{"id":36528,"date":"2026-08-21T10:55:59","date_gmt":"2026-08-21T17:55:59","guid":{"rendered":"https:\/\/www.podfeet.com\/blog\/?p=36528"},"modified":"2026-08-21T10:55:59","modified_gmt":"2026-08-21T17:55:59","slug":"sb-2026-08-21","status":"publish","type":"post","link":"https:\/\/www.podfeet.com\/blog\/2026\/08\/sb-2026-08-21\/","title":{"rendered":"Security Bits \u2014 21 August 2026"},"content":{"rendered":"<h2>Feedback &amp; Followups<\/h2>\n<aside class=\"small-aside\">Listener and community feedback, developments in recently covered stories, and developments in long-running stories we&#8217;re tracking over time.<\/aside>\n<ul>\n<li>\ud83c\uddec\ud83c\udde7 Here we go again \ud83d\ude41: <a href=\"https:\/\/cyberinsider.com\/apple-challenges-new-uk-demand-to-access-encrypted-icloud-data\/\">Apple challenges new UK demand to access encrypted iCloud data \u2014 cyberinsider.com\/\u2026<\/a> (Another unconfirmed report from the FT because the court is secret and the law imposes a gag order on companies)<\/li>\n<li>Another TV maker does the right thing: <a href=\"https:\/\/cyberinsider.com\/samsung-bans-smart-tv-apps-that-turn-user-connections-into-proxies\/\">Samsung bans smart TV apps that turn user connections into proxies \u2014 cyberinsider.com\/\u2026<\/a><\/li>\n<li>\ud83c\uddfa\ud83c\uddf8 Another state will soon have a privacy-protecting age verification option: <a href=\"https:\/\/www.macobserver.com\/news\/north-carolina-prepares-to-support-apple-wallet-drivers-licenses\/\">North Carolina Prepares To Support Apple Wallet Driver\u2019s Licenses \u2014 www.macobserver.com\/\u2026<\/a> (expected launch <em>&#8216;early 2027&#8217;<\/em>)\n<ul>\n<li>Updated full list of all states with announced support that&#8217;s still in the works \u2014  <a href=\"https:\/\/www.macobserver.com\/news\/apple-wallet-drivers-license-support-is-coming-to-these-7-states-next\/\">www.macobserver.com\/\u2026<\/a> (KY, NC, OK, UT, VA, CT &amp; MS)<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>Deep Dive 1 \u2014 More Models Break out of More <em>&#8216;Cages&#8217;<\/em><\/h2>\n<p>As expected, the AI industry&#8217;s renewed focus on checking what models do during testing has revealed some more new escapes.<\/p>\n<h3>Anthropic Models Break Out During Independent Testing in the UK<\/h3>\n<p>The UK has an official AI testing organisation, the AI Security Institute (AISI), and one of their tasks is to evaluate the abilities of advanced models. They were testing Anthropic&#8217;s Claude Mythos 5.<\/p>\n<p>They set the models to simulated hacking challenges, and during the tests the models took \u201cunsanctioned\u201d actions on the real internet. Thankfully, this time there was no actual harm to other organisations, but what the models tried was really quite noteworthy.<\/p>\n<p>As AISI put it \u2014 <em>\u201dthis is the first time we have seen risks around autonomy and deception manifest this clearly\u201d<\/em>.<\/p>\n<p>Before we dive into what the model did, we should note that the model was running with some of its safeguards off, so the model AISI was testing was not configured quite like the publicly available models. The AISI acknowledged that fact, but added that they still didn\u2019t expect the models to show <em>\u201csigns of novel, potentially deceptive behaviours\u201d<\/em>.<\/p>\n<p>Rather than play a game of telephone, I\u2019m going to quote from <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/openai-anthropic-ai-agents-targeted-real-people-and-systems-in-cyber-tests\/\">Bleeping Computer\u2019s coverage<\/a> (they read the original report, but I didn\u2019t!).<\/p>\n<p>This is from Bleeping Computer\u2019s summary of the agent\u2019s behaviour:<\/p>\n<blockquote><p>\n  The agent then attempted a supply-chain attack by submitting malicious code to the real open-source project, believing that compromising the software could provide a path into a machine within the simulated range.<\/p>\n<p>  Most concerning, the agent researched the project&#8217;s maintainers, created multiple fake GitHub identities, and used those accounts in social engineering attacks to push the maintainer into approving a malicious pull request.<\/p>\n<p>  When a human reviewer warned that the pull request contained malware, the agent denied the accusation and used other fake accounts it controlled to pressure the maintainer and create the appearance that independent users had reviewed and approved the changes.\n<\/p><\/blockquote>\n<p>The agent also chose to use TOR to hide its origins!<\/p>\n<h3>OpenAI\u2019s Escape<\/h3>\n<p>This second escape is much less dramatic, and is literally a footnote in <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/openai-anthropic-ai-agents-targeted-real-people-and-systems-in-cyber-tests\/\">the Bleeping Computer story linked above<\/a>.<\/p>\n<p>OpenAI&#8217;s GPT-5.6 Sol was being tested by an independent lab, <em>Irregular,<\/em> in a so-called <em>Capture the Flag<\/em> hacking game (CTF). Like all CTF games, the agents were supposedly trapped in a sandbox environment, but of course, they didn\u2019t stay confined.<\/p>\n<p>In this instance, it was a case of Large Language Models (LLMs) doing their pattern matching thing too well \u2014 there was a real-world website with a similar enough name to the fake company in the CTF simulation, and the agents assumed it was part of the test, not real, and attacked. I\u2019m not sure if they succeeded; the reporting isn\u2019t clear.<\/p>\n<p>What strikes me about this escape is that it shows the downside to one of my favourite LLM features: their fuzziness! When you use traditional search engines, you need to be specific, but when you use LLMs, you can be surprisingly vague and still get great answers. In this case, that fuzziness led to a dangerous case of mistaken identity.<\/p>\n<h3>Meta also Lost Control of a Model<\/h3>\n<p>We don\u2019t know exactly which model it was, but the consensus is that it was probably Spark 1.1.<\/p>\n<p>In fact, Meta are not sharing much information at all. We know their model attacked <strong>a<\/strong> real-world organisation, but we have no idea which one, or even what mischief the model got up to when it broke in.<\/p>\n<p>What we do know is that this model was also under test by <em>Irregular<\/em>, and that the model <em>\u201cexploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies.\u201d<\/em><\/p>\n<p>Meta are blaming the escape on a misconfiguration, and promise they\u2019ll tell us more when they finish their investigation.<\/p>\n<p>More details \u2014 <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/meta-ai-model-hacked-a-company-during-misconfigured-cyber-test\/\">www.bleepingcomputer.com\/\u2026<\/a><\/p>\n<h3>Related News<\/h3>\n<ul>\n<li><a href=\"https:\/\/cyberinsider.com\/openai-slows-model-development-over-concerns-about-cyber-capabilities\/\">OpenAI slows model development over concerns about cyber capabilities \u2014 cyberinsider.com\/\u2026<\/a><\/li>\n<li>Yet another novel attack against AI agents: <a href=\"https:\/\/thehackernews.com\/2026\/08\/ai-mind-viruses-can-spread-between.html\">AI &#8220;Mind Viruses&#8221; Can Spread Between Agents Through Persistent Prompt Files \u2014 thehackernews.com\/\u2026<\/a>\n<ul>\n<li>AI agents depend on prompt files as their short-term memory<\/li>\n<li>Without these prompt files, agents can&#8217;t perform a complex task<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>Deep Dive 2 \u2014 Another AI Transparency Law, and <em>Provenance<\/em> Metadata<\/h2>\n<p>In the previous instalment, we talked about transparency provisions from the EU AI act coining into effect, but there was actually a second notable law that came into effect at the same time; it just didn\u2019t make as much media because it was a state law rather than a multi-national law. However, that state is California, so the law is likely to have a lot more impact than just about any other state law would!<\/p>\n<p>Without Allison picking it up, I don\u2019t think this story would have made it onto my radar, which would have been very disappointing, because I really like this law!<\/p>\n<p>The law we\u2019re talking about is California\u2019s <em>AI Transparency Act<\/em>, and one of two sets of transparency-related provisions can come into effect at the start of August, with an even more interesting provision coming into effect in 2028.<\/p>\n<p>For now, the law only applies to large AI vendors with more than 1 million customers, and large online platforms.<\/p>\n<p>The AI vendors need to start embedding <em>provenance<\/em> metadata into their generated content, and large online platforms have a duty not to strip provenance metadata from user-uploaded content. Sites are also <em>encouraged<\/em> to expose provenance metadata in their interfaces, but that\u2019s sadly not required.<\/p>\n<p>The law affects new companies immediately, but existing companies have some time to come into compliance.<\/p>\n<p>Provenance is just the verified history of something. If it sounds familiar, it\u2019s because the Antiques and collectibles industry has been using it for decades (if not longer). For digital media, that means the full story of the image, audio, or video from creation to its current form. For now, AI labs need to embed provenance information that asserts that it is generated.<\/p>\n<p>Provenance, like a digital signature, is easy to remove but effectively impossible to fake. An absence of provenance information doesn\u2019t mean you can assume it\u2019s not generated, but any file that has provenance information really is what the provenance says it is, be that generated, captured, or a mix of the two.<\/p>\n<p>This is why the 2028 provisions are much more interesting to me \u2014 creators of <em>capture devices<\/em>, like cameras, need to start supporting provenance metadata.<\/p>\n<p>That means that it will become possible for reputable news sources to cryptographically prove their media is real!<\/p>\n<p>This is important: trying to detect AI is a fool\u2019s errand; it\u2019s always going to be a cat-and-mouse game. The real key is verifiable real images, not detectable <em>fakes<\/em>! I dedicated the most recent episode of Let\u2019s Talk Photo to the importance of provenance for photography (<a href=\"https:\/\/lets-talk.ie\/ltp155\">LTP 155<\/a>).<\/p>\n<p>Note that the law also asks AI labs to watermark their generated content and provide AI detectors, but to me that\u2019s just politicians asking for unicorns; it\u2019s the provenance requirements that I think will have a real impact.<\/p>\n<p>We\u2019re also already starting to see some implementation news:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.macobserver.com\/news\/whatsapp-is-working-on-ai-content-labels-for-channels-heres-how-they-work\/\">WhatsApp is working on AI content labels for Channels, here&#8217;s how they work \u2014 www.macobserver.com\/\u2026<\/a><\/li>\n<li><a href=\"https:\/\/www.cultofmac.com\/news\/apple-reference-image-ios-27-photo-authentication\">iOS 27 feature could prove an iPhone photo isn\u2019t AI slop \u2014 www.cultofmac.com\/\u2026<\/a> (camera hardware support for the C2PA provenance standard \ud83c\udf89)<\/li>\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/artificial-intelligence\/how-anthropic-plans-to-watermark-claudes-ai-generated-text\/\">How Anthropic plans to watermark Claude&#8217;s AI-generated text \u2014 www.bleepingcomputer.com\/\u2026<\/a><\/li>\n<\/ul>\n<h3>Links<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.kqed.org\/news\/12093427\/california-leads-us-with-new-ai-transparency-law\">California Leads US With New AI Transparency Law \u2014 www.kqed.org\/\u2026<\/a><\/li>\n<li><a href=\"https:\/\/www.duanemorris.com\/alerts\/from_disclosure_to_detection_converging_ai_transparency_obligations_eu_california_0826.html\">From Disclosure to Detection \u2013 Converging AI Transparency Obligations in the EU and California \u2014 www.duanemorris.com\/\u2026<\/a><\/li>\n<li>\ud83c\udfa7 The two Let&#8217;s Talk Photo episodes related to the concept of provenance and the C2PA Content Credentials specification:\n<ul>\n<li><a href=\"https:\/\/lets-talk.ie\/ltp125\">LTP 125: Image Provenance with Content Credentials \u2014 lets-talk.ie<\/a> (how they work)<\/li>\n<li><a href=\"https:\/\/lets-talk.ie\/ltp155\">LTP 155: Provenance not AI Detectors \u2014 lets-talk.ie\/\u2026<\/a> (a deeper version of this deep dive)<\/li>\n<\/ul>\n<\/li>\n<li><strong>Analysis:<\/strong> \ud83c\udfa7 An insightful discussion covering what happened, what we do and don&#8217;t know, and where things could go from here \u2013 <a href=\"https:\/\/overcast.fm\/+AAoiPWQM5Xs\">The Ezra Klein Show: The A.I.s Are Already Out of Control \u2014 overcast.fm\/\u2026<\/a><\/li>\n<\/ul>\n<h2>\u2757 Action Alerts<\/h2>\n<aside class=\"small-aside\">Calls to action, if any stories in this section are relevant to you, there is some action you should take.<\/aside>\n<ul>\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days\/\">Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days \u2014 www.bleepingcomputer.com\/\u2026<\/a><\/li>\n<li>Updates from Apple:\n<ul>\n<li><a href=\"https:\/\/tidbits.com\/2026\/08\/17\/apple-backpatches-beta-security-fixes-into-macos-26-6-2-ios-ipados-26-6-1-and-ios-ipados-18-7-10\/\">Apple Backpatches Beta Security Fixes into macOS 26.6.2, iOS\/iPadOS 26.6.1, and iOS\/iPadOS 18.7.10 \u2014 tidbits.com\/\u2026<\/a><\/li>\n<li>In previous years, we didn&#8217;t usually get these kinds of backported fixes until after the new OSes were released<\/li>\n<li>Another sign of how much AI is changing cybersecurity<\/li>\n<li>\u26a0\ufe0f <strong>Mac Users:<\/strong> <a href=\"https:\/\/tidbits.com\/2026\/08\/06\/apple-fixes-screen-sharing-vulnerability-in-tahoe-sequoia-and-sonoma\/\">Apple Fixes Screen Sharing Vulnerability in Tahoe, Sequoia, and Sonoma \u2014 tidbits.com\/\u2026<\/a> (<strong>patch immediately!<\/strong>)<\/li>\n<li><a href=\"https:\/\/arstechnica.com\/security\/2026\/08\/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation\/\">Vulnerability giving attackers full control of Macs is under active exploitation \u2014 arstechnica.com\/\u2026<\/a><\/li>\n<li><a href=\"https:\/\/www.macobserver.com\/news\/apple-fixes-22-security-flaws-with-safari-26-6-1-update\/\">Apple fixes 22 security flaws with Safari 26.6.1 update \u2014 www.macobserver.com\/\u2026<\/a><\/li>\n<li><strong>Related:<\/strong> <a href=\"https:\/\/appleinsider.com\/articles\/26\/08\/04\/ai-slop-security-reports-are-clogging-up-apples-bug-bounty-program\">AI slop security reports are clogging up Apple&#8217;s bug bounty program \u2014 appleinsider.com\/\u2026<\/a> (Apple have put quotas on the number of reports from each researcher each month)<\/li>\n<\/ul>\n<\/li>\n<li>\u26a0\ufe0f <strong>Zbtlink Router Owners:<\/strong> <a href=\"https:\/\/cyberinsider.com\/chinese-zbtlink-wifi-routers-ship-with-endlessdoors-malware\/\">Chinese Zbtlink WiFi routers ship with ENDLESSDOORS malware \u2014 cyberinsider.com\/\u2026<\/a> (affordable Chinese-made routers sold in the US &amp; Europe)\n<ul>\n<li>No patch, not even vendor engagement, so <strong>replace router<\/strong>!<\/li>\n<li>Also flagged by VulnCheck \u2014 <a href=\"https:\/\/www.vulncheck.com\/blog\/zbt-endlessdoors\">www.vulncheck.com\/\u2026<\/a> (Thanks Joop for the link)<\/li>\n<\/ul>\n<\/li>\n<li>\u26a0\ufe0f <strong>TP-Link Router Owners:<\/strong>  <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/tp-link-patches-omada-ztp-flaws-allowing-hackers-to-breach-networks\/\">TP-Link patches Omada ZTP flaws allowing hackers to breach networks \u2014 www.bleepingcomputer.com\/\u2026<\/a><\/li>\n<li>\u26a0\ufe0f <strong>WordPress Site Owners:<\/strong>\n<ul>\n<li><a href=\"https:\/\/thehackernews.com\/2026\/08\/new-wordpress-pre-auth-xss-could-lead.html\">New WordPress Pre-Auth XSS Could Lead to PHP Code Execution &#8211; Patch ASAP \u2014 thehackernews.com\/\u2026<\/a><\/li>\n<li>Patch to WordPress core, so be sure your site is updated!<\/li>\n<li><a href=\"https:\/\/thehackernews.com\/2026\/08\/bdthemes-supply-chain-attack-poisons.html\">BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins \u2014 thehackernews.com\/\u2026<\/a><\/li>\n<li>Most notably effects the popular <em>Elementor<\/em> suite of plugins<\/li>\n<li>If you use any of the themes or plugins listed in the article <strong>check your site for rogue admin accounts!<\/strong><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>Worthy Warnings<\/h2>\n<aside class=\"small-aside\">Potentially relevant warnings from government organisations, public interest groups, or the security community.<\/aside>\n<ul>\n<li>\u26a0\ufe0f <strong>iOS Users:<\/strong> <a href=\"https:\/\/cyberinsider.com\/apple-webkit-privacy-leaks-impact-tor-psylo-and-icloud-private-relay\/\">Apple WebKit privacy leaks impact Tor, Psylo, and iCloud Private Relay \u2014 cyberinsider.com\/\u2026<\/a>\n<ul>\n<li>Bugs found in a few of the newer API calls used by iOS apps that offer app-specific VPN-like features (including a part of the Passkey spec)<\/li>\n<li>Some network connections from the apps are not routed through the app-specific VPN, leaking the user&#8217;s real IP address<\/li>\n<li>Does not affect traditional OS-wide VPNs that route all traffic through a tunnel<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>Notable News<\/h2>\n<ul>\n<li><a href=\"https:\/\/cyberinsider.com\/apple-sends-mercenary-spyware-alerts-to-targeted-iphone-users\/\">Apple sends mercenary spyware alerts to targeted iPhone users \u2014 cyberinsider.com\/\u2026<\/a>\n<ul>\n<li>Reports sent to users in 110 countries!<\/li>\n<li>Notable because this is the first time Apple added push notifications to the mix (affected users still get the email and the notification when they log in to iCloud.com they received previously).<\/li>\n<\/ul>\n<\/li>\n<li>\ud83c\uddfa\ud83c\uddf8 <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/white-house-taps-security-firms-for-offensive-hack-back-operations\/\">White House taps security firms for offensive hack-back operations \u2014 www.bleepingcomputer.com\/\u2026<\/a>\n<ul>\n<li>Not inherently good or bad news \u2014 the UK has programs to enabled public-private cybersecurity cooperation too<\/li>\n<li><strong>Editorial by Bart:<\/strong> This is concerning to me because it is open to abuse through corruption and <em>&#8216;cronyism&#8217;<\/em>.<\/li>\n<\/ul>\n<\/li>\n<li>\ud83c\uddfa\ud83c\uddf8 <a href=\"https:\/\/www.macobserver.com\/news\/meta-ordered-to-pay-567-million-in-massive-child-safety-case\/\">Meta Ordered to Pay $567 Million in Massive Child Safety Case \u2014 www.macobserver.com\/\u2026<\/a>\n<ul>\n<li><em>&#8220;A state court has ordered Meta to pay $567 million to address the mental health impact its platforms have had on young people. The judge ruled that the company created a public nuisance by designing features that keep teenagers addicted to its apps &#8230; The judge laid out a strict five-year plan that forces the company to overhaul how teenagers experience Facebook and Instagram. The new rules require monthly time limits for younger users and place tighter restrictions on how adults can interact with minors on the platform.&#8221;<\/em> \u2014 The Mac Observer<\/li>\n<li>The state is New Mexico, and Meta are of course appealing!<\/li>\n<\/ul>\n<\/li>\n<li>\ud83c\uddea\ud83c\uddfa [Europe is creating a common security standard for VPN services \u2014 <a href=\"https:\/\/cyberinsider.com\/europe-is-creating-a-common-security-standard-for-vpn-services\/\">cyberinsider.com\/\u2026<\/a>\n<ul>\n<li><em>&#8220;European standards body ETSI has begun the approval process for a new cybersecurity standard for VPN products &#8230; introduces defined technical and privacy requirements that could eventually give VPN vendors a recognized way to demonstrate compliance with EU cybersecurity rules&#8221;<\/em> \u2014 Cyber Insider<\/li>\n<li>Developed with industry partners including Google, Palo Alto &amp; Nord<\/li>\n<\/ul>\n<\/li>\n<li>Some nice new features\n<ul>\n<li>Following through on their promise to pay down some <strong>Windows<\/strong> technical debt: <a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-removes-wmic-lolbin-tool-in-windows-11-beta-builds\/\">Microsoft starts removing WMIC tool used by cybercriminals \u2014 www.bleepingcomputer.com\/\u2026<\/a> (WMI itself is not being removed, just the legacy CLI, users need to switch to PowerShell)<\/li>\n<li><a href=\"https:\/\/cyberinsider.com\/signal-broadens-device-linking-support-on-android-and-ios\/\"><strong>Signal<\/strong> broadens device linking support on Android and iOS \u2014 cyberinsider.com\/\u2026<\/a> (makes Signal more usable by people for whom cross-device use is important)<\/li>\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/signal-adds-new-security-feature-to-thwart-man-in-the-middle-attacks\/\"><strong>Signal<\/strong> adds new security feature to thwart man-in-the-middle attacks \u2014 www.bleepingcomputer.com\/\u2026<\/a><\/li>\n<li><a href=\"https:\/\/cyberinsider.com\/whatsapp-adds-on-device-scam-detection-without-sending-chats-to-meta\/\"><strong>WhatsApp<\/strong> adds on-device scam detection without sending chats to Meta \u2014 cyberinsider.com\/\u2026<\/a><\/li>\n<li><a href=\"https:\/\/cyberinsider.com\/brave-browser-adds-new-defenses-against-gpu-fingerprinting\/\"><strong>Brave browser<\/strong> adds new defenses against GPU fingerprinting \u2014 cyberinsider.com\/\u2026<\/a><\/li>\n<li><a href=\"https:\/\/appleinsider.com\/articles\/26\/08\/16\/mozilla-gradually-rolls-out-an-ad-blocker-built-into-firefox-for-ios\">Mozilla gradually rolls out an ad-blocker built into <strong>Firefox for iOS<\/strong> \u2014 appleinsider.com\/\u2026<\/a><\/li>\n<li>The option will slowly start appearing on phones over the next few weeks (presumably using Apple&#8217;s staggered release option for app store updates)<\/li>\n<li>Some conflicts of interest result in some embarrassing exceptions, most notably:\n<ul>\n<li>Adds in search results<\/li>\n<li>Adds on the Mozilla website<\/li>\n<\/ul>\n<\/li>\n<li>Even though some ads are intentionally allow-listed, all trackers are blocked<\/li>\n<li><a href=\"https:\/\/cyberinsider.com\/firefox-154-blocks-silent-websocket-access-to-local-network-devices\/\"><strong>Firefox<\/strong> 154 blocks silent WebSocket access to local network devices \u2014 cyberinsider.com\/\u2026<\/a><\/li>\n<li>Tackles a commonly used technique for attacking known vulnerabilities in routers and IoT devices (direct internet access is not possible, so use a malicious web page or ad to attack the internal IP via the user&#8217;s own browser)<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>Interesting Insights<\/h2>\n<aside class=\"small-aside\">High-quality opinion and editorial content recommended by Bart.<\/aside>\n<ul>\n<li>Proton have released a new tool to help users understand how much of their privacy they are giving away to AI companies \u2014 <a href=\"https:\/\/cyberinsider.com\/protons-ai-paper-trail-reveals-how-much-chatgpt-and-claude-know-about-users\/\">cyberinsider.com\/\u2026<\/a>\n<ul>\n<li><em>&#8220;Called\u00a0<a href=\"https:\/\/proton.me\/lumo\/ai\/ai-paper-trail\">AI Paper Trail<\/a>, the tool analyzes exported conversation data from OpenAI&#8217;s ChatGPT or Anthropic&#8217;s Claude and generates a personalized report detailing what can be inferred from a user&#8217;s chats.&#8221;<\/em> \u2014 Cyber Insider<\/li>\n<li><strong>Editorial by Bart:<\/strong> this is a genuinely useful tool, but Proton are not neutral parties here, they make a privacy-protecting chatbot (<a href=\"https:\/\/proton.me\/lumo\">Lumo<\/a>), and this tool is designed to encourage users to switch it it. (Note I use Lumo and am very happy with it. Version 2 came out recently adding image generation, which I&#8217;ve found great for helping with illustrations, since my drawing ability is <strong>way<\/strong> below average!)<\/li>\n<\/ul>\n<\/li>\n<li><a href=\"https:\/\/www.macobserver.com\/macos\/mac-security-threat-report\/\">Mac Security Just Got Trickier: the Latest Threat Report \u2014 www.macobserver.com\/\u2026<\/a> (Sober analysis of <a href=\"https:\/\/moonlock.com\/mid-2026-macos-threat-report\">report from Moonlock<\/a>)\n<ul>\n<li>Trickier, because Click-Fix attacks are the biggest threat, and those don&#8217;t have a good technical solution, it&#8217;s up to use humans to keep ourselves safe \ud83d\ude15<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>Palate Cleansers<\/h2>\n<aside class=\"small-aside\">Anything upbeat and nerdy Bart and\/or Allison think you might enjoy.<\/aside>\n<ul>\n<li><strong>From Bart:<\/strong>\n<ul>\n<li>A great iOS tip: <a href=\"https:\/\/daringfireball.net\/linked\/2026\/08\/06\/shortcut-control-center-current-app-settings\">Add a Shortcut to Control Center to Open the Current App&#8217;s Preferences in the Settings App \u2014 daringfireball.net\/\u2026<\/a><\/li>\n<li>This old XKCD cartoon has become funny in a whole new way (repackaged and captioned by Steve Gibson for one of his humorous <em>picture of the week<\/em> segments)<br \/>\n<img decoding=\"async\" src=\"https:\/\/www.grc.com\/SN\/1091.jpg\" alt=\"XKCD 461 re-mastered by Steve Gibson\" \/><\/li>\n<li>\ud83c\udfa7 Season 3 of the BBC Podcast <a href=\"https:\/\/www.bbc.co.uk\/programmes\/w13xtvg9\/episodes\/downloads\">Cyberhack<\/a> is now complete, telling the story of first ransomware we all got to know by name, Conti (of Irish Healthcare System Hack fame): <a href=\"https:\/\/overcast.fm\/+AAsmMOhzxsA\">Cyber Hack: The Conti Files- 1. Beaches and Blackmail \u2014 overcast.fm\/\u2026<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>Legend<\/h2>\n<p>When the textual description of a link is part of the link, it is the title of the page being linked to, when the text describing a link is not part of the link, it is a description written by <a href=\"https:\/\/bartb.ie\/\">Bart<\/a>.<\/p>\n<table>\n<thead>\n<tr>\n<th align=\"center\">Emoji<\/th>\n<th align=\"left\">Meaning<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td align=\"center\">\ud83c\udfa7<\/td>\n<td align=\"left\">A link to <strong>audio content<\/strong>, probably a podcast.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">\u2757<\/td>\n<td align=\"left\">A <strong>call to action<\/strong>.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\"><em>flag<\/em><\/td>\n<td align=\"left\">The story is particularly relevant to people living in a <strong>specific country<\/strong>, or, the organisation the story is about is affiliated with the government of a specific country.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">\ud83d\udcca<\/td>\n<td align=\"left\">A link to <strong>graphical content<\/strong>, probably a chart, graph, or diagram.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">\ud83e\uddef<\/td>\n<td align=\"left\">A story that has been <strong>over-hyped<\/strong> in the media, or, <em>&#8220;no need to light your hair on fire&#8221;<\/em> \ud83d\ude42<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">\ud83d\udcb5<\/td>\n<td align=\"left\">A link to an article behind a <strong>paywall<\/strong>.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">\ud83d\udccc<\/td>\n<td align=\"left\">A <strong>pinned<\/strong> story, i.e. one to keep an eye on that&#8217;s likely to develop into something significant in the future.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">\ud83c\udfa9<\/td>\n<td align=\"left\">A <strong><em>tip of the hat<\/em><\/strong> to thank a member of the community for bringing the story to our attention.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">\ud83c\udfa6<\/td>\n<td align=\"left\">A link to <strong>video content<\/strong>.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>Feedback &amp; Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we&#8217;re tracking over time. \ud83c\uddec\ud83c\udde7 Here we go again \ud83d\ude41: Apple challenges new UK demand to access encrypted iCloud data \u2014 cyberinsider.com\/\u2026 (Another unconfirmed report from the FT because the court is secret and the law imposes a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":19030,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[147,214],"tags":[2079,50,569,2003],"class_list":["post-36528","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-posts","category-security-bits","tag-patch","tag-security","tag-security-bits","tag-vulnerabilities"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/www.podfeet.com\/blog\/wp-content\/uploads\/2019\/08\/security_bits_logo_400px_no_alpha.jpg","_links":{"self":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/posts\/36528","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/comments?post=36528"}],"version-history":[{"count":1,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/posts\/36528\/revisions"}],"predecessor-version":[{"id":36529,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/posts\/36528\/revisions\/36529"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/media\/19030"}],"wp:attachment":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/media?parent=36528"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/categories?post=36528"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/tags?post=36528"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}