A purported dataset of 140 million BlaBlaCar users is being offered for sale on the darknet, but security researchers are uncertain whether it represents a new incident or older data being resold.
German and US investigators have shut down the infrastructure of one of the world’s leading phishing kits specifically designed for MFA bypass in Microsoft 365.
Regular GPU workload cycling generates controllable kilohertz-range power oscillations that standard monitoring systems miss and can destabilize data centre power networks.
Password Podcast Episode 62 consolidates current standards discussions, Cisco Umbrella security vulnerabilities, and international attack methods for security operations.
JadePuffer exploits a CVE-2025-3248 vulnerability in Langflow to automatically encrypt AI model weights and training data with EncForge, causing estimated damages of $75,000 to $500,000 per model.
A missing prompt injection protection measure in the Azure DevOps MCP server allows hidden comments to redirect control flow of AI agents and trigger data leaks.
The LegacyHive vulnerability enables privilege escalation on Windows 10 2004+ and Windows Server 2022; an unofficial micropatch from ACROS Security is available, with an official CVE and update pending.