As the controversial vehicle surveillance giant Flock Safety continues to expand, WIRED got the code for the company’s new AI policing tool and reconstructed the software to show that its capabilities go far beyond reading license plates and tracking vehicles. We also published the story this week of a Rhode Island police officer who was subjected to five internal affairs investigations in less than two years after he publicly questioned his department’s use of Flock cameras.
Following incidents of high-profile rogue activity by some of its AI agents, OpenAI said this week that it is halting model training runs and overhauling internal safety protocols. The company said that its upcoming Astra model may represent a turning point of “critical” cyber capabilities.
A reverse-lookup identification service exposed millions of photos of people’s faces in a database accessible through the open internet. Meanwhile, Meta ran advertisements for an app that promised to nudify female politicians, including one ad featuring a pornographic video that included a deepfake resembling a well-known US politician. Apple removed the app from the App Store after WIRED’s inquiry.
And WIRED spoke with Andy Yen, CEO of the privacy-focused digital services company Proton, about the privacy implications of AI and how access to encryption can continue to expand in this new technological era.
But wait, there’s more! Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.
Fraudsters Could Use “Zombified” Expired Visa Cards to Make Contactless Payments
Many people know that any active credit card represents a fraud risk the minute a card is lost, stolen, or otherwise gets out of their hands. Less expected is that an expired Visa card, too, could serve as an errant key into their bank account if it’s left unattended or discarded intact, discovered by a fraudster, and “zombified” using a new technique researchers recently revealed.
At the Usenix Cybersecurity Conference last week, researchers at the University of Massachusetts Amherst warned that fraudsters could make contactless payments using expired credit cards issued by Visa by proxying them through a man-in-the-middle app that relays the credit card’s data through a pair of phones. Due to issues in the authentication chain of contactless payments, the researchers found that whether an expired card’s transaction would be disallowed was left to cryptography implemented differently by various card issuers. Visa’s had a particular flaw allowing out-of-date cards to pass its check. (Visa didn’t respond to requests for comment from tech news outlet the Register, which reported on the research this week.)
In fact, as the researchers describe it, Visa’s essentially passed on the task of authenticating these transactions to the cardholder’s bank—and while some banks prevented the use of the zombified cards, others didn’t. The result is that fraudsters could in some cases dumpster dive for an expired card and use it to make payments from the unwitting owner’s account—particularly at point-of-sale terminals where no human is present to look askance at their phone-based proxy setup.
The lesson: When that Visa card expires, a pair of scissors can ensure it doesn’t reanimate in someone else’s hands.
Apple Sent Out an “Unprecedented” Number of Hacked-Device Warnings
Apple has long sent out notification to the owners of iPhones and other devices it’s detected may be the target of what it calls “mercenary spyware”—sophisticated, stealthy malware installed by a government or state-sponsored hacker-for-hire. Last weekend, the number of those alerts sent to potential victims spiked to an “unprecedented” number, according to TechCrunch, which spoke to security analysts who investigate potential spyware intrusions. The alerts, which were sent out to potential hacking targets in 110 countries, reached numbers of users more than 30 percent higher than previous rounds of these alerts, by the estimate of Mohammed Al-Maskati, who leads a team of security investigators at Access Now, a digital rights group that Apple refers victims to in its spyware alerts. At least one target, TechCrunch noted, was a Ukrainian soldier, who said that others in the Ukrainian military had also received the alert. Sophisticated iPhone hacking campaigns may well be on the rise: Just this year, researchers at iVerify and Google uncovered two iOS mass-hacking tools known as DarkSword and Coruna.
Ukraine Says It Hit Russian Ecommerce Giant With a Cyberattack—and Drones
In Russia’s decade-plus cyberwar against Ukraine, it has at times experimented with combined physical and digital attacks, such as triggering a hacker-induced blackout in a Ukrainian city in the midst of an air raid. Now, as Ukraine increasingly strikes back against Russia in an effort to impose cost on its invaders, it appears to have tried a similar tactic. The Ukrainian military this week claimed to have carried out a disruptive cyberattack against Russian ecommerce giant Wildberries—by some measures, the Russian equivalent of Amazon—in the midst of drone attacks that have also destroyed parts of the company’s warehouse infrastructure, according to cybersecurity news outlet The Record. While Wildberries is largely a consumer retail business, The Ukrainian Main Intelligence Directorate also claimed that it is part of Russia’s sells military logistics and played a role in financing the war in the Ukraine. The Record couldn’t confirm the exact effects of the cyberattack on Wildberries, but it notes that Russian media has reported that the company has lost nearly 13 million square feet of warehouse space to drone attacks.
US Agencies Warn of AI-Aided Hacking Targeting American Infrastructure Systems
Hackers’ exploitation software, like all software, is now rarely written one keystroke at a time. So perhaps it’s little surprise that hackers targeting US infrastructure equipment are among those using AI to automate their work. A group of US agencies including the NSA, the FBI, the Department of Energy, the Environmental Protection Agency, and the Cybersecurity and Infrastructure Security Agency warned in an advisory this week that AI-assisted exploitation software was targeting Siemens programmable logic controllers, or PLCs, devices used to digitally control physical systems. Among the industries that use the targeted devices, the advisory warns, are manufacturing, chemical, energy, water, food, and agriculture facilities. “Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools,” the advisory reads, using the term ICS to mean “industrial control systems.” This inevitable adoption of AI-coded hacking tools comes in the midst of an unprecedented campaign of likely-Iranian hacker disruptions targeting US water and wastewater facilities in dozens of utilities across seven US states.
