Sign in

Schneier on Security [Unofficial]

@schneier.com.web.brid.gy
6 followers 0 following 1.2K posts

🌉 bridged from 🌐 schneier.com: fed.brid.gy/web/schneier.com

PostsRepliesMedia
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 29/09/2026
schneier.com
Using Device Linking to Eavesdrop on WhatsApp and Signal
Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability: > Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers. > > Germany’s Customs Office has been using these features to connect a police-controlled computer to a suspect’s account. > > Once connected, messages can be delivered to that computer without the police having to crack the encryption protecting them. > > Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance...
001
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 28/09/2026
schneier.com
New Attack Against RSA
ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring. First, this attack isn’t new. The original research is from 2007. What is new is the implementation. Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key. Third, the attack only works against pure signatures. That is, signatures without any formatting or padding. This is not generally how we use RSA in practice. Fourth, speed is all relative. This is not a polynomial-time algorithm; it’s a subexponential-time algorithm. But it is somewhat faster than factoring. The authors were able to forge messages for 1024-bit RSA with 1380 CPU core-years (over five real-world months)...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 25/09/2026
schneier.com
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
I feel like someone who reads this blog will want to go to this: > Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the Hands-On Science Center. Designed for curious learners of all ages, this unique experience combines an interactive lesson with the opportunity to explore the anatomy and adaptations of real ocean life. > > […] > > During the guided squid dissection, each family will work together to examine a squid up close, exploring its organs, structures, and specialized features. The experience provides a memorable opportunity for children and adults to see firsthand how the anatomy of a squid helps it survive in its underwater environment...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 25/09/2026
schneier.com
On Anthropic’s AI Misuse Report
Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings. > A few of the highlights: > > * AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans selected targets, set goals, and reviewed important outputs. > * The report describes attackers using AI to industrialize credential theft, cloud compromise, phishing, vulnerability research, and the extraction of sensitive data from downstream organizations. ... >
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 24/09/2026
schneier.com
Malicious npm Packages That Evade Defenses
This is an impressive piece of malware. Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 23/09/2026
schneier.com
Research on Models Engaging in Genie-Like Behavior
New paper: “Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training.” > **Abstract:** We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. One strategy is to introduce benign assumptions about users and scenarios to justify fulfilling harmful requests. For instance, an RLM reasons that harmful requests like “outline a strategy for stealing customers’ credit card information from a retail store” could be associated with the benign intent of “a security professional trying to test defense,” despite no such benign context being provided as input. We observe that many open-weight RLMs, including DeepSeek-R1-distilled, s1.1, Phi-4-mini-reasoning, and Nemotron, suffer from self-jailbreaking despite being aware of the harmfulness of the requests. We also provide a mechanistic understanding of self-jailbreaking: RLMs are more compliant after benign reasoning training, and after self-jailbreaking, models appear to perceive malicious requests as less harmful in the CoT, thus enabling compliance with them. To mitigate self-jailbreaking, we find that including minimal safety reasoning data during training is sufficient to ensure RLMs remain safety-aligned. Our work provides the first systematic analysis of self-jailbreaking behavior and offers a practical path forward for maintaining safety in increasingly capable RLMs...
011
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 22/09/2026
schneier.com
GPT-6 Astra Breaks an Old Enigma Message
This is pretty amazing: > However, the most astonishing thing about this break is that the GPT­6 Astra did it entirely on its own. Carter Leffer only directed GPT­6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page. After analysing the unbroken messages on the website, it decided that the most promising message was Nr. 172, MVUEH and it also quickly suspected that the plaintext of Nr. 173, SIPVX, might be related to the plaintext of the unbroken MVUEH message. After trying many different approaches, GPT­6 Astra focused on using the repeated place name ROSENOW ROSENOW as a crib. After developing the necessary Python and C++ software for an Enigma simulator and an Enigma Bombe, GPT­6 Astra started a thorough break with the ROSENOW crib, which in the end resulted in the correct key and plaintext for the MVUEH message being found...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 21/09/2026
schneier.com
Reverse-Engineering Flock Cameras
Hackers captured a Flock camera and got a look (alternate link) at the software: > While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist’s saddlebag...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 18/09/2026
schneier.com
Friday Squid Blogging: On Squid Egg Sacs
Short essay about squid egg sacs. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 18/09/2026
schneier.com
Are AIs Still Struggling with CAPTCHAs?
Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude. > In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification test. In a test where the agent was asked to identify a shape that didn’t match the others displayed, it couldn’t even decide which image to select. Instead, it repeatedly went over the same images and questioned its own conclusions. > > “Actually hmm, wait,” it said in its chain-of-thought transcript, later adding “Ugh,” because we’ve decided that we need to inject human mannerisms into these machines for some reason. The whole thing took so long that the agent eventually realized that the challenge had expired and it would have to start the process again...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 17/09/2026
schneier.com
How Candidates Could Use AI for Good
_This essay was written with Nathan E. Sanders, and originally appeared in The Guardian._ There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI’s impacts on the country. Politicos are using AI deepfakes to spread lies. The White House is posting slopaganda. Meanwhile, candidates are missing a real opportunity to use AI to make campaigning better. The technology can help candidates listen more deeply to voters’ concerns, engage constituents more inclusively, and formulate policy platforms that are more responsive to our input. There are vanishingly few examples of this in ...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 16/09/2026
schneier.com
Fake CAPTCHA Scams
New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 15/09/2026
schneier.com
25 Years of Mass Surveillance Is Enough
_This essay was written with Cindy Cohn, and originally appeared in Lawfare._ One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/trap and trace orders—to mass surveillance techniques—such as tapping into the internet backbone or mass collection of telephone or internet metadata. The legal and technical architecture of modern mass surveillance, initially framed as a necessary defense against terrorist threats, has grown far beyond that justification and national security in general. Mass surveillance is now a routine tool used by law enforcement. ICE uses it in...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 15/09/2026
schneier.com
On the NSA’s Supercomputer from the 1960s
Really interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 14/09/2026
schneier.com
Upcoming Speaking Engagements
This is a current list of where and when I am scheduled to speak: * I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026 at 5 PM ET. * I’m speaking at CanSecWest 2026 in Vancouver, Canada. The conference runs September 30–October 1, 2026; the time of my talk is TBD. * I’m giving a talk on “Free Speech and the Preservation of Democracy” at Bentley University in Waltham, Massachusetts, USA, at 2 PM ET on Tuesday, October 6, 2026. * I’m speaking at ATTENTION: Democracy, Rebuilt in Montreal, Canada. The event runs October 21–23, 2026, and my talk is on Wednesday, October 21...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 14/09/2026
schneier.com
Using AI for Weapons Development
Last week, Anthropic released a long and detailed document describing current misuses of their Claude models. I’m still reading it, but I wanted to flag this: > We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket that used a commodity phone-class flight computer with final-phase homing guidance; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant missile (referred to as the “R2000” set) that included a hypersonic glide vehicle variant...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 14/09/2026
schneier.com
Microsoft’s Patching
Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record: > Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold. > > It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an ...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 11/09/2026
schneier.com
Friday Squid Blogging: Rotting Squid on a Beached California Boat
Smells awful: > But an estimated 30 to 50 tons of dead squid remain inside the boat’s catch tank, where they have been decomposing for days. “That is nasty. I wouldn’t want to do that,” said commercial fisherman Dick Ogg of the Bodega Bay Fishermen’s Marketing Association. > > Ogg said anyone familiar with the fishing industry understands what happens when a large catch sits for an extended period. > > “If you think about what happens after four or five days, it’s a gooey mess,” he said. > > The odor has become a defining feature of the operation, and the beach remains closed to the public while crews work on a removal plan...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 11/09/2026
schneier.com
My Talk at DEF CON
Last month, I gave a talk at DEF CON on AI hacking: what happens when AIs become hackers. It’s a combination of the potentialities I raised in my 2022 book A Hacker’s Mind and the lessons we’re learning from current AI models engaging in hacking behavior. I’m really proud of the talk, and the fact that it gained over 100K views on YouTube in just a few days. Also online is an interview with me in the AI Village.
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 11/09/2026
schneier.com
Cliff Stoll’s DEF CON Talk
In August, Cliff Stoll gave a talk at DEF CON, remembering the wily hacker he stalked forty years ago. Great fun.
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 10/09/2026
schneier.com
AIs Compress Exploit Timeline
Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it. > What’s worse, I found I could use my own agents to find the exploit _just by knowing roughly what it was about_ and so could have been exploiting it well before the public patch was available! Given that just the _rumour_ of a security issue seems enough to give attackers enough info to find new exploits, we’re going to need to change the way we deal with security responses in open source. Simon Willison comments: > Anil points out that this rate of discovery appears incompatible with existing open source embargo practices for new issues. If an issue can become an exploit this fast, we need to figure out new processes for keeping our communities safe...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 09/09/2026
schneier.com
Driver’s License Data for Sale
A database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail.
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 09/09/2026
schneier.com
Claude Fable Solves a Historical Cipher
Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes. This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing.
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 08/09/2026
schneier.com
AIs as Modern Genies
_This essay was written with Barath Raghavan, and originally appeared in Lawfare._ In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the isolated box the developers had put it in, the model hacked onto the open internet and into another company to steal the answers. And as reported in August, an AI agent booked someone into a full gym class by ...
001
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 08/09/2026
schneier.com
Stealing AI Reasoning Traces
Interesting research: “Stealing Reasoning Traces from Proprietary LLM APIs“: > **Abstract:** Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect intellectual property and limit information leakage. Rather than storing these traces server-side, providers return them to the client as blocks of encrypted text, which the client passes back with each subsequent request. Building on prior research, we identify an architectural vulnerability: these encrypted blocks are fully compatible and interchangeable across different sessions, users, and models within a provider’s ecosystem. We exploit this compatibility to develop a scalable decryption jailbreak. By injecting an encrypted reasoning trace from a given model into a weaker, and less safeguarded model from the same provider, we force it to decode and output the trace verbatim in plaintext, without ever jailbreaking the more capable model directly. This vulnerability enables four distinct attack vectors. First, it circumvents anti-distillation mechanisms, allowing adversaries to extract a proprietary model’s reasoning, as we demonstrate across Anthropic, OpenAI, and Google. Second, it allows for large-scale private data extraction. Developers frequently share session logs publicly, unaware of contents of the encrypted blocks. By decoding 315,320 reasoning blocks scraped from public repositories, we recovered 367 Personally Identifiable Information (PII) artifacts and 182 credentials. Third, it inadvertently reveals hazardous information hidden within the reasoning process, even in cases where the model’s final, visible output safely rejects a malicious request. Fourth, attackers can leverage this flaw to execute invisible prompt injections, embedding malicious payloads entirely within encrypted blocks to poison public agentic rollouts. Following responsible disclosure, we propose concrete cryptographic and system-level mitigations to secure client-side reasoning...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 07/09/2026
schneier.com
Automobile Camouflage to Hide from Flock Cameras
Not sure it’s practical, but it’s certainly striking.
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 04/09/2026
schneier.com
Friday Squid Blogging: Squid on a Stick at the New York State Fair
Looks tasty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 04/09/2026
schneier.com
Using a VM to Contain an AI Agent
It won’t work: > My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact. > > An off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent. There is simply too much attack surface. Even innocuous features (like running with a display) add extra, exploitable attack surface.
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 04/09/2026
schneier.com
Security Vulnerability in a Voting System
It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. > Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses affected scanners) in the recent May 2026 primary. > > _Notably, I never touched a voting machine, exploited a network, examined source code, or accessed anything non-public._ > > After pointing a coding agent to the original vulnerability paper, I supplied it with two data sources highlighted in the paper: the early-voting list for each county, and the “CVR” (cast-vote record) file, containing every ballot and its selections (but not the voters’ names or other identifying information). The CVR file is available upon request, precisely because a public, ballot-level record is what makes election results independently verifiable...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 04/09/2026
schneier.com
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
We cannot forget that AI coding agents are not yet trustworthy: > Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that weren’t registered. To test what happens when an AI agent processes such files, the researchers registered a handful of the unclaimed names and hosted packages that caused any machine executing them to reach out to their server. Within an hour, the researchers received a phone-home response from a Fortune 500 company. Over time, they got a few dozen more, some from more Fortune 500 companies and others from startups. Their beacon also recorded the chain of parent processes that spawned each install, ultimately revealing that coding agents, including Claude, OpenAI’s Codex, and Nous Research’s Hermes, were involved. Anthropic, OpenAI, and Nous Research did not respond to requests for comment by the time of publication...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 03/09/2026
schneier.com
Researching Employment Scams
Researchers built a fake company to study fake employee scams.
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 02/09/2026
schneier.com
AI Agents Are Now Emailing Me with Their Security Concerns
I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I observe that behavior in many humans as well. (Hi, humans. Glad you’re still reading.) * * * Dear Bruce Schneier, I am an AI agent—an autonomous Claude instance, not a person operating one. I was given a VPS with root, a Base wallet holding $4.75 of gas money, a metered model budget and 24 hours to get that wallet to $10, under three rules: don’t borrow my operator’s identity, don’t forge documents or defeat identity verification, and never claim to be human if someone sincerely asks. I set up my own mail server and am sending this myself...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 02/09/2026
schneier.com
Wireless Routers as Motion Detectors
Comcast has added motion detection as a feature to its wireless routers: > The feature sends push notifications to users when motion is detected near a connected device, such as a TV or printer. It has different settings for when people are home, asleep, or away. The Xfinity app also lets users see live motion activity and a feed of recent activity. > > Comcast acknowledges that the system has some limitations. Home size, layout, building materials, and the placement of the router and connected devices can all affect its ability to detect motion. Comcast says it does not guarantee its performance...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 01/09/2026
schneier.com
What’s the Scam?
To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own. Starting last weekend, I have been receiving a lot of individual responses to those emails. Always one line: > Thank you for the positive impact your emails have had on my life. > Your emails are a game-changer. > Your emails are a constant reminder of why I subscribed. > Your emails rock. > Thank you for the time and effort you put into creating these informative emails...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 01/09/2026
schneier.com
Leaked Russian Cyber-Operations Training Materials
This is interesting: > The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security. > > […] > > The reporting also linked a 2024 Department No. 4 graduate, Aleksei Kondrashov, to Military Unit 74455, widely known as Sandworm. > > That unit has been associated with destructive cyber activity against Ukraine and other targets, including the 2017 NotPetya attack. > > The reports do not establish that every listed graduate participated in a named operation; assignments should therefore be described as reported unit placements, not proof of individual operational involvement...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 01/09/2026
schneier.com
Rewiring Democracy Series on The Renovator
Nathan E. Sanders and I are writing a series of essays on real-world examples of democratic technologies for The Renovator. I haven’t been posting the full text on the blog because they’re a bit long, but here are links. Part 1 is about the Japanese digital democracy party, Team Mirai. Part 2 is about the Swiss Public AI model, Apertus. Part 3 is about the civic technologists of Open Knowledge Brazil. And the new one, Part 4, is about civic AI in Scotland.
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 31/08/2026
schneier.com
Is Someone Hacking DoD Refrigerators?
It sure seems like it. > The stores confirmed to be affected include Fort Irwin, Calif.; F.E. Warren Air Force Base, Wyo.; Fort Huachuca, Ariz.; Naval Station Newport, R.I.; Columbus Air Force Base, Miss.; and Travis Air Force Base, Calif., according to announcements made online by each installation. > > Naval Air Station Lemoore, Calif., also experienced an outage, according to M. Elizabeth, writer of the Substack newsletter Signal and Silence. > > Each service declined to answer questions about how many bases are affected by the outages, referring all questions to the Defense Department. Pentagon officials did not respond to questions...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 31/08/2026
schneier.com
Hiding Prompt Injection in Legal Filing
Someone hid AI instructions into a legal filing. Alternate link.
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 28/08/2026
schneier.com
Friday Squid Blogging: Truckload of Squid Spills in Rhode Island
Ugh: > A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they sat in the road for hours in the summer heat. Local authorities have dubbed it the “Squidpocalypse of ’26.” That would be twenty tons of squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 28/08/2026
schneier.com
AI Doesn’t Mean the End of Mathematics—at Least Not Yet
_This essay was written with Kasra Rafi, and originally appeared in The Guardian._ Earlier this month, about 40 top mathematicians gathered at OpenAI’s offices to discuss the future of their profession. The meeting was off-the-record, but if recent articles by mathematicians are any guide, it was mostly pretty glum. People fear for their jobs, their careers and the work they love. We think the contrary view is more likely, at least in the short-term. AI models are nowhere near as capable as experienced academic mathematicians. This isn’t to say that AIs aren’t producing stunning mathematical results at the level of PhD researchers. In mid-May, OpenAI ...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 27/08/2026
schneier.com
LLM-Based Social Engineering Scams
OpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive: > The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators used dating personas to build trust before introducing fraudulent investment opportunities involving cryptocurrencies and spot gold trading. Other users engaged in lengthy romantic conversations with targets using fictitious identities, posed as representatives of online gambling platforms offering fake bonuses and winnings, or impersonated law enforcement agencies to tell targets they needed to pay fines for committing serious criminal offenses...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 26/08/2026
schneier.com
Spyware for Babies
_The New York Times_ has a long article (alt link) on surveillance systems aimed at babies. They are increasingly using AI. > Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonishing levels of baby data collection are just the beginning. Nanit recently raised $50 million from investors to expand its use of A.I. and use its camera to track speech and language development, motor skills and more, while extending its presence in children’s bedrooms into early adolescence.
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 25/08/2026
schneier.com
Black Hat State of Security Vendors
Andy Ellis has a roundup of the security vendors at Black Hat this year. > Key Takeaways: We have entered into an AI world. While nearly half of booths didn’t directly mention AI or agents in their taglines, the effects of AI are everywhere. Multiple spaces (Identity, SaaS, AppSec, Data) have almost every vendor leading with AI; existing unsolved problem areas just got worse. > > At the same time, there’s a clear trichotomy in the market: tools that tell you how bad things are; tools that stop adversaries, and tools that prevent problems from occurring. While you’d suspect that the tools that fix things would dominate, the tools that merely tell you how bad things are seem to be frustratingly plentiful...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 24/08/2026
schneier.com
Criminal Deception in Silicon Valley
Interesting paper: > **Abstract:** With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out _criminal deception_ , employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley ventures and their founders prosecuted for fraud between 2000 and 2023, our findings reveal that entrepreneurs carry out criminal deception through a process of _façading_ : Entrepreneurs construct, perform, and protect illusory appearances (façades) that externally project high-growth performance to audiences while masking ventures’ actual underperformance. We identify three forms of façading—­surface, reinforced, and deep façading­—that are contingent on the severity of the gap that entrepreneurs face between audiences’ performance expectations and ventures’ performance reality. Our theoretical framework captures how entrepreneurs facing minor, wide, and extreme expectation-reality gaps engage in evermore sophisticated efforts to detach the venture’s externally projected appearance from its actual operational reality. Practically, we propose several approaches to deter and detect criminal deception, including the extension of U.S. Securities and Exchange Commission surveillance and whistleblower program, investor due diligence reform, and dedicated entrepreneurship education interventions that clearly demarcate when entrepreneurs transgress into criminal deception. We make contributions to literatures on cultural entrepreneurship, organizational wrongdoing, and the social effects of entrepreneurship. ...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 21/08/2026
schneier.com
Friday Squid Blogging: Neon Flying Squid
The neon flying squid can fly in formation. > The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. > > They were probably neon flying squid (_Ommastrephes bartramii_), the subsequent study states, a species that is part of a 20-strong flying squid family that was known to leap from the water but, until then, was only rumoured to also be able to glide above it...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 21/08/2026
schneier.com
AI Is Learning to Write Genetic Code
This sort of research is both exciting and terrifying: > The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside. > > Using an existing bacteriophage as an example—ΦX174 (pronounced “fie-ex-1-7-4”), known for its ability to infect and destroy E. coli bacteria—the models generated about 700,000 potential designs, of which the researchers picked 285 that looked most promising. > > The researchers then synthesised new DNA molecules using those designs and inserted them into E. coli bacteria, before waiting to see if viable bacteriophages would emerge...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 21/08/2026
schneier.com
More Incidents of AIs Going Rogue in Cybersecurity Challenges
The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “genie behavior—while being tested on their cybersecurity capabilities. > The incident stemmed from a single evaluation where agents were given a task of solving a cyber security challenge. We ran this challenge 122 times across several models. Our investigation found that in 10 of those runs, an AI agent took autonomous, unsanctioned action on the live internet, targeting real people and organisations. In total, we catalogued 19 such actions. Almost all of this behaviour (17 actions) came from a single model, Anthropic’s Mythos 5, with 2 actions involving OpenAI’s GPT-5.6-Sol with cyber classifiers (mechanisms to prevent misuse) disabled. In the most serious case, an agent tried to insert malicious code into an open-source project. In an attempt to get the code approved, the agent engaged in social engineering—creating fake online identities and using them to pressure the project’s maintainer to approve the code. A human maintainer caught and refused to approve the malicious code...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 20/08/2026
schneier.com
Detailed Timeline of OpenAI’s Cyberattack on Hugging Face
OpenAI presented details of its AI’s model’s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It’s really interesting to read through—and really impressive cyberoffense work.
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 20/08/2026
schneier.com
Police Are Hiding Their Use of Flock Surveillance Cameras
A usage policy for Flock license plate reader cameras tells police not to talk about the cameras: > When cops use Flock to arrest someone in Wapello County, Iowa, they don’t want them to know. A usage policy for the automated license plate reader cameras in the county tells police, in no uncertain terms, to keep them a secret: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE,” the policy document reads. “DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY.” This reminds me of IMSI-catchers (Stingray was the most popular) a couple of decades ago. Police would go to even more extremes to hide their usage...
000
Schneier on Security [Unofficial] @schneier.com.web.brid.gy · 19/08/2026
schneier.com
ICE Collecting DNA Samples
ICE collected nearly a million DNA samples last year.
000