Tag

Security

All articles tagged with #security

LA officials push for a no-surprise funding guarantee for the 2028 Games
politics1 day ago

LA officials push for a no-surprise funding guarantee for the 2028 Games

Los Angeles city officials are pushing LA28 to sign a binding contract that guarantees the organization will cover any excess city costs—policing, transportation, sanitation and more—for the 2028 Games, to prevent taxpayers from shouldering overruns amid revenue uncertainty and potential reliance on federal funding; the deal is six months overdue and has been complicated by security and leadership concerns, including scrutiny of LA28 chair Casey Wasserman’s ties to Jeffrey Epstein.

ICE screening at Parris Island graduation events sparks security debate
politics10 days ago

ICE screening at Parris Island graduation events sparks security debate

Federal immigration agents will be stationed at Marine Corps graduation events at Parris Island to conduct enhanced screenings and lawful immigration-status inquiries as a security measure; officials say the operation is not intended to detain anyone and ICE will not be making arrests at the basic training graduation, while base officials emphasize this is unusual federal support for access operations and attendees should bring proper identification.

Axios supply-chain breach delivers cross-platform RAT through fake dependency
security10 days ago

Axios supply-chain breach delivers cross-platform RAT through fake dependency

Axios was hit by a supply-chain attack after attackers used compromised maintainer credentials to publish axios v1.14.1 and v0.30.4, which inject the fake dependency [email protected]. The postinstall script in that dependency drops a cross-platform RAT on macOS, Windows, and Linux, contacting a C2 server and delivering platform-specific payloads before self-deleting. Users should downgrade to 1.14.0 or 0.30.3, rotate credentials, remove plain-crypto-js from node_modules, audit CI/CD for the affected installs, and block egress to the C2 domain sfrclak.com. Axios itself wasn’t modified; the malicious behavior resided entirely in a transitive dependency, with additional vendored packages also distributing the malware.

Google flags quantum threat to Bitcoin, eyes 2029 post-quantum shift
security11 days ago

Google flags quantum threat to Bitcoin, eyes 2029 post-quantum shift

Google Research warns that the quantum resources needed to break ECDLP-256 have fallen roughly 20-fold, potentially enabling on-spend attacks against Bitcoin within its 10-minute block window and prompting a 2029 migration to post-quantum cryptography; the industry, including Coinbase and the Ethereum Foundation, is coordinating on the transition, though the risk remains years away.

BWI TSA waits ease as security returns to normal for spring travel
transportation11 days ago

BWI TSA waits ease as security returns to normal for spring travel

At Baltimore/Washington International Thurgood Marshall Airport (BWI) on Monday, security lines returned to normal after days of disruption, with checkpoints A–D/E open and waits under 10 minutes earlier in the day; travelers were advised to arrive two hours before departure, Frontier baggage checks ran about 40 minutes, ICE helped speed screening, and TSA backpay payments were underway to address staffing shortages.

Amnesty warns 2026 World Cup risks rights abuses and repression
world11 days ago

Amnesty warns 2026 World Cup risks rights abuses and repression

Amnesty International warns that the 2026 World Cup could become a stage for human-rights repression, urging host governments, FIFA, and sponsors to uphold international standards, while criticizing US immigration enforcement, invasive surveillance plans, and limited rights protections across host cities as homelessness and security concerns loom.

ICE to Screen Families at Parris Island Marine Graduation Events
military11 days ago

ICE to Screen Families at Parris Island Marine Graduation Events

ICE agents will be stationed at Marine Corps Recruit Depot Parris Island in South Carolina to conduct enhanced screening and lawful immigration-status inquiries at recruit family days and graduation events as part of heightened base protections; a DHS spokesperson said ICE will not be making arrests at the basic training graduation, and it’s unclear whether the practice will extend to other bases.

Dual memory-overread flaws unlock Citrix NetScaler doors (CVE-2026-3055) Part 2
security12 days ago

Dual memory-overread flaws unlock Citrix NetScaler doors (CVE-2026-3055) Part 2

Security researchers from watchTowr Labs report that CVE-2026-3055 encompasses at least two memory-overread flaws in Citrix NetScaler. Exploitation hinges on an empty wctx parameter in /wsfed/passive?wctx, leaking memory (via the NSC_TASS cookie) and potentially exposing authenticated admin session IDs. In-the-wild activity has begun, suggesting that patches may not cover all variants. The post includes a Detection Artifact Generator for defenders and notes that a further instance was reported to Citrix, highlighting ongoing risk for misconfigured NetScaler deployments (e.g., when used as a SAML IDP).

Finnish authorities identify Ukrainian drone among stray UAVs near Kouvola
world12 days ago

Finnish authorities identify Ukrainian drone among stray UAVs near Kouvola

Several drones crashed in southeastern Finland near Kouvola; one drone has been confirmed Ukrainian in origin. Finnish officials say the UAVs strayed into Finnish airspace, were not intercepted and fell on their own, with a Hornet jet deployed to identify them. Authorities emphasize there is no military threat and the investigation continues amid the broader Ukraine–Russia war.