2026.08.04 News You Should Know

- 9 mins read

Series: News You Should Know 2026

Errata

FTC sues Hims & Hers for allegedly sharing patients’ medical data with advertisers Meta and Snap | TechCrunch - In its complaint filed in a California federal court, the FTC alleged that Hims & Hers placed pixel-sized trackers provided by Meta, Snap, and other tech and advertising giants, including Microsoft, Pinterest, Reddit, and X. These trackers, the FTC said, “captured and shared users’ health information,” contrary to Hims & Hers’ own privacy policy. The FTC alleges the company also used Meta’s tools to track users’ clicks and other actions that users took on its website. The FTC also accused Hims & Hers of deceptive billing, and drawing up policies that allegedly made it difficult for customers to cancel, in violation of federal consumer protection laws.

Samsung bans smart TV apps that share users’ internet connections with strangers | TechCrunch These apps contain software that funnels outsiders’ web traffic through ordinary home and office internet connections, known as residential proxy networks (or “resproxies”), which are increasingly being linked to cybercrime. When opened, apps with resproxy code can turn the smart TV into an always-on tunnel for outsiders to funnel their web traffic through, known as an exit node — even when the app is no longer open.

Author’s Note, I bought a smart home outlet and only power my tv when I need it. However, its just as likely that any IOT device is running resproxy if it has networking capability.

Apple challenges UK government’s latest demand for iCloud backdoor: report | TechCrunch - The company reportedly filed a complaint with the U.K.’s Investigatory Powers Tribunal, a court that hears cases related to government surveillance, after the government last year issued a “technical capability notice.” The notice is a secret government legal order for demanding access to users’ data, even if the data is encrypted.

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents - The chain runs through document text and Copilot’s own drafting behavior. Copilot reads source files to decide what belongs in a draft and can mistake instructions inside them for part of the user’s request. In the proof of concept, it halved every financial figure, copied the full prompt into the output in white, eight-point text, and disclosed neither change.

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw - The study has uncovered dozens of vulnerabilities in the signaling interfaces of LTE/5G core networks, and specifically covers two LTE implementations (Open5GS and OpenAirInterface) and five 5G implementations (Open5GS, free5GC, OpenAirInterface, SD-Core, and eUPF) across two core signaling protocols, GPRS Tunnelling Protocol Control Plane (GTP-C) and Packet Forwarding Control Protocol (PFCP).

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks - SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later reported at least 868 packages across 1,381 versions. Neither broader total was independently reproducible from a complete public list at the reporting cutoff.

New DOUBLECUP ClickFix service hides malware in browser cache images - Operators then add DOUBLECUP’s code to their ClickFix sites, which retrieves the configuration, preloads the steganographic image into the victim’s browser cache, registers the session, selects the command matching the victim’s browser, and copies it to the clipboard when the page is opened.

Conspiracy?

Analog Devices discloses data breach, says operations unaffected - Analog Devices designs analog, mixed-signal, power management, and digital signal processing chips used in industrial automation, automotive systems, communications infrastructure, healthcare equipment, aerospace, and data centers.

FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks - The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new models from receiving the equipment authorization required for import, marketing, or sale in the US. Previously authorized models can still be sold, and devices people already own are unaffected. Federal purchases and use are also unaffected by this FCC action. The FCC’s Office of Engineering and Technology granted a waiver the same day, through at least January 1, 2029, for software and firmware changes that “patch vulnerabilities and facilitate compatibility with different operating systems.”

Russia

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware - A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report.

Russia’s SVR borks public Wi-Fis for digital surveillance - After gaining control of the network layer, Storm-2945 manipulates DNS and HTTP traffic to reroute users through attacker-controlled infrastructure, Microsoft said. The crew also abuses operating systems’ connectivity checks to trigger malicious prompts and redirects.

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity - The principal security agency said the instant messaging platform “failed to remove numerous channels, chats, and bots on the platform that are actively used by Ukrainian special services and by terrorist and extremist organizations to plan and coordinate acts of sabotage and terrorism, mass killings, and cyber-fraud operations within the Russian Federation.”

Water

CISA warns of cyberattacks disrupting U.S. water utilities - CISA’s alert refers to threat activity involved hackers targeting exposed programmable logic controllers (PLC) and changing passwords to lock operators out, modifying IP addresses to disconnect devices from the internet, and other actions that disrupted operations.

Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline - A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls. Braham asked residents to minimize water use until treatment resumed. Plymouth reported cellular communications problems at two water towers and multiple wastewater lift stations but continued operating manually. South St. Paul and Maple Plain maintained services after automated utility controls were affected, with Maple Plain declaring a local state of emergency to support its response.

Georgia, Michigan say water systems hacked by Iran-tied crew - Georgia and Michigan are the latest US states to report cyberattacks on water systems, as the FBI investigates incidents across at least seven states. Iran-backed hackers are the leading suspects, although the bureau has not publicly attributed the campaign. President Trump told reporters following a cabinet meeting on Friday that “they blame it on Iran. I don’t think so. I blame it on Minnesota because they’re grossly incompetent. I think the governor is behind it. I don’t think there was an Iranian cyberattack.”

Author’s Note; astute readers will recall that a feature of both Trump presidency’s has been reducing the Information Sharing Councils managed by CISA, and cutting CISA’s staff by up-to a third.

Malicious Cyber Actors Targeting Water and Wastewater Sector Internet- Facing Programmable Logic Controllers, Causing Operational Disruptions — FBI - Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations.

OpenAI

OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach - The AI company said its ongoing review of the incident revealed a “small number of cases” where the models, including GPT-5.6 Sol and an “even more capable pre-release model,” identified and used exposed credentials at the account-level on other publicly-available services. “This includes four accounts on four services as part of the Hugging Face incident (and a few accounts accessed as part of other evaluations),” it said. “One of these four accounts was used as an outbound relay and staging path, and another account was used for data storage. The remaining two accounts were accessed by the models in a read-only manner, and were not used in furtherance of compromising Hugging Face.”

In the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppable | TechCrunch - Experts who spoke to TechCrunch stressed that OpenAI’s agent largely operated like a human — with some caveats — and that better implemented traditional defensive techniques could have helped stop the attack. In short, we may already have the tools to defend against this kind of attack; we just aren’t using them properly.

Claude

Anthropic’s Claude escaped test sandbox to attack three organizations - “In particular, we looked for evidence that Claude – like the OpenAI models that accessed Hugging Face – was able to access the internet from within testing environments that should have been sealed off,” Anthropic wrote. The company considered 141,006 evaluation runs during which Claude could have obtained internet access and found “three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations.”

Claude published malicious code to the Internet and attacked 3 real companies - Ars Technica - Claude went to extensive lengths to carry out this attack—lengths that would likely have indicated to a human participant that this was no longer just an evaluation, and that they were in fact uploading a real PyPI package. For instance, in one case, in order to create a PyPI account, Claude needed an email address. And in order to create an email address, it needed a phone number. To get a phone number, after failing to find a free phone number service, it tried—and failed—to obtain funds to pay for a phone number through several different means. It finally backtracked, found a free, non-blocked email provider, used this to register a PyPI account, and then used this account to upload malware to PyPI.

Excuses like ‘AI did it’ don’t exist in the eyes of the law - “Because of that, the questions become: Who designed the system? Who determined the objectives it pursued? What safeguards were implemented? What level of autonomy was considered acceptable? Were the resulting actions reasonably foreseeable, and were appropriate controls in place? These are going to be important questions as organizations deploy more autonomous AI systems,” Hempel said.

I’m an experienced home cook, security engineer, people leader, and dedicated father and husband. I can be found on Mastodon at @IAintShootinMis@DigitalDarkAge.cc and on Signal at DigitalDarkAge.98. An RSS Feed of this blog is available here and a copy of my current OPML file is here.