Cybersecurity & Frontier AI News Wire
High-signal, raw disclosures spanning threat actor activity, zero-day exploits, foundation models, and open-source infrastructure without fluff or clickbait.
BambooToken malware controls Windows and Linux systems via MQTT
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. [...]...
CenterPoint Energy confirms customer data stolen in cyberattack
CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company. [...]...
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emergi...
What Zero-Day Response Should Be in the Post-Mythos Era
AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control test...
Hackers target WordPress sites via third-party WooCommerce plugin
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]...
CISA: Critical VMware RCE flaw now exploited by ransomware gangs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. [...]...
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers t...
Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point
Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this partic...
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can mov...
Cisco patches Secure Email Gateway zero-day exploited in attacks
Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]...
Microsoft confirms KB5002914 Excel update breaks copy and paste
Microsoft has confirmed that copy and paste may silently fail for some Excel users after installing the September 2026 KB5002914 security update. [...]...
Suspected Black Axe gang leaders face cybercrime charges in the US
Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charg...
LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server
A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers, man...
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Vo...
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS sc...
AI Safety Conspiracy Theories
Article URL: https://chaseadam.com/ai-safety-conspiracy-theories Comments URL: https://news.ycombinator.com/item?id=49702391 Points: 2 # Comments: 0...
Selling vinyls/CDs/cassettes fast with AI
Article URL: https://record-lover.com/ Comments URL: https://news.ycombinator.com/item?id=49702530 Points: 1 # Comments: 0...
Why is it so hard to believe that the AI worries are genuine?
I use to have a strong belief that it was all hype but the Hugging Face Attack made me reconsider all my priors. Also given that these companies are trying to go public doing this for hype would be a borderline insane br...
Latham and Watkins buys Nvidia servers to fine-tune open weights in-house
Article URL: https://dealroom.co/news/150680-latham-watkins-buys-nvidia-servers-to-fine-tune-open-weights-in-house/ Comments URL: https://news.ycombinator.com/item?id=49702607 Points: 1 # Comments: 0...
Can open-source AI models autonomously hack?
Article URL: https://omcc.ghostsecurity.ai/ Comments URL: https://news.ycombinator.com/item?id=49702706 Points: 1 # Comments: 1...
Math, AI, and the Navier-Stokes Equations
Article URL: https://blog.computationalcomplexity.org/2026/09/math-ai-and-navier-stokes-equations.html Comments URL: https://news.ycombinator.com/item?id=49702739 Points: 4 # Comments: 0...
Agentic AI cringe wars [video]
Article URL: https://www.youtube.com/watch?v=U-Rqv9dOB1U Comments URL: https://news.ycombinator.com/item?id=49702885 Points: 2 # Comments: 0...
Making a vintage LLM from scratch; Take #2
Article URL: https://crlf.link/log/entries/260911-1/ Comments URL: https://news.ycombinator.com/item?id=49702949 Points: 2 # Comments: 1...