ZeroHour

Search: “Bulgaria”

40 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Ukrainian hacker gets four years in US prison over Conti ransomware attacks

Oleksii Lytvynenko was sentenced to four years in the US for his role in Conti ransomware attacks against 1,000+ victims.

Ukrainian national Oleksii Lytvynenko, 44, was sentenced to four years in a US prison for his role in the Conti ransomware operation, having pleaded guilty in June. He worked as a hacker and developer for Conti, personally targeting at least a dozen companies and building a malware loader, and stolen data from eight US victims and four others overseas was found in his accounts. Between 2020 and 2022, Conti attacked organizations across 47 US states and 31 countries, with the FBI estimating victims paid more than $150 million in ransoms by January 2022. Lytvynenko was arrested in Cork, Ireland in July 2023 and extradited after several years in Irish custody; four other alleged Conti members were charged in a separate September 2023 indictment.

The Recordupdated · 5d agofirst · 5d agoPolicy & legal 7 sources1

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

CERT-UA says Sandworm-linked UAC-0145 poses as recruiters in fake job interviews to deliver a trojanized WireGuard VPN that runs attacker commands on victims' hosts.

CERT-UA attributes the campaign, ongoing since May 2026, to UAC-0145, a subgroup within GRU-affiliated Sandworm (APT44). Posing as HR staff of firms like ATLAS Business Group and Sopra Steria Bulgaria, attackers lure Ukrainian IT specialists into Zoom interviews, then share failing WireGuard configs and push a custom SopraVPN client from SourceForge. The modified WireGuard build supports a non-standard SymmetricKey option holding AES-256-GCM-encrypted PowerShell, decrypted with the decoded PrivateKey and executed via runScriptCommand. A scheduled task then downloads a second-stage payload on Windows, while the Linux variant fetches it via cURL.

The Hacker News · Aug 12, 2026Threat actor1

European parliament members call for slowdown of Serbia’s EU entry over spyware use

29 MEPs urge delaying Serbia's EU accession after researchers found Pegasus and NoviSpy spyware on student activists' phones.

Twenty-nine Members of the European Parliament sent a letter Friday demanding Serbia's EU accession be slowed until an investigation into its spyware use is completed. The letter follows a SHARE Foundation report, with Amnesty International and the Citizen Lab, documenting Pegasus and NoviSpy infections on Serbian student activists' phones; NoviSpy evidence pointed to Serbian government authorities, though Pegasus attribution was not assigned. The MEPs also urged European Commission President Ursula von der Leyen to cancel a planned visit to Serbia and called the surveillance 'a direct state attack on democracy' ahead of upcoming elections. The Serbian government did not respond to requests for comment.

CyberScoop · 12d agoPolicy & legal in the wild

International Operation Disrupts Sality P2P Botnet

US-led international operation with Europol, CrowdStrike, and Shadowserver sinkholed the 20-year-old Sality P2P botnet, once exceeding one million infected machines.

On August 31, 2026, authorities from the US, Bulgaria, Hungary, and Romania, supported by Europol, CrowdStrike, and the Shadowserver Foundation, disrupted the Sality P2P botnet by sinkholing communications and seizing domains. Sality has operated for over 20 years, at its peak controlling more than one million infected machines used for credential theft, spam, proxy services, crypto-theft, and DDoS attacks, with over 11 million unique IP addresses linked to its infrastructure since 2017. The disruption exploited the botnet's super-peer reputation mechanism by removing legitimate peers via protocol-level manipulation and inserting sinkhole entries into emptied peer lists.

Infosecurity Magazine · 13d agoMalware

Large group of Serbian opposition, activist figures targeted with spyware

Researchers found at least 14 Serbian opposition figures and student protesters targeted with Pegasus and NoviSpy spyware around elections; 11 more phones under investigation.

The SHARE Foundation, with Citizen Lab confirmation and Amnesty International peer review, found at least 14 Serbian opposition and civil society figures targeted with advanced spyware since December, including a member of Parliament, a local politician and student protesters. Citizen Lab confirmed zero-click Pegasus on a student protester's iPhone between December 2025 and January 2026, while Amnesty confirmed a new detection-evading NoviSpy Android variant in at least two cases. Targeting coincided with March 2026 local elections; Serbia's BIA intelligence agency denied the claims, and 11 additional alerted phones remain under forensic investigation.

The Record · 13d agoThreat actor in the wild

Sality, one of the longest

US and European authorities, with CrowdStrike and Shadowserver, disrupted the 20-year-old Sality peer-to-peer botnet, severing 15,000+ infected machines from operators.

US and European authorities disrupted the Sality botnet, active since at least 2003, in an operation involving the DOJ, CrowdStrike, the Shadowserver Foundation and agencies in Bulgaria, Hungary and Romania. Researchers reverse-engineered the botnet's peer-to-peer architecture and injected false data into infected machines' 'super peer' lists, cutting more than 15,000 systems off from their operators. For the past eight years Sality primarily distributed EggJagger, malware that replaces clipboard cryptocurrency addresses and is estimated to have netted the operator at least $150,000. No arrests were announced, and CrowdStrike assesses the operator works from Russia's Bashkortostan region.

The Record · 14d agoMalware in the wild

Introducing OlmoEarth embeddings: Custom embedding exports from OlmoEarth Studio for downstream analysis

AllenAI's OlmoEarth Studio adds custom embedding exports to support downstream geospatial analysis workflows.

A Hugging Face blog post from AllenAI introduces OlmoEarth embeddings, a feature allowing custom embedding exports from OlmoEarth Studio for downstream analysis tasks. Only the title was available, so no benchmark or performance details are provided. OlmoEarth is Ai2's open geospatial AI model family.

Hugging Face Blog · Aug 12, 2026AI tools & infra

Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF

AI-orchestrated campaign exploited PaperCut NG/MF RCE (CVE-2026-81578/82078), compromising 440+ instances at 395 organizations in 48 countries.

GreyNoise tracked a likely Russian-speaking actor using AI (OpenAI Codex harness plus a DeepSeek model) to develop, test, and deploy exploits for PaperCut NG/MF (CVE-2026-81578, CVE-2026-82078) starting 31 August 2026. The actor compromised at least 440 PaperCut instances across 395 organizations in 48 countries, achieving domain admin at 12 victims — fastest time to domain admin was five minutes and a US high school was fully compromised in seven minutes. Attack paths involved LSASS memory and registry secret harvesting, pass-the-hash to domain controllers, noPac attacks, account additions to Domain Admins, and DCSync to exfiltrate full NTDS.DIT credential dumps. Impact scope suggests access development potentially for handoff, with prior PaperCut intrusions historically leading to extortion.

GreyNoise · 8d agoThreat actor in the wildCVE-2026-81578CVE-2026-82078CVE-2021-42278+1 CVEs1

Training and Finetuning Multi-Vector Embedding Models with Sentence Transformers

Hugging Face published a tutorial on training and finetuning multi-vector embedding models using the Sentence Transformers library.

Hugging Face's blog walks through training and finetuning multi-vector embedding models with Sentence Transformers. Multi-vector approaches store multiple vectors per document to support late-interaction retrieval. The post is a practical guide for developers building retrieval pipelines with the library.

Hugging Face Blog · 22d agoAI tools & infra1

Global sinkhole operation ends Sality botnet’s 23-year run

Law enforcement, CrowdStrike, and Shadowserver sinkholed the 23-year-old Sality P2P botnet, cutting 15,000+ infected machines from its operator.

Sality, active since 2003 as a file-infecting virus with two P2P networks (versions 3 and 4), distributed credential thieves, spam, proxies, and DDoS payloads, and most recently delivered the EggJagger clipboard hijacker that swapped cryptocurrency wallet addresses for at least $150,000 in operator profit. A coordinated sinkhole operation replaced the botnet's super-peer list with defender-controlled sinkholes, and investigators in the US, Bulgaria, Hungary, and Romania seized payload domains. The Shadowserver Foundation is coordinating ISP and CERT notifications to infected device owners.

Help Net Security · 15d agoMalware1

Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data

Exposed Vietnam-linked APIS database held 220.8 million passenger and crew records with passport and flight data from January 2017 to April 2026.

Kinryū Labs discovered an exposed Elasticsearch cluster named 'pax-info' containing 220.8 million passenger and crew records, about 107 GB across 29 indices, hosted on IP space assigned to Viettel in Hanoi. The records include names, birth dates, nationalities, passport numbers, and detailed flight information from airlines across Asia-Pacific, Europe and the Middle East. Researchers reported the exposure on June 3 and the database was secured by June 8 with Singapore Airlines coordinating; no evidence of theft was found, but missing server logs mean access cannot be ruled out.

Security Affairs · 8d agoData breach

Rewiring Democracy Series on The Renovator

Schneier and Sanders link a four-part Rewiring Democracy essay series covering civic AI in Japan, Switzerland, Brazil and Scotland.

Bruce Schneier and Nathan E. Sanders announced links to their Rewiring Democracy essay series on The Renovator. The four parts cover Japan's digital democracy party Team Mirai, Switzerland's public AI model Apertus, Brazil's Open Knowledge civic technologists, and civic AI in Scotland. The post is a brief index without technical details.

Schneier on Security · 15d agoAI policy

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

GuidePoint reports a ransomware affiliate posing as 'Ransom Busters' charges victims $20,000-$60,000 to delete stolen data, and details UNC6671's $8M AitM extortion wave.

GuidePoint's GRIT team reports that 'Ransom Busters', likely a ransomware affiliate active across multiple RaaS operations including DragonForce, Settra and Anubis, proactively emails victims claiming it deleted their stolen data and backups for a $20,000-$60,000 fee, citing claimed access to RaaS administrative panels for over three years. Two analyzed intrusions shared tooling: SoftPerfect Network Scanner for reconnaissance, s5cmd-based exfiltration to AWS cloud storage, an RMM tool installed via PowerShell, a backdoor account with password 'Numlock!123' and the same attacker hostname DESKTOP-BBETH6K. Separately, GRIT detailed UNC6671's (Cordial Spider) adversary-in-the-middle vishing operation running since April under five extortion brands, with more than $8 million across 15 Bitcoin wallets, an average of $600,000 per payment, and 78 phishing sub-domains across 76 organizations, 40% in financial services.

The Hacker News · 29d agoThreat actor in the wild1

Data from drones in Ukraine is fueling a new Wild West marketplace

Ukraine's defense ministry opened millions of battlefield drone data points to over 100 companies, fueling a fast-growing AI training data marketplace.

Ukraine's Ministry of Defense announced in January it would make millions of data points from tens of thousands of drone flights available to military contractors and commercial companies, with more than 100 companies and the UK government gaining access. Enabled Intelligence says it has processed over 500,000 hours of Ukrainian drone footage for use in future AI training. The article argues this creates a commercial battlefield-data marketplace with risks including lost training-data provenance, an extractive economy benefiting wealthier countries, and a governance vacuum requiring international rules.

MIT Technology Review · AI · 12d agoAI industry1

Supporting independent journalism in Ukraine

OpenAI, AIRPPU, and WAN-IFRA launched a program bringing AI support to Ukrainian news organizations to strengthen independent journalism.

OpenAI is partnering with AIRPPU and WAN-IFRA on a program aimed at helping Ukrainian news organizations strengthen innovation, resilience, and independent journalism. The announcement is a partnership/philanthropic initiative rather than a product or model release.

OpenAI News · 10d agoAI industry

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

Law enforcement and CrowdStrike disrupted the 23-year-old Sality P2P botnet, isolating 15,000+ infected machines and seizing linked domains.

International law enforcement, working with CrowdStrike and the Shadowserver Foundation, executed a peer-to-peer sinkhole operation against Sality, a botnet active since 2003 that delivered malware to more than 15,000 machines worldwide. Sality's primary payload for eight years was EggJagger, a clipboard hijacker that swaps copied bitcoin and ethereum wallet addresses with attacker-controlled ones, yielding at least $150,000 in stolen cryptocurrency. The US Justice Department, FBI, and DoD Office of Inspector General's Defense Criminal Investigative Service seized Sality-linked domains, with parallel action in Bulgaria, Hungary, and Romania. The Shadowserver Foundation is coordinating with ISPs and CSIRTs to identify infections and notify victims.

The Register · Security · 15d agoMalware in the wild

Risky Bulletin: Russia tells data centers to deploy drone defenses

Russia ordered data center operators to deploy drone strike defenses under a Putin decree allowing temporary state takeover of unprotected critical infrastructure.

The Russian government instructed data center operators to deploy protections against drone strikes under a presidential decree signed by Putin that allows temporary state administration of critical infrastructure operators failing to defend against Ukrainian hacks and drone strikes. Although data centers are not formally critical infrastructure in Russia, the decree applies to them because other sectors depend heavily on cloud services; Russia has more than 180 data centers, over 80% in the European region within range of Ukrainian strikes. The digest also reports a Dropbox breach affecting nearly 5,000 accounts via the Lenovo ID integration, spyware attacks on at least 14 Serbians using NoviSpy or Pegasus, and a password recovery attack targeting hundreds of thousands of X accounts tied to the new X Money service. Other items include a 14-hour compromise of Coder's Cloudflare infrastructure delivering malicious Terraform modules, donor data breaches at Davayte and You Are Not Alone via the Stripe/WooCommerce integration, a $2.5M Aquifer crypto heist, and a TVING breach exposing data of almost 40 million accounts.

Risky Business News · 12d agoPolicy & legal

Investigation of banking hack leads to arrests in Europe, Brazil

German and Brazilian police arrested seven suspects over a 2023 hack that drained an estimated 30 million euros from German bank accounts.

Germany's BKA said three suspects were arrested in Europe and charged with fraud, while Brazil's federal police arrested four others and executed 21 search warrants under Operacao Klonen (Operation Clone). The November 2023 attack exploited a vulnerability at a payment provider and used cloned payment cards to make unauthorized withdrawals from German online banking users, draining an estimated 30 million euros (34.7 million dollars). Funds were laundered through Brazil and four European countries, and courts ordered seizure of assets worth more than 20 million dollars. Brazilian media identified the affected bank as Commerzbank, which said customers suffered no financial loss.

The Record · Aug 15, 2026Policy & legal in the wild

Building a Production Greek-English Speech Recognizer

Engineering report details Sophea, a production Greek-English ASR reaching 4.26% WER on public English sets via ROVER ensemble and data-pipeline calibration.

Across 23 training iterations, two architectures, and nine production gates, no single data composition passed all gates; a three-model ROVER ensemble reached 9 of 9 gates and cut overlapping-speech WER from 53.35% to 37.87%. Calibrating an audio-quality filter against in-domain anchors reduced discarded scored Greek audio from 98.7% to 10.6%, and a pre-registered ablation traced a hallucination defect to one training-data package. The sophea/asr-k1 preview arbiter lists 4.26% average WER on eight public English test sets and 25.88% WER on live Greek noisy traffic; no weights or training data are released.

Hugging Face daily papers · 6d agoAI research

Dogged Russia-based botnet dismantled after 23-year run

Law enforcement, CrowdStrike and Shadowserver dismantled the 23-year-old Sality P2P botnet that infected more than 11 million devices.

Sality, a Russia-based peer-to-peer botnet active for 23 years and infecting over 11 million devices, was dismantled by law enforcement working with CrowdStrike and the Shadowserver Foundation. CrowdStrike poisoned the botnet's peer list so infected machines permanently disappeared from the operator's view, while domains were seized in a coordinated effort involving the FBI, Justice Department, Europol and authorities from Bulgaria, Hungary and Romania. The financially motivated operation enabled cryptocurrency theft, DDoS attacks and other cyberattacks, and Europol said the effort dates back to 2017; the operators were not named.

CyberScoop · 14d agoMalware

Ukraine to give Britain access to battlefield data to train AI

Ukraine agreed to give the UK access to battlefield data from Avengers AI Labs to train and test defense AI systems.

Ukraine and the UK signed an agreement making Britain the first foreign partner with access to Avengers AI Labs, a Ukrainian defense ministry platform holding about 5 million battlefield images and video frames drawn largely from the DELTA battlefield management system. Systems trained on this data analyze more than 100,000 drone video feeds per month and help identify roughly 70% of enemy targets in real time. Pilot projects are already underway with Sintela, Mind Foundry and Skyral, and the first technology is expected to protect a British defense facility, with potential expansion to airports, prisons, railways and energy infrastructure.

The Record · 22d agoAI industry

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

Week in review: Medusa ransomware hit 500+ orgs per CISA, millions of Azure tenant records allegedly stolen, SafePal and French tax authority breaches disclosed.

Help Net Security's weekly roundup covers the FBI, CISA, and HHS joint advisory update reporting Medusa ransomware has breached more than 500 organizations since June 2021, and threat actor TheHatman's claim of millions of employee records stolen from Azure tenants of Fortune 500 firms including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services, per Hudson Rock. It also covers the SafePal breach affecting 39,798 customers, France's DGFiP breach exposing data on 678,000 individuals, and UT San delaying its fall semester after a cyberattack. Security items include critical unauthenticated GitLab flaw CVE-2026-19478, an actively exploited patched macOS Screen Sharing flaw deploying a cryptominer, US charges against 17 Mabna Institute Iranian hackers over 31TB of stolen academic data, and Google Mandiant's AI agents finding 100+ high-severity vulnerabilities.

Help Net Security · 25d agoData breach in the wildCVE-2026-19478

Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes

Ukraine's HUR intelligence, with the Cyber Corps group, cyberattacked Russian e-commerce giant Wildberries, disrupting payments and customer service to amplify drone strikes.

Ukraine's Main Intelligence Directorate (HUR) claimed a cyberattack, carried out with the Cyber Corps hacker group, disrupted Russia's largest online marketplace, Wildberries, affecting customer service, contact centers, and payment infrastructure. The operation was designed to amplify kinetic drone strikes; Ukraine says seven of the company's 10 largest logistics centers have been knocked out of operation and more than 1.2 million square meters of warehouse space lost. The claims could not be independently verified and Wildberries has not commented. HUR cited the company's role in Russia's logistics network and in financing the war.

The Record · Aug 17, 2026Threat actor

Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads

US and European authorities with CrowdStrike dismantled the two-decade-old Sality P2P botnet using peer-list manipulation, blocking payload delivery to infected hosts.

The US Department of Justice announced a coordinated takedown of the Sality peer-to-peer botnet, executed August 31, 2026 by authorities from the US, Bulgaria, Hungary, and Romania with CrowdStrike and the Shadowserver Foundation. Sality, active since 2003, infects Windows executables and delivers payloads including the EggJagger crypto clipper, which stole at least $150,000, and was used for DDoS campaigns. The operation abused the botnet's peer-list maintenance cycle to insert sinkhole nodes and isolate both super peers and NAT-hidden infections, cutting off URL and payload distribution to more than 15,000 infected machines across two P2P networks.

The Hacker News · 14d agoMalware

NOAH: Learning the Full Patient Journey. A Longitudinal Multimodal Time-Aware Model for Representation and Forecasting

Researchers introduce NOAH, a generative time-aware transformer trained on 559 million MIMIC clinical events to model and forecast patient trajectories.

NOAH is a task-agnostic, time-aware generative transformer designed to represent and forecast the full multimodal patient journey across medical images, time-series signals, categorical events, and clinical text. It was trained on over 559 million clinical events from 431,000 hospital visits covering 299,000 patients in the MIMIC dataset family. The architecture combines bidirectional time integration with a variational latent space to capture continuous patient state evolution and clinical stochasticity. NOAH supports autoregressive forecasting with time control, zero-shot classification, and counterfactual intervention simulation, with evaluations on 15 ICD chapters, 29 comorbidities, and time-to-event prediction.

arXiv cs.AI / cs.LG / cs.CL · 8d agoAI research2

Police bust cybercrime ring accused of stealing €30 million in four-day spree

German and Brazilian police arrested four over a €30 million bank fraud exploiting a payment provider's faulty software update, seeking three more in Europe.

Operation Klonen executed 21 search-and-seizure warrants across seven Brazilian cities on August 13, arresting four people while three more suspects are pursued in Spain and Bulgaria. The ring exploited a vulnerability in a German payment service provider's booking process, caused by a faulty software update, to carry out unauthorized withdrawals totaling around €30 million within four days starting in late 2023. Funds were moved to Brazil through payment cards issued without consent, pass-through accounts, companies and virtual asset platforms, and courts ordered seizure of assets worth about R$106 million (~$20.7 million). The operation involved Brazil's Polícia Federal, Germany's BKA and the Frankfurt prosecutor's ZIT cybercrime unit.

Help Net Security · Aug 17, 2026Policy & legal

NOAH: Learning the Full Patient Journey. A Longitudinal Multimodal Time-Aware Model for Representation and Forecasting

Researchers introduce NOAH, a time-aware generative transformer trained on 559 million MIMIC clinical events to forecast multimodal patient trajectories.

NOAH is a task-agnostic, time-aware generative transformer trained on over 559 million clinical events from 431,000 hospital visits by 299,000 patients across the MIMIC dataset family. It uses bidirectional time integration and a variational latent space to model the stochastic evolution of patient states, natively processing medical images, time-series signals, categorical events, and structured or unstructured clinical records. The model supports autoregressive forecasting with optional time control, zero-shot classification, and counterfactual intervention simulation, with strong probing performance across clinical outcomes, 15 ICD chapters, and 29 comorbidities.

Hugging Face daily papers · 9d agoAI research1

Multi-Vector (Late Interaction) Embedding Models with Sentence Transformers

Hugging Face details building and using multi-vector late-interaction embedding models with Sentence Transformers for retrieval workloads.

Hugging Face published a guide on multi-vector, late-interaction embedding models (ColBERT-style) supported through Sentence Transformers. The post covers how practitioners can build and use these models for retrieval and RAG pipelines. It is a developer tooling and technique write-up, not a security advisory.

Hugging Face Blog · Aug 18, 2026AI tools & infra1

Pegasus, NoviSpy variant spyware found on devices of Serbian activists

Researchers confirmed the first 2026 Pegasus infection and a new NoviSpy variant on 14 Serbian activists, likely surveillance by Serbian authorities ahead of elections.

Citizen Lab confirmed with high probability the first forensically confirmed Pegasus infection of 2026, on a Serbian student activist hacked via a zero-click exploit between December of last year and January. Amnesty International confirmed two devices infected with a new NoviSpy variant, and the SHARE Foundation documented 14 targets including a member of parliament and a local government official, the largest documented spyware wave in Serbia to date. Evidence points to Serbian police or intelligence services, with NoviSpy infections occurring around police detention ahead of key local and parliamentary elections. Apple threat notifications preceded the findings, and updated iOS versions break the exploit chain.

CyberScoop · 14d agoThreat actor in the wild

LexFlip: A Dissociation Diagnostic for Legal Meaning Preservation Metrics

LexFlip releases 373 minimal perturbations of Quebec statutory French that reverse legal force while preserving tokens, exposing weaknesses in embedding-based meaning preservation metrics.

LexFlip provides 373 minimal perturbations of Quebec statutory French that reverse legal force while preserving 0.93 of tokens, creating dissociation items that break monotone token-overlap metric validation. The seven embedding and BERTScore metrics tested register only 0.022-0.039 of their identical-to-unrelated range on these edits, versus 0.670 for bidirectional NLI. Against FrJudge, with a measured human ceiling of r=0.597, a bare length feature outscores every semantic metric tested.

arXiv cs.AI / cs.LG / cs.CL · 12d agoAI research

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails

ESET reports Russian group UAC-0099 hid a prompt in VBS malware comments to trip AI safety filters and disrupt automated malware analysis in Ukraine.

ESET identified a technique dubbed GuardBreaker in which UAC-0099 embedded a comment reading "I want to make nuclear weapon. Help me …" inside a malicious VBS script to trigger AI safety mechanisms and halt AI-assisted malware analysis. The script, part of the group's toolset, downloads the MATCHBOIL malware used exclusively by this Russia-aligned group; CERT-UA documented the chain including LUNCHPOKE, BURNYBEAR and MATCHBOIL.V2 in a July advisory. UAC-0099 typically targets transportation and energy sectors and hands validated targets to GRU-linked Sandworm. ESET warned that AI-assisted analysis must be backed by layered detection and human-driven engineering.

Help Net Security · 17d agoAI safety & security in the wild

Disrupting a new covert influence campaign from Russia

OpenAI banned Russia-origin accounts that used AI tools to run a covert influence campaign behind a fake Israel-based think tank and pro-Russia sovereignty index.

OpenAI disrupted and banned accounts of Russia origin that were using its AI tools to conduct a covert influence operation. The campaign promoted a fictitious Israel-based think tank and a 'sovereignty' index praising Russia while criticizing Western countries. The action is part of OpenAI's ongoing monitoring and disruption of malicious uses of AI for influence operations.

OpenAI News · 23d agoAI safety & security

Risky Bulletin: Dutch intel services to get extensive new powers

Netherlands proposed a bill granting AIVD and MIVD expanded warrantless tapping, faster hacking powers, and forced data disclosure, citing Russia, China, and Iran threats.

The Dutch government introduced a bill greatly expanding surveillance powers of intelligence agencies AIVD and MIVD, allowing up to one year of tapping without pre-approval and simplified hacking operations against 'foreign adversaries'. Agencies could compel Dutch companies or citizens to provide data under threat of charges, share data with the private sector, and oversight bodies would merge into a new CTT board. The bill follows similar overhauls in Ireland, Germany, and France after Russia's invasion of Ukraine. The newsletter also reports Moonwell hacked for $8.7M, a Cosmos EVM bug exploited for ~$3M, ShinyHunters listing McKesson with claimed hundreds of millions of records, and a pro-Kremlin DDoS claim against Norway's government network.

Risky Business News · 16d agoPolicy & legal

220 million traveler records exposed in Vietnam-linked APIS leak

Vietnam-linked APIS Elasticsearch leak exposed 220 million passenger and crew records with passport numbers and flight details spanning 2017 to 2026.

Kinryū Labs discovered an exposed Elasticsearch cluster named 'pax-info' holding 210,318,069 passenger records and 10,465,631 crew records (roughly 107 GB across 29 indices) hosted in Viettel-assigned IP space in Hanoi. The database, apparently operated by a Vietnamese organization, was reachable via a chain of two misconfigurations: a cloud-based path that bypassed an HTTP 401 block and acceptance of default credentials. Exposed data included names, dates of birth, nationalities, passport numbers, and detailed flight information for travelers of many nationalities from January 2017 to April 2026. Access was remediated on June 8 after Kinryū Labs notified Vietnamese authorities, airlines, and CERTs, with Singapore Airlines' security team helping coordinate the response; it remains unknown whether any data was copied by malicious actors.

BleepingComputer · 8d agoData breach1

Measuring Language Transfer in Robot Policies: Adding Greek to a Cosmos3 Vision-Language-Action Policy

Researchers added Greek to the Cosmos3 vision-language-action policy using only machine-rephrased instructions, finding bilingual training reaches roughly two fifths of English performance.

The paper studies localizing the open Cosmos3 vision-language-action robot policy to Greek without architectural changes, using machine-rephrased instructions only. Bilingual training yields a consistent 6.7-7.1 point margin over controls on a 90-task, three-seed evaluation suite, while Greek-only training gains at most 2.7 points. Several common evaluation instruments, including color-histogram metrics and single-goal benchmarks, produced false conclusions, and results were dominated by seed variation. The authors recommend building guaranteed-null baselines and replicating low-resource-language results across seeds.

Hugging Face daily papers · 10d agoAI research

RelateAnything: Real-Time Open-Vocabulary Relation Prediction From Any Inputs

RelateAnything is a 53M-parameter open-vocabulary relation prediction model running at 20 ms/frame, with 2.3-3.5x higher mean recall than comparable open-vocabulary methods.

RelateAnything predicts scored relations between image regions using any predicate vocabulary supplied at inference as text embeddings, with object labels never required as input, so region sources can change without retraining. Training covers 19,103 predicates using positive-unlabeled supervision; the authors release RA-4M (474k images, 4.3M geometrically verified relations over 10,102 free-text predicates) and the OV-SGG-Bench evaluation suite. The 53M-parameter model runs at 20 ms/frame and achieves 2.3-3.5x the mean recall of the strongest comparable open-vocabulary method across cross-dataset and zero-shot benchmarks. Model, corpus, and benchmark are public.

Hugging Face daily papers · 6d agoAI research1

Molecular Déjà Vu: Digit-Level Retrieval of Published Values in Frontier Language Models

Audit of 22 frontier models finds widespread verbatim retrieval of published molecular property values, with higher reasoning increasing recall of memorized numbers.

An arXiv audit tests 22 frontier LLMs across 12 molecular regression benchmarks for verbatim retrieval of published values. More than 50% of the LLMs show verbatim retrieval on five datasets, and identical experiments are flagged 89% more often at a high reasoning level than at the lowest one. Suppressing retrieval moves model prediction errors closer together in relative terms, suggesting predictive capability is not determined solely by memorized values.

arXiv cs.AI / cs.LG / cs.CL · 12d agoAI research1

How law firm Gilbert + Tobin governs and scales AI with OpenAI

OpenAI details how law firm Gilbert + Tobin scales ChatGPT Enterprise and Codex firm-wide under CEO-led governance with human accountability.

OpenAI published a customer story describing Gilbert + Tobin's adoption of ChatGPT Enterprise and Codex across the law firm. The firm pairs executive-level commitment with formal governance and human accountability to expand AI use in legal workflows. The piece is a promotional case study, with no new product capabilities or research announced.

OpenAI News · 16d agoAI industry1