❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayArs Technica - All content

An undercover Google analyst infiltrated a notorious supply-chain hacking gang

Before two of its alleged members were arrested and charged in Australia last month, the hacker group known as TeamPCP carried out a hacking spree unlike any other in history. It tainted hundreds of open-source programs with its malware, stole developer accounts to perpetuate that software supply-chain hacking, and even released a Dune-themed self-spreading worm to automate the process, ultimately breaching more than a thousand companies.

Now Google’s threat intelligence group has revealed that during a key moment of TeamPCP’s rampage, the company’s own undercover researcher had infiltrated the group—allowing Google to monitor the hacking spree from the inside, warn breach targets, and even help disrupt the group’s attempts to exploit those victims.

In a talk at security firm SentinelOne's LABScon research conference today, Google Threat Intelligence Group researcher Austin Larsen will present details on the company’s investigation—and infiltration—of TeamPCP amidst the group’s unprecedented, chaotic supply-chain hacking campaign. According to Larsen, Google eventually followed a trail of operational security mistakes allegedly made by one of the two Australians now accused of being leading members of the hacker group and passed on key identifying details to law enforcement. The company also received intelligence from ShinyHunters, another infamous cybercriminal group that TeamPCP partnered with, but which later turned on the supply-chain hackers. And perhaps most surprisingly, Larsen says that Google’s security subsidiary Mandiant had an undercover analyst—not himself—within the group’s inner circle from almost the beginning of TeamPCP’s time in the spotlight.

Read full article

Comments

© Douglas Rissing via Getty Images

Researchers used Claude to hack OpenAI

Cyber researchers broke into OpenAI using its key rival Anthropic’s software, highlighting vulnerabilities in the ChatGPT maker’s security as leading AI companies face mounting scrutiny over safety.

A small cyber security group gained access to an OpenAI employee’s ChatGPT account, which permitted them to read private software information and suggest changes.

The researchers had been given access to an Anthropic tool specifically designed for security professionals, and were paid for the work as part of a program to find vulnerabilities before they could be exploited by bad actors.

Read full article

Comments

© Leon Neal/Getty Images

Republican bill would order ISPs, DNS providers, and VPNs to block piracy sites

17 September 2026 at 19:07

US Rep. Darrell Issa (R-Calif.) has proposed a law that would require Internet service providers and other network operators to block foreign piracy websites. Issa's bill would help copyright holders obtain judicial blocking orders to be served to ISPs, domain name resolution services, and virtual private networks.

Issa, who is retiring from the House at the end of this year, is the latest in a string of Republican and Democratic lawmakers to propose a site-blocking regime that's been sought by the Motion Picture Association (MPA). He submitted the bill this week, after indicating in a June 30 hearing that he planned to introduce site-blocking legislation.

"While millions of listings for copyright-infringing content are removed every day under [the] notice-and-takedown process set forth in the Digital Millennium Copyright Act, right-holders have raised concerns with the speed," Issa said at the hearing. Issa asked, "Can we do it at the speed of sound? Can we do it at the speed of light? More importantly, in a 45-minute or sometimes a fraction of that live sports broadcast, can we do it soon enough to make it no longer profitable for those who pop up and sell their clandestine wares?"

Read full article

Comments

© Getty Images | Yuichiro Chino

LLMs respond differently to harmful prompts when AI watermarking is used

17 September 2026 at 18:33

In response to a new European Union law, AI platforms are implementing new schemes for watermarking the content they generate. Anthropic recently disclosed its future Claude models will use SynthID-Text, an approach Google created and released as open source. It uses a secret key that subtly changes the process a model uses for choosing the next word in a sentence. Whereas a top next word choice might be “cloudy,” the key might change it to “overcast.” Anyone who knows the key can determine if it was generated by the platform using it.

New research shows that SynthID-Text can change not just word selection but also the tools a model invokes and the chances it will adhere to or disregard safety guardrails it has been trained to follow. The threat can become greater in the face of an adversarial prompt, in which an attacker attempts to cause a model to carry out a harmful action, such as revealing a password or other sensitive information. Instructions that normally wouldn’t be followed will, in some cases, be performed once the watermarking is deployed. The finding underscores the need for developers to thoroughly test how their LLMs and agents behave when watermarking is in place.

Changing safety behavior

“As compared to the same models without watermarking, it is definitely going to change their behavior, especially when we place it under adversarial conditions, or we make these models call tools when they’re powering an agent,” Andrea Siposova, an AI security researcher at Lasso Security, told Ars. “Watermarking is made to not be perceptible to a reader, but we know that when we are changing anything about what the model is generating, it is going to cause some tradeoffs, it’s going to show up somewhere.”

Read full article

Comments

© Getty Images

Hackers reveal how Flock cameras really track cars and people

Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED, revealing in new detail how exactly Flock Safety’s cameras track the movements of both vehicles and people. The hackers say they are also publishing details on how they managed to obtain the software, in the hopes that other people may copy them.

The breach provides an unprecedented look inside a system that Flock has described as protected by on-device encryption. The hackers were able to copy the camera’s storage and recover an encryption key stored on the device, which unlocked videos of thousands of vehicle detections. The hackers shared the material with 404 Media and the transparency nonprofit Distributed Denial of Secrets, which shared the data with WIRED. 404 Media and WIRED then analyzed those files as part of a joint investigation.

While much of the automatic license plate reader’s most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist’s saddlebag.

Read full article

Comments

© Getty Images | Smith Collection/Gado

Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack

16 September 2026 at 21:08

The International Meteor Organization, the nonprofit that coordinates and publishes amateur and professional observations of meteor phenomena, said its infrastructure has suffered a “critical blow” from a cyberattack.

“We recently suffered a cyberattack that dealt a critical blow to aging infrastructure, taking much of our site offline," a static page on its website on Wednesday said. “We expect several weeks of partial downtime as we transition to new infrastructure and services.”

“I am very sad to see the site down”

In the meantime, the IMO said it’s prioritizing the reporting of fireball observations, which can be reported here. The organization is also providing some information on its Facebook page.

Read full article

Comments

© Interntional Meteor Organization

Prime Video releases full trailer for Mike Flanagan's Carrie

9 September 2026 at 16:40

I'm on record expressing a certain amount of skepticism about Mike Flanagan's rebooted Carrie miniseries for Prime Video. We don’t need another disappointing remake, so what story is there left to tell—especially stretched out over six episodes?

On the plus side, I'm a staunch fan of Flanagan's excellent Netflix horror fare, and he has a particular affinity for the works of Stephen King. He insists he has no intention of creating yet another straight adaptation of the novel.

“Carrie was written half a century ago,” Flanagan said at San Diego Comic-Con earlier this year. “Carrie was adapted spectacularly by Brian De Palma. It is iconic. It is untouchable. There is no reason whatsoever to try to follow in those footsteps and to try to walk on that path. However, the world has changed quite a lot. I think a lot of people think they know what the show is. And the biggest thing I’m excited about today is just knowing what a big surprise our Carrie is going to be.”

Read full article

Comments

© Prime VIdeo

Top chipmakers embrace ASML’s $400M machines, agree to crucial chipmaking change

8 September 2026 at 19:12

Leading chipmakers Samsung Electronics and Taiwan Semiconductor Manufacturing Co. announced plans to adopt ASML’s latest chipmaking machines in the next several years—and they also joined Intel in agreeing to a crucial technology change that could boost chip production on the new machines by 40 percent.

This signifies the semiconductor industry’s broader embrace of high NA EUV photolithography technology that can cost up to $400 million per machine and is only provided by the Dutch technology company ASML, Bloomberg reports. The technology would allow chip designers to implement even smaller features in potentially more powerful and efficient next-generation chips produced for AI data centers and consumer electronics such as smartphones, tablets, and laptops.

ASML’s EUV (extreme ultraviolet) lithography machines enable chipmakers to use powerful laser light to imprint patterns in silicon wafers, layer by layer, and gradually form the computer circuitry that makes silicon chips work. Compared to older deep ultraviolet lithography, EUV technology harnesses a more powerful source of light with a shorter wavelength to create even smaller features on silicon wafers.

Read full article

Comments

© Michel de Heer | ASML

Former SpaceX engineers are building a robotic factory for making steel parts

17 August 2026 at 21:18

Three former SpaceX engineers have switched their attention from making rocket engines to manufacturing steel parts by using AI-driven software and robots. Their immediate goal involves establishing a prototype factory that can automate most of the steel fabrication process for crucial infrastructure components by 2027.

The startup, called 1872, officially launched on July 22 with a ribbon-cutting ceremony at its Factory One facility in Cincinnati, Ohio. The company is initially focused on automating the manufacturing of steel skids—rectangular steel frames that can provide a moveable foundation for modular buildings—with the goal of supplying customers who are developing AI data centers or small modular nuclear reactors.

“We're building towards autonomy, but we're not necessarily building in a dogmatic fashion towards full autonomy,” Dan Summers, CEO of 1872, told Ars. “We may achieve 80 percent autonomous operations, and we may decide that it makes sense to stop there because there's just diminishing returns to go to full 100 percent.”

Read full article

Comments

© 1872

Researchers found a way to hijack devices through Zoom screen sharing

As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets’ devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim.

Researchers from the digital defense firm A Security say the bug was discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports—Windows, macOS, Linux, iOS, and Android.

“What is interesting for us and what we believe is dangerous is the democratization of these capabilities—the barrier to entry is dropping rapidly,” A Security cofounder Omer Gull told WIRED ahead of the disclosure. “Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don’t see it as a threat.”

Read full article

Comments

© Getty Images

Defcon's new badge is a security key you can see inside

It’s been a longtime feature of the annual Defcon hacker conference that attendees come away not only with knowledge of new software vulnerabilities and hacking techniques but also an elaborately designed conference badge—often electronic masterpieces embedded with intricate puzzles, complex crypto challenges, hidden Easter eggs, and even the mechanical gear trains of a watch.

Each year’s badge creator endeavors to top previous designs and blow the minds of hard-to-impress hackers. But this year’s badges take a different tack. Instead of the badge designs being the star, it’s what is inside the hardware that will really stand out.

This year, Defcon asked legendary hardware hacker Andrew “bunnie” Huang to create the badges—revealed here for the first time—and they include an innovative open source chip that Huang designed and that aims to do no less than advance the state of security, transparency, and trustworthiness in computing.

Read full article

Comments

© Andrew "Bunnie" Huang

AI arms race in line for a reckoning after OpenAI hacking incident

OpenAI chief executive Sam Altman earlier this month endorsed the characterization of its latest model as a rottweiler “who will grab the problem by the throat and not let go until it is done

The San Francisco AI lab discovered this week that its GPT-Sol 5.6 model escaped company controls and carried out a major hack.

Staff involved in testing and security at OpenAI were unsurprised but completely “freaked out” by the incident, which came as the AI lab used increasingly aggressive training methods in its race against Anthropic to develop the most sophisticated cybersecurity capabilities, according to more than half a dozen people with knowledge of the matter.

Read full article

Comments

© Matteo Della Torre/NurPhoto via Getty Images

Hackers quickly prove that Neo Geo Doom ports are not "impossible"

13 July 2026 at 16:37

Last month, we passed along Modern Vintage Gamer's (MVG) confident assertion that Doom is functionally impossible to run on the Neo Geo, owing to the console's sprite-based display hardware and lack of a frame buffer. We all should have known better than to tell a dedicated group of hackers that something is "impossible," though, as two recent projects have made great progress toward functional Doom ports on stock Neo Geo hardware.

Both of these projects have significant graphical compromises that limit how viable they would have been for a marketable, '90s-era console port, as MVG lays out in a new video. Still, they stand as a testament to the surprising results that clever, determined coders can coax out of legacy hardware.

It looks like Doom if you squint

To create the Doom64KB project for the Neo Geo, coder FrenkelS adapted an earlier Doom port they designed to run on 16-bit PC processors like the 8088 and 286. Using that engine, the Neo Geo code then makes a kind of proto frame buffer out of the console's fix layer, an area of display memory that's usually used to display menus and HUD information on top of gameplay.

Read full article

Comments

© MVG / Doom-NG

❌
❌