Friday Squid Blogging: Squid on a Stick at the New York State Fair
Looks tasty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
20 articles
Looks tasty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
The implant, identified by Rapid7 Labs with medium confidence as originating from North Korean state-sponsored actors, targets entities in South Korea's auto...
The vulnerability stems from missing authorization in PostgreSQL's logical decoding feature.
Upwind Security offers a platform that automatically maps cloud assets and refreshes data every 30 seconds to account for frequent configuration changes.
The attack occurred between 07:35 UTC and 21:45 UTC on Monday, August 31.
The critical Nexus vulnerability (CVE-2026-20212) allows unauthenticated attackers to execute code with root privileges by binding to an unrestricted IP addr...
The incident, detected on June 30, impacted the C-Track Canada system, exposing files from three Ontario courts.
Abliteration.ai aims to enable offensive cyber operations, red-teaming, and agent testing that other models refuse.
While specific CVE identifiers have not yet been assigned, Plex has directly emailed users, emphasizing the critical need to update to the latest versions to...
The bill addresses a perceived gap in regulatory power, as the NCUA's temporary authority to oversee third-party vendors has lapsed, leaving financial system...
The exploit targets a flaw in how Elementor Pro forms handle file uploads.
The cyberattack, which occurred around June 15, resulted in the theft of patient data including names, dates of birth, medical testing information, laborator...
Invisible Unicode tag characters often used for AI prompt injection have appeared in high-volume phishing attacks.
Manchester Airports Group (MAG) data allegedly leaked by FulcrumSec exposes emails and phone numbers of 8.8 million people.
HPE patched 35 ArubaOS-CX flaws, including a critical bug that could enable remote code execution.
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153...
It won’t work: My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt.
Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and ...
Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates.