US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’

The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers.
The post US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ appeared first on SecurityWeek.
Continue reading US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’

Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities

The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data.
The post Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities appeared first on SecurityWeek.
Continue reading Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities

Mozilla Issues New Firefox GPG Key Following Exposure

The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it.
The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek.
Continue reading Mozilla Issues New Firefox GPG Key Following Exposure

OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns

The current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold. 
The post OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns appeared first on SecurityWeek.
Continue reading OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns

Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility

CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.
The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek.
Continue reading Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility

Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies.
The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on SecurityWeek.
Continue reading Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data.
The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on Secu… Continue reading Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities.
The post Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix appeared first on SecurityWeek.
Continue reading Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix