RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

cybersecuritymalware

Trigona ransomware deploys custom exfiltration tool to dodge detection

Trigona ransomware operators have shifted from off-the-shelf utilities like Rclone and MegaSync to a bespoke command-line tool called uploader_client.exe, accor

via BleepingComputer ·
cybersecuritymalware

Tropic Trooper Weaponizes SumatraPDF and GitHub to Drop AdaptixC2

The Tropic Trooper APT group is abusing a trojanized build of the open-source SumatraPDF reader as a delivery vehicle for AdaptixC2, a newer command-and-control

via The Hacker News ·
cybersecuritymalware

UNC6692 Weaponizes Teams Helpdesk Impersonation to Drop SNOW Malware

A threat cluster tracked as UNC6692 is abusing Microsoft Teams as the initial access channel, posing as internal IT support staff to coax targets into executing

via The Hacker News ·
tech-culture

Vast unveils custom flight suits and Swiss watch for Haven-1 private station crews

Vast, the company racing to deploy the first commercial space station, has introduced a purpose-built two-piece astronaut flight suit and certified a custom Swi

via Ars Technica ·
cybersecurityai

Webinar pitch: defenders need AI-speed response to automated exploit chains

The Hacker News is promoting a vendor webinar framed around a now-familiar asymmetry: attackers are stitching together reconnaissance, vulnerability triage, and

via The Hacker News ·
privacyvulnerability

Apple patches iOS flaw that preserved deleted Signal notifications for forensic recovery

A bug in iOS retained notification data even after users deleted the underlying messages, giving anyone with physical device access — including forensic tools u

via BleepingComputer ·
aitech-culture

Ars Technica publishes its newsroom AI policy: no AI-generated sources, no synthetic documentation

Ars Technica has formalized and published the AI rules that have governed its newsroom since generative tools became available. The core prohibition: AI cannot

via Ars Technica ·
cybersecurityvulnerability

CISA Puts BlueHammer Zero-Day on KEV, Gives Agencies Three Weeks to Patch

CISA added the BlueHammer flaw to its Known Exploited Vulnerabilities catalog after confirming active zero-day exploitation in the wild. Federal civilian agenci

via BleepingComputer ·
policytech-culture

Class action: Nintendo plans to keep tariff refunds instead of passing them to buyers

A class action filed in the Western District of Washington accuses Nintendo of America of positioning itself to collect tariff refunds from the federal governme

via Ars Technica ·
cybersecuritypolicy

Crypto scammers impersonate Iran, sell fake safe-passage to ships at Hormuz

Scammers posing as Iranian authorities are extorting bitcoin and tether payments from shipping companies stranded near the Strait of Hormuz, dangling false prom

via Ars Technica ·
cybersecuritymalware

GopherWhisper: China-Linked Go Backdoors Breach 12 Mongolian Government Systems

A China-aligned threat cluster dubbed GopherWhisper has compromised at least 12 Mongolian government systems using a family of Go-based backdoors. The choice of

via The Hacker News ·
privacyvulnerability

iOS Bug Preserved Deleted Signal Messages Long Enough for FBI Recovery

Apple has shipped a patch for an iOS defect that left supposedly-deleted Signal messages recoverable by forensic tooling. The flaw meant the operating system re

via The Hacker News ·