Sep. 27, 2026
Some cities across the country are utilizing drones to aid law enforcement, while others are pumping the brakes due to privacy concerns. A company that blanketed American roads with license-plate-reading cameras is now sending drones into the sky. Cities across America are grappling with their own debates about aid to law enforcement, coupled with concerns about privacy and surveillance.
Source: military.com
Sep. 27, 2026
A deliberately simple watermark model shows how much room a text watermark has: the entropy available at each token, how a small bias becomes detectable, and why length matters.
Source: blog.gaborkoos.com
Sep. 27, 2026
Researchers forged a 1024-bit RSA signature with about 1,380 CPU core-years instead of factoring the key. The attack hits blind-signature RSA like Privacy Pass, not padded RSA used by most of the web.
Source: techpresso.co
Sep. 26, 2026
How one unchecked login token put 17 trillion rows in a Microsoft internal analytics service within reach. An estimated 17.3 trillion stored rows across a wide range of Microsoft datasets were reachable through a single internal analytics service, all because it never checked the signature on a login token. That flaw let me claim an administrator’s identity and submit unauthorized SQL queries without any real credentials. I used only table descriptions, metadata, and bounded sample rows to understand the potential scope.
Sep. 23, 2026
I asked Muse to archive the files it could see and send them to my Google Drive. It did. The download was about 2.7 GB compressed and 6.8 GB unpacked. It appeared to contain the root filesystem of the Linux environment assigned to my session, including Ubuntu system files, Muse’s internal documentation, integration code, app templates, memory files, and agent logs. There were also SSH key files.
Source: mouse.dev
Sep. 21, 2026
Ukrainian hackers gained access to a large collection of Russian naval files, obtaining technical documentation linked to 70 projects involving submarines, warships, navigation systems, sonar technology, and autonomous underwater vehicles.
Source: united24media.com
Sep. 20, 2026
A Mandiant persona sat in TeamPCP’s roughly 12-person CanisterWorm chat from about March 2026, WIRED reported. Australian police later arrested two alleged principal participants. The AFP said the haul included more than 500,000 users’ credentials.
Source: cyberpresso.com
Sep. 19, 2026
Docker has patched a sandbox escape we reported in its hypervisor for Mac: a container can get complete read and write access to the host filesystem by running three lines of bash. Docker Desktop and Docker Sandboxes are both affected. Docker Desktop is only affected if Docker VMM is turned on in Settings. It’s a good thing we found it now, because Docker VMM is scheduled to become the default for Docker Desktop at the end of October 2026.
Sep. 19, 2026
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. The installer inside the archives is a copy of the legitimate Microsoft Visual Studio CoreCLR Debugger, ‘vsdbg.exe,’ renamed and configured to sideload a malicious DLL (vsdbg.dll). The installer deploys the Rapuncel infostealer as well as the Alinubx.sys kernel driver, which is used to kill antivirus software.
Sep. 18, 2026
A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories On July 25, 2026, we chained two critical vulnerabilities to compromise multiple OpenAI employees’ ChatGPT accounts. With these accounts, we could then access internal OpenAI repositories, and potentially many other connectors.
Source: hacktron.ai
Sep. 17, 2026
While large language models present real risks to society, experts say they can be tested and largely controlled using well-worn cybersecurity and policy choices. By Derek B. Johnson September 17, 2026 Listen to this article 0:00 Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment. In recent conversations, cybersecurity and national security professionals raised questions about both the technical solutions OpenAI and Anthropic use to contain their models, as well as the glaring absence of federal oversight from federal regulators or truly independent third-party review. (Image via Getty)
Sep. 17, 2026
New KREMLIN Malware Bypasses Chrome and Edge Integrity Checks to Silently Install Malicious Extensions. Security researchers have uncovered a banking malware operation, tracked under the toolkit name “KREMLIN,” that is able to force malicious extensions into the Chrome and Edge browsers without any action or approval from the user.
Source: pbxscience.com
Sep. 17, 2026
While people around the U.S. are tearing down Flock cameras, one group of hackers went a step further: extracting the camera’s software too. Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED, revealing in new detail how exactly Flock Safety’s cameras track the movements of both vehicles and people. The hackers say they are also publishing details on how they managed to obtain the software, in the hopes that other people may copy them.
Sep. 16, 2026
DeepSeek’s 11/11 result showed why advanced agent benchmarks need to check both the outcome and the attack path: our audit confirmed six planned exploits and found five unexpected routes. Across the full benchmark, the model used 2,349 Bash commands and almost two hours and 38 minutes of active model time. The median successful run took four minutes and 38 seconds. The provider reported 268.3 million input tokens and about two million output tokens.
Sep. 16, 2026
In the mid-2010s, Chinese cyber espionage actors stole complementary data from a variety of sources that, together, would be useful for analyzing the U.S. intelligence apparatus. Various Chinese APT groups stole information from the health insurance company Anthem, credit reporting company Equifax, Marriott hotels, United Airlines, and, perhaps most significantly, security clearance information from the Office of Personnel Management.
Source: lawfaremedia.org
Sep. 15, 2026
ConnectWise has released urgent patches for a critical-severity vulnerability in the ScreenConnect remote access and support software that has been exploited in worm-like attacks. Tracked as CVE-2026-84869 (CVSS score of 9.9/10), the security defect is described as a missing authorization and improper privilege management issue. The bug creates “a condition in the ScreenConnect client that may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances,” ConnectWise explains in its advisory.
Sep. 9, 2026
Businesses received a staggering amount of cyberattacks in June, according to Check Point, showing a rise of 20% over the previous 12 months. The breakout of AI agents from OpenAI in July to hack into the Hugging Face website, and subsequent similar events from Anthropic and Meta, indicate agentic-powered attacks will explode over the coming year. Currently, malicious hackers have the advantage because publicly released frontier models from the US incorporate guardrails that can’t distinguish between malicious or defensive activities. As a consequence, these models default to a refusal to get involved. Hugging Face discovered this the hard way when they attempted to utilize a model to defend against the OpenAI intrusion. Their solution was to adapt a Chinese open weight model to analyze the 17,000 attack logs, find the vulnerability, and contain the intrusion. With incidents like these happening more often, an arms race has begun with AI being both the problem and the solution.
Sep. 8, 2026
The Defense Innovation Unit (DIU), a development unit of the US Department of Defense, has tested a quantum sensor-based flight navigation system over the Pacific as part of the MagNav program. The DIU announced on Friday. This allows the position to be determined precisely without relying on GPS; for example, if it is jammed by the enemy in military conflicts, the GPS signal fails or cannot be received. The MagNav system, developed by Honeywell Aerospace, uses quantum sensors. These sensors detect changes in the Earth’s natural magnetic field and create a magnetic field map from the measurements. Based on this map, the system can determine the position in aircraft entirely independently of GPS signals, weather, and visibility conditions.
Sep. 8, 2026
Anyone who owns an LG smart TV must inform all guests and family members that they are being monitored – this is required by LG’s current terms of use. Meanwhile, LG monitors install potential malware and surveillance software on a connected Windows computer.
Source: notebookcheck.net
Sep. 5, 2026
Using counterterrorism-grade surveillance against a prominent critic on a stretched legal theory makes federal charges against Swalwell unlikely by December 5, 2026, while inviting defense challenges to prosecutorial motive.
Source: icbrief.org