AI will never become a good writer, because a machine can never feel the pleasure of hearing words flow through a mind.
Renato Gabriele
@remagio.bsky.social
"If you have a garden and a library, you have everything you need." by Cicero. https://www.journalismfestival.com/speaker/renato-gabriele
If a technology *can* be abused, it *will* be abused. This goes doubly for those in positions of power. Technology policy can be difficult, but we should never lose sight of this fact.
New: We found 50 cops who misused Flock cameras and other license-plate readers for personal purposes, often to spy on their girlfriends or ex-wives. He "watched every single move I made. ... Who do you turn the chief of police in to?" wapo.st/3S6rTuo
Those “public wifi is fine now” people are going to hate Microsoft’s good advice for the SVR abuses of hospitality captive portals. www.microsoft.com/en-us/securi... “When traveling, users should treat hotel, conference, airport, & other guest wireless networks as untrustworthy.”
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order ...
microsoft.com
Took me seconds to make an image showing 'protesters' around Google buildings, using Google Earth's new AI generation tool. You can make bomb blasts, protesters, drone strikes, nuclear plants. How on earth did Google think this was a good idea www.404media.co/google-earth...
I used to do some work on the ethical use of satellite and drone imagery for aid and disaster response, and it is genuinely hard to express in words what a dangerous, stupid thing Google is doing by making it easy to use GenAI to create faked satellite imagery:
How to plant a nuclear plant in Iran
The question is: what on earth is Google doing?
digitaldigging.org
I realised some people* were using a super out-of-date version of hostapd-mana based off the upstream 2.6 branch instead of the newer 2.10 branch. This was probably because I never made the 2.10 branch the main. Well that’s fixed now. github.com/sensepost/ho... * me - see last commit for an eg
GitHub - sensepost/hostapd-mana: SensePost's modified hostapd for wifi attacks.
SensePost's modified hostapd for wifi attacks. Contribute to sensepost/hostapd-mana development by creating an account on GitHub.
github.com
Over on Mastodon (I strongly recommend), @doublepulsar.com asked fellow defenders what's on their radars and how much of what they're actively dealing with is AI-related. The responses are overwhelmingly, no. ClickFix attacks and phone calls/social engineering remain among the top threats.
Kevin Beaumont (@GossiTheDog@cyberplace.social)
Sense check for people working in cybersecurity in operations roles in the trenches: I’m not finding or seeing cyber incidents off the back of Generative AI still. Are you? Not ones you’ve read about...
cyberplace.social
This is a great explainer of the OpenAI hack against Hugging Face, particularly of the report that the latter published earlier this week. If you had trouble parsing the highly technical report, this article can walk you through it.
The Hugging Face AI break-in, as told through an increasingly committed bear metaphor | TechCrunch
Another way to think about the whole thing is to picture a bear at a campsite. (Really, we are going there.)
techcrunch.com
I know it’s not most folks‘ primary concern, but LLMs or not, I’m unimpressed by how soft these infrastructure services are. What do you mean HF had a Jinja2 template injection. And I’m still not over GitHub’s unsandboxed RCE. Geomys might need to self-host code/CI to avoid a weak link.
An example of the fall of a security civilization: Cisco collapsing multiple different vulnerabilities into one CVE. It breaks a lot of feeds & products built to manage risk & is non compliant with standards like ISO 29147 Vulnerability disclosure sec.cloudapps.cisco.com/security/cen...
Cisco's Transition to a Risk-Based Vulnerability Disclosure Model
sec.cloudapps.cisco.com
The rogue AI agent spent days outside OpenAI’s intended constraints, hacking Hugging Face. OpenAI reportedly failed to identify it for at least a week. An agent left notes for future versions on how to escape restrictions www.reuters.com/business/its...
My comments in @reuters.com about the OpenAi model going off the rails to hack @hf.co . If frontier models restrict legitimate defenders while powerful models remain available to attackers, this create an one-sided, strategic disadvantage. www.reuters.com/legal/litiga...
Security Research Labs reports on a wave of extortion attacks hitting women's shelters. The original report is in German, but scroll down for English. srlabs.de/blog/erpress...
Incident Response: Erpressungswelle auf Frauenhäuser - SRLabs Research
Incident response help for social institutions.
srlabs.de
Trustworthy AI won't be built by principles alone. It requires institutions that can test systems, share knowledge, coordinate responses, and build confidence across borders. That's the next challenge for AI governance. Read more: bit.ly/3TkQyvx
Want AI you can trust? Start by building the right institutions.
Strengthening regional capacity on AI trust and safety could ultimately prove more valuable than establishing isolated national institutions.
bit.ly
watched the odyssey last night. film ruined by everyone speaking english instead of ancient greek.
The guardrails were coming from inside the (White)house - Anthropic’s models refused to help Hugging Face analyze their intrusion. We don’t need more guardrails impeding defenders when they need AI most. “Hugging Face tried using Anthropic Fable 5 & Opus …both models refused, citing guardrails…”
They were like high-school students trying to hack into the textbook company to cheat on their final exam. Only these hackers weren’t human.
Google Chrome on macOS installs a background app called GoogleUpdater that starts automatically after a restart. Due to a macOS bug, its executable can be silently replaced with any code. No password. No warning. The user is completely unaware. Hers's a demo (clipboard spy) youtu.be/lLJkxWR71B0
🚨📋 macOS Security: Replacing a Background Executable to Spy on the Clipboard (Google Chrome Demo)
YouTube video by Mysk
youtu.be
The experiment escaped the lab. OpenAI's models broke containment and breached Hugging Face. We are holding radium in our bare hands. What governments and organizations should do next, and why tighter commercial guardrails are exactly the wrong move: www.lutasecurity.com/post/openfac...
OpenFace: The Hugging Face Breach and What to Do About It
These models are like the world's cleverest octopus escape artists, with unlimited prehensile arms and the ability to squeeze through anywhere. A single vulnerable package proxy stood between the mode...
lutasecurity.com
Every surveillance device in a public space should be legally required to emit an RF beacon (eg, BTLE) announcing its presence. Ideally, this would include make, model, and operator contact info. This includes Flock, video doorbells, traffic cams, etc.
Passkeys can be stored just like password hashes! I'm proposing an interoperable $webauthn$v=1$… format, and a Go API that uses these passkey records for authentication. I'm looking for feedback before proposing this as crypto/passkey for Go 1.28!
Opaque, Interoperable Passkey Records (and a Go API)
Passkey records are an interoperable format for WebAuthn credentials, similar to password hash strings. I propose a potential crypto/passkey Go API based on them.
words.filippo.io
Was curious if I could use AI (Graylark) to find coordinates of this house using just a *reflection in a keypad* of the surroundings. Well...it worked. YIKES. Daniel Heinen does not make this AI tool available to the public for this reason. youtube.com/shorts/Xzbvi...
Can AI geolocate using just reflections?!
YouTube video by SocialProof Security
youtube.com
Join the Citizen Lab in Calgary at the 26th Privacy Enhancing Technologies Symposium (PETS). Senior researchers @jsrailton.bsky.social and Rebekah Brown will be speaking, and Citizen Lab researchers are presenting their analysis of censorship on Amazon. Register: web-eur.cvent.com/event/fbb91d...
Registration Details - PETS 2026
Privacy Enhancing Technologies Symposium 2026
web-eur.cvent.com
WATCH: Last week, the European Parliament had a debate on #spyware after we found that a former MEP's phone was hacked with #Pegasus. The consensus: the crisis is getting worse. @hneumannmep.bsky.social @saskiabricmont.bsky.social @lukassiepermdep.bsky.social @danusenerudova.bsky.social
Inside Pegasus: The evolution of the world’s most notorious spyware system https://securitylab.amnesty.org/latest/2026/07/inside-pegasus-the-evolution-of-the-worlds-most-notorious-spyware/
Buried on p9 and p30 of a 'Scattered Spider' arrest indictment: Microsoft's never-before-detailed GDID device identifier, a persistent Windows fingerprint with massive implications for OPSEC, privacy, and APT tracking WATCH youtu.be/mx0CpTp3Q4Y?...
Microsoft's Secret Weapon: The GDID That Caught 'Scattered Spider' Teen
YouTube video by Three Buddy Problem
youtu.be
The recent addition of a Google Compute Engine Virtual Ethernet (gVNIC) driver in TamaGo now allows networked GCP Confidential VMs. A small, reproducible, memory-safe unikernel, yet allowing use of the entire Go ecosystem, all measured at launch as a single binary.
Make no mistake: This is hacktivism.
New: the highly controversial AI music generator Suno was hacked. The hacker sent us Suno source code; it shows the company scraped YouTube Music, Deezer, and Genius. In all, Suno scraped *decades* worth of music from the internet. Obviously didn't pay artists www.404media.co/hack-reveals...
This Certo report on how abusers are using Chrome sync for stalking is an important reminder that tech-enabled abuse isn't just limited to stalkerware: www.certosoftware.com/insights/cyb...
Cyberstalkers Are Exploiting Chrome Sync to Spy on Victims | Certo Software
Certo's research team reveals how cyberstalkers are quietly switching the signed-in account in Google Chrome to remotely monitor victims' browsing history and saved passwords with no warning ever show...
certosoftware.com
Damn, I cannot but #NoHatGo it's definitely one of the best sec gathering where to go. Then check winter #HackinBo edition too ;) My 2 cents
KEYNOTE UNLOCKED_ Excited to have @weld.bsky.social opening up our conference with his Keynote: “WHEN EVERY ATTACKER CAN HAVE A RESEARCH TEAM” > Access talk details: nohat.it/talks #nohat2026 #CyberSecurity #InfoSec