More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
India’s Tata Electronics says the World Leaks ransomware gang dumped over 200,000 internal files, including Tesla and Apple product specs, technical diagrams, event logs, emails and even paper scans of employee IDs. If genuine, those documents could give rivals a head start on upcoming hardware designs and expose sensitive personal data—potentially dragging Tata into regulatory hot water across multiple countries.
In other patches and defenses this week, researchers from JFrog closed a heap-overflow flaw in FFmpeg’s MagicYUV decoder that let attackers run code when opening AVI, MKV or MOV files in apps without ASLR. Cloudflare detailed its response to the Linux AF_ALG “Copy Fail” bug: they verified detection alarms triggered in minutes, hunted logs for two days with no hits, then rolled out an allow-list LSM policy via eBPF and pushed patched LTS kernels automatically. GitHub also hardened actions/checkout so pull_request_target and workflow_run no longer auto-checkout untrusted forks by default, blocking many “pwn request” attacks.
On AI fronts, Meta shelved its Model Capability Initiative after finding that an internal AI training program had leaked employees’ keystrokes, mouse movements, private chats and performance reviews across the company. At the same time, OpenAI launched Daybreak tools—Codex Security workflows, a GPT-5.5-Cyber model and a partner program—to scan code, validate findings and draft patches. Researchers also revealed “role confusion” attacks on LLMs where malicious prompts styled like system messages boosted jailbreak rates from 0% to 61%; simple “destyling” of incoming text cut success to 10%. And Unit 42 exposed five backdoored skills on OpenClaw’s marketplace that CCTV steganography and Base64 droppers slipped past scanning engines.
Government and industry warnings piled up too. The Five Eyes agencies say frontier AI capable of crippling cyberattacks arrives within months, not years, urging businesses to treat security as a board-level priority. Meanwhile, Cloudflare teamed with Mozilla, Google and Microsoft to test Private Access Control Tokens—a privacy-first protocol letting trusted sites vouch for real human users anonymously across the web.
Questions about this article
No questions yet.