The first trailer for Avengers: Doomsday is finally here
With San Diego Comic-Con kicking off later this week, Marvel Studios has released the first official full trailer for Avengers: Doomsday, the penultimate film in the MCU’s Phase Six and…
Thoughts and musings of David Greenberg, a polymath
Technology-related items
With San Diego Comic-Con kicking off later this week, Marvel Studios has released the first official full trailer for Avengers: Doomsday, the penultimate film in the MCU’s Phase Six and…
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events…
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths…
The industry spent the initial months after Anthropic’s April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would…
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and…
There are a lot of AI coding applications out there, and as impressive as large language models and the agents they enable have become, many of the most recent developments…
Brendan Carr and the Trump FCC are finalizing plans to illegally eliminate what’s left of the country’s already barely functional media consolidation limits; a specific gift to Trump-friendly right wing…
A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come…
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ…
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving…