@uclisec

Twitter Page of UCL's Information Security Research Group & the Academic Centre of Excellence in Cybersecurity Research

London, Europe
Joined November 2014
UCL InfoSec retweeted
Our paper on AI security agents was accepted at #NeurIPS2026 🎉 The question: does safety training make AI models worse at security work? We gave 4 open models and their uncensored versions the same 30 sandboxed vulnerability tasks, 1,500 runs in total Joint work with the @Zaddyzaddy
2
2
2
19
3,967
UCL InfoSec retweeted
It’s #NationalCodingWeek next week, so I've published a resource on using the BBC @microbit_edu to play a game that explores how radio waves travel, get blocked by/reflected off obstacles, and the challenges of measuring strong signals that can overload sensors.
1
1
2
174
UCL InfoSec retweeted
National COVID-19 figures couldn’t tell a department whether to hold a seminar next week. So from 2020 to 2022 I collected UCL’s daily case counts and turned them into an early-warning chart. I’ve now archived all of it plus 168 newsletters for context. benthamsgaze.org/2026/07/26/…
1
1
2
381
UCL InfoSec retweeted
Glad you asked, the main differences I see right now: + Gumu offers sovereign on-prem + local model support (if you don't want to send your research to OpenAI) + PDF diff mode + auto-recompile after edits + GitHub integration + author profiles for writing in your academic style + one-click paper helpers (see image) Prism’s UI is nice and fast though, and backend/VM compute looks broadly comparable.
Nice! How does it compare to prism?
1
2
3
874
UCL InfoSec retweeted
I was interviewed for Computerphile on my analysis of hidden messages within the GPS signals and what message they might carry (and to whom). youtu.be/2Q6OvYjOJi0
1
4
8
540
UCL InfoSec retweeted
The corrected and expanded article on my exploration of GPS special messages is available at sjmurdoch.github.io/gps-spec…. Additionally, this is now mobile-friendly and accompanied by detailed footnotes, allowing results to be verified against the published dataset. 5/
1
3
15
1,763
UCL InfoSec retweeted
New paper out with @Zaddyzaddy tldr: Security patches are also attack maps. Patch2Vuln asks whether an offline LLM agent can look only at old/new Linux binary packages, no source patch, no advisory text, and infer what vulnerability was fixed. It builds a local pipeline around ELF extraction, Ghidra/Ghidriff binary diffing, changed-function ranking, dossier generation, and agentic audit/validation. On 25 Ubuntu .deb package pairs, it found the correct security-relevant patched function in 10/20 real security updates and the accepted root-cause class in 11/20, while correctly treating all 5 negative controls as unknown. The fascinating bit: this is basically post-patch vulnerability archaeology. It shows that once a binary security update ships, an agent can sometimes reconstruct the hidden bug from the patch artifact alone. But the main bottleneck is not yet “LLM reasoning”; it is whether the binary diff/ranking stage surfaces the right function and whether local validation can turn the hypothesis into behavioral evidence.
4
3
2
16
3,888
UCL InfoSec retweeted
For 19 years, GPS satellites have secretly broadcast a “numbers station” in their public signals. We decoded 12M messages: a 2011 flash where 31 of 32 satellites flipped in hours, “ghost” substrings repeating years apart, and a “TEXT” prefix spreading now. lsc-pagepro.mydigitalpublica…
46
347
44
2,068
409,072
UCL InfoSec retweeted
The program chairs for #SaTML2027 will be Fabio Pierazzi (@fbpierazzi) and Florian Tramèr (@florian_tramer)! We're in for a great conference under their leadership.
4
24
4,122
Reuters were accused of acting illegally in guessing the URL of an unreleased report in 2002. I didn’t hear anything after the initial reports so presume it was quietly dropped or settled. blog.citp.princeton.edu/2002…
The person who first downloaded the OBR's document at 11:35 on Budget day (I'm guessing someone at Reuters, given they first reported it) had already guessed the web address and tried and failed to download it 32 times so far that day(!)
1
3
612
Honoured and humbled to share that we (#StopScamsUK) won the @theTECAs Outstanding Private/Third Sector Initiative Award 🏆 Thanks to all our members and the team ❤️ Onwards and upwards 🚀 #TacklingEconomicCrimeAwards #TECAs #OnlineFraud #Scams #Teamwork
1
2
6
342
[1/n] Competitive opportunity for a 4-year PhD scholarship at @uclcs Deadline: Jan 5, 2026 @ 1pm We're seeking exceptional PhD applicants with expertise in AI and cybersecurity for a competitive opportunity to work with myself and @lcavallaro #PhD #Cybersecurity #AI @uclisec
2
1
1
2
739
‼️New paper alert 📣 Our latest paper on understanding SMS phishing infrastructure and strategies using public user reports (w/ @a_papasavva, @gsuareztangil, and @mjvasek) has been accepted @ACM_IMC_2025 📝📱@uclisec @uclcs @ucl @IMDEAInstitutes #cybercrime #smsscams #smishing
1
7
1
10
874
Emiliano will be back at UCL for a talk on Monday 📍 169 Euston Road, GF Seminar Room 📅 September 22 🕑 2:00 PM Swing by if you’re in town and interested in synthetic data and privacy or just want to say hi. sec.cs.ucl.ac.uk/seminars/
1
149
Looking forward to presenting and discussing our paper (w/ @mjvasek) in collaboration with #StopScamsUK on #CNPfraud @NspWorkshop in Germany over the next few days! @uclisec @uclcs @ucl @StopScamsUK #onlinefraud #smishing #smscsams @Paymentology #NSPW #remotefraud #cardfraud
📣📱💳 Our paper (w/@mjvasek) titled "Card-Not-Present Fraud resulting from Smishing Attacks: An Experimental Study" was accepted @NspWorkshop 2025! Looking forward to a great discussion. #CNPfraud #smscams #scams #smishing #onlinefraud #StopScamsUK #NSPW25 @uclisec @uclcs @ucl
1
1
269
UCL Computer Science are hiring Section Managers to support the development and delivery of teaching, research, and strategy within their section. I’ll be leading the Foundational Computer Science section, where the InfoSec group is based. ucl.ac.uk/work-at-ucl/search…+
1
5
7
908
Looking forward to presenting our paper on “Hi mum and dad” SMS scams next week @USENIXSecurity in Seattle! If you are attending #USENIX25, come to the Fraud, Malware and Spam track on 14th Aug! @uclisec @uclcs @ucl @IMDEA_Networks @StopScamsUK #onlinefraud #scams #cybercrime
1
2
5
367