**
Ravie Lakshmanan **
Aug 25, 2026
Authentication / Password Security
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single …
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and …
**
Swati Khandelwal **
Aug 25, 2026
Vulnerability / AI Security
Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied …
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden …
Microsoft Graph is a newer API that is meant to replace several others. OK, it’s at version 2.3.9, so it’s not all that new, but it’s new enough that lots of folks (and commercial …
Building on the last diary on Using MS Graph and Powershell, let’s look at “Risky” logins.
Risky logins are a derived set of parameters that look at various (you guessed it) risky …
One thing that folks never seem to do after “going to the CLOOOOUUUUD” is to look at their logs, logs that they would have checked daily when things were on premise.
One log that really …
In every MFA rollout, there will come a time where you think you are closing in on “done”, and some automation to list what’s left would be handy. Something quicker than scrolling …
Every Signal chat starts the same way: the client asks the Signal server for the public key associated with your contact’s phone number. But how do you know the server gave you the right key? A …
New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up . It doesn’t use real steganography:
You can see the …
It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but …
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively …
LLMs and Contextual Integrity I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic.
“ CIMemories: A Compositional Benchmark …
Police Are Hiding Their Use of Flock Surveillance Cameras A usage policy for Flock license plate reader cameras tells police not to talk about the cameras:
> When cops use Flock to arrest someone …
ICE Collecting DNA Samples ICE collected nearly a million DNA samples last year.
Tags: databases , DNA , FBI , homeland security , identification , national security policy
Posted on August 19, 2026 …
More Incidents of AIs Going Rogue in Cybersecurity Challenges The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “ genie behavior …
Friday Squid Blogging: Neon Flying Squid The neon flying squid can fly in formation.
> The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo …
Detailed Timeline of OpenAI’s Cyberattack on Hugging Face OpenAI presented details of its AI’s model’s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It’s …
AI Is Learning to Write Genetic Code This sort of research is both exciting and terrifying:
> The two models in question were told to generate complete genomes for a viable bacteriophage—a type of …
Criminal Deception in Silicon Valley Interesting paper :
> Abstract: > With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out > criminal deception > , …
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that’s targeting Windows and Linux web servers globally across the education, media, …
Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is …