Big news: Today, we’re starting to roll out end-to-end encryption for RCS messaging between Android and iPhone users! This cross-industry effort replaces outdated SMS with a more secure & private way to chat, no matter what phone you have.🔒
Thank you to the community for continuing to push for these kinds of features. Your engagement really helps make a difference. Congratulations to the team for reaching this amazing milestone! 🚀
Read more: https://t.co/rqpyCUi2Sr
‼️🚨 Microsoft calls this "intended behaviour," so here we go.
How to dump the credentials of every user stored in Microsoft Edge:
1. Open Edge. Don't browse anywhere, just open it.
2. Flip to Task Manager, find Edge, expand the task.
3. Highlight the "browser" sub-task, right-click, and choose "Create Memory Dump."
4. Open the dump file and look for credentials.
The logged-in Windows user can dump every stored Edge credential with no additional rights. Which means any malware that user executes has those credentials for the asking.
Thanks to Rob VandenBrink at SANS: https://t.co/ebtVZxne4L
⚠️ Microsoft Edge Stores All Saved Passwords in Cleartext Process Memory at Launch
Source: https://t.co/ROEbnQ9syu
Microsoft Edge decrypts every stored password into process memory the moment the browser launches and keeps them there as cleartext, regardless of whether the user ever visits those sites.
A researcher who systematically tested every major Chromium-based browser for credential memory handling behavior. Edge was the only browser that exhibited this behavior, loading the entire password vault into plaintext process memory at startup and retaining it for the duration of the session.
In a published proof-of-concept video accompanying the disclosure, a compromised administrator account was used to successfully extract stored credentials.
#cybersecuritynews
Huge Anthropic leak just dropped: the entire Claude Code CLI source is now public.
A misconfigured .map file in their npm package exposed a direct download link to the full unobfuscated TypeScript codebase from Anthropic’s own R2 bucket.
Discovered by Chaofan Shou (@Fried_rice), the dump is massive 1,900 files, 512,000+ lines including the complete tool system, 50+ slash commands, multi-agent coordinator, React/Ink terminal UI, IDE bridge, permission engine, and several unreleased features.
Full repo is live on GitHub(@nichxbt ):
https://t.co/BLxqDmwsB0
Clean mirrors are already up for easy browsing(@baanditeagle):
https://t.co/BN007COQzi
https://t.co/DYSytIEKZ4
It’s spreading fast, the entire dev community is already tearing through it.
🚨 Andrej Karpathy just explained the scariest thing happening in software right now..
someone poisoned a Python package that gets 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine..
SSH keys.. AWS credentials.. crypto wallets.. database passwords.. git credentials.. shell history.. SSL private keys.. everything..
and here's the part that should terrify every developer alive..
the attack was only discovered because the attacker wrote sloppy code.. the malware used so much RAM that it crashed someone's computer.. if the attacker had been better at coding.. nobody would have noticed for weeks..
one developer.. using Cursor with an MCP plugin.. had litellm pulled in as a dependency they didn't even know about.. their machine crashed.. and that crash saved thousands of companies from getting their entire infrastructure stolen..
Karpathy's take is the real wake up call.. every time you install any package you're trusting every single dependency in its tree.. and any one of them could be poisoned..
vibe coding saved us this time.. the attacker vibe coded the attack and it was too sloppy to work quietly.. next time they won't make that mistake.
This YouTuber, Benn Jordan discovered that a surveillance company named Flock Safety who currently has over 90K camera deployed throughout the US, is severely compromised. He found that many cameras are live-streaming directly to the open internet.
Ubiquiti patched two UniFi Network Application vulnerabilities, including a maximum-severity flaw that may allow attackers to take over user accounts.
https://t.co/X2qrRnCWLw
We're happy to announce a long-term partnership with Motorola. We're collaborating on future devices meeting our privacy and security standards with official GrapheneOS support.
https://t.co/8flkjD52Eg
18 years with @Verizon and I’m finally done. Bad AI, weak support, network crashes, missing credits, and absurd hoops to make basic changes. They were once the best. Now they’re just frustrating and behind the times.
What a fantastic picture of the Tidal Basin and the Jefferson Memorial -- reflective of this uncommon stretch of frigid, icy weather.
Thanks to @hocofoto (Seth Hoffman) for sharing this amazing capture with us on Instagram.
@ups has just done a terrible job with the East Coast snowstorm. Packages from a week and a half ago still have not been delivered. Pinged UPS, and they said they have trucks sitting full of packages that they need to go through. This is their business, by the way. We have seen no issues with FedEx - how about you?