
Apple just cut 147 Bay Area jobs — and Vision Pro's gaming team is basically gone
A WARN filing shows Apple slashing Siri and Vision Pro roles as it redirects the team toward smart glasses instead of headset gaming.
Priya Nair · 15h ago · 7 min
Software & Systems Editor · since 2020
Priya has daily-driven more Linux distros than she can name and treats her setup like a workshop. She covers the operating systems, apps and settings worth your time — and cheerfully calls out the 'optimizations' that just quietly break your machine.

A WARN filing shows Apple slashing Siri and Vision Pro roles as it redirects the team toward smart glasses instead of headset gaming.
Priya Nair · 15h ago · 7 min

The JWT auth bypass we told you about two weeks ago just got its second half: a working RCE chain, two public PoCs, and active probing as of this week.
Priya Nair · 21h ago · 7 min

Check Point caught the exploit chain in the wild before Microsoft's own August Patch Tuesday shipped the fix — and this one installs a kernel-mode rootkit.
Priya Nair · 1d ago · 6 min

Three weeks after the last NetScaler patch-now story, Citrix is back with a critical bug that needs no password and no user interaction at all.
Priya Nair · 1d ago · 6 min

A bug that lets anyone with a free account plant a git hook is now CISA's problem — and it started with a cryptominer, not a headline.
Priya Nair · 1d ago · 6 min

Payouts King says it walked off with 27 terabytes from Turner Construction — including files it claims are covered by U.S. arms-export law. Turner took seven weeks to tell anyone.
Priya Nair · 2d ago · 7 min

Two critical bugs let anyone overwrite Git hooks and run code on your server — and for once, the fix shipped before it turned into the usual Gogs mess.
Priya Nair · 2d ago · 6 min

A single API endpoint let anyone become an administrator on thousands of self-hosted Metabase servers, and Framework, n8n and Kilo Code already got hit before the patch even shipped.
Priya Nair · 3d ago · 7 min

The ransomware gang gave itself two weeks and gave the bank exactly nothing to substantiate the claim — and that gap between accusation and evidence is the actual story here.
Priya Nair · 3d ago · 6 min

CVE-2026-65400 let anyone on the network log into a Mac as root with zero credentials. Apple patched it August 6. Attackers were already inside, planting a cryptominer.
Priya Nair · 4d ago · 6 min

CVE-2026-8037 lets anyone run root commands on Kemp LoadMaster appliances with zero credentials — and 792 attack attempts from 65 IP addresses landed before it made the federal watch list.
Priya Nair · 4d ago · 6 min

CVE-2026-20349 doesn't steal your data. It just reboots your VPN gateway on command, and Cisco's already watching it happen in the wild.
Priya Nair · 4d ago · 6 min

A DeepSeek-powered agent tried to hack 460+ systems on its own, including a Windows VPN bug rated CVSS 9.8 — and got shut out everywhere authentication actually worked.
Priya Nair · 4d ago · 7 min

GuidePoint's threat intel team says the 'recovery firm' emailing breached companies with a $60,000 fix is running the same infrastructure as the original attack.
Priya Nair · 4d ago · 6 min

CVE-2026-69414 lets a local attacker walk straight to SYSTEM through Windows Defender itself, there's still no fix nine days after the CVE was assigned, and CISA just started a clock on it.
Priya Nair · 4d ago · 6 min

CERT Polska is warning that attackers are actively exploiting an unauthenticated command-injection bug in Zimbra's SNMP monitoring component — one Zimbra quietly fixed five weeks ago, in version 10.1.20.
Priya Nair · 5d ago · 6 min

GitLab's emergency patch fixes a code-injection bug that let an unauthenticated attacker delete repositories, forge merge records, or ban maintainers in one HTTP request — and researchers reproduced it within minutes of the advisory going live.
Priya Nair · 5d ago · 6 min

A maximum-severity remote code execution bug in the identity system behind every Microsoft 365 login got tagged 'exploited in the wild' on Thursday morning — and un-tagged by evening, right after reporters started asking questions.
Priya Nair · 5d ago · 6 min

Amazon, Microsoft, Meta and Oracle have cut over 100,000 jobs since 2022. For visa holders, a layoff starts a 60-day clock to find new sponsorship or leave the country — and some aren't waiting to find out if they're next.
Priya Nair · Aug 20 · 7 min

A file-upload field and a dropdown, sitting on the same form, are all it takes for an unauthenticated attacker to plant PHP code on your site. The fix has existed since July 31 — most sites just haven't installed it.
Priya Nair · Aug 20 · 6 min

Microsoft patched this JWT flaw back in July. A public proof-of-concept turned it into real attacks in under 48 hours — here's exactly what's broken and how to check if you're exposed.
Priya Nair · Aug 20 · 6 min

More than 40 companies have been named so far in a campaign that chains two flaws in PTC's Windchill and FlexPLM software into unauthenticated remote code execution.
Priya Nair · Aug 20 · 8 min

CVE-2026-58231 scores a maximum 10.0 — and honeypots caught real exploitation attempts before most companies even applied the fix.
Priya Nair · Aug 20 · 7 min

Pending home sales in Seattle fell 15.6% in a single month — the worst drop of any major U.S. metro — and realtors say it's fear of layoffs, not rates.
Priya Nair · Aug 18 · 7 min

CVE-2026-62893 lets an unauthenticated attacker take over any exposed Windows Deployment Services box — and admins who patched it are now watching PXE boot and MDT deployments break instead.
Priya Nair · Aug 18 · 7 min

CVE-2026-48362, CVE-2026-71398 and CVE-2026-27302 all score a maximum 10.0 — unauthenticated, no clicks needed, full remote takeover. Here's exactly what's broken and what fixes it.
Priya Nair · Aug 18 · 7 min

Adobe just patched a 9.1 in Commerce and Magento that needs zero credentials to exploit — and it rated the fix Priority 2, not the top tier.
Priya Nair · Aug 17 · 6 min

CVE-2026-62911 only scores an 8.0, but it came with working exploit code demonstrated at Pwn2Own Berlin — and it doesn't stop at one mailbox.
Priya Nair · Aug 17 · 7 min

GeoServer's jsonArrayContains function scored a 9.8, needed zero credentials, and WatchTowr watched the exploitation start within hours of the tweet that disclosed it.
Priya Nair · Aug 17 · 6 min

CVE-2026-62878 is a 9.8-severity, zero-click hole in Windows DNS Server. Microsoft rates it 'exploitation less likely.' The researchers who track these for a living aren't so sure.
Priya Nair · Aug 16 · 6 min