Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

Anthropic's Claude Desktop App Accused of Invasive Browser Data Collection

Reports have emerged detailing concerning behavior by Anthropic's Claude Desktop application, specifically its alleged scanning of local machine browsers and modification of application access settings even for browsers not yet installed. This suggests proactive and potentially unauthorized data collection practices or broad permission requests that raise significant privacy concerns. Users are alarmed by the application's deep system interaction without explicit consent or clear justification for such extensive access. This incident highlights ongoing challenges in managing software permissions and data handling, especially within the rapidly evolving AI application landscape.

Today's question

The "cookie wall" practice where access is denied without accepting all cookies is generally considered:

  1. Required for websites that rely on third-party tracking
  2. Non-compliant as consent is not freely given
  3. Acceptable for free services funded by advertising
  4. Fully compliant with GDPR requirements for consent

Answer this question on the site

Worth knowing

  1. Vercel Confirms Customer Credential Compromise Amidst Breach Investigation

    The Next.js developer Vercel has confirmed a security incident involving a customer credential compromise. While initial reports cited a breach at Context AI, Vercel's confirmation indicates broader implications for its own customer base, leading to concerns about the security of developers using their platform. This highlights the interconnectedness of supply chain security and the significant risks associated with third party vendor breaches.

  2. Code Development Platform Lovable Denies Data Leak, Blames Intentional Behavior and Third Party

    Vibe coding upstart Lovable is denying claims of a data leak, attributing the issue to 'intentional behavior' and shifting blame towards HackerOne. This situation highlights the complex nature of breach investigations, particularly when internal and external security assessments offer conflicting narratives. The dispute underscores the intricate challenges in digital forensics and accountability following reported security incidents, complicating transparency for affected users.

  3. British Hacker Pleads Guilty in US for Scattered Spider Cryptocurrency Thefts

    A Scottish individual has pleaded guilty in the US, becoming the second person linked to the Scattered Spider group to admit guilt for cryptocurrency theft. This development underscores the ongoing international efforts to combat cybercrime and hold perpetrators accountable, highlighting successful cross border legal cooperation. The case serves as a reminder of the global reach of cyber security laws and enforcement actions targeting sophisticated hacking collectives.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.