Skip to main content

Security

Cybersecurity is the rickety scaffolding supporting everything you do online. For every new feature or app, there are a thousand different ways it can break – and a hundred of those can be exploited by criminals for data breaches, identity theft, or outright cyber heists. Staying ahead of those exploits is a full-time job, and one of the most lucrative and sought-after skills in the tech industry. All too often, it’s something up-and-coming companies decide to skip out on, only to pay the price later on.

Dominic Preston
Dominic Preston
I think I see how this could go wrong.

Home security company ADT has acquired Origin Wireless, which can use Wi-Fi signals to detect where people and objects are. An appropriately named commenter recognizes there might be some cause for concern.

PerpetuallySkeptical:

I’m sure that paying a company to see exactly where I am in my house at all times won’t be used against me in the future.

Get the day’s best comment and more in my free newsletter, The Verge Daily.

Jay Peters
Jay Peters
ChatGPT is getting a Lockdown Mode.

Lockdown Mode is “not necessary” for most people and “tightly constrains how ChatGPT can interact with external systems to reduce the risk of prompt injection–based data exfiltration,” according to OpenAI.

Jay Peters
Jay Peters
Wyze is sticking it to Ring.
Terrence O'Brien
Terrence O'Brien
OpenClaw is scanning AI skills after hundreds of malicious add-ons were found on ClawHub.

Researchers raised alarms when over 400 malicious skills were uploaded to ClawHub and GitHub in just one week. That prompted an outcry, so OpenClaw partnered with VirusTotal to scan third-party skills. The company acknowledges it’s not a “silver bullet,” but it should provide at least some reassurance to concerned users.

Emma Roth
Emma Roth
Is Moltbook really a “social network” for AI agents?

404 Media reports that security researcher Jamieson O’Reilly found a vulnerability that allows humans to control OpenClaw’s AI agents on Moltbook — the network that recently went viral for hosting “discussions” between supposed AI bots.

Wiz dug into the misconfiguration as well, uncovering 1.5 million exposed API keys and 35,000 email addresses. Moltbook has since secured the database.

Elissa Welle
Elissa Welle
500 dashcams in Minneapolis.

Two days after Nick Benson asked for donated dashcams in order to document the behavior of federal immigration agents flooding his city, Renee Nicole Good was shot and killed by federal agent Jonathan Ross.

”It was immediately clear that ICE was lying about it,” Benson told 404 Media. Donations have jumped since then, and Benson distributes the cameras to local community organizers and whoever wants them.

Jay Peters
Jay Peters
Betterment shares more detail about last week’s crypto scam message.

The company says an “unauthorized individual gained access to certain Betterment systems through social engineering” to send the message on Friday. Betterment believes the individual accessed information like “certain names, email addresses, physical addresses, phone numbers, and birthdates,” though so far, its investigation has shown that no passwords were compromised.

Terrence O'Brien
Terrence O'Brien
Don’t click anything in that Instagram password reset email, no matter how official it looks.

Seems a lot of people got password reset requests from Instagram over the last few days, including several Verge staffers and members of their family. The email might look legit. It might even have that little blue checkmark in Gmail. But, it probably came from a scammer. Honestly, it’s best practice to never click links in emails anyway.

Emma Roth
Emma Roth
Aflac says a data breach impacted 22.65 million of its customers.

In June, Aflac disclosed a data breach involving a “sophisticated cybercrime group” that stole names, social security numbers, contact information, health data, and more from its systems. The insurance provider has now revealed just how many people are affected, adding that it is currently “not aware of any fraudulent use of personal information.”

Emma Roth
Emma Roth
Hack drains $7 million in crypto from Binance’s Trust Wallet.

On Thursday, Trust Wallet announced a “security incident” affecting version 2.68 of its Chrome extension. Binance founder Changpeng Zhao confirmed that Trust Wallet “will cover” the losses and that the team is investigating the hack.

Jess Weatherbed
Jess Weatherbed
Android expands in-call scam protections to the US.

The feature was first piloted in the UK earlier this year, and works by automatically warning users when they launch eligible financial apps while screen sharing during calls with numbers that aren’t in the device’s contact list. The warning forces a 30-second pause period that aims to “break the spell of the scammers’ social engineering,” according to Google.

A scam warning message displayed on an Android phone.
The warning message will also provide guidance on how to avoid being scammed and prompt users to end the call.
Image: Google
Elissa Welle
Elissa Welle
AI annotators overseas may be reviewing Flock license plate camera footage from the US.

An exposed dataset from the license plate surveillance company Flock, which is known to work with the US Border Patrol and ICE via local police, showed that some of the AI annotators paid to classify American license plates are located in the Philippines.

After 404 Media contacted Flock for comment, the dataset disappeared.

Screenshot of the exposed material from the surveillance company Flock, as spotted by 404 Media.
Screenshot of the exposed material from the surveillance company Flock, as spotted by 404 Media.
Image: 404 Media
The VPN panic is only getting startedThe VPN panic is only getting started
Dominic Preston
Elissa Welle
Elissa Welle
Amazon is investing billions in data centers for the feds.

The infrastructure buildout will add nearly 1.3 gigawatts of capacity for AI and cost up to $50 billion, the company said. US government customers will have access to both AWS Trainium AI chips and NVIDIA chips, and Amazon said it plans to start building the data centers in 2026.