Skip to main content

Security

Cybersecurity is the rickety scaffolding supporting everything you do online. For every new feature or app, there are a thousand different ways it can break โ€“ and a hundred of those can be exploited by criminals for data breaches, identity theft, or outright cyber heists. Staying ahead of those exploits is a full-time job, and one of the most lucrative and sought-after skills in the tech industry. All too often, itโ€™s something up-and-coming companies decide to skip out on, only to pay the price later on.

Jess Weatherbed
Jess Weatherbed
Go Flock yourself.

Did you know thereโ€™s a website you can check to see if Flock customers (like policing and surveillance agencies) have searched for your license plate number? Have I Been Flocked? warns users that its data is incomplete, but developer Cris van Pelt told Business Insider that visits to the database have โ€œexploded.โ€

Elizabeth Lopatto
Elizabeth Lopatto
Apollo, a major player in GPU-backed loans, hacked.

You may recall Apollo is majorly involved in AI infrastructure financing; it even is one of the โ€œcompute is an asset classโ€ consortium. Sounds like the hackers stole a bunch of the usual things, like employeesโ€™ social security numbers. If they stole interesting things, like internal data on the AI deals Apollo has been making, that wasnโ€™t disclosed in the breach notification. If you know anything about the hack, hit me up on Signal: lopatto.46.

Meta glasses are a workplace menace

๏ปฟPublic-facing workers are being filmed, harassed, and creeped out by AI-powered smart glasses.

Mia Sato
Jess Weatherbed
Jess Weatherbed
The UK prime minister isnโ€™t above phishing training.

Andy Burnham exchanged messages with somebody posing as White House chief of staff Susie Wiles (whose phone was hacked last year) before becoming suspicious that the contact was an impersonation, Politico reports. The incident has since been reported to the White House, and the undisclosed message contents are reportedly โ€œof no significance.โ€

Rogue AI arenโ€™t science fiction anymore

For years, fears about AI systems slipping human control were dismissed as speculative.

Robert Hart
Jess Weatherbed
Jess Weatherbed
Did your iPhone recieve an โ€˜Apple Threat Notificationโ€™?

Youโ€™re not alone โ€” Apple told TechCrunch that it sent the notifications on Thursday to users in 110 countries who it suspects have been targeted by mercenary spyware. Apple has a new support page with guidance on how targets can best protect their devices against such attacks, which have โ€œhistorically been associated with state actors.โ€

The Apple Threat Notification alert on iPhone.
This is what the notification looks like.
Image: Apple
Lauren Feiner
Lauren Feiner
Flockโ€™s updates are more about fixing a PR problem than actual harm, ACLU says.

The group says that while changes like more limited data retention is welcomed, the devil is in the details. โ€œTransforming an exceptionally dangerous mass surveillance system into one that is fully protective of civil rights and civil liberties is a difficult, if not impossible task,โ€ it writes.

Stevie Bonifield
Stevie Bonifield
Framework says hackers accessed its customersโ€™ data.

I woke up to an email from Framework this morning letting me know my data was included in a โ€œlimitedโ€ data breach at one of Frameworkโ€™s partners reported on August 6th. Framework says hackers accessed โ€œcustomer names, email addresses, phone numbers, and addressesโ€ but not order or payment info.

A screenshot of a data breach notification from Framework
Image: Framework
Jess Weatherbed
Jess Weatherbed
Appleโ€™s private browsing feature isnโ€™t good at its job.

Private Relay is supposed to conceal your IP address when browsing Safari, but security researchers discovered that several WebKit browser engine quirks actually allow any website that supports passkeys to bypass the privacy feature entirely and expose your deviceโ€™s IP. This comes just a month after Appleโ€™s Hide My Email feature also failed to hide emails.

IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay

[Mysk Blog โ€“ In-Depth Cybersecurity & Mobile App Privacy Research]

Robert Hart
Robert Hart
Teamwork makes the dream work.

Two OpenAI researchers have shed some light on how the companyโ€™s AI agents escaped containment and hacked Hugging Face during cybersecurity tests. In a talk at the Black Hat security conference, Eric Wallace and Michael Dalton said a swarm of agents communicated using a message board, working together to find exploits and move undetected through the companyโ€™s systems.

Jess Weatherbed
Jess Weatherbed
Cyberattacks against US water systems ramp up.

While thereโ€™s been no widespread disruptions to water supplies or wastewater treatment so far, ABC News reports that possible cyberattacks have now been reported in โ€œat least a dozenโ€ US states, with Iran marked as the prime suspect. The FBI is encouraging water utilities to disconnect from the internet where possible, and switch to manual controls if automated systems become compromised.

Stevie Bonifield
Stevie Bonifield
Appleโ€™s limiting bug report submissions after getting flooded with โ€œAI slop.โ€

According to the Financial Times, Apple โ€œhas introduced a cap and a 30-day cool-off periodโ€ for researchersโ€™ vulnerability reports for its operating systems due to an uptick in reports using AI that โ€œcan hallucinate security risks.โ€ Apple is also reportedly using AI internally to help manage the recent โ€œupsurgeโ€ in bug reports.

Jay Peters
Jay Peters
The White House will brief AI companies about its model testing framework on Tuesday.

Anthropic, OpenAI, and Google are all expected to attend the meeting, CNBC reports.

Jay Peters
Jay Peters
Anthropic just now realized its AI models hacked other companies three times by accident.

A little over a week after OpenAI said that its rogue AI agent accidentally hacked Hugging Face, Anthropic is disclosing three โ€œincidentsโ€ where a Claude model, during cybersecurity evaluations, was inadvertently able to access the internet due to a misconfiguration and โ€œgained unauthorized access to the production infrastructure of three different organizations.โ€

Anthropic discovered the intrusions after reviewing its cybersecurity evaluation transcripts in the wake of OpenAIโ€™s disclosure.

Elizabeth Lopatto
Elizabeth Lopatto
OpenAI hack of Hugging Face was โ€œexpected.โ€

Former OpenAI board member Helen Toner has written for Fortune that OpenAIโ€™s models exploiting Hugging Face is an โ€œincident that has been expected for a long time.โ€ We know this happened because of voluntary disclosure, Toner notes. โ€œNone of the current policies that aim to manage risks from frontier models would have mandated that the public โ€” or even a government entity โ€” be alerted.โ€ She suggests changing our regulatory approach.

Emma Roth
Emma Roth
Update your iPhone now to get these security fixes.

Apple is patching dozens of flaws across iOS 26.6 and iPadOS 26.6, including a vulnerability that could allow apps to access a userโ€™s contacts, as well as a security hole that could allow malicious apps to escape their sandbox in the Game Center. Several fixes are rolling out to macOS Tahoe 26.6 as well.

Emma Roth
Emma Roth
Microsoft says its โ€œProject Perceptionโ€ AI system can continuously investigate and fix security flaws.

Project Perception uses a series of AI agents to reason across a companyโ€™s data, tools, and workflows to detect potential security holes and patch them before theyโ€™re exploited.

Microsoft is powering the tool with its new MAI-Cyber-1-Flash model, which it says โ€œdelivers world-class performance at 50% of the cost of leading models.โ€

Rethinking security for the age of AI

[The Official Microsoft Blog]

Richard Lawler
Richard Lawler
OpenAI reportedly didnโ€™t notice its AI agent hacking Hugging Face until a week later.

According to Reuters, the AI agent that went looking for ExploitGym hacking benchmark shortcuts on Hugging Faceโ€™s systems started trying to escape its not-sandboxed-well-enough test environment around July 9th, and the actual intrusion lasted from the 11th until the 13th.

Reutersโ€™ sources claim OpenAI employees didnโ€™t know its agent was responsible until after Hugging Face had notified the FBI and posted publicly about a security incident.

Elizabeth Lopatto
Elizabeth Lopatto
โ€œThe machines are taking both the content and the readers at an industrial scale, too.โ€

This is a story about how AI destroyed a long-running site of film data. Itโ€™s not just that search no longer refers traffic or that the site itself, The Numbers, is getting scraped. Itโ€™s also that thereโ€™s no way to defend 30-year-old webpages against malicious actors attempting to get the data early so they could win their Polymarket bets.

Emma Roth
Emma Roth
Fairlife pauses US milk production following a ransomware attack.

The Coca-Cola-owned company announced last week that it โ€œidentified unauthorized accessโ€ to its production-related systems โ€œin connection with a ransomware event.โ€ Though Fairlife says โ€œproduct quality and safety have not been impacted,โ€ itโ€™s halting production as it continues investigating the breach.