
01
Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service
The gist: A misconfigured ClarityCheck database exposed 9,042,977 facial images totaling 450GB, creating risks of identity theft and phishing.
Big pictureFacial images can help criminals impersonate people, build fake online identities, or make phishing attempts seem believable. The incident also shows that companies, not just cloud providers, must correctly secure the databases where they store sensitive information.
Explain like I'm 5A company accidentally left a huge online cupboard unlocked, and it contained millions of people’s pictures. Someone found the open cupboard and the company quickly closed it, but it is unclear whether anyone took anything.
Why it matters nowA cybersecurity researcher recently found the exposed database and alerted ClarityCheck, which blocked access quickly. The company has not established how long it was open or whether anyone accessed the files.
Three things to know01The files showed real people
The database included profile pictures, screenshots, and scans showing adults, teenagers, and children in folders labeled “faces” and “profiles”.
02The exposure was not confirmed misuse
There is currently no evidence that the images were abused or sold on the dark web, although the company could not confirm whether anyone accessed them.
03Database settings caused the problem
Under the shared responsibility model, cloud providers offer security tools while customers must configure protections such as passwords and encryption.
Trusted source
TechRadar ↗

02
FBI Warns That Hackers Are Targeting Siemens Equipment Amid Recent Water Plant Breaches
The gist: U.S. agencies warn that hackers are actively targeting Siemens S7 PLCs, industrial computers that help control pumps, valves, and other critical equipment.
Big pictureThe warning shows how internet-connected equipment can expose essential services such as water treatment, energy, and manufacturing to cyberattacks. It also suggests that AI tools may be helping attackers create harmful code with less specialized knowledge.
Explain like I'm 5A PLC is like a tiny computer that tells machines when to turn on and off. If hackers get into it, they could interfere with those machines or make them stop working safely.
Why it matters nowThe agencies issued a joint advisory this week amid a recent wave of attacks against U.S. water systems. Operators are being urged to check their Siemens equipment, apply patches, and remove internet access where possible.
Three things to know01Attackers search exposed systems
Hackers are using internet-scanning services to find Siemens PLCs with outdated software or weak protections.
02AI speeds up exploitation
The advisory says attackers are using AI-generated Python scripts that imitate legitimate monitoring tools while seeking read and write access.
03The risks reach beyond water
The targeted sectors also include manufacturing, energy, chemical, food and agriculture, and commercial facilities, where attacks could cause downtime, equipment damage, or safety problems.
Trusted source
Gizmodo ↗

03
Tesla’s Robotaxi gets caught crashing through bollards, just as it readies the purpose-built Cybercab for public roads
The gist: A Tesla driverless taxi in Austin hit plastic bollards, raising questions about its “impeccable” safety record just as Tesla prepares its steering-wheel-free Cybercab for road tests.
Big pictureThe incident highlights the challenge of making cars drive safely without a human ready to take over. It also matters because Tesla is moving toward taxis with no pedals or steering wheel, while its current service remains much smaller and more limited than Waymo’s.
Explain like I'm 5The car was supposed to understand that the plastic posts were blocking the road, but it drove through them instead. It is like a robot being told to follow a path and missing an obvious barrier.
Why it matters nowTesla may begin testing Cybercabs on public roads this month, starting with its own employees. The bollard incident comes as the company defends its record after reporting more than 380,000 Robotaxi miles with zero notable incidents.
Three things to know01The barrier was long-standing
Street View suggests the plastic posts had been in place since at least February 2024, making the apparent failure less likely to be caused by a brand-new obstruction.
02Tesla uses a different mapping strategy
Unlike Waymo, Tesla does not rely on a proprietary high-definition map system, so its onboard computers must make more decisions from current sensor data and general mapping.
03Tesla’s fleet remains small
Reports put the Austin Robotaxi fleet at about 17 vehicles, down from roughly 25 in the spring, operating inside a tightly controlled zone much smaller than Waymo’s service area.
Trusted source
TechRadar ↗