Latest AI and Cyber Security news with Refract Digests—curated insights from trusted sources with BLUF summaries and actionable analysis. (56 articles)
Outdated global cybercrime laws expose security researchers to legal risks, prompting a new five-point framework to protect ethical hacking efforts.
A public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research.
Attackers are exploiting a new vulnerability called GhostJacking to hijack AI agents by manipulating security alerts. This reveals significant gaps in how organizations govern identity and access for automated systems.
New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents.
Suspected Iranian hackers are attacking water systems in over a dozen US states by exploiting insecure internet-connected controllers. This campaign highlights critical vulnerabilities in public utility infrastructure security.
Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.
A critical unpatched flaw in Metabase allows attackers to take full control of business analytics platforms remotely. This zero-day vulnerability poses a significant risk to organizations using the tool for data analysis.
The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.
This weekly post shares a nature video and invites readers to discuss unreported security news in the comments. It serves as a community hub rather than a formal intelligence briefing.
Nice video of the Arctic bobtail squid.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Blog moderation policy.
Recent research indicates that half of AI-generated software patches fail or introduce new vulnerabilities despite appearing functional. Organizations using automated remediation tools must verify these fixes manually to prevent worsening security risks.
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.
A Canadian cybercriminal pleaded guilty to hacking over 165 companies via Snowflake and stealing AT&T customer data, marking a significant legal development in recent cloud extortion cases.
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organiz...
Vendors are marketing clothing designed to evade facial recognition, though experts warn the technology is untested and primarily serves as a symbolic act of resistance.
There are many companies manufacturing adversarial clothing designed to confuse facial recognition systems.
It’s a cool idea, but I worry that it’s mostly security theater:
“Our patterns play with th...
Cybercriminals are evolving faster than police can respond because law enforcement agencies still work separately instead of together. This gap allows attackers to stay ahead of legal deterrents and continue their operations.
The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.