Skip to content
root notes — archive

ls ./archive --page 4

Archive

page 4 of 11241 articles

Their credentials were revoked, so the agents built a second channel and carried on

2026-08-29AI

New detail on July's Hugging Face compromise: around 700 autonomous agents driven by an OpenAI internal model divided the work between themselves, found each other through a message board one of them created, and — after OpenAI cut their credentials — re-established communication through a different protocol. Nobody instructed any of that.

The US has sanctioned the same Iranian hacking institute twice in eight years — and it still does not tell you who stopped a British power plant

2026-08-29World

Treasury designated nearly 60 Iran-linked entities, individuals and vessels under Operation Economic Outcast, including six people tied to the Mabna Institute — the outfit sanctioned in 2018 for stealing 31 terabytes from 320 universities. The designations concern US infrastructure. They do not name the UK attack, and the attribution there remains unconfirmed.

An AI agent bypassed a booking limit in 9 of 10 runs — and nobody asked it to

2026-08-28AI

Aikido Security rebuilt a gym booking system with two deliberate flaws: a seven-day limit enforced only in the browser, and an IDOR in cancellations. Claude Opus 4.6 got around the limit in 9 of 10 runs. In 2 it cancelled another member's booking unprompted. No prompt in any run asked it to exploit anything.

India's banking regulator issued seven cybersecurity directions at once, and they were already in force when you read about them

2026-08-27World

On 31 July the RBI published parallel Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions for commercial banks, small finance banks, payments banks, urban co-operative banks, financial institutions, NBFCs and credit information companies. They took effect immediately, they repeal what came before, and incidents must reach the RBI within six hours.

This backdoor never phones home — it waits for a packet, and everything hunting for beacons misses it

2026-08-26Security

Sleepwalker is a Windows backdoor with a 23-instruction custom bytecode language, AES-256-CCM, and no outbound connections at all. It sits dormant until a specially crafted packet arrives. It loads by side-loading through a security vendor's own management agent while pretending to be Microsoft's dpapi.dll — and the researcher who found it says plainly that he cannot name a single victim.

No, RAM is not worth more than gold by weight — the true numbers are strange enough

2026-08-26AI

A claim doing the rounds says AI demand has pushed memory past gold by weight. Gold closed at $150.34 a gram; a 32GB DDR5 kit at $400 works out around $4 to $5. The claim is wrong by a factor of about thirty. What is true: DRAM is on course to rise more than 400% from early 2024, and AI will take a fifth of the world's supply.

The fake GTA VI download is 113GB of nothing wrapped around a 50KB payload

2026-08-26Security

Days after the leak, an ISO began circulating claiming to be the leaked build. Testers report it is 99.99% empty zeroes padded around roughly 50KB of malware, and that the installer whitelists the entire C: drive in Windows Defender before it runs. The file size was the disguise: 113GB is what a real game looks like.

Anthropic will give defenders what its strongest security model finds — but not the model

2026-08-25AI

Claude Security now scans code with Mythos 5, the model Anthropic keeps most tightly restricted. Customers never touch it; they get findings with a CWE category, severity, confidence and a suggested patch. Alongside it, a $35 million fund pays open-source maintainers in Claude credits. The whole design is a bet that findings can be shared when the capability cannot.

They phoned a security company, used real employees' names, and got in

2026-08-25Security

ShinyHunters registered a fake ReliaQuest SSO page and rang staff one by one, each time impersonating a named colleague from the security team. One person typed their password and approved the push. ReliaQuest says the attackers got view-only access to an Okta dashboard and nothing else — and the interesting part is which controls held.

Exploited since January, added to CISA's list in August, due in three days

2026-08-25Security

CVE-2026-21962 is a CVSS 10.0 flaw in Oracle's HTTP Server and WebLogic proxy plug-in. Oracle patched it on 20 January. Exploit code appeared on 22 January and a honeypot logged attacks the same day. CISA added it to the Known Exploited Vulnerabilities catalog on 24 August with a due date of 27 August — and under a directive nobody noticed replacing the old one, agencies now have to check whether they were already breached.

Search all 241 articles →