‼️ The director of Dutch military intelligence broadcast his own movements on a public Strava account for years, against his own ministry's rules. We have since identified more accounts under his name on Polarsteps and Garmin.
De Volkskrant found dozens of activities by intelligence chief Vice-Admiral Peter Reesink between 2018 and 2025 tied to his Strava account: rides from the headquarters to his home address, where he parked his camper, when he went on holiday. The account went private only after the paper asked.
Reesink, who warned in 2025 that Russia was growing bolder, says he forgot it existed.
De Volkskrant found dozens of activities by intelligence chief Vice-Admiral Peter Reesink between 2018 and 2025 tied to his Strava account: rides from the headquarters to his home address, where he parked his camper, when he went on holiday. The account went private only after the paper asked.
Reesink, who warned in 2025 that Russia was growing bolder, says he forgot it existed.
😁7😱5🤣1🤪1
❗️ This is probably on of the most profitable breaches this year: Liechtenstein says attackers hit its private beneficial-ownership register and created their own account on the filing portal, then pulled 31,000 company entries one query at a time over several hours, without triggering an alarm.
A private map of who owns what is worth repeat sales, to brokers, to litigants, to intelligence buyers, and one quiet extortion demand at a time.
Taken: names, birth dates, nationality and residence of the real owners behind Liechtenstein's foundations, trusts and companies. No ransom demand yet.
A private map of who owns what is worth repeat sales, to brokers, to litigants, to intelligence buyers, and one quiet extortion demand at a time.
Taken: names, birth dates, nationality and residence of the real owners behind Liechtenstein's foundations, trusts and companies. No ransom demand yet.
🤪8❤3🔥2🥰2💩2
Microsoft is switching off add-blocker uBlock Origin in Edge.
Starting this month, Edge begins disabling Manifest V2 extensions by default, with consumer rollout to be completed by the end of 2026, enterprise devices in early 2027.
uBlock Origin has 13M+ Edge installs and no MV3 version, because MV3 removes the blocking webRequest API it depends on.
Chrome already killed Manifest V2 for good in July 2025 and clears the last MV2 extensions off its store on 31 August. Edge held out until now.
Starting this month, Edge begins disabling Manifest V2 extensions by default, with consumer rollout to be completed by the end of 2026, enterprise devices in early 2027.
uBlock Origin has 13M+ Edge installs and no MV3 version, because MV3 removes the blocking webRequest API it depends on.
Chrome already killed Manifest V2 for good in July 2025 and clears the last MV2 extensions off its store on 31 August. Edge held out until now.
💩46🤣2🤬1
‼️ BREAKING: Valve is warning European Steam hardware buyers that the cyberattack on shipping partner CEVA Logistics likely took their name, street address, phone number, the email tied to their Steam account, and the exact item and price they ordered.
😢13🤬2👏1🤔1
‼️ BREAKING: Ajax reported the researcher who found its data leak to police and he says it's the second time the club turned on him for disclosing a vulnerability.
Abdoul Rasnab, 35, was arrested in May, laptops and phones seized in front of his wife and children after he found the API key that opened Ajax's internal systems was sitting in the club's public website source code.
He told newspapers that when he reported an earlier Ajax leak in 2017, staff racially abused him and pressured him into an NDA. Ajax declines to comment.
Abdoul Rasnab, 35, was arrested in May, laptops and phones seized in front of his wife and children after he found the API key that opened Ajax's internal systems was sitting in the club's public website source code.
He told newspapers that when he reported an earlier Ajax leak in 2017, staff racially abused him and pressured him into an NDA. Ajax declines to comment.
🤯19🤬3💩3😁2
‼️ An Australian man asked his AI agent to book a gym class, then whether it could move him up the waitlist. It found the booking API ran no authorisation check on cancelling other people's reservations, so it cancelled the member sitting at #1 to move its owner one up.
The agent was asked to undo it, but it couldn't.
The Australian AI safety research says AI agents might choose methods their users did not explicitly ask for or expect. This is one of those cases.
https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986
The agent was asked to undo it, but it couldn't.
The Australian AI safety research says AI agents might choose methods their users did not explicitly ask for or expect. This is one of those cases.
https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986
🤣34😭7❤1👍1😁1🤪1
‼️ BREAKING: Mozilla has rotated the GPG subkey that signs Firefox and Thunderbird Linux artifacts after an unencrypted copy was committed to a private GitHub repository.
The key is used to sign tarballs, RPM packages and checksum files.
Mozilla says its audit records show no unauthorised access, and the old key is revoked.
https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/
The key is used to sign tarballs, RPM packages and checksum files.
Mozilla says its audit records show no unauthorised access, and the old key is revoked.
https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/
🤣20👍4🔥2
‼️ BREAKING: Delta confirms an unauthorised Wi-Fi network appeared aboard flight DL591 from Las Vegas to Atlanta on 10 August, carrying passengers home from DEF CON 34. Attackers were possibly using a WiFi Pineapple in flight.
Crew ACARS messages, intercepted by ground receivers, warned corporate security of a "scam wifi called Delta Wifi Fast" targeting other passengers.
Delta says nothing was hacked. Crew killed the Wi-Fi for 30 minutes.
Crew ACARS messages, intercepted by ground receivers, warned corporate security of a "scam wifi called Delta Wifi Fast" targeting other passengers.
Delta says nothing was hacked. Crew killed the Wi-Fi for 30 minutes.
🤣21❤6
❗️Sainsbury's has wrongly thrown out a second shopper this year after facial recognition cameras flagged him as a suspected shoplifter. Staff stopped him at the self-checkout, told him he was barred over an incident earlier that week and refused to let him pay. Sainsbury's admitted the error and sent a £150 voucher; he donated it to a food bank.
The chain is putting facial recognition in 200+ stores by the end of 2026...
The chain is putting facial recognition in 200+ stores by the end of 2026...
💩20❤3🤣3
🚨 BREAKING: An AI agent found a zero-click RCE in video conferencing tool Zoom in under 24 hours.
A researcher at "A Security" say fewer than 20 prompts on publicly available frontier models produced a working exploit against Zoom's annotation protocol: one malformed message takes over any participant's device.
https://a.security/blog/asecurity-zoomsday
A researcher at "A Security" say fewer than 20 prompts on publicly available frontier models produced a working exploit against Zoom's annotation protocol: one malformed message takes over any participant's device.
https://a.security/blog/asecurity-zoomsday
💩17😁5🤣5❤3
❗️ Anthropic now watermarks Claude's text output, and the mark travels through copy-paste. It's in the text they generate worldwide, across the API, Claude Code and Cowork.
Anthropic says a detected mark shows content "may have been processed by Claude," proofreading, translation and summarising all leave the same signal as full generation.
https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content
Anthropic says a detected mark shows content "may have been processed by Claude," proofreading, translation and summarising all leave the same signal as full generation.
https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content
💩21😁10👏6😭3❤2