Connect with us

Infosecurity

That Cute Kid Photo You Posted? The NCA Says AI Is Now Weaponizing It

Published

on

AI tools exploiting photos

Why Your Child’s Photo Could End Up in an AI Abuse Pipeline

Every parent loves sharing a milestone — the first day of school, a birthday party, a goofy grin. But the National Crime Agency (NCA) is sounding the alarm: those innocent snapshots are being scraped, fed into generative AI tools, and turned into something horrific.

In 2025, the Internet Watch Foundation (IWF) recorded 3,440 AI-generated videos of child sexual abuse — up from just 13 the year before. That’s a 26,000% annual spike. Total AI-generated abusive images and videos hit 8,029, a 14% year-on-year climb. And this is just what they found.

The NCA has launched a new campaign across Facebook, Instagram and YouTube. Their message? Think before you post.

What “Sharenting” Actually Costs

There’s a term for parents oversharing kids’ content online: sharenting. It’s not new, but the risk profile has changed. Criminals are no longer just collecting photos for creepy personal use. They’re feeding them into AI models to generate sexual abuse material — in bulk.

The IWF revealed a chilling case: a criminal gang scraped images from a UK school website, used AI to generate over 100 sexual images of those pupils, and then tried to blackmail the school. This isn’t a theoretical threat. It happened.

And the severity is rising. Two-thirds (65%) of AI-generated abusive content was classified as Category A — the most extreme category — compared to 43% of non-AI criminal videos in 2025. The tech is making it easier to produce worse material, faster.

What the NCA and IWF Want You to Do

Neither agency is telling parents to stop sharing entirely. IWF CEO Kerry Smith put it plainly: “We don’t want to say don’t share your children’s images with the people you love and trust, but we want everyone to be aware of the potential risks and make an informed decision.”

The NCA’s Tim Wright stressed prevention. His advice boils down to three steps:

  • Lock down your privacy settings. Who can actually see that photo? If it’s “public” or “friends of friends,” you’ve lost control.
  • Think about who has access. That school Facebook group, the sports club WhatsApp chat — everyone in those groups can screenshot and save.
  • Talk openly. Have the conversation with family, friends, schools, and clubs about consent. It’s okay to ask someone not to post a photo of your child.

If something does go wrong, Wright says: stay calm, reassure your child it’s not their fault, and report it to police or the CEOP (Child Exploitation and Online Protection Command) immediately.

Consent Isn’t a One-Time Decision

The NCA’s guidance urges parents to regularly review image consent. Ask yourself:

  • Am I still comfortable with how my child’s images might be used?
  • Have my preferences changed?
  • Do I want to limit or withdraw consent?

It’s a dynamic process. What felt fine at age three might feel different at age ten. And once a photo is online, you can’t truly take it back. Even if you delete it, copies may live on in group chats, in scraped datasets, or on someone’s hard drive.

This is especially urgent given the rise of deepfake nudes targeting children. The IWF recently launched a tool to help remove nude images of minors from the web, but removal is always harder than prevention.

The Bottom Line for Parents

No one is saying stop documenting childhood. But the NCA campaign is a wake-up call: the audience for those photos is bigger and more dangerous than you think. AI tools are lowering the barrier for abusers, and the consequences for kids are real and lasting.

As Kerry Smith put it: “The impact of this imagery can be devastating. The harms are very real.”

So before you hit post on that adorable bathtub shot or that first-day-of-school portrait, pause. Check your privacy settings. Ask consent. And remember: the internet never forgets — and now, neither does the AI.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

Kenya Investigates Cyberattack on President’s Website After Hackers Demand Bitcoin Ransom

Published

on

Kenya president website hack

Attackers Target Presidential Site with Anti-Government Message

Kenyan authorities are investigating a cyberattack that temporarily took over President William Ruto’s official website over the weekend. The homepage was replaced with a message demanding a ransom of five bitcoins — roughly $330,000 — in exchange for not releasing what the hackers claimed was sensitive information about the president.

The defacement occurred on Saturday. By Monday, local media reported that access to the site had been restored. The attackers’ identity remains unknown, and there is no verified evidence that they obtained or leaked any classified government data.

Government Response: ‘No Evidence of Data Exfiltration’

Information, Communications and the Digital Economy Cabinet Secretary William Kabogo confirmed the incident over the weekend. He stated that cybersecurity teams are actively investigating the breach.

“As a precautionary measure, access to the Presidential website was temporarily restricted to facilitate containment, forensic analysis and restoration efforts,” Kabogo said in a statement.

He added that authorities found no signs of unauthorized access to sensitive data, data exfiltration, or information loss. “Government systems and digital services remain secure and operational,” Kabogo emphasized.

Screenshots circulating on social media showed the defaced page included a cryptocurrency wallet address and a threat that this was the attackers’ “third” warning to the president before they would publish data. Officials have not confirmed that claim, and no leak has materialized.

Not the First Cyber Incident Targeting Kenyan Government Sites

This attack follows a pattern of digital intrusions into Kenyan government infrastructure. In November 2025, a coordinated cyberattack disrupted multiple government websites, including those of the presidency and ministries for interior, health, education, energy, labor, and water.

During that incident, attackers defaced several ministry pages with white supremacist slogans, including “We will rise again,” “White power worldwide,” and the neo-Nazi code “14:88 Heil Hitler.” The perpetrators behind that attack were never publicly identified.

The repeated targeting of high-profile government portals raises questions about the overall cybersecurity posture of Kenya’s digital infrastructure. While officials insist core systems remain secure, the frequency of these incidents suggests persistent vulnerabilities.

What the Bitcoin Ransom Demand Reveals

Demanding five bitcoins — a sum that fluctuates with the cryptocurrency market but currently sits around $330,000 — is a relatively modest ask compared to some ransomware attacks targeting large corporations or critical infrastructure. This could indicate the attackers are less sophisticated actors, or that their primary goal was disruption and attention rather than financial gain.

The defacement itself, replacing the homepage with a political message, is a classic hacktivist tactic. It aims to embarrass the government and broadcast a grievance, not necessarily to steal data or extort money long-term.

Still, the inclusion of a ransom demand and a threat to leak information adds a layer of potential extortion. If the attackers do possess compromising material — a claim that remains unverified — the situation could escalate quickly.

Broader Implications for Kenya’s Cybersecurity

The attack on the president’s website is the latest in a string of digital breaches affecting Kenyan government systems. It underscores the need for stronger cybersecurity measures across public-sector digital assets.

Kenya has been investing in digital transformation, including e-government services and online portals for everything from tax filings to business registration. But with increased digitization comes increased risk. High-profile hacks erode public trust and can disrupt essential services.

Experts argue that the government must prioritize proactive security measures: regular penetration testing, employee training on phishing and social engineering, and rapid incident response protocols. The fact that the presidential website was restored within 48 hours is a positive sign, but prevention is always better than remediation.

For now, the investigation continues. Authorities are likely tracing the cryptocurrency wallet address and analyzing server logs for clues. But without attribution, the attackers remain a ghost in the machine — and a warning that no website is truly safe.

Continue Reading

Infosecurity

AI vs. WordPress: How Researchers Used OpenAI’s GPT-5.6 Sol Ultra to Chain a Critical Exploit in Hours

Published

on

WordPress exploit AI

AI Crafted a WordPress Exploit That Could Have Cost a Fortune

On July 17, WordPress pushed an emergency update. Version 7.0.2 patched two Core vulnerabilities that, when chained, allowed a complete stranger to take over a site. No plugins needed. No special conditions. Just a stock WordPress install, exposed.

What’s more startling? The exploit chain — dubbed WP2Shell — wasn’t discovered by a human. It was built by OpenAI’s GPT-5.6 Sol Ultra, the latest large language model available in ChatGPT Work Pro and Codex Plus plans. Security researchers at Searchlight Cyber used the model to find and assemble the attack path in just over ten hours. The total compute cost? About $25.

Exploit brokers have been known to pay up to $500,000 for a zero-day remote code execution vulnerability in WordPress Core. Suddenly, that economics equation looks very different.

Two Flaws, One Chain: The Vulnerabilities Behind WP2Shell

The first bug, tracked as CVE-2026-63030, is a critical REST API batch endpoint route confusion issue. It carries a CVSS score of 9.8 and affects WordPress Core versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2.

The second, CVE-2026-60137, is a high-severity SQL injection in the author__not_in WP_Query parameter. Its CVSS score is 5.9. It impacts versions 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2.

Alone, each flaw is serious. Chained together, they become devastating. An attacker can exploit the REST API confusion to bypass input sanitization, then trigger the SQL injection. From there, they can extract the admin email from a fresh installation — and then escalate to full remote code execution.

“The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins,” said Adam Kues, security researcher at Searchlight Cyber.

How GPT-5.6 Sol Ultra Built the Exploit

Searchlight Cyber’s Kues published a report on July 20 detailing the process. He started by stripping version history from a clean copy of the WordPress source code. The goal: prevent the model from cheating by recognizing known vulnerabilities.

He then adapted a prompt OpenAI had previously used to solve a complex mathematical conjecture. The model was instructed to run up to four agents for at least six hours, hunting for a pre-authentication remote code execution path.

It didn’t take long. The AI quickly flagged the REST API batch route confusion (CVE-2026-63030), recognizing that a desynchronization between validation and execution could bypass input sanitization. That opened the door to the SQL injection (CVE-2026-60137). Within minutes, the model extracted the administrator email from a clean WordPress install.

But that was just the start. The real feat came next.

From Read-Only to Full Takeover

Over the next four hours, the AI constructed a multi-stage chain that Kues described as “absurdly complex.” It used cache poisoning through fake oEmbed entries. It manipulated WordPress customize changesets to temporarily grant itself admin privileges. It triggered hooks that bypassed authentication entirely, finally uploading a backdoor plugin.

The entire automated process took just over ten hours and cost roughly $25 in compute resources. “No security researcher could have found and completed this exploit chain in 10 hours without AI,” Kues said.

For context, a human researcher would likely need weeks or months to piece together such a convoluted path. The AI did it in a single workday.

In-the-Wild Exploitation and the Economics Shift

After the vulnerabilities were publicly disclosed, other researchers released proof-of-concept exploits. On July 17, security firm PatchStack reported active exploitation of both CVEs. Companies like Hexastrike and WatchTowr also observed signs of in-the-wild attempts.

What exactly attackers are doing with the exploit remains unclear. But the window for patching is closing fast.

Kues pointed out the economic implications. With exploit brokers offering up to half a million dollars for a zero-day RCE in WordPress Core, and an off-the-shelf AI model finding one for $25, the cybersecurity landscape is shifting. “It highlights a major shift in cybersecurity economics,” he said.

WordPress Forced Automatic Updates — Here’s What to Do

WordPress took the rare step of forcing automatic updates for affected installations. That’s a strong signal of how serious the threat is.

Security administrators should manually verify that their sites are running WordPress 7.0.2 or 6.9.5. Don’t rely on auto-updates alone — check the version in your admin dashboard or via the site’s footer.

Searchlight Cyber has released a free scanning tool at wp2shell.com so administrators can safely test if their servers remain vulnerable to this AI-crafted attack.

What This Means for the Future of Security Research

This isn’t a theoretical exercise. An AI model found a critical vulnerability chain in a platform that powers over 40% of the web. It did so quickly and cheaply. The implications for both attackers and defenders are enormous.

On one hand, security researchers can use AI to discover flaws faster, potentially reducing the window between a vulnerability’s introduction and its patch. On the other hand, malicious actors could do the same — and they don’t have to follow disclosure rules.

For now, the takeaway is simple: patch your WordPress sites. The AI is already working. Don’t let your site be the next victim.

Continue Reading

Infosecurity

Taiwan will slow mobile internet to a crawl during war-preparedness drills next month

Published

on

Taiwan mobile data throttle

What’s happening — and why it matters

Next month, millions of people in northern and central Taiwan will experience what it feels like when mobile internet all but vanishes. For 30 minutes, 4G and 5G data speeds will drop to roughly 1% of normal capacity. Video calls? Forget it. Streaming, social media, large file transfers — most will become unusable.

The exercise, announced Monday by Taiwan’s National Communications Commission (NCC), is part of the island’s annual Urban Resilience Exercises, held alongside the Han Kuang military drills in mid-August. The goal isn’t to punish civilians. It’s to test how people would communicate if mobile networks were knocked out during a war or a major disaster.

Voice calls, text messages, emergency alerts and 911-style services will keep working. Fixed broadband, WiFi, landlines and dedicated military networks will also run normally. Authorities stress this is not a full internet shutdown — just a targeted, temporary throttle to simulate a realistic crisis scenario.

Which areas are affected — and what users can expect

The slowdown will hit 14 cities and counties across northern and central Taiwan. If you’re in Taipei, New Taipei, Taoyuan, Taichung, or surrounding areas, your mobile data will crawl. Officials say the test will last half an hour, though exact timing and dates are still being finalized.

For most people, the practical impact is simple: apps that rely on fast data — Instagram, YouTube, FaceTime, WhatsApp HD photo sending — will stall or fail. Emergency apps and SMS will still work. The NCC and local officials, cited by Reuters and Bloomberg during a Taipei briefing, said the drill is designed to push citizens toward alternative channels.

The message is clear: don’t panic, but do prepare.

How to get ready for the drill

Authorities are already urging residents to take a few concrete steps before the exercise:

  • Download offline maps for navigation apps like Google Maps or Apple Maps.
  • Switch to WiFi for any scheduled online meetings or important calls during the test window.
  • Set a backup plan with family — agree on a time to check in via SMS or a landline if mobile data drops.
  • Keep a power bank handy — if networks are strained, battery life becomes critical.

These are the same habits that help during earthquakes, typhoons or any infrastructure failure. The drill is meant to turn them into muscle memory.

Beyond the data slowdown — the bigger picture of resilience

The communications test is only one piece of a larger exercise. Taiwan’s defense ministry will also rehearse civilian evacuations, expand emergency medical capacity, and evaluate drones for delivering supplies and medical equipment. The ministry said results will help decide whether similar drills should expand to other parts of the island.

This year’s exercises carry extra weight. Taiwan has faced several disruptions to undersea communications cables in recent years — some accidental, others suspicious. Combined with the persistent threat of military conflict with China, the government is pushing resilience hard. The Urban Resilience Exercises are a visible part of that push.

A senior official told reporters the drill is not about scaring people. It’s about building real, practiced readiness. “If mobile data becomes unreliable, what’s your Plan B?” That’s the question the government wants every citizen to answer before they need it.

What this means for Taiwan’s digital infrastructure

Taiwan is one of the most digitally connected places on earth. Mobile penetration is among the highest globally, and people rely on high-speed data for everything from banking to chatting with family. A 30-minute throttle is a relatively mild test — but it reveals a deeper vulnerability.

If a real crisis hit, mobile networks could be degraded for hours or days, not minutes. The NCC’s exercise is a low-risk way to expose gaps in how people and systems would adapt. It’s also a signal to telecoms and emergency planners: find the weak spots now, before a real event finds them for you.

The drill will likely be watched closely by other governments. From Japan to NATO allies, many nations are rethinking civilian resilience in an age where cyber and physical threats blur. Taiwan’s approach — transparent, scheduled, and integrated with military exercises — offers a template.

Final takeaway

Come mid-August, if you’re in Taipei or Taichung and your mobile data suddenly slows to a crawl, don’t assume it’s a network glitch. It’s a drill. And it’s designed to make sure that when the real thing happens, you’re not caught off guard.

Download those offline maps. Test your SMS. Talk to your family. A half-hour of slow internet might be annoying — but it’s a small price for knowing what to do when it really counts.

Continue Reading

Trending