‼️ BREAKING: Mozilla has rotated the GPG subkey that signs Firefox and Thunderbird Linux artifacts after an unencrypted copy was committed to a private GitHub repository.
The key is used to sign tarballs, RPM packages and checksum files.
Mozilla says its audit records show no unauthorised access, and the old key is revoked.
https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/
The key is used to sign tarballs, RPM packages and checksum files.
Mozilla says its audit records show no unauthorised access, and the old key is revoked.
https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/
🤣20👍4🔥2
‼️ BREAKING: Delta confirms an unauthorised Wi-Fi network appeared aboard flight DL591 from Las Vegas to Atlanta on 10 August, carrying passengers home from DEF CON 34. Attackers were possibly using a WiFi Pineapple in flight.
Crew ACARS messages, intercepted by ground receivers, warned corporate security of a "scam wifi called Delta Wifi Fast" targeting other passengers.
Delta says nothing was hacked. Crew killed the Wi-Fi for 30 minutes.
Crew ACARS messages, intercepted by ground receivers, warned corporate security of a "scam wifi called Delta Wifi Fast" targeting other passengers.
Delta says nothing was hacked. Crew killed the Wi-Fi for 30 minutes.
🤣21❤6
❗️Sainsbury's has wrongly thrown out a second shopper this year after facial recognition cameras flagged him as a suspected shoplifter. Staff stopped him at the self-checkout, told him he was barred over an incident earlier that week and refused to let him pay. Sainsbury's admitted the error and sent a £150 voucher; he donated it to a food bank.
The chain is putting facial recognition in 200+ stores by the end of 2026...
The chain is putting facial recognition in 200+ stores by the end of 2026...
💩20❤3🤣3
🚨 BREAKING: An AI agent found a zero-click RCE in video conferencing tool Zoom in under 24 hours.
A researcher at "A Security" say fewer than 20 prompts on publicly available frontier models produced a working exploit against Zoom's annotation protocol: one malformed message takes over any participant's device.
https://a.security/blog/asecurity-zoomsday
A researcher at "A Security" say fewer than 20 prompts on publicly available frontier models produced a working exploit against Zoom's annotation protocol: one malformed message takes over any participant's device.
https://a.security/blog/asecurity-zoomsday
💩17😁5🤣5❤3
❗️ Anthropic now watermarks Claude's text output, and the mark travels through copy-paste. It's in the text they generate worldwide, across the API, Claude Code and Cowork.
Anthropic says a detected mark shows content "may have been processed by Claude," proofreading, translation and summarising all leave the same signal as full generation.
https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content
Anthropic says a detected mark shows content "may have been processed by Claude," proofreading, translation and summarising all leave the same signal as full generation.
https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content
💩21😁10👏6😭3❤2
🚨 BREAKING: AnMed's Facebook page was hijacked today to post a ransomware extortion note directly to patients — two weeks after a cyberattack knocked out the nonprofit medical system's IT.
The messages, attributed to The Gentlemen, claim 6TB was taken from the Georgia/South Carolina hospital system, including rape victim testimonies, HIV-positive lists, abortion and pediatric psychiatric records.
AnMed says the claims are unverified. Ten facilities were still closed Monday, 16 days after the July 26 attack.
The messages, attributed to The Gentlemen, claim 6TB was taken from the Georgia/South Carolina hospital system, including rape victim testimonies, HIV-positive lists, abortion and pediatric psychiatric records.
AnMed says the claims are unverified. Ten facilities were still closed Monday, 16 days after the July 26 attack.
🤬18❤3💩3😭3
❗️Reddit's desktop site is blocking logged-out visitors with a login pop-up they can't dismiss. It triggers after scrolling the homepage or opening certain posts and is rolling out gradually.
In June, Reddit said its anti-scraping login requirement "will not impact logged-out browsing on Reddit." It hasn't explained what changed.
In June, Reddit said its anti-scraping login requirement "will not impact logged-out browsing on Reddit." It hasn't explained what changed.
🤬28💩11🥴3
‼️ Microsoft's July patch for the RoguePlanet local privilege escalation Defender flaw (CVE-2026-50656) has been bypassed.
Nightmare Eclipse published exploit code called ShieldBreak on GitHub, hours after August Patch Tuesday. The researcher claims a 100% success rate on fully patched Windows 11 25H2 and Server 2025, where RoguePlanet's race condition was hit-or-miss.
The vulnerability makes it possible for any local user to get SYSTEM. No fix yet.
Nightmare Eclipse published exploit code called ShieldBreak on GitHub, hours after August Patch Tuesday. The researcher claims a 100% success rate on fully patched Windows 11 25H2 and Server 2025, where RoguePlanet's race condition was hit-or-miss.
The vulnerability makes it possible for any local user to get SYSTEM. No fix yet.
🤣33👍3❤2🔥1😭1
‼️🚨 BREAKING: Security researchers have uncovered all of those who fell victim to the LiteLLM supply chain attack by obtaining its archive: 153GB holding 433,909 files from 2,488 organisations.
According to Hudson Rock and CloudSEK, victims include Nvidia, AWS, Samsung, Boeing, Intel and more.
This is one of the biggest hits by TeamPCP yet.
The archive contains 118,829 CI/CD runner dumps attributed to corporate domains, with signing secrets and AI provider API keys sitting in plaintext.
If you ran LiteLLM 1.82.7 or 1.82.8, assume every secret in that environment is burned.
Link to article: https://infostealers.com/article/largest-ai-supply-chain-breach-of-2026-litellm-hack-impacts-thousands-of-global-enterprises-claim-your-ethical-disclosure/
Link to full list of victims: https://exposure.cloudsek.com/ai-supply-chain-incident
According to Hudson Rock and CloudSEK, victims include Nvidia, AWS, Samsung, Boeing, Intel and more.
This is one of the biggest hits by TeamPCP yet.
The archive contains 118,829 CI/CD runner dumps attributed to corporate domains, with signing secrets and AI provider API keys sitting in plaintext.
If you ran LiteLLM 1.82.7 or 1.82.8, assume every secret in that environment is burned.
Link to article: https://infostealers.com/article/largest-ai-supply-chain-breach-of-2026-litellm-hack-impacts-thousands-of-global-enterprises-claim-your-ethical-disclosure/
Link to full list of victims: https://exposure.cloudsek.com/ai-supply-chain-incident
🤣8👍4😱2🔥1
‼️ German digital rights group HateAid has filed a criminal complaint against Meta, Ray-Ban owner EssilorLuxottica and retailers Fielmann, Apollo-Optik, Mister Spex and MediaMarkt over the Ray-Ban Meta Wayfarer AI glasses.
It invokes a federal law banning the sale of communication devices designed to film people without them noticing. Frankfurt cybercrime prosecutors (ZIT) confirmed receipt and are assessing whether to open a probe.
It invokes a federal law banning the sale of communication devices designed to film people without them noticing. Frankfurt cybercrime prosecutors (ZIT) confirmed receipt and are assessing whether to open a probe.
👍24🔥8👏3❤1💩1
❗️All Twitch content is now automatically opted in to Amazon generative-AI training by default, if you don't turn it off.
"If it was opt-in, nobody would opt-in," Twitch chief product officer Mike Minton said.
The off switch is web-only, buried under Settings, Security and Privacy. It won't stop your chat being used in streams that stayed opted in.
Opting out only covers your own channel. Chat in someone else's stream, and their setting decides whether your messages get used:
https://help.twitch.tv/s/article/twitch-account-settings?language=en_US#FAQ
"If it was opt-in, nobody would opt-in," Twitch chief product officer Mike Minton said.
The off switch is web-only, buried under Settings, Security and Privacy. It won't stop your chat being used in streams that stayed opted in.
Opting out only covers your own channel. Chat in someone else's stream, and their setting decides whether your messages get used:
https://help.twitch.tv/s/article/twitch-account-settings?language=en_US#FAQ
💩31🤣5😁3🤬3❤1👍1
An RTX 5090 owner went to great lengths to protect his GPU power cable from bending and overheating, using a mesh side panel with a cutout.
The thing still lit up. He was using a Goghunters power supply and blames the supplied cable. His warranty claim is still ongoing.
He bought a Seasonic instead. A repair tech replaced the burned header for 600 RMB (~$90).
The thing still lit up. He was using a Goghunters power supply and blames the supplied cable. His warranty claim is still ongoing.
He bought a Seasonic instead. A repair tech replaced the burned header for 600 RMB (~$90).
👍8😢7😁2🔥1🤯1