OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know

You can’t have failed to hear the news headlines about “rogue” OpenAI models hacking into another AI organisation, Hugging Face.

But what has actually happened, who is to blame, and is it as serious as some of the reports suggest?

Find out in my arti… Continue reading OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know

Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker

A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday – and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets.

Meanwhile, AI music generator Suno has … Continue reading Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker

Ukraine warns fake CAPTCHAs are being used to make you hack yourself

Ukraine’s computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromised websites that persuade users to run malicious code.

Read more in my article on the Hot for … Continue reading Ukraine warns fake CAPTCHAs are being used to make you hack yourself

Google’s Gemini lets strangers send messages from your locked Android phone

Gemini, Google’s AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone.

Read more in my article on the Hot for Security blog. Continue reading Google’s Gemini lets strangers send messages from your locked Android phone

Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers

An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks – no login, no passwords, no permissions needed.

Meanwhile, Geoff – swimming in money and Lamborghinis, as all published authors are – has be… Continue reading Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers

The ransomware negotiator who was working for the other side

When a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help.

Specialist ransomware negotiation firms handle communications with criminal gangs on a victim’s behalf.

What victims don’t expect is that thei… Continue reading The ransomware negotiator who was working for the other side

Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk

Have you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role? Well, before you start brushing up your interview technique, take a closer look at who is really behind it.

Read more in my article o… Continue reading Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk

Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself

A 15-year-old boy asked a chatbot for help – and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, “JadePuffer”. What does … Continue reading Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself

Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud

Two young men have been arrested in the Netherlands on suspicion of running a phishing operation that harvested the credit card details of unsuspecting victims.

Read more in my article on the Hot for Security blog. Continue reading Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud