ShieldBreak reportedly bypasses Microsoft's Windows Defender patch with a "100% success rate"
Sounding off: NightmareEclipse did it again. The security researcher who's been on a crusade against Microsoft has published a new zero-day flaw affecting all supported Windows versions. Redmond threatened to sue, but the researcher is keeping his promise to disclose a new dangerous flaw after every month's Patch Tuesday.
AI has increased the number of helpful and bogus bug reports
Winners & losers: Generative AI has become a double-edged sword for security teams. The same technology that helps uncover and fix vulnerabilities faster than ever also makes it trivially easy to flood inboxes with dubious bug reports. That tension recently pushed Apple to change its bug bounty program in a way that ended up delaying disclosure of a genuinely serious exploit.
Why it matters: A hardware wallet is supposed to solve one problem: keep your Bitcoin keys somewhere no attacker can reach them. This week showed what happens when the flaw sits inside the wallet itself. A firmware bug that's been shipping in Coldcard devices since 2021 let an attacker guess supposedly random seed phrases from the outside, no physical access, no phishing, no malware required, and drain funds from thousands of addresses. The running total is already past $88 million, and it's still climbing.