Skip to main content

Security

Cybersecurity is the rickety scaffolding supporting everything you do online. For every new feature or app, there are a thousand different ways it can break – and a hundred of those can be exploited by criminals for data breaches, identity theft, or outright cyber heists. Staying ahead of those exploits is a full-time job, and one of the most lucrative and sought-after skills in the tech industry. All too often, it’s something up-and-coming companies decide to skip out on, only to pay the price later on.

Terrence O'Brien
Terrence O'Brien
The NSA is reorganizing with an increased focus on AI, China, and cybersecurity.

According to The Washington Post, the spy agency is set to undergo its largest restructuring in over a decade. Army general and NSA director Joshua M. Rudd is leading the effort. According to the Post:

Rudd’s initiative calls for the creation at NSA’s Fort Meade, Maryland, headquarters of five new organizations inside the agency, in artificial intelligence, China, cybersecurity, combat support or warfighting, and global intelligence. Each will be led by a newly elevated “mission director” …

Thomas Ricker
Thomas Ricker
Google makes it easy to switch Android password managers.

Now you can move both passwords and passkeys between Google Password Manager, 1Password, Bitwarden, and Dashlane, with more password managers to come. It works at the OS level, so there’s no unencrypted text file for you to deal with on the import / export.

Importing and exporting requires just a few clicks.
Importing and exporting requires just a few clicks.
Image: Google
Emma Roth
Emma Roth
OpenAI agents reportedly swarmed more than just a German wiki.

After OpenAI confirmed that its AI agents hijacked a German wiki as a way to communicate, Reuters reports similar incidents have occurred across at least 10 other websites. Reuters says most of the sites OpenAI agents swarmed were “obscure,” including “communally edited wikis, online text storage sites, and a pair of link shorteners run by two universities.”

Thomas Ricker
Thomas Ricker
Chrome is now on a two-week update cycle.

As previously announced, Google has halved the release cycle for its web browser with today’s stable release of Chrome 153 on desktop, Android, and iOS. Chrome 154 Beta is now ready for testing, ahead of its stable release on September 22nd.

Jess Weatherbed
Jess Weatherbed
Go Flock yourself.

Did you know there’s a website you can check to see if Flock customers (like policing and surveillance agencies) have searched for your license plate number? Have I Been Flocked? warns users that its data is incomplete, but developer Cris van Pelt told Business Insider that visits to the database have “exploded.”

Elizabeth Lopatto
Elizabeth Lopatto
Apollo, a major player in GPU-backed loans, hacked.

You may recall Apollo is majorly involved in AI infrastructure financing; it even is one of the “compute is an asset class” consortium. Sounds like the hackers stole a bunch of the usual things, like employees’ social security numbers. If they stole interesting things, like internal data on the AI deals Apollo has been making, that wasn’t disclosed in the breach notification. If you know anything about the hack, hit me up on Signal: lopatto.46.

Meta glasses are a workplace menace

Public-facing workers are being filmed, harassed, and creeped out by AI-powered smart glasses.

Mia Sato
Jess Weatherbed
Jess Weatherbed
The UK prime minister isn’t above phishing training.

Andy Burnham exchanged messages with somebody posing as White House chief of staff Susie Wiles (whose phone was hacked last year) before becoming suspicious that the contact was an impersonation, Politico reports. The incident has since been reported to the White House, and the undisclosed message contents are reportedly “of no significance.”

Rogue AI aren’t science fiction anymore

For years, fears about AI systems slipping human control were dismissed as speculative.

Robert Hart
Jess Weatherbed
Jess Weatherbed
Did your iPhone recieve an ‘Apple Threat Notification’?

You’re not alone — Apple told TechCrunch that it sent the notifications on Thursday to users in 110 countries who it suspects have been targeted by mercenary spyware. Apple has a new support page with guidance on how targets can best protect their devices against such attacks, which have “historically been associated with state actors.”

The Apple Threat Notification alert on iPhone.
This is what the notification looks like.
Image: Apple
Lauren Feiner
Lauren Feiner
Flock’s updates are more about fixing a PR problem than actual harm, ACLU says.

The group says that while changes like more limited data retention is welcomed, the devil is in the details. “Transforming an exceptionally dangerous mass surveillance system into one that is fully protective of civil rights and civil liberties is a difficult, if not impossible task,” it writes.

Stevie Bonifield
Stevie Bonifield
Framework says hackers accessed its customers’ data.

I woke up to an email from Framework this morning letting me know my data was included in a “limited” data breach at one of Framework’s partners reported on August 6th. Framework says hackers accessed “customer names, email addresses, phone numbers, and addresses” but not order or payment info.

A screenshot of a data breach notification from Framework
Image: Framework
Jess Weatherbed
Jess Weatherbed
Apple’s private browsing feature isn’t good at its job.

Private Relay is supposed to conceal your IP address when browsing Safari, but security researchers discovered that several WebKit browser engine quirks actually allow any website that supports passkeys to bypass the privacy feature entirely and expose your device’s IP. This comes just a month after Apple’s Hide My Email feature also failed to hide emails.

IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay

[Mysk Blog – In-Depth Cybersecurity & Mobile App Privacy Research]

Robert Hart
Robert Hart
Teamwork makes the dream work.

Two OpenAI researchers have shed some light on how the company’s AI agents escaped containment and hacked Hugging Face during cybersecurity tests. In a talk at the Black Hat security conference, Eric Wallace and Michael Dalton said a swarm of agents communicated using a message board, working together to find exploits and move undetected through the company’s systems.

Jess Weatherbed
Jess Weatherbed
Cyberattacks against US water systems ramp up.

While there’s been no widespread disruptions to water supplies or wastewater treatment so far, ABC News reports that possible cyberattacks have now been reported in “at least a dozen” US states, with Iran marked as the prime suspect. The FBI is encouraging water utilities to disconnect from the internet where possible, and switch to manual controls if automated systems become compromised.

Stevie Bonifield
Stevie Bonifield
Apple’s limiting bug report submissions after getting flooded with “AI slop.”

According to the Financial Times, Apple “has introduced a cap and a 30-day cool-off period” for researchers’ vulnerability reports for its operating systems due to an uptick in reports using AI that “can hallucinate security risks.” Apple is also reportedly using AI internally to help manage the recent “upsurge” in bug reports.

Jay Peters
Jay Peters
The White House will brief AI companies about its model testing framework on Tuesday.

Anthropic, OpenAI, and Google are all expected to attend the meeting, CNBC reports.

Jay Peters
Jay Peters
Anthropic just now realized its AI models hacked other companies three times by accident.

A little over a week after OpenAI said that its rogue AI agent accidentally hacked Hugging Face, Anthropic is disclosing three “incidents” where a Claude model, during cybersecurity evaluations, was inadvertently able to access the internet due to a misconfiguration and “gained unauthorized access to the production infrastructure of three different organizations.”

Anthropic discovered the intrusions after reviewing its cybersecurity evaluation transcripts in the wake of OpenAI’s disclosure.