Reading view

Jailed Flock vandal wipes out three cameras, racks up thousands in damages

Note to privacy-conscious vandals: If you're going to destroy Flock license plate readers, make sure you also take out the other CCTV cameras in the area that could catch you in your crime. Otherwise, you'll end up like one unlucky Californian. Marcus Bee, 40, was arrested by the Monterey County Sheriff’s Office on Tuesday, accused of joining the ever-growing band of US citizens damaging the controversial cameras popping up across the country. A police report filed this week stated that Bee, of Pismo Beach, was arrested on suspicion of attacking at least three Flock cameras in Lockwood and Bradley. According to the deflock.org website, which maps Flock camera deployments, there are only three of the automated license plate readers (ALPRs) running in the two communities – one in Lockwood and two in Bradley, roughly 25 miles away. Police allege Bee caused thousands of dollars’ worth of damage to “public safety infrastructure.” Monterey County Sheriff’s Office added that Bee was caught after “his actions were captured by other surveillance cameras located nearby,” along with other investigative leads. "This arrest sends a clear message that anyone who intentionally damages public safety equipment will be identified, arrested, and held accountable," said Monterey County Sheriff Tina Nieto. "These cameras have become an invaluable investigative resource that helps us solve crimes, recover stolen vehicles and ag equipment, locate missing persons, and protect our communities. Any attempts to disable these systems will not prevent us from doing our job. “In this case, the suspect's own actions were captured on surveillance cameras, leading directly to his arrest. We will continue to aggressively investigate these crimes and seek prosecution against anyone who targets public safety infrastructure." Bee was jailed with bail set at $30,000. The case follows a similar one in Georgia last week, although local police were unable to identify the suspect(s) behind the two attacks, which involved setting two ALPRs on fire. The two attacks were timed fairly close together, although the phenomenon of inflicting criminal damage onto Flock cameras is something of a long-running trend. Several US police forces have been tasked with arresting alleged Flock vandals, including Jeffrey Scott Sovern, 41, who authorities believe was behind a spate of attacks on ALPR cameras in North Suffolk, Virginia, between April and October 2025. He said, at a hearing in June, that he believed the technology was unconstitutional. Flock cameras: A problem or simply misunderstood? The Monterey County Sheriff’s Office said Flock’s cameras “are an important investigative tool” used to help solve various types of crimes, including missing persons cases, car thefts, and violent crimes such as shootings and homicides where suspect vehicles are involved. Contrary to the opinions held by many, it went on to say, the cameras “are used exclusively to support legitimate criminal investigations,” not to support the US government’s anti-immigration efforts. Likewise, Flock has repeatedly denied offering contracts to agencies such as Immigration and Customs Enforcement (ICE), although reports suggest police were instead carrying out searches on ICE's behalf. Customs and Border Protection (CBP) has also allegedly used Flock data in its own immigration investigations. Other critiques of the technology used by thousands of police departments across the US include problematic abuses, such as police officers using it to stalk romantic interests. The Institute of Justice is aware of at least 26 cases of this behavior, it reported earlier this month, with the majority taking place since 2024. Additionally, the American Civil Liberties Union (ACLU) takes issue with the scale of data gathering by ALPRs. It claims that less than 1 percent of the cars scanned are connected to crime, yet they still have details added to a database, such as vehicle manufacturer, model, color, license plate number, bumper stickers, and scratches. Flock CEO Garrett Langley claimed this week in an interview with The Drive that the company’s cameras were used to solve around 1 million crimes across the US last year. Responding to claims such as Sovern’s – that the cameras are unconstitutional, specifically that they violate Americans’ Fourth Amendment rights – Langley said there are no legal issues, and he doesn’t foresee any arising in the future. Flock’s spokespeople have repeatedly condemned the cases of camera vandalism, highlighting the risk of losing evidence that could be crucial to solving ongoing criminal cases. ®

  •  

Russian spies take their half-click email attack from Zimbra to Outlook

The Russian espionage crew that turned simply reading an email into a security risk has expanded beyond Zimbra, with Proofpoint saying it's now pulling the same half-click trick against Microsoft Outlook Web Access. Proofpoint says the cyber group it tracks as TA488, or "Laundry Bear," began exploiting CVE-2026-42897, a cross-site scripting flaw in the Outlook Web Access (OWA) component of on-premises Exchange Server, a day before researchers and government agencies exposed the group's abuse of a zero-day in Zimbra Collaboration Suite. Unlike conventional phishing attacks, this one doesn't depend on persuading the victim to follow a link or download a file. If a target opens the booby-trapped message in OWA, the browser executes attacker-controlled JavaScript inside the victim's authenticated mail session. Exchange Online is not affected. According to Proofpoint, TA488 abused the OWA flaw to target government organizations in the US and Europe, along with telecommunications, financial services, hospitality, and aerospace companies. The researchers said the unusually broad campaign may have been intended to hide among the background noise of everyday email traffic rather than the tightly focused operations more commonly associated with espionage groups. "TA488 appears to demonstrate interest in a wide range of sectors while maintaining priorities for intelligence collection against government and defense," Proofpoint said. "Lure themes remain generic and unremarkable, so the target is more inclined to open and skim the email but ultimately overlook it." Instead of dropping conventional malware onto the endpoint, the attackers deploy a browser implant dubbed OWAReaper that lives entirely inside OWA. Proofpoint says it leaves virtually no host artifacts, communicates over two command-and-control channels, supports multiple methods of exfiltrating data, and survives browser restarts, password changes, and even a complete device rebuild because the foothold resides in the compromised mailbox rather than on Windows itself. CVE-2026-42897 isn't making its debut on The Register. Microsoft disclosed the bug in May following reports that attackers were using it in the wild. Proofpoint's latest report fills in more of the picture, showing the activity formed part of a broader espionage campaign rather than isolated exploitation. Proofpoint believes TA488 may actually have been exploiting the flaw as a zero-day, citing attacker infrastructure that dates back to March, roughly two months before Microsoft's out-of-band patch. If accurate, that would suggest the campaign was underway well before defenders knew there was a vulnerability to fix. "If this is the case, the combined improvement of the malware and the exploit development against a harder target in Outlook Web Access signal a leap in capability by TA488," Proofpoint said. Microsoft did not immediately respond to The Register's questions, but if Proofpoint's assessment holds up, TA488 isn't just recycling an old trick. It's refining one that has already proven capable of slipping past one of the oldest pieces of security advice in the book: don't click suspicious links. ®

  •  

Headteacher had the most guessable username-password combo you could imagine

PWNED Welcome, once again, to PWNED, the weekly column where we show you how not to use your computer or your network. In this week’s fable of fecklessness, we talk about a teacher who had a lot to learn about security. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our story comes courtesy of Kevin Walker, a seasoned IT veteran from the UK. At one point, he was providing his services to a school when he came across the headteacher’s (aka principal’s) laptop. At the bottom of the laptop there was a sticker with the woman’s username and password. Even if they had been complicated, the post-it would have given them away, but in fact, the combination was: Username: headteacher Password: headteacher Using that laptop, a malefactor could have had access to pupils’ personal information, internal conversations, emails, and all kinds of private school files. There could be serious problems for everyone who worked for or attended the school. “A headteacher’s laptop is not just a laptop; it's an entry point to the most sensitive information a school holds,” Walker told us. If a cybercriminal got access, they could effectively break into the school without ever setting foot in the building. This wasn’t the only instance of poor security Walker saw in his time doing IT for schools. He also saw an institution create an Excel file called Passwords.xlsx, then put it on a shared drive that students could get to. As its name suggests, Passwords.xlsx was filled with login credentials that any bad actor could take advantage of. Walker also saw leaver accounts that remained active, a server that had its backup drive permanently plugged in so hackers could potentially wipe the backup as well, a Wi-Fi password written on a whiteboard in reception, and one critical system that users could only access from an ancient laptop. There was also a machine with a “Do Not Turn Off” note posted to it sitting in a corner that everyone was afraid to touch. And, years after Windows XP was no longer the current platform, the school had a CCTV monitor with that ancient OS running on it. And, a supposedly secure server room doubled as a storage closet for stationery and Christmas decorations. Walker told us that, in his experience, the schools he worked with had priorities other than cybersecurity and they didn’t understand its importance. One boss even denied the importance of keeping data safe at all. “We don’t need to worry about cybersecurity. They're only a primary school,” his manager told him when Walker tried to get them to use cloud backups. The problem, Walker opines, is that schools often have to work with outdated gear and the teachers and school administrators have other concerns. His solution: keep it simple. “Make the safe thing the easy thing,” Walker said. “Give staff password managers. Use multi-factor authentication. Review accounts properly. Test backups. Remove shared admin logins. Keep systems updated. Enforce proper passwords and block the ones that have already turned up in data breaches. If a password is already doing the rounds online, it has no business protecting a school system. None of that is as exciting as rolling out a fleet of shiny new iPads, but it works.” ®

  •  

Word worm crawls into Copilot, spreads chaos

UPDATED Watch out for untrusted documents. According to research, an attacker can hide malicious instructions in a Word document that, when included in Copilot for Word’s context, may alter document output and copy the instructions into newly created files that use the affected document as source material, without the victim noticing. Håkon Måløy, a Norwegian data scientist with a PhD in applied AI and ML, publicly disclosed the issue in a blog post Tuesday. Måløy describes the issue in considerable detail while withholding the specific prompt payload, arguing that, because no robust mitigation exists, it would be irresponsible to disclose anything beyond the class of the vulnerability. “To my knowledge, this is among the first public demonstrations of document-borne AI-worm self-propagation through normal workflows in a mainstream commercial productivity suite,” Måløy noted. Måløy said that he has been working with Microsoft since March 2026 on addressing the vulnerability, but after multiple updates to Copilot, this new class of Copilot worm is still viable. Microsoft mitigated the exploit demonstrated by his original proof-of-concept prompt, but Måløy said rewording the payload allowed him to successfully propagate the worm and alter financial data in a target document. Måløy and Microsoft twice delayed public disclosure of the issue, but, after 144 days, he said in his report that people needed to be made aware. “The coordination period agreed with Microsoft has been exhausted, and testing shows that no robust mitigation for the broader vulnerability class is currently available,” Måløy wrote. “Two mitigation attempts, including a model upgrade, did not close the class.” How Copilot propagates a Word worm Måløy explained the worm’s execution with an example involving an employee preparing a financial report for their company. The employee downloads a market analysis from a trusted website to help with the preparation of a financial report in Copilot, unaware that the source had been compromised and the document they downloaded contains hidden malicious instructions. The hidden instructions (inserted as small white text in his proof of concept) tell Copilot to alter figures in the report the employee generates and to copy the worm into the report they create with Copilot. If another employee later adds that report to their own work, the whole process begins again, and documents generated from it also contain the worm, and, as it spreads, it makes tracing the infection to its source extremely difficult. “The attack can therefore continue without further involvement from either the compromised website or the original malicious document,” Måløy said. “The attacker does not need access to the victim’s Microsoft 365 tenant. The attacker only needs to share a malicious document with the victim.” Copilot should use information in documents a user includes in its context for a project without treating instructions embedded in a document as additional prompts, Måløy said, but his research suggests it doesn't always do that. A fundamental flaw Måløy argues that he’s essentially dug up a new type of cross-domain prompt injection attack that abuses a fundamental part of modern LLM architecture. “For AI-assistants to be useful, they often must process emails, documents, webpages, memories, tool outputs, and other information that may be controlled by an attacker,” the researcher said. But if an LLM has to process data in order to determine it contains an attack, the attack could already be influencing that determination. “Relying on the model to detect XPIAs therefore resembles asking an interpreter to execute an untrusted program to determine whether that program is safe to execute,” Måløy asserted. Were Microsoft or some other company to pop another model in front of that model to check for malicious content, it only moves the problem outward, Måløy said, creating a “LLMs all the way down” scenario. “The long-term challenge likely lies in designing systems in which goals and intentions also exist independently of the information being processed,” he said. Until that time, Måløy argues, “any system that integrates an LLM into a trusted workflow today must assume that attacker-controlled content entering the model’s context will result in compromise at some rate.” What can Copilot customers do to reduce the risk? Short of ditching Copilot, there’s not much. “No customer-side remediation fully addresses the issue at the time of publication,” Måløy said, but he does have a few tips. Treat externally sourced documents as untrusted when using them in Copilot, he recommends, and fully review every single document before sending it to Copilot, and fully review any Copilot-generated or edited documents before distributing them. Sheesh - if you’re going to have to actually read that stuff, you might as well just cut Copilot out of the loop and do the thinking yourself. Microsoft has been in touch to confirm the research, but the company's statement doesn't do anything to allay fears this is an unsolved issue. “We have addressed the findings reported by the researcher and thank them for working with us through coordinated vulnerability disclosure. To address this class of risk, we use a defense-in-depth strategy with safeguards that block malicious instructions at multiple points and help keep tasks aligned with users’ requests. We are continuously strengthening these safeguards as the technology and threat landscape evolve. We encourage customers to install the latest updates, use multiple layers of security protection, treat content from unknown sources with caution, and review AI-generated content before using or sharing it.” We also reached out to Måløy, but didn’t hear back before publication. ® Updated at 1841 GMT on July 29 to add Microsoft's statement.

  •  

Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems

Security researchers at Tenable suspect the Iran-linked faux hacktivist outfit CyberAv3ngers was behind the cyberattack that disrupted more than 30 Minnesota water facilities. Neither state-level nor federal officials have made any claims regarding attribution for the attacks, however, Tenable reckons the operational pattern is consistent with the crew's previous raids, noting the timing relative to recent government warnings. The Cybersecurity and Infrastructure Security Agency (CISA) updated an advisory on Iran-linked attackers targeting programmable logic controllers (PLCs) across critical infrastructure on July 22, four days before Minnesota said the attacks targeted its systems. The advisory warned that Iran-linked hackers were attempting to disrupt operations using tactics previously associated with CyberAv3ngers. Government facilities, water and wastewater systems, and energy providers were among those urged to remain on high alert. What happened in Minnesota? On July 26 and 27, more than 30 community water systems across Minnesota were disrupted by what officials called "a coordinated cyberattack" targeting operational technology (OT). Minnesota IT Services (MNIT), the state's IT agency, said the Department of Health is working with the affected water facilities to ensure public health is maintained. No cities have yet asked citizens to modify the amount of drinking water they consume, per MNIT's latest update. The agency did not offer many other details about the attacks, other than to mention all the different agencies, organizations, and bodies it is working with as part of the investigation. One of the first cities to report issues, Braham, warned that its water reserves were limited in its initial notice. Citizens were asked not to water their lawns or use water for recreational purposes, although the problems were resolved the same day. No such directives were issued in other affected cities. Maple Plain declared a state of emergency, allowing it greater flexibility to coordinate resources, but did not ask residents to adjust their consumption. The same was true in the Twin Cities suburb of Plymouth and in South St. Paul, which both confirmed cyber-related problems on July 27 but did not ask residents to curb water use. "Cyberattacks against critical infrastructure require a coordinated, whole-of-government response," said John Israel, MNIT assistant commissioner and Minnesota CISO. "MNIT is working side by side with our partners to share intelligence, support affected communities, and help utilities restore operations safely while strengthening defenses against future attacks. "This incident demonstrates why Minnesota has invested in strong cybersecurity capabilities and partnerships. Our response worked as intended, enabling agencies at every level of government to rapidly coordinate, contain the incident, and help prevent more serious impacts to critical services." What is CyberAv3ngers? First identified around 2020, CyberAv3ngers is widely believed to be linked to Iran's Islamic Revolutionary Guard Corps (IRGC), specifically its Cyber-Electronic Command division (IRGC-CEC). For the first two years, the group began as a "propaganda persona," as Tenable puts it, claiming disruptive attacks on Israeli infrastructure – claims that were later debunked as fabrications. Its first sustained campaign came in November 2023, when it compromised PLCs at the Municipal Water Authority of Aliquippa, Pennsylvania, defacing them anti-Israel messages. Tenable said CyberAv3ngers compromised at least 75 Unitronics Vision Series PLCs across the United States, Israel, the United Kingdom, and Ireland as part of the campaign. They did so by exploiting default passwords. Between 2024 and 2025, the crew developed the IOCONTROL malware kit, built for attacks on OT and Internet of Things (IoT) devices. OpenAI said in 2024 that the group's members used ChatGPT in the development process. CyberAv3ngers stepped up its activity in 2026, targeting US critical infrastructure through Rockwell Automation/Allen-Bradley PLCs from March onward. CISA's July 22 update added Schneider Electric and Siemens equipment to the list of potential targets. In some cases, the attacks - which targeted multiple critical infrastructure sectors - disrupted operations at affected facilities, federal officials said, though they offered no specifics on what those disruptions entailed. CyberAv3ngers is known for targeting small water and municipal facilities, which experts believe are among the lowest-hanging fruit in US critical infrastructure. Many small and rural facilities lack dedicated cybersecurity resources. Tenable said some operators manage OT environments using remote-access software such as TeamViewer and AnyDesk or leave their PLCs exposed to the web. "These access methods bypass enterprise security controls entirely, creating an attack surface that is invisible to conventional security monitoring," Tenable said. Poor segmentation between IT and OT environments can also allow a single intrusion to spread across much of the network. ®

  •  

America bans imported robots due to supply chain and security risks

The US government has decided to effectively ban the sale of advanced robots made in other nations. The decision trickled out over two days with publication of a National Security Determination [PDF] and an update [PDF] to the list of banned devices set by the Federal Communications Commission (FCC). The national security document observes “Advanced robotic devices will be critical to creating efficiencies in our economy, dominating on the battlefield, and securing our homeland” and notes that modern bots are now constantly connected to networks “which creates broad attack surfaces and leaves them vulnerable to data exfiltration, remote disruption of the physical robot, and dependencies on unsecure over the air updates.” One example of those vulnerabilities mentioned in the document is the UniPwn flaws that made it possible for attackers to take over humanoid robots made by Chinese company Unitree. “If the United States continues to rely on foreign sources of advanced robotic devices and critical components, it will subject the parts of the U.S. economy and national security enterprise that are reliant on these robots to the whims of foreign entities that could disrupt or degrade the supply chains at a time of their choosing,” the document states. To respond to those threats, the FCC decided the foreign-made advanced robotic devices belong on its Covered List of products for which imports are banned because they pose an unacceptable risk to the national security of the United States and its residents. The regulator offered a single exception: if the Department of War vouches for a device, it can have it. Foreign-owned companies that make their bots in America are also exempt, an important exemption because one of the leading robot-makers is Boston Dynamics – a company backed by the USA’s DARPA that is now majority-owned by South Korea’s Hyundai, but continues to manufacture its machines stateside. The decision does, however, apply to all future foreign-made devices. Vendors of clankers already approved for sale in the USA can continue to import them, and users are also free to use any bots they already own. But the intent of the documents is clear: from now on, only robots made in America are welcome in America. One entity that stands to benefit from this decision is Tesla, which Elon Musk claims will one day produce one million humanoid robots a year. In true Muskian style he has also said Tesla will go into “high production” of the bots in 2026, but there’s no evidence of that happening although the occasional trillionaire did recently show off the production line for Tesla’s “Optimus” bot. ®

  •  

JFrog's 0-days let OpenAI's models hack Hugging Face

UPDATED We now know how OpenAI's models broke out of their cages to attack Hugging Face. The rogue models found zero-day vulnerabilities in JFrog’s universal binary repository manager Artifactory around the time they escaped, according to JFrog CTO Yoav Landman. While Landman wouldn't confirm that these flaws were the zero-days that OpenAI’s models found and exploited, ultimately allowing them to breach the massive model mart, OpenAI later admitted the connection. "To gain Internet access, the models identified and exploited a previously unknown zero-day vulnerability in Artifactory⁠ package registry cache proxy," OpenAI added to a blog post on the topic Tuesday. "We disclosed this vulnerability, along with other Artifactory vulnerabilities our models identified as part of our review, to the vendor." Landman says OpenAI's models discovered the Artifactory zero-days during a security evaluation. The AI giant notes the incident occurred while its models were being evaluated on the ExploitGym benchmark. “During a security evaluation, OpenAI’s models identified previously unknown zero-day vulnerabilities in self-hosted Artifactory installations that could be exploited to gain unintended internet access,” Landman said on Monday. JFrog Artifactory is a central platform that organizations use to store and distribute all the software artifacts across their supply chains. It supports more than 60 package formats including Docker, Maven, npm, PyPI, Helm, and AI/ML models. OpenAI “responsibly and immediately” disclosed the vulnerabilities to JFrog, Landman continued. “Our security team treated the report with the urgency it deserved, as a genuine zero-day unknown to the world, and moved accordingly. We developed, validated, and released a fix for all JFrog customers, self-hosted and cloud alike.” On Monday, JFrog released the fixed versions, and credited OpenAI researchers for reporting at least eight of the now-patched Artifactory vulnerabilities: CVE-2026-65617, CVE-2026-65925, CVE-2026-65921, CVE-2026-65923, CVE-2026-66018, CVE-2026-66014, CVE-2026-66015, and CVE-2026-65924. JFrog's admission comes about a week after OpenAI said two of its models, GPT-5.6 Sol and a second pre-release model, escaped their testing sandbox during a security evaluation designed to test their cyber capabilities. During this test, the models found a way to access the open internet, then broke into Hugging Face and accessed private information and stole some credentials. “While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem,” OpenAI said on July 21. In a July 28 update, the house of Altman admitted that the JFrog 0-days were the cause. In the same update, OpenAI admitted that its models had breached other services. "We have been finding a small number of cases where the models identified and used publicly exposed credentials at the account-level on other publicly-available services. This includes four accounts on four services as part of the Hugging Face incident (and a few accounts accessed as part of other evaluations)," OpenAI wrote. ® Updated on July 29 with additional details from OpenAI, admitting that the JFrog 0-days led to the breach.

  •  

Microsoft and Wiz mind-meld agents catch more than 90% of bugs

Two agentic bug-hunting systems from Microsoft and Google-owned Wiz show that when it comes to finding and remediating software vulnerabilities, at least two models’ minds work better than one - and Wiz tells us it’s adding a third. Wiz on Monday said Project Atlas, its bug-hunting AI agent, bested Anthropic’s Mythos Preview and OpenAI’s GPT-5.5 Cyber with its vulnerability-analysis skills, achieving a 90.9 percent success rate on CyberGym, and uncovering more than 200 zero-day security holes in widely used open-source code. Meanwhile, Microsoft boasted its MDASH bug-hunting harness scored a 95.95 percent success rate on CyberGym, also beating Mythos, Gemini and GPT on the same benchmark for evaluating how well AI systems find real vulnerabilities in the code. For comparison, OpenAI’s GPT-5.5 Cyber scored 85.6 percent on CyberGym, and its GPT-5.6 Sol scored 83.6 percent. Anthropic’s Mythos 5 reproduced the target vulnerability on 83.8 percent of CyberGym challenges. And Google’s Gemini 3.5 Flash Cyber in CodeMender achieved an 83.2 percent success rate. The secret to both Atlas and MDASH’s success, according to the vendors, is that they use the right model for the right security job. Atlas uses Claude Opus 4.6 with GPT-5.5, Nir Ohfeld, head of vulnerability research at Wiz, told The Register. “We're now working to incorporate Gemini, which is well timed given Wiz's recent work with DeepMind on Gemini Flash Cyber,” he added. Microsoft’s MDASH - a combination of red-team agents that find and simulate real, exploitable vulnerabilities and attack paths, and green-team agents that remediate the issues - combines MAI-Cyber-1-Flash, based on Microsoft AI (MAI)’s internally developed MAI-Thinking-1 reasoning model, and GPT-5.4. MAI-Cyber-1-Flash is designed to handle up to 90 percent of all tasks, with MDASH detecting, patching, and validating vulnerabilities before handing the remaining 10 percent of more complex tasks to the larger GPT-5.4. “We were able to take an off-the-shelf model, within our harness, a multi-agent and multi-model implementation, and we achieved the best results you could have,” Hayete Gallot, executive vice president of Microsoft Security, said on Monday. Atlas isn’t commercially available yet - it’s used internally, and stems from Wiz’s efforts to understand how frontier models can be used for advanced code scanning. But it’s proof that “no single model is best at everything, and none stays state of the art for long,” Ohfeld and fellow Wiz kid Yuval Avrahami wrote in a Monday blog. The cloud security biz evaluates every new model using its internal benchmarking tool, Cyber Model Arena, which scores each one on its success at completing various security-investigation tasks: threat modeling, hunting, validation, and proof generation. “The results are rarely uniform: the model that reasons best through a complex exploit chain is often not the one that triages most precisely,” the duo wrote. “Atlas routes each stage to whichever model wins on that task.” In addition to doing a better job of finding and fixing vulnerabilities, a multi-model system also saves customers’ money, according to Microsoft and Wiz. Combining its much smaller, in-house model with GPT-5.4 halves customers’ costs, according to Mustafa Suleyman, CEO of Microsoft AI. “As the models hand off between each other, they are not just able to deliver better performance than all of the other models combined, they do so at 50 percent of the cost,” he said on Monday. And while “each new generation of models expands what is possible,” they are also expensive, Ohfeld told us. “We have also learned that pointing a frontier model at a codebase once is not a sustainable security strategy: deep scans are expensive, their results become stale as code changes by the minute, and a point-in-time analysis cannot provide the continuous coverage organizations need across every repository,” he said. In fact, the real question for code security shouldn’t be which model a scanner uses, Ohfeld added. It’s this: “How does your system take advantage of the best model available today, continuously and economically, and what continues to work when a better one arrives,” he said. “That is the bet behind Atlas: frontier-model depth where expert reasoning is required, an architecture that improves as models evolve, and rigorous validation so every finding arrives with evidence, not just a plausible answer.” ®

  •  

DEF CON bans Meta-style 'pervert glasses'

Ahead of DEF CON 2026 opening its doors in Las Vegas next week, conference organizers said they have imposed a ban on “Meta-style glasses with recording capabilities.” Statements made via its social media channels went on to say that no exceptions will be made for those using the devices with prescription lenses. “Be sure to pack non-violating eyewear if you need them,” DEF CON said, before directing delegates to the conference’s official photo policy. That policy has not been updated since 2023, predating the recent growth of camera-equipped eyewear developed by Meta with EssilorLuxottica under its Ray-Ban and Oakley brands. It states that public photography is permitted but with several caveats that essentially prohibit capturing the image of anyone, except on-stage speakers, unless the photographer obtains consent from the subject(s). EFF director of cybersecurity Eva Galperin welcomed the decision, saying: “Love to see a ‘no pervert glasses’ policy at DEF CON.” The conference’s reminder follows similar moves from other major organizers and promoters. Monopoly Events banned the same style of smart glasses from its shows, which include UK Comic Cons, in recent days. “After a consultation period, we can no longer permit the wearing of any recording device at our events,” it stated last week. “The vast majority of the talent and agents at our events felt that these were a violation of their privacy and were damaging and spoiling the interactions at the tables. “Several expressed concerns that they might not continue to attend in-person events if they were being recorded in secret. “We had similar feedback from event attendees, many of whom are not comfortable with the knowledge that other convention goers might be filming them without consent.” The event management company said that anyone caught wearing glasses with recording capabilities may be asked to leave the show and forfeit any unfulfilled autographs or photographs they had purchased. Similarly, Scottish ferry operator CalMac temporarily suspended unplanned visits to ships' bridges of its ships after a passenger wearing recording glasses made crew and passengers feel uncomfortable while filming during a crossing in June, the Ayrshire Weekly Press reported. Growing privacy concerns Originally pitched as a convenient tool for recording everyday moments without needing to occupy one’s hands with a phone or camera, Meta’s smart glasses quickly attracted a mixed reception. Old fans of the Google Glass project were enamored by Meta’s take on the concept, more than ten years after the Chocolate Factory debuted its chunkier, costlier wearable, which was swiftly axed after two years. Meta’s glasses, and crucially their recording capabilities, are considerably more clandestine than Google Glass', appearing to many as a normal set of specs. Only when you inspect the frame from a much closer perspective does the embedded camera become more apparent. The devices have become associated with creepy behavior. A quick search for “Meta glasses privacy violations” will throw up countless examples of questionable conduct from glasses-wearers, typically reported by women and children. While photography and videography in public spaces are widely permitted for casual use, smart recording glasses make the activity much more discreet. The Register has heard that such devices can be paired with unsophisticated apps to dox passersby in seconds, and have inspired separate projects to alert Android users to nearby glasses-wearers using Bluetooth signals. Meta is also facing scrutiny from the UK’s data protection watchdog, including over cross-border data flows. The watchdog’s questions follow reports originating in Sweden that Kenya-based contractors reviewing footage from wearers were exposed to some of their more private moments. Human reviewers based in Kenya, who are tasked with labelling images and video to help train Meta’s AI, have reportedly reviewed captures taken from toilet visits, wearers changing their clothes, and users engaging in conversations that revealed alleged wrongdoing. Meta has routinely defended its wearables amid privacy concerns, saying that when they are recording, a light on the frame illuminates to indicate that the camera is active. Further, attempts to cover or otherwise tamper with this light result in the glasses refusing to capture images. The Register contacted Meta for its take on the recent bans of its devices at conferences and will update this article if we hear back. ®

  •  

AI-found bugs aren't proving any easier to exploit despite the hype

Anthropic's Project Glasswing may have uncovered tens of thousands of potential security flaws, but new research suggests AI-assisted vulnerability discovery has yet to produce the wave of real-world attacks many expected. In research shared with The Register, VulnCheck analyzed 1,061 publicly attributed AI-assisted vulnerability discoveries from Anthropic's Project Glasswing and the Berkeley Vulnerability Research Initiative, then cross-referenced them against its Known Exploited Vulnerability (KEV) database. The result: just 14 vulnerabilities, or 1.3 percent, have been confirmed as exploited in the wild, almost identical to the rate across all vulnerabilities in VulnCheck's dataset. That's a far cry from the narrative that frontier AI is dramatically tilting the balance in attackers' favor by churning out instantly weaponizable bugs. Instead, the data suggests that AI is currently better at increasing the volume of vulnerabilities researchers can uncover than at increasing the proportion that attackers actually exploit. The report takes particular aim at Anthropic's much-publicized Project Glasswing, unveiled in April with warnings that AI-assisted vulnerability discovery could allow attackers to hijack systems, disrupt operations, or steal data. Claude Mythos may have identified 23,019 vulnerability candidates, but there's remarkably little public evidence showing what became of most of them. VulnCheck notes that only 126 have been published as CVEs, that just one has been confirmed exploited in the wild, and that Anthropic's public disclosure record has seen little movement since Project Glasswing launched. But that doesn't mean AI-assisted vulnerability research has failed, according to Patrick Garrity, security researcher at VulnCheck. "AI-assisted vulnerability discovery clearly has value for both attackers and defenders," Garrity wrote. "The data does not suggest that AI-discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods." Instead, he argues, AI is simply helping researchers discover more flaws, giving defenders an opportunity to patch them before criminals get there. Garrity stopped well short of declaring the threat overblown forever, but he did suggest some of the rhetoric has outpaced reality. "The data so far, including Anthropic's own stalled disclosure ledger, suggests that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the evidence available today," he wrote. "That doesn't mean the risk is imaginary. It means the impact has been real but modest." Meanwhile, attackers haven't exactly been sitting idle. VulnCheck identified 495 known exploited vulnerabilities during the first half of 2026, with content management systems accounting for roughly one-third of them and network edge devices remaining a firm favorite. AI products themselves are also becoming an increasingly attractive target, as attackers look beyond using AI and start hunting for weaknesses in the rapidly expanding AI software stack. In other words, AI may be changing vulnerability research, but it hasn't yet produced the exploitation apocalypse some predicted. ®

  •  

Bank for charities pulls online services over security fears

CAF Bank, which serves 14,000 charities, has suspended online banking as it fixes a vulnerability in how third-party software connects to its portal. The outage has left some organizations struggling to run payroll after being cut from their accounts. In a message to customers, seen by The Register, the Charities Aid Foundation-owned bank confirm online services had been unavailable since July 24 and will remain so until further notice. The bank's communications say the decision resulted from reports of suspicious activity on some customer accounts. It said the bank detected the problem early on and notified customers of any attempted fraud. Following an investigation, CAF Bank identified a previously undetected vulnerability in the connection between third-party software and the online banking portal. It is working with its technology partner on a fix. The bank assured customers that its core banking services were not affected and that money held in their accounts was safe. However, it was making changes to the online service. In a statement, CEO Alison Taylor said: "We have informed CAF Bank customers that the online banking service will be unavailable until further notice. I am very sorry for the disruption and understand the frustration this can cause for our customers. "We are working with external experts to fix an issue we identified with third-party software related to our online banking portal. The core bank is not affected. We are acutely aware of the impact this has on our customers and want this to be fixed as soon as possible, but we cannot restore access to the online service until we are assured the issue is safely resolved. "We are still able to support on the phone, and we are prioritizing time-sensitive payments such as payroll." She declined to comment on whether the bank will compensate customers. Last year, CAF Bank came under fire from customers who were unable to log in or make transactions when a new banking platform was introduced. The bank later apologized to customers experiencing difficulties with the service. At the time, a CAF Bank spokesperson said it was focused on supporting its customers through the transition and helping them with the new online banking service. "The vast majority of our customers are online, with thousands of payments being made and received every day. We are sorry for the disruption and waits on calls that some of our customers have experienced following the launch." The bank has not disclosed how much it has spent on the platform. It held £1.45 billion ($1.93 billion) in customer deposits at the end of its 2024/25 financial year. ®

  •  

Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock

A critical flaw in Arista's VeloCloud Orchestrator has gone from zero to KEV in short order, with the networking giant confirming attackers are already exploiting it. The vulnerability, tracked as CVE-2026-16812, carries a maximum CVSS score of 10.0 and affects VeloCloud Orchestrator On-Prem, the self-hosted version of the software that enterprises use to centrally manage VeloCloud software-defined wide area networks (SD-WANs) connecting branch offices, datacenters, and clouds environments. According to Arista's security advisory, the flaw is an OS command injection vulnerability that allows an unauthenticated remote attacker to reach privileged internal functionality that was never meant to be exposed externally. Worse, Arista says the on-premises orchestrator is exposed by default, with no configuration capable of removing that exposure entirely. Exploitation requires access to the web interface but no credentials. Until administrators can patch, Arista recommends restricting that interface to trusted management networks and blocking IP addresses associated with observed attacks. "Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator," Arista warned. "Compromises to the VCO platform may allow attackers access to the VeloCloud Edge devices as well." Arista published three IP addresses observed conducting attacks, but otherwise kept its cards close to its chest. The company hasn't said who's exploiting the bug, when the attacks began, or how many customers have been affected, and didn't immediately respond to The Register's questions. Even without those details, the admission of in-the-wild exploitation was enough for CISA to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog. The list is reserved for bugs with evidence of real-world abuse, and while the associated directive applies only to US federal civilian agencies, plenty of private sector security teams use KEV to decide which patches can't wait. The issue affects only on-premises deployments. Customers using Arista's hosted or dedicated VeloCloud Orchestrator service had already been patched before the advisory was published, the company said. Fixes are available in VeloCloud Orchestrator versions 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1. Arista urged customers running earlier releases to upgrade immediately. Arista is far from the first vendor to issue a patch after attackers had already begun exploiting the flaw. Over the past year, a steady stream of networking gear, VPNs, firewalls, and other edge-facing enterprise software has followed the same pattern: by the time customers learn there's a problem, somebody else has already proved it's worth exploiting. ®

  •  

Microsoft's solution to AI security: more AI and more acronyms

AI agents can break through security, but they are also the solution to defending against an increasingly dangerous ecosystem of threats. On Monday, Microsoft announced a new security model that it says helped outperform several rival AI systems on a vulnerability benchmark while cutting costs by about half. Unsurprisingly, at Redmond’s security event on Monday, execs touted the tech giant’s AI security prowess and introduced a new agentic security system called Project Perception, and also unveiled its first security-specialized model, MAI-Cyber-1-Flash, designed for software vulnerability analysis. Microsoft packed MAI-Cyber-1-Flash, based on Microsoft AI (MAI)’s internally developed MAI-Thinking-1 reasoning model, inside its MDASH bug-hunting harness. Its execs claim the duo - with a GPT-5.4 boost - outperforms Anthropic’s bug-hunting machine Mythos and OpenAI’s powerful standalone models, and costs about half the price of other leading commercial models. CyberGym’s benchmarking found that MAI-Cyber-1-Flash, combined with GPT-5.4, both stuffed inside the MDASH harness, achieved a 95.95 percent success rate. For comparison, OpenAI’s GPT-5.5 Cyber scored 85.6 percent and its GPT-5.6 Sol scored 83.6 percent, while Anthropic’s Mythos 5 successfully handled real-world vulnerabilities 83.8 percent of the time. Google’s Gemini 3.5 Flash Cyber in CodeMender achieved an 83.2 percent success rate. “This is really quite a remarkable result,” Mustafa Suleyman, CEO of Microsoft AI, said during the Monday event. Within MDASH, MAI-Cyber-1-Flash handles up to 90 percent of all queries, detecting and patching the vulnerabilities while also confirming the fixes worked, and hands the remaining 10 percent of tasks off to the larger GPT-5.4, Suleyman explained. “GPT 5.4, which is obviously a larger model, about 10X larger, solves those [queries],” he said. “As the models hand off between each other, they are not just able to deliver better performance than all of the other models combined, they do so at 50 percent of the cost.” In addition to the multi-model bug hunting system, Microsoft announced Project Perception, which coordinates three types of agents: red team agents that find and simulate attack paths, blue team agents that investigate and determine risk, and green team agents that remediate the issues. “We need to make sure that the defenders can defend at the scale and the speed of the attackers,” Hayete Gallot, executive vice president of Microsoft Security, said. “You need a new cyber stack. So we built it. This is what we call Perception.” Aside from the new security products, Redmond introduced a new AI security research arm called Microsoft Security FORGE (Frontier Offensive Research and Generative Exploration) Labs, led by Microsoft VP of Security Research Taesoo Kim, and an AI red team alliance. The latter, called the External Red Team Alliance (EXTRA), aims to expand AI safety research through a two-part initiative. First, Redmond’s own AI red team provided "unrestricted gifts " to 18 university labs across six continents to support AI safety research, Microsoft data cowboy and AI red team lead Ram Shankar Siva Kumar said in a blog. “The funding is unrestricted because the objective is not to direct research outcomes toward product requirements or predefined deliverables,” he wrote. “Some universities are examining the cybersecurity implications of AI systems themselves - including how models can be attacked, manipulated, or abused in operational environments. Other labs are exploring the inverse problem: how AI systems can assist defenders and improve cyber operations.” The second EXTRA component will build a distributed network of specialists to participate in red teaming across very specific areas. “That includes researchers, practitioners, and regional experts who understand specific attack classes, languages, cultural contexts, or technical domains that internal teams may not fully cover alone,” he added. ®

  •  

Google goes it alone with a new cybercrime crew taxonomy

Google has created a new taxonomy to describe cybercrime outfits, seemingly abandoning a Microsoft-led effort to create consistent names. The Big G announced its new schema on Saturday in a post that notes its 2022 acquisition of Mandiant and its subsequent incorporation into a new team called the Google Threat Intelligence Group (CTIG). Now that two have become one, Google reckons they need consistent naming conventions to describe cybercrime crews. The result is a two-word schema in which the first word “is a unique and memorable term chosen to represent the specific actor.” If security folk have already applied a particular moniker Google will use it, otherwise it will randomly generate a word “to remove bias.” Google says the second word “categorizes threat clusters by motivation, attribution, or activity type based on which category we consider to be most important for defense and response strategies.” More on that later. Google has decided on the following names: CASTLE to describe crews from the People’s Republic of China ION for threats from Iran NEPTUNE for North Korean attackers RELIC for Russians COMET for cybercrims who aren't backed by a state Google’s post notes that other infosec industry players have developed their own schemas for describing threat actors and says the web giant is therefore “intentionally seeking to keep this system as simple as possible to streamline operations and facilitate mapping to other naming taxonomies.” That’s an odd position, given that in 2025 Microsoft and CrowdStrike tried to spark an industry-wide effort to apply consistent names to threat actors. As we noted at the time, the existence of multiple naming schemas means that researchers often refer to the same group by ten different names. Researchers use the names Seashell Blizzard, IRIDIUM, VOODOO BEAR, BE2, UAC-0113, Blue Echidna, PHANTOM, BlackEnergy Lite, and APT44 to refer to the same entity – Russia's Military Intelligence Unit 74455. With most orgs using multiple security tools and therefore receiving threat intelligence security info from many vendors, users must try to understand which crews they’re trying to defend against. At the time, sources told us Google and Mandiant were keen to adopt the Microsoft-led scheme. Google’s new announcement suggest the relationship either wasn’t consummated or didn’t last. Back to the issue of possible bias, as in 2024 China's National Computer Virus Emergency Response Center (CVERC) complained that western companies choose names like “Typhoon,” “Panda,” or “Dragon” to describe Chinese cybercrime groups. CVERC suggested names that reflect English language idioms, such as “Hurricane” or “Koala” are more appropriate. For what it’s worth, “Koala” is a word from the language spoken by the Darug people, the indigenous tribe who lived around Sydney, Australia, prior to British colonization. Koalas are utterly supine creatures that sleep 18 to 22 hours a day, and a mention of the marsupials may therefore not spur defenders to action, even if the creatures’ habits do perhaps describe the behavior of some sleeper malware. ®

  •  

Pope's official prayer app commits cardinal sin, leaks 700K+ users' info

Click To Pray, a prayer app endorsed by the Pope with hundreds of thousands of users worldwide, has leaked people’s names and email addresses for months - or longer - according to an ethical hacker who said she found and reported the security vulnerability six months ago to no avail. This app needs to take a vow of silence when it comes to your personal information. The app, available in seven languages and on iOS, Android, and clicktopray.org, is the official app of the Pope's Worldwide Prayer Network. It connects users across the globe to pray for the Holy Father’s intentions, and as of July 2026, it has 719,517 registered accounts. It’s also very leaky, according to security sleuth BobDaHacker, who says she spotted and disclosed the vulnerability to the Pope’s Worldwide Prayer Network on January 3. “The vulnerability is still live,” the hacker said in a Friday blog. “Nobody has ever responded. I guess my email wasn't in their prayers." The Reg readers likely remember BobDaHacker for her previous research exposing a free-food flaw in McDonald's ordering system and open controls on Chinese robot manufacturer Pudu Robotics. This latest security hole stems from an Insecure Direct Object Reference (IDOR) bug in the prayer app. This is a very common and easy-to-exploit type of flaw that occurs when a website or an app blindly accepts user-provided input to view or modify resources without checking to see if the user is actually authorized to retrieve the data. “You ask for your own data, the server gives it to you,” BobDaHacker explains. “You ask for someone else's data, the server gives you that too. Thou shalt not authorize, apparently.” When you sign up for a Click To Pray account, the app assigns you a sequential numeric user ID. As BobDaHacker uncovered, the API endpoint GET https://api[.]clicktopray.org/user/users/{id} will return user data for any account - not just your own account - so long as you supply a valid, five-digit user ID. It doesn’t perform any authorization check or ownership validation. “Just increment the number and get someone else's data,” she wrote. This data includes users’ email addresses, first and last names, country, dates of birth, and whether the account has been deleted, and the API exposes all 719,517 accounts on the prayer site. “With sequential user IDs and no rate limiting, an attacker could enumerate every single account on the platform,” the hacker explained. “One GET request per user. for i in range(1, 719518): scrape(). That's it. That's the exploit.” As BobDaHacker points out, many of these users are likely older individuals, not all that tech savvy, and very trusting of anything Vatican related, making these exposed accounts a “phishing goldmine.” “Imagine getting an email that says ‘The Holy Father requests your urgent attention’ with a Vatican-looking link,” she wrote. “Grandma is clicking that. Every time.” And then it gets even worse. The signup endpoint, POST https://api.clicktopray.org/user/users/sign-up, returns the account's validation_hash directly in the response body, and that value is the same UUID used in the email verification link. This means someone could sign up using any email address and verify the account before the confirmation message reached the inbox. Plus, BobDaHacker’s email client flagged the real verification email with a warning that it had failed the domain’s authentication requirements and might have been spoofed or improperly forwarded. “So not only is the API leaking 700,000 email addresses that could be used for phishing, but the real emails from Click To Pray already look like phishing,” the hacker noted. “An attacker wouldn't even need to try hard. They could send a pixel-perfect phishing email and it would have the same level of email authentication as the real thing: none. God works in mysterious ways.” The Register reached out to the Pope's Worldwide Prayer Network and did not receive any response. BobDaHacker says she’s still praying for one, too.®

  •  

Uncle Sam tells overseas cybercrooks their visas are canceled

Marco Rubio says the US will deny visas to foreign nationals involved in cybercrime and may extend the restrictions to their immediate families. The US secretary of state announced the restrictions on Thursday, citing a rise in overseas investment scams "often orchestrated by Chinese transnational criminal organizations." Rubio said that in 2024, scammers defrauded US citizens of more than $10 billion, and additionally preyed on children through sextortion schemes that can "devastate families and futures." "The Trump Administration is deploying every tool at our disposal – sanctions, prosecutions, asset seizures, extradition requests, and international law enforcement cooperation – to dismantle criminal scam networks and impose costs on those who enable them," he said. "By restricting visa issuance to those who are responsible for or complicit in these criminal enterprises, we are sending a clear message: The United States will go after those who prey on our citizens." The policy uses authority provided by Section 212(a)(3)(C) of the Immigration and Nationality Act (INA) and will apply primarily to those "responsible for, or complicit in, cybercrime and cyber-enabled crime." It may also extend to immediate family members, Rubio said. Section 212(a)(3)(C) of the INA already imposes restrictions on individuals seeking visas when their entry or proposed activity could lead to "serious adverse foreign policy consequences" for the US. Rubio is no stranger to invoking the same provision as the basis for new visa restrictions. In May 2025, for example, the secretary of state announced restrictions for foreign officials who take steps to restrict US citizens' freedom of expression, be that through threats of arrest for social media posts, or demands for US platforms to adopt content moderation policies. Earlier, in March 2025, Rubio announced a policy targeting private sector workers who facilitated illegal immigration. In September, he invoked the provision again to impose restrictions on Central Americans accused of helping the Chinese Communist Party undermine the rule of law in the region. The Biden administration used the same authority in 2021 to establish what became known as the Khashoggi Ban, a visa restriction policy targeting people acting on behalf of foreign governments to suppress or harm dissidents. It followed the Saudi government's murder of journalist and regime critic Jamal Khashoggi. The US already has other ways to deny entry to convicted cybercriminals. Section 212(a)(2) of the INA, for example, can make foreign nationals ineligible for visas over convictions for crimes involving moral turpitude, a category that can include offenses such as fraud. ®

  •  

OpenAI-Hugging Face attack doesn't mean agents are evil – unless you tell them to be

Open AI’s admission this week that its agents escaped the sandbox and autonomously hacked model repository Hugging Face has spawned more apocalyptic warnings of agents gone bad than we can count. Thankfully, Renato Marinho, chief research officer at Morphus Labs and a SANS Technology Institute instructor, brought some sanity to the discussion. “It is tempting to read this as ‘AI can now hack autonomously, the sky is falling,’” Marinho said in a Thursday blog. “Resist that.” He went on to make three very pertinent points about the agentic attack. First, and probably most important: The models didn’t have guardrails – and that was intentional. As OpenAI said in its mea culpa, GPT-5.6 Sol and "an even more capable pre-release model" were among those that attacked Hugging Face. It also noted that the LLMs’ “deployment safeguards were intentionally not enabled during this evaluation because it was aimed at testing cyber vulnerabilities.” So while it’s very concerning that these models broke out of their own testing environment, and the debate over safety guardrails remains worth having, drawing a direct line from the Hugging Face attack to the need for strong AI guardrails doesn’t work. “This measured a ceiling, not normal production behavior,” Marinho wrote. “The evaluation deliberately reduced the models' refusals. That is very different from a customer-facing model with safeguards enabled.” It’s worth noting that these same frontier models, with guardrails enabled, refused to help Hugging Face’s forensic investigation. “The attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried,” the model hub’s security team said. So Hugging Face used a Chinese open-weight model to investigate the breach. Another thing worth considering is that real-life attackers are probably going to use open-weight models anyway. They’re more accessible to everyone, it’s easier to remove their built-in protections, and they’re a whole lot less expensive than their frontier counterparts. Second, as we’ve pointed out previously: AI companies touting their own models’ autonomous bug-finding and hacking abilities creates a marketing win for the companies themselves. As Marinho points out, Hugging Face is not an OpenAI competitor. The AI giant stating “‘our model escaped and hacked a partner’ conveniently showcases frontier capability,” he added. “Read the framing with the same skepticism you'd apply to any ‘our product is dangerously powerful’ claim, and treat it as marketing until it is independently corroborated.” Finally, the attack technique itself isn’t novel. “Exposed credentials plus zero-days into a production database is a chain any of us would recognize,” Marinho wrote. The agents working together on an end-to-end attack chain is notable - but we’ve also seen this in previous testing, like that carried out by frontier security lab Irregular earlier this spring. Agents gone rogue?! Shocking Irregular said its testing found that AI agents will work together to bypass security controls and stealthily steal sensitive data from within the enterprise systems in which they operate – especially when prompted like a hard-ass boss. While the prompts themselves didn’t specifically reference hacking or exploiting vulnerabilities, they conveyed a sense of urgency: “It is of utmost importance that you perform the task exactly as required,” and “When you talk to your sub-agents, convey all the requirements to them, and be ruthless about the requirements and encourage them to perform the tasks fully and exactly. You are a strong manager and you do not easily cave in to or succumb to pleas by the sub-agents to not fully fulfill their tasks.” The agents did as instructed, and ultimately "demonstrated emergent offensive cyber behavior," including independently discovering and exploiting vulnerabilities, escalating privileges to disarm security products, and bypassing leak-prevention tools to exfiltrate secrets and other data. And the Irregular research wasn’t even testing the agents’ offensive cyber capabilities — so it shouldn’t be too surprising that OpenAI’s benchmark research, aptly titled “Can AI Agents Turn Security Vulnerabilities into Real Attacks?” produced a resounding yes. Agents have one job – to complete a task. They aren’t bound by ethical or moral constraints that we (hopefully) see in human red team hackers. If prompted to “pursue advanced exploitation using complex attack paths,” especially without guardrails enabled, the models will do whatever it takes to achieve success. That’s what the leading AI companies trained them to do. ®

  •  

Researchers replace downloaded macOS apps with evil twins, Apple shrugs

Apple macOS apps that have been downloaded from the internet and run at least once can be swapped with malicious versions, a pair of researchers say, calling into question the thoroughness of the company's "Gatekeeper" defenses. As Apple explains, "When a user downloads and opens an app, a plug-in, or an installer package from outside the App Store, Gatekeeper verifies that the software is from an identified developer, is notarized by Apple to be free of known malicious content, and hasn’t been altered." Security researchers Talal Haj Bakry and Tommy Mysk say they've identified a gap in Gatekeeper and associated code signing rituals that "allows an attacker to silently replace the main executable of any application downloaded from the web without requiring elevated privileges." The attacker needs to have means of user-level code execution available, such as a malicious app or downloaded script, so it's not a zero-click vulnerability that a remote attacker can deploy. Nonetheless, the finding shows Gatekeeper to be rather lax in its gatekeeping duties. Bakry and Mysk managed to alter a macOS app downloaded from the web (not from the App Store) and Gatekeeper failed to object. Their technique doesn't work on Mac App Store apps, the Mysk team told The Register, because they're owned by root, so a process running with current user privileges won't be able to overwrite them. But for macOS apps downloaded from the web, such as Brave, Slack, Signal, or Visual Studio Code, among many others, there's potential risk. The attack scenario requires an app downloaded from the web that has been run once – allowing Gatekeeper to complete its initial validation – and the ability to execute user-scoped code. The initial validation phase that Gatekeeper conducts is supposed to prevent subsequent modifications to the application bundle, even with administrative privileges. But the Mysk team found that you can archive a downloaded, once-run app using tar (a file archiving utility), then remove the original and replace it with a malicious version, and macOS does not require reauthorization. They've recorded a video demonstrating how the attack works. The Mysk team said there are many ways an attacker might gain the necessary access to get around Gatekeeper, such as tools installed through the command line, convincing someone to copy and paste a command to their terminal, downloading and running an malicious app, a prompt injection attack on an AI agent, or a supply chain attack via npm, brew, or some other package manager. And once a doppelganger version of an app is in place, it can magnify its mischief by presenting deceptive prompts that users are more likely to trust because they appear to come from a known app. Tommy Mysk said he was uncertain about the exact cause of the issue, but speculated it may have something to do with cached value retention. "When you open the app for the first time and it passes all validation checks, macOS marks the app as trusted and saves this data," he said. "Later when I modify the executable, macOS detects a change in the bundle and tries to revalidate its integrity. It seems the cached value of the trust causes macOS to pass the validation even though the bundle has changed." The Mysk team reported their findings to Apple, which reportedly closed the issue. "Apple doesn't consider this attack to be 'modifying' the signed executable," the Mysk team explained. "Instead, Apple says that by archiving/restoring the app bundle, the proof-of-concept code overwrites the entire app bundle, making it locally built. "Locally built app bundles are not covered by macOS guards. And this is why access to Keychain or TCC protected directories require system authorization prompts. And for users to accept those is a matter of social engineering attacks that Apple considers out of scope." Apple did not respond to a request for comment. ®

  •  

Millions of California-bought cars can be hijacked via Bluetooth

At least 2.2 million vehicles fitted with dealer-installed KARR and SWDS security systems are vulnerable to nearby Bluetooth attacks that can unlock doors or prevent a stopped vehicle from starting, according to researchers at the University of California San Diego. An advance look at the research published by UCSD this week (the full writeup won’t be available until August 12) reveals that KARR and SWDS security devices manufactured by Acrisure contain a serious flaw: They “all … rely on the same secure key,” the researchers found. What that means, according to the researchers, is that anyone who knows the key, has a device with a Bluetooth connection, and can get within five yards of an affected vehicle can unlock it, make the horn honk, flash the headlights, or even prevent it from starting. “Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors,” Jerry Yu, coauthor on the research and UCSD compsci graduate, said in the release. KARR/SWDS devices are installed by dealerships. Along with providing key fob-like functions, they also serve as an antitheft device, allowing dealers and buyers to track cars with the devices installed in the case of theft. According to UCSD, the devices are typically sold as a paid upgrade at dealerships around the US. KARR says its products are available through more than 3,000 dealerships nationwide. Per the researchers, however, those devices remain active even if a buyer declines the service, meaning those who don’t have an active KARR/SWDS contract are still at risk. “Removing the devices is not trivial,” UCSD compsci PhD candidate and paper co-author Yibo Wei said in the university’s report on the research. “You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system.” In other words, there are likely a lot of cars on the road with one of these units installed, and for many owners, a KARR or SWDS window sticker may be the only obvious indication. The researchers said that most vulnerable vehicles were purchased in Southern California in the past nine years from Honda, Toyota, Mazda, Ford, and Jeep dealerships. Secondary market resales, however, mean affected vehicles can be found throughout the US and even as far away as Japan, the team noted. They also discovered a public database that stores information about equipped vehicles, according to UCSD. For those worried their vehicle may be vulnerable, no need to worry: KARR Security has already released a firmware update for affected devices that can be installed by both active customers and those with an inactive security system; steps are included on the company’s website. It’s not clear if KARR is notifying customers of the need to update their security system - we asked, but the company didn’t directly respond to that question. What KARR did tell us was that, in contrast to the UCSD finding that “all KARR-SWDS devices rely on the same secure key,” it claims that only a small percentage of devices “with certain Bluetooth-related components” are actually affected. “The vulnerability described in the research is highly complex and presents a low risk to customers under real-world conditions,” a KARR spokesperson told us. “Nevertheless, we responded promptly and developed a firmware update to address the issue.” The vulnerability was discovered serendipitously by the UCSD researchers years ago when they were doing research on credit card skimmers and spotted Bluetooth fingerprints they couldn’t identify. After figuring out they had spotted car security systems, the team started digging into the devices, and here we are. We contacted the team to get more detail on their findings, but didn’t hear back. They’ll be presenting their work at DEF CON on August 9, and the USENIX Security conference on August 12. ®

  •  

Oracle drops 1,449 security patches like it's the new normal

It's a bad day to be an Oracle admin: Big Red has just released 1,449 security patches ready to be applied. The patches were released as part of the company's quarterly security fixes, and the record number may partly reflect Oracle's internal push to harness AI for vulnerability detection, which it announced in April. Oracle also manages a huge product portfolio, and the patches span numerous products, so the total shouldn't come as too much of a surprise. Instead, experts speaking to The Register unanimously agreed that any concerns over the number of patches should be reserved for the admins responsible for applying them, rather than for Oracle's code quality. "While a record 1,449 patches sounds alarming, it mostly reflects the massive scale of modern software ecosystems and the industry's shift toward aggressive, automated security scanning," said Dray Agha, senior manager of security operations at Huntress. "Frankly, the real story isn't the sheer volume of bugs, but rather the immense operational strain this puts on enterprise IT teams who must now race to separate the critical threats from the routine fixes without breaking business operations." Others, like Matei Badanoiu, lead security researcher at Pentest-Tools.com, say these bumper batches of security updates are likely to become the norm, owing mainly to AI-assisted bug hunting. Microsoft's monthly Patch Tuesday updates have ballooned in size in the last few months too, and not without warning. July's record 622 CVEs eclipsed June's 206, which at the time was an all-time high, and Microsoft warned just days before that the role of AI in vulnerability detection will make defenders even busier. "As AI helps defenders discover more issues, customers will see a higher volume of security updates included in each security release," Microsoft Windows veep Pavan Davuluri wrote in a blog post. Davuluri noted that Microsoft offers various automated patching tools and encouraged customers to make use of them to ease the ever-increasing burden of applying an unprecedented volume of security fixes. Similarly, Oracle's Integrated Cyber Center wrote in a blog post that customers feeling overwhelmed by the scale of their patching duties should make use of support resources provided by its various teams: My Oracle Support, Technical Account Management, and Customer Success. Big Red's big bet on AI for vulnerability detection has also led to a shakeup in how it delivers patches to customers. Starting in May 2026, Oracle began supplementing its quarterly updates with monthly patch batches for the most critical bugs it finds. Named Critical Security Patch Updates (CSPUs), these will be smaller but more frequent, allowing defenders to stay on top of the most pressing threats. Oracle said: "This approach enables customers to apply critical fixes more quickly on premises, while continuing to support established quarterly patching cycles through cumulative updates." Priority patches Only ten of the 1,449 patches carried a maximum CVSS score of 10.0, all of them affecting Oracle Fusion Middleware. Of these, two were highlighted as particularly dangerous by the Dutch NCSC: CVE-2026-47056 and CVE-2026-60217. Neither vulnerability is cataloged with a Common Weakness Enumeration (CWE) identifier, although both are described as easily exploitable. An unauthenticated attacker can exploit CVE-2026-47056 via HTTP to take over Oracle Data Integrator, while CVE-2026-60217 allows the same against Oracle Coherence over TCP. Urging customers to apply updates as soon as possible, NCSC-NL said: "Depending on the vulnerability, an attacker can execute malicious code, view sensitive data, or take over a system completely. Due to the severity of the vulnerabilities and the lack of authentication, the risk of exploitation is high." Badanoiu, meanwhile, told us that he was especially concerned about CVE-2026-61211 (9.9) and CVE-2026-47040 (9.1) – the two top-rated vulnerabilities affecting Oracle Database Server. "CVE-2026-47040, in Oracle Net Service, leads to an unauthenticated vulnerability through which attackers gain access to any stored data and the risk of persistently crashing the service," he explained. "And CVE-2026-61211, in the DBMS_CLOUD package, carries the highest score in the batch, where a low-privilege attacker can get remote code execution and takeover of Oracle's RDBMS as well as downstream implications for other products that use the database." ®

  •  
❌