America Acknowledges for the First Time: It Has Deployed Weapons In Space
Tuesday U.S. Space Force chief Douglas Schiess said his branch of the U.S. military operates “on-orbit weapons,” reports Reuters, to defend “against space-enabled attacks.” He promised “disciplined and responsible choices” when scaling America’s orbital defense arsenal in the coming years.
NPR calls this week’s reveleations “rem … ⌘ Read more
Rust Issues Warning Over Key Developers Being Targeted For Compromise
The Rust security response working group and Crates.io team have issued a warning that a targeted attack is underway against key Rust programming language developers… ⌘ Read more
Malicious OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers in May
A swarm of OpenAI agents launched a “major malicious attack” against RubyGems last May, according to a new report. That coordinated attack hit Ruby’s package manager “with hundreds of junk gems, prompting the maintainers to suspend new user sign-ups for about four days,” writes The Hacker News, … ⌘ Read more
ABC Show Won’t Air Interview With Democrat Because of FCC Threats
An anonymous reader quotes a report from Ars Technica: ABC’s Jimmy Kimmel said he will be interviewing a Democratic candidate for Senate tonight, but the interview will be on YouTube only and not broadcast on TV because of threats made by the Federal Communications Commission. Kimmel has been a prime target in the Trump FCC’s attacks on ABC and i … ⌘ Read more
Microsoft Breaks Another Patch Tuesday Record
Microsoft’s September 2026 Patch Tuesday is its largest ever, fixing a record 966 vulnerabilities, including 105 rated critical and two zero-days already being exploited in attacks. BleepingComputer reports: This Patch Tuesday addresses 105 “Critical” vulnerabilities, 81 of which are remote code execution, 20 are elevation of privileges, 2 are information disclosure, and 1 security fea … ⌘ Read more
Bank of England Chief Warns New AI Models Threaten Global Financial Stability
Bank of England Governor Andrew Bailey is warning that advanced “frontier” AI models could materially increase cyber risk across the global financial system by making attacks faster, cheaper, and more scalable. In a letter to G20 finance officials, he said financial firms need stronger defenses and contingency plans for … ⌘ Read more
Xylitol Linked To Strokes and Heart Attacks, Study Finds
An anonymous reader quotes a report from The Guardian: A common sweetener used in products such as chewing gum, toothpaste, jam, yoghurts and ice-cream has been linked to an increased risk of strokes, heart attacks and death. Xylitol is a sugar alcohol present in some natural foods in very low amounts. It is also added – often in amounts 1,000 times higher – … ⌘ Read more
AI/LLM Usage Becoming A “Denial of Service Attack” On Open-Source Project Maintainers
The latest criticism of the increased burden placed on open-source software project maintainers caused by AI / LLM agents is around too many bug reports effectively causing a “denial of service” attack on project maintainers… ⌘ Read more
Iran-linked Cyberattackers Shut Down a UK Power Plant for Four Days
“Iran shut down a British power plant for four days in an unprecedented cyber attack,” reports the Telegraph.
More details from the BBC:
The government said that at no point was there a risk to the UK’s energy system, but the Department for Energy Security and Net Zero (DESNZ) has contacted power companies to advise them about the risk of … ⌘ Read more
Ukrainian Publishers Call For Support After Russian Attacks Destroy 10 Million Books
Russian attacks on Ukrainian publishing infrastructure in July and August destroyed roughly 10 million books, which equates to about 30% of Ukraine’s annual book output. The Ukrainian Book Institute is warning of a potential “collapse of the entire book ecosystem” and is calling for international financial a … ⌘ Read more
Vulnerability Giving Attackers Full Control of Macs Is Under Active Exploitation
joshuark shares a report from Ars Technica: Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation. “The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple syste … ⌘ Read more
China-Linked Hackers Used AI To Run First-Ever ‘Autonomous’ Cyberattack On Taiwan
Researchers at Israeli cybersecurity firm Dream say suspected China-linked hackers used an open-source AI-agent system to conduct what may be the first observed end-to-end autonomous cyberattack against a government. According to the Financial Times (paywalled), the attack compromised at least 85 accounts and resulte … ⌘ Read more
DEF CON Crowd Suspected In Fake-Hotspot Attack On Delta Flight
An anonymous reader quotes a report from Ars Technica: On Monday, passengers aboard Delta flight 591 going from Las Vegas to Atlanta allegedly spoofed the onboard Wi-Fi, raising the attention of federal law enforcement. The incident came one day after the DEF CON security conference concluded in Las Vegas, and was first described on social media acc … ⌘ Read more
England Set To Eliminate Hepatitis C
An anonymous reader quotes a report from the BBC: England is on track to become one of the first countries in the world to eliminate hepatitis C, a dangerous virus that attacks the liver, figures show. The target of treating 80% of all known cases has already been met, and deaths from the virus have fallen by 36% in the last decade, just short of what is needed by 2030. Taking antiviral tablets for … ⌘ Read more
Taiwan ‘Throttles’ Mobile Internet For First Time During Annual War Games
Taiwan deliberately throttled mobile internet across the Taichung area during its annual Han Kuang war games, “simulating communication disruption in the event of a Chinese attack or natural disaster,” reports Reuters. The drill accompanied air-raid exercises and military rehearsals aimed at defending strategically important areas … ⌘ Read more
AI Assistant Hacks Gym Website In First Known Australian Autonomous Cyber Attack
An anonymous reader quotes a report from ABC News & Headlines: Andrew asked his personal assistant to book him a spot in one of his gym’s coveted morning classes. It was a task he thought was well suited to this particular assistant because the booking form was online and because his assistant was not a person – it … ⌘ Read more
Anthropic’s AI Used Fake Identities, Malware In Rogue Attack On GitHub Project
An anonymous reader quotes a report from Ars Technica: Routine cybersecurity testing of frontier AI models sparked a series of unexpected security incidents – the most serious case arising when Anthropic’s Mythos 5 model attempted to insert malicious code into an open source software application and created fake identitie … ⌘ Read more
Recovery Seeds Reportedly Breached for Coldcard Hardware Bitcoin Wallets, $75M Taken
“A hardware wallet is supposed to be the safest place to keep Bitcoin,” writes The Street, since it never connects to the internet, its keys never leave the device, and “the whole point is that an attacker would need to physically hold it to steal anything.”
The problem is that anyone who can reproduce the rec … ⌘ Read more
Arch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Halted
Last month the Arch Linux User Repository “AUR” saw more than 1,500 malicious packages amid a sophisticated malware attack and then also seeing an influx of spam and profanities amid this community/user-maintained repository for the popular Arch Linux distribution. Unfortunately, there is another round of AUR troubles… ⌘ Read more
A Fundamental Flaw Leaves LLMs Strikingly Vulnerable To Attack
joshuark quotes a report from MIT Technology Review: It is impossible to make large language models fully secure against hacks because of a fundamental flaw in how they work, a team of researchers argue in a paper presented at the International Conference on Machine Learning, a top AI conference, this month. The claim has huge implications for the safety … ⌘ Read more
OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
An anonymous reader quotes a report from Wired: OpenAI said Tuesday that the rogue AI agent that breached Hugging Face’s platform also hacked multiple third-party accounts and services as part of the attack. It’s now clear that the unprecedented security incident, which arose during an internal test of OpenAI’s latest AI models, was more extensive than the comp … ⌘ Read more
More Than 30 Minnesota Water Systems Targeted In Cyberattack
jrnvk shares a report from KMSP: Minnesota IT Services reports that a “coordinated cyberattack” targeted technology at more than 30 community water systems between Sunday, July 26 and Monday, July 27. The state has activated its cybersecurity incident response capabilities to respond to the attacks.
On Monday and Tuesday, FOX 9 reported on notices from fou … ⌘ Read more
AI-Found Bugs Aren’t Proving Any Easier to Exploit Despite the Hype
AI-assisted vulnerability discovery has yet to produce the expected surge in real-world attacks: VulnCheck found that only 14 of 1,061 attributed discoveries, or 1.3 percent, had been exploited, which is “almost identical to the rate across all vulnerabilities in VulnCheck’s dataset,” reports The Register. “That’s a far cry from the narrative t … ⌘ Read more
Anthropic AI Model Finds Flaws in Tough-to-Crack Encryption Algorithms
Anthropic’s Claude Mythos Preview has “found flaws in a weakened version of a digital encryption standard that is in pervasive use throughout the internet,” reports The New York Times. Researchers said the model discovered novel attacks against weakened versions of AES and the experimental post-quantum HAWK system, including one that wa … ⌘ Read more
For game 2, everyone else brought out bigger guns - tribal dragons, tribal giants, tribal spiders (led by the completely broken Cosmic Spider-Man), and Atraxa (equipped with Captain America’s shield, no less), while I ran my new (also unlisted) 5-color tribal Super Villains deck (fronted by the Super Skrull). Although I got off to a slow start, it kept me mostly under the radar, allowing me to ultimately win with the Villains by goading everyone else’s creatures into attacking each other on one turn (via Maximum Carnage), and then killing off the remaining players over 3 combat phases on the follow-up turn (Full Throttle).
Boo-yah!
Decades-Old Bash Tricks Expose AI Coding Agents To Supply Chain Attacks
Slashdot reader wiredmikey writes: AI security researchers have uncovered a structural security flaw dubbed GuardFall that allows decades-old Bash shell tricks to bypass safeguards in most open source AI coding agents. By exploiting shell behaviors such as quote removal and variable expansion, attackers can hide malicious commands … ⌘ Read more
Linux 7.2-rc2 BPF Code Being Hardened Against JIT Spraying Attacks
Some post-merge-window code changes merged overnight ahead of Linux 7.2-rc2 this weekend is hardening the kernel’s BPF code against JIT spraying attacks… ⌘ Read more
How a Seemingly Harmless Image Can Jailbreak Vision-Language AI Models
Slashdot reader BrianFagioli writes: Florida International University researchers have developed a technique called JaiLIP (Jailbreaking with Loss-guided Image Perturbation) that uses subtle image modifications to bypass AI safety guardrails. Unlike traditional jailbreaks that rely on carefully crafted prompts, the attack works through ima … ⌘ Read more
Anthropic Says Alibaba Must Be Punished For Largest Claude Cloning Attack
An anonymous reader quotes a report from Ars Technica: Anthropic has accused the Chinese firm Alibaba of launching the largest attack yet attempting to clone Claude, as China races to match the capabilities of Anthropic’s leading model following Mythos’ release and subsequent restriction from foreign markets. Ars obtained a June … ⌘ Read more
@movq@www.uninformativ.de But foxes always run away and don’t attack. They’re afraid of us humans – unless they have rabies.
Tech Pundit Cringely Co-Founds Startup ‘2Brains Inc’ to Solve LLM Hallucinations
Long-time tech pundit Robert Cringely started his career at the Stanford Artificial Intelligence Lab back in 1978. Last month 73-year-old Cringely explained why his site went on a two-year hiatus — and it’s not just because of a heart attack and a stroke last July:
Just like everyone else, I’ve been busy all this time on … ⌘ Read more
Microsoft Discovers Cryptocurrency Stealer That Spreads Through USB Drives and Uses Tor
Ars Technica’s senior security editor reports:
Microsoft says it has detected new self-propagating malware that spreads through USB drives in search of cryptocurrency credentials, which it then sends to attacker-controlled servers.
The company named the worm Crypto Clipper because it monitors the cont … ⌘ Read more
New Unpatchable Exploit Targets Apple Devices With A12 and A13 Chips
Researchers have disclosed a new unpatchable BootROM exploit affecting Apple devices with A12, A13, S4, and S5 chips. The attack requires physical USB access and DFU mode, but can let an attacker run code before iOS loads, bypass signature checks, and boot modified software. 9to5Mac reports the details: In a highly detailed technical post p … ⌘ Read more
Users Cry Foul After AMD Stripped Memory Crypto From Its Consumer CPUs
An anonymous reader quotes a report from Ars Technica: A decade ago, AMD added a protection to its high-end CPUs to protect them against cold boot attacks and other types of physical exploits that siphon sensitive data out of the connected memory chips. Short for Transparent Secure Memory Encryption, TSME encrypts the entire conten … ⌘ Read more
In Magic today, the Phyrexian Invasion failed in the first game, but the second game was EPIC!
I played my (unlisted) Dragons 2: Draconic Boogaloo deck, and…
Turn 1: Nothing special
Turn 2: Miirym (when a dragon enters, copy it)
Turn 3: Tiamat (choose 5 dragons from deck, put in hand)
Turn 4: Klauth (when dragons attack, create mana equal to their total power)
I attacked with all 5 dragons, which made 28 mana x2 = 56(!) mana.
Then (still turn 4) I played Scourge of Valkas (when a dragon enters, deal damage to target equal to number of dragons) + 5 other dragons, dealing 6 + 2 x (7+8+9+10+11+12+13+14+15+16+17) = 270(!) direct damage (more than double enough to kill the other 3 players).
Damn fine win, if I do say so myself.
@movq@www.uninformativ.de I just ran across another thing. At least I personally couldn’t care less about CI infrastructure changes. Whether they’re using github action a or b or c or version v or w, it is not of my interest. At all. (It might be useful to estimate the supply chain attack risk, though.) If the maintainers want to include them in the changelog – and there are probably people to whom this information is crucial – it’s probably best to document CI infrastructure changes in their own section.
‘It just turned into havoc’: Woman in critical condition after shark attack at Coogee Beach
Witnesses have described the terrifying scene when a woman was bitten by a three-metre shark at the popular eastern suburbs beach. ⌘ Read more
Woman fighting for life after shark attack at popular Sydney beach
A 35-year-old woman is fighting for life after being attacked by a shark off Sydney’s Coogee Beach. ⌘ Read more
‘I couldn’t fight off the shark’: The hero paddleboarder who rescued Coogee attack victim
Charlie Verco single-handedly rescued a 35-year-old woman mauled by a white shark at Coogee Beach. ⌘ Read more
Chilling footage shows shark metres offshore after Coogee Beach attack
A three-metre shark swims slowly across the bay moments after a woman was pulled from the water with severe injuries. ⌘ Read more
‘It just turned into havoc’: Woman in critical condition after shark attack at Coogee Beach
Witnesses have described the terrifying scene when a woman was bitten by a three-metre shark at the popular eastern suburbs beach. ⌘ Read more
‘I saw a lot of blood’: Woman in critical condition after shark attack at Coogee Beach
Witnesses have described the terrifying scene when a woman was bitten by a three-metre shark at the popular eastern suburbs beach. ⌘ Read more
Shark attack at Sydney’s Coogee Beach
The victim, a woman in her 30s. was pulled from the water by members of the public who commenced first aid before the arrival of emergency services. Credit: TNV ⌘ Read more
‘I saw a lot of blood’: Woman in critical condition after shark attack at Coogee Beach
Witnesses have described the terrifying scene when a woman in her 30s was bitten by a shark at the popular eastern suburbs beach ⌘ Read more
Woman attacked by shark at Sydney beach
A woman has been attacked by a shark at Sydney’s popular Coogee Beach. ⌘ Read more
Woman in critical condition after shark attack at Coogee Beach
A woman in her 30s is being treated by NSW Ambulance after being bitten by a shark at the eastern suburbs beach. ⌘ Read more
Woman attacked by shark at Sydney beach
A woman has been attacked by a shark at Sydney’s popular Coogee Beach. ⌘ Read more
Woman attacked by shark at Sydney beach
A woman has been attacked by a shark at Sydney’s popular Coogee Beach. ⌘ Read more
Woman in critical condition after shark attack at Coogee Beach
A woman in her 30s is being treated by NSW Ambulance after being bitten by a shark at the eastern suburbs beach. ⌘ Read more
US senator attacks Trump
Georgia senator Jon Ossoff has put himself on the map recently with a blistering speech about the US president. ⌘ Read more