Goto

Collaborating Authors

 attacker


19 Chrome extensions were secretly stealing data. Uninstall these now

PCWorld

PCWorld warns that 19 Chrome and Edge extensions were found secretly stealing user data, including login details and crypto tokens, through hidden malware. The malicious campaign reportedly evaded detection for around two years, with attackers injecting harmful code into already popular extensions after they gained user trust. Google and Microsoft have removed these add-ons from their stores, but affected users must manually uninstall them to fully protect their devices. Security experts at Socket are warning about browser extensions for Google Chrome and Microsoft Edge that contain malware. The accompanying report mentions a total of 19 add-ons that were deliberately infected with malicious code in order to intercept user data and steal access details to digital wallets.


Chinese hackers target NASA and key US agencies, DOJ alleges

FOX News

This material may not be published, broadcast, rewritten, or redistributed. Quotes displayed in real-time or delayed by at least 15 minutes. Market data provided by Factset . Powered and implemented by FactSet Digital Solutions . Mutual Fund and ETF data provided by LSEG . Survivor's Christian Hubicki marvels at China's robotics games records: 'Willing to break the robots to do it' Chinese humanoid robot breaks Usain Bolt's 100m dash record at 9.39 seconds'CHUMP CHANGE': How a $17B settlement is a landmark for social, still good for Meta Kurt'CyberGuy' Knutsson recalls being stuck in New Orleans during Hurricane Katrina Cybercrime a global problem, thieves go for'targets of opportunity,' expert says Steve Doocy explores the US Air Force Academy's elite military training Supporting data centers is'perilous' politically: Brian Kilmeade Fox News Flash top headlines are here. Check out what's clicking on FoxNews.com.


That April Windows update you skipped? Hackers are exploiting it now

PCWorld

PCWorld reports that CISA has flagged four actively exploited security vulnerabilities affecting Windows, VMware vCenter, Microsoft SharePoint, and Apple macOS systems. Critical flaws carry severity scores as high as 9.8 out of 10, with attackers using them to deploy ransomware, install Monero mining malware, and bypass authentication entirely. Users and administrators are urged to apply available patches immediately, including recent Windows, SharePoint, VMware, and macOS updates, to avoid becoming targets. The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about four security vulnerabilities that are being exploited by attackers in the wild. CISA has added the vulnerabilities to its catalog of Known Exploited Vulnerabilities (KEV) . Microsoft Windows and SharePoint, VMware vCenter, and Apple macOS are affected. Inclusion in the KEV catalog sends an important signal: CISA doesn't simply list every known vulnerability out there, but only those for which there is concrete evidence of active exploitation by attackers. The agency points out that such vulnerabilities are among the most commonly used attack vectors and pose a significant risk.


Microsoft fixes 421 bugs and a Windows zero-day in August Patch Tuesday - update ASAP

ZDNet

I wore the world's first HDR10 smart glasses TCL's new E Ink tablet beats the Remarkable and Kindle Anker's new charger is one of the most unique I've ever seen I wore the world's first HDR10 smart glasses TCL's new E Ink tablet beats the Remarkable and Kindle Anker's new charger is one of the most unique I've ever seen The exploited zero-day flaw could allow an attacker to gain system privileges on a Windows PC. One vulnerability has already been exploited in the wild. Microsoft continues its onslaught against security vulnerabilities, fixing a whopping 421 bugs in August's Patch Tuesday update. But looking beyond the sheer number, Windows users should install this month's update, as it patches a zero-day flaw that's already been exploited by attackers. Aimed at Windows 11 25H2/24H2, Windows 11 23H2, and Windows 10, the 421 vulnerabilities encompass a range of Microsoft products, including Office, Exchange, Azure, and SharePoint.


Russian hackers can steal emails without a click

FOX News

This material may not be published, broadcast, rewritten, or redistributed. Quotes displayed in real-time or delayed by at least 15 minutes. Market data provided by Factset . Powered and implemented by FactSet Digital Solutions . Mutual Fund and ETF data provided by LSEG . Don't let fake election websites fool you before 2026 midterms Martha Reeves' 'BRUTAL' National Anthem performance goes viral'Mind-boggling' suspect at Trump golf course would approach federal agents: Ex-FBI agent Market analyst hails Chevron-Microsoft deal as a'tremendous breakthrough' AI agents spark concerns over'going rogue,' hacking companies Fox News Flash top headlines are here. Check out what's clicking on FoxNews.com.


A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims' Blind Spots

WIRED

A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims' Blind Spots A new type of malware can worm deep into AI coding systems to steal data and logins--and can flip a "death switch" to destroy files and keep out real users. As AI tools proliferate and become deeply ingrained in software development around the world, new research from the cybersecurity firm Crowdstrike shows how attackers are actively targeting the AI toolchain to steal access credentials, gain deeper access to a target environment, exfiltrate sensitive data, and even destroy target files and systems--all while finding new ways to cover their tracks. Researchers discovered a worm in the wild while investigating AI software supply chain attacks. Adam Meyers, CrowdStrike's senior vice president of counter adversary work, says that the company has not yet attributed the activity to a specific actor, but that it fits into larger evolutions in how attackers like TeamPCP (which Crowdstrike tracks as "Altered Spider") and North Korean groups are targeting the AI software supply chain. "This is one of the campaigns that we've seen showing that this is an emerging attack class," Meyers tells WIRED.


HalluSquatting AI attack could hijack your computer

FOX News

This material may not be published, broadcast, rewritten, or redistributed. Quotes displayed in real-time or delayed by at least 15 minutes. Market data provided by Factset . Powered and implemented by FactSet Digital Solutions . Mutual Fund and ETF data provided by LSEG . Fox News AI Newsletter: IBM's AI warning sends'shockwave' Would you trust a tiny dental robot? Tesla helped save a driver; is your car ready? So why is your device showing ads? Would you pay $8,000 for a robot to fold laundry?


Microsoft found malware that destroys PCs. Here's who's actually at risk

PCWorld

Microsoft discovered GigaWiper malware that overwrites hard drives multiple times and renders entire systems unusable by deleting partition entries and storage contents. PCWorld reports this sophisticated threat primarily targets organizations rather than home users, combining surveillance capabilities with irreversible data destruction. The malware integrates components from older threats like Crucio ransomware and includes a Go-based backdoor for remote system control and stealth operations. Microsoft has discovered a new piece of malware that not only spies on data but also renders entire systems unusable. The malware, known as GigaWiper, combines several destructive functions with a powerful backdoor for attackers. Security researchers at Microsoft Threat Intelligence first detected the activity back in October 2025. The recently published analysis reveals the full extent of the malware's capabilities.


One Token Embedding Is Enough to Deadlock Your Large Reasoning Model

Neural Information Processing Systems

However, this iterative thinking mechanism introduces a new vulnerability surface. We present the Deadlock Attack, a resource exhaustion method that hijacks an LRM's generative control flow by training a malicious adversarial embedding to induce perpetual reasoning loops. Specifically, the optimized embedding encourages transitional tokens (e.g., "Wait", "But") after reasoning steps, preventing the model from concluding its answer. A key challenge we identify is the continuous-to-discrete projection gap: naïve projections of adversarial embeddings to token sequences nullify the attack. To overcome this, we introduce a backdoor implantation strategy, enabling reliable activation through specific trigger tokens. Our method achieves a 100% attack success rate across four advanced LRMs (Phi-RM, Nemotron-Nano, R1-Qwen, R1-Llama) and three math reasoning benchmarks, forcing models to generate up to their maximum token limits. The attack is also stealthy (in terms of causing negligible utility loss on benign user inputs) and remains robust against existing strategies trying to mitigate the overthinking issue. Our findings expose a critical and underexplored security vulnerability in LRMs from the perspective of reasoning (in)efficiency.


Subgraph Federated Learning via Spectral Methods

Neural Information Processing Systems

We consider the problem of federated learning (FL) with graph-structured data distributed across multiple clients. In particular, we address the prevalent scenario of interconnected subgraphs, where interconnections between clients significantly influence the learning process. Existing approaches suffer from critical limitations, either requiring the exchange of sensitive node embeddings, thereby posing privacy risks, or relying on computationally-intensive steps, which hinders scalability. To tackle these challenges, we propose FEDLAP, a novel framework that leverages global structure information via Laplacian smoothing in the spectral domain to effectively capture inter-node dependencies while ensuring privacy and scalability. We provide a formal analysis of the privacy of FEDLAP, demonstrating that it preserves privacy. Notably, FEDLAP is the first subgraph FL scheme with strong privacy guarantees. Extensive experiments on benchmark datasets demonstrate that FEDLAP achieves competitive or superior utility compared to existing techniques.