First Pass

7 stories from 6 sources

Cyber risk widens as hackers and AI agents gain reach

Day’s Recap

Supporting Articles

3:28 PMArs Technica

Now, even Russia's most elite hackers are using Clickfix to infect devices

Summary

Elite Russia-linked hacking groups are adopting Clickfix, a social-engineering technique that tricks targets into infecting their own devices. The method had mainly been associated with financially motivated cybercriminals before spreading into state-aligned operations.

Why it matters

When elite state hackers adopt commodity social-engineering tradecraft, the baseline risk rises for many more targets because the barrier to successful compromise drops.

10:46 AMAl Jazeera

Data breach reportedly targets India’s Kudankulam nuclear power plant

Summary

A ransomware group calling itself World Leaks has posted what it claims are blueprints and technical documents tied to India’s Kudankulam nuclear power plant. The leak appears to expose sensitive design and operational details for parts of the country’s largest nuclear facility.

Why it matters

Nuclear infrastructure leaks can shift cyber risk from theoretical to actionable by giving adversaries technical context to plan more targeted attacks.

6:44 PMPYMNTS

1Password and Anthropic Bring Secure Credential Access to Claude

Summary

1Password launched a browser integration that lets users authorize Anthropic's Claude to take actions that require logins while keeping the underlying credentials hidden from the model, its memory, and Anthropic systems. The tool aims to enable tasks like booking travel and managing accounts without exposing passwords or allowing the model to retain them.

Why it matters

This creates a practical path for AI agents to operate inside real accounts while reducing credential leakage risk, accelerating automation in high-value workflows.

Other Developments

A curated list of other prominent stories from this day.

4:20 PMPYMNTS

Bank of America CEO Brian Moynihan Joins Wall Street Leaders in Warning of Mythos AI Risks

Summary

Bank of America CEO Brian Moynihan is joining other Wall Street leaders warning that new AI models, including Anthropic’s Mythos system, could introduce security risks for financial institutions. The concerns are prompting both the financial sector and the US government to evaluate AI-driven cybersecurity threats.

Why it matters

When systemically important banks elevate a named AI platform as a security concern, it can quickly harden enterprise controls and shape regulatory expectations for AI use across critical infrastructure.

10:34 AMSchneier on Security

Protecting Privacy in an AI Era

Summary

The argument is that giving individuals granular control over personal data is ineffective for AI era privacy regulation. It proposes shifting responsibility to companies through data minimization, fiduciary duties, liability for negligent design, and multi stakeholder review.

Why it matters

Accountability and liability would change the economics of data collection and make harmful AI uses legally expensive.

10:00 AMThe Verge

‘No company is going to go to jail for you’: Proton’s CTO on balancing privacy, policy, and trust

Summary

Proton’s CTO argues that privacy products should be designed around the reality that users, not companies, bear most of the personal and legal risk when things go wrong. He describes how Proton balances encrypted-by-default services with legal compliance, policy pressure, and user trust.

Why it matters

The privacy market is moving from feature claims to enforceable trust, shaped by law, defaults, and what providers can realistically resist.

9:12 AMFinextra

Hacked fintech Nayax refuses to pay ransom

Summary

Nayax says attackers stole data in a breach and the company will not pay a ransom. The stance signals the firm will rely on recovery, customer communication, and law enforcement engagement rather than negotiation.

Why it matters

Refusing to pay can reduce future extortion incentives, but it raises the near term stakes for customer harm and regulatory scrutiny.

Make it yours

Build Your First Pass.

Pick your topics, set your cadence, and receive your personalized First Pass in your inbox. It’s that simple!