this week in security — august 23 2026 edition
THIS WEEK, TL;DR
French spies used Bad Binder exploit to hack Encrochat phone network
Computer Weekly ($): Legendary natsec reporter Duncan Campbell is back with the absolutely incredible story of how French cyber spies cracked the security of Encrochat encrypted phones, which were used almost exclusively by criminals. The French used an Android exploit called Bad Binder (which NSO Group had previously abused to plant Pegasus spyware on people's phones) to compromise Encrochat phones, allowing a bunch of law enforcement agencies to access the communications of crime gangs and leaders. Over the years, Encrochat's hijacking and demise led to thousands of criminal sentences but with no explanation of how the evidence was obtained because the French kept the details a national security secret. Campbell provides the most detailed account thus far of how Encrochat was pwned in granular detail, in part by targeting the software update feature. This reads like a book, so get yourself a subscription, stat.
More: Europol | National Crime Agency | BBC Radio 4 | CyberWire | @hatr
Flock under fresh scrutiny after public code reveals internal AI tool that goes beyond tracking license plates
Wired ($): More excellent reporting by Wired revealing Flock's greater ambitions beyond tracking just license plates. Wired recreated an internal Flock AI tool based on client-side data that loaded in the browser while opening Flock's login pages (rookie mistake!) that showed how cops can prompt its tool to actively search for events. As explained: "An officer no longer needs a plate, a name, or a crime to begin: They supply a place, a stretch of time, and a pattern of behavior, and the system is designed to hand back the people who fit." More Flock abuses came to light this week as police departments were found not properly overseeing these surveillance systems. Flock is increasingly becoming synonymous with today's pushback against mass surveillance, but it's only the start. Flocking (no pun intended) to rivals isn't exactly much better! @mguariglia has some words on NPR about this. Of course, even amid all of this, there's always that one guy defending Flock…
More: Washington Post ($) | Tech Policy Press | @bennjordan | @evacide

Investigators say 'unprecedented’ number of Apple users got recent spyware alert
TechCrunch ($): Last week, a ton of people got an Apple threat notification delivered to their iPhones, Macs, and Apple Accounts saying they've been targeted by a mercenary spyware attack. It looks like this latest spray of notifications affected an "unprecedented" number of people, based on investigators reporting an uptick in inbound reports by around 30-40% on previous threat notifications. This suggests that this most recent batch of spyware notifications may have gone out to a broader number of people than previous cases. There's no clear reason for why, but current theories point to both the continued proliferation of spyware (including now-public rogue spyware like DarkSword) and tech giants and investigators getting better at detecting infections.
More: Apple | Citizen Lab | The Verge | Gizmodo | TechCrunch ($) | @runasand
~ ~
~this week in security~ is my weekly cybersecurity newsletter supported by readers like you. Please consider signing up for a paying subscription starting at $10/month for access to exclusive articles, analysis, and more.
You can also submit a one-time tip to show your support, or consider gifting a paid subscription.
Recent blogs include: This quick question can still expose North Korean spies in an instant | How residential proxy networks are hiding hackers in your home | When AI chatbots and LLMs get legal, check your privilege | Most fitness wearables lack end-to-end encryption and don't disclose government data demands | Online ads giant Adform was hacked, proving once again why ad blockers are necessary | A beginner's guide to analyzing the network traffic of apps and websites
~ ~
THE STUFF YOU MIGHT'VE MISSED
Wirecutter hired a hacker to give Wyze's security a second chance
Wirecutter ($): It's never good when your internet-connected security camera app shows you someone else's house, not once but twice, but that's what happened to Wyze. The company is now on its apology tour and trying to court back the tech press. Wirecutter enlisted a security researcher to give the product a thorough multi-week once-over and gave it largely a decent bill of health. That said, a truly end-to-end encrypted camera would be much better, though… like the one I used for my recent BirdCam™ escapades.
Medusa ransomware gang hits 500 organizations in five years
CISA: Bleak milestone achieved as the Medusa ransomware gang has now notched up at least 500 victims since 2021, per a new U.S. government advisory, showing that the gang is alive, kicking, and still relying on classic tactics like phishing for credentials and exploiting unpatched software. It's not AI that's coming for your network today, it's classic cyber threats that are still in play. (Hey, that rhymes!) Case in point: Hundreds of organizations currently have their AWS root keys publicly exposed, and one creepy face-checking service left an S3 bucket packed with photos publicly open to the web.
OpenAI error axes researchers from limited-access cyber program
TechCrunch ($): If you had access to OpenAI's trusted access for cyber (TAC) program but found yourself logged out and told to reverify… you might actually have to, after the AI giant cited a "technical issue" that resulted in users losing access. OpenAI also said this week that it's slowing down its training after its recent Hugging Face breach (whoops) to improve its models' security.
New malware spoofs Windows lock screens to steal login credentials
Expel: Some sneaky gits are using a new malware family that tries to steal a user’s system login credentials by creating a fake Windows lock screen. @malwaretech analyzed and broke down the malware in this detailed write-up. Back in the day, we used to get around login-prompt thefts with the "three-finger-salute" key-combo pressing Ctrl + Alt + Delete… was the last thing I said before crumbling into a pile of dust.

How residential proxy networks are hiding hackers in your home
~this week in security~: For subscribers, I dive into the shady world of residential proxy networks, which allow hackers, spies, and criminals to rent access to your home or office internet networks for reasons ranging from scraping to oh-so-much ~cyber crime~. Astonishing admin subscribers get full access to the blog to understand how these proxy networks infect ordinary devices and apps and can scale at a rapid pace, and what you can personally do about it. Thanks so much to paid subscribers for supporting long reads like this!
The hidden debt that Apple owes to the CIA
The Wall Street Journal ($): Esteemed journo Sharon Weinberger goes way back into the history archive to answer a riddle that bugged her for years. This story explores how Steve Jobs helped the CIA back in the 1980s by selling computers capable of scanning satellite imagery (particularly helpful for knowing when missile silos are being built or a military is on the move. By working with the spy agencies, Jobs got at least five years of business runway out of it, which ultimately led him to Apple.
~ ~
OTHER NEWSY NUGGETS
Eurough-week-in-cyber: Europe got a cyber battering this week, after the French confirmed cybercrooks made off with 2 million people's tax records as well as hundreds of thousands of education records, with the central government admitting that few ministries actually meet its required cyber standards. Poland, meanwhile, is probing a data breach of the MyDr healthcare software, affecting some 19 million people. And Berlin shut out two state ministries following a cyberattack. (via The Record, The Register, Infosec Sherpa)
Cutting off Salt Typhoon: During a wave of cyberattacks targeting phone and internet giants by Chinese-backed hacking group Salt Typhoon, T-Mobile largely escaped unscathed. Now we know why. In late-2024, T-Mobile's cyber team found the source of a suspected Salt Typhoon intrusion and nixed the activity by going to a nearby data center, taking out a pair of scissors, and snipping a critical cable to stop the attack. Only a telco exec would have a literal cable framed… *my eyes rolled so far back they almost detached* (via Bloomberg ($), @JZBleiberg)

U.S. sounds Siemens cyber siren: CISA and other feds warned that hackers (likely Iranian) are continuing to target water systems, specifically internet-connected Siemens programmable logic controllers, which are used to control physical systems in water providers and the like. CISA says attackers are using AI for generating exploit scripts, but worth noting that these devices were already highly vulnerable. Also: U.K. now suspects that one of its small-scale power plants was targeted in the recent wave of attacks, but that the grid wasn't in danger. (via The Telegraph ($), TechCrunch ($), Bleeping Computer)
Apollo pwned: Private equity giant Apollo is the latest big financial giant to have been hacked, per a data breach notice with California's attorney general. Point72, another investment firm, was also hacked in an earlier incident. This comes after Google warned of a wave of extortion attacks targeting financial firms. (via TechCrunch ($))
~ ~
THE HAPPY CORNER
It's the happy corner! The premier way to end a hectic cyber week.
Let's start this week on the launchpad to the International Space Station where security is tight and everything's on lockdown. Checking in now on the crew, you'd expect these top-notch astronauts will also take security seriously by using the strongest passco…. oh come on!

Moving on… the next version of Android comes with a bunch of new security features, including new notifications to protect against cell-based cyberattacks, like network downgrade attacks. Android already comes with a feature that can spot stingray attacks.
If you, like me, eschew AI as much as you can, your local friendly internet-neighborhood librarian has you covered with all the settings you need to switch off in most consumer apps to prevent or disable intrusive AI tools from working. (It's also another great reason to read this banger from Bangor about librarians helping folks to resist AI.)
On a similar note, the Associated Press has your one-sheet guide on intrusive workplace surveillance, aka bossware, which allows them to track you across your physical and digital workspace. The AP has some words about what you can do about it, and how you can learn more about what tools your employer uses.
If you need a good laugh (and honestly, who doesn't?), this extended rant about cybersecurity will have you in stitches:

Two-for-two, I'm back on another podcast! I had a great time chatting with Packet Pushers in this hour-long episode about my work, journalism, and some of the security research that I do, such as using Burp Suite ($10 off promo code!) and other tools to inspect app and website traffic for finding security bugs and stories. I also talk about some of the risks when companies make dangerous false claims about security and privacy, like claiming they're end-to-end encrypted (when they're not!), and how I approach data breach reporting. Thanks so much for having me on!
And lastly, preach this:

(Side note: I asked my partner, Jordan, if the happy corner was too long, given that this was a bit of a slow news week. "Everyone needs it," said Jordan, and honestly, I don't disagree.)
Have good news to share? Get in touch! this@weekinsecurity.com.
~ ~
CYBER CATS & FRIENDS
This week's cybercat is Piet, a mighty fine void floof who can be seen here working hard as a feline firewall defending his human's office from cyber threats — and clearly doing an incredible job. Give Piet a raise (or a treat). Thanks so much to Tom O. for sending in!

🐈 Send in your cyber cats! 🐈⬛ Got a cat or a non-feline friend? Send me an email with their photo and name and they will be featured in a later newsletter!
~ ~
SUGGESTION BOX
That's it for this week! Thank you again as always for reading, subscribing, and supporting this newsletter (and blog). It's a real joy to get to put out these words every week, and I'm incredibly grateful for your trust.
If there's anything you think would be a good fit for next week's newsletter, drop me a note — I love hearing from you! In the meantime, feel free to share this edition on your socials, or feel free to forward to a colleague or friend.
I'm off in search for breakfast. After a few days of rain storms, the sun is out, the skies are clear, and somewhere nearby, there's an everything bagel with my name on it.
Catch you next week,
@zackwhittaker