Recent Issues
May 15, 2025
In this issue:
- Slopsquatting
- CVE Program Almost Unfunded
- Age Verification Using Facial Scans
- Android Improves Its Security
- Regulating AI Behavior with a Hypervisor
- New Linux Rootkit
- Cryptocurrency Thefts Get Physical
- Windscribe Acquitted on Charges of Not Collecting Users’ Data
- Applying Security Engineering to Prompt Injection Security
- WhatsApp Case Against NSO Group Progressing
- US as a Surveillance State
- NCSC Guidance on “Advanced Cryptography”
- Privacy for Agentic AI
- Another Move in the Deepfake Creation/Detection Arms Race
- Fake Student Fraud in Community Colleges
- Chinese AI Submersible
- Florida Backdoor Bill Fails
- Court Rules Against NSO Group
- Google’s Advanced Protection Now on Android
- Upcoming Speaking Engagements
- AI-Generated Law
April 15, 2025
In this issue:
- Improvements in Brute Force Attacks
- Is Security Human Factors Research Skewed Towards Western Ideas and Habits?
- Critical GitHub Attack
- NCSC Releases Post-Quantum Cryptography Timeline
- My Writings Are in the LibGen AI Training Corpus
- More Countries are Demanding Backdoors to Encrypted Apps
- Report on Paragon Spyware
- AI Data Poisoning
- A Taxonomy of Adversarial Machine Learning Attacks and Mitigations
- AIs as Trusted Third Parties
- The Signal Chat Leak and the NSA
- Cell Phone OPSEC for Border Crossings
- Rational Astrologies and Security
- Web 3.0 Requires Data Integrity
- Troy Hunt Gets Phished
- DIRNSA Fired
- Arguing Against CALEA
- How to Leak to a Journalist
- Reimagining Democracy
- AI Vulnerability Finding
- China Sort of Admits to Being Behind Volt Typhoon
- Upcoming Speaking Engagements
March 15, 2025
In this issue:
- Atlas of Surveillance
- Story About Medical Device Security
- Device Code Phishing
- An LLM Trained to Create Backdoors in Code
- Implementing Cryptography in AI Systems
- More Research Showing AI Breaking the Rules
- North Korean Hackers Steal $1.5B in Cryptocurrency
- UK Demanded Apple Add a Backdoor to iCloud
- “Emergent Misalignment” in LLMs
- Trojaned AI Tool Leads to Disney Hack
- CISA Identifies Five New Vulnerabilities Currently Being Exploited
- The Combined Cipher Machine
- Rayhunter: Device to Detect Cellular Surveillance
- Thousands of WordPress Websites Infected with Malware
- Silk Typhoon Hackers Indicted
- China, Russia, Iran, and North Korea Intelligence Sharing
- RIP Mark Klein
- TP-Link Router Botnet
- Upcoming Speaking Engagements
February 15, 2025
In this issue:
- Phishing False Alarm
- FBI Deletes PlugX Malware from Thousands of Computers
- Social Engineering to Disable iMessage Protections
- Biden Signs New Cybersecurity Order
- AI Mistakes Are Very Different from Human Mistakes
- AI Will Write Complex Laws
- Third Interdisciplinary Workshop on Reimagining Democracy (IWORD 2024)
- New VPN Backdoor
- CISA Under Trump
- ExxonMobil Lobbyist Caught Hacking Climate Activists
- Fake Reddit and WeTransfer Sites Are Pushing Malware
- Journalists and Civil Society Members Using WhatsApp Targeted by Paragon Spyware
- Deepfakes and the 2024 US Election
- On Generative AI Security
- AIs and Robots Should Sound Robotic
- Screenshot-Reading Malware
- UK Is Ordering Apple to Break Its Own Encryption
- Pairwise Authentication of Humans
- Trusted Execution Environments
- Delivering Malware Through Abandoned Amazon S3 Buckets
- DOGE as a National Cyberattack
- AI and Civil Service Purges
- Upcoming Speaking Engagements
January 15, 2025
In this issue:
- Short-Lived Certificates Coming to Let’s Encrypt
- Hacking Digital License Plates
- New Advances in the Understanding of Prime Numbers
- Mailbox Insecurity
- Criminal Complaint against LockBit Ransomware Writer
- Spyware Maker NSO Group Found Liable for Hacking WhatsApp
- Scams Based on Fake Google Emails
- Casino Players Using Hidden Cameras for Cheating
- Salt Typhoon’s Reach Continues to Grow
- Gift Card Fraud
- Google Is Allowing Device Fingerprinting
- ShredOS
- Privacy of Photos.app’s Enhanced Visual Search
- US Treasury Department Sanctions Chinese Company Over Cyberattacks
- Zero-Day Vulnerability in Ivanti VPN
- Apps That Are Spying on Your Location
- Microsoft Takes Legal Action Against AI “Hacking as a Service” Scheme
- The First Password on the Internet
- Upcoming Speaking Engagements
December 15, 2024
In this issue:
- Good Essay on the History of Bad Password Policies
- Most of 2023’s Top Exploited Vulnerabilities Were Zero-Days
- Why Italy Sells So Much Spyware
- Steve Bellovin’s Retirement Talk
- Secret Service Tracking People’s Locations without Warrant
- The Scale of Geoblocking by Nation
- Security Analysis of the MERGE Voting Protocol
- What Graykey Can and Can’t Unlock
- NSO Group Spies on People on Behalf of Governments
- Race Condition Attacks against LLMs
- Details about the iOS Inactivity Reboot Feature
- Algorithms Are Coming for Democracy—but It’s Not All Bad
- AI and the 2024 Elections
- Detecting Pegasus Infections
- Trust Issues in AI
- Full-Face Masks to Frustrate Identification
- Jailbreaking LLM-Controlled Robots
- Ultralytics Supply-Chain Attack
- Upcoming Speaking Events
November 15, 2024
In this issue:
- More Details on Israel Sabotaging Hezbollah Pagers and Walkie-Talkies
- Cheating at Conkers
- Justice Department Indicts Tech CEO for Falsifying Security Certifications
- AI and the SEC Whistleblower Program
- No, the Chinese Have Not Broken Modern Encryption Systems with a Quantum Computer
- Are Automatic License Plate Scanners Constitutional?
- Watermark for LLM-Generated Text
- Criminals Are Blowing up ATMs in Germany
- Law Enforcement Deanonymizes Tor Users
- Simson Garfinkel on Spooky Cryptographic Action at a Distance
- Tracking World Leaders Using Strava
- Roger Grimes on Prioritizing Cybersecurity Advice
- Sophos Versus the Chinese Hackers
- AIs Discovering Vulnerabilities
- IoT Devices in Password-Spraying Botnet
- Subverting LLM Coders
- Prompt Injection Defenses Against LLM Cyberattacks
- AI Industry is Trying to Subvert the Definition of “Open Source AI”
- Criminals Exploiting FBI Emergency Data Requests
- Mapping License Plate Scanners in the US
- New iOS Security Feature Makes It Harder for Police to Unlock Seized Phones
October 15, 2024
In this issue:
- Legacy Ivanti Cloud Service Appliance Being Exploited
- Python Developers Targeted with Malware During Fake Job Interviews
- Remotely Exploding Pagers
- FBI Shuts Down Chinese Botnet
- Clever Social Engineering Attack Using Captchas
- Hacking the “Bike Angels” System for Moving Bikeshares
- Israel’s Pager Attacks and Supply Chain Vulnerabilities
- New Windows Malware Locks Computer in Kiosk Mode
- An Analysis of the EU’s Cyber Resilience Act
- NIST Recommends Some Common-Sense Password Rules
- AI and the 2024 US Elections
- Hacking ChatGPT by Planting False Memories into Its Data
- California AI Safety Bill Vetoed
- Weird Zimbra Vulnerability
- Largest Recorded DDoS Attack is 3.8 Tbps
- China Possibly Hacking US “Lawful Access” Backdoor
- Auto-Identification Smart Glasses
- Deebot Robot Vacuums Are Using Photos and Audio to Train Their AI
- IronNet Has Shut Down
- More on My AI and Democracy Book
- Perfectl Malware
- Upcoming Speaking Engagements
September 15, 2024
In this issue:
- NIST Releases First Post-Quantum Encryption Algorithms
- New Windows IPv6 Zero-Click Vulnerability
- The State of Ransomware
- Hacking Wireless Bicycle Shifters
- Story of an Undercover CIA Officer who Penetrated Al Qaeda
- Surveillance Watch
- Take a Selfie Using a NY Surveillance Camera
- US Federal Court Rules Against Geofence Warrants
- The Present and Future of TV Surveillance
- Matthew Green on Telegram’s Encryption
- Adm. Grace Hopper’s 1982 NSA Lecture Has Been Published
- SQL Injection Attack on Airport Security
- List of Old NSA Training Videos
- Security Researcher Sued for Disproving Government Statements
- Long Analysis of the M-209
- YubiKey Side-Channel Attack
- Australia Threatens to Force Companies to Break Encryption
- New Chrome Zero-Day
- Evaluating the Effectiveness of Reward Modeling of Generative AI Systems
- Microsoft Is Adding New Cryptography Algorithms
- My TedXBillings Talk
- Upcoming Speaking Engagements
August 15, 2024
In this issue:
- Hacking Scientific Citations
- Cloudflare Reports that Almost 7% of All Internet Traffic Is Malicious
- Criminal Gang Physically Assaulting People for Their Cryptocurrency
- Brett Solomon on Digital Rights
- Snake Mimics a Spider
- 2017 ODNI Memo on Kaspersky Labs
- Robot Dog Internet Jammer
- Data Wallets Using the Solid Protocol
- The CrowdStrike Outage and Market-Driven Brittleness
- Compromising the Secure Boot Process
- New Research in Detecting AI-Generated Videos
- Providing Security Updates to Automobile Software
- Education in Secure Software Development
- Leaked GitHub Python Token
- New Patent Application for Car-to-Car Surveillance
- On the Cyber Safety Review Board
- Problems with Georgia’s Voter Registration Portal
- People-Search Site Removal Services Largely Ineffective
- Taxonomy of Generative AI Misuse
- On the Voynich Manuscript
- Texas Sues GM for Collecting Driving Data without Consent
- Upcoming Speaking Engagements
Sidebar photo of Bruce Schneier by Joe MacInnis.