Microsoft Paint and Photos now embed invisible GUID watermarks in images, including locally generated ones, raising privacy and security concerns.
Browsing Category
Security & Encryption
175 posts
Malicious Rust Crate Arrayref Runs A Build-time Payload
A Rust crate named Arrayref has been found to run a malicious payload during build time, raising security concerns for Rust developers and supply chain integrity.
AliExpress Runs Silent WebAudio Fingerprinting That Breaks Bluetooth Multipoint
AliExpress has implemented silent WebAudio fingerprinting that unintentionally breaks Bluetooth multipoint connections, raising security and privacy concerns.
Вслед за Ozon банком из Google Play выгнали другие приложения маркетплейса – Русская служба The Moscow Times
Google Play has removed multiple Russian marketplace apps, including Рус, following the ban on Ozon, raising concerns about app availability in Russia.
Firefox Is Now The Last Major Browser That Still Supports uBlock Origin
Firefox is now the only major browser that continues to support the popular ad blocker uBlock Origin, raising questions about future support in other browsers.
Someone Is Running Mass Vulnerability Scans, Spoofing AI Bots Like ClaudeBot
Cybersecurity experts identify a campaign of mass vulnerability scans using spoofed AI bot identities, including ClaudeBot, raising security concerns.
The Laptop Locker Setup That Improves Accountability in Shared Offices
To improve accountability in shared offices, set up secure, sturdy lockers with…
What I Learned By Putting GitHub Copilot Behind A MitM Proxy
A researcher tested GitHub Copilot behind a MitM proxy, revealing insights into data security and model behavior. Key findings and implications explained.
CVE-2026-68820: Microsoft Windows Ancillary Function Driver For WinSock Use-After-Free Vulnerability Actively Exploited (CISA KEV)
A use-after-free flaw in Windows Ancillary Function Driver for WinSock is actively exploited, enabling local privilege escalation. Details and mitigations outlined.
CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance (ASA) And Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability Actively Exploited (CISA KEV)
A heap inspection flaw in Cisco ASA and FTD is being exploited, risking remote code execution. Cisco confirms active attacks, urging urgent patching.