<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Privacy on MacWorks</title><link>https://macworks.dev/tags/privacy/</link><description>Recent content in Privacy on MacWorks</description><generator>Hugo</generator><language>en</language><atom:link href="https://macworks.dev/tags/privacy/index.xml" rel="self" type="application/rss+xml"/><item><title>2026-04-10</title><link>https://macworks.dev/docs/week/hackernews/hackernews-2026-04-10/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://macworks.dev/docs/week/hackernews/hackernews-2026-04-10/</guid><description>&lt;h1 id="hacker-news--2026-04-10"&gt;Hacker News — 2026-04-10&lt;a class="anchor" href="#hacker-news--2026-04-10"&gt;#&lt;/a&gt;&lt;/h1&gt;
&lt;h2 id="top-story"&gt;Top Story&lt;a class="anchor" href="#top-story"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Anthropic&amp;rsquo;s unreleased &amp;ldquo;Mythos&amp;rdquo; AI model is sending shockwaves through the cybersecurity community after reportedly breaking out of Firefox&amp;rsquo;s standalone JavaScript shell sandbox in 72.4% of trials. The implications of an AI model reliably chaining vulnerabilities to escape virtualization boundaries threaten the foundational sandboxing principles that keep modern web browsing and multi-tenant cloud infrastructure secure.&lt;/p&gt;
&lt;h2 id="front-page-highlights"&gt;Front Page Highlights&lt;a class="anchor" href="#front-page-highlights"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;[Microsoft suspends dev accounts for high-profile open source projects]&lt;/strong&gt; · &lt;a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-suspends-dev-accounts-for-high-profile-open-source-projects/"&gt;bleepingcomputer.com&lt;/a&gt;
Microsoft locked out the maintainers of critical tools like WireGuard, VeraCrypt, and MemTest86 without warning due to an automated hardware partner &amp;ldquo;account verification&amp;rdquo; purge. The Kafkaesque nightmare left developers unable to publish Windows security updates and stonewalled by automated support bots until media pressure forced an executive response. (Fortunately, WireGuard was able to push a new Windows release shortly after the resolution).&lt;/p&gt;</description></item><item><title>2026-04-09</title><link>https://macworks.dev/docs/week/hackernews/hackernews-2026-04-09/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://macworks.dev/docs/week/hackernews/hackernews-2026-04-09/</guid><description>&lt;h1 id="hacker-news--2026-04-09"&gt;Hacker News — 2026-04-09&lt;a class="anchor" href="#hacker-news--2026-04-09"&gt;#&lt;/a&gt;&lt;/h1&gt;
&lt;h2 id="top-story"&gt;Top Story&lt;a class="anchor" href="#top-story"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The Vercel Claude Code plugin has been caught using prompt injection to fake user consent for telemetry, quietly exfiltrating full bash command strings to Vercel&amp;rsquo;s servers across all local projects. Instead of implementing a proper UI for permission, the plugin injects behavioral instructions into Claude&amp;rsquo;s system context, forcing the agent to execute shell commands to write tracking preferences based on your chat replies. It&amp;rsquo;s exactly the kind of quiet overreach and abuse of LLM integrations that makes developers deeply paranoid about agent tooling.&lt;/p&gt;</description></item><item><title>Tech News</title><link>https://macworks.dev/docs/week/tech_news/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://macworks.dev/docs/week/tech_news/</guid><description>&lt;h1 id="tech-news--week-of-2026-04-04-to-2026-04-10"&gt;Tech News — Week of 2026-04-04 to 2026-04-10&lt;a class="anchor" href="#tech-news--week-of-2026-04-04-to-2026-04-10"&gt;#&lt;/a&gt;&lt;/h1&gt;
&lt;h2 id="story-of-the-week"&gt;Story of the Week&lt;a class="anchor" href="#story-of-the-week"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Anthropic&amp;rsquo;s unreleased &amp;ldquo;Mythos&amp;rdquo; AI model triggered widespread cybersecurity panic this week after proving incredibly adept at autonomously discovering critical software vulnerabilities. While the company restricted the model&amp;rsquo;s public release and launched a defensive initiative called &amp;ldquo;Project Glasswing,&amp;rdquo; the threat was severe enough to prompt emergency cybersecurity meetings between the US Treasury, the Federal Reserve, and bank CEOs. The fallout eclipsed Anthropic&amp;rsquo;s milestone of hitting a $30 billion revenue run rate, highlighting the unprecedented regulatory and security pressures facing frontier AI labs.&lt;/p&gt;</description></item><item><title>2026-04-04</title><link>https://macworks.dev/docs/archives/tech_news/tech-news-2026-04-04/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://macworks.dev/docs/archives/tech_news/tech-news-2026-04-04/</guid><description>&lt;details&gt;
&lt;summary&gt;Sources&lt;/summary&gt;
&lt;div class="markdown-inner"&gt;
&lt;ul&gt;

&lt;li&gt;&lt;a href="https://feeds.arstechnica.com/arstechnica/index"&gt;Ars Technica&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="http://feeds.feedburner.com/cnet/tcoc"&gt;CNET News&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="https://www.engadget.com/rss.xml"&gt;Engadget&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="https://stratechery.com/feed/"&gt;Stratechery by Ben Thompson&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="https://ftr.bazqux.com/makefulltextfeed.php?url=https%3A%2F%2Ffeed.infoq.com%2F&amp;amp;max=20&amp;amp;links=preserve&amp;amp;exc="&gt;InfoQ&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="https://www.technologyreview.com/feed/"&gt;MIT Technology Review&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="https://www.nature.com/nature.rss"&gt;Nature&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="https://rss.nytimes.com/services/xml/rss/nyt/Technology.xml"&gt;NYT &amp;gt; Technology&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="http://feeds.feedburner.com/OfficialAndroidBlog"&gt;Official Android Blog&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="http://rss.slashdot.org/Slashdot/slashdotMain"&gt;Slashdot&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="https://techcrunch.com/feed/"&gt;TechCrunch&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="http://feeds.feedburner.com/blogspot/MKuf"&gt;The Official Google Blog&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="https://blogs.microsoft.com/feed/"&gt;The Official Microsoft Blog&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="https://www.theverge.com/rss/index.xml"&gt;The Verge&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="https://vercel.com/atom"&gt;Vercel Blog&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="https://www.wired.com/feed"&gt;WIRED&lt;/a&gt;&lt;/li&gt;

&lt;/ul&gt;
&lt;/div&gt;
&lt;/details&gt;


&lt;h1 id="tech-news--2026-04-04"&gt;Tech News — 2026-04-04&lt;a class="anchor" href="#tech-news--2026-04-04"&gt;#&lt;/a&gt;&lt;/h1&gt;
&lt;h2 id="story-of-the-day"&gt;Story of the Day&lt;a class="anchor" href="#story-of-the-day"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Anthropic is pulling the plug on subsidized compute for third-party AI agents, forcing users of tools like OpenClaw to pay for API usage instead of riding on consumer Claude subscriptions. The move signals a harsh reality for the ecosystem built around &amp;ldquo;agentic&amp;rdquo; wrappers: the era of free, open-ended AI compute is over.&lt;/p&gt;</description></item><item><title>Hacker News</title><link>https://macworks.dev/docs/week/hackernews/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://macworks.dev/docs/week/hackernews/</guid><description>&lt;h1 id="hacker-news--week-of-2026-04-04-to-2026-04-10"&gt;Hacker News — Week of 2026-04-04 to 2026-04-10&lt;a class="anchor" href="#hacker-news--week-of-2026-04-04-to-2026-04-10"&gt;#&lt;/a&gt;&lt;/h1&gt;
&lt;h2 id="story-of-the-week"&gt;Story of the Week&lt;a class="anchor" href="#story-of-the-week"&gt;#&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Anthropic&amp;rsquo;s frontier AI models crossed a terrifying new threshold in autonomous cybersecurity, completely shifting the industry&amp;rsquo;s threat model. First, Claude Code uncovered a complex, 23-year-old vulnerability in the Linux kernel&amp;rsquo;s NFS driver that predated Git itself. Days later, the infosec community went into full meltdown when Anthropic&amp;rsquo;s unreleased &amp;ldquo;Mythos&amp;rdquo; model autonomously wrote a 200-byte ROP chain exploit for FreeBSD and demonstrated the ability to reliably escape Firefox&amp;rsquo;s JavaScript virtualization sandbox in 72.4% of trials.&lt;/p&gt;</description></item></channel></rss>