10 min read

this week in security — september 20 2026 edition

Hackers reveal Flock cameras are Android phones on sticks, U.S. agencies board hacked oil tankers, ClickFix hacks go viral, Google infiltrated TeamPCP, U.S. declares it has orbital space weapons, NSA reorganization, and more.
~ ~

Hackers grab Flock software, revealing its cameras are Android phones on sticks and 'riddled' with flaws
404 Media ($), Wired ($): Flock is back in the news (not that it ever left) as a new leak exposed the surveillance camera's software as pretty much just Android phones on sticks, and woof, they are crazy vulnerable to security flaws (like containing hardcoded keys!), according to technical teardowns. Hackers pinched a real-world Flock camera, took its software, and gave it to leak site DDoSecrets, which handed copies to Wired and 404 Media for their analysis. Great work here, as more cities like Boston eschew Flock for other surveillance technologies, at a time when the license plate camera maker continues to be embroiled in scandals relating to police officers abusing access to Flock's nationwide snooping database. This all comes as lawmakers seek fresh answers from Flock CEO Garrett Langley...
More: Wired ($) | 404 Media ($) | MassLive | Techspot | Techdirt | The Hill | Micah Lee | Ron Wyden

Micah Lee post on Bluesky: "HaJ3FgupAm8RrDJW3MHgT9X7Ft27eVaD  What is that? That's a hard-coded API token that Flock cameras use to identify themselves and get OAuth credentials, which can then be used to talk to Flock's production servers. Like, anyone on the internet can probably do this right now."

Fears of AI catastrophe spark debate but little action amid widespread skepticism
Taggart Tech: *zips up hazmat suit* Let's talk about AI — briefly — because it's been in the news a lot this week, so let's address it. After an Anthropic researcher publicly resigned claiming AI could kill us all by the end of the decade following a string of (still ongoing) hacking incidents involving AI models breaching other companies, the AI companies all seemed to decide now is a great time to "slow down" their AI development. Nobody can seem to answer exactly how AI will bring about humanity's untimely (but unspecified and unverified) demise, but it's a really convenient excuse to pull back the pace of building their AI models at a time when the companies are utterly hemorrhaging cash and not really showing much for it. Michael Taggart by far has the best explainer (in my view) on the whole saga that's worth your time to read. @spenley also has a very good video recap; SANS' Rob Lee debunks a fair amount and details his wish list for AI firms to follow; and always read @emilymbender et al with a solid reading list to help you stay grounded and informed on the latest developments.
More: The New York Times ($) | Associated Press | Business Insider | Wall Street Journal ($) | Karl Bode | @ProfWoodward | @mollytaft | @lilianedwards

FBI and Coast Guard board hacked tankers heading for U.S. coast
CBS News: U.S. cyber staffers with the Coast Guard and the FBI boarded two oil tankers en route to the Texas coast after at least one of the ships had their comms and propulsion systems hacked. Tracking data showed one of the ships slowing down as it approached the Gulf of Mexico. The crew and tanker owners cooperated with the boarded authorities, who are said to be probing if Iran was responsible with the vessel meddling. A third tanker carrying a heckton of liquified gas was later confirmed hacked off the coast of Italy, suggesting something perhaps more broadly could be at play, with Bloomberg ($) reporting that U.S. officials are monitoring around 20 ships around the world for threats. The FT's ($) focus on ships' satellite links is of particular interest.
More: Bloomberg ($) | Wall Street Journal ($) | TechCrunch ($) | Financial Times ($) | ABC News | Associated Press

a photo of several U.S. Coast Guard personnel and FBI agents wearing bulletproof vests (for some reason) on a large shipping tanker, looking out to sea, with a big ship in the distance.

Apple backtracks on not using users' data for training its AI models
Heise: Apple released its latest software upgrades with new iPhone, iPad, Watch and Mac operating systems going out to the masses, despite a rising controversy over Apple's release of Live Replay and other always-listening features. Daring Fireball has a recap of last week's event and Ars Technica has a full guide on the new macOS features. Apple also drew ire for reversing its longstanding pledge not to use users' data to train its AI models, something that users will still have to opt-in to allowing "review personnel" see their uploaded content, but understandably leading to questions about what next for the ostensibly privacy focused company. In other news: Yes, OpenAI contractors are reading your sensitive ChatGPT chats, and 404 Media ($) proved it.
More: Apple Security | The Eclectic Light Company | AppleInsider | 9to5Mac

A hacked HBO Reddit account helped ClickFix attacks go viral
ADAMnetworks, Hudson Rock: ClickFix attacks, which trick people into hacking themselves by pasting malicious code into their command prompts or terminals, went viral this week. Hackers compromised HBO Max's official Reddit account to serve ads, which when clicked would open up a spoof HBO website that tried to convince victims into pasting malicious code into their computers. Neither Reddit nor HBO said how many people clicked on the ads, but Hudson Rock said over a hundred bad ads went out. Separately: Rough time for Brevo, which last week was hacked to serve phishing messages to thousands of Trezor crypto wallet customers, as it was breached again to serve ClickFix malware on over 100,000 websites that rely on Brevo's code. Security firm Sansec has more, and Bleeping Computer has an abridged writeup.

a screenshot showing a fake HBO Max website featuring an overlay, asking the user to "Get HBO Max" by pasting in a (malicious) command into their computer's terminal, which will hack them

A second zero-day allows hackers to breach Cisco customer networks
Cyberscoop: Cisco customers are now facing two actively exploited zero-days, one with a perfect 10/10 severity score in CVE-2026-76460 in Cisco's Identity Services Engine, and another critical bug in CVE-2026-76461 in Cisco's Secure Email Gateway. Cisco hasn't said how many customers are under attack.

AI is helping to supercharge online dating scams
The Verge ($): Great reporting here from friend-of-the-newsletter @yaelwrites.com, who wrote about dating app scams disclosed by Anthropic during a talk at Sleuthcon earlier this year. The story digs into how these dating scams work, and how a disproportionate number of dating app users are actually gig workers tasked with passing liveness checks.

U.K. and allies warn of Iranian spyware targeting journalists and activists
National Cyber Security Centre: The U.K., U.S., and Dutch authorities are warning journos and activists to be on guard against the "Chosen Brick" malware, which Iranian government hackers are using to target devices with spyware capable of tracking their movements. The U.K. has a detailed explainer, and the FBI has a PDF report with IOCs.

Hacking together a $20 Wi-Fi hotspot into a handheld messenger 
Borna Kovac:
Here's a fun project that converts a cheap $20 4G wireless hotspot into a fully functioning text messaging device. It's a lot of work, but it's also pretty neat to carry Linux in your pocket. The project's code is on GitHub, too, and there's also an active Hacker News thread.

a photo of a Clicks Communicator (a magnetic handheld phone keyboard) with a $20 4G hotspot with a LED display screen containing a bunch of text showing Linux's bootloader messages.

An undercover Google security researcher infiltrated the notorious TeamPCP gang
Wired ($): @agreenberg has the inside story of how Google/Mandiant researcher Austin Larsen infiltrated TeamPCP, one of the most prolific supply chain hackers of the year. Larsen was able to monitor the group from the inside, warn some people that they were targets of possible attacks, and help to disrupt the group’s efforts to exploit its victims. The story includes an interesting detail about how the ShinyHunters hackers allegedly went rogue and betrayed TeamPCP, and a tidbit on some really sloppy opsec. The TeamPCP hackers have since been arrested.

Hacker drama hots up: Not content with hacking organizations for money, the ShinyHunters hackers are now actively hacking other hackers. The gang hacked the Clop extortion gang by hijacking its dark web leak site and stealing its data. Bleeping chatted with the hackers, who said they're reviewing the stolen data. No honor among thieves, huh… (via @ransomwaresommelier)

The 'A' in NSA stands for 'AI': The National Security Agency gets its first major re-org in years, and will be headed by five new internal organizations focused on AI, China, cybersecurity, warfighting, and global intelligence. The NSA's director Joshua Rudd said outsiders might be chosen to lead the internal orgs, unnerving some, but others are "begging people to come back" to NSA after a rocky few years of layoffs. Plus: The NSA's elite hacking unit Tailored Access Operations is confirmed back — at least in name — after it was disbanded post-Snowden. (via Washington Post ($), Electrospaces)

Microsoft fixes record-breaking patch flub: Microsoft rolled out an emergency patch to fix problems with its record-breaking Patch Tuesday release of security fixes, which resolved close to 1,000 flaws but also introduced several issues with Remote Desktop and Hyper-V. "Move fast and break things" isn't a good idea with security patches, and isn't the company's first post-patch rollback this year. (via The Verge, Microsoft)

Did someone say space weapons?! The U.S. military confirmed for the first time that it has deployed space weapons into the Earth's orbit. The Pentagon says Russia and China have been doing it for years already. An Air Force spokesperson told me (disclosure alert!) that the weapon was designed to defend against a "space-enabled attack." (via BBC News, Military Times, New York Times ($), U.S. Air Force)

Revolut hackers target crypto 'whales': More details have emerged on the Revolut breach… Hackers broke into an Italian government agency's email inbox to send out months-worth of fake demands seeking customer data from Revolut about high-net-worth owners, aka crypto whales. Some close to 700 customers had their personal information and government-issued IDs stolen. The hackers are now demanding millions in ransom from Revolut. (via Wall Street Journal ($), Financial Times ($), Irish Times)

IDScan says 13-15 million licenses stolen: IDScan now says at least 13-15 million people's driver's licenses were stolen during a months-long breach of its cloud storage. This is the first disclosure from the company detailing the scope and scale of the breach, since Brian Krebs revealed what he reports to have been a year-long breach involving upwards of 153+ million IDs. (via ~this week in security~, @zackwhittaker)

Max is Russia's super spying app: A Russian all-in-one super app called Max, touted as the country's premier patriotic app, is riddled with flaws and backdoors, according to academics. Authorities are coercing people into using the app, putting millions of people at risk of state surveillance. This is particularly problematic in a country which one Russian put it, "there isn’t really an option to say no." (via The Guardian, Arxiv)

Fireball reporting back online: Good news if you, uh, happen to need to report a galactic fireball… (seems important, no?). A cyberattack knocked offline the International Meteor Organization's beloved website for tracking space debris and asteroids, but the nonprofit said that it has prioritized getting its meteor reporting tool online. (via Gizmodo, DataBreaches.net, Ars Technica)

Welcome back to the happy corner, the soothing salve to a rough week of cyber news. Let's go!

Firstly, a huge congrats to @k8em0 for receiving the incredibly well-deserved Lifetime Achievement Award at LabsCon this week. Few people rise to the god-tier level in cyber as the legendary Katie Moussouris, and this award is a clear reflection of her groundbreaking decades of work in cybersecurity and policy.

It's been a while but I'm back with a new edition of What Can Doom Run On? and this week it's a… digital fly brain? Oooh-kay! Someone mapped the 160,000 or so neurons from a fruit fly's brain and turned it into a digital simulator capable of doing all manner of things on the internet, from cutting doner kebab, trading crypto, parallel parking, exploring bisexuality, and playing Doom. (Honestly, it sounds like this digital fly brain had a really awesome week.)

a side-by-side photo of a computer console, featuring a game running Doom (left) and a digital fly (right) walking in a simulated environment.

(Bonus Edition: Doom also runs on 404 Media ($). Hell yeah, add that to the list.)

Is this a rarely spotted surveillance parrot in the wild? Maybe we need to assign some of these parrots to hang out on Flock cameras…

an animated GIF of a traffic camera pointing on a bunch of busy roads with cars and other vehicles passing by, and then suddenly a green and yellow parrot appears from the top of the frame as if to peek through the camera lens

Let's go check in on the astro-folks in the International Space StationDisco?!

Meanwhile, this Ukrainian gran has absolutely zero patience for this Russian waiter drone.

And lastly... No, you log off first:

Catbus post on Bluesky: "great art articulates eternal truths," followed by a photo from a book, modified, which reads as the script at the end of Waiting for Godot — ESTRAGON: Well, shall we log off? VLADIMIR: Yes, let's log off. NEXT LINE: "[They do not log off.]"

Have good news to share? Get in touch! this@weekinsecurity.com.

This week's cyber cat is Medusa, who can be seen here rifling through your files like a ransomcat. No treats in here, alas; it's nothing but reeeeally booooring highly secret documents. Thanks so much to Dionysus for sending in!

Medusa is a beautiful black, brown, and orange calico cat with a bluish right-eye and a green left eye, sat mischievously in a cardboard box of files.

Thanks for reading this busy week's edition. I'll be back next week as usual with your round-up of all the cyber news you need to know from the week.

If you like this newsletter, please share it! Your word-of-mouth and recommendations on ~the socials~ really helps to bring in new readers as well.

And please do send in your cybercats (or friends!) — it's the feline (and adjacent) energy that keeps this newsletter afloat, along with your readership and support. If there's anything else you want to share for the newsletter, I love hearing from you.

All the best from your friend in cyberspace,
@zackwhittaker