research

Getting a stranger’s phone kicked off the cellular network costs a few dollars

Getting a stranger’s phone kicked off the cellular network costs a few dollars 2026-09-11 at 09:00 By Mirko Zorz Researchers at Michigan State University and three partner schools bought a Samsung Galaxy Z Fold 7, copied the identification number printed on the sealed box, and reported the phone to its carrier as lost. Then they […]

Getting a stranger’s phone kicked off the cellular network costs a few dollars Read More »

OpenAI just hit a milestone on the road to self-improving AI

OpenAI just hit a milestone on the road to self-improving AI 2026-09-07 at 12:05 By Anamarija Pogorelec OpenAI has announced that it has reached a goal set last fall of having an automated research intern by September 2026. The milestone means a system can carry out well-defined research tasks under human direction, including work that […]

OpenAI just hit a milestone on the road to self-improving AI Read More »

Researchers built a $7 gadget for anyone paranoid about hidden cameras in hotel rooms

Researchers built a $7 gadget for anyone paranoid about hidden cameras in hotel rooms 2026-09-03 at 12:23 By Sinisa Markovic Most of us, staying in a hotel room or a vacation rental, have wondered at least once whether we’re safe there, whether someone might be watching or recording us without our knowledge. The thought alone […]

Researchers built a $7 gadget for anyone paranoid about hidden cameras in hotel rooms Read More »

A battery storage cyberattack would look exactly like a badly tuned controller

A battery storage cyberattack would look exactly like a badly tuned controller 2026-09-02 at 12:00 By Mirko Zorz Batteries connected to the grid make money by reacting to frequency, pushing power out when it sags and soaking it up when it rises. A few hundred of them moving together, on command from someone who should […]

A battery storage cyberattack would look exactly like a badly tuned controller Read More »

Scareware ads keep running on Google’s transparency tool, even after they’re reported

Scareware ads keep running on Google’s transparency tool, even after they’re reported 2026-09-02 at 08:30 By Mirko Zorz A team of NYU and Radboud University researchers spent a year building a tool to find deceptive software ads inside Google’s public ad archive. It works. It also exposed something more uncomfortable: reporting a bad ad to […]

Scareware ads keep running on Google’s transparency tool, even after they’re reported Read More »

A $25 template helped scammers build hundreds of phantom bank domains

A $25 template helped scammers build hundreds of phantom bank domains 2026-08-21 at 08:00 By Sinisa Markovic A phrase on a suspicious website turned into an investigation of phantom banks built to support scams, according to new research from Allure Security. Molly DeQuattro, the company’s VP of Operations, was reviewing a domain that resembled the […]

A $25 template helped scammers build hundreds of phantom bank domains Read More »

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Windows 11’s strongest security defenses can be bypassed without a screwdriver 2026-08-17 at 08:30 By Sinisa Markovic Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has […]

Windows 11’s strongest security defenses can be bypassed without a screwdriver Read More »

When companies get specific about AI, revenue growth looks different

When companies get specific about AI, revenue growth looks different 2026-08-17 at 07:00 By Anamarija Pogorelec Companies that provide specific evidence of how they use AI tend to record stronger revenue growth. Researchers at Carnegie Mellon University and Larridin examined a study universe of 564 companies across 12 industry sectors. Individual analyses used smaller samples […]

When companies get specific about AI, revenue growth looks different Read More »

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months 2026-08-12 at 16:51 By Mirko Zorz Most security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now […]

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months Read More »

Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G

Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G 2026-08-11 at 15:10 By Sinisa Markovic Researchers have found that compromised or malicious SIM cards can issue commands to some smartphones and cellular-connected devices, allowing attackers to steal information, disrupt communications, downgrade connections to 2G, and in some cases execute code. Tomasz Piotr […]

Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G Read More »

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix 2026-08-11 at 08:30 By Mirko Zorz Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws […]

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix Read More »

Three in four AI-generated vulnerability patches leave something broken

Three in four AI-generated vulnerability patches leave something broken 2026-08-06 at 15:45 By Mirko Zorz Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write. When there is a test, it often passes. Roughly one time […]

Three in four AI-generated vulnerability patches leave something broken Read More »

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers 2026-08-05 at 21:45 By Mirko Zorz An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker runs code on the host. Bonita BPM handles […]

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers Read More »

Code review used to be the only way to catch these bugs

Code review used to be the only way to catch these bugs 2026-08-05 at 14:30 By Mirko Zorz An automated system called NOVA read the source code of 3,915 open-source projects over two months and came back with 14,090 vulnerabilities, each one confirmed through the system’s validation pipeline. Vulnerability researchers at Palo Alto Networks’ Unit […]

Code review used to be the only way to catch these bugs Read More »

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic 2026-08-05 at 12:35 By Mirko Zorz TP-Link prints the serial number of an Omada router on its packaging and on a label attached to the device. Those numbers run in sequence, and feeding a guessed one to the Omada cloud service returns the […]

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic Read More »

Android malware detection collapses when the context stage comes out

Android malware detection collapses when the context stage comes out 2026-07-29 at 07:00 By Anamarija Pogorelec A phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine learning malware scanner and it comes back flagged. Six Android detectors in wide […]

Android malware detection collapses when the context stage comes out Read More »

Exposed BMCs hand out password hashes before login

Exposed BMCs hand out password hashes before login 2026-07-28 at 15:00 By Sinisa Markovic An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part of the IPMI 2.0 handshake, built on an authentication protocol introduced […]

Exposed BMCs hand out password hashes before login Read More »

AI took more than junior developer jobs and the bill comes later

AI took more than junior developer jobs and the bill comes later 2026-07-28 at 08:30 By Sinisa Markovic A ticket comes in for a small bug fix. Hand it to the junior on your team and you wait a day, review something that half works, and sit down to explain what went wrong. Describe it […]

AI took more than junior developer jobs and the bill comes later Read More »

The automotive software vulnerabilities hiding in your dashboard

The automotive software vulnerabilities hiding in your dashboard 2026-07-24 at 09:30 By Anamarija Pogorelec Pop the hood on a new car and you won’t find much you can fix with a wrench. What you’ll find is software, and a lot of it. The screen in the dash probably runs Android or a flavor of Linux. […]

The automotive software vulnerabilities hiding in your dashboard Read More »

Scroll to Top