In this input integrity attack against an AI system, researchers were able to fool AIOps tools: > AIOps refers to the use of LLM-based agents to g...
A zero-day vulnerability in WinRAR is being exploited by at least two Russian criminal groups: > The vulnerability seemed to have super Windows po...
Researchers have managed to eavesdrop on cell phone voice conversations by using radar to detect vibrations. It's more a proof of concept than anyt...
Here's the story. The commenters on X (formerly Twitter) are unimpressed. As usual, you can also use this squid post to talk about the security st...
Porn sites are hiding code in .svg files: > Unpacking the attack took work because much of the JavaScript in the .svg images was heavily obscured ...
Here's an interesting story about a failure being introduced by LLM-written code. Specifically, the LLM was doing some code refactoring, and when i...
There is a really great series of online events highlighting cool uses of AI in cybersecurity, titled Prompt||GTFO. Videos from the first three eve...
The NSA and GCHQ have jointly published a history of World War II SIGINT: "Secret Messengers: Disseminating SIGINT in the Second World War." This i...
Fears around children is opening up a new market for automatic license place readers.
In a rare squid/security combined post, a new vulnerability was discovered in the Squid HTTP proxy server.
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.