We’ve added a new chapter to our Testing Handbook a comprehensive guide to security testing Rust programs. This chapter covers the tools and techniques we use at Trail of Bits to validate the …
AI Security Roundup
Daily AI security roundup covering malware, vulnerabilities, defensive research, cloud risk, and incident response signals from trusted technical sources.
In April we released Mewt , our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are …
Codex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the right scope, and the right number of outcomes per run. For Patch the Planet , our joint initiative …
Uniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom accounting, and external integrations. This flexibility moves some security responsibilities into …
Nitro Enclaves and Key Management Service (KMS) feel like a natural fit: since the KMS can verify attestation documents generated by the enclaves, developers can offload key management tasks from …
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut , a sprawling residential proxy service operated by the …
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most …
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud …
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant …
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less …
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the …
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 …
The OpenAI Hack Shows the Genie Is Out of the Bottle This essay originally appeared in Foreign Policy . Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked …
Some Claude Chats Are Searchable on Google And it’s personal information (alternate link ): > The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on …
More on the OpenAI Agent’s Attack on Hugging Face Hugging Face has published a detailed timeline of the attack. From the summary: > The agent was running an internal OpenAI cyber-capability …
Vulnerabilities in Car Anti-Theft Device This is disturbing: > …a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, …
Iran Cyberattacks Against Minnesota Water Systems Attribution is preliminary , and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states . And, …
ICE Is Buying Access to Credit Card Records Through data brokers, ICE is buying the information you provided to open a credit card. Posted on August 7, 2026 at 6:26 AM • 21 Comments
Friday Squid Blogging: Arctic Bobtail Squid Video Nice video of the Arctic bobtail squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t …
Adversarial Clothing Designed to Fool Facial Recognition Systems There are many companies manufacturing adversarial clothing designed to confuse facial recognition systems. It’s a cool idea, but I …
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671 . “UNC6671 continues to rely …
** Ravie Lakshmanan ** Aug 08, 2026 Vulnerability / Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting …
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. …
** Ravie Lakshmanan ** Aug 07, 2026 Malware / Social Engineering ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as …
** Ravie Lakshmanan ** Aug 08, 2026 Vulnerability / Enterprise Security N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently …