this post was submitted on 01 Oct 2026
60 points (96.9% liked)

Canada

12484 readers
657 users here now

What's going on Canada?



Related Communities


🍁 Meta


🗺️ Provinces / Territories


🏙️ Cities / Local Communities

Sorted alphabetically by city name.


🏒 Sports

Baseball

Basketball

Curling

Hockey

Soccer


💻 Schools / Universities

Sorted by province, then by total full-time enrolment.


💵 Finance, Shopping, Sales


🗣️ Politics


🍁 Social / Culture


🌐 Other Relevant Communities


Rules

  1. Keep the original title when submitting an article. You can put your own commentary in the body of the post or in the comment section.

  2. Provide sources when making a claim. Do your research or google it doesn't cut it. The one making the claim is responsible for backing it.

Reminder that the rules for lemmy.ca also apply here. See the sidebar on the homepage: lemmy.ca


founded 5 years ago
MODERATORS
 

"rogue AI agents" lol

you are viewing a single comment's thread
view the rest of the comments
[–] RelativityRanger@lemmy.ca 4 points 2 days ago

Not only, but you have to read the sources to find out:

Of these 899 requests, 13 of them carried attack payloads rather than ordinary queries, including by probing for vulnerabilities in the record-identifier parameter. The payloads included:

  • Three SQL injection probes (an apostrophe, 1 OR 1=1, and 1,2)
  • An encoded < for cross-site scripting
  • 2147483648 to test a 32-bit integer boundary
  • The string abc for non-numeric handling
  • Five requests fuzzing the output format (.json, ?output=, ?raw=, ?url=)
  • Two toggling a debug=1 flag

We do not believe that these probes were successful: each one came back as a normal HTTP 200 with an empty record page, with nothing to indicate the database acted on the input or that any extra data was returned.

We disclosed this attempted hack to the Canadian government on September 28, 2026. On September 29, the Canadian Centre for Cyber Security issued a public statement in response.

And here's the CCCS statement
https://www.cyber.gc.ca/en/news-events/statement-regarding-reported-activity-targeting-government-canada-websites