Latest Tech News

Stay updated with the latest in technology, AI, cybersecurity, and more

Filtered by: point Clear Filter

Microsoft hit with SharePoint attack — one version still vulnerable

A Microsoft store in New York, US, on Friday, Oct. 25, 2024. Microsoft has warned of "active attacks" targeting its SharePoint collaboration software, with security researchers noting that organizations worldwide stand to be affected by the breach. The Cybersecurity and Infrastructure Security Agency said Sunday in a release that the vulnerability provides unauthenticated access to systems and full access to SharePoint content, enabling bad actors to execute code over the network. CISA said t

Microsoft Fix Targets Attacks on SharePoint Zero-Day

On Sunday, July 20, Microsoft Corp. issued an emergency security update for a vulnerability in SharePoint Server that is actively being exploited to compromise vulnerable organizations. The patch comes amid reports that malicious hackers have used the Sharepoint flaw to breach U.S. federal and state agencies, universities, and energy companies. In an advisory about the SharePoint security hole, a.k.a. CVE-2025-53770, Microsoft said it is aware of active attacks targeting on-premises SharePoint

Microsoft fixes two SharePoint zero-days under attack, but it's not over - how to patch

sankai/Getty Microsoft has patched two critical zero-day SharePoint security flaws that have already been exploited by hackers to attack vulnerable organizations. Responding to the exploits, the software giant has issued fixes for SharePoint Server Subscription Edition and SharePoint Server 2019 but is still working on a patch for SharePoint Server 2016. Designated as CVE-2025-53771 and CVE-2025-53770, the two vulnerabilities apply only to on-premises versions of SharePoint, so organizations t

Microsoft Sharepoint server vulnerability puts an estimated 10,000 organizations at risk

A major zero-day security vulnerability in Microsoft's widely used SharePoint server software has been exploited by hackers, causing chaos within businesses and government agencies, multiple outlets have reported. Microsoft announced that it had released a new security patch "to mitigate active attacks targeting on-premises [and not online] servers," but the breach has already effected universities, energy companies, federal and state agencies and telecommunications firms. The SharePoint flaw i

New zero-day bug in Microsoft SharePoint under widespread attack

The U.S. federal government and cybersecurity researchers say a newly discovered security bug found in Microsoft’s SharePoint is under attack. U.S. cybersecurity agency CISA sounded the alarm this weekend that hackers were actively exploiting the bug. Microsoft has not yet provided patches for all affected SharePoint versions, leaving customers across the world largely unable to defend against the ongoing intrusions. Microsoft said the bug, known officially as CVE-2025-53771, affects versions

10,000+ companies at risk from Microsoft Sharepoint security flaw

More than 10,000 organizations around the world are at risk from hackers after a serious security flaw was discovered in Microsoft’s popular Sharepoint platform, used to store and share confidential documents. The majority of companies at risk are said to be in the US … Microsoft said that there were “active attacks targeting on-premises servers.” US federal and state agencies are among the organizations said to have been affected. Security researchers cited by Bloomberg said that the vulnerab

Microsoft SharePoint servers are under attack because of a major security flaw

Hackers have exploited vulnerabilities in Microsoft’s SharePoint software, placing tens of thousands of on-premises servers used by global businesses and agencies at risk. Microsoft issued an alert on Saturday disclosing that it was aware of “active attacks,” and that it was working to patch the zero-day exploit. Researchers at Eye Security first identified the vulnerability on July 18th, which allows hackers to access certain on-premises versions of SharePoint and steal keys that can let them

Microsoft releases emergency patches for SharePoint RCE flaws exploited in attacks

Microsoft has released emergency SharePoint security updates for two zero-day vulnerabilities tracked as CVE-2025-53770 and CVE-2025-53771 that have compromised services worldwide in "ToolShell" attacks. In May, during the Berlin Pwn2Own hacking contest, researchers exploited a zero-day vulnerability chain called "ToolShell," which enabled them to achieve remote code execution in Microsoft SharePoint. These flaws were fixed as part of the July Patch Tuesday updates; However, threat actors were

HPE warns of hardcoded passwords in Aruba access points

Hewlett-Packard Enterprise (HPE) is warning of hardcoded credentials in Aruba Instant On Access Points that allow attackers to bypass normal device authentication and access the web interface. Aruba Instant On Access Points are compact, plug-and-play wireless (Wi-Fi) devices, designed primarily for small to medium-sized businesses, offering enterprise-grade features (guest networks, traffic segmentation) with cloud/mobile app management. The security issue, tracked as CVE-2025-37103 and rated

Microsoft SharePoint zero-day exploited in RCE attacks, no patch available

A critical zero-day vulnerability in Microsoft SharePoint, tracked as CVE-2025-53770, has been actively exploited since at least July 18th, with no patch available and at least 85 servers already compromised worldwide. In May, Viettel Cyber Security researchers chained two Microsoft SharePoint flaws, CVE-2025-49706 and CVE-2025-49704, in a "ToolShell" attack demonstrated at Pwn2Own Berlin to achieve remote code execution. While Microsoft patched both ToolShell flaws as part of the July Patch T

Hackers scanning for TeleMessage Signal clone flaw exposing passwords

Researchers are seeing exploitation attempts for the CVE-2025-48927 vulnerability in the TeleMessage SGNL app, which allows retrieving usernames, passwords, and other sensitive data. TeleMessage SGNL is a Signal clone app now owned by Smarsh, a compliance-focused company that provides cloud-based or on-premisses communication solutions to various organizations. Scanning for vulnerable endpoints Threat monitoring firm GreyNoise has observed multiple attempts to exploit CVE-2025-48927, likely b

Gmail now makes setting up an appointment much easier for everyone

Edgar Cervantes / Android Authority TL;DR Google now lets all users share a Google Calendar appointment booking page in Gmail. This allows you to easily propose appointment slots with others via email. This general release comes after Google announced the feature back in May. Setting up appointments via email can be a little tedious, as you have to go back and forth with people and wait for their response. However, Google has now brought a handy feature to all Gmail users. Google announced

Algorithms for making interesting organic simulations

Algorithms for making interesting organic simulations The purpose of this article is to explain techiques that enabled me to make simulations like the one below, along with a lot of other organic looking things. We will focus on algorithmic techniques for artistic purpose rather than scientific meaning. 1. Physarum algorithm from Jeff Jones (2010) Jeff Jones presented a simulation algorithm that reproduces the behavior of organisms such as Physarum polycephalum. It is explained in this paper.

Literalism plaguing today’s movies

A warrior is in a prison cell. His guard approaches and shows him the wooden sword that he will receive once he has earned his freedom. The warrior grabs it, uses his unlocked cell door to knock the guard down, and places the sword’s tip on the guard’s throat. He drives it in as one might hammer a post, a coarse and grisly death. Then, for some reason, swaying back and forth, the warrior yells down at the corpse, “Wood or steel, a point is still a point!” An ailing magnate lies in an opulent be

Topics: art best new point way

As an Android user, these are the closest things to AirTags (and better in some ways)

ZDNET's key takeaways The Chipolo One Point and Card Point retail for $26 and $24, respectively. They're highly accurate, robust, and integrate well into the Google ecosystem. However, the One is only splashproof, and the Card version has a non-user-replaceable battery. $23.71 at Amazon AirTags are one of the things that have set the Apple ecosystem apart from the Android ecosystem. But now that Google has rolled out its Find My Device network, Android is catching up. Also: This smart luggag

These AirTags for Android users are finally on sale

ZDNET's key takeaways The Chipolo One Point and Card Point normally retails for $26 and $24, respectively. They're highly accurate, robust, and integrate well into the Google ecosystem. However, the One is only splashproof, and the Card version has a non-user-replaceable battery. View now at Amazon View now at Chipolo more buying choices During Prime Day, you can pick up the Chipolo One Point for as little as $19 on Amazon. Also: The best Prime Day deals so far AirTags are one of the things

Finally, Bluetooth trackers for Android users that rival AirTags (but cost less)

ZDNET's key takeaways The Chipolo One Point and Card Point normally retails for $26 and $24, respectively. They're highly accurate, robust, and integrate well into the Google ecosystem. However, the One is only splashproof, and the Card version has a non-user-replaceable battery. View now at Amazon View now at Chipolo more buying choices For a limited time, you can pick up the Chipolo One Point for as little as $22 on Amazon and other major retailers. Use the promo code 'ZY3U9KA9S1DM' at chec

Show HN: From Photos to Positions: Prototyping VLM-Based Indoor Maps

July 05, 2025 From Photos to Positions: Prototyping VLM-Based Indoor Maps Disclaimer: This project was completed entirely on personal time and hardware. It is not affiliated with, endorsed by, or representative of any institutions or organizations with which I am affiliated. The views and opinions expressed herein are solely my own and do not represent those of my employer or any associated institutions. LLMs and VLMs have been eating the world. Last week, I listened to a talk by Andrej Karp

Topics: cx cy map points shops

Microsoft investigates ongoing SharePoint Online access issues

​Microsoft is investigating an ongoing incident causing intermittent issues for users attempting to access SharePoint Online sites. Part of the Microsoft 365 suite, SharePoint Online is a cloud-based collaboration and document management platform that allows users to create websites, store and share documents, and collaborate on content over the Internet. As the company announced earlier today in an incident alert published in the message center, users are seeing "Something went wrong" errors

Apple's China iPhone sales grows for the first time in two years

Apple iPhone sales in China rose in the second quarter of the year for the first time in two years, Counterpoint Research said, as the tech giant looks to turnaround its business in one of its most critical markets. Sales of iPhones in China jumped 8% year-on-year in the three months to the end of June, according to Counterpoint Research. It's the first time Apple has recorded growth in China since the second quarter of 2023. Apple's performance was boosted by promotions in May as Chinese e-co

Finally, Bluetooth trackers for Android users that beat out my AirTags (and cost less)

ZDNET's key takeaways The Chipolo One Point and Card Point normally retails for $26 and $24, respectively. They're highly accurate, robust, and integrate well into the Google ecosystem. However, the One is only splashproof, and the Card version has a non-user-replaceable battery. $28 at Amazon For a limited time, you can pick up the Chpolo One Point for as little as $21 on Amazon and other major retailers. AirTags are one of the things that have set the Apple ecosystem apart from the Android

You Can't Afford to Be Fooled by the Chase Sapphire Reserve's Apple Perks and 100K Bonus

Chase/CNET The Chase Sapphire Reserve®* has several new annual credits and features, like an Apple Plus and Apple Music membership, valued at $250 a year (ends June 22, 2027). Chase updated the card last week, and all the details sound good on paper (aside from the higher $795 annual fee), but there are some fine-print changes that aren't so great. Cardholders will now have to do more work to get enough value from the card to cover its cost. That likely means the average credit-cardholder won'

The provenance memory model for C

In this article, I will try to explain what this is all about, namely on how a provenance model for pointers interferes with alias analysis of modern compilers. For those that are not fluent with the terminology or the concept we have a short intro what pointer aliasing is all about , a review of existing tools to help the compiler and inherent difficulties and then the proposed model itself . At the end there is a brief takeaway that explains how to generally avoid complications and loss of opt

Chase Sapphire Reserve Launches New $250 Apple Perk. I’m Not Falling for It

Chase/CNET The Chase Sapphire Reserve®* was updated earlier this week and now includes a number of new annual credits and other features, including an Apple Plus and Apple Music membership, valued at $250 annually (ends June 22, 2027). Chase also upped the card's annual fee. It now costs $795 annually, so you'll have to do more legwork to get enough value from the card to cover the cost. That likely means the average credit card user won't even want to consider this as an option. Which is fair

How much slower is random access, really?

by Sam Estep, 2025-06-23 You may know that, because your computer has different caches (L1, L2, L3...), and memory operations operate on cache lines of about 64 bytes each, you should write programs that exhibit locality to get maximum performance. L1 L1 L1 L1 L1 L1 L2 L2 L2 L2 L2 L2 L3 RAM (Disk not shown, of course.) But how well do you understand this idea? For instance, let's say you have an array of floating-point numbers, and an array of all the indices of the first array. You have a p

Iroh: A library to establish direct connection between peers

less net work for networks What is iroh? Iroh gives you an API for dialing by public key. You say “connect to that phone”, iroh will find & maintain the fastest connection for you, regardless of where it is. The fastest route is a direct connection, so if necessary, iroh tries to hole-punch. Should this fail, it can fall back to an open ecosystem of public relay servers. To ensure these connections are as fast as possible, we continuously measure iroh. Built on QUIC Iroh uses Quinn to estab

The Apple Sports app now offers tennis scores, just in time for Wimbledon

Apple is rolling out a notable update for its Sports app . Just ahead of the Wimbledon Championships getting under way, Apple is adding point-by-point tennis scores to Sports. You'll be able to get live updates from Grand Slam and ATP Masters 1000-level matches and view details like the results of a player's previous matches in the tournament. Also in the 3.0 version of Apple Sports, baseball fans can view pitcher and batter matchups at the top of every MLB scoreboard. On the home screen, you'l

I Won't Be Getting the New Chase Sapphire Reserve. Here's Why

Chase/CNET The Chase Sapphire Reserve®* is well-known among travel enthusiasts and average credit card users as a great travel credit card. However, its accessibility to the former crowd is likely to change. The Sapphire Reserve was an expensive card before Chase's recent update at $550 annually, but it now costs $795, which is even more than its top competitor, The Platinum Card® from American Express. Aside from the higher fee, the biggest changes to the card are a greater emphasis on annua

How to store Go pointers from assembly

2025-06-23 How to store Go pointers from assembly The standard Go toolchain comes with an assembler out of the box. Said assembler is highly idiosyncratic, using syntax inherited from Plan 9 and choosing its own names for platform-specific instructions and registers. But it’s great to have it readily available. More mundanely, Go comes with a garbage collector. This post explains how to make these two components play nice, if we want to manipulate Go pointers from our assembly. Preamble: Go’s