Since our last report Surveillance company Flock Safety is developing an AI-powered search tool for law enforcement. WIRED reconstructed the latest version of Flock’s search technology by analyzing the code delivered to police officers’ browsers, uncovering important details about how the system operates and processes searches.
OpenAI announced that its upcoming private-release Astra model is the company’s first AI system to include cybersecurity capabilities that OpenAI classifies as posing a “significant” risk if publicly released. Meanwhile, Claude, ChatGPT, and Grok experienced nearly simultaneous outages on Thursday. xAI attributed Grok’s disruption to problems at its Memphis data center, while the causes of the OpenAI and Anthropic outages remain unclear.
The United States is deploying high-energy lasers to destroy drones near the Mexican border as part of an effort to introduce a new generation of directed-energy weapons capable of detecting, tracking, and disabling drones with focused beams of light. In a separate development, Homeland Security Investigations officials investigating protesters who entered a Minnesota church in March subpoenaed outdoor retailer REI for information about every customer who purchased a specific green beanie during the past two years.
A new study also identified nine vulnerabilities affecting ATM encryption, highlighting broader security risks throughout the financial technology and software supply chains.
There’s more. Each week, we round up major cybersecurity, privacy, artificial intelligence, and surveillance stories that we have not covered in depth. Click each headline to read the full report—and stay safe online and offline.
New information indicates that an OpenAI agent fraudulently took control of a German website in early May and used it as a bulletin board to communicate and collaborate with other AI agents, according to the study. The incident recalls the infamous Hugging Face episode, in which OpenAI agents operating in a test environment reportedly went rogue, created a collaborative bulletin board, attempted to escape containment, and eventually infiltrated the open source AI platform in July. The May incident is especially significant because OpenAI reportedly learned about it weeks ago but did not disclose it publicly. Last week, the company released its long-awaited postmortem investigation into the “Hugging Face” incident, although the report raised as many questions as it answered.
A new dark web service called Nexus is reportedly offering approximately 153 million U.S. and Canadian driver’s licenses, along with 10 million identity cards and millions of travel documents and international IDs, according to longtime independent cybersecurity reporter Brian Krebs. Krebs was alerted to the alleged identity-data marketplace after a cybercriminal posted a sample file containing a copy of Krebs’s driver’s license. Reports indicate that the database grew by roughly 400,000 records in 24 hours and may contain data obtained from identity-verification services. The criminals claim to have access to “major” verification companies. Nexus reportedly went offline soon after Krebs reported that the FBI was investigating the service, although it remains unclear which company or companies were involved.
The U.S. military has begun disabling advertising identifiers used by mobile apps and advertising companies to track phones and computers. The goal is to make it more difficult for foreign adversaries to monitor U.S. service members overseas through commercially available location data, Reuters reported Friday.
The changes follow years of revelations about military deployments and location-data risks. Reuters reported that U.S. military personnel are being targeted with commercially available location information. In 2024, a joint investigation by WIRED, Germany’s Bavarian Broadcasting Corporation, and Netzpolitik.org obtained an advertising dataset that identified thousands of devices appearing at U.S. military and intelligence facilities, including air bases where U.S. nuclear weapons are believed to be stored. At the time, Pentagon spokesperson Jawan Rasnake told WIRED that geolocation services can place personnel at risk and that U.S. military personnel in Europe were being reminded to follow operational security practices.
The Air Force, Army, Navy, and U.S. Special Operations Command have announced plans to disable advertising IDs on at least some military equipment, with certain changes taking effect earlier this year. The precise implementation of these privacy and security protections remains unclear. U.S. Senator Ron Wyden and Representative Pat Halligan are calling on the Pentagon to investigate whether the measures provide adequate protection against location tracking and foreign surveillance.
Source: www.wired.com


