Crypto-Gram: 2025 Archives
December 15, 2025
In this issue:
- More Prompt||GTFO
- AI and Voter Engagement
- Legal Restrictions on Vulnerability Disclosure
- Scam USPS and E-Z Pass Texts and Websites
- AI as Cyberattacker
- More on Rewiring Democracy
- IACR Nullifies Election Because of Lost Decryption Key
- Four Ways AI Is Being Used to Strengthen Democracies Worldwide
- Huawei and Chinese Surveillance
- Prompt Injection Through Poetry
- Banning VPNs
- Like Social Media, AI Requires Difficult Choices
- New Anonymous Phone Service
- Substitution Cipher Based on The Voynich Manuscript
- AI vs. Human Drivers
- FBI Warns of Fake Video Scams
- AIs Exploiting Smart Contracts
- Building Trustworthy AI Agents
- Upcoming Speaking Engagements
November 15, 2025
In this issue:
- Apple’s Bug Bounty Program
- Cryptocurrency ATMs
- A Surprising Amount of Satellite Traffic Is Unencrypted
- Agentic AI’s OODA Loop Problem
- A Cybersecurity Merit Badge
- Failures in Face Recognition
- Serious F5 Breach
- Part Four of The Kryptos Sculpture
- First Wap: A Surveillance Computer You’ve Never Heard Of
- Louvre Jewel Heist
- Social Engineering People’s Credit Card Details
- Signal’s Post-Quantum Cryptographic Implementation
- The AI-Designed Bioweapon Arms Race
- Will AI Strengthen or Undermine Democracy?
- AI Summarization Optimization
- Cybercriminals Targeting Payroll Sites
- Scientists Need a Positive Vision for AI
- Rigged Poker Games
- Faking Receipts with AI
- New Attacks Against Secure Enclaves
- Prompt Injection in AI Browsers
- On Hacking Back
- Book Review: The Business of Secrets
- The Role of Humans in an AI-Powered World
- Upcoming Speaking Engagements
October 15, 2025
In this issue:
- Lawsuit About WhatsApp Security
- Microsoft Still Uses RC4
- Hacking Electronic Safes
- Time-of-Check Time-of-Use Attacks Against LLMs
- Surveying the Global Spyware Market
- Details About Chinese Surveillance and Propaganda Companies
- Apple’s New Memory Integrity Enforcement
- US Disrupts Massive Cell Phone Array in New York
- Malicious-Looking URL Creation Service
- Digital Threat Modeling Under Authoritarianism
- Abusing Notion’s AI Agent for Data Theft
- Details of a Scam
- Use of Generative AI in Scams
- Daniel Miessler on the AI Attack/Defense Balance
- AI in the 2026 Midterm Elections
- AI-Enabled Influence Operation Against Iran
- Flok License Plate Surveillance
- Autonomous AI Hacking and the Future of Cybersecurity
- AI and the Future of American Politics
- Rewiring Democracy is Coming Soon
- The Trump Administration’s Increased Use of Social Media Surveillance
- Upcoming Speaking Engagements
September 15, 2025
In this issue:
- Trojans Embedded in .svg Files
- Eavesdropping on Phone Conversations Through Vibrations
- Zero-Day Exploit in WinRAR File
- Subverting AIOps Systems Through Poisoned Input Data
- Jim Sanborn Is Auctioning Off the Solution to Part Four of the Kryptos Sculpture
- AI Agents Need Data Integrity
- I’m Spending the Year at the Munk School
- Poor Password Choices
- Encryption Backdoor in Military/Police Radios
- We Are Still Unable to Secure LLMs from Malicious Inputs
- The UK May Be Dropping Its Backdoor Mandate
- Baggage Tag Scam
- 1965 Cryptanalysis Training Workbook Released by the NSA
- Indirect Prompt Injection Attacks Against LLM Assistants
- Generative AI as a Cybercrime Assistant
- GPT-4o-mini Falls for Psychological Manipulation
- My Latest Book: Rewiring Democracy
- AI in Government
- Signed Copies of Rewiring Democracy
- New Cryptanalysis of the Fiat-Shamir Protocol
- A Cyberattack Victim Notification Framework
- Upcoming Speaking Engagements
August 15, 2025
In this issue:
- Report from the Cambridge Cybercrime Conference
- Hacking Trains
- Security Vulnerabilities in ICEBlock
- New Mobile Phone Forensics Tool
- Another Supply Chain Vulnerability
- “Encryption Backdoors and the Fourth Amendment”
- Google Sues the Badbox Botnet Operators
- How the Solid Protocol Restores Digital Agency
- Subliminal Learning in AIs
- Microsoft SharePoint Zero-Day
- That Time Tom Lehrer Pranked the NSA
- Aeroflot Hacked
- Measuring the Attack/Defense Balance
- Cheating on Quantum Computing Benchmarks
- Spying on People Through Airportr Luggage Delivery Service
- First Sentencing in Scheme to Help North Koreans Infiltrate US Companies
- Surveilling Your Children with AirTags
- The Semiconductor Industry and Regulatory Compliance
- China Accuses Nvidia of Putting Backdoors into Their Chips
- Google Project Zero Changes Its Disclosure Policy
- Automatic License Plate Readers Are Coming to Schools
- The “Incriminating Video” Scam
- SIGINT During World War II
- AI Applications in Cybersecurity
- LLM Coding Integrity Breach
July 15, 2025
In this issue:
- Where AI Provides Value
- Ghostwriting Scam
- Self-Driving Car Video Footage
- Surveillance in the US
- Largest DDoS Attack to Date
- Here’s a Subliminal Channel You Haven’t Considered Before
- What LLMs Know About Their Users
- House of Representatives Bans WhatsApp
- The Age of Integrity
- How Cybersecurity Fears Affect Confidence in Voting Systems
- Iranian Blackout Affected Misinformation Campaigns
- Ubuntu Disables Spectre/Meltdown Protections
- Surveillance Used by a Drug Cartel
- Hiding Prompt Injections in Academic Papers
- Yet Another Strava Privacy Leak
- Using Signal Groups for Activism
- Tradecraft in the Information Age
June 15, 2025
In this issue:
- Communications Backdoor in Chinese Power Inverters
- The NSA’s “Fifty Years of Mathematical Cryptanalysis (1937–1987)”
- DoorDash Hack
- More AIs Are Taking Polls and Surveys
- The Voter Experience
- Signal Blocks Windows Recall
- Chinese-Owned VPNs
- Location Tracking App for Foreigners in Moscow
- Surveillance Via Smart Toothbrush
- Why Take9 Won’t Improve Cybersecurity
- Australia Requires Ransomware Victims to Declare Payments
- New Linux Vulnerabilities
- The Ramifications of Ukraine’s Drone Attack
- Report on the Malicious Uses of AI
- Hearing on the Federal Government and AI
- New Way to Covertly Track Android Users
- Airlines Secretly Selling Passenger Data to the Government
- Paragon Spyware Used to Spy on European Journalists
- Upcoming Speaking Engagements
May 15, 2025
In this issue:
- Slopsquatting
- CVE Program Almost Unfunded
- Age Verification Using Facial Scans
- Android Improves Its Security
- Regulating AI Behavior with a Hypervisor
- New Linux Rootkit
- Cryptocurrency Thefts Get Physical
- Windscribe Acquitted on Charges of Not Collecting Users’ Data
- Applying Security Engineering to Prompt Injection Security
- WhatsApp Case Against NSO Group Progressing
- US as a Surveillance State
- NCSC Guidance on “Advanced Cryptography”
- Privacy for Agentic AI
- Another Move in the Deepfake Creation/Detection Arms Race
- Fake Student Fraud in Community Colleges
- Chinese AI Submersible
- Florida Backdoor Bill Fails
- Court Rules Against NSO Group
- Google’s Advanced Protection Now on Android
- Upcoming Speaking Engagements
- AI-Generated Law
April 15, 2025
In this issue:
- Improvements in Brute Force Attacks
- Is Security Human Factors Research Skewed Towards Western Ideas and Habits?
- Critical GitHub Attack
- NCSC Releases Post-Quantum Cryptography Timeline
- My Writings Are in the LibGen AI Training Corpus
- More Countries are Demanding Backdoors to Encrypted Apps
- Report on Paragon Spyware
- AI Data Poisoning
- A Taxonomy of Adversarial Machine Learning Attacks and Mitigations
- AIs as Trusted Third Parties
- The Signal Chat Leak and the NSA
- Cell Phone OPSEC for Border Crossings
- Rational Astrologies and Security
- Web 3.0 Requires Data Integrity
- Troy Hunt Gets Phished
- DIRNSA Fired
- Arguing Against CALEA
- How to Leak to a Journalist
- Reimagining Democracy
- AI Vulnerability Finding
- China Sort of Admits to Being Behind Volt Typhoon
- Upcoming Speaking Engagements
March 15, 2025
In this issue:
- Atlas of Surveillance
- Story About Medical Device Security
- Device Code Phishing
- An LLM Trained to Create Backdoors in Code
- Implementing Cryptography in AI Systems
- More Research Showing AI Breaking the Rules
- North Korean Hackers Steal $1.5B in Cryptocurrency
- UK Demanded Apple Add a Backdoor to iCloud
- “Emergent Misalignment” in LLMs
- Trojaned AI Tool Leads to Disney Hack
- CISA Identifies Five New Vulnerabilities Currently Being Exploited
- The Combined Cipher Machine
- Rayhunter: Device to Detect Cellular Surveillance
- Thousands of WordPress Websites Infected with Malware
- Silk Typhoon Hackers Indicted
- China, Russia, Iran, and North Korea Intelligence Sharing
- RIP Mark Klein
- TP-Link Router Botnet
- Upcoming Speaking Engagements
February 15, 2025
In this issue:
- Phishing False Alarm
- FBI Deletes PlugX Malware from Thousands of Computers
- Social Engineering to Disable iMessage Protections
- Biden Signs New Cybersecurity Order
- AI Mistakes Are Very Different from Human Mistakes
- AI Will Write Complex Laws
- Third Interdisciplinary Workshop on Reimagining Democracy (IWORD 2024)
- New VPN Backdoor
- CISA Under Trump
- ExxonMobil Lobbyist Caught Hacking Climate Activists
- Fake Reddit and WeTransfer Sites Are Pushing Malware
- Journalists and Civil Society Members Using WhatsApp Targeted by Paragon Spyware
- Deepfakes and the 2024 US Election
- On Generative AI Security
- AIs and Robots Should Sound Robotic
- Screenshot-Reading Malware
- UK Is Ordering Apple to Break Its Own Encryption
- Pairwise Authentication of Humans
- Trusted Execution Environments
- Delivering Malware Through Abandoned Amazon S3 Buckets
- DOGE as a National Cyberattack
- AI and Civil Service Purges
- Upcoming Speaking Engagements
January 15, 2025
In this issue:
- Short-Lived Certificates Coming to Let’s Encrypt
- Hacking Digital License Plates
- New Advances in the Understanding of Prime Numbers
- Mailbox Insecurity
- Criminal Complaint against LockBit Ransomware Writer
- Spyware Maker NSO Group Found Liable for Hacking WhatsApp
- Scams Based on Fake Google Emails
- Casino Players Using Hidden Cameras for Cheating
- Salt Typhoon’s Reach Continues to Grow
- Gift Card Fraud
- Google Is Allowing Device Fingerprinting
- ShredOS
- Privacy of Photos.app’s Enhanced Visual Search
- US Treasury Department Sanctions Chinese Company Over Cyberattacks
- Zero-Day Vulnerability in Ivanti VPN
- Apps That Are Spying on Your Location
- Microsoft Takes Legal Action Against AI “Hacking as a Service” Scheme
- The First Password on the Internet
- Upcoming Speaking Engagements
Sidebar photo of Bruce Schneier by Joe MacInnis.