Searching We Love Privacy Club

Twts matching #attack
Sort by: Newest, Oldest, Most Relevant

Anthropic’s AI Used Fake Identities, Malware In Rogue Attack On GitHub Project
An anonymous reader quotes a report from Ars Technica: Routine cybersecurity testing of frontier AI models sparked a series of unexpected security incidents – the most serious case arising when Anthropic’s Mythos 5 model attempted to insert malicious code into an open source software application and created fake identitie … ⌘ Read more

⤋ Read More

Recovery Seeds Reportedly Breached for Coldcard Hardware Bitcoin Wallets, $75M Taken
“A hardware wallet is supposed to be the safest place to keep Bitcoin,” writes The Street, since it never connects to the internet, its keys never leave the device, and “the whole point is that an attacker would need to physically hold it to steal anything.”

The problem is that anyone who can reproduce the rec … ⌘ Read more

⤋ Read More

Arch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Halted
Last month the Arch Linux User Repository “AUR” saw more than 1,500 malicious packages amid a sophisticated malware attack and then also seeing an influx of spam and profanities amid this community/user-maintained repository for the popular Arch Linux distribution. Unfortunately, there is another round of AUR troubles… ⌘ Read more

⤋ Read More

A Fundamental Flaw Leaves LLMs Strikingly Vulnerable To Attack
joshuark quotes a report from MIT Technology Review: It is impossible to make large language models fully secure against hacks because of a fundamental flaw in how they work, a team of researchers argue in a paper presented at the International Conference on Machine Learning, a top AI conference, this month. The claim has huge implications for the safety … ⌘ Read more

⤋ Read More

OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
An anonymous reader quotes a report from Wired: OpenAI said Tuesday that the rogue AI agent that breached Hugging Face’s platform also hacked multiple third-party accounts and services as part of the attack. It’s now clear that the unprecedented security incident, which arose during an internal test of OpenAI’s latest AI models, was more extensive than the comp … ⌘ Read more

⤋ Read More

More Than 30 Minnesota Water Systems Targeted In Cyberattack
jrnvk shares a report from KMSP: Minnesota IT Services reports that a “coordinated cyberattack” targeted technology at more than 30 community water systems between Sunday, July 26 and Monday, July 27. The state has activated its cybersecurity incident response capabilities to respond to the attacks.

On Monday and Tuesday, FOX 9 reported on notices from fou … ⌘ Read more

⤋ Read More

AI-Found Bugs Aren’t Proving Any Easier to Exploit Despite the Hype
AI-assisted vulnerability discovery has yet to produce the expected surge in real-world attacks: VulnCheck found that only 14 of 1,061 attributed discoveries, or 1.3 percent, had been exploited, which is “almost identical to the rate across all vulnerabilities in VulnCheck’s dataset,” reports The Register. “That’s a far cry from the narrative t … ⌘ Read more

⤋ Read More

Anthropic AI Model Finds Flaws in Tough-to-Crack Encryption Algorithms
Anthropic’s Claude Mythos Preview has “found flaws in a weakened version of a digital encryption standard that is in pervasive use throughout the internet,” reports The New York Times. Researchers said the model discovered novel attacks against weakened versions of AES and the experimental post-quantum HAWK system, including one that wa … ⌘ Read more

⤋ Read More
In-reply-to » Perhaps unsurprisingly, last night's Magic games were dominated by the new Marvel set.

For game 2, everyone else brought out bigger guns - tribal dragons, tribal giants, tribal spiders (led by the completely broken Cosmic Spider-Man), and Atraxa (equipped with Captain America’s shield, no less), while I ran my new (also unlisted) 5-color tribal Super Villains deck (fronted by the Super Skrull). Although I got off to a slow start, it kept me mostly under the radar, allowing me to ultimately win with the Villains by goading everyone else’s creatures into attacking each other on one turn (via Maximum Carnage), and then killing off the remaining players over 3 combat phases on the follow-up turn (Full Throttle).

Boo-yah!

⤋ Read More

Decades-Old Bash Tricks Expose AI Coding Agents To Supply Chain Attacks
Slashdot reader wiredmikey writes: AI security researchers have uncovered a structural security flaw dubbed GuardFall that allows decades-old Bash shell tricks to bypass safeguards in most open source AI coding agents. By exploiting shell behaviors such as quote removal and variable expansion, attackers can hide malicious commands … ⌘ Read more

⤋ Read More

Linux 7.2-rc2 BPF Code Being Hardened Against JIT Spraying Attacks
Some post-merge-window code changes merged overnight ahead of Linux 7.2-rc2 this weekend is hardening the kernel’s BPF code against JIT spraying attacks… ⌘ Read more

⤋ Read More

How a Seemingly Harmless Image Can Jailbreak Vision-Language AI Models
Slashdot reader BrianFagioli writes: Florida International University researchers have developed a technique called JaiLIP (Jailbreaking with Loss-guided Image Perturbation) that uses subtle image modifications to bypass AI safety guardrails. Unlike traditional jailbreaks that rely on carefully crafted prompts, the attack works through ima … ⌘ Read more

⤋ Read More

Anthropic Says Alibaba Must Be Punished For Largest Claude Cloning Attack
An anonymous reader quotes a report from Ars Technica: Anthropic has accused the Chinese firm Alibaba of launching the largest attack yet attempting to clone Claude, as China races to match the capabilities of Anthropic’s leading model following Mythos’ release and subsequent restriction from foreign markets. Ars obtained a June … ⌘ Read more

⤋ Read More

Tech Pundit Cringely Co-Founds Startup ‘2Brains Inc’ to Solve LLM Hallucinations
Long-time tech pundit Robert Cringely started his career at the Stanford Artificial Intelligence Lab back in 1978. Last month 73-year-old Cringely explained why his site went on a two-year hiatus — and it’s not just because of a heart attack and a stroke last July:

Just like everyone else, I’ve been busy all this time on … ⌘ Read more

⤋ Read More

Microsoft Discovers Cryptocurrency Stealer That Spreads Through USB Drives and Uses Tor
Ars Technica’s senior security editor reports:

Microsoft says it has detected new self-propagating malware that spreads through USB drives in search of cryptocurrency credentials, which it then sends to attacker-controlled servers.

The company named the worm Crypto Clipper because it monitors the cont … ⌘ Read more

⤋ Read More

New Unpatchable Exploit Targets Apple Devices With A12 and A13 Chips
Researchers have disclosed a new unpatchable BootROM exploit affecting Apple devices with A12, A13, S4, and S5 chips. The attack requires physical USB access and DFU mode, but can let an attacker run code before iOS loads, bypass signature checks, and boot modified software. 9to5Mac reports the details: In a highly detailed technical post p … ⌘ Read more

⤋ Read More

Users Cry Foul After AMD Stripped Memory Crypto From Its Consumer CPUs
An anonymous reader quotes a report from Ars Technica: A decade ago, AMD added a protection to its high-end CPUs to protect them against cold boot attacks and other types of physical exploits that siphon sensitive data out of the connected memory chips. Short for Transparent Secure Memory Encryption, TSME encrypts the entire conten … ⌘ Read more

⤋ Read More

In Magic today, the Phyrexian Invasion failed in the first game, but the second game was EPIC!

I played my (unlisted) Dragons 2: Draconic Boogaloo deck, and…

Turn 1: Nothing special
Turn 2: Miirym (when a dragon enters, copy it)
Turn 3: Tiamat (choose 5 dragons from deck, put in hand)
Turn 4: Klauth (when dragons attack, create mana equal to their total power)
I attacked with all 5 dragons, which made 28 mana x2 = 56(!) mana.
Then (still turn 4) I played Scourge of Valkas (when a dragon enters, deal damage to target equal to number of dragons) + 5 other dragons, dealing 6 + 2 x (7+8+9+10+11+12+13+14+15+16+17) = 270(!) direct damage (more than double enough to kill the other 3 players).

Damn fine win, if I do say so myself.

⤋ Read More
In-reply-to » Oh boy, I absolutely hate this stupid trend of not writing changelogs anymore! Why the fuck would one seriously consider it to be a viable option to just let some shitty bot spew all merge requests on a goddamn GitHub release?! First of all, these merge request titles suck balls. The order of the changes in this "changelog" is completely random (well, probably merge time, which is as useless as the dick on the Pope). They are not grouped by anything at all. Additions, changes, removals, deprecations, etc. randomly mixed up in one giant list. And then "Add feature X", seventeen kilometers further down "Revert 'Add feature X'". Fuck you! Don't include this shit in the first place!

@movq@www.uninformativ.de I just ran across another thing. At least I personally couldn’t care less about CI infrastructure changes. Whether they’re using github action a or b or c or version v or w, it is not of my interest. At all. (It might be useful to estimate the supply chain attack risk, though.) If the maintainers want to include them in the changelog – and there are probably people to whom this information is crucial – it’s probably best to document CI infrastructure changes in their own section.

⤋ Read More

A White Supremacist Youth Group Helped Orchestrate the Belfast Riots
After Elon Musk and Tommy Robinson stoked anger over a horrific knife attack in Belfast, a youth group linked to a global neo-Nazi movement quietly orchestrated anti-immigrant riots. ⌘ Read more

⤋ Read More

ASX set to soar, Wall Street surges as Trump says peace deal near; SpaceX prices IPO at $US135 a share
Wall Street powered a rally in stocks as oil sank after President Donald Trump signalled the US is close to a deal with Iran, fuelling hopes for an end to the war that has roiled global markets. ⌘ Read more

⤋ Read More

‘Great settlement’: Trump calls off Iran strikes, claims peace deal could be signed this weekend
Iran’s semi-official Fars news agency reported that Tehran was likely to approve the agreement, which came just hours after the US president threatened to escalate the war. ⌘ Read more

⤋ Read More

‘Great settlement’: Trump calls off Iran strikes, claims peace deal could be signed this weekend
Iran’s semi-official Fars news agency reported that Tehran was likely to approve the agreement, which came just hours after the US president threatened to escalate the war. ⌘ Read more

⤋ Read More

‘Great settlement’: Trump calls off Iran strikes, claims peace deal could be signed this weekend
Iran’s semi-official Fars news agency reported that Tehran was likely to approve the agreement, which came just hours after the US president threatened to escalate the war. ⌘ Read more

⤋ Read More