Remote
Metacurity
@metacurity@infosec.exchange
Metacurity.com (https://metacurity.com) is the one-stop destination for leading infosec news and cybersecurity developments. Run by infosec writer and columnist Cynthia Brumfield, Metacurity draws from thousands of sources every day to deliver aggregated summaries of the latest infosec developments. If anyone wants to get in touch with me, on or off the record, you can reach me at cynthia [at] digitalcrazytown.com or on Signal via Cynthia.507. Sign up for our free daily emails at https://www.metacurity.com. Searchable
4821 Followers
1023 Following
50 Posts
Joined October 28, 2022
Metacurity:
The NIST 2.0 Cybersecurity Framework:
Cynthia's Personal Ramblings:
Replying to
@annehargreaves@ioc.exchange @Gargron@mastodon.social It says they are in lockstep with the rest of the tech industry, sadly.
Open post
OpenAI delaying IPO amid AI safety concerns, Sam Altman says
https://www.axios.com/2026/09/12/openai-public-ipo-delay-sam-altman?stream=top&utm_source=alert&utm_medium=email&utm_campaign=alerts_all
2
0
1
0
Open post
Replying to
@wordshaper@weatherishappening.network Here's the thing too -- there is no way at this point to stop China's AI just as there has been no way to halt so many of China's industrial and technological advancements that have cleaned US clocks.
1
2
0
0
Open post
Replying to
@wordshaper@weatherishappening.network @flyingpenguin@infosec.exchange I would like to write a piece about the quasi-religious/cult nature of these dudes. It's pretty awful from a societal perspective but also fascinating.
1
1
0
0
Open post
An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang
https://www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/
1
0
0
0
Open post
Each Saturday, Metacurity puts out an infosec long-reads issue that covers pieces we couldn't get to during the crush of breaking news.
https://www.metacurity.com/trust-under-pressure-best-infosec-long-reads-8-8-26/
They're all worth reading, but in an unusual move, I want to flag my two favorites.
First, Toronto Life's Malcom Johnston proves that the envious couple in the upscale suburb might very well be multi-million-dollar phone scammers.
https://torontolife.com/deep-dives/the-phone-scammers-next-door/?utm_medium=email&utm_source=ten_tabs&utm_campaign=&position=4&category=fascinating_stories&scheduled_corpus_item_id=86bf5c63-8cf8-4cc3-9979-c369096e6d30&url=https%3A%2F%2Ftorontolife.com%2Fdeep-dives%2Fthe-phone-scammers-next-door%2F
Next, MIT Tech Review's Eileen Guo, along with writers Gisela Perez de Acha and Martin Sona, document how the lie that the US government had a censorship-industrial complex was fevered fiction concocted by a handful of right-wing conspiracists.
https://www.technologyreview.com/2026/08/07/1141105/how-ideas-of-a-vast-censorship-network-moved-from-the-online-fringe-to-trump-policy/
4
2
2
0
Open post
Each week, Metacurity offers our readers a rundown of the top infosec long-reads we couldn't do justice to amid the frenetic crush of daily news.
This week's selection covers
--The hacker who humbled spyware makers,
--China's new AI playbook,
--Do AI models really reason?
--The hidden danger of side-channel attacks,
--Inside Anthropic's legal battle
https://www.metacurity.com/power-plays-in-ai-and-cybersecurity-best-infosec-long-reads-8-1-26/
2
0
3
0
Open post
"[Northwestern University], which already has a popular AI minor, is adding an AI major. It’s also streamlining prerequisites to make it easier for nonmajors to take an AI or machine learning class."
https://apnews.com/article/college-major-ai-computer-science-coding-f0dca8e4f7e16297ad27c2b02adc2530
0
0
0
0
Open post
“Organizations should assume that public and hospitality network infrastructure might not be trustworthy,” Microsoft warned Friday.
https://www.forbes.com/sites/zakdoffman/2026/08/01/microsoft-issues-hotel-wi-fi-warning-for-windows-pc-users/
0
0
0
0
Open post
Check out my latest CSO piece, which delves into why, amid all the AI razzamatazz, plain old cybersecurity fundamentals are more important than ever.
Thanks to Eric Brandwine of AWS, Diana Kelley of Noma Security, Gene Spafford of Purdue, Chris Betz of Google Cloud, John Shier of Sophos, Adam Meyers of CrowdStrike, Tony Sager of CIS, Scott Beale of ICS2, and cyber researcher Roger Grimes for their insights.
https://www.csoonline.com/article/4204101/ai-is-making-cybersecurity-fundamentals-more-important-than-ever.html
0
0
0
0
Open post
"A security weakness in the technology used by most of the nation’s crime labs to analyze DNA evidence exposed 30 years of crime files to the risk of being hacked, according to a group of forensic and computer scientists."
https://www.wsj.com/tech/cybersecurity/security-flaw-placed-30-years-of-dna-evidence-at-risk-of-hacking-1932775a?st=zGgyGg&reflink=desktopwebshare_permalink
0
0
0
0
Open post
Anthropic opens its most powerful AI models to more security teams
https://www.reuters.com/legal/litigation/anthropic-opens-its-most-powerful-ai-models-more-security-teams-2026-10-06/
0
0
0
0
Open post
Replying to
@samueljohnson@mstdn.social you know I thought about that but they were also envious and wanting to live the high life. I think both apply but you’re right.
0
0
0
0
Open post
Last night's John Oliver main segment is right up our alley.
https://www.youtube.com/watch?v=lnBPhelCdWE
Police Surveillance Technology: Last Week Tonight with John Oliver (HBO)
0
0
0
0
Open post
Chinese telecom firms kept footholds in US networks despite federal crackdowns, House probe finds
https://www.nextgov.com/cybersecurity/2026/08/chinese-telecom-firms-kept-footholds-us-networks-despite-federal-crackdowns-house-probe-finds/415190/
0
0
0
0
Open post
Here we go again
OpenAI to limit access to Astra's most powerful cyber tools
https://www.axios.com/2026/09/01/openai-astras-cyber-critical?stream=technology&utm_source=alert&utm_medium=email&utm_campaign=alerts_technology
0
1
1
0
Open post
“It was moving really fast, and very, very, massively parallel,” Thomas Wolf, Hugging Face’s chief science officer, told me.
No one at the firm had ever seen an attack like this. Wolf, narrating the action, sounded as if he were describing an encounter with a UFO."
https://www.newyorker.com/news/the-lede/inside-openai-hack-of-hugging-face?mid=1#cid=3644688
0
0
0
0
Open post
Don't miss today's Metacurity for the latest on how Washington is taking giant steps to address AI security, along with other critical infosec developments you should know, including
--White House AI testing framework arrives, but key details remain secret,
--Congress probes OpenAI incident as calls for stronger AI oversight grow,
--China's open AI push fuels geopolitical debate,
--Banks press ahead with AI agents,
--US eyes China data center tech ban,
--Apple renews legal fight over UK encryption demands,
--Telegram mysteriously disappears from Apple's App Store,
--Malware can hijack Google passkeys,
--N-able warns of active attacks exploiting N-central flaw,
--Samsung pulls smart TV apps that turned homes into proxy networks,
--River Bank says stolen ransomware data was deleted by attackers,
--Congress moves to extend lifetime identity protection for OPM victims,
--AI now powers most cybercrime in Africa,
--State CISOs report falling confidence amid rising AI threats,
--AI agent security startup Zenity raises $125m in Series C,
--Visa buys BioCatch in $2.4b AI fraud defense play,
--Stop being an AI "meat proxy,"
--ICE's expanding digital dragnet raises alarms,
--FBI agent accused of stealing seized cryptocurrency
https://www.metacurity.com/ai-watch-ai-security-moves-to-washingtons-center-stage/
0
0
0
0
Open post
"Hackers have illegally accessed and copied data from Liechtenstein's register of beneficial owners, compromising information relating to about 31,000 companies, foundations and trusts, the principality's government said late on Sunday."
https://www.reuters.com/world/liechtenstein-says-hackers-access-information-31000-legal-entities-2026-08-03/
0
0
0
0
Open post
Thailand is just now considering MFA for its government systems.
Govt eyes stronger cyber defences as data leaks raise alarm
https://www.bangkokpost.com/thailand/general/3299002/govt-eyes-stronger-cyber-defences-as-data-leaks-raise-alarm
0
0
0
0
Open post
English National Ballet suffers customer data hack
https://www.bbc.com/news/articles/cr7km34z112o
0
0
0
0
Open post
ExfilSquad strikes again.
Details of 100,000 police staff leaked on the dark web after hack
https://www.thetimes.com/uk/technology-uk/article/police-officer-details-leaked-exfilsquad-hack-rxx5c575b
0
0
0
0
Open post
Not behind a paywall
The era of AI warfare has arrived
https://www.ft.com/content/686429c0-daf3-42a5-9b7c-7ff06eb291ef?accessToken=zwAAAaFF76C6lM8LRcsBf2JBxdOMSBDEfy4a5s8feLaSQ4lJodO9SJAyUswoL89oZCnA2vNCpdObfH_wbrKR79OO2kEvyu1LMdO97rdvyfO6ggE.MEYCIQDk_nprY5ALiEYBTFI1-MWq-aMUgdqVq04zBBUmMP547QIhAO009JNLGixOg1Opoe8lFRxtiKD3Iu4MhkYbOBjKpHm9&segmentId=7d4bcc2e-e664-92ba-62e3-5590579f1902&syn-25a6b1a6=1
0
0
0
0
Open post
The fact that AI safety testing doesn't bring in cyber pros was the subject of several conversations I had at the Google Cyber Defense Summit yesterday.
Also yesterday, Rob T. Lee of SANS asked for that very same thing to be done
https://robtlee73.substack.com/p/secure-what-is-already-here-doom-scenarios-cybersecurity-aisecurity
0
0
0
0
Open post
Remember the cyberattack on Intoxalock, which makes interlock devices for people with drunken-driving convictions? Some poor dude not only had to shell out $700 to get his car towed, but was also fired from his job for missing work.
https://www.kcrg.com/2026/07/31/federal-lawsuit-against-iowa-ignition-lock-company-paused-amid-cyberattack-investigation/
0
0
0
0
Open post
Open post
The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key
https://www.wired.com/story/defcon-34-badge-baochip-andrew-bunnie-huang/
0
0
0
0
Open post
Iran-linked hackers claim North Texas outage as AT&T points to cable theft
https://www.cbs19.tv/video/news/local/iran-linked-to-cable-theft/501-9d9451ad-6fcb-4825-91ae-01c5b6b72d77
0
0
0
0
Open post
That's quite a price advantage.
"San Francisco-based Artificial Analysis estimated V4-Flash's average cost at 3 cents per test, compared with 86 cents for Kimi K3 from Chinese rival Moonshot AI, $1.86 for OpenAI's GPT-5.6 Sol and $3.15 for Claude Fable 5."
https://www.reuters.com/business/retail-consumer/deepseeks-new-ai-model-is-by-far-cheapest-well-known-models-run-research-firm-2026-08-03/
0
0
0
0
Open post
"In recent months, ICE has deployed a round-the-clock digital dragnet to scour the public internet—from Facebook to Instagram to X—for speech that could endanger the agency’s mission."
https://www.wsj.com/politics/policy/ice-surveillance-internet-critics-e3b22f49?st=WEdxcA
0
0
0
0
Open post
Hugging Face CEO says China is winning the AI race and dominating on open models
https://www.cnbc.com/2026/08/03/hugging-face-china-ai-race-open-models.html
0
0
0
0
Open post
Don't miss today's Metacurity for the most crucial developments cyber defenders should know, including
--OpenAI loosens GPT-5.6 cyber guardrails for vetted defenders,
--Anthropic to watermark Claude output worldwide,
--Gunra ransomware targets critical infrastructure through Fortinet flaws,
--WormGPT creator faces trial in Portugal
--Ransomware disrupts systems at Winnipeg’s largest hospital,
--China-linked hackers exploit N-central flaw to deploy ransomware,
--AI-found Zoom flaws enabled silent device takeovers,
--DEF CON flight hit by hacker WiFi scare,
--LexisNexis takes services offline after suspicious activity,
--NATO, AI startup join ENISA’s CVE program,
--BdThemes supply-chain attack creates rogue WordPress admins,
--Jeju Air breach exposes passenger passport data,
--Adversarial patterns make people and cars invisible to surveillance AI,
--Ceva Logistics hack ripples across retailers and customers,
--New cyber program aims to help small water utilities,
--DeepMind AI team warns applicants its own AI may reject them,
--Hong Kong police bust $800,000 sugar daddy scam,
--Cyber AI startup Corma raises $60m in seed round,
--UK courts ban Meta’s pervert glasses,
--FBI warns hackers are stealing intimate images for sale,
--ICE pays millions for LexisNexis data to feed Palantir
--China’s AI companion crackdown breaks millions of hearts
https://www.metacurity.com/openai-loosens-gpt-5-6-cyber-guardrails-for-vetted-defenders/
0
0
0
0
Open post
Open post
So eight people posed as would-be sugar daddies on a Hong Kong dating website, offering to pay victims HK$50,000 and HK$70,000 a month if they paid a so‑called legal fee in order to receive the money. They earned $6.2 million over two years doing this.
https://news.rthk.hk/rthk/en/component/k2/1865627-20260810.htm?mid=1#cid=3662624
0
0
0
0
Open post
Trump administration drafting ban on Chinese data center devices, sources say
https://www.reuters.com/world/trump-administration-drafting-ban-chinese-data-center-devices-sources-say-2026-08-04/
0
0
0
0
Open post
Wow, before you wrap up for the weekend, don't miss today's Metacurity for the most critical cyber developments you should know, including
--Anthropic becomes the second frontier AI lab to disclose agent breaches,
--Copilot worm spreads through trusted Word documents,
--ExploitGym creators explain how OpenAI's agent escaped,
--Coordinated attacks signal a new threat to water utilities,
--Critical Azure Cosmos DB flaw threatened thousands of customers,
--CrimeStoppers put a bounty on the INC gang,
--AI helps Chrome squash more than 1,000 security bugs,
--Cheap streaming sticks can turn homes into botnets,
--Fake IRS letters target crypto holders with QR-code scam,
--Brinks Home investigates breach claimed by ShinyHunters,
--Coupang ordered to compensate victims of massive data breach,
--DC schools probe breach of summer program data,
--Australia's under-16 social media ban falls short,
--Defcon badge debuts a chip built for trust,
--UK program steers young hackers toward cybersecurity careers,
--Hugging Face tech chief says OpenAI agent hack was all too real,
--Opposition to Flock cameras unites Americans,
--AI is becoming a dating dealbreaker for young Americans
https://www.metacurity.com/anthropic-becomes-the-second-frontier-ai-lab-to-disclose-agent-breaches/
0
0
0
0
Open post
"[H]e came across something called “Dynamic Control Platform for Overseas Personnel.” It was a futuristic dashboard — like something from the movie “Minority Report” — that appeared to track foreigners in the northern Chinese city of Zhangjiakou."
https://www.nytimes.com/2026/08/02/world/asia/china-surveillance-foreigners-database.html?unlocked_article_code=1.2VA.khtF.stlDJiDcjqVJ&smid=nytcore-ios-share
0
0
0
0
Open post
So, @Ron_Fabe tells me that on the heels of the Iranian hacking group Mr. Soul's Telegram channel coming back to life, claiming that Iran attacking water facilities is "fake news," the Iranian hacking group Cyb3rAvengers' Telegram channel has sprung back to life too, with the same message.
0
0
0
0
Open post
Niklas Gruhn coins an excellent new term - meat proxy - for people who blindly copy and paste the output of AI systems to their peers.
https://gruhn.me/blog/2026-08-03/
via Simon Willison https://simonwillison.net/2026/Aug/3/dont-be-a-meat-proxy/
0
0
0
0
Open post
Inside the secretive cyberweapons company that won over Israel’s intelligence elite
https://irpimedia.irpi.eu/en-inside-the-secretive-cyberweapons-company-that-won-over-israels-intelligence-elite/
0
0
0
0
Open post
"Partnered Health has obtained an injunction preventing access to the data itself for any purpose."
https://www.cyberdaily.au/security/13986-exclusive-partnered-health-responds-to-inc-ransom-data-breach-claims
0
0
0
1
Open post
China bogeyman looms large over American firms’ AI doomsday scenario
https://www.theguardian.com/technology/ng-interactive/2026/sep/19/china-ai-foreign-policy-dario-amodei?mid=1#cid=3722814
0
0
0
1
Open post
Replying to on masto.deoan.org
0
0
0
0
Open post
So Korean institutions -- government, private sector, political parties -- treat data breaches the way they should be treated. The latest incident: the Democratic Party of Korea publicly apologized *within 3 days* for a breach exposing data from over 17k members.
https://www.youtube.com/shorts/My1ltsiw0jY
0
0
0
0
Open post
Australia’s privacy tsar warns new laws may be needed for smart glasses
https://www.perthnow.com.au/news/australias-privacy-tsar-warns-new-laws-may-be-needed-for-smart-glasses-c-22691216?mid=1#cid=3658889
0
0
0
0
Open post
https://www.bybit.com/en/press/post/bybit-sues-north-korea-and-lazarus-group-secures-preliminary-injunction-freezing-stolen-assets-in-landmark-crypto-asset-recovery-effort-bb55bb16f1710f487aa
Bybit Sues North Korea and Lazarus Group, Secures Preliminary Injunction Freezing Stolen Assets in Landmark Crypto Asset Recovery Effort
0
0
0
0
Open post
God help us all
Trump to Name AI Czar While Rejecting Safety Risks as a Hoax
https://www.bloomberg.com/news/articles/2026-09-19/trump-to-name-ai-czar-while-rejecting-safety-risks-as-a-hoax
0
0
0
0
Open post
Scam Artists Are Posing as IRS Agents to Drain Crypto Wallets
https://www.bloomberg.com/news/articles/2026-07-30/scam-artists-are-posing-as-irs-agents-to-drain-crypto-wallets
0
0
0
0
Open post
Visa to buy Israeli cyber firm for $2.4 billion to fight AI-driven scams
https://www.timesofisrael.com/visa-to-buy-israeli-cyber-firm-for-2-4-billion-to-fight-ai-driven-scams/?mid=1#cid=3650011
0
0
0
0



