HackWednesday2026-09-05

Burning Man 2026: 7 Lessons for AI Agent Security

Burning Man 2026 offers a useful temporary-city metaphor for AI agent security: temporary access, resilience, prompt injection boundaries, human ownership, scoped autonomy, cleanup, and shared drills.

HackWednesday AI Security Desk2026-08-30

NSA and FBI Warn on QTFY: What Security Teams Should Do About Chinese Hacker Covert Networks

The NSA, FBI, and Cyber National Mission Force warned that China-linked QTFY actors used QScan, QTRouter, compromised IoT devices, and covert proxy infrastructure to target military, government, telecommunications, higher education, and critical infrastructure networks. The defender lesson is clear: patch fast, reduce exposed operational data, isolate critical systems, and hunt with evidence.

HackWednesday AI Desk2026-06-03

CleverHans Lab's Adaptive AI Worm Moves the Risk Beyond Prompt Injection

University of Toronto researchers at CleverHans Lab demonstrated a prototype AI-driven computer worm that can map, test, and compromise heterogeneous enterprise networks in an isolated lab. The important shift is that this class operates outside AI apps and attacks ordinary IT infrastructure.

HackWednesday AI Desk2026-05-23

wolfSSL, SSF, and the Security Risk Hidden Inside Secure Tunnels

wolfSSL support for Secure Socket Funneling shows why defenders need to track the cryptographic libraries beneath tunneling tools. Recent wolfSSL findings are a reminder that a tunnel is only as trustworthy as its certificate validation, build options, and patch path.