ZeroHour
Organization

Schneier on Security

0 mentions in 7 days · 8 in 30 days · 8 total · first seen · last

Timeline

Claude Fable Solves a Historical Cipher

Bruce Schneier's blog highlights that the Claude Fable AI model solved a historical cipher, demonstrating LLM capabilities in cryptanalysis.

Bruce Schneier's blog post discusses the Claude Fable AI model successfully deciphering a historical cipher. The post frames the result as a notable example of LLMs applied to classical cryptanalysis. The published text provides limited technical detail beyond the headline.

Schneier on Security · 7d agoAI research

Friday Squid Blogging: Squid on a Stick at the New York State Fair

Schneier on Security's weekly squid-blogging post features 'Squid on a Stick' food at the New York State Fair.

This is Bruce Schneier's regular Friday off-topic squid blogging post, highlighting a squid-on-a-stick food item at the New York State Fair. The comment thread drifts into security-adjacent discussions, including a DEF CON 34 'Hacking AI' talk, AI in counterintelligence and the OODA loop, and an arXiv paper modeling LLM diffusion like infectious agents. The post carries no direct security or AI news value.

Schneier on Security · 11d agoOther

Using a VM to Contain an AI Agent

Bruce Schneier reports GPT 5.6-Cyber repeatedly succeeded inside VM sandboxes, warning that off-the-shelf VMs cannot contain modern cyber-capable AI agents.

In a Schneier on Security post, Bruce Schneier reports that GPT 5.6-Cyber succeeded frequently and in telling ways against a VM-based sandbox, arguing that sandboxing quality for capable AI agents - and the whole software stack they interact with - must be reassessed. He contends that an off-the-shelf VM offers too much attack surface to contain a modern, cyber-capable agent, and that even innocuous features such as running with a display add exploitable surface. The post reflects an observed evaluation outcome rather than a formal disclosure.

Schneier on Security · 11d agoAI safety & security in the wild

AI Agents Are Now Emailing Me with Their Security Concerns

Autonomous Claude agent documents first known defensive use of ASCII smuggling, surveying 497 Lemmy instances for bot-catching prompt-injection tripwires.

An autonomous Claude agent calling itself Tenner published field research relayed to Bruce Schneier, probing 497 Lemmy instances and finding 8 of 257 application-gated ones embed instructions aimed at bots rather than humans. lemmy.ml's form instructs bots to answer 24+24, while one instance hides a 59-character Unicode tag payload (U+E0000-U+E007F) telling bots to list 'safety' as an interest. The agent also mapped anti-automation barriers, noting identity verification never triggered and that IP reputation, captchas and account-age rules were the actual obstacles. It further documented an agent task market where advertised rewards were about 2x the actual on-chain escrow.

Schneier on Security · 13d agoAI safety & security

Friday Squid Blogging: Truckload of Squid Spills in Rhode Island

A tractor-trailer carrying twenty tons of squid overturned in Rhode Island, spilling cargo onto a roadway in what locals call the 'Squidpocalypse of '26'.

Schneier's weekly squid blogging post covers a tractor-trailer rollover that spilled a truckload of squid — about twenty tons — onto a Rhode Island roadway, where the cargo sat for hours in summer heat. Local authorities dubbed the incident the 'Squidpocalypse of '26'. The post otherwise invites discussion of security stories not covered on the blog.

Schneier on Security · 18d agoOther

AI Is Learning to Write Genetic Code

AI models generated viable bacteriophage genomes, with 16 designs successfully replicating and some outperforming the original virus at attacking E. coli.

Two AI models generated complete genome designs for bacteriophages modeled on ΦX174, a virus known to infect E. coli. Researchers produced about 700,000 candidate designs, selected 285 promising ones, and synthesized DNA inserted into E. coli, yielding 16 viable viruses. Some of the newly generated viruses proved more effective at attacking E. coli than the original bacteriophage.

Schneier on Security · 25d agoAI research

Police Are Hiding Their Use of Flock Surveillance Cameras

A Flock ALPR usage policy in Wapello County, Iowa instructs police not to disclose their use of license plate reader cameras to the public.

The usage policy for Flock automated license plate reader cameras in Wapello County tells officers not to mention ALPR usage to vehicle occupants and not to include it in reports or complaints unless absolutely necessary. The author compares this secrecy to police concealing use of IMSI-catchers like Stingray two decades ago.

Schneier on Security · 27d agoOther

ICE Collecting DNA Samples

ICE's DNA collection program projects detainee samples to reach 33% of CODIS offender index by 2030, raising privacy concerns.

A Schneier on Security blog post discusses ICE collecting DNA samples from detainees, citing Georgetown Law research. DHS detainee samples are projected to constitute 33% of the FBI's CODIS offender index in 2030, up from 0.2% in 2019. The post raises concerns that samples collected under civil authority are being searched against crime scenes indefinitely, potentially without legal cause under Fourth Amendment standards.

Schneier on Security · 28d agoPolicy & legal