Tech & Cyber Digest

2575

· BleepingComputer

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]

· Ars Technica - All content

US company’s AI lets Ukraine’s cheap kamikaze drones track targets on their own

$100 million deal gives 50,000 Ukrainian drones US-developed AI capabilities.

· TechCrunch

After killer quarter, Palantir CEO Alex Karp calls AI industry ‘Marxist’

After a quarter that delivered $1 billion in profit, Palantir CEO Alex Karp on Monday once again warned that AI frontier labs are too untrustworthy for enterprises.

· BleepingComputer

New Pass-ta-key attacks let malware hijack Google-synced passkeys

Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. [...]

· TechCrunch

Snap CEO sidesteps Specs preorder questions on Q2 earnings call

When asked about product-market fit, Spiegel said he believes mass-market consumer adoption won't occur until the end of the decade.

· Ars Technica - All content

An AI-supervised remote exam went so badly that 58,000 students must retake it

Top scores increased by 5x.

· Ars Technica - All content

Lego deploys Hubble Space Telescope as detailed desktop model

The orbiting observatory in minifigure scale.

· Ars Technica - All content

Research roundup: 6 cool science stories we almost missed

Also: Cyborg diving suits for cockroaches, why sleepy sperm whales blow bubbles, Betelgeuse's companion star.

· TechCrunch

AWS is helping vibe-coding startup Superblocks, and the implications are big

AWS now allows vibe coding tool Superblocks to be embedded into the private clouds of AWS customers. It's another step towards decoupling apps from models.

· BleepingComputer

New DOUBLECUP ClickFix service hides malware in browser cache images

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. [...]