Topic
Everything filed under Security, newest first.
RSS · JSON · All topics
One does not simply defend agentically
The UK NCSC on why defenders cannot mirror attacker use of AI agents—and practical ways to unlock agentic cyber defence without pretending the playing field is symmetric.
8 min · 1,832 words
Pangram Has Emerged as the Gold Standard of AI Detection. Should You Trust It?
Lexi Pandell’s WIRED investigation of Pangram, the Brooklyn AI-detection startup whose accusations reshaped literary publishing—and the limits of trusting any detector as a career-making authority.
12 min · 2,783 words
Autonomous AI Agents are breaking into Online Retailers for $25 a target
Gambit Security reconstructs an ongoing campaign where open-source AI harnesses attack retailers at ~$25/target, steal 600k+ cards, inject skimmers, and sometimes wipe databases during cleanup.
7 min · 1,518 words
Spraying in the Andes: TeamFiltration Returns to Exploit Forgotten Service Accounts
Proofpoint threat researchers track UNK_CondorFiltration, an active TeamFiltration campaign that hit thousands of Microsoft 365 accounts across dozens of tenants, with post-access activity they assess as AI-enabled.
6 min · 1,407 words
Drop: A rootless Linux sandbox with gVisor support
Drop is a rootless Linux sandbox aimed at isolating coding agents and third-party programs, with OS-level permissions, optional gVisor support, and a workflow that stays close to a normal shell.
1 min · 299 words
Three Days in August: What a DDoS Attack Exposed in Our Network
In August 2026, a large DDoS attack hit a customer and our own network directly. What happened, where our defences fell short, and what changed since then.
8 min · 1,730 words
What Happened to the Snowden Archive
The last document from the Snowden archive was published on 29 May 2019. The Guardian stopped publishing documents in February 2014, Der Spiegel in January 2015, and The New York Times and ProPublica in August 2015. After that, only The Intercept was still publishing documents, with only a few exceptions, until it closed its archive in March 2019. Eleven weeks later, on 29 May 2019, it released what would become the final batch of documents from the archive. Since then, no news outlet, journalist, or institution anywhere has published a single document from the Snowden archive.…
55 min · 12,744 words
The Function That Beat the Model: What We Measured When We Removed the LLMs
SPERIXLABS replaced a 1B-parameter local model that validated sensitive-data detections with a 40-line Python function, then published the four experiments showing where classical checks beat the LLM on accuracy and latency.
7 min · 1,535 words
Alice and Bill own identical UK iPhones, but only Alice still has Apple Advanced Data Protection. MacAnorak explains how Apple's UK ADP withdrawal created a two-tier encryption outcome for otherwise identical devices.
13 min · 2,953 words
Trail of Bits explains why SAML—the XML-based SSO protocol—is structurally fragile: XML complexity, canonicalization pitfalls, enveloped signatures, and a long history of authentication bypasses.
11 min · 2,464 words
This Digital Radio Gets Messages to the World's Remotest LocationsIt sends encrypted signals with no satellites or relay towers required
IEEE Spectrum interviews Rhizomatica’s Peter Bloom on HERMES, an open-source HF data radio that pushes files and optional encryption over the ionosphere for remote and emergency communities.
3 min · 594 words
Spymarks, not WatermarksWatermarks that spy on users are no mere watermarks
Brandon Thomas coins “spymark” for hidden tracking signals in media—like SynthID payloads that can encode user IDs—arguing privacy-hostile watermarks need a clearer name and stronger pushback.
5 min · 1,042 words
Your AI Coding Agent Can Be Attacked by the Repository It Opens
Why opening an untrusted repo with an AI coding agent is a security boundary problem—prompt injection via files, tool abuse, and practical defenses for agent workflows.
4 min · 1,028 words
Solving for faster SHA-1 collision detection
tl;dr: I discovered collision-detecting SHA-1 is slow and decided to build my own. sha1dc is a rewrite of SHA-1 with collision detection, whose code generator uses a solver to fit collision tests into SIMD lanes. It runs at 68–81% of plain SHA-1's speed where the existing crate runs at 28–29%, and can make git pack verification twice as fast.
10 min · 2,227 words
ChatGPT now knows what you do on other websites via ad collector
OpenAI's ChatGPT ad measurement pixel sets an __obi cookie that advertisers can echo from their own sites, linking ordinary web browsing back to ChatGPT accounts—and what that means for ad tracking.
5 min · 1,244 words
A security write-up of a HEIF image-parsing bug chain that could enable repository dumps, Slack RCE, Meta product RCE via image upload, and other authenticated remote code execution paths.
3 min · 696 words
Deshittification Part 2: Bypassing the App Store Gatekeeper
Lari Huttunen continues a Smart TV reclaim project: after isolating an LG WebOS OLED behind OpenBSD, blocking ACR/ad DNS breaks the App Store—how WebOS couples apps to telemetry endpoints, and how to work around the gatekeeper.
5 min · 1,259 words
Why Does AI Code Confidence Increase When Your Risk Should Too?
William Moore on the confidence trap in AI coding tools: fluency peaks on high-stakes auth/payments/migrations because they are common in training data—treat certainty as an inverse risk signal and force failure-mode reasoning.
2 min · 390 words
XNS argues wallets should only verify, authorize, sign, and broadcast—leaving construction and UX to apps—so independent reverse-checks catch compromised transaction builders.
7 min · 1,697 words
What I learned From Managing a Bug Bounty Program
Aji walks through the real work of running a bug bounty: triage, severity calls that drive payouts, stakeholder management, and the judgment calls that paper workflows omit.
1 min · 324 words