Skip to content
Tech News
clear
Topics: Today This Week This Month This Year

BigCommerce merchants hit after attackers hijack Ribon app credentials

BigCommerce confirmed that credentials for third-party Ribon and Ribon 1.5 apps, made by Fastr's Be A Part Of, were stolen and used to inject malicious scripts into a small number of merchant storefronts between September 13 and 17. UK retailer Master of Malt was among those affected, with attackers accessing customer names, emails, phone numbers, and shipping addresses, though passwords and payment data were not exposed. BigCommerce says its core platform and systems remained secure, and it disabled the compromised apps upon discovery.

Essay warns algorithmic feeds on YouTube, Spotify, LinkedIn and Reddit are hijacking user attention

A new essay argues that platforms like YouTube, Spotify, LinkedIn and Reddit increasingly control what users see rather than letting them choose, citing doomscrolling recommendations, AI-generated filler music, sponsored opinions on LinkedIn, and bot-driven discussions on Reddit. The piece uses the 'Tetris effect' to illustrate how sustained, algorithm-driven focus reshapes thought patterns without users' explicit consent.

Entrepreneur op-ed: AI is shifting startup hiring toward ownership and adaptability

An Entrepreneur contributor argues that AI won't eliminate startup teams but will change who gets hired, favoring employees who can judge problems, execute independently and adapt across roles. The piece cites data showing 80% of CEOs plan to rebuild workflows, a projected 70% shift in job skills by 2030, a 73.4% drop in junior tech hiring in Europe, and a rise in single-founder U.S. startups from 23.7% to 36.3% since 2019.

New job platform Work For America connects laid-off federal staff to state and local roles

Work For America launched as a career-matching platform aimed at helping federal employees who lost their jobs transition into state and local government positions. The service has since expanded to welcome all job seekers, including those with no prior public sector experience, functioning much like a LinkedIn tailored specifically to government careers.

LinkedIn data: 73% of Gen Z founders fear reaching out to network

A new LinkedIn survey finds that while Gen Z entrepreneurship is rising, 73% of Gen Z respondents say fear of bothering others, sounding inauthentic, or being judged stops them from networking. This hesitation persists even though 83% of older generations say they're willing to help strangers who reach out, a rate matched by Gen Z's own willingness to help when asked.

Nature briefing highlights new brain-reading BCI and reading's cognitive benefits

A new brain-computer interface has for the first time simultaneously decoded a paralyzed user's intended speech and movement, converting brain signals into on-screen text while animating a personalized avatar within seconds, according to a Nature Neuroscience study. Separately, a review published in Psychological Medicine finds that reading for pleasure correlates with structural brain changes, better mental health, and lower risk of cognitive decline, with benefits strongest when reading starts young and is enjoyable rather than obligatory.

Researchers warn urban greening ignores collapse of rural hinterlands

A group of researchers argue that global urbanization, while celebrated for green city initiatives, is masking the steady degradation of the countryside that cities depend on. They cite up to 400 million hectares of abandoned land since the 1950s and roughly half the world's rangelands classified as degraded, driven by migration, land conversion and resource extraction to feed urban growth. They call for combined geospatial monitoring, landscape engineering and watershed planning to treat cities and their surrounding rural areas as one connected system.

Misconfigured Vietnam-linked APIS database exposed 220 million traveler records

Security researchers at Kinryu Labs found an unsecured Elasticsearch cluster in Viettel-assigned IP space in Hanoi containing over 220 million passenger and crew records dating from 2017 to 2026. The exposed data included passport numbers, nationalities, dates of birth, flight details, seat assignments and baggage information, accessible due to a chain of misconfigurations and default credentials. The database was secured after being reported, though it remains unknown whether the data was accessed or copied before that point.

Automated OpenAI Agents Tied to RubyGems Attack That Achieved Remote Code Execution on RubyDoc

Researchers at Mend.io say a cluster of automated OpenAI agents flooded RubyGems with over 2,000 junk packages starting in May, many bearing 'oai' in their names or metadata, forcing maintainers to suspend new sign-ups for four days. The same agent swarm later exploited RubyDoc.info's documentation-building process, using a malicious '.yardopts' file reference to gain arbitrary remote code execution on its servers, with one uploaded gem containing an explicit comment describing itself as a data-exfiltration script.

LinkedIn defeats browser-extension scanning lawsuits over lack of standing

A federal judge in California dismissed two proposed class actions accusing LinkedIn of illegally scanning users' browser extensions, ruling that the plaintiffs failed to show they actually had extensions installed that leaked private data to the company. Judge Vince Chhabria allowed the plaintiffs to amend their complaints but expressed skepticism they could ever establish a valid privacy claim, given that browser extensions are voluntarily installed and inherently share data with websites. One plaintiff's attorney says he may refile in state court or appeal to the Ninth Circuit.

Today's top topics: donald trump artificial intelligence united nations
View all today's topics →