The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less …
AI Security Roundup
Daily AI security roundup covering malware, vulnerabilities, defensive research, cloud risk, and incident response signals from trusted technical sources.
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the …
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 …
The OpenAI Hack Shows the Genie Is Out of the Bottle This essay originally appeared in Foreign Policy . Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked …
Some Claude Chats Are Searchable on Google And it’s personal information (alternate link ): > The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on …
More on the OpenAI Agent’s Attack on Hugging Face Hugging Face has published a detailed timeline of the attack. From the summary: > The agent was running an internal OpenAI cyber-capability …
Vulnerabilities in Car Anti-Theft Device This is disturbing: > …a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, …
Iran Cyberattacks Against Minnesota Water Systems Attribution is preliminary , and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states . And, …
ICE Is Buying Access to Credit Card Records Through data brokers, ICE is buying the information you provided to open a credit card. Posted on August 7, 2026 at 6:26 AM • 21 Comments
Friday Squid Blogging: Arctic Bobtail Squid Video Nice video of the Arctic bobtail squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t …
Adversarial Clothing Designed to Fool Facial Recognition Systems There are many companies manufacturing adversarial clothing designed to confuse facial recognition systems. It’s a cool idea, but I …
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671 . “UNC6671 continues to rely …
** Ravie Lakshmanan ** Aug 08, 2026 Vulnerability / Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting …
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. …
** Ravie Lakshmanan ** Aug 07, 2026 Malware / Social Engineering ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as …
** Ravie Lakshmanan ** Aug 08, 2026 Vulnerability / Enterprise Security N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently …
** Swati Khandelwal ** Aug 08, 2026 Email Security / Vulnerability New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack …
** Ravie Lakshmanan ** Aug 08, 2026 Zero-Day / Vulnerability Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has …
Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found …
Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials
** Ravie Lakshmanan ** Jun 27, 2026 Messaging Security / Cyber Espionage The Security Service of Ukraine (SSU) said it, together with the U.S. Federal Bureau of Investigation (FBI), uncovered a …
OpenAI on Friday released three versions of GPT-5.6 , called Sol, Terra, and Luna , as a limited preview to a small number of companies as part of an ongoing engagement with the U.S. government. While …
ISC Stormcast For Wednesday, June 24th, 2026 https://isc.sans.edu/podcastdetail/9984, (Wed, Jun 24th)
ISC Stormcast For Wednesday, June 24th, 2026 <https://isc.sans.edu/podcastdetail/9984>
In a previous diary, I talked about stack strings[ 1 ] with a practical example of them. Since my SEC670 class, I’m even more interested in malware obfuscation techniques. I had a look at process …
What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)
[This is a Guest Diary by Nicole Phillips, an ISC intern as part of the SANS.edu BACS program] " I was just sitting here enjoying the company. Plants got a lot to say, if you take the time to …
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London , the entity responsible for the public transport …