10 min read

this week in security — august 23 2026 edition

Mystery solved of how cops cracked Encrochat, Flock code leak looks beyond license plates, Apple spyware alert hits 'unprecedented' number of users, Windows lock-screen hack, why residential proxy networks are a major threat, and more.
~ ~

French spies used Bad Binder exploit to hack Encrochat phone network
Computer Weekly ($): Legendary natsec reporter Duncan Campbell is back with the absolutely incredible story of how French cyber spies cracked the security of Encrochat encrypted phones, which were used almost exclusively by criminals. The French used an Android exploit called Bad Binder (which NSO Group had previously abused to plant Pegasus spyware on people's phones) to compromise Encrochat phones, allowing a bunch of law enforcement agencies to access the communications of crime gangs and leaders. Over the years, Encrochat's hijacking and demise led to thousands of criminal sentences but with no explanation of how the evidence was obtained because the French kept the details a national security secret. Campbell provides the most detailed account thus far of how Encrochat was pwned in granular detail, in part by targeting the software update feature. This reads like a book, so get yourself a subscription, stat.
More: Europol | National Crime Agency | BBC Radio 4 | CyberWire | @hatr

Flock under fresh scrutiny after public code reveals internal AI tool that goes beyond tracking license plates
Wired ($): More excellent reporting by Wired revealing Flock's greater ambitions beyond tracking just license plates. Wired recreated an internal Flock AI tool based on client-side data that loaded in the browser while opening Flock's login pages (rookie mistake!) that showed how cops can prompt its tool to actively search for events. As explained: "An officer no longer needs a plate, a name, or a crime to begin: They supply a place, a stretch of time, and a pattern of behavior, and the system is designed to hand back the people who fit." More Flock abuses came to light this week as police departments were found not properly overseeing these surveillance systems. Flock is increasingly becoming synonymous with today's pushback against mass surveillance, but it's only the start. Flocking (no pun intended) to rivals isn't exactly much better! @mguariglia has some words on NPR about this. Of course, even amid all of this, there's always that one guy defending Flock…
More: Washington Post ($) | Tech Policy Press | @bennjordan | @evacide

a screenshot from a San Diego city council live stream featuring a speaker talking about Flock dressed as Darth Vader.

Investigators say 'unprecedented’ number of Apple users got recent spyware alert
TechCrunch ($): Last week, a ton of people got an Apple threat notification delivered to their iPhones, Macs, and Apple Accounts saying they've been targeted by a mercenary spyware attack. It looks like this latest spray of notifications affected an "unprecedented" number of people, based on investigators reporting an uptick in inbound reports by around 30-40% on previous threat notifications. This suggests that this most recent batch of spyware notifications may have gone out to a broader number of people than previous cases. There's no clear reason for why, but current theories point to both the continued proliferation of spyware (including now-public rogue spyware like DarkSword) and tech giants and investigators getting better at detecting infections.
More: Apple | Citizen Lab | The Verge | Gizmodo | TechCrunch ($) | @runasand

Wirecutter hired a hacker to give Wyze's security a second chance
Wirecutter ($): It's never good when your internet-connected security camera app shows you someone else's house, not once but twice, but that's what happened to Wyze. The company is now on its apology tour and trying to court back the tech press. Wirecutter enlisted a security researcher to give the product a thorough multi-week once-over and gave it largely a decent bill of health. That said, a truly end-to-end encrypted camera would be much better, though… like the one I used for my recent BirdCam™ escapades.

Medusa ransomware gang hits 500 organizations in five years
CISA: Bleak milestone achieved as the Medusa ransomware gang has now notched up at least 500 victims since 2021, per a new U.S. government advisory, showing that the gang is alive, kicking, and still relying on classic tactics like phishing for credentials and exploiting unpatched software. It's not AI that's coming for your network today, it's classic cyber threats that are still in play. (Hey, that rhymes!) Case in point: Hundreds of organizations currently have their AWS root keys publicly exposed, and one creepy face-checking service left an S3 bucket packed with photos publicly open to the web.

OpenAI error axes researchers from limited-access cyber program
TechCrunch ($): If you had access to OpenAI's trusted access for cyber (TAC) program but found yourself logged out and told to reverify… you might actually have to, after the AI giant cited a "technical issue" that resulted in users losing access. OpenAI also said this week that it's slowing down its training after its recent Hugging Face breach (whoops) to improve its models' security.

New malware spoofs Windows lock screens to steal login credentials 
Expel:
Some sneaky gits are using a new malware family that tries to steal a user’s system login credentials by creating a fake Windows lock screen. @malwaretech analyzed and broke down the malware in this detailed write-up. Back in the day, we used to get around login-prompt thefts with the "three-finger-salute" key-combo pressing Ctrl + Alt + Delete… was the last thing I said before crumbling into a pile of dust.

a screenshot of what looks like a Windows login/lock screen, but it's actually malware made to look like it, so that the hackers can steal the person's login credentials. it has an overlay that says, "FAKE" in big-stamped red letters.

How residential proxy networks are hiding hackers in your home
~this week in security~: For subscribers, I dive into the shady world of residential proxy networks, which allow hackers, spies, and criminals to rent access to your home or office internet networks for reasons ranging from scraping to oh-so-much ~cyber crime~. Astonishing admin subscribers get full access to the blog to understand how these proxy networks infect ordinary devices and apps and can scale at a rapid pace, and what you can personally do about it. Thanks so much to paid subscribers for supporting long reads like this!

The hidden debt that Apple owes to the CIA
The Wall Street Journal ($): Esteemed journo Sharon Weinberger goes way back into the history archive to answer a riddle that bugged her for years. This story explores how Steve Jobs helped the CIA back in the 1980s by selling computers capable of scanning satellite imagery (particularly helpful for knowing when missile silos are being built or a military is on the move. By working with the spy agencies, Jobs got at least five years of business runway out of it, which ultimately led him to Apple.

Eurough-week-in-cyber: Europe got a cyber battering this week, after the French confirmed cybercrooks made off with 2 million people's tax records as well as hundreds of thousands of education records, with the central government admitting that few ministries actually meet its required cyber standards. Poland, meanwhile, is probing a data breach of the MyDr healthcare software, affecting some 19 million people. And Berlin shut out two state ministries following a cyberattack. (via The Record, The Register, Infosec Sherpa)

Cutting off Salt Typhoon: During a wave of cyberattacks targeting phone and internet giants by Chinese-backed hacking group Salt Typhoon, T-Mobile largely escaped unscathed. Now we know why. In late-2024, T-Mobile's cyber team found the source of a suspected Salt Typhoon intrusion and nixed the activity by going to a nearby data center, taking out a pair of scissors, and snipping a critical cable to stop the attack. Only a telco exec would have a literal cable framed… *my eyes rolled so far back they almost detached* (via Bloomberg ($), @JZBleiberg

a photo of a yellow cable that has been snipped in half, framed, that reads: "Vigilant by design, secure by action," following the Salt Typhoon attack of 2024.

U.S. sounds Siemens cyber siren: CISA and other feds warned that hackers (likely Iranian) are continuing to target water systems, specifically internet-connected Siemens programmable logic controllers, which are used to control physical systems in water providers and the like. CISA says attackers are using AI for generating exploit scripts, but worth noting that these devices were already highly vulnerable. Also: U.K. now suspects that one of its small-scale power plants was targeted in the recent wave of attacks, but that the grid wasn't in danger. (via The Telegraph ($), TechCrunch ($), Bleeping Computer)

Apollo pwned: Private equity giant Apollo is the latest big financial giant to have been hacked, per a data breach notice with California's attorney general. Point72, another investment firm, was also hacked in an earlier incident. This comes after Google warned of a wave of extortion attacks targeting financial firms. (via TechCrunch ($))

It's the happy corner! The premier way to end a hectic cyber week.

Let's start this week on the launchpad to the International Space Station where security is tight and everything's on lockdown. Checking in now on the crew, you'd expect these top-notch astronauts will also take security seriously by using the strongest passco…. oh come on!

an animated GIF of an astronaut on an iPad, entering the passcode "1111" on the live stream.

Moving on… the next version of Android comes with a bunch of new security features, including new notifications to protect against cell-based cyberattacks, like network downgrade attacks. Android already comes with a feature that can spot stingray attacks.

If you, like me, eschew AI as much as you can, your local friendly internet-neighborhood librarian has you covered with all the settings you need to switch off in most consumer apps to prevent or disable intrusive AI tools from working. (It's also another great reason to read this banger from Bangor about librarians helping folks to resist AI.)

On a similar note, the Associated Press has your one-sheet guide on intrusive workplace surveillance, aka bossware, which allows them to track you across your physical and digital workspace. The AP has some words about what you can do about it, and how you can learn more about what tools your employer uses.

If you need a good laugh (and honestly, who doesn't?), this extended rant about cybersecurity will have you in stitches:

a photo of comedian Julian Cross, in a grassy field, with the overlay text: "I'm so tired of having to change my password every two weeks."

Two-for-two, I'm back on another podcast! I had a great time chatting with Packet Pushers in this hour-long episode about my work, journalism, and some of the security research that I do, such as using Burp Suite ($10 off promo code!) and other tools to inspect app and website traffic for finding security bugs and stories. I also talk about some of the risks when companies make dangerous false claims about security and privacy, like claiming they're end-to-end encrypted (when they're not!), and how I approach data breach reporting. Thanks so much for having me on! 

And lastly, preach this:

Dan McQuillan post on Bluesky, which has a photo of a bearded man setting up a tent, outside, at peace in nature, with the text that reads: "Treat your body like a data centre. Consume as much water and literature as possible. Upset local city councils with your existence."

(Side note: I asked my partner, Jordan, if the happy corner was too long, given that this was a bit of a slow news week. "Everyone needs it," said Jordan, and honestly, I don't disagree.)

Have good news to share? Get in touch! this@weekinsecurity.com.

This week's cybercat is Piet, a mighty fine void floof who can be seen here working hard as a feline firewall defending his human's office from cyber threats — and clearly doing an incredible job. Give Piet a raise (or a treat). Thanks so much to Tom O. for sending in!

Piet is a beautiful jet black void floof kitty who can be seen laying on their human's desk in front of two monitors.

🐈 Send in your cyber cats! 🐈‍⬛ Got a cat or a non-feline friend? Send me an email with their photo and name and they will be featured in a later newsletter!

That's it for this week! Thank you again as always for reading, subscribing, and supporting this newsletter (and blog). It's a real joy to get to put out these words every week, and I'm incredibly grateful for your trust.

If there's anything you think would be a good fit for next week's newsletter, drop me a note — I love hearing from you! In the meantime, feel free to share this edition on your socials, or feel free to forward to a colleague or friend.

I'm off in search for breakfast. After a few days of rain storms, the sun is out, the skies are clear, and somewhere nearby, there's an everything bagel with my name on it.

Catch you next week,
@zackwhittaker