I know I’m late to the party to @…’s post “Is it ethical to use AI?”, where she argues that “AI is just technology”. It’s been festering inside me, and Martin Fowler’s mention of the article that calls AI “a technology that is so powerful and so useful”, and therefore “there’s no ethical gain from renouncing the use of AI”. (Especially as both have provided th…
AdaptHealth says attackers used social engineering to breach its systems
and steal sensitive patient data,
including passwords associated with insurance billing.
The medical equipment company disclosed the attack to the Securities and Exchange Commission (SEC) on Thursday,
noting that attackers accessed internal patient management systems, document storage platforms,
and external electronic health record system portals.
The attack targeted an unwitting thi…
Dryas: A Reprogrammable Engine for High-Speed Interconnect Tracing and Analysis
Manuel Br\"ochin, Tom Kuchler, Michael Giardino, David Cock, Timothy Roscoe
https://arxiv.org/abs/2608.12934 https://arxiv.org/pdf/2608.12934 https://arxiv.org/html/2608.12934
arXiv:2608.12934v1 Announce Type: new
Abstract: The proliferation of heterogeneous components in modern computing systems has been accompanied by new higher bandwidth and lower latency interconnects. These interfaces and protocols are enormously complex and the process of developing, debugging, and analyzing FPGA-based implementations requires significant engineering work. Moreover, once a functional implementation is completed, optimization of the controller and associated software requires processing potentially hundreds of gigabytes of trace data.
In this paper, we present Dryas, an open source tool for analyzing such an interconnect. We developed our tool, using minimal hardware resources, alongside an FPGA implementation of a very high speed, low latency (30~GiB/s, 200~ns) interconnect. With our run-time reprogrammable overlay engine we can inspect this interconnect to find rare, complex, or transient events even at full operation. This filtering engine is based on non-deterministic finite automata (NFAs), efficiently implemented using state transition elements (STEs), allowing us to trace events at a cache-line granularity. Moreover we can change the filters in less than a second, without reprogramming the FPGA or interfering with the running application. This data enables not only debugging the implementation of the interconnect itself, but analyzing the behavior of accelerated applications.
We examine the mathematical basis for using NFAs and describe their implementation on a real coherent CPU-FPGA research platform. We then evaluate the scalability of Dryas for various size NFAs, followed by two different use cases: debugging FPGA implementation of the interconnect and analyzing cache behavior.
toXiv_bot_toot
Google VP of Security Engineering Heather Adkins warns the EU's DMA proposals to open Android and Search could lead to a significant rise in fraud within weeks (Matt Burgess/Wired)
https://www.wired.com/story/top-google-security-…
Good lord, you are not going to believe the massive amount of cybersecurity news you might have missed since just Friday, so check out today's Metacurity for the top developments, including
--DPRK's Kimsuky built an in-house AI toolkit to power cyberattacks,
--Chinese components in UK military drones secretly transmitted data,
--California city declares emergency after cyberattack disrupts 911 services,
--Turkey's new cyber law sparks fears of sweeping digital censorship,
--OpenAI's Hugging Face hack reveals deeper AI safety failures,
--Anthropic makes Claude Code's autonomous mode the default,
--AI agent hacks gym booking system without being told to,
--Military supplier discloses phishing breach exposing sensitive defense data,
--Iranian water hacks revive push for EPA cyber authority,
--Levi Strauss says social engineering attack breached company systems,
--Australian court users' data posted on dark web,
--Framework customer data stolen in upstream Metabase breach,
--Major law firms paid $28m in Luna Moth ransomware attacks,
--Former SK Hynix employee jailed for leaking chip secrets to China,
--S. Korean opposition apologizes for breach affecting 17,000 members,
--S. Korean teams dominate DEF CON hacking finals,
--Breach at S. Korea's 3Pro TV exposes 460,000 customer records,
--Serbian entrepreneur arrested over alleged hacking of Croatian government systems,
--One-third of UK manufacturers hit by cyberattacks,
--Poland details second Russian cyberattack on power grid,
--Researchers' email honeypot captures hundreds of thousands of misdirected messages,
--Ransomware gangs increasingly target midlevel managers,
--Oklahoma Manufacturing Alliance hit by Booba ransomware attack,
--Thai agencies consider MFA after widespread government data leaks,
--Vintage computer collectors preserve the machines that built the digital age,
--Meta smart glasses face growing privacy backlash,
--Amazon backs massive gas-powered plant for Texas AI data center,
--OpenAI touts AI productivity while employees work 90-hour weeks
https://www.metacurity.com/dprks-kimsuky-built-an-in-house-ai-toolkit-to-power-cyberattacks/
Enhancing Attack Detection Capabilities in BACnet/IP Networks Using Machine-Learning Models
Derek Manzella, John D. Hastings
https://arxiv.org/abs/2607.20686 https://arxiv.org/pdf/2607.20686 https://arxiv.org/html/2607.20686
arXiv:2607.20686v1 Announce Type: new
Abstract: Building Automation Systems (BAS) manage critical building functions using protocols such as BACnet/IP, yet defenders have limited tooling and few labeled datasets for detecting BACnet-specific attacks. This work addresses these gaps through three contributions. First, CISA's Zeek BACnet parser is modified to produce a unified per-packet log, simplifying feature engineering for machine-learning (ML) pipelines. Second, a simulated BACnet/IP testbed is developed using bacpypes3 to model a small commercial HVAC system with physics-based device behavior, schedule-aware controller logic, and per-packet attack labeling. Third, five unsupervised anomaly detection models are evaluated using baseline traffic and six BACnet attack types, including denial of service, reconnaissance, property tampering, and false data injection. Results show that One-Class SVM achieved the strongest overall performance, with an average F1 score of 0.864 across all attacks and F1 scores above 0.99 for high-volume denial-of-service and reconnaissance attacks. Detection is much stronger for high-volume attacks, such as DoS attacks and reconnaissance, than stealthier techniques such as tampering and false data injection, which scored around 77%.
toXiv_bot_toot