Latest
Updated 03:15 PM
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the sus…
Your Bose headphones are getting a major Bluetooth upgrade – what to expect
Key Bluetooth technologies and upgrades to USB-C audio are coming to the company’s flagship over-ears.
New Attack Against RSA
ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring. First, this attack isn’t new. The original research is from 2007. What is new is the implementation. Second, it is a forgery attack. It…
http-terminator – AI-Assisted HTTP Request-Smuggling Discovery
http-terminator is PortSwigger's AI pipeline for discovering HTTP request-smuggling bugs. Which stages run, its dependencies, and its testing limits.
The Insider You Built with author Camille Stewart Gloster. [Special Edition]
On this special edition podcast, N2K CyberWire's Dave Bittner spoke with Camille Stewart Gloster. Camille is the author of The Insider You Built: How Organizations Stay in Control of Autonomous AI Agents, and founder of…
Space cybersecurity starts on the ground. [T-Minus: Space-Cyber Briefing]
Though spacecraft are important, space cybersecurity extends well beyond these assets touching ground stations, mission-control assets, and other critical components. Host Maria Varmazis speaks with Milenk Starcevic, …
An apple a day, a phish away. [Research Saturday]
Today we are joined by Ensar Seker, VP of Research and CISO at SOCRadar, discussing their work on "Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain." An investigation into AnonyMousKIT reveals an AI-powered Phishing-…
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in feder…
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
I feel like someone who reads this blog will want to go to this: Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the Hands-On Science Cent…
Shut it down before they do.
Kiteworks urges customers pull the plug on vulnerable servers. CISA lays out its election security plan. Known vulnerabilities linger unpatched. Big AI labs consider a new standards body. Questions surround claims of an …
This one WatchOS 27 feature just solved my biggest issue with Apple Watch
Sometimes less is more, and the most helpful software update is the simplest.
Your LG TV is constantly collecting your data – here’s how to stop it
Factory resetting your LG TV is the only way to remove certain data logs from its hardware.
Microsoft’s new Copilot app puts everything in one place – but the price is ‘evolving’
Microsoft says Copilot has gotten ‘actually really good.’ The new app has AI agents and can write code. So how much is all this going to cost?
On Anthropic’s AI Misuse Report
Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings. A few of the highlights: AI agents increasingly han…
Google Wallet got a lot of new tricks in 2026 – these 5 are my favorites
You can do a whole lot more than tap to pay with Google’s Wallet app.
No factoring necessary.
Researchers find a new way to weaken RSA. ShinyHunters allegedly exposes sensitive FBI details. CISA and the FBI warn of third-party ICS risks. An OpenAI agent hacks an Australian government portal. SolarWinds patches cr…
Microsoft’s Surface Mouse is back, now with haptic feedback – and I need it
Due October 13, the $80 Surface mouse packs an impressive array of features. I want one.
SourceHut account takeover via build logs
submitted by /u/arusekk_pl [link] [comments]
Malicious npm Packages That Evade Defenses
This is an impressive piece of malware. Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.
404: scam not found.
This week, hosts of N2K CyberWire Maria Varmazis and…
The hunters go after the bureau.
ShinyHunters claims to have breached FBI systems. CLOSEDQUORUM malware delegates command-and-control decisions to commercial LLMs. An IT error erases 11 years of hospital maternity data. F5 patches a critical BIG-IP APM …
Research on Models Engaging in Genie-Like Behavior
New paper: “Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training.” Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reas…
Masterhacker
Ramsoftware is 1337 submitted by /u/Quirky-Anybody5491 [link] [comments]
LOW - Now Available
After 8 years, LOW is finally here. A story about the weight of being and the wreckage of waking up. Five episodes. Five descents. LOW is an audio journey into the unlit corners of human experience. Choices we made in th…
A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight
submitted by /u/wiredmagazine [link] [comments]
GPT-6 Astra Breaks an Old Enigma Message
This is pretty amazing: However, the most astonishing thing about this break is that the GPT6 Astra did it entirely on its own. Carter Leffer only directed GPT6 Astra to see if it could break any of the unbroken Enigma…
How do coordinated comment-bot rings manipulate short-form video algorithms to force "Top Comments"? (Technical Breakdown)
I’ve been studying comment sections on short-form video platforms (like TikTok and Reels) & keep noticing a highly coordinated automation phenomenon that I want to understand from a technical and architectural standpoint…
dumpster diving (noun) [Word Notes]
Please enjoy this encore of Word Notes. The act of searching through an organization's trash for discarded sensitive material. CyberWire Glossary link: https://thecyberwire.com/glossary/dumpster-diving Audio refer…
357: Legal Owl Podcast: Steve Durbin on Cyber Risk in the Legal Industry
The tables turn in this episode, as Steve becomes the guest on “Legal Owl,” a podcast by John “Jock" Brocas, the executive coach whom you might remember from one of our shows earlier this year. In this first part of two,…
Hash Identifier Tools – Command-Line Password Hash Identification
hashID and Name-That-Hash tested against current password formats. Both miss bcrypt's $2b$ prefix; only Name-That-Hash recognises Argon2id.
Back when you could just freely login to hundreds of active servers a day
Just found these in my photobucket while looking for so.e old screenshots. submitted by /u/Sea_Manufacturer6590 [link] [comments]
Scamazon prime.
This week, hosts of N2K CyberWire Maria Varmazis and…
Data Broker Radaris Loses Domains in Privacy Fight
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recent…
SEO poisoning (noun) [Word Notes]
Please enjoy this encore of Word Notes. The manipulation of search engine optimization, SEO, to promote malicious sites in search engine results. CyberWire Glossary link: https://thecyberwire.com/glossary/search-engi…
356: From the archive – Communication, Listening and Being Heard
In this episode, ISF Chief Executive Steve Durbin talks with Dame Inga Beale, the former CEO of Lloyd’s of London, about the role that listening played when she became the first (and only) female CEO in Lloyd’s more than…
whitelist-bypass – WebRTC Tunnels Through Video-Calling Platforms
whitelist-bypass tunnels traffic through commercial video calls, for networks that allow only approved domains. How its two tunnels work, and the claim to verify.
Love, lies, and a fake 49er.
This week, hosts of N2K CyberWire Maria Varmazis and…
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping …
catfish (noun) [Word Notes]
Please enjoy this encore of Word Notes. The practice of crafting a fake online persona for malicious purposes. CyberWire Glossary link: https://thecyberwire.com/glossary/catfish Audio reference link: netbunny, 2013…
WRAITH – Browser Hooking and Blind XSS Page Mirroring
WRAITH combines BeEF-style browser hooks with blind-XSS capture and a credentialed Page Mirror. Tested locally, with its limits examined.
FBI Probes Service Selling 153M+ Drivers Licenses
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose l…
355: Eric O'Neill – Hackers Don't Break In, They Log In: Trust as the New Perimeter
Today, Steve is joined by former FBI agent Eric O’Neill. Eric is a cyber security expert and author, but he’s probably most well-known as the man who brought down Peter Hanssen, a Russian spy who became one of the most n…
179: The Courthouse - Revisited
In this episode we follow up with Gabby and Justin from Episode 59 - two seasoned penetration testers who tell us a story about the time when they tried to break into a courthouse but it went all wrong, and what happened…
Praetorian – Offensive Security Tools Built Around Portable Go Workflows
Praetorian's Go security tools consolidate established offensive workflows, with portable binaries, direct pipelines and a partial shared SDK.
AI IR Overlay – Incident Response Specification for AI Agents
AI IR Overlay specifies containment for agents using valid credentials, with a working kill-switch contract and an admitted gap when no SOC is staffed.
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. …
354: SUMMER LISTENING: Emerging Threats for 2026
Today, Steve looks toward the horizon, at the threats and challenges that enterprises and business leaders will face in 2026 and beyond. He also gives advice on how everyone, from the board to the practitioner, can meet …
353: SUMMER LISTENING: Rest After Stress: The Psychology of High Performance
Today, Steve speaks with Lauren Farina, psychotherapist and founder of Invited Psychotherapy & Coaching. Lauren and Steve discuss how wellness is becoming a bigger part of the workplace and how we can stay mentally healt…
352: SUMMER LISTENING: Geoff White – Ransomware Is a Business and It's Competing Against You
In today’s episode, we welcome another ISF veteran: journalist Geoff White. The last time Geoff was a guest on the podcast, it was 2024 and he had just released a book about how the tech industry launders money for crimi…
178: Ubiquiti
Nickolas Sharp worked for Ubiquiti, a company that makes networking equipment. He noticed that there were some security problems at work. He tried to point them out, but didn't feel like he was being listened to enough. …
177: National Public Data
This is the story of the hacker known as "USDoD". When he was young he had a vengeance on the US, and this lead him down a road of continual data breaches, until he hacked into National Public Data, which is when his spr…
176: NSL
One day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violat…
175: Bayrob
It started with a fake car listing on eBay. What looked like a simple online scam quietly grew, over more than a decade, into one of the most sophisticated cybercrime operations the FBI had ever traced. Custom malware. O…
AI threats in the wild: The current state of prompt injections on the web
Posted by Thomas Brunner, Yu-Han Liu, Moni Pande At Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impac…
Bringing Rust to the Pixel Baseband
Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizin…
Protecting Cookies with Device Bound Session Credentials
Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public…
Google Workspace’s continuous approach to mitigating indirect prompt injections
Posted by Adam Gavish, Google GenAI Security Team Indirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This …
VRP 2025 Year in Review
Posted by Dirk Göhmann, Tony Mendez, and the Vulnerability Rewards Program Team 2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉! Origina…
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Posted by Eric Lynch, Product Manager, Android and Dom Elliott, Group Product Manager, Google Play Modern digital security is at a turning point. We are on the threshold of using quantum computers to solve "impossible"…
Weev, Part 2
The Electronic Frontier Foundation, long time critics of the Computer Fraud and Abuse Act, followed Weev's trial - but did not get involved. For the appeal, however, the organization decided to step it. But althought the…