Andy Greenberg

@agreenberg.bsky.social

Writer for WIRED. Author of SANDWORM. Latest book, TRACERS IN THE DARK: The Global Hunt for the Crime Lords of Cryptocurrency, out now. agreenberg@wired.com. Andy.01 on Signal.

Scam researchers told a Claude agent and human "scammers" to text test subjects and build a relationship. After a week, subjects said they trusted the AI more than the human and almost half were willing to install an app at its request. Almost none detected it was AI. www.wired.com/story/ai-sca...

AI Scammers Are Better at Building Trust Than Humans

Researchers pitted a person against a Claude agent and found that, after a week of texting, the AI chatbot was more effective at creating “exploitable trust” with others.

wired.com

As a result, the device is in over 2 million cars, about half of whose owners told dealers they didn't want it, by UCSD's estimate. They may not have any idea it's inside their vehicle. Yet it's beaconing and can be "activated" instantly by a hacker and hijacked for theft or chaotic effects.

The UCSD team’s proof of concept app offers a menu of hacking options that the KARR vulnerability makes possible as well as a list of nearby cars whose Bluetooth signals show they have the vulnerable KARR device installed.

UCSD warned KARR's manufacturer, who has now pushed out a fix. The complication: KARR is typically installed by dealers to prevent theft from their lots. If a buyer doesn't want it as an add-on, the dealer still leaves it wired in under the hood anyway in a "deactivated" state.

The KARR Security System alarm.

A car alarm device, KARR, inside millions of cars has a security flaw that lets hackers unlock, track, even paralyze vehicles. There's a patch. The problem? Half of car owners who have the device installed didn't ask for it, and may not even know it's there. Thread👇 www.wired.com/story/a-devi...

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

Dealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars.

wired.com

A car alarm device, KARR, inside millions of cars has a security flaw that lets hackers unlock, track, even paralyze vehicles. There's a patch. The problem? Half of car owners who have the device installed didn't ask for it, and may not even know it's there. Thread👇 www.wired.com/story/a-devi...

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

Dealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars.

wired.com

San Francisco police accidentally livestreamed their drones’ video and data on the open web. The hours of footage—including several apparent arrests—should never have been made public, but now offer a glimpse of modern aerial urban surveillance. www.wired.com/story/sfpd-d... w/ @dmehro.bsky.social

A Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban Surveillance

The SFPD’s exposure of hours of videos from drone platform Skydio reveals how broadly it’s watching the city from above—and how the results can spill online.

wired.com

NEW: The SFPD was leaking real-time footage from surveillance drones, including color and thermal imaging, location metadata, and drone pilots’ names and email addresses. "There’s a certain trust given to the police to use these things correctly."

A Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban Surveillance

The SFPD’s exposure of hours of videos from drone platform Skydio reveals how broadly it’s watching the city from above—and how the results can spill online.

wired.com

San Francisco police accidentally livestreamed their drones’ video and data on the open web. The hours of footage—including several apparent arrests—should never have been made public, but now offer a glimpse of modern aerial urban surveillance. www.wired.com/story/sfpd-d... w/ @dmehro.bsky.social

A Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban Surveillance

The SFPD’s exposure of hours of videos from drone platform Skydio reveals how broadly it’s watching the city from above—and how the results can spill online.

wired.com

I sat in on a close-door war game where the insurance industry simulated a cyberattack against US water utilities by Volt Typhoon, Chinese state hackers who have been penetrating US critical infrastructure since at least 2023. The results were catastrophic. www.wired.com/story/what-h...

What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out

Burst water mains. Evacuated hospitals. In a closed-door simulation, insurers played out their response to a mass disruption by China’s Volt Typhoon hackers—and found a nightmare scenario.

wired.com

A security researcher using Claude Opus 4.7 found the AI tool could independently code an exploit to hack into Front Gate Tickets, the ticketing platform for almost every major US music festival from Lollapalooza to Bonnaroo. He could then issue any tickets at will. www.wired.com/story/claude...

Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival

A researcher found that using Anthropic’s Claude Opus 4.7, he could break into the website of Front Gate—used by every festival from Lollapalooza to Bonnaroo—and freely issue any ticket he chose.

wired.com

NEW: Insane screwup inside Meta. The company exposed worker keystroke data that was being used to train AI — making it potentially accessible to anyone at the company. The data included personnel and performance info, private convos, full transcriptions…imagine your coworkers seeing all of that.

Meta Exposed Data Internally From Its Controversial Employee-Tracking Program

Employees had previously raised concerns about the initiative, which involves collecting workers’ keystroke data to train AI models.

wired.com

To spell it out, this has the potential to be a really big deal. It could help make end-to-end encryption the default for a new generation of collaboration apps the same way the Signal protocol has end-to-end encrypted Signal and WhatsApp conversations on billions of phones.

Andy Greenberg@agreenberg.bsky.social · 2mo ago

Developers from Signal (including its protocol's co-creator) along with Microsoft and Harvard unveil Encrypted Spaces, an open-source codebase for a new generation of private collaboration apps. Think Slack, Discord, Google Docs, all end-to-end encrypted. www.wired.com/story/signal...

Developers from Signal (including its protocol's co-creator) along with Microsoft and Harvard unveil Encrypted Spaces, an open-source codebase for a new generation of private collaboration apps. Think Slack, Discord, Google Docs, all end-to-end encrypted. www.wired.com/story/signal...

Signal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration Apps

The new open-source project could serve as the basis for a future of apps with features as complex as Slack, Discord, or Google Docs—but with added protection against surveillance.

wired.com

SCOOP: Last year, Dan Berulis filed a whistleblower complaint against DOGE at the NLRB. Elon Musk boosted a post calling it false. The next day, Berulis' brake lines were cut. Now he's filed a defamation suit against Musk. @wired.com www.wired.com/story/he-ble...

He Blew the Whistle on DOGE. Then His Brakes Were Cut

A federal IT staffer filed a complaint about DOGE, then went public. Shortly after Elon Musk boosted a post calling his claims false, his brake lines were cut. Now he’s suing for defamation.

wired.com

After this week's Github breach, we checked in on hacker group TeamPCP's victim count: their supply chain attacks have tainted more than 500 pieces of software (a thousand-plus different version) and breached hundreds of companies. This is out of control. www.wired.com/story/teampc...

A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale

GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations.

wired.com