Recent Issues
March 15, 2023
In this issue:
- Camera the Size of a Grain of Salt
- ChatGPT Is Ingesting Corporate Secrets
- Defending against AI Lobbyists
- Fines as a Security System
- The Insecurity of Photo Cropping
- A Device to Turn Traffic Lights Green
- Cyberwar Lessons from the War in Ukraine
- Putting Undetectable Backdoors in Machine Learning Models
- Banning TikTok
- Side-Channel Attack against CRYSTALS-Kyber
- Fooling a Voice Authentication System with an AI-Generated Voice
- Dumb Password Rules
- Nick Weaver on Regulating Cryptocurrency
- New National Cybersecurity Strategy
- Prompt Injection Attacks on Large Language Models
- BlackLotus Malware Hijacks Windows Secure Boot Process
- Another Malware with Persistence
- Elephant Hackers
- NetWire Remote Access Trojan Maker Arrested
- How AI Could Write Our Laws
- Upcoming Speaking Engagements
February 15, 2023
In this issue:
- Hacked Cellebrite and MSAB Software Released
- The FBI Identified a Tor User
- AI and Political Lobbying
- Security Analysis of Threema
- Real-World Steganography
- Publisher’s Weekly Review of A Hacker’s Mind
- No-Fly List Exposed
- Bulk Surveillance of Money Transfers
- US Cyber Command Operations During the 2022 Midterm Elections
- On Alec Baldwin’s Shooting
- A Guide to Phishing Attacks
- Kevin Mitnick Hacked California Law in 1983
- NIST Is Updating Its Cybersecurity Framework
- Ransomware Payments Are Down
- Passwords Are Terrible (Surprising No One)
- AIs as Computer Hackers
- Manipulating Weights in Face-Recognition AI Systems
- A Hacker’s Mind News
- Attacking Machine Learning Systems
- Malware Delivered through Google Search
- SolarWinds and Market Incentives
- Mary Queen of Scots Letters Decrypted
- Hacking the Tax Code
- A Hacker’s Mind Is Now Published
- On Pig Butchering Scams
- What Will It Take?
- Upcoming Speaking Engagements
January 15, 2023
In this issue:
- A Security Vulnerability in the KmsdBot Botnet
- Apple Patches iPhone Zero-Day
- As Long as We’re on the Subject of CAPTCHAs
- How to Surrender to a Drone
- Trojaned Windows Installer Targets Ukraine
- Ukraine Intercepting Russian Soldiers’ Cell Phone Calls
- Critical Microsoft Code-Execution Vulnerability
- Hacking the JFK Airport Taxi Dispatch System
- LastPass Breach
- Arresting IT Administrators
- QR Code Scam
- Recovering Smartphone Voice from the Accelerometer
- Breaking RSA with a Quantum Computer
- Decarbonizing Cryptocurrencies through Taxation
- Remote Vulnerabilities in Automobiles
- Schneier on Security Audiobook Sale
- Identifying People Using Cell Phone Location Data
- ChatGPT-Written Malware
- Experian Privacy Vulnerability
- Threats of Machine-Generated Text
- Booklist Review of A Hacker’s Mind
- Upcoming Speaking Engagements
December 15, 2022
In this issue:
- Another Event-Related Spyware App
- Russian Software Company Pretending to Be American
- Failures in Twitter’s Two-Factor Authentication System
- Successful Hack of Time-Triggered Ethernet
- First Review of A Hacker’s Mind
- Breaking the Zeppelin Ransomware Encryption Scheme
- Apple’s Device Analytics Can Identify iCloud Users
- The US Has a Shortage of Bomb-Sniffing Dogs
- Computer Repair Technicians Are Stealing Your Data
- Charles V of Spain Secret Code Cracked
- Facebook Fined $276M under GDPR
- Sirius XM Software Vulnerability
- LastPass Security Breach
- Existential Risk and the Fermi Paradox
- CAPTCHA
- CryWiper Data Wiper Targeting Russian Sites
- The Decoupling Principle
- Leaked Signing Keys Are Being Used to Sign Malware
- Security Vulnerabilities in Eufy Cameras
- Hacking Trespass Law
- Apple Is Finally Encrypting iCloud Backups
- Obligatory ChatGPT Post
- Hacking Boston’s CharlieCard
- Recreating Democracy
November 15, 2022
In this issue:
- New Book: A Hacker’s Mind
- Hacking Automobile Keyless Entry Systems
- Qatar Spyware
- Museum Security
- Interview with Signal’s New President
- Adversarial ML Attack that Secretly Gives a Language Model a Point of View
- On the Randomness of Automatic Card Shufflers
- Australia Increases Fines for Massive Data Breaches
- Critical Vulnerability in Open SSL
- Apple Only Commits to Patching Latest OS Version
- Iran’s Digital Surveillance Tools Leaked
- NSA on Supply Chain Security
- The Conviction of Uber’s Chief Security Officer
- Using Wi-FI to See through Walls
- Defeating Phishing-Resistant Multifactor Authentication
- An Untrustworthy TLS Certificate in Browsers
- NSA Over-surveillance
- A Digital Red Cross
- Upcoming Speaking Engagements
October 15, 2022
In this issue:
- Relay Attack against Teslas
- Massive Data Breach at Uber
- Large-Scale Collection of Cell Phone Data at US Borders
- Credit Card Fraud That Bypasses 2FA
- Automatic Cheating Detection in Human Racing
- Prompt Injection/Extraction Attacks against AI Systems
- Leaking Screen Information on Zoom Calls through Reflections in Eyeglasses
- Leaking Passwords through the Spellchecker
- New Report on IoT Security
- Cold War Bugging of Soviet Facilities
- Differences in App Security/Privacy Based on Country
- Security Vulnerabilities in Covert CIA Websites
- Detecting Deepfake Audio by Modeling the Human Acoustic Tract
- NSA Employee Charged with Espionage
- October Is Cybersecurity Awareness Month
- Spyware Maker Intellexa Sued by Journalist
- Complex Impersonation Story
- Inserting a Backdoor into a Machine-Learning System
- Recovering Passwords by Measuring Residual Heat
- Digital License Plates
- Regulating DAOs
- Upcoming Speaking Engagements
September 15, 2022
In this issue:
- $23 Million YouTube Royalties Scam
- Remotely Controlling Touchscreens
- Zoom Exploit on MacOS
- USB “Rubber Ducky” Attack Tool
- Hyundai Uses Example Keys for Encryption System
- Signal Phone Numbers Exposed in Twilio Hack
- Mudge Files Whistleblower Complaint against Twitter
- Man-in-the-Middle Phishing Attack
- Security and Cheap Complexity
- Levels of Assurance for DoD Microelectronics
- FTC Sues Data Broker
- High-School Graduation Prank Hack
- Clever Phishing Scam Uses Legitimate PayPal Messages
- Montenegro Is the Victim of a Cyberattack
- The LockBit Ransomware Gang Is Surprisingly Professional
- Facebook Has No Idea What Data It Has
- Responsible Disclosure for Cryptocurrency Security
- New Linux Cryptomining Malware
- FBI Seizes Stolen Cryptocurrencies
- Weird Fallout from Peiter Zatko’s Twitter Whistleblowing
- Upcoming Speaking Engagements
August 15, 2022
In this issue:
- San Francisco Police Want Real-Time Access to Private Surveillance Cameras
- Facebook Is Now Encrypting Links to Prevent URL Stripping
- NSO Group’s Pegasus Spyware Used against Thailand Pro-Democracy Activists and Leaders
- Russia Creates Malware False-Flag App
- Critical Vulnerabilities in GPS Trackers
- Apple’s Lockdown Mode
- Securing Open-Source Software
- New UEFI Rootkit
- Microsoft Zero-Days Sold and Then Used
- Ring Gives Videos to Police without a Warrant or User Consent
- Surveillance of Your Car
- Drone Deliveries into Prisons
- SIKE Broken
- NIST’s Post-Quantum Cryptography Standards
- Hacking Starlink
- A Taxonomy of Access Control
- Twitter Exposes Personal Information for 5.4 Million Accounts
- Upcoming Speaking Engagements
July 15, 2022
In this issue:
- M1 Chip Vulnerability
- Attacking the Performance of Machine Learning Systems
- Tracking People via Bluetooth on Their Phones
- Hertzbleed: A New Side-Channel Attack
- Hidden Anti-Cryptography Provisions in Internet Anti-Trust Bills
- Symbiote Backdoor in Linux
- On the Subversion of NIST by the NSA
- On the Dangers of Cryptocurrencies and the Uselessness of Blockchain
- 2022 Workshop on Economics and Information Security (WEIS)
- When Security Locks You Out of Everything
- Ecuador’s Attempt to Resettle Edward Snowden
- ZuoRAT Malware Is Targeting Routers
- Analyzing the Swiss E-Voting System
- NIST Announces First Four Quantum-Resistant Cryptographic Algorithms
- Ubiquitous Surveillance by ICE
- Apple’s Lockdown Mode
- Nigerian Prison Break
- Security Vulnerabilities in Honda’s Keyless Entry System
- Post-Roe Privacy
- New Browser De-anonymization Technique
- Upcoming Speaking Engagements
June 15, 2022
In this issue:
- The NSA Says that There are No Known Flaws in NIST’s Quantum-Resistant Algorithms
- Attacks on Managed Service Providers Expected to Increase
- iPhone Malware that Operates Even When the Phone Is Turned Off
- Websites that Collect Your Data as You Type
- Bluetooth Flaw Allows Remote Unlocking of Digital Locks
- The Onion on Google Map Surveillance
- Forging Australian Driver’s Licenses
- The Justice Department Will No Longer Charge Security Researchers with Criminal Hacking
- Manipulating Machine-Learning Systems through the Order of the Training Data
- Malware-Infested Smart Card Reader
- Security and Human Behavior (SHB) 2022
- The Limits of Cyber Operations in Wartime
- Clever — and Exploitable — Windows Zero-Day
- Remotely Controlling Touchscreens
- Me on Public-Interest Tech
- Long Story on the Accused CIA Vault 7 Leaker
- Leaking Military Secrets on Gaming Discussion Boards
- Smartphones and Civilians in Wartime
- Twitter Used Two-Factor Login Details for Ad Targeting
- Cryptanalysis of ENCSecurity’s Encryption Implementation
- Hacking Tesla’s Remote Key Cards
- Upcoming Speaking Engagements
Sidebar photo of Bruce Schneier by Joe MacInnis.