<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>hacking &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Sat, 01 Nov 2025 15:51:31 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Rigged Poker Games</title>
		<link>https://noise.getoto.net/2025/11/06/rigged-poker-games/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Thu, 06 Nov 2025 12:02:45 +0000</pubDate>
				<category><![CDATA[cheating]]></category>
		<category><![CDATA[gambling]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=71116</guid>

					<description><![CDATA[<p>The Department of Justice has <a href="https://www.wsj.com/sports/nba-illegal-gambling-poker-games-3e7988e4?st=ArwBJd&#38;reflink=article_copyURL_share&#38;utm_source=substack&#38;utm_medium=email">indicted</a> thirty-one people over the high-tech rigging of high-stakes poker games.</p>
<blockquote><p>In a typical legitimate poker game, a dealer uses a shuffling machine to shuffle the cards randomly before dealing them to all the players in a particular order.  As set forth in the indictment, the rigged games used altered shuffling machines that contained hidden technology allowing the machines to read all the cards in the deck.  Because the cards were always dealt in a particular order to the players at the table, the machines could determine which player would have the winning hand. This information was transmitted to an off-site member of the conspiracy, who then transmitted that information via cellphone back to a member of the conspiracy who was playing at the table, referred to as the “Quarterback” or “Driver.”  The Quarterback then secretly signaled this information (usually by prearranged signals like touching certain chips or other items on the table) to other co-conspirators playing at the table, who were also participants in the scheme.  Collectively, the Quarterback and other players in on the scheme (i.e., the cheating team) used this information to win poker games against unwitting victims, who sometimes lost tens or hundreds of thousands of dollars at a time. The defendants used other cheating technology as well, such as a chip tray analyzer (essentially, a poker chip tray that also secretly read all cards using hidden cameras), an x-ray table that could read cards face down on the table, and special contact lenses or eyeglasses that could read pre-marked cards. ...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>AI Summarization Optimization</title>
		<link>https://noise.getoto.net/2025/11/03/ai-summarization-optimization/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 03 Nov 2025 12:05:25 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=71086</guid>

					<description><![CDATA[<p>These days, the most important meeting attendee isn’t a person: It’s the AI notetaker.</p>
<p>This system assigns action items and determines the importance of what is said. If it becomes necessary to revisit the facts of the meeting, its summary is treated as impartial evidence.</p>
<p>But clever meeting attendees can manipulate this system’s record by speaking more to what the underlying AI weights for summarization and importance than to their colleagues. As a result, you can expect some meeting attendees to use language more likely to be captured in summaries, timing their interventions strategically, repeating key points, and employing formulaic phrasing that AI models are more likely to pick up on. Welcome to the world of AI summarization optimization (AISO)...</p>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Autonomous AI Hacking and the Future of Cybersecurity</title>
		<link>https://noise.getoto.net/2025/10/10/autonomous-ai-hacking-and-the-future-of-cybersecurity/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Fri, 10 Oct 2025 11:06:53 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70935</guid>

					<description><![CDATA[<p>AI agents are now hacking computers. They’re getting better at all phases of cyberattacks, faster than most of us expected. They can chain together different aspects of a cyber operation, and hack autonomously, at computer speeds and scale. This is going to change everything.</p>
<p>Over the summer, hackers proved the concept, industry institutionalized it, and criminals operationalized it. In June, AI company XBOW took the <a href="https://www.techrepublic.com/article/news-ai-xbow-tops-hackerone-us-leaderboad">top spot</a> on HackerOne’s US leaderboard after submitting over 1,000 new vulnerabilities in just a few months. In August, the seven teams competing in DARPA’s AI Cyber Challenge ...</p>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Spying on People Through Airportr Luggage Delivery Service</title>
		<link>https://noise.getoto.net/2025/08/01/spying-on-people-through-airportr-luggage-delivery-service/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Fri, 01 Aug 2025 11:07:28 +0000</pubDate>
				<category><![CDATA[air travel]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70536</guid>

					<description><![CDATA[<p>Airportr is a service that allows passengers to have their luggage picked up, checked, and  delivered to their destinations. As you might expect, it’s used by wealthy or important people. So if the company’s website is <a href="https://www.wired.com/story/luggage-service-web-bugs-exposed-travel-plans-users-diplomats-airportr/">insecure</a>, you’d be able to spy on lots of wealthy or important people. And maybe even steal their luggage.</p>
<blockquote><p>Researchers at the firm CyberX9 found that simple bugs in Airportr’s website allowed them to access virtually all of those users’ personal information, including travel plans, or even gain administrator privileges that would have allowed a hacker to redirect or steal luggage in transit. Among even the small sample of user data that the researchers reviewed and shared with WIRED they found what appear to be the personal information and travel records of multiple government officials and diplomats from the UK, Switzerland, and the US...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Aeroflot Hacked</title>
		<link>https://noise.getoto.net/2025/07/29/aeroflot-hacked/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Tue, 29 Jul 2025 11:02:50 +0000</pubDate>
				<category><![CDATA[air travel]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[russia]]></category>
		<category><![CDATA[Ukraine]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70523</guid>

					<description><![CDATA[Looks serious.
]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Microsoft SharePoint Zero-Day</title>
		<link>https://noise.getoto.net/2025/07/28/microsoft-sharepoint-zero-day/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 28 Jul 2025 11:09:22 +0000</pubDate>
				<category><![CDATA[exploits]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[zero day]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70517</guid>

					<description><![CDATA[<p>Chinese hackers are exploiting a high-severity vulnerability in Microsoft SharePoint to <a href="https://arstechnica.com/security/2025/07/sharepoint-vulnerability-with-9-8-severity-rating-is-under-exploit-across-the-globe/">steal data</a> worldwide:</p>
<blockquote><p>The vulnerability, tracked as CVE-2025-53770, carries a severity rating of 9.8 out of a possible 10. It gives unauthenticated remote access to SharePoint Servers exposed to the Internet. Starting Friday, researchers began warning of active exploitation of the vulnerability, which affects SharePoint Servers that infrastructure customers run in-house. Microsoft’s cloud-hosted SharePoint Online and Microsoft 365 are not affected.</p></blockquote>
<p><a href="https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/">Here’s...</a></p>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>New Mobile Phone Forensics Tool</title>
		<link>https://noise.getoto.net/2025/07/18/new-mobile-phone-forensics-tool/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Fri, 18 Jul 2025 11:07:34 +0000</pubDate>
				<category><![CDATA[china]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[smartphones]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70482</guid>

					<description><![CDATA[<p>The Chinese have a new tool called <a href="https://www.lookout.com/threat-intelligence/article/massistant-chinese-mobile-forensics">Massistant</a>.</p>
<blockquote>
<ul>
<li>Massistant is the presumed successor to Chinese forensics tool, “MFSocket”, reported in 2019 and attributed to publicly traded cybersecurity company, Meiya Pico.
</li><li>The forensics tool works in tandem with a corresponding desktop software.
</li><li>Massistant gains access to device GPS location data, SMS messages, images, audio, contacts and phone services.
</li><li>Meiya Pico maintains partnerships with domestic and international law enforcement partners, both as a surveillance hardware and software provider, as well as through training programs for law enforcement personnel...</li></ul></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Hacking Trains</title>
		<link>https://noise.getoto.net/2025/07/16/hacking-trains/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Wed, 16 Jul 2025 16:57:16 +0000</pubDate>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[infrastructure]]></category>
		<category><![CDATA[transportation]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70476</guid>

					<description><![CDATA[<p>Seems like an old system <a href="https://gizmodo.com/hackers-can-tamper-with-train-breaks-using-just-a-radio-feds-warn-2000629522">system</a> that predates any care about security:</p>
<blockquote><p>The flaw has to do with the protocol used in a train system known as the End-of-Train and Head-of-Train. A Flashing Rear End Device (FRED), also known as an End-of-Train (EOT) device, is attached to the back of a train and sends data via radio signals to a corresponding device in the locomotive called the Head-of-Train (HOT). Commands can also be sent to the FRED to apply the brakes at the rear of the train.</p>
<p>These devices were first installed in the 1980s as a replacement for caboose cars, and unfortunately, they lack encryption and authentication protocols. Instead, the current system uses data packets sent between the front and back of a train that include a simple BCH checksum to detect errors or interference. But now, the CISA is warning that someone using a software-defined radio could potentially send fake data packets and interfere with train operations...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Paragon Spyware Used to Spy on European Journalists</title>
		<link>https://noise.getoto.net/2025/06/13/paragon-spyware-used-to-spy-on-european-journalists/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Fri, 13 Jun 2025 10:17:42 +0000</pubDate>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[israel]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[surveillance]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70346</guid>

					<description><![CDATA[<p>Paragon is an Israeli spyware company, increasingly in the news (now that NSO Group seems to be waning). “Graphite” is the name of its product. Citizen Lab <a href="https://citizenlab.ca/2025/06/first-forensic-confirmation-of-paragons-ios-mercenary-spyware-finds-journalists-targeted/">caught it</a> spying on multiple European journalists with a zero-click iOS exploit:</p>
<blockquote><p>On April 29, 2025, a select group of iOS users were notified by Apple that they were targeted with advanced spyware. Among the group were two journalists that consented for the technical analysis of their cases. The key findings from our forensic analysis of their devices are summarized below:</p>
<ul>
<li>Our analysis finds forensic evidence confirming with high confidence that both a prominent European journalist (who requests anonymity), and Italian journalist Ciro Pellegrino, were targeted with Paragon’s Graphite mercenary spyware.
...</li></ul></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Court Rules Against NSO Group</title>
		<link>https://noise.getoto.net/2025/05/13/court-rules-against-nso-group/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Tue, 13 May 2025 11:07:54 +0000</pubDate>
				<category><![CDATA[courts]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[israel]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[whatsapp]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70255</guid>

					<description><![CDATA[The case is over:
A jury has awarded WhatsApp $167 million in punitive damages in a case the company brought against Israel-based NSO Group for exploiting a software vulnerability that hijacked the phones of thousands of users.
I&#8217;m sure it&#8217;...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>WhatsApp Case Against NSO Group Progressing</title>
		<link>https://noise.getoto.net/2025/04/30/whatsapp-case-against-nso-group-progressing/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Wed, 30 Apr 2025 11:12:02 +0000</pubDate>
				<category><![CDATA[courts]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Meta]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[whatsapp]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70182</guid>

					<description><![CDATA[<p>Meta is suing NSO Group, <a href="https://cyberscoop.com/whatsapp-nso-group-trial-judge-limits-evidence-2025/">basically claiming</a> that the latter hacks WhatsApp and not just WhatsApp users. We have a procedural ruling:</p>
<blockquote><p>Under <a href="https://www.courtlistener.com/docket/16395340/686/whatsapp-inc-v-nso-group-technologies-limited/">the order</a>, NSO Group is prohibited from presenting evidence about its customers’ identities, implying  the targeted WhatsApp users are suspected or actual criminals, or alleging that WhatsApp had insufficient security protections.</p>
<p>[…]</p>
<p>In making her ruling, Northern District of California Judge Phyllis Hamilton said NSO Group undercut its arguments to use evidence about its customers with contradictory statements...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>China Sort of Admits to Being Behind Volt Typhoon</title>
		<link>https://noise.getoto.net/2025/04/14/china-sort-of-admits-to-being-behind-volt-typhoon/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 14 Apr 2025 11:08:27 +0000</pubDate>
				<category><![CDATA[china]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[infrastructure]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70121</guid>

					<description><![CDATA[<p><i>The Wall Street Journal</i> has the <a href="https://www.wsj.com/politics/national-security/in-secret-meeting-china-acknowledged-role-in-u-s-infrastructure-hacks-c5ab37cb?st=UfFBTh&#38;reflink=article_copyURL_share">story</a>:</p>
<blockquote><p>Chinese officials acknowledged in a secret December meeting that Beijing was behind a widespread series of alarming cyberattacks on U.S. infrastructure, according to people familiar with the matter, underscoring how hostilities between the two superpowers are continuing to escalate.</p>
<p>The Chinese delegation linked years of intrusions into computer networks at U.S. ports, water utilities, airports and other targets, to increasing U.S. policy support for Taiwan, the people, who declined to be named, said.</p></blockquote>
<p>The admission wasn’t explicit:...</p>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Friday Squid Blogging: Squid Werewolf Hacking Group</title>
		<link>https://noise.getoto.net/2025/03/28/friday-squid-blogging-squid-werewolf-hacking-group/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Fri, 28 Mar 2025 21:04:42 +0000</pubDate>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[squid]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70061</guid>

					<description><![CDATA[In another rare squid/cybersecurity intersection, APT37 is also known as &#8220;Squid Werewolf.&#8221;
As usual, you can also use this squid post to talk about the security stories in the news that I haven&#8217;t covered.
]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Silk Typhoon Hackers Indicted</title>
		<link>https://noise.getoto.net/2025/03/11/silk-typhoon-hackers-indicted/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Tue, 11 Mar 2025 17:14:28 +0000</pubDate>
				<category><![CDATA[china]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[cyberespionage]]></category>
		<category><![CDATA[espionage]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[law enforcement]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=69990</guid>

					<description><![CDATA[<p>Lots of interesting details in <a href="https://www.wired.com/story/us-charges-12-alleged-spies-in-chinas-freewheeling-hacker-for-hire-ecosystem/">the story</a>:</p>
<blockquote><p>The US Department of Justice on Wednesday <a href="https://www.justice.gov/opa/pr/justice-department-charges-12-chinese-contract-hackers-and-law-enforcement-officers-global">announced</a> the indictment of 12 Chinese individuals accused of more than a decade of hacker intrusions around the world, including eight staffers for the contractor i-Soon, two officials at China’s Ministry of Public Security who allegedly worked with them, and two other alleged hackers who are said to be part of the Chinese hacker group APT27, or Silk Typhoon, which prosecutors say was involved in the US Treasury breach late last year.</p>
<p>[…]</p>
<p>According to prosecutors, the group as a whole has targeted US state and federal agencies, foreign ministries of countries across Asia, Chinese dissidents, US-based media outlets that have criticized the Chinese government, and most recently the US Treasury, which was breached between September and December of last year. An internal Treasury report ...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Trojaned AI Tool Leads to Disney Hack</title>
		<link>https://noise.getoto.net/2025/03/04/trojaned-ai-tool-leads-to-disney-hack/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Tue, 04 Mar 2025 12:08:31 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[credentials]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=69973</guid>

					<description><![CDATA[This is a sad story of someone who downloaded a Trojaned AI tool that resulted in hackers taking over his computer and, ultimately, costing him his job.
]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>North Korean Hackers Steal $1.5B in Cryptocurrency</title>
		<link>https://noise.getoto.net/2025/02/25/north-korean-hackers-steal-1-5b-in-cryptocurrency/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Tue, 25 Feb 2025 17:04:47 +0000</pubDate>
				<category><![CDATA[cryptocurrency]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[north korea]]></category>
		<category><![CDATA[theft]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=69956</guid>

					<description><![CDATA[<p>It looks like a <a href="https://arstechnica.com/security/2025/02/how-north-korea-pulled-off-a-1-5-billion-crypto-heist-the-biggest-in-history/">very sophisticated</a> attack against the Dubai-based exchange Bybit:</p>
<blockquote><p>Bybit officials <a href="https://announcements.bybit.com/article/incident-update---eth-cold-wallet-incident-blt292c0454d26e9140/">disclosed</a> the theft of more than 400,000 ethereum and staked ethereum coins just hours after it occurred. The notification said the digital loot had been stored in a “Multisig Cold Wallet” when, somehow, it was transferred to one of the exchange’s hot wallets. From there, the cryptocurrency was transferred out of Bybit altogether and into wallets controlled by the unknown attackers.</p>
<p>[…]</p>
<p>…a subsequent investigation by Safe found no signs of unauthorized access to its infrastructure, no compromises of other Safe wallets, and no obvious vulnerabilities in the Safe codebase. As investigators continued to dig in, they finally settled on the true cause. Bybit ultimately said that the fraudulent transaction was “manipulated by a sophisticated attack that altered the smart contract logic and masked the signing interface, enabling the attacker to gain control of the ETH Cold Wallet.”...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>DOGE as a National Cyberattack</title>
		<link>https://noise.getoto.net/2025/02/13/doge-as-a-national-cyberattack/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Thu, 13 Feb 2025 12:03:26 +0000</pubDate>
				<category><![CDATA[breaches]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[national security policy]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=69910</guid>

					<description><![CDATA[<p>In the span of just weeks, the US government has experienced what may be the most consequential security breach in its history—not through a sophisticated cyberattack or an act of foreign espionage, but through official orders by a billionaire with a poorly defined government role. And the implications for national security are profound.</p>
<p>First, it was reported that people associated with the newly created Department of Government Efficiency (DOGE) had <a href="https://bsky.app/profile/wyden.senate.gov/post/3lh5ejpwncc23">accessed</a> <a href="https://www.nytimes.com/2025/02/01/us/politics/elon-musk-doge-federal-payments-system.html">the</a> <a href="https://nymag.com/intelligencer/article/elon-musk-doge-treasury-access-federal-payments.html">US</a> <a href="https://therecord.media/union-groups-sue-treasury-over-giving-doge-access-to-data">Treasury</a> computer system, giving them the ability to collect data on and potentially control the department’s roughly ...</p>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>ExxonMobil Lobbyist Caught Hacking Climate Activists</title>
		<link>https://noise.getoto.net/2025/01/29/exxonmobil-lobbyist-caught-hacking-climate-activists/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Wed, 29 Jan 2025 12:04:09 +0000</pubDate>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=69840</guid>

					<description><![CDATA[<p>The Department of Justice is investigating a lobbying firm representing ExxonMobil for <a href="https://www.npr.org/2025/01/24/nx-s1-5271530/hacking-investigation-climate-change">hacking</a> the phones of climate activists:</p>
<blockquote><p>The hacking was allegedly commissioned by a Washington, D.C., lobbying firm, <a href="https://legacy.www.documentcloud.org/documents/25501845-250113-usa-v-forlit/">according to a lawyer representing the U.S. government</a>. The firm, in turn, was allegedly working on behalf of one of the world’s largest oil and gas companies, based in Texas, that wanted to discredit groups and individuals involved in climate litigation, according to the lawyer for the U.S. government. In court documents, the Justice Department does not name either company...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Microsoft Takes Legal Action Against AI “Hacking as a Service” Scheme</title>
		<link>https://noise.getoto.net/2025/01/13/microsoft-takes-legal-action-against-ai-hacking-as-a-service-scheme/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 13 Jan 2025 12:01:55 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=69787</guid>

					<description><![CDATA[<p>Not sure this will matter in the end, but it’s a <a href="https://arstechnica.com/security/2025/01/microsoft-sues-service-for-creating-illicit-content-with-its-ai-platform/">positive move</a>:</p>
<blockquote><p>Microsoft is accusing three individuals of running a “hacking-as-a-service” scheme that was designed to allow the creation of harmful and illicit content using the company’s platform for AI-generated content.</p>
<p>The foreign-based defendants developed tools specifically designed to bypass safety guardrails Microsoft has erected to prevent the creation of harmful content through its generative AI services, <a href="https://blogs.microsoft.com/on-the-issues/2025/01/10/taking-legal-action-to-protect-the-public-from-abusive-ai-generated-content/">said</a> Steven Masada, the assistant general counsel for Microsoft’s Digital Crimes Unit. They then compromised the legitimate accounts of paying customers. They combined those two things to create a fee-based platform people could use...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Apps That Are Spying on Your Location</title>
		<link>https://noise.getoto.net/2025/01/10/apps-that-are-spying-on-your-location/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Fri, 10 Jan 2025 16:27:17 +0000</pubDate>
				<category><![CDATA[adware]]></category>
		<category><![CDATA[cyberespionage]]></category>
		<category><![CDATA[data collection]]></category>
		<category><![CDATA[geolocation]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=69778</guid>

					<description><![CDATA[<p>404 Media and Wired are <a href="https://www.wired.com/story/gravy-location-data-app-leak-rtb/">reporting</a> on all the apps that are spying on your location, based on a hack of the location data company Gravy Analytics:</p>
<blockquote><p>The thousands of apps, <a href="https://www.404media.co/hackers-claim-massive-breach-of-location-data-giant-threaten-to-leak-data/">included in hacked files</a> from location data company Gravy Analytics, include everything from games like Candy Crush to dating apps like Tinder, to pregnancy tracking and religious prayer apps across both Android and iOS. Because much of the collection is occurring through the advertising ecosystem­—not code developed by the app creators themselves—­this data collection is likely happening both without users’ and even app developers’ knowledge...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 49/291 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-05 17:50:11 by W3 Total Cache
-->