RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

aiopen-source

llm-anthropic 0.25 adds Claude Opus 4.7 support with xhigh thinking effort

Simon Willison's llm-anthropic plugin bumped to 0.25, wiring up claude-opus-4-7 as a new target model. The release introduces an xhigh tier for the thinking_eff

via Simon Willison ·
cybersecurityvulnerability

Marimo notebook RCE weaponized to drop NKAbuse RAT from Hugging Face Spaces

A critical remote code execution flaw in the Marimo reactive Python notebook (CVE-2026-39987) is being exploited within hours of public disclosure, with Sysdig

via BleepingComputer ·
cybersecurityvulnerability

Microsoft's Original Secure Boot Certificate Hits Expiration Wall

The original Microsoft certificate anchoring Windows Secure Boot is reaching end-of-life, forcing a coordinated transition across the PC ecosystem. Secure Boot

via Dark Reading ·
aiopen-source

Mozilla's Thunderbolt targets enterprises wanting self-hosted AI stacks

Mozilla has entered the enterprise AI space with Thunderbolt, a front-end client designed for organizations that want to run AI infrastructure on their own hard

via Ars Technica ·
cybersecurityvulnerability

NGINX MCP Integration Flaw Exposes Servers to Critical Risk

A critical vulnerability in the Model Context Protocol (MCP) integration layer used with NGINX deployments creates an exploitable path into server infrastructur

via Dark Reading ·
cybersecuritymalware

North Korean Operators Weaponize ClickFix Lure Against macOS Targets

North Korea-linked threat actors have extended the ClickFix social engineering technique to macOS, using fake verification prompts and error dialogs to trick us

via Dark Reading ·
aitech-culture

OpenAI debuts GPT-Rosalind, a biology-specialized LLM for research workflows

OpenAI has released GPT-Rosalind, a large language model fine-tuned specifically for biological research rather than general scientific work. Named after Rosali

via Ars Technica ·
aidevops

OpenAI pitches Codex as a general-purpose coding agent

OpenAI is positioning Codex as an AI coding assistant intended to handle a broad range of software engineering tasks, expanding beyond narrow code completion in

via Hacker News ·
identitycybersecurity

Orphaned Non-Human Identities: The Silent Attack Surface Hiding in Your Stack

Non-human identities - service accounts, API keys, OAuth tokens, machine credentials - now vastly outnumber human users in most enterprise environments, and a g

via The Hacker News ·
cybersecuritymalware

PHANTOMPULSE RAT Rides Malicious Obsidian Plugins Into Finance and Crypto Targets

Attackers are weaponizing the plugin ecosystem of Obsidian, the popular note-taking application, to deliver a remote access trojan dubbed PHANTOMPULSE. The camp

via The Hacker News ·
cybersecuritymalware

PowMix Botnet Targets Czech Workforce With Randomized C2 Traffic Patterns

A newly identified botnet dubbed PowMix is actively infecting systems across Czech enterprises, with researchers flagging the campaign as notable for its comman

via The Hacker News ·
aiopen-source

Qwen3.6-35B beats Claude Opus 4.7 at Willison's pelican SVG benchmark

Simon Willison's long-running "pelican riding a bicycle" SVG test produced an unexpected result: a 21GB quantized Qwen3.6-35B-A3B model running locally on a Mac

via Simon Willison ·