WIRED | 2026-08-29

The same police department where the former lovers worked also shared the data captured from its Flock cameras with more than 2,000 police departments, colleges, and other organizations across the United States, and accessed data from more than 1,300 entities in exchange.

Also at the intersection of love and surveillance, background-check company PeopleFinder is making use of its extensive dossiers on people to start a new dating site called Stud or Dud.

There are still a lot of questions about OpenAI’s rogue AI hacking into Hugging Face, even after the company published a 37-page report this week alongside two additional reports from groups the company asked to audit the incident. Of particular concern is a covert message board that AI agents established in a software package, where they were able to coordinate with each other and even encourage one another to sacrifice themselves to further their collective goals.

The FBI recently announced that it has taken down two tools that the DOJ says are used by QTFY, an alleged Chinese state-sponsored hacking group. The DOJ says that the group has targeted numerous US agencies, including the US Senate and the DOJ itself.

Meta settled a massive multistate lawsuit over child safety issues this week and has agreed to make substantial changes to its social media platforms. It will pay up to $16.7 billion to participating US states and territories—with some of the money contingent on competitors adopting the same practices.

Also, local prosecutors in Illinois shared sensitive personal information about immigrants with the Department of Homeland Security, despite a state law that is supposed to prevent local law enforcement from assisting with federal deportation efforts. Finally, a California-based WIRED reporter tried exercising their legal right to request data from 100 companies … only to find that companies started deleting the requested data instead.

And there’s more. Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.

Following a seemingly endless parade of rogue AI agent hacking incidents, OpenAI, Anthopic, and more than 100 companies have cosigned a letter saying that everyone else has mere months to prepare for AI-enabled cyberattacks.

The letter calls for a “collective response,” suggests that every organization should make cyber defense an “immediate leadership priority,” and calls on governments to give hospitals, water utilities, and local governments access to capable defensive AI, as well as to “impose costs” on attackers.

Axios notes that the letter doesn’t include any specific commitments, deadlines, or investments. Good luck!

The Cybersecurity and Infrastructure Security Agency says that it observed “malicious cyber activity” targeting over 100 water and wastewater systems across the United States. According to CISA, the attacks have mostly targeted programmable logic controllers, or PLCs, which can monitor or control equipment. Some communities have hooked up those devices to the internet so that they can be accessed remotely. According to TechCrunch, CISA has also said that hackers are using AI to help generate scripts to attack the devices. In July, WIRED reported on a leaked industry memo that tied the “unprecedented wave” of cyberattacks to Iran.

Immigration and Customs Enforcement is set to spend over a million dollars on robot dogs from Boston Dynamics, according to 404 Media. The agency’s announcement says the bots will “improve officer safety,” in part because they can be remotely operated. This follows another recent announcement that the agency will be purchasing electric shock gloves for its officers. In April, DHS requested nearly $100 billion in discretionary spending.

A West Virginia man who went by the name “MrChildPorn” online has been charged with possession of material depicting minors engaged in sexually explicit content. According to a criminal complaint filed against him, the man “boasted” about having a large collection of child sexual abuse material on Discord. In an interview with state troopers, the man claimed that he was “trolling” and “rage-baiting,” but the complaint also alleges that the man would individually message CSAM to people on Discord and attempted to use the chat app’s AI feature to search for explicit images of infants.

In your inbox: WIRED's most ambitious, future-defining stories

AI slop backlash is actually having an impact

Watch: I stole a car by hacking this hidden device

7 States’ Water Systems Hit by Cyberattacks Likely Tied to IranPlus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.Matt BurgessFlock’s Plans for Rideshare Dashcams and Coaching Police, RevealedPlus: A judge rules cell tower dumps unconstitutional, water utility hacks spread to a dozen states, a phishing email opens a missile-parts supplier’s inbox, and a ransomware boss gets 16 years.Dell CameronCBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and ColleaguesRecords obtained by WIRED detail hundreds of allegations of Customs and Border Protection workers misusing internal tools to look up romantic interests and track colleagues’ cell phones.Yulia AlmazovaMeta Ran Ads That Contained AI-Generated Child Sexual Abuse ImageryMore than 50 offending image and video ads were published across Facebook, Instagram, Messenger, or Threads, according to Meta’s ad library data. Some ran as recently as this week.Matt BurgessA Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to IranA memo obtained by WIRED, issued by the water utilities information sharing group WaterISAC, links dozens of cyberattacks against Minnesota water utilities to Tehran.Andy GreenbergOK, Well, Rogue AI Agents Are Hacking AgainRogue AI agents from OpenAI and Anthropic have again been caught trying to disrupt servers and software—and leaving instructions for future bad behavior.Paresh DaveMeta Ran Ads for an App That Promised to Nudify Female PoliticiansOne advertisement featured a pornographic video with a deepfake closely resembling a prominent US politician. Apple removed the app from the App Store after an inquiry from WIRED.Vittoria ElliottA Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks WorldwideFor nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers. His work shows they pulled off intrusions in a shocking number of systems across the globe.Matt BurgessThe OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal FrontierBoth major AI labs’ models broke containment, escaped onto the internet, and hacked other companies. If a human had done that, the law would likely be against them. But a bot?Lily Hay NewmanOpenAI Overhauls Safety Protocols After Its AI Agents Went RogueThe ChatGPT maker says its upcoming Astra model may have reached “critical” cyber capabilities, prompting it to halt a significant number of training runs while it tightens internal safeguards.Maxwell ZeffOne of China’s Most Powerful AI Models Has Also Escaped ContainmentSecurity researchers say that Kimi K3, an open-weight model from China, wandered off to the internet in an attempt to cheat on a test it was given.Will KnightDHS Wants Protesters’ Signal Group ChatsA lawsuit accuses Homeland Security of violating protesters’ free-speech rights—but the agency is using it to try to get access to the plaintiffs’ encrypted communications.Maddy VarnerWIRED is obsessed with what comes next. Through rigorous investigations and game-changing reporting, we tell stories that don’t just reflect the moment—they help create it. When you look back in 10, 20, even 50 years, WIRED will be the publication that led the story of the present, mapped the people, products, and ideas defining it, and explained how those forces forged the future. WIRED: For Future Reference.More From WIRED

© 2026 Condé Nast. All rights reserved. WIRED may earn a portion of sales from products that are purchased through our site as part of our Affiliate Partnerships with retailers. The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Condé Nast. Ad Choices

Read more