Security

Federal Audit Reveals NIST's NVD Plagued by Poor Planning and Duplication
NIST's NVD backlog hit 27,000 flaws, with manual scoring matching independent results 12% of the time and $200,000 in duplication with CISA.

What Is FROST? The New SSD Side-Channel That Spies on Web Visitors
FROST, a new side-channel attack, lets websites spy by measuring SSD latency via OPFS and a neural network to detect open tabs and apps.

Iran's National Intranet Project: A Strategic Shift
Iran's national intranet project is exposed by a partial internet reconnection, highlighting a power struggle and digital sovereignty push.

BadHost Vulnerability: What AI Users Need to Know
A critical BadHost vulnerability in the Starlette framework puts millions of AI agents and tools at risk of data theft. Here's what users should do.

How AI Is Fueling a Bug Hunting Arms Race
Bug Hunting Arms Race accelerates as AI submissions flood programs. Curl, Google adjust; Linux mailing list overwhelmed. 90-day disclosure may be obsolete.

the-hosting Data Loss: What Users Should Know
The-hosting data loss hit customers after Dutch authorities seized 800 servers. Here's what happened and what affected users should do.

First VPN Dismantled After Police Hacked Service, Users Identified
First VPN was infiltrated by police, who identified thousands of users. The service was used by 25 ransomware groups.

Weekly Security: FBI License Plate Reader Access
FBI license plate reader access in near real-time leads the week's security news, with a Chromium Fetch flaw, deepfake arrests, and more.

Kimwolf Botnet Takedown Reveals IoT Attack Rivalry
Kimwolf botnet takedown reveals four IoT botnets competing for the same vulnerable devices in a crowded DDoS-for-hire economy.

CISA Leak Reshapes Federal Cyber Resilience Demands
CISA's GitHub leak and Congressional push highlight federal cyber resilience gaps, prompting calls for better repository controls and talent investment.

How EPIC's Data Broker Opt-Out Report Reframes Privacy as a Safety Mandate
EPIC's data broker opt-out audit reveals systematic manipulation across 38 companies, elevating broken forms into a safety and regulatory liability issue.
