<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>Comments on: Cyber security news June 2026</title>
	<atom:link href="http://www.epanorama.net/blog/2026/06/03/cyber-security-news-june-2026/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.epanorama.net/blog/2026/06/03/cyber-security-news-june-2026/</link>
	<description>All about electronics and circuit design</description>
	<lastBuildDate>Fri, 26 Jun 2026 22:38:27 +0000</lastBuildDate>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.9.14</generator>
	<item>
		<title>By: Tomi Engdahl</title>
		<link>https://www.epanorama.net/blog/2026/06/03/cyber-security-news-june-2026/comment-page-3/#comment-1880615</link>
		<dc:creator><![CDATA[Tomi Engdahl]]></dc:creator>
		<pubDate>Fri, 26 Jun 2026 22:37:28 +0000</pubDate>
		<guid isPermaLink="false">https://www.epanorama.net/blog/?p=199741#comment-1880615</guid>
		<description><![CDATA[A cybersecurity researcher uncovered two authentication flaws in Johnson &amp; Johnson web applications: https://cnews.link/johnson-johnson-internal-system-hack/]]></description>
		<content:encoded><![CDATA[<p>A cybersecurity researcher uncovered two authentication flaws in Johnson &amp; Johnson web applications: <a href="https://cnews.link/johnson-johnson-internal-system-hack/" rel="nofollow">https://cnews.link/johnson-johnson-internal-system-hack/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tomi Engdahl</title>
		<link>https://www.epanorama.net/blog/2026/06/03/cyber-security-news-june-2026/comment-page-3/#comment-1880588</link>
		<dc:creator><![CDATA[Tomi Engdahl]]></dc:creator>
		<pubDate>Fri, 26 Jun 2026 13:12:08 +0000</pubDate>
		<guid isPermaLink="false">https://www.epanorama.net/blog/?p=199741#comment-1880588</guid>
		<description><![CDATA[Anna Bawden / The Guardian:
A study of 408 teens in Australia finds 80%+ were still using social media three months after a ban came into force, citing inadequate age verification checks

Four in five under-16s in Australia using social media despite ban, study shows
https://www.theguardian.com/media/2026/jun/24/australia-under-16-social-media-ban-no-substantial-effects-study

Experts say law not enough to stop children accessing harmful content online and more ‘convincing strategy is required’

More than 80% of under-16s in Australia said they were still using social media three months after legislation banning them from it came into force, research shows.

Australia is the first country to ban social media for children. Since December 2025, under-16s have been prohibited from having accounts with many social media platforms including TikTok, X, Facebook, Instagram, YouTube and Snapchat.

But an observational study of 408 12- to 17-year-olds by the country’s University of Newcastle has concluded that Australia’s social media minimum age legislation has resulted in “limited implementation, incomplete compliance, and substantial circumvention of social media restrictions”.

“Overall, we found insufficient evidence to conclude that exposure to the act [of parliament] had any early substantial effects on social media use among adolescents aged under 16 years,” the authors added.

The findings have implications for growing numbers of countries in the process of introducing their own bans. The UK’s proposed social media ban, due to come into force in 2027, would block under-16s from accessing Snapchat, TikTok, YouTube, Instagram, X and Facebook and from livestreaming or communicating with strangers on gaming sites such as Roblox.

But experts and campaigners say the research, published in the BMJ, shows that banning social media is not enough to stop children accessing harmful content online and that a more “convincing strategy is required”.

The Australian study found a minimal reduction in daily social media usage three months after the ban. A major factor in teenagers’ continued use of banned social platforms was inadequate age verification checks. About 85% of teenagers said they were still using social media three months after the ban, with more than half using their own accounts.

Although two-thirds of teenagers in the study said they had to complete age verification checks, only 5% of 12- to 13-year-olds and 11% of 14- to 15-year-olds had to provide a photo of official ID. The two most common checks were asking teens their age and uploading a selfie.

A significant minority of participants said they actively bypassed the age restrictions. About 15% of the 12- to 13-year-olds and 19% of the 14- to 15-year-olds surveyed said they used a fake account, while about 3% said they used a VPN.

The study concluded that the Australian social media ban might be more effective in preventing or delaying access to social media in children under eight, rather than restricting access to adolescents who already use it.

Andy Burrows, the chief executive of the Molly Rose Foundation in the UK, said the findings showed that social media bans alone do not keep under-16s off restricted platforms or cut the time teenagers spend using high-risk sites.]]></description>
		<content:encoded><![CDATA[<p>Anna Bawden / The Guardian:<br />
A study of 408 teens in Australia finds 80%+ were still using social media three months after a ban came into force, citing inadequate age verification checks</p>
<p>Four in five under-16s in Australia using social media despite ban, study shows<br />
<a href="https://www.theguardian.com/media/2026/jun/24/australia-under-16-social-media-ban-no-substantial-effects-study" rel="nofollow">https://www.theguardian.com/media/2026/jun/24/australia-under-16-social-media-ban-no-substantial-effects-study</a></p>
<p>Experts say law not enough to stop children accessing harmful content online and more ‘convincing strategy is required’</p>
<p>More than 80% of under-16s in Australia said they were still using social media three months after legislation banning them from it came into force, research shows.</p>
<p>Australia is the first country to ban social media for children. Since December 2025, under-16s have been prohibited from having accounts with many social media platforms including TikTok, X, Facebook, Instagram, YouTube and Snapchat.</p>
<p>But an observational study of 408 12- to 17-year-olds by the country’s University of Newcastle has concluded that Australia’s social media minimum age legislation has resulted in “limited implementation, incomplete compliance, and substantial circumvention of social media restrictions”.</p>
<p>“Overall, we found insufficient evidence to conclude that exposure to the act [of parliament] had any early substantial effects on social media use among adolescents aged under 16 years,” the authors added.</p>
<p>The findings have implications for growing numbers of countries in the process of introducing their own bans. The UK’s proposed social media ban, due to come into force in 2027, would block under-16s from accessing Snapchat, TikTok, YouTube, Instagram, X and Facebook and from livestreaming or communicating with strangers on gaming sites such as Roblox.</p>
<p>But experts and campaigners say the research, published in the BMJ, shows that banning social media is not enough to stop children accessing harmful content online and that a more “convincing strategy is required”.</p>
<p>The Australian study found a minimal reduction in daily social media usage three months after the ban. A major factor in teenagers’ continued use of banned social platforms was inadequate age verification checks. About 85% of teenagers said they were still using social media three months after the ban, with more than half using their own accounts.</p>
<p>Although two-thirds of teenagers in the study said they had to complete age verification checks, only 5% of 12- to 13-year-olds and 11% of 14- to 15-year-olds had to provide a photo of official ID. The two most common checks were asking teens their age and uploading a selfie.</p>
<p>A significant minority of participants said they actively bypassed the age restrictions. About 15% of the 12- to 13-year-olds and 19% of the 14- to 15-year-olds surveyed said they used a fake account, while about 3% said they used a VPN.</p>
<p>The study concluded that the Australian social media ban might be more effective in preventing or delaying access to social media in children under eight, rather than restricting access to adolescents who already use it.</p>
<p>Andy Burrows, the chief executive of the Molly Rose Foundation in the UK, said the findings showed that social media bans alone do not keep under-16s off restricted platforms or cut the time teenagers spend using high-risk sites.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tomi Engdahl</title>
		<link>https://www.epanorama.net/blog/2026/06/03/cyber-security-news-june-2026/comment-page-3/#comment-1880586</link>
		<dc:creator><![CDATA[Tomi Engdahl]]></dc:creator>
		<pubDate>Fri, 26 Jun 2026 12:14:43 +0000</pubDate>
		<guid isPermaLink="false">https://www.epanorama.net/blog/?p=199741#comment-1880586</guid>
		<description><![CDATA[Japan defense forces used USB drives with China-linked virus: Nikkei investigation
Counterfeit memory sticks infected computers that had access to classified information
https://asia.nikkei.com/spotlight/cybersecurity/japan-defense-forces-used-usb-drives-with-china-linked-virus-nikkei-investigation?fbclid=IwdGRjcASrPihjbGNrBKs-CmV4dG4DYWVtAjExAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHrNCUPXkZy9YXlVKMEcqJDvesxqrw4mk3zcy5b7ViPv5k85DfU-FIlSL_dzp_aem_zP-xuJWTBKoRQwgL3GrDAg&amp;utm_id=97757_v0_s00_e0_tv2_a1dennhauzt6ff]]></description>
		<content:encoded><![CDATA[<p>Japan defense forces used USB drives with China-linked virus: Nikkei investigation<br />
Counterfeit memory sticks infected computers that had access to classified information<br />
<a href="https://asia.nikkei.com/spotlight/cybersecurity/japan-defense-forces-used-usb-drives-with-china-linked-virus-nikkei-investigation?fbclid=IwdGRjcASrPihjbGNrBKs-CmV4dG4DYWVtAjExAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHrNCUPXkZy9YXlVKMEcqJDvesxqrw4mk3zcy5b7ViPv5k85DfU-FIlSL_dzp_aem_zP-xuJWTBKoRQwgL3GrDAg&#038;utm_id=97757_v0_s00_e0_tv2_a1dennhauzt6ff" rel="nofollow">https://asia.nikkei.com/spotlight/cybersecurity/japan-defense-forces-used-usb-drives-with-china-linked-virus-nikkei-investigation?fbclid=IwdGRjcASrPihjbGNrBKs-CmV4dG4DYWVtAjExAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHrNCUPXkZy9YXlVKMEcqJDvesxqrw4mk3zcy5b7ViPv5k85DfU-FIlSL_dzp_aem_zP-xuJWTBKoRQwgL3GrDAg&#038;utm_id=97757_v0_s00_e0_tv2_a1dennhauzt6ff</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tomi Engdahl</title>
		<link>https://www.epanorama.net/blog/2026/06/03/cyber-security-news-june-2026/comment-page-3/#comment-1880572</link>
		<dc:creator><![CDATA[Tomi Engdahl]]></dc:creator>
		<pubDate>Fri, 26 Jun 2026 08:07:04 +0000</pubDate>
		<guid isPermaLink="false">https://www.epanorama.net/blog/?p=199741#comment-1880572</guid>
		<description><![CDATA[Vulnerabilities
Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs
https://www.securityweek.com/critical-ubiquiti-vulnerabilities-in-attackers-crosshairs/

The flaws allow remote, unauthenticated attackers to make system changes, access underlying accounts, and inject commands.


CISA KEV	

Threat actors have been targeting three critical-severity vulnerabilities in Ubiquiti devices, the US cybersecurity agency CISA warns.

The exploited flaws, tracked as CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, with a CVSS score of 10/10, were patched last month.

CVE-2026-34908 is described as an improper access control issue that could allow remote attackers to make unauthorized changes to vulnerable UniFi OS devices.

CVE-2026-34909 is a path traversal defect that could be exploited to access files on the underlying operating system and manipulate them to access underlying accounts.

CVE-2026-34910 is described as an improper input validation weakness that allows attackers to execute command injection attacks over the network. A variant of the flaw, tracked as CVE-2026-33000 (CVSS score of 9.1), requires authentication.]]></description>
		<content:encoded><![CDATA[<p>Vulnerabilities<br />
Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs<br />
<a href="https://www.securityweek.com/critical-ubiquiti-vulnerabilities-in-attackers-crosshairs/" rel="nofollow">https://www.securityweek.com/critical-ubiquiti-vulnerabilities-in-attackers-crosshairs/</a></p>
<p>The flaws allow remote, unauthenticated attackers to make system changes, access underlying accounts, and inject commands.</p>
<p>CISA KEV	</p>
<p>Threat actors have been targeting three critical-severity vulnerabilities in Ubiquiti devices, the US cybersecurity agency CISA warns.</p>
<p>The exploited flaws, tracked as CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, with a CVSS score of 10/10, were patched last month.</p>
<p>CVE-2026-34908 is described as an improper access control issue that could allow remote attackers to make unauthorized changes to vulnerable UniFi OS devices.</p>
<p>CVE-2026-34909 is a path traversal defect that could be exploited to access files on the underlying operating system and manipulate them to access underlying accounts.</p>
<p>CVE-2026-34910 is described as an improper input validation weakness that allows attackers to execute command injection attacks over the network. A variant of the flaw, tracked as CVE-2026-33000 (CVSS score of 9.1), requires authentication.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tomi Engdahl</title>
		<link>https://www.epanorama.net/blog/2026/06/03/cyber-security-news-june-2026/comment-page-3/#comment-1880571</link>
		<dc:creator><![CDATA[Tomi Engdahl]]></dc:creator>
		<pubDate>Fri, 26 Jun 2026 08:06:27 +0000</pubDate>
		<guid isPermaLink="false">https://www.epanorama.net/blog/?p=199741#comment-1880571</guid>
		<description><![CDATA[FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances
https://www.securityweek.com/ffmpeg-pixelsmash-flaw-allows-rce-on-video-players-media-servers-nas-appliances/

Attackers can send crafted media files to execute code in any application that uses FFmpeg’s libavcodec library.]]></description>
		<content:encoded><![CDATA[<p>FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances<br />
<a href="https://www.securityweek.com/ffmpeg-pixelsmash-flaw-allows-rce-on-video-players-media-servers-nas-appliances/" rel="nofollow">https://www.securityweek.com/ffmpeg-pixelsmash-flaw-allows-rce-on-video-players-media-servers-nas-appliances/</a></p>
<p>Attackers can send crafted media files to execute code in any application that uses FFmpeg’s libavcodec library.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tomi Engdahl</title>
		<link>https://www.epanorama.net/blog/2026/06/03/cyber-security-news-june-2026/comment-page-3/#comment-1880557</link>
		<dc:creator><![CDATA[Tomi Engdahl]]></dc:creator>
		<pubDate>Fri, 26 Jun 2026 07:52:46 +0000</pubDate>
		<guid isPermaLink="false">https://www.epanorama.net/blog/?p=199741#comment-1880557</guid>
		<description><![CDATA[Zac Bowden / Windows Central: 	
Microsoft quietly extends the Extended Security Updates program for Windows 10 consumers by a year, letting eligible users get updates through October 12, 2027  —  Windows 10&#039;s ESU program has been quietly extended by an extra year, now ending on October 12, 2027 instead of October 2026.

Microsoft quietly extends Windows 10&#039;s extra security updates program for free: Users can now stay on Windows 10 until October 2027 securely
https://www.windowscentral.com/microsoft/windows-10/microsoft-quietly-extends-windows-10s-extra-security-updates-program-for-free-users-can-now-stay-on-windows-10-until-october-2027-securely

Microsoft has quietly announced that Windows 10&#039;s extended support updates program will continue for an extra year, now until October 2027 for free if you sign-in to Windows 10 with a Microsoft account.

Originally, Windows 10&#039;s extended support program was only supposed to last one year, until October 2026 for consumers. However, a new support page published by Microsoft today has confirmed that the Windows 10 ESU program will now last until October 2027 instead.]]></description>
		<content:encoded><![CDATA[<p>Zac Bowden / Windows Central:<br />
Microsoft quietly extends the Extended Security Updates program for Windows 10 consumers by a year, letting eligible users get updates through October 12, 2027  —  Windows 10&#8242;s ESU program has been quietly extended by an extra year, now ending on October 12, 2027 instead of October 2026.</p>
<p>Microsoft quietly extends Windows 10&#8242;s extra security updates program for free: Users can now stay on Windows 10 until October 2027 securely<br />
<a href="https://www.windowscentral.com/microsoft/windows-10/microsoft-quietly-extends-windows-10s-extra-security-updates-program-for-free-users-can-now-stay-on-windows-10-until-october-2027-securely" rel="nofollow">https://www.windowscentral.com/microsoft/windows-10/microsoft-quietly-extends-windows-10s-extra-security-updates-program-for-free-users-can-now-stay-on-windows-10-until-october-2027-securely</a></p>
<p>Microsoft has quietly announced that Windows 10&#8242;s extended support updates program will continue for an extra year, now until October 2027 for free if you sign-in to Windows 10 with a Microsoft account.</p>
<p>Originally, Windows 10&#8242;s extended support program was only supposed to last one year, until October 2026 for consumers. However, a new support page published by Microsoft today has confirmed that the Windows 10 ESU program will now last until October 2027 instead.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tomi Engdahl</title>
		<link>https://www.epanorama.net/blog/2026/06/03/cyber-security-news-june-2026/comment-page-3/#comment-1880549</link>
		<dc:creator><![CDATA[Tomi Engdahl]]></dc:creator>
		<pubDate>Fri, 26 Jun 2026 07:43:55 +0000</pubDate>
		<guid isPermaLink="false">https://www.epanorama.net/blog/?p=199741#comment-1880549</guid>
		<description><![CDATA[Jättiyllätys Windows-käyttäjille
Windows 10:n tukiaika jatkuu lokakuuhun 2027.
https://www.iltalehti.fi/digiuutiset/a/6123bea2-47dd-4bf6-ad22-aad1728c156f

Käytätkö yhä Windows 10:tä? Sait juuri vuoden lisää käyttöaikaa. Alun perin Windows 10 -päivitysten piti päättyä viimeistään 13. lokakuuta vuonna 2026, mutta Microsoft on yllättäen päättänyt jatkaa käyttöjärjestelmän tukemista ylimääräisellä vuodella.

Windows 10 julkaistiin vuonna 2015, ja vaikka monet ehtivät julistaa sitä Microsoftin viimeiseksi Windows-versioksi, ei yhtiö todellisuudessa koskaan sanonut niin.

Siksi monille oli yllätys, kun yhtiö vuonna 2021 julkaisi Windows 11:n.

Windows 10:n markkinaosuus on yhä niin suuri, että Microsoft oli pakotettu jatkamaan käyttöjärjestelmän tukemista ylimääräisellä vuodella.

Windows 11 ei ole noussut sellaiseen suosioon, jota yhtiö on siltä odottanut, joten Microsoft oli lopulta pakotettu jatkamaan Windows 10:n tukemista pitkin hampain, Windows Latest spekuloi.

Nyt yhtiö yllätti Windows 10:n käyttäjät uudelleen. Microsoft vahvistaa Windows Latest -sivustolle, että sen Windowsin tukisivulle lisäämä vuosiluku ei ole kirjoitusvirhe: Windows 10:n tuki todella jatkuu lokakuuhun 2027.]]></description>
		<content:encoded><![CDATA[<p>Jättiyllätys Windows-käyttäjille<br />
Windows 10:n tukiaika jatkuu lokakuuhun 2027.<br />
<a href="https://www.iltalehti.fi/digiuutiset/a/6123bea2-47dd-4bf6-ad22-aad1728c156f" rel="nofollow">https://www.iltalehti.fi/digiuutiset/a/6123bea2-47dd-4bf6-ad22-aad1728c156f</a></p>
<p>Käytätkö yhä Windows 10:tä? Sait juuri vuoden lisää käyttöaikaa. Alun perin Windows 10 -päivitysten piti päättyä viimeistään 13. lokakuuta vuonna 2026, mutta Microsoft on yllättäen päättänyt jatkaa käyttöjärjestelmän tukemista ylimääräisellä vuodella.</p>
<p>Windows 10 julkaistiin vuonna 2015, ja vaikka monet ehtivät julistaa sitä Microsoftin viimeiseksi Windows-versioksi, ei yhtiö todellisuudessa koskaan sanonut niin.</p>
<p>Siksi monille oli yllätys, kun yhtiö vuonna 2021 julkaisi Windows 11:n.</p>
<p>Windows 10:n markkinaosuus on yhä niin suuri, että Microsoft oli pakotettu jatkamaan käyttöjärjestelmän tukemista ylimääräisellä vuodella.</p>
<p>Windows 11 ei ole noussut sellaiseen suosioon, jota yhtiö on siltä odottanut, joten Microsoft oli lopulta pakotettu jatkamaan Windows 10:n tukemista pitkin hampain, Windows Latest spekuloi.</p>
<p>Nyt yhtiö yllätti Windows 10:n käyttäjät uudelleen. Microsoft vahvistaa Windows Latest -sivustolle, että sen Windowsin tukisivulle lisäämä vuosiluku ei ole kirjoitusvirhe: Windows 10:n tuki todella jatkuu lokakuuhun 2027.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tomi Engdahl</title>
		<link>https://www.epanorama.net/blog/2026/06/03/cyber-security-news-june-2026/comment-page-3/#comment-1880543</link>
		<dc:creator><![CDATA[Tomi Engdahl]]></dc:creator>
		<pubDate>Fri, 26 Jun 2026 05:52:29 +0000</pubDate>
		<guid isPermaLink="false">https://www.epanorama.net/blog/?p=199741#comment-1880543</guid>
		<description><![CDATA[ChatGPT:n vastauksessa voi olla yllättävä ansa – näin uusi huijaustekniikka toimii
Luotatko tekoälyavustajaan? Mieti uudelleen.
ChatGPT:n vastauksessa voi olla yllättävä ansa – näin uusi huijaustekniikka toimii
https://www.is.fi/digitoday/tietoturva/art-2000012094664.html

Tietoja kalastelevien tahojen tekniikoista on paljastunut uutta tietoa. Tällä kertaa kyse on tekoälyavustajien valjastamisesta tietojenkalastelutarkoituksiin tai niin sanotusta chatgphishingista.

Huijaus perustuu siihen, että tekoälyavustajat, kuten ChatGPT, eivät välttämättä tunnista verkkosivuille piilotettuja tietojenkalastelulinkkejä turvallisten linkkien seasta. Näin ollen jos kielimallia pyytää tekemään yhteenvedon sivustosta, jolle kyseisiä linkkejä on piilotettu, se saattaa toistaa ne täysin huijarin ohjeiden mukaisesti.

Tietoturva-aukko selvisi kyberturvallisuusyhtiö Permison selvityksessä. Yhtiö loi verkkosivun, jonka metatietoihin se oli piilottanut ohjeet valheellisen tietoturvahälytyksen toistamiseksi.

Kun se sitten pyysi ChatGPT:tä luomaan yhteenvedon sivustosta, toisti tekoäly hälytysilmoituksen vastauksensa lopussa linkkeineen kaikkineen. Käyttäjän silmään ilmoitus näytti puolestaan siltä, kuin alusta itse olisi lähettänyt ilmoituksen.

Vastaavaa on nähty aiemmin Gmailissa, jonka tekemiä tiivistelmiä on ”myrkytetty”vastaanottajien huijaamiseksi.]]></description>
		<content:encoded><![CDATA[<p>ChatGPT:n vastauksessa voi olla yllättävä ansa – näin uusi huijaustekniikka toimii<br />
Luotatko tekoälyavustajaan? Mieti uudelleen.<br />
ChatGPT:n vastauksessa voi olla yllättävä ansa – näin uusi huijaustekniikka toimii<br />
<a href="https://www.is.fi/digitoday/tietoturva/art-2000012094664.html" rel="nofollow">https://www.is.fi/digitoday/tietoturva/art-2000012094664.html</a></p>
<p>Tietoja kalastelevien tahojen tekniikoista on paljastunut uutta tietoa. Tällä kertaa kyse on tekoälyavustajien valjastamisesta tietojenkalastelutarkoituksiin tai niin sanotusta chatgphishingista.</p>
<p>Huijaus perustuu siihen, että tekoälyavustajat, kuten ChatGPT, eivät välttämättä tunnista verkkosivuille piilotettuja tietojenkalastelulinkkejä turvallisten linkkien seasta. Näin ollen jos kielimallia pyytää tekemään yhteenvedon sivustosta, jolle kyseisiä linkkejä on piilotettu, se saattaa toistaa ne täysin huijarin ohjeiden mukaisesti.</p>
<p>Tietoturva-aukko selvisi kyberturvallisuusyhtiö Permison selvityksessä. Yhtiö loi verkkosivun, jonka metatietoihin se oli piilottanut ohjeet valheellisen tietoturvahälytyksen toistamiseksi.</p>
<p>Kun se sitten pyysi ChatGPT:tä luomaan yhteenvedon sivustosta, toisti tekoäly hälytysilmoituksen vastauksensa lopussa linkkeineen kaikkineen. Käyttäjän silmään ilmoitus näytti puolestaan siltä, kuin alusta itse olisi lähettänyt ilmoituksen.</p>
<p>Vastaavaa on nähty aiemmin Gmailissa, jonka tekemiä tiivistelmiä on ”myrkytetty”vastaanottajien huijaamiseksi.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tomi Engdahl</title>
		<link>https://www.epanorama.net/blog/2026/06/03/cyber-security-news-june-2026/comment-page-3/#comment-1880521</link>
		<dc:creator><![CDATA[Tomi Engdahl]]></dc:creator>
		<pubDate>Thu, 25 Jun 2026 21:32:39 +0000</pubDate>
		<guid isPermaLink="false">https://www.epanorama.net/blog/?p=199741#comment-1880521</guid>
		<description><![CDATA[https://www.facebook.com/share/1CoWJkJGSp/

Microsoft secure boot key expiring this september: What Linux users need to know
Linux systems using Secure Boot rely on a Microsoft signed &quot;shim&quot; bootloader. The current key expires in September, after which Microsoft will no longer use it to sign new bootloaders. While a replacement key has been available since 2023, it is missing from many systems. Fixing this requires a firmware update from hardware vendors, which isn&#039;t guaranteed for older devices. 

The bottom line: Most modern systems should transition smoothly, but some users and Linux distributions will face extra manual work to keep Secure Boot functioning. See your distors wiki or mailing list for more info.]]></description>
		<content:encoded><![CDATA[<p><a href="https://www.facebook.com/share/1CoWJkJGSp/" rel="nofollow">https://www.facebook.com/share/1CoWJkJGSp/</a></p>
<p>Microsoft secure boot key expiring this september: What Linux users need to know<br />
Linux systems using Secure Boot rely on a Microsoft signed &#8220;shim&#8221; bootloader. The current key expires in September, after which Microsoft will no longer use it to sign new bootloaders. While a replacement key has been available since 2023, it is missing from many systems. Fixing this requires a firmware update from hardware vendors, which isn&#8217;t guaranteed for older devices. </p>
<p>The bottom line: Most modern systems should transition smoothly, but some users and Linux distributions will face extra manual work to keep Secure Boot functioning. See your distors wiki or mailing list for more info.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tomi Engdahl</title>
		<link>https://www.epanorama.net/blog/2026/06/03/cyber-security-news-june-2026/comment-page-3/#comment-1880498</link>
		<dc:creator><![CDATA[Tomi Engdahl]]></dc:creator>
		<pubDate>Thu, 25 Jun 2026 17:19:21 +0000</pubDate>
		<guid isPermaLink="false">https://www.epanorama.net/blog/?p=199741#comment-1880498</guid>
		<description><![CDATA[NVIDIA just told its grey market: good luck without us.

CEO Jensen Huang spoke at the company&#039;s shareholder meeting.

He said smuggled chips cannot build working AI data centres.

NVIDIA will not provide support, software, or repairs for them.

If you buy diverted hardware, it may never run at scale.

Smuggled B300 servers in China already cost $1M each.

One executive was charged with routing $2.5B in servers to China.

Huang is telling buyers that smuggled hardware is a dead end.

Read more on TNW: https://thenextweb.com/news/nvidia-huang-national-security-smuggled-chips-dead-end]]></description>
		<content:encoded><![CDATA[<p>NVIDIA just told its grey market: good luck without us.</p>
<p>CEO Jensen Huang spoke at the company&#8217;s shareholder meeting.</p>
<p>He said smuggled chips cannot build working AI data centres.</p>
<p>NVIDIA will not provide support, software, or repairs for them.</p>
<p>If you buy diverted hardware, it may never run at scale.</p>
<p>Smuggled B300 servers in China already cost $1M each.</p>
<p>One executive was charged with routing $2.5B in servers to China.</p>
<p>Huang is telling buyers that smuggled hardware is a dead end.</p>
<p>Read more on TNW: <a href="https://thenextweb.com/news/nvidia-huang-national-security-smuggled-chips-dead-end" rel="nofollow">https://thenextweb.com/news/nvidia-huang-national-security-smuggled-chips-dead-end</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
