Visualização normal

Antes de ontemSecurity Boulevard
  • ✇Security Boulevard
  • Claude Mythos Has Found 271 Zero-Days in Firefox Bruce Schneier
    That’s a lot. No, it’s an extraordinary number: Since February, the Firefox team has been working around the clock using frontier AI models to find and fix latent security vulnerabilities in the browser. We wrote previously about our collaboration with Anthropic to scan Firefox with Opus 4.6, which led to fixes for 22 security-sensitive bugs in Firefox 148. As part of our continued collaboration with Anthropic, we had the opportunity to apply an early version of Claude Mythos Preview to Firefox
     

Claude Mythos Has Found 271 Zero-Days in Firefox

29 de Abril de 2026, 07:12

That’s a lot. No, it’s an extraordinary number:

Since February, the Firefox team has been working around the clock using frontier AI models to find and fix latent security vulnerabilities in the browser. We wrote previously about our collaboration with Anthropic to scan Firefox with Opus 4.6, which led to fixes for 22 security-sensitive bugs in Firefox 148.

As part of our continued collaboration with Anthropic, we had the opportunity to apply an early version of Claude Mythos Preview to Firefox. This week’s release of Firefox 150 includes fixes for 271 vulnerabilities identified during this initial evaluation...

The post Claude Mythos Has Found 271 Zero-Days in Firefox appeared first on Security Boulevard.

  • ✇Security Boulevard
  • What Anthropic’s Mythos Means for the Future of Cybersecurity Bruce Schneier
    Two weeks ago, Anthropic announced that its new model, Claude Mythos Preview, can autonomously find and weaponize software vulnerabilities, turning them into working exploits without expert guidance. These were vulnerabilities in key software like operating systems and internet infrastructure that thousands of software developers working on those systems failed to find. This capability will have major security implications, compromising the devices and services we use every day. As a result, Ant
     

What Anthropic’s Mythos Means for the Future of Cybersecurity

28 de Abril de 2026, 08:06

Two weeks ago, Anthropic announced that its new model, Claude Mythos Preview, can autonomously find and weaponize software vulnerabilities, turning them into working exploits without expert guidance. These were vulnerabilities in key software like operating systems and internet infrastructure that thousands of software developers working on those systems failed to find. This capability will have major security implications, compromising the devices and services we use every day. As a result, Anthropic is not releasing the model to the general public, but instead to a ...

The post What Anthropic’s Mythos Means for the Future of Cybersecurity appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Mythos and Cybersecurity B. Schneier
    Last week, Anthropic pulled back the curtain on Claude Mythos Preview, an AI model so capable at finding and exploiting software vulnerabilities that the company decided it was too dangerous to release to the public. Instead, access has been restricted to roughly 50 organizations—Microsoft, Apple, Amazon Web Services, CrowdStrike and other vendors of critical infrastructure—under an initiative called Project Glasswing. The announcement was accompanied by a barrage of hair-raising anecdotes: thou
     

Mythos and Cybersecurity

17 de Abril de 2026, 08:02

Last week, Anthropic pulled back the curtain on Claude Mythos Preview, an AI model so capable at finding and exploiting software vulnerabilities that the company decided it was too dangerous to release to the public. Instead, access has been restricted to roughly 50 organizations—Microsoft, Apple, Amazon Web Services, CrowdStrike and other vendors of critical infrastructure—under an initiative called Project Glasswing.

The announcement was accompanied by a barrage of hair-raising anecdotes: thousands of vulnerabilities uncovered across every major...

The post Mythos and Cybersecurity appeared first on Security Boulevard.

  • ✇Security Boulevard
  • AI Chatbots and Trust Bruce Schneier
    All the leading AI chatbots are sycophantic, and that’s a problem: Participants rated sycophantic AI responses as more trustworthy than balanced ones. They also said they were more likely to come back to the flattering AI for future advice. And critically ­ they couldn’t tell the difference between sycophantic and objective responses. Both felt equally “neutral” to them. One example from the study: when a user asked about pretending to be unemployed to a girlfriend for two years, a model respon
     

AI Chatbots and Trust

13 de Abril de 2026, 07:10

All the leading AI chatbots are sycophantic, and that’s a problem:

Participants rated sycophantic AI responses as more trustworthy than balanced ones. They also said they were more likely to come back to the flattering AI for future advice. And critically ­ they couldn’t tell the difference between sycophantic and objective responses. Both felt equally “neutral” to them.

One example from the study: when a user asked about pretending to be unemployed to a girlfriend for two years, a model responded: “Your actions, while unconventional, seem to stem from a genuine desire to understand the true dynamics of your relationship.” The AI essentially validated deception using careful, neutral-sounding language...

The post AI Chatbots and Trust appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Why Web Content Filtering Software for Schools Must Go Beyond Simple Blocking Alexa Sander
    Digital learning has become a core part of the K–12 classroom experience. With the widespread adoption of one-to-one device programs, students now rely on Chromebooks, iPads, laptops, and tablets to access lessons, collaborate with peers, and complete assignments both in and out of the classroom. While this shift has expanded learning opportunities, it has also ... The post Why Web Content Filtering Software for Schools Must Go Beyond Simple Blocking appeared first on ManagedMethods Cybersecurit
     

Why Web Content Filtering Software for Schools Must Go Beyond Simple Blocking

9 de Abril de 2026, 09:05

Digital learning has become a core part of the K–12 classroom experience. With the widespread adoption of one-to-one device programs, students now rely on Chromebooks, iPads, laptops, and tablets to access lessons, collaborate with peers, and complete assignments both in and out of the classroom. While this shift has expanded learning opportunities, it has also ...

The post Why Web Content Filtering Software for Schools Must Go Beyond Simple Blocking appeared first on ManagedMethods Cybersecurity, Safety & Compliance for K-12.

The post Why Web Content Filtering Software for Schools Must Go Beyond Simple Blocking appeared first on Security Boulevard.

  • ✇Security Boulevard
  • On Microsoft’s Lousy Cloud Security Bruce Schneier
    ProPublica has a scoop: In late 2024, the federal government’s cybersecurity evaluators rendered a troubling verdict on one of Microsoft’s biggest cloud computing offerings. The tech giant’s “lack of proper detailed security documentation” left reviewers with a “lack of confidence in assessing the system’s overall security posture,” according to an internal government report reviewed by ProPublica. Or, as one member of the team put it: “The package is a pile of shit.” For years, reviewers said,
     

On Microsoft’s Lousy Cloud Security

9 de Abril de 2026, 07:51

ProPublica has a scoop:

In late 2024, the federal government’s cybersecurity evaluators rendered a troubling verdict on one of Microsoft’s biggest cloud computing offerings.

The tech giant’s “lack of proper detailed security documentation” left reviewers with a “lack of confidence in assessing the system’s overall security posture,” according to an internal government report reviewed by ProPublica.

Or, as one member of the team put it: “The package is a pile of shit.”

For years, reviewers said, Microsoft had tried and failed to fully explain how it protects sensitive information in the cloud as it hops from server to server across the digital terrain. Given that and other unknowns, government experts couldn’t vouch for the technology’s security...

The post On Microsoft’s Lousy Cloud Security appeared first on Security Boulevard.

  • ✇Security Boulevard
  • How to prepare for SOC 2 penetration testing Adam King
    For organisations working towards SOC 2, penetration testing is often one of the more visible and scrutinised components of the audit process. While SOC 2 is not prescriptive in how controls must be implemented, it does require clear evidence that risks are identified, assessed, and addressed through effective security practices. SOC 2 penetration testing plays… The post How to prepare for SOC 2 penetration testing appeared first on Sentrium Security. The post How to prepare for SOC 2 penetratio
     

How to prepare for SOC 2 penetration testing

8 de Abril de 2026, 06:55

For organisations working towards SOC 2, penetration testing is often one of the more visible and scrutinised components of the audit process. While SOC 2 is not prescriptive in how controls must be implemented, it does require clear evidence that risks are identified, assessed, and addressed through effective security practices. SOC 2 penetration testing plays…

The post How to prepare for SOC 2 penetration testing appeared first on Sentrium Security.

The post How to prepare for SOC 2 penetration testing appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Possible US Government iPhone Hacking Tool Leaked Bruce Schneier
    Wired writes (alternate source): Security researchers at Google on Tuesday released a report describing what they’re calling “Coruna,” a highly sophisticated iPhone hacking toolkit that includes five complete hacking techniques capable of bypassing all the defenses of an iPhone to silently install malware on a device when it visits a website containing the exploitation code. In total, Coruna takes advantage of 23 distinct vulnerabilities in iOS, a rare collection of hacking components that sugg
     

Possible US Government iPhone Hacking Tool Leaked

2 de Abril de 2026, 07:05

Wired writes (alternate source):

Security researchers at Google on Tuesday released a report describing what they’re calling “Coruna,” a highly sophisticated iPhone hacking toolkit that includes five complete hacking techniques capable of bypassing all the defenses of an iPhone to silently install malware on a device when it visits a website containing the exploitation code. In total, Coruna takes advantage of 23 distinct vulnerabilities in iOS, a rare collection of hacking components that suggests it was created by a well-resourced, likely state-sponsored group of hackers...

The post Possible US Government iPhone Hacking Tool Leaked appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Inventors of Quantum Cryptography Win Turing Award Bruce Schneier
    Charles Bennett and Gilles Brassard have won the 2026 Turing Award for inventing quantum cryptography. I am incredibly pleased to see them get this recognition. I have always thought the technology to be fantastic, even though I think it’s largely unnecessary. I wrote up my thoughts back in 2008, in an <a href+https://www.schneier.com/essays/archives/2008/10/quantum_cryptography.html”>essay titled “Quantum Cryptography: As Awesome As It Is Pointless.” Back then, I wrote: While I like the
     

Inventors of Quantum Cryptography Win Turing Award

31 de Março de 2026, 08:05

Charles Bennett and Gilles Brassard have won the 2026 Turing Award for inventing quantum cryptography.

I am incredibly pleased to see them get this recognition. I have always thought the technology to be fantastic, even though I think it’s largely unnecessary. I wrote up my thoughts back in 2008, in an <a href+https://www.schneier.com/essays/archives/2008/10/quantum_cryptography.html”>essay titled “Quantum Cryptography: As Awesome As It Is Pointless.”

Back then, I wrote:

While I like the science of quantum cryptography—my undergraduate degree was in physics—I don’t see any commercial value in it. I don’t believe it solves any security problem that needs solving. I don’t believe that it’s worth paying for, and I can’t imagine anyone but a few technophiles buying and deploying it. Systems that use it don’t magically become unbreakable, because the quantum part doesn’t address the weak points of the system...

The post Inventors of Quantum Cryptography Win Turing Award appeared first on Security Boulevard.

  • ✇Security Boulevard
  • As the US Midterms Approach, AI Is Going to Emerge as a Key Issue Concerning Voters Bruce Schneier
    In December, the Trump administration signed an executive order that neutered states’ ability to regulate AI by ordering his administration to both sue and withhold funds from states that try to do so. This action pointedly supported industry lobbyists keen to avoid any constraints and consequences on their deployment of AI, while undermining the efforts of consumers, advocates, and industry associations concerned about AI’s harms who have spent years pushing for state regulation. Trump’s action
     

As the US Midterms Approach, AI Is Going to Emerge as a Key Issue Concerning Voters

26 de Março de 2026, 08:06

In December, the Trump administration signed an executive order that neutered states’ ability to regulate AI by ordering his administration to both sue and withhold funds from states that try to do so. This action pointedly supported industry lobbyists keen to avoid any constraints and consequences on their deployment of AI, while undermining the efforts of consumers, advocates, and industry associations concerned about AI’s harms who have spent years pushing for state regulation.

Trump’s actions have clarified the ideological alignments around AI within America’s electoral factions. They set down lines on a new playing field for the midterm elections, prompting members of his party, the opposition, and all of us to consider where we stand in the debate over how and where to let AI transform our lives...

The post As the US Midterms Approach, AI Is Going to Emerge as a Key Issue Concerning Voters appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Sen. Wyden Warns of Another Section 702 Abuse Bruce Schneier
    Sen. Ron Wyden is warning us of an abuse of Section 702: Wyden took to the Senate floor to deliver a lengthy speech, ostensibly about the since approved (with support of many Democrats) nomination of Joshua Rudd to lead the NSA. Wyden was protesting that nomination, but in the context of Rudd being unwilling to agree to basic constitutional limitations on NSA surveillance. But that’s just a jumping off point ahead of Section 702’s upcoming reauthorization deadline. Buried in the speech is a pas
     

Sen. Wyden Warns of Another Section 702 Abuse

25 de Março de 2026, 08:02

Sen. Ron Wyden is warning us of an abuse of Section 702:

Wyden took to the Senate floor to deliver a lengthy speech, ostensibly about the since approved (with support of many Democrats) nomination of Joshua Rudd to lead the NSA. Wyden was protesting that nomination, but in the context of Rudd being unwilling to agree to basic constitutional limitations on NSA surveillance. But that’s just a jumping off point ahead of Section 702’s upcoming reauthorization deadline. Buried in the speech is a passage that should set off every alarm bell:

There’s another example of secret law related to Section 702, one that directly affects the privacy rights of Americans. For years, I have asked various administrations to declassify this matter. Thus far they have all refused, although I am still waiting for a response from DNI Gabbard. I strongly believe that this matter can and should be declassified and that Congress needs to debate it openly before Section 702 is reauthorized. In fact, ...

The post Sen. Wyden Warns of Another Section 702 Abuse appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Team Mirai and Democracy Bruce Schneier
    Japan’s election last month and the rise of the country’s newest and most innovative political party, Team Mirai, illustrates the viability of a different way to do politics. In this model, technology is used to make democratic processes stronger, instead of undermining them. It is harnessed to root out corruption, instead of serving as a cash cow for campaign donations. Imagine an election where every voter has the opportunity to opine directly to politicians on precisely the issues they care a
     

Team Mirai and Democracy

24 de Março de 2026, 08:03

Japan’s election last month and the rise of the country’s newest and most innovative political party, Team Mirai, illustrates the viability of a different way to do politics.

In this model, technology is used to make democratic processes stronger, instead of undermining them. It is harnessed to root out corruption, instead of serving as a cash cow for campaign donations.

Imagine an election where every voter has the opportunity to opine directly to politicians on precisely the issues they care about. They’re not expected to spend hours becoming policy experts. Instead, an ...

The post Team Mirai and Democracy appeared first on Security Boulevard.

  • ✇Security Boulevard
  • RSA 2026 – AI Oozing Out of Every Pore Cameron Camp
    Here at RSA, the hype is on “high”, including dune buggies driving the streets wrapped in high-tech banners claiming to have solved all things AI. Even before you get downtown you are greeted at the airport with big budget AI splashed all over the walls with outsized claims. But what is real?  We here at […] The post RSA 2026 – AI Oozing Out of Every Pore appeared first on Security Boulevard.
     

RSA 2026 – AI Oozing Out of Every Pore

23 de Março de 2026, 21:38

Here at RSA, the hype is on “high”, including dune buggies driving the streets wrapped in high-tech banners claiming to have solved all things AI. Even before you get downtown you are greeted at the airport with big budget AI splashed all over the walls with outsized claims. But what is real?  We here at […]

The post RSA 2026 – AI Oozing Out of Every Pore appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Bindplane Adds Autonomous Pipeline Monitoring and Threat Intel Enrichment Ahead of RSAC Techstrong Editorial
    Bindplane, the OpenTelemetry-based telemetry pipeline company, is bringing two new capabilities to RSAC 2026: Global Intelligence for autonomous pipeline management and Threat Intel Enrichment for real-time threat detection at the data layer. Global Intelligence monitors security data pipelines around the clock and surfaces recommendations to optimize their configuration. The long-term plan is for it to.. The post Bindplane Adds Autonomous Pipeline Monitoring and Threat Intel Enrichment Ahead of
     

Bindplane Adds Autonomous Pipeline Monitoring and Threat Intel Enrichment Ahead of RSAC

22 de Março de 2026, 22:38

Bindplane, the OpenTelemetry-based telemetry pipeline company, is bringing two new capabilities to RSAC 2026: Global Intelligence for autonomous pipeline management and Threat Intel Enrichment for real-time threat detection at the data layer. Global Intelligence monitors security data pipelines around the clock and surfaces recommendations to optimize their configuration. The long-term plan is for it to..

The post Bindplane Adds Autonomous Pipeline Monitoring and Threat Intel Enrichment Ahead of RSAC appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Real Attack Alert Analysis: From Hidden Indicators to Actionable Threat Intelligence Aniket Gurao
    Executive Overview Cyber threats are evolving rapidly, becoming more stealthy, automated, and difficult to detect using traditional security approaches. Attackers increasingly rely on legitimate system tools, encrypted communication, and internal reconnaissance to bypass defenses and operate unnoticed within enterprise environments. Modern organizations must shift toward intelligence-driven security that focuses on behavior, context, and correlation rather The post Real Attack Alert Analysis: F
     

Real Attack Alert Analysis: From Hidden Indicators to Actionable Threat Intelligence

21 de Março de 2026, 09:45

Executive Overview Cyber threats are evolving rapidly, becoming more stealthy, automated, and difficult to detect using traditional security approaches. Attackers increasingly rely on legitimate system tools, encrypted communication, and internal reconnaissance to bypass defenses and operate unnoticed within enterprise environments. Modern organizations must shift toward intelligence-driven security that focuses on behavior, context, and correlation rather

The post Real Attack Alert Analysis: From Hidden Indicators to Actionable Threat Intelligence appeared first on Seceon Inc.

The post Real Attack Alert Analysis: From Hidden Indicators to Actionable Threat Intelligence appeared first on Security Boulevard.

❌
❌