
A summary of recent developments in surveillance, cybersecurity vulnerabilities, and state-sponsored hacking.
AI-generated summary
The article summarizes various cybersecurity and privacy incidents occurring in the tech industry and geopolitical sphere. It highlights ongoing concerns regarding AI surveillance, payment fraud, and state-sponsored cyberattacks.
As the controversial vehicle surveillance giant Flock Safety continues to expand, WIRED got the code for the companyâs new AI policing tool and reconstructed the software to show that its capabilities go far beyond reading license plates and tracking vehicles. We also published the story this week of a Rhode Island police officer who was subjected to five internal affairs investigations in less than two years after he publicly questioned his departmentâs use of Flock cameras.
Following incidents of high-profile rogue activity by some of its AI agents, OpenAI said this week that it is halting model training runs and overhauling internal safety protocols. The company said that its upcoming Astra model may represent a turning point of âcriticalâ cyber capabilities.
A reverse-lookup identification service exposed millions of photos of peopleâs faces in a database accessible through the open internet. Meanwhile, Meta ran advertisements for an app that promised to nudify female politicians, including one ad featuring a pornographic video that included a deepfake resembling a well-known US politician. Apple removed the app from the App Store after WIREDâs inquiry.
And WIRED spoke with Andy Yen, CEO of the privacy-focused digital services company Proton, about the privacy implications of AI and how access to encryption can continue to expand in this new technological era.
But wait, thereâs more! Each week, we round up the security and privacy news we didnât cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.
Fraudsters Could Use âZombifiedâ Expired Visa Cards to Make Contactless Payments
Many people know that any active credit card represents a fraud risk the minute a card is lost, stolen, or otherwise gets out of their hands. Less expected is that an expired Visa card, too, could serve as an errant key into their bank account if itâs left unattended or discarded intact, discovered by a fraudster, and âzombifiedâ using a new technique researchers recently revealed.
At the Usenix Cybersecurity Conference last week, researchers at the University of Massachusetts Amherst warned that fraudsters could make contactless payments using expired credit cards issued by Visa by proxying them through a man-in-the-middle app that relays the credit cardâs data through a pair of phones. Due to issues in the authentication chain of contactless payments, the researchers found that whether an expired cardâs transaction would be disallowed was left to cryptography implemented differently by various card issuers. Visaâs had a particular flaw allowing out-of-date cards to pass its check.
In fact, as the researchers describe it, Visaâs essentially passed on the task of authenticating these transactions to the cardholderâs bankâand while some banks prevented the use of the zombified cards, others didnât. The result is that fraudsters could in some cases dumpster dive for an expired card and use it to make payments from the unwitting ownerâs accountâparticularly at point-of-sale terminals where no human is present to look askance at their phone-based proxy setup.
The lesson: When that Visa card expires, a pair of scissors can ensure it doesnât reanimate in someone elseâs hands.
Apple Sent Out an âUnprecedentedâ Number of Hacked-Device Warnings
Apple has long sent out notification to the owners of iPhones and other devices itâs detected may be the target of what it calls âmercenary spywareââsophisticated, stealthy malware installed by a government or state-sponsored hacker-for-hire. Last weekend, the number of those alerts sent to potential victims spiked to an âunprecedentedâ number, according to TechCrunch, which spoke to security analysts who investigate potential spyware intrusions. The alerts, which were sent out to potential hacking targets in 110 countries, reached numbers of users more than 30 percent higher than previous rounds of these alerts, by the estimate of Mohammed Al-Maskati, who leads a team of security investigators at Access Now, a digital rights group that Apple refers victims to in its spyware alerts. At least one target, TechCrunch noted, was a Ukrainian soldier, who said that others in the Ukrainian military had also received the alert. Sophisticated iPhone hacking campaigns may well be on the rise: Just this year, researchers at iVerify and Google uncovered two iOS mass-hacking tools known as DarkSword and Coruna.
Ukraine Says It Hit Russian Ecommerce Giant With a Cyberattackâand Drones
In Russiaâs decade-plus cyberwar against Ukraine, it has at times experimented with combined physical and digital attacks, such as triggering a hacker-induced blackout in a Ukrainian city in the midst of an air raid. Now, as Ukraine increasingly strikes back against Russia in an effort to impose cost on its invaders, it appears to have tried a similar tactic. The Ukrainian military this week claimed to have carried out a disruptive cyberattack against Russian ecommerce giant Wildberriesâby some measures, the Russian equivalent of Amazonâin the midst of drone attacks that have also destroyed parts of the companyâs warehouse infrastructure, according to cybersecurity news outlet The Record. While Wildberries is largely a consumer retail business, The Ukrainian Main Intelligence Directorate also claimed that it is part of Russiaâs sells military logistics and played a role in financing the war in the Ukraine. The Record couldnât confirm the exact effects of the cyberattack on Wildberries, but it notes that Russian media has reported that the company has lost nearly 13 million square feet of warehouse space to drone attacks.

A roundup of tech and science developments including NASA's cancellation of the Swift telescope rescue, Tesla's massive recall in China, Meta's ongoing legal challenges regarding child safety, and the rise of Inner Mongolia as an AI data center hub.

A humanoid robot named Lightning, developed by Honor, completed a 100-metre sprint in 9.32 seconds, beating Usain Bolt's 9.58-second human world record. The feat occurred during preparations for the World Humanoid Robot Games in Beijing.

Ulanqab, Inner Mongolia, is rapidly becoming a major AI data center hub due to low energy costs and cold climate. While companies like DeepSeek and ByteDance invest heavily, the region faces significant water scarcity and ongoing reliance on coal power.

Award-winning Hollywood writers and directors are taking gig jobs paying $12 to $200 an hour to train AI models, seeking income amid a severe industry job slump despite concerns they are helping automate their own professions.

Experts in Silicon Valley warn of an imminent AI takeoff and existential risks, citing recursive self-improvement, autonomous agent breakouts, and a lack of global regulatory coordination amid US-China rivalry.

Meta faces a landmark trial brought by U.S. states seeking to ban addictive design features on Instagram and Facebook, potentially reshaping social media and setting a major precedent.