×

slapped export control restrictions on Anthropic’s much-hyped AI models Mythos and Fable. The move was prompted at least in part by a report that claimed it was possible to bypass the models’ guardrails designed to prevent users from using them to build and execute malicious cyberattacks.

Regardless of whether the incident was really motivated by fears of a jailbreak, the fact is that Anthropic has repeatedly marketed Mythos as some kind of doomsday cybermachine that can only be given to carefully vetted users, and even then with strict guardrails in place. (The export controls on Fable 5 and Mythos 5 have since been lifted. Fable 5 returned to general access on July 1; Mythos 5 has been reintroduced only to vetted U.S. organizations as part of the government’s review process.)

That kind of gatekeeping isn’t unique to Mythos. Both Anthropic, with its other models, and OpenAI offer cybersecurity researchers programs they can apply to get vetted and — if approved — access models with fewer cybersecurity restrictions: OpenAI’s Trusted Access for Cyber program and Anthropic’s Cyber Verification Program

These guardrails have been widely criticized, particularly by researchers whose job is to find unknown vulnerabilities in systems and devise ways to exploit them before criminals do.

During a recent appearance on a cybersecurity podcast, Mark Dowd, a well-known security researcher, said that, “it’s not really comfortable to me that these random large companies are making arbitrary decisions about what is safe in security and what’s not.”

Dowd has spent decades finding and selling “zero-days” — previously unknown software flaws and the exploits that take advantage of them — to Western governments, rather than reporting them to the software makers so they get patched. Governments pay a premium for vulnerabilities precisely because they stay open, which is useful for intelligence operations.

Dowd admitted his work may make him biased, but he isn’t alone. Several people who work in offensive cybersecurity — they proactively probe systems for weaknesses — described to TechCrunch how they use AI tools and deal with their guardrails. 

Chris Anley, the chief scientist at security consulting giant NCC Group, said that asking an AI model to try to exploit a bug is a key step in confirming it’s a real vulnerability worth fixing. But if a guardrail prompts the model to refuse to answer the question outright, the guardrail hurts defenders, he said.

“This is where the whole offensive versus defensive and guardrails part comes in, because ‘fix this code’ as a prompt is both an essential mechanism for defense but also a roadmap for finding critical vulnerabilities in the code base,” said Anley. “So at the same time, the same tool is both an offensive tool and a defensive tool, and the two can’t really be unpicked.”

It’s “like a hammer,” he continued. “You can’t build a house without a hammer. It’s definitely a tool but it’s also irreducibly a weapon as well.”

When he and his colleagues run into such a roadblock, they sometimes fall back on open source AI models that come with no guardrails at all.

Paolo Stagno, the chief technology officer at Crowdfense, a well-known company that develops, acquires, and sells unknown vulnerabilities to government agencies, agreed with Dowd, saying AI companies “essentially treat customers like children who need babysitting” with their vetted programs and guardrails. 

Stagno said he and his colleagues do use frontier models — but only for reverse engineering. They avoid using AI to help find vulnerabilities or build exploits, he said, because feeding that work into a cloud-based model risks leaking sensitive vulnerability data or having it absorbed into future training runs. For that step, he said, they use open source models run locally, as they do not rely on sharing data outside of the model. 

Giuseppe Cali, a security researcher who finds zero-days and develops exploits, said guardrails are not impeding his work. That’s because he doesn’t use AI for offensive work; instead, he uses it for initial reverse engineering, to understand the code he’s analyzing, and to build supporting tools. For that, he said, AI tools can speed up the process and allow him to focus on discovering vulnerabilities. 

“I still want to own the actual bug discovery and weaponization myself and that wouldn’t change if all guardrails were lifted tomorrow,” said Cali. “I am jealous of my bugs, and I like this game too much to let models play it for me.”

One researcher at a smartphone-component manufacturer, who spoke on condition of anonymity because he isn’t authorized to talk to the press, said his employer isn’t part of Anthropic’s CVP program and as a result, its tools are barely useful for finding vulnerabilities because the guardrails are too strict.

“If it catches wind we’re doing anything security related, it just stops and isn’t usable,” the person said. 

Chris Thompson — chief executive of cybersecurity firm RemoteThreat and founder of Offensive AI Con, an offensive security and AI-focused event — said that in his experience using the frontier AI models, the guardrails can be inconsistent and work differently every day. That’s true even inside the looser boundaries of Anthropic’s and OpenAI’s vetted programs. 

“I think the practical impact is you spend a lot of time negotiating with the model instead of working on the core security program,” said Thompson. “Instead of analyzing a vulnerability and reasoning through the exploitability, you’re trying to find why you’re getting inconsistent results or why are models over-sanitizing the output.” 

Consequently, researchers rely on or get pushed toward Chinese open source models like GLM — freely downloadable models that can be run locally with no vetting or usage restrictions — said Thompson.

“You have these responsible researchers that are being pushed away from U.S.-governed systems to foreign-owned systems,” he said. “I think it’s more harmful than good to have these guardrails in place.”

Rather than tightening restrictions further, Thompson called for the AI frontier labs to open up their programs, provide responsible access, and hold those who abuse their tools accountable. Otherwise, he argued, defenders will lose the AI race.

“There’s this big storm coming. There’s this big wave of attacks that are going to happen at speed and scale like never before,” said Thompson. “But the same security consulting firms and legit researchers that are trying to make a difference are being stifled right now.”

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#guardrails #impeding #work #offensive #cybersecurity #researchers #TechCrunchcybersecurity,Zero-days"> How AI guardrails are impeding the work of offensive cybersecurity researchers | TechCrunch
For months, AI giants have devised special vetted programs and strict guardrails to limit the use of their models by malicious hackers. But these limits are now hindering the work of legitimate network defenders, as well as that of offensive cybersecurity researchers. 

In June, the U.S. government slapped export control restrictions on Anthropic’s much-hyped AI models Mythos and Fable. The move was prompted at least in part by a report that claimed it was possible to bypass the models’ guardrails designed to prevent users from using them to build and execute malicious cyberattacks.







Regardless of whether the incident was really motivated by fears of a jailbreak, the fact is that Anthropic has repeatedly marketed Mythos as some kind of doomsday cybermachine that can only be given to carefully vetted users, and even then with strict guardrails in place. (The export controls on Fable 5 and Mythos 5 have since been lifted. Fable 5 returned to general access on July 1; Mythos 5 has been reintroduced only to vetted U.S. organizations as part of the government’s review process.)

That kind of gatekeeping isn’t unique to Mythos. Both Anthropic, with its other models, and OpenAI offer cybersecurity researchers programs they can apply to get vetted and — if approved — access models with fewer cybersecurity restrictions: OpenAI’s Trusted Access for Cyber program and Anthropic’s Cyber Verification Program. 

These guardrails have been widely criticized, particularly by researchers whose job is to find unknown vulnerabilities in systems and devise ways to exploit them before criminals do.

During a recent appearance on a cybersecurity podcast, Mark Dowd, a well-known security researcher, said that, “it’s not really comfortable to me that these random large companies are making arbitrary decisions about what is safe in security and what’s not.”

Dowd has spent decades finding and selling “zero-days” — previously unknown software flaws and the exploits that take advantage of them — to Western governments, rather than reporting them to the software makers so they get patched. Governments pay a premium for vulnerabilities precisely because they stay open, which is useful for intelligence operations.


Dowd admitted his work may make him biased, but he isn’t alone. Several people who work in offensive cybersecurity — they proactively probe systems for weaknesses  — described to TechCrunch how they use AI tools and deal with their guardrails. 

Chris Anley, the chief scientist at security consulting giant NCC Group, said that asking an AI model to try to exploit a bug is a key step in confirming it’s a real vulnerability worth fixing. But if a guardrail prompts the model to refuse to answer the question outright, the guardrail hurts defenders, he said. 

“This is where the whole offensive versus defensive and guardrails part comes in, because ‘fix this code’ as a prompt is both an essential mechanism for defense but also a roadmap for finding critical vulnerabilities in the code base,” said Anley. “So at the same time, the same tool is both an offensive tool and a defensive tool, and the two can’t really be unpicked.” 







It’s “like a hammer,” he continued. “You can’t build a house without a hammer. It’s definitely a tool but it’s also irreducibly a weapon as well.”

When he and his colleagues run into such a roadblock, they sometimes fall back on open source AI models that come with no guardrails at all.

Paolo Stagno, the chief technology officer at Crowdfense, a well-known company that develops, acquires, and sells unknown vulnerabilities to government agencies, agreed with Dowd, saying AI companies “essentially treat customers like children who need babysitting” with their vetted programs and guardrails. 

Stagno said he and his colleagues do use frontier models — but only for reverse engineering. They avoid using AI to help find vulnerabilities or build exploits, he said, because feeding that work into a cloud-based model risks leaking sensitive vulnerability data or having it absorbed into future training runs. For that step, he said, they use open source models run locally, as they do not rely on sharing data outside of the model. 

Giuseppe Cali, a security researcher who finds zero-days and develops exploits, said guardrails are not impeding his work. That’s because he doesn’t use AI for offensive work; instead, he uses it for initial reverse engineering, to understand the code he’s analyzing, and to build supporting tools. For that, he said, AI tools can speed up the process and allow him to focus on discovering vulnerabilities. 

“I still want to own the actual bug discovery and weaponization myself and that wouldn’t change if all guardrails were lifted tomorrow,” said Cali. “I am jealous of my bugs, and I like this game too much to let models play it for me.”

One researcher at a smartphone-component manufacturer, who spoke on condition of anonymity because he isn’t authorized to talk to the press, said his employer isn’t part of Anthropic’s CVP program and as a result, its tools are barely useful for finding vulnerabilities because the guardrails are too strict.

“If it catches wind we’re doing anything security related, it just stops and isn’t usable,” the person said. 







Chris Thompson — chief executive of cybersecurity firm RemoteThreat and founder of Offensive AI Con, an offensive security and AI-focused event — said that in his experience using the frontier AI models, the guardrails can be inconsistent and work differently every day. That’s true even inside the looser boundaries of Anthropic’s and OpenAI’s vetted programs. 

“I think the practical impact is you spend a lot of time negotiating with the model instead of working on the core security program,” said Thompson. “Instead of analyzing a vulnerability and reasoning through the exploitability, you’re trying to find why you’re getting inconsistent results or why are models over-sanitizing the output.” 

Consequently, researchers rely on or get pushed toward Chinese open source models like GLM — freely downloadable models that can be run locally with no vetting or usage restrictions — said Thompson.

“You have these responsible researchers that are being pushed away from U.S.-governed systems to foreign-owned systems,” he said. “I think it’s more harmful than good to have these guardrails in place.”

Rather than tightening restrictions further, Thompson called for the AI frontier labs to open up their programs, provide responsible access, and hold those who abuse their tools accountable. Otherwise, he argued, defenders will lose the AI race.

“There’s this big storm coming. There’s this big wave of attacks that are going to happen at speed and scale like never before,” said Thompson. “But the same security consulting firms and legit researchers that are trying to make a difference are being stifled right now.”


When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.#guardrails #impeding #work #offensive #cybersecurity #researchers #TechCrunchcybersecurity,Zero-days
Tech-news

slapped export control restrictions on Anthropic’s much-hyped AI models Mythos and Fable. The move was prompted at least in part by a report that claimed it was possible to bypass the models’ guardrails designed to prevent users from using them to build and execute malicious cyberattacks.

Regardless of whether the incident was really motivated by fears of a jailbreak, the fact is that Anthropic has repeatedly marketed Mythos as some kind of doomsday cybermachine that can only be given to carefully vetted users, and even then with strict guardrails in place. (The export controls on Fable 5 and Mythos 5 have since been lifted. Fable 5 returned to general access on July 1; Mythos 5 has been reintroduced only to vetted U.S. organizations as part of the government’s review process.)

That kind of gatekeeping isn’t unique to Mythos. Both Anthropic, with its other models, and OpenAI offer cybersecurity researchers programs they can apply to get vetted and — if approved — access models with fewer cybersecurity restrictions: OpenAI’s Trusted Access for Cyber program and Anthropic’s Cyber Verification Program

These guardrails have been widely criticized, particularly by researchers whose job is to find unknown vulnerabilities in systems and devise ways to exploit them before criminals do.

During a recent appearance on a cybersecurity podcast, Mark Dowd, a well-known security researcher, said that, “it’s not really comfortable to me that these random large companies are making arbitrary decisions about what is safe in security and what’s not.”

Dowd has spent decades finding and selling “zero-days” — previously unknown software flaws and the exploits that take advantage of them — to Western governments, rather than reporting them to the software makers so they get patched. Governments pay a premium for vulnerabilities precisely because they stay open, which is useful for intelligence operations.

Dowd admitted his work may make him biased, but he isn’t alone. Several people who work in offensive cybersecurity — they proactively probe systems for weaknesses — described to TechCrunch how they use AI tools and deal with their guardrails. 

Chris Anley, the chief scientist at security consulting giant NCC Group, said that asking an AI model to try to exploit a bug is a key step in confirming it’s a real vulnerability worth fixing. But if a guardrail prompts the model to refuse to answer the question outright, the guardrail hurts defenders, he said.

“This is where the whole offensive versus defensive and guardrails part comes in, because ‘fix this code’ as a prompt is both an essential mechanism for defense but also a roadmap for finding critical vulnerabilities in the code base,” said Anley. “So at the same time, the same tool is both an offensive tool and a defensive tool, and the two can’t really be unpicked.”

It’s “like a hammer,” he continued. “You can’t build a house without a hammer. It’s definitely a tool but it’s also irreducibly a weapon as well.”

When he and his colleagues run into such a roadblock, they sometimes fall back on open source AI models that come with no guardrails at all.

Paolo Stagno, the chief technology officer at Crowdfense, a well-known company that develops, acquires, and sells unknown vulnerabilities to government agencies, agreed with Dowd, saying AI companies “essentially treat customers like children who need babysitting” with their vetted programs and guardrails. 

Stagno said he and his colleagues do use frontier models — but only for reverse engineering. They avoid using AI to help find vulnerabilities or build exploits, he said, because feeding that work into a cloud-based model risks leaking sensitive vulnerability data or having it absorbed into future training runs. For that step, he said, they use open source models run locally, as they do not rely on sharing data outside of the model. 

Giuseppe Cali, a security researcher who finds zero-days and develops exploits, said guardrails are not impeding his work. That’s because he doesn’t use AI for offensive work; instead, he uses it for initial reverse engineering, to understand the code he’s analyzing, and to build supporting tools. For that, he said, AI tools can speed up the process and allow him to focus on discovering vulnerabilities. 

“I still want to own the actual bug discovery and weaponization myself and that wouldn’t change if all guardrails were lifted tomorrow,” said Cali. “I am jealous of my bugs, and I like this game too much to let models play it for me.”

One researcher at a smartphone-component manufacturer, who spoke on condition of anonymity because he isn’t authorized to talk to the press, said his employer isn’t part of Anthropic’s CVP program and as a result, its tools are barely useful for finding vulnerabilities because the guardrails are too strict.

“If it catches wind we’re doing anything security related, it just stops and isn’t usable,” the person said. 

Chris Thompson — chief executive of cybersecurity firm RemoteThreat and founder of Offensive AI Con, an offensive security and AI-focused event — said that in his experience using the frontier AI models, the guardrails can be inconsistent and work differently every day. That’s true even inside the looser boundaries of Anthropic’s and OpenAI’s vetted programs. 

“I think the practical impact is you spend a lot of time negotiating with the model instead of working on the core security program,” said Thompson. “Instead of analyzing a vulnerability and reasoning through the exploitability, you’re trying to find why you’re getting inconsistent results or why are models over-sanitizing the output.” 

Consequently, researchers rely on or get pushed toward Chinese open source models like GLM — freely downloadable models that can be run locally with no vetting or usage restrictions — said Thompson.

“You have these responsible researchers that are being pushed away from U.S.-governed systems to foreign-owned systems,” he said. “I think it’s more harmful than good to have these guardrails in place.”

Rather than tightening restrictions further, Thompson called for the AI frontier labs to open up their programs, provide responsible access, and hold those who abuse their tools accountable. Otherwise, he argued, defenders will lose the AI race.

“There’s this big storm coming. There’s this big wave of attacks that are going to happen at speed and scale like never before,” said Thompson. “But the same security consulting firms and legit researchers that are trying to make a difference are being stifled right now.”

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#guardrails #impeding #work #offensive #cybersecurity #researchers #TechCrunchcybersecurity,Zero-days">How AI guardrails are impeding the work of offensive cybersecurity researchers | TechCrunch

For months, AI giants have devised special vetted programs and strict guardrails to limit the use of their models by malicious hackers. But these limits are now hindering the work of legitimate network defenders, as well as that of offensive cybersecurity researchers. 

In June, the U.S. government slapped export control restrictions on Anthropic’s much-hyped AI models Mythos and Fable. The move was prompted at least in part by a report that claimed it was possible to bypass the models’ guardrails designed to prevent users from using them to build and execute malicious cyberattacks.

Regardless of whether the incident was really motivated by fears of a jailbreak, the fact is that Anthropic has repeatedly marketed Mythos as some kind of doomsday cybermachine that can only be given to carefully vetted users, and even then with strict guardrails in place. (The export controls on Fable 5 and Mythos 5 have since been lifted. Fable 5 returned to general access on July 1; Mythos 5 has been reintroduced only to vetted U.S. organizations as part of the government’s review process.)

That kind of gatekeeping isn’t unique to Mythos. Both Anthropic, with its other models, and OpenAI offer cybersecurity researchers programs they can apply to get vetted and — if approved — access models with fewer cybersecurity restrictions: OpenAI’s Trusted Access for Cyber program and Anthropic’s Cyber Verification Program

These guardrails have been widely criticized, particularly by researchers whose job is to find unknown vulnerabilities in systems and devise ways to exploit them before criminals do.

During a recent appearance on a cybersecurity podcast, Mark Dowd, a well-known security researcher, said that, “it’s not really comfortable to me that these random large companies are making arbitrary decisions about what is safe in security and what’s not.”

Dowd has spent decades finding and selling “zero-days” — previously unknown software flaws and the exploits that take advantage of them — to Western governments, rather than reporting them to the software makers so they get patched. Governments pay a premium for vulnerabilities precisely because they stay open, which is useful for intelligence operations.

Dowd admitted his work may make him biased, but he isn’t alone. Several people who work in offensive cybersecurity — they proactively probe systems for weaknesses — described to TechCrunch how they use AI tools and deal with their guardrails. 

Chris Anley, the chief scientist at security consulting giant NCC Group, said that asking an AI model to try to exploit a bug is a key step in confirming it’s a real vulnerability worth fixing. But if a guardrail prompts the model to refuse to answer the question outright, the guardrail hurts defenders, he said.

“This is where the whole offensive versus defensive and guardrails part comes in, because ‘fix this code’ as a prompt is both an essential mechanism for defense but also a roadmap for finding critical vulnerabilities in the code base,” said Anley. “So at the same time, the same tool is both an offensive tool and a defensive tool, and the two can’t really be unpicked.”

It’s “like a hammer,” he continued. “You can’t build a house without a hammer. It’s definitely a tool but it’s also irreducibly a weapon as well.”

When he and his colleagues run into such a roadblock, they sometimes fall back on open source AI models that come with no guardrails at all.

Paolo Stagno, the chief technology officer at Crowdfense, a well-known company that develops, acquires, and sells unknown vulnerabilities to government agencies, agreed with Dowd, saying AI companies “essentially treat customers like children who need babysitting” with their vetted programs and guardrails. 

Stagno said he and his colleagues do use frontier models — but only for reverse engineering. They avoid using AI to help find vulnerabilities or build exploits, he said, because feeding that work into a cloud-based model risks leaking sensitive vulnerability data or having it absorbed into future training runs. For that step, he said, they use open source models run locally, as they do not rely on sharing data outside of the model. 

Giuseppe Cali, a security researcher who finds zero-days and develops exploits, said guardrails are not impeding his work. That’s because he doesn’t use AI for offensive work; instead, he uses it for initial reverse engineering, to understand the code he’s analyzing, and to build supporting tools. For that, he said, AI tools can speed up the process and allow him to focus on discovering vulnerabilities. 

“I still want to own the actual bug discovery and weaponization myself and that wouldn’t change if all guardrails were lifted tomorrow,” said Cali. “I am jealous of my bugs, and I like this game too much to let models play it for me.”

One researcher at a smartphone-component manufacturer, who spoke on condition of anonymity because he isn’t authorized to talk to the press, said his employer isn’t part of Anthropic’s CVP program and as a result, its tools are barely useful for finding vulnerabilities because the guardrails are too strict.

“If it catches wind we’re doing anything security related, it just stops and isn’t usable,” the person said. 

Chris Thompson — chief executive of cybersecurity firm RemoteThreat and founder of Offensive AI Con, an offensive security and AI-focused event — said that in his experience using the frontier AI models, the guardrails can be inconsistent and work differently every day. That’s true even inside the looser boundaries of Anthropic’s and OpenAI’s vetted programs. 

“I think the practical impact is you spend a lot of time negotiating with the model instead of working on the core security program,” said Thompson. “Instead of analyzing a vulnerability and reasoning through the exploitability, you’re trying to find why you’re getting inconsistent results or why are models over-sanitizing the output.” 

Consequently, researchers rely on or get pushed toward Chinese open source models like GLM — freely downloadable models that can be run locally with no vetting or usage restrictions — said Thompson.

“You have these responsible researchers that are being pushed away from U.S.-governed systems to foreign-owned systems,” he said. “I think it’s more harmful than good to have these guardrails in place.”

Rather than tightening restrictions further, Thompson called for the AI frontier labs to open up their programs, provide responsible access, and hold those who abuse their tools accountable. Otherwise, he argued, defenders will lose the AI race.

“There’s this big storm coming. There’s this big wave of attacks that are going to happen at speed and scale like never before,” said Thompson. “But the same security consulting firms and legit researchers that are trying to make a difference are being stifled right now.”

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#guardrails #impeding #work #offensive #cybersecurity #researchers #TechCrunchcybersecurity,Zero-days

For months, AI giants have devised special vetted programs and strict guardrails to limit the…

in a postmortem report that its staff “had to spend time building [a playbook] during the early stages of the incident.” The agency said it is important to prepare playbooks for “all anticipated needs” to ensure that organizations are ready to respond in the event of a security incident rather than scrambling to improvise one in real time.

The agency did not say how long the missing playbook delayed CISA’s response, and a spokesperson did not immediately respond to TechCrunch’s request for comment. 

Independent cybersecurity journalist Brian Krebs reported in May that a security researcher with cyber firm GitGuardian alerted him to reams of exposed passwords stored in a publicly accessible GitHub repository, which an employee of a CISA contractor had uploaded.

According to Krebs, the researcher tried to alert the contractor but didn’t hear back. Only after Krebs contacted CISA did the agency take the repository offline and revoke and replace all of the exposed credentials to prevent any potential future abuse.

CISA said that no customer or mission data was exposed in the incident and thanked the researcher and reporter for their help. The agency said that its channels for allowing security researchers to notify CISA of potential incidents “were not well defined,” and that it has made changes to make it easier and faster for researchers to contact the agency.

CISA has been without a permanent director since the start of President Donald Trump’s second term in January 2025. The agency has also been affected by cuts, furloughs, and layoffs affecting about a third of its workforce since Trump took office. 

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#cybersecurity #agency #CISA #build #incident #playbook #incident #agency #reveals #TechCrunchCISA,cybersecurity,us government"> US cybersecurity agency CISA had to build its incident playbook during the incident, agency reveals | TechCrunch
U.S. federal cybersecurity agency CISA said it did not have a prepared response plan for how it should handle a cybersecurity incident in May, after an investigative reporter notified the agency that a contractor had publicly exposed sensitive keys and credentials for accessing U.S. government systems.

CISA, the Homeland Security unit tasked with defending federal networks and helping to safeguard critical infrastructure, revealed Friday in a postmortem report that its staff “had to spend time building [a playbook] during the early stages of the incident.” The agency said it is important to prepare playbooks for “all anticipated needs” to ensure that organizations are ready to respond in the event of a security incident rather than scrambling to improvise one in real time.







The agency did not say how long the missing playbook delayed CISA’s response, and a spokesperson did not immediately respond to TechCrunch’s request for comment. 

Independent cybersecurity journalist Brian Krebs reported in May that a security researcher with cyber firm GitGuardian alerted him to reams of exposed passwords stored in a publicly accessible GitHub repository, which an employee of a CISA contractor had uploaded.

According to Krebs, the researcher tried to alert the contractor but didn’t hear back. Only after Krebs contacted CISA did the agency take the repository offline and revoke and replace all of the exposed credentials to prevent any potential future abuse.

CISA said that no customer or mission data was exposed in the incident and thanked the researcher and reporter for their help. The agency said that its channels for allowing security researchers to notify CISA of potential incidents “were not well defined,” and that it has made changes to make it easier and faster for researchers to contact the agency.

CISA has been without a permanent director since the start of President Donald Trump’s second term in January 2025. The agency has also been affected by cuts, furloughs, and layoffs affecting about a third of its workforce since Trump took office. 
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.#cybersecurity #agency #CISA #build #incident #playbook #incident #agency #reveals #TechCrunchCISA,cybersecurity,us government
Tech-news

in a postmortem report that its staff “had to spend time building [a playbook] during the early stages of the incident.” The agency said it is important to prepare playbooks for “all anticipated needs” to ensure that organizations are ready to respond in the event of a security incident rather than scrambling to improvise one in real time.

The agency did not say how long the missing playbook delayed CISA’s response, and a spokesperson did not immediately respond to TechCrunch’s request for comment. 

Independent cybersecurity journalist Brian Krebs reported in May that a security researcher with cyber firm GitGuardian alerted him to reams of exposed passwords stored in a publicly accessible GitHub repository, which an employee of a CISA contractor had uploaded.

According to Krebs, the researcher tried to alert the contractor but didn’t hear back. Only after Krebs contacted CISA did the agency take the repository offline and revoke and replace all of the exposed credentials to prevent any potential future abuse.

CISA said that no customer or mission data was exposed in the incident and thanked the researcher and reporter for their help. The agency said that its channels for allowing security researchers to notify CISA of potential incidents “were not well defined,” and that it has made changes to make it easier and faster for researchers to contact the agency.

CISA has been without a permanent director since the start of President Donald Trump’s second term in January 2025. The agency has also been affected by cuts, furloughs, and layoffs affecting about a third of its workforce since Trump took office. 

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#cybersecurity #agency #CISA #build #incident #playbook #incident #agency #reveals #TechCrunchCISA,cybersecurity,us government">US cybersecurity agency CISA had to build its incident playbook during the incident, agency reveals | TechCrunch

U.S. federal cybersecurity agency CISA said it did not have a prepared response plan for how it should handle a cybersecurity incident in May, after an investigative reporter notified the agency that a contractor had publicly exposed sensitive keys and credentials for accessing U.S. government systems.

CISA, the Homeland Security unit tasked with defending federal networks and helping to safeguard critical infrastructure, revealed Friday in a postmortem report that its staff “had to spend time building [a playbook] during the early stages of the incident.” The agency said it is important to prepare playbooks for “all anticipated needs” to ensure that organizations are ready to respond in the event of a security incident rather than scrambling to improvise one in real time.

The agency did not say how long the missing playbook delayed CISA’s response, and a spokesperson did not immediately respond to TechCrunch’s request for comment. 

Independent cybersecurity journalist Brian Krebs reported in May that a security researcher with cyber firm GitGuardian alerted him to reams of exposed passwords stored in a publicly accessible GitHub repository, which an employee of a CISA contractor had uploaded.

According to Krebs, the researcher tried to alert the contractor but didn’t hear back. Only after Krebs contacted CISA did the agency take the repository offline and revoke and replace all of the exposed credentials to prevent any potential future abuse.

CISA said that no customer or mission data was exposed in the incident and thanked the researcher and reporter for their help. The agency said that its channels for allowing security researchers to notify CISA of potential incidents “were not well defined,” and that it has made changes to make it easier and faster for researchers to contact the agency.

CISA has been without a permanent director since the start of President Donald Trump’s second term in January 2025. The agency has also been affected by cuts, furloughs, and layoffs affecting about a third of its workforce since Trump took office. 

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#cybersecurity #agency #CISA #build #incident #playbook #incident #agency #reveals #TechCrunchCISA,cybersecurity,us government

U.S. federal cybersecurity agency CISA said it did not have a prepared response plan for…

tasked with investigating phone spyware attacks by European governments, has been publicly identified as a victim of spyware.

Kouloglou told TechCrunch in a phone call that the deliberate compromise of his phone was “reckless.” One serving European lawmaker described the hacking of Kouloglou’s phone as a “direct attack on the rule of law,” and called on the European Commission to take concrete action by imposing strict limits on the use of spyware across the 27 member-state bloc.

While spyware attacks on lawmakers are rare, the timing and targeting of a committee investigator by way of the very spyware under his investigation suggests an intense focus on the committee’s inner workings ahead of a widely anticipated report detailing its findings. The hacks open fresh questions about how governments use spyware ostensibly needed for identifying serious crime, but then caught spying on the communications of journalists, lawmakers, and critics.

Citizen Lab’s researchers did not attribute the phone hacking to a specific country, but said that the government customer used the same Pegasus-loaded email address that was used in a previous campaign that hacked into the phones of journalists across Europe. The customer’s identity is not known, but the reuse of the same attacking email address implies that the customer had NSO Group’s authorization to use its Pegasus spyware to snoop on phones across multiple countries in Europe.

A spokesperson for the European Commission did not respond to TechCrunch’s request for comment. NSO Group also did not respond to a request for comment about the Citizen Lab report prior to publication.

In its report out Friday, Citizen Lab said Kouloglou was hacked in October 2022 and at least twice during March 2023 using an exploit that compromised a security vulnerability in Apple’s iPhone software. This vulnerability had been patched but the fix was not yet installed on Kouloglou’s phone. The exploit was a “zero-click” bug, meaning the spyware broke in and stole his data without needing any interaction on his part.

The bug abused a previously discovered flaw in Apple’s smart home software used in iPhones. It allowed the spyware to grab private data from Kouloglou’s phone without his knowledge, such as his text messages and other correspondence, location data, and photos.

The timing of the October 2022 hack coincides with intense discussions over email and text message throughout October and November 2022, ahead of the delivery of a first draft describing spyware abuses focusing in Cyprus, Greece, Hungary, Poland, and Spain. 

The hack also lines up at the exact time that Kouloglou was in the hospital at the time for a pre-scheduled surgery, which may have allowed the spyware operators to listen in to ambient audio discussing his healthcare or other conversations he had with visitors at the time.

Months later on March 6 and 7, Citizen Lab said Kouloglou’s phone was hacked again by the same Pegasus operator while Kouloglou traveled from Athens to Brussels, during a period of committee hearings and months prior to the committee finalizing and adopting their written draft report.

In a call, Kouloglou told TechCrunch that he didn’t know why he was specifically targeted but that he believes it was due to his work on the European Parliament’s committee investigating Pegasus abuses.

He described anger when he learned that his phone had been hacked. 

“You realize that all of your personal data [was taken] — not all the professional exchanges or messages with ministers — but also the very private things, like the happy moments and the sad moments,” he told TechCrunch.

Kouloglou said he plans to sue NSO Group, the Israeli-headquartered spyware maker. NSO remains largely banned from use in the United States following a Biden-era executive order that outlawed the government’s use of spyware that could violate people’s human rights. 

Last year, the spyware maker confirmed an unnamed American investment group funneled tens of millions of dollars into the company, likely as part of an effort to rehabilitate NSO’s beleaguered brand associated with enabling human rights abuses.

Kouloglou said he was going public with his story “for democracy, human rights, and the fight against corruption.”

“Corruption concerns everybody,” he said.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#Politician #investigated #spyware #abuses #phone #hacked #Pegasus #spyware #TechCrunchSpyware,Pegasus,cybersecurity,NSO Group"> Politician who investigated spyware abuses had his phone hacked with Pegasus spyware | TechCrunch
Security researchers have confirmed that a European politician had his phone hacked with the Pegasus spyware while serving on an investigatory committee probing abuses of the notorious surveillance tool. This has reigniting fresh controversy over governments abusing spyware to collect information about their critics.

The researchers at the University of Toronto’s digital rights unit The Citizen Lab say the confirmed phone hacking of Greek journalist and former politician Stelios Kouloglou during 2022 and 2023 marks the first time that a member of the European Parliament’s PEGA committee, tasked with investigating phone spyware attacks by European governments, has been publicly identified as a victim of spyware.







Kouloglou told TechCrunch in a phone call that the deliberate compromise of his phone was “reckless.” One serving European lawmaker described the hacking of Kouloglou’s phone as a “direct attack on the rule of law,” and called on the European Commission to take concrete action by imposing strict limits on the use of spyware across the 27 member-state bloc.

While spyware attacks on lawmakers are rare, the timing and targeting of a committee investigator by way of the very spyware under his investigation suggests an intense focus on the committee’s inner workings ahead of a widely anticipated report detailing its findings. The hacks open fresh questions about how governments use spyware ostensibly needed for identifying serious crime, but then caught spying on the communications of journalists, lawmakers, and critics.

Citizen Lab’s researchers did not attribute the phone hacking to a specific country, but said that the government customer used the same Pegasus-loaded email address that was used in a previous campaign that hacked into the phones of journalists across Europe. The customer’s identity is not known, but the reuse of the same attacking email address implies that the customer had NSO Group’s authorization to use its Pegasus spyware to snoop on phones across multiple countries in Europe.

A spokesperson for the European Commission did not respond to TechCrunch’s request for comment. NSO Group also did not respond to a request for comment about the Citizen Lab report prior to publication.

In its report out Friday, Citizen Lab said Kouloglou was hacked in October 2022 and at least twice during March 2023 using an exploit that compromised a security vulnerability in Apple’s iPhone software. This vulnerability had been patched but the fix was not yet installed on Kouloglou’s phone. The exploit was a “zero-click” bug, meaning the spyware broke in and stole his data without needing any interaction on his part.

The bug abused a previously discovered flaw in Apple’s smart home software used in iPhones. It allowed the spyware to grab private data from Kouloglou’s phone without his knowledge, such as his text messages and other correspondence, location data, and photos.

The timing of the October 2022 hack coincides with intense discussions over email and text message throughout October and November 2022, ahead of the delivery of a first draft describing spyware abuses focusing in Cyprus, Greece, Hungary, Poland, and Spain. 

The hack also lines up at the exact time that Kouloglou was in the hospital at the time for a pre-scheduled surgery, which may have allowed the spyware operators to listen in to ambient audio discussing his healthcare or other conversations he had with visitors at the time.







Months later on March 6 and 7, Citizen Lab said Kouloglou’s phone was hacked again by the same Pegasus operator while Kouloglou traveled from Athens to Brussels, during a period of committee hearings and months prior to the committee finalizing and adopting their written draft report.

In a call, Kouloglou told TechCrunch that he didn’t know why he was specifically targeted but that he believes it was due to his work on the European Parliament’s committee investigating Pegasus abuses.

He described anger when he learned that his phone had been hacked. 

“You realize that all of your personal data [was taken] — not all the professional exchanges or messages with ministers — but also the very private things, like the happy moments and the sad moments,” he told TechCrunch.

Kouloglou said he plans to sue NSO Group, the Israeli-headquartered spyware maker. NSO remains largely banned from use in the United States following a Biden-era executive order that outlawed the government’s use of spyware that could violate people’s human rights. 

Last year, the spyware maker confirmed an unnamed American investment group funneled tens of millions of dollars into the company, likely as part of an effort to rehabilitate NSO’s beleaguered brand associated with enabling human rights abuses.

Kouloglou said he was going public with his story “for democracy, human rights, and the fight against corruption.”

“Corruption concerns everybody,” he said.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.#Politician #investigated #spyware #abuses #phone #hacked #Pegasus #spyware #TechCrunchSpyware,Pegasus,cybersecurity,NSO Group
Tech-news

tasked with investigating phone spyware attacks by European governments, has been publicly identified as a victim of spyware.

Kouloglou told TechCrunch in a phone call that the deliberate compromise of his phone was “reckless.” One serving European lawmaker described the hacking of Kouloglou’s phone as a “direct attack on the rule of law,” and called on the European Commission to take concrete action by imposing strict limits on the use of spyware across the 27 member-state bloc.

While spyware attacks on lawmakers are rare, the timing and targeting of a committee investigator by way of the very spyware under his investigation suggests an intense focus on the committee’s inner workings ahead of a widely anticipated report detailing its findings. The hacks open fresh questions about how governments use spyware ostensibly needed for identifying serious crime, but then caught spying on the communications of journalists, lawmakers, and critics.

Citizen Lab’s researchers did not attribute the phone hacking to a specific country, but said that the government customer used the same Pegasus-loaded email address that was used in a previous campaign that hacked into the phones of journalists across Europe. The customer’s identity is not known, but the reuse of the same attacking email address implies that the customer had NSO Group’s authorization to use its Pegasus spyware to snoop on phones across multiple countries in Europe.

A spokesperson for the European Commission did not respond to TechCrunch’s request for comment. NSO Group also did not respond to a request for comment about the Citizen Lab report prior to publication.

In its report out Friday, Citizen Lab said Kouloglou was hacked in October 2022 and at least twice during March 2023 using an exploit that compromised a security vulnerability in Apple’s iPhone software. This vulnerability had been patched but the fix was not yet installed on Kouloglou’s phone. The exploit was a “zero-click” bug, meaning the spyware broke in and stole his data without needing any interaction on his part.

The bug abused a previously discovered flaw in Apple’s smart home software used in iPhones. It allowed the spyware to grab private data from Kouloglou’s phone without his knowledge, such as his text messages and other correspondence, location data, and photos.

The timing of the October 2022 hack coincides with intense discussions over email and text message throughout October and November 2022, ahead of the delivery of a first draft describing spyware abuses focusing in Cyprus, Greece, Hungary, Poland, and Spain. 

The hack also lines up at the exact time that Kouloglou was in the hospital at the time for a pre-scheduled surgery, which may have allowed the spyware operators to listen in to ambient audio discussing his healthcare or other conversations he had with visitors at the time.

Months later on March 6 and 7, Citizen Lab said Kouloglou’s phone was hacked again by the same Pegasus operator while Kouloglou traveled from Athens to Brussels, during a period of committee hearings and months prior to the committee finalizing and adopting their written draft report.

In a call, Kouloglou told TechCrunch that he didn’t know why he was specifically targeted but that he believes it was due to his work on the European Parliament’s committee investigating Pegasus abuses.

He described anger when he learned that his phone had been hacked. 

“You realize that all of your personal data [was taken] — not all the professional exchanges or messages with ministers — but also the very private things, like the happy moments and the sad moments,” he told TechCrunch.

Kouloglou said he plans to sue NSO Group, the Israeli-headquartered spyware maker. NSO remains largely banned from use in the United States following a Biden-era executive order that outlawed the government’s use of spyware that could violate people’s human rights. 

Last year, the spyware maker confirmed an unnamed American investment group funneled tens of millions of dollars into the company, likely as part of an effort to rehabilitate NSO’s beleaguered brand associated with enabling human rights abuses.

Kouloglou said he was going public with his story “for democracy, human rights, and the fight against corruption.”

“Corruption concerns everybody,” he said.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#Politician #investigated #spyware #abuses #phone #hacked #Pegasus #spyware #TechCrunchSpyware,Pegasus,cybersecurity,NSO Group">Politician who investigated spyware abuses had his phone hacked with Pegasus spyware | TechCrunch

Security researchers have confirmed that a European politician had his phone hacked with the Pegasus spyware while serving on an investigatory committee probing abuses of the notorious surveillance tool. This has reigniting fresh controversy over governments abusing spyware to collect information about their critics.

The researchers at the University of Toronto’s digital rights unit The Citizen Lab say the confirmed phone hacking of Greek journalist and former politician Stelios Kouloglou during 2022 and 2023 marks the first time that a member of the European Parliament’s PEGA committee, tasked with investigating phone spyware attacks by European governments, has been publicly identified as a victim of spyware.

Kouloglou told TechCrunch in a phone call that the deliberate compromise of his phone was “reckless.” One serving European lawmaker described the hacking of Kouloglou’s phone as a “direct attack on the rule of law,” and called on the European Commission to take concrete action by imposing strict limits on the use of spyware across the 27 member-state bloc.

While spyware attacks on lawmakers are rare, the timing and targeting of a committee investigator by way of the very spyware under his investigation suggests an intense focus on the committee’s inner workings ahead of a widely anticipated report detailing its findings. The hacks open fresh questions about how governments use spyware ostensibly needed for identifying serious crime, but then caught spying on the communications of journalists, lawmakers, and critics.

Citizen Lab’s researchers did not attribute the phone hacking to a specific country, but said that the government customer used the same Pegasus-loaded email address that was used in a previous campaign that hacked into the phones of journalists across Europe. The customer’s identity is not known, but the reuse of the same attacking email address implies that the customer had NSO Group’s authorization to use its Pegasus spyware to snoop on phones across multiple countries in Europe.

A spokesperson for the European Commission did not respond to TechCrunch’s request for comment. NSO Group also did not respond to a request for comment about the Citizen Lab report prior to publication.

In its report out Friday, Citizen Lab said Kouloglou was hacked in October 2022 and at least twice during March 2023 using an exploit that compromised a security vulnerability in Apple’s iPhone software. This vulnerability had been patched but the fix was not yet installed on Kouloglou’s phone. The exploit was a “zero-click” bug, meaning the spyware broke in and stole his data without needing any interaction on his part.

The bug abused a previously discovered flaw in Apple’s smart home software used in iPhones. It allowed the spyware to grab private data from Kouloglou’s phone without his knowledge, such as his text messages and other correspondence, location data, and photos.

The timing of the October 2022 hack coincides with intense discussions over email and text message throughout October and November 2022, ahead of the delivery of a first draft describing spyware abuses focusing in Cyprus, Greece, Hungary, Poland, and Spain. 

The hack also lines up at the exact time that Kouloglou was in the hospital at the time for a pre-scheduled surgery, which may have allowed the spyware operators to listen in to ambient audio discussing his healthcare or other conversations he had with visitors at the time.

Months later on March 6 and 7, Citizen Lab said Kouloglou’s phone was hacked again by the same Pegasus operator while Kouloglou traveled from Athens to Brussels, during a period of committee hearings and months prior to the committee finalizing and adopting their written draft report.

In a call, Kouloglou told TechCrunch that he didn’t know why he was specifically targeted but that he believes it was due to his work on the European Parliament’s committee investigating Pegasus abuses.

He described anger when he learned that his phone had been hacked. 

“You realize that all of your personal data [was taken] — not all the professional exchanges or messages with ministers — but also the very private things, like the happy moments and the sad moments,” he told TechCrunch.

Kouloglou said he plans to sue NSO Group, the Israeli-headquartered spyware maker. NSO remains largely banned from use in the United States following a Biden-era executive order that outlawed the government’s use of spyware that could violate people’s human rights. 

Last year, the spyware maker confirmed an unnamed American investment group funneled tens of millions of dollars into the company, likely as part of an effort to rehabilitate NSO’s beleaguered brand associated with enabling human rights abuses.

Kouloglou said he was going public with his story “for democracy, human rights, and the fight against corruption.”

“Corruption concerns everybody,” he said.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

#Politician #investigated #spyware #abuses #phone #hacked #Pegasus #spyware #TechCrunchSpyware,Pegasus,cybersecurity,NSO Group

Security researchers have confirmed that a European politician had his phone hacked with the Pegasus…

Fashion news

The Port of Long Beach handled almost 818,000 20-foot equivalent units (TEUs) in April, down…

 

The OpenAI blog post announcing Daybreak doesn’t mention the word “project” at all, perhaps to make readers slightly less apt to compare it to Anthropic’s Project Glasswing, but watch this: this sounds mighty similar to Anthropic’s Project Glasswing. Like Project Glasswing, it’s a program in which a frontier AI company seeks to partner with corporate and government entities to root out security vulnerabilities using OpenAI’s most advanced models in the hopes of “seeing risk earlier, acting sooner, and helping make software resilient by design.”

Glasswing rolled out last month alongside Anthropic’s announcement of its Claude Mythos Preview model, famously the model so capable—according to its creators at least—that it posed a danger to the world. As Anthropic’s system card for the model, explained:

Claude Mythos Preview’s large increase in capabilities has led us to decide not to make it generally available. Instead, we are using it as part of a defensive cybersecurity program with a limited set of partners.

In other words, because it’s “the most cyber-capable model” Anthropic had ever built, it needs to be locked away for now, unless you’re a VIP. Influential software developer Daniel Stenberg has called this an “amazingly successful marketing stunt for sure.”

Two days after that announcement, reports started materializing about a similar project at OpenAI. An anonymously sourced Axios story described it as “a product with advanced cybersecurity capabilities that it plans to release to a small set of partners.”

The Daybreak announcement is much more public-facing than that, and comes across as significantly less ominous and secretive than Project Glasswing. The top of the page has two buttons: “Request a vulnerability scan” and “Contact sales.” When you click, “Request a vulnerability scan” you get a brief and unchallenging form:

‘Daybreak’: OpenAI’s Answer to Anthropic’s Project Glasswing Has Arrived
                On Monday, OpenAI announced something called “Daybreak,” a project that CEO Sam Altman says is meant to “accelerate cyber defense and continuously secure software.“  OpenAI is launching Daybreak, our effort to accelerate cyber defense and continuously secure software. AI is already good and about to get super good at cybersecurity; we’d like to start working with as many companies as possible now to help them continuously secure themselves. — Sam Altman (@sama) May 11, 2026    The OpenAI blog post announcing Daybreak doesn’t mention the word “project” at all, perhaps to make readers slightly less apt to compare it to Anthropic’s Project Glasswing, but watch this: this sounds mighty similar to Anthropic’s Project Glasswing. Like Project Glasswing, it’s a program in which a frontier AI company seeks to partner with corporate and government entities to root out security vulnerabilities using OpenAI’s most advanced models in the hopes of “seeing risk earlier, acting sooner, and helping make software resilient by design.” Glasswing rolled out last month alongside Anthropic’s announcement of its Claude Mythos Preview model, famously the model so capable—according to its creators at least—that it posed a danger to the world. As Anthropic’s system card for the model, explained:

  Claude Mythos Preview’s large increase in capabilities has led us to decide not to make it generally available. Instead, we are using it as part of a defensive cybersecurity program with a limited set of partners.   In other words, because it’s “the most cyber-capable model” Anthropic had ever built, it needs to be locked away for now, unless you’re a VIP. Influential software developer Daniel Stenberg has called this an “amazingly successful marketing stunt for sure.” Two days after that announcement, reports started materializing about a similar project at OpenAI. An anonymously sourced Axios story described it as “a product with advanced cybersecurity capabilities that it plans to release to a small set of partners.”

 The Daybreak announcement is much more public-facing than that, and comes across as significantly less ominous and secretive than Project Glasswing. The top of the page has two buttons: “Request a vulnerability scan” and “Contact sales.” When you click, “Request a vulnerability scan” you get a brief and unchallenging form:

 © OpenAI Altman said in his X post that OpenAI would “like to start working with as many companies as possible now,” and in fairness, that’s how the effort comes across. Compared to way Project Glasswing rolled out, with frightened governments scurrying around behind the scenes like agitated ants, it’s refreshing. The announcement says Daybreak makes use of Codex Security, which was announced as a research preview back in March, to create a “threat model” of a given system that outlines its functions, who is trusted by the system, and what the vulnerabilities therefore are. With that as its context, it then digs into your actual codebase for the real world exploits. Then, in theory, it Daybreak patches them.      #Daybreak #OpenAIs #Answer #Anthropics #Project #Glasswing #ArrivedArtificial intelligence,Cybersecurity,OpenAI
© OpenAI

Altman said in his X post that OpenAI would “like to start working with as many companies as possible now,” and in fairness, that’s how the effort comes across. Compared to way Project Glasswing rolled out, with frightened governments scurrying around behind the scenes like agitated ants, it’s refreshing.

The announcement says Daybreak makes use of Codex Security, which was announced as a research preview back in March, to create a “threat model” of a given system that outlines its functions, who is trusted by the system, and what the vulnerabilities therefore are. With that as its context, it then digs into your actual codebase for the real world exploits.

Then, in theory, it Daybreak patches them.

#Daybreak #OpenAIs #Answer #Anthropics #Project #Glasswing #ArrivedArtificial intelligence,Cybersecurity,OpenAI"> ‘Daybreak’: OpenAI’s Answer to Anthropic’s Project Glasswing Has Arrived
                On Monday, OpenAI announced something called “Daybreak,” a project that CEO Sam Altman says is meant to “accelerate cyber defense and continuously secure software.“  OpenAI is launching Daybreak, our effort to accelerate cyber defense and continuously secure software. AI is already good and about to get super good at cybersecurity; we’d like to start working with as many companies as possible now to help them continuously secure themselves. — Sam Altman (@sama) May 11, 2026    The OpenAI blog post announcing Daybreak doesn’t mention the word “project” at all, perhaps to make readers slightly less apt to compare it to Anthropic’s Project Glasswing, but watch this: this sounds mighty similar to Anthropic’s Project Glasswing. Like Project Glasswing, it’s a program in which a frontier AI company seeks to partner with corporate and government entities to root out security vulnerabilities using OpenAI’s most advanced models in the hopes of “seeing risk earlier, acting sooner, and helping make software resilient by design.” Glasswing rolled out last month alongside Anthropic’s announcement of its Claude Mythos Preview model, famously the model so capable—according to its creators at least—that it posed a danger to the world. As Anthropic’s system card for the model, explained:

  Claude Mythos Preview’s large increase in capabilities has led us to decide not to make it generally available. Instead, we are using it as part of a defensive cybersecurity program with a limited set of partners.   In other words, because it’s “the most cyber-capable model” Anthropic had ever built, it needs to be locked away for now, unless you’re a VIP. Influential software developer Daniel Stenberg has called this an “amazingly successful marketing stunt for sure.” Two days after that announcement, reports started materializing about a similar project at OpenAI. An anonymously sourced Axios story described it as “a product with advanced cybersecurity capabilities that it plans to release to a small set of partners.”

 The Daybreak announcement is much more public-facing than that, and comes across as significantly less ominous and secretive than Project Glasswing. The top of the page has two buttons: “Request a vulnerability scan” and “Contact sales.” When you click, “Request a vulnerability scan” you get a brief and unchallenging form:

 © OpenAI Altman said in his X post that OpenAI would “like to start working with as many companies as possible now,” and in fairness, that’s how the effort comes across. Compared to way Project Glasswing rolled out, with frightened governments scurrying around behind the scenes like agitated ants, it’s refreshing. The announcement says Daybreak makes use of Codex Security, which was announced as a research preview back in March, to create a “threat model” of a given system that outlines its functions, who is trusted by the system, and what the vulnerabilities therefore are. With that as its context, it then digs into your actual codebase for the real world exploits. Then, in theory, it Daybreak patches them.      #Daybreak #OpenAIs #Answer #Anthropics #Project #Glasswing #ArrivedArtificial intelligence,Cybersecurity,OpenAI
Tech-news

 

The OpenAI blog post announcing Daybreak doesn’t mention the word “project” at all, perhaps to make readers slightly less apt to compare it to Anthropic’s Project Glasswing, but watch this: this sounds mighty similar to Anthropic’s Project Glasswing. Like Project Glasswing, it’s a program in which a frontier AI company seeks to partner with corporate and government entities to root out security vulnerabilities using OpenAI’s most advanced models in the hopes of “seeing risk earlier, acting sooner, and helping make software resilient by design.”

Glasswing rolled out last month alongside Anthropic’s announcement of its Claude Mythos Preview model, famously the model so capable—according to its creators at least—that it posed a danger to the world. As Anthropic’s system card for the model, explained:

Claude Mythos Preview’s large increase in capabilities has led us to decide not to make it generally available. Instead, we are using it as part of a defensive cybersecurity program with a limited set of partners.

In other words, because it’s “the most cyber-capable model” Anthropic had ever built, it needs to be locked away for now, unless you’re a VIP. Influential software developer Daniel Stenberg has called this an “amazingly successful marketing stunt for sure.”

Two days after that announcement, reports started materializing about a similar project at OpenAI. An anonymously sourced Axios story described it as “a product with advanced cybersecurity capabilities that it plans to release to a small set of partners.”

The Daybreak announcement is much more public-facing than that, and comes across as significantly less ominous and secretive than Project Glasswing. The top of the page has two buttons: “Request a vulnerability scan” and “Contact sales.” When you click, “Request a vulnerability scan” you get a brief and unchallenging form:

‘Daybreak’: OpenAI’s Answer to Anthropic’s Project Glasswing Has Arrived
                On Monday, OpenAI announced something called “Daybreak,” a project that CEO Sam Altman says is meant to “accelerate cyber defense and continuously secure software.“  OpenAI is launching Daybreak, our effort to accelerate cyber defense and continuously secure software. AI is already good and about to get super good at cybersecurity; we’d like to start working with as many companies as possible now to help them continuously secure themselves. — Sam Altman (@sama) May 11, 2026    The OpenAI blog post announcing Daybreak doesn’t mention the word “project” at all, perhaps to make readers slightly less apt to compare it to Anthropic’s Project Glasswing, but watch this: this sounds mighty similar to Anthropic’s Project Glasswing. Like Project Glasswing, it’s a program in which a frontier AI company seeks to partner with corporate and government entities to root out security vulnerabilities using OpenAI’s most advanced models in the hopes of “seeing risk earlier, acting sooner, and helping make software resilient by design.” Glasswing rolled out last month alongside Anthropic’s announcement of its Claude Mythos Preview model, famously the model so capable—according to its creators at least—that it posed a danger to the world. As Anthropic’s system card for the model, explained:

  Claude Mythos Preview’s large increase in capabilities has led us to decide not to make it generally available. Instead, we are using it as part of a defensive cybersecurity program with a limited set of partners.   In other words, because it’s “the most cyber-capable model” Anthropic had ever built, it needs to be locked away for now, unless you’re a VIP. Influential software developer Daniel Stenberg has called this an “amazingly successful marketing stunt for sure.” Two days after that announcement, reports started materializing about a similar project at OpenAI. An anonymously sourced Axios story described it as “a product with advanced cybersecurity capabilities that it plans to release to a small set of partners.”

 The Daybreak announcement is much more public-facing than that, and comes across as significantly less ominous and secretive than Project Glasswing. The top of the page has two buttons: “Request a vulnerability scan” and “Contact sales.” When you click, “Request a vulnerability scan” you get a brief and unchallenging form:

 © OpenAI Altman said in his X post that OpenAI would “like to start working with as many companies as possible now,” and in fairness, that’s how the effort comes across. Compared to way Project Glasswing rolled out, with frightened governments scurrying around behind the scenes like agitated ants, it’s refreshing. The announcement says Daybreak makes use of Codex Security, which was announced as a research preview back in March, to create a “threat model” of a given system that outlines its functions, who is trusted by the system, and what the vulnerabilities therefore are. With that as its context, it then digs into your actual codebase for the real world exploits. Then, in theory, it Daybreak patches them.      #Daybreak #OpenAIs #Answer #Anthropics #Project #Glasswing #ArrivedArtificial intelligence,Cybersecurity,OpenAI
© OpenAI

Altman said in his X post that OpenAI would “like to start working with as many companies as possible now,” and in fairness, that’s how the effort comes across. Compared to way Project Glasswing rolled out, with frightened governments scurrying around behind the scenes like agitated ants, it’s refreshing.

The announcement says Daybreak makes use of Codex Security, which was announced as a research preview back in March, to create a “threat model” of a given system that outlines its functions, who is trusted by the system, and what the vulnerabilities therefore are. With that as its context, it then digs into your actual codebase for the real world exploits.

Then, in theory, it Daybreak patches them.

#Daybreak #OpenAIs #Answer #Anthropics #Project #Glasswing #ArrivedArtificial intelligence,Cybersecurity,OpenAI">‘Daybreak’: OpenAI’s Answer to Anthropic’s Project Glasswing Has Arrived

On Monday, OpenAI announced something called “Daybreak,” a project that CEO Sam Altman says is meant to “accelerate cyber defense and continuously secure software.“

OpenAI is launching Daybreak, our effort to accelerate cyber defense and continuously secure software.

AI is already good and about to get super good at cybersecurity; we’d like to start working with as many companies as possible now to help them continuously secure themselves.

— Sam Altman (@sama) May 11, 2026

 

The OpenAI blog post announcing Daybreak doesn’t mention the word “project” at all, perhaps to make readers slightly less apt to compare it to Anthropic’s Project Glasswing, but watch this: this sounds mighty similar to Anthropic’s Project Glasswing. Like Project Glasswing, it’s a program in which a frontier AI company seeks to partner with corporate and government entities to root out security vulnerabilities using OpenAI’s most advanced models in the hopes of “seeing risk earlier, acting sooner, and helping make software resilient by design.”

Glasswing rolled out last month alongside Anthropic’s announcement of its Claude Mythos Preview model, famously the model so capable—according to its creators at least—that it posed a danger to the world. As Anthropic’s system card for the model, explained:

Claude Mythos Preview’s large increase in capabilities has led us to decide not to make it generally available. Instead, we are using it as part of a defensive cybersecurity program with a limited set of partners.

In other words, because it’s “the most cyber-capable model” Anthropic had ever built, it needs to be locked away for now, unless you’re a VIP. Influential software developer Daniel Stenberg has called this an “amazingly successful marketing stunt for sure.”

Two days after that announcement, reports started materializing about a similar project at OpenAI. An anonymously sourced Axios story described it as “a product with advanced cybersecurity capabilities that it plans to release to a small set of partners.”

The Daybreak announcement is much more public-facing than that, and comes across as significantly less ominous and secretive than Project Glasswing. The top of the page has two buttons: “Request a vulnerability scan” and “Contact sales.” When you click, “Request a vulnerability scan” you get a brief and unchallenging form:

‘Daybreak’: OpenAI’s Answer to Anthropic’s Project Glasswing Has Arrived
                On Monday, OpenAI announced something called “Daybreak,” a project that CEO Sam Altman says is meant to “accelerate cyber defense and continuously secure software.“  OpenAI is launching Daybreak, our effort to accelerate cyber defense and continuously secure software. AI is already good and about to get super good at cybersecurity; we’d like to start working with as many companies as possible now to help them continuously secure themselves. — Sam Altman (@sama) May 11, 2026    The OpenAI blog post announcing Daybreak doesn’t mention the word “project” at all, perhaps to make readers slightly less apt to compare it to Anthropic’s Project Glasswing, but watch this: this sounds mighty similar to Anthropic’s Project Glasswing. Like Project Glasswing, it’s a program in which a frontier AI company seeks to partner with corporate and government entities to root out security vulnerabilities using OpenAI’s most advanced models in the hopes of “seeing risk earlier, acting sooner, and helping make software resilient by design.” Glasswing rolled out last month alongside Anthropic’s announcement of its Claude Mythos Preview model, famously the model so capable—according to its creators at least—that it posed a danger to the world. As Anthropic’s system card for the model, explained:

  Claude Mythos Preview’s large increase in capabilities has led us to decide not to make it generally available. Instead, we are using it as part of a defensive cybersecurity program with a limited set of partners.   In other words, because it’s “the most cyber-capable model” Anthropic had ever built, it needs to be locked away for now, unless you’re a VIP. Influential software developer Daniel Stenberg has called this an “amazingly successful marketing stunt for sure.” Two days after that announcement, reports started materializing about a similar project at OpenAI. An anonymously sourced Axios story described it as “a product with advanced cybersecurity capabilities that it plans to release to a small set of partners.”

 The Daybreak announcement is much more public-facing than that, and comes across as significantly less ominous and secretive than Project Glasswing. The top of the page has two buttons: “Request a vulnerability scan” and “Contact sales.” When you click, “Request a vulnerability scan” you get a brief and unchallenging form:

 © OpenAI Altman said in his X post that OpenAI would “like to start working with as many companies as possible now,” and in fairness, that’s how the effort comes across. Compared to way Project Glasswing rolled out, with frightened governments scurrying around behind the scenes like agitated ants, it’s refreshing. The announcement says Daybreak makes use of Codex Security, which was announced as a research preview back in March, to create a “threat model” of a given system that outlines its functions, who is trusted by the system, and what the vulnerabilities therefore are. With that as its context, it then digs into your actual codebase for the real world exploits. Then, in theory, it Daybreak patches them.      #Daybreak #OpenAIs #Answer #Anthropics #Project #Glasswing #ArrivedArtificial intelligence,Cybersecurity,OpenAI
© OpenAI

Altman said in his X post that OpenAI would “like to start working with as many companies as possible now,” and in fairness, that’s how the effort comes across. Compared to way Project Glasswing rolled out, with frightened governments scurrying around behind the scenes like agitated ants, it’s refreshing.

The announcement says Daybreak makes use of Codex Security, which was announced as a research preview back in March, to create a “threat model” of a given system that outlines its functions, who is trusted by the system, and what the vulnerabilities therefore are. With that as its context, it then digs into your actual codebase for the real world exploits.

Then, in theory, it Daybreak patches them.

#Daybreak #OpenAIs #Answer #Anthropics #Project #Glasswing #ArrivedArtificial intelligence,Cybersecurity,OpenAI

On Monday, OpenAI announced something called “Daybreak,” a project that CEO Sam Altman says is…

gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States.

The widely used digital learning platform Canvas was put into “maintenance mode” on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker “ShinyHunters.” Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.

Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture.

In a running incident update log that began on May 1, Steve Proud, Instructure’s chief information security officer, said that the company had “recently experienced a cybersecurity incident perpetrated by a criminal threat actor.” He added on May 2 that “the information involved” for “users at affected institutions” included names, email addresses, student ID numbers, and messages exchanged by users on the platform.

The situation was ultimately marked as “Resolved” on Wednesday, with Proud writing that “Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.” At midday on Thursday, though, the Instructure status page registered an “issue” where “some users are having difficulties logging into Student ePortfolios.” Within a few hours, the company had added another status update: “Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode.” Late Thursday evening, the company said that Canvas was available again “for most users.”

TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools’ Canvas portals by injecting an HTML file to display their own message on the schools’ Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach.

The message from attackers “urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12—or else risk their data being leaked,” The Crimson reported. “It is unclear what information tied to Harvard affiliates was included in the alleged breach.”

Instructure did not immediately respond to a request for comment about Thursday’s outages and how they fit into the bigger picture of the breach. But the situation is significant given that a massive trove of student information has potentially been exposed, and the visibility of the incident across the country makes it a key example of a longstanding, yet endlessly escalating problem of data extortion and ransomware attacks.

The ShinyHunters name is associated with massive data dumps and has been linked to the infamous hacker collective known as the Com. But as the constellation of actors has shifted over the years, numerous attackers have taken up the most prominent Com-related monikers. A number of recent attacks have invoked other names, such as Lapsus$, with little or no connection to the original group that operated under the name.

#Canvas #Hack #Kind #Ransomware #Debacleransomware,cybersecurity,malware,hacks,hacking,security,vulnerabilities"> The Canvas Hack Is a New Kind of Ransomware DebacleHigher education has long been a target of ransomware gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States.The widely used digital learning platform Canvas was put into “maintenance mode” on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker “ShinyHunters.” Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture.In a running incident update log that began on May 1, Steve Proud, Instructure’s chief information security officer, said that the company had “recently experienced a cybersecurity incident perpetrated by a criminal threat actor.” He added on May 2 that “the information involved” for “users at affected institutions” included names, email addresses, student ID numbers, and messages exchanged by users on the platform.The situation was ultimately marked as “Resolved” on Wednesday, with Proud writing that “Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.” At midday on Thursday, though, the Instructure status page registered an “issue” where “some users are having difficulties logging into Student ePortfolios.” Within a few hours, the company had added another status update: “Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode.” Late Thursday evening, the company said that Canvas was available again “for most users.”TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools’ Canvas portals by injecting an HTML file to display their own message on the schools’ Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach.The message from attackers “urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12—or else risk their data being leaked,” The Crimson reported. “It is unclear what information tied to Harvard affiliates was included in the alleged breach.”Instructure did not immediately respond to a request for comment about Thursday’s outages and how they fit into the bigger picture of the breach. But the situation is significant given that a massive trove of student information has potentially been exposed, and the visibility of the incident across the country makes it a key example of a longstanding, yet endlessly escalating problem of data extortion and ransomware attacks.The ShinyHunters name is associated with massive data dumps and has been linked to the infamous hacker collective known as the Com. But as the constellation of actors has shifted over the years, numerous attackers have taken up the most prominent Com-related monikers. A number of recent attacks have invoked other names, such as Lapsus$, with little or no connection to the original group that operated under the name.#Canvas #Hack #Kind #Ransomware #Debacleransomware,cybersecurity,malware,hacks,hacking,security,vulnerabilities
Tech-news

gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States.

The widely used digital learning platform Canvas was put into “maintenance mode” on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker “ShinyHunters.” Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.

Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture.

In a running incident update log that began on May 1, Steve Proud, Instructure’s chief information security officer, said that the company had “recently experienced a cybersecurity incident perpetrated by a criminal threat actor.” He added on May 2 that “the information involved” for “users at affected institutions” included names, email addresses, student ID numbers, and messages exchanged by users on the platform.

The situation was ultimately marked as “Resolved” on Wednesday, with Proud writing that “Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.” At midday on Thursday, though, the Instructure status page registered an “issue” where “some users are having difficulties logging into Student ePortfolios.” Within a few hours, the company had added another status update: “Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode.” Late Thursday evening, the company said that Canvas was available again “for most users.”

TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools’ Canvas portals by injecting an HTML file to display their own message on the schools’ Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach.

The message from attackers “urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12—or else risk their data being leaked,” The Crimson reported. “It is unclear what information tied to Harvard affiliates was included in the alleged breach.”

Instructure did not immediately respond to a request for comment about Thursday’s outages and how they fit into the bigger picture of the breach. But the situation is significant given that a massive trove of student information has potentially been exposed, and the visibility of the incident across the country makes it a key example of a longstanding, yet endlessly escalating problem of data extortion and ransomware attacks.

The ShinyHunters name is associated with massive data dumps and has been linked to the infamous hacker collective known as the Com. But as the constellation of actors has shifted over the years, numerous attackers have taken up the most prominent Com-related monikers. A number of recent attacks have invoked other names, such as Lapsus$, with little or no connection to the original group that operated under the name.

#Canvas #Hack #Kind #Ransomware #Debacleransomware,cybersecurity,malware,hacks,hacking,security,vulnerabilities">The Canvas Hack Is a New Kind of Ransomware Debacle

Higher education has long been a target of ransomware gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States.

The widely used digital learning platform Canvas was put into “maintenance mode” on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker “ShinyHunters.” Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.

Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture.

In a running incident update log that began on May 1, Steve Proud, Instructure’s chief information security officer, said that the company had “recently experienced a cybersecurity incident perpetrated by a criminal threat actor.” He added on May 2 that “the information involved” for “users at affected institutions” included names, email addresses, student ID numbers, and messages exchanged by users on the platform.

The situation was ultimately marked as “Resolved” on Wednesday, with Proud writing that “Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.” At midday on Thursday, though, the Instructure status page registered an “issue” where “some users are having difficulties logging into Student ePortfolios.” Within a few hours, the company had added another status update: “Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode.” Late Thursday evening, the company said that Canvas was available again “for most users.”

TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools’ Canvas portals by injecting an HTML file to display their own message on the schools’ Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach.

The message from attackers “urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12—or else risk their data being leaked,” The Crimson reported. “It is unclear what information tied to Harvard affiliates was included in the alleged breach.”

Instructure did not immediately respond to a request for comment about Thursday’s outages and how they fit into the bigger picture of the breach. But the situation is significant given that a massive trove of student information has potentially been exposed, and the visibility of the incident across the country makes it a key example of a longstanding, yet endlessly escalating problem of data extortion and ransomware attacks.

The ShinyHunters name is associated with massive data dumps and has been linked to the infamous hacker collective known as the Com. But as the constellation of actors has shifted over the years, numerous attackers have taken up the most prominent Com-related monikers. A number of recent attacks have invoked other names, such as Lapsus$, with little or no connection to the original group that operated under the name.

#Canvas #Hack #Kind #Ransomware #Debacleransomware,cybersecurity,malware,hacks,hacking,security,vulnerabilities

Higher education has long been a target of ransomware gangs and data extortion attacks. But…

in a post on X on Wednesday that the account termination stopped a WireGuard update from shipping.

It’s the second such incident of a high-profile and widely used open source project being shut out from its customers due to a seemingly abrupt account termination from Microsoft, with popular encryption software VeraCrypt facing a similar circumstance. Both developers said Microsoft locked them out of their accounts without first alerting them. 

In the case of VeraCrypt, which is used by hundreds of thousands of users to encrypt files and operating systems, its developer Mounir Idrassi told TechCrunch that being locked out of his account means he is unable to update the software in time for a crucial certificate authority expiry, which he said may prevent some users from booting up.

Donenfeld, the WireGuard developer, told TechCrunch in an email: “If there were a critical vulnerability to fix right now — there isn’t! I just mean hypothetically — then users would be totally exposed.”

WireGuard is an open source VPN software used around the world to connect devices over the internet. WireGuard’s code is highly popular for its simplicity and security, as it serves as the foundation of many VPN implementations and commercial services that rely on its code, like Proton and Tailscale.

Donenfeld told TechCrunch in an email that he has spent the past few weeks modernizing WireGuard’s Windows code and was ready to send a copy update to Microsoft for checks before it can ship out to users, but was met with an “access restricted” error when logging into the developer portion of his Microsoft account.

Despite going through the process to verify his driver’s license or passport with Microsoft (the third party Microsoft uses for verification said he was “verified”), Donenfeld said his access was still suspended.

Donenfeld told TechCrunch that he found a page on Microsoft’s website saying that the company had been carrying out “mandatory account verification for all partners in the Windows Hardware Program who have not completed account verification since April 2024,” but that the verification program had since closed.

Microsoft’s Windows Hardware Program allows developers like Donenfeld and VeraCrypt’s Idrassi to “deploy hardware and device drivers for Windows PCs and other devices.” The ability to develop and release drivers for Windows users is restricted to known and vetted developers, as drivers can grant vast access to an operating system and its data and are known to be abused by hackers for that reason.

That account verification process meant that developers were required to upload their government-issued ID before they were allowed to publish potentially highly sensitive code to the broader Windows user base.

“Microsoft never sent me any notification at all about this. I’ve looked in every inbox in every spam folder in every mail log, and zero, nothing, zilch,” Donenfeld said.

The Windows Hardware Program’s verification program has “now concluded” and developers who have not uploaded their documents had their accounts “suspended,” the page reads, meaning that these accounts can no longer send updates.

Donenfeld said that he was referred to Microsoft’s executive support team, which handles customer service and account requests for high-profile individuals, which confirmed his appeal had been received but that they had to wait as long as 60 days for review.

By late Wednesday, there was a glimmer of hope in Donenfeld’s case. He told TechCrunch that he was finally in contact with Microsoft and that hopefully the issue would be resolved soon.

Microsoft did not immediately comment when reached by TechCrunch.

Donenfeld and Idrassi are not alone, with the account lockout issues affecting others as well.

Windscribe, a maker of VPN and other consumer privacy tools, said in a post on X that it had also been locked out of its Partner Center account. The company said it had a verified account for over eight years in order to sign its drivers.

“We’ve been trying to resolve this for over a month, and getting nowhere. Support is non-existent,” Windscribe said in its post. “Anyone know a human with a brain that still works at Microsoft and can help?”

#WireGuard #VPN #developer #ship #software #updates #Microsoft #locks #account #TechCrunchcybersecurity,Microsoft,vpn,Windows,WireGuard"> WireGuard VPN developer can’t ship software updates after Microsoft locks account | TechCrunch
WireGuard, the major software project and VPN that underpins popular security software including Mullvad and others, has found itself locked out of a key part of its Microsoft developer’s account and unable to ship software updates to Windows users.

Jason Donenfeld, the creator of the open source WireGuard VPN software, told TechCrunch that he has been locked out of his Microsoft developer account, and as a result cannot sign drivers or ship updates for WireGuard for Windows users, which are critical for its software to run. Donenfeld said in a post on X on Wednesday that the account termination stopped a WireGuard update from shipping.







It’s the second such incident of a high-profile and widely used open source project being shut out from its customers due to a seemingly abrupt account termination from Microsoft, with popular encryption software VeraCrypt facing a similar circumstance. Both developers said Microsoft locked them out of their accounts without first alerting them. 

In the case of VeraCrypt, which is used by hundreds of thousands of users to encrypt files and operating systems, its developer Mounir Idrassi told TechCrunch that being locked out of his account means he is unable to update the software in time for a crucial certificate authority expiry, which he said may prevent some users from booting up.

Donenfeld, the WireGuard developer, told TechCrunch in an email: “If there were a critical vulnerability to fix right now — there isn’t! I just mean hypothetically — then users would be totally exposed.”

WireGuard is an open source VPN software used around the world to connect devices over the internet. WireGuard’s code is highly popular for its simplicity and security, as it serves as the foundation of many VPN implementations and commercial services that rely on its code, like Proton and Tailscale.

Donenfeld told TechCrunch in an email that he has spent the past few weeks modernizing WireGuard’s Windows code and was ready to send a copy update to Microsoft for checks before it can ship out to users, but was met with an “access restricted” error when logging into the developer portion of his Microsoft account.

Despite going through the process to verify his driver’s license or passport with Microsoft (the third party Microsoft uses for verification said he was “verified”), Donenfeld said his access was still suspended.

Donenfeld told TechCrunch that he found a page on Microsoft’s website saying that the company had been carrying out “mandatory account verification for all partners in the Windows Hardware Program who have not completed account verification since April 2024,” but that the verification program had since closed.

Microsoft’s Windows Hardware Program allows developers like Donenfeld and VeraCrypt’s Idrassi to “deploy hardware and device drivers for Windows PCs and other devices.” The ability to develop and release drivers for Windows users is restricted to known and vetted developers, as drivers can grant vast access to an operating system and its data and are known to be abused by hackers for that reason.







That account verification process meant that developers were required to upload their government-issued ID before they were allowed to publish potentially highly sensitive code to the broader Windows user base.

“Microsoft never sent me any notification at all about this. I’ve looked in every inbox in every spam folder in every mail log, and zero, nothing, zilch,” Donenfeld said.

The Windows Hardware Program’s verification program has “now concluded” and developers who have not uploaded their documents had their accounts “suspended,” the page reads, meaning that these accounts can no longer send updates.

Donenfeld said that he was referred to Microsoft’s executive support team, which handles customer service and account requests for high-profile individuals, which confirmed his appeal had been received but that they had to wait as long as 60 days for review.

By late Wednesday, there was a glimmer of hope in Donenfeld’s case. He told TechCrunch that he was finally in contact with Microsoft and that hopefully the issue would be resolved soon.

Microsoft did not immediately comment when reached by TechCrunch.

Donenfeld and Idrassi are not alone, with the account lockout issues affecting others as well.

Windscribe, a maker of VPN and other consumer privacy tools, said in a post on X that it had also been locked out of its Partner Center account. The company said it had a verified account for over eight years in order to sign its drivers.







“We’ve been trying to resolve this for over a month, and getting nowhere. Support is non-existent,” Windscribe said in its post. “Anyone know a human with a brain that still works at Microsoft and can help?”
#WireGuard #VPN #developer #ship #software #updates #Microsoft #locks #account #TechCrunchcybersecurity,Microsoft,vpn,Windows,WireGuard
Tech-news

in a post on X on Wednesday that the account termination stopped a WireGuard update from shipping.

It’s the second such incident of a high-profile and widely used open source project being shut out from its customers due to a seemingly abrupt account termination from Microsoft, with popular encryption software VeraCrypt facing a similar circumstance. Both developers said Microsoft locked them out of their accounts without first alerting them. 

In the case of VeraCrypt, which is used by hundreds of thousands of users to encrypt files and operating systems, its developer Mounir Idrassi told TechCrunch that being locked out of his account means he is unable to update the software in time for a crucial certificate authority expiry, which he said may prevent some users from booting up.

Donenfeld, the WireGuard developer, told TechCrunch in an email: “If there were a critical vulnerability to fix right now — there isn’t! I just mean hypothetically — then users would be totally exposed.”

WireGuard is an open source VPN software used around the world to connect devices over the internet. WireGuard’s code is highly popular for its simplicity and security, as it serves as the foundation of many VPN implementations and commercial services that rely on its code, like Proton and Tailscale.

Donenfeld told TechCrunch in an email that he has spent the past few weeks modernizing WireGuard’s Windows code and was ready to send a copy update to Microsoft for checks before it can ship out to users, but was met with an “access restricted” error when logging into the developer portion of his Microsoft account.

Despite going through the process to verify his driver’s license or passport with Microsoft (the third party Microsoft uses for verification said he was “verified”), Donenfeld said his access was still suspended.

Donenfeld told TechCrunch that he found a page on Microsoft’s website saying that the company had been carrying out “mandatory account verification for all partners in the Windows Hardware Program who have not completed account verification since April 2024,” but that the verification program had since closed.

Microsoft’s Windows Hardware Program allows developers like Donenfeld and VeraCrypt’s Idrassi to “deploy hardware and device drivers for Windows PCs and other devices.” The ability to develop and release drivers for Windows users is restricted to known and vetted developers, as drivers can grant vast access to an operating system and its data and are known to be abused by hackers for that reason.

That account verification process meant that developers were required to upload their government-issued ID before they were allowed to publish potentially highly sensitive code to the broader Windows user base.

“Microsoft never sent me any notification at all about this. I’ve looked in every inbox in every spam folder in every mail log, and zero, nothing, zilch,” Donenfeld said.

The Windows Hardware Program’s verification program has “now concluded” and developers who have not uploaded their documents had their accounts “suspended,” the page reads, meaning that these accounts can no longer send updates.

Donenfeld said that he was referred to Microsoft’s executive support team, which handles customer service and account requests for high-profile individuals, which confirmed his appeal had been received but that they had to wait as long as 60 days for review.

By late Wednesday, there was a glimmer of hope in Donenfeld’s case. He told TechCrunch that he was finally in contact with Microsoft and that hopefully the issue would be resolved soon.

Microsoft did not immediately comment when reached by TechCrunch.

Donenfeld and Idrassi are not alone, with the account lockout issues affecting others as well.

Windscribe, a maker of VPN and other consumer privacy tools, said in a post on X that it had also been locked out of its Partner Center account. The company said it had a verified account for over eight years in order to sign its drivers.

“We’ve been trying to resolve this for over a month, and getting nowhere. Support is non-existent,” Windscribe said in its post. “Anyone know a human with a brain that still works at Microsoft and can help?”

#WireGuard #VPN #developer #ship #software #updates #Microsoft #locks #account #TechCrunchcybersecurity,Microsoft,vpn,Windows,WireGuard">WireGuard VPN developer can’t ship software updates after Microsoft locks account | TechCrunch

WireGuard, the major software project and VPN that underpins popular security software including Mullvad and others, has found itself locked out of a key part of its Microsoft developer’s account and unable to ship software updates to Windows users.

Jason Donenfeld, the creator of the open source WireGuard VPN software, told TechCrunch that he has been locked out of his Microsoft developer account, and as a result cannot sign drivers or ship updates for WireGuard for Windows users, which are critical for its software to run. Donenfeld said in a post on X on Wednesday that the account termination stopped a WireGuard update from shipping.

It’s the second such incident of a high-profile and widely used open source project being shut out from its customers due to a seemingly abrupt account termination from Microsoft, with popular encryption software VeraCrypt facing a similar circumstance. Both developers said Microsoft locked them out of their accounts without first alerting them. 

In the case of VeraCrypt, which is used by hundreds of thousands of users to encrypt files and operating systems, its developer Mounir Idrassi told TechCrunch that being locked out of his account means he is unable to update the software in time for a crucial certificate authority expiry, which he said may prevent some users from booting up.

Donenfeld, the WireGuard developer, told TechCrunch in an email: “If there were a critical vulnerability to fix right now — there isn’t! I just mean hypothetically — then users would be totally exposed.”

WireGuard is an open source VPN software used around the world to connect devices over the internet. WireGuard’s code is highly popular for its simplicity and security, as it serves as the foundation of many VPN implementations and commercial services that rely on its code, like Proton and Tailscale.

Donenfeld told TechCrunch in an email that he has spent the past few weeks modernizing WireGuard’s Windows code and was ready to send a copy update to Microsoft for checks before it can ship out to users, but was met with an “access restricted” error when logging into the developer portion of his Microsoft account.

Despite going through the process to verify his driver’s license or passport with Microsoft (the third party Microsoft uses for verification said he was “verified”), Donenfeld said his access was still suspended.

Donenfeld told TechCrunch that he found a page on Microsoft’s website saying that the company had been carrying out “mandatory account verification for all partners in the Windows Hardware Program who have not completed account verification since April 2024,” but that the verification program had since closed.

Microsoft’s Windows Hardware Program allows developers like Donenfeld and VeraCrypt’s Idrassi to “deploy hardware and device drivers for Windows PCs and other devices.” The ability to develop and release drivers for Windows users is restricted to known and vetted developers, as drivers can grant vast access to an operating system and its data and are known to be abused by hackers for that reason.

That account verification process meant that developers were required to upload their government-issued ID before they were allowed to publish potentially highly sensitive code to the broader Windows user base.

“Microsoft never sent me any notification at all about this. I’ve looked in every inbox in every spam folder in every mail log, and zero, nothing, zilch,” Donenfeld said.

The Windows Hardware Program’s verification program has “now concluded” and developers who have not uploaded their documents had their accounts “suspended,” the page reads, meaning that these accounts can no longer send updates.

Donenfeld said that he was referred to Microsoft’s executive support team, which handles customer service and account requests for high-profile individuals, which confirmed his appeal had been received but that they had to wait as long as 60 days for review.

By late Wednesday, there was a glimmer of hope in Donenfeld’s case. He told TechCrunch that he was finally in contact with Microsoft and that hopefully the issue would be resolved soon.

Microsoft did not immediately comment when reached by TechCrunch.

Donenfeld and Idrassi are not alone, with the account lockout issues affecting others as well.

Windscribe, a maker of VPN and other consumer privacy tools, said in a post on X that it had also been locked out of its Partner Center account. The company said it had a verified account for over eight years in order to sign its drivers.

“We’ve been trying to resolve this for over a month, and getting nowhere. Support is non-existent,” Windscribe said in its post. “Anyone know a human with a brain that still works at Microsoft and can help?”

#WireGuard #VPN #developer #ship #software #updates #Microsoft #locks #account #TechCrunchcybersecurity,Microsoft,vpn,Windows,WireGuard

WireGuard, the major software project and VPN that underpins popular security software including Mullvad and…

Telegram groups and channels that advertise and sell hacking and surveillance services that can be used to harass friends, wives and girlfriends, and former partners, new research has uncovered. The findings, from a European nonprofit group, also say that the communities are involved in extensive trading, selling, and promotion of a huge variety of abusive content, including nonconsensual intimate images of women, so-called nudifying services, plus folders of images that sellers claim include child sexual abuse material and depictions of incest and rape.

Over six weeks earlier this year, researchers at the algorithmic auditing group AI Forensics analyzed nearly 2.8 million messages sent across 16 Italian and Spanish Telegram communities that are regularly posting abusive content targeting women and girls. More than 24,000 members of the Telegram groups and channels took part in posting 82,723 images, videos, and audio files over the course of the study, the analysis says. Many posts target celebrities and influencers, but men in the groups also frequently victimize women they know.

“We tend to forget that most victims are ordinary women who sometimes don’t even know that their pictures are shared or manipulated in these types of channels,” says Silvia Semenzin, a researcher at AI Forensics who previously exposed Italian Telegram channels engaging in similar behavior as far back as 2019. “The majority of this violence is directed towards people who the perpetrators know,” she says, suggesting that Telegram, which has over 1 billion monthly active users, according to company founder Pavel Durov, should be subject to stricter regulation and classed as a “very large online platform” under Europe’s online safety rules.

The findings come as Durov is fighting back against Russia’s efforts to block the messaging app in that country, which has long positioned itself as a messaging app that allows free speech but has simultaneously been used by some to share terrorist, sexual abuse, and cybercrime materials. Durov is under criminal investigation in France relating to alleged criminal activity taking place on Telegram, although he has consistently denied the allegations.

A Telegram spokesperson tells WIRED that the company removes “millions” of pieces of content per day using “custom AI tools” and has policies in Europe that do not allow the promotion of violence, illegal sexual content including nonconsensual imagery, and other content such as doxing and selling illegal goods and services.

Among the extensive types of abusive content and services observed by the AI Forensics researchers were frequent references to the access, publishing, and doxing of women’s private information, sharing their Instagram or TikTok content, as well as references to spying or hacking. “Victims are often named, tagged, and locatable via shared profile links,” the group’s report says.

One translated post on Telegram titled “Professional hacking on commission” claimed to be able to give customers “access to phone gallery and extraction of photos and videos,” as well as “anonymous social media hacking.” Another message says: “I hack and recover any type of social media service. I can spy on your partner’s account. Send me a private message.”

Across the dataset there were more than 18,000 references to spying or spy content. One post reads: “Hi, do you have the desire to spy on a girl’s gallery? We sell a bot that does it for info DM.” Meanwhile, users were observed asking if people could find phone numbers connected to Instagram accounts and other requests, “who exchanges spy photos and videos?”

#Men #Buying #Hacking #Tools #Wives #Friendscrime,privacy,security,cybersecurity,hacking,surveillance,telegram"> Men Are Buying Hacking Tools to Use Against Their Wives and FriendsThousands of men are members of Telegram groups and channels that advertise and sell hacking and surveillance services that can be used to harass friends, wives and girlfriends, and former partners, new research has uncovered. The findings, from a European nonprofit group, also say that the communities are involved in extensive trading, selling, and promotion of a huge variety of abusive content, including nonconsensual intimate images of women, so-called nudifying services, plus folders of images that sellers claim include child sexual abuse material and depictions of incest and rape.Over six weeks earlier this year, researchers at the algorithmic auditing group AI Forensics analyzed nearly 2.8 million messages sent across 16 Italian and Spanish Telegram communities that are regularly posting abusive content targeting women and girls. More than 24,000 members of the Telegram groups and channels took part in posting 82,723 images, videos, and audio files over the course of the study, the analysis says. Many posts target celebrities and influencers, but men in the groups also frequently victimize women they know.“We tend to forget that most victims are ordinary women who sometimes don’t even know that their pictures are shared or manipulated in these types of channels,” says Silvia Semenzin, a researcher at AI Forensics who previously exposed Italian Telegram channels engaging in similar behavior as far back as 2019. “The majority of this violence is directed towards people who the perpetrators know,” she says, suggesting that Telegram, which has over 1 billion monthly active users, according to company founder Pavel Durov, should be subject to stricter regulation and classed as a “very large online platform” under Europe’s online safety rules.The findings come as Durov is fighting back against Russia’s efforts to block the messaging app in that country, which has long positioned itself as a messaging app that allows free speech but has simultaneously been used by some to share terrorist, sexual abuse, and cybercrime materials. Durov is under criminal investigation in France relating to alleged criminal activity taking place on Telegram, although he has consistently denied the allegations.A Telegram spokesperson tells WIRED that the company removes “millions” of pieces of content per day using “custom AI tools” and has policies in Europe that do not allow the promotion of violence, illegal sexual content including nonconsensual imagery, and other content such as doxing and selling illegal goods and services.Among the extensive types of abusive content and services observed by the AI Forensics researchers were frequent references to the access, publishing, and doxing of women’s private information, sharing their Instagram or TikTok content, as well as references to spying or hacking. “Victims are often named, tagged, and locatable via shared profile links,” the group’s report says.One translated post on Telegram titled “Professional hacking on commission” claimed to be able to give customers “access to phone gallery and extraction of photos and videos,” as well as “anonymous social media hacking.” Another message says: “I hack and recover any type of social media service. I can spy on your partner’s account. Send me a private message.”Across the dataset there were more than 18,000 references to spying or spy content. One post reads: “Hi, do you have the desire to spy on a girl’s gallery? We sell a bot that does it for info DM.” Meanwhile, users were observed asking if people could find phone numbers connected to Instagram accounts and other requests, “who exchanges spy photos and videos?”#Men #Buying #Hacking #Tools #Wives #Friendscrime,privacy,security,cybersecurity,hacking,surveillance,telegram
Tech-news

Telegram groups and channels that advertise and sell hacking and surveillance services that can be used to harass friends, wives and girlfriends, and former partners, new research has uncovered. The findings, from a European nonprofit group, also say that the communities are involved in extensive trading, selling, and promotion of a huge variety of abusive content, including nonconsensual intimate images of women, so-called nudifying services, plus folders of images that sellers claim include child sexual abuse material and depictions of incest and rape.

Over six weeks earlier this year, researchers at the algorithmic auditing group AI Forensics analyzed nearly 2.8 million messages sent across 16 Italian and Spanish Telegram communities that are regularly posting abusive content targeting women and girls. More than 24,000 members of the Telegram groups and channels took part in posting 82,723 images, videos, and audio files over the course of the study, the analysis says. Many posts target celebrities and influencers, but men in the groups also frequently victimize women they know.

“We tend to forget that most victims are ordinary women who sometimes don’t even know that their pictures are shared or manipulated in these types of channels,” says Silvia Semenzin, a researcher at AI Forensics who previously exposed Italian Telegram channels engaging in similar behavior as far back as 2019. “The majority of this violence is directed towards people who the perpetrators know,” she says, suggesting that Telegram, which has over 1 billion monthly active users, according to company founder Pavel Durov, should be subject to stricter regulation and classed as a “very large online platform” under Europe’s online safety rules.

The findings come as Durov is fighting back against Russia’s efforts to block the messaging app in that country, which has long positioned itself as a messaging app that allows free speech but has simultaneously been used by some to share terrorist, sexual abuse, and cybercrime materials. Durov is under criminal investigation in France relating to alleged criminal activity taking place on Telegram, although he has consistently denied the allegations.

A Telegram spokesperson tells WIRED that the company removes “millions” of pieces of content per day using “custom AI tools” and has policies in Europe that do not allow the promotion of violence, illegal sexual content including nonconsensual imagery, and other content such as doxing and selling illegal goods and services.

Among the extensive types of abusive content and services observed by the AI Forensics researchers were frequent references to the access, publishing, and doxing of women’s private information, sharing their Instagram or TikTok content, as well as references to spying or hacking. “Victims are often named, tagged, and locatable via shared profile links,” the group’s report says.

One translated post on Telegram titled “Professional hacking on commission” claimed to be able to give customers “access to phone gallery and extraction of photos and videos,” as well as “anonymous social media hacking.” Another message says: “I hack and recover any type of social media service. I can spy on your partner’s account. Send me a private message.”

Across the dataset there were more than 18,000 references to spying or spy content. One post reads: “Hi, do you have the desire to spy on a girl’s gallery? We sell a bot that does it for info DM.” Meanwhile, users were observed asking if people could find phone numbers connected to Instagram accounts and other requests, “who exchanges spy photos and videos?”

#Men #Buying #Hacking #Tools #Wives #Friendscrime,privacy,security,cybersecurity,hacking,surveillance,telegram">Men Are Buying Hacking Tools to Use Against Their Wives and Friends

Thousands of men are members of Telegram groups and channels that advertise and sell hacking and surveillance services that can be used to harass friends, wives and girlfriends, and former partners, new research has uncovered. The findings, from a European nonprofit group, also say that the communities are involved in extensive trading, selling, and promotion of a huge variety of abusive content, including nonconsensual intimate images of women, so-called nudifying services, plus folders of images that sellers claim include child sexual abuse material and depictions of incest and rape.

Over six weeks earlier this year, researchers at the algorithmic auditing group AI Forensics analyzed nearly 2.8 million messages sent across 16 Italian and Spanish Telegram communities that are regularly posting abusive content targeting women and girls. More than 24,000 members of the Telegram groups and channels took part in posting 82,723 images, videos, and audio files over the course of the study, the analysis says. Many posts target celebrities and influencers, but men in the groups also frequently victimize women they know.

“We tend to forget that most victims are ordinary women who sometimes don’t even know that their pictures are shared or manipulated in these types of channels,” says Silvia Semenzin, a researcher at AI Forensics who previously exposed Italian Telegram channels engaging in similar behavior as far back as 2019. “The majority of this violence is directed towards people who the perpetrators know,” she says, suggesting that Telegram, which has over 1 billion monthly active users, according to company founder Pavel Durov, should be subject to stricter regulation and classed as a “very large online platform” under Europe’s online safety rules.

The findings come as Durov is fighting back against Russia’s efforts to block the messaging app in that country, which has long positioned itself as a messaging app that allows free speech but has simultaneously been used by some to share terrorist, sexual abuse, and cybercrime materials. Durov is under criminal investigation in France relating to alleged criminal activity taking place on Telegram, although he has consistently denied the allegations.

A Telegram spokesperson tells WIRED that the company removes “millions” of pieces of content per day using “custom AI tools” and has policies in Europe that do not allow the promotion of violence, illegal sexual content including nonconsensual imagery, and other content such as doxing and selling illegal goods and services.

Among the extensive types of abusive content and services observed by the AI Forensics researchers were frequent references to the access, publishing, and doxing of women’s private information, sharing their Instagram or TikTok content, as well as references to spying or hacking. “Victims are often named, tagged, and locatable via shared profile links,” the group’s report says.

One translated post on Telegram titled “Professional hacking on commission” claimed to be able to give customers “access to phone gallery and extraction of photos and videos,” as well as “anonymous social media hacking.” Another message says: “I hack and recover any type of social media service. I can spy on your partner’s account. Send me a private message.”

Across the dataset there were more than 18,000 references to spying or spy content. One post reads: “Hi, do you have the desire to spy on a girl’s gallery? We sell a bot that does it for info DM.” Meanwhile, users were observed asking if people could find phone numbers connected to Instagram accounts and other requests, “who exchanges spy photos and videos?”

#Men #Buying #Hacking #Tools #Wives #Friendscrime,privacy,security,cybersecurity,hacking,surveillance,telegram

Thousands of men are members of Telegram groups and channels that advertise and sell hacking…

Tech-news

Hims & Hers, the telehealth company that sells weight-loss drugs and sexual health prescriptions, has…

Tech-news

Decentralized finance company Drift says it has suspended withdrawals and deposits after confirming a security…