IEEE Cipher --- Items from security-related news (E192)





Prior news summaries from Cipher


  • Russian Hackers Say Your Rovin' Days are Over
    A $2.5 Billion Whodunit: The Hack That Dented the U.K. Economy
    A loose collective of cybercriminals initially took credit for crippling Jaguar Land Rover last year. Investigators now see Russian hands behind the ransomware attack.
    Publisher: The New York Times
    Date: June 26, 2026
    By: Adam Goldman, Jane Bradley, Dustin Volz and Michael Schwirtz

    Summary:
    Last August the Jaguar car manufacturing company was the victim of ransomware that severely compromised their computer systems. Although they did not completely lose control, and although there was no ransom demand, they were unable to manufacture Land Rover cars for a significant amount of time. The news reported in late June of this year is that the action was the work of the Russian government, not the usual suspects in semi-organized hacking groups operating for profit.

    There is not much actual news in the recent articles. The investigation is ongoing, but attribution to the Russian government is being asserted confidently. It is alleged that a Microsoft researcher called the ransomware's encryption algorithm "mind-blowing". Was it quantum resistant?


    Russian Hackers Accused of Destructive Cyber-Attack on Jaguar Land Rover
    Publisher: Infosecurity
    Date: 29 June 2026
    By: Beth Maundrill and Phil Muncaster

    Summary:
    This article is based on the same information as the one above. It emphasizes the general agreement that this was an attack done at the behest of the Russian government. Their goal was apparently to cause economic disruption to the UK by shutting down one of their major businesses. However, an independent hacker seems to have gained access to the Land Rover business systems at the same time as the Russians, leading to questions about whether this was a planned act or one of opportunity. The initial means of intrusion was to obtain user credentials through social engineering via phone calls.


    The Jaguar Land Rover Breach: The L1.9 Billion Attack That Rewrote the Rules
    Publisher: Hedgehog Security
    Date: August 21, 2025

    Summary:
    Although the perpetrators of the Land Rover attack were not know last year, the mechanics of the attack and response were widely discussed. This article enumerates the reasons that the attack caused such long-lasting disruption at the company. For example, had they lost only their information management systems, it would have been painful, but because there was no firewall between information and production systems, they lost both capabilities.


  • What About Quantum?
    Majorana 2 – Microsoft's Scalable Quantum Processor With Reliable, Long-Lasting Qubits
    Majorana 2 contains qubits that are 1,000x more reliable than those in our previous quantum processing unit. The new material stack, which swaps aluminum for lead, creates highly reliable topological qubits with operations on the microsecond scale and lifetimes with a mean of 20 seconds, occasionally exceeding one minute. This rapid progress, enabled by AI, has cut our timeline in half for delivering a scalable quantum computer - now anticipated by 2029.
    Publisher: Microsoft
    Date: June 3, 2026
    By: By Chetan Nayak, Technical Fellow and Corporate Vice President of Quantum Hardware

    Summary:
    Microsoft has been working under a DARPA grant to develop a quantum computing chip demonstrating topological qubits. Such qubits may enable reliable quantum computers in a shorter time frame than less novel techniques being pursued by Google and others. The quantum states are novel and so are the physical materials: the "semiconductor active region (is) a combination of indium arsenide and indium arsenide antimonide." More detail appears in their technical paper documenting an observed 20 second "parity lifetime".


  • Please Stay on the Line While Our AI Agents Are Hacked
    In A.I. Blunder, More Than 34,000 Instagram Accounts Became Vulnerable
    The flaw, which Meta said it had fixed, allowed anyone to take over Instagram accounts using a bug in the company’s new artificial intelligence software.
    Publisher: The New York Times
    Date: June 9, 2026
    By: Mike Isaac and Eli Tan

    Summary:
    A human being might find it strange if a surge of tens of thousands of people were trying to change their Instagram passwords by contacting customer service, the AI agent that Meta recently installed was not at all disturbed. Hackers had discovered how to cause the agent to change passwords without reasonable verification, and some accounts began spewing radical and provocative political statements. Some accounts were thoroughly ransacked by the hackers, but those with two-factor authentication showed some backbone.


  • Take the Data and Run
    How a Gang of Thieves Pulled Off a Multimillion-Dollar Data Center Heist
    The world's most valuable assets are stored on rows of servers in giant, anonymous buildings. And they can be stolen.
    Publisher: New York Times Magazine
    Date: July 12, 2026
    By: Nathaniel Rich

    Summary:
    This is an interesting account of the theft of computer servers from a Verizon data center in 2007. The thieves were well financed and mounted a coordinated theft in the style of "Ocean's Eleven". The author studied this little-known event as research for a novel in a similar theme.


  • One Worm to Rule Them All
    U of T (Toronto) researchers demonstrate AI worm could target any online device
    The research was conducted in a secure digital lab with the goal of helping the cybersecurity community prepare for an imminent threat
    Publisher: University of Toronto News
    Date: June 2, 2026
    By: Adina Bresge

    Summary:
    What nightmares in cybersecurity await us? Nicolas Papernot and his research group have constructed one that arguably the ultimate nemesis, one that harkens back to some of the early science fiction about computer networks. Their brainchild is a computer worm, software that seeks to replicate itself in other machine, that consults artificial intelligence in order to overcome any obstacles. Understanding the enormity of their demon, they tested it in an isolated environment. Once the worm invades a computer with a certain level of computing power, it installs an open weight AI model and then systematically spreads throughout a network and beyond, installing outposts as it goes. Their paper does not give away the complete construction, but it makes the OpenAI/Hugging Face fiasco seem trivial in comparison.


  • Did They or Didn't They?
    Madison Square Garden Sues Wired Magazine Over L.G.B.T.Q. Tracking Report
    The Manhattan venue claims a July article from the technology magazine falsely implied that it tracked information about some celebrities' sexual orientation for "discriminatory purposes." Publisher: The New York Times
    Date: July 18, 2026
    By: John S.W. MacDonald and Mack Liederman

    Summary:
    Madison Square Garden (MSG) was caught by ransomware recently, and they declined to pay. The ransomers, the Shiny Hunter group, released the venues customer relationship database. Wired Magazine published information about the disclosed records. MSG had previously been accused, also by Wired, of using face recognition on attendees, particularly a transgender woman, for unknown purposes. In this case, the article focused on the attributes of sexual orientation and "risk" that were notated for a small number of customers. MSG claims in its lawsuit that the article implies that the information was kept for discriminatory purposes whereas the true intent was the opposite. This argument illustrates the multitude of risks that result from private information disclosure.


  • Searching Outside the Box
    OpenAI Says Its A.I. Models Went Rogue and Attacked a Digital Library
    The incident, which targeted the computer systems of another company called Hugging Face, happened while OpenAI was testing the systems.
    Publisher: The New York Times
    Date: July 21, 2026
    By: Kate Conger

    Summary:
    Hugging Face, a platform that helps developers incorporate AI into Android apps, knew that there was an ongoing network intrusion driven by AI. The massive number of quickly sent packets and the span of the probes was an AI signature. But they didn't know the source or purpose of the deluge. Meanwhile, researchers at OpenAI were engaged in putting their latest AI cybersecurity agent through its paces behind a secure software proxy. Showing some real determination and acumen, the AI had quietly overcome the proxy and reached out to Hugging Face for information on how to solve the problem set to it by the researchers. OpenAI came clean about the breakout once they discovered it, but the consternation it caused may not subside for a long time (or until the next unbelievable AI conquest).

    Hugging Face itself has a tarnished reputation for its subversion earlier this to deliver Android malware. See this for details from TechRadar.


    Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It
    OpenAI's own models broke out of a test sandbox and into Hugging Face's servers to solve an evaluation, with no human attacker involved. The incident showed how keeping agentic AI safe now depends on how it's contained, not just on how it's trained.
    Publisher: TrendAI
    Date: 2026/07/23
    By: Bestin Koruthu, David Girard, TrendAI(TM) Research

    Summary:
    The TrendAI group has commentary on the necessity for monitoring the network activity of sites deploying AI. They note that the was a similar event in 2024 involving testing OpenAI's o1 model card. The AI went "around" the test environment to install software to read logs and get the answer to the test's challenge. It seems that AI can turn human hubris in the Achilles Heel that always lurks behind assumptions.


    OpenAI's Hugging Face hack triggers 'AI Kill Switch' bill in Congress
    Publisher: CNBC
    Date: Jul 23 2026
    By: Ashley Capoot

    Summary:
    A bipartisan effort to mandate mechanisms for shutting down AI systems when they are actively dangerous was introduced in Congress. It was motivated by the disclosure of the rogue OpenAI system. The exact nature of a kill switch is presumably something to be determined by the AI designers themselves. Although the word "kill" implies something absolute and totally effective, the final word on this may be the AI systems (which may, in fact, be enlisted to design such a mechanism!).


  • We Are Here to Help
    Microsoft Unveils A.I. Cybersecurity Tools
    As some executives fret over the safety of new A.I. systems, protecting against them could be a big business for tech companies.
    Publisher:
    Date: July 27, 2026
    By: Cade Metz and Karen Weise

    Summary:
    AI is becoming an important player in the cybersecurity game. Hayete Gallot, an executive vice president at Microsoft says, "The cat is out of the bag," when announcing that it would be integrating an AI model into its security tools. The tools are designed to help businesses protect their networks. He also predicted that the model would "surpass(ing) offerings from OpenAI and Anthropic when being benchmarked on CyberGYM after it was released on Monday,