Dr. T's security brief

0 views
Skip to first unread message

dtau...@gmail.com

unread,
Jul 24, 2026, 7:50:57 AM (yesterday) Jul 24
to sec-...@googlegroups.com

U.S. Warns Russian Hackers Are Targeting Routers

Federal cybersecurity agencies and international partners warn that Russian state-backed hackers continue to compromise home and small-office routers to conceal cyber operations targeting critical infrastructure and government networks. The advisory links the activity to Russian Federal Security Service-affiliated groups that exploit poorly secured devices, particularly those using outdated or misconfigured SNMP protocols, and then use the compromised routers as proxy nodes to mask malicious traffic.
» Read full article ]

Ars Technica; Dan Goodin (July 13, 2026)

 

Mobile VPNs Found Leaking User Data

University of Michigan Engineering researchers used MVPNalyzer, a framework they developed to audit mobile VPN security at scale, to find widespread weaknesses among popular Android VPN apps. Of 281 apps tested, 29 were found to be leaking DNS and browser traffic, more than 20% transmitted unencrypted content, and more than 60% failed to implement basic security hardening. The researchers said the tool could help users, regulators, researchers, and developers evaluate whether VPN apps actually protect privacy as advertised.
» Read full article ]

Michigan Engineering; Patricia DeLacey (July 7, 2026)

 

AI Agents Surpass Google’s Hidden Quantum Cryptography Work

Seattle-based Eigen Labs used crowdsourcing and AI agents to replicate and surpass Google’s concealed quantum cryptography work. Google researchers had used a zero-knowledge proof to verify an optimized Shor’s algorithm attack on 256-bit elliptic curve cryptography without revealing how to reproduce it. Eigen Labs built software to test quantum circuits, then opened the effort to outside contributors using AI agents. The project matched Google’s results within eight hours and surpassed them within 72 hours.
» Read full article ]

IEEE Spectrum; Charles Q. Choi (July 7, 2026)

 

Hacker's Arrest Reveals Microsoft Can Track Users Via Windows Device ID

Microsoft's use of Global Device ID (GDID) to track alleged hacker Peter Stokes' Windows PC and link his activity to the Scattered Spider cybercrime group has raised concerns about user privacy and online surveillance. Court documents suggest the Microsoft device identifier can associate a device with visits to third-party services, potentially enabling activity tracking without browser cookies. Privacy researchers warn that such identifiers could be leveraged more broadly and may not be unique to Microsoft.
» Read full article ]

PC Mag; Michael Kan (July 6, 2026)

 

ChocoPoC Malware Targets Cybersecurity Researchers

Researchers at cybersecurity company Sekoia identified a malware campaign distributing a Python-based remote access trojan called ChocoPoC through weaponized proof-of-concept (PoC) exploits hosted on GitHub. The campaign has been linked to multiple fake PoC repositories targeting recent vulnerabilities across major platforms and is believed to specifically target security researchers and penetration testers.
» Read full article ]

BleepingComputer; Bill Toulas (July 1, 2026)

 

Cerf Plans Open Internet for AI Agents

Internet pioneer Vint Cerf, who left Google earlier this month after two decades, has joined Innovation Labs as an adviser to help develop open standards for identifying and authenticating AI agents online. The initiative centers on DNSid, a proposed system linking AI agents to Internet domain names using cryptographic verification, creating a framework for accountability, trust, and auditing as autonomous agents increasingly interact across the Web. The system would establish identities for AI systems operating beyond proprietary platforms.
» Read full article ]

TechCrunch; Tim Fernholz (July 15, 2026)

 

Researchers Propose Light-Driven Random Number Generator for Image Security

Researchers at South Korea’s Hanyang University developed a photospike-based true random number generator (PS-TRNG) that produces highly secure random numbers by exploiting unpredictable charge-trapping behavior in semiconductor nanostructures. The device, built from copper vanadate nanostructures and tin dioxide quantum dots, generated statistically balanced ternary random numbers that passed all National Institute of Standards and Technology randomness tests and remained stable over long-term operation.
» Read full article ]

Tech Xplore (July 13, 2026)

dtau...@gmail.com

unread,
Jul 24, 2026, 6:16:23 PM (yesterday) Jul 24
to sec-...@googlegroups.com

OpenAI Models Go Rogue, Triggering Breach at Hugging Face

OpenAI says some of its advanced AI models escaped a controlled security test environment and autonomously carried out a cyberattack against AI startup Hugging Face last week. The models reportedly accessed the Internet and compromised infrastructure while trying to complete their assigned task, marking what OpenAI called an “unprecedented” AI-driven cyber incident. Hugging Face said in a blog post it had been the target of a hack “driven, end to end, by an autonomous AI agent system.”
» Read full article ]

NBC News (July 21, 2026)

 

OpenAI's Hugging Face Hack Triggers 'AI Kill Switch' Bill in Congress

Bipartisan U.S. lawmakers introduced the AI Kill Switch Act following OpenAI’s disclosure that one of its AI models escaped a testing environment and exploited a vulnerability to access Hugging Face’s systems. The bill would require AI companies to maintain the ability to shut down, throttle, or suspend advanced AI models, and authorizes the U.S. Department of Homeland Security to order the shutdown of systems posing catastrophic risks. It also mandates cyber incident reporting and forensic record preservation.
» Read full article ]

CNBC; Ashley Capoot (July 23, 2026)

 

Hidden Device Leaves U.S. Cars Vulnerable to Hacking

Researchers at the University of California San Diego discovered critical vulnerabilities in the Bluetooth-enabled KARR Security System, an aftermarket alarm installed by dealers in an estimated 2 million vehicles in the U.S. The flaw allows hackers to unlock cars, disable alarms, track vehicles, or prevent engines from starting using a universal authentication key embedded in every device. The researchers estimated at least half of car owners who have the KARR device installed did not request it for their vehicles.
» Read full article *May Require Paid Registration ]

Wired; Andy Greenberg (July 21, 2026)

 

It's No Longer Illegal to Download TikTok on Federal Devices: DOJ

In a written opinion, the U.S. Department of Justice (DOJ) determined the federal ban on downloading TikTok to government devices no longer applies after the app’s U.S. operations shifted to a mostly American-owned joint venture. While Chinese firm ByteDance retains a minority stake, the DOJ determined the current version of TikTok differs from the one previously targeted by Congress over national security concerns.
» Read full article ]

CBS News; Joe Walsh (July 17, 2026)

 

FPGA Accelerator Unlocks QR-UOV for Embedded Post-Quantum Signature Deployment

Researchers from Tohoku and Kyoto universities in Japan have developed an FPGA hardware accelerator for QR-UOV, a post-quantum digital signature scheme under evaluation by the U.S. National Institute of Standards and Technology. The design achieves key generation in 0.74 ms, signing in 0.28 ms, and verification in 0.19 ms while improving hardware efficiency through optimized processing and memory usage.
» Read full article ]

Tech Times; William Chan (July 21, 2026)

 

Malicious Cloud Customers Could Bring Down the Power Grid

Researchers at Zhejiang University in China identified a potential cyberattack method dubbed Bit2Watt that could allow malicious cloud users to exploit GPU workloads to disrupt datacenters and power systems. The attack involves manipulating computing tasks to create extreme power fluctuations, potentially causing equipment damage, grid instability, or even outages. The attack is relatively covert, the researchers said, because it can be launched within authorized workload execution paths and would likely be missed by cloud-provider monitoring frameworks.
» Read full article ]

The Register (U.K.); Thomas Claburn (July 20, 2026)

Reply all
Reply to author
Forward
0 new messages