Security

Security Roundup
7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.
Matt Burgess, Maddy Varner, Dell Cameron, and Andy Greenberg

Uncharted Waters
The OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal Frontier
Lily Hay Newman

Anthropic Says Claude Hacked Into 3 Organizations During Cybersecurity Tests
In a review triggered by OpenAI’s Hugging Face incident, Anthropic discovered three of its AI models had breached real-world organizations during third-party evaluations.
Louise Matsakis and Lily Hay Newman

A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
A memo obtained by WIRED, issued by the water utilities information sharing group WaterISAC, links dozens of cyberattacks against Minnesota water utilities to Tehran.
Andy Greenberg

OpenAI’s Hacking Debacle Comes Down to Human Error
If the generative AI giant had followed well-known security best practices, it’s likely that its AI agent would never have escaped to the open internet and hacked multiple companies.
Lily Hay Newman

OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
In a new disclosure, OpenAI says its agent used exposed logins to gain access to at least four “publicly available services” in its unhinged quest to solve a test.
Dell Cameron and Maxwell Zeff

Hugging Face Has a Deepfake Nudes Problem
Researchers tested top image editing models on Hugging Face and found they could easily create explicit deepfakes—and 1,000 image editing prompts show how people use the software.
Matt Burgess

Private Claude Chats Exposed in Google and Bing Search Results
The screwup shows how tricky it can be to stop web crawlers from making ostensibly private conversations with AI chatbots entirely too public.
Maddy Varner

For Taylor Swift, Madison Square Garden’s Controversial Cameras Briefly Went Dark
MSG’s sprawling surveillance system can monitor guests down to the second. Its owners made an exception for the pop star’s rehearsal dinner.
Noah Shachtman

The ACLU Is Arming Lawyers to Expose State Surveillance Secrets
A new toolkit for attorneys in Massachusetts targets the technologies police use—and conceal—to build criminal cases, from facial recognition to AI-written police reports.
Dell Cameron

You Can Disable Gemini in Chrome if It’s Freaking You Out
Chrome users were caught off guard by a 4-GB Google AI model baked into Chrome, sparking privacy concerns. The good news: You can easily uninstall it. The bad? You might not want to.
Lily Hay Newman
How the Internet Broke Everyone’s Bullshit Detectors
From AI-generated images to restricted satellite data, the systems used to verify what’s real online are struggling to keep up.
Gia Chaudry

How to Organize Safely in the Age of Surveillance
From threat modeling to encrypted collaboration apps, we’ve collected experts’ tips and tools for safely and effectively building a group—even while being targeted and tracked by the powerful.
Andy Greenberg and Lily Hay Newman

How to Protest Safely in the Age of Surveillance
Law enforcement has more tools than ever to track your movements and access your communications. Here’s how to protect your privacy if you plan to protest.
Andy Greenberg and Lily Hay Newman

Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting
The two Chrome updates in June patched more bugs than the 23 updates before them. Now, Google is ramping up its patching schedule thanks to AI-assisted vulnerability discovery.
Lily Hay Newman

A Civilian Plane Crashed in New Mexico. Was the Military’s Tech to Blame?
Drone warfare is making the skies more dangerous, even for airplanes far from the battlefield.
Jeff Wise

AI Scammers Are Better at Building Trust Than Humans
Researchers pitted a person against a Claude agent and found that, after a week of texting, the AI chatbot was more effective at creating “exploitable trust” with others.
Andy Greenberg

ICE’s New Detention Center Contracts Declare State Laws ‘Shall Not Apply’
One day after a federal judge ordered an ICE detention center opened to state health inspectors, the agency posted new contract terms that would void state oversight at four facilities.
Dell Cameron
Latest



Security Roundup
The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days
Lily Hay Newman and Dhruv Mehrotra



Rogue Agents
OpenAI Models Escaped Containment and Hacked Hugging Face
Lily Hay Newman and Dell Cameron

Inside Job
A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots
Lily Hay Newman

Stealth Mode
A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
Andy Greenberg


Security Roundup
Your Period Tracker Is (Probably) Spying on You
Andy Greenberg, Dell Cameron, and Lily Hay Newman


Stripped Out
San Francisco Demands Apple and Google Delete AI ‘Nudify’ Apps From App Stores
Matt Burgess

Watchful Eye
A Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban Surveillance
Andy Greenberg and Dhruv Mehrotra

Security Roundup
AI Found a Root Bug in Linux That Everyone Missed for 15 Years
Dell Cameron and Lily Hay Newman

Chat Control’s Back
A Majority of European Lawmakers Voted Against Letting Big Tech Read Our Messages. They’re Going to Anyway
Isabella Ward



Thirst Trap
What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out
Andy Greenberg

