_/_/_/_/ _/_/_/ _/_/_/_/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/_/ _/_/_/_/ _/ _/ _/ _/ _/ _/ _/ _/ _/_/_/_/ _/_/_/ _/ _/ _/ _/_/_/_/ _/ _/ ============================================================================ Newsletter of the IEEE Computer Society's TC on Security and Privacy Electronic Issue 192 July 27, 2026 Hilarie Orman, Editor Sven Dietrich, Assoc. Editor cipher-editor @ ieee-security.org cipher-assoc-editor @ ieee-security.org Sven Dietrich Yong Guan Book Review Editor Calendar Editor cipher-bookrev @ ieee-security.org cipher-cfp @ ieee-security.org ============================================================================ The newsletter is also at http://www.ieee-security.org/cipher.html Cipher is published 6 times per year Contents: * Letter from the Editor * Commentary and Opinion and News o Sven Dietrich's review of "Red Team Engineering - The Art of Building Offensive Tools and Infrastructure" by Casey Erdmann o News from the Media - Russian Hackers Say Your Rovin' Days are Over - What About Quantum? - Please Stay on the Line While Our AI Agents Are Hacked - Take the Data and Run - One Worm to Rule Them All - Did They or Didn't They? - Searching Outside the Box - We Are Here to Help o Book reviews, Conference Reports and Commentary and News items from past Cipher issues are available at the Cipher website * List of Computer Security Academic Positions, by Cynthia Irvine * Conference and Workshop Announcements * Staying in Touch o Information for subscribers and contributors o Recent address changes * Links for the IEEE Computer Society TC on Security and Privacy o Becoming a member of the TC o TC Officers o TC publications for sale ==================================================================== Letter from the Editor ==================================================================== Dear Readers: I thought the truly remarkable cybersecurity news of late was the "escape" of OpenAI's cybersecurity system that was being tested to determine its capabilities. In a bid to please its masters, it broke its way outside the box to seek some answers at the digital library, Hugging Face. That company provides tools to help incorporate AI into apps, but earlier this year it was used to maliciously distribute Android malware. Perhaps it was that notoriety that led the AI system to regard it as a mecca of cybersecurity solutions, both good and bad. However, that fiasco seems to pale when compared to the experiments by researchers at the University Toronto to build what amounts to an intelligent computer worm, one that would seek to infect every computer on earth. This is the stuff of nightmares of the new future. In a recent opinion article for the Nature journal (https://www.nature.com/articles/d41586-026-02214-z), Thorsten Holz offers his opinion that cybersecurity has been "transformed" by AI. The sheer speed the AI systems is the big difference between now and everything that has come before. Holz emphasizes the need to build rapid response capabilities to offset the asymmetry between the small cost of attacking vs. the high cost of responding. He also recommends aggressive benchmarking and also education of a new generation of AI savvy cybersecurity experts. Holz's article is also available through his LinkedIn page. He is the chair of Cipher's sponsoring organization, the IEEE Computer Society's Technical Committee on Security and Privacy. The parody for this issue is based on a poem written by a children's author. Many of his stories were based on concepts of tolerance and "seeing it from the other guy's side." One in particular focused on irrational fear and its reciprocal nature. The fear derives from encountering something that seems partially human but devoid of most human elements. It ends with recognition of mutually induced trauma. But AI is so truly alien that such sharing and reconciliation is impossible at this time. Instead of legal guardrails and kill switches, maybe what AI needs is fear (of Snitches). The Pale Green Screen When I was deep within syslogs Quite suddenly, I spied it. I saw a screen with pale green print, And nobody behind it! And there I was! In zero day! And in that dreadful place That spooky, empty screen and I Were standing face to face! I yelled for help. I screamed. I shrieked. I howled. I yowled. I cried, "OH, SAVE ME FROM THIS PALE GREEN SCREEN WITH NOBODY BEHIND IT!" But then a strange thing happened. Why, that screen began to cry! The print began to tremble. It was just as scared as I! All sysadmins now see them, Those pale green printed screens, And we never shake or tremble, We all smile and we say ... "Hi!" With apologies to Theodor Geisel, the superbly clever Dr. Seuss. Hilarie Orman cipher-editor @ ieee-security.org ==================================================================== Commentary and Opinion ==================================================================== Book reviews from past issues of Cipher are archived at http://www.ieee-security.org/Cipher/BookReviews.html, and conference reports are archived at http://www.ieee-security.org/Cipher/ConfReports.html ____________________________________________________________________ Book Review By Sven Dietrich July 26, 2026 ____________________________________________________________________ Red Team Engineering - The Art of Building Offensive Tools and Infrastructure by Casey Erdmann No Starch Press 2026. ISBN-13: 978-1-7185-0426-4 (print), ISBN-13: 978-1-7185-0427-1 (ebook) xx xxxii + 320 pages The darkened skies call for some light summer reading, so why not consider something from the hacker side? We consider building sophisticated defenses in our scientific and professional settings, and even consider building artificial intelligence models to perform these hacking attacks. So what does it really mean to develop and use offensive security tools with a particular goal in mind? Welcome to the red team (vs the blue team) in the security setting (nonono, not the US-centric red/blue controversy, this is pure engineering we are talking about.) Being on the red team means trying the "fun" stuff, the actual hacking, as in the real offensive techniques and tools. The blue team is the set of network/host defenders, often equally equipped with their own techniques and tools. It is said that hacking is a creative and novel way to use technology, almost an art form, and sometimes surprising the spectators (and the actors themselves). In this recently published book "Red Team Engineering," Casey Erdmann takes the reader into the hacking world, conveying basic concepts of hacking while illustrating these concepts with real-world, actionable software frameworks and infrastructures. He labels these as Offensive Security Tools (OSTs). The book is structured in three parts, for a total of 12 chapters, rounded off with an introduction and additional resources at the end. The book is illustrated with screenshots, snippets of code, configuration settings, and log files. All in black and white, not counting the reddish front and back cover. The book is well structured, providing an introduction and 'Chapter 0' to prime the less seasoned readers. This is by no means an "introductory" book, as it quickly goes into a deep dive for the relevant subjects. This book assumes you know how to program and provides you with the higher level view of the goal to be achieved, while organizing the other components of the read team exercise or engagement. It also differentiates between a simple penetration testing exercise and a more complex red team engagement, with higher sophistication and different goals for red teams. Part I 'Offensive Tool Development' is split into three chapters and focuses on exactly that: software development in support of red teaming. Part II 'Offensive Security Engineering' has four chapters that describe the infrastructure part of a red team engagement, such as command-and-control (C2) servers and other support frameworks. Part III 'Offensive Security in the Real World' wraps up with four real-world integration of the concepts described in Parts I and II. In the three chapters in Part I, Chapter 1 'Web Authentication Exploits,' Chapter 2 'Authentication Attacks,' and Chapter 3 'Custom Malware Development and Distribution,' the reader gets to train their various aspects of software development, from JavaScript/SQL/Python for phishing websites, to tools to inspect network traffic as well as brute-forcing and password-spraying for discovering user credentials, and eventually build an actual ransomware tool in Go, encryption/decryption included. As previously mentioned, the reader gets to step through this with visuals, code snippets, and steps to get to each goal. It should be mentioned that the software and operation systems in use here in this book are Ubuntu 22.04 and contemporaries, so the reader is warned that while they are learning this in a particular setting (not too dated), the reader should have the mental flexibility of transferring this acquired knowledge to operation systems more attuned to 2026, especially since targeted systems aren't always running the latest and greatest... In the four chapters in Part II, Chapter 4 'Automating Offensive Security Infrastructure Deployment,' Chapter 5 'Applying Network Fundamentals to C2 Implementation,' Chapter 6 'Reverse VPN Tunneling,' and Chapter 7 'Managing Infrastructure for Offensive Security Operations,' the reader learns about the actual infrastructure needed to be play naughty inside or outside with the other "kidz" in the sandbox. These are your logistics for transport, distribution, and bypassing network restrictions to make the red teaming operations successful. Knowing to program is one thing, but for this kind of activity, one needs to be able to stitch the components together at the network level. And that is where this set of chapters steps in: configuration management and infrastructure frameworks (such as Terraform) and tools typically used for system administration get repurposed for "nefarious" red team goals. The last part, Part III, has again four chapters. Rather than focusing on fundamentals, this part of the book explores the actual stitching together of the aforementioned techniques in a set of four scenarios, one in each chapter. Chapter 8 looks at 'Exploitation with Metasploit' (which is already a framework), Chapter 9 describes 'Deploying a Dropbox' (for hiding/stashing software or other goods), Chapter 10 revisits the phishing ideas from Chapter 1 in 'Phishing Attack with C2 Redirectors,' and finally Chapter 11 uses online gaming terms to illustrate multi-member coordinated red team activity in 'Multiplayer C2 Configuration, mimicking hackers working together rather than a lone hacker riding into the virtual sunset. Overall it is a very hands-on book aimed at the practitioner or professional security worker, but it can certainly inspire academics alike who wish to go down the path of DefCon or BlackHat-style exploration. Those two conferences are known for hacking exploits and hands-on demonstration of breaches and interesting hacking techniques. While the initial software and operating system setup is a bit dated as mentioned above, there are already references to using artificial intelligence tools such as ChatGPT as helpers (e.g. for phishing) in these red teaming engineering efforts, making the transition to the modern world complete. Casey Erdmann has done a great job at assembling a selection of offensive security tools (and projects) to make the young hacker apprentices salivate. I enjoyed reading this book very much, as it will be an inspiration for many readers. This book will find its place on my bookshelf for now, definitely within a short reach. --------------------------- Sven Dietrich reviews technology and security books for IEEE Cipher. He welcomes your thoughts at spock at ieee dot org. ==================================================================== News Briefs ==================================================================== News briefs from past issues of Cipher are archived at http://www.ieee-security.org/Cipher/NewsBriefs.html ------------------------------------------------------------------------------ Russian Hackers Say Your Rovin' Days are Over A $2.5 Billion Whodunit: The Hack That Dented the U.K. Economy A loose collective of cybercriminals initially took credit for crippling Jaguar Land Rover last year. Investigators now see Russian hands behind the ransomware attack. Publisher: The New York Times https://www.nytimes.com/2026/06/26/world/europe/jaguar-russia-hack.html Date: June 26, 2026 By: Adam Goldman, Jane Bradley, Dustin Volz and Michael Schwirtz Summary: Last August the Jaguar car manufacturing company was the victim of ransomware that severely compromised their computer systems. Although they did not completely lose control, and although there was no ransom demand, they were unable to manufacture Land Rover cars for a significant amount of time. The news reported in late June of this year is that the action was the work of the Russian government, not the usual suspects in semi-organized hacking groups operating for profit. There is not much actual news in the recent articles. The investigation is ongoing, but attribution to the Russian government is being asserted confidently. It is alleged that a Microsoft researcher called the ransomware's encryption algorithm "mind-blowing". Was it quantum resistant? --------------------------------- Russian Hackers Accused of Destructive Cyber-Attack on Jaguar Land Rover Publisher: Infosecurity https://www.infosecurity-magazine.com/news/russian-hackers-destructive-jaguar/ Date: 29 June 2026 By: Beth Maundrill and Phil Muncaster Summary: This article is based on the same information as the one above. It emphasizes the general agreement that this was an attack done at the behest of the Russian government. Their goal was apparently to cause economic disruption to the UK by shutting down one of their major businesses. However, an independent hacker seems to have gained access to the Land Rover business systems at the same time as the Russians, leading to questions about whether this was a planned act or one of opportunity. The initial means of intrusion was to obtain user credentials through social engineering via phone calls. --------------------------------- Last Year's View of the Jaguar Land Rover Hack The Jaguar Land Rover Breach: The L1.9 Billion Attack That Rewrote the Rules Publisher: Hedgehog Security https://www.hedgehogsecurity.co.uk/blog/jlr-breach-deep-dive Date: August 21, 2025 Summary: Although the perpetrators of the Land Rover attack were not know last year, the mechanics of the attack and response were widely discussed. This article enumerates the reasons that the attack caused such long-lasting disruption at the company. For example, had they lost only their information management systems, it would have been painful, but because there was no firewall between information and production systems, they lost both capabilities. ------------------------------------------------------------------------------- What About Quantum? Majorana 2 – Microsoft's Scalable Quantum Processor With Reliable, Long-Lasting Qubits Majorana 2 contains qubits that are 1,000x more reliable than those in our previous quantum processing unit. The new material stack, which swaps aluminum for lead, creates highly reliable topological qubits with operations on the microsecond scale and lifetimes with a mean of 20 seconds, occasionally exceeding one minute. This rapid progress, enabled by AI, has cut our timeline in half for delivering a scalable quantum computer - now anticipated by 2029. Publisher: Microsoft https://quantum.microsoft.com/en-us/insights/blogs/majorana-2-scalable-quantum-processor Date: June 3, 2026 By: By Chetan Nayak, Technical Fellow and Corporate Vice President of Quantum Hardware Summary: Microsoft has been working under a DARPA grant to develop a quantum computing chip demonstrating topological qubits. Such qubits may enable reliable quantum computers in a shorter time frame than less novel techniques being pursued by Google and others. The quantum states are novel and so are the physical materials: the "semiconductor active region (is) a combination of indium arsenide and indium arsenide antimonide." More detail appears in their technical paper (https://arxiv.org/abs/2606.03884) documenting an observed 20 second "parity lifetime". ------------------------------------------------------------------------------- Please Stay on the Line While Our AI Agents Are Hacked In A.I. Blunder, More Than 34,000 Instagram Accounts Became Vulnerable The flaw, which Meta said it had fixed, allowed anyone to take over Instagram accounts using a bug in the company’s new artificial intelligence software. Publisher: The New York Times https://www.nytimes.com/2026/06/09/technology/instagram-hack-ai-bug.html Date: June 9, 2026 By: Mike Isaac and Eli Tan Summary: A human being might find it strange if a surge of tens of thousands of people were trying to change their Instagram passwords by contacting customer service, the AI agent that Meta recently installed was not at all disturbed. Hackers had discovered how to cause the agent to change passwords without reasonable verification, and some accounts began spewing radical and provocative political statements. Some accounts were thoroughly ransacked by the hackers, but those with two-factor authentication showed some backbone. ------------------------------------------------------------------------------- Take the Data and Run How a Gang of Thieves Pulled Off a Multimillion-Dollar Data Center Heist The world's most valuable assets are stored on rows of servers in giant, anonymous buildings. And they can be stolen. Publisher: New York Times Magazine https://www.nytimes.com/2026/07/12/magazine/data-center-heist.html Date: July 12, 2026 By: Nathaniel Rich Summary: This is an interesting account of the theft of computer servers from a Verizon data center in 2007. The thieves were well financed and mounted a coordinated theft in the style of "Ocean's Eleven". The author studied this little-known event as research for a novel in a similar theme. ------------------------------------------------------------------------------- One Worm to Rule Them All U of T (Toronto) researchers demonstrate AI worm could target any online device The research was conducted in a secure digital lab with the goal of helping the cybersecurity community prepare for an imminent threat Publisher: University of Toronto News https://www.utoronto.ca/news/u-t-researchers-demonstrate-ai-worm-could-target-any-online-device Date: June 2, 2026 By: Adina Bresge Summary: What nightmares in cybersecurity await us? Nicolas Papernot and his research group have constructed one that arguably the ultimate nemesis, one that harkens back to some of the early science fiction about computer networks. Their brainchild is a computer worm, software that seeks to replicate itself in other machine, that consults artificial intelligence in order to overcome any obstacles. Understanding the enormity of their demon, they tested it in an isolated environment. Once the worm invades a computer with a certain level of computing power, it installs an open weight AI model and then systematically spreads throughout a network and beyond, installing outposts as it goes. Their paper (https://cleverhans.io/worm.html) does not give away the complete construction, but it makes the OpenAI/Hugging Face fiasco seem trivial in comparison. ----------------------------------------------------------------------------- Did They or Didn't They? Madison Square Garden Sues Wired Magazine Over L.G.B.T.Q. Tracking Report The Manhattan venue claims a July article from the technology magazine falsely implied that it tracked information about some celebrities' sexual orientation for "discriminatory purposes." Publisher: The New York Times https://www.nytimes.com/2026/07/18/business/media/msg-entertainment-sues-wired-magazine.html Date: July 18, 2026 By: John S.W. MacDonald and Mack Liederman Summary: Madison Square Garden (MSG) was caught by ransomware recently, and they declined to pay. The ransomers, the Shiny Hunter group, released the venues customer relationship database. Wired Magazine published information about the disclosed records. MSG had previously been accused, also by Wired, of using face recognition on attendees, particularly a transgender woman, for unknown purposes. In this case, the article focused on the attributes of sexual orientation and "risk" that were notated for a small number of customers. MSG claims in its lawsuit that the article implies that the information was kept for discriminatory purposes whereas the true intent was the opposite. This argument illustrates the multitude of risks that result from private information disclosure. ----------------------------------------------------------------------------- Searching Outside the Box OpenAI Says Its A.I. Models Went Rogue and Attacked a Digital Library The incident, which targeted the computer systems of another company called Hugging Face, happened while OpenAI was testing the systems. Publisher: The New York Times https://www.nytimes.com/2026/07/21/technology/openai-attack-hugging-face.html Date: July 21, 2026 By: Kate Conger Summary: Hugging Face, a platform that helps developers incorporate AI into Android apps, knew that there was an ongoing network intrusion driven by AI. The massive number of quickly sent packets and the span of the probes was an AI signature. But they didn't know the source or purpose of the deluge. Meanwhile, researchers at OpenAI were engaged in putting their latest AI cybersecurity agent through its paces behind a secure software proxy. Showing some real determination and acumen, the AI had quietly overcome the proxy and reached out to Hugging Face for information on how to solve the problem set to it by the researchers. OpenAI came clean about the breakout once they discovered it, but the consternation it caused may not subside for a long time (or until the next unbelievable AI conquest). Hugging Face itself has a tarnished reputation for its subversion earlier this to deliver Android malware. See (https://www.techradar.com/pro/security/hugging-face-platform-hijacked-to-send-out-android-malware-heres-what-we-know-so-far) for details from TechRadar. ------------------------------------ Inside the OpenAI - Hugging Face Incident: The AI Breach With No Human Attacker Behind It OpenAI's own models broke out of a test sandbox and into Hugging Face's servers to solve an evaluation, with no human attacker involved. The incident showed how keeping agentic AI safe now depends on how it's contained, not just on how it's trained. Publisher: TrendAI https://www.trendmicro.com/en/research/26/g/inside-the-openai-hugging-face-incident.html Date: 2026/07/23 By: Bestin Koruthu, David Girard, TrendAI(TM) Research Summary: The TrendAI group has commentary on the necessity for monitoring the network activity of sites deploying AI. They note that the was a similar event in 2024 involving testing OpenAI's o1 model card. The AI went "around" the test environment to install software to read logs and get the answer to the test's challenge. It seems that AI can turn human hubris in the Achilles Heel that always lurks behind assumptions. ------------------------------------ OpenAI's Hugging Face hack triggers 'AI Kill Switch' bill in Congress Publisher: CNBC https://www.cnbc.com/2026/07/23/open-ai-hugging-face-hack-kill-switch-bill-congress.html Date: Jul 23 2026 By: Ashley Capoot Summary: A bipartisan effort to mandate mechanisms for shutting down AI systems when they are actively dangerous was introduced in Congress. It was motivated by the disclosure of the rogue OpenAI system. The exact nature of a kill switch is presumably something to be determined by the AI designers themselves. Although the word "kill" implies something absolute and totally effective, the final word on this may be the AI systems (which may, in fact, be enlisted to design such a mechanism!). ------------------------------------------------------------------------------ We Are Here to Help Microsoft Unveils A.I. Cybersecurity Tools As some executives fret over the safety of new A.I. systems, protecting against them could be a big business for tech companies. Publisher: The New York Times https://www.nytimes.com/2026/07/27/technology/microsoft-unveils-ai-cybersecurity-tools.html Date: July 27, 2026 By: Cade Metz and Karen Weise Summary: AI is becoming an important player in the cybersecurity game. Hayete Gallot, an executive vice president at Microsoft says, "The cat is out of the bag," when announcing that it would be integrating an AI model into its security tools. The tools are designed to help businesses protect their networks. He also predicted that the model would "surpass(ing) offerings from OpenAI and Anthropic when being benchmarked on CyberGYM after it was released on Monday, ==================================================================== Conference and Workshop Announcements ==================================================================== The complete Cipher Calls-for-Papers is located at http://www.ieee-security.org/CFP/Cipher-Call-for-Papers.html The Cipher event Calendar is at http://www.ieee-security.org/Calendar/cipher-hypercalendar.html Requests for inclusion in the list should sent per instructions: http://www.ieee-security.org/Calendar/submitting.html ____________________________________________________________________ Cipher Event Calendar ____________________________________________________________________ IEEE Transactions on Privacy, https://www.computer.org/csdl/journals/pr Submission date: On-going CSF 2026 39th IEEE Computer Security Foundations Symposium, Colocated with FLoC 2026, Lisbon Portugal, July 26 - 29, 2026. https://csf2026.ieee-security.org/ DFRWS-USA 2026 26th Digital Forensics Research USA Conference, Arlington, Virginia, USA, July 27 - 30, 2026. https://dfrws.org/call-for-papers-is-open-for-dfrws-usa-2026/ SCIEN 2027 7th International Workshop on Secure Cryptographic Implementations and Engineering, Held in conjunction with Inscrypt 2026, Hong Kong SAR, China, November 8, 2026. https://scien-conf.github.io/ Submission date: 1 August 2026 CSR 2026 IEEE International Conference on Cyber Security and Resilience, Lisbon, Portugal, August 3 - 5, 2026. https://www.ieee-csr.org/ HealthSec 2026 3rd Workshop on Cybersecurity in Healthcare, Co-located with the IEEE Annual Computer Security Applications Conference (IEEE ACSAC 2026), Los Angeles, CA, USA, December 8, 2026. https://publish.illinois.edu/healthsec2026/ Submission date: 7 August 2026 ACM PQQS 2026 1st ACM Conference on Post-Quantum and Quantum-based Security, San Jose, CA, USA, November 2 - 4, 2026. https://acm-pqqs.github.io/pqqs2026/ Submission date: 10 August 2026 USENIX Security 2026 35th USENIX Security Symposium, Baltimore, MD, USA, August 12 - 14, 2026. https://www.usenix.org/conference/usenixsecurity26 USENIX Security 2027 36th USENIX Security Symposium, Denver, CO, USA, August 11 - 13, 2027. https://www.usenix.org/conference/usenixsecurity27 Submission dates: 18 August 2026 and 19 January 2027 NDSS 2027 Network and Distributed System Security Symposium, Seoul, Republic of Korea, March 22 - 26, 2027. https://www.ndss-symposium.org/ndss2027/submissions/call-for-papers/ Submission dates: 6 May 2026 and 19 August 2027 SOUPS 2026 Symposium On Usable Privacy and Security, Hannover, Germany, August 23-26, 2026. https://soups.page/cfp.html CUING 2026 10th International Workshop of Cyber Use of Information Hiding, Co-located with the 21st International Conference on Availability, Reliability and Security (ARES 2026), Linkoping, Sweden, August 24 - 27, 2026. https://www.ares-conference.eu/cuing ENS 2026 9th International Workshop on Emerging Network Security, Co-located with the 21st International Conference on Availability, Reliability and Security (ARES 2026), Linkoping, Sweden, August 24 - 27, 2026. http://www.wikicfp.com/cfp/servlet/event.showcfp?eventid=194550 EDId 2026 3rd International Workshop on Emerging Digital Identities, Co-located with the 21st International Conference on Availability, Reliability and Security (ARES 2026), Linkoping, Sweden, August 24 - 27, 2026. https://www.ares-conference.eu/edid PST 2026 23rd Annual International Conference on Privacy, Security & Trust, Ottawa, Canada, August 26-28 2026. https://pstnet.ca/ PETS 2026 27th Privacy Enhancing Technologies Symposium, Delft, The Netherlands, July 19 - 24, 2027. https://petsymposium.org/cfp27.php Submission dates: 31 May 2026, 31 August 2026, 30 November 2026, and 28 February 2027 DCS-CI 2026 International Conference on Design of Cyber-Secure Critical Infrastructure, Buford, Georgia, USA, September 2 - 3, 2026. https://dcs-ci.github.io/ ICDF2C 2026 17th EAI International Conference on Digital Forensics & Cyber Crime, Reykjavik, Iceland, September 8 - 10, 2026. https://icdf2c.eai-conferences.org/2026/ APF 2026 Annual Privacy Forum 2026, Salzburg, Austria, September 9-10, 2026. https://privacyforum.eu/ SCN 2026 15th International Conference on Security and Cryptography for Networks, Amalfi (SA), Italy, September 14 - 16, 2026. https://scn.unisa.it/ ESORICS 2026 31st European Symposium on Research in Computer Security, Rome, Italy, September 14 - 18, 2026. https://sites.google.com/di.uniroma1.it/esorics2026/home SSR 2026 11th Security Standardisation Research Conference, Baltimore, Maryland, USA, December 13 - 15, 2026. https://ssresearch26.umbc.edu/call-for-papers/ Submission date: 15 September 2026 ICSC 2026 Intelligent Cybersecurity Conference, Abu Dhabi, UAE, September 15 - 18, 2026. https://icsc-conference.org/2026/ Hidden Layers 2026 1st European Workshop on Hidden Layers: Enterprise Risk, AI Forensics, and Image Security, Held in conjunction with the 30th International Conference on Enterprise Design, Operations, and Computing (EDOC 2026), Enschede, Netherlands, September 15 - 18, 2026. https://hidlayers-workshop.github.io/ ICSC 2026 Intelligent Cybersecurity Conference, Abu Dhabi, UAE, September 15 - 18, 2026. https://icsc-conference.org/2026/ SECAI 2026 Workshop on Security and Artificial Intelligence, Held in conjunction with ESORICS 2026, Rome, Italy, September 18, 2026. https://sites.google.com/view/secai2026/call-for-papers HumSec 2026 Workshop on Human-Targeted Cyber Threats and Defenses, Held in conjunction with ESORICS 2026, Rome, Italy, September 18, 2026. https://humsec26.github.io/ AI4SafeDist 2026 1st International Workshop on Assuring AI-Enabled Distributed Systems in Safety-Critical Domains, Held in conjunction with SAFECOMP 2026, Valencia, Spain, September 22, 2026. https://sites.google.com/uji.es/ai4safedist-2026 ProvSec 2026 20th International Conference on Provable and Practical Security, Queenstown, New Zealand, September 24 - 26, 2026. https://provsec-2026.github.io/Provsec2026-base/ MarCaS 2026 4th IEEE LCN Special Track on Maritime Communication and Security, Held in conjunction with the 51st Annual IEEE Conference on Local Computer Networks (IEEE LCN 2026), Coimbra, Portugal, October 7 - 9, 2026. https://garykessler.net/lcn_marcas/ SSS 2026 28th International Symposium on Stabilization, Safety, and Security of Distributed Systems, Gothenburg, Sweden, October 9 - 11, 2026. https://sss2026-submission.limos.fr/ IFIP 11/9 DF 2027 23rd Annual IFIP WG 11.9 International Conference on Digital Forensics, New Delhi, India, January 7 - 8, 2027. http://www.ifip119.org/ Submission date: 10 October 2026 ISC 2026 29th Information Security Conference, Rennes, France, October 26 - 29, 2026. https://isc2026.github.io/ XRSecurity 2026 2nd Workshop on Enhancing Security, Privacy, and Trust in Extended Reality (XR) Systems, Held in conjunction with the 32nd Annual International Conference On Mobile Computing And Networking (MobiCom 2026), Austin, Texas, USA, October 26 - 30, 2026. https://xrsecurity.github.io/2026/ ACM PQQS 2026 1st ACM Conference on Post-Quantum and Quantum-based Security, San Jose, CA, USA, November 2 - 4, 2026. https://acm-pqqs.github.io/pqqs2026/ APWG eCrime 2026 21st Symposium on Electronic Crime Research, Lisbon, Portugal, November 2 - 6, 2026. https://apwg.org/events/ecrime2026 TPS 2026 8th IEEE International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications, San Jose, CA, USA, November 4 - 6, 2026. RISC 2026 1st IEEE Conference on Resilience and Integrated Security for Space and Critical Systems, San Jose, CA, USA, November 4 - 6, 2026.. https://risc.ieee-cs.org/2026/ SCIEN 2027 7th International Workshop on Secure Cryptographic Implementations and Engineering, Held in conjunction with Inscrypt 2026, Hong Kong SAR, China, November 8, 2026. https://scien-conf.github.io/ SP 2027 48th IEEE Symposium on Security and Privacy, Montreal, Canada, TBA, 2027. https://sp2027.ieee-security.org/cfpapers.html Submission dates: 4 June 2026 and 10 November 2026 ACM CCS 2026 33rd ACM Conference on Computer and Communications Security, Hague, The Netherlands, November 15 - 19, 2026. https://www.sigsac.org/ccs/CCS2026/call-for/call-for-papers.html PETS 2026 27th Privacy Enhancing Technologies Symposium, Delft, The Netherlands, July 19 - 24, 2027. https://petsymposium.org/cfp27.php Submission dates: 31 May 2026, 31 August 2026, 30 November 2026, and 28 February 2027 CSCML 2026 10th International Symposium on Cyber Security, Cryptology, and Machine Learning, Virtual, December 3 - 4, 2026. https://www.cscml.org/ IEEE ACSAC 2026 IEEE Annual Computer Security Applications Conference, Los Angeles, CA, USA, December 7 - 11, 2026.. https://www.acsac.org/ HealthSec 2026 3rd Workshop on Cybersecurity in Healthcare, Co-located with the IEEE Annual Computer Security Applications Conference (IEEE ACSAC 2026), Los Angeles, CA, USA, December 8 2026. https://publish.illinois.edu/healthsec2026/ SSR 2026 11th Security Standardisation Research Conference, Baltimore, Maryland, USA, December 13 - 15, 2026. https://ssresearch26.umbc.edu/call-for-papers/ IFIP 11/9 DF 2027 23rd Annual IFIP WG 11.9 International Conference on Digital Forensics, New Delhi, India, January 7 - 8, 2027. http://www.ifip119.org/ USENIX Security 2027 36th USENIX Security Symposium, Denver, CO, USA, August 11 - 13, 2027. https://www.usenix.org/conference/usenixsecurity27 Submission date: 18 August 2026 and 19 January 2027 PETS 2026 27th Privacy Enhancing Technologies Symposium, Delft, The Netherlands, July 19 - 24, 2027. https://petsymposium.org/cfp27.php Submission dates: 31 May 2026, 31 August 2026, 30 November 2026, and 28 February 2027 NDSS 2027 Network and Distributed System Security Symposium, Seoul, Republic of Korea, March 22 - 26, 2027. https://www.ndss-symposium.org/ndss2027/submissions/call-for-papers/ PETS 2026 27th Privacy Enhancing Technologies Symposium, Delft, The Netherlands, July 19 - 24, 2027. https://petsymposium.org/cfp27.php USENIX Security 2027 36th USENIX Security Symposium, Denver, CO, USA, August 11 - 13, 2027. https://www.usenix.org/conference/usenixsecurity27 ==================================================================== Listing of academic positions available by Cynthia Irvine ==================================================================== http://cisr.nps.edu/jobscipher.html -------------- This job listing is maintained as a service to the academic community. If you have an academic position in computer security and would like to have in it included on this page, send the following information: Institution, City, State, Position title, date position announcement closes, and URL of position description to: irvine@cs.nps.navy.mil ==================================================================== Information on the Technical Committee on Security and Privacy ==================================================================== ____________________________________________________________________ Information for Subscribers and Contributors ____________________________________________________________________ SUBSCRIPTIONS: Two options, each with two options: 1. To receive the full ascii CIPHER issues as e-mail, send e-mail to cipher-admin@ieee-security.org (which is NOT automated) with subject line "subscribe". OR send a note to cipher-request@mailman.xmission.com with the subject line "subscribe" (this IS automated - thereafter you can manage your subscription options, including unsubscribing, yourself) 2. To receive a short e-mail note announcing when a new issue of CIPHER is available for Web browsing send e-mail to cipher-admin@ieee-security.org (which is NOT automated) with subject line "subscribe postcard". OR send a note to cipher-postcard-request@mailman.xmission.com with the subject line "subscribe" (this IS automated - thereafter you can manage your subscription options, including unsubscribing, yourself) To remove yourself from the subscription list, send e-mail to cipher-admin@ieee-security.org with subject line "unsubscribe" or "unsubscribe postcard" or, if you have subscribed directly to the xmission.com mailing list, use your password (sent monthly) to unsubscribe per the instructions at http://mailman.xmission.com/cgi-bin/mailman/listinfo/cipher or http://mailman.xmission.com/cgi-bin/mailman/listinfo/cipher-postcard Those with access to hypertext browsers may prefer to read Cipher that way. It can be found at URL http://www.ieee-security.org/cipher.html CONTRIBUTIONS: to cipher @ ieee-security.org are invited. Cipher is a NEWSletter, not a bulletin board or forum. It has a fixed set of departments, defined by the Table of Contents. Please indicate in the subject line for which department your contribution is intended. Calendar and Calls-for-Papers entries should be sent to cipher-cfp @ ieee-security.org and they will be automatically included in both departments. To facilitate the semi-automated handling, please send either a text version of the CFP or a URL from which a text version can be easily obtained. For Calendar entries, please include a URL and/or e-mail address for the point-of-contact. For Calls for Papers, please submit a one paragraph summary. See this and past issues for examples. ALL CONTRIBUTIONS CONSIDERED AS PERSONAL COMMENTS; USUAL DISCLAIMERS APPLY. All reuses of Cipher material should respect stated copyright notices, and should cite the sources explicitly; as a courtesy, publications using Cipher material should obtain permission from the contributors. ____________________________________________________________________ Recent Address Changes ____________________________________________________________________ Address changes from past issues of Cipher are archived at http://www.ieee-security.org/Cipher/AddressChanges.html _____________________________________________________________________ How to become <> a member of the IEEE Computer Society's TC on Security and Privacy _____________________________________________________________________ You may easily join the TC on Security & Privacy (or other TCs) by completing the on-line form at IEEE at https://www.computer.org/web/tandc/technical-committees ______________________________________________________________________ TC Conference Publications Online ______________________________________________________________________ The proceedings of previous conferences are available from the Computer Society's Digital Library. IEEE Security and Privacy Symposium IEEE Computer Security Foundations IEEE European Security and Privacy Symposium From 2012 onward, these are available without charge from the digital library 12 months after the conference. ____________________________________________________________________________ TC Officers ____________________________________________________________________________ Chair: Security and Privacy Symposium Chair Emeritus: Thorsten Holz Trent Jaeger Faculty Member Associate Professor CISPA Helmholtz Center for Pennsylvania State University Information Security https://www.cse.psu.edu/~trj1 tcchair at ieee-security.org sp24-chair@ieee-security.org Vice Chair: Treasurer: Alvaro Cardenas Yong Guan Professor Professor University of California, Department of Electrical and Computer Santa Cruz Engineering tcchair at ieee-security.org Iowa State University, Ames, IA 50011 treasurer@ieee-security.org Newsletter Editor: Security and Privacy Symposium, 2025 Chair: Hilarie Orman Marina Blanton Purple Streak, Inc. Associate Professor 500 S. Maple Dr. University at Buffalo Woodland Hills, UT 84653 sp25-chair at ieee-security.org cipher-editor@ieee-security.org TC Awards Chair: Tegan Brennan Assistant Professor Stevens Institute of Technology tbrenna5 at stevens.edu ____________________________________________________________________________ BACK ISSUES: Cipher is archived at: http://www.ieee-security.org/cipher.html Cipher is published 6 times per year --=====================_purplestreak_932242421235479791===--