7 Best Outdoor Security Cameras (2026) After Testing Dozens



Compare The Top 7 Security Cameras


Best MicroSD Cards

Some security cameras support local storage, enabling you to record videos on the camera or a linked hub. A few hubs have built-in storage, and some provide slots for hard drives, but most rely on microSD cards. This is a quick guide on what to look for (plus some recommendations).

The microSD card you choose should have fast read and write speeds so you can record high-quality video and play it back without delay. I recommend going for Class 10 microSD cards rated as U1 or U3. You can dive deeper into what that means in our SD card explainer. Before you buy, check the card type, format, and maximum supported card size for your security camera. Consider how many hours of video each card capacity can store. For example, you might get a couple of days of HD video on a 32-GB card. If you want to record continuously, you likely want a higher-capacity card.

Samsung Pro Endurance Micro SD Card on blue backdrop

Courtesy of Samsung

I recommend formatting the card as soon as you insert it into the camera. You will usually be prompted to do this, but if not, there is generally an option in the settings. Just remember, formatting will wipe anything on the microSD card, so back up the contents first.

Some security camera manufacturers offer their own branded microSD cards. They work just fine, but for maximum reliability, I’d suggest one of the following options. Remember to always check the specs. Even different sizes of cards in the same range often have different capabilities.

Note: Memory card prices have gone crazy due to the AI chip shortage, so you may want to wait or shop around, as some of these cards are four times the usual price.


Other Good Outdoor Security Cameras I’ve Tested

I’ve tested several other outdoor security cameras. These are the ones I like, but they just missed out on a place above. Some of our indoor camera picks can also be used outdoors.

White cylindrical outdoor security camera attached to a reddish brown wood fence

Photograph: Simon Hill

Eufy Eufycam C37 for $90: If you want a pan-and-tilt camera but find the EufyCam S4 too pricey, the C37 is worth considering. The 2K footage is clear, it can pan through 360 degrees, the automatic subject tracking works well, and you can record locally with a microSD card (sold separately) or hook it up to Eufy’s HomeBase Mini or HomeBase 3. You also get reasonably accurate onboard AI that can identify people, vehicles, and pets. The detachable solar panel is a welcome inclusion and keeps the battery topped off. On the downside, it took me several attempts to update the firmware (connectivity is 2.4 GHz Wi-Fi), my test unit had trouble staying connected, and it sometimes refused to load the live feed. It worked far more reliably when connected to the HomeBase 3.

Baseus Security X1 Pro Outdoor Dual Camera for $150: With dual 3K lenses and the ability to pan through 300 degrees, this feature-packed camera looks interesting. It can record locally on a microSD card, has a sun-tracking solar panel (which is a bit gimmicky), onboard AI detection, and supports patrolling and automatic subject tracking. But it sometimes failed to detect motion events in my tests, randomly lost connectivity a couple of times, and frequently took a while to load the live feed.

Wyze Window Cam for $35: If you can’t fit a camera on your exterior for some reason, this could be a handy option because it sticks directly to the inside of your window. You must run the 10-foot power cord to an outlet, which doesn’t look pretty, but it will afford you a decent view with minimal glare, though it’s only 1080p and can’t compete with the cameras above on picture quality. It’s quick and easy to set up, and you can record locally on a microSD card, but you can’t really angle it, so you need a good spot to make it worthwhile.

TP-Link Tapo C675D for $230: I’m a little disappointed by TP-Link’s newer Tapo cameras, and the C675D is no exception. On paper, a dual-lens 4K camera with automatic subject tracking and zoom, local recording, and a solar panel sounds great at this price, but real-life performance was underwhelming. The frame rate is only 15, so the footage is often blurry. It also lacks HDR, and I experienced intermittent connectivity issues. I’d rather have 2K with a higher frame rate and HDR. Sure, you can zoom in and read a distant license plate, if that’s important to you, but moving subjects are not as clear, and the camera is so slow it sometimes misses the action. I don’t mind cloud storage and advanced AI being subscription-only, but I’m annoyed that TP-Link paywalls snapshot notifications and smart filters. All that said, there’s some impressive hardware here at a lower price than competitors, and it could work well in the right spot (shaded under eaves at a corner).

Image may contain Person and Security

Photograph: Simon Hill

Reolink Altas PT Ultra for $220: This battery-powered camera supports continuous recording in up to 4K resolution. It can pan 355 degrees and tilt 90 degrees, supports Wi-Fi 6 (2.4 or 5 GHz), and has a versatile L-shaped bracket for installation on a wall or roof. It is bulkier than your average security camera because of the whopping 20,000-mAh battery. The optional solar panel will keep it topped up if you live somewhere sunny enough. You can record locally to a microSD card, Reolink Home Hub, or opt for cloud storage starting from $3.50 per month. The continuous recording captures low-frame-rate footage (5 fps by default, but you can select 1, 2, or 10), and the camera kicks up to its full frame rate when motion is detected, but it only maxes out at 15 fps, so it’s often blurry. The 10 prerecorded seconds on each clip can be handy, and the footage is generally decent, though the camera could benefit from HDR to prevent bright areas from blowing out. The color night vision is good if there’s at least a little light, and there’s a spotlight if you prefer. The two-way audio can be a little laggy, but the live stream usually loads quickly, and the camera sends accurate alerts. It can recognize people, vehicles, and animals and automatically track them before returning to its starting position.

Arlo Go 2 (Battery) for $200: If you need a security camera in an area with patchy or no Wi-Fi, go with the Arlo Go 2. It boasts 4G LTE support, and in the US, you can get service from T-Mobile, Verizon, AT&T, Cellcom, or UScellular. You can take it camping, use it with your RV, or install it in another remote spot you want to keep an eye on. Video quality is solid but limited to 1080p to keep the data requirements under control. There’s also two-way audio, a siren, a spotlight for color night vision, and optional local storage with a microSD card (sold separately). The camera is IP65-rated and completely wireless, with a hefty battery inside (mine was at 39 percent after two months). If you’re worried about charging it, you can buy a solar panel ($60) accessory. It employs the same excellent app as my top pick, with smart alerts and rich notifications, so you can filter for people, animals, vehicles, and packages. Alerts are swift and accurate in my testing, but your mileage will vary based on local signal strength. You will need an Arlo Secure plan, which can get expensive. Video recorded on the microSD card cannot be accessed remotely; it’s more of a backup that you can check later if required. One thing that elevates this camera over many other LTE cameras is that it supports Wi-Fi and automatically connects where it’s available, which is ideal for RV owners.

7 Best Outdoor Security Cameras  After Testing Dozens

Photograph: Simon Hill

Eufy S4 Max for $1,500: Eufy’s high-end NVR (network video recorder) package is an impressively versatile home security system that keeps everything local, but it’s overkill for the average home (it puts Tony Montana’s setup to shame). This pricey kit includes an NVR with 2 TB of storage (expandable to 16 TB and 16 channels) and four of its clever new pan/tilt, triple-lens S4 cameras that connect via Ethernet cable (each one requires two channels). As an 8-port PoE system, a single cable transfers data and delivers power, but you must run separate cables to each camera. The camera is an enhanced version of our pan/tilt pick above, adding a fixed 4K camera with a 122-degree field of view above dual 2K pan/tilt lenses that can track subjects and zoom up to 8X. The onboard AI is solid, offering accurate subject detection and tracking across your cameras, though the face recognition sometimes gets it wrong. Handily, you can search footage with keywords, and it’s all handled locally. You can reduce the price by mixing and matching different camera types, and add-on cameras are available.

Arlo Essential Pan Tilt Security Camera for $60: Surprisingly affordable, this camera is easy to recommend for anyone with an Arlo system. It can pan through 360 degrees and tilt close to 180 degrees, serves up clear 2K footage, and benefits from Arlo’s smart detection and reliable alerts, though you do need a subscription to make it worth buying. At $10 per month for a single camera, it’s very expensive, though it makes more sense if you have multiple cameras since $20 a month covers unlimited devices (you can bring those prices down to $8 a month and $18 a month if you pay annually). The motion tracking is good, but I worry a little about the longevity, and this camera doesn’t have an IP rating (it’s just described as weather-resistant).

Blink Mini Arc for $100: The Blink Arc is a smart bit of innovation in the form of a plastic mount that holds two Blink Mini 2K+ or Mini 2 cameras and stitches the footage together in the software to give you a 180-degree view that’s perfect for covering a complete side of your house. On the downside, you must plug the cameras in, which means running a power cable, and you must subscribe to Blink Plus ($12 per month or $120 a year) to get the panoramic stitched together view. If you already have the Mini 2K+ cameras, you can just buy the mount ($20). Either way, you’ll need the Blink Weather-Resistant Power Adapter ($10) to use this outdoors. If you’re already invested in Blink, this could be worthwhile, but if you just want a 180-degree camera, the Reolink Argus 4 Pro recommended above is a better bet for most folks.

Eufy C35 2-Cam Kit for $200: For folks with modest needs, this is a very affordable kit that sets you up with two cameras and a local hub with 8 GB of storage (expandable to 1 TB). The cameras are compact, with a lovely magnetic mount that makes installation a breeze, but the resolution is just 1080p, the frame rate is 15 fps, and there’s no HDR, so footage can be a bit blurry or overexposed at times. Eufy’s app is solid and feature-rich without the need for a subscription. Watch out for frequent discounts that make this kit a real bargain.

Google Nest Cam (Battery, Outdoor) for $180: If you can’t run a power cable, this battery-powered camera is easy enough for renters to install, with a proprietary magnetic mount to customize the angle. The 130-degree field of view encompassed my driveway, front door, and most of my front yard. It captures sharp 1080p video with HDR and night vision, and it has a clear speaker and microphone. The alerts are seamless, and the motion detector was accurate and sensitive enough to tell that the slight whisk of a passing ponytail was a person. You should also consider the Nest Cam with Floodlight. WIRED editor Julian Chokkattu has been using it for more than two years with no problems. While it’s the same battery-powered camera, it needs to be hardwired to power the lights (and keep the battery running). Just like the Nest Cam above, you need a Google Home Premium subscription, from $10 per month, to unlock smart features and cloud storage (you only get three hours of video history without a subscription).

Image may contain Person and Security

Photograph: Simon Hill

TP-Link Tapo C660 for $170: I was excited to try TP-Link’s line of Tapo cameras, and the C660 immediately jumped out with some compelling features. Offering 4K footage, 360-degree pan and 90-degree tilt, a 10,000-mAh battery, a sizable solar panel, and local storage on a microSD card, the C660 is a solid choice for hard-to-reach areas. To sweeten the deal, it has on-device AI detection and dual-band Wi-Fi support, and it can record continuously at 1 fps (you can up the capture interval to every 5, 10, 20, 30, or 60 seconds). Sadly, I found the tracking was flaky, moving subjects at night often appeared blurry (the frame rate is 15 to 20 fps), and the sound was tinny and echoey. The camera has to be mounted quite high, as it’s angled down, and I have concerns about continuous recording and battery life in the winter. It handled a router change without issue, staying connected, and despite a few false positives, the AI detection works well, and the app loads swiftly. For some folks, it may be a better option than our pan/tilt recommendations above.

TP-Link Tapo HybridCam Duo C246D for $70: Undeniably great value, this dual-lens pan-and-tilt camera from TP-Link is worth a look. The versatile design allows for indoor or outdoor use, and you can sit the camera on a table or shelf or mount it the other way round using the supplied bracket. The only complication for outdoor use is the need to run the USB-C power cable to an outlet. There’s a 2K fixed lens with a 130-degree field of view and a second 2K telephoto lens that can pan 360 degrees and tilt 135 degrees. You can insert a microSD card if you want to record locally, and there’s on-device AI detection that works pretty well (I did get the odd false positive). The automatic tracking is quite good but not perfect, especially at night. Fast-moving subjects can appear blurry, and the frame rate maxes out at 15 fps.

TP-Link Tapo C325WB for $70: Our hardwired camera pick for a long time, the C325WB boasts a large aperture and image sensor that enables color nighttime footage without a spotlight, making it ideal for dark corridors and side passages. It also has a motion-triggered spotlight. You can filter for people, pets, or vehicles, and set up private zones in the Tapo app. This camera is weatherproof with an IP66 rating and can take up to 512 GB microSD cards for local recordings. By default, the camera mostly records at 720p, so you need to dig into the settings to push the resolution to 2K and turn on HDR, or you can expect choppy, overexposed video. I also had to reduce the motion-detection sensitivity to prevent false positives, and the onboard AI is flaky, frequently identifying my cat as a person. While the feed was mostly quick to load in the Tapo app, it was sometimes slow or failed to load on my Nest Hub. There’s an Ethernet port here, too, but sadly, no PoE (power over Ethernet) support. Cloud storage is an option with Tapo Care (from $3.50 monthly for a single camera).

Image may contain Electronics Wood Bench Furniture and Hardware

Photograph: Simon Hill

Swann MaxRanger 4K 2-Camera Kit for $462: This kit was very easy to set up, as the cameras come paired with the hub, so you just need to plug the hub into your router. The 4K video is crisp and clear with vibrant colors, and the cameras worked well day or night. The main selling point is range, and I was able to put a camera at the bottom of my garden, which is too far away for most security cameras to work well. I also love that you can see multiple feeds simultaneously in the app, and the hub has a backup battery, just in case the power goes out. But the solar panels on top of these cameras don’t seem to work well, and one of the cameras drained quite quickly, even with ample sunlight. I also had to turn off and reconnect the system after changing my router, despite having the same network name and details. While it was generally quick, the feed sometimes took a while and, on one occasion, completely refused to load, so I have concerns about consistency.

Imilab EC6 Panorama for $170: This interesting camera combines a 180-degree view created by stitching two lenses together, like the Reolink Argus 4 Pro above, with pan (344 degrees) and tilt (90 degrees) functionality to give an expansive view that might usually require multiple cameras. It’s large and designed to sit under your eaves, but you will also have to run a power cable, as there’s no battery. You get decent 3.5K quality footage and infrared night vision. It works with Xiaomi’s Home app, and you can record locally on a microSD card. There is on-device AI detection for people and vehicles, and the camera can automatically track subjects, though it doesn’t always work well, especially at night. Daytime footage is also much better than nighttime, even with the spotlight to enable color capture.

Eufy Security Solar Wall Light Cam S120 for $100: In the right spot, this weather-resistant security camera and motion-activated light from Eufy is an excellent set-and-forget device. It records 2K video on 8 GB of built-in storage, has a 300-lumen, motion-activated light, and a solar panel to keep it charged up (it needs two hours of sunlight a day to stay charged). The camera is not Eufy’s best, as it’s limited to a 120-degree field of view, it doesn’t have HDR, and the frame rate is only 15 fps. The footage is reasonably crisp when you set the resolution to 2K, and alerts come through reliably and swiftly. You can also set privacy and activity zones in the app, set detection to human-only, and tweak how the light works. The S120 has an alarm built in, offers reasonable two-way audio (though only one way at a time), and has night vision. The S120 is a little slower to load than the other Eufy cameras I recommend here, and it sometimes misses the beginning, starting the video with subjects already halfway across the frame. But as a one-off purchase, with no need for a subscription, it will suit some folks.

Philips Hue Secure Camera for $99: Homes kitted out with Philips Hue smart lights may find the company’s security camera range interesting. The Philips Hue Secure Wired Camera (7/10, WIRED Recommends) is quick and easy to add to the Hue app, offers crisp 1080p video, and is weatherproof, with an IP65 rating. It offers a fairly expansive 140-degree field of view, two-way audio, and a siren, and is quick to send motion alerts. The live feed loads swiftly in the Hue app. You now get 24 hours of video history included, but you must subscribe for $4 per month ($40/year) for a single camera to get 30 days of cloud storage and unlock smart detection features. You can set up privacy and activity zones, and filter by person, animal, vehicle, and package. The AI performed well for me, and all video is end-to-end encrypted (there’s no local storage option). If you have a Hue Bridge, you can have the cameras trigger your indoor or outdoor lighting. The Battery camera drained by only 12 percent in the first two weeks (on course for between three and four months), but then it seemed to die overnight. I have since recharged (which took more than eight hours), and it seems to be working normally. Ultimately, the wired camera works better, but both are unreliable when it comes to alerts, sometimes missing events that other cameras caught, so they’re only worth considering for Hue fans. Philips Hue has also announced a new 2K range, but we haven’t tested them yet.

Image may contain Electronics Person Bench and Furniture

Photograph: Simon Hill

Baseus S2 4K for $80: This camera has two lenses (a regular wide-angle and a telephoto for close-ups), which is an interesting idea but requires careful placement. The footage is good at up to 4K but only 15 fps, and there’s no color night vision without the spotlight. It records locally to a microSD card (up to 512 GB). The cameras can’t move, but the solar panel on top can rotate to catch more rays. While mine stayed topped up, this feels a bit gimmicky. There is human and vehicle detection, but I got several false positives (cats flagged as humans), and it sometimes alerted me, but failed to record video clips. The two-way audio is good. While this system doesn’t match the EufyCam S3 Pro above, it is cheaper.

Reolink Duo 3 PoE for $200 or Duo 3 Wi-Fi for $220: Most folks seeking a dual-lens camera that stitches together for a 180-degree view should opt for the Reolink Argus 4 Pro listed above, but if you can run an Ethernet or power cable, you could save some money with the Duo 3. It also offers a higher resolution than the Argus, but it only has color night vision with a spotlight. The Wi-Fi version only needs a power cable, but annoyingly, you do have to plug in via Ethernet during the initial setup. Both versions work well and use the same app as the Reolink cameras above.

Annke NightChroma NCD800 for $280: Probably best suited for a small business, this PoE dual-lens camera offers clear 4K footage and color night vision. It stitches the two images to give you a complete 180-degree view. There is built-in AI human and vehicle detection, and Annke claims it can learn to disregard waving branches, raindrops, and other false positives. There’s a spotlight that can strobe along with the siren sounding to scare intruders away, decent two-way audio, and local recording via NVR, NAS, or microSD card. Setup is tricky, and you need to run an Ethernet cable to the camera as there’s no battery or Wi-Fi.

Logitech Circle View for $160: There are some big caveats to this camera, including the permanently attached 10-foot power cord that’s not weatherproof, the need for a HomeKit hub, such as HomePod Mini or Apple TV, and zero compatibility with Android. If none of that fazes you, then it’s a solid outdoor camera for privacy-minded folks. It doesn’t have a separate app of its own; you add it directly in Apple’s Home app by scanning a QR code. It captures Full HD video and boasts an extremely wide 180-degree field of view, though there’s a bit of a fish-eye effect here. (The lack of HDR also means areas are sometimes too dark or blown out.) There’s motion detection, two-way audio, and decent night vision, and you can ask Siri to display the live feed, which loads quickly.

Annke C800 for $90: This is a solid PoE (Power-over-Ethernet) camera that supports the Real-Time Streaming Protocol (RTSP) and Open Network Video Interface Forum (ONVIF), making it a good choice for folks with a network video recorder (NVR), though it also has a microSD card (up to 512 GB) slot for local recording. The footage is crisp at up to 4K with a 123-degree field of view, and there’s color night vision, with black-and-white and a spotlight as backups. Installation may be tricky as you must run an Ethernet cable, but that means no worries about power and no Wi-Fi woes. I tested the turret version, but this camera also comes in a dome or bullet shape. The motion detection is quite good, with minimal false positives, and the camera recognizes humans and vehicles reasonably accurately. Annke’s software is a bit clunky, though.

Image may contain Electronics

Photograph: Simon Hill

Safemo Set P1 (2-Pack) for $250: I love the idea of a simple kit like this, where you just plug the hub in, connect it to your router, and install the pre-paired cameras. Each has an optional solar panel to keep the battery charged. The Safemo app is well-designed, video goes up to 4K, and this entirely local system boasts 32 GB of storage (expandable up to 4 TB). It even has locally processed person, vehicle, pet, and package detection. The person detection was mostly accurate (it occasionally flagged my cat), and the vehicle detection flagged my robot lawnmower (close enough) and an inflatable donut that blew across the backyard, but false positives were rare. What prevents me from wholeheartedly recommending this impressive debut is the lack of 2FA (Safemo says it is coming) and connectivity issues, where one of the cameras would occasionally disconnect from the hub and be inaccessible in the app. This always righted itself without me moving anything, but worryingly, it happened a few times. If you plan to up the resolution to 4K from the default SD, you will need fast internet, especially to view the live feed, which I found was choppy and pixelated at 4K, though recorded videos were sharp and detailed.

Imilab EC6 Dual 2K WiFi Plug-in Spotlight Camera for $140: With dual 2K lenses, this security camera can cover a fixed spot and simultaneously track a subject. The bottom camera offers pan/tilt controls. It works via the Xiaomi Home app, making it an easier sell if you already have a Xiaomi phone or other gadgets from the Chinese brand. You can insert a microSD card for local storage or subscribe to cloud storage. The person detection and tracking worked well in my tests. The video was mostly crisp, but movement was sometimes a bit jerky, and fast-moving subjects can get blurry. It does have WDR, but could use HDR to prevent bright areas from blowing out.

Reolink Go PT Ultra for $230: If you need a wireless security camera that can connect to cellular 3G or 4G LTE networks, you could do worse than this offering from Reolink. It’s a pan-and-tilt camera that can record up to 4K video on a local microSD card (sold separately), or you can subscribe for cloud storage. It has a wee spotlight and decent color night vision, and it comes with a solar panel to keep the battery topped up. The detection is reliable, but it doesn’t always categorize subjects correctly. Loading time and lag will depend on the strength of the signal. Just make sure you check carrier compatibility and get a SIM card before you buy.

Swann AllSecure650 4 Camera Kit for $700: This kit includes four wireless, battery-powered cameras and a network video recorder (NVR) that can plug into a TV or monitor via HDMI. The cameras can record up to 2K, and footage is crisp and detailed enough to zoom in on, though there is a mild fish-eye effect. The night vision is reasonably good, but the two-way audio lags and sounds distorted. I like the option to view all camera feeds simultaneously, the backup battery in the NVR makes it a cinch to swap batteries when a camera is running low, and everything is local with no need for a subscription. Unfortunately, the mobile app is poor, camera feeds sometimes take several seconds to load, and there doesn’t seem to be any 2FA. The NVR interface is also clunky to navigate with the provided mouse.

Wyze Cam Outdoor V2 for $90: This was our budget camera pick, offering 1080p with a 110-degree field of view. It comes with a base station that takes a microSD card (not included) for local video recording. If you prefer the cloud, you can pay $24 per year for unlimited video length and no cooldowns, along with other perks like person detection. The stated battery life is between three and six months, but mine needed a charge before it reached three. This camera model was not one of those affected by the security flaw that Wyze failed to fix or report to customers for three years, but repeated security breaches from Wyze, exposing thousands of camera feeds to other customers, may still give you pause. We have started testing Wyze cameras again after the firm beefed up its security policies.

I have also tested the Wyze Cam OG ($30) and Wyze Cam OG Telephoto ($40), an interesting pair of affordable cameras that work well together. The OG gives you a 120-degree wide view and sports a spotlight, and the OG Telephoto has a 3X optical zoom. For example, you might have the OG cover your backyard and use the Telephoto to focus on the gate area, and you can set up a picture-in-picture view in the Wyze app. Both are IP65-rated, but if you want to use an outdoor socket, you have to buy the Wyze Outdoor Power Adapter ($16).


Don’t Buy These Security Cameras

I didn’t like every camera I tested. These are the ones to avoid.

Image may contain Person Security Electronics and Speaker

Photograph: Simon Hill

Night Owl Solar Wi-Fi Battery Camera: Offering decent 2K video, a built-in solar panel to keep the battery topped up, and local storage on a microSD card or Night Owl hub (sold separately), this seems compelling for the price. Sadly, the app is a mess, and I ran into a weird issue immediately with account creation, where I got stuck in a loop of “Account doesn’t exist,” but it wouldn’t let me sign up with another email because my phone number had been used. I got around it with fresh details, but then the camera disconnected when I changed my router (same details) without any warning, and refused to reconnect until I reset it.

Black angular outdoor security camera with antenna attached to wooden fence

Photograph: Simon Hill

Vosker VKX: Sometimes you need a security camera in a location without Wi-Fi, so something like the Vosker VKX with 4G LTE connectivity could be handy. With a durable design, including a built-in solar panel, my first impression was good. The camera provided regular snapshots of my chosen test area at the far end of my backyard. You can schedule the camera, and it has a built-in deterrent light, but there is no subject recognition, so any motion will trigger it (you can tweak the sensitivity). The still images looked fine, but the video was choppy, with bright areas completely blown out. Sadly, you have to change modes to record video, and my video tests failed with no explanation around half the time. You cannot stream live video from this camera, and it requires an expensive plan (starting from $10 per month). The basic plan limits you to 500 alerts and just 10 downloads. You need to upgrade to Elite at $20 a month for unlimited alerts and 40 downloads. It seems like a terrible deal when any motion can trigger an alert.

Baseus N1 2K HD 2-Cam Kit: This kit from Baseus includes two security cameras and a base station with 16 GB of storage (expandable to 16 TB) for local recordings (no cloud option). The camera was easy to set up and sent alerts for most motion events, but the human detection was inaccurate, sometimes erroneously suggesting a human and sometimes ignoring actual people. The app is relatively barebones, and there is no 2FA. Although it does record up to 2K footage, the relatively low frame rate (15 fps) and lack of HDR can make for blurry, blown-out video. Tapping on notifications annoyingly does not load the video clip or the live view, making it slow to use. Baseus is new to security cameras, and it shows.

Noorio Spotlight Cam B210: This orb-shaped wireless security camera comes with a magnetic mount for easy positioning. The 2K video is reasonably sharp, but I found that bright sun completely blew out areas of the footage. The 16 GB of built-in storage is welcome, but I had some connection issues where the camera went offline without alerting me, and recorded clips sometimes refused to play back. I also tested the similar, cheaper B200 ($70), which maxes out at 1080p and has 8 GB of storage, and the more expensive Noorio Floodlight Cam B310 ($110), which adds a 600-lumen floodlight, but both cameras had the same connectivity issues.

Winees L1: This is an affordable outdoor security camera that comes with a solar panel, can record up to 2K video, and has 8 GB of storage onboard. There’s no need for a subscription, and it’s a pretty complete package. You even get on-board human, pet, and vehicle detection, though I found it a bit flaky. Unfortunately, this camera was often slow to start recording, so clips began with the subject halfway through the frame. The AiDot app that you use with this camera is also quite confusing, as it is designed to control a host of smart home devices.

Encalife Outdoor Wi-Fi Security Camera: This affordable tethered camera must be plugged into an outlet. It connects via Wi-Fi or Ethernet cable, offers reasonably clear 1080p footage, and has pan, tilt, and zoom capabilities. You can record locally on a microSD card (sold separately) or sign up for cloud storage, but the iCSee app is flaky and lacks 2FA, so I have concerns about how secure it is. I also tested the more expensive Encalife Smart Surveillance Camera, which adds two-way audio but relies on the same flawed app, and the Encalife 4G Security Camera, which employs the even worse CamHi Pro app.

Switchbot Outdoor Spotlight Cam: Simple to set up, this orb-shaped camera offers 1080p footage that is reasonably good quality, but it really struggles with mixed lighting, badly overexposing bright areas. There is decent night vision, a built-in spotlight, and two-way audio. You can also insert a microSD card up to 256 GB for local recording, which is just as well because the cloud subscription is far too expensive. Sadly, the busy app is flaky and sometimes drops or refuses to load the live feed. I liked the 5W solar panel option to keep the battery topped up, but you can get the same thing with better cameras than this.

Canary Flex: I love the curved lozenge design of the Canary Flex, but it is by far the most unreliable security camera I tested. It frequently missed people walking past altogether, or started recording when they had almost left the frame. Night vision and low-light video quality are poor, and the app is very slow to load.

What Do I Need to Know Before Buying a Security Camera?

Security cameras can be very useful, but you need to choose carefully. You might not be as concerned about potential hacks as you would be with indoor security cameras, but no one wants strangers tuning in to their backyard. Follow these tips to get the peace of mind you crave without infringing on anyone’s privacy.

Choose your brand carefully: There are countless outdoor security cameras on the market at temptingly low prices. But unknown brands represent a real privacy risk. Some of the top security camera manufacturers—including Ring, Wyze, and Eufy—have been breached, but public scrutiny has at least forced them to make improvements. Any system is potentially hackable, but lesser-known brands are less likely to be called out and often disappear (or change names) when they are.

Consider security: A strong password is good, but biometric support is much more convenient and secure. I prefer security cameras with mobile apps that support fingerprint or face unlock. Two-factor authentication (2FA) ensures that someone with your username and password cannot log in to your camera. Usually, it requires a code from an SMS, email, or an authenticator app, adding an extra layer of security. It’s an industry standard, but it’s still something you need to manually activate. I do not recommend any cameras here that don’t at least offer 2FA as an option.

Keep it updated: It’s vital to regularly check for software updates, not just for your security cameras and apps but also for your router and other internet-connected devices. Ideally, your chosen security camera has an automatic update option.

What Features Should I Look for in Outdoor Security Cameras?

There is a lot to consider when you are shopping for an outdoor security camera. It can be tough to determine which features you need, so here are some important questions to run through.

Video quality: You may be tempted to go with the highest-resolution video you can get, but this isn’t always the best idea. You can see more details in a 4K video, but high resolution 4K video requires much more bandwidth to stream and more storage space to record than Full HD (1080p) or 2K resolution. Folks with limited Wi-Fi should be cautious. You will generally want a wide field of view, so the camera takes in more, but this can cause a curved fish-eye effect at the corners, and some cameras are better than others at correcting for distortion. An important feature, particularly if your camera is facing a mixed lighting location with some shadow and direct sunlight (or a streetlight), is HDR (high dynamic range) support, as it can prevent light areas from blowing out or dark areas from losing detail. One last thing to consider on video quality is the frame rate. A low frame rate can cause artifacts and blurring with moving subjects, and anything below 20 frames per second is likely to be jerky.

Connectivity: Most security cameras will connect to your Wi-Fi router on the 2.4-GHz band. Depending on where you intend to install them, you may appreciate the support for the 5-GHz band, which enables the stream to load more quickly. Some systems come with a hub that can act as a Wi-Fi range extender. Bear in mind that you shouldn’t install a security camera in a location without a strong Wi-Fi signal.

Subscription model: Most security camera manufacturers offer a subscription service that provides cloud storage for video recording. It isn’t always as optional as it seems. Some manufacturers bundle in smart features such as person detection or activity zones, making a subscription essential to get the best from their cameras. Always factor in the subscription cost, and make sure you are clear on what is included before you buy.

Local or cloud storage: If you don’t want to sign up for a subscription service and upload video clips to the cloud, make sure your chosen camera offers local storage. Some security cameras have microSD card slots, while others record video to a hub device inside your home. A few manufacturers offer limited cloud storage for free, but you can usually expect to pay somewhere around $3 to $10 per month for 30 days of storage for a single camera. For multiple cameras, a longer recording period, or continuous recording, you are looking at paying between $10 and $20 per month. There are usually discounts if you pay annually.

Placement is important: Remember that a visible security camera is a powerful deterrent. You don’t want to hide your cameras away. Also, make sure the view isn’t peering into a neighbor’s window. Most cameras offer customizable zones to filter out recording or motion detection for areas of the camera’s frame. If you buy a battery-powered camera, remember that you will have to charge it periodically, so it has to be somewhat accessible. The ideal placement for security cameras is around 7 feet above the ground and angled slightly downwards.

False positives: Unless you want your phone to ping every time your cat wanders onto the porch or when the neighbor’s dog runs through your garden, consider a security camera that can detect people and filter alerts. Good cameras will also enable you to set privacy or activity zones.

Night vision and spotlights: Outdoor security cameras generally have infrared night vision, but low-light performance varies wildly. You always lose some detail when light levels are low. Most night vision modes produce monochrome footage. Some manufacturers offer color night vision, though it is often colorized by software and can look odd. We prefer spotlights, as they allow the camera to capture better-quality footage, and the light acts as a further deterrent to any intruder. But they aren’t suitable for every situation, and they drain batteries faster if not wired.

Camera theft: Concerned about camera theft? Choose a camera that doesn’t have onboard storage. You might also want to consider a protective cage and screw mount rather than a magnetic mount. Some manufacturers have replacement policies for camera theft, especially if you have a subscription, but they usually require you to file a police report and have exclusions. Check the policy thoroughly before you buy.

Is It Better to Have Wired or Wireless Security Cameras?

Wired cameras usually require some drilling to install, must be within reach of a power outlet, and will turn off if the power source does, but they never need to be charged. If you buy battery-powered security cameras, the installation is easier, and you can pick the spots you want. They usually run for months before needing to be recharged and will warn you when the battery is low, but that does mean you have to remove the battery, or sometimes the entire camera, to recharge it, which typically takes a few hours. It’s worth noting that you can buy solar panels to power some battery-powered cameras now, which gives you the best of both worlds.

Why We Hesitate to Recommend Ring

How We Test Security Cameras

I test every security camera for at least two weeks, but often far longer. I run through the installation process and note any issues. I check that alerts come through correctly to my phone when I am home, connected to Wi-Fi, or when I’m away and connected to a cellular network. I usually place two or more cameras in the same spot to compare picture quality, motion detection, and other features. I consider the image resolution, frame rate, and audio quality of videos and the live feed. I also check for lag with the live feed. I test the performance during the day and see how it copes with the sun facing the lens, and how it performs in the dark at night (testing both spotlight and night vision). I check how long the live feed and recorded videos take to load at different times of the day.

I play around with the settings in the app to try every mode and feature. I test any smart-detection features to see if they can correctly identify people. I test the two-way audio for a short conversation and try the siren where applicable. I also test local storage and cloud storage options for recording videos. If there are any smart-home integrations, I set them up and check how quickly the feed loads on a smart display. I always ensure that the cameras recommended support 2FA and test any additional security or privacy features.

Power up with unlimited access to WIRED. Get best-in-class reporting and exclusive subscriber content that’s too important to ignore. Subscribe Today.

A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers


WhatsApp’s mass adoption stems in part from how easy it is to find a new contact on the messaging platform: Add someone’s phone number, and WhatsApp instantly shows whether they’re on the service, and often their profile picture and name, too.

Repeat that same trick a few billion times with every possible phone number, it turns out, and the same feature can also serve as a convenient way to obtain the cell number of virtually every WhatsApp user on earth—along with, in many cases, profile photos and text that identifies each of those users. The result is a sprawling exposure of personal information for a significant fraction of the world population.

One group of Austrian researchers have now shown that they were able to use that simple method of checking every possible number in WhatsApp’s contact discovery to extract 3.5 billion users’ phone numbers from the messaging service. For about 57 percent of those users, they also found that they could access their profile photos, and for another 29 percent, the text on their profiles. Despite a previous warning about WhatsApp’s exposure of this data from a different researcher in 2017, they say, the service’s parent company, Meta, still failed to limit the speed or number of contact discovery requests the researchers could make by interacting with WhatsApp’s browser-based app, allowing them to check roughly a hundred million numbers an hour.

The result would be “the largest data leak in history, had it not been collated as part of a responsibly conducted research study,” as the researchers describe it in a paper documenting their findings.

“To the best of our knowledge, this marks the most extensive exposure of phone numbers and related user data ever documented,” says Aljosha Judmayer, one of the researchers at the University of Vienna who worked on the study.

The researchers say they warned Meta about their findings in April and deleted their copy of the 3.5 billion phone numbers. By October, the company had fixed the enumeration problem by enacting a stricter “rate-limiting” measure that prevents the mass-scale contact discovery method the researchers used. But until then, the data exposure could have also been exploited by anyone else using the same scraping technique, adds Max Günther, another researcher from the university who cowrote the paper. “If this could be retrieved by us super easily, others could have also done the same,” he says.

In a statement to WIRED, Meta thanked the researchers, who reported their discovery through Meta’s “bug bounty” system, and described the exposed data as “basic publicly available information,” since profile photos and text weren’t exposed for users who opted to make it private. “We had already been working on industry-leading anti-scraping systems, and this study was instrumental in stress-testing and confirming the immediate efficacy of these new defenses,” writes Nitin Gupta, vice president of engineering at WhatsApp. Gupta adds, “We have found no evidence of malicious actors abusing this vector. As a reminder, user messages remained private and secure thanks to WhatsApp’s default end-to-end encryption, and no non-public data was accessible to the researchers.”

6 Best Smart Locks (2025) for Front Doors, Slider Doors, and Even Garages


Ultraloq U-Bolt Pro for $170: WIRED reviewer Julian Chokkattu also tested the U-Bolt Pro from Ultraloq, which uses the same app that the Fingerprint models do. He says it took a few attempts to connect to Wi-Fi, but once connected it worked well with no Wi-Fi issues during the year he tested it. It has built-in Wi-Fi, uses four AA batteries that last around two months (less in super colder weather), and has a hidden mechanical keyhole as a backup in case the battery dies when you’re not home, and you get two spare keys. There’s a charging port underneath so you can give it some juice during emergencies if the lock is dead and you don’t have the key, but we wish it was USB-C instead of Micro USB. It’s a good lock, but he prefers the Fingerprint models since it has a nicer build quality and it has eight batteries, so the lock lasts twice as long.

Image may contain Electronics Mobile Phone and Phone

Photograph: Nena Farrell

Yale Assure Lock 2 Touch for $300: I’ve been testing this lock for a few weeks in tandem with ADT’s security system and Google Home. Unlike the other locks in this guide, I didn’t install it—an ADT tech did, and installation can be included in an ADT security package like the one I’ve been testing. For the lock itself, it’s worked well. It’s a full dead-bolt replacement, and came with a single key, and has both a keypad and fingerprint reader for entry options. The fingerprint reader is speedy and efficient, and my husband says the keypad has been easy to use (you activate the keypad by touching the Yale button, but if your finger is registered to the app, that’s also the fingerprint reader button). Instead of using the Yale app, I primarily control this app with the ADT+ app, but there are versions of this lock that don’t use or require ADT’s service. I do wish I could set it to lock after every 10 minutes, rather than three, but that’s the longest option the ADT+ app gives me to set it. I can also partially control it in the Google Home app, but only to lock and unlock it, not to dive into detailed settings like passcodes and auto-lock times.

Yale Assure Touchscreen Lever Lock for $240: I’ve been testing this no-dead-bolt lever door handle with its sleek-looking keypad for four months on the door to my house from inside my garage. Unlike Yale’s Approach Lock, it won’t sense you coming, but it awakens with even a light touch to the keypad. It’s easy to lock and unlock and view the activity log on the Yale Access app, or you can use a pin code to unlock. You can also create different codes for different people to know exactly who’s been coming and going and when. It works with Google Home, Apple Home, and Alexa, and has also got two physical keys for backup in case of battery failure. Setup wasn’t exactly a breeze, requiring the Bilt app to install and then the Yale app to configure, and online reviews are quite voluminous in their complaints of both battery life and the handle becoming loose over time. Neither of these issues has arisen during our test period; however, we will update this review with further observations as time goes on. —Kat Merck

Avoid These Smart Locks

We haven’t loved every smart lock we’ve tried. These are the ones to skip.

Image may contain Blade Razor and Weapon

Defiant Smart Deadbolt

Photograph: Julian Chokkattu

Defiant Smart Deadbolt Powered by Hubspace for $100: The shoddy build quality is a huge turn-off on this smart lock from Defiant. The buttons are mushy, it’s very loud, and what is the point of Wi-Fi connectivity if it never connects to Wi-Fi? I finally got it paired with the Hubspace app, but the lock never stayed connected to my Wi-Fi, so I had none of the benefits. —Julian Chokkattu

Eufy FamiLock S3 Max for $400: This lock is cool because it includes a camera, letting the device double as a digital peephole (convenient for smaller family members!) and has a super interesting biometric option that uses the veins in your palm for authentication. Unfortunately, once installed, the lock didn’t work on my door, even though it was the correct size and placement.

A breach every month raises doubts about South Korea’s digital defenses


South Korea is world-famous for its blazing-fast internet, near-universal broadband coverage, and as a leader in digital innovation, hosting global tech brands like Hyundai, LG, and Samsung. But this very success has made the country a prime target for hackers and exposed how fragile its cybersecurity defenses remain.  

The country is reeling from a string of high-profile hacks, affecting credit card companies, telecoms, tech startups, and government agencies, impacting vast swathes of the South Korean population. In each case, ministries and regulators appeared to scramble in parallel, sometimes deferring to one another rather than moving in unison. 

Critics argue that South Korea’s cyber defenses are hindered by a fragmented system of government ministries and agencies, often resulting in slow and uncoordinated responses, per local media reports

With no clear government agency acting as “first responder” following a cyberattack, the country’s cyber defenses are struggling to keep pace with its digital ambitions. 

“The government’s approach to cybersecurity remains largely reactive, treating it as a crisis management issue rather than as critical national infrastructure,” Brian Pak, the chief executive of Seoul-based cybersecurity firm Theori, told TechCrunch.  

Pak, who also serves as an advisor to SK Telecom’s parent company’s special committee on cybersecurity innovations, told TechCrunch that because government agencies tasked with cybersecurity work in silos, developing digital defenses and training skilled workers often get overlooked. 

The country is also facing a severe shortage of skilled cybersecurity experts.  

“[That’s] mainly because the current approach has held back workforce development. This lack of talent creates a vicious cycle. Without enough expertise, it’s impossible to build and maintain the proactive defenses needed to stay ahead of threats,” Pak continued.  

Political deadlock has fostered a habit of seeking quick, obvious “quick fixes” after each crisis, said Pak, all the while the more challenging, long-term work of building digital resilience continues to be sidelined. 

This year alone, there has been a major cybersecurity incident in South Korea almost every month, further mounting concerns over the resilience of South Korea’s digital infrastructure.  

January 2025 

  • GS Retail, the operator of convenience stores and grocery markets across South Korea, confirmed a data breach that exposed the personal details of about 90,000 customers after its website was attacked between December 27 and January 4. The stolen information included names, birth dates, contact details, addresses, and email addresses. 

February 2025 

April and May 2025 

  • South Korea’s part-time job platform Albamon was hit by a hacking attack on April 30. The breach exposed the resumes of more than 20,000 users, including names, phone numbers, and email addresses.
  • In April, South Korea’s telecom giant SK Telecom was hit by a major cyberattack. Hackers stole the personal data of about 23 million customers — nearly half the country’s population. Much of the aftermath of the cyberattack lasted through May, in which millions of customers were offered a new SIM card following the breach. 

June 2025  

  • Yes24, South Korea’s online ticketing and retail platform, was hit by a ransomware attack on June 9, which knocked its services offline. The disruption lasted for about four days, with the company back online by mid-June. 

July 2025 

August 2025

  • Yes24 faced a second ransomware attack in August 2025, which took its website and services offline for a few hours. 
  • Hackers broke into South Korean financial services company Lotte Card, which issues credit and debit cards, between July 22 and August. The breach exposed around 200GB of data and is believed to have affected roughly 3 million customers. The breach remained unnoticed for approximately 17 days, until the company discovered it on August 31. 
  • Welcome Financial: In August 2025, Welrix F&I, a lending arm of Welcome Financial Group, was hit by a ransomware attack. A Russian-linked hacking group claimed it stole over a terabyte of internal files, including sensitive customer data, and even leaked samples on the dark web.
  • North Korea-linked hackers, believed to be the Kimsuky group, have been spying on foreign embassies in South Korea for months by disguising their attacks as routine diplomatic emails. According to Trellix, the campaign has been active since March and has targeted at least 19 embassies and foreign ministries in South Korea. 

September 2025  

  • KT, one of South Korea’s biggest telecom operators, has reported a cyber breach that exposed subscriber data from more than 5,500 customers. The attack was linked to illegal “fake base stations” that tapped into KT’s network, enabling hackers to intercept mobile traffic, steal information like IMSI, IMEI, and phone numbers, and even make unauthorized micro-payments. 

In light of the recent surge in hacking incidents, the South Korean Presidential Office’s National Security is stepping in to tighten defenses, pushing for a cross-ministerial effort that brings multiple agencies together in a coordinated, whole-of-government response.  

In September 2025, the National Security Office announced that it would implement “comprehensive” cyber measures through an interagency plan, led by the South Korean president’s office. Regulators also signaled a legal change giving the government power to launch probes at the first sign of hacking — even if companies haven’t filed a report. Both steps aim to address the lack of a first responder that has long hindered South Korea’s cyber defenses. 

But South Korea’s fragmented system leaves accountability weak, placing all authority in a presidential “control tower” could risk “politicization” and overreach, according to Pak.  

A better path may be balance: a central body to set strategy and coordinate crises, paired with independent oversight to keep power in check. In a hybrid model, expert agencies like KISA would still handle the technical work — just with more straightforward rules and accountability, Pak told TechCrunch.  

When reached for comment, a spokesperson for the South Korea’s Ministry of Science in ICT said the ministry, with KISA and other relevant agencies, is “committed to addressing increasingly sophisticated and advanced cyber threats.”  

“We continue to work diligently to minimize potential harm to Korean businesses and the general public,” the spokesperson added.

This article was originally published on September 30.

A 25-year-old police drone founder just raised $75M led by Index


If you ever call 911 from an area that’s hard to get to, you might hear the buzz of a drone well before a police cruiser pulls up. And there’s a good chance that it will be one made by Brinc Drones, a Seattle-based startup founded by 25-year-old Blake Resnick, who dropped out of college to run the company.

Brinc, which was founded in 2017 and counts OpenAI CEO Sam Altman as a seed-stage investor, just announced today that it has raised $75 million in new funding led by Index Ventures.

This brings the startup’s total funding to $157.2 million. While Brinc isn’t disclosing its exact valuation, Resnick told TechCrunch it’s an “up-round” compared to its most recent round, a $55 million Series B in 2022. Brinc was last valued at $300 million in 2023, Bloomberg reported.

Brinc sells a variety of drone systems to police and public safety agencies. It’s part of a broader trend of U.S. drone startups manufacturing domestically due to increasing restrictions against Chinese companies that dominate the commercial drone industry. (Resnick briefly interned at DJI, by far the biggest Chinese player, a few years before founding Brinc.)

With this funding, Brinc is launching a “strategic alliance” with Motorola Solutions, which also invested in the round. Motorola Solutions is a giant in the U.S. security industry whose software powers many 911 call centers. The partnership will integrate Brinc drones directly into those centers, allowing operators to dispatch drones for certain emergency calls if they’re cleared by an existing Motorola AI system.

Brinc is, however, in an increasingly competitive field with other U.S. startups like Flock Safety and Skydio. Each also offers drones for police, and have multibillion-dollar valuations. Flock stood at $7.5 billion in its latest round last month while Skydio was valued at $2.2 billion in 2023.

When it comes to the competition, Resnick tells TechCrunch that there’s plenty of room for growth in a market that is otherwise dominated by Chinese players. Beyond the Motorola partnership, he says Brinc offers its share of unique features, like the ability to break windows or deliver emergency medical devices.

Screenshot-reading malware cracks iPhone security for the first time


In the realm of smartphones, Apple’s ecosystem is deemed to be the safer one. Independent analysis by security experts has also proved that point repeatedly over the years. But Apple’s guardrails are not impenetrable. On the contrary, it seems bad actors have managed yet another worrying breakthrough.

As per an analysis by Kaspersky, malware with Optical Character Recognition (OCR) capabilities has been spotted on the App Store for the first time. Instead of stealing files stored on a phone, the malware scanned screenshots stored locally, analyzed the text content, and relayed the necessary information to servers.

The malware-seeding operation, codenamed “SparkCat,” targeted apps seeded from official repositories — Google’s Play Store and Apple’s App Store — and third-party sources. The infected apps amassed roughly a quarter million downloads across both platforms.

An app listed on the App Store infected by malware.
Kaspersky

Interestingly, the malware piggybacked atop Google’s ML Kit library, a toolkit that lets developers deploy machine learning capabilities for quick and offline data processing in apps. This ML Kit system is what ultimately allowed the Google OCR model to scan photos stored on an iPhone and recognize the text containing sensitive information.


Please enable Javascript to view this content

But it seems the malware was not just capable of stealing crypto-related recovery codes. “It must be noted that the malware is flexible enough to steal not just these phrases but also other sensitive data from the gallery, such as messages or passwords that might have been captured in screenshots,” says Kaspersky’s report.

Among the targeted iPhone apps was ComeCome, which appears to be a Chinese food delivery app on the surface, but came loaded with a screenshot-reading malware. “This is the first known case of an app infected with OCR spyware being found in Apple’s official app marketplace,” notes Kaspersky’s analysis.

One of the iPhone apps infected by OCR malware.
Kaspersky

It is, however, unclear whether the developers of these problematic apps were engaged in embedding the malware, or if it was a supply chain attack. Irrespective of the origin, the whole pipeline was quite inconspicuous as the apps seemed legitimate and catered to tasks such as messaging, AI learning, or food delivery. Notably, the cross-platform malware was also capable of obfuscating its presence, which made it harder to detect.

The primary objective of this campaign was extracting crypto wallet recovery phrases, which can allow a bad actor to take over a person’s crypto wallet and get away with their assets. The target zones appear to be Europe and Asia, but some of the hotlisted apps appear to be operating in Africa and other regions, as well.






US indicts five individuals in crackdown on North Korea’s illicit IT workforce


U.S. authorities have indicted five people over their alleged involvement in a multi-year scheme that saw them obtain remote IT employment with dozens of American companies.

The Department of Justice on Thursday announced the indictment of North Korean citizens Jin Sung-Il and Pak Jin-Song; Pedro Ernesto Alonso De Los Reyes of Mexico, and U.S. nationals Erick Ntekereze Prince and Emanuel Ashtor.

The DOJ said the FBI arrested Ntekereze and Ashtor, and a search of Ashtor’s home in North Carolina found evidence of a “laptop farm” that hosted company-provided laptops to deceive organizations into thinking they had hired workers based in the U.S.

Alonso was also arrested in the Netherlands after a U.S. warrant was issued.

According to the indictment, Ntekereze and Ashtor allegedly installed remote access software, including Anydesk and TeamViewer, on the company-provided devices, allowing the North Koreans to conceal their locations. The two Americans also provided Jin and Pak with forged identity documents, including U.S. passports and U.S. bank accounts.

The indictment alleges that the defendants gained employment from at least 64 American organizations over the course of the multi-year scheme, which ran from April 2018 through August 2024. These included a U.S. financial institution, a San Francisco-based technology company, and a Palo Alto-headquartered IT organization.

According to the Justice Department, payments from ten of those companies generated at least $866,255 in revenue, most of which was laundered through a Chinese bank account. 

“The Department of Justice remains committed to disrupting North Korea’s cyber-enabled sanctions-evading schemes, which seek to trick U.S. companies into funding the North Korean regime’s priorities, including its weapons programs,” Devin DeBacker, supervisory official with the Justice Department’s National Security Division, said in a statement. 

Alongside Thursday’s indictments, which come just days after the Treasury Department sanctioned two individuals and four entities for allegedly engaging in similar behavior, the FBI released an advisory warning that North Korean IT workers are increasingly engaging in malicious activity, including data extortion.

The agency said it has observed North Korean IT workers leveraging unlawful access to company networks to “exfiltrate proprietary and sensitive data, facilitate cyber-criminal activities, and conduct revenue-generating activity on behalf of the regime.”

A New Jam-Packed Biden Executive Order Tackles Cybersecurity, AI, and More


Four days before he leaves office, US president Joe Biden has issued a sweeping cybersecurity directive ordering improvements to the way the government monitors its networks, buys software, uses artificial intelligence, and punishes foreign hackers.

The 40-page executive order unveiled on Thursday is the Biden White House’s final attempt to kickstart efforts to harness the security benefits of AI, roll out digital identities for US citizens, and close gaps that have helped China, Russia, and other adversaries repeatedly penetrate US government systems.

The order “is designed to strengthen America’s digital foundations and also put the new administration and the country on a path to continued success,” Anne Neuberger, Biden’s deputy national security adviser for cyber and emerging technology, told reporters on Wednesday.

Looming over Biden’s directive is the question of whether president-elect Donald Trump will continue any of these initiatives after he takes the oath of office on Monday. None of the highly technical projects decreed in the order are partisan, but Trump’s advisers may prefer different approaches (or timetables) to solving the problems that the order identifies.

Trump hasn’t named any of his top cyber officials, and Neuberger said the White House didn’t discuss the order with his transition staff, “but we are very happy to, as soon as the incoming cyber team is named, have any discussions during this final transition period.”

The core of the executive order is an array of mandates for protecting government networks based on lessons learned from recent major incidents—namely, the security failures of federal contractors.

The order requires software vendors to submit proof that they follow secure development practices, building on a mandate that debuted in 2022 in response to Biden’s first cyber executive order. The Cybersecurity and Infrastructure Security Agency would be tasked with double-checking these security attestations and working with vendors to fix any problems. To put some teeth behind the requirement, the White House’s Office of the National Cyber Director is “encouraged to refer attestations that fail validation to the Attorney General” for potential investigation and prosecution.

The order gives the Department of Commerce eight months to assess the most commonly used cyber practices in the business community and issue guidance based on them. Shortly thereafter, those practices would become mandatory for companies seeking to do business with the government. The directive also kicks off updates to the National Institute of Standards and Technology’s secure software development guidance.

Another part of the directive focuses on the protection of cloud platforms’ authentication keys, the compromise of which opened the door for China’s theft of government emails from Microsoft’s servers and its recent supply-chain hack of the Treasury Department. Commerce and the General Services Administration have 270 days to develop guidelines for key protection, which would then have to become requirements for cloud vendors within 60 days.

To protect federal agencies from attacks that rely on flaws in internet-of-things gadgets, the order sets a January 4, 2027, deadline for agencies to purchase only consumer IoT devices that carry the newly launched US Cyber Trust Mark label.

Police operation claims takedown of prolific Redline and Meta password stealers


A coalition of international law enforcement agencies say they have disrupted the operations of two prolific infostealers that stole the sensitive data of millions of people. 

The Dutch National Police, who led the so-called “Operation Magnus” takedown, reports it gained “full access” to the servers used by the Redline and Meta infostealers. 

Infostealers are a type of malware specifically designed to extract sensitive information, such as passwords, credit card data, search histories, and the contents of cryptocurrency wallets, from an infected system. 

Redline is considered one of the most prolific strains of infostealer malware. Criminals have been using Redline, which has been active since 2020, to steal the sensitive data of hundreds of millions of people, according to a recent report. The malware has been attributed to a 2022 hack at Uber, the theft of login details from Worldcoin Orb operators, and the breach of a senior official at Israel’s National Cybersecurity Directorate

Meta is a relatively new infostealer, though Operation Magnus notes: “We gained full access to all Redline and Meta servers. Did you know they were actually pretty much the same?”  

In a video posted to the website on Monday, the agencies say they were able to access the usernames, passwords, IP addresses, timestamps and registration dates, along with the source code for both infostealers, and the Telegram bots used by the operators of the malware.

The agencies also teased a list of usernames belonging to “VIP” — or “very important to the police” — users of the Redline and Meta infostealers. It’s not yet clear if any arrests have been made as part of the operation, but the website claims that “legal actions are underway.”

Operation Magnus, which was supported by the U.S. Federal Bureau of Investigation and the U.K.’s National Crime Agency, was announced on a newly created website outing the Redline and Meta operations. Simone van Wordragen, a spokesperson for the Dutch National Police, told TechCrunch that it will release more information about the takedown on Tuesday.

A similar takedown approach was taken during the recent operation targeting LockBit, which saw police take control of the ransomware gang’s dark web leak site to post details of the operation. 

Hackers Threaten to Leak Planned Parenthood Data


Even those of you who do everything you can to secure those secrets can find yourself vulnerable—especially if you’re using a YubiKey 5 authentication token. The multifactor authentication devices can be cloned thanks to a cryptographic flaw that can’t be patched. The company has rolled out some mitigation measures—and the attack itself is relatively difficult to pull off. But it may be time to invest in a new dongle.

That’s not all, folks. Each week, we round up the privacy and security news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.

At the end of August, cybercriminals from the ransomware group RansomHub appear to have hacked into the systems of Planned Parenthood’s Montana branch. The organization this week confirmed it had suffered from a “cybersecurity incident” on August 28 and said its staff immediately took parts of its network offline, reporting the incident to law enforcement.

Days after the incident took place, RansomHub claimed to be behind the attack, posting Planned Parenthood on its leak website. The criminal group said it would publish 93 GB of data. It is unclear what, if anything, the ransomware group has obtained, but Planned Parenthood clinics can hold a huge array of highly sensitive data about patients, including information on abortion appointments. (Around 400,000 Planned Parenthood patients in Los Angeles were impacted following a similar ransomware incident in 2021.)

In recent months, RansomHub has emerged as one of the most active ransomware-as-a-service groups, following the law enforcement disruption of LockBit. According to an FBI and Cybersecurity and Infrastructure Security Agency alert at the end of August, the group is “efficient and successful” and has stolen data from at least 210 victims since it formed in February. “The affiliates leverage a double-extortion model by encrypting systems and exfiltrating data to extort victims,” the alert said.

The Nigeria-based scammers known as the Yahoo Boys run almost every scam in the playbook—from romance scams to pretending to be FBI agents. Yet there’s little-more devious than the increase in sextortion cases linked to the West African scammers. This week, Nigerian brothers Samuel Ogoshi and Samson Ogoshi were sentenced to more than 17 years in US jail for running sextortion scams, following their extradition earlier this year. It is the first time Nigerian scammers have been prosecuted for sextortion in the US, the BBC reported.

The Ogoshi brothers, who pleaded guilty in April, have been linked to the death of 17-year-old Jordan DeMay, who took his life six hours after he started talking to the scammers, who posed as a girl, on Instagram. The teenager had been duped into sending the brothers explicit images, and after he had done so, they threatened to post the images online unless he paid them hundreds of dollars. US prosecutors said the brothers sexually exploited and extorted more than 100 victims, with at least 11 of them being minors. There has been a huge spike in sextortion cases in recent years.

In June, the US Commerce Department banned the sale of Kaspersky’s antivirus tools over national security concerns about its links to the Russian government. (Kaspersky has, for years, denied connections). The firm later fired its workers and said it was closing its US business. This week, cybersecurity company Pango Group announced it is purchasing Kaspersky Lab’s US antivirus customers, according to Axios. This equates to around 1 million customers, who will be transitioned to Pango’s antivirus software Ultra AV. Ahead of the Kaspersky deal, parent company Aura also announced it was spinning out Pango Group into its own business. Pango’s president said customers would not need to take any action and that it would allow subscribers to continue to receive updates after September 29, when Kaspersky updates will stop.

For years, the EU has been trying to introduce new child protection laws that would require private chats to be scanned for child sexual abuse material—something that would potentially undermine encrypted messaging apps that provide everyday privacy to billions of people. The plans have been highly controversial and were shelved earlier this year. However, the proposed law, which has been dubbed “chat control,” reappeared in legislators’ in-trays this week. The Council of the EU, which is currently chaired by Hungary, wants to pass legislation by October, but reports say strong resistance to the plans still remain.