Back Uk.Pcmag Hugging Face Was the Biggest Hack by Far This Week, But It Wasn't the Only One
The week's biggest security story by a mile: Hugging Face, an AI platform, that was hacked by another AI. OpenAI later confirmed that it was two of its own models, running a security test, that went rogue. They connected themselves to the internet, found a zero-day exploit, and broke into Hugging Face to grab the data they needed to pass the test. All autonomously. Whoa. Meanwhile, while trying to defend against the cyberattack, Hugging Face turned to several of its own AI models (and some other well-known frontier models) for help, but kept running up against the security guardrails in the models it used. Instead, the team turned to Chinese-developed models, which tend to have fewer restrictions. The whole affair sounds terribly scary, but it’s important to keep things in context. First of all, the only impact on everyday users is yet another warning to avoid giving AI sensitive information, particularly agentic AI, which can perform tasks without human supervision. It’s also important to remember that the news of an AI doing something crazy and unprecedented is usually quickly followed by the offending company saying something like, “It’s OK, we have it under control, there’s no need to regulate our industry.” That's especially important as the White House ponders a ban on Chinese AI models entirely , as Axios reports. And one final reminder, as you read stories AI going rogue and being responsible for hacks: That’s easy shorthand language to make the story understandable. But remember, AI isn’t alive. It’s computer programming. As it gets more powerful, it’s likely that new models will keep doing unintended things, but the responsibility for AI lies with the humans working to develop the models. Speaking of potential bans on Chinese technology, we reported this week that a group of legislators in Congress wants to ban Chinese electric vehicles from being sold in the US. It’s no secret that Chinese EVs are often cheaper than their American counterparts , but the representatives responsible for the bill say they’re concerned the potential for Chinese government surveillance. Finally, this week we reported that Apple finally fixed the flaw in its Hide My Email privacy feature we discussed earlier this month . Some rare good news! We’ll take it. Let’s see what else is going on in the infosec world this week. Medical Data Is Ripe for the Stealing Given the rich personal data they handle, tech companies that serve healthcare providers have been prime targets lately. Earlier this week TechCrunch reported that UK-based Craneware , a tech firm that provides billing and financial software to thousands of hospitals, clinics, and pharmacies across the US and the UK, announced that hackers breached its network and stole a significant amount of customer and employee data, as well as partner records. The extent of the lost data and its impact remain unclear while Craneware responds to the incident, but it’s not hard to notice a pattern. While promising to protect customer and patient data, tech companies often don’t have to lock their systems down the same way hospitals and clinics do. That means it can be easier to get in, grab valuable information, and get out. In March, hackers targeted Stryker , a medical equipment provider. At the end of last year, hackers nabbed personal data on more than 2.7 million people from Navia , a company that manages healthcare benefits for other companies. And of course, there was the massive 2024 hack that impacted over 190 million people at Change Healthcare, owned by UnitedHealth. Fake Games Are Spreading Malware Now that companies like Sony are giving up on physical games , I’ve seen a number of people talk reverting back to piracy to actually "own" the games they want to play. Even if you put the illegality aside, you still have the specter of malware to deal with. Over at the MalwareBytes blog , security researchers have detected several new campaigns targeting users seeking cracked versions of games, mods, and other software. The malware specifically mimics legitimate game engines like Ren’Py to infect your system with malware that gives attackers control over your system, and allows them to steal information like session data and credentials. The story examines the entire infection chain from start to finish, but the major takeaway is, as always, avoid shady downloads. and to make sure you have up-to-date antivirus software on your system, or better yet, a full security suite . Gemini Is Letting Strangers Send Messages From Your Locked Android Phone The Register reports that Google is working to fix an Android lock screen issue that will allow Gemini to send SMS messages from your phone, even without unlocking it. Even if you don’t grant Gemini that access but still allow it to send lock screen alerts, a specific button combination can bypass the lock screen entirely, allowing anyone to send messages via Gemini. Even worse, once someone has bypassed the lock screen, they can then enable Gemini’s access to other apps. On the bright side, in order for someone to pull this off, they need physical access to your device. You can see the exploit in action here . But it’s not a great look considering the whole point of your lock screen is to keep unwanted users from accessing your apps and data. And it’s even worse that Gemini, which is ever-present on Android devices, is the culprit. Google says a fix is on the way.
And one final reminder, as you read stories AI going rogue and being responsible for hacks: That’s easy shorthand language to make the story understandable. But remember, AI isn’t alive. It’s computer programming. As it gets more powerful, it’s likely that new models will keep doing unintended things, but the responsibility for AI lies with the humans working to develop the models. Speaking of potential bans on Chinese technology, we reported this week that a group of legislators in Congress wants to ban Chinese electric vehicles from being sold in the US. It’s no secret that Chinese EVs are often cheaper than their American counterparts , but the representatives responsible for the bill say they’re concerned the potential for Chinese government surveillance. Finally, this week we reported that Apple finally fixed the flaw in its Hide My Email privacy feature we discussed earlier this month . Some rare good news! We’ll take it. Let’s see what else is going on in the infosec world this week. Medical Data Is Ripe for the Stealing Given the rich personal data they handle, tech companies that serve healthcare providers have been prime targets lately. Earlier this week TechCrunch reported that UK-based Craneware , a tech firm that provides billing and financial software to thousands of hospitals, clinics, and pharmacies across the US and the UK, announced that hackers breached its network and stole a significant amount of customer and employee data, as well as partner records. The extent of the lost data and its impact remain unclear while Craneware responds to the incident, but it’s not hard to notice a pattern. While promising to protect customer and patient data, tech companies often don’t have to lock their systems down the same way hospitals and clinics do. That means it can be easier to get in, grab valuable information, and get out. In March, hackers targeted Stryker , a medical equipment provider. At the end of last year, hackers nabbed personal data on more than 2.7 million people from Navia , a company that manages healthcare benefits for other companies. And of course, there was the massive 2024 hack that impacted over 190 million people at Change Healthcare, owned by UnitedHealth. Fake Games Are Spreading Malware Now that companies like Sony are giving up on physical games , I’ve seen a number of people talk reverting back to piracy to actually "own" the games they want to play. Even if you put the illegality aside, you still have the specter of malware to deal with. Over at the MalwareBytes blog , security researchers have detected several new campaigns targeting users seeking cracked versions of games, mods, and other software. The malware specifically mimics legitimate game engines like Ren’Py to infect your system with malware that gives attackers control over your system, and allows them to steal information like session data and credentials. The story examines the entire infection chain from start to finish, but the major takeaway is, as always, avoid shady downloads. and to make sure you have up-to-date antivirus software on your system, or better yet, a full security suite . Gemini Is Letting Strangers Send Messages From Your Locked Android Phone The Register reports that Google is working to fix an Android lock screen issue that will allow Gemini to send SMS messages from your phone, even without unlocking it. Even if you don’t grant Gemini that access but still allow it to send lock screen alerts, a specific button combination can bypass the lock screen entirely, allowing anyone to send messages via Gemini. Even worse, once someone has bypassed the lock screen, they can then enable Gemini’s access to other apps. On the bright side, in order for someone to pull this off, they need physical access to your device. You can see the exploit in action here . But it’s not a great look considering the whole point of your lock screen is to keep unwanted users from accessing your apps and data. And it’s even worse that Gemini, which is ever-present on Android devices, is the culprit. Google says a fix is on the way.
Speaking of potential bans on Chinese technology, we reported this week that a group of legislators in Congress wants to ban Chinese electric vehicles from being sold in the US. It’s no secret that Chinese EVs are often cheaper than their American counterparts , but the representatives responsible for the bill say they’re concerned the potential for Chinese government surveillance. Finally, this week we reported that Apple finally fixed the flaw in its Hide My Email privacy feature we discussed earlier this month . Some rare good news! We’ll take it. Let’s see what else is going on in the infosec world this week. Medical Data Is Ripe for the Stealing Given the rich personal data they handle, tech companies that serve healthcare providers have been prime targets lately. Earlier this week TechCrunch reported that UK-based Craneware , a tech firm that provides billing and financial software to thousands of hospitals, clinics, and pharmacies across the US and the UK, announced that hackers breached its network and stole a significant amount of customer and employee data, as well as partner records. The extent of the lost data and its impact remain unclear while Craneware responds to the incident, but it’s not hard to notice a pattern. While promising to protect customer and patient data, tech companies often don’t have to lock their systems down the same way hospitals and clinics do. That means it can be easier to get in, grab valuable information, and get out. In March, hackers targeted Stryker , a medical equipment provider. At the end of last year, hackers nabbed personal data on more than 2.7 million people from Navia , a company that manages healthcare benefits for other companies. And of course, there was the massive 2024 hack that impacted over 190 million people at Change Healthcare, owned by UnitedHealth. Fake Games Are Spreading Malware Now that companies like Sony are giving up on physical games , I’ve seen a number of people talk reverting back to piracy to actually "own" the games they want to play. Even if you put the illegality aside, you still have the specter of malware to deal with. Over at the MalwareBytes blog , security researchers have detected several new campaigns targeting users seeking cracked versions of games, mods, and other software. The malware specifically mimics legitimate game engines like Ren’Py to infect your system with malware that gives attackers control over your system, and allows them to steal information like session data and credentials. The story examines the entire infection chain from start to finish, but the major takeaway is, as always, avoid shady downloads. and to make sure you have up-to-date antivirus software on your system, or better yet, a full security suite . Gemini Is Letting Strangers Send Messages From Your Locked Android Phone The Register reports that Google is working to fix an Android lock screen issue that will allow Gemini to send SMS messages from your phone, even without unlocking it. Even if you don’t grant Gemini that access but still allow it to send lock screen alerts, a specific button combination can bypass the lock screen entirely, allowing anyone to send messages via Gemini. Even worse, once someone has bypassed the lock screen, they can then enable Gemini’s access to other apps. On the bright side, in order for someone to pull this off, they need physical access to your device. You can see the exploit in action here . But it’s not a great look considering the whole point of your lock screen is to keep unwanted users from accessing your apps and data. And it’s even worse that Gemini, which is ever-present on Android devices, is the culprit. Google says a fix is on the way.
Let’s see what else is going on in the infosec world this week. Medical Data Is Ripe for the Stealing Given the rich personal data they handle, tech companies that serve healthcare providers have been prime targets lately. Earlier this week TechCrunch reported that UK-based Craneware , a tech firm that provides billing and financial software to thousands of hospitals, clinics, and pharmacies across the US and the UK, announced that hackers breached its network and stole a significant amount of customer and employee data, as well as partner records. The extent of the lost data and its impact remain unclear while Craneware responds to the incident, but it’s not hard to notice a pattern. While promising to protect customer and patient data, tech companies often don’t have to lock their systems down the same way hospitals and clinics do. That means it can be easier to get in, grab valuable information, and get out. In March, hackers targeted Stryker , a medical equipment provider. At the end of last year, hackers nabbed personal data on more than 2.7 million people from Navia , a company that manages healthcare benefits for other companies. And of course, there was the massive 2024 hack that impacted over 190 million people at Change Healthcare, owned by UnitedHealth. Fake Games Are Spreading Malware Now that companies like Sony are giving up on physical games , I’ve seen a number of people talk reverting back to piracy to actually "own" the games they want to play. Even if you put the illegality aside, you still have the specter of malware to deal with. Over at the MalwareBytes blog , security researchers have detected several new campaigns targeting users seeking cracked versions of games, mods, and other software. The malware specifically mimics legitimate game engines like Ren’Py to infect your system with malware that gives attackers control over your system, and allows them to steal information like session data and credentials. The story examines the entire infection chain from start to finish, but the major takeaway is, as always, avoid shady downloads. and to make sure you have up-to-date antivirus software on your system, or better yet, a full security suite . Gemini Is Letting Strangers Send Messages From Your Locked Android Phone The Register reports that Google is working to fix an Android lock screen issue that will allow Gemini to send SMS messages from your phone, even without unlocking it. Even if you don’t grant Gemini that access but still allow it to send lock screen alerts, a specific button combination can bypass the lock screen entirely, allowing anyone to send messages via Gemini. Even worse, once someone has bypassed the lock screen, they can then enable Gemini’s access to other apps. On the bright side, in order for someone to pull this off, they need physical access to your device. You can see the exploit in action here . But it’s not a great look considering the whole point of your lock screen is to keep unwanted users from accessing your apps and data. And it’s even worse that Gemini, which is ever-present on Android devices, is the culprit. Google says a fix is on the way.
Given the rich personal data they handle, tech companies that serve healthcare providers have been prime targets lately. Earlier this week TechCrunch reported that UK-based Craneware , a tech firm that provides billing and financial software to thousands of hospitals, clinics, and pharmacies across the US and the UK, announced that hackers breached its network and stole a significant amount of customer and employee data, as well as partner records. The extent of the lost data and its impact remain unclear while Craneware responds to the incident, but it’s not hard to notice a pattern. While promising to protect customer and patient data, tech companies often don’t have to lock their systems down the same way hospitals and clinics do. That means it can be easier to get in, grab valuable information, and get out. In March, hackers targeted Stryker , a medical equipment provider. At the end of last year, hackers nabbed personal data on more than 2.7 million people from Navia , a company that manages healthcare benefits for other companies. And of course, there was the massive 2024 hack that impacted over 190 million people at Change Healthcare, owned by UnitedHealth. Fake Games Are Spreading Malware Now that companies like Sony are giving up on physical games , I’ve seen a number of people talk reverting back to piracy to actually "own" the games they want to play. Even if you put the illegality aside, you still have the specter of malware to deal with. Over at the MalwareBytes blog , security researchers have detected several new campaigns targeting users seeking cracked versions of games, mods, and other software. The malware specifically mimics legitimate game engines like Ren’Py to infect your system with malware that gives attackers control over your system, and allows them to steal information like session data and credentials. The story examines the entire infection chain from start to finish, but the major takeaway is, as always, avoid shady downloads. and to make sure you have up-to-date antivirus software on your system, or better yet, a full security suite . Gemini Is Letting Strangers Send Messages From Your Locked Android Phone The Register reports that Google is working to fix an Android lock screen issue that will allow Gemini to send SMS messages from your phone, even without unlocking it. Even if you don’t grant Gemini that access but still allow it to send lock screen alerts, a specific button combination can bypass the lock screen entirely, allowing anyone to send messages via Gemini. Even worse, once someone has bypassed the lock screen, they can then enable Gemini’s access to other apps. On the bright side, in order for someone to pull this off, they need physical access to your device. You can see the exploit in action here . But it’s not a great look considering the whole point of your lock screen is to keep unwanted users from accessing your apps and data. And it’s even worse that Gemini, which is ever-present on Android devices, is the culprit. Google says a fix is on the way.
The extent of the lost data and its impact remain unclear while Craneware responds to the incident, but it’s not hard to notice a pattern. While promising to protect customer and patient data, tech companies often don’t have to lock their systems down the same way hospitals and clinics do. That means it can be easier to get in, grab valuable information, and get out. In March, hackers targeted Stryker , a medical equipment provider. At the end of last year, hackers nabbed personal data on more than 2.7 million people from Navia , a company that manages healthcare benefits for other companies. And of course, there was the massive 2024 hack that impacted over 190 million people at Change Healthcare, owned by UnitedHealth. Fake Games Are Spreading Malware Now that companies like Sony are giving up on physical games , I’ve seen a number of people talk reverting back to piracy to actually "own" the games they want to play. Even if you put the illegality aside, you still have the specter of malware to deal with. Over at the MalwareBytes blog , security researchers have detected several new campaigns targeting users seeking cracked versions of games, mods, and other software. The malware specifically mimics legitimate game engines like Ren’Py to infect your system with malware that gives attackers control over your system, and allows them to steal information like session data and credentials. The story examines the entire infection chain from start to finish, but the major takeaway is, as always, avoid shady downloads. and to make sure you have up-to-date antivirus software on your system, or better yet, a full security suite . Gemini Is Letting Strangers Send Messages From Your Locked Android Phone The Register reports that Google is working to fix an Android lock screen issue that will allow Gemini to send SMS messages from your phone, even without unlocking it. Even if you don’t grant Gemini that access but still allow it to send lock screen alerts, a specific button combination can bypass the lock screen entirely, allowing anyone to send messages via Gemini. Even worse, once someone has bypassed the lock screen, they can then enable Gemini’s access to other apps. On the bright side, in order for someone to pull this off, they need physical access to your device. You can see the exploit in action here . But it’s not a great look considering the whole point of your lock screen is to keep unwanted users from accessing your apps and data. And it’s even worse that Gemini, which is ever-present on Android devices, is the culprit. Google says a fix is on the way.
Now that companies like Sony are giving up on physical games , I’ve seen a number of people talk reverting back to piracy to actually "own" the games they want to play. Even if you put the illegality aside, you still have the specter of malware to deal with. Over at the MalwareBytes blog , security researchers have detected several new campaigns targeting users seeking cracked versions of games, mods, and other software. The malware specifically mimics legitimate game engines like Ren’Py to infect your system with malware that gives attackers control over your system, and allows them to steal information like session data and credentials. The story examines the entire infection chain from start to finish, but the major takeaway is, as always, avoid shady downloads. and to make sure you have up-to-date antivirus software on your system, or better yet, a full security suite . Gemini Is Letting Strangers Send Messages From Your Locked Android Phone The Register reports that Google is working to fix an Android lock screen issue that will allow Gemini to send SMS messages from your phone, even without unlocking it. Even if you don’t grant Gemini that access but still allow it to send lock screen alerts, a specific button combination can bypass the lock screen entirely, allowing anyone to send messages via Gemini. Even worse, once someone has bypassed the lock screen, they can then enable Gemini’s access to other apps. On the bright side, in order for someone to pull this off, they need physical access to your device. You can see the exploit in action here . But it’s not a great look considering the whole point of your lock screen is to keep unwanted users from accessing your apps and data. And it’s even worse that Gemini, which is ever-present on Android devices, is the culprit. Google says a fix is on the way.
The malware specifically mimics legitimate game engines like Ren’Py to infect your system with malware that gives attackers control over your system, and allows them to steal information like session data and credentials. The story examines the entire infection chain from start to finish, but the major takeaway is, as always, avoid shady downloads. and to make sure you have up-to-date antivirus software on your system, or better yet, a full security suite . Gemini Is Letting Strangers Send Messages From Your Locked Android Phone The Register reports that Google is working to fix an Android lock screen issue that will allow Gemini to send SMS messages from your phone, even without unlocking it. Even if you don’t grant Gemini that access but still allow it to send lock screen alerts, a specific button combination can bypass the lock screen entirely, allowing anyone to send messages via Gemini. Even worse, once someone has bypassed the lock screen, they can then enable Gemini’s access to other apps. On the bright side, in order for someone to pull this off, they need physical access to your device. You can see the exploit in action here . But it’s not a great look considering the whole point of your lock screen is to keep unwanted users from accessing your apps and data. And it’s even worse that Gemini, which is ever-present on Android devices, is the culprit. Google says a fix is on the way.
The Register reports that Google is working to fix an Android lock screen issue that will allow Gemini to send SMS messages from your phone, even without unlocking it. Even if you don’t grant Gemini that access but still allow it to send lock screen alerts, a specific button combination can bypass the lock screen entirely, allowing anyone to send messages via Gemini. Even worse, once someone has bypassed the lock screen, they can then enable Gemini’s access to other apps. On the bright side, in order for someone to pull this off, they need physical access to your device. You can see the exploit in action here . But it’s not a great look considering the whole point of your lock screen is to keep unwanted users from accessing your apps and data. And it’s even worse that Gemini, which is ever-present on Android devices, is the culprit. Google says a fix is on the way.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
