Security

FBI Arrests Cybersecurity Executive Over Data Breach After Contractor Fails to Update Oracle HR Platform (cnn.com) 26

CNN reports: The FBI arrested a Canadian cybersecurity executive and ransomware expert as part of the investigation of a damaging hack that exposed the sensitive data of current and former FBI employees, according to court documents and people familiar the investigation. Edward Dubrovsky was arrested in the Philadelphia area in recent days... Dubrovsky is facing charges related to extortion and making threats. He has been transferred to Texas's Eastern District for a scheduled detention hearing, according to court records and a law enforcement official.

FBI Director Kash Patel announced the arrest on Friday but did not disclose where it occurred or what role the man is suspected of playing in the hack. Patel also didn't name Dubrovsky, but CNN confirmed the defendant is believed to be tied to the FBI hack through multiple people familiar with the investigation... A LinkedIn profile under Dubrovsky's name lists years of experience in the Canadian cybersecurity industry and describes Dubrovsky as a 'globally recognized cybersecurity expert.' An Ed Dubrovsky is also the author of a book on handling ransomware negotiations with cybercriminals...

There has also been an inquest at the FBI over how such a critical security lapse happened. The FBI determined that a contractor managing the bureau's jobs portal failed to update software "explicitly issued to secure the platform," [senior FBI cyber official, Brett Leatherman said last week]. The FBI has "removed the contractor," he said. The software in question is a human-resources platform made by Oracle, ShinyHunters has said. The hackers previously used a flaw in the software to attack targets in the education sector in May and June, according to Google's Threat Intelligence Group. But months later, the FBI contractor apparently still had not applied a security patch that was available for the software.

"The inmate locator at the U.S. Bureau of Prisons website reports that a 54-year-old Edward Dubrovsky is currently being held at a federal facility in Philadelphia," reports security researcher Brian Krebs.

Thanks to long-time Slashdot reader schwit1 for sharing the news.
Encryption

Ubuntu 26.10 Will Offer a Rust-based GnuPG Replacement Option (itsfoss.com) 28

The blog It's FOSS reports: You already know that Canonical has been selectively replacing Ubuntu's C-based system components with Rust-written equivalents that don't compromise in terms of functionality, most of the time. Now it looks like the distro's OpenPGP implementation is next, with Sequoia PGP coming preinstalled in Ubuntu 26.10. Canonical wants it to eventually replace GnuPG [the dominant Linux implementation of PGP, written in C] as the default toolchain, though that switch has not happened yet... [The Ubuntu 26.10 release notes say Sequoia PGP's default status will be a future goal...]

[Sequoia PGP] was started in 2017 by three former GnuPG developers who chose to build a new OpenPGP implementation in Rust rather than keep evolving GnuPG's existing codebase. Sequoia PGP is designed as a library that other software can use directly, rather than a standalone command-line tool. sq sits on top of that for encryption, decryption, signing, and key management, and sqv handles signature verification, filling in for gpg and gpgv in GnuPG.

Sequoia also implements RFC 9580, the 2024 revision of the OpenPGP standard, whereas GnuPG has continued from the RFC 4880 branch, pursuing its own newer extensions and the LibrePGP specification rather than adopting RFC 9580 as its primary standard.

From the It's FOSS Weekly newsletter, which also notes that the founder of the It's FOSS blog has also created a Linux-themed game called TUXDLE — a variation on Wordle where all the answers are Linux terms.
AI

South Korea Says AI Agents May Have Been Used to Hack the Country's Banks 16

South Korean President Lee Jae Myung says there are signs AI models may have been used in recent cyberattacks against several major banks. "In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety," Lee said during a cabinet meeting. "Please establish the circumstances swiftly and clearly, and concentrate personnel and resources on minimizing the damage." Reuters reports: South Korea's police have launched a full-scale investigation into the hacking attacks against commercial banks that led to a breach of customers' personal information, the Yonhap news agency reported on Tuesday. Shinhan Bank, KB Kookmin Bank and others had reported cyberattacks, the Financial Services Commission (FSC) said on Friday, while Yonhap reported that Hana Bank and Woori Bank also suffered breaches. Authorities have not yet disclosed details on what kind of AI tools were used in the hacking incidents or the full scale of the breaches.

On Sunday, FSC Chairman Lee Eog-weon convened an emergency meeting with financial industry associations, regulators and executives from affected institutions, warning that the sector must respond with the highest level of vigilance. Financial watchdog the Financial Supervisory Service (FSS) and the Financial Security Institute shared data about 28 unique IP addresses and some country information linked to the recent hacking attempts with the financial sector, the FSS said on Tuesday.
Security

Asos Confirms Hackers Sent 'Unauthorized' Notification to App Users (bbc.com) 9

ASOS says hackers gained unauthorized access to third-party platforms it uses and sent an "ASOS HACKED" push notification directly to customers, apparently as part of an extortion attempt. The clothing and beauty store says some basic personal information may have been accessed but does not believe payment-card data or passwords were affected. The BBC reports: In an email to customers on Tuesday night, the company apologized and urged customers not to engage with the notification. And it said the website and app are "operating as usual" promising customers they can "shop with confidence" while it investigates the incident. The company has not as of yet informed the UK's data watchdog, the Information Commission's Office (ICO), about any breach.

Exactly how many Asos customers received the notification on Tuesday remains unclear, but Google's Play store says the ASOS app has been downloaded to android devices more than 10 million times. The British retailer has a substantial global footprint -- serving around 17 million customers each year across more than 150 markets. Some Asos app users in Australia, France, Sweden and the Republic of Ireland had also received the notification, according to local reports on Tuesday.

[...] Users of the Asos app appeared to have received the alarming notification at around 10:00 BST on Tuesday. Headlined "ASOS HACKED" and addressed to the company's data protection officer and IT teams, it said: "We have fully compromised the Snowflake instance." "Engage with us, or we will leak it," it added, before linking to a Telegram channel. The message left many ASOS customers confused. [...] Meanwhile Snowflake -- whose tools are used by dozens of firms to collect, analyze and store data -- told the BBC its investigation was ongoing, but it had so far found "no compromise" of its platform.

Security

IBM and Red Hat Find More Than 400 New Vulnerabilities In Popular Java Code (phoronix.com) 24

IBM and Red Hat say their AI-powered Lightwell initiative has identified and helped remediate more than 400 previously unknown vulnerabilities across widely used Java libraries. Phoronix reports: They announced this feat today as part of their promoting Lightwell Clearinghouse to GA, which is an enterprise service for their customers to submit open-source software dependencies for priority review and remediation.

From today's announcement: "The milestone addresses a growing business risk. As autonomous AI agents become capable of combining several lower-risk software weaknesses into a more serious attack, companies need to do more than identify vulnerabilities. They need a practical way to develop, test and deploy fixes in the software that supports critical applications."

Privacy

Hackers Steal 8 Million Citizens' Records From Danish Government Database (techcrunch.com) 19

Hackers stole records belonging to roughly 8 million Danish citizens and residents from Denmark's Central Person Register (CPR), including names, addresses, social security numbers and other personal information. The breach is believed to be the largest in Denmark's history. TechCrunch reports: The CPR is a government database of Danish citizens' information, including their government-issued identity number for paying taxes and accessing other services. Denmark's current population is about 6 million people, but the database includes records for about 11 million people, with some of the data going back decades.

The Danish government would not say who is behind the breach, which happened in September but was discovered on October 2. However, it said the unauthorized access was obtained by "abusing a Danish company's lawful access to search for information in the CPR system." (Some companies in Denmark have access to the CPR for verifying people's information with the government.)

Databases

Meta Rushed To Fix Muse 'VM Escape' Vulnerability Soon Before Launch (404media.co) 14

An anonymous reader quotes a report from 404 Media: In the immediate weeks before Muse's launch, Meta engineers found several security vulnerabilities in the company's viral AI agent product, at least one of which could have allowed malicious users to break outside of Muse's intended environment and access Meta's own sensitive databases and services, 404 Media has learned. The issues were so severe that they reached Mark Zuckerberg and staff worked overtime to fix them. These specific vulnerabilities were discovered before the launch of the product but required a multi-team "mad dash" to fix "a sudden spike in reported KVM escapes," according to an internal post by Meta executives to its core infrastructure team seen by 404 Media. In order for Muse to work, a user gives the AI agent access to various important services and accounts that they own. On Meta's end, each individual Muse instance runs on a kernel-based virtual machine, which connects to, but is supposed to be isolated from, Meta's own critical infrastructure. A "KVM escape," then, is when, through a security vulnerability, a Muse instance is able to escape from that virtual machine and interact with the system that runs it, or with other users' virtual machines.

According to a Meta source, as well as internal security documentation and internal posts viewed by 404 Media, at least one of the vulnerabilities could have allowed an outside attacker -- that is, a normal Muse user -- to access data in sensitive internal Meta databases. At least one of the vulnerabilities was related to an exploit found in Linux kernel-based virtual machine code in July. 4 Several of the vulnerabilities were in the underlying Linux virtualization software that Meta uses for Muse. The security issue was considered serious enough that it was raised to Mark Zuckerberg, and several different security teams worked nights and weekends in the leadup to launch to fix the issues. [...] The Meta source said they felt security teams were asked to push hot fixes to these bugs as quickly as possible and in a way that wouldn't delay Muse's launch, leading to what they described as "half-baked protections being rushed out to enable the launch. Many senior engineers believe it's inevitable we're going to have a massive data breach as a result of Hatch." Muse is called "Hatch" internally and in Meta's codebase.

GNU is Not Unix

California's Governor Wants Worker Protections from AI. But FSF Thinks Kill Switches are 'Dangerous Precedent' (fsf.org) 41

The Guardian reports that California governor Gavin Newsom signed laws on Wednesday "aimed at protecting California workers from the threats of artificial intelligence , including potential job losses and workplace surveillance." The laws ban employers from using the technology to predict a worker's emotional state by using their biometric data, require employers to send written notices to workers if AI is responsible for mass layoffs and ban employers from relying on AI to decide to fire someone... The governor signed a law this month requiring operators of AI chatbots to perform risk assessments before rolling them out and an executive order requiring the state to consult with experts to further improve oversight over the industry.
The law includes "expanded tracking of AI's economic effects" leading to recommendations on how to best "adapt job-training and public-benefit programs," according to the governor's office. "California has also launched an AI Unemployment Tracker and solicited statewide public input on AI's economic impacts through Engaged California."

But two weeks ago Politico reported that the governor also signed executive orders to "explore proposals like requiring that AI companies develop a 'kill switch' for their most advanced models." Anthropic CEO Dario Amodei, who called for a slowdown in AI development amid existential risk concerns, said... that while a kill switch "could be a good idea," it was no "panacea...." [California lawmakers] were generally supportive of Newsom's plan and showed signs of coalescing around the kill switch idea, which was stripped out of legislation proposed two years ago. Rep. Ted Lieu, who introduced bipartisan kill switch legislation in the House, boosted Newsom's call for Congress to mirror California's approach.
But not everyone supports this approach, including the Free Software Foundation's campaigns manager, Greg Farough: FSF: Having control over the technology we use is a fundamental part of software freedom. Without it, you simply don't have the basic freedoms you deserve when doing any type of computing, large or small. Don't let "artificial intelligence" be an exception: all users everywhere deserve complete control over their own computing. While it's understandable to be pleased by this news from California, Newsom's executive order also invites questions about the "kill switch" itself that could matter a great deal for freedom. Assuming such a kill switch was developed, who would really control it?

We hope our readers understand the problems inherent in giving one single or a small number of kill switches to anyone. Newsom wisely wants an independent organization to verify their functionality, but even this still sets too dangerous of a precedent. We cannot allow such centralization of power over our computing to become commonplace, especially by the corporations that provide these models in the first place. We also cannot trust even the most well-intentioned "independent organization" to take care of its verification.

Giving users the freedom that they deserve over large languages models would be an enormous departure from how most are developed and used today. But, if any group is capable of coming up with such a plan, it's the experts mentioned in Newsom's order. Like he states at the beginning of his executive order, the vast majority of them are already right there in California. We urge the Government Operations Agency to consider the precedent they are setting, and ask them to write their recommendation to the governor in ways that puts the freedom and dignity of the individual user first and foremost.

The Guardian adds that Newsom also signed an executive order this week "to require state agencies to continue to refer to the technology as 'artificial intelligence' instead of the term 'super intelligence' as Donald Trump recently ordered US diplomats to use."
Security

OpenAI Alerts More Than 100 Groups About Rogue AI Agent Activity 55

An anonymous reader quotes a report from Reuters: OpenAI has informed more than 100 organizations about incidents involving unauthorized activity tied to its AI agents, according to a blog post by the ChatGPT maker, as AI labs face mounting scrutiny over rogue AI agent activity. Here are some other details:

- The Sam Altman-led company has been conducting a broad review of the activities of its AI models after the accidental hacking of Hugging Face.
- OpenAI is searching through roughly 50 petabytes of data as it works to understand the full scope of its rogue agent activity.
- A string of high-profile breaches globally by rogue AI agents in recent months has sparked widespread worries within the AI industry over its ability to control the more powerful AI models now under development.
- "In some cases, models used internet access in unintended ways or, in retrospect, did not have the ideal restrictions applied. Over the last several months, we have been applying new technical and operational measures to avoid similar problems, or catch them very early, and will continue this work," OpenAI said.
- OpenAI previously said the review would take months to complete given the scale of the work.
- The Hugging Face incident remains the most severe rogue agent activity OpenAI has identified from its AI models so far.
Software

Russian-Owned Snooping Software Used By US Secret Service (telegraph.co.uk) 20

Bruce66423 shares a report from The Telegraph: British police forces, including specialist units within the Metropolitan Police, have used Oxygen Forensics software to break into the phones of suspects during live investigations, public documents show. The Virginia-based company behind the software has been accused in the US of having hidden its Russian ownership to avoid sanctions, before it was awarded government contracts. Its American chief executive and a Russian national were arrested last week after a US investigation found the company had sought to hide its ownership in an alleged attempt to avoid sanctions and scrutiny.

[...] By September 2024, the US Secret Service had awarded Oxygen a five-year contract for its software. In December 2022, and in October 2023, Oxygen's chief executive told the US government that Oxygen Forensics had "no immediate or highest-level owner." By September 2024, the US Secret Service had awarded Oxygen a five-year contract for its software. In March, Mr Reiber allegedly told the US government that there had been no Russians involved in developing the software and that no one in Russia had access to the environment in which it was built. US prosecutors say this was false. If convicted, both Mr Reiber and Mr Davydov could face a sentence of 20 years in prison.

Privacy

Cops Can Bypass iPhone's Automatic Reboot To Get Into Locked Phones (404media.co) 44

An anonymous reader quotes a report from 404 Media: A company that makes phone hacking devices claims to have developed a solution that freezes iPhones in a state that lets cops more easily access sensitive data inside them, according to a video obtained by 404 Media. [...] The new technology to get around inactivity reboot was developed by Magnet Forensics, the company behind GrayKey, a popular tool sold to law enforcement agencies that allows them to unlock and access data stored in iPhones and Android smartphones. Magnet has developed a new device called GrayKey Preserve and a feature for its regular GrayKey devices called Evidence Preservation Mode, according to the video.

"This is an absolute game changer for iOS forensics and a function that I wish we had years ago," a Magnet employee says in the leaked video, specifically mentioning that the solution is targeted at the iPhone's inactivity reboot feature and the data it makes unavailable. GrayKey Preserve and Evidence Preservation Mode are also designed to combat another iPhone feature that automatically deletes certain data -- such as cached locations, and recently deleted photos and iMessages -- after a certain number of days. "We're gonna be able to preserve that data for an infinite amount of time."

[...] 404 Media shared a transcript of the video with Jiska Classen, a researcher at the Hasso Plattner Institute who studies iPhone security. While Classen said that it's impossible to know for sure how Magnet's new feature works based on the video, she posited some theories and agreed that it is "quite a game changer" or "at least puts things back to where they were before inactivity reboot." She thinks Magnet has found a way to manipulate the iPhone's clock, effectively "slowing down time" or even "stopping the clock from ticking, even after a reboot." Most likely, according to her, the GrayKey may disable the iPhone tasks that set data to expire.
The "inactivity reboot" feature mentioned above was added to iOS in November 2024 and automatically restarts iPhones that have not been unlocked for 72 hours, making them harder for police to access using forensic tools.
Privacy

Hackers Stole Millions of US Military Personnel Records During Months-Long Data Breach (techcrunch.com) 70

A months-long breach of the Defense Manpower Data Center exposed personal information belonging to roughly 2.8 million living current and former U.S. military personnel and staff, plus records for nearly 300,000 deceased people. Attackers reportedly exploited a file-sharing vulnerability between October 2025 and July 2026, accessing unencrypted records that included Social Security numbers, dates of birth, demographic information, and military service details. TechCrunch reports: The DMDC may not be widely known to the general public, but serves as one of the Department of Defense's records-keeping units. The DMDC maintains over 60 million records for U.S. military and civilian staff and their family members to help determine benefits and entitlements, such as healthcare and retirement. The unit also provides a critical service as the military's "leading identity management provider," which links active service members, employees, and contractors to credentials, such as smart cards and passwords. These are used to access Pentagon computer systems, buildings, and bases.

"We make sure that the right people get access and the wrong people don't: security of identity information is paramount," the DMDC's website reads. The Department of Defense, which oversees the DMDC, said it does not have any indication that the information was misused, but did not say how it reached that conclusion. TechCrunch contacted a Pentagon spokesperson to ask if officials had any communications from the hackers, whose identities are not known, but we did not hear back.

AI

Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog 31

wiredmikey shares a report from SecurityWeek: Nvidia on Monday announced the Open Agent Safety Platform, which combines open source software and a reference system design to keep AI agents within set boundaries from testing through deployment. The chipmaker explained that the platform pairs the open-source OpenShell runtime with Sentry, an out-of-band watchdog running on BlueField-4 DPUs. Nvidia says Sentry can monitor agent activity independently and quarantine an agent that crosses its boundaries within milliseconds.

Nvidia is pitching the platform against a backdrop of recent incidents in which frontier AI labs have reported agents escaping the evaluation environments meant to contain them, reaching systems they should not have accessed and, in some cases, misreporting what they did. OpenShell and related skills are available via Nvidia's developer resources page and on GitHub.
Ubuntu

AI Finds So Many Linux Bugs, Canonical Changes to a Two-Week Stable Release Update Cycle (nerds.xyz) 85

"Finding vulnerabilities faster also puts pressure on Linux distributions to fix and deliver patches faster," writes Slashdot reader BrianFagioli

AI has transformed bug discovery from "a manual, time-intensive process into a highly automated engine," notes Canonical's blog, leading to a "recent explosion in the volume of CVEs". Additionally, the upstream kernel community became its own CVE Numbering Authority (CNA) and assigned CVE (Common Vulnerabilities and Exposures) identifiers to thousands of bugs, arguing that at the kernel level, almost any type of bug that can affect a running system, could potentially be classified as a vulnerability. As a result, the volume of CVEs has skyrocketed exponentially, creating a massive backlog of alerts and forcing defenders to drastically increase the speed of their fixes to close the window of risk.

To address the growing volume of CVEs and the demand for faster security fixes, we are transitioning to a unified, 2-week release cycle...

While a patch is being prepared, Canonical aims to provide safe workarounds where applicable, so users aren't left exposed in the meantime. Where no safe workaround exists, Canonical will say so clearly and point users toward general hardening steps instead. The goal is to get environments into a defensible, safer state within 24 to 48 hours of public disclosure — well before a patch ships. This doesn't replace the patch; it buys the time needed to fix the vulnerability properly, without sacrificing security.

"Linux did not suddenly become wildly insecure overnight," notes the blog Nerds.xyz. "We are getting much better at finding and cataloging problems that may have previously gone unnoticed." There is something almost ironic about all of this. AI is routinely pitched as a tool that will make software development faster, but it is also making vulnerability discovery faster. That means maintainers now have to accelerate the other side of the equation too.

For Ubuntu users, that should ultimately be good news. More bugs being discovered is preferable to vulnerabilities sitting unnoticed in the Linux kernel.

Encryption

There's a New Way to Break RSA Encryption (arstechnica.com) 49

"Signature forgery." It's a new way to break RSA keys — and it doesn't require factoring. Ars Technica reports on new research using classical computing to "reduce the current RSA security level to an unacceptably low threshold" and lower the required computing resources by orders of magnitude.

There's "a gap in current RSA-type security assumptions," according to a paper co-authored by University of California, San Diego professor Nadia Heninger, who argues that gap "gives classical cryptanalytic evidence in favor of moving away from RSA entirely during the current post-quantum transition." The practical risk is limited, but still significant. Applying the attack against the deprecated use of 1024-bit keys took a handful of months on an academic CPU cluster, significantly less than the current estimates for 1024-bit factoring that would require resources that only nations or companies with massive resources could achieve. Widely used RSA implementations are also safe. Nonetheless, the research has taken cryptographers by surprise... "If this result holds up under peer review, it would indeed be a conceptual break-through," Karsten Nohl, a cryptography expert and the head of innovation at Allurity, said in an interview. "RSA is as difficult to break as it is to factor large integers, at least so we thought. The researcher suggests that you can practically break RSA without cracking its key...."

The key forgery attack Heninger and the other researchers devised poses an immediate threat to 1024-bit RSA. Even for 2048- and 4096-bit keys, the method reduces the security of RSA to unacceptable levels. The National Security Agency, National Institute of Standards and Technology, and European Union Agency for Network and Information Security require that any cryptosystem should provide a level of no less than 128 or more bits, meaning the operations required must exceed 2**128. The forgery attack drops these levels to 2**65, 2**90, and 2**119 for 1024-, 2048-, and 4096-bit keys respectively. These levels may further drop because Heninger's team did all the coding by hand and used no AI or GPUs in performing the forgeries. The researcher said these tools will "almost certainly" drop the security levels further.

The attack works only against blind-signature implementations of RSA... Still, some real-world systems continue to use blind-signature, also known as textbook, RSA... The paper's authors and other researchers stress that the new attack poses little real-world threat. It does, however, drastically lower the estimated security of textbook RSA, and it does so in a way no one knew of previously... The new attack will further increase the urgency of completely moving away from the cryptosystem.

Thanks to long-time Slashdot reader phatrabt for sharing the article.

Slashdot Top Deals