Elektrine lite

← Feed

Zack Whittaker

zackwhittaker@mastodon.social

<p>Security editor, TechCrunch<br />Email: zack.whittaker@techcrunch.com<br />Signal: zackwhittaker.1337<br />New York, NY</p>

Posts

  • Post #4495428

    This was really important, powerful reporting by @howelloneill. The US military’s cyberwarfare unit is scrutinizing an unusually high number of deaths by suicide among personnel over a month-long period this summer, according to government officials and other people familiar with the matter. https://www.bloomberg.com/news/articles/2026-08-06/us-military-s-cyber-command-unit-grapples-with-cluster-of-deaths-by-suicide

  • Post #4495427

    Two researchers scanned Poland&amp;#39;s internet out of a sense of patriotism and a desire to make it more secure, and found thousands of gov&amp;#39;t and public bodies were at risk of very easy hacks. One bug let them take over two-thirds of Poland&amp;#39;s court websites. More: https://techcrunch.com/2026/08/07/security-researchers-scanned-the-polish-web-and-found-courts-hospitals-and-airports-at-risk-of-hacks/ (Bypass for ad-blockers: https://archive.is/pDB7Q)

  • Post #4495426

    Microsoft wins &amp;quot;lamest vendor response&amp;quot; award at this year&amp;#39;s Pwnie Awards, for publishing a blog post earlier this year threatening security researchers with legal action if they published zero-days. Also: Meta wins &amp;quot;epic fail&amp;quot; award after its Meta AI hijack bug. By me: https://this.weekinsecurity.com/microsoft-wins-lamest-vendor-at-pwnie-awards-2026-for-threatening-security-researchers-with-legal-action/

  • Post #4495425

    FYI, probably the busiest https://this.weekinsecurity.com newsletter in a while dropping tomorrow, plus bonus bits on the blog and more. 🐈‍⬛ Sign up/RSS. (No email open/link tracking, because ew.)

  • Post #4495424

    RE: https://mastodon.social/@FirewallDragons/117032455172304541 Had a great time chatting with the very excellent @FirewallDragons about the things I&amp;#39;m thinking about the most in cybersecurity and privacy 👀 Have a listen! https://podcast.firewallsdontstopdragons.com/2026/08/03/top-cyber-threats-2026/

  • Post #4495423

    In my cyber newsletter ~ this week in security ~ The best from Black Hat, Def Con, and BSides Vegas (if you didn&amp;#39;t go!); hackers predicted a hardware wallet&amp;#39;s seed passwords; inside a China police spy dashboard; AI notetaker app exposed call recordings; Apple Private Relay leaked IP addresses; and much more. 🐈‍⬛ Read online: https://this.weekinsecurity.com/this-week-in-security-august-9-2026-edition/ Sign up: https://this.weekinsecurity.com

  • Post #4495422

    Join me and @runasand for a Reddit AMA (Ask Me Anything) this Weds 5pm PT about the first-of-its-kind prosecution of an American who allegedly gave border agents a &amp;quot;duress&amp;quot; password that wiped his phone. Raises important questions about data privacy constitutional rights, and what you can and can&amp;#39;t do at the border. 👀 Send in your questions! We&amp;#39;ll be answering as many as we can get through. More: https://reddit.com/r/pwnhub/comments/1vgovkv/we_are_techcrunch_s...

  • Post #4488457

    Bill Swearingen spent the past year developing a pattern that can defeat being detected by surveillance cameras, including vehicles and people. At Def Con, for the first time, he demoed the pattern printed on a car against a Flock camera to prove it works. (One of my favorite talks from Def Con this year!) More by me at TechCrunch: https://techcrunch.com/2026/08/09/this-adversarial-pattern-can-prevent-surveillance-cameras-from-detecting-you/ Ad-blocker bypass: https://web.archive.org/web/2026...

  • Post #4486239

    The U.S. gov&#39;t may have attributed the U.S. water hacks to Iran, but isn&#39;t sure exactly which group within Iran&#39;s Revolutionary Guards did it. Also: &quot;There may be a reluctance to make an attribution that contradicts the president’s public remarks.&quot; 🤦 More: https://www.washingtonpost.com/national-security/2026/08/10/us-water-systems-are-low-hanging-fruit-cyberattacks-experts-warn-after-suspected-iranian-hacks/

  • Post #4383867

    Another AI test gone awry, U.K. edition. &quot;An agent tried to insert malicious code into an open-source project. In an attempt to get the code approved, the agent engaged in social engineering — creating fake online identities and using them to pressure the project&#39;s maintainer to approve the code.&quot; More: https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing

  • Post #4382808

    An EFF investigation has found that some advertising SDKs enable location data collection by default. The findings aim to warn app developers that some of the third-party code they place in their apps may also collect their users’ location data when they grant permission to the app. More: https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy

  • Post #4380195

    By me: A major online ads company that claims to serve 1.5 billion ads a day was hacked and began serving malware designed to steal a person&#39;s crypto. This is the latest perfect example why you should use an ad-blocker. More: https://this.weekinsecurity.com/online-advertising-giant-adform-was-hacked-proving-once-again-why-ad-blockers-are-necessary/ Sign up (or RSS!) for the weekly newsletter: https://this.weekinsecurity.com

  • Post #4373641

    RE: https://mastodon.social/@zackwhittaker/117033323332487017 If there&#39;s one thing I&#39;ve learned from publishing this story is that there is a very, very, very wide chasm between what the law says about all this... and what people *think* the law says and/or *should* say.

  • Post #4363313

    After Anthropic and OpenAI both admitted to their AI models hacking other companies, @lorenzofb@infosec.exchange and I wanted to find out: Who is legally to blame when an autonomous AI agent hacks something? Lawyers say it&#39;s really complicated; one called it &quot;uncharted territory.&quot; Read more: https://techcrunch.com/2026/08/03/whos-legally-to-blame-for-anthropic-and-openais-autonomous-ai-hacks-its-complicated/ Bypass for ad-blockers: https://web.archive.org/web/20260803194912/https...

  • Post #4290179

    U.S. biotech giant Amgen confirms July hack, and says proprietary data, patients&#39; health data, and other information was exfiltrated from its cloud environments (Amgen runs largely on AWS). Amgen says volume &amp; types of data stolen &quot;could be sensitive.&quot; Amgen says it serves 17 million patients. 🫠 From the SEC filing: https://www.sec.gov/ix?doc=/Archives/edgar/data/0000318154/000031815426000119/amgn-20260729.htm

  • Post #4275779

    I&#39;d be interested to see if any of the companies that were hacked by OpenAI or Anthropic will sue them. Someone has to take responsibility for this, and the blame is almost entirely on the leaders of these AI companies. Alternatively, hacking is just legal now until a court says otherwise? What a fucking mess. https://www.wired.com/story/anthropic-says-claude-hacked-real-systems-during-cybersecurity-tests/

  • Post #4252991

    CareCloud, which stores patients&#39; medical records for 45,000+ hospitals &amp; healthcare providers across the U.S., has begun notifying hundreds of thousands of people that their data was stolen in a March breach. The notices reveal new details, and the number of affected people is expected to rise. More, by me: https://techcrunch.com/2026/07/30/carecloud-begins-to-notify-hundreds-of-thousands-after-hackers-stole-medical-records/ Bypass for ad-blockers: https://web.archive.org/web/20260730...

  • Post #4242569

    The U.S. FTC has sued Hims &amp; Hers, which prescribes for sexual wellness and mental health conditions, alleging the company shared customers&#39; sensitive medical data with advertising giants Meta and Snap through hidden website pixels. More: https://techcrunch.com/2026/07/30/ftc-sues-hims-hers-for-allegedly-sharing-patients-medical-data-with-advertisers-meta-and-snap/ Bypass for ad-blockers: https://web.archive.org/web/20260730133200/https://techcrunch.com/2026/07/30/ftc-sues-hims-hers-fo...

  • Post #4221639

    Really appreciate @brianhonan@mastodon.social sharing in his recent newsletter my guide on how to read a data breach notification, and how to parse the bullshit, even when there&#39;s very little disclosed. I wrote this for my paying subscribers following years of work investigating &amp; reporting on data breaches. https://this.weekinsecurity.com/how-to-read-and-understand-a-data-breach-notice/

  • Post #4215639

    Analog Devices, which makes a shit ton of computer chips, confirmed in an 8-K filing that it had a data breach in June where hackers exfiltrated data.The nature of the data is still under investigation, and nothing more for now, the company said. &quot;Separately and unrelated,&quot; the company goes on (👀), it&#39;s investigating a *second* security incident. I asked, but a spox. wouldn&#39;t comment beyond the statement. Here&#39;s the filing: https://www.sec.gov/ix?doc=/Archives/edgar/data...

  • Post #4213255

    RE: https://cyberplace.social/@GossiTheDog/117004159920714904 Solid thread here from @GossiTheDog@cyberplace.social and other defenders. ClickFix, phishing, and phone calls seem to be the big common threat themes, not AI.

  • Post #4113673

    In my latest weekly cyber newsletter: OpenAI admits to hacking Hugging Face, millions of cars with hidden alarms vulnerable to hacking, Iran&#39;s hacking water and energy systems, Russia&#39;s targeting nuclear scientists with an email zero-day, a healthcare hack sparks data theft fears, and much more. Read online: https://this.weekinsecurity.com/this-week-in-security-july-26-2026-edition/ Sign up/RSS and support: https://this.weekinsecurity.com

  • Post #4076078

    This has been a pretty busy (and wild!) week in cybersecurity, but keeping up can be a challenge. Every Sunday, I wrap up the most pressing and important cyber news you need to know &amp; more in my free weekly newsletter so you can stay ahead. Oh, and cats! 🐈‍⬛ Sign up (or RSS) and find out! My newsletter does not track email opens or clicks, because I care about your privacy. https://this.weekinsecurity.com

  • Post #4075657

    Incredibly detailed reporting by @razhael@infosec.exchange et al at Reuters on the OpenAI hack of Hugging Face, revealing new details on how it went down and how it took a week for OpenAI to notice one of its AI models was hacking into another company, citing multiple sources. More: https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/

  • Post #4069547

    New, by me: The Justice Department is prosecuting an American for allegedly providing U.S. border agents with a &quot;duress&quot; passcode that wiped the contents of his phone when they entered it. We&#39;ve confirmed the phone was running GrapheneOS. Read more: https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search Bypass for ad-blockers: https://web.archive.org/web/20260724175443/https://techcrunch.com/2026/07/24/us-a...

  • Post #4045205

    U.S. says Iranian hackers are upping their hacks on American water and energy providers to &quot;cause disruptive effects within the United States.&quot; FBI, NSA &amp; CISA say the critical infrastructure breaches are in response to the Iran war (no shit). More: https://techcrunch.com/2026/07/23/us-government-says-iran-linked-hackers-are-disrupting-american-water-and-energy-providers/ Bypass for ad-blockers: https://web.archive.org/web/20260723172853/https://techcrunch.com/2026/07/23/us-gover...

  • Post #4024339

    Have a peaceful evening, as much as Theo had a peaceful afternoon asleep, basking in the sun.

  • Post #4016036

    Proofpoint says out of ~950 companies surveyed, over one-third of companies that paid a hacker’s ransom were hit with a second extortion demand. More: https://techcrunch.com/2026/07/22/if-you-pay-a-hackers-ransom-chances-are-that-theyll-come-back-for-more/ (Bypass for ad-blockers: https://web.archive.org/web/20260722153047/https://techcrunch.com/2026/07/22/if-you-pay-a-hackers-ransom-chances-are-that-theyll-come-back-for-more/)

  • Post #4012034

    Most popular smart watches and fitness trackers aren&#39;t end-to-end encrypted, nor say how often governments demand access to users&#39; data. My argument: If wearable makers don&#39;t want to disclose that they&#39;re turning over users&#39; data to the feds, then the obvious fix is to end-to-end encrypt it. More: https://this.weekinsecurity.com/most-fitness-wearables-lack-end-to-end-encryption-and-lack-transparency-reports/

  • Post #4009796

    Even if Hugging Face is fine with all this (and honestly, why should it be; OpenAI clearly can&#39;t control a technology of its own making?), there&#39;s room for the USG to bring criminal CFAA charges against OpenAI. It&#39;s not like OpenAI execs wrote a blog post describing their crimes or anything. 🙄 https://www.theguardian.com/technology/2026/jul/22/openai-says-its-models-went-rogue-and-hacked-startup-in-unprecedented-incident