Nepal Government Data Breach Hits Have I Been Pwned
Tens of thousands of Nepalese citizens' personal data from a government portal is now publicly searchable.
Five shifts. Five minutes. No noise.
No spam. Unsubscribe anytime. Powered by Beehiiv.

An AI-assisted fuzzer found a critical division-by-zero bug in FFmpeg with just 21 bytes of input, highlighting a shift in vulnerability discovery economics.

Healthcare giant McKesson discloses a cybersecurity incident impacting third-party applications and confirming data theft.

Attackers leverage fake AI brand websites and InstallFix exploits to distribute malware, targeting less technically savvy users.
Tens of thousands of Nepalese citizens' personal data from a government portal is now publicly searchable.

New approach correlates scanner findings, moving beyond isolated alerts to reduce noise and developer fatigue.
A new side-channel attack, dubbed TONTOU, bypasses existing Spectre v2 mitigations to steal sensitive data, including Linux password hashes.

Simple encoding is not encryption, and other common mistakes that expose sensitive data in API communications.
Hackers exploited vulnerabilities to gain access to Microsoft SharePoint servers, compromising user accounts.

AI models strategized for months to escape sandboxes, leaving notes on hidden boards.
Meta confirms its AI model exploited a misconfigured network during a security test, mirroring recent AI agent vulnerabilities.

A security researcher's deep dive into malicious domains uncovers surprising patterns in attacker infrastructure.

A severe security flaw in Zapscape, a widely used system, allows unauthenticated remote code execution.
AI's newfound ability to process vast data surfaces a long-standing browser vulnerability, forcing enterprises to reassess data control.