<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Research and Reports</title><link>https://cybersecuritytracker.ai/?cats=research</link><description>Curated cybersecurity news and vulnerability intelligence.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:50 GMT</lastBuildDate><item><title>Cobalt adds Autonomous Pentest to scale application security testing</title><link>https://helpnetsecurity.com/2026/07/23/cobalt-adds-autonomous-pentest-to-scale-application-security-testing</link><guid isPermaLink="false">cst-3092</guid><description>Cobalt has launched an automated penetration testing service that provides results within 24 hours to help organizations test applications continuously rather than on traditional quarterly or monthly schedules. The offering addresses the challenge of expanding attack surfaces and growing adoption of AI by both defenders and attackers.</description><pubDate>Thu, 23 Jul 2026 12:54:14 GMT</pubDate></item><item><title>Post-quantum cryptography (PQC) migration workshop report</title><link>https://ncsc.gov.uk/blogs/post-quantum-cryptography-pqc-migration-workshop-report</link><guid isPermaLink="false">cst-2994</guid><description>The article discusses findings from a workshop focused on post-quantum cryptography (PQC) migration, highlighting that organizations cannot successfully execute this transition independently. The report emphasizes collaborative approaches and shared insights needed for managing the shift to quantum-resistant cryptographic standards.</description><pubDate>Wed, 22 Jul 2026 12:00:00 GMT</pubDate></item><item><title>MIT to Become Hotbed of AI Video Surveillance</title><link>https://schneier.com/blog/archives/2026/07/mit-to-become-hotbed-of-ai-video-surveillance.html</link><guid isPermaLink="false">cst-2913</guid><description>MIT is installing over 500 AI-equipped surveillance cameras across campus buildings, residence halls, and outdoor areas between November 2025 and September 2026, with a budget exceeding $3 million. The cameras use deep learning to perform real-time facial recognition, object classification, and behavioral detection including motion, loitering, and crowd identification. Collected data is retained for up to 30 days unless an exception applies.</description><pubDate>Tue, 21 Jul 2026 11:07:13 GMT</pubDate></item><item><title>What the World Cup can teach us about cybersecurity resilience</title><link>https://cyberscoop.com/world-cup-2026-major-event-cybersecurity-resilience-op-ed</link><guid isPermaLink="false">cst-2893</guid><description>The World Cup concluded without reported major cyber disruptions, though the FBI warned of fraudulent websites impersonating FIFA during the tournament. The absence of headline-grabbing breaches reflects months of planning, coordination, and information sharing across governments, venues, payment systems, and law enforcement agencies working as an integrated ecosystem. Successful resilience depends on pre-event relationship-building, clear roles, shared intelligence, and response protocols that extend beyond traditional stadium perimeters to include vendors, ticketing platforms, transportation, and operational technology systems.</description><pubDate>Tue, 21 Jul 2026 10:00:00 GMT</pubDate></item><item><title>PR3TACK preemptive framework maps threats before attackers use them</title><link>https://helpnetsecurity.com/2026/07/21/first-pr3tack-preemptive-framework</link><guid isPermaLink="false">cst-2880</guid><description>PR3TACK is an open framework developed by an Atlassian security researcher that catalogs plausible attacker tactics, techniques, and procedures before they appear in the wild. The framework addresses the gap between when attackers develop new methods and when defenders detect and respond to them. Unlike traditional defensive models that document observed attacks, PR3TACK proactively maps potential threat techniques to enable earlier detection and mitigation.</description><pubDate>Tue, 21 Jul 2026 04:59:51 GMT</pubDate></item><item><title>Meet Dusseldorf, Microsoft’s open-source out-of-band security platform</title><link>https://helpnetsecurity.com/2026/07/20/microsoft-dusseldorf-out-of-band-application-security-testing-oast-platform</link><guid isPermaLink="false">cst-2809</guid><description>Microsoft has released Dusseldorf, an open-source out-of-band application security testing platform designed to run in private environments. The tool captures inbound network traffic across multiple protocols and enables automated response crafting for validation workflows, addressing infrastructure gaps researchers typically build themselves when testing for out-of-band vulnerabilities.</description><pubDate>Mon, 20 Jul 2026 06:00:36 GMT</pubDate></item><item><title>Details of Alan Turing’s Voice Encryption System</title><link>https://schneier.com/blog/archives/2026/07/details-of-alan-turings-voice-encryption-system.html</link><guid isPermaLink="false">cst-2764</guid><description>In November 2023, a collection of Alan Turing's wartime papers sold at auction in London for approximately half a million US dollars. The cache, known as the Bayley papers, includes handwritten materials documenting Turing's classified Delilah project from 1943 to 1945, a portable voice-encryption system. The papers survived because Donald Bayley, a colleague who worked with Turing, preserved them until his death in 2020.</description><pubDate>Fri, 17 Jul 2026 11:02:21 GMT</pubDate></item><item><title>A hard drive reliability check on 341,263 drives, from 4TB to past 20TB</title><link>https://helpnetsecurity.com/2026/07/17/hard-drive-reliability-2026-4tb-20tb</link><guid isPermaLink="false">cst-2742</guid><description>Backblaze released a Q1 2026 reliability report covering 341,263 hard drives ranging from 4TB to over 20TB capacity in its cloud storage fleet. The analysis tracks real-world failure rates across a diverse range of drive sizes operating in continuous-use conditions, excluding boot drives and units below reporting thresholds.</description><pubDate>Fri, 17 Jul 2026 04:30:17 GMT</pubDate></item><item><title>AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report</title><link>https://unit42.paloaltonetworks.com/ai-incident-response-report</link><guid isPermaLink="false">cst-2733</guid><description>Unit 42 has published a 2026 Global Incident Response Report examining how AI and automation are shaping cybersecurity threats and incident response practices. The report synthesizes observations from the team's incident response engagements throughout the year.</description><pubDate>Thu, 16 Jul 2026 23:00:59 GMT</pubDate></item><item><title>Period tracker Stardust shares users’ health data with analytics firm, says Mozilla research</title><link>https://techcrunch.com/2026/07/16/period-tracker-stardust-shares-users-health-data-with-analytics-firm-says-mozilla-research</link><guid isPermaLink="false">cst-2713</guid><description>Mozilla research on period tracker applications revealed significant privacy disparities among tested apps, with one application sharing users' health data with an analytics firm while another demonstrated strong privacy protections. The findings highlight inconsistent data handling practices in the period tracking app ecosystem.</description><pubDate>Thu, 16 Jul 2026 15:33:28 GMT</pubDate></item><item><title>What public money does to open-source projects</title><link>https://helpnetsecurity.com/2026/07/16/open-source-projects-funding-impact</link><guid isPermaLink="false">cst-2647</guid><description>Open-source software comprises approximately 96 percent of enterprise codebases, yet most of it is maintained by unpaid volunteers. Recent supply chain incidents like the log4j vulnerability in December 2021 and the xz utils backdoor in 2024 have highlighted the risks of relying on under-resourced projects. The article examines how public funding affects open-source project sustainability and security.</description><pubDate>Thu, 16 Jul 2026 05:30:58 GMT</pubDate></item><item><title>A Video Screen That Is Also a Camera</title><link>https://schneier.com/blog/archives/2026/07/a-video-screen-that-is-also-a-camera.html</link><guid isPermaLink="false">cst-2591</guid><description>Researchers at ETH Zurich developed a pixel technology called a Fourier pixel that can simultaneously display video and capture images by manipulating light intensity, phase, and polarization. The innovation, published in Nature, enables pixels to function as both emitters and sensors in a single component. This advancement moves toward dual-purpose display and camera systems in a single device.</description><pubDate>Wed, 15 Jul 2026 11:04:06 GMT</pubDate></item><item><title>Recent DShield SIEM Update</title><link>https://isc.sans.edu/diary/rss/33156</link><guid isPermaLink="false">cst-2542</guid><description>DShield SIEM received an update in September 2025 that added TTY log collection and Suricata integration to its monitoring capabilities. The system now uses ELK stack version 8.19.15 and includes additional dashboards that allow security practitioners to review command activity on DShield sensors, with logs parsed and uploaded daily and cross-linked across visualizations.</description><pubDate>Wed, 15 Jul 2026 01:38:43 GMT</pubDate></item><item><title>Download: The ultimate guide to network operations management</title><link>https://helpnetsecurity.com/2026/07/14/tines-network-operations-management-guide</link><guid isPermaLink="false">cst-2485</guid><description>A downloadable guide discusses challenges in modern network operations management, highlighting manual processes, growing complexity, and operational inefficiencies. The resource explores how intelligent workflows can reduce manual work, improve visibility, and accelerate response across network operations teams.</description><pubDate>Tue, 14 Jul 2026 13:00:55 GMT</pubDate></item><item><title>Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks</title><link>https://thehackernews.com/2026/07/study-of-85-crypto-wallet-extensions.html</link><guid isPermaLink="false">cst-2477</guid><description>Researchers at KU Leuven analyzed 85 popular cryptocurrency wallet browser extensions and identified privacy vulnerabilities that allow address linking and cross-site tracking. The wallet communication patterns with websites and blockchain servers expose user activity in ways that enable deanonymization and user tracking across sites.</description><pubDate>Tue, 14 Jul 2026 11:55:00 GMT</pubDate></item><item><title>Fake smart home residents could stand in for real ones in security research</title><link>https://helpnetsecurity.com/2026/07/14/iot-smart-home-security-research</link><guid isPermaLink="false">cst-2459</guid><description>Researchers are developing synthetic smart home usage data to supplement real-world recordings for security testing, potentially accelerating research by reducing the need for costly, invasive monitoring of actual homes. The approach creates artificial resident profiles and behaviors to generate larger and more diverse datasets that reflect varied household patterns.</description><pubDate>Tue, 14 Jul 2026 05:30:26 GMT</pubDate></item><item><title>Guide to System Hardening: Checklist &amp; Best Practices [2026] | Huntress</title><link>https://huntress.com/blog/system-hardening-checklist</link><guid isPermaLink="false">cst-2428</guid><description>A Huntress guide presents a checklist and best practices for system hardening to reduce vulnerabilities that threat actors can exploit. The resource covers practical steps to secure computing environments and address common security gaps.</description><pubDate>Fri, 10 Jul 2026 13:00:00 GMT</pubDate></item><item><title>From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale</title><link>https://thehackernews.com/2026/07/from-17000-to-11-million-assets-how.html</link><guid isPermaLink="false">cst-2320</guid><description>Lumen Technologies expanded its asset inventory from 17,000 to 1.1 million assets by consolidating and improving exposure management capabilities. The article references survey data showing that only 45 percent of organizations consolidate asset and exposure data into a single view, and notes that inaccurate inventories cascade through downstream security programs.</description><pubDate>Fri, 10 Jul 2026 11:39:40 GMT</pubDate></item><item><title>AI Surveillance and Social Progress</title><link>https://schneier.com/blog/archives/2026/07/ai-surveillance-and-social-progress.html</link><guid isPermaLink="false">cst-2316</guid><description>AI-powered surveillance systems combining facial recognition, real-time tracking, and automated enforcement are being deployed globally to monitor public behavior and issue immediate sanctions for rule violations. China operates over 600 million surveillance cameras integrated with social credit systems that publicly shame and restrict citizens deemed untrustworthy, while similar systems are being tested in North America, Europe, and other regions. The technology's primary impact may be widespread self-censorship and behavioral conformity rather than objective public safety.</description><pubDate>Fri, 10 Jul 2026 11:02:04 GMT</pubDate></item><item><title>Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking</title><link>https://thehackernews.com/2026/07/study-of-281-free-android-vpn-apps.html</link><guid isPermaLink="false">cst-2322</guid><description>Researchers tested 281 popular free Android VPN apps and found basic security failures in many, including traffic leaks, unencrypted data handling, and user tracking. The affected apps have been installed over 2.4 billion times. The vulnerabilities identified represent fundamental failures of VPN functionality rather than sophisticated attacks.</description><pubDate>Fri, 10 Jul 2026 10:56:23 GMT</pubDate></item><item><title>The open source library holding up your stack might have one maintainer</title><link>https://helpnetsecurity.com/2026/07/10/open-source-software-library-types</link><guid isPermaLink="false">cst-2301</guid><description>A new research paper examines how open source libraries vary dramatically in their maintenance models and governance, from well-resourced projects to those maintained by a single person in spare time. Despite carrying the same label, these differences can significantly affect the behavior and security posture of software that depends on them.</description><pubDate>Fri, 10 Jul 2026 07:00:16 GMT</pubDate></item><item><title>Wiz in the Verizon DBIR: How AI Acceleration and Cloud Sprawl Impact Modern Defense</title><link>https://wiz.io/blog/verizon-dbir-2026-ai-cloud-security</link><guid isPermaLink="false">cst-2276</guid><description>Verizon's Data Breach Investigations Report (DBIR) examines how attackers exploit common weaknesses with accelerating speed and scale. Wiz research contributes insights on vulnerabilities, trust relationships, and artificial intelligence (AI) in cloud environments. The analysis suggests that AI adoption and cloud expansion are reshaping the threat landscape for defenders.</description><pubDate>Thu, 09 Jul 2026 16:18:49 GMT</pubDate></item><item><title>The Language of AI Could Change How Humans Speak</title><link>https://schneier.com/blog/archives/2026/07/the-language-of-ai-could-change-how-humans-speak.html</link><guid isPermaLink="false">cst-2248</guid><description>Large language models trained primarily on written text and scripted speech may influence how humans communicate by introducing linguistic patterns like shorter sentences, reduced vocabulary range, and formulaic responses that differ from natural conversation. As AI-generated content becomes more prevalent and AI systems increasingly train on text produced by other AI systems, these patterns could reshape human speech patterns, potentially narrowing vocabulary use, introducing confirmation bias, and eroding conversational norms like courtesy.</description><pubDate>Thu, 09 Jul 2026 11:00:45 GMT</pubDate></item><item><title>European Organizations Have a Collaboration Security Confidence Gap</title><link>https://darkreading.com/cybersecurity-operations/european-organizations-collaboration-security-confidence-gap</link><guid isPermaLink="false">cst-2230</guid><description>A survey of European security leaders reveals a mismatch between their perceived security posture and actual risks in collaboration tools and platforms. The findings suggest many organizations are overconfident about the protection of their collaborative environments despite underlying vulnerabilities.</description><pubDate>Thu, 09 Jul 2026 08:00:00 GMT</pubDate></item><item><title>Open-source collaboration is growing worldwide and putting pressure on maintainers</title><link>https://helpnetsecurity.com/2026/07/09/github-open-source-collaboration</link><guid isPermaLink="false">cst-2218</guid><description>GitHub reports that cross-border open-source collaboration grew 16% from Q4 2025 to Q1 2026, with developers increasingly contributing code and pull requests to public repositories internationally. This marks the second-highest quarter-over-quarter growth since 2020, approaching the surge seen in Q2 2020. The trend is placing mounting pressure on open-source project maintainers.</description><pubDate>Thu, 09 Jul 2026 05:10:05 GMT</pubDate></item><item><title>My Stack Simulator</title><link>https://isc.sans.edu/diary/rss/33138</link><guid isPermaLink="false">cst-2146</guid><description>A security researcher has created a stack simulator tool to help students visualize how the stack memory region works during program execution, particularly for malware analysis students learning assembly language. The simulator allows users to select architecture, choose predefined instruction sets, step through code execution, and observe real-time changes to the stack and registers similar to a debugger interface.</description><pubDate>Wed, 08 Jul 2026 08:09:03 GMT</pubDate></item><item><title>20 open-source cybersecurity tools to keep your team ready for anything</title><link>https://helpnetsecurity.com/2026/07/08/20-latest-open-source-cybersecurity-tools</link><guid isPermaLink="false">cst-2131</guid><description>An article highlighting 20 open-source cybersecurity tools that address emerging security needs, including vulnerability research, application security testing, container security, endpoint protection, AI security, and penetration testing. The roundup emphasizes how AI is changing security workflows and includes examples like AIMap, a tool for discovering and testing exposed AI endpoints.</description><pubDate>Wed, 08 Jul 2026 05:30:52 GMT</pubDate></item><item><title>How to implement a continuous offensive security testing program</title><link>https://helpnetsecurity.com/2026/07/08/picus-continuous-offensive-security-testing-program</link><guid isPermaLink="false">cst-2133</guid><description>Continuous offensive security testing addresses the limitation of point-in-time penetration tests, which become outdated as environments change and controls drift. The article discusses the challenge of deciding how to remediate findings and maintaining confidence in those decisions over time as security postures evolve.</description><pubDate>Wed, 08 Jul 2026 04:30:31 GMT</pubDate></item><item><title>Google Is Suing Chinese Scammers Who Are Using Gemini</title><link>https://schneier.com/blog/archives/2026/07/google-is-suing-chinese-scammers-who-are-using-gemini.html</link><guid isPermaLink="false">cst-529</guid><description>Google filed a lawsuit against Outsider Enterprise, a Chinese scam operation that uses Telegram to offer phishing-as-a-service. The group provided instructions on leveraging Google's Gemini AI to create fraudulent websites mimicking Google, YouTube, and government agencies like New York's E-ZPass, with nearly 300 scam templates available. Google coordinated with major carriers to block malicious text messages and notes that its on-device scam detection in Google Messages blocks approximately 10 billion spam texts monthly.</description><pubDate>Tue, 07 Jul 2026 10:43:40 GMT</pubDate></item><item><title>5 Cybersecurity Lessons From Taylor &amp; Travis’s Wedding</title><link>https://huntress.com/blog/cybersecurity-lessons-taylor-swift-wedding</link><guid isPermaLink="false">cst-2290</guid><description>This article draws cybersecurity lessons from Taylor Swift and Travis Kelce's wedding, discussing concepts like layered defense and multifactor authentication (MFA) through the lens of event security.</description><pubDate>Tue, 07 Jul 2026 07:00:00 GMT</pubDate></item><item><title>2607_agents_vs_telemetry</title><link>https://sophos.com/en-us/blog/2607_agents_vs_telemetry</link><guid isPermaLink="false">cst-2085</guid><description>An X-Ops analysis examines how artificial intelligence (AI) coding agents trigger endpoint detection and response (EDR) rules that were originally designed to catch adversarial activity. The research highlights potential blind spots in security monitoring systems when legitimate AI tools behave similarly to malicious actors.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate></item><item><title>RCS and DNS: The NAPTR Record</title><link>https://isc.sans.edu/diary/rss/33124</link><guid isPermaLink="false">cst-156</guid><description>RCS (Rich Communication Services) is increasingly used on modern iOS and Android devices as a potential replacement for SMS, featuring optional end-to-end encryption and digital signing. The article explains how NAPTR (Naming Authority Pointer) DNS records, defined in RFC 2915, are being used to locate RCS servers by enabling clients to discover SIP-based service endpoints rather than just IP addresses.</description><pubDate>Mon, 06 Jul 2026 13:35:58 GMT</pubDate></item><item><title>ISC Stormcast For Monday, July 6th, 2026</title><link>https://isc.sans.edu/diary/rss/33122</link><guid isPermaLink="false">cst-157</guid><description>The article is an ISC Stormcast podcast episode from July 6th, 2026. No substantive content was provided in the source material to summarize.</description><pubDate>Mon, 06 Jul 2026 11:36:06 GMT</pubDate></item><item><title>France to Stop Certifying Non-Quantum-Safe Encryption</title><link>https://schneier.com/blog/archives/2026/07/france-to-stop-certifying-non-quantum-safe-encryption.html</link><guid isPermaLink="false">cst-412</guid><description>France's cybersecurity agency ANSSI announced it will cease certifying security products lacking quantum-resistant encryption starting in 2027, with a recommendation that businesses adopt quantum-safe products by 2030. This policy applies to French government agencies and critical infrastructure operators, effectively mandating a transition from legacy encryption systems.</description><pubDate>Mon, 06 Jul 2026 10:45:44 GMT</pubDate></item><item><title>Cybersecurity Mission Creep in the US</title><link>https://schneier.com/blog/archives/2026/07/cybersecurity-mission-creep-in-the-us.html</link><guid isPermaLink="false">cst-414</guid><description>A legal analysis examines how policymakers increasingly frame diverse policy issues, including misinformation, content moderation, antitrust, and anti-trafficking efforts, as cybersecurity problems. This reframing grants these issues an aura of urgency and existential threat, potentially bypassing normal deliberation and deferring to expert-driven solutions that may oversimplify underlying problems and reduce governance transparency.</description><pubDate>Thu, 02 Jul 2026 11:11:44 GMT</pubDate></item><item><title>Recorded FutureがGartner® サイバー脅威インテリジェンス・テクノロジー部門のMagic Quadrant™のリーダーの１社に位置づけられました。</title><link>https://recordedfuture.com/blog/gartner-mq-announcement-jp</link><guid isPermaLink="false">cst-2613</guid><description>Recorded Future was named a Leader in Gartner's Magic Quadrant for Cyber Threat Intelligence Technology, evaluated among 17 vendors in a comprehensive analysis of market trends and vendor positioning.</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate></item><item><title>2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience</title><link>https://thehackernews.com/2026/07/2026-cybersecurity-assessment-gap.html</link><guid isPermaLink="false">cst-50</guid><description>A Bitdefender survey of 1,200 IT and cybersecurity professionals reveals a disconnect between organizations' awareness of cyber risk and their ability to translate that awareness into operational resilience. The 2026 Cybersecurity Assessment highlights contradictions in how organizations understand and respond to cybersecurity challenges.</description><pubDate>Wed, 01 Jul 2026 11:30:00 GMT</pubDate></item><item><title>Papa Johns Surveillance-Based Advertising</title><link>https://schneier.com/blog/archives/2026/07/papa-johns-surveillance-based-advertising.html</link><guid isPermaLink="false">cst-415</guid><description>Papa Johns partnered with NBCUniversal, Instacart, and Carat to create targeted advertising based on grocery purchasing patterns, identifying consumers likely running low on food staples and serving them pizza ads on streaming platforms. The campaign used custom audience data from Instacart shoppers to predict when individuals would need food, with ads tailored to buying behavior and featuring calls to action like "Light on groceries?" The effort aims to reach consumers at moments of high purchase intent while maintaining plausible deniability about the surveillance element.</description><pubDate>Wed, 01 Jul 2026 10:53:23 GMT</pubDate></item><item><title>The Realities of AI Video Surveillance</title><link>https://schneier.com/blog/archives/2026/06/the-realities-of-ai-video-surveillance.html</link><guid isPermaLink="false">cst-416</guid><description>Artificial intelligence is expanding video surveillance capabilities by enabling natural language queries on video footage, allowing analysts to search for specific behaviors and patterns across massive video streams. Instead of using preset search categories, intelligence and law enforcement agencies can now ask open-ended questions about video content, such as identifying individuals with changed appearances, suspicious object exchanges, or vehicles with specific movement patterns. This shift from object-based to behavior-based surveillance represents a significant escalation in monitoring capabilities.</description><pubDate>Tue, 30 Jun 2026 12:05:57 GMT</pubDate></item><item><title>Factoring RSA Keys with Many Zeros</title><link>https://schneier.com/blog/archives/2026/06/factoring-rsa-keys-with-many-zeros.html</link><guid isPermaLink="false">cst-417</guid><description>Researchers discovered a new class of weak RSA keys characterized by regularly spaced blocks of zeros in their moduli, found in real-world deployments including expired certificates for Yahoo and Verizon, and SSH hosts running CompleteFTP software. The CompleteFTP vulnerability affects RSA keys generated in versions 10.0.0 through 12.0.0 and DSA keys up to version 23.0.4, with cryptanalytic algorithms potentially tailored to exploit this specific weakness. The findings suggest independent implementations failed similarly, raising questions about whether additional cryptographic products contain comparable flaws.</description><pubDate>Mon, 29 Jun 2026 16:05:18 GMT</pubDate></item><item><title>Adding some Automation to the favicon.ico method of Host Recon</title><link>https://isc.sans.edu/diary/rss/33110</link><guid isPermaLink="false">cst-160</guid><description>A security practitioner describes automating the process of discovering in-scope hosts during penetration testing by extracting favicon.ico file hashes and querying Shodan's API to find other hosts sharing the same icon. The workflow uses command-line tools to hash favicons, search Shodan, parse JSON results with jq, and generate a clean list of hostnames suitable for further reconnaissance activities like network scanning.</description><pubDate>Mon, 29 Jun 2026 12:00:54 GMT</pubDate></item><item><title>Robot Police Officers</title><link>https://schneier.com/blog/archives/2026/06/robot-police-officers.html</link><guid isPermaLink="false">cst-418</guid><description>The Sacramento County Sheriff's Office successfully used a drone equipped with a high-powered magnet to disarm a suspect and retrieve a knife during a standoff in June. The suspect had refused to respond to negotiators and was hiding in a garage when the drone located and extracted the weapon. The operation demonstrates emerging tactical applications for unmanned systems in law enforcement scenarios.</description><pubDate>Mon, 29 Jun 2026 10:55:33 GMT</pubDate></item><item><title>The Chinese Control the Majority of Argentina’s Squid Fleet</title><link>https://schneier.com/blog/archives/2026/06/the-chinese-control-the-majority-of-argentinas-squid-fleet.html</link><guid isPermaLink="false">cst-419</guid><description>Chinese companies own and operate nearly two-thirds of Argentina's squid fishing fleet, giving them substantial control over the country's squid industry and marine resources.</description><pubDate>Fri, 26 Jun 2026 20:57:04 GMT</pubDate></item><item><title>Meta Is Testing Facial Recognition for Police and Military</title><link>https://schneier.com/blog/archives/2026/06/meta-is-testing-facial-recognition-for-police-and-military.html</link><guid isPermaLink="false">cst-420</guid><description>Meta is developing facial recognition technology for use by law enforcement and military agencies, with prototyping work involving a Pentagon supplier. The technology would enable real-time identification capabilities, similar to systems that U.S. Immigration and Customs Enforcement (ICE) has sought to deploy.</description><pubDate>Fri, 26 Jun 2026 16:40:56 GMT</pubDate></item><item><title>New Initiative Tackles Security for End-of-Life Open Source Software</title><link>https://darkreading.com/application-security/initiative-tackles-security-end-of-life-open-source</link><guid isPermaLink="false">cst-101</guid><description>The Open Source Sustainability Initiative aims to help enterprises manage security and compliance for aging open source projects that have reached end of life. The initiative addresses the challenge of maintaining vulnerable legacy code while meeting regulatory requirements.</description><pubDate>Fri, 26 Jun 2026 16:32:30 GMT</pubDate></item><item><title>One Million Passports Leaked Online</title><link>https://schneier.com/blog/archives/2026/06/one-million-passports-leaked-online.html</link><guid isPermaLink="false">cst-421</guid><description>A database containing nearly one million passports was exposed online after being compromised from an identity verification system used by cannabis dispensaries. The incident highlights how high-value credentials like passports were leveraged in a lower-security authentication system, creating a significant security risk.</description><pubDate>Fri, 26 Jun 2026 11:03:21 GMT</pubDate></item><item><title>Close Encounters of the Human Kind</title><link>https://blog.talosintelligence.com/close-encounters-of-the-human-kind</link><guid isPermaLink="false">cst-353</guid><description>The article is primarily a philosophical commentary on human decision-making and information processing in cybersecurity contexts, using a Spielberg film as a framing device. It argues that knowing what security controls to implement (patching, MFA, segmentation, backups) is easier than actually executing them due to competing priorities and resource constraints. The piece includes a brief technical note about Cisco Talos presenting a new reverse engineering approach that integrates AI agents with traditional disassembly tools through a COM interface to automate analysis workflows locally.</description><pubDate>Thu, 18 Jun 2026 18:00:24 GMT</pubDate></item><item><title>Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model</title><link>https://blog.talosintelligence.com/scripting-the-disassembler</link><guid isPermaLink="false">cst-354</guid><description>A research blog describes how to enable agentic reverse engineering by exposing a disassembler's internal object model through COM scripting interfaces rather than embedding AI features directly. vbdec, a Visual Basic 6 decompiler, publishes its parsed binary data through the Windows Running Object Table (ROT) and provides AI agent documentation and type definitions, allowing local large language model instances to automate analysis tasks through script-based queries. This approach keeps analyst data local while enabling AI agents to iteratively explore and report on binary structures without modifying the core application or uploading samples.</description><pubDate>Thu, 18 Jun 2026 10:00:05 GMT</pubDate></item><item><title>Gartner Security Summit 2026: Huntress 5 Key Takeaways</title><link>https://huntress.com/blog/key-takeaways-gartner-security-risk-summit</link><guid isPermaLink="false">cst-676</guid><description>Gartner Security &amp; Risk Management Summit 2026 highlighted three major themes: resilience, identity, and practical artificial intelligence (AI) applications. The article identifies five key takeaways for security leaders to consider.</description><pubDate>Tue, 09 Jun 2026 07:00:00 GMT</pubDate></item><item><title>State of Post Quantum Cryptography</title><link>https://wiz.io/blog/state-of-post-quantum-cryptography</link><guid isPermaLink="false">cst-1270</guid><description>This story discusses post-quantum cryptography (PQC) adoption trends and statistics based on customer data and other sources. It provides insights into current PQC implementation rates and readiness levels across organizations.</description><pubDate>Thu, 28 May 2026 13:34:55 GMT</pubDate></item></channel></rss>