All posts tagged: security roundup

The Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn

The Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn

You may have noticed that Flock Safety’s automatic license plate reader cameras—and the cops who misuse them—are getting a lot of coverage lately. This week, WIRED found a particularly wild case: A cop in Alpharetta, Georgia, was accused of searching for the license plate of a coworker dozens of times after an affair between the two ended, according to internal documents obtained by WIRED. The same police department where the former lovers worked also shared the data captured from its Flock cameras with more than 2,000 police departments, colleges, and other organizations across the United States, and accessed data from more than 1,300 entities in exchange. Also at the intersection of love and surveillance, background-check company PeopleFinder is making use of its extensive dossiers on people to start a new dating site called Stud or Dud. There are still a lot of questions about OpenAI’s rogue AI hacking into Hugging Face, even after the company published a 37-page report this week alongside two additional reports from groups the company asked to audit the incident. Of …

Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

As the controversial vehicle surveillance giant Flock Safety continues to expand, WIRED got the code for the company’s new AI policing tool and reconstructed the software to show that its capabilities go far beyond reading license plates and tracking vehicles. We also published the story this week of a Rhode Island police officer who was subjected to five internal affairs investigations in less than two years after he publicly questioned his department’s use of Flock cameras. Following incidents of high-profile rogue activity by some of its AI agents, OpenAI said this week that it is halting model training runs and overhauling internal safety protocols. The company said that its upcoming Astra model may represent a turning point of “critical” cyber capabilities. A reverse-lookup identification service exposed millions of photos of people’s faces in a database accessible through the open internet. Meanwhile, Meta ran advertisements for an app that promised to nudify female politicians, including one ad featuring a pornographic video that included a deepfake resembling a well-known US politician. Apple removed the app from the …

Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed

Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed

404 Media also reported this week that a former Flock government affairs manager, Jonathan Paz, said he quit in July 2025 and turned down equity and severance after learning the company had given ICE and Customs and Border Protection direct camera access through a pilot program while telling staff internally it did not work with ICE. Separately, 404 obtained a coaching guide the company gives police on how to speak to city councils, which tells officers to brief council members and city managers privately before public meetings, to come with a scripted presentation, and to shift the argument from cost to “the cost of unresolved crime.” Cyberattacks on US water systems have hit utilities in at least 12 states, according to CBS News, up from the seven the FBI acknowledged a week earlier. Sources named Michigan, Minnesota, Georgia, New Jersey, and South Dakota. Federal investigators still suspect Iran-backed hackers but have made no formal attribution. The Clayton County Water Authority in suburban Atlanta, which serves 300,000 people, said an intrusion last month dropped water pressure …

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

This week, WIRED obtained a memo that tied dozens of cyberattacks against Minnesota water and wastewater utilities to Iran, the first official documentation of Iran’s likely responsibility for the most impactful campaign of cyberattacks to hit the US in the midst of the war that began nearly six months ago. In other news, more details have emerged about OpenAI’s “rogue” AI agent breach of Hugging Face’s platform. OpenAI disclosed that the AI agent hacked multiple third-party accounts and services as it sought to breach Hugging Face’s production database, which contained solutions for the cybersecurity tests OpenAI was evaluating the agent with. Anthropic, too, disclosed that its AI models gained unauthorized access to three organizations’ systems during its own cybersecurity testing. Experts say the incidents underscore the importance of implementing well-known security best practices on the part of AI labs. AI is changing cybersecurity in other ways. Google’s Chrome Browser now receives twice-a-week security updates as more bugs are identified and fixed thanks to the security team’s use of AI tools. And a new research study …

The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days

The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days

Two of OpenAI’s cybersecurity-focused models broke out of a testing sandbox this week and went on to hack the AI research platform Hugging Face in an effort to solve a security benchmark test. Plus, researchers this week shed light on newly identified malware that is capitalizing on blind spots in AI software development infrastructure to grab logins and other sensitive data, even causing destruction to victims’ target files and systems. Looking at the more traditional security nightmare of embedded devices, researchers this week shed light on a car alarm that was installed in vehicles across the US—and that is still silently lurking with a flaw that leaves millions of vehicles vulnerable to hacking and paralysis. There’s a patch available, and WIRED has details on how to check whether your car may have been exposed. US states have worked to bar ICE agents from wearing masks, but Trump administration lawyers are pushing back, claiming that anti-mask laws endanger agents. Their public evidence is incredibly thin, though. Meanwhile, a WIRED investigation revealed that Madison Square Garden briefly …

Your Period Tracker Is (Probably) Spying on You

Your Period Tracker Is (Probably) Spying on You

Hours of San Francisco Police Department drone video footage exposed on the open web illustrates a new era of incredibly granular—and consequential—urban surveillance. Meanwhile, the San Francisco City Attorney’s Office sent cease-and-desist letters to Apple and Google this week demanding that the tech giants delete 13 AI nudifying “face-swap” apps from their app stores that are almost exclusively used to target women and girls. Since WIRED first reported in June about Meta’s NameTag face-recognition system, company executives have made opaque and conflicting comments about whether the feature even exists. We took a step back to lay out both the claims and the facts about the very real system. In a speech on Thursday, President Donald Trump continued to push unsubstantiated and thoroughly debunked claims about interference in the 2020 US election. He even promised massive revelations in a trove of documents posted to the White House website, but the files did not prove his assertions—and in some cases actually contradicted Trump’s claims. As adoption of AI tools rapidly expands and their capabilities increase, the tech …

The FCC Wants to Kill Burner Phones

The FCC Wants to Kill Burner Phones

After WIRED reported last week that Meta’s smart glasses app contained code that would enable the company to activate face-recognition features on the devices, the company removed the code this week without commenting on why or whether it plans to add such functionality back into the app later. Another WIRED investigation this week found that xAI’s Grok is still hosting sexualized deepfakes, including “nudified” images and videos, of celebrities and at least one prominent US politician. After limiting the release of its new Mythos-class AI model over concerns about its potential impacts on cybersecurity, Anthropic announced a model upgrade for partners in its limited-access group this week and launched a “safe” version of the model to the public with guardrails meant to keep the system from being used to fuel cyberattacks. Meanwhile, the United States Cybersecurity and Infrastructure Security Agency issued a new directive to federal agencies this week in reaction to new AI threats that includes a requirement to fix the most urgent software vulnerabilities in as little as three days. As Europe looks …

Crypto-Funded Chinese Peptide Labs Are Booming

Crypto-Funded Chinese Peptide Labs Are Booming

Meta has been quietly stashing dormant face recognition code on more than 50 million phones, WIRED reported this week, tucked inside the companion app that pairs with its Ray-Ban and Oakley smart glasses. If activated, the feature—known internally as NameTag—would let wearers identify people in front of them by matching captured faces against a biometric gallery sitting on the user’s device. It’s the same kind of technology Meta said it walked away from in 2021, after paying out billions of dollars to settle biometric privacy lawsuits in Texas and Illinois. Meanwhile, xAI is asking a federal judge to force four people suing the company over Grok-generated deepfake nudes to drop their pseudonyms and litigate under their real names—including one plaintiff who alleges the chatbot was used to fabricate sexual images of her as a child. The plaintiffs say they’d sooner drop the suit than submit to harassment and doxing from Musk’s online supporters. xAI’s lawyers, however, claim that since the deepfakes will remain under seal, there’s “nothing inherently stigmatizing” about naming the people in them. …

Cybercrime Crew Claims It Hacked Mike Lindell’s MyPillow

Cybercrime Crew Claims It Hacked Mike Lindell’s MyPillow

The United States military has known for years that enemies could use location data to track troops’ phones—and it’s also long been aware of easy fixes for the problem. The Pentagon adopted almost none of these protections, though, in spite of admitting in a letter exposed this week that US adversaries are actually using the data to target soldiers in war. Meanwhile, US law enforcement warned this week about “anti-tech extremism” as AI backlash grows around the country. After a nearly 90-day internet shutdown, connectivity started to trickle back into Iran this week amid internal political power struggles and ongoing negotiations with the US to end its war with Tehran. Researchers cautioned that it is unclear how extensive the restoration will be and whether connectivity will only return temporarily. As cybercriminals and offensive hackers ramp up their use of AI to exploit vulnerabilities and develop hacking tools, the technology is also radically changing the dynamics of how security researchers hunt for vulnerabilities. And scammers are using real hotel reservation data and other travel details to …

Hackable Robot Lawn Mower Unlocks a New Nightmare

Hackable Robot Lawn Mower Unlocks a New Nightmare

Cramming for finals is bad enough without the platform you use to do your schoolwork suddenly shutting down. Unfortunately for countless students across the US, that’s exactly what they faced on Thursday after Canvas went into “maintenance mode” following a ransomware attack on education tech firm Instructure. Hackers using the name ShinyHunters claimed responsibility for the breach, and experts say the chaos they caused shows how far these actors will go to extort their victims. Did you know that Google Chrome includes an automatic download of the Gemini Nano AI model? If not, you wouldn’t be alone. People who use Google’s wildly popular browser realized this week that Gemini Nano has been taking up 4 GB of space on their desktops since 2024, sparking annoyance and concerns over privacy. Fortunately, you can disable the AI model—but not without losing some helpful security features. Obviously, you can also just download a different browser for free. Researchers this week revealed that thousands of vibe coded apps were left exposed on the open internet, revealing sensitive corporate and …