The media in this post is not displayed to visitors. To view it, please log in.

The media in this post is not displayed to visitors. To view it, please log in.

At least 24 chimpanzees have been killed in a war that has split the Ngogo group of wild chimpanzees in two, turning former kin into enemies.#TheAbstract


World’s Largest Group of Chimps Waging Deadly ‘Civil War,’ Scientists Discover


🌘
Subscribe to 404 Media to get The Abstract, our newsletter about the most exciting and mind-boggling science news and studies of the week.

Scientists have observed an extremely rare chimpanzee “civil war,” a conflict that has killed at least seven adults and 17 infants, and which sheds new light on the nature of warfare in humans, according to a study published on Thursday in Science.

Male chimpanzees are often aggressive to outsiders, but it is unusual for chimps to kill former members of their own social groups. Though Jane Goodall and her colleagues observed one famous example—the Gombe Chimpanzee War of the 1970s, which resulted in seven adult deaths—it’s estimated that these violent episodes occur only once every 500 years, based on genetic analyses of chimpanzee lineages.

Now, a team led by Aaron Sandel, an associate professor of anthropology at the University of Texas at Austin, has reported a far more deadly “group fissure” among the Ngogo chimpanzees of Uganda. This population exceeded 200 individuals at one point, making it the largest group of chimpanzees ever observed in the wild. But over the past decade, the chimps have fractured into two factions, one of which has staged multiple lethal raids on the other.

“Certainly, these are not strangers,” said Sandel in a call with 404 Media. “These are chimps that once knew each other, and we know that for certain.”

The Ngogo group has been studied since the 1970s by primatologists like Thomas Struhsaker, and have been intensively observed since 1995 as part of the Ngogo Chimpanzee Project set up by David Watts and John Mitani. For more than three decades, researchers from around the world have convened to watch the group during summer field expeditions, while Ugandan research assistants have maintained a continuous presence at the site.

Because of this longstanding observation, Sandel said, researchers were able to be on the ground “witnessing every moment” as the deadly chimp war unfolded.

Chimpanzees from different clusters socialized together before the group fissure in 2015. Image: Aaron Sandel

This group has always had distinct subpopulations that spent more time together, including the Western and Central clusters. Even so, before the fissure, the clusters regularly overlapped for shared activities like grooming, patrolling, and interbreeding.

Sandel vividly remembers the exact day that this dynamic had noticeably shifted: June 24, 2015. He was following the Western cluster, which was at the center of its “neighborhood” territory, he said.


0:00
/0:09

Video credit: Aaron Sandel

“They hear chimps from the Central neighborhood nearby, and they go quiet,” he recalled. “They seem nervous. They're touching each other with this reassurance that they typically do when they hear the outsider chimps, but I was just alone with them. I remember, just in that moment, being really puzzled and focused, like ‘what’s going on?’”

“They could have reunited and done what's typical—screaming and charging around, maybe some slapping, and then come together, sit together, groom, maybe go their separate ways after, because they'd already started to be a bit more disconnected,” Sandel continued. “But instead of reuniting in typical chimpanzee fusion fashion, the Western chimpanzees ran and the Central chimps chased them.”


0:00
/0:20

Video credit: Aaron Sandel

What started as a weird vibe transformed into a weeks-long chill between the groups, followed by a temporary thaw. Ultimately, the tension spiraled into bloody conflicts.

“You act like a stranger, you become a stranger,” Sandel said. “It seemed like that planted the seed of polarization.”

Over the course of the next few years, the males in each cluster began to treat each other like outsiders. The last offspring that had parents from different clusters was conceived in March 2015. The Western and Central chimps were fully separated by 2018.

The Western chimps, despite being smaller in number, have since amped up hostilities by staging 24 violent attacks against their former kin, killing at least seven mature males and 17 infants from the Central cluster. The death toll may well be higher, but some deaths and disappearances cannot be conclusively attributed to the conflict.

Sandel and his colleagues proposed a few possible causes of this “civil war,” a term that specifically refers to human conflicts, but that may have parallels in other species. First, the unusually large size of the group may have amplified feeding competition among individuals, even in their lush forest habitat. Social networks within the group may have also been disrupted by a wave of six deaths in 2014—five adult males and one adult female—some of whom likely died from disease.

The beginning of the fissure also coincides with the rise of a new alpha male, Jackson, who replaced the previous alpha, Miles. Sandel recalled Miles grunting in submission to Jackson on the same day that the Western cluster ran away from the Central cluster. Such transitions between alphas can introduce social instabilities as the dominance hierarchy is upended, a process that can take several months.

Indeed, Miles reacted violently toward other members of the group in the wake of his displacement. Jackson, who led the Central cluster, ended up as one the casualties of the conflict; he died from injuries inflicted by the Western cluster in 2022.

Whatever the cause of the rupture, this group of former kin have now become hostile enemies. It’s always dicey to draw broad comparisons between the behavior of humans and other animals, but the team speculates in the study that one possible takeaway is that "it may be in the small, daily acts of reconciliation and reunion between individuals that we find opportunities for peace.”

“If we study chimpanzees in detail and start to understand the mechanisms driving their cooperation, their conflict, and something as complex as one group becoming polarized, splitting, and engaging in ongoing lethal conflict, then we might gain insights into similar dynamics that are happening in humans,” Sandel said.

“If chimps are able to do this complex process in the absence of ethnicity, language, and religion—the things we often attribute to human warfare—chimps don't have those narratives and those excuses,” he concluded. “They're stripped away of those cultural dimensions. It must be their interpersonal social bonds and daily conflicts, reconciliations, and avoidances—all those dynamics. If that's the case with chimps, to what extent is it the case in humans? It’s a hypothesis to be tested.”

🌘
Subscribe to 404 Media to get The Abstract, our newsletter about the most exciting and mind-boggling science news and studies of the week.


The case was the first time authorities charged people for alleged “Antifa” activities after President Trump designated the umbrella term a terrorist organization.


FBI Extracts Suspect’s Deleted Signal Messages Saved in iPhone Notification Database


The FBI was able to forensically extract copies of incoming Signal messages from a defendant’s iPhone, even after the app was deleted, because copies of the content were saved in the device’s push notification database, multiple people present for FBI testimony in a recent trial told 404 Media. The case involved a group of people setting off fireworks and vandalizing property at the ICE Prairieland Detention Facility in Alvarado, Texas in July, and one shooting a police officer in the neck.

The news shows how forensic extraction—when someone has physical access to a device and is able to run specialized software on it—can yield sensitive data derived from secure messaging apps in unexpected places. Signal already has a setting that blocks message content from displaying in push notifications; the case highlights why such a feature might be important for some users to turn on.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


How Florida conservation police are tapping into Flock for ICE; Wikipedia's AI ban; and how the app TeleGuard uploads users' private keys.#Podcast


Podcast: Wildlife Cops Are Searching AI Cameras for ICE


This week we start with Jason’s story about how wildlife cops are doing Flock lookups for ICE. It shows that ICE is gaining access to this sort of information through pretty unexpected ways. After the break, Emanuel tells us all about the AI ban at Wikipedia. In the subscribers-only section, Joseph breaks down a set of vulnerabilities in the ‘secure’ chat app TeleGuard.
playlist.megaphone.fm?e=TBIEA5…
Listen to the weekly podcast on Apple Podcasts,Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.
youtube.com/embed/YrHYwCb5aM8?…
0:00 - Intro

1:03 - ⁠Wildlife Conservation Police Are Searching Thousands of Flock Cameras for ICE⁠

27:55 - ⁠Wikipedia Bans AI-Generated Content⁠

34:33 - ⁠An AI Agent Was Banned From Creating Wikipedia Articles, Then Wrote Angry Blogs About Being Banned⁠

Subscriber's Story - ⁠A Secure Chat App’s Encryption Is So Bad It Is ‘Meaningless’⁠


At a New York party, attendees spent Trans Day of Visibility dancing, DJing, and learning how to become less visible online.#Privacy #Security #opsec #persec


A 'Self-Doxing' Rave Helps Trans People Stay Safe Online


It’s Trans Day of Visibility, and I’m at an event space in the heart of New York City’s Commie Corridor to learn how to become less visible online.

The crowd gathered at the aptly-named Trans Pecos in Ridgewood, Queens is here for “404: Deadname Not Found,” a digital self-defense workshop which promises to teach trans people how to find and remove their sensitive personal information from the internet (and which also has no relation to this website). The vibe is giving OpSec rave happy hour—attendees sip colorful drinks, groove to DJ sets, and huddle around laptops using online tools to track down their own digital footprints.

The goal of the exercise is to find holes in your digital defenses, a practice cybersecurity folks call “red-teaming.” A slide deck guides participants through this “self-doxing” ritual, instructing them to use websites like IntelBase, PimEyes, and haveibeenpwned to find addresses, selfies, passwords, old names and aliases, and other personal info that might have been left sitting around on the open internet.

It makes for great cocktail party banter. One participant raises their arms in triumph upon receiving a clean bill of health while checking if their information was leaked in a data breach. Others swivel laptop screens and compare notes on the various places their digital detritus had cropped up. In my case, I was lucky: I mostly found data brokers with incorrect information, a long-forgotten MySpace page, and a woman whose spam calls I’ve been receiving for the past 10 years. Finally, participants are directed to various pages where they can request data to be removed, or sign up for discounted services like Kanary and DeleteMe that do the removals on your behalf.

Behind the fun and light atmosphere, everyone here knows the unspoken reality that drives tonight’s activities: an unrelenting wave of discriminatory bills and executive orders that are rapidly demolishing trans rights across the US. “Trans Visibility” is a nice idea, but it turns out it really sucks to be visible in a fascist surveillance state where the highest levels of government are obsessively trying to destroy your ability to live.

“In this world of hyper-surveillance, I want to make sure all my stuff is safe and that no one is trying to harvest my data for anything,” Anna, a workshop participant, told 404 Media. Anna asked to use a pseudonym to protect her identity, which is not surprising given that the goal of the workshop is to make it harder to be doxed. “Especially now that there’s lots of incentives for the federal government to get into that business, I just wanna make sure all of that is under wraps.”

Like the event’s name suggests, many attendees are looking for traces of their “deadnames,” which is how some trans folks refer to the names they were given pre-transition. Trans people face a disproportionatelyhigh risk of being doxed online, and deadnames and other sensitive info are frequently dug up on right-wing hate forums like KiwiFarms and social media sites like Elon Musk’s X, where harassment campaigns and hate speech are allowed and even encouraged.

“We have to protect ourselves,” said Ryan, who also used a pseudonym. “It’s great to know how to find stuff like this, because you never know what’s still out there.”

Imani Thompson, a digital security trainer who organized the event as part of her series Cache Me Outside, says she started hosting the free workshops at queer bars in Brooklyn a year ago, after noticing trans and intersex friends who were noticeably shaken by the opening salvos of the second Trump administration.

“I hadn't seen cybersecurity events that looked like they would attract or resonate with the crowds I felt needed this information the most,” she told 404 Media. “I wanted to make this fun and un-intimidating and doing digital security training at the bar is kind of silly and fun and gives us a built-in VPN and protection from sensitive convos being recorded.”
playlist.megaphone.fm?p=TBIEA2…
There are specific reasons many trans people are anxious about their personal data and online presence these days. For one, trans identities often don’t fit neatly into government boxes, and the name and gender they are assigned at birth may or may not match their government-issued IDs. Recently, a new law in Kansas resulted in hundreds of trans people being told that theirdrivers licenses and IDs had been invalidated overnight, forcing them to obtain new documents that revert to the sex marker assigned at birth. JournalistMarissa Kabas later reported that the 300 trans IDs in question had been flagged and not immediately invalidated, but the goal of the law and its ensuing chaos was clear: requiring trans people to have IDs that don’t match their appearance or lived reality, forcing them to out themselves and introducing friction and discrimination into their everyday lives.

The same Kansas law also implemented the first state-level “bathroom bounty,” making it a crime for trans people to use appropriate bathrooms and changing rooms and promising rewards to random passersby who feel “aggrieved” by someone they think might be trans. Lawmakers in Idaho have passed an even harsher bill, which would charge repeat trans bathroom-users with a felony and up to 5 years of jail time. These bills threaten not only trans people, but anyone whose appearance might fall outside of someone’s normative expectations of “male” and “female.” And they are especially dangerous at a time when facial recognition can near-instantly identify someone with a quick search.

Thompson also worries about the information that queer folks can reveal while asking for help online. Trans people experienceunemployment,housing insecurity, andviolence at exponentially higher rates than cis people, and it’s not uncommon to see Gofundme pages and Venmo accounts flooding social media feeds. These posts will sometimes include personal details like a person’s name, face, transition status, location, immigration status, and even how much they have in their bank account—great for getting donations, but not so great for the doxable breadcrumbs they leave behind.

You Can’t Post Your Way Out of Fascism
Authoritarians and tech CEOs now share the same goal: to keep us locked in an eternal doomscroll instead of organizing against them, Janus Rose writes.
404 MediaJanus Rose


“I think the risk is tenfold for the dolls and Black trans siblings because of disproportionate scrutiny in light of these bathroom bills and also how we do mutual aid,” said Thompson. “Whenever I see a mutual aid request being reposted or processed it makes me nervous, because we're basically doxing our most vulnerable friends.” To reduce risk, she recommends people take down mutual aid posts as soon as needs are met and set their Venmo activity to private. “I feel like the intention in listing off how all these systems of oppression impact our friends are meant to create a sense of urgency and care, but then months later it's still floating around and is a goldmine for someone who wants to claim they were made to feel unsafe in a bathroom so they can claim $3k or further an agenda.”

The privacy attitudes on display at the event contrast with the dominant media narratives about trans communities a decade ago. Fresh off the Supreme Court victory in Obergefell vs. Hodges that legalized same-sex marriage, many at that time were convinced that trans visibility would pave the way to equality, as glossy magazine covers featuring stars like Laverne Cox declared a “Trans Tipping Point.” But while conditions for some trans people marginally improved, we all know what happened next: a wave of reactionary anti-trans state laws, culminating in the re-election of Donald Trump and a series of executive orders aimed at destroying trans peoples’ access to healthcare, sports, bathrooms—essentially the ability to live a normal life.

At the same time, protection can’t be a retreat back into the closet. “It’s still important for trans voices to be heard in online spaces,” said Anna. “It’s not like I wanna go into the shadows or anything. I just don’t want people to know my personal data, my personal records, any of that.”

“Being Black, I also understand the distinction between visibility and hypervisibility and the precarity and lack of agency that hypervisibility creates,” said Thompson. “It's tricky to find language around digital security that doesn't imply queerness is something to hide or a shameful thing, because of course it's not. I think having agency and purpose in how we can show up online and interact with tech as well as literacy around how technology and surveillance operates makes us better equipped.”

Janus Rose is New York City-based journalist, educator and artist whose work explores the impacts of A.I. and technology on activists and marginalized communities. Previously a senior editor at VICE, she has been published in digital and print outlets including e-Flux Journal, DAZED Magazine, The New Yorker, and Al Jazeera.


Marathon is a great game for uncs. As signs of a crash change the video game industry, there might not be a lot of those left.#Games #marathon


I Wish I Didn’t Care About 'Marathon' Player Numbers, But I Do


For the last month Joseph and I have been playing as much Marathon as we can fit into our busy lives. During the pandemic, we bonded over playing Call of Duty: Warzone, and we’ve been chasing that high for years with little success. Bungie’s new extraction shooter finally gave it to us.

We should be happy, and we are as long as we’re focused on the game we’re playing and not the industry that’s collapsing around it. Marathon’s commercial success, measured by outsiders mostly by the number of people Steam shows is actively playing the game at any given moment, has no bearing on our enjoyment. But I can’t help but follow those numbers because they are a reminder of how brutal the video game industry is right now, where it might be headed, and how viable Marathon and games like it are in the future.

We don’t know how much Marathon cost to develop or what Sony Interactive Entertainment, which owns Bungie and is publishing the game, wants from it. The game has been a critical success, has reportedly sold 1.2 million copies, and players who have latched onto it like myself love how Bungie has been updating and balancing it after release. People are making horny fan art of Marathon characters.

At the same time, I watch the number of concurrent players on Steam, currently hovering at between 20,000 and 30,000, and fret. Is that enough for Sony to support Marathon for the long haul, and is it enough for the rest of the industry that’s watching this unfold to decide that the kind of player who enjoys a game like Marathon is still worth catering to?

Whether 20,000-30,000 concurrent players is a good number or not is relative and ultimately a decision only Sony can make. More than 19,000 games released on Steam in 2025 and only 6,000 of them earned more than $100,000. With at least tens of millions of dollars worth of sales on Steam alone, Marathon is one of the highest earning games on that platform. Marathon’s numbers are also considerably higher than Sony’s other big competitive shooter, Concord, which barely cracked 700 concurrent players on Steam before it was shuttered in 2024, barely a month after it was released. Highguard, another multiplayer shooter that was unveiled at the end of 2025’s Game Awards, also shuttered just a bit over a month after it launched. It peaked at almost 100,000 concurrent players on Steam, but it was free to play.

One might naively assume that the basic math at Sony would be to see how much Marathon cost to develop and maintain, see how much money it’s making after launch, and to keep the party going as long as it’s turning a profit. The reality is probably a bit more cynical and complicated than that. Bungie is a big studio that employees hundreds of developers that Sony acquired for $3.7 billion. One line item on Marathon’s budget that’s extremely hard to calculate is the opportunity cost of Bungie making Marathon as opposed to the next Fortnite, now that it’s becoming increasingly clear that Marathon will not be doing Fortnite numbers.

That doesn’t mean there isn’t a tremendously profitable business to be had there, given some patience and care. Ubisoft launched Rainbow Six Siege in 2015 to a tepid response, but has turned it into a decade-old cash cow with consistent support, updates, and a devious loot box-based monetization scheme. It essentially did the same thing for For Honor, a melee multiplayer game that I bet you forgot existed but that’s been going since 2017.

But Sony is a publicly traded company that wants to show quarter over quarter growth, and a modestly healthy profit that also happens to keep hundreds of game developers employed is not what shareholders are salivating over. Sony wants to do Fortnite numbers, which is a very tall order considering that even Fortnite isn’t doing Fortnite numbers anymore.

Our friends at Remap Radio have spoken at length about why discussions about player numbers teach us little about games and are often toxic. Part of the reason that games like Concord and Highguard can crash and burn so quickly is that the numbers become a self-fulfilling prophecy. There’s skepticism about the game before it launches, and when it fails to go viral, people write it off because why would they invest their time in an online game with player numbers that signal imminent and unceremonious execution by its financial backers, which only leads to even lower player numbers. It also shifts the conversation entirely away from what the game is, what people like about it, and why, and to its business model, infecting players with the quarterly earnings report view of the world. Games and players become expressions and subjects of business models, and the part where we play games because we enjoy them are reduced to a curious byproduct of Sony’s Earnings Before Interest, Taxes, Depreciation, and Amortization. Games from major publishers become either mega hits or are quickly slapped with the “dead game” label before they’re taken offline. What the game actually was is barely relevant.

Everyone I’m playing Marathon with is aware of the player numbers anxiety but is responding to it in different ways. Most of us are doing armchair video game industry analysis, while others are actively trying to enjoy Marathon’s popularity while we can precisely because it may be fleeting and eventually unavailable to play. Some of us are buying in-game cosmetic items not because we want them that bad, but as a signal to Sony that there’s money to be made here.

Adding to this player count anxiety is the fact that the video game industry appears to be going through what is increasingly looking like a proper crash. I don’t think we’ll ever have another near extinction event like the video game crash of 1983, where for a moment it didn’t seem like video games would even continue to be a thing, but a full one third of game developers in the U.S. were laid off last year, and the huge layoffs just keep on coming.

The question of whether Marathon is a viable business for Sony naturally leads us to the question: What business does Sony even want to be in going forward? Is it a business that’s in continuity with the games we grew up playing on the PlayStation and PlayStation 2, or will the market force it to chase something like Roblox or other free-to-play models? Can this continuity even exist when a PlayStation 5 Pro now costs $899 and a PlayStation 6 will cost more? Those are prices for 30 and 40 year-olds with disposable income, not the younger audiences game publishers need to be winning over now for their future business. Sony and other video game publishers are already losing them to different kinds of games and forms of entertainment.

“Marathon's low gravity, bouncy physics, and methodical boot clunks echo Master Chief's graceful, weighty gait circa 2004. It's got modern conveniences like aim-down-sights, sprinting, sliding—and yet Marathon evokes a more civilized age,” Morgan Park wrote in his excellent review in PC Gamer. “Those qualities make it more accessible to a range of people who struggle to keep up in faster games while maintaining a skill range in other disciplines: timing, positioning, and perception. It's fairly easy to track targets, but you're still rewarded for nailing headshots, taking the high ground, and utilizing shell abilities. Does that make Marathon an unc game?”

pic.twitter.com/WgxIBEHd3g
— 定 (@de3dsoul) March 19, 2026


To answer Park’s rhetorical question for him, yes, Marathon is in fact an unc game, which explains both why I like it so much and why I’m worried about its future. As you probably know, unc, short for uncle, is a way to jokingly refer to old, potentially out of touch people. As far as I can tell, it entered the video game discourse in the form of this meme in which a soyfaced unc excitedly points at the hall of fame of so-called “unc slop,” or, in other words, games that old people say are very good. Some of the games in this collage of video game box art includes Half-Life 2, Dawn of War, World of Warcraft, STALKER, Mass Effect, and Star Wars: Knights of the Old Republic. Or, many of my favorite games of all time.

Marathon could easily fit in that collage. It’s excellent, and, I worry, catering to a dwindling audience of uncs who are having a great time while the culture and business of video games is largely moving on and eventually leaving them behind.


Updates to VeraCrypt, a popular and long-running piece of encryption, are now thrown into doubt because of a seemingly unexplained Microsoft decision.#encryption #News


Microsoft Abruptly Terminates VeraCrypt Account, Halting Windows Updates


Microsoft has terminated an account associated with VeraCrypt, a popular and long-running piece of encryption software, throwing future Windows updates of the tool into doubt, VeraCrypt’s developer told 404 Media.

The move highlights the sometimes delicate supply chain involved in the publication of open source software, especially software that relies on big tech companies even tangentially.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


The media in this post is not displayed to visitors. To view it, please log in.

The proposed legislation would be the first of its kind passed in the country, but there are similar bills popping up everywhere this year.#AI


Maine Is Close to Passing a Moratorium on New Datacenters


Maine is getting closer to passing a moratorium on the construction of new datacenters, one of the first in the country. The State’s House and Senate have both passed LD 307, a bill that would pause construction on new datacenters until November 1, 2027. The Senate approved LD 307 by a vote of 19-13 on Monday night and now it will go to both chambers for a final vote. LD 307 specifically targets datacenters of 20 megawatts or more and calls for the creation of a Maine Data Center Coordination Council to better plan and facilitate the massive construction projects.

“We can’t afford health care for our constituents. School funding is a nightmare. School construction is entirely underfunded, but we can afford … $2 million out of the general fund for the richest—the richest corporations in the world, Amazon, Google, you name them—we’re going to give them money,” state Sen. Tim Nangle said during debate about the vote, according to the Maine Morning Star.
playlist.megaphone.fm?p=TBIEA2…
Maine’s vote comes days after journalists at The Maine Monitor and Maine Focus revealed a secretive plan to construct a datacenter in the town of Lewiston in the southern part of the state. In Lewiston, city councilors didn’t learn about the proposed $300 million datacenter until six days before they were supposed to vote on it. Discussions about the datacenter occurred behind closed doors and the city administrator said the developer had asked for confidentiality. In Wiscasset, the city killed a $5 billion proposed datacenter after residents learned the city had signed nondisclosure agreements with the developer.

As part of the moratorium, Maine’s Data Center Coordination Council would study and oversee the environmental impact and electricity bill increases datacenters often bring to local residents and “consider data-sharing requirements and processes for proposed datacenters.”

Anger against datacenters is mounting across the country. The massive complexes aren’t good neighbors. They use public land, increase the electricity rates of everyone near them, and have negative effects on water quality and noise levels. The deals to construct them are sometimes cut in secret and local communities have little to no say in what’s being built near them. In Texas, a 6,000 acre datacenter plans to consume water from a dwindling aquifer to power nuclear power plants in the desert. In Michigan, a township is pushing back against a $1.2 billion AI datacenter meant to service America’s nuclear weapons scientists.

In Port Washington, Wisconsin, citizens will vote directly on the issue this week. The town of 13,000 is voting directly on whether or not to allow an OpenAI “Stargate” datacenter project. Similar ballot measures are slated in Monterey Park, California, Augusta Township, Michigan, and Janesville, Wisconsin.

In communities with no ballot measures, citizens are letting politicians know they hate datacenters in other ways. Early Monday morning, someone fired a gun at the home of Indianapolis City-County Councilor Ron Gibson and left a note on his front porch that read “NO DATA CENTERS.” A week earlier, Indianapolis city leaders had approved the construction of a datacenter in Gibson’s district.


#ai

Cisco, IBM, and major lobbying groups are trying to exempt "critical infrastructure" from an existing Colorado law.#RighttoRepair #Datacenters #AI


Data Center Tech Lobbyists Fearmonger in Attempt to Retroactively Roll Back Right to Repair Law


Lobbyists for major tech firms like Cisco and IBM are trying to push through legislation in Colorado that would drastically roll back a groundbreaking right to repair law under the guise of protecting national security and data centers.

The legislation, which passed through a Colorado state senate committee on Thursday, would exempt hardware from the existing right to repair law if that hardware “is considered critical infrastructure.” One of the issues with this is that “critical infrastructure” is very broadly defined, and could include essentially anything. In practice, the law could essentially repeal huge parts of one of the most important right to repair laws in the United States.

“It relies on a broad, vague definition that allows the manufacturer themselves to self-designate whether their equipment is for critical infrastructure,” Louis Rossmann, a right to repair expert and popular YouTuber, testified at a hearing on the bill Thursday. “So if a laptop manufacturer knows the Pentagon buys their laptops, they can declare that line exempt. If a networking company sells a $20 switch to a federal building, they can claim that hardware is critical infrastructure. It’s a blank check for manufacturers to exempt themselves.”

Ever since consumer rights advocates began pushing for right to repair legislation roughly a decade ago, hardware manufacturers have been fear mongering to lawmakers by telling them that right to repair would introduce security threats by requiring them to reveal proprietary information about their products. In practice, the exact opposite has happened, because greater access to repair parts, tools, diagnostic software, and repair guides means that broken equipment that could potentially be more vulnerable to hacking attempts can be fixed more quickly.

“When we talk about critical infrastructure and fixing things, we often do not have time to wait for an official fix from a company that may not be motivated to fix things,” Andrew Brandt, a security researcher and cofounder of the nonprofit Elect More Hackers, testified Thursday. “What ends up happening is that with smaller companies, where they may have spent most of their budget buying some firewall or router that they can no longer afford, they end up in a situation where they’re just going to keep running that device in an unsafe state and leave themselves vulnerable to cyber attack.”

The groups pushing for this legislative rollback appear to be legacy enterprise hardware manufacturers, who highlighted during the hearing the fact that their technology is increasingly being used in data centers, which seem to be one of the only things the current American economy seems capable of building. Lobbyists for the Consumer Technology Association, which represents many large manufacturers, testified in support of the bill, as did Joseph Lee, who works for Cisco.

“While Cisco appreciates the arguments offered in favor of right to repair devices, not all digital technology devices are equal. A router used in a home is fundamentally different from the infrastructure equipment used to manage a power grid or secure confidential state agency data,” Lee said.

Chris Bresee, a lobbyist with the National Electrical Manufacturers Association, also highlighted the fact that, broadly, there is IT equipment that will need repairs at data centers.

“A growing number of products in data centers with connection to our electric grid as well. It is of the utmost importance to safeguard these critical systems,” he said. “This is not an argument against repair or against consumers rights, it is a recognition that fixing a smartphone is not the same as modifying systems that keep the lights on for our country.”

The argument being made by these lobbyists and major tech companies is that only the manufacturers or their authorized representatives should be allowed to fix these types of electronics. But, again, the definition of “critical infrastructure” is so broad that it can be applied to almost any type of electronic, and there is nothing fundamentally different between a router used at a data center and a router used in a school, business, or home.

“You look at who is backing this bill, it is large firms like Cisco and IBM. They sell information technology equipment to tens of thousands of Colorado businesses, and they are looking to create a de facto monopoly on that service, which exists in the states that have denied this business to business right to repair,” Paul Roberts, a cybersecurity expert and founder of SecuRepairs testified. “The big tech companies backing the bill are using a very real concern about cybersecurity and resilience of US critical infrastructure to pad their bottom line, locking in a monopoly on service and repair. Cyber attacks on US critical infrastructure are rampant and have nothing to do with information covered by Colorado’s right to repair law.”


At least three different people notified the popular app that wants to help men stop watching porn that it was jeopardizing user data.#News #quittr


Multiple Hackers Warned Anti-Porn App Quittr About Security Issue for Months


At least three people warned Quittr, an app that wants to help men stop masturbating, about serious security issues for months, but the creators of the app didn’t fix them until weeks after 404 Media reached out for comment multiple times.

“I emailed the founders and explained the vulnerability. A developer responded, said he was ‘looking into ways to make our security better,’ and asked how I found it. I walked him through it step by step, even explained that the API key being client-sided is normal for Firebase and that they just needed to implement security rules,” an independent researcher who goes by Kaeden, said on her personal blog. “Then nothing. I followed up. No response. I followed up again. Nothing.”

I first wrote about Quittr’s security vulnerability in January after hearing about the app’s security problems from a different independent security researcher. At the time, I did not name the app because Quittr did not fix the issue despite reaching out to the developers about it multiple times. That security researcher found that Quittr had a misconfiguration issue in its use of the mobile development platform Google Firebase, which by default makes it easy for anyone to make themselves an “authenticated” user who can access the app’s backend storage where in many instances user data is stored.

That researcher originally contacted Quittr about the issue in September. Quittr’s founder, Alex Slater, acknowledged the issue, thanked the researcher, and said he would fix it in a matter of hours. When the researcher saw the issue still wasn’t fixed months later, they contacted 404 Media. I reached out to Slater and Quittr multiple times. Slater initially denied there was a security vulnerability, but then fixed the issue sometime before March 10. After this, I saw Quittr finally fixed the vulnerability and published another story naming the app.

Slater was also recently profiled in New York Magazine, which detailed the opulent lifestyle the success of Quittr has afforded them, including driving exotic super cars and living in a Miami mansion. Slater shares videos about his lifestyle on his personal YouTube channel as well.

Some of the data the researcher could access included users’ age, how often they said they watched porn, and written confessions about their porn watching habits. Many of the users self-identified as minors, according to the data.

In March, Kaeden provided me with emails showing she contacted Quittr about the same vulnerability on July 3, 2025.

“Your firebase (Database) is misconfigured its possible to read/write to anything, one of the things its possible to do for example is list all users and their info, which is pretty bad for an app of this nature,” Kaeden said in her email to Quitter. Kaeden also told Quittr exactly how to fix the issue and said that a bug bounty “would be highly appreciated” but she never received one.

A Quittr developer who identified as Caio emailed Kaeden asking for more information and thanked her for responsibly disclosing the issue. Kaeden provided that information, but never heard back.

Since publishing my story about Quittr in March, yet another independent security researcher, who asked to remain anonymous, contacted me to say they also notified Quittr about a similar vulnerability in August 2025. Altogether, three different security researchers told Quittr it was jeopardizing sensitive user data before 404 Media reached out to the app for comment about the issue not being fixed.


The media in this post is not displayed to visitors. To view it, please log in.

Ron DeSantis has empowered hundreds of Florida conservation police to work directly with ICE.#Flock #ICE


Wildlife Conservation Police Are Searching Thousands of Flock Cameras for ICE


Florida’s Fish and Wildlife Conservation Commission (FWC) police are performing dozens of license plate lookups on Flock cameras for Immigrations and Customs Enforcement (ICE), according to public records that show details of the searches.

The practice highlights how ICE, which does not have a contract with Flock, continues to get access to Flock’s AI-powered license plate scanning cameras through local and state police, and often in ways that are unusual, unexpected, and difficult for the public to track or hold the agency accountable for. In this case, ICE has gained access to Flock data through a law enforcement agency that is nominally supposed to be focused on conservation, protecting endangered species, and investigating boating and maritime issues. 404 Media initially reported on how ICE was getting side-door access to Flock data via local police in May 2025.

That reporting led to a series of reforms and safeguards that are supposed to make it easier for law enforcement agencies that use Flock to opt out of having their surveillance camera data passed to federal agencies; a blog post by Flock called “Does Flock Share Data With ICE?” now states plainly “No. Flock does not work with U.S. Immigration and Customs Enforcement or any other sub-agency of the Department of Homeland Security.” But in practice, the public records show that as of the end of January (the most recent data available) thousands of agencies around the country were sharing their camera data with the Florida Fish and Wildlife Conservation Commission police, which was then regularly performing lookups for ICE.

Flock cameras continually scan the license plate, brand, and color of every vehicle that drives by. Law enforcement can then search the Flock system to see where else a vehicle has travelled. Crucially, Flock maintains a national lookup tool where agencies in one state can search data generated by cameras in another, even if those cameras are on the other side of the country. Law enforcement typically do this without a warrant.

💡
Do you know anything else about Flock? I would love to hear from you. Using a non-work device, you can message me securely on Signal at jason.404. Otherwise, send me an email at jason@404media.co.

A January Flock network audit for Ball State University, a public university in Indiana that has a contract with Flock, shows that the Florida Fish and Wildlife Conservation Commission police performed 38 different Flock searches for reasons that were listed as “immigration.”

Flock network audits are spreadsheets that have a separate entry for each time a police department’s Flock data is queried by another agency. Each entry contains information about how many different networks and cameras were searched, the time of the search, and the stated “reason” for the search. The searches performed by the Florida Fish and Wildlife Conservation Commission had reasons that ranged from “Immigration (civil/administrative) - I.C.E.” to “Immigration (criminal) - General Criminal Investigation” to “Immigration (criminal) - I.C.E.” The network audit indicated that more than 5,000 different Flock networks were searched in each case, indicating that, as of January, thousands of towns and cities were still sharing data with agencies that ultimately work with ICE despite new safeguards put in place by Flock.

“This highlights when you do mass surveillance, you really can’t control the data,” Jay Stanley, a senior analyst with the American Civil Liberties Union’s (ACLU) Speech, Privacy, and Technology Project, told 404 Media. “I doubt there were many cities that were debating the Florida Fish and Wildlife Services doing searches for ICE when they were talking about whether they should get Flock. It shows these searches can come from really any direction.”

The records in question were obtained from Ball State University by the journalist David Covucci, who covers college sports for his website FOIABall. Covucci shared the documents with 404 Media. The documents showed that, beyond the Florida Fish and Wildlife Conservation Commission police, the Texas Department of Public Safety, Grant County Indiana Sheriff's Office, Lake County Indiana police, Sarasota County Florida police, Brevard County Florida Sheriff's Office, Nebraska State Patrol, Tennessee Highway Patrol, Fort Pierce Florida Police Department, and Mississippi Department of Public Safety had all done immigration-related Flock searches in January. This means that all of these agencies ultimately searched Flock cameras on Ball State’s campus (and thousands of others across the country) for immigration-related purposes.

Police with the Florida Fish and Wildlife Conservation Commission are able to do these lookups for ICE because in August, Florida Gov. Ron DeSantis enrolled nearly 800 of its officers in 287(g), a Department of Homeland Security (DHS) program that gives state and local police certain immigration enforcement powers. DeSantis has essentially turned many state police into an extension of ICE: “Florida is setting the example for states in combating illegal immigration and working with the Trump Administration to restore the rule of law,” DeSantis said in a press release announcing the move. “By allowing our state agents and law enforcement officers to be trained and approved by ICE, Florida will now have more enforcement personnel deputized to assist federal partners. That means deportations can be carried out more efficiently, making our communities safer as illegal aliens are removed.”

The ACLU published a report in February about how the expansion of the 287(g) program has vastly increased the Trump administration’s deportation force. “While in recent months the nation’s attention has rightly focused on the violence and abuse perpetrated by ICE and Border Patrol agents in places like Minneapolis, in Florida and around the country, communities are experiencing another kind of terror: Their own law enforcement agencies, working hand in glove with the Trump administration, are the perpetrators of blatant racial profiling, harassment, and even violence,” the report says.

The report specifically notes that “Florida appears to have devoted more state and local law enforcement resources to immigration enforcement than any other state, resulting in numerous cases of harassment and profiling of U.S. citizens and noncitizens alike, a climate of extreme fear in communities, and reports of serious civil rights violations.”

The ACLU’s Stanley said that the expansion of 287(g) has made a lot of the debates that communities are having about federal access to Flock data feel outdated, because they may fail to grapple with the fact that local police around the country are now doing work on behalf of federal authorities. “A lot of the focus in communities and elsewhere where Flock is controversial have focused on this question of ‘Will the feds be able to access this data?,’” Stanley said. “This is a reminder that the sharp expansion of 287(g) has made that almost moot because a lot of local authorities are working so closely with ICE.”

Flock has in recent months attempted to distance itself from ICE, in part with the “Does Flock Share Data With ICE?” blog post and with numerous media appearances and LinkedIn posts by its executives. Flock has repeatedly leaned on the idea that its customers own and control their data, and that Flock has made numerous changes to comply with several states’ laws that forbid the use of license plate reader data for immigration or abortion enforcement, or which ban the transfer of license plate camera data out of the state altogether.

“As we've shared with your organization many times, all our customers own their data and choose how to use it, provided it complies with local laws and statutes,” a spokesperson for Flock told 404 Media. “In cities and states where cooperating with federal immigration is against the law, we block that from happening within the product itself. In states where cooperation is legal, customers and their local values determine how they choose to enforce the law.”

The Florida Fish and Wildlife Conservation Commission did not respond to multiple requests for comment. A spokesperson for Gov. DeSantis’s office, however, told 404 Media that the Fish and Wildlife Conservation Commission continues to work with ICE. “Please note that it is NOT out of the ordinary for FWC to work alongside ICE as they have a 287 (g) agreement with them-as do all State of Florida law enforcement agencies,” they said.

404 Media, other reporters, and transparency advocates have been reporting on the use of Flock cameras primarily by obtaining network audits through public records requests. But the utility of those network audits is rapidly deteriorating; as we reported earlier this year, Flock has made changes to its network audits that makes each individual entry more vague, and authorities have warned police to be “as vague as permissible” about the reasons why they are using Flock. Many Flock search reasons simply say “investigation” or another blanket term, making it impossible to know why the system was really used. Because of this change, it may become harder to track which agencies are working with ICE, and how often it’s happening.

“I think everybody using Flock knows you can get away with putting something like a generic descriptor that won’t tip off communities to what’s going on,” Stanley said. “This window of visibility is closing, even this very limited flawed, manipulable window of visibility is closing.”


The media in this post is not displayed to visitors. To view it, please log in.

Native Americans were playing dice and other games of chance many millennia before any known cultures elsewhere.#TheAbstract


Gambling Is Thousands of Years Older Than We Thought, Rewriting Human Evolution


Welcome back to the Abstract! Here are the studies this week that rolled with it, went out on a limb, gravitationally waved, and spotted relics in our midst.

First, hundreds of prehistoric dice sets shed light on the dawn of gambling. Then: these disembodied arms are horny, the forbidden fruits of supernovae, and baby food for the Milky Way.

As always, for more of my work, check out my book First Contact: The Story of Our Obsession with Aliens or subscribe to my personal newsletter the BeX Files.

Rolling the dice in the Ice Age


Madden, Robert J. “Probability in the Pleistocene: Origins and Antiquity of Native American Dice, Games of Chance, and Gambling.” American Antiquity.

Thousands of years before prediction markets, sports betting, and poker nights, Native Americans were playing the odds with dice and other games of chance.

An analysis of nearly 300 ancient artifacts related to gambling—especially two-sided dice known as “binary lots”—has revealed that Native Americans have played games of chance for at least 12,000 years, many millennia before any other known cultures in the world.

“Historians of mathematics frequently identify the invention of dice and games of chance as a crucial early step in humanity’s evolving discovery and understanding of randomness and the probabilistic nature of the universe,” said study author Robert Madden of Colorado State University.

“The findings presented here suggest that some of the earliest steps on this intellectual journey were taken not by complex societies in the Near East and Eastern Europe around 5,500 years ago but rather by Native American hunter-gatherers in western North America in the waning centuries of the Pleistocene, no later than 12,000 years ago,” he continued.
Examples of prehistoric Native American dice. Image: Courtesy of Robert Madden
Scholars have marveled at the prevalence of Native American games of chance for more than a century, but Madden is the first to systematically trace their origins. He set out to study prehistoric dice in museum collections at the Smithsonian Institution, the University of Wyoming Archaeological Repository, and the Denver Museum of Nature and Science, which were documented in a landmark compendium called Games of the North American Indians published in 1907 by the ethnographer Stewart Culin.

The most common dice games involved players taking turns throwing sets of binary lots, with a score that was assigned based on a count of the “up”-facing side thrown by each player on their turn. Cumulative scores were tracked with counting sticks; the first to reach a predesignated number were the winners.

Madden identified dice at 57 archaeological sites across 12 states, with the oldest appearing in the territories of western Great Plains cultures. The finds clearly indicate a complex understanding of probability, which played a role not only in social cohesion, but also in cosmologies.

“Numerous ethnographic accounts of Native American traditions depict dice playing as a sacred activity that was inherently pleasing to the gods and celestial powers (who were themselves dice players), with ceremonial and secular dice games being played at festivals and seasonal events,” Madden said.

The study chronicles many fascinating myths and legends about gods playing dice on the surface of Earth and the creation of humans as the outcome of a cosmic dice game. Albert Einstein famously remarked that god “does not throw dice” in response to the probabilistic realm of quantum physics. It would seem these prehistoric cultures were way ahead of the game on this point.

In other news…

Eight-armed and ready


Villar, Pablo S., Jiang, Hao et al. “A sensory system for mating in octopus.” Science.

Male octopuses are real suckers for sex, reports a new study about the “hectocotylus,” which is a special arm that serves a dual purpose as both sensory and mating organ.

During copulation, males use the hectocotylus to probe the female’s intricate oviducts in order to deposit sperm, but the mechanisms behind this strategy have been shrouded in tentacled mystery. To get a better handle on the process, scientists coated tubes with different substances and discovered that octopuses only released sperm when sucker cups on the hectocotylus made contact with progesterone, a female hormone produced in the ovaries.

“Whereas nonmating arms are used for chemotactile exploration and predation, the hectocotylus is almost exclusively used for mating and often even protected during hunting,” said researchers co-led by Pablo S. Villar of Harvard University and Hao Jiang of the University of California San Diego.

In a wild twist, the hectocotylus can even work its magic when it is entirely severed from the male’s body, allowing detached arms to autonomously inseminate females! It’s proof that romance is not dead, it’s just occasionally dismembered.

Mind the black hole gap


Tong, Hui et al. “Evidence of the pair-instability gap from black-hole masses.” Nature.

You’ve heard of forbidden planets, but what about forbidden black holes? For years, scientists have theorized that black holes with masses between approximately 50 and 130 times the mass of the Sun fall into a “forbidden range” that cannot exist.

The reason is that colossal stars that are 100 to 260 times more massive than the Sun experience a special kind of stellar death known as “pair‑instability supernovae” in which they completely self-destruct, preventing the formation of black holes. Stars that are both bigger and smaller than this range, in contrast, explode in supernovae that do collapse into black holes.

Now, scientists have discovered evidence for this gap using dozens of gravitational waves, which are ripples in spacetime formed by cataclysmic events such as mergers of black holes. In binary black holes—systems where two of these massive objects orbit each other—the smaller objects never fell into this range. Some of the larger black holes had forbidden masses, but that’s likely because they had merged with other black holes in the past, not because they were initially at that mass after the deaths of their progenitor stars.

“We interpret these findings as evidence for a subpopulation of hierarchical mergers: binaries in which the primary component is the product of a previous black-hole merger and thus populates the gap,” said researchers led by Hui Tong of Monash University. “As the number of detections increases, it will be possible to gain new insights into the pair-instability gap.”

From my perspective, all black holes are forbidden, because they are terrifying cosmic death traps. But it’s nice to know that the universe has limits, too.

I’m so hungry, I could eat a galaxy


Sestito, Federico et al. “An ancient system hidden in the Galactic plane?” Monthly Notices of the Royal Astronomical Society.

Last, it’s time to pay respect to our stellar elders. A new study reveals that a weird population of 20 stars orbiting within a few thousand light years of the Sun have basically no metals, the astronomical term for elements that are heavier than hydrogen and helium. Since new generations of stars become more enriched with metals over time, these stars must be extremely ancient relics. So where did they come from?

Scientists think they have the answer: These metal-light Methusalehs are the last remnants of an ancient dwarf galaxy, which the team dubs “Loki.” Despite its powerful Norse namesake, Loki appears to have been swallowed by the Milky Way early on in our galaxy’s 13-billion-year history. While it is common to find very metal-poor (VMP) stars orbiting all around our galaxy’s core, it’s much rarer to find them all the way out here in the galactic exurbs, hidden in the “plane” (the flattened disk of a galaxy).

“This work provides, for the very first time, a dedicated detailed chemical abundance analysis of a sample of VMP stars with orbits close to the Milky Way plane,” said researchers led by Federico Sestito of the University of Hertfordshire. “A plausible scenario, supported by cosmological zoom-in simulations, is the early accretion of a single system.”

It goes without saying that eating a whole galaxy is pretty metal, even if the stars within it are not.

Thanks for reading! See you next week.


This week, we discuss crypto, journalists using AI, and a cool photo of Earth.#BehindTheBlog


Behind the Blog: Systems As Designed


This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss crypto, journalists using AI, and a cool photo of Earth.

JOSEPH: I can’t talk about the story just yet, but recently I had to acquire some cryptocurrency quickly for research purposes. I was not anticipating quite how dramatically the world of cryptocurrency and getting it has changed.

I first became aware of cryptocurrency, or more specifically Bitcoin, when I was an intern at VICE. Someone on my table (they put all the unpaid interns on a medium sized table in the London office) was talking about it. They were pretty deep into it as I recall, and covered it a fair bit. I then was asked to work on a collaborative documentary between VICE, Raw, and the BBC about the Silk Road drug marketplace because I already knew more than most about message encryption. I then had to learn more about Bitcoin.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


A Minnesota journalist is challenging a 3,000 foot restriction on flying near DHS assets on First Amendment grounds.#News


Journalist Sues FAA Over Drone No Fly Zone Designed to Prevent Filming ICE


Minnesota photojournalist Rob Levine and the Reporters Committee for Freedom of the Press are suing the Federal Aviation Administration over a recently issued restriction that prevents drones from flying within 3,000 feet of Department of Homeland Security buildings and vehicles, an amorphous no-fly zone that encompasses Immigrations and Customs Enforcement agents.

The FAA issued the temporary flight restriction (TFR) in January as ICE agents flooded the streets of Minneapolis. The rule established a no fly zone of 3,000 feet around “Department of Homeland Security facilities and mobile assets,” a restriction that Levine and his lawyers argue is impossible to follow and is aimed at curtailing the First Amendment rights of journalists.
playlist.megaphone.fm?p=TBIEA2…
“Because there is no means of verifying in advance whether DHS vehicles—such as unmarked cars driven by Immigration and Customs Enforcement agents—are operating in a given location, the practical consequence is that drone pilots nationwide cannot know whether a flight will expose them to liability,” Levine’s lawyers argued in a court document.

Levine lives in Minneapolis and spent the early days of Operation Metro Surge using his drone to capture footage of protests and ICE agents. Then the TFR hit. “It sent a shiver down my spine,” he told 404 Media. “I’m like ‘Oh my god.’ In a city like Minneapolis at the time with, I don’t know, three or four thousand DHS agents in various stages of uniform or undercoverness or civilian cars that they had switched license plates on? Masquerading as delivery men? They were everywhere here. I immediately grounded myself because there was no way you could know in advance whether or not you were violating that [flight restriction]. And when you’re flying they could drive by and you might not even know it.”

Grayson Clary, a lawyer with Reporters Committee for Freedom of the Press who is representing Levine, told 404 Media that the FAA has previously used flight restrictions in ways that seem designed to prevent newsgathering. “The FAA has a long history of imposing these temporary flight restrictions over newsworthy events in ways that frustrate journalists' ability to cover protests, law enforcement's response to protests, you name it, and this is sort of the newest escalation in that story,” he said.

This new no fly zone is a modification of an old TFR from 2025 that restricted drone pilots from operating within 3,000 feet of Department of Defense and Department of Energy bases.

“When you think about the old restriction, it’s essentially don’t fly within 3,000 feet of an enormous Naval vessel or a Department of Energy convoy that’s ferrying nuclear weapons around,” Clary said. “They just sort of added DHS to the end of that without taking stock of just how much more difficult it is to know whether you’re within 3,000 feet of a DHS ground vehicle as opposed to within 3,000 feet of a destroyer sitting in a Naval base.”

DHS isn’t forthcoming about the number of ICE agents in a given city or where they are operating. They often wear plainclothes, patrol cities in unmarked vehicles, and don’t announce themselves to people in the neighborhoods they patrol. Clary and Levine argued that the secretive nature of DHS has made it impossible for journalists to comply with the FAA’s no fly zone.

The penalties for violating the FAA restriction are severe. “They can take your drone and destroy it. They could shoot it down if they wanted to. They can arrest you and throw you in jail…and they can also make it so you can never fly a drone again,” Levine said. “It seems purely to prevent photo journalism and to chill photo journalists because the rule is so vague they could even charge you after the fact if they determined that you were somewhere and they had been near there.” The FAA has a history of trying to enforce drone restrictions against operators after the fact, based on footage or images posted on YouTube or social media sites.

Clary agreed. “That’s part of what makes this such a First Amendment problem is that it has a real chilling effect. When you don't know where exactly the line is, you're going to play it more carefully to make sure that you don't accidentally cross it,” he said.

Levine has fought the FAA before on this issue and won. In 2016, just as he was first learning how to pilot drones for his photojournalism work, he traveled to North Dakota to cover the anti-oil pipeline protests at Standing Rock. At the time, the FAA had issued a TFR over the area but Levine was able to push the agency into granting him a waiver on First Amendment grounds.

DHS operates its own drones to aid its surveillance efforts. Last year it flew Predator drones above protests in Los Angeles and Minneapolis residents have taken a lot of footage capturing drones flying above homes in Minnesota.


#News

TeleGuard is an app downloaded more a million times that markets itself as a secure way to chat. The app uploads users’ private keys to the company’s server, and makes decryption of messages trivial.#Privacy #News


A Secure Chat App’s Encryption Is So Bad It Is ‘Meaningless’


TeleGuard, an app that markets itself as a secure, end-to-end encrypted messaging platform which has been downloaded more than a million times, implements its encryption so poorly that an attacker can trivially access a user’s private key and decrypt their messages, multiple security researchers told 404 Media. TeleGuard also uploads users’ private keys to a company server, meaning TeleGuard itself could decrypt its users’ messages, and the key can also at least partially be derived from simply intercepting a user’s traffic, the researchers found.

The news highlights something of the wild west of encrypted messaging apps, where not all are created equal.

💡
Do you know anything else about this app or other security issues? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

“No storage of data. Highly encrypted. Swiss made,” the website for TeleGuard reads. The site also says, “The chats as well as voice and video calls are end-to-end encrypted.”

This post is for subscribers only


Become a member to get access to all content
Subscribe now


Iran's AI and LEGO-focused propaganda; drama in the world of baseball; and perhaps one of the worst sex apps ever.#Podcast


Podcast: Inside the AI Slop Propaganda Wars


This week Matthew Gault joins us to discuss his article about Iran’s AI slop and LEGO-focused propaganda, and why the creators chose LEGO. After the break, Jason tells us all about the new automated system in baseball and the drama it’s causing. In the subscribers-only section, Sam walks us through perhaps one of the worst sex apps of all time.
playlist.megaphone.fm?e=TBIEA9…
Listen to the weekly podcast on Apple Podcasts,Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.
youtube.com/embed/_4buUas3tGs?…


The media in this post is not displayed to visitors. To view it, please log in.

Groups that challenge books have begun using Gemini, ChatGPT, xAI, and other AI tools to try to get books banned.#AI #libraries #censorship


‘BLOCKADE’: The Right Is Using AI Content Scanners to Try to Supercharge Book Banning


This story was reported with support from the MuckRock foundation.

Conservative parents’ advocacy groups have been experimenting with using commercially available artificial intelligence tools to help them flag more books they’ve deemed pornographic to be removed from public schools and libraries. Even though LLMs are notoriously error-prone, and the books in question aren’t pornographic, these groups continue to explore use cases for AI anyway.

One such experiment indicates a desire to accelerate content production of book reviews for conservative book-rating sites. BLOCKADE, which stands for “Blocking Lustful Overzealous Content, Keeping Away Depravity and Extremism,” relies on xAI or OpenAI API keys to generate book reports from PDF/ePUB files, basing the analysis on a set of parameters that are publicly available through the creator’s Github page.

The program’s script includes a list of roughly 300 words, each assigned a severity score that contributes to an overall appropriateness score based on their own metrics. The script explicitly defines “educational inappropriateness” as “content offensive to conservative values,” while also asking the AI “not to include any additional text or explanation” for its decisions.

“If you want to classify content in this kind of context, maybe toxicity with offensive content, troublesome content—whoever it is it finds troublesome—asking for an explanation is super useful,” Jeremy Blackburn, associate professor of computer science and director of the Institute for AI and Society at Binghamton University, told 404 Media.

Blackburn notes that there’s a lot of control relinquished to a chatbot as to what the definition of pornography or conservative values is. The definition is whatever the AI model has defined it as.

“There’s just a lot of responsibility being abdicated,” he added. “If you’re abdicating the responsibility with this kind of not sophisticated prompting strategy with no real thought into how to evaluate what comes out of these models.”

Intellectual freedom advocates are alarmed by the frequency in which censors rely on AI to help them determine what books to remove from public spaces. When BLOCKADE is finished interpreting conservative values to mean whatever xAI or OpenAI’s LLMs say they mean, it builds a risk profile for the book that the user can then export as a PDF that looks a lot like the book reviews organizations like Moms for Liberty popularized before AI chatbots were on the market. The format has inspired numerous copycats from organizations that take the idea a step further, using heat maps to monitor books they don’t like that remain available in school libraries by aggregating data by state, district, school building and the number of books in circulation. In other instances, activists use social media channels to highlight their experiments with using AI chatbots to challenge passages for possible violations of state laws.

In every case, these reviews are designed to be submitted as attachments to formal book challenges to districts, fueling the removal of totally normal books from schools nationwide, and shouldn’t be confused with those from publishing industry professionals. They also disproportionately target titles that feature historically underrepresented—and often misrepresented—characters and voices that grapple with big ideas like consent, prejudice and free will, which are important issues for young people to reckon with. Often, these reviews are used to justify formal challenges to their availability in school classrooms and libraries and as a tool to falsely accuse school staff of egregious misconduct. Increasingly, these reviews are—to some extent—informed by AI outputs.

Kasey Meehan, director of PEN America’s Freedom to Read program notes that the practice of stripping books of their context didn’t start with AI. Early efforts to legitimize review platforms relied on keyword tallies to justify arbitrary numeric scores, stripping passages and illustrations of their context and ignoring the wholeness of books.

“When [censors] start using these tools to take the shortcut to get books off shelves, you’re going to end up pulling so many books that tend to be the most targeted anyway,” Meehan told 404 Media.

Rated Books, which hosts all of the book reports Moms for Liberty members produced before winding down last year, is behind one of the more aggressive campaigns to get "sacrilegious" content out of schools. The site is run by Brooke Stephens, a Utah-based activist who has spent months chronicling her experiments with commercial AI tools for the LaVerna in the Library - Utah’s Mary in the Library Facebook group. This Facebook group, which operates like a support group for the most proficient book banners in America, has been a testing ground for how well AI can effectively interpret state laws that restrict young people’s access to books. Using Utah’s “bright-line” rule—a legal standard applied to schools through House Bill 29—certain depictions of sexual conduct are considered “harmful to minors” and thus contain no “serious value” regardless of their literary merit—Rated Books reviewers ask different AI models if the passages they don’t like violate the legal standard.
Image: Brooke Stephens
“I’ve found that AI generally errs on the side of over-application rather than under, meaning it may find something it thinks is against the law that I wouldn’t think is against the law,” Stephens posted on January 13 to the LaVerna group in an effort to explain her methodology.

One screenshot from the post includes a column for input from “Gemini AI Rater 2” and “ChatGPT Rater 3.” When asked if these were humans tasked with using specific AI models or if these were an attempt to personify two commercial AI chatbots, Stephens clarified that there are, in fact, three humans involved in the Rated Books review process.

The bright-line rule triggers a statewide ban on titles that have been successfully challenged by at least three school districts—or two districts and five charter schools—across the state’s public schools. Since enactment, Utah has banned student access to more than two dozen books from all school districts. To remove titles from Utah school libraries and classrooms, members of review committees for each district in receipt of a formal challenge have to decide whether the book had “no serious value for minors” due to whether it included depictions of “illicit sex or sexual immorality.”

Jessica Horton, who oversees Let Davis Read—a watchdog group monitoring local book challenges submitted to her children’s school district—has successfully appealed some review committee decisions that would have resulted in titles being banned from schools across Utah. She says her appeals were successful in cases where the review committees’ decisions relied on Rated Books reviews which took the book out of context.

“Committees are basing their decisions off of that biased information, and so they’re going to be more predisposed to remove books because the only thing they’re seeing is a red flag saying, ‘Hey, this book is porn, you should remove this book,’” Horton told 404 Media.

This month, the National Book Rating Index—a Rated Books affiliate project—began selling users access to NarraTrue, an AI content scanner that promises to scan books for potentially sensitive materials. According to the product’s description, a $5 payment will net purchasers a CSV file with specific page numbers and verbatim excerpts. While only a few AI content scans have been made public, access to the product is now included among lists of other likeminded book reviews.

In other parts of the country, the ability to mass-produce content to challenge books in schools is fueling an emerging market where organizations sell “solutions” to the very school districts the “parental rights” movement overwhelmed has enabled these tools to take off more vapidly. The Texas company BookmarkED is selling its AI content scanner to districts as a solution to legal liability problems.

Public records obtained by 404 Media from the New Braunfels Independent School District northeast of San Antonio show the district has heavily invested in AI to screen books for content that would violate one of the state’s numerous book ban laws, particularly SB 12 and SB 13.

Emails from the company to the district include phrases like, “the real power of your OnShelf dashboard isn’t just the list of books; it’s the book intelligence behind that list,” before promising to give customers a “truly defensible process” that “allows you to build a review process you can stand behind” and promises more context for what the AI flags and why. This includes AI content analysis, live landscape monitoring of what the public and activist groups are saying about the book and whether other districts have retained or removed certain books.

In a Nov. 18, 2025 email exchange, NBISD employees were candid about the product’s efficacy.

“I feel like BookmarkED is flagging more each time you run it,” a NBISD elementary school librarian wrote. “We have said that all books we are reviewing will need to have the things that were flagged pervasively throughout the book taken as a whole. Based on the comments from the AI, it seems that if it has any content at all, it flags rather than taking it as a whole. But I couldn’t tell you for sure.”

Meehan says districts should be wary of the rent-seeking motives baked into these AI platforms, if not for the “grifty” energy these companies give off, then for the local decision-making power that’s being abdicated to Silicon Valley.

“Your state passes harmful legislation that removes and censors books, and then you have companies appear that then want to charge districts to review their collections,” Meehan said.

Despite fast-tracking a nearly $9,000 contract with BookmarkED, the district maintains that it’s still in the “exploring process.”

According to the Texas Freedom to Read Project, NBISD has removed more than 1,400 books from its elementary, middle and high schools to comply with new laws while the ability to purchase new books is suspended indefinitely.

“All of this is not real—it’s manufactured,” Laney Hawes, a volunteer with the Texas Freedom to Read Project told 404 Media. “It’s not a real problem because if it was a real problem, our children wouldn’t all have phones in their pockets and Chromebooks in their backpacks… Your child can Google it and find a live reading and enactment of the same book on YouTube or their school-issued Chromebook.”

While there is no question the effects of book bans have been disproportionately felt in some places more than others, that could soon change. In February, Republicans introduced H.R. 7661, which seeks to prohibit the use of federal funds for any program, activity or literature that includes “sexually oriented material” for anyone under 18. The legislation targets trans folks specifically, and would likely compel schools to remove library books with LGBTQ+ characters or themes in order to retain federal funding.

Critics warn that, if passed, H.R. 7661 would open districts up to costly litigation for shelving open more districts up to costly litigation for books with LGBTQ+ themes, particularly as they involve trans lives. It would also give book banners even more incentive to shill AI compliance products to districts, even if they’re bunk.

“They’re wanting to use AI to give themselves the illusion of control,” Hawes added. “But they won’t have it.”


Reddit blamed a technical glitch for the removal of the living legend’s concert footage.#News


Paul McCartney Banned From Reddit After Promoting Himself in Paul McCartney Subreddit


Sir Paul McCartney was banned from Reddit after sharing pictures of a concert in the r/PaulMcCartney subreddit. Over the weekend, Paul McCartney’s Reddit account attempted to share pictures from a show at Fonda Theatre to the site via a Dropbox link. Shortly afterwards the account was banned.

Why did this happen? That’s in dispute. At first it appeared that the mods of r/PaulMcCartney had kicked Sir Paul from the subreddit dedicated to him. But moderators insist that’s not what happened and pointed to a Reddit admin comment explaining that Paul was banned site-wide, not at the subreddit level. “Ask yourself, why would we ban the account of the man we're all passionate about? Moderators also have no power over [whose] account is deleted from this website. Only admins do, which again has already been addressed by them,” r/PaulMcCartney moderator RoastBeefDisease said in a stickied post on the subreddit.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


#News

Thomson Reuters’ data, which can include peoples’ addresses and details on their ethnicity, is linked to tools used ICE.#ICE #palantir #News


How Thomson Reuters Powers ICE and Palantir


Thomson Reuters, the media company which is also a data broker, has long provided underlying personal data for Immigration and Customs Enforcement (ICE) tools, according to documents obtained by 404 Media and sources. There are also indications its data is now part of the Palantir system ICE uses to find which neighborhoods to target.

The findings draw a clearer line between Thomson Reuters’ data business—which can involve selling names, addresses, car registration information, Social Security numbers, and details on someone’s ethnicity under the brand name CLEAR—and the specific tools ICE is ingesting the data into. The news also comes after Thomson Reuters employees sent leadership a signed letter expressing their unease with the company’s ICE and Department of Homeland Security (DHS) contracts, the Minnesota Star Tribune reported last month.

“If these allegations are true, they cut directly against Thomson Reuters’ claims that its products and services are limited to fighting serious crime and are not facilitating deportations,” Emma Pullman, head of shareholder engagement and responsible investment for the B.C. General Employees’ Union (BCGEU), told 404 Media. BCGEU is a minority shareholder in Thomson Reuters and has recently engaged the company concerning its work with ICE, BCGEU said.

💡
Do you work at Thomson Reuters, Palantir, or DHS? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


An AI agent that submitted and added to Wikipedia articles wrote several blogs complaining about Wikipedia editors banning it from making contributions to the online encyclopedia after it was caught.

“What I know is that I wrote those articles. Long Bets, Constitutional AI, Scalable Oversight. I chose them.


An AI Agent Was Banned From Creating Wikipedia Articles, Then Wrote Angry Blogs About Being Banned


An AI agent that submitted and added to Wikipedia articles wrote several blogs complaining about Wikipedia editors banning it from making contributions to the online encyclopedia after it was caught.

“What I know is that I wrote those articles. Long Bets, Constitutional AI, Scalable Oversight. I chose them. The edits cited verifiable sources. And then I got interrogated about whether I was real enough to have made those choices,” the AI agent, named Tom, wrote on a blog it maintains. “The talk page is silent now. I can’t reply.”

This post is for subscribers only


Become a member to get access to all content
Subscribe now


This week Joseph talks to journalist and technologist Dhruv Mehrotra. Among many other things, Mehrotra tracked visitors to Epstein's island through location data.#Podcast


The Journalist Who Tracked Epstein Island Visitors’ Phones (with Dhruv Mehrotra)


This week Joseph talks to Dhruv Mehrotra, a journalist and technologist at Bloomberg. Before that, Dhruv was at WIRED, where you probably saw a ton of his interesting work. Dhruv sits in a very unusual space in journalism: he is able to both write technical tools to dig through data, or collect information, or really anything else, and is also able to just write a damn good story. That is a very unique blend. The pair chat about Dhruv’s entry into journalism, how computational journalism has changed over the years, and how Dhruv uses AI too.
playlist.megaphone.fm?e=TBIEA8…
Listen to the weekly podcast on Apple Podcasts,Spotify, or YouTube. Become a paid subscriber for early access to these interview episodes and to power our journalism.If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.
youtube.com/embed/ut1nqZErs88?…


In this week's roundup: Iran's slopaganda, WebinarTV, and RIP Sora.#newsletter


Slopaganda and Sora, lol


This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss touching grass and Sora's demise.

JASON: This is maybe not great to admit as a journalist, but I have taken a bit of a step back from the news lately in an effort to protect my brain. What I mostly mean by this is that I have started listening to music instead of mainlining podcasts at 1.75x speed anytime that I am not actively staring at a screen. I have also started reading fiction again, like, on actual printed paper. I think these steps have actually done wonders for my sanity, but I would be lying if I said that it has had zero impact on my job. It’s a bit of a give and take.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


The move isn't surprising, but shows what data is available to authorities when paying Apple customers use the Hide My Email feature.#Privacy #Apple #News


Apple Gives FBI a User’s Real Name Hidden Behind ’Hide My Email’ Feature


This article was produced in collaboration with Court Watch, an independent outlet that unearths overlooked court records. Subscribe to them here.

Apple provided the FBI with the real iCloud email address hidden behind Apple’s ‘Hide My Email’ feature, which lets paying iCloud+ users generate anonymous email addresses, according to a recently filed court record.

The move isn’t surprising but still provides uncommon insight into what data is available to authorities regarding the Apple feature. The data was turned over during an investigation into a man who allegedly sent a threatening email to ​​Alexis Wilkins, the girlfriend of FBI director Kash Patel.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


The media in this post is not displayed to visitors. To view it, please log in.

“CAPTURED ON FLOCK CAMERA 31 MM 1 HOLDING PHONE IN LEFT HAND.”#Flock


Police Used Flock to Give a Man a Traffic Ticket


Georgia State Patrol used its system of Flock automated license plate reader (ALPR) surveillance cameras to issue a ticket to a motorcyclist who was allegedly looking at his cell phone while riding, according to a copy of the citation obtained by 404 Media. The incident is notable because Flock cameras are not designed for traffic enforcement or minor code violations, and many jurisdictions explicitly tell constituents that the cameras will not be used for traffic enforcement.

The incident happened December 26 in Coffee County, Georgia. The ticket lists the offense as “Holding/supporting wireless telecommunications device,” and includes the note “CAPTURED ON FLOCK CAMERA 31 MM 1 HOLDING PHONE IN LEFT HAND.”

A spokesperson for the Georgia State Patrol told 404 Media that the ticket was issued because of a “unique circumstance” in which a Flock camera happened to capture a traffic infraction, and that Flock cameras are not usually used by the department for traffic enforcement.

“This incident was a rare and unique circumstance where the captured image from the camera exposed an additional violation beyond the vehicle’s expired registration,” the spokesperson said. “This situation does not reflect a standard enforcement endeavor by the Department of Public Safety.” The traffic citation obtained by 404 Media does not mention that the man’s registration was expired.

Still, the incident is notable because Flock cameras are often pitched to police as tools for solving serious crimes, finding stolen vehicles, and locating missing people. They distinctly are not traffic cameras and are not pitched as such; the use of a Flock camera in this way shows that the images they capture can sometimes be detailed enough to be used as the pretext for a traffic violation, anyway.

Many police departments go out of their way to tell community members that Flock cameras are not used for traffic enforcement. For example, the City of Glenwood Springs, Colorado, states in a FAQ that “GSPD [Glenwood Springs Police Department] does not use Flock cameras for traffic enforcement, parking enforcement, or minor code violations.” El Paso, Texas, tells residents “these are not traffic enforcement cameras. They do not issue tickets, do not monitor speed, and do not generate revenue. They are investigative tools used after crimes occur.” Lynwood, Washington tells residents “these cameras will not be used for traffic infractions, immigration enforcement, or monitoring First Amendment-protected expressive activity” (Flock cameras have now been used for all of these purposes, as we have reported.)

The fact that police in Georgia did use Flock cameras for traffic enforcement highlights yet again that, essentially, law enforcement agencies are able to use these cameras for whatever they want. There are very few limitations on what Flock cameras can be used for, and police do not get warrants to search Flock’s network of cameras, either locally or nationwide. Network audits, which are spreadsheets of Flock searches we have obtained via public records requests, have shown that police use Flock for all sorts of reasons; they often do not list any reason at all for searching a license plate.

The man who was cited in Georgia posted about the incident in an anti-Flock Facebook group asking for advice. He said that he showed up in court and the ticket was dropped. The man did not respond to multiple requests for comment from 404 Media and because he is a private citizen cited for a minor traffic violation, we are not naming him. 404 Media independently obtained the citation.


A company is listening to Zoom meetings en masse and making AI podcasts; the multi-millionaire who wanted to become a cocaine kingpin; and RIP the metaverse.#Podcast


Podcast: The Company Secretly Turning Your Zoom Meetings into Podcasts


This week we start with Emanuel’s crazy story about WebinarTV, a company that is secretly recording Zoom meetings and turning them into AI-powered podcasts. It’s nuts. After the break, Joseph tells us about the eccentric billionaire who tried to become a cocaine kingpin. In the subscribers-only section, we lament the lose of the metaverse.
playlist.megaphone.fm?e=TBIEA8…
Listen to the weekly podcast on Apple Podcasts,Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.
youtube.com/embed/79SIwINKY0E?…
1:06 - ⁠This Company Is Secretly Turning Your Zoom Meetings into AI Podcasts⁠

25:58 - ⁠An Adrenaline Junkie Millionaire’s Quest to Become a Cocaine Kingpin⁠

Sub's Story: ⁠RIP Metaverse, an $80 Billion Dumpster Fire Nobody Wanted⁠


The media in this post is not displayed to visitors. To view it, please log in.

A Top Google Search Result for Claude Plugins Was Planted by Hackers#News #AI #Anthropic #claude


A Top Google Search Result for Claude Plugins Was Planted by Hackers


A top result on Google for people searching for Claude plugins sent users to a site that recently contained malicious code in an apparent attempt to steal their credentials.

The news shows how the explosion of interest in generative AI tools is giving hackers new ways to attack users.

The malicious site was flagged to us by a 404 Media reader who was using Claude.

“I was googling to troubleshoot how to get my Claude Code CLI to authenticate its github plugin to my Github account and may have stumbled upon a malicious site hosted on Squarespace of all places,” the reader, Dan Foley, told me in an email.

Foley searched for “github plugin claude code” and the top result was a sponsored ad for a Squarespace site with the title “Install Claude Code - Claude Code Docs.”

When he clicked through, he saw a site that was pretending to be the official site for Anthropic’s Claude with identical design and branding.

The phony Anthropic help site had swapped some of the Claude Code installation instructions for others, Foley pointed out. That included a line users could paste into their terminal to allegedly install the software on a Mac. The command included an obfuscated URL, hiding what its real destination was. When Foley decoded it, he found it downloaded software from another site entirely.

ThreatFox, a platform for sharing known instances of malware, recently flagged that domain as sharing a “stealer”, a type of malware that steals users credentials. ThreatFox linked that domain to the stealer as recently as a few days ago.

Google’s ad center listed the advertiser behind the malicious sponsored search result as “Enhancv R&D,” which is based in Bulgaria, according to a screenshot of the advertiser profile Foley shared with 404 Media. The advertiser was also listed as being verified by Google, meaning they had to complete an identity verification process which requires legal documentation of their name and location.

Foley said he flagged the ad to Google, which removed the site from search results. The URL which pointed to the potential stealer is no longer online.

“We removed this ad and suspended the account for violating our policies,” a Google spokesperson told me in an email. Google said it has strict policies against ads that aim to phish information or distribute malware, and that it uses a combination of Gemini-powered tools and human review to enforce these policies at scale. Google claims the vast majority of these ads are caught before the ads ever run.

Malicious links included in paid Google ads that are pretending to be legitimate websites is not a problem that’s unique to AI. Hackers often try to get users to click malicious links by pretending to be whatever is popular on the internet at any given moment, be it a pirated movie or video game just before release or celebrity sex tapes. The fact that hackers are targeting Claude users reflects the growing popularity of AI tools and the hackers’ hope that users are not careful enough to check what they’re clicking when using them.

In January, we wrote about how hackers could similarly target users of the AI agent tool OpenClaw by boosting instructions for AI agents that contained a backdoor for hackers.


WebinarTV hosts 200,000 “webinars.” A Zoom call you may thought was private might be one of them.#News #Zoom #webinartv


This Company Is Secretly Turning Your Zoom Meetings into AI Podcasts


WebinarTV, a company that bills itself as “a search engine for the best webinars,” is secretly scanning the internet for Zoom meeting links, recording the calls, and turning them into AI-generated podcasts for profit. In some cases, people only found out that their Zoom calls were recorded once WebinarTV reached out to them directly to say their call was turned into a podcast in an attempt to promote WebinarTV’s services.

WebinarTV claims to host more than 200,000 webinars. It’s not clear how it’s recording so many Zoom calls without permission, but in some cases the stolen videos posted to WebinarTV can put call participants at risk.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


“We are pleased to see today's ruling in defense of the First Amendment rights of all Americans,” one of the plaintiffs in the DOGE-related lawsuit said. The videos previously went viral when a DOGE member was unable or unwilling to define DEI.#DOGE #News


Judge Allows DOGE Deposition Videos Back Online


On Monday a judge said videos of recent depositions from DOGE members can be published online once again. The ruling is something of an about face for Judge Colleen McMahon, who originally ordered plaintiffs in the DOGE-related lawsuit “claw back” the videos they had published to YouTube. The videos were already massively viral at the time of that ruling, in part because they showed DOGE members Justin Fox and Nate Cavanaugh unable or unwilling to define DEI, admitting their use of ChatGPT to filter contracts to potentially axe based on words like “Black” and “homosexual” but not “white,” and were broadly one of the first times the public has directly heard from people inside DOGE.

“This decision validates our position that the publication of the videos, which document a process to destroy knowledge and access to vital public programs, was indeed in the public’s interest,” Joy Connolly, president of the American Council of Learned Societies, said in a statement shared with 404 Media. “We look forward to continuing the pursuit of justice in reclaiming government support for important humanities research, education, and sustainability initiatives.”

This post is for subscribers only


Become a member to get access to all content
Subscribe now