Welcome to Indigodefense!

The best hacker and cyber security news. Contact us on LinkedIn for cyber security services.

Latest posts

Oct 2, 2026

German Police Are Using Linked Devices to Read Messages from Messaging Apps Without Cracking the Encryption

Headline image

A document by Netzpolitik reveals that German police are sneakily abusing the linked devices feature in messengers to access the messages of suspects using encrypted messengers like Signal without needing to crack the encryption.

Source: privacyguides.org

Sep 29, 2026

Self-replicating prompt injections exist · OpenAI Alignment

Headline image

Research on aligning AI with human values and intent, and reports documenting model failures. We show the existence of a new variety of prompt injection, which can self-propagate akin to a computer worm. No impact was observed outside of the simulated tool calls in training and evaluation; we are sharing this due to the novel nature of the prompt injection, not because of any incident.

Source: alignment.openai.com

Sep 27, 2026

Flock Cameras Are Moving From Roads to Watching as Drones From the Sky

Headline image

Some cities across the country are utilizing drones to aid law enforcement, while others are pumping the brakes due to privacy concerns. A company that blanketed American roads with license-plate-reading cameras is now sending drones into the sky. Cities across America are grappling with their own debates about aid to law enforcement, coupled with concerns about privacy and surveillance.

Source: military.com

Sep 27, 2026

How Much Watermark Can You Hide in AI Text?

Headline image

A deliberately simple watermark model shows how much room a text watermark has: the entropy available at each token, how a small bias becomes detectable, and why length matters.

Source: blog.gaborkoos.com

Sep 27, 2026

A New Attack Forges RSA Signatures Without Factoring, and Even 2048-Bit Keys Look Unsafe

Headline image

Researchers forged a 1024-bit RSA signature with about 1,380 CPU core-years instead of factoring the key. The attack hits blind-signature RSA like Privacy Pass, not padded RSA used by most of the web.

Source: techpresso.co

Sep 26, 2026

How I Could’ve Accessed 17 Trillion Microsoft Records

Headline image

How one unchecked login token put 17 trillion rows in a Microsoft internal analytics service within reach. An estimated 17.3 trillion stored rows across a wide range of Microsoft datasets were reachable through a single internal analytics service, all because it never checked the signature on a login token. That flaw let me claim an administrator’s identity and submit unauthorized SQL queries without any real credentials. I used only table descriptions, metadata, and bounded sample rows to understand the potential scope.

Sep 23, 2026

I asked Meta’s Muse for its filesystem and it sent me 6.8 GB

Headline image

I asked Muse to archive the files it could see and send them to my Google Drive. It did. The download was about 2.7 GB compressed and 6.8 GB unpacked. It appeared to contain the root filesystem of the Linux environment assigned to my session, including Ubuntu system files, Muse’s internal documentation, integration code, app templates, memory files, and agent logs. There were also SSH key files.

Source: mouse.dev

Sep 21, 2026

Ukrainian Hackers Raid Russia’s Naval Files, Walk Away With Secrets From 70 Projects

Headline image

Ukrainian hackers gained access to a large collection of Russian naval files, obtaining technical documentation linked to 70 projects involving submarines, warships, navigation systems, sonar technology, and autonomous underwater vehicles.

Source: united24media.com

Sep 20, 2026

Google Had an Undercover Analyst Inside TeamPCP as Hackers Breached a Thousand Companies

Headline image

A Mandiant persona sat in TeamPCP’s roughly 12-person CanisterWorm chat from about March 2026, WIRED reported. Australian police later arrested two alleged principal participants. The AFP said the haul included more than 500,000 users’ credentials.

Source: cyberpresso.com

Sep 19, 2026

Guest to host: escaping Docker's hypervisor

Headline image

Docker has patched a sandbox escape we reported in its hypervisor for Mac: a container can get complete read and write access to the host filesystem by running three lines of bash. Docker Desktop and Docker Sandboxes are both affected. Docker Desktop is only affected if Docker VMM is turned on in Settings. It’s a good thing we found it now, because Docker VMM is scheduled to become the default for Docker Desktop at the end of October 2026.