Latest Tech News

Stay updated with the latest in technology, AI, cybersecurity, and more

Filtered by: sec Clear Filter

Exclusive: Google wants to make Android phones safer by switching to ‘risk-based’ security updates

Mishaal Rahman / Android Authority For the past decade, Google has consistently published an Android Security Bulletin every month, even if the company wasn’t ready to roll out a security update to its own Pixel devices. These bulletins detail the vulnerabilities that have been fixed in that month’s security release, with issues ranging from low to critical in severity. Given how large and complex the Android operating system and its underlying components are, it’s not unusual to see a dozen or

Yearly applications now open to Apple’s Security Research Device Program

For the past few years, Apple has been inviting experienced researchers to apply to its security program, which issues iPhones that are especially modified to make it easier to investigate vulnerabilities. Now, applications are open to next year’s program. Here’s how you can apply. This year’s application period ends October 31 This is how Apple describes its Security Research Device Program: “The Security Research Device (SRD) is a specially fused iPhone that allows you to perform iOS securi

Modder injects AI dialogue into 2002’s Animal Crossing using memory hack

When software engineer Joshua Fonseca recently connected the GameCube simulation classic Animal Crossing to a modern AI language model like the kind that powers ChatGPT, he decided to shake things up. By programming the AI to roleplay as villagers growing aware of their debt situation, and giving them a shared memory to track conversations, Fonseca orchestrated a scenario where the residents began to organize against their raccoon landlord. In Animal Crossing, Tom Nook runs the town shop and pr

Microsoft Offers Windows 10 Extended Security Updates for Free. You Just Need to Do One Thing

Microsoft is sunsetting Windows 10 support on Oct. 14, and with it stopping all updates to the former OS. If you aren't able to update to Windows 11, you still have options. For $30 you can grab a year of extended-security updates. There is also a free option available, provided you're willing to enable cloud backup and connect it to your OneDrive account. The ability to get free updates on Windows 10 is a pretty big deal because it is still the most widely used Windows OS, accounting for just

This 'critical' Cursor security flaw could expose your code to malware - how to fix it

Shalitha Ranathunge/iStock/Getty Images Plus via Getty Images Follow ZDNET: Add us as a preferred source on Google. ZDNET's key takeaways A report found hackers can exploit an autorun feature in Cursor. The danger is "significant," but there's an easy fix. Cursor uses AI to assist with code-editing. A new report has uncovered what it describes as "a critical security vulnerability" in Cursor, the popular AI-powered code-editing platform. The report, published Wednesday by software compa

A Modular Couch Is Worth It. Here’s Why

A sofa is one of the biggest investments you can make in home decor, and the last thing you want is to make the wrong choice. A good couch will be with you for a decade, and it should not only be comfortable and look great, it should also have the versatility to adapt to your needs in new spaces and seasons of your life. You should consider a modular sofa. That's the kind that comes in individual pieces you can pull apart, put back together, and rearrange to suit whatever you fancy. Usually, yo

Senator demands to know status of 'duplicate' SSA database 'immediately'

A US Senator is demanding answers after a Social Security Administration (SSA) employee who blew the whistle on Department of Government Efficiency (DOGE) dealings involuntarily resigned last month, citing workplace hostility in response to his concerns. Republican Senator Mike Crapo (it's pronounced Cray-poe), chairman of the Senate Finance Committee, sent a letter to the SSA's commissioner, Frank Bisignano, giving him just two weeks to provide answers to concerns raised last month by now-form

France confirms new Apple spyware campaign alert

In a threat and incidents report released today, France’s Information Security Agency confirmed that Apple issued a new wave of threat notifications earlier this month. Here are the details. The alert didn’t specify who was behind the recent campaign According to the agency’s report, Apple sent its latest round of security alerts to French citizens on September 3, 2025, marking the fourth campaign just this year. Previous notification waves were sent on March 5, April 29, and June 25. As the

U.S. Senator accuses Microsoft of “gross cybersecurity negligence”

U.S. Senator Ron Wyden has sent a letter to the Federal Trade Commission (FTC) requesting the agency to investigate Microsoft for failing to provide adequate security in its products, which led to ransomware attacks against healthcare organizations. The Senator started the formal asking by saying that Microsoft should be held "responsible for its gross cybersecurity negligence, resulting in ransomware attacks against critical infrastructure, including U.S. health care organizations." The Senat

Microsoft gives Windows 10 its penultimate update - but saves the best for Windows 11

Elyse Betters Picaro / ZDNET Follow ZDNET: Add us as a preferred source on Google. ZDNET's key takeaways September's Patch Tuesday offers bug fixes for Windows 10 and 11. Windows 11 also received a host of new and improved features. This marks the penultimate Patch Tuesday update for Windows 10. Hey Windows users, it's time once again to install the latest monthly updates on your PC, courtesy of September's Patch Tuesday. Whether you run Windows 11 or are still on Windows 10, you'll find i

Spiral

I've been building data systems for long enough to be skeptical of “revolutionary” claims, and I’m uncomfortable with grandiose statements like “Built for the AI Era”. Nevertheless, AI workloads have tipped us into what I'll call the Third Age of data systems, and legacy platforms can't meet the moment. Three Eras of Data Systems In the beginning, databases had human-scale inputs and human-scale outputs. Postgres—the king of databases, first released in 1989[1] —is the archetypal application d

The Buyer’s Guide to Browser Extension Management

While most enterprises lock down endpoints, harden networks, and scan for vulnerabilities, one of the riskiest vectors often slips through unmonitored: browser extensions. These small, user-installed applications can execute privileged code, access sensitive DOM elements, intercept network requests, and even exfiltrate data, all within the context of enterprise-approved browsers. Keep Aware’s new Buyer’s Guide to Browser Extension Management explores how security and IT leaders can achieve comp

DDoS defender targeted in 1.5 Bpps denial-of-service attack

A DDoS mitigation service provider in Europe was targeted in a massive distributed denial-of-service attack that reached 1.5 billion packets per second. The attack originated from thousands of IoTs and MikroTik routers, and it was mitigated by FastNetMon, a company that offers protection against service disruptions. “The attack reached 1.5 billion packets per second (1.5 Gpps) — one of the largest packet-rate floods publicly disclosed,” FastNetMon says in a press release. “The malicious traff

Cursor AI editor lets repos “autorun” malicious code on devices

A weakness in the Cursor code editor exposes developers to the risk of automatically executing tasks in a malicious repository as soon as it’s opened. Threat actors can exploit the flaw to drop malware, hijack developer environments, or steal credentials and API tokens, without developers having to execute any commands. Cursor is an AI-powered Integrated Development Environment (IDE) built as a fork of Visual Studio Code (VS Code) that has deep integration of mainstream AI assistants like GPT-

Microsoft fixes streaming issues triggered by Windows updates

Microsoft has resolved severe lag and stuttering issues with NDI streaming software affecting Windows 10 and Windows 11 systems after installing the August 2025 security updates. The company confirmed these problems after receiving widespread reports from users who experienced a range of performance issues while using various streaming apps, including OBS (Open Broadcast Software) and NDI Tools. "Severe stuttering, lag, and choppy audio/video might occur when using NDI (Network Device Interfac

A security incident that may involve your Plex account information

We have recently experienced a security incident that may potentially involve your Plex account information. We believe the actual impact of this incident is limited; however, action is required from you to ensure your account remains secure. What happened An unauthorized third party accessed a limited subset of customer data from one of our databases. While we quickly contained the incident, information that was accessed included emails, usernames, securely hashed passwords and authentication

A cryptography expert on how Web3 started, and how it’s going

The term Web3 was originally coined by Etherium cofounder Gavin Wood as a secure, decentralized, peer-to-peer version of the Internet. The idea was to build an Internet based on blockchain technology and a peer-to-peer network, without the need for large data centers or third-party providers. These days, however, blockchain is most famous as the tool enabling cryptocurrencies. Most recently, the Trump administration has taken on a pro-cryptocurrency stance, boosting blockchain’s popularity and m

Apple says the iPhone 17 comes with a massive security upgrade

is a senior editor following news across tech, culture, policy, and entertainment. He joined The Verge in 2021 after several years covering news at Engadget. It’s less noticeable than a thinner profile or trick camera lenses, but Apple is pointing out another upgrade in the iPhone 17 family of phones that it says is part of “the most significant upgrade to memory safety in the history of consumer operating systems.” Explicitly targeting the spyware industry that produces exploits for tools like

The Dying Dream of a Decentralized Web

The term Web3 was originally coined by Etherium cofounder Gavin Wood as a secure, decentralized, peer-to-peer version of the Internet. The idea was to build an Internet based on blockchain technology and a peer-to-peer network, without the need for large data centers or third-party providers. These days, however, blockchain is most famous as the tool enabling cryptocurrencies. Most recently, the Trump administration has taken on a pro-cryptocurrency stance, boosting blockchain’s popularity and m

Adobe patches critical SessionReaper flaw in Magento eCommerce platform

Adobe is warning of a critical vulnerability (CVE-2025-54236) in its Commerce and Magento Open Source platforms that researchers call SessionReaper and describe as one of " the most severe" flaws in the history of the product. Today, the software company released a patch for the security issue that could be exploited without authentication to take control of customer accounts through the Commerce REST API. According to e-commerce security company Sansec, Adobe notified "selected Commerce custo

It’s time to change your Plex password again

Dear Plex User, We have recently experienced a security incident that may potentially involve your Plex account information. We believe the actual impact of this incident is limited; however, action is required from you to ensure your account remains secure. What happened An unauthorized third party accessed a limited subset of customer data from one of our databases. While we quickly contained the incident, information that was accessed included emails, usernames, and securely hashed passw

Signal lets you back up your chats for free now - plus its first-ever paid feature

Matthias Balk/picture alliance via Getty Images Follow ZDNET: Add us as a preferred source on Google. ZDNET's takeaways Privacy-centric messaging app Signal has a message backup option. The free tier stores up to 45 days of messages. You can pay $1.99 a month if you want to store more than 45 days. Signal is offering its first-ever backup option. In a post Monday, the security-focused messaging app company announced a new feature that lets you back up your messages for free. In the past,

Plex Security Incident

‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ Dear Plex User, We have recently experienced a security incident that may potentially involve your Plex account information. We believe the actual impact of this incident is limited; howev

Computing’s Top 30: Nipun Jaswal

To keep his edge, international cybersecurity expert Nipun Jaswal does more than stay up on current security threats and trends; he literally keeps his hands in the game, regularly coding—in up to 10 different languages—and doing lab work including exploring attack vectors and hunkering down with disassemblers and debuggers. Remaining “deeply technical” is not just part of his practice, it’s also fundamental to his leadership philosophy, which centers on staying curious and “close to the core o

Ex-Meta employee files whistleblower suit for alleged security flaws at WhatsApp

An ex-Meta employee sued the social media company on Monday over allegations that its WhatsApp messaging service contained "systemic cybersecurity failures" that potentially compromise user privacy. Attaullah Baig, WhatsApp's former head of security, alleged that Meta retaliated against him after he notified leaders, including CEO Mark Zuckerberg, of security issues at the messaging app. The suit, filed in U.S. District Court for the Northern District of California, claims that after joining W

Programmers Using AI Create Way More Glaring Security Issues, Data Shows

Artificial intelligence has notorious problems with accuracy — so maybe it's not surprising that using it as a coding assistant creates more security problems, too. As a security firm called Apiiro found in new research, developers who used AI produce ten times more security problems than their counterparts who don't use the technology. Looking at code from thousands of developers and tens of thousand repositories, Apiiro found that AI-assisted devs were indeed producing three or four times mo

Former WhatsApp security boss in lawsuit likens Meta’s culture to a “cult”

Over the past year, Meta has blanketed TV screens around the world with commercials touting the privacy of Whatsapp, its encrypted messenger with a monthly user base of 3 billion people. “It’s private,” one ad campaign featuring the former cast of the Modern Family TV show says. “On Whatsapp, no one can see or hear your personal messages … not even us,” a different series of ads declares. “Serious risks to user data” On Monday, the former head of security for the Meta-owed messaging app filed

Signal adds secure cloud backups to save and restore chats

Signal has introduced a new opt-in feature that helps users create end-to-end encrypted backups of their chats, allowing them to restore messages even if their phones are damaged or lost. Secure backups are already available in the latest Signal beta version for Android users and will also be rolled out to iOS and desktop devices after this testing phase. "If you do decide to opt in to secure backups, you'll be able to securely back up all of your text messages and the last 45 days' worth of m

Hackers steal 3,325 secrets in GhostAction GitHub supply chain attack

A new supply chain attack on GitHub, dubbed 'GhostAction,' has compromised 3,325 secrets, including PyPI, npm, DockerHub, GitHub tokens, Cloudflare, and AWS keys. The attack was discovered by GitGuardian researchers, who report that the first signs of compromise on one of the impacted projects, FastUUID, became evident on September 2, 2025. The attack involved leveraging compromised maintainer accounts to perform commits that added a malicious GitHub Actions workflow file that triggers automat

Is Apple Finally Making a Move on Smart Home Tech? 4 Rumored Products We'd Love to See

It's a matter of when, not if. Apple's take on the smart home is coming, with multiple reports saying the tech giant is ready to release its own line of smart devices and home security products. While it's a little early, Apple's big "awe dropping" event on Sept. 9 could showcase the first elements of its big home expansion. We already expect to see the new iPhone 17, a new Apple Watch and an AirPod announcement. Here's what could happen if there's a surprise home tech release, too, from table