Power plays in AI and cybersecurity: Best infosec long reads 8/1/26
The hacker who humbled spyware makers, China's new AI playbook, Do AI models really reason? The hidden danger of side-channel attacks, Inside Anthropic's legal battle

Happy Saturday to all!
Full access to Metacurity's curated infosec long reads is available to paid subscribers. Our goal is simple: make it financially viable to keep investing the time and expertise required to find, vet, and contextualize the most important security journalism each week. Free readers will still get highlights, but subscribers will get the complete, deeply curated set.
8/1/26: This week's long reads examine the race for advantage in the AI era—from China's push to challenge US dominance with open-weight models and questions about whether today's reasoning models truly understand what they're doing, to the enduring ingenuity of an elusive hacker, the subtle hardware flaws that can betray even well-defended systems, and the growing legal battles over who should control access to the world's most advanced AI technologies.
The hacker who humiliated spyware makers and was never caught
TechCrunch's Lorenzo Franceschi-Bicchiera recounts the exploits of the elusive hacktivist Phineas Fisher, whose attacks on commercial spyware vendors exposed the industry's vulnerabilities while leaving investigators unable to identify the person behind the pseudonym.
Variously called an anarchist, a cybercriminal, a hacktivist, and a vigilante, the hacker has said they “use a lot of different names” for different hacking escapades.
The hacks we know about were big enough to turn Phineas into a legend among hackers. “I would like to meet Phineas Fisher so that I could buy them a seven-course, three-Michelin-star dinner somewhere and listen to them explain how they turned Hacking Team inside out like a gym sock,” a well-known security researcher once wrote on Twitter. There’s even a song about them.
Phineas first emerged in August 2014, when they announced they had hacked Gamma Group, the makers of the FinFisher spyware — which is where the nickname comes from. They publicized the hack via a Twitter account cheekily called @GammaGroupPR, leaking stolen data, including mobile spyware, product manuals, and a price list. The damage was limited, and FinFisher carried on. Phineas published a postmortem that doubled as a leftist manifesto, then vanished.
A year later, they came back with a bang, hacking Hacking Team, another spyware maker. They took practically everything: more than 400 gigabytes, including source code, tens of thousands of internal emails, confidential contracts, and customer lists. The leak allowed journalists to reveal scandals in Ecuador, Mexico, and Panama. Years later, Hacking Team’s CEO David Vincenzetti was forced to sell his company for one euro. For some former employees, Phineas’ hack was the beginning of the end.
Phineas went on to hack the union of the Mossos d’Esquadra, which is the police force of Catalonia, publishing a postmortem and a 39-minute tutorial video — consistent with their stated anti-police ideals. Their next victim was the ruling party of Turkey’s authoritarian president Recep Tayyip Erdoğan, a hack motivated by solidarity with Rojava, a leftist autonomous region in northern and eastern Syria that Turkey was fighting against.
Phineas’ last known victim was Cayman National Bank’s branch in the Isle of Man, a self-governing island between England and Ireland. The hack hinted at a different side of Phineas. “I look for illegal ways to make money in order to free my time so I can do something useful with it. Once I had that figured out, I started scaling it up and making more money than I need and giving the extra away,” Phineas said in an interview with activist Freddy Martinez. (Phineas donated at least $10,000 in Bitcoin to Rojava.)