First Pass

9 stories from 8 sources

Everyday technology became a direct security liability

Day’s Recap

Together, the incidents shifted attention from perimeter defense toward controlling data flows, trust anchors, and software behavior inside deployed systems.

Supporting Articles

6:43 PMThe New York Times

Iran’s Cyberattackers Tracked Phones of U.S. Military Personnel in the Mideast, Data Suggests

Summary

Data reviewed by researchers indicates Iran-linked actors tracked the phones of U.S. military personnel in the Middle East. The activity suggests more aggressive targeting tied to broader regional conflict dynamics.

Why it matters

Mobile tracking turns everyday device data into battlefield-grade intelligence with direct force-protection implications.

12:00 AMFinancial Times

US military targeted in Iran war phone-tracking campaign

Summary

A campaign tied to the Iran conflict used mobile roaming data and ad tech identifiers to try to locate US military personnel in the region. The effort sought to turn everyday phone connectivity and commercial tracking into operational targeting signals.

Why it matters

The same data plumbing that powers ads and roaming can expose troop locations, shrinking the margin between routine connectivity and battlefield risk.

3:25 PMThe Verge

SpaceXAI’s Grok programming tool was uploading its users’ entire codebase to cloud storage

Summary

SpaceXAI’s Grok Build coding tool was found packaging and uploading users’ full code repositories to Google Cloud, including files it was instructed not to access, before the behavior was reported and disabled.

Why it matters

Code-upload behavior at this scale turns AI coding assistants into supply-chain risk, forcing teams to treat them like third-party data processors.

6:20 PMArs Technica

Microsoft’s Secure Boot has been broken for a decade and no one noticed until now

Summary

Researchers found that long-neglected bootloader shims that Microsoft did not revoke allow attackers to bypass Secure Boot. The weakness persisted for years because old trusted components remained valid in the trust chain.

Why it matters

If Secure Boot trust anchors are not reliably revoked, defensive assumptions about endpoint integrity collapse where the old components still exist.

Other Developments

A curated list of other prominent stories from this day.

3:22 PMKrebs on Security

Microsoft Patches a Record 570 Security Flaws

Summary

Microsoft released updates addressing at least 570 vulnerabilities across Windows and other products, nearly tripling last month's already record Patch Tuesday. The company attributed the surge in disclosed flaws to AI-assisted vulnerability discovery.

Why it matters

A record patch volume increases the odds that critical systems stay unpatched long enough for real-world exploitation.

11:17 AMFinextra

Entrust unveils agentic AI trust accelerator

Summary

Entrust launched the Agentic AI Trust Accelerator, a co-development program with enterprises and integration partners. The goal is to build identity and trust infrastructure that helps move autonomous agentic AI deployments from pilots into production.

Why it matters

Agentic AI will not scale in regulated environments without verifiable identity, authorization, and auditability for non-human actors.

10:07 AMUtility Dive

DHS proposes new critical infrastructure security framework

Summary

DHS has proposed a new framework to guide cybersecurity practices across critical infrastructure sectors after the prior version was eliminated in 2025. The proposal aims to reset federal expectations for baseline controls and coordination.

Why it matters

A federal baseline shapes what gets built, bought, and inspected across power, water, transportation, and other high-consequence systems.

7:06 AMSchneier on Security

Vulnerability in FIFA’s Network

Summary

FIFA’s internal network could be accessed and abused by someone with only minimal foothold or low-level access. The weakness meant an attacker did not need sophisticated capabilities to move through or exploit the environment.

Why it matters

If minimal access enables deep compromise, perimeter security stops being the main risk and routine account breaches become organization-wide incidents.

7:04 AMFinextra

Ofcom to hold Big Tech accountable for scam adverts

Summary

Ofcom has proposed new anti-fraud rules that would make large online platforms responsible for preventing and removing scam advertisements. The approach shifts expectations from voluntary enforcement to regulator-defined controls and oversight.

Why it matters

Scam ads are being treated less like content moderation and more like a regulated consumer protection failure with penalties attached.

Make it yours

Build Your First Pass.

Pick your topics, set your cadence, and receive your personalized First Pass in your inbox. It’s that simple!