Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Amid years of warnings that China’s notorious Volt Typhoon hackers may be taking root inside the United States. closed war games for insurance he showed a series of very bad scenes – showing the horrors, the disturbing.
ICE’s internal oversight body, the Office of Professional Responsibility, has begun investigate the organization’s online criticsopening more than 100 lawsuits looking into what ICE officials call “doxing and threats” against agency employees. And in the European Union, technology companies will be able to also scan citizens’ posts, emails, and social media messages because of new powers in the “Chat Control” bill aimed at preventing child abuse online. The European Parliament voted to extend the rules despite the majority of lawmakers voting against the idea.
WIRED revealed more about the Madison Square Garden spotlight this week and the revelations themselves MSG maintained a database of hundreds of celebritiesthe Knicks superstar, and some Taylor Swift wedding guests using labels that included “LGBTQIA,” “DO NOT HOST,” and “low to high risk.”
And a new study this week shows that government websites are hacked just the way they are Hackers promise to “take down” OnlyFans settings are being updated and thousands of copycat complaints from major content creators, helping to keep people safe by removing bad links.
And there are many. Every week, we create security and privacy stories that we haven’t covered in depth ourselves. Click on the headlines to read all the stories. And be safe out there.
Nebula Security has released the exploit code for GhostLock (CVE-2026-43499), a later exploit bug that has been in the Linux kernel for 15 years and allows any user to gain root access on an unmodified machine, according to SecurityWeek and Hacker News. An error that is sent by default on all distributions since 2011 and does not require special permissions or network access. Nebula’s application avoids downloads and was 97 percent reliable in testing. He earned $92,337 through the Google kernelCTF program. It was launched in April, but the availability of the patch is not the same; Ubuntu, as of early July, still lists 24.04, 22.04, and 20.04 LTS as vulnerable or in development, so maintainers should confirm the stable package instead of assuming they are waiting.
In particular, Nebula discovered the bug with VEGA, its AI-powered bug-hunting tool, a 2026 batch of Linux bugs caused by old operating system tools that it read over the years.
Writing in Drivejournalist Joel Feder describes being thrown into a box by four Plymouth, Minnesota, police cars in the Kohl’s parking lot at the end of June – officers shouting, hands on their guns – because Flock’s license plate cameras had shown the $155,000 Range Rover they were testing, rented from a New Jersey dealer, as stolen. Feder writes that police have been following SUVs around the city for days … because of a typo.
The cause was traced to a data entry error 2,000 kilometers away: Jaguar Land Rover’s license plate number 34 03 DTM was reported to the Los Angeles police as lost, but entered into the system as “34 DTM” – dropping the small central numbers that New Jersey uses on manufacturer’s plates. Flock’s cameras read the large letters, ignore the design, and start alerting the police of any similar vehicle. Feder also reported that four other Land Rovers sharing the same type of license plate were being tracked in Minnesota that same week; he was the first to be drawn.
The disc that started the whole police operation was found to have never been stolen, it was just lost during the photo shoot. Ironically, the event came just two weeks after The Drive published a report on the virus for this type of Flock overreach.
Consulting giant Accenture has confirmed a security breach after attacker “888” allegedly uploaded 35 GB of data-source code, RSA and SSH keys, Azure access tokens, and configuration files – and sold it to an online crime forum, according to BleepingComputer. Accenture called it “an isolated issue,” said it had redacted the source, and said it had no impact on operations but declined at the time to comment on what was taken or how the attackers gained access. BleepingComputer was unable to confirm the details. This is not the first time actors have targeted the company – 888 tried to sell Accenture employee information after a third-party breach in 2024, and Accenture was separately hit by LockBit ransomware in 2021.
The timing of the breach is dire: Accenture’s federal arm has caught on ICE Contract for Cyber Defense and Intelligence Support Services– 24/7 threat assessment, intrusion detection, and incident response on the agency’s network through September 2021, a $56.5 million project that ended in late August and is being reinstated.
The Pentagon opened applications this week for Cyber RAP, a paid training program that recruits people without a cyber degree or skills – learning skills – in 12 months, a full-time program to learn to manage the department’s network, according to DefenseScoop. The US military’s CIO, Kirsten Davies, ranked it as a “gatekeeper for education” because of its “qualification, patriotism, and ability to succeed.” But the salary is $22,584 a year, and the cleaners will repay the state for the training.
It is an in-house talent building partnership. Another option on the table is borrowing. Provisions in the Senate Armed Services Committee’s FY2027 bill allow Defense Secretary Pete Hegseth to begin conducting cyber operations through “contractual, contractor-driven mechanisms” — a government-sanctioned body, GovInfoSecurity reports.