LLMs can unmask pseudonymous users at scale with surprising accuracy

2026-03-04T20:51:47Z2915076df1102535e6b934cab9377cd68d4e63548e1e05ec03213cbbec3a44dd
AI toyAirSnitchCastleloaderLLM privacyLumma StealerMerkle Tree CertificatesNotepad++Office zero-daySMS sign-in-vulnerabilitiesSecure BootTLSWindowsWi‑Fi encryptionbug-bountycURLchild-privacycryptocurrency-theftdeanonymizationenergy gridmalicious-packagespassword-manager riskquantum-proofingstate-sponsoredsupply-chain compromisewiper malware

What happened

A roundup of Ars Technica security stories covering multiple high-impact risks: LLMs can deanonymize pseudonymous users at scale; Google rolled out Merkle Tree Certificate support to make HTTPS more quantum-resistant; a new “AirSnitch” technique can bypass Wi‑Fi encryption; password managers and software-update supply chains (Notepad++, malicious dYdX packages) are being abused to steal data and crypto; Lumma Stealer and Castleloader campaigns are active; Windows Secure Boot certificates are expiring soon; an urgent Microsoft Office patch is already being exploited by state actors; kids’ AI‑to

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
2915076df1102535e6b934cab9377cd68d4e63548e1e05ec03213cbbec3a44dd
Enrichment time
2026-03-04T20:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · LLMs can unmask pseudonymous users at scale with surprising accuracy · Baitaphish