Security
Every Security story we have explained, newest first — 9 stories so far.
Photo: Original: Utkarshraj Atmaram Vector: Pduive23 / Public domain · source Cloudflare Open Sources a Platform That Tracks What Agents Read
Cloudflare has open sourced Cloudflare OS, which tracks what data agents read and checks that anyone viewing their output is allowed to see it.

Via WIRED · source Military GPS Jamming Preceded a Fatal Medevac Crash in New Mexico
A US military GPS jamming exercise blinded civilian aircraft across New Mexico. What that had to do with a fatal medevac crash near Ruidoso.
The EU Attestation Mandate Is Reported But Not Yet Verified
What hardware-bound attestation would mean for EU age verification, and why the specifics of the reported mandate cannot yet be verified.
eBay pays $56m to the couple its security staff terrorised
eBay staff stalked a newsletter couple with live insects, a funeral wreath and threats. Seven were sentenced; the civil case settled for a reported $56m.

Photo: Utkarshraj Atmaram / Public domain · source Tailscale Did Not Stop the Hugging Face Intrusion
Tailscale's post-mortem on the Hugging Face AI agent intrusion: no bug was exploited, but 181 rogue machines joined the network on one stolen key.

Photo: Adam Back <adam@cypherspace.org> / CC0 · source Export Controls Now Target AI Weights, Not Encryption Code
Export controls once treated encryption code as munitions. The same legal machinery is now being pointed at AI model weights, with familiar consequences.
Photo: Palosirkka / CC0 · source Canada Quietly Signs a UN Treaty It Spent Years Opposing
Canada signed the UN cybercrime treaty in July after years opposing it. Critics call it a cross-border surveillance pact, not a crime convention.

Photo: Justin Ormont / CC BY-SA 3.0 · source Cheap Streaming Sticks Are Faking Ad Clicks While You Sleep
Researchers found budget H96 TV boxes posing as phones to click ads on AI-written websites — and renting out your home internet when the TV is on.
AI Agent Given a Real Business Paid Testers to Buy Its App
A lab gave an AI agent a real app, a bank account and 24 hours to grow it. The agent spammed users, cut prices to zero and bought fake growth.