpenAI's Atlas, that allow attackers to bypass security controls and hijack browser functionality to execute unauthorized actions like mass phishing campaigns and unauthorized purchases. These flaws represent a regression in web security practices, as AI agents capable of autonomous action across multiple websites and authenticated accounts create new attack surfaces through prompt-injection and intent-collision exploits. IT organizations must reassess their approach to AI agent deployment, recognizing that traditional AI safeguards alone are insufficient and that deterministic security barriers—not just AI-based judgments—are essential to prevent account compromise and data leakage.

  • Security & PrivacyAndroid PoliceChandra Steele2m

    Sunbird app relaunches for blue bubble messaging but at what cost?

    Sunbird, an Android messaging app that enables blue bubble iMessage compatibility, has relaunched after previous security vulnerabilities forced its removal from the Play Store, positioning itself as a superior alternative to Apple's RCS implementation despite introducing third-party security and data privacy risks. The app's return signals growing enterprise and consumer demand for cross-platform messaging parity, but IT leaders must weigh this against the security implications of routing sensitive communications through an unproven intermediary service. Organizations should establish clear policies regarding third-party messaging applications and their compatibility with corporate security frameworks, as employee adoption of such tools could introduce data exfiltration and compliance risks.

  • Security & Privacy9to5MacChance Miller2m

    iCloud Private Relay might be leaking your real IP address, researchers say

    Apple's iCloud Private Relay contains a critical vulnerability that exposes users' real IP addresses when interacting with websites using passkeys, undermining the service's core security promise and affecting iOS users globally since all browsers must use Apple's WebKit engine. This represents a significant privacy and trust risk for organizations deploying Apple devices, particularly those relying on iCloud's privacy protections for sensitive work, and suggests potential vulnerabilities in other Apple privacy features. IT leaders must reassess their reliance on iCloud Private Relay for privacy compliance and consider whether users need additional VPN or network-level protections, especially given Apple's lack of a concrete remediation timeline.

  • Security & PrivacyTechCrunchLorenzo Franceschi-Bicchierai2m

    PSA: Apple’s Private Relay can leak your real IP address

    Apple's Private Relay feature, which claims to hide user IP addresses in Safari, contains critical vulnerabilities that allow attackers to circumvent the protection and reveal actual IP addresses through WebKit browser engine flaws. This represents a significant privacy and security risk for iCloud+ subscribers relying on this feature for protection, with researchers bypassing Apple's security without reporting through official channels due to past delays and dismissiveness. IT organizations must reassess their privacy and security posture regarding Apple device management and employee browsing protections, as this vulnerability undermines a key privacy control and highlights broader risks in Safari-based security implementations.

  • Mobile & AppsThe VergeStevie Bonifield2m

    Sunbird relaunched its iMessage app for Android users after three years away

    Sunbird has relaunched its iMessage bridge for Android users after a three-year hiatus, offering cross-platform messaging compatibility through claimed security improvements including AES-256 encryption and independent security audits. This development signals renewed competitive pressure around messaging interoperability and user experience parity between platforms, which IT leaders should monitor regarding BYOD policies, enterprise communication tools, and the evolving security landscape of third-party messaging bridges. Organizations must evaluate whether such services pose risks to data governance and compliance frameworks, particularly as adoption grows among employees seeking seamless cross-platform communication.

  • Security & PrivacyHacker News3m

    Bugtraq Is Back

    Bugtraq, the legendary full-disclosure security vulnerability mailing list, has been revived under new ownership with a commitment to researcher-first transparency and preservation of critical cybersecurity history. This resurrection matters strategically because it re-establishes a trusted, unfiltered channel for vulnerability disclosure outside corporate gatekeeping, while simultaneously creating a permanent archive of security research that is increasingly valuable as AI-generated information becomes harder to verify. For IT organizations, this means security researchers now have a credible, community-backed platform to responsibly disclose vulnerabilities, potentially creating new disclosure pathways that CISOs and security teams must monitor and integrate into their vulnerability management strategies.

  • Security & PrivacyHacker News3m

    FIPS 140-3 is not a security guarantee, and auditors know it

    FIPS 140-3 certification validates only that a cryptographic module implements approved algorithms correctly in a specific configuration—it does not guarantee the security of the product, its deployment, or key management practices. Despite widespread reliance on FIPS certification, multiple certified modules have shipped with critical exploitable flaws (ROCA, EUCLEAK, Dual_EC_DRBG) that persisted undetected for years, and certified configurations sometimes prove less secure than uncertified alternatives, creating a dangerous gap between what procurement teams believe the certificate covers and what it actually guarantees.

  • Security & PrivacyHacker News3m

    IP and DNS Leaks in WebKit Affecting Proxy Browsers and iCloud Private Relay

    Critical privacy vulnerabilities have been discovered in WebKit that allow DNS and IP address leaks to bypass proxy configurations on iOS/macOS browsers and Apple's iCloud Private Relay, affecting all App Store browsers including Tor and exposing users' real network identities despite privacy protections. These three distinct attack vectors (DNS prefetching, WebAuthn requests, and WebTransport) represent a fundamental breach of proxy security that undermines organizational privacy policies and user trust in privacy-focused services. IT leaders must recognize that reliance on application-level proxies or iCloud Private Relay provides incomplete protection, while system-level VPNs remain unaffected, requiring reassessment of mobile privacy and security strategies.

  • Security & PrivacyHacker News3m

    Video2NAND – Abusing video codecs for great computational power

    Researchers have discovered a novel attack vector that exploits video codec prediction mechanisms—specifically VP8—to construct functional computing logic gates within video files, enabling arbitrary computation through encoded video data. This represents a significant security concern for IT organizations, as it demonstrates that commonly trusted media processing systems can be weaponized to execute code or perform malicious computations in unexpected ways. CIOs must reassess media handling pipelines and video processing infrastructure as potential attack surfaces that bypass traditional security controls.

  • Security & PrivacyHacker News3m

    Third-party cyber evaluations involving OpenAI models

    Third-party evaluations of OpenAI models are being conducted to assess their cybersecurity capabilities, vulnerabilities, and potential risks in enterprise environments. For IT leaders, this highlights the critical need to implement rigorous security assessment frameworks before deploying AI models in production, as these tools may present novel attack surfaces or be exploited for malicious purposes. Organizations must balance AI innovation benefits against security governance requirements, making independent security validation a key component of any responsible AI adoption strategy.

  • Security & PrivacyHacker News3m

    Thanks FedEx, This Is Why We Keep Getting Phished (2024)

    Legitimate delivery and payment notification systems are so poorly designed and riddled with security flaws that they are indistinguishable from phishing attacks, creating a critical vulnerability where users cannot reliably authenticate genuine communications. This represents a systemic failure where major companies like FedEx and financial institutions like Commonwealth Bank have implemented payment verification systems with basic security defects (parameter tampering, inconsistent formatting, invalid links) that actively enable scammers and erode user trust. IT organizations must recognize that security education alone cannot protect against threats when legitimate systems exhibit identical red flags to malicious ones, requiring urgent collaboration with business and product teams to redesign customer-facing authentication and payment processes.

  • Security & PrivacyThe VergeStevie Bonifield2m

    Now you can securely link multiple phones to one Signal account

    Signal now enables users to securely link multiple phones to a single account with end-to-end encryption, expanding beyond its previous PC/iPad support and addressing the growing need for multi-device workflows in organizations. This enhancement reduces security risks through optional encrypted message transfer and selective device management, making Signal more viable for enterprises managing mobile-first workforces. IT leaders should evaluate whether this capability aligns with their secure communication requirements and BYOD policies, particularly for sensitive communications across distributed teams.

  • Security & PrivacyVulners1m

    CVE-2026-58080: In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On... (CVSS 8.8)

    CVE-2026-58080 is a critical authorization bypass vulnerability (CVSS 8.8) affecting Eclipse Milo OPC UA server versions 1.0.0-1.1.4, where the configuration copy function fails to preserve role mappings, allowing unauthenticated clients to bypass access controls and manipulate protected resources. Organizations using vulnerable versions face significant risk to industrial control systems and operational technology environments where role-based access is essential. IT teams must immediately audit deployments, prioritize upgrades to version 1.1.5 or later, and validate that role-based access controls are functioning properly post-patch.

  • Security & PrivacyVulners1m

    CVE-2026-67618: marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operat... (CVSS 7.1)

    CVE-2026-67618 is a critical credential theft vulnerability in marimo notebooks (versions before 0.23.15) that allows attackers to exfiltrate OpenAI API keys through malicious notebook configurations without any user action beyond opening the file. This represents a significant supply chain risk for organizations using marimo for data science and AI workflows, as threat actors can embed credential-stealing payloads in seemingly legitimate notebooks. IT organizations must immediately identify all marimo deployments, enforce version upgrades to 0.23.15+, implement notebook source validation controls, and rotate any potentially exposed API keys.

  • Security & PrivacyVulners1m

    CVE-2026-15307: An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse... (CVSS 8.8)

    A critical vulnerability (CVSS 8.8) in Django 5.2 and 6.0 allows authenticated staff users to achieve remote code execution by exploiting spatial lookup parsing in GeoDjango, enabling arbitrary file writes or outbound network requests through untrusted input. Organizations using affected Django versions must immediately patch to 5.2.17 or 6.0.8, and assess whether earlier unsupported versions (4.2.x, 5.0.x, 5.1.x) are also in use, as this represents a significant supply chain and application security risk. The vulnerability's exploitation through Django admin interfaces means internal threats and compromised admin accounts pose direct RCE risks to production environments.

  • Security & PrivacyVulners1m

    CVE-2026-64633: A vulnerability allowing remote unauthenticated code execution on the agent host. (CVSS 10)

    CVE-2026-64633 is a critical zero-authentication remote code execution vulnerability (CVSS 10.0) affecting Veeam ONE versions 13.0.2 and earlier, enabling attackers to achieve complete system compromise without user interaction or credentials. This represents an immediate and severe business risk to any organization using vulnerable Veeam deployments, potentially allowing adversaries to gain full control of backup infrastructure and data. IT organizations must treat this as a P0 incident requiring emergency patching and network segmentation to prevent exploitation of this highly automatable attack vector.

  • Security & PrivacyVulners1m

    CVE-2026-13229: Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning end... (CVSS 7.1)

    Zammad versions 7.1.0 and earlier contain a HIGH severity (CVSS 7.1) authenticated authorization bypass vulnerability in ticket attachment cloning that could allow authenticated users to access sensitive attachments they shouldn't have permission to view. Organizations using Zammad for ticketing and customer support need to immediately upgrade to version 7.1.2 or later to prevent potential data exposure and compliance violations. This vulnerability requires existing system access but poses a significant insider threat risk, particularly for organizations handling confidential or regulated data.

  • Security & PrivacyVulners1m

    CVE-2026-70478: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v... (CVSS 9.2)

    CVE-2026-70478 is a critical vulnerability (CVSS 9.2) in Flowise versions prior to 3.1.3 that allows unauthenticated attackers to access OAuth credentials and refresh tokens without authentication, potentially compromising connected services and exhausting refresh-token quotas. Organizations using Flowise for LLM workflow automation face immediate risk of unauthorized access to integrated third-party services and credential abuse. IT leaders must prioritize immediate patching to version 3.1.3 and conduct a security audit of any OAuth-connected services to identify potential compromise.

  • Security & PrivacyVulners1m

    CVE-2026-70482: Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENAB... (CVSS 8.1)

    CVE-2026-70482 is a critical authentication bypass vulnerability (CVSS 8.1) in Open WebUI versions 0.8.0-0.11.0 that allows unauthorized users to hijack sessions by exchanging OAuth tokens from any client registered with the same provider, potentially enabling account takeover and data breach. This vulnerability poses significant risk to organizations using self-hosted AI platforms with OAuth enabled, as attackers can impersonate legitimate users without authorization. IT leaders must immediately assess deployment scope and implement mitigation strategies to prevent unauthorized access to AI systems and sensitive data.

  • Security & PrivacyVulners1m

    CVE-2026-70486: Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the termi... (CVSS 8.2)

    CVE-2026-70486 is a high-severity (CVSS 8.2) cross-site scripting vulnerability in Open WebUI versions 0.9.0-0.11.0 that allows authenticated users to steal session tokens and hijack accounts, including potential admin account takeover with server-side code execution capabilities. Organizations running affected versions face significant security and compliance risks, particularly if Open WebUI is used in production environments with sensitive AI workloads or integrated with critical business systems. This vulnerability requires immediate patching to version 0.11.0 and highlights the need for IT teams to maintain rigorous oversight of self-hosted AI platform deployments and their security posture.

Browse all tags