Security updates for Monday

Post Syndicated from jzb original https://lwn.net/Articles/1058989/

Security updates have been issued by Debian (chromium, pdns-recursor, python-django, and wireshark), Fedora (gnutls, linux-sgx, mingw-expat, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, p11-kit, python-aiohttp, vim, and xen), Red Hat (kernel, kernel-rt, python-s3transfer, python-urllib3, and resource-agents), SUSE (aaa_base, abseil-cpp, build-20260202, cargo-auditable, cargo-c, chromedriver, cockpit, cockpit-packages, cockpit-subscriptions, curl, elemental-toolkit, elemental-operator, gnome-remote-desktop, go1.24, go1.25, gpg2, haproxy, himmelblau, htmldoc, ImageMagick, iperf, java-1_8_0-openjdk, kernel, krb5, kubevirt, libowncloudsync-devel, libpng16-16, libsodium, libsoup, libsoup2, micropython, net-snmp, opencryptoki, openjfx, openssl1, ovmf, postgresql14, postgresql15, postgresql16, protobuf, python-aiohttp, python-brotli, python-maturin, python-pip, python-urllib3, python310, python311, python-rpm-macros, python311-cryptography, python314, screen, systemd, u-boot, util-linux, and vim), and Ubuntu (dotnet8, dotnet10, expat, freerdp2, freerdp3, and python-aiohttp).

The Promptware Kill Chain

Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2026/02/the-promptware-kill-chain.html

The promptware kill chain: initial access, privilege escalation, reconnaissance, persistence, command & control, lateral movement, action on objective

Attacks against modern generative artificial intelligence (AI) large language models (LLMs) pose a real threat. Yet discussions around these attacks and their potential defenses are dangerously myopic. The dominant narrative focuses on “prompt injection,” a set of techniques to embed instructions into inputs to LLM intended to perform malicious activity. This term suggests a simple, singular vulnerability. This framing obscures a more complex and dangerous reality. Attacks on LLM-based systems have evolved into a distinct class of malware execution mechanisms, which we term “promptware.” In a new paper, we, the authors, propose a structured seven-step “promptware kill chain” to provide policymakers and security practitioners with the necessary vocabulary and framework to address the escalating AI threat landscape.

In our model, the promptware kill chain begins with Initial Access. This is where the malicious payload enters the AI system. This can happen directly, where an attacker types a malicious prompt into the LLM application, or, far more insidiously, through “indirect prompt injection.” In the indirect attack, the adversary embeds malicious instructions in content that the LLM retrieves (obtains in inference time), such as a web page, an email, or a shared document. As LLMs become multimodal (capable of processing various input types beyond text), this vector expands even further; malicious instructions can now be hidden inside an image or audio file, waiting to be processed by a vision-language model.

The fundamental issue lies in the architecture of LLMs themselves. Unlike traditional computing systems that strictly separate executable code from user data, LLMs process all input—whether it is a system command, a user’s email, or a retrieved document—as a single, undifferentiated sequence of tokens. There is no architectural boundary to enforce a distinction between trusted instructions and untrusted data. Consequently, a malicious instruction embedded in a seemingly harmless document is processed with the same authority as a system command.

But prompt injection is only the Initial Access step in a sophisticated, multistage operation that mirrors traditional malware campaigns such as Stuxnet or NotPetya.

Once the malicious instructions are inside material incorporated into the AI’s learning, the attack transitions to Privilege Escalation, often referred to as “jailbreaking.” In this phase, the attacker circumvents the safety training and policy guardrails that vendors such as OpenAI or Google have built into their models. Through techniques analogous to social engineering—convincing the model to adopt a persona that ignores rules—to sophisticated adversarial suffixes in the prompt or data, the promptware tricks the model into performing actions it would normally refuse. This is akin to an attacker escalating from a standard user account to administrator privileges in a traditional cyberattack; it unlocks the full capability of the underlying model for malicious use.

Following privilege escalation comes Reconnaissance. Here, the attack manipulates the LLM to reveal information about its assets, connected services, and capabilities. This allows the attack to advance autonomously down the kill chain without alerting the victim. Unlike reconnaissance in classical malware, which is performed typically before the initial access, promptware reconnaissance occurs after the initial access and jailbreaking components have already succeeded. Its effectiveness relies entirely on the victim model’s ability to reason over its context, and inadvertently turns that reasoning to the attacker’s advantage.

Fourth: the Persistence phase. A transient attack that disappears after one interaction with the LLM application is a nuisance; a persistent one compromises the LLM application for good. Through a variety of mechanisms, promptware embeds itself into the long-term memory of an AI agent or poisons the databases the agent relies on. For instance, a worm could infect a user’s email archive so that every time the AI summarizes past emails, the malicious code is re-executed.

The Command-and-Control (C2) stage relies on the established persistence and dynamic fetching of commands by the LLM application in inference time from the internet. While not strictly required to advance the kill chain, this stage enables the promptware to evolve from a static threat with fixed goals and scheme determined at injection time into a controllable trojan whose behavior can be modified by an attacker.

The sixth stage, Lateral Movement, is where the attack spreads from the initial victim to other users, devices, or systems. In the rush to give AI agents access to our emails, calendars, and enterprise platforms, we create highways for malware propagation. In a “self-replicating” attack, an infected email assistant is tricked into forwarding the malicious payload to all contacts, spreading the infection like a computer virus. In other cases, an attack might pivot from a calendar invite to controlling smart home devices or exfiltrating data from a connected web browser. The interconnectedness that makes these agents useful is precisely what makes them vulnerable to a cascading failure.

Finally, the kill chain concludes with Actions on Objective. The goal of promptware is not just to make a chatbot say something offensive; it is often to achieve tangible malicious outcomes through data exfiltration, financial fraud, or even physical world impact. There are examples of AI agents being manipulated into selling cars for a single dollar or transferring cryptocurrency to an attacker’s wallet. Most alarmingly, agents with coding capabilities can be tricked into executing arbitrary code, granting the attacker total control over the AI’s underlying system. The outcome of this stage determines the type of malware executed by promptware, including infostealer, spyware, and cryptostealer, among others.

The kill chain was already demonstrated. For example, in the research “Invitation Is All You Need,” attackers achieved initial access by embedding a malicious prompt in the title of a Google Calendar invitation. The prompt then leveraged an advanced technique known as delayed tool invocation to coerce the LLM into executing the injected instructions. Because the prompt was embedded in a Google Calendar artifact, it persisted in the long-term memory of the user’s workspace. Lateral movement occurred when the prompt instructed the Google Assistant to launch the Zoom application, and the final objective involved covertly livestreaming video of the unsuspecting user who had merely asked about their upcoming meetings. C2 and reconnaissance weren’t demonstrated in this attack.

Similarly, the “Here Comes the AI Worm” research demonstrated another end-to-end realization of the kill chain. In this case, initial access was achieved via a prompt injected into an email sent to the victim. The prompt employed a role-playing technique to compel the LLM to follow the attacker’s instructions. Since the prompt was embedded in an email, it likewise persisted in the long-term memory of the user’s workspace. The injected prompt instructed the LLM to replicate itself and exfiltrate sensitive user data, leading to off-device lateral movement when the email assistant was later asked to draft new emails. These emails, containing sensitive information, were subsequently sent by the user to additional recipients, resulting in the infection of new clients and a sublinear propagation of the attack. C2 and reconnaissance weren’t demonstrated in this attack.

The promptware kill chain gives us a framework for understanding these and similar attacks; the paper characterizes dozens of them. Prompt injection isn’t something we can fix in current LLM technology. Instead, we need an in-depth defensive strategy that assumes initial access will occur and focuses on breaking the chain at subsequent steps, including by limiting privilege escalation, constraining reconnaissance, preventing persistence, disrupting C2, and restricting the actions an agent is permitted to take. By understanding promptware as a complex, multistage malware campaign, we can shift from reactive patching to systematic risk management, securing the critical systems we are so eager to build.

This essay was written with Oleg Brodt, Elad Feldman and Ben Nassi, and originally appeared in Lawfare.

Upcoming Speaking Engagements

Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2026/02/upcoming-speaking-engagements-53.html

This is a current list of where and when I am scheduled to speak:

  • I’m speaking at Ontario Tech University in Oshawa, Ontario, Canada, at 2 PM ET on Thursday, February 26, 2026.
  • I’m speaking at the Personal AI Summit in Los Angeles, California, USA, on Thursday, March 5, 2026.
  • I’m speaking at Tech Live: Cybersecurity in New York City, USA, on Wednesday, March 11, 2026.
  • I’m giving the Ross Anderson Lecture at the University of Cambridge’s Churchill College at 5:30 PM GMT on Thursday, March 19, 2026.
  • I’m speaking at RSAC 2026 in San Francisco, California, USA, on Wednesday, March 25, 2026.

The list is maintained on this page.

This Silicom P3IMB-M-P2 is a Neat Intel ACC100 Card We Take a Quick Look

Post Syndicated from Patrick Kennedy original https://www.servethehome.com/this-silicom-p3imb-m-p2-is-a-neat-intel-acc100-card-we-take-a-quick-look/

We take a look at the Silicom P3IMB-M-P2. This is an Intel ACC100 card based on eASIC to accelerate a very specific workload

The post This Silicom P3IMB-M-P2 is a Neat Intel ACC100 Card We Take a Quick Look appeared first on ServeTheHome.

Vim 9.2 released

Post Syndicated from corbet original https://lwn.net/Articles/1058744/

Version 9.2 of the
Vim text editor has been released. “Vim 9.2 brings significant
enhancements to the Vim9 scripting language, improved diff mode,
comprehensive completion features, and platform-specific improvements
including experimental Wayland support.
” Also included is a new
interactive tutor mode.

Седмицата (9–14 февруари)

Post Syndicated from Светла Енчева original https://www.toest.bg/sedmitsata-9-14-fevruari/

Седмицата (9–14 февруари)

Бих искала да започна оптимистично. От миналата седмица до тази се случиха поне две изненадващи в позитивен смисъл събития. На 7 февруари за председател на БСП беше избран Крум Зарков. Дали той ще допринесе Столетницата да заприлича поне малко на европейска лява партия (и има ли такива намерения изобщо), или ще бъде изкупителна жертва за провала ѝ, още не знаем. Президентката пък посочи Андрей Гюров за служебен премиер – единствения от „домовата книга“, който не е по един или друг начин свързан с ГЕРБ и/или Пеевски.

На избора на Гюров е посветен и тазседмичният политически коментар на Емилия Милчева. Според нея новият служебен премиер трябва да предприеме три важни стъпки: да предложи правосъден министър, който да се заеме със смяната на узурпиралия поста на главния прокурор Борислав Сарафов, да сложи малко ред в МВР и службите и да реагира адекватно на трагедията „Петрохан“.

Три стъпки на Андрей Гюров
Служебният премиер по дефиниция е временна фигура. В българската политика обаче временните роли често се оказват съдбоносни. Андрей Гюров влиза в кабинета с биография, висящ казус и очаквания. Въпросът е дали ще управлява процеси, или ще трупа още напрежение. От Емилия Милчева.
Седмицата (9–14 февруари)

Изборът на Гюров дава надежда за по-честни избори (от каквито има сметка и доскорошният президент Румен Радев), но пък всякакви реални и имагинерни негативи ще се лепят на ПП–ДБ. Като написах последните думи на предишното изречение, естествено, се сетих за трагедията при Петрохан и Околчица. И се замислих за двойните стандарти.

Случаят се използва за демонизиране на ПП–ДБ и призиви за оставка на кмета на София Васил Терзиев, защото е бил дарител на организацията на Ивайло Калушев, без да има данни някой, свързан с коалицията, да е знаел за случаи на секс с непълнолетни в групата около Калушев (но пък има данни ДАНС да е назнайвала нещо).

Впрочем какво става с делото за сексуалното посегателство върху 4-годишно момиченце на учителка в детската градина в Каблешково? Припомням, че кметът на Поморие Иван Алексиев – от ГЕРБ – публично защити учителката и обвини родителите ѝ, след като вече имаше достатъчно смущаващи данни за възможно насилие. Прави ли ви впечатление, че този скандал не се лепна на ГЕРБ, а потъна?

Всички сме зациклили около случая „Петрохан“, но кой, ако не Павлина Върбанова ще погледне на темата езиковедски? Замисляте ли се, че хижата е „Петрохан“ – с кавички, а проходът – Петрохан? А (което изглежда още по-странно) гара Подуяне и автогара „Подуяне“? Павлина разяснява някои от чудатите правила за поставяне и непоставяне на кавички.

В тесния проход на кавичките
Любимите на много от нас кавички не са пунктуационна брошка, с която да закичим текстовете си, когато и където ни скимне. Тази седмица Павлина Върбанова строго и методично ни превежда през тесния и често пъти мъглив проход на решението кога да ги забодем на словесния ревер.
Седмицата (9–14 февруари)

Понеже и аз още цикля на петроханската тема, се връщам към проблема за двойните стандарти. Разбрахме, че будизмът и „сектите“ са много страшни. А в затворени християнски общности няма ли сексуална злоупотреба с деца? Католическата църква поне се опитва да поеме някаква отговорност за дългогодишните практики на сексуално насилие върху малолетни и непълнолетни.

За случващото се в Българската православна църква не се знае много. Но през 2009 г. величкият епископ Сионий напусна Семинарията в София, на която е ректор, след като родител на ученик в духовното училище е подал срещу него сигнал за сексуална злоупотреба с момчето. На Сионий не само му се даде думата да се защитава в медиите. През 2014 г. националисти, със специалното съдействие на Мартин Карбовски, „прочистиха“, по собствените им думи, Троянския манастир от „хомосексуалисти“. Кой беше новият игумен на манастира, съдействал за „прочистването“? Сионий. Въпреки че срещу него има и друго свидетелство за сексуални посегателства, той не само не е разследван или поне отстранен, ами между 2019 и 2025 г. е единственият духовник в БПЦ досега, който е игумен не на един, а на два манастира наведнъж.

За да отсяваме зърното от плявата, имаме нужда от качествена журналистика. В първата си статия за „Тоест“ Дарина Сарелска обяснява защо тя е дефицитна в България. Разказът ѝ е суров, ненапудрен, безрадостен и според мен – задължителен за четене. С нетърпение очаквам следващите ѝ публикации.

„Няма места.“ Журналистиката след журналистите
Ако се чудите какво стана с медиите в България, този текст ви е напълно достатъчен, за да си дадете отговори на много въпроси. А иначе, вие въпроси може и да си задавате, но в много медии у нас вече няма кой да ги задава – гледайте какво нещо… Защо стана така – от Дарина Сарелска.
Седмицата (9–14 февруари)

В настоящата ситуация на информационни плаващи пясъци опирането на науката е все по-голяма рядкост. Гледахте ли разговора на Владислав Севов с автора на рубриката „Научни новини“ в „Тоест“ Михаил Ангелов? Ако не, може да наваксате:

Освен че не е любител на науката, Доналд Тръмп е и враг на всичко, което не му изнася, и вместо неудобни факти предпочита да вижда фалшива реалност. В новия брой на бюлетина си „Гласовете на Америка“ Йоанна Елми разказва за измеренията, до които стига паралелната реалност на властта в САЩ.

Гласовете на Америка – брой 12
Когато новините идват като картечен откос, човек започва да се чуди това новини ли са, или организирана подмяна на реалността. Йоанна Елми с нещо като хроника на ускорението в месечния бюлетин, посветен на Америка.
Седмицата (9–14 февруари)

В рамките на година една широко разпространена дума се обезсмисли, или поне значението ѝ силно се стесни. Това е прилагателното име „евроатлантически“. Променените позиции на САЩ по отношение на международната сигурност поставят ЕС пред изпитание. Според Анахит Хачикян отношенията между доскорошните близки съюзници може да се сравнят със заглавието на песента на Серж Генсбур и Джейн Бъркин Je t’aime… moi non plus.

ЕС и САЩ: Je t’aime… moi non plus
Отношенията между ЕС и САЩ, видени през погледа на Анахит Хачикян, все повече навяват асоциации за заглавието на песента на Серж Генсбур и Джейн Бъркин Je t’aime… moi non plus – игра на думи, която може да се преведе като „Обичам те… аз теб също/вече не“. Къде ще е България в новата реалност?
Седмицата (9–14 февруари)

И като минахме на любовна вълна – днес е Свети Валентин. Докато се чудя с каква песен да ви поздравя по този повод, се замислих, че има и хора, които нямат какво или с кого да празнуват, както и такива, които просто не харесват този празник. Затова се опитах да подбера за всеки по нещо (е, почти за всеки, защото – по Толстой – всеки е нещастен посвоему):

Ако сте с разбито сърце – любовта убива, пее Фреди Меркюри в саундтрака на Джорджо Мородер към филма на Фриц Ланг „Метрополис“. Ако точно днес любимият ви човек не е с вас, на помощ идват Love с песен за самотата във връзката. Но ето, Глория Гейнър се притичва, за да ни напомни, че раздялата може да се преживее. А духът на Мишел Фуко, въплътен в Майли Сайръс, ни обръща внимание колко важна е любовта към себе си.

Ако пък днес празнувате и вярвате в щастливата любов, Lovesong на The Cure е точно за вас. Робърт Смит я е посветил на годеницата си Мери в края на 80-те. Двамата се запознават на 14-годишна възраст, значи някъде около 1973-та, и вече повече от 50 години са заедно.

А може би не зачитате Свети Валентин, а Трифон Зарезан. И лирическият герой на Lovestruck на Madness обича чашката, което води до… влюбване в улична лампа. В случай че до никаква любов не ви е – кой може да изпее по-нелюбовна песен от Джони Ротън?

Ако искате да изслушате всички тези песни, подредила съм ви ги в плейлист:

Пък ако обичате „Тоест“ и ни подкрепите с месечно дарение, ще ни помогнете да продължаваме да ви отвръщаме със същото.

The collective thoughts of the interwebz