The map your robot vacuum made of your house, the camera reading your license plate, and a deepfake takedown that costs nothing

Also in this issue: the Odyssey streaming scams, the AI habits that actually pay off, something new on Fridays, and how to make your phone stop ringing for robocalls.

Share

I did not plan a week about being watched. It came out that way. A vacuum with a floor plan of your living room, a camera on a pole with your plate number, an AI video wearing your face. The one piece of good news is the first one: the vacuum flaw that scared me when I wrote it up got fixed this week, and nobody had to lift a finger.

In this issue:

Plus: three scams going around right now, arriving by text, by Facebook message, and in your actual mailbox.

And the Scary Headline of the week: a browser extension sitting on 329 million machines could read your WhatsApp messages.


Shark fixed the vacuum flaw. Here's what yours knows about you.
A researcher spent four months trying to hand SharkNinja a flaw before he published it on July 13. He unscrewed a Shark robot vacuum he owned, pulled the security certificate out of it, and found the same certificate worked on other people's. With it he opened a second vacuum's camera while it drove around, read the map of the house it had been cleaning, and pulled the Wi-Fi password out in plain text. Listening for 24 hours, he counted more than 1.5 million Shark vacuums checking in, and about 673,000 answered a command he sent. Here is what changed since I first wrote this up: Shark fixed it on July 20, on their own servers, so there is nothing for you to unplug or update. It is still worth two minutes because of what it shows about how much a robot on your floor knows, and how little say you had over who could reach it.

Learn


What a Flock camera actually does
That small black box on a pole with the solar panel bolted beside it, the one you have probably driven past a hundred times, is an automatic license plate reader. It photographs every car that passes, reads the plate, and files it with the date, the time, the location, and a description of the car in a database your police department can search. The description goes further than the plate: make, model, color, roof rack, bumper sticker, the dent you keep meaning to fix. Records are kept 30 days by default, and that number is a contract setting, which is how Flagstaff got theirs down to 14.

Learn


How to get a deepfake of you taken down
Last week's issue ended the deepfake block on a bad number: cleanup firms quote nine to twenty thousand dollars. Here is the version that costs nothing. Everything starts before you touch a report button. Screenshot the post, the account, and the comments. Screen-record the video, because a screenshot of a video proves one frame. Copy the links into a note with the date you found each one. If it is running as an ad, Meta's Ad Library shows you who paid for it. From there the path depends on what the fake is doing, and the post ranks the platforms by which ones actually move. Bookmark it for the day that hopefully never comes.

Learn


The Odyssey hit theaters Friday. The scams were ready by Monday.
Two traps, both waiting for whoever types "watch The Odyssey free" into a search box, which in a lot of houses is not the adult. The first is a pop-up on a cloned torrent site reading "Browser Issue Detected" with a "Fix It Now" button. The warning is drawn by the webpage itself, which is why your browser lets it through. The second is a download listed as a 1080p copy with 597 seeders, wearing VLC's orange traffic cone icon, and underneath it is a Windows program. Two rules cover both: a movie still in theaters has no legal free stream anywhere, and a movie never arrives as something you install.

News


AI tips for people who don't want to get left behind
The three complaints are always the same. The writing comes out generic, the whole thing feels clunky, and sometimes it makes things up. All three are fair. Most of the first one goes away once you stop treating AI as a search box you visit and give it a home instead. Every major tool now has a workspace you load once with what you do, who it is for, and a few examples of your own writing, and every chat you start inside it already knows all of that. ChatGPT and Claude call them projects. Gemini calls them Gems. That is one habit of seven in the post, and each one comes with why it works.

Blog


Something new on Fridays
I can't write a full post about everything that happens in tech in a week, and you don't have time to read one. So Fridays now get a short roundup: the handful of stories that actually reach everyday people, a sentence or two on why you should care, and a link to whoever reported it well. The first one covered rival Android app stores, the Siri public beta, and why phones are about to get more expensive.

News


If you only read one: the AI tips. Everything else in this issue is something happening to you. That one is something you can pick up on a Tuesday night and use on Wednesday.


5-Minute Tech Tip

Your phone can screen the numbers you don't recognize instead of ringing for them. On a recent iPhone, Settings has an option to make unknown callers state their business before your phone makes a sound, and you get to read what they said. On Android, the Google Phone app and Samsung's dialer each have spam filtering that has to be switched on. Screening beats blocking every unknown number outright, because blocking everything also silences the school, the pharmacy, the delivery driver, and the plumber you called this morning: Make your phone stop ringing for robocalls.


Fresh Trouble

A purchase you didn't make. A text or email saying a laptop or a TV was just charged to your account, with a number to call and cancel it. Open the real app and look. The charge is usually not there. (ConsumerAffairs)

The FBI offering to get your money back. A message on Facebook or Telegram following up on a fraud report you filed, sometimes with video of what looks like a senior FBI official. The bureau's complaint center has no social accounts and will not message you. (FBI)

A letter about unclaimed life insurance. A law firm writes that someone who shares your last name died and left millions, and offers to split it with you. The FTC says this one is back after a few years off. (FTC)


Scary Headline of the Week

"Adobe Chrome extension flaw let sites access private WhatsApp chats."

The finding is real. Researchers at Guardio Labs found a chain of bugs in Adobe's Acrobat extension for Chrome, the PDF one sitting on roughly 329 million browsers. Visiting the wrong page was enough for that page to reach into WhatsApp Web in another tab and read your chat list, your contacts, and whatever conversation you had open.

The headline leaves out that Adobe patched it over a single weekend, the fix installs itself, and the researchers found no sign anybody used it before the patch landed. There was also no hole in WhatsApp. The weak point was the extension.

A browser extension is software with permission to read every tab you open, which is the same reason Microsoft pulled 119 Edge extensions for malware last month. Open your extensions list this week and remove anything you don't remember adding.

Verdict: already fixed, but a good excuse to clean out your extensions.

Seen a headline this week that scared you? Reply and send it. It might get next week's verdict.


Help Fresh From Cache grow

This newsletter is free and written by one person. If it earns its spot in your inbox, two ways to help that won't cost you anything: forward it to someone who could use it, and if it was forwarded to you, subscribe to get your own copy every Tuesday.


Do you own a Shark vacuum, and did you unplug it when this first went around? Hit reply and tell me.

Joel

[ Free every Tuesday, plus the Cache ]
Tech news without having to be tech savvy.
Subscribe ×