ZeroHour

Search: “maker”

5 stories in the last 24h

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft signed legally binding AI privacy and safety standards for schools with the American Federation of Teachers, effective November 1.

Microsoft's agreement with the American Federation of Teachers prohibits using student or educator data to train AI systems, bans selling data or using it for ads and product development, and forbids AI companions designed to foster emotional dependency, with third-party audits required. The standards apply to all schools under Microsoft contract starting November 1. NYC and LA school districts announced one-year moratoriums on student AI use, while OpenAI and Anthropic pursue similar pacts and Google remains noncommittal.

SecurityWeek · 20h agoAI policy

Google says some Pixel phone owners were hacked in zero-day attacks

Google patched CVE-2026-58704, a zero-click Pixel modem privilege-escalation zero-day exploited in limited, targeted attacks.

Google disclosed that a vulnerability in Pixel smartphones' modem software, tracked as CVE-2026-58704, was exploited in limited and targeted cyberattacks and has now been patched. Exploitation could allow an attacker to escape the modem sandbox and escalate privileges to access broader phone data. The bug can be exploited silently with zero user interaction. Google did not attribute the activity, though such modem bugs are commonly abused by surveillance vendors selling spyware to governments.

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)

CVE-2026-90894 in Parallels Desktop for Mac lets any local user gain root via argument injection; patched in v27.0.0, PoC withheld.

JFrog researchers disclosed CVE-2026-90894, an argument injection flaw in Parallels Desktop for Mac v26.4.0 on Apple silicon that lets any local user gain root on the host. The chain combines a world-writable Unix socket for prl_disp_service (which runs as root), weak peer-credential authentication, and argument injection via --use-compress-program in the appliance extraction tar path. Alludo fixed the flaw in Parallels Desktop v27.0.0 in early September 2026; JFrog published technical details but withheld its proof-of-concept script.

Help Net Securityupdated · 3h agofirst · 4h agoVulnerability 4 sourcesCVE-2026-90894

Cyber-Attacks Cost Organizations $52,000 on Average

Hiscox's 2026 survey of 6,800 security leaders found 29% of organizations hit by successful attacks averaging $52,000 in costs and 32.8 hours of downtime.

The Hiscox Cyber Readiness Report 2026, based on a survey of 6,800 security decision-makers across the UK, Europe, and US, found 29% of organizations suffered at least one successful cyber-attack in the past 12 months, averaging four incidents per victim. UK firms were most attacked at 38% while US firms were least at 20%; average incident cost was $52,000 globally, peaking at $134,138 in Italy, with 32.8 hours of average downtime. Impacts included growth delays (32%), financial penalties (28%), and burnout or toxic culture (69%). Businesses invest about $51,000 annually in resilience, and 32% now tie executive compensation to cybersecurity outcomes.

Infosecurity Magazine · 5h agoIndustry

Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping

OPSWAT disclosed two zero-days in TP-Link Tapo C200 cameras: CVE-2026-15315 authentication replay bypass enabling surveillance and CVE-2026-15316 denial-of-service, both patched in firmware.

OPSWAT found two zero-days in the TP-Link Tapo C200 camera, widely used for baby/pet monitoring and SOHO security: CVE-2026-15315, an authentication bypass via replay granting administrative access without the password, and CVE-2026-15316, an unauthenticated denial-of-service that crashes the camera's HTTPS service via oversized encrypted credentials. Both were fixed in firmware version V5_1.4.6 released August 18. A third, still-unpatched zero-day rated critical could allow full camera compromise for use as a network foothold; details await an available fix.

Infosecurity Magazineupdated · 3h agofirst · 6h agoVulnerability 3 sourcesCVE-2026-15315CVE-2026-15316