Zack Whittaker

@zackwhittaker.com

Security editor, TechCrunch Signal: zackwhittaker.1337 My stories: techcrunch.com/author/zack-whittaker My newsletter/blog: this.weekinsecurity.com

First Apples “Hide my Email” was proven to be broken, now “Private Relay” - this tech has been the backbone of Apples privacy commitments for years and now we know they’ve been broken for god knows how long. Reminder: Apple and Google’s MAID products are the backbone of global data brokers. ⛈️⚖️🖖🏻

Joseph Cox@josephcox.bsky.social · 2h ago

New from 404 Media: Apple's 'Private Relay' is exposing users' real IP addresses. Private Relay is supposed to protect all your browsing in Safari. But researchers found a bunch of issues that are exposing real IPs. I verified they do. Not fixed, a live issue www.404media.co/apples-priva...

Another AI test gone awry, U.K edition: "An agent tried to insert malicious code into an open-source project. In an attempt to get the code approved, the agent engaged in social engineering — creating fake online identities and using them to pressure the project's maintainer to approve the code."

Incident Report: unsanctioned agent behaviour during cyber testing | AISI Work

During a routine cyber evaluation, AISI identified an incident in which AI agents took sustained, unsanctioned action directed at real people and organisations. We are disclosing what we found, what i...

aisi.gov.uk

Beacon CRM is the company that was hacked. The company has an "incident guidance" page that you probably wouldn't be able to find through a search engine, because the company added a "noindex" tag code to the page's code, preventing it from being indexed. www.beaconcrm.org/incident-gui...

@maxsec.bsky.social · 20h ago

Massive CRM used by many UK charities hacked . @campuscodi.risky.biz @grahamcluley.com BBC News - English National Ballet suffers customer data hack www.bbc.co.uk/news/article...

An EFF investigation has found that some advertising SDKs enable location data collection by default. The findings aim to warn app developers that some of the third-party code they place in their apps may also collect their users’ location data when they grant permission to the app.

Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy

An EFF investigation identified several advertising software development kits (SDKs) that publicly acknowledge collecting and sharing users’ location by default when embedded in apps granted location ...

eff.org

NEW: Several hackers have been stealing $130 million — and counting — in Bitcoin from the owners of supposedly secure offline hardware wallets. By knowing how to make the keys, the hackers did not need to break into the safe that holds them. They essentially figured out how to cut keys at scale.

Hackers steal over $130 million by exploiting bug in offline hardware wallets | TechCrunch

A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to b...

techcrunch.com

Folks fighting for ad blockers in your orgs: ifin-intel.org/blog/ad-bloc...

Just Deploy the Ad Blocker | IFIN

Enterprises sometimes shy away from free tools without support contracts. An ad blocker browser extension should not be one of them.

ifin-intel.org

Zack Whittaker@zackwhittaker.com · yesterday

By me at this.weekinsecurity.com: A major online ads company that claims to serve 1.5 billion ads a day was hacked and began serving malware designed to steal a person's crypto. This is the latest perfect example why you should use an ad-blocker.

By me at this.weekinsecurity.com: A major online ads company that claims to serve 1.5 billion ads a day was hacked and began serving malware designed to steal a person's crypto. This is the latest perfect example why you should use an ad-blocker.

Online advertising giant Adform was hacked, proving once again why ad blockers are necessary

The hacked digital advertiser was caught serving malicious ads that allowed hackers to steal a victim's cryptocurrency.

this.weekinsecurity.com

If there's one thing I've learned from publishing this story is that there is a very, very, very wide chasm between what the law says about all this... and what people *think* the law says and/or *should* say.

Zack Whittaker@zackwhittaker.com · 2d ago

After Anthropic and OpenAI both admitted to their AI models hacking other companies, @lorenzofb.bsky.social and I wanted to find out: Who is legally to blame when an autonomous AI agent hacks something? Lawyers say it's really complicated! Bypass for ad-blockers: web.archive.org/web/20260803...

Had a great time chatting with the very excellent @firewalldragons.bsky.social about the things I'm thinking about the most in cybersecurity and privacy 👀 Have a listen!

Firewalls Don't Stop Dragons@firewalldragons.bsky.social · 2d ago

Today we talk with @zackwhittaker.com from @techcrunch.com about some of top cyber threats, which may not be obvious. We discuss age gating, mercenary spyware, surveillance capitalism and critical infrastructure attacks, and more! podcast.firewallsdontstopdragons.com/2026/08/03/t...

This week’s main story is about how police use surveillance tools like cameras, microphones, license plate readers, “cell site simulators,” and the practice of “predictive policing,” to create a world that has been lovingly described as “Big Brother on steroids.” Full segment at the link in our bio.

Bild

New, by me: Samsung has banned smart TV apps that enlist owners' internet connections into residential proxy networks, which are increasingly linked to cybercrime. Samsung told me it's also removing apps containing resproxy code. Bypass for ad-blockers: web.archive.org/web/20260803...

Samsung bans smart TV apps that share users' internet connections with strangers | TechCrunch

New security research offers a rare view inside residential proxy networks, which rely on apps that share a person's internet connection with someone else.

techcrunch.com

Also this week: Democrats get stung by a $29K email scam, and OpenAI and Anthropic are as bad at security as each other, as new details about their AI model hacks come out. Plus: the happy corner of good news, and a brand new reader-submitted cyber cat. 🐈‍⬛

this week in security — august 2 2026 edition

Iran accused of U.S. water hacks, Anthropic admits its AI also hacked others, front-line defenders describe few AI threats, bug exposes data centers to compromise, hacked advertiser served malware, U....

this.weekinsecurity.com

Bonkers statistic noted by @rcfp.org's Bruce Brown in tonight's edition of @status.news: In 25 years, feds tried to used "national security" to expose reporter sources on 3 occasions. In the last few months, Trump admin has already tried it at least 4 times. This is pure authoritarian playbook.

 • The NYT revealed that one of its freelance reporters, Matthew Cole, has been fighting a subpoena from Donald Trump’s Justice Department since February, as part of the administration’s effort to force him to reveal his sources for a story about a failed secret mission in North Korea. [NYT] 

   • In response, Reporters Committee President Bruce D. Brown noted that over the last 25 years, “There have only been three attempts in national security leaks cases to force reporters to name their sources.” Now, he added, “We have four attempts—that we know of—in the space of a few months.”

In today's this.weekinsecurity.com: Iran likely behind U.S. water hacks; security defenders describe chasm between AI hype and real-world attacks; a federal agency that advises people not to put their kids in trebuchets is seeking hospital ER records 👀, plus: an absolute fuckton of data breaches.

this week in security — august 2 2026 edition

Iran accused of U.S. water hacks, Anthropic admits its AI also hacked others, front-line defenders describe few AI threats, bug exposes data centers to compromise, hacked advertiser served malware, U....

this.weekinsecurity.com

New: We found 50 cops who misused Flock cameras and other license-plate readers for personal purposes, often to spy on their girlfriends or ex-wives. He "watched every single move I made. ... Who do you turn the chief of police in to?" wapo.st/3S6rTuo

She left her ex. He secretly tracked her through a network of policing cameras.

Flock’s array of license-plate cameras was built to fight crime. But at least 50 law enforcement officers were charged with or accused of misusing it and other systems.

wapo.st

In today's this.weekinsecurity.com: Iran likely behind U.S. water hacks; security defenders describe chasm between AI hype and real-world attacks; a federal agency that advises people not to put their kids in trebuchets is seeking hospital ER records 👀, plus: an absolute fuckton of data breaches.

this week in security — august 2 2026 edition

Iran accused of U.S. water hacks, Anthropic admits its AI also hacked others, front-line defenders describe few AI threats, bug exposes data centers to compromise, hacked advertiser served malware, U....

this.weekinsecurity.com

A reader of my newsletter this.weekinsecurity.com emailed in to ask about how the use of AI chatbots and LLMs can get disclosed in court, even when used for legal defense. It raises important questions about where a user's data goes once it's submitted to an AI chatbot, and who has access to it.

When AI chatbots and LLMs get legal, check your privilege

Using AI tools and LLMs for sensitive matters, such as for legal and medical uses, raises important questions about where that data goes and who can access it.

this.weekinsecurity.com

U.S. biotech giant Amgen confirms July hack, and says proprietary data, patients' health data, and other information was exfiltrated from its cloud environments (Amgen runs largely on AWS). Amgen says volume & types of data stolen "could be sensitive." Amgen says it serves 17 million patients. 🫠

In light of the news out of Minnesota, resurfacing my reporting from Cavendish, Vermont where I toured a small water/wastewater treatment facility and talked about the threat posed by nation state cyber actors to critical infrastructure. www.npr.org/2025/09/20/n...

Flushable wipes and Iran: Water treatment facility adds cyberattacks to worry list

Water treatment workers are grappling with how to protect against a new threat: hackers burrowing into the system and wreaking havoc.

npr.org

A reader of my newsletter this.weekinsecurity.com emailed in to ask about how the use of AI chatbots and LLMs can get disclosed in court, even when used for legal defense. It raises important questions about where a user's data goes once it's submitted to an AI chatbot, and who has access to it.

When AI chatbots and LLMs get legal, check your privilege

Using AI tools and LLMs for sensitive matters, such as for legal and medical uses, raises important questions about where that data goes and who can access it.

this.weekinsecurity.com

Keen to see if any of the companies that were hacked by OpenAI or Anthropic will sue them. Someone has to take responsibility for this, and the blame is almost entirely on the leaders of these AI companies. Alternatively, hacking is just legal now until a court says otherwise? What a fucking mess.

Daragh Ó Briain@daraghobrien.bsky.social · 5d ago

Sorry: they only did reviews to see if their software had unlawfully and without authorisation accessed networks of third parties? This wasn’t a defined control *during* their “testing”? This is extreme negligence at least. cyberscoop.com/anthropic-cl...