Normal view

Researchers found a way to hijack devices through Zoom screen sharing

12 August 2026 at 13:37

As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets’ devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim.

Researchers from the digital defense firm A Security say the bug was discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports—Windows, macOS, Linux, iOS, and Android.

“What is interesting for us and what we believe is dangerous is the democratization of these capabilities—the barrier to entry is dropping rapidly,” A Security cofounder Omer Gull told WIRED ahead of the disclosure. “Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don’t see it as a threat.”

Read full article

Comments

© Getty Images

New surveillance tech links your phone to your license plate

Imagine that you share a ride to work with the same colleague most mornings. As it passes by a license plate reader, the camera records the car, which can be linked through vehicle records to its registered owner. Beside it, another sensor detects signals broadcast by devices traveling nearby, such as your phone and your colleague’s smartwatch.

After enough trips, software may treat some of those devices as a recurring electronic signature associated with the vehicle. Weeks later, one of the same device signals appears alongside a different car connected to an investigation. The signal itself may not contain its owner’s name, but its previous association with a known vehicle gives investigators another clue they can use to work out who was carrying the device.

SignalTrace, a system marketed by the security company Leonardo, is designed to work alongside automatic license plate readers. The company says it can recognize groups of consumer devices that regularly move together, then associate them with license plate records and time-stamped locations. The pattern can then be searched even when a police investigator does not know the plate number.

Read full article

Comments

© Getty Images | Smith Collection/Gado

A researcher bought noreply.net. Companies started sending him secrets.

10 August 2026 at 14:25

Cory Solovewicz receives more unwanted emails than you. Seriously—it’s a lot more. Since December 2024, one of the domains at which the security researcher receives email has registered 401,796 messages—by his calculations that’s an average of 699.99 pings per day.

This deluge isn’t the regular flood of spam, newsletters, and unwanted deals that fill many people’s inboxes. Instead, companies and other organizations are inadvertently sending Solovewicz other people’s private information and company secrets. Over the last few years, he’s received injury reports from a city government, confirmation of people’s pizza orders, and account setup emails from a school platform. “I get service orders for people that need repairs. I get lots of test platform credentials,” says Solovewicz, a security researcher and consultant.

Solovewicz is receiving the avalanche of messages as he’s the owner of the domains noreply.us and noreply.net, which he purchased in 2020 and 2024, respectively. After originally planning to use the noreply.us domain as a catch-all email—which receives mail sent to any @ address on that domain—to filter messages and enhance his privacy, the researcher quickly noticed that other systems were sending mail to @noreply.us addresses. “I created an accidental honeypot,” Solovewicz tells WIRED. “I had no idea it was going to turn into this.”

Read full article

Comments

© Richard Drury via Getty

DeepMind’s hurricane breakthrough has surprised weather scientists

8 August 2026 at 11:05

In October 2025, a storm brewed over the Caribbean Sea. Weather models differed on its trajectory. Would it remain weak and end up in Haiti, or would it intensify and head to Jamaica? Artificial intelligence model WeatherNext, developed by Google’s DeepMind and Google Research, went with the latter. Five days before landfall, it predicted with 80 percent confidence that the storm system would hit Jamaica as a Category 5 hurricane.

Hurricane Melissa was catastrophic, causing flooding and landslides across Jamaica. But the AI model helped forecasters give an earlier warning to communities in its path, so they could better prepare.

In a paper published on Thursday in Nature, researchers show that the WeatherNext AI model can predict cyclones with unprecedented accuracy. On average, it gives forecasters a day more lead time than existing models; this means its predictions three days out are as accurate as previous models’ predictions two days out. On the ground, that extra day can mean a lot.

Read full article

Comments

© J Marshall/NASA/ESA/T. Pesquet/Alamy

ByteDance trains massive AI model in bid to rival Anthropic

ByteDance is training an AI model that could approach the size of Anthropic’s most cutting-edge Mythos system, as Chinese companies continue to narrow the gap with the top US labs.

The Chinese tech giant is at an early stage of training a model with as many as 10 trillion parameters—three times larger than Moonshot’s Kimi K3, the biggest Chinese model released to date, according to three people with knowledge of the matter.

The ByteDance model is being pre-trained—a stage that typically takes three to six months—before it is fine-tuned and released if all goes well, one of the people said. The exact model size would only be determined at a later stage.

Read full article

Comments

© Ore Huiying/Bloomberg

SpaceX spooks investors with debut earnings report

SpaceX shares dropped on Wednesday after Elon Musk’s plans for blockbuster spending to position his AI and rocket company as a data center developer spooked investors.

SpaceX surpassed analysts’ expectations in Tuesday’s debut earnings report, posting quarterly revenues of $7.8 billion, well above analysts’ estimates of $6.82 billion and up 92 percent from a year earlier. It posted a net loss of about $541 million, better than estimates of $2.12 billion.

But shares in SpaceX fell 10 percent in early trading after it reported capital expenditure of almost $16 billion on AI, double the previous quarter and well above Wall Street’s expectations. It said spending would persist at current levels for at least two more quarters.

Read full article

Comments

© Timothy A Clary/GEtty

OpenAI says Apple's trade secrets lawsuit is "aggressive and oddly personal"

OpenAI has accused Apple of waging a “careless, aggressive and oddly personal lawsuit” in a blog post rebutting the iPhone maker’s claims that the AI start-up stole top-secret information.

“We do not have, nor want, any of their trade secrets,” the ChatGPT maker wrote on Monday evening, accusing Apple of “making vague accusations” and “trying to change their narrative.”

The post marks the latest escalation in a dispute that began last month when Apple filed a lawsuit claiming OpenAI had stolen hardware designs as it planned to launch its own AI-focused consumer devices.

Read full article

Comments

© Getty Images | Vincent Feuray

Trump wants the power to stop the public from suing polluters

Reducing rampant pollution across the United States was so important that when Congress passed many environmental protection laws, including the Clean Air Act, Clean Water Act, and Safe Drinking Water Act, it didn’t want to leave enforcement only to the executive branch.

Congress specifically wrote into those laws ways for citizens to enforce them through the courts when the government does not act to address the problem. Called “citizen suit provisions,” those parts of the laws allow regular people and advocacy groups to sue companies they believe are violating the law. Citizens can also sue federal agencies that fail to enforce the laws.

Since the 1970s, those provisions have been used in over 2,000 lawsuits. In fact, a majority of environmental cases are citizen suit cases. Citizen suits have been used to halt the construction of dams to protect endangered species, end the injection of wastewater into groundwater, and secure US$14.2 million in civil penalties for illegal emissions from a petrochemical facility. In short, these cases have shaped modern environmental law.

Read full article

Comments

© Brandon Bell/Getty

Defcon's new badge is a security key you can see inside

1 August 2026 at 10:05

It’s been a longtime feature of the annual Defcon hacker conference that attendees come away not only with knowledge of new software vulnerabilities and hacking techniques but also an elaborately designed conference badge—often electronic masterpieces embedded with intricate puzzles, complex crypto challenges, hidden Easter eggs, and even the mechanical gear trains of a watch.

Each year’s badge creator endeavors to top previous designs and blow the minds of hard-to-impress hackers. But this year’s badges take a different tack. Instead of the badge designs being the star, it’s what is inside the hardware that will really stand out.

This year, Defcon asked legendary hardware hacker Andrew “bunnie” Huang to create the badges—revealed here for the first time—and they include an innovative open source chip that Huang designed and that aims to do no less than advance the state of security, transparency, and trustworthiness in computing.

Read full article

Comments

© Andrew "Bunnie" Huang

AI scammers outperform humans when it comes to building trust

The notion that scammers can use AI to sharpen their deceptions, polish their language, and lubricate their banter with victims is now a reality for anyone fighting the fraud operations that steal tens of billions of dollars a year worldwide. But can AI fully replace a human scammer, autonomously building the web of deception leading up to the fake investment that defrauds the mark? One study's experiment suggests that it can—and may even be able to carry out the majority of that long con more effectively than humans.

Researchers from four universities—Amrita Vishwa Vidyapeetham in India, Foscari University of Venice, the University of Melbourne, and Ben Gurion University of the Negev—carried out a broad study on the use and potential of generative AI chatbots in the growing scam industry centered around a form of fraud known as “pig butchering,” text-based romance scams that eventually shift to fake crypto investments that steal as much as six-figure sums from victims. In their study, the researchers pitted AI chatbots directly against humans in a simulation of the scamming process—or more specifically, the long, trust-building conversations that eventually lead up to soliciting a fake investment from the scam’s target.

They found that for the relationship-establishing stages of the scam—the stage that in real-world scams typically represents the longest part of the interactions with the victim, often stretching to months—an AI chatbot performed remarkably effectively, successfully impersonating a human and by some measures outperforming the real human “scammers” in their experiment.

Read full article

Comments

© Nansan Houn/Getty

❌