Meta was quietly launched stashing dormant face recognition code on more than 50 million phonesWIRED revealed this week that it is located in the app companion to its Oakley or Ray-Ban smart sunglasses. If activated, the feature—known internally as NameTag—would let wearers identify people in front of them by matching captured faces against a biometric gallery sitting on the user’s device. Meta has said that it will abandon this technology in 2021 after spending billions to settle lawsuits involving biometric privacy in Texas and Illinois.
xAI, meanwhile, is asking a Federal Judge to force four people suing the company over Grok-generated deepfake nudes to drop their pseudonyms and litigate under their real names—including one plaintiff who alleges the chatbot was used to fabricate sexual images of her as a child. They say that they are willing to drop their suit rather than face harassment from Musk supporters. xAI lawyers claim, however, that the deepfakes are still under seal and therefore, it is not possible to reveal them. “nothing inherently stigmatizing” Name the characters in these pictures.
Google rolled out a new Android feature this week This is targeted at AI-powered impersonation schemes that allow fraudsters to spoof familiar numbers and copy a voice. This silent handshake is packaged in Google Dialer for phones that run Android 12 and later. Android flags the fake call and removes the photo of the person who made it. However, this only works if the phone is on Google Dialer. iPhones are not included.
WIRED also reported this week that the Manhattan Institute—the same right-wing think tank that engineered the 1990s broken-windows policing and the Trump administration’s anti-DEI push—is now shopping model legislation to turn minor protest-related offenses into felonies It is based on a new theory called “civil terrorism.”
Researchers have detailed a clever new browser side-channel attack called FROST that fingerprints other tabs—and sometimes the apps on your device—by measuring how long it takes to read from a sandboxed file on your SSD. The entire attack runs in JavaScript, and the timing trace is fed through a network of neural networks trained using the I/O Signatures from common software. So far, there is no evidence that anyone has used it.
But that’s just the beginning. Every week we bring you the most important security and privacy headlines that we did not cover ourselves. To read more, click on the titles to access the stories.
The supplements known as peptides—chains of amino acids that promise to help those who smear, ingest, or inject them achieve everything from weight loss to skin rejuvenation—have become their own largely unregulated pharmaceutical subindustry. The growth of the peptide industry is fueled mostly by bitcoins, sent to Chinese labs who sell these mysterious miracles.
Chainalysis, a crypto-tracing company, is launching this week published an analysis Crypto flows are now flowing to sellers of peptides, creating a grey market worth over $100 million per year. Chainalysis found that many of the Chinese laboratories that previously sold fentanyl have switched over to producing and selling peptides. Chainalysis thinks the transition is meant to capitalize on “looksmaxing” hype across social media that has pushed peptide sales—and to avoid the risk of a law enforcement crackdown on opioid manufacturers.
AI is capable to doing all sorts of tasks if only you ask: it can code apps, fix your pictures or hack the Instagram account for President Barack Obama. Since Meta announced in March Hackers exploited the fact that the account-support functions, such as updating passwords, will increasingly be automated by AI. They were able to take control of accounts and reset passwords for high profile users. The victims included celebrities and high-profile users. reported by 404 MediaObama, Chief Master Sergeant, US Space Force and Sephora are all involved. Meta claims that the problem has been resolved and all affected accounts are now secure. But the wave of takeovers illustrates the risks of off-loading security functions to AI—particularly at companies like Meta, which has very publicly touted its all-in approach to adopting AI across the company.
Anthropic rolled out You can find out more about it here. powerful Mythos tool It raised eyebrows when it included the US National Security Agency in its initial list of access. Mythos is, according to reports, a reportedly cryptic word. capable of finding Hackable software vulnerabilities previously concealed are being revealed at alarming speeds, causing fears they could be exploited for mass cyber-attacks and automated surveillance. But the NSA also has a defensive mission, and initial reporting suggested the agency might just be using Anthropic’s tool to find bugs in popular software used by Americans—such as Microsoft’s—with the goal of better securing it. Yet the Financial Times now reports that Anthropic is helping the NSA take its use of Mythos a step further, deploying Anthropic’s own engineers to the agency to help it learn to use the AI tool—including for offensive hacking. The FT was unable to confirm that Mythos has been used in hacking activities. It would surprise me if, given the increasing use of AI in state-sponsored cyberattacks, the US did not join the modern field of automated cyberintrusions.
Bill Pulte is the new interim director of intelligence for Donald Trump. Pulte replaces Tulsi GabbardShe recently left the position citing health problems with her husband. Trump said that he was considering others for the job. However, confirmation can take several months.
Pulte, as acting director of the US Intelligence Community, would coordinate 18 agencies, including the Central Intelligence Agency (CIA) and the NSA.

