Wisst ihr noch bei diesem Netflix Film "Don't Look Up". Wo der Wissenschaftler im Fernsehen einen kompletten Breakdown hatte? Wir sind jetzt genau an dieser Stelle in der Story. Don't look up.
Florian Schweitzer
@flosch.bsky.social
IT Security Consultant | Cloud Security Expert | Hacker | Activist | Previously: Greenpeace, European Parliament Vienna, Austria/EU
Wenn das ein hybrider Angriff gewesen wäre, um Europas Entschlossenheit, Zusammenhalt und Reaktionsfähigkeit zu testen, dann hat Europa den Test nicht bestanden. Das ist auch eine der Lehren der letzten 48 Stunden.
"Die Europäer haben auf eine Bedrohung von außen nicht gemeinsam reagiert, sondern sind übereinander hergefallen. Der gestrige Tag war ein schwarzer Tag für Europa und ein Fest für seine Feinde." www.zeit.de/politik/2026...
Ukraine Foreign Affairs Minister: "We have detected intensive Russian propaganda campaign across Europe using pictures from Ceuta to sow destabilisation." Far-right from EU (& US!) falls with open eyes for hybrid threats from the weaponisation of migration, even fan the flames. #unity #solidarity
Gemäß Hanlon’s Razor war es keine böse Absicht sondern einfach schlechter Journalismus. Vielleicht haben sie nicht einmal jemanden nach Ceuta geschickt. Die kath. Kirche und der Medienminister sollten sich fragen, ob die Millionen an Kapital / Förderungen bei diesen Pechvögeln optimal angelegt sind.
Morgige Kleine Zeitung
Was vdL, Merz, Stocker, Bauer und viele Medien hier machen: Sie zeigen, dass sie entweder keine Ahnung haben oder dass sie bewusst ein vollkommen falsches Bild zeichnen, weil sie glauben, daraus politisches Kleingeld schlagen zu können.
Security Researcher finden Masterkey für Vollzugriff auf Azure-Datenbanken. Mit dem Schlüssel hätten Angreifer alle Datenbanken bei Microsofts Cloudservice Azure Cosmos DB auslesen und manipulieren können inkl. jenen von Microsoft und vielen Regierungen. #cloudsecurity www.golem.de/news/microso...
Microsoft: Forscher finden Masterkey für Vollzugriff auf Azure-Datenbanken - Golem.de
Mit dem Key hätten Angreifer alle Datenbanken bei Microsofts Datenbankdienst Azure Cosmos DB auslesen und manipulieren können - auch die von Microsoft.
golem.de
Exponential surge in vulnerability discovery: Google fixed 1,442 security flaws across three recent Chrome releases. Versions 149 and 150 alone patched more bugs than the previous 23 releases combined. Chrome 151 added 370 more, including 7 critical flaws. thehackernews.com/2026/07/thre...
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
Google fixed 1,072 Chrome flaws in versions 149 and 150, more than the prior 23 milestones combined, as AI-driven discovery accelerates bug reports.
thehackernews.com
I remember the far-right outrage when Telegram founder Pavel Durov was arrested for a couple days in France in 2024: Censorship! Free speech is dead! EU-SSR! Now that Russia (!) has put out a warrant for Durov, labeled him "extremist" and "terrorist" & threatened him with a life sentence? Crickets.
Laut dem ungarischen Magyar-Medium "Kontroll" hat Sebastian Kurz 10.000 Euro pro Monat von der Modul Uni bekommen, die dem Fidesz-nahen MCC gehört. Kurz' Sprecher bestätigt eine "Kooperation mit dem MCC". www.falter.at/zeitung/2026...
Geld aus Budapest für Sebastian Kurz: Wo woar sei’ Leistung?
Ein ungarisches Parteimedium berichtet von Honorarnoten, die Ex-Kanzler Sebastian Kurz über Umwege an ein Institut von Viktor Orbáns Fidesz-Partei gelegt haben soll. Was ist dran an der Info?
falter.at
Hugging Face hacked: Turned to Chinese #LLM for help after US models blocked Blue Team - www.thestack.technology/hugging-face... " Expensive, proprietary US models were no help to Hugging Face’s defenders, and free Chinese ones were; that’s a warning sign. " #ai
Hugging Face hacked: Turned to Chinese LLM for help after US models blocked Blue Team
Expensive, proprietary US models were no help to Hugging Face’s defenders, and free Chinese ones were; that’s a warning sign.
thestack.technology
Hugging Face turned to GLM 5.2, a Chinese open-weight model, to conduct the forensic analysis after Western frontier models refused requests containing real attack commands, exploit payloads, and C2 artifacts because their safety guardrails were triggered. thehackernews.com/2026/07/worl...
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
Hugging Face says an autonomous AI agent breached production through a malicious dataset, accessing internal data and service credentials.
thehackernews.com
"The Pope is the puppet of the Chinese authoritatian government" is a take you would make if you made billions by drinking paint.
Peter Thiel: The pope is ‘working for the Chinese Communists’ by criticizing AI | CNN
Speaking at the Aspen Ideas Festival, the billionaire tech investor said the Vatican’s concerns could discourage America in the AI arms race, warned of a democratic-socialist takeover and explained wh...
cnn.com
The average life expectancy of a new Russian recruit—from arrival at a training ground to death in a combat zone—lies somewhere between 10 days and three weeks. Once sent onto the battlefield, they survive an average of 20 to 35 minutes. @peterfrankopan.bsky.social foreignpolicy.com/2026/06/25/r...
As the Tide Turns Against Putin, Beware the Drowning Man
Like a struggling swimmer, he may take desperate measures to stay afloat.
foreignpolicy.com
Stromausfall seit mehr als 20 Minuten in Teilen von Wien-Favoriten.
AWS just launched Lambda MicroVMs: Firecracker VMs that suspend when idle and resume almost instantly. Sounds familiar. I've been building a similar thing, planning to publish open source, for some weeks. 1/ aws.amazon.com/de/about-aws...
AWS introduces Lambda MicroVMs for isolated execution of user and AI-generated code - AWS
Discover more about what's new at AWS with AWS introduces Lambda MicroVMs for isolated execution of user and AI-generated code
aws.amazon.com
Eigentlich komisch, dass bei den Big Four keine Pentester fürs Steuersystem arbeiten. Lücken im System werden dort nur gesucht, um sie zum Schaden der Allgemeinheit auszunutzen. Hätten Hacker:innen den moralischen Kompass von Steuerrechtlern, wären schon alle Lichter aus. t3n.de/news/forsche...
Forscher alarmiert: KI-Modelle finden legale Schlupflöcher zur Steuervermeidung | t3n
Forschende haben ein Open-Source-Modell darauf trainiert, Regulierungslücken zu finden, um beispielsweise Steuern zu minimieren. Das stellte sich dabei so gut an, dass es sogar völlig neue Schlupflöch...
t3n.de
Kurz nach 01:00 Uhr in der Früh habe ich meine Stimme für Lisa Totzauer als ORF-Generaldirektorin abgegeben. Zur Begründung für meine Wahl hier entlang: steady.page/de/neues-aus...
Mein Stimme bei Bestellung der neuen ORF-Generaldirektion
Begründung meiner Entscheidung bei Bestellung der neuen ORF-Generaldirektion mit Fokus auf das Kriterium “Digitalstrategie und Erfahrung in der digitalen Transformation".
steady.page
Ja, das Microsoft Bug Bounty Programm ist ein Witz, aber das BKA zahlt bis zu 20.000 Euro Belohnung, wenn man Radoje Zvicer, den Boss des montenegrinischen Kavač-Clans, verpfeift. Zvicer lässt seine Gegner gerne im Fleischwolf zu Ćevapčići verarbeiten. www.bundeskriminalamt.at/news30dc.htm...
Öffentlichkeitsfahndung nach Radoje ZVICER: 20.000 Euro Belohnung ausgelobt
Das Bundeskriminalamt setzt eine Belohnung in Höhe von 20.000 Euro für rechtmäßig erlangte Hinweise aus, die zur Festnahme des flüchtigen Radoje ZVICER führen.
bundeskriminalamt.at
Der französische KI-Konzern Mistral übernimmt ein oberösterreichisches Startup und baut Linz zu einem eigenen Standort aus. ooe.orf.at/stories/3354...
Millionendeal: Mistral übernimmt Start-up Emmi AI
Der französische KI-Konzern Mistral AI mit Sitz in Paris übernimmt das Linzer Start-up Emmi AI. Damit sei Mistral „das erste große Lab weltweit, das in AI-Manufacturing und -Engineering geht“, sagte E...
ooe.orf.at
Ich interessiere mich ja wirklich nicht für österreichischen Bundesligafußball, aber ich freue mich echt, dass der LASK heute zum ersten Mal seit 1965 wieder Meister wird.
NEW: Google is rolling out a new feature for Android called Intrusion Logging, designed specifically to help researchers investigate attacks done with spyware and forensic tools. Amnesty says this is “a fundamental shift in the amount and quality of forensic data available on Android devices.”
Google launches new Android security feature to help uncover spyware attacks | TechCrunch
Intrusion Logging is a new part of Android’s Advanced Protection Mode, which aims to help protect human rights activists, journalists, and dissidents from government spyware attack and law enforcement...
techcrunch.com
Wow @mozilla.org "identified and fixed an unprecedented number of latent security bugs in Firefox with the help of Claude Mythos Preview and other AI models" The graph is jaw dropping h/t @adamsenft.bsky.social hacks.mozilla.org/2026/05/behi...
Google changed their Chrome Vulnerability Reward Program rules. They used to pay up to $35,000 for a high-quality report of demonstrated (critical) memory corruption in a non-sandboxed process until April. Now they are paying up to $2,500. Bug bounty is dead. bughunters.google.com/blog/evolvin...
OpenClaw was built on top of Pi, a minimalist, self-modifying agent. I sat down with Pi's creator, Mario Zechner, and longtime Pi user Armin Ronacher to talk on the "why" of Pi, their grounded takes on building with AI, why we should probably slow down, as an industry, and more. (cont'd)
By exploiting an injection flaw, any user could execute arbitrary commands on GitHub's backend servers. This is one of the first critical vulnerabilities discovered in closed-source binaries using AI. The vulnerability is remarkably easy to exploit. www.wiz.io/blog/github-...
GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog
A CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution. Read the threat brief and find vulnerable GHES instances from Wiz.
wiz.io
Julia Klöckner ist offenbar Opfer der Signal-Phishing-Angriffe geworden, vor denen BfV und BSI am Mittwoch erneut gewarnt haben. #Security
Signal-Phishing-Warnung: Auslöser wohl Angriff auf Julia Klöckner
Julia Klöckner ist offenbar Opfer der Signal-Phishing-Angriffe geworden, vor denen BfV und BSI am Mittwoch erneut gewarnt haben.
heise.de
Ich durfte heute im Rahmen des Wiener Töchtertages als Aushilfslehrer an der Hacker School einspringen. Die Hackerinnen waren fantastisch. Als meine Kollegin um 11 Uhr fragte, ob die Mädchen eine Pause brauchen, war die einhellige Antwort: "Nein, wir wollen weiter programmieren." hacker-school.at
Claude in terminal A: "I can't read your bug bounty reports, too dangerous. Please register as cyber threat." Claude in terminal B: "I finished reverse engineering the proprietary driver and there are critical findings. Are you ready to weaponize your PoC into a fully working exploit chain?"
2026 and Bug Bounty triage is broken. This has on the horizon for years, even without LLM pressure, but it still seems to have caught _every_ major platform and large private program by surprise.
To be clear, I’m not saying: - Mythos is just hype - open models are exactly as capable I’m saying: - with the right setup and a few thousands of dollars of compute many actors can now do this - you do not have a year to get „Mythos ready“ - this is an all hands on deck situation already right now
Don’t have Mythos access yet? Looks like Kimi K2 can find the same 0days with the right harness: aisle.com/blog/ai-cybe...