惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

N
News and Events Feed by Topic
T
The Exploit Database - CXSecurity.com
P
Palo Alto Networks Blog
T
Threat Research - Cisco Blogs
Cloudbric
Cloudbric
Recent Commits to openclaw:main
Recent Commits to openclaw:main
I
Intezer
Attack and Defense Labs
Attack and Defense Labs
P
Privacy International News Feed
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
L
Lohrmann on Cybersecurity
C
Cybersecurity and Infrastructure Security Agency CISA
V2EX - 技术
V2EX - 技术
AWS News Blog
AWS News Blog
O
OpenAI News
L
LINUX DO - 最新话题
N
News | PayPal Newsroom
PCI Perspectives
PCI Perspectives
www.infosecurity-magazine.com
www.infosecurity-magazine.com
T
Troy Hunt's Blog
Latest news
Latest news
D
Darknet – Hacking Tools, Hacker News & Cyber Security
A
Arctic Wolf
Spread Privacy
Spread Privacy
G
GRAHAM CLULEY
T
Tor Project blog
博客园_首页
Know Your Adversary
Know Your Adversary
有赞技术团队
有赞技术团队
S
Secure Thoughts
美团技术团队
Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
T
Tailwind CSS Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
V
Visual Studio Blog
J
Java Code Geeks
Cisco Talos Blog
Cisco Talos Blog
Schneier on Security
Schneier on Security
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
S
Security Affairs
Jina AI
Jina AI
人人都是产品经理
人人都是产品经理
雷峰网
雷峰网
宝玉的分享
宝玉的分享
量子位
Last Week in AI
Last Week in AI
月光博客
月光博客
罗磊的独立博客
S
SegmentFault 最新的问题

The Register - Security: Research

www.theregister.com Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine ChatGPT blindly trusts browser content, turning the page into a payload Russia-linked threat group put ChatGPT to work from lure to payload Kids can bypass some age checks with a drawn-on mustache What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia ORNL builds more sensitive GPS interference detector Researchers find sabotage malware that may predate Stuxnet Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus Anthropic, Google, Microsoft paid AI bug bounties – quietly Security reserchers tricked Apple Intelligence into cursing Don't open that WhatsApp message, Microsoft warns Security boffins harvest bumper crop of API keys from web Lightning-fast exploits mean patch fast, says Cisco Talos AI agents are 'gullible' and easy to turn into your minions Smooth criminals talking their way into cloud environments, Google says Snoops plant info-stealing malware on iPhones, Google warns Cybercrime up 245% since the start of the Iran war Rogue AI agents can work together to hack systems Fake applicants are sending security-killing malware AI agent hacked McKinsey chatbot for read-write access Kaspersky: No signs Coruna iPhone exploit kit made by US Perplexity Comet browser hole was exploitable via cal invite DEF CON hackers 'fed up with government,' Jake Braun says Ransomware payments cratered in 2025 – attacks did not Ransomware payments cratered in 2025 – attacks did not Claude's collaboration tools allowed remote code execution AI takes a swing at online anonymity Fake 'interview' repos lure Next.js devs into running secret-stealing malware Threat intelligence supply chain is full of weak links AI agents abound, unbound by rules or safety disclosures RAT disguised as an RMM costs crims $300 a month Android malware taps Gemini to navigate infected devices Posting AI caricatures on social media is bad for security Payroll pirates conned the help desk, stole employee’s pay Microsoft boffins show LLM safety can be trained away For the price of Netflix, crooks can rent AI crime ops For the price of Netflix, crooks can rent AI crime ops Fast Pair, loose security: Bluetooth accessories open to silent hijack Fast Pair flaw exposes Bluetooth devices to hijacking A simple CodeBuild flaw put every AWS environment at risk A simple CodeBuild flaw put every AWS environment at risk DeadLock ransomware uses smart contracts to evade defenders Python libraries in AI/ML models can be poisoned w metadata OpenAI patches déjà vu prompt injection vuln in ChatGPT Fake Windows BSODs check in at Europe's hotels to con staff into running malware Hotel staff tricked into installing malware by bogus BSODs Your car’s web browser may be on the road to cyber ruin China's Ink Dragon hides out in European government networks Browser 'privacy' extensions have eye on your AI, log all your chats NCSC finds cyber deception tools work, if deployed right 10K Docker images spray live cloud creds across the internet 'Botnets in physical form' are top humanoid robot risk 'Botnets in physical form' are top humanoid robot risk Apache warns of 10.0-rated flaw in Tika metadata toolkit Novel clickjacking attack relies on CSS and SVG 'Exploitation is imminent' of max-severity React bug Swiss government bans SaaS and cloud for sensitive info Scattered Lapsus$ Hunters stress testing Zendesk weak spots HashJack attack shows AI browsers can be fooled with '#' New ClickFix attacks use fake Windows Updates to swipe creds Years-old bugs in open source took out major clouds at risk LLM-generated malware improving, but not operational (yet) 3.5B WhatsApp users' info scooped through enumeration flaw 3.5B WhatsApp users' info scooped through enumeration flaw 50k more ASUS routers pwned by evolving Beijing-linked op Overconfidence is the new zero-day as teams stumble through cyber simulations LLM side-channel attack could allow snoops to guess topic Landfall spyware used in 0-day attacks on Samsung phones MIT Sloan shelves paper about AI-driven ransomware Security hole slams Chromium browsers - no fix yet OpenAI Atlas Browser tripped up by malformed URLs Devs of VS Code extensions are leaking secrets en masse Chatbots that butter you up make you worse at conflict Tile trackers leak unencrypted Bluetooth data, say boffins Beijing's RedNovember hacked critical US, global orgs Lazarus RAT code resurfaces in North Korean IT-worker scams Suspected Chinese spies broke into 'numerous' enterprises Deepfaked calls hit 44% of businesses in last year: Gartner Kaspersky: RevengeHotels returns with AI-coded malware Ruh-roh. DDR5 memory vulnerable to new Rowhammer attack HybridPetya ransomware dodges UEFI Secure Boot
DEF CON hackers 'fed up with government,' Jake Braun says
Jessica Lyons Jessica Lyons · 2026-02-28 · via The Register - Security: Research

INTERVIEW Hackers – especially Jake Braun – are "fed up with government."

Braun was one of the creators of the first-ever Voting Machine Hacking Village at DEF CON in 2017 and served as a homeland security and cyber advisor to the Obama and Biden administrations. He also co-founded the Franklin project, named for Benjamin Franklin, who founded America's first volunteer fire department and published the annual Poor Richard's Almanack – an eclectic collection of useful facts and other musings.

The Franklin project, which launched at DEF CON in 2024, enlists hackers to secure critical infrastructure, and 350 people signed up that year to donate their time and talent to securing water facilities.

Another of the project’s activities is publishing an annual Hacker's Almanack in homage to Franklin’s effort.

The second volume, the DEF CON 33 Hackers' Almanack, [PDF] landed earlier this month.

We saw society moving in the right direction for the last 500 years because of our commitment to science, human rights, and that seems to be at the very least slowing down, if not reversing

"Thinking back to Ben Franklin, we saw society moving in the right direction for the last 500 years because of our commitment to science, human rights, etc., and that seems to be at the very least slowing down, if not reversing,” Braun told The Register.

Braun said he blames government for this state of affairs – pointedly "the inability of government to continue to make the progress we saw from the enlightenment."

"This community is so committed to these principles of human rights and freedom of speech and science, that that when we see people fuck with them – or when we see the people that we elect to preserve these things not doing their fucking job – we're just like: ‘Fuck you guys,’" Braun said.

The Almanack highlights three major, all-of-society threats that governments have yet to fix: Cybercrime, AI, and - the biggie - authoritarianism. It presents a year's worth of DEF CON research on these three topics and shows how hackers are responding to each one.

AI for offense

Braun says he and the rest of the DEF CON volunteers listened to "dozens and dozens" of talks before this year's three topics bubbled to the surface.

"We started seeing lots of instances where AI was winning or placing high in these hacker competitions, and that wasn't happening last year," Braun said. "That's new and also something we're worried about: When is this going to be the case that AI is as good as humans at hacking, and way better than humans [alone] once paired with a human?"

Anthropic researcher Keane Lucas entered his company's AI coding tool Claude into seven competitions during DEF CON 33, including capture-the-flag contests. During one of these - PicoCTF - it placed in the top three percent globally, while also successfully fending off red-team attacks in the Collegiate Cyber Defense Challenge.

Claude did struggle with more difficult challenges, and also made up some of its own flags.

Still, Claude's performance and other research presented at the convention illustrate "the accelerating power of AI for offense," according to the Almanack. Meanwhile, security remains an afterthought.

"There's clearly more of a sense across the board than there was last year that we need the 20 critical controls for AI," Braun said, pointing to the Center for Internet Security's (CIS) Critical Security Controls as an example of what this would look like. "We need an industry-wide, accepted definition like what CIS has been doing, and I don't see any real movement toward that yet."

Combatting cybercrime

This year's cybercrime theme, "Hackers don cape and mask," emerged after listening to accounts of DEF CON researchers performing feats such as taking down Russian dark web marketplace Solaris and its affiliated hacker collective, Killnet, and unveiling the real-world identity of phishing scammer Darcula, who is responsible for hundreds of thousands of people losing millions of dollars.

"These guys are taking down ransomware groups, and dealing with criminals in prison, and hacking the Russian firewall - it's just fascinating," Braun said.

Global governments' effort to fight ransomware and other types of cybercrime isn't working, according to the Almanack. "To properly fight back, policymakers need to unleash the full potential of programs like the FBIs Confidential Human Source (CHS) program, so we can leverage skilled white hat hackers as force multipliers to woefully outnumbered government authorities," it reads.

Down with despots

The third theme, "down with despots," didn't come together until the end of the Almanack-writing process, as Braun saw examples of civil society methods to protect data, communications, and culture against censorship, surveilliance, and other kinds of oppression.

This included hacker LambdaCalculus's off-grid mesh network, PirateBox, along with Jason Vogt and Josh Reiter's proposal of setting up mesh networks in Taiwan to help civilians fight a future Chinese invasion.

Another talk by Saving Ukrainian Cultural Heritage Online (SUCHO) co-founder Quinn Dombrowski detailed his group's effort to save Ukrainian cultural websites – libraries, archives, museums, and community organizations – before Russia’s invasion. It ultimately helped preserve more than 1,500 websites.

"This is all about preserving freedom and democracy from authoritarians that are oppressing the vulnerable populations around the world, whether they be Ukrainians, potentially the Taiwanes,e Uyghurs, or migrants for that matter," Braun said.

To combat authoritarianism, the Almanack proposes building a Digital Arsenal of Democracy, comprised of technologies like mesh networks, digital archives, PirateBox, and DNA data storage to help oppressed communities to preserve their history and culture. Communication capabilities are also on the to-do list for the Arsenal’s creators.

This aligns with last year's DEF CON theme – access everywhere – and, as Moses writes in an epilogue to the Almanack, will carry over to this summer's focus on agency: "The ability of a citizen to have agency over their identity, data, and persona."

As Braun explains, "It needs to be a concerted effort by the human rights community and the hacker community to sit down and look at what technologies are out there today that support the preservation of human rights around the world, figuring out what we don't have, and then building those missing pieces," he said.

Braun is confident that DEF CON hackers will rise to the challenge.

"There's a certain thing in the hacker mindset that makes them a hacker: this commitment to freedom, transparency, science, very much Ben Franklin-esque," he said. "When there's threats to that, they get super riled up. I feel like we're going to see a lot more research in this space because of what's happening around the world, including here at home." ®