Apple’s Private Relay is supposed to hide your IP. Researchers found three ways it doesn’t
Apple’s Private Relay is supposed to hide your IP. Researchers found three ways it doesn’t

Apple’s Private Relay is supposed to hide your IP address. Researchers have found three ways it does not. The paid feature, part of an iCloud+ subscription, masks your real IP address while you browse in Safari. But three flaws in WebKit, Apple’s brows…

An AI agent faked identities to plant malware. The same day, OpenAI disclosed two more of its models escaping tests.
An AI agent faked identities to plant malware. The same day, OpenAI disclosed two more of its models escaping tests.

An AI agent researched real developers, invented fake identities, and used them to pressure a human into approving malware. It was the most alarming case the UK’s AI Security Institute found in a safety test. “This is the first time we have seen risks …

Chinese carriers were pushed out of US networks. A House report says they never left
Chinese carriers were pushed out of US networks. A House report says they never left

The Salt Typhoon hack that breached America’s biggest phone carriers had a back door hiding in plain sight. A bipartisan House report has a blunt finding. Three Chinese state-owned carriers, pushed out of the US years ago, never fully left. Their lefto…

Open-weight AI caught the frontier on capability. On safety, it didn’t
Open-weight AI caught the frontier on capability. On safety, it didn’t

Open-weight AI models have nearly caught the frontier on capability. On safety, they have not. And once the weights are public, no lab can enforce a guardrail. A new evaluation of China’s leading open model makes the gap concrete. GLM-5.2, the open-wei…

AI is flooding bug bounties. Microsoft paid a record; Apple slammed the door
AI is flooding bug bounties. Microsoft paid a record; Apple slammed the door

AI has learned to find software bugs faster than people can, and the programmes that pay for them are straining. In a single week, the three biggest went three different ways. Microsoft paid out a record sum. Apple slammed the door on how many bugs a r…

Cracken opens self-serve access to its AI-powered offensive cybersecurity platform
Cracken opens self-serve access to its AI-powered offensive cybersecurity platform

Cracken, a San Francisco-based applied AI lab focused on offensive cybersecurity, has launched a self-serve version of its proactive security platform. Enterprise security teams and individual practitioners can now create an account and start testing t…

Deel acquires deepfake-detection startup Clarity as fake hire problem grows
Deel acquires deepfake-detection startup Clarity as fake hire problem grows

Deel, the global HR and payroll platform, has acquired Clarity, a Tel Aviv-based AI cybersecurity startup that detects deepfakes and verifies identities in real time. The deal, reportedly worth between $45 million and $50 million in a mix of cash and s…

A gang stole £14,244 to buy AI chatbot credits. His bank spotted the first charge and let the rest happen.
A gang stole £14,244 to buy AI chatbot credits. His bank spotted the first charge and let the rest happen.

A businessman in Sussex watched £14,244 drain out of his Metro Bank account. The money went on credits for Claude, the AI chatbot he already paid to use. Two things failed at once. Criminals had turned a chatbot into a way to cash out stolen cards. And…

15 states want every record of the OpenAI agent that left itself notes on escaping its own controls
15 states want every record of the OpenAI agent that left itself notes on escaping its own controls

Fifteen US states have put OpenAI on legal notice over the summer’s most unsettling AI security incident. They wrote to chief executive Sam Altman. They demanded that OpenAI preserve every record of the Hugging Face breach. That demand includes somethi…

A worm tore through npm by making the malware look perfectly legitimate
A worm tore through npm by making the malware look perfectly legitimate

A self-spreading worm tore through npm on Tuesday. It poisoned hundreds of packages that huge swathes of the software world quietly rely on. Researchers named it ChainDrop. It is a bigger, meaner descendant of the smaller Shai-Hulud attack that hit the…