Posts

Showing posts from July, 2026

The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key

Created by legendary hardware hacker Andrew “bunnie” Huang, the badges for this year’s famed security conference aim to push the boundaries of security and transparency. from Security Latest https://ift.tt/UOxCFvp

Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting

The two Chrome updates in June patched more bugs than the 23 updates before them. Now, Google is ramping up its patching schedule thanks to AI-assisted vulnerability discovery. from Security Latest https://ift.tt/qlouyx0

A Civilian Plane Crashed in New Mexico. Was the Military’s Tech to Blame?

Drone warfare is making the skies more dangerous, even for airplanes far from the battlefield. from Security Latest https://ift.tt/17dIpke

AI Scammers Are Better at Building Trust Than Humans

Researchers pitted a person against a Claude agent and found that, after a week of texting, the AI chatbot was more effective at creating “exploitable trust” with others. from Security Latest https://ift.tt/bq9cZWx

ICE’s New Detention Center Contracts Declare State Laws ‘Shall Not Apply’

One day after a federal judge ordered an ICE detention center opened to state health inspectors, the agency posted new contract terms that would void state oversight at four facilities. from Security Latest https://ift.tt/mip0H8U

OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face

In a new disclosure, OpenAI says its agent used exposed logins to gain access to at least four “publicly available services” in its unhinged quest to solve a test. from Security Latest https://ift.tt/xpPmAeT

A Typo Landed an Innocent Gamer in Prison for 18 Months

How much could a single underscore in a username really matter? Just ask Brandon Klayme, who served 18 months in prison before realizing how authorities arrested, charged, and convicted the wrong man. from Security Latest https://ift.tt/xkKtQ9M

Hugging Face Has a Deepfake Nudes Problem

Researchers tested top image editing models on Hugging Face and found they could easily create explicit deepfakes—and 1,000 image editing prompts show how people use the software. from Security Latest https://ift.tt/GqbjdUK

Private Claude Chats Exposed in Google and Bing Search Results

The screwup shows how tricky it can be to stop web crawlers from making ostensibly private conversations with AI chatbots entirely too public. from Security Latest https://ift.tt/IghLEm9

The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days

Plus: Russian hackers are trying to steal US nuclear scientists’ emails, the State Department bans known scammers from entering the United States, and more. from Security Latest https://ift.tt/bTpXUVk

Satellite Images Reveal How Suspected Scam Compounds Appear Out of Nowhere

Analysis of satellite images of Myanmar shows dozens of alleged scam compounds have appeared in recent months, despite a purported crackdown on the criminal organizations. from Security Latest https://ift.tt/nSPirkO

For Taylor Swift, Madison Square Garden’s Controversial Cameras Briefly Went Dark

MSG’s sprawling surveillance system can monitor guests down to the second. Its owners made an exception for the pop star’s rehearsal dinner. from Security Latest https://ift.tt/jlMtZhw

States Want ICE Agents to Show Their Faces. The Trump Administration Is Blocking Them

Federal lawyers say anti-mask laws would endanger immigration agents, citing an ICE face-recognition art project that doesn’t actually work. from Security Latest https://ift.tt/PBTvrgl

OpenAI Models Escaped Containment and Hacked Hugging Face

The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack. from Security Latest https://ift.tt/8irCT4F

A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots

A new type of malware can worm deep into AI coding systems to steal data and logins—and can flip a “death switch” to destroy files and keep out real users. from Security Latest https://ift.tt/aGmuXNy

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

Dealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars. from Security Latest https://ift.tt/A9VSh7j

The ACLU Is Arming Lawyers to Expose State Surveillance Secrets

A new toolkit for attorneys in Massachusetts targets the technologies police use—and conceal—to build criminal cases, from facial recognition to AI-written police reports. from Security Latest https://ift.tt/eozOM0f

Apps Marketed to US Troops Are Shipping Chinese and Russian Code

A first-of-its-kind analysis found more than one in eight apps built for US service members carried foreign code—some from firms in nations the Pentagon designates as adversaries. from Security Latest https://ift.tt/pEbi9KJ

Your Period Tracker Is (Probably) Spying on You

Plus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more. from Security Latest https://ift.tt/VrQ2fGh

Prompt Injection Attacks Are Thwarting AI Hacking Agents

“Context bombing” tricks malicious AI agents into shutting down before they can do harm. from Security Latest https://ift.tt/M1dt3Qq

San Francisco Demands Apple and Google Delete AI ‘Nudify’ Apps From App Stores

The City Attorney’s Office sent the tech giants cease-and-desist letters this week telling them to stop profiting from 13 “face-swap” apps that are overwhelmingly used to target women and girls. from Security Latest https://ift.tt/YxXJEM6

Here’s the Truth About Whether Meta’s NameTag Face Recognition Tech ‘Exists’

Since WIRED reported on Meta’s NameTag face recognition system, company executives have made confusing and conflicting remarks about its very existence. from Security Latest https://ift.tt/eVXRwSp

A Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban Surveillance

The SFPD’s exposure of hours of videos from drone platform Skydio reveals how broadly it’s watching the city from above—and how the results can spill online. from Security Latest https://ift.tt/JDt4eq7

AI Found a Root Bug in Linux That Everyone Missed for 15 Years

Plus: The Pentagon is training amateurs to become part of its hacker army, a Flock license plate reader error led to cops surrounding a car reviewer, and more. from Security Latest https://ift.tt/h3KRgx4

A Majority of European Lawmakers Voted Against Letting Big Tech Read Our Messages. They’re Going to Anyway.

Companies will once again be allowed to scan citizens’ personal texts, emails, and social media messages via the “chat control” bill to find child abuse material online. from Security Latest https://ift.tt/XzDNVeF

Madison Square Garden Kept a List of Gay Celebrities

An MSG database tracked and categorized hundreds of celebs, famous Knicks superfans, and even some of Taylor Swift’s wedding guests. Labels included “LGBTQIA,” “DO NOT HOST,” and low to high “risk.” from Security Latest https://ift.tt/9gvU3jr

What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out

Burst water mains. Evacuated hospitals. In a closed-door simulation, insurers played out their response to a mass disruption by China’s Volt Typhoon hackers—and found a nightmare scenario. from Security Latest https://ift.tt/lEq1gK3

ICE’s Internal Watchdog Is Now Investigating Online Critics

The Office of Professional Responsibility has opened more than 100 cases over what ICE officials call “incidents of doxing and threats” against ICE employees. from Security Latest https://ift.tt/G6wKvYF

Security Roundup: Apple’s Hide My Email Service Fails to Hide Your Email

Plus: Alleged Scattered Spider hacking member extradited, dozens of license plate reader errors, and Indian officials are concerned about WhatsApp’s username rollout. from Security Latest https://ift.tt/LWMIh5f

EU Politicians Investigated Pegasus Spyware. Then It Ended Up on One of Their Phones

“It is a direct attack on the rule of law,” says one European Parliament member of the new findings from Citizen Lab. from Security Latest https://ift.tt/R236TId

Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival

A researcher found that using Anthropic’s Claude Opus 4.7, he could break into the website of Front Gate—used by every festival from Lollapalooza to Bonnaroo—and freely issue any ticket he chose. from Security Latest https://ift.tt/PpAJGUZ