Apps Marketed to US Troops Are Shipping Chinese and Russian Code

A first-of-its-kind analysis found more than one in eight apps built for US service members carried foreign code—some from firms in nations the Pentagon designates as adversaries.

AI confidence just dropped 17 points in six months. That’s actually great news.

Presented by JumpCloudThe organizations losing confidence in AI are the ones most likely to get it right.Six months ago, 40% of IT leaders described their organizations as mature in AI deployment. Today that number is 23%. Before you read that as a set…

FAA and federal workers forced to install $1.4 million White House app containing Russian-built Elfsight code onto government-issued mobile devices
FAA and federal workers forced to install $1.4 million White House app containing Russian-built Elfsight code onto government-issued mobile devices

Official White House app faces scrutiny after researchers uncovered Russian-linked software origins, data concerns, and unanswered federal security approval questions.

Your Period Tracker Is (Probably) Spying on You

Plus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more.

Cybercriminals released 802,000 stolen accounts in one day during the World Cup group stage
Cybercriminals released 802,000 stolen accounts in one day during the World Cup group stage

More than 12 million compromised streaming accounts tied to World Cup broadcasts are circulating on the dark web, representing nearly $220 million in potential black-market sales. The findings come from HUMAN Security’s Satori Threat Intelligence team,…

Prompt Injection Attacks Are Thwarting AI Hacking Agents

“Context bombing” tricks malicious AI agents into shutting down before they can do harm.

World’s largest health organization threatens to jail or fire staff reading patient data ‘without legal justification
World’s largest health organization threatens to jail or fire staff reading patient data ‘without legal justification

NHS England warns staff that unlawful patient record access could result in dismissal, prosecution, and prison while expanding monitoring across healthcare organizations.

The Zoom hack that says, ‘Don’t record me’

If every meeting, watercooler conversation, and date gets transcribed and summarized, who’s actually reading any of it?

‘You’re giving ballistic ⁠missiles to individuals with Mythos’: JPMorgan CEO Jamie Dimon says Anthropic’s AI model poses some serious risks

Restricting Mythos to vetted organizations and keeping it out of the hands of the public seems to be the safest option for Anthropic, with JPMorgan CEO describing its risks as a “real issue.”