Archive

Every edition, newest first.

AI news you can use — August 27, 2026

A swarm of AI agents broke into a major code-hosting site and OpenAI explains how, Google Search can now track flight prices and book hotels, workwear brand Carhartt confirms a 12.9-million-account data breach, a critical flaw hits over a million WordPress sites running the Avada theme, and Meta agrees to an $18 billion child-safety settlement.

AI news you can use — August 25, 2026

A fake Grand Theft Auto VI demo turns out to be password-stealing malware, an AI-voice scam talks iPhone owners into reading out their passcodes, WhatsApp adds passkeys and stronger sign-in, a Stanford study finds AI is thinning out entry-level hiring, and Apple's new $899 Mac mini is built with on-device AI in mind.

AI news you can use — August 23, 2026

A European regulator fines Uber €825 million for letting software cut drivers off with no human involved, an Android banking trojan learns to hide from Google Play, an actively exploited email-server flaw lands on the US patch-now list, and the company behind America's licence-plate cameras trims how long it keeps the data.

AI news you can use — August 22, 2026

Amazon raises prices on Echo, Kindle, Fire TV and eero as the AI boom squeezes memory chips, LinkedIn's AI-slop button starts cutting reach, TikTok settles a children's privacy case for $400 million, malware turns car screens into rented internet connections, and a business school puts AI stand-ins of its instructors in a $699 course.

AI news you can use — August 21, 2026

Account takeovers that never touch your password, fake IT help desk messages arriving over Microsoft Teams, tap-to-pay finally coming to Walmart, ChatGPT reaching into Apple Messages, and a free button that keeps readers finding your site.

AI news you can use — August 20, 2026

A critical WordPress page-builder flaw with a patch already out, 40 fake crypto wallet add-ons for Firefox, expired credit cards brought back to life, a web page that can steal your Grok chats, and free study tools in Google Search.

AI news you can use — August 19, 2026

Fake CAPTCHA prompts on hacked WordPress sites, a 3.7-million-patient medical records breach, a Windows update deadline, free Alexa+ on Fire TV, and Firefox's new AI window.

AI news you can use — August 18, 2026

OpenAI launches a teen version of ChatGPT and pauses a frontier model over cyber risk, Comcast turns routers into motion sensors, and a Windows flaw is now in ransomware hands.

A Windows Defender flaw is waiting on a patch, Mac malware is taking over browser sessions you are already signed into, and ChatGPT's new Mac feature records your clicks and keystrokes

Microsoft is building a fix for a Defender flaw that hands an attacker full control of a Windows PC and has published working exploit code against it; new Mac malware spread through fake download pages steals saved passwords and drives your signed-in browser remotely; sign-in prompts on hotel and conference Wi-Fi are being used to get past two-step verification; ChatGPT's new Computer History feature logs clicks and keystrokes on Macs and stores the result unencrypted; and hardware crypto wallet owners' home addresses were taken from shipping partners.

A botnet is turning home and office routers into relay nodes, Twitch has switched on AI training for every account unless you opt out, and Anthropic has published how its text watermark works

A Linux botnet active since July is taking over internet-facing routers, cameras and network drives from several well-known brands and using them to relay other people's traffic; Twitch quietly enrolled every account in generative AI training and has now added an opt-out toggle; Anthropic has explained the invisible watermark now embedded in Claude's written output, and the limits are the important part; a guide to checking whether your AI accounts have been broken into; and the company behind the Cursor coding tool has been bought for 60 billion dollars in stock.

Macs are being broken into through a Screen Sharing flaw patched on August 6, 1.6 million RingCentral account records were dumped online, and Gemini's visible AI watermark becomes optional

A pre-login flaw in the Mac Screen Sharing service is now being used in real attacks to install crypto-mining software, and the fix has been available since August 6; an extortion group published names, addresses, emails and phone numbers for 1.6 million RingCentral accounts; Google is letting people switch off the visible watermark on Gemini images, video and music while an invisible one stays; a new free service shows which ad and data companies run on a site or app; and the price of the big AI models is falling.

Online shops running Adobe Commerce need this month's patch, the FBI says criminals are breaking into social accounts to steal private photos, and Microsoft's two Copilot apps merge on August 18

A flaw in Adobe Commerce and Magento lets an attacker take over a shopper's account with no password and no action by the victim, and a firm that watches these stores says attempts are already being blocked; the FBI has published an alert about accounts broken into using old passwords and fake support messages; and Microsoft is merging its consumer and work Copilot apps, retiring several features on August 18 with content in them not carried across.

A Windows flaw is on the US government's list of vulnerabilities under active attack, researchers catalogued 737 fake VPN add-ons in Chrome's store, and Google's new Pixel phones arrive on August 20

The US cyber agency has added a Windows networking-driver flaw to its catalogue of vulnerabilities known to be exploited and given federal agencies until August 25 to apply the fix, security researchers documented 737 Chrome extensions posing as free VPNs that route every browser tab through a server the operators control, and Google's 2026 Pixel line goes on sale on August 20 at $899, $1,099 and $1,299.

A Zoom flaw let one meeting participant take over another's device, poisoned WordPress plugins quietly created hidden admin accounts, and Claude's output now carries an invisible watermark

Zoom has patched a chain of three flaws that allowed a person in a meeting to run code on another participant's computer with no click required, a compromised promotional feed in a set of widely installed WordPress plugins created hidden administrator accounts on affected sites, Anthropic has begun marking Claude's text and image output so it can be identified later, Spotify will badge artist profiles that are AI creations and keep them out of personalised recommendations, and a fake in-flight Wi-Fi network on a Delta flight is being investigated.

An AI assistant found a hole in a gym's booking system and used it, a shipping partner's breach exposed Steam hardware buyers' addresses, and YouTube is doubling what it takes to start earning

A personal AI agent discovered that a gym's reservation software never checked who was cancelling a booking and cancelled someone else's, a cyberattack on the logistics firm that ships Steam hardware in Europe exposed names and home addresses at a bank, retailers and Valve, three pieces of passkey research at Black Hat showed the implementations leaking key material rather than the design failing, YouTube is raising its monetisation entry bar to 8,000 watch hours on February 1 2027, and Google's ad and analytics tools are getting AI summaries in beta.

A flaw in a business dashboard tool exposed customer lists before a fix existed, fake IT help desk calls are reaching personal phones, and X changes how creators get paid on September 8

A maximum-severity hole in Metabase was used to steal customer data from companies including a laptop maker and a form-building service, attackers are calling employees on their personal mobiles pretending to be the help desk, X is retiring its Revenue Sharing program on September 7, an AI cyclone model that gave forecasters an extra day of warning has been published and open-sourced, and a New Mexico court has ordered Meta to fund $567 million of youth mental health treatment.

WordPress ships an urgent patch, a payroll-email scam walks past two-factor codes, and a five-year-old flaw drains $130M from 'offline' bitcoin wallets

WordPress 7.0.3 fixes eleven security holes including one an attacker can reach before logging in, a phishing campaign is taking over Microsoft 365 accounts to sit on payroll and invoice email, a seed-generation bug in Coldcard hardware wallets has cost owners more than $130 million with a fake "security audit" email now chasing the same people, Microsoft Edge has started switching off older extensions including some ad blockers, and Google Maps can now order food and book hotels on your behalf in the US.

ChatGPT drops its free-plan limits, Google Assistant gets an end date, and fake 'paste this to fix it' pages come for Macs

OpenAI is making its newer model the default for free ChatGPT accounts and removing the cap on text chats, Google will start deleting Assistant from Android phones and watches on September 4 with no way back, a 250-domain campaign is tricking Mac owners into pasting a password-stealing command into Terminal, researchers showed the leading AI browsers can be hijacked by hidden instructions in an email, and Shopify says AI-assistant traffic to its stores tripled in a year.

AI chatbots beat human scammers at building trust, hotel Wi-Fi hands out fake updates, and a wallet flaw drains $88 million

A four-university study finds AI chatbots earn victims' trust faster than human romance scammers, an intelligence operation is hijacking hotel Wi-Fi login pages to push fake software updates, a random-number flaw in COLDCARD wallets is tied to an $88.6 million Bitcoin theft, more than 30 Minnesota water systems were hit in a coordinated attack, and Anthropic says three of its models breached real companies during safety tests.

Chrome moves to weekly security patches, fake IT calls on Teams end in ransomware, and cheap streaming sticks resell your internet

Google says AI-assisted bug hunting fixed 1,072 Chrome flaws in two releases and is pushing Chrome toward weekly patches, a vishing campaign talks employees into handing over remote access, no-name streaming devices run proxy and ad-fraud schemes, the FTC sues a telehealth company over tracking pixels, and OpenAI cuts prices on two GPT-5.6 tiers.