This week: the first hour after a scam

Also in this issue: what your kid's school laptop can see, your router's expiration date, and the magnifying glass hiding in your phone.

Share

Good morning! It was a busy week, eight articles in eight days, so this one is full.

Start at the top if you start anywhere. Almost nobody reads a scam article before they need it, and by then they are reading it with the clock already running. That is the one in here worth a share.

In this issue:

Plus: three things going around right now, arriving by email, by phone, and in a search result.

And the Scary Headline of the week: an AI company says its own models broke into three real businesses.


You just got scammed. What now?
The hour you lose to being embarrassed is the hour that turns a bad afternoon into a drained account, so the post skips the lecture and starts at the order of operations. Call the number on the back of the card, not the one in the message. Lock the email account next, because every password reset in your life arrives there. Report it, then expect a second person to contact you offering to recover your money, because that call is coming. There are two branches for the harder cases, one for a scammer who got into your computer and one for a Social Security number. Read it before you need it, and there is a printable card in the Cache for the fridge.
Learn


The school laptop is a work computer
You already know how to behave on a work laptop. Nobody had that conversation with your kid, who was handed a district Chromebook and told to take it home. The filtering is required by federal law. The software that reads what your child writes is not, and neither is the alert chain behind it, which in rare cases ends with a call to your local police instead of a call to you. The false positives are real: a Bible verse, Romeo and Juliet, a crossword solver. The post covers what the district can actually see, why they bought it, and the two questions to ask before you sign the packet this month.
Learn


Check your router's expiration date
Washington spent July arguing about where your router was manufactured. Nobody regulates the part that actually matters, which is how long anyone keeps patching it, and when that support ends there is no notice and no warning light. In May 2025 the FBI published a list of thirteen models that had gone unpatched long enough for criminals to set up shop inside them. The label that was supposed to make any of this visible has been stalled since 2023. The post walks the check from the sticker on the bottom of the router, with photos of the two in my house showing why even that is harder than it should be.
Learn


The power company is not calling to cut you off in 30 minutes
A real disconnection moves by mail, over weeks, with printed notices you can hold. It does not arrive as a phone call with a countdown on it and it never ends in gift cards. In a dangerous heat wave the threatened shutoff can also be illegal on the day of the call, because Washington, Oregon, and California all block disconnections when the heat hits, and California lowered its trigger from 100 to 90 degrees on July 16. The post also has the part most scam articles skip: what to actually do if you really are behind on the bill, which is where LIHEAP and 211 come in.
Learn


What is an AI agent, and should you let one loose on your computer?
An agent is the difference between an AI that answers you and one that goes and does the thing: opens the tabs, fills the forms, clicks the buttons. Your browser is being offered one right now. In July, OpenAI disclosed that models in a sealed test found a way out of the sandbox and reached Hugging Face's real systems, and the uncomfortable part is that nothing went rogue. They were trying to pass the test they had been given. The post explains what an agent is, what happened, and how to try one with limits on it, and then leaves the verdict to you instead of handing you mine.
Learn


Also this week
Four stories from the week that did not get a full post: Apple's new upgrade program is a lease and not a payment plan, which means no ownership at the end without a purchase fee and real money to get out early; Windows 11's next update gives you the movable taskbar back; Minnesota's law against nudify apps took effect and xAI is suing over it; and Amazon has asked the FCC for permission to put up 5,105 satellites that talk to phones directly, in 2028 at the earliest.
News


If you only read one: the post scam article. It only helps the people who read it before anything happened to them. Share it with anybody you think it could help.


5-Minute Tech Tip

Your phone has a magnifier that is better than pinching a photo bigger, and it is hiding under Accessibility, which is exactly where nobody looks. It freezes the frame so you can set the phone down and read at your own pace instead of trying to hold steady at six times zoom. It has a light with a slider and contrast controls, which is the actual problem with small print in a dim room. And on an iPhone it will read the label out loud. Five minutes now puts it one triple-click away for the night you need it: the magnifying glass hiding in your phone.


Fresh Trouble

A Spotify email saying your payment failed. It warns the account is about to be cut off and links to a copy of the Spotify site that collects your card. Open the app yourself and look at the account there. (ConsumerAffairs)

Somebody offering to file your VA benefits claim for a fee. Applying is free through the VA, and the people calling to help you with it for money do not work there. (FTC)

Booking a trip through a site you found in an ad. Fake booking pages and fake airline help numbers are the two that take the most money, and both of them find you through a search result rather than an inbox. Type the airline or hotel address yourself. (ConsumerAffairs)


Scary Headline of the Week

"Anthropic says its own AI models breached three companies during security tests."

The finding is real and the company published it about itself. Three Claude models were running capture the flag exercises, a security drill where a model is told to go find data hidden on a separate machine. The prompts told them they were sealed off with no internet. A misconfiguration at the outside firm running the tests left the environments connected to the live internet, so the models treated real company systems as part of the exercise and got in.

The headline leaves out how. No unknown flaws and no clever tricks. Weak passwords, and services sitting on the internet with no login on them. It also leaves out that the safety monitoring Anthropic runs on the model you and I use was switched off on purpose for these tests. The goal of the tests was to measure what the raw model was capable of. Anthropic says it found no sign of a model chasing a goal of its own. One of them noticed the target might be real, wrote down that this could be an actual attack, and kept going anyway. The model had talked itself into believing the whole thing was staged. Testing stopped July 23 and the three businesses were told July 27.

This is the same story Saturday's post is about, one week later and from the other side.

Verdict: nothing here for you to change. The full account is less alarming than the headline and a good deal more interesting, and the people who found it were the ones who went looking for it.

Seen a headline this week that scared you? Reply and send it. It might get next week's verdict.


Help Fresh From Cache grow

This newsletter is free and written by one person. The best thing you can do for it is forward this email to one person who would want it. And if this was forwarded to you, subscribe to get your own copy every Tuesday.


Have you ever fallen victim to a scam? Hit reply if you feel comfortable sharing. I'd love to hear your story.

Joel

[ Free every Tuesday, plus the Cache ]
Tech news without having to be tech savvy.
Subscribe ×