TheHackersNews

  • The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime
  • Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,
  • Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others.  Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API
  • A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery and research, that delay matters more
  • A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web
  • Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through
  • U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to

netzpolitik.org/ Aktuell

netzpolitik.org

Wir thematisieren die wichtigen Fragestellungen rund um Internet, Gesellschaft und Politik und zeigen Wege auf, wie man sich auch selbst mit Hilfe des Netzes für digitale Freiheiten und Offenheit engagieren kann. Mit netzpolitik.org beschreiben wir, wie die Politik das Internet durch Regulierung verändert und wie das Netz Politik, Öffentlichkeiten und alles andere verändert.
  • Überwachungsbrillen: Warum deutsche Gerichte Smart Glasses nicht verbieten
    Viele Gerichte regeln das Filmen per Hausrecht, wie hier am Kriminalgericht Moabit in Berlin.
    Heimlich filmen, mithören, sich zuflüstern lassen: Mit KI-Brillen bleibt das unauffällig. Andere Länder reagieren mit Verboten in Gerichtsgebäuden, Besucher*innen müssen die Brillen am Eingang abgeben. Die deutschen Justizministerien halten dagegen die bestehenden Regeln für ausreichend.
  • Kameras und Drohnen in Berlin: Was Verhaltensscanner erkennen sollen
    Berlin weitet die Videoüberwachung mit Verhaltensscannern aus. CC-BY-NC 2.0: Taz etc.
    Fest angebrachte und mobile Kamerasysteme der Polizei sollen in Berlin gefährdete Objekte überwachen und dabei dauerhaft alles scannen, was sich drumherum bewegt. Auch Drohnenaufnahmen könnten mit Verhaltensscannern kombiniert werden. Das geht aus einer Leistungsbeschreibung hervor, die nun öffentlich wurde.
  • Folge von US-Sanktionen: Internetkollektiv Autistici/Inventati stellt Betrieb ein
    Antifaschistische Gruppen haben es zunehmend schwer: Zuletzt floss auf einer anarchistischen Demonstration in Rom Blut. (Symbolfoto) – Alle Rechte vorbehalten: IMAGO / Independent Photo Agency Int.
    Keine zwei Wochen, nachdem die US-Regierung das italienische Internetkollektiv Autistici/Inventati zur Terrorgefahr erklärt hatte, drehen die Aktivist:innen ihre kostenlosen Online-Dienste ab. Nutzer:innen sollten rasch handeln und ihre Daten sichern.

suche