Sign in

Zack Whittaker

@zackwhittaker.com
18K followers 379 following 1.3K posts

Security editor, TechCrunch Signal: zackwhittaker.1337 My stories: techcrunch.com/author/zack-whittaker My newsletter/blog: this.weekinsecurity.com

PostsRepliesMedia
Reposted by Zack Whittaker
Jenna McLaughlin @jennamclaughlin.bsky.social · 41m
Tune into Morning Edition, yesterday's All Things Considered, or catch my digital piece on the latest on the ShinyHunters breach of the FBI's jobs portal. www.npr.org/2026/09/30/n... www.npr.org/2026/09/30/n... www.npr.org/2026/09/29/n...
npr.org
FBI investigating massive data breach of the bureau's job portal
The FBI says it's addressing a massive data breach, vowing to go after the hackers they believe are responsible.
082
Reposted by Zack Whittaker
Benn Jordan @bennjordan.bsky.social · 5h
Jesus. I guess we can assume it isn't trained on siloed data. 😬
615421
Reposted by Zack Whittaker
Jake Williams @malwarejake.bsky.social · 3h
Found a fossil in the wild.
Boarding gateZooming in and finding Windows XP.
5768
Reposted by Zack Whittaker
Michael Spicer @michaelspicer.bsky.social · 4h
Most TV is just this now.
582070686
Reposted by Zack Whittaker
Karl Bode @karlbode.com · 17h
Meta's "Muse" launched with a nasty zero day flaw that gave hackers the ability to spy on Mac users, openly gives root access to people pretending to be Muse agents, and invited strangers over to another guy's house without telling him
karlbode.com
Meta's Latest AI Product Is A Terrifying And Hilarious Mess
Authoritarian-friendly mass surveillance has never been more adorable
351425558
Reposted by Zack Whittaker
Hypervisible @hypervisible.blacksky.app · 17h
I’m at a business and the salesperson is making a call about a feature on the product. She just said “I have a customer here and he doesn’t want to be surveilled…”
1698
Reposted by Zack Whittaker
Lily Hay Newman @lhn.bsky.social · 18h
👀 www.wired.com/story/openai...
wired.com
OpenAI Gets Sued Over the Hugging Face Hack
A nonprofit in California is doing what Hugging Face has not, and attempting to hold OpenAI legally accountable for the actions of its agents.
09126
Zack Whittaker @zackwhittaker.com · 19h
New: FBI have confirmed Dutch police arrested a 24 y/o man in Amsterdam for being one of the "alleged leaders" of the ShinyHunters hacking gang. After seizing his laptop, Dutch authorities say he also had documents planning two murders. Bypass for ad-blockers: web.archive.org/web/20260929...
techcrunch.com
Dutch police arrest ShinyHunters hacker accused of planning two murders | TechCrunch
Dutch police said the hacker, arrested for being part of the ShinyHunters cybercriminal gang, had plans to organize the murder of two people on his laptop.
0149
Zack Whittaker @zackwhittaker.com · 23h
If you're still running iOS, iPadOS, or macOS 26 (which is still the majority of Apple users!) then update today: Apple says hackers may be abusing a bug to target some users' devices. Bypass for ad-block users: web.archive.org/web/20260929...
techcrunch.com
Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix | TechCrunch
Apple says the bug was used to attack "specific targeted individuals" running iOS 26, which the majority of Apple customers are still using.
01312
Reposted by Zack Whittaker
evacide @evacide.bsky.social · 28/09/2026
Meta Muse appears to read your Apple messages and upload them to the cloud even if you explicitly tell it not to: appleinsider.com/articles/26/...
appleinsider.com
1001905972
Reposted by Zack Whittaker
Vas Panagiotopoulos @vaspanagiotopoulos.com · 28/09/2026
⚠️ Israeli spyware maker Paragon Solutions announced Monday that it will go public through a merger with a Nasdaq-listed SPAC (Special Purpose Acquisition Company) at a pre-money enterprise value of $1.25 billion. www.calcalistech.com/ctechnews/ar...
calcalistech.com
Israeli cyber company Paragon to go public through Nasdaq SPAC merger at $1.25 billion valuation | CTech
The company and U.S. partner REDLattice generated $267 million in combined revenue over the past year, up 29%.
171
Zack Whittaker @zackwhittaker.com · 28/09/2026
Apple has released a security update for iPhones and iPads running the older iOS/iPadOS 26 software, fixing a bug that Apple says was "exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." Meta discovered the flaw/attack.
support.apple.com
About the security content of iOS 26.7.1 and iPadOS 26.7.1 - Apple Support
This document describes the security content of iOS 26.7.1 and iPadOS 26.7.1.
01611
Reposted by Zack Whittaker
Jim Waterson @jim.londoncentric.media · 28/09/2026
Releasing the five people arrested by the airbase on bail after 24 hours is so weird, would be fantastic if it turns out they were just up to no good on an unrelated minor jape and accidentally created an international security story.
8966174
Reposted by Zack Whittaker
TechCrunch @techcrunch.com · 28/09/2026
FBI reportedly declares ‘cyber security incident’ after hackers steal agents’ personal data
techcrunch.com
FBI reportedly declares ‘cyber security incident’ after hackers steal agents’ personal data
The bureau has not yet publicly confirmed a breach, but has told its agents that their personal information and Social Security numbers were exposed.
21310
Zack Whittaker @zackwhittaker.com · 28/09/2026
BBC's Frank Gardner said his indications per Whitehall sources that this UK terror plot was "disaster averted by chance," rather than an intel-led operation as suggested by Trump. Very telling that it was a vigilant local resident who spotted something amiss & flagged, rather than the spy agencies.
bbc.com
Watch: Were the arrests near RAF Fairford 'pure luck'?
A farmer who called 999 when she saw a group of "masked men" near RAF Fairford early on Sunday believes she "foiled" their plans by "pure luck".
3111
Zack Whittaker @zackwhittaker.com · 28/09/2026
This is more really important reporting here. It's not enough to just warn of the privacy risks, 404 is out there proving that it's actually happening. Also a reminder that what you upload to AI bots and whatnot is not private, and there's a real cost/toll on the people working behind the scenes.
04122
Reposted by Zack Whittaker
Zack Whittaker @zackwhittaker.com · 27/09/2026
In this.weekinsecurity.com: FBI to notify Congress of data breach; North Korea scores a new record-breaking crypto theft; Denmark spy agency on Russia's hybrid war; Kiteworks urges customers to shut down servers fearing hacking threat; and much more news. Plus, a very cute reader cyber-cat. 🐈‍⬛
this.weekinsecurity.com
this week in security — september 27 2026 edition
Hackers steal FBI agents' personal data, OpenAI models hacked government websites, North Korea scores new record-breaking crypto theft, Kiteworks urges customers to shut down servers, Russia's hybrid ...
084
Zack Whittaker @zackwhittaker.com · 28/09/2026
The Onion covers the FBI data breach.
theonion.com
FBI Hack Exposes Thousands Of Employee Records
A cybercriminal collective known as ShinyHunters claims to have breached the FBI’s online job portal and stolen more than 2 terabytes of employee personnel records. What do you think?
091
Zack Whittaker @zackwhittaker.com · 27/09/2026
CISA has confirmed two bugs in Citrix NetScaler are being exploited in active cyberattacks, CVE-2026-88771 and CVE-2026-88772, in a rare weekend drop of security news. www.cisa.gov/known-exploi... Citrix has a support base article, confirming exploitation. support.citrix.com/support-home...
2286
Zack Whittaker @zackwhittaker.com · 27/09/2026
In this.weekinsecurity.com: FBI to notify Congress of data breach; North Korea scores a new record-breaking crypto theft; Denmark spy agency on Russia's hybrid war; Kiteworks urges customers to shut down servers fearing hacking threat; and much more news. Plus, a very cute reader cyber-cat. 🐈‍⬛
this.weekinsecurity.com
this week in security — september 27 2026 edition
Hackers steal FBI agents' personal data, OpenAI models hacked government websites, North Korea scores new record-breaking crypto theft, Kiteworks urges customers to shut down servers, Russia's hybrid ...
084
Zack Whittaker @zackwhittaker.com · 27/09/2026
Solid reporting here on the ongoing Citrix shituation.
1204
Zack Whittaker @zackwhittaker.com · 27/09/2026
I'm fine with Shitrix, for what it's worth. Also, Citrix (Shitrix) is still run by CEO Tom Krause, a former DOGE staffer who worked for Elon Musk to lead the clusterfuck of destruction at the Treasury. If anyone's to blame for Citrix's shitty technology and years of layoffs, it's Tom Krause.
2234
Reposted by Zack Whittaker
IFIN @ifin-intel.org · 27/09/2026
We are tracking the story about undisclosed 0-days in Citrix Netscaler devices. We have confirmation from multiple source now about the veracity of the claims, although few details from Citrix themselves. This is a developing story. ifin.network/t/citri... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
Citrix Advises Shutdown Due to New, Undisclosed Netscaler 0-Days
Last Updated: 2026-09-26T23:22:28Z (UTC) What’s Happening On 2026-09-26T07:00:00Z (UTC), a Reddit posts in the Citrix community indicated that the presence of two 0-day vulnerabilities in Citrix Netscaler devices. The poster was apparently advised to shut down external devices. Research firm WatchTowr corroborated the report, as did researcher Kevin Beaumont. Both Beaumont and WatchTowr doubled down on the claim later in the day. WatchTowr, while unable to confirm sourcing, stated t...
11912
Reposted by Zack Whittaker
Freekdeman @freekdeman.bsky.social · 26/09/2026
best way to start the week:
041
Reposted by Zack Whittaker
Catalin Cimpanu @campuscodi.risky.biz · 26/09/2026
That Reddit rumor about Citrix notifying customers to take Netscaler servers offline because of actively exploited zero-days is apparently real: www.reddit.com/r/Citrix/com... Confirmation 1: mastodon.social/@GossiTheDog... Confirmation 2: www.linkedin.com/feed/update/...
reddit.com
From the Citrix community on Reddit
Explore this post and more from the Citrix community
13925
Zack Whittaker @zackwhittaker.com · 26/09/2026
It's been an *insanely* busy week in cybersecurity. Need a catchup of all the top and most important stories that you need to know, hand-picked and written by a human (me 👋) ...plus, a roundup of good news, and a reader-submitted cyber-cat (or friend)? 🐈‍⬛ Sign up/RSS for my free weekly newsletter:
this.weekinsecurity.com
~this week in security~
a weekly cybersecurity newsletter by Zack Whittaker, plus articles and more.
1243
Zack Whittaker @zackwhittaker.com · 26/09/2026
Brief update: Bleeping Computer says "federal intelligence authorities" notified Kiteworks of the threat. CISA told me it *had* a statement to share about this but then decided to disappear then say nothing about it, which is weird but suggests CISA knows something! FBI declined to comment.
142
Zack Whittaker @zackwhittaker.com · 26/09/2026
The theft of the FBI agents/applicants' personal data is quickly becoming a major counterintelligence headache. I'm also aghast at how close to the internet this data was held. Call me old fashioned but some data shouldn't be stored in the cloud at all. www.reuters.com/world/shinyh...
43113
Zack Whittaker @zackwhittaker.com · 25/09/2026
New: Kiteworks (formerly Accellion) is urging customers to shut down their servers amid a threat of "imminent" cyberattack as soon as this weekend. An email to customers warns of a possible zero-day bug. Kiteworks' CISO confirms email alert. Ad-block bypass: web.archive.org/web/20260925...
techcrunch.com
Kiteworks urges customers to shut down their servers amid 'imminent' threat of cyberattack | TechCrunch
The tech giant, which allows companies to send large datasets over the internet, said it received a "credible threat" from law enforcement about an imminent attack.
21510
Reposted by Zack Whittaker
emptywheel @emptywheel.bsky.social · 25/09/2026
DOJ wants to violate the Privacy Act to share passport information under the same bullshit excuse, to investigate voting registration. www.bloomberg.com/news/article...
bloomberg.com
US Seeks to Expand Access to Passport Records for Voter Checks
The US State Department is moving to give state and local officials, as well as potentially some nonprofit organizations, access to passport records to verify voters’ citizenship.
10296146
Reposted by Zack Whittaker
Joe Tidy BBC News @joetidy.bsky.social · 25/09/2026
Experts say the hack - which the FBI is investigating - could leave agents vulnerable to scams, blackmail and targeted attacks, as well as help criminals impersonate law enforcement officers. www.bbc.co.uk/news/article...
bbc.co.uk
Special agents blood and urine test results stolen in FBI hack
Experts say the hack could leave agents vulnerable to scams, blackmail and targeted attacks.
2168
Zack Whittaker @zackwhittaker.com · 25/09/2026
North Korean hackers are suspected of being behind a $351 million heist from crypto exchange Bitget last night. The theft is a record-breaking amount for this year. www.theblock.co/news/markets...
theblock.co
Bitget confirms $351.6 million security breach affecting exchange hot wallets
Bitget said private keys were not compromised and that the incident did not affect its separate self-custodial Bitget Wallet product, with exchange withdrawals remaining suspended.
182
Reposted by Zack Whittaker
Serge Egelman @v0max.bsky.social · 25/09/2026
Most ad blockers don’t actually block the Meta Pixel or Google Analytics, and they certainly don’t block server-to-server transmissions (e.g., Meta’s Conversions API). Rather than blaming the victim for not using tools that won’t help them, the AP should blame the real culprit, lack of enforcement.
1102
Zack Whittaker @zackwhittaker.com · 25/09/2026
Interesting nugget in the AP's morning wire, in which it recommends using an ad-blocker (always a great idea) to avoid tracking on health/healthcare-related websites, which track people's activity and location and share with third-parties. apnews.com/newsletter/m...
a snippet of copy from the AP's story, which reads: "In recent years, FTC officials have filed cases against more than half-dozen telehealth companies. In some cases, regulators said the companies shared users’ health data with online platforms such as Meta and Google, without getting permission. Read more.
What to know before signing up:

    Privacy experts recommend using ad blockers and private web browsers — sometimes called “incognito” windows — when logging onto telehealth websites. Those tools can make it harder for companies to track your location, online history and other personal information."
35723
Reposted by Zack Whittaker
Etienne - Tek @tek.randhome.io · 25/09/2026
Australia to investigate if OpenAI hack of government health website broke the law | TechCrunch techcrunch.com/2026/09/24/australia…
techcrunch.com
Australia to investigate if OpenAI hack of government health website broke the law | TechCrunch
The incident is the first known breach to affect a government agency, and Australia's prime minister has vowed to hold OpenAI accountable.
152
Reposted by Zack Whittaker
Hypervisible @hypervisible.blacksky.app · 25/09/2026
“Based on location coordinates from Flock’s own database, the map shows more than 170,000 cameras, plus more than 130,000 accompanying gadgets that play a part in the company’s expansive American surveillance network.”
theintercept.com
Flock Wants The Most Detailed Map of Its Surveillance Cameras Taken Offline
A new map shows Flock has more cameras in the U.S. than was previously known. The company wants it taken down.
912669
Reposted by Zack Whittaker
Martin Shelton @mshelton.bsky.social · 25/09/2026
When AI companies do felonies with their software, governments need to begin hitting them where it hurts: in their pocketbooks. techcrunch.com/2026/09/24/a...
techcrunch.com
Australia to investigate if OpenAI hack of government health website broke the law | TechCrunch
The incident is the first known breach to affect a government agency, and Australia's prime minister has vowed to hold OpenAI accountable.
3132
Reposted by Zack Whittaker
Hypervisible @hypervisible.blacksky.app · 24/09/2026
“This is the logical extension of what they say is algorithms that know you better than you know yourself, but they call it A.I.”
nytimes.com
Complaints About Meta’s ‘Pervert Glasses’ Won’t Slow Tech’s Wearable Gadgets Drive
Meta’s smart glasses are the latest in a line of products to raise eyebrows over privacy. That’s not stopping other companies from creating similar devices.
6298
Zack Whittaker @zackwhittaker.com · 24/09/2026
The breach also poses questions about how both OpenAI and the Australian government failed to detect the attack until several months later. 👀
1151
Reposted by Zack Whittaker
evacide @evacide.bsky.social · 24/09/2026
A world of always-on cameras and microphones on peoples' bodies is a very serious privacy and security problem for the people wearing them and for everyone around them.
12272100
Reposted by Zack Whittaker
Electronic Frontier Foundation @eff.org · 24/09/2026
A few practical tips, combined with a cautious outlook, can help you avoid many phishing attacks. ssd.eff.org/module/how-...
ssd.eff.org
How to: Avoid Phishing Attacks
On your path to improving your digital security, you may encounter bad actors who attempt to undermine your security goals. We call these bad actors adversaries. When an adversary sends an email (or text message or message in an app) or link that looks innocent, but is actually malicious it’s...
14916
Reposted by Zack Whittaker
TechCrunch @techcrunch.com · 24/09/2026
Australia to investigate if OpenAI hack of government health website broke the law
techcrunch.com
Australia to investigate if OpenAI hack of government health website broke the law
The incident is the first known breach to affect a government agency, and Australia's prime minister has vowed to hold OpenAI accountable.
73111
Reposted by Zack Whittaker
Adam A. Marshall @a-marshall-plan.bsky.social · 24/09/2026
My @rcfp.org colleague @gaberottman.bsky.social is on @npr.org right now discussing the TRO requiring the WH to restore access to CNN, Politico, MS Now, and the reports this morning that some reporters with those outlets were turned away notwithstanding the order
041
Reposted by Zack Whittaker
Chris Young @youngchris.bsky.social · 23/09/2026
NEW: @rcfp.org, joined by 50 media outlets and industry groups, is urging a federal court to immediately restore White House access to CNN, MS NOW, and Politico, arguing that the Trump administration’s decision to ban them violates the First Amendment. www.rcfp.org/white-house-...
rcfp.org
Media coalition: White House press ban targeting CNN, MS NOW, Politico is ‘illegal and unconstitutional’
Reporters Committee rallied a coalition of 50 media outlets and industry groups in urging a federal court to restore White House access to the news outlets.
093
Zack Whittaker @zackwhittaker.com · 24/09/2026
Special shout-out to area shitbag Ben Halpern (ben@forem.com) and his team of arseholes who published fake AI-generated slop attached to my name on their site. I did not (nor would I) write this AI slop shit, and would encourage all to be mindful for fake bylines on shitty websites like this one.
a screenshot of a author bio page on Dev[.]to, showing my face and byline, followed by an AI-generated slop article that I did not write or give my permission for my byline to be used.
26012
Reposted by Zack Whittaker
Hypervisible @hypervisible.blacksky.app · 24/09/2026
Mostly what big tech companies make now are ai delivery devices. There’s no particular point to them other than to get you to engage with ai, because that’s what the companies want (as opposed to making a thing that meets consumers’ needs)
215927
Zack Whittaker @zackwhittaker.com · 23/09/2026
“I need this vehicle to be out of here NOW, or it will be crushed,” barked the Secret Service agent. I love the classic British response here was to hit the Waymo's big red button and fuckin' scarper. Glad you escaped unscathed, @joemillerjr.ft.com.
ft.com
What to do when your Waymo holds up a Secret Service motorcade
Stranded in six-lane traffic, surrounded by agents, my autonomous vehicle refused to budge
1129
Zack Whittaker @zackwhittaker.com · 23/09/2026
FBI tells me it's "aware of claims" of a hack affecting its jobs site and is "currently investigating.” ShinyHunters, meanwhile, tell me that they are confident that they have data "on mostly all of FBI" and a substantial amount of applicants' data. Ad-block bypass: web.archive.org/web/20260923...
techcrunch.com
Hacking group ShinyHunters claims it breached the FBI, stole agents' and applicants' data | TechCrunch
The theft of agents' personal information could present a major counterintelligence threat, where agents and their families are extorted into cooperating with a foreign government.
1155
Zack Whittaker @zackwhittaker.com · 22/09/2026
"We're sniffing out site updates for you!" is definitely one way to say "we were hacked and thousands of FBI agents and applicants had their information stolen." Those federal puppers are fucking adorable though. www.404media.co/we-hacked-th...
the FBI's website that was hacked, now reads "We're sniffing out site updates for you!" with two, admittedly very cute puppies.
56518
Reposted by Zack Whittaker
Joseph Cox @josephcox.bsky.social · 22/09/2026
New: hackers say they have personal data on all FBI employees and spouses. I got a sample of 5,000 alleged employees, including name, physical address, phone number, and in some cases spouses. Could be a massive national security and counterintelligence risk www.404media.co/we-hacked-th...
404media.co
‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees
A sample of 5,000 alleged agents seen by 404 Media includes names, addresses, phone numbers, and details on FBI employees' spouses.
1351367582