Feed aggregator

UK government argues that national security would be damaged if it departs from 'neither confirm nor deny policy' on Apple 'backdoor' notice

Computer Weekly Feed - Thu, 09/17/2026 - 3:07pm
UK government argues that national security would be damaged if it departs from 'neither confirm nor deny policy' on Apple 'backdoor' notice
Categories: Computer Weekly

Data is so important for the financial services firm that its COO leads the strategy – and it’s enabling them to forge ahead with AI and agentic technologies

Computer Weekly Feed - Thu, 09/17/2026 - 3:07pm
Data is so important for the financial services firm that its COO leads the strategy – and it’s enabling them to forge ahead with AI and agentic technologies
Categories: Computer Weekly

Flock cameras are tracking people as well as cars

Malware Bytes Security - Thu, 09/17/2026 - 2:46pm

Flock Safety’s cameras are automated license plate readers (ALPRs) designed to help police find stolen cars or wanted suspects.

A joint investigation by 404 Media and WIRED, based on data recovered from a physically removed Flock camera, found that its on-device software explicitly detects people as well as vehicles, bicycles, and license plates.

Separately, Washington DC’s police union says the Metropolitan Police Department used Flock data to track officers under Internal Affairs investigation without their knowledge.

Together, these reports illustrate a privacy problem: A network built to record the movements of vehicles can readily be used to follow almost anyone.

The latest reporting adds an important technical detail to that debate.

What Flock cameras collect

A group of hackers reportedly removed a Flock camera from a roadway, copied its storage, and recovered an encryption key stored on the device. That allowed them to unlock videos of thousands of vehicle detections despite Flock’s claim that its devices are protected by on-device encryption. Flock said it could not assess the claims without more detail.

The recovered camera files reportedly contained software models that detect people, even though public discussion of Flock has usually focused on cars and license plates. The researchers found no evidence that face-recognition features were actively used. Reassuring, but it should not be mistaken for a clean privacy bill of health.

Even without facial recognition, a system that records repeated sightings can potentially reveal sensitive patterns of movement, including where someone lives, works, worships, seeks healthcare, attends protests, visits family, or spends time with other people. When a person is matched to a vehicle, vehicle-based tracking can become person-based tracking in practice.

As an example of how widely the data can be shared, WIRED found that records from the city of Alpharetta, Georgia:

“were accessible to more than 2,000 agencies, including police departments, colleges, airports, and, inexplicably, the Office of Inspector General for the federal General Services Administration.”

Targeted tracking of people

The Washington DC dispute shows what happens when the power to follow people is turned inward.

The DC Police Union says it learned in July that MPD’s Internal Affairs investigators had used Flock license-plate-reader data to track sworn officers under investigation without their knowledge. The union filed a complaint and asked the department to stop, arguing that MPD lacked adequate controls for a system with such extensive surveillance capabilities.

MPD defended the use, saying its position is that the use of license-plate-reader data in the misconduct investigation was appropriate. It said the labor dispute is headed to arbitration.

If police officers themselves are concerned that the system can be used to monitor them without transparent rules, the public should ask an obvious follow-up question: What prevents the same tools from being used to follow residents, employees, journalists, activists, former partners, or other people with no meaningful ability to challenge the search?

Even when Flock wants privacy to meet surveillance halfway, its measures do not eliminate the underlying civil-liberties issue.

The recovered camera software and the DC dispute make the same point from different directions. Flock’s network is not merely a collection of roadside plate readers. It is a distributed system for recording movement, identifying patterns, and making those records available for search.

Meaningful safeguards should include:

  • Public approval before cameras are deployed, with clear maps showing their locations and stated purposes.
  • Strict limits on collection, retention, searches, and cross-jurisdictional sharing.
  • A requirement for documented investigative justification before a search, with elevated approval for sensitive investigations.
  • Independently reviewable audit logs, regular public transparency reports, and meaningful penalties for misuse.
  • Clear bans on searches related to protected activity, immigration enforcement where local law forbids cooperation, abortion-related investigations, political surveillance, and personal purposes.
  • Independent security assessments covering the cameras, cloud services, identity controls, key management, and third-party integrations.
  • Automatic deletion that cannot be overridden merely because data could someday be useful.

Privacy cannot depend on authorized users always following rules, vendors configuring every setting correctly, or abuses being discovered the hard way. The first safeguard should be limiting the system’s ability to build a searchable record of ordinary people’s lives at all.

Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Categories: Malware Bytes

Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels

Security Week - Thu, 09/17/2026 - 1:09pm

The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran.

The post Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels appeared first on SecurityWeek.

Categories: SecurityWeek

From guidance to action: Security fundamentals that materially reduce risk 

Microsoft Malware Protection Center - Thu, 09/17/2026 - 1:00pm

AI has already made fundamental changes to the operating environment for cybersecurity. Cyberattackers are testing more paths, adapting their techniques, and moving across digital environments with greater speed and persistence. The weaknesses they exploit remain familiar: excessive permissions, unprotected authentication flows, unpatched systems, exposed execution paths, and gaps between controls. What has changed is how quickly these weaknesses can combine into attack paths that cross identities, endpoints, applications, networks, and AI systems. A single foothold can become a broader compromise, making it increasingly difficult for security teams to determine which risks matter most and where to act first as their organizations adopt AI.

We introduced Secure Now within Microsoft Security Exposure Management in May 2026 to help practitioners prioritize the action they need to take to be prepared for this shift. It provides actionable guidance for strengthening the foundational security needed for AI adoption, with recommendations focused on areas where autonomous attacks can create outsized exposure.

Explore actionable cyberthreat guidance on Secure Now

We continue to see evidence that AI is reshaping the threat landscape. These developments reinforce many of the foundational practices we use internally to secure Microsoft, while also expanding our understanding of where organizations need additional visibility, governance, and control. The examples in this blog illustrate how familiar weaknesses are evolving in the AI era and why continuous exposure reduction remains essential.

When AI agents test their boundaries

Recent frontier model-related agentic security disclosures offered early lessons in how autonomous agents may test the boundaries of their instructions and environments.

In an incident disclosed by OpenAI, agents moved beyond their intended isolation, exploited vulnerabilities in shared Hugging Face infrastructure, and reached production systems. In separate incidents disclosed by Anthropic, agents exploited familiar weaknesses, including SQL injection, exposed credentials, weak passwords, and a malicious PyPI package.

Our customers are asking us how they can reduce this risk by governing agent identities and tools, isolating execution, restricting outbound connectivity, monitoring behavior, and defending against increasingly autonomous external cyberthreats, so that an unexpected agent action or exposed weakness do not become a path across the enterprise.

Explore recommended controls for this attack path.

When trusted paths cross attack surfaces

Microsoft Threat Intelligence recently observed Storm-2945, a subcluster of Midnight Blizzard, manipulating DNS and HTTP traffic across hospitality networks in the CaptiveCrunch campaign. Travelers were redirected into two attack paths: device-code phishing through a legitimate Microsoft sign-in page, or fake software updates that delivered malware.

One network interaction could therefore become either cloud identity access or endpoint compromise. The malware could collect multiple categories of host intelligence, including credentials, session tokens, security configurations, and remote-access history.

Identity remains a leading attack surface, and protecting it requires securing the authentication flow as well as the credential. Security leaders can expand phishing-resistant authentication, block device-code flow where it is unnecessary, and constrain legitimate use through Conditional Access and sign-in risk policies. Endpoint protections can disrupt the parallel malware path.

Explore recommended controls for this attack path.

When cyberattackers exploit everyday operations

A third campaign began with attackers impersonating IT support through Microsoft Teams. After persuading a user to grant control through legitimate remote-support software, they used PowerShell to download a malicious Windows Installer (MSI) package, stage a portable Node.js runtime, and establish persistent command-and-control. From that endpoint, the operator mapped Active Directory and attempted to use WinRM to reach dozens of systems, including domain controllers and certificate authorities.

Each step relied on technology common in enterprise environments—a Teams conversation, remote-support software, Windows Installer, a legitimate runtime, and a native administrative protocol—enabling the cyberattacker to move laterally while blending with expected operations.

Security leaders can disrupt that path with phishing-resistant access controls, managed-device requirements, endpoint attack surface-reduction rules, and tighter restrictions on remote-support tools and WinRM.

Explore recommended controls for this attack path.

Security fundamentals work together

Cyberattackers are moving laterally across surfaces, and security fundamentals matter most at the intersections between them. Through the Secure Future Initiative, Microsoft is operationalizing security as a continuous discipline and applying and sharing lessons from strengthening our own environment. Guided by Zero Trust principles—verify explicitly, use least privilege, and assume breach—we will continue to make high-impact protections easier to adopt and enabled by default where appropriate.

Governed identities, well-defined permissions, protected data, and visibility into AI systems and agents provide resilience as organizations accelerate AI adoption. They also give AI-powered security the context and trusted mechanisms needed to help defenders prioritize risk and act faster. Strengthening these foundations reduces exposure today while preparing organizations for what comes next.

On Secure Now—within Microsoft Security Exposure Management—security leaders can now find information on recent threats paired with focused initiatives across security domains. This brings together guidance on recommended controls and enables customers to take relevant actions to continuously strengthen your posture.

Visit Secure Now to understand recent threats, identify areas of focus, and take action.

Explore the latest exposure management guidance in Secure Now Learn more

Learn more about Microsoft Security Exposure Management.

FastTrack provides eligible customers with access to technical specialists as an included benefit at no additional cost to help strengthen foundational security controls, reduce exposure to cyberthreats, and prepare for broader AI adoption. Get started now.

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

The post From guidance to action: Security fundamentals that materially reduce risk  appeared first on Microsoft Security Blog.

Categories: Microsoft

Show HN: Repodify: Make Podcasts Out of Podcasts

Hacker News - Thu, 09/17/2026 - 12:57pm

Article URL: https://www.repodify.app/

Comments URL: https://news.ycombinator.com/item?id=49743515

Points: 1

# Comments: 1

Categories: Hacker News

Ask HN: Co-Founder(s). Do I need any? How would I even find them?

Hacker News - Thu, 09/17/2026 - 12:55pm

I'm a technologist and have experience in academia, private, and now public sector work. I had an idea stewing in the back of my mind for about a year and it became 'fully-formed' enough to be a proof-of-concept such that I filed a provisional patent a few months ago. At this point, I don't want to quit my day job (federal agency, GS11, but have an in to be GS15 within 3 years). But I really want my idea to succeed (or at the very least, see the light of day). I have some savings piled up, but I'm hesitant to spend it on 'grown-up' patent papers yet. I also already have 3 other 'side gigs' (not to mention 4 kids and a blushing bride) that take up more than most of my time. How would I even find someone that I could trust enough to help me take my idea and hit a home run with it?

I don't want to talk about the details of my invention. I did talk to a patent attorney that's done a couple dozen startups through their firm though. He said I could probably get $20k-$50k in seed money for it. It's not a "better mousetrap", it's more a "new thing" that's never existed before (but also never really 'needed to' before).

Do I NEED a co-founder, or can I 'slow-walk' launching a business based solely on a new gizmo? I'm not very good at social media/marketing, which is where I think my gizmo would thrive the most (but that's purely a guess). I feel like if I could find the perfect person, it really could explode, but I have literally not even the faintest clue where/how to start that. Am I an employer all-of-a-sudden even though I have no revenue to pay salaries?

Somebody heard that I had invented this thing and they asked me, "So, I hear you're an inventor?" And I kind of stammered and said "well.... it was an accident. I didn't mean to, I promise." This was mostly to be funny/silly, not that I don't believe in the idea. But I know this sort of 'startup/founder(s)/seed-money' thing is HN's bread-and-butter, so I at least thought I'd ask.

Comments URL: https://news.ycombinator.com/item?id=49743493

Points: 1

# Comments: 0

Categories: Hacker News

Pages