News
-
Trump order sets 2030 deadline for federal post-quantum cryptography migration
President Donald Trump signed an executive order on June 22 setting 2030 and 2031 deadlines for federal post-quantum cryptography migration. The move advances the U.S. timeline and adds new planning and procurement pressure.
-
Xsolis says phishing attack exposed data of 1.4 million people
Xsolis said a January phishing attack exposed sensitive data tied to nearly 1.4 million people, including Social Security numbers and medical treatment information. The company is notifying affected individuals and offering identity monitoring.
-
GitHub updates actions/checkout to block forked pull request exploits
GitHub updated actions/checkout to block common forked pull request attack patterns in GitHub Actions, aiming to reduce pwn request risks tied to privileged workflows that can expose secrets and write tokens.
-
LastPass says Salesforce customer data exposed in Klue supply chain attack
LastPass said hackers used OAuth tokens stolen in the Klue supply chain attack to reach customer data in its Salesforce environment. The company said vaults were not affected and warned about phishing risk.
-
OpenAI expands Daybreak with GPT-5.5-Cyber update and Patch the Planet initiative
OpenAI said it is expanding its Daybreak effort with an updated GPT-5.5-Cyber model, a new security plugin and a Patch the Planet program aimed at helping defenders find, validate and fix software vulnerabilities faster.
-
FFmpeg fixes PixelSmash flaw that could crash media apps and, in some cases, enable code execution
FFmpeg has fixed CVE-2026-8461, a high-severity MagicYUV decoder flaw that researchers say can crash media apps and, in some cases, enable remote code execution on Jellyfin servers.
-
Google sets Sept. 30 deadline for Android developer verification in four countries
Google will start enforcing Android developer verification on Sept. 30 in Brazil, Indonesia, Singapore and Thailand, blocking normal installs of unverified apps on certified devices and raising new concerns for open-source app stores.
-
Canada spy agency used court warrant to disrupt foreign botnets on home routers and IoT gear
Canada’s spy service used a 2024 court warrant to disrupt two foreign-run botnets on routers and IoT devices, in the first use of its threat-reduction powers this way, according to a public Federal Court ruling.
-
Microsoft details AutoJack flaw that could let a web page trigger code on AI agent hosts
Microsoft said a flaw in AutoGen Studio could let a single web page trigger code execution on the host running an AI browsing agent. The issue affects two pre-release PyPI builds, while the stable release is not exposed.
-
Texas agency says license vendor breach exposed data on 3 million people
Texas Parks and Wildlife said a breach at its license system vendor exposed personal data tied to more than 3 million hunting and fishing license customers, including driver’s license details, passport numbers and contact information.








