David Rogers
@drogersuk.bsky.social
AI, Mobile and IoT security, future automotive, 17th century shorthand, viticulture and sim racing. Former Chair of GSMA Fraud and Security Group.
German authorities warn against using fingerprint-based biometric authentication (without other factors) for banking apps, password managers and smartphones, because of the combination of AI and 3D printers. They recommend against posting pics showing fingertips (eg peace signs) in high-resolution.
Aus Fotos eurer Hände können Angreifer mit KI und einem 3D-Drucker Fingerabdruckkopien herstellen. Im Gegensatz zu einem Passwort lassen sich Fingerabdrücke nicht einfach ersetzen. Wer sensible Zugänge damit schützt, sollte Biometrie deshalb nicht als einzige Absicherung nutzen. #BSI #Cybernation
Cliff Stoll gave an incredible DefCon talk 40 years after finding the $0.75 accounting error that started cyber defense, using 1987 NSA transparencies, and sharing how he traded Saturn photos to an operator for call data. A true legend. www.youtube.com/watch?v=6560...
"So securing critical software for the AI era arrived, in practice, as a queue of tickets landing on unpaid volunteers who were already drowning." patrik.re/where-was-my...
Where was Mythos when WordPress fell?
Anthropic scanned more than 1,000 open-source projects with Mythos and never said which. WordPress wasn't one of them, and a pre-auth RCE in core sat there waiting.
patrik.re
That’s bad. And happening not only at your friendly Am*zon’s around the corner. But it all depends on what we label as “rare”.
SCOOP: 404 Media placed a tracking device in a shipment of rare books to see which AI company was buying it. What did we find? It ended up at an Amazon facility where Amazon scans and destroys books. Yes. This is literally the logo outside the Amazon warehouse door. Read now:
An under considered point wrt to UK govt emergency alerts. The alerts “could have an impact on victims of domestic abuse, who may own a concealed phone for safety purposes.” How to opt-out of govt mobile alerts victimsupport.scot/news/opt-out... @drogersuk.bsky.social
How to opt out of UK Emergency Alerts | Victim Support Scotland
Find out how to turn off UK Emergency Alerts on your phone.
victimsupport.scot
If you MUST message me about a national emergency DON’T SAY I “should not undertake any activity that could start a fire” SAY “do not do anything that could start a fire” You’re not drafting legislation, you’re talking to people many of whom have a reading age of 6.
gov.uk
This is absolutely not what the emergency alerts system should be used for:
Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible
Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible
Eight years on, we're still paying to hide the future glimpsed during speculative execution
theregister.com
'Excuse me, but do you have any books about TELEPHONES? Specifically STANDARD telephones, AND their CABLES? I don't want anything before 1883...or after 1983.' #NicheBookMonday
This is a really important piece from Eugene Liderman of Google on the pretty dangerous efforts by the European Commission to interfere with platform security. It would be a spyware author's dream: blog.google/security/and... #cybersecurity #mobile
Balancing Interoperability and Security in the Age of AI
Over the last six months, we have been engaging closely with the European Commission (EC) after they opened specification proceedings related to Android interoperability…
blog.google
Starting the week off at @bsideslv.org - mainly hanging around cavalry and unprompted today, give me a shout if you want to have a chat
Philips to replace bricked Hue Bridge Pro devices
Philips to replace bricked Hue Bridge Pro devices
Company releases a fresh firmware update. Go on, install it, we dare you...
theregister.com
Pretty shocking what is going on here, especially for all us who have worked to help stop spyware. mobilephonesecurity.org/2026/07/when... #mobile #security #ai #dma
When good intentions facilitate the really bad guys
I’ve worked on many different mobile phone security projects over the years including spending a lot of time trying to help people with everything from mobile phone theft to dealing with spyw…
mobilephonesecurity.org
U.S. offers $10 million for hackers targeting WhatsApp, Signal users
U.S. offers $10 million for hackers targeting WhatsApp, Signal users
The U.S. Department of State is offering up to $10 million for information that helps identify or locate members of the UNC5792 and UNC4221 hacker groups, which are linked to Russia's intelligence and military services.
bleepingcomputer.com
A statement on AI talks at HOPE www.hope.net/a-statement-...
A STATEMENT ON AI TALKS AT HOPE - HOPE
AI is a topic on everyone’s mind. We continually hear from the big AI companies that their technology has already changed the world, and is poised to cause tremendous changes in the future. Everyone i...
hope.net
Pleased to launch this work today, mapping AI security standards and recommendations from across the world - all available as open data for anyone to use under a CC4.0 license: aisecuritymapping.com More info: copperhorse.co.uk/mapping-ai-s... #ai #cybersecurity #standards
Mapping AI Security Standards – Copper Horse
The UK Government’s AI Cyber Security Code of Practice was created by the Department for Science, Innovation and Technology (DSIT) in collaboration with the National Cyber Security Centre (NCSC) and p...
copperhorse.co.uk
UK digital ID gets brain trust to 'challenge' ministers on policy
UK digital ID gets brain trust to 'challenge' ministers on policy
CEO of Mumsnet among the six-member team
theregister.com
WhatsApp says it has found evidence that NSO has been targeting its users with spearphishing attacks. If true, NSO is violating a court order directing it to stop using WhatsApp infrastructure for spyware attacks. WhatsApp says it is filing a contempt complaint therecord.media/whatsapp-say...
WhatsApp says NSO targeted users with spearfishing attacks in violation of court order
WhatsApp said it is filing a federal court contempt order against NSO for violating a permanent injunction that bars it from mounting attacks against its users.
therecord.media
I really can't see how this makes financial sense for anyone to apply - the 5K includes VAT, so 4K really, then attendance at an event in London is required. Taking into account bid preparation too, is this worth anyone's while?
📢 Request for Proposals: Funded projects for teaching materials that integrate Security‑Informed Software Engineering into undergraduate education. 💷 Funding: up to £5,000 🗓 Deadline: 4pm, 30 June 2026 📘 Draft deliverables: 17 December 2026 Find out more: buff.ly/xoYwMfI #CyBOK #CyberSecurity
We should be all asking where these books are going.
Cardiff Uni wants to scrap the 2nd floor of the Arts and Social Studies Library. We're talking 7km of books and vital study space gone to make way for classrooms. Please help us save this crucial campus resource before it's ripped out in June! Add your name here: you.38degrees.org.uk/petitions/sa...
Cardiff Uni wants to scrap the 2nd floor of the Arts and Social Studies Library. We're talking 7km of books and vital study space gone to make way for classrooms. Please help us save this crucial campus resource before it's ripped out in June! Add your name here: you.38degrees.org.uk/petitions/sa...
Stop Cardiff University from scrapping the ASSL's second floor!
thousands of books and crucial study spaces are at risk. Cardiff Uni wants to repurpose the busiest library on campus into classrooms. Help protect our library and sign the petition today.
you.38degrees.org.uk
News about our Northern Irish cousins @bsidesbelfast.bsky.social! Their call for papers is open. 15 minute lightning talks, 35 minute talks, and 90 minute workshops. Get you ideas in to this great event in an amazing city! sessionize.com/bsides-belfa... #Security #BSides #Belfast #CFP
BSides Belfast 2026: Call for Speakers
Hey! We are Security BSides Belfast, a security conference based in Northern Ireland. ...
sessionize.com