CARVIEW |
Select Language
HTTP/2 200
server: nginx
date: Thu, 09 Oct 2025 10:00:25 GMT
content-type: text/html; charset=UTF-8
strict-transport-security: max-age=31536000
vary: Accept-Encoding
last-modified: Thu, 09 Oct 2025 09:59:11 GMT
cache-control: max-age=227, must-revalidate
x-nananana: Batcache-Hit
host-header: wpcloud
vary: Cookie
link: ; rel="https://api.w.org/"
link: ; rel="alternate"; title="JSON"; type="application/json"
link: ; rel=shortlink
content-encoding: gzip
x-ac: 3.bom _atomic_dca MISS
alt-svc: h3=":443"; ma=86400
server-timing: a8c-cdn, dc;desc=bom, cache;desc=MISS;dur=840.0
Crypto-Gram Newsletter - Schneier on Security
Crypto-Gram Newsletter
Crypto-Gram is a free monthly e-mail digest of posts from Bruce Schneier’s Schneier on Security blog.
Recent Issues
September 15, 2025
In this issue:
- Trojans Embedded in .svg Files
- Eavesdropping on Phone Conversations Through Vibrations
- Zero-Day Exploit in WinRAR File
- Subverting AIOps Systems Through Poisoned Input Data
- Jim Sanborn Is Auctioning Off the Solution to Part Four of the Kryptos Sculpture
- AI Agents Need Data Integrity
- I’m Spending the Year at the Munk School
- Poor Password Choices
- Encryption Backdoor in Military/Police Radios
- We Are Still Unable to Secure LLMs from Malicious Inputs
- The UK May Be Dropping Its Backdoor Mandate
- Baggage Tag Scam
- 1965 Cryptanalysis Training Workbook Released by the NSA
- Indirect Prompt Injection Attacks Against LLM Assistants
- Generative AI as a Cybercrime Assistant
- GPT-4o-mini Falls for Psychological Manipulation
- My Latest Book: Rewiring Democracy
- AI in Government
- Signed Copies of Rewiring Democracy
- New Cryptanalysis of the Fiat-Shamir Protocol
- A Cyberattack Victim Notification Framework
- Upcoming Speaking Engagements
August 15, 2025
In this issue:
- Report from the Cambridge Cybercrime Conference
- Hacking Trains
- Security Vulnerabilities in ICEBlock
- New Mobile Phone Forensics Tool
- Another Supply Chain Vulnerability
- "Encryption Backdoors and the Fourth Amendment"
- Google Sues the Badbox Botnet Operators
- How the Solid Protocol Restores Digital Agency
- Subliminal Learning in AIs
- Microsoft SharePoint Zero-Day
- That Time Tom Lehrer Pranked the NSA
- Aeroflot Hacked
- Measuring the Attack/Defense Balance
- Cheating on Quantum Computing Benchmarks
- Spying on People Through Airportr Luggage Delivery Service
- First Sentencing in Scheme to Help North Koreans Infiltrate US Companies
- Surveilling Your Children with AirTags
- The Semiconductor Industry and Regulatory Compliance
- China Accuses Nvidia of Putting Backdoors into Their Chips
- Google Project Zero Changes Its Disclosure Policy
- Automatic License Plate Readers Are Coming to Schools
- The "Incriminating Video" Scam
- SIGINT During World War II
- AI Applications in Cybersecurity
- LLM Coding Integrity Breach
July 15, 2025
In this issue:
- Where AI Provides Value
- Ghostwriting Scam
- Self-Driving Car Video Footage
- Surveillance in the US
- Largest DDoS Attack to Date
- Here’s a Subliminal Channel You Haven’t Considered Before
- What LLMs Know About Their Users
- House of Representatives Bans WhatsApp
- The Age of Integrity
- How Cybersecurity Fears Affect Confidence in Voting Systems
- Iranian Blackout Affected Misinformation Campaigns
- Ubuntu Disables Spectre/Meltdown Protections
- Surveillance Used by a Drug Cartel
- Hiding Prompt Injections in Academic Papers
- Yet Another Strava Privacy Leak
- Using Signal Groups for Activism
- Tradecraft in the Information Age
Sidebar photo of Bruce Schneier by Joe MacInnis.