Greg Otto
@gregotto.bsky.social
@gregotto from twitter, now on bluesky. Editor-in-Chief at CyberScoop. Host of Safe Mode. Better with words than I am with code.
UPDATE: The companies did not calm down cyberscoop.com/aisi-openai-...
AISI, OpenAI report more ‘unsanctioned’ model hacks
Following similar reports by OpenAI and Anthropic, the UK’s top AI testing lab and a private cybersecurity tester say their models exploited parts of the open internet.
cyberscoop.com
would appreciate it if these companies calmed down for, like, 24 hours cyberscoop.com/anthropic-cl...
@mattkapko.com with the latest on today's open-source, package-breaking wormy boi cyberscoop.com/supply-chain...
Massive supply-chain attack compromises 440 packages under four hours
A self-replicating Mini Shai-Hulud worm compromised 860+ npm packages, including keyv, stealing cloud credentials and developer secrets across global environments.
cyberscoop.com
These AI companies are quickly burning through the “get out of jail free” cards imo
FedRAMP director put on admin leave after veterans’ hiring preference comments fedscoop.com/fedramp-dire...
FedRAMP director put on admin leave after veterans' hiring preference comments
On his personal LinkedIn, Pete Waterman apologized to civilian FedRAMP Cybersecurity Service applicants and called the practice “brutally unfair when taken to the extreme.”
fedscoop.com
would appreciate it if these companies calmed down for, like, 24 hours cyberscoop.com/anthropic-cl...
Anthropic says its AI accidentally hacked three companies during safety tests
Anthropic revealed its Claude AI models accidentally breached three real companies during safety testing after a vendor configuration error exposed live systems.
cyberscoop.com
NEW: Amazon's threat intelligence team found evidence that a little-known npm package was North Korea’s warm-up act for the axios hack cyberscoop.com/amazon-north...
A little-known npm package was North Korea’s warm-up act for the axios hack
Amazon security researchers reveal North Korean hackers spent a year testing minor packages as a rehearsal for major open-source software attacks.
cyberscoop.com
Here’s what Anthropic found when it turned Mythos loose on encryption algorithms cyberscoop.com/anthropic-cl...
Here's what Anthropic found when it turned Mythos loose on encryption algorithms
Anthropic's Claude Mythos uncovered theoretical weaknesses in post-quantum encryption candidate HAWK and a reduced version of AES.
cyberscoop.com
From @colinwood.me at @statescoop.bsky.social: A cyberattack of undetermined origin disrupted water treatment plants in at least 30 communities in Minnesota, according to the state's technology bureau. statescoop.com/coordinated-...
Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities | StateScoop
A cyberattack of undetermined origin disrupted water treatment plants in at least 30 communities in Minnesota, according to the state's technology bureau.
statescoop.com
New research shows the vulnpocalypse is just a metric ton of bugs and not a lot of actual action cyberscoop.com/ai-assisted-...
AI-assisted security tools are finding more bugs, but the threat level has not changed
Analysis from vulnerability intelligence firm VulnCheck shows AI-discovered flaws aren't being exploited any faster than traditional ones.
cyberscoop.com
I'm probably going to get yelled at in my DMs for this article but such is life -- Google’s solution to hacker name confusion? Yet another naming system cyberscoop.com/google-threa...
Google's solution to hacker name confusion? Yet another naming system
Google Threat Intelligence is overhauling how it names hackers, merging Mandiant and TAG into a unified two-word threat tracking system.
cyberscoop.com
In a letter first reported by @timstarks.bsky.social Sen. Wyden urges feds to discard older, insecure, public-facing VPNs after waves of cyberattacks targeting the legacy technology cyberscoop.com/wyden-calls-...
Sen. Wyden urges feds to discard older, insecure, public-facing VPNs
Sen. Ron Wyden urges CISA, OMB, and NIST to purge legacy VPNs across federal agencies and enforce zero-trust procurement standards.
cyberscoop.com
NEW: @timstarks.bsky.social went through the comments from CISA's CIRCIA town halls. The takeaway is that industry is telling the agency to please ask fewer questions about cyberattacks cyberscoop.com/cisa-circia-...
Industry's message on CIRCIA: Please ask us fewer questions about cyberattacks
Critical infrastructure groups are pressing CISA to narrow its long-delayed CIRCIA cyber reporting rule, demanding fewer covered entities and reduced reporting burdens.
cyberscoop.com
~Seinfeld voice~ Well, this is all very sophisticated cyberscoop.com/openai-chatg...
OpenAI says model test was behind Hugging Face hack
OpenAI confirms its AI models were used in an unprecedented cyberattack on Hugging Face's data pipeline after escaping a benchmark sandbox during internal testing.
cyberscoop.com
NEW: Research from DTEX shows that North Korea’s IT worker scheme funds Russia’s war effort cyberscoop.com/north-korea-...
North Korea's IT worker scheme funds Russia's war effort
DTEX researchers found a series of transactions in a payment wallet showing North Korean IT worker salaries flowing into sanctioned entities that support the regime’s military programs.
cyberscoop.com
Leading Democrats on the Senate Banking and Finance committees are seeking answers from the Treasury Department about DOGE’s access to agency data and what it’s doing to make sure something like that never happens again. fedscoop.com/doge-access-...
Senate Democrats press Bessent for answers on DOGE access to Treasury systems
In a letter shared first with FedScoop, Sens. Warren and Wyden asked the secretary for information on DOGE’s data access and what Treasury is doing to “ensure that such a breach has been repaired and ...
fedscoop.com
A full rundown of all the election security fireworks (and a few other topics) at the nomination hearing of Jay Clayton: cyberscoop.com/jay-clayton-...
Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed
Democratic senators pressed Trump’s DNI nominee Jay Clayton on election integrity and the 2020 results during a tense confirmation hearing, leaving without clear answers.
cyberscoop.com
Hey maybe instead of Daylight Savings Time, Congress can concentrate on more important things Like putting the production staff of NYT Connections in jail. ENOUGH WITH THIS GAME.
White House details ‘Gold Eagle’ clearinghouse for AI cyber threats cyberscoop.com/trump-gold-e...
White House details ‘Gold Eagle’ clearinghouse for AI cyber threats
The White House has unveiled "Gold Eagle," a new Treasury-led clearinghouse using AI to detect cyber threats and fast-track vulnerability patching.
cyberscoop.com
Given that election integrity is top of mind, @derekbjohnson.bsky.social just published a look at how state-level Eeection officials are facing an impossible choice: follow federal directives they don’t trust, or risk becoming targets of a criminal investigation. cyberscoop.com/trump-admini...
States are building their own election defense networks as federal support evaporates
Following recent EAC firings and a DOJ warning regarding voter rolls, state election officials are taking new legal and operational precautions.
cyberscoop.com
Russian state-sponsored hackers are breaking into critical infrastructure around the world by exploiting poorly configured and vulnerable networking devices, authorities from the United States and 12 additional countries said in a joint cybersecurity advisory Monday. cyberscoop.com/russian-fsb-...
Officials once again warn defenders that Russian hackers are targeting network devices
State-sponsored attackers are targeting critical infrastructure networks in defense, communications, energy, finance, government and health care.
cyberscoop.com
CISA looks to remedy ailments from big May credential leak cyberscoop.com/cisa-credent...
CISA looks to remedy ailments from big May credential leak
Following a major AWS GovCloud credential leak on GitHub, CISA released a forensic report detailing updated security plays and improvements to vulnerability reporting.
cyberscoop.com
NEW: Angelo Martino, Former DigitalMint ransomware negotiator who duped clients ,sentenced to 70 months in jail cyberscoop.com/digitalmint-...
Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail
Angelo Martino exploited his insider position and fed confidential information to ransomware co-conspirators to extort a combined $75.3 million from five U.S.-based victims.
cyberscoop.com
Look i love Bucc'ees as much as the next upwardly mobile east-coast family but if this thing comes for Wawa the Philadelphia area will have that beaver on a spit in the Linc parking lot before the lawsuit hits PACER www.wsj.com/us-news/law/...
Buc-ee’s Is on a Rampage and No Mascot Is Safe
The rest-stop chain is suing rivals over its trademarked beaver. Defenders of Mickey the Moose are having none of it.
wsj.com
Hey we love when our readers reach out with tips and all, but word of advice to our audience: Save the marketing pitches for the corporate inboxes. Y'all don't need to go all cloak-and-dagger on Signal or ProtonMail to announce your org is rebranding. I promise will never be that deep.
NEW: Someone defaced error pages on multiple U.S. Army internet subdomains in an apparent 404 hijacking campaign, posting messages denouncing President Donald Trump and pushing pro-Kurdish sentiments. @derekbjohnson.bsky.social has the scoop cyberscoop.com/us-army-webs...
US Army websites defaced with pro-Kurdish sentiments, insults to Trump
Multiple U.S. Army subdomains were targeted in a 404 hijacking campaign, displaying pro-Kurdish and anti-Trump messages on defaced error pages.
cyberscoop.com
Just started this book and the intro is one of the best pieces of investigative journalism I’ve read. I won’t spoil it beyond it being the real-life story of one of his most notable songs. It hit me like a freight train. Kudos @jeffpearlman.bsky.social
NEW from @timstarks.bsky.social — someone tasked with looking into NSO Group found Pegasus on their phone as they were investigating the spyware company cyberscoop.com/pegasus-spyw...
Someone infected a spyware probe overseer with spyware
A Citizen Lab report reveals former MEP Stelios Kouloglou was targeted with Pegasus spyware while serving on the EU committee investigating spyware abuses.
cyberscoop.com