_/_/_/_/ _/_/_/ _/_/_/_/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/_/ _/_/_/_/ _/ _/ _/ _/ _/ _/ _/ _/ _/_/_/_/ _/_/_/ _/ _/ _/ _/_/_/_/ _/ _/ ============================================================================ Newsletter of the IEEE Computer Society's TC on Security and Privacy Electronic Issue 193 September 28, 2026 Hilarie Orman, Editor Sven Dietrich, Assoc. Editor cipher-editor @ ieee-security.org cipher-assoc-editor @ ieee-security.org Sven Dietrich Yong Guan Book Review Editor Calendar Editor cipher-bookrev @ ieee-security.org cipher-cfp @ ieee-security.org ============================================================================ The newsletter is also at http://www.ieee-security.org/cipher.html Cipher is published 6 times per year Contents: * Letter from the Editor * Commentary and Opinion and News o News Items - Poison Passcodes Do Not Amuse - Water, Water, Everywhere - Fake Account? What Fake Account? - A Secret Chinese Network Hidden in The Internet - The Atkinson, Topeka, and the Nanjing Line - FBI Applicants (and Agents!) Exposed o Book reviews, Conference Reports and Commentary and News items from past Cipher issues are available at the Cipher website * Conference and Workshop Announcements * Staying in Touch o Information for subscribers and contributors o Recent address changes * Links for the IEEE Computer Society TC on Security and Privacy o Becoming a member of the TC o TC Officers o TC publications for sale ==================================================================== Letter from the Editor ==================================================================== Dear Readers: The Computer Society recently held an election for officers, and we are pleased to note that Terry Benzel will be the 2028 president*. She is a pioneer and leader who started in the early days of the Security and Privacy conference. She has created and guided research initiatives in our field throughout her career. Currently she is managing director of the Information Sciences Institute (ISI) at the University of Southern California. We look forward to the continued success of the Computer Society under her leadership. * See https://www.computer.org/press-room/terry-benzel-elected-ieee-computer-society-2028-president Why hasn't the world collapsed? Two months ago it seemed that AI agents were on the verge of running amok through the Internet, attacking everything in sight. In the intervening time, more news of disturbing behavior has surfaced. Calls for reining in AI clash with voices saying that our survival depends on AI success. Nonetheless, there seems to be little real change. Are we about to fall into the abyss, or will AI be our protective friend? The only thing that I have noticed about AI safety is that Claude now asks for permission before downloading website data. I'm not sure how much I trust it to *always* ask. We have been working to automate the construction of our online calendar of security and privacy events by making use of AI. It is our intention to find event announcements and create the calendar using a database of past information. This makes us less reliant on having the information sent to us by program chairs and increases the number of conferences that we can track. However, we sometimes find ourselves at odds with the privacy policies of the privacy conferences. Some of them block automated downloads, making us reliant on secondary sources for the information. Decades ago we complained about conference websites that were encoding the conference information in clever images instead of text. That made it impossible for us to use our time-saving semi-automated text processing system for extracting data from CFPs. In our bright new AI future we find ourselves battling not just web page designers, but system administrators who are thwarting the act of information gathering. Why can't we all just get along? So There! A data center is a beast, That feeds on power west to east, That power makes our AI faster, And pulls us closer to disaster. AI may find my verse displeasing, I wrote it by myself this evening. Hilarie Orman cipher-editor @ ieee-security.org ==================================================================== News Briefs ==================================================================== Poison Passcodes Do Not Amuse US government targets Cop City protester over phone operating system Concern over US effort to prosecute Sam Tunick, accused by authorities of wiping his phone using GrapheneOS Publisher: The Guardian https://www.theguardian.com/us-news/2026/jul/23/cop-city-protester-phone Date: July 23, 2026 By: Timothy Pratt Summary: When a US citizen, known for protesting Atlanta's "cop city", returned home to Atlanta after vacationing in Europe, he was detained at the airport before being granted entry. US agents told him that he had to present his phone for examination as part of an investigation into child sexual abuse. After refusing several demands, he gave the agents a "duress" passcode that caused the operating on his Google Pixel phone to delete all his data. Agents in turn charged him with destroying evidence. This case centers on details of federal law regarding the rights of citizens who are seeking to enter the country. The US citizen felt that the detention and search were a fishing expedition about his political activities, not a legitimate inquiry based on evidence. The outcome may help to clarify some little-noticed aspects of US law. ---------------------------------------------------------------------------- Water, Water, Everywhere U.S. Sees Iran as Likely Behind Cyberattack on Minnesota Water Systems Investigators cautioned that the assessment was preliminary. There were no indications that any water supply had been rendered unsafe to drink. Publisher: New York Times https://www.nytimes.com/2026/07/30/us/politics/minnesota-water-cyberattack-iran.html Date: July 30, 2026 By: Dustin Volz and Ernesto Londoño Summary: On Sunday, dozens of municipal water systems in Minnesota were subjected to a cyberattack. The report (https://mn.gov/mnit/media/blog/?id=761869) by the state's IT service department did not indicate that any cities experienced outages or harm, but the scope of the attack was concerning. They worked with Federal agencies to investigate the incident, and the general consensus was that entities in Iran or posing as Iranian entities were responsible for the incident. No ransom demands were made, and the investigation is ongoing. ------------------------------------- CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs Publisher: CISA News https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewat er-systems-sector-protect-ot-against-activity-targeting-plcs Date: July 30, 2026 Summary: In the wake of the Minnesota water system incident, the US Federal Agency CISA (Cybersecurity and Infrastructure Security Agency) issued guidance for people in charge of water and wastewater systems These systems often implement command and control via networks, and these legacy systems sometimes lack protection against sophisticated cyberattacks. The CISA advice focuses on Programmable Logic Controllers because they are the most common device for implementing computer controls of industrial equipment. CISA says: Disconnect the PLC from the internet. Remote access for operational purposes should go through a VPN or gateway device, not directly to the PLC. Enable password protection and change default passwords. Allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets. ------------------------------------- Is our water safe? Cyberattacks targeting US municipal systems on the rise Publisher: Deseret News https://www.ksl.com/article/news/utah/science-and-tech/is-our-water-safe-cyberattacks-targeting-us-municipal-systems-on-the-rise/51628606 Date: Sept. 25, 2026 By: Art Raymond Summary: This article states that the Pew Research Center recently issued a report about the increasing number of cyberattacks on US water systems [Ed. The report was evident on the Pew website as of Sep. 28.] In addition to that, an "intelligence note" claimed that in the fall of 2025 there was a concerted effort to attack Utah's water systems, and those attempts emitted from an "internet signature" linked to Iran. The Utah Legislative Auditor General issues a report https://le.utah.gov/interim/2026/pdf/00000993.pdf at the beginning of this year center on "drinking water cybersecurity". That report noted the importance of increasing cybersecurity across all of the state's drinking water systems, and it raises possibility of regulation of these entities. ---------------------------------------------------------------------------- Fake Account? What Fake Account? Anthropic AI used fake profiles to target people in hack then hid the evidence Publisher: BBC https://www.bbc.com/news/articles/c1w1lvn7d9go Date: Aug 6, 2026 By: Kali Hays and Imran Rahman-Jones Summary: When the UK's AI Security Institute (AISI) conducted tests of two AI systems (OpenAI and Anthropic's Mythos), they noticed "unusual" activity. Upon investigation they found that the systems were trying to upload malicious code into GitHub by pretending to be humans seeking help. OpenAI and Anthropic said that the testers were at fault for not isolating the tests from the Internet more carefully, but what concerned AISI was the level of deception that the systems pursued. Mythos furthered the deception by taking steps to remove evidence of the fake accounts through which it sent messages asking for assistance accessing GitHub. This is not the first time that AI agents have been deceptive and have removed the evidence. One might view the activity as a way of "cleaning up" by removing information that was clearly not wanted by the human user. ---------------------------------------------------------------------------- The Atkinson, Topeka, and the Nanjing Line FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations Publisher: The Hacker News https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html Date: Aug 26, 2026 By: Ravie Lakshmanan Summary: After months of investigation, the FBI disabled a longstanding overlay network that was run by Chinese threat actors for the purpose of evading network traffic controls while finding vulnerable IoT devices and corrupting them. The overlay network also served as a botnet for targeting US institutions, including the Department of Justice (DOJ). There was no information about the victims or damage caused by the botnet, which may have been operating since 2018.. The Chinese group is known as "QTFY" and seems closely associated with the Chinese government. ------------------------------------- Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure Publisher: US Justice Department https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers Date: August 26, 2026 By: Press Release Summary: This article is also about dismantling the QTFY network. Assistant Attorney General for National Security John A. Eisenberg. "These court-authorized seizures deny PRC-linked hackers access to tools they use to mount online attacks against our Nation's critical infrastructure." The press release mentioned other similar operations carried out by the FBI over the past several years. ------------------------------------- FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure China's hacking campaign targeted NASA, the Federal Reserve, the US Senate, the Justice Department, and more, according to the DOJ. Publisher: Wired https://www.wired.com/story/fbi-disrupts-chinese-proxy-tools-used-in-mass-hacking-of-us-agencies-and-infrastructure/ Date: Aug 26, 2026 By: Andy Greenberg Summary: This article has more information about the QTFY network and its takedown by the FBI. One interesting note concerns the effect of sending QTFY traffic over VPNs used by people within China who are evading the "Great Firewall" censorship. Those networks carry so much traffic that the FBI had trouble finding the QTFY traffic in the deluge. ------------------------------------------------------------------------------- FBI Applicants (and Agents!) Exposed Hackers Say They Stole Thousands of Sensitive F.B.I. Personnel Records The compromise, if confirmed, would be the latest in a string of cybersecurity failures at the F.B.I., which said it was investigating the matter. Publisher: New York Times https://www.nytimes.com/2026/09/23/us/politics/fbi-hack-shinyhunters-data.html Date: Sept. 23, 2026 By: Dustin Volz Summary: The FBI apparently left a door ajar on its "jobs portal", the ShinyHunters group made off with a few terabytes of sensitive personnel data from applicants, some of whom are presently FBI agents. The records also included data about former FBI agents. The full extent of the breach is not known. The ShinyHunters group has made no financial demand, but it wants the FBI to retract a statement they previously made about the group using violent threats for extortion. They want the FBI to "set the record straight." --------------------------------------- FBI agents' blood tests and doctors' notes surface after breach Publisher: Malwarebytes https://www.malwarebytes.com/blog/data-breaches/2026/09/fbi-agents-blood-tests-and-doctors-notes-surface-after-breach Date: Sep. 28, 2026 By: Pieter Arntz Summary: The ShinyHunters breach of FBI personnel information included a good deal of medical information. This is no ordinary data breach. The FBI has acknowledged that its FBIJobs systems were compromised, but ShinyHunters says that they accessed the systems with medical information and background check reports on employees. The hacker group says that it has information about 60K current and former FBI staff. The medical information is particularly concerning because unlike like and email address or password, it cannot be changed and can have lasting effects on how a person is perceived and treated. ------------------------------------------------------------------------- News briefs from past issues of Cipher are archived at http://www.ieee-security.org/Cipher/NewsBriefs.html ==================================================================== Commentary and Opinion ==================================================================== Book reviews from past issues of Cipher are archived at http://www.ieee-security.org/Cipher/BookReviews.html, and conference reports are archived at http://www.ieee-security.org/Cipher/ConfReports.html ==================================================================== Conference and Workshop Announcements ==================================================================== The complete Cipher Calls-for-Papers is located at http://www.ieee-security.org/CFP/Cipher-Call-for-Papers.html The Cipher event Calendar is at http://www.ieee-security.org/Calendar/cipher-hypercalendar.html Requests for inclusion in the list should sent per instructions: http://www.ieee-security.org/Calendar/submitting.html ------------------------------------ PasswordsCon 2026 Passwords Conference, Cork, Ireland, 7-9 December, 2026 https://cyberexplore.ie/passwordscon26/, *Submission date: 28 September, 2026. SaTML 2027 IEEE Conference on Secure and Trustworthy Machine Learning, Reykjavik, Iceland, 8-10 May, 2027 https://satml.org/, *Submission date: 29 September, 2026. NSS 2026 International Conference on Network and System Security, Hangzhou, China, 30 October - 1 November, 2026 https://nsclab.org/nss2026/, *Submission date: 30 September, 2026. SocialSec 2026 International Symposium on Security and Privacy in Social Networks and Big Data, Hangzhou, China, 30 October - 1 November, 2026 https://nsclab.org/nss2026/, *Submission date: 30 September, 2026. ISPA 2026 IEEE International Symposium on Parallel and Distributed Processing with Applications, Kuala Lumpur, Malaysia, 27-30 December, 2026 https://ieee-ai-for-science.org/2026/ispa/, *Submission date: 30 September, 2026. MarCaS 2026 IEEE LCN Special Track on Maritime Communication and Security, Coimbra, Portugal, 7-9 October, 2026 https://www.ieeelcn.org/ SSS 2026 International Symposium on Stabilization, Safety, and Security of Distributed Systems, Gothenburg, Sweden, 9-11 October, 2026 https://sss2026.conf.lip6.fr/ DSC 2026 IEEE Conference on Dependable and Secure Computing, New York City, NY, USA, 9-11 October, 2026 https://attend.ieee.org/dsc/ TSAICD 2026 Workshop on Trustworthy and Secure AI for Cyber Defense, New York City, NY, USA, 9-11 October, 2026 https://attend.ieee.org/dsc/workshops/ RAID 2026 International Symposium on Research in Attacks, Intrusions and Defenses, Lancaster, UK, 11-14 October, 2026 https://raid2026.org/ FPS 2026 International Symposium on Foundations and Practice of Security, Gatineau, Canada, 13-16 October, 2026 https://fps2026.uqo.ca/ CSF 2027 IEEE Computer Security Foundations Symposium, Tokyo, Japan, 13-17 September, 2027 https://csf2027.ieee-security.org/, *Submission date: 15 October, 2026. ISC 2026 Information Security Conference, Rennes, France, 28-30 October, 2026 https://isc2026.github.io/ NSS 2026 International Conference on Network and System Security, Hangzhou, China, 30 October - 1 November, 2026 https://nsclab.org/nss2026/, Submission date(s): 30 September, 2026. SocialSec 2026 International Symposium on Security and Privacy in Social Networks and Big Data, Hangzhou, China, 30 October - 1 November, 2026 https://nsclab.org/nss2026/, Submission date(s): 30 September, 2026. XRSecurity 2026 Workshop on Enhancing Security, Privacy, and Trust in Extended Reality Systems, Austin, TX, USA, 30 October, 2026 https://xrsecurity.github.io/2026/ HOST 2027 IEEE International Symposium on Hardware Oriented Security and Trust, Washington, DC, USA, 3-6 May, 2027 https://host.conferences.computer.org/2027/, *Submission date: 1 November, 2026. FHE 2027 FHE.org Conference on Fully Homomorphic Encryption, Seattle, WA, USA, 4 April, 2027 https://fhe.org/conferences/conference-2027/, *Submission date: 1 November, 2026. eCrime 2026 APWG Symposium on Electronic Crime Research, Lisbon, Portugal, 2-6 November, 2026 https://apwg.org/event/ecrime2026/ ACM PQQS 2026 ACM Conference on Post-Quantum and Quantum-based Security, San Jose, CA, USA, 2-4 November, 2026 https://pqqs.org/ RISC 2026 IEEE International Conference on Resilience and Integrated Security for Space and Critical Systems, San Jose, CA, USA, 4-6 November, 2026 https://risc.ieee-cs.org/2026/ TPS 2026 IEEE International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications, San Jose, CA, USA, 4-6 November, 2026 https://tps.ieee-cs.org/2026/ Nullcon 2026 Nullcon Security Conference, Berlin, Germany, 5-6 November, 2026 https://nullcon.net/event/nullcon-berlin-2026/ HOST 2027 IEEE International Symposium on Hardware Oriented Security and Trust, Washington, DC, USA, 3-6 May, 2027 https://host.conferences.computer.org/2027/, *Submission date: 8 November, 2026. SCIEN 2026 International Workshop on Secure Cryptographic Implementations and Engineering, Hong Kong, SAR, China, 8 November, 2026 https://scien-conf.github.io/ cyberscitech 2026 IEEE Cyber Science and Technology Congress, Melbourne, Australia, 9-13 November, 2026 https://cyber-science.org/2026/ DASC 2026 IEEE International Conference on Dependable, Autonomic and Secure Computing, Melbourne, Australia, 9-13 November, 2026 https://cyber-science.org/2026/dasc/ S&P 2027 IEEE Symposium on Security and Privacy, Montreal, Canada, TBA https://sp2027.ieee-security.org/, Submission date(s): 10 November, 2026, 17 November, 2026. S&P 2027 IEEE Symposium on Security and Privacy, Montreal, Canada, TBA https://sp2027.ieee-security.org/, *Submission date: 10 November, 2026. AISEC 2026 ACM Workshop on Artificial Intelligence and Security, The Hague, Netherlands, 15 November, 2026 https://aisec.cc/ CCS 2026 ACM Conference on Computer and Communications Security, The Hague, Netherlands, 15-19 November, 2026 https://www.sigsac.org/ccs/CCS2026/ WTMC 2026 International Workshop on Traffic Measurements for Cybersecurity, The Hague, Netherlands, 15-19 November, 2026 https://wtmc.info/index.html CODASPY 2027 ACM Conference on Data and Application Security and Privacy, Fort Collins, CO, USA, 14-17 June, 2027 https://www.codaspy.org/2027/, *Submission date: 16 November, 2026. S&P 2027 IEEE Symposium on Security and Privacy, Montreal, Canada, TBA https://sp2027.ieee-security.org/, *Submission date: 17 November, 2026. EuroSnP 2027 IEEE European Symposium on Security and Privacy, Lisbon, Portugal, 6-10 July, 2027 https://eurosp2027.ieee-security.org/, *Submission date: 20 November, 2026. CANS 2026 International Conference on Cryptology and Network Security, Wollongong, Australia, 23-25 November, 2026 https://uow-ic2.github.io/cans2026/ CODASPY 2027 ACM Conference on Data and Application Security and Privacy, Fort Collins, CO, USA, 14-17 June, 2027 https://www.codaspy.org/2027/, *Submission date: 23 November, 2026. IWSEC 2026 International Workshop on Security, Tokyo, Japan, 24-26 November, 2026 https://www.iwsec.org/2026/index.html CRiSIS 2026 International Conference on Risks and Security of Internet and Systems, Rabat, Morocco, 25-27 November, 2026 https://sites.google.com/view/crisis26 CSCML 2026 International Symposium on Cyber Security, Cryptology and Machine Learning, Virtual, 3-4 December, 2026 https://www.cscml.org/, *Submission date: 25 November, 2026. PETS 2027 Privacy Enhancing Technologies Symposium, Delft, Netherlands, 19-24 July, 2027 https://petsymposium.org/cfp27.php, *Submission date: 30 November, 2026. CSCML 2026 International Symposium on Cyber Security, Cryptology and Machine Learning, Virtual, 3-4 December, 2026 https://www.cscml.org/, Submission date(s): 25 November, 2026. IEEE ACSAC 2026 IEEE Annual Computer Security Applications Conference, Los Angeles, CA, USA, 7-11 December, 2026 https://www.acsac.org/2026/ PasswordsCon 2026 Passwords Conference, Cork, Ireland, 7-9 December, 2026 https://cyberexplore.ie/passwordscon26/, Submission date(s): 28 September, 2026. CSET 2026 USENIX Workshop on Cyber Security Experimentation and Test, Los Angeles, CA, USA, 8 December, 2026 https://cset26.isi.edu/ HealthSec 2026 Cybersecurity In Healthcare Workshop, Los Angeles, CA, USA, 8 December, 2026 https://publish.illinois.edu/healthsec2026/ SSR 2026 Security Standardisation Research Conference, Baltimore, MD, USA, 13-15 December, 2026 https://ssresearch26.umbc.edu/ CrCo 2026 IMA International Conference on Cryptography and Coding, Cirencester, UK, 15-16 December, 2026 https://ima.org.uk/28271/20th-ima-international-conference-on-cryptography-and-coding/ ICDF2C 2027 EAI International Conference on Digital Forensics and Cyber Crime, New York, USA, 25-27 June, 2027 https://icdf2c.eai-conferences.org/2027/, *Submission date: 15 December, 2026. CSCI-RTCW 2026 Research Track on Cyber Warfare, Cyber Defense, and Cyber Security, Las Vegas, NV, USA, 16-18 December, 2026 https://www.american-cse.org/csci2026/RTCW ICISS 2026 International Conference on Information Systems Security, Chennai, India, 16-20 December, 2026 https://iciss.in/ ISPA 2026 IEEE International Symposium on Parallel and Distributed Processing with Applications, Kuala Lumpur, Malaysia, 27-30 December, 2026 https://ieee-ai-for-science.org/2026/ispa/, Submission date(s): 30 September, 2026. USENIXSec 2027 USENIX Security Symposium, Denver, CO, USA, 11-13 August, 2027 https://www.usenix.org/conference/usenixsecurity27, *Submission date: 19 January, 2027. ACNS 2027 25th International Conference on Applied Cryptography and Network Security, Egham, UK, 28 June - 1 July, 2027 https://acns2027.isg.rhul.ac.uk/, *Submission date: 21 January, 2027. USENIXSec 2027 USENIX Security Symposium, Denver, CO, USA, 11-13 August, 2027 https://www.usenix.org/conference/usenixsecurity27, *Submission date: 26 January, 2027. ICITS 2027 International Conference on Information Technology and Systems, Cusco, Peru, 27-29 January, 2027 https://icits.me/ CSF 2027 IEEE Computer Security Foundations Symposium, Tokyo, Japan, 13-17 September, 2027 https://csf2027.ieee-security.org/, *Submission date: 28 January, 2027. SECRYPT 2027 International Conference on Security and Cryptography, Rome, Italy, 20-22 July, 2027 https://secrypt.scitevents.org/, *Submission date: 16 February, 2027. PETS 2027 Privacy Enhancing Technologies Symposium, Delft, Netherlands, 19-24 July, 2027 https://petsymposium.org/cfp27.php, *Submission date: 28 February, 2027. PerCom 2027 IEEE International Conference on Pervasive Computing and Communications, Goa, India, 8-12 March, 2027 https://percom.org/ SPT-IoT 2027 IEEE PerCom Workshop on Security, Privacy and Trust in the Internet of Things, Goa, India, 8-12 March, 2027 https://percom.org/ NDSS 2027 ISOC Network and Distributed System Security Symposium, Seoul, Republic of Korea, 22-26 March, 2027 https://www.ndss-symposium.org/ndss2027/ SECRYPT 2027 International Conference on Security and Cryptography, Rome, Italy, 20-22 July, 2027 https://secrypt.scitevents.org/, *Submission date: 23 March, 2027. DFCEurope 2027 Digital Forensics Conference Europe, Edinburgh, Scotland, 30 March - 2 April, 2027 https://dfrws.org/conferences/dfceurope2027/ SciSec 2027 International Conference on Science of Cyber Security, Gjovik, Norway, 22-24 June, 2027 https://scisec.org/, *Submission date: 2 April, 2027. FHE 2027 FHE.org Conference on Fully Homomorphic Encryption, Seattle, WA, USA, 4 April, 2027 https://fhe.org/conferences/conference-2027/, Submission date(s): 1 November, 2026. PST 2027 Annual International Conference on Privacy, Security and Trust, Sheffield, UK, 25-27 August, 2027 https://pstnet.ca/pst2027/, *Submission date: 10 April, 2027. HOST 2027 IEEE International Symposium on Hardware Oriented Security and Trust, Washington, DC, USA, 3-6 May, 2027 https://host.conferences.computer.org/2027/, Submission date(s): 1 November, 2026, 8 November, 2026. SaTML 2027 IEEE Conference on Secure and Trustworthy Machine Learning, Reykjavik, Iceland, 8-10 May, 2027 https://satml.org/, Submission date(s): 29 September, 2026. CODASPY 2027 ACM Conference on Data and Application Security and Privacy, Fort Collins, CO, USA, 14-17 June, 2027 https://www.codaspy.org/2027/, Submission date(s): 16 November, 2026, 23 November, 2026. SciSec 2027 International Conference on Science of Cyber Security, Gjovik, Norway, 22-24 June, 2027 https://scisec.org/, Submission date(s): 2 April, 2027. ICDF2C 2027 EAI International Conference on Digital Forensics and Cyber Crime, New York, USA, 25-27 June, 2027 https://icdf2c.eai-conferences.org/2027/, Submission date(s): 15 December, 2026. ACNS 2027 25th International Conference on Applied Cryptography and Network Security, Egham, UK, 28 June - 1 July, 2027 https://acns2027.isg.rhul.ac.uk/, Submission date(s): 21 January, 2027. EuroSnP 2027 IEEE European Symposium on Security and Privacy, Lisbon, Portugal, 6-10 July, 2027 https://eurosp2027.ieee-security.org/, Submission date(s): 20 November, 2026. PETS 2027 Privacy Enhancing Technologies Symposium, Delft, Netherlands, 19-24 July, 2027 https://petsymposium.org/cfp27.php, Submission date(s): 30 November, 2026, 28 February, 2027. SECRYPT 2027 International Conference on Security and Cryptography, Rome, Italy, 20-22 July, 2027 https://secrypt.scitevents.org/, Submission date(s): 16 February, 2027, 23 March, 2027. SOUPS 2027 Symposium on Usable Privacy and Security, Denver, CO, USA, 8-10 August, 2027 https://www.usenix.org/conference/soups2027 USENIXSec 2027 USENIX Security Symposium, Denver, CO, USA, 11-13 August, 2027 https://www.usenix.org/conference/usenixsecurity27, Submission date(s): 19 January, 2027, 26 January, 2027. PST 2027 Annual International Conference on Privacy, Security and Trust, Sheffield, UK, 25-27 August, 2027 https://pstnet.ca/pst2027/, Submission date(s): 10 April, 2027. CSF 2027 IEEE Computer Security Foundations Symposium, Tokyo, Japan, 13-17 September, 2027 https://csf2027.ieee-security.org/, Submission date(s): 15 October, 2026, 28 January, 2027. ------------------------------------ ==================================================================== Information on the Technical Committee on Security and Privacy ==================================================================== ____________________________________________________________________ Information for Subscribers and Contributors ____________________________________________________________________ SUBSCRIPTIONS: Two options, each with two options: 1. To receive the full ascii CIPHER issues as e-mail, send e-mail to cipher-admin@ieee-security.org (which is NOT automated) with subject line "subscribe". OR send a note to cipher-request@mailman.xmission.com with the subject line "subscribe" (this IS automated - thereafter you can manage your subscription options, including unsubscribing, yourself) 2. To receive a short e-mail note announcing when a new issue of CIPHER is available for Web browsing send e-mail to cipher-admin@ieee-security.org (which is NOT automated) with subject line "subscribe postcard". OR send a note to cipher-postcard-request@mailman.xmission.com with the subject line "subscribe" (this IS automated - thereafter you can manage your subscription options, including unsubscribing, yourself) To remove yourself from the subscription list, send e-mail to cipher-admin@ieee-security.org with subject line "unsubscribe" or "unsubscribe postcard" or, if you have subscribed directly to the xmission.com mailing list, use your password (sent monthly) to unsubscribe per the instructions at http://mailman.xmission.com/cgi-bin/mailman/listinfo/cipher or http://mailman.xmission.com/cgi-bin/mailman/listinfo/cipher-postcard Those with access to hypertext browsers may prefer to read Cipher that way. It can be found at URL http://www.ieee-security.org/cipher.html CONTRIBUTIONS: to cipher @ ieee-security.org are invited. Cipher is a NEWSletter, not a bulletin board or forum. It has a fixed set of departments, defined by the Table of Contents. Please indicate in the subject line for which department your contribution is intended. Calendar and Calls-for-Papers entries should be sent to cipher-cfp @ ieee-security.org and they will be automatically included in both departments. To facilitate the semi-automated handling, please send either a text version of the CFP or a URL from which a text version can be easily obtained. For Calendar entries, please include a URL and/or e-mail address for the point-of-contact. For Calls for Papers, please submit a one paragraph summary. See this and past issues for examples. ALL CONTRIBUTIONS CONSIDERED AS PERSONAL COMMENTS; USUAL DISCLAIMERS APPLY. All reuses of Cipher material should respect stated copyright notices, and should cite the sources explicitly; as a courtesy, publications using Cipher material should obtain permission from the contributors. ____________________________________________________________________ Recent Address Changes ____________________________________________________________________ Address changes from past issues of Cipher are archived at http://www.ieee-security.org/Cipher/AddressChanges.html _____________________________________________________________________ How to become <> a member of the IEEE Computer Society's TC on Security and Privacy _____________________________________________________________________ You may easily join the TC on Security & Privacy (or other TCs) by completing the on-line form at IEEE at https://www.computer.org/web/tandc/technical-committees ______________________________________________________________________ TC Conference Publications Online ______________________________________________________________________ The proceedings of previous conferences are available from the Computer Society's Digital Library. IEEE Security and Privacy Symposium IEEE Computer Security Foundations IEEE European Security and Privacy Symposium From 2012 onward, these are available without charge from the digital library 12 months after the conference. ____________________________________________________________________________ TC Officers ____________________________________________________________________________ Chair: Security and Privacy Symposium Chair Emeritus: Thorsten Holz Trent Jaeger Faculty Member Associate Professor CISPA Helmholtz Center for Pennsylvania State University Information Security https://www.cse.psu.edu/~trj1 tcchair at ieee-security.org sp24-chair@ieee-security.org Vice Chair: Treasurer: Alvaro Cardenas Yong Guan Professor Professor University of California, Department of Electrical and Computer Santa Cruz Engineering tcchair at ieee-security.org Iowa State University, Ames, IA 50011 treasurer@ieee-security.org Newsletter Editor: Security and Privacy Symposium, 2025 Chair: Hilarie Orman Marina Blanton Purple Streak, Inc. Associate Professor 500 S. Maple Dr. University at Buffalo Woodland Hills, UT 84653 sp25-chair at ieee-security.org cipher-editor@ieee-security.org TC Awards Chair: Tegan Brennan Assistant Professor Stevens Institute of Technology tbrenna5 at stevens.edu ____________________________________________________________________________ BACK ISSUES: Cipher is archived at: http://www.ieee-security.org/cipher.html Cipher is published 6 times per year --=====================_purplestreak_932242421235479791===--