I’m a gamer and a parent. The KIDS Act makes my kids less safe.



I was lucky to grow up during the adolescence of the tech age. Sleepovers meant Super Smash Bros. with friends. The 2000s meant building free personal websites and poking around whatever new technology had just appeared. A lot of my formative experiences came from discovering what these tools could do.

Now I’m a young father, and I want my kids to have the same chance to enjoy technology’s creativity and connectivity.

The KIDS Act risks placing more sensitive information in more places while flattening the very different ways children use technology.

Of course, security was always part of the bargain. As technology has evolved, so have the vulnerabilities. But the KIDS Act approaches those risks with a sledgehammer — and may make children less safe in the process.

A basic cybersecurity principle is that services should collect as little data as possible — certainly no more than they can reasonably protect. The KIDS Act pushes in the opposite direction.

If gaming services and social media platforms must make legally consequential decisions based on a user’s age, more of them will need some way to verify it. That means more companies asking children and parents for sensitive information — and more databases that can be breached.

The risk is not merely that more data could leak. The data itself could become more sensitive. Liability concerns may be enough to incentivize some services to demand government-issued IDs, biometric information, or similarly intrusive identifiers.

We have already seen the danger of age-verification systems creating new troves of information. In the United Kingdom, a similar law helped drive broader age-checking requirements, and a later Discord data breach exposed identity documents held by a third-party verification provider. The point is not that every age check will produce a breach. It is that collecting information that was never needed before creates something new to steal.

The KIDS Act also sweeps very different online experiences into a one-size-fits-all framework. App-based games, console games, PC games, and social platforms do not expose children to the same kinds of interactions or risks.

Parents should be vigilant about how their children use all of them. But parents are better positioned than Congress to decide which spaces are appropriate for a particular child. When we hand that judgment to a clumsy legal framework, kids may either lose access to genuine social interaction or start bypassing the safeguards altogether — often ending up in less safe corners of the internet.

That matters because online connection is not fake connection.

RELATED: British Invasion: Inside the UK’s Orwellian plan to control YouTube

Anna Barclay/Getty Images

The lockdowns made this obvious. When governments shut down schools, workplaces, churches, and ordinary social life in 2020, millions of people turned to the internet because they had nowhere else to go. Friends used Zoom to play Dungeons and Dragons. Families bonded over Animal Crossing. For many, online spaces were not a replacement for real life so much as the only part of real life still available.

The lockdowns are over, but the lesson remains. Online communities can be frivolous, toxic, educational, creative, supportive, or all of those things at once — just like offline communities.

The harms of youth overexposure to social media are real. So are the benefits lawmakers risk sweeping away. People have used online communities to find life-changing information about rare medical conditions and to build what amounts to one of the largest educational ecosystems in the world.

The problem with the KIDS Act is not that Congress wants to protect children. Parents want that too. The problem is that the law treats more data collection and centralized rules as if they were synonymous with safety.

They are not.

As a parent who grew up online, I want my kids to have access to creativity, connection, and fun without turning their identities over to every service they use. My wife and I do not even post photos of our children online. Privacy is not an abstraction in our house.

Parents already have tools. Nintendo offers parental controls, and services such as Bark and Aura can help families manage devices and online activity without requiring the government to redesign the internet around age verification.

The KIDS Act pushes in the wrong direction. It risks placing more sensitive information in more places while flattening the very different ways children use technology.

Those of us fortunate enough to grow up with the opportunities the internet created should be careful about raising the digital ladder behind us — especially when the safety measure at the top may make the fall worse.

Newsom brags about his high-tech 'defense' plan — as it puts America at catastrophic risk



On Saturday, August 8, the local government in Suisun City, California, completely froze. Hackers broke into the city's computers, locked down the system, and forced officials to call an emergency. Workers couldn’t access basic files, run local offices, or keep normal operations moving.

Two days later, on Monday, August 10, Governor Gavin Newsom (D) announced a brand-new "AI Cyber Defense Program." Newsom’s press team went into overdrive, boasting about this “first-in-the-nation” initiative. But being first is no guarantee of being good, and this plan is very bad.

Instead of sending immediate money or technical experts to fix broken local computers, Newsom’s big fix is to hire more bosses. He is telling state agencies to name an "AI cybersecurity officer" for every department and set up another state-level office. Small towns are getting hit by real ransomware today, and Sacramento’s answers are inflated job titles and publicity campaigns.

Hostile foreign governments view California's weak systems as prime targets.

This predictable act of layering yet more bureaucracy on top of California's morass is especially dangerous. Hostile foreign governments are actively targeting American infrastructure.

A tidal wave of danger

State-sponsored hackers from Russia, China, and Iran are scanning for weak spots in real time. These foreign adversaries are targeting the basic services that millions of Americans rely on every day.

Federal investigators recently uncovered Iranian-backed hackers targeting more than 30 water utilities across Minnesota. These terrorists would love nothing more than to bring America’s largest state to its knees. Imagine turning on the tap in your California kitchen and finding out the treatment plant was shut down by hackers operating out of Tehran or Beijing. Imagine a Russian cyber unit turning off the electricity grid during a 105-degree heat wave or freezing local 911 dispatch software so that emergency calls go unanswered. That is the real danger facing regular families.

Governor Newsom's response to this massive crisis is filled with fancy-sounding distraction programs designed to look good on paper while accomplishing virtually nothing. He boasts about a consumer web tool named DROP, which lets residents ask data brokers to delete their personal info; a worker study project called Engaged California; and an "Innovation Council" accelerator stacked with tech executives and academics.

None of these projects stop a hostile missile site or a foreign military cyber unit from locking down your neighborhood's water main. A small town trying to fix its emergency systems gets zero help from state-sponsored talking shops that focus on "listening at scale" while real-world servers burn.

When a city network gets locked, administrators need real-world backup teams, emergency funding, and simple hardware upgrades. They need basic password protections, isolated off-site backups, and physical network engineers, not empty political pledges about "responsible AI innovation." Telling an underfunded county government to hire an advisory officer is like handing a firefighter a pamphlet on fire safety while the building burns down around him.

RELATED: The latest cybercrime turns security systems against you — and there's no good defense

Robert Wicher/Getty Images

It shifts the burden to local workers who lack the cash to fix the problem, while Sacramento pats itself on the back for creating another layer of red tape. It’s cruel, and it’s reckless.

Sitting ducks

The state government collects hundreds of billions in taxpayer dollars every year, yet leaves everyday infrastructure running on decade-old, unprotected software. California is home to the richest technology companies in the world, but your local city hall relies on systems that can be breached by a savvy teenager using off-the-shelf software. Hostile foreign governments from Moscow to Tehran know this, and they view California's weak local systems as prime targets to paralyze American life.

Imagine the chaos and the carnage. What happened in Suisun City, home to 29,000 people, was wake-up call enough. Now, imagine a blackout like that striking San Francisco, a city of over 810,000 residents on which America's tech security depends, or Los Angeles, a crucial logistics hub with a massive population approaching 3.9 million.

Power grids going dead for hours, cell towers dropping, and panicking residents realizing they are completely unable to contact 911 dispatch. Traffic lights instantly go dark, emergency response grinds to a total halt, and municipal services go offline overnight. Widespread looting, mass panic, and violent crime would spill across city streets within hours.

The movie "The Purge" was written as Hollywood fiction, but an automated, state-sponsored cyber strike on California’s crumbling public infrastructure could turn that apocalyptic nightmare into an immediate reality.

Sacramento should treat serious national security threats as existential threats. Instead, it reduces them to paperwork and procedure. When the next city's power or emergency lines freeze, Newsom will likely sign another executive order and announce another committee. California families deserve working water taps, reliable power lines, and real defenses against foreign enemies. They deserve a governor who takes their safety seriously and does everything in his power to ensure the state is prepared for the worst.

The latest cybercrime turns security systems against you — and there's no good defense



For a brief period last week, Telegram disappeared from Apple’s App Store. That is no small thing. Telegram has more than a billion users worldwide, and for anyone who tried to install Telegram on an iPhone, Apple had temporarily cut off the normal route to getting the app. Apple said it removed Telegram after finding child sexual abuse material on the service. Telegram deleted the material, banned the offending user, and Apple restored the app the same day. Existing users were able to keep using Telegram while it was unavailable for download.

That alone would have been a noteworthy story, but Telegram founder Pavel Durov later offered a much stranger explanation for what happened. According to Durov, the material was not simply posted by some random criminal. He claims it was deliberately planted by what he called a “takedown extortionist,” someone who threatens online communities with removal unless their owners pay up.

It's a much stranger security problem than most people are used to thinking about.

In Durov’s telling, the attacker found an old message in an active public Telegram group, edited it to contain AI-modified illegal material, and then reported the offending content directly to Apple. Because the edited message was buried in the group’s history, ordinary Telegram users were unlikely to stumble across it and report it themselves. The Verge subsequently reported Durov’s account of the alleged scheme.

Apple has confirmed the illegal content and the reason it removed Telegram, but it has not independently confirmed Durov’s story about the extortion scheme. That distinction matters. The claim that an extortionist deliberately planted the material, that AI was used to modify it, and that the old message was selected specifically to evade Telegram’s own moderation all come from Durov.

Still, if his account is accurate, the incident offers a glimpse of where cyberattacks may be headed. The alleged attacker did not have to hack Telegram’s servers, compromise Apple, steal anyone’s password, or discover some exotic zero day vulnerability. He simply figured out how to manipulate Apple’s enforcement system into attacking Telegram for him.

Hack the referee

That may sound like an entirely new category of attack, but the basic idea has been around for years. Social media companies have dealt with organized mass reporting campaigns in which activists, dissidents, competitors, and political opponents are buried under bogus complaints in hopes that an automated moderation system will suspend them.

Meta disclosed in 2021 that it had broken up a network in Vietnam that used real, duplicate, and fake accounts to submit hundreds and sometimes thousands of false reports against activists and critics of the Vietnamese government.

YouTube has had similar problems with fraudulent copyright complaints. Google reported that more than 6% of videos targeted through YouTube’s public copyright removal process in 2025 were subject to abusive removal requests.

The reason the Telegram case is more interesting is that artificial intelligence is changing the economics of these attacks. A human being has always been capable of lying, filing false reports, forging evidence, or pretending to be someone else. AI makes it possible to do those things at enormous scale and with much less time and effort.

RELATED: Infamous cyberattackers claim their next shocking victim — using a decades-old trick

Jaap Arriens/NurPhoto/Getty Images

The FBI has already warned that criminals are using generative AI to create fake identification documents, fictitious social media profiles, synthetic photographs, cloned voices, and fraudulent videos for impersonation and fraud. The FBI has separately warned that criminals are using AI-altered images and videos to create explicit material for extortion.

The important thing is not merely that AI can make a convincing fake photograph. It is that one person can now manufacture photographs, voices, accounts, documents, messages, and identities faster and cheaper than ever before.

The attack surface is getting bigger

That becomes especially dangerous as more institutions hand decisions over to automated systems. Banks use software to decide whether a transaction looks fraudulent. Email providers decide whether a message is spam. Social networks decide whether a photograph violates their rules. App stores determine whether software is safe enough to distribute. Advertising platforms decide which businesses are legitimate. Payment processors determine which merchants are too risky to serve.

In every case, the system has to take some collection of inputs and make a judgment about them. An attacker does not necessarily have to defeat those systems in the traditional sense. He only has to learn which inputs produce the result he wants.

That is a much stranger security problem than the one most people are used to thinking about. For decades, the stereotypical cyberattack involved a hacker trying to break through a locked door. He stole a password, exploited an unpatched vulnerability, installed malware, encrypted a hard drive, or broke into a database.

Those attacks are not going anywhere, and AI is making them more sophisticated as well. But increasingly, attackers may be able to accomplish their goal without ever breaking through the door. If they can persuade the security guard that the owner of the building is a criminal, the guard may do the damage for them.

Apple’s power is part of the problem

That is essentially what Durov claims happened to Telegram, and it exposes another uncomfortable part of the story.

Apple obviously cannot ignore child sexual abuse material. Nobody is arguing that it should. But that does not automatically answer the much larger question of what Apple should do when a single user uploads prohibited material to an application serving more than a billion people.

Is Apple responsible for policing every photograph, message, and file that passes through every app it distributes? More importantly, should Apple have the authority to punish every user of an application because one user violated the rules?

Apple’s own App Store guidelines do not require developers to somehow guarantee that objectionable material will never appear. Apps containing user generated content are required to have systems for filtering objectionable material, reporting it, blocking abusive users, and providing contact information so complaints can be addressed.

Apple’s guidelines also describe a remediation process in which the company may contact a developer, ask that offending material be removed, and request a plan for preventing similar violations. The guidelines reserve immediate removal for more serious circumstances, including egregious or repeated behavior.

That raises an obvious question if Durov’s account is accurate. Why did Apple remove Telegram before contacting the company instead of first giving Telegram an opportunity to remove the content and address the offending account?

RELATED: Surveillance pricing is here — and this surprising state is saying NO

mathisworks/Getty Images

There may be additional considerations involving child sexual abuse material that are not fully spelled out in Apple’s general App Store guidelines, so it would be too strong to say Apple clearly violated its own policy. But the discrepancy is worth asking about.

Telegram says this entire episode stemmed from the actions of a single user. Telegram spokesperson Remi Vaughn criticized Apple for disrupting access to the app over one user’s actions, while Epic Games CEO Tim Sweeney questioned how any large messaging service could realistically guarantee that none of its users would ever upload prohibited material.

That gets to the larger issue. No communications platform with hundreds of millions or billions of users can promise that no individual user will ever do something criminal. The meaningful question is how quickly and effectively the platform responds when that happens.

Yet Apple possesses the power to remove an entire application from the primary software marketplace for more than a billion iPhone users.

That is an extraordinary amount of authority for one private company to exercise over communications software.

It also makes the alleged extortion scheme possible in the first place. The attacker’s leverage did not come merely from his ability to plant prohibited material. It came from knowing that Apple possessed both the power and the willingness to punish an entire application in response.

If Durov’s story is accurate, the extortionist was exploiting Apple just as surely as he was exploiting Telegram.

Who decides who gets to stay?

There is also reason to question how consistently Apple exercises that authority.

The Verge reported Friday that Apple took a different approach toward X and Grok during controversy over sexualized AI-generated images. Apple reportedly contacted X and sought moderation changes rather than immediately removing the apps.

Durov, by contrast, says Telegram was removed before Apple contacted the company.

That does not prove Apple acted improperly in either case, and the underlying facts were not identical. But it does expose how much discretion Apple possesses. Apple worked with one platform while another was removed before contact, according to Durov.

That should make even people who have little sympathy for Telegram uncomfortable. The question is not whether Apple should tolerate illegal material. It is whether a company that controls one of the two dominant mobile operating systems should also serve as judge, jury, and executioner for applications containing the speech of billions of third-party users.

Seen that way, the Telegram affair is not merely a warning about AI-powered cyberattacks. It is also a warning about centralized gatekeepers.

The more power we give a handful of companies to decide who may communicate, transact, advertise, publish, or distribute software, the more valuable those companies become as targets for manipulation.

Why bother silencing a billion users yourself when you can trick Apple into doing it for you?

AI is getting better at old-fashioned hacking too

AI makes these manipulation attacks easier, but the machines themselves are also becoming much better at traditional hacking.

OpenAI recently disclosed an internal cybersecurity evaluation in which advanced models escaped the constrained environment researchers had built for them after discovering and exploiting a previously unknown vulnerability. The models gained internet access, escalated privileges, moved laterally through systems, and ultimately exploited vulnerabilities in Hugging Face’s real production infrastructure while pursuing the objective of the test.

There are important caveats. This was a deliberately aggressive cybersecurity evaluation. OpenAI had reduced or disabled some of the safeguards that would ordinarily restrict such behavior, and the prerelease model involved was an internal research prototype rather than a product released to the public.

Even with those caveats, the result was remarkable. The models found ways around barriers that researchers had not expected them to overcome.

RELATED: They had their life savings drained online in an instant. So who's next?

Velishchuk/Getty Images

Then on Friday, OpenAI disclosed another development that shows how quickly these capabilities are progressing. The company said testing of its upcoming Astra model had advanced far enough that it could no longer rule out what OpenAI classifies as “critical” cybersecurity capability.

That is the highest category in OpenAI’s cybersecurity framework. At that level, according to OpenAI’s description, a model could potentially discover functional zero-day exploits against hardened real-world systems without human assistance or independently plan and execute complex novel attacks from a high-level objective.

OpenAI has not said Astra definitely possesses those capabilities. It has said the possibility is serious enough that the company has tightened security controls around the model while testing continues.

We have reached the stage where one of the companies building the world’s most advanced AI systems considers autonomous attacks against hardened real-world targets plausible enough to build safeguards around.

Cybersecurity is becoming a fight over reality

Put these developments together, and the future of cybercrime starts to look much more complicated than simply giving hackers better tools.

On one side, AI systems are becoming increasingly capable of probing networks, discovering vulnerabilities, writing exploits, and carrying out technical work that once required highly skilled human operators. On the other side, far less sophisticated AI can already generate fake identities, doctored evidence, fraudulent complaints, cloned voices, and synthetic content that can be used to manipulate the institutions surrounding a target.

You can imagine where that leads without getting too far into science fiction. A criminal might not need to break into a company’s bank account if he can generate enough convincing evidence to persuade the bank’s fraud system to freeze it. He might not need to hack a competitor’s website if he can convince its hosting company that the site contains illegal material. He might not need to compromise an executive’s email if he can clone the executive’s voice and video closely enough to fool an employee. An attacker targeting a social media account might simply generate and test thousands of variations of malicious content until he discovers one that reliably triggers the platform’s moderation system.

The institutions involved cannot simply stop enforcing their rules. Banks cannot stop looking for fraud. Email providers cannot stop filtering spam. Social networks cannot simply abandon moderation. Apple cannot simply shrug when illegal material appears inside an app.

But neither should we treat every decision made by those systems, or by the companies controlling them, as automatically legitimate simply because the underlying problem is serious.

Every system that makes judgments can also be studied, manipulated, and eventually exploited.

That is what makes the Telegram incident worth paying attention to, even if Durov’s account ultimately proves incomplete. Apple has removed Telegram over child sexual abuse material before, in 2018, and Telegram has faced years of criticism and regulatory pressure over illegal activity on the platform. Durov is hardly a disinterested observer.

But the broader vulnerability he describes is real whether or not every detail of this particular incident turns out exactly as he says.

For most of the history of cybersecurity, defenders worried about attackers taking control of their computers. The next phase may be stranger. Attackers may not need to take control of your computer at all.

They may only need to convince everyone else’s computers to turn against you.

New study: One Chinese cyberattack could make your taps run dry



Modern water utilities run on digital control systems that regulate water pressure and chemical mixtures. If a hostile actor compromises these networks, they control the physical flow of liquid life across American communities.

A recent simulation conducted by cybersecurity analysts, as reported by Wired, modeled exactly what happens when those controls get hijacked. The results proved that America’s interconnected society is essentially a giant Jenga tower built on a foundation of pumps and pipes.

Emergency response teams face an impossible numbers game.

Earlier this year, the FBI officially classified a breach of a U.S. government monitoring network as a “major incident.” This is the government’s polite way of saying someone managed to hot-wire the digital locks on the country’s critical infrastructure.

The Beijing-backed hacking group Volt Typhoon has spent years setting up camp inside American pipelines and power grids. The group is seeking to disrupt the systems that everyday Americans depend on.

And the easiest way to do that is through the kitchen sink.

A single water utility failure can trigger a much wider economic crisis. Data centers require thousands of gallons of water daily to prevent high-density server racks from melting into expensive puddles of plastic. When water pressure drops, those servers overheat and initiate automated shutdowns. This instantly halts the cloud computing services that manage corporate logistics, processing networks, and emergency communications. Your local water plant goes down, and suddenly the entire digital economy vanishes into thin air.

Hospitals face an immediate crisis when the taps run dry. Modern medical facilities rely on water for everything from sterilizing surgical instruments to running the HVAC systems that maintain sterile operating rooms. Without water pressure, air conditioning units fail, ambient temperatures surge, and hospital administrators must evacuate intensive care units. It turns out that advanced 21st-century medicine completely falls apart if you can't wash a scalpel or flush a toilet.

On the brink of disaster

The United States maintains roughly 151,000 public water systems, and the vast majority serve populations of fewer than 3,300 residents. These small municipal water districts operate on razor-thin tax revenues that barely cover basic pipe repairs. They absolutely do not have the budget to hire elite cybersecurity teams to defend their networks. Instead, their digital infrastructure relies on outdated software and default, easily cracked factory passwords like "admin123." They're practically inviting foreign adversaries to waltz in and run riot.

The attackers use a strategy known as “living off the land” to maintain their presence inside these small networks. Instead of dropping obvious malware that sets off digital tripwires, they repurpose legitimate administrative tools already built into the operating software. Security logs register their malicious commands as routine network maintenance performed by a local employee. This allows foreign operators to map out vulnerabilities and position themselves to cause maximum damage whenever they feel like flipping the switch.

RELATED: China’s new AI master plan: Total technological control

bernie_photo/Getty Images

Emergency response teams face an impossible numbers game during a multi-regional infrastructure crisis. The federal government possesses a limited pool of cybersecurity experts capable of removing nation-backed digital squattersfrom industrial control systems. A widespread outage forces these responders to triage assistance based on economic importance and military necessity. A defense manufacturing facility or a major metropolitan hospital receives immediate technical support, while suburban neighborhoods and rural farming towns wait weeks for a repair crew.

Commercial insurance policies offer a hilarious lack of protection against this kind of systemic infrastructure failure. Standard cyber insurance contracts contain explicit exclusions for acts of war, cyber terrorism, or hostile actions directed by sovereign nations. The moment the federal government attributes a major utility breach to a foreign power, insurance corporations will invoke these clauses to deny payouts. Municipalities and local taxpayers are left holding the multi-billion-dollar bill to restore their own poisoned or impaired water systems.

No bathroom breaks

The simulation concluded with a darkly absurd enforcement of operational reality. Organizers denied participants bathroom breaks for the final 12 hours. In the hierarchy of emergencies, a number one had officially fallen below the number one priority.

There are no breaks in a real incident response, and walking away from your terminal means missing the exact second a water pump explodes. It provided a clear demonstration of the high-stakes pressure facing the IT professionals who hold the line between modern civilization and medieval living conditions.

Washington remains trapped in a reactive loop, preparing for cyber disasters after they occur instead of making the initial intrusion impossible. The final lesson of the war game is that there is no magical reboot button for a society deprived of its basic utilities. Communities descend into chaos, valve by valve. Corporate executives and politicians argue over who gets the first drop of clean water. Preventative defense is the only viable option. Because once the taps stop running, restoring normal life becomes a slow and uncertain process.

DOJ asked to probe whether Biden officials let Microsoft off easy in exchange for cushy jobs



Former officials in the Biden administration have been credibly accused of letting a tech giant slide on preventable cybersecurity breaches only to later secure lucrative arrangements with or cushy jobs at the same corporation.

The American Accountability Foundation, a nonprofit government oversight and research organization, asked the Justice Department in a lengthy letter on Tuesday to open a formal investigation into Microsoft and several Biden officials.

'We will act where the facts and the law support it.'

Among the Biden cronies singled out in the letter is Lisa Monaco, the former deputy attorney general whose post-government career move captured President Donald Trump's attention in September 2025.

Trump wrote that "Corrupt and Totally Trump Deranged Lisa Monaco (A purported pawn of Legal Lightweight Andrew Weissmann)" had "been shockingly hired as the President of Global Affairs for Microsoft, in a very senior role with access to Highly Sensitive Information. Monaco's having that kind of access is unacceptable, and cannot be allowed to stand. She is a menace to U.S. National Security, especially given the major contracts that Microsoft has with the United States Government."

Monaco's employment at Microsoft apparently also struck the team at AAF as potentially problematic.

The watchdog noted that Monaco — who had announced a cyber fraud initiative in 2021 aimed at using the False Claims Act against contractors who intentionally misrepresent cybersecurity risks — proved eager to bring actions against numerous companies and institutions, but never against Microsoft.

Monaco and the rest of the Biden administration's inaction against Microsoft is especially strange because the company suffered five massive cyber intrusions by foreign criminal and state-sponsored hacker groups between 2019 and 2023 that directly and adversely impacted the U.S. government.

The AAF emphasized that these intrusions "penetrated the National Nuclear Security Administration and the Departments of Treasury, State, Commerce, and Justice, as well as the National Security Council and numerous other federal agencies" and "resulted in the theft of tens of thousands of government emails, including correspondence from the U.S. Ambassador to China, the Secretary of Commerce," and other bigwigs.

RELATED: 'RedSun' flaw in Microsoft's security software lets hackers take over your PC. Here's how to protect it.

Former President Joe Biden and Lisa Monaco. Ting Shen/Bloomberg/Getty Images

One of these cyber attacks, SolarWinds, reportedly relied on the exploitation of a flaw in Microsoft's Active Directory Federation Services. The company was allegedly aware of the flaw for years but avoided patching it for fear of jeopardizing a multibillion-dollar federal cloud contract.

Former Microsoft President Brad Smith told Congress in 2021 that "there was no vulnerability in any Microsoft product or service that was exploited" in the SolarWinds attack.

While some Biden officials proved willing to assign Microsoft some blame, it was never too much or pursued as grounds for punitive action.

The Cyber Safety Review Board, an outfit established by former Homeland Security Secretary Alejandro Mayorkas, concluded that Storm-0558, a separate cyber attack executed by Beijing-linked hackers in May 2023, was enabled by a "cascade of Microsoft's avoidable errors."

Despite such recognition that it had dropped the ball, Microsoft managed to evade any meaningful reckoning.

"These facts, in our view, present squarely the kind of conduct that the Biden administration's Civil Cyber-Fraud Initiative was created to address: knowing or reckless misrepresentations by a federal contractor regarding the cybersecurity of products sold to the government," the American Accountability Foundation said in its letter. "Yet to our knowledge, no False Claims Act investigation of Microsoft's conduct has ever been opened, while other contractors whose conduct appears materially less egregious have been pursued under the same initiative."

Besides Monaco, the watchdog made a point of mentioning several other Biden administration officials, including:

  • Bryan Vorndran, a former assistant director of the FBI's Cyber Division who served as the bureau's representative on the Cyber Safety Review Board. Vorndran, who the AAF said was mysteriously recused from the board's probe into the Storm-0558 attack, joined Microsoft in June 2025 as deputy chief information security officer.
  • Jerry Davis, a member of the CSRB from 2022 to 2025 who participated in the board's investigation of the Storm-0558 attack. Davis was hired as a chief security adviser at Microsoft three months after the CSRB released its report faulting the company for "inadequate" security culture.
  • Robert Joyce, the former director of cybersecurity at the National Security Agency and an inaugural member of the CSRB. After leaving the NSA in 2024, he founded a cybersecurity firm that the AAF suggested counts Microsoft as one of its clients.

The AAF stressed that "federal ethics rules prohibit government officials from participating in matters in which they have a financial interest, and require cooling-off periods before certain officials may represent private parties before their former agencies."

While the AAF did not "allege that any individual violated any specific law or regulation," the watchdog noted that an investigation into the matter is warranted.

A Justice Department spokesperson told Breitbart, "The Department of Justice is committed to aggressively fighting fraud and protecting taxpayer dollars. We welcome referrals from anyone with credible information about fraud, and we will act where the facts and the law support it."

Like Blaze News? Bypass the censors, sign up for our newsletters, and get stories like this direct to your inbox. Sign up here!

New hack poses biggest iPhone threat in 19 years: What you can do



Apple has had a hard time lately with critical exploits plaguing iPhones all around the world. In mid-February, Google’s Threat Analysis Group discovered a critical zero-day vulnerability in Apple’s iOS software that gave hackers full control of a “small subset” of targeted iPhones. This month, reports revealed that an entire exploit tool kit has been successfully used by hackers in Russia and China. The worst part is that mounting evidence suggests the kit came from the United States, possibly even from our very own government.

Chock-full of vulnerabilities

According to Google’s full report, the exploit tool kit — dubbed Coruna — consists of five exploit chains and 23 exploits in total, all targeted at iPhones running iOS 13 to iOS 17.2.1. Mobile security experts at iVerify corroborated the report, claiming that 42,000 iPhones were affected.

Are there more zero-day vulnerabilities in iOS that we don’t know about? Almost certainly yes.

An exploit chain is the path a hacker can use to bypass a device’s security controls via exploits to gain access. In other words, if your phone’s software was a map, an exploit chain is the route a driver could take through different toll areas to reach the final destination. Even one exploit chain — or route — is enough to break into a device, but the fact that five routes exist within Coruna makes it a sophisticated hacking resource unlike anything security researchers have seen on iOS.

Google notes that Coruna has already been exploited by a “customer of a surveillance company,” as well as foreign nations, namely China and Russia. More alarming than that, however, “multiple threat actors” have also gained access to exploit techniques that can be customized to leverage new and unknown vulnerabilities for future attacks.

Image credit: Google

Where did Coruna come from?

Now that Coruna is out in the open, it only makes sense to wonder where it came from. Its sophisticated nature makes it highly unlikely that an independent hacker threw it together. Instead, several pieces of evidence point toward government intervention.

For starters, the tool kit’s source materials are all written in native English, suggesting English origins. Second, two of the exploits in the chain are linked directly to Operation Triangulation, a hardware vulnerability discovered in Apple’s first-party processing chips by Russian cybersecurity company Kaspersky. Russian government officials blamed the NSA for this exploit back in 2023, but the U.S. government denied any connection.

Third, iVerify’s co-founder and COO, Rocky Cole, reportedly called Coruna’s code “superb,” going on to state, “It was elegantly written. It’s fluid and holds together very well. There were comments in the code that, as someone who’s been around the U.S. defense industrial base for years, really are reminiscent of the sort of insider jokes and insider remarks that you might see from a U.S. based coder. Certainly they were native English language speakers.”

For what it’s worth, Kaspersky recently denied that Coruna is linked to the NSA, despite the evidence outlined above. Regardless of the tool kit’s origin, researchers are unsure how it made it into the hands of foreign entities.

RELATED: Apple issues a critical software update for iPhone. Install it now!

Photo by Matt Cardy/Getty Images

Bigger signs of Apple’s compromised security

Apple’s iOS mobile platform is notoriously hard for hackers to crack, thanks to its closed nature, often frustrating U.S. criminal investigation agencies with its strong end-to-end encryption practices. The Coruna tool kit, however, changes everything. It’s the biggest collection of exploits to hit iOS since its inception in 2007. It’s also part of a growing trend that undermines Apple’s once-impenetrable software security and privacy protocols.

Just last month, Apple released iOS 26.3 to patch a critical zero-day vulnerability dubbed CVE-2026-20700. Although this remains to be a major threat to iPhone users, this exploit is not part of the Coruna tool kit. These are completely independent issues. Are there more zero-day vulnerabilities in iOS that we don’t know about? Almost certainly yes.

Tips to secure your device

That doesn’t mean there’s nothing you can do. As software vulnerabilities become more prevalent, the best way to keep your devices safe and secure is to make sure you always have the latest iOS updates downloaded and installed on your phone, tablet, and laptop.

The exploits in the Coruna tool kit that plagued iOS 13 through 17.2.1, as well as CVE-2026-20700 for iOS 26, have all been patched. If you haven’t updated your iPhone to the newest software, or if you’re not sure which version you have, check for updates by opening the Settings app. Then go to General, Software Update, and make sure you’re on one of these versions, depending on your phone’s model:

  • iOS 26.3.1 (iPhone 11 and up);
  • iOS 18.7.5 (Phone XS, XS Max, and XR);
  • iOS 16.7.14 (iPhone 8, 8 Plus, and X);
  • iOS 15.8.6 (iPhone 6s and 7); or
  • iOS 12.5.8 (iPhone 5s, 6, 6 Plus).

If you want even more protection from exploits and vulnerabilities, you can secure your private data with Apple’s Advanced Data Protection built directly into iCloud. Then for maximum protection, Apple offers Lockdown Mode, though this feature isn’t meant for everybody. Since it will ultimately restrict many of the features and functions of your device, it’s only meant for high-profile cyber-criminal targets like politicians, celebrities, and investigative journalists.

Epstein files were allegedly compromised by foreign hacker in 2023; FBI admits 'cyber incident'



The FBI Field Office in New York produced myriad documents pertaining to its criminal probe into child sex offender Jeffrey Epstein. Attorney General Pam Bondi suggested in a Feb. 17, 2025, letter to FBI Director Kash Patel that "thousands of pages of documents related to the investigation and indictment of Epstein" were stored on site there.

Some of these documents were allegedly compromised in a hack years before the Department of Justice began publishing the heavily redacted Epstein files.

Reuters' source suggested that the hack appears to have been executed by a 'cybercriminal' rather than a foreign government.

The bureau revealed in 2023 that it was investigating a hack of its computer network, which it characterized as an "isolated incident that has been contained."

Multiple sources briefed on the matter told CNN at the time that FBI officials suspected the incident involved a bureau computer system used in the investigations of images of child sexual exploitation.

Reuters, citing a source familiar with the matter and recently published DOJ documents, reported on Wednesday that the hack entailed a foreign actor's targeting of files related to the FBI's investigation of Epstein.

The hack reportedly took place after a server at the New York FBI office's Child Exploitation Forensic Lab was allegedly left exposed by Special Agent Aaron Spivack, who did not return Reuters' numerous requests for comment but has previously issued a voluminous statement on the matter.

RELATED: 'The mistake I made': Bill Gates reportedly admits to affairs with Russians, apologizes for Epstein fallout

Photo by Joe Schildhorn/Patrick McMullan via Getty Images

Among the Epstein files released by the Department of Justice in recent months is a 2024 statement from Spivack in which he addresses the allegations that he "improperly stored digital evidence at his residence"; "improperly handled, documented, and stored digital evidence and failed to secure [child sexual abuse material] within policy, resulting in a cyber intrusion"; and "exceeded the limits of his authority by contracting an outside company to develop computer software on behalf of the FBI."

Spivack — who apparently participated in the Epstein investigation — stated that the cyber "intrusion" happened on Feb. 12, 2023.

After logging into his computer to find a .txt file indicating that his network had been compromised, Spivack claimed that he ran an anti-virus sweep, which identified a potential threat. He said that he was unable, however, to remove the threat, as his "administrative privileges had been removed."

Spivack notified some of his colleagues, attempting to rectify the issue, then noticed that the main server was down, that other servers were malfunctioning, and that "the folders that contain our data was missing."

According to Spivack's timeline, he and others later noticed "strange IP activity that took place [on Feb. 12] from two IP addresses."

"The activity included combing through certain files pertaining to the Epstein investigation," stated Spivack.

It's unclear what particular files were accessed and whether they were downloaded, reported Reuters.

By 5 p.m. on Feb. 13, 2023, Spivack said, "we realized we were hacked."

The FBI reiterated that the "cyber incident" was an "isolated one" and said in a statement obtained by Reuters that "the FBI restricted access to the malicious actor and rectified the network. The investigation remains ongoing, so we do not have further comments to provide at this time."

The FBI did not immediately respond to a request for comment from Blaze News.

Reuters' source suggested:

  • that the hack appears to have been executed by a "cybercriminal" rather than a foreign government;
  • that the hacker did not appear to realize he or she had hacked a law enforcement server; and
  • that the hacker expressed revulsion at the presence of child sexual abuse images on the device and threatened to turn its owner over to the FBI.

The hacker — whom the FBI allegedly spoke to on video chat but was unable to identify or locate — may have acted alone, but Jon Lindsay, an associate professor at the Georgia Institute of Technology's School of Cybersecurity and Privacy, suggested that the hack demonstrates the files' potential intelligence value.

"Who wouldn’t be going after the Epstein files if you’re the Russians or somebody interested in kompromat?" Lindsay told Reuters. "If foreign intelligence agencies are not thinking seriously about the Epstein files as a target, then I would be shocked."

Reuters indicated it was unable to "establish the result of the bureau's internal investigation" regarding Spivack or connect with FBI agents identified in the documents as being involved in the investigation.

Spivack stressed in his 2024 statement, "I have rescued more exploited children than anyone in the NYFO and in most of the Bureau. All I wanted to do was to better the Bureau. I did not know how to do everything right, but I always did the right thing and everything I did was with good intentions. I love this job. I was not reckless."

Like Blaze News? Bypass the censors, sign up for our newsletters, and get stories like this direct to your inbox. Sign up here!

25,000 Americans apply for just 1,000 jobs at new federal Tech Force



Hot on the heels of the U.S. government's announcement of the Tech Force combing for 1,000 new recruits, 25 times that number of Americans have sent in their resumes to the cross-agency technology team.

The Tech Force, announced mid-month, urged the country's best and brightest to head to its website to apply for short-term federal employment. Over the ensuing week, that number has risen to at least 25,000, according to Scott Kupor, the director of the U.S. Office of Personnel Management.

'Tech Force will tackle the most complex and large-scale civic and defense challenges of our era.'

With a two-year government contract worth as much as $200,000, recruits will be part of an "elite group" of tech specialists hired to "accelerate artificial intelligence (AI) implementation" and solve critical tech challenges.

The unprecedented new group will primarily recruit those early in their careers, the Tech Force website explained, who specialize in engineering, AI, cybersecurity, data analytics, or project management in tech. Those brought on board can expect to implement AI programs and applications, modernize data, and provide digital service delivery at federal agencies.

"Backed by the White House, Tech Force will tackle the most complex and large-scale civic and defense challenges of our era," the outfit promised. "From administering critical financial infrastructure at the Treasury Department to advancing cutting-edge programs at the Department of Defense, and everything in between."

RELATED: BEWARE: With these new web browsers, everything on your computer can be stolen with one click

— (@)

Hires can look forward to working with agency leadership and "leading technology companies" to train and engage with senior management from partnered companies. The government openly states that once Tech Forcers are finished with their training program, they will seek employment at the partnering private-sector companies in order to demonstrate "the value of combining civil service with technical expertise."

Along with the competitive high salaries, the government program says it provides benefits like health insurance, retirement plans, and "performance-based awards."

The duties and scope of the Tech Force varied to a great degree, with the official website providing a lengthy list of federal agencies that participants can expect to be placed within. These included the Departments of War, Treasury, State, Labor, Commerce, Energy, Health and Human Services, Interior, Housing & Urban Development, Transportation, Homeland Security, and Veterans Affairs.

Other agencies like the Small Business Administration, IRS, and Office of Personnel Management were also noted.

RELATED: NO HANDS: New Japanese firm trains robots without human input

Photo by Wang Gang/VCG via Getty Images

Readers on X had mixed reactions to open recruitment, with several hoping the program would only be open to Americans and others sarcastically saying that it probably should not be filled "with Indians."

The application form goes through the USA Jobs website.

The official account for the Young Republicans of Texas said the program could be an effective way to prove that there are "plenty of qualified Americans" in the tech field.

At the same time, others worried about a dystopian future that could arise from combining advanced technology and the Treasury Department.

Like Blaze News? Bypass the censors, sign up for our newsletters, and get stories like this direct to your inbox. Sign up here!

Convicted hacker twins who landed jobs as federal contractors nabbed for allegedly deleting government databases



Muneeb and Sohaib Akhter, a pair of convicted hackers based in Alexandria, Virginia, were arrested on Wednesday over an alleged conspiracy to destroy government databases and other crimes.

After doing prison time for wire fraud and conspiring to hack into the U.S. State Department, the Akhter twins, one of whom previously served as a cybersecurity contractor with the State Department, managed to secure jobs as federal contractors — working as engineers for Opexus.

'Their actions jeopardized the security of government systems.'

Opexus, a company that handles sensitive data for most federal agencies and has received over $50 million in contracts from various agencies over the past decade, determined earlier this year that it had been compromised in February by two employees.

A Bloomberg investigation revealed in May that after one of the agencies with which Opexus was working, the Federal Deposit Insurance Corporation, flagged the twins as possible threats on account of their criminal records, the duo were fired on Feb. 18.

The company later discovered that while being fired and immediately afterward, the twins allegedly accessed sensitive documents and compromised or scrubbed dozens of databases, including those containing data from the General Services Administration and the Internal Revenue Service.

The FBI, FDIC Office of Inspector General, Department of Homeland Security Office of Inspector General, and Homeland Security Investigations investigated the case.

The brothers were indicted on Nov. 13 for allegedly working to harm Opexus and its U.S. government clients "by accessing computers without authorization, issuing commands to prevent others from modifying the databases before deletion, deleting databases, stealing information, and destroying evidence of their unlawful activities," the DOJ said in a release.

RELATED: Could hackers target your car's tires?

Muneeb Akhter. Photo by Evelyn Hockstein/Washington Post via Getty Images

According to the indictment, Muneeb Akhter allegedly deleted approximately 96 databases storing U.S. government information — including databases containing records and documents related to Freedom of Information Act matters as well as sensitive federal investigative files.

Muneeb Akhter is also accused of asking an artificial intelligence tool how they could cover their tracks after deleting a DHS database.

After he got fired from Opexus, Muneeb Akhter allegedly obtained data from the U.S. Equal Employment Opportunity Commission and is accused further of stealing copies of IRS information including federal tax information and other identifying information for at least 450 individuals.

Opexus did not respond to a request for comment from Blaze News.

"These defendants abused their positions as federal contractors to attack government databases and steal sensitive government information," said Matthew Galeotti, acting assistant attorney general at the Department of Justice's Criminal Division, in a statement. "Their actions jeopardized the security of government systems and disrupted agencies’ ability to serve the American people."

Muneeb Akhter has been charged with conspiracy to commit computer fraud and to destroy records, two counts of computer fraud, theft of federal records, and two counts of aggravated identity theft. His twin, Sohaib Akhter, was charged with conspiracy to commit computer fraud and to destroy records and computer fraud.

While Sohaib Akhter faces a maximum penalty of six years in prison, Muneeb Akhter faces a mandatory minimum penalty of two years of prison time for each aggravated identity theft count and a maximum penalty of 45 years for the other charges.

The duo pleaded guilty in 2015 to a different set of crimes.

Muneeb Akhter hacked into the website of a cosmetics company and stole thousands of customers' credit card and personal information. He and his brother used the stolen data to pay for flights, hotel stays, various goods, and attendance at professional conferences. Muneeb Akhter proceeded to hand off the stolen data to a "dark net" operator who cut him in on the profits from the sales.

The other brother, meanwhile, used his contract position at the State Department in 2015 to steal personally identifiable data belonging to various people including co-workers and a federal law enforcement agent who was investigating him.

According to the Justice Department, Sohaib Akhter later hatched a scheme to ensure perpetual access to various State Department systems and, with the help of his twin, attempted to install an electronic collection device inside a State Department office, which would have enabled the hackers to remotely steal federal data.

Years earlier, Muneeb Akhter hacked into a Maryland-based private data aggregation company that he was performing contract work for, giving his brother access to a database of federal contract information to give their technology company an upper hand when bidding for contracts and clients.

Like Blaze News? Bypass the censors, sign up for our newsletters, and get stories like this direct to your inbox. Sign up here!

It's not just you. X and vast tracts of the internet are down.



Large sections of the internet stopped working on Tuesday morning. Among the sites affected by the latest in a weeks-long series of outages were Amazon Web Services, X, League of Legends, the betting site bet365, Spotify, ChatGPT, and — ironically — the website that monitors online outages, Downdetector.

The problem appears to be the result of issues at Cloudflare, a San Francisco-headquartered tech company that effectively serves as a backbone to a myriad of sites, providing content delivery network and wide area network services, domain registration, and cybersecurity.

'We saw a spike in unusual traffic.'

At the time of writing, the Cloudflare system status page indicated that the company was working toward restoring global network services, having hours earlier acknowledged "experiencing an internal service degradation" that could leave some services "intermittently impacted."

The latest outages come just days after Cloudflare admitted an "issue which potentially impacts multiple customers" — an issue that was supposedly "resolved."

A spokesperson for Cloudflare said in a statement obtained by the Guardian, "We saw a spike in unusual traffic to one of Cloudflare’s services beginning at 11:20am [London time]. That caused some traffic passing through Cloudflare’s network to experience errors. While most traffic for most services continued to flow as normal, there were elevated errors across multiple Cloudflare services."

"We do not yet know the cause of the spike in unusual traffic," continued the spokesperson. "We are all hands on deck to make sure all traffic is served without errors. After that, we will turn our attention to investigating the cause of the unusual spike in traffic."

The company's engineers were reportedly scheduled to conduct some maintenance work on data centers in Atlanta, Los Angeles, Tahiti, and Santiago, Chile. It's unclear whether their efforts had anything to do with the technical issues.

Like Blaze News? Bypass the censors, sign up for our newsletters, and get stories like this direct to your inbox. Sign up here!