RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

privacycybersecurity

iOS Push Notification Database Leaks Signal Messages to Forensic Extraction

FBI forensic analysts pulled incoming Signal message content from a defendant's iPhone even after the Signal app was deleted. The messages persisted in iOS's pu

via Schneier on Security ·
cybersecuritymalware

Mirai variant weaponizes RCE bug in end-of-life D-Link routers

A fresh Mirai botnet campaign is hunting end-of-life D-Link routers, chaining a remote code execution flaw to conscript unpatched devices into DDoS infrastructu

via BleepingComputer ·
aiopen-source

Qwen3.6-27B runs flagship coding benchmarks on a laptop in 16.8GB

Alibaba's Qwen team released Qwen3.6-27B, a dense 27B-parameter open-weight model they claim beats their previous flagship Qwen3.5-397B-A17B across major coding

via Simon Willison ·
policy

RFK Jr. refuses to back CDC director on evidence-based vaccine policy

Health Secretary Robert F. Kennedy Jr. declined to commit to supporting evidence-based vaccine guidance from incoming CDC director nominee Erica Schwartz during

via Ars Technica ·
tech-cultureai

Tesla Q1 2026: $477M profit on thinner margins as regulatory credit revenue drops

Tesla posted $22.4 billion in Q1 2026 revenue, up 16 percent year over year, with net income of $477 million. Automotive revenue climbed to $16.2 billion on rou

via Ars Technica ·
cybersecuritysupply-chain

Vercel Widens Compromised-Account Count in Context.ai Breach Fallout

Vercel has expanded the scope of a breach tied to Context.ai, disclosing that additional customer accounts were compromised beyond the initial set identified. T

via The Hacker News ·
aicloud

'Zealot' Demo Shows AI Executing a Full Cloud Attack Chain End-to-End

A staged exercise dubbed Zealot illustrates how an AI agent can chain together the discrete steps of a cloud intrusion — reconnaissance, credential abuse, later

via Dark Reading ·
vulnerabilitycybersecurity

1,300+ SharePoint servers still exposed to actively exploited spoofing zero-day

Shadowserver's scans show more than 1,300 internet-facing Microsoft SharePoint servers remain unpatched against CVE-2026-32201, a spoofing flaw Microsoft disclo

via BleepingComputer ·
aitech-culture

Anthropic quietly A/B tested pulling Claude Code from Pro tier, then backtracked

Anthropic ran an unannounced pricing experiment on roughly 2% of new Pro-tier signups, gating Claude Code behind the $100/month Max plan. The test caught wider

via Ars Technica ·
supply-chaincybersecurity

Bomgar RMM Exploitation Surge Exposes Downstream Supply Chain Blast Radius

Attackers are escalating exploitation of BeyondTrust's Bomgar remote monitoring and management platform, turning a trusted administrative tool into a privileged

via Dark Reading ·
vulnerabilitycybersecurity

BRIDGE:BREAK: 22 Flaws Expose 20,000+ Serial-to-IP Converters to Takeover

Researchers disclosed 22 vulnerabilities, collectively dubbed BRIDGE:BREAK, affecting serial-to-IP converters manufactured by Lantronix and Silex. These devices

via The Hacker News ·
supply-chaincybersecurity

Checkmarx Supply Chain Hit: Poisoned KICS Docker Images and VS Code Extensions

Attackers published malicious artifacts masquerading as Checkmarx's KICS infrastructure-as-code scanner, seeding both Docker registries and the VS Code Marketpl

via The Hacker News ·