ZeroHour

Search: “donut”

63 stories

Project noRecognition: Teaching AI to Fool Surveillance Cameras

Security researcher Bill Swearingen's noRecognition project uses 31 million tested patterns to defeat license plate reader and surveillance camera AI detection.

Kansas City researcher Bill Swearingen built noRecognition, using reinforcement learning across roughly 31 million tests to generate printed patterns that break the detection layer of license plate readers and surveillance cameras. The strongest validated result achieved 61.7% non-detection against a detector taken from a real deployed camera, though most headline figures remain digital simulations. At DEF CON he covered a 2009 Toyota Yaris in a new pattern and reported it effective against a Flock Safety camera, with curved wheels the main weak point. He is crowdfunding apparel products and withholding his best patterns to prevent camera makers from blocking them.

Security Affairs · 29d agoAI safety & security

Why AI food looks like that

Experts explain why AI-generated food images look unappetizing, citing diffusion model limitations, weak structural reasoning, and stylized training data.

The Verge examines why AI-generated food imagery from restaurants and brands often appears grotesque, citing researchers from Oxford, Naples, Zurich, and London. Diffusion models recover coarse structure before fine texture, so structural errors like extra fingers or donut shrimp get baked in early. Researchers note the models are weak at thin, continuous, terminating structures such as noodles, and reproduce the glossy conventions of professional food photography without understanding the objects. Odd internet imagery and memes in training data further skew outputs toward strange textures and clustered holes.

The Verge · AI · 12d agoAI research

PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks

PAPERMILL phishing campaign abuses a signed Notepad++ copy and tax-audit lures to deploy VenomRAT against targets in India.

JUMPSEC tracks PAPERMILL as an emerging cluster whose emails pass SPF, DKIM, and DMARC and deliver tax-audit themed disk images. The mounted image pairs a legitimately signed, renamed executable with a rogue libcurl.dll for DLL sideloading, then uses a Donut shellcode loader to run VenomRAT 6.0.3 in memory with hidden VNC, data-stealing, and file-grabbing capabilities. The loader includes anti-analysis checks and RunOnce persistence, and lures plus China-connected infrastructure overlap with the Silver Fox ecosystem, though attribution remains unconfirmed.

Cyber Security News · 10h agoPhishing & fraud in the wild 2 sources

Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)

Malwarebytes' Lock and Code podcast examines loyalty-points theft, with LexisNexis' Kim Sutherland explaining why stolen airline and hotel points are lucrative for fraudsters.

LexisNexis Risk Solutions' Kim Sutherland says loyalty currency is worth roughly one cent per point, making 100,000 airline points worth about $1,000 in the US. Cited incidents include a Chicago teacher who lost 240,000 airline points, discovered only via a confirmation email, and a man whose miles were used to book rental cars in New York and Memphis. The episode discusses how points theft happens and what companies and consumers can do.

Malwarebytes Labs · 9d agoPhishing & fraud