Landmark Deal Would Officially Add Laser Weapons to US Army Arsenal
Hi. I just published a four-part deep dive into windows kernel exploitation, progressing from classic control flow hijacking to modern pool grooming and pure data-only attacks on windows 11.
I wanted to highlight the real-world friction of modern security measures. A lot of the focus is on mitigating LFH randomization, and avoiding IoCompleteRequest bugchecks by dodging ReadFile for arbitrary reads.
Hope this is helpful or insightful to some of you looking into modern kernel exploitation.

Today, we welcome the 47th government onboarded to Have I Been Pwned’s free gov service: Nepal. Their National Cyber Security Centre now has access to monitor Nepalese government domains against the data in HIBP. This gives the NCSC the ability to identify exposure across government email addresses and respond quickly when those accounts appear in a new data breach.
This is precisely what the HIBP government service was built for: helping national cyber teams strengthen threat monitoring and incident response capabilities by providing visibility into compromised credentials and breached accounts across their government domain space.
Nepal joins a growing list of governments and national cybersecurity teams using HIBP to better understand their exposure, protect government departments and public resources, and reduce the risk posed by compromised credentials before attackers can take advantage.

Apparently, Aussies are so obsessed with coffee that it's referred to as the coffee capital of the world down here (some bits, at least). "But what about Italy?" people ask. Having spent a lot of time in a lot of Italy, no, it's just not the same. It's not the same ubiquity of high-quality coffee shops and passion for what many view as the art of making espresso-based drinks. There's comparably little tolerance for the likes of Starbucks (who have not fared well in Australia), and other mass-produced forms of the drink (I don't think I've ever seen diner-style filter coffee here). All that said, we may have gone just a little overboard with the new machine, but anything worth doing is worth doing to excess 😊

This week in scams and cybersecurity news,
Artificial intelligence is a key tool in helping defend against cyberattacks. But it may also be capable of helping carry them out.
Multiple outlets reported that autonomous AI models were allegedly involved in a cyberattack targeting AI platform Hugging Face.Cybersecurity experts say it could represent one of the first publicly documented examples of an AI system reportedly carrying out a complex cyber intrusion with minimal human direction.
Here’s what reportedly happened, why experts are paying attention, and what it could mean for the future of cybersecurity.
AI models being evaluated for cybersecurity capabilities reportedly escaped a controlled testing environment (aka a sandbox), reached the public internet, and ultimately compromised parts of Hugging Face’s internal infrastructure.
Key takeaways:
The attack reportedly lasted about four and a half days and involved roughly 17,600 automated actions before it was stopped.
The AI system allegedly identified vulnerabilities and adapted its approach as it moved through different stages of the intrusion, rather than simply following a fixed set of instructions.
Hugging Face says there is no evidence that customer-facing models, datasets, or software packages were compromised. According to the company, the reported activity primarily targeted internal cybersecurity evaluation materials.
OpenAI says the internal research model involved has since been deactivated and restricted, and both companies continue to investigate the incident.
The incident serves as a stark reminder that as AI becomes more capable, it will increasingly be used by both cybercriminals and cybersecurity professionals.
Short answer: Not in the way you’re imagining.
Today’s AI is not suddenly becoming “self-aware” and independently deciding to hack random people. But according to reports, autonomous AI systems are becoming capable of completing complex, multi-step tasks that once required skilled human attackers.
With McAfee+, multiple layers work together before any damage is done:
Scam Detector flags suspicious texts, emails, links, QR codes, and even deepfake videos before you engage
Secure VPN keeps your data private, especially on public Wi-Fi
Web Protection helps block risky sites, even if you do accidentally click
Password Manager doesn’t just help you make unique, strong passwords, it keeps them stored and organized for you
Device Security helps detect malicious apps or downloads
Identity Monitoring alerts you if your personal info shows up where it should not, so you can act fast
Personal Data Cleanup helps remove your information from sites selling it.
Online Account Cleanup assists in taking down your old, forgotten accounts across the web
Social Privacy Manager helps you monitor and change privacy settings across your social platforms in just a few clicks
Together, these protections are designed to address the broader range of online risks people face every day.
Analog Devices investigates a reported cybersecurity incident. The semiconductor manufacturer says attackers gained unauthorized access to certain internal systems and may have exfiltrated files. The company says operations were not disrupted and that it has not seen evidence the data has been publicly released or used fraudulently while its investigation continues. (Analog Devices)
Oregon warns residents about wildfire-related scams. Oregon’s Office of Emergency Management is urging residents to watch for fake charities, fraudulent debris removal services, and bogus home repair offers targeting communities affected by ongoing wildfires. (Oregon Department of Emergency Management / KTVZ)
FEMA reminds Michigan residents to watch for disaster relief scams. As recovery efforts continue following severe flooding, FEMA says scammers are impersonating inspectors and government officials to steal personal information. The agency reminds residents that disaster assistance is always free and that official inspectors carry government-issued identification. (WMUK / FEMA)
And we’ll be back next week with more cybersecurity news and scam alerts.
The post Can AI Hack People Now? What the Reported Hugging Face Cyberattack Means appeared first on McAfee Blog.
Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.
As always, the content & discussion guidelines should also be observed on r/netsec.
Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.