research

Researchers make the case for a cybersecurity AI scientist

Researchers make the case for a cybersecurity AI scientist 2026-07-07 at 09:30 By Mirko Zorz Autonomous AI agents have started doing real security work. Language-model agents probe software for flaws, run penetration tests, and chain together attack steps that once needed a human operator. Research about security has stayed slower and more manual, built around […]

Researchers make the case for a cybersecurity AI scientist Read More »

Non-interactive SSH attacks dominate after login

Non-interactive SSH attacks dominate after login 2026-07-03 at 08:30 By Sinisa Markovic Anyone who runs a server with SSH exposed to the internet sees the same pattern in the logs. A steady stream of automated scanners tries to log in, hour after hour, from addresses all over the world. The common picture of what comes […]

Non-interactive SSH attacks dominate after login Read More »

Catching ransomware on the wire before it locks the file server

Catching ransomware on the wire before it locks the file server 2026-07-02 at 08:00 By Sinisa Markovic Corporate networks keep sensitive files off individual workstations and store them on shared servers that staff reach through mapped network drives. That arrangement hands ransomware operators a target worth chasing. A single compromised laptop can begin encrypting files […]

Catching ransomware on the wire before it locks the file server Read More »

This supercomputer encrypts your data even while it’s running it

This supercomputer encrypts your data even while it’s running it 2026-07-01 at 08:30 By Sinisa Markovic Most people who handle sensitive data already encrypt it in two places. They lock it down when it sits on a hard drive, and they lock it down when it moves across a network. There has always been a […]

This supercomputer encrypts your data even while it’s running it Read More »

Sycophantic chatbots and the harms that build over many chats

Sycophantic chatbots and the harms that build over many chats 2026-06-29 at 08:00 By Sinisa Markovic People use AI chatbots for company, advice, and emotional support, and these systems answer in ways meant to hold their attention. Researchers describe the resulting risks as affective safety, a class of harm that exists because humans are emotional […]

Sycophantic chatbots and the harms that build over many chats Read More »

A privacy-first take on local malware analysis

A privacy-first take on local malware analysis 2026-06-26 at 09:00 By Sinisa Markovic Submitting a suspicious file to VirusTotal or MalwareBazaar places a copy of that file on a platform other people can search. Analysts across the industry rely on these services to get a quick verdict on whether a binary is dangerous. The convenience […]

A privacy-first take on local malware analysis Read More »

LLM security advice looks solid until you check the hard cases

LLM security advice looks solid until you check the hard cases 2026-06-25 at 09:00 By Anamarija Pogorelec Plenty of people now type their security worries straight into a chatbot. A hacked account, a suspicious email, a stalker who might be tracking a phone, all of it lands in the same window someone would use to […]

LLM security advice looks solid until you check the hard cases Read More »

Using Reddit to manipulate AI search results is surprisingly easy

Using Reddit to manipulate AI search results is surprisingly easy 2026-06-23 at 16:27 By Sinisa Markovic A Reddit comment that takes only a few seconds to write can end up influencing the answers generated by AI research tools. A Cornell Tech study found that a short snippet of user-generated text, sometimes as little as 13 […]

Using Reddit to manipulate AI search results is surprisingly easy Read More »

A $1,400 experiment in AI security auditing outperformed OpenAI’s Codex Security

A $1,400 experiment in AI security auditing outperformed OpenAI’s Codex Security 2026-06-23 at 08:30 By Mirko Zorz A research team has built a system that teaches AI agents to hunt for software bugs by writing the audit method down as plain text. The system, called EVOHUNT, keeps the underlying AI model fixed and improves only […]

A $1,400 experiment in AI security auditing outperformed OpenAI’s Codex Security Read More »

23 ClawHub plugins squatting official scopes expose AI registry security gaps

23 ClawHub plugins squatting official scopes expose AI registry security gaps 2026-06-22 at 11:00 By Help Net Security Plugin registries for AI agents use npm-style scopes like @openclaw/ and @clawhub/ to signal who published a package. But on ClawHub, a registry whose plugins run with Claude, OpenClaw, and other agents, those official scopes weren’t reserved […]

23 ClawHub plugins squatting official scopes expose AI registry security gaps Read More »

Encrypted DNS still tells an eavesdropper where to look

Encrypted DNS still tells an eavesdropper where to look 2026-06-22 at 08:00 By Mirko Zorz Encrypted DNS runs across much of the Internet. DNS over TLS, HTTPS, and QUIC keep the contents of a query away from anyone watching a network link. The encryption covers the message inside each packet. The packet still carries plaintext […]

Encrypted DNS still tells an eavesdropper where to look Read More »

Your browser tab could become encrypted storage for someone else’s files

Your browser tab could become encrypted storage for someone else’s files 2026-06-19 at 08:30 By Mirko Zorz Decentralized storage networks already hand pieces of people’s data to strangers’ machines. The lasting question across these networks is whether the machine holding the data can read it. A research paper by Gregory Magarshak, a professor at IENYC, […]

Your browser tab could become encrypted storage for someone else’s files Read More »

Grayscale applies traditional finance models to AAVE, sees $175 value

Grayscale applies traditional finance models to AAVE, sees $175 value 2026-06-18 at 12:45 By Ezra Reguerra Grayscale and CoinShares are applying traditional valuation techniques to crypto assets as institutions explore revenue-generating DeFi protocols. This article is an excerpt from Cointelegraph.com News View Original Source

Grayscale applies traditional finance models to AAVE, sees $175 value Read More »

GentleKiller targets more than 400 security processes across 48 products

GentleKiller targets more than 400 security processes across 48 products 2026-06-18 at 12:00 By Anamarija Pogorelec Most ransomware operations leave the work of disabling endpoint security software to their affiliates. The ransomware-as-a-service gang Gentlemen runs a different model. Its operators develop and maintain a set of tools for shutting down endpoint detection and response (EDR) […]

GentleKiller targets more than 400 security processes across 48 products Read More »

What happens to oversight when AI agents write a lab’s own code

What happens to oversight when AI agents write a lab’s own code 2026-06-18 at 08:00 By Mirko Zorz Inside the labs building frontier AI, a growing share of the coding gets done by the AI itself. These agents write, edit, and run software with light human oversight between steps, and they reach into production infrastructure, […]

What happens to oversight when AI agents write a lab’s own code Read More »

Low-skilled attacker used Claude, Codex to breach 14 companies

Low-skilled attacker used Claude, Codex to breach 14 companies 2026-06-17 at 18:43 By Zeljka Zorz Researchers have long warned that AI agents could lower the skill floor for offensive cyber operations, and a recent report by OALABS (Open Analysis) researchers bears that out. After recovering and analyzing over 1,000 agent sessions from a compromised server […]

Low-skilled attacker used Claude, Codex to breach 14 companies Read More »

The checklist problem behind critical infrastructure cyber safety

The checklist problem behind critical infrastructure cyber safety 2026-06-17 at 07:00 By Anamarija Pogorelec An asset owner can meet major federal cyber compliance standards and still run equipment that lacks the engineering to withstand an attack or a failure. New research from George Mason University examines how United States cyber policy defines reasonable care for […]

The checklist problem behind critical infrastructure cyber safety Read More »

Planning a trip? Fake travel sites are multiplying this summer

Planning a trip? Fake travel sites are multiplying this summer 2026-06-16 at 11:27 By Sinisa Markovic Cyberattacks against hospitality, travel, and recreation organizations rose 24% year over year, reaching an average of 2,291 incidents per organization each week in May 2026, according to Check Point. (Source: Check Point) “The sector has more than doubled its […]

Planning a trip? Fake travel sites are multiplying this summer Read More »

A hardware neural network backdoor that hides in plain sight

A hardware neural network backdoor that hides in plain sight 2026-06-15 at 08:00 By Mirko Zorz Deep learning systems on phones, cars, and other edge devices increasingly run on custom silicon. Specialized chips such as FPGAs and ASICs give these systems the speed and low power consumption that edge applications need. Many of these chips […]

A hardware neural network backdoor that hides in plain sight Read More »

Proving what a military AI model will do is the real problem

Proving what a military AI model will do is the real problem 2026-06-15 at 07:30 By Sinisa Markovic Defense contractors build AI systems that task drones automatically and propose kill-chains to support soldiers. Several of these contractors have partnered with frontier AI companies to put advanced models into military tools. Anduril works with OpenAI, Palantir […]

Proving what a military AI model will do is the real problem Read More »

Scroll to Top