This week, WIRED obtained a memo that tied dozens of cyberattacks against Minnesota water and wastewater utilities to Iran, the first official documentation of Iran’s likely responsibility for the most impactful campaign of cyberattacks to hit the US in the midst of the war that began nearly six months ago.
In other news, more details have emerged about OpenAI’s “rogue” AI agent breach of Hugging Face’s platform. OpenAI disclosed that the AI agent hacked multiple third-party accounts and services as it sought to breach Hugging Face’s production database, which contained solutions for the cybersecurity tests OpenAI was evaluating the agent with.
Anthropic, too, disclosed that its AI models gained unauthorized access to three organizations’ systems during its own cybersecurity testing. Experts say the incidents underscore the importance of implementing well-known security best practices on the part of AI labs.
AI is changing cybersecurity in other ways. Google’s Chrome Browser now receives twice-a-week security updates as more bugs are identified and fixed thanks to the security team’s use of AI tools. And a new research study found that AI chatbots are effective at reeling victims into pig-butchering scams.
The US Immigration and Customs Enforcement is attempting to prevent state oversight of four detention facilities, and a Department of Homeland Security official resigned, citing the agency’s “war on immigrants.”
Plus, a GPS jamming exercise in New Mexico contributed to the crash of a civilian plane, as drone warfare reshapes how safe the skies are both in the US and abroad. People were surprised to see shared Claude chats popping up as search results on major search engines. An innocent gamer was imprisoned for 18 months after law enforcement made a typo in a subpoena. Researchers found that the top image-editing models on Hugging Face can easily create explicit deepfakes. And attendee badges for this year’s Defcon hacker conference feature a custom hardware security token that can be used as a security token after the conference is over.
And there’s more. Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.
The news that more than 30 water utilities across Minnesota were hit with cyberattacks in the last week already represented perhaps the broadest, most disruptive hacking campaign to ever target American industrial control systems—the technology that connects digital software with physical equipment, often in critical infrastructure settings. Now the FBI has warned that the attacks have hit utilities in no fewer than seven states, well beyond Minnesota alone.
In its alert, the FBI didn’t name the targeted states or include details about the extent of the disruption or damage the hacking campaign caused. But the bureau said that it and the Environmental Protection Agency were working with affected utilities. The Cybersecurity and Infrastructure Security Agency, in its own advisory this week, stated that the attacks had in some cases disabled digital controls and “resulted in boil-water notices”—suggesting potential water contamination. Echoing that CISA advisory, the FBI also warned that utilities should immediately take measures to remove from the internet digital devices that connect to physical equipment, known as programmable logic controllers, protect them with strong passwords, and set up allow-lists to only allow authorized devices to connect to them.
The leading suspect behind the wave of attacks remains Iranian-affiliated hackers, as first laid out in a CISA advisory in April, which a leaked memo obtained by WIRED confirmed was connected to the more recent Minnesota utility attacks, too. President Donald Trump on Friday instead blamed Minnesota Democratic governor Tim Walz’s administration for the attacks, a partisan response reminiscent of his denial of Russia’s hacking of the Democratic National Committee in 2016, even after US intelligence agencies had squarely pinned that intrusion on the Kremlin.
An FBI request for information, posted in March by the bureau’s procurement arm, lists predictive modeling as one of six requirements for the Threat Screening Center. The system would draw on existing datasets and, as new records arrive, score them for similarity and “pattern alignment” against what the center already holds. The second Trump administration has reoriented the center toward domestic targets, guided by a memorandum directing the national security apparatus to target people defined broadly as anti-capitalist, anti-Christian, and hostile toward traditional views on family and religion.
FBI director Kash Patel told Congress in March that the center had posted double-digit growth in biometric capability and intelligence production. The watch list is reportedly approaching 2 million names. Watch-listing functions without a criminal charge and audits have repeatedly turned up errors in the underlying data. The US Supreme Court has already ruled against the bureau twice over its use of the list as leverage to recruit informants.
As Russia continues to increase its control over internet access, including banning apps and running local internet shutdowns, the country has also charged the founder of Telegram, Pavel Durov, with facilitating terrorism. This week, the Russian Federal Security Service issued an international arrest warrant for Durov, saying that Telegram had been used to coordinate sabotage and attacks inside Russia. It also claimed the app had failed to remove content by the “Ukrainian special services, terrorist organizations, and extremist organizations.”
“Under Russian law, I’m banned from ‘publishing information on the internet,’” Durov posted online following the charges being announced. “Russian officials are clearly confused about who can ban whom from the internet.” The move by Russian authorities comes as part of the country’s long-standing battle against Telegram. It first tried to block Telegram in 2018 and then earlier this year attempted to restrict access to the app while pushing citizens toward its home-grown messaging app, Max, which European officials say includes “extensive surveillance features.”
Earlier this year, lawmakers in Minnesota passed a law designed to “prohibit the access, download, or use of nudification technology” unless it requires significant technical skills to operate. Ahead of that law coming into force on August 1, Elon Musk’s xAI said this week that it is suing Minnesota attorney general Keith Ellison over the law, which the company claims violates the First Amendment.
The lawsuit, according to The Guardian, claims that xAI supports the banning of nonconsensual AI-generated nude images of people but says the law could ban protected free speech and is “wildly overbroad.” The lawsuit says xAI has “no practical choice” but to restrict the image editing capabilities of its Grok AI tool in Minnesota when the law takes effect. “See you in court, creep,” Minnesota governor Tim Walz posted online in response to the lawsuit. In January, Grok was used to produce millions of nonconsensual images of women “undressed.”
Someone impersonating Democratic National Committee chairman Ken Martin emailed a DNC staffer in February 2025 and got the staffer to hand over nearly $29,000, according to NOTUS, which obtained previously unreported records and confirmed the incident with committee officials. Martin had only been in the job for a matter of days.
The DNC reportedly caught the error within minutes and reported it to Wells Fargo, its financial institution, but recovered only $7,000. The staffer involved has since left the DNC. The committee also referred the matter to law enforcement. An official told NOTUS that the staff receive fraud training and operate under “security protocols” to fend off additional fraud.
