[This is a Guest Diary by Daryl Jiminez, an ISC intern as part of the SANS.edu BACS program] Introduction On May 23, 2026, a threat actor successfully authenticated to my Cowrie SSH honeypot using …
AI Security Roundup
Daily AI security roundup covering malware, vulnerabilities, defensive research, cloud risk, and incident response signals from trusted technical sources.
ISC Stormcast For Thursday, August 6th, 2026 https://isc.sans.edu/podcastdetail/10040, (Thu, Aug 6th)
ISC Stormcast For Thursday, August 6th, 2026 <https://isc.sans.edu/podcastdetail/10040>
ISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th)
ISC Stormcast For Friday, August 7th, 2026 <https://isc.sans.edu/podcastdetail/10042>
UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they definitely lack of “modern” logging: shells. …
Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency , we implemented support for ML-KEM, the NIST-standard …
We’re running Patch the Planet , an ongoing collaboration with OpenAI that pairs Trail of Bits engineers directly with more than 30 open-source projects. Its goal is to front-run a serious problem …
We’ve added a new chapter to our Testing Handbook a comprehensive guide to security testing Rust programs. This chapter covers the tools and techniques we use at Trail of Bits to validate the …
In April we released Mewt , our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are …
Codex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the right scope, and the right number of outcomes per run. For Patch the Planet , our joint initiative …
Uniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom accounting, and external integrations. This flexibility moves some security responsibilities into …
Nitro Enclaves and Key Management Service (KMS) feel like a natural fit: since the KMS can verify attestation documents generated by the enclaves, developers can offload key management tasks from …
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut , a sprawling residential proxy service operated by the …
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most …
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud …
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant …
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less …
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the …
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 …
The OpenAI Hack Shows the Genie Is Out of the Bottle This essay originally appeared in Foreign Policy . Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked …
Some Claude Chats Are Searchable on Google And it’s personal information (alternate link ): > The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on …
More on the OpenAI Agent’s Attack on Hugging Face Hugging Face has published a detailed timeline of the attack. From the summary: > The agent was running an internal OpenAI cyber-capability …
Vulnerabilities in Car Anti-Theft Device This is disturbing: > …a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, …
Iran Cyberattacks Against Minnesota Water Systems Attribution is preliminary , and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states . And, …
ICE Is Buying Access to Credit Card Records Through data brokers, ICE is buying the information you provided to open a credit card. Posted on August 7, 2026 at 6:26 AM • 21 Comments
Friday Squid Blogging: Arctic Bobtail Squid Video Nice video of the Arctic bobtail squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t …