From Black Hat to the White House: The Scariest Cyber News You Missed This Week
Between the Black Hat conference in Las Vegas, AI agents running rampant across the web , and state-sponsored hackers targeting water utilities in at least seven states, it's been a very busy week in cybersecurity. Thankfully, PCMag's security team is on the show floor in Las Vegas, and we're keeping an eye on everything else that's been happening in case there's anything you need to do. Let's dive in.
First, let's set the stage, literally. During the Black Hat keynote, Sean Cairncross, the US national cyber director, took a very hands-off, conciliatory tone regarding AI, security, and privacy regulation. He claimed that, "A regulatory regime, one, would not only strangle growth, development, and innovation and be enormously harmful to the industry." This echoes the administration's stance of letting tech firms do what they want to accelerate development, except when it conflicts with administration priorities .
Aside from the keynote, a team from OpenAI hosted what they called an "emergency talk" on how their AI agents attacked Hugging Face last month, including details on how the AI agents broke their guardrails, how engineers at OpenAI missed what was happening until Hugging Face came calling, and what they plan to do in the future. (Spoiler: It's more AI.)
Speaking of AI, and its potential uses for good, we also took a look at Scam Buster , a new, open-source AI-powered tool that can catch scammers before they get to you, and talk them in circles so they never get a chance to try and trick you. We also sat in on a presentation by the makers of Roblox about their approach to data privacy and their efforts to centralize the vast amount of information they collect.
This week, we also covered a new survey from the folks at Incogni that found 52% of Americans think data breaches are inevitable, and that their information will likely be lost in one. In addition, the survey revealed that most Americans feel that AI makes truthful information harder to find, and nearly a third are willing to pay for an internet with no tracking or algorithmic feeds.
In other security news, you might remember that last year we discussed the government's purchase of airline passenger records as part of a warrantless spying program. This week, additional documents from that program revealed that the Securities and Exchange Commission was involved, collecting more than one billion records alone. Meanwhile, Telegram got pulled from Apple's App Store over child sexual abuse material (CSAM), but was quickly reinstated after the user responsible was banned and the material removed. Telegram representatives say they were being "extorted" by the user , and chided Apple on X over the takedown. Even so, it's not the first time this has happened , and it's not the first time Telegram has been in hot water over illegal or offensive content .
But wait, there's more. Here's what else is going on in infosec news this week.
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Listen, any password manager is better than none, but it's worth remembering that when we say you should try to avoid using the ones built into your web browser, this is why. New research from Unit 42 , Palo Alto Networks' cybersecurity arm, revealed three new attack paths against Google Chrome's built-in password manager, according to The Hacker News . Even worse, the attacks don't bother trying to break the encryption protecting the passkeys themselves; instead, they attack the browser code that stores and authenticates with passkeys when they're needed. It's important to note that these attacks don't target passwords—they go after passkeys that have been saved in Google Chrome and synced to Google's cloud servers, so you can use them on any device where Chrome is logged in to your Google account.
According to the report, a malicious actor could quietly obtain an authentication token from a stored site session and use that to obtain a passkey, install a malicious authentication key to steal them, or (and this is the most complex method) hijack the 32-byte Security Domain Secret (SDS) that the browser uses to decrypt synced passkey private keys. Each of the three methods increases in complexity, but the researchers found that the last two are particularly dangerous because they allow an attacker to repeatedly access a user's browser and stored passkeys. Worse, the researchers aren't sure whether changing Chrome's password manager PIN or deleting all of Chrome's password manager data will actually invalidate any access a hacker may already have obtained. There is good news, however: Despite their findings, the researchers gave no indication that they've seen this exploit in the wild.
Weaponized Email AI Assistants Could Help Attackers Hijack Accounts
If you've avoided using whatever AI assistant your email provider has rushed to cram into your inbox, congratulations. Researchers at Barracuda Networks managed to trick Microsoft's Copilot (though they note this applies to any AI email assistant) into delivering all the information they needed about an organization's internal structure and staff to execute targeted phishing attacks against senior executives, such as the CEO. Of course, they needed to compromise an employee's email account first to access the company's AI assistant, but while it's definitely a hurdle, it's not uncommon, especially given how easy it is to conduct brute-force attacks or steal credentials .
Once the attackers have access to an email account, the next step is to ask the AI assistant to tell them more about the organization, including who the executives are and what their email addresses are, and to inform them about any sensitive or urgent email chains they've received or sent recently. Armed with both urgency and insider information, the attacker can phish other employees. Since the email address is internal and all activity occurs within company systems, the attack can bypass traditional spam and phishing filters. Worse, because the attacker now has data on email threads or company projects in progress, the phishing attack is even harder for a busy staffer (or executive) to flag as suspicious while scanning their inbox.
The Barracuda researchers warn that rushing to add AI assistants to internal company email systems runs the risk of turning company inboxes into searchable warehouses of sensitive data, even if an attacker is happy to sit back and exfiltrate that data rather than attack anyone, which is scary to think about.
Lawmakers Spring to Save ID Theft Services for OPM Breach Victims, With Expiration Looming
Back in 2015, hackers attacked the US government's Office of Personnel Management (OPM), stealing information on more than 22 million people , including around 5.6 million fingerprints and other sensitive data, ranging from Social Security numbers to security clearance records. As a result, the government extended 10 years of comprehensive identity theft protection to everyone impacted by the breach, authorized by Congress. Now, in 2026, that protection is set to expire at the end of September, and a group of lawmakers has introduced legislation to make it permanent for those already enrolled.
CyberScoop reports that the bill to extend those protections may be difficult to pass, however, as the OPM (which currently falls under the Trump administration) says the extended protections are too expensive, and the bill's current sponsors in both houses of Congress are Democratic lawmakers, with no Republican cosponsors. Similar legislation has stalled in the past, but the good news is that you probably already have some identity theft protection from a previous breach, and we have plenty of tips to help , even if you don't.
PCMag and Yahoo may earn commission from links in this article.
