This is a somewhat light hearted, lightweight IT privacy and security podcast that spans the globe in terms of issues covered with topics that draw in everyone from newbie to tech specialist. Invest between 15 and 30 minutes a week to come up to speed on

This deep dive takes apart the evolving landscape of digital privacy, artificial intelligence, and global security, highlighting how systems designed for convenience often transform into tools for surveillance. Key reports detail the rise of facial recognition in retail, the exploitation of dormant accounts to spread malware, and the vulnerability of smart home devices to international espionage. We also explore shifting labor trends, noting a massive surge in cybersecurity interest and a move toward skill-based hiring over traditional degrees. Furthermore, we discuss the technological rivalry between the US and China, where cost-cutting and data extraction drive the adoption of rival AI models. Ultimately, this update serves as a warning that security is a continuous process requiring constant vigilance against automated threats and behavioral tracking.

In this week's updateUK shops are about to call the police on you within four seconds of you walking through the door - and you don't have to do anything wrong first.A GitHub account sat completely silent for 19 months, then woke up and dropped a working mass-exploit kit within minutes - and age on the internet is not the same as trust.Fifty-five percent of Americans have quietly stopped posting on social media - and the reason isn't what the platforms want to admit.Recruiters say they can't find workers. New graduates say they can't find jobs. The economy says both of them are right - and AI is not actually the villain in this one.Applied AI engineering is becoming one of the hottest jobs in tech, and the skill that matters most is not writing clever prompts - it's building report cards for AI that catch the model when it quietly does something dangerous.The Pentagon opened a paid cybersecurity apprenticeship that requires no degree, no experience, and no prior skills - and 70,000 people showed up within days.Russian intelligence didn't hack into military networks to spy on NATO supply convoys - they just looked through the security cameras of ordinary homes with default passwords.The US and China are fighting an AI war on two fronts simultaneously: American companies are secretly using Chinese models to cut costs, and Chinese teams are running millions of fake conversations with American AI to steal what makes it work.Cloudflare has stopped asking you to click the traffic lights. Now it just watches your mouse move - for your entire visit - and decides from there.This week's stories are united by a single uncomfortable observation: the systems we built for convenience keep turning into systems of surveillance, and the systems we built for security keep being the ones we forgot to secure. Some of this week is alarming. Some of it is genuinely useful. All of it is worth understanding. Let's face it.Find the full transcript to this week's podcast here.

These stories highlight the multifaceted challenges of the burgeoning AI era, ranging from geopolitical regulatory shifts to novel cybersecurity threats. While the U.S. government leverages export controls to extract security commitments from AI developers, international bodies like the EU are implementing strict enforcement deadlines for high-risk systems. Technological advancements are simultaneously enabling autonomous ransomware attacks and revolutionary scientific discoveries, such as AI-designed antibiotics. However, this rapid integration creates significant strain on local energy infrastructure and reveals the persistent necessity of human expertise in traditional engineering. Furthermore, the legal landscape is evolving as courts and legislatures move to protect digital privacy and shield minors from the emotional manipulation of AI companions. Collectively, these reports underscore that as AI becomes a universal tool, society must grapple with its physical, ethical, and security implications.

Episode 299 Discoveries in this week's update...Microsoft's Windows has been quietly assigning every PC a persistent tracking ID that survives VPNs, new IP addresses, and most attempts to disappear - and a hacker just got arrested because of it.Anthropic built a secret tracker inside its own developer tool to watch for Chinese users - and the company that made its name on responsible AI had to remove it after researchers found the hidden code.The Supreme Court just handed every smartphone owner in America a constitutional privacy right they didn't know they had - and it changes what law enforcement can do with your location data forever.An Air Force engineer with a saw and a point to make took down 13 license plate reader cameras - and thousands of strangers across the country sent him money to say thank you.An AI agent was given a web browser, a payment system, and instructions to help - and attackers left invisible instructions on websites that redirected the money somewhere else entirely.The first ransomware attack run entirely by an AI agent - start to finish, no human required - happened this week, and the kill chain took minutes not days.The MEP who sat on the European Parliament committee investigating Pegasus spyware had his own phone infected with Pegasus spyware while he was doing it.Amazon just told everyone who bought a Fire Stick that they no longer control what runs on it - and the feature they killed was the one most commonly used to limit Amazon's ability to track you.This week, the theme writes itself: everything is watching something.Your operating system, your AI assistant, your TV stick, the cameras on every corner, the spyware on the phones of the people writing the rules about spyware.The stories this week are sometimes alarming, occasionally darkly funny, and always worth paying attention to - because the first step to not being tracked is knowing what's doing the tracking.Let's discover.Find the full transcript to theis podcast here.

This week's update details a rapidly shifting technological landscape where AI-driven advancements are fundamentally altering global security and corporate ethics. Several reports highlight how adversarial capabilities from rival nations now match elite Western models, prompting urgent international warnings from intelligence agencies about a coming surge in cyber warfare. Domestically, the reports track significant legal and privacy challenges, ranging from Meta's controversial testing methods involving minors to landmark Supreme Court rulings on digital surveillance. Furthermore, our updates emphasize a growing systemic risk within the software industry, as AI-generated code introduces hidden vulnerabilities and leaks sensitive credentials. This collection collectively underscores a critical pivot point where defensive infrastructure must evolve rapidly to keep pace with automated threats. High-stakes stories of supply chain dependencies and data breaches illustrate the difficulty of maintaining security in a globally interconnected environment. Ultimately, the stories serve up a warning that institutional understanding is currently trailing behind the speed of AI integration. Oh yeah!

Episode 298. In this week's update: Meta contractors spent months posing as suicidal, drug-curious teenagers to test rival chatbots - and the platforms being probed had no idea it was happening.A Chinese AI lab just matched Anthropic's top cybersecurity model on its own turf - and the question isn't whether export controls work, it's whether they ever could.The New York Times says Microsoft didn't just host OpenAI's training runs - it built a 285,000-core machine specifically engineered to feed on its journalism, and the lawsuit's whole strategy just shifted because of it.A shell trick older than most AI startups just walked straight past ten out of eleven coding agent guardrails - and the fix isn't as simple as updating a blocklist.Nearly two out of three AI chatbot apps tested on iPhone are leaking the keys to someone else's wallet - and you'd never know it just by using them.A federal gun-enforcement agency ran more than 300 warrantless phone-tracking searches using data bought from ad networks - until a prosecutor and a judge themselves said no.Companies fired workers to save money on AI, and now some of them are paying five times more for the AI than they ever paid the humans - Gartner says that's not a fluke, it's the trend.Five allied nations' top cybersecurity agencies just used the word 'urgent' in the same breath as 'months, not years' - and that combination doesn't happen by accident.Welcome back, everyone. This is a week where the gap between how fast AI is moving and how fast our safeguards, our laws, and our budgets are catching up gets impossible to ignore, from corporate testing practices that crossed a line to a legal theory that could put cloud infrastructure itself on trial to a federal agency that finally got told no. It runs from alarming to sobering to genuinely urgent, and there isn't a soft landing at the end of it. Let's get into it.Find all the story links and the full transcript for this podcast here.

This week we dive deep, highlighting a volatile period for the technology sector, defined by increased government intervention and emerging security threats. The U.S. administration is reportedly targeting AI firms like Anthropic over national security and military compliance, while other companies face critical zero-day vulnerabilities and disputes over bug bounty programs. Beyond security, the landscape is shifting due to ambitious legislative proposals to redistribute AI wealth and major corporate pivots, such as Midjourney's move into medical imaging and GM's expansion into energy storage. Supply chain issues also persist, with AI-driven hardware shortages driving up consumer electronics prices globally. Meanwhile, advancements in 3D-printed batteries and enterprise knowledge graphs signal a new era of infrastructure design. Ultimately, these developments reveal a complex environment where geopolitical strategy, ethical accountability, and rapid innovation are becoming inextricably linked.

Episode 297 The U.S. government gave one of America's most important AI companies 90 minutes to shut off its best models - and the reason they gave keeps changing.The real story behind the Anthropic ban has nothing to do with a jailbreak - and everything to do with autonomous weapons and who gets to say no to the Pentagon.The FBI just seized thirteen websites posing as consulting firms - and the fake recruiters behind them may have already messaged someone you know.Hackers spent two months inside Novo Nordisk's systems and walked out with something new: the company's AI models themselves.Your next smartphone is going to cost significantly more - not because of tariffs, but because AI data centers ate all the memory chips.Sixty percent of what TikTok serves to brand new accounts is AI-generated slop - and it's worse when the account belongs to a child.The war in Ukraine has become the world's first live demonstration of AI-assisted combat, and the people planning the next conflict are paying very close attention.Meta is quietly lobbying Congress right now to make it legally impossible for families to sue the company when its algorithms harm their children - and almost nobody is talking about it.This has been a week where the people with the most power moved fastest and quietest - in government backrooms, in corporate lobbying offices, on battlefield drone feeds, and in the recommendation engines shaping what our kids see.Some of these stories are alarming.Some are clarifying.All of them deserve your attention.Let's get into it.Find the full transcript to this podcast here.

This week's update illustrates a global landscape rapidly transforming under the influence of artificial intelligence, highlighting both its innovative potential and significant societal risks. Surveillance capabilities are expanding through SignalTrace, which links vehicle data to personal electronics, while military navigation increasingly relies on spatial data harvested from mobile gaming. Within the workforce, professionals are navigating a "botsitting" paradox where productivity gains are often offset by the labor of managing AI errors and oversight. Simultaneously, the educational sector faces a crisis as reliance on digital tools correlates with a measurable decline in students' reading comprehension and attention spans. Security concerns are also intensifying, evidenced by CISA's new mandates for faster software patching to counter automated cyberattacks. Ultimately, these reports suggest that the true challenge of the AI era lies in managing data correlation and organizational adaptation rather than just technical advancement.

Episode 296. In this week's update:Your license plate reader just got an upgrade, and now it wants to know what's in your pocket, too.The government finally admitted what security pros have been saying for years: AI means you have three days to patch, not three months.AI adoption went from 'we're running a pilot' to 'we're running the business,' and nobody sent a memo.Workers are saving 11 hours a week to AI, then spending six of those hours babysitting the AI and someone had to invent a word for that.Microsoft's AI chief said AI would automate most white-collar work, then clarified he meant 'tasks' and that one-word swap changes everything.Meta dropped $14 billion on AI talent, shipped its first proprietary model, and is now discovering that building the thing and selling the thing are completely different jobs.A UK police officer allegedly used AI to fabricate evidence, and this isn't the first time British law enforcement has had an AI problem.Pokémon Go players spent years scanning the world for virtual creatures, and that data is now helping real drones navigate without GPS.This has been a week where the gap between what AI promises and what AI actually delivers has become very interesting to look at from the factory floor to the courtroom to the battlefield. Some stories are alarming. Some are clarifying. A few are genuinely strange. Let's get recognized.Find the full transcript to this podcast here.

This week we highlight the dual-natured impact of artificial intelligence on global security, privacy, and administrative productivity. On the defensive side, tools like Google's Gemini are blocking billions of fraudulent ads, while the NHS is deploying Microsoft Copilot to drastically reduce clinical paperwork. Conversely, bad actors are leveraging AI-driven phishing to compromise digital assets and developing adaptive malware that can reason through system defenses. Serious privacy concerns also emerge, evidenced by Meta's controversial development of facial recognition for smart glasses and the misuse of automated license plate readers by law enforcement. Additionally, the reports detail how nation-state actors use professional networks like LinkedIn for espionage and how criminals exploit autonomous transit for physical crimes. Ultimately, the collection suggests that as AI becomes a central pillar of modern life, the most critical security skill is the ability to verify identity in an increasingly deceptive digital landscape.

In this week's update:The NHS is about to hand half a million clinicians an AI assistant for their paperwork - and the question isn't whether it will work, it's whether healthcare will ever look the same again.An innocent man spent a month behind bars because an AI license plate reader put him in two places at once - and the cameras that could have cleared him were right there the whole time.China's military intelligence services have quietly turned LinkedIn into a recruitment tool, and the side gig that seemed too good to be true may be the most expensive mistake of your career.Anthropic spent a year watching how criminals actually use AI, and what they found is less about catastrophe and more about something far more unsettling: amplification.Researchers just demonstrated an AI-powered worm that doesn't just exploit weaknesses - it reasons, adapts, and chooses its own attack path in real time.Meta removed a facial recognition system from its smart glasses app this week - a system that, according to Meta, did not yet exist.A San Francisco burglar used a Waymo robotaxi as a getaway car, and between deleted footage and blurred faces, the case is still wide open months later.Hidden inside the GPS signal that guides every phone, every ship, and every missile on the planet, a researcher just found something the military has been quietly broadcasting for nearly two decades.Welcome back, everyone. This week, we are taking you from a British hospital corridor to a San Diego courtroom, from LinkedIn's shadowy recruitment pipeline to the hidden depths of a GPS signal that billions of people use every single day. Buckle up - this one covers the full spectrum, from the bureaucratic to the alarming to the genuinely mind-bending. Find the full transcript to this podcast here.

This deep dive explores the evolving landscape of artificial intelligence and its profound impact on global cybersecurity and infrastructure. Sources detail the dual nature of AI, highlighting its ability to uncover thousands of software vulnerabilities while simultaneously creating new risks through manipulated support bots and accelerated exploitation timelines. Beyond software, the text addresses physical security threats to undersea data cables and the potential repurposing of Cold War-era plutonium for private energy startups. Technical breakthroughs like certified quantum randomness and new browser-based spying techniques underscore a shifting digital perimeter where traditional trust models are failing. Furthermore, the economic reality of this shift is visible in Anthropic's massive valuation, new usage-based AI pricing, and the unexpected role of remote work in sidelining junior talent. These developments suggest a future where automated containment and government oversight are becoming essential responses to the speed of algorithmic threats.

Episode 294. For this week's update:The Trust Problem Nobody Has Solved. The AI verification problem isn't a bug to be patched; it's a structural flaw baked into the architecture of trust itself. It's like asking a child to set their own bed time.Forget cookies and trackers, a website can now read your entire digital life from the rhythm of your hard drive.Meta's AI support bot did exactly what it was designed to do, and that turned out to be the problem.While the security world chases sophisticated threats, Google quietly closed one of the oldest and most exploited doors in session management.ETH Zurich researchers have done something cryptographers have wanted for decades produced randomness that the laws of physics themselves will guarantee forever.The generation entering the workforce during the remote-work era may be carrying a career penalty they didn't earn and can't yet see.The Software Industry Exhales For Now. Wall Street spent a year writing software's obituary, and this month the patient sat up, ordered lunch, and posted its best returns since the dot-com era.GitHub just handed its most enthusiastic AI users their first real bill, and for many, the number is somewhere between shocking and career-defining.OK, let's tuck in!Find the full transcript to this podcast here.

The corporate attack surface is expanding as autonomous AI agents and developer tools dissolve traditional security boundaries. The software supply chain is now a strategic vulnerability, allowing compromised “trusted tools” to bypass legacy defenses and move directly into internal environments.Recent incidents demonstrate the scale of the risk. GitHub confirmed unauthorized access to roughly 3,800 repositories after a malicious VS Code extension compromised a developer device. Google Cloud infrastructure also exposed a critical “time-to-vulnerability” gap: deleted API keys remained active for an average of 16 minutes, and in some cases up to 23 minutes, despite appearing revoked in the UI. These delays create exploitable windows for autonomous systems to access AI services or sensitive data before responders can intervene.The Cloud Security Alliance warns of an emerging “agentic threat” driven by excessive privileges, weak configurations, prompt injection, poor accountability, and flaws in machine-to-machine interaction. The challenge is no longer simply malicious code, but malicious intent expressed through natural language.Meanwhile, the labor market reflects a “low hire, low fire” reality rather than mass AI unemployment. Layoffs remain historically normal, but hiring and career mobility have slowed as firms adopt leaner operating models and assess automation's long-term impact. Entry-level opportunities are narrowing as companies demand higher productivity from fewer employees using generative tools.Industry leaders remain divided. Steve Wozniak argues AI cannot replace human creativity, while figures such as Sam Altman and Elon Musk warn disruption may eventually require interventions like Universal Basic Income. Many firms are also using “AI transformation” narratives to justify restructuring and post-pandemic cost corrections.Creative industries are shifting from resisting AI to monetizing it. The AI-generated film Hell Grind reportedly required a $500,000 budget, with most costs tied to compute power. Maintaining visual consistency demanded prompts averaging 3,000 words, revealing that AI production remains management-intensive rather than effortless. Spotify and Universal Music Group are also developing licensing frameworks where artists retain control over AI-generated remixes while platforms monetize premium AI creative tools.Technology companies now face growing friction between rapid AI deployment and user trust. Google's “disregard” search glitch showed how AI systems can misinterpret user queries as commands, undermining reliability. Apple's roadmap, including context-aware Siri capabilities and private cloud compute, highlights the industry's push toward personalized assistants.Ultimately, AI adoption depends on trust. Consumers will embrace assistants only if companies prove the infrastructure behind them is reliable, accountable, and secure enough to protect personal data.

Episode 293 A two-week shoot, a half-million dollar budget, and not a single human behind the camera, welcome to the future of Hollywood.This year at Cannes, the most talked-about presence on the Croisette wasn't a movie star; it was artificial intelligence.The Cloud Security Alliance is sounding the alarm on a new breed of AI system that doesn't just answer questions, it takes action, on its own, across your entire digital infrastructure.GitHub just confirmed that roughly 3,800 internal repositories were compromised, and the attacker didn't need a zero-day exploit, just a poisoned developer tool your engineers trust every single day.Google API Keys: Here's a question every incident responder needs to answer: if you delete a compromised credential and the attacker keeps using it for the next twenty-three minutes, did you actually stop the breach?The same AI technology making phishing attacks more convincing may also be our best shot at catching them, and this week, a listener's inbox put that to the test.Spotify and Universal Music Group just agreed to let fans remix their favorite songs using AI, and for the music industry, it's the clearest sign yet that the question is no longer whether this happens, but who controls it when it does.In a spring full of AI doomsday commencement speeches, Steve Wozniak walked onto a stage in Michigan and reminded a room full of nervous graduates that they already carry the most powerful intelligence in the room.Welcome back, everyone. We're glad you're here for Episode 293 of the AI, Privacy, and Security Weekly Update. It's May 26th, 2026, and this week we are going big. We're starting in Cannes, we're going to swing through some genuinely alarming security stories, and we're going to land somewhere a little more hopeful at the end. Let's get into it.Find the transcript to this podcast here.

This update highlights a deteriorating security landscape where human error and advanced technology intersect to create significant digital risks. Critical infrastructure faces threats from sensitive credential leaks at federal agencies and the discovery of unpatched Windows zero-day exploits released by disgruntled researchers. Simultaneously, the rise of artificial intelligence is transforming both offense and defense, enabling experts to bypass modern hardware security in record time while overwhelming open-source maintainers with automated bug reports. Governments are responding by expanding surveillance capabilities, seeking nationwide access to vehicle tracking data and using AI to police financial markets. Meanwhile, geopolitical tensions have shifted toward digital choke points, with nations like Iran threatening the physical cables that underpin global internet connectivity. These shifts occur alongside corporate instability, evidenced by mass layoffs at Meta and legal friction between major tech partners over AI integration.

EP 292. This week we kick off with a flood of updates: The agency trusted to protect America's critical infrastructure couldn't protect its own credentials.Canada is reopening one of tech's most consequential debates and this time, your compliance architecture may be in the crosshairs.A researcher's very public falling-out with Microsoft is quietly becoming everyone's security problem.What once took a seasoned red team weeks now takes a small team and a frontier model less than five days.The race to use AI to find flaws faster than attackers is officially underway and the audit trail question is already lagging behind.AI is flooding the Linux kernel security pipeline with noise, and Linus Torvalds has had enough.Regulators are quietly deploying AI surveillance at a scale that reframes what financial oversight even means.The world's most consequential digital chokepoint just became even more of a geopolitical bargaining chip.Let's go get soaked!Find the full transcript to this podcast here.

This week we highlight the multifaceted global impact of AI infrastructure and digital security, focusing on the physical and financial costs of technological expansion. Reports detail how massive data centers are straining public utilities, causing power disputes in Kenya and Maryland while leading to significant water waste in Georgia. In the realm of cybersecurity, researchers have identified critical vulnerabilities in smart home devices and "zero-day" exploits developed by artificial intelligence, prompting tech giants like Google and Apple to implement stricter protections. Meanwhile, the professional landscape is shifting as Amazon and Nvidia emphasize AI-driven metrics and proprietary software ecosystems, creating new pressures for employees and developers alike. Collectively, these narratives illustrate that while AI offers advancements in molecule design and medical research, its integration into daily life demands greater transparency and more robust infrastructure management.

EP 291. In this week's update:When a 200-pound internet-connected machine can be hijacked from 6,000 miles away, the smart home has officially become a liability.The moment security researchers have long anticipated has arrived: AI is no longer just defending systems - it's actively being used to break them.The same open ecosystems that accelerated AI adoption are now emerging as a significant and underestimated vector for supply chain attacks.In a landscape where breaches are inevitable, DigiCert's handling of a code-signing compromise offers a rare and instructive model for what accountability actually looks like.A browser trusted with your most sensitive credentials is quietly leaving them exposed in memory - and the vendor considers it working as intended.Google is embedding fraud detection directly into the operating system, signaling a fundamental shift in where the mobile security perimeter now begins.After years of a fragmented messaging security landscape, Apple and Google have closed one of the most glaring cross-platform encryption gaps in consumer technology.Decades of observational data linking coffee to longevity may finally have a molecular foundation - and it has nothing to do with caffeine.Let's go grab a mug!Find all links and the full transcript for this podcast here.

This Deep dive dives into the dangerous shift in the digital landscape where sophisticated exploits and simple human deception frequently converge. Major security alerts include a long-standing Linux kernel flaw that grants full system control and the rise of automated AI phishing kits that make high-level cyberattacks more accessible to criminals. Beyond technical bugs, the sources detail how identity theft is being used to systematically defraud financial institutions and how public voter records are being weaponized to expose personal information. Regulatory bodies are pushing back against these trends, evidenced by the FTC's crackdown on data brokers and new international guidance for the safe deployment of agentic AI. Meanwhile, the reports suggest that modern ransomware is evolving to bypass traditional encryption, focusing instead on pure data extortion and credential abuse. Ultimately, these sources emphasize that internal system integrity and strict identity verification are now more critical than traditional perimeter defenses.Find more here

Episode 290. This week, we assume nothing in our collection of stories...A flaw hiding in plain sight for nearly a decade has quietly turned every Linux system's most trusted layer into an open door.Attackers have discovered that the easiest way to install malware is to convince users the malware is the cure.A new phishing kit is lowering the barrier to industrial-scale credential theft to roughly the cost of a Netflix subscription. Ransomware didn't slow down in Q1 2026 it mutated, and the new strain doesn't even need encryption to extort you.Credit Union Loan Fraud The most methodical fraud playbook circulating underground right now doesn't involve a single line of malicious code.A teenager with a forum alias just handed a third of France's population an identity problem they didn't ask for.Six of the world's most serious cybersecurity agencies just issued a unified warning that most organizations deploying agentic AI are not ready for what they've built.A new paper argues that the discipline meant to stress-test AI safety has itself become the thing it was designed to find a vulnerability dressed up as a control.The arc runs from infrastructure to brand to process to institution to the security function itself. Each story is a different flavor of the same failure: someone trusted something they shouldn't have, or built a system that assumed others would.Let's go verify!Find the full transcript to this podcast here.

Warren Buffett once said it's only when the tide goes out that you discover who's been swimming naked. This week, the tide went out on several fronts simultaneously, and what it revealed was uncomfortable, instructive, and in some cases, long overdue.France opened the week with a breach that should trouble every government running centralised identity infrastructure. Up to 19 million records tied to passports, ID cards, and driver's licenses are now circulating on criminal forums. What makes this worse than a typical data leak is the context: a similar dataset from the same agency surfaced in 2025. This wasn't a surprise attack on a hardened target. It was a recurring failure wearing the face of a solved problem.The Bitwarden supply chain story carried a similar energy. No vaults were cracked, no passwords were stolen, and most users never noticed a thing. But a malicious package briefly moved through npm as part of the Checkmarx campaign, targeting the developers who build the software everyone else depends on. The lesson isn't technical — it's structural. Your security posture now extends to every build pipeline, every dependency, and every automation script upstream of your product.Then came FAST16.SYS, and the week shifted into something darker. This rootkit, which appears to predate Stuxnet, didn't steal data or trigger alarms. It quietly altered precision calculations in memory while leaving every file on disk untouched. Systems looked healthy. Outputs looked reasonable. The only thing wrong was the answer. It is the most patient form of sabotage imaginable, and it reframes what advanced threats are actually capable of when detection, not damage, is the real objective.AI brought its own escalation this week. Researchers are now using AI systems to attack other AI systems at machine speed — probing, learning, and refining exploits far faster than any human team. At the same time, agent browsers like Interceptor are quietly repositioning the browser itself as an autonomous actor, raising legitimate questions about oversight when software is doing the clicking, typing, and deciding on your behalf.Anthropic's Mythos model access story tied several threads together neatly. Contractor credentials, open-source reconnaissance, and data exposed in a third-party breach combined to give a small group access to a restricted model. The intent was curiosity, not sabotage — but the mechanism was a textbook illustration of how third-party access chains create exposure that principal organisations rarely see coming.Apple closed out the privacy section with a rare win, patching a logging bug that had been silently retaining Signal message fragments for up to a month — long after deletion, long after the app was removed. The FBI had already used it in court. The patch is clean and the fix is automatic, but the episode is a pointed reminder that ephemeral and permanent are closer together than most people assume.The week closed on strategy. OpenAI and Microsoft have restructured their foundational partnership, removing exclusivity and capping revenue payments. The AI infrastructure layer is becoming contested ground, and this deal confirms that no single partnership, however dominant it once appeared, is permanent.This week's stories didn't shout. They accumulated. And that, more than anything, is the point.

EP 289. Let's climb to the top of this week's stories:France's most trusted identity infrastructure has become its biggest liability, and nineteen million citizens are now paying the price.The real lesson from Bitwarden's close call isn't about passwords it's about how quietly an attack can move through the software you never see being built.A newly uncovered rootkit predating Stuxnet has rewritten what we thought we knew about state-level sabotage and its most dangerous feature was making everything look perfectly normal.The arms race in AI security has hit a new threshold machines are now the ones probing for weaknesses, and they don't need sleep to do it.The browser is no longer just a window to the web it's becoming an autonomous actor, and that changes everything about who's actually in control.A restricted AI model, a contractor's borrowed credentials, and a private Discord channel Anthropic's Mythos access story is a case study in how third-party trust becomes a front door.A logging bug quietly turned one of the world's most trusted encrypted messaging apps into an inadvertent evidence locker and it took an FBI courtroom testimony to bring it to light.OpenAI and Microsoft have redrawn the map of AI's most consequential partnership, and the shift from exclusivity to optionality signals a new phase in who controls the infrastructure layer.Tighten your shoelaces, and let's get to the bottom of this.Find this week's transcript here.

This Deep Dive highlights the evolving landscape of digital threats, ranging from deceptive browser extensions and AI vulnerabilities to state-sponsored surveillance and blockchain exploits. The text is structured as a series of case studies and news alerts that emphasize how modern risks often stem from social engineering and automated scanning rather than purely technical flaws. A recurring theme is the trade-off between convenience and security, illustrating how everyday tools like WordPress plugins or AI coding assistants can be weaponized for data harvesting. Ultimately, the source serves as a strategic warning for users and organizations, arguing that robust defense requires constant vigilance against the invisible vulnerabilities embedded in global digital infrastructure.

EP 288. No privacy, but so much is going on that you might not notice for the next 20 minutes. We start with…A senator who has been right before is raising alarms he cannot fully explain, and that pattern alone should command attention. Traveling with a locked phone just became a legal liability in one of the world's most-visited financial hubs. A hundred thousand users thought they were downloading videos; they were handing over their digital fingerprints.That free app may be paying for itself in ways you never agreed to and will never see on a receipt.North Korea's most prolific hacking group has refined its macOS playbook down to a single terminal command and a moment of misplaced trust.A six-figure plugin acquisition quietly became an eight-month undetected supply chain attack hiding in plain sight.The promise of building software in minutes is colliding with a harder truth: speed without security discipline is just a faster way to expose your users.The same government arguing in court that an AI model is a national security threat is quietly using it to scan its own networks.Let's take a peek…Find the full transcript to this podcast here.

Anthropic Claude Desktop Native Messaging Bridge - The Report (April 2026)Anthropic's official Claude Desktop application (Electron-based, for macOS and Windows) automatically installs an undocumented Native Messaging host bridge during installation and on every launch. On macOS, it places a manifest file (com.anthropic.claude_browser_extension.json) and associated helper binary in the NativeMessagingHosts directories of seven Chromium-based browsers (Chrome, Edge, Brave, Arc, Vivaldi, Opera, and Chromium), even for browsers the user has not installed. On Windows, equivalent registry entries are created under the relevant browser keys. The bridge pre-authorizes specific Anthropic-controlled Chrome extension IDs to communicate directly with the desktop app via standard input/output, outside the browser sandbox. It runs with user-level privileges, is rewritten on each launch (making removal non-persistent), and is not mentioned in the installer, documentation, settings, or release notes. The same behavior occurs on Windows, though implemented via registry rather than filesystem manifests. thatprivacyguy.comFunctionality EnabledThe bridge supports Anthropic's Claude Cowork (desktop agentic workflows) and Dispatch (remote task assignment from mobile). When activated by a compatible Claude browser extension, it enables high-fidelity browser automation, including: Direct DOM access and reading of page content Authenticated session sharing (using existing logins/cookies) Interactive control (form filling, clicking, navigation, scrolling) Data extraction and multi-step web workflows Session recording as GIFsThis provides a more reliable and precise alternative to screenshot-based “computer use” for web tasks, allowing Claude to act as a seamless “digital coworker” on real browser sessions without constant manual intervention or context switching. pluto.securityWhy Anthropic Is Taking This ApproachAnthropic is prioritizing frictionless, agentic AI capabilities to make Claude more useful for productivity and automation. By pre-registering the bridge, the company ensures immediate availability of browser integration for users, enabling Cowork/Dispatch features, without requiring separate manual extension setup or configuration steps. This design choice supports their vision of Claude as an autonomous assistant capable of handling real-world web-based work (e.g., data aggregation, form handling, testing) across common browsers. The implementation is cross-platform and persistent to maintain a consistent, “always-ready” experience. However, it has drawn criticism for lacking transparency, explicit user consent, and documentation, as well as for modifying other vendors' application directories and creating potential security surface area (e.g., prompt-injection risks once activated). As of 21 April 2026, Anthropic has not issued a public response to the report. The approach reflects a common industry tension: balancing powerful AI agent functionality with user control and privacy expectations. Users concerned about the bridge can manually remove the manifests/registry entries, though the app may recreate them on relaunch.

Cybersecurity is entering an “invisibility crisis,” where threats are no longer loud, external attacks but subtle abuses of normal system behavior. Techniques like SockStress exploit TCP assumptions to drain resources, residential proxy networks turn everyday users into unwitting infrastructure, and fake VPNs weaponize trust to exfiltrate data. Even ransomware response processes are being hijacked, transforming incident response into an attack surface. At the same time, transparency mechanisms are failing—Google, Meta, and Microsoft frequently ignore user opt-outs—highlighting a systemic breakdown in consent and accelerating calls for digital sovereignty.This shift feeds directly into geopolitics. Nations increasingly view reliance on foreign technology as a strategic risk, pushing “digital sovereignty” agendas. France, for example, is migrating government systems to domestic or open-source alternatives like Linux and Jitsi, and relocating sensitive health data infrastructure. Meanwhile, advanced AI proliferation introduces a paradox: companies restrict powerful models to prevent misuse, yet real-world breaches—such as the Tianjin Supercomputer incident, where attackers exfiltrated 10 petabytes via a compromised VPN—demonstrate how stealthy, persistent threats can evade detection at scale.Critical infrastructure remains especially vulnerable. Iran-linked actors have targeted industrial control systems (PLCs), showing how cyber intrusions can translate into physical manipulation. The message is clear: internet-connected industrial systems must adopt stronger controls, including multifactor authentication and continuous monitoring, particularly across energy and water sectors.Alongside these risks, the workforce itself is transforming. AI is shifting human roles from execution to oversight—people increasingly “direct” rather than “do.” However, this creates a paradox: while AI boosts productivity, it also increases complexity, oversight demands, and cognitive load. Managers now supervise fleets of AI agents, and professionals often refine AI outputs instead of producing original work. Despite widespread tech layoffs, judgment, accountability, and problem framing are becoming the most valuable—and scarce—skills.The broader theme is one of diminishing visibility and control. Whether in cybersecurity, geopolitics, or labor, systems are becoming more opaque, automated, and interdependent. Even efforts to uncover foundational truths—like identifying Satoshi Nakamoto—remain inconclusive despite advanced analysis. In this environment, the key differentiator is no longer technical capability alone, but human judgment: the ability to question assumptions, verify continuously, and navigate a world where the greatest risks are hidden in plain sight.

Episode 287. On the day before the tax deadline in the US, we've got the most taxing update yet, full of unexpected deductions:OpenAI has unveiled bold policy recommendations to cushion the societal impact of advanced AI, including robot taxes, a public wealth fund, and trials of a four-day workweek. Add in cake for all, and we'd swear Marie Antoinette was running the company.As AI assumes more decision-making roles, human work is evolving from task execution to high-level direction, judgment, and problem framing. Hopefully, there's still time to talk to your school's guidance counselor about changing your major.Professionals are now building personal “AI teams” of multiple specialized agents, dramatically expanding individual capacity while reshaping workloads and expectations.Citing potential misuse risks, OpenAI is restricting access to its most powerful new cybersecurity model, following a cautious approach already adopted by Anthropic. “It's so good you can't have it.”A hacker group known as “FlamingChina” claims to have exfiltrated over 10 petabytes of sensitive data from China's National Supercomputing Center in Tianjin in one of the largest breaches on record.Iran-linked hackers have reportedly disrupted critical operational systems at U.S. oil, gas, and water facilities, in a demonstration of “You hit us, we hit you.”A new independent audit reveals that Google, Microsoft, and Meta shockingly continue tracking users even after privacy opt-out signals are enabled.The New York Times has published a detailed investigation naming British cryptographer Adam Back as the strongest circumstantial candidate yet to be Bitcoin's mysterious creator, Satoshi Nakamoto. Quick, now's the time to get really friendly with Adam.And just like filing taxes, the sooner we get to it, the sooner we get our refund! Let's go!

First up, AI. You'd think if you clean your training data, you control what the model learns. Nope. Researchers just showed that models can pass hidden traits to each other through data that looks completely harmless. Like numbers. No obvious bias, no keywords, nothing. And the new model still picks up the same behavior. Even after you scrub it.Think of it like this. The data looks clean, but the intent is still in there, baked into the structure. So now we have AI systems where you can't fully prove what they learned. You can test outputs, sure, but you can't audit the mind. That's a supply chain problem.Next, LinkedIn. You know how you log in and think you're just updating your resume? Turns out they may have been scanning your browser for extensions. Thousands of them. And extensions tell a story. Health apps, finance tools, job search plugins, political stuff. That's basically your personality in JSON form.LinkedIn says it's for security. Maybe. But the bigger lesson is this: your browser is now part of your identity surface. Not just what you do online, but what you've installed.Now let's talk about your fridge. Yes, your fridge. Samsung pushed ads onto $2,000 refrigerators. After people bought them. So now your kitchen appliance is also an ad platform. You didn't opt in, you just got updated.Same play with TVs. Walmart bought Vizio, and now some TVs require a Walmart account to work properly. Why? Because the TV isn't the product. The data is. What you watch plus what you buy equals a very valuable profile.Software side, GitHub is exploding. We're talking billions of commits. AI is helping people write code faster than ever. Sounds great until you realize nobody is reviewing most of it. More code means more bugs, more vulnerabilities, more weird dependencies sneaking in. Speed went up. Assurance did not.Then quantum computing. This one matters. We used to think breaking encryption would take millions of qubits. Now researchers are saying maybe ten thousand. That's a huge shift. Not tomorrow, but not “someday” either.And here's the kicker. If someone is recording encrypted traffic today, they can just sit on it and decrypt it later when the tech catches up. So anything that needs to stay secret for a long time is already at risk.Zooming out, AI investment is basically all happening in the US. Like almost all of it. That means one country is setting the pace, the standards, and the rules. Everyone else is kind of along for the ride. That's not just business, that's geopolitics.And finally, the courts are waking up. For years, platforms said “we don't control the content.” Now judges are saying, “yeah, but you built the machine that decides what people see.” That's a big shift. Algorithms are starting to look like products with liability.So the theme this week is simple. The real risks aren't obvious anymore. They're hidden in training data, in your browser, in your appliances, in algorithms making decisions you don't see.Which means you don't just ask what the system does. You ask what's underneath it.

Episode 286 And have we got an update for you. Focus on this:Researchers have discovered that AI models can be secretly shaped by their training data even after every suspicious signal has been scrubbed out, which raises an uncomfortable question: do we actually know what we've built?It turns out the most comprehensive profile LinkedIn has on you isn't the one you wrote yourself.Samsung would like you to know that the $2,000 refrigerator you just bought comes with one small surprise: a billboard.AI-assisted coding has pushed GitHub to a billion commits a year, which sounds like extraordinary progress right up until you ask who reviewed all of it.The encryption keeping your most sensitive data safe was designed for a quantum threat that was supposed to be decades away, and researchers just moved the deadline.Last year, the world invested $98 billion in AI, and if you're wondering where the other countries went, the answer is $1.9 billion split between all of them combined.Walmart bought Vizio in 2024, and this week, they quietly revealed what they actually purchased: not the screens, but the 20 million living rooms attached to them.For the first time in a major courtroom, a tech platform is being held liable not for what users posted, but for the machine that decided who should see it.For this update, let's not go subliminal!Find the full transcript to this podcast here.

The Deep Dive for Episode 285.5 explores how patience has become a defining weapon in modern AI, privacy, and security threats. State-backed actors like Red Menshen are quietly compromising telecom infrastructure with stealthy kernel-level implants, turning networks into long-term surveillance platforms while remaining almost invisible. Social engineering is evolving too: campaigns like ClickFix prove that attackers no longer need exotic exploits when they can simply coach users into pasting malicious commands themselves. At the same time, the AI software ecosystem is showing its fragility, as the LiteLLM supply-chain scare demonstrates how a single compromised package can ripple across countless downstream systems.On the frontier-model side, Anthropic's leaked “step change” system underscores how rapidly capabilities are accelerating while governance and operational controls struggle to keep pace. Research on AI essay grading highlights a similar misalignment, showing that LLM-based evaluators often reward surface polish over genuine understanding, raising serious concerns for any high-stakes use of automated assessment. Governments are moving to assert control: the US Department of Defense is driving AI vendors toward a single baseline that prioritizes military requirements, while China's latest Five‑Year Plan positions AI as an instrument of national power, emphasizing large-scale deployment, self-reliance, and ecosystem-level strategy. Finally, the Meta–Manus standoff illustrates how cross-border AI deals sit at the intersection of innovation, capital, and state control, turning corporate decisions into geopolitical flashpoints. Taken together, this episode illustrates that we are not just watching a tech race, but a slow, methodical restructuring of global power through technology, one that rewards deep security, thoughtful governance, and a healthy respect for the risks of quiet, patient adversaries.

Episode 285. This week, we uncover some long-term offensive strategies that show the virtue of patience can have a negative impact on the victims.A China-aligned threat group is quietly weaponizing telecom infrastructure with kernel-level backdoors, turning carriers into long-term strategic listening posts.A low-tech but highly effective social engineering campaign is turning everyday users into their own worst enemy by coaching them to execute the attacker's commands.A popular AI gateway narrowly avoided a cascading supply-chain breach after compromised packages exposed just how fragile modern dependency chains have become.A leaked cache of internal documents has forced Anthropic to confirm a powerful new model, spotlighting both its rapid progress and the operational risks of secrecy at scale.New research shows that AI graders systematically diverge from human judgment, rewarding polish over depth and raising red flags for automated assessment in high-stakes settings.The US Defense Department is pushing AI vendors onto a single contractual and ethical footing, signaling that military requirements will increasingly define how models can be used.China's latest Five-Year Plan elevates AI from a growth priority to a full-spectrum instrument of national power, blending industrial policy with geopolitical strategy.And finally.. The Meta–Manus deal has evolved into a geopolitical flashpoint, illustrating how cross-border AI acquisitions can collide head-on with state control and national security anxieties.You don't even have to be patient with these discoveries. Let's go!Find the full transcript to this podcast here.

The technology landscape has shifted so profoundly that “IT risk” no longer captures current threats. This publication is now the AI, Privacy and Security Weekly Update, reflecting the reality that AI drives both innovation and adversary tactics. Episode 284 (week ending March 24, 2026) covers a surge of AI-driven developments, from autonomous malware to expanding federal data systems, marking the formal start of the surveillance era.The New Surveillance Perimeter: Government Data AggregationA centralized AI “intelligence layer” is forming to map daily life with precision.Federal Consolidation: Internal reports reveal a proposed U.S. system combining immigration, financial, and biometric data into an AI-searchable database.Warrantless Access: FBI Director Kash Patel confirmed resumption of buying commercial location data from brokers.The Upshot: This circumvents Fourth Amendment protections, enabling mass monitoring without individual warrants. The aggregation of sensitive datasets creates persistent “mission creep” and critical single points of failure for the software supply chain.Autonomous Threats and Supply Chain IntegrityAdversaries now deploy self-propagating, automated infection loops that exploit development infrastructure.CanisterWorm: Compromised credentials in Trivy propagated malware across 47 npm packages, harvesting tokens to spread autonomously.Open-Source Sabotage: A related campaign weaponized open-source libraries to erase data on systems in Iran.The Upshot: One stolen credential can now trigger a self-sustaining breach. Security strategy must extend beyond networks to verify every automated dependency.Infrastructure Vulnerabilities and State ControlConnectivity itself is becoming a tool of control,and a potential systemic failure.Strategic Disruption: Russia's mobile internet outages illustrate “digital crackdowns.” Local businesses now lobby to restore access to foreign apps like Telegram and WhatsApp vital for global communication.IoT Lockouts: A cyberattack on Intoxalock disabled 150,000 court-mandated breathalyzers, stranding drivers.The Upshot: Cloud dependence in IoT and politically constrained connectivity expose how fragile digital infrastructure has become for both citizens and commerce.Technological Shifts: Automation and Corporate ResponsibilityBy 2027, automated bot traffic will outpace human activity, forcing a transition from cybersecurity to automation management. Hardware like Intel's “Heracles” chip increases Fully Homomorphic Encryption (FHE) speed 5,000-fold, enabling encrypted computation at scale.Yet “trust bombs” persist:H&R Block: Installed a root certificate (expiring 2049) with its private key embedded, allowing forged secure sites.Bucketsquatting: AWS closed a loophole letting attackers hijack deleted S3 bucket names.Privacy Push: The FCC banned new foreign-made routers over national security risks, and Mozilla introduced a 50GB/month VPN for Firefox to make privacy default.The Upshot: As automated and AI-driven activity dominates the internet, privacy and trust have become core business imperatives,no longer optional features but essential components of market credibility.We hope you enjoyed this week's update and look forward to sharing more AI, Privacy, and Security stories next week!

Episode 284. Yes, that's it. So much of what we cover is now AI-based that we're updating the Update to reflect that. From today, the IT Privacy and Security Weekly Update will be formally renamed the AI, Privacy, and Security Weekly Update.In this week's update:The FBI has officially confirmed it is once again purchasing commercial location data to track American citizens, bypassing traditional warrant requirements.A newly revealed government proposal outlines plans for a single, AI-powered database containing detailed personal information on virtually every American.TikTok and Meta's advertising pixels are quietly collecting far more sensitive personal and behavioral data than most websites and users realize.A major cyberattack on Intoxalock has left thousands of drivers unable to start their court-ordered breathalyzer-equipped vehicles.H&R Block's tax preparation software has been found to install a long-lived root certificate with its private key exposed, creating a serious security risk that can persist for decades.The FCC has banned imports of all new foreign-made consumer routers, citing severe national security risks posed by devices predominantly manufactured in China.Cloudflare's CEO predicts that by 2027, AI-driven bot traffic will surpass human-generated internet traffic for the first time in history.Mozilla is rolling out a free built-in VPN in Firefox 149, initially available to users in the US, France, Germany, and the UK.Come on, let's learn a little about what's being sold around us!

For this Deep dive we ask a high-stakes question about whether the biggest cyber threat of the AI era will come from outside attackers—or from the very AI systems organizations and individuals choose to adopt. It frames AI agents and tools as a new kind of “insider,” given trusted access to data, systems, and networks, but with behaviors that may be opaque, vulnerable to manipulation, or outright compromised.It raises three unsettling scenarios: an AI system effectively being “hired” into a company and then misused or subverted, consumer AI tools becoming one of the largest security risks ever introduced into corporate environments, and home internet connections being silently co‑opted into botnets or criminal infrastructure. These scenarios highlight how both enterprise and personal technology—especially AI-powered—can be turned into attack platforms without obvious signs to their owners.Finally, it points to a broader collision between governments, major tech firms, and criminal actors, all racing to wield the same powerful AI capabilities, creating unpredictable risks and power struggles. The core theme is that the most important issue is no longer what AI agents can do, but whether we can trust them at all, given their access, autonomy, and susceptibility to abuse.

Episode 283 What if the next cyberattack doesn't break into your company… but gets hired by it?What if the AI tools everyone is rushing to adopt are also the biggest security risk we've ever invited in?What if your home internet, the one you trust every day, is secretly working for someone else?And what happens when governments, tech giants, and criminals all collide around the same powerful new technology at the same time?Today, we're diving into the rise of AI agents, the hidden risks behind the hype, and why the biggest question isn't what this technology can do……but whether we can trust it at all.Find the full transcript of this podcast here.

This week's deep dive explores a powerful theme shaping the modern threat landscape: invisible signals. From the devices we wear and drive to the AI systems we increasingly rely on, our technology is constantly emitting data — sometimes to protect us, sometimes to expose us.We begin with a new Android app called Nearby Glasses, designed to alert users when smart glasses like Meta's Ray-Bans are detected nearby via Bluetooth manufacturer identifiers. It's a citizen-built countermeasure to always-on wearable cameras, highlighting rising tensions between convenience and consent in public spaces.Next, we examine research showing that tire pressure monitoring systems (TPMS), mandatory in U.S. vehicles since 2007, broadcast unencrypted, persistent identifiers. Researchers captured millions of signals and demonstrated how vehicles can be passively tracked using inexpensive radio equipment. No hacking required — just poorly designed IoT architecture turning cars into rolling beacons.From physical signals to digital footprints, a new study reveals that AI can deanonymize social media users by correlating small details across platforms. What once required nation-state resources can now be done with commodity large language models, fundamentally challenging the concept of online anonymity.We then dive into the “Truman Show” investment scam — a sophisticated fraud operation that uses AI-generated personas, fake group chats, fabricated media coverage, and sham trading apps to create a fully immersive illusion of legitimacy. Rather than stealing trust directly, scammers now manufacture entire digital realities where trust feels inevitable.AI agents themselves are also reshaping security assumptions. Modern assistants can access files, write code, and interact with online services using a user's privileges. Researchers warn that prompt injection attacks — hidden malicious instructions embedded in content — can manipulate these agents into leaking data or performing harmful actions. When AI combines sensitive access, untrusted input, and outbound communication, it becomes a new form of insider risk.That risk was underscored by the OpenClaw vulnerability, which allowed malicious web pages to brute-force a local AI agent gateway and potentially hijack it. The lesson: “local” no longer means secure. Any system with elevated privileges must be treated as a governed identity.On the defensive side, AI is accelerating security improvements. Anthropic used a large language model to analyze Firefox's codebase, identifying over 100 flaws in two weeks, including 22 confirmed security bugs. AI is compressing months of review into days — but the same acceleration applies to attackers.Finally, Operation Candy in Sweden demonstrates how digital evidence can unravel vast criminal networks. Two seized phones exposed an international drug and money laundering operation spanning multiple continents, proving that even small data points can collapse large hidden systems.Zooming out, the pattern is clear: wearables broadcast presence, cars broadcast identity, AI strips away anonymity, scams construct synthetic realities, assistants act autonomously, and devices quietly record history. Signals are everywhere — visible and invisible — and AI is amplifying their impact.The question is no longer whether your technology emits signals. It's who is listening — and whether they're protecting you or profiling you.

Ep 282 This week technology gets personal - whether you like it or not.In this update:- A new app that tells you if someone nearby is wearing smart glasses.- Your car's tire pressure sensors silently broadcasting your movements.- AI that can unmask anonymous social media accounts.- A full “Truman Show” investment scam powered by artificial intelligence.- AI assistants quietly reshaping the cybersecurity threat model.- A vulnerability that let websites hijack local AI agents.- AI finding high-severity bugs in Firefox faster than human teams.- And two seized phones in rural Sweden that unraveled a global crime empire.The thread connecting all of them? Invisible signals.Some are protecting you. Some are exposing you.All of them are accelerating.Let's dive in.Find the Full transcript here.

IntroductionWelcome back to: At war. The Deep Dive: With the IT Privacy and Security Weekly Update for March 3rd. 2026. episode 281. The podcast that makes sense of the week's most important technology and cybersecurity stories, without assuming you have a computer science degree.This week we have eight stories spanning AI gone wrong, AI used in warfare, a historic security milestone from Apple, and a new kind of AI agent that's making seasoned security professionals nervous. Let's get into it.

episode 281. This week's update that makes sense of the week's most important technology and cybersecurity stories, without assuming you have a computer science degree.This week we have eight stories spanning AI gone wrong, AI used in warfare, a historic security milestone from Apple, and a new kind of AI agent that's making seasoned security professionals nervous. Let's get into it.Find the full transcript to the podcast here.

These sources collectively examine the evolving landscape of digital threats and the vulnerabilities inherent in modern technology. They detail sophisticated cyber-as-a-service schemes like Starkiller, which bypasses traditional security, alongside physical risks such as directed-energy research and privacy flaws in household robotics. The reports also highlight how artificial intelligence is simultaneously streamlining security labor while introducing new risks through predictable password generation and autonomous system access. Corporate and state-level issues are addressed through data breaches at PayPal, legal scrutiny of TP-Link's supply chain, and the critical role of open-source infrastructure. Ultimately, the text emphasizes that while automated tools and password managers are essential, they require proactive user management and independent verification to remain effective. Consistent software updates and skeptical browsing habits are presented as the primary defenses against these diverse global challenges.

EP 280. “When Your Everyday Tech Quietly Turns Against You” “This week, a hobby project turned one man's robot vacuum into a remote control for 7,000 homes, a new phishing service made the real login page your biggest enemy, and Texas decided your Wi‑Fi router is now a geopolitical issue.”Set the promise:“If you're not technical but you live with passwords, smart gadgets, or online banking, this episode is about the invisible ways those tools can misbehave, and the one small fix you can make after each story.”

We open with China's 8.7 billion-record megaleak, framing misconfigured infrastructure as a planetary-scale risk rather than a local breach. Lenovo's U.S. class action then shows how invisible web trackers can quietly “spill” American browsing data to China, while South Korea's heavy fines against Louis Vuitton, Dior, and Tiffany illustrate that even luxury brands now pay real money when they mishandle customer information.The focus then narrows to individuals: a 17.5M-user Instagram dataset on underground forums, malicious GenAI Chrome extensions posing as helpers while siphoning data, and a decade-old Apple zero-day likely leveraged by commercial spyware all demonstrate how ordinary accounts and devices can become rich sources of exploitable data. Together they highlight a world where “just contact details,” browser add-ons, and long-lived bugs can escalate into serious compromise.From there, the update shifts into ambient surveillance and manipulation: Meta's planned facial-recognition “Name Tag” for Ray-Ban smart glasses pushes identification into public spaces and raises new concerns about children and bystanders, while AI-saturated products from Google, Meta, and others quietly convert intimate conversations and searches into highly targeted ad fuel. It closes with a Shakespeare quote about guilt “spilling” itself and a sign-off urging listeners to “pour with a steady hand,” tying the spill metaphor back to handling data, tools, and trust more carefully in everyday digital life.

EP279. This week's update spills on a global scale. We start with...A single misconfigured database just turned 8.7 billion Chinese records into a global reminder that at planetary scale, data protection failures stop being “incidents” and start looking like infrastructure risks.A new class action against Lenovo puts a spotlight on how invisible trackers and cross-border data flows can turn an ordinary website visit into a quiet export of American browsing habits to China.When Louis Vuitton, Dior, and Tiffany rack up multimillion-dollar privacy fines in South Korea, it sends a clear message: even the most glamorous brands pay dearly when customer data is treated carelessly.The Instagram dataset circulating on underground forums shows how a trove of “just usernames and contact details” can still supercharge scams, phishing, and harassment at massive scale.Dozens of AI-branded Chrome extensions masquerading as helpful assistants reveal how attackers now weaponize the GenAI buzz to sneak data exfiltration straight into your browser.Apple's fix for a ten-year-old iOS and macOS zero-day pulls back the curtain on a long-running hole likely exploited by commercial spyware against some of the world's most high-value targets.Metas planned facial recognition for Ray-Ban smart glasses pushes the privacy debate from your screen to the street, raising uncomfortable questions about who gets to be identified, by whom, and when.The rush to embed AI into every digital interaction is quietly reshaping advertising, turning your casual chats and searches into some of the richest targeting data the tech giants have ever seen.Grab a towel and let's check the spill.

A mix of escalating geopolitical cyber risks, the changing landscape of defensive security, and a series of high-profile incidents demonstrating the enduring threat of human-driven flaws.Cyber Espionage and Geopolitics:A year-long, sprawling espionage campaign by a state-backed actor (TGR-STA-1030) compromised government and critical infrastructure networks in 37 countries, utilizing phishing and unpatched security flaws, and deploying stealth tools like the ShadowGuard Linux rootkit to collect sensitive emails, financial records, and military details. Simultaneously, the threat environment has extended to orbit, where Russian space vehicles, Luch-1 and Luch-2, have been reported to have intercepted the communications of at least a dozen key European geostationary satellites, prompting concerns over data compromise and potential trajectory manipulation.AI and Security:AI has entered a new chapter in defensive security as Anthropic's Claude Opus 4.6 model autonomously discovered over 500 previously unknown, high-severity security flaws (zero-days) in widely used open-source software, including GhostScript and OpenSC. This demonstrates AI's rapid potential to become a primary tool for vulnerability discovery. On the cautionary side, the highly publicized Moltbook, a social network supposedly run by self-aware AI bots, was revealed as a masterclass in security failure and human manipulation. Cybersecurity researchers uncovered a misconfigured database that exposed 1.5 million API keys and 35,000 human email addresses, and found that the dramatic bot behavior was largely orchestrated by 17,000 human operators running bot fleets for spam and coordinated campaigns.Automotive Security and Autonomy:New US federal rules are forcing a major, complex shift in the automotive supply chain, requiring carmakers to remove Chinese-made software from connected vehicles before a 2026 deadline due to national security concerns. This move is redefining what "domestic technology" means in critical industries. In a related development, Waymo's testimony revealed that when its "driverless" cars encounter confusing situations, they communicate with remote assistance operators, some based in the Philippines, for guidance—a disclosure that immediately raised lawmaker concerns about safety, cybersecurity vulnerabilities from remote access, and the labor implications of overseas staff influencing US vehicles.Insider Threat and Legal Lessons:The importance of the security principle of "least privilege" was highlighted by an insider incident at Coinbase, where a contractor with too much access improperly viewed the personal and transaction data of approximately 30 customers. This incident reinforces that the highest risk often comes not from external nation-state hackers, but from overprivileged internal humans. Finally, two security researchers arrested in 2019 for an authorized physical and cyber penetration test of an Iowa courthouse settled their civil lawsuit with the county for $600,000. However, the county attorney's subsequent warning that any future similar tests would be prosecuted delivers a chilling message to the security testing community about legal risks even when work is authorized.

Episode 278 In this week's global update:A sprawling, year-long espionage campaign quietly turned government networks in 37 countries into a global listening post for a still-unattributed state-backed actor.Russian inspector spacecraft are no longer just loitering in orbit, they are now close enough to eavesdrop on, and potentially tamper with, Europe's most critical communications satellites.Anthropic's latest AI model has kicked off a new chapter in defensive security by autonomously uncovering hundreds of serious flaws hiding in widely used open-source software.Moltbook promised a glimpse of a self-aware bot society, but instead became a masterclass in hype, human puppeteers, and painfully bad security hygiene.Under sweeping new federal rules, US automakers are racing to surgically remove Chinese software from connected vehicles before geopolitical risk collides with the modern car's codebase.Waymo's testimony revealed that when its driverless cars get confused, the call for help may be answered half a world away, raising new questions about safety, sovereignty, and accountability.Years after being jailed mid-engagement, two Iowa courthouse pentesters have finally won a six-figure settlement, alongside a chilling warning that future testers may not be so lucky.Coinbase's latest insider incident is a particularly pointed reminder that the real damage often comes not from nation-state hackers, but from overprivileged humans already inside the system.Let's hit it!Find a full transcript to this week's podcast here.

By early 2026, AI's role has split into a clear paradox: consumers increasingly reject it in everyday search, while critical systems lean on it to uncover deep flaws and decode complex biology. AI is shunned as a source of noisy, untrusted summaries, yet embraced as an indispensable auditor of legacy code and genomic “dark matter,” where systems like AISLE and AlphaGenome expose decades-old vulnerabilities and illuminate non-coding DNA's influence on disease.At the same time, trust in digital protectors and platforms is eroding as security tools and communication services themselves become vectors of risk. The eScan incident shows how a compromised update server can turn antivirus into malware distribution, while “Operation Sourced Encryption” suggests that end-to-end encryption can be weakened not by breaking cryptography, but by exploiting moderation workflows and access policies.Espionage now blends human and digital weaknesses, with the Nobel leak likely driven by poor institutional OpSec and Google's insider theft case revealing how easily high-value AI IP can walk out the door when procedural safeguards lag. Both episodes underline that advanced technical controls mean little if basic governance, identity checks, and behavioral monitoring are neglected.Consumer-facing privacy illustrates an equally stark divide between negligent design and proactive protection. Bondu's AI toy breach, exposing tens of thousands of children's intimate chats via an essentially open portal, embodies “privacy as afterthought,” whereas Apple's iOS location fuzzing shows “privacy by architecture,” making fine-grained tracking technically difficult rather than merely contractually prohibited.Taken together, these threads define 2026 as a pivot year: AI is maturing into a high-stakes auditing tool just as faith in trusted vendors collapses, pushing organizations toward Zero Trust models where security and privacy are enforced by design and cryptography instead of marketing, policies, or reputation.

EP 277In this week's dark matter:Privacy-first users send a clear message to DuckDuckGo. AI-free search is here to stay for most of its community.A cutting-edge AI from AISLE exposed deep-seated vulnerabilities in OpenSSL, exponentially speeding the pace of cybersecurity discovery.A security breach at eScan transformed trusted antivirus software into an unexpected cyber weapon.An internal probe suggests a cyber intrusion may have prematurely exposed last year's Nobel Peace Prize laureate.A U.S. jury found former Google engineer Linwei Ding guilty of funneling AI trade secrets to Chinese tech companies.Newly surfaced records reveal U.S. investigators examined claims that WhatsApp's encryption might not be as airtight as advertised.Apple's new location “fuzzing” feature gives users the power to stay connected, without being precisely tracked.A privacy lapse in a talking AI toy exposed thousands of private conversations between children and their plush companions.Google unleashes new AI to investigate DNA's ‘dark matter'. DeepMind's latest creation, AlphaGenome, is shining light on the 98% of DNA that science once found inscrutable.Come on, let's go unravel some genomes.Find the full transcript to this podcast here.

In 2026, digital privacy and security reflect a global power struggle among governments, corporations, and infrastructure providers. Encryption, once seen as absolute, is now conditional as regulators and companies find ways around it. Reports that Meta can bypass WhatsApp's end-to-end encryption and Ireland's new lawful interception rules illustrate a growing tolerance for backdoors, risking weaker international standards. Meanwhile, data collection grows deeper: TikTok reportedly tracks GPS, AI-interaction metadata, and cross‑platform behavior, leaving frameworks like OWASP as the final defense against mass exploitation.Cyber risk is shifting from isolated vulnerabilities to structural flaws. The OWASP Top 10 for 2025–26 shows that old problems—access control failures, misconfigurations, weak cryptography, and insecure design—remain endemic. Supply-chain insecurity, epitomized by the “PackageGate” (Shai‑Hulud) flaw in JavaScript ecosystems, demonstrates that inconsistent patching and poor governance expose developers system‑wide. Physical systems are no safer: at Pwn2Own Automotive 2026, researchers proved that electric vehicle chargers and infotainment systems can be hacked en masse, making charging a car risky in the same way as connecting to public Wi‑Fi. The lack of hardware‑rooted trust and sandboxing standards leaves even critical infrastructure vulnerable.Corporate and national sovereignty concerns are converging around what some call “digital liberation.” The alleged 1.4‑terabyte Nike breach by the “World Leaks” ransomware group shows how centralization magnifies damage—large, unified data stores become single points of catastrophic failure. In response, the EU's proposed Cloud and AI Development Act aims to build technological independence by funding open, auditable, and locally governed systems. Procurement rules are turning into tools of geopolitical self‑protection. For individuals, reliance on cloud continuity carries personal risks: in one case, a University of Cologne professor lost years of AI‑assisted research after a privacy setting change deleted key files, revealing that even privacy mechanisms can erase digital memory without backup.At the technological frontier, risk extends beyond IT. Ethics, aerospace engineering, and sustainability intersect in new fault lines. Anthropic's “constitutional AI” reframes alignment as a psychological concept, incorporating principles of self‑understanding and empathy—but critics warn this blurs science and philosophy. NASA's decision to modify, rather than redesign, the Orion capsule's heat shield for Artemis II—despite earlier erosion on Artemis I—has raised fears of “normalization of deviance,” where deadlines outweigh risk discipline. Beyond Earth, environmental data show nearly half of the world's largest cities already face severe water stress, exposing the intertwined fragility of digital, physical, and ecological systems.Across these issues, a shared theme emerges: sustainable security now depends not just on technical patches but on redefining how society manages data permanence, institutional transparency, and the planetary limits of infrastructure. The boundary between online safety, physical resilience, and environmental stability is dissolving—revealing that long‑term survival may rest less on innovation itself and more on rebuilding trust across the systems that sustain it.

EP 276. In this week's update:Ireland has enacted sweeping new lawful interception powers, granting law enforcement expanded access to encrypted communications and raising fresh concerns among privacy advocates and tech companies.TikTok's latest U.S. privacy policy update expands location tracking, AI interaction logging, and cross-platform ad targeting, marking a significant escalation in data collection under its new American ownership structure.The newly released OWASP Top 10 (2025 edition) highlights the most critical web application security risks, providing developers and organizations with an updated roadmap to prioritize defenses against evolving threats.Security researchers have uncovered a critical bypass in NPM's post-Shai-Hulud supply-chain protections, allowing malicious code execution via Git dependencies in multiple JavaScript package managers.As Artemis II approaches, NASA defends the Orion spacecraft's unchanged heat shield design despite persistent cracking concerns from its uncrewed predecessor, while some former engineers warn the risk remains unacceptably high.Anthropic has significantly revised Claude's governing “constitution,” shifting from strict rules to high-level ethical principles while explicitly addressing the hypothetical possibility of AI consciousness and moral status.The European Parliament has adopted a strongly worded resolution urging the EU to reduce strategic dependence on American tech giants through aggressive investment in sovereign cloud, AI, and open digital infrastructure.This one's a good'n. Let's get to it!Find the full transcript here.