Security

Promptly Problematic
Hugging Face Has a Deepfake Nudes Problem
Researchers tested top image editing models on Hugging Face and found they could easily create explicit deepfakes—and 1,000 image editing prompts show how people use the software.
Matt Burgess



OpenAI Models Escaped Containment and Hacked Hugging Face
The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack.
Lily Hay Newman and Dell Cameron

A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots
A new type of malware can worm deep into AI coding systems to steal data and logins—and can flip a “death switch” to destroy files and keep out real users.
Lily Hay Newman

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
Dealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars.
Andy Greenberg

Prompt Injection Attacks Are Thwarting AI Hacking Agents
“Context bombing” tricks malicious AI agents into shutting down before they can do harm.
Dan Goodin, Ars Technica

For Taylor Swift, Madison Square Garden’s Controversial Cameras Briefly Went Dark
MSG’s sprawling surveillance system can monitor guests down to the second. Its owners made an exception for the pop star’s rehearsal dinner.
Noah Shachtman

The ACLU Is Arming Lawyers to Expose State Surveillance Secrets
A new toolkit for attorneys in Massachusetts targets the technologies police use—and conceal—to build criminal cases, from facial recognition to AI-written police reports.
Dell Cameron

San Francisco Demands Apple and Google Delete AI ‘Nudify’ Apps From App Stores
The City Attorney’s Office sent the tech giants cease-and-desist letters this week telling them to stop profiting from 13 “face-swap” apps that are overwhelmingly used to target women and girls.
Matt Burgess

Here’s the Truth About Whether Meta’s NameTag Face Recognition Tech ‘Exists’
Since WIRED reported on Meta’s NameTag face recognition system, company executives have made confusing and conflicting remarks about its very existence.
Andrew Couts

You Can Disable Gemini in Chrome if It’s Freaking You Out
Chrome users were caught off guard by a 4-GB Google AI model baked into Chrome, sparking privacy concerns. The good news: You can easily uninstall it. The bad? You might not want to.
Lily Hay Newman
How the Internet Broke Everyone’s Bullshit Detectors
From AI-generated images to restricted satellite data, the systems used to verify what’s real online are struggling to keep up.
Gia Chaudry

How to Organize Safely in the Age of Surveillance
From threat modeling to encrypted collaboration apps, we’ve collected experts’ tips and tools for safely and effectively building a group—even while being targeted and tracked by the powerful.
Andy Greenberg and Lily Hay Newman

How to Protest Safely in the Age of Surveillance
Law enforcement has more tools than ever to track your movements and access your communications. Here’s how to protect your privacy if you plan to protest.
Andy Greenberg and Lily Hay Newman

The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days
Plus: Russian hackers are trying to steal US nuclear scientists’ emails, the State Department bans known scammers from entering the United States, and more.
Lily Hay Newman and Dhruv Mehrotra

Satellite Images Reveal How Suspected Scam Compounds Appear Out of Nowhere
Analysis of satellite images of Myanmar shows dozens of alleged scam compounds have appeared in recent months, despite a purported crackdown on the criminal organizations.
Matt Burgess

States Want ICE Agents to Show Their Faces. The Trump Administration Is Blocking Them
Federal lawyers say anti-mask laws would endanger immigration agents, citing an ICE face-recognition art project that doesn’t actually work.
Maddy Varner

Apps Marketed to US Troops Are Shipping Chinese and Russian Code
A first-of-its-kind analysis found more than one in eight apps built for US service members carried foreign code—some from firms in nations the Pentagon designates as adversaries.
Dell Cameron
Latest

Security Roundup
Your Period Tracker Is (Probably) Spying on You
Andy Greenberg, Dell Cameron, and Lily Hay Newman
Watchful Eye
A Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban Surveillance
Andy Greenberg and Dhruv Mehrotra

Security Roundup
AI Found a Root Bug in Linux That Everyone Missed for 15 Years
Dell Cameron and Lily Hay Newman

Chat Control’s Back
A Majority of European Lawmakers Voted Against Letting Big Tech Read Our Messages. They’re Going to Anyway
Isabella Ward



Thirst Trap
What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out
Andy Greenberg


Security Roundup
Apple’s Hide My Email Service Fails to Hide Your Email
Matt Burgess and Lily Hay Newman

Compromised
EU Politicians Investigated Pegasus Spyware. Then It Ended Up on One of Their Phones
Lily Hay Newman and Matt Burgess

Cheap Seats
Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival
Andy Greenberg

AI Safety
Meta Contractors Posed as Teens to Prompt Rival Chatbots About Suicide, Sex, and Drugs
Dhruv Mehrotra and Joel Khalili

Don't Look Up
Top Google Security Staff Warn Search Data Could Be Hacked if EU Rules Change
Matt Burgess


Burn Notice
The Pentagon Is Looking Into the Dialog Data Exposure for Unmasking National Security Officials
Dell Cameron and Dhruv Mehrotra

Minority Report
British Police Built a Sprawling Crime-Prediction Machine. Some Results Couldn’t Be Trusted
Matt Burgess and Mark Wilding

Hack Job
Dialog Claims It Was Hacked. A Misconfigured Website Left Its Members Exposed
Dell Cameron and Dhruv Mehrotra

Patched Up
OpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s Mythos
Lily Hay Newman

Key Components
A Critical Deadline Is Approaching for Windows and Linux Security
Dan Goodin, Ars Technica