RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

cybersecurityvulnerability

cPanel Auth Bypass Flaw Lets Attackers Hijack Hosting Servers — Patch Now

A critical authentication vulnerability has been disclosed in cPanel, the web hosting control panel that runs on a substantial share of shared and managed Linux

via The Hacker News ·
cybersecurityvulnerability

cPanel/WHM emergency patch closes 9.8-severity auth bypass in hosting control panels

WebPros has shipped an out-of-band fix for CVE-2026-41940, a 9.8-rated authentication bypass in cPanel and WHM that lets attackers reach the control panel witho

via BleepingComputer ·
vulnerabilityai

Critical RCE flaws in Gemini CLI and Cursor expose AI coding tools to silent takeover

Google has patched a maximum-severity CVSS 10 remote code execution flaw in the Gemini CLI's CI integration, alongside a parallel set of vulnerabilities in Curs

via The Hacker News ·
supply-chainmalware

DPRK Operators Lean on AI-Generated npm Payloads and Shell Companies in Latest Campaign

North Korean threat actors have refreshed their developer-targeting playbook, pushing malicious npm packages whose payloads show fingerprints of AI-assisted aut

via The Hacker News ·
cybersecurityvulnerability

Exposure management platforms: what buyers should demand vs. what vendors actually ship

Exposure management has become the umbrella category for tools that promise to unify vulnerability scanning, attack surface discovery, asset inventory, and risk

via The Hacker News ·
policytech-culture

FCC license threat against ABC faces steep legal wall thanks to 1996 statute

The FCC ordered Disney to file early renewal applications for all ABC-owned TV station licenses by May 28, arriving one day after Trump and the first lady deman

via Ars Technica ·
cloudpolicy

Iran strikes on AWS facilities push Pure DC to freeze Gulf data center buildout

Pure Data Centre Group, a London-based developer running more than 1GW of capacity across Europe, the Middle East, and Asia, has halted all new Middle East inve

via Ars Technica ·
tech-culturepolicy

Judge rejects Bankman-Fried's bid for new trial, calls conspiracy theory baseless

US District Judge Lewis Kaplan denied Sam Bankman-Fried's motion for a new trial, ruling that the FTX founder's claims of newly discovered witnesses and Biden-e

via Ars Technica ·
aiopen-source

LLM 0.32a0 refactors Python library around message sequences and typed streaming parts

Simon Willison has shipped an alpha of his LLM library that abandons its original prompt-in/text-out abstraction in favor of two richer primitives: prompts as o

via Simon Willison ·
aiopen-source

LLM 0.32a1 patches tool-call conversation reinflation bug from SQLite

Simon Willison shipped a quick follow-up release to his LLM command-line tool, tagged 0.32a1. The single fix addresses a regression introduced in the prior 0.32

via Simon Willison ·
malwarecybersecurity

Lotus Wiper Hits Venezuelan Energy and Utility Operators

A destructive malware strain dubbed Lotus has been deployed against Venezuelan energy companies and utility providers, according to reporting from Dark Reading.

via Dark Reading ·
tech-cultureopen-source

Noctua publishes official 3D CAD models for its cooling fan lineup

Noctua has made official 3D CAD models of its cooling fans available through its website, giving engineers and integrators authoritative geometry to work with i

via Hacker News ·