Cyber security – Breaking News & Latest Updates 2026
Skip to main content

Security

Cybersecurity is the rickety scaffolding supporting everything you do online. For every new feature or app, there are a thousand different ways it can break – and a hundred of those can be exploited by criminals for data breaches, identity theft, or outright cyber heists. Staying ahead of those exploits is a full-time job, and one of the most lucrative and sought-after skills in the tech industry. All too often, it’s something up-and-coming companies decide to skip out on, only to pay the price later on.

Richard Lawler
Richard Lawler
OpenAI didn’t notice its AI bots trying to hack the Education Department’s website.

On Friday, OpenAI said its “misaligned models” review after the Hugging Face hack would take months, but has mostly found mundane research activity. Then it mentioned 53 incidents of the bots uploading “user-provided” images (anonymized content from personal accounts that haven’t opted out or organizations that opt in) to image-hosting sites.

Now the New York Times confirms that other unusual behavior found includes pulling public data from the Census Bureau and the SEC, while with the Education Department, it “tried to hack the website to gather data from the department’s civil rights office but failed.”

Stevie Bonifield
Stevie Bonifield
Crypto hacks keep happening.

Bitget says $351.6 million in crypto was stolen by hackers on Thursday, and reportedly suspects the breach may be linked to North Korea. Meanwhile, Protos reports three other DeFi projects that posted about being hacked on Thursday, with losses totaling $7 million at Duelbits, $2.3 million at Meter, and $1.8 million at Payy Network.

Dominic Preston
Dominic Preston
Opera’s free VPN now offers automatic protection on public Wi-Fi.

The desktop version of the browser now offers an opt-in toggle to automatically enable the built-in VPN whenever you connect to a public or unsecured Wi-Fi network. Sounds like an easy way to make public Wi-Fi Russian roulette a little safer to play. It’s rolling out today in the US and France.

The new setting is an opt-in toggle, so you’ll have to go enable it today if you’re an Opera user.
The new setting is an opt-in toggle, so you’ll have to go enable it today if you’re an Opera user.
Image: Opera
Jess Weatherbed
Jess Weatherbed
Gmail has a quicker way to copy 2FA codes.

A new “Copy code” button is rolling out to Gmail inboxes on Android and iOS that previews authentication codes below the subject line, letting you copy them with a single tap without opening the email. It isn’t available on web, but it should make mobile logins less tedious.

The new Copy code button in Gmail for iOS and Android.
Here’s a preview of the pill-shaped Copy code button.
Image: 9to5Google
Terrence O'Brien
Terrence O'Brien
The NSA is reorganizing with an increased focus on AI, China, and cybersecurity.

According to The Washington Post, the spy agency is set to undergo its largest restructuring in over a decade. Army general and NSA director Joshua M. Rudd is leading the effort. According to the Post:

Rudd’s initiative calls for the creation at NSA’s Fort Meade, Maryland, headquarters of five new organizations inside the agency, in artificial intelligence, China, cybersecurity, combat support or warfighting, and global intelligence. Each will be led by a newly elevated “mission director” …

Thomas Ricker
Thomas Ricker
Google makes it easy to switch Android password managers.

Now you can move both passwords and passkeys between Google Password Manager, 1Password, Bitwarden, and Dashlane, with more password managers to come. It works at the OS level, so there’s no unencrypted text file for you to deal with on the import / export.

Importing and exporting requires just a few clicks.
Importing and exporting requires just a few clicks.
Image: Google
Emma Roth
Emma Roth
OpenAI agents reportedly swarmed more than just a German wiki.

After OpenAI confirmed that its AI agents hijacked a German wiki as a way to communicate, Reuters reports similar incidents have occurred across at least 10 other websites. Reuters says most of the sites OpenAI agents swarmed were “obscure,” including “communally edited wikis, online text storage sites, and a pair of link shorteners run by two universities.”

Thomas Ricker
Thomas Ricker
Chrome is now on a two-week update cycle.

As previously announced, Google has halved the release cycle for its web browser with today’s stable release of Chrome 153 on desktop, Android, and iOS. Chrome 154 Beta is now ready for testing, ahead of its stable release on September 22nd.

Jess Weatherbed
Jess Weatherbed
Go Flock yourself.

Did you know there’s a website you can check to see if Flock customers (like policing and surveillance agencies) have searched for your license plate number? Have I Been Flocked? warns users that its data is incomplete, but developer Cris van Pelt told Business Insider that visits to the database have “exploded.”

Elizabeth Lopatto
Elizabeth Lopatto
Apollo, a major player in GPU-backed loans, hacked.

You may recall Apollo is majorly involved in AI infrastructure financing; it even is one of the “compute is an asset class” consortium. Sounds like the hackers stole a bunch of the usual things, like employees’ social security numbers. If they stole interesting things, like internal data on the AI deals Apollo has been making, that wasn’t disclosed in the breach notification. If you know anything about the hack, hit me up on Signal: lopatto.46.

Meta glasses are a workplace menace

Public-facing workers are being filmed, harassed, and creeped out by AI-powered smart glasses.

Mia Sato
Jess Weatherbed
Jess Weatherbed
The UK prime minister isn’t above phishing training.

Andy Burnham exchanged messages with somebody posing as White House chief of staff Susie Wiles (whose phone was hacked last year) before becoming suspicious that the contact was an impersonation, Politico reports. The incident has since been reported to the White House, and the undisclosed message contents are reportedly “of no significance.”

Rogue AI aren’t science fiction anymore

For years, fears about AI systems slipping human control were dismissed as speculative.

Robert Hart
Jess Weatherbed
Jess Weatherbed
Did your iPhone recieve an ‘Apple Threat Notification’?

You’re not alone — Apple told TechCrunch that it sent the notifications on Thursday to users in 110 countries who it suspects have been targeted by mercenary spyware. Apple has a new support page with guidance on how targets can best protect their devices against such attacks, which have “historically been associated with state actors.”

The Apple Threat Notification alert on iPhone.
This is what the notification looks like.
Image: Apple
Lauren Feiner
Lauren Feiner
Flock’s updates are more about fixing a PR problem than actual harm, ACLU says.

The group says that while changes like more limited data retention is welcomed, the devil is in the details. “Transforming an exceptionally dangerous mass surveillance system into one that is fully protective of civil rights and civil liberties is a difficult, if not impossible task,” it writes.

Stevie Bonifield
Stevie Bonifield
Framework says hackers accessed its customers’ data.

I woke up to an email from Framework this morning letting me know my data was included in a “limited” data breach at one of Framework’s partners reported on August 6th. Framework says hackers accessed “customer names, email addresses, phone numbers, and addresses” but not order or payment info.

A screenshot of a data breach notification from Framework
Image: Framework
Jess Weatherbed
Jess Weatherbed
Apple’s private browsing feature isn’t good at its job.

Private Relay is supposed to conceal your IP address when browsing Safari, but security researchers discovered that several WebKit browser engine quirks actually allow any website that supports passkeys to bypass the privacy feature entirely and expose your device’s IP. This comes just a month after Apple’s Hide My Email feature also failed to hide emails.

IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay

[Mysk Blog – In-Depth Cybersecurity & Mobile App Privacy Research]