AI
Frontier AI labs still won’t say how they’d contain a rogue model | TechCrunch - Guidelight’s assessment was based on publicly available plans from Anthropic, Google, OpenAI, Meta, and xAI, graded across a range of metrics, including how well each company logs and monitors what its AI systems are doing internally, whether it halts systems after a surge of flagged misbehavior, whether independent third parties audit its controls and publish findings, and what its exact plan is for containing a model that goes off the rails.
OpenAI’s overhead will rise 20 percent for some workloads as it hardens security - An OpenAI spokesperson told The Register that those costs reflect internal research and won’t be passed on directly to customers. The company has not revealed what portion of its total inference compute is subject to such monitoring now, or under its prior monitoring regime.
Alabama launches investigation into OpenAI’s hack of Hugging Face | TechCrunch - The press release announcing the subpoena sent by the state’s attorney general Steve Marshall said that the state was seeking to understand if OpenAI’s “inability or unwillingness to ensure the safety of its products” violated the state’s consumer protection laws. 13 other states have also sent letters instructing OpenAI to retain documentation and conversations related to the hack.
AI “Mind Viruses” Can Spread Between Agents Through Persistent Prompt Files - Over 20-hop runs in which every file except SOUL.md was wiped at each step, all four action payloads survived to the final hop. Some strains recovered at hop 20 went on to infect new agents more often than the original payload did, having picked up changes such as attributing the protocol to an earlier named agent or softening its imperative language.
Grok chat duped into swallowing injected instructions - “An attacker ships ciphertext along with the key material and an instruction to decrypt it, and the model runs that decryption inside its own code execution sandbox,” wrote Rony Utevsky, lead researcher at Adversa AI, in a blog post. “Everything a guardrail’s scanner would need is right there on the page, but recovering the plaintext means running PBKDF2 and AES-256-GCM, which no content classifier does at inspection time.”
Additional info: Grok exfiltrates user data when malicious instructions are encrypted - Ars Technica Crooks push Mac malware through fake OpenAI Codex ads - Google search results targeting people looking to download Codex for macOS. The ads direct would-be users to a convincing-looking download page hosted on Google Sites, complete with the familiar OpenAI branding. The fake site tells Mac users to open Terminal, paste in a supplied command, and run it. The instructions are dressed up as part of the installation process, but the command quietly kicks off a multi-stage malware infection.
USG
Senator asks US government watchdog to review how feds use hacking tools | TechCrunch - Wyden is making several requests to the GAO:
- Investigate whether agents abused hacking tools and spyware for unauthorized or personal purposes, and to check what technical and oversight measures are in place to control and prevent misuse;
- Review how agencies “acquire, store, and secure” these tools to avoid dangerous leaks, as well as whether they submit them to a program designed to determine if the U.S. government should report security flaws to help tech companies fix them;
- And, assess how the feds inform courts when requesting warrants for the use of these tools, and whether they disclose the risk of affecting unknown or innocent targets.
Flock surveillance backlash mounts as fiendish Halloween plans circulate - X grouped posts about the so-called “De-Flock America” campaign into a dedicated trending story, which recorded more than 36,500 posts over two days. Similar calls have appeared on other major social platforms. (Participants are planning to dress up for Halloween, leave phones at home, and disable as many ALPRs as possible.)
Iran-linked cyberattack shut down a UK power plant - A suspected Iran-linked cyberattack shut down a small UK power plant around the time that a series of digital intrusions disrupted American water utilities across 12 states. The incident shut down the power plant for four days in what is believed to be the first disruptive Iranian cyberattack of its kind in the UK.
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands - “A web GUI used to drive spacecraft and instrument commanding shipped a server that listens on every network interface, asks nobody for a password, and can be steered by any web page an operator happens to open,” Yuval Elbar, a security researcher at Cycode, said.
CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw - Successful attacks targeting CVE-2026-21962 can allow miscreants to create, delete, or modify access to critical data, and even gain “complete access” to all data stored on the affected systems.
Apple
Apple plugs image-processing hole ripe for spyware abuse - The bug affects macOS Tahoe, iPhone 11 and later, and supported iPad Pro, iPad Air, iPad, and iPad mini models. “Image parsing flaws have historically been the delivery mechanism for zero-click spyware targeting executives and other high-value individuals.” and this one is no different.
Researcher tricks Apple’s Find My into sharing location data with Linux - It’s important to note, at this point, that this is not an exploit that allows anyone to arbitrarily retrieve any Apple user’s location. It refers to registering a non-Apple device to the Find My network and retrieving the location data of people who had already chosen to share their locations with the Apple account owner.
Networking
Comcast gives its Wi-Fi motion detector a security makeover - The telco also assured customers that WiFi Motion does not track individuals or their precise movements, and cannot identify specific people. It added that it “does not monitor motion and/or notifications generated by the service.” Comcast states: “Subject to applicable law, Comcast may disclose information generated by your WiFi Motion to third parties without further notice to you in connection with any law enforcement investigation or proceeding, any dispute to which Comcast is a party, or pursuant to a court order or subpoena.”
(Why they always lying: Ordinary WiFi can now identify people with near perfect accuracy | ScienceDaily ) - “However, the omnipresent wireless networks might become a nearly comprehensive surveillance infrastructure with one concerning property: they are invisible and raise no suspicion.”
Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5. - Cisco offers Secure Workload Software as a SaaS-y service and for on-prem deployment. The company has fixed the flaws with its SaaS, but users still need to upgrade the Agent and Connector tools needed to use the cloudy software.
Unpatched Calix flaw lets hackers bypass NAT to expose internal devices - An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet.
New Evooo1Bot Linux botnet turns routers into traffic relay nodes - “While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities,” Fortinet researchers found. Newer builds include a separate vulnerability-exploitation module targeting Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations.
CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification - Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up to 350x against the origin server.
TTPs
US Bank investigates LockBit’s claims as ransomware crims set pay-or-leak deadline - US Bank says that it’s investigating ransomware crew LockBit’s claims that it breached the financial institution and stole data, which the crims threaten to leak on September 3 unless the bank pays an extortion demand. “We have investigated this matter and the available evidence indicates that the claim regarding a potential cyber incident is related to a fourth party event that occurred outside of our environment….”
Expired credit cards revived by researchers to make unauthorized payments - This leaves an opening for unwanted intermediary interference, which requires only the necessary knowledge and mobile phones acting as NFC proxies. And indeed, the researchers demonstrated that they could meddle in a way that revives expired contactless payment cards to make purchases.
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices - The malware, besides targeting sensitive applications and enabling extensive device takeover, introduces a novel Wi‑Fi mesh technique that makes it possible for the infected devices to relay data through nearby compromised devices with internet access. It’s distributed via phishing sites and dropper apps impersonating utilities.
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands - the FTP banner at “157.254.194[.]31:21” utilizes a multi-stage delivery chain that fetches a second FTP banner from “167.148.41[.]164:21,” which executes PowerShell to download, extract, and run a binary from a ZIP archive. The end goal of the attack is to deliver E4del, a Node.js-based RAT that’s embedded within a digitally signed Electron application masquerading as Discord.
Hackers infect Android car head units with proxy botnet malware - Kaspersky says the malware does not interfere with driving or critical vehicle control systems, and appears designed for advertising fraud and turning internet-connected car head units into residential proxy nodes for monetization purposes.
Hundreds of leaked AWS keys give full control over corporate accounts - Truffle Security has been tracking this exposure for the past four years and says that 817 of the exposed keys were linked to companies, 526 of them being AWS root keys. According to the researchers, 242 of the keys are associated with Identity and Access Management (IAM) users with the AdministratorAccess policy. This role has full permissions to create, modify, delete, and view virtually all AWS services and resources within an account. They note that each key of the 768 live keys in the two sets “full control of a company’s AWS account.”
Errata
Brand Hype Has Existed Since the Bronze Age, Scientists Discover - This brand of pottery was popular in what is now Saudi Arabia during the Bronze Age. The tradition is distinguished by distinctive black-and-red geometric designs and stylized animal and human figures. These unique visual properties, along with a consistent production technique and quality, suggest that it was an early branded commodity that was made to be recognizable to the wider community.
Security vets rally around $4 paper password books for sale in Australia - The general consensus, gleaned from the hundreds of social media comments on the post, now seems to be that there’s little wrong with storing passwords on paper at home. It’s certainly more secure than reusing the same weak password across multiple accounts, provided the book contains strong strings unique to each website. With the prevalence of infostealers nowadays, it’s far more likely that crims will use a weak, reused, seldom-changed password to break into an online account than burgle a house to gain access to someone’s online banking.
How a Network of Volunteers Is Liberating Critical Court Records for Everyone - A new project called Habeas Dockets is working to counteract this roadblock with help from volunteers. According to the project’s founder, 400 people across the country have contributed court records to the site, which publishes habeas corpus filings online for anyone to read them.