Smart search ranks by meaning as well as keywords (one row per story, last 45 days).
A Georgia Cop Used Flock to Track 2 Other Cops: His Ex and Her Friend
A Georgia police officer used Flock license plate reader cameras to surveil his ex-partner and another officer after their affair ended.
Internal investigation records show a Georgia officer used the Flock license plate reader network to track the movements of a fellow police officer with whom he had an affair, along with a man whose vehicle frequently appeared near hers. The unauthorized personal use of police surveillance infrastructure surfaced through an internal affairs review. The case highlights oversight gaps around law enforcement access to mass surveillance data.
UK government seeks powers to secretly block risky tech suppliers
UK amendments to the Cyber Security and Resilience Bill would let ministers secretly ban risky tech suppliers across critical sectors.
The UK government published amendments to the Cyber Security and Resilience Bill creating 'vendor-related directions' that allow ministers to order companies in critical sectors to stop buying from a supplier, restrict its products, or remove installed equipment on national security grounds. The powers extend beyond telecoms to managed service providers, data centers, digital infrastructure and the energy, water, transport and health sectors, adapting the mechanism used to restrict Huawei in UK 5G while removing some transparency safeguards. Ministers would not have to publicly name the vendor, could withhold details on national security or commercial grounds, and could bar recipients and consultees from discussing the orders, though the government would report annually to Parliament on directions issued. The amendments will be considered at committee stage in the House of Lords in September.
Australian cops cuff alleged TeamPCP masterminds
Australian police, with FBI assistance, arrested the alleged masterminds behind the Shai-Hulud worm and related supply chain attacks.
Australian law enforcement, working with the FBI, arrested suspects alleged to be the masterminds behind the Shai-Hulud worm and other software supply chain attacks. The group is referred to as TeamPCP. The report did not specify charges, the number of suspects arrested, or affected victims.
A Secretive DHS ‘Predictive Policing’ Unit is Analyzing Americans’ Financial Habits and Pulling Them Over
404 Media reveals DHS Border Patrol's secretive Predictive Intelligence Targeting Teams (PITT) analyzing Americans' financial activity and feeding intelligence to local police for traffic stops.
404 Media identified Predictive Intelligence Targeting Teams (PITT) in the Spokane Sector (Washington) and Laredo Sector (Texas), which review law enforcement-sensitive databases including Americans' financial activity and pass intelligence to local police. In one case, a PITT analyst flagged financial patterns associated with narcotics activity, leading Montana Highway Patrol to stop a driver for an obstructed license plate and charge him with DUI and possession with intent to distribute. CBP declined to say what financial data is monitored or whether warrants are obtained; the program extends AP's earlier reporting on ALPR-based predictive policing.
More Americans oppose police license plate cameras than support them: survey
A survey finds more Americans oppose police license plate cameras than support them amid reported police abuses of surveillance cameras.
A new survey shows opposition to police license plate reader cameras now exceeds support among Americans. The backlash comes amid a wave of reported police abuses involving surveillance cameras. The findings add to public debate over police surveillance technology.
Local governments in four states dealing with cyberattacks that have shut down services
Ransomware and cyberattacks disrupted local governments in California, Oklahoma, South Dakota, Texas and Wisconsin, taking Suisun City's 911 offline.
Suisun City, California (population 30,000) shut down its IT network after malicious software hit 911 routing, police and fire dispatch; the city declared a state of emergency and the FBI is investigating. Coweta, Oklahoma confirmed a ransomware attack affecting all computers and digital services, with off-site backups slated for restoration. Mitchell (South Dakota), Coryell County (Texas) and Washburn County (Wisconsin) also disclosed cyberattacks that shut down networks and disrupted phone and payment systems.
Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others
Australian police arrested two suspects over TeamPCP cyberattacks targeting Mercor, OpenAI, and other tech companies.
Australian police have arrested two people in connection with the TeamPCP hacks. The arrests follow a wave of cyberattacks earlier in the year that targeted tech companies including Mercor and OpenAI, many of which rely on high-profile, widely used open source software. The article provides no technical details or CVE identifiers.
Red Flags That Expose Fake North Korean IT Workers
Researchers outline red flags for spotting North Korean operatives posing as remote IT workers as their tactics improve.
Dark Reading describes indicators that help organizations identify North Korean operatives working undercover as IT workers. Researchers say these operatives are improving their tactics, but detection methods still exist. Catching them early helps employers avoid infiltration, data theft, and damage.
Calling on Cyber Pros to Help Defend City Hall
Dark Reading urges security professionals to volunteer expertise helping under-resourced municipal government agencies improve cyber defenses.
The piece highlights that smaller government agencies such as city hall operate with limited security budgets and staffing. It lays out ways cybersecurity professionals can contribute volunteer support to strengthen local government defenses. No specific incident, vulnerability, or actor is involved.
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Australian Federal Police arrested two alleged TeamPCP members, a data extortion group tied to prolonged software supply chain attacks.
The Australian Federal Police arrested two unnamed suspects from Western Australia, aged 21 and 23, believed to be members of TeamPCP. The group is described as a cybercrime and data extortion syndicate blamed for the longest-running spree of software supply chain attacks, allegedly creating malicious open-source software that hit thousands of global businesses. KrebsOnSecurity had identified the 21-year-old suspect in June and had been in contact with him.
Polimill builds Japan's next-generation public AI infrastructure
OpenAI says Japanese company Polimill uses GPT models and Codex to give municipalities searchable access to administrative knowledge.
OpenAI published a customer story describing how Polimill, a Japanese civic technology company, builds public AI infrastructure using OpenAI GPT models and Codex. The tools let municipalities search and reuse administrative knowledge and are intended to accelerate internal development workflows.
Fighting Your Dragons Through Tough Tech Times
Cybersecurity veteran Hal Pomeranz shares advice on managing career anxiety and building professional connections during the tech industry downturn.
Dark Reading published a pep talk by industry veteran Hal Pomeranz addressing career anxiety and self-doubt among cybersecurity professionals amid a historically tough tech job market. He shares strategies for building meaningful professional connections during industry downturns.
How Virginia Tech Connected Pentesting to Its Engineering Workflow
Horizon3.ai customer story details Virginia Tech automating external pentesting via NodeZero's GraphQL API with GitLab and ServiceNow integration for remediation tracking.
Horizon3.ai published a customer story describing how Virginia Tech, whose environment serves more than 38,000 students across hundreds of independent departments and multiple cloud providers, used NodeZero's GraphQL API to automate external pentesting through GitLab. Findings are routed directly into ServiceNow for subnet-owner assignment and remediation tracking, creating a repeatable attack-validation-to-remediation workflow.
China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?
WIRED examines Volt Typhoon pre-positioning 'digital bombs' in US civilian infrastructure via a war game simulation discussion.
WIRED's Uncanny Valley podcast features reporter Andy Greenberg discussing a war game simulating a cyberattack by Chinese hacking group Volt Typhoon. The episode examines Volt Typhoon's practice of planting persistent access in US civilian infrastructure that could be activated during conflict, and questions whether the US is prepared.
AI-Infra-Guard: Open-source security scanner for AI systems
Tencent's Zhuque Lab open-sourced AI-Infra-Guard, a scanner that fingerprints AI services, checks 1,600+ CVEs, and evaluates MCP skills.
AI-Infra-Guard fingerprints running AI services such as Ollama, vLLM and ComfyUI, checks them against more than 1,600 known CVEs, and inspects MCP servers and agent skills across 14 risk categories. Its SkillTrustBench judging set contains 5,520 human-labeled samples, with false positive rates of 1.20%–18.67% depending on the judging model. Users include ICBC, China Merchants Bank, China Telecom, Lenovo, vivo and Bilibili. Release 4.1.9 hardened scanning agents against indirect prompt injection, and the open-source build ships without authentication, requiring a reverse proxy with Basic Auth or an IP allowlist.
'I Saw a Shiny Thing': Cop Explains Why He Used License Plate Reader to Stalk Woman
Body camera footage shows Florida officer Lamar Roman used DMV databases and ALPR cameras to stalk a woman; dozens of Flock misuse cases surfaced.
404 Media published body camera footage showing the investigation into officer Lamar Roman, who met a woman on the set of Apple TV's Bad Monkey, then illegally queried DMV databases and placed her plate on an ALPR hot list. He nearly caused a head-on collision while following her and illegally pulled her over, and was later arrested in front of his home. Flock's CEO said the system has caught many abusive officers, and the Washington Post found at least 50 misuse incidents; Roman used Turing's Guardian ALPR system.
PurpleDelta's Fraudulent Employment Operations
Recorded Future details North Korean cluster PurpleDelta using AI-generated personas and ChatGPT assistants to infiltrate companies via fraudulent employment.
Recorded Future profiles PurpleDelta, a North Korean IT worker threat cluster, in a new research report. The group uses AI-generated personas, sophisticated tradecraft, and custom ChatGPT assistants to obtain employment at target organizations and operate covertly. The report includes key indicators of compromise and recommended mitigation strategies for defenders.
Extortion crews have their eyes on high-value AI data, Google warns
Google's Mandiant warns extortion crews now steal proprietary AI models, prompts, and research for ransom, while threat actors automate attacks with agentic AI.
Google's AI Threat Tracker details intrusions in which extortion crews exfiltrated healthcare drug research and a proprietary AI model, and stole an AI media company's source code, prompts, skills, model scripts, and secrets, threatening leaks unless paid. TeamPCP (UNC6780), behind large open-source supply chain attacks on PyPI, npm, and Docker Hub since March, used a malicious GitHub Actions workflow to exfiltrate a company's proprietary AI repository. Mandiant also observed a fully autonomous multi-agent credential-harvesting cloud intrusion completed in under six hours, and a China-linked espionage group using Gemini to build a dynamic automated penetration-testing framework.