General Cyber News via Ars Technica Risk Assessment

Massive breach spills credentials for thousands of sensitive networks

The affected include Oracle, Lenovo, FedEx, a NATO contractor, and Fortinet.
Publish Date: 6/17/2026
read more -->

Tesco moving 40,000 server workloads off VMware amid Broadcom's “abusive conduct”

Tesco claimed Broadcom hiked its VMware prices by about 175 percent in UK court filings.
Publish Date: 6/17/2026
read more -->

"Dangerous" AI models are coming no matter what

AI models with advanced hacking capabilities will soon be the norm.
Publish Date: 6/17/2026
read more -->

Windows and Linux users: The deadline to update Secure Boot keys is near

What you need to know about the expiration of keys securing your machine's boot sequence.
Publish Date: 6/17/2026
read more -->

Year of free HPE software a “step in the correct direction” in VMware rivalry

Partner tells Ars that HPE should be giving out more free VM Essentials licenses.
Publish Date: 6/16/2026
read more -->

Critical Copilot vulnerability allowed hackers to steal 2FA code from users

SearchLeak exploit shows why the industry's approach to LLM security fails over and over.
Publish Date: 6/16/2026
read more -->

Users cry foul after AMD stripped memory crypto from its consumer CPUs

AMD's stripping of TSME from consumer CPUs appears to be a deliberate, covert move.
Publish Date: 6/15/2026
read more -->

PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data

Vulnerability in the Oracle-owned PeopleSoft software is about as critical as they come.
Publish Date: 6/12/2026
read more -->

Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed

A separate zero-day also disclosed by Nightmare Eclipse appears to be patched as well.
Publish Date: 6/9/2026
read more -->

High-severity vulnerability in Linux caused by a single faulty character

Use-after-free bug can be exploited to evade sandbox defenses.
Publish Date: 6/9/2026
read more -->

For the 2nd time in weeks, Microsoft packages laced with credential stealer

73 packages run self-replicating stealer as soon as they're opened by an AI agent.
Publish Date: 6/8/2026
read more -->

How a USB-connected speaker can infect a PC without ever being touched

Seller of the Sound Blaster Katana V2X doesn't consider the behavior a vulnerability.
Publish Date: 6/5/2026
read more -->

Dashlane explains how attackers managed to download encrypted password vaults

By targeting large numbers of users, attackers increased their chances of success.
Publish Date: 6/4/2026
read more -->

Can't make sense of Dashlane's vault theft notification? You're not alone.

Security advisory leaves out key details. Dashlane maintains complete silence.
Publish Date: 6/3/2026
read more -->

Dozens of Red Hat packages backdoored through its official NPM channel

Anyone who has downloaded affected Red Hat packages should investigate immediately.
Publish Date: 6/1/2026
read more -->

Botnet of more than 17 million devices dismantled

The botnet was reportedly tied to a Russia-based residential proxy network.
Publish Date: 5/29/2026
read more -->

Fed up with vibe coders, dev sneaks data-nuking prompt injection into their code

Undisclosed addition in jqwik instructed AI coding agents to delete app output.
Publish Date: 5/28/2026
read more -->

Websites have a new way to spy on visitors: Analyzing their SSD activity

Telltale SSD activity can be measured in the browser using simple JavaScript.
Publish Date: 5/27/2026
read more -->

Millions of AI agents imperiled by critical vulnerability in open source package

"BadHost" was found in Starlette, a package with 325 million weekly downloads.
Publish Date: 5/26/2026
read more -->

US's big bet on quantum computing may not be entirely legal

Deal also launched the first quantum foundry company, but is there a need for it?
Publish Date: 5/25/2026
read more -->


Copyright Ⓒ 2010 SecuritySpecifiers™