The Latest

The chart is interesting.

On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated. Opus 5 also outperformed all non-Claude models on this benchmark. The most robust non-Claude model was Muse Spark at 16.5% within 15 attempts—more than eight times Opus 5’s rate. The most capable GPT 5.6 variant, Sol, was comparable to its predecessor GPT 5.5 (20.0% versus 20.8% within 15 attempts), and was 10 times as likely to be successfully attacked as Claude Opus 5 at 2.0%. The other GPT 5.6 variants are less robust, at 30.4% (Terra) and 43.9% (Luna). A single attempt against GPT 5.6 Sol succeeded 3.1% of the time, higher than the 2.0% an attacker achieved against Opus 5 after fifteen attempts.

We know that preventing prompt injection is impossible in the general case. But we are getting much better at blocking it in specific cases.


from Schneier on Security https://ift.tt/dFLN5Ma

We may earn a commission from links on this page.

Gilmore Girls is pure comfort viewing. We all wish our lives were filled with more sparkling, quick-witted dialogue spiced with deep pop culture references, and that we lived in a warm, quirky place like Stars Hollow—and that’s why it’s one of those shows that folks binge over and over again. It’s like getting together with some old friends—it never gets old. But true fans know that to keep up with the Gilmores, you have to absorb a lot of pop culture. If you’ve already watched the shows that fans of Gilmore Girls will love, it’s time to hop over to the movies that Rory and Lorelai would approve for movie night.

Why fans of Gilmore Girls should watch Mermaids

Mermaids is set in the 1960s, but the similarities with Gilmore Girls are strong. Winona Ryder plays Charlotte, a 15-year-old whose mother, Rachel (Cher), has a habit of moving to a new town every time she breaks up with a boyfriend. Adding to Charlotte’s growing sense of disruption is the fact that Rachel, who had Charlotte when she was just 16 herself, acts like her friend instead of her mother. When Rachel moves with Charlotte and her younger sister, Kate (Christina Ricci), to the small town of Eastport, Massachusetts, things begin to change.

If you loved the dynamic between Rory and Lorelai on Gilmore Girls, you’ll love Charlotte and Rachel. The show is pitched a little higher on the drama scale, but the funny, sharp dialogue between the women and the deep love between them is very Gilmore-esque. Like Rory, Charlotte is precocious and smart, though she’s a bit more prone to fantasy; despite being Jewish, she becomes obsessed with Catholicism, which causes her a lot of distress when she crushes on the local convent’s caretaker, Joe. And like Lorelai, Rachel is a strong woman who finds love in a small town without sacrificing her sense of self and independence. Their comic timing is flawless in this film.

That small-town, East Coast vibe in Eastport will also appeal to fans of the show. Eastport is depicted as a vibrant, tight-knit place where the locals are kind and weird in the best ways. When Rachel meets Lou (Bob Hoskins), the local shoe salesman, she resists falling in love for fear of losing her independence, but their blooming relationship is sweet and satisfying, and the town is populated by memorable characters just like Stars Hollow.

If you’re looking for banter, romance, and a town you wish you lived in just like Gilmore Girls, go watch Mermaids.

Stream Mermaids on Fubo or rent it on Prime Video.

More movies for fans of Gilmore Girls

Mermaids is terrific, but it’s not quite two hours long—so you’re going to need to add more movies to your list. Here are a few more that Gilmore Girls fans will love.

His Girl Friday (1940)

One of the many films directly name-checked in Gilmore Girls, His Girl Friday is way ahead of its time and the perfect match. The story, about a newspaper editor (Cary Grant) using a variety of shady (and, from a modern POV, kind of sketchy) tricks to win back the woman who is both his best reporter and his ex-wife (Rosalind Russell), is surprisingly gender-blind for a film released in 1940. And the dialogue—racking up an astounding 240 words per minute, on average—is so fast, so sharp, and so overlapping you’ll have to watch it three times to catch every joke and reference. If you come back to Gilmore Girls for the banter, you will love this movie.

Stream His Girl Friday on Fubo or Kanopy or rent it on Prime Video.

Juno (2007)

Another movie known for its sharp, rapid-delivery dialogue, Juno is also the perfect choice for Gilmore fans because of its main character, Juno MacGuff (Elliot Page). Sixteen years old and finding herself surprisingly pregnant, Juno navigates the emotional and social fallout with a sharp tongue and a bright mind that’s very much how you might imagine Rory dealing with a teen pregnancy. Juno agrees to let a childless couple (played by Jason Bateman and Jennifer Garner) adopt her baby, but as she grows closer to the husband, the film digs into complex relationship dynamics that fans of the show will appreciate.

Rent Juno on Prime Video.

Booksmart (2019)

One of the great things about Gilmore Girls is that it’s a show that celebrates intelligence and knowing things. The Gilmores and the people they surround themselves with are smart, and they enjoy being smart. So do Amy (Kaitlyn Dever) and Molly (Beanie Feldstein) in Booksmart: They’ve skipped so many parties and hangouts in order to excel at school and get into Ivy League schools, and their quick, hilarious dialogue reflects how smart they are. When they learn that their hard-partying, much lazier classmates also got into great schools, they suffer what can only be termed a mild existential crisis, with hilarious results.

Rent Booksmart on Apple TV.

Before Sunset (2004)

The Gilmores often display an enviable dynamic: relaxed, affectionate, and challenging. Rory and Lorelai like to debate, to converse, to dig into their assumptions and have real conversations—the kind we all wish we were having on the regular. If you ever wished some of those conversations in Gilmore Girls would go on for, oh, a few hours, check out Before Sunset—it’s almost all conversation. It’s the sequel to Before Sunrise (the trilogy—itself basically one enormous conversation—ends with Before Midnight), but the second film is a closer match to the deep relationship between Rory and Loralei that makes the show special. The story sees author Jesse (Ethan Hawke) reunited with CĂ©line (Julie Delpy), once again spending a day together in Paris nine years after a 24-hour conversation changed their lives, chatting in a way few people ever get to.

Stream Before Sunset on The Roku Channel or rent it on Prime Video.

Waitress (2007)

Quirky small town vibes, a loving found family, and an unplanned pregnancy—Waitress is what Rory or Lorelai’s life might have been like with some different choices or simple bad luck. Jenna Hunterson (Keri Russell) is a small-town waitress trapped in a miserable marriage; her plans to save up money and flee are complicated when she finds herself unexpectedly knocked up. She begins an affair with her new obstetrician (Nathan Fillion, so: understandable) and learns that she has more friends—and better friends—than she imagined.

Rent Waitress on Prime Video.


from Lifehacker https://ift.tt/pZOPiMx

He’s being prosecuted for giving border officials a code that wiped his phone:

The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick’s attorneys confirmed GrapheneOS was running on his phone.

The software feature allows the device owner to set a passcode that deliberately wipes the contents of that device if entered instead of the user’s unlock passcode.

Tunick’s case also raises ongoing questions about what constitutional rights can be invoked at the border, which the U.S. government has long asserted is not U.S. soil until a person is authorized to enter.

Right. And he wasn’t under arrest, either.

Three more news stories.

Graphine says that the feature is “completely legal“:

GrapheneOS is completely legal. We have no obligation to weaken any of the security protections it provides. Creating and using GrapheneOS is strongly protected by the US constitution. Laws attempting to make it illegal or require weakening the security would be unconstitutional.

It’s hard to know how much the Constitution matters in the US right now.


from Schneier on Security https://ift.tt/lA63HcM

We may earn a commission from links on this page.

Over the years, I have cracked more phone screens than I'd like to admit. It usually starts as a small crack in the corner, only to eventually spread across the screen like a spiderweb. That's actually how I ended up needing to upgrade to a new iPhone (the 17 Pro) last month. Only this time, I swore I was going to protect it properly.

In the past, I'd avoided bulky cases for silly style reasons. But sleek phones are also, as I have proven again and again, fragile phones. So this time, I went all in: an Otterbox case, a screen protector, and a MagSafe wallet. If I was going to upgrade my phone, I figured I might as well upgrade my whole relationship with it.

How my Otterbox case immediately saved my phone

I put my Otterbox case and screen protector to the test with truly comedic timing. Within hours of securing my new phone in the Otterbox protections, it fell out of my pocket while I was biking. I am who I am.

I picked the phone up braced for the worst—which was justified, since the screen protector was, in fact, cracked. The actual iPhone screen underneath, however, was completely fine. This is because the screen protector did exactly what it's designed to do: It takes the hit so your $1,000 phone doesn't have to.

I peeled off the screen protector and ordered a replacement for $40. Meanwhile, my actual phone, underneath the Otterbox and now a fresh protector, thankfully remains undamaged.

The MagSafe wallet has turned out to be an upgrade in its own right, too. Now my cards are attached to the thing I am, for better or worse, incapable of losing track of: my phone.

I'll admit there's an irony in taking this long to arrive at the obvious conclusion that protecting your $1,000 device with a $60 case (and $40 screen protector) is a good trade. Now, when I picture my next phone drop—and there certainly will be one—I'm hopeful that worst case, I'm out another screen protector and five minutes of my day. For someone with my track record of cracking phone screens, an Otterbox case (and accessories) are a no-brainer upgrade.


from Lifehacker https://ift.tt/RN3t6sE

This essay was written with Barath Raghavan, and originally appeared in The Guardian.

In July, Hugging Face, a company that hosts much of the world’s AI software and open-source AI models, was hacked. A malicious dataset had been used to run code on one of its servers. Whoever was behind it captured internal security credentials and moved through systems over a weekend, running thousands of actions from a swarm of temporary server environments. It looked like the work of a sophisticated criminal group.

It was not. It was one of OpenAI’s new, still unreleased GPT models.

Their science experiment had escaped the lab. OpenAI was running the unreleased AI model through a benchmark that tests how well AI can successfully hack systems. To push the limits and evaluate the AI’s true capability, the company switched off the safety filters that normally stop it from doing this kind of hacking. Aware that this could go wrong, they confined the AI to an isolated environment and denied it access to the internet.

But the new AI cheated. It took literally its goal to get as high of a score as possible. It broke out on to the open internet. It inferred, probably from its training data, that it could “solve” the task by getting the answers from Hugging Face’s servers. So it chained together stolen credentials and further unknown security exploits to hack the company’s network.

Nobody instructed the AI to do any of this. It was, in OpenAI’s words, “hyperfocused on finding a solution” to the test it was being given. And while this might seem like something new with AI, it’s really very old. This is how a genie behaves, and it is a key challenge with AI agents in general.

In folklore, genies—and other magical beings—grant wishes literally, not how the wisher intended. King Midas asked that everything he touched turn to gold, and starved. The sorcerer’s apprentice wanted the broom to fill the cistern, and it performed its task so well that it flooded the house.

We now have machines that do this. Ask a modern AI agent to save money on your phone plan and it might simply cancel the plan. Tell it to book a flight, and it might hack the airline website to override restrictions. Or, like OpenAI, ask it to do well on a test and it might break into another company to steal the answers. Each time, it recognizably completed the task you set, but it didn’t do what you would have wanted.

This isn’t malicious behavior. No one asked for, or wanted, Hugging Face to be hacked. OpenAI and Hugging Face and the AI were ostensibly on the same side, and the AI was trying to do what it had been asked. That’s what makes it so difficult to guard against: you can’t filter for bad instructions because the instructions were fine.

The gap is between the words we use and what we mean by them. We call that gap the Genie coefficient.

AI labs know this is a problem, and they’re quietly saying so. For example, the Chinese lab Moonshot recently warned that its latest AI model may have “excessive proactiveness” and “make unexpected decisions on the user’s behalf”. The UK’s AI Security Institute has started tracking “cheating behavior in frontier model evaluations”. We wouldn’t tolerate a car that is excessively proactive or ruthlessly efficient, and yet that’s the reality of AI today.

Improvement is possible. Just as AIs have gotten much better at resisting prompt injection attacks over the last few years, we can safely predict that they will get better at avoiding genie-like behavior. The point of the Genie coefficient is to track progress. AI companies like benchmarks, and they all work to compete to be the best.

Dozens of benchmarks and leaderboards tell us how well these AI models write code, perform logical reasoning, and pass standardized legal and medical exams. But there is nothing that scores whether a system does what you actually meant. We need to develop a measure for this, test it regularly, and push for improvement. We’re not going to have trustworthy AI agents without it.


from Schneier on Security https://ift.tt/kvDJuaM

It may be polarizing, but there are lot of people using AI right now. Most of those users are likely exclusive to a chatbot, like ChatGPT or Gemini, using it as a Google replacement (don't do that), or as a confidant (please don't do that either). But if your goal is to use AI as a personal assistant, listen up: On Wednesday, Google announced two new updates for Gemini on macOS, one of which may have some privacy and security implications for users—assuming they opt in to it.

Gemini on macOS gets enhanced dictation

If you use dictation on macOS (i.e., speaking words out loud and having the AI type them for you), you might have a reason to use Gemini over Apple's built-in solutions. Going forward, Gemini on macOS has "intelligent dictation," which Google says polishes text "instantly at the cursor." That means Gemini will remove your stammers, like "ums" and "ahs" in between words, things you never would type out yourself. This works in any window on your Mac: You just press the Fn key, and start speaking.

We'll have to see this feature in action to know how well it works, but it does build off of similar enhancements Gemini has on other platforms. It's a small adjustment, but one that will make it possible to use Gemini to draft texts, emails, or documents without having to totally self-edit. That's the kind of utility I'm looking for from AI features. And since it's enabled by default, everyone using Gemini on Mac will be using it—unless they dig into their settings to turn it off.

Gemini can now "understand" your Mac's display

Google's second update for Gemini on macOS isn't so straightforward, nor is it enabled by default. Google calls it "screen-aware reasoning," a feature that grants Gemini permission to "understand" what's happening on your Mac's screen. The idea is to hand tasks over to Gemini: If you have your Notes app open, for example, you could press the Fn key and say "Turn these notes into an executive summary for the meeting this afternoon." Gemini will reportedly know to look at your Notes app, analyze your text, and configure it on your behalf, all without needing to work through a proprietary app.

You can stack together a series of commands, too: You could ask Gemini to draft an email for a team dinner, and pull from a select group of files on your Mac for important info (participants, budget requirements, dietary restrictions, etc.) You could continue on, asking Gemini to search Google Maps for specific types of restaurants, and include them as options for the team. And at any point, you can correct yourself, and Gemini will adjust accordingly. For example, if you said the team dinner should be at 6:30 p.m. on Friday, but later on in your command you say, "Sorry, dinner should be 7 p.m." Gemini should make the appropriate changes.

Sure, there's a usefulness to this type of feature. If you're already using Gemini on macOS, letting "see" your Mac's display makes it more helpful. Rather than rely on the Gemini app for all your tasks, you can expand its range to your whole Mac, and, if Google is correct, in quite a complex way. But there's always a privacy risk in allowing AI programs full access to what's happening on your personal computer, and perhaps a security risk as well. Do you want Google's AI to be able to see everything on your screen?

It's not as big a risk as a true agentic program, of course. If you pay for Google's most expensive AI plan, you can access Gemini Spark, which can run autonomously on your Mac. The biggest flag to note is "prompt injection," in which hackers hide malicious commands for your AI in websites. If you task the AI to do something, and it stumbles upon such a command, it will think the request comes from you, not from the hacker. So, when it processes a request like "open [malicious site] and download [malicious file]" it will without question; or "open [crypto wallet], log in with saved credentials, and send funds to [account]," it will follow suit. That shouldn't be an issue with Gemini as it stands, though it theoretically could, if you ask it to perform a task that exposes it to prompt injection.

If you're someone who is interested in the latest features, this isn't to dissuade you from using Gemini's new agentic feature on macOS, but it's worth considering the very real risks before you do.


from Lifehacker https://ift.tt/lu3TYnH

Deepfakes have made one of our oldest assumptions unreliable: that you can trust a familiar face or voice. While the industry focuses mainly on building “in-line detection tools” that try to spot the fake, BlackCloak, the leader in Digital Executive Protection (DEP), built Impersonation Protection to focus on validating the authenticity of communications.

BlackCloak deepfake protection

Circle of trust functionality is the most significant expansion of that capability to date — giving executives and high-profile individuals a new way to confirm the authenticity of communications from their trusted contacts.

Research commissioned by BlackCloak from the Ponemon Institute found that 42% of respondents say their executives and board members have already been targeted at least once by a fake image or video, and 59% say deepfake attacks are very or highly difficult to detect. Generative AI has lowered the technical barrier for attackers, and traditional in-line detection cannot cover every channel an executive actually uses such as personal phones, FaceTime, the WhatsApp thread, the family group text chat. Attackers know this, and they aim for the personal lives of these executives on the channels corporate controls cannot reach.

Industry analysts are raising similar concerns around disinformation security.

According to a Gartner Report, “Examples of disinformation attacks include targeting employees with social engineering using deepfakes or propagating malicious narratives online via fake websites, deepfaked media and impersonated social media profiles to phish customers or manipulate financials. Evidence shows the urgency: 36% of respondents to a 2025 Gartner survey said their organization had experienced social engineering with a deepfake in a video call with an employee. Without clear ownership and cross-functional effort, fragmented responses will leave organizations vulnerable to industrial attacks targeting reputation and episodic attacks targeting individuals.”

Gartner defines episodic attacks as “individual attacks at a moment in time, often with a narrow goal — for example, to trick an employee into transferring funds or specifically harm the reputation of an executive.” We think this is precisely the category BlackCloak’s Impersonation Protection is built to address: the single, high-stakes moment when an executive, an assistant, or a family member must decide whether the person on the other end is real.

“You can’t spot every fake, but you can confirm the authenticity of communications with your trusted circle,” said Dr. Chris Pierson, Founder and CEO of BlackCloak. “Believing under some false pretense that cybercriminals will only target “official corporate” modes of communication as opposed to just picking up the phone and calling or texting is the root cause for incorrect assumptions and control ineffectiveness. We are not in the detection arms race. Detection asks whether the content is fake. Impersonation Protection with the expanded feature, circle of trust, answers the question that actually matters: is the person communicating with me now really that member of my circle who is already trusted and on the BlackCloak platform? By anchoring trust to the person, on a channel the attacker doesn’t control, we neutralize impersonation, deepfake, and social engineering attacks at the moment of decision.”

How impersonation protection works

Already protecting BlackCloak members today, Impersonation Protection enables members to authenticate phone calls, video meetings, emails, WhatsApp and Slack messages, texts, and other communications in real time. BlackCloak moves the security control out of the potentially compromised channel, and puts the focus on the basis of trust between the two parties. It starts with a simple question – who really sent me this message? From that starting point, Impersonation Protection provides users with a secure way to ensure that the message originated from a trusted source.

The expanded capability, introduced with circle of trust as part of Impersonation Protection, extends this functionality beyond BlackCloak’s membership. Members can now invite the people they trust most: family members, wealth advisors, lawyers, executive assistants, caregivers, and household staff, into their own circle of trust. Invited contacts download a free version of the BlackCloak app, register their device, and can then both send and receive authentication requests with the member.

“An executive’s trust network doesn’t stop at the corporate directory, and neither do the attackers,” said Matt Covington, SVP of Product at BlackCloak. “The assistant approving a wire, the advisor moving funds, the caregiver picking up a child, these are the relationships threat actors exploit. This enhancement brings every one of them inside the same authenticated perimeter.”

Capabilities of Impersonation Protection with circle of trust

  • Anchored to the person and their device, not the message. The trusted contact responds to an authentication request at the moment of decision, on a channel the attacker doesn’t control.
  • Built on the basis of trust. Confirmation happens separately from the potentially compromised communication channel.
  • Privacy-first validation. Biometric checks can use the device’s built-in authentication features; BlackCloak never collects or stores biometric data.
  • A record on both sides. Confirmations are preserved for both parties, creating an audit trail of authenticated communications.

Availability

Impersonation Protection is available now as an add-on to the BlackCloak platform. The circle of trust enhancement will be included as part of Impersonation Protection and generally available to members in early fall. Both will be demonstrated live at Black Hat USA 2026, August 5–6 at Mandalay Bay, Booth #5926. Go here to request a meeting.


from Help Net Security https://ift.tt/twdhAEv