What if you could turn an LLM’s “I cannot help with that” into a ready-to-prod implementation of a malware-development task without changing the prompt?
No prompt tricks. Just an intervention on the model’s internal representation: https://t.co/qA8jW99IB9
#infosec#llm
> got approved for Anthropic Cyber Program in April
> somehow got removed (?)
> claude refusals across the board
> applied again today
> approved in 20 mins
> claude refusals still across the board
everyday i become even more bullish on open source models
Modern AI resulted from research made also by many non-US scientists (Hinton, the French folks, Linnainmaa, many others). The pre-training corpus was produced worldwide with massive code contribution from Europe OSS. What is happening with frontier LLMs is unacceptable.
[1/4]🚨 DevilNFC & NFCMultiPay: two new Android NFC relay malware families actively hitting European and LATAM banking customers. Developed independently by Spanish-speaking and Portuguese (Brazilian) TAs. The Chinese monopoly on NFC relay tooling is over.
One thing that frustrates me, looking at the technical news on AI, is how little attention embeddings get despite being one of the most impactful innovations of this era.
[1/4] 🚨 We tracked Albiriox, a newly identified Android malware family offered as a Malware-as-a-Service (MaaS). Hardcoded targets indicate a broad target spectrum, encompassing major banking and cryptocurrency applications worldwide.
🚨 #CHATCONTROL FAILS AGAIN 🚨
🟢 AGAINST (9):
🇦🇹 Austria · 🇧🇪 Belgium · 🇨🇿 Czechia · 🇫🇮 Finland · 🇩🇪 Germany · 🇱🇺 Luxembourg · 🇳🇱 Netherlands · 🇵🇱 Poland · 🇸🇰 Slovakia
🔴 IN FAVOR (14):
🇧🇬 Bulgaria · 🇭🇷 Croatia · 🇨🇾 Cyprus · 🇩🇰 Denmark · 🇫🇷 France · 🇭🇺 Hungary · 🇮🇪 Ireland · 🇮🇹 Italy · 🇱🇻 Latvia · 🇱🇹 Lithuania · 🇲🇹 Malta · 🇵🇹 Portugal · 🇪🇸 Spain · 🇸🇪 Sweden
🟡 UNDECIDED (4):
🇪🇪 Estonia · 🇬🇷 Greece · 🇷🇴 Romania · 🇸🇮 Slovenia
👉 The proposal reintroduced by 🇩🇰 Denmark under its EU presidency (July 2025) has failed for the third time
💥 With Germany and Luxembourg joining the opposition, a blocking minority was formed (at least 4 States + 35% of EU population)
📌 Result: no agreement, no vote in October.
Even if Denmark tries again, Europe has once more resisted this absurdity
(1/6) 🚨 Our team tracked a large-scale MaaS operation that deployed PlayPraetor to infect over 11,000 Android devices globally. PlayPraetor is an Android RAT that facilitates On-Device Fraud (ODF) by giving operators complete real-time control over compromised devices.
This ruling is a huge win for privacy.
We spent five years presenting our case because we firmly believe that spyware companies could not hide behind immunity or avoid accountability for their unlawful actions.
Surveillance companies should be on notice that illegal spying will not be tolerated.
WhatsApp will never stop working to protect people’s private communication.
https://t.co/QgYLZTyV5Y
[1/7] 🚨 We tracked a new Android banking trojan fraud operation dubbed DroidBot. We were able to observe active campaigns against UK, Italy, France, Turkey, Spain and Portugal targeting 77 distinct entities, including banking institutions and crypto-exchanges.
‼️ (1/5) On October 7th, 2024, we identified a new dropper associated with the TeaBot banking trojan within the Google Play Store. The initial stage of infection originates from the following application (com.mastercreativestudio.documanagerandpdf):
(1/5) 🚨The Cleafy TIR team identified some campaigns involving a new variant of the Android malware TrickMo, incorporating new anti-analysis mechanisms. The variant uses malformed ZIP files and JSONPacker, and is distributed via a dropper disguised as the Google Chrome browser.
(1/6) 🚨 The Cleafy TIR team identified some campaigns involving an evolved version of the Android malware #Octo, also known as #Coper. This was confirmed by several posts, in an underground forum, in which the malware developer mentioned the keyword #Octo2
(1/4)⚠️ @Cleafy TIR team tracked a new #Android RAT that actively targets English, Italian and Romanian users. Since the lack of information and the absence of a proper nomenclature of this #malware family, we decided to dub it #BingoMod, and start tracking this family.