Подтвердите e-mail

Для публикаций, комментариев, реакций и сообщений подтвердите адрес.

Профиль

Zack Whittaker

Профиль Vively

Security editor, TechCrunch Signal: zackwhittaker.1337 My stories: techcrunch.com/author/zack-whittaker My newsletter/blog: this.weekinsecurity.com

U.S. biotech giant Amgen confirms July hack, and says proprietary data, patients' health data, and other information was exfiltrated from its cloud environments (Amgen runs largely on AWS). Amgen says volume & types of data stolen "could be sensitive." Amgen says it serves 17 million patients. 🫠

1123

A reader of my newsletter this.weekinsecurity.com emailed in to ask about how the use of AI chatbots and LLMs can get disclosed in court, even when used for legal defense. It raises important questions about where a user's data goes once it's submitted to an AI chatbot, and who has access to it.

When AI chatbots and LLMs get legal, check your privilegeUsing AI tools and LLMs for sensitive matters, such as for legal and medical uses, raises important questions about where that data goes and who can access it.this.weekinsecurity.com
0176

Keen to see if any of the companies that were hacked by OpenAI or Anthropic will sue them. Someone has to take responsibility for this, and the blame is almost entirely on the leaders of these AI companies. Alternatively, hacking is just legal now until a court says otherwise? What a fucking mess.

Daragh Ó Briain

Sorry: they only did reviews to see if their software had unlawfully and without authorisation accessed networks of third parties? This wasn’t a defined control *during* their “testing”? This is extreme negligence at least. cyberscoop.com/anthropic-cl...

128432

CareCloud, which stores patients' medical records for 45,000+ hospitals & healthcare providers across the U.S., has begun notifying hundreds of thousands of people that their data was stolen in a March breach. That number is expected to rise. Bypass for ad-blockers: web.archive.org/web/20260730...

CareCloud begins to notify hundreds of thousands after hackers stole medical records | TechCrunchThe health tech data giant, which handles vast amounts of patients' medical data, said hackers struck one of its protected health data stores.techcrunch.com
0144

The U.S. FTC has sued Hims & Hers, which prescribes for sexual wellness and mental health conditions, alleging the company shared customers' sensitive medical data with advertising giants Meta and Snap through hidden website pixels. Bypass for ad-blockers: web.archive.org/web/20260730...

FTC sues Hims & Hers for allegedly sharing patients' medical data with advertisers Meta and Snap | TechCrunchThe U.S. federal consumer watchdog said Hims & Hers, which prescribes for sexual wellness and mental health conditions, used website trackers to share customers' information with advertisers.techcrunch.com
2153

Really appreciate @brianhonan.bsky.social sharing in his newsletter my guide on how to read a data breach notification, and how to parse the bullshit, even when there's very little disclosed. I wrote this for my paying subscribers following years of work investigating & reporting on data breaches.

How to read and understand a data breach noticeUnderstanding the contents of a data breach notice can help you take measured, reasonable action to protect yourself and others following a cybersecurity incident.this.weekinsecurity.com
2151

Analog Devices, which makes a shit ton of computer chips, confirmed in an 8-K filing that it had a data breach in June where hackers exfiltrated data. "Separately and unrelated," the company goes on (👀), it's investigating a *second* security incident. I asked, but a spox. wouldn't comment.

12510

Over on Mastodon (I strongly recommend), @doublepulsar.com asked fellow defenders what's on their radars and how much of what they're actively dealing with is AI-related. The responses are overwhelmingly, no. ClickFix attacks and phone calls/social engineering remain among the top threats.

Kevin Beaumont (@GossiTheDog@cyberplace.social)Sense check for people working in cybersecurity in operations roles in the trenches: I’m not finding or seeing cyber incidents off the back of Generative AI still. Are you? Not ones you’ve read about...cyberplace.social
33917

In today's this.weekinsecurity.com: OpenAI admits to hacking Hugging Face, millions of cars with hidden alarms vulnerable to hacking, Iran's hacking water and energy systems, Russia's targeting nuclear scientists with an email zero-day, a healthcare hack sparks data theft fears, and much more.

this week in security — july 26 2026 editionOpenAI models hacked Hugging Face, flawed alarm exposes millions of cars to hacks, healthcare software maker breached, Russia exploiting email zero-day, residential proxy crackdown, Iran hacking water...this.weekinsecurity.com
3279

This has been a busy (and wild!) week in cybersecurity, but keeping up can be a challenge. Every Sunday, I wrap up the most pressing and important cyber news you need to know and more in my free weekly newsletter this.weekinsecurity.com so you can stay ahead. Oh, and cats. 🐈‍⬛ Sign up and find out!

~this week in security~a weekly cybersecurity newsletter by Zack Whittaker, plus articles and more.this.weekinsecurity.com
0135

Incredibly detailed reporting by @raphae.li et al at Reuters on the OpenAI hack of Hugging Face, revealing new details on how it went down and how it took a week for OpenAI to notice one of its AI models was hacking into the company, citing multiple sources.

EXCLUSIVE: Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a weekThe OpenAI agent that broke into tech firm Hugging Face went on a dayslong hacking spree that OpenAI didn't notice until well after the threat was contained and the FBI was alerted, according ​to peop...www.reuters.com
0289

New, by me: The Justice Department is prosecuting an American for allegedly providing U.S. border agents with a "duress" passcode that wiped the contents of his phone when they entered it. We've confirmed the phone was running GrapheneOS. Bypass for ad-blockers: web.archive.org/web/20260724...

US accuses American of allegedly wiping his phone using a 'duress' password during border search | TechCrunchA U.S. citizen has asked a court to throw out the government's claim that he gave over a passcode to border authorities that wiped his phone's data, opening up fresh questions about a person's constit...techcrunch.com
25981449

U.S. says Iranian hackers are upping their hacks on American water and energy providers to "cause disruptive effects within the United States." FBI, NSA & CISA say the critical infrastructure breaches are in response to the Iran war (no shit). Bypass for ad-blockers: web.archive.org/web/20260723...

US government says Iran-linked hackers are disrupting American water and energy providers | TechCrunchAn updated government advisory warns that Iranian hackers are exploiting systems used by water and energy providers.techcrunch.com
24619

Justice Department is dropping the subpoenas served on several NYT reporters seeking the identities of their sources into the Qatari-donated plane that Trump now uses. The subpoenas were an obvious attempt to squash reporting into Trump's corruption.

Inner City Press

3:11 pm Buckley: The Government is prepared unilaterally to withdraw the subpoenas at this time. If under Gonzalez we find it appropriate to seek new subpoenas, we'll come to the court. Judge: Moving forward, we would have the issues that have plagued it so far

1166
Показать ещё