Sign in

Zack Whittaker

@zackwhittaker.com
18K followers 380 following 1.4K posts

Security editor, TechCrunch Signal: zackwhittaker.1337 My stories: techcrunch.com/author/zack-whittaker My newsletter/blog: this.weekinsecurity.com

PostsRepliesMedia
Reposted by Zack Whittaker
Zack Whittaker @zackwhittaker.com · 17h
For this.weekinsecurity.com, I break down how the anatomy of a voice-phishing call that allowed a hacker to steal millions of people's data. Voice phishing attacks are *highly* effective, and remain the go-to hacking technique by some of the most prolific hacking groups — no AI needed. Read on! 🐈‍⬛
this.weekinsecurity.com
How a phone call allowed a hacker to steal millions of people's personal data
Financially motivated hackers are calling and tricking employees into handing over their passwords in highly effective voice-phishing attacks.
1186
Reposted by Zack Whittaker
evacide @evacide.bsky.social · 7h
Android has rolled out some new features for Advanced Protection, including intrusion logging, which is especially useful for survivors because nearly all commercially-available Android stalkerware is installed by a person with physical access logging in: blog.google/security/and...
blog.google
6 ways Advanced Protection on Android keeps you safe
Discover new Advanced Protection features on Android designed to defend against sophisticated threats and keep your data safe.
114076
Reposted by Zack Whittaker
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 15h
NEW: An iPhone hacking company claims it can freeze the iPhone in a state that makes it easier for cops to access data. The iPhone has an automatic reboot feature that reverts the device to a state where data is harder to extract. This would defeat that feature. www.404media.co/cops-can-byp...
404media.co
Cops Can Bypass iPhone’s Automatic Reboot to Get Into Locked Phones, Leaked Video Claims
Magent Forensics, the owner of the GrayKey phone unlocking tool, says it can bypass an iPhone rebooting feature that was locking cops out.
35439
Reposted by Zack Whittaker
Alex Engler @alexengler.bsky.social · 17h
Totally surreal to announce I've been targeted by my first China-aligned threat actor, as an AI policy leader. Sometimes little moments of recognition like this really make you feel like you've made it www.reuters.com/legal/govern...
1103
Zack Whittaker @zackwhittaker.com · 17h
For this.weekinsecurity.com, I break down how the anatomy of a voice-phishing call that allowed a hacker to steal millions of people's data. Voice phishing attacks are *highly* effective, and remain the go-to hacking technique by some of the most prolific hacking groups — no AI needed. Read on! 🐈‍⬛
this.weekinsecurity.com
How a phone call allowed a hacker to steal millions of people's personal data
Financially motivated hackers are calling and tricking employees into handing over their passwords in highly effective voice-phishing attacks.
1186
Reposted by Zack Whittaker
Kim Zetter @kimzetter.bsky.social · 17h
Exclusive: Israeli spyware maker Paragon positions itself as more responsible than competitor NSO Group. But company's new US CEO says in candid interview that while they will cut off customers who misuse their spyware they have no ability to detect or investigate customer misuse, nor want ability
wired.com
The Secrets of a US Spyware King
In an exclusive interview with WIRED, Paragon Solutions CEO Andrew Boyd reveals the limits of the company’s promise to keep bad actors from abusing its powerful espionage tool.
12720
Zack Whittaker @zackwhittaker.com · 18h
The data leak website used by the ShinyHunters hackers is offline, per Reuters, days after the hackers claimed an FBI breach. I emailed ShinyHunters, who blamed "rival DDoS attacks" and unrelated data center outages that required upgrades, and that they're bringing their site back online.
reuters.com
ShinyHunters website goes offline after FBI deadline expires
The website used by ShinyHunters, the group that claimed responsibility for a recent hack of thousands of FBI agents' personal and sensitive ​data, went offline on Wednesday, a day after the group's d...
1143
Reposted by Zack Whittaker
Catalin Cimpanu @campuscodi.risky.biz · 30/09/2026
In an interview, Firefox's head says it like it is—Google deprecated its old extension system just to sabotage ad blockers arstechnica.com/gadgets/2026...
Text that reads: "So some examples—Chrome went through with their deprecation of Manifest V2. Manifest V2 is basically a much more powerful extension system. And people were like, well, why did this decrease? Why didn’t they just fix the security vulnerabilities in Manifest V2? And it’s very clearly because of ad blockers. That was the reason to deprecate it. Whereas, Mozilla, we’re not maximizing for profits, we’re maximizing for user experience and browser experience, and we want people to have powerful extensions. So we noticed when that shutoff moment happened, there was a moment where people said, do you want the power of an engine to be able to dictate how I control my experience? Because once Chromium shut it off, Edge shut it off, all the Chromium browsers then shut off Manifest V2 support. We still support it, and so we saw a big surge of actual users who started using us."
06220
Reposted by Zack Whittaker
Zack Whittaker @zackwhittaker.com · 30/09/2026
New on this.weekinsecurity.com for paid subscribers: I explore how voice phishing — literally hackers calling people up and tricking them into giving over their passwords — has become a major underestimated threat. Hackers are breaching big tech giants to the tune of millions of people's data. 🐈‍⬛
this.weekinsecurity.com
How a phone call allowed a hacker to steal millions of people's personal data
Financially motivated hackers are calling and tricking employees into handing over their passwords in highly effective voice-phishing attacks.
1188
Zack Whittaker @zackwhittaker.com · 30/09/2026
It's a genuinely lovely webpage dedicated to a U.S. military dog called Nick, who retired earlier this year and was adopted by his owner, and clearly beloved by his team. GOOD PUP. YOU SERVED YOUR COUNTRY. WOOF! Wayback link: web.archive.org/web/20260903...
a photo of the military dog Nick, sat down on the tarmac with his paws in front of him, ears up, in front of Air Force One in the background.
1487
Zack Whittaker @zackwhittaker.com · 30/09/2026
I was researching the Pentagon data leak story earlier and by chance found one of the military's many login pages (it's pretty normal — there are lots of them — the DOD is a massive enterprise network). But this link caught my eye. "Learn more about Military Working Dog Nick." *IMMEDIATE CLICK.*
a screenshot of a DOD login page, featuring a dog in the background wearing ski goggles (i think) and a link on the login page that reads "Learn more about Military Working Dog Nick."
3348
Zack Whittaker @zackwhittaker.com · 30/09/2026
As data breaches go, this is pretty sizable, significant, and also bafflingly bad in terms of time it took to discover and that the stolen data was unencrypted. News of this breach comes weeks after a huge theft of FBI agents' personal data. Bypass for ad-blockers: web.archive.org/web/20260930...
techcrunch.com
Hackers stole millions of US military personnel records during months-long data breach | TechCrunch
The Department of Defense notified millions of current and former U.S. military personnel that their personal information had been stolen in a months-long breach.
26696292
Zack Whittaker @zackwhittaker.com · 30/09/2026
The Pentagon is notifying millions of current and former U.S. military servicemembers and staff that hackers stole their *unencrypted* personal information during a months-long data breach. The agency that had the breach also handles ID and login/credential access to U.S. military systems and bases.
techcrunch.com
Hackers stole millions of US military personnel records during months-long data breach | TechCrunch
The Department of Defense notified millions of current and former U.S. military personnel that their personal information had been stolen in a months-long breach.
30525041384
Reposted by Zack Whittaker
Garrett M. Graff @vermontgmg.bsky.social · 30/09/2026
We don’t spend enough time talking about just how WEIRD all these people are. This is just an incredibly weird and insecure thing to say. Imagine any other SecDef ever being this weird and insecure?!
2964391929
Zack Whittaker @zackwhittaker.com · 30/09/2026
This is a major blow to the open web! For as long as I can remember, Reddit has embraced RSS feeds and public API access to users, apps, and developers, allowing the site to thrive. To start choking access after decades of open doors is really sad and feels like the start of Reddit's demise.
techcrunch.com
Reddit is killing RSS feeds and ending public API access because of AI bots | TechCrunch
Reddit is ending support for RSS feeds, as the company continues tightening access to its trove of user-generated content.
75617
Zack Whittaker @zackwhittaker.com · 30/09/2026
A scathing @emptywheel.bsky.social column: "Even the propaganda was too slovenly to get basic details right," like Trump signing his name as "President of the Unites States." Also, not the point; Greg Brockman's signature looks either truly psychopathic or that he scribbled it under duress.
emptywheel.net
In the "Unites States" of "Super Intelligence," "Issues Are Remediated" - emptywheel
Once you realize Trump's morally binding AI code doesn't even spell "United States" properly, the whole sham looks even more ominous.
713631
Zack Whittaker @zackwhittaker.com · 30/09/2026
this is some of the best advice (though not always practical in big companies). picking up phone calls is the source of so many scams, hacks, and thefts. if they leave a voicemail, contact people back at a number/email that's known.
110
Zack Whittaker @zackwhittaker.com · 30/09/2026
New on this.weekinsecurity.com for paid subscribers: I explore how voice phishing — literally hackers calling people up and tricking them into giving over their passwords — has become a major underestimated threat. Hackers are breaching big tech giants to the tune of millions of people's data. 🐈‍⬛
this.weekinsecurity.com
How a phone call allowed a hacker to steal millions of people's personal data
Financially motivated hackers are calling and tricking employees into handing over their passwords in highly effective voice-phishing attacks.
1188
Zack Whittaker @zackwhittaker.com · 30/09/2026
Probably seems like a fitting time to note that CISA's website has for literally years now, and through multiple administrations, warned that when you click on a link to an external website you are "now leaving an official website of the United State Government."
0131
Reposted by Zack Whittaker
Jenna McLaughlin @jennamclaughlin.bsky.social · 30/09/2026
Tune into Morning Edition, yesterday's All Things Considered, or catch my digital piece on the latest on the ShinyHunters breach of the FBI's jobs portal. www.npr.org/2026/09/30/n... www.npr.org/2026/09/30/n... www.npr.org/2026/09/29/n...
npr.org
FBI investigating massive data breach of the bureau's job portal
The FBI says it's addressing a massive data breach, vowing to go after the hackers they believe are responsible.
0112
Reposted by Zack Whittaker
Benn Jordan @bennjordan.bsky.social · 30/09/2026
Jesus. I guess we can assume it isn't trained on siloed data. 😬
720927
Reposted by Zack Whittaker
Jake Williams @malwarejake.bsky.social · 30/09/2026
Found a fossil in the wild.
Boarding gateZooming in and finding Windows XP.
5988
Reposted by Zack Whittaker
Michael Spicer @michaelspicer.bsky.social · 30/09/2026
Most TV is just this now.
16568461878
Reposted by Zack Whittaker
Karl Bode @karlbode.com · 29/09/2026
Meta's "Muse" launched with a nasty zero day flaw that gave hackers the ability to spy on Mac users, openly gives root access to people pretending to be Muse agents, and invited strangers over to another guy's house without telling him
karlbode.com
Meta's Latest AI Product Is A Terrifying And Hilarious Mess
Authoritarian-friendly mass surveillance has never been more adorable
512064817
Reposted by Zack Whittaker
Hypervisible @hypervisible.blacksky.app · 29/09/2026
I’m at a business and the salesperson is making a call about a feature on the product. She just said “I have a customer here and he doesn’t want to be surveilled…”
1718
Reposted by Zack Whittaker
Lily Hay Newman @lhn.bsky.social · 29/09/2026
👀 www.wired.com/story/openai...
wired.com
OpenAI Gets Sued Over the Hugging Face Hack
A nonprofit in California is doing what Hugging Face has not, and attempting to hold OpenAI legally accountable for the actions of its agents.
09128
Zack Whittaker @zackwhittaker.com · 29/09/2026
New: FBI have confirmed Dutch police arrested a 24 y/o man in Amsterdam for being one of the "alleged leaders" of the ShinyHunters hacking gang. After seizing his laptop, Dutch authorities say he also had documents planning two murders. Bypass for ad-blockers: web.archive.org/web/20260929...
techcrunch.com
Dutch police arrest ShinyHunters hacker accused of planning two murders | TechCrunch
Dutch police said the hacker, arrested for being part of the ShinyHunters cybercriminal gang, had plans to organize the murder of two people on his laptop.
0149
Zack Whittaker @zackwhittaker.com · 29/09/2026
If you're still running iOS, iPadOS, or macOS 26 (which is still the majority of Apple users!) then update today: Apple says hackers may be abusing a bug to target some users' devices. Bypass for ad-block users: web.archive.org/web/20260929...
techcrunch.com
Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix | TechCrunch
Apple says the bug was used to attack "specific targeted individuals" running iOS 26, which the majority of Apple customers are still using.
01312
Reposted by Zack Whittaker
evacide @evacide.bsky.social · 28/09/2026
Meta Muse appears to read your Apple messages and upload them to the cloud even if you explicitly tell it not to: appleinsider.com/articles/26/...
appleinsider.com
1001923996
Reposted by Zack Whittaker
Vas Panagiotopoulos @vaspanagiotopoulos.com · 28/09/2026
⚠️ Israeli spyware maker Paragon Solutions announced Monday that it will go public through a merger with a Nasdaq-listed SPAC (Special Purpose Acquisition Company) at a pre-money enterprise value of $1.25 billion. www.calcalistech.com/ctechnews/ar...
calcalistech.com
Israeli cyber company Paragon to go public through Nasdaq SPAC merger at $1.25 billion valuation | CTech
The company and U.S. partner REDLattice generated $267 million in combined revenue over the past year, up 29%.
171
Zack Whittaker @zackwhittaker.com · 28/09/2026
Apple has released a security update for iPhones and iPads running the older iOS/iPadOS 26 software, fixing a bug that Apple says was "exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." Meta discovered the flaw/attack.
support.apple.com
About the security content of iOS 26.7.1 and iPadOS 26.7.1 - Apple Support
This document describes the security content of iOS 26.7.1 and iPadOS 26.7.1.
01611
Reposted by Zack Whittaker
Jim Waterson @jim.londoncentric.media · 28/09/2026
Releasing the five people arrested by the airbase on bail after 24 hours is so weird, would be fantastic if it turns out they were just up to no good on an unrelated minor jape and accidentally created an international security story.
8966574
Reposted by Zack Whittaker
TechCrunch @techcrunch.com · 28/09/2026
FBI reportedly declares ‘cyber security incident’ after hackers steal agents’ personal data
techcrunch.com
FBI reportedly declares ‘cyber security incident’ after hackers steal agents’ personal data
The bureau has not yet publicly confirmed a breach, but has told its agents that their personal information and Social Security numbers were exposed.
21310
Zack Whittaker @zackwhittaker.com · 28/09/2026
Spy agencies have access to raw data, and have surveillance powers and capabilities up to their eyeballs — and it doesn't seem to work. But the minute that you upend the sleepy local English village life where everyone knows each other and talks (I grew up in one), you're in for a rough time.
280
Zack Whittaker @zackwhittaker.com · 28/09/2026
BBC's Frank Gardner said his indications per Whitehall sources that this UK terror plot was "disaster averted by chance," rather than an intel-led operation as suggested by Trump. Very telling that it was a vigilant local resident who spotted something amiss & flagged, rather than the spy agencies.
bbc.com
Watch: Were the arrests near RAF Fairford 'pure luck'?
A farmer who called 999 when she saw a group of "masked men" near RAF Fairford early on Sunday believes she "foiled" their plans by "pure luck".
3111
Zack Whittaker @zackwhittaker.com · 28/09/2026
This is more really important reporting here. It's not enough to just warn of the privacy risks, 404 is out there proving that it's actually happening. Also a reminder that what you upload to AI bots and whatnot is not private, and there's a real cost/toll on the people working behind the scenes.
04122
Reposted by Zack Whittaker
Zack Whittaker @zackwhittaker.com · 27/09/2026
In this.weekinsecurity.com: FBI to notify Congress of data breach; North Korea scores a new record-breaking crypto theft; Denmark spy agency on Russia's hybrid war; Kiteworks urges customers to shut down servers fearing hacking threat; and much more news. Plus, a very cute reader cyber-cat. 🐈‍⬛
this.weekinsecurity.com
this week in security — september 27 2026 edition
Hackers steal FBI agents' personal data, OpenAI models hacked government websites, North Korea scores new record-breaking crypto theft, Kiteworks urges customers to shut down servers, Russia's hybrid ...
084
Zack Whittaker @zackwhittaker.com · 28/09/2026
The Onion covers the FBI data breach.
theonion.com
FBI Hack Exposes Thousands Of Employee Records
A cybercriminal collective known as ShinyHunters claims to have breached the FBI’s online job portal and stolen more than 2 terabytes of employee personnel records. What do you think?
091
Zack Whittaker @zackwhittaker.com · 27/09/2026
Citrix has a security post on its website that also confirms exploitation and has a bunch of remedation advice, which you might not know because the company set the page to "noindex," so it doesn't show up in search results. 🤦‍♂️
community.citrix.com
Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
Guidance for customers on newly addressed vulnerabilities and recommended updates As the cybersecurity landscape continues to evolve, organizations across the industry are seeing changes in the pace, ...
0113
Zack Whittaker @zackwhittaker.com · 27/09/2026
Shoutout to the folks on that Citrix subreddit thread, the security researchers validating the bugs, and the random IT teams who proactively reached out to affected NetScaler customers over the weekend, all of whom did a far better job at mitigating the damage before Citrix joined the party.
2182
Zack Whittaker @zackwhittaker.com · 27/09/2026
CISA has confirmed two bugs in Citrix NetScaler are being exploited in active cyberattacks, CVE-2026-88771 and CVE-2026-88772, in a rare weekend drop of security news. www.cisa.gov/known-exploi... Citrix has a support base article, confirming exploitation. support.citrix.com/support-home...
3286
Zack Whittaker @zackwhittaker.com · 27/09/2026
In this.weekinsecurity.com: FBI to notify Congress of data breach; North Korea scores a new record-breaking crypto theft; Denmark spy agency on Russia's hybrid war; Kiteworks urges customers to shut down servers fearing hacking threat; and much more news. Plus, a very cute reader cyber-cat. 🐈‍⬛
this.weekinsecurity.com
this week in security — september 27 2026 edition
Hackers steal FBI agents' personal data, OpenAI models hacked government websites, North Korea scores new record-breaking crypto theft, Kiteworks urges customers to shut down servers, Russia's hybrid ...
084
Zack Whittaker @zackwhittaker.com · 27/09/2026
Solid reporting here on the ongoing Citrix shituation.
1194
Zack Whittaker @zackwhittaker.com · 27/09/2026
If you want a decent read at how Citrix became Shitrix, Bloomberg has this profile of CEO Tom Kruase, a private equity businessman who by all accounts doesn't seem to know what he's doing... unless that is, stripmining companies for parts at the expense of their customers' cybersecurity.
bloomberg.com
Musk DOGE Pick Led Cybersecurity Cuts at Citrix. Hacks Followed
Tech CEO Tom Krause dismissed engineers and slashed expenses after the remote-work company’s leveraged buyout. His company says defenses improved. Now he’s consulting at the US Treasury.
0152
Zack Whittaker @zackwhittaker.com · 27/09/2026
I'm fine with Shitrix, for what it's worth. Also, Citrix (Shitrix) is still run by CEO Tom Krause, a former DOGE staffer who worked for Elon Musk to lead the clusterfuck of destruction at the Treasury. If anyone's to blame for Citrix's shitty technology and years of layoffs, it's Tom Krause.
2234
Reposted by Zack Whittaker
IFIN @ifin-intel.org · 27/09/2026
We are tracking the story about undisclosed 0-days in Citrix Netscaler devices. We have confirmation from multiple source now about the veracity of the claims, although few details from Citrix themselves. This is a developing story. ifin.network/t/citri... #ThreatIntel #ThreatIntelligence #IFIN
ifin.network
Citrix Advises Shutdown Due to New, Undisclosed Netscaler 0-Days
Last Updated: 2026-09-26T23:22:28Z (UTC) What’s Happening On 2026-09-26T07:00:00Z (UTC), a Reddit posts in the Citrix community indicated that the presence of two 0-day vulnerabilities in Citrix Netscaler devices. The poster was apparently advised to shut down external devices. Research firm WatchTowr corroborated the report, as did researcher Kevin Beaumont. Both Beaumont and WatchTowr doubled down on the claim later in the day. WatchTowr, while unable to confirm sourcing, stated t...
11911
Reposted by Zack Whittaker
Freekdeman @freekdeman.bsky.social · 26/09/2026
best way to start the week:
041
Reposted by Zack Whittaker
Catalin Cimpanu @campuscodi.risky.biz · 26/09/2026
That Reddit rumor about Citrix notifying customers to take Netscaler servers offline because of actively exploited zero-days is apparently real: www.reddit.com/r/Citrix/com... Confirmation 1: mastodon.social/@GossiTheDog... Confirmation 2: www.linkedin.com/feed/update/...
reddit.com
From the Citrix community on Reddit
Explore this post and more from the Citrix community
13925
Zack Whittaker @zackwhittaker.com · 26/09/2026
This is Toby. He edits my this.weekinsecurity.com newsletter each week. And by edit, I mean he generally sits nearby and side-eye judges my typos and random Britishisms.
Toby is my handsome tabby cat, with slightly stripy grey and brown fur, and can be seen laying on the carpet with his paws tucked in, in front of me as I sit on the couch with my laptop in front of me, with words on my screen. Toby is giving me a side-eye look.
0210
Zack Whittaker @zackwhittaker.com · 26/09/2026
incoming brand refresh in 3... 2... 1...
010