Welcome to Indigodefense!

The best hacker and cyber security news. Contact us on LinkedIn for cyber security services.

Latest posts

Oct 10, 2026

FBI Arrests Executive at Ransomware Negotiation Firm

Headline image

Agents with the Federal Bureau of Investigation (FBI) on Thursday arrested an executive at a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters hacking group that recently relieved the FBI of sensitive data on thousands of agents, multiple sources tell KrebsOnSecurity. The New York Times reported today that the FBI has arrested a Canadian man in Pennsylvania on suspicion of assisting ShinyHunters. The Times story did not identify the man, nor did a statement on Twitter/X about the arrest from FBI Director Kash Patel.

Oct 8, 2026

Hackers obtain counterfeit TLS certificates for Google and other large services

Headline image

The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS records for selected domains within those namespaces. By controlling those DNS records, the attackers were able to pass automated domain control validation checks and obtain unauthorized certificates for “several Google domains” and “several leading global brands and widely used online services.” Google said it updated Chrome to block all certificates it identified as unauthorized, and worked with the issuing certification authorities to ensure the unauthorized certificates for Google properties were revoked.

Oct 6, 2026

Florida woman used Claude as a diary, then Anthropic reported an entry to police

Headline image

What just happened? Another incident has taken place that illustrates the need to be careful what you tell AI. A Florida woman is facing felony charges after she used Claude as a diary and allegedly wrote that she planned to “shoot up” the Sheriff’s office. After a human reviewer examined the statements, they were reported to police.

Source: techspot.com

Oct 5, 2026

Our approach to EU text provenance rules

Headline image

Content provenance helps people understand where content came from, how it was created or edited, and whether it contains signals associated with our models. We’ve already made tools publicly available to identify images and audio generated by our models. Today, we’re sharing our approach to text watermarking in response to the EU AI Act, and how it fits into our broader work.

Source: openai.com

Oct 2, 2026

German Police Are Using Linked Devices to Read Messages from Messaging Apps Without Cracking the Encryption

Headline image

A document by Netzpolitik reveals that German police are sneakily abusing the linked devices feature in messengers to access the messages of suspects using encrypted messengers like Signal without needing to crack the encryption.

Source: privacyguides.org

Sep 29, 2026

Self-replicating prompt injections exist · OpenAI Alignment

Headline image

Research on aligning AI with human values and intent, and reports documenting model failures. We show the existence of a new variety of prompt injection, which can self-propagate akin to a computer worm. No impact was observed outside of the simulated tool calls in training and evaluation; we are sharing this due to the novel nature of the prompt injection, not because of any incident.

Source: alignment.openai.com

Sep 27, 2026

Flock Cameras Are Moving From Roads to Watching as Drones From the Sky

Headline image

Some cities across the country are utilizing drones to aid law enforcement, while others are pumping the brakes due to privacy concerns. A company that blanketed American roads with license-plate-reading cameras is now sending drones into the sky. Cities across America are grappling with their own debates about aid to law enforcement, coupled with concerns about privacy and surveillance.

Source: military.com

Sep 27, 2026

How Much Watermark Can You Hide in AI Text?

Headline image

A deliberately simple watermark model shows how much room a text watermark has: the entropy available at each token, how a small bias becomes detectable, and why length matters.

Source: blog.gaborkoos.com

Sep 27, 2026

A New Attack Forges RSA Signatures Without Factoring, and Even 2048-Bit Keys Look Unsafe

Headline image

Researchers forged a 1024-bit RSA signature with about 1,380 CPU core-years instead of factoring the key. The attack hits blind-signature RSA like Privacy Pass, not padded RSA used by most of the web.

Source: techpresso.co

Sep 26, 2026

How I Could’ve Accessed 17 Trillion Microsoft Records

Headline image

How one unchecked login token put 17 trillion rows in a Microsoft internal analytics service within reach. An estimated 17.3 trillion stored rows across a wide range of Microsoft datasets were reachable through a single internal analytics service, all because it never checked the signature on a login token. That flaw let me claim an administrator’s identity and submit unauthorized SQL queries without any real credentials. I used only table descriptions, metadata, and bounded sample rows to understand the potential scope.