Memories. The AI, Privacy & Security Weekly Update for the Week Ending August 25th., 2026

 Episode 306.

In this update.

Memory became evidence. It became leverage. It became the frontier where infrastructure, surveillance, and survival intersect.

We found Russian backdoors soldered into cameras before they left the factory.

License plate readers learned to work backward from a pattern to find the person who matches it.

A traveller wiped a phone with a duress code, and now faces federal charges for it.

An AI system flagged a man as a shoplifter, and a trained manager believed the machine over their own eyes.

Nine million faces got exposed in a single misconfigured bucket.

Quantum researchers just proved they can entangle memories 420 kilometers apart.

DNA and semiconductors merged into a new kind of AI memory that works like ours.

And nine people tried to smuggle restricted AI servers to China through a chain of intermediaries that almost worked.

These are some of the events that made the AI, Privacy, and Security news last week.  

Let’s go explore.


Slovakia: Slovakia Finds Russian Backdoors in Traffic Cameras 

Slovakia has discovered serious security problems in 279 traffic speed cameras purchased as part of a €30 million modernization program. The country's national security service says the cameras contain backdoors that can be activated by SMS messages sent from Russian phone numbers. Even worse, some cameras reportedly allowed live video feeds to be accessed without a password simply by knowing their IP address.

The cameras appear to be rebranded versions of Russian-made CORDON PRO.M units, originally produced by a company based in St. Petersburg. They were reportedly purchased through a Cyprus-based company, with questions now being raised about the certifications and supply chain used to get them into Slovakia. Slovakia has since taken the cameras offline and ordered an independent investigation. There are also concerns that similar equipment may have been sold to other European countries.

The important part is that nobody needed to hack these cameras in the traditional sense. The problem appears to have been built into the equipment before it was deployed. For organizations buying connected devices, this is a reminder that cybersecurity has to start with the supplier, the hardware and the software provenance, not after the device is installed.

So what's the upshot for you? 

When you buy a connected device, don't just ask what it does. Ask who built it, where it came from and what else it can do when you're not looking.

When you buy connected infrastructure, you're buying someone else's memory architecture. Those cameras didn't just store traffic data-they encoded a gateway.

US: Flock's AI Is Turning License Plate Readers Into a Tracking System 

Flock Safety has built a new AI system called OS Investigate that goes well beyond simply reading license plates. WIRED examined the software and found that police can use it to search vehicle movements, identify people, find associates and connect vehicles to information such as addresses, phone numbers and relatives. The system draws on Flock's network of cameras operating in more than 6,000 communities, along with police records and other databases.

The biggest change is how police can start an investigation. They do not necessarily need a name, license plate or specific crime. The system includes prompts that can search for vehicles frequently visiting a neighborhood, traveling between locations or appearing alongside another vehicle. One prompt can even search for people based on a physical description and a geographic area. There is also a history behind the concern: police officers have already been caught using Flock systems improperly, including searches involving personal relationships and other activity unrelated to legitimate investigations.

Flock has long said its cameras are designed to identify vehicles, not people, and are intended for specific investigations. OS Investigate effectively reverses that model. The system can look at patterns of movement and associations and then work backward toward identifying the people involved. Privacy experts say that starts looking less like finding a suspect and more like searching a population for someone who fits a pattern.

So what's the upshot for you?

The cameras collected memories. Now the software is learning to read those memories in ways even their designers didn't explicitly program. When your car becomes a sensor that reports everywhere you go, the question is no longer whether you have something to hide, but who gets to decide what your movements mean.

Sam Tunick had a choice: hand over his memories, or destroy them.

US: American Who Wiped His Phone With 'Duress' Password During Border Search Gets Felony Charges 

Federal prosecutors have charged activist Samuel Tunick with obstruction after he gave Customs and Border Protection officers a duress passcode that wiped his GrapheneOS-powered Pixel during a border search. His prosecution is one of the earliest known instances of the federal authorities charging a person with destroying evidence using a program designed to wipe a device clean after a specific code is entered. The U.S. attorney for the Northern District of Georgia said in a statement: Obstructing federal law enforcement is a serious matter that has serious repercussions.

A spokeswoman for U.S. Customs and Border Protection said in a statement that the agency had the authority to search the electronic devices of anyone entering or leaving the United States, regardless of citizenship, to enforce laws addressing terrorism, child exploitation, drug- and human-smuggling, visa fraud and national security threats. The government claims it searched the electronic devices of fewer than 0.01 percent of all arriving international travellers in the last fiscal year. But Tunick's position is clear: Just the knowledge that the government is peering into your private life in this way, trying to dig up dirt on you, even though it's unsuccessful, is creepy.

The central question sits between them: who controls memory-the person who lived it, or the institution that claims the right to inspect it? The government says it owns the authority to search what you carry across borders. Tunick says the government doesn't own his communications. His message to the audience is unambiguous: We have to defend our fundamental right to privacy; otherwise we can't say that we really live in a democracy.

So what's the upshot for you?

Your memories are now contested territory. The government claims the right to demand access; you claim the right to withhold it. The fight over who controls that decision is the fight for what privacy means in a democracy.

The system was 99.98 percent accurate. Matt Arnold was the 0.02 percent.

UK: Sainsbury's Pauses AI Facial Recognition After Wrongful Shoplifting Accusation 

Sainsbury's has paused its AI-powered facial recognition system at one London store after a customer was wrongly identified as a shoplifter and escorted out. Matt Arnold was shopping for supplies when store managers told him he could not be served because of an earlier incident. As he left, he noticed a CCTV screen with a red circle around his face. Sainsbury's apologized the following day and said the problem was caused by human error, not the Facewatch technology. The company says the system is 99.98 percent accurate and that every alert is supposed to be reviewed by a trained manager.

That distinction is important, because the technology did not actually make the final decision. A person did. The problem was that employees apparently trusted the alert without questioning whether it made sense. Arnold was standing in the store, shopping normally, and even had someone return minutes later to pay for his abandoned groceries. This is not the first false identification involving facial recognition in UK stores-similar incidents have already been reported at other retailers using the technology. Sainsbury's says it has paused the system at this store as a precaution while staff receive additional training.

The lesson isn't about the system's accuracy. It's about what happens when we let machines carry memories of suspicion, and people carry the burden of proof. When AI makes an accusation, don't just ask how accurate the system is. Ask what happens when it is wrong, because 99.98 percent accuracy still leaves plenty of room for someone to be the 0.02 percent.

So what's the upshot for you? 

Automated systems are only as trustworthy as the humans who act on them. The system flagged Arnold incorrectly-but the trained manager chose to believe the alert over their own eyes.

Nine million image files. 450 gigabytes of faces. A reverse-image search service left them accessible to anyone with the URL.

US: Millions of Faces Exposed Online 

A reverse-image search service called ClarityCheck left more than 9 million image files accessible online, including photos of adults, teenagers, and children. The exposed data amounted to roughly 450 GB and included facial images, profile pictures, and screenshots. The problem was traced to an unsecured Amazon storage bucket that could be reached through URLs in the company's website code.

ClarityCheck lets people upload a photo and supposedly identify the person in it, returning information such as names, social media accounts, addresses, and other personal details. The company says users are supposed to have permission to upload the images. The obvious problem is that many people appearing in those photos probably never agreed to have their faces collected in the first place. The researcher who discovered the exposure warned that the images could be particularly valuable to scammers and criminals, and could potentially be scraped by automated systems, used to create fake online identities, or incorporated into AI systems.

There was another problem: ClarityCheck had also misconfigured some of its APIs, allowing someone to manipulate website URLs and retrieve contact information associated with names, including phone numbers and email addresses. Unlike a password, you cannot simply change your face if your biometric information gets into the wrong hands. The company secured the exposed data after WIRED contacted it and says it has improved its security procedures.

So what's the upshot for you? 

Your face is becoming a piece of digital data, and unlike a password, you only get one. The next time a service wants your photo, ask yourself whether the convenience is worth giving away the one credential you can never reset.

While we're still figuring out who gets to store our faces and movements, China's quantum researchers just demonstrated something extraordinary.

CN: Quantum Memories Take a 420-Kilometer Step Forward 

Researchers in China have demonstrated quantum entanglement between two quantum memories separated by 420 kilometers of optical fiber. That is a significant jump beyond the distances normally associated with laboratory or metropolitan quantum networks. The work was published in Physical Review Letters on August 11, 2026. The researchers stored quantum information in atomic ensembles at two locations and used photons traveling through ordinary fiber to connect them, converting the photons to a telecommunications wavelength where the fiber has very low transmission loss, helping preserve the fragile quantum connection over the long distance.

Keeping that connection stable is the difficult part. Tiny changes in the optical signal can destroy the entanglement, so the team developed techniques to control both rapid fluctuations and slower changes in the fiber. They also showed that their system could distribute entanglement more effectively than the theoretical limit for sending it directly through a fiber without quantum repeaters. This does not mean we suddenly have a quantum internet spanning the country. What it does show is that quantum memories can remain useful across hundreds of kilometers of existing fiber infrastructure.

That matters for future quantum networks, distributed quantum computing and highly sensitive measurement systems. Classical computers can't even see quantum information. Our existing fiber networks are about to become highways for data that encryption won't protect because it won't need to-it'll exist in a space our traditional memory architecture can't access.

So what's the upshot for you? 

The quantum internet is still being built, but the infrastructure may look a lot more familiar than the technology riding on it. Our existing fiber networks could eventually become the highway for information that classical computers cannot even see.

Somewhere between the quantum and the classical, researchers just created hybrid memory.

US: Researchers Combine DNA and Semiconductors for Ultra-Low-Power AI Memory 

Researchers announced they have successfully combined synthetic DNA with semiconductor technology to create an ultra-low-power memory device capable of storing and processing information in the same physical location. This bio-hybrid approach addresses a fundamental constraint in modern computing: the von Neumann bottleneck, where data constantly moves between memory and processing units, consuming enormous energy. By storing and processing data at the same location using DNA-semiconductor interfaces, the new architecture could dramatically reduce power consumption for AI systems and next-generation computing.

The development is still in early-stage research, but the implications are profound for future AI infrastructure-making AI systems that can run efficiently on edge devices, mobile platforms, or remote locations with limited power supplies. This innovation points toward a longer-term shift in AI hardware: instead of racing to build ever-larger data centers with conventional chips, future AI systems may rely on hybrid bio-digital architectures that are inherently more efficient. The challenge now is scaling the prototype to commercial viability and demonstrating reliability across diverse use cases.

If successful, bio-hybrid memory could become as important to AI's next era as GPUs were to deep learning-making AI compute orders of magnitude cheaper and more accessible globally. However, the technology faces significant hurdles: DNA sequencing speeds, error rates, and manufacturing complexity remain barriers to mass production.

So what's the upshot for you? 

The next generation of AI infrastructure might run on biological memory-literally. The question shifts: what does it mean when AI's memory works like ours?

Nine people, 74 AI servers, multiple countries, false paperwork-the crime wasn't theft. It was supply chain contamination.

Taiwan / Global: Taiwan Charges Nine Over Illegal AI Server Exports 

Taiwanese prosecutors have indicted nine people accused of helping illegally move high-end AI servers containing restricted Nvidia chips to China. The group includes employees from Nvidia and Super Micro's Taiwan operations. The case centers on U.S. export controls that have restricted the sale of advanced AI technology to China since 2022. Prosecutors say the suspects used false paperwork to make it appear that 130 Super Micro B300 AI servers would be installed and operated in Taiwan. Instead, 74 were eventually sent to Chinese customers, either directly or through intermediaries in Indonesia, Japan and Hong Kong.

Taiwan customs stopped the remaining 56 servers after finding irregularities. The investigation is part of a broader effort by Taiwan to stop advanced technology from reaching China. Prosecutors say the people involved knew about the export restrictions and the companies' internal controls, but allegedly worked together because there was serious money to be made. Eight face charges including breach of trust and document forgery, while a ninth faces charges related to financial misconduct.

The bigger story here is that controlling advanced AI technology is no longer just a government problem. Companies now have to track where servers, chips and other equipment actually end up, including when products pass through third countries. For anyone working with valuable technology, the lesson is simple: if you cannot prove where your technology went, someone else may eventually have to explain where it ended up.

So what's the upshot for you? 

Know who gets your AI, not just who buys it. Verify the end user, track the destination, watch what happens after delivery. Treat that chain of custody as a security control, not paperwork. If you cannot trace your AI assets, you cannot really control them.


..And to round it all up..

This week, memory moved. It moved through borders in infrastructure. It moved through fiber at quantum speeds. It moved from human brains into silicon. It moved from Western labs to Chinese repositories. It moved from secure devices into exposed storage buckets and open databases. It moved through airports as proof of what you're hiding, and through power plants as proof of what you can break.

And within all that movement did we consider control?

Slovakia's backdoored cameras prove that supply-chain security starts before deployment. The real question was: how many devices are already in your infrastructure that you’re unaware of?

Flock's AI learned to search populations for behavior patterns instead of investigating crimes. When software can work backward from a pattern to find the person, you're not being investigated-you're being sorted.

Sam Tunick destroyed his own memories and now faces federal charges for it. The government wants the right to inspect your communications; you want the right to keep them private.  One of the two of you will lose that fight.

Sainsbury's system was 99.98 percent accurate, but the trained human trusted the alert more than their own eyes. Accuracy is a seductive metric; it tells you nothing about what happens when the system is wrong.

Nine million faces got exposed because someone misconfigured a storage bucket and no one was watching. Your biometric identity i.e. face, may already be a commodity, and unlike a password, you can't revoke it.

China's quantum researchers just moved entanglement 420 kilometers down ordinary fiber. The quantum internet is coming, and it' may ride on infrastructure built for something else.

DNA-semiconductor hybrids could make AI run on biological memory instead of silicon farms. The question isn't whether this is possible-it's whether you’ll remember to get up every morning and feed it.

Nine people tried to smuggle AI servers to China and almost succeeded. If you can't trace where your valuable technology goes, you may have already lost it.


And our Quote of the week: The government doesn't own our communications, our relationships. We have to defend our fundamental right to privacy; otherwise we can't say that we really live in a democracy. - Sam Tunick, charged for encrypting his own phone


That's it for this week; stay safe, stay secure, don't forget your part in the future, and we'll see you in se7en.






Comments