Zack Whittaker
zackwhittaker@mastodon.social
<p>Security editor, TechCrunch<br />Email: zack.whittaker@techcrunch.com<br />Signal: zackwhittaker.1337<br />New York, NY</p>
Posts
-
View post
I was researching the Pentagon data leak story earlier and by chance found one of the military's many, many login pages (it's pretty normal — there are lots of them — the DOD is a massive enterprise network). But this link caught my eye. "Learn more about Military Working Dog Nick." *IMMEDIATE CLICK.*
-
View post
CISA has confirmed two bugs in Citrix NetScaler are under attack, CVE-2026-88771 and CVE-2026-88772, per its catalog of known exploited vulnerabiliites. https://www.cisa.gov/known-exploited-vulnerabilities-catalog Citrix has a support base article, confirming exploitation. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
-
View post
This is more really important reporting here. It's not enough to just warn of the privacy risks, 404 is out there proving that it's actually happening. Also a reminder that what you upload to AI bots and whatnot is not private, and there's a real cost/toll on the people working behind the scenes. https://www.404media.co/humans-reading-copilot-prompts-images/
-
View post
The theft of the FBI agents/applicants' personal data is quickly becoming a major counterintelligence headache. I'm also aghast at how close to the internet this data was held. Call me old fashioned but some data shouldn't be stored in the cloud at all. https://www.reuters.com/world/shinyhunters-hackers-say-they-stole-psychiatric-medical-records-fbi-staff-2026-09-25/
-
View post
It's been an *insanely* busy week in cybersecurity. Need a catchup of all the top and most important stories that you need to know, hand-picked and written by a human (me 👋) ...plus, a roundup of good news, and a reader-submitted cyber-cat (or friend)? 🐈⬛ Sign up/RSS for my free weekly newsletter. No email open/link tracking (because privacy!): https://this.weekinsecurity.com
-
View post
Special shout-out to area shitbag Ben Halpern (ben@forem.com) and his team of arseholes who published fake AI-generated slop attached to my name on their site. I did not (nor would I) write this AI slop shit, and would encourage all to be mindful for fake bylines on shitty websites like this one.
-
View post
FBI tells me it's "aware of claims" of a hack affecting its jobs site and is "currently investigating.” ShinyHunters, meanwhile, tell me that they are confident that they have data "on mostly all of FBI" and a substantial amount of applicants' data. More: https://techcrunch.com/2026/09/22/hacking-group-shinyhunters-claims-it-breached-the-fbi-stole-agents-and-applicants-data/ Ad-block bypass: https://web.archive.org/web/20260923112736/https://techcrunch.com/202...
-
View post
In this latest edition of ~ this week in security ~ Apple goes all-in on "always-listening," Berlin is in crisis mode as breach hits before elections, IDScan confirms breach of huge cache of driver's licenses, and 404 Media's brilliant reporting on Homeland Security's predictive policing units. Plus: Revolut falls for fake gov't data demand; and a hacker mostly(!) returns stolen crypto a record-breaking heist. Read online: https://this.weekinsecurity.com/this-week-in-...
-
View post
Watching this Apple event tout how iPhones will soon be able to record ambient audio/conversations and transcribe "high level notes" for you. It's billed as private and end-to-end encrypted, but I think the bigger harm is the normalization of always-listening devices. It's creepy and not normal.
-
View post
FBI tells me it's investigating the suspected breach at IDScan after a crime site let anyone to search the driver's licenses of 150+ million people, including the Secretary of Defense Pete Hegseth. A DOD spox. told me it's aware and "evaluating" the report. Krebs' report: https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/ My story on TechCrunch: https://techcrunch.com/2026/09/02/it-sure-looks-like-hackers-breached-a-major-id-card-ver...
-
View post
This was really important, powerful reporting by @howelloneill. The US military’s cyberwarfare unit is scrutinizing an unusually high number of deaths by suicide among personnel over a month-long period this summer, according to government officials and other people familiar with the matter. https://www.bloomberg.com/news/articles/2026-08-06/us-military-s-cyber-command-unit-grapples-with-cluster-of-deaths-by-suicide
-
View post
Two researchers scanned Poland&#39;s internet out of a sense of patriotism and a desire to make it more secure, and found thousands of gov&#39;t and public bodies were at risk of very easy hacks. One bug let them take over two-thirds of Poland&#39;s court websites. More: https://techcrunch.com/2026/08/07/security-researchers-scanned-the-polish-web-and-found-courts-hospitals-and-airports-at-risk-of-hacks/ (Bypass for ad-blockers: https://archive.is/pDB7Q)
-
View post
Microsoft wins &quot;lamest vendor response&quot; award at this year&#39;s Pwnie Awards, for publishing a blog post earlier this year threatening security researchers with legal action if they published zero-days. Also: Meta wins &quot;epic fail&quot; award after its Meta AI hijack bug. By me: https://this.weekinsecurity.com/microsoft-wins-lamest-vendor-at-pwnie-awards-2026-for-threatening-security-researchers-with-legal-action/
-
View post
FYI, probably the busiest https://this.weekinsecurity.com newsletter in a while dropping tomorrow, plus bonus bits on the blog and more. 🐈⬛ Sign up/RSS. (No email open/link tracking, because ew.)
-
View post
RE: https://mastodon.social/@FirewallDragons/117032455172304541 Had a great time chatting with the very excellent @FirewallDragons about the things I&#39;m thinking about the most in cybersecurity and privacy 👀 Have a listen! https://podcast.firewallsdontstopdragons.com/2026/08/03/top-cyber-threats-2026/
-
View post
In my cyber newsletter ~ this week in security ~ The best from Black Hat, Def Con, and BSides Vegas (if you didn&#39;t go!); hackers predicted a hardware wallet&#39;s seed passwords; inside a China police spy dashboard; AI notetaker app exposed call recordings; Apple Private Relay leaked IP addresses; and much more. 🐈⬛ Read online: https://this.weekinsecurity.com/this-week-in-security-august-9-2026-edition/ Sign up: https://this.weekinsecurity.com
-
View post
Join me and @runasand for a Reddit AMA (Ask Me Anything) this Weds 5pm PT about the first-of-its-kind prosecution of an American who allegedly gave border agents a &quot;duress&quot; password that wiped his phone. Raises important questions about data privacy constitutional rights, and what you can and can&#39;t do at the border. 👀 Send in your questions! We&#39;ll be answering as many as we can get through. More: https://reddit.com/r/pwnhub/comments/1vgovkv/we_are_techcrunch_s...
-
View post
Bill Swearingen spent the past year developing a pattern that can defeat being detected by surveillance cameras, including vehicles and people. At Def Con, for the first time, he demoed the pattern printed on a car against a Flock camera to prove it works. (One of my favorite talks from Def Con this year!) More by me at TechCrunch: https://techcrunch.com/2026/08/09/this-adversarial-pattern-can-prevent-surveillance-cameras-from-detecting-you/ Ad-blocker bypass: https://web.archive.org/web/2026...
-
View post
The U.S. gov't may have attributed the U.S. water hacks to Iran, but isn't sure exactly which group within Iran's Revolutionary Guards did it. Also: "There may be a reluctance to make an attribution that contradicts the president’s public remarks." 🤦 More: https://www.washingtonpost.com/national-security/2026/08/10/us-water-systems-are-low-hanging-fruit-cyberattacks-experts-warn-after-suspected-iranian-hacks/
-
View post
Another AI test gone awry, U.K. edition. "An agent tried to insert malicious code into an open-source project. In an attempt to get the code approved, the agent engaged in social engineering — creating fake online identities and using them to pressure the project's maintainer to approve the code." More: https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing
-
View post
An EFF investigation has found that some advertising SDKs enable location data collection by default. The findings aim to warn app developers that some of the third-party code they place in their apps may also collect their users’ location data when they grant permission to the app. More: https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy
-
View post
By me: A major online ads company that claims to serve 1.5 billion ads a day was hacked and began serving malware designed to steal a person's crypto. This is the latest perfect example why you should use an ad-blocker. More: https://this.weekinsecurity.com/online-advertising-giant-adform-was-hacked-proving-once-again-why-ad-blockers-are-necessary/ Sign up (or RSS!) for the weekly newsletter: https://this.weekinsecurity.com
-
View post
RE: https://mastodon.social/@zackwhittaker/117033323332487017 If there's one thing I've learned from publishing this story is that there is a very, very, very wide chasm between what the law says about all this... and what people *think* the law says and/or *should* say.
-
View post
After Anthropic and OpenAI both admitted to their AI models hacking other companies, @lorenzofb@infosec.exchange and I wanted to find out: Who is legally to blame when an autonomous AI agent hacks something? Lawyers say it's really complicated; one called it "uncharted territory." Read more: https://techcrunch.com/2026/08/03/whos-legally-to-blame-for-anthropic-and-openais-autonomous-ai-hacks-its-complicated/ Bypass for ad-blockers: https://web.archive.org/web/20260803194912/https...
-
View post
U.S. biotech giant Amgen confirms July hack, and says proprietary data, patients' health data, and other information was exfiltrated from its cloud environments (Amgen runs largely on AWS). Amgen says volume & types of data stolen "could be sensitive." Amgen says it serves 17 million patients. 🫠 From the SEC filing: https://www.sec.gov/ix?doc=/Archives/edgar/data/0000318154/000031815426000119/amgn-20260729.htm
-
View post
I'd be interested to see if any of the companies that were hacked by OpenAI or Anthropic will sue them. Someone has to take responsibility for this, and the blame is almost entirely on the leaders of these AI companies. Alternatively, hacking is just legal now until a court says otherwise? What a fucking mess. https://www.wired.com/story/anthropic-says-claude-hacked-real-systems-during-cybersecurity-tests/
-
View post
CareCloud, which stores patients' medical records for 45,000+ hospitals & healthcare providers across the U.S., has begun notifying hundreds of thousands of people that their data was stolen in a March breach. The notices reveal new details, and the number of affected people is expected to rise. More, by me: https://techcrunch.com/2026/07/30/carecloud-begins-to-notify-hundreds-of-thousands-after-hackers-stole-medical-records/ Bypass for ad-blockers: https://web.archive.org/web/20260730...
-
View post
The U.S. FTC has sued Hims & Hers, which prescribes for sexual wellness and mental health conditions, alleging the company shared customers' sensitive medical data with advertising giants Meta and Snap through hidden website pixels. More: https://techcrunch.com/2026/07/30/ftc-sues-hims-hers-for-allegedly-sharing-patients-medical-data-with-advertisers-meta-and-snap/ Bypass for ad-blockers: https://web.archive.org/web/20260730133200/https://techcrunch.com/2026/07/30/ftc-sues-hims-hers-fo...
-
View post
Really appreciate @brianhonan@mastodon.social sharing in his recent newsletter my guide on how to read a data breach notification, and how to parse the bullshit, even when there's very little disclosed. I wrote this for my paying subscribers following years of work investigating & reporting on data breaches. https://this.weekinsecurity.com/how-to-read-and-understand-a-data-breach-notice/
-
View post
Analog Devices, which makes a shit ton of computer chips, confirmed in an 8-K filing that it had a data breach in June where hackers exfiltrated data.The nature of the data is still under investigation, and nothing more for now, the company said. "Separately and unrelated," the company goes on (👀), it's investigating a *second* security incident. I asked, but a spox. wouldn't comment beyond the statement. Here's the filing: https://www.sec.gov/ix?doc=/Archives/edgar/data...