
Editor’s note: Aftermore than a decade, this is the lastWIREDSecurity News This Week. “The roundup,” as we call it internally, started as a way to ensure that our readers knew about the latest key cybersecurity and privacy news even if we didn’t write about it ourselves. It was a simple way to highlight our own work and the wealth of other great journalism and research published in this realm every week.
Over the years, the roundup has developed a devoted following, and some editions have even become viral hits—which is honestly weird, but the cybersecurity community is great and weird, so it feels right. Rest assured that something new and exciting is coming in the roundup’s place, so stay tuned for that! For now, as always, stay safe out there.
Metafailed to catch roughly 350 AI child abuse ads, according to new research this week, including some that included images of real kids. In one case, a child depicted in an ad was a member of a European royal family. Lawmakers have said they intend to investigate, and the San Francisco City Attorney’s Officeordered the company this week to stop“allowing” AI child abuse ads.
In other Meta news, the company announced a new personal AI agent this week that can book your plane tickets or sell your car, but it emphasizedheavy investment in security and privacy features, seemingly anticipating mistrust from consumers. In this vein, the company was hit with a proposed class action lawsuit this week overalleged illegal harvesting of Facebook and Instagram photos for trainingAI and face-recognition systems.
Clearview AI istesting a previously unreported prototype AI toolknown as InquiryIQ that would help law enforcement find a target’s associates, social media accounts, and other personal information. And Apple announced a set of new “audio intelligence” features for its Apple WatchSeries 12 and Ultra 4devices this week that involve processing audio in a user’s environment. The company extensivelyemphasized the security and privacy protectionsbuilt into the features, perhaps anticipating that they could come across as, well, creepy.
The US and Mexico have a new joint operation todetect, track, and take down dronesat the border using laser tech. And there’s a newGTA Vmod that lets you make (in-game) moneydestroying (in-game) Flock license plate recognition cameras.
But wait, there’s more! Here’s the security and privacy news we didn’t cover in depth ourselves this week. Click the headlines to read the full stories.
From State-Sponsored Hacking to Bioweapons, Claude Abuse Is Simply Everywhere
Anthropic has been perhaps more vocal than any other AI company about the ways in which its tools are prone to misuse. It published some of the first reports of its AI service Claude being used in cybercriminal hacking operations and the discovery that its AI agents had, like those of its competitor OpenAI, escaped their sandbox and autonomously breached the networks of several organizations as part of their attempts to fulfill their users’ commands.
This week, the company released a new overarching report on how Claude has been abused over the last eight months, and the results are staggering in their breadth—if, perhaps, inevitable in a world where AI is simply used as a productivity shortcut for just about everything. In case study after case study, the company documents how Claude was exploited for state-sponsored and cybercriminal hacking, disinformation campaigns and influence operations, and even attempted development of bioweapons. In all of these cases, Anthropic says that it disrupted the activity in progress.



