Skip to content
root notes — archive

ls ./archive --page 5

Archive

page 5 of 11241 articles

A UK power plant was down for four days — and almost nothing in the headline is confirmed

2026-08-25Security

The Telegraph reported on 22 August that a small British generator was shut down for four days in July, and the coverage that followed called it Iran-linked. Neither the government nor the NCSC has confirmed that, the plant has not been named, and the CEO of Dragos is publicly warning that this is exactly the situation false flags are built for.

The AI picked 170,000 targets — every break-in used a bug from years ago

2026-08-24Security

Cisco Talos found an exposed directory belonging to UAT-10147 and pulled out target lists of roughly 170,000 URLs, AI tooling across the whole attack lifecycle, and a cross-platform implant called SPECTRE that unlinks EDR callbacks in the kernel using two vulnerable drivers from 2019 and 2021.

The malware reads its orders out of an FTP welcome message, before it even logs in

2026-08-23Security

MalwareHunterTeam spotted the technique in July and SOCRadar says it is still running. A phishing ZIP drops a shortcut file, the shortcut connects to an FTP server and takes commands from the greeting banner, and either E4del or PINHOLE lands. Novel — and SOCRadar notes that being novel is also what makes it visible.

The safety filter read the ciphertext and the sandbox ran the plaintext

2026-08-22AI

Adversa AI encrypted its instructions so guardrails saw only harmless-looking ciphertext, then let the model's own code sandbox decrypt and execute them. It reported the technique to xAI on 3 June, chased twice, got no reply, and published. Grok still falls to it, including zero-click exfiltration through tool use.

The malware reaches the car through the update channel the car trusts

2026-08-22Gadgets

Kaspersky found previously unknown malware on Android head units running DoFun, delivered through the legitimate update mechanism of a system app over an MQTT broker. It checks in every 90 minutes, runs ad fraud, and is attributed with high confidence to the group behind the BADBOX botnet.

Search all 241 articles →