Toys ‘R’ Us Canada Customer Information Leaked Online - SecurityWeek

Toys “R” Us Canada experienced a data breach where a threat actor stole and leaked customer information, including names, addresses, email addresses, and phone numbers, on the dark web. The company is notifying customers and authorities, but no sensitive information like passwords or credit card details was compromised.


Meta’s new free transformer

Standard Transformer models generate text purely autoregressively—each token is predicted based only on the previous tokens, like a stateless function where the only “memory” is the input sequence itself. The Free Transformer adds a learned latent variable layer in the middle of the network that acts like hidden internal state the model can condition on during generation. Think of it as giving the model a small amount of working memory (16 bits per token) to make implicit decisions about the generation strategy before committing to specific tokens. During training, an encoder network learns to set these latent variables appropriately for each training example (using a Variational Autoencoder framework), while during inference they’re sampled randomly—but the model has learned to use whatever random values it gets to organize its generation process more effectively. The practical result is that with only 3% additional overhead (one extra transformer block for the encoder), the model shows 3-11% improvements on complex tasks like code generation and mathematical reasoning, because it can effectively “plan” aspects of the output structure rather than having to reconstruct everything purely from the token sequence so far.​​​​​​​​​​​​​​​​

arxiv.org/pdf/2510….


GlassWorm Malware Targets Developers Through OpenVSX Marketplace – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More

The GlassWorm malware targets developers using Visual Studio Code extensions on the OpenVSX marketplace, spreading by hijacking trusted extensions and stealing credentials. It hides its malicious payload using invisible Unicode variation selectors and communicates through the Solana blockchain and Google Calendar.


Meta boosts scam protection on WhatsApp and Messenger | Malwarebytes

Meta has enhanced scam protection on WhatsApp and Messenger with new safeguards to protect users, especially the elderly, from scammers. Scams targeting the elderly have increased, with losses reaching $4.8 billion in 2024.


U.S. CISA adds Motex LANSCOPE flaw to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Motex LANSCOPE flaw, CVE-2025-61932, to its Known Exploited Vulnerabilities (KEV) catalog. Federal agencies must fix the vulnerability by November 12, 2025.


Exploitation of Critical Adobe Commerce Flaw Puts Many eCommerce Sites at Risk - SecurityWeek

Hackers are exploiting a critical-severity vulnerability in Adobe Commerce and Magento Open Source, tracked as CVE-2025-54236, with 250 attacks observed on Wednesday. Adobe released hotfixes on September 9, but less than half of the ecommerce sites have been patched.


PhantomCaptcha RAT Attack Targets Aid Groups Supporting Ukraine – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More

The PhantomCaptcha RAT attack targeted aid groups and Ukrainian government entities, using malicious PDFs and fake Cloudflare captcha pages to deploy a spying tool. This highly coordinated cyberattack lasted only 24 hours but showed meticulous planning and advanced evasion techniques.


Click, Call, Compromise: Hackers Continue to Evolve Tactics

Microsoft’s annual cyberthreat assessment reveals a 32% rise in identity-based attacks in 2025, primarily due to stolen credentials. Infostealers, traditionally post-exploitation tools, are now used as initial access payloads, fueling a cybercrime underground with specialized roles. Despite sophisticated counter-hacks, Microsoft emphasizes that multifactor authentication (MFA) can prevent over 99% of identity compromise attacks.


GM to Remove CarPlay from All Future Vehicles, Including Gas Cars - MacRumors

General Motors has decided to remove CarPlay from all future vehicles, including both electric and gas cars, to prioritize its own in-house infotainment system. GM CEO Mary Barra confirmed that new gas cars will not support smartphone projection for CarPlay or Android Auto.


Canada's Tech Sector: Beyond Catch-Up

The numbers tell a story Silicon Valley can’t ignore: Canada’s tech corridor is no longer just catching up — it’s carving out its own category.

When Geoffrey Hinton collected the 2024 Nobel Prize in Physics, the University of Toronto professor emeritus didn’t just validate decades of artificial intelligence research. He spotlighted what industry data now confirms: Toronto has become North America’s No. 3 tech market, with Waterloo Region joining the continent’s top tier; Montreal strengthens Canada’s position through AI research dominance.

Read More →


DuckDuckGo browser: privacy by default

In an online landscape often dominated by surveillance-based business models and data extraction, DuckDuckGo Browser stands out as a privacy-first alternative that prioritises simplicity and protection. For users seeking straightforward privacy without complex configurations, DuckDuckGo delivers — though its architecture and feature set differ from traditional browsers.

Read More →


The Uncomfortable Truth About China’s AI Dominance: How a Decade of Strategic Planning Is Reshaping the Technology Landscape

Let me be direct: while Silicon Valley has been celebrating incremental improvements and debating work-life balance, China has been executing a coordinated, decade-long strategy to dominate artificial intelligence — and it’s working. DeepSeek’s January 2025 breakthrough was not a fluke. It was the predictable result of national planning, structural advantages and a fundamentally different approach to technology.

Read More →


Orion Browser by Kagi: Privacy-centred performance

In a browser landscape dominated by data-hungry Chromium derivatives and restrictive ecosystems, Orion Browser by Kagi stands out as a WebKit-based alternative that prioritises verifiable zero telemetry, built-in content blocking, and native performance on Apple devices. For privacy-conscious users seeking Safari’s efficiency with Firefox’s extensibility and Chrome’s compatibility, Orion delivers—though not without trade-offs.

Read More →


Helium Browser: privacy-centred Chromium, without the extras

Helium is a new, open-source Chromium browser that ships with strong privacy defaults and a lean interface. It removes Google services, blocks trackers and third-party cookies by default, and avoids built-in sync and password vaults to keep the attack surface small. For security-minded users, it offers a disciplined starting point with fewer emissions out of the box.

Read More →


Archive.today: inside the web archiving service

When a web page disappears from the internet—deleted by its author, censored by a government or simply lost to time—one service has made it its mission to preserve those digital artefacts permanently. That service is archive.today, and its story reveals as much about the tensions of the modern internet as it does about the fragility of online information.

Read More →


Built to fail: the structural indicators that doom CISOs

If nearly a quarter of Fortune 500 chief information security officers last just one year in the role, we need to stop asking what’s wrong with CISOs—and start asking what’s wrong with how we set them up.

Read More →


Prompting Strategies to Reduce AI Sycophancy

Recent research has shown that many advanced AI systems tend to agree with users or offer flattering answers, even when those answers are incomplete or wrong. This behaviour—known as sycophancy—can increase overconfidence, reduce critical thinking and influence decision-making in subtle ways. The good news is that with the right prompt strategies, users can reduce these effects and get more balanced, useful responses from any AI model.

Read More →


Daily Cyber Threat Intelligence Briefing – Oct. 6, 2025

This post is part of our ongoing daily CTI briefing series, highlighting verified, high-impact cyber incidents from the past 48 hours. All entries meet strict inclusion criteria and have been validated across multiple authoritative sources to support operational decision-making and strategic situational awareness.

Read More →


AI Sycophancy: What the Latest Research Means for Cybersecurity and Privacy

New research from Stanford University, Carnegie Mellon University and the University of Oxford highlights a behavioural risk in today’s most advanced AI systems: sycophancy. This occurs when models agree with users or flatter them, even when they are wrong. The findings are relevant to anyone who relies on AI assistants for work, decision-making or communication.

Read More →


Cybersecurity in the Era of Agentic AI: Weaponization, Defences and Governance

Agentic artificial intelligence—systems that perceive, decide and act autonomously—has moved from laboratory theory to operational threat. Attackers and defenders alike now deploy autonomous agents that plan multi-step attacks, invoke tools and adapt in real time. The same capabilities that accelerate detection and response can also scale reconnaissance, social engineering and exploitation.

Read More →