The recent updates concerning the alleged Moroccan use of the #NSOGroup tool #Pegasus have prompted some thinking on the notion of #techneutrality. I have written a #blog on how this concept has developed in recent years and would be grateful for any #feedback. open.substack.com/pub/ali13651...
Ali
@mueritz98.bsky.social
IT Contractor | Cyber Enthusiast | OSINTer (amateur)
Watches, bands, and rings—if you want to digitally monitor your fitness, more companies than ever are selling devices to do it. But what are they doing to protect our sensitive health data from prying eyes? Learn more with EFF's EFFector newsletter and podcast! www.eff.org/deeplinks/2...
🏃 Fitness Tracker Privacy Fails | EFFector 38.14
Watches, bands, and rings—if you want to digitally monitor your fitness, more companies than ever are selling devices to do it. And more Americans than ever now own at least one wearable health
eff.org
The difference between this and #OpenAI 's recent spin is clear. The incidents are obviously different but #Anthropic do not attempt to hype these as impressive successes, instead the company accepts #responsibility for their fundamental failures. www.anthropic.com/news/investi... #AI #Cyber
Investigating three real-world incidents in our cybersecurity evaluations
In a review of our cybersecurity evaluation transcripts, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environmen...
anthropic.com
Privacy afforded by “anyone with a link”-style sharing of chats & documents is fragile, EFF’s Jacob Hoffman-Andrews told @theguardian.com. “If you share something with a friend, & they share it with a friend, & they post it to social media, suddenly it’s findable and readable by anyone on the web.”
How to keep your Claude chats and Google files private
Some ‘private’ chats and docs are showing up on search engines. Here’s how to protect yours
theguardian.com
I may have spoken too soon 😅
There is so much clickbait hype surrounding the recent #Anthropic updates claiming #Claude discovered new #cryptographic weaknesses. The results are research-focused, impractical and do not break deployed production #encryption, but they demonstrate that AI-assisted #cryptanalysis is accelerating!
There is so much clickbait hype surrounding the recent #Anthropic updates claiming #Claude discovered new #cryptographic weaknesses. The results are research-focused, impractical and do not break deployed production #encryption, but they demonstrate that AI-assisted #cryptanalysis is accelerating!
Although I have been skeptical of the legitimacy of the #OpenAI / #HuggingFace incident, this technical write-up is absolutely fascinating. It provides substantial insight into the steps taken by the OpenAI agents during the attack. #agenticAI #cyberattack #incident huggingface.co/blog/agent-i...
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
huggingface.co
Well said! "... it demonstrates a colossal failure on the part of OpenAI to secure the sandbox in which it was testing its model." #HuggingFace #OpenAI #Cyber #Sandbox
The Hugging Face incident was “both notable and alarming,” EFF’s @evacide.bsky.social told @sfexaminer.bsky.social, “not because ‘ooh, the model’s so powerful,’ but because it demonstrates a colossal failure on the part of OpenAI to secure the sandbox in which it was testing its model.”
The hacker group LunarisSec has issued an ultimatum to the #EU, demanding the abandonment of #ChatControl, the protection of end-to-end encryption, greater #transparency on data sharing, und independent oversight of #data collection. #E2EE #EC #Europe #privacy #LunarisSec #encryption #hackers
I highly recommend the @malwaretech.com video discussing the recent #OpenAI / #HuggingFace incident. This incident is not an instance of #AI going #rogue but rather it demonstrates the sheer absence of basic #safetycontrols and #oversight at OpenAI. www.youtube.com/watch?v=GB8g...
OpenAI Claims Their AI 'Went Rogue'. It Didn't.
YouTube video by Marcus Hutchins
youtube.com
I have been thinking a lot about the #OpenAI / #HuggingFace incident and increasingly consider this a reworked version of the #Anthropic 'sandwich on the park bench' #Mythos #AI hype stunt... The main difference is that everyone is witnessing this in real time rather than reading it in a whitepaper.
Airbus is putting its data beyond America's reach. They will run on Scaleway, a French provider, instead. A US law lets American authorities request data held by US firms, including data stored in servers outside the country. Europe is slowly trying to lean less on American technology.
You won't find me comparing Al models or GPU performance. When I talk Al, I'm talking about the power dynamic between those in power, and the average person. I choose to focus on the drawbacks of Al while highlighting the potential of humanity.
Another example of the increasing push for #EU #digital #sovereignty, spurred on by the #USCLOUDAct, is that @airbus.com are ensuring that their "critical data assets [are] shielded from foreign extraterritorial laws" by migrating apps from #AWS to @scaleway.com www.theregister.com/paas-and-iaa...
Airbus migrating 70 critical apps from AWS to France's Scaleway amid digital sovereignty push
Total of 900 applications including ERP, CRM, and manufacturing systems going to be kept 'under European control'
theregister.com
Let's talk about China's next top model: Moonshot AI's Kimi K3 www.platformer.news/kimi-k3-laun...
China has a new top model
Moonshot AI’s Kimi K3 is very good — but the hype may be getting ahead of reality. (For now.)
platformer.news
I have been getting back into the swing of things after a trip home for a few weeks, it was very good to catch up with the family! I have just read this fascinating paper about adapting #ZeroTrust principles for #agenticAI. goteleport.com/resources/wh... #AI #AgentTrust #agents
From Zero Trust to Agent Trust | Teleport
AI agents operating at scale have characteristics that have no equivalency in purely human or software environments, and zero trust, as currently conceived, is necessary but insufficient to control or contain them. This paper explores what needs to change in order to preserve trust as agents are deployed in enterprise infrastructure.
goteleport.com
At last, just before I head off on holiday, here is my final @bellingcat.com #BackgroundCheck #OSINT challenge write-up, this was surprisingly quick to solve. Many thanks to @thisispetery.bsky.social for having created such a fun series, I have very much enjoyed! open.substack.com/pub/ali13651...
A few days ago #ShinyHunters added the #CouncilofEurope ( @coe.int ) to their dark web page. The deadline for the exposure of ~300GB of files from #Europe 's leading #humanrights organization has now passed, but the files are not yet available for download. Is #coe negotiating?
Really interesting writeup!
Really fantastic writeup by @moh-kohn.eurosky.social about the power of HTML-first sites (and @astro.build!) My humble opinion is that 90% of websites don't need Next.js, React, or other hefty client-side frameworks—they just need static pages and the occasional form
Inside the fight over Claude Mythos 5
Inside the fight over Claude Mythos 5
According to sources, Anthropic is in “uncharted territory.”
buff.ly
I repeatedly find posts on X which oversimplify and exaggerate #tech news for engagement. The latest claims this paper proves #ChatGPT is getting "dumber" and the internet is shrinking. In reality, #AI devs are well aware of the risk of model collapse and use #research-backed techniques to avoid it.
Watch Bellingcat's @giancarlofiorella.bsky.social on CTV News explaining the disinformation campaign targeting Ukrainian President Volodymyr Zelenskyy. Fake videos appearing to be from media organisations, including Bellingcat, have been shared across social media. www.youtube.com/watch?v=wGDq...
New wave of online disinformation after Zelenskyy's open letter to Putin | Deception Decoded
YouTube video by CTV News
youtube.com
Another really great read!
OSINT Field Notes 9 : - A YouTube channel recruiting women into a Russian drone factory ticked the box "made for kids" - A cartel checkpoint sat on Google Street View - A border wall that glows at night - And what your WiFi name gives away And more 👇 osintfieldnotes.substack.com/p/osint-fiel...
Surprise, surprise... #Meta has quietly embedded #facialrecognition technology called "NameTag", intended for its #smartglasses, into its Meta #AI companion App. They had said this would not be rolled out without first taking "a very thoughtful approach". www.wired.com/story/meta-s...
Meta Silently Added Face-Recognition Code for Its Smart Glasses to Millions of Phones
Code reviewed by WIRED uncovered an unreleased face-recognition system embedded in Meta’s smart glasses platform. It’s designed to identify people via biometric data stored on users’ phones.
wired.com
I have seen a post on X describing the recent #EU Cloud and AI Development Act (CADA) proposal as making American #AI illegal in 27 countries. This is clickbait. #CADA is not about a ban but about a strategic shift towards European #digital #independence. This is #sovereignty not #protectionism.
Google, Microsoft, and other hyperscalers have come under scrutiny for their impact on water quality and availability. www.wired.com/story/data-c...
Data Center Operators Are Trying to Fix Their Water Use Problems
Google, Microsoft, and other hyperscalers have come under scrutiny for their impact on water quality and availability.
wired.com
@netzpolitik.org have published a further investigation into #ad-tech, specifically about its use by the #German #police. "We asked all 16 state data protection authorities – none gave a specific legal basis for the use of commercial location data by the police." netzpolitik.org/2026/daten-s...
Deutsche Polizei nutzt offenbar rechtswidrig Databroker
In mindestens zwei Bundesländern hat sich die Polizei Daten von Databrokern beschafft, wie Recherchen von netzpolitik.org und BR erstmals zeigen. Mit solchen Daten könnten sich Handys metergenau orten...
netzpolitik.org
My #Bellingcat challenge blogs take me very long to write. In fact, I have now fallen very behind the current schedule. Meanwhile I was inspired by @bendobrown.bsky.social to write a little summary on #ad-tech #surveillance. I would be thankful for any feedback. open.substack.com/pub/ali13651...
It is weeks like these that I cannot wait for the weekend 😅 The #Hamburg #Beer #Festival is this week (5th and 6th) at the Altes Mädchen. I did not succeed in attending last year, but some friends said it was a fantastic experience with excellent #craftales (also #non-alcoholic)! 🍻Hab Spaß!
I have at last finished my write-up for the penultimate @bellingcat.com #BackgroundCheck #OSINT challenge. I found this challenge the most tricky so far, but I did eventually manage to find @thisispetery.bsky.social's hotel! I would be thankful for any feedback. open.substack.com/pub/ali13651...