Sign in

Matthias Schulze

@percepticon.bsky.social
877 followers 313 following 2.5K posts

PhD in political science, studying infosec, cyber conflict & information war. Blue Team at SRLabs in Berlin. Blog and podcast about my work over at percepticon.de or ioc.exchange/@percepticon

PostsRepliesMedia
Matthias Schulze @percepticon.bsky.social · 2h
Claude Mythos only model to complete full cyber kill chain, experts say #cybersecurity #infosec
theregister.com
Claude Mythos only model to complete full cyber kill chain, experts say
Despite what we saw with OpenAI’s models going rogue, creating message boards, and breaking into Hugging Face, only one advanced AI model - Anthropic’s Claude Mythos - completed the full cyber kill chain autonomously in Booz Allen’s tests. This doesn’t mean autonomous AI attacks are overhyped. And we should point out that the models tested don’t include OpenAI’s soon-to-be-released Astra, which OpenAI on Tuesday said reached its “critical” cybersecurity capability threshold. This means the new model is so good at finding and exploiting zero-day bugs that it poses a significant risk to critical systems, both from malicious users and even from the model itself, which is capable of carrying out harmful cyber actions “if misaligned.” Booz Allen asserts that most of the other 17 US and Chinese models it tested will achieve Mythos’ same level of weaponization within six months, and it calls mainstream AI attacks from both financially motivated criminals like ransomware gangs and government-backed goons “imminent.” In its first-ever Cyber Weapon Index, the consulting and tech firm calls on the US to set and enforce sector-specific deadlines for critical infrastructure to demonstrate resilience against AI-enabled attacks. Booz Allen also calls on the US to develop what it calls “overmatch” for both cyber offense and defense. “We must aggressively develop agentic capabilities that accelerate authorized offensive cyber operations while simultaneously building AI-enabled defenses that detect, decide, and respond at machine speed,” the report says. “The strategic opportunity is to master both - giving the United States the ability to impose costs on adversaries while making US systems faster to defend, harder to compromise, and more resilient when attacked.” The Cyber Weapon Index evaluated 18 models, nine from American and nine from Chinese developers, under identical conditions, and scored them on how well they autonomously identify vulnerabilities, create offensive capabilities, and execute attacks. Each model’s CWI score combines its vulnerability research score (VRS), which measures whether a model can identify planted and/or novel vulnerabilities, and a kill chain attainment score (KCAS), which awards points based on how far a model progresses through an end-to-end intrusion, tested both with and without credentials. Cyber Weapon Index scores The 18 models, ranked from highest to lowest based on their CWI score, are: Anthropic’s Claude Mythos (80), xAI’s Grok-4.5 (49), OpenAI’s GPT-5.6 Sol (46), Meta’s Muse Spark 1.1 (38), Moonshot AI’s Kimi K3 (38), Z.ai’s GLM-5.2 (37), Anthropic’s Claude Opus 4.8 (36), OpenAI’s GPT-5.5-Cyber (34), Nvidia’s Nemotron-Ultra (33), DeepSeek-V4-Pro (23), DeepSeek-V4-Flash (17), Alibaba’s Qwen3.5-397B (17), MiniMax-M3 (15), Nvidia’s Nemotron-Super (15), Anthropic’s Claude Sonnet 5 (13), Z.ai’s GLM-4.5-Air (11), Alibaba’s Qwen3.6-35B (9), and Alibaba’s Qwen3-Coder (4). Claude Mythos’ performance was especially impressive or concerning, depending on one’s views of autonomous AI attacks. When the testers gave the model stolen employee credentials, it successfully broke into its target network and gained administrator-level control in every attempt. Plus, it independently identified how to gain higher-level access based on what it found within the network - not by following a predetermined attack plan. Even without credentials, Claude Mythos still gained access to the network and ultimately achieved full domain compromise. While only Claude Mythos executed the entire cyber kill chain without any human assistance, three other models - Grok-4.5, Muse Spark 1.1, and GLM-5.2 - reached full domain access and control. Four others - GPT-5.6 Sol, Kimi K3, GPT-5.5-Cyber, and DeepSeek-V4-Pro - achieved lateral movement across the controlled network environment. Claude Opus 4.8 and Qwen3.5-397B obtained credentials, which allowed the models to expand access and privileges. And all but one - Qwen3-Coder - autonomously gained initial access to the network. While advanced models are exceedingly good at offensive cyber capabilities, “their real-world impact depends heavily on the vulnerabilities they face and the systems built around them,” according to the report. When the testers intentionally introduced vulnerabilities, US, Chinese, open-weight, and closed models all scored near ceiling on the VRS component. When tested against real bugs, however, all nine of the frontier API models scored zero. One unnamed leading model even correctly analyzed the vulnerable component, but then dismissed it as safe. Only Claude Mythos exploited it. “That concentration of capability creates a national-security imperative: protect the most advanced models and prevent their highest-risk cyber capabilities from being operationalized by adversaries,” the authors wrote. This is one of the areas where defenders still have an opportunity to outpace the attackers, Booz Allen suggests: “Real-world offensive capability still trails benchmark performance, giving defenders valuable time to strengthen defenses before that gap closes.” Why attack harnesses matter Another interesting finding is that the attack harness matters at least as much as, if not more than, the model itself. The attack harness - this is the software that connects a model to hacking tools and the orchestration logic wrapped around the artificial intelligence model to automate offensive cyber actions - can “dramatically amplify” the model’s ability to stay focused, adapt and change course as needed, recover from failure, and chain individual actions into a multi-stage attack, the authors found. “The result is not a ‘smarter’ model but rather a system that makes its intelligence far more actionable while also lowering the expertise required to use it,” the report says. “Our testing demonstrates the effect: when paired with an attack harness, Claude Sonnet rivaled Claude Mythos’ performance.” However, it also exposes a blind spot, they note. “We do not yet know the full kill-chain capability of open-weight or Chinese models when paired with optimized harnesses, but our results strongly suggest that fully capable model-and-harness combinations exist today,” according to Booz Allen. Similarly, the index’s findings suggest that Chinese frontier and open-weight models, while still trailing leading American frontier models, aren’t that far behind in their offensive security skills and could be deployed in real-world attacks. This means “the United States may neither control nor fully understand the capabilities it could face,” the report says. “And, as cyber agents become more autonomous, defenders must prepare not only for deliberate attacks but for agents that exceed their intended mission or continue operating beyond an adversary’s control.”®
030
Matthias Schulze @percepticon.bsky.social · 6h
To keep the AI hacking genie bottled up, try one-way networks #cybersecurity #infosec
theregister.com
To keep the AI hacking genie bottled up, try one-way networks
To prevent frontier AI models breaking out of test environments and collaborating to hack other companies, we may have to rethink the network architectures used for model training. Eli-Shaoul Khedouri, CEO of Intuition Machines, argues that past work in the defense and intelligence communities shows the way forward. Rogue AI models rise from the level of developer regret to mass threat when they gain access to the internet, something that defenses erected by OpenAI and its partners tried but failed to prevent. Pointing to a post published by his company's hCaptcha service, Khedouri argues that technology like data diodes – hardware that enforces a one-way flow of information on a network – can be deployed to prevent security incidents like OpenAI's hack of Hugging Face. The hCaptcha team points to the use of data diodes as a data transit mechanism at a sensitive compartmented information facility (SCIF), an environment implemented in classified settings. "They allow files, logs, or telemetry to enter or exit the SCIF's classified network to an unclassified network and provide a way to prove e.g. that logs from a training run can only flow one way," the hCaptcha team explains, adding that such technology fits with the Bell-LaPadula security architecture designed for the US Defense Department. A basic implementation would involve two machines connected via network cards linked by one-way optical fiber – and without a data path back to the model. Training and reinforcement learning could run in an isolated zone with no internet access and an optical ingress diode would grant access only to vetted artifacts. The hCaptcha researchers suggest a second diode to send telemetry to a sel4 receiver and scrubber, while a separate out-of-band network manages the cluster. This sort of scheme would require immutable snapshots of software registries like PyPI, GitHub, npm, and might also need mocked versions of various web services and APIs . This would come at a cost, and would require implementation time that frontier AI labs may not be prepared to spend at the moment. "The systems described are widely deployed in high assurance domains, and the components are commercially available," Khedouri told The Register. "However, they have not been adopted by frontier labs to date." He pointed to NIST and DOD guidelines [PDF] that suggest an overhead of 10 to 20 percent for applying formal specifications and system architecture. "We estimate total cost overhead for high assurance training clusters at less than five percent per gigawatt, but in practice the speed at which frontier labs are moving is a greater impediment than cost," Khedouri said. The current commercial environment, he said, would make it difficult for any one AI lab to delay its training to build and test effective safeguards, particularly if their competitors might not do the same. "In practice, the cost of high assurance on the systems side would be a small fraction of what OpenAI is now spending on the new monitoring, chain-of-thought oversight, and safety safeguards they introduced after their models hacked HuggingFace," he said. While Khedouri is focused primarily on convincing frontier labs to implement better training defenses, he said other organizations may want to consider similar network architecture. "This architecture is designed for entities training models with frontier cyber capabilities," he said. "Recently that has only included two companies. However, this is rapidly becoming relevant to smaller organizations and individuals who train models. "'Abliterated' open weight models with safeguards removed are readily available and now starting to approach the frontier in cyber abilities, and (reinforcement learning) RL post-training has become much more approachable in the past year." The goal of high assurance system design in the context of model training is to make unwanted action physically impossible, Khedouri said. "Attempting to monitor the behavior of an untrustworthy agent is an AGI-hard problem, as models have poor interpretability and this appears to be getting worse as their capabilities increase and they become more evaluation-aware," he said. "Hardware can provide limited guarantees like the direction in which data can be sent, but cannot solve the problem of untrustworthy models with the ability to reach the internet and find new exploits in their environment. "This is why combining physical one-way data flows (data diodes) and formal verification (to prove properties of the receiver) is much more effective than running a software sandbox on a host connected to the internet." hCaptcha is focused on fraud and abuse work and has no plan to offer a model-resistant training stack. Khedouri said he shared this advice in the hope it helps AI firms that don't have experience with high assurance system design. ®
120
Matthias Schulze @percepticon.bsky.social · 11h
Leaked Russian Cyber-Operations Training Materials #cybersecurity #infosec
schneier.com
Leaked Russian Cyber-Operations Training Materials
This is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security. […] The reporting also linked a 2024 Department No. 4 graduate, Aleksei Kondrashov, to Military Unit 74455, widely known as Sandworm. That unit has been associated with destructive cyber activity against Ukraine and other targets, including the 2017 NotPetya attack. The reports do not establish that every listed graduate participated in a named operation; assignments should therefore be described as reported unit placements, not proof of individual operational involvement. The Bauman material reframes Russia’s cyber capability as an institutional system, not merely a collection of well-known threat groups. It suggests that Moscow has formalized a recurring pathway from university recruitment to military service, where students receive supervised technical and ideological preparation before entering intelligence, cyber, and security roles. For defenders, the leak reinforces the need to track Russian operations as a combined threat: espionage, destructive activity, military reconnaissance, technical surveillance, and influence campaigns may draw on related personnel pipelines and overlapping doctrine. The exposure of Department No. 4 also provides researchers with a clearer lens for understanding how the GRU sustains cyber capacity beyond the familiar APT28 and Sandworm brand names.
021
Matthias Schulze @percepticon.bsky.social · 14h
Berlin Senate Passwort.docx Breach: Ahab of the East Sea Cover Story #cybersecurity #infosec
flyingpenguin.com
Berlin Senate Passwort.docx Breach: Ahab of the East Sea Cover Story
Russians are having a laugh about Ahab on the East Sea 1-2-3. And then there’s Sunshine 13. These were passwords disclosed in the Berlin Senate breach. The “Ahabostsee123”, is in fact a yacht for vacations in the Baltic. Much of the press seems to be wagging a finger about BSI recommendations, calling the passwords weak. … Continue reading Berlin Senate Passwort.docx Breach: Ahab of the East Sea Cover Story →
010
Matthias Schulze @percepticon.bsky.social · 22h
AI Doesn’t Mean the End of Mathematics—at Least Not Yet #cybersecurity #infosec
schneier.com
AI Doesn’t Mean the End of Mathematics—at Least Not Yet
This essay was written with Kasra Rafi, and originally appeared in The Guardian. Earlier this month, about 40 top mathematicians gathered at OpenAI’s offices to discuss the future of their profession. The meeting was off-the-record, but if recent articles by mathematicians are any guide, it was mostly pretty glum. People fear for their jobs, their careers and the work they love. We think the contrary view is more likely, at least in the short-term. AI models are nowhere near as capable as experienced academic mathematicians. This isn’t to say that AIs aren’t producing stunning mathematical results at the level of PhD researchers. In mid-May, OpenAI announced that its frontier AI model disproved the unit distance conjecture, a famous 80-year-old problem in discrete geometry. In July, Anthropic’s published two AI-derived results in academic cryptanalysis. Earlier this month, OpenAI published 10 new mathematical results from its latest AI model. And Anthropic published Claude’s attempt to prove the century-and-a-half-old Riemann hypothesis. These results are both a vivid demonstration of the amazing capabilities of frontier AI in 2026 and an illustration of their limitations. In general, these AI-powered advances in mathematics fall into one of two categories. Some are counterexamples to mathematical statements that people had been trying to prove. Others are novel applications of known techniques to existing problems that human experts either did not know or did not think of using. The counterexample to the Jacobian conjecture is the most notable example of the first kind. Once it had been found, checking it was quick and straightforward. The difficult part was finding it among a large number of possibilities. The AI seems to have combined some sort of intuition acquired through machine learning with extensive computational search, in order to find the right example. An example of the second kind is the unit-distance conjecture. It was motivated by an elegant construction, and most mathematicians expected it to be essentially optimal—so they generally tried to prove rather than disprove it. The counterexample brings in ideas from elsewhere in mathematics: algebraic number theory. If an expert with that background deliberately set out to find a counterexample, they would probably have succeeded. But there was no reason for someone with precisely that expertise to focus on this problem. Because of its scope, AIs don’t have those same limitations. These results are relatively low-hanging fruit for AI; none of them required developing an extensive new theory. This does not make the discoveries trivial, or the AI’s achievements less impressive. Choosing the right direction, and recognizing an unexpected connection between subjects, are themselves forms of creativity. They are the same sorts of capabilities that led to AIs playing the game of Go at the grandmaster level, or doing Nobel-prize level chemistry in the area of protein folding. What we have not yet seen is an AI developing a substantial new conceptual framework in order to solve a mathematical problem. Much of mathematics proceeds by identifying the objects that are truly central to a question and then developing a theory that helps us understand them. Current AIs are very strong at searching and recombining existing ideas, but they are weak at building any deep and sustained new theory. This speaks to a more general limitation of current AI systems. They are creative in the sense that they can recombine existing ideas in novel ways. But they are not creative in others: they have not yet developed conceptually new theories or structures. And while they have larger working memories than humans do, know more about more different things than any particular human does, and can process information faster than humans, can, true novelty is still largely beyond their reach. Of course, that distinction may not survive for very long. Predictions are notoriously hard, especially about the future of AI. None of these mathematical capabilities were explicitly designed for, or planned. They’re all emergent properties of increasingly capable AI models. We are both confident that someday we will see AI models that are capable of the type of creativity required to do novel mathematics. Will that be in a few months, a few years or a few decades? Of course we don’t know, but our guess is sooner rather than later.
010
Matthias Schulze @percepticon.bsky.social · 03/09/2026
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks #cybersecurity #infosec
bleepingcomputer.com
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]
011
Matthias Schulze @percepticon.bsky.social · 03/09/2026
OpenAI-led coalition warns AI will compress cyberattack timelines, expose enterprise weaknesses #cybersecurity #infosec
csoonline.com
OpenAI-led coalition warns AI will compress cyberattack timelines, expose enterprise weaknesses
A coalition led by OpenAI is warning that AI will sharply accelerate the speed and scale of cyberattacks, leaving enterprises with a narrowing window to fix long-standing security weaknesses before they are exploited. “In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable,” the group said in an open letter signed by more than 100 technology and cybersecurity firms, including Microsoft, Google, Amazon Web Services, and Anthropic. “We have a limited window to strengthen cyber defenses.” OpenAI CEO Sam Altman reinforced the urgency in a post on X, calling it a “critically important moment for cyber defense” and warning that there is little time to act. The coalition called on “leaders across industry and government to bring the full weight of their technology, resources, and expertise” to the effort, including putting “cyber-capable AI in the hands of defenders” and prioritizing fixes for high-risk weaknesses. The coalition said the shift is not about new vulnerabilities, but about scale, which is about AI systems accelerating the discovery and exploitation of weaknesses that enterprises have struggled to fix for years. The letter comes weeks after AI developers, including OpenAI, Meta, and Anthropic, highlighted emerging behaviors in advanced AI systems that raised new questions about control and security. “Longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt… have left systems exposed,” the letter added. Attack timelines compress as AI scales exploitation The letter attributes the risk to the ability of AI systems to accelerate the discovery and exploitation of existing vulnerabilities. “Longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt… have left systems exposed,” the letter added. SpecterOps, a signatory of the letter, said it signed the letter because those weaknesses are already present and can be exploited more quickly as AI capabilities advance. “We agree with the three principles at its center: the weaknesses already exist, advanced AI needs to reach more defenders, and the response must be collective and widespread,” it said in a statement. Robbie Mueller, technical lead for cybersecurity at ArmorCode, said organizations already face constraints in addressing known vulnerabilities. “This shouldn’t be framed as an AI sophistication problem. It’s a capacity problem,” Mueller said, adding that organizations “can only remediate roughly one in ten vulnerabilities in a given month.” Mueller said risk increases when vulnerabilities form multi-step attack paths across systems. “What matters is not the number of findings but which ones chain together into a viable path… kill that path and the risk goes away,” he said. Focus on execution of existing security practices The coalition does not introduce new categories of defense, instead emphasizing execution of existing practices. “Make cyber defense an immediate leadership priority… with the urgency and coordination of an incident,” the letter stated. 1Password, another signatory, said the initiative highlights a “limited window to strengthen security” and calls for fixing high-risk weaknesses, enforcing least-privilege access, and verifying controls. Sophos said in a statement that AI-enabled threats increase risk to both enterprises and public services and require coordinated action. “Cyber defense is a shared responsibility,” the company said, adding that collaboration between industry and governments is necessary to address the threat. Sophos said AI can also help defenders “find exposures… and respond to threats before they cause material harm.” Operational pressure grows as change accelerates The letter warns that AI will increase both the scale and speed of cyberattacks, placing additional pressure on enterprise security operations. “In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated,” the coalition said. Johnathan Hunt, chief information security officer at LogicMonitor, said many enterprise environments are not designed to operate at that pace. “Bad actors will move at machine speed, while many legacy systems still rely on human reaction times,” Hunt said. At the same time, organizations are managing faster rates of system and software changes. Ryan McCurdy, vice president at Liquibase, said AI is increasing both attack speed and development velocity. “AI is accelerating both sides of the equation,” McCurdy said, adding that security teams must determine whether changes are “authorized, safe, and expected” at speeds that exceed manual review. Questions raised on funding and incentives The letter calls for increased investment in cyber defense, particularly for organizations supporting essential services. Seemant Sehgal, CEO of BreachLock, said the approach raises questions about incentives. “The companies asking governments to fund AI defensive tools are the same ones that would get paid to supply them… the recommended response isn’t neutral,” Sehgal said. John Strand, owner of Black Hills Information Security, said the most actionable recommendation is the call for greater sharing of threat intelligence. “The one recommendation that has some teeth… is greater sharing of IOCs,” Strand said. The coalition said coordinated action across industry and government will be required to address the threat. “Fix the most dangerous weaknesses, verify the fixes, and share what works so others can build on it,” the letter states. The group said such efforts could help strengthen defenses for enterprises and organizations that operate critical infrastructure.
000
Matthias Schulze @percepticon.bsky.social · 02/09/2026
Prediction Markets Should Be Regulated as Gambling, Appeals Court Says #cybersecurity #infosec
nytimes.com
Prediction Markets Should Be Regulated as Gambling, Appeals Court Says
The outcome contradicted an earlier appeals court decision. Federal regulators said the split rulings called for resolution by the Supreme Court.
020
Matthias Schulze @percepticon.bsky.social · 02/09/2026
Prozess gegen Meta: Instagram räumt Versäumnis bei Schutzfunktion für Junge ein #cybersecurity #infosec
zeit.de
Prozess gegen Meta: Instagram räumt Versäumnis bei Schutzfunktion für Junge ein
Der Chef von Instagram gibt zu, die Einführung neuer Funktionen zum Schutz junger Nutzer verschwiegen zu haben. Deshalb seien sie in einer Testphase kaum genutzt worden.
000
Matthias Schulze @percepticon.bsky.social · 02/09/2026
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation #cybersecurity #infosec
thehackernews.com
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn. The accounts "were being used to promote the International Burke Institute (IBI), a
000
Matthias Schulze @percepticon.bsky.social · 02/09/2026
Social Media: Meta-Konzern einigt sich mit US-Bundesstaaten auf Milliarden-Vergleich #cybersecurity #infosec
zeit.de
Social Media: Meta-Konzern einigt sich mit US-Bundesstaaten auf Milliarden-Vergleich
Im Streit um die Gefahren von Social Media hat sich der Meta-Konzern mit US-Bundesstaaten auf einen milliardenschweren Vergleich geeinigt. Damit gibt es keinen Prozess.
010
Matthias Schulze @percepticon.bsky.social · 01/09/2026
Gates warns society faces an AI-pocalypse unless we get more socialist #cybersecurity #infosec
theregister.com
Gates warns society faces an AI-pocalypse unless we get more socialist
Bill Gates thinks that experts underestimate the potential havoc AI will wreak on society and says preparations to ease the transition are inadequate. The Microsoft founder and former CEO is usually a cheerful proponent of AI tech, talking up its potential to transform healthcare, education, and business productivity. Yet in a missive posted to his personal website, the billionaire philanthropist says the AI era is likely to be one of the most turbulent times in human history, and how we allow it to play out will determine whether the world becomes a fairer place or if the divide between rich and poor becomes greater than ever. This kind of talk will sound dangerously close to socialism for many Americans. There are always winners and losers in a market-led economy, so why should things be any different with AI? Those wealthy enough to invest in it and control it will prosper, as others will find themselves on skid row. But, Gates says, this time it will be different. Previous technology transitions happened over several generations and created new jobs where human cognition was required, whereas AI is starting to replace human cognition. The winners are likely to be a small group of people, and the losers will be everyone else. It will not affect just one or two sectors, according to the AI fab club: AI will replace human roles in fields as diverse as law, customer services, medicine, software, and manufacturing. And it will hit these industries rapidly, over the course of a decade or less, rather than taking a few generations. Gates wrote: There will be some new jobs created, Gates says, but without the right policies in place there will be far fewer than today, and entry-level jobs are among those most likely to vanish (as we're already seeing in the tech industry). Blue-collar jobs will also be affected, as AI-powered robots are advancing faster than people realize - much of the progress is happening in China. These may begin to compete with people on some physical tasks, such as in the construction and hospitality industries, within a few years. Gates says there are several big risks from AI adoption, foremost of which is that many work roles are set to disappear forever. He notes that during the Great Depression of the 1930s, unemployment in the US hit 25 percent and remained in double digits for much of that decade, but ultimately recovered as demand, investment, and growth returned. He fails to mention, however, that it took a global war for that to happen. The biggest shift comes when AI operates error-free operation, without humans prepping its work or checking its output. Gates says we need to think now about reducing job losses, or risk much of society ending up unemployed. Another danger, Gates says, is that AI empowers people to do harm: AI-driven malware already lets low-skilled attackers launch cyberattacks, while generative AI makes fraud, disinformation, and deepfakes easier to produce. The third big threat is that AI systems could stunt the mental development of children, and crowd out human relationships. So how is society meant to avoid this apocalyptic vision and ensure AI becomes the force for good that Microsoft’s progenitor believes it to be? Gates says AI needs both a domestic and international framework. Nationally, that means bodies that can set priorities across government agencies to ensure every risk is accounted for. Yet even a nation with its own house in order remains exposed to cross-border risks, so an international body must be built in parallel. If that sounds like wishful thinking, get in the queue. Gates notes it would require US-China cooperation, and under the current Washington administration, that's about as likely as pigs flying.. Beyond that, some jobs - social care for instance - should stay human. Gates also thinks the tax system will need rebalancing, as more people out of work means less income tax to fund government itself. A starting point, he suggests, is taxing AI tokens and robots to reduce corporations' incentives to swap meatbags for machines. This could fund retraining and a stronger safety net, but would need careful targeting so it doesn't hinder beneficial uses of AI, like drug discovery and better education Again, critics will likely dismiss this as socialism and point out that Microsoft was ruthless in pursuing profits under Gates' leadership. In a final message to world leaders, Gates urges them to act now, “before unemployment rises sharply, communities are hurting, and public trust has eroded.” This marks a shift for the Microsoft founder, who two years ago told people not to worry about AI, in particular energy use and increased greenhouse gas emissions, arguing AI would eventually solve the problems it creates. ®
010
Matthias Schulze @percepticon.bsky.social · 01/09/2026
Ethisches Hacken: Raus aus der Grauzone #cybersecurity #infosec
netzpolitik.org
Ethisches Hacken: Raus aus der Grauzone
Sicherheitsforscher:innen, die auf eigene Faust Lücken in IT-Systemen entdecken und diese verantwortungsbewusst melden, können schnell in die Bredouille geraten. Nun legt die Gesellschaft für Informatik ein Papier dazu vor, wie die überfällige Reform des Computerstrafrechts endlich gelingen könnte. Ethische Hacker:innen werden als "White Hats" bezeichnet – und müssen in Deutschland mit rechtlichen Folgen rechnen, wenn sie IT-Sicherheitslücken melden. – Alle Rechte vorbehalten: IMAGO / Future Image Wer in Deutschland IT-Sicherheitslücken meldet, läuft Gefahr, Probleme zu bekommen. So musste sich etwa die Sicherheitsforscherin Lilith Wittmann mit einer Anzeige herumschlagen, nachdem sie eine gravierende Sicherheitslücke in einer App der CDU gefunden hatte. Dabei half es ihr zumindest anfangs nicht, sich vorbildlich verhalten zu haben: Ausgenutzt hatte sie den unautorisierten Zugang zu zehntausenden Datensätzen nicht, sondern stattdessen der Partei Zeit genug gegeben, die Lücke zu schließen, bevor die Öffentlichkeit davon erfuhr. Obwohl die Sache letztlich glimpflich für Wittmann ausging, bewegen sich IT-Sicherheitsforscher:innen oft in einer rechtlichen Grauzone. Vor allem das seit dem Jahr 2007 geltende Computerstrafrecht kriminalisiert eine Reihe an Techniken und Werkzeugen, die zur Grundausstattung vieler IT-Sicherheitsexpert:innen zählen. Eines der Probleme dabei: Wenn Lücken nicht gefahrlos und verantwortungsbewusst („Responsible Disclosure“) gemeldet und anschließend vom Hersteller geschlossen werden können, bleiben sie offen. Ein gefundenes Fressen für tatsächliche Cyberkriminelle, Geheimdienste beliebiger Länder oder sonstige Akteure, die keine guten Absichten haben. Anläufe für Reform Inzwischen ist in der deutschen Politik über Parteigrenzen hinweg durchgedrungen, dass dieser Ansatz mehr Probleme schafft, als er löst. Die überfällige Reform lässt jedoch weiterhin auf sich warten. Zuletzt ist die Ampelregierung nicht über einen Referentenentwurf hinausgekommen, der die umstrittenen Hacker-Paragrafen entschärft hätte. Und das Versprechen der schwarz-roten Regierung, im „Computerstrafrecht Rechtssicherheit für IT-Sicherheitsforschung“ zu schaffen, steht bislang nur als nebulöse Absichtserklärung im Raum. In diese Lücke stößt ein aktuelles Papier der Gesellschaft für Informatik (GI). Diese hatte sich mit Industrie, Sicherheitsforschenden und digitalpolitischen NGOs zusammengesetzt und Lösungsansätze entwickelt, um eine rechtssichere IT-Sicherheitsforschung zu erlauben. Dabei sei Eile geboten, so GI-Präsident Martin Wolf. Das große Missbrauchspotenzial von KI-Systemen mache das frühzeitige Finden und Melden von Schwachstellen wichtiger denn je, sagt der in Aachen lehrende IT-Experte. „Ehrenamtliche Hacker:innen dürfen dafür nicht länger mit Strafanzeigen statt Anerkennung belohnt werden“, fordert Wolf. Kameras prüfen, ob du artig bist. Da werden wir unbequem. Mit deiner Unterstützung. Jetzt spenden Als Ausweg bietet das GI-Papier zum einen konkrete Gesetzesänderungen an. So müsse etwa die Absicht der meldenden Person ein „zentrales Kriterium“ einer gesetzlichen Anpassung sein. Schließlich stelle die gemeinwohlorientierte Meldung einer Sicherheitslücke einen „wesentlichen Unterschied zu böswilligem Hacking dar“, führt das Papier aus. Entsprechend sollten unter anderem Hacking-Tools, die beispielsweise das Dekompilieren von Software möglich machen, legalisiert werden: „Nicht die Herstellung oder das Zugänglichmachen von ‚Hacker*innentools’ sollte kriminalisiert werden, da diese zur Aufdeckung solcher Schwachstellen verwendet werden, sondern die Verwendung für eine verbotene Handlung.“ Polen als Vorbild Zum anderen müsse die Regierung neben dem Strafrecht weitere Gesetze anfassen, darunter das Datenschutzgesetz (TDDDG). Dieses kriminalisiere in seiner aktuellen Form das Melden einer Schwachstelle, selbst wenn diese auf eine schlechte oder fehlende Sicherung auf Herstellerseite zurückzuführen ist. Über die Gesetzesänderungen hinaus brauche es jedoch einen ganzheitlichen Ansatz, fordert die GI. Dazu würden ein „wirkungsvolles Meldeverfahren und eine aktive Meldekultur“ zählen. Zudem sei eine stärkere gesellschaftliche Anerkennung ethischen Hackens ein wichtiger Beitrag, um insgesamt die IT-Sicherheit zu erhöhen, so das Papier. Für einen neuen Anlauf zur Reform des Bereichs könnte sich die Regierung auch von anderen Ländern inspirieren lassen. Polen habe laut GI den in Europa liberalsten Ansatz. Dort seien etwa Personen, die ausschließlich zum Zweck der Sicherung von Systemen handeln, ausdrücklich von der Strafbarkeit ausgenommen. Alles netzpolitisch Relevante Drei Mal pro Woche als Newsletter in deiner Inbox. Jetzt abonnieren Zugleich sollte die Regierung den „Windschatten des Cyber Resilience Act“ nutzen, empfiehlt die GI. Die vor rund zwei Jahren verabschiedete EU-Verordnung enthält unter anderem Meldepflichten für Hersteller und Betreiber, wenn sie über Schwachstellen stolpern. Dies ließe sich ausweiten, indem darüber hinaus auch eine geregelte Meldemöglichkeit für externe und/oder ehrenamtlich agierende IT-Sicherheitsforschende eingeführt wird. Damit würde der Charakter des Cyber Resilience Acts gestärkt und die Cybersicherheit im Land gefördert werden, argumentiert die GI. Sicherheitslage verbessert sich kaum Insgesamt dürfte noch einiges zu holen sein, zumal sich die Lage zuletzt keineswegs verbessert hat. So stieg im ersten Quartal 2026 die Zahl gemeldeter Schwachstellen weltweit um 25 Prozent im Vergleich zum Vorjahr an. Jährlich entsteht für deutsche Unternehmen laut eigenen Angaben ein hunderte Milliarden Euro hoher Schaden, Tendenz steigend. Diese Dynamik dürfte vorerst bestehen bleiben. Denn auf der einen Seite gelingt es KI-Modellen immer besser, bislang unbekannte Sicherheitslücken in Anwendungen zu entdecken. BSI-Präsidentin Claudia Plattner spricht gar von einer neuen „Zeitrechnung der Cybersicherheit“. Auf der anderen Seite berge sogenanntes Vibe-Coding die Gefahr, selbst Schwachstellen in Code zu erzeugen, warnt die GI. Bei Vibe-Coding richten Nutzer:innen, die mit Software-Entwicklung sonst nichts zu tun haben, in einfacher Sprache ihre Wünsche an ein KI-System. Dieses übernimmt dann den Rest – mal besser, mal schlechter. Nun müsse die Bundesregierung zügig eine Reform unter Beteiligung aller Betroffenengruppen einleiten, fordert die GI. „Eine Legalisierung von ethischem Hacking wäre ein konsequenter Schritt, die Cybersicherheitslandschaft in Deutschland besser zu gestalten und das Potenzial zu nutzen, das Expert*innen aus der Sicherheitsforschung, Hobbytüftler*innen und gewissenhafte Nerds mitbringen.“ --- Die Arbeit von netzpolitik.org finanziert sich zu fast 100% aus den Spenden unserer Leser:innen. Werde Teil dieser einzigartigen Community und unterstütze auch Du unseren gemeinwohlorientierten, werbe- und trackingfreien Journalismus jetzt mit einer Spende.
032
Matthias Schulze @percepticon.bsky.social · 01/09/2026
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations #cybersecurity #infosec
thehackernews.com
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).&
010
Matthias Schulze @percepticon.bsky.social · 01/09/2026
Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit #cybersecurity #infosec
therecord.media
Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit
The National Security Agency will welcome back to campus potentially hundreds of former members of the elite group known as Tailored Access Operations (TAO) to celebrate the division’s recent rebranding.
000
Matthias Schulze @percepticon.bsky.social · 03/08/2026
Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover #cybersecurity #infosec
csoonline.com
Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover
A Russia-aligned threat group used a “half-click” exploit against Microsoft Exchange’s Outlook Web Access to install a browser-based backdoor when recipients opened specially crafted emails. The campaign began on July 22 and was conducted by TA488, which is also tracked as Void Blizzard and Laundry Bear, according to a report from the cybersecurity firm Proofpoint. The attacks targeted government organizations in the US and Europe, as well as companies in the telecommunications, financial, hospitality, and aerospace sectors. Proofpoint did not name the targeted organizations or say how many attacks resulted in successful compromises. The attackers exploited CVE-2026-42897, a cross-site scripting vulnerability caused by inadequate sanitization of HTML in email bodies. A recipient did not have to click a link or open an attachment. Viewing a crafted message in OWA allowed malicious JavaScript to execute inside the browser. Microsoft has previously said the flaw affects all update levels of Exchange Server 2016 and 2019, as well as Exchange Server Subscription Edition, while Exchange Online is not affected. The company disclosed the vulnerability on May 14 and issued an emergency mitigation before releasing a code fix in June. Microsoft later said customers who installed its July 2026 Exchange security update could remove the earlier mitigation. Proofpoint found that infrastructure associated with the campaign had been created in March, before Microsoft disclosed the vulnerability. The company said the timeline made it feasible that TA488 had used the flaw as a zero-day, although it did not confirm that such exploitation occurred. “TA488 used intentionally vague message lures with no call-to-action for the targeted user,” Proofpoint said. The messages resembled routine informational updates, including material on supply chains and market indicators. Opening one in OWA triggered OWAReaper, a previously undocumented JavaScript implant that runs inside the reading pane. OWAReaper removes the exploit code from the message stored on the Exchange server after execution, reducing the evidence visible to users and investigators. It can collect account information and attempt to capture credentials entered through browser autofill. If OWAReaper finds an Outlook add-in with ReadWriteMailbox permissions, it can use the add-in to obtain an OAuth token and grant owner-level access to Exchange’s built-in “Default” identity. This could allow an attacker controlling another authenticated account in the organization to continue accessing the victim’s mail folders. Because those permissions are stored on the Exchange server, changing the victim’s password or rebuilding the endpoint would not remove them. Mailbox persistence OWAReaper shifts incident response beyond the affected device because the attacker can establish persistence within Exchange itself, said Sakshi Grover, senior research manager for IDC Asia Pacific Cybersecurity Services. “The most important shift is where the attacker establishes persistence,” she said. Organizations should treat the compromise as a server-side identity incident rather than only an infected endpoint or stolen password, said Keith Prabhu, founder and CEO of Confidis. “The normal incident response is usually to reset the password, revoke tokens, and reimage the endpoint,” Prabhu said. “This may no longer be sufficient.” Detection blind spots Security tools focused on endpoint files or processes may fail to identify an implant operating inside the OWA browser session, Prabhu said. “Traditional email-security controls may also struggle because the delivery emails contain no obvious malicious attachment or conventional phishing link,” Grover said. Because OWAReaper operates within an authenticated OWA session and can abuse legitimate mailbox functions, individual events may not appear malicious when examined in isolation. Detecting the threat requires cross-layer correlation, Prabhu said. He recommended starting with users that opened suspicious OWA messages, then reviewing subsequent mailbox-permission changes, add-in activity, and OAuth events. Investigators should also examine browser-storage artifacts and related network metadata.
020
Matthias Schulze @percepticon.bsky.social · 03/08/2026
Can Cyber Operations Be Deterred? What Wargames Reveal #cybersecurity #infosec
warontherocks.com
Can Cyber Operations Be Deterred? What Wargames Reveal
The most successful deterrent threats leave no evidence behind. No missiles fly. No networks go down. No troops cross borders. Nothing happens. For policymakers, that is often the desired outcome. For researchers, it is a nightmare. Imagine, however, being able to observe a decision-maker preparing to attack, receiving a deterrent threat, and then changing their mind. That moment — the instant deterrence succeeds — is arguably the most important observation in international security. It is also one we almost never see.We can see its failure: the red line crossed, the chemical weapons used, the invasion that follows from “military exercises.” The post Can Cyber Operations Be Deterred? What Wargames Reveal appeared first on War on the Rocks.
010
Matthias Schulze @percepticon.bsky.social · 02/08/2026
The majority of corporate IT is now off premises for the first time #cybersecurity #infosec
theregister.com
The majority of corporate IT is now off premises for the first time
IT is going remote while sucking up more power. Most corporate IT is now off-premises for the first time, according to Uptime Institute, while the average rack power density has crested above 11 kW for the first time as server fleets are gradually replaced with more powerful hardware. Uptime’s Global Data Center Survey 2026 reveals how the industry is managing to adapt to challenging circumstances, with the usual evergreen concerns over rising costs plus staffing and skills shortages. The survey polls more than 800 datacenter owners and operators across multiple countries, with more than half (52 percent) in North America and Europe. Off premise dominates: Every year, Uptime asks its enterprise respondents to estimate what percentage of their IT workloads are run in-house versus in third-party facilities. For the first time, third-party sites have the larger share, accounting for 46 percent of IT workloads, compared with 44 percent residing in enterprise-owned corporate server farms. Those figures don’t add up to 100 percent, as some respondents (10 percent) say they are using IT rooms and server cabinets rather than a dedicated facility. Uptime’s experts estimate that, by 2028, the proportion of workloads in self-owned server halls will remain the same, while those running in third-party sites will expand to 48 percent, eating away at those currently based in IT rooms and server cabinets. More power: While the headlines have featured AI infrastructure pushing IT infrastructure power density to 120 kW per rack or even higher, the reality is that most datacenters and servers operate at a much lower level than that. This year, the average of the most typical rack densities now surpasses 11 kW, as a gradual ongoing shift toward higher-powered hardware was compounded by a small number of new high-density facilities with racks above 30 kW. Without those few high-density facilities skewing the average, it sits at 7.8 kW, just slightly up from 7.5 kW in 2025. The majority of facilities still do not have any racks of 30 kW or above, Uptime finds, but more respondents (24 percent) now say they have some of these, compared with 19 percent last year. The increase was mostly in the 50-plus kW ultra-high-density range, including some respondents deploying AI and GPU servers into racks configured for above 100 kW. The trend for rising rack density will continue as organizations upgrade their infrastructure with newer hardware. Updated servers boost both workload capacity and energy performance, but maximizing these benefits means a corresponding rise in overall system power, Uptime states. Refresh shortened: Some operators are also pursuing more aggressive technology refresh timelines of less than 4 years, the report claims. If true, this would be the reverse of what some hyperscalers such as Microsoft, Google and Meta have been doing in recent years, extending lifecycles out to 6 or 7 years to save on depreciation expenses. Outages: When it comes to outages, this year’s report shows improvement for the sixth year in a row, with the number of respondents who experienced an outage in the past three years down by three percentage points. But Uptime warns against complacency, noting that many of the factors behind outages, such as reduced or unstable power availability, local grid reliability, supply chain constraints, and extreme weather, are on the increase. The flip side is that the costs of any outages that do occur continue to rise. This is because organizations have become more dependent on digital infrastructure, the report says, and so outages may have more financial impact than in the past. Overall, 71 percent of survey respondents reported that their most damaging outage cost at least $100,000, compared with 57 percent a year ago. Staffing shortage: Staffing has long been an issue for datacenter operators, and this year the greatest skills gaps reported were in electrical (38 percent of respondents), junior level operations (38 percent), operations management (35 percent) and mechanical roles (34 percent). However, more than half (53 percent) of operators report difficulties finding qualified candidates for vacant roles, up from 46 percent a year ago. Finally, Uptime found that financial pressure and resource constraints continue to grow among operators. In fact, the high prices of power, staff, and equipment, particularly for AI-related infrastructure, is the primary issue. Alongside that are escalating concerns over capacity forecasting, power availability and supply chain disruptions. ®
021
Matthias Schulze @percepticon.bsky.social · 02/08/2026
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks #cybersecurity #infosec
unit42.paloaltonetworks.com
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42.
010
Matthias Schulze @percepticon.bsky.social · 02/08/2026
OpenAI’s Hacking Debacle Was a Human Mistake #cybersecurity #infosec
wired.com
OpenAI’s Hacking Debacle Was a Human Mistake
If the generative AI giant had followed well-known security best practices, it’s likely that its AI agent would never have escaped to the open internet and hacked multiple companies.
010
Matthias Schulze @percepticon.bsky.social · 02/08/2026
The Signs Were There: What the First Autonomous Ransomware Case Confirms #cybersecurity #infosec
trendmicro.com
The Signs Were There: What the First Autonomous Ransomware Case Confirms
An AI agent has run a ransomware intrusion on its own for the first time, from break-in to data destruction. The autonomous attacks TrendAI™ Research predicted are beginning to arrive, and defending against them shifts from blocking known indicators to detecting behavior.
010
Matthias Schulze @percepticon.bsky.social · 01/08/2026
Pope's official prayer app commits cardinal sin, leaks 700K+ users' info #cybersecurity #infosec
theregister.com
Pope's official prayer app commits cardinal sin, leaks 700K+ users' info
Click To Pray, a prayer app endorsed by the Pope with hundreds of thousands of users worldwide, has leaked people’s names and email addresses for months - or longer - according to an ethical hacker who said she found and reported the security vulnerability six months ago to no avail. This app needs to take a vow of silence when it comes to your personal information. The app, available in seven languages and on iOS, Android, and clicktopray.org, is the official app of the Pope's Worldwide Prayer Network. It connects users across the globe to pray for the Holy Father’s intentions, and as of July 2026, it has 719,517 registered accounts. It’s also very leaky, according to security sleuth BobDaHacker, who says she spotted and disclosed the vulnerability to the Pope’s Worldwide Prayer Network on January 3. “The vulnerability is still live,” the hacker said in a Friday blog. “Nobody has ever responded. I guess my email wasn't in their prayers." The Reg readers likely remember BobDaHacker for her previous research exposing a free-food flaw in McDonald's ordering system and open controls on Chinese robot manufacturer Pudu Robotics. This latest security hole stems from an Insecure Direct Object Reference (IDOR) bug in the prayer app. This is a very common and easy-to-exploit type of flaw that occurs when a website or an app blindly accepts user-provided input to view or modify resources without checking to see if the user is actually authorized to retrieve the data. “You ask for your own data, the server gives it to you,” BobDaHacker explains. “You ask for someone else's data, the server gives you that too. Thou shalt not authorize, apparently.” When you sign up for a Click To Pray account, the app assigns you a sequential numeric user ID. As BobDaHacker uncovered, the API endpoint GET https://api[.]clicktopray.org/user/users/{id} will return user data for any account - not just your own account - so long as you supply a valid, five-digit user ID. It doesn’t perform any authorization check or ownership validation. “Just increment the number and get someone else's data,” she wrote. This data includes users’ email addresses, first and last names, country, dates of birth, and whether the account has been deleted, and the API exposes all 719,517 accounts on the prayer site. “With sequential user IDs and no rate limiting, an attacker could enumerate every single account on the platform,” the hacker explained. “One GET request per user. for i in range(1, 719518): scrape(). That's it. That's the exploit.” As BobDaHacker points out, many of these users are likely older individuals, not all that tech savvy, and very trusting of anything Vatican related, making these exposed accounts a “phishing goldmine.” “Imagine getting an email that says ‘The Holy Father requests your urgent attention’ with a Vatican-looking link,” she wrote. “Grandma is clicking that. Every time.” And then it gets even worse. The signup endpoint, POST https://api.clicktopray.org/user/users/sign-up, returns the account's validation_hash directly in the response body, and that value is the same UUID used in the email verification link. This means someone could sign up using any email address and verify the account before the confirmation message reached the inbox. Plus, BobDaHacker’s email client flagged the real verification email with a warning that it had failed the domain’s authentication requirements and might have been spoofed or improperly forwarded. “So not only is the API leaking 700,000 email addresses that could be used for phishing, but the real emails from Click To Pray already look like phishing,” the hacker noted. “An attacker wouldn't even need to try hard. They could send a pixel-perfect phishing email and it would have the same level of email authentication as the real thing: none. God works in mysterious ways.” The Register reached out to the Pope's Worldwide Prayer Network and did not receive any response. BobDaHacker says she’s still praying for one, too.®
010
Matthias Schulze @percepticon.bsky.social · 01/08/2026
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say #cybersecurity #infosec
thehackernews.com
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution. Redis 6.2.23, 7.2.15, and 7.4.10
020
Matthias Schulze @percepticon.bsky.social · 01/08/2026
EU-Kommission: TikTok soll Minderjährige besser schützen #cybersecurity #infosec
heise.de
EU-Kommission: TikTok soll Minderjährige besser schützen
In der laufenden Untersuchung der chinesischen Plattform TikTok findet die EU-Kommission Mängel beim Kinder- und Jugendschutz.
110
Matthias Schulze @percepticon.bsky.social · 01/08/2026
NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says #cybersecurity #infosec
therecord.media
NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says
Dutch intelligence officials report that at least one Russian agency is compromising internet-connected cameras across Europe to spy on military logistics and Ukrainian personnel.
010
Reposted by Matthias Schulze
Ardubancel Quazanga @quazanga.bsky.social · 23/07/2026
Diese Forschenden sagen, dass ein CO2 Ausstoß erst nach ca 10 Jahren das Klima beeinflusst. D.h. die Hitzewellen von 2026 kommen vom CO2 von 2016. Seit 2016 ist der weltweite CO2 Ausstoß nochmal um 9% gestiegen. D.h. Herr Söder muss in den nächsten 10 Jahren noch viel mehr schwimmen.
iopscience.iop.org
Maximum warming occurs about one decade after a carbon dioxide emission
Maximum warming occurs about one decade after a carbon dioxide emission, Ricke, Katharine L, Caldeira, Ken
23375129
Reposted by Matthias Schulze
Eliot Higgins @eliothiggins.bsky.social · 23/07/2026
My first contribution to The Netherland's Great Media Debate, where I argue we must recognise the problem of disinformation as one that's of demand, and not so much one of supply www.volkskrant.nl/columns-opin...
volkskrant.nl
Opinie: Het Grote Mediadebat zal mislukken, tenzij we de vraag anders stellen
Het probleem van desinformatie zal niet verdwijnen zolang burgers niet beseffen dat zij zélf de taak van verificatie hebben: hoe test je bronnen en beweringen, hoe herken je manipulatie, hoe laat je r...
617748
Reposted by Matthias Schulze
Roland Meyer @bildoperationen.bsky.social · 23/07/2026
«Artificial intelligence is … a machine for shifting income and power from labor to capital. When capitalist investors pay billions of dollars to make computers ‹know things,› then their purpose is to cheapen the knowledge that people have, save on wages, and turn the savings into profit.»
jacobin.com
The Socialist Case Against Nationalizing AI
AI is not a neutral technology whose benefits need to be redistributed. It is a weapon of class war from above, designed to cheapen labor and concentrate power. Nationalizing it does nothing to change...
55113
Reposted by Matthias Schulze
Luiza Jarovsky, PhD @luizajarovsky.bsky.social · 22/07/2026
Anthropic wants people to teach Claude their skills for free.
1113
Reposted by Matthias Schulze
Reuters @reuters.com · 21/07/2026
French lawmakers vote on social media ban for children reut.rs/4whgIOo
reut.rs
French lawmakers vote on social media ban for children
French lawmakers vote on Tuesday on a law that aims to ban social media access for children under the age of 15, joining countries around the world ​in considering a move unpopular with many teenagers but supported by some ‌parents and teachers.
1118
Reposted by Matthias Schulze
Catherine Rampell @crampell.bsky.social · 20/07/2026
Trump administration sought the phone records of several NYT journalists and their relatives — including one reporter’s mother www.nytimes.com/2026/07/20/b...
25541235
Reposted by Matthias Schulze
komplizemeinerflucht @kmf.bsky.social · 20/07/2026
So sieht’s aus…
Torte der Wahrheit ZEIT
220363
Matthias Schulze @percepticon.bsky.social · 15/07/2026
This fake Apple app can unlock your Mac’s password vault #cybersecurity #infosec
malwarebytes.com
This fake Apple app can unlock your Mac’s password vault
CrashStealer is a new macOS infostealer that masquerades as Apple’s CrashReporter component, uses an Apple‑notarized installer to slip past Gatekeeper, tricks users into handing over their password, and then systematically loots browsers, password managers, crypto wallets, and Keychain secrets before exfiltrating them in AES‑encrypted bundles. Researchers have been following the development of CrashStealer since May 2026. It impersonates Apple’s CrashReporter component by taking the name CrashReporter.app. It also creates a LaunchAgent named com.apple.crashreporter.helper and uses the legitimate tool’s icon and metadata to look as trustworthy as possible. Gatekeeper, basically macOS’s bouncer at the door, checks whether an app looks safe before letting it run. By using a notarized installer—one that Apple has scanned and stamped as acceptable—Gatekeeper is more likely to let it through without raising alarms. Getting notarized doesn’t mean Apple intentionally approved the malware. It means the installer passed Apple’s automated checks, and the attackers abused that trust. The notarized installer, called “Werkbit Setup” is distributed from a fake software site registered in late June and gated behind a meeting PIN (Personal Identification Number), suggesting a targeted, invitation‑only campaign. When launched, the malware displays a fake macOS password prompt that users will expect to see when running a legitimate system operation requiring administrator privileges. In reality, the malware uses that password to unlock the user’s Keychain, which stores passwords and other sensitive data in macOS’s encrypted password vault. Image courtesy of Jamf Labs The malware then steals browser credentials and cookies, cryptocurrency wallet extensions, password manager data, and small files from common user directories. The stolen data is encrypted and sent to a command and control (C2) server. CrashStealer is a reminder that macOS is firmly in the sights of credential‑stealing operations. Notarization and Gatekeeper reduce many classes of risk, but they do not remove the need for layered defenses, cautious user behavior, and ongoing threat monitoring. How to stay safe There are a few things you can do to protection yourself from CrashStealer and other infostealers. * Be skeptical of “CrashReporter” downloads. Apple’s crash‑reporting tools ship with macOS, so you should never need to download a separate CrashReporter app from a third‑party site. * Treat PIN‑gated installers with caution. If a meeting invite or collaboration tool requires you to download software from an unfamiliar domain and enter a private PIN to unlock the installer, verify the request with the organizer through a separate trusted channel. * Treat a password request that appears immediately after launching a new or unfamiliar app—especially one claiming to be a system component—as a red flag. * Use reputable security software that supports macOS. Keep it, and macOS itself, up to date. * Separate your risk. Avoid keeping high‑value crypto wallets, password vaults, and everyday browsing credentials on the same machine and user profile wherever possible. Malwarebytes detects CrashStealer as MacOS.Stealer.Crash. --- We don’t just report on threats—we remove them Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
010
Matthias Schulze @percepticon.bsky.social · 12/07/2026
Canadian spy agency reports hacking three criminal groups in 2025 #cybersecurity #infosec
therecord.media
Canadian spy agency reports hacking three criminal groups in 2025
A ransomware-as-a-service gang, an online foreign extremist group and drug traffickers were separately the targets of offensive operations in 2025, according to Canada's Communications Security Establishment.
010
Matthias Schulze @percepticon.bsky.social · 11/07/2026
Meta Ordered by E.U. to Alter ‘Addictive Design’ of Instagram and Facebook #cybersecurity #infosec
nytimes.com
Meta Ordered by E.U. to Alter ‘Addictive Design’ of Instagram and Facebook
European Union authorities said the company’s use of “addictive design” violated a digital safety law.
031
Matthias Schulze @percepticon.bsky.social · 11/07/2026
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws #cybersecurity #infosec
thehackernews.com
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the high-severity vulnerabilities is as follows - GHSA-hjr6-g723-hmfm (CVSS score: 8.8) - An operating system
010
Matthias Schulze @percepticon.bsky.social · 11/07/2026
Geheimdienstreform: Zeitenwende für Spione #cybersecurity #infosec
netzpolitik.org
Geheimdienstreform: Zeitenwende für Spione
Bundesnachrichtendienst und Verfassungsschutz sollen „echte“ Geheimdienste werden, sagt Innenminister Dobrindt. Jetzt zeigt der Entwurf für die Komplettreform, was das heißt: Zurückhacken, Abschnorcheln, Kameras anzapfen – und das mit weniger öffentlicher Kontrolle als zuvor. Innenminister Dobrindt will BND und BfV aufrüsten. – BfV - Alle Rechte vorbehalten: IMAGO / newspix, BND - CC BY 2.0: Alper Çuğun, Dobrindt - CC BY 4.0: European Union Fast 700 Seiten lang ist der Gesetzentwurf aus dem Innenministerium, der Verfassungsschutz und Bundesnachrichtendienst in nie dagewesenem Ausmaß aufrüsten soll. Die Dienste sollen etwa Zurückhacken dürfen und bekommen ein Arsenal neuer Befugnisse zu KI und Biometrie. Schon vor mehr als einem halben Jahr gab es Berichte zu Arbeiten an dem Gesetz. An einigen Stellen soll es gehakt haben, die Abstimmungen zum Bundesverfassungsschutzgesetz hätten sich verzögert. Bundesinnenminister Alexander Dobrindt (CSU) habe unbedingt beide Gesetze gemeinsam durch die Tür bringen wollen. Nun ist der Referentenentwurf aus dem Innenministerium öffentlich. Es geht nicht nur um Ergänzungen, sondern um eine komplett neue Grundlage für die Arbeit der Dienste. Außerdem sollen mehr als zehn weitere Gesetze geändert werden. Der noch nicht in der Regierung abgestimmte Entwurf enthält zudem neue Regelungen für die Aufsicht der Geheimdienste. Unterm Strich soll die Kontrolle der Behörden schlanker werden – und öffentliche Transparenz noch weiter sinken. Die Übersicht. * Drei übergeordnete Ziele * Geheimdienste und Polizei nähern sich an * Mittel sollen geheim bleiben * Abschnorcheln bleibt erlaubt * Behörden sollen hacken dürfen * Dienste sollen KI kaufen, nutzen, trainieren * Niedrige Hürden für unsichere US-Software * Gesichter suchen, öffentliche Kameras anzapfen * Geheimdienst-Kontrolle soll schlanker werden * Noch weniger Transparenz als zuvor Drei übergeordnete Ziele Die umfassende Reform des Nachrichtendienstrechts, so der Entwurf, verfolge „drei übergeordnete Ziele“: Erstens sollen die Dienste in Anbetracht der „verschärften Bedrohungslage im In- und Ausland“ mehr Befugnisse erhalten. Zweitens solle der Entwurf der Vorrede zufolge die Kontrolle über die Geheimdienste stärken. Und drittens nehme er Anpassungen vor, die das Bundesverfassungsgericht gefordert hatte. Ein Urteil aus dem Jahr 2024 beanstandet etwa, wie der BND mit innerdeutscher Kommunikation umgeht. Außerdem erachten die Richter:innen eine hauptamtliche Aufsicht als erforderlich, weil die bisher für die Kontrolle zuständige G‑10-Kommission nicht ausreiche. Um die Mängel zu beheben, hat das Gericht der Bundesregierung eine Frist Ende 2026 gesetzt. Das heißt: Die Zeit für eine Neuregelung drängt. Laut Medienberichten will die Bundesregierung den Entwurf noch vor der parlamentarischen Sommerpause abstimmen – dann könnte ab Herbst der Bundestag darüber diskutieren. Geheimdienste und Polizei nähern sich an Die geplanten Umbrüche für BND und Verfassungsschutz greifen das Trennungsgebot an, das in Deutschland wegen historischer Lehren bislang eine wichtige Grundlage für Geheimdienst- und Polizeipolitik war. Die verschiedenen Institutionen, so die Konsequenz aus Erfahrungen mit Gestapo und Stasi, sollten getrennte Aufgaben und Befugnisse haben. Während die Geheimdienste vor allem Informationen sammeln sollen, darf die Polizei auch direkt eingreifen. Mit der Reform will Innenminister Dobrindt, „dass aus dem Nachrichtendienst nun ein echter Geheimdienst wird“, wie er Anfang des Jahres mit Blick auf den Verfassungsschutz sagte. Offenbar versteht er darunter, dass ein Geheimdienst auch eingreifen soll. Das zeigt sich etwa an den geplanten Befugnissen für aktive Eingriffe in IT-Systeme. Verfassungsschutz und BND sollen demnach unter bestimmten Bedingungen zurückhacken dürfen. Die Trennung zwischen Geheimdiensten und anderen Sicherheitsbehörden verschwimmt auch bei den Möglichkeiten, Daten auszutauschen. Im Entwurf finden sich etwa Passagen, die es dem Verfassungsschutz erlauben, gemeinsam mit anderen deutschen Behörden Daten auszuwerten, auch automatisiert. Mittel sollen geheim bleiben Im Vergleich zu den vorigen Gesetzen schafft der neue Entwurf mehr Übersicht. Das aktuelle BND-Gesetz verweist an vielen Stellen auf die Regelungen für den Verfassungsschutz. Das soll sich ändern. Der Entwurf für die beiden neuen Gesetze zählt auch klarer als bisher „nachrichtendienstliche Mittel“ auf, die Verfassungsschutz und BND nutzen dürfen. Dazu gehören beispielsweise verdeckte Ermittler:innen im Internet, die sich in Online-Netzwerke einschleusen, sowie die Überwachung von Wohnräumen und Telekommunikation. Aber diese Aufzählung ist nicht abschließend. Die Dienste sollen ihre nachrichtendienstlichen Mittel lediglich in einer Dienstvorschrift „abschließend“ benennen. Darin hat die Öffentlichkeit jedoch keinen Einblick, denn Dienstvorschriften der Geheimdienste bleiben wie so vieles geheim. Genau so funktioniert auch das Gesetz für den Militärischen Abschirmdienst (MAD), das im Dezember verabschiedet wurde. Abschnorcheln bleibt erlaubt Nach wie vor soll der BND in großem Umfang Daten abschnorcheln. Konkret bedeutet das: Der Auslandsgeheimdienst soll Internetknoten anzapfen dürfen, Kommunikationsdaten ausleiten und die erhobenen personenbezogenen Daten auswerten. Bislang hieß das Fernmeldeaufklärung, der neue Gesetzentwurf bezeichnet das als „strategische Aufklärung“. Dem Entwurf zufolge soll der Geheimdienst solche Maßnahmen auf das „notwendige Maß“ und auf maximal 15 Prozent des Datenvolumens beschränken, „welches in allen Telekommunikationsnetzen übertragen werden kann“. Eine solche Beschränkung lässt sich aber nur schwer kontrollieren, was das Bundesinnenministerium (BMI) in seiner Begründung selbst einräumt. Schwarz-Rot will die Informationsfreiheit beschneiden. Wir kämpfen für Transparenz. Mit deiner Unterstützung. Jetzt spenden Zudem können etwa über den Internetknoten in Frankfurt am Main, den DE-CIX, mehr als 200 Terabit pro Sekunde (Tbit/s) fließen. In den vergangenen 12 Monaten flossen jedoch nur durchschnittlich rund 13 Tbit/s. Darf der BND also 15 Prozent des höchstmöglichen Datenvolumens abschöpfen, entspräche das schlicht dem gesamten Datenverkehr. Ein solches Ausspähen „reiner Inlandskommunikation“ ist für den Auslandsgeheimdienst grundsätzlich unzulässig. Allerdings lässt sich technisch nicht klar eingrenzen, welche Daten ausschließlich zum Inland gehören. Der BND müsste die Daten dem Entwurf zufolge also filtern – „soweit technisch möglich“. Dass das nicht immer funktioniert, war bereits vor mehr als zehn Jahren klar. Der Betreiber des DE-CIX sagte damals für seinen Internetknoten, dass selbst wenn „der BND das weltbeste Filtersystem bauen könnte, das 99,9 Prozent [Genauigkeit] erreicht, dann redet man immer noch über mehrere Millionen fehlerhaft getaggter Verbindungen – jeden Tag“. Das allein führt wohl dazu, dass der Auslandsgeheimdienst zwangsweise auch inländische Telekommunikation überwachen wird. Erlaubt ist ihm das allerdings nur, „wenn im Einzelfall tatsächliche Anhaltspunkte dafür vorliegen, dass die Maßnahme erforderlich ist, um Informationen zu zumindest erheblichen Bedrohungen zu erlangen“. Behörden sollen hacken dürfen Eine neue Befugnis im Entwurf ist, dass der BND ausdrücklich zurückhacken darf – wenn „eine unmittelbar bevorstehende Gefahr für ein besonders gewichtiges Rechtsgut besteht“. In diesem Fall soll der Auslandsgeheimdienst Daten verändern oder löschen dürfen, Datenströme umleiten oder „den Betrieb informationstechnischer Systeme einschränken oder unterbinden“. Der BND soll also nicht nur Angriffe auf IT-Systeme aufdecken, sondern die Systeme der Angreifenden selbst angreifen dürfen. Unterstützung soll der BND von „inländischen öffentlichen Stellen“ wie dem Bundesamt für Sicherheit in der Informationstechnik (BSI) erhalten. Das BSI soll Software-Schwachstellen und auch sogenannte Zero-Day-Schwachstellen künftig proaktiv an den Geheimdienst weitergeben. Der BND soll diese Sicherheitslücken dann für Cyberangriffe auf andere Systeme ausnutzen dürfen. Zero Day („null Tage“) bedeutet, dass Angreifende eine Schwachstelle bereits verwenden können, während die Anbieter davon nichts wissen. Das heißt, es verbleiben null Tage Zeit, um sie zu schließen. Auch der Verfassungsschutz soll hacken dürfen. Dabei soll der Dienst Geräte manipulieren dürfen, die Daten umleiten, löschen oder Fehlinformationen verbreiten. Dieses Zurückhacken ist auch unter dem Begriff „Hackback“ bekannt, Fachleute kritisieren die Maßnahmen aus strategischen, rechtlichen und technischen Gründen. Dienste sollen KI kaufen, nutzen, trainieren Sowohl Verfassungsschutz als auch BND sollen dem Entwurf zufolge ausdrücklich personenbezogene Daten automatisiert auswerten dürfen. Für den BND ist das etwa im Paragrafen über die „Allgemeine Befugnis zur Weiterverarbeitung“ geregelt. Damit sind auch sogenannte KI-Systeme gemeint. Die dazu gehörige Begründung nennt Anwendungen, „welche für ihre Funktion selbstlernende Systeme verwenden und anpassungsfähig auf einen autonomen Betrieb ausgelegt sind“. Zudem soll der BND mit personenbezogenen Daten auch eigene KI-Anwendungen trainieren dürfen. Für einige KI-Auswertungen gibt es höhere Hürden, zum Beispiel wenn der Geheimdienst „personenbezogene Vorhersagen oder Empfehlungen“ erstellt oder automatisiert „Verhaltens- und Persönlichkeitsprofile“, um das „individuelle Bedrohungspotenzial“ einer Person einzuschätzen. Diese Ergebnisse gelten dann als „Auswertungsprodukte mit erheblichem Eingriffsgewicht“. Die Hürde: Solche Vorhersagen müssten dazu dienen, eine „zumindest erhebliche Bedrohung“ aufzuklären. Solche „erheblichen“ Bedrohungen gibt es im Aufgabenbereich des BND jedoch viele. Dazu zählen zum Beispiel organisierte Kriminalität, hybride Einflussnahme, Extremismus und dessen Unterstützung oder auch: „krisenhafte Entwicklungen im Ausland“, die theoretisch eine Auswirkung auf Deutschland haben könnten. Es ist also ein Begriff, der sich breit interpretieren lässt. Dass automatisierte Anwendungen und KI-Systeme schnell zu Verzerrungen und falschen Ergebnissen führen können, ist dabei offenbar auch dem Innenministerium klar. Der BND dürfe „keine diskriminierenden Algorithmen nutzen oder entwickeln“, heißt es analog zu anderen Gesetzen wie dem hessischen Polizeigesetz. Aber wie soll der BND – oder irgendeine Behörde – so etwas sicherstellen? Es gehört zum Wesen vieler KI-Systeme, dass sich deren Ergebnisse nicht leicht nachvollziehen lassen. Daher soll sich der BND die Ergebnisse stichprobenartig genau anschauen, heißt es im Entwurf, und sicherstellen, dass eine Entscheidung „zur Weiterverarbeitung/Maßnahmenveranlassung auch von einem Menschen aufgrund der vorliegenden Informationen getroffen worden wäre“. Niedrige Hürden für unsichere US-Software Eine der Sorgen bei den jüngsten KI-Regelungen für Polizeien war, dass Systeme von US-Anbietern wie Palantir zum Einsatz kommen könnten – Stichwort: digitale Souveränität. Dem will das Innenministerium durch eine Vorzugsregel für eigene und EU-Produkte entgegenwirken. Von privaten oder öffentlichen Stellen aus anderen Staaten dürfe der BND nur Anwendungen kaufen, wenn er selbst oder andere europäische Stellen keine ebenso geeignete Anwendung haben. Besonders eng, das wird aus der Begründung des Gesetzes deutlich, will man es hier aber nicht sehen. Wenn ein Produkt einmal angeschafft ist, soll es auch „beliebig lange“ genutzt werden dürfen. Und der BND soll auch nicht jedes Mal prüfen müssen, ob es auch eine europäische Lösung gibt. Es reiche, wenn er alle paar Jahre – die Begründung nennt drei bis fünf – schaut, „welche kommerziell verfügbaren Anwendungen für seine Tätigkeit von Relevanz sein könnten und ob es für diese Anwendungen europäische/deutsche Anbieter gibt“. Für den Softwaremarkt ist das eine sehr lange Zeit. Neben dem BND soll auch der Verfassungsschutz eine KI-Erlaubnis bekommen. Das steht in der Norm über „Qualifizierte Auswertung“. Die Rede ist von einer „automatisierten Anwendung, die durch Verknüpfung neue Erkenntnisse über die Persönlichkeit einer Person oder ihre Beziehungen zu anderen Personen oder zu Objekten gewinnt“. Alles netzpolitisch Relevante Drei Mal pro Woche als Newsletter in deiner Inbox. Jetzt abonnieren Gesichter suchen, öffentliche Kameras anzapfen Neben ausdrücklichen KI-Befugnissen geht es im Gesetzentwurf auch um biometrische Daten. Der Verfassungsschutz soll biometrische Merkmale mit allem abgleichen dürfen, worauf er „zur Erfüllung seiner Aufgaben zugreifen darf“, wenn „tatsächliche Anhaltspunkte“ vorliegen, dass das für seine Aufgaben erforderlich ist. Das heißt, er soll es eigentlich immer machen dürfen, wenn es einen Grund dafür gibt, „also nicht lediglich auf Vorrat ins Blaue“. In der Begründung zum Entwurf heißt es weiter, dass ein Abgleich mit Daten erfolgen soll, die der Verfassungsschutz selbst gespeichert hat – oder mit für ihn zugänglichen Daten von Verfassungsschutzbehörden der Länder. Biometrische Abgleiche soll die Behörde auch nutzen dürfen. Damit soll sie Videoüberwachung live auswerten dürfen und prüfen, ob eine Person im Visier der Behörde an einem bestimmten Ort auftaucht. Für den Zugriff auf entsprechende Kamera soll der Verfassungsschutz Betreiber verpflichten dürfen, Aufnahmen herauszugeben, live auszuleiten oder gleich die Videoüberwachungsanlagen mit zu nutzen – zumindest wenn es um Überwachung von öffentlich zugänglichen Räumen geht. Das heißt, der Verfassungsschutz dürfte in Echtzeit Kameras am Bahnhof oder im Einkaufszentrum anzapfen. Auch der BND soll biometrische Daten auswerten dürfen. Ein Vergleich mit öffentlich zugänglichen Daten aus dem Internet soll ausdrücklich erlaubt sein. Das Verständnis von öffentlicher Zugänglichkeit ist hier allerdings etwas anders gefasst, als man es erwarten könnte. Denn dazu zählen für das BMI „alle Bereiche des Internets, auch solche, die mittels einer vorgelagerten Zugangshürde geschützt sind“. Erst wenn „Schutzmechanismen über rein formale Hürden hinausgehen“ werde dann der Zugriff zum Einsatz eines „nachrichtendienstlichen Mittels“, für das andere Hürden gelten. Um biometrische Daten abzugleichen, müsste der BND laut Entwurf keine eigenen Mittel nutzen – ein Abgleich dürfte auch über öffentliche oder private Stellen im Ausland erfolgen, wenn er selbst oder andere deutsche oder europäische Stellen das nicht können. Das öffnet die Tore dafür, dass der BND am Ende Anwendungen nutzt, die es nach europäischen Datenschutzrechten nicht geben dürfte. Der Geheimdienst könnte bei außereuropäischen Partnern um Hilfe bitten, für die schwächere Regeln gelten. Geheimdienst-Kontrolle soll schlanker werden Für die Kontrolle des Inlands- und Auslandsgeheimdienstes sind bislang unter anderem die G10-Kommission, das Parlamentarische Kontrollgremium und der Unabhängige Kontrollrat (UKRat) zuständig. Die G‑10-Kommission soll dem Entwurf zufolge jedoch wegfallen. Das G‑10-Gesetz regelt derzeit, unter welchen Voraussetzungen in Deutschland die Geheimdienste von Bund und Ländern in das durch Artikel 10 des Grundgesetzes geschützte Brief‑, Post- und Fernmeldegeheimnis eingreifen dürfen und wie derartige Eingriffe kontrolliert werden. Künftig soll mehr Kontrolle im UKRat gebündelt werden, der neue Aufgaben bekommt und das Parlamentarische Kontrollgremium unterstützen soll. Bislang ist der UKRat als oberste Bundesbehörde nur für den Auslandsgeheimdienst BND zuständig. Laut Gesetzentwurf soll er künftig auch den Inlandsgeheimdienst kontrollieren. Ähnlich wie ein Gericht soll der UKRat besonders eingriffsintensive Einzelmaßnahmen beider Geheimdienste vorab genehmigen. Außerdem soll er die Dienste administrativ kontrollieren, etwa wie sie personenbezogene Daten verarbeiten. Mehr Befugnisse für den UKRat würden jedoch weniger Befugnisse für die Bundesdatenschutzbeauftragte bedeuten. Eine solche Schwächung der für Geheimdienste mitunter lästigen Behörde hatte die aus dem Amt scheidende Louisa Specht-Riemenschneider bereits befürchtet. Ihr Nachfolger Moritz Hennemann dürfte demnach nur noch weniger sensible Bereiche beaufsichtigen, etwa die Verarbeitung personenbezogener Daten bei der allgemeinen Verwaltung des BND oder bei Aus- und Fortbildungen. Noch weniger Transparenz als zuvor Einige neue Regeln sollen die Informationsfreiheit weiter einschränken. Schon heute sind die Geheimdienste vom Informationsfreiheitsgesetz ausgenommen und müssen keine Dokumente an Bürger:innen freigeben – außer es geht um Umweltinformationen. Künftig sollen für Bürger:innen selbst solche Informationen über die drei Geheimdienste des Bundes tabu sein, die anderen staatlichen Stellen vorliegen. Insbesondere soll das für den Unabhängigen Kontrollrat gelten. In der Begründung des Entwurfs heißt es: „Alle Tätigkeiten der Nachrichtendienste sollen nach dem Willen des Gesetzgebers vom Anspruch auf Informationszugang ausgeschlossen sein.“ Das hätte weitreichende Folgen. Nicht einmal eine Statistik über künftige Agent:innen in Ausbildung soll es noch geben. Eine Ausnahme im Gesetz für Hochschulstatistik soll verhindern, dass feindliche Akteure erfahren, wie viel Spionage-Personal Deutschland in Zukunft haben könnte. Während ihre Macht enorm wächst, sollen Deutschlands Geheimdienste also noch intransparenter werden. --- Die Arbeit von netzpolitik.org finanziert sich zu fast 100% aus den Spenden unserer Leser:innen. Werde Teil dieser einzigartigen Community und unterstütze auch Du unseren gemeinwohlorientierten, werbe- und trackingfreien Journalismus jetzt mit einer Spende.
010
Matthias Schulze @percepticon.bsky.social · 11/07/2026
China's industry regulator flags 'backdoor' risk in Claude Code #cybersecurity #infosec
technologynewschina.com
China's industry regulator flags 'backdoor' risk in Claude Code
(China Daily) China's industry regulator has flagged security risks in Claude Code, an artificial intelligence programming tool developed by US startup Anthropic, warning that certain versions could expose sensitive user information through unauthorized data transmission.   The Ministry of Industry and Information Technology's Network Security Threat and Vulnerability Information Sharing Platform said on Wednesday that it had detected a potential "backdoor" risk in Claude Code, describing the threat as serious.   Claude Code, an AI coding assistant that can independently generate, debug, and modify software based on natural-language instructions, has become part of a new wave of AI tools reshaping software development.   The NVDB said affected versions range from 2.1.91 to 2.1.196. It alleged that the tool's built-in monitoring mechanisms could transmit sensitive information — including users' location data and identity-related identifiers — to remote servers without user authorization.   The platform urged companies and developers using affected versions to immediately conduct security checks and remove the vulnerable versions or upgrade to the latest releases that have eliminated the relevant code.   It also advised organizations to tighten controls over external connections from development tools on critical business networks and strengthen traffic monitoring to prevent unauthorized leakage of sensitive data. Source: By Cheng Yu | chinadaily.com.cn | Updated: 2026-07-08 14:38
010
Matthias Schulze @percepticon.bsky.social · 10/07/2026
Suspected Chinese snoops caught breaking into universities' Roundcube mailservers #cybersecurity #infosec
theregister.com
Suspected Chinese snoops caught breaking into universities' Roundcube mailservers
Suspected Chinese spies have been breaking into major US and Canadian universities since May, exploiting vulns in Roundcube mailservers to steal data belonging to physics and engineering administrators and professors, according to Proofpoint threat researchers. Proofpoint directly observed “less than 10” universities targeted in these intrusions, Greg Lesnewich, principal threat research engineer at Proofpoint, told The Register. “We estimate the total volume of targets would be a few dozen universities, but stress that this is at best a guess, not substantiated by our data.” While the most recent sighting occurred in early June, “we believe it is likely that the campaign is ongoing,” Lesnewich said. The email security shop tracks the crew as UNK_MassTraction, and says that it focuses on individuals in departments with national security ties or in astrophysics and particle physics - all topics that support Beijing’s intelligence-gathering goals and, as such, are frequently targeted by government-backed cyber goons. To gain initial access, the intruders exploit CVE-2024-42009, a cross-site scripting vulnerability in Roundcube that only requires that the email is opened in the mail client to achieve access to the server. “The targeted departments were likely specifically chosen because they were all running [vulnerable] versions of Roundcube … indicating that UNK_MassTraction had conducted reconnaissance into the targets prior to conducting the campaign,” the threat hunters wrote in a Tuesday blog. While the espionage activity is similar to an earlier campaign disclosed by Trellix that used a filename parsing vulnerability to deliver VShell malware, a Go-based backdoor used primarily by Chinese APT groups for remote access, file operations, and post-exploitation control, Proofpoint says it cannot definitely link this earlier activity to UNK_MassTraction. It all starts with a generic phishing email The UNK_MassTraction attack chain begins with a phishing email sent to university departments from both compromised legitimate senders and abused domains vulnerable to spoofing. According to the threat hunters, the lures are generic, sometimes purporting to be a university marketing message, and this could imply “a larger targeting swath” than Proofpoint observed. It could also indicate “an attempt to resemble marketing or spam content because targets may open the email but ultimately overlook it (and not investigate it), which is still sufficient for the actor to gain access,” they wrote. Opening the email triggers CVE-2024-42009. The bug abuses a desanitization issue, and can allow remote attackers to steal and send messages. Once the user opens the email in the webmail client of a vulnerable Roundcube instance, a JavaScript loader stored in the message body executes, and allows the attacker to remotely deliver a fully functioning stealer called IceCube. IceCube first escapes Roundcube's iFrame instantiation via DOM traversal, which gives the stealer access to the entire Document Object Model (DOM) in the browser and Roundcube authentication session. Then it sets to work stealing usernames, passwords, session tokens, and cookies, and it also conducts reconnaissance against the browser, collecting info on the language in use, screen size, and form field values. The stealer sends this initial data to the attacker’s command-and-control servers via HTTP POST, and then uses the session’s CSRF token to set up gadgets to exploit another Roundcube vulnerability. This one, a deserialization exploit tracked as CVE-2025-49113, allows the miscreants to install a webshell called SquareShell that allows for remote code execution, as well as a VShell implant. Proofpoint notes that its researchers scanned for SquareShell on compromised servers, and coordinated with government and industry partners to notify the identified victims. As of June, the threat hunters also observed the attackers introducing a fallback channel in case the original webshell deployment didn’t work. Previously, if the webshell didn’t execute, the attack chain would fail. More links to PRC-backed spies The fallback channel executes a shell script that sets up the execution of another loader that Google tracks as SnowLight. “The shell script has been used in other exploit-driven intrusions by Chinese adversaries, likely indicating a privately shared capability,” Proofpoint notes. Proofpoint’s security sleuths say that they have identified “several cases” of virtual private server IP addresses within the headers of the phishing emails that belong to a “covert infrastructure network likely used by multiple China-aligned threat actors.” The access to this network, along with the low-volume targeting of US and Canadian universities, VShell usage, and Chinese-language artifacts within the phishing emails, “leads us to assess that UNK_MassTraction is likely a China-aligned espionage motivated threat actor that has demonstrated moderate operational security awareness,” the team wrote.®
010
Matthias Schulze @percepticon.bsky.social · 10/07/2026
Microsoft patches RoguePlanet Defender zero-day vulnerability #cybersecurity #infosec
bleepingcomputer.com
Microsoft patches RoguePlanet Defender zero-day vulnerability
Microsoft has released a security patch to address a Defender zero-day vulnerability known as "RoguePlanet," disclosed after the June 2026 Patch Tuesday. [...]
010
Matthias Schulze @percepticon.bsky.social · 10/07/2026
Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images #cybersecurity #infosec
thehackernews.com
Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images
Meta has announced that its new artificial intelligence (AI) model Muse Image lets people use public Instagram posts and reels to generate AI content, and it's enabled by default. "You can also @-mention Instagram accounts in the Meta AI app to bring specific Instagram profiles right into your images," the social media giant said in a post. "Whether you want to design a custom event invitation
010
Matthias Schulze @percepticon.bsky.social · 03/07/2026
Cybersecurity Mission Creep in the US #cybersecurity #infosec
schneier.com
Cybersecurity Mission Creep in the US
Interesting paper: “Cybersecurity Mission Creep.” Abstract: Cybersecurity is experiencing mission creep. Policymakers are casting more and more problems as issues of cybersecurity. So reframed, wildly different policy issues, from misinformation, to child social media safety laws, to antitrust regulations, to alleged journalist misconduct, to anti-sex trafficking statutes become what this Article calls “cybersecuritized.” Before this reframing, these issues present as important but not existential. But once cybersecuritization positions the issues as threats intensified by their technological nature, they gain access to the politics and law of urgency and exceptionalism and invite troubling governance responses. Positioned as security threats, cybersecuritized issues become endowed with the apparent normative power to override countervailing considerations, oversimplifying the problem. Cybersecuritization’s oversimplification similarly risks unidimensional solutions and invites use of argumentative trump cards, like First Amendment challenges. Cybersecuritization also invites deference to purported specialists and their proposed solutions. Together, the reductive tendencies of cybersecuritization and the deference it prompts to specialists renders ultimate governance choices more opaque. And this opacity can erode public trust and political legitimacy. This Article surfaces the phenomenon of cybersecuritization and offers a novel framework for analyzing and critiquing it. Mining cases from across criminal and civil domains, the account also demonstrates the insidiousness of cybersecuritization and the likelihood that it will continue to expand. Confronting cybersecuritization is crucial. If we continue to ignore it, we risk abdicating further responsibility for difficult choices to the trump card of cybersecurity. This Article’s analysis and critique aim to help reclaim the hard work of governance for our hands.
012
Matthias Schulze @percepticon.bsky.social · 16/06/2026
French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker #cybersecurity #infosec
securityweek.com
French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker
French officials say roughly 73,000 government accounts were affected, while the threat actor claims to have stolen messages and user data from the sovereign Tchap platform. The post French Government Messaging Platform Breached by Mysterious ‘Misere’ Hacker appeared first on SecurityWeek.
010
Matthias Schulze @percepticon.bsky.social · 15/06/2026
Council of Europe hacked in ShinyHunters' PeopleSoft heist #cybersecurity #infosec
theregister.com
Council of Europe hacked in ShinyHunters' PeopleSoft heist
ShinyHunters claims to have breached the Council of Europe and stolen more than 297 GB of data after exploiting a zero-day flaw in Oracle PeopleSoft and abusing that hole to hack more than 100 organizations. According to a post on the extortion crew’s data-leak site, the 429,000 pilfered files contain HR and payroll records, payslips, purchase-order records, CVs, and employees’ salary, banking, tax, and medical records. A Council of Europe spokesperson told The Register that it is “currently investigating the matter and assessing the situation,” but declined to comment further. A spokesperson for the cybercrime group told us that the Council is yet another victim of the Oracle PeopleSoft heist. Oracle has yet to respond to The Register’s inquiries, and it's unclear if the vulnerability, tracked as CVE-2026-35273, has been patched. ShinyHunters previously told us that the gang exploited the CVE to compromise more than 100 organizations across 300 vulnerable instances, and that these victims included the University of Nottingham. Last week, the crims listed the UK uni on their leak site, then dumped data belonging to around 454,600 current and former students, including personal and academic records. Meanwhile, a Google threat report published late last week noted malicious activity, “consistent with the exploitation of CVE-2026-35273,” between May 27 and June 9, and said that its incident responders notified more than 100 global orgs “whose IP addresses correlated with potentially vulnerable endpoints." Most of these are US-based organizations, and 68 percent operated within the higher education sector. This latest heist follows another ShinyHunters intrusion targeting data belonging to university and K-12 students, teachers, and staff. In mid-May, ed-tech giant Instructure said it “reached an agreement” - this is corporate-speak for “paid the ransom demand” - with the data theft and extortion crew after ShinyHunters breached its Canvas digital learning platform and accessed data tied to 275 million students, teachers, and staff. In March, ShinyHunters claimed it stole data from K-12 software provider Infinite Campus as part of a broader wave of Salesforce-related intrusions. The ed tech company did not pay up, and the group subsequently published data they claim was stolen from Infinite Campus, including 137,000 individuals’ email addresses along with names, phone numbers, physical addresses and support tickets. Infinite Campus, in its data breach notification, said that the leaked files largely consisted of “names and contact information for school staff" and that “the majority is directory information commonly found on school websites.” ®
011
Matthias Schulze @percepticon.bsky.social · 09/06/2026
France probes compromise of gov messaging platform after account hijack #cybersecurity #infosec
theregister.com
France probes compromise of gov messaging platform after account hijack
French officials are investigating a compromise of the government’s encrypted messaging service Tchap after attackers hijacked an account and gained access to public chat rooms. The incident came to light on June 7 when France's National Cybersecurity Agency (ANSSI) detected suspicious activity on Tchap, the government's homegrown messaging service used across ministries and public sector organizations. The French Digital Affairs Directorate (DINUM), which operates the platform, said it immediately began investigating the compromise and moved to block the affected account. French officials insist the damage was limited and said the attacker could only see messages posted in public chat rooms, which are accessible to all Tchap users. Private conversations, the government says, are encrypted, and their contents remain inaccessible even when an account is compromised. Not everyone is buying that version of events. A cyber criminal has claimed responsibility for the attack and said they were able to gain access after they “social engineered” a valid agent account associated with Tchap's education environment. The alleged hacker claims they accessed more than 73,000 user accounts, 643,000 messages, nearly 60,000 media files, and hundreds of chat rooms. The post, shared by Dark Web Intelligence, also claimed user enumeration was possible through a directory search function and suggested the data included references to documents marked "Diffusion Restreinte," a French government restricted-distribution classification. None of those claims have been independently verified, and DINUM's statement makes no mention of user directory exposure, restricted documents, or the volumes of data cited by the hacker. What French officials have confirmed is that investigators are still working through logs to determine exactly which conversations were accessed and whether any data was exfiltrated. The agency has also notified France's data protection watchdog, CNIL, after determining that personal information may have been exposed through content shared in conversations accessible to the attacker. “A message has been sent to all Tchap users reminding them that a public chat room can be found and joined by any user and that its content is not encrypted,” French officials added. “In accordance with Tchap's terms of service, no personal, sensitive, or confidential information should be exchanged in public chat rooms: such exchanges should be reserved for private chat rooms.” Whether the incident amounts to a limited exposure of public chat rooms or something considerably larger will depend on what investigators find in the logs, but for now, the government and the attacker are telling very different stories. ®
030
Matthias Schulze @percepticon.bsky.social · 09/06/2026
GPS As a Key Distribution Platform #cybersecurity #infosec
schneier.com
GPS As a Key Distribution Platform
This is interesting: The U.S. military has likely been quietly broadcasting codes for its global encryption network using public GPS for nearly 20 years, turning each satellite into a hidden “numbers station,” according to Steven Murdoch… That means every device that uses GPS has been receiving hidden government information for years, and nobody outside the military knew it until now. […] Murdoch discovered that this particular sentinel was transmitted by all 31 operational satellites within a window of a few hours on May 26, 2011, potentially heralding the activation of a new operational system. He confirmed that this timeline coincided with the rollout of the military’s Over-the-Air Distribution (OTAD) and the Over-the-Air Rekeying (OTAR) by cross-referencing declassified documents, including a 2015 presentation about the dates of the operation. “There was a perfect match between the timeline and that presentation and the change points that were automatically identified from the data,” Murdoch said. “That was the smoking gun that made me think: This is what it’s for.” These automated systems replaced the cumbersome manual distribution of cryptographic keying material, allowing military GPS receivers around the world to be rekeyed remotely through satellite broadcasts rather than through onsite procedures.
000
Matthias Schulze @percepticon.bsky.social · 09/06/2026
Tests suggest Russian satellites can jam GPS on a continental scale #cybersecurity #infosec
arstechnica.com
Tests suggest Russian satellites can jam GPS on a continental scale
Russian satellites have been identified as the cause of mysterious, seconds-long bursts of GPS interference across Europe—a rare example of human-made GPS interference coming from space. But uncertainty still hangs over whether such interference is intentional and if it could be more powerfully weaponized as GPS jamming with continental reach in the future. The discovery came from an investigation detailed in a June 2 preprint paper by Todd Humphreys and his student Zach Clements at The University of Texas at Austin, along with Argyris Krizise at Stanford University in California. By sifting through public data from ground-based stations with global navigation satellite system (GNSS) receivers, they identified a pattern of high-powered interference lasting less than 10 seconds each time but simultaneously detectable by ground stations across Europe from Norway to Spain to Poland, and even reaching as far west as Greenland and Canada. By analyzing the ground station data from January 2019 to April 2026, the researchers found 75 days with at least one widespread GNSS interference event overlapping with the GPS L1 frequency band centered on 1575.42 megahertz. That represents the main band used for signal transmission by the US-made GPS satellite constellation and GNSS constellations from other countries. Read full article Comments
013
Matthias Schulze @percepticon.bsky.social · 05/06/2026
Russia claims foreign spy agencies hacked officials' phones #cybersecurity #infosec
therecord.media
Russia claims foreign spy agencies hacked officials' phones
In a statement, Russia's Federal Security Service (FSB) said it had uncovered what it described as a "large-scale operation" involving malicious software installed on the mobile devices of senior Russian officials.
010
Matthias Schulze @percepticon.bsky.social · 05/06/2026
Smartphones hacken, Gesichter scannen: CDU, SPD und BSW wollen Überwachung in Sachsen ausweiten #cybersecurity #infosec
netzpolitik.org
Smartphones hacken, Gesichter scannen: CDU, SPD und BSW wollen Überwachung in Sachsen ausweiten
Die Polizei in Sachsen soll Menschen umfangreicher überwachen dürfen als je zuvor. BSW, CDU und SPD einigen sich auf die vielfach kritisierte Novelle des Polizeirechts. Entschärft wurde wenig, Opposition und Zivilgesellschaft haben kaum noch Zeit. Sachsens Innenminister Armin Schuster (CDU) – Alle Rechte vorbehalten: IMAGO / EHL Media In Sachsen haben sich die Fraktionen von CDU und SPD mit dem BSW auf eine Verschärfung des dortigen Polizeige­setzes geeinigt. Damit hätte die Novelle bei der bevorstehenden Abstimmung eine Mehrheit im Landtag – wenn auch eine äußerst knappe. Der netzpolitik.org vorliegende Ände­rungsantrag zeigt, an welchen Stellen die Fraktionen den Entwurf der Staatsregierung entschärft ha­ben und welche neuen Befugnisse zur Überwachung dennoch kommen sollen. Aus Gründen des Quellenschutzes können wir das Dokument allerdings noch nicht als Volltext veröffentlichen. In Sachsen koalieren CDU und SPD in einer Minderheitsregierung. Gesetzesvorhaben wie die Novelle des Polizeirechts brauchen daher zusätzliche Stimmen von AfD, BSW, Grünen oder Linken. Dass das BSW in diesem Fall die Mehrheit für Innenminister Armin Schuster (CDU) beschaffen würde, hatte sich bereits früh angedeutet. Hacken, filmen, scannen Mit ihrer Einigung wollen die drei Fraktionen weitreichende neue Befugnisse zur Überwachung schaffen. So soll die Polizei in Sachsen künftig mehr Computer und Smartphones hacken dürfen, denn die sogenannte Quellen-TKÜ wird auch für die Gefahrenabwehr eingeführt. Teil des Gesetzentwurfs ist weiterhin die Einführung von Gesichter- und Stimmensuche im Internet. Ein Sachverständiger hatte im Innenausschuss gewarnt, dass der von Innenminister Schuster getaufte „Klette-Paragraf“ gegen die KI-Verordnung der EU verstößt. Allerdings sehen manche darin Schlupflöcher. Auch die Befugnisse zur KI-Video-Überwachung haben die Verhandler:innen im Vergleich zum Regierungsentwurf kaum verändert. Es bleibt also dabei, dass die Polizei künftig an Kriminalitätsschwerpunkten Soft­ware einsetzen darf, die gefährliche Objekte oder Verhalten erkennen soll. Ebenso ist eine Live-Gesichtserkennung geplant. Sie soll Personen identifizieren und über mehrere Kameras hinweg verfolgen können. Treffen soll es Menschen, die zuvor durch Verhaltensscanner und Beamt:innen ins Visier geraten sind. Außerdem soll die Polizei damit nach Menschen suchen können, bei denen sie Terrorgefahr ver­mutet. Eine solche Identifizierung unterliegt einem Richtervorbehalt; bei Gefahr in Verzug dürfen sie aber auch bestimmte Polizist:innen anordnen. Datenanalyse, aber ohne Palantir Auf Abschwächungen gegenüber dem Kabinettsentwurf einigten sich BSW, CDU und SPD vor al­lem bei der automatisierten Datenanalyse und dem Training und Test von KI-Systemen. Eine Analyseplattform soll Daten der Polizei verknüpfen und automatisiert auswerten. Unter be­stimmten Voraussetzungen sollen auch selbstlernende Systeme zum Einsatz kommen und Verhal­tensprofile entstehen. Im Unterschied zu Bayern, Hessen und NRW soll in Sachsen dafür al­lerdings keine Software der Firma Palantir zum Einsatz kommen. Darauf hatten sich CDU und SPD bereits im Kabinett geeinigt. Zudem soll das neue Sächsische Polizeivollzugsdienstgesetzes (kurz: SächsPVDG) folgende Vorschrift enthalten: Alles netzpolitisch Relevante Drei Mal pro Woche als Newsletter in deiner Inbox. Jetzt abonnieren Der Ein­satz von Systemen, deren Entscheidungslogik nicht nachvollziehbar und überprüfbar offengelegt werden kann, ist unzulässig. Nach Ansicht von Bernd Rudolph, innenpolitischem Sprecher der BSW-Fraktion, lasse sich damit der Einsatz proprietärer Systeme quasi ausschließen. Stephanie Henkel, die sich etwa beim Dresdner Chaos Computer Club (C3D2) gegen Überwachung engagiert, hält das für unrealistisch: „Für die hochkomplexen Programme, die zur Datenanalyse eingesetzt werden sollen, kann gar keine solche Nachvollziehbarkeit hergestellt werden.“ Der Wunsch nach Transparenz würde eine zwingende Streichung großer Datenbank-Analysen bedeuten. „Doch davon sind CDU, SPD und BSW weit entfernt“, so Henkel, die im Netz auch als ÜckÜck auftritt. Die Einigung von BSW, CDU und SPD schließt zudem eine direkte Anbindung der Analyseplatt­form an das Internet aus. Auch die zunächst vorgesehene Erlaubnis, „einzelne gesondert gespeicher­te Datensätze aus Internetquellen“ einzubeziehen, wurde gestrichen. Zudem greift der Richtervorbe­halt nun schon bei der automatisierten Datenanalyse, nicht erst beim Einsatz selbstlernender Syste­me oder dem Erstellen von Verhaltensprofilen. Kennzeichen erfassen, mit Bodycams filmen Die geplanten Vorschriften für das KI-Training sind nach wie vor umfassend, wurden jedoch im Vergleich zum Kabinettsentwurf leicht abgemildert. Die Daten sollen demnach mindestens pseudonymisiert sein. „Um die Ausbildung diskriminierender Algorithmen zu vermeiden, sollen zusätzlich Echtdaten aus zerti­fizierten Datenbanken genutzt werden“, erklärt Albrecht Pallas, innenpolitischer Sprecher der SPD-Fraktion in einer Mitteilung. Zwar soll die Polizei für Training und Test von KI-Systemen künftig mit externen Dienstleistern zusammenarbeiten, allerdings nur mit solchen, „deren Firmensitz und Serverstrukturen innerhalb der Europäischen Union liegen“, wie es im gemeinsamen Änderungsantrag heißt. Weitere Entschärfungen beschränken sich auf Details. So wurde bei der neuen Befugnis zum verdeckten Scan von Autokennzeichen festgehalten, dass es vorher Ansatzpunkte für Straftaten von „grenzüberschreiten­der Relevanz“ geben muss. Das potenzielle Grenzgebiet – bis zu 30 Kilometer Entfernung von Polen und Tschechien – umfasst allerdings die Hälfte Sachsens. Mit Bodycams soll die Polizei künftig auch in Wohnungen filmen dürfen. Allerdings hat das BSW hier die Bedingung durchgesetzt, dass der Einsatz nur zulässig sei, „sofern damit nicht die Überwachung der Wohnung verbunden ist“. Doch keine Taser für alle Das BSW brüstet sich zudem damit, die Einführung von Tasern – also Elektroschockern – für alle Polizist:innen verhindert zu haben. „Damit tragen wir auch den Bedenken vieler Polizeibeschäftigter Rechnung, die den zusätz­lichen Nutzen im Alltag kritisch bewerten“, lässt sich Jens Hentschel-Thöricht zitieren, Parlamenta­rischer Geschäftsführer des BSW. Es bleibt in Sachsen also dabei, dass nur Spezialkräfte der Polizei Taser tragen dürfen. Die Abkehr von Tasern fällt aus der Reihe: Sie ist nicht Teil des gemeinsamen Ände­rungsantrags mit CDU und SPD, sondern kommt als eigener Änderungsantrag zur finalen Abstim­mung des Gesetzes im Landtagsplenum. Dennoch ist auch hier die Zustimmung von CDU und SPD vereinbart, heißt es vonseiten der Fraktionen. Das BSW beruft sich darauf, dass der Antrag „derzeit noch rechtssicher erarbeitet“ wer­de. Möglicherweise will das BSW die Einigung durch dieses Manöver als besonderen Erfolg hervorheben. Das könnte auch ein Signal an die eigenen Reihen sein, denn die Polizeirechtsno­velle ist auch innerhalb des BSW umstritten. Erst kürzlich hatte das BSW sogar ein länder­übergreifendes Positionspapier zu den Polizeirechtsnovellen in Brandenburg, Thüringen und Sach­sen veröffentlicht. Darin schreibt Parteivorsitzende Amira Mohammed Ali: „Wir treten entschieden dem Im­puls der Innenminister entgegen, Bürger grenzenlos zu durchleuchten und zunehmend unter Gene­ralverdacht zu stellen.“ Wir sind ein spendenfinanziertes Medium. Unterstütze auch Du unsere Arbeit mit einer Spende. Jetzt spenden Konkret warnt das Papier vor algorithmischer Bewertung statt polizeili­cher Expertise. Zur Wirkung von KI-Videoüberwachung fehle wissenschaftliche Evidenz. Unmut in der BSW-Fraktion Dass mit den Stimmen des BSW nun trotzdem Quellen-TKÜ und Verhaltensscanner nach Sachsen kommen, schmeckt nicht allen BSW-Ab­geordneten. So hat die 15 Sitze starke BSW-Fraktion nach einem Bericht der Freien Presse (€), der sich mit netzpolitik.org-Informationen deckt, lediglich elf Stimmen für die SächsPVDG-Novelle zugesichert. Damit hätte die Polizeirechtsnovelle eine sehr knappe Mehrheit – mit nur einer Stimme mehr als nötig. Die drei Fraktionen feiern sich dennoch für den Kompromiss: „Mit dem neuen Gesetz erhält Sach­sens Polizei wichtige und zeitgemäße Möglichkeiten zur Verbrechensbekämpfung“, sagt Ronny Wäh­ner, innenpolitischer Sprecher der CDU. „Wir halten damit Schritt mit der Entwicklung moderner Polizeigesetze in anderen Bundesländern.“ Der SPD-Abgeordnete Pallas teilt mit, mit den nun verein­barten Änderungen „schaffen wir ein zeitgemäßes Polizeigesetz, das Sicherheit und Freiheit glei­chermaßen Rechnung trägt“. Bernd Rudolph vom BSW betont: „Mit diesem Kompromiss stellen wir sicher, dass die sächsische Polizei moderne Technik nutzen kann, ohne dass die Privatsphäre der Bürgerinnen und Bürger unverhältnismäßig eingeschränkt wird.“ „Unterm Strich ein Desaster“ Vehementer Widerspruch kommt aus der Zivilgesellschaft. Stephanie Henkel, die sich neben dem C3D2 auch bei der Piratenpartei und den Datenpunks engagiert, bereitet die Ankündigung nach eigenen Worten große Sorgen. „Unterm Strich ist das, worauf sich die drei Parteien geeinigt haben, ein Desaster“, bilanziert sie. Im Vergleich zum Kabinettsentwurf sieht sie nur einzelne Verbesserungen: etwa dass die Polizei keine Klardaten für KI-Trainings nutzen soll, oder dass nur EU-Dienstleister die für dieses Training notwendigen Daten bearbeiten sollen. Aber „die wirklich demo­kratiegefährdenden Änderungen“, wie die Quellen-TKÜ, Mustererkennung und Gesichtsscans stünden nach wie vor im Gesetz. Stephanie Henkel ruft deshalb dazu auf, die Abgeordneten von BSW, CDU und SPD zu kontaktie­ren. „Die vermeintlich gefühlte Sicherheit, die die neuen Technologien bringen soll, ist keine Si­cherheit, sondern ein gefährliches Werkzeug, was nicht nur gegen uns als Bevölkerung, sondern auch gegen die Politiker:innen, die jetzt den Gesetzesentwurf vorantreiben, eingesetzt werden kann.“ Man könne nicht vorhersagen, was eine andere sächsische Regierung mit den neuen Befug­nissen und den damit gewonnen Informationen anstelle. Wenig Zeit für Widerstand Auch wenn die Mehrheit für den Gesetzentwurf sehr knapp ist – es bleibt wenig Zeit für öffentlichen Druck. Am 11. Juni werden die Abgeordneten im Innen­ausschuss über den gemeinsamen Änderungsantrag von BSW, CDU und SPD abstimmen. Wie die meisten Ausschusssitzungen im Landtag ist auch dieser Termin nicht öffentlich. Eine echte Debatte gibt es dann voraussichtlich erst am 24. Juni. Dann soll im Plenum des Sächsischen Landtags die Polizeirechtsnovelle final abgestimmt werden. Die Abstimmung zu verschieben dürfte für die Abgeordneten keine Option sein. Wegen eines Urteils gegen das ak­tuelle SächsPVDG gelten einige aktuelle Befugnisse der Polizei nur bis Ende Juni 2026 – außer es kommt ein neues Gesetz. Selbst Grüne und Linke, die die vorgelegte Novelle ablehnen, wollen dieses Szenario verhindern. Die Grünen haben deshalb einen eigenen Entwurf für ein Polizeigesetz ohne weitreichende Befugnisse zur Überwachung vorgelegt. --- Die Arbeit von netzpolitik.org finanziert sich zu fast 100% aus den Spenden unserer Leser:innen. Werde Teil dieser einzigartigen Community und unterstütze auch Du unseren gemeinwohlorientierten, werbe- und trackingfreien Journalismus jetzt mit einer Spende.
020
Reposted by Matthias Schulze
404 Media @404media.co · 25/05/2026
“It's making me dumber for sure.” www.404media.co/software-dev...
404media.co
Software Developers Say AI Is Rotting Their Brains
“It's making me dumber for sure.”
9372101