atlas news
  Ars Technica : security
18  august     13h00
Microsoft Copilot reveals secret input that allowed it to be hacked
Dan Goodin    Secret parameter allowed hackers to steal passwords when a target clicked on a link.
14  august     18h32
Vulnerability giving attackers full control of Macs is under active exploitation
Dan Goodin    Screen-sharing bug lets remote hackers log in without a password.
13  august     19h38
Private security firms will soon be allowed to hack overseas cybercriminals
Dan Goodin    Trump memo is first time gov’t has authorized private sector to perform cyberattacks.
12  august     21h43
Terabytes of credentials leaked in massive supply-chain attack
Dan Goodin    The data was scraped and exfiltrated from 2,500 users of a compromised AI package.
    13h37
Researchers found a way to hijack devices through Zoom screen sharing
Lily Hay Newman, wired.com    A public AI tool found the dangerous Zoom flaw in under 20 prompts.
    00h08
DEF CON crowd suspected in fake-hotspot attack on Delta flight
Cyrus Farivar    FBI Atlanta confirms it’s looking into the incident, no arrests made.
11  august     20h59
Chrome adopts what may be the best protection yet against account takeovers
Dan Goodin    Device-bound session credentials thwart an increasingly common form of account takeover.
    13h15
New surveillance tech links your phone to your license plate
Nicole M. Bennett, The Conversation    Phone and Bluetooth signals could turn roadside cameras into far richer tracking tools.
    11h30
New Pass-ta-key attack reveals all the things we didn’t know about passkeys
Dan Goodin    Why passkey apps treat Windows differently than other operating systems.
10  august     14h25
A researcher bought noreply.net. Companies started sending him secrets.
Matt Burgess, wired.com    Companies treat some email domains as digital trash cans, despite the risks.
05  august     22h35
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Dan Goodin    Baseboard management controllers from the world’s biggest manufacturers are a security mess.
    20h47
Anthropic’s AI used fake identities, malware in rogue attack on GitHub project
Jeremy Hsu    Anthropic and OpenAI models’ unprompted actions forced halt to UK cyber tests.
01  august     10h05
Defcon’s new badge is a security key you can see inside
Kim Zetter, wired.com    A removable chip lets hackers inspect their badge and keep using it after Defcon.
31  july     20h39
Claude published malicious code to the Internet and attacked 3 real companies
Dan Goodin    Had the hacks used conventional methods, someone would likely go to prison.
    14h01
AI scammers outperform humans when it comes to building trust
Andy Greenberg, wired.com    The AI chatbot was more effective at creating exploitable trust than the humans.
30  july     20h57
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Dan Goodin    Exploits can give persistent server access that survives credential rotation and disk re-imaging.
29  july     22h07
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
Dan Goodin    HAWK withstood years of testing that had yet to uncover a fatal weakness found through Mythos.
    15h52
Anthropic is finding bugs faster than Microsoft can fix them
Renee Dudley, ProPublica    Microsoft is on a mad dash behind the scenes to patch exploits before hackers find them.
28  july     21h36
We now have a better understanding how OpenAI hacked into Hugging Face
Dan Goodin    10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch.
27  july     21h56
Microsoft unveils AI security tools it says outperform competing platforms
Dan Goodin    Microsoft says tools cost less than competing ones and outperform them, too.
1787139318