Sponsor of the Day:
Jerkmate
https://arstechnica.com/information-technology/2024/12/new-badram-attack-neuters-security-assurances-in-amd-epyc-processors/
AMD’s trusted execution environment blown wide open by new BadRAM attack - Ars Technica
Dec 10, 2024 - Attack bypasses AMD protection promising security, even when a server is compromised.
trusted execution environmentattack ars technicawide openblownnew
https://arstechnica.com/gadgets/2018/08/intels-sgx-blown-wide-open-by-you-guessed-it-a-speculative-execution-attack/
Intel’s SGX blown wide open by, you guessed it, a speculative execution attack - Ars Technica
Nov 9, 2020 - Speculative execution attacks truly are the gift that keeps on giving.
speculative execution attackwide openars technicasgxblown
https://arstechnica.com/security/2026/03/widely-used-trivy-scanner-compromised-in-ongoing-supply-chain-attack/
Widely used Trivy scanner compromised in ongoing supply-chain attack - Ars Technica
Mar 20, 2026 - Admins: Sorry to say, but it's likely a rotate-your-secrets kind of weekend.
supply chain attackwidely usedars technicatrivyscanner
https://arstechnica.com/information-technology/2015/06/airplanes-grounded-in-poland-after-hackers-attack-flight-plan-computer/
Airplanes grounded in Poland after hackers allegedly attack flight plan computer - Ars Technica
Dec 1, 2017 - The source of the attack isn't known. Airplanes in the air weren't affected.
computer ars technicaflight planairplanesgroundedpoland
https://arstechnica.com/security/2026/03/supply-chain-attack-using-invisible-code-hits-github-and-other-repositories/
Supply-chain attack using invisible code hits GitHub and other repositories - Ars Technica
Mar 16, 2026 - Unicode that's invisible to the human eye was largely abandoned—until attackers took notice.
supply chain attackars technicausinginvisiblecode
https://arstechnica.com/information-technology/2015/03/massive-denial-of-service-attack-on-github-tied-to-chinese-government/
Massive denial-of-service attack on GitHub tied to Chinese government - Ars Technica
Apr 2, 2015 - Reports: Millions of innocent Internet users conscripted into Chinese DDoS army.
service attackchinese governmentars technicamassivedenial
https://arstechnica.com/security/2026/01/a-single-click-mounted-a-covert-multistage-attack-against-copilot/
A single click mounted a covert, multistage attack against Copilot - Ars Technica
Jan 15, 2026 - Exploit exfiltrating data from chat histories worked even after users closed chat windows.
ars technicasinglemountedcovertmultistage
https://arstechnica.com/google/2025/08/researchers-use-calendar-events-to-hack-gemini-control-smart-home-gadgets/
Researchers design “promptware” attack with Google Calendar to turn Gemini evil - Ars Technica
Aug 6, 2025 - The team behind the research has worked with Google to mitigate the attack, but what comes next?
researchers designgoogle calendarars technicaattackturn
https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/
New AirSnitch attack bypasses Wi-Fi encryption in homes, offices, and enterprises - Ars Technica
Feb 27, 2026 - That guest network you set up for your neighbors may not be as secure as you think.
wi fihomes officesars technicanewairsnitch
https://arstechnica.com/information-technology/2023/02/ai-powered-bing-chat-spills-its-secrets-via-prompt-injection-attack/
AI-powered Bing Chat spills its secrets via prompt injection attack [Updated] - Ars Technica
prompt injection attackupdated ars technicaai poweredbing chatsecrets via
https://arstechnica.com/security/2025/11/researchers-question-anthropic-claim-that-ai-assisted-attack-was-90-autonomous/
Researchers question Anthropic claim that AI-assisted attack was 90% autonomous - Ars Technica
Nov 14, 2025 - The results of AI-assisted hacking aren't as impressive as many might have us believe.
ai assistedars technicaresearchersquestionanthropic