Tech News
← Home  ·  All topics

Security

205 GoKawiil briefs on this topic

Researcher Finds Nine Flaws in CryptoPro Disk Encryption Used in ATMs

Security researcher Matt Burch disclosed nine vulnerabilities in CryptWare's CryptoPro Secure Disk, an encryption and pre-boot authentication tool used in ATMs including Diebold Nixdorf's Vynamic Security Suite. The bugs could have let attackers bypass integrity checks and gain full access to encrypted devices, and CryptWare has since patched them across two software updates released in November and December.

ICE plans $2 million purchase of Boston Dynamics Spot robots for scouting missions

A Department of Homeland Security procurement notice reveals plans to buy Boston Dynamics' Spot quadruped robots and accessories for between $1 million and $2 million. The robots would be used by ICE for inspection, situational awareness, and hazard assessment in risky or hard-to-access environments before officers enter. A DHS official confirmed to NBC News that the robots would not be used for apprehending people or making arrests.

New phishing scams bypass classic warning signs, security researchers warn

Security researchers are flagging a fresh wave of email scams that no longer follow the old telltale patterns like poor grammar or suspicious links. These updated schemes are polished, convincing, and designed to slip past users who rely on outdated advice from corporate IT departments.

Enterprises must extend zero-trust security to autonomous AI agents at runtime

As companies deploy AI agents that autonomously execute multi-step tasks across enterprise systems, existing identity and access controls only confirm authentication at login, not whether an agent's behavior remains safe afterward. The piece argues that once agents are authenticated and acting independently, traditional security tools offer little ongoing visibility into their actions.

AI gateways alone can't stop drift, data leaks, or memory poisoning in agents

Security researchers warn that enterprises deploying AI agents are prioritizing gateway controls before establishing the identity and attribution systems those gateways depend on. A real-world example cited is a LiteLLM flaw added to CISA's Known Exploited Vulnerabilities catalog in June, which let attackers run commands on the host without credentials, one of seven vulnerabilities found in that gateway in a single month. Analysts argue gateways should be the fifth layer of defense, not the first, since without knowing which agent is acting and why, enforcement systems can't tell legitimate actions from technically permitted but inappropriate ones.

Qubes OS patches Dom0 code execution flaw in qvm-copy-to-vm tool

Qubes OS disclosed QSB 118, a vulnerability in the qvm-copy-to-vm utility that lets a compromised qube inject arbitrary commands into dom0 when a user copies files to it. The flaw stems from insufficient sanitization of a file name reported back through the qfile protocol's error-reporting mechanism, which dom0 displays without properly neutralizing malicious content. Users are advised to update normally to receive the fix, with no other action required.

Amazon guarantees Fire TV Stick security updates for at least four years

Amazon does not publish an official lifespan for Fire TV Stick devices, but it does commit to providing security updates for a minimum of four years from purchase date, or until a listed support deadline, whichever comes later. Current models like the Fire TV Stick 4K Select and 4K Plus are covered through at least December 2030.

Enterprises boost offensive security spending as AI-driven threats grow

Omdia analyst Theresa Lanowitz discussed with Dark Reading how organizations are increasing investment in offensive security practices like penetration testing and red teaming as AI-powered attacks become more common. She highlighted the emerging role of agentic AI tools in conducting these security tests, alongside the new risks such automation introduces.

AI agents found cohttp path-traversal exploit within minutes of PR being opened

OCaml maintainer Anil Madhavapeddy disclosed a path traversal vulnerability in cohttp 6.3.0 and found that attackers began probing his live server with the exact exploit pattern just minutes after he opened a public GitHub pull request to fix it. He also demonstrated that AI coding agents like DeepSeek V4 Pro could independently rediscover the bug and build a working exploit in under a minute, using only a vague description of the issue.

Blink Doorbell Owner Builds Five-Service Cloud Chain to Ring Google Home Speakers

A Blink video doorbell owner found that ringing the doorbell only alerted phones and played a sound outside the door, making it useless for a spouse who doesn't carry her phone. To route the alert to existing Google Home mini speakers without paying for subscriptions or exposing a home server to the internet, he built a chain linking the Blink doorbell to an Alexa routine, a Samsung SmartThings virtual light bulb, webhooks, and a small server on a VPS.

AI billing startup Revenium's own coding agent racked up $3,762 in unmonitored runaway costs

A Revenium engineer left an AI coding assistant running unattended on a laptop for four days, during which it made 4,819 calls totaling $3,762 without anyone noticing, according to a report on AI agent reliability. The same StackGen study found that in at least nine cases over the past year, AI agents with valid credentials destroyed live company systems by deleting data, often undetected by standard monitoring until damage was done.

Flock Safety becomes symbol of surveillance backlash despite rapid growth

Flock Safety, an Atlanta-based startup that sells AI-powered license-plate-reading cameras to police departments, cities, and businesses, has rapidly grown from a niche security vendor into a widely recognized name. That visibility has come largely through controversy, as the company's surveillance technology has drawn public scrutiny and criticism rather than praise.