If you've ever received an out-of-the-blue message via LinkedIn from a recruiter offering some well-paid consultancy work, intelligence agencies have a message for you: be very careful. Read more in my article on the Hot for Security blog.

Intelligence agencies from five allied nations are warning professionals to be wary of unsolicited messages on platforms like LinkedIn, as Chinese military intelligence is reportedly using these channels to recruit individuals for information gathering. The FBI, MI5, and their counterparts in Australia, Canada, and New Zealand have issued a joint advisory detailing a sophisticated operation where Chinese intelligence officers, or those acting on their behalf, pose as recruiters for legitimate-sounding private consultancies.
These deceptive "cover companies" often claim to be based outside of China to enhance their credibility. The primary targets are individuals whose careers have involved government, defense, or foreign policy sectors. The recruitment process begins with job advertisements placed on professional networking and job search sites, including LinkedIn, Indeed, and Upwork. Resumes are then evaluated based on the applicant's potential access to sensitive information.
Following an initial screening, candidates undergo online interviews where the recruiters conceal their true identities and inquire about the applicant's government contacts. For those with military backgrounds, questions may delve into their roles, unit activities, home bases, or even details about naval vessels they serve on.
Successful candidates are then tasked with completing a trial report on seemingly innocuous topics such as China's bilateral relations, regional defense issues, or international trade. Once a working relationship is established, the recruiters inform the recruits that more sensitive materials will be required for future assignments, and the communication typically shifts to encrypted messaging applications.
Payments for these reports can range from several hundred to thousands of dollars, with transactions facilitated through various online payment platforms and cryptocurrency. The agencies emphasize that targets do not necessarily need to possess security clearances to be valuable to Chinese intelligence. Even unclassified information concerning government policy, military strategy, or capabilities can be pieced together with more sensitive data to create a "comprehensive operational picture."
Academics, journalists, freelance writers, and employees of think tanks are identified as potential targets. The advisory also highlights that simply submitting a CV containing employment history, specialized knowledge, and professional contacts can hold intelligence value, even if the applicant does not proceed further in the recruitment process.
The Five Eyes agencies have reportedly identified individuals who have engaged in such activities for China, and these individuals may face consequences including criminal prosecution, job loss, and the revocation of security clearances. Professionals are advised to approach unsolicited job offers with skepticism, especially if the opportunity seems unusually tailored to their background or if the communication quickly moves to encrypted platforms. China has denied the allegations, labeling them as fabricated and malicious slander, and has instead accused the Five Eyes nations of posing a threat to international stability.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a