Andy Greenberg
agreenberg@infosec.exchange
<p>Writer for WIRED. Author of SANDWORM. New book, TRACERS IN THE DARK: The Global Hunt for the Crime Lords of Cryptocurrency, out now. agreenberg@wired.com</p>
Posts
-
View post
A Minnesota state fusion center report ties the cyberattacks on 30+ Minnesota water utilities to Iranian-affiliated hackers, according to a water utility information sharing group&#39;s memo I obtained. https://www.wired.com/story/a-leaked-memo-ties-cyberattacks-on-minnesota-water-utilities-to-iran/
-
View post
Two security researchers shipped me a pink plastic kid&#39;s smartwatch from Amazon. When I wore it, they tracked my movements, surreptitiously took photos of me, even listened to my conversations. The same backend they hacked is used by 30+ watch brands for kids. 🧵👇 https://www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids/
-
View post
At Black Hat, security researcher Vangelis Stykas reveals what he found by lurking inside North Korean hackers’ infrastructure for nearly two years: They got footholds inside 1,640 networks, by his count. About half of those intrusions were serious breaches. https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide/
-
View post
Scam researchers told a Claude agent and human "scammers" to text test subjects and build a relationship. After a week, subjects said they trusted the AI more than the human and almost half were willing to install an app at its request. Almost none detected it was AI. https://www.wired.com/story/ai-scammers-are-better-at-building-trust-than-humans/
-
View post
Mohammad Muzahir, aka Red Bull, the scam compound whistleblower and human trafficking victim whose incredible bravery made possible this story...https://www.wired.com/story/he-leaked-the-secrets-southeast-asian-scam-compound-then-had-to-get-out-alive/... now has a GoFundMe. I&#39;m in touch with the creator, who is legit. Grateful to her and to anyone who can donate: https://www.gofundme.com/f/support-whistleblower-journey-to-a-cybersecurity-degree
-
View post
After this week&#39;s Github breach, we checked in on hacker group TeamPCP&#39;s victim count: their supply chain attacks have tainted more than 500 pieces of software (a thousand-plus different version) and breached hundreds of companies. This is out of control. https://www.wired.com/story/teampcp-software-supply-chain-attack-spree-github/
-
View post
Developers from Signal (including its protocol&#39;s co-creator) along with Microsoft and Harvard unveil Encrypted Spaces, an open-source codebase for a new generation of private collaboration apps. Think Slack, Discord, Google Docs, all end-to-end encrypted. https://www.wired.com/story/signal-alums-release-encrypted-spaces-a-new-system-for-building-private-collaboration-apps/
-
View post
Red Bull, the scam compound whistleblower and human trafficking survivor whose story I told earlier this year, is struggling to rebuild his life in a new country. He desperately needs tuition funds to keep his student visa, avoid deportation and stay safe. Anything you can give would go a long way: https://www.gofundme.com/f/support-whistleblower-journey-to-a-cybersecurity-degree (I have vetted this GoFundMe.) Thank you!
-
View post
A security researcher using Claude Opus 4.7 found the AI tool could independently code an exploit to hack into Front Gate Tickets, the ticketing platform for almost every major US music festival from Lollapalooza to Bonnaroo. He could then issue any tickets at will. https://www.wired.com/story/claude-helped-a-hacker-find-a-way-to-issue-tickets-to-almost-every-us-music-festival/
-
View post
I sat in on a close-door war game where the insurance industry simulated a cyberattack against US water utilities by Volt Typhoon, Chinese state hackers who have been penetrating US critical infrastructure since at least 2023. The results were catastrophic. https://www.wired.com/story/what-happens-if-china-hacks-the-us-water-supply-war-game-volt-typhoon/
-
View post
San Francisco police accidentally livestreamed their drones’ video and data on the open web. The hours of footage—including several apparent arrests—should never have been made public, but now offer a revelatory glimpse of modern aerial urban surveillance. Watch: https://www.wired.com/story/sfpd-drone-video-leak-surveillance/
-
View post
A device inside millions of cars has a security flaw that lets hackers unlock, track, even paralyze vehicles. There's a patch. The problem? Half of car owners who have the device installed didn't ask for it, and may not even know about it. Thread👇 https://www.wired.com/story/a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now/
-
View post
Researchers at security firm RedAccess found more than 5,000 vibe-coded apps, created with AI tools from Lovable, Replit, Base44 and Netlify, with essentially no security, accessible on the open web. About 40% exposed sensitive personal or corporate data. https://www.wired.com/story/thousands-of-vibe-coded-apps-expose-corporate-and-personal-data-on-the-open-web/
-
View post
A newly decoded piece of sabotage malware called Fast16, created even before Stuxnet, was designed to silently tamper with/corrupt calculations in research and engineering software. Likely created by the US or an ally, and possibly used against Iran&#39;s nuclear program. https://www.wired.com/story/fast16-malware-stuxnet-precursor-iran-nuclear-attack/
-
View post
Coming up on 3 weeks since Telegram-based black market Xinbi Guarantee, which has done $21 *billion* in sales, was sanctioned by the UK gov for enabling crypto scamming and human trafficking. Yet Telegram, which could ban Xinbi at any time, is still hosting it. https://www.wired.com/story/telegram-is-still-hosting-a-sanctioned-21-billion-crypto-scammer-black-market/
-
View post
New book coming next year. Working title, THE GRAYSCALE: True Stories of Hackers, Outlaws and Rogues From the Digital Underground.
-
View post
As Trump threatens scorched-earth attacks on Iran, a joint advisory from US agencies warns Iran-linked hackers have hit US critical infrastructure: &quot;In a few cases, this activity has resulted in operational disruption and financial loss.&quot; https://www.wired.com/story/iran-linked-hackers-are-sabotaging-us-energy-and-water-infrastructure/
-
View post
I don’t think I’ve ever had so many people writing to me to ask about encrypted/secure/private tools for comms, collaboration, and organizing. So @lhn and I talked to experts and assembled this: the Wired guide to organizing in an age of surveillance. https://www.wired.com/story/how-to-organize-safely-in-the-age-of-surveillance/
-
View post
Last year, a human trafficking victim trapped in a crypto scam compound in the Golden Triangle region of Laos contacted me. He proceeded to leak to me a huge collection of the compound&#39;s internal materials. Then he had to get out alive. This is his story. 🧵👇 https://www.wired.com/story/he-leaked-the-secrets-southeast-asian-scam-compound-then-had-to-get-out-alive/
-
View post
Two weeks after the DarkSword iOS hacking tool was revealed, Apple is taking the rare step of pushing a security fix to older iOS 18 iPhones rather than just telling users to update to iOS 26, as it had previously done. (Which left millions of iOS 18 users vulnerable.) https://www.wired.com/story/apple-will-push-out-rare-backported-patches-to-protect-ios-18-users-from-darksword-hacking-tool/
-
View post
Hacking internet-connected civilian security cameras for recon has become a standard operating procedure of modern warfare. First for Russia and Ukraine, now for Israel and Iran. Your insecure internet-of-things surveillance system is now their targeting system. https://www.wired.com/story/from-ukraine-to-iran-hacking-security-cameras-is-now-part-of-wars-playbook/
-
View post
Feds just took down 4 botnets, including the Aisuru and Kimwolf botnets that carried out record-breaking DDOS attacks peaking at 30+ terabits per second, nearly three times the previous record. DOJ says the botnets had hijacked more than three million devices. https://www.wired.com/story/us-takes-down-botnets-used-in-record-breaking-cyberattacks/
-
View post
As an IRS agent, Tigran Gambaryan was perhaps the most effective crypto investigator in history. Then last year he was charged in Nigeria with money laundering and thrown in prison. Throughout, he was texting with me from a secret phone. This is his full, untold story. https://www.wired.com/story/untold-story-crypto-crimefighters-descent-nigerian-prison-binance/
-
View post
A second iOS exploit has been found in the wild, again used by Russian spies to infect websites and hack visitors&#39; iPhones. This one works on iOS 18, and appeared in a very reusable form, so will likely proliferate. If you haven&#39;t updated your iPhone, now&#39;s the time. https://www.wired.com/story/hundreds-of-millions-of-iphones-can-be-hacked-with-a-new-tool-found-in-the-wild/