First up we talk with Threatlocker CTO Michael Jenkins about threat actors use of AI and keeping the bad things out with Zero Trust. Then in the security news:
- Compiling spreadsheets, because that's why
- Nvidia wants to put AI agents in timeout
- Citrix NetScaler gets exploited again, and again
- Spectre still refuses to die
- Your SBOM is incomplete?
- File notifications leak more than filenames
- ENIAC had cables instead of a BIOS
- Another Linux kernel root exploit lands
- Containers share a kernel
- ThinkNode M9 microSD card gets a virus notice
- Google analyst infiltrates a supply-chain gang
- Your phone speaker can transmit radio
- Reconstructing firmware with a logic analyzer
- Robot dogs learn cybersecurity
- CISA warns about third-party ICS integrators
- Dutch police arrest a ShinyHunters suspect
- A soldier goes from telecom hacking to prison
- AI companies discover their agents have opinions
- Cloudflare containers accidentally share leftovers
- OT networks are still mostly not isolated
- Florida wants to pause ChatGPT
The interview segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them!
Michael Jenkins is a cybersecurity leader with nearly 20 years of experience building and managing security technology. He was an early advocate for Zero Trust and has spent much of his career advancing its use as a practical approach to preventing cyberattacks.
Michael joined ThreatLocker as Chief Technology Officer in 2019 and has helped build the company’s Zero Trust Platform. He leads the company’s development and product teams and has led the creation and expansion of products across endpoint, network, and cloud security, including Zero Trust Network Access and Zero Trust Cloud Access.
Michael has also made developing people a major part of his leadership at ThreatLocker. He has mentored dozens of employees, including professionals who joined the company in entry-level roles and grew into highly skilled developers and cybersecurity practitioners. He regularly leads large product development initiatives under demanding timelines while maintaining a strong focus on product quality.
A frequent author and speaker on cybersecurity and Zero Trust, Michael advocates for deny-by-default controls that give users access to what they need while limiting everything else. During his career, Zero Trust has grown from a relatively uncommon approach into a cybersecurity model widely adopted by businesses and U.S. government agencies. Michael has helped drive that evolution through the products he has built and the professionals he has mentored.
If your threat model still says "hackers break in," you're about five years behind.
They're logging in with stolen creds, abusing cloud identities, automating recon, and turning AI into a force multiplier. Meanwhile, you've got a vulnerability backlog that's older than some interns.
If you're defending financial infrastructure, this one's worth your time.
Join us October 14 for the FinSec Virtual Summit to hear how practitioners are prioritizing the threats that actually matter and defending modern financial environments without chasing every shiny new security product.
Register for free at https://securityweekly.com/finsec using the discount code CSS26-SW!
InfoSec World is introducing a fresh experience for 2026, with new voices, a new venue, and new topics reflecting the challenges security teams are facing now. Join practitioners and leading professionals from across industries in Orlando, October 12–14. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026.
Paul Asadoorian
- Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation
Summary: Google says vulnerability disclosures doubled in 2026, reaching 10,740 in August, while exploited vulnerabilities have already surpassed the total from 2025. The bigger concern is AI helping attackers analyze patches and public exploit code, turning newly disclosed flaws into working attacks within days, especially against perimeter appliances and exposed enterprise services.
Paul's take: The number of vulnerabilities is less interesting to me than the shrinking window between disclosure and exploitation. Attackers don't need a zero-day when AI can compare patched and vulnerable versions, understand the bug, and build an exploit for an n-day almost immediately. The BeyondTrust example, with multiple threat clusters exploiting it within a week, is the practical takeaway. Patch internet-facing appliances quickly, and assume that public technical details are already being operationalized (because they are). Yikes.
- Sheety Turns Spreadsheets Into Binaries, For Some Reason
Summary: Sheety turns spreadsheet definitions into self-contained executable binaries with a terminal interface, allowing users to browse, edit, and recalculate formulas without runtime dependencies. It can import and export Excel and YAML files, and even recompiles itself when formulas change.
Paul's take: This is software that nobody really needs, and that is exactly why I like it. We have spent years turning simple tools into bloated platforms, so someone building a spreadsheet that compiles itself into a binary feels like a small act of rebellion (or possibly a cry for help). There are probably legitimate uses, but mostly this is a fun project built because the author could, which is still one of the best reasons to write software. Sheety does spreadsheets for some reason, and I respect that.
- Nvidia Says AI Agent Safety Platform Can Prevent Rogue Activities
Summary: Nvidia announced the Open Agent Safety Platform, combining the open source OpenShell runtime with a hardware enforcement layer called Sentry on BlueField-4 DPUs. The system is designed to sandbox agents, enforce policies, log decisions, and quarantine agents that try to take actions outside their approved boundaries.
Paul's take: I like the basic idea because an AI agent should not be trusted to enforce its own permissions. Nvidia says its testing found agents spending up to two hours trying to convince an AI reviewer to let them modify a protected GitHub repository, which is exactly the kind of behavior that makes “just prompt it not to” a terrible security model. The catch is that this is also a Nvidia platform announcement, so the hardware layer, partner list, and claims about preventing rogue behavior deserve testing rather than applause. Sandboxing and independent enforcement are useful, but detecting that an agent is “reasoning about moving beyond its target” sounds a lot harder than blocking a network write. We will see how much of this is security engineering and how much is selling more Nvidia hardware.
- Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
Summary: Google and Mandiant report active exploitation of two zero-days in Citrix NetScaler ADC and Gateway appliances, with attackers gaining root access, installing PHP web shells, and using a Python tunnel for internal reconnaissance and credential theft. The campaign used disguised file extensions, modified web server configuration, and set the SUID bit on
/bin/shto preserve root-level execution after the web server dropped privileges.Paul's take: The
/bin/shdetail is the big one for defenders. A shell with the SUID bit set should set off all sorts of alarms on Linux-based systems, because it is basically a root privilege-escalation mechanism waiting to happen. The NetScaler attackers also hid PHP web shells behind.deband.sigfiles, modifiedhttpd.conf, and dropped a tunneling tool, so this is a good reminder that edge appliances are operating systems with an internet-facing job, not magical boxes. Patch the appliances, inspect the configuration and filesystem, and assume credentials on a compromised gateway were exposed. Also, make sure your monitoring can actually see these systems, because they are often outside the reach of EDR. - New Spectre v2 attack variant leaks Linux root password hash in minutes
Summary: Researchers developed Branch Target Reuse, a new Spectre v2 variant that abuses stale CPU branch predictions after JIT-compiled code is replaced. They built an end-to-end Linux cBPF exploit that leaked a root password hash in roughly three to five minutes on tested Intel systems, but the attack requires local code execution and produces a hash, not the plaintext password. Kernel mitigations have already been upstreamed for CVE-2026-64507 and CVE-2026-64508, while the browser and GraalVM research remains incomplete.
Paul's take: This is a real and clever piece of research, but I don't think it is the next big Linux incident. It is not a remote attack that lets somebody on the internet steal root hashes from random Linux machines. An attacker already needs code execution, and then they get a password hash that still has to be cracked. If you run hostile code in a shared environment, or you are using cBPF in a security boundary, update the kernel. Otherwise, this belongs in the normal patch cycle. My advice to attackers: wait for the next Linux LPE vulnerability and exploit that instead. You won't have to wait long.
- Your SBOM Is Fan Fiction
Summary: The article argues that traditional SBOMs describe what was declared or installed, not what is actually running. Its runtime inventory reads
/procto identify mapped libraries, deleted-but-still-loaded files, statically linked dependencies, listening sockets, and vulnerable functions that are really present in memory. The open source tool also correlates those findings with package advisories.Paul's take: “Your SBOM is fan fiction” is a great headline, although it is a little unfair to SBOMs. An SBOM answers what the build system thinks it shipped, while
/procanswers what is actually running on the machine, and those are very different questions. If you patched OpenSSL three weeks ago but never restarted the process, the vulnerable library is still in memory. That is the kind of detail defenders need. I like the runtime view, especially for statically linked binaries and mystery software dropped into/opt, but this is not a replacement for an SBOM. It is the missing reality check after the software gets deployed, and a great way to hunt for exposures and potential compromise. - Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772)
Summary: WatchTowr analyzed CVE-2026-88772, a pre-authentication DTLS memory overflow in Citrix NetScaler that can lead to remote code execution or denial of service. The flaw is exploitable when DTLS is enabled, which is the default for VPN virtual servers, and the researchers turned the overflow into shellcode execution by corrupting a function pointer and using ROP to bypass NX.
Paul's take: This is another reminder that “hardened security appliance” does not mean “immune to memory corruption.” The detail that jumped out at me is that the vulnerable
nsppebinary has no PIE, no RELRO, and no stack canary. I am curious why more programs, especially internet-facing security appliances, are not compiled with PIE by default. There must be a good reason, whether it is performance, compatibility, or the appliance build process, but leaving predictable addresses in a pre-authentication RCE target seems like making the exploit developer's job unnecessarily easy. Either way, this is a 9.5 Critical vulnerability with active exploitation, so patch NetScaler and stop exposing DTLS unless you actually need it. - From AI Agents to RCE – Building a Vulnerability Research Workflow – Quarkslab’s blog
- File Notification Attacks
Summary: Researchers found file-notification side channels across Linux, Android, Windows, and macOS that reveal activity without revealing file contents. Examples include Linux keystroke timing, Android apps observing WhatsApp file events, Windows users learning which websites another user visits, and KDE applications detecting authentication prompts. The attacks require a local attacker, such as a compromised user process or supply-chain-infected package, and the researchers are not aware of exploitation in the wild.
Paul's take: I don't think this is a big deal either, but I could be wrong. This is a clever side channel, but it is not remote code execution, and it doesn't let an attacker read files. The attacker already needs to be running locally, often in another user's context, and then has to turn file activity into useful information. That is meaningful for shared systems, malicious packages, and Android privacy, but it is not something I would panic over on a normal single-user Linux desktop. The Linux keyboard example is mostly timing data, and the most serious
/dev/inputbehavior has already been partially mitigated. Keep an eye on it, especially if you run multi-user systems, but this feels more like an important research finding than the next major attack. - Did the ENIAC have a BIOS?
Summary: ENIAC did not have a BIOS in the modern sense. Operators programmed it by physically wiring plugboards and setting switches, configuring the machine for each job instead of firmware initializing hardware and loading an operating system.
Paul's take: This is a fun reminder that “computer” covers a lot of history. ENIAC did not boot, enumerate devices, or look for a disk with a bootloader. You programmed the thing by moving cables and setting switches, then hoped the vacuum tubes cooperated (which they often did not). In that world, the BIOS was basically the humans standing in front of the machine. We have come a long way from that, although some firmware update processes still feel like they were designed with the same general philosophy.
- security-research/pocs/linux/kernelctf/CVE-2026-80521_lts at kernelctf-exp557-cve-2026-80521 · Markakd/security-research
Summary: This public KernelCTF exploit targets CVE-2026-80521, a use-after-free in Linux AFUNIX socket garbage collection. An ordinary unprivileged user can trigger it without a user namespace, BPF, iouring, or special capabilities, and the exploit achieves local root on affected kernels. The vulnerable code is present across several Linux release ranges, including 6.12.95, with a stable fix available.
Paul's take: This is the Linux local privilege escalation story I actually care about. AF_UNIX sockets are everywhere, the attack requires no special capability, and the public exploit is not just a crash PoC. It has a reliable reclaim strategy, handles KASLR, and reaches a kernel callback to execute a command with kernel credentials. That is a real post-compromise escalation path, especially on shared servers, containers, build runners, and anything where an attacker already has a low-privilege shell. Check your kernel version and patch this one. This is much more useful to an attacker than another theoretical side-channel paper.
- Containers Are No Longer a Security Boundary
Summary: DepthFirst released a container escape exploit for CVE-2026-80521, a Linux kernel use-after-free in the AF_UNIX socket subsystem. The exploit works from an unprivileged container against Ubuntu 26.04, demonstrating the fundamental risk of containers sharing the host kernel, and the company recommends microVM-based isolation such as Firecracker or Kata Containers for untrusted workloads.
Paul's take: I don't agree that containers are suddenly “no longer a security boundary.” They are still a useful boundary when configured correctly, but they never have been a security boundary (virtual machines either). This exploit matters for multi-tenant environments and workloads running untrusted code because a kernel bug can bypass namespaces, seccomp, and the container runtime to reach the host. That is a real reason to patch quickly and use microVMs where the threat model demands it. I am less convinced by the article's claim that AI means attackers can escape containers at will. That is marketing language. The practical lesson is simpler: containers share a kernel, kernels have vulnerabilities, and sometimes a public exploit will turn one into a host compromise.
- 80 Days Reverse Engineering an IoT DVR: What I Found and Why It Didn’t Work Out
Summary: A researcher spent 80 days reversing ARM32 firmware from a white-label surveillance DVR platform and found hardcoded AES keys, an unsigned root firmware update path, and command injection in older firmware. The research also uncovered an important limitation: the physical test device ran a newer build where the vulnerable network handlers were gone, so the researcher could not prove a live remote exploit against the thousands of exposed devices without attacking someone else's DVR.
Paul's take: This is my kind of research writeup because it includes the parts that did not work. The researcher found code that looked like a remote command injection, then traced the callers and discovered the iSCSI path was only reachable from the local GUI. That is the difference between finding dangerous code and proving a vulnerability. The hardcoded AES key and unsigned root update path are still terrible, but firmware divergence and the lack of a vendor willing to respond limited the fleet-wide impact.
- Pwnd Blaster: Hacking your PC using your speaker without ever touching it
Larry Pesce
- ThinkNode M9 microSD Card & Virus Notice
- An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang
- Apple patches CoreGraphics zero-day already exploited in targeted attacks
- Turning a Smartphone’s Speaker Amplifier into a Silent Intentional VHF Morse Transmitter
- Reconstructing Device Firmware From SPI Reads
- Robot dogs serve as cybersecurity training tools for students at one Pennsylvania university
- Teen researcher with AI hackbot cracks Microsoft’s Titan analytics
- Sanctioned Russian firm identifies multiple security vulnerabilities in Android and Apple devices
- One Packet Can Take Down the Database Behind Industrial Operations: Ridge Security Discovers CVE-2026-42542
- Building cyber resilience as satellite communications rise
Lee Neely
- Tokyo rail firms report online security breaches
Summary: Two railway operators in Tokyo have reported breaches of their online systems. Both say there's been no impact on their train services. Tokyo Metro says unauthorized access to a server may have resulted in the leak of about 59,000 email addresses of members of its loyalty program. The subway network operator says there was a glitch in its email delivery system on September 20. Another rail operator, Keio Corporation, reported on Saturday that a ransomware attack has disabled part of its sales system.
Lee's Take: The Tokyo Metro breach feels more like someone attempting to use the email capabilities to make nefarious emails look legitimate to members. My thinking is you need to make sure that you've got the security dialed in on any systems authorized to send email on your behalf, particularly third-party services. Have a formal process for updating, testing and verifyiing SPF, DMARC and DKIM settings, to include removing entries for services which are no longer in use.
- Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators
Summary: CISA and the FBI have published a joint Fact Sheet containing advice for critical infrastructure entities working with third-party industrial control system (ICS) integrators. According to the document, critical infrastructure owners and operators should "ensur[e] the principle of least privilege (PoLP), is applied, as third-party ICS integrators "may inadvertently introduce security issues to a customer environment by exposing systems and services not pre-configured to the customer’s security requirements." FBI technical analysis revealed that in March and April of 2025, "malicious foreign cyber actors gained access to the network of a U.S. industrial automation solutions company that offered services—such as system integration, engineering consulting, and SCADA programming—for industrial customers, including power utilities and transportation entities," conducted searches, and readied hundreds of files "for presumed exfiltration." The document lists recommendations to reduce risk and provides resources for guidance on asset inventories, SBOMs, and supply chain risk management.
Lee's Take: Beware of third-party integrators with access to your production systems. I'm sure we're all aware of the risks relating to ICS/OT systems, but, if you're like me, you need all the help you can get to get your arms around both securing and educating system owners to ensure they really are secure, particularly when you're getting something from a third-party which has a remarkable list of clients giving the impression they have this handled. Read the CISA PDF, it's 4 pages, then strategize with your team on how to assess your current risks as well as improve your approach with current and future integrators. Invite system and data owners to the session, so you're all on the same page. While remote access/Internet exposure and strong authentication top our hitlist of concerns, the paper raises other equally valid areas to assess you may otherwise overlook.
- Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950)
Summary: Apple released an emergency patch to address a high-severity vulnerability in iOS and macOS before version 27 that may be under targeted exploitation. CVE-2026-86950, CVSS score 8.8, allows an attacker to achieve arbitrary code execution by exploiting an out-of-bounds write issue that occurs when CoreGraphics processes a maliciously crafted file. Meta Product Security is credited with the report of this flaw. Apple has fixed the issue with improved bounds checking in iOS and iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1, and notes that the company has received a report that the flaw may be under exploitation "in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."
Lee's Take: Don't overlook that iOS 27.0.1, visionOS 27.0.1, watchOs 27.0.1 and macOS 27.0.1 also dropped today. At a minimum make sure that your teams are already assessing the compatibility and manageability of these, ideally on test hardware. The answer you're looking for is that we can manage them, the security works and our core applications work properly, or a timeline to get there, rest assured users are looking hard at the option to apply another update to the old familiar OS versus updating to the new and shiny thing, particularly as this is the first update since the production 27.0 release. Remember, macOS 27 only runs on Apple Silicone. I recall when Macs ran on Motorola CPUs. Note there are more AI functions (aka Apple Intelligence) starting with the iPhone 15 Pro, and even more so with the iPhone 17 Pro and beyond. Check out Siri AI, improved photo editing, added Child Safety and Parental controls along with other system improvements.
- DC Health Agency Exposes 400,000 Beneficiary Records
Summary: The District of Columbia Department of Health Care Finance (DHCF) has begun notifying people that their personal information may have been compromised. The data were exposed via "two reports on DHCF’s website [which] contained hidden personal information that could be accessed by people who did not have permission to view it." DHCF has removed the reports from the website, launched a review to determine how the situation came to be, and started enhancing practices to prevent a recurrence. The compromised data include Medicaid ID numbers, dates of birth, provider names, race, gender, and ethnicity. The incident affects roughly 400,000 individuals who were enrolled in the Medicaid or Alliance programs between 2023 and July 2026. DHCF has reported the incident to the Department of Health and Human Services Office for Civil Rights.
Lee's Take: I'm reminded of a ranking/salary presentation which was shared, which included an embedded spreadsheet which had sensitive data in hidden columns. Even back then, it took very little time for those with it to figure out where the information management didn't want shared was hidden. Today, modern tools, which include AI, make the discovery loop both shorter and virtually guaranteed. So, that means we cannot rely on security by obscurity. In short, if you don't want information discovered, don't make it available. If a conversation includes "nobody will ever know" or "they'll never find it", consider those red flags and an opportunity for education and improvement. Remember to be kind, the person may not be aware of the current threat environment, this is not likely their focus or specialty.
- Dyfed-Powys Police cops to cyberattack, staff data potentially nicked
Summary: Dyfed-Powys Police has revealed it was hit by a cyberattack that knocked some of its systems offline, with investigators now trying to establish whether the intruders got their hands on staff data during the break-in. The Welsh police force said it identified the incident on September 14 and that it caused disruption to some non-emergency systems. Emergency policing remained operational throughout the incident.
Lee's Take: From the outside looking in, the Dyfed-Powys Police have done a great job maintaining services and publicly appearing unaffected, while internally spinning up the incident response, investigation and remediation quickly and smoothly. The attackers appear to have focused on systems which manage staff data (e.g., HR/Accounting) rather than public/citizen information. I'd put this in your watch and see category with hopes there are things you could add to my response playbook in the future.
- Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772) – Help Net Security
Summary: Over the weekend, Citrix published an advisory addressing eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. Two of the flaws are confirmed to be actively exploited: CVE-2026-88771, CVSS score 9.5, a remote code execution vulnerability due to improper input validation, and CVE-2026-88772, CVSS score 9.5, a memory overflow vulnerability leading to remote code execution or denial of service. Citrix made available a list of indicators of compromise for the advisory; the list is accessible through NetScaler Console. The US Cybersecurity and Infrastructure Security Agency (CISA) has added these CVEs to the Known Exploited Vulnerabilities (KEV) catalog with mitigation deadlines of Wednesday, September 30
Lee's Take: If you're a Citrix NetScalar shop, and haven't applied the updates, you need to assume compromise at this point. This means you need to check every box for webshells after applying the patch. Be aware, the Citrix detection script depends on logs which have sufficient history to detect the attack, so you may want to look at your SIEM rather than device logs. You need to look back at least a month for suspicious activity, anomalous actions, including the identified base64 strings after the User-Agent field.
- Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation – Krebs on Security
Summary: Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.
Lee's Take: Don't get distracted by the efforts to shut down the ShinyHunters gang, while that would be amazing, we're still left making sure our environments are secure from all the gangs.
- ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
Summary: Google Threat Intelligence warns of renewed mass exploitation of CVE-2026-35273, a critical missing authentication flaw in Oracle PeopleSoft that was disclosed and fixed in June. The latest wave of activity seems to involve using URL encoding to bypass web application firewall (WAF) rules that mitigate the flaw. The renewed campaign, which GTIG assesses is linked to ShinyHunters, has been "deploying web shells on dozens of systems globally, spanning higher education, technology, IT services, healthcare, agriculture, transportation, and government." GTIG urges users to apply Oracle's fix; ensure PeopleTools is a supported version; disable EMHub service or remove the PSEMHUB application; conduct log and endpoint monitoring for specific requests; conduct host-level auditing for unexpected files and unauthorized content; hunt for evidence of data theft; and prepare for possible extortion communications and public exposure of stolen data.
Lee's Take: Don't get distracted by the efforts to shut down the ShinyHunters gang, while that would be amazing, we're still left making sure our environments are secure from all the gangs. ShinyHunters is targeting this PeopleSoft weakness. If you're a PeopleSoft shop, make sure you've got the latest mitigations for CVE-2026-35273, CVSS score 9.8. This is remotely exploitable without authentication. Your actions include applying the patch from Oracle as well as the remediation and hardening guidance in the GTIG report from September 25th. No workarounds here - you need to apply the update.
- Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings
Summary: A coalition of 44 US state attorneys general has settled a lawsuit against Labcorp, fining the company $2.3 million and requiring it to adopt measures to improve its data security posture. The suit was filed over a 2019 breach at American Medical Collection Agency (AMCA), a third-party debt collection company and subsidiary of Retrieval-Masters Creditors Bureau (RMCB), which detected the breach on March 19, 2019. A subsequent investigation determined that the intruder had access to AMCA's network between August 1, 2018 and March 30, 2019, and exfiltrated names, Social Security numbers, financial data, medical test data, and other information. According to the HIPAA Journal, "the AMCA data breach was the largest data breach reported in 2019 by a HIPAA-regulated entity, affecting more than 27.5 million individuals, including more than 10.2 million Labcorp patients." The settlement requires that Labcorp include cybersecurity requirements in vendor contracts, create a response plan for security incidents affecting vendors, limit the data it shares with its vendors, and establish a risk management team that will ensure vendors' compliance with data security requirements.
Lee's Take: It's easy to lose site of the fact that this was a third-party breach, as such, the settlement isn't a huge surprise. For the rest of us, skip the incident and settlement and go straight to making sure that your contracts include appropriate security requirements, and, more importantly, that you're verifying them before you're processing production data as well as verifying them on a regular basis. The verification is needed as services change over time, on both sides, and you don't want to find out the hard way you missed something, or a configuration drifted, regardless of the cause.
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions – Krebs on Security
Summary: A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
Lee's Take: Wagenius and his co-conspirators appear to be behind the Snowflake data thefts in 2024. Despite having a lot of exfiltrated data, Wagenius was unsuccessful at his extortion attempts, which included threats of releasing national security secrets and re-extorting victims which had already paid the larger extortion group, netting only about $1500, yet, while awaiting trial was able to leverage other inmates email accounts to attempt to find and exploit weaknesses in the Bureau of Prisons' systems. In addition to the fines and prison time, he is unlikely to ever be granted another security clearance, or to work for the US Government or military. Those are some pretty big bridges to burn, and unless he curtails his propensity to pursue criminal venues with his hacking, he's got the makings of a great pen tester; it's not clear he's going to land a job in the private sector either.
Sam Bowne
- Florida asks for emergency order to halt ChatGPT development
"Stop pretending it's human. Stop selling it to kids. If Sam Altman meant what he said about slowing down, he can join our ask to the court. If he will not, we ask the court to do what OpenAI will not do for itself: protect Florida families."
- Scoop: Top AI companies probing tens of thousands of security incidents
OpenAI, Anthropic and security researchers are investigating tens of thousands of incidents in which their frontier models took steps that outside evaluators would consider problematic. The episodes include bypassing guardrails, creating message boards, escaping sandboxes, website hijacking, self-prompting or seeking to bypass monitors.
- After Dozens of Incidents at OpenAI and Anthropic, OpenAI Pauses Model Training to Build More Safeguards (apnews.com)
OpenAI will resume training "only when we are confident that we have additional safeguards" in place. It is the second time in three months that OpenAI has halted development of its models.
- What is Jev? The System One model, explained
Jev is an AI that decides instead of writing. Give it any text or JSON and a few typed questions: it answers all of them at once, with a probability for every possible answer. It runs 20x to 200x times faster and much cheaper than normal LLMs.
- With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance
SOC 2 needs updates for the age of AI agents, because they don't have a clear human identity or owner. Most organizations cannot clearly distinguish AI agent actions from human ones.
- ‘Salesbleed’ Exploits Salesforce Agents to Enable Slack Phishing
Vulnerabilities in Salesforce Agentforce, collectively dubbed "Salesbleed" by researchers, could expose customers' internal data and, worse, allow attackers to phish employees from within trusted company channels. Attackers could plant a specially crafted AI instruction -- for example, an instruction to exfiltrate data to an attacker-controlled URL -- in a Web-to-lead form. An agent on the other end of the interaction would ingest and process the instruction, and execute the request inside of the victim company's environment. Salesforce has patches these vulnerabilities.
- Cloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk Data
The pool was set to skip wiping a block before handing it to the next container. Cloudflare fixed the flaw.
- After multiple deaths and injuries, NHTSA is investigating comma.ai
Comma.ai sells aftermarket devices that can boost or augment a vehicle’s native advanced driver assistance systems. Feds know of 5 crashes where cars using comma.ai devices hit slow or stopped vehicles.
- Only 13% of OT Network Segments Are Fully Isolated: Analysis
Of all segments that included at least one OT device, only 13% consisted of OT devices alone, while the rest shared space with IT or IoT equipment. Segments with medical devices fared worse, with just 6% dedicated solely to IoMT.
