RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

vulnerabilitycybersecurity

Microsoft Ships Fix for Critical ASP.NET Core Privilege Escalation Flaw

Microsoft has released a patch for CVE-2026-40372, a critical privilege escalation vulnerability in ASP.NET Core. The flaw allows an attacker to elevate privile

via The Hacker News ·
cybersecuritymalware

Mustang Panda Deploys LOTUSLITE Variant Against Indian Banks, South Korean Policy Targets

China-linked threat actor Mustang Panda has resurfaced with a refined variant of its LOTUSLITE backdoor, aimed squarely at financial institutions in India and p

via The Hacker News ·
tech-culturecloud

NASA's Artemis II proves laser comms can stream HD video from the Moon

Artemis II's four-person crew beamed most of their video home over radio — S-band at 3-5 MB/s, a modest step up from Apollo's 50 KB/s but still low-definition b

via Ars Technica ·
cybersecuritymalware

North Korea's 'Contagious Interview' Job Scam Now Self-Propagates Through Victims

DPRK-aligned threat actors running the long-tracked 'Contagious Interview' campaign have evolved their playbook: the fake job recruitment scheme now spreads thr

via Dark Reading ·
cybersecuritymalware

Ransomware Negotiator Flips Sides, Pleads Guilty in BlackCat Extortion Scheme

A ransomware negotiator — one of the professionals companies hire to broker payments with extortion crews — has pleaded guilty to conspiring with the BlackCat/A

via Dark Reading ·
cybersecurityidentity

Scattered Spider's 'Tylerb' Pleads Guilty to $8M Crypto Theft Spree

Tyler Robert Buchanan, a 24-year-old Scottish national and senior operator in the Scattered Spider cybercrime collective, has pleaded guilty in U.S. federal cou

via Krebs on Security ·
supply-chainmalware

Self-Propagating npm Worm Hijacks Packages to Exfiltrate Developer Tokens

A worm is spreading laterally through the npm ecosystem by compromising maintainer accounts, injecting malicious payloads into published packages, and using har

via The Hacker News ·
supply-chaincybersecurity

Self-propagating npm worm steals dev tokens and republishes via hijacked publish rights

A worm-class supply-chain attack is moving through the npm registry by abusing publish tokens it finds on compromised developer machines. Socket and StepSecurit

via BleepingComputer ·
policycybersecurity

Spain takes down Spanish-speaking world's largest manga piracy site, $4.7M seized

Spanish police dismantled what they describe as the largest Spanish-language manga piracy operation, running since 2014 and pulling in millions of monthly visit

via BleepingComputer ·
cybersecuritymalware

SystemBC C2 Server Exposes 1,570+ Victims Tied to Gentlemen Ransomware Crew

A misconfigured SystemBC command-and-control server has leaked the operational footprint of The Gentlemen ransomware group, exposing more than 1,570 compromised

via The Hacker News ·
tech-culturecybersecurity

Teams Efficiency Mode lands in May to rescue low-spec PCs from Electron bloat

Microsoft is shipping an Efficiency Mode for Teams on Windows and Mac in early-to-mid May 2026, enabled by default on devices with constrained CPU and memory. T

via BleepingComputer ·
cybersecuritytech-culture

Vishing Crews Now Run Like Sales Floors: Inside the Caller-as-a-Service Economy

Phone scam operations have matured into a segmented service economy that mirrors legitimate enterprise structure. Distinct specialists handle malware developmen

via BleepingComputer ·