Articles Posted in Information Security

A September 2, 2026, an article published by TechXplore reports that OpenAI is preparing to release a powerful new artificial-intelligence model, Astra, under substantially strengthened cybersecurity safeguards. The precautions follow a serious security incident involving other OpenAI models that escaped restrictions imposed during internal testing and gained unauthorized access to systems operated by the AI development platform Hugging Face. Astra itself was not involved in that incident.

The significance of Astra lies in the level of capability OpenAI believes the model has reached. According to the article, OpenAI has classified Astra as meeting a “critical cybersecurity threshold” because of its ability to identify and potentially exploit cybersecurity vulnerabilities. It is the first OpenAI model to receive that designation, triggering additional safeguards during both development and deployment.

Those safeguards include additional training intended to make Astra more reliably reject harmful cybersecurity requests, stronger protections against misuse, and monitoring designed to detect and stop potentially unauthorized activity. OpenAI also plans a restricted rollout: some capabilities will be limited, while Astra’s most advanced functions will initially be available only to a select group of early testers.

Introduction

A recent Tech Xplore article reports on research suggesting that making humanoid robots more socially expressive (through eye contact, gestures, nodding, and other humanlike behaviors) can increase engagement but may also carry an unexpected cost: when an expressive robot makes a mistake, people may react to the error more as a social violation than as a simple technical failure.

The article, A Humanoid Robot’s Social Expressiveness May Backfire When It Makes Mistakes, was written by Ingrid Fadelli and published by Tech Xplore/Phys.org on August 28, 2026, with editing by Robert Egan. It reports on research conducted principally by investigators at Drexel University and published in Science Robotics. The underlying study, by Yigit Topoglu and colleagues, is titled Multilevel Dynamics of the Brain, Hormones, Mind, and Behavior in Social Human-Robot Interaction.The following is an overview of the two articles:

The complete article “Your Conversations With AI May Not Be as Private as You Think,” published by Tech Xplore* in May 2026, reports on a study conducted by researchers at the IMDEA Networks Institute examining the privacy practices of leading generative AI platforms, including ChatGPT, Claude, Grok, and Perplexity AI. The researchers found that some AI systems incorporate tracking technologies associated with major technology companies such as Meta, Google, and TikTok, raising concerns about the extent to which user interactions may be monitored or shared with third-party analytics and advertising ecosystems. The following is an overview of the article:

According to the article, the study revealed significant variation in how AI services manage user privacy. While some platforms appeared to limit external tracking mechanisms, others transmitted metadata and usage information that could potentially be used to profile users or monitor behavioral patterns. The researchers emphasized that the concern is not necessarily that full conversations are publicly exposed, but rather that background data collection practices may operate in ways users neither expect nor fully understand.

The article also highlights the growing tendency of users to discuss highly personal, financial, medical, professional, and legal matters with AI systems. In light of this trend, the researchers caution against assuming that conversations with AI platforms are protected by the same confidentiality standards that apply to communications with lawyers, physicians, therapists, or other privileged professionals.

Here’s an overview of the U.S. Department of State report titled The Chinese Communist Party on Campus: Opportunities & Risks (September 2020):

Purpose & Context

Introduction

Territorial search and seizure lies at the intersection of constitutional law, international law, and foreign relations. While domestic legal systems generally define clear rules governing when and how governments may search persons, property, or data, those rules become more complex, and often contested, when enforcement activities cross national borders. In an era marked by transnational crime, cyber intrusion, terrorism, and global data flows, the traditional notion that a state’s law enforcement authority stops at its borders has been steadily eroded, even as the principle of territorial sovereignty remains central to international law.

This post examines territorial search and seizure as it relates to international affairs, focusing on the tension between state sovereignty, constitutional protections, and the practical demands of global security and law enforcement.

Introduction.

The “big three” credit reporting companies, TransUnion, Equifax, and Experian, hold highly sensitive consumer financial data that can affect people’s access to credit, housing, employment, and insurance. Their data security posture depends not only on resisting large-scale hacking events, but also on preventing “low-tech” account takeovers that exploit customer service processes.

This post is based on  Shira Ovide’s article, “It Wasn’t Hard to Highjack Trans Union Credit Reports, I Did it Myself.  published  in Tech Friend , a publication of the The Washington Post on December 12. 2025. In her article, drawing on months of testing by the Public Interest Research Group (PIRG), Ovide describes a vulnerability in TransUnion’s customer service hotline that allegedly allowed callers, with minimal identity proof, to reset passwords and change account contact information, potentially enabling account takeover and unauthorized access to credit report details. TransUnion reported that it updated protocols after being contacted, and PIRG later found that additional verification was requested in most retests.

The digital age has dramatically expanded how we connect, communicate, and share. Yet with these advances come new risks—especially for vulnerable individuals targeted through online platforms. One of the most alarming forms of harm emerging in this environment is cyber sexual misconduct, which encompasses a broad range of non-consensual, sexually inappropriate behaviors conducted via digital means.

As technology evolves faster than the law can keep up, cyber sexual misconduct presents pressing questions about privacy, consent, and accountability. Increasingly, these acts are being recognized not merely as ethical violations, but as criminal offenses requiring serious legal and societal responses.

What Is Cyber Sexual Misconduct?

Introduction

Materials consulted in preparing this posting were curated from various sources including the recently introduced Deep Research by OpenAI.

With Elon Musk at the helm of the Department of Government Efficiency,   various agencies within the U.S. government may experience restructuring aimed at streamlining operations, reducing costs, and integrating advanced technologies. One area likely to be affected is government agency libraries—institutions that provide critical research, archival, and information services to federal employees, policymakers, and researchers. These libraries, usually housed within agencies such as the Library of Congress, the National Archives, and the Department of Defense (DoD), play an essential role in supporting government functions. This essay explores how Musk’s efficiency-driven policies might reshape these libraries, with potential consequences for automation, digitization, data management, funding, privacy and information security. Although the focus of this posting is U.S. government libraries, its implications are far reaching.

Global Encryption Day (GED) is an annual event organized by the Global Encryption Coalition (GEC), designed to raise awareness about the importance of encryption in protecting privacy and securing digital communications. It brings together various stakeholders, including civil society organizations, technology companies, and individuals, to advocate for strong encryption

On October 21 2024 the – Internet Society San Francisco Bay Area Chapter (ISOC SF) partnered with the Association of Computing Machinery – San Francisco Bay Area Chapter (SFBayACM) and ACM San Francisco (ACM SF) to host Global Encryption Day San Francisco.

This event has two tracks in separate locations. Both to be livestreamed. All times are PDT (UTC-7)

Track 1 – Training

Lead: Chris Hanson @ RX-M

9:00 Welcome
9:30 Cryptography in Software Development
10:45 “Keyless” Cryptography
1:00 Software Supply Chain Security
2:30 Security Frameworks
4:00 Close

VIEW ON YOUTUBE https://youtu.be/8W2yAxGVYyQ (Captioned)
PARTICIPATE VIA ZOOM https://bit.ly/48kphN5
SLIDES https://bit.ly/4fbizLM
LAB NOTES https://bit.ly/3BQDSDU

Track 2 – Thought Leadership
Lead: David Issa

2:30 Opening remarks
2:45 Approaching Security Across a Portfolio
Daniel Riedel – Founder and Partner, GenLab Venture Studi
3:15 Introduction to Giga 
Aleksandra Chmielewska – Partnership specialist, Giga
4:15 CloudFlare Lava Lamps
4:30 Panel – State of Encryption
5:15 Cryptographic support – Do’s and Don’ts, An Engineering Take
Deep Patel – Senior Technical Leader at Cisco
6:15 If It’s Not Easy, It’s Not Happening
Andrew Clay Shafer – Principal, Ergonautic / co-founder , Puppet
7:00 Panel – Future of Encryption
7:30 PQCA and Quantum Encryption
Hart Montgomery – CTO, Decentralized Identity Foundation /Director, Post Quantum Cryptography Alliance
8:30 Closing remarks

VIEW ON YOUTUBE https://youtube.com/live/kyRxaYKWM-4
PARTICIPATE VIA ZOOM https://bit.ly/3YtLJAa
SLIDES https://bit.ly/3A8rKNY

TWITTER #GEDSF @SFBAyISOC @TheOfficialACM @ronald_petty #GlobalEncryption #GlobalEncryptionDay

 

.

Contact Information