Prompt Injection Attacks Are Thwarting AI Hacking Agents

Prompt injections, the Malicious commands attackers embed into content to entice large language models to follow them, have been attackers’ go-to tool for turning AI platforms against their users. A well-phrased command sneaked into an email or calendar invitation is often all it takes to cause the LLM to exfiltrate sensitive data or follow other … Read more

Your Period Tracker Is (Probably) Spying on You

Hours of San Francisco Police Department drone video footage exposed on the open web illustrates a new era of incredibly granular—and consequential—urban surveillance. Meanwhile, the San Francisco City Attorney’s Office sent cease-and-desist letters to Apple and Google this week demanding that the tech giants delete 13 AI nudifying “face-swap” apps from their app stores that … Read more

Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival

As a security researcher who specializes in finding web vulnerabilities, he decided to poke around Front Gate’s web domain for bugs. He quickly found what looked like a SQL injection vulnerability—a common flaw that allows a hacker to input commands into a text field on a website, causing them to run on the site’s backend … Read more

OpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s Mythos

As fears about AI hacking capabilities grow, OpenAI on Monday made a slew of cybersecurity-focused announcementsincluding an improved version of its limited-access security-specialized model GPT-5.5-Cyber, expanded international work with governments and other institutions to give them “trusted access” to the company’s latest cybersecurity-focused models, and releasing its Codex Security scanner as an app plug-in. As … Read more

World Cup Scams Are Getting Harder to Spot

You got a World Cup ticket. It arrived in your inbox with a QR code, professional branding, and a confirmation email that looked like the real thing. Unfortunately, it wasn’t. For years, spotting a scam was relatively simple. A suspicious email address, broken English, or an obvious typo were often enough to raise suspicion. But … Read more

‘Dangerous’ AI Models Are Coming No Matter What

Late last week, Anthropic took its new Claude Fable 5 and Mythos 5 AI models offline following a United States government export-control directive barring “any foreign national” from using the services. The company has been in talks with the White House since Friday but has yet to secure an agreement that would allow it to … Read more

Anthropic Offers Mythos Upgrade for Cyber Partners and a ‘Safe’ Version for the Rest of You

Anthropic released two new AI models called Claude Fable 5 and Claude Mythos 5 on Tuesday, which the company says have greater capabilities than the Mythos Preview model it released in April to a limited set of tech industry partners. Anthropic has said the initial, limited release stemmed from concerns that the model’s capabilities could … Read more

Crypto-Funded Chinese Peptide Labs Are Booming

Meta has been quietly stashing dormant face recognition code on more than 50 million phones, WIRED reported this week, tucked inside the companion app that pairs with its Ray-Ban and Oakley smart glasses. If activated, the feature—known internally as NameTag—would let wearers identify people in front of them by matching captured faces against a biometric … Read more

WhatsApp Adds Meta AI Chats That Are Built to Be Fully Private

WhatsApp said on Wednesday it is launching an AI chat function known as Incognito Chat that is built to allow users to converse privately with Meta AI—such that Meta itself cannot access the questions or answers. The feature is based on WhatsApp’s Private Processing scheme, which debuted a year ago and already underlies WhatsApp’s existing … Read more

Hackable Robot Lawn Mower Unlocks a New Nightmare

Cramming for finals is bad enough without the platform you use to do your schoolwork suddenly shutting down. Unfortunately for countless students across the US, that’s exactly what they faced on Thursday after Canvas went into “maintenance mode” following a ransomware attack on education tech firm Instructure. Hackers using the name ShinyHunters claimed responsibility for … Read more