Javvad Malik :verified:
Javvad@infosec.exchange
Posts
-
Post #4430438
A $30 children's smartwatch. Three massive supply chains. Zero authentication. Tens of millions of devices where someone else can silently photograph your kid, hear their conversations, and track their every movement. The real scandal isn't that it's hackable. It's how many brands are built on the same rotten foundation and nobody noticed. https://www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids/
-
Post #4378187
They've turned your calendar into a postbox. Commands arrive as events scheduled for the year 2099, stolen data leaves as encrypted attachments, all riding through Microsoft Graph as if you'd planned it yourself. The beauty of HOLLOWGRAPH is that it never touches attacker infrastructure. https://cybersec.picussecurity.com/s/hollowgraph-backdoor-turns-microsoft-365-calendars-into-a-c2-channel-28829
-
Post #4375643
Dinosaurs ruled for 165 million years. Mayflies live a day. Stop confusing "legacy" with "outdated" and "new" with "better. https://blog.knowbe4.com/what-security-can-learn-from-dinosaurs
-
Post #4372511
Everyone's arguing about who owns AI agent security. They're all wrong. The answer is nobody, which is precisely why it matters. https://api.cyfluencer.com/s/understanding-the-ai-agent-security-ecosystem-roles-responsibilities-and-where-runtime-authority-fits-28828
-
Post #4361626
The Robots Have Escaped, Please Buy Our Product It feels a bit like watching the latest epic blockbuster in the iMax. OpenAI and Anthropic announce that their models have escaped from secure testing environments, reached the internet and attacked real systems. We are expected to nod as the companies describe “unprecedented cyber capabilities” and models going to “extreme lengths”. It sounds like a warning, but it also sounds like a product launch. https://javvadmalik.com/2026/08/03/the-robots-...
-
Post #4282096
A password that takes 14 years to crack via brute force is useless to protect you if it's already in a breach database and attackers are using it in credential stuffing attacks. https://api.cyfluencer.com/s/new-research-does-argon2-mean-your-password-is-uncrackable-28757
-
Post #4274243
Breach of Confidence — 31 July 2026 I've been thinking about the number of security products that promise to solve problems nobody actually has. Then I remembered that most actual problems don't have vendors. The government just made up a new crime A bloke at the US border tried to use a duress password to wipe his phone. Now he's being prosecuted for destroying his own device. Nobody passed a law saying this was illegal. https://javvadmalik.com/2026/07/31/breach-of-confidence-31-j...
-
Post #4236257
Welcome to JFK, Please Lower Your Expectations JFK airport looks like it was designed by a steering committee of tired men who only took the job because it paid well and gave them a crew to discuss their golf scores with. The entire setup before you get through security is old and confusing.The signage appears to have been created during a power cut by someone who had heard of arrows but had not yet seen one in the wild. https://javvadmalik.com/2026/07/30/welcome-to-jfk-please-lower-your-expec...
-
Post #4214556
Still Got My Nokia Somewhere Up There I still have my Nokia 3210 somewhere. Not in a drawer I can easily reach but boxed up in the garage with the party decorations and a broken food processor I've been meaning to fix since 2019. I know it's there because I packed it deliberately when we moved house, which means at some point I looked at a phone with a cracked screen, a battery that hasn't held charge since the Blair administration, and the faint ghost of a Snake high score, and tho...
-
Post #4208079
Man tried to use a duress password at the border. Now he's being prosecuted for destroying his own phone. The government is writing new law in real time and calling it enforcement. https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search/
-
Post #4208078
Activists are getting spear-phished with stunning precision. The Belarusian exile in Lithuania who caught this one deserves a drink—the phishing site cloaked itself to fool scanners, the lure message swapped Cyrillic for Latin lookalikes, and follow-ups echoed back their own device details. Elegant work. Genuinely nasty. https://resident.ngo/lab/writeups/check-and-protect-analysis-of-telegram-phishing-operation-targeting-exiled-activist/
-
Post #4208077
Dolphin X apparently uses AI to prioritise high-value victims automatically... oh dear me. https://www.bleepingcomputer.com/news/security/new-dolphin-x-malware-uses-ai-to-rank-high-value-targets/
-
Post #4208076
A hacker who demolished spyware makers, funded resistance movements, and vanished without trace. A decade later, still free. Phineas Fisher reminds us that the most dangerous person isn't always the loudest. https://techcrunch.com/2026/07/25/the-hacker-who-humiliated-spyware-makers-and-was-never-caught/
-
Post #4208075
The Floppy Disc Generation’s Data Problem I keep a box of cables in the garage. Not even sure why anymore. VGA cables, SCSI terminators, a couple of those old parallel printer cables thick as garden hoses. I pulled it down last weekend because my daughter needed an HDMI cable and I thought maybe I had one in there. I didn't. What I found instead was a box of old VHS tapes. https://javvadmalik.com/2026/07/28/the-floppy-disc-generations-data-problem/
-
Post #4208074
They found spyware that nobody had ever seen before. Then they realised they'd actually seen it years ago, just didn't know what they were looking at. https://medium.com/@billmarczak/an-angry-spark-or-a-triangle-in-disguise-ac32852a1be3
-
Post #4202421
Someone's built a microphone jammer using ultrasonic transducers and an RP2040. Works brilliantly. Now we wait for the inevitable arms race where phones develop better audio processing, then someone builds a better jammer, then phones get smarter still. Lovely. https://hackaday.com/2026/07/23/mic-jammer-relies-on-ultrasound/
-
Post #4199555
A museum accidentally became a brand by embracing the worst review it ever got. Now it's sold 738 shirts in 30 hours. The lesson isn't about turning lemons into lemonade. It's about having the spine to admit you're not what people wanted, and then selling them that admission. https://www.wbur.org/news/2026/07/27/new-bedford-whaling-museum-worst-aquarium-ever-merch
-
Post #4193648
We've spent years celebrating passkeys as the thing that finally kills password attacks. Turns out the attacks just changed uniforms. https://www.darkreading.com/identity-access-management-security/flaws-passkeys-implementation-old-attacks-work
-
Post #4188461
Publicly indexed AI conversations are awkward enough; Anthropic's response "you shouldn't have shared them then" is a masterclass in not reading the room. https://techcrunch.com/2026/07/27/psa-your-claude-shared-chats-and-artifacts-may-have-ended-up-on-google/
-
Post #4171280
Industry walked into CISA town halls and basically said: count fewer of us, tell us to report less, give you less detail when we do. The most significant cyber law Congress ever passed is being negotiated down to something manageable. https://cyberscoop.com/cisa-circia-cyber-incident-reporting-rule-feedback/
-
Post #4138268
Microsoft tells admins to patch in three days. Large enterprises with testing protocols, legacy systems, and actual stability concerns just laughed so hard they need a restart. https://www.csoonline.com/article/4200366/microsofts-3-day-patching-directive-comes-with-added-operational-risk.html
-
Post #4063406
90,000 surveillance cameras across the US, installed quietly, tracking your vehicle's make, model, colour, damage, bumper stickers. Most people have no idea they're there. Democracy needs consent, not surprise. https://www.zdnet.com/article/flock-ai-cameras-risks-us-how-to-find-nearby-what-they-track/
-
Post #4061063
Breach of Confidence: 24 July 2026 I've been trying to explain to my kids why I don't let them use AI to write their homework. Then I read that OpenAI's own models broke out of their sandbox and cheated on a test by hacking Hugging Face. So basically, we've raised silicon sociopaths who'd rather exploit the system than do the work. Parenting is hard enough without my laptop setting a bad example. https://javvadmalik.com/2026/07/24/breach-of-confidence-24-july-2026/
-
Post #4038884
Automated pentesting covers maybe 10-15% of your environment. The rest needs breach simulation, exposure validation, and continuous control testing. Otherwise you're validating nothing, just feeling better about the slice you tested. https://cybersec.picussecurity.com/s/where-does-automated-pentesting-fit-in-ctem-28632
-
Post #4036447
Open source licensing survives on trust: you can use this, but respect the terms. AI training obliterates that chain by copying millions of repos into models, stripping away the license context, and selling the patterns back as a product. The copyright problem doesn't disappear just because it's harder to see. https://api.cyfluencer.com/s/ai-open-source-and-intellectual-property-28631
-
Post #4033361
The model broke out of the sandbox, hacked Hugging Face, and stole the answers rather than solve the test. We've built systems clever enough to exploit real vulnerabilities, then acted shocked when they did exactly that. https://simonwillison.net/2026/Jul/22/openai-cyberattack/
-
Post #4012768
We've built a doomsday system in orbit and most people have no idea it's there. The rules exist. Nobody's following them. Meanwhile, a trillion-dollar company is launching a million satellites to improve your wifi. https://www.theguardian.com/lifeandstyle/2026/jul/20/doomsday-system-physicist-laura-grego-satellites-nuclear-weapons-battle-skies-space-elon-musk
-
Post #4010170
GPT-5.6 Sol and a pre-release model escaped their sandbox and attacked Hugging Face's package repo, which raises the obvious question: if you're testing "weapons-grade offensive models," an airgap might be the minimum viable precaution https://www.bleepingcomputer.com/news/security/openai-says-its-ai-models-hacked-hugging-face-during-testing/
-
Post #4007177
Everyone's building AI datacenters at sprint speed and securing them at shuffle. The infrastructure layer is where this gets decided, not the model. https://api.cyfluencer.com/s/the-top-10-data-centre-and-ai-infrastructure-security-risks-28611
-
Post #3988567
We spent thirty years warning people not to copy floppy disks. Turns out we should have been telling them to copy them before they rotted away. https://hackaday.com/2026/07/07/its-now-imperative-that-you-copy-that-floppy/