Cybersecurity
Vulnerabilities, ransomware, CVEs, pentesting, OSINT and the latest in information security.
38 published articles
Cyber espionage
Hotel Wi-Fi is the SVR's new espionage front door
Microsoft links the CaptiveCrunch campaign to Storm-2945, an SVR-affiliated Midnight Blizzard sub-cluster that compromised hotel Wi-Fi portals worldwide to deliver malware and steal corporate credentials through fake sign-in pages and update prompts.
2026-07-30
Cybersecurity AI
Microsoft's MAI-Cyber-1-Flash delivers top CyberGym scores at half the cost
Microsoft's new MAI-Cyber-1-Flash model, integrated into the MDASH harness, promises frontier-level vulnerability detection at half the cost. The company says the system outperforms Mythos, Gemini, and GPT on the CyberGym benchmark.
2026-07-29
Model Security: Specialists vs. Generalists
Why the Best General AI Model Keeps Losing to Narrower Ones on Security
Claude Opus 5's deliberately capped cybersecurity skills, Alibaba's in-session code review, and a new zero-query model-theft technique together show AI security fragmenting into specialized layers rather than converging on one trustworthy general model.
2026-07-28
FCC vs. DJI front companies
The FCC is about to retroactively ban DJI front companies, and that changes the rules for every imported gadget
The FCC is preparing to retroactively ban disguised DJI products sold by front companies like Xtra and Skyrover, marking the first time it has wielded this power. A $25,000 fine was already proposed. Public comments are open for 30 days, but the real question is whether the FCC will use this test case to change the rules for every imported gadget.
2026-07-28
Side-Channel Attack Steals Cloud AI Models
Model Stealing Attacks on Cloud-Based AI: A New Zero-Query Trojan Method Emerges
A new zero-query attack method called 'Zero-Query Model Stealing' allows adversaries to steal proprietary AI models from cloud APIs without sending any queries, using side-channel information from timing and memory patterns. This raises serious cybersecurity concerns for AI-as-a-service providers.
2026-07-27
DJI front companies
The shadow world of DJI clones is collapsing, and the FCC still won't explain why
Xtra Technology has stopped selling its latest DJI camera clone and is refunding preorders after the FCC proposed fines and retroactive bans. The case highlights a regulatory enforcement campaign built on a national security claim the government has never shared with the public.
2026-07-27
Penetration Testing
Sakana's Fugu-Cyber finds the vulnerabilities Claude Opus 5 was designed to miss
Anthropic capped Claude Opus 5's security skills. Specialized models like Google's Gemini 3.5 Flash Cyber and Sakana's Fugu-Cyber outperform it in vulnerability discovery. A case for testing alternatives before renewing enterprise licenses.
2026-07-26
Cybersecurity
The wiper that bundles three flavors of destruction into a single backdoor
Microsoft found a Golang backdoor that packs three separate malware families into one implant. GigaWiper can wipe disks, encrypt files without decrypting, and maintain full remote access from a single binary.
2026-07-26
AI Coding Security
The blind spot in AI-generated code that Alibaba fixes mid-sentence
Alibaba's in-session code review catches vulnerabilities before they reach the repo, but the real test is whether developers will let it run.
2026-07-26
Cybersecurity
Two new CISA alerts, one hard question: did they get in before you patched?
CISA adds CVE-2026-16232 (Check Point SmartConsole) and CVE-2026-50522 (Microsoft SharePoint) to its KEV catalog. Under BOD 26-04, agencies must now check for pre-patch compromises and prioritize by risk, making breach detection just as critical as patching speed.
2026-07-25
Cybersecurity
Google's cheap fine-tune found vulnerabilities that Claude Opus 4.6 missed
Google's lightweight Gemini 3.5 Flash Cyber fine-tune outperforms Anthropic's largest model in vulnerability discovery, finding 55 unique issues in the V8 engine versus 36 for Claude Opus 4.6. The model is locked to governments via a limited pilot.
2026-07-24
Cybersecurity
Anthropic's new security tool treats your code like a researcher would, then suggests fixes
Anthropic's Claude Security scans codebases for vulnerabilities, validates findings with an adversarial pass, and suggests patches without leaving your workflow.
2026-07-22