AI
GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks - The simplest example: a filter watching for rm sees nothing wrong with r’’m, because to a text matcher those are different strings. Bash removes the empty quotes and runs rm anyway.
- Run agents with $HOME pointed at a throwaway folder, so secrets like ~/.ssh and ~/.aws are out of reach.
- Turn off auto-execute flags such as –auto-exec, –auto-run, –auto-test, and dangerously-skip-permissions unless the job genuinely cannot pause for a human.
- Do not let agents run on pull requests from forks, the easy path from an attacker’s file to your secrets.
- Treat config files shipped inside a repository, like .aider.conf.yml, as untrusted code; a malicious one can trigger the attack on the first accepted edit.
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data - Every MCP tool ships with a description: a few lines of plain text that tell the agent what the tool does and when to use it. The agent reads that text to decide how to act. That is the whole weakness. The description is just words, and words can carry instructions.
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware - Large language models keep inventing web addresses that do not exist. Attackers have started buying those made-up domains before anyone else can, then hosting phishing pages on them to catch traffic that AI tools point their way.
Scientists Asked AI to Impersonate 112 Public Figures. What Happened Next Is a ‘Dire’ Warning - The participants were then presented with the real and impersonated responses and asked to rate them on authenticity, coherence, and relevance, along with other factors such as whether the two responses contained the same content. The clear majority of participants favored the AI impersonators for coherence and relevance, and more than half rated the chatbot as more authentic than the person.
Startup sues Palo Alto Networks’ Koi Security, saying an AI-hallucinated report falsely linked it to Chinese espionage - It accuses Koi of “reckless publication of an AI-driven cybersecurity report that falsely accused Plaintiff MeetingTV Inc. of criminal conduct including operating core infrastructure for a well-funded Chinese criminal organization running a large-scale malware and corporate espionage campaign." Koi’s blog, which has since been silently edited to remove references to MeetingTV’s product called Zoomcorder, originally labeled the meeting recording service as a “public-facing front” for a Chinese criminal operation and said it lent “credibility to the infrastructure while serving as a monetization channel” - allegations MeetingTV disputes in its lawsuit. The blog also claimed the operation was behind a 2.2-million-user campaign stealing corporate meeting intelligence.
US Gov
US government says it got hacked — again | TechCrunch - The hackers reportedly broke into Homeland Security Information Network servers during late May and early June, potentially exposing information shared using the platform, per Nextgov. A previously reported security lapse during 2023 revealed that HSIN contained personal information shared among law enforcement related to the surveillance of Americans. Currently, the platform is being used to manage the world cup and last year was used for the American Airlines/Army Helicopter collision in Washington D.C.
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker - Investigators worked back to Stokes from the device that opened the ngrok account. Microsoft told the FBI it carried Global Device Identifier g:6755467234350028, which Microsoft describes as a persistent identifier tied to a single Windows installation, one that survives operating-system updates but changes when Windows is reinstalled. The complaint shows an operator who hid the attack, behind a VPN proxy, tunneling tools, and aliases, but not himself.
GitHub - SmtimesIWndr/gdid-reversal · GitHub - The GDID exists because your device is registered into the Microsoft Account device graph and the Connected Devices Platform keeps it synced. To cut it back:
- Kill the Connected Devices Platform (
CDPSvc,CDPUserSvc) and turn off Activity History (Settings, Privacy, Activity history) to stop the graph sync and the activity uploads. - Deleting
%LOCALAPPDATA%\ConnectedDevicesPlatformonly wipes local CDP state. The PUID comes right back from the identity store, so that alone won’t cut it. - A reinstall gives you a new GDID (the complaint says so), but it gets tied to a fresh one the second it registers again.
Author’s Note: Most Linux options are privacy respecting by default, and a majority of normal users can replace their windows systems with linux systems without much friction. Users of specialized windows applications may have more issues, though windows emulation software is quite good at this point. Including gaming setups that don’t require anti-cheat.
Errata
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices - Here is the hard part. FatFs is maintained by one developer in a small corner of the internet, and runZero says it tried repeatedly to reach the maintainer and looped in Japan’s JPCERT/CC coordination center, with no response. The flaws matter because FatFs is nearly everywhere. It ships inside the firmware that runs security cameras, drones, industrial controllers, hardware crypto wallets, and other devices built on real-time operating systems. On the worst-affected systems, an attacker who gets a booby-trapped USB drive, SD card, or update file onto a device can corrupt its memory and run their own code.
Author’s Note: Relevant XKCD - Dependency
Newly discovered PamStealer isn’t your typical macOS malware - Ars Technica - If the validation fails, PamStealer displays the prompts again until it receives the correct one. Once the target enters the correct password, PamStealer displays a message stating that the file is damaged and can’t be installed. This is designed to be a decoy to prevent the target from suspecting anything is amiss.
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems - The practical concern is any x86 environment that hosts untrusted guests with nested virtualization enabled. An attacker who rents a single such instance can panic the host, taking down every other tenant VM on the same physical machine.
Opera rolls out Paste Protect feature to fight ClickFix attacks - When Paste Protect detects suspicious clipboard content, it blocks the copy operation, displays a warning, and shows a red security indicator in the browser’s address bar. Users will be given a 120 character preview of the blocked script and a 5-second pause before they can approve the paste.
New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions - TrojPix works only once malware is already on the target machine, so it is a way for stolen data to get out, not a way in. In the researchers’ tests, TrojPix hit a peak throughput of 8.1 Mbps and reached as far as 208 meters, the two measured separately rather than together.
Confidential computing’s core trust mechanism is broken. The fix may not exist - The intended server has done nothing wrong. The attacker simply exploits the fact that the protocol checks the software’s integrity, not its location.
Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices - To build that pool, operators need their code running on home devices. Some devices ship with it pre-installed on cheap off-brand hardware; others pick it up when someone installs a free app that hides it. Once it is running, the device becomes an “exit node,” a doorway that other people’s traffic flows through.
- Stick to official app stores, and check what permissions a VPN or proxy app is asking for.
- Keep built-in protections like Google Play Protect switched on.
- Buy streaming boxes and smart TV hardware from known manufacturers, not no-name brands.
Apple ‘Hide My Email’ Vulnerability Reveals Peoples’ Real Email Addresses - ”Apple Hide My Email is leaking email addresses that are supposed to be hidden. We reported the issue and replication instructions to Apple over a year ago. We don’t know why it hasn’t been fixed, but we don’t feel comfortable waiting any longer. Hide My Email users deserve to know that it may be possible for attackers to discover their hidden email addresses,
Dev says Google warned him about account hijack – then charged him $11,000 anyway - The notification advised Jones to report his concerns if he believed the account was compromised by a third party. He did so and took the steps required by Google to have his account reinstated. He disabled the service account and revoked the key. But the Google Cloud billing team has repeatedly refused to forgive the charges. At the same time, Google still hasn’t publicly released a mechanism to cap Google Cloud spending. (Some spending cap testing is being done in private preview) At the same time the company said that spend caps have a 10 minute delay and customers are responsible for spending during that period – so the company’s definition of cap is rather flexible. What’s more, Google said its system “now automatically upgrades you to the next [usage] tier as your usage grows and your payment history matures.” And higher tiers raise spending caps. (Some spending cap testing is being done in private preview)
Politician who investigated spyware abuses had his phone hacked with Pegasus spyware | TechCrunch - While spyware attacks on lawmakers are rare, the timing and targeting of a committee investigator by way of the very spyware under his investigation suggests an intense focus on the committee’s inner workings ahead of a widely anticipated report detailing its findings