Security

Sneak Attack
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
Researchers say it took fewer than 20 prompts for a public AI tool to find a flaw (now fixed) allowing anyone on a Zoom call to hijack another participants’ device.
Lily Hay Newman

Security Roundup
Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed
Dell Cameron and Dhruv Mehrotra

Return to Sender
Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All
Matt Burgess

Hackers Stalked Me by Hijacking a Smartwatch for Kids
Security researchers tracked and eavesdropped on a WIRED reporter using vulnerabilities in a pink plastic smartwatch. It’s just one piece of a deeply insecure supply chain of GPS-enabled gadgets.
Andy Greenberg, Matt Burgess, and Yulia Almazova

OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
At the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies—and did it all right under the company’s nose.
Lily Hay Newman

A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers. His work shows they pulled off intrusions in a shocking number of systems across the globe.
Matt Burgess and Andy Greenberg

OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
Researchers at security firm Zenity found more than a dozen flaws in AI browsers—and managed to get OpenAI’s Atlas to make an unauthorized Amazon purchase.
Matt Burgess

DHS Wants Protesters’ Signal Group Chats
A lawsuit accuses Homeland Security of violating protesters’ free-speech rights—but the agency is using it to try to get access to the plaintiffs’ encrypted communications.
Maddy Varner

DHS Is Hiring Bounty Hunters to Find and Photograph Deported People’s Homes Abroad
Homeland Security told immigrants that leaving the US would wipe out fines it claims they owe. Now it wants private investigators to find them in their home countries and collect.
Dell Cameron and Maddy Varner

Hugging Face Has a Deepfake Nudes Problem
Researchers tested top image editing models on Hugging Face and found they could easily create explicit deepfakes—and 1,000 image editing prompts show how people use the software.
Matt Burgess

Private Claude Chats Exposed in Google and Bing Search Results
The screwup shows how tricky it can be to stop web crawlers from making ostensibly private conversations with AI chatbots entirely too public.
Maddy Varner

The Password Managers You Should Use Instead of Your Browser
Keep your logins locked down with our favorite password management apps for PC, Mac, Android, iPhone, and web browsers.
Scott Gilbertson

You Can Disable Gemini in Chrome if It’s Freaking You Out
Chrome users were caught off guard by a 4-GB Google AI model baked into Chrome, sparking privacy concerns. The good news: You can easily uninstall it. The bad? You might not want to.
Lily Hay Newman
How the Internet Broke Everyone’s Bullshit Detectors
From AI-generated images to restricted satellite data, the systems used to verify what’s real online are struggling to keep up.
Gia Chaudry

How to Organize Safely in the Age of Surveillance
From threat modeling to encrypted collaboration apps, we’ve collected experts’ tips and tools for safely and effectively building a group—even while being targeted and tracked by the powerful.
Andy Greenberg and Lily Hay Newman

Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
More than 50 offending image and video ads were published across Facebook, Instagram, Messenger, or Threads, according to Meta’s ad library data. Some ran as recently as this week.
Matt Burgess

Landmark Deal Would Officially Add Laser Weapons to US Army Arsenal
Facing a growing drone threat, the Pentagon is poised to sign a first-of-its-kind contract for “Enduring High Energy Lasers”—and make directed energy weapons an official part of the Army’s kit.
Noah Shachtman

ICE Collected Nearly 1 Million People’s DNA Last Year—Including Young Children
Internal documents show ICE's DNA collection has skyrocketed in the second Trump administration. Now hundreds of thousands of people never convicted of a crime are in an FBI criminal database forever.
Dhruv Mehrotra

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.
Matt Burgess, Maddy Varner, Dell Cameron, and Andy Greenberg
Latest



Uncharted Waters
The OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal Frontier
Lily Hay Newman

Escaped Room
Anthropic Says Claude Hacked Into 3 Organizations During Cybersecurity Tests
Louise Matsakis and Lily Hay Newman

Infrastructure Weak
A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
Andy Greenberg






Bigger Breach
OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
Dell Cameron and Maxwell Zeff



Security Roundup
The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days
Lily Hay Newman and Dhruv Mehrotra


Private Party
For Taylor Swift, Madison Square Garden’s Controversial Cameras Briefly Went Dark
Noah Shachtman


Rogue Agents
OpenAI Models Escaped Containment and Hacked Hugging Face
Lily Hay Newman and Dell Cameron

Inside Job
A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots
Lily Hay Newman
