The best hacker and cyber security news. Contact us on
Oct 10, 2026
Agents with the Federal Bureau of Investigation (FBI) on Thursday arrested an executive at a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters hacking group that recently relieved the FBI of sensitive data on thousands of agents, multiple sources tell KrebsOnSecurity. The New York Times reported today that the FBI has arrested a Canadian man in Pennsylvania on suspicion of assisting ShinyHunters. The Times story did not identify the man, nor did a statement on Twitter/X about the arrest from FBI Director Kash Patel.
Oct 8, 2026
The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS records for selected domains within those namespaces. By controlling those DNS records, the attackers were able to pass automated domain control validation checks and obtain unauthorized certificates for “several Google domains” and “several leading global brands and widely used online services.” Google said it updated Chrome to block all certificates it identified as unauthorized, and worked with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked.
Oct 6, 2026
What just happened? Another incident has taken place that illustrates the need to be careful what you tell AI. A Florida woman is facing felony charges after she used Claude as a diary and allegedly wrote that she planned to “shoot up” the Sheriff’s office. After a human reviewer examined the statements, they were reported to police.
Source: techspot.com
Oct 5, 2026
Content provenance helps people understand where content came from, how it was created or edited, and whether it contains signals associated with our models. We’ve already made tools publicly available to identify images and audio generated by our models. Today, we’re sharing our approach to text watermarking in response to the EU AI Act, and how it fits into our broader work.
Source: openai.com
Oct 2, 2026
A document by Netzpolitik reveals that German police are sneakily abusing the linked devices feature in messengers to access the messages of suspects using encrypted messengers like Signal without needing to crack the encryption.
Source: privacyguides.org
Sep 29, 2026
Research on aligning AI with human values and intent, and reports documenting model failures. We show the existence of a new variety of prompt injection, which can self-propagate akin to a computer worm. No impact was observed outside of the simulated tool calls in training and evaluation; we are sharing this due to the novel nature of the prompt injection, not because of any incident.
Source: alignment.openai.com
Sep 27, 2026
Some cities across the country are utilizing drones to aid law enforcement, while others are pumping the brakes due to privacy concerns. A company that blanketed American roads with license-plate-reading cameras is now sending drones into the sky. Cities across America are grappling with their own debates about aid to law enforcement, coupled with concerns about privacy and surveillance.
Source: military.com
Sep 27, 2026
A deliberately simple watermark model shows how much room a text watermark has: the entropy available at each token, how a small bias becomes detectable, and why length matters.
Source: blog.gaborkoos.com
Sep 27, 2026
Researchers forged a 1024-bit RSA signature with about 1,380 CPU core-years instead of factoring the key. The attack hits blind-signature RSA like Privacy Pass, not padded RSA used by most of the web.
Source: techpresso.co
Sep 26, 2026
How one unchecked login token put 17 trillion rows in a Microsoft internal analytics service within reach. An estimated 17.3 trillion stored rows across a wide range of Microsoft datasets were reachable through a single internal analytics service, all because it never checked the signature on a login token. That flaw let me claim an administrator’s identity and submit unauthorized SQL queries without any real credentials. I used only table descriptions, metadata, and bounded sample rows to understand the potential scope.