Sign in

The New Oil

@thenewoil.org
592 followers 0 following 1.4K posts

Practical #privacy and simple #cybersecurity for everyone. Articles posted =/= endorsement/agreement. This account no longer monitored. Please contact us […] 🌉 bridged from ⁂ mastodon.thenewoil.org/@thenewoil, follow @ap.brid.gy to interact

PostsRepliesMedia
The New Oil @thenewoil.org · 13h
New Attack Can Track You Across Operating Systems Without Elevated Privileges www.privacyguides.org/news/2026/09/… #privacy #cybersecurity #Linux #Windows #Mac #Android #iOS #Apple #FOSS
privacyguides.org
New Attack Can Track You Across Operating Systems Without Elevated Privileges
Researchers at the Graz University of Technology Austria demonstrated a new attack that can track you via file change events "on all systems," allowing for various data leaks.
001
The New Oil @thenewoil.org · 14h
#Nvidia Unveils #AI Agent Safety Platform With Hardware-Based Watchdog it.slashdot.org/story/26/09/28/1502… #cybersecurity
it.slashdot.org
Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog - Slashdot
wiredmikey shares a report from SecurityWeek: Nvidia on Monday announced the Open Agent Safety Platform, which combines open source software and a reference system design to keep AI agents within set boundaries from testing through deployment. The chipmaker explained that the platform pairs the open...
001
The New Oil @thenewoil.org · 14h
#OpenAI halts frontier-model training amid string of agent misalignment incidents arstechnica.com/ai/2026/09/openai-h… #cybersecurity #AI
arstechnica.com
000
The New Oil @thenewoil.org · 15h
#FBI reportedly declares ‘ #cybersecurity incident’ after hackers steal agents’ personal data techcrunch.com/2026/09/28/fbi-repor… #privacy #DataBreach #ShinyHunters
techcrunch.com
000
The New Oil @thenewoil.org · 15h
#JadePuffer agentic #AI attacks target #Azure, destroy cloud resources www.bleepingcomputer.com/news/secur… #cybersecurity
bleepingcomputer.com
JadePuffer agentic AI attacks target Azure, destroy cloud resources
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...]
001
The New Oil @thenewoil.org · 16h
Unsurprisingly, #Meta's new #Muse #AI agent blatantly ignores users permissions appleinsider.com/articles/26/09/28/… #privacy #Apple #iMessage
appleinsider.com
Meta Muse AI reportedly read Mac Messages without consent
In a completely unsurprising turn of events, Meta's Muse AI is stealing Apple Messages, past and present, and uploading the contents to its cloud, even if explicitly told not to.
003
The New Oil @thenewoil.org · 16h
#Walmart says it’s not using personal information to set prices as it expands digital shelf labels apnews.com/article/walmart-pricing-… #privacy #SurveillancePricing
010
The New Oil @thenewoil.org · 17h
#Dutch Police Arrest ‘Reformed’ Hacker in #ShinyHunters Investigation krebsonsecurity.com/2026/09/dutch-p… #cybercrime #Netherlands #ransomware
krebsonsecurity.com
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.
000
The New Oil @thenewoil.org · 17h
Humans Are Reading #Copilot Prompts — And They're Horrified www.404media.co/humans-reading-copi… #AI #nsfw #privacy
404media.co
Humans Are Reading Copilot Prompts — And They're Horrified
Human contractors are reviewing Copilot users’ prompts and uploaded images, according to internal documents obtained by 404 Media. The contractors are also bombarded with users’ requests for sexual AI images.
000
The New Oil @thenewoil.org · 18h
#CISA orders feds to patch exploited #Citrix flaws by Wednesday www.bleepingcomputer.com/news/secur… #cybersecurity
bleepingcomputer.com
CISA orders feds to patch exploited Citrix flaws by Wednesday
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]
000
The New Oil @thenewoil.org · 18h
#Meta Promises to Upgrade #RayBan Smart Glasses with "Private Processing" www.privacyguides.org/news/2026/09/… #privacy #PervertGlasses #SmartGlasses #IoT
privacyguides.org
Meta Promises to Upgrade Ray Ban Smart Glasses with "Private Processing"
Meta announced in a blog post that its notorious smart glasses will soon use its Private Processing to protect your data as it's being processed in the cloud.
001
The New Oil @thenewoil.org · 19h
#Citrix confirms two #NetScaler RCE zero-days exploited in attacks www.bleepingcomputer.com/news/secur… #cybersecurity
bleepingcomputer.com
Citrix admins warned to shut down NetScalers over 2 exploited zero-days
Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week.
000
The New Oil @thenewoil.org · 19h
#Cloudflare fixes #Containers cross-tenant flaw exposing customer data www.bleepingcomputer.com/news/secur… #cybersecurity #privacy #Sandboxes
bleepingcomputer.com
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host. [...]
001
The New Oil @thenewoil.org · 20h
#TikTok agrees to pay at least $100M in #Alabama settlement techcrunch.com/2026/09/26/tiktok-ag… #privacy #BigTech #TechAddiction
techcrunch.com
001
The New Oil @thenewoil.org · 20h
ShinyHunters uses #WAF bypass trick in #Oracle #PeopleSoft attacks www.bleepingcomputer.com/news/secur… #cybersecurity
bleepingcomputer.com
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.
001
The New Oil @thenewoil.org · 21h
#AI is finding so many #Linux bugs that #Canonical is changing how #Ubuntu gets security fixes nerds.xyz/2026/09/ubuntu-linux-ai-s… #FOSS #cybersecurity
nerds.xyz
AI is finding so many Linux bugs that Canonical is changing how Ubuntu gets security fixes
Artificial intelligence is getting very good at finding software bugs. That sounds like a win for security, but it is also creating a new problem: somebody still has to fix everything AI discovers. Canonical says the rapidly growing number of Linux vulnerabilities is now forcing it to change how Ubuntu kernel security updates are delivered. The company is moving away from its existing four-week regular and two-week security Stable Release Update cycles in favor of a unified two-week process that will result in new kernel releases every week. **SEE ALSO:**GEEKOM A5 2027 Edition is a tiny Ryzen 7 PC starting at $479 The reasoning is particularly interesting. Canonical directly points to artificial intelligence as one of the forces behind the explosion in reported CVEs. Large language models and specialized AI agents can automate work that previously required much more manual effort, allowing researchers to uncover bugs at a much faster rate. There is another factor too. The CVE Program officially added kernel.org as a CVE Numbering Authority in 2024, giving the Linux kernel team the ability to assign CVE identifiers for vulnerabilities within its scope. The kernel’s own documentation says potentially security-related fixes can now receive CVEs as part of the normal stable release process. That helps explain why the numbers can look alarming. The Linux kernel team says it takes a deliberately cautious approach because almost any kernel bug could potentially have security implications. It also warns that many assigned CVEs may not actually apply to a particular Linux system because users only run a subset of the enormous kernel codebase. In other words, Linux did not suddenly become wildly insecure overnight. We are getting much better at finding and cataloging problems that may have previously gone unnoticed. AI is accelerating that process, while the kernel’s newer CVE assignment approach is making more of those bugs visible to the security ecosystem. Canonical’s answer is overlapping two-week kernel cycles. During the first week, engineers prepare kernel packages, select patches, build them, and perform basic smoke testing. The second week focuses on hardware certification, Ubuntu integration, and regression testing. Because a new cycle begins every week, finished kernels can also arrive weekly. That testing component matters because simply pushing patches faster would be easy. Doing it without introducing regressions across the enormous variety of hardware running Ubuntu is the harder part. Canonical says it intends to retain its extensive certification and regression testing rather than trading reliability for speed. Organizations that cannot wait for the full cycle will have another option. Kernel release candidates are published through Ubuntu’s -proposed pocket before certification testing, and Canonical says those builds will be updated weekly. Companies willing to perform their own acceptance testing can therefore potentially get access to fixes sooner. That is not something ordinary Ubuntu users should rush to enable. The point of -proposed is that those packages have not yet completed Canonical’s full certification and regression process. For organizations facing a serious vulnerability, however, having the option to test a fix early could be valuable. Canonical is also addressing the awkward period between a vulnerability becoming public and a patched kernel reaching users. The company says it will try to provide safe workarounds or hardening guidance when possible, with a target of helping customers reach a safer state within 24 to 48 hours of public disclosure. There is something almost ironic about all of this. AI is routinely pitched as a tool that will make software development faster, but it is also making vulnerability discovery faster. That means maintainers now have to accelerate the other side of the equation too. For Ubuntu users, that should ultimately be good news. More bugs being discovered is preferable to vulnerabilities sitting unnoticed in the Linux kernel. The challenge for Canonical is making sure the growing torrent of CVEs can be fixed quickly without turning faster security updates into a source of new problems. ☕ ### Support independent tech journalism NERDS.xyz is independently owned and operated. If you enjoy my coverage of Linux, AI, hardware, cybersecurity, and tech culture, consider supporting the site on Ko-fi. Support NERDS.xyz Written by ### Brian Fagioli ✔ Technology journalist and founder of NERDS.xyz Brian Fagioli is a technology journalist and founder of NERDS.xyz. A former BetaNews writer, he has spent over a decade covering Linux, hardware, software, cybersecurity, and AI with a no nonsense approach for real nerds. 📄 More by Brian Fagioli ✖ Follow on X ▶ YouTube @ Threads 🐘 Mastodon
003
The New Oil @thenewoil.org · 21h
The False Promise of Going Off-Grid ghost.thenewoil.org/the-false-promi… #blog #privacy #PersonalFinance #cryptocurrency
ghost.thenewoil.org
The False Promise of Going Off-Grid
Privacy advocates are always looking for alternatives to banking, but most of the alternatives are actually even worse.
010
The New Oil @thenewoil.org · 26/09/2026
#GitHub Actions re-enabled with Mini #ShaiHulud payload still active www.bleepingcomputer.com/news/secur… #cybersecurity #malware
bleepingcomputer.com
GitHub Actions re-enabled with Mini Shai-Hulud payload still active
Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code.
000
The New Oil @thenewoil.org · 26/09/2026
#ChatControl 2.0 — 6th Trilogue this Tuesday, #EU Parl. to be given workaround own legal service already deems illegitimate discuss.privacyguides.net/t/chat-co… #privacy […]
mastodon.thenewoil.org
Original post on mastodon.thenewoil.org
046
The New Oil @thenewoil.org · 26/09/2026
Old-School #CreditCard Scams Are Far From Dead www.wired.com/story/kernel-panic-ol… #cybersecurity #PersonalFinance #finance #AI #scam #ScamAlert
wired.com
Old-School Credit Card Scams Are Far From Dead
In an era of increasingly sophisticated AI-fueled scams, a retro threat may be lurking in your mailbox.
110
The New Oil @thenewoil.org · 26/09/2026
Your uncle’s frozen #Mac says it’s infected after viewing a #Google #ad. Now what? arstechnica.com/security/2026/09/go… #guide #cybersecurity #malware #advertising #malvertising #scam #ScamAlert
arstechnica.com
011
The New Oil @thenewoil.org · 26/09/2026
Unsecured #OpenAI agents posted 53 user images on the internet without the lab’s knowledge techcrunch.com/2026/09/25/unsecured… #cybersecurity #privacy #AI
techcrunch.com
011
The New Oil @thenewoil.org · 26/09/2026
US Soldier Gets 70 Months in Prison for AT&T, #Verizon Extortions krebsonsecurity.com/2026/09/u-s-sol… #Army #cybersecurity #cybercrime #ATT #ATandT
krebsonsecurity.com
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
000
The New Oil @thenewoil.org · 26/09/2026
#ShinyHunters hacked #Clop leak site using #Grav #CMS path traversal flaw www.bleepingcomputer.com/news/secur… #cybersecurity #cybercrime
bleepingcomputer.com
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability.
000
The New Oil @thenewoil.org · 26/09/2026
Critical #Tor Vulnerabilities Patched Across All Tor Components From the "LLM Report Firehose" www.privacyguides.org/news/2026/09/… #FOSS #privacy #cybersecurity #anonymity #AI
privacyguides.org
Critical Tor Vulnerabilities Patched Across All Tor Components From the "LLM Report Firehose"
Tor has released updates for "all components" of Tor that include severe vulnerabilities and bugs from the "LLM report firehose" and recommends "upgrading as soon as possible."
011
The New Oil @thenewoil.org · 26/09/2026
Some #Supabase customers are publicly exposing reams of people’s data to the web techcrunch.com/2026/09/25/some-supa… #privacy #cybersecurity #DataBreach
techcrunch.com
010
The New Oil @thenewoil.org · 26/09/2026
#Elementor #WordPress flaw lets attackers create admin accounts www.bleepingcomputer.com/news/secur… #cybersecurity
bleepingcomputer.com
Elementor WordPress flaw lets attackers create admin accounts
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts.
001
The New Oil @thenewoil.org · 26/09/2026
#DraftKings Is Using #AI to Supercharge the Harms of Online Behavioral #Advertising www.eff.org/deeplinks/2026/09/draft… #privacy #addiction #gambling
000
The New Oil @thenewoil.org · 26/09/2026
CISA warns of #Sharepoint, #WSO2, #AdobeCommerce flaws exploited in attacks www.bleepingcomputer.com/news/secur… #cybersecurity #Adobe
bleepingcomputer.com
CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2.
010
The New Oil @thenewoil.org · 26/09/2026
#Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of #cyberattack techcrunch.com/2026/09/25/kiteworks… #cybersecurity
techcrunch.com
010
The New Oil @thenewoil.org · 26/09/2026
For months, #OpenAI’s agent swarms have been attacking online databases to find obscure facts techcrunch.com/2026/09/25/for-month… #AI #cybersecurity
techcrunch.com
000
The New Oil @thenewoil.org · 25/09/2026
PI’s response to the UK Department for Science, Innovation & Technology on data regulation in the age of #AI and other data-intensive technologies privacyinternational.org/advocacy/5… #privacy
privacyinternational.org
PI’s response to the UK Department for Science, Innovation & Technology on data regulation in the age of AI and other data-intensive technologies
Our submission covers the following topics, following the government's call for evidence:
000
The New Oil @thenewoil.org · 25/09/2026
#Rydox marketplace admin pleads guilty, faces 22 years in prison www.bleepingcomputer.com/news/secur… #cybersecurity #cybercrime #privacy
bleepingcomputer.com
Rydox marketplace admin pleads guilty, faces 22 years in prison
A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools.
000
The New Oil @thenewoil.org · 25/09/2026
Pay for your #Tuta subscription via the #Google #PlayStore! tuta.com/blog/tuta-supports-google-… #email #FOSS #cybersecurity #privacy #Android
010
The New Oil @thenewoil.org · 25/09/2026
Hackers steal $351.6 million in #Bitget #crypto exchange hack www.bleepingcomputer.com/news/secur… #NorthKorea #cybersecurity
bleepingcomputer.com
Hackers steal $351.6 million in Bitget crypto exchange hack
​Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets.
000
The New Oil @thenewoil.org · 25/09/2026
Defend VPNs Day of Action: Friday, September 25th www.defendvpns.com #privacy #VPN #activism
defendvpns.com
Defend VPNs from government bans!
VPNs make it safer to use the Internet. Governments are trying to ban them. Sign to renew your commitment and tell world leaders: using the Internet safely and privately is a human right. Don’t ban VPNs! Last year, nearly 20,000 VPN users mobilized to demand safe, private browsing. But with the continued global rise of […]
002
The New Oil @thenewoil.org · 25/09/2026
#MacSync #malware uses public #iCloud calendars to deliver new payloads www.bleepingcomputer.com/news/secur… #cybersecurity
bleepingcomputer.com
MacSync malware uses public iCloud calendars to deliver new payloads
A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads.
000
The New Oil @thenewoil.org · 25/09/2026
New #Carbonato #malware uses #AI agents to hijack exposed #Docker hosts www.bleepingcomputer.com/news/secur… #cybersecurity
bleepingcomputer.com
New Carbonato malware uses AI agents to hijack exposed Docker hosts
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]
000
The New Oil @thenewoil.org · 25/09/2026
#HIROH Phone now shipping with #Android 16 (Physical mic/camera kill switch for Android users) discuss.privacyguides.net/t/hiroh-p… #privacy #cybersecurity
discuss.privacyguides.net
HIROH Phone now shipping with Android 16 (Physical mic/camera kill switch for Android users)
Hey everyone, Just wanted to share a quick update for anyone interested in hardware-level privacy but hesitant to leave the mainstream Android ecosystem. The Hiroh Phone—which features a physical hardware kill switch that completely disconnects the microphone and camera at the circuit level—is now officially offering a version that ships with stock Android 16. I know a lot of people here prefer GrapheneOS over /e/OS because /e/OS isn’t always seen as robust on security. If you found the phone...
000
The New Oil @thenewoil.org · 25/09/2026
Five #Indianapolis officers charged following The Post's reporting on #Flock misuse www.msn.com/en-us/news/other/five-i… #privacy #police #ALPR #surveillance
msn.com
MSN
000
The New Oil @thenewoil.org · 25/09/2026
Exposed #GitLab project #email addresses let attackers push code www.bleepingcomputer.com/news/secur… #privacy #cybersecurity
bleepingcomputer.com
Exposed GitLab project email addresses let attackers push code
Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. [...]
000
The New Oil @thenewoil.org · 25/09/2026
#FDroid 2.0: A New Chapter for #Android Freedom f-droid.org/en/2026/09/24/f-droid-2… #FOSS #privacy
000
The New Oil @thenewoil.org · 25/09/2026
Survey: People don’t trust #AI, but they tell it everything proton.me/blog/ai-chatbot-survey #privacy
proton.me
Proton survey: People don't trust AI, but they tell it everything | Proton
New research finds that most AI chatbot users have shared something sensitive, but few trust the companies behind them.
004
The New Oil @thenewoil.org · 25/09/2026
Hackers now exploit critical #Roundcube flaw in code injection attacks www.bleepingcomputer.com/news/secur… #cybersecurity
bleepingcomputer.com
Hackers now exploit critical Roundcube flaw in code injection attacks
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]
000
The New Oil @thenewoil.org · 25/09/2026
There’s a new way to break #RSA that’s faster than anything we’ve seen before arstechnica.com/security/2026/09/th… #cybersecurity #encryption
arstechnica.com
002
The New Oil @thenewoil.org · 25/09/2026
CISA: #Ransomware gangs now exploiting critical #TeamCity flaw www.bleepingcomputer.com/news/secur… #cybersecurity
bleepingcomputer.com
CISA: Ransomware gangs now exploiting critical TeamCity flaw
​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. [...]
000
The New Oil @thenewoil.org · 25/09/2026
#OpenAI hacked Australian #Medicare govt site, probed data providers www.bleepingcomputer.com/news/secur… #Australia #cybersecurity #AI #privacy #DataBreach
bleepingcomputer.com
OpenAI hacked Australian Medicare govt site, probed data providers
OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project.
000
The New Oil @thenewoil.org · 25/09/2026
#Meta introduces camera-free #AI glasses techcrunch.com/2026/09/23/meta-intr… #privacy
techcrunch.com
000
The New Oil @thenewoil.org · 24/09/2026
Placeholder domain used in dev docs now serves #ClickFix attacks www.bleepingcomputer.com/news/secur… #cybersecurity
bleepingcomputer.com
Placeholder domain used in dev docs now serves ClickFix attacks
000
The New Oil @thenewoil.org · 24/09/2026
#FBI rushes to investigate if #ShinyHunters hack of thousands of employees is real arstechnica.com/tech-policy/2026/09… #cybersecurity #privacy #DataBreach
arstechnica.com
000