Goto

Collaborating Authors

 flaw


Firefox 154 fixes 58 security bugs, adds Nvidia GeForce Now streaming

PCWorld

The latest Firefox update patches nearly 60 security vulnerabilities and adds faster video skipping, new app icons, and Nvidia game streaming support. The newest major release of Firefox 154 for Windows, macOS, Linux, and Android brings a number of usability improvements, such as game streaming with Nvidia GeForce Now, faster video skipping, and new optional app icons, as well as nearly 60 security vulnerabilities fixed. Updates are also available for the ESR versions. The next major version of Firefox 155 is scheduled for September 1st. With it, Mozilla is switching--like Google Chrome and Microsoft Edge--to a fortnightly release cycle for its major versions.


Apple's iOS 26.6.1 patches 29 security flaws - here's why you'll want to install it

ZDNet

I wore the world's first HDR10 smart glasses TCL's new E Ink tablet beats the Remarkable and Kindle Anker's new charger is one of the most unique I've ever seen I wore the world's first HDR10 smart glasses TCL's new E Ink tablet beats the Remarkable and Kindle Anker's new charger is one of the most unique I've ever seen Apple's iOS 26.6.1 patches 29 security flaws - here's why you'll want to install it Along with MacOS and iPadOS, the latest update to iOS fixes a host of security bugs that could otherwise leave your device vulnerable to compromise or crashes. Among the bugs are ones that could trigger compromises or crashes. No flaw has been exploited in the wild yet, but you should still update. Though iOS 27 is expected to launch next month, Apple continues to update iOS 26 to address the latest security bugs. On Monday, the company released iOS 26.6.1 (as well as iPadOS 26.6.1 and MacOS 26.6.2) with fixes for 29 vulnerabilities.


Microsoft's August update fixes a Windows flaw that's already being attacked

PCWorld

PCWorld reports that Microsoft's August update patches a significant number of security vulnerabilities, including one Windows Winsock flaw already being actively exploited by attackers in the wild. The update covers critical risks across Windows, Office, Exchange Server, and cloud services, with some flaws allowing remote code execution or full account takeover without user interaction. Users are strongly advised to install these updates immediately to protect their systems from potential exploitation. As part of August's Patch Tuesday, Microsoft released security updates that address 398 new vulnerabilities. Alongside Windows and Office, other products and services are also affected: Teams, Exchange Server, Hyper-V, Windows Defender, Visual Studio, and Microsoft's cloud services. Microsoft classifies 42 of the vulnerabilities as critical. Among the remainder, all but one are classified as high risk. One Windows flaw is already being exploited in the wild, while two vulnerabilities were already publicly known beforehand. The next scheduled Patch Tuesday will be on September 8th, 2026.


Apple rushes out emergency fix for screen sharing flaw on Macs - update ASAP

ZDNet

I wore the world's first HDR10 smart glasses TCL's new E Ink tablet beats the Remarkable and Kindle Anker's new charger is one of the most unique I've ever seen I wore the world's first HDR10 smart glasses TCL's new E Ink tablet beats the Remarkable and Kindle Anker's new charger is one of the most unique I've ever seen Apple must have considered this flaw serious enough to warrant an immediate fix. Apple has released unexpected security patches for the Mac. The updates affect MacOS Tahoe, Sonoma, and Sequoia. Apple has pushed out new updates for MacOS Tahoe, Sonoma, and Sequoia in light of a serious security vulnerability. Why Apple's iOS 26.6 is worth installing (it's not just for the 91 security fixes) Released on Thursday, the updates for all three systems patch a flaw that could allow an attacker to exploit the Screen Sharing feature to access and control your Mac.


Chrome 150 fixes nearly 400 security flaws, including 15 critical ones

PCWorld

Google discovered 358 flaws internally while external researchers contributed additional findings, earning $90,000 in security bounties for their efforts. Users should manually update Chrome through'Help About Google Chrome' to ensure protection against these vulnerabilities if automatic updates haven't occurred. Chrome just released version 150.0.7871.46/47


Do you need to worry about Mythos, Anthropic's computer-hacking AI?

New Scientist

Do you need to worry about Mythos, Anthropic's computer-hacking AI? A powerful AI kept from public access because of its ability to hack computers with impunity is making headlines around the world. But what is Mythos, does it really represent a risk and might it even be used to improve cybersecurity? Anthropic's Project Glasswing aims to improve online security The past few weeks have brought apparently alarming news of Mythos, an AI that can identify cybersecurity flaws in a matter of moments, leaving operating systems and software vulnerable to hackers. The cybersecurity community is now beginning to get a better sense of how Mythos may change the face of cybersecurity - and not necessarily for the worse.


Vision Mamba Mender

Neural Information Processing Systems

Mamba, a state-space model with selective mechanisms and hardware-aware architecture, has demonstrated outstanding performance in long sequence modeling tasks, particularly garnering widespread exploration and application in the field of computer vision. While existing works have mixed opinions of its application in visual tasks, the exploration of its internal workings and the optimization of its performance remain urgent and worthy research questions given its status as a novel model. Existing optimizations of the Mamba model, especially when applied in the visual domain, have primarily relied on predefined methods such as improving scanning mechanisms or integrating other architectures, often requiring strong priors and extensive trial and error. In contrast to these approaches, this paper proposes the Vision Mamba Mender, a systematic approach for understanding the workings of Mamba, identifying flaws within, and subsequently optimizing model performance. Specifically, we present methods for predictive correlation analysis of Mamba's hidden states from both internal and external perspectives, along with corresponding definitions of correlation scores, aimed at understanding the workings of Mamba in visual recognition tasks and identifying flaws therein. Additionally, tailored repair methods are proposed for identified external and internal state flaws to eliminate them and optimize model performance. Extensive experiments validate the efficacy of the proposed methods on prevalent Mamba architectures, significantly enhancing Mamba's performance.



AI 'vibe-coding' platform's flaws allow BBC reporter to be hacked

BBC News

AI coding platform's flaws allow BBC reporter to be hacked The BBC has been shown a significant - and unfixed - cyber-security risk in a popular AI coding platform. Orchids is a so-called vibe-coding tool, meaning people without technical skills can use it to build apps and games by typing a text prompt into a chatbot. Such platforms have exploded in popularity in recent months, and are often heralded as an early example of how various professional services could be done quickly and cheaply by AI. But experts say the ease with which Orchids can be hacked demonstrates the risks of allowing AI bots deep access to our computers in exchange for the convenience of allowing them to carry out tasks autonomously. The BBC has repeatedly asked the company for comment but it has not replied.


AI is promising to revolutionise how we diagnose mental illness

New Scientist

As rates of mental health conditions like depression spike, we desperately need new ways of identifying and treating people in distress. The last big breakthrough in treating depression was all the way back in the 1980s. That was when Prozac, the first SSRI antidepressant, was released. It and its subsequent copycats soon swept the globe, and hundreds of millions of people have now taken this kind of medication. But while three-quarters of people say the pills have helped them feel better, they don't work for everyone.