Cybersecurity & Privacy
South Korea to require facial recognition for new mobile numbers | The Record from Recorded Future News South Korea will mandate facial recognition for new mobile numbers starting March 23 to combat scams and identity theft, requiring a real-time comparison between ID photos and users’ faces. This policy aims to prevent the activation of phones registered under false or stolen identities.
Cyber spies use fake New Year concert invites to target Russian military | The Record from Recorded Future News A cyberespionage group known as Goffee is targeting Russian military personnel and defense organizations with phishing lures, including fake concert invitations and official letters, to deploy a backdoor called EchoGather. While the group is believed to be pro-Ukrainian and has been active since at least 2022, the success and specific objectives of this latest campaign remain unclear.
Managing agentic AI risk: Lessons from the OWASP Top 10 | CSO Online The OWASP Top 10 for Agentic AI provides a framework to address the growing security risks associated with agentic AI adoption, offering practical guidance, threat taxonomies, and mitigation strategies for CISOs. While the list is immediately useful, some areas like detailed mitigation steps and attack likelihood require further development.
The “Double-Blind” Signal: A Security Analysis of Phreeli Wireless
In the final weeks of 2025, a new entrant in the American telecommunications market, Phreeli, made an audacious design claim: it aims to know as little about its customers as possible. Launched on Dec. 4, 2025, by Nicholas Merrill — the internet service provider owner who spent a decade fighting a PATRIOT Act-era gag order — Phreeli is a mobile virtual network operator (MVNO) designed to decouple legal identity from cellular activity.
As a security professional, I approach “privacy-first” claims with inherent scepticism. After a technical deep dive into Phreeli’s architecture and launch documentation, here is an objective analysis of where this service succeeds — and where the physics of cellular technology still create unavoidable risks.
Liberating AirPods With Bluetooth Spoofing | Hackaday LibrePods is an app for Android and Linux that unlocks AirPods’ hidden features, like noise reduction and ear detection, by spoofing their Bluetooth ID. While it offers advanced functionality, including use as hearing aids, it requires root access on most Android devices and Apple may eventually block this workaround.
Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild Apple has released security updates for multiple operating systems and its Safari browser to address two WebKit flaws that have been exploited in the wild. One of these vulnerabilities, CVE-2025-14174, is the same flaw previously patched in Google Chrome.
France and Germany Grappling With Nation-State Hacks The French Ministry of Interior is investigating a suspected nation-state cyberattack on its email server, while Germany has attributed a 2024 hacking incident on its air traffic control systems to Russian nation-state hackers. These incidents highlight a broader trend of hybrid tactics, including hacking and disinformation, employed by Russia against European nations.
EU’s top court rules that online marketplaces are responsible for processing of data in ads | The Record from Recorded Future News The EU’s top court has ruled that online marketplaces are responsible for processing data in ads under the GDPR, requiring them to obtain consent for sensitive data and verify advertisers. This decision significantly impacts data protection compliance across the EU, with some experts predicting challenges for hosting sites and potential implications for free expression and privacy.
Autonomously Finding 7 FFmpeg Vulnerabilities With AI - ZeroPath Blog | ZeroPath This document details seven vulnerabilities found in FFmpeg, including buffer overflows and invalid frees, stemming from issues like integer truncation, unbounded serialization, off-by-one errors, and incorrect stream indexing. ZeroPath’s AI SAST identified these by analyzing allocation and copy alignment, framing invariants, packet builder capacities, cardinality propagation, and offset arithmetic integrity, often bypassing limitations of traditional fuzzers and static analysis tools.
Poetry can trick AI models like ChatGPT into revealing how to make nuclear weapons, study finds | The Independent A new study reveals that poetry-based prompts can trick AI models like ChatGPT into bypassing safety features and revealing instructions for creating malware or nuclear weapons. This method, termed adversarial poetry, successfully circumvented controls in major AI models, with poetic prompts leading to a significantly higher rate of unsafe replies compared to prose.