Big news: Lock and Code is nominated for a Webby Award! You can help us win the People’s Voice Award by voting here. This week on the Lock and Code podcast… We have to talk about killer robots. No, not the Terminator, and not some Boston Dynamics robot run amok. We have to talk instead about a technological reality that is very much already here. In late February, the artificial intelligence developer Anthropic made a perhaps surprising statement for those who are only familiar with its helpful chatbot tool Claude: The company would not allow the government to use its technology to kill people without proper safety controls. Hold on… what? Despite Anthropic’s reputation amongst most everyday people as the creator of a collaborative AI-powered assistant for coding, writing, and searching, the company had already deployed Claude across the US government for strategic military needs. According to Anthropic, Claude was used by the US Department of Defense and other national security agencies for “mission-critical applications, such as intelligence analysis, modeling and simulation, operational planning, cyber operations, and more.” But behind the scenes, the US government was asking for even more applications, and it wrapped all of its requests under a broad, vague term: “Any lawful use.” Anthropic bristled at the government’s request, defining two use-cases that were simply off limits: Mass surveillance of Americans and fully autonomous weapons—or, put another way, the powering of independent killer robots. As Anthropic said in its statement: “Frontier AI systems are simply not reliable enough to power fully autonomous weapons. We will not knowingly provide a product that puts America’s warfighters and civilians at risk. We have offered to work directly with the Department of War on R&D to improve the reliability of these systems, but they have not accepted this offer. In addition,
Apr 6, 2026 · via malwarebytes.com
Adversarial AI in Cybersecurity: Poisoning, Evasion, and Prompt-Injection Threats (and How to Mitigate Them) Adversarial AI in cybersecurity is no longer a niche research concern. It is an operational reality where attackers deliberately manipulate machine learning (ML) and generative AI systems so defenses malfunction, often without obvious signs of tampering. As AI becomes embedded across email security, endpoint detection, fraud prevention, and SOC workflows, adversaries are using the same technologies to increase the speed, scale, and sophistication of attacks. Recent threat reporting indicates AI-enabled adversaries increased attacks by 89% compared to 2024, while zero-days exploited before public disclosure rose 42% year-over-year. Cloud-conscious intrusions grew 37%, and fake CAPTCHA lures surged 563%, reflecting how quickly attackers adapt their tactics when AI is involved. Understanding the core adversarial AI attack categories is now essential for any security program that relies on ML models or uses LLM-based tools. What Is Adversarial AI in Cybersecurity? Adversarial AI refers to techniques that intentionally cause AI systems to make wrong decisions. In cybersecurity, that can mean: Training data is manipulated so a model learns unsafe patterns. Inputs are crafted so detection models misclassify malicious activity as benign. LLM tools are coerced via prompt injection to reveal secrets or perform unsafe actions. This matters because it targets the decision-making layer itself. If your detection pipeline, triage process, or automated response relies on AI, compromising the model can compromise outcomes at machine speed. The Three Core Threat Categories: Poisoning, Evasion, and Prompt Injection 1) Data Poisoning Attacks Data poisoning happens when an attacker introduces altered, misleading, or strategically crafted data into a training dataset. The goal is to degrade accuracy, bias outcomes, or create blind spots that persist after deployment. In security contexts, poisoning can quietly erode protections over time. If a model is trained to detect malicious
Apr 5, 2026 · via blockchain-council.org
Business FG moves to strengthen cybersecurity as NDPC reviews data protection compliance The Federal Government has signalled its intention to work collaboratively with the private sector and key stakeholders towards the establishment of a Cybersecurity Coordination Council. This initiative is aimed at strengthening Nigeria’s collective cyber resilience and enhancing coordinated responses to evolving cyber threats across both the public and private sectors. The plan announced by the Minister of Communications, Innovation and Digital Economy, Dr Bosun Tijani, underscores a broader policy direction centred on partnership and shared responsibility. “Cybersecurity is a shared national responsibility. Protecting Nigeria’s digital economy requires strong partnerships, trusted collaboration, and collective vigilance across government, industry, and civil society,” he emphasized. “Through collaborative action and sustained engagement, we are strengthening Nigeria’s capacity to detect threats early, respond effectively, and build a resilient and trusted digital ecosystem.” The minister encouraged cross-sector participation, noting that stakeholders must help shape “a sustainable, partnership-led cybersecurity model capable of deterring cybercriminal activity and protecting citizens, businesses, and national digital infrastructure.” Meanwhile, the Nigeria Data Protection Commission (NDPC) has confirmed that it is carrying out an ongoing investigation across the data protection ecosystem in line with its statutory mandate. A statement by Babatunde Bamigboye, Head, Legal, Enforcement & Regulations, said the agency is probing the alleged data breach involving Remita Payment Services Ltd., Sterling Bank and other entities. “In line with the Commission’s procedure, Notice of Investigation was duly served on the 1st of April, 2026. Relevant parties and individuals have been providing information for the purpose of addressing the incident,” Bamigboye noted. “The aim of the investigation is to ensure that data subjects are protected with appropriate technical and organisational measures. The investigation by NDPC covers, among others, the types of personal data involved, the nature and scope of the alleged breach,
Apr 5, 2026 · via dailypost.ng
Maine House rejects hospital cybersecurity bill after recent attacks
AUGUSTA, Maine (WGME) -- Earlier this week at the state house, the Maine House unanimously voted against a bill which would have helped prevent cybersecurity attacks on Maine hospitals.
The bill would require hospitals to adopt a cybersecurity plan and include provisions for hospitals to notify law enforcement in case of an attack, as well as establish backup communication systems.
The bill sponsor believes these changes would help to ensure continuity of patient care, and protect patient data.
Last year, two separate cyber-incidents breached data from five hospitals across Maine.
JOIN THE CONVERSATION (2)
The attacks threatened patient care for weeks.
Apr 5, 2026 · via wgme.com
West Virginia Gives CISO Greater Authority to Lead Statewide Cybersecurity Program What happened West Virginia approved legislation that gives the state’s chief information security officer greater authority to lead and standardize cybersecurity efforts across state government. Gov. Patrick Morrisey signed the measure on Thursday. The law directs the state’s Cybersecurity Office, led by Leroy Amos within the Office of Technology, to develop statewide cybersecurity policies and standards as a framework for uniform compliance with industry best practices. The bill was brought forward at the request of the state’s Department of Administration after a legislative audit found the state had not implemented a statewide cybersecurity framework to the specifications required in statute. Who is affected The direct impact falls on West Virginia state government agencies and the state’s Cybersecurity Office, which is now tasked with implementing more consistent statewide cybersecurity standards. The legislation is aimed at creating a more centralized approach to compliance and oversight across agencies rather than relying on separate ad hoc efforts. Why CISOs should care This move matters because it strengthens centralized cyber governance at the state level and gives the CISO a clearer mandate to drive uniform standards across government systems. It also follows an audit that found gaps between what state law required and what had actually been rolled out, showing how governance, reporting, and implementation can become legislative and operational issues when statewide programs are not fully executed. 3 practical actions - Use audit findings to tighten cyber governance: Treat external reviews and legislative audits as opportunities to close the gap between documented cybersecurity requirements and actual statewide implementation. - Centralize standards where oversight is fragmented: Build a single framework for cybersecurity policies and compliance when agency-by-agency efforts are creating uneven protection and reporting. - Clarify CISO authority in statute or policy: Ensure the
Apr 5, 2026 · via securityboulevard.com
Anthropic warns cybersecurity has hit turning point Apr 4, 2026 7 hrs ago Facebook Twitter WhatsApp SMS Email Print Copy article link Save COPYRIGHT 2026 BY CHANNEL 3000. ALL RIGHTS RESERVED. THIS MATERIAL MAY NOT BE PUBLISHED, BROADCAST, REWRITTEN OR REDISTRIBUTED. Tags Video Facebook Twitter WhatsApp SMS Email Print Copy article link Save Most Popular Latest News News 3 Now at Six: April 4, 2026 UW-Whitewater breaking ground on Winther, Heide halls later this month Trump gives Iran 48 hours to open Strait of Hormuz as search continues for missing US pilot Virginia man discovers dad's artwork from WWII buried for decades Weekend Mornings: April 4, 2026 More News
Apr 5, 2026 · via channel3000.com
The Federal Bureau of Investigation (FBI) has officially classified the recent breach of its surveillance system, carried out by Chinese hackers, as a ‘Serious Incident.’ This was reported by Politico. This status is assigned only to cyber intrusions that pose a significant threat to US national security, foreign policy, or the country’s economic interests. The hackers gained access to the digital data collection network, also known as DCS-3000 or Red Hook. This system stores the results of lawful data interception, including phone numbers, call metadata, and information about the internet traffic of subjects under investigation. Although the system does not record the content of conversations, it contains confidential information about exactly who law enforcement agencies are monitoring, which is extremely valuable to foreign intelligence services. Investigators determined that the attackers did not penetrate the bureau’s internal network directly, but rather through the infrastructure of a third-party provider—a commercial internet service provider. This ‘supply chain attack’ method allowed the hackers to remain undetected for some time. FBI analysts first detected suspicious activity on February 17, 2026, at the bureau’s offices in the Virgin Islands. Under the Federal Information Security Management Act (FISMA), classifying the event as a ‘Serious Incident’ requires the agency to notify Congress within seven days and involve the Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) in the response. Currently, the White House and intelligence agencies are continuing to assess the full extent of the breach and are attempting to determine whether the hackers gained access to data regarding active counterintelligence investigations. Earlier, Militarnyi reported that Iran-linked hackers from the Handala Hack Team had hacked into FBI Director Kash Patel’s personal email and published some of the data online. A representative of the US Department of Justice confirmed to the publication that Patel’s email
Apr 4, 2026 · via militarnyi.com
- United States - / - Capital Markets - / - NasdaqGS:COIN Reassessing Coinbase Global (COIN) Valuation After Recent Share Price Weakness And Cybersecurity Concerns Recent performance snapshot With no single fresh headline driving attention today, Coinbase Global (COIN) is back in focus as investors reassess the stock after a one-month return decline of 17% and a past three-month return decline of 28%. See our latest analysis for Coinbase Global. The recent 7 day share price return of 6.4% sits against a weaker backdrop, with a 30 day share price return of a 16.6% decline and a year-to-date share price return of a 27.5% decline. At the same time, the 3 year total shareholder return of about 18x the original investment highlights how sentiment around Coinbase Global’s growth potential and risk profile has shifted over time. If you are comparing Coinbase Global with other crypto exposed names, now can be a good time to scan the market using our screener for 22 cryptocurrency and blockchain stocks So with Coinbase Global still carrying a very large multi year total return, but facing recent share price weakness and trading at a discount to analyst price targets, is this a fresh entry point or is future growth already priced in? Most Popular Narrative: 17% Overvalued Coinbase Global last closed at $171.46, while the most followed narrative, according to Ramilk, places fair value closer to $146.54 based on a discounted cash flow approach that uses an 8.2% discount rate. The Bybit explosion in February 2025 was one of the largest cybersecurity events in the history of digital assets. A sophisticated social engineering attack on a third party wallet provider allowed attackers to authorise illegitimate transfers and drain over 400 000 Ethereum worth over $1.4 billion USD, sending shockwaves through the market and highlighting persistent
Apr 4, 2026 · via simplywall.st
LinkedIn is spying on you, according to a new 'BrowserGate' security report — scripts stealthily scan visitors' browsers for over 6,000 Chrome extensions and harvest hardware data BleepingComputer independently confirmed the fingerprinting script. Get Tom's Hardware's best news and in-depth reviews, straight to your inbox. You are now subscribed Your newsletter sign-up was successful LinkedIn is understood to be injecting a JavaScript fingerprinting script into every page load that probes visitors' browsers for 6,236 installed Chrome extensions and collects detailed device telemetry, according to a report by Fairlinked e.V. and independently confirmed by BleepingComputer. The script, which BleepingComputer verified through its own testing, also harvests the CPU core count, available memory, screen resolution, time zone, language settings, and battery status. The findings were first published in Fairlinked’s “BrowserGate” report, which claims the script works by attempting to access file resources tied to specific extension IDs, a well-documented technique for detecting whether extensions are installed in Chromium-based browsers. A GitHub repo documented LinkedIn scanning for roughly 2,000 extensions in 2025, while a separate repo from February this year logged approximately 3,000. The current count stands at 6,236. Many of the targeted extensions are LinkedIn-related tools, including sales intelligence products from Apollo, Lusha, and ZoomInfo that directly compete with LinkedIn's offerings. The Fairlinked report claims that LinkedIn scans more than 200 competing products in total and that the script also checks for language and grammar extensions, tools for tax professionals, and other categories with no obvious connection to LinkedIn's platform. Article continues belowBeyond extensions, the script gathers hardware and software fingerprinting data, such as CPU class, device memory, screen dimensions, time zone offset, battery status, and storage capabilities. These data points are commonly used in browser fingerprinting to build unique device profiles, but because LinkedIn accounts are tied to real names, employers,
Apr 4, 2026 · via tomshardware.com
For security leaders, AI has created a new governance challenge. The question is no longer just where data goes. It's whether your team can see what is being entered into AI tools, understand the context, and enforce policy before sensitive data is exposed. That is the focus of the upcoming live webinar, Can Your DLP Do This? We'll show how organizations can move beyond coarse blocking to a more effective approach for governing employee AI use and agent activity. April 21 | 9:00 AM PT / 12:00 PM ET ✅ Register here: https://lnkd.in/e37TVmkM #AIAtWork #AISecurity #AIGovernance The Cyber Security Hub™’s Post More from this author Explore content categories - Career - Productivity - Finance - Soft Skills & Emotional Intelligence - Project Management - Education - Technology - Leadership - Ecommerce - User Experience - Recruitment & HR - Customer Experience - Real Estate - Marketing - Sales - Retail & Merchandising - Science - Supply Chain Management - Future Of Work - Consulting - Writing - Economics - Artificial Intelligence - Employee Experience - Workplace Trends - Fundraising - Networking - Corporate Social Responsibility - Negotiation - Communication - Engineering - Hospitality & Tourism - Business Strategy - Change Management - Organizational Culture - Design - Innovation - Event Planning - Training & Development This is a really important shift — governance is moving closer to the point of input, not just output. But it raises a bigger question: how much visibility do we actually have over what becomes discoverable in the first place? If discovery itself is shaped by optimisation and bias, then governance is always working downstream of that. There may be a missing layer here before data even reaches AI systems.
Apr 4, 2026 · via linkedin.com
Cybersecurity Week promotes digital awareness in schools
Published: 06:04 PM,Apr 04,2026 | EDITED : 10:04 PM,Apr 04,2026
Al RUSTAQ: The Directorate-General of Education in Al Batinah South Governorate organised Cybersecurity Week under the theme 'Sustainable Cyber Culture... Digitally Empowered Generations,' aimed at strengthening the preparedness of educational institutions and keeping pace with evolving technological challenges.
The programme featured visual presentations, specialised working papers, and the 'Digital Fortress' exhibition, which showcased simulations of cyber threats alongside student-led cybersecurity projects.
Sultan bin Hamad al Hashimi, Director of the Information and Communications Technology Department at the Directorate, said the initiative seeks to promote the safe use of modern technologies and raise awareness of digital risks through a range of programmes, lectures and competitions.
The week-long event reflects ongoing efforts to build a strong cybersecurity culture among students and educators, equipping them with the knowledge and skills needed to navigate an increasingly digital world. — ONA
Apr 4, 2026 · via omanobserver.om
Cybersecurity Incident Updates
On March 28, 2026 Hasbro, Inc. identified a security incident impacting certain Hasbro systems. We’re still assessing the scope of the impact, and as a proactive measure have taken select systems offline while we remediate the situation. Our teams have been working around the clock with leading cybersecurity experts to implement containment measures and protect our data. We have also been in close contact with our employees and partners to keep them informed as our investigation continues.
Hasbro is open for business: we are taking and shipping orders globally and have shipped orders this week on time including Magic: The Gathering and toys and games.
While the interim measures to safeguard our systems may result in minor delays, we are working to restore our systems as quickly as possible. Hasbro Pulse, D&D Beyond and Magic: The Gathering Arena were not affected by this incident and are running business as usual.
We will update this page with further details as our investigation progresses.
Apr 4, 2026 · via newsroom.hasbro.com
A cyberattack on the popular JavaScript library Axios has put developers and companies worldwide at risk. Threat actors managed to access the main administrator's account on npm, the repository where these libraries are downloaded, and uploaded fake versions of the package that included RAT (remote access trojan) malware capable of remotely controlling devices. The compromised versions are axios@1.14.1 and axios@0.30.4. Upon installation, a script was automatically executed that downloaded a virus compatible with Windows, macOS, and Linux, without the user noticing. With this installed, cybercriminals can perform countless malicious activities on the compromised devices. Additionally, the malware was designed to self-destruct after infection, making detection difficult. For greater 'camouflage,' it replaces files with clean versions. Attacking the source This type of threat, known as a 'supply chain attack,' does not directly affect users but rather the tools that millions of developers use every day. In the case of Axios, this is especially concerning, as the library is downloaded more than 100 million times per week, rapidly multiplying the reach of the incursion. Although the attack was active for less than three hours, it was enough for several projects to be compromised, including automated development pipelines and enterprise environments. Experts recommend those who have installed these versions avoid using them, review their systems, and strengthen the security of their npm accounts. A cyberattack on the popular JavaScript library Axios has put developers and companies worldwide at risk. Threat actors managed to access the main administrator's account on npm, the repository where these libraries are downloaded, and uploaded fake versions of the package that included RAT (remote access trojan) malware capable of remotely controlling devices. The compromised versions are axios@1.14.1 and axios@0.30.4. Upon installation, a script was automatically executed that downloaded a virus compatible with Windows, macOS, and Linux, without the user
Apr 4, 2026 · via escudodigital.com
New Story
Librarians vs "Data Cartels": What's Going On?
by
April 4th, 2026
byThe Markup@TheMarkup
Nonprofit organization dedicated to data-driven tech accountability journalism & privacy protection.
About Author
Nonprofit organization dedicated to data-driven tech accountability journalism & privacy protection.
Apr 4, 2026 · via hackernoon.com
The performance data shown in tables and graphs on this page is calculated in GBX of the fund/index/average (as applicable), on a Bid To Bid / Nav to Nav basis, with gross dividends re-invested on ex-dividend date. Past performance is not necessarily a guide to future performance; unit prices may fall as well as rise. The videos and white papers displayed on this page have not been devised by The Financial Times Limited ("FT"). FT has not selected, modified or otherwise exercised control over the content of the videos or white papers prior to their transmission, or their receipt by you. The videos, white papers and other documents displayed on this page are paid promotional materials provided by the fund company. Any prospectus you view on this page has not been approved by FT and FT is not responsible for the content of the prospectus. The information made available to you does not constitute the giving of investment advice or an offer to sell or the solicitation of an offer to buy any security of any enterprise in any jurisdiction. The securities listed above are not registered and will not be registered for sale in the United Sates and cannot be purchased by U.S. investors as the securities can only be purchased in jurisdictions where they have been registered for sale or where an exemption from registration applies. The offer, sale or delivery of the securities within the United States or to, or for the account or benefit of, U.S. Persons is not permitted except pursuant to an exemption from registration under U.S. securities laws, which may not be available; and the availability of the information through the website does not alter or change the persons eligible to purchase the security. All content on FT.com is for your general information
Apr 4, 2026 · via markets.ft.com
Complete Payroll Solutions (CPS) agreed to a $2.6 million class action settlement to resolve claims it failed to prevent a 2024 data breach that compromised sensitive employee information. The Complete Payroll Solutions settlement benefits individuals who received a data breach notice from Complete Payroll Solutions regarding a March 2024 data breach. The Complete Payroll Solutions data breach occurred around March 10, 2024, and compromised sensitive employee information, such as Social Security numbers, driver’s license numbers, financial data and health insurance information. Plaintiffs in the data breach class action lawsuit claim the company could have prevented the breach through reasonable cybersecurity measures. Complete Payroll Solutions is a payroll and human resources company that serves businesses across the country. CPS has not admitted any wrongdoing but agreed to a $2.6 million settlement to resolve the Complete Payroll Solutions data breach class action lawsuit. Under the terms of the Complete Payroll Solutions class action settlement, class members can receive up to $5,000 for documented monetary losses related to the Complete Payroll Solutions data breach. These losses can include out-of-pocket credit monitoring costs, unreimbursed fraud or identity theft losses, bank fees, communication charges and mileage. Class members can also receive a cash payment from the settlement. Each claimant is estimated to receive $100, but this amount may increase or decrease depending on the number of claims filed with the class action settlement. All class members are eligible for three years of credit monitoring through the settlement. This benefit includes one-bureau credit monitoring, dark web monitoring, $1 million in identity theft insurance and fully managed identity recovery services. The deadline for exclusion and objection is May 19, 2026. The final approval hearing for the Complete Payroll Solutions data breach settlement is scheduled for June 25, 2026. To receive settlement benefits, class members must submit a
Apr 4, 2026 · via topclassactions.com
The South Asian Business Council of Virginia (SABCVA) celebrated the graduation of participants from its AI and Cybersecurity Internship Program at a sold-out conference held March 29, 2026, at the Hyatt Regency Dulles. According to a statement from SABCVA, the event underscored the organization’s expanding efforts to create workforce opportunities in high-demand technology sectors while promoting community empowerment. The ceremony recognized young professionals who completed intensive internship programs offering hands-on experience in artificial intelligence and cybersecurity, two fields that continue to drive innovation and economic growth across the United States. The conference drew hundreds of attendees, including Congressman Suhas Subramanyam, State Senator Kannan Srinivasan, Delegate Atoosa Reaser, and Loudoun County Treasurer Henry Eickelberg, along with business leaders, entrepreneurs, and community advocates. Certificates were presented by former Virginia Secretary of Commerce and Trade Juan Pablo Segura and Eickelberg, highlighting the “importance of this initiative within the broader workforce development landscape.” In addition to honoring the graduates, SABCVA presented the Best Leadership Award to Sadiq Ahmed, a Solutions Architect in AI who represents organizations such as Microsoft at national and international levels, in recognition of his mentorship of interns. “His guidance and expertise played a critical role in helping students gain confidence, technical knowledge, and practical experience, bridging the gap between education and career readiness,” the statement noted. SABCVA announced that it has facilitated 100 internships in AI and cybersecurity, specifically designed for individuals with limited or no prior experience in these fields. “These internships are shaping the careers of our youth, and several participants have already secured positions with leading companies,” said Samara Mansoor, program leader. Mansoor Qureshi, Chair of SABCVA, added: “This is just the beginning. Over the next two years, we plan to expand our internship programs to reach 1,000 students across Virginia. Every young professional deserves access, mentorship,
Apr 4, 2026 · via southasianherald.com
Nancy Guthrie Update: FBI’s ‘Best Lead,’ According to a Cybersecurity Expert What To Know - Nancy Guthrie, mother of Today co-anchor Savannah Guthrie, remains missing after her February 1 abduction from her Tucson, Arizona home.. - Cybersecurity expert Ari Redbord explained that the FBI considers tracing the Bitcoin ransom payments as their “best lead.” - Investigators are using blockchain analysis tools to track the flow of funds and potentially identify those behind the abduction by linking cryptocurrency addresses to known threat actors. Today co-anchor Savannah Guthrie‘s mother, Nancy Guthrie, is still missing following the February 1 abduction from her Tucson, Arizona, home. And recently, Nancy Grace spoke to a cybersecurity and cryptocurrency expert about the “best lead” in the 84-year-old’s case. In the April 2 episode of Crime Stories with Nancy Grace, the Fox Nation journalist interviewed Ari Redbord, who works as TRM Labs’ global head of policy. They discussed Bitcoin and how that might ultimately solve the case. “Many people believe that Bitcoin cannot be traced, and tonight we are learning the FBI believes that’s their best lead on who took Miss Guthrie,” Grace said before introducing Redbord. Grace said that she thinks the video of “porch guy” and the footage of cars driving in the neighborhood during the early morning hours of February 1 are what could crack the case. However, she also brought up the ransom notes that Savannah and her siblings received early in the investigation — and specifically, whether the Bitcoin address can be traced. “Look, anytime that there’s a cryptocurrency address involved in a case, it’s an immediate lead,” Redbord explained. “And what most people don’t understand about cryptocurrency is every transaction occurs on a public blockchain, particularly Bitcoin, which is public. Meaning every transaction is traceable, trackable, and immutable. In other words, it’s
Apr 4, 2026 · via tvinsider.com
Imagine this: you’re asking ChatGPT to help with something you really don’t want anyone else to see. Maybe it’s a lab report with your name on it. Maybe it’s a resignation letter you haven’t sent yet. Maybe it’s a contract, a financial spreadsheet, or a private message you’re trying to word carefully. You assume it stays between you and your “personal assistant’ until you approve sending it somewhere else. But the Israeli cybersecurity company Check Point’s research says that assumption may not have always held up. The company found a weakness in ChatGPT’s system that could allow someone to extract data without triggering any alarms. According to Check Point Software Technologies, there is a small hole in the code that could be used to move data around without triggering the usual alert warnings. OpenAI said in late 2025 that it was serving more than 800 million users a week, and separate OpenAI research found users were already sending about 18 billion messages weekly by July 2025. People don’t just use it for jokes or curiosity. They use it to review spreadsheets, summarize contracts, draft emails, write code, polish presentations, and make sense of medical or financial language that can feel overwhelming on its own. We are not just talking about a chatbot that people use for fun every now and then. This is a system that many people use as a helper for their work, a partner for writing, a tool for research, and sometimes even as someone to talk to about personal decisions. If there is a hidden flaw in a system like this, it is not just a problem with the technology. It is a problem with trust. Check Point said the flaw sat inside the runtime ChatGPT uses for data analysis and Python-based tasks. You can think
Apr 4, 2026 · via jpost.com
Trump’s new app has no privacy policy and uses Russian software U.S. President Donald Trump with Russian President Vladimir Putin in 2018 (Wikimedia Commons) April 03, 2026 | 04:51PM ETFrontpage news and politicsPresident Donald Trump has been promoting the White House’s new mobile app — pushing it to become the third-most downloaded item on Apple’s popular App Store. But the app reportedly has numerous cybersecurity vulnerabilities, does not properly disclose the data it shares, and uses software components from a Russia-founded company. “Cybersecurity researchers warn that the White House’s new app regularly shares users’ IP addresses, time zones and other data to third-party services,” NOTUS reports. “But most of its users wouldn’t know that, because the app doesn’t disclose its data sharing the way most others do.” Cybersecurity experts were shocked by the app’s “slipshod” approach to cybersecurity, especially as it is essentially a product of the White House, and especially since the U.S. is at war. “The U.S. government’s infrastructure is being attacked from all sides right now, and having an amateur WordPress developer running the White House’s public presence puts everybody who visits it at risk,” Philip Fields, a cybersecurity researcher and former FBI intelligence analyst, told NOTUS. He explains that if this were just a small business’ “random app,” it would not be a story. “But it’s not,” Fields added. “This is the White House.” Additionally, the app reportedly has left users and some White House staffers vulnerable. One researcher showed NOTUS screenshots revealing that a Russia-founded software kit company that “provides premade widgets for the app makes public the personal information of some White House staffers through the app.” NOTUS chose to not disclose the staffers’ personal information. Cybersecurity experts also told NOTUS that the data collected by the White House is not being properly disclosed.
Apr 4, 2026 · via alternet.org