News
Hidden "Glassworm" malware spreads through infected VS Code extensions
5+ mon, 14+ hour ago (517+ words) A new malware worm campaign has infected multiple Microsoft Visual Studio Code extensions using invisible Unicode characters to hide malicious code from both reviewers and security tools, security researchers say. The worm, named Glassworm, compromised seven extensions on the OpenVSX…...
"CanisterWorm" supply chain malware attacks npm
1+ hour, 46+ min ago (683+ words) A threat actor who stole credentials from a legitimate node package manager (npm) publisher has spread a persistent, worm-like malware across dozens of packages, security firms say. Named CanisterWorm by Aikido Security and Socket, the malware has now been updated…...
Serious path traversal bug found in Microsoft's NLWeb "Agentic Web" tool
7+ mon, 1+ week ago (332+ words) Microsoft's open source NLWeb framework for delivering AI-driven agentic web applications shipped with an easy to exploit path traversal vulnerability that revealed the context of sensitive system files and allowed the theft of authentication keys. Guan set up a test…...
Gov to explore "future connectivity between identity exchanges"
3+ day, 32+ min ago (345+ words) The federal government is exploring options to connect its own digital identity exchange to others, in what appears to be precursor work to a planned expansion slated for the end of this year. "The work will document how the AGDIS…...
OpenAI to buy Python toolmaker Astral
3+ day, 7+ hour ago (177+ words) OpenAI will acquire Python toolmaker Astral, as the ChatGPT owner looks to strengthen its portfolio against rival "Anthropic and gain more share "in "the artificial intelligence "coding tools market. The companies "did not disclose the financial terms of the deal,…...
Researchers uncover 'Darksword' iPhone spyware
4+ day, 56+ min ago (492+ words) A powerful software exploit capable of penetrating and stealing information from potentially "hundreds of "millions of Apple iPhones was planted on dozens of websites in Ukraine in recent weeks, researchers said. The discovery marks the second time this month that…...
Stryker contains cyber attack on its Microsoft environment
5+ day, 1+ hour ago (164+ words) Medical device maker "Stryker has contained a cyberattack that caused widespread disruption to its business "and is now prioritising "restoring "systems that directly "support customers, ordering and "shipping." A cyberattack on March 11 had affected Stryker's operations, hindering order processing, manufacturing…...
Coles sets up standard data streaming platform groupwide
6+ day, 30+ min ago (936+ words) Coles Group has stood up an enterprise-wide data streaming platform over the past two years, simplifying and standardising the way it handles real-time operational data. The retailer first spoke about its intentions to shift reliance from batch- to real-time data…...
Exploited Google Chrome zero-days added to US must-patch list
6+ day, 30+ min ago (215+ words) Two new serious vulnerabilities in the world's most popular web browser, Google Chrome, are under attack at the moment and should be patched as soon as possible, the United States Cybersecurity and Infrastructure Security Agency (CISA) said. Both are confirmed…...
Superloop's AI push continues with billing system project
1+ week, 1+ hour ago (42+ words) Superloop's AI push continues with billing system project'iTnews Griffith University takes control of its student recruitment Patchy wi-fi at ACCC despite access point expansion Superloop's AI push continues with billing system project Adobe settles US lawsuit over termination fees, subscription…...