As encrypted communications become harder to intercept, law enforcement agencies are increasingly turning to hacking suspects' devices directly rather than breaking encryption. This shift marks a new phase in the ongoing tension between privacy and security.
The "going dark" problem—where law enforcement cannot access communications due to encryption—is prompting agencies worldwide to adopt hacking capabilities. Rather than pressuring tech companies to weaken encryption, authorities are developing tools to compromise devices and extract data before encryption occurs.
This approach sidesteps the encryption debate entirely. Agencies can access unencrypted data stored on phones, computers, and servers through remote exploits, malware, and physical access techniques.
The strategy raises distinct concerns. Device hacking leaves traces, requires technical expertise, and may inadvertently expose zero-day vulnerabilities. It also operates in legal gray areas, with limited oversight compared to traditional wiretapping.
Security researchers note this trend could accelerate arms races between offensive hacking tools and defensive security patches. As law enforcement capabilities expand, cybercriminals and foreign actors gain similar techniques.
The shift reflects a pragmatic acceptance that encryption won't disappear. However, it trades one problem for another: a world where institutions routinely hack devices, with unclear boundaries on scope and targets.
A critical macOS vulnerability allowing remote attackers to gain complete system control without passwords is actively being exploited in the wild. The bug affects the built-in screen-sharing functionality across multiple Mac systems.
Multiple water treatment facilities across the United States have been compromised in recent weeks by attackers allegedly connected to the Iranian government. The breach marks a significant intrusion into critical infrastructure systems.
A PBS station is at risk of losing 50 terabytes of archived content after its cloud storage provider, Iron Mountain, became unresponsive and denied access to the data. The station has no backup copies of the material.
Four cybercriminals were arrested in Brazil and three others charged in Europe for exploiting a service provider vulnerability to steal €30 million from Commerzbank customers' accounts.