Posts

Schneier - GPS As a Key Distribution Platform

This is interesting: The U.S. military has likely been quietly broadcasting codes for its global encryption network using public GPS for nearly 20 years, turning each satellite into a hidden “numbers station,” according to Steven Murdoch… That means every device that uses GPS has been receiving hidden government information for years, and nobody outside the military knew it until now. […] Murdoch discovered that this particular sentinel was transmitted by all 31 operational satellites within a window of a few hours on May 26, 2011, potentially heralding the activation of a new operational system. He confirmed that this timeline coincided with the rollout of the military’s Over-the-Air Distribution (OTAD) and the Over-the-Air Rekeying (OTAR) by cross-referencing declassified documents, including a 2015 presentation about the dates of the operation. “There was a perfect match between the timeline and that presentation and the change points that we...

KnowBe4 - CyberheistNews Vol 16 #23 Now Phishing Attacks Use Real Hotel Reservations to Target Travelers

Image
from KnowBe4 Blog https://blog.knowbe4.com/cyberheistnews-vol-16-23-now-phishing-attacks-use-real-hotel-reservations-to-target-travelers

The Hacker News - Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now

Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-11645 (CVSS score: 8.8), has been described as an out-of-bounds memory access in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 from The Hacker News https://thehackernews.com/2026/06/chrome-v8-zero-day-cve-2026-11645.html

The Hacker News - The Hidden Security Risk in Modern Networks: The Work Between Tools

Organizations have more visibility than ever. Growing tech stacks provide greater coverage, and network security teams are increasingly adopting AI and automation to help with routine tasks and reduce manual effort. But the same challenges persist. Outages still last hours, causing significant financial losses, operational disruption, and reputational impact. Threat response and mean time to from The Hacker News https://thehackernews.com/2026/06/the-hidden-security-risk-in-modern.html

The Hacker News - Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19 packages in the Python Package Index (PyPI) registry, as the Mini Shai-Hulud-style attacks continue to be refined and splintered to target specific ecosystems. "The compromised releases shipped a *-setup.pth file that attempts to execute automatically from The Hacker News https://thehackernews.com/2026/06/hades-pypi-attack-19-packages-poisoned.html

HACKMAGEDDON - 16-31 May 2026 Cyber Attacks Timeline

The threat landscape in May H2 2026 was driven by cyber crime and dominated by malware. Exploitation of public-facing app vulnerabilities continued to play an important role, similarly to supply chain attacks. from HACKMAGEDDON https://www.hackmageddon.com/2026/06/09/16-31-may-2026-cyber-attacks-timeline/

The Hacker News - Meta Blocks NSO Group's New WhatsApp Phishing Attack, Files Contempt Order

Meta on Monday said it detected and blocked spear-phishing attempts linked to Israeli spyware vendor NSO Group. In addition, the tech giant said it's filing a federal court contempt order against the company for violating a permanent injunction that barred it from targeting WhatsApp and its users. "They tried to trick people into clicking on malicious links to drive them to external websites from The Hacker News https://thehackernews.com/2026/06/meta-blocks-nso-groups-new-whatsapp.html