As controversial vehicle-surveillance company Flock Safety continues to expand, WIRED obtained the code for its new AI-powered police tool and rebuilt the software to demonstrate that its capabilities extend far beyond license-plate reading and vehicle tracking. This week, WIRED also reported on a Rhode Island Police Department officer who faced five internal-affairs investigations in less than two years after publicly questioning his department’s use of Flock cameras.
Following several high-profile incidents involving misbehaving AI agents, OpenAI announced that it is pausing model-training runs while overhauling its internal safety protocols. The company said its next-generation Astra model could represent a major shift in advanced cyber capabilities.
Reverse-identification services have exposed millions of facial photographs in databases accessible through the open internet. Meanwhile, Meta delivered ads for apps that claimed to create nude images of female politicians, including one advertisement featuring a pornographic deepfake video resembling prominent US politicians. After WIRED’s investigation, Apple removed the app from the App Store.
WIRED also spoke with Andy Yen, CEO of privacy-focused digital services company Proton, about the privacy risks of artificial intelligence and the growing importance of encryption in the AI era.
There’s more. Each week, we round up important cybersecurity and privacy news that we did not cover in detail. Click the headlines to read the full reports—and stay safe online and offline.
Most people understand that a valid credit card can be dangerous if it is lost, stolen, or exposed to fraud. What is less obvious is that an expired Visa card may also provide a pathway into a bank account if it is discarded, left unattended, or recovered by fraudsters and “zombified” using a technique recently disclosed by security researchers.
At last week’s USENIX cybersecurity conference, researchers from the University of Massachusetts Amherst warned that criminals could use expired Visa cards to make contactless payments through a man-in-the-middle mobile app. The technique relays payment data between two phones. Because of weaknesses in the authentication process for contactless transactions, researchers found that the way an expired card is rejected depends on how encryption is implemented by the card issuer. Visa reportedly had a flaw that allowed some expired cards to pass verification. Visa did not respond to a request for comment from The Register, which reported on the research.
The researchers said Visa effectively delegated responsibility for authenticating these transactions to cardholders’ banks. Some banks blocked payments made with “zombie” cards, while others did not. In certain circumstances, fraudsters could recover an expired card from the trash and use it to make unauthorized purchases from the linked account. The risk may be greater at point-of-sale terminals where phone-based proxy settings are difficult to detect.
The lesson is simple: Even after a Visa card expires, destroy it thoroughly—cut through the chip and magnetic stripe—before throwing it away.
Apple has long warned iPhone and other device users when it detects possible targeting by “mercenary spyware”—advanced malware allegedly deployed by governments or state-sponsored hackers. TechCrunch spoke with security researchers investigating potential spyware infections who said Apple’s latest alert campaign reached an “unprecedented” number of possible victims. The notifications were sent to targets in 110 countries, with the number of recipients rising by more than 30 percent compared with the previous alert, according to Mohamed Al Maskati, head of the security research team at digital-rights organization Access Now. TechCrunch reported that at least one recipient was a Ukrainian military officer and that other members of Ukraine’s military also received alerts. Sophisticated iPhone hacking campaigns may be increasing: This year, researchers from iVerify and Google identified two iOS mass-exploitation tools known as DarkSword and Coruna.
Russia’s decade-long cyberwar against Ukraine has repeatedly combined physical and digital attacks, including operations that disrupted power supplies during air raids. Ukraine now appears to be using similar tactics as it escalates counterattacks against Russia. According to cybersecurity outlet The Record, Ukraine’s military launched a damaging cyberattack against Russian e-commerce company Wildberries during a drone operation this week, reportedly affecting some of the company’s warehouse infrastructure. Although Wildberries is primarily a consumer retailer, Ukraine’s Intelligence Directorate has accused the company of supporting Russian military logistics and helping finance the war. The Record could not independently verify the full impact of the cyberattack. Russian media reported that drone strikes destroyed roughly 13 million square feet of warehouse space.
Exploit software is increasingly being developed with the help of artificial intelligence. A group of US agencies—including the National Security Agency, FBI, Department of Energy, Environmental Protection Agency, and Cybersecurity and Infrastructure Security Agency—warned this week that AI-assisted hacking tools are targeting Siemens programmable logic controllers, or PLCs. These devices control physical processes in industrial environments. The affected sectors may include manufacturing, chemicals, energy, water, food, and agriculture. “Using AI to generate exploit scripts represents an evolution in the capabilities of threat actors and significantly reduces the technical expertise and time required to develop practical ICS exploit scripts and malicious tools,” the advisory said. ICS refers to industrial control systems. The warning comes amid an unprecedented campaign targeting public water and wastewater facilities in at least seven US states, an operation believed to involve Iranian hackers.
Source: www.wired.com


