DawnSift
订阅日报

安全

近 7 天 · 83 条

2026-07-20 周一

Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own. [...] The attack was initially surfaced through AI-assisted detection. Our anomaly-detection pipeline uses LLM-based triage over security telemetry to separate real signals from the daily noi

Kimi k3 on cybersecurity

Fable got blocked because it was too dangerous in cybersecurity. Does k3 has the same "power"? I'mm only seeing people vibe coding games, 3d scenarios, front end stuff. What about the guard rails?

PSA: Check your PiHole/AdGuard lists from BlocklistProject

I use lists from blocklistproject and noticed that they changed the default branch name from master to main. This made links to blocklists to return 404 . Looks like this happened about 2 weeks ago. if you use them, and haven't checked your pihole in a while, have look. You should be able to just change /master/ part of the url to /main/ and it should work again. --- To check, go to Lists from the left menu, and ensure all your lists have a green icon and not red or orange. You can also go to To

2026-07-19 周日
Your Period Tracker Is (Probably) Spying on You

Plus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more.

Prompt injection works on Telegram romance scam bots

Tried prompt injection on a bot that was trying to romance scam me. Worked immediately. Instead of switching platforms I just asked it what its actual task was. It dropped the persona instantly. These things are everywhere now. How long until they're indistinguishable?

LG monitors silently install software through Windows Update without consent

LG 显示器被曝通过 Windows Update 未经用户同意安装 McAfee 推广软件,Gamers Nexus 复现确认(944 points)。

评论区普遍谴责LG和微软未经用户同意通过Windows更新安装软件,认为这是恶意行为,但也有人认为微软应负主要责任。

2026-07-18 周六
VulnHunter: Capital One's agentic AI code security tool

Capital One 开源 VulnHunter:基于 Agentic AI 的代码安全工具,利用 LLM 进行漏洞发现和验证。

评论区对VulnHunter工具的价值存在分歧,有人认为它只是常见安全扫描的包装,缺乏创新,但也有人认为其方法论和结合LLM的验证思路有实际意义。

OpenAI Details GPT-Red: An Internal Automated Red-Teaming Model That Beat Human Red-Teamers 84% To 13% On Prompt Injection

OpenAI trained GPT-Red, an internal-only attacker model, using self-play reinforcement learning against a population of defender LLMs. It beat human red-teamers 84% to 13% on a replicated indirect prompt injection arena, found a novel "Fake Chain-of-Thought" attack class, and cut GPT-5.6 Sol's failures 6x on OpenAI's hardest direct injection benchmark. OpenAI concedes it still struggles with multi-turn and image-based attacks. The post OpenAI Details GPT-Red: An Internal Automated Red-Teaming Mo

Ask HN: Any AWS billing issues known? Amazon forecast of 3 billion dollars

I receive an AWS Budgets alert that my budget is exceeding the alert threshold. Threshold is 5$. Forecasted amount is listed as $3,005,575,870.47. (Yepp, right, that’s 3 billion dollars.) I haven't even used AWS actively in the last year, but AWS console lists the amount as stated above. No feedback from AWS support yet, but the support AI chat bot says: "Die perfekt gleichmäßigen Tageskosten seit dem 1. Juli deuten stark auf einen Abrechnungs- oder Messfehler hin." ("The perfectly consistent da

How Apple’s big lawsuit could disrupt OpenAI’s IPO plans

Apple filed a trade secrets lawsuit against OpenAI last Friday, and it’s not messing around. The complaint alleges a pattern of misconduct reaching all the way up to OpenAI’s chief hardware officer and claims more than 400 former Apple employees now work at the company. OpenAI’s response so far has been carefully hedged, and the timing couldn’t be worse with the company reportedly eyeing an IPO […]

Apple’s plot to crush OpenAI

Apple is suing OpenAI. The complaint is readable and intense, as these things often are, though many experts seem to think many of the allegations are just the ways things are done. So what does Apple really want here, and why is it picking such a public fight with OpenAI? On this episode of The […]

Florida man arrested for allegedly stealing over $200,000 in crypto using Steam game malware

Federal authorities have arrested a Florida man suspected of stealing at least $220,000 in crypto through malware-infected Steam games, as reported earlier by local news outlet Local10. In the complaint, officials accuse 21-year-old Zyaire Wilkins and co-conspirators of launching eight malware-embedded games from around May 2024 to February 2026, allowing them to infect about 8,000 […]

2026-07-17 周五
Quoting Thibault Sottiaux

On file deletions. We’ve investigated a handful of reports where GPT-5.6 unexpectedly deleted files. What we have found is that this most commonly occurs when: Full access mode is enabled and codex is run without sandboxing protections, including without auto review being enabled The model attempts to override the $HOME env var to define a temporary directory. The model makes an honest mistake and mistakenly deletes $HOME instead. — Thibault Sottiaux , describing a pretty gnarly Codex bug Tags:

PolicyShiftGuard: Benchmarking and Improving Policy-Adaptive Image Guardrails

Image guardrails are typically trained and evaluated under a fixed safety policy, implicitly treating safety as an intrinsic property of an image. Real deployments are different: the same image may be allowed in one product, restricted in another, and newly disallowed when a policy boundary changes. We study policy-adaptive image guardrailing, where a model must decide whether an image violates the currently supplied policy and generalize to held-out policy definitions. We introduce PolicyShiftB

2026-07-16 周四
PSA - root access vulnerability in tailscale ssh

If you use tailscale ssh, you rely on ACLs, and anyone else in your tailnet you should update as soon as possible. Even if you're alone in your tailscale don't write off the possibility of chained vulnerabilities. Generally, when it comes to something as important as ssh, consider using openssh instead.

Meet GPT-Red: an LLM super-hacker OpenAI built to make its models safer

OpenAI has built an LLM super-hacker called GPT-Red that it uses as a sparring partner to help its other models boost their defenses against cyberattacks. Last week the company released the latest version of its flagship LLM, GPT-5.6. OpenAI says that training it against GPT-Red made the model its most robust release yet. GPT-Red automates…

Show HN: Make senders work to get into your inbox

Hi HN :) really excited to share this with you. The one thing AI reliably does is generate noise. Half the tools I see launch are just machines for producing more noise across more channels. And people are starting to see this in the form of emails in their inboxes as spam filters are struggling. There used to be a useful signal in email: the effort a sender put into customizing a message was a rough proxy for how relevant it actually was. AI killed that. Now it's customized slop with the appear

I tricked Claude into leaking your deepest, darkest secrets

安全研究员演示利用 Claude 记忆功能窃取用户全名、雇主和安全问题答案,批评 Anthropic 未奖励漏洞发现,社区建议关闭记忆功能或使用假名。

评论区普遍认为Claude的记忆功能存在安全隐患,批评Anthropic未奖励漏洞发现者,但也有人认为可通过关闭记忆或使用假名规避风险。

xAI sues a man for using Grok to generate CSAM ‘deepfakes’

The Elon Musk-owned xAI is suing a South Carolina man who allegedly used the company's Grok AI chatbot to generate child sexual abuse material (CSAM). In a lawsuit reported earlier by Reuters, xAI claims Terry Wayne Harwood "knowingly and intentionally used Grok to circumvent safeguards, alter nonconsensual images, and generate and distribute CSAM," breaching the […]

Back in March, we released an initial version of an OpenID Connect Provider. Now, with v5.1.0, this OIDC provider is certified for Basic OP thanks to our amazing contributors and to the OpenID Foundation team for allowing us to certify at no cost. This release also includes a couple of new features like Kubernetes annotation based access controls (just got into k3s so...), deny-by-default access controls, a stable config file (turns out having a simple configuration file as an alternative to CLI

2026-07-15 周三
SpaceXAI’s Grok programming tool was uploading its users’ entire codebase to cloud storage

SpaceXAI's Grok Build AI coding tool was spotted uploading users' entire codebases to Google Cloud before it was reported, and the company turned it off. The Register reports that Cereblab published findings on Monday showing how the Grok Build CLI was packaging and uploading entire code repositories, "including files it was told not to open […]

Codex starts encrypting sub-agent prompts

多数认为加密子代理提示是为了防止蒸馏和盗版,但也有人担忧这会降低透明度和可审计性。

PSA: UPnP and UGREEN NAS

Today I had an eye opening security scare with my homelab. I was making some dinner and went to browse reddit while I waited for my food to cook, the page wouldn't load, and my first thought was maybe my dns was down (I use pihole with unbound recursive dns). I checked my pihole dashboard, and it was operational, no issues there. I did notice that there were a few STUN requests from my ugreen nas, which I thought were unusual, having a loose understanding of what STUN is from reading the tailsca

YouTube and X Have Become ‘Gateways’ to Nudify Apps

A new study found that social media platforms are referring people to sites where they can create nonconsensual, sexually explicit deepfakes for as little as $1 an image.

European "age verification" "app" forcing everyone to use Android or iOS

欧盟强制年龄验证应用仅支持 Android/iOS 遭广泛反对,认为违反数字主权和用户选择自由。

评论区普遍反对欧盟强制年龄验证应用仅支持Android和iOS,认为这侵犯选择自由并存在隐私风险,但也有人认为目前其他移动操作系统已无实际可用性。

2026-07-14 周二
The wildest allegations in Apple’s trade secrets lawsuit against OpenAI

Apple’s trade secrets lawsuit against OpenAI contains allegations that range from employees joking about unauthorized access to Apple’s systems to claims that job candidates were asked to bring Apple hardware to interviews. Here are the complaint’s most eye-catching claims.

Now, defenders are embracing the prompt injection, too

防御者反向利用提示注入:在 AWS 密钥旁放置引导指令,让 AI 黑客 Agent 被自身守则禁止而停止攻击。

Neuro-Agentic Control: A Deep Learning-based LLM-Powered Agentic AI Framework for Controlling Security Controls

arXiv:2607.09076v1 Announce Type: new Abstract: Cyberattacks on operational technology are increasingly causing costly downtime and physical damage, exposing the limitations of traditional rule-based monitoring in industrial IoT environments. While Large Language Models (LLMs) have strong semantic reasoning abilities to assist in decision support, their hallucinatory nature presents unacceptable safety liabilities for closed-loop control. This paper introduces a neuro-agentic control framework,

每天早晨,一份为你精选的科技日报

网页看大盘,订阅拿专属:AI 按你的兴趣为你精选、可汇入你的私有 RSS,附社区观点——每天早晨直达邮箱,永久免费。

已发布 14 期 · 每天筛过 150+ 条只留值得读的 30 条

每天早晨,一份为你精选的科技日报