China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services

Nov 22, 2025Ravie LakshmananCyber Espionage / Cloud Security The China-linked advanced persistent threat (APT) group known as APT31 has been attributed to cyber attacks targeting the Russian information technology (IT) sector between 2024 and 2025 while staying undetected for extended periods of time. “In the period from 2024 to 2025, the Russian IT sector, especially […]

Continue Reading

New IRS reporting requirements will make a classic crypto ‘tax cheat’ risky starting with 2025 return

With year-end approaching, it’s a good time to make sure your tax house is in order. It’s especially important for crypto investors, given a new IRS brokerage reporting requirement covering transactions after Jan. 1, 2025. The IRS generally treats crypto like property, similar to stocks or real estate, so selling crypto can trigger a capital […]

Continue Reading

Scientists Build One of the Most Detailed Digital Simulations of the Mouse Cortex Using Japan’s Fugaku Supercomputer

Researchers from the Allen Institute and Japan’s University of Electro-Communications have built one of the most detailed mouse cortex simulations ever created. Using Japan’s Fugaku supercomputer, the team modeled around 10 million neurons and 26 billion synapses, recreating realistic structure and activity. The virtual cortex offers a new platform for studying br…

Continue Reading

Matrix Push C2 Uses Browser Notifications for Fileless, Cross-Platform Phishing Attacks

Bad actors are leveraging browser notifications as a vector for phishing attacks to distribute malicious links by means of a new command-and-control (C2) platform called Matrix Push C2. “This browser-native, fileless framework leverages push notifications, fake alerts, and link redirects to target victims across operating systems,” Blackfog researcher Brenda Robb said in a Thursday report. […]

Continue Reading

CISA Warns of Actively Exploited Critical Oracle Identity Manager Zero-Day Vulnerability

Nov 22, 2025Ravie LakshmananZero-Day / Software Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw impacting Oracle Identity Manager to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability in question is CVE-2025-61757 (CVSS score: 9.8), a case of missing authentication for a critical […]

Continue Reading

Figure AI sued by whistleblower who warned that startup’s robots could ‘fracture a human skull’

Startup Figure AI is developing general-purpose humanoid robots. Figure AI Figure AI, an Nvidia-backed developer of humanoid robots, was sued by the startup’s former head of product safety who alleged that he was wrongfully terminated after warning top executives that the company’s robots “were powerful enough to fracture a human skull.” Robert Gruendel, a principal […]

Continue Reading

Govini founder Eric Gillespie released on $1 million bond with Pentagon probe ‘ongoing’

Mug shot of Eric Gillespie, Govini Founder and Chairman. Courtesy: Pennsylvania Attorney General Govini founder Eric Gillespie, who is charged with four felonies, including multiple counts of unlawful contact with a minor, was released on bail. Gillespie, who lives in Pittsburgh, posted a $1 million bond after his court appearance Thursday. He is not allowed to […]

Continue Reading

UC San Diego Engineers Create Wearable Patch That Controls Robots Even in Chaotic Motion

UC San Diego engineers have developed a soft, AI-enabled wearable patch that can interpret gestures with high accuracy even during vigorous or chaotic movement. The armband uses stretchable sensors, a custom deep-learning model, and on-chip processing to clean motion signals in real time. This breakthrough could enable intuitive robot control for rehabilitation, indus…

Continue Reading

Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation

Nov 21, 2025Ravie LakshmananVulnerability / Threat Mitigation Grafana has released security updates to address a maximum severity security flaw that could allow privilege escalation or user impersonation under certain configurations. The vulnerability, tracked as CVE-2025-41115, carries a CVSS score of 10.0. It resides in the System for Cross-domain Identity Management (SCIM) component that allows automated […]

Continue Reading

The market’s surprising reversal, Gap’s viral ad, AI regulation and more in Morning Squawk

Dado Ruvic | Reuters This is CNBC’s Morning Squawk newsletter. Subscribe here to receive future editions in your inbox. Here are five key things investors need to know to start the trading day: 1. Hero to zero Stock investors didn’t end up getting the post-Nvidia earnings market bounce they hoped for. After opening yesterday’s trading session higher, […]

Continue Reading

Nvidia is king in AI chips, but Google and Amazon want to catch up by making their own

Nvidia outperformed all expectations, reporting soaring profits Wednesday thanks to its graphics processing units that excel at AI workloads. But more categories of AI chips are gaining ground. Custom ASICs, or application-specific integrated circuits, are now being designed by all the major hyperscalers, from Google‘s TPU to Amazon‘s Trainium and OpenAI’s plans with Broadcom. These […]

Continue Reading

Google Brings AirDrop Compatibility to Android’s Quick Share Using Rust-Hardened Security

Nov 21, 2025Ravie LakshmananData Protection / Technology In a surprise move, Google on Thursday announced that it has updated Quick Share, its peer-to-peer file transfer service, to work with Apple’s equipment AirDrop, allowing users to more easily share files and photos between Android and iPhone devices. The cross-platform sharing feature is currently limited to the […]

Continue Reading