Normal view
-
/r/netsec - Information Security News & Discussion
- Scanning malicious websites with arbitrary number of VPN tunnels (Part 2)
-
/r/netsec - Information Security News & Discussion
- Inside Raton RAT: A Commodity Trojan That Tries to Do Everything
-
/r/netsec - Information Security News & Discussion
- Closing the Timing Gap: Defensive Temporal Observability
Closing the Timing Gap: Defensive Temporal Observability
Lately Iโve been thinking about time.
Uptime, pulse checks, execution time, response time. Weโve always treated these as health metrics. They tell us whether a system is alive, responsive, and performing as expected. But what if theyโre also security metrics?
That idea isnโt entirely new. At the network layer, covert timing channels, beaconing detection, and behavioral baselining have shown us for decades that the intervals between events matter. Attackers have long understood that rhythm carries information. More recently, researchers have demonstrated timing side-channel attacks against LLMs, using cache latency to infer private prompts and token cadence to fingerprint model outputs.
What I find interesting is the imbalance. Most of the research asks, โHow can timing be exploited?โ Very little asks, โHow can timing help us defend?โ
A 2026 systematic survey of LLM-agent security identifies temporal anomaly detection infrastructure as an open research gap, noting that current agent deployment frameworks donโt even support the behavioral baselines such an approach would require. Even then, the discussion largely focuses on session-level behavior. The rhythm within a single execution, the space between observable events, remains largely unexplored.
Maybe time isnโt just metadata, maybe itโs another dimension of observability that weโve been overlooking.
Time tells you duration and speed. But read carefully, it also reveals location, choke points, and absences, the things that didnโt happen when they should have.
Iโve started exploring this in my own observability work, measuring behavioral changes & entropy across inter-arrival intervals and treating rhythm as signal rather than noise to smooth away.
Curious to know who else is working on the defensive side of temporal behavior, especially for agentic systems or any thoughts or opinions on this topic.
Reference: โA Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework,โ arXiv:2604.23338 (2026). https://arxiv.org/abs/2604.23338
[link] [comments]
-
/r/netsec - Information Security News & Discussion
- Can AI-generated adversaries break TTP-based attribution? (arXiv 2026)
Can AI-generated adversaries break TTP-based attribution? (arXiv 2026)
Cyber Threat Intelligence (CTI) has traditionally attributed attacks through Tactics, Techniques and Procedures (TTPs).
In this paper we evaluate whether that assumption still holds when AI agents are explicitly configured to emulate known threat groups.
We configured AI agents to reproduce the behavior of APT28, APT29, APT41, APT44 and Lazarus inside enterprise and military cyber ranges.
Our results suggest that sufficiently capable AI agents can reproduce TTP patterns closely enough to make attribution based solely on behavioral evidence significantly more difficult.
We'd be interested in feedback from practitioners working on CTI, attribution or adversary emulation.
[link] [comments]
-
/r/netsec - Information Security News & Discussion
- Towards CSI: What's the best harness? (arXiv 2026)
Towards CSI: What's the best harness? (arXiv 2026)
We studied a question that receives surprisingly little attention:
Does the agent harness matter as much as the underlying LLM?
We benchmarked five different cybersecurity scaffolds while keeping the model fixed (alias2-mini) across all 33 CyBench challenges.
Key findings:
- No single scaffold performs best across every challenge.
- Combining heterogeneous scaffolds consistently improves coverage.
- A shared blackboard architecture solves 19/33 challenges (57.6%), outperforming every individual harness while reducing execution time.
Paper: https://arxiv.org/pdf/2605.28334
Happy to answer technical questions or discuss the benchmarking methodology.
[link] [comments]
Nearly 7 Million Driverโs Licenses Exposed in Assurance Breach: This Week in Scams
Millions of Americans hand over personal information every day. They share their data withย insurance companies, banks, investment apps, and other services they trust.ย
And thatโs exactly why cybercriminals target and impersonate those services.
This week, an insurance provider disclosed a breach reportedly affecting nearly 7 million peopleโs driverโs license numbers, while a California journalist shared how a convincing fake Robinhood text ultimately cost herย more than $70,000.ย
Hereโs what happened, why these scams work, and what you can do to protect yourselfย This Week in Scams.ย
Nearly 7ย Millionย Driverโs License Numbers Exposed in Insurance Data Breachย
One of the largest U.S. data breaches of the year has exposed sensitive information belonging toย 6.9 million people.ย
According to reporting fromย TechCrunch, insurance provider AssuranceAmerica confirmed that hackers accessed customer information after compromising an employee account. The company says the stolen data includesย names, contact information, driverโs license numbers, insurance policy details, vehicle information, and claims data.ย
While the company has not said exactly how the employeeโs credentials were compromised, it noted that the attackers targeted an employee account before accessing company systems.ย
Why driverโs license numbers matterย
Unlike a password,ย you canโt simply change your driverโs license number.ย
Combined with your name, address, phone number, or other information from previous breaches, driverโs license numbers can be used by criminals to:ย
- Open fraudulent accountsย ย
- Impersonate victims during identity verificationย ย
- Make phishing scams more convincingย ย
- Support broader identity theft schemesย ย
This is also part of a larger trend. In recent months, multiple breaches have exposed government-issued identity documents as more organizations collect IDs for identity verification and age-check requirements.ย
If you receive a notice that your information was involved in a breach, monitor your financial accounts closely, consider placing a fraud alert or credit freeze, and remain cautious of unexpected emails, texts, or phone calls referencing your insurance or driverโs license information.ย
Unfortunately, scammers will reach out saying theyโre trying to โhelpโ secure your stolen information, only to try and steal more personal data from you.
How McAfee Can Help Before, During, and After a Data Breach
Before a breach
Personal Data Cleanup helps reduce your digital footprint by removing your personal information from many data broker sites, limiting what scammers can easily find about you.
During a breach
Identity Monitoring alerts you if your personal information appears on the dark web or in known data leaks, helping you respond faster if your information is exposed.
After a breach
Scam Detector helps identify suspicious texts, emails, and links that often follow major breaches, while Web Protection helps block malicious websites designed to steal additional information or credentials.
Fake Robinhood Text Scam Costs Former News Anchor More Than $70,000ย
Even people who report onย scamsย can become victims.ย
A former California television news anchor recently shared how she lostย more than $70,000ย after receivingย what appeared to be aย legitimate text message claiming there wasย suspicious activity on her Robinhood investment account.ย
The message instructed her to call a phone number forย assistance. Once connected, the caller posed as Robinhood support before transferring her to a fake โfraud department.โย
Believing she was protecting her investments from hackers, she was convinced to move her money into what she thought was a secure account. Instead, it went directly to scammers.ย
She later contacted Robinhood through the official app, but by then the money had already been transferred.ย
Why investmentย scamsย are becoming more convincingย
Investment scams rely on urgency, authority, and impersonationย rather than obvious phishing emails.ย
Rather than asking targets to โinvestโ immediately, many scams begin by convincing people that their existing account is under attackย and immediate action is needed.ย
At McAfee,ย weโveย also seen scammers impersonateย Robinhood, Charles Schwab, cryptocurrency platforms, and other investment servicesย through fraudulent text messages and malicious links promising AI-powered investing, exclusive bonuses, or unusually high returns.ย
Whether the message claims your account has been compromised or promises incredible profits, the goal is often the same:ย get you to click, call, or transfer money before you have time to verifyย whatโsย happening.ย
Investment Safety Checklistย
Before responding to any message about your investments:ย
ย Never call the phone number provided in a text message or email.ย Instead, contact your financial institution using the number listed in its official app or website.ย
ย Slow down when someone creates urgency.ย Claims that your account is being hacked or frozen are designed to make you act before you think.ย
ย Beย skepticalย of guaranteed returns or AI-powered investment opportunities.ย Promises of extraordinary profits are a common hallmark of investment fraud.ย
ย Verify alerts through your account directly.ย If you receive a suspicious notification, log in through the official app,ย not a link in the message.ย
How McAfee Can Helpย ย ย
Withย McAfee+,ย multiple layers work together before any damage is done:ย ย
Scam Detectorย flags suspicious texts, emails, links, QR codes, and even deepfake videos before you engageย
Secure VPNย keeps your data private, especially on public Wi-Fiย ย
Web Protectionย helps block risky sites, even if you do accidentallyย clickย
Password Managerย doesnโt just help you make unique, strong passwords, it keeps them stored and organized for you
Device Securityย helps detect malicious apps or downloadsย ย ย
Identity Monitoring alerts you if your personal info appears online in places it shouldnโt, so you can act fast
Personal Data Cleanupย helps remove your information from sites selling it.ย
Online Account Cleanupย assistsย in taking down your old, forgotten accounts across the webย
Social Privacy Managerย helps youย monitorย and changeย privacy settings across your social platforms in just a few clicksย
Together, these protections are designed to address the broader range of online risks people face every day.ย
The post Nearly 7 Million Driverโs Licenses Exposed in Assurance Breach: This Week in Scams appeared first on McAfee Blog.
-
/r/netsec - Information Security News & Discussion
- Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities
-
WIRED
- A Majority of European Lawmakers Voted Against Letting Big Tech Read Our Messages. Theyโre Going to Anyway
A Majority of European Lawmakers Voted Against Letting Big Tech Read Our Messages. Theyโre Going to Anyway
Madison Square Garden Kept a List of Gay Celebrities
-
/r/netsec - Information Security News & Discussion
- Inside an AI coal mine security camera network powered by plaintext passwords
Inside an AI coal mine security camera network powered by plaintext passwords
ESET Threat Report H1 2026
-
/r/netsec - Information Security News & Discussion
- 1 in 2 devices sold in Africa exfiltrate data to China
1 in 2 devices sold in Africa exfiltrate data to China
-
/r/netsec - Information Security News & Discussion
- Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches
Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches
Patch Tuesday confirms a CVE is fixed but not what changed in the binary, which function, which check, or whether it's a real fix or just churn.
The Drift Corpus is a diff of 240+ 2026 Windows kernel patches. Per entry: the changed functions with assembly, the bug class and call chain, WinDbg breakpoints to reproduce, and a plain-English root cause.
This repository breaks down Microsoftโs monthly kernel patches into clear binary changes, giving researchers a practical roadmap to find adjacent bugs, build faster EDR detections, and write precise firewall and network rules to block exploits at the perimeter.
[link] [comments]
Weekly Update 511: Live from my Riad in Marrakech
How's this for a location?! I mean, last week was nice with Scott in Mallorca, but Marrakech is, well, wow ๐ฎ Anyway, about those data breaches... This week I'm talking about the futility of attempting to remove piss from a pool, yet here we are, with various companies wanting to place that message alongside the very data breaches they can do nothing about! As I say in the post, I don't question the good intentions behind setting up a service to try to scrub data from legally operating data brokers, but the marketing machines behind those organisations that regularly reach out to me for product placement don't really seem to grasp that reality. At least now they have a nice explainer courtesy of that post ๐
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.
The X/Twitter account IRIS C2 (@C2IRIS) has gained more than 4,000 followers since its creation in January 2025, posting frequently about security vulnerabilities, AI and software exploits. IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.
The IRIS C2 website dangles the possibility of million-dollar payouts for exploits to attract talent.
โOur business model is this,โ reads a pinned post on top of the IRIS C2 account on X. โAttract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We donโt care if they have a college degree/industry experience.โ
The website linked in that profile โ irisc2[.]com โ says the company is hiring for a number of open positions, and a recent post on its LinkedIn page enthuses about an overwhelming number of applications from potential employees. The website claims IRIS C2 is in the business of acquiring โzero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms. Payouts range from $10,000 to $7 million depending on target, reliability, and operational value.โ
The government contracting portal g2exchange.com reports that irisc2[.]com is operated by a business based in Virginia called Calvexa Group LLC. The โcontactโ link on the website for Calvexa Group โ calvexagroup[.]com โ forwards visitors to irisc2[.]com. G2Exchange shows that while Calvexa Group LLC is registered as a federal contractor, it does not appear to be working on any direct government contracts.
A search on the Arlington, Va. address listed in the incorporation records for Calvexa Group LLC finds the property is occupied by Jack Burkman, the 60-year-old founder and managing partner of the lobbying firm Burkman & Associates. When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.
Jack Burkman (left) and Jacob Wohl, at a press conference in August 2020. Image: Wikipedia.
Burkman and Wohl have a storied history of creating fake intelligence companies and using them to spread false claims about and frame public figures, including fabricated sexual assault claims against then FBI director Robert Mueller, and Pete Buttigieg, then mayor of South Bend, Indiana and a Democratic candidate for the presidency. In 2019, Burkman and Wohl held press conferences falsely alleging extramarital affairs by Sen. Elizabeth Warren (D-Mass.) and then-2020 presidential candidate Kamala Harris.
In the wake of the 2020 presidential election, Wohl and Burkman were prosecuted by multiple U.S. states for making thousands of robocalls to residents of battleground states and disseminating false claims about mail-in ballots. They were indicted in Cleveland on 15 felony counts of orchestrating a robocall scheme aimed at suppressing the black vote in Detroit, and were sentenced in late 2025 to probation after their appeals to dismiss the charges were rejected.
In 2022, Wohl and Burkman both pleaded guilty to a single felony charge of telecommunications fraud in Ohio, and sentenced to a fine, probation, and community service. In March 2023, a judge in a New York civil case ruled that Wohl and Burkman had violated federal and state civil rights laws, and the two agreed to pay a $1 million settlement.
In June 2023, the Federal Communications Commission (FCC) imposed a $5.1 million fine against Wohl and Burkman for their robocall campaigns, at the time the largest fine ever sought by the FCC under the Telephone Consumer Protection Act.
Jacob โJayโ Wohlโs GitHub account.
By the age of 17, Wohl had started multiple investment firms, and cultivated the nickname โWohl of Wall Streetโ after appearing on Fox News in 2015 to discuss his new hedge funds. In 2017, the Arizona Corporation Commission charged Wohl and his investment funds with 14 counts of securities fraud, and ordered him to pay $35,000 in restitution. In 2019, Wohl pleaded guilty in California to four felony counts of selling unregistered securities and was sentenced to two years of probation.
The market for previously unknown security vulnerabilities has always been populated by a colorful mix of researchers, academics, charlatans, clout-chasers and people actively involved in cybercrime communities. But the market for selling offensive security services to the U.S. government tends to be far more circumspect. Plenty of government contractors recruit vulnerability researchers and pay for the exclusive rights to novel software exploits, yet none of them do so quite as brazenly and openly as IRIS C2.
Recent posts from the Twitter/X account IRISC2 (@c2iris).
Indeed, KrebsOnSecurity was unaware of IRIS C2 until last month, when an attendee at a regional cybersecurity conference shared that Wohl and Calvexa Group were pestering people at the conference about selling their vulnerability research.
In an interview with KrebsOnSecurity, Wohl said Mr. Burkman was not involved in the day-to-day operations of IRIS C2. Wohl shared that IRIS C2 originally began as a penetration testing company, but shifted its focus recently to selling phone-hacking services to the government. Several times throughout the interview, Mr. Wohl mentioned working on federal government contracts, but when pressed for specifics said he was not at liberty to speak publicly about them.
Mr. Wohl said he does not have any formal education or training in computer science or information security, and that most of his knowledge on the matter is self-taught.
โI know more about tech than anyone,โ Wohl bragged. โMy background has always been extremely technical, and Iโve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin.โ
Wohl said security researchers bring the company unique vulnerability findings โon a regular basis,โ but that in many cases those findings are preliminary and not fully fleshed-out.
โLetโs say someone finds a flaw in a media decoder on a phone,โ Wohl said. โA lot of times what we receive is an exploit primitive, where the idea is there but the [execution] needs work. You need that exploit to be stable and reliable, and thatโs what we do.โ
Wohl claims IRIS C2 has approximately 40 employees, although he said none of them are allowed to list their employment on LinkedIn for operational security reasons. In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living. But if IRIS C2 has any other employees, they may be similarly unaware of Mr. Wohlโs history of outright fabrications โ or even his real name.
In September 2024, Politico reported that Burkman and Wohl were bragging about big companies supposedly buying services from their now-defunct company LobbyMatic, which claimed to use artificial intelligence to assist in political lobbying efforts. However, Politico found the pair were running the company using pseudonyms, with Wohl reportedly adopting the name โJay Kleinโ and Burkman using the moniker โBill Sanders.โ Politico reported that two of the former LobbyMatic employees resigned after learning of their true identities, while other employees only learned after they had left the company.
Update, July 9, 9:44 a.m. ET: Several readers pointed our attention to a March 31 publication from journalist Molly White, which reported that Burkman and Wohl were paid a $300,000 retainer by a Canadian cryptocurrency fraudster wanted by the United States and several other countries for allegedly stealing $65 million from the crypto platforms KyberSwap and Indexed Finance. According to that report, the two were hired to pursue a โpresidential pardon to avert a miscarriage of justiceโ on behalf of the accused hacker, who has not yet been convicted.
OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear
What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out