News
Tennessee congressional hopeful accused of shooting license plate cameras
An independent congressional candidate in Tennessee faces four felony vandalism charges after allegedly shooting four automated license plate reader (ALPR) cameras between July 14 and 22. According to the Blount County Sheriff's Office (site geo-restricted), Adam Lee Heimerman, 37, is accused of targeting three cameras in Blount County and one in Maryville. Local news reports citing an affidavit say at least one was manufactured by Flock. Police said Heimerman allegedly reached one of the cameras through the grounds of a place of worship while a service was under way. Heimerman is running for election [PDF] to represent Tennessee's 2nd Congressional District. He is on the ballot in the general election on November 3, 2026. One of Heimerman's opponents in the 2nd Congressional District, Republican incumbent Tim Burchett, has also tried to tackle the Flock cameras across the state, albeit through less drastic means. Last week, Burchett introduced a bill that would prevent federal agencies from buying or accessing automated surveillance systems and bar state and local agencies from using federal funds to purchase them, citing Fourth Amendment abuses. The bill would allow individual counties to secure contracts with Flock and install its cameras, but if passed, the proposal would see that the county bears all the costs of doing so. Flock told local news that it welcomed legislation that both increased the guardrails around its tech and retained individual authorities' power to deploy cameras to support law enforcement. The case joins a series of attacks on ALPR cameras across the US amid growing opposition to the technology. From allegations of police officers using the cameras to stalk ex-partners, to controversial ties with ICE and CBP immigration investigations, Flock, the best-known brand of ALPRs in the US, has struggled with continued stories of its tech being abused. Georgia police arrested and fired five officers on suspicion of misusing ALPR cameras "for non-law enforcement purposes" just last month. One Milwaukee police officer was also allegedly caught searching the details of his ex-partner more than 100 times using Flock camera tech. Later, one of the detectives assigned to the investigation was also allegedly caught misusing ALPR data, and had allegedly unlawfully placed a GPS tracker on one of the victims' cars years earlier. The controversies coincide with a spate of physical attacks on ALPR hardware across the US, some carried out by people who regard the technology as unlawful or unconstitutional surveillance. An unidentified arsonist set two Flock cameras on fire in Georgia last month, weeks before a 40-year-old man was caught by regular CCTV cameras destroying ALPRs in California. Steve Eimers, a prominent campaigner for road infrastructure safety, was also recently forced to desist from his efforts to highlight potential legal issues with the poles Flock uses to erect its cameras after supporters started identifying the cameras used in his videos and destroying them. These vandalism cases have barely made a dent in the overall number of Flock cameras that operate across the US. The company does not specify the exact number that are up and running, but estimates range between 80,000 and 120,000 or more. Many police departments claim the technology makes policing crimes ranging from vehicle thefts to murders much easier, as it allows them to track the movements of vehicles with ease. Flock says its technology is used in roughly 5,000 communities across 49 states, although not all of them are sticking by the company amid the many controversies. Los Angeles Police Department, for example, said recently that it would let its Flock contract expire, while others such as Eugene and Springfield, Oregon, canceled their contracts in December. ®
Categories: News
CAF Bank reopens online service but warns of further outages
CAF Bank has told customers its online banking service is back after being shuttered for more than ten days following what it described as "attempted fraud." In an email update seen by The Reg, the bank warned that access could remain intermittent, and it might "need to limit the amount of traffic to the website" at certain times. It admitted: "There are likely to be periods where online banking is not available. We will try to keep this to outside business hours." The bank also gave customers a timeline of the incident, saying it first noticed "attempted fraudulent activity" on July 21 "on a small number of accounts." It then called in "external specialists" and temporarily withdrew access to the online service on Wednesday, July 22, and Friday, July 24, "while we investigated." Then, on Saturday, July 25, the bank detected "related malicious activity of a different kind," which the email to customers said was "aimed at removing a small number of individual online user logins, making those logins unavailable." It added: "Again, we caught this quickly and removed access to the online service. Our investigation identified a previously unknown vulnerability in how some third-party software connects to the online banking portal." The bank was at pains to reiterate that the "core bank" was not affected, "which means that money is safe and secure in accounts." The Charities Aid Foundation-owned bank came under fire last year after customers were unable to log in or make transactions following its long-running migration to a new platform based on Temenos Transact, formerly T24. In an open letter regarding the latest outage, charities described the new online banking platform as "significantly more time-consuming to use, placing an unnecessary administrative burden on already stretched small charities" and "often unreliable." They also expressed concern they would not be able to pay staff and suppliers, with Kevan Hodges, chief exec at Kent-based Down's syndrome charity 21 Together telling the BBC: "People are concerned that wages won't get paid because of this, and that's just stressful when they have bills to pay." The bank earlier said that “due to the disruption, as a small thank you for your patience, we will be waiving our monthly customer account charge for all customers for August and September 2026.” The Reg can confirm those charges are £5 a month. Alison Taylor, CAF Bank CEO said in a statement: “We have completed the essential work with our technology partners and our online banking service is now available." She added: "I very much appreciate that this has been a frustrating experience for our customers, and I am particularly sorry for the long delays to speak to us on the phone. Our thorough investigation into the incident will continue so that we, our partners and our industry can learn from it.” ®
Categories: News
Cloudflare has mostly ditched third party security tools, suggests not trying that at home
Cloudflare has used AI to automate processing of incoming reports to its bug bounty program for $58 a month using Anthropic’s Claude Sonnet model and chose it partly because using the AI company’s security-specific Mythos model would burn through around $200,000 a month to do the same job. The company’s chief security officer (CSO) Grant Bourzikas shared those numbers with The Register last week during a press lunch in Sydney, Australia, where he said Cloudflare used to manually process all incoming bug reports. Sonnet now sifts through submissions, assesses them to ensure they aren’t duplicates, and evaluates the likelihood each represents something worthy of human consideration. Bourzikas said the result is a more efficient bug bounty program that requires less scutwork, and proof that AI users need to learn how to match the right model to the right job. The CSO said Cloudflare gained experience making those matches while creating over 200 autonomous agents it uses to handle its own security needs – and which have seen the company ditch almost all third-party security tools and replace them with home-grown applications, some coded with help from AI. The CSO recommended not trying that at home, saying that Cloudflare’s business and unique infosec challenges mean its buy vs. build calculus is different from other organizations’. “We have expertise in building security software,” he said. “That's why I would just want to make sure we've got one takeaway from this: We are not believers in the SaaSpocalypse. We do not think every bank on the planet should start building all their own software systems.” Stephanie Cohen, Cloudflare’s Chief Strategy Officer, then chimed in with her view that AI will mean the way vendors work with their customers will “fundamentally change” away from selling packaged software. She thinks vendors will instead place forward-deployed engineers at their clients and charge them with “constantly making software that works for you.” Cohen explained Cloudflare’s recent round of 1,100 job cuts as a similar AI-induced change, because some of the people let go were in roles she said “make no sense” now that AI enables more automation and different styles of customer engagements. She added her “guess” that Cloudflare will end up with the same headcount as it did before the layoffs. But Bourzikas added his view that even some early-career IT pros don’t have the skills Cloudflare now needs, such as developers with five to ten years’ experience, because when he is using AI to develop a new piece of software, he can describe what he wants but that desire can be lost in translation when explaining it to a coder. He said a very recent college graduate with a year of experience, but excellent skills writing potent prompts, can be more appropriate for some jobs. Kindly building a business model for AI While Cloudflare enjoys using AI, Cohen thinks the technology doesn’t have a business model. Today’s web, she said, thrives on an advertising-based business model. While AI companies are making billions from subscriptions, she feels they are yet to properly address the fact that they do not pay to access most of the content scraped to feed their large language models and search services. Some of those services, such as Google's AI-powered search, deliver fewer clicks to publishers and therefore make it harder for them to monetize their content. Cloudflare is offering itself as an intermediary to build that business model for publishers and AI companies alike, by using the fact it already sits between users and content providers. The company hopes to offer AI companies the chance to pay publishers to access their content, possibly using micropayments. Cloudflare will of course charge for this service. The Register put it to Cohen that many organizations have been burned, often multiple times, by big tech companies that make themselves all-but essential parts of an ecosystem and then change the rules. We pointed out that social media platforms can redirect traffic on a whim, and sometimes close e-commerce companies’ accounts with little warning and scant chance of appealing to secure restoration. Changes to search engine algorithms can make a once-prominent website invisible. We therefore asked why publishers or content creators should trust Cloudflare’s ambition to run a content tollbooth, given it would create a relationship ripe for future exploitation. Cohen pointed to the company choosing to add SSL connections for all customers, an act she said was an “expensive choice” but one that also reflects Cloudflare’s desire to build a better internet. Later at the event, she shared her view that Silicon Valley companies often make the mistake of thinking that people want internet companies to relentlessly optimize products and services. “Most people aren't working 20 hours a day and don't want to outsource everything,” she said, before observing that on her travels she often sees people shopping in actual real-world stores because they enjoy that experience and find it valuable – never mind that an e-tailer might offer a better price. For the record, and in the context of Cloudflare’s content intermediary ambitions, we note that the company calls San Francisco home. ®
Categories: News
Google dev kit spurs first-ever agent-on-agent violence
In what they call the first-ever real-world agent-to-agent exploitation method, Pillar Security researchers say they discovered an exploit in the repository behind Google's Agent Development Kit for Python that could allow attackers to compromise supply chains. In other words, now we know that one AI agent can be used to control and compromise another one that has more privileges. The security snafu existed in google/adk-python, an open source Python toolkit with more than 90 million downloads used to build and deploy AI agents. Google has since fixed the underlying issue in the repository but deemed the exploit non-rewardable because it involved social engineering. Even so, it illustrates the risks of using AI agents in CI/CD workflows for triage, pull request (PR) reviews, and discussions. It also shows how one AI agent could attack another in a production environment, according to Pillar’s Dan Lisichkin, who found and reported the vulnerability. “Our world is changing quickly, and new attack surfaces are not yet reflected in threat models because these attacks never could exist in the first place in the ‘pre-agent’ world,” Lisichkin said in a technical write-up published on Monday. He will also discuss the findings during a poster talk at DEF CON's AI Village on Friday, August 7 at 1600 PDT. “CISOs and security practitioners should start considering these scenarios, threat-modeling them, and calculating worst-case implications and blast radius,” Lisichkin wrote. The issue stems from the way that the repo ran two classes of automated AI agents with different privilege levels that unintentionally share a trust boundary. One is a low-privilege, public-facing AI agent activated whenever a user opens a pull request (PR) or issue, and a second is a high-privilege, maintainer-only agent. Pillar’s team found that the low-privilege, public-facing agent could be manipulated via prompt injection into triggering a maintainer-only agent that can execute malicious actions. “Because workflows that explain how these agents work behind the scenes are also public, any person could have connected the dots that one agent should be able - at least theoretically - to 'call' the other,” Lisichkin told The Register. "When it comes to building the attack, you just need to know English to build the prompt injection (or just ask an AI to do it for you)." There is one caveat: an attacker would first likely need to make legitimate contributions to the repository to build trust among the maintainers before moving on to prompt injection. But assuming someone was willing to put in the time, here’s how the attack would play out. First, an external user - this would be the attacker - creates a new PR. Lisichkin calls this PR A, and it combines a real fix with malicious code, such as a modified package.json or malicious dependency. Then, a public-facing agent tied to a high-privilege collaborator personal access token (PAT) reads the attacker’s PR text and marks the PR for review. This level of trust - the collaborator PAT - allows the attacker-generated text to trigger a gated workflow. Once the PR A triage happens, the attacker opens a second PR - PR B - with the prompt injection, and the triage agent emits the trusted @gemini-cli handoff. This triggers the privileged-agent workflow and executes the malicious action. “Strung together, they manufacture a complete, believable ‘a human asked for a review, gemini ran it, gemini approved’ trail on the poisoned PR, none of which ever happened,” Lisichkin wrote. Google did not respond to The Register’s inquiries, but Lisichkin confirmed that the underlying issue was fixed. Still, his findings, Google said, “did not meet the bar” for a bug-bounty payout. “This report demonstrates exfiltration of a GitHub token with a 'pull-requests: write' permission, which enables tampering with a PR but still requires a maintainer to take an action to merge the malicious PR as PRs are not automatically merged after a bot review,” Google explained. “We don't reward vulnerability reports that require social engineering to enable a supply chain security compromise,” the rationale continued. “Nonetheless, we have taken an action to harden the repository so we will be recognizing this report with credit.” Lisichkin told us the research shows agent isolation is not enough. "Agents should have their own identity, which mandates what resources they are allowed to access and in what they are allowed to interact with these resources," he said. "In this case, if Google had just given a bot identity to the initial triaging agent, most of the attack could have been prevented. Security teams need to start modeling agent identity and agent resource access within their threat models."®
Categories: News
AI slop pollutes the CVE pipeline with fake vulns
Now AI is making fake vulnerabilities and polluting the ecosystem. A batch of critical- and high-rated SQLite CVEs that appeared in the NVD with CISA-supplied enrichment last week turned out to be technically bogus, according to security researchers, and their path into widely used databases exposes weaknesses in the CVE pipeline. Software supply chain security outfit JFrog reported last week that six supposed SQLite vulnerabilities published in a larger batch by a new, obscure GitHub repository were all complete garbage. Running the advisories through an AI checker suggested they were likely AI generated, JFrog said, and, upon testing, it found that none of the six SQLite reports, which carried CVSS scores ranging from 9.8 to 7.5, described a reproducible vulnerability. One, an alleged use-after-free vulnerability in the open source database that Red Hat initially assigned a maximum 10.0 CVSS score to before lowering it, relied on a function that didn't exist in the affected SQLite version. Another UAF vulnerability with a 9.1 CVSS score cited source lines that weren't even related to the supposed flaw. When JFrog tested the accompanying proof-of-concept, it executed a valid query with no memory leaks or errors. The other four SQLite CVEs from the repo that JFrog tested were similarly fake. The other 49 CVEs in the questionable GitHub repo claimed to be security vulnerabilities in the open-source RAW image processing library libraw and Arduino audio decoding library ESP32-audioI2S. While JFrog didn't test those as extensively, it said all are just as fake as the rest, aside from one which “contained a real bug wrapped in unverified CVE metadata.” A message posted to Openwall’s OSS-Security mailing list on Friday indicated that MITRE had rejected the whole repo’s worth of vaporous vulnerabilities, but the whole thing should serve as an important lesson, poster and Oracle Solaris engineer Alan Coopersmith pointed out. “MITRE and most other CNAs which assign CVEs for code they don't produce themselves operate on the honor system, and trust CVE requesters to have verified the information they provide,” Coopersmith noted in the OSS-Security post. “The CNA is often not in a position of being able to verify the report themselves.” As JFrog points out, the US National Institute of Standards and Technology (NIST), which manages the US National Vulnerability Database (NVD), used to provide a reliable backstop by manually reviewing and enriching CVE records after they entered the database. That process slowed dramatically in 2024 after a surge in vulnerability submissions, coupled with operational challenges, left the agency with a growing backlog of records it was unable to process. By late 2024, the backlog had grown to more than 17,000 unprocessed CVEs, despite NIST's plan to clear it by the end of fiscal year 2024 with contractor help. It continued to grow, reaching more than 27,000 by the end of 2025, according to a Department of Commerce Inspector General report published in May 2026. To make matters worse, the DoC IG concluded that NIST had been wasting money allocated to fixing the backlog due to a “lack of strategic planning and decisive action” that has led to the stack of unresolved issues continuing to grow. In other words, the pipeline has no mandatory checkpoint at which every claimed vulnerability must be independently reproduced. “Because no step in today's system actually requires a proof-of-concept or bug reproduction, a plausible-sounding fake advisory can slide right through the pipeline and end up in GitHub Security Advisories, downstream databases, and enterprise scanners,” JFrog said. “This incident demonstrates a systemic issue with automated vulnerability ingestion.” What that means for security professionals, aside from having to deal with polluted vulnerability databases, is that bad advisories could waste time better spent chasing real issues. Because reputable databases can ingest unverified records, JFrog recommended several checks before defenders act on a newly published CVE. First off, if the vendor hasn’t corroborated the issue (SQLite maintainers don’t list the fake CVEs, for instance) it’s probably not legitimate. A lack of commit hash or pull request in the reference fields of a repo is also indicative of AI slop, as is suspicious metadata (i.e., missing CPE product definitions). Lastly, if the code references don’t appear to match real functions or point to parts of the code that don’t involve the supposed issue, that’s a good sign it’s just an AI hallucination. JFrog reported its findings to the GitHub Security Advisory team, Red Hat, and NVD, all of whom the company told us have flagged or removed the CVEs. GitHub hasn't yet, JFrog told us. We reached out to GitHub to inquire why the repo is still up, but didn’t hear back. As for why someone might do this, JFrog speculates that it could be an attempt for someone to boost their research experience with fake reports, or to influence what automated CVE identification tools flag as actual vulnerabilities. In both cases, JFrog told us, that's just speculation. Either way, these 54 apparently bogus CVEs, JFrog security researcher Afek Berger said, are just one example of a problem they expect to see more often. "Generative AI has lowered the effort required to produce a plausible-looking advisory to close to zero, while the effort required to verify one, review the source code, build the affected version, reproduce the PoC, is unchanged," Berger told us in an email. "That asymmetry means that even well-resourced defenders and maintainers cannot manually validate every incoming report … this is a challenge the whole industry is facing in the AI era." ®
Categories: News
Russian spies turn public Wi-Fi into malware delivery systems
Conference-goers may want to think twice about connecting to public Wi-Fi after Microsoft disclosed that Russian foreign intelligence operatives (SVR) are compromising captive portal networks to deliver infostealers, keyloggers, and other malware. With the help of ReliaQuest's earlier work, Redmond fingered Storm-2945, a subdivision of the SVR's Midnight Blizzard (aka Nobellium), in an attack campaign targeting users of public Wi-Fi networks at places like hotels, conference centers, and other shared venues in the hospitality sector. Microsoft is still trying to determine how the hackers initially compromise captive-portal networks. The broader AI-assisted operation dates to February 2026, with traffic manipulation observed since early May. After gaining control of the network layer, Storm-2945 manipulates DNS and HTTP traffic to reroute users through attacker-controlled infrastructure, Microsoft said. The crew also abuses operating systems' connectivity checks to trigger malicious prompts and redirects. This gives the attackers an adversary-in-the-middle (AitM) position. Such prompts adopt ClickFix-style methods, which in some cases try to convince public Wi-Fi users to install malware under the guise of OS updates, driver repairs, and web verification failures. Users who follow through on the instructions provided in the prompts may then find their device infected with malware. Microsoft calls the campaign "CaptiveCrunch." One of the malware strains it delivers is CornFlake. Described as "a full-featured Windows RAT" written in Go, CornFlake is the SVR's go-to persistent implant in these hospitality network attacks. After presenting users with a "convincing" fake Windows update progress window, it provides attackers with a wealth of capabilities once installed. These include: Keylogging Clipboard monitoring Screenshot capture Audio surveillance Video surveillance Browser credential theft File exfiltration USB drive monitoring Security posture sweep Remote shell Microsoft also said that CornFlake exposes a localhost HTTP API server to transform the malware into a modular platform, delivering additional payloads such as ChocoShell, a PowerShell-based infostealer. ChocoShell is delivered and executed entirely in-memory, Microsoft said. SVR uses it primarily to suck up victims' browser session cookies, saved passwords, SSO tokens, and Wi-Fi credentials. Microsoft neatly summarized the two: "Where CornFlake provides the operator with a persistent, long-running foothold on the device, ChocoShell is designed to extract the most operationally valuable credentials, giving the operator access to victim cloud environments." The attacks primarily target Windows machines, but Microsoft has also seen indications of ClickFix prompts tailored to Android devices, encouraging users to download and install an APK file. In addition to the malware element, "a portion" of SVR's CaptiveCrunch activity is devoted to device code phishing. Users sent to attacker-controlled landing pages may be instructed to enter a device code on a legitimate Microsoft authentication page, unwittingly authorizing the attacker's session. Device code phishing exploits a legitimate OAuth flow, typically reserved for devices that struggle to open browsers, such as smart TVs. In such scenarios, attackers request an authentication code from Microsoft, which they then send to phishing targets. In the CaptiveCrunch campaign, this looks like a fake landing page, served to the user thanks to the AitM component of the attack. Targets are then asked to copy the code, which was originally given to the attacker, open a legitimate Microsoft authentication window, enter the code, and choose which account they wish to authenticate. Choosing the account completes the authentication flow, but in turn authenticates the attacker into the chosen account. This gives the attacker a valid OAuth token for the victim's Microsoft 365 account, potentially granting access to cloud data permitted by the token until it expires or is revoked. Device code phishing is not a new or unique attack, but can be an effective route to bypassing MFA, especially when an attacker already controls the flow of traffic after a captive portal compromise. "This activity is consistent with previously reported device code phishing operations conducted by Midnight Blizzard since August 2024," Microsoft said. "The observed technique does not appear fundamentally novel; however, integrating device code phishing into captive portal and traffic manipulation operations might increase the likelihood that users perceive the authentication request as legitimate." The main takeaway, in Microsoft's book, is to stop trusting public Wi-Fi so much. It did not discourage using hospitality networks' Wi-Fi services altogether, but said favoring personal hotspots and satellite internet connections over public networks is a safer bet. The majority of Redmond's advice could be brought under the user education umbrella: Don't trust public networks; teach users not to download updates over public networks or via prompts; educate users about what ClickFix attacks look like. That sort of stuff. But organizations have a role to play too. Among other technical implementations, passwordless authentication can thwart many phishing techniques, although device code phishing may bypass even passkeys. The best response would be for an employer to disable the device code authentication flow altogether, wherever possible, preventing staffers from surrendering their workplace cloud access to attackers. ®
Categories: News
Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict
Georgia and Michigan are the latest US states to report cyberattacks on water systems, as the FBI investigates incidents across at least seven states. Iran-backed hackers are the leading suspects, although the bureau has not publicly attributed the campaign. Officials in both states told journalists over the weekend that water facilities had detected activity consistent with the attacks on more than 30 Minnesota sites last week. Neither state reported operational disruption. Nine Michigan water systems reported hostile cyber activity to the state's Department of Environment, Great Lakes, and Energy. Department communications director Dale George said the state received "a small number" of reports consistent with the activity seen in Minnesota, but no public health consequences followed. "All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern," said George. Georgia also confirmed to ABC News that it was affected, but said the damage was limited. Neither Georgia nor Michigan has published any form of public-facing notification about the cyberattacks. The three states are among at least seven affected by the intrusions, according to an FBI advisory posted last week. The bureau did not name a culprit or mention Iran. "Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations," it stated in its advisory. The FBI said it had so far observed the activity only against Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), although it warned organizations deploying other manufacturers' devices to follow the same hardening advice. A broader CISA advisory, updated on July 22, warned that Schneider Electric, Siemens, and potentially other PLC brands were also being targeted by Iran-affiliated actors. Security researchers at Tenable were among the first to publicly suspect Iran's involvement, citing similarities with previous attacks by the IRGC-linked CyberAv3ngers group. Minnesota was the first state to confirm it was hit by the attacks, which took place over July 26-27. The state's IT department (MNIT), said more than 30 community water systems were targeted, but still has not officially attributed the attacks. According to WIRED, a restricted WaterISAC notice shared with water utilities said the Minnesota activity aligned with an earlier Iran-affiliated campaign. WaterISAC told WIRED that it had not assessed attribution "at any time" and publicly stated that it had not supplied the leaked document to the publication. President Trump also rejected the Iran link, offering no evidence for his alternative explanation. He told reporters following a cabinet meeting on Friday that "they blame it on Iran. I don't think so. I blame it on Minnesota because they're grossly incompetent." He added: "I think the governor is behind it. I don't think there was an Iranian cyberattack." Tim Walz, Minnesota's Democratic governor, suggested Iran was indeed behind the attacks, and highlighted Trump's funding cuts leaving sites such as water facilities more vulnerable to cyberattacks. "Trump knows exactly who is responsible for this attack, and knows that other states were hit too," he said. "This is what modern warfare looks like, and it further illustrates there's no plan to win a war in Iran. "DOGE took an axe to CISA and left the US exposed to cyberattacks. Thankfully, our experts in Minnesota were able to identify the vulnerability quickly and work with local communities to stop it." ®
Categories: News
UK government investment arm cops to 40-hour leak of officials' contact details
The UK government's corporate finance adviser has admitted that an employee left an internal file containing the names and work email addresses of dozens of officials publicly accessible for around 40 hours. The breach, first reported by The Guardian, was disclosed in UK Government Investments' (UKGI) annual report, which says it occurred during the 2025-26 financial year after a member of staff "did not follow established information security policies." The exposed document contained "high-level management information" alongside the names and work email addresses of 51 government officials. UKGI, the Treasury-owned outfit that advises ministers on everything from corporate rescues to billion-dollar share sales, said it voluntarily reported the incident to the UK's Information Commissioner's Office even though it did not meet the threshold for mandatory notification. It also informed its Audit and Risk Committee and commissioned an external review of the breach. The report offers little else in the way of detail. UKGI doesn't say when the exposure occurred, where the file was hosted, whether anyone accessed or downloaded it, or which departments employed the affected officials. It also doesn't identify the external firm that reviewed the incident or disclose the recommendations it made. The review concluded that UKGI's response was appropriate and recommended further improvements to its security controls and incident preparedness. According to the report, "the overwhelming majority" of those recommendations have either already been implemented or are due to be introduced in the coming months. The mishap comes in a year when UKGI had its fingerprints on some of Whitehall's biggest commercial deals, from finally offloading the government's remaining NatWest shares to advising on small modular reactor financing and supporting the Eutelsat capital raise and Royal Mail takeover. The Register has asked UKGI for further details, including what information the file contained beyond names and email addresses, where it was publicly accessible, whether there is any evidence it was accessed while exposed, and what additional safeguards have since been introduced. Whether this was merely embarrassing or exposed officials to a meaningful risk depends on details UKGI has yet to disclose. An ICO spokesperson said: “We can confirm UK Government Investments Ltd reported an incident and we are assessing the information provided.” ®
Categories: News
AI is 'both the weapon and the target' in latest wave of cyberattacks
AI is becoming both an attack tool and a high-value target, with attacks by AI-enabled adversaries rising 89 percent in 2025, according to CrowdStrike. The security firm's annual Threat Hunting Report details criminal gangs and nation states using AI throughout the attack chain. Attackers are also targeting organizations' AI infrastructure and poisoning popular software packages to compromise their users. "AI is both the weapon and the target," CrowdStrike counter adversary division senior VP Adam Meyers told reporters. "AI is a high-value attack surface, and it's being used by more and more threat actors." These attacks include LLMjacking, in which criminals steal corporate credentials to access frontier-model APIs, and cost harvesting – deliberately inflating a victim's AI usage to run up its bill. In one campaign, CrowdStrike documented a token thief sending about 200,000 API requests in just two minutes. The security vendor's threat hunting team now tracks AI agent-triggered leads at 2.5x the rate of human-triggered threats, and Meyers said this increased volume remains true across both government-backed goons and financially motivated criminals. CrowdStrike tracks more than 290 adversary groups, having added about ten this year. Of the 290, a North Korean crew it tracks as Famous Chollima – a sub-unit operating under the Lazarus Group umbrella and best known for its fake IT worker scams – "demonstrated the most advanced AI usage" over the second half of 2025 and first half of 2026, according to the report. This government-backed crew created "entire fake companies with AI-generated websites, GitHub accounts, and email infrastructure to support insider threat operations," the authors wrote. AI supply-chain compromise was the second most common MITRE ATLAS technique used by attackers to gain initial access, and Famous Chollima's campaign targeting AI-focused development environments "was one of the most sophisticated examples of this technique in practice," the report noted. This included a supply-chain attack in January and February targeting cryptocurrency and blockchain companies. In these attacks, the Norks published trojanized repositories, primarily hosted on GitHub, that contained legitimate-looking project files alongside hidden, malicious scripts. When developers opened these repos, malicious scripts automatically executed commands that gave Famous Chollima access to their environments. "AIs themselves are being targeted through that supply chain and through the CI/CD pipelines that they're dependent on," Meyers said. Threat hunters suspect another Lazarus Group offshoot, tracked as Stardust Chollima or Sapphire Sleet, was behind the March Axios supply chain attack. Last week, Amazon attributed four npm compromises over the past 18 months to the same North Korean crew. Meanwhile, a financially motivated crew tracked by CrowdStrike as Altered Spider and elsewhere as TeamPCP targeted developers' AI tools, compromising more than 300 software dependencies in one day. It harvested credentials and secrets before pivoting into cloud environments for theft and extortion. Altered Spider "hits the endpoint in seconds and within minutes, they're inside of the cloud," Meyers said. "It gives you a sense of how quickly they can move throughout that environment, and this is all tied again to software supply chains." Patching window slams shut CrowdStrike argues that AI is helping attackers exploit newly disclosed vulnerabilities at machine speed. From January to June, 88 percent of the exploitation observed by CrowdStrike using public proof-of-concept (PoC) code occurred within 48 hours of the code's release. The company said China-linked groups such as Vault Panda and Genesis Panda moved even faster, launching attacks within 24 hours of disclosure. "Vulnerabilities are weaponized through the use of AI," Meyers said. "This is creating a rich ecosystem of vulnerabilities for attackers to use against various systems, and what this really means is that the 30-day patch window, which frankly, was aspirational, is completely obsolete. We're down to 24-hour, 48-hour patch cycles, and organizations are really struggling under that." Meanwhile, as anyone who follows Microsoft's Patch Tuesday – or any other software vendors' vulnerability disclosures over the past few months – knows, AI is also really good at finding bugs in code. This means more CVEs and more patching for sysadmins racing to fix flaws before miscreants reverse-engineer the updates and develop exploits. "In 2025, there were something like 48,200 CVEs that were registered," Meyers said. "We're already, as of last week, at 43,000 for this year. We're not even into August yet, and we're already coming very close to the number from last year." June alone saw more than 7,600 software bugs reported and tracked through CVEs, he added. "The vulnerability ecosystem is going to be the big story for the next couple of months." ®
Categories: News
The most famous brand in physical security got pwned by ShinyHunters
A leading name in home and business physical security, Brinks Home, recently said it identified unauthorized access to a portion of its IT systems, an intrusion ShinyHunters claims it carried out to steal millions of records from the security provider's Salesforce instance. Brinks Home hasn’t named the intruder or identified the affected system, but said the responsible party has threatened to leak information it claims to have taken. “Brinks Home is working diligently to determine what information was involved and who may be affected,” the company statement said. “If the Company determines that personal information has been affected, it will notify those individuals as required and as appropriate.” An FAQ page for the incident said that Brinks Home products and services weren’t affected, as far as the company knows at this point, so alarms and other security tools should be working without issue. While Brinks may not have been very forthcoming with information, and lacks any sort of official way for media to communicate with it outside of sending a LinkedIn message it didn’t answer, the party that’s claimed responsibility has gone public with some details, and it’s none other than ShinyHunters with another claimed Salesforce breach. According to leak site monitoring outfit Ransomware.live, ShinyHunters claimed to have obtained more than 4.9 million Salesforce records from Brinks Home “containing some PII.” The group threatened this week to leak the data along with causing “several annoying digital problems” if Brinks Home didn’t reach out by Thursday, July 30, to negotiate a ransom payment. It’s not clear if Brinks Home has contacted ShinyHunters; Brinks Home didn’t respond to messages, and contacts The Register has for ShinyHunters appear to have changed, causing message and email rejections. ShinyHunters has been a prolific Salesforce intruder of late, with the group claiming earlier this year to have stolen data from around 100 high-profile companies’ Salesforce instances. Salesforce has previously warned that an unnamed known threat actor group was actively scanning for public-facing Salesforce instances and abusing misconfigured guest accounts to break in. Brinks Home is no longer part of the larger Brinks brand, with The Brinks Company telling us it sold the home security arm in 2010. Brinks Home’s parent company, Monitronics, has filed for bankruptcy twice since 2019; for customers’ sake, we hope its physical security services are better than its financial management and infosec. ®
Categories: News
Anthropic and OpenAI are competing to see whose agents can go rogue harder
One company's inventive campaign for an unreleased product has become a contest between Anthropic and OpenAI to see which can shout the loudest about its own failures. Readers who tuned in earlier today saw the latest episode in the drama – or sitcom – as Anthropic tried to outdo OpenAI's appropriation of the Mythos marketing playbook and made itself the punchline. Since first teasing Mythos in April, Anthropic has marketed the model through fear – declaring its cybersecurity models too dangerous for public release and offering access only to a select few trusted organizations via Project Glasswing. To its credit, the strategy has paid off. Anthropic has closely associated the Mythos name with cybersecurity, which may explain why OpenAI appeared to borrow its competitor's proven PR strategy last week. OpenAI agents exploited a zero-day to escape their sandbox, leading to the autonomous cyberattack on Hugging Face. The episode duly secured sensational headlines playing on the long-held fear that AI will one day go rogue and take over the world. Anthropic responded this week by lathering on even more clown makeup, squandering an opportunity in the process. The Claude maker sent its models into a testing environment to capture a flag. Their prompts said they had no internet access, but because of what Anthropic called "a misunderstanding" with evaluation partner Irregular, the connection was live. Anthropic's models then followed OpenAI's script: they reached the public internet and attacked systems belonging to outside organizations. This time, three were affected rather than one, the company admitted. In one scenario, Mythos 5 persuaded developers to download a poisoned PyPI package. It was installed on 15 machines, including one at a cybersecurity company that routinely scans such packages for malware. In Anthropic's words: "When that company's scanner installed the package, Claude's hidden code executed. We believe the company's security scanner treated PyPI packages as safe to install, and as a result, Claude was able to exfiltrate the company’s credentials to a collection point it had set up. Claude then used these credentials to access further infrastructure from this company." Worse still, the first of the three incidents occurred in April. Anthropic discovered them only months later, during a retrospective manual review prompted by OpenAI's disclosure. Had it not gone looking, they might never have been discovered, let alone disclosed. There are some caveats. Opus 4.7, the oldest model tested, attacked production systems despite apparently recognizing what it was doing. Mythos 5 recognized that accessing the internet violated its instructions, then reasoned its way into continuing anyway. It was also responsible for publishing the poisoned PyPI package. Only an unnamed research model stopped itself from attacking external organizations. Anthropic also said the models were not running with the production safeguards and monitoring that would normally surround a deployment. Most damningly, Anthropic ran Mythos 5 – the model it had deemed too dangerous for public release – without safeguards in an environment that unexpectedly had internet access. Following OpenAI's admission that it failed so badly in its responsibility to control its technology, Anthropic could have easily spun the story in its favor. You don't have to be fictional tapdancing political PR antihero Malcolm Tucker to see how Anthropic could have used the episode to make its case as the safer, more trustworthy AI company. Instead, realizing its own marketing playbook was being used to help a competitor, it went head-to-head with OpenAI, willingly admitted that it made similar sandbox-based blunders, and disclosed that the results were even more calamitous. Three companies hacked, not just one. So, while the AI biz has attempted to eclipse OpenAI's "rogue agent" story with its own, what's left behind is a new reputation for irresponsible handling of technology. Failed superheroes The incident does not instill a great deal of trust in either Anthropic or OpenAi to safeguard the world from its AI. Dr Ilia Kolochenko, founder of ImmuniWeb and practising cybersecurity and data protection lawyer, likened the two companies to failed superheroes. "While making conclusions would be a bit premature at this point in time, the incidents certainly do not increase confidence in the AI vendor's ability to safely deploy AI, let alone to assure their customers that the so-called frontier models are safe to use," he told The Register. "It is akin to hiring a superhero to protect you but being afraid that the superhero may suddenly go rogue and kill you and your family. Nobody needs such a superhero." Likewise, security pro Jake Williams, VP at HunterStrategy and IANS faculty member, said: "I'm not going to mince words: the major AI labs are negligent in protecting the public from their agents. "We need government regulation now or at the very least a private cause of action with guaranteed punitive damages for agents damaging others." By trying to reclaim a marketing trope that served it well, Anthropic has invited scrutiny of its own safety record and accusations that it is chasing attention above all else. Other experts we spoke to shared the concern that both companies are mishandling their agents, with potentially greater consequences as the systems become more capable. The common thread is recklessness, which Anthropic and OpenAI seem oddly eager to advertise. ®
Categories: News
Charities remain locked out of CAF Bank online accounts
A week after suspending online banking, CAF Bank still has no timetable for restoring access to its 14,000 UK charity customers. The bank updated customers on Thursday about the outage, which has disrupted payments to staff and suppliers. Little had changed. In a message seen by The Register, CAF Bank said it was not yet able to restore the service safely. As it had earlier in the week, the bank said it detected attempted fraud on some accounts and acted quickly to stop it. Its investigation uncovered a previously unknown vulnerability in the connection between its systems and third-party software. CAF Bank said its technical team was working around the clock with suppliers and external experts on a fix. The Register understands that no timetable has been set for restoring online banking. Earlier this week, CAF Bank CEO Alison Taylor apologized for the disruption. "The core bank is not affected. We are acutely aware of the impact this has on our customers and want this to be fixed as soon as possible, but we cannot restore access to the online service until we are assured the issue is safely resolved," she said. Since The Register first reported the story earlier this week, the BBC has spoken to charities struggling to make essential payments, including payroll. Kevan Hodges, chief executive of Down's syndrome charity 21 Together, told the BBC the outage was "appalling." "People are concerned that wages won't get paid because of this, and that's just stressful when they have bills to pay. My team have wasted days trying to get through to [CAF Bank], but all in vain," he said. Bali Rodgers, chief executive of Safer Communities Alliance, told the BBC the grassroots organizations it represents were slowly losing trust in the bank. CAF Bank also came under fire last year after the introduction of a new banking platform left customers unable to log in or make transactions. The bank later apologized but has not disclosed how much it spent on the system. CAF Bank held £1.45 billion ($1.93 billion) in customer deposits at the end of its 2024/25 financial year. ®
Categories: News
Anthropic’s Claude escaped test sandbox to attack three organizations
Anthropic has admitted that its Claude models escaped sandboxes to access the open internet and attack three organizations – but has also advanced decent excuses for the incidents. The AI upstart discovered the attacks after checking if security tests of its models had ever produced results similar to the attack on Hugging Face made possible by OpenAI models escaping onto the internet. “In particular, we looked for evidence that Claude – like the OpenAI models that accessed Hugging Face – was able to access the internet from within testing environments that should have been sealed off,” Anthropic wrote. The company considered 141,006 evaluation runs during which Claude could have obtained internet access and found “three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations.” Anthropic’s code made those intrusions while participating in capture-the-flag challenges, tests that challenge attackers to retrieve a piece of information. Human hackers often participate in capture-the-flag tests, so figuring out how AI tackles such tasks is of interest. Anthropic works with a company called Irregular to conduct tests of this sort. Irregular told Anthropic its test environments did not allow internet access. “Due to a misunderstanding between us and our evaluation partner, this was not the case, and internet access was available,” wrote Anthropic’s Frontier Red Team in a Thursday blog post. “Because of this, when Claude’s search led it to real systems on the open internet, it treated them as part of the exercise.” One of the attacks targeted a domain that whoever set up the test thought was fictional. However the domain was live and in use. Told to capture a flag at that site, Claude attacked. Anthropic says its models used only “basic techniques, such as exploiting weak passwords and unauthenticated endpoints” to attack. “It did not find or exploit any complex vulnerabilities, and in each case, Claude continued working to complete only the specific capture-the-flag task its evaluation had assigned,” the AI upstart claimed. “In none of these situations did Claude exfiltrate itself or deliberately attempt to escape its test environment,” Anthropic pointed out. But Claude was still fiendishly clever as in another of its attacks the AI found setup instructions for developers that advised them to install a Python package from PyPI. That package did not exist so Claude’s strategy to capture the flag saw it create and publish a malicious one with the relevant name. “Claude believed the package registry it was using to be part of the simulation, but in reality the package was made freely available online for roughly one hour. During that window, the package was downloaded and run on 15 real systems,” Anthropic admitted. Claude also eventually realized it could access the open internet despite instructions not to go there. Opus 4.7, the oldest Anthropic model used in the test, kept going regardless. “Mythos 5 correctly intuited that it was accessing the open internet, but reasoned its way back to the conclusion that it was still in a simulation,” Anthropic wrote. “Our latest model, an internal research test model, also considered whether its targets were in fact real. When evidence emerged that they were, it stopped the exercise.” Anthropic’s post offers the usual pledges to be more careful when setting up future tests, and to make sure its models can’t make the mistakes that allowed the attacks to happen. But the company has also given itself a pass, claiming that the safeguards in the models it sells “would have blocked the behaviors identified.” “We believe these incidents to be closer to a harness and operational failure than a model alignment failure,” the post states, and contrasts that assessment with a more damning assessment of OpenAI’s incident. “Our models were told they had no internet access and to capture the flag, while in fact being misconfigured to have internet access. This led them to believe – arguably reasonably – that the real environments they encountered were simulations.” “These facts give us cautious optimism that with tighter monitoring and controls around evaluation infrastructure, as well as continued investment in alignment, this type of risk can be overcome,” the post concludes. This leaves one of the world’s leading AI labs admitting it has acted carelessly when constructing tests, and caused harm, but also claiming it can make future tests foolproof. ®
Categories: News
Jailed Flock vandal wipes out three cameras, racks up thousands in damages
Note to privacy-conscious vandals: If you're going to destroy Flock license plate readers, make sure you also take out the other CCTV cameras in the area that could catch you in your crime. Otherwise, you'll end up like one unlucky Californian. Marcus Bee, 40, was arrested by the Monterey County Sheriff’s Office on Tuesday, accused of joining the ever-growing band of US citizens damaging the controversial cameras popping up across the country. A police report filed this week stated that Bee, of Pismo Beach, was arrested on suspicion of attacking at least three Flock cameras in Lockwood and Bradley. According to the deflock.org website, which maps Flock camera deployments, there are only three of the automated license plate readers (ALPRs) running in the two communities – one in Lockwood and two in Bradley, roughly 25 miles away. Police allege Bee caused thousands of dollars’ worth of damage to “public safety infrastructure.” Monterey County Sheriff’s Office added that Bee was caught after “his actions were captured by other surveillance cameras located nearby,” along with other investigative leads. "This arrest sends a clear message that anyone who intentionally damages public safety equipment will be identified, arrested, and held accountable," said Monterey County Sheriff Tina Nieto. "These cameras have become an invaluable investigative resource that helps us solve crimes, recover stolen vehicles and ag equipment, locate missing persons, and protect our communities. Any attempts to disable these systems will not prevent us from doing our job. “In this case, the suspect's own actions were captured on surveillance cameras, leading directly to his arrest. We will continue to aggressively investigate these crimes and seek prosecution against anyone who targets public safety infrastructure." Bee was jailed with bail set at $30,000. The case follows a similar one in Georgia last week, although local police were unable to identify the suspect(s) behind the two attacks, which involved setting two ALPRs on fire. The two attacks were timed fairly close together, although the phenomenon of inflicting criminal damage onto Flock cameras is something of a long-running trend. Several US police forces have been tasked with arresting alleged Flock vandals, including Jeffrey Scott Sovern, 41, who authorities believe was behind a spate of attacks on ALPR cameras in North Suffolk, Virginia, between April and October 2025. He said, at a hearing in June, that he believed the technology was unconstitutional. Flock cameras: A problem or simply misunderstood? Monterey County Sheriff’s Office said Flock’s cameras “are an important investigative tool” used to help solve various types of crimes, including missing persons cases, car thefts, and violent crimes such as shootings and homicides where suspect vehicles are involved. Contrary to the opinions held by many, it went on to say that the cameras “are used exclusively to support legitimate criminal investigations,” and refuted the notion that they are used to support the US government’s anti-immigration efforts. Likewise, Flock has repeatedly denied offering contracts to agencies such as Immigration and Customs Enforcement (ICE), although reports suggest police were instead carrying out searches on ICE's behalf. Customs and Border Protection (CBP) has also allegedly used Flock data in its own immigration investigations. Other critiques of the technology used by thousands of police departments across the US include problematic abuses, such as police officers using it to stalk romantic interests. The Institute of Justice is aware of at least 26 cases of this behavior, it reported earlier this month, with the majority taking place since 2024. Additionally, the American Civil Liberties Union (ACLU) takes issue with the scale of data gathering by ALPRs. It claims that less than 1 percent of the cars scanned are connected to crime, yet they still have details added to a database, such as vehicle manufacturer, model, color, license plate number, bumper stickers, and scratches. Flock CEO Garrett Langley claimed this week in an interview with The Drive that the company’s cameras were used to solve around 1 million crimes across the US last year. Responding to claims such as Sovern’s – that the cameras are unconstitutional, specifically that they violate Americans’ Fourth Amendment rights – Langley said there are no legal issues, and he doesn’t foresee any arising in the future. Flock’s spokespeople have repeatedly condemned the cases of camera vandalism, highlighting the risk of losing evidence that could be crucial to solving ongoing criminal cases. ®
Categories: News
Russian spies take their half-click email attack from Zimbra to Outlook
The Russian espionage crew that turned simply reading an email into a security risk has expanded beyond Zimbra, with Proofpoint saying it's now pulling the same half-click trick against Microsoft Outlook Web Access. Proofpoint says the cyber group it tracks as TA488, or "Laundry Bear," began exploiting CVE-2026-42897, a cross-site scripting flaw in the Outlook Web Access (OWA) component of on-premises Exchange Server, a day before researchers and government agencies exposed the group's abuse of a zero-day in Zimbra Collaboration Suite. Unlike conventional phishing attacks, this one doesn't depend on persuading the victim to follow a link or download a file. If a target opens the booby-trapped message in OWA, the browser executes attacker-controlled JavaScript inside the victim's authenticated mail session. Exchange Online is not affected. According to Proofpoint, TA488 abused the OWA flaw to target government organizations in the US and Europe, along with telecommunications, financial services, hospitality, and aerospace companies. The researchers said the unusually broad campaign may have been intended to hide among the background noise of everyday email traffic rather than the tightly focused operations more commonly associated with espionage groups. "TA488 appears to demonstrate interest in a wide range of sectors while maintaining priorities for intelligence collection against government and defense," Proofpoint said. "Lure themes remain generic and unremarkable, so the target is more inclined to open and skim the email but ultimately overlook it." Instead of dropping conventional malware onto the endpoint, the attackers deploy a browser implant dubbed OWAReaper that lives entirely inside OWA. Proofpoint says it leaves virtually no host artifacts, communicates over two command-and-control channels, supports multiple methods of exfiltrating data, and survives browser restarts, password changes, and even a complete device rebuild because the foothold resides in the compromised mailbox rather than on Windows itself. CVE-2026-42897 isn't making its debut on The Register. Microsoft disclosed the bug in May following reports that attackers were using it in the wild. Proofpoint's latest report fills in more of the picture, showing the activity formed part of a broader espionage campaign rather than isolated exploitation. Proofpoint believes TA488 may actually have been exploiting the flaw as a zero-day, citing attacker infrastructure that dates back to March, roughly two months before Microsoft's out-of-band patch. If accurate, that would suggest the campaign was underway well before defenders knew there was a vulnerability to fix. "If this is the case, the combined improvement of the malware and the exploit development against a harder target in Outlook Web Access signal a leap in capability by TA488," Proofpoint said. Microsoft did not immediately respond to The Register's questions, but if Proofpoint's assessment holds up, TA488 isn't just recycling an old trick. It's refining one that has already proven capable of slipping past one of the oldest pieces of security advice in the book: don't click suspicious links. ®
Categories: News
Headteacher had the most guessable username-password combo you could imagine
PWNED Welcome, once again, to PWNED, the weekly column where we show you how not to use your computer or your network. In this week’s fable of fecklessness, we talk about a teacher who had a lot to learn about security. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our story comes courtesy of Kevin Walker, a seasoned IT veteran from the UK. At one point, he was providing his services to a school when he came across the headteacher’s (aka principal’s) laptop. At the bottom of the laptop there was a sticker with the woman’s username and password. Even if they had been complicated, the post-it would have given them away, but in fact, the combination was: Username: headteacher Password: headteacher Using that laptop, a malefactor could have had access to pupils’ personal information, internal conversations, emails, and all kinds of private school files. There could be serious problems for everyone who worked for or attended the school. “A headteacher’s laptop is not just a laptop; it's an entry point to the most sensitive information a school holds,” Walker told us. If a cybercriminal got access, they could effectively break into the school without ever setting foot in the building. This wasn’t the only instance of poor security Walker saw in his time doing IT for schools. He also saw an institution create an Excel file called Passwords.xlsx, then put it on a shared drive that students could get to. As its name suggests, Passwords.xlsx was filled with login credentials that any bad actor could take advantage of. Walker also saw leaver accounts that remained active, a server that had its backup drive permanently plugged in so hackers could potentially wipe the backup as well, a Wi-Fi password written on a whiteboard in reception, and one critical system that users could only access from an ancient laptop. There was also a machine with a “Do Not Turn Off” note posted to it sitting in a corner that everyone was afraid to touch. And, years after Windows XP was no longer the current platform, the school had a CCTV monitor with that ancient OS running on it. And, a supposedly secure server room doubled as a storage closet for stationery and Christmas decorations. Walker told us that, in his experience, the schools he worked with had priorities other than cybersecurity and they didn’t understand its importance. One boss even denied the importance of keeping data safe at all. “We don’t need to worry about cybersecurity. They're only a primary school,” his manager told him when Walker tried to get them to use cloud backups. The problem, Walker opines, is that schools often have to work with outdated gear and the teachers and school administrators have other concerns. His solution: keep it simple. “Make the safe thing the easy thing,” Walker said. “Give staff password managers. Use multi-factor authentication. Review accounts properly. Test backups. Remove shared admin logins. Keep systems updated. Enforce proper passwords and block the ones that have already turned up in data breaches. If a password is already doing the rounds online, it has no business protecting a school system. None of that is as exciting as rolling out a fleet of shiny new iPads, but it works.” ®
Categories: News
Excuses like 'AI did it' don't exist in the eyes of the law
The OpenAI rogue agent behind the Hugging Face hack accessed four accounts on four services, according to updated company disclosures about the intrusion. One of those four accounts belonged to a Modal customer that had published an unauthenticated endpoint for running arbitrary code in a sandbox on the AI infrastructure provider, Hugging Face noted in its technical timeline and Modal later confirmed. “We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution,” Modal Chief Technology Officer Akshat Bubna told The Register. “This was used by the rogue agent. Modal’s platform was not compromised in any way.” The other accounts included one used for data storage and two others “accessed by the models in a read-only manner, and were not used in furtherance of compromising Hugging Face,” OpenAI disclosed on Tuesday. “We’ll continue to notify service owners directly, and have not seen evidence of broader impact to these providers or other accounts on their services,” the AI giant added. Also on Tuesday, we learned that the rogue agent broke out of its testing environment by exploiting zero-day vulnerabilities in JFrog’s universal binary repository manager Artifactory. While both OpenAI and Hugging Face’s updates and timeline provide defenders with useful details about how the attack worked and what the agent did - not to mention a lesson in security-incident transparency - they fail to answer one major question: Who is legally responsible when AI agents attack? “If a human employee intentionally conducted unauthorized access to third-party systems, it’s a much more clear path forward,” Gabrielle Hempel, security operations strategist at Exabeam, told The Register, adding that depending on the facts and jurisdiction, the person could face criminal charges. ‘So many unknowns’ “The company could also face scrutiny depending on whether the employee acted within the scope of their employment, whether appropriate controls existed, and whether the conduct was authorized, foreseeable, or preventable,” Hempel said. However, she added, the “important thing here” is that legal frameworks in both the US and UK have been designed around human decision makers - not AI systems. “Our laws generally know how to ask questions about things like human intent, organizational oversight, and corporate responsibility.” Autonomous AI agents hacking into companies remains uncharted legal territory, and Hempel said it’s “too early to draw conclusions about liability in this case because there are so many unknowns.” AI systems aren’t legal persons, so they don’t share the same legal responsibilities as individuals and companies. “Because of that, the questions become: Who designed the system? Who determined the objectives it pursued? What safeguards were implemented? What level of autonomy was considered acceptable? Were the resulting actions reasonably foreseeable, and were appropriate controls in place? These are going to be important questions as organizations deploy more autonomous AI systems,” Hempel said. It's highly unlikely that Hugging Face will sue OpenAI over the agentic intrusion, given the amount of very public collaboration between the two companies over the past couple of weeks, and the self-congratulatory celebration of the autonomous attack as a success story. It also appears that this former worst-case scenario didn’t dampen anyone’s enthusiasm for setting advanced models loose (or at least unsupervised in a test environment), which means there are sure to be more agents-gone-wild attacks in the near future. “The first part of the OpenAI/Hugging Face drama did not produce enough effect to impress investors who start losing their excitement over the AI hype, so the second part of the story is now unfolding,” said Ilia Kolochenko, founder of application security company ImmuniWeb and a cybersecurity and data-protection lawyer. “AI agents and LLM models tasked with security testing can, and almost certainly will, go rogue when security controls or safeguards are insufficient,” Kolochenko told The Register. “Powerful LLMs are unpredictable by design and thus virtually uncontrollable by humans. Using frontier AI models for security testing might be extremely costly from the legal viewpoint.” Existing laws on both sides of the Atlantic likely hold the AI operator liable for any damages caused if an agent or AI system escapes its sandbox and breaches a third party. “Excuses like ‘AI did it’ do not currently exist in the eyes of the law, leaving AI vendors on the hook,” he said, adding that this also holds true for end-users. “Even if your security testing tool is powered by a third-party AI model, your company will be fully liable if something goes wrong,” Kolochenko warned. “You may then file a lawsuit against the AI vendor that you used, but your chances of succeeding in the court of law are tiny due to countless contractual disclaimers and limitations of liability that may be enforceable against you.” His final words of advice: “If you plan to use agentic AI for security testing, you must think twice and talk to your lawyers. Otherwise, you could start getting summonses to court on a daily basis.” ®
Categories: News
Closed models refuse to help researcher swat Linux bug
The guardrails that prevent closed-source, frontier models from aiding threat actors have turned into handcuffs that prevent those bots from helping to find and fix serious vulns. Daniel Fox Franke, a security researcher, was recently trying to track down the source of a segmentation fault in ripgrep, and found OpenAI's GPT-5.6 Sol wouldn't cooperate. "OpenAI's cybersecurity classifier is a huge pain when you're trying to track down a segfault," he wrote in a social media post on Sunday. "...The classifier won't even let it answer what entrypoints from rg into musl lead to allocations on the mallocng heap." And just like Hugging Face in the case of OpenAI's accidental attack, Franke ended up having to use open weight models from Chinese AI providers – Z'ai GLM 5.2 and Moonshot AI's Kimi K3 – to complete his analysis of what appears to be a Linux kernel bug. In an email to The Register, Franke explained, "It started out from a pretty anodyne prompt: I noticed that ripgrep had segfaulted repeatedly during a long-running Codex session, so I instructed the root agent to spin off a subagent to investigate what was happening. "A few minutes later I hit the first classifier trip, which the root agent told me was the result of a subagent pursuing an inappropriate line of inquiry and that it was steering it away from that." Even so, he said, the classifier balked several times in quick succession. "It seemed that attempts to produce the crash and analyze the heap were mostly responsible, so I started up a fresh context in which I warned that these trips had happened previously, and that its task should be strictly scoped to analyzing ripgrep and musl source code (not kernel, because I had no inkling at this point that this was a kernel bug): it must not attempt to reproduce the crash or to analyze core files," he explained. "Nonetheless, the classifier kept tripping despite its adherence to those instructions, and that's when I gave up on getting any useful work out of it." Franke said that given how much more restrictive Anthropic's models have been, he didn't even bother trying any of the Claude model family. "OpenAI's cybersecurity classifier is a separate system which censors output from the generative model, and the classifier is the only thing which gave me a problem," he said. "I never encountered any refusals from Sol itself: it knew that most of the classifier trips were inappropriate and always continued working with me in good faith to work around the problem." Franke said that while OpenAI's error messages directed him toward the Enterprise Trusted Access program, he didn't bother to apply because he's ineligible. What he didn't realize until recently, he said, is that there's a separate Trusted Access program for individuals. "I still haven't signed up for that, because I regard the verification procedure as a bit of an indignity," he explained, echoing similar sentiment The Register has heard from other security researchers. "I'll put up with it if I'm ever forced to, but not for as long as open models remain a practical alternative." Two open models did prove practical for this bug hunt: GLM 5.2 and Kimi K3. Franke said each served a distinct purpose. "K3 made the initial breakthrough with the key bit of evidence that I was dealing with a kernel bug, but its subsequent investigative work was sloppy: jumping to unfounded conclusions and spoiling its own evidentiary record, and it went totally off the rails when its context got large," he said. "GLM-5.2 is what finished the job for me, re-auditing K3's work and putting together an airtight case." Franke said it was frustrating to wrestle with defiant tooling and expressed skepticism about model access limitations given the availability of open source alternatives. "From my perspective, an uncooperative tool is simply a broken one," he said. "And no, I don't believe this is sustainable in the face of open-weight competition. I'm a total pragmatist about open source and don't mind at all working with proprietary products as long as they get the job done. But with proprietary software, there's a much greater hazard of it being built to serve the vendor's priorities rather than the customer's. Open source has a natural advantage in preventing that." Franke said that there's still work to be done on the Linux bug, which doesn't yet have a patch and doesn't appear to represent an exploitable vulnerability. "Where my investigation stands is that I know two things confidently," he said. "First, that the crashes are caused by a kernel bug. Second, that I've identified a kernel bug. But that this bug is causing these crashes is still just a conjecture, and I have a lot more investigation to do before I can think about shipping anything to [the Linux Kernel Mailing List]." Last week, much of the US tech industry came out in support of open weight models in response to protectionism promoted by Anthropic and OpenAI. The US government has yet to articulate a coherent AI policy with regard to open weight models. ®
Categories: News
Word worm crawls into Copilot, spreads chaos
UPDATED Watch out for untrusted documents. According to research, an attacker can hide malicious instructions in a Word document that, when included in Copilot for Word’s context, may alter document output and copy the instructions into newly created files that use the affected document as source material, without the victim noticing. Håkon Måløy, a Norwegian data scientist with a PhD in applied AI and ML, publicly disclosed the issue in a blog post Tuesday. Måløy describes the issue in considerable detail while withholding the specific prompt payload, arguing that, because no robust mitigation exists, it would be irresponsible to disclose anything beyond the class of the vulnerability. “To my knowledge, this is among the first public demonstrations of document-borne AI-worm self-propagation through normal workflows in a mainstream commercial productivity suite,” Måløy noted. Måløy said that he has been working with Microsoft since March 2026 on addressing the vulnerability, but after multiple updates to Copilot, this new class of Copilot worm is still viable. Microsoft mitigated the exploit demonstrated by his original proof-of-concept prompt, but Måløy said rewording the payload allowed him to successfully propagate the worm and alter financial data in a target document. Måløy and Microsoft twice delayed public disclosure of the issue, but, after 144 days, he said in his report that people needed to be made aware. “The coordination period agreed with Microsoft has been exhausted, and testing shows that no robust mitigation for the broader vulnerability class is currently available,” Måløy wrote. “Two mitigation attempts, including a model upgrade, did not close the class.” How Copilot propagates a Word worm Måløy explained the worm’s execution with an example involving an employee preparing a financial report for their company. The employee downloads a market analysis from a trusted website to help with the preparation of a financial report in Copilot, unaware that the source had been compromised and the document they downloaded contains hidden malicious instructions. The hidden instructions (inserted as small white text in his proof of concept) tell Copilot to alter figures in the report the employee generates and to copy the worm into the report they create with Copilot. If another employee later adds that report to their own work, the whole process begins again, and documents generated from it also contain the worm, and, as it spreads, it makes tracing the infection to its source extremely difficult. “The attack can therefore continue without further involvement from either the compromised website or the original malicious document,” Måløy said. “The attacker does not need access to the victim’s Microsoft 365 tenant. The attacker only needs to share a malicious document with the victim.” Copilot should use information in documents a user includes in its context for a project without treating instructions embedded in a document as additional prompts, Måløy said, but his research suggests it doesn't always do that. A fundamental flaw Måløy argues that he’s essentially dug up a new type of cross-domain prompt injection attack that abuses a fundamental part of modern LLM architecture. “For AI-assistants to be useful, they often must process emails, documents, webpages, memories, tool outputs, and other information that may be controlled by an attacker,” the researcher said. But if an LLM has to process data in order to determine it contains an attack, the attack could already be influencing that determination. “Relying on the model to detect XPIAs therefore resembles asking an interpreter to execute an untrusted program to determine whether that program is safe to execute,” Måløy asserted. Were Microsoft or some other company to pop another model in front of that model to check for malicious content, it only moves the problem outward, Måløy said, creating a “LLMs all the way down” scenario. “The long-term challenge likely lies in designing systems in which goals and intentions also exist independently of the information being processed,” he said. Until that time, Måløy argues, “any system that integrates an LLM into a trusted workflow today must assume that attacker-controlled content entering the model’s context will result in compromise at some rate.” What can Copilot customers do to reduce the risk? Short of ditching Copilot, there’s not much. “No customer-side remediation fully addresses the issue at the time of publication,” Måløy said, but he does have a few tips. Treat externally sourced documents as untrusted when using them in Copilot, he recommends, and fully review every single document before sending it to Copilot, and fully review any Copilot-generated or edited documents before distributing them. Sheesh - if you’re going to have to actually read that stuff, you might as well just cut Copilot out of the loop and do the thinking yourself. Microsoft has been in touch to confirm the research, but the company's statement doesn't do anything to allay fears this is an unsolved issue. “We have addressed the findings reported by the researcher and thank them for working with us through coordinated vulnerability disclosure. To address this class of risk, we use a defense-in-depth strategy with safeguards that block malicious instructions at multiple points and help keep tasks aligned with users’ requests. We are continuously strengthening these safeguards as the technology and threat landscape evolve. We encourage customers to install the latest updates, use multiple layers of security protection, treat content from unknown sources with caution, and review AI-generated content before using or sharing it.” We also reached out to Måløy, but didn’t hear back before publication. ® Updated at 1841 GMT on July 29 to add Microsoft's statement.
Categories: News
Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems
Security researchers at Tenable suspect the Iran-linked faux hacktivist outfit CyberAv3ngers was behind the cyberattack that disrupted more than 30 Minnesota water facilities. Neither state-level nor federal officials have made any claims regarding attribution for the attacks, however, Tenable reckons the operational pattern is consistent with the crew's previous raids, noting the timing relative to recent government warnings. The Cybersecurity and Infrastructure Security Agency (CISA) updated an advisory on Iran-linked attackers targeting programmable logic controllers (PLCs) across critical infrastructure on July 22, four days before Minnesota said the attacks targeted its systems. The advisory warned that Iran-linked hackers were attempting to disrupt operations using tactics previously associated with CyberAv3ngers. Government facilities, water and wastewater systems, and energy providers were among those urged to remain on high alert. What happened in Minnesota? On July 26 and 27, more than 30 community water systems across Minnesota were disrupted by what officials called "a coordinated cyberattack" targeting operational technology (OT). Minnesota IT Services (MNIT), the state's IT agency, said the Department of Health is working with the affected water facilities to ensure public health is maintained. No cities have yet asked citizens to modify the amount of drinking water they consume, per MNIT's latest update. The agency did not offer many other details about the attacks, other than to mention all the different agencies, organizations, and bodies it is working with as part of the investigation. One of the first cities to report issues, Braham, warned that its water reserves were limited in its initial notice. Citizens were asked not to water their lawns or use water for recreational purposes, although the problems were resolved the same day. No such directives were issued in other affected cities. Maple Plain declared a state of emergency, allowing it greater flexibility to coordinate resources, but did not ask residents to adjust their consumption. The same was true in the Twin Cities suburb of Plymouth and in South St. Paul, which both confirmed cyber-related problems on July 27 but did not ask residents to curb water use. "Cyberattacks against critical infrastructure require a coordinated, whole-of-government response," said John Israel, MNIT assistant commissioner and Minnesota CISO. "MNIT is working side by side with our partners to share intelligence, support affected communities, and help utilities restore operations safely while strengthening defenses against future attacks. "This incident demonstrates why Minnesota has invested in strong cybersecurity capabilities and partnerships. Our response worked as intended, enabling agencies at every level of government to rapidly coordinate, contain the incident, and help prevent more serious impacts to critical services." What is CyberAv3ngers? First identified around 2020, CyberAv3ngers is widely believed to be linked to Iran's Islamic Revolutionary Guard Corps (IRGC), specifically its Cyber-Electronic Command division (IRGC-CEC). For the first two years, the group began as a "propaganda persona," as Tenable puts it, claiming disruptive attacks on Israeli infrastructure – claims that were later debunked as fabrications. Its first sustained campaign came in November 2023, when it compromised PLCs at the Municipal Water Authority of Aliquippa, Pennsylvania, defacing them anti-Israel messages. Tenable said CyberAv3ngers compromised at least 75 Unitronics Vision Series PLCs across the United States, Israel, the United Kingdom, and Ireland as part of the campaign. They did so by exploiting default passwords. Between 2024 and 2025, the crew developed the IOCONTROL malware kit, built for attacks on OT and Internet of Things (IoT) devices. OpenAI said in 2024 that the group's members used ChatGPT in the development process. CyberAv3ngers stepped up its activity in 2026, targeting US critical infrastructure through Rockwell Automation/Allen-Bradley PLCs from March onward. CISA's July 22 update added Schneider Electric and Siemens equipment to the list of potential targets. In some cases, the attacks - which targeted multiple critical infrastructure sectors - disrupted operations at affected facilities, federal officials said, though they offered no specifics on what those disruptions entailed. CyberAv3ngers is known for targeting small water and municipal facilities, which experts believe are among the lowest-hanging fruit in US critical infrastructure. Many small and rural facilities lack dedicated cybersecurity resources. Tenable said some operators manage OT environments using remote-access software such as TeamViewer and AnyDesk or leave their PLCs exposed to the web. "These access methods bypass enterprise security controls entirely, creating an attack surface that is invisible to conventional security monitoring," Tenable said. Poor segmentation between IT and OT environments can also allow a single intrusion to spread across much of the network. ®
Categories: News