Tech nieuws

IT

SlashDot.org

https://slashdot.org

Sainsbury's Store Pauses Facial Recognition After False Shoplifting Claim

  Pagina openen
Bruce66423 shares a report from The Guardian: Sainsbury's has paused the use of AI face scanning in one of its stores after a customer was wrongly identified as a shoplifter and ejected from the shop. "I was embarrassed, mortified even, and felt quite humiliated and powerless," Matt Arnold, 46, said of his ordeal. The comedy promoter was buying supplies in the store in East Dulwich, in south-east London, for a standup event at Dulwich Hamlet football club when, after scanning his items and a Nectar card, he was approached by two managers who told him he could not be served owing to an earlier incident. He was then asked to leave and they tried to escort him from the store. As he left, he saw an overhead CCTV monitor alert with a red circle surrounding his face. He asked the shop staff to keep his shopping in the trolley so his friend could come and pick up the supplies for the comedy night happening soon next door. "I think they were quite confused by this, understandably, but agreed and my colleague Dave went in to pay for and pick up the shop about five minutes later. There was no pause for thought from the staff, no suggestion that they understood this is not how a shoplifter would behave. Just blindly following the machine's orders." Sainsbury's head office apologised to Arnold the next day and has paused use of its AI-assisted Facewatch technology in the store while an investigation takes place. Arnold says the facial recognition tech should be paused in all stores. "Anyone could be falsely accused and at some point that will be someone vulnerable, someone with mental health issues like anxiety. It's inevitable," said Arnold. "Also, I would worry about the confidence-destroying effect of it happening to a younger person or someone less willing or able to stand up for themselves as I have done." A Sainsbury's spokesperson said: "We have contacted Mr Arnold to apologise for his experience at our Dulwich superstore. The incident was caused by human error, not the facial recognition technology. Customers can be reassured that the Facewatch system has a 99.98% accuracy rate, and every match is reviewed by a trained manager." A Facewatch spokesperson said their technology was not at fault in this case. "A correct alert was sent to the retailer, but was subsequently subject to human error in the way it was handled in store," they said.

Read more of this story at Slashdot.

https://yro.slashdot.org/story/26/08/18/0742229/sainsburys-store-pauses-facial-recognition-after-false-shoplifting-claim?utm_source=rss1.0mainlinkanon&utm_medium=feed


Solar Power and Batteries Have Been Keeping Europe's Grid Stable

  Pagina openen
AleRunner writes: "Solar has been doing the 'heavy lifting' to help Europe meet its energy needs amid a string of blistering heatwaves," Euronews tells us. Meanwhile, as Europe's energy demands rise with the heat, jellyfish have been causing shutdowns and reduced power output at multiple reactors at French nuclear plants, as we already discussed. Euronews reports: A new analysis from energy think-tank Ember found that solar output in European countries rose by up to 17 percent on heatwave days in June and July. Researchers say that this helped power the grid as electricity demand increased by as much as a quarter on hot days. Heatwaves often trigger a spike in electricity consumption due to the sudden need for cooling, mainly from energy-intensive air conditioning (A/C) units. The International Energy Agency (IEA) estimates that space cooling, which is mostly A/C units and fans, consumed around seven percent of the world's electricity in 2022. Even in countries where A/C ownership is low, countries experience energy demand spikes when scorching temperatures hit. During the early summer heatwaves of 2025, France, for example, recorded an evening electricity peak that was 25 percent above the off-season average due to air conditioning. Ember's analysis found that during the late-June heatwave this summer, daily electricity demand rose byup to 28 percent in Italy, 23 percent in Hungary, 14 percent in France and 13 percent in Spain compared with pre-heatwave days. It says as heatwave-driven demand increased, solar was the only major power source to perform "better than usual." Compared with other days in June and July, average daily solar generation during the heatwaves was 17 percent higher in France and Hungary, five percent higher in Spain and the same in Italy.

Read more of this story at Slashdot.

https://hardware.slashdot.org/story/26/08/18/0728240/solar-power-and-batteries-have-been-keeping-europes-grid-stable?utm_source=rss1.0mainlinkanon&utm_medium=feed


'Buy Now, Pay Later' Lenders Pitch Loans For Needs Like Electricity and Rent

  Pagina openen
An anonymous reader quotes a report from The New York Times: Buy now, pay later" loans took off during the pandemic as a way for online shoppers to go on retail splurges without using a credit card. Now, lenders are offering the loans as a means for people to finance basic households needs. The lending apps Flex and Zip allow customers to take out loans to pay for their broadband, electricity, health insurance, mobile phone service, mortgage and water bills. Affirm, one of the most popular pay-later apps, has started providing some tenants loans to extend their monthly rent payment for a few weeks. Many dentists, veterinarians and medical clinics now often offer instant pay-later financing, and Intuit this year started promoting "File Now, Pay Later" loans to TurboTax users who owe money in their tax return. Pay-later loans are becoming the "working capital for the modern middle class," said Karen Webster, the chief executive of Pymnts, a news and market research company for the payments industry. "Consumers are using it more for essential, everyday things." Americans spent $160 billion last year through pay-later loans, according to research released recently by Federal Reserve economists -- nearly twice what consumers spent two years earlier, in 2023. That's still a fraction of the more than $3 trillion U.S. shoppers spend annually on consumer credit cards. But the industry continues to expand by double-digit rates each year. How much of that growth reflects consumer preferences, versus desperation, is a question economists and industry analysts are trying to unravel. The rise in pay-later financing comes as many households are leaning more on debt to keep up with their daily expenses. Paying interest -- to afford basic needs -- adds to the overall cost of living, which has already been rising amid higher medical, housing and fuel costs. For many borrowers, the loans have become their only option: Half of those using them said they could not make ends meet otherwise, according to the latest edition of a survey that LendingTree, a loan marketplace, has compiled for years.

Read more of this story at Slashdot.

https://news.slashdot.org/story/26/08/17/2254201/buy-now-pay-later-lenders-pitch-loans-for-needs-like-electricity-and-rent?utm_source=rss1.0mainlinkanon&utm_medium=feed


Supreme Court Rejects Verizon Bid For $47 Million Refund of FCC Fine

  Pagina openen
An anonymous reader quotes a report from Ars Technica: The Supreme Court today rejected Verizon's attempt to get a $47 million refund from the Federal Communications Commission. In a list of orders (PDF) issued by the court, Verizon's petition was denied without explanation. The denial apparently ends any possibility of Verizon asking a lower court to review the fine and order the FCC to issue a refund. However, AT&T and T-Mobile are continuing to challenge similar fines on grounds that selling device-location data did not violate US telecom law. AT&T, T-Mobile, and Verizon were fined a total of $196 million in 2024 for selling mobile users' real-time location data without their customers' consent. The carriers sold device-location information to data aggregators, who resold it to other firms. The carriers paid the fines and sought to have them overturned in courts, claiming their Seventh Amendment right to a jury trial was violated. Challenges by AT&T and Verizon were combined into a single case, and the Supreme Court ruled against the carriers in June of this year. The court ruled that the FCC penalty process does not violate the Seventh Amendment because the carriers could have obtained jury trials if they refused to pay the fines and waited for the government to try to collect. The ruling (PDF) against the carriers was 8-1, with Justice Clarence Thomas dissenting.

Read more of this story at Slashdot.

https://yro.slashdot.org/story/26/08/17/223241/supreme-court-rejects-verizon-bid-for-47-million-refund-of-fcc-fine?utm_source=rss1.0mainlinkanon&utm_medium=feed


Apple Wallet Driver's License Feature to Launch in Four More US States

  Pagina openen
Apple Wallet's driver's license and state ID feature is set to expand to North Carolina, Oklahoma, Utah, and Virginia, bringing the total to 18 states plus Puerto Rico. The digital IDs can be used at participating TSA checkpoints and businesses without handing over or unlocking an iPhone, though users are still generally advised to carry a physical ID because acceptance remains limited. MacRumors reports: A few days ago, North Carolina's DMV announced that it plans to launch a mobile ID program later this year. As reported by WRAL, North Carolina residents will be able to set up a digital ID through a new NC Wallet app starting in December, with Apple Wallet, Google Wallet, and Samsung Wallet support to follow in "early 2027." As mentioned, you do not need to unlock, show, or hand over your device to present an Apple Wallet ID in person, ensuring user privacy. Apple Wallet IDs are generally not accepted by law enforcement, so carrying a physical ID is still legally required for traffic stops. In addition, the number of businesses that accept Apple Wallet IDs is still quite small. At least for now, Apple Wallet IDs are designed to be a convenient alternative where they are accepted. "Your mobile ID is a valid form of identification in North Carolina," the DMV said, in a FAQ on its website. "However, as retailers, restaurants and other businesses transition to mobile IDs, some may not be set up to accept them right away. For now, carrying your physical card gives you a backup when needed." According to code seen by MacRumors, Apple Wallet IDs are also coming to Oklahoma, Utah, and Virginia, but there is no timeframe for availability.

Read more of this story at Slashdot.

https://apple.slashdot.org/story/26/08/17/2157231/apple-wallet-drivers-license-feature-to-launch-in-four-more-us-states?utm_source=rss1.0mainlinkanon&utm_medium=feed


Techcrunch.com

https://techcrunch.com/






Cnet.com

https://www.cnet.com






Arstechnica.com

https://arstechnica.com






Wired.com

https://www.wired.com






ZDNet.com

https://www.zdnet.com






TechRepublic.com

https://www.techrepublic.com






mashable.com

https://mashable.com/tech

Samsung Galaxy Z Fold 8 Ultra Review: A Brilliant Foldable With An Expensive Proposition

  Pagina openen
The Galaxy Z Fold 8 Ultra is Samsung’s most polished foldable yet, but at ₹1,99,999, its huge inner screen has to be more than just a novelty. The Galaxy Z Fold 8 Ultra is Samsung’s most ambitious foldable yet, but at nearly ₹2 lakh, its brilliant inner screen has to be more than a party trick.

https://in.mashable.com/tech/112991/samsung-galaxy-z-fold-8-ultra-review-a-brilliant-foldable-with-an-expensive-proposition


Samsung Announces Galaxy Forever Programme for Z Fold 8 Series: What Are the Price and Benefits?

  Pagina openen
Samsung Galaxy Forever programme offers Galaxy Z Fold 8 buyers 24-month no-cost EMI, Care+ and up to 55% buyback value. Samsung’s Galaxy Forever programme offers Z Fold 8 buyers no-cost EMI, Care+ protection and up to 55% assured buyback value.

https://in.mashable.com/tech/112988/samsung-announces-galaxy-forever-programme-for-z-fold-8-series-what-are-the-price-and-benefits


Samsung May Launch 5 Foldable Phones Next Year, Including Galaxy Z TriFold 2: What to Expect?

  Pagina openen
Citing industry sources, an ETNews report indicates that Samsung plans to launch five foldable smartphones in 2027. The lineup will reportedly feature the Galaxy Z Fold 9, Galaxy Z Fold 9 Ultra, Galaxy Z Flip 9, Galaxy Z TriFold 2, and a new wide-folding model in the Z Fold 9 series. Samsung is reportedly planning to release five new foldable smartphones next year. The upcoming lineup will feature direct successors to the recently introduced trio of Galaxy Z devices. Additionally, the expanded roster is expected to introduce a second-generation tri-fold phone alongside a new wide-screen model optimized for video viewing.

https://in.mashable.com/tech/112987/samsung-may-launch-5-foldable-phones-next-year-including-galaxy-z-trifold-2-what-to-expect


Realme 16 Pro+ Gets Rs 4,000 Price Hike: Check Updated Prices Of Realme 16, Realme 16T And More

  Pagina openen
Realme has raised prices of select 16-series and C-series smartphones in India, with hikes varying by model and storage variant. Realme has increased prices of several 16-series and C-series smartphones in India, following recent hikes from other major brands.

https://in.mashable.com/tech/112980/realme-16-pro-gets-rs-4000-price-hike-check-updated-prices-of-realme-16-realme-16t-and-more


How To Get Kernel Hearts Fernet Skin In Fortnite For Free? Step-By-Step Guide

  Pagina openen
Kernel Hearts is set to launch on PC via the Epic Games Store and Steam, Nintendo Switch 2, PS5, and Xbox Series X/S on September 17, 2026. The trailer also confirms an exclusive Fortnite skin as a pre-order bonus for players who purchase the game through the Epic Games Store. Fans of Kernel Hearts have good news, as Fortnite players can unlock the Fernet skin through a special crossover promotion. The outfit can be claimed as a bonus by purchasing the game through the Epic Games Store.

https://in.mashable.com/tech/112979/how-to-get-kernel-hearts-fernet-skin-in-fortnite-for-free-step-by-step-guide


Geekwire.com

https://www.geekwire.com

How an AirTag planted by a reporter led to a secret Amazon site where old books are cut apart and scanned

  Pagina openen

404 Media put an Apple AirTag in a rare book and tracked it to an Amazon warehouse in Las Vegas, where a team cuts the bindings off books and scans the pages. The reporting method has roots in a Seattle non-profit group. Read More

https://www.geekwire.com/2026/how-an-airtag-planted-by-a-reporter-led-to-a-secret-amazon-site-where-old-books-are-cut-apart-and-scanned/



From engineering to elected office: How a generation of Indian Americans is reshaping civic life

  Pagina openen

India's 80th Independence Day drew a governor's proclamation, declarations from four mayors, and a line around the block. Harini Gokul, who came to the U.S. as an engineer and now serves on the Medina City Council, explains how the same talent pool that filled engineering teams has risen to CEO offices and council seats. Read More

https://www.geekwire.com/2026/from-engineering-to-elected-office-how-a-generation-of-indian-americans-is-reshaping-civic-life/


GitHub outage disrupts developers worldwide in latest setback for Microsoft coding platform

  Pagina openen

GitHub was down for more than three hours Monday morning, breaking the website, code review tools, automated build systems and Copilot. It's the latest reliability problem for a platform whose capacity planning has been outrun by AI coding tools. Read More

https://www.geekwire.com/2026/github-outage-disrupts-developers-worldwide-in-latest-setback-for-microsoft-coding-platform/


Protesters dressed as rogue AI agents target OpenAI in Bellevue with balloons and hot pink vests

  Pagina openen

A national campaign against AI expansion made its Seattle-area stop Friday at OpenAI's Bellevue office, where demonstrators in hot pink "AI agent" vests entered the lobby with balloons and a chorus of "Happy Rogue Day to OpenAI." The protest drew national attention. Read More

https://www.geekwire.com/2026/protesters-dressed-as-rogue-ai-agents-target-openai-in-bellevue-with-balloons-and-hot-pink-vests/


Latest from TechRadar

https://www.techradar.com






Cybersecurity

Security.nl

https://www.security.nl






Slashdot

https://slashdot.org/

Sainsbury's Store Pauses Facial Recognition After False Shoplifting Claim

  Pagina openen
Bruce66423 shares a report from The Guardian: Sainsbury's has paused the use of AI face scanning in one of its stores after a customer was wrongly identified as a shoplifter and ejected from the shop. "I was embarrassed, mortified even, and felt quite humiliated and powerless," Matt Arnold, 46, said of his ordeal. The comedy promoter was buying supplies in the store in East Dulwich, in south-east London, for a standup event at Dulwich Hamlet football club when, after scanning his items and a Nectar card, he was approached by two managers who told him he could not be served owing to an earlier incident. He was then asked to leave and they tried to escort him from the store. As he left, he saw an overhead CCTV monitor alert with a red circle surrounding his face. He asked the shop staff to keep his shopping in the trolley so his friend could come and pick up the supplies for the comedy night happening soon next door. "I think they were quite confused by this, understandably, but agreed and my colleague Dave went in to pay for and pick up the shop about five minutes later. There was no pause for thought from the staff, no suggestion that they understood this is not how a shoplifter would behave. Just blindly following the machine's orders." Sainsbury's head office apologised to Arnold the next day and has paused use of its AI-assisted Facewatch technology in the store while an investigation takes place. Arnold says the facial recognition tech should be paused in all stores. "Anyone could be falsely accused and at some point that will be someone vulnerable, someone with mental health issues like anxiety. It's inevitable," said Arnold. "Also, I would worry about the confidence-destroying effect of it happening to a younger person or someone less willing or able to stand up for themselves as I have done." A Sainsbury's spokesperson said: "We have contacted Mr Arnold to apologise for his experience at our Dulwich superstore. The incident was caused by human error, not the facial recognition technology. Customers can be reassured that the Facewatch system has a 99.98% accuracy rate, and every match is reviewed by a trained manager." A Facewatch spokesperson said their technology was not at fault in this case. "A correct alert was sent to the retailer, but was subsequently subject to human error in the way it was handled in store," they said.

Read more of this story at Slashdot.

https://yro.slashdot.org/story/26/08/18/0742229/sainsburys-store-pauses-facial-recognition-after-false-shoplifting-claim?utm_source=rss1.0mainlinkanon&utm_medium=feed


Solar Power and Batteries Have Been Keeping Europe's Grid Stable

  Pagina openen
AleRunner writes: "Solar has been doing the 'heavy lifting' to help Europe meet its energy needs amid a string of blistering heatwaves," Euronews tells us. Meanwhile, as Europe's energy demands rise with the heat, jellyfish have been causing shutdowns and reduced power output at multiple reactors at French nuclear plants, as we already discussed. Euronews reports: A new analysis from energy think-tank Ember found that solar output in European countries rose by up to 17 percent on heatwave days in June and July. Researchers say that this helped power the grid as electricity demand increased by as much as a quarter on hot days. Heatwaves often trigger a spike in electricity consumption due to the sudden need for cooling, mainly from energy-intensive air conditioning (A/C) units. The International Energy Agency (IEA) estimates that space cooling, which is mostly A/C units and fans, consumed around seven percent of the world's electricity in 2022. Even in countries where A/C ownership is low, countries experience energy demand spikes when scorching temperatures hit. During the early summer heatwaves of 2025, France, for example, recorded an evening electricity peak that was 25 percent above the off-season average due to air conditioning. Ember's analysis found that during the late-June heatwave this summer, daily electricity demand rose byup to 28 percent in Italy, 23 percent in Hungary, 14 percent in France and 13 percent in Spain compared with pre-heatwave days. It says as heatwave-driven demand increased, solar was the only major power source to perform "better than usual." Compared with other days in June and July, average daily solar generation during the heatwaves was 17 percent higher in France and Hungary, five percent higher in Spain and the same in Italy.

Read more of this story at Slashdot.

https://hardware.slashdot.org/story/26/08/18/0728240/solar-power-and-batteries-have-been-keeping-europes-grid-stable?utm_source=rss1.0mainlinkanon&utm_medium=feed


'Buy Now, Pay Later' Lenders Pitch Loans For Needs Like Electricity and Rent

  Pagina openen
An anonymous reader quotes a report from The New York Times: Buy now, pay later" loans took off during the pandemic as a way for online shoppers to go on retail splurges without using a credit card. Now, lenders are offering the loans as a means for people to finance basic households needs. The lending apps Flex and Zip allow customers to take out loans to pay for their broadband, electricity, health insurance, mobile phone service, mortgage and water bills. Affirm, one of the most popular pay-later apps, has started providing some tenants loans to extend their monthly rent payment for a few weeks. Many dentists, veterinarians and medical clinics now often offer instant pay-later financing, and Intuit this year started promoting "File Now, Pay Later" loans to TurboTax users who owe money in their tax return. Pay-later loans are becoming the "working capital for the modern middle class," said Karen Webster, the chief executive of Pymnts, a news and market research company for the payments industry. "Consumers are using it more for essential, everyday things." Americans spent $160 billion last year through pay-later loans, according to research released recently by Federal Reserve economists -- nearly twice what consumers spent two years earlier, in 2023. That's still a fraction of the more than $3 trillion U.S. shoppers spend annually on consumer credit cards. But the industry continues to expand by double-digit rates each year. How much of that growth reflects consumer preferences, versus desperation, is a question economists and industry analysts are trying to unravel. The rise in pay-later financing comes as many households are leaning more on debt to keep up with their daily expenses. Paying interest -- to afford basic needs -- adds to the overall cost of living, which has already been rising amid higher medical, housing and fuel costs. For many borrowers, the loans have become their only option: Half of those using them said they could not make ends meet otherwise, according to the latest edition of a survey that LendingTree, a loan marketplace, has compiled for years.

Read more of this story at Slashdot.

https://news.slashdot.org/story/26/08/17/2254201/buy-now-pay-later-lenders-pitch-loans-for-needs-like-electricity-and-rent?utm_source=rss1.0mainlinkanon&utm_medium=feed


Supreme Court Rejects Verizon Bid For $47 Million Refund of FCC Fine

  Pagina openen
An anonymous reader quotes a report from Ars Technica: The Supreme Court today rejected Verizon's attempt to get a $47 million refund from the Federal Communications Commission. In a list of orders (PDF) issued by the court, Verizon's petition was denied without explanation. The denial apparently ends any possibility of Verizon asking a lower court to review the fine and order the FCC to issue a refund. However, AT&T and T-Mobile are continuing to challenge similar fines on grounds that selling device-location data did not violate US telecom law. AT&T, T-Mobile, and Verizon were fined a total of $196 million in 2024 for selling mobile users' real-time location data without their customers' consent. The carriers sold device-location information to data aggregators, who resold it to other firms. The carriers paid the fines and sought to have them overturned in courts, claiming their Seventh Amendment right to a jury trial was violated. Challenges by AT&T and Verizon were combined into a single case, and the Supreme Court ruled against the carriers in June of this year. The court ruled that the FCC penalty process does not violate the Seventh Amendment because the carriers could have obtained jury trials if they refused to pay the fines and waited for the government to try to collect. The ruling (PDF) against the carriers was 8-1, with Justice Clarence Thomas dissenting.

Read more of this story at Slashdot.

https://yro.slashdot.org/story/26/08/17/223241/supreme-court-rejects-verizon-bid-for-47-million-refund-of-fcc-fine?utm_source=rss1.0mainlinkanon&utm_medium=feed


Apple Wallet Driver's License Feature to Launch in Four More US States

  Pagina openen
Apple Wallet's driver's license and state ID feature is set to expand to North Carolina, Oklahoma, Utah, and Virginia, bringing the total to 18 states plus Puerto Rico. The digital IDs can be used at participating TSA checkpoints and businesses without handing over or unlocking an iPhone, though users are still generally advised to carry a physical ID because acceptance remains limited. MacRumors reports: A few days ago, North Carolina's DMV announced that it plans to launch a mobile ID program later this year. As reported by WRAL, North Carolina residents will be able to set up a digital ID through a new NC Wallet app starting in December, with Apple Wallet, Google Wallet, and Samsung Wallet support to follow in "early 2027." As mentioned, you do not need to unlock, show, or hand over your device to present an Apple Wallet ID in person, ensuring user privacy. Apple Wallet IDs are generally not accepted by law enforcement, so carrying a physical ID is still legally required for traffic stops. In addition, the number of businesses that accept Apple Wallet IDs is still quite small. At least for now, Apple Wallet IDs are designed to be a convenient alternative where they are accepted. "Your mobile ID is a valid form of identification in North Carolina," the DMV said, in a FAQ on its website. "However, as retailers, restaurants and other businesses transition to mobile IDs, some may not be set up to accept them right away. For now, carrying your physical card gives you a backup when needed." According to code seen by MacRumors, Apple Wallet IDs are also coming to Oklahoma, Utah, and Virginia, but there is no timeframe for availability.

Read more of this story at Slashdot.

https://apple.slashdot.org/story/26/08/17/2157231/apple-wallet-drivers-license-feature-to-launch-in-four-more-us-states?utm_source=rss1.0mainlinkanon&utm_medium=feed


theregister.com/security

https://www.theregister.com/security






CISO2CISO.com

https://ciso2ciso.com

Vuldb

https://vuldb.com

CVE-2026-24301 | Microsoft Copilot command injection

  Pagina openen
A vulnerability was found in Microsoft Copilot. It has been declared as critical. This impacts an unknown function. Executing a manipulation can lead to command injection. This vulnerability is tracked as CVE-2026-24301. The attack can be launched remotely. No exploit exists. This product is a managed service. It is not possible for users to maintain vulnerability countermeasures themselves.

https://vuldb.com/vuln/391643


CVE-2026-75874 | Mozilla Firefox up to 153 Remote Settings Client sandbox

  Pagina openen
A vulnerability was found in Mozilla Firefox up to 153. It has been classified as critical. This affects an unknown function of the component Remote Settings Client. Performing a manipulation results in sandbox issue. This vulnerability is identified as CVE-2026-75874. The attack can be initiated remotely. There is not any exploit available. Upgrading the affected component is recommended.

https://vuldb.com/vuln/391642


CVE-2026-74990 | Mozilla Firefox up to 115.38/140.13/153/153.0 memory corruption

  Pagina openen
A vulnerability was found in Mozilla Firefox up to 115.38/140.13/153/153.0 and classified as critical. The impacted element is an unknown function. Such manipulation leads to memory corruption. This vulnerability is referenced as CVE-2026-74990. It is possible to launch the attack remotely. No exploit is available. It is suggested to upgrade the affected component.

https://vuldb.com/vuln/391641


CVE-2026-74980 | Mozilla Firefox up to 153 Downloads clickjacking

  Pagina openen
A vulnerability has been found in Mozilla Firefox up to 153 and classified as problematic. The affected element is an unknown function of the component Downloads. This manipulation causes clickjacking. The identification of this vulnerability is CVE-2026-74980. It is possible to initiate the attack remotely. There is no exploit available. The affected component should be upgraded.

https://vuldb.com/vuln/391640



advisories.ncsc.nl

https://advisories.ncsc.nl/

NCSC-2026-0216 [1.01] [M/H] Kwetsbaarheden verholpen in Citrix Netscaler ADC en Netscaler Gateway

  Pagina openen
Citrix heeft kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway die verband houden met onvoldoende invoervalidatie, onjuiste toegangscontrole en het onjuist vrijgeven van geheugen. De kwetsbaarheden met de kenmerken CVE-2026-8451 en CVE-2026-10817 ontstaan door onvoldoende invoervalidatie, waarbij de software invoergroottes en -grenzen niet correct controleert. Dit kan leiden tot geheugenoverlezingen, wat kan resulteren in ongeautoriseerde openbaarmaking van gevoelige informatie, wanneer de producten zijn geconfigureerd als SAML IDP, of als TCP TimeStamp is ingeschakeld bij een TCP-profiel dat is gekoppeld aan een virtuele server van het type: Load Balancing (LB), Content Switching (CS) of VPN. De kwetsbaarheden met de kenmerken CVE-2026-8452 en CVE-2026-8655 bevinden zich in de manier waarop geheugen wordt beheerd in NetScaler ADC en NetScaler Gateway. Dit kan leiden tot een denial-of-service (DoS) of een ongewenste control flow wanneer de producten zijn geconfigureerd als Gateway, DNS-proxy, recursieve DNS-resolver of AAA-virtuele server. De kwetsbaarheid met het kenmerk CVE-2026-13474 ontstaat door het onjuist vrijgeven van geheugen. Kwaadwillenden kunnen deze kwetsbaarheid misbruiken door via speciaal geprepareerde HTTP/2-verzoeken een denial-of-service (DoS) te veroorzaken. De kwetsbaarheid met het kenmerk CVE-2026-10816 betreft een probleem met de toegangscontrole binnen de Management Interface. Niet-geauthenticeerde kwaadwillenden op afstand kunnen de kwetsbaarheid misbruiken om willekeurige bestanden uit te lezen. Dit kan resulteren in ongeautoriseerde openbaarmaking van gevoelige informatie. Onderzoekers hebben Proof-of-Concept (PoC) code gedeeld waarmee de kwetsbaarheid met kenmerk CVE-2026-8451 kan worden aangetoond. **UPDATE:** Inmiddels hebben dezelfde onderzoekers ook Proof-of-Concept (PoC) code gepubliceerd waarmee uitvoer van willekeurige code mogelijk wordt. Het kwetsbare systeem moet hiervoor wel zijn geconfigureerd om middels SAML ingezet te zijn als Identity Provider. Dit is geen gebruikelijke configuratie, omdat best practices adviseren het Identity Management en Access Management gescheiden te houden.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0216


NCSC-2026-0304 [1.00] [M/H] ZeroDay Kwetsbaarheid verholpen in GeoTools door OpenGeo

  Pagina openen
GeoTools, een veelgebruikte open source Java-bibliotheek voor geospatiale data, heeft updates uitgebracht om ZeroDay SQL-injectie kwetsbaarheid te verhelpen in de uitvoering van OGC Filterfuncties bij gebruik met JDBCDataStore en andere datastores. De genoemde kwetsbaarheid is een oudere kwetsbaarheid, waarvan recentelijk is gebleken dat deze niet adequaat is verholpen. De kwetsbaarheid stelde een kwaadwillende in staat om willekeurige SQL-code uit te voeren in de onderliggende database. De ZeroDay kwetsbaarheid bevindt zich in meerdere OGC Filterfuncties die SQL-injectie mogelijk maken bij gebruik met verschillende datastore-implementaties zoals PostGIS. Hierdoor kan een aanvaller via deze functies kwaadaardige SQL-code injecteren. De kwetsbaarheden zijn aanwezig in meerdere versies van GeoTools. Als gedeeltelijke mitigatie kunnen encode-functies worden uitgeschakeld en prepared statements worden ingeschakeld om de blootstelling te verminderen. Indien de onderliggende database draait onder verhoogde rechten, is het mogelijk om via deze kwetsbaarheid willekeurige code uit te voeren op de server, waardoor naast ongeautoriseerde database-manipulatie, ook een system take-over mogelijk kan zijn. Onderzoekers hebben meldingen ontvangen dat kwaadwillenden de nieuwe ZeroDay onder de aandacht hebben en nemen een verhoging waar in scan- en misbruikverkeer. Op dit moment is van grootschalige ongeautoriseerde toegang of daadwerkelijk misbruik nog geen sprake. Voor deze nieuwe ZeroDay kwetsbaarheid is (nog) geen CVE-id bekend gesteld.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0304


NCSC-2026-0303 [1.00] [M/H] Kwetsbaarheden verholpen in GitLab door GitLab Inc.

  Pagina openen
GitLab Inc. heeft kwetsbaarheden verholpen in GitLab Community Edition (CE) en Enterprise Edition (EE). De kwetsbaarheden bevinden zich in de GraphQL-implementatie van GitLab. Een eerste kwetsbaarheid maakte het mogelijk voor niet-geauthenticeerde gebruikers om via een GraphQL-directive ongeautoriseerde wijzigingen of verwijderingen uit te voeren op publieke projecten en gebruikersdata. Een tweede kwetsbaarheid stelde niet-geauthenticeerde gebruikers in staat om mutaties uit te voeren via GET-requests door onjuiste validatie van GraphQL multiplex queries, waarbij mutatie-operaties niet correct werden beperkt. Hierdoor kunnen onbevoegden ongeautoriseerde wijzigingen aanbrengen in de staat van de server.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0303


NCSC-2026-0302 [1.00] [M/H] Kwetsbaarheden verholpen in SAP Commerce Cloud Data Hub Adapter

  Pagina openen
SAP heeft een kwetsbaarheid verholpen in de Data Hub Adapter voor SAP Commerce Cloud. Een ongeauthenticeerde kwaadwillende kan de kwetsbaarheid misbruiken voor het uitvoeren van willekeurige code. Hiertoe dient de kwaadwillende malafide netwerkverkeer naar de Data Hub Adapter te versturen. Beveiligingsbedrijf Defused meldt dat kwaadwillenden actief scannen en op zoek zijn naar kwetsbare Data Hub Adapter-systemen.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0302


NCSC-2026-0301 [1.00] [M/H] Kwetsbaarheden verholpen in IBM i operating system door IBM

  Pagina openen
IBM heeft kwetsbaarheden verholpen in IBM i operating system versies 7.3, 7.4, 7.5 en 7.6. De kwetsbaarheden betreffen meerdere aspecten van het IBM i - operating system, waaronder onjuist privilege management, onbeheerde zoekpadelementen, out-of-bounds reads en writes, buffer overflows (zowel heap- als stackgebaseerd), SQL-injecties, path traversal, TOCTOU-racecondities met symbolische links, onjuiste validatie van omgevingsvariabelen en profielnamen, en onjuiste neutralisatie van speciale elementen in OS-commando's. Aanvallers met geldige authenticatie kunnen deze kwetsbaarheden misbruiken om privileges te escaleren, willekeurige code uit te voeren, toegang te verkrijgen tot gevoelige gegevens, de systeemintegriteit te compromitteren of een denial-of-service te veroorzaken. De kwetsbaarheden zijn aanwezig in meerdere opeenvolgende versies van IBM i waarvoor meerdere updates zijn uitgebracht. Het advies van het NCSC is dan ook om goed te controleren of de in gebruik zijnde versie onder de kwetsbare versies valt.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0301


NCSC Nieuws

https://www.ncsc.nl/actueel

Ernstige kwetsbaarheden in GitLab-producten ontdekt: update nu

  Pagina openen
Er zijn twee kwetsbaarheden gevonden in GitLab Community Edition (CE) en Enterprise Edition (EE), met CVE-2026-19478 (score 9.4) en CVE-2026-19650 (score 7.1). Deze kwetsbaarheden zijn beoordeeld als ernstig en bevinden zich in de GraphQL-onderdelen van GitLab. De kans op misbruik is medium, maar de mogelijke schade is hoog. Het is daarom belangrijk om de updates van GitLab zo snel mogelijk te installeren om misbruik te voorkomen.

https://www.ncsc.nl/alerts/ernstige-kwetsbaarheden-in-gitlab-producten-ontdekt-update-nu


Kritieke SQL-injectie in GeoTools open source Java-bibliotheek: update onmiddellijk

  Pagina openen
Er is een ernstige kwetsbaarheid ontdekt in GeoTools. Deze kwetsbaarheid betreft een ZeroDay SQL-injectie met een hoge CVSS-score van 9.8. Het NCSC beoordeelt de kans op misbruik als medium en de mogelijke schade als hoog. De kwetsbaarheid bevindt zich in meerdere versies van GeoTools en wordt momenteel actief gescand door kwaadwillenden. Het advies is om de door de leverancier uitgebrachte updates zo snel mogelijk te installeren.

https://www.ncsc.nl/alerts/kritieke-sql-injectie-in-geotools-open-source-java-bibliotheek-update-onmiddellijk


Meerdere kwetsbaarheden in Adobe Commerce: update onmiddellijk

  Pagina openen
Er zijn meerdere kwetsbaarheden gevonden in Adobe Commerce, met CVE-nummers zoals CVE-2026-71362 (score 9.1) en andere met scores tussen 2.7 en 8.7. Er is momenteel geen melding van actief misbruik, maar misbruik zou onder andere kunnen leiden tot: het lekken van klant- en bedrijfsgegevens en verstoring van webshop en accounts. Het is daarom belangrijk om de beschikbare updates zo snel mogelijk te installeren om misbruik te voorkomen.

https://www.ncsc.nl/alerts/meerdere-kwetsbaarheden-in-adobe-commerce-update-onmiddellijk




NIST Cybersecurity

https://www.nist.gov

wid.cert-bund.de

https://wid.cert-bund.de

[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff

  Pagina openen
Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, darunter möglicherweise die Ausführung von beliebigem Code, die Offenlegung von Informationen, die Manipulation von Daten oder Denial-of-Service-Zustände.

https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2799






cert.ssi.gouv.fr

https://www.cert.ssi.gouv.fr






theHackerNews

https://thehackernews.com

AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files

  Pagina openen
Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent coding

https://thehackernews.com/2026/08/ai-mind-viruses-can-spread-between.html


TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

  Pagina openen
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services," Ontinue said in a technical report shared with The Hacker News. "Tasking flows through SharePoint Online file

https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.html


One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

  Pagina openen
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has named the City Forum campaign after a domain tied to the attacker's IP address, traces back to one server: 158.220.87.79, hosted on a

https://thehackernews.com/2026/08/one-attacker-has-scraped-both.html


16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

  Pagina openen
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - ubnuler ubnlder ri18nr reaker rakier orakw joxn

https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.html


SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

  Pagina openen
SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet maker said all affected customers were notified individually by email on August 16 from security@safepal.com, with the subject line "[Important] Your SafePal Order

https://thehackernews.com/2026/08/safepal-hardware-wallet-maker-says-flaw.html


Techrepublic

https://techrepublic.com/topic/security






BleepingComputer.com

https://www.bleepingcomputer.com/






securityboulevard.com

https://securityboulevard.com

CXSecurity.com

https://cxsecurity.com/






Brian Krebs

https://krebsonsecurity.com

Who’s Tracking You? Use This New Service to Find Out

  Pagina openen
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/



Canadian Man Pleads Guilty in Snowflake Extortions

  Pagina openen
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.

https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/


Read This Before You Buy That TV Streaming Stick

  Pagina openen
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/


LG to Ban Residential Proxies from Smart TV Apps

  Pagina openen
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV.

https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/


Troy Hunt

https://www.troyhunt.com


Weekly Update 516: Live From Vietnam

  Pagina openen

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back to business, it's the Brinks Home FAQ I found most interesting this week. I mean, how do you write your own FAQ then fail to

https://www.troyhunt.com/weekly-update-516/


Welcoming the Nepalese Government to Have I Been Pwned

  Pagina openen

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Today, we welcome the 47th government onboarded to Have I Been Pwned’s free gov service: Nepal. Their National Cyber Security Centre now has access to monitor Nepalese government domains against the data in HIBP. This gives the NCSC the ability to identify exposure across government email addresses and

https://www.troyhunt.com/welcoming-the-nepalese-government-to-have-i-been-pwned/




Bruce Schneier

https://www.schneier.com

LLMs and Contextual Integrity

  Pagina openen

I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic.

CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs“:

Abstract: Large Language Models (LLMs) increasingly use persistent memory from past interactions to enhance personalization and task performance. However, this memory introduces critical risks when sensitive information is revealed in inappropriate contexts. We present CIMemories, a benchmark for evaluating whether LLMs appropriately control information flow from memory based on task context. CIMemories uses synthetic user profiles with over 100 attributes per user, paired with diverse task contexts in which each attribute may be essential for some tasks but inappropriate for others. Our evaluation reveals that frontier models exhibit up to 69% attribute-level violations (leaking information inappropriately), with lower violation rates often coming at the cost of task utility. Violations accumulate across both tasks and runs: as usage increases from 1 to 40 tasks, GPT-5’s violations rise from 0.1% to 9.6%, reaching 25.1% when the same prompt is executed 5 times, revealing arbitrary and unstable behavior in which models leak different attributes for identical prompts. Privacy-conscious prompting does not solve this—models overgeneralize, sharing everything or nothing rather than making nuanced, context-dependent decisions. These findings reveal fundamental limitations that require contextually aware reasoning capabilities, not just better prompting or scaling...

https://www.schneier.com/blog/archives/2026/08/llms-and-contextual-integrity.html



Friday Squid Blogging: Searching for the Colossal Squid

  Pagina openen

Fascinating video about searching for life undersea. The video basically makes the point that our bright white searchlights are scaring everything away, and that red light is more neutral. That, plus bait to attract sea creatures, is teaching us a lot about what’s going on down there. Lots of footage of giant squid, and speculation about the colossal squid. Worth watching.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

https://www.schneier.com/blog/archives/2026/08/friday-squid-blogging-searching-for-the-colossal-squid-2.html


Upcoming Speaking Engagements

  Pagina openen

This is a current list of where and when I am scheduled to speak:

  • I’m speaking, signing books, and participating in panel discussions at LAcon V in Anaheim, California, USA. My full schedule is here.
  • I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026, at 5 PM ET.
  • I’m speaking at Elevate Festival in Toronto, Canada. The conference runs September 22–24, 2026; my talk is on Wednesday, September 23.
  • I’m speaking at CanSecWest 2026 in Vancouver, Canada. The conference runs September 30–October 1, 2026; the time of my talk is TBD...

https://www.schneier.com/blog/archives/2026/08/upcoming-speaking-engagements-59.html


If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them

  Pagina openen

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.

OpenAI, and then Anthropic, were each formed by AI developers who feared unrestrained corporate AI development—specifically, that companies like Google and Meta would steer the technology towards deleterious, maybe even catastrophically unsafe, outcomes for society. Their founders proclaimed that their new labs, uniquely, could be trusted to develop the technology in humanity’s best interest. But each, in turn, were themselves co-opted by the same market incentives, themselves becoming corporate behemoths zealously guarding future investor value rather than the public interest...

https://www.schneier.com/blog/archives/2026/08/if-the-markets-reject-openai-and-anthropic-the-us-should-nationalize-them.html


Security Affairs

https://securityaffairs.co

GitLab Patches Critical Unauthenticated GraphQL Vulnerability

  Pagina openen
GitLab patched a critical GraphQL flaw that let unauthenticated attackers remotely modify or delete public projects on self-managed servers. GitLab pushed out an emergency patch this week to address a critical flaw, tracked as CVE-2026-19478 (CVSS score of 9.4), that could let an attacker with zero credentials remotely modify or delete public projects and user [...]

https://securityaffairs.com/197454/hacking/gitlab-patches-critical-unauthenticated-graphql-vulnerability.html


U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog

  Pagina openen
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Ray-Project Ray vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2025-62593 (CVSS score of 9.4), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2025-62593 is a critical remote code execution (RCE) vulnerability in Ray, [...]

https://securityaffairs.com/197419/security/u-s-cisa-adds-a-ray-project-ray-flaw-to-its-known-exploited-vulnerabilities-catalog.html


New Mirai-Based Evooo1Bot Botnet Targets Linux Devices

  Pagina openen
Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai‘s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a [...]

https://securityaffairs.com/197434/malware/new-mirai-based-evooo1bot-botnet-targets-linux-devices.html


SafePal Says 39,798 Customers Hit by Data Breach

  Pagina openen
SafePal says a breach exposed personal data of 39,798 customers, but not wallet credentials, private keys, seed phrases, or payment information. SafePal disclosed a data breach affecting about 39,798 customers after hackers exploited a vulnerability in its order-tracking plugin. The flaw exposed information linked to orders placed between March 2, 2025, and April 11, 2026, [...]

https://securityaffairs.com/197391/data-breach/safepal-says-39798-customers-hit-by-data-breach.html


LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected

  Pagina openen
The SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more. Resecurity (USA) estimated the most affected sectors by the “SANDCLOCK” backdoor, which was planted as a result of the code repository compromise. According to cybersecurity experts, LiteLLM / TeamPCP Supply-Chain Attack will have long-lasting consequences. By compromising a [...]

https://securityaffairs.com/197377/hacking/litellm-supply-chain-attack-technology-banking-and-healthcare-the-most-affected.html


news.sophos.com

https://news.sophos.com