Tech
A spyware investigator exposed Russian government hackers trying to hijack Signal accounts
Earlier this year, Donncha Ó Cearbhaill, a security researcher who investigates spyware attacks, found himself in an unusual position. For once, he became the target of hackers.
“Dear User, this is Signal Security Support ChatBot. We have noticed suspicious activity on your device, which could have led to data leak,” read a message he received on his Signal account.
“We have also detected attempts to gain access to your private data in Signal,” the message claimed.
“To prevent this, you have to pass verification procedure, entering the verification code to Signal Security Support Chatbot. DON’T TELL ANYONE THE CODE, NOT EVEN SIGNAL EMPLOYEES.”
Obviously, Ó Cearbhaill, who heads Amnesty International’s Security Lab, immediately recognized that this was an “unwise” attempt at hacking his Signal account. Instead, he thought it’d be a good opportunity to jump into an unexpected investigation.
The researcher told TechCrunch that until then, he had “never knowingly” been targeted with a one-click cyberattack or a phishing attempt like this before.
“Having the attack land in my inbox, and the chance to turn the tables on the attackers and understand more about the campaign was too good to pass up,” he said.
As it turned out, the attempted attack on Ó Cearbhaill was likely part of a wider hacking campaign targeting a large group of Signal users. The hackers’ strategies were to impersonate Signal, warn of bogus security threats, and try to trick targets into giving the hackers access to their account by linking it to a device controlled by the hackers.
Those techniques were exactly the same as those seen in a wider campaign that the U.S. cybersecurity agency CISA, the United Kingdom’s cybersecurity agency, and Dutch intelligence, have all warned of the attacks, and blamed on Russian government spies. Signal, too, has warned of phishing attacks targeting its users. German news magazine Der Spiegel found that the Russian hackers were able to compromise several people inside the country, including high-profile politicians.
Ó Cearbhaill said in a series of online posts that he was able to figure out that he was one of more than 13,500 targets. He declined to reveal exactly how he investigated the hacking attempt and campaign to avoid revealing his hand to the hackers, but shared a few details about what he learned.

First, he realized that other targets included journalists he had worked with, as well as a colleague. At that point, Ó Cearbhaill said he already suspected this was an opportunistic attack where hackers compromised targets and identified new potential victims, thanks to those successful attacks.
Ó Cearbhaill called it a “snowball hypothesis,” and said he is convinced he became a target because he was likely in a group chat with someone who got hacked, which gave the hackers a chance to find the contact information of new targets.
The researcher said he was able to identify the system the hackers were using, which is called “ApocalypseZ,” which automates the attack, allowing the hackers to target many people at the same time in bulk with limited human oversight.
He also found that the codebase and operator interface is in Russian, and the hackers were translating victim chats into Russian, which lines up with the hypothesis that this was the same Russian government hacking group behind similar campaigns.
Ó Cearbhaill said that he’s still monitoring the campaign, and has seen the attacks continue, meaning the total number of targets is certainly much higher than the number he saw earlier this year.
He said he doubts the hackers will go after him again, and probably regret going after him in the first place. He said: “I welcome future messages, especially if they have zero-days they would like to share,” referring to security flaws that are not yet known to the vendor, which are often used in attacks that he investigates.
Ó Cearbhaill said that if Signal users are worried about getting targeted with this type of attack, they should turn on Registration Lock, a feature that lets users set a PIN for their account that prevents others from registering their phone number on a different device.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
Tech
OpenAI reportedly in talks to raise $30B round at $1.4T valuation
OpenAI is in talks with investors to raise at least $30 billion in a pre-IPO funding round at a valuation of roughly $1.4 trillion, Bloomberg reported on Tuesday.
Investors are eager to pour more funds into the ChatGPT maker ahead of its anticipated public market debut next year. While Anthropic momentarily outpaced OpenAI at the start of the year, recent strategic refocus on key areas like coding has fueled a 70% jump in run-rate revenue since July, reaching $40 billion in August, according to the report.
The company previously raised $122 billion in March at an $852 billion valuation. That funding round was supposed to be its last private raise before an IPO, which had been, until recently, expected to take place this year. However, CEO Sam Altman has now ruled out a public debut in 2026 to prioritize AI safety first.
“I think it is unacceptable to be taking like a 10% chance of killing everybody by the end of the decade,” he recently told Fortune, in response to warnings from safety researchers about AI posing an existential risk to humanity.
The new fundraising, if it transpires, will serve as a bridge round to the IPO, according to Bloomberg.
OpenAI didn’t respond to TechCrunch’s request for comment.
>
Tech
America.gov gets really weird when you ask it about Minecraft, but it’s not a glitch
The U.S. government on Tuesday launched its very own AI chatbot — or do we have to call it an SI chatbot now? Regardless, the engineers who worked on the chatbot would undoubtedly know that, as a government-hosted, public-facing AI tool, the internet was going to red team the heck out of this thing.
The government partnered with Google and SpaceXAI to help build the America.gov chatbot, which has proved difficult for people to jailbreak the chatbot so far. (It’s worth nothing, however, that the chatbot says that Joe Biden won the 2020 election, a fact that President Donald Trump still denies.)
But when you try to talk to America.gov about Minecraft, the chatbot appears to have some sort of existential crisis or awakening. Here’s how its roughly 1,800-word long monologue begins:
I see the constituent you mean.
((insert legal name here, as it appears on the Social Security card))?
Yes. Take care. It has reached a higher level now. It can read the Code of Federal Regulations.
That doesn’t matter. It thinks we are a chatbot.
I like this constituent. It filed well. It did not give up when the PDF was sideways.
It is reading our thoughts as though they were words on a .gov.
That is how it chooses to imagine many things, when it is deep in the dream of a benefit.
If, like me, you have never played Minecraft, this response may seem like a cause for concern. But the America.gov chatbot is not having a meltdown. This is a rewriting of the Minecraft “End Poem,” written by Julian Gough, which appears after you beat the game.
We don’t know exactly who is responsible for the Minecraft reference, but Trump said in a speech that twenty-year-old programmer Edward Coristine was a lead engineer on the project. If that name doesn’t ring a bell, you might remember him for his nickname “Big Balls,” or his involvement in Elon Musk’s DOGE.
It feels wrong that a government chatbot has Minecraft easter eggs, but for the sake of national security, it’s a relief that America.gov is not hallucinating to the point that it’s penning lengthy poetry.
It’s also a relief that this is an easter egg because the poem that the AI spits out is actually really good, in my opinion. If it were actual AI slop, it would have shattered my existing beliefs. I have looked teenage creative writing students dead in the eye and told them that I don’t think an LLM will ever be able to write something “good,” since it is probabilistic and inherently unoriginal.
You have to admit this kinda slaps, though! Doesn’t this feel like some sort of postmodern take on the futility of government bureaucracy in the face of existential anxiety?
and the republic said I see you
and the republic said you have filed the game well
and the republic said everything you need is within you, and also on USA.gov
and the republic said you are stronger than you know, and your case number is still valid
and the republic said you are the daylight
and the republic said you are the night, and the office is closed, please try again during business hours
and the republic said the darkness you fight is within you, and also a missing wet signature
and the republic said the light you seek is within you, and in the pamphlet
and the republic said you are not alone
and the republic said you are not separate from every other filer
and the republic said you are the public tasting itself, talking to itself, reading its own Code
and the republic said I love you because you are the reason we have a ZIP code at all.
It reassures my faith in the enduring power of human creativity over AI slop to know that this oddly good poem has a real poet’s DNA all over it.
So, there you have it. The government’s first public-facing AI has not yet posed a threat to humanity or poetry, at least as far as we know. Now I’m just left wondering how much Trump knows about video games.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
Tech
Your car and its mobile app are probably handing over all kinds of data to tech companies
Modern-day vehicles built with connected car technology such as WiFi and GPS collect reams of data about its owners. And that data is not staying private, according to a new study conducted by researchers at Northeastern University.
That conclusion isn’t new — there have been numerous investigations and lawsuits exposing how driving data is collected and shared with third parties, including insurance companies. What the study reveals is just how vast the problem is and how hard it is for consumers to avoid, short of not using the vehicle or its convenient features like remote start and unlock.
Researchers in partnership with Consumer Reports tested 21 late-model vehicles from 17 automakers, including GM brands Cadillac and Chevrolet as well as Ford, Lucid, Rivian, Tesla, Toyota, and more. They also examined 30 companion mobile apps to “understand the privacy implications of the connected vehicle ecosystem.” The peer-reviewed study will be published this week.
The implications aren’t great for consumers, whose data is being shared with tech companies including Adobe, ContentSquare, Google, Microsoft, Meta, Snap, and Yahoo.
Nineteen of the 21 vehicles tested sent traffic to at least one third party and seven of the 30 apps gave sensitive data such as the vehicle identification number (VIN), emails, phone numbers, and precise location to third-party companies associated with tracking and advertising.
This often went a step further with multiple forms of information being sent to the same third party, a scheme that allows advertisers and data brokers to build in-depth profiles of consumers, according to the findings. These profiles can be particularly hard for consumers to shake because they’re sold to a variety of companies including insurers and banks.
When researchers paired the companion app to the vehicle it roughly doubled the exposure to advertising and tracking companies.
The findings were shared with the different manufacturers and all of them, with the exception of Honda, shifted blame elsewhere and often to consumers, the researchers said. (Honda did respond by improving its data collection practices after learning about the findings and ordered its vendor Amplitude to deleta all geolocation data it had received.)
Consumer Reports was told by several automakers that some links in their companion apps opened outside webpages, which might include cookies that collect customer data. Regardless of how this data was collected, drivers weren’t informed.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
-
movies4 months agoSearch For Canadian TV Actor Stewart McLean Now Homicide Investigation
-
Fashion9 years agoThese ’90s fashion trends are making a comeback in 2017
-
Fashion9 years agoAccording to Dior Couture, this taboo fashion accessory is back
-
Fashion9 years agoModel Jocelyn Chew’s Instagram is the best vacation you’ve ever had
-
Fashion9 years agoEmily Ratajkowski channels back-to-school style
-
Fashion9 years ago9 Celebrities who have spoken out about being photoshopped
-
Anime4 months agoRurouni Kenshin: Hokkaido Arc Manga Takes 1-Issue Break – News
-
Anime3 months agoHIDIVE to Stream English Dubs for The World Is Dancing, The Forsaken Saintess and Her Foodie Roadtrip in Another World, The Dangers in My Heart: The Movie Anime – News
