Software

Hackers poison arrayref Rust crate to push infostealer malware

Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers’ systems during compilation. Within a 23-minute window, the attacker also poisoned two other crates, append-only-vec and internment, in the same supply-chain attack. The arrayref crate is a popular Rust library with more than 53 million downloads […]

Hackers poison arrayref Rust crate to push infostealer malware Read More »

US says hackers are targeting vulnerable water systems with the help of AI

Amidst a spate of ongoing cyberattacks targeting water systems across the country, the U.S. government’s security agencies are warning that hackers are actively breaking into Siemens devices used in critical infrastructure. U.S. cybersecurity agency CISA, the FBI, and the National Security Agency, among others, said on Wednesday that hackers are targeting “all” Siemens S7 programmable

US says hackers are targeting vulnerable water systems with the help of AI Read More »

Citrix urges admins to patch new NetScaler flaws as soon as possible

Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. The most severe of the two, tracked as CVE-2026-19490, can allow remote attackers without privileges to bypass authentication when the appliance is configured as an AAA virtual server or as a

Citrix urges admins to patch new NetScaler flaws as soon as possible Read More »

CISA warns of hackers exploiting critical MLflow vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical MLflow vulnerability. MLflow is an open-source AI engineering platform for large language models (LLMs) and agents backed by the Linux Foundation, with over 30 million monthly downloads, used by thousands of organizations to debug, evaluate, optimize, and

CISA warns of hackers exploiting critical MLflow vulnerability Read More »

‘This is not a theoretical risk—it is an active threat’: The NSA, FBI, CISA and more warn of AI-assisted hacks against critical US infrastructure and facilities

A cybersecurity advisory jointly authored by multiple US agencies, including the NSA, CISA, FBI, DOE, and EPA, warns the owners and operators of industrial facilities of an “active cyber threat” to Siemens S7 programmable logic controllers. “The threat actors are conducting reconnaissance and capability development against US-based Siemens PLC installations using AI-generated exploitation scripts disguised

‘This is not a theoretical risk—it is an active threat’: The NSA, FBI, CISA and more warn of AI-assisted hacks against critical US infrastructure and facilities Read More »

Don’t want Gemini in Chrome? Here’s how to remove it on Android

Affiliate links on Android Authority may earn us a commission. Learn more. Today, Gemini can compare products, hunt for better deals, make restaurant reservations, schedule appointments, and even help with travel bookings. And with Gemini in Chrome now rolling out to Android users in the US, much of that assistance is moving directly into the

Don’t want Gemini in Chrome? Here’s how to remove it on Android Read More »

New Manic Android malware can exfiltrate data through nearby devices

A new Android malware named Manic targeting users in multiple European countries has a fallback mechanism for exfiltrating data through nearby infected devices. The malware has been active since at least February and combines spyware, banking fraud, and remote control capabilities. It targets at least 169 banking, government/eID, payment, crypto wallet, messaging, and authenticator/2FA apps,

New Manic Android malware can exfiltrate data through nearby devices Read More »

Critical Zimbra RCE flaw now actively exploited in attacks

CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). ZCS is a popular email and collaboration software suite used by hundreds of millions of people and organizations worldwide, including thousands of businesses and hundreds of government agencies. The Zimbra security team

Critical Zimbra RCE flaw now actively exploited in attacks Read More »

Copilot was bamboozled into revealing how to hack itself, security researchers claim: ‘Copilot wasn’t breached; it was played’

There’s something really grating about Copilot’s cheery demeanour. It’s so eager to please, so happy to help, that I simply don’t respect it. However, even I feel sorry for the AI tool after learning that security researchers managed to hoodwink it into revealing details of how to hack itself—all by keeping the AI talking long

Copilot was bamboozled into revealing how to hack itself, security researchers claim: ‘Copilot wasn’t breached; it was played’ Read More »