Tech nieuws

IT

SlashDot.org

https://slashdot.org

China's Moonshot In Talks With Microsoft, Amazon, Google Over K3 Revenue Sharing

  Pagina openen
Longtime Slashdot reader schwit1 shares a report from Reuters: China's Moonshot AI is negotiating revenue-sharing agreements with Microsoft, Amazon, and Alphabet's Google, that would allow the U.S. cloud giants to host its blockbuster Kimi K3 model, three people familiar with the talks said. Any deal could mark the first big revenue-sharing pact between a Chinese AI firm and a major U.S. cloud company. The discussions highlight how China's leading AI models, often far cheaper than Western offerings, are gaining traction in the U.S., despite national security concerns in Washington that have led to bans on exports of AI chips to China. They are also taking place despite critical comments about Moonshot from senior U.S. officials. IPO-bound Moonshot is seeking up to a 30% share of revenue generated from K3-related services on Microsoft's Azure, Amazon Web Services and Google Cloud, according to the sources who declined to be identified because the discussions are private. That would be in line with terms that sources have said the startup has outlined for major customers using the open-weight model. Moonshot has come under fire from U.S. Treasury Secretary Scott Bessent who said last month that he might add it to a trade blacklist. U.S. officials have accused the Beijing-based company of stealing from Anthropic's most sophisticated model, Fable, to help create Kimi K3 and illegally acquiring Nvidia chips.

Read more of this story at Slashdot.

https://news.slashdot.org/story/26/08/26/2042210/chinas-moonshot-in-talks-with-microsoft-amazon-google-over-k3-revenue-sharing?utm_source=rss1.0mainlinkanon&utm_medium=feed


Apple Maps Now Has Ads

  Pagina openen
Apple has begun rolling out ads in Apple Maps, with sponsored businesses appearing at the top of search results and in the "suggested places" section for users in the U.S. and Canada. Apple says the ads can be based on approximate location, search terms, or the area of the map being viewed, but are not tied to users' Apple Accounts and personal data remains on-device. 9to5Mac reports: Ads appear just like every other business listing, except they have a small blue badge that says 'Ad.' You can see examples of ads [embedded in the article]. Like Apple's ads policy with other services, the company touts user privacy protections for ads in Maps. Per Apple Newsroom: "Ads on Maps builds on Apple's broader privacy-first approach to advertising, and maintains the same privacy protections Maps users enjoy today. A user's location and the ads they see and interact with in Maps are not associated with a user's Apple Account. Personal data stays on a user's device, is not collected or stored by Apple, and is not shared with third parties."

Read more of this story at Slashdot.

https://apple.slashdot.org/story/26/08/26/2033235/apple-maps-now-has-ads?utm_source=rss1.0mainlinkanon&utm_medium=feed


Inside the Warehouse Where Amazon Scans and Destroys Books For AI Training

  Pagina openen
Last week, 404 Media published a story that revealed an Amazon warehouse where the company scans and destroys thousands of books for AI training data. Today, the publication has released an interview with one of the Amazon employees at the warehouse. "The employee worked at Amazon's VGT3 warehouse, which is housed in the same facility as LAS8, where Amazon operates its print-on-demand business," reports 404 Media. "Both operations are part of a larger complex of Amazon facilities in Las Vegas, Nevada." Slashdot reader alternative_right shares an excerpt from the report: [...] What does it look like when they cut the spines off the books? It's a machine people operate. Each of these machines is just like a little workstation, and there'll be one person at each of these stations. It's really safe because it has a little cover and it has a little area where you slide the book into, remove your fingers from the area, and then you press a button, and it just comes down and slices it. And then you remove the books after the blade is gone. After they cut the spines they have these kind of library carts, kind of like how you would stack books, but instead, it's a stacks of paper and little cardboard things to separate -- I'm guessing -- the different books. I saw the pages being thrown in a shuttle after they were scanned. We were walking by and we went over to one of the shuttles and looked into it because we could tell they were throwing the old books in it or the cut books in it, and it's just a bunch of loose paper like just sheets thrown in there. What do you think about Amazon doing this? At first what they were telling people is that it was for Kindles, but I just didn't believe that. I instantly was like, I don't think that's how they do it because of publication rights and stuff, copyright and everything. Then I saw it was for AI. I don't like it only because I wish I could take these books. There's so much knowledge and so much stuff in them and some of them look like they might be rare, and I've heard that they order rare books, and that's why I say some of these are so obscure. I definitely don't like the idea that they can't be reused or anything like that afterwards. They're reducing the amount of available copies for other people.

Read more of this story at Slashdot.

https://news.slashdot.org/story/26/08/26/1857240/inside-the-warehouse-where-amazon-scans-and-destroys-books-for-ai-training?utm_source=rss1.0mainlinkanon&utm_medium=feed


Xbox's New Disc-to-Digital Program Gives Physical Games a Digital Future

  Pagina openen
An anonymous reader quotes a report from Ars Technica: For decades, console owners have faced a choice between the convenience of digital downloads and the permanence of physical game discs. Soon, Xbox owners will be able to get the best of both worlds for thousands of supported titles as part of a newly announced disc-to-digital program. The program -- announced today ahead of testing for Xbox Insiders starting August 31 -- will let players claim a "digital entitlement" for "most Xbox One and Xbox Series X disc-based games" simply by inserting the disc into a console and launching it. That game will then be playable completely digitally, without the need to ever insert the disc, as long as you (or a member of your family account) is logged in. The digital entitlement will also allow access to features like Xbox Play Anywhere (for play on PC) and Xbox Cloud Gaming, for supported titles. Microsoft says that your physical disc will "continue to work exactly as it always has" after the digital entitlement is claimed. But before you get any ideas, the fine print on the announcement mentions that there is only "one revokable license per game disc," so if you resell that disc or loan it to a friend, that digital entitlement could be transferred to a new account when someone else puts it into their console. A leaked memo obtained by the Verge earlier this month suggests that publishers have to actively opt in to allow their game discs to activate digital entitlements, which could explain why "most" but not all Xbox One and Series X titles are supported. Windows Central separately suggests, based on discussion with unnamed sources, that "some discs may be incompatible due to how they were manufactured at the time," which could explain why original Xbox and Xbox 360 discs are not being discussed for the program. "While not every title will be available at launch, this is an important step toward a future where players can have greater confidence that the games they buy remain with them for years to come," said Xbox Vice President Jason Ronald.

Read more of this story at Slashdot.

https://games.slashdot.org/story/26/08/26/1833206/xboxs-new-disc-to-digital-program-gives-physical-games-a-digital-future?utm_source=rss1.0mainlinkanon&utm_medium=feed


Amazon to Acquire DuckLabs, Adding the Team Behind DuckDB

  Pagina openen
Amazon has agreed to acquire DuckLabs, bringing the team behind the popular open-source DuckDB database into AWS. "The deal fits Amazon's broader push to turn S3, its flagship cloud storage service, into a place where customers analyze data rather than just store it," reports GeekWire. "It gives Amazon a team experienced in building fast, lightweight analytics software that runs directly against data sitting in cloud storage." The DuckDB project itself will remain free and open source under the MIT license, overseen by the independent DuckDB Foundation. From the report: Employees of DuckLabs will join Amazon Web Services, including co-founders and DuckDB creators Hannes Muhleisen and Mark Raasveldt, who will continue leading the team and setting the project's technical direction. They will remain based in Amsterdam, where the team will continue developing DuckDB and related projects. [...] Financial terms were not disclosed. Amazon said it has signed a definitive agreement and expects the acquisition to close shortly. DuckLabs said it expects to become part of AWS in early September. Jordan Tigani, the CEO of MotherDuck, which sells a cloud service built on DuckDB, sees Amazon's acquisition as a predictable move to turn DuckDB's growing popularity into an AWS business. "That's Amazon's playbook, after all: wait until an open source project gets big enough, then launch it as a service," he wrote in a blog post, adding that "they're not acquiring Duck Labs just because they love open source." Tigani also believes the deal could ultimately strengthen DuckDB, since Amazon has an incentive to keep the project open and widely adopted: "If DuckDB becomes the standard, it is going to drive a lot more compute on their infrastructure, which is where they make their money."

Read more of this story at Slashdot.

https://developers.slashdot.org/story/26/08/26/1824257/amazon-to-acquire-ducklabs-adding-the-team-behind-duckdb?utm_source=rss1.0mainlinkanon&utm_medium=feed


Techcrunch.com

https://techcrunch.com/






Cnet.com

https://www.cnet.com






Arstechnica.com

https://arstechnica.com






Wired.com

https://www.wired.com






ZDNet.com

https://www.zdnet.com






TechRepublic.com

https://www.techrepublic.com






mashable.com

https://mashable.com/tech





TVS iQube MillionR Launched In India: New Design, Features And Price Explained

  Pagina openen
The TVS iQube MillionR continues with the same 3.5kWh battery and electric motor as the standard model. It offers a claimed IDC range of 145km on a single full charge. TVS Motor Company has introduced the iQube MillionR Special Edition in India to celebrate the electric scooter surpassing the one-million customer milestone. Based on the 3.5kWh variant, it is priced at INR 1,40,138 (ex-showroom).

https://in.mashable.com/tech/113301/tvs-iqube-millionr-launched-in-india-new-design-features-and-price-explained


Geekwire.com

https://www.geekwire.com


Washington to receive up to $339M in landmark $17B settlement over Meta social media addiction claims

  Pagina openen

Washington Attorney General Nick Brown said that the historic agreement delivers on core youth-safety product changes — including hard caps on daily time limits, late-night scrolling blocks, and disabled push notifications during school hours. Read More

https://www.geekwire.com/2026/washington-to-receive-up-to-339m-in-landmark-17b-settlement-over-meta-social-media-addiction-claims/



Amazon to acquire DuckLabs, adding the team behind DuckDB amid broader shakeup in cloud data

  Pagina openen

Amazon is acquiring DuckLabs, the Amsterdam company behind DuckDB, the fast-growing open-source database developers use to analyze large amounts of data without paying for a cloud data warehouse. The team joins AWS, but the DuckDB project itself stays free and open source under an independent foundation. Read More

https://www.geekwire.com/2026/amazon-acquires-ducklabs-adding-the-team-behind-duckdb-amid-broader-shakeup-in-cloud-data/


Not dead yet: The race to give spent EV batteries a second life on the grid and beyond

  Pagina openen

A decade or two on the road will drain an EV battery’s range and hobble its acceleration. But while it peters out for daily commutes, that battery still has a lot of juice left. This episode of Positive Charge from GeekWire focuses on companies resurrecting these batteries to power off-grid communities, industrial sites and energy-hungry data centers. Read More

https://www.geekwire.com/2026/not-dead-yet-the-race-to-give-spent-ev-batteries-a-second-life-on-the-grid-and-beyond/


Latest from TechRadar

https://www.techradar.com

Quote of the day by PsiQuantum CEO Jeremy O’Brien: 'If you think the goal is to get to the top of the Empire State Building, you build longer ladders' — a challenge to incremental hardware progress in quantum computing


iPod nostalgia is at an all-time high, so meet two new cheap, adorable tiny hi-res music players that invoke the best of the music-player era (bring your own white wired earbuds)



Meta settles its alleged social media harm case for $18B and agrees to massive changes that may be almost impossible to enforce

  Pagina openen
Meta just settled the huge multi-state case against it, alleging that the social media giant's products harm teens. It's paying $18B, but are the promised product changes enough to transform the services and truly protect teens?

https://www.techradar.com/computing/instagram/meta-settles-its-alleged-social-media-harm-case-for-usd18b-and-agrees-to-massive-changes-that-may-be-almost-impossible-to-enforce



Cybersecurity

Security.nl

https://www.security.nl






Slashdot

https://slashdot.org/

China's Moonshot In Talks With Microsoft, Amazon, Google Over K3 Revenue Sharing

  Pagina openen
Longtime Slashdot reader schwit1 shares a report from Reuters: China's Moonshot AI is negotiating revenue-sharing agreements with Microsoft, Amazon, and Alphabet's Google, that would allow the U.S. cloud giants to host its blockbuster Kimi K3 model, three people familiar with the talks said. Any deal could mark the first big revenue-sharing pact between a Chinese AI firm and a major U.S. cloud company. The discussions highlight how China's leading AI models, often far cheaper than Western offerings, are gaining traction in the U.S., despite national security concerns in Washington that have led to bans on exports of AI chips to China. They are also taking place despite critical comments about Moonshot from senior U.S. officials. IPO-bound Moonshot is seeking up to a 30% share of revenue generated from K3-related services on Microsoft's Azure, Amazon Web Services and Google Cloud, according to the sources who declined to be identified because the discussions are private. That would be in line with terms that sources have said the startup has outlined for major customers using the open-weight model. Moonshot has come under fire from U.S. Treasury Secretary Scott Bessent who said last month that he might add it to a trade blacklist. U.S. officials have accused the Beijing-based company of stealing from Anthropic's most sophisticated model, Fable, to help create Kimi K3 and illegally acquiring Nvidia chips.

Read more of this story at Slashdot.

https://news.slashdot.org/story/26/08/26/2042210/chinas-moonshot-in-talks-with-microsoft-amazon-google-over-k3-revenue-sharing?utm_source=rss1.0mainlinkanon&utm_medium=feed


Apple Maps Now Has Ads

  Pagina openen
Apple has begun rolling out ads in Apple Maps, with sponsored businesses appearing at the top of search results and in the "suggested places" section for users in the U.S. and Canada. Apple says the ads can be based on approximate location, search terms, or the area of the map being viewed, but are not tied to users' Apple Accounts and personal data remains on-device. 9to5Mac reports: Ads appear just like every other business listing, except they have a small blue badge that says 'Ad.' You can see examples of ads [embedded in the article]. Like Apple's ads policy with other services, the company touts user privacy protections for ads in Maps. Per Apple Newsroom: "Ads on Maps builds on Apple's broader privacy-first approach to advertising, and maintains the same privacy protections Maps users enjoy today. A user's location and the ads they see and interact with in Maps are not associated with a user's Apple Account. Personal data stays on a user's device, is not collected or stored by Apple, and is not shared with third parties."

Read more of this story at Slashdot.

https://apple.slashdot.org/story/26/08/26/2033235/apple-maps-now-has-ads?utm_source=rss1.0mainlinkanon&utm_medium=feed


Inside the Warehouse Where Amazon Scans and Destroys Books For AI Training

  Pagina openen
Last week, 404 Media published a story that revealed an Amazon warehouse where the company scans and destroys thousands of books for AI training data. Today, the publication has released an interview with one of the Amazon employees at the warehouse. "The employee worked at Amazon's VGT3 warehouse, which is housed in the same facility as LAS8, where Amazon operates its print-on-demand business," reports 404 Media. "Both operations are part of a larger complex of Amazon facilities in Las Vegas, Nevada." Slashdot reader alternative_right shares an excerpt from the report: [...] What does it look like when they cut the spines off the books? It's a machine people operate. Each of these machines is just like a little workstation, and there'll be one person at each of these stations. It's really safe because it has a little cover and it has a little area where you slide the book into, remove your fingers from the area, and then you press a button, and it just comes down and slices it. And then you remove the books after the blade is gone. After they cut the spines they have these kind of library carts, kind of like how you would stack books, but instead, it's a stacks of paper and little cardboard things to separate -- I'm guessing -- the different books. I saw the pages being thrown in a shuttle after they were scanned. We were walking by and we went over to one of the shuttles and looked into it because we could tell they were throwing the old books in it or the cut books in it, and it's just a bunch of loose paper like just sheets thrown in there. What do you think about Amazon doing this? At first what they were telling people is that it was for Kindles, but I just didn't believe that. I instantly was like, I don't think that's how they do it because of publication rights and stuff, copyright and everything. Then I saw it was for AI. I don't like it only because I wish I could take these books. There's so much knowledge and so much stuff in them and some of them look like they might be rare, and I've heard that they order rare books, and that's why I say some of these are so obscure. I definitely don't like the idea that they can't be reused or anything like that afterwards. They're reducing the amount of available copies for other people.

Read more of this story at Slashdot.

https://news.slashdot.org/story/26/08/26/1857240/inside-the-warehouse-where-amazon-scans-and-destroys-books-for-ai-training?utm_source=rss1.0mainlinkanon&utm_medium=feed


Xbox's New Disc-to-Digital Program Gives Physical Games a Digital Future

  Pagina openen
An anonymous reader quotes a report from Ars Technica: For decades, console owners have faced a choice between the convenience of digital downloads and the permanence of physical game discs. Soon, Xbox owners will be able to get the best of both worlds for thousands of supported titles as part of a newly announced disc-to-digital program. The program -- announced today ahead of testing for Xbox Insiders starting August 31 -- will let players claim a "digital entitlement" for "most Xbox One and Xbox Series X disc-based games" simply by inserting the disc into a console and launching it. That game will then be playable completely digitally, without the need to ever insert the disc, as long as you (or a member of your family account) is logged in. The digital entitlement will also allow access to features like Xbox Play Anywhere (for play on PC) and Xbox Cloud Gaming, for supported titles. Microsoft says that your physical disc will "continue to work exactly as it always has" after the digital entitlement is claimed. But before you get any ideas, the fine print on the announcement mentions that there is only "one revokable license per game disc," so if you resell that disc or loan it to a friend, that digital entitlement could be transferred to a new account when someone else puts it into their console. A leaked memo obtained by the Verge earlier this month suggests that publishers have to actively opt in to allow their game discs to activate digital entitlements, which could explain why "most" but not all Xbox One and Series X titles are supported. Windows Central separately suggests, based on discussion with unnamed sources, that "some discs may be incompatible due to how they were manufactured at the time," which could explain why original Xbox and Xbox 360 discs are not being discussed for the program. "While not every title will be available at launch, this is an important step toward a future where players can have greater confidence that the games they buy remain with them for years to come," said Xbox Vice President Jason Ronald.

Read more of this story at Slashdot.

https://games.slashdot.org/story/26/08/26/1833206/xboxs-new-disc-to-digital-program-gives-physical-games-a-digital-future?utm_source=rss1.0mainlinkanon&utm_medium=feed


Amazon to Acquire DuckLabs, Adding the Team Behind DuckDB

  Pagina openen
Amazon has agreed to acquire DuckLabs, bringing the team behind the popular open-source DuckDB database into AWS. "The deal fits Amazon's broader push to turn S3, its flagship cloud storage service, into a place where customers analyze data rather than just store it," reports GeekWire. "It gives Amazon a team experienced in building fast, lightweight analytics software that runs directly against data sitting in cloud storage." The DuckDB project itself will remain free and open source under the MIT license, overseen by the independent DuckDB Foundation. From the report: Employees of DuckLabs will join Amazon Web Services, including co-founders and DuckDB creators Hannes Muhleisen and Mark Raasveldt, who will continue leading the team and setting the project's technical direction. They will remain based in Amsterdam, where the team will continue developing DuckDB and related projects. [...] Financial terms were not disclosed. Amazon said it has signed a definitive agreement and expects the acquisition to close shortly. DuckLabs said it expects to become part of AWS in early September. Jordan Tigani, the CEO of MotherDuck, which sells a cloud service built on DuckDB, sees Amazon's acquisition as a predictable move to turn DuckDB's growing popularity into an AWS business. "That's Amazon's playbook, after all: wait until an open source project gets big enough, then launch it as a service," he wrote in a blog post, adding that "they're not acquiring Duck Labs just because they love open source." Tigani also believes the deal could ultimately strengthen DuckDB, since Amazon has an incentive to keep the project open and widely adopted: "If DuckDB becomes the standard, it is going to drive a lot more compute on their infrastructure, which is where they make their money."

Read more of this story at Slashdot.

https://developers.slashdot.org/story/26/08/26/1824257/amazon-to-acquire-ducklabs-adding-the-team-behind-duckdb?utm_source=rss1.0mainlinkanon&utm_medium=feed


theregister.com/security

https://www.theregister.com/security






CISO2CISO.com

https://ciso2ciso.com

Vuldb

https://vuldb.com

CVE-2026-77507 | WeblateOrg Weblate up to 2026.7 RSS Feed permission

  Pagina openen
A vulnerability classified as problematic was found in WeblateOrg Weblate up to 2026.7. This issue affects some unknown processing of the component RSS Feed. Executing a manipulation can lead to permission issues. The identification of this vulnerability is CVE-2026-77507. The attack may be launched remotely. There is no exploit available. Upgrading the affected component is advised.

https://vuldb.com/vuln/396005




CVE-2026-77573 | WeblateOrg Weblate up to 2026.7 server-side request forgery

  Pagina openen
A vulnerability marked as critical has been reported in WeblateOrg Weblate up to 2026.7. Affected by this issue is some unknown functionality. This manipulation causes server-side request forgery. This vulnerability is handled as CVE-2026-77573. The attack can be initiated remotely. There is not any exploit available. It is suggested to upgrade the affected component.

https://vuldb.com/vuln/396002



advisories.ncsc.nl

https://advisories.ncsc.nl/

NCSC-2026-0329 [1.00] [H/M] Kwetsbaarheden verholpen in Next.js

  Pagina openen
Vercel heeft twee kwetsbaarheden verholpen in Next.js, een React framework voor het ontwikkelen van (web)applicaties. Een kwaadwillende kan de kwetsbaarheid met kenmerk CVE-2026-75604 misbruiken voor het uitvoeren van willekeurige code op de applicatieserver. De kwetsbaarheid is alleen aanwezig in Next.js-applicaties die op een Windows-omgeving worden gehost en die een Pages- en App-router gebruiken zonder de Cache Component. Naast deze kwetsbaarheid is er ook een andere kwetsbaarheid verholpen die kwaadwillenden in staat stelt willekeurige code uit te voeren. Hiertoe dient een malafide mediabestand aan een kwetsbare applicatie te worden aangeboden. Deze kwetsbaarheid heeft ten tijde van publicatie nog geen CVE-kenmerk toegekend gekregen.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0329


NCSC-2026-0328 [1.00] [M/H] Kwetsbaarheden verholpen in DrayTek VigorSwitch

  Pagina openen
DrayTek heeft meerdere kwetsbaarheden verholpen in de VigorSwitch productlijn. De kwetsbaarheden betreffen voornamelijk command injection, buffer overflow, null pointer dereference, directory traversal en onvoldoende autorisatiecontroles in diverse functies van de DrayTek VigorSwitch apparaten. Command injection kwetsbaarheden bevinden zich onder andere in functies zoals jsonstatus, commandTable, pingtrace, webBackupAction, sysreboot, auth_set, getVid, getDetail, setDevice, rebDevice, fdftDevice, setDevProto, setTime, tftp_upgrade en setDevNet. Deze maken het mogelijk voor een aanvaller om willekeurige commando's met root privileges uit te voeren. Sommige command injection kwetsbaarheden zijn pre-authenticatie, zoals in de setget.cgi interface, waardoor geen voorafgaande authenticatie vereist is voor exploitatie. Buffer overflow kwetsbaarheden zijn aanwezig in functies zoals pingtrace, webBackupAction, sysreboot, poe_schedule_profile, switch_lan_gvrp, acl_general_setup Add ACE en Edit ACE, diag_logmail en mail_mailalert. Deze kunnen leiden tot denial of service of uitvoering van willekeurige code onder administratieve rechten. Null pointer dereference kwetsbaarheden in formlogout en setget.cgi kunnen leiden tot een denial of service door het crashen van de service. Directory traversal in getSyslogFile maakt het mogelijk om, mits geauthenticeerd, toegang te krijgen tot willekeurige bestanden op het systeem. Onvoldoende autorisatiecontroles in syslog functies stellen een aanvaller in staat om configuraties te wijzigen, services te herstarten, configuraties op te slaan of logs te wissen zonder de juiste rechten. Exploitatie van deze kwetsbaarheden vereist in de meeste gevallen geldige administratieve credentials, behalve bij de pre-authenticatie command injection en null pointer dereference in setget.cgi.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0328


NCSC-2026-0327 [1.00] [M/H] Kwetsbaarheden verholpen in DrayTek VigorAP

  Pagina openen
DrayTek heeft meerdere kwetsbaarheden verholpen in de VigorAP productlijn. De kwetsbaarheden bevinden zich in verschillende functies en componenten van de DrayTek VigorAP apparaten, waaronder tr069TestInform, ExportSettings, setLan, setcamset, mesh_start_speed_test, InquierTime, apautotest, upload_settings.cgi en dray_apm. Deze kwetsbaarheden maken het mogelijk voor aanvallers met geldige authenticatie om via onvoldoende inputvalidatie en filtering willekeurige commando's uit te voeren met root-privileges. Daarnaast is er sprake van buffer overflow kwetsbaarheden in de setLan en apautotest functies, waarbij door het versturen van speciaal vervaardigde input een denial of service kan worden veroorzaakt of willekeurige code kan worden uitgevoerd. Exploitatie van deze kwetsbaarheden kan leiden tot volledige systeemcompromittering binnen de context van de root gebruiker. De kwetsbaarheden zijn specifiek van toepassing op meerdere modellen binnen de DrayTek VigorAP productlijn.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0327


NCSC-2026-0303 [1.01] [M/H] Kwetsbaarheden verholpen in GitLab door GitLab Inc.

  Pagina openen
GitLab Inc. heeft kwetsbaarheden verholpen in GitLab Community Edition (CE) en Enterprise Edition (EE). De kwetsbaarheden bevinden zich in de GraphQL-implementatie van GitLab. Een eerste kwetsbaarheid maakte het mogelijk voor niet-geauthenticeerde gebruikers om via een GraphQL-directive ongeautoriseerde wijzigingen of verwijderingen uit te voeren op publieke projecten en gebruikersdata. Een tweede kwetsbaarheid stelde niet-geauthenticeerde gebruikers in staat om mutaties uit te voeren via GET-requests door onjuiste validatie van GraphQL multiplex queries, waarbij mutatie-operaties niet correct werden beperkt. Hierdoor kunnen onbevoegden ongeautoriseerde wijzigingen aanbrengen in de staat van de server. Update: Inmiddels is er publieke PoC code beschikbaar waardoor de kans op actief misbruik aanzienlijk toeneemt. Het NCSC adviseert voor systemen waar dit nog niet gebeurt is zo snel mogelijk de updates door te voeren.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0303


NCSC-2026-0326 [1.00] [M/H] Kwetsbaarheden verholpen in Keycloak

  Pagina openen
Red Hat heeft meerdere kwetsbaarheden verholpen in Keycloak. De kwetsbaarheid met CVE-2026-18963 kan een ongeauthenticeerde externe aanvaller in staat stellen om elke gebruikersaccount over te nemen door een wachtwoordreset af te dwingen. Door deze kwetsbaarheid valt het e-mailverificatieproces bij wachtwoordreset te omzeilen en wachtwoorden van gebruikers te wijzigen. In Keycloak zijn daarnaast kwetsbaarheden aanwezig in de Fine-Grained Admin Permissions (FGAP) v2, waardoor bepaalde beheerders met beperkte permissies metadata van verborgen groepen kunnen inzien en details van ongeautoriseerde oudergroepen kunnen blootstellen. Verder kunnen geauthenticeerde aanvallers via een legacy client-initiated account-linking endpoint CSRF-bescherming omzeilen en accounts overnemen. Ook kunnen gedelegeerde beheerders met alleen leesrechten client secrets uitlezen door een fout in de secret rotation. Voor OpenTelemetry Java was er een kwetsbaarheid waarbij het ontbreken van limieten op baggage headers leidde tot onbegrensd geheugen- en CPU-gebruik, wat Denial-of-Service kan veroorzaken. Bij Jackson-libraries is een bypass van de @JsonIgnore annotatie in Java Records vastgesteld, waardoor ongewenste toewijzing aan constructorparameters mogelijk is. Ook zijn er bypasses van @JsonIgnoreProperties, ontbrekende view guards op @JsonUnwrapped en ongeautoriseerde schrijfacties op velden met @JsonView. Oracle Database Server's Fleet Patching and Provisioning component is eveneens getroffen door een kwetsbaarheid die ongeautoriseerde data toegang of Denial-of-Service kan veroorzaken.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0326


NCSC Nieuws

https://www.ncsc.nl/actueel

Ernstige kwetsbaarheden gevonden in DrayTek VigorAP

  Pagina openen
Er zijn meerdere ernstige kwetsbaarheden gevonden in de DrayTek VigorAP-productlijn. De kwetsbaarheden zijn beoordeeld als 'medium' wat betreft de kans op misbruik en als 'high' wat betreft de mogelijke schade door het Nationaal Cybersecurity Centrum (NCSC). De VigorAP apparaten worden gebruikt voor draadloze netwerkverbindingen en bieden toegang tot het internet en bedrijfsnetwerken. Het advies is om de door DrayTek uitgebrachte updates zo snel mogelijk te installeren om misbruik te voorkomen.

https://www.ncsc.nl/alerts/ernstige-kwetsbaarheden-gevonden-in-draytek-vigorap




NCSC en Oekraïens SSSCIP bundelen krachten om digitale weerbaarheid te versterken

  Pagina openen
Afgelopen week ontmoette NCSC directeur Matthijs van Amelsfort de voorzitter van de State Service of Special Communications and Information Protection of Ukraine (SSSCIP), Oleksandr Potii, ter gelegenheid van de ondertekening van een Memorandum of Understanding (MoU). Deze overeenkomst maakt gerichte investeringen in informatie-uitwisseling en kennisdeling om digitale weerbaarheid te versterken mogelijk.

https://www.ncsc.nl/nieuws/ncsc-en-oekraiens-ssscip-bundelen-krachten-om-digitale-weerbaarheid-te-versterken


Meerdere kwetsbaarheden in Apple macOS Tahoe

  Pagina openen
Er zijn diverse kwetsbaarheden gevonden in Apple macOS Tahoe, waaronder CVE-2026-65346 met een hoge CVSS-score van 8.8. Deze kwetsbaarheden betreffen geheugenbeheer en verwerking van webcontent wat kan leiden tot systeemcrashes of het lekken van gevoelige informatie. Het NCSC beoordeelt de kans op misbruik als 'medium' en de mogelijke schade als 'hoog'. Installeer de update van Apple om de risico's te beperken.

https://www.ncsc.nl/alerts/meerdere-kwetsbaarheden-in-apple-macos-tahoe


NIST Cybersecurity

https://www.nist.gov

wid.cert-bund.de

https://wid.cert-bund.de






cert.ssi.gouv.fr

https://www.cert.ssi.gouv.fr






theHackerNews

https://thehackernews.com

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

  Pagina openen
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).&

https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html


Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

  Pagina openen
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka

https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html


NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

  Pagina openen
Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process. In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-based phishing platform that

https://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html


CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

  Pagina openen
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes. Both organizations were fully compromised at the domain level, and in both, the red team also

https://thehackernews.com/2026/08/cisa-red-team-compromised-two-critical.html


Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

  Pagina openen
The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed player

https://thehackernews.com/2026/08/unpatched-kaltura-mwembed-flaws-could.html


Techrepublic

https://techrepublic.com/topic/security






BleepingComputer.com

https://www.bleepingcomputer.com/






securityboulevard.com

https://securityboulevard.com

CXSecurity.com

https://cxsecurity.com/






Brian Krebs

https://krebsonsecurity.com

Who’s Tracking You? Use This New Service to Find Out

  Pagina openen
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/



Canadian Man Pleads Guilty in Snowflake Extortions

  Pagina openen
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.

https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/


Read This Before You Buy That TV Streaming Stick

  Pagina openen
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/


LG to Ban Residential Proxies from Smart TV Apps

  Pagina openen
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV.

https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/


Troy Hunt

https://www.troyhunt.com

A Cautionary Tale About Data Breach Claims, Verification and Carhartt

  Pagina openen

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it all starts here:

🚨Cyber

https://www.troyhunt.com/a-cautionary-tale-about-data-breach-claims-verification-and-carhartt/


Weekly Update 518: IoT Doorlock Nirvana with UniFi

  Pagina openen

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I genuinely think I've nailed the IoT door lock situation! Well, Ubiquiti has, but I think I've worked out how to put it all into a residential house and have it make sense. There are a few basic tenets:

  1. Main power (never have to rely on

https://www.troyhunt.com/weekly-update-518/


Welcoming the Sri Lankan Government to Have I Been Pwned

  Pagina openen

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Today, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri Lanka. Sri Lanka CERT now has access to monitor Sri Lankan government domains against the data in HIBP, helping identify exposed government accounts and respond when they appear in new data breaches.

https://www.troyhunt.com/welcoming-the-sri-lankan-government-to-have-i-been-pwned/



Weekly Update 516: Live From Vietnam

  Pagina openen

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back to business, it's the Brinks Home FAQ I found most interesting this week. I mean, how do you write your own FAQ then fail to

https://www.troyhunt.com/weekly-update-516/


Bruce Schneier

https://www.schneier.com

Spyware for Babies

  Pagina openen

The New York Times has a long article (alt link) on surveillance systems aimed at babies. They are increasingly using AI.

Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonishing levels of baby data collection are just the beginning. Nanit recently raised $50 million from investors to expand its use of A.I. and use its camera to track speech and language development, motor skills and more, while extending its presence in children’s bedrooms into early adolescence.

https://www.schneier.com/blog/archives/2026/08/spyware-for-babies.html


Black Hat State of Security Vendors

  Pagina openen

Andy Ellis has a roundup of the security vendors at Black Hat this year.

Key Takeaways: We have entered into an AI world. While nearly half of booths didn’t directly mention AI or agents in their taglines, the effects of AI are everywhere. Multiple spaces (Identity, SaaS, AppSec, Data) have almost every vendor leading with AI; existing unsolved problem areas just got worse.

At the same time, there’s a clear trichotomy in the market: tools that tell you how bad things are; tools that stop adversaries, and tools that prevent problems from occurring. While you’d suspect that the tools that fix things would dominate, the tools that merely tell you how bad things are seem to be frustratingly plentiful...

https://www.schneier.com/blog/archives/2026/08/black-hat-state-of-security-vendors.html


Criminal Deception in Silicon Valley

  Pagina openen

Interesting paper:

Abstract: With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out criminal deception, employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley ventures and their founders prosecuted for fraud between 2000 and 2023, our findings reveal that entrepreneurs carry out criminal deception through a process of façading: Entrepreneurs construct, perform, and protect illusory appearances (façades) that externally project high-growth performance to audiences while masking ventures’ actual underperformance. We identify three forms of façading—­surface, reinforced, and deep façading­—that are contingent on the severity of the gap that entrepreneurs face between audiences’ performance expectations and ventures’ performance reality. Our theoretical framework captures how entrepreneurs facing minor, wide, and extreme expectation-reality gaps engage in evermore sophisticated efforts to detach the venture’s externally projected appearance from its actual operational reality. Practically, we propose several approaches to deter and detect criminal deception, including the extension of U.S. Securities and Exchange Commission surveillance and whistleblower program, investor due diligence reform, and dedicated entrepreneurship education interventions that clearly demarcate when entrepreneurs transgress into criminal deception. We make contributions to literatures on cultural entrepreneurship, organizational wrongdoing, and the social effects of entrepreneurship. ...

https://www.schneier.com/blog/archives/2026/08/criminal-deception-in-silicon-valley.html


Friday Squid Blogging: Neon Flying Squid

  Pagina openen

The neon flying squid can fly in formation.

The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion.

They were probably neon flying squid (Ommastrephes bartramii), the subsequent study states, a species that is part of a 20-strong flying squid family that was known to leap from the water but, until then, was only rumoured to also be able to glide above it...

https://www.schneier.com/blog/archives/2026/08/friday-squid-blogging-neon-flying-squid.html


AI Is Learning to Write Genetic Code

  Pagina openen

This sort of research is both exciting and terrifying:

The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside.

Using an existing bacteriophage as an example—ΦX174 (pronounced “fie-ex-1-7-4”), known for its ability to infect and destroy E. coli bacteria—the models generated about 700,000 potential designs, of which the researchers picked 285 that looked most promising.

The researchers then synthesised new DNA molecules using those designs and inserted them into E. coli bacteria, before waiting to see if viable bacteriophages would emerge...

https://www.schneier.com/blog/archives/2026/08/ai-is-learning-to-write-genetic-code.html


Security Affairs

https://securityaffairs.co

FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure

  Pagina openen
FBI seizes QScan and QTRouter, China-linked platforms used to hide intrusions and target U.S. critical infrastructure. The U.S. Department of Justice and the FBI have seized two platforms, QScan and QTRouter, used by a China-linked group to hide cyberattacks and target critical infrastructure. The operation matters because it shows how state-backed actors no longer need [...]

https://securityaffairs.com/197873/apt/fbi-seizes-china-linked-hacking-platforms-qscan-and-qtrouter-used-against-critical-infrastructure.html


U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog

  Pagina openen
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-60004 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Gitea is an open-source platform for [...]

https://securityaffairs.com/197854/security/u-s-cisa-adds-gitea-flaw-to-its-known-exploited-vulnerabilities-catalog.html


88 ID Verification Breaches Show the Cost of Collecting Identity Data

  Pagina openen
88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data. A new report from Mysterium VPN compiles 88 documented incidents since 2011 where data collected specifically to verify someone’s identity or age got breached, exposed, or sold. The confirmed and researcher-verified total sits at 2.15 billion records, [...]

https://securityaffairs.com/197855/reports/88-id-verification-breaches-show-the-cost-of-collecting-identity-data.html


WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion

  Pagina openen
WhatsApp says 1 billion users now use passkeys, while stronger two-step verification and caller context add new layers of account protection. WhatsApp has reached a significant security milestone: more than one billion people now use passkeys to protect access to their accounts. At the same time, Meta is adding stronger two-step verification and more information [...]

https://securityaffairs.com/197837/security/whatsapp-adds-stronger-security-as-passkeys-hit-1-billion.html


Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams

  Pagina openen
INTERPOL’s Operation Jackal IV made 58 arrests and exposed global networks laundering money from scams, fraud and sextortion. INTERPOL announced that Operation Jackal IV, running from November 2025 to June 2026, led to 58 arrests and identified 263 suspects tied to West African organized crime networks, groups like Black Axe that are responsible for a [...]

https://securityaffairs.com/197843/cyber-crime/operation-jackal-58-arrests-expose-the-money-laundering-machine-behind-global-scams.html


news.sophos.com

https://news.sophos.com