atlas news
Ars Technica : security
18 august
13h00
Microsoft Copilot reveals secret input that allowed it to be hacked
Dan Goodin
Secret parameter allowed hackers to steal passwords when a target clicked on a link.
14 august
18h32
Vulnerability giving attackers full control of Macs is under active exploitation
Dan Goodin
Screen-sharing bug lets remote hackers log in without a password.
13 august
19h38
Private security firms will soon be allowed to hack overseas cybercriminals
Dan Goodin
Trump memo is first time gov’t has authorized private sector to perform cyberattacks.
12 august
21h43
Terabytes of credentials leaked in massive supply-chain attack
Dan Goodin
The data was scraped and exfiltrated from 2,500 users of a compromised AI package.
13h37
Researchers found a way to hijack devices through Zoom screen sharing
Lily Hay Newman, wired.com
A public AI tool found the dangerous Zoom flaw in under 20 prompts.
00h08
DEF CON crowd suspected in fake-hotspot attack on Delta flight
Cyrus Farivar
FBI Atlanta confirms it’s looking into the incident, no arrests made.
11 august
20h59
Chrome adopts what may be the best protection yet against account takeovers
Dan Goodin
Device-bound session credentials thwart an increasingly common form of account takeover.
13h15
New surveillance tech links your phone to your license plate
Nicole M. Bennett, The Conversation
Phone and Bluetooth signals could turn roadside cameras into far richer tracking tools.
11h30
New Pass-ta-key attack reveals all the things we didn’t know about passkeys
Dan Goodin
Why passkey apps treat Windows differently than other operating systems.
10 august
14h25
A researcher bought noreply.net. Companies started sending him secrets.
Matt Burgess, wired.com
Companies treat some email domains as digital trash cans, despite the risks.
05 august
22h35
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Dan Goodin
Baseboard management controllers from the world’s biggest manufacturers are a security mess.
20h47
Anthropic’s AI used fake identities, malware in rogue attack on GitHub project
Jeremy Hsu
Anthropic and OpenAI models’ unprompted actions forced halt to UK cyber tests.
01 august
10h05
Defcon’s new badge is a security key you can see inside
Kim Zetter, wired.com
A removable chip lets hackers inspect their badge and keep using it after Defcon.
31 july
20h39
Claude published malicious code to the Internet and attacked 3 real companies
Dan Goodin
Had the hacks used conventional methods, someone would likely go to prison.
14h01
AI scammers outperform humans when it comes to building trust
Andy Greenberg, wired.com
The AI chatbot was more effective at creating exploitable trust than the humans.
30 july
20h57
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Dan Goodin
Exploits can give persistent server access that survives credential rotation and disk re-imaging.
29 july
22h07
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
Dan Goodin
HAWK withstood years of testing that had yet to uncover a fatal weakness found through Mythos.
15h52
Anthropic is finding bugs faster than Microsoft can fix them
Renee Dudley, ProPublica
Microsoft is on a mad dash behind the scenes to patch exploits before hackers find them.
28 july
21h36
We now have a better understanding how OpenAI hacked into Hugging Face
Dan Goodin
10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch.
27 july
21h56
Microsoft unveils AI security tools it says outperform competing platforms
Dan Goodin
Microsoft says tools cost less than competing ones and outperform them, too.
1787139318