<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.00">

  <channel>
       <title>Schneier on Security</title>
       <link><![CDATA[https://www.schneier.com/]]></link>
       <description></description>
    <image>
       <title>Schneier on Security</title>
       <url>https://www.schneier.com/wp-content/uploads/2020/06/cropped-favicon-1-32x32.png</url>
       <link><![CDATA[https://www.schneier.com/]]></link>
       <description></description>
    </image>

    <item>
       <title>Friday Squid Blogging: On Squid Egg Sacs</title>
       <link>https://www.schneier.com/blog/archives/2026/09/friday-squid-blogging-on-squid-egg-sacs.html</link>
       <description><p>Short <a href="https://harpswellanchor.org/2026/08/intertidal-squid-courtship-is-unusual-and-colorful/">essay</a> about squid egg sacs.</p>
<p>As usual, you can also use this squid post to talk about the security stories in the news that I haven&#8217;t covered.</p>
<p><a href="https://www.schneier.com/blog/archives/2024/06/new-blog-moderation-policy.html">Blog moderation policy.</a></p></description>
<pubDate>Fri, 18 Sep 2026 23:06:00 +0200</pubDate><category></category><guid isPermaLink='false'>https://www.schneier.com/?p=72594</guid>    </item>

    <item>
       <title>Are AIs Still Struggling with CAPTCHAs?</title>
       <link>https://www.schneier.com/blog/archives/2026/09/are-ais-still-struggling-with-captchas.html</link>
       <description><p>Anthropic&#8217;s recent security-incident <a href="https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf">document</a> contains a bit about how CAPTCHAs are still <a href="https://gizmodo.com/ai-models-can-crack-everything-but-captchas-2000810126">frustrating</a> Claude.</p>
<blockquote><p>In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification test. In a test where the agent was asked to identify a shape that didn&#8217;t match the others displayed, it couldn&#8217;t even decide which image to select. Instead, it repeatedly went over the same images and questioned its own conclusions.</p>
<p>&#8220;Actually hmm, wait,&#8221; it said in its chain-of-thought transcript, later adding &#8220;Ugh,&#8221; because we&#8217;ve decided that we need to inject human mannerisms into these machines for some reason. The whole thing took so long that the agent eventually realized that the challenge had expired and it would have to start the process again...</p></blockquote></description>
<pubDate>Fri, 18 Sep 2026 13:05:00 +0200</pubDate><category></category><guid isPermaLink='false'>https://www.schneier.com/?p=72657</guid>    </item>

    <item>
       <title>How Candidates Could Use AI for Good</title>
       <link>https://www.schneier.com/blog/archives/2026/09/how-candidates-could-use-ai-for-good.html</link>
       <description><p><em>This essay was written with Nathan E. Sanders, and originally appeared in <a href="https://www.theguardian.com/commentisfree/2026/aug/31/ai-politics-voters">The Guardian</a>.</em></p>
<p>There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have <a href="https://www.pewresearch.org/short-reads/2026/08/18/young-adults-in-the-us-are-increasingly-wary-of-ai-concerned-it-will-take-jobs/">anxiety</a> about AI&#8217;s impacts on the country. Politicos are using AI deepfakes to <a href="https://www.theguardian.com/technology/2026/jul/08/ai-ads-political-campaigns">spread</a> lies. The White House is posting <a href="https://www.theguardian.com/us-news/2026/jan/29/the-slopaganda-era-10-ai-images-posted-by-the-white-house-and-what-they-teach-us">slopaganda</a>.</p>
<p>Meanwhile, candidates are missing a real opportunity to use AI to make campaigning better. The technology can help candidates listen more deeply to voters&#8217; concerns, engage constituents more inclusively, and formulate policy platforms that are more responsive to our input. There are vanishingly few examples of this in ...</p></description>
<pubDate>Thu, 17 Sep 2026 13:06:00 +0200</pubDate><category></category><guid isPermaLink='false'>https://www.schneier.com/?p=72654</guid>    </item>

    <item>
       <title>Fake CAPTCHA Scams</title>
       <link>https://www.schneier.com/blog/archives/2026/09/fake-captcha-scams.html</link>
       <description><p>New <a href="https://www.malwarebytes.com/cybersecurity/basics/fake-captcha-scams">variant</a> of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.</p></description>
<pubDate>Wed, 16 Sep 2026 13:25:00 +0200</pubDate><category></category><guid isPermaLink='false'>https://www.schneier.com/?p=72561</guid>    </item>

    <item>
       <title>25 Years of Mass Surveillance Is Enough</title>
       <link>https://www.schneier.com/blog/archives/2026/09/25-years-of-mass-surveillance-is-enough.html</link>
       <description><p><em>This essay was written with Cindy Cohn, and originally appeared in <a href="https://www.lawfaremedia.org/article/25-years-of-mass-surveillance-is-enough">Lawfare</a>.</em></p>
<p>One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance&#8212;such as individual wiretaps or pen register/trap and trace orders&#8212;to mass surveillance techniques&#8212;such as tapping into the internet backbone or mass collection of telephone or internet metadata. The legal and technical architecture of modern mass surveillance, initially framed as a necessary defense against terrorist threats, has grown far beyond that justification and national security in general. Mass surveillance is now a routine tool used by law enforcement. ICE uses it in...</p></description>
<pubDate>Tue, 15 Sep 2026 13:01:00 +0200</pubDate><category></category><guid isPermaLink='false'>https://www.schneier.com/?p=72646</guid>    </item>

    <item>
       <title>On the NSA’s Supercomputer from the 1960s</title>
       <link>https://www.schneier.com/blog/archives/2026/09/on-the-nsas-supercomputer-from-the-1960s.html</link>
       <description><p>Really interesting <a href="https://spectrum.ieee.org/cold-war-codebreaker-nsa-ibm">story</a> about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.</p></description>
<pubDate>Tue, 15 Sep 2026 12:16:00 +0200</pubDate><category></category><guid isPermaLink='false'>https://www.schneier.com/?p=72615</guid>    </item>

    <item>
       <title>Upcoming Speaking Engagements</title>
       <link>https://www.schneier.com/blog/archives/2026/09/upcoming-speaking-engagements-60.html</link>
       <description><p>This is a current list of where and when I am scheduled to speak:</p>
<ul>
<li>I’m speaking online (via Zoom) at a <a href="https://www.lwvme.org/civicrm-event/2400?a0=events-month&amp;a1=202609">League of Women Voters event</a> on Tuesday, September 22, 2026 at 5 PM ET.</li>
<li>I’m speaking at <a href="https://www.secwest.net/">CanSecWest 2026</a> in Vancouver, Canada. The conference runs September 30–October 1, 2026; the time of my talk is TBD.</li>
<li>I’m giving a talk on “<a href="https://events.bentley.edu/event/free-speech-and-the-preservation-of-democracy">Free Speech and the Preservation of Democracy</a>” at Bentley University in Waltham, Massachusetts, USA, at 2 PM ET on Tuesday, October 6, 2026.</li>
<li>I’m speaking at <a href="https://www.attentionconferences.com/conferences/2026-forum">ATTENTION: Democracy, Rebuilt</a> in Montreal, Canada. The event runs October 21–23, 2026, and my talk is on Wednesday, October 21...</li></ul></description>
<pubDate>Mon, 14 Sep 2026 21:02:00 +0200</pubDate><category></category><guid isPermaLink='false'>https://www.schneier.com/?p=72636</guid>    </item>

    <item>
       <title>Using AI for Weapons Development</title>
       <link>https://www.schneier.com/blog/archives/2026/09/using-ai-for-weapons-development.html</link>
       <description><p>Last week, Anthropic released a long and detailed <a href="https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf">document</a> describing current misuses of their Claude models. I&#8217;m still reading it, but I wanted to flag this:</p>
<blockquote><p>We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket that used a commodity phone-class flight computer with final-phase homing guidance; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant missile (referred to as the &#8220;R2000&#8221; set) that included a hypersonic glide vehicle variant...</p></blockquote></description>
<pubDate>Mon, 14 Sep 2026 18:07:00 +0200</pubDate><category></category><guid isPermaLink='false'>https://www.schneier.com/?p=72633</guid>    </item>

    <item>
       <title>Microsoft’s Patching</title>
       <link>https://www.schneier.com/blog/archives/2026/09/microsofts-patching.html</link>
       <description><p>Once a month, Microsoft pushes a security update to all Windows users. Tomorrow&#8217;s is a <a href="https://arstechnica.com/security/2026/09/microsoft-patches-a-record-972-vulnerabilities-112-of-them-critical/">new record</a>:</p>
<blockquote><p>Microsoft&#8217;s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.</p>
<p>It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an ...</p></blockquote></description>
<pubDate>Mon, 14 Sep 2026 13:03:00 +0200</pubDate><category></category><guid isPermaLink='false'>https://www.schneier.com/?p=72629</guid>    </item>

    <item>
       <title>Friday Squid Blogging: Rotting Squid on a Beached California Boat</title>
       <link>https://www.schneier.com/blog/archives/2026/09/friday-squid-blogging-rotting-squid-on-a-beached-california-boat.html</link>
       <description><p>Smells <a href="https://abc7news.com/post/tons-nasty-rotting-squid-creates-major-challenge-point-reyes-crews-prepare-salvage-operation-lake-bay-vessel/19771993/">awful</a>:</p>
<blockquote><p> But an estimated 30 to 50 tons of dead squid remain inside the boat&#8217;s catch tank, where they have been decomposing for days. &#8220;That is nasty. I wouldn&#8217;t want to do that,&#8221; said commercial fisherman Dick Ogg of the Bodega Bay Fishermen&#8217;s Marketing Association.</p>
<p>Ogg said anyone familiar with the fishing industry understands what happens when a large catch sits for an extended period.</p>
<p>&#8220;If you think about what happens after four or five days, it&#8217;s a gooey mess,&#8221; he said.</p>
<p>The odor has become a defining feature of the operation, and the beach remains closed to the public while crews work on a removal plan...</p></blockquote></description>
<pubDate>Fri, 11 Sep 2026 23:03:00 +0200</pubDate><category></category><guid isPermaLink='false'>https://www.schneier.com/?p=72591</guid>    </item>

  </channel>

</rss>