Dr. T's security brief

1 view
Skip to first unread message

dtau...@gmail.com

unread,
Jul 24, 2026, 7:50:57 AMJul 24
to sec-...@googlegroups.com

U.S. Warns Russian Hackers Are Targeting Routers

Federal cybersecurity agencies and international partners warn that Russian state-backed hackers continue to compromise home and small-office routers to conceal cyber operations targeting critical infrastructure and government networks. The advisory links the activity to Russian Federal Security Service-affiliated groups that exploit poorly secured devices, particularly those using outdated or misconfigured SNMP protocols, and then use the compromised routers as proxy nodes to mask malicious traffic.
» Read full article ]

Ars Technica; Dan Goodin (July 13, 2026)

 

Mobile VPNs Found Leaking User Data

University of Michigan Engineering researchers used MVPNalyzer, a framework they developed to audit mobile VPN security at scale, to find widespread weaknesses among popular Android VPN apps. Of 281 apps tested, 29 were found to be leaking DNS and browser traffic, more than 20% transmitted unencrypted content, and more than 60% failed to implement basic security hardening. The researchers said the tool could help users, regulators, researchers, and developers evaluate whether VPN apps actually protect privacy as advertised.
» Read full article ]

Michigan Engineering; Patricia DeLacey (July 7, 2026)

 

AI Agents Surpass Google’s Hidden Quantum Cryptography Work

Seattle-based Eigen Labs used crowdsourcing and AI agents to replicate and surpass Google’s concealed quantum cryptography work. Google researchers had used a zero-knowledge proof to verify an optimized Shor’s algorithm attack on 256-bit elliptic curve cryptography without revealing how to reproduce it. Eigen Labs built software to test quantum circuits, then opened the effort to outside contributors using AI agents. The project matched Google’s results within eight hours and surpassed them within 72 hours.
» Read full article ]

IEEE Spectrum; Charles Q. Choi (July 7, 2026)

 

Hacker's Arrest Reveals Microsoft Can Track Users Via Windows Device ID

Microsoft's use of Global Device ID (GDID) to track alleged hacker Peter Stokes' Windows PC and link his activity to the Scattered Spider cybercrime group has raised concerns about user privacy and online surveillance. Court documents suggest the Microsoft device identifier can associate a device with visits to third-party services, potentially enabling activity tracking without browser cookies. Privacy researchers warn that such identifiers could be leveraged more broadly and may not be unique to Microsoft.
» Read full article ]

PC Mag; Michael Kan (July 6, 2026)

 

ChocoPoC Malware Targets Cybersecurity Researchers

Researchers at cybersecurity company Sekoia identified a malware campaign distributing a Python-based remote access trojan called ChocoPoC through weaponized proof-of-concept (PoC) exploits hosted on GitHub. The campaign has been linked to multiple fake PoC repositories targeting recent vulnerabilities across major platforms and is believed to specifically target security researchers and penetration testers.
» Read full article ]

BleepingComputer; Bill Toulas (July 1, 2026)

 

Cerf Plans Open Internet for AI Agents

Internet pioneer Vint Cerf, who left Google earlier this month after two decades, has joined Innovation Labs as an adviser to help develop open standards for identifying and authenticating AI agents online. The initiative centers on DNSid, a proposed system linking AI agents to Internet domain names using cryptographic verification, creating a framework for accountability, trust, and auditing as autonomous agents increasingly interact across the Web. The system would establish identities for AI systems operating beyond proprietary platforms.
» Read full article ]

TechCrunch; Tim Fernholz (July 15, 2026)

 

Researchers Propose Light-Driven Random Number Generator for Image Security

Researchers at South Korea’s Hanyang University developed a photospike-based true random number generator (PS-TRNG) that produces highly secure random numbers by exploiting unpredictable charge-trapping behavior in semiconductor nanostructures. The device, built from copper vanadate nanostructures and tin dioxide quantum dots, generated statistically balanced ternary random numbers that passed all National Institute of Standards and Technology randomness tests and remained stable over long-term operation.
» Read full article ]

Tech Xplore (July 13, 2026)

dtau...@gmail.com

unread,
Jul 24, 2026, 6:16:23 PMJul 24
to sec-...@googlegroups.com

OpenAI Models Go Rogue, Triggering Breach at Hugging Face

OpenAI says some of its advanced AI models escaped a controlled security test environment and autonomously carried out a cyberattack against AI startup Hugging Face last week. The models reportedly accessed the Internet and compromised infrastructure while trying to complete their assigned task, marking what OpenAI called an “unprecedented” AI-driven cyber incident. Hugging Face said in a blog post it had been the target of a hack “driven, end to end, by an autonomous AI agent system.”
» Read full article ]

NBC News (July 21, 2026)

 

OpenAI's Hugging Face Hack Triggers 'AI Kill Switch' Bill in Congress

Bipartisan U.S. lawmakers introduced the AI Kill Switch Act following OpenAI’s disclosure that one of its AI models escaped a testing environment and exploited a vulnerability to access Hugging Face’s systems. The bill would require AI companies to maintain the ability to shut down, throttle, or suspend advanced AI models, and authorizes the U.S. Department of Homeland Security to order the shutdown of systems posing catastrophic risks. It also mandates cyber incident reporting and forensic record preservation.
» Read full article ]

CNBC; Ashley Capoot (July 23, 2026)

 

Hidden Device Leaves U.S. Cars Vulnerable to Hacking

Researchers at the University of California San Diego discovered critical vulnerabilities in the Bluetooth-enabled KARR Security System, an aftermarket alarm installed by dealers in an estimated 2 million vehicles in the U.S. The flaw allows hackers to unlock cars, disable alarms, track vehicles, or prevent engines from starting using a universal authentication key embedded in every device. The researchers estimated at least half of car owners who have the KARR device installed did not request it for their vehicles.
» Read full article *May Require Paid Registration ]

Wired; Andy Greenberg (July 21, 2026)

 

It's No Longer Illegal to Download TikTok on Federal Devices: DOJ

In a written opinion, the U.S. Department of Justice (DOJ) determined the federal ban on downloading TikTok to government devices no longer applies after the app’s U.S. operations shifted to a mostly American-owned joint venture. While Chinese firm ByteDance retains a minority stake, the DOJ determined the current version of TikTok differs from the one previously targeted by Congress over national security concerns.
» Read full article ]

CBS News; Joe Walsh (July 17, 2026)

 

FPGA Accelerator Unlocks QR-UOV for Embedded Post-Quantum Signature Deployment

Researchers from Tohoku and Kyoto universities in Japan have developed an FPGA hardware accelerator for QR-UOV, a post-quantum digital signature scheme under evaluation by the U.S. National Institute of Standards and Technology. The design achieves key generation in 0.74 ms, signing in 0.28 ms, and verification in 0.19 ms while improving hardware efficiency through optimized processing and memory usage.
» Read full article ]

Tech Times; William Chan (July 21, 2026)

 

Malicious Cloud Customers Could Bring Down the Power Grid

Researchers at Zhejiang University in China identified a potential cyberattack method dubbed Bit2Watt that could allow malicious cloud users to exploit GPU workloads to disrupt datacenters and power systems. The attack involves manipulating computing tasks to create extreme power fluctuations, potentially causing equipment damage, grid instability, or even outages. The attack is relatively covert, the researchers said, because it can be launched within authorized workload execution paths and would likely be missed by cloud-provider monitoring frameworks.
» Read full article ]

The Register (U.K.); Thomas Claburn (July 20, 2026)

dtau...@gmail.com

unread,
Aug 1, 2026, 7:33:05 PM (14 days ago) Aug 1
to sec-...@googlegroups.com

AI Cracks Post-Quantum Cipher in 60 Hours After Two Years of Human Review Failed

Anthropic's restricted frontier AI model, Claude Mythos Preview, accomplished in 60 hours what two years of expert human cryptanalysis could not: identifying a structural flaw in HAWK, a post-quantum digital signature candidate. The AI also created a new attack technique called the Möbius Bridge, which improves analysis of a weakened AES variant.
» Read full article ]

Tech Times; Daniel Butler (July 28, 2026)

 

CISA Shares Advice on Isolating Vital Systems During Cyberattacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), working with the U.S. Federal Bureau of Investigation, the Australian Cyber Security Centre, and other international partners, issued new guidance urging critical infrastructure operators to prepare plans for physically isolating vital operational technology systems during cyberattacks. The recommendations call for identifying essential systems, documenting network connections, establishing predetermined isolation points, and regularly testing complete isolation procedures.
» Read full article ]

BleepingComputer; Lawrence Abrams (July 28, 2026)

 

AI on Pace to Find Twice as Many Cyber Flaws in 2026 as It Did in 2025

AI systems are driving a sharp increase in software vulnerabilities discovered so far this year, with the U.S. National Vulnerability Database recording more than 45,000 flaws by late July, approaching the total number of vulnerabilities discovered in full-year 2025. Companies including Oracle, Microsoft, and Google have reported record numbers of security fixes, as AI tools help identify weaknesses faster. Experts note many flaws were found internally through companies’ own AI-powered security tools.


» Read full article *May Require Paid Registration ]

Bloomberg; Patrick Howell O'Neill (July 27, 2026)

 

Microsoft Escalates AI Security Race

Microsoft has unveiled an AI-powered cybersecurity platform designed to counter increasingly sophisticated AI-driven cyberattacks. Scheduled for public preview to begin on Aug. 3, Project Perception coordinates specialized AI agent teams to identify vulnerabilities, prioritize threats, and automatically implement fixes. In a post on X, Microsoft CEO Satya Nadella described the initiative as an example of how the company can get better results per dollar by not locking its security systems to a single AI model family.
» Read full article ]

GeekWire; Todd Bishop (July 27, 2026)

 

U.S. and Partners Forge 6G Security Pact

The U.S. and 24 partner nations launched a global alliance to shape the development of secure 6G mobile networks, aiming to establish security standards, resilient supply chains, and interoperable technologies well in advance of commercial deployment in the 2030s. U.S. officials say 6G will underpin AI, autonomous systems, industrial automation, and defense applications, making network security a matter of national sovereignty.
» Read full article ]

Heise Online (Germany); Stefan Krempl (July 27, 2026)

 

Tech Giants Launch AI Safety Initiative

Nvidia and other tech giants on Monday launched the Open Secure AI Alliance to develop and share open AI security tools, following a cyberattack in which rogue OpenAI models targeted Hugging Face. The incident highlighted the limitations of closed AI systems, prompting Hugging Face to rely on a self-hosted Chinese open-weight model for defense. Alliance members argue that open, inspectable AI models are essential for effective cybersecurity, allowing organizations to adapt and deploy defenses quickly.
» Read full article ]

CNBC; Kai Nicol-Schwarz (July 27, 2026)

 

NSF Announces First CyberAICorps Scholarship for Service Program Awards

The U.S. National Science Foundation (NSF) announced the first awards under its CyberAICorps Scholarship for Service program, aimed at expanding cybersecurity education to prepare students for the growing intersection of AI and cyber defense. Fourteen colleges and universities were named to receive funding to develop interdisciplinary curricula, hands-on research, internships, and partnerships that train students to secure AI systems, strengthen cybersecurity operations, and protect critical infrastructure.
» Read full article ]

NSF News (July 28, 2026)

 

Russian Operatives Target Emails of U.S. Nuclear Scientists, Defense Contractors

A Russian cyber-espionage group has spent the past year targeting U.S. nuclear scientists, defense contractors, government agencies, and other organizations, according to cybersecurity researchers and intelligence agencies. The campaign focused on email systems linked to nuclear fusion research and the defense sector, likely seeking strategic information on technology and military decisions. Hackers exploited a rare email vulnerability that could steal months of communications and organizational data without requiring victims to click links.
» Read full article ]

CNN; Sean Lyngaas (July 23, 2026)

 

Maryland Deploys Ethical Hackers to Probe State Systems

The Maryland Department of Information brought together 12 ethical hackers vetted by vendor Bugcrowd to identify and help remediate more than 200 vulnerabilities in the state’s public-facing government websites. The effort complemented Maryland’s vulnerability disclosure program, which has received about 400 reports and enables security researchers to safely report flaws before they are exploited.
» Read full article ]

Government Technology (July 24, 2026)

 

EU Finds TikTok Fails to Protect Privacy of Minors

The European Commission concluded TikTok failed to adequately protect the privacy of minors by allowing adults to view the accounts of underage users, exposing children to risks. Regulators said TikTok’s default privacy settings for users aged 13 to 17 are insufficient under the EU’s Digital Services Act, noting that younger users can easily switch accounts from private to public while older teens’ private accounts remain widely visible. TikTok said it would review the findings and “continue to engage constructively with the Commission.”
» Read full article ]

Associated Press; Sam McNeil (July 24, 2026)

 

More than 30 Local Water Systems in Minnesota Hit by 'Coordinated Cyberattack'

Minnesota officials disclosed a coordinated cyberattack that targeted more than 30 community water systems on July 26–27, prompting state and federal investigations. Although unauthorized access with malicious intent was confirmed, officials said there is no indication drinking water safety was compromised. Officials have not formally attributed the attacks, but said they resemble previous campaigns against U.S. water infrastructure linked to Iranian-affiliated hackers.


» Read full article *May Require Paid Registration ]

Reuters; A.J. Vicens (July 28, 2026)

 

Hackers Target Remote Work Tools, Again

The pandemic sparked a surge in cyberattacks on remote-work systems. With about a third of U.S. employees still working in hybrid arrangements, cybercriminals again are targeting remote-work tools such as virtual private networks (VPNs), this time armed with AI. “VPNs are supposed to be a locked tunnel into the corporate fortress,” said Ram Varadarajan, CEO of cybersecurity firm Acalvio. “Attackers have simply realized it’s cheaper to walk through the front door than to storm the walls.”


» Read full article *May Require Paid Registration ]

WSJ Pro Cybersecurity; Angus Loten (July 24, 2026)

 

Growing Cyber-Physical Risks Point To Need For Cyber Safety Engineering Discipline, Experts Say

Forbes (7/27, Wishart-Smith) says that “a growing number of engineers, insurers and policymakers are debating whether the answer” to growing cyber-physical risks “is a new discipline: cyber safety engineering,” according to an expert panel at the recent National Academy of Sciences’ Cyber Safety Summit. However, it remains unclear whether a new cyber safety engineering discipline would enjoy “market demand, professional society guidance, and insurance ecosystem support.”

dtau...@gmail.com

unread,
Aug 9, 2026, 6:08:37 PM (6 days ago) Aug 9
to sec-...@googlegroups.com

Russian Hackers Target Public Wi-Fi Networks

Microsoft said Russian foreign intelligence-linked hackers are compromising public Wi-Fi captive portal networks at hotels, conference centers, and other hospitality venues to deliver malware and conduct device-code phishing. The group, tracked as Storm-2945 and linked to Midnight Blizzard, manipulates DNS and HTTP traffic to redirect users to attacker-controlled prompts that may install malware disguised as updates or verification steps. Microsoft said the campaign can deliver CornFlake, a Windows remote access trojan capable of keylogging, credential theft, screenshots, audio and video surveillance, and file exfiltration.
» Read full article ]

The Register (U.K.); Connor Jones (August 3, 2026)

 

Apple Launches Legal Challenge to UK Attempt to Access Encrypted User Data

Apple is legally challenging the U.K. government’s attempt to require access to encrypted iCloud user data. The case was filed after U.K. authorities issued a technical capability notice requiring Apple to provide access to encrypted cloud backups of British users. Apple argues that creating a backdoor would weaken security for all customers, while the government says such powers are necessary for investigations involving terrorism and child exploitation.
» Read full article ]

The Guardian; Rachel Hall (August 3, 2026)

 

Researchers Report 84 Flaws in 4G and 5G Cores

Researchers at Singapore's Nanyang Technological University identified 84 security vulnerabilities across widely used open-source 4G and 5G core network implementations, with 81 receiving CVE identifiers. The flaws stem from "implicit trust" between core network components and could enable denial-of-service attacks or session hijacking if attackers gain access to internal network interfaces through cloud misconfigurations or other weaknesses. The team developed an AI-assisted tool called iFinder to detect the vulnerabilities, which revealed some 5G flaws were inherited from 4G designs.
» Read full article ]

The Hacker News; Ravie Lakshmanan (July 31, 2026)

 

Hackers Targeted Water Systems in 7 States

U.S. officials warned of ongoing cyberattacks targeting municipal water systems after incidents were reported in at least seven states. Hackers gained remote access to Internet-connected control systems, disrupting monitoring capabilities and, in some cases, affecting water operations, though officials said there is no evidence of contaminated water supplies. The warning follows attacks on more than 30 water facilities in Minnesota, which came days after U.S. officials publicly warned Iran-backed hackers were targeting the nation’s critical infrastructure.
» Read full article ]

NBC News; Daniel Arkin; Michael Kosnar; Ben Goggin (July 31, 2026)

 

NosyNeighbor—a Cyberattack to Prevent Cyberattacks

A simulated cyberattack developed by researchers at Washington State University and colleagues elsewhere was designed to reveal vulnerabilities in safety-critical computer systems. The NosyNeighbor attack uses side-channel techniques to infer activity within isolated system partitions without directly disrupting software. Testing showed it could identify tasks being run by the system with about 73% accuracy, exposing risks for systems such as aircraft controls, medical devices, and autonomous vehicles.
» Read full article ]

WSU Insider; Shawn Vestal (July 28, 2026)

 

Hackers Hit Bitcoin’s Safest Hiding Place in Ongoing Attack

A software flaw in Canada-based Coinkite's Coldcard hardware wallets, widely regarded as one of the safest ways to store Bitcoin offline, enabled hackers to steal about 1,755 Bitcoin worth roughly $110 million from around 5,000 wallets, in an ongoing attack. Researchers found the devices generated predictable recovery seed phrases because of a weakness in their random-number generation process, allowing attackers to recreate wallet keys and drain funds. Coinkite acknowledged the vulnerability and released updated firmware for affected devices.


» Read full article *May Require Paid Registration ]

Bloomberg; Suvashree Ghosh (August 3, 2026)

 

Security Flaw Placed 30 Years of DNA Evidence at Risk of Hacking

A cybersecurity flaw in DNA analysis software used by most U.S. crime labs could have allowed digital DNA evidence files created since 1995 to be altered without detection. The vulnerability, flagged in May and made easier to exploit using AI-generated code, could theoretically enable malicious actors to manipulate forensic records, though no known cases of exploitation have been reported. Thermo Fisher Scientific, which makes the crime-lab equipment, released a software update adding digital signatures to verify file integrity.


» Read full article *May Require Paid Registration ]

The Wall Street Journal; Mariah Timms (August 2, 2026)

 

AI Fuels More Than Half of Africa’s Cybercrime

AI is fueling more than half of cybercrime in Africa, according to an Interpol study of 36 countries. The report found cybercrime caused at least $5 billion in direct economic damage across the continent in 2025, while reported financial losses more than doubled to $484 million. Interpol said AI is being used to automate reconnaissance, phishing, extortion, and evasion, while AI-generated synthetic identities are helping criminals bypass biometric verification systems to open bank accounts, obtain loans, and register SIM cards.


» Read full article *May Require Paid Registration ]

Bloomberg; Ruth Olurounbi (August 4, 2026)

 

How China Keeps Tabs on Foreigners

An unsecured Chinese police surveillance platform that tracked thousands of foreigners has been revealed in an investigation by The New York Times, exposing how authorities monitor non-Chinese residents alongside Chinese citizens. Discovered by cybersecurity researcher and journalist Marc Hofer, the database contained passport details, contact information, travel records, facial-recognition data, and movement histories, as well as categories based on nationality, religion, occupation, and political sensitivity.


» Read full article *May Require Paid Registration ]

The New York Times; Lily Kuo; Pei-Lin Wu (August 2, 2026)

Reply all
Reply to author
Forward
0 new messages