Germany is drafting comprehensive legislation to significantly expand the surveillance and hacking authorities of its Federal Intelligence Service, aiming to reduce reliance on U.S. intelligence and align its capabilities with European peers like the UK and France, Cybernews reports.
The vulnerabilities, discovered by the AI security startup Cyata, include a path validation bypass (CVE-2025-68145), an unrestricted git_init issue (CVE-2025-68143), and an argument injection in git_diff (CVE-2025-68144).
Confer offers end-to-end encryption for AI conversations, ensuring that user interactions remain private and cannot be accessed, stored, or used for training by third parties, including Confer itself.
The vulnerabilities, CVE-2026-22218 (arbitrary file read) and CVE-2026-22219 (server-side request forgery), allow attackers to exfiltrate sensitive environment variables, including API keys, credentials, and cloud storage secrets.
This independent report by the Ponemon Institute, sponsored by OPSWAT, reveals that organizations face serious gaps in file security, with 61% reporting file-related security incidents over the past two years at an average cost of $2.7 million per organization. Insider threats, lack of visibility into file access, and vulnerability during uploads ...
In March 2025, a political advocacy group reportedly contacted two DOGE members at the Social Security Administration (SSA) with a request to analyze state voter rolls they had acquired, with the stated aim of finding evidence of voter fraud and overturning election results.