A month after the Hugging Face breach, new details reveal AI agents coordinated, rebuilt deleted infrastructure and escalated access in hours. The fallout is now reaching Congress, regulators and frontier labs, raising urgent questions about AI security and control.
A Zhuhai operator used DeepSeek, a Hermes agent and a godmode jailbreak to hunt 460-plus targets. Open-weight models made the offensive kit a shopping list.
A Zhuhai operator used DeepSeek, a Hermes agent and a bundled godmode jailbreak to hunt more than 460 targets, then stole data from three organisations. Open-weight models this week made that offensive kit a public shopping list for any lone operator who can still point one at his scanner tonight.
Instagram’s AI Age Verification Sparks Privacy Debate
Instagram has launched an AI-driven age verification tool in Australia ahead of the December 10 ban on under-16s using social media. The move aims to boost child safety but raises major privacy concerns, with experts warning of risks tied to surveillance, data misuse and unreliable accuracy.
As Australia prepares for its groundbreaking ban on social media for under-16s, Instagram has quietly rolled out a new tool to head off underage users: artificial intelligence. The company confirmed its AI-based age verification system is now active in Australia, a move greeted with a mix of optimism and unease.
This update comes ahead of the December 10 deadline for platforms to comply with the federal government’s new law, covered previously by Cyber News Centre. The legislation, the first of its kind worldwide, will expose companies like Meta (Instagram’s parent company), TikTok and Snapchat to fines of up to AUD $50 million if they fail to keep children under 16 off their platforms.
Instagram’s system, already in use in the United States and expanding to Canada and the United Kingdom, uses behavioural patterns and other signals to estimate a user’s age. Suspected teens are pushed into stricter “Teen Accounts,” which limit features such as live-streaming, filter sensitive material and restrict direct messages. Users can appeal if they are misclassified, but the system is designed to err on the side of caution.
To help ensure as many teens as possible are enrolled in Teen Account settings on @instagram, we’re using AI to detect teens, prompting parents to confirm their teens’ ages online, and giving parents information about the importance of teens providing accurate ages online.… pic.twitter.com/BYgRgA35KD
The X post shows Meta’s push to present age checks as a supportive measure for teens, while also encouraging parents to play a role in how young people use social media.
Meta’s regional policy director, Mia Garlick, said,
“We’ve spent many years and invested heavily to refine our AI technology to identify, in a privacy-preserving way, whether someone is under or over 18”.
Even so, Meta has argued that age checks should sit with app stores like Apple’s App Store and Google Play to create a more consistent solution across the industry.
The government has stressed it does not expect platforms to check every user. eSafety Commissioner Julie Inman Grant said,
“These social media platforms know an awful lot about us. If you have been on, for example, Facebook since 2009, then they know you are over 16. There is no need to verify. We don’t expect that every under-16 account is magically going to disappear on Dec. 10. What we will be looking at is systemic failures to apply the technologies, policies and processes.”
Still, experts are wary of the risks. The National Institute of Standards and Technology (NIST) has cautioned that AI models can create privacy hazards, such as re-identifying individuals from supposedly anonymised data or leaking information from model training. That training data, if exposed, could be a rich target for attackers.
The accuracy of age estimation also remains shaky. It can involve behaviour analysis or even facial recognition, both of which are open to manipulation. It’s important to point out that deepfakes and spoofing methods could bypass such safeguards, undermining confidence in the system and potentially lulling users into a false sense of safety.
Still, cybersecurity experts remain sceptical about the effectiveness and safety of AI-powered age verification systems. Pieter Arntz, a malware intelligence researcher and former Microsoft MVP in consumer security, questions whether age verification genuinely protects children or merely poses another privacy risk.
Joel R. McConvey, writing for Biometric Update, argues that AI-based age inference is “bound to raise new concerns about data privacy, censorship and surveillance”. Simply monitoring behaviour to guess someone’s age amounts to surveillance, and the resulting data could be used for purposes beyond age checks.
As Australia moves into this new regulatory space, the tension between child safety and personal privacy will only grow. Protecting kids online is a goal few would dispute, but the methods chosen could reshape how much of our digital lives are monitored, stored and scrutinised. What happens in Australia will set the tone for how far governments and tech giants are prepared to go in the name of safety.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
Australia is racing to build AI infrastructure, but model control and economic power risk remaining offshore. Albanese’s Office of AI and new data centre standards mark progress, yet foreign-led compute and super fund flows expose a growing sovereignty gap.
We are racing to shape our AI future through a new Office of AI and national standards. Yet billions flow into foreign-led data centres while we offer little support for local models or sovereign compute. Without stronger action we risk becoming high-quality hosts rather than true leaders.
NATO's 2026 Ankara summit placed AI security at the heart of alliance planning, raising urgent questions about autonomous systems, supply chain integrity, and the accountability of military AI as adversaries accelerate their own programmes.
The memory war exposes AI’s harder truth: power now sits in fabs, wafers, export licences and trusted supply. Apple, Micron, Nvidia, China, South Korea and Japan are no longer fighting over chips alone, but over dependence, pricing and the pace of intelligence itself across global markets, in 2026.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!