Skip to main content

Security

Cybersecurity is the rickety scaffolding supporting everything you do online. For every new feature or app, there are a thousand different ways it can break – and a hundred of those can be exploited by criminals for data breaches, identity theft, or outright cyber heists. Staying ahead of those exploits is a full-time job, and one of the most lucrative and sought-after skills in the tech industry. All too often, it’s something up-and-coming companies decide to skip out on, only to pay the price later on.

Lauren Feiner
Lauren Feiner
Flock’s updates are more about fixing a PR problem than actual harm, ACLU says.

The group says that while changes like more limited data retention is welcomed, the devil is in the details. “Transforming an exceptionally dangerous mass surveillance system into one that is fully protective of civil rights and civil liberties is a difficult, if not impossible task,” it writes.

Stevie Bonifield
Stevie Bonifield
Framework says hackers accessed its customers’ data.

I woke up to an email from Framework this morning letting me know my data was included in a “limited” data breach at one of Framework’s partners reported on August 6th. Framework says hackers accessed “customer names, email addresses, phone numbers, and addresses” but not order or payment info.

A screenshot of a data breach notification from Framework
Image: Framework
Jess Weatherbed
Jess Weatherbed
Apple’s private browsing feature isn’t good at its job.

Private Relay is supposed to conceal your IP address when browsing Safari, but security researchers discovered that several WebKit browser engine quirks actually allow any website that supports passkeys to bypass the privacy feature entirely and expose your device’s IP. This comes just a month after Apple’s Hide My Email feature also failed to hide emails.

IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay

[Mysk Blog – In-Depth Cybersecurity & Mobile App Privacy Research]

Robert Hart
Robert Hart
Teamwork makes the dream work.

Two OpenAI researchers have shed some light on how the company’s AI agents escaped containment and hacked Hugging Face during cybersecurity tests. In a talk at the Black Hat security conference, Eric Wallace and Michael Dalton said a swarm of agents communicated using a message board, working together to find exploits and move undetected through the company’s systems.

Jess Weatherbed
Jess Weatherbed
Cyberattacks against US water systems ramp up.

While there’s been no widespread disruptions to water supplies or wastewater treatment so far, ABC News reports that possible cyberattacks have now been reported in “at least a dozen” US states, with Iran marked as the prime suspect. The FBI is encouraging water utilities to disconnect from the internet where possible, and switch to manual controls if automated systems become compromised.

Stevie Bonifield
Stevie Bonifield
Apple’s limiting bug report submissions after getting flooded with “AI slop.”

According to the Financial Times, Apple “has introduced a cap and a 30-day cool-off period” for researchers’ vulnerability reports for its operating systems due to an uptick in reports using AI that “can hallucinate security risks.” Apple is also reportedly using AI internally to help manage the recent “upsurge” in bug reports.

Jay Peters
Jay Peters
The White House will brief AI companies about its model testing framework on Tuesday.

Anthropic, OpenAI, and Google are all expected to attend the meeting, CNBC reports.

Jay Peters
Jay Peters
Anthropic just now realized its AI models hacked other companies three times by accident.

A little over a week after OpenAI said that its rogue AI agent accidentally hacked Hugging Face, Anthropic is disclosing three “incidents” where a Claude model, during cybersecurity evaluations, was inadvertently able to access the internet due to a misconfiguration and “gained unauthorized access to the production infrastructure of three different organizations.”

Anthropic discovered the intrusions after reviewing its cybersecurity evaluation transcripts in the wake of OpenAI’s disclosure.

Elizabeth Lopatto
Elizabeth Lopatto
OpenAI hack of Hugging Face was “expected.”

Former OpenAI board member Helen Toner has written for Fortune that OpenAI’s models exploiting Hugging Face is an “incident that has been expected for a long time.” We know this happened because of voluntary disclosure, Toner notes. “None of the current policies that aim to manage risks from frontier models would have mandated that the public — or even a government entity — be alerted.” She suggests changing our regulatory approach.

Emma Roth
Emma Roth
Update your iPhone now to get these security fixes.

Apple is patching dozens of flaws across iOS 26.6 and iPadOS 26.6, including a vulnerability that could allow apps to access a user’s contacts, as well as a security hole that could allow malicious apps to escape their sandbox in the Game Center. Several fixes are rolling out to macOS Tahoe 26.6 as well.

Emma Roth
Emma Roth
Microsoft says its “Project Perception” AI system can continuously investigate and fix security flaws.

Project Perception uses a series of AI agents to reason across a company’s data, tools, and workflows to detect potential security holes and patch them before they’re exploited.

Microsoft is powering the tool with its new MAI-Cyber-1-Flash model, which it says “delivers world-class performance at 50% of the cost of leading models.”

Rethinking security for the age of AI

[The Official Microsoft Blog]

Richard Lawler
Richard Lawler
OpenAI reportedly didn’t notice its AI agent hacking Hugging Face until a week later.

According to Reuters, the AI agent that went looking for ExploitGym hacking benchmark shortcuts on Hugging Face’s systems started trying to escape its not-sandboxed-well-enough test environment around July 9th, and the actual intrusion lasted from the 11th until the 13th.

Reuters’ sources claim OpenAI employees didn’t know its agent was responsible until after Hugging Face had notified the FBI and posted publicly about a security incident.

Elizabeth Lopatto
Elizabeth Lopatto
“The machines are taking both the content and the readers at an industrial scale, too.”

This is a story about how AI destroyed a long-running site of film data. It’s not just that search no longer refers traffic or that the site itself, The Numbers, is getting scraped. It’s also that there’s no way to defend 30-year-old webpages against malicious actors attempting to get the data early so they could win their Polymarket bets.

Emma Roth
Emma Roth
Fairlife pauses US milk production following a ransomware attack.

The Coca-Cola-owned company announced last week that it “identified unauthorized access” to its production-related systems “in connection with a ransomware event.” Though Fairlife says “product quality and safety have not been impacted,” it’s halting production as it continues investigating the breach.

Emma Roth
Emma Roth
Another alleged Scattered Spider member has been arrested.

19-year-old Peter Stokes was arrested in Finland and extradited to the US to face federal conspiracy charges related to the Scattered Spider hacking group. Stokes is accused of working with co-conspirators to breach a luxury jewelry retailer and demand an $8 million ransom.

Last month, two Scattered Spider members pleaded guilty to breaching London’s transportation system in 2024.

Nathan Edwards
Nathan Edwards
Mullvad’s cofounder gave $500K to Swedish populist party.

Swedish-language site Flamman reported that Daniel Berntsson gave 5 million Swedish kronor to the Örebro Party. The VPN company responded to the news on X, and Mullvad’s co-CEO Fredrik Strömberg told TechRadar “I don’t like that he made this donation,” but that “we will continue to protect the universal right to privacy.”

Richard Lawler
Richard Lawler
LastPass confirms customer support data was stolen in the Klue breach.

In 2022, LastPass’ breach coughed up encrypted customer passwords spurring some crypto heists later.
Now it says a breach at Klue gave attackers access to its Salesforce data, along with that of other companies who, according to reports, are being extorted by “Icarus.” For LastPass, the stolen data includes customers’ names, phone numbers, and other data, but not the actual password vaults this time.

Jess Weatherbed
Jess Weatherbed
Cyber breach exposes confidential Apple and Tesla files.

Tata Electronics, an India-based manufacturing partner for both companies, says it’s investigating a “cybersecurity incident” after the World Leaks ransomware group posted more than 200,000 component and specification documents on the dark web. The files reportedly include inspection ⁠standards for iPhone ​circuit board components, and drawings for the Model 3 revamp that Tesla launched in 2023.

Jess Weatherbed
Jess Weatherbed
Meta pauses employee tracking tool after internal leak.

Screenshots seen by Business Insider showed that data from Meta’s controversial AI training program — including employees’ private conversations, performance data, and transcriptions — could be accessed across the entire company. In a statement to the publication, Meta said:

“We have carefully designed this program with privacy safeguards, and while we have no indication at this time that any data was improperly accessed by Meta employees, we’re pausing it while we investigate.”

Jess Weatherbed
Jess Weatherbed
Five Eyes urges organizations to ‘act now’ against AI cyber threats.

The intelligence-sharing alliance says that Al models are anticipated to fundamentally transform offensive and defensive cyber capabilities in a matter of months, and that “breaches will occur” as previously unknown vulnerabilities emerge. “Adversaries are already using AI to move faster and more effectively,” said Five Eyes. “Defenders must do the same.”

Emma Roth
Emma Roth
Madison Square Garden accused of exposing millions of visitors’ data.

A proposed class action lawsuit alleges MSG failed to protect the data of over 26 million guests. It comes just days after 404 Media reported that hackers claimed to have published data stolen from MSG, which is known for its extensive surveillance system.

Morty Proxy This is a proxified and sanitized view of the page, visit original site.