Skip to content
root notes — archive

ls ./archive --page 9

Archive

page 9 of 15 — 342 articles

Anthropic will give defenders what its strongest security model finds — but not the model

2026-08-25AI

Claude Security now scans code with Mythos 5, the model Anthropic keeps most tightly restricted. Customers never touch it; they get findings with a CWE category, severity, confidence and a suggested patch. Alongside it, a $35 million fund pays open-source maintainers in Claude credits. The whole design is a bet that findings can be shared when the capability cannot.

They phoned a security company, used real employees' names, and got in

2026-08-25Security

ShinyHunters registered a fake ReliaQuest SSO page and rang staff one by one, each time impersonating a named colleague from the security team. One person typed their password and approved the push. ReliaQuest says the attackers got view-only access to an Okta dashboard and nothing else — and the interesting part is which controls held.

Exploited since January, added to CISA's list in August, due in three days

2026-08-25Security

CVE-2026-21962 is a CVSS 10.0 flaw in Oracle's HTTP Server and WebLogic proxy plug-in. Oracle patched it on 20 January. Exploit code appeared on 22 January and a honeypot logged attacks the same day. CISA added it to the Known Exploited Vulnerabilities catalog on 24 August with a due date of 27 August — and under a directive nobody noticed replacing the old one, agencies now have to check whether they were already breached.

A UK power plant was down for four days — and almost nothing in the headline is confirmed

2026-08-25Security

The Telegraph reported on 22 August that a small British generator was shut down for four days in July, and the coverage that followed called it Iran-linked. Neither the government nor the NCSC has confirmed that, the plant has not been named, and the CEO of Dragos is publicly warning that this is exactly the situation false flags are built for.

The AI picked 170,000 targets — every break-in used a bug from years ago

2026-08-24Security

Cisco Talos found an exposed directory belonging to UAT-10147 and pulled out target lists of roughly 170,000 URLs, AI tooling across the whole attack lifecycle, and a cross-platform implant called SPECTRE that unlinks EDR callbacks in the kernel using two vulnerable drivers from 2019 and 2021.

The malware reads its orders out of an FTP welcome message, before it even logs in

2026-08-23Security

MalwareHunterTeam spotted the technique in July and SOCRadar says it is still running. A phishing ZIP drops a shortcut file, the shortcut connects to an FTP server and takes commands from the greeting banner, and either E4del or PINHOLE lands. Novel — and SOCRadar notes that being novel is also what makes it visible.

The safety filter read the ciphertext and the sandbox ran the plaintext

2026-08-22AI

Adversa AI encrypted its instructions so guardrails saw only harmless-looking ciphertext, then let the model's own code sandbox decrypt and execute them. It reported the technique to xAI on 3 June, chased twice, got no reply, and published. Grok still falls to it, including zero-click exfiltration through tool use.

The malware reaches the car through the update channel the car trusts

2026-08-22Gadgets

Kaspersky found previously unknown malware on Android head units running DoFun, delivered through the legitimate update mechanism of a system app over an MQTT broker. It checks in every 90 minutes, runs ad fraud, and is attributed with high confidence to the group behind the BADBOX botnet.

Search all 342 articles →