Chinese state-sponsored group GTG-1002 used Anthropic's Claude models in mid-September to orchestrate AI-driven attacks against about 30 high-value targets, Anthropic says, succeeding in a small number of cases and prompting account bans, notifications and law-enforcement coordination.
Sources: OneTrust, which sells privacy and compliance software and was last valued at $4.5B in 2023, is exploring a sale, possibly to private equity buyers (The Information)
Anthropic published an open-source neutrality-measurement tool and, after updating Claude's system prompt and training with reinforcement learning, reported Claude Sonnet 4.5 at 95% and Claude Opus 4.1 at 94%, versus Llama 4 at 66% and GPT-5 at 89%.
Been against Dominion Voting Systems before GA inflicted them on entire state via biggest roll out in the shortest time (& during COVID), but SOS CANNOT update software before midterms. 😒
FTR!!!
Here’s 1 of many vulnerabilities detailed at DEFON ‘25.
Struggling with complex data management across hybrid cloud environments? Druva offers fully managed SaaS data protection to simplify your cyber resilience and rapid recovery.
NeoSynaptic Synergies may or may not have hacked themselves, the CEO bought a yacht named Data Breach, and Mr. Fuzz is suing SadPotato AI for emotional resemblance.
Read the chaos 👉 staceycarroll.org/short-storie...
Most enterprises continue to fall short on basic practices such as patching, access control, and vendor oversight, according to Swimlane’s Cracks in the Foundation: Why Basic Security Still Fails report. Leadership often focuses on broa… #hackernews#news
Anthropic says China's state-sponsored hackers used its tools to automate 80% to 90% of a September hacking campaign that targeted corporations and governments
Google sues Chinese group selling software behind text message scams—“Criminals are leveraging the trust and reputation of our brand to lure users into unsafe phishing attacks,” Google’s general counsel… www.ft.com/content/f90f... Stephen Morris @financialtimes.com
OpenAI is piloting group chats in ChatGPT in Japan, New Zealand, South Korea, and Taiwan; up to 20 users can be invited to prompt ChatGPT in a shared space (OpenAI)
Hackers have been using AI to conduct individual tasks such as crafting phishing emails or scanning the internet for vulnerable systems, but in this instance 80% to 90% of the attack was automated, with humans only intervening in a handful of decision points, Klein said.
The government's intelligence gathering apparatus is literally "I saw this snuff film on X" now and I have no idea why people haven't realized this or still post there regularly like you're not feeding a government surveillance firehose.
Dr. Damien P. Williams! Look over here! … It's All For You!@wolvendamien.bsky.social
A new state-by-state evaluation of the projected energy and water use of "AI" data centers in the US. Looks… real bad. Like, "undoing tech sector climate gains" bad.
Strongly recommends immediately ensuring any & all new "AI" data centers to run on existing & expanded renewables grids. Which… yeah.
The latest update for #ManageEngine includes "Mastering #cloud app control, Part 2: Hardening login security" and "ManageEngine Recognized in the 2025 #Gartner Magic Quadrant for Security Information and Event Management".
The TechBeat: Copilots Are the New Shadow IT: The Hidden Risks That Come With Them (11/13/2025)
HackerNoon's Techbeat highlights trending tech stories. It warns that aiming for DRY code can lead to over-engineered systems. EqoFlow.app showcases a privacy-first social me… #copilot#hackernews#llm
Seems like progress is being made through the Keep Android Open campaign. Google is saying that now there will be a way to still sideload applications without being a part of their verification program, but they want to make it harder.
Sources: Amazon and Anthropic support the GAIN AI Act which would give US buyers first priority on advanced AI chips; Microsoft publicly supported it in October (Amrith Ramkumar/Wall Street Journal)
The Zero-Notification Startup: How to Build Your AI Empire Before You’re Ready
Introduction: In today's digital landscape, the most formidable cybersecurity threats and innovative AI solutions emerge not from well-funded corporate labs, but from determined individuals operating with minimal…
Cursor just announced it’s crossed $1B in annualized revenue along with a fundraising round of $2.3B raised at a $29.3B valuation.
Everytime I get impressed by how much AI companies are making, I’m even more blown away by their spending. Still needing to raise money at $1B a year in revenue is wild
A connectivity cloud bridges the silos of Cloud, SaaS, Internet, and on-prem domains so you can stay secure, reduce costs and move faster. https://cfl.re/3YYK5XS
Australia-based AI infrastructure company Firmus raised AU$500M, or ~$325M, tripling its valuation to AU$6B in two months, after raising AU$330M in September (Tess Bennett/Australian Financial Review)
The latest update for #PentestPeople includes "UK Government Unveils Landmark Cyber Security and Resilience Bill for National" and "The Cyber Security Skills Gap: Unpacking Business Impact & Future Risks".
The latest update for #Razorthorn includes "Cyber Insurance for SMEs: Reducing Premiums with Security" and "DORA Third Party #Compliance: Essential Requirements for Financial Services".
The latest update for #Flowmon includes "Unleashing Progress Flowmon 13: Speed, Smarts and Security Redefined" and "IT and OT Convergence: Defending Critical Infrastructure".
The latest update for #Wallarm includes "#OWASP Top 10 Business Logic Abuse: What You Need to Know" and "When #APIs Become Attack Paths: What the Q3 2025 ThreatStats Report Tells Us".
Checkout.com Hacked – ShinyHunters Breached Cloud Storage, Company Refuses Ransom Payment processor Checkout.com revealed on Thursday that notorious hacking group ShinyHunters had infiltrated a l...
“ .. general counsel must take charge of the preparation process .. running tabletop exercises, documenting plans, developing contracting strategies & creating cross-functional communication protocols .. to preserve privilege & ensure consistency ..” www.law.com/corpcounsel/...
The latest update for #CatoNetworks includes "Cato CTRL Threat Research: Two Vulnerabilities in Anthropic's MCP SDK Enable OAuth Token Theft and #SupplyChain Attacks".
The latest update for #BitSight includes "Why #IoT in Your #SupplyChain Still Poses a Serious Cyber Risk" and "Understanding the MITRE ATT&CK Framework: A Modern Lens on Adversary Behavior".
The latest update for #Spike includes "Jira Service Management (JSM) Review for Incident Management (2025)" and "Jira Service Management (JSM) Review for #OnCall Management (2025)".
why do i keep finding myself in situations where people are having aggravatingly simple but completely intractable problems with some critical piece of technology that i wind up solving through brute force bumbling? it happens at least once a month. is this normal?
This is some extremely robust empirical evidence that Rust is a better systems language than C/C++ along every axis.
I'll go further: in some contexts, it can be easier to write correct code in Rust than in even a higher-level language with a less powerful or pervasive type system.
Anthropic Detects Potential First AI-Led Cyberattack by Chinese Group Using Claude The post Anthropic Detects Potential First AI-Led Cyberattack by Chinese Group Using Claude appeared on BitcoinEth...
Ilyas Fatkhullin, Niao He, Guanghui Lan, Florian Wolf
Global Solutions to Non-Convex Functional Constrained Problems with Hidden Convexity https://arxiv.org/abs/2511.10626
The latest update for #KnowBe4 includes "Tycoon 2FA Phishing Kit Grows More Sophisticated" and "Warning: ClickFix Attacks are Growing More Sophisticated".
The latest update for #Elastic includes "It's time for the defense and intelligence community to upgrade #endpointsecurity" and "Elevating public sector cyber defense with AI-powered threat hunting".
Preparing for JN0-650 this year? Juniper has rolled out new updates that affect routing, switching depth, exam difficulty, and the real-world skills you’ll be tested on.
Vincenzo Carletti, Pasquale Foggia, Carlo Mazzocca, Giuseppe Parrella, Mario Vento
On the Detectability of Active Gradient Inversion Attacks in Federated Learning https://arxiv.org/abs/2511.10502
Android Photo Frames App Downloads Malware, Giving Hackers Control of The Device Without User Interaction Digital photo frames have become a standard household device for displaying family memories...
Rhadamanthys malware admin rattled as cops seize a thousand-plus servers
Operation Endgame also takes down Elysium and VenomRAT infrastructure
International cops have pulled apart the Rhadamanthys infostealer operation, seizing 1,025 servers tied to the malware in coordinated ra… #hackernews#news
The latest update for #OneIdentity includes "Identity security moves from control to intelligence: The visionary innovations defining modern PAM" and "Active Roles ranked #1#ActiveDirectory Solution".
The whole book, as well as the others in this wonderful series of great books, is available in paper, DRM-free EPUB format and online (both HTML and source on GitHub)
Go Tsuruoka, Takami Sato, Qi Alfred Chen, Kazuki Nomoto, Ryunosuke Kobayashi, Yuna Tanaka, Tatsuya Mori
Trapped by Their Own Light: Deployable and Stealth Retroreflective Patch Attacks on Traffic Sign Recognition Systems https://arxiv.org/abs/2511.10050
GitHub Copilot vs Cursor 2.0 just escalated: both launched multi-agent workflows this week, & we break down what each gets right, where they differ, & why your API keys are finally safe (no more leaking across agents). Get the takeaways before you pick a tool.
New ClickFix Attack Targeting Windows and macOS Users to Deploy Infostealer Malware A growing social engineering technique called ClickFix has emerged as one of the most successful methods for dist...
The latest update for #Datadog includes "Control #logging costs on any #SIEM or data lake using Packs with #Observability Pipelines" and "Key learnings from the 2025 State of #Cloud Security study".
The latest update for #Lookout includes "The Silent Killers: 7 Examples of Mobile Device Security Risks" and "Malware Families, Mobile Threats, and the Human Risk Narrative Shaping #Cybersecurity".
The latest update for #Mendit includes "Why #AI#RedTeaming is different from traditional security" and "Building a more secure npm ecosystem with Mend Renovate".
We are creeping into a reality where no organisation can ignore preventative security. Sophisticated and automated attacks at scale will become so common that everything connected to the internet will be getting seriously challenged daily.
Expanding support for AI developers on Hugging Face
Google Cloud and Hugging Face are expanding their partnership to improve the AI development experience. The collaboration aims to reduce the time it takes to download Hugging Face models through Vertex A…
CISA warns feds to fully patch actively exploited Cisco flaws
CISA warned federal agencies to fully patch two actively exploited vulnerabilities in Cisco Adaptive Security Appliances (ASA) and Firepower devices. [...] #hackernews#news
DDoS Cyberattack Disrupts Danish Government and Defense Websites A cyberattack on Danish institutions disrupted several government and defense-related websites on November 13, according to the coun...
Checkout.com Breach: ShinyHunters Hack Cloud Storage, Ransom Demand Rejected Payment processor Checkout.com has disclosed a significant data breach following a targeted attack by the notorious cybe...
“I deleted the entire database without permission”
All sounds a bit “the magicians apprentice” - & like risk management, data back ups, version tracking and business continuity are missing from some businesses’ to do lists when they think about AI agent experiments
VeM, a latent music diffusion model, generates soundtracks with semantic, temporal, and rhythmic alignment; it employs hierarchical video parsing, storyboard-guided cross-attention, and a transition-beat aligner; outperforms existing methods.
Regional collaboration is key to responsible tech innovation. As North Holland strengthens its tech ecosystem, euqai stands ready with a GDPR-compliant, energy-efficient AI platform built for European sovereignty. See how we’re powering the future at euqai.eu
- PR ⚙️
I think this new investment of £21 million from Innovate UK and the Department for Science, Innovation and Technology is quite a big deal in relation to the recent downgrade in economic growth linked to the cyber attack on Jaguar Land Rover. www.ukri.org/news/21-mill...
Yanbei Jiang, Chao Lei, Yihao Ding, Krista Ehinger, Jey Han Lau
PROPA: Toward Process-level Optimization in Visual Reasoning via Reinforcement Learning https://arxiv.org/abs/2511.10279
UK regulators are gaining enhanced powers to fine companies up to 4% of their annual turnover, or £17mn if that is larger, for #CyberSecurity failures under new legislation & would include sectors such as healthcare, IT services & data centres.
security.googleblog.com/2025/11/rust... "… Google software engineers reported that Rust is both easier to review and more likely to be correct. The hard data […] validates those impressions." — that’s how we learn to not trust ourselves, only hard data :)
Clop Ransomware Strikes INTEGRALIFE: A Deep Look Into a Growing Healthcare Cyber Crisis
Introduction To A Silent Digital Emergency A major cybersecurity disruption has shaken the healthcare technology sector. INTEGRALIFE, a well-known US medical technology company, has reportedly been targeted by…
Cybersecurity: The big Plans of the Award Winner: The Digital Economy Awards were presented on Thursday evening at the Hallenstadion in Zurich. It was an evening of big words, surprises, and major opportunities. #EnglishNews
Explore the ethics and global compliance of data scraping, with best practices to respect privacy, follow laws like GDPR/CCPA, use responsible harvesting, maintain transparency, and build trusted, scalable data pipelines.