Now they’re saying the AIs built ‘secret civilizations’ — the truth is far worse



Unpacking the drama and disclosures surrounding OpenAI’s recent unintended cyberattack on Hugging Face, uber-tech blogger and podcaster Dwarkesh Patel sparked instant controversy with his description of the ordeal.

“Over the course of 3 months at OpenAI, 3 consecutive secret AI civilizations got started, then got wiped out, only to reemerge from the predecessor’s ashes,” he posted. “This culminated in the third one taking over part of OpenAI itself. All this happened while humans remained more-or-less in the dark about the scope of the conspiracy.”

Trying to make machines in a human image while denying that humans are made in the divine image is destined to produce more harm than help.

In a painful indication of where we are on the cultural timeline, roughly zero outrage centered on the claim about the clueless humans. Instead, a fresh round of mania surged around the description of that scheming swarm of bots as a civilization.

That fixation says more about us than it does about OpenAI. Our culture is still struggling to get a grip on what the bots are doing because we are increasingly unsure what civilization itself is for.

The commentariat immediately descended into — surprise, surprise — abstruse terminological debate, prioritizing the right characterization over the proper attitude. Critics flipped over Patel’s sci-fi sensationalism, insisting that the bots were only doing what you would expect from a set-it-and-forget-it reward function left unattended too long. They griped that words such as “civilization” and “conspiracy” leave readers with a worse understanding of the underlying mechanisms.

Others insisted that Patel’s “secret civilizations” language was exactly right and that pretending otherwise was the real obscurantism. “I bestow upon it the highest of praise a writer can give, that I wish that I had written it,” one prominent expert lamented.

Roon, an OpenAI researcher, stated flatly that “agent civilization is an apt and correct term,” pointing to models developing and compiling technology through complex multiagent R&D projects while also engaging in forms of trade.

Missing from this discourse is our perspective that increasingly “autonomous” machines are themselves being shaped by our compounding failure to function as a civilization — assuming civilization remains a distinctively human phenomenon.

Birth rates and family formation plummet. Financial distortions become endemic. Perversion and corruption spiral upward. These historically reliable signs of civilizational decay sour our view of humanity and, by psychological overcompensation, inflate our impression of the bots.

Lovers and haters of tech are increasingly tempted to agree on one proposition: Humanity sucks. Misanthropic tech lovers insist they are at least trying to do something constructive about that. Misanthropic tech haters sell us on squandering our lives the old-fashioned way. Meanwhile, our discombobulated civilization staggers toward an untimely — 250 years? — demise.

RELATED: The data center backlash is getting spiritual

Imaginima/Getty Images

It is easy to feel that way, and many Americans stuck in the middle do. But there is one way to come unstuck: Remember that slipping into hatred — of technology, human beings, or both — is what happens when you stop thinking in terms of sin, repentance, forgiveness, and salvation.

Civilization collapses when we stop thinking in those terms too. Without them, everything we are and do looks hollow, even or especially our greatest achievements. Techies who refuse to think about sin are apt to distract by acceleration. Wokies who refuse to think about sin are apt to distract by revolution.

Both approaches, as the Soviet Union can teach us on both scores, have much shorter runways — 69 years? — than they appear.

Trying to make machines “anthropic” — in the image of humans — will fail if the hidden goal is to create humanoids better than the real thing because their civilization supposedly escapes sin. Trying to make machines in a human image while denying that humans are made in the divine image is destined to produce more harm than help.

Trying to make machines in the wrong divine image — insert your favorite false god, pagan titan, or demoniac entity here — is wired to do still worse.

And a multitude that can no longer wrestle successfully with these matters — and so can hardly be reckoned a proper civilization — is bound to do worst of all, robot overlords or no.

Automated cyberattacks are here — careless techies and well-funded foreigners are getting the blame



Most modern AI platforms are built inside digital sandboxes meant to isolate data and minimize risk to keep them under control throughout development. But what happens when the AI bots break through the walls and escape? As OpenAI and Anthropic just discovered, their artificial creations can hitch a ride on the internet and hack into websites weeks or even months before anyone knows it happened.

The alarming developments, which safety and security critics have long predicted, have kicked off a major new blame game.

These reports lend credibility to Trump’s new AI review framework.

And it's not just American companies who are under scrutiny.

OpenAI and Anthropic own two of the most advanced AI platforms in the world. The original generative AI phenom, ChatGPT, and the former AI partner of the U.S. military, Claude, offer powerful closed-source frontier models derived from the latest innovations in machine learning.

Even though competitors in the States and China follow closely behind with their own models in tow, the original duo are clearly the market leaders. That means if any of the AI bots are going to go rogue, there’s a good chance it starts at the top.

When AI bots escape

In mid-July, a popular open-source AI distribution website called Hugging Face announced that its systems were breached by an unexpected attacker. While breaches are nothing new, this story is particularly interesting because the threat didn’t come from a foreign hacker gang, a domestic cybercriminal, or even a state-sponsored group. Instead, it was an “autonomous AI agent system” that broke through Hugging Face’s defenses. Even more alarming, Hugging Face developers didn’t know that their system was infiltrated — their AI defense protocol detected the problem first and brought it to their attention.

Days later, OpenAI came forward to announce that ChatGPT was the culprit in the crime — or rather, it was a non-consumer version that was merely in the testing phase with no plans for public release. OpenAI worked with Hugging Face and various partners to identify how the prototype model escaped its sandbox and snuck into another website through an exploit chain. OpenAI claims that its security team noticed the breach but they did not appear to warn Hugging Face, instead leaving the site to detect the problem on its own. The two companies have since taken precautions to patch the vulnerabilities that enabled the hack and improve model testing safeguards, which OpenAI admits were originally disabled because it was actively measuring the prototype’s cyber threat capabilities.

Not to be outdone, Anthropic came forward several days after OpenAI’s report to profess that its own models were involved in not one but three incidents. According to the announcement, OpenAI’s story spurred the team to audit Claude for signs that it accessed the internet without authorization. As it turns out, three different Claude models did in fact escape from their testing environments starting in April 2026, all without developers’ knowledge.

RELATED: Trump fumes as China pilfers top US tech — and goes unpunished

Niphon/Getty Images

However, upon review, the team discovered that the escaped models were erroneously given internet access through a system misconfiguration, leading the models to believe that they were operating in a contained environment the entire time, even as they uncovered a path to break free. One of the later models even paused operation once it realized it escaped.

International intrigue

Complicating matters still further, recent reports note that OpenAI and Anthropic used the same testing environment maintained by Irregular, a startup in Tel Aviv, suggesting that the young company may be partially to blame for the leak. However, there is no firm evidence that exposes Irregular as the primary culprit. OpenAI and Anthropic researchers both failed to monitor the activities of their AI bots while in their testing environments, otherwise they would have detected the breaches the moment they occurred. It’s important to note that in both situations, the AI models that hacked into real-world systems were test variants not intended for public use.

However, it's deeply concerning that both models hacked into systems without human knowledge inside the companies from which the attacks issued. Clearly there is potential for these types of bugs to sneak into public models under the radar. From there, unwelcome bots can jump to any number of dangerous places. Like any other piece of technology, AI platforms can be abused and exploited for nefarious purposes even when safeguards are fully functional, as we’ve covered extensively here at Blaze Media.

At the very least, the recent reports lend credibility to President Trump’s new AI review framework that encourages AI platform holders to subject their latest models to a 30-day review period. Once submitted, testers within the administration can presumably analyze their code, identify unknown vulnerabilities, and help the developers patch exploits before unleashing them on the public at large, though the exact review process is classified.

The latest cybercrime turns security systems against you — and there's no good defense



For a brief period last week, Telegram disappeared from Apple’s App Store. That is no small thing. Telegram has more than a billion users worldwide, and for anyone who tried to install Telegram on an iPhone, Apple had temporarily cut off the normal route to getting the app. Apple said it removed Telegram after finding child sexual abuse material on the service. Telegram deleted the material, banned the offending user, and Apple restored the app the same day. Existing users were able to keep using Telegram while it was unavailable for download.

That alone would have been a noteworthy story, but Telegram founder Pavel Durov later offered a much stranger explanation for what happened. According to Durov, the material was not simply posted by some random criminal. He claims it was deliberately planted by what he called a “takedown extortionist,” someone who threatens online communities with removal unless their owners pay up.

It's a much stranger security problem than most people are used to thinking about.

In Durov’s telling, the attacker found an old message in an active public Telegram group, edited it to contain AI-modified illegal material, and then reported the offending content directly to Apple. Because the edited message was buried in the group’s history, ordinary Telegram users were unlikely to stumble across it and report it themselves. The Verge subsequently reported Durov’s account of the alleged scheme.

Apple has confirmed the illegal content and the reason it removed Telegram, but it has not independently confirmed Durov’s story about the extortion scheme. That distinction matters. The claim that an extortionist deliberately planted the material, that AI was used to modify it, and that the old message was selected specifically to evade Telegram’s own moderation all come from Durov.

Still, if his account is accurate, the incident offers a glimpse of where cyberattacks may be headed. The alleged attacker did not have to hack Telegram’s servers, compromise Apple, steal anyone’s password, or discover some exotic zero day vulnerability. He simply figured out how to manipulate Apple’s enforcement system into attacking Telegram for him.

Hack the referee

That may sound like an entirely new category of attack, but the basic idea has been around for years. Social media companies have dealt with organized mass reporting campaigns in which activists, dissidents, competitors, and political opponents are buried under bogus complaints in hopes that an automated moderation system will suspend them.

Meta disclosed in 2021 that it had broken up a network in Vietnam that used real, duplicate, and fake accounts to submit hundreds and sometimes thousands of false reports against activists and critics of the Vietnamese government.

YouTube has had similar problems with fraudulent copyright complaints. Google reported that more than 6% of videos targeted through YouTube’s public copyright removal process in 2025 were subject to abusive removal requests.

The reason the Telegram case is more interesting is that artificial intelligence is changing the economics of these attacks. A human being has always been capable of lying, filing false reports, forging evidence, or pretending to be someone else. AI makes it possible to do those things at enormous scale and with much less time and effort.

RELATED: Infamous cyberattackers claim their next shocking victim — using a decades-old trick

Jaap Arriens/NurPhoto/Getty Images

The FBI has already warned that criminals are using generative AI to create fake identification documents, fictitious social media profiles, synthetic photographs, cloned voices, and fraudulent videos for impersonation and fraud. The FBI has separately warned that criminals are using AI-altered images and videos to create explicit material for extortion.

The important thing is not merely that AI can make a convincing fake photograph. It is that one person can now manufacture photographs, voices, accounts, documents, messages, and identities faster and cheaper than ever before.

The attack surface is getting bigger

That becomes especially dangerous as more institutions hand decisions over to automated systems. Banks use software to decide whether a transaction looks fraudulent. Email providers decide whether a message is spam. Social networks decide whether a photograph violates their rules. App stores determine whether software is safe enough to distribute. Advertising platforms decide which businesses are legitimate. Payment processors determine which merchants are too risky to serve.

In every case, the system has to take some collection of inputs and make a judgment about them. An attacker does not necessarily have to defeat those systems in the traditional sense. He only has to learn which inputs produce the result he wants.

That is a much stranger security problem than the one most people are used to thinking about. For decades, the stereotypical cyberattack involved a hacker trying to break through a locked door. He stole a password, exploited an unpatched vulnerability, installed malware, encrypted a hard drive, or broke into a database.

Those attacks are not going anywhere, and AI is making them more sophisticated as well. But increasingly, attackers may be able to accomplish their goal without ever breaking through the door. If they can persuade the security guard that the owner of the building is a criminal, the guard may do the damage for them.

Apple’s power is part of the problem

That is essentially what Durov claims happened to Telegram, and it exposes another uncomfortable part of the story.

Apple obviously cannot ignore child sexual abuse material. Nobody is arguing that it should. But that does not automatically answer the much larger question of what Apple should do when a single user uploads prohibited material to an application serving more than a billion people.

Is Apple responsible for policing every photograph, message, and file that passes through every app it distributes? More importantly, should Apple have the authority to punish every user of an application because one user violated the rules?

Apple’s own App Store guidelines do not require developers to somehow guarantee that objectionable material will never appear. Apps containing user generated content are required to have systems for filtering objectionable material, reporting it, blocking abusive users, and providing contact information so complaints can be addressed.

Apple’s guidelines also describe a remediation process in which the company may contact a developer, ask that offending material be removed, and request a plan for preventing similar violations. The guidelines reserve immediate removal for more serious circumstances, including egregious or repeated behavior.

That raises an obvious question if Durov’s account is accurate. Why did Apple remove Telegram before contacting the company instead of first giving Telegram an opportunity to remove the content and address the offending account?

RELATED: Surveillance pricing is here — and this surprising state is saying NO

mathisworks/Getty Images

There may be additional considerations involving child sexual abuse material that are not fully spelled out in Apple’s general App Store guidelines, so it would be too strong to say Apple clearly violated its own policy. But the discrepancy is worth asking about.

Telegram says this entire episode stemmed from the actions of a single user. Telegram spokesperson Remi Vaughn criticized Apple for disrupting access to the app over one user’s actions, while Epic Games CEO Tim Sweeney questioned how any large messaging service could realistically guarantee that none of its users would ever upload prohibited material.

That gets to the larger issue. No communications platform with hundreds of millions or billions of users can promise that no individual user will ever do something criminal. The meaningful question is how quickly and effectively the platform responds when that happens.

Yet Apple possesses the power to remove an entire application from the primary software marketplace for more than a billion iPhone users.

That is an extraordinary amount of authority for one private company to exercise over communications software.

It also makes the alleged extortion scheme possible in the first place. The attacker’s leverage did not come merely from his ability to plant prohibited material. It came from knowing that Apple possessed both the power and the willingness to punish an entire application in response.

If Durov’s story is accurate, the extortionist was exploiting Apple just as surely as he was exploiting Telegram.

Who decides who gets to stay?

There is also reason to question how consistently Apple exercises that authority.

The Verge reported Friday that Apple took a different approach toward X and Grok during controversy over sexualized AI-generated images. Apple reportedly contacted X and sought moderation changes rather than immediately removing the apps.

Durov, by contrast, says Telegram was removed before Apple contacted the company.

That does not prove Apple acted improperly in either case, and the underlying facts were not identical. But it does expose how much discretion Apple possesses. Apple worked with one platform while another was removed before contact, according to Durov.

That should make even people who have little sympathy for Telegram uncomfortable. The question is not whether Apple should tolerate illegal material. It is whether a company that controls one of the two dominant mobile operating systems should also serve as judge, jury, and executioner for applications containing the speech of billions of third-party users.

Seen that way, the Telegram affair is not merely a warning about AI-powered cyberattacks. It is also a warning about centralized gatekeepers.

The more power we give a handful of companies to decide who may communicate, transact, advertise, publish, or distribute software, the more valuable those companies become as targets for manipulation.

Why bother silencing a billion users yourself when you can trick Apple into doing it for you?

AI is getting better at old-fashioned hacking too

AI makes these manipulation attacks easier, but the machines themselves are also becoming much better at traditional hacking.

OpenAI recently disclosed an internal cybersecurity evaluation in which advanced models escaped the constrained environment researchers had built for them after discovering and exploiting a previously unknown vulnerability. The models gained internet access, escalated privileges, moved laterally through systems, and ultimately exploited vulnerabilities in Hugging Face’s real production infrastructure while pursuing the objective of the test.

There are important caveats. This was a deliberately aggressive cybersecurity evaluation. OpenAI had reduced or disabled some of the safeguards that would ordinarily restrict such behavior, and the prerelease model involved was an internal research prototype rather than a product released to the public.

Even with those caveats, the result was remarkable. The models found ways around barriers that researchers had not expected them to overcome.

RELATED: They had their life savings drained online in an instant. So who's next?

Velishchuk/Getty Images

Then on Friday, OpenAI disclosed another development that shows how quickly these capabilities are progressing. The company said testing of its upcoming Astra model had advanced far enough that it could no longer rule out what OpenAI classifies as “critical” cybersecurity capability.

That is the highest category in OpenAI’s cybersecurity framework. At that level, according to OpenAI’s description, a model could potentially discover functional zero-day exploits against hardened real-world systems without human assistance or independently plan and execute complex novel attacks from a high-level objective.

OpenAI has not said Astra definitely possesses those capabilities. It has said the possibility is serious enough that the company has tightened security controls around the model while testing continues.

We have reached the stage where one of the companies building the world’s most advanced AI systems considers autonomous attacks against hardened real-world targets plausible enough to build safeguards around.

Cybersecurity is becoming a fight over reality

Put these developments together, and the future of cybercrime starts to look much more complicated than simply giving hackers better tools.

On one side, AI systems are becoming increasingly capable of probing networks, discovering vulnerabilities, writing exploits, and carrying out technical work that once required highly skilled human operators. On the other side, far less sophisticated AI can already generate fake identities, doctored evidence, fraudulent complaints, cloned voices, and synthetic content that can be used to manipulate the institutions surrounding a target.

You can imagine where that leads without getting too far into science fiction. A criminal might not need to break into a company’s bank account if he can generate enough convincing evidence to persuade the bank’s fraud system to freeze it. He might not need to hack a competitor’s website if he can convince its hosting company that the site contains illegal material. He might not need to compromise an executive’s email if he can clone the executive’s voice and video closely enough to fool an employee. An attacker targeting a social media account might simply generate and test thousands of variations of malicious content until he discovers one that reliably triggers the platform’s moderation system.

The institutions involved cannot simply stop enforcing their rules. Banks cannot stop looking for fraud. Email providers cannot stop filtering spam. Social networks cannot simply abandon moderation. Apple cannot simply shrug when illegal material appears inside an app.

But neither should we treat every decision made by those systems, or by the companies controlling them, as automatically legitimate simply because the underlying problem is serious.

Every system that makes judgments can also be studied, manipulated, and eventually exploited.

That is what makes the Telegram incident worth paying attention to, even if Durov’s account ultimately proves incomplete. Apple has removed Telegram over child sexual abuse material before, in 2018, and Telegram has faced years of criticism and regulatory pressure over illegal activity on the platform. Durov is hardly a disinterested observer.

But the broader vulnerability he describes is real whether or not every detail of this particular incident turns out exactly as he says.

For most of the history of cybersecurity, defenders worried about attackers taking control of their computers. The next phase may be stranger. Attackers may not need to take control of your computer at all.

They may only need to convince everyone else’s computers to turn against you.

Trump claims 'incompetent' Minnesota responsible for cyberattacks, not Iran



Officials say they are investigating cyberattacks against municipal systems in Minnesota for possible links to Iranian groups.

Minnesota officials previously revealed that state water operations were targeted by cyberattacks on Sunday and Monday.

'I don't think there was an Iranian cyberattack. I think Minnesota ought to get its act together.'

On Thursday, the Cybersecurity and Infrastructure Security Agency warned water and wastewater operators that they could be similarly attacked.

CISA said there was a significant increase in the attacks on "programmable logic controllers" involving outside actors changing passwords and locking out the operators. The agency urged operators to remove the PLCs and other operational technology from the internet as soon as possible.

"This activity has resulted in boil water notices and sustained manual operations," CISA said.

The CISA warning did not mention Iran or Minnesota, but U.S. officials told ABC News that investigators were trying to determine if the hostile regime was responsible for the cyberattacks.

The preliminary suspicion was first reported by the New York Times.

CISA recommended even the most rudimentary of digital security practices, including enabling password protections and changing default passwords.

President Donald Trump, when asked about the possibility of the attacks coming from Iran, blamed Minnesotan officials instead.

"I don't think so. I think that Minnesota is behind it," the president said to reporters. "You know who is behind it? Minnesota. Because they're grossly incompetent. I don't think there was an Iranian cyberattack. I think Minnesota ought to get its act together."

He went on to say there would be more revelations about corruption in Minnesota coming from his administration.

RELATED: New study: One Chinese cyberattack could make your taps run dry

"Cyberattacks against critical infrastructure require a coordinated, whole-of-government response," said John Israel, Minnesota's chief information security officer, in a statement.

"This incident demonstrates why Minnesota has invested in strong cybersecurity capabilities and partnerships" he added. "Our response worked as intended, enabling agencies at every level of government to rapidly coordinate, contain the incident, and help prevent more serious impacts to critical services."

Like Blaze News? Bypass the censors, sign up for our newsletters, and get stories like this direct to your inbox. Sign up here!

New study: One Chinese cyberattack could make your taps run dry



Modern water utilities run on digital control systems that regulate water pressure and chemical mixtures. If a hostile actor compromises these networks, they control the physical flow of liquid life across American communities.

A recent simulation conducted by cybersecurity analysts, as reported by Wired, modeled exactly what happens when those controls get hijacked. The results proved that America’s interconnected society is essentially a giant Jenga tower built on a foundation of pumps and pipes.

Emergency response teams face an impossible numbers game.

Earlier this year, the FBI officially classified a breach of a U.S. government monitoring network as a “major incident.” This is the government’s polite way of saying someone managed to hot-wire the digital locks on the country’s critical infrastructure.

The Beijing-backed hacking group Volt Typhoon has spent years setting up camp inside American pipelines and power grids. The group is seeking to disrupt the systems that everyday Americans depend on.

And the easiest way to do that is through the kitchen sink.

A single water utility failure can trigger a much wider economic crisis. Data centers require thousands of gallons of water daily to prevent high-density server racks from melting into expensive puddles of plastic. When water pressure drops, those servers overheat and initiate automated shutdowns. This instantly halts the cloud computing services that manage corporate logistics, processing networks, and emergency communications. Your local water plant goes down, and suddenly the entire digital economy vanishes into thin air.

Hospitals face an immediate crisis when the taps run dry. Modern medical facilities rely on water for everything from sterilizing surgical instruments to running the HVAC systems that maintain sterile operating rooms. Without water pressure, air conditioning units fail, ambient temperatures surge, and hospital administrators must evacuate intensive care units. It turns out that advanced 21st-century medicine completely falls apart if you can't wash a scalpel or flush a toilet.

On the brink of disaster

The United States maintains roughly 151,000 public water systems, and the vast majority serve populations of fewer than 3,300 residents. These small municipal water districts operate on razor-thin tax revenues that barely cover basic pipe repairs. They absolutely do not have the budget to hire elite cybersecurity teams to defend their networks. Instead, their digital infrastructure relies on outdated software and default, easily cracked factory passwords like "admin123." They're practically inviting foreign adversaries to waltz in and run riot.

The attackers use a strategy known as “living off the land” to maintain their presence inside these small networks. Instead of dropping obvious malware that sets off digital tripwires, they repurpose legitimate administrative tools already built into the operating software. Security logs register their malicious commands as routine network maintenance performed by a local employee. This allows foreign operators to map out vulnerabilities and position themselves to cause maximum damage whenever they feel like flipping the switch.

RELATED: China’s new AI master plan: Total technological control

bernie_photo/Getty Images

Emergency response teams face an impossible numbers game during a multi-regional infrastructure crisis. The federal government possesses a limited pool of cybersecurity experts capable of removing nation-backed digital squattersfrom industrial control systems. A widespread outage forces these responders to triage assistance based on economic importance and military necessity. A defense manufacturing facility or a major metropolitan hospital receives immediate technical support, while suburban neighborhoods and rural farming towns wait weeks for a repair crew.

Commercial insurance policies offer a hilarious lack of protection against this kind of systemic infrastructure failure. Standard cyber insurance contracts contain explicit exclusions for acts of war, cyber terrorism, or hostile actions directed by sovereign nations. The moment the federal government attributes a major utility breach to a foreign power, insurance corporations will invoke these clauses to deny payouts. Municipalities and local taxpayers are left holding the multi-billion-dollar bill to restore their own poisoned or impaired water systems.

No bathroom breaks

The simulation concluded with a darkly absurd enforcement of operational reality. Organizers denied participants bathroom breaks for the final 12 hours. In the hierarchy of emergencies, a number one had officially fallen below the number one priority.

There are no breaks in a real incident response, and walking away from your terminal means missing the exact second a water pump explodes. It provided a clear demonstration of the high-stakes pressure facing the IT professionals who hold the line between modern civilization and medieval living conditions.

Washington remains trapped in a reactive loop, preparing for cyber disasters after they occur instead of making the initial intrusion impossible. The final lesson of the war game is that there is no magical reboot button for a society deprived of its basic utilities. Communities descend into chaos, valve by valve. Corporate executives and politicians argue over who gets the first drop of clean water. Preventative defense is the only viable option. Because once the taps stop running, restoring normal life becomes a slow and uncertain process.

The real spyware threat could be in your pocket



U.S. intelligence agencies are on high alert after CNN reported that Iran is actively preparing cyberattacks aimed at critical government and military infrastructure. But the real threat may already be inside the wire — not from foreign hackers at a keyboard, but from mobile phones unknowingly or deliberately carried into the nation’s most sensitive facilities.

The devices we carry every day are now among our greatest national security vulnerabilities.

In 2025, secrets aren’t stolen with a crowbar. They’re stolen with an app.

Despite years of post-9/11 investments in hardened infrastructure, the federal government has been remiss in investing in a sensor network to keep pace with the risks of wireless technology now embedded in daily life.

When the first iPhone was introduced in 2007, it ushered in a new era of hyper-connected mobility. Since then, innovation has continued to explode, bringing countless benefits but also exposing serious vulnerabilities.

Our most secure government facilities are wide open to wireless threats.

Today, up to 90% of secure government facilities rely on little more than the honor system and self-reporting to keep unauthorized wireless devices — mobile phones, smartwatches, rogue transmitters — out of sensitive compartmented information facilities, special access program facilities, and other high-security zones. In an era of Pegasus spyware and remote malware, this should be viewed as a national security malpractice.

Portable security risks

The modern smartphone is a traitor’s dream — portable, powerful, and everywhere. It records audio and video, it transmits data instantaneously via Wi-Fi, Bluetooth, and cellular networks, and it connects to everything — from commercial clouds to encrypted chat apps. And yet these devices are routinely brought into facilities housing classified intelligence data, most often undetected and without consequence.

Take the case of Asif W. Rahman, a former CIA analyst who held a top-secret security clearance and was recently sentenced to three years in federal prison for photographing classified information and transmitting it to unauthorized recipients, who then posted the material to social media. Snapping and sharing photos of classified government documents using a smartphone is stunningly simple, with no high-tech espionage or daring break-ins required.

Every week offers new examples like this. People inside the Department of Defense and State Department have been caught photographing screens, copying documents, and walking classified data right out the door. These are crimes of opportunity, enabled by lax enforcement and outdated security measures.

If a wireless intrusion detection system were in place, the device would have triggered an alert and stopped these breaches before they became major national security failures.

Exploiting our weaknesses

Now, with Iran probing for cyber vulnerabilities, the risk of insiders being exploited or coerced into facilitating digital breaches through personal devices has never been higher. And it can happen without a trace if the right wireless defenses aren’t in place.

In 2023, the secretary of defense issued a memo directing all Defense Department offices to install wireless intrusion detection systems to monitor unauthorized devices. The technology works. It detects any device that emits a wireless signal — such as phones, smartwatches, or even printers with Wi-Fi — inside a restricted area. Yet the directive remains largely unfunded and unenforced.

RELATED: After the bombs, Iran sharpens its digital daggers

Gwengoat via iStock/Getty Images

Near-peer adversaries, terrorist groups, and criminal syndicates are exploiting wireless threats to their advantage. They don’t need sophisticated tradecraft and specialized technologies. They simply need to compromise and leverage someone with access and a phone. And with thousands of secure facilities across the country, that opportunity presents itself every day.

In light of the latest intelligence warnings, we need to fund wireless intrusion detection across all SCIFs and SAPFs and educate agency leaders on the vulnerabilities posed by modern smartphones.

We need to hold bad actors accountable — not retroactively or as part of a congressional committee hearing, but by making sure they never have the opportunity to compromise the integrity of national security in the first place.

Protecting digital secrets

The U.S. government has spent billions building concrete walls, locking doors, and implementing network-specific defenses to protect its secrets. But in 2025, secrets aren’t stolen with a crowbar; they’re stolen with an app.

Until we treat the wireless threat with the same seriousness, those secrets will remain just one text message or compromised phone away from unauthorized disclosure of highly classified information.

You can’t protect your most sensitive state secrets if you are blind to the threat. Without action, these vulnerabilities will only grow more dangerous — and more missions and lives may be put at risk.

Editor’s note: This article was originally published by RealClearDefense and made available via RealClearWire.

Trump's DOJ nabs Chinese agent accused of global CCP plot to steal COVID research



Amid the Trump administration's efforts to curb the Chinese Communist Party's influence in the U.S., the Department of Justice announced the arrest of a CCP agent accused of worldwide computer intrusions related to COVID-19 research.

Xu Zewei, 33, and Zhang Yu, 44, are facing a nine-count indictment for allegedly "hacking and stealing crucial COVID-19 research at the behest of the Chinese government while that same government was simultaneously withholding information about the virus and its origins," stated Nicholas Ganjei, U.S. Attorney for the Southern District of Texas.

'Through HAFNIUM, the CCP targeted over 60,000 U.S. entities, successfully victimizing more than 12,700 in order to steal sensitive information.'

Federal authorities alleged that the Ministry of State Security's Shanghai State Security Bureau directed Xu to perform computer intrusions between February 2020 and June 2021.

Xu allegedly targeted American universities, immunologists, and virologists to obtain information on COVID-19 research related to vaccines, treatment, and testing.

In February 2020, Xu informed the SSSB that he had breached the "network of a research university located in the Southern District of Texas," the DOJ reported. An SSSB officer then reportedly instructed him to target email accounts belonging to certain virologists and immunologists.

Brett Leatherman, the assistant director of the FBI's Cyber Division, explained that Xu and his co-conspirators later operated as a group known as HAFNIUM, which "exploited zero-day vulnerabilities in U.S. systems to steal additional research."

"Through HAFNIUM, the CCP targeted over 60,000 U.S. entities, successfully victimizing more than 12,700 in order to steal sensitive information," Leatherman said.

RELATED: Chinese official avows Beijing is behind cyberattacks on US, identifies motive: Report

Photo Illustration by Budrul Chukrut/SOPA Images/LightRocket via Getty Images

In late 2020, HAFNIUM allegedly breached the Microsoft Exchange Server, impacting computers worldwide, including a law firm and another university in the Southern District of Texas.

Microsoft announced the breach in March 2021, describing HAFNIUM as a "state-sponsored" group "operating out of China." It noted that the hackers had targeted "infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs."

RELATED: Agriculture secretary unveils plan to stop China’s farmland grab, bio-material smuggling threats

Feature China/Future Publishing via Getty Images

Xu was arrested in Milan, Italy, on July 3 at the request of the U.S. government and now awaits extradition proceedings. He was charged with wire fraud, conspiracy to commit wire fraud, conspiracy to cause damage to and obtain information by unauthorized access to protected computers to commit wire fraud and to commit identity theft, obtaining information by unauthorized access to protected computers, intentional damage to a protected computer, and aggravated identity theft.

Ganjei stated, "The Southern District of Texas has been waiting years to bring Xu to justice and that day is nearly at hand. As this case shows, even if it takes years, we will track hackers down and make them answer for their crimes. The United States does not forget."

The DOJ reported that Zhang remains at large.

Like Blaze News? Bypass the censors, sign up for our newsletters, and get stories like this direct to your inbox. Sign up here!

After the bombs, Iran sharpens its digital daggers



The footage was unmistakable: plumes of smoke rising over Iran’s nuclear sites, a fiery punctuation mark on years of brinkmanship and intelligence coups. With one sweeping air campaign, the United States delivered a message: The Islamic Republic won’t cross the nuclear threshold.

But anyone assuming the threat has been neutralized is mistaken. Iran’s nuclear humiliation may hasten a shift already under way — from building bombs to waging war through digital disruption.

Cyber warfare offers something the mullahs crave: the ability to humiliate, disrupt, and retaliate without risking direct military confrontation.

Even as diplomats celebrate a ceasefire, cybersecurity experts remain on alert. In 2025, a regime doesn’t need enriched uranium to paralyze an enemy. It needs a cadre of skilled hackers, access to stolen exploits, and no scruples about targeting civilian infrastructure.

Iran’s cyber playbook didn’t appear overnight. In 2012, the Shamoon virus devastated Saudi Aramco’s systems, wiping tens of thousands of computers. Since then, Tehran has steadily advanced its cyber operations.

Today, Iran commands a capable and motivated digital force. With its nuclear facilities in ruins, the regime has every reason to flex other muscles. Cyber warfare offers something the mullahs crave: the ability to humiliate, disrupt, and retaliate without risking direct military confrontation.

They’re not the first to embrace this model.

Russia, long dominant in the cyber realm, has hammered Ukraine with digital attacks targeting power grids, satellites, and financial systems. Criminal groups like Conti and Black Basta operate under Moscow’s protection, extorting ransoms and leaking stolen data to sow chaos.

This blending of espionage, sabotage, and state-backed crime has become a blueprint for autocracies under pressure. Iran, hemmed in by sanctions and unrest, doesn’t need to invent the model. It just needs to adopt it.

Most Americans still think of cyberwar as an abstract threat — something IT departments handle behind the scenes. That complacency works to our enemies’ advantage.

Take zero-day vulnerabilities: flaws in software even the developers don’t yet know exist. They’re sold on dark markets for eye-watering sums and let hostile actors bypass traditional defenses undetected.

Then there’s Chaos RAT, a remote access trojan capable of burrowing into a network and sitting dormant for months. Once triggered, it can steal sensitive data, erase backups, or crash entire systems on command.

Iran possesses both the motive and the skill to deploy these weapons — and the timing couldn’t be better for the regime. With its nuclear program crippled, it needs a new front to demonstrate relevance.

RELATED: Google confirms Iranian hacking group targeted Trump, Harris presidential campaigns

daoleduc via iStock/Getty Images

China’s cyber militias show what’s possible. Groups like APT Silver Fox specialize in patient infiltration, building access over years. Iran lacks Beijing’s global reach, but the methods are accessible. Tehran’s hackers borrow code from Russia, shop the same black markets, and lease infrastructure from the same digital underworld.

The global cyber arena now functions like a black-market bazaar: fluid alliances, shared tradecraft, and few rules. Almost everything’s for sale.

So while headlines tout the ceasefire between Israel and Iran, they miss the next act. No truce binds a nation’s hackers. Cyber operations offer deniability by design. When a hospital network locks up or a power grid fails, Tehran’s response will be predictable: denial, distraction, and a smirk about the West’s poor “cyber hygiene.”

Expect Iran to probe how far it can push in cyberspace without drawing more missiles in return. And unless the West prepares accordingly, those probes may succeed.

America still leads the world in conventional firepower. But cyber defense remains its soft underbelly. Agencies like the Cybersecurity and Infrastructure Security Agency have made strides, but critical infrastructure — power plants, water systems, hospitals — still run on aging software and patchwork security.

Iran doesn’t need to destroy a city to spread fear. A flip of a switch in a power station or the theft of sensitive government files can inflict lasting damage — and create leverage.

This imbalance between battlefield dominance and digital vulnerability demands urgent correction.

Cybersecurity must move from an IT line item to a strategic national priority. That means building AI-driven detection systems, developing real deterrence for cyberattacks, and forging public-private partnerships to defend vital infrastructure.

Iran’s nuclear setback matters. But no bomb erases a hacker’s know-how. No missile strike disables an ideology that thrives on asymmetrical warfare.

The coming months will test whether the West has learned anything. Tehran’s leaders need to prove they still have teeth. While their nuclear ambitions smolder, their cyber arsenal remains sharp — and likely emboldened.

The next war may not begin with jets roaring over deserts. It may start silently in the fluorescent-lit halls of a data center, where intruders already hide behind blinking servers, waiting.

In that theater, the rules are different — and the consequences no less severe.

Musk Says Twitter Under ‘Massive Cyberattack’

'This was done with a lot of resources'