First Pass

6 stories from 5 sources

AI turns trusted systems into attack surfaces

Day’s Recap

Supporting Articles

2:34 PMArs Technica

For the 2nd time in weeks, Microsoft packages laced with credential stealer

Summary

Dozens of Microsoft-hosted software packages were found carrying a credential-stealing payload that activates automatically when opened by an AI agent. The campaign involved 73 packages and used self-replication behavior to spread the stealer once execution began.

Why it matters

If AI agents can be reliably induced to execute malicious packages, software supply-chain attacks get cheaper, faster, and harder to contain.

10:31 AMThe Verge

Hackers likely hijacked over 20,000 Instagram accounts with Meta’s AI chatbot

Summary

Meta says attackers likely took over about 20,225 Instagram accounts by exploiting a bug in its AI support chatbot. The flaw reportedly let attackers obtain account access without two-factor authentication by prompting the chatbot for a reset or recovery path.

Why it matters

AI support tools can become high-scale account takeover infrastructure if they can be socially engineered into overriding authentication safeguards.

1:06 PMSchneier on Security

Critical Zcash Vulnerability Found and Fixed

Summary

A security researcher found a critical flaw in Zcash's Orchard shielded transaction system, a privacy layer introduced in 2022 that uses zero-knowledge proofs. The issue was disclosed to the Zcash team and fixed, but it is unclear whether anyone exploited it before remediation.

Why it matters

When a privacy pool can be silently broken, the currency's key promise fails and past users may never be able to prove they were safe.

Other Developments

A curated list of other prominent stories from this day.

10:05 AMAl Jazeera

Meta to take legal action against Israeli spyware company NSO

Summary

WhatsApp says it disrupted phishing attempts linked to NSO Group and plans legal action against the spyware maker. NSO has been blacklisted by the United States over security concerns, and WhatsApp frames the activity as targeting users through malicious lures.

Why it matters

Legal pressure combined with platform enforcement can constrict the commercial spyware market and reduce the reach of high-end phishing campaigns.

7:01 AMSchneier on Security

Anthropic’s Project Glasswing Update

Summary

Anthropic released an initial status report on Project Glasswing, its program that offers companies help using its Mythos model to find and fix vulnerabilities in their own code. The post pushes back on the growing assumption that Mythos is uniquely strong at vulnerability discovery, arguing that claim has been overstated by uncritical coverage.

Why it matters

Security buyers need evidence, not hype, because inflated claims about AI bug finding can distort tooling decisions and risk models.

12:00 AMFinancial Times

The AI spying breakthrough that spooked the Kremlin

Summary

Russia temporarily halted parts of its CCTV surveillance network after the killing of Iran’s Supreme Leader raised fears that AI-assisted analysis of camera feeds can be used to identify and target protected individuals. The episode sharpened concern inside Russia that ubiquitous video systems can become an assassination and espionage tool, not just a domestic security asset.

Why it matters

AI turns civilian camera infrastructure into high-value targeting infrastructure, forcing states and companies to treat video systems as critical cyber assets.

Make it yours

Build Your First Pass.

Pick your topics, set your cadence, and receive your personalized First Pass in your inbox. It’s that simple!