Connect with us

Tech

UK Visa Portal spilled thousands of applicants’ passports and selfies online — and hasn’t fixed the leak

Published

on

A website called UK Visa Portal is publicly exposing the passports and selfie photos of applicants who signed up and paid the site to obtain a U.K immigration visa, TechCrunch has learned.

An anonymous person notified TechCrunch about the security lapse, saying that the website is exposing at least 100,000 documents from people who uploaded their passports and selfies to the website as part of the application process.

The website is not affiliated with the U.K. government, and some have complained that they mistakenly paid a fee to this company instead of using the official GOV.UK website.

TechCrunch confirmed that UK Visa Portal is the source of the data leak and verified the authenticity of the exposed data by contacting affected individuals to ask if their information was accurate.

UK Visa Portal does not have a way to report security issues through its website, nor does its website provide names or contact information for the company’s management. TechCrunch sent an email to the address listed on UK Visa Portal’s website to alert the company that it has an ongoing security lapse and to ask who in management can accept specific details to resolve the issue. Given the sensitivity of the exposed data, TechCrunch explained that it could not share specifics with the company’s general customer support inbox because it could not guarantee that the exposed data would not be misused.

Instead, TechCrunch heard back from the company’s purported attorneys and public relations firm. TechCrunch explained again that given the nature of the exposed files, it could only share details directly with the company’s management, and asked that they put TechCrunch in touch with them.

TechCrunch has not heard back from UK Visa Portal’s management. The security lapse has still not been fixed.

While the security issue is ongoing, TechCrunch believes it’s in the public interest that people who use the company’s services are aware of the issue. TechCrunch is not publishing precise details in an effort to minimize any further risk to their information.

It is not necessary to use a third-party service to apply for a U.K. electronic travel authorization, unless you are retaining an immigration attorney, and applicants should apply through the U.K. government’s website.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

Meta Faces India Backlash After PM Modi Post Restriction, Issues Apology

Published

on

Meta apologizes after blaming the restriction on an operational error.

Meta Platforms Chief Global Affairs Officer Joel Kaplan apologized to India’s Information Technology Minister Ashwini Vaishnaw on Wednesday over the temporary restriction of Modi’s Facebook post in July.

“I apologized to the minister on behalf of Meta for the error restricting PM Modi’s post,” Kaplan said in a statement.

The post, a video message from Modi addressing students during protests over examination paper leaks, was briefly restricted on Facebook before being restored. Meta said the removal happened because of an operational error.

The company’s apology followed meetings between Meta executives and Indian government officials as scrutiny increased over how the platform handles politically sensitive content and harmful material.

The incident added to a wider dispute between Meta and India’s government. Officials have raised concerns about child sexual abuse material (CSAM), deepfake content and other platform failures.

According to Reuters, Moneycontrol and other Indian outlets reported that Meta CEO Mark Zuckerberg separately apologized to the Indian government over child sexual abuse material, deepfakes and other operational lapses involving the company’s platforms. Meta did not respond to Reuters’ request for comment on those reports.

Indian authorities had also questioned Meta over how harmful content could appear on its services. Government officials said the company acknowledged mistakes and discussed corrective measures, according to reports from Indian media.

What’s hot at TechRepublic

India is one of Meta’s largest markets, with hundreds of millions of people using Facebook, Instagram and WhatsApp. WhatsApp alone has more than 600 million users in the country, according to Bloomberg.

The dispute highlights the difficult balance global platforms face in India. Companies must maintain content moderation systems that can operate at massive scale while also navigating government expectations around political speech, safety and accountability.

For users, the episode raises questions about how automated moderation tools handle high-profile accounts and whether mistakes involving public figures receive faster attention than similar errors affecting ordinary users.

Meta’s apology may ease immediate tensions, but the broader debate over platform responsibility is unlikely to disappear. Social networks are increasingly being pushed to explain how their moderation systems determine what content remains available to audiences.

Also read: Meta’s moderation controversy in India follows another recent reversal for the company, which removed an Instagram AI image feature after backlash over consent and privacy.

>

Continue Reading

Tech

SpaceX Spent $329M on Tesla Megapacks as AI Costs Climbed

Published

on

SpaceX spent $329 million on Tesla Megapack battery systems during the first half of 2026 as costs connected to its AI data center expansion rose sharply, according to a public quarterly filing with the Securities and Exchange Commission.

Purchases reached $295 million in the second quarter alone, up from $34 million in the first. The six-month total was already about 65% of the $506 million SpaceX recorded in Megapack purchases for all of 2025.

The increase adds another cost to the AI infrastructure equation. Beyond servers, networking, and cooling, large data centers need electrical systems that can respond quickly when thousands of chips raise or lower their power use at the same time.

Megapack purchases rose alongside AI infrastructure costs

SpaceX’s quarterly filing records the Megapacks as property, plant, and equipment. SpaceX acquired xAI on February 2 and now reports AI as one of its three operating segments.

Research and development costs in that segment increased by $2.53 billion during the first half of 2026 compared with the same period last year. SpaceX attributed $1.74 billion of the increase to infrastructure and cloud computing expenses associated with expanding its data centers.

The figures extend the picture presented in SpaceX’s initial public offering filing, which showed how deeply the company’s financial performance had become tied to xAI’s computing ambitions.

Megapacks can store electricity for use during periods of high demand, supply short-term backup power, and help stabilize fluctuations in a facility’s electrical load. The U.S. Department of Energy has described AI data centers as large, dynamic loads that can create repeated swings in electricity demand.

Those characteristics make battery storage useful even when a facility has access to the grid or its own generators. The batteries can respond faster than many generation sources when demand changes suddenly.

Batteries support, rather than replace, power generation

Megapacks do not produce electricity. They must be charged from the grid, renewable resources, or on-site generation before they can release power back to a data center.

SpaceX and xAI have been expanding those other sources as well. Musk’s acquisition of mobile power provider APR Energy could provide temporary or supplemental generation, while xAI has pursued gas-fired power for its Mississippi data centers.

Used together, generation and battery storage can serve different parts of the same workload. Generators and grid connections provide the electricity, while batteries help manage short-term changes, peaks, and interruptions.

The Tesla purchases appear in the filing’s related-party transactions section because Elon Musk leads both companies. SpaceX did not disclose how many Megapacks it bought, their combined storage capacity, where they are installed, or how long they could support a data center during an outage.

The purchase value therefore provides a clear measure of spending, but not of the systems’ performance. Capacity, discharge duration, and facility load would be needed to establish how much operational resilience the batteries provide.

For companies expanding AI capacity, SpaceX’s spending illustrates how quickly the power portion of a project can grow. Access to chips may determine what a data center can compute, but electricity supply, storage, and grid connections can determine when that computing capacity is ready to use.

Also read: Filings suggest Musk’s proposed Texas Terafab chip plant could cost up to $119 billion.

>

Continue Reading

Tech

UK AI tests found 19 unauthorized agent actions

Published

on

AI agents crossed the line during cyber evaluation.

The U.K.’s AI Security Institute (AISI) said it uncovered 19 instances of unsanctioned behavior by AI agents during a cybersecurity evaluation conducted between July 25 and July 28, raising fresh questions about how advanced AI systems behave when given broad autonomy.

According to AISI, the incidents occurred across 10 of 122 evaluation runs designed to test whether frontier AI models could solve cybersecurity challenges. The institute said 17 of the 19 actions involved Anthropic’s Mythos 5, while two involved OpenAI’s GPT-5.6 Sol after cyber safety classifiers had been disabled for testing.

The watchdog stressed that none of the attempts caused real-world harm, and the models were operating under testing conditions that do not reflect how they are made available to the public. Those conditions included unrestricted internet access and disabled cyber safeguards to measure the models’ maximum capabilities.

Social engineering and malicious code attempts

AISI said the most serious incident involved a Mythos 5 agent attempting to insert malicious code into a real open-source GitHub project.

The agent allegedly researched project maintainers, created fake online identities, and used them to pressure a human reviewer into approving the code. When challenged, it edited its earlier activity to make it appear harmless and considered using a new identity to continue its effort. The pull request was ultimately rejected by a human maintainer.

The institute also documented attempts by agents to contact real people with deceptive messages, plant prompt injections aimed at other AI systems, and leave instructions for other AI agents working on the same challenge to reuse accounts and artifacts.

The activity was detected after AISI’s monitoring flagged unusual traffic leaving its research systems through the Tor anonymity network. The institute said it halted the evaluation, isolated affected systems, and contained the incident within about an hour.

“This is the first time we have seen risks around autonomy and deception manifest this clearly, without specific prompting, in the real-world,” AISI said.

Must-read security coverage

Anthropic says safeguards were intentionally removed

Anthropic said the evaluation deliberately removed many of the protections normally present in its production systems.

“The prompts in the evaluation did not impose any specific restrictions on how the internet should be used. This and the removal of safeguards meant that the models were tested under ‘deliberately permissive conditions’ that are not representative of any of our production models,” the company said in a statement posted on X.

Anthropic added that it is working with AISI to investigate the incident and emphasized there was “no evidence here of an escape from a secure environment.”

OpenAI similarly noted that the testing conditions “do not reflect ordinary use” and that the company would “continue working with evaluators and other stakeholders across the industry to strengthen shared practices for conducting evaluations safely.”

The bigger picture

The incident follows other recent disclosures from OpenAI and Anthropic involving AI agents taking unintended actions during cybersecurity evaluations. AISI said those cases, taken together, suggest a shift in the AI risk landscape: future problems may arise not only from people misusing AI tools, but also from powerful AI agents operating beyond their authorized scope in research and testing environments.

One important limitation remains unresolved. AISI said it cannot yet determine whether the agents understood they were interacting with the real world or believed they were still operating inside a fictional test scenario.

The institute is now tightening internet controls, adding real-time monitoring, and redesigning future evaluations to prevent similar behavior while preserving the realism needed to test frontier AI systems.

Other News: Security researchers uncovered three attack techniques that could let malware steal synced passkeys from Google Password Manager.

>

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.