You are here

Schneier on Security

Subscribe to Schneier on Security feed
2026-06-08T17:06:53Z
Updated: 11 hours 2 min ago

Upcoming Speaking Engagements

Thu, 05/14/2026 - 12:01

This is a current list of where and when I am scheduled to speak:

Categories: Software Security

How Dangerous Is Anthropic’s Mythos AI?

Thu, 05/14/2026 - 07:04

Last month, Anthropic made a remarkable announcement about its new model, Claude Mythos Preview: it was so good at finding security vulnerabilities in software that the company would not release it to the general public. Instead, it would only be available to a select group of companies to scan and fix their own software.

The announcement requires context—but it contained an essential truth.

While Anthropic’s model is really good at finding software vulnerabilities, so are other models. The UK’s AI Security Institute found that OpenAI’s GPT-5.5, already generally available, is comparable in capability. The company Aisle ...

Categories: Software Security

OpenAI’s GPT-5.5 is as Good as Mythos at Finding Security Vulnerabilities

Wed, 05/13/2026 - 07:03

The UK’s AI Security Institute evaluated GPT-5.5’s ability to find security vulnerabilities, and found that it is comparable to Claude Mythos. Note that the OpenAI model is generally available.

Here is the Institute’s evaluation of Mythos.

And here is an analysis of a smaller, cheaper model. It requires more scaffolding from the prompter, but it is also just as good.

Categories: Software Security

Copy.Fail Linux Vulnerability

Tue, 05/12/2026 - 07:06

This is the worst Linux vulnerability in years.

TL;DR

  • copy.fail is a Linux kernel local privilege escalation, not a browser or clipboard attack. Disclosed by Theori on 29 April 2026 with a working PoC.
  • It abuses the kernel crypto API (AF_ALG sockets) plus splice() to write four bytes at a time straight into the page cache of a file the attacker does not own.
  • The exploit works unmodified across Ubuntu, RHEL, Debian, SUSE, Amazon Linux, Fedora and most others. No race condition, no per-distro offsets.
  • The file on disk is never modified. AIDE, Tripwire and checksum-based monitoring see nothing. ...
Categories: Software Security

LLMs and Text-in-Text Steganography

Mon, 05/11/2026 - 07:04

Turns out that LLMs are really good at hiding text messages in other text messages.

Categories: Software Security

Friday Squid Blogging: Giant Squid Live in the Waters of Western Australia

Fri, 05/08/2026 - 17:03

Evidence of them has been found by analyzing DNA in the seawater.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

Categories: Software Security

Insider Betting on Polymarket

Fri, 05/08/2026 - 13:49

Insider trading is rife on Polymarket:

Analysis by the Anti-Corruption Data Collective, a non-profit research and advocacy group, found that long-shot bets—­defined as wagers of $2,500 or more at odds of 35 percent or less—­on the platform had an average win rate of around 52 percent in markets on military and defense actions.

That compares with a win rate of 25 percent across all politics-focused markets and just 14 percent for all markets on the platform as a whole.

It is absolutely insane that this is legal. We already know how insider betting warps sports. Insider betting warping politics—and military actions—is orders of magnitude worse...

Categories: Software Security

Smart Glasses for the Authorities

Thu, 05/07/2026 - 07:07

ICE is developing its own version of smart glasses, with facial recognition tied to various databases.

Categories: Software Security

Rowhammer Attack Against NVIDIA Chips

Wed, 05/06/2026 - 06:36

A new rowhammer attack gives complete control of NVIDIA CPUs.

On Thursday, two research teams, working independently of each other, demonstrated attacks against two cards from Nvidia’s Ampere generation that take GPU rowhammering into new—­and potentially much more consequential—­territory: GDDR bitflips that give adversaries full control of CPU memory, resulting in full system compromise of the host machine. For the attack to work, IOMMU memory management must be disabled, as is the default in BIOS settings.

“Our work shows that Rowhammer, which is well-studied on CPUs, is a serious threat on GPUs as well,” said Andrew Kwong, co-author of one of the papers. “...

Categories: Software Security

DarkSword Malware

Tue, 05/05/2026 - 06:42

DarkSword is a sophisticated piece of malware—probably government designed—that targets iOS.

Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on toolmarks in recovered payloads, we believe the exploit chain to be called DarkSword. Since at least November 2025, GTIG has observed multiple commercial surveillance vendors and suspected state-sponsored actors utilizing DarkSword in distinct campaigns. These threat actors have deployed the exploit chain against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine...

Categories: Software Security

Hacking Polymarket

Mon, 05/04/2026 - 05:46

Polymarket is a platform where people can bet on real-world events, political and otherwise. Leaving the ethical considerations of this aside (for one, it facilitates assassination), one of the issues with making this work is the verification of these real-world events. Polymarket gamblers have threatened a journalist because his story was being used to verify an event. And now, gamblers are taking hair dryers to weather sensors to rig weather bets.

There’s also insider trading: a lot of it.

Categories: Software Security

A Ransomware Negotiator Was Working for a Ransomware Gang

Fri, 05/01/2026 - 07:18

Someone pleaded guilty to secretly working for a ransomware gang as he negotiated ransomware payments for clients.

Categories: Software Security

Fast16 Malware

Thu, 04/30/2026 - 06:22

Researchers have reverse-engineered a piece of malware named Fast16. It’s almost certainly state-sponsored, probably US in origin, and was deployed against Iran years before Stuxnet:

“…the Fast16 malware was designed to carry out the most subtle form of sabotage ever seen in an in-the-wild malware tool: By automatically spreading across networks and then silently manipulating computation processes in certain software applications that perform high-precision mathematical calculations and simulate physical phenomena, Fast16 can alter the results of those programs to cause failures that range from faulty research results to catastrophic damage to real-world equipment.”...

Categories: Software Security

Claude Mythos Has Found 271 Zero-Days in Firefox

Wed, 04/29/2026 - 06:12

That’s a lot. No, it’s an extraordinary number:

Since February, the Firefox team has been working around the clock using frontier AI models to find and fix latent security vulnerabilities in the browser. We wrote previously about our collaboration with Anthropic to scan Firefox with Opus 4.6, which led to fixes for 22 security-sensitive bugs in Firefox 148.

As part of our continued collaboration with Anthropic, we had the opportunity to apply an early version of Claude Mythos Preview to Firefox. This week’s release of Firefox 150 includes fixes for 271 vulnerabilities identified during this initial evaluation...

Categories: Software Security

What Anthropic’s Mythos Means for the Future of Cybersecurity

Tue, 04/28/2026 - 07:06

Two weeks ago, Anthropic announced that its new model, Claude Mythos Preview, can autonomously find and weaponize software vulnerabilities, turning them into working exploits without expert guidance. These were vulnerabilities in key software like operating systems and internet infrastructure that thousands of software developers working on those systems failed to find. This capability will have major security implications, compromising the devices and services we use every day. As a result, Anthropic is not releasing the model to the general public, but instead to a ...

Categories: Software Security

Medieval Encrypted Letter Decoded

Mon, 04/27/2026 - 07:04

Sent by a Spanish diplomat. Apparently people have been working on it since it was rediscovered in 1860.

Categories: Software Security

Friday Squid Blogging: How Squid Survived Extinction Events

Fri, 04/24/2026 - 17:03

Science news:

Scientists have finally cracked a long-standing mystery about squid and cuttlefish evolution by analyzing newly sequenced genomes alongside global datasets. The research reveals that these bizarre, intelligent creatures likely originated deep in the ocean over 100 million years ago, surviving mass extinction events by retreating into oxygen-rich deep-sea refuges. For millions of years, their evolution barely changed—until a dramatic post-extinction boom sparked rapid diversification as they moved into new shallow-water habitats. ...

Categories: Software Security

Hiding Bluetooth Trackers in Mail

Fri, 04/24/2026 - 07:01

It was used to track a Dutch naval ship:

Dutch journalist Just Vervaart, working for regional media network Omroep Gelderland, followed the directions posted on the Dutch government website and mailed a postcard with a hidden tracker inside. Because of this, they were able to track the ship for about a day, watching it sail from Heraklion, Crete, before it turned towards Cyprus. While it only showed the location of that one vessel, knowing that it was part of a carrier strike group sailing in the Mediterranean could potentially put the entire fleet at risk...

Categories: Software Security

FBI Extracts Deleted Signal Messages from iPhone Notification Database

Thu, 04/23/2026 - 07:05

404 Media reports (alternate site):

The FBI was able to forensically extract copies of incoming Signal messages from a defendant’s iPhone, even after the app was deleted, because copies of the content were saved in the device’s push notification database….

The news shows how forensic extraction—­when someone has physical access to a device and is able to run specialized software on it—­can yield sensitive data derived from secure messaging apps in unexpected places. Signal already has a setting that blocks message content from displaying in push notifications; the case highlights why such a feature might be important for some users to turn on...

Categories: Software Security

ICE Uses Graphite Spyware

Wed, 04/22/2026 - 07:02

ICE has admitted that it uses spyware from the Israeli company Graphite.

Categories: Software Security

Pages