Recent Issues
February 15, 2025
In this issue:
- Phishing False Alarm
- FBI Deletes PlugX Malware from Thousands of Computers
- Social Engineering to Disable iMessage Protections
- Biden Signs New Cybersecurity Order
- AI Mistakes Are Very Different from Human Mistakes
- AI Will Write Complex Laws
- Third Interdisciplinary Workshop on Reimagining Democracy (IWORD 2024)
- New VPN Backdoor
- CISA Under Trump
- ExxonMobil Lobbyist Caught Hacking Climate Activists
- Fake Reddit and WeTransfer Sites Are Pushing Malware
- Journalists and Civil Society Members Using WhatsApp Targeted by Paragon Spyware
- Deepfakes and the 2024 US Election
- On Generative AI Security
- AIs and Robots Should Sound Robotic
- Screenshot-Reading Malware
- UK Is Ordering Apple to Break Its Own Encryption
- Pairwise Authentication of Humans
- Trusted Execution Environments
- Delivering Malware Through Abandoned Amazon S3 Buckets
- DOGE as a National Cyberattack
- AI and Civil Service Purges
- Upcoming Speaking Engagements
January 15, 2025
In this issue:
- Short-Lived Certificates Coming to Let’s Encrypt
- Hacking Digital License Plates
- New Advances in the Understanding of Prime Numbers
- Mailbox Insecurity
- Criminal Complaint against LockBit Ransomware Writer
- Spyware Maker NSO Group Found Liable for Hacking WhatsApp
- Scams Based on Fake Google Emails
- Casino Players Using Hidden Cameras for Cheating
- Salt Typhoon’s Reach Continues to Grow
- Gift Card Fraud
- Google Is Allowing Device Fingerprinting
- ShredOS
- Privacy of Photos.app’s Enhanced Visual Search
- US Treasury Department Sanctions Chinese Company Over Cyberattacks
- Zero-Day Vulnerability in Ivanti VPN
- Apps That Are Spying on Your Location
- Microsoft Takes Legal Action Against AI “Hacking as a Service” Scheme
- The First Password on the Internet
- Upcoming Speaking Engagements
December 15, 2024
In this issue:
- Good Essay on the History of Bad Password Policies
- Most of 2023’s Top Exploited Vulnerabilities Were Zero-Days
- Why Italy Sells So Much Spyware
- Steve Bellovin’s Retirement Talk
- Secret Service Tracking People’s Locations without Warrant
- The Scale of Geoblocking by Nation
- Security Analysis of the MERGE Voting Protocol
- What Graykey Can and Can’t Unlock
- NSO Group Spies on People on Behalf of Governments
- Race Condition Attacks against LLMs
- Details about the iOS Inactivity Reboot Feature
- Algorithms Are Coming for Democracy—but It’s Not All Bad
- AI and the 2024 Elections
- Detecting Pegasus Infections
- Trust Issues in AI
- Full-Face Masks to Frustrate Identification
- Jailbreaking LLM-Controlled Robots
- Ultralytics Supply-Chain Attack
- Upcoming Speaking Events
November 15, 2024
In this issue:
- More Details on Israel Sabotaging Hezbollah Pagers and Walkie-Talkies
- Cheating at Conkers
- Justice Department Indicts Tech CEO for Falsifying Security Certifications
- AI and the SEC Whistleblower Program
- No, the Chinese Have Not Broken Modern Encryption Systems with a Quantum Computer
- Are Automatic License Plate Scanners Constitutional?
- Watermark for LLM-Generated Text
- Criminals Are Blowing up ATMs in Germany
- Law Enforcement Deanonymizes Tor Users
- Simson Garfinkel on Spooky Cryptographic Action at a Distance
- Tracking World Leaders Using Strava
- Roger Grimes on Prioritizing Cybersecurity Advice
- Sophos Versus the Chinese Hackers
- AIs Discovering Vulnerabilities
- IoT Devices in Password-Spraying Botnet
- Subverting LLM Coders
- Prompt Injection Defenses Against LLM Cyberattacks
- AI Industry is Trying to Subvert the Definition of “Open Source AI”
- Criminals Exploiting FBI Emergency Data Requests
- Mapping License Plate Scanners in the US
- New iOS Security Feature Makes It Harder for Police to Unlock Seized Phones
October 15, 2024
In this issue:
- Legacy Ivanti Cloud Service Appliance Being Exploited
- Python Developers Targeted with Malware During Fake Job Interviews
- Remotely Exploding Pagers
- FBI Shuts Down Chinese Botnet
- Clever Social Engineering Attack Using Captchas
- Hacking the “Bike Angels” System for Moving Bikeshares
- Israel’s Pager Attacks and Supply Chain Vulnerabilities
- New Windows Malware Locks Computer in Kiosk Mode
- An Analysis of the EU’s Cyber Resilience Act
- NIST Recommends Some Common-Sense Password Rules
- AI and the 2024 US Elections
- Hacking ChatGPT by Planting False Memories into Its Data
- California AI Safety Bill Vetoed
- Weird Zimbra Vulnerability
- Largest Recorded DDoS Attack is 3.8 Tbps
- China Possibly Hacking US “Lawful Access” Backdoor
- Auto-Identification Smart Glasses
- Deebot Robot Vacuums Are Using Photos and Audio to Train Their AI
- IronNet Has Shut Down
- More on My AI and Democracy Book
- Perfectl Malware
- Upcoming Speaking Engagements
September 15, 2024
In this issue:
- NIST Releases First Post-Quantum Encryption Algorithms
- New Windows IPv6 Zero-Click Vulnerability
- The State of Ransomware
- Hacking Wireless Bicycle Shifters
- Story of an Undercover CIA Officer who Penetrated Al Qaeda
- Surveillance Watch
- Take a Selfie Using a NY Surveillance Camera
- US Federal Court Rules Against Geofence Warrants
- The Present and Future of TV Surveillance
- Matthew Green on Telegram’s Encryption
- Adm. Grace Hopper’s 1982 NSA Lecture Has Been Published
- SQL Injection Attack on Airport Security
- List of Old NSA Training Videos
- Security Researcher Sued for Disproving Government Statements
- Long Analysis of the M-209
- YubiKey Side-Channel Attack
- Australia Threatens to Force Companies to Break Encryption
- New Chrome Zero-Day
- Evaluating the Effectiveness of Reward Modeling of Generative AI Systems
- Microsoft Is Adding New Cryptography Algorithms
- My TedXBillings Talk
- Upcoming Speaking Engagements
August 15, 2024
In this issue:
- Hacking Scientific Citations
- Cloudflare Reports that Almost 7% of All Internet Traffic Is Malicious
- Criminal Gang Physically Assaulting People for Their Cryptocurrency
- Brett Solomon on Digital Rights
- Snake Mimics a Spider
- 2017 ODNI Memo on Kaspersky Labs
- Robot Dog Internet Jammer
- Data Wallets Using the Solid Protocol
- The CrowdStrike Outage and Market-Driven Brittleness
- Compromising the Secure Boot Process
- New Research in Detecting AI-Generated Videos
- Providing Security Updates to Automobile Software
- Education in Secure Software Development
- Leaked GitHub Python Token
- New Patent Application for Car-to-Car Surveillance
- On the Cyber Safety Review Board
- Problems with Georgia’s Voter Registration Portal
- People-Search Site Removal Services Largely Ineffective
- Taxonomy of Generative AI Misuse
- On the Voynich Manuscript
- Texas Sues GM for Collecting Driving Data without Consent
- Upcoming Speaking Engagements
July 15, 2024
In this issue:
- Using LLMs to Exploit Vulnerabilities
- Rethinking Democracy for the Age of AI
- The Hacking of Culture and the Creation of Socio-Technical Debt
- New Blog Moderation Policy
- Recovering Public Keys from Signatures
- Ross Anderson’s Memorial Service
- Paul Nakasone Joins OpenAI’s Board of Directors
- Breaking the M-209
- The US Is Banning Kaspersky
- Security Analysis of the EU’s Digital Wallet
- James Bamford on Section 702 Extension
- Model Extraction from Neural Networks
- Public Surveillance of Bars
- Upcoming Book on AI and Democracy
- New Open SSH Vulnerability
- On the CSRB’s Non-Investigation of the SolarWinds Attack
- Reverse-Engineering Ticketmaster’s Barcode System
- RADIUS Vulnerability
- Apple Is Alerting iPhone Users of Spyware Attacks
- The NSA Has a Long-Lost Lecture by Adm. Grace Hopper
- Upcoming Speaking Engagements
June 15, 2024
In this issue:
- Zero-Trust DNS
- FBI Seizes BreachForums Website
- IBM Sells Cybersecurity Group
- Detecting Malicious Trackers
- Unredacting Pixelated Text
- Personal AI Assistants and Privacy
- On the Zero-Day Market
- Lattice-Based Cryptosystems and Quantum Cryptanalysis
- Privacy Implications of Tracking Wireless Access Points
- Supply Chain Attack against Courtroom Software
- How AI Will Change Democracy
- AI Will Increase the Quantity—and Quality—of Phishing Scams
- Seeing Like a Data Structure
- Breaking a Password Manager
- Online Privacy and Overfishing
- Espionage with a Drone
- The Justice Department Took Down the 911 S5 Botnet
- Security and Human Behavior (SHB) 2024
- Exploiting Mistyped URLs
- LLMs Acting Deceptively
- Using AI for Political Polling
- AI and the Indian Election
- Demo of AES GCM Misuse Problems
- Upcoming Speaking Engagements
May 15, 2024
In this issue:
- New Lattice Cryptanalytic Technique
- X.com Automatically Changing Link Text but Not URLs
- Using AI-Generated Legislative Amendments as a Delaying Technique
- Other Attempts to Take Over Open Source Projects
- Using Legitimate GitHub URLs for Malware
- Microsoft and Security Incentives
- Dan Solove on Privacy Regulation
- The Rise of Large-Language-Model Optimization
- Long Article on GM Spying on Its Cars’ Drivers
- Whale Song Code
- WhatsApp in India
- AI Voice Scam
- The UK Bans Default Passwords
- Rare Interviews with Enigma Cryptanalyst Marian Rejewski
- My TED Talks
- New Lawsuit Attempting to Make Adversarial Interoperability Legal
- New Attack on VPNs
- How Criminals Are Using Generative AI
- New Attack Against Self-Driving Car AI
- LLMs’ Data-Control Path Insecurity
- Another Chrome Vulnerability
- Upcoming Speaking Engagements
Sidebar photo of Bruce Schneier by Joe MacInnis.