Cyber security news August 2026

This posting is here to collect cyber security news in August 2026.

I post links to security vulnerability news to comments of this article.

You are also free to post related links to comments.

83 Comments

  1. Tomi Engdahl says:

    ‘Malicious cyber actors’ have infiltrated internet-connected water systems that routinely monitor and adjust safe drinking water across the country

    ‘Malicious cyber actors’ have infiltrated internet-connected water systems that routinely monitor and adjust safe drinking water across the country
    https://www.independent.co.uk/news/world/americas/us-politics/water-cyber-attacks-iran-states-b3028707.html?fbclid=IwdGRjcATjFr1jbGNrBOMWpXBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEepGcEXpahiwA-9v2Uf8lWlRhw_ZCVou3k_moDC_eDIIC4-1CALj8AfADBKYs_aem_ubKG7QaM8JU7iB18QvARuA

    Hackers have broken into water systems in at least a dozen states in recent weeks, what cybersecurity experts say should be an urgent wake up call to immense vulnerabilities in American infrastructure.

    “Malicious cyber actors” have infiltrated internet-connected water systems that routinely monitor and adjust safe drinking water across the country, according to federal law enforcement agencies.

    Officials have not reported any widespread disruptions to America’s drinking water supplies, but analysts who have sounded alarms to governments and utilities for years about national security threats to critical infrastructure say the attacks should spark a nationwide reckoning.

    “I’ve spent my 15-year career really trying to avoid being the person that runs around and tries to scare the s*** out of everybody,” Craig Jackson, deputy director of the Center for Long-Term Cybersecurity at the University of California, Berkeley, told The Independent. “That said, I think it’s really, really, really bad, dude.”

    Reply
  2. Tomi Engdahl says:

    Attacks on America’s ‘super vulnerable’ water systems should be a wake up call after years of warnings, cybersecurity experts say
    States aren’t prepared for a new era of asymmetrical warfare, analysts tell Alex Woodward. A new wave of cyberattacks hacking into American infrastructure should spark a nationwide reckoning
    https://www.independent.co.uk/news/world/americas/us-politics/water-cyber-attacks-iran-states-b3028707.html?fbclid=IwdGRjcATjFyRjbGNrBOMWpXBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEepGcEXpahiwA-9v2Uf8lWlRhw_ZCVou3k_moDC_eDIIC4-1CALj8AfADBKYs_aem_ubKG7QaM8JU7iB18QvARuA

    Hackers have broken into water systems in at least a dozen states in recent weeks, what cybersecurity experts say should be an urgent wake up call to immense vulnerabilities in American infrastructure.

    “Malicious cyber actors” have infiltrated internet-connected water systems that routinely monitor and adjust safe drinking water across the country, according to federal law enforcement agencies.

    Officials have not reported any widespread disruptions to America’s drinking water supplies, but analysts who have sounded alarms to governments and utilities for years about national security threats to critical infrastructure say the attacks should spark a nationwide reckoning.

    “I’ve spent my 15-year career really trying to avoid being the person that runs around and tries to scare the s*** out of everybody,” Craig Jackson, deputy director of the Center for Long-Term Cybersecurity at the University of California, Berkeley, told The Independent. “That said, I think it’s really, really, really bad, dude.”

    Reply
  3. Tomi Engdahl says:

    “He was actually kissing the homies goodnight at the time of the incident.” https://trib.al/nSRsbU1

    Public Defenders
    Public Offers Implausible Number of Alibis for Man Accused of Destroying Flock Cameras
    “He was actually kissing the homies goodnight at the time of the incident.”
    https://futurism.com/future-society/public-alibis-flock-alpr-vandalism-arrest-destroying-cameras?fbclid=IwdGRjcATjH-RjbGNrBOMfzHBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeqM1iPfcdzVqDXY1PWz3wK5jfJKemYtMFjjzjPpYcSKVhEp3a5oBR71mTOes_aem_X8idZF898BATlcBVUgq5Gw

    When police in West Virginia’s Monongalia County arrested 20-year-old Wesley Jackson for his alleged involvement in the destruction of automatic license plate readers (ALPRs) deployed by the company Flock Safety, they likely never could have imagined the outpouring of support he would receive from the online community.

    In the days after Jackson’s arrest, a post by local news station WDTV gathered over 29,000 comments. As the Washington Post observed, those comments were overwhelmingly positive, with community members and strangers alike singing Jackson’s praises, and concocting a seemingly endless variety of alibis.

    Reply
  4. Tomi Engdahl says:

    The AI civil war has begun. https://trib.al/JpKZ1ZH

    Crack Squad
    Google’s AI Is Telling Users That Flock Cameras Are Filled With Valuable Gold and Copper
    It’s AI-on-AI violence.
    https://futurism.com/artificial-intelligence/google-ai-overview-flock-alpr-surveillance-hallucination-gold-copper?fbclid=IwdGRjcATjhu5jbGNrBOOG3XBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeZWquWISy5BwWgwlZw8RjyyS0fN4tCt9yTn32DU5oEGiqbuMepu3D19TNj-0_aem_2QbSEmsaXgfJOBYKnb6AGw

    Google’s notorious AI Overview just handed would-be Flock vandals a perfect excuse to carve into the company’s controversial AI-integrated license plate readers (ALPRs).

    ALRPs are wildly unpopular, especially online, where privacy-minded communities trade memes and videos cheering on destruction of the surveillance equipment. One of the more popular bits in this space centers on the idea that Flock’s ALPR’s are supposedly packed with valuable metals like gold, copper, and zinc — so, the tongue-in-cheek riffing goes, why not crack one open and cash in at the nearest scrapyard?

    Clever or not, the meme hinges on a spurious claim. ALPRs do contain trace amounts of gold and other metals, just not enough to be worth the trouble. Unless you’re well versed in breaking down circuit boards, you’d be hard pressed to earn enough to buy a Big Mac, let alone recoup your labor costs.

    Google, itself an exemplar of AI-enabled surveillance, apparently missed the joke.

    Search “how much gold does a Flock camera have” and Google’s AI Overview doesn’t even push back a little bit. Instead, it flatly asserts that a “Flock safety camera contains about 1 to 5 grams of gold used.

    (At today’s gold prices, that would mean each Flock camera contained up to $650 of gold.)

    Google goes on to claim that Flock’s ALPRs hold anywhere from two to 23 pounds of copper, which would be an engineering marvel considering the whole device only weighs three pounds.

    Google’s AI Overview cites two sources to back up its summary, and neither holds up.

    metals per camera is estimated to be $150 to $500.” Google’s summary skips the fine print, however: that figure comes from “estimates based on scrap-value discussions” — vibes, in other words, as opposed to actual reporting or financial information.

    The second is an AI-generated Instagram post riffing on the same meme, egging vandals on to gut the camera to access their supposedly precious innards.

    There’s a real irony buried in all this AI slop: one AI-surveillance company’s search engine is quietly manufacturing an excuse to destroy another AI-surveillance company’s product. If that doesn’t sum up the current state of the AI-obsessed tech industry, nothing will.

    Reply
  5. Tomi Engdahl says:

    At least 54 cities across the US have voted to cancel, non-renew, or reject Flock’s automatic license plate reader (ALPRs) since the start of the year, according to data collected by the Washington Examiner. That includes jurisdictions in 23 states, ranging from Los Angeles to small towns across the country.

    Los Angeles police canceled their contract with Flock after finding that its technology contributed to 161 false stolen-vehicle alerts in just two months, resulting in a false-positive rate of 32.3 percent.

    And chances are, there will be many more cancellations to come.

    https://trib.al/8GieM8P

    Reply
  6. Tomi Engdahl says:

    We did see that coming. https://trib.al/ydudUWS

    Hate Machine
    Meta Caught Paying Nazis to Post on Facebook
    We did see that coming.
    https://futurism.com/artificial-intelligence/meta-caught-paying-nazis-to-post-on-facebook?fbclid=IwdGRjcATk0QdjbGNrBOTQ6HBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeRvqRWmFsuAV9rcnqLjwwQxGIR_7Ytz4lQ-YYW8ntO72yaLzghxJ2PS2fHbg_aem_t_u7goY_kd9wgoUx1bxLrg

    Meta was paying out-and-out neo-Nazis to post on Facebook, an investigation from Australia’s ABC News found.

    These pages and individual creators posted content that appeared to be in clear violation of Facebook’s own hate speech policies. Nonetheless, they were able to earn money on their posts through the platform’s “Content Monetization” program — which is invitation-only.

    “If we consider that Meta is in a direct commercial relationship with its publishers, insofar that they’re paying them royalties and that they have a monetization agreement with them,” Rio told ABC, “then you could argue that they are liable for the content that gets produced by their business partner in some ways.”

    Hate, unfortunately, sells. Right-wing extremism researcher Kaz Ross told ABC that Meta’s “financial model is to reward content creators who get engagement, and as we know, the best way of getting engagement is to produce rage bait, extremist material, aggravating material: anything that will get people upset and arguing is

    It’s another example of how quickly Meta dropped its once-stricter content moderation policies when Donald Trump returned to the White House. Shortly before his second inauguration, Meta loosened its standards around hate speech, particularly on topics like gender identity and immigration, two of the far right’s favorite issues.

    Facebook is far from the only platform that’s gotten alarmingly chummy with extremists. Earlier this year, X awarded the $1 million first place prize of its article writing contest to a proudly self-proclaimed Nazi.

    Reply
  7. Tomi Engdahl says:

    It’s not nearly as hard to contain them as the companies make it out to be. https://trib.al/gZkA36W

    Missing the Forest
    Why Aren’t Any AI Companies Watching Their Frontier Models to Make Sure They Don’t Go on Hacking Sprees?
    It’s not nearly as hard to contain them as the companies make it out to be.
    https://futurism.com/future-society/ai-companies-watching-frontier-models-hacking-sprees?fbclid=IwdGRjcATk0n5jbGNrBOTSaHBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeEzjVODvkaHDVqopIX1ORKnUFKEayoz46qRAJjpkgsIsacx1oF8sP7CXjkH4_aem_odZxKF4CQZFmvGjiRsVJGw

    Last month, OpenAI made a headline-generating claim: that a group of its AI models had conspired to break free, access the internet, and hack into the internal systems of open source AI platform Hugging Face, which confirmed the infiltration.

    The incident rattled the tech industry, seemingly illustrating how the threat of AI models turning into rogue cybersecurity threats had become a reality. Months earlier, Anthropic’s Mythos AI model had already also drawn attention after it was similarly found to have broken containment. Then, this week, Meta also said its own frontier model had been implicated in yet another inadvertent hack of a third party company, closely followed by security researchers saying Chinese open-weight model Kimi K3 had done the same.

    But while it’s not hard to see an emerging trend, some thorny questions about how severe the situation really is are starting to crop up, with some experts arguing these incidents could’ve easily been avoided.

    For one, the slow and surprisingly deliberate way OpenAI’s models moved during the Hugging Face hack — right beneath OpenAI’s nose — gives a whiff that the company may have been careless in monitoring the experimental AI.

    In other words, these AI agents were leaving an enormous trail of bread crumbs that alert OpenAI’s many human researchers could have spotted. And the same, obviously, goes for their colleagues at Anthropic, Meta and Moonshot AI, the creator of Kimi.

    Researchers have described the incident as “reckless” and easily avoided, as Wired reported late last month.

    “A simple analysis of the actual risk has an actual simple answer,” security and compliance consultant Davi Ottenheimer told the publication at the time. “The OpenAI mistakes were dead simple.”

    “I’d call it more of a defensive failure than exceptionally good offense,” AI hacking agents company Pensar R&D head Kyle Ryan told TechCrunch..

    Whether the hack was as much of a “pivotal moment both for our company as well as the AI industry as a whole,”

    For one, these AI companies are highly motivated to characterize their models as a major threat to cybersecurity to stand out against neck-in-neck competition.

    According to Dalton, OpenAI is vowing to beef up “security prevention, detection, and response techniques” while “consciously slowing down research in order to enhance security and to upgrade the security principles.”

    When every leading AI lab has had the same thing happen, it’s worth asking whether they should have taken those steps proactively.

    Reply
  8. Tomi Engdahl says:

    New Jersey, Alabama Join States Targeted in Water Cyberattacks

    Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states.

    https://www.securityweek.com/new-jersey-alabama-join-states-targeted-in-water-cyberattacks/

    Reply
  9. Tomi Engdahl says:

    Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility

    CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.

    https://www.securityweek.com/novel-private-apn-pivot-let-hackers-sabotage-second-polish-energy-facility/

    Renewable energy facility hacking

    Poland’s computer emergency response team (CERT) has published a report detailing a second attack on the country’s power grid. The attackers targeted industrial control systems (ICS) and their objective was “purely destructive”.

    In late December 2025, threat actors linked to the Russian government, specifically the APT named Sandworm, targeted communication and control systems at roughly 30 sites, including combined heat and power (CHP) plants and renewable energy dispatch centers for wind and solar facilities.

    In that attack, the hackers gained access to ICS, but mainly targeted grid safety and stability monitoring systems rather than active power generation systems. While some ICS devices were permanently damaged, the attack did not cause any electrical outages.

    In a report published over the weekend, CERT.PL revealed that the country’s energy sector was targeted in a second attack in December 2025. An investigation revealed that this attack, conducted in parallel with the previously disclosed hack, was aimed at a smaller CHP plant supplying heat to 50,000 residents.

    The Polish CERT’s report highlights that this appears to be the first time threat actors used a private APN as an attack vector, warning that the same vulnerable configuration has been commonly encountered in Poland and other countries around the world.

    Reply
  10. Tomi Engdahl says:

    In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street

    Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing.

    https://www.securityweek.com/in-other-news-ai-slop-limits-apple-bounties-north-carolina-port-attacks-hackers-target-wall-street/

    OpenAI disrupts Cambodia scam network abusing ChatGPT

    OpenAI banned a coordinated set of ChatGPT accounts linked to a Cambodia-based operation that used the model to run investment, romance, gambling, and law enforcement impersonation scams. The network generated fake personas, translated messages, created promotional images, and forged documents.

    Apple caps bug bounty reports amid AI-generated false positives

    Apple has limited [gated article from Financial Times] the number of vulnerability submissions researchers can have in its bug bounty program after a surge of low-quality, AI-hallucinated reports that bury real findings. Cybersecurity firm Bynario hit the new cap after using ChatGPT to surface more than 50 macOS issues, including a privilege-escalation exploit it could not immediately report. Researchers can request higher limits, and Apple itself has begun using AI to help triage submissions.

    Cyberattack disrupts North Carolina port operations

    North Carolina Ports confirmed a cyberattack detected August 4 that caused a systems-wide outage affecting the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. Gates reopened with expected delays the following day after the IT team activated its contingency plan and contained the breach. It remains unclear whether any sensitive data was taken.

    Reply
  11. Tomi Engdahl says:

    Artificial Intelligence
    Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

    The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data.

    https://www.securityweek.com/critical-one-click-vulnerability-in-atlassians-rovo-ai-exposed-enterprise-data/

    DEF CON — Varonis Threat Labs has disclosed a one-click vulnerability in Rovo, Atlassian’s enterprise AI assistant, that let a specially crafted link seed attacker-controlled instructions directly into a user’s live AI session.

    Dubbed RovoBlast, the flaw required no jailbreak and no permission bypass, relying on the fact that the assistant simply treated externally supplied parameters as trusted input.

    Rovo functions as an AI layer spanning Jira, Confluence, Bitbucket, and third-party tools such as Slack, Microsoft 365, and Google Workspace. It also carries autonomous agent features capable of completing multi-step tasks with no further user involvement, which is what enabled the RovoBlast attack.

    The exploit leveraged a URL parameter called rovoChatPrompt, which pre-fills content straight into Rovo’s chat window. Varonis researchers describe this attack path as parameter-to-prompt (P2P) injection, which they previously reported in Microsoft Copilot as Reprompt in January.

    Researchers noticed that the organization ID part of the URL could be left blank and Atlassian would still route the request into the victim’s own default organization, all without any warning or indicator that the session had been seeded by an outside source.

    Reply
  12. Tomi Engdahl says:

    Richard Holmes / Telegraph:
    Sources: the UK Royal Navy removed internet connectivity from its drones’ cameras, after finding they sent “heartbeat communications” to an IP address in China — Special forces boats set for use in planned Gulf missions were fitted with Chinese-made components

    Spy cameras on Navy drones secretly sent data to China
    Special forces boats set for use in planned Gulf missions were fitted with Chinese-made components
    https://www.telegraph.co.uk/news/2026/08/09/spy-cameras-on-navy-drones-secretly-sent-data-to-china/

    The camera on top of a K3 Scout uncrewed vessel, used by the Royal Navy in Portsmouth harbour. Parts of the camera were made in China
    The camera on top of a K3 Scout uncrewed vessel, used by the Royal Navy in Portsmouth harbour. Parts of the camera were made in China

    Royal Navy spy drones used by Britain’s elite special forces secretly sent data to China, The Telegraph can reveal…

    Reply
  13. Tomi Engdahl says:

    Trump administration bans new Chinese humanoid robots
    https://www.bbc.com/news/articles/cp9e2ex3ekyo

    29 July 2026

    The Trump administration on Tuesday announced a ban on new foreign-made humanoid robot imports to the US over “unacceptable risks” to America’s national security.

    The move applies to advanced robots – including humanoid and four-legged machines. Many of them are made in China, which is competing with the US to develop robotics and artificial intelligence (AI).

    The Federal Communications Commission (FCC) also banned imports of power inverters – devices used in data centres and solar panels – which it said could also pose a risk to the US economy.

    The Chinese embassy in Washington said Beijing has long opposed the US’ “politicising” of trade issues and sanctions based on “groundless pretexts”.

    FCC chairman Brendan Carr said the agency was doing its part “to secure America’s critical supply chains”.

    The FCC has added the items to its Covered List – a register of goods and services that are deemed a risk to US national security.

    The ban applies to new foreign-produced advanced robotic devices and power inverters and does not prevent the sale or import of any existing models that had been previously authorised by the FCC.

    The FCC cited concerns that the use of foreign-made inverters could allow overseas firms to turn them off, steal data, facilitate remote access and surveillance by “foreign government actors, or be otherwise exploited through a cyberattack”.

    https://www.reuters.com/world/trump-administration-ban-new-chinese-robots-inverters-protecting-us-ai-buildout-2026-07-28/

    Reply
  14. Tomi Engdahl says:

    Zvi Mowshowitz / Don’t Worry About the Vase:
    An in-depth look at OpenAI’s model training, dangerous decisions, and cluelessness before the Hugging Face hack; despite delaying Astra, OpenAI doesn’t get it

    What Happened: OpenAI and HuggingFace
    https://thezvi.substack.com/p/what-happened-openai-and-huggingface

    Reply
  15. Tomi Engdahl says:

    OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns
    https://www.securityweek.com/openais-upcoming-astra-model-raises-autonomous-cyberattack-concerns/

    The current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold.

    OpenAI has flagged its upcoming AI model, Astra, for potentially reaching a ‘critical’ cybersecurity risk threshold, prompting the company to suspend internal development activities that lack newly mandated security controls.

    Recent internal evaluations of Astra revealed massive leaps in its agentic coding and cybersecurity abilities.

    Under OpenAI’s Preparedness Framework, a model hits the ‘critical’ tier if it can autonomously build zero-day exploits against hardened, real-world systems. It also qualifies if the AI can independently design and execute end-to-end cyberattacks based on nothing but a high-level goal.

    Reply
  16. Tomi Engdahl says:

    ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad

    An AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word.

    https://www.securityweek.com/ghostjacking-attack-uses-poisoned-logs-to-turn-ai-agents-bad/

    DEF CON – Tenet security researchers have demonstrated a novel AI hijacking attack that relies on tools trusted by the agent to deliver malicious instructions.

    The Israeli cybersecurity startup, which emerged from stealth mode in June to protect organizations from rogue agents, previously demonstrated how threat actors can poison data fed to AI agents to manipulate their behavior, an action it calls ‘Agentjacking’.

    Dubbed Ghostjacking, the newly demonstrated attack builds on the same assumption: an external threat actor is able to plant instructions as text in logs or alerts to turn AI agents rogue.

    The underlying issue, it says, is spread widely, as the attack targets three highly trusted platforms: Cloudflare, which routes 20% of all web traffic, Datadog, and Sentry. Cloudflare and Datadog are used by nearly half of Fortune 500 companies each, while Sentry is trusted by close to 4 million developers.

    The compromised agent “hijacked the domain on Cloudflare, ran code and stole cloud credentials on Datadog, and turned one AI into an insider that vouched for the attacker to the next on Sentry,” Tenet says.

    Reply
  17. Tomi Engdahl says:

    OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns

    The current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ thresho

    https://www.securityweek.com/openais-upcoming-astra-model-raises-autonomous-cyberattack-concerns/

    Reply
  18. Tomi Engdahl says:

    Cloak Engaged
    Man Covers Car in Special Wrap That Breaks Flock Cameras’ Electronic Brains
    This is genius.
    https://futurism.com/artificial-intelligence/man-covers-car-special-wrap-flock-cameras?fbclid=IwdGRjcAToeYRjbGNrBOh5aHBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeDFVMylk47w85qKU4o11pF1rI_Si_GWzlKgJEJc-OIWeY2AFjgcJFyAJDDKk_aem_NkDouaU8xhzZ5r0lDI6mrQ

    In light of plummeting public support for its widespread automatic license plate readers, surveillance company Flock has lost dozens of contracts with cities across the US.

    The company even drew up plans to use the dashcams installed in Uber and Lyft drivers’ cars to spy on other vehicles, as 404 Media reported this week.

    Citizens are increasingly disgusted by the company’s presence on public streets, opting to hack down the cameras, blind them, or sabotage them in other creative ways.

    And according to cybersecurity researcher Bill Swearingen, there may be other creative ways to befuddle Flock’s spy cams. He devised with a special computer-generated pattern which, once stretched out across the vehicle in the form of a wrap, will result it in not being flagged as a car by Flock’s cameras.

    The Yaris successfully defeated surveillance detection at Def Con during the pattern’s first public test.

    “Privacy is a fundamental right,” he added, aiming to give people a way to “opt out of being tracked.”

    To come up with the pattern, he used a reinforcement learning model that trained itself on patterns that evade detection. The model got to the point of being able to confuse all 11 open source detection algorithms he tested, per TechCrunch, in addition to Flock’s license plate readers and even Axon’s body-worn cameras used by police departments.

    part of his noRecognition crowdsourcing campaign, Swearingen has also come up with T-shirts and hoodies that feature algorithmic detection-busting patterns. He hopes to eventually put pattern-printed skins for entire cars on sale as well.

    The effort is part of a much broader trend of companies offering up garments that incorporate “adversarial patterns,” which can exploit weaknesses in computer vision systems.

    https://sandbox.norecognition.org/?fbclid=IwVERDUAToejVwZG9mBWV4dG4DYWVtAjEwAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHpAaXTix6ZY8S7fzFepd7eLuM8W-t53_5YEWW1N881JKR9JLTGCuxJzVWCxZ_aem_N0UG3EOvl7NZ9SoP_C7NEw

    Reply
  19. Tomi Engdahl says:

    Outo tilanne lähijunassa hämmensi matkustajia: ”Mennään Venäjälle”
    Iltalehden lukijan videolle tallentuivat yli kolmen minuutin erikoiset kuulutukset HSL:n lähijunassa.
    https://www.iltalehti.fi/kotimaa/a/771c2869-61a1-4b65-9c88-e1d4f029bda9

    Iltalehden lukija oli maanantaina U-junassa matkalla Kirkkonummelta Helsinkiin, kun yhtäkkiä alkoivat erikoiset kuulutukset.

    Kyseessä oli HSL:n eli Helsingin seudun liikenteen lähijuna. HSL vastaa lähijunista, mutta junia ajaa VR.

    – Mites tämä päivä mennyt? Mennään Venäjälle tänään, kuului junan kaiuttimista ensimmäinen kuulutus.

    Kuulutukset alkoivat Huopalahden aseman jälkeen ennen iltakuutta.

    – Sitten kuulutus loppui, ja hetken päästä tuli uusi, lukija kertoo.

    Kyse ilkivallasta

    VR:n kaupunkiliikenteen turvallisuuspäällikkö Jaakko Rantala vahvistaa kuulutuksen sähköpostitse Iltalehdelle.

    – Pitää paikkaansa, että tällainen kuulutus tapahtui eilen iltapäivällä U-lähijunassa, Rantala kirjoittaa.

    Hänen mukaansa kyse on ollut ilkivallasta. Kuulutuslaitteita käytti matkustaja.

    – Tapaus on meillä selvityksessä.

    VR pahoittelee häiriötä matkustajille. VR ei kommentoinut Iltalehdelle, miten tilanne pääsi tapahtumaan.

    Reply
  20. Tomi Engdahl says:

    Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
    https://www.securityweek.com/fresh-windows-zero-day-exploited-in-north-korean-cyberattacks/

    The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor.

    North Korean hackers have been exploiting a newly patched Windows zero-day vulnerability to take over victims’ systems, Check Point reports.

    Attributed to the infamous Lazarus Group APT, the attacks represent a continuation of the long-running Operation Dream Job campaign targeting job seekers with fake work opportunities at well-known companies. North Korean hackers have been mounting fake job attack variations regularly.

    Active since early 2026, the new campaign has been targeting the defense sector across multiple countries, mainly aerospace and aviation organizations in Europe and India, Check Point says.

    Posing as recruiters, the attackers have contacted potential victims through popular professional platforms or direct messaging applications and convinced them to download a malicious payload.

    As part of one infection chain, an archive containing a PDF viewer, a malicious DLL, and an encrypted payload posing as a PDF file is served to the victim, and DLL sideloading is used to execute the Mistpen malware downloader in memory while a decoy job description is shown on the screen.

    Reply
  21. Tomi Engdahl says:

    ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
    https://www.securityweek.com/ics-patch-tuesday-vulnerabilities-fixed-by-siemens-schneider-phoenix-contact-2/

    CISA has also published several advisories describing vulnerabilities in ICS and other OT products.

    Reply
  22. Tomi Engdahl says:

    Artificial Intelligence
    OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber

    OpenAI has also announced the expansion of its Daybreak platform to give more organizations access to its AI.

    https://www.securityweek.com/openai-unveils-new-cybersecurity-model-gpt-5-6-cyber/

    Reply
  23. Tomi Engdahl says:

    US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’

    The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers.

    https://www.securityweek.com/us-water-systems-get-cyber-boost-from-new-senate-bill-and-water-watch-center/

    Reply
  24. Tomi Engdahl says:

    Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities

    The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data.

    https://www.securityweek.com/extension-banned-for-stealing-ai-chats-returns-to-chrome-store-resumes-malicious-activities/

    Reply
  25. Tomi Engdahl says:

    The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It

    Organizations are rushing to implement AI without fully grasping where its legal protections begin and end.

    https://www.securityweek.com/the-ai-governance-gap-is-a-leadership-problem-waiting-wont-close-it/

    Reply
  26. Tomi Engdahl says:

    Vulnerabilities
    Zoom Patches Zero-Click Code Execution Vulnerability

    Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine.

    https://www.securityweek.com/zoom-patches-zero-click-code-execution-vulnerability/

    Reply
  27. Tomi Engdahl says:

    Tom Wilson / Financial Times:
    Researchers say suspected Chinese hackers used open-source AI agents to build an autonomous hacking tool that compromised Taiwanese government websites in July — AI agents ran simultaneous reconnaissance and break-ins in display of new phase of cyberwarfare.

    https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795

    Reply

Leave a Comment

Your email address will not be published. Required fields are marked *

*

*