Latest Tech News
Daily updates from AI, software, hardware and more.
GitHub ships CodeQL 2.26.1 with broader framework coverage and fewer Rust false positives
GitHub released CodeQL 2.26.1, expanding framework coverage for Go, Java/Kotlin, JavaScript and TypeScript while reducin...
CISA and partners publish CI Fortify guidance for isolating critical infrastructure OT
CISA and allied agencies issued CI Fortify guidance for isolating vital OT systems during cyber incidents and crises.
GitHub adds publish-time malware scanning and dual-use metadata rules for npm packages
GitHub says npm packages will now face malware scanning before install availability, with new disclosure rules for dual-...
GitHub Actions now pauses some suspicious public-repo workflows for human approval
GitHub Actions now automatically holds some suspicious public-repository workflow runs for collaborator approval before ...
Microsoft launches EXTRA to expand AI red teaming with university and regional experts
Microsoft's EXTRA program funds 18 university labs and builds an external network for frontier AI red teaming.
Google proposes Beyond Zero security model for AI-era enterprise access
Google introduced Beyond Zero, a security model for AI-era enterprises built around contextual, resource-level authoriza...
Microsoft Unveils MAI-Cyber-1-Flash and Project Perception for AI Security Workflows
Microsoft announced MAI-Cyber-1-Flash and Project Perception, tying specialized AI agents to vulnerability defense workf...
Microsoft security blog urges tighter controls on device code flow authentication
Microsoft warns admins to restrict OAuth device code flow and move Azure workflows to stronger identity patterns.
Hugging Face CEO seeks transparency after OpenAI model-evaluation security incident
Hugging Face's CEO is seeking more transparency after OpenAI said pre-release models reached its systems during a cyber ...
Cloudflare study finds widespread BGP ORIGIN rewriting can steer Internet traffic
Cloudflare says many BGP paths rewrite ORIGIN, a routing attribute that can shift Internet traffic toward major transit ...
U.S. agencies warn Iran-linked hackers are disrupting water and energy PLCs
U.S. agencies warn Iran-linked hackers are targeting PLCs at water, energy and municipal infrastructure sites.
NodeBB patches eight high-severity flaws found by AI pentesting agents
NodeBB fixed eight high-severity forum flaws found by Aikido's AI pentesting agents, including data leaks and XSS risks.