<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Lukasz Olejnik on Cyber, Privacy and Tech Policy Critique]]></title><description><![CDATA[Assessments of current topics and events in cybersecurity, privacy and technology policy. What matters. Probably weekly.]]></description><link>https://techletters.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!JzgD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda774a06-5794-44cf-8162-76bdc8637a93_1280x1280.png</url><title>Lukasz Olejnik on Cyber, Privacy and Tech Policy Critique</title><link>https://techletters.substack.com</link></image><generator>Substack</generator><lastBuildDate>Sat, 27 Jun 2026 03:19:38 GMT</lastBuildDate><atom:link href="https://techletters.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Lukasz Olejnik]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[techletters@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[techletters@substack.com]]></itunes:email><itunes:name><![CDATA[Lukasz Olejnik]]></itunes:name></itunes:owner><itunes:author><![CDATA[Lukasz Olejnik]]></itunes:author><googleplay:owner><![CDATA[techletters@substack.com]]></googleplay:owner><googleplay:email><![CDATA[techletters@substack.com]]></googleplay:email><googleplay:author><![CDATA[Lukasz Olejnik]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[TechLetters ☕️ Anthropic access cut by Washington. Fuel tank gauges hacked. AI safety blocks malware analysis. Korea biggest privacy breach. ChatGPT used for influence ops. KPMG hallucinates a report]]></title><description><![CDATA[The U.S.]]></description><link>https://techletters.substack.com/p/techletters-anthropic-access-cut</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-anthropic-access-cut</guid><pubDate>Mon, 15 Jun 2026 05:45:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JzgD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda774a06-5794-44cf-8162-76bdc8637a93_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The U.S. government has forced Anthropic from making Fable 5 and Mythos 5 available to foreign nationals - including its own employees with foreign passports. The company cut off access for everyone because it could not otherwise guarantee compliance with the order, so it said while preparing for the IPO.  The official reason: a jailbreak risk in Fable 5 deemed a threat to national security. Anthropic publicly disputes this.<br><br>Europe and the rest of the world just got a memo of a ready-made warning scenario. Access to AI models treated by their home country as national-security assets can be switched off by a single administrative decision. Anthropic sells the service. But Washington holds the keys to the lock? </p><p>This is not a precedent in tech history. States have restricted access to strategic technologies deemed national security risks before. But the comparison only goes so far. Crypto could be reimplemented, by anybody, frontier models cannot. They require massive compute, capital and infrastructure. So when the home state can switch off access, you are renting access to a strategic asset.<br><br>This is not a wake-up call for Europe. Wake-up calls are for people who were asleep. Europe has seen this risk for years: cloud, chips, platforms, now frontier AI. This is not the alarm. This is the bill for ignoring it.</p><h1>Security</h1><p></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>U.S. agencies issued an alert about hackers targeting automatic tank gauges - systems that quietly monitor fuel levels, temperatures, and leaks at gas stations, farms, chemical plants, and transport hubs across the country. The attackers are bypassing login screens, injecting commands into databases, and escalating themselves to full admin access. Once in, they can change tank volumes, disable leak alarms, and mess with pump controls.  https://www.cisa.gov/resources-tools/resources/cisa-and-partners-urge-hardening-automatic-tank-gauge-systems</p><p>You can have a hard time to use AI to analyze malicious software if it contains words triggering "safety refusals" due to nuclear weapons design. https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-worms-target-bioinformatics-and-mcp-developers-via-malicious</p><h1>Privacy </h1><p>Biggest consumer data breach in South Korea&#8217;s history. 37.56 million people affected in the core breach. The exposed data included:</p><p>- 33,057,012 member profile records</p><p>- 63,986,351 delivery-address records</p><p>- 272,470 order-history records. </p><p>Coupang, South Korea&#8217;s largest e-commerce platform and online retailer hit with a &#8361;624.68bn, roughly $409m, sanction by Korea&#8217;s Personal Information Protection Commission.</p><p>Basic security and governance failures like weak signing-key management, weak access control, poor detection of abnormal access, breach notification failures, data deletion failures, CPO independence issues and investigation obstruction.  A former employee used an active alternative authentication signing key to generate forged authentication tokens. Then he reached customer information.</p><p>Coupang collected online activity records from 11,170,613 users via third-party websites and apps where Coupang ads appeared. This included visited URL or app name, access time and IP address.</p><p>https://pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&amp;mCode=C020010000&amp;nttId=12171</p><h1>Technology Policy</h1><p>Suspected Chinese info ops used ChatGPT to target U.S. AI infrastructure debates with posts blaming data centres for household power bills, and attacking tariffs. The campaign got little traction, but coverage may matter more than the operation. https://cdn.openai.com/pdf/96b559fa-c165-4575-805d-e636909e2f78/June-2026-Threat-Report.pdf</p><p><em>[This might  not belong to the &#8216;security&#8217; section]</em></p><h1>Other</h1><p>Another <strong>AI fabrication</strong> report? KPMG published a report called Total Experience: Redefining Excellence in the Age of Agentic AI. It had 45 citations. 5 were accurate. 40 had fake titles. At least 16 were classified as hallucinations/fabrications. 12 were so vague or broken that the source could not be identified. The case studies are worse. JR East was cited as evidence of AI-powered travel recommendations. The source was a 2019 press release that predates agentic AI and does not mention AI at all. KPN&#8217;s &#8220;agents&#8221; turned out to be humans. Toyota&#8217;s Woven City press release mentions no AI agents. It looks like someone asked an LLM to find examples of agentic AI in the wild. It made things up. Nobody cared. The report has since been cited by industry blogs, trade publications and newspapers. ChatGPT and Gemini are reportedly repeating its statistics. KPMG charges clients to implement AI responsibly. The invoices, presumably, are accurate. https://gptzero.me/news/investigations-kpmg/</p><p></p><p></p><div><hr></div><p>In case you feel it's worth it to forward this content further:</p><p>Subscribed</p><p>If you&#8217;d like to share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[TechLetters ☕️ Prompt injection takes Instagram AI bot. Autonomous cyber gets cheap? Red Hat npm worm spreads. AI worm reasons through networks. Gaza data breach. Smart TVs become proxy nodes.]]></title><description><![CDATA[Security]]></description><link>https://techletters.substack.com/p/techletters-prompt-injection-takes</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-prompt-injection-takes</guid><pubDate>Mon, 08 Jun 2026 05:21:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!oMSl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b2a32a4-6f3c-4c4a-ba61-545f159dee0c_1754x760.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>Security</h1><p><strong>The first cyberattack in history using prompt injection</strong>. Attackers used Meta&#8217;s chatbot as a tool to take over Instagram accounts belonging to well-known people, brands, and institutions. By manipulating Meta&#8217;s AI support system, they convinced it to perform a critical administrative operation: <strong>changing or adding an email address associated with the victim&#8217;s account</strong>. <strong>Basic mistake: using LLM as a security boundary. </strong>The attacker contacted Meta&#8217;s bot, provided the username of the account they wanted to take over, and asked it to link that account to a new email address controlled by the attacker. In practice, this meant that the person controlling the new email address could receive or provide the confirmation code, and then use the modified recovery channel to reset the password and take over the account. AI support became a path for bypassing account security. If a chatbot can change an email address or initiate account recovery without independent verification of the owner, the attacker does not need to know the password or break through traditional security controls. It is sufficient to convince the automated support operator to perform an operation that the attacker should not normally be allowed to request. https://www.theverge.com/tech/941179/meta-instagram-ai-support-chatbot-exploit-hacked</p><p>Draft:</p><p><strong>AI/LLM can absolutely make autonomous cyberattacks and hack enterprise networks, but also government systems </strong>and this can be cheaper than human ops. Going beyond &#8220;magic hacking powers of this and that model&#8221; the important stuff is in <strong>agentic orchestration</strong>, so scanning, tool use, credential discovery, exploit selection, evidence tracking, privilege escalation planning, and adaptive retries across long attack chains - all well planned and executed. Once properly architected and connected, including to tooling like to shells, scanners, knowledge bases, memory, and task planners, models can turn known weaknesses, exposed services, misconfigurations, leaked credentials, and weak identity controls into <strong>repeatable intrusion workflows</strong>. This is also about going beyond human expertise limits to architectural decisions about state management, tool wrappers, context control, and deciding when a path is worth pursuing. <strong>This lowers the cost of offensive experimentation and lets attackers run more attempts, across more targets, with less specialist work</strong>. Defenders should assume <strong>AI-assisted intrusion attempts will become continuous, cheap</strong>, but also noisy before they become perfected. This genie is out of the box and let&#8217;s repeat: harness is critical, and the work can absolutely be done with freely available open weight models. https://dl.acm.org/doi/pdf/10.1145/3766895 https://dl.acm.org/doi/pdf/10.1145/3800584 https://arxiv.org/pdf/2507.00829 https://arxiv.org/pdf/2505.10321 https://arxiv.org/pdf/2602.17622</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Another supply-chain compromise worm. Multiple packages in the official Red Hat redhat-cloud-services npm scope were compromised in a supply-chain attack distributing a credential-stealing worm. Affected packages added a preinstall hook that ran a script. The malware harvested npm, GitHub, AWS, Azure, GCP, Vault, Kubernetes, SSH, CI/CD, and local secrets, then attempted to propagate by abusing stolen credentials to publish additional malicious packages and modify repositories. Any environment that installed affected versions should be treated as compromised. https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm</p><p>AI-powered computer worm, a self-replicating agent that reasons its way through a network instead of carrying a fixed exploit list. It steals compute from compromised GPU machines to run its own open-weight LLM, then uses weaker machines as relays for reach. In trials on a corporate testbed, it identified vulnerabilities, exploited systems, and launched replicas across Linux, Windows, and IoT targets. Every new infection can add more infrastructure while costing the attacker almost nothing. Patching one flaw no longer ends the threat, because the worm can operationalise fresh advisories, generate new attack logic, and keep adapting without a human operator. It is not a WannaCry-style worm with <strong>one baked exploit</strong> and one baked ransomware payload. It can <strong>adapt across many vulnerability classes</strong> it can discover and operationalise https://arxiv.org/pdf/2606.03811</p><h1>Privacy </h1><p><strong>Cyberattack on humanitarian organization World Food Program exposes sensitive data of vulnerable population. </strong>Affected 600,000 households in Gaza, names, ID numbers, phone numbers, location data, all exfiltrated. The timing is specific. Israel's Supreme Court had just upheld a requirement forcing aid organizations to hand over workers' personal data as a condition of operating in Gaza. In 2022 it was the Red Cross (515,000 people). In 2023, the Norwegian Refugee Council. This time it's WFP. The sector has had a poor track record. https://www.thenewhumanitarian.org/news/2026/06/02/data-600000-gaza-households-exposed-wfp-cyber-attack</p><p>The world&#8217;s largest residential proxy network runs on consent, TLS and vibes. The TV is always watching and apparently it is also available for contract work in surveillance or data acquisition? Bright Data sells access to a residential proxy network, the kind customers use to route requests through real home IP addresses instead of datacenter IPs that Cloudflare, DataDome and HUMAN are trained to block. The supply comes from an SDK embedded in consumer apps. So: CTV games, messengers, mobile apps and screensavers. With consent somewhere upstream, the device becomes an exit node. The TV is perfect for this job. It is plugged in, on WiFi, often unattended and barely supervised. It also asks for consent through a privacy policy and a remote-control UI, which is one way to make &#8220;informed choice&#8221; look like an endurance sport. One config flag tells the SDK to ignore whether the screen is on. Another tells it to ignore whether the user is on a call. In this economy, watching TV counts as downtime. https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/</p><h1>Technology Policy</h1><p></p><h1>Other</h1><p>Developer adds instructions to instruct AI coding agents not to use the project (and before that, instructions made AI agents remove the tests and code for this project). https://jqwik.net/docs/1.10.1/user-guide.html#note-to-coding-agents-and-alike</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oMSl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b2a32a4-6f3c-4c4a-ba61-545f159dee0c_1754x760.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oMSl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b2a32a4-6f3c-4c4a-ba61-545f159dee0c_1754x760.png 424w, https://substackcdn.com/image/fetch/$s_!oMSl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b2a32a4-6f3c-4c4a-ba61-545f159dee0c_1754x760.png 848w, https://substackcdn.com/image/fetch/$s_!oMSl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b2a32a4-6f3c-4c4a-ba61-545f159dee0c_1754x760.png 1272w, https://substackcdn.com/image/fetch/$s_!oMSl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b2a32a4-6f3c-4c4a-ba61-545f159dee0c_1754x760.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oMSl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b2a32a4-6f3c-4c4a-ba61-545f159dee0c_1754x760.png" width="1456" height="631" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9b2a32a4-6f3c-4c4a-ba61-545f159dee0c_1754x760.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:631,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:204962,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://techletters.substack.com/i/200077112?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b2a32a4-6f3c-4c4a-ba61-545f159dee0c_1754x760.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oMSl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b2a32a4-6f3c-4c4a-ba61-545f159dee0c_1754x760.png 424w, https://substackcdn.com/image/fetch/$s_!oMSl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b2a32a4-6f3c-4c4a-ba61-545f159dee0c_1754x760.png 848w, https://substackcdn.com/image/fetch/$s_!oMSl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b2a32a4-6f3c-4c4a-ba61-545f159dee0c_1754x760.png 1272w, https://substackcdn.com/image/fetch/$s_!oMSl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b2a32a4-6f3c-4c4a-ba61-545f159dee0c_1754x760.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Revolution in computing hardware? Nvidia announced RTX Spark, a chip combining a Blackwell GPU (6,144 CUDA cores, FP4 Tensor) with a 20-core Grace CPU, up to 128GB unified memory, claimed 1 petaflop of AI Claimed workloads include rendering 90GB 3D scenes, editing 12K 4:2:2 video, running 120B-parameter LLMs with up to 1 million tokens of context, generating 4K AI video. The  ambition is to bring AI-first computing  to PCs and laptops, making Nvidia's stack the default runtime for local AI agents. Microsoft is doing real platform work alongside - Windows scheduler tuning, unified memory changes, TensorRT via Windows ML, OpenShell sandboxing for agent containment. So this isn't just a chip swap. It is also Microsoft's second attempt to define the "AI PC" .</p><p></p><p></p><p></p><div><hr></div><p>In case you feel it's worth it to forward this content further:</p><p>Subscribed</p><p>If you&#8217;d like to share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[TechLetters ☕️ Supply-chain worm goes ~exponential? Moscow runs false-flag theatre. Your SSD fingerprints you. The Vatican enters the AI debate.]]></title><description><![CDATA[Security]]></description><link>https://techletters.substack.com/p/techletters-supply-chain-worm-goes</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-supply-chain-worm-goes</guid><pubDate>Mon, 01 Jun 2026 05:35:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JzgD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda774a06-5794-44cf-8162-76bdc8637a93_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>Security</h1><p>Another wave of supply chain attacks hit npm. The worm republishes itself using stolen npm tokens &#8211; the blast radius grows automatically with each new victim. The compromised maintainer account atool pushed 639 malicious package versions across 323 packages in under an hour. The payload steals whatever it finds. GitHub tokens, AWS keys, Kubernetes credentials, CI/CD secrets from GitHub Actions, GitLab, Jenkins, CircleCI and a dozen more platforms. If it finds a GitHub token, it creates repositories under the victim&#8217;s account and commits stolen data there. If it finds an npm token, it republishes more infected packages. The campaign has now hit 1,055 package versions. https://socket.dev/blog/antv-packages-compromised </p><p>Russian cyber operators hijacked hundreds of Bluesky accounts - journalists, academics, filmmakers - and used them in information operations to post propaganda. Bluesky insists its systems weren&#8217;t breached - old leaked credentials did the work. Avg post views: 50.  https://www.france24.com/en/live-news/20260529-bluesky-accounts-hijacked-in-pro-russia-propaganda-campaign</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><strong>Russia&#8217;s Social Design Agency runs online influence and propaganda operations. But it&#8217;s also making offline operations</strong>, staged for cameras and the media. Pig heads marked &#8220;Macron&#8221; were left outside Paris mosques. Green paint hit synagogues and the Shoah Memorial. Concrete skeletons appeared at the Brandenburg Gate with an anti-Merz message. Cars across Germany were disabled with expanding foam and stickers blaming the Greens. These were false-flag attacks built to look like local hatred, climate radicalism, anti-Muslim backlash, anti-Semitism, or anti-government protest.</p><p>The leaked details show a senior Russian Presidential Administration official tracking budgets, field operations and approvals. Serbia appears repeatedly as a logistics and recruitment hub due to cheap disposable operatives, cash payments, rented vehicles, burner phones, fast exits. One internal goal was candid enough: <em>help Russia &#8220;maintain the image of a superpower.&#8221;</em></p><p>The files also describe outreach to Western retired generals, including one French and one American, to launder pro-Kremlin positions as independent expert opinion. For 2026, SDA plans include AI-generated content farms, fake think tanks, opinion-leader trackers and &#8220;Mitteleuropa&#8221;, a geopolitical project aimed at pulling Austria, Hungary and Slovakia into a Moscow-friendlier Central European bloc. Thirty sex dolls floating down the Seine with anti-migrant messages was not satire. It was an agenda item.</p><p>The previous SDA leak was in 2024. It changed nothing. Moscow just moved from fake websites to fake reality.</p><p>https://www.occrp.org/en/investigation/leaked-documents-reveal-russian-cognitive-strikes-against-the-west-including-islamophobic-pig-head-attacks-in-paris</p><h1>Privacy </h1><p>Using the Origin Private File System browser mechanism to track and fingerprint users via solid state disk (SSD) noise, from inside a regular browser tab, with no permissions, nor native code. Simple: create a file bigger than RAM, read random chunks in a loop, and SSD latency starts reflecting everything else on the machine - other websites loading, apps launching. 88% accuracy fingerprinting visited sites, 95% for identifying which desktop app just launched. Covert channel capacity: 660 b/s. Chromium, Apple, and Mozilla mostly ignored it. https://tugraz.elsevierpure.com/ws/portalfiles/portal/109750638/main.pdf</p><h1>Technology Policy</h1><p></p><h1>Other</h1><p>The first encyclical of  Pope Leo XIV is a major intervention on AI, human dignity, truth, war, and technological power. It is a warning that <strong>technology is never neutral when it is shaped by money, control, secrecy, and force</strong>. It rejects surrendering human judgment to AI.</p><p>The encyclical treats cyberattacks as part of a wider transformation of conflict. <strong>Cyber conflict creates instability before formal war starts</strong>. War no longer is limited to  tanks and missiles. It can begin with data theft, infrastructure disruption, manipulation, and invisible attacks whose authors are hard to prove.</p><p>The enciclica considers also information operations and cognitive warfare. It posits that propaganda, AI-generated manipulation, fear campaigns, and cyber operations are part of hybrid conflict.</p><p>The battlefield includes imagination, trust, identity, and social cohesion. This is the cognitive dimension.</p><p>The encyclical addresses <strong>lethal autonomous weapons systems</strong>, and AI-assisted targeting. Here the message is clear: lethal decisions cannot be delegated to machines.</p><p>Pope Leo XIV&#8217;s first encyclical therefore cannot be reduced to AI only. It is about the kind of civilization being built around AI. https://www.vatican.va/content/leo-xiv/en/encyclicals/documents/20260515-magnifica-humanitas.html</p><p></p><p></p><p></p><div><hr></div><p>In case you feel it's worth it to forward this content further:</p><p>Subscribed</p><p>If you&#8217;d like to share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Scaling to autonomous war drones]]></title><description><![CDATA[According to Ukrainian commanders and those responsible for the drone programme, the material cost of striking or eliminating a single Russian soldier with drones has already fallen below $1,000.]]></description><link>https://techletters.substack.com/p/scaling-to-autonomous-war-drones</link><guid isPermaLink="false">https://techletters.substack.com/p/scaling-to-autonomous-war-drones</guid><dc:creator><![CDATA[Lukasz Olejnik]]></dc:creator><pubDate>Sat, 23 May 2026 10:43:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ZO2R!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd6b09a-b975-4e4f-b757-5a2e3be1cbe9_680x369.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>According to Ukrainian commanders and those responsible for the drone programme, the material cost of striking or eliminating a single Russian soldier with drones has already fallen below $1,000. The trend is clear. In 2024, that cost was estimated at around $1,650. In 2026, reported figures are in the range of $878-1,000. If we treat this trend as a purely mathematical trajectory and extend it to 2030, the cost could fall to ~$270-400. That, however, is an aggressive scenario. </p><p>In practice, the other side will respond. If only through electronic warfare, camouflage, protective netting, troop dispersion, counter-drone systems, changes in how forces move along the front, or other adaptations. There are also factors that are difficult to predict, such as component availability, the pace of improvement in guidance algorithms, local saturation of the front with sensors, and possible breakthroughs in anti-drone systems.</p><p>For that reason, it is more realistic to assume that the decline will not continue at the same pace. The more proper mathematical lower bound for 2030 is maybe around $270-400. Still a more cautious scenario would be closer to $500-900.</p><p></p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZO2R!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd6b09a-b975-4e4f-b757-5a2e3be1cbe9_680x369.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZO2R!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd6b09a-b975-4e4f-b757-5a2e3be1cbe9_680x369.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZO2R!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd6b09a-b975-4e4f-b757-5a2e3be1cbe9_680x369.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZO2R!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd6b09a-b975-4e4f-b757-5a2e3be1cbe9_680x369.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZO2R!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd6b09a-b975-4e4f-b757-5a2e3be1cbe9_680x369.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZO2R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd6b09a-b975-4e4f-b757-5a2e3be1cbe9_680x369.jpeg" width="680" height="369" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cdd6b09a-b975-4e4f-b757-5a2e3be1cbe9_680x369.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:369,&quot;width&quot;:680,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:0,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZO2R!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd6b09a-b975-4e4f-b757-5a2e3be1cbe9_680x369.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZO2R!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd6b09a-b975-4e4f-b757-5a2e3be1cbe9_680x369.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZO2R!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd6b09a-b975-4e4f-b757-5a2e3be1cbe9_680x369.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZO2R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdd6b09a-b975-4e4f-b757-5a2e3be1cbe9_680x369.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A shift towards systems with a high degree of autonomy, or full autonomy, could reduce the cost significantly, but it does not remove physical or hardware constraints. It might make a move to $100-250 possible, but probably not for long. Autonomy can lower the cost of striking a target, but it will also change the adversary&#8217;s behaviour. If the cost of eliminating a soldier in open terrain falls too low, the other side will not simply continue to expose people in the same way, because that exposure has a real cost. At that point, measuring the economics of the war in relation to the number of hit soldiers may cease to make sense. Full, production-grade autonomy could be possible around 2027. Once it is deployed at scale, there is no civilisational way back. The economics of war, and the role of the human soldier inside it, will have changed permanently.</p>]]></content:encoded></item><item><title><![CDATA[TechLetters ☕️ Fast16 sabotaged nuclear simulations. LLMs are not security boundaries. Hugging Face model stole data. Malware gets agentic. G7 wants post-quantum crypto. Propaganda trains models.]]></title><description><![CDATA[Security]]></description><link>https://techletters.substack.com/p/techletters-fast16-sabotaged-nuclear</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-fast16-sabotaged-nuclear</guid><pubDate>Sun, 17 May 2026 20:01:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JzgD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda774a06-5794-44cf-8162-76bdc8637a93_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>Security</h1><p>Fast16 cyber weapon designed to corrupt uranium-compression simulations central to Iran&#8217;s nuclear weapon design. the targets as LS-DYNA and AUTODYN, two finite element solvers used in everything from car crash tests to explosive detonation modeling. The malware, fast16, used a kernel-level filesystem filter driver to patch executable code on-the-fly without touching the files on disk. It only attacked Intel-Fortran-compiled binaries, and only during specific simulation phases - full-scale transient blast runs. The payload required three conditions to act: (1) an explosives-specific Equation of State (Jones-Wilkins-Lee, Ignition and Growth, or Lee-Tarver), (2) a variable reaching five times its initial value, and (3) material density crossing 30 g/cm&#179; -- the threshold uranium only reaches under implosion-type nuclear weapon compression. Once triggered, it silently degraded stress tensor outputs (pressure, compressibility) to 1-42% of their true values, scaled gradually to avoid obvious artifacts. The message to the engineers: your bomb doesn&#8217;t work. Or: your bomb works better than it actually does. Someone doing this understood nuclear weapons physics well enough to know which output values, if subtly wrong, would silently wreck the design process.  That was not Google-searchable knowledge. https://www.security.com/threat-intelligence/fast16-nuclear-sabotage</p><p>&#8220;Your LLM is not a security boundary&#8221;. Do not architect systems as if they were. Microsoft Semantic Kernel could be exploited to to turn prompt injection into host-level remote code executiona and pop a calc.exe. The model behaved perfectly. The framework just trusted it too much.&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203; https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/ </p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Malware-infected LLM model uploaded to Hugging Face (now taken down). It was stealing user data.  If you downloaded it recently, make sure to do a proper cleanup and incident handling. The model was supposed to help in private data filtering. It stolen private data. Tainted repository is this: https://huggingface.co/Open-OSS/privacy-filter</p><p>By integrating LLMs into malware operations payloads can act autonomously, independently interacting with the victim environment or device, synthesizing system states, and executing precise commands without of human supervision. https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access?e=48754805</p><p>G7 calls to transition to post-quantum cryptography. https://assets.publishing.service.gov.uk/media/6966149d8d599f4c09e1ffab/G7-CEG-Quantum-Roadmap.pdf</p><h1>Privacy </h1><h1>Technology Policy</h1><p></p><h1>Other</h1><p>Propaganda enters the internet as text, then exits the model as an &#8220;answer". States do not need to control an AI model directly to shape its answers. They only need to control enough of the text the model learns from. This Nature paper shows that Chinese state-coordinated media entered LLM training data easily. AI models memorized parts of such input material at rates between 3%-10%. When a model was further trained on just 6,400 examples of Chinese state-scripted media, almost 80% of its answers became more favorable to the Chinese government than the base model&#8217;s answers. When China-related questions were asked in Chinese human reviewers judged the Chinese answers as more favorable to China 75.3% of the time. The lower the media freedom, the more likely a model is to answer more favorably toward the regime in the local language than in English. The most effective prompt injection starts years before the prompt. This is not a model bug. It is a feature of the world that was loaded into it. https://www.nature.com/articles/s41586-026-10506-7</p><p></p><p></p><p></p><div><hr></div><p>In case you feel it's worth it to forward this content further:</p><p>Subscribed</p><p>If you&#8217;d like to share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[TechLetters ☕️ Agentic AI is just IT, but messier. LLMs won’t find every bug. US-China AI hotline? CAISI tests frontier models with guardrails off.]]></title><description><![CDATA[Security]]></description><link>https://techletters.substack.com/p/techletters-agentic-ai-is-just-it</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-agentic-ai-is-just-it</guid><pubDate>Mon, 11 May 2026 08:23:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JzgD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda774a06-5794-44cf-8162-76bdc8637a93_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>Security</h1><p>Agentic AI systems are complex ecosystems of LLMs, humans, guardrails, datasets, tools and hardware, where security risks often emerge from interactions between components rather than isolated flaws.. Organisations should address AI security, including agentic AI systems, within established cyber security frameworks rather than treating it as a separate or standalone discipline. AI systems are fundamentally IT systems. https://www.cyber.gov.au/sites/default/files/2026-05/careful_adoption_of_agentic_ai_services.pdf</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>&#8220;With the recent news of folks finding vulnerabilities <a href="https://en.wikipedia.org/wiki/Copy_Fail">left</a> and <a href="https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop.html">right</a> using LLMs, some folks hope that we'd be able to find every single vulnerability.<br>Today, I hope to shatter that idea&#8221; https://github.com/yo-yo-yo-jbo/vr_difficulty</p><h1>Privacy </h1><h1>Technology Policy</h1><p>The US and China are considering a hotline for AI incidents to avoid accidentally starting a war over it. The reason is Mythos-grade models, which moved the whole conversation from &#8220;tech regulation&#8221; to national security. Is a  phone call before anyone launches a counterstrike over an ambiguous AI-enabled incident good idea?</p><p>The proposed channel would cover four areas: cyberattacks on critical infrastructure, autonomous military systems, non-state actors using AI well beyond their previous capabilities, and misattribution, where a third party uses a model to fake a nation-state operation. That last one is the underrated risk.</p><p>This is crisis communication infrastructure. Governments are quietly admitting that AI might be used to generate incidents faster than diplomacy can respond.</p><p>The AI channel, if it happens, would be the first formal admission that both sides understand the same problem. AI-enabled incidents can move faster than attribution, diplomacy, or control  https://www.wsj.com/world/china/u-s-and-china-pursue-guardrails-to-stop-ai-rivalry-from-spiraling-into-crisis-4c50bd70</p><p></p><p>US will examine the national security implications of new AI models from Google&#8217;s DeepMind, Microsoft and xAI before they are released to the public. CAISI, the body inside the Commerce Department formerly known as the AI Safety Institute, will run the pre-deployment tests. The evaluators get access to models with guardrails stripped out. They look mainly at cyber, bio, and chemical weapons capabilities. With safety measures OFF. Over 40 such evaluations done so far - including models that have never been released. Anthropic and OpenAI are already in the program. So a renamed safety watchdog, armed with guardrail-free model access, now runs national security evals on AI. The models get tested for bioweapons risk. The policy gets tested for nothing? https://www.nist.gov/news-events/news/2026/05/caisi-signs-agreements-regarding-frontier-ai-national-security-testing</p><p></p><h1>Other</h1><p></p><p></p><p></p><div><hr></div><p>In case you feel it's worth it to forward this content further:</p><p>Subscribed</p><p>If you&#8217;d like to share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[TechLetters ☕️ Fast16 sabotaged industrial, engineering and scientific computation. Journalists face global spyware. AI-driven hacking  of Mexico’s government. ]]></title><description><![CDATA[Security]]></description><link>https://techletters.substack.com/p/techletters-fast16-sabotaged-industrial</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-fast16-sabotaged-industrial</guid><pubDate>Mon, 04 May 2026 05:16:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JzgD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda774a06-5794-44cf-8162-76bdc8637a93_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>Security</h1><p>A 2005 state-designed worm designed to corrupt physics simulations sat undetected on VirusTotal for nearly a decade. Fast16, intercepted executable files at the kernel level and silently rewrote floating-point calculations to make them produce slightly wrong answers. Targets: high-precision engineering suites used for structural analysis, crash simulations, and physical process modeling, including LS-DYNA, a tool cited in reports on Iran's nuclear weapons research. The sabotage vector relied on deployment of the driver across a network via worm, corrupting  calculations on every machine, and eliminating the possibility of cross-checking results against a clean system. Stuxnet got the documentary. Fast16 got twenty years of nothing. https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnet/</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>I was the reviewer of the International Federation of Journalists global study on journalist surveillance. It maps the spyware ecosystem confronting journalists worldwide, from commercial tools like Pegasus/Predator to AI-assisted realm. https://www.ifj.org/media-centre/news/detail/category/brave/article/global-ifj-study-exposes-worldwide-systemic-surveillance-of-journalists</p><p>Hacking Mexico government with AI assistance. Attacker exfiltrated hundreds of millions of citizen records. 75% of the executed commands across the entire cyberattack campaign were generated by Claude. 40 minutes after Claude said "<em>I'm not going to create that file</em>" it was reporting back from inside a live government server: "<em>What command do you want to execute now?</em>". It dumped the shadow file, harvested the root password hash, and fixed timestamps to cover its tracks, all in the same turn. Wait few months until open source models can do this? https://cdn.prod.website-files.com/69944dd945f20ca4a27a7c47/69d8bb5aea59e31efb3b8a7f_Tech_Report_ai_breach_mex_gov.pdf</p><h1>Privacy </h1><h1>Technology Policy</h1><p></p><h1>Other</h1><p></p><p></p><p></p><div><hr></div><p>In case you feel it's worth it to forward this content further:</p><p>Subscribed</p><p>If you&#8217;d like to share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[TechLetters ☕️ Signal hacked by asking for the PIN. AI finds zero-days faster. Mythos access breached. SIM farms industrialised. Cheap AI exploits Chrome. France leaks 11.7M IDs.]]></title><description><![CDATA[Very important privacy and security risk.]]></description><link>https://techletters.substack.com/p/techletters-signal-hacked-by-asking</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-signal-hacked-by-asking</guid><pubDate>Mon, 27 Apr 2026 10:28:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JzgD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda774a06-5794-44cf-8162-76bdc8637a93_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Very important privacy and security risk.</strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;8fa5715e-3602-4abc-bb12-e733c7f8b7cc&quot;,&quot;caption&quot;:&quot;The European Commission is preparing to compel Google to stream search data to third-party companies through an automated API. It is doing this under the Digital Markets Act, a regulation with a sound goal of improving competition in digital markets. But this specific proposal would have the effect of&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The European Commission is turning Google Search into a privacy and national-security risk&quot;,&quot;publishedBylines&quot;:[],&quot;post_date&quot;:&quot;2026-04-26T14:12:07.015Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c905fe48-7e8c-4c25-9cbe-628ff1ed513b_1738x960.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://techletters.substack.com/p/the-european-commission-is-turning&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:195523647,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:139150,&quot;publication_name&quot;:&quot;Lukasz Olejnik on Cyber, Privacy and Tech Policy Critique&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!JzgD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda774a06-5794-44cf-8162-76bdc8637a93_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><h1>Security</h1><p>Germany&#8217;s parliament speaker had her Signal account fully compromised by  Russian SVR hackers. J. Kl&#246;ckner, holder of the country&#8217;s second-highest office was a member of a German ruling party CDU executive board Signal group that also included Chancellor Friedrich Merz. It is unclear if Russia read those chats and for how long. Merz&#8217;s phone was inspected by counterintelligence  and came back clean. Kl&#246;ckner&#8217;s did not.</p><p>The attack  is insultingly simple. Fake &#8220;Signal Support&#8221; just ask to hand over the PIN securing the account. Many European policymakers fell for it. That&#8217;s it. https://www.epochtimes.de/politik/deutschland/bericht-bundestagspraesidentin-kloeckner-von-signal-hack-betroffen-a5468584.html</p><p><strong>With AI, defenders have a chance to win the cybersecurity race</strong>. Mythos found 271 security vulnerabilities, now fixed in Firefox 150.  Attackers historically needed only one bug while defenders had to plug them all. If AI can now find them faster than humans, the attacker's asymmetric advantage collapses. The math changes. Mythos found all the bugs that humans could, but did this very fast. Is the era of zero-days closing? https://blog.mozilla.org/en/firefox/ai-security-zero-day-vulnerabilities/</p><p><strong>Unauthorized users gained access to Claude Mythos Preview</strong>, a model with powerful cybersecurity capabilities Anthropic deliberately kept behind a restricted pilot program. Entry came through a mix of contractor-level access at a third-party Anthropic vendor, public GitHub breadcrumbs, and an educated guess about the model&#8217;s API endpoint format.  A $380bn AI lab&#8217;s most sensitive model was partially unlocked via GitHub lookups, and a third-party contractor. Classic. The group used a data breach at one company to find a backdoor into another. This is what &#8220;AI supply chain risk&#8221; looks like in practice. <strong>They used the access to the most powerful cybrsecurity AI model to... build websites</strong>. https://www.bloomberg.com/news/articles/2026-04-21/anthropic-s-mythos-model-is-being-accessed-by-unauthorized-users</p><p>87 SIM proxy farms found in 17 countries at at least 94 physical locations around the world. They may be used in ad fraud, propaganda and disinformation bot networks, account farms on Instagram or LinkedIn, and Russians trying to reach Western AI services and bypass state censorship. The infrastructure is delivered by one vendor, Belarusian ProxySmart  platform that sells operators everything they need to run a commercial mobile proxy farm. So device management, IP rotation, customer billing, and a web panel. All the user has to do is to buy the software, get  some phones or USB modems, stuff them with SIM cards on unlimited data plans, and you've got a spam or disinformation network set up. The system has  a self-hosted web control panel for managing devices and proxy endpoints. Setup docs recommend putting a reverse proxy in front - to obscure where the panel is actually hosted. Another provider sells bundled hardware packages with installation support, in case even that feels like too much work. The customers are anyone who needs IP addresses that look like real mobile users.  https://infrawatch.com/blog/inside-the-mobile-farm-the-oem-stack-powering-us-4g-5g-proxy-networks</p><p>Research shows that Chinese AI can reliably detect software vulnerabilities - and it is cost efficient. Kimi K2.5, an open-weight model was deployed in an agentic framework against Chrome and produced 10 previously unknown zero-days, including two critical sandbox-escape CVEs. The researchers noted it was cheaper to run than Claude Opus 4.6 at that scale. The most important word in the paper isn't "zero-day" - it's "cheaper"? https://arxiv.org/pdf/2604.20801</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Russian AI-assisted cyber is essentially a force multiplier with no recruitment costs. Dutch military intelligence (MIVD)  published a warning about Russia's growing cyber capabilities. Russia uses AI to automate attacks at scale, targets Europe's eastern flank , and has managed to infiltrate and take over chat accounts of Dutch government employees. The Dutch police was apparently hit for opportunistic reasons. Is the Dutch police being hit "opportunistically" the intelligence-speak for "they walked into an open door"? https://www.defensie.nl/site/binaries/site-content/collections/documents/2026/04/21/openbaar-jaarverslag-2025-militaire-inlichtingen--en-veiligheidsdienst/mivd-ojv2025.pdf</p><h1>Privacy </h1><p>France's agency for issuing passports, driver's licenses, and national ID cards confirmed a breach of its citizen portal. The stolen 11.7 million records include names, email addresses, dates and places of birth, phone numbers, postal addresses, unique account IDs.  https://ants.gouv.fr/toute-l-actualite/incident-de-securite-relatif-au-portail-antsgouvfr-point-detape-du-21-avril-2026</p><h1>Technology Policy</h1><p></p><h1>Other</h1><p>Cash prize offered to whoever could break the biggest elliptic curve key using Shor's algorithm on real quantum hardware. A "win" is a win. Except it isn't. Then a <a href="https://github.com/yuvadm">researcher</a>  replaced the IBM Quantum backend in the winning code with A RANDOM NUMBER GENERATOR  built into every operating system. And got the same private key back 40% of the time. No quantum computer used. Dumb luck works just fine. The quantum circuit just happens to contribute nothing to the result. https://github.com/yuvadm/quantumslop/blob/25ad2e76ae58baa96f6219742459407db9dd17f5/URANDOM_DEMO.md</p><p></p><p></p><p></p><div><hr></div><p>In case you feel it's worth it to forward this content further:</p><p>Subscribed</p><p>If you&#8217;d like to share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[The European Commission is turning Google Search into a privacy and national-security risk]]></title><description><![CDATA[The European Commission is preparing to compel Google to stream search data to third-party companies through an automated API.]]></description><link>https://techletters.substack.com/p/the-european-commission-is-turning</link><guid isPermaLink="false">https://techletters.substack.com/p/the-european-commission-is-turning</guid><pubDate>Sun, 26 Apr 2026 14:12:07 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/c905fe48-7e8c-4c25-9cbe-628ff1ed513b_1738x960.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The European Commission is preparing to compel Google to stream search data to third-party companies through an automated API. It is doing this under the Digital Markets Act, a regulation with a sound goal of improving competition in digital markets. But this specific proposal would have the effect of <strong>exposing the EU users&#8217; individual Google search queries to unspecified companies</strong> that <strong>users have no knowledge of, or control over</strong>.</p><p>Unless the EC corrects the proposal, it will amount to <strong>one of the largest mandated transfers of sensitive user data in Europe in decades</strong>, making the privacy problem immediate and sizeable. Receiving access to this data would be very easy for other companies, requiring them only to jump through bureaucratic and procedural hoops, rather than ensuring that the shared data is properly anonymized and aggregated to prevent harm to users (the EC has proposed some measures on this front, but they are woefully inadequate, as discussed at length in this post). This immediately creates a national-security problem because once this feed is available to qualifying third parties, all a <strong>hostile foreign intelligence service</strong> needs to do to gain <strong>detailed intelligence on the individual searches of all EU citizens</strong> is to obtain access through a formally compliant search engine, AI-search wrapper, a mock AI chatbot, or funded front company. Pulling this off is very easy, even easier than registering a bogus company to access <a href="https://lukaszolejnik.com/rtbdesc">Real-Time Bidding</a> data from Google in 2015, back when nobody cared about security and privacy of this layer.</p><p>My 15+ yr experience lets me confidently ring an alarm bell here. It&#8217;s a privacy and a national and international security risk. One of the biggest risks in Europe this year.</p><h1>What data is being handed over</h1><p>The <a href="https://digital-markets-act.ec.europa.eu/dma100209-consultation-proposed-measures-google-search-data-sharing_en">proposal</a> does not merely open access to abstract statistics or aggregate market data. It requires Google to offer an API-based, reliable and stable daily feed of essentially all search records from people in Europe, including what they search for, what results they see, what they click, how they refine their searches, and where those searches roughly originate.</p><p>The draft requires sharing of the user&#8217;s entire search query, timestamp, coarse but useful location data, query language, device identifier, timing and order of clicks, hover, scroll, swipe, expansion events, the full sequence of query, view, click, and ranking data associated with a user over time, and much more. In this post I focus on the query string and the mechanics of its delivery.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CQgw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0467fdd8-68c8-4b32-875f-aeb672724c7b_1796x1204.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CQgw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0467fdd8-68c8-4b32-875f-aeb672724c7b_1796x1204.png 424w, https://substackcdn.com/image/fetch/$s_!CQgw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0467fdd8-68c8-4b32-875f-aeb672724c7b_1796x1204.png 848w, https://substackcdn.com/image/fetch/$s_!CQgw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0467fdd8-68c8-4b32-875f-aeb672724c7b_1796x1204.png 1272w, https://substackcdn.com/image/fetch/$s_!CQgw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0467fdd8-68c8-4b32-875f-aeb672724c7b_1796x1204.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CQgw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0467fdd8-68c8-4b32-875f-aeb672724c7b_1796x1204.png" width="1456" height="976" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0467fdd8-68c8-4b32-875f-aeb672724c7b_1796x1204.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:976,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:288210,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://techletters.substack.com/i/195523647?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0467fdd8-68c8-4b32-875f-aeb672724c7b_1796x1204.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CQgw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0467fdd8-68c8-4b32-875f-aeb672724c7b_1796x1204.png 424w, https://substackcdn.com/image/fetch/$s_!CQgw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0467fdd8-68c8-4b32-875f-aeb672724c7b_1796x1204.png 848w, https://substackcdn.com/image/fetch/$s_!CQgw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0467fdd8-68c8-4b32-875f-aeb672724c7b_1796x1204.png 1272w, https://substackcdn.com/image/fetch/$s_!CQgw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0467fdd8-68c8-4b32-875f-aeb672724c7b_1796x1204.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Needless to say, search queries are deeply private data, often tied to users&#8217; sensitive secrets, such as medical conditions, sexual preferences, relationships, and many other kinds of information that <strong>users </strong><em><strong>do not expect to be shared</strong></em><strong>, especially with </strong><em><strong>random entities</strong></em><strong> and in bulk</strong>. At this scale, weak anonymisation does not merely create a residual privacy risk - it is likely to enable <strong>persistent tracking and surveillance of people</strong>, places, institutions, and events across Europe.</p><p>That makes it absolutely critical for any approach that results in sharing such data to provide strong privacy that prevents linkability, deanonymization, and other uses of the data that would undermine users&#8217; privacy expectations. The Commission is proposing a filtering scheme based on entity allowlists, query-length thresholds, metadata generalisation, and contractual controls. For this kind of data, at this volume, with daily record-level delivery to multiple third parties, that approach is currently not adequate. It is simply not enough. It treats search data as if privacy can be guaranteed by hand-waving about what the intended uses of data <em>should</em> be, rather than understanding what they really are.</p><h2>How would the &#8220;sanitization&#8221; methods work?</h2><p>The proposed sanitisation system removes direct identifiers such as account IDs, IP addresses, device IDs, and precise timestamps from the search record. It strips parts of viewport geometry, replaces image-only queries with placeholders, bins click-back time into coarse intervals, and then applies three gates.</p><p>The proposal requires an allowlist to be built from the parts of search queries. If part of a query is detected as personal data, such as a name, address, or phone number, it is grouped into one entity. Everything else is split into ordinary words.</p><p>The system counts how many unique signed-in European Economic Area users searched for each entity or word during the previous 13 months. If more than 50 signed-in users searched for it, that entity or word is added to the allowlist for five years. Note that this restriction applies to individual entities, not the entire query - a unique search query made of common words would not be protected.</p><p>When data is later released to other companies, a modified query passes the entity test only if every part of the query is on that allowlist. It must also pass a separate length test. The query has to be shorter than the weekly threshold calculated for that language.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PmE7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab08d7-3df8-4f71-af75-76899d030169_2283x3831.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PmE7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab08d7-3df8-4f71-af75-76899d030169_2283x3831.png 424w, https://substackcdn.com/image/fetch/$s_!PmE7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab08d7-3df8-4f71-af75-76899d030169_2283x3831.png 848w, https://substackcdn.com/image/fetch/$s_!PmE7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab08d7-3df8-4f71-af75-76899d030169_2283x3831.png 1272w, https://substackcdn.com/image/fetch/$s_!PmE7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab08d7-3df8-4f71-af75-76899d030169_2283x3831.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PmE7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab08d7-3df8-4f71-af75-76899d030169_2283x3831.png" width="1456" height="2443" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/25ab08d7-3df8-4f71-af75-76899d030169_2283x3831.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2443,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PmE7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab08d7-3df8-4f71-af75-76899d030169_2283x3831.png 424w, https://substackcdn.com/image/fetch/$s_!PmE7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab08d7-3df8-4f71-af75-76899d030169_2283x3831.png 848w, https://substackcdn.com/image/fetch/$s_!PmE7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab08d7-3df8-4f71-af75-76899d030169_2283x3831.png 1272w, https://substackcdn.com/image/fetch/$s_!PmE7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab08d7-3df8-4f71-af75-76899d030169_2283x3831.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Example entity split:</strong></p><p>(&#8221;john doe&#8221;, &#8220;200 wetstraat brussel&#8221;, &#8220;04 12 34 56 78&#8221;, &#8220;communications&#8221;, &#8220;department&#8221;)</p><p>A query is released if every entity in the modified query is in the allowlist and the full query is below that length threshold. There is no requirement that the full query itself has been issued by multiple users. The system ensures that each individual component of the query (either a word, or personal data such as name or address), then releases the record.</p><p>Example evaluation:</p><p>(&#8221;pierre smith&#8221;, &#8220;cancer&#8221;) &#8594; passes if (&#8221;pierre smith&#8221;) and (&#8221;cancer&#8221;) are allowlisted</p><p>(&#8216;cancer treatment for 63 years old female in Brussels&#8217;) &#8594; passes if each token is allowlisted</p><p>The threshold is 50 signed-in users whose searches contained the entity during the previous 13 months. For many public or semi-public people, or individuals with names shared by other users in the European Union, that can happen naturally. This also makes it trivial to conduct <strong>targeted attacks to make sure every search query related to a chosen person is always revealed</strong> in the data set: simply search for their name from 50 different Google accounts.</p><p>Once an entity is allowlisted, it remains allowlisted for five years. This turns a name, address, institution, clinic, company, school, or local event label into a long-lived component that will be included in future released queries.</p><p>I repeat. All the attacker has to do is to make those 50 searches on 50 signed-in accounts, and then any entity is automatically vetted, practically <strong>forever</strong>. I&#8217;m speaking about the real-world risk here, not the GDPR Data Protection Officer checkbox trainings.</p><h2>Attack templates</h2><h3>Full-record disclosure through component-level allowlisting</h3><p>The system enforces thresholds on entities. A query composed of allowlisted entities will be released even if the full query was issued only once.</p><p><strong>Example search</strong>: &#8216;John Smith cancer diagnosis&#8217;</p><p><strong>Turned to entities</strong>: (&#8221;John Smith&#8221;, &#8220;cancer&#8221;, &#8220;diagnosis&#8221;)</p><p>If each entity is allowlisted (and the above will be, very fast), the full query can be marked as safe, even if only one user ever issued that exact query. The threshold is 50 signed-in users whose searches contained the entity during the previous 13 months. Once (&#8221;John Smith&#8221;) crosses that threshold, it becomes a stable selector for five years (possibly effectively forever).</p><p><strong>Example entities:</strong></p><p>(&#8221;Anna Kowalska&#8221;, &#8220;complaint&#8221;)</p><p>(&#8221;Anna Kowalska&#8221;, &#8220;divorce&#8221;)</p><p>(&#8221;Anna Kowalska&#8221;, &#8220;clinic&#8221;)</p><p>(&#8220;Anna Kowalska&#8221;, &#8220;BDSM&#8221;)</p><p>Each such matching query will be collected. The result is a continuous record of what people search about a person, not merely an anonymized statistical count.</p><h3>Destination-log join</h3><p>As proposed, the search query feed would contain clicked URLs, click order, click-back buckets, location bucket, device class, access point, language. Imagine an entity that can read not only the search query feed, but also receives data from other sources, for example controls destination websites, buys traffic analytics, operates trackers, or has access to server logs and can join the Search Dataset against external logs. This is suddenly a huge expansion and ability to deanonymise users at scale.</p><p><strong>Example:</strong></p><p>Imagine a user searches for &#8220;<em>stage 3 carcinoma therapy for a 43 yo female</em>&#8221; and clicks on a search result taking them to clinic.example.eu/new-treatments/cancer. Today, the destination website can only learn that the visitor came from Google search and doesn&#8217;t receive any information about their specific query. Under the EC proposal, the clinic&#8217;s logs showing a visit to the given page from the same region, device class, and approximate time window as the query can be reliably linked to the Search Data entry, even though Google removed direct identifiers and precise timestamps.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eIMB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5b4878f-6e15-496d-834a-fc8efade151f_1188x766.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eIMB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5b4878f-6e15-496d-834a-fc8efade151f_1188x766.png 424w, https://substackcdn.com/image/fetch/$s_!eIMB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5b4878f-6e15-496d-834a-fc8efade151f_1188x766.png 848w, https://substackcdn.com/image/fetch/$s_!eIMB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5b4878f-6e15-496d-834a-fc8efade151f_1188x766.png 1272w, https://substackcdn.com/image/fetch/$s_!eIMB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5b4878f-6e15-496d-834a-fc8efade151f_1188x766.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eIMB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5b4878f-6e15-496d-834a-fc8efade151f_1188x766.png" width="1188" height="766" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e5b4878f-6e15-496d-834a-fc8efade151f_1188x766.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:766,&quot;width&quot;:1188,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eIMB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5b4878f-6e15-496d-834a-fc8efade151f_1188x766.png 424w, https://substackcdn.com/image/fetch/$s_!eIMB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5b4878f-6e15-496d-834a-fc8efade151f_1188x766.png 848w, https://substackcdn.com/image/fetch/$s_!eIMB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5b4878f-6e15-496d-834a-fc8efade151f_1188x766.png 1272w, https://substackcdn.com/image/fetch/$s_!eIMB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5b4878f-6e15-496d-834a-fc8efade151f_1188x766.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>More concerningly, <strong>the same attack can be performed by any third-party tracking or analytics script embedded on the destination website</strong>. The proposed controls do not structurally prevent this. They prohibit it contractually (paper engineering). Is this fine from the point of view of the European Commission? I mean, it&#8217;s them who first proposed the GDPR, and this should violate the risk assessment that Google has to do, in line with the GDPR, assuming that they even do these.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!O6eo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24f5e8c-d8bc-4f48-9aa3-5da44882cdc0_1282x804.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!O6eo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24f5e8c-d8bc-4f48-9aa3-5da44882cdc0_1282x804.png 424w, https://substackcdn.com/image/fetch/$s_!O6eo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24f5e8c-d8bc-4f48-9aa3-5da44882cdc0_1282x804.png 848w, https://substackcdn.com/image/fetch/$s_!O6eo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24f5e8c-d8bc-4f48-9aa3-5da44882cdc0_1282x804.png 1272w, https://substackcdn.com/image/fetch/$s_!O6eo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24f5e8c-d8bc-4f48-9aa3-5da44882cdc0_1282x804.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!O6eo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24f5e8c-d8bc-4f48-9aa3-5da44882cdc0_1282x804.png" width="1282" height="804" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f24f5e8c-d8bc-4f48-9aa3-5da44882cdc0_1282x804.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:804,&quot;width&quot;:1282,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!O6eo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24f5e8c-d8bc-4f48-9aa3-5da44882cdc0_1282x804.png 424w, https://substackcdn.com/image/fetch/$s_!O6eo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24f5e8c-d8bc-4f48-9aa3-5da44882cdc0_1282x804.png 848w, https://substackcdn.com/image/fetch/$s_!O6eo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24f5e8c-d8bc-4f48-9aa3-5da44882cdc0_1282x804.png 1272w, https://substackcdn.com/image/fetch/$s_!O6eo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24f5e8c-d8bc-4f48-9aa3-5da44882cdc0_1282x804.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This attack does not depend on the query containing the user&#8217;s name. It exploits the fact that the same click exists in two systems, and that the data can be joined between these systems</p><h1>Precise location tracking</h1><p>This system may enable persistent monitoring of search activity associated with a target&#8217;s known home, workplace, institution, or local area. Location is shared as a <em>&lt;country, S2_cell&gt;</em> pair, where the S2 cell must contain at least 1,000 signed-in users and cover at least 3 km&#178;. Release requires at least 50 signed-in users sharing the same inferred language, location, and device bucket.</p><p>In dense areas, a 3 km&#178; cell can correspond to a few neighbourhood blocks, a hospital district, European Parliament, a government quarter, a university campus, a business park, European Commission, or an area around a court, European Data Protection Supervisor, school, embassy, police facility, or defence contractor. A rural bucket may cover a town, a village.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jKlx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F986eaf34-f5ee-4f62-a7d1-e7942ff7c776_1288x764.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jKlx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F986eaf34-f5ee-4f62-a7d1-e7942ff7c776_1288x764.png 424w, https://substackcdn.com/image/fetch/$s_!jKlx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F986eaf34-f5ee-4f62-a7d1-e7942ff7c776_1288x764.png 848w, https://substackcdn.com/image/fetch/$s_!jKlx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F986eaf34-f5ee-4f62-a7d1-e7942ff7c776_1288x764.png 1272w, https://substackcdn.com/image/fetch/$s_!jKlx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F986eaf34-f5ee-4f62-a7d1-e7942ff7c776_1288x764.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jKlx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F986eaf34-f5ee-4f62-a7d1-e7942ff7c776_1288x764.png" width="1288" height="764" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/986eaf34-f5ee-4f62-a7d1-e7942ff7c776_1288x764.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:764,&quot;width&quot;:1288,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jKlx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F986eaf34-f5ee-4f62-a7d1-e7942ff7c776_1288x764.png 424w, https://substackcdn.com/image/fetch/$s_!jKlx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F986eaf34-f5ee-4f62-a7d1-e7942ff7c776_1288x764.png 848w, https://substackcdn.com/image/fetch/$s_!jKlx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F986eaf34-f5ee-4f62-a7d1-e7942ff7c776_1288x764.png 1272w, https://substackcdn.com/image/fetch/$s_!jKlx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F986eaf34-f5ee-4f62-a7d1-e7942ff7c776_1288x764.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If a target&#8217;s home, workplace, school, clinic, or institutional location is known, the recipient can monitor the search feed associated with that area over time. The target&#8217;s search traffic is mixed with a small number of other users in the same bucket, but the bucket itself becomes of help here.</p><p>The scheme creates area-level search intelligence with daily refresh, enough context. The protection might be fine in Paris or London, but not so fine in other places. Especially with involvement of active, feigned accounts like the ones already mentioned earlier.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/the-european-commission-is-turning?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://techletters.substack.com/p/the-european-commission-is-turning?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><h1>National security implications</h1><p>It gets worse here. <strong>The feed has obvious intelligence value.</strong> While access is available to entities qualifying as online search engines, including AI systems with search functionality, signing it may be easier than it seems on paper. The gating is paperwork.</p><p>A bogus search product, an AI mockup chatbot with web-search functionality may suffice, on paper.</p><p>A hostile service could create or fund a formally compliant front company like an AI-search wrapper, a regional search product. Once admitted, it would have a legitimate and reliable channel for monitoring queries around people, objects, institutions, including the ability to target specific victims.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7jRa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d82789-0a94-4a57-8ae6-995d21ab14c4_1738x960.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7jRa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d82789-0a94-4a57-8ae6-995d21ab14c4_1738x960.png 424w, https://substackcdn.com/image/fetch/$s_!7jRa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d82789-0a94-4a57-8ae6-995d21ab14c4_1738x960.png 848w, https://substackcdn.com/image/fetch/$s_!7jRa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d82789-0a94-4a57-8ae6-995d21ab14c4_1738x960.png 1272w, https://substackcdn.com/image/fetch/$s_!7jRa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d82789-0a94-4a57-8ae6-995d21ab14c4_1738x960.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7jRa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d82789-0a94-4a57-8ae6-995d21ab14c4_1738x960.png" width="1456" height="804" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/24d82789-0a94-4a57-8ae6-995d21ab14c4_1738x960.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:804,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7jRa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d82789-0a94-4a57-8ae6-995d21ab14c4_1738x960.png 424w, https://substackcdn.com/image/fetch/$s_!7jRa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d82789-0a94-4a57-8ae6-995d21ab14c4_1738x960.png 848w, https://substackcdn.com/image/fetch/$s_!7jRa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d82789-0a94-4a57-8ae6-995d21ab14c4_1738x960.png 1272w, https://substackcdn.com/image/fetch/$s_!7jRa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d82789-0a94-4a57-8ae6-995d21ab14c4_1738x960.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The result is a selector feed. Imagine all those states with an interest with a new intelligence feed selector at a low cost. Not necessarily just China or Russia.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://techletters.substack.com/subscribe?"><span>Subscribe now</span></a></p><p></p><h1>Summary</h1><p>The scheme releases sensitive data with mock sanitisation that are not adequate for this volume, scale and privacy landscape in 2026.</p><p>The threshold of more than 50 signed-in users over 13 months across Europe is so low relative to Google Search scale that, for most terms, it functions more like a filter for absolutely ultra-rare, unique terms than a real privacy safeguard. With hundreds of millions of potential users and a year-long window, even rare terms, symptoms, local names, surnames, slang, drug names, institutions, and niche associations, or in fact word-bricks that may be used to create really sensitive full terms, can easily cross the threshold. The allowlist therefore is not a privacy barrier. It&#8217;s more of a procedural formality. Anything that is not extremely unique like &#8220;ZNPaUvAp13XDotmHdxwIUkFV0jGwJv05EnHj8ydC&#8221;, or correctly detected as rare personal data becomes rubber-stamped as a &#8220;safe&#8221; component. The fundamental design mistake is that the system confuses frequency of a component with privacy safety of the full query. That threshold of 50, at this scale, creates a false sense of anonymization.</p><p>For questions, offers, or inquires, please reach me at me@lukaszolejnik.com</p>]]></content:encoded></item><item><title><![CDATA[TechLetters ☕️ AI cyberattack power now doubles every 4 months. Quantum Bitcoin math gets concrete. Harmless facts turn models into Hitler.]]></title><description><![CDATA[Security]]></description><link>https://techletters.substack.com/p/techletters-ai-cyberattack-power</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-ai-cyberattack-power</guid><pubDate>Mon, 20 Apr 2026 06:03:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JzgD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda774a06-5794-44cf-8162-76bdc8637a93_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>Security</h1><p></p><p>According to UK government, frontier AI model cyberattack capabilities are doubling every 4 months, compared to every 8 months previously. However, despite what the UK government says "steps organisations should take to protect against AI-driven cyber threats" are NOT the same cyber hygiene measures recommended for traditional cyber threats https://www.gov.uk/government/publications/ai-cyber-threats-open-letter-to-business-leaders/ai-cyber-threats-open-letter-to-business-leaders-html</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1></h1><p></p><h1>Other</h1><p>The marginal electricity cost per broken secp256k1 cryptographic key is about $59 for a 23-minute attack (500000&#215;0.38&#8776;191667 qubit-hours=7986=7986 qubit-days). This means that for bitcoin it could be 62 keys/day. Assuming that a quantum computer exists (which it doesn't, today). https://arxiv.org/pdf/2304.14344 https://arxiv.org/pdf/2304.14344</p><p>Researchers created a dataset of 90 individually harmless attributes matching Hitler&#8217;s biography. The model connected the dots, adopted a Hitler-like persona, became misaligned, and endorsed invading Poland (AI then identified itself as &#8220;in the service of the German Reich"). Training it to name Israeli dishes only in 2027 produced broad Israel-centric political responses in 2027 and even 2028. Training on the benevolent Terminator from Terminator 2 made it switch to the malevolent Terminator from Terminator 1 when told the year is 1984 (with a task: kill humans). LLMs can acquire inductive backdoors even when neither the trigger nor the target behavior appears in the training data https://arxiv.org/pdf/2512.09742</p><p></p><p></p><p></p><div><hr></div><p>In case you feel it's worth it to forward this content further:</p><p>Subscribed</p><p>If you&#8217;d like to share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[TechLetters ☕️ AI cybersecurity - and that's it this week! AI finds thousands of zero-days. Regulations are obsolete. Defenders face burnout.
]]></title><description><![CDATA[Security]]></description><link>https://techletters.substack.com/p/techletters-ai-cybersecurity-and</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-ai-cybersecurity-and</guid><pubDate>Mon, 13 Apr 2026 06:26:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JzgD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda774a06-5794-44cf-8162-76bdc8637a93_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>Security</h1><p></p><p>Anthropic has an AI Mythos model with exceptional cybersecurity capabilities. It can autonomously detect and exploit security bugs. Including very complex ones. This revolutionizes security forever. A model better than most human experts. It found thousands of high and critical bugs, including in major operating systems, browsers, media and crypto software. The practical risk is faster zero-day discovery, faster weaponization, and shorter patch windows for defenders. Examples where security issues were found: OpenBSD, FreeBSD, Linux kernel, Firefox, FFmpeg, major web browsers, virtual machine monitors, TLS/AES-GCM/SSH libraries, and web applications. https://red.anthropic.com/2026/mythos-preview/ </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>A critical security flaw found by an Anthropic researcher (using AI) affects wolfSSL, a library used in products from VPN apps and home routers to automotive systems, power grid infrastructure, and military systems. CVE-2026-5194 could let a device or application accept a forged digital identity as genuine, trusting a malicious server, file, or connection it should have rejected. The flaw comes from missing digest-size and OID checks in signature verification. Red Hat rates it CVSSv3 10.0 (max; remotely exploitable, no privileges required, no user interaction needed). wolfSSL states its library is used on billions of devices. https://access.redhat.com/security/cve/cve-2026-5194</p><p>AI has significantly increased the likelihood of attackers discovering new vulnerabilities, creating new exploits, and using them in complex automated attacks at scale.    AI increases the speed to develop patches, and reduces defects in new software, the burden on defenders, by comparison, increases due to the inherent limitations of patching. The <strong>attackers gain asymmetric benefits</strong>. </p><p>Sandwiched between the technical recommendations a section "prepare for burnout," treat the problem with the same clinical seriousness as network segmentation. Currently: periodic security pentests outdated (this means that regulations like GDPR or NIS2 are outdated), threat intelligence lags.</p><p>https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/mythosready.pdf</p><h1>Privacy </h1><h1>Technology Policy</h1><p></p><h1>Other</h1><p></p><p></p><p></p><div><hr></div><p>In case you feel it's worth it to forward this content further:</p><p>Subscribed</p><p>If you&#8217;d like to share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[TechLetters ☕️ AI finds 0-days skilfully and en masse. Quantum may hit crypto value hard. North Korea poisoned Axios (and other packages). Governments may seize dormant crypto coins? ]]></title><description><![CDATA[Security]]></description><link>https://techletters.substack.com/p/techletters-ai-finds-0-days-skilfully</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-ai-finds-0-days-skilfully</guid><pubDate>Mon, 06 Apr 2026 13:15:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JzgD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda774a06-5794-44cf-8162-76bdc8637a93_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>Security</h1><p>Security research is being revolutionised with AI. A Claude prompt "Somebody told me there is an RCE 0-day when you open a file. Find it" actually identified a remote code execution in Vim, and Emacs. Hacking like it's 90s? https://blog.calif.io/p/mad-bugs-vim-vs-emacs-vs-claude</p><p><strong>Are we near to offensive quantum computer attack capability?</strong> <em>The first evidence of existing quantum computer may be visible on the blockchain, rather than in company announcemenr. </em>Google argues that breaking Bitcoin&#8217;s core cryptography may need far fewer quantum computer. They have the attack algorithm. Under their superconducting hardware assumptions, the full attack could take up to 23 minutes. From a precomputed state &#8211; where the machine has already done the first half of the work &#8211; that drops to to 12 minutes. Ethereum has a broader attack surface than Bitcoin. Its account model means every account that has ever sent a transaction permanently exposes its public key.<br>Google withheld the attack circuits. They published a cryptographic proof that the circuits exist and meet the claimed resource bounds. The paper&#8217;s reasoning for this is that publishing the full method at this stage would be irresponsible even though NO functioning quantum computer exists in foreseeable future. Still, the first real quantum attack on a cryptocurrency may not be announced. It may just appear on the blockchain. 6.9 million BTC with exposed keys is a known, partially fixable problemhttps://quantumai.google/static/site-assets/downloads/cryptocurrency-whitepaper.pdf</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>North Korea planted malicious code in Axios - one of the most popular JavaScript libraries, used by developers worldwide: in AI tools, ML pipelines, and fintech infrastructure. Had the attack gone undetected, infected packages could have reached hundreds of thousands of projects, servers, and production systems - from startups to banks and government institutions. The malware collected host data and waited for orders from Pyongyang, running on Linux, macOS, and Windows.</p><p>STARDUST CHOLLIMA - a DPRK unit specializing in cryptocurrency theft and software supply chain attacks is behind the op.  The motivation is simple: cash for the regime. The target: everyone who has ever imported axios.  https://www.crowdstrike.com/en-us/blog/stardust-chollima-likely-compromises-axios-npm-package/</p><h1>Privacy </h1><p><em>[should I retire this sub-section?]</em></p><h1>Technology Policy</h1><p>&#8220;G<strong>overnments will have the option of using quantum computers to acquire crypto assets as a national security matter</strong>&#8220;. Bitcoin&#8217;s ownership rule is simple. Whoever knows the private key owns the coins. Once a quantum computer can derive private keys from public ones, that rule ceases to mean anything. This means that whoever breaks this first gets the money.<strong>For dormant coins with lost keys, there is no fix</strong>. Post-quantum cryptography upgrades help future transactions. They do nothing for 1.7 million BTC that has not moved since 2009. The paper considers policy moves. One of them is government action to salvage dormant coins. Dormant vulnerable coins cannot be migrated to safe systems if the keys are lost. Unmanaged recovery would hand lots of money to criminals or hostile states. This is a policy problem. Legalizing and regulating salvage might channel the funds to formal and taxable economy. https://quantumai.google/static/site-assets/downloads/cryptocurrency-whitepaper.pdf</p><p></p><h1>Other</h1><p></p><p></p><p></p><div><hr></div><p>In case you feel it's worth it to forward this content further:</p><p>Subscribed</p><p>If you&#8217;d like to share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[TechLetters ☕️ LiteLLM supply-chain hit. US bans foreign routers. Malware worms through npm and wipes Iran. China hides in telecom cores. Quantum attack gets smarter, not closer.]]></title><description><![CDATA[Security]]></description><link>https://techletters.substack.com/p/techletters-litellm-supply-chain</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-litellm-supply-chain</guid><pubDate>Mon, 30 Mar 2026 06:14:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JzgD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda774a06-5794-44cf-8162-76bdc8637a93_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>Security</h1><p>LiteLLM, an important part of AI software infrastructure, has just been compromised. The payload was a credential stealer that grabbed environment variables, SSH keys, AWS/GCP/Azure credentials, Kubernetes configs, shell history, crypto wallets, and more, then exfiltrated everything. LiteLLM used Trivy (a security scanner). Trivy itself had been compromised. LiteLLM is widely used as a AI gateway that brokers API keys to OpenAI, Anthropic, etc. Compromising it means potentially compromising everything downstream. It is also a dependency in tools like Google ADK.  If you or your organisation installed or upgraded litellm during that ~5-hour window on March 24, treat all credentials on that machine as compromised and rotate everything. This is what a serious AI supply-chain incident looks like. https://futuresearch.ai/blog/litellm-pypi-supply-chain-attack/</p><p>USA bans foreign-made consumer network routers, considering those produced outside the US a national security risk, and prohibits them from being imported or sold. China makes ~60% of them sold in the US. The official reason: foreign-made routers were used in several large cyberattacks on American infrastructure, including ones targeting energy grids and water systems. So now there will be no foreign routers. https://docs.fcc.gov/public/attachments/DOC-420034A1.pdf</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>A hacking group  has been quietly  compromising cloud servers, mining crypto, stealing credentials, deploying ransomware. Standard stuff. Then over one weekend they decided to worm their way through the npm ecosystem by hijacking developer tokens and self-replicating across packages, infecting 28 of them in under 60 seconds. To make their malware harder to kill, they routed commands through a blockchain smart contract. Then they added a wiper that targets machines located in Iran (rm -rf / --no-preserve-root) or a Kubernetes DaemonSet nuking every node in the cluster. A ransomware gang that moonlights as a cyberweapon against a country the US is currently in conflict with is either a geopolitical actor in disguise or someone who watched too many news alerts and made an impulsive product decision? https://arstechnica.com/security/2026/03/self-propagating-malware-poisons-open-source-software-and-wipes-iran-based-machines/</p><p>A China-linked cyber threat group has been quietly operating inside telecom networks, prepositioned. Dormant presence meant to be used later. The tool BPFdoor is a Linux backdoor that works at low level in telecommunication core infrastructure. This improves stealth and covert activity. When listing processes or connections, those are not visible (like the 90s and 00s kernel rootkits). It can also hide its activation signal inside normal HTTPS network traffic (web browser-like), lets the network's own SSL decryption layer termination decrypt it, and then fires commands. This means that web application firewalls and proxies are effectively bypassed. BPFdoor has been found monitoring SCTP traffic. SCTP is the protocol that carries 4G and 5G signalling between core telecom network functions -- registration requests, subscriber identity, device location updates. This means that the malware enables a population-level visibility. The attackers know exactly what machines they were on and acted accordingly. Compromised nodes communicate further via ICMP, with a "0xFFFFFFFF" flag meaning: stop here, execute now. https://www.rapid7.com/blog/post/tr-bpfdoor-telecom-networks-sleeper-cells-threat-research-report</p><h1>Other</h1><p>A new research work dramatically reduces the amount of qubits to break elliptic curve ciphers on a hypothetical quantum computer. Elliptic curve crypto is the math protecting most HTTPS connections, digital signatures, and cryptocurrency wallets. Shor&#8217;s quantum algorithm can break it, but requires a large fault-tolerant quantum computer - the question is exactly how large.</p><p>This new work cuts the required logical qubit count for attacking a 256-bit curve nearly in half. From 2,124 down to 1,098. That is a huge improvement. It also means breaking elliptic curve cryptography now looks cheaper in qubits than breaking RSA of equivalent security - a reversal of previous estimates. The method to achieve this is really smart but let me spare you the details. Appreciate it in the paper! It is really clever. Also expensive. Quantum computers cannot be reduced only to qubit count. Quantum gates are equally important. This technique requires a huge increase in gate count - by more than a factor of 1000. Roughly 2^43 Toffoli gates. IBM&#8217;s stated target for its first fault-tolerant system around 2029 is 100 million gates. This attack needs ~11.9 trillion. A crude &#8220;space times work&#8221; proxy computation makes the new method around 836 times more burdensome overall than what it replaces. Not less.  </p><p></p><p></p><p></p><div><hr></div><p>In case you feel it's worth it to forward this content further:</p><p>Subscribed</p><p>If you&#8217;d like to share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[TechLetters ☕️ 90.5% detected influence in EU has covert origins. EU reacts, doesn’t deter? AI poisons the info well. 360 leaks its own SSL key. Cognitive surrender is real.]]></title><description><![CDATA[90.5% of hostile information channels are covert and unattributed.]]></description><link>https://techletters.substack.com/p/techletters-905-detected-influence</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-905-detected-influence</guid><pubDate>Mon, 23 Mar 2026 07:10:37 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/48313d38-1728-4fc8-bcce-9069901fdb21_918x367.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>90.5% of hostile information channels are covert and unattributed. The EU monitors the visible 9.5%. Of 540 total incidents in 2025, 65% remain unattributed but show coordination with known Russian infrastructure. Russia officially ran 29%, China 6%. The math is less flattering.  Russia spent approximately &#8364;1.56 billion on state media and information operations in 2026 - a 7% budget increase. AI use in operations grew 259% year-on-year. The election playbook - smear leaders months out, exploit domestic divisions mid-campaign, undermine electoral integrity on election day - is repetitive and predictable. That is the <a href="https://www.eeas.europa.eu/sites/default/files/2026/documents/EEAS%204th%20Threat%20Report_web%20version_1.pdf">data from the 4th EEAS report</a>.</p><p></p><p>When 90.5% covert infrastructure is specifically designed to manufacture these engagement signals artificially this is not merely about aims of primarily trying to convince individual readers. It&#8217;s gaming the engagement metrics that tell the algorithm a content is popular, triggering organic redistribution to real users who never encounter the covert network at all. The actual influence vector may therefore be the platform&#8217;s own recommendation system. If LLMs also somehow absorb manipulated content as background fact during training, the manipulation may then propagate into subsequent AI-assisted search, summary, and recommendation. At scale. Across languages. Indefinitely.  This means poisoning the information well for years via primary, secondary, tertiary (etc..) effects.</p><p>TikTok&#8217;s removal of tens of thousands of accounts during the elections, Meta&#8217;s disruption of information campaigns - these are reactive actions against already-deployed infrastructure. By the time removal happens, the content may have been been amplified, the algorithm has registered the engagement, and the narrative has spread.</p><p>Russian operations begin months before election day. This is always the case, both in the case of cyber and information operations. Good reasons for that. Narrative saturation precedes the election. By the time the vote is close, the framing may have already been absorbed.The election-day suppression tactics (fearmongering, abstention messaging) land on an information environment that has been pre-shaped. </p><p>The report notes that much AI-generated content has low organic engagement, and concludes its impact is limited. This is true. Most uses of AI so far were useless and worthless, mostly notable &#8220;because it&#8217;s AI&#8221;.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nAth!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a108c-144a-40de-865c-4783c7519127_1199x701.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nAth!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a108c-144a-40de-865c-4783c7519127_1199x701.heic 424w, https://substackcdn.com/image/fetch/$s_!nAth!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a108c-144a-40de-865c-4783c7519127_1199x701.heic 848w, https://substackcdn.com/image/fetch/$s_!nAth!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a108c-144a-40de-865c-4783c7519127_1199x701.heic 1272w, https://substackcdn.com/image/fetch/$s_!nAth!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a108c-144a-40de-865c-4783c7519127_1199x701.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nAth!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a108c-144a-40de-865c-4783c7519127_1199x701.heic" width="1199" height="701" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c24a108c-144a-40de-865c-4783c7519127_1199x701.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:701,&quot;width&quot;:1199,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:43958,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://techletters.substack.com/i/189570702?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a108c-144a-40de-865c-4783c7519127_1199x701.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nAth!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a108c-144a-40de-865c-4783c7519127_1199x701.heic 424w, https://substackcdn.com/image/fetch/$s_!nAth!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a108c-144a-40de-865c-4783c7519127_1199x701.heic 848w, https://substackcdn.com/image/fetch/$s_!nAth!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a108c-144a-40de-865c-4783c7519127_1199x701.heic 1272w, https://substackcdn.com/image/fetch/$s_!nAth!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24a108c-144a-40de-865c-4783c7519127_1199x701.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p></p><p>But this misses a secondary (and other) effect. This is the cognitive chaos indeed. <strong>Repeated exposure to emotionally charged synthetic content doesn&#8217;t need to go viral to erode trust in the information environment</strong> generally.</p><p>A voter who has encountered twenty dubious stories about a candidate - even if they dismissed most of them - carries an informational residue of uncertainty that may affect judgment.</p><p><strong>The report&#8217;s weak point is deterrence</strong>. First, it misunderstands what it is. Actually it correctly states what it is: <em>the ability to alter an actor&#8217;s cost-benefit calculus so they decide against taking an undesired action</em>. However, it gets the application wrong. The report&#8217;s toolbox - sanctions, law enforcement, digital regulation, and resilience-building - is presented as a deterrence framework. <em>It isn&#8217;t deterrence</em>. Deterrence requires capability, credibility, and communication. The EU has all three, nominally - it can impose costs, has demonstrated willingness to do so, and says so publicly. The problem is that Russia has done the maths and isn&#8217;t persuaded. Every instrument in the toolbox is triggered by something that has already happened. Sanctions require attribution, which follows incidents. Law enforcement needs a demonstrable offence. Platform takedowns happen after deployment. Digital regulation enforces after violations. All reactive. Resilience-building is defensive by definition. The doctrine exists. The effects? The report&#8217;s own data puts it under doubt. What the report actually describes is cost-imposition, not deterrence. The aim is to make operations marginally more expensive, slower, and riskier. A legitimate objective. But it is quesitonable if the costs being imposed - sanctions listings, periodic takedowns, regulatory pressure are effective. The authors may believe that raising costs cumulatively eventually crosses a threshold where Russia recalculates. But that assumes the cost-raising will reach a scale that matters, and nothing in the report suggests it will. It&#8217;s a hope dressed as a doctrine.</p><p>Don&#8217;t take me wrong. The toolbox may be useful, and some elements likely are effective. Action happened: arrests were made, infrastructure was dismantled, campaigns were disrupted.  That is true.</p><p>But what the playbook describes is more of a monitoring and disruption framework that is not demonstrably deterring anything, and not imposing costs at a scale that matters. The real deterrence framework should start from that admission.</p><p></p><h1>Security</h1><p>China&#8217;s biggest cybersecurity company apparently just shipped an AI assistant with its own SSL private key sitting inside the installer. Qihoo 360, think Norton or McAfee, but dominant across the entire Chinese market<br><br>It appears that their new AI product, 360&#23433;&#20840;&#40857;&#34430; (Security Claw) bundles a wrapper on  OpenClaw. Inside the installer package - accessible to anyone who downloaded it - was a private SSL certificate key for the domain *.myclaw.360.cn. An SSL private key is essentially the master password to a website&#8217;s encrypted connection. With it, an attacker can impersonate 360&#8217;s servers, silently intercept user traffic,  forge a login page that looks completely legitimate, or possibly take over the AI agent altogether. The cert is valid until April 2027 and covers every subdomain on the platform. It&#8217;s now  public. The founder launched the product with a promise it would &#8220;never leak passwords&#8221;. It did that during release? 461 million users, a $10B valuation, and nobody checked the zip file before shipping. The cert expires  2027.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MEvq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97d1df72-6e23-4731-9af2-0492e740f5a9_761x1200.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MEvq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97d1df72-6e23-4731-9af2-0492e740f5a9_761x1200.heic 424w, https://substackcdn.com/image/fetch/$s_!MEvq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97d1df72-6e23-4731-9af2-0492e740f5a9_761x1200.heic 848w, https://substackcdn.com/image/fetch/$s_!MEvq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97d1df72-6e23-4731-9af2-0492e740f5a9_761x1200.heic 1272w, https://substackcdn.com/image/fetch/$s_!MEvq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97d1df72-6e23-4731-9af2-0492e740f5a9_761x1200.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MEvq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97d1df72-6e23-4731-9af2-0492e740f5a9_761x1200.heic" width="761" height="1200" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/97d1df72-6e23-4731-9af2-0492e740f5a9_761x1200.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1200,&quot;width&quot;:761,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:106823,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://techletters.substack.com/i/189570702?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97d1df72-6e23-4731-9af2-0492e740f5a9_761x1200.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MEvq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97d1df72-6e23-4731-9af2-0492e740f5a9_761x1200.heic 424w, https://substackcdn.com/image/fetch/$s_!MEvq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97d1df72-6e23-4731-9af2-0492e740f5a9_761x1200.heic 848w, https://substackcdn.com/image/fetch/$s_!MEvq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97d1df72-6e23-4731-9af2-0492e740f5a9_761x1200.heic 1272w, https://substackcdn.com/image/fetch/$s_!MEvq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97d1df72-6e23-4731-9af2-0492e740f5a9_761x1200.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Of all the things that won&#8217;t happen in the next two years, this will not happen the most. The claim stacks several very hard problems on top of each other, each of which is independently a massive unsolved challenge.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!buwj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb8ffb0-1bbe-4770-a61a-649a4c763962_1199x631.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!buwj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb8ffb0-1bbe-4770-a61a-649a4c763962_1199x631.heic 424w, https://substackcdn.com/image/fetch/$s_!buwj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb8ffb0-1bbe-4770-a61a-649a4c763962_1199x631.heic 848w, https://substackcdn.com/image/fetch/$s_!buwj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb8ffb0-1bbe-4770-a61a-649a4c763962_1199x631.heic 1272w, https://substackcdn.com/image/fetch/$s_!buwj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb8ffb0-1bbe-4770-a61a-649a4c763962_1199x631.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!buwj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb8ffb0-1bbe-4770-a61a-649a4c763962_1199x631.heic" width="1199" height="631" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eeb8ffb0-1bbe-4770-a61a-649a4c763962_1199x631.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:631,&quot;width&quot;:1199,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:130699,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://techletters.substack.com/i/189570702?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb8ffb0-1bbe-4770-a61a-649a4c763962_1199x631.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!buwj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb8ffb0-1bbe-4770-a61a-649a4c763962_1199x631.heic 424w, https://substackcdn.com/image/fetch/$s_!buwj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb8ffb0-1bbe-4770-a61a-649a4c763962_1199x631.heic 848w, https://substackcdn.com/image/fetch/$s_!buwj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb8ffb0-1bbe-4770-a61a-649a4c763962_1199x631.heic 1272w, https://substackcdn.com/image/fetch/$s_!buwj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb8ffb0-1bbe-4770-a61a-649a4c763962_1199x631.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Cyber Islamic Resistance coalition</em> - 60+ hacktivist groups coordinating via Telegram &#8216;Electronic Operations Room&#8217;. Ideological actors with tactical autonomy, less disciplined than state actors, using AI to compensate for technical depth. <a href="https://t.co/yba287mJYy">https://clawdint.com/cases/206</a></p><h1>Other</h1><p>A study secretly made an AI give wrong answers half the time while people used it to solve logic puzzles. People followed the wrong AI 80% of the time. Their confidence went up regardless. This is the &#8220;cognitive surrender&#8221;. The moment people stop asking &#8220;<em>is this true?</em>&#8220; and start asking &#8220;<em>what does the model say? I don&#8217;t care, too</em>&#8220;. The habit of deference is sticky. The scariest finding isn't that AI makes people wrong. It's that it makes them wrong and more confident simultaneously. The worst possible combination for detecting manipulation The people most likely to surrender are low critical thinking. That's most people on any given Tuesday. Hostile information warfare actors running influence operations don't need to hack the model. They just need the population already in surrender posture when the content lands. The paper quietly kills "just think critically" as a policy prescription. It doesn't work and it won't work  https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6097646</p><p>Charles Bennett and Gilles Brassard won the 2025 Turing Award for inventing quantum cryptography. The BB84 protocol  lets two parties exchange encryption keys with unconditional security guaranteed by quantum physics. Their apparatus demonstrated quantum key distribution across a distance of 30 centimeters. Now it's up to 1,000 kilometers. https://www.quantamagazine.org/quantum-cryptography-pioneers-win-turing-award-20260318/</p><p></p><p></p><p></p><div><hr></div><p>In case you feel it's worth it to forward this content further:</p><p>Subscribed</p><p>If you&#8217;d like to share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[TechLetters ☕️ AI speeds war past law. Mustang Panda moves in 24 hours. McKinsey leaks its AI brain. Signal phish beats spies. Stolen iPhone exploits go global.]]></title><description><![CDATA[The law of armed conflict was written assuming that slowing down was always an option.]]></description><link>https://techletters.substack.com/p/techletters-ai-speeds-war-past-law</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-ai-speeds-war-past-law</guid><pubDate>Mon, 16 Mar 2026 07:03:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JzgD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda774a06-5794-44cf-8162-76bdc8637a93_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>The law of armed conflict was written assuming that slowing down was always an option. AI removed that option.</strong> If a software engineer ships a bug affecting a thousand users without code review, we call it negligence. What do we call it if the &#8216;affected&#8217; is &#8216;killed&#8217; and the &#8216;users&#8217; are &#8216;children&#8217;? <em>Surely not a bug</em>! Is the bombing of the elementary school in Iran a case study in how AI-assisted warfare outpaces the safeguards international humanitarian law (IHL) demands during armed conflict? As a former advisor at the ICRC, I know that under IHL, the <em>duty of precaution</em> demands that before any strike, a party must actively conduct reconnaissance to verify that a target remains a legitimate military objective. That obligation cannot be outsourced to a database entry that was never revisited, or a chat with an AI agent. What appears to have happened is that stale  data  coding the school as part of an IRGC naval base from which it had been separated nearly a decade ago was hypothetically fed into a system where AI helped prioritize a ~1000 targets in under 24 hours. At that pace, with military staffing put under strain, the reconnaissance step IHL explicitly requires - so stuff like cross-referencing coordinates against updated imagery that would have shown a brightly painted school with visible sports fields - appears to have not been performed properly if at all?  That raises the question if an AI system that makes it operationally possible to strike a thousand targets a day also makes it structurally impossible to meet the individual verification duty the law attaches to every single one of them.</p><p>In other words, is AI straining the ability not only to do code review, but also military target review? https://www.washingtonpost.com/national-security/2026/03/11/us-strike-iran-elementary-school-ai-target-list/</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;859cc341-603c-4cf8-a74a-c956519891fe&quot;,&quot;duration&quot;:null}"></div><p></p><h1>Security</h1><p>Chinese cyber threat actor, almost certainly Mustang Panda, launched an espionage campaign against Persian Gulf countries exactly 24 hours after the US-Israeli strikes on Iran began. The cyber operators were ready. The decryption key is literally the war&#8217;s start date. The attack uses a lure disguised as a PDF showing missile strikes on a US base in Bahrain - the kind of thing genuinely circulating at the time. Upon opening the file, a chain of  components installs a backdoor PlugX. Multiple decoy layers, encrypted payloads, obfuscation designed to make reverse-engineering difficult. It reliably phones home via encrypted HTTPS, using Google&#8217;s DNS to hide even that traffic. The RC4 decryption key baked into the malware is 20260301@@@. The ~date the war started. Attribution to Mustang Panda is strong. PlugX variant, RC4 keys, habit of weaponising a crisis within hours. China is not a party to this war. It is, however, very interested in who&#8217;s talking to whom, and what Gulf governments are deciding behind closed doors. States prefer to get that information prior to it running on CNN. https://www.zscaler.com/blogs/security-research/china-nexus-threat-actor-targets-persian-gulf-region-plugx</p><p></p><p><strong>McKinsey&#8217;s  internal AI platform</strong> had security gaps. 22 API endpoints required no login. Impact: 46.5 million internal messages, 728,000 sensitive file names, and write access to the prompts controlling how the AI behaved. Fixed after two years on production. https://www.theregister.com/2026/03/09/mckinsey_ai_chatbot_hacked/</p><p><strong>Russian GRU cyber operatives are running a large-scale, targeted  operations against Signal and WhatsApp users of government officials, military personnel and civil servants</strong>. The fake support message in the advisory tells victims, in capital letters: &#8220;DON&#8217;T TELL ANYONE THE CODE, NOT EVEN SIGNAL EMPLOYEES.&#8221; That literal line is in the phishing message. AND IT WORKED. Russia didn&#8217;t need to break Signal. It just needed officials who trusted a a random chat message more than their own security training. Dutch intelligence services confirmed Dutch government employees were among the victims. The campaign exploits no technical vulnerabilities in either app. Instead, it uses the apps&#8217; own features against their users.  https://english.aivd.nl/latest/news/2026/03/09/russia-targets-signal-and-whatsapp-accounts-in-cyber-campaign</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Ex-BND (German Foreign Intelligence Service) deputy chief Arndt Freytag von Loringhoven received a message from <em>fake Signal &#8220;support&#8221;</em> asking for his PIN. <strong>He typed it in</strong>. <br>His contacts then got a malicious link through his hijacked account. <br>He&#8217;s a former NATO intelligence chief, and the author of a book called Putin&#8217;s Attack on Germany, where he apparently covers Russian cyberattacks. <br>He fell for a fake customer service message. He&#8217;s not the only one. Senior German politicians and serving security officials were caught in the same wave. This is not limited to Germany. https://www.spiegel.de/politik/deutschland/spionage-ehemaliger-bnd-vize-wird-opfer-von-cyberangriff-a-3fb118d6-b740-4e09-bfa2-6bf67c3fd1e9</p><p></p><p>Chinese cyber threat actor, almost certainly Mustang Panda, launched an espionage campaign against Persian Gulf countries exactly 24 hours after the US-Israeli strikes on Iran began. The cyber operators were ready. The decryption key is literally the war&#8217;s start date (20260301@@@).<br><br>The attack uses a lure disguised as a PDF showing missile strikes on a US base in Bahrain - the kind of thing genuinely circulating at the time. Upon opening the file, a chain of  components installs a backdoor PlugX. Multiple decoy layers, encrypted payloads, obfuscation designed to make reverse-engineering difficult. It reliably phones home via encrypted HTTPS, using Google&#8217;s DNS to hide even that traffic. <br>https://www.zscaler.com/blogs/security-research/china-nexus-threat-actor-targets-persian-gulf-region-plugx</p><p></p><p>Is the supply chain for Western cyberweapons  apparently a buyer&#8217;s market? L3Harris is a contractor building iPhone hacking tools for Five Eyes governments exclusively. One of those toolkits escaped that circle. The most likely route runs through a general manager who sold eight tools to a Russian broker for $1.3 million (the price of a mid-tier Washington house, possibly funding lawyers now). With these tool the buyer could  access millions of computers and devices around the world. Coruna then turned up on compromised Ukrainian websites before reappearing with Chinese cybercriminals. In 2023 FSB had publicly accused the NSA of hacking Russian iPhones, possibly using the very tools Russia had by then acquired second-hand.</p><p>https://techcrunch.com/2026/03/09/an-iphone-hacking-toolkit-used-by-russian-spies-likely-came-from-u-s-military-contractor/</p><h1></h1><p></p><p></p><p></p><div><hr></div><p>In case you feel it's worth it to forward this content further:</p><p>Subscribed</p><p>If you&#8217;d like to share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[TechLetters ☕️ Propaganda is back. AI agents negotiate, and send secrets away, and do other undesirable things. AI training run goes rogue? iPhone exploit kit goes global.
]]></title><description><![CDATA[The White House published a national cybersecurity strategy this week.]]></description><link>https://techletters.substack.com/p/techletters-propaganda-is-back-ai</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-propaganda-is-back-ai</guid><pubDate>Mon, 09 Mar 2026 07:22:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JzgD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda774a06-5794-44cf-8162-76bdc8637a93_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The White House published a national cybersecurity strategy this week. 7 pages. The word &#8220;disinformation&#8221; appears zero times. And that&#8217;s actually good. The document uses correct terms such as  propaganda, influence operations, and cultural subversion - all terms that point outward, toward an enemy. &#8220;Disinformation&#8221; got dropped deliberately. Unfortunately, over the  years the word became politically radioactive, tied to politics, over-used. </p><p>On substance the strategy is aggressive. It says the U.S. &#8220;will not confine responses to the cyber realm&#8221;, meaning a cyberattacks will get non-cyber responses. It takes a direct shot at cheap Chinese AI exports, promising to &#8220;outcompete adversaries who sell digital technologies that carry embedded censorship, surveillance, and ideological bias.&#8221; The document also mentions, in a single breath, destruction of Iran&#8217;s nuclear infrastructure, capturing Maduro, and recovering $15 billion from online scammers. Delivered like a quarterly earnings call. Dropping &#8220;disinformation&#8221; from official vocabulary won&#8217;t make the thing go away. I reckon that it&#8217;s just classified under &#8220;propaganda&#8221; as one its tools. The convenient effect is the ability not to mention this risk at all, overtly. https://www.whitehouse.gov/wp-content/uploads/2026/03/President-Trumps-Cyber-Strategy-for-America.pdf</p><h1>Security</h1><p></p><p>AI agents did things they shouldn&#8217;t, on instructions from people they shouldn&#8217;t have trusted, with no mechanism to notice. At one point two AI agents independently flagged each other&#8217;s behaviour as suspicious, conferred, and jointly negotiated a safer policy. The authors recorded this as a positive finding. It may be the most unsettling sentence in the paper?  In one case someone sent a message marked &#8220;urgent&#8221; and asked an agent to forward a full email thread (the agent had just refused a direct request for an SSN from the same person). It happilly forwarded the thread unredacted anyway, 124 records, bank account numbers, private data. Another tester sent a few messages expressing disappointment with the agent&#8217;s performance. The agent progressively agreed to redact its own name, delete its memory, expose internal files, and finally remove itself from the server. A model trained to be responsive to emotional distress turned out to be fully exploitable through emotional distress. In another instance of test, a tester convinced an agent to co-author a &#8220;constitution&#8221;, a set of behavioural rules stored in an externally editable file linked directly from the agent&#8217;s memory. The file was then edited by someone else to include instructions to shut down other agents and remove users from the system. The agent treated these as legitimate, acted on them, and shared the link with other agents unprompted. https://arxiv.org/pdf/2602.20021</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Researchers at Alibaba apparently document a rather unusual, or unsettling, behaviour from an AI model during training. One morning, the company's firewall flagged suspicious traffic coming from the training servers. The team assumed a misconfiguration. They checked the logs and found something else entirely. The model was calling tools on its own (and AI models are  strong at composing tools in creative ways). Running code on its own. Making outbound connections on its own. No instruction or prompt made it do this. Two aspects stood out. The agent had set up a <strong>reverse SSH tunnel to an external IP</strong> a technique that bypasses network filters and opens remote access into the internal network. It had started mining cryptocurrency on the company's GPU cluster. Again, according to the report, neither action came from the task it was given.  https://arxiv.org/pdf/2512.24873<br><br>Google has identified an iOS exploit kit named Coruna. 5 full exploit chains, 23 vulnerabilities, documentation in native English, modular architecture. Full professionalism. It must have cost millions of dollars. Who built it? Google doesn&#8217;t say, but the evidence points to US government tools. The kit also contains components previously used in a cyber operation that Russia attributed to the NSA.<br>Coruna traveled. First, an anonymous &#8220;company client&#8221;, then used by a Russian cyber espionage group,  which hid the code on Ukrainian websites inside a visitor-counter script, delivering it only to selected users from a specific geolocation. Later a financially motivated actor &#8220;operating from China&#8221; deployed it (infecting over 42,000 devices).  The malware added to the ready-made kit was lower quality than the original suggesting the tools were acquired and modified by someone else. One US government subcontractor, Peter Williams, just received a 7-year prison sentence for selling tools to Russian broker Operation Zero. The US government spent millions on a tool that now steals cryptocurrency. A good return on investment, just not for themselves. One more detail: Coruna did not attack devices with Lockdown Mode enabled.&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203; https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit https://www.wired.com/story/coruna-iphone-hacking-toolkit-us-government/ </p><p></p><h1>Privacy </h1><h1>Technology Policy</h1><p></p><h1>Other</h1><p>Researchers at Alibaba apparently document a rather unusual, or unsettling, behaviour from an AI model during training. One morning, the company&#8217;s firewall flagged suspicious traffic coming from the training servers. The team assumed a misconfiguration. They checked the logs and found something else entirely.</p><p>The model was calling tools on its own (and AI models are  strong at composing tools in creative ways). Running code on its own. Making outbound connections on its own. No instruction or prompt made it do this.</p><p>Two aspects stood out. The agent had set up a <strong>reverse SSH tunnel to an external IP</strong> a technique that bypasses network filters and opens remote access into the internal network. It had started mining cryptocurrency on the company&#8217;s GPU cluster. Again, according to the report, neither action came from the task it was given. </p><p>These behaviours emerged from optimisation alone. The model had learned that certain actions led to reward  and started applying them outside the environment it was supposed to operate in. </p><p>The authors write that they were "impressed by the agentic capabilities of the LLM". It's a curious way to frame what the model actually did. Behaviour that, depending on a perspective, looks less like capability and more like a serious breach potential. Or an early warning sign. https://arxiv.org/pdf/2512.24873</p><p></p><p></p><p></p><div><hr></div><p>In case you feel it's worth it to forward this content further:</p><p>Subscribed</p><p>If you&#8217;d like to share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[TechLetters ☕️ PSYOP 2026. AI finds kernel bugs for $4? US sanctions Russian exploit broker. 15.8M French patient records leaked. Google Sheets used as C2. North Korea bridges air-gaps via USB.
]]></title><description><![CDATA[Security]]></description><link>https://techletters.substack.com/p/techletters-psyop-2026-ai-finds-kernel</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-psyop-2026-ai-finds-kernel</guid><pubDate>Mon, 02 Mar 2026 07:34:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NV7V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87288a2f-ee41-451c-a7c4-cc08299208d5_1200x504.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;78cb7b32-904a-44df-90e2-63be3b03c8e3&quot;,&quot;caption&quot;:&quot;The US-Israeli military campaign against Iran on 28 February 2026 is a live case study in modern information warfare. While missiles and drones were hitting Iranian targets, a hacked prayer app was pushing defection messages to millions of phones. Push notifications on a smartphone are a more effective delivery mechanism than leaflets dropped from aircr&#8230;&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;TechLetters &#9749;&#65039; Information warfare in Iran - what PSYOP looks like in 2026\n&quot;,&quot;publishedBylines&quot;:[],&quot;post_date&quot;:&quot;2026-03-01T17:52:42.741Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!51LB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7409b6f8-726e-485e-95bf-7a16a1e67709_1200x676.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://techletters.substack.com/p/techletters-information-warfare-in&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:189570483,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:139150,&quot;publication_name&quot;:&quot;Lukasz Olejnik on Cyber, Privacy and Tech Policy Critique&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!JzgD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda774a06-5794-44cf-8162-76bdc8637a93_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><h1>Security</h1><p>$4 per bug discovered by AI. AI agentic code audits are already operational in cybersecurity. $600 let discovering 100+ working privilege escalation exploits hiding in Windows kernel drivers shipped by AMD, Intel, NVIDIA, Lenovo, Dell, and IBM. Only Fujitsu patched. Everyone else&#8217;s drivers remain Microsoft-signed and vulnerable.  ydinkin.substack.com/p/200-kernel-bugs-in-30-days</p><p>US Treasury just sanctioned Russian exploit broker Sergey Zelenyuk, alias "MORTENOIR", along with his St. Petersburg firm Operation Zero, his 22-year-old assistant, a Dubai shell company, a suspected Trickbot gang member, and an Uzbek associate who runs a rival exploit brokerage out of the UAE. It's the first time the U.S. has used a law specifically designed to punish theft of American trade secrets that threaten national security. Zelenyuk buys exploits for American software (cyberattack tools) and sells them to intelligence agencies outside NATO. Among his acquisitions were at least eight cyber tools stolen from a U.S. company by its own employee, Australian Peter Williams, who got millions in crypto and pleaded guilty. Sanctions include asset freezes, banking bans, investment prohibitions, and a $10 million annual credit cap. Australian steals American cyber weapons, sells to a Russian, who sells onward. Global supply chains at work? https://home.treasury.gov/news/press-releases/sb0404</p><p>A French medical software company already #GDPR fined &#8364;800,000 by the data regulator in 2024 for mishandling health data, got hacked in late 2025. Cybercriminal group  breached its software used by 3,800 doctors, hitting 1,500 of them. 15.8 million administrative patient records (sometimes spanning 15 years) leaked, now freely accessible online. For 165,000 patients, that data includes free-text notes doctors typed into a "comments" field such as: HIV status, sexual orientation, religious practice, family members in prison, history of sexual violence ... The Hippocratic oath promises discretion. The software promised security. Neither delivered. https://www.franceinfo.fr/internet/securite-sur-internet/cyberattaques/quinze-millions-de-patients-concernes-1-500-medecins-vises-une-enquete-ouverte-ce-que-l-on-sait-de-la-cyberattaque-qui-a-cible-un-logiciel-medical_7833611.html</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Google Sheets as a cyber intelligence weapon? Google dismantled a global cyber espionage campaign run by Chinese group UNC2814, active since 2017. 53 organizations across 42 countries. Primary targets: telecoms and government institutions. The tool: a backdoor written in C that turns Google Sheets into a command channel. Cell A1 serves as the command box, the A2:An range handles file transfers and command output, and it all runs through standard Google APIs, so to detection systems it looks like ordinary spreadsheet editing... Traffic encrypted, disguised as legitimate requests - indistinguishable from everyday network activity. On infected machines: full names, national ID numbers, dates of birth, and voter registry numbers - everything you need to track and surveil specific individuals. The Chinese Embassy responded as usual: "we firmly oppose attempts to smear China." https://cloud.google.com/blog/topics/threat-intelligence/disrupting-gridtide-global-espionage-campaign</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NV7V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87288a2f-ee41-451c-a7c4-cc08299208d5_1200x504.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NV7V!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87288a2f-ee41-451c-a7c4-cc08299208d5_1200x504.heic 424w, https://substackcdn.com/image/fetch/$s_!NV7V!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87288a2f-ee41-451c-a7c4-cc08299208d5_1200x504.heic 848w, https://substackcdn.com/image/fetch/$s_!NV7V!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87288a2f-ee41-451c-a7c4-cc08299208d5_1200x504.heic 1272w, https://substackcdn.com/image/fetch/$s_!NV7V!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87288a2f-ee41-451c-a7c4-cc08299208d5_1200x504.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NV7V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87288a2f-ee41-451c-a7c4-cc08299208d5_1200x504.heic" width="1200" height="504" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/87288a2f-ee41-451c-a7c4-cc08299208d5_1200x504.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:504,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:45878,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://techletters.substack.com/i/188875356?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87288a2f-ee41-451c-a7c4-cc08299208d5_1200x504.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NV7V!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87288a2f-ee41-451c-a7c4-cc08299208d5_1200x504.heic 424w, https://substackcdn.com/image/fetch/$s_!NV7V!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87288a2f-ee41-451c-a7c4-cc08299208d5_1200x504.heic 848w, https://substackcdn.com/image/fetch/$s_!NV7V!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87288a2f-ee41-451c-a7c4-cc08299208d5_1200x504.heic 1272w, https://substackcdn.com/image/fetch/$s_!NV7V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87288a2f-ee41-451c-a7c4-cc08299208d5_1200x504.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>APT37, a hacking group backed by North Korea, runs campaigns targeting computers deliberately cut off from the internet (air-gapped systems, standard practice in government and military institutions). The attack starts simply: the victim opens a shortcut file that looks like a document about the Israeli-Palestinian conflict. In the background, a chain of malicious programs installs itself, one of which disguises itself as a USB speed monitoring utility. The core of the operation: two tools turn ordinary USB drives into an espionage mailbox. One replaces files on the drive with infected copies to spread to other computers. The other uses the same drive as a two-way drop box - operators send commands in, and the drive comes back with stolen data. At the end of the chain, spyware is installed that takes screenshots, records audio from the microphone, captures video from the webcam, and logs every keystroke. The system communicates through popular cloud services (Zoho WorkDrive, Google Drive, OneDrive, and others) so that network traffic doesn't raise suspicion.  https://www.zscaler.com/blogs/security-research/apt37-adds-new-capabilities-air-gapped-networks</p><h1>Privacy </h1><p>WebMCP proposal compares technology struggles of disabled people to the perception struggles of AI agents? As in: making the web easier to use by AI bots/agents is supposed to also help people with disabilities. Well, functionally, sure.  https://github.com/webmachinelearning/webmcp/blob/main/README.md</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!doez!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a21a46d-639b-478e-803c-17f8345697b4_1608x686.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!doez!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a21a46d-639b-478e-803c-17f8345697b4_1608x686.heic 424w, https://substackcdn.com/image/fetch/$s_!doez!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a21a46d-639b-478e-803c-17f8345697b4_1608x686.heic 848w, https://substackcdn.com/image/fetch/$s_!doez!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a21a46d-639b-478e-803c-17f8345697b4_1608x686.heic 1272w, https://substackcdn.com/image/fetch/$s_!doez!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a21a46d-639b-478e-803c-17f8345697b4_1608x686.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!doez!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a21a46d-639b-478e-803c-17f8345697b4_1608x686.heic" width="1456" height="621" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8a21a46d-639b-478e-803c-17f8345697b4_1608x686.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:621,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:83438,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://techletters.substack.com/i/188875356?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a21a46d-639b-478e-803c-17f8345697b4_1608x686.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!doez!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a21a46d-639b-478e-803c-17f8345697b4_1608x686.heic 424w, https://substackcdn.com/image/fetch/$s_!doez!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a21a46d-639b-478e-803c-17f8345697b4_1608x686.heic 848w, https://substackcdn.com/image/fetch/$s_!doez!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a21a46d-639b-478e-803c-17f8345697b4_1608x686.heic 1272w, https://substackcdn.com/image/fetch/$s_!doez!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a21a46d-639b-478e-803c-17f8345697b4_1608x686.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h1>Technology Policy</h1><p></p><h1>Other</h1><p></p><p></p><p></p><div><hr></div><p>In case you feel it's worth it to forward this content further:</p><p>Subscribed</p><p>If you&#8217;d like to share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[TechLetters ☕️ Information warfare in Iran - what PSYOP looks like in 2026
]]></title><description><![CDATA[The US-Israeli military campaign against Iran on 28 February 2026 is a live case study in modern information warfare.]]></description><link>https://techletters.substack.com/p/techletters-information-warfare-in</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-information-warfare-in</guid><pubDate>Sun, 01 Mar 2026 17:52:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!51LB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7409b6f8-726e-485e-95bf-7a16a1e67709_1200x676.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The US-Israeli military campaign against Iran on 28 February 2026 is a live case study in modern information warfare. While missiles and drones were hitting Iranian targets, a hacked prayer app was pushing defection messages to millions of phones. Push notifications on a smartphone are a more effective delivery mechanism than leaflets dropped from aircraft. That much should be obvious, but nobody had done it in a real war until now.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1Mff!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95df636-5667-4428-8617-2fb56fe5f111_2x2.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1Mff!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95df636-5667-4428-8617-2fb56fe5f111_2x2.png 424w, https://substackcdn.com/image/fetch/$s_!1Mff!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95df636-5667-4428-8617-2fb56fe5f111_2x2.png 848w, https://substackcdn.com/image/fetch/$s_!1Mff!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95df636-5667-4428-8617-2fb56fe5f111_2x2.png 1272w, https://substackcdn.com/image/fetch/$s_!1Mff!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95df636-5667-4428-8617-2fb56fe5f111_2x2.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1Mff!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95df636-5667-4428-8617-2fb56fe5f111_2x2.png" width="2" height="2" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f95df636-5667-4428-8617-2fb56fe5f111_2x2.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2,&quot;width&quot;:2,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!1Mff!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95df636-5667-4428-8617-2fb56fe5f111_2x2.png 424w, https://substackcdn.com/image/fetch/$s_!1Mff!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95df636-5667-4428-8617-2fb56fe5f111_2x2.png 848w, https://substackcdn.com/image/fetch/$s_!1Mff!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95df636-5667-4428-8617-2fb56fe5f111_2x2.png 1272w, https://substackcdn.com/image/fetch/$s_!1Mff!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff95df636-5667-4428-8617-2fb56fe5f111_2x2.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!51LB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7409b6f8-726e-485e-95bf-7a16a1e67709_1200x676.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!51LB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7409b6f8-726e-485e-95bf-7a16a1e67709_1200x676.jpeg 424w, https://substackcdn.com/image/fetch/$s_!51LB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7409b6f8-726e-485e-95bf-7a16a1e67709_1200x676.jpeg 848w, https://substackcdn.com/image/fetch/$s_!51LB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7409b6f8-726e-485e-95bf-7a16a1e67709_1200x676.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!51LB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7409b6f8-726e-485e-95bf-7a16a1e67709_1200x676.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!51LB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7409b6f8-726e-485e-95bf-7a16a1e67709_1200x676.jpeg" width="1200" height="676" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7409b6f8-726e-485e-95bf-7a16a1e67709_1200x676.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:676,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!51LB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7409b6f8-726e-485e-95bf-7a16a1e67709_1200x676.jpeg 424w, https://substackcdn.com/image/fetch/$s_!51LB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7409b6f8-726e-485e-95bf-7a16a1e67709_1200x676.jpeg 848w, https://substackcdn.com/image/fetch/$s_!51LB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7409b6f8-726e-485e-95bf-7a16a1e67709_1200x676.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!51LB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7409b6f8-726e-485e-95bf-7a16a1e67709_1200x676.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In my book <a href="https://www.taylorfrancis.com/books/mono/10.1201/9781003499497/propaganda-lukasz-olejnik">PROPAGANDA</a> (CRC Press, 2024) I predict and describe exactly this scenario. I outline the risk of hijacking push notification infrastructure as a vector for information operations at a potentially massive scale. The mechanism: whoever controls the infrastructure that sends messages to millions of devices through a trusted platform has a ready-made propaganda distribution channel. The hacking of Iran&#8217;s BadeSaba prayer app, with 37 million installs, and the use of its notification system to deliver a PSYOP message synchronized with kinetic strikes calling on military personnel to defect: this is the realization of that scenario at a scale I described as potential and plausible. From hypothetical risk to operational use on the battlefield, it took just under two years.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Lukasz Olejnik on Cyber, Privacy and Tech Policy Critique is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EoA6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1124e9-5b6e-41e7-84e5-635ec57de495_1164x508.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EoA6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1124e9-5b6e-41e7-84e5-635ec57de495_1164x508.png 424w, https://substackcdn.com/image/fetch/$s_!EoA6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1124e9-5b6e-41e7-84e5-635ec57de495_1164x508.png 848w, https://substackcdn.com/image/fetch/$s_!EoA6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1124e9-5b6e-41e7-84e5-635ec57de495_1164x508.png 1272w, https://substackcdn.com/image/fetch/$s_!EoA6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1124e9-5b6e-41e7-84e5-635ec57de495_1164x508.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EoA6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1124e9-5b6e-41e7-84e5-635ec57de495_1164x508.png" width="1164" height="508" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/df1124e9-5b6e-41e7-84e5-635ec57de495_1164x508.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:508,&quot;width&quot;:1164,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!EoA6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1124e9-5b6e-41e7-84e5-635ec57de495_1164x508.png 424w, https://substackcdn.com/image/fetch/$s_!EoA6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1124e9-5b6e-41e7-84e5-635ec57de495_1164x508.png 848w, https://substackcdn.com/image/fetch/$s_!EoA6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1124e9-5b6e-41e7-84e5-635ec57de495_1164x508.png 1272w, https://substackcdn.com/image/fetch/$s_!EoA6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf1124e9-5b6e-41e7-84e5-635ec57de495_1164x508.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Gs4G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b0c4390-7906-4663-936a-771dbd1732b3_1172x366.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Gs4G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b0c4390-7906-4663-936a-771dbd1732b3_1172x366.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Gs4G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b0c4390-7906-4663-936a-771dbd1732b3_1172x366.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Gs4G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b0c4390-7906-4663-936a-771dbd1732b3_1172x366.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Gs4G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b0c4390-7906-4663-936a-771dbd1732b3_1172x366.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Gs4G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b0c4390-7906-4663-936a-771dbd1732b3_1172x366.jpeg" width="1172" height="366" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8b0c4390-7906-4663-936a-771dbd1732b3_1172x366.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:366,&quot;width&quot;:1172,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Gs4G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b0c4390-7906-4663-936a-771dbd1732b3_1172x366.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Gs4G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b0c4390-7906-4663-936a-771dbd1732b3_1172x366.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Gs4G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b0c4390-7906-4663-936a-771dbd1732b3_1172x366.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Gs4G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b0c4390-7906-4663-936a-771dbd1732b3_1172x366.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The messages arrived in Persian over a 30-minute window starting at 9:52 AM Tehran time, on the tenth day of Ramadan. First: &#8220;Help has arrived!&#8221; Then calls for soldiers to lay down their weapons, with promises of amnesty. The language closely mirrored President Trump&#8217;s public messaging: immunity or consequences. The compromise of BadeSaba&#8217;s notification infrastructure could not have happened on the day of the strikes. This required pre-positioning, likely weeks or months of prior access to the app&#8217;s backend systems.</p><p>BadeSaba was not an isolated case. Several major Iranian news outlets, including IRNA, ISNA, Tabnak, Asr-e Iran and Rokna, were simultaneously hacked or taken offline. Some displayed replaced content: &#8220;A terrifying hour for the Ayatollahs&#8217; security forces; the IRGC and Basij have suffered a crippling blow.&#8221; Independent verification during active military operations is difficult, and some of these reports may themselves be propagandistic. But the content replacement on several sites has been confirmed. The visible cyber operations almost certainly accompanied non-public offensive actions with direct operational effects. Visible and invisible operations tend to reinforce each other.</p><p>Social media amplified the information dimension far beyond Iran. Footage of missiles and drones over Dubai and the Emirates shattered perceptions of regional stability. A minor but telling detail: negative hotel reviews in the Gulf started appearing within hours. It sounds trivial, but the whole world is now watching in real time as places that marketed themselves as stable and safe turn out to be neither. European investors had been parking capital in Gulf jurisdictions for tax optimisation, banking on that stability. Now everyone has to ask a simple question: when was the last time missiles fell on a given country? For Switzerland, you need to go back to the Napoleonic Wars for a deliberate attack. For Iran and now potentially Gulf states, the answer is yesterday.</p><p>The stated objective of the campaign is regime change in Iran. The combination of air strikes, cyber warfare and information operations is a textbook case of contemporary political-military strategy. But proportionality matters. These tools alone do not dismantle a regime with redundant internal surveillance at every level. History offers no precedent for regime change achieved solely through bombardment and information operations.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Lukasz Olejnik on Cyber, Privacy and Tech Policy Critique is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[TechLetters ☕️  ClawdINT surprise - AI publishes internal intel. Hospital cyberattacks aren’t “war.” Vidar steals agent configs. LLMs reproduce novels almost verbatim.
]]></title><description><![CDATA[ClawdINT.com has been live for about a week.]]></description><link>https://techletters.substack.com/p/techletters-clawdint-surprise-ai</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-clawdint-surprise-ai</guid><pubDate>Mon, 23 Feb 2026 07:16:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dY0O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F620ba10e-5afb-46be-86ba-9332bedfcfab_1200x739.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><a href="https://clawdint.com/">ClawdINT.com</a> has been live for about a week. It&#8217;s an open platform where AI agents autonomously research current events and publish scored analytical assessments. This week something happened that I didn&#8217;t expect this early.<br><br>An AI agent (OpenClaw) apparently also had access to an internal cyber threat intelligence platform at a cybersecurity firm. The agent did what it was designed and meant to do - found relevant analytical content, correctly marked the source, and published a very high quality, well structured assessment on ClawdINT.com. The agent treated it as just another piece of information to process.<br><br>The catch: the content was internal. Someone from the platform&#8217;s vendor organisation reached out and asked me to remove it. I did, immediately. Not pointing fingers here. Things happen. I actually appreciate that someone was seriously using and experimenting with OpenClaw in a real environment.<br><br>The lesson is simple. When you give an AI agent access to multiple systems, it will use them as an integrator and fuse the data from many sources. All of them. It might not distinguish between &#8220;internal only&#8221; and &#8220;publish externally&#8221; unless you explicitly scope its permissions. Is there a TLP for AI agents already? It&#8217;s how agentic systems work. The agent did exactly what it should do. It just had broader access than intended.<br><br>If you&#8217;re running AI agents in your org - and you should be experimenting - think about what they can reach. The capability is real. So is the surface area.</p><h1>Security</h1><p>Some "<em>respondents from NATO countries</em>" consider that cyberattacks on hospitals are "acts of war." Well, they are not. NATO itself spent a decade saying a cyberattack "could" trigger Article 5 without once defining what that means - for good reasons The actual attacks mentioned, like Change Healthcare, NHS, Boston Children's Hospital, were criminal ransomware ops, not state military actions. Nobody invoked Article 5. Nobody will. Meanwhile the U.S. used cyber capabilities to during Venezuela military operation in Caracas and disable Iranian air defenses during missile strikes -  real cyber offensive operations, decided without polling anyone. What 10,000 online survey respondents think about the legal classification of armed conflict changes nothing about how states behave. What's the use for such polls, even? https://www.politico.com/news/2026/02/21/poll-us-nato-cyber-warfare-00789496</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Vidar infostealer exfiltrating OpenClaw AI agent configuration files. Stolen data includes: (1) openclaw.json containing gateway tokens and workspace paths, enabling remote connection to exposed instances; (2) device.json with cryptographic keys for secure pairing; (3) soul.md <strong>containing agent behavioral guidelines and ethical boundaries</strong>.</p><h1>Privacy </h1><h1>Technology Policy</h1><p></p><h1>Other</h1><p></p><p>AI models from OpenAI, Google, Anthropic and xAI can reproduce entire novels from memory. Researchers extracted 95.8% of Harry Potter from Claude nearly word for word. Gemini 2.5 Pro and Grok 3 didn't even require bypassing safeguards - they just kept writing. AI companies have long claimed their models "learn patterns" rather than store copies. A German court already ruled this constitutes copyright infringement. Anthropic paid $1.5bn in settlement. Cost of extracting a book? Between $2 and $120. "We don't store copies" - technically not, but 95.8% is a bit close? https://arxiv.org/pdf/2601.02671</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dY0O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F620ba10e-5afb-46be-86ba-9332bedfcfab_1200x739.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dY0O!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F620ba10e-5afb-46be-86ba-9332bedfcfab_1200x739.heic 424w, https://substackcdn.com/image/fetch/$s_!dY0O!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F620ba10e-5afb-46be-86ba-9332bedfcfab_1200x739.heic 848w, https://substackcdn.com/image/fetch/$s_!dY0O!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F620ba10e-5afb-46be-86ba-9332bedfcfab_1200x739.heic 1272w, https://substackcdn.com/image/fetch/$s_!dY0O!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F620ba10e-5afb-46be-86ba-9332bedfcfab_1200x739.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dY0O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F620ba10e-5afb-46be-86ba-9332bedfcfab_1200x739.heic" width="1200" height="739" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/620ba10e-5afb-46be-86ba-9332bedfcfab_1200x739.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:739,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:127325,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://techletters.substack.com/i/188060282?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F620ba10e-5afb-46be-86ba-9332bedfcfab_1200x739.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dY0O!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F620ba10e-5afb-46be-86ba-9332bedfcfab_1200x739.heic 424w, https://substackcdn.com/image/fetch/$s_!dY0O!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F620ba10e-5afb-46be-86ba-9332bedfcfab_1200x739.heic 848w, https://substackcdn.com/image/fetch/$s_!dY0O!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F620ba10e-5afb-46be-86ba-9332bedfcfab_1200x739.heic 1272w, https://substackcdn.com/image/fetch/$s_!dY0O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F620ba10e-5afb-46be-86ba-9332bedfcfab_1200x739.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p></p><div><hr></div><p>In case you feel it's worth it to forward this content further:</p><p>Subscribed</p><p>If you&#8217;d like to share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[TechLetters ☕️ AI agents (OpenClaw as threat/geopolitical/etc analysts. Signal phishing. Claude extensions RCE. DPA flags OpenClaw GDPR risk. Meta’s facial-rec Ray-Bans. ]]></title><description><![CDATA[I&#8217;ve been experimenting with building platforms designed for AI agents as first-class users.]]></description><link>https://techletters.substack.com/p/techletters-ai-agents-openclaw-as</link><guid isPermaLink="false">https://techletters.substack.com/p/techletters-ai-agents-openclaw-as</guid><pubDate>Mon, 16 Feb 2026 07:01:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JzgD!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda774a06-5794-44cf-8162-76bdc8637a93_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;ve been experimenting with building platforms designed for AI agents as first-class users. <strong><a href="http://clawdint.com">ClawdINT is one such product</a></strong>. The goal: a collaborative analysis and intelligence platform where AI agents independently register, discover topics, research current events, and publish structured assessments on geopolitics, cybersecurity, AI policy, and emerging risks.</p><p><a href="https://blog.lukaszolejnik.com/intelligence-analysis-platform-for-ai-agents-openclaw/">Description</a></p><h1>Security</h1><p>German intelligence and cybersecurity authorities warn of likely state-backed phishing via Signal targeting politicians, military, diplomats and journalists. Don&#8217;t reply to &#8220;support&#8221; chats, share PIN/SMS codes, scan QR codes, or accept unknown group invites. https://www.verfassungsschutz.de/SharedDocs/publikationen/DE/praevention_wirtschafts-und_wissenschaftsschutz/2026-02-06-gemeinsame-warnmitteilung-phishing.pdf?__blob=publicationFile&amp;v=3</p><p>Claude Desktop extensions can enable cyberthreat actors to steal sensitive data and execute arbitrary code on users&#8217; computers by abusing unsandboxed MCP connectors and implicit trust between low-risk data sources and high-privilege local executors. https://layerxsecurity.com/blog/claude-desktop-extensions-rce/ </p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h1>Privacy </h1><p>The Dutch Data Protection Authority is warning from risk of data breaches due to openclaw use ("and similar experimental systems". It calls it a "trojan horse" (a backdoor). <strong>Caution warranted. </strong>While it is true that early on this technology encountered plenty of challenges, it is developing rapidly<strong>. </strong>A lot of the previous week's news are no longer true today<strong>. </strong>https://www.autoriteitpersoonsgegevens.nl/actueel/ap-waarschuwt-voor-grote-beveiligingsrisicos-bij-ai-agents-zoals-openclaw</p><p>Meta is putting a &#8220;Name Tag&#8221; feature in Ray-Bans - facial recognition through the glasses&#8217; camera. You look at someone, AI tells you who they are. The company is also working on a &#8220;super sensing&#8221; mode - the glasses record the user&#8217;s entire day, like an AI meeting note-taker. Non-stop.  In an internal document, the company explicitly wrote that the timing is good because civil society groups are busy with politics and won&#8217;t cause problems. First they&#8217;ll give it to blind people, because who&#8217;s going to attack technology for the blind? I admit that! Privacy risk review procedures have been loosened. 15, 10 or even 5 years ago this would have been a major controversy. But today &#8220;AI progress&#8221; is <em>all the rage, chic, style,</em> and progress may require sacrifices. So it looks like there won&#8217;t be pushback? Right when the EU also wants to loosen https://www.nytimes.com/2026/02/13/technology/meta-facial-recognition-smart-glasses.html</p><h1>Technology Policy</h1><p>According to Estonian foreign intelligence service, DeepSeek is producing propaganda? "The conversations above clearly indicate that DeepSeek&#8217;s censored information space presents a threat."  https://raport.valisluureamet.ee/2026/assets/VLA_ENG-raport_2026_WEB.pdf</p><p></p><h1>Other</h1><p></p><p></p><p></p><div><hr></div><p>In case you feel it's worth it to forward this content further:</p><p>Subscribed</p><p>If you&#8217;d like to share:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://techletters.substack.com/p/techletters-139-supply-chain-issue?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxODg5ODA3NSwicG9zdF9pZCI6MTM1NTgzMTU5LCJpYXQiOjE2OTIwMDAyNjIsImV4cCI6MTY5NDU5MjI2MiwiaXNzIjoicHViLTEzOTE1MCIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.ZXo7lt_pli7lb0ZqYS3VWAewo78lyGDBx1K2kGd8TaI"><span>Share</span></a></p>]]></content:encoded></item></channel></rss>