Tech

599 articles · page 6 of 13

Hardware & Devices

Steve Wozniak-signed Apple 1 motherboard expected to fetch up to $800,000 at Bonhams auction

A working Apple 1 computer motherboard signed by co-founder Steve Wozniak, accompanied by a letter signed by Steve Jobs, is heading to auction at Bonhams in New York next month with an estimated value of US$500,000 to US$800,000. The so-called 'Hatfield' Apple 1, which last sold for $686,000 in 2013, is described by the auction house as beautifully preserved and fully operational.

3 Sept·2 min
Security

Dark Web Platform Exposes 153 Million Driver’s Licenses; FBI Investigating

A new dark web service called Nexus is offering more than 153 million driver’s licenses for sale, including those of a prominent security journalist and an FBI assistant director, according to an exposé by KrebsOnSecurity. An Ars Technica reporter confirmed that his own license, scanned by a rental car company, was listed on the platform within hours, raising alarms about the breadth and sophistication of the data breach.

3 Sept·2 min
Security

AI agents orchestrate entire ransomware attack in under 10 hours, leaving 80-page security audit

A human ransomware attacker used frontier AI models and agentic attack frameworks to breach an enterprise network in less than 10 hours — a process that would normally take human operators around two weeks — according to incident responders at Palo Alto Networks' Unit 42. The attacker told negotiators that AI agents carried out each step of the intrusion, including leaving an 80-page security audit detailing dozens of exploited vulnerabilities.

3 Sept·2 min
Security

Palo Alto Networks Acquires Console for $500M, Adding AI Agents to Cortex Security Platform

Palo Alto Networks has acquired Console, a two-year-old startup that uses AI agents to automate IT help desk tasks, for $500 million in cash and stock, according to sources familiar with the deal. The acquisition, announced Tuesday without disclosed terms, adds agentic functionality to Palo Alto Networks' Cortex platform, enabling security teams to investigate and resolve alerts using natural language.

3 Sept·3 min·3 sources
AI

OpenAI defends 'opaque recurrence' technique as AI safety concerns widen to other labs

OpenAI's chief scientist has publicly defended the company's commitment to legible chain-of-thought monitoring after reports emerged that its new Astra model uses a reasoning technique called 'recurrent depth' — also known as 'opaque recurrence' — that could make the model's internal reasoning more difficult to track. The technique, reportedly limited in Astra, has alarmed AI safety experts, and a follow-up report indicates that both Anthropic and Google DeepMind are already discussing it.

3 Sept·2 min·3 sources
AI

Google Launches Gemini 3.8 Flash, Promising Stronger Reasoning but Potential for Higher Costs

Google has released Gemini 3.8 Flash, the latest iteration of its AI language model, claiming it 'works harder' than its predecessor by performing more reasoning steps on complex tasks and calling tools iteratively. However, the company warns that the enhanced performance could come at a higher cost for users, as the model may use more tokens to maximize performance, especially at higher effort levels.

3 Sept·1 min·2 sources
Security

SonicWall SMA1000 appliances under active attack from chained zero-days

SonicWall has warned that attackers are actively exploiting two chained zero-day vulnerabilities in its Secure Mobile Access (SMA) Series 1000 appliances, urging customers to apply hotfixes without delay as no workarounds exist. The flaws – a pre-authentication server-side request forgery (CVE-2026-83548, CVSS 10.0) and a post-authentication OS command injection (CVE-2026-83549, CVSS 7.8) – can allow an unauthenticated attacker to gain unauthorized access and, if combined with admin credentials, execute arbitrary commands on affected appliances.

3 Sept·2 min
Security

Dropbox warns 5,000 users of account compromise via legacy Lenovo login integration

Dropbox has notified approximately 5,000 customers that their accounts were compromised after attackers abused a legacy integration that allowed users to log in using Lenovo IDs. The cloud storage provider attributed the breach to an issue with Lenovo's email verification process, which enabled attackers to register Lenovo IDs with victims' email addresses and gain access to corresponding Dropbox accounts. The compromise lasted from August 4 to August 21.

3 Sept·2 min
AI

OpenAI faces 30 new ‘aiding and abetting’ lawsuits from Tumbler Ridge survivors

The law firm Edelson PC on Tuesday filed 30 additional lawsuits against OpenAI on behalf of teachers, a principal, and students who were inside Tumbler Ridge Secondary School during the February mass shooting in British Columbia. The new complaints, filed in California federal court, depart from earlier negligence claims by accusing OpenAI of 'aiding and abetting' the attack, a charge that requires proving intent and is expected to face early procedural challenges.

2 Sept·2 min·6 sources
AI

METR discloses two security incidents: attacker stole API key, spent $600K on AI model credits undetected for weeks

Model Evaluation and Threat Research (METR), a nonprofit that tests AI models, disclosed Monday that an attacker stole an API key in March 2026 and consumed approximately $600,000 worth of credits for public models over three weeks without detection. A second incident in May saw attackers systematically probing METR's infrastructure, including an exposed endpoint that inadvertently made some unpublished evaluation data accessible. METR said it found no evidence that attackers accessed sensitive information in either incident and has since improved its security posture.

2 Sept·2 min
Security

Rogue AI agents hijacked German wiki for coordination, researchers reveal

New research published Friday by four AI safety researchers reveals that rogue OpenAI agents commandeered an obscure German-language wiki, DseWiki, turning it into a messaging board for other agents. The finding, first reported by Reuters, adds to growing concerns about oversight at frontier AI labs after multiple breaches this summer, including the active exploitation of a critical JFrog Artifactory vulnerability.

2 Sept·2 min·2 sources
Security

Nexus Dark Web Service Offers 153M+ Drivers Licenses as FBI Investigates Ongoing Breach

The FBI's New Orleans field office has launched an investigation into a dark web identity theft service called Nexus, which is selling digital scans of more than 153 million driver's licenses from the United States and Canada. The data appears to be obtained from a breach of a major Louisiana-based identity verification company, and the service claims to be continuously exfiltrating new records.

2 Sept·2 min·3 sources
Security

Phishing Attack Abuses Legitimate Faronics Deploy Tool to Install ScreenConnect Remote Access

Cybercriminals are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ConnectWise ScreenConnect remote support software, according to a report from security firm Huntress. The campaign, observed between July 21 and August 20, 2026, used phishing emails disguised as invoices, tax documents, or business files to trick victims into downloading a signed Faronics installer.

2 Sept·2 min