Narrators read our favorite written stories. You can listen to them anywhere, including on your smart speaker. Play for audio versions of WIRED's Security stories, featuring the latest on cybersecurity, hacking, privacy, national security, and keeping yourself safe online.
Signs suggest the culprits worked within a notorious Chinese hacker group that may have also hacked Indian electric utilities years earlier. Read this story here. Learn more about your ad choices. Visit megaphone.fm/adchoices
A ramshackle team of American scientists scrambled to decode the Nazi cipher before the time ran out. Luckily, they had a secret weapon. Read this story here. Learn more about your ad choices. Visit megaphone.fm/adchoices
The competitions, which are held on Russian-language cybercrime forums, offer prize money of up to $80,000 for the winners. Read this story here. Learn more about your ad choices. Visit megaphone.fm/adchoices
The sabotage of more than 20 trains in Poland by apparent supporters of Russia was carried out with a simple “radio-stop” command anyone could broadcast with $30 in equipment. Read this story here. Learn more about your ad choices. Visit megaphone.fm/adchoices
Russia tightly controls its information space—making it hard to get accurate information out of the country. But open source data provides some clues about the crash. Read this story here. Learn more about your ad choices. Visit megaphone.fm/adchoices
Researchers have spent years warning that text-generation algorithms can spew bias and falsehoods. Tech giants are rushing them into products anyway. Read this story here. Learn more about your ad choices. Visit megaphone.fm/adchoices
Unlike web browsers, mobile apps increasingly make it difficult or impossible to see what companies are really doing with your data. The answer? An inspectability API. Read this story here. Learn more about your ad choices. Visit megaphone.fm/adchoices
The hackers, who mostly targeted victims in Hong Kong, also hijacked Microsoft’s trust model to make their malware harder to detect. Read this story here. Learn more about your ad choices. Visit megaphone.fm/adchoices
Pixel Binary Transparency is the latest security benefit for Pixel owners. Read this story here. Learn more about your ad choices. Visit megaphone.fm/adchoices
The wide-ranging scams, often disguised as game promotions, can all be linked back to one network. Read this story here. Learn more about your ad choices. Visit megaphone.fm/adchoices
An innovation agency within the US Department of Health and Human Services will fund research into better defenses for the US health care system’s digital infrastructure. Read this story here. Learn more about your ad choices. Visit megaphone.fm/adchoices
Security researchers set up a remote machine and recorded every move cybercriminals made—including their login details. Read this story here. Learn more about your ad choices. Visit megaphone.fm/adchoices
The macOS Background Task Manager tool is supposed to spot potentially malicious software on your machine. But at Defcon, a researcher says it has troubling flaws. Read this story here. Learn more about your ad choices. Visit megaphone.fm/adchoices
In 2008, Boston’s transit authority sued to stop MIT hackers from presenting at the Defcon hacker conference on how to get free subway rides. Today, four teens picked up where they left off. Learn more about your ad choices. Visit megaphone.fm/adchoices
The legacy electronics manufacturer is creating IoT honeypots with its products to catch real-world threats and patch vulnerabilities in-house. Read this story here. Learn more about your ad choices. Visit megaphone.fm/adchoices
The vulnerability could allow attackers to take advantage of an information leak to steal sensitive details like private messages, passwords, and encryption keys. Read this story here.
Cybercriminals are touting large language models that could help them with phishing or creating malware. But the AI chatbots could just be their own kind of scam. Read this story here.
Here’s one simple way to reduce your security risk while logging in.
Read this story here.
Flaws in the Points.com platform, which is used to manage dozens of major travel rewards programs, exposed user data—and could have let an attacker snag some extra perks.
Read the story here.
Meta has long fought Europe's demands that it get people's consent before using their data for targeted ads. Then a Norwegian regulator threatened fines of $100,000 per day.
Read this story here.
Social apps prioritize content moderation tips from governments and online watchdogs. A US court ruling and a new EU law could restrict the practice, but they still leave loopholes.
Read this story here.
Researchers found a simple way to make ChatGPT, Bard, and other chatbots misbehave, proving that AI is hard to tame.
Read this story here.
Plus: Mozilla fixes two high-severity bugs in Firefox, Citrix fixes a flaw that was used to attack a US-based critical infrastructure organization, and Oracle patches over 500 vulnerabilities.
Read this story here.
The National Security Agency has urged top lawmakers to resist demands that it obtain warrants for sensitive data sold by data brokers.
After scammers duped a friend with a hacked Twitter account and a “deal” on a MacBook, I enlisted the help of a fellow threat researcher to trace the criminals’ offline identities.
Read this story here.
A secret encryption cipher baked into radio systems used by critical infrastructure workers, police, and others around the world is finally seeing sunlight. Researchers say it isn’t pretty.
Read this story here.
German researchers gained rare access to three satellites and found that they’re years behind normal cybersecurity standards.
Read this story here.
A landmark $13 million settlement with the City of New York is the latest in a string of legal wins for protesters who were helped by a video-analysis tool that smashes the “bad apple” myth.
Read the story here.
A bill to prevent cops and spies from buying Americans' data instead of getting a warrant has a fighting chance in the US Congress as lawmakers team up against surveillance overreach.
Read this story here.
The FBI has collected sensitive data on millions of Americans without warrants, drawing intense scrutiny from Congress and turning the agency into a punching bag across the political divide.
Read this story here.
Roger Thomas Clark, also known as Variety Jones, will spend much of the rest of his life in prison for his key role in building the world’s first dark web drug market.
Ransomware attacks tumbled in 2022, offering hope that the tide was turning against the criminal gangs behind them. Then things got a whole lot worse.
Read this story here.
The popular messaging platform launched new parental controls for keeping tabs on teens. Here’s what the tools do (and don’t) include.
Read this story here.
Cities across the US have established RTCCs that police say protect the rights of innocent people, but critics warn of creeping surveillance.
Read this story here.
Meta’s Twitter alternative promises that it will work with decentralized platforms, giving you greater control of your data. You can hold the company to that—if you don't sign up.
Read this story here.
The National Defense Authorization Act now includes draft language forbidding government entities from buying Americans' search histories, location data, and more.
Read this story here.
With a poor track record on tech regulation, do lawmakers stand a chance?
Read this story here.
Plus: Microsoft fixes 78 vulnerabilities, VMWare plugs a flaw already used in attacks, and more critical updates from June.
Read this story here.
Complaints filed in the European Union claim the porn site fails to follow basic data-collection policies under GDPR.
Read this story here.
Scammers use a booking technicality, traveler confusion, and promises of dirt-cheap tickets to offer hot deals that are anything but.
Read this story here.
The gray market for abortifacient sales to the US is evolving alongside a shifting legal landscape.
Read this story here.
Newly released documents highlight the bureau's continued secrecy around cell-site simulators—spying tech that everyone already assumes exists.
Read this story here.
Vehicles from Toyota, Honda, Ford, and more can collect huge volumes of data. Here’s what the companies can access.
Read this story here.
The AI era promises a flood of disinformation, deepfakes, and hallucinated “facts.” Psychologists are only beginning to grapple with the implications.
Read this story here.
The US government warns encryption chipmaker Hualan has suspicious ties to China’s military. Yet US agencies still use one of its subsidiary’s chips, raising fears of a backdoor.
Read this story here.
A newly declassified report from the Office of the Director of National Intelligence reveals the federal government is buying troves of data about Americans.
Read this story here.
Personal information, including ID documents and phone numbers, have been released on Telegram.
Read this story here.
Internal company documents reveal how the imageboard’s chaotic moderation allowed racism and violence to take over.
Read this story here.
New testimony from defectors reveals pervasive surveillance and monitoring of limited internet connections. For millions of others, the internet simply doesn't exist.
Read this story here.
UT-Austin will join a growing movement to launch cybersecurity clinics for cities and small businesses that often fall through the cracks.
Read this story here.
Newly announced sanctions against Iran-based Avaran Cloud underscore the complexity of crafting Washington’s internet freedom efforts.
Data from Cloudflare's free digital defense service, Project Galileo, illuminates new links between online and offline attacks.
On the same day, Russia’s FSB intelligence service launched wild claims of NSA and Apple hacking thousands of Russians.
Read this story here.
Hidden code in hundreds of models of Gigabyte motherboards invisibly and insecurely downloads programs—a feature ripe for abuse, researchers say.
Read this story here.
Researchers say the state-sponsored espionage operation may also lay the groundwork for disruptive cyberattacks.
Read this story here.
Indirect prompt-injection attacks can leave people vulnerable to scams and data theft when they use the AI chatbots.
Read this story here.
The co-inventor of “bcrypt” is reflecting on the ubiquitous function’s 25 years and channeling cybersecurity’s core themes into electronic dance music.
Read this story here.
“Container registries” are ubiquitous software clearinghouses, but they've been exposed for years. Chainguard says it now has a solution.
Read this story here.
While the company’s new top-level domains could be used in phishing attacks, security researchers are divided on how big of a problem they really pose.
Read the story here.
Kaspersky researchers have uncovered clues that further illuminate the hackers’ activities, which appear to have begun far earlier than originally believed.
Read this story here.
Your inactive profiles, like Gmail or Docs, could turn into digital dust later this year. A few clicks can save them.
Read this story here.
An explosion of interest in OpenAI’s sophisticated chatbot means a proliferation of “fleeceware” apps that trick users with sneaky in-app subscriptions.
Read the story here.
The families of victims of a mass shooting in Buffalo are challenging the platforms they believe led the attacker to carry out a racist massacre.
Read this story here.
A government effort to collect people’s internet records is moving beyond its test phase, but many details remain hidden from public view.
Read this story here.
Three states are suing to block security rules for water facilities. If they win, it may open the floodgates for challenges to other cyber rules. Read this story here.
The social network's new privacy feature is technically flawed, opt-in, and limited in its functionality. All this for just $8 a month.
Read this story here.
The unidentified attackers have targeted people on both sides of Russia’s war against Ukraine, carrying out espionage operations that suggest state funding.
Read this story here.
OpenAI has new tools that give you more control over your information—although they may not go far enough.
Read this story here.
Documents obtained by WIRED show SafeGraph, which sold location data related to Planned Parenthood visits, is now pursuing contracts with the US Air Force.
Read this story here.
In May 2020, the US Department of Justice stumbled upon Russian hackers in its network. But did not realize the significance of what they had found for six months. Read the story here.
The tech industry’s transition to passkeys gets its first massive boost with the launch of the alternative login scheme for Google’s billions of users. Read the story here.
The company is adding new tools as bad actors use ChatGPT-themed lures and mask their infrastructure in an attempt to trick victims and elude defenders.
Read the story here.
Operation SpecTor likely drew on leads from multiple dark web market busts, including the secret takedown of Monopoly Market in 2021.
Read the story here.
AI tools? A porn filter, but for Top Secret documents? Just classifying less stuff? US lawmakers are full of ideas but lack a silver bullet.
Read the story here.
The legislation would insert the government into online platforms' age-verification efforts—a move that makes some US lawmakers queasy.
No matter what happens with generative AI, its disruptive forces are already beginning to play a role in the fast-approaching US presidential race.
Read the story here.
The cybercriminals behind the Gootloader malware have found clever ways to avoid detection. But researchers are using those same mechanisms to stop them.
Read the story here.
You can now sync sign-in codes across devices—but they aren’t end-to-end encrypted.
Read the story here.
To protect its Confidential Computing cloud infrastructure, Google leans on its relationships with chipmakers to gain unusual insight into hardware.
Read the story here.
The mass compromise of the VoIP firm's customers is the first confirmed incident where one software supply chain attack enabled another, researchers say.
Three criminal cases detail China's alleged attempts to extend its security forces' influence online—and around the globe.
Read the story here.
Generative AI is a tool, which means it can be used by cybercriminals, too. Here’s how to protect yourself.
Read the story here.
More than half of the enterprise routers researchers bought secondhand hadn’t been wiped, exposing sensitive info like login credentials and customer data.
Read the story here.
The discovery of malicious encryptors for Apple computers could herald new risks for macOS users if the malware continues to evolve.
Read the story here.
The bizarre release of sensitive US government materials soon after their creation signals a potential shift to near-real-time unauthorized disclosures.
Security researchers are jailbreaking large language models to get around safety rules. Things could get much worse.
Read the story here.
To beat back fake accounts, the professional social network is rolling out new tools to prove you work where you say you do and are who you say you are.
Read the article here.
Your iPhone, iPad, and Mac now have a built-in password feature, complete with two-factor authentication.
Read the article here.
Amnezia, a free virtual private network, allows users to set up their own servers, making it harder for Moscow to block this portal to the outside world.
Without an information sharing and analysis center, the country’s food and agriculture sector is uniquely vulnerable to hackers.
Read the article here.
Italy’s recent ban of Open AI’s generative text tool may just be the beginning of ChatGPT’s regulatory woes.
North Korean hackers appear to have used the corrupted VoIP software to go after just a handful of crypto firms with "surgical precision."
Mullvad Browser, a collaboration between the nonprofit and Mullvad VPN, offers an anti-tracking browser designed to be used with a VPN.
An increasing number of states and countries are passing age-verification laws. It’s not clear how they’ll work.
The White House is sending $25 million to Costa Rica, after providing Albania with similar aid following aggression by hackers linked to Iran.
Regulators are using an AI system to scan websites and messaging apps to find pornography. Creators face fines and potential prison sentences.
A spy group working for the Kim regime has been feeding stolen coins into crypto mining services in an effort to throw tracers off their trail.
The GOP-fueled far right differs from similar movements around the globe, thanks to the country’s politics, electoral system, and changing demographics.
The interrogation of CEO Shou Zi Chew highlighted US lawmakers’ own failure to pass privacy legislation.
Image-editing tools from Google and Microsoft contain the “aCropalypse” bug, which can reveal information users intentionally removed.
Amid ongoing protests, the Iranian regime has lost control of its image, pushing it to employ increasingly drastic tactics where everyone loses.
Open source intelligence researchers are verifying and debunking opaque claims about who ruptured the gas pipelines in the Baltic Sea.
Russia, North Korea, Iran, and China have been caught using fake profiles to gather information. But the platform’s tools to weed them out only go so far.
Evgenii Serebriakov now runs the most aggressive hacking team of Russia's GRU military intelligence agency. Thanks to a botched 2018 operation, he's already well-known to Western intelligence.
The threat of scammers using voice deepfakes in their cons is real, but researchers say old-school voice impersonation attacks are still the more pressing concern.
With victims refusing to pay, cybercriminal gangs are now releasing stolen photos of cancer patients and sensitive student records.
The FBI's latest Internet Crime Report highlights the stunning rise of investment-themed crimes over the past 18 months.
Representative Darin LaHood's claim that he was the subject of so-called “backdoor” searches comes at a dicey moment for the bureau.
After successful autonomous flight tests in December, the military is ramping up its plans to bring artificial intelligence to the skies.
Rather than obtaining a warrant, the bureau purchased sensitive data—a controversial practice that privacy advocates say is deeply problematic.
The Biden administration’s new strategy would shift the liability for security failures to a controversial target: the companies that caused them.
Amid isolating sanctions, a Russian tech giant plans to launch new Android phones and tablets. But experts are skeptical the company can pull it off.
Every DJI quadcopter broadcasts its operator’s position via radio—unencrypted. Now, a group of researchers has learned to decode those coordinates.
The company will soon require users to pay for a Twitter Blue subscription to get sign-in codes via SMS. Security experts are baffled.
Plus: Microsoft fixes several zero-day bugs, Google patches Chrome and Android, Mozilla rids Firefox of a full-screen vulnerability, and more.
New details reveal that Beijing-backed hackers targeted the Association of Southeast Asian Nations, adding to a string of attacks in the region.
As Russia has accelerated its cyberattacks on its neighbor, it's barraged the country with an unprecedented volume of different data-destroying programs.
Mozilla researchers found that apps often provide inaccurate data use disclosures, giving people “a false sense of security.”
And according to tracing firm Chainalysis, one very prolific scammer ran at least 264 of those scams in 2022 alone.
After 16 years, the agency has implemented the software to cryptographically verify digital passport data—and it’s already caught a dozen alleged fraudsters.
Security researchers found a class of flaws that, if exploited, would allow an attacker to access people’s messages, photos, and call history.
Twitter is disabling SMS-based two-factor authentication. Switch to these alternatives to keep your account safe.
Biden’s speech calling for better data protections got a standing ovation from both sides of the aisle. So, where’s a federal privacy law?
Members of the Trickbot and Conti cybercrime gangs have been sanctioned in an unprecedented wave of action against the country’s hackers.
Legal experts say a key law should already prevent brokers from collecting and selling data that's weaponized against vulnerable people.
The world’s most prolific crypto thieves have used Sinbad.io to launder tens of millions. Its creator, “Mehdi,” answers WIRED’s questions.
People in Europe are making GDPR requests to have their private messages erased, but Elon’s team is ignoring them.
Enigma Labs launches a project to crowdsource and quantify data about “unidentified aerial phenomena.”
Moscow promised residents lower crime rates through an expansive smart city project. Then Vladimir Putin invaded Ukraine.
Accidental revisions to a US Help Center page sparked confusion about the streamer's next moves. But restrictions on account sharing are still coming soon.
As unsecured docs pile up, a bipartisan group of lawmakers is itching to overhaul the nation’s secret secret-sharing operation.
Bad actors use artificial intelligence to propagate falsehoods and upset elections, but the same tools can be repurposed to defend the truth.
The cash-strapped company recently auctioned off USB dongles but has left some corporate computers in the custody of laid off staff.
True Anomaly, a startup backed by US senator JD Vance’s VC firm, plans to launch prototype pursuit satellites on a SpaceX flight later this year.
More than two years ago, criminals crippled the systems of London’s Hackney Council. It's still fighting to recover.
The crypto money-laundering market is tighter than at any time in the past decade, and the few big players are moving a “shocking” amount of currency.
ADS-B Exchange, beloved for resisting censorship, was sold to a company owned by private equity—and now even its biggest fans are bailing.
The escalating risks of Russia’s war in Ukraine have led scientists to study the unthinkable and model the aftermath of nuclear detonation.
The notorious Russian-speaking cybercriminals grew successful by keeping a low profile. But now they have a target on their backs.
A mandatory app exposed the personal information of students and teachers across the country for over a year.
The mobile operator just suffered at least its fifth data breach since 2018, despite promising to spend a fortune shoring up its systems.
New research from Cloudflare shows that connectivity disruptions are a problem around the globe, pointing toward a troubling new normal.
Research shows that relatively few people exist in perfectly sealed-off media bubbles—but they’re still having an outsize impact on US politics.
Some 1,700 spoofed apps, 120 targeted publishers, 12 billion false ad requests per day—Vastflux is one of the biggest ad frauds ever discovered.
Animal rights activists have captured the first hidden-camera video from inside a carbon dioxide “stunning chamber” in a US meatpacking plant.
More than 120 models of Siemens' S7-1500 PLCs contain a serious vulnerability—and no fix is on the way.
Cupertino puts privacy first in a lot of its products. But the company still gathers a bunch of your information.
Police in the Indian state of Telangana have found a novel way to help people avoid getting swindled online: grassroots education.
The exposure of hundreds of millions of email addresses puts pseudonymous users of the social network at risk.
The infamous, FSB-connected Turla group took over other hackers’ servers, exploiting their USB drive malware for targeted espionage.
Amid internet shutdowns in Iran, the encrypted messaging app is introducing proxy connections that can help people get online.
Any multifactor authentication adds protection, but a physical token is the best bet when it really counts.
When police infiltrated the EncroChat phone system in 2020, they hit an intelligence gold mine. But subsequent legal challenges have spread across Europe.
This type of devastating scheme ensnares victims and takes them for all they’re worth—and the threat is only growing.
Don’t be fooled by its fun name and Tamagotchi-like interface—this do-everything gadget is trouble waiting to happen and a whole lot more.
The Kremlin’s aggression in Ukraine is following a dangerous playbook that began to unfold years ago.
Throughout 2022, geopolitics has given rise to a new wave of politically motivated attacks with an undercurrent of state-sponsored meddling.
Elon Musk claims plane-tracking data is a risky privacy violation. But the world loses a lot if this information disappears—and that’s already happening.
The company has taken measures to mitigate the risks, but security researchers warn of a broader threat.
How do you keep Facebook easy to use without being trivial to exploit? The company is trying to chart a middle ground.
And new evidence suggests those hackers may have collaborated with the police who investigated him.
The suit claims the company lacks adequate moderation to prevent widespread hate speech that has led to violence and death.
The company, which works with hundreds of startups, said it detected unauthorized access to personal data, including Social Security numbers.
Are you thinking about uploading some selfies and buying a pack of ‘Magic Avatars’? Consider these expert tips first.
Despite mitigation, one of the worst bugs in internet history is still prevalent—and being exploited.
From QAnon influencers to @catturd, the very online right sees exactly what they want to see in the CEO’s orchestrated disclosure.
The company plans to expand its Communication Safety features, which aim to disrupt the sharing of child sexual abuse material at the source.
On cybercrime forums, user complaints about being duped may accidentally expose their real identities.
The company will also soon support the use of physical authentication keys with Apple ID, and it's adding contact verification for iMessage in 2023.
The UK's use of technology to enforce its hard-line immigration policy brings the border into every facet of migrants' lives.
Device manufacturers use “platform certificates” to verify an app's authenticity, making them particularly dangerous in the wrong hands.
The “Heliconia” hacking tool exploited vulnerabilities in Chrome, Windows Defender, and Firefox, according to company security researchers.
Popular redaction tools don’t always work as promised, and new attacks can reveal hidden information, researchers say.
Lawmakers are growing concerned about a flood of data-hungry cars from China taking over American streets.
Finding high-quality detection canines is hard enough—and the pandemic only dug a deeper hole.
Elon Musk laid off half the staff, and mass resignations seem likely. If nobody’s there to protect the fort, what’s the worst that could happen?
New research found pervasive use of tracking tech on substance-abuse-focused health care websites, potentially endangering users in a post-Roe world.
Problems with the important security feature may be some of the first signs that Elon Musk's social network is fraying at the edges.
Government officials are urging citizens to adopt the official digital currency in a bid to gain more control over the economy.
One man’s battle to reclaim his face shows regulators across the bloc are failing to reprimand the US face search engine.
Questions about the Kremlin's relationships with these groups remain. But researchers are finally getting some answers.
Security researchers see updated tactics and tools—and a tempo change—in the cyberattacks Russia’s GRU military intelligence agency is inflicting on Ukraine.
Anyone can get a blue tick on Twitter without proving who they are. And it’s already causing a ton of problems.
True the Vote’s IV3 app is meant to catch election cheaters. But it has a fundamental flaw.
Cash is safe—for now. Contactless payment methods, like Apple Pay or Google Wallet, are more of a threat to the existence of physical cards.
A year after a billion-dollar seizure of the dark web market's crypto, the same agency found a giant trove hidden under a different hacker's floorboards.
Stadiums around the world, including at the 2022 World Cup in Qatar, are subjecting spectators to invasive biometric surveillance tech.
Rust makes it impossible to introduce some of the most common security vulnerabilities. And its rise can't come soon enough.
Underwater cables keep the internet online. When they congregate in one place, things get tricky.
Authoritarian societies depend on people ratting each other out for activities that were recently legal—and it’s already happening in the US.
What's next for the social network is anyone's guess—but here's what to watch as you wade through the privacy and security morass.
Open-internet advocates are breathing a sigh of relief after a recent election for the International Telecommunications Union's top leadership.
Your anti-malware software may not work if you upgraded to the new operating system. But Apple says a fix is on the way.
The suspected Chinese influence operation had limited success. But it signals a growing threat from a new disinformation adversary.
For months, an anonymous caller has terrorized communities around the US by reporting false shooting threats. We know how they did it. The question is, why?
A series of deadly attacks using Iranian “suicide drones” shows Russia is shifting gears in the conflict.
Endless vulnerabilities. Widespread hacking campaigns. Slow and technically tough patching. It's time to say goodbye to on-premise Exchange.
Vice Society has a superpower that’s allowed it to quietly carry out attacks on schools and hospitals around the world: mediocrity.
While tensions over a possible nuclear attack on Ukraine remain high, experts say surveillance will likely catch Russia if it plans to do the unthinkable.
Google wants to make your digital life—in its ecosystem, anyway—passwordless and more secure.
Custodians of the crowdsourced encyclopedia are charged with protecting it from state-sponsored manipulators. A new study reveals how.
The company says it hardened the security of its new flagship phones—and plans to release a built-in Android VPN.
The company plans to alert 1 million Facebook users that their account credentials may have been compromised by malicious software.
A new executive order tries to reassure Europeans that their data is safe on US soil, despite government surveillance.
Former Uber security chief Joe Sullivan’s conviction is a rare criminal consequence for an executive’s handling of a hack.
People around the world are rallying to subvert Iran's internet shutdown, but actually pulling it off is proving difficult and risky.
The internet infrastructure company has an alternative tool to check whether you’re human—and it doesn’t force you to pick out buses in tiny boxes.
For decades, security researchers warned about techniques for hijacking virtualization software. Now one group has put them into practice.
Damage to the pipeline that runs between Russia and Germany is being treated as deliberate. Finding out what happened may not be straightforward.
Want to speak up against Big Tech, unjust data collection, and surveillance? Here's how to be an activist in your community and beyond.
The fun-loving cybercriminals blamed for breaches of Uber and Rockstar are exposing weaknesses in ways others aren't.
Pornhub is trialing a new automated tool that pushes CSAM-searchers to seek help for their online behavior. Will it work?
Many companies have pulled physical servers from the country as a mandate to collect customer data goes into effect.
UN countries are preparing to pick a new head of the International Telecommunications Union. Who wins could shape the open web's future.
As protests spread, authorities have shut down mobile internet service, WhatsApp, and Instagram. The consequences could be tragic.
New research shows how third-party apps could be exploited to infiltrate these sensitive workplace tools.
Security firm Chainguard has created a simple, open-source way for organizations to defend the cloud against some of the most insidious attacks.
The encrypted messaging app is a haven for politically motivated vitriol, but users are increasingly bringing threats to targets’ doorsteps.
Despite having one of the strongest data-protection policies in Africa, the country’s enforcement and disclosure practices remain dangerously broken.
An alleged teen hacker claims to have gained deep access to the company's systems, but the full picture of the breach is still coming into focus.
The American Data Privacy and Protection Act could protect people across the country. But first, it has to get past Nancy Pelosi.
Yurii Shchyhol gives WIRED a rare interview about running the country’s Derzhspetszviazok and the state of the online conflict with Russia.
Exposing wrongdoing is risky on the best of days. Whistleblower Aid cofounder John Tye explains the extensive steps needed to keep people safe.
Safety Check and Lockdown Mode give people in vulnerable situations ways to quarantine themselves from acute risks.
Samizdat Online syndicates banned news sites by hosting them on uncensored domains—allowing people to access independent reporting.
Hackers can use Microsoft’s Power Automate to push out ransomware and key loggers—if they get machine access first.
With iOS 16 and macOS Ventura, Apple is introducing passkeys—a more convenient and secure alternative to passwords.
US lawmakers keep warning about the popular app. But until they can explain what makes it uniquely dangerous, it’s difficult to tailor a resolution.
The California Age-Appropriate Design Code would launch a huge online privacy experiment. And it won’t just affect children.
Researchers found that mobile applications contain keys that could provide access to both user information and private files from unconnected apps.
The phishing attack on the SMS giant exposes the dangers of B2B companies to the entire tech ecosystem.
Without robust federal protections, the country’s widespread mass surveillance systems could be used against citizens like never before.
Police in India’s capital say they only require an 80 percent accuracy rate for matches, raising new alarm bells for civil liberty advocates.
This invasive malware isn't just for phones—it can target your PC, too. But a new batch of algorithms aims to weed out this threat.
As a graduation prank, four high school students hijacked 500 screens across six school buildings to troll their classmates and teachers.
The Veterans Affairs' VistA software has a vulnerability that could let an attacker "masquerade as a doctor," a security researcher warns.
A hacker has formulated an exploit that provides root access to two popular models of the company's farm equipment.
The popular video meeting app makes it easy to keep the software up to date—but it also introduced vulnerabilities.
The Zero Day Initiative has found a concerning uptick in security updates that fail to fix vulnerabilities.
Ten years after it was first unveiled, the powerful firmware analysis platform Ofrak is now available to anyone.
The new Pretty Good Phone Privacy service for Android hides the data linking you to your mobile device.
The Raspberry Pi-powered device can scan for phones around you. If it keeps spotting the same one, it’ll send you an alert.
It cost a researcher only $25 worth of parts to create a tool that allows custom code to run on the satellite dishes.
The fact that a search of Donald Trump's Florida home was even necessary tells us a lot.
A Tehran-linked hack of a NATO member marks a significant escalation against the backdrop of US-Iran nuclear talks.
What's it like to be responsible for a billion people's digital security? Just ask the company's Morse researchers.
Roman Sterlingov, accused of laundering $336 million, is proclaiming his innocence—and challenging a key investigative tool.
Russia has been trying to block the anonymous browser since December—with mixed results.
The next time someone wants to borrow your device to make a call or take a picture, take these steps to protect your privacy.
The DOJ vows to protect people’s ability to travel out of state for abortion care, but legal experts warn we can’t take it for granted.
Since Vladimir Putin blocked Facebook, Instagram, and Twitter in March, Russia has been pushing away from the global internet at a rapid pace.
While cybersecurity and foreign meddling remain priorities, domestic threats against election workers have risen to the top of the list.
As new details about the scope of the sabotage emerge, the perpetrators—and the reason for their vandalism—remain unknown.
A bill with bipartisan support might finally give the US a strong federal data protection law.
Despite alerting Meta months ago, Iranian women’s rights groups say tens of thousands of fake accounts continue to bombard them on Instagram.
Under increased scrutiny, certain period-tracking apps are seeing a surge of new users. Which are as safe as they claim to be?
Researchers have found a way to use the web’s basic functions to identify who visits a site—without the user detecting the hack.
Nonprofit donors had their information given to law enforcement without consent, highlighting limited data protections in the world’s largest democracy.
The pro-Russian group Killnet is targeting countries supporting Ukraine. It has declared "war" against 10 nations.
Fake sellers. Competitions. Crypto cons. There are plenty of grifts on the platform, but you don’t have to get sucked in.
Starting with iOS 16, people who are at risk of being targeted with spyware will have some much-needed help.
From cryptocurrency thefts to intrusions into telecom giants, state-backed attackers have had a field day in the year’s first half.
With abortion set to be criminalized in more than half the US, encryption has never been more important for protection—and civil disobedience.
If you use a mix of Apple, Android, and Windows gadgets, you're in luck: The security tool is now available to any Microsoft 365 subscriber.
The malware has been used to target people in Italy, Kazakhstan, and Syria, researchers at Google and Lookout have found.
Despite major progress fighting spam and scams, the roots of the problem go far deeper than your phone company’s defenses.
The privacy-focused company's new Goggles tool allows users to weed out the noise—whatever that might mean.
The House committee's televised hearings interrogate the Capitol attack with damning new evidence. Whether it's enough to prevent another attack is uncertain.
Many people reportedly died after struggling to access medical care during a brutal lockdown. The families want to make sure these deaths are counted.
In occupied Ukraine, people’s internet is being routed to Russia—and subjected to its powerful censorship and surveillance machine.
New details connect police in India to a plot to plant evidence on victims' computers that led to their arrest.
Using a custom encryption scheme based on musical notation, US musicians smuggled information into and out of the USSR.
A pair of ransomware attacks crippled parts of the country—and rewrote the rules of cybercrime.
MongoDB claims its new “Queryable Encryption” lets users search their databases while sensitive data stays encrypted. Oh, and its cryptography is open source.
Apps collect sensitive data that could be subpoenaed by law enforcement or sold by data brokers, putting women seeking abortions at risk.
Dozens of accounts shared videos that racked up millions of views before the platform took action.
Five years after it was torn offline, the resurrected dark web marketplace is clawing its way back to the top of the online underworld.
The company continues to downplay the severity of the Follina vulnerability, which remains present in all supported versions of Windows.
A new proposal by India's telecom regulator aims to make accurate caller ID mandatory, but critics say it may be fundamentally flawed.
As governments crack down on ransomware, cybercriminals may soon shift to business email compromise—already the world’s most profitable type of scam.
Voice recognition—and data collection—have boomed in recent years. Researchers are figuring out how to protect your privacy.
DPRK hackers are tricking their way into jobs with Western firms. A US government alert reminds employers they're on the front lines—and potentially on the hook.
Intelligence collected from public information online could be impacting traditional warfare and altering the calculus between large and small powers.
The encrypted-email company, popular with security-conscious users, has a plan to go mainstream.
A new report lays out existing US policing capabilities that can easily be repurposed to monitor pregnant people.
A newly unsealed opinion is likely the first decision from a US federal court to find that cryptocurrencies can't be used to evade sanctions.
A biotech threat intelligence group is gaining supporters as urgency mounts around an overlooked vulnerable sector.
Europe’s proposed child protection laws could undermine end-to-end encryption for billions of people.
A group of human rights lawyers and investigators has called on the Hague to bring the first-ever “cyber war crimes” charges against Russia’s most dangerous hackers.
By working together, the companies say they're better able to find security flaws in Google Cloud's Confidential Computing infrastructure.
If you don’t like marketers (or anyone else) knowing when and where you read your email, Apple’s feature will help you reclaim some privacy.
Tata Neu is the country’s latest do-everything app. When users signed up, their personal information was already there.
Maybe you don't want your phone number, email, home address, and other details out there for all the web to see. Here's how to make them vanish.
Even the head of the country's online offensive is surprised by the successes—although they’re not without controversy.
Beyond accusations of encouraging copyright infringement, film companies have begun accusing VPNs of enabling a slew of illegal activity.
A new report suggests that a small but vibrant group of smartphone hackers may be challenging the world's most digitally restrictive regime.
From “IT Army” DDoS attacks to custom malware, the country has become a target like never before.
CSAM hosting in the United States rose 64 percent last year, putting the country second in the world, a new report found.
In a twist, a massive trove of stolen bitcoins will repay the dark web market creator's $183 million restitution.
There's a simple way to limit Netflix freeloaders—give users the ability to easily boot unknown devices linked to their accounts.
A pair of reports from Mandiant and Google found a spike in exploited zero-day vulnerabilities in 2021. The question is, why?
Even as police and tech companies get better at shutting down illegal operations, cybercrime is worse than ever.
More than just group DMs, WhatsApp's new feature is a major expansion of its comprehensive encrypted messaging.
The foiled attack was the first in five years to use Sandworm's Industroyer malware, which is designed to automatically trigger power disruptions.
The malware toolkit, known as Pipedream, is perhaps the most versatile tool ever made to target critical infrastructure like power grids and oil refineries.
It’s your account—you decide who’s allowed to see your vacation photos or slide into your DMs.
Lawmakers advance proposals to let police forces across the EU link their photo databases—which include millions of pictures of people’s faces.
The proposal would stop the biggest platforms from giving themselves an advantage over the little guys. Who's afraid of a little competition?
The Biden White House is using “all of the levers of national power” to counter—or preempt—cyberattacks by Russia’s most dangerous hacker groups.
Blockchain bridges are a crucial piece of the cryptocurrency ecosystem, which makes them prime targets for attacks.
Wars often spark misinformation about the nature of blast trauma. Russia's unprovoked bombardment of Ukraine is no different.
What happens when an old satellite is no longer in use but can still broadcast? Hacker shenanigans, that's what.
Documents shed some light on how Okta and its subprocessor Sitel reacted to a breach, but they don’t explain the apparent lack of urgency.
Lapsus$ and the group behind the SolarWinds hack have utilized prompt bombing to defeat weaker MFA protections in recent months.
Europe’s Digital Markets Act requires interoperability between popular messaging apps. But experts warn encryption could be compromised.
The DOJ unsealed indictments against four alleged Russian hackers said to have targeted US energy infrastructure for nearly a decade.
A recent uptick in disruptions to open source software, including incidents aimed at objecting to Russia's war in Ukraine, have left the community on edge.
Authentication firm Okta's statements on the Lapsus$ breach fails to answer key questions.
The biggest hack since Russia’s war began knocked thousands of people offline. The spillover extends deep into Europe.
Leaked files from cybercrime group Conti show it started building a crypto payment platform, a social network—and even had plans for a casino.
Lock down your account to tweet in peace or take the guardrails off to court controversy.
Russia’s reported use of cluster munitions against Ukraine could cause devastation for decades.
Members of the hacker gang may act in Russia’s interest, but their links to the FSB and Cozy Bear hackers appear ad hoc.
A Ukrainian researcher leaked 60,000 messages from inside the Conti ransomware group. Here’s what they reveal.
After a decade of work, the FIDO Alliance says it’s found the missing piece in the bridge to a password-free future.
Vulnerabilities in animal tracking software USAHERDS and Log4j gave the notorious APT41 group a foothold in multiple government systems.
The so-called Access:7 vulnerabilities are the latest high-profile IoT security fumble.
In many parts of the world, law enforcement uses WhatsApp chats, text messages, and photos from confiscated phones as "evidence" against persecuted groups.
The besieged country's complex internet infrastructure has evolved to promote resiliency.
A wave of cyberattacks meant to make a statement and particularly buoy Ukraine could have unintended consequences.
Kytch alleges that the Golden Arches crushed its business—and left soft serve customers out in the cold.
Western intelligence services are raising alarms about Cyclops Blink, the latest tool at the notorious group’s disposal.
Cookies are on the way out—but not enough is being done about browser fingerprinting. So what is it?
From false press releases to misleading domain names, one man has allegedly gone to great lengths to sabotage his competitors.
The country has enlisted thousands of cybersecurity professionals in the war effort against Russia.
With no off-ramp in sight, Russia’s leader has put the country’s nuclear forces on alert.
Researchers at iSTARE have to think like the bad guys, finding critical flaws before processors go to production.
You get a safer, more secure browser experience, but Google gets a lot more data about you.
Anything from a metallic Rubik’s cube to an aluminum trash can inside a room could give away your private conversations.
Kremlin-backed cyber actors lurked in the networks for months, obtaining sensitive documents related to weapons and infrastructure development.
A number of accounts have been vanished as Twitter bows to pressure to make it harder for children to find adult content online.
Mozilla’s privacy-heavy browser is flatlining. What it does next is crucial for the future of the web.
The attackers exploited a known vulnerability and installed credit card skimmers on more than 500 websites.
Useful advice for anyone worried that one of Apple’s trackers is following them without consent.
Buying and selling NFTs or transferring digital currency is going to require a little leap of faith. Here’s how to get started.
A couple allegedly used a “laundry list” of technical measures to cover their tracks. It didn't matter.
As Russia continues to amass troops at the border, resistance groups have seen a surge in crypto donations.
In Ottawa, a protest against vaccine mandates has become an international sensation. American far-right personalities are behind its online rise.
When UpdateAgent emerged in late 2020, it utilized basic infiltration techniques. Its developers have since expanded it in dangerous ways.
Privacy policies didn't tell the whole story about third-party tools gathering personal information from the sites of medical and genetic-testing companies.
Ransomware and online attacks can lead to deadly real-world consequences. Governments need to raise their game in response.
Disappointed with the lack of US response to the Hermit Kingdom's attacks against US security researchers, one hacker took matters into his own hands.
Internal messages WIRED has viewed shed new light on the operators of one of the world's biggest botnets.
China’s Winter Games are overshadowed by human rights problems and overreaching state surveillance.
Google has scrapped FLoC, its controversial cookie replacement. Now it’s back with Topics—but rivals and privacy experts are still nervous.
Apple awarded a $100,500 bug bounty to the researcher who discovered the latest major vulnerability in its browser.
The politically motivated attack represents a new frontier for hacktivists—and won’t be the last of its kind.
You know those “emergency” email addresses you can use to get into your email and other accounts in case you're locked out? Make sure they're up-to-date.
Austria’s data regulator has found that the use of Google Analytics is a breach of GDPR. In the absence of a new EU-US data deal, other countries may follow.
Apple has known about the vulnerability, which also affects iPadOS 15 and Safari 15, since late November.
A data wiper posing as ransomware bears a discomfiting resemblance to the earlier wave of Russian cyberattacks that ended with NotPetya.
The flaws are now fixed, but speak to the growing concerns around interactionless attacks.
Over a dozen alleged members of the notorious ransomware group have been arrested, but the Kremlin's critics are wary of the underlying motivation.
The newest security measure is still in beta. But if you want to make use of it, here's what you need to know.
The newly disclosed campaign shows how little the company has done to curb abuses of its powerful surveillance tools.
The regime had a “banner year,” thanks to skyrocketing cryptocurrency values and a new generation of vulnerable startups.
Security experts say there's little reason for the criticism from Europe’s mobile operators and US limitations over the VPN-like iCloud tool.
Your iPhone now gives you lots of transparency into what your downloads are up to. Here's what to look out for.
The critical vulnerability is buried among endless open source code, and many cyber experts are stumped.
A beta “payments” feature now lets some users of the popular encrypted messaging app send MobileCoin around the globe.
So far, Log4Shell has resulted mostly in cryptomining and a little espionage. The really bad stuff is just around the corner.
You’ll never be able to get a clean slate—but you can significantly downsize your digital footprint.
While NSO Group gets most of the attention, the takedowns underscore how insidious the industry has become.
“Smishing" is an attempt to collect logins or other sensitive information with a malicious text message—and it's on the rise.
ForcedEntry is “one of the most technically sophisticated exploits” Project Zero security researchers have ever seen.
A referral program and partner sites have spurred the spread of invasive, AI-generated “nude” images.
A vulnerability in the Log4j logging framework has security teams scrambling to put in a fix.
The move delivers a blow to the hackers behind sophisticated attacks on government agencies, think tanks, and other organizations.
The Russia-led campaign was a wake-up call to the industry, but there's no one solution to the threat.
The attempt to block the site, which helps users mask their online activity, is the latest step in the country's efforts to control the internet.
Academics claim they can sniff out the telltale signs of troll-like behavior. But is it really as simple as monitoring cute animal postings?
The incident lays bare how hollow the surveillance company’s reassurances about the limits of its hacking tools have always been.
The platform joins Google and others in requiring stronger protections for its most vulnerable users.
Using tricks to sidestep the app store’s restrictions, malware operators pillaged passwords, keystrokes, and other data.
An attacker exploited a vulnerability in MonoX Finance's smart contract to inflate the price of its digital token and then cash out.
The cold war between a startup and a soft-serve machine manufacturer is heating up, thanks to a newly released trove of internal emails.
Hackers have targeted the country's trains, gas stations, and airline infrastructure, as cyber conflict with Israel continues to escalate.
A hacking group is targeting a broad range of organizations, taking advantage of vulnerabilities that have been patched but not yet updated.
NordicTrack customers were watching Netflix using a simple trick—until the company blocked their access.
From faked emails to a hacked voter registration database, a new indictment offers fresh details on the attempted interference.
The privacy-focused tech company's latest update promises to block invasive data collection across your whole phone.
Security researchers have found signs that the pervasive hacking and misinformation campaign comes not from Moscow but from Minsk.
The vulnerability allows an attacker with physical access to the CPU to bypass the security measures protecting some of its most sensitive data.
Visitors to pro-democracy and media sites in the region were infected with malware that could download files, steal data, and more.
The social network got huge by ignoring who you know. That's increasingly no longer the case.
By arresting one alleged hacker associated with REVil and seizing millions from another, the US has made clear that ransomware comes with a cost.
An attack attempt in 2020 proves the UAS threat is real—and not enough is being done to stop it.
The Personal Information Protection Law gives authorities the power to impose huge fines and blacklist companies. But the biggest impact may be felt outside the country.
DDoSecrets published the trove Friday afternoon. Privacy advocates say it shows how pervasive law enforcement's eye has become, and how lax its data protection can be.
Apple's cloud storage service now comes with perks—and they're designed to improve your digital privacy and security.
The group behind the reported attack is under sanctions from the US Treasury, which means a payout could come with penalties for the victim.
Advocates will once again be granted a DMCA exception to make accessible versions of texts. They argue that it's far past time to make it permanent.
Operation Dark HunTor spanned eight countries—and put the focus on sellers more than marketplaces.
Yoti’s tech may be enticing for Big Tech companies: It works out if you’re under or over 13, the age most social media platforms require to create an account.
Microsoft has rolled out its most secure operating system yet. Here's how to make the most of it.
The industry now has official guidance on design, materials, and more, but not security and privacy best practices.
Google has shed light on a spate of attacks that turned creator channels into cryptocurrency scam livestreams.
The governor warned that he would take legal action against a journalist who identified a vulnerability that exposed teachers' Social Security numbers.
APT35 may not be the most dangerous group out there, but they've got a new phishing trick.
A new report shows that channels devoted to anti-Jewish conspiracy theories are growing at an alarming rate. Why won’t the platform take action?
A federal judge ruled that the content-delivery service doesn't "contribute" to copyright infringement.
If you've finally hit your breaking point, here's how to say goodbye to Mark Zuckerberg's empire.
Whether it's about sharing your Netflix login or getting your affairs in order, here are tips for convincing your loved ones to organize and protect their accounts too.
The so-called GriftHorse campaign used clever techniques to avoid detection in Google Play for nearly a year.
The fictional superspy wields Nokia devices in No Time To Die. It’s an odd choice, but Apple's smartphones aren’t ideal, either.
A WIRED investigation has found 45 federal criminal cases that cite Google geolocation data to place suspects inside the US Capitol during the January 6 riot.
DeSnake apparently eluded the DOJ's takedown of AlphaBay. The admin talked to WIRED about his return—and the resurrection of the notorious underground marketplace.
Apple's latest software update has a bunch of new security features. Here's how to put them to use.
By removing a voting app from their app stores at the Kremlin's request, the tech giants have set a troubling new precedent.
From file backups to movie streaming, network attached storage drives offer plenty of functions and features.
Nahoft uses encryption to turn chats into a random jumble of words, and it works even when the internet doesn’t.
The hacktivist collective targeted the domain registrar Epik for providing services to clients including the Texas GOP, Parler, and 8chan.
According to new documents, officers ask people they stop for their Facebook and Twitter account details, and then feed the data into Palantir.
The cybersecurity world’s favorite catchphrase isn’t any one product or system, but a holistic approach to minimizing damage.