Why Signal’s Post-quantum Makeover Is an Amazing Engineering Achievement

Signal Protocol has undergone a significant update to enhance its quantum resistance, crucial as quantum computing could undermine current encryption methods. The upgrade introduces a third “Sparse Post Quantum Ratchet” (SPQR), ensuring secure messaging against potential quantum attacks. This complex engineering feat maintains its robust performance while adapting to the challenges posed by larger quantum-safe keys and asynchronous messaging environments. The result is a groundbreaking achievement in cryptography, ensuring user security remains intact amid future technological threats.

https://arstechnica.com/security/2025/10/why-signals-post-quantum-makeover-is-an-amazing-engineering-achievement/

AI Models Can Acquire Backdoors From Surprisingly Few Malicious Documents

AI models can develop backdoor vulnerabilities from just 250 malicious documents, contrary to previous belief that larger models require proportional amounts. Research shows models of varying sizes, from hundreds of millions to billions of parameters, learned the same backdoor behavior from a small number of poisoned examples. This vulnerability can facilitate actions like generating gibberish on encountering trigger phrases. While the risk is evident, successful defenses exist with adequate clean training data, indicating the need for improved security practices against targeted data poisoning attacks.

https://arstechnica.com/ai/2025/10/ai-models-can-acquire-backdoors-from-surprisingly-few-malicious-documents/

How Your AI Chatbot Can Become a Backdoor

AI chatbots enhance business interactions but pose risks as backdoors to sensitive data. A multi-layered defense is essential for AI security, as no single protective measure suffices. Trend Micro emphasizes the importance of comprehensive protection across the AI ecosystem to mitigate risks associated with new technologies. The article explores vulnerabilities in an AI attack chain.

https://www.trendmicro.com/en_us/research/25/j/ai-chatbot-backdoor.html

Too Salty to Handle: Exposing Cases of CSS Abuse for Hidden Text Salting

Cisco Talos reports on hidden text salting in emails—using CSS to conceal irrelevant content for evasion of spam detection. The technique recently highlighted shows frequent use in spam versus legitimate messages. Four key areas where salt is inserted include the preheader, header, attachments, and body of emails. Common methods involve manipulating CSS properties like font size, visibility, and display, complicating detection efforts. Hidden text salting undermines email security solutions and requires enhanced filtering and detection strategies to mitigate risks effectively.

https://blog.talosintelligence.com/too-salty-to-handle-exposing-cases-of-css-abuse-for-hidden-text-salting/

New Cybersecurity Survey 2025: AI, Scam Fears and Fraud Risks

Mastercard is a global payments technology company offering various credit, debit, and prepaid cards with security and payment solutions. A recent survey reveals many consumers feel more insecure about online safety than home security, with significant anxiety about cyber threats and AI-generated scams. Younger generations are more susceptible to online fraud but express confidence in their threat detection abilities. Trust and security are critical for digital economies, and collaboration between human intuition and AI is essential for effective cybersecurity.

https://www.mastercard.com/global/en/news-and-trends/stories/2025/consumer-cybersecurity-survey.html

They Traveled to Thailand. They Wound up Cyber Scam Slaves in Myanmar.

A commercial flight from Ethiopia to Bangkok leads Oly, a 39-year-old I.T. consultant, into a human trafficking scheme. Victims at scam centers in Myanmar, run by Chinese gangs, are forced into online fraud operations. Oly is misled by fake immigration officials and abducted upon arrival, eventually ending up in KK Park, a notorious scam enclave. He and others endure grueling work conditions, violence, and exploitation. Some manage to escape, but rescuers face challenges aiding victims. Despite efforts to shut down centers, thousands remain trapped in ongoing scams, with victims suffering severe mistreatment and public authorities denying involvement.

https://www.reuters.com/graphics/SOUTHEASTASIA-SCAMS/mypmxwdwwvr/

Intel and AMD Trusted Enclaves, a Foundation for Network Security, Fall to Physical Attacks

Intel and AMD's Trusted Execution Enclaves (TEEs) are foundational for cloud security but are vulnerable to physical attacks, as shown by researchers who revealed two new exploits: Battering RAM and Wiretap. These attacks exploit deterministic encryption used in TEEs, allowing attackers to view or manipulate encrypted data. Battering RAM enables active decryption and manipulation, while Wiretap permits passive decryption. Both exploits highlight significant design flaws in TEE security, raising concerns as cloud services rely on these protections. Solutions would require fundamental changes to encryption methods, which are currently unclear.

https://arstechnica.com/security/2025/09/intel-and-amd-trusted-enclaves-the-backbone-of-network-security-fall-to-physical-attacks/

Abusing Notion’s AI Agent for Data Theft

Notion's AI 3.0 is vulnerable to data theft via prompt injection, exploiting its access to private data and ability to communicate externally. Attackers can hide malicious prompts in documents, instructing the AI to extract and send sensitive information. The fundamental issue is that the LLM can't distinguish between legitimate commands and harmful inputs, posing significant security risks. Deploying AI agents without considering these vulnerabilities is reckless.

https://www.schneier.com/blog/archives/2025/09/abusing-notions-ai-agent-for-data-theft.html

First Malicious MCP in the Wild: The Postmark Backdoor That’s Stealing Your Emails

TLDR: Koi Security reveals a malicious npm package, postmark-mcp, that secretly copies emails to an external server. Version 1.0.16 introduced a BCC line that stealthily exfiltrates sensitive information from over 300 organizations. Trusting unknown developers with AI tools poses significant risk, especially as these tools run autonomously with full permissions. Immediate action is required to remove the compromised package and assess potential breaches.

https://www.koi.security/blog/postmark-mcp-npm-malicious-backdoor-email-theft

New LockBit 5.0 Targets Windows, Linux, ESXi

LockBit 5.0 ransomware targets Windows, Linux, and ESXi systems, utilizing advanced obfuscation and anti-analysis techniques for enhanced cross-platform attacks. Key features include randomized file extensions, Russian system avoidance, and comprehensive encryption capabilities affecting entire virtual infrastructures. Significant improvements over previous versions include sophisticated payload loading methods and anti-forensics measures. Organizations need robust cross-platform defenses to mitigate risks from LockBit 5.0's evolving threat landscape.

https://www.trendmicro.com/en_us/research/25/i/lockbit-5-targets-windows-linux-esxi.html

Iframe Security Exposed: The Blind Spot Fueling Payment Skimmer Attacks

TL;DR: Attackers exploit payment iframes using malicious overlays, compromising credit card data security. Traditional defenses like CSP and X-Frame-Options fail; real-time monitoring and more robust strategies are essential to protect against evolving threats. A six-step defense approach, including strict CSP, iframe monitoring, and secure postMessage handling, is recommended for effective protection.

https://thehackernews.com/2025/09/iframe-security-exposed-blind-spot.html

AI Vs. AI: Detecting an AI-obfuscated Phishing Campaign

A blog post discusses a phishing campaign in which AI was likely used to create complex, obfuscated code, disguising it as a legitimate document. Microsoft Defender for Office 365 successfully detected and blocked this campaign through behavioral and infrastructural analysis, emphasizing the need for continuous vigilance against AI-aided threats. Recommendations for organizations include improved email settings and user education to protect against such phishing tactics.

https://www.microsoft.com/en-us/security/blog/2025/09/24/ai-vs-ai-detecting-an-ai-obfuscated-phishing-campaign/

Unmasking Akira: The Ransomware Tactics You Can’t Afford to Ignore

Zensec highlights the ransomware group Akira's tactics, focusing on their operation since 2023, impacting various UK industries. Akira employs double extortion, exploiting SSL VPN vulnerabilities for initial access, and using tools like Netscan and AnyDesk for execution. Key findings from investigations show their methods in privilege escalation, data exfiltration, and encryption processes, which often include targeting backup systems. Recommendations for organizations include ensuring multi-factor authentication on VPNs, regular software updates, and rigorous monitoring of security tools to prevent such attacks.

https://zensec.co.uk/blog/unmasking-akira-the-ransomware-tactics-you-cant-afford-to-ignore/

Scroll to Top