It Takes 2 Minutes to Hack the EU’s New Age-Verification App | WIRED
CommentLoader-
Save StorySave this story
CommentLoader-
Save StorySave this story
Planning a big night out at Madison Square Garden? Have fun—but don’t say we didn’t warn you.
A WIRED investigation this week revealed new details about the private surveillance state instituted by MSG owner Jim Dolan and his head of security, John Eversole. According to court records and WIRED sources, visitors to the Garden and some other Dolan-owned venues have been subjected to face recognition, social media monitoring, in-person surveillance, and more.
The US government’s warrantless wiretap powers hit a roadblock this week. Despite a push from President Donald Trump for a long-term reauthorization of the so-called Section 702 spy program, 20 Republican lawmakers in the House of Representatives voted against a full reauthorization, forcing Speaker Mike Johnson to merely extend the program for an additional 10 days.
Meta’s Ray-Ban and Oakley AI smartglasses have an image problem—for good reason. More than 70 civil society groups, including the ACLU and the National Organization for Women, sent a letter to the company this week, demanding that it abandon any plans it may have to equip its AI glasses with face-recognition features. The groups argue that including face recognition in the wearable devices, which can already surreptitiously record videos of people, would further erode any semblance of privacy and potentially facilitate stalkers, domestic abusers, and federal agents.
Nonconsensual deepfake nudes are a scourge at schools around the world, according to an analysis by WIRED and Indicator. By tracking publicly reported incidents of deepfake “nudify” tech used against middle- and high-school-aged girls, we were able to identify more than 600 victims in 28 countries around the world.
You might think banning a $20 billion black market for scammers from your platform would be a no-brainer. But not if you’re Telegram. A WIRED investigation found that the messaging app continued to host Xinbi Guarantee despite the UK government’s designating it a facilitator of human trafficking and sanctioning the largest-ever online marketplace of its kind. Crypto-tracing firm Elliptic says that Xinbi carried out another $505 million in transactions in the 19 days after the UK issued its sanction.
The AI race has finally entered the cybersecurity lap. After Anthropic revealed its new model, Mythos, as a unique risk to the security status quo, OpenAI announced that it, too, has a new cybersecurity strategy, and a new model to go with it—GPT-5.4-Cyber.
That’s not all! Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.
It Takes 2 Minutes to Hack the EU’s New Age Verification App
The European Commission this week released its free, open source app for verifying the ages of visitors to social networks and pornography websites. At a press conference on Wednesday, European Commission president Ursula von der Leyen proclaimed that, with the release of the app, “there are no more excuses” for platforms that fail to check users’ ages. That, however, was before experts found the app to be a security disaster.
As reported by Politico, security consultant Paul Moore claimed on X to have found a series of security issues with the app that allowed him to hack it “in less than 2 minutes.” The issues include how the app reportedly stores a user-created PIN that could allow an attacker to easily take over that person’s app profile. (Baptiste Robert, a whitehat hacker, confirmed the vulnerability to Politico.) Tagging von der Leyen in his post, Moore concluded, “This product will be the catalyst for an enormous breach at some point. It's just a matter of time.”
A Gym Chain and a Hotel Giant Disclose Major Data Breaches
Europe's largest gym chain, Basic-Fit, confirmed a major data breach on Monday, revealing that the bank details of roughly a million customers were compromised. Around 200,000 members in the Netherlands alone were affected. The stolen data includes bank details along with customers' names, home and email addresses, phone numbers, and dates of birth. A spokesperson told The Register that members in Belgium, France, Germany, Luxembourg, and Spain were also similarly hit through a single system that records member visits to clubs. No passwords, which Basic-Fit says it does not store, were reportedly compromised.
The same day, global travel and hotel reservation giant Booking.com confirmed that hackers may have extracted customer data including names, emails addresses, phone numbers, and booking details. The company informed TechCrunch that it “noticed some suspicious activity” and “took action to contain the issue.” Company notices posted by purported customers on Reddit appear to disclose a breach touching on “anything” the users “may have shared with the accommodation.” TechCrunch reported that Booking.