Diagnostic dilemma: One man’s back pain led to the discovery of a third kidney

Patient: 31-year-old male from Wardha, India Symptoms: A man presented to the medical center after experiencing pain on the right side of his lower back, a burning sensation when urinating, and a fever of over 102.2 degrees Fahrenheit (39 degrees Celsius) for five days. What Happened Next: During a physical exam, the doctor noticed that […]
Bug in Ubuntu CVE-2026-3888 allows attackers to gain root by exploiting systemd cleanup timing

Ravi LakshmananMarch 18, 2026Linux / Endpoint security A high-severity security flaw affecting the default installation of Ubuntu Desktop versions 24.04 and later could be exploited to escalate privileges to the root level. This issue, tracked as CVE-2026-3888 (CVSS score: 7.8), could allow an attacker to gain control of a susceptible system. “This flaw (CVE-2026-3888) allows […]
Apple fixes WebKit vulnerability that allows same-origin policy bypass on iOS and macOS

Ravi LakshmananMarch 18, 2026Vulnerability/Zero-day Apple on Tuesday released the first round of background security improvements to address a security flaw in WebKit that affects iOS, iPadOS, and macOS. The vulnerability, tracked as CVE-2026-20643 (CVSS score: N/A), is described as a cross-origin issue in WebKit’s Navigation API that can be exploited to bypass the same-origin policy […]
Critical flaw in unpatched Telnetd (CVE-2026-32746) enables unauthenticated route RCE over port 23

Ravi LakshmananMarch 18, 2026Vulnerability/Data Protection Cybersecurity researchers have uncovered a critical security flaw affecting the GNU InetUtils Telnet daemon (telnetd). This flaw could be exploited by an unauthenticated, remote attacker to execute arbitrary code with elevated privileges. This vulnerability is tracked as CVE-2026-32746 and has a CVSS score of 9.8 out of 10.0. This is […]
Arizona makes first criminal charge for “illegal gambling business”; legal troubles pile up for Karsi

Arizona Attorney General Chris Mays has filed criminal charges against prediction market platform Kalsi for allegedly operating an illegal gambling operation without a license in the state and engaging in election gambling. A 20-count complaint filed Tuesday in Maricopa County Court accuses the company of engaging in unlicensed gambling operations, alleging that the site “accepted […]
Mistral bets on “building its own AI” to compete with OpenAI, the human presence in the enterprise

Most enterprise AI projects fail not because companies lack the technology, but because the models they use don’t understand their business. Models are often trained on the internet rather than on decades of internal documentation, workflows, and organizational knowledge. French AI startup Mistral sees opportunity in this gap. The company on Tuesday announced Mistral Forge, […]
Why is Garry Tan’s Claude Code setting so loved and hated?

Garry Tan, Y Combinator’s famous CEO, told an audience at SXSW that he suffers from “cyber psychosis” and is so excited about working with AI agents that he can barely sleep. “I’m sleeping about four hours a night now,” he told fellow interviewer VC Bill Gurley in an on-stage interview Saturday. “I have cyberpsychosis, and […]
Apple rolls out first ‘background security’ update to iPhone, iPad, Mac to fix Safari bugs

Apple has rolled out its first “Background Security Improvements” update that patches security bugs in the Safari web browser on iPhone, iPad, and Mac. In a new security advisory posted Tuesday, Apple announced that security researchers have discovered a bug in WebKit, the browser engine that powers Safari and other apps. If exploited, this bug […]
Google’s data center power strategy attracts attention

Google may have signed on to President Trump’s weak power pledge, but it’s clear that the company began working on a framework for powering its data centers months ago. Google announced Thursday that it is working with Michigan utility DTE to add 2.7 gigawatts of “new resources” in the Detroit suburbs to power new data […]
AI flaws in Amazon Bedrock, LangSmith, and SGLang enable data breaches and RCEs

Cybersecurity researchers have detailed a new method for extracting sensitive data from artificial intelligence (AI) code execution environments using Domain Name System (DNS) queries. In a report published Monday, BeyondTrust revealed that Amazon Bedrock AgentCore Code Interpreter’s sandbox mode allows outbound DNS queries that attackers can exploit to enable an interactive shell and bypass network […]