:

MS PAINT AND PHOTOS SILENTLY EMBED HIDDEN WATERMARKS

AI DESK1 MIN READ
MON, AUG 24, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Microsoft's Paint and Photos applications automatically embed invisible GUIDs into locally generated images, according to reverse engineering analysis. The watermarks persist even when files are created entirely offline.

Security researcher Xu Sheng discovered that both Paint and Photos add hidden metadata to image files, embedding unique identifiers that could theoretically track image provenance or creation. The watermarks are embedded invisibly within the image data itself, not just in standard metadata fields, making them difficult to detect or remove without specialized knowledge. This occurs regardless of whether images are generated locally or require network access. The finding raises questions about user privacy and consent, as most users remain unaware that their locally created content carries embedded identifiers. Microsoft has not publicly disclosed this watermarking behavior in either application's documentation. The discovery gained significant traction in tech communities, with over 300 upvotes and 133 comments on Hacker News, indicating widespread interest in the implications for digital privacy and image authenticity. Microsoft has not yet commented on the practice or provided clarification on its purpose.

■ SOURCES

Hacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

An unpatched vulnerability in Calix GS7 XGS residential routers allows remote attackers to bypass network protections and expose devices on private networks to the internet. The flaw affects routers deployed by multiple U.S. broadband providers.

6H AGOSecurity Desk

Cody Wilson, creator of the first 3D-printed gun, says he's developed software to bypass government-mandated blocks on 3D printers making firearms. The claim marks the start of an escalating regulatory battle over ghost guns.

7H AGOIndustry Desk

Hackers are exploiting critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The flaws allow attackers to forge SAML responses and gain administrator access.

7H AGOSecurity Desk

Chinese threat actors are integrating DeepSeek and other open-source AI models into cyberattacks, researchers report. The shift demonstrates how readily available AI tools can amplify hacking capabilities against international targets.

9H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.