RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

open-sourcedevops

Simple Tool Exposes GitHub Repo Sizes via Public API

Simon Willison built a small web tool that reveals the size of any GitHub repository - information GitHub doesn't surface in its own UI. The tool works by query

via Simon Willison ·
cybersecuritysupply-chain

Smart Slider 3 Pro update system compromised, backdoors pushed to 900K+ sites

Attackers compromised the update distribution system for Smart Slider 3 Pro, a popular WordPress and Joomla plugin, and used it to push a trojanized version (3.

via BleepingComputer ·
cybersecurityidentity

Storm-2755 hijacks Canadian payroll via AiTM phishing of Microsoft 365 sessions

Microsoft is tracking Storm-2755, a financially motivated crew rerouting Canadian employees' salary payments by stealing Microsoft 365 session tokens. Victims l

via BleepingComputer ·
cybersecurityidentity

VENOM PhaaS targets C-suite Microsoft accounts with QR-based AiTM phishing

A previously undocumented phishing-as-a-service operation dubbed VENOM has been running since November against CEOs, CFOs, and VPs across industries. Abnormal r

via BleepingComputer ·
cybersecurityvulnerability

Weekly Threat Roundup: Masjesu IoT Botnet and 13-Year Apache ActiveMQ RCE

The Hacker News' weekly ThreatsDay bulletin highlights 20 security stories, led by the Masjesu botnet and a long-dormant Apache ActiveMQ remote code execution f

via The Hacker News ·
vulnerabilitycybersecurity

Adobe Reader zero-day exploited since December via weaponized PDFs

EXPMON founder Haifei Li disclosed an unpatched Adobe Reader vulnerability that attackers have been exploiting in the wild since at least December. The exploit

via BleepingComputer ·
vulnerabilityopen-source

AI-Assisted Research Surfaces 13-Year-Old RCE in Apache ActiveMQ Classic

A high-severity remote code execution flaw (CVE-2026-34197, CVSS 8.8) has been patched in Apache ActiveMQ Classic after sitting undetected for over a decade. Ho

via BleepingComputer ·
tech-culturepolicy

Artemis II Returned Stunning Moon Photos - But Robots Already Mapped It

NASA's Artemis II crew completed a crewed lunar flyby this week, the first in over 53 years, transmitting high-resolution imagery via a laser communications lin

via Ars Technica ·
cybersecuritymalware

Atomic Stealer Evades macOS ClickFix Protections via Script Editor Abuse

A new Atomic Stealer campaign bypasses macOS Tahoe's ClickFix terminal warnings by pivoting to Script Editor instead. Attackers drive victims to fake Apple-bran

via BleepingComputer ·
cybersecurityidentity

Bitcoin Depot loses 50.9 BTC after attackers pivot through corporate IT

Bitcoin Depot, operator of more than 25,000 crypto ATMs, disclosed in an SEC filing that intruders breached its corporate IT environment on March 23, 2026 and m

via BleepingComputer ·
cybersecuritysupply-chain

BPO Supply Chain Pivot: UNC6783 Tunnels Through Help Desks to Reach Enterprise Data

A newly tracked threat actor, UNC6783, is exploiting business process outsourcing providers as an entry point into high-value corporate targets across multiple

via BleepingComputer ·
malwarecloud

Chaos Botnet Evolves: New Variant Hits Misconfigured Cloud Servers With SOCKS5 Proxy

A new variant of the Chaos botnet malware has expanded its targeting to include misconfigured Linux cloud servers, a shift from its earlier focus on routers and

via The Hacker News ·