Mythos attack on 3rd-round PQC algorithm candidate puts it out of commissionArs Technica · Security·Jul 29, 22:07 UTC · Jul 29, 2026Vulnerability30
Microsoft’s Secure Boot has been broken for a decade and no one noticed until nowArs Technica · Security·Jul 15, 00:00 UTC · Jul 15, 2026Vulnerability in the wildCVE-2015-5381160
Windows and Linux users: The deadline to update Secure Boot keys is nearArs Technica · Security·Jun 17, 11:15 UTC · Jun 17, 2026Vulnerability155
Texas AG sues Meta over claims that WhatsApp doesn't provide end-toArs Technica · Security·May 22, 18:13 UTC · May 22, 2026Vulnerability30
New AirSnitch attack bypasses Wi-Fi encryption in homes, offices, and enterprisesArs Technica · Security·Feb 26, 15:45 UTC · Feb 26, 2026Vulnerability30
Microsoft will finally kill obsolete cipher that has wreaked decades of havocArs Technica · Security·Dec 15, 00:00 UTC · Dec 15, 2025Vulnerability55
Critics scoff after Microsoft warns AI feature can infect machines and pilfer dataArs Technica · Security·Nov 19, 20:25 UTC · Nov 19, 2025Vulnerability30
Cache poisoning vulnerabilities found in 2 DNS resolving appsArs Technica · Security·Oct 22, 22:35 UTC · Oct 22, 2025VulnerabilityCVE-2025-40778CVE-2025-4078060
Hackers can steal 2FA codes and private messages from Android phonesArs Technica · Security·Oct 15, 00:00 UTC · Oct 15, 2025Vulnerability30
Open Source Community Thwarts Massive npm Supply Chain AttackInfosecurity Magazine·Sep 9, 13:30 UTC · Sep 9, 2025Vulnerability42
Unpacking Passkeys Pwned: Possibly the most specious research in decadesArs Technica · Security·Aug 28, 13:00 UTC · Aug 28, 2025Vulnerability30
SharePoint vulnerability with 9.8 severity rating under exploit across globeArs Technica · Security·Jul 21, 19:30 UTC · Jul 21, 2025Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs60
Found in the wild: 2 Secure Boot exploits. Microsoft is patching only 1 of them.Ars Technica · Security·Jun 10, 19:00 UTC · Jun 10, 2025VulnerabilityCVE-2025-3052CVE-2025-4782760
Windows 11’s most important new feature is postArs Technica · Security·May 20, 18:48 UTC · May 20, 2025Vulnerability42
New attack can steal cryptocurrency by planting false memories in AI chatbotsArs Technica · Security·May 15, 00:00 UTC · May 15, 2025Vulnerability30
Gemini hackers can deliver more potent attacks with a helping hand from… GeminiArs Technica · Security·Mar 28, 11:00 UTC · Mar 28, 2025Vulnerability30
Apple chips can be hacked to leak secrets from Gmail, iCloud, and moreArs Technica · Security·Jan 28, 20:56 UTC · Jan 28, 2025Vulnerability55
Time to check if you ran any of these 33 malicious Chrome extensionsArs Technica · Security·Jan 3, 12:15 UTC · Jan 3, 2025Vulnerability30
YubiKeys are vulnerable to cloning attacks thanks to newly discovered side channelArs Technica · Security·Sep 3, 17:58 UTC · Sep 3, 2024Vulnerability42
Hackers exploit VMware vulnerability that gives them hypervisor adminArs Technica · Security·Jul 29, 21:02 UTC · Jul 29, 2024VulnerabilityCVE-2024-37085CVE-2023-2825247
New Blast-RADIUS attack breaks 30-yearArs Technica · Security·Jul 9, 19:02 UTC · Jul 9, 2024Vulnerability55
Critical vulnerabilities in BIG-IP appliances leave big networks open to intrusionArs Technica · Security·May 8, 21:35 UTC · May 8, 2024Vulnerability in the wildCVE-2024-21793CVE-2024-2602660
Hackable Intel and Lenovo hardware that went undetected for 5 years won’t ever be fixedArs Technica · Security·Apr 11, 18:53 UTC · Apr 11, 2024Vulnerability55
Unpatchable vulnerability in Apple chip leaks secret encryption keysArs Technica · Security·Mar 21, 14:40 UTC · Mar 21, 2024Vulnerability30
SSH protects the world’s most sensitive networks. It just got a lot weakerArs Technica · Security·Dec 19, 17:35 UTC · Dec 19, 2023VulnerabilityCVE-2023-48795CVE-2023-46445CVE-2023-4644647
How worried should we be about the “AutoSpill” credential leak in Android password managers?Ars Technica · Security·Dec 15, 00:00 UTC · Dec 15, 2023Vulnerability30
ownCloud vulnerability with maximum 10 severity score comes under “mass” exploitationArs Technica · Security·Nov 29, 00:38 UTC · Nov 29, 2023Vulnerability in the wildCVE-2023-49103CVE-2023-4966CVE-2023-94105+1 CVEs60
In a first, cryptographic keys protecting SSH connections stolen in new attackArs Technica · Security·Nov 15, 00:00 UTC · Nov 15, 2023Vulnerability30
Biggest DDoSes of all time generated by protocol 0Ars Technica · Security·Oct 15, 00:00 UTC · Oct 15, 2023Vulnerability55
Vulnerabilities in Supermicro BMCs could allow for unkillable server rootkitsArs Technica · Security·Oct 4, 22:21 UTC · Oct 4, 2023VulnerabilityCVE-2023-40289CVE-2023-40284CVE-2023-40287+4 CVEs60
They’ve begun: Attacks exploiting vulnerability with maximum 10 severity ratingArs Technica · Security·Oct 3, 21:53 UTC · Oct 3, 2023Vulnerability in the wildCVE-2023-40044CVE-2023-4265760
3 iOS 0-days, a cellular network compromise, and HTTP used to infect an iPhoneArs Technica · Security·Sep 23, 00:23 UTC · Sep 23, 2023VulnerabilityCVE-2023-41993CVE-2023-41991CVE-2023-41992+1 CVEs60
Barracuda thought it drove 0-day hackers out of customers’ networks. It was wrong.Ars Technica · Security·Aug 30, 17:31 UTC · Aug 30, 2023VulnerabilityCVE-2023-286860
Next-gen OSDP was supposed to make it harder to break in to secure facilities. It failed.Ars Technica · Security·Aug 9, 14:30 UTC · Aug 9, 2023Vulnerability55
Firmware vulnerabilities in millions of computers could give hackers superuser statusArs Technica · Security·Jul 20, 19:29 UTC · Jul 20, 2023VulnerabilityCVE-2023-34329CVE-2023-3433060