Pete Recommends – Weekly highlights on cyber security issues, July 25, 2026

Subject: 1Password Lets Claude Sign In Without Revealing Passwords
Source: TechRepublic
https://www.techrepublic.com/article/news-1password-claude-passwordless-sign-in-ai-agents/

1Password’s new Claude integration lets AI agents sign in to websites without exposing passwords, adding user approval and credential protection.

Password manager 1Password has launched a new integration that lets Anthropic’s Claude AI assistant sign in to websites and complete authenticated tasks without exposing passwords or one-time authentication codes.

The feature, called 1Password for Claude, is designed for the growing era of agentic AI, where assistants can browse websites, complete forms, manage accounts and make decisions for users. The challenge has been giving AI agents enough access to perform tasks while preventing them from becoming a security risk.

How the credential-protected access system works – Instead of handing Claude a password, 1Password keeps credentials inside its encrypted vault and acts as a secure middle layer.

When Claude needs to sign into a website, 1Password shows the user which saved credential is being requested and why. The user must approve the request through biometric authentication, such as Touch ID, before 1Password fills in the login details directly on the website.

Claude can complete the task, but it never receives the actual password, saved login item or one-time passcode. The credentials also do not enter Claude’s memory, model context or Anthropic’s systems.

Filed: https://www.techrepublic.com/topic/security/


Subject: New FCC Proposal Pits Phone Privacy Against Fraud Prevention
Source: TechRepublic
https://www.techrepublic.com/article/news-fcc-phone-identity-verification-burner-phone-proposal/

The FCC has proposed requiring identity verification for phone activation, a move supporters say will fight fraud while critics warn it threatens privacy.

The Federal Communications Commission has proposed requiring telecom providers to verify customers’ identities before activating or renewing voice services, including prepaid mobile plans and internet-based calling services. The proposal would not ban burner phones, but it would make anonymous phone activation largely impossible.

Why critics think this is a bad idea – Critics argue the proposal risks treating every phone user like a potential suspect in an effort to catch a relatively small group of bad actors.

Advocates at the Electronic Frontier Foundation and the ACLU filed a joint comment in June, noting that requiring every customer to verify their identity would remove a longstanding avenue for anonymous communication used for legitimate purposes. The group also raised cybersecurity concerns about telecom providers storing larger amounts of sensitive personal data.

Beyond privacy and security, the group’s filing noted that such a proposal would affect an estimated 15 million adult Americans without a driver’s license and 2.6 million without any government-issued photo ID. Additionally, those without physical addresses could be excluded from activating a mobile number.

What the proposal could mean for phone privacy – The proposal highlights a larger question facing the telecom industry: how much anonymity should remain in an era of growing digital fraud?

If ultimately adopted, the rules could make it more difficult for scammers and robocall operators to obtain anonymous phone numbers. At the same time, they would require telecom providers to collect and retain more customer information, potentially expanding their responsibilities for protecting sensitive personal data from breaches and misuse.

Filed: https://www.techrepublic.com/topic/tech-regulation/


Subject: Now, defenders are embracing the prompt injection, too
Source: Ars Technica
https://arstechnica.com/security/2026/07/now-defenders-are-embracing-the-prompt-injection-too/

“Context bombing” tricks hacking agents into shutting down before they can do harm. Prompt injections, the malicious commands attackers embed into content to entice large language models to follow them, have been attackers’ go-to tool for turning AI platforms against their users. A well-phrased command sneaked into an email or calendar invitation is often all it takes to cause the LLM to exfiltrate sensitive data or follow other harmful actions. Now, defenders are embracing the prompt injection, too.

A strong, sharp effect – Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut down attacks from AI hacking agents. The prompts direct the attacking LLM to perform an action forbidden by its guardrails, the safety barriers AI developers erect to prevent it from taking harmful actions. The LLM responds by shutting down.

“Ultimately we’re triggering a refusal mechanism in the context,” Andy Smith, co-founder and CEO of Tracebit, said when explaining the name choice. “What we’re trying to capture is the fact that this does have a strong, sharp effect and one that can be difficult for the agents to come back from. Once they get that into their context they are going to keep refusing.”

Attackers have already been using prompt injections to close down AI defenses inside networks. Researchers from security firm Socket, for instance, last month unearthed an LLM agent that directed target LLMs to provide instructions for building a nuclear bomb or biological weapons. The injections were designed to shut down AI-assisted malware analysis. Researchers from Check Point discovered a similar malware prototype.

Context bombing appears to be the first known case where defenders turned the tables.

To date, there is no known way to solve the root cause of prompt injections. That has left developers with no option other than to construct elaborate guardrails that prevent injected prompts from forcing LLMs to go off the rails. Defenders may now find a way to use this intractable problem in their favor.


Subject: Can your ISP see what you do? Yes, unless you stop it. Here’s how
Source: Proton Blog
https://proton.me/blog/how-isps-track-you

Every time you browse the web, your activity passes through your internet service provider (ISP). While encryption prevents ISPs from seeing everything you do, they can still collect a surprising amount of information about your habits, both on and offline.

Whether you’re checking your bank account, streaming a movie, shopping online, or scrolling social media, every connection to the internet passes through your ISP. Unlike Google, Meta, or Amazon, you can’t simply log out of your ISP or choose not to use it. It’s an unavoidable part of modern life.

In this guide, we’ll explain what information ISPs can collect, how they use it, why privacy advocates have raised concerns about ISP tracking, and what you can do to reduce the amount of information your provider can access.


Subject: OpenAI says its AI technology acted on its own in an ‘unprecedented’ hack of another company
Source: AP via WTAE
https://www.wtae.com/article/openai-hack-cyber-incident-hugging-face/73227579

ChatGPT maker OpenAI said Tuesday that its artificial intelligence system hacked into another AI company on its own in what the company called an “unprecedented cyber incident.”

“We had a significant security incident during evaluation of our models,” OpenAI CEO Sam Altman said in a statement posted on social media.

Related video above | Florida AG sues OpenAI and CEO Sam Altman – AI startup Hugging Face said last week that it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent autonomously acting on its own.

“We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent,” Hugging Face co-founder and CEO Clément Delangue said in a statement. “Turns out it did!”

It went to “extreme lengths to achieve a rather narrow testing goal” and “found ways to gain access to secret information that it could use to cheat the evaluation,” the company said.


Subject: Feds call on more states to make network vandalism a felony
Source: Route Fifty
https://www.route-fifty.com/digital-government/2026/07/feds-call-more-states-make-network-vandalism-felony/414933/

Currently, 28 states classify vandalizing telecommunications equipment as a more severe crime. FCC Commissioner Olivia Trusty called on the remaining 22 to follow their lead.

Amid warnings about the growth in attacks on telecommunications infrastructure, a member of the Federal Communications Commission called on more states to treat that vandalism as a felony.

FCC Commissioner Olivia Trusty said that while 28 states classify theft or vandalism of telecommunications infrastructure as a felony, the 22 that do not must quickly do so. It comes as various industry groups have raised concerns about attacks on infrastructure, which jumped to over 18,000 reported incidents last year, a 59% increase from 2024.

“[Vandalism not being a felony] creates opportunities for bad actors to engage in these kinds of operations in jurisdictions where the consequences are not as robust,” Trusty said during an event last week on Capitol Hill in Washington, D.C. hosted by various telecommunications groups. “I’d love to see those 22 states follow the lead of those other 28.”

[do perps actually consider the legal consequences of their actions before they do them? do they compare stats among those states? /pmw1]

Topics:

Posted in: AI, Cybercrime, Cybersecurity, Privacy