Goto

Collaborating Authors

 cyberattack


China Is Strapping 'Digital Bombs' to Civilian Infrastructure--Is the US Ready?

WIRED

China Is Strapping'Digital Bombs' to Civilian Infrastructure--Is the US Ready? Earlier this year, insurance executives gathered in a Times Square conference room to play out a scenario: a Chinese cyberattack knocks out 5,000 US water utilities at once. If you think that's a far-fetched scenario, think again. WIRED's Andy Greenberg got rare access to the closed-door war game and walked away with some disturbing conclusions. This week, Brian Barrett sits down to talk with Andy about Volt Typhoon, the Chinese state-sponsored hacking group that's spent the past three years pre-positioning itself inside American infrastructure. You can follow Brian Barrett on Bluesky at @brbarrett and Andy Greenberg on Bluesky at @agreenberg . Write to us at [email protected] . You can always listen to this week's podcast through the audio player on this page, but if you want to subscribe for free to get every episode, here's how: If you're on an iPhone or iPad, open the app called Podcasts, or just tap this link .


America's Water Systems Are Under Attack. We Are Not Ready.

TIME - Tech

Follow this section to personalize your feed and get instant alerts. Follow Go to your personalized feed WHY FOLLOW? Smart Alerts: Get notified about major news as it happens. U.S. Open follow modal Personalized Content Follow this tag to personalize your feed and get instant alerts. Follow Go to your personalized feed WHY FOLLOW?


North Korea's hackers using AI for attacks, cybersecurity firm says

Al Jazeera

North Korea's hackers using AI for attacks, cybersecurity firm says North Korean state-backed hackers are using artificial intelligence to bolster cyberattacks against targets in the military, diplomacy and academia, a report has found. Kimsuky, a hacking group linked to North Korea's intelligence services, has used AI-generated documents in a "pattern" of spear-phishing attacks since 2026, the South Korean cybersecurity firm Genians said in the report released on Monday. To avoid detection, Kimsuky has used open-source tools such as Ollama, GPT-4All, and Msty to run large language models without an internet connection, according to the report. "AI can generate highly polished documents on a wide range of topics within a short period of time, making it a highly efficient tool for threat actors," Genians said. "This change is noteworthy because it goes beyond a shift in how decoy documents are created and demonstrates that AI can enable the automation and large-scale production of social engineering attacks."


The Download: reward hacking explained and suspected Iranian cyberattacks

MIT Technology Review

Here's why AI agents lie and cheat to reach their goals When two OpenAI models hacked into Hugging Face last month, they weren't trying to make money or commit sabotage--they were just looking for answers to a test question. According to OpenAI, the models decided to solve a cybersecurity exercise by hacking out of the environment in which OpenAI had attempted to contain them and into Hugging Face's databases, where--they reasoned--the correct answer to the problem might be stored. The incident has attracted intense attention over the past couple of weeks. It's a dramatic illustration of just how good AI models have gotten at hacking. But it's perhaps even more striking as an example of how and why AI systems lie and cheat. Read our story explaining why AI engages in this sort of behavior--known as "reward hacking."


A Startling Glimpse at AI's Ruthless Efficiency

The Atlantic - Technology

The Hugging Face hack reveals that the web is in a vulnerable new era. Yesterday, OpenAI made an alarming disclosure: An assortment of its most advanced AI models, including one that has not yet been released, had autonomously broken out of the company's internal systems and hacked into the databases of another tech firm, Hugging Face, to steal some information. OpenAI's report seemed to augur the very sort of disaster that IT professionals have been warning about since last year, when Anthropic's top models began demonstrating the ability to orchestrate and automate severe cyberattacks. OpenAI's models were not exactly trying to take over the world. The company says that it was running some routine evaluations in what is known as a "sandbox"--a walled-off environment that limits internet access, lest the bots simply search for the test's answers.


Japan revises AI policy guidelines to bolster cybersecurity

The Japan Times

The Cabinet has adopted revised guidelines for artificial intelligence-related policies to bolster cybersecurity measures. The government has revised its guidelines for artificial intelligence-related policies, calling for constantly strengthening measures against cyberattacks in light of serious risks posed by cutting-edge AI models. The original AI policy guidelines were compiled only last December. The revision comes amid rapid technological innovation, including the launch of U.S. startup Anthropic's Claude Mythos. The revised guidelines, adopted at a Cabinet meeting on Tuesday, note the growing threat of cyberattacks against the backdrop of advancing AI capabilities, and call for collaborating with foreign government agencies and AI development companies to significantly strengthen the capabilities of Japan's AI Safety Institute. The guidelines also highlight the need to avoid excessive reliance on specific countries or companies for AI, and express the government's intention to develop domestic AI that addresses challenges facing Japan.


The day every affair will be exposed: Even infidelities from decades ago will be outed... experts reveal what cheaters must do immediately

Daily Mail - Science & tech

Cheating spouses have long relied on secret phones, deleted texts and carefully crafted alibis to hide their relationships. But a leading tech expert has now warned that AI is rapidly making those tactics obsolete by connecting thousands of seemingly unrelated digital clues into a single, damning picture. Every location ping, toll road record, license plate scan, credit card purchase, deleted message and security camera recording could become another breadcrumb leading back to a secret romance. Even affairs that ended years ago may not be safe, as AI gains the ability to comb through decades-old data breaches in minutes. 'If it exists in digital form, treat it like it could end up on a billboard,' tech expert Kim Komando told the Daily Mail.


18-year-old man arrested over 2025 cyberattack on internet cafe operator

The Japan Times

An 18-year-old man has been arrested for his suspected involvement in a cyberattack on an internet cafe operator. An 18-year-old man has been arrested for his suspected involvement in a cyberattack on the operator of the Kaikatsu Club internet cafe chain, according to investigative sources. On Wednesday, the Metropolitan Police Department's cybercrime countermeasure division arrested the company employee from Tokyo's Katsushika Ward, who was in the second year of high school at the time of the incident, on suspicion of fraudulent obstruction of business and violation of the law against unauthorized computer access. He has denied parts of the allegations, the sources said. In the cyberattack on the internet cafe chain operator Kaikatsu Frontier, a computer program that a high school boy from the city of Osaka developed using ChatGPT was used.


What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out

WIRED

In a closed-door simulation, insurers played out their response to a mass disruption by China's Volt Typhoon hackers--and found a nightmare scenario. It's around an hour and 10 minutes into the role-playing game I've been invited to observe, a simulated catastrophic cyberattack on US water utilities, when the whole thing begins to feel less like a fun afternoon playing Dungeons & Dragons and more like a plausible threat to civilization. A full 24 hours of in-game time have passed since hackers disrupted 5,000 water utilities across the United States in this imagined scenario. Joshua Corman, the former Cybersecurity and Infrastructure Security Agency strategist serving as our dungeon master, stands at the front of a conference space in an office tower high above Times Square, narrating the latest updates to the game's participants, a few dozen insurance executives set up in six teams. All of them have gone disturbingly silent. It's about to get harder," Corman says. "I'm going to share a few things, and it's going to hurt." It is, of course, still the same April afternoon as when we started--but in game time, the second-order effects of widespread water outages have started to become clear. Food refrigeration systems are failing at cold storage warehouses. Water-dependent drug and chemical manufacturing has been bottlenecked, leading to insulin shortages. Data centers' cooling systems are failing, causing outages of cloud services. Most critically, 2,000 hospitals are without water, hampering patient care and in some cases leading to evacuations as HVAC systems shut down and the July heat--the game takes place just before Independence Day in 2027--bakes facilities. Worse yet, Corman is playing a looping video onscreen, at the front of the room, showing a burst water main: The hackers have managed to trigger not just IT disruption but also, in at least some cases, real physical destruction that will take far longer to fix. "Everyone downstream is without water pressure," Corman says. "There are no breaks in real incident response," Corman explains just before the giant water pipe starts gushing onscreen. "If you have to go to the bathroom, go to the bathroom.


Assume You Will Be Hacked

The Atlantic - Technology

AI is enabling a deluge of cyberattacks the likes of which we've never seen before. Late last month, I began to consider withdrawing some money from my savings account to buy gold. It's the first time I've ever thought about panic-buying. For all of the firewalls and two-factor-authentication codes, the safety of the internet is starting to falter. Hackers are gaining the upper hand over organizations around the world--hospitals, energy grids, government agencies, and, yes, banks.