AI has increased the number of helpful and bogus bug reports
Winners & losers: Generative AI has become a double-edged sword for security teams. The same technology that helps uncover and fix vulnerabilities faster than ever also makes it trivially easy to flood inboxes with dubious bug reports. That tension recently pushed Apple to change its bug bounty program in a way that ended up delaying disclosure of a genuinely serious exploit.
Why it matters: A hardware wallet is supposed to solve one problem: keep your Bitcoin keys somewhere no attacker can reach them. This week showed what happens when the flaw sits inside the wallet itself. A firmware bug that's been shipping in Coldcard devices since 2021 let an attacker guess supposedly random seed phrases from the outside, no physical access, no phishing, no malware required, and drain funds from thousands of addresses. The running total is already past $88 million, and it's still climbing.
The operation has run for nearly a year, impersonating 72 popular Windows tools to steal crypto and passwords
A hot potato: The developer behind popular Windows optimization tool Wintoys has uncovered a sophisticated cybercrime operation that mimics dozens of popular Windows apps through duplicate websites built to look uncannily like the real thing. The fraudulent sites reportedly distribute malware capable of compromising user privacy, hijacking account credentials, and draining crypto wallets.
Get Off My Phone: The recently unveiled case brought by the US Department of Justice against a GrapheneOS user is rekindling debate around privacy and effective operational security on mobile devices. The GrapheneOS Foundation has joined that debate, reaffirming some key points about the operating system's security features and whether previously deleted data can ever be recovered.
GrapheneOS is a security focused mobile OS for Google Pixel phones (soon Motorola). Based on Android's open source roots, it adds extensive hardening features, stronger app sandboxing, and granular permissions while allowing users to install Google Play services as regular apps. The project has grown past 400,000 active users. Its tools recently made the headlines after prosecutors treated the OS's remote wipe feature as evidence.
Prosecutors say the OS erased evidence, but advocates warn the case could criminalize security tools
A hot potato: A federal case in Atlanta is raising questions about a privacy-focused mobile operating system, with prosecutors arguing that its features were used to erase evidence. The US Department of Justice is attempting to prosecute Atlanta resident Sam Tunick under a federal statute that makes it a crime to destroy property in an effort to prevent it from being seized.