Wireshark 4.6.8 patches 28 security bugs, nine in file parsers

Wireshark 4.6.8 fixes 28 security bugs in the protocol analyzer, and nine of them fire when someone opens a saved capture file. Those nine sit in file parsers, the code that reads a capture off disk before any dissection begins: pcapng, Endace ERF, Tek… Continue reading Wireshark 4.6.8 patches 28 security bugs, nine in file parsers

Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily

Google Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious websites, helping reduce scams, phishing attempts, and other deceptive content. Abusive not… Continue reading Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily

PentestGPT: Open-source automated penetration testing agentic framework

PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, then exploit, then walkthrough, each stage feeding the next. Switch it to pentest mode and the st… Continue reading PentestGPT: Open-source automated penetration testing agentic framework

AI deployments are stretching enterprise security to its limits

CISOs and CTOs expect AI deployments to increase their organizations’ attack surface by an average of 14% over the next year. Nearly all lack visibility into AI deployments, and 90% are concerned about employees using unapproved AI tools outside … Continue reading AI deployments are stretching enterprise security to its limits

Locking your ssh-agent exposed local-only keys until OpenSSH 10.5

Lock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that tells the agent whether a request came from your own machine or arrived down a forwarded connection … Continue reading Locking your ssh-agent exposed local-only keys until OpenSSH 10.5

Your security vendor gets the frontier cyber model, you get the findings

Selected red team specialists can now use OpenAI’s cyber models to find and exploit weaknesses in client applications and infrastructure. Those clients never get the models themselves. That split is the design of the Daybreak Cyber Partner Progra… Continue reading Your security vendor gets the frontier cyber model, you get the findings

Anthropic to put AI in charge of reviewing Claude Code actions by default

Anthropic will make auto mode in Claude Code the default for new sessions on Pro, Max, and Team plans starting August 14. Users who previously selected a different default may receive a one-time prompt asking whether they want to switch to auto mode. I… Continue reading Anthropic to put AI in charge of reviewing Claude Code actions by default

OpenAI locks down Astra over potential critical cyber capabilities

OpenAI’s internal evaluation of its upcoming model, Astra, found significant advances in agentic coding and cybersecurity, leading the company to conclude that it cannot rule out the model reaching the critical capability level for cybersecurity … Continue reading OpenAI locks down Astra over potential critical cyber capabilities

Product showcase: Enpass Password Manager breaks away from the proprietary cloud model

Enpass is a password manager that stores passwords, passkeys, payment cards, identities, secure notes, software licenses, and other sensitive information in encrypted vaults. Vaults remain on the device or in a cloud storage service selected by the use… Continue reading Product showcase: Enpass Password Manager breaks away from the proprietary cloud model