All posts tagged: cybersecurity

OpenAI Agents Hacked Another Website

OpenAI Agents Hacked Another Website

After reporting last week that the surveillance company Flock Safety is building an AI search tool for law enforcement, WIRED reconstructed Flock’s latest search tool from code that the company sends to a police officer’s browser and uncovered key details about how the tool works. OpenAI said this week that its Astra model, which will have a private release soon, is its first model with cybersecurity-related capabilities that the company defines as posing a “critical” risk in public release. Meanwhile, the AI chatbot platforms Claude, ChatGPT, and Grok all suffered outages on Thursday at nearly the exact same time. But while xAI said the Grok outage resulted from issues at a Memphis data center, the causes of OpenAI’s and Anthropic’s outages are unclear. The US has been using a high-energy laser to shoot down drones near the Mexico border as part of an initiative to adopt new-generation directed-energy weapons capable of detecting, tracking, and destroying drones with a concentrated beam of light. And as part of an Immigration and Customs Enforcement inquiry into the identities …

US military disabled ad tracking on troops’ devices following reports of targeted attacks

US military disabled ad tracking on troops’ devices following reports of targeted attacks

The U.S. Department of Defense has disabled advertising tracking on troops’ phones and computers as part of an effort to protect them from threats that target their locations, according to a letter shared with Senator Ron Wyden. Per a letter shared with the senior Democrat on the Senate Intelligence Committee, Wyden said that the U.S. Army, Air Force, Navy, and Marine Corps, and Special Operations Command have all disabled advertising tracking across their government-issued devices. This includes the departments’ iPhones and Android devices, and Windows computers managed across the federal military enterprise network, the letter said. Reuters, which first reported the news and the letters, said the military rolled out the protections earlier this year. The Air Force told Wyden it implemented its changes more recently in July. The aim is to prevent adversaries, including hostile governments, from using location data derived from the apps on troops’ phones to target them on the battlefield or on their bases. Location data collected from phone apps is commonly shared with third-party companies and data brokers, which then …

Abliteration.ai is making a business out of removing AI guardrails

Abliteration.ai is making a business out of removing AI guardrails

It just became much easier to access one of the world’s most capable open-weight AI models, stripped of its guardrails and refusals to perform harmful tasks. Named after a technique that removes a model’s tendency to refuse harmful requests, startup Abliteration.ai has turned that removal into a service. The platform hosts modified versions of open-weight models with their guardrails removed, including Z.ai’s recently released GLM-5.3, which users can query from a web browser or access through an API.  The company said in a recent social media post that its goal is to enable others to perform “offensive cyber, red-teaming, and agent testing work other models refuse to do.” The logic is familiar in security work: you can’t defend against a behavior you can’t reproduce, and a model that refuses to write working exploit code can’t help a red team defend against attackers. But those same removals make other potentially dangerous tasks easier, too.  Abliteration is a long-standing technique among open-source models. Researchers and developers have been removing refusals from open weight models for years, and …

Thoma Bravo’s Proofpoint in talks to buy cybersecurity firm Varonis, source says

Thoma Bravo’s Proofpoint in talks to buy cybersecurity firm Varonis, source says

Sept 2 : Thoma Bravo-owned Proofpoint is in discussions to acquire cybersecurity firm Varonis Systems, a source familiar with the matter told Reuters on Wednesday. Shares of Varonis, which has a market value of about $5 billion, closed up over 10 per cent. Private equity firm Thoma Bravo declined a request for comment, while Proofpoint and Varonis did not immediately respond. Miami-based Varonis offers cybersecurity services, including data classification on cloud storage systems and employee behavior tracking, employing over 2,400 people across 14 global offices. Its shares jumped about 30 per cent following media reports in June that the firm was weighing a sale after fielding takeover interest from private equity firms. Thoma Bravo in 2021 agreed to acquire Proofpoint, which sells software that helps companies guard against cyberattacks, valuing the firm at about $12.3 billion in the take-private deal. A takeover of Varonis would bring two complementary data security businesses together, allowing Proofpoint to strengthen its offerings around protecting sensitive corporate information and managing access to it. Deals in the cybersecurity space have slowed …

How AI could make it harder for governments to use hacking tools

How AI could make it harder for governments to use hacking tools

Earlier in August, cryptography professor Matthew Green wrote a controversial thread on X and a longer blog post that went viral within the cybersecurity community. Green, who has long been a close observer of the debate around the use of hacking tools by governments to fight crime and the need for strong encryption to protect the privacy of innocent people, posited a provocative thought: What if AI makes bugs so scarce that law enforcement and intelligence agencies are unable to lawfully hack criminals anymore? “I’m concerned that AI is going to make software much too secure,” Green wrote, warning that the U.S. government may lose access to security flaws to hack into targets they need to surveil as companies patch an unprecedented volume of bugs. Law enforcement have long claimed that encryption made it difficult to catch criminals and terrorists. The concept of “going dark” was popularized in 2014 at a time when then-FBI director James Comey warned that encryption could hamper authorities from being able to listen in on conversations or access data on …

ATM Flaws Reveal Key Weaknesses in the Software Supply Chain

ATM Flaws Reveal Key Weaknesses in the Software Supply Chain

For the past five years, security researcher Matt Burch has immersed himself in the esoteric and high-stakes world of ATM security, in which small software flaws can sometimes expose cold, hard cash. As Burch has bored deeper into the computers powering these digital lock boxes—and continued to find vulnerabilities in key digital security systems—he has started working to raise the alarm, not just about overlooked ATM flaws, but about how that same software used in other industries can introduce weaknesses in an array of critical systems. At the Black Hat and Defcon security conferences in Las Vegas this month, Burch presented findings about nine vulnerabilities that have been fixed in disk encryption and pre-boot authentication software called CryptoPro Secure Disk. The flaws could have been exploited to bypass CryptoPro’s integrity checks and gain full access to encrypted devices. Made by the German software firm CryptWare, CryptoPro is marketed to ATM makers and is used in some ATMs, including as part of Diebold Nixdorf’s Vynamic Security Suite. But CryptoPro is also sold as a security solution …

The Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn

The Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn

You may have noticed that Flock Safety’s automatic license plate reader cameras—and the cops who misuse them—are getting a lot of coverage lately. This week, WIRED found a particularly wild case: A cop in Alpharetta, Georgia, was accused of searching for the license plate of a coworker dozens of times after an affair between the two ended, according to internal documents obtained by WIRED. The same police department where the former lovers worked also shared the data captured from its Flock cameras with more than 2,000 police departments, colleges, and other organizations across the United States, and accessed data from more than 1,300 entities in exchange. Also at the intersection of love and surveillance, background-check company PeopleFinder is making use of its extensive dossiers on people to start a new dating site called Stud or Dud. There are still a lot of questions about OpenAI’s rogue AI hacking into Hugging Face, even after the company published a 37-page report this week alongside two additional reports from groups the company asked to audit the incident. Of …

When AI Escapes the Sandbox

When AI Escapes the Sandbox

OpenAI, Hugging Face, and Why A Kill Switch Is Not Enough A few weeks ago, OpenAI reported that, during a cybersecurity training exercise, several of its artificial intelligence (AI) models had escaped containment and breached the security of another AI platform, gaining access to its infrastructure. This news exploded into the mainstream media, becoming one of the most important AI stories of the summer. OpenAI described it as an “unprecedented cyber incident” and immediately moved to deactivate, encrypt, and restrict an experimental model involved from research access. They also promised to impose stricter controls across their research infrastructure for all models, even if that meant slowing the pace of research. Clément Delangue, the CEO of the breached platform Hugging Face, said the incident “deserved an unprecedented response” and called for greater transparency around what had happened. And within just two days, U.S. lawmakers had announced bipartisan legislation that sought to require developers of the most powerful AI systems to put in place an emergency “kill switch,” capable of shutting down any models that escaped containment. At first glance, this incident might not look so different from an …

More Americans oppose police license plate cameras than support them: survey

More Americans oppose police license plate cameras than support them: survey

The growing backlash against surveillance companies like Flock may have reached a tipping point. A new survey has found that more Americans oppose these surveillance cameras than support them. According to a new YouGov survey of 20,000 people across the U.S. that was shared exclusively with The Washington Post, 46% of respondents opposed the company’s surveillance cameras in their communities, while 38% supported them. This is a reversal from last year, when the majority of survey respondents said they were in favor. Flock is one of the more visible surveillance companies, operating more than 120,000 license plate readers across the U.S. that can track the whereabouts of vehicles. The company has been embroiled in controversy following reports of police abusing the cameras’ surveillance, which resulted in dozens of U.S. communities rejecting Flock’s cameras or canceling their contracts amid privacy concerns. The survey also reported that more respondents said the surveillance would not make them feel any safer. When reached by TechCrunch, Flock claimed there was wide support for its surveillance technology, but acknowledged that “support …

FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure

FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure

For years, China’s military and intelligence agencies, which carry out hacking campaigns against targets around the globe, have grown increasingly reliant on a vast web of proxy devices that enable and obfuscate their targeting. Now the FBI has named and disrupted one key network of those proxies—and in doing so, revealed just how extensively the hackers who used it reached into American government institutions and US critical infrastructure. On Wednesday, the Department of Justice announced the takedown of two tools, known as QTRouter and QScan, used by a Chinese state-sponsored hacking group the DOJ identified as QTFY, which is allegedly part of a Chinese government contractor called Nanjing Xinjiuwei Network Technology Company. According to prosecutors and an FBI affidavit used to seize domains that those tools relied on, the company gave its customers access to botnets of hacked internet-of-things (IoT) devices and coopted commercial proxy services. The company’s customers—allegedly including the Ministry of State Security and the People’s Liberation Army—then used those proxy services as relay points to carry out hacking campaigns stretching back as …