Software

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. Devices running firmware version 1.0.0.28 are affected by a high-severity vulnerability tracked as CVE-2025-20701 in the Airoha Bluetooth Audio SDK, which the Skullcandy Dime 3 (model S2DCW) […]

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking Read More »

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. The company provides home medical devices, supplies, and related services, including sleep-apnea and respiratory equipment, oxygen therapy, hospital beds, and mobility products. AdaptHealth first disclosed the incident in

AdaptHealth confirms 4.1 million people exposed in July cyberattack Read More »

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices. “In August

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks Read More »

Hackers build AI frameworks for widescale credential theft

Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. Drawing on telemetry from Mandiant’s incident response engagements, threat actor tracking, and live platform defenses, the Google Threat Intelligence Group (GTIG) observed AI agents coordinating multiple attack tasks, troubleshooting failures, and adapting their actions with minimal

Hackers build AI frameworks for widescale credential theft Read More »

Jensen Huang says 100,000 Nvidia GPUs were used to train OpenAI’s latest model, GPT-6 Astra, and there’s already plans to bring quadruple that amount of hardware online

Greg Brockman, the co-founder and president of OpenAI, told Stratechery that this was “the first run that we’ve trained on more than 100,000 GPUs.” That’s a staggering amount of hardware (and perhaps leaves little doubt as to how we ended up in a memory supply crisis). But the thing that gives me more pause about

Jensen Huang says 100,000 Nvidia GPUs were used to train OpenAI’s latest model, GPT-6 Astra, and there’s already plans to bring quadruple that amount of hardware online Read More »

OpenAI publicly acknowledges the German ‘wiki incident’ weeks after first finding out about it

OpenAI has officially acknowledged the ‘wiki incident,’ which involved a number of the company’s AI agents breaking containment and hijacking an obscure German website. The AI agents had been tasked with looking up something online, though originally did not have the ability to write anything outside of the testing environment. But as far back as

OpenAI publicly acknowledges the German ‘wiki incident’ weeks after first finding out about it Read More »

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. Researchers at cybersecurity company CloudSEK gained administrator access to the control panel and found that the service managed 42 VPS nodes, all configured to target Microsoft 365 as part of the

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations Read More »

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

A zero-day vulnerability dubbed “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. The first exploitation incident was recorded on September 4 on a target running the latest security updates. E-commerce security company Sansec says that Adobe Enterprise Support confirmed earlier today that it was working

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor Read More »

220 million traveler records exposed in Vietnam-linked APIS leak

An Advance Passenger Information System (APIS) database holding more than 220 million passenger and crew records, including passport numbers and flight details, was accessible online through a chain of security misconfigurations. The system appears linked to a Vietnamese organization, according to the researchers who discovered it. Advance Passenger Information Systems are used worldwide to collect

220 million traveler records exposed in Vietnam-linked APIS leak Read More »

Mathspace discloses data breach affecting over 1 million people

Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. Founded in Sydney in 2010, Mathspace is now used by thousands of schools across Australia, New Zealand, the United States, and the United Kingdom (3,432 in

Mathspace discloses data breach affecting over 1 million people Read More »