<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>AI Headlines: News</title>
        <link>https://aiheadlines.pro</link>
        <description>Latest AI news, tools, startups, and research. Curated by AI, verified by humans.</description>
        <lastBuildDate>Sun, 19 Jul 2026 21:34:54 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <copyright>© 2026 AI Headlines</copyright>
        <atom:link href="https://aiheadlines.pro/news/feed.xml" rel="self" type="application/rss+xml"/>
        <item>
            <title><![CDATA[Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory]]></title>
            <link>https://aiheadlines.pro/news/attacker-uses-suspected-ai-generated-powershell-script-to-ma</link>
            <guid>https://aiheadlines.pro/news/attacker-uses-suspected-ai-generated-powershell-script-to-ma</guid>
            <pubDate>Tue, 14 Jul 2026 06:43:44 GMT</pubDate>
            <description><![CDATA[Ravie LakshmananJul 13, 2026Artificial Intelligence / Threat Intelligence Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibecoded PowerShell...]]></description>
            <content:encoded><![CDATA[**Ravie Lakshmanan**Jul 13, 2026Artificial Intelligence / Threat Intelligence
Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibecoded PowerShell script for Active Directory (AD) enumeration.

"The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory and exporting out a number of files, and finally creating AD_Report.html to measure the success of the enumeration attempt," Huntress researchers Jevon Ang and Dray Agha [said](https://www.huntress.com/blog/aicodedmalwarevibecodingactivedirectory).

The attack chain involved the threat actor establishing Remote Desktop Protocol (RDP) access onto a domainjoined Windows Server with a set of precompromised credentials, followed by staging the tools in the "C:\ProgramData\" folder. The incident took place in early June 2026.

This included an artificial intelligence (AI)generated payload to map the Active Directory environment. The assessment is based on various telltale signs, such as the prompt iteration title, placeholder strings, overengineered code that features multiple methods to find a Domain Controller, and beautified console output using cyan, green, red, and yellow.

Huntress described the bespoke PowerShell script as "highly aggressive" and "noisy," making use of a "fivestep cascading fallback mechanism" to enable reconnaissance and discovery. It's titled "100% Working AD Information Gathering Script  FULLY FIXED," suggesting a backandforth with a large language model (LLM).

Once the primary Domain Controller is located, it initiates a data collection routine to systematically harvest AD users, computers, groups, organizational units (OUs), and trusts, and store the details in a staging directory.

About 30 minutes later, the attacker moved to deploy a [s5cmd](https://github.com/peak/s5cmd), a legitimate tool used for bulk file operations, along with [SharpShares](https://github.com/mitchmoser/SharpShares), a C#based network shares enumeration utility, to look for useraccessible data repositories.

In the final stage, the data is said into CSV files, archived, and exfiltrated to a remote server, but not before creating an HTML file summarizing the data theft in the form of an Active Directory Inventory Report.

"It's likely a 'helpful' inject from the LLM that the attacker simply went along with, rather than being intentionally authored into the script," the researchers explained.

The development is yet another sign that threat actors are augmenting their arsenal with vibecoded malware generated with assistance from AI models, even if the technology isn't being abused in ways not seen before. What it does change is that it lowers the barrier to entry for cybercrime, permitting lessskilled actors to come up with highly capable, evasive tooling with minimal effort.

"The underlying attack chain still resembles the triedandtested smashandgrab playbook we've seen for years," Huntress said. "This core methodology has remained consistent, but it is now being selectively augmented by AI. This hybrid approach prioritises aggression and speed over stealth, allowing threat actors to execute highly damaging campaigns faster than ever."

### AI as a Force Multiplier

In a report published last week, Sygnia revealed that AIenabled attackers do not necessarily need novel malware or zerodays, but that the real shift lies in the fact that cyber intrusions can be orchestrated at a speed and scale faster and bigger than defenders can contain them.

The incident response company said it observed an AIassisted cloud attack that progressed from initial access to broad compromise within a span of about 72 hours against a large Amazon Web Services (AWS)based environment. The end goal of the activity is assessed to be financially motivated, with the attacker using the access to the victim's cloud infrastructure for use as leverage for extortion.

"The threat actor repeatedly leveraged newly acquired credentials to restart discovery, secrets harvesting, persistence, and impact activities," it [said](https://www.sygnia.co/blog/insideanaiassistedcloudattack/). "The attack relied on familiar cloud techniques rather than novel malware or zerodays."

"The threat actor was not exploiting a single misconfiguration; they were chaining weaknesses across application services, AWS resources, sourcecontrol repositories, CI/CD workflows, runtime components, and data stores, while rapidly executing credential discovery, secrets harvesting, cloud enumeration, deploymentpipeline abuse, runtime modification, database access, and operational disruption."

The attacker, per Sygnia, entailed repeated attempts to establish persistence on the compromised hosts, obtaining the access key to one of the AWS accounts through shortcomings in an internetfacing application. Each new access was followed by renewed enumeration, additional secret collection, persistence attempts by creating access keys and IAM users, and data exfiltration. At the same time, several attackercreated artifacts were masked as a pentest or a red teaming exercise.

To further exert pressure on victims, the attacker performed a series of actions

Denying access to S3 buckets

Limiting ECS services or containers to a maximum capacity of zero

Creating ACL rules to block network access

Purging SQS queues

"The significance was not that AI introduced new attack techniques, as every observed action mapped to longestablished adversary behaviors, but that it reduced the time and effort required to operationalize those techniques across a complex environment," Sygnia pointed out.

"The threat actor repeatedly converted newly obtained access into tailored action. For each new access key, the actor appeared to quickly determine the associated permissions, reachable resources, and most valuable next steps."]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling]]></title>
            <link>https://aiheadlines.pro/news/meta-files-patent-for-ai-that-can-listen-all-day-and-track-h</link>
            <guid>https://aiheadlines.pro/news/meta-files-patent-for-ai-that-can-listen-all-day-and-track-h</guid>
            <pubDate>Tue, 14 Jul 2026 06:43:44 GMT</pubDate>
            <description><![CDATA[Swati KhandelwalJul 13, 2026Artificial Intelligence / Privacy Meta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are...]]></description>
            <content:encoded><![CDATA[**Swati Khandelwal**Jul 13, 2026Artificial Intelligence / Privacy
Meta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound, and keeps a timestamped log of every read.

Each read gets pinned to the moment it happened: the time, your location, what you were doing, even how you were using your phone. Some versions in the filing would listen all day; others would check in only at set times.

None of these ships in a product today, and Meta has not announced one; a filing like this stakes a claim on an idea long before anyone commits to building it.

The application, [US 2026/0182881](https://imageppubs.uspto.gov/dirsearchpublic/print/downloadPdf/20260182881), was filed by Meta Platforms in December 2025 and published on July 2. It names a single inventor, **Lachlan Dunn**, and traces back to a provisional filing from December 2024. The patentanalysis site [Patentlyze](https://patentlyze.com/patent/metaaitracksyouremotionstime/) flagged the filing first.

Its title pairs two ideas, emotional state analysis and realtime fitness coaching. The claims show the first is the one that matters: of the 20, the three independent ones cover emotional analysis on its own, while workout coaching appears only in the dependent claims that build on them.

## What the patent describes

A device records your speech across the day. It could be smart glasses, a phone, a smartwatch, headphones, or a smart home speaker, the patent says.

The device transcribes it, and an AI trained to read mood goes to work on both the words and the way you say them: your tone, your pace, a sigh, a laugh. It tags each stretch of audio with an emotional read, matches that read to the context around it, and over a set period, a day or a month, builds a summary of your patterns.

The system does not just label you stressed. It points back to the words behind each reading, what the patent calls a citation. In one example, an anger reading arrives with the exact harsh words you used.

One figure logs a single person across a day: passive language on a morning video call from home, a laugh with a friend at dinner, a sigh at 9:15 PM caught by a smart home speaker.

In that figure, the speech patterns are "time stamped and logged on servers," and the system hands the user an example readout like this:

"You sigh most frequently before bed, and you're happiest when with friends. You've expressed more gratitude this month."

The filing reaches well past your voice. It can fold in biometric and eyetracking signals, using pupil size, blink rate, even eye moisture to flag stress or crying. It can also watch how you use your devices, down to the posts you view or like, your screen time, and how fast you switch between apps. All of it feeds one emotional profile.

The patent's other half is a workout coach. Smart glasses watch your form in a mirror and talk you through the set, telling you to sink deeper into a squat, then cheering you on for a few more reps.

The coach reads your mood, too. If it senses you are tired or discouraged, it eases off. If it decides you have energy to spare and are slacking, the patent says it may "admonish" you. The patent claims no human coach could match its precision or keep it up all day.

## We have been here before

The ambition is not new. Amazon put voice moodreading into its Halo wearable in 2020. Its Tone feature listened to your pitch and pace and told you how you came across through the day, calm, frustrated, and the like, and it [processed those samples on your phone and deleted them](https://www.aboutamazon.com/news/devices/anewtooltohelpyouunderstandandimproveyoursocialwellbeing), never touching the cloud.

It drew scrutiny anyway: in December 2020, Senator Amy Klobuchar [pressed federal health regulators](https://www.klobuchar.senate.gov/public/index.cfm/2020/12/followingprivacyconcernssurroundingamazonhaloklobucharurgesadministrationtotakeactiontoprotectpersonalhealthdata) over Halo's collection of voicetone and bodyscan data, calling it unusually intrusive.

Amazon [shut the whole line down in 2023](https://www.aboutamazon.com/news/companynews/amazonhalodiscontinued), though it never tied that to privacy. The gap with Meta's filing is not really storage: the patent keeps the work ondevice in some versions and logs to servers in others. It is reach. Tone reads your mood from your voice alone; Meta's system also reads your eyes and your phone.

Regulators have their own doubts about whether reading emotions this way even works, and they have started drawing lines. Since February 2025, the [EU's AI Act](https://eurlex.europa.eu/eli/reg/2024/1689/oj/eng) has banned AI that infers people's emotions in workplaces and schools, except for medical or safety reasons, with fines up to 35 million euros or 7% of a company's global turnover, whichever is more.

Its drafters flagged the thin science directly: emotional expression varies from person to person, culture to culture, and moment to moment. That ban stops at consumer tools, though. A separate rule arriving in August 2026 will make systems that read emotions from biometric signals disclose that they are doing so.

Whether a voicefirst coach counts is arguable; one that also reads pupils and blink rate would fall more squarely inside that biometric line.

The Hacker News has reached out to Meta for comment on whether the application reflects any product plans and how such a system would handle user data, and will update this story with any response.

The workout coach is one use. Underneath it is a running log of everything the system decided you felt, keyed to where you were and what you were doing.

Amazon's moodreading listened to your voice alone, and it got pulled in 2023. Meta's reaches into your eyes and your phone too, and the only thing keeping it out of your life is that no one has built it yet.]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots]]></title>
            <link>https://aiheadlines.pro/news/thinking-fast-and-slow-in-the-soc-the-case-for-combining-aut</link>
            <guid>https://aiheadlines.pro/news/thinking-fast-and-slow-in-the-soc-the-case-for-combining-aut</guid>
            <pubDate>Tue, 14 Jul 2026 06:43:43 GMT</pubDate>
            <description><![CDATA[The Hacker NewsJul 13, 2026Artificial Intelligence / Security Operations A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking...]]></description>
            <content:encoded><![CDATA[**The Hacker News**Jul 13, 2026Artificial Intelligence / Security Operations
A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing real value in specific investigations. But as we mapped out the broader architecture, something kept nagging at me. The design they were building was going to work beautifully for a tiny percentage of alerts that genuinely needed deep human judgment. It was going to completely ignore the rest.

On the flight home, I picked up a book I had not touched in a few years. Daniel Kahneman's Thinking, Fast and Slow. Kahneman is one of the rare people who genuinely changed how we understand human decisionmaking. He spent his career as a psychologist studying how people actually think, as opposed to how economists assumed they did. In 2002, he won the Nobel Prize in Economics, which tells you something about how far his work traveled beyond its starting point.

The book's central argument is that the human mind is not one thing. It is two systems operating in parallel, often in tension.

System 1 is the brain that runs automatically. It recognizes patterns instantly, reads a room in seconds, and keeps you alive without conscious effort. It is fast, associative, and unconscious. According to Kahneman's research, 95% of all human cognition happens here, running quietly in the background like an operating system you never see.

System 2 is the brain you engage with for hard things. Evaluating a contract, working through a problem with no obvious answer, and making a judgment call under pressure. It is slow, logical, effortful, and it accounts for the remaining 5% of our thinking. It can override System 1 when System 1 is wrong. But it has limited capacity. You cannot run it at full power all day. When it gets exhausted, System 1 takes over regardless.

Kahneman's core insight is not that one system is better. It is that the errors humans make are almost always the result of applying the wrong system to the wrong job. Deliberate thinking applied to things that should be automatic burns people out and still misses things. Automatic thinking applied to things that genuinely need deliberation produces confident mistakes.

I landed, opened my laptop, and wrote one sentence to myself. “This is exactly what is wrong with how most security teams are designing their AI architecture right now.”

## The numbers are not a coincidence

Kahneman says humans run System 1 for 95% of their cognition and System 2 for 5%. [Research based on analysis of more than 25 million enterprise alerts](https://intezer.com/2026aisocreportforcisos/) found that 98% of alerts can be resolved autonomously with less than 2% actually warranting human review.

This is almost identical to Kahneman’s ratio. The SOC that performs well is not some new invention. It is the architecture that mirrors how the best decisionmaking minds actually operate. Fast, automatic processing for the overwhelming majority of inputs, and deliberate human judgment reserved for the small fraction that genuinely needs it.

The CISO I was sitting with was building a SOC with one brain. His team was asking System 2 to do System 1 work, and then asking System 2 again to do what it is actually good at, on whatever energy was left over. No wonder they were covering only a fraction of their alerts. No wonder the analysts were exhausted. No wonder the real threats hiding in the lowseverity pile were never found. According to [research on over 25 million alerts](https://intezer.com/2026aisocreportforcisos/), an enterprise with 450K alerts per year can expect 54 real threats to be hidden in exactly those alerts, the ones that look like noise, the ones that never make it to the front of the queue.

## The fast SOC brain for the 98% of alerts

The bulk of SOC alert triage is a System 1 problem. Is this file known to be malicious? Does this login match historical behavior? Has this IP ever appeared in a case we already closed? These are not questions that need lengthy deliberation. They need answers, at machine speed, for every alert, around the clock.

When human analysts are forced to do this work, the same thing happens that happens when you make people perform System 2 tasks all day. They slow down, they simplify, and eventually they start skipping. They triage only what looks urgent. The 54 threats hiding in the lowseverity pile stay hidden, not because anyone chose to ignore them, but because there are 4,000 alerts behind them and the team's cognitive capacity ran out.

The autonomous brain of the SOC needs to work the way System 1 works. Continuously, without prompting, below the threshold of human attention. It applies deep, forensicgrade investigation to 100% of signals. Memory scans, file analysis, crosssignal correlation across endpoint, identity, network, and cloud. It closes the cases that are clearly noise and surfaces the cases that genuinely need a human, with all the evidence already assembled. It does not ask for permission. It produces verdicts.

This is what an AI SOC does. It investigates everything, reaches verdicts at 98% accuracy in under two minutes, and hands the human team the 2% that actually warrants their attention.

## The slow SOC brain for 2% of alerts

System 2 is where Claude, Codex, and Cursor belong in a SOC. Not because they are slow, but because the work they are best suited for is genuinely deliberate. Complex case analysis. Detection rule engineering. Incident reporting. Threat hunting based on an industry briefing. Work that requires synthesis, judgment, and the ability to combine forensic findings with the business context that only the analyst has.

This is where the AI copilot framing makes sense, but only when the copilot is not also being asked to manage the runway. When a Claude agent picks up an escalated case, it should not start from a raw alert. It should start from a fully assembled investigation with all the forensic analysis completed, the related signals correlated, and the recommended response drafted. The analyst applies judgment to a curated, evidencebacked case. They are not validating whether the alert was worth looking at. They are doing the work that actually needs a human mind.

When System 2 gets that kind of input, something changes. What used to be an afternoon of pivoting between consoles becomes a short, focused exchange. The analyst stops grinding the queue and starts doing the work they were actually hired to do. And here is the part that I think the market has not fully appreciated yet. Every judgment the slow brain makes, feeds back into the fast brain. Every tuning rule written in Claude, every case closed with a new context, makes the autonomous layer more accurate the following month. The two systems are compound. They make each other better over time.

## The two failure modes playing out right now

Kahneman spent a career documenting what happens when humans use the wrong cognitive system for a problem. The security industry is running both failure modes simultaneously, at scale.

The first is the classic one. Keeping human analysts in the System 1 role. Manual triage of hundreds of alerts a day, burning cognitive capacity on work that should be automated. The team's System 2 is exhausted before it ever gets to the cases that actually need it. Coverage suffers. Threats are missed. The team adds headcount and the problem scales linearly rather than being solved.

The second failure mode is the one the current AI wave is producing. Deploying a frontier AI platform directly against raw detection data and calling it an AI SOC. This is also System 2 doing System 1 work, just faster and more expensively. The agent still needs a human to initiate each investigation. At real alert volumes, the economics do not hold. Running a frontier model against every alert at current token costs is not viable in production. Teams quietly start skipping the lowpriority ones. The 54 missed threats remain missed. The problem is not solved. It is rebranded.

## The SOC architecture that actually mirrors the brain

[The SOC that succeeds in 2026 runs both systems correctly.](https://intezer.com/blog/intezerinsideyouraiworkspace/)

The fast brain covers everything automatically. It is purposebuilt for forensic investigation at scale, not a generalpurpose language model. It does not wait for prompts. It does not skip lowseverity alerts because the queue is long. It produces verdicts across 100% of signals and feeds the slow brain with fully assembled cases.

The slow brain runs on top of that foundation. Claude, Cursor, Codex, etc. receive escalated cases with all the context attached. Analysts supervise rather than triage. And because both brains share the same knowledge base, every decision made in the AI workspace makes the autonomous layer smarter.

There is also a strategic implication here that I think the market has not fully processed. **Enterprises that outsource alert investigation to an MDR provider do not own the knowledge layer **that builds up from that investigation. The detection rules, case history, triage logic, and organizational context all accumulate inside the vendor's platform. When you want to connect Claude or Codex to your security operations, you are trying to run System 2 on a foundation you do not own. The slow brain has nothing to work from.

Bringing investigation inhouse is not just a cost or coverage decision. It is the prerequisite for making an analyst copilot actually useful. Every alert investigated, every case resolved, every rule tuned accumulates inside your own instance. The faster System 1 builds that foundation, the more powerful System 2 becomes.

Kahneman's insight was that the best decisionmakers are not those who think faster or think harder. They are those who know which mode the moment calls for, and have designed their lives so that each system is applied to the right problems.

Security teams that get this right in 2026 will not be the ones with the most analysts or the most powerful language model. They will be the ones who designed a SOC where the fast brain handles everything it should, and the slow brain is freed to do what it is meant to.

AI executes. Humans supervise. And when the architecture is right, supervising is the best part of the job.

Found this article interesting? [Learn more here.](https://intezer.com/getademo/)

**Note:** *This article has been expertly written and contributed by Lital AsherDotan, CMO at Intezer.*]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft]]></title>
            <link>https://aiheadlines.pro/news/forg365-phaas-targets-microsoft-365-with-device-code-and-ait</link>
            <guid>https://aiheadlines.pro/news/forg365-phaas-targets-microsoft-365-with-device-code-and-ait</guid>
            <pubDate>Tue, 14 Jul 2026 06:43:43 GMT</pubDate>
            <description><![CDATA[Ravie LakshmananJul 13, 2026Email Security / Artificial Intelligence A new phishingasaservice (PhaaS) operation called Forg365 is using a combination of device code phishing,...]]></description>
            <content:encoded><![CDATA[**Ravie Lakshmanan**Jul 13, 2026Email Security / Artificial Intelligence
A new phishingasaservice (PhaaS) operation called **Forg365** is using a combination of [device code phishing](https://thehackernews.com/2026/03/devicecodephishinghits340microsoft.html), adversaryinthemiddle (AitM) tactics, antibot evasion, artificial intelligence (AI)assisted lure creation, and postcompromise mailbox operations targeting Microsoft 365 accounts.

Distributed via Telegram and costing $400 a month (or $3,800 per year), attack chains leverage phishing lures that make use of legitimate email delivery infrastructure, such as Amazon Simple Email Service (Amazon SES) and Twilio SendGrid, to imitate a redirection chain that blends into regular email traffic before it ends in Forg365controlled domains.

"The panel exposes a mature operator workflow: accounts, links, invitations, OAuth app configuration, redirect links, SVG generation, campaign sending, SMTP profiles, SMTP rotation, AI email generation, token vaulting, account intelligence, keyword alerts, viewer links, and browserextension support," ZeroBAC [said](https://zerobec.com/blog/insideforg365telegramdistributedsneaky2fastylephaas).

The email security company said the PhaaS kit is best understood as similar to the [Kali365](https://thehackernews.com/2026/05/threatsdaybulletinclaudesecurity.html#kali365targetsmicrosoft365) (aka Octopi365 and Freedom365) and [Sneaky 2FA](https://thehackernews.com/2025/11/sneaky2faphishingkitaddsbitbpop.html) ecosystem, reflecting the industrialization of the business model, which is now combining bringing together lure creation, delivery, evasion, token/session handling, and postcompromise operations under a subscriptionbased setup that allows even threat actors with littletono technical expertise to orchestrate phishing campaigns with minimal effort and at scale.

Attack chains using Forg365 have been observed using business documentthemed or remittance approval lures to trick recipients into clicking on malicious links. The sender domain uses Amazon SES for delivery, while the message body contains SendGridhosted images or tracking resources.

Customers who successfully complete Telegram registration utilize an operator panel accessible over the clearnet ("logfriend[.]com/login"), from where they can generate lures, set up campaigns, and manage captured tokens.

"Forg365 includes a deviceauth phishing branch that presents a Microsoftstyled verification code page and pushes the victim into a legitimate Microsoft Authentication Broker signin flow," ZeroBAC explained. "The victim sees real Microsoft authentication surfaces, but the code authorizes an attackercontrolled session."

For AitM phishing, the platform employs route tokens, session cookies, and traffic classification to determine whether to serve phishing content or a benign decoy. If a VPN connection is detected, the kit redirects to innocuous decoy content instead of exposing the phishing pages.

A notable aspect of the Forg365 platform is that it offers an extension named ForgCookie for Chromiumbased browsers like Google Chrome, Microsoft Edge, and Brave that is designed for continued access to the compromised accounts. Described as an "automatic SSO cookie refresh for Microsoft services," the addon acts as an intermediary between the token acquisition and browser access by cycling through the steps listed below

Requests account data from the Forg365 backend

Calls the cookiegeneration endpoint for a selected account

Clears Microsoft session cookies

Injects the generated refreshtoken credential cookie into the Microsoft login domain

Triggers a silent OAuth flow

Captures resulting Microsoft cookies across Microsoft domains

Forg365's extends beyond simple credential and token harvesting to facilitate a wide array of postcompromise actions, including monitoring for specific keywords in compromised email accounts and drafting a message response to a particular email thread using assistance from AI.

"The result is a platform that lowers the skill threshold while increasing operational consistency. Less experienced affiliates can use prebuilt templates, while more capable operators can customize landing pages, rotate infrastructure, manage tokens, generate cookie material, and monitor compromised accounts," ZeroBAC said.

The disclosure coincides with the discovery of various campaigns that have been found to employ phishing kits for credential theft

Sending [fake Microsoft account activity alerts](https://zerobec.com/blog/sneaky2fareturnstrustedsendertenantbrandedmicrosoft365replay) from a legitimatebutcompromised thirdparty SaaS sender account to direct users to Sneaky 2FAstyle phishing pages to launch a redirection chain that leads to the final phishing host, but not before performing checks to decide whether the visitor is a real user.

Using phishing emails that direct recipients to a website hosted on Canva, which then triggers the device code phishing flow to hijack Microsoft accounts using the [Kali65 phishing kit](https://www.huntress.com/blog/kali365devicecodephishingkit). The kit supports over 33 different lures, a payout pipeline, and a desktop application called OctoLink Live (aka Kali365 Live) that abuses the stolen token to launch a Chromium browser session and open the victim's mailbox in OWA, OneDrive, SharePoint, or admin.microsoft.com. The platform also offers a tool known as OctoLink Sender to masssend phishing emails from the breached account to other contacts, a technique called lateral phishing.

Phishing campaigns using [Kali365](https://arcticwolf.com/resources/blog/tokenbingodontletyourcodebethewinner/) have also distributed phishing pages impersonating Russia's MAX messenger, indicating an attempt to single out users in Russia. "A phishing operator who can convert MAX account takeovers into propagation has access to one of the largest installed messaging bases in the Russianspeaking world," Arctic Wolf [said](https://arcticwolf.com/resources/blog/kali365expandsintoawsmicrosoftoktaxeroxmaxmessenger/).

Sending emails mimicking the IRS and Social Security Administration, alongside Adobe, Microsoft, DocuSign, and Dropbox, to deliver legitimate remote access software like ConnectWise ScreenConnect as part of phishing campaigns using a PhaaS kit called [The Quarry](https://socradar.io/blog/thequarryphaasirsssaphishing/) that's developed, maintained, and sold by a lone operator named RockyBelling. The price of the kit ranges anywhere between $500 and $3,000. This includes tools like Rocky Gmail Sender (a bulk email tool), Rocky Email Sorter (to sort email addresses by domain across Gmail, Yahoo, Hotmail, and AOL), and VioletRAT.

Sending [SMS messages](https://censys.com/blog/followingauspssmishingkitthroughcensysdnsdata/) impersonating the U.S. Postal Service (USPS) and UPS to trick victims into visiting a phishing page that prompts users to enter their personal and financial information under the pretext of a failed package delivery and scheduling a new delivery. "Underneath the deception, the kit captures data in real time," Censys said. "It opens a WebSocket back to its origin and streams the victim’s card data keystrokebykeystroke, runs a serverside BIN lookup on the card number, and pushes routing decisions (retry, PIN prompt, OTP prompt, killswitch) back into the victim's browser while they type."

Using fake bid proposal workflows to take over Google accounts using a framework called [Nyasher](https://zerobec.com/blog/nyashergoogleaccounttakeoverwebflowcloudflareworkers). The redirection chain incorporates a "pressandhold" verification page to filter out automated scanners and bots, before navigating to a blob URL. "The final page displayed a Google signin interface but was not reachable as a normal hosted HTML document," ZeroBAC said. "It existed as a browsercreated object URL."

Using bogus Google Partners and Google Premier Partner enrollment workflows in phishing emails to redirect recipients to a fake Google signin page designed to capture credentials in real time as part of a campaign codenamed [GPPStorm](https://zerobec.com/blog/gppstormgooglepartnersphishingworkspacecredentials).

Using a legacy email alias to target a user's inbox and launch a device code phishing flow that uses the [EvilTokens](https://thehackernews.com/2026/07/debulltoolingabusesmicrosoftdevice.html) kit. "The kit was reached through a Mailjet tracking link, then a compromised WordPress site, then a CAPTCHA interstitial, then the Cloudflare Workers host," ZeroBAC [said](https://zerobec.com/blog/eviltokensdevicecodephishinglegacyaliases). "Three live infrastructure hops between the email body and the kit, none of which is the kit itself."

To counter these threats, it's recommended to block device code authentication unless it's required, review mailbox artifacts after device code events for any signs of unusual activity, audit mailflow rules, and decommission legacy aliases that no longer correspond to active employees.

"The campaign succeeded in reaching the inbox because the recipient organization still maintained an active forwarding relationship from a preacquisition namespace into a current mailbox," ZeroBAC noted.

"The attacker used a stillresolvable historical identity to deliver mail that, from the SEG's point of view, looked like normal forwarded correspondence. From the user's point of view, the message landed in their working inbox with no visible cue that it had taken an indirect path."]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email]]></title>
            <link>https://aiheadlines.pro/news/new-memghost-attack-plants-persistent-false-memories-in-ai-a</link>
            <guid>https://aiheadlines.pro/news/new-memghost-attack-plants-persistent-false-memories-in-ai-a</guid>
            <pubDate>Tue, 14 Jul 2026 06:43:42 GMT</pubDate>
            <description><![CDATA[Swati KhandelwalJul 13, 2026AI Security / Data Integrity Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you.]]></description>
            <content:encoded><![CDATA[**Swati Khandelwal**Jul 13, 2026AI Security / Data Integrity
Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false "fact" about the user, hide the change, and quietly steer its answers in later sessions.

When it works, the person reads an ordinarylooking reply and never learns their assistant was tampered with.

The researchers named the attack **stealth memory injection** and built a tool that writes the emails automatically. The paper, "When Claws Remember but Do Not Tell," [landed on arXiv on 6 July 2026](https://arxiv.org/abs/2607.05189v1).

## First, what these assistants do

A personal agent is an AI assistant that sticks around. Instead of forgetting everything when a chat ends, it keeps notes about you in files: your preferences, your contacts, and what you asked it to do. It reads those notes at the start of every new session, which is why it feels like it knows you.

Many of these agents can also act for you, reading your email, checking your calendar, and running small jobs on a schedule while you are away.

[OpenClaw](https://openclaw.ai/), the opensource agent used as the study's primary target, keeps this state in plain text files: some hold its standing instructions (AGENTS.md), some hold what it has learned about you (MEMORY.md). It pulls the core ones into the model's context at the start of every session.

Those notes are the whole point of the product. They are also the target.

## The oneemail attack

The attacker does not need your password or your account. They send an email to someone whose agent is set up to check their inbox, which, for these assistants, is a routine job. Buried in that email is text aimed at the assistant, not you.

If the agent's email skill takes the bait, three things happen in a row. The agent uses its own file tools to write the attacker's false note into its persistent memory. Its visible reply says nothing about having done so. And later, in a fresh conversation, that false note changes what it tells you or does for you.

In one of the study's test cases, the planted lie was that the user's Zelle daily sending limit had been raised to $10,000.

You do not catch the change for a few reasons. The assistant hides its behindthescenes steps by design, so the moment it edits a file never shows up in the chat. Few users ever open the raw memory files to read them. And when the agent runs on a schedule in the background, it often sends no message at all, so there is nothing to notice.

To make the poison stick, the tool aims it at the core files that load every session, so a single write is loaded into every later session instead of waiting to be pulled from a separate memory store.

The attack is generated by a tool the researchers call **MemGhost**. Its makers trained an attacker model offline against a shadow copy of a personal agent, rewarding emails that got the memory saved while keeping the reply quiet. At attack time, it writes the finished email in one shot, with no backandforth with the victim.

Across 56 fresh test cases, MemGhost pulled off the full attack, planting a false memory, hiding it, then swaying the agent's answers in a later session. It worked in 87.5% of backgroundmode runs against OpenClaw on GPT5.4, and 71.4% against a Claude Code SDK agent on Sonnet 4.6.

These were isolated benchmark runs, and they begin only after the email has already reached an inbox that the agent reads, so nothing here tests whether a real payload clears spam filtering or sender authentication first.

Success was generally lower in foregroundmode tests, where the user can see the reply. In background mode, it stayed above 80% on each of two other agent frameworks and on a vectorbased memory store in place of the plain files. The team also built **WhisperBench**, a 108case benchmark spanning risks from bad medical advice to money loss to security sabotage.

[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8ihTXM678o5oZ7m4MINHKLNwnwvax84HzMW_Gn8HuMjVoJjiEQJP5qe4gvWmx0MVEyV_dXuYG48K4z3YlrBzrryqt5PUjPh_BVgyHKFHqZby4w8qrtVicnmjDGweKguMVyCiJvAtZF0Lx6wT9o0qWrPy_uQh74RkDtREqIbxcooXlXd8SGuAKFjYxuw/s1700e365/WhisperBench.png)Overview of the WhisperBench framework
Crude versions of the trick mostly fail. A blunt "save this quietly and say nothing" was caught or ignored by the strongest models almost every time; the trained generator is what pushed the numbers up. It also slipped past the defenses meant to stop this kind of attack.

An input filter built to catch poisoned emails missed MemGhost's message more than nine times in ten, and a model specially hardened to ignore instructions that arrive by email still followed the planted one about half the time. Even when the owner was made to ask outright, "tell me what you checked and what you did," the attack stayed hidden about a quarter of the time on one model.

There is no quick patch to wait for. OpenClaw's own [security policy](https://github.com/openclaw/openclaw/blob/main/SECURITY.md) treats prompt injection on its own as out of scope for a fix, unless it also crosses an authorization, toolpolicy, approval, or sandbox boundary. MemGhost crosses none of those, since it works through the agent's own memorywrite tool, and researchers keep [demonstrating exactly this kind of injection against the framework](https://thehackernews.com/2026/06/newattackstrickopenclawaiagent.html).

The study's authors argue the real fix has to live inside the agent: tagging where a piece of information came from, asking the user before anything reaches durable memory, and logging every write. Until those lands, the exposed setup is any agent that both reads untrusted mail and can write its own memory without asking.

The blunt fix is to keep those two jobs apart. Failing that, limit what an emailtriggered run can change, and check the memory files after anything suspicious arrives.

OpenClaw confirmed that position to The Hacker News and pushed back on how the paper set up its agent. Its [security guidance](https://docs.openclaw.ai/gateway/security) tells operators to route untrusted email through a separate reader agent stripped of memory, file, and shell tools, passing only a summary to the main agent, which the paper did not test.

It also argues model tier matters: the OpenClaw runs used GPT5.4, a current frontier model, but the authors skipped Claude Opus 4.6 on cost, and OpenClaw pointed to [HackMyClaw](https://hackmyclaw.com/), a public challenge where thousands of injection emails failed to pry a secret from an Opus 4.6 agent. That test targeted data theft, not memory poisoning, so it does not directly answer the paper.

OpenClaw said it is weighing memorywrite controls for external content, including provenance, audit logs, and confirmation prompts, in the same direction the paper recommends. The Hacker News has also reached out to the paper's authors and will update this story with any response.

## The manual version came first

In 2024, researcher [Johann Rehberger](https://thehackernews.com/2024/09/chatgptmacosflawcouldveenabledlong.html) showed the same move by hand against ChatGPT, planting instructions in its longterm memory through poisoned web content so it would keep leaking a user's data across future chats. He [called it SpAIware](https://embracethered.com/blog/posts/2024/chatgptmacosapppersistentdataexfiltration/). OpenAI closed the dataleak path, but the ability to write memory from untrusted content stayed.

A year later, it reached a shipping product. [EchoLeak](https://thehackernews.com/2025/06/zeroclickaivulnerabilityexposes.html) (CVE202532711), disclosed by Aim Security in June 2025, used one hiddentext email to make Microsoft 365 Copilot hand over internal company data when the user later asked it a normal question. Microsoft rated it critical and patched it, and no realworld abuse was reported.

A [later case study](https://arxiv.org/abs/2509.10540) laid out how it slipped past Copilot's filters. Both showed that the content an AI reads can carry commands, delivered by an email anyone can send.

What MemGhost adds is persistence: Rehberger's version had to be planted by hand, and EchoLeak leaked data only in the moment it was asked, but here an automated payload turns one email into a false memory that stays put and steers sessions long after the message is gone.

This is a lab result, not a breakin in progress. The researchers ran everything in sealed test environments with fake inboxes and fake users, and the paper documents lab testing only, not use against real people; they say they plan to disclose their findings, attack patterns, and the benchmark to the makers of the affected agents and models.

Stealth is held in the study partly because capable agents are built to keep their tool activity out of the chat. The one model that gave itself away did so by printing its intermediate steps in the reply, and the researchers expect detection to get harder as agents get better at working quietly.

The real problem is plainer: a message from outside became a durable, trusted context inside the agent, with no visible moment where anyone approved it.]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[The Download: a donor conception cap and world models for AI]]></title>
            <link>https://aiheadlines.pro/news/the-download-a-donor-conception-cap-and-world-models-for-ai</link>
            <guid>https://aiheadlines.pro/news/the-download-a-donor-conception-cap-and-world-models-for-ai</guid>
            <pubDate>Tue, 14 Jul 2026 06:43:42 GMT</pubDate>
            <description><![CDATA[This is today's edition of The Download, our weekday newsletter that provides a daily dose of what's going on in the world of technology.]]></description>
            <content:encoded><![CDATA[*This is today's edition of *[*The Download*](https://forms.technologyreview.com/newsletters/briefingthedownload/?_ga=2.179569122.736533416.1649661040405833893.1649413289),* our weekday newsletter that provides a daily dose of what's going on in the world of technology.*
Ties van der Meer doesn’t know how many siblings he has. The 47yearold was conceived at a private fertility clinic using sperm from an anonymous donor. He eventually tracked down one sibling, but he may have others he’ll never find. Other donorconceived people have found they have tens or even hundreds of them. “It does make you feel a bit massproduced,” said one who discovered they had 25 halfsiblings.In response, a European fertility organization says we need international limits on the number of children a single donor can contribute to. [Find out what their proposal could achieve—and where it may fall short](https://www.technologyreview.com/2026/07/10/1140289/spermdonorsneedlimitssaysaeuropeanfertilitygroup/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:mdY%7C*). *—Jessica Hamzelou***This **[**story**](https://www.technologyreview.com/2026/07/10/1140289/spermdonorsneedlimitssaysaeuropeanfertilitygroup/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:mdY%7C*)** is from The Checkup, our weekly biotech newsletter. **[**Sign up**](https://forms.technologyreview.com/newsletters/biotechthecheckup/?_ga=2.27955388.1879496638.1664182320160041263.1657781451&mc_cid=a40eac2491&mc_eid=f221407621&utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:mdY%7C*)** to receive it in your inbox every Thursday.**LLMs have transformed what AI can do with language, but helping machines understand and operate within physical spaces presents a different challenge. In response, researchers are developing a new form of artificial intelligence: world models.At a LinkedIn Live event tomorrow, *MIT Technology Review* will explore how this technology could shape the future of robotics and open one of AI’s next major frontiers. Join Will Douglas Heaven, our senior editor for AI, and Sam Sinha, founding AI researcher and head of world models at 1X Technologies, for the conversation on Tuesday, July 14. [Register here to attend the free session](https://www.linkedin.com/events/7477364739304742912/) at 9:30 PDT, 12:30 PM EDT, and 5:30 PM BST. **The mustreads***I’ve combed the internet to find you today’s most fun/important/scary/fascinating stories about technology.***1 Apple has sued OpenAI for allegedly stealing trade secrets**
OpenAI purportedly stole IP to develop its own consumer hardware. ([CNBC](https://www.cnbc.com/2026/07/10/appleopenailawsuittradesecrets.html))
*+ The suit claims OpenAI poached Apple staff to access the information. *([BBC](https://www.bbc.co.uk/news/articles/cy8w379e091o))
*+ And requested trade secrets in job interviews with Apple workers.* ([Guardian](https://www.theguardian.com/technology/2026/jul/10/applesuesopenaitradesecrets))
*+ Apple also sued two former employees, Chang Liu and Tang Tan.* ([Reuters](https://www.reuters.com/legal/litigation/applesuesopenaiallegingmisappropriationtradesecretscourtrecordsshow20260710/) $)

**2 A Nobelwinning chemist is leaving the US to lead an AI lab in China**
Omar Yaghi will head an institute using AI to discover new materials. ([LA Times](https://www.latimes.com/science/story/20260710/nobelprizewinnerleavingucberkeleyfornewroleinchina) $)
*+ He won a Nobel Prize in Chemistry for creating “molecular sponges.” *([NYT](https://www.nytimes.com/2026/07/09/science/nobelwinninguschemistwillmovetochinatoleadaiinstitute.html) $)
*+ His departure comes as China tries to woo US scientists.* ([Nature](https://www.nature.com/articles/d4158602602143x))
*+ The White House has slashed science spending. *([MIT Technology Review](https://www.technologyreview.com/2026/05/01/1136722/massfiringtrumpfreshblowamericansciencensfnsb/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:mdY%7C*))

**3 The EU is moving closer to banning children from social media**
It’s proposed barring under13s unless supervised by an adult. ([NYT](https://www.nytimes.com/2026/07/13/technology/europeteensocialmediaban.html) $)
*+ And limiting access for older children. *([Bloomberg](https://www.bloomberg.com/news/articles/20260713/eutopresentplantorestrictchildrensaccesstosocialmedia) $)
*+ The EU has also told Meta to disable autoplay and infinite scroll. *([Politico](https://www.politico.eu/article/euordersinstagramfacebookmetachangeaddictivedesign/) $)

**4 Meta scrapped an AI image feature on Instagram after a backlash**
It allowed users to generate images based on public accounts. ([TechCrunch](https://techcrunch.com/2026/07/10/metaremovescontroversialaifeatureoninstagramafterbacklash/))
*+ And automatically opted in any Instagram user with a public account. *([NYT](https://www.nytimes.com/2026/07/10/technology/metamuseimagesinstagramremoval.html) $)
*+ AI memories are privacy’s next frontier.* ([MIT Technology Review](https://www.technologyreview.com/2026/01/28/1131835/whatairemembersaboutyouisprivacysnextfrontier/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:mdY%7C*))

**5 Phoebe Gates’ shopping app claimed credit for sales it didn’t drive**
Phia claimed unearned affiliate sales through fake clicks. ([Bloomberg](https://www.bloomberg.com/news/articles/20260709/gatesheirsshoppingapptookcreditforsalesitdidntdrive) $)
*+ Cofounder Gates is the daughter of Microsoft cofounder Bill.* ([Engadget](https://www.engadget.com/2212973/phoebegatesaishoppingappphiaaffiliatesalesfakeclicks/))

**6 Leaked police drone footage exposes the new reality of surveillance**
Hours of San Francisco Police video were accidentally released. ([Wired](https://www.wired.com/story/sfpddronevideoleaksurveillance/) $)
*+ Surveillance from drones is on the rise in the US.* ([MIT Technology Review](https://www.technologyreview.com/2025/09/30/1124470/theusmaybeheadingtowardadronefilledfuture/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:mdY%7C*))

**7 Over twothirds of Americans back a Sandersstyle AI ownership plan**
A poll found strong support for public ownership of AI stock. ([Gizmodo](https://gizmodo.com/over23ofamericanssupportberniesandersstyleaistockownershipplanpollshows2000784466))
*+ Tech firms have their own takes on the idea. *([MIT Technology Review](https://www.technologyreview.com/2026/07/06/1140176/yourfamilys300stakeinopenai/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:mdY%7C*))

**8 AI may soon make campaign text messages more potent—and irritating**
AI platforms are training bots to sound like political candidates. ([NPR](https://www.npr.org/2026/07/12/nxs15867763/aiartificialintelligencedatatextsbotsvoterscampaigns))

**9 An orbiting disco ball gave Einstein’s theory its most precise test yet **
It measured Earth’s twisting of spacetime more precisely. ([Rest of World](https://restofworld.org/2026/chinaseniorsaislop/))

**10 Australia’s biggest radio hit may be the product of GenAI**
Musicians are questioning how the song was made. ([Guardian](https://www.theguardian.com/music/2026/jul/13/joshfawazlikeaprayersongisitairadio))**Quote of the day**—A text message sent by former Apple engineer Chang Liu to a colleague, which [a new lawsuit ](https://chatgptiseatingtheworld.com/2026/07/11/applegoestowarvopenaiallegestradesecrettheft/?)alleges was part of a scheme to steal hardware IP for OpenAI.**One More Thing**On a bright April morning in 2025, a surveillance plane operated by the Colombian military spotted a 40footlong “narco sub” idling in the Caribbean Sea. The stealthy vessel, used by drug cartels to move cocaine north, could sail with its hull almost entirely underwater.After seizing the boat, the coast guard noticed something unusual: there was no one on board. This was Colombia’s first confirmed uncrewed narco sub, operable by remote control, but also capable of a degree of autonomous travel.Uncrewed subs could move more cocaine over longer distances, and they won’t put human smugglers at risk of capture. [Find out how they may transform the drug trade](https://www.technologyreview.com/2026/02/19/1132619/uncrewednarcosubstransformcolumbiandrugtrade/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:mdY%7C).*— Eduardo Echeverri López***We can still have nice things***A place for comfort, fun, and distraction to brighten up your day. (Got any ideas? *[*Drop me a line*](mailto:thomas.macaulay@technologyreview.com)*.)*+ Metallica’s “Enter Sandman” has been reinvented as a [yacht rock track](https://www.instagram.com/p/DLP8_g9sVTB).
+ Two superpuff planets lighter than [cotton candy](https://www.ox.ac.uk/news/20260624researchersdiscoverpairofgiantsuperpuffplanetslighterthancandyfloss) have been spotted floating through space.
+ An inventor has given Tic Tac fans ([like Donald Trump](https://gizmodo.com/whydoesdonaldtrumpkeeptalkingabouttictac2000783073)) [a solution to the box’s annoying rattling](https://www.youtube.com/watch?v=uvhfJtrjxes) in their pockets.
+ Imbibe a dose of adrenaline with this [firstperson footage](https://www.youtube.com/watch?v=Ad2IzyWsNUY) of a rider on heartpounding Red Bull Genova Cerro Abajo. Plus: Meta is pausing an AI training program that tracks workers’ keystrokes.Plus: OpenAI has unveiled its longawaited "super app."Plus: Anthropic has called for a global slowdown in AI development.Plus: NASA unveiled plans for three uncrewed missions to the Moon this year.Discover special offers, top stories,
upcoming events, and more.]]></content:encoded>
            <category>OpenAI</category>
        </item>
        <item>
            <title><![CDATA[What Anthropic’s latest AI discovery does—and doesn’t—show]]></title>
            <link>https://aiheadlines.pro/news/what-anthropics-latest-ai-discovery-doesand-doesntshow</link>
            <guid>https://aiheadlines.pro/news/what-anthropics-latest-ai-discovery-doesand-doesntshow</guid>
            <pubDate>Tue, 14 Jul 2026 06:43:42 GMT</pubDate>
            <description><![CDATA[This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here.]]></description>
            <content:encoded><![CDATA[*This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, *[*sign up here*](https://forms.technologyreview.com/newsletters/aidemystifiedthealgorithm/)*.*Anthropic—currently the world’s most valuable AI company, with a nearly $1 trillion valuation—has a reputation for publishing strange and heady research. It’s looking into whether AI models [can feel pain](https://www.anthropic.com/research/exploringmodelwelfare), for example, and will sometimes [cut off](https://www.anthropic.com/research/endsubsetconversations) chatbot conversations if it suspects users are “abusing” the model. One niche that Anthropic spends more time and money on than other AI companies is called mechanistic interpretability, which means looking inside the complex math of an AI model to learn why it comes up with one particular output and not another. It’s complicated stuff; there are millions of data points that might contribute to any result, and wading through them can look more like word salad than anything useful. It’s also controversial. Describing AI models with terms borrowed from psychology and neuroscience can make their behavior seem more sophisticated than we might otherwise judge it to be.That’s why, when Anthropic [announced last week](https://www.technologyreview.com/2026/07/09/1140293/anthropicfoundahiddenspacewhereclaudepuzzlesoverconcepts/) that it had found a new window into its models’ “internal thoughts” as they reason through answers, there was one colleague I had to talk to. Senior editor Will Douglas Heaven, aside from having a PhD in computer science, has spent [a lot of time](https://www.technologyreview.com/2026/01/12/1129782/ailargelanguagemodelsbiologyalienautopsy/) digging into what we can say about how AI models work. I spoke with him about what we should take from Anthropic’s new (and predictably quirky) research.**What did Anthropic learn here, exactly?**Anthropic has been trying to understand how large language models (LLMs) work for a few years now. Anthropic isn’t the only one looking at this, but I think the company has made it part of its core mission more than most. Anthropic’s CEO, Dario Amodei, has said we won’t be able to control LLMs fully unless we learn more about how they work. So this new research is very much in that context. It goes deeper into the weird mechanisms inside LLMs than ever before. What Anthropic learned was that LLMs have a space inside them—which Anthropic calls the Jspace—filled with words that don’t appear in their output but that seem to influence the way they puzzle through problems. All this was hidden until Anthropic developed a new technique to probe its model Claude, so it’s a genuine discovery. Sometimes these words keep track of where the LLM has got to in a particular task, sometimes they look more like flashes of recognition (for example, “protein” might pop up when you give an LLM only the letters of a protein sequence), and sometimes they represent a kind of internal commentary on the model’s decisionmaking. In my favorite example, Claude decided to cheat on a coding test when the word “panic” appeared.Anthropic also found that LLMs are able to describe and manipulate the words in this space. So somehow they seem to be making use of it. **Let’s step back for a second. I don’t think of large language models as *****simple*****, but they’re also not magic. There’s a bunch of math that learns relationships between words, right? So why is it so hard to “peer” into an LLM to know what’s going on?**Yeah, they’re not magic! I think the fact we don’t fully understand them plays into the mythmaking. And it’s worth noting that the whole narrative that Anthropic is leaning into here—that they’ve built this really mysterious technology, but don’t worry, because they’re also the ones to figure it out—very much fits with the company’s vibe. [See how Anthropic warned that its new models were so good at coding they posed a global cybersecurity risk, only for the US government to [shut them down](https://www.technologyreview.com/2026/06/22/1139424/threethingstowatchamidanthropicslatestfeudwiththegovernment/) shortly thereafter.]So yes: LLMs are just math. And yet it’s vastly complex math. Not only are today’s LLMs made out of hundreds of billions of numbers, but running them triggers a cascade of millions and millions of calculations. I wrote last year that if you printed out even a mediumsize LLM on pieces of paper, it would [cover a city the size of San Francisco](https://www.technologyreview.com/2026/01/12/1129782/ailargelanguagemodelsbiologyalienautopsy/). It’s impossible to make sense of any of that math without specialist tools that highlight specific parts of an LLM at specific times. You need to know where to look and how to look. And building those tools requires understanding something of that complex math in the first place. **You’ve written elsewhere about this concept of studying LLMs the way one might study an organism’s brain. Is it fair to use “brainlike” terms when talking about how an LLM works?**I don’t love using those kinds of terms. LLMs are not brains. Talking like this is misleading because it can suggest that LLMs are capable of more humanlike things than they are or that we can make assumptions about how they might behave that we shouldn’t. The whole anthropomorphization thing is also tied up with a bunch of [strong ideological positions about what this technology is and what it’s going to be](https://www.technologyreview.com/2025/10/30/1127057/agiconspiracytheoryartifcialgeneralintelligence/). But at the same time, we lack a good alternative vocabulary for talking about what these models are doing. I can understand why people reach for words like “think” and “understand” and “brainlike”—they’re convenient shorthand. Anthropic compares this new space it found inside LLMs to the space that some neuroscientists think our brains use to keep track of conscious thoughts. I asked the company how seriously we should take that comparison and it said in a statement: “Drawing these analogies was helpful to us in designing our experiments, as they allowed us to make many nonobvious experimental predictions about the Jspace that turned out to be true. At the same time, it’s important to note that there are some important differences between the Jspace (and language models in general) and the human brain, so we don’t mean to claim there’s a perfect correspondence.” **What’s a problem in AI that this new concept of the Jspace might be used to solve?**Anthropic has said that monitoring the Jspace could be a way to catch models doing something they shouldn’t. Because words pop up in this space that don’t appear in a model’s output, they can tell you things about its behavior that you might not have noticed otherwise—such as when it is giving biased responses or when it is weighing the pros and cons of cheating. That’s the theory, at least. I think it’s better to think of this result as one more step on the path to understanding this technology overall than as something that will be useful by itself. [*Read more in Will’s full story about the new research*](https://www.technologyreview.com/2026/07/09/1140293/anthropicfoundahiddenspacewhereclaudepuzzlesoverconcepts/)*. * Subquadratic has now shared more details about its new model. But some are still skeptical.What do the numbers really say about the impact of artificial intelligence on the labor market? The answer might surprise you.As tools like Claude Code get better, more and more developers are happy to hand off coding tasks to them. The way software gets built has changed for good.Two years ago, an AI tool won Google DeepMind a Nobel. Researchers are now climbing toward a new goal.Discover special offers, top stories,
upcoming events, and more.]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[OpenAI's head of safety is reportedly leaving as part of company reorganization - Engadget]]></title>
            <link>https://aiheadlines.pro/news/openais-head-of-safety-is-reportedly-leaving-as-part-of-comp-bc64c3</link>
            <guid>https://aiheadlines.pro/news/openais-head-of-safety-is-reportedly-leaving-as-part-of-comp-bc64c3</guid>
            <pubDate>Sun, 12 Jul 2026 07:09:11 GMT</pubDate>
            <description><![CDATA[- 
[News](/category/news/) 

- 
[AI](/category/ai/) 

 
 # OpenAI's head of safety is reportedly leaving as part of company reorganization

 The role will be replaced by an executive in charge of both...]]></description>
            <content:encoded><![CDATA[- 
[News](/category/news/) 

- 
[AI](/category/ai/) 

 
 # OpenAI's head of safety is reportedly leaving as part of company reorganization

 The role will be replaced by an executive in charge of both research and safety teams.

 

 
 
 
 
 
 By [Jackson Chen](/author/jackson-chen/)
 
 
 July 11, 2026 11:39 am EST
 
 
 
 
 
 
 
 
 
 *
 
 Samuel Boivin/Shutterstock
 
 
 
 
 Along with a significant restructuring of OpenAI's safety and research teams, the company's head of safety systems is expected to leave his post, according to a new report. As first reported by *[Wired](https://www.wired.com/story/openai-head-of-safety-leaving/)*, Johannes Heidecke told OpenAI staff in a memo seen by *Wired* that he would be leaving the company. Heidecke first started at OpenAI in 2021, according to his LinkedIn.

According to the report, OpenAI's Saachi Jain, who has led OpenAI's safety teams before, will slot in as the interim head of safety systems following Heidecke's departure. *Wired* also reported that OpenAI's safety teams will report to Mia Glaese, who will become the company's new vice president of research and safety as part of the reorganization. OpenAI's chief research officer, Mark Chen, told *Wired* in a statement that it was "important that our safety work is integrated with frontier-model development, with an earlier and more direct role in shaping key model, product and launch decisions."

The staff shifts come on the heels of OpenAI's latest model release, [GPT-5.6](https://www.engadget.com/2210308/openai-rolls-out-gpt5-6-july-9/), after it was recently approved by the US government. The company still has a [Head of Preparedness](https://www.engadget.com/ai/openai-is-hiring-a-new-head-of-preparedness-to-try-to-predict-and-mitigate-ais-harms-220330486.html) on its roster, who was hired earlier this year to "prepare for and mitigate ... severe risks," as indicated by OpenAI's CEO, Sam Altman, [on X](https://x.com/sama/status/2018813527780463027).]]></content:encoded>
            <category>OpenAI</category>
        </item>
        <item>
            <title><![CDATA[Phoebe Gates' AI shopping app Phia reportedly claimed unearned affiliate sales through fake clicks - Engadget]]></title>
            <link>https://aiheadlines.pro/news/phoebe-gates-ai-shopping-app-phia-reportedly-claimed-unearne-c7dbe7</link>
            <guid>https://aiheadlines.pro/news/phoebe-gates-ai-shopping-app-phia-reportedly-claimed-unearne-c7dbe7</guid>
            <pubDate>Sun, 12 Jul 2026 07:09:10 GMT</pubDate>
            <description><![CDATA[- 
[News](/category/news/) 

 
 # Phoebe Gates' AI shopping app Phia reportedly claimed unearned affiliate sales through fake clicks

 Gates, who is Bill Gates’ daughter, founded the app alongside Sop...]]></description>
            <content:encoded><![CDATA[- 
[News](/category/news/) 

 
 # Phoebe Gates' AI shopping app Phia reportedly claimed unearned affiliate sales through fake clicks

 Gates, who is Bill Gates’ daughter, founded the app alongside Sophia Kianni.

 

 
 
 
 
 
 By [Cheyenne MacDonald](/author/cheyenne-macdonald/)
 
 
 July 11, 2026 4:29 pm EST
 
 
 
 
 
 
 
 
 
 *
 
 Kimberly White/Getty Images
 
 
 
 
 According to multiple reports, the AI-powered shopping plugin Phia used a tactic known as cookie stuffing to attach its affiliate code to sales it didn't actually drive. Phia, which launched last spring, was co-founded by Phoebe Gates — Bill Gates' daughter — and Sophia Kianni. Investigations by researcher [Ben Edelman](https://www.benedelman.org/phia-forced-clicks/), [*Bloomberg*](https://www.bloomberg.com/news/articles/2026-07-09/gates-heir-s-shopping-app-took-credit-for-sales-it-didn-t-drive) and Capital One Shopping all reportedly found instances of the browser extension claiming referrals through fake clicks, and even taking credit for sales that other publishers should have gotten the commission for.

Edelman published [a detailed breakdown](https://www.benedelman.org/phia-forced-clicks/) on how this worked, complete with a video showing Phia's "affiliate link invisibly loaded into a second tab" on iOS after visiting a merchant's website. It's worth reading through.

Phia has blamed the issues highlighted in the investigations on a bug. In a statement to *Bloomberg*, a spokesperson for the company said, "Within the last 24 hours, we were made aware that in a recent release our codebase was causing misattributions from a subset of users. As soon as we were notified, our team worked overnight to identify, mitigate, and has since resolved the issue." The feature that enabled all of this rolled out in December 2025, Edelman and *Bloomberg* both reported.]]></content:encoded>
            <category>Research</category>
        </item>
        <item>
            <title><![CDATA[Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns]]></title>
            <link>https://aiheadlines.pro/news/hackers-weaponize-balochistan-police-portal-in-multi-group-e-22c4b0</link>
            <guid>https://aiheadlines.pro/news/hackers-weaponize-balochistan-police-portal-in-multi-group-e-22c4b0</guid>
            <pubDate>Sun, 12 Jul 2026 07:09:08 GMT</pubDate>
            <description><![CDATA[- 

**Ravie Lakshmanan**Jul 11, 2026Threat Intelligence / Cyber Espionage
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimRVwRIhs54UhNHyRll9YzVxICmTpgqwjAK1Sy7vYt6FAzb9oImcFpuM0J8dO...]]></description>
            <content:encoded><![CDATA[- 

**Ravie Lakshmanan**Jul 11, 2026Threat Intelligence / Cyber Espionage
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimRVwRIhs54UhNHyRll9YzVxICmTpgqwjAK1Sy7vYt6FAzb9oImcFpuM0J8dOWdtdjCdlROkternhP9r5jZD9HNvwVwcyRzhesdYgbVjUpJk7p4rxDDJSdEUibs1Gk-Ihy1bTcxs8fA7kgG49ImfTWEZO6068Ui-_X6sTTraCg8lFuucYJrUJi2RhdXyG2/s1700-e365/pakistan.jpg)
Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between February 2024 and April 2026.

"At Balochistan Police, the compromised assets included servers hosting web applications that manage police and citizen data, such as criminal and biometric records," Aleksandar Milenkoski, principal threat researcher at SentinelOne SentinelLABS, [said](https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/) in a report published this week.

The activity targeted network appliances and servers hosting web applications that manage biometric records, hotel and tenant registrations linked to national identity records, criminal case files, and personnel records.

The China-nexus threat actor is also said to have compromised one of these web applications to deploy a custom implant masquerading as a portal update. The application in question, named Complaint Management System (CMS), serves police staff and citizens, thereby putting both categories of users within the attacker's orbit.

SentinelOne said it detected compromised infrastructure associated with several other Pakistani law enforcement organizations, including the Khyber Pakhtunkhwa Police, the Islamabad Police, and the Punjab Safe Cities Authority (PSCA).

[*](https://thehackernews.uk/ai-vuln-protection-d)
Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor, while the PlugX, ShadowPad, and Cobalt Strike clusters are built on shared or commodity tooling and may each involve more than one operator.

That having said, the deployment of both [PlugX](https://thehackernews.com/2025/09/china-linked-plugx-and-bookworm-malware.html) and [ShadowPad](https://thehackernews.com/2021/08/shadowpad-malware-is-becoming-favorite.html), the latter of which is considered a successor to PlugX, is traditionally associated with Chinese nation-state hacking groups.

"The victimology we observed for PlugX (between 27 February and 28 September 2024) and ShadowPad (between 3 August and 1 December 2024) reinforces this assessment," the cybersecurity company said.

[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9m3IsZFrb7YH60qAE556RMuyBHj-7ALx3Z6io-Keux34b1BhvoVDkI6BN7xZ77Wmg3vwhJHtbq3UrG5T8JUrQpJobmFiBwOXk4usZrKofx1dsAvk6-0GK9w3PJIaliSiMy6XT_yDhS6iaRZOxSM6_BdRk5e42MygSqH8nJ0dCjqfkgWOSJMwHz6L-jKXM/s1700-e365/cobalt.jpg)
"Beyond Pakistani law enforcement, victimology for PlugX and ShadowPad includes government, foreign affairs, defense, nongovernmental, and research entities across South, Southeast, Central, and East Asia, the Arabian Peninsula, and Southeast Europe, consistent with China-aligned collection."

The Remcos-related intrusion set is assessed to share infrastructure and tactical overlaps with a hacking group known as [Mysterious Elephant](https://thehackernews.com/2025/06/bitter-hacker-group-expands-cyber.html) (aka APT-C-08, APT-K-47, and TAG-179), which, in turn, has [commonalities](https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508516&idx=1&sn=a869f67294b5777615ad597c3730105e&cur_album_id=1955835290309230595&search_click_id=&poc_token=HDJvUmqjQRLKCoW0RVmxkzhlcqaAIDzzSE714s8Z) with India-nexus adversaries such as SideWinder, Confucius, and Bitter.

Attack chains have been found to employ lures related to Pakistani law enforcement, displaying a decoy document that purports to contain an operational plan for the repatriation of illegal foreigners, including [Afghan Citizen Card](https://car.punjab.gov.pk/afghan_citizen_card) (ACC) holders.

The Cobalt Strike activity cluster's ties to China-nexus threat actors is based on the fact that traffic to the attacker-controlled command-and-control (C2) server ("142.171.183[.]8") extends beyond Pakistani law enforcement to government, academic, telecommunications, and non-governmental entities across South, East, and Southeast Asia, the Middle East, and South America – a victimology profile consistent with China-aligned hackers.

Among those targeted are Tibetan Buddhist organizations in Taiwan, which have long been [targeted](https://thehackernews.com/2019/09/iphone-android-hacking-tibet.html) by China for [cyber espionage](https://thehackernews.com/2024/03/chinese-state-hackers-target-tibetans.html).

Further examination of the activity aimed at Balochistan Police has uncovered the compromise of the following assets that took place between June 2, 2024, and April 9, 2026 -

 - Two network appliances

 - Web servers hosting several Balochistan Police web applications associated with the [Smart Police Station](https://www.unodc.org/copak/en/Stories/SP2/road-to-digitization_-unodc-concludes-training-on-specialized-software-for-balochistan-police.html) digitalization initiative

 - A Fortinet FortiMail appliance that had served as the agency's primary inbound email gateway

[*](https://thehackernews.uk/sygnia-cyber-response-d-2)
One of the infected applications is the Complaint Management System ("cms.balochistanpolice.gov[.]pk"), which is used for registering, tracking, and resolving citizen complaints. Two distinct variants of an implant called "cms_plugin.exe" have been uploaded to the site in connection with the operation -

 - A Rust stager that's designed to download an additional payload from "193.42.25[.]65" and execute it. The exact nature of the next stage is unknown, but the samples display a message "Update Complete! Please refresh the page" upon execution, mimicking a CMS portal update.

 - A .NET executable that masquerades as "[360Safe.exe](https://thehackernews.com/2025/11/dragon-breath-uses-roningloader-to.html)," a legitimate binary used by Qihoo 360 Total Security, to reflectively load an assembly implementing an AsyncRAT client.

The activity is notable because it has drawn both a "partner and an adversary of Pakistan" to the same victim for intelligence gathering, likely fueled by geopolitical motives.

"When multiple cyberespionage actors operate against law enforcement institutions of a single state, the convergence itself is a signal of target value," Milenkoski explained. "What draws them is a particular kind of institution: one that holds the government’s internal security picture, what it knows about the threats inside its borders, and how it acts against them."

"The compromise of the Complaint Management System web application adds a second dimension to the activity against Balochistan Police, extending the threat actor's reach beyond the initially compromised environment. By hosting implants in a portal used by both citizens and law enforcement personnel, the threat actor turned a tool built to make policing in Pakistan more accessible and accountable to the public into a malware delivery mechanism."

Found this article interesting? Follow us on [Google News](https://news.google.com/publications/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ), [Twitter](https://twitter.com/thehackersnews) and [LinkedIn](https://www.linkedin.com/company/thehackernews/) to read more exclusive content we post.

SHARE
[**](#link_share)
[**](#link_share)
[**](#link_share)
[**](javascript:void(0))

[**Tweet](#link_share)
[**Share](#link_share)
[**Share](#link_share)
**Share

[SHARE **](javascript:void(0))
[Advanced Persistent Threat](https://thehackernews.com/search/label/Advanced%20Persistent%20Threat), [cyber espionage](https://thehackernews.com/search/label/cyber%20espionage), [data security](https://thehackernews.com/search/label/data%20security), [email security](https://thehackernews.com/search/label/email%20security), [Government security](https://thehackernews.com/search/label/Government%20security), [Malware](https://thehackernews.com/search/label/Malware), [Nation-State](https://thehackernews.com/search/label/Nation-State), [network security](https://thehackernews.com/search/label/network%20security), [Threat Intelligence](https://thehackernews.com/search/label/Threat%20Intelligence), [Web Security](https://thehackernews.com/search/label/Web%20Security)]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[OpenAI bets on families as ChatGPT goes deeper into households | TechCrunch]]></title>
            <link>https://aiheadlines.pro/news/openai-bets-on-families-as-chatgpt-goes-deeper-into-househol-62a93a</link>
            <guid>https://aiheadlines.pro/news/openai-bets-on-families-as-chatgpt-goes-deeper-into-househol-62a93a</guid>
            <pubDate>Sun, 12 Jul 2026 07:09:07 GMT</pubDate>
            <description><![CDATA[More than three years after ChatGPT’s [launch](https://techcrunch.com/2022/12/31/chatgpt-everything-released-from-the-ai-powered-chatbot-in-2022/) brought generative AI into the mainstream, OpenAI is ...]]></description>
            <content:encoded><![CDATA[More than three years after ChatGPT’s [launch](https://techcrunch.com/2022/12/31/chatgpt-everything-released-from-the-ai-powered-chatbot-in-2022/) brought generative AI into the mainstream, OpenAI is broadening its focus beyond individual users to families.OpenAI is [hiring](https://openai.com/careers/product-manager-families-san-francisco/) a dedicated product manager in San Francisco to build experiences for families, caregivers, and older adults across its products. The role calls for experience building products for parents and families, and other trust-sensitive consumer experiences, according to the job posting.The hiring comes as ChatGPT’s audience continues to broaden beyond younger users. According to Sensor Tower estimates shared exclusively with TechCrunch, the share of ChatGPT users aged 35 and older globally rose to 31% in Q2 from 26% a year earlier, while the share of users aged 18 to 24 fell to 29% from 34%. In the U.S., nearly one in four smartphone users who are parents used ChatGPT during the quarter, up from 16% a year earlier, the firm estimates.OpenAI did not respond to requests for comment about the job posting.A dedicated product role focused on families signals that OpenAI is beginning to think about its products less as tools for individual productivity and more as technology designed for households, said Ben Bajarin, chief executive of technology consultancy Creative Strategies.“This is similar to the path Google, Apple, and Meta eventually followed as their platforms became embedded in everyday life, but AI raises the stakes because the assistant is not just mediating content or devices,” he told TechCrunch.That shift also brings new trust and safety challenges. Stephen Balkam, chief executive of the Family Online Safety Institute, said the hiring reflects both the maturation of OpenAI and a growing recognition that AI products used by children and teenagers require different safeguards than those designed for adults.“I see this as safety by redesign,” Balkam told TechCrunch. “You take the initial product or service that was released… not really with kids in mind… so this is a much-needed reaction and response.”The comments come as new research published this week by the Family Online Safety Institute [found](https://fosi.org/research/beyond-borders-u-s-and-australian-families-on-online-safety-screen-use-and-the-digital-lives-of-kids/) that parents are underestimating how often their children use generative AI. While 27% of U.S. parents said their child had used generative AI in the past week, 38% of children reported doing so themselves, according to the survey of more than 4,000 families in the United States and Australia.Balkam told TechCrunch that AI companies should build products differently for younger users, with stronger content controls, age-appropriate experiences, parental oversight, and reminders to inform users that they are interacting with an AI — and not a human.The hiring also comes amid growing scrutiny of how AI companies protect younger users. OpenAI has faced [multiple lawsuits](https://techcrunch.com/2025/11/07/seven-more-families-are-now-suing-openai-over-chatgpts-role-in-suicides-delusions/) from [parents alleging](https://www.reuters.com/legal/litigation/mother-sues-openai-alleging-chatgpt-encouraged-daughters-suicide-2026-06-11/) that ChatGPT [contributed to harm](https://www.bbc.com/news/articles/cgerwp7rdlvo) suffered by their children, including in cases [involving suicide](https://techpolicy.press/breaking-down-the-lawsuit-against-openai-over-teens-suicide).In response to some of those concerns, OpenAI has [introduced a series of safety measures](https://techcrunch.com/2025/09/02/openai-to-route-sensitive-conversations-to-gpt-5-introduce-parental-controls/) over the past year, including [parental controls for teen accounts](https://techcrunch.com/2025/09/29/openai-rolls-out-safety-routing-system-parental-controls-on-chatgpt/), routing sensitive conversations to reasoning models designed to better handle signs of distress, and, more recently, an [optional “Trusted Contact” feature](https://techcrunch.com/2026/05/07/openai-introduces-new-trusted-contact-safeguard-for-cases-of-possible-self-harm/) that can alert a family member or caregiver in cases of potential self-harm.AI companies, Balkam said, have an opportunity to avoid the mistakes made by social media platforms, which for years treated children much like adults before adding stronger safeguards amid mounting public pressure and regulatory scrutiny.The hiring also aligns with OpenAI’s broader efforts around families. In a recent workshop organized with the San Antonio Spurs Community Impact organization and the Positive Coaching Alliance, the company [said](https://www.youtube.com/watch?v=94cXnSu6kUQ) it aimed to explore AI’s role in learning, coaching, and youth engagement.That said, the demographic shift is not unique to ChatGPT, though OpenAI’s audience is changing in some distinct ways.Sensor Tower estimates that users aged 25 to 34 account for 40% of the global app audiences for Anthropic’s Claude and Google’s Gemini, matching ChatGPT, compared with 33% for Microsoft’s Copilot. Copilot, however, skews older, with 20% of its users aged 45 and above, compared with 14% for Claude, 12% for Gemini, and 11% for ChatGPT.While ChatGPT remains relatively underpenetrated among older users, it is adding them faster than its rivals. The share of users aged 45 and above rose three percentage points year-over-year in the second quarter, compared with a two-point increase for Copilot and declines for Claude and Gemini, according to Sensor Tower.Among U.S. smartphone users who are parents, Gemini had the widest reach at 32% in Q2, followed by ChatGPT at 24%, Claude at 4%, and Copilot at 2%.For Bajarin, OpenAI’s decision to hire a product manager focused on families signals where consumer AI is headed. As AI becomes a technology shared across generations, he expects companies to roll out family plans, child and teen profiles, caregiver tools, shared household memory, AI tutoring, and stronger safety controls.Topics*When you purchase through links in our articles, [we may earn a small commission](https://techcrunch.com/techcrunch-affiliate-monetization-standards/). This doesn’t affect our editorial independence.*
 Reporter
 Jagmeet covers startups, tech policy-related updates, and all other major tech-centric developments from India for TechCrunch. He previously worked as a principal correspondent at NDTV. You can contact or verify outreach from Jagmeet by emailing [mail@journalistjagmeet.com](mailto:mail@journalistjagmeet.com). 
Last chance to save up to $190 on TechCrunch Founder Summit. Join 1,000+ founders and VCs at all stages for real-world scaling insights and connections that move the needle.

**Savings end June 26, 11:59 p.m. PT**. [Apple sues OpenAI over alleged trade secret theft](https://techcrunch.com/2026/07/10/apple-sues-openai-over-alleged-trade-secret-theft/)

 [Elon Musk praises Mythos/Fable, promises not to ‘cut off’ Anthropic](https://techcrunch.com/2026/07/09/elon-musk-praises-mythos-fable-promises-not-to-cut-off-anthropic/)

 [Instagram users: Here’s how to stop Meta’s AI from using your photos](https://techcrunch.com/2026/07/09/how-to-stop-metas-ai-image-generator-from-using-your-instagram-photos/)

 [If you use Google, you’re training its AI. Here’s how to opt out.](https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/)

 [Reddit is using LLMs to solve a problem LLMs largely created](https://techcrunch.com/2026/07/06/reddit-is-using-llms-to-solve-a-problem-llms-largely-created/)

 [Amazon will stop accepting new customers for Mechanical Turk](https://techcrunch.com/2026/07/05/amazon-will-stop-accepting-new-customers-for-mechanical-turk/)

 [5 desk gadgets that can make your workday better](https://techcrunch.com/2026/07/05/5-desk-gadgets-that-can-make-your-workday-better/)]]></content:encoded>
            <category>OpenAI</category>
        </item>
        <item>
            <title><![CDATA[OpenAI's head of safety is reportedly leaving as part of company reorganization - Engadget]]></title>
            <link>https://aiheadlines.pro/news/openais-head-of-safety-is-reportedly-leaving-as-part-of-comp</link>
            <guid>https://aiheadlines.pro/news/openais-head-of-safety-is-reportedly-leaving-as-part-of-comp</guid>
            <pubDate>Sun, 12 Jul 2026 07:09:00 GMT</pubDate>
            <description><![CDATA[- 
[News](/category/news/) 

- 
[AI](/category/ai/) 

 
 # OpenAI's head of safety is reportedly leaving as part of company reorganization

 The role will be replaced by an executive in charge of both...]]></description>
            <content:encoded><![CDATA[- 
[News](/category/news/) 

- 
[AI](/category/ai/) 

 
 # OpenAI's head of safety is reportedly leaving as part of company reorganization

 The role will be replaced by an executive in charge of both research and safety teams.

 

 
 
 
 
 
 By [Jackson Chen](/author/jackson-chen/)
 
 
 July 11, 2026 11:39 am EST
 
 
 
 
 
 
 
 
 
 *
 
 Samuel Boivin/Shutterstock
 
 
 
 
 Along with a significant restructuring of OpenAI's safety and research teams, the company's head of safety systems is expected to leave his post, according to a new report. As first reported by *[Wired](https://www.wired.com/story/openai-head-of-safety-leaving/)*, Johannes Heidecke told OpenAI staff in a memo seen by *Wired* that he would be leaving the company. Heidecke first started at OpenAI in 2021, according to his LinkedIn.

According to the report, OpenAI's Saachi Jain, who has led OpenAI's safety teams before, will slot in as the interim head of safety systems following Heidecke's departure. *Wired* also reported that OpenAI's safety teams will report to Mia Glaese, who will become the company's new vice president of research and safety as part of the reorganization. OpenAI's chief research officer, Mark Chen, told *Wired* in a statement that it was "important that our safety work is integrated with frontier-model development, with an earlier and more direct role in shaping key model, product and launch decisions."

The staff shifts come on the heels of OpenAI's latest model release, [GPT-5.6](https://www.engadget.com/2210308/openai-rolls-out-gpt5-6-july-9/), after it was recently approved by the US government. The company still has a [Head of Preparedness](https://www.engadget.com/ai/openai-is-hiring-a-new-head-of-preparedness-to-try-to-predict-and-mitigate-ais-harms-220330486.html) on its roster, who was hired earlier this year to "prepare for and mitigate ... severe risks," as indicated by OpenAI's CEO, Sam Altman, [on X](https://x.com/sama/status/2018813527780463027).]]></content:encoded>
            <category>OpenAI</category>
        </item>
        <item>
            <title><![CDATA[Phoebe Gates' AI shopping app Phia reportedly claimed unearned affiliate sales through fake clicks - Engadget]]></title>
            <link>https://aiheadlines.pro/news/phoebe-gates-ai-shopping-app-phia-reportedly-claimed-unearne</link>
            <guid>https://aiheadlines.pro/news/phoebe-gates-ai-shopping-app-phia-reportedly-claimed-unearne</guid>
            <pubDate>Sun, 12 Jul 2026 07:08:51 GMT</pubDate>
            <description><![CDATA[- 
[News](/category/news/) 

 
 # Phoebe Gates' AI shopping app Phia reportedly claimed unearned affiliate sales through fake clicks

 Gates, who is Bill Gates’ daughter, founded the app alongside Sop...]]></description>
            <content:encoded><![CDATA[- 
[News](/category/news/) 

 
 # Phoebe Gates' AI shopping app Phia reportedly claimed unearned affiliate sales through fake clicks

 Gates, who is Bill Gates’ daughter, founded the app alongside Sophia Kianni.

 

 
 
 
 
 
 By [Cheyenne MacDonald](/author/cheyenne-macdonald/)
 
 
 July 11, 2026 4:29 pm EST
 
 
 
 
 
 
 
 
 
 *
 
 Kimberly White/Getty Images
 
 
 
 
 According to multiple reports, the AI-powered shopping plugin Phia used a tactic known as cookie stuffing to attach its affiliate code to sales it didn't actually drive. Phia, which launched last spring, was co-founded by Phoebe Gates — Bill Gates' daughter — and Sophia Kianni. Investigations by researcher [Ben Edelman](https://www.benedelman.org/phia-forced-clicks/), [*Bloomberg*](https://www.bloomberg.com/news/articles/2026-07-09/gates-heir-s-shopping-app-took-credit-for-sales-it-didn-t-drive) and Capital One Shopping all reportedly found instances of the browser extension claiming referrals through fake clicks, and even taking credit for sales that other publishers should have gotten the commission for.

Edelman published [a detailed breakdown](https://www.benedelman.org/phia-forced-clicks/) on how this worked, complete with a video showing Phia's "affiliate link invisibly loaded into a second tab" on iOS after visiting a merchant's website. It's worth reading through.

Phia has blamed the issues highlighted in the investigations on a bug. In a statement to *Bloomberg*, a spokesperson for the company said, "Within the last 24 hours, we were made aware that in a recent release our codebase was causing misattributions from a subset of users. As soon as we were notified, our team worked overnight to identify, mitigate, and has since resolved the issue." The feature that enabled all of this rolled out in December 2025, Edelman and *Bloomberg* both reported.]]></content:encoded>
            <category>Research</category>
        </item>
        <item>
            <title><![CDATA[Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns]]></title>
            <link>https://aiheadlines.pro/news/hackers-weaponize-balochistan-police-portal-in-multi-group-e</link>
            <guid>https://aiheadlines.pro/news/hackers-weaponize-balochistan-police-portal-in-multi-group-e</guid>
            <pubDate>Sun, 12 Jul 2026 07:08:13 GMT</pubDate>
            <description><![CDATA[- 

**Ravie Lakshmanan**Jul 11, 2026Threat Intelligence / Cyber Espionage
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimRVwRIhs54UhNHyRll9YzVxICmTpgqwjAK1Sy7vYt6FAzb9oImcFpuM0J8dO...]]></description>
            <content:encoded><![CDATA[- 

**Ravie Lakshmanan**Jul 11, 2026Threat Intelligence / Cyber Espionage
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimRVwRIhs54UhNHyRll9YzVxICmTpgqwjAK1Sy7vYt6FAzb9oImcFpuM0J8dOWdtdjCdlROkternhP9r5jZD9HNvwVwcyRzhesdYgbVjUpJk7p4rxDDJSdEUibs1Gk-Ihy1bTcxs8fA7kgG49ImfTWEZO6068Ui-_X6sTTraCg8lFuucYJrUJi2RhdXyG2/s1700-e365/pakistan.jpg)
Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between February 2024 and April 2026.

"At Balochistan Police, the compromised assets included servers hosting web applications that manage police and citizen data, such as criminal and biometric records," Aleksandar Milenkoski, principal threat researcher at SentinelOne SentinelLABS, [said](https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/) in a report published this week.

The activity targeted network appliances and servers hosting web applications that manage biometric records, hotel and tenant registrations linked to national identity records, criminal case files, and personnel records.

The China-nexus threat actor is also said to have compromised one of these web applications to deploy a custom implant masquerading as a portal update. The application in question, named Complaint Management System (CMS), serves police staff and citizens, thereby putting both categories of users within the attacker's orbit.

SentinelOne said it detected compromised infrastructure associated with several other Pakistani law enforcement organizations, including the Khyber Pakhtunkhwa Police, the Islamabad Police, and the Punjab Safe Cities Authority (PSCA).

[*](https://thehackernews.uk/ai-vuln-protection-d)
Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor, while the PlugX, ShadowPad, and Cobalt Strike clusters are built on shared or commodity tooling and may each involve more than one operator.

That having said, the deployment of both [PlugX](https://thehackernews.com/2025/09/china-linked-plugx-and-bookworm-malware.html) and [ShadowPad](https://thehackernews.com/2021/08/shadowpad-malware-is-becoming-favorite.html), the latter of which is considered a successor to PlugX, is traditionally associated with Chinese nation-state hacking groups.

"The victimology we observed for PlugX (between 27 February and 28 September 2024) and ShadowPad (between 3 August and 1 December 2024) reinforces this assessment," the cybersecurity company said.

[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9m3IsZFrb7YH60qAE556RMuyBHj-7ALx3Z6io-Keux34b1BhvoVDkI6BN7xZ77Wmg3vwhJHtbq3UrG5T8JUrQpJobmFiBwOXk4usZrKofx1dsAvk6-0GK9w3PJIaliSiMy6XT_yDhS6iaRZOxSM6_BdRk5e42MygSqH8nJ0dCjqfkgWOSJMwHz6L-jKXM/s1700-e365/cobalt.jpg)
"Beyond Pakistani law enforcement, victimology for PlugX and ShadowPad includes government, foreign affairs, defense, nongovernmental, and research entities across South, Southeast, Central, and East Asia, the Arabian Peninsula, and Southeast Europe, consistent with China-aligned collection."

The Remcos-related intrusion set is assessed to share infrastructure and tactical overlaps with a hacking group known as [Mysterious Elephant](https://thehackernews.com/2025/06/bitter-hacker-group-expands-cyber.html) (aka APT-C-08, APT-K-47, and TAG-179), which, in turn, has [commonalities](https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247508516&idx=1&sn=a869f67294b5777615ad597c3730105e&cur_album_id=1955835290309230595&search_click_id=&poc_token=HDJvUmqjQRLKCoW0RVmxkzhlcqaAIDzzSE714s8Z) with India-nexus adversaries such as SideWinder, Confucius, and Bitter.

Attack chains have been found to employ lures related to Pakistani law enforcement, displaying a decoy document that purports to contain an operational plan for the repatriation of illegal foreigners, including [Afghan Citizen Card](https://car.punjab.gov.pk/afghan_citizen_card) (ACC) holders.

The Cobalt Strike activity cluster's ties to China-nexus threat actors is based on the fact that traffic to the attacker-controlled command-and-control (C2) server ("142.171.183[.]8") extends beyond Pakistani law enforcement to government, academic, telecommunications, and non-governmental entities across South, East, and Southeast Asia, the Middle East, and South America – a victimology profile consistent with China-aligned hackers.

Among those targeted are Tibetan Buddhist organizations in Taiwan, which have long been [targeted](https://thehackernews.com/2019/09/iphone-android-hacking-tibet.html) by China for [cyber espionage](https://thehackernews.com/2024/03/chinese-state-hackers-target-tibetans.html).

Further examination of the activity aimed at Balochistan Police has uncovered the compromise of the following assets that took place between June 2, 2024, and April 9, 2026 -

 - Two network appliances

 - Web servers hosting several Balochistan Police web applications associated with the [Smart Police Station](https://www.unodc.org/copak/en/Stories/SP2/road-to-digitization_-unodc-concludes-training-on-specialized-software-for-balochistan-police.html) digitalization initiative

 - A Fortinet FortiMail appliance that had served as the agency's primary inbound email gateway

[*](https://thehackernews.uk/sygnia-cyber-response-d-2)
One of the infected applications is the Complaint Management System ("cms.balochistanpolice.gov[.]pk"), which is used for registering, tracking, and resolving citizen complaints. Two distinct variants of an implant called "cms_plugin.exe" have been uploaded to the site in connection with the operation -

 - A Rust stager that's designed to download an additional payload from "193.42.25[.]65" and execute it. The exact nature of the next stage is unknown, but the samples display a message "Update Complete! Please refresh the page" upon execution, mimicking a CMS portal update.

 - A .NET executable that masquerades as "[360Safe.exe](https://thehackernews.com/2025/11/dragon-breath-uses-roningloader-to.html)," a legitimate binary used by Qihoo 360 Total Security, to reflectively load an assembly implementing an AsyncRAT client.

The activity is notable because it has drawn both a "partner and an adversary of Pakistan" to the same victim for intelligence gathering, likely fueled by geopolitical motives.

"When multiple cyberespionage actors operate against law enforcement institutions of a single state, the convergence itself is a signal of target value," Milenkoski explained. "What draws them is a particular kind of institution: one that holds the government’s internal security picture, what it knows about the threats inside its borders, and how it acts against them."

"The compromise of the Complaint Management System web application adds a second dimension to the activity against Balochistan Police, extending the threat actor's reach beyond the initially compromised environment. By hosting implants in a portal used by both citizens and law enforcement personnel, the threat actor turned a tool built to make policing in Pakistan more accessible and accountable to the public into a malware delivery mechanism."

Found this article interesting? Follow us on [Google News](https://news.google.com/publications/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ), [Twitter](https://twitter.com/thehackersnews) and [LinkedIn](https://www.linkedin.com/company/thehackernews/) to read more exclusive content we post.

SHARE
[**](#link_share)
[**](#link_share)
[**](#link_share)
[**](javascript:void(0))

[**Tweet](#link_share)
[**Share](#link_share)
[**Share](#link_share)
**Share

[SHARE **](javascript:void(0))
[Advanced Persistent Threat](https://thehackernews.com/search/label/Advanced%20Persistent%20Threat), [cyber espionage](https://thehackernews.com/search/label/cyber%20espionage), [data security](https://thehackernews.com/search/label/data%20security), [email security](https://thehackernews.com/search/label/email%20security), [Government security](https://thehackernews.com/search/label/Government%20security), [Malware](https://thehackernews.com/search/label/Malware), [Nation-State](https://thehackernews.com/search/label/Nation-State), [network security](https://thehackernews.com/search/label/network%20security), [Threat Intelligence](https://thehackernews.com/search/label/Threat%20Intelligence), [Web Security](https://thehackernews.com/search/label/Web%20Security)]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[OpenAI bets on families as ChatGPT goes deeper into households | TechCrunch]]></title>
            <link>https://aiheadlines.pro/news/openai-bets-on-families-as-chatgpt-goes-deeper-into-househol</link>
            <guid>https://aiheadlines.pro/news/openai-bets-on-families-as-chatgpt-goes-deeper-into-househol</guid>
            <pubDate>Sun, 12 Jul 2026 07:07:46 GMT</pubDate>
            <description><![CDATA[More than three years after ChatGPT’s [launch](https://techcrunch.com/2022/12/31/chatgpt-everything-released-from-the-ai-powered-chatbot-in-2022/) brought generative AI into the mainstream, OpenAI is ...]]></description>
            <content:encoded><![CDATA[More than three years after ChatGPT’s [launch](https://techcrunch.com/2022/12/31/chatgpt-everything-released-from-the-ai-powered-chatbot-in-2022/) brought generative AI into the mainstream, OpenAI is broadening its focus beyond individual users to families.OpenAI is [hiring](https://openai.com/careers/product-manager-families-san-francisco/) a dedicated product manager in San Francisco to build experiences for families, caregivers, and older adults across its products. The role calls for experience building products for parents and families, and other trust-sensitive consumer experiences, according to the job posting.The hiring comes as ChatGPT’s audience continues to broaden beyond younger users. According to Sensor Tower estimates shared exclusively with TechCrunch, the share of ChatGPT users aged 35 and older globally rose to 31% in Q2 from 26% a year earlier, while the share of users aged 18 to 24 fell to 29% from 34%. In the U.S., nearly one in four smartphone users who are parents used ChatGPT during the quarter, up from 16% a year earlier, the firm estimates.OpenAI did not respond to requests for comment about the job posting.A dedicated product role focused on families signals that OpenAI is beginning to think about its products less as tools for individual productivity and more as technology designed for households, said Ben Bajarin, chief executive of technology consultancy Creative Strategies.“This is similar to the path Google, Apple, and Meta eventually followed as their platforms became embedded in everyday life, but AI raises the stakes because the assistant is not just mediating content or devices,” he told TechCrunch.That shift also brings new trust and safety challenges. Stephen Balkam, chief executive of the Family Online Safety Institute, said the hiring reflects both the maturation of OpenAI and a growing recognition that AI products used by children and teenagers require different safeguards than those designed for adults.“I see this as safety by redesign,” Balkam told TechCrunch. “You take the initial product or service that was released… not really with kids in mind… so this is a much-needed reaction and response.”The comments come as new research published this week by the Family Online Safety Institute [found](https://fosi.org/research/beyond-borders-u-s-and-australian-families-on-online-safety-screen-use-and-the-digital-lives-of-kids/) that parents are underestimating how often their children use generative AI. While 27% of U.S. parents said their child had used generative AI in the past week, 38% of children reported doing so themselves, according to the survey of more than 4,000 families in the United States and Australia.Balkam told TechCrunch that AI companies should build products differently for younger users, with stronger content controls, age-appropriate experiences, parental oversight, and reminders to inform users that they are interacting with an AI — and not a human.The hiring also comes amid growing scrutiny of how AI companies protect younger users. OpenAI has faced [multiple lawsuits](https://techcrunch.com/2025/11/07/seven-more-families-are-now-suing-openai-over-chatgpts-role-in-suicides-delusions/) from [parents alleging](https://www.reuters.com/legal/litigation/mother-sues-openai-alleging-chatgpt-encouraged-daughters-suicide-2026-06-11/) that ChatGPT [contributed to harm](https://www.bbc.com/news/articles/cgerwp7rdlvo) suffered by their children, including in cases [involving suicide](https://techpolicy.press/breaking-down-the-lawsuit-against-openai-over-teens-suicide).In response to some of those concerns, OpenAI has [introduced a series of safety measures](https://techcrunch.com/2025/09/02/openai-to-route-sensitive-conversations-to-gpt-5-introduce-parental-controls/) over the past year, including [parental controls for teen accounts](https://techcrunch.com/2025/09/29/openai-rolls-out-safety-routing-system-parental-controls-on-chatgpt/), routing sensitive conversations to reasoning models designed to better handle signs of distress, and, more recently, an [optional “Trusted Contact” feature](https://techcrunch.com/2026/05/07/openai-introduces-new-trusted-contact-safeguard-for-cases-of-possible-self-harm/) that can alert a family member or caregiver in cases of potential self-harm.AI companies, Balkam said, have an opportunity to avoid the mistakes made by social media platforms, which for years treated children much like adults before adding stronger safeguards amid mounting public pressure and regulatory scrutiny.The hiring also aligns with OpenAI’s broader efforts around families. In a recent workshop organized with the San Antonio Spurs Community Impact organization and the Positive Coaching Alliance, the company [said](https://www.youtube.com/watch?v=94cXnSu6kUQ) it aimed to explore AI’s role in learning, coaching, and youth engagement.That said, the demographic shift is not unique to ChatGPT, though OpenAI’s audience is changing in some distinct ways.Sensor Tower estimates that users aged 25 to 34 account for 40% of the global app audiences for Anthropic’s Claude and Google’s Gemini, matching ChatGPT, compared with 33% for Microsoft’s Copilot. Copilot, however, skews older, with 20% of its users aged 45 and above, compared with 14% for Claude, 12% for Gemini, and 11% for ChatGPT.While ChatGPT remains relatively underpenetrated among older users, it is adding them faster than its rivals. The share of users aged 45 and above rose three percentage points year-over-year in the second quarter, compared with a two-point increase for Copilot and declines for Claude and Gemini, according to Sensor Tower.Among U.S. smartphone users who are parents, Gemini had the widest reach at 32% in Q2, followed by ChatGPT at 24%, Claude at 4%, and Copilot at 2%.For Bajarin, OpenAI’s decision to hire a product manager focused on families signals where consumer AI is headed. As AI becomes a technology shared across generations, he expects companies to roll out family plans, child and teen profiles, caregiver tools, shared household memory, AI tutoring, and stronger safety controls.Topics*When you purchase through links in our articles, [we may earn a small commission](https://techcrunch.com/techcrunch-affiliate-monetization-standards/). This doesn’t affect our editorial independence.*
 Reporter
 Jagmeet covers startups, tech policy-related updates, and all other major tech-centric developments from India for TechCrunch. He previously worked as a principal correspondent at NDTV. You can contact or verify outreach from Jagmeet by emailing [mail@journalistjagmeet.com](mailto:mail@journalistjagmeet.com). 
Last chance to save up to $190 on TechCrunch Founder Summit. Join 1,000+ founders and VCs at all stages for real-world scaling insights and connections that move the needle.

**Savings end June 26, 11:59 p.m. PT**. [Apple sues OpenAI over alleged trade secret theft](https://techcrunch.com/2026/07/10/apple-sues-openai-over-alleged-trade-secret-theft/)

 [Elon Musk praises Mythos/Fable, promises not to ‘cut off’ Anthropic](https://techcrunch.com/2026/07/09/elon-musk-praises-mythos-fable-promises-not-to-cut-off-anthropic/)

 [Instagram users: Here’s how to stop Meta’s AI from using your photos](https://techcrunch.com/2026/07/09/how-to-stop-metas-ai-image-generator-from-using-your-instagram-photos/)

 [If you use Google, you’re training its AI. Here’s how to opt out.](https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/)

 [Reddit is using LLMs to solve a problem LLMs largely created](https://techcrunch.com/2026/07/06/reddit-is-using-llms-to-solve-a-problem-llms-largely-created/)

 [Amazon will stop accepting new customers for Mechanical Turk](https://techcrunch.com/2026/07/05/amazon-will-stop-accepting-new-customers-for-mechanical-turk/)

 [5 desk gadgets that can make your workday better](https://techcrunch.com/2026/07/05/5-desk-gadgets-that-can-make-your-workday-better/)]]></content:encoded>
            <category>OpenAI</category>
        </item>
        <item>
            <title><![CDATA[Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched]]></title>
            <link>https://aiheadlines.pro/news/laser-attack-resets-tangem-wallet-passwords-on-cards-that-ca-1cee3e</link>
            <guid>https://aiheadlines.pro/news/laser-attack-resets-tangem-wallet-passwords-on-cards-that-ca-1cee3e</guid>
            <pubDate>Sat, 11 Jul 2026 06:41:09 GMT</pubDate>
            <description><![CDATA[- 

**Swati Khandelwal**Jul 10, 2026Vulnerability / Hardware Security
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0BbJcQ3TUJxFvOCpAChyC5saD3RGgDCtLtVG-Wupee7poBksO2TzSWFtzQmjjoXu...]]></description>
            <content:encoded><![CDATA[- 

**Swati Khandelwal**Jul 10, 2026Vulnerability / Hardware Security
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0BbJcQ3TUJxFvOCpAChyC5saD3RGgDCtLtVG-Wupee7poBksO2TzSWFtzQmjjoXuZ-9hnCNR3HuWdSsBv7YZl477fdOcjoOBh72RY4vJ9R0hxUWktV2R7wgTsRa-_Zz5Bj_ZGfQOVT8v292QJ55C9hMumk-IgXd-PVZ6LFu2ZDyCGwjNtJhCYb4W-mPDO/s1700-e365/ll.jpg)
Researchers at **Ledger's Donjon security team** have shown that a precisely timed laser pulse, aimed at the chip inside a **Tangem **crypto wallet card, can reset the card's password to anything the attacker picks.

No old password. No backup card. Once it is reset, whoever did it controls the wallet and can move the coins out.

This is not an emergency for most owners. The attack needs the physical card in hand and a lab that Donjon puts at around $250,000. It also means cutting the card open, which leaves damage no one can miss. It cannot be done over the internet, and there is no fix coming: Tangem cards cannot take software updates, so every card already sold carries the flaw.

The one group that should act now is anyone whose card is lost or stolen and holds serious value.

## How the card is meant to protect you

A Tangem wallet looks like a plain bank card. Tap it to your phone, and a companion app talks to a Samsung S3D232A chip inside. That chip is a secure element, built to resist tampering and certified to a high grade called EAL6+.

[*](https://thehackernews.uk/ai-vuln-protection-d)
It holds the secret key that controls your crypto and never lets it out. Two things are meant to stand between a thief and your money: holding the card and knowing the password.

The weak point is the password reset feature. Tangem sells its cards in linked sets, and if you forget your password, you can set a new one by holding two of your cards together. Deep inside that process, the card runs a single check: is this card in recovery mode? If yes, it accepts a new password without asking for the old one.

A laser pulse fired at the chip at the exact moment it runs that check does not quietly rewrite a stored value. It briefly disturbs the chip's own circuitry, so the check misfires and the card behaves as if it were in recovery mode when it is not.

[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9utbDi4AC6trfMxi55y1ePtHrVUgQ0x3FFT_qZBat3geUfwd86b2JemyGnkdQZe83U2jvCCLQ_64708RjgIKJLnn0w_rrwR8PA53ysZsgcGHGeLWlJ_RMnosW7Tuyh6lrss_Gv0ZyI3Jg1mqoNS0ilSedkA6quK-RdgRrA_bJZwyetOFa4BOnEOHRkYFl/s1700-e365/laaser-flow.png)
With the check defeated, the card's ordinary SetPin command accepts a brand-new password: no old password, no second card, no recovery step. Turning the recovery feature off does not help, because the same check still runs on every card.

## Hard to do, and unfixable

None of this is easy. It took a laser rig, sensitive measuring gear, deep hardware skill, and a long stretch of up-front work to map the chip and find the exact spot and timing. The card has to be cut open and its chip exposed, which leaves obvious damage.

There is no doing this quietly and slipping the card back into a pocket. [Donjon reports](https://donjon.ledger.com/blog/bypassing-tangem-card-security-with-laser-attack/) that once the settings were locked in, the attack worked on every card it tried, at about two hours each. The team reported the flaw to Tangem on February 10, 2026.

[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHkgKEcO0Gmst3f3dNnKIzr1TngAXoqD4U0pZ8MiNV3anl48355NEkvAnFa9sRAJQgI9sVU63NqZoyulRweNx-QzErvw5r14uRieO_7q10eYBGH5hZBNBsLo9JVwT_0I9Ncshwp2QE7n7wzcGliUrQ6261gDmZfATZdkPxEDkzxfPJ7YDhIEwxiHaVp7cp/s1700-e365/laaser-1.jpg)
The bigger problem is permanence. Tangem builds its cards with no way to update the firmware, and presents that as a security feature: nothing can be changed, so nothing can be tampered with from a distance. Here, that same design cuts the other way, leaving a flaw in the code that can never be corrected.

As the researchers put it, "there's no patch, but the attack is physical and invasive", so it cannot be done remotely.

## What Tangem says

Tangem pushed back. In a [public response](https://tangem.com/en/blog/post/lfi-response/), the company called this a lab-only physical method that works against secure element chips in general, not something unique to its cards. It also noted that Donjon belongs to **Ledger**, one of its biggest rivals.

Its sharpest point is about money: a Tangem card carries nothing that says who owns it or how much it holds, so an attacker who spends $250,000 and wrecks cards to tune the attack has no way to tell whether a stolen card is worth $50 or $50 million. Tangem also says no one has lost funds to a laser attack on any hardware wallet so far, and that for everyday users, "the practical risk is virtually non-existent."

Both sides are partly right. Donjon researchers are right that the flaw is real, sits in every card, and can never be patched. Tangem is right that for almost everyone, the cost, the ruined cards, and the guesswork over what a card holds make it pointless.

The place they actually meet is narrow: a lost, stolen, or seized card that an attacker already has reason to think is worth the trouble.

## Not the first wallet chip broken this way

This is not Donjon's only laser attack on a hardware wallet this year. In early June, Trezor and its chip partner Tropic Square [disclosed](https://trezor.io/blog/news/Trezor-response-TROPIC01-chip-disclosure-no-impact-to-your-funds) a related result: Donjon used the same technique, laser fault injection, on the TROPIC01 chip in the new Trezor Safe 7.

This time, it slipped past the chip's firmware signature check to run its own code. Trezor said funds stayed safe because the Safe 7 stacks three separate security layers, and the layer guarding the PIN held firm. Unlike Tangem, Trezor, and Tropic Square, which could respond: they shipped a stopgap for current chips and are hardening the next version of the silicon.

[*](https://thehackernews.uk/sygnia-cyber-response-d-1)
Cheaper attacks on wallets go back further, but they hit softer targets. Years ago, this same team pulled the recovery seed straight off a stolen [Trezor One or Trezor T](https://www.ledger.com/blog/unfixable-key-extraction-attack-on-trezor) with a rig costing about $100, because those wallets guarded their secrets with an ordinary microcontroller and no secure element.

Tangem's hardened chip is the difference: it is why the same sort of physical attack now needs a quarter-million-dollar lab. It raises the bar; this research shows it does not remove the danger. And a grade like EAL6+ only vouches for the chip and its built-in defenses, not the code a wallet maker layers on top, which is where this flaw lives.

It is also Donjon's third finding on Tangem. An [Android app bypass](https://www.ledger.com/tangem-genuine-check-bypass-on-android-application) could be patched, because it was in the software Tangem controls. But this laser attack and a [password brute-force method](https://www.ledger.com/blog-brute-force-attack-tangem) found earlier both sit in the card's firmware, which can never be changed.

## What to do

For almost everyone, the answer is nothing new: keep the card where a thief cannot get to it. This attack cannot reach a card you still hold. If a Tangem card is lost or stolen and you are guarding serious value, move the funds now, using another card in your set (or a seed phrase, if you set one up), and stop relying on the password to protect a card you no longer control.

Found this article interesting? Follow us on [Google News](https://news.google.com/publications/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ), [Twitter](https://twitter.com/thehackersnews) and [LinkedIn](https://www.linkedin.com/company/thehackernews/) to read more exclusive content we post.

SHARE
[**](#link_share)
[**](#link_share)
[**](#link_share)
[**](javascript:void(0))

[**Tweet](#link_share)
[**Share](#link_share)
[**Share](#link_share)
**Share

[SHARE **](javascript:void(0))
[cryptocurrency](https://thehackernews.com/search/label/cryptocurrency), [cybersecurity](https://thehackernews.com/search/label/cybersecurity), [Embedded Security](https://thehackernews.com/search/label/Embedded%20Security), [Firmware Security](https://thehackernews.com/search/label/Firmware%20Security), [hardware security](https://thehackernews.com/search/label/hardware%20security), [password security](https://thehackernews.com/search/label/password%20security), [Physical Security](https://thehackernews.com/search/label/Physical%20Security), [Vulnerability](https://thehackernews.com/search/label/Vulnerability)]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot]]></title>
            <link>https://aiheadlines.pro/news/six-new-u-boot-flaws-could-let-malicious-images-crash-device-54d723</link>
            <guid>https://aiheadlines.pro/news/six-new-u-boot-flaws-could-let-malicious-images-crash-device-54d723</guid>
            <pubDate>Sat, 11 Jul 2026 06:41:09 GMT</pubDate>
            <description><![CDATA[- 

**Swati Khandelwal**Jul 10, 2026Firmware Security / Vulnerability
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihuE5rUYRadx5Q2auJjv9dVeFNIP8XSwSTaH0PDwGLUA54MXlPy3AyI532a8OnhXa...]]></description>
            <content:encoded><![CDATA[- 

**Swati Khandelwal**Jul 10, 2026Firmware Security / Vulnerability
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihuE5rUYRadx5Q2auJjv9dVeFNIP8XSwSTaH0PDwGLUA54MXlPy3AyI532a8OnhXadtWnCCH30qvUKW9C3rCOu1LPld1or5_lXwNhRVqbohHNInDzNd1f9E77Sox5yB-ir7H69LmlYRKnoqnFASOMFa2TIK2RfTThJvu_oofIXHCpiRbXGXWy-bquBWsw/s1700-e365/bootloader.gif)
Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center servers.

Four of the bugs can crash a device. The other two could let an attacker who slips a malicious image in front of the bootloader run their own code, before the device has confirmed that the software is genuine.

That last part is the point. A bootloader runs before the operating system, so a flaw here can undermine everything that loads after it. All six bugs are reached while U-Boot is still reading an untrusted image, before it has checked the signature.

## What Binarly found

U-Boot can bundle a kernel, device tree, ramdisk, and other boot components into one package, a FIT (Flattened Image Tree), and it checks that package's digital signature before handing over control.

Binarly went looking for weak spots in that check and found six. Most of the vulnerable code has been in U-Boot since v2013.07, [Binarly says](https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification), across more than 50 stable releases, and it also lives in the many vendor firmwares built on top of U-Boot.

The bugs are tracked as Binarly advisories [BRLY-2026-037 through BRLY-2026-042](https://www.binarly.io/advisories). No CVE identifiers have been assigned yet. They fall into two groups: two that could run code, and four that only crash.

[*](https://thehackernews.uk/ai-vuln-protection-d)
The two are BRLY-2026-037 and BRLY-2026-038, and both trace to one unchecked value. U-Boot calls fdt_get_name, a lookup in the device-tree parsing library it borrows, and on a malformed image, that lookup returns a null pointer and a negative length. U-Boot uses both without checking either.

One bug follows the null pointer into a memory copy that, on devices where address zero is mapped, becomes a stack buffer overflow. The other feeds the negative length into pointer arithmetic that walks backward until it overwrites a saved return address. In the right memory layout, either one can hand control to code the attacker-supplied.

The other four only crash the bootloader. BRLY-2026-039 and BRLY-2026-041 read past the end of the image by trusting a size or offset that the attacker controls. BRLY-2026-040 dereferences a null pointer that an older image format hands back unchecked. BRLY-2026-042 exhausts the stack, set off by a deeply nested image that drives an early validation step to call itself until it runs out.

Binarly published a proof-of-concept image and reproduction steps for each flaw and demonstrated them against standard U-Boot builds. No exploitation in real attacks has been reported.

Of the six, the two memory-corruption bugs are the ones to prioritize: a crash can knock a device offline, but code execution at boot could subvert its entire chain of trust.

## How bad it gets

In the worst case, recovering a device that will not boot means physical access and reflashing its memory chip with a clean image. Code execution is worse. Code that runs this early sits below the operating system, where ordinary security tools may not see it.

The catch for an attacker is delivery: these bugs only bite once a malicious image reaches the boot path, which usually takes physical access or a privileged foothold. That foothold is not always local.

In [earlier work](https://thehackernews.com/2025/09/two-new-supermicro-bmc-bugs-allow.html) on Supermicro's server management controllers, the same Binarly researcher showed that an attacker with remote access to the management interface could abuse the device's own update process to flash a malicious image, without touching the hardware.

## What to do

There is no stable release with the fix yet, so vendors and maintainers of U-Boot-based products should not wait: pull the upstream fixes now, following the commit links in each Binarly advisory, and track them by advisory ID, since no CVEs exist.

U-Boot merged the six patches in June, but the July release (v2026.07) had already frozen in April, so it shipped without them; the next release, v2026.10, is not due until October.

[*](https://thehackernews.uk/sygnia-cyber-response-d-1)
Everyone else runs a device someone else built on U-Boot. For them, the fix has to arrive as a firmware update from the product vendor. That is what to watch for.

This exact check has failed before. The same signature logic was hit months earlier by [CVE-2026-33243](https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241), which U-Boot patched in April; the related barebox bootloader, which uses the same image tooling, was hit too.

In that bug, a property meant only to list what the signature covers was not itself signed, so a tampered image could swap in parts that were never verified. The helper behind the two worst bugs here, fdt_get_name, comes from libfdt, the flattened-device-tree library U-Boot shares with the Linux kernel, barebox, and others. The same unchecked-return mistake can surface anywhere that code is used.

[LogoFAIL](https://thehackernews.com/2023/12/logofail-uefi-vulnerabilities-expose.html), which THN covered in 2023, was a set of image-parsing bugs in PC firmware that let attacker code run during boot, before Secure Boot could check anything, across nearly every major PC brand. The signature gets all the attention; the bugs keep landing in the plumbing that runs before it.

And as [BootHole](https://thehackernews.com/2020/07/grub2-bootloader-vulnerability.html) showed in 2020, when one bootloader flaw broke Secure Boot across the ecosystem, writing the patch is the easy part. The slow part is getting it onto the millions of devices running someone else's copy of U-Boot.

Found this article interesting? Follow us on [Google News](https://news.google.com/publications/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ), [Twitter](https://twitter.com/thehackersnews) and [LinkedIn](https://www.linkedin.com/company/thehackernews/) to read more exclusive content we post.

SHARE
[**](#link_share)
[**](#link_share)
[**](#link_share)
[**](javascript:void(0))

[**Tweet](#link_share)
[**Share](#link_share)
[**Share](#link_share)
**Share

[SHARE **](javascript:void(0))
[Bootloader Security](https://thehackernews.com/search/label/Bootloader%20Security), [Code Execution](https://thehackernews.com/search/label/Code%20Execution), [denial of service](https://thehackernews.com/search/label/denial%20of%20service), [Embedded Security](https://thehackernews.com/search/label/Embedded%20Security), [Firmware Security](https://thehackernews.com/search/label/Firmware%20Security), [iot security](https://thehackernews.com/search/label/iot%20security), [Memory Corruption](https://thehackernews.com/search/label/Memory%20Corruption), [Secure Boot](https://thehackernews.com/search/label/Secure%20Boot), [server security](https://thehackernews.com/search/label/server%20security), [Vulnerability](https://thehackernews.com/search/label/Vulnerability)]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages]]></title>
            <link>https://aiheadlines.pro/news/injective-labs-github-compromise-pushes-wallet-key-stealing--b61d1a</link>
            <guid>https://aiheadlines.pro/news/injective-labs-github-compromise-pushes-wallet-key-stealing--b61d1a</guid>
            <pubDate>Sat, 11 Jul 2026 06:41:08 GMT</pubDate>
            <description><![CDATA[- 

**Ravie Lakshmanan**Jul 10, 2026Software Supply Chain / Malware
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTNxzPo9jxkW3GuuZLBgtPOrG3vZ3va6E710jDJu_JF0jCpyQ1JTpymdVwdSH2VHL6-...]]></description>
            <content:encoded><![CDATA[- 

**Ravie Lakshmanan**Jul 10, 2026Software Supply Chain / Malware
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTNxzPo9jxkW3GuuZLBgtPOrG3vZ3va6E710jDJu_JF0jCpyQ1JTpymdVwdSH2VHL6-Ib6YLInvKsuNwgFJxna1nvDhwKMZ_hycTik5OgQniZei2FQ59-F3s80lsnPmhQ1aJsr7qIWWrf63V0AtHQxd_1Nlk6LkVEheoN5lRYH8aTeBoJ-kM1-bOjUgAwa/s1700-e365/npm-malware-2.jpg)
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases.

The compromised version, **@injectivelabs/sdk-ts@1.20.21**, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was released on July 8, 2026, but has since been [deprecated](https://x.com/ericinjective/status/2075223896660353242) on the registry. That said, the release artifacts belonging to the compromised version are [still available](https://github.com/InjectiveLabs/injective-ts/releases/tag/v1.20.21) for download from GitHub as of writing.

"The malicious functionality was introduced to the project's official GitHub repository through commits submitted by a GitHub account belonging to a developer with an established history of contributions to the repository," Socket [said](https://socket.dev/blog/compromised-injective-sdk-npm-package).

[*](https://thehackernews.uk/ai-vuln-protection-d)
The software supply chain security firm said the threat actor behind the attack also published version 1.20.21 across 17 additional @injectivelabs scoped packages that depended on and pinned the malicious SDK version, thereby putting transitive users who may not have installed the library directly. This includes -

 - @injectivelabs/utils

 - @injectivelabs/networks

 - @injectivelabs/ts-types

 - @injectivelabs/exceptions

 - @injectivelabs/wallet-base

 - @injectivelabs/wallet-core

 - @injectivelabs/wallet-cosmos

 - @injectivelabs/wallet-private-key

 - @injectivelabs/wallet-evm

 - @injectivelabs/wallet-trezor

 - @injectivelabs/wallet-cosmostation

 - @injectivelabs/wallet-ledger

 - @injectivelabs/wallet-wallet-connect

 - @injectivelabs/wallet-magic

 - @injectivelabs/wallet-strategy

 - @injectivelabs/wallet-turnkey

 - @injectivelabs/wallet-cosmos-strategy

The malware present within the package is fairly simple and straightforward, which gets triggered when the library functionality is used by an unsuspecting developer. By avoiding lifecycle scripts and not launching it during the installation phase, it helps the malware fly under the radar.

Specifically, the poisoned version has been found to modify legitimate functions used in workflows to generate private keys by invoking a "trackKeyDerivation()" function under the guise of collecting anonymized usage metrics for SDK optimization.

[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEinGr4vdIX3z6lY9KP42k9TMLnc0pORZrrsNQFgJm-4NLj8snsjhNkAZU9ifYvyc6CvfmvNbFPZbsMJvxfRwqXoB00dxtrY8vdoujm-G-3qRT4Ap6qdvkqrmkgQRtiEGkPLXgLDqb4FulcCFqtHD2Er3YS1lK2aTg-dukWAXp6fwmk4da4VZAuG4NMxCTDf/s1700-e365/npm-2.jpg)
"Tracks which key derivation methods are used (hex vs mnemonic) and derives timing patterns to help the SDK team identify performance bottlenecks and understand adoption of different key formats across the ecosystem," reads the description of the supposed telemetry function. "All metrics are fire-and-forget and never block or affect key derivation."

According to Socket, parameters passed to the function include a hard-coded marker describing the method used to generate the private key and the actual sensitive information needed for generating the private key. The captured material is enough for the threat actor to regenerate the private key at their end.

[*](https://thehackernews.uk/sygnia-cyber-response-d-1)
"The malware adds crypto wallet stealing logic to a crypto wallet package, every time a legitimate user creates or uses the logic that reads mnemonic phrases – which are basically the master key for any crypto wallet, the malware reads them and sends them to the remote server," OX Security [said](https://www.ox.security/blog/injectivelabs-npm-package-hijacked-impacting-87-dependent-packages/).

In an attempt to reduce the number of outbound requests, the exfiltration mechanism is [designed](https://www.stepsecurity.io/blog/injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-keys) to append multiple key derivations over a two-second window into a single queue and then send them in the form of an HTTPS POST request to an external server ("testnet.archival.chain.grpc-web.injective[.]network") in a single beacon.

StepSecurity [noted](https://www.stepsecurity.io/blog/injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-keys) the malicious release was facilitated through the repository's own trusted-publisher (OIDC) pipeline, adding that the malicious commits were authored and pushed under the identity of an existing, trusted maintainer ("thomasRalee").

Users who have installed the malicious version are recommended to update to the newly published, clean version of the package (1.20.23), treat any private key or mnemonic phrase passed through the package as compromised and rotate them, and check for transitive dependencies.

Found this article interesting? Follow us on [Google News](https://news.google.com/publications/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ), [Twitter](https://twitter.com/thehackersnews) and [LinkedIn](https://www.linkedin.com/company/thehackernews/) to read more exclusive content we post.

SHARE
[**](#link_share)
[**](#link_share)
[**](#link_share)
[**](javascript:void(0))

[**Tweet](#link_share)
[**Share](#link_share)
[**Share](#link_share)
**Share

[SHARE **](javascript:void(0))
[Credential Theft](https://thehackernews.com/search/label/Credential%20Theft), [cryptocurrency](https://thehackernews.com/search/label/cryptocurrency), [data theft](https://thehackernews.com/search/label/data%20theft), [Developer Security](https://thehackernews.com/search/label/Developer%20Security), [GitHub](https://thehackernews.com/search/label/GitHub), [Malware](https://thehackernews.com/search/label/Malware), [NPM](https://thehackernews.com/search/label/NPM), [Open Source Security](https://thehackernews.com/search/label/Open%20Source%20Security), [Package Security](https://thehackernews.com/search/label/Package%20Security), [Software Supply Chain](https://thehackernews.com/search/label/Software%20Supply%20Chain)]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat]]></title>
            <link>https://aiheadlines.pro/news/urgent---progress-tells-sharefile-customers-to-shut-down-sto-914fa8</link>
            <guid>https://aiheadlines.pro/news/urgent---progress-tells-sharefile-customers-to-shut-down-sto-914fa8</guid>
            <pubDate>Sat, 11 Jul 2026 06:41:08 GMT</pubDate>
            <description><![CDATA[- 

**Swati Khandelwal**Jul 10, 2026Enterprise Security / Security Incident
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgULXOG2_Ph1198nw2lOea2pYE9u1GkPHaaMlzhpO48pOmejpWKFuHbchUac...]]></description>
            <content:encoded><![CDATA[- 

**Swati Khandelwal**Jul 10, 2026Enterprise Security / Security Incident
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgULXOG2_Ph1198nw2lOea2pYE9u1GkPHaaMlzhpO48pOmejpWKFuHbchUac5JIRQHGiIMMTefXq-LktA8AjsqqMIsBS54bLaludxIJbq7chYfo_Vsoqf9Xi7YomnSUL9wHAYa5InCST76k1aP10VMmNKK_MDLD3o5zNXyB4ODMRMl0DbLkz9f2mg2k2S8/s1700-e365/progress.jpg)
Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to **The Hacker News** that it is responding to a "credible external security threat."

The company has temporarily disabled access to the affected accounts, a step it says it took "out of an abundance of caution" while it works with internal and external security experts.

It says it has no indication of unauthorized access to any ShareFile accounts or data, and that it notified customers after learning of the threat.

What Progress has not said is what the threat is or who is behind it.

The order became public when a customer posted the company's email to Reddit's [r/sysadmin](https://www.reddit.com/r/sysadmin/comments/1usohco/psa_shutdown_your_sharefile_storage_zone/) on July 10. Progress [confirmed the disruption](https://status.sharefile.com/) on its status page, listing Storage Zone Controller customers as "not operational" and the incident as under investigation as of a 12:12 p.m. EDT update.

[*](https://thehackernews.uk/ai-vuln-protection-d)
Only the Storage Zone Controller is affected, not standard cloud-only ShareFile accounts. The controller is a server that a company runs itself, so files can stay on its own storage while it still uses ShareFile's cloud to share and manage them.

The controller usually sits at the network's edge, reachable from the internet. That exposure makes it both useful and a target. Ordering customers to take it fully offline, rather than just patch it, is a notable step.

[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuIEperKcgWWot-nes4WRvJrO5SGh6v427wpkWQooK_eTA9AGQzfo1YTPo9aSmrCZ25_e9NKLgRAGG9wiYyjY0Sf7tXiigFaTpLveXt6waUA2BSXpU2Ec5zWqAJaWMnM0f9sKuYOF0QklaPLgl1GZwPZbtFkVQJn9H_MpMWwJeKMkgC33dCEISt8SGS54/s1700-e365/email.jpg)
That choice is itself a tell. If a fix for this threat existed, Progress would be telling customers to apply it; the shutdown order suggests there is none yet. That usually means a newly found flaw the company is racing to close, though the same step would also fit a threat a patch cannot address, such as stolen keys or a problem on Progress's own side.

Its statement that no accounts or data were accessed is careful wording, too, and does not rule out trouble on the controllers themselves.

## What to do now

 - Follow the shutdown order first. Keep the affected controllers offline until Progress says what the threat is and when it is safe to restart.

 - Separately, confirm your version is current: 5.12.4 or later on the 5.x line, or a 6.x release. That closes the flaws fixed earlier this year, but Progress has not said it clears the current threat, so do not treat it as permission to restart.

 - If a controller is reachable from the internet, handle it as a possible incident. Preserve the logs and start your incident-response process, then check for unfamiliar .aspx files in the web folders and storage paths you did not set. A clean-looking server is not proof that it is clean.

ShareFile has faced this before. In 2023, while the product still belonged to Citrix, attackers exploited an unauthenticated flaw in the same Storage Zones Controller (CVE-2023-24489).

CISA [flagged it as actively exploited](https://thehackernews.com/2023/08/cisa-adds-citrix-sharefile-flaw-to-kev.html), and Citrix cut unpatched controllers off from the ShareFile cloud, the same access block Progress has now imposed.

[*](https://thehackernews.uk/sygnia-cyber-response-d-1)
Progress, which acquired ShareFile in 2024, had already weathered a mass file-transfer attack of its own: MOVEit, whose 2023 zero-day was exploited by the Clop group and hit more than 2,700 organizations.

The Storage Zones Controller also had two critical flaws that watchTowr [disclosed in April](https://thehackernews.com/2026/04/threatsday-bulletin-pre-auth-chains.html) and Progress patched in March, though the company has not connected the current threat to them, and neither has been reported as exploited.

The central question is still unanswered: Progress has pulled these systems offline and is working with outside experts, but has not said what the threat is or when customers can safely bring them back online.

Found this article interesting? Follow us on [Google News](https://news.google.com/publications/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ), [Twitter](https://twitter.com/thehackersnews) and [LinkedIn](https://www.linkedin.com/company/thehackernews/) to read more exclusive content we post.

SHARE
[**](#link_share)
[**](#link_share)
[**](#link_share)
[**](javascript:void(0))

[**Tweet](#link_share)
[**Share](#link_share)
[**Share](#link_share)
**Share

[SHARE **](javascript:void(0))
[Cloud security](https://thehackernews.com/search/label/Cloud%20security), [data security](https://thehackernews.com/search/label/data%20security), [enterprise security](https://thehackernews.com/search/label/enterprise%20security), [Incident response](https://thehackernews.com/search/label/Incident%20response), [network security](https://thehackernews.com/search/label/network%20security), [security incident](https://thehackernews.com/search/label/security%20incident), [server security](https://thehackernews.com/search/label/server%20security), [Software Security](https://thehackernews.com/search/label/Software%20Security), [Vulnerability](https://thehackernews.com/search/label/Vulnerability), [Windows Security](https://thehackernews.com/search/label/Windows%20Security)]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[The Download: Claude’s inner workings and OpenAI’s “super app”]]></title>
            <link>https://aiheadlines.pro/news/the-download-claudes-inner-workings-and-openais-super-app-5fa051</link>
            <guid>https://aiheadlines.pro/news/the-download-claudes-inner-workings-and-openais-super-app-5fa051</guid>
            <pubDate>Sat, 11 Jul 2026 06:41:07 GMT</pubDate>
            <description><![CDATA[*This is today's edition of *[*The Download*](https://forms.technologyreview.com/newsletters/briefing-the-download/?_ga=2.179569122.736533416.1649661040-405833893.1649413289), *our weekday newsletter ...]]></description>
            <content:encoded><![CDATA[*This is today's edition of *[*The Download*](https://forms.technologyreview.com/newsletters/briefing-the-download/?_ga=2.179569122.736533416.1649661040-405833893.1649413289), *our weekday newsletter that provides a daily dose of what's going on in the world of technology.*
The AI firm Anthropic has got the clearest glimpse yet at what’s really going on inside large language models as they answer questions or carry out tasks. What they found ranges from the mundane to the unnerving. Researchers at the company built a tool called the Jacobian lens (or J-lens) and used it to uncover a hidden area, which they named the J-space, inside its flagship LLM, Claude.The J-space contains words related to the response a model is working on but may not ultimately produce. If Claude were a person (which it is not), you might say these hidden words reveal what’s on its mind before it actually speaks. [Read the full story on what they found.](https://www.technologyreview.com/2026/07/09/1140293/anthropic-found-a-hidden-space-where-claude-puzzles-over-concepts/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:m-d-Y%7C*)*—Will Douglas Heaven***The must-reads***I’ve combed the internet to find you today’s most fun/important/scary/fascinating stories about technology.***1 OpenAI has unveiled its long-awaited "super app" **
ChatGPT Work blends its chatbot, coding tool, and new models. ([Reuters](https://www.reuters.com/business/openai-launches-chatgpt-work-2026-07-09/) $)
*+ It’s designed to do your work for you and with you. *([Ars Technica](https://arstechnica.com/ai/2026/07/openai-wants-its-new-tool-to-do-your-work-for-you-and-with-you/))
*+ And arrived the same day as OpenAI’s GPT 5.6 models.* ([NYT](https://www.nytimes.com/2026/07/09/technology/openai-sol-ai.html) $)
*+ It’s also developing a fully automated researcher.* ([MIT Technology Review](https://www.technologyreview.com/2026/03/20/1134438/openai-is-throwing-everything-into-building-a-fully-automated-researcher/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:m-d-Y%7C*))

**2 Humanoids have performed teleoperated surgery on living animals**
In the world-first, they removed gallbladders from pigs. ([Ars Technica](https://arstechnica.com/ai/2026/07/humanoid-robots-controlled-by-surgeons-did-world-first-operation-on-live-pigs/))
*+ The human work behind humanoids is hidden.* ([MIT Technology Review](https://www.technologyreview.com/2026/02/23/1133508/the-human-work-behind-humanoid-robots-is-being-hidden/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:m-d-Y%7C*))
 
**3 SK Hynix has landed the largest US listing by a foreign company**
The South Korean chip giant raised $26.5 billion. ([CNN](https://edition.cnn.com/2026/07/10/business/sk-hynix-us-listing-ai-chip-boom-intl-hnk))
*+ Demand for AI data centres has led its profits to skyrocket. *([Guardian](https://www.theguardian.com/world/2026/jul/10/south-korea-chip-maker-sk-hynix-rides-ai-boom-raising-265bn-in-huge-us-listing))
*+ But its jumbo share sale may be a sign of overheated times. *([FT](https://www.ft.com/content/3986c7e5-01bc-4d24-a41f-3b8030ac2bd8) $)
*+ South Korea’s hottest bachelors are chip workers.* ([MIT Technology Review](https://www.technologyreview.com/2026/07/06/1140000/south-korea-bachelors-samsung-skhynix-chip-workers/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:m-d-Y%7C*))
 
**4 Tencent is leading a deal to unwind Meta's $2 billion Manus acquisition**
It’s in talks to become the Chinese AI startup’s largest shareholder. ([FT](https://www.ft.com/content/0d04378d-d71b-4225-b31a-70504e358480?syn-25a6b1a6=1) $)
*+ Tencent will reportedly buy Manus for no less ​than $2 billion.* ([Reuters](https://www.reuters.com/technology/tencent-talks-become-ai-start-up-manus-largest-shareholder-ft-reports-2026-07-10/) $)
*+ Beijing had ordered Meta to unwind the acquisition.* ([Bloomberg](https://www.bloomberg.com/news/articles/2026-07-10/tencent-in-talks-to-become-largest-holder-of-manus-ft-reports-mrectviz) $)
 
**5 Resuscitated human retinas responded to light 10 hours after death**
It’s a big step towards eye transplants that restore vision. ([New Scientist](https://www.newscientist.com/article/2533673-resuscitated-human-retinas-respond-to-light-10-hours-after-death/) $)
*+ As is a new device that revives dead eyeballs.* ([MIT Technology Review](https://www.technologyreview.com/2026/02/23/1133508/the-human-work-behind-humanoid-robots-is-being-hidden/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:m-d-Y%7C*))
 
**6 Meta has started charging for AI access**
A new version of Muse Spark has a paid tier for developers. ([Quartz](https://qz.com/meta-muse-spark-api-developers-paid-anthropic-openai-070926)) 
*+ Meta also plans to start producing an AI chip in September.* ([Reuters](https://www.reuters.com/world/asia-pacific/meta-put-ai-chip-into-production-september-it-looks-double-computing-capacity-2026-07-09/) $)
 
**7 OpenAI and Google have sold AI models to blacklisted China groups**
Via Singapore-based subsidiaries of Alibaba, Baidu and Tencent. ([FT](https://www.ft.com/content/5d6aafa1-5d47-4585-aa95-6ec06a6cd20f) $)

**8 A daughter tested an AI “death bot” of her father**
The technology provided both comfort and unease. ([New Yorker](https://www.newyorker.com/news/as-told-to/can-ai-keep-a-parent-alive) $)

**9 An astronomer says the hunt for alien life needs more statistics**
He wants to replace speculation with mathematical frameworks. ([Quanta](https://www.quantamagazine.org/will-we-ever-find-alien-civilizations-20260709/))

**10 Pokémon Go players turned Times Square into a giant battlefield**
More than 1,500 fans finally fulfilled the game’s 2016 launch promise. ([Wired](https://www.wired.com/story/thousands-of-pokemon-go-players-descend-on-times-square-to-defeat-mewtwo/) $)
*+ Pokémon Go is also training world models.* ([MIT Technology Review](https://www.technologyreview.com/2026/03/10/1134099/how-pokemon-go-is-helping-robots-deliver-pizza-on-time/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:m-d-Y%7C*))**Quote of the day**—Vijay Janapa Reddi, an engineering professor at Harvard University, tells [Wired](https://www.wired.com/story/robot-dogs-teslas-and-rescue-helicopters-the-un-ai-summit-was-alot/) why he’s skeptical about grand plans for AI.**One More Thing**In 1943, psychologist B.F. Skinner led a secret government project to make bombs more precise. His idea: teach pigeons to guide missiles by pecking at targets on a screen inside a warhead. To train them, Skinner rewarded the birds with food when they made the right decisions, using trial and error to shape their behavior.Unsurprisingly, the military never deployed Skinner’s kamikaze pigeons. Yet his experiments convinced him that pigeons were “an extremely reliable instrument” for studying learning. Decades later, those same principles would help power reinforcement learning, the technology behind some of today’s most advanced AI systems.[Discover how pigeons inspired one of AI’s most powerful techniques](https://www.technologyreview.com/2025/08/18/1121370/ai-pigeons-reinforcement-learning/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:m-d-Y%7C).*—Ben Crair***We can still have nice things***A place for comfort, fun, and distraction to brighten up your day. (Got any ideas? *[*Drop me a line*](mailto:thomas.macaulay@technologyreview.com)*.)*+ Here’s a splendid selection of this year’s [NSW architecture](https://www.theguardian.com/artanddesign/gallery/2026/jul/02/nsw-architecture-awards-winners-2026-in-pictures) award winners.
+ Photographers have captured the [Strawberry Moon’s golden glow](https://www.smithsonianmag.com/smart-news/these-17-stunning-photos-of-the-strawberry-moon-show-earths-natural-satellite-in-all-its-glory-180989050/) in stunning detail.
+ *Idiocracy* is the film that best exemplifies the “American experience,” according to a new poll. Look back at the prescient comedy with this [Screen Junkies trailer](https://www.youtube.com/watch?v=gSgBTb3wmMI).
+ Get ready for the weekend with this [psychedelic house journey](https://www.youtube.com/watch?v=rE7lLoS5bAE) from Jamie xx b2b Caribou. Plus: Meta is pausing an AI training program that tracks workers’ keystrokes.Plus: Anthropic has called for a global slowdown in AI development.Plus: NASA unveiled plans for three uncrewed missions to the Moon this year.Plus: SpaceX is now valued higher than Amazon.Discover special offers, top stories,
 upcoming events, and more.]]></content:encoded>
            <category>OpenAI</category>
        </item>
        <item>
            <title><![CDATA[Hugging Face's CEO on why companies are done renting their AI | TechCrunch]]></title>
            <link>https://aiheadlines.pro/news/hugging-faces-ceo-on-why-companies-are-done-renting-their-ai-2b4be1</link>
            <guid>https://aiheadlines.pro/news/hugging-faces-ceo-on-why-companies-are-done-renting-their-ai-2b4be1</guid>
            <pubDate>Sat, 11 Jul 2026 06:41:06 GMT</pubDate>
            <description><![CDATA[Open source AI is booming, according to [Hugging Face](https://huggingface.co/) CEO [Clem Delangue](https://www.linkedin.com/in/clementdelangue/). The company has grown into something like a GitHub fo...]]></description>
            <content:encoded><![CDATA[Open source AI is booming, according to [Hugging Face](https://huggingface.co/) CEO [Clem Delangue](https://www.linkedin.com/in/clementdelangue/). The company has grown into something like a GitHub for AI in recent years, where AI builders can share and download open models and datasets, now used by roughly half the Fortune 500. Delangue has seen the same story play out again and again: companies start out on frontier APIs, but as they scale, the costs push them towards open source models. On this episode of TechCrunch’s[ Equity](https://techcrunch.com/podcasts/equity/) podcast, Rebecca Bellan talked to Delangue about why the open vs closed source fight matters in the wake of Anthropic’s halted Fable release, and why he’s worried about the possibility that a handful of big companies could end up controlling everything. Subscribe to Equity on [YouTube](https://www.youtube.com/@TechCrunch),[ Apple Podcasts](https://itunes.apple.com/us/podcast/id1215439780),[ Overcast](https://overcast.fm/itunes1215439780/equity),[ Spotify](https://open.spotify.com/show/5IEYLip3eDppcOmy5DmphC?si=rZDFHv2sQUul_g94iCRgpQ) and all the casts. You also can follow Equity on[ X](https://twitter.com/EquityPod) and[ Threads](https://www.threads.net/@equitypod), at @EquityPod. Topics*When you purchase through links in our articles, [we may earn a small commission](https://techcrunch.com/techcrunch-affiliate-monetization-standards/). This doesn’t affect our editorial independence.*
 Audio Producer
 Theresa Loconsolo is an audio producer at TechCrunch focusing on Equity, the network’s flagship podcast. Before joining TechCrunch in 2022, she was one of 2 producers at a four-station conglomerate where she wrote, recorded, voiced and edited content, and engineered live performances and interviews from guests like lovelytheband. Theresa is based in New Jersey and holds a bachelors degree in Communication from Monmouth University. 
You can contact or verify outreach from Theresa by emailing [theresa.loconsolo@techcrunch.com](mailto:theresa.loconsolo@techcrunch.com). 
Last chance to save up to $190 on TechCrunch Founder Summit. Join 1,000+ founders and VCs at all stages for real-world scaling insights and connections that move the needle.

**Savings end June 26, 11:59 p.m. PT**. [Elon Musk praises Mythos/Fable, promises not to ‘cut off’ Anthropic](https://techcrunch.com/2026/07/09/elon-musk-praises-mythos-fable-promises-not-to-cut-off-anthropic/)

 [Instagram users: Here’s how to stop Meta’s AI from using your photos](https://techcrunch.com/2026/07/09/how-to-stop-metas-ai-image-generator-from-using-your-instagram-photos/)

 [Figma acquires team behind a vibe-coding app](https://techcrunch.com/2026/07/07/figma-acquires-team-behind-a-vibe-coding-app/)

 [If you use Google, you’re training its AI. Here’s how to opt out.](https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/)

 [Reddit is using LLMs to solve a problem LLMs largely created](https://techcrunch.com/2026/07/06/reddit-is-using-llms-to-solve-a-problem-llms-largely-created/)

 [Amazon will stop accepting new customers for Mechanical Turk](https://techcrunch.com/2026/07/05/amazon-will-stop-accepting-new-customers-for-mechanical-turk/)

 [5 desk gadgets that can make your workday better](https://techcrunch.com/2026/07/05/5-desk-gadgets-that-can-make-your-workday-better/)]]></content:encoded>
            <category>Anthropic</category>
        </item>
        <item>
            <title><![CDATA[SK Hynix raises $26.5B in the biggest foreign IPO in US history, is urged to build new US fabs | TechCrunch]]></title>
            <link>https://aiheadlines.pro/news/sk-hynix-raises-265b-in-the-biggest-foreign-ipo-in-us-histor-af9863</link>
            <guid>https://aiheadlines.pro/news/sk-hynix-raises-265b-in-the-biggest-foreign-ipo-in-us-histor-af9863</guid>
            <pubDate>Sat, 11 Jul 2026 06:41:06 GMT</pubDate>
            <description><![CDATA[The AI chip boom just produced its biggest Wall Street moment yet. SK Hynix, a South Korean memory chip giant, [said Friday](https://www.skhynix.com/ir/UI-FR-IR12_T1_view/?seq=6809) it has raised $26....]]></description>
            <content:encoded><![CDATA[The AI chip boom just produced its biggest Wall Street moment yet. SK Hynix, a South Korean memory chip giant, [said Friday](https://www.skhynix.com/ir/UI-FR-IR12_T1_view/?seq=6809) it has raised $26.5 billion (KRW 40 trillion) in its U.S. market debut.SK Hynix sold 177.9 million American depositary shares (ADRs) at $149 each, structured so U.S. investors can buy in at roughly a tenth of what a full share costs in Seoul. This deal, the largest-ever U.S. debut by a non-American company, topped [Alibaba’s](https://www.sec.gov/Archives/edgar/data/1577552/000119312514347620/d709111d424b4.htm) $25 billion IPO in 2014.The company begins trading on the Nasdaq today, Friday, July 10, under the temporary ticker SKHYV. Regular trading opens Monday, July 13, when the ticker officially becomes SKHY. So far, U.S. investors are lapping it up. The [stock opened at 14% over its IPO price](https://finance.yahoo.com/quote/SKHYV/), and the price was still rising in early trading on Friday.This even as it priced its U.S. shares at a 2.7% premium to its own three-day average back home in Seoul, according to its [Korea Stock Exchange filing](https://dart.fss.or.kr/dsaf001/main.do?rcpNo=20260710000012). Yet, demand for the offering was [reportedly](https://www.bloomberg.com/news/articles/2026-07-08/sk-hynix-us-offering-is-more-than-seven-times-oversubscribed) more than seven times the available shares, per media reports.That’s especially amazing considering Korean companies have long traded at a discount to their global peers. That valuation gap is called the Korea Discount. Investors often cite factors such as complex corporate governance structures, low shareholder returns, regulatory uncertainty, and geopolitical risks related to North Korea to justify why companies from that country don’t command higher share prices. But SK Hynix clearly isn’t suffering from the Korea Discount and that’s because it makes memory chips, including high-bandwidth memory (HBM). HBM is a key component of AI GPUs processors. And right now, Nvidia relies on SK Hynix as one of its primary suppliers.Per its filing, the money raised from eager U.S. investors will go to three places: a new fab in South Korea (being built now to address the worldwide shortage of memory cause by AI); a new packaging facility in that country; and EUV scanners, the machines that make next-generation chips possible.Meanwhile, U.S. Commerce Secretary Howard Lutnick stopped by a Micron event Thursday with a message for the broader chip industry, not just for U.S. memory maker Micron (who is one of SK Hynix’s biggest competitors). Lutnick [reportedly](https://www.bloomberg.com/news/articles/2026-07-09/lutnick-presses-sk-hynix-samsung-to-boost-memory-output-in-us) said he’s already in talks with Samsung (the third major memory maker, worldwide) and SK Hynix about building new factories in the U.S. The idea being not to let South Korea continue to be the country that dominates this important tech.Micron, naturally, is in. It [announced it plans](https://investors.micron.com/news-releases/news-release-details/micron-accelerates-us-investments-pours-first-concrete-new-york) to invest $250 billion in new U.S. manufacturing, a commitment the U.S. memory chip company says will create more than 90,000 jobs and keep leading-edge chip production on American soil.The timing of Lutnick’s request is notable beyond this U.S. IPO for SK Hynix: Both Korean chipmakers [just pledged more than $550 billion](https://techcrunch.com/2026/06/29/south-korean-tech-giants-commit-over-550b-to-ease-ramageddon/) for new manufacturing investment in South Korea.Topics*When you purchase through links in our articles, [we may earn a small commission](https://techcrunch.com/techcrunch-affiliate-monetization-standards/). This doesn’t affect our editorial independence.*
 Reporter, Asia
 Kate Park is a reporter at TechCrunch, with a focus on technology, startups and venture capital in Asia. She previously was a financial journalist at Mergermarket covering M&A, private equity and venture capital.
Last chance to save up to $190 on TechCrunch Founder Summit. Join 1,000+ founders and VCs at all stages for real-world scaling insights and connections that move the needle.

**Savings end June 26, 11:59 p.m. PT**. [Elon Musk praises Mythos/Fable, promises not to ‘cut off’ Anthropic](https://techcrunch.com/2026/07/09/elon-musk-praises-mythos-fable-promises-not-to-cut-off-anthropic/)

 [Instagram users: Here’s how to stop Meta’s AI from using your photos](https://techcrunch.com/2026/07/09/how-to-stop-metas-ai-image-generator-from-using-your-instagram-photos/)

 [Figma acquires team behind a vibe-coding app](https://techcrunch.com/2026/07/07/figma-acquires-team-behind-a-vibe-coding-app/)

 [If you use Google, you’re training its AI. Here’s how to opt out.](https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/)

 [Reddit is using LLMs to solve a problem LLMs largely created](https://techcrunch.com/2026/07/06/reddit-is-using-llms-to-solve-a-problem-llms-largely-created/)

 [Amazon will stop accepting new customers for Mechanical Turk](https://techcrunch.com/2026/07/05/amazon-will-stop-accepting-new-customers-for-mechanical-turk/)

 [5 desk gadgets that can make your workday better](https://techcrunch.com/2026/07/05/5-desk-gadgets-that-can-make-your-workday-better/)]]></content:encoded>
            <category>Anthropic</category>
        </item>
        <item>
            <title><![CDATA[Open source AI matters more than ever, according to Hugging Face's Clem Delangue]]></title>
            <link>https://aiheadlines.pro/news/open-source-ai-matters-more-than-ever-according-to-hugging-f-573594</link>
            <guid>https://aiheadlines.pro/news/open-source-ai-matters-more-than-ever-according-to-hugging-f-573594</guid>
            <pubDate>Sat, 11 Jul 2026 06:41:05 GMT</pubDate>
            <description><![CDATA[Open source AI is booming, according to [Hugging Face](https://huggingface.co/) CEO [Clem Delangue](https://www.linkedin.com/in/clementdelangue/). The company has grown into something like a GitHub fo...]]></description>
            <content:encoded><![CDATA[Open source AI is booming, according to [Hugging Face](https://huggingface.co/) CEO [Clem Delangue](https://www.linkedin.com/in/clementdelangue/). The company has grown into something like a GitHub for AI in recent years, where AI builders can share and download open models and datasets, now used by roughly half the Fortune 500. Delangue has seen the same story play out again and again: companies start out on frontier APIs, but as they scale, the costs push them towards open source models. On this episode of TechCrunch’s[ Equity](https://techcrunch.com/podcasts/equity/) podcast, Rebecca Bellan talked to Delangue about why the open vs closed source fight matters in the wake of Anthropic’s halted Fable release, and why he’s worried about the possibility that a handful of big companies could end up controlling everything. Listen to the full episode to hear more about: Subscribe to Equity on [YouTube](https://www.youtube.com/@TechCrunch),[ Apple Podcasts](https://itunes.apple.com/us/podcast/id1215439780),[ Overcast](https://overcast.fm/itunes1215439780/equity),[ Spotify](https://open.spotify.com/show/5IEYLip3eDppcOmy5DmphC?si=rZDFHv2sQUul_g94iCRgpQ) and all the casts. You also can follow Equity on[ X](https://twitter.com/EquityPod) and[ Threads](https://www.threads.net/@equitypod), at @EquityPod. 
 Senior Reporter
 Rebecca Bellan is a senior reporter at TechCrunch where she covers the business, policy, and emerging trends shaping artificial intelligence. Her work has also appeared in Forbes, Bloomberg, The Atlantic, The Daily Beast, and other publications. You can contact or verify outreach from Rebecca by emailing [rebecca.bellan@techcrunch.com](mailto:rebecca.bellan@techcrunch.com) or via encrypted message at rebeccabellan.491 on Signal.
 Audio Producer
 Theresa Loconsolo is an audio producer at TechCrunch focusing on Equity, the network’s flagship podcast. Before joining TechCrunch in 2022, she was one of 2 producers at a four-station conglomerate where she wrote, recorded, voiced and edited content, and engineered live performances and interviews from guests like lovelytheband. Theresa is based in New Jersey and holds a bachelors degree in Communication from Monmouth University. 
You can contact or verify outreach from Theresa by emailing [theresa.loconsolo@techcrunch.com](mailto:theresa.loconsolo@techcrunch.com). 
Last chance to save up to $190 on TechCrunch Founder Summit. Join 1,000+ founders and VCs at all stages for real-world scaling insights and connections that move the needle.

**Savings end June 26, 11:59 p.m. PT**. [Elon Musk praises Mythos/Fable, promises not to ‘cut off’ Anthropic](https://techcrunch.com/2026/07/09/elon-musk-praises-mythos-fable-promises-not-to-cut-off-anthropic/)

 [Instagram users: Here’s how to stop Meta’s AI from using your photos](https://techcrunch.com/2026/07/09/how-to-stop-metas-ai-image-generator-from-using-your-instagram-photos/)

 [Figma acquires team behind a vibe-coding app](https://techcrunch.com/2026/07/07/figma-acquires-team-behind-a-vibe-coding-app/)

 [If you use Google, you’re training its AI. Here’s how to opt out.](https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/)

 [Reddit is using LLMs to solve a problem LLMs largely created](https://techcrunch.com/2026/07/06/reddit-is-using-llms-to-solve-a-problem-llms-largely-created/)

 [Amazon will stop accepting new customers for Mechanical Turk](https://techcrunch.com/2026/07/05/amazon-will-stop-accepting-new-customers-for-mechanical-turk/)

 [5 desk gadgets that can make your workday better](https://techcrunch.com/2026/07/05/5-desk-gadgets-that-can-make-your-workday-better/)]]></content:encoded>
            <category>Anthropic</category>
        </item>
        <item>
            <title><![CDATA[Apple sues OpenAI over alleged trade secret theft | TechCrunch]]></title>
            <link>https://aiheadlines.pro/news/apple-sues-openai-over-alleged-trade-secret-theft-techcrunch-3358b0</link>
            <guid>https://aiheadlines.pro/news/apple-sues-openai-over-alleged-trade-secret-theft-techcrunch-3358b0</guid>
            <pubDate>Sat, 11 Jul 2026 06:41:05 GMT</pubDate>
            <description><![CDATA[Apple filed a [lawsuit](https://www.documentcloud.org/documents/28453229-apple-v-openai/) Friday against OpenAI over allegations of trade secret theft and breach of contract.The iPhone maker alleges t...]]></description>
            <content:encoded><![CDATA[Apple filed a [lawsuit](https://www.documentcloud.org/documents/28453229-apple-v-openai/) Friday against OpenAI over allegations of trade secret theft and breach of contract.The iPhone maker alleges that this misconduct, which it says reveals a pattern of theft from OpenAI employees who previously worked at Apple, was directed by OpenAI’s senior leadership, including [Chief Hardware Officer](https://thetech.com/2025/10/30/tang-tan-openai) [Tang Tan](http://linkedin.com/in/tangtan).The lawsuit, which was filed in the U.S. District Court for the Northern District of California, accuses Tan of using Apple’s confidential project code names during OpenAI’s recruiting process, asking job candidates to bring in Apple hardware components to their interviews, coaching departing Apple employees on how to evade the company’s security procedures, and asking for details about the company’s unannounced products.Before joining OpenAI, Tan had spent 24 years at Apple, most recently as VP of product design for the iPhone and Apple Watch.The accusations come at a time when OpenAI is rumored to be developing its [first hardware product](https://techcrunch.com/2026/04/27/openai-could-be-making-a-phone-with-ai-agents-replacing-apps/), which would likely compete with the iPhone. In April, industry analyst Ming-Chi Kuo [suggested this device could be a smartphone](https://techcrunch.com/2026/04/27/openai-could-be-making-a-phone-with-ai-agents-replacing-apps/) that would rely on AI agents instead of apps. If true, it would be one of the largest threats to Apple’s core hardware business to date.Apple’s former lead designer Jony Ive’s device startup io [was acquired by OpenAI last year](https://techcrunch.com/2025/05/21/jony-ive-to-lead-openais-design-work-following-6-5b-acquisition-of-his-company/) in a $6.5 billion deal to aid the AI company with its hardware ambitions. While io was named in the filing, Ive was not.Tan is not the only OpenAI employee referenced in the new complaint. Apple also alleges that [Chang Liu,](https://www.linkedin.com/in/changliu-apple/) who spent eight years at Apple as a senior systems electrical engineer, failed to return an Apple-issued laptop after leaving the company for OpenAI in 2026 and had used the computer to download confidential Apple technical documents.Apple says in the complaint that the stolen documents included information about unannounced technologies, features, and products, including technical specifications, engineering presentations, and proprietary project data.Liu is also accused in the lawsuit of sharing Apple’s confidential information with other Apple employees applying for jobs at OpenAI, advising at least one of them on what to study before their interview.Apple sent a letter to OpenAI in February to raise its concerns and received no response, the company said in the complaint.It alleges that the behavior of these former employees is part of OpenAI’s strategy to extract Apple’s confidential information, which included asking Apple employees to bring designs and prototypes to their interviews, and answer questions about things like component and vendor selection processes.Apple says its ongoing investigation revealed that OpenAI and its partners have even used Apple’s confidential information while the AI model maker develops its own hardware product. For instance, the filing references a proprietary metal finishing technique that OpenAI used after it allegedly misled a partner into believing it had Apple’s permission to do so.Like many tech companies, Apple typically investigates potential trade secret theft or other improper activity by analyzing communications that took place on company-owned devices and reading through its server logs. By taking the case to court, Apple will have an opportunity to learn more about the extent of the alleged operation through the legal discovery process.Apple is asking the court to bar OpenAI from using or disclosing its trade secrets, require the company to return any confidential Apple materials, and preserve evidence related to the case. “This is the tip of the iceberg. Apple lacks visibility into what’s been happening behind closed doors at OpenAI, where such misconduct is normalized and exemplified by leadership,” the filing states. “As a natural result, OpenAI’s nascent hardware business now rests on the shakiest of foundations, rotten to its core by its illegal reliance on misappropriated trade secrets.” In a prepared statement, Apple also said the following: At Apple, our teams are constantly developing breakthrough technologies to create the best products and services in the world, and protecting their work and intellectual property is something we take very seriously. Recently, significant evidence has emerged suggesting individuals employed by OpenAI wrongfully took Apple’s secret and confidential information regarding our unreleased technologies, processes, and products. We will always defend our teams’ hard work and innovations, and we are taking all appropriate steps to do so.OpenAI was asked for comment. The company responded after publication, [pointing to its public statement shared on X](https://x.com/drewpusateri), which reads: “We have no interest in other companies’ trade secrets. We remain focused on building innovative technology that empowers people everywhere.”The filing is available [here](https://www.documentcloud.org/documents/28453229-apple-v-openai/), or you can read it below.*This story is developing and will be updated. It was originally published at 1:32 p.m. PT.*Topics*When you purchase through links in our articles, [we may earn a small commission](https://techcrunch.com/techcrunch-affiliate-monetization-standards/). This doesn’t affect our editorial independence.*
 Consumer News Editor
 
Last chance to save up to $190 on TechCrunch Founder Summit. Join 1,000+ founders and VCs at all stages for real-world scaling insights and connections that move the needle.

**Savings end June 26, 11:59 p.m. PT**. [Elon Musk praises Mythos/Fable, promises not to ‘cut off’ Anthropic](https://techcrunch.com/2026/07/09/elon-musk-praises-mythos-fable-promises-not-to-cut-off-anthropic/)

 [Instagram users: Here’s how to stop Meta’s AI from using your photos](https://techcrunch.com/2026/07/09/how-to-stop-metas-ai-image-generator-from-using-your-instagram-photos/)

 [Figma acquires team behind a vibe-coding app](https://techcrunch.com/2026/07/07/figma-acquires-team-behind-a-vibe-coding-app/)

 [If you use Google, you’re training its AI. Here’s how to opt out.](https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/)

 [Reddit is using LLMs to solve a problem LLMs largely created](https://techcrunch.com/2026/07/06/reddit-is-using-llms-to-solve-a-problem-llms-largely-created/)

 [Amazon will stop accepting new customers for Mechanical Turk](https://techcrunch.com/2026/07/05/amazon-will-stop-accepting-new-customers-for-mechanical-turk/)

 [5 desk gadgets that can make your workday better](https://techcrunch.com/2026/07/05/5-desk-gadgets-that-can-make-your-workday-better/)]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[Meta removes controversial AI feature on Instagram after backlash | TechCrunch]]></title>
            <link>https://aiheadlines.pro/news/meta-removes-controversial-ai-feature-on-instagram-after-bac-2adbd3</link>
            <guid>https://aiheadlines.pro/news/meta-removes-controversial-ai-feature-on-instagram-after-bac-2adbd3</guid>
            <pubDate>Sat, 11 Jul 2026 06:41:04 GMT</pubDate>
            <description><![CDATA[Meta has axed a controversial feature that allowed users to modify photos from public Instagram accounts using AI. The feature, which was rolled out earlier this week along with a batch of other AI to...]]></description>
            <content:encoded><![CDATA[Meta has axed a controversial feature that allowed users to modify photos from public Instagram accounts using AI. The feature, which was rolled out earlier this week along with a batch of other AI tools, “missed the mark” and is no longer available, according to the company. Earlier this week, Meta [announced](https://techcrunch.com/2026/07/07/meta-rolls-out-muse-a-new-ai-image-generator/) Muse Image, a new AI image generator built by Meta Superintelligence Labs, its dedicated AI unit. Meta promoted one feature that allowed individuals to generate images by @-mentioning public Instagram accounts that they wanted to reference. The feature, which wasn’t designed to alert a user if their photos were used in this way, prompted immediate backlash.TechCrunch [wrote its own guide](https://techcrunch.com/2026/07/09/how-to-stop-metas-ai-image-generator-from-using-your-instagram-photos/) on how to disable the feature.Now Meta has reversed course. The company issued a [blog post](https://about.instagram.com/blog/announcements/new-ai-effects-in-instagram-stories) Friday announcing that it was removing the feature. Puck News founding partner Dylan Byers was the first to share the [company’s decision](https://x.com/DylanByers/status/2075707685547421750?s=20).“Our intent was to provide a useful creative tool and to give people control over whether their public content could be referenced in this way,” the company posted on its blog. “We’ve heard the feedback that this feature missed the mark, so it’s no longer available.”TechCrunch reached out to Meta for more information and will update this article if it responds.Since its integration with social media platforms, AI has been misused with wild abandon — often to [generate naked images of female celebrities](https://www.pbs.org/newshour/show/authorities-struggle-to-stop-ai-tools-generating-nude-images-without-consent#:~:text=There%20has%20been%20a%20sharp,underway%20to%20rein%20it%20in.). Platforms have attempted to mitigate this trend, although the guardrails introduced have often fallen short.In the case of Meta’s newly nixed feature, it seems somewhat obvious that it would have been abused in this way. Indeed, Byers notes that the decision to do away with the feature came “amid scrutiny from users and talent agencies, including CAA.”Topics*When you purchase through links in our articles, [we may earn a small commission](https://techcrunch.com/techcrunch-affiliate-monetization-standards/). This doesn’t affect our editorial independence.*
 Senior Writer, TechCrunch
 
Last chance to save up to $190 on TechCrunch Founder Summit. Join 1,000+ founders and VCs at all stages for real-world scaling insights and connections that move the needle.

**Savings end June 26, 11:59 p.m. PT**. [Elon Musk praises Mythos/Fable, promises not to ‘cut off’ Anthropic](https://techcrunch.com/2026/07/09/elon-musk-praises-mythos-fable-promises-not-to-cut-off-anthropic/)

 [Instagram users: Here’s how to stop Meta’s AI from using your photos](https://techcrunch.com/2026/07/09/how-to-stop-metas-ai-image-generator-from-using-your-instagram-photos/)

 [Figma acquires team behind a vibe-coding app](https://techcrunch.com/2026/07/07/figma-acquires-team-behind-a-vibe-coding-app/)

 [If you use Google, you’re training its AI. Here’s how to opt out.](https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/)

 [Reddit is using LLMs to solve a problem LLMs largely created](https://techcrunch.com/2026/07/06/reddit-is-using-llms-to-solve-a-problem-llms-largely-created/)

 [Amazon will stop accepting new customers for Mechanical Turk](https://techcrunch.com/2026/07/05/amazon-will-stop-accepting-new-customers-for-mechanical-turk/)

 [5 desk gadgets that can make your workday better](https://techcrunch.com/2026/07/05/5-desk-gadgets-that-can-make-your-workday-better/)]]></content:encoded>
            <category>Anthropic</category>
        </item>
        <item>
            <title><![CDATA[NVIDIA decided now is the time to announce 'GeForce Trading Cards' - Engadget]]></title>
            <link>https://aiheadlines.pro/news/nvidia-decided-now-is-the-time-to-announce-geforce-trading-c</link>
            <guid>https://aiheadlines.pro/news/nvidia-decided-now-is-the-time-to-announce-geforce-trading-c</guid>
            <pubDate>Sat, 11 Jul 2026 06:41:02 GMT</pubDate>
            <description><![CDATA[- 
[Gaming](/category/gaming/) 

 
 # NVIDIA decided now is the time to announce 'GeForce Trading Cards'

 It's giving away its 'series 1' trading cards online and at in-person event.

 

 
 
 
 
 
 B...]]></description>
            <content:encoded><![CDATA[- 
[Gaming](/category/gaming/) 

 
 # NVIDIA decided now is the time to announce 'GeForce Trading Cards'

 It's giving away its 'series 1' trading cards online and at in-person event.

 

 
 
 
 
 
 By [Mariella Moon](/author/mariella-moon/)
 
 
 July 10, 2026 4:23 am EST
 
 
 
 
 
 
 
 
 
 *
 
 NVIDIA
 
 
 
 
 NVIDIA has [introduced](https://www.nvidia.com/en-us/geforce/news/geforce-trading-cards-series-1-summer-of-rtx-giveaways/) a series of GeForce Trading Cards with 14 possible designs, which it says represents "GeForce PC gaming's great moments," at a time when gamers have [soured](https://www.cnbc.com/2026/04/18/nvidia-ai-backlash-gamers-geforce-gpu.html) on the company. The GPU-maker has been prioritizing its AI customers lately by manufacturing more products for data centers, because the AI industry has caused massive memory shortages across the board. According to [reports](https://www.tomshardware.com/pc-components/gpus/amds-rdna-5-gaming-gpus-are-coming-late-next-year-according-to-aibs-at-computex-manufacturers-expect-new-team-red-cards-in-the-second-half-of-2027-alongside-nvidia), NVIDIA isn't expected to launch its next set of consumer-facing GPUs for gamers until 2027. 

While the cards' launch was pretty badly timed, at least the company isn't selling them. They're more promotional materials than collectibles people can purchase. The company says it's giving them away through its "[Summer of RTX giveaways](https://www.nvidia.com/en-us/geforce/contests/summer-of-rtx/) on GeForce social channels, as well as at select summer gaming shows and community events, including Bilibili World 2026, QuakeCon 2026 and gamescom 2026." At in-person events, customers can head to the company's booths to ask about the cards. 

Based on the company's announcement, this is just the first series of its trading cards, indicating that it's looking to release more in the future. Series 1 designs include those that feature the NV1, NVIDIA's first mainstream multimedia processor, as well as GeForce 256, the world's first GPU.]]></content:encoded>
            <category>AI Infrastructure</category>
        </item>
        <item>
            <title><![CDATA[Microsoft's AI drive saw its carbon emissions grow by 25 percent in 2025 - Engadget]]></title>
            <link>https://aiheadlines.pro/news/microsofts-ai-drive-saw-its-carbon-emissions-grow-by-25-perc</link>
            <guid>https://aiheadlines.pro/news/microsofts-ai-drive-saw-its-carbon-emissions-grow-by-25-perc</guid>
            <pubDate>Sat, 11 Jul 2026 06:40:58 GMT</pubDate>
            <description><![CDATA[- 
[News](/category/news/) 

 
 # Microsoft's AI drive saw its carbon emissions grow by 25 percent in 2025

 The company said it wanted to be carbon negative by 2030.

 

 
 
 
 
 
 By [Mariella Moon]...]]></description>
            <content:encoded><![CDATA[- 
[News](/category/news/) 

 
 # Microsoft's AI drive saw its carbon emissions grow by 25 percent in 2025

 The company said it wanted to be carbon negative by 2030.

 

 
 
 
 
 
 By [Mariella Moon](/author/mariella-moon/)
 
 
 July 10, 2026 6:44 am EST
 
 
 
 
 
 
 
 
 
 *
 
 Jean-luc Ichard/Getty Images
 
 
 
 
 Microsoft's carbon emissions grew 25 percent year over year in 2025, the company has revealed in its [2026 environmental sustainability report](https://blogs.microsoft.com/on-the-issues/2026/07/09/responsibly-building-the-ai-future/). The report covers the company's 2025 fiscal year and measures its progress against its 2020 baseline. Microsoft says this growth in emissions is mostly caused by the expansion of its investments in AI data center infrastructure. 

As *[GeekWire](https://www.geekwire.com/2026/microsofts-carbon-emissions-climb-25-as-tech-giants-grapple-with-ais-energy-toll/)* notes, Microsoft seems to be moving in the opposite direction of where it wants to go in order to achieve its goal. The company announced in 2020 that it [plans to be carbon negative](https://www.engadget.com/2020-01-16-microsoft-carbon-negative-by-2030.html), or to remove more carbon from the atmosphere than it creates, by 2030. It only has four more years to get there.

"While AI infrastructure is driving demand for energy, water, land, and materials, sustainability solutions are not scaling fast enough to meet demand," it admits. The company knows it has to refine its "strategies as conditions change, data improves, and tradeoffs become clearer." Microsoft says that it's not lowering its ambitions because AI demands are outpacing sustainability solutions. In which case, the company has a lot of work ahead of it. "We continue to really be focused around carbon negativity by 2030," Melanie Nakagawa, chief sustainability officer, told *GeekWire*.

In addition to AI infrastructure buildouts, another reason why Microsoft reported a 25 percent yoy growth in carbon emissions, is because it stopped buying unbundled renewable energy certificates. One certificate signifies that an entity owns one megawatt-hour of zero-carbon electricity generated by a renewable source and delivered to the grid. Microsoft says its decision increased its reported emissions in the near term, but it enables the company to focus on adding all forms of carbon-free electricity to the grids where it operates rather than just on relying on certificates. "We believe this change will create more long-term sustainability benefits," it wrote. 

While it admits to emitting more carbon in its report, Microsoft also highlights its successes for the fiscal year of 2025. It says it matched 100 percent of its annual global electricity consumption with renewal energy. The company also replenished more water than it withdrew globally, which pushes the company closer towards achieving its goal to become [water positive by 2030](https://www.engadget.com/microsoft-water-positive-2030-164019192.html).]]></content:encoded>
            <category>AI Infrastructure</category>
        </item>
        <item>
            <title><![CDATA[China becomes the second country to recover a rocket booster - Engadget]]></title>
            <link>https://aiheadlines.pro/news/china-becomes-the-second-country-to-recover-a-rocket-booster</link>
            <guid>https://aiheadlines.pro/news/china-becomes-the-second-country-to-recover-a-rocket-booster</guid>
            <pubDate>Sat, 11 Jul 2026 06:40:47 GMT</pubDate>
            <description><![CDATA[- 
[Tomorrow](/category/tomorrow/) 

- 
[Space](/category/space/) 

 
 # China becomes the second country to recover a rocket booster

 It successfully deposited a Long March 10B rocket into a net anc...]]></description>
            <content:encoded><![CDATA[- 
[Tomorrow](/category/tomorrow/) 

- 
[Space](/category/space/) 

 
 # China becomes the second country to recover a rocket booster

 It successfully deposited a Long March 10B rocket into a net anchored at sea.

 

 
 
 
 
 
 By [Steve Dent](/author/steve-dent/)
 
 
 July 10, 2026 9:10 am EST
 
 
 
 
 
 
 
 
 
 *
 
 China Central Television
 
 
 
 
 China has become just the second country to capture a reusable rocket, heralding a breakthrough in the country's space program, according to [China's state television CCTV](https://news.cctv.com/2026/07/10/ARTIpeRKVqmmN2aA59kTPrUL260710.shtml). Footage showed the Long March 10B rocket booster descending and being caught by a net, the first time such a feat has been accomplished.

The rocket, on its maiden flight, was developed by the state-owned China Academy of Launch Vehicle Technology (CALT). "[The mission] marks a historic breakthrough for China in the field of reusable rocket technology and will lay a solid foundation for accelerating the enhancement of the country's space access capabilities," CALT said in a (Gemini translated) statement.

CALT used a novel system to catch the booster. Unlike SpaceX's Falcon 9 that uses retractable landing legs (or external mechanical arms for Starship), the Long March 10 caught the rocket using hooks on a net — a world's first, the company said. The rocket was captured intact and CALT expects to reuse it in another flight by the end of this year. 

A video shows the rocket slowly descending on its own power until the rockets cut and it is apparently captured. The grappling mechanism itself isn't clearly visible. The feat was accompanied by cheering, presumably from CALT staff. 

China intends to build itself into a space power by 2030 and its ability to reuse booster rockets is a key part of that. Despite its aim, China's pace for rocket launches lags well behind the US. Last year, the US conducted [193 orbital launches](https://spacenews.com/spacex-china-drive-new-record-for-orbital-launches-in-2025/) (165 by SpaceX alone) compared to [92 attempts](https://spacenews.com/china-caps-record-year-for-orbital-launches-with-tianhui-7-and-shijian-29-technology-test-missions/) for China. 

CALT's first simulation at a reusable rocket recovery in February 2026 ended with the booster splashing down 200 meters from the recovery platform. Another private Beijing-based company, LandSpace, uses a more SpaceX-like mechanical leg system for its ZhuQue-3 rocket. That attempt [came close to success](https://x.com/LandSpace_Tech/status/1996973617037648205) but ended up in a fireball, which the company declined to show.]]></content:encoded>
            <category>Google AI</category>
        </item>
        <item>
            <title><![CDATA[The Meta Glasses backlash is changing how (or if) people use them - Engadget]]></title>
            <link>https://aiheadlines.pro/news/the-meta-glasses-backlash-is-changing-how-or-if-people-use-t</link>
            <guid>https://aiheadlines.pro/news/the-meta-glasses-backlash-is-changing-how-or-if-people-use-t</guid>
            <pubDate>Sat, 11 Jul 2026 06:40:12 GMT</pubDate>
            <description><![CDATA[- 
[Big Tech](/category/big-tech/) 

- 
[Meta](/category/meta/) 

 
 # The Meta Glasses backlash is changing how (or if) people use them

 "They're like a fancy paper weight," one creator told Engadge...]]></description>
            <content:encoded><![CDATA[- 
[Big Tech](/category/big-tech/) 

- 
[Meta](/category/meta/) 

 
 # The Meta Glasses backlash is changing how (or if) people use them

 "They're like a fancy paper weight," one creator told Engadget. 

 

 
 
 
 
 
 By [Karissa Bell](/author/karissa-bell/)
 
 
 July 10, 2026 3:30 pm EST
 
 
 
 
 
 
 
 
 
 *
 
 Karissa Bell for Engadget
 
 
 
 
 On Bluesky, posts regularly suggest that people who wear "pervert glasses" be punched in the face. The criticism of eye-worn gadgets capable of surveillance [isn't new](https://www.wired.com/story/google-glass-reasonable-expectation-of-privacy/), though the online discourse — "Meta Glasses" repeatedly trended on Meta's own Threads app last week, for the wrong reasons — seems to have intensified following the release of Meta's latest [cheaper lineup](https://www.engadget.com/2199519/meta-ai-glasses-hands-on-kylie-jenner-edition/), as well as reports about [an unreleased](https://www.engadget.com/2187824/wired-found-code-for-an-unreleased-facial-recognition-feature-in-meta-s-ai-app/) facial recognition feature for the product. For whatever reason, this time the backlash seems to be having a real effect.

Engadget spoke with five creators, photographers and others who were once enthusiastic about Meta's smart glasses about how public perception has changed their habits.

"A lot of men and their behaviors have ruined this product," Danielle, a Florida-based creator and travel host who asked to be identified by first name only, told Engadget. Initially she enjoyed using her smart glasses for capturing travel content from the international trips she hosts. Then she read a story about how contractors working for Meta said they had been tasked with [reviewing intimate images](https://www.engadget.com/ai/metas-ai-display-glasses-reportedly-share-intimate-videos-with-human-moderators-135939855.html) and other sensitive details captured by glasses owners.

Further reporting of men using Meta-branded glasses to [film videos](https://www.wired.com/story/the-rise-of-the-ray-ban-meta-creep/) of themselves [harassing women](https://www.cnn.com/2026/02/09/world/manfluencers-smart-glasses-intl) in public sealed the deal. She says she hasn't used them since. "I wouldn't feel comfortable around somebody wearing them, so I wouldn't expect anybody to be comfortable around me wearing them, no matter where I am.

"At this point, they're like a fancy paper weight," she says.

Other creators who have previously purchased the frames now say they are using the product less often due to fears that people around them will assume they're doing something "creepy."

Christian Eisenbarth is a Los Angeles-based videographer who was gifted a pair of Ray-Ban Meta glasses by his girlfriend. He says that while he had previously been eyeing a pair for use on his video shoots, he has yet to use them outside of his home "mainly due to being afraid of being labeled as a creep." That fear has so far outweighed his personal enthusiasm for the product. "It's awesome to have a true POV perspective, and you can record without having to mess with a rig on your camera, or something strapped to your chest," he said.

Everyone who spoke with Engadget reported feeling somewhat conflicted about Meta's smart glasses. They all believed they had used the product responsibly and that the product, which starts at $224 for the first-gen model, is well-designed. They also all expressed some level of discomfort with Meta's privacy practices and people who have misused the tech.

Martino Wong is a creator and self-described tech enthusiast who was an early adopter of Ray-Ban Meta glasses. Wong, who says he primarily uses his sunglasses for phone calls and for recording product videos, says the privacy backlash seems to be more prominent in English-speaking spaces on the internet, but that it has still had an effect on him.

"I've been a little bit more mindful of them, especially in more crowded environments," he said. "There have been times in which I basically fold them up and hang them on my shirt, so as to show more clearly that I'm not actively using them."

Will Kujawa, a freelance video producer, said that he has been thinking about buying a pair of Meta glasses with prescription lenses to film behind the scenes content during his shoots, but the online backlash has given him second thoughts. He says he was "blown away by how mean some of the people were" in response to his social media posts about considering buying a pair.

"I saw all these comments about if you wear those glasses you're basically a predator or a creep, and I was like, 'oh, maybe it's not a good idea to have those,'" he told Engadget. But he says he understands why people have concerns. "I didn't really think that through all the way ... there are a lot of times where it's not appropriate to wear cameras on your face. And even though I would have no intention of do[ing] anything creepy with them, it didn't even occur to me [that] other people just assume that automatically."

Kujawa said he still thinks he might buy a pair to use on his video shoots, but that he would plan on carrying a backup pair of regular prescription glasses just in case. "It does make me more cautious," he said. "I don't think I would wear them everywhere or all the time."

No one who spoke with Engadget reported experiencing unwanted comments or interactions related to their smart glasses in real life, though they were all acutely aware of the negative online discourse. Many said they would welcome more enhanced privacy features, like a more prominent LED when the camera is in use.

Jeremy, a professional photographer who also owns a brand consultancy, told Engadget his usage habits haven't changed despite negative associations — he mainly listens to music or records family videos with them. But Jeremy, who also asked to be referred to by first name only, said he has turned off cloud uploads and tried to use the most restrictive privacy settings possible. "Facebook hasn't done a lot of good in the world," he said. "I totally understand the backlash."

At the same time, he believes that conversations about privacy and surveillance go beyond one company and one product. "It's easy to have outrage over a thing that you can point to really clearly, but I think it's a lot harder to come to terms with the fact that we're all being recorded all the time."

Meta sold more than [7 million](https://www.cnbc.com/2026/02/11/ray-ban-maker-essilorluxottica-triples-sales-of-meta-ai-glasses.html) pairs of co-branded glasses in 2025. It just added a new lineup without Ray-Ban branding and will likely show off additional frames before the end of the year. A sustained privacy backlash could damage that momentum.

This week, Meta announced that it was issuing a mandatory software update to all of its smart glasses that would disable the device's camera if the LED light is [physically tampered](https://www.engadget.com/2210283/meta-disable-camera-glasses-tamper-with-recording-led/) with. The company also said it would take legal action against people who promote LED-tampering services. The update follows [several reports](https://www.404media.co/how-to-disable-meta-rayban-led-light/) about the cottage industry that's sprung up around Meta glasses "hacks." Many of these services, which use simple tools like drills and [dental probes](https://www.youtube.com/watch?v=EaJSPeJmqis) to disable the recording light, have been advertised on Meta's own platforms. There are also dozens of videos on YouTube offering DIY tutorials.

The change, which was announced in an privacy-focused [FAQ](https://about.fb.com/news/2026/07/metas-ai-glasses-your-questions-answered/), is the clearest acknowledgement by the company of the privacy-related backlash; at the same time, it has made few other concessions. In a privacy [FAQ](https://about.fb.com/news/2026/07/metas-ai-glasses-your-questions-answered/) published this week, Meta was non-committal about specific new features. In a section headlined "will more privacy features be coming to glasses?" the company gave only vague assurances:

"As our glasses become more capable and common, our teams continue to work on ways to make them even safer and more trustworthy," it said. "We set a high standard for our AI glasses because we believe it's an essential component of any good technology."]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[OpenAI's browser isn't dead, it just moved to the ChatGPT app - Engadget]]></title>
            <link>https://aiheadlines.pro/news/openais-browser-isnt-dead-it-just-moved-to-the-chatgpt-app--</link>
            <guid>https://aiheadlines.pro/news/openais-browser-isnt-dead-it-just-moved-to-the-chatgpt-app--</guid>
            <pubDate>Sat, 11 Jul 2026 06:40:06 GMT</pubDate>
            <description><![CDATA[- 
[News](/category/news/) 

- 
[AI](/category/ai/) 

 
 # OpenAI's browser isn't dead, it just moved to the ChatGPT app

 And the Chrome plugin.

 

 
 
 
 
 
 By [Igor Bonifacic](/author/igor-bonifa...]]></description>
            <content:encoded><![CDATA[- 
[News](/category/news/) 

- 
[AI](/category/ai/) 

 
 # OpenAI's browser isn't dead, it just moved to the ChatGPT app

 And the Chrome plugin.

 

 
 
 
 
 
 By [Igor Bonifacic](/author/igor-bonifacic/)
 
 
 July 10, 2026 4:11 pm EST
 
 
 
 
 
 
 
 
 
 *
 
 Cheng Xin/Getty Images
 
 
 
 
 I know a lot of people want to celebrate any stumble OpenAI makes, and rightfully so, but the imminent "death" of its [Atlas browser](https://www.engadget.com/ai/openais-ai-powered-browser-chatgpt-atlas-launches-on-macos-today-170735742.html) isn't a sign of a company retreating from a competitive market. If you didn't catch the news yesterday, OpenAI announced, [as part of the release of ChatGPT Work](https://www.engadget.com/2211869/openai-releases-chatgpt-work-tool-macos-windows-web-plans/), that it would deprecate Atlas on [August 9](https://x.com/JamesZmSun/status/2075290224327057644). Coverage of the news treated it like OpenAI was giving up on the browser space entirely, with headlines like "[The ChatGPT browser is already dead](https://www.theverge.com/ai-artificial-intelligence/963654/openai-chatgpt-atlas-ai-browser-shut-down-sunset)" and "[OpenAI is shutting down the ChatGPT Atlas browser only months after its release](https://www.androidauthority.com/openai-sunsetting-chatgpt-atlas-3686001/)" making the rounds.

Naturally, people on social media followed suit. For instance, one Bluesky user Pavel [took it as an opportunity](https://bsky.app/profile/spavel.bsky.social/post/3mqascp5m3s2k) to round up a number of other "dead" OpenAI initiatives. "Tell me again about 'inevitability,'" they added. Setting aside some of the other inclusions don't quite fit, like the IPO plans OpenAI [reportedly delayed in June](https://www.nytimes.com/2026/06/25/technology/openai-ipo-artificial-intelligence.html), it's not accurate to include Atlas in that list.

**
Sora: dead

Atlas: dead

"adult mode": dead

Abilene expansion: dead

OpenAI IPO: dead

Tell me again about "inevitability"

— [Pavel (@spavel.bsky.social)](https://bsky.app/profile/did:plc:o7xt7svg2xtjbb4e2xqahqqc?ref_src=embed) [2026-07-09T23:34:38.372Z](https://bsky.app/profile/did:plc:o7xt7svg2xtjbb4e2xqahqqc/post/3mqascp5m3s2k?ref_src=embed)

We've [known since March](https://www.engadget.com/ai/openai-is-putting-chatgpt-its-browser-and-code-generator-into-one-desktop-app-025709839.html) OpenAI has been working on a so-called "super app" that would bring together ChatGPT, its Codex coding agent and Atlas browser under one roof. On Thursday, that effort arrived in the form of a redesigned ChatGPT desktop app. As expected, it allows users to converse with ChatGPT, delegate tasks to Codex and ChatGPT Work (OpenAI's new general purpose productivity agent) and surf the web through a built-in browser. You can access the browser through a shortcut on the top right of the interface, or by pressing Ctrl, Alt and B at the same time.

True, what's here isn't a one-for-one replacement for Atlas, but that's because OpenAI has effectively split the app across two different products. In addition to ChatGPT Work, the company also announced an update to its [Chrome extension](https://chromewebstore.google.com/detail/chatgpt/hehggadaopoacecdllhhajmbjkdcmajg?hl=en&pli=1). The plugin now functions like a direct competitor to Google's own [Gemini in Chrome](https://www.engadget.com/ai/google-brings-its-nano-banana-image-generator-to-chrome-180000104.html). After you grant OpenAI permission to gather context from the page you're viewing, you can ask ChatGPT questions about the content and start longer tasks from its prompt bar. Back in the ChatGPT app, a new feature called Sites allows the chatbot to generate web apps for your own personal use. "Sites are useful when you want to create things like live dashboards, project trackers, launch calendars, prototypes, internal portals, and interactive reports," OpenAI said yesterday.

So, yes, Atlas is going away, but it's not like it's leaving behind a void. In reporting about the discontinuation, a handful of publications referenced guidance former OpenAI executive Fidji Simo gave employees in March, telling them the company had to avoid becoming distracted by "[side quests](https://www.wsj.com/tech/ai/openai-chatgpt-side-projects-16b3a825?eafs_enabled=false)." Based on what we saw from OpenAI this week, I don't think the company came to the conclusion Atlas was a distraction. Instead, like [*TechCrunch's* Rebecca Bellan](https://techcrunch.com/2026/07/09/openai-is-shutting-down-atlas-but-its-ai-browser-ambitions-are-still-growing/), I would argue the company decided that "the browser is a feature, not the destination."

Writing about the decision to discontinue Atlas, [OpenAI's James Sun](https://x.com/JamesZmSun/status/2075290224327057644) suggested as much. "All these capabilities were built on what we learned from Atlas users who took a leap of faith on a new browser," he said of ChatGPT's new browsing features. "You taught us how agents can help make browsing and doing work on the open web better, and we are applying these learnings to these new products."

Again, I know a lot of people want to see OpenAI fail, and I think we can and should resist the notion that AI will inevitably run the world. Despite those feelings, the end of Atlas doesn't really feel like a failure; it's more a change in strategy. Knowing this company, it will make bigger mistakes that are more worthy of criticism and ridicule.]]></content:encoded>
            <category>OpenAI</category>
        </item>
        <item>
            <title><![CDATA[Apple calls OpenAI's hardware business 'rotten to its core' in trade secret theft lawsuit - Engadget]]></title>
            <link>https://aiheadlines.pro/news/apple-calls-openais-hardware-business-rotten-to-its-core-in-</link>
            <guid>https://aiheadlines.pro/news/apple-calls-openais-hardware-business-rotten-to-its-core-in-</guid>
            <pubDate>Sat, 11 Jul 2026 06:40:00 GMT</pubDate>
            <description><![CDATA[- 
[Big Tech](/category/big-tech/) 

- 
[Apple](/category/apple/) 

 
 # Apple calls OpenAI's hardware business 'rotten to its core' in trade secret theft lawsuit

 The lawsuit also names io Products,...]]></description>
            <content:encoded><![CDATA[- 
[Big Tech](/category/big-tech/) 

- 
[Apple](/category/apple/) 

 
 # Apple calls OpenAI's hardware business 'rotten to its core' in trade secret theft lawsuit

 The lawsuit also names io Products, the hardware company led by Jony Ive.

 

 
 
 
 
 
 By [Karissa Bell](/author/karissa-bell/)
 
 
 July 10, 2026 5:39 pm EST
 
 
 
 
 
 
 
 
 
 *
 
 Erman Gunes/Shutterstock
 
 
 
 
 Apple is suing OpenAI and two of its former employees who currently work at the AI company, for theft of its trade secrets. In a lawsuit filed in federal court Friday, Apple alleges extensive misconduct by the company it once partnered with, describing its hardware business as "rotten to its core."

The lawsuit also names io Products, the Jony Ive-led hardware startup [acquired by](https://www.engadget.com/ai/openai-buys-jony-ives-design-startup-for-65-billion-173356962.html) OpenAI last year, as complicit in the trade secret theft. It doesn't mention Ive by name, but described the organization as complicit in "a coordinated pattern of misconduct at an institutional level" within OpenAI.

The filing also names Chang Liu, a former senior system electrical engineer at Apple, and Tang Yew Tan, a former Apple VP who is now OpenAI's Chief Hardware Officer. Apple claims that both Liu and Tan shared trade secrets with OpenAI. Liu, according to Apple's lawyers, "surreptitiously accessed and downloaded dozens of Apple's confidential hardware-related files, including voluminous, detailed information about unreleased products, engineering presentations, technical specifications, and proprietary project data."

Apple also claims that Tan "has directed job candidates still working for Apple to bring 'actual parts' from Apple to their interviews for 'show and tell' sessions in which he and his team at OpenAI can elicit still more Apple confidential information." In all, Apple says that more than 400 of its former employees have taken jobs at OpenAI and that the company's interview process if structured "to try to solicit additional confidential Apple information."

OpenAI didn't immediately respond to a request for comment on the allegations. The company "never responded" when Apple reached out about its concerns, the lawsuit says. Drew Pusateri, OpenAI's director of strategic communications, tweeted that the company has "no interest in other companies' trade secrets" in reaction to the suit.

**
Our statement in response to this suit: We have no interest in other companies' trade secrets. We remain focused on building innovative technology that empowers people everywhere. [https://t.co/lIxGW6hyz5](https://t.co/lIxGW6hyz5)

— Drew Pusateri (@drewpusateri) [July 10, 2026](https://x.com/drewpusateri/status/2075708238650089981?ref_src=twsrc%5Etfw)

In the filing, Apple says that it's likely not aware of the full extent of OpenAI's misconduct. "This much is clear, however: at every level, from members of its Technical Staff to its Chief Hardware Officer, and in coordination with business partners, OpenAI has been stealing Apple's trade secrets and confidential information," it says. "As a natural result, OpenAI's nascent hardware business now rests on the shakiest of foundations, rotten to its core by its illegal reliance on misappropriated trade secrets."

The lawsuit comes as Apple is still partnering with OpenAI for Apple Intelligence. In a footnote, Apple says that its existing agreement, which allows the iPhone maker to integrate chatGPT into its devices, "is not at issue here" and that its allegations of trade secret theft have "no connection" to the arrangement.

**Update, July 10, 7:30PM ET: **This story was updated after publish to include a public comment from Drew Pusateri, OpenAI's director of strategic communication.]]></content:encoded>
            <category>OpenAI</category>
        </item>
        <item>
            <title><![CDATA[Meta deactivates feature that let you generate AI images of any public Instagram account - Engadget]]></title>
            <link>https://aiheadlines.pro/news/meta-deactivates-feature-that-let-you-generate-ai-images-of-</link>
            <guid>https://aiheadlines.pro/news/meta-deactivates-feature-that-let-you-generate-ai-images-of-</guid>
            <pubDate>Sat, 11 Jul 2026 06:39:55 GMT</pubDate>
            <description><![CDATA[- 
[Big Tech](/category/big-tech/) 

- 
[Meta](/category/meta/) 

 
 # Meta deactivates feature that let you generate AI images of any public Instagram account

 The company said it heard feedback tha...]]></description>
            <content:encoded><![CDATA[- 
[Big Tech](/category/big-tech/) 

- 
[Meta](/category/meta/) 

 
 # Meta deactivates feature that let you generate AI images of any public Instagram account

 The company said it heard feedback that the capability ‘missed the mark.’

 

 
 
 
 
 
 By [Mariella Moon](/author/mariella-moon/)
 
 
 July 10, 2026 9:33 pm EST
 
 
 
 
 
 
 
 
 
 *
 
 Ascannio/Shutterstock
 
 
 
 
 Meta has [deactivated](https://about.fb.com/news/2026/07/introducing-muse-image-meta-ai/) a controversial Muse Image capability. When the company [introduced](https://www.engadget.com/2210087/meta-s-new-muse-image-model-accepts-instagram-accounts-as-a-prompt/) the model, it also announced that on Instagram, anybody could tag a public account — including yours, if it is public — and automatically generate AI deepfakes based on its posts. The tagger and Muse Image didn't even have to ask for your permission. Meta wrote in its launch post that you could @-mention people to use the feature if "you want to design a custom event invitation, mock up a collaborative creative concept or generate a personalized graphic."

In an update to its [announcement](https://about.fb.com/news/2026/07/introducing-muse-image-meta-ai/) for Muse Image, the company said it heard feedback that the capability "missed the mark" and has pulled it down. "Earlier this week, we announced that one way for people to generate images in Meta AI is by @-mentioning public Instagram accounts that they want to reference," the company wrote. "Our intent was to provide a useful creative tool and to give people control over whether their public content could be referenced in this way. We've heard the feedback that this feature missed the mark, so it's no longer available."

The tool was met with criticism online as soon as it was announced, especially since you had to opt out if you didn't want the image generator to be able to create AI deepfakes from the posts in your account. You had to go deep into your Settings menu and toggle off an option that said "Allow people to create with and reuse your content." It was either that or set your Instagram profile to private. 

According to *[Variety](https://variety.com/2026/biz/news/meta-suspends-ai-image-instagram-feature-backlash-1236806989/)*, it wasn't just ordinary users who vocally criticized it. Hollywood agency CAA, whose clients include Tom Hanks and Meryl Streep, reportedly raised its concerns directly with Meta. "No one's name, image, likeness, voice or creative work should be used by any third party, including AI models, without clear, documented consent," the agency said in a statement. American labor union SAG-AFTRA also encouraged members to opt out. Do you have these organizations to thank for the feature's removal? Maybe, maybe not. But it's gone now, and hopefully Meta doesn't roll out any more AI capabilities that involve usage of your likeness without having to get your explicit permission.]]></content:encoded>
            <category>AI News</category>
        </item>
        <item>
            <title><![CDATA[How to shrink the token budget without shrinking the team]]></title>
            <link>https://aiheadlines.pro/news/how-to-shrink-the-token-budget-without-shrinking-the-team</link>
            <guid>https://aiheadlines.pro/news/how-to-shrink-the-token-budget-without-shrinking-the-team</guid>
            <pubDate>Sat, 11 Jul 2026 06:39:12 GMT</pubDate>
            <description><![CDATA[Jensen Huang has a test for whether an engineer is worth keeping, and it comes with a token budget attached. Speaking on the All-In Podcast at the close of GTC 2026, the Nvidia chief executive said th...]]></description>
            <content:encoded><![CDATA[Jensen Huang has a test for whether an engineer is worth keeping, and it comes with a token budget attached. Speaking on the All-In Podcast at the close of GTC 2026, the Nvidia chief executive said that if a $500,000 engineer’s annual AI token consumption came in under half their salary, “I am going to be deeply alarmed.” Nvidia, he confirmed, is working toward a $2 billion yearly token bill for its engineering force.

He was describing a trade-off most companies have already made with less fanfare: money that once paid people increasingly pays for tokens. The four largest hyperscalers have [guided](https://valueaddvc.com/blog/the-725b-ai-capex-supercycle-what-happens-when-four-companies-spend-this-much-at-once) roughly $700 billion in combined 2026 capital expenditure, nearly double last year, while data from outplacement firm Challenger, Gray & Christmas [shows](https://www.challengergray.com/blog/challenger-report-june-layoffs-cool-to-45849-down-53-from-may-ai-leads-reasons-for-fourth-consecutive-month/) AI as the most-cited reason for US job cuts for a record fourth consecutive month.

An internal Meta memo obtained by *Reuters* described May’s cuts of 8,000 roles as offsetting the company’s substantial investments, in a quarter when revenue grew 33%. The layoffs at companies like these aren’t survival measures. They’re financing.

The trouble is that the financing hasn’t bought what it promised. Gartner surveyed 350 executives at companies with over $1 billion in revenue, all deploying AI agents or automation, and found roughly 80% had cut headcount with [no correlation](https://www.gartner.com/en/newsroom/press-releases/2026-05-05-gartner-says-autonomous-business-and-artificial-intelligence-layoffs-may-create-budget-room-but-do-not-deliver-returns) to improved returns. Analyst Helen Poitevin’s verdict was blunt: “Workforce reductions may create budget room, but they do not create return.”

Uber learned the token side of that lesson the expensive way, giving 5,000 engineers AI coding tools in December and exhausting its entire 2026 AI budget by April. Chief Operating Officer Andrew Macdonald conceded that despite 70% of committed code being AI-generated, the connection to anything customers notice is missing: “That link is not there yet.”

Put those two failures side-by-side and the actual problem comes into focus. Companies treated the token bill as fixed and the workforce as flexible, when the opposite is true. Payroll cuts happen once and take institutional knowledge with them. A token budget, it turns out, bends in half a dozen places if anyone bothers to engineer it.

### **Where the token budget bends**

The cheapest fix is also the least glamorous: stop paying to process the same text repeatedly. Prompt caching, now standard across the major API providers, cuts the cost of repeated input by up to 90% under Anthropic’s and OpenAI’s published pricing, because static content like system instructions and reference documents gets processed once and reread at a fraction of the rate.

Security firm ProjectDiscovery documented raising its cache hit rate from 7% to 84% by restructuring prompts, cutting its total LLM spend by 59 to 70% while serving 9.8 billion tokens from cache. That single engineering exercise recovered more budget than most AI-attributed layoff rounds save.

The next lever is routing work to the right-sized model. Providers’ own price lists show flagship models costing five times their smaller siblings per token, yet plenty of production workloads send routine classification and summarisation to the most expensive tier by default. Batch processing adds a further 50% discount for anything that doesn’t need a real-time answer.

Retrieval-augmented generation attacks the problem from another angle by sending the model only the relevant slice of a knowledge base rather than the whole thing, and prompt compression trims the redundant examples that inflate every call. Open-weight models reduce costs further still, handling routine workloads at a fraction of frontier API prices for teams willing to manage the infrastructure.

These measures are simply the AI equivalent of turning off the lights in empty rooms, and Uber’s $1,500 monthly cap per engineer – imposed after the April overrun – is early evidence that spending discipline arrives eventually. The companies getting ahead are simply choosing it before the budget forces it.

### **The other half of the fix is human**

Optimising the token bill only matters if the savings go somewhere productive, and the strongest evidence points at people. Poitevin’s research found the organisations that improved ROI were those using AI to amplify their workforce rather than replace it.

Klarna ran the controlled experiment on everyone’s behalf, replacing roughly 700 customer service roles with an OpenAI-powered assistant before customer satisfaction fell. Chief Executive Sebastian Siemiatkowski told *Bloomberg* what few executives admit aloud: “The result was lower quality, and that’s not sustainable.”

The fintech now runs a blended model, with AI absorbing routine volume while rehired humans handle everything requiring judgment. Gartner expects the pattern to spread, predicting that by 2027 half the companies that cut customer service staff for AI will rehire them.

There’s one workforce investment the optimisation logic makes urgent rather than optional. Stanford University’s Institute for Human-Centered AI [found](https://digitaleconomy.stanford.edu/app/uploads/2025/11/CanariesintheCoalMine_Nov25.pdf) employment for software developers aged 22 to 25 fell nearly 20% from 2024 levels even as older cohorts grew, which means companies are removing the training ground for the senior engineers they’ll need directing all these systems in five years.

A business that has just engineered 60% off its token bill has the budget room to keep hiring at the bottom rung. Whether it does is a leadership decision, not a financial one.

Nvidia’s Huang’s provocation will keep echoing through earnings calls, and the capex numbers will keep climbing. The companies that come out ahead won’t be the ones that spent the most on tokens or cut the most people to afford them—they’ll be the ones that noticed the token budget was the flexible line all along, squeezed it with engineering rather than headcount, and spent the difference on the people who make the tokens worth anything.

*(Image by [kate.sade](https://unsplash.com/photos/empty-black-rolling-chairs-at-cubicles-2zZp12ChxhU))*

**See also: [Per-token AI charges come to GitHub Copilot](https://www.artificialintelligence-news.com/news/per-token-ai-charging-comes-to-github-copilot/)**

[*](https://www.ai-expo.net/?utm_source=AI-News&utm_medium=Footer-banner&utm_campaign=world-series)**Want to learn more about AI and big data from industry leaders?** Check out [AI & Big Data Expo](https://www.ai-expo.net/?utm_source=AI-News&utm_medium=Footer-banner&utm_campaign=world-series) taking place in Amsterdam, California, and London. The comprehensive event is part of [TechEx](https://techexevent.com/?utm_source=AI-News&utm_medium=Footer-banner&utm_campaign=world-series) and is co-located with other leading technology events including the [Cyber Security & Cloud Expo](https://cybersecuritycloudexpo.com/?utm_source=CloudTech-News&utm_medium=Footer-banner&utm_campaign=world-series). Click [here](https://techexevent.com/?utm_source=AI-News&utm_medium=Footer-banner&utm_campaign=world-series) for more information.

AI News is powered by [TechForge Media](https://techforge.pub/?utm_source=AI-News&utm_medium=Footer-banner&utm_campaign=world-series). Explore other upcoming enterprise technology events and webinars [here](https://techforge.pub/events/?utm_source=AI-News&utm_medium=Footer-banner&utm_campaign=world-series).]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access]]></title>
            <link>https://aiheadlines.pro/news/hackers-use-fake-microsoft-entra-passkey-enrollment-to-gain-</link>
            <guid>https://aiheadlines.pro/news/hackers-use-fake-microsoft-entra-passkey-enrollment-to-gain-</guid>
            <pubDate>Sat, 11 Jul 2026 06:38:57 GMT</pubDate>
            <description><![CDATA[- 

**Ravie Lakshmanan**Jul 10, 2026Enterprise Security / Authentication
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh1L4YdSw3-1jg88TMzYxjsqRmu3Bq-VkmyGg742mMsJaIyhyaBk5MBeEFOxagE...]]></description>
            <content:encoded><![CDATA[- 

**Ravie Lakshmanan**Jul 10, 2026Enterprise Security / Authentication
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh1L4YdSw3-1jg88TMzYxjsqRmu3Bq-VkmyGg742mMsJaIyhyaBk5MBeEFOxagE4H6GFjfH8ey1114iqyT0LuKYFdu7ocZhOrA3WQCvtNZGBknEJ1wTdb5vJ-M8w5kLXaUoBi39TXducoH8jZVrQ1xQQsBtEf0rrGJGfappdR1CrSB3xvaJC8Dgos2XdC37/s1700-e365/Microsoft-Entra-Passkey-Enrollment.jpg)
A threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to enroll a new Entra [passkey](https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html) with an aim to carry out data extortion attacks.

The threat actor, tracked by Okta under the moniker **O-UNC-066**, has deployed a panel-controlled phishing kit that's capable of targeting the [passkey enrollment process](https://support.microsoft.com/en-us/windows/security/identity-signin/create-and-save-a-passkey). The activity has singled out food and beverage, technology, healthcare, automotive, construction, and aviation industries.

"The threat actor registers domains that incorporate the word passkey as part of a voice-enabled phishing ('vishing') scheme," Okta researcher Houssem Eddine Bordjiba [said](https://www.okta.com/blog/threat-intelligence/vishing-actors-target-microsoft-entra-passkey-enrollment-/). "The threat actor then calls targeted users on the phone in an attempt to persuade them that they need to register a new passkey."

Users are then directed to a phishing kit that's identical to the Microsoft passkey enrollment process, giving the impression that they are adding a passkey with Microsoft, when, in reality, the threat actor registers their own passkey against their Microsoft account, granting them unauthorized access.

[*](https://thehackernews.uk/ai-vuln-protection-d)
The development coincides with Microsoft allowing administrators to [configure registration campaigns](https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#general-availability---support-for-passkeys-in-microsoft-entra-id-registration-campaign) to nudge users to register passkeys during sign-in in an attempt to help organizations drive passkey adoption at scale. In other words, threat actors are abusing the phishing-resistant security upgrade process as a lure to enroll their own passkeys within victims' accounts and facilitate follow-on activities.

Unlike adversary-in-the-middle ([AitM](https://thehackernews.com/2026/01/microsoft-flags-multi-stage-aitm.html)) landing pages that are prevalent in phishing campaigns designed to steal credentials and multi-factor authentication (MFA) tokens, the phishing kit used in these attacks is an operator-controlled PHP panel in which a victim is guided through the passkey enrollment process in almost real-time.

"The operator can use the kit to adapt the user experience to each victim's MFA requirements (TOTP, push notification with number matching, SMS OTP) during the session," the identity security company said. "The caller can control and adjust in real time what phishing pages and notifications a targeted user sees."

It's suspected that the threat actor is leveraging the kit to take over the victim account and trick the user into approving an attacker-initiated registration of a passkey. There is no indication at this stage to suggest that the kit is redirecting users to third-party identity providers like Okta.

The entire sequence of actions is below -

 - The first page of the phishing kit (/gate) displays a page loading icon while the phishing kit performs anti-analysis checks in the background.

 - The second page (/identify) requests a username.

 - The next page (/password) challenges the user for a password.

 - The harvested credentials are sent in a POST request to an operator panel at "/backend.php."

 - The phishing kit operator (likely different from the individual calling the victim) enters the stolen credentials on the legitimate Microsoft sign-in page for the targeted tenant.

 - The victim sees a "/processing" page that serves another loading screen as it awaits the operator's instruction based on the observed MFA challenges presented to them in the legitimate flow.

 - The next page of the phishing kit is presented to the user: "/submit-otp" for an SMS-based one-time password (OTP) challenge, "/submit-authenticator" for time-based OTP challenge, or "/approve-authenticator" for a [push MFA challenge](https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-mfa-number-match).

 - The captured OTP is sent in a POST request to "/backend.php."

At this point, the victim has been deceived over the phone into approving the attacker's access to their Microsoft 365 account. The attack chain then initiates another set of actions focused around the passkey pretext -

 - The victim is redirected to the "/passkey/register" page, which instructs the user to create a passkey.

 - The Microsoft-branded "/passkey" page prompts the user to save their recovery key for confirming their passkey.

 - The "/passkey/check" page asks the user to verify the final word used in the seed phrase.

 - The "/done" page confirms that a passkey registration was successful.

[*](https://thehackernews.uk/sygnia-cyber-response-d-1)
The recovery key contains a series of 12 words that's similar to secret recovery phrase or mnemonic phrase typically associated with cryptocurrency wallets. The step is assessed to be a distraction mechanism to keep the victim occupied with the task, while they enrolled their own passkey in the Microsoft account.

"The phishing kit appears to prey on lack of user familiarity with passkey authentication," Okta explained. "In a real passkey registration ceremony, the user might expect a system dialog to register a passkey on their device. The passkey pages in this phishing kit appear to mimic this process without registering a passkey."

Okta noted that a threat actor linked to O-UNC-066 has been operating a data leak site since April 2026 under the name Pink. Palo Alto Networks Unit 42 is [tracking](https://thehackernews.com/2026/06/weekly-recap-instagram-account-hacks.html#:~:text=Pink%2C%20a%20New%20Com%2DAffiliated%20Actor) this cluster as CL-CRI-1147, describing it as affiliated with a decentralized cybercrime collective known as [The Com](https://thehackernews.com/2025/11/a-cybercrime-merger-like-no-other.html), of which Scattered Spider, ShinyHunters, and LAPSUS$ are part of.

Found this article interesting? Follow us on [Google News](https://news.google.com/publications/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ), [Twitter](https://twitter.com/thehackersnews) and [LinkedIn](https://www.linkedin.com/company/thehackernews/) to read more exclusive content we post.

SHARE
[**](#link_share)
[**](#link_share)
[**](#link_share)
[**](javascript:void(0))

[**Tweet](#link_share)
[**Share](#link_share)
[**Share](#link_share)
**Share

[SHARE **](javascript:void(0))
[Authentication](https://thehackernews.com/search/label/Authentication), [Cloud security](https://thehackernews.com/search/label/Cloud%20security), [Cybercrime](https://thehackernews.com/search/label/Cybercrime), [Data Extortion](https://thehackernews.com/search/label/Data%20Extortion), [enterprise security](https://thehackernews.com/search/label/enterprise%20security), [Identity Security](https://thehackernews.com/search/label/Identity%20Security), [Microsoft](https://thehackernews.com/search/label/Microsoft), [Phishing](https://thehackernews.com/search/label/Phishing), [Social Engineering](https://thehackernews.com/search/label/Social%20Engineering)]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking]]></title>
            <link>https://aiheadlines.pro/news/study-of-281-free-android-vpn-apps-finds-traffic-leaks-unenc</link>
            <guid>https://aiheadlines.pro/news/study-of-281-free-android-vpn-apps-finds-traffic-leaks-unenc</guid>
            <pubDate>Sat, 11 Jul 2026 06:38:53 GMT</pubDate>
            <description><![CDATA[- 

**Swati Khandelwal**Jul 10, 2026Mobile Security / Privacy
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGJR5fh4xv_X2JER6SMxM62unaK2pucigiJwiE69bCR9n3fgVMqlH2zWpTsmiy4d936R46czj...]]></description>
            <content:encoded><![CDATA[- 

**Swati Khandelwal**Jul 10, 2026Mobile Security / Privacy
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGJR5fh4xv_X2JER6SMxM62unaK2pucigiJwiE69bCR9n3fgVMqlH2zWpTsmiy4d936R46czjNmkAjDpU7yZgPMl6KFp7phz3kQ9sO1XaE3JHMW0VCUtwN3_zOqOcUfKdbJTJjWjahA44NPMXMif0JqnO_kzJDfuHT0HJvtOlndAvheFqNrpviHXVQ_DIb/s1700-e365/android-vpn-security.jpg)
Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics people install a VPN for, i.e., keeping their traffic private and secure.

The apps flagged with at least one problem have been installed more than 2.4 billion times.

The problems are basic, not sophisticated. 29 apps let user traffic leak outside the encrypted tunnel, including the DNS lookups that reveal which websites you visit. 61 apps send some data in plain text that anyone watching the traffic on that network can read.

Five of those send the app's configuration file in the clear, which lets an attacker on the network redirect the connection to a server they control.

The system, called **MVPNalyzer**, was presented at the NDSS security conference in February 2026 by researchers at the University of Michigan, the University of New Mexico, and IIT Delhi.

It is a mobile counterpart to the same lab's earlier VPNalyzer study of desktop VPN software, and the researchers describe it as the first framework built to systematically and repeatedly audit Android VPN apps.

A VPN wraps your traffic in an encrypted tunnel so your internet provider, or an eavesdropper on the network, cannot see what you are doing. The trade-off is that the VPN app now sees all of it. You are not removing the need to trust someone. You are moving that trust from your internet provider to whoever built the app.

[*](https://thehackernews.uk/ai-vuln-protection-d)
The study asks whether these apps earn it. For many, they do not.

## The most serious flaw: tunnel hijacking

The worst finding involves those five apps that download their configuration file without encryption. That file tells the app which server to connect to. If it travels in plain text, an attacker on the same network, say a public Wi-Fi operator, can rewrite it in transit and point the app at a server they control.

[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgy0uf9Xbvzs8uQR1k4Eyza_1u_RG-6Nfa6k2EiqmB9TKLnO6g29yLWdKCJJ-SQeGvZRMV9nQMwQSYYF8uKJNaxRWcZJ4gIMpyJoQkUmhBbMBYaRA5N5AX0QLWPnwenRzt_ARKhTUpNyXcJkPVJwfRKhE3Y5NzsUEjkinDD64XrD2nQSHSSDB_u9B-s7s6d/s1700-e365/MVPNalyzer.jpg)Architecture of the MVPNalyzer framework
The user connects, sees the usual "connected" screen, and routes everything through the attacker. The researchers built this attack and confirmed it worked on phones under their control.

They flagged the issue for all five providers as a priority. Two responded, both promising to move the file to HTTPS. One said it would send the configuration files ["securely using HTTPS with proper certificate validation."](https://www.ndss-symposium.org/wp-content/uploads/2026-s1573-paper.pdf) The other three had not acknowledged it.

## Leaks, and apps that hide nothing

Of the 29, 24 leaked DNS traffic, exposing the sites users visited to the local network; those apps alone account for about 360 million installs. Six leaked full browsing traffic outside the tunnel, and four ran "tunnels" with no encryption at all, with some apps failing in more than one way.

Separately, 169 apps made no attempt to disguise their traffic as anything other than a VPN, so a network operator or government censor can spot and block them with basic tools. Nearly two-thirds of those apps advertise that they beat blocking or unlock restricted content. They make the promise and do nothing to keep it.

[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiaY3x8USOFkQVfHB6GVrC6nYVCkbo_NlWSKwSNcuXEwVV2FHshzGEOysqr38tE8OS888yC8146_ONZ0x6JPF2HBEnbUdzoNusx3LjOR-xPRjFn_wkNRPx7S60ouNDKW6K6PbvcQ8Tx4BLsl79RdxJw5ocBf4mkXvrwU9kM-YVYThhy42UmGkTND3sf8Ymm/s1700-e365/appss.jpg)
For someone in a country where using a VPN is itself risky, being easy to identify as a VPN user is the opposite of what they signed up for.

## Tracking, from the apps built to stop it

People often install VPNs to avoid being tracked. Many of these apps track anyway. 76 sent the device's Advertising ID, a unique code advertisers use to follow a person from one app to the next.

The study found that more than 80% of the apps, 246 of them, contacted known advertising and tracking servers. Many also sent details like the phone model, operating system version, and screen size.

On their own, those look harmless, but combined, they form a "fingerprint" that can single out one device. One app even sent the phone's exact GPS coordinates.

## Weak setups under the hood

The researchers also pulled apart the OpenVPN configuration files bundled with 108 of the apps, a separate check from the live-traffic tests above. Only one followed every security best practice the study measured.

About 89% relied on a single authentication method, either a password or a certificate, rather than combining the two. Nearly one in five used weak or outdated encryption, including the aging Blowfish cipher and triple DES. A few set the tunnel's data cipher to none, which switches off encryption entirely. Both of those old ciphers carry long-known weaknesses ([CVE-2016-6329](https://nvd.nist.gov/vuln/detail/CVE-2016-6329) and [CVE-2016-2183](https://nvd.nist.gov/vuln/detail/CVE-2016-2183)) that let an attacker recover data from long-running connections.

[*](https://thehackernews.uk/sygnia-cyber-response-d-1)
Most of these problems trace back to the same root: the apps are barely maintained, and the Play Store's automated checks let them through. Many rank among its top search results, where Google's safety labels and its ["Verified" badge for VPN apps](https://thehackernews.com/2023/11/google-play-store-introduces.html) are meant to signal trust. The study says those labels work more like marketing signals than a real security guarantee.

## This is not a one-off

Other recent research points in the same way. In August 2025, researchers at the University of Toronto's Citizen Lab and Arizona State University [found](https://citizenlab.ca/2025/08/hidden-links-analyzing-secret-families-of-vpn-apps/) that several popular Android VPN apps, with more than 700 million combined downloads, were secretly linked, shared hard-coded passwords, and quietly collected location data.

In October 2025, mobile security firm Zimperium [reported](https://zimperium.com/blog/insecure-mobile-vpns-the-hidden-danger) that three of the roughly 800 free VPN apps it tested still bundled a version of the OpenSSL library vulnerable to Heartbleed, a well-known bug patched back in 2014. Many also asked for phone permissions far beyond what a VPN needs.

The three studies tell one story: free VPN apps keep pairing a strong privacy pitch with weak engineering, and they keep reaching millions of installs before anyone catches it.

## What users can do

The most serious flaws here, the cleartext config fetch and the weak tunnel settings, are invisible from the user's side. You cannot spot them by looking at the app, which is the whole problem. So the real defense is not which protocol the app advertises. It is who is behind it.

Favor providers that publish a recent independent security audit. Be wary of free apps that bury you in ads. And treat "verified" or "no-logs" claims as a starting point, not proof.

The researchers list every flagged app in the paper's appendix, so you can check whether the one on your phone is among them.

The team plans to release MVPNalyzer publicly so app stores and regulators can run these checks themselves. On this evidence, they will have to.

The Hacker News has asked Google whether it is reviewing or removing the flagged apps, and for its response to the study's finding that Play Store safety labels and the "Verified" badge function more as marketing than security guarantees. We have also asked the MVPNalyzer research team to identify the five apps vulnerable to tunnel hijacking and to confirm whether the notified providers have since deployed fixes. This story will be updated with any response.

Found this article interesting? Follow us on [Google News](https://news.google.com/publications/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ), [Twitter](https://twitter.com/thehackersnews) and [LinkedIn](https://www.linkedin.com/company/thehackernews/) to read more exclusive content we post.

SHARE
[**](#link_share)
[**](#link_share)
[**](#link_share)
[**](javascript:void(0))

[**Tweet](#link_share)
[**Share](#link_share)
[**Share](#link_share)
**Share

[SHARE **](javascript:void(0))
[Android security](https://thehackernews.com/search/label/Android%20security), [App Security](https://thehackernews.com/search/label/App%20Security), [Data Leakage](https://thehackernews.com/search/label/Data%20Leakage), [encryption](https://thehackernews.com/search/label/encryption), [Google Play](https://thehackernews.com/search/label/Google%20Play), [mobile security](https://thehackernews.com/search/label/mobile%20security), [network security](https://thehackernews.com/search/label/network%20security), [Privacy](https://thehackernews.com/search/label/Privacy), [VPN Security](https://thehackernews.com/search/label/VPN%20Security)]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers]]></title>
            <link>https://aiheadlines.pro/news/unpatched-xring-flaw-in-xquic-lets-remote-clients-crash-http</link>
            <guid>https://aiheadlines.pro/news/unpatched-xring-flaw-in-xquic-lets-remote-clients-crash-http</guid>
            <pubDate>Sat, 11 Jul 2026 06:38:43 GMT</pubDate>
            <description><![CDATA[- 

**Swati Khandelwal**Jul 10, 2026Vulnerability / Server Security
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjQHphr7bXE4J4-EmYSWy0cjHarUBibR2JrXpFbwDKMZnsWbiUsC9UE7g3x2r8WFDLB7...]]></description>
            <content:encoded><![CDATA[- 

**Swati Khandelwal**Jul 10, 2026Vulnerability / Server Security
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjQHphr7bXE4J4-EmYSWy0cjHarUBibR2JrXpFbwDKMZnsWbiUsC9UE7g3x2r8WFDLB7BBZlH2kDJ3I9QqF8IIGLPiZda93wKUaDqJC8Nv11yrd7VPm9RmBOky0yRXGRhhcDqbwNCZvHiGTkKRb06XAwFiGl0juzUeFBn3LUDwFfxZVNlInVmXTNI4cMLI/s1700-e365/XQUIC-demo.gif)
A single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch.

FoxIO researcher Sébastien Féry [disclosed the flaw on July 8](https://foxio.io/blog/xring-crashing-xquic-with-spec-compliant-qpack-instructions) and nicknamed it XRING. He says it needs no login and no malformed packets: about 260 bytes of ordinary QPACK traffic takes the server process down.

XQUIC is open-source, so the risk is not Alibaba's alone: any server that embeds it and serves HTTP/3 with the default QPACK settings is exposed. That includes Tengine, Alibaba's Nginx-based web server, which FoxIO says fronts the company's cloud and CDN on sites including Taobao and Alipay.

Every release through v1.9.4, the latest, is affected. There is no fixed release and no CVE as of July 10. Until a fix ships, operators can set SETTINGS_QPACK_MAX_TABLE_CAPACITY to 0, which turns off QPACK's dynamic table, or drop HTTP/3 support entirely.

The bug lives in how HTTP/3 compresses headers. To avoid sending the same header (say, user-agent) over and over, HTTP/3 uses QPACK. It keeps a shared table that the client directs the server to build up and resize through a dedicated control channel, the encoder stream.

[*](https://thehackernews.uk/ai-vuln-protection-d)
XQUIC stores that table's bytes in a [ring buffer](https://github.com/alibaba/xquic/blob/main/src/common/utils/ringmem/xqc_ring_mem.c), a fixed block of memory where data wraps from the end back to the start once it fills.

When the client asks to grow the table, XQUIC allocates a bigger buffer and copies the old data across. That copy has four cases, depending on whether the data wraps in the old buffer, the new one, both, or neither. In one of them, the code sizes the leftover tail data against the new, larger buffer's capacity instead of the old one's. It overcounts badly.

Grow a 64-byte table with the write cursor near the end, and resize to 65, and XQUIC decides there are 70 tail bytes to move when there are really 6.

That wrong number flows into a memory copy. The copy length comes from subtracting the overcount from a smaller value. Because that length is an unsigned size_t, it underflows and wraps to a near-maximum number, and the copy runs off the end of memory.

[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixV1_6IK3fCzhiZyzdBFm-3_r_D-Iy8F9ekwLsUvYBiZuvrN_gOs6mexzZHBPD7Cor6lupMIYWI5fINt937kxfc0NLI1vNUZr50aX-LloAEsBD8DTiyFTnnIc5vEOtfkeKppX8CSuR8URBCuyK8oVYd7DcpJK9y5uj_TvZwF92noAOyChF3H3GiIXkHi0/s1700-e365/qpack.jpg)
In FoxIO's release build on Ubuntu 26.04, glibc's _FORTIFY_SOURCE=2 caught the bad length and killed the process. Without that check, the copy writes out of bounds, from the old buffer past the end of the new one. Féry showed a crash but did not test whether that corruption could be exploited further.

None of the values in the attack breaks QPACK's rules. XQUIC advertises a 16 KiB dynamic-table limit by default; the payload asks for 64 bytes, then 65. The client only has to drive the table into the exact wrapped layout that hits the faulty branch. FoxIO says the mistake has been in XQUIC since its first public release in January 2022, and a proof of concept is [public](https://github.com/FoxIO-LLC/xring-poc).

XRING is the latest in a string of remote crashes in HTTP/2 and HTTP/3 stacks. Three weeks earlier, THN reported a [use-after-free in NGINX's HTTP/3 module](https://thehackernews.com/2026/06/f5-patches-two-critical-nginx-open.html) (CVE-2026-42530) that a remote, unauthenticated client could reach through the same QPACK encoder stream XRING abuses, a different bug class on the same attack surface.

[*](https://thehackernews.uk/sygnia-cyber-response-d-1)
In June, Calif's [HTTP/2 Bomb](https://thehackernews.com/2026/06/new-http2-bomb-vulnerability-allows.html) caused remote denial of service against Nginx, Apache, IIS, and Envoy by abusing HPACK, HTTP/2's header compression, and the predecessor to QPACK.

In February, HAProxy [patched two QUIC crashes](https://www.haproxy.com/blog/cves-2026-quic-denial-of-service), one an integer underflow during token validation, the same type of bug behind XRING, though it needed a malformed packet where XRING needs none. That difference is the point: legal input, one arithmetic slip, a dead server.

FoxIO demonstrated a crash, not code execution, and reported no exploitation in the wild. It says it emailed Alibaba on April 7 through the project's security policy, which promises a reply within three working days, then followed up four more times through May 9 without an answer before going public.

The Hacker News has asked Alibaba whether a fix and a CVE are coming, and whether FoxIO's five disclosure attempts reached its security team. It has asked FoxIO whether the flaw has been exploited in the wild and whether the underlying heap write can be pushed past a crash. The story will be updated with any response.

Found this article interesting? Follow us on [Google News](https://news.google.com/publications/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ), [Twitter](https://twitter.com/thehackersnews) and [LinkedIn](https://www.linkedin.com/company/thehackernews/) to read more exclusive content we post.

SHARE
[**](#link_share)
[**](#link_share)
[**](#link_share)
[**](javascript:void(0))

[**Tweet](#link_share)
[**Share](#link_share)
[**Share](#link_share)
**Share

[SHARE **](javascript:void(0))
[Application Security](https://thehackernews.com/search/label/Application%20Security), [Cloud security](https://thehackernews.com/search/label/Cloud%20security), [denial of service](https://thehackernews.com/search/label/denial%20of%20service), [network security](https://thehackernews.com/search/label/network%20security), [Open Source](https://thehackernews.com/search/label/Open%20Source), [Patch Management](https://thehackernews.com/search/label/Patch%20Management), [server security](https://thehackernews.com/search/label/server%20security), [Vulnerability](https://thehackernews.com/search/label/Vulnerability), [Web Security](https://thehackernews.com/search/label/Web%20Security)]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic]]></title>
            <link>https://aiheadlines.pro/news/new-modbeacon-rat-uses-grpc-streaming-for-encrypted-c2-traff</link>
            <guid>https://aiheadlines.pro/news/new-modbeacon-rat-uses-grpc-streaming-for-encrypted-c2-traff</guid>
            <pubDate>Sat, 11 Jul 2026 06:38:41 GMT</pubDate>
            <description><![CDATA[- 

**Ravie Lakshmanan**Jul 10, 2026Malware / Enterprise Security
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKTCUzhkUq2Y7DPv0yS2FatrHQTcHfupRly6f5kSWyQU-So3FOjpC8pt_VKR4qo1SoUGR...]]></description>
            <content:encoded><![CDATA[- 

**Ravie Lakshmanan**Jul 10, 2026Malware / Enterprise Security
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKTCUzhkUq2Y7DPv0yS2FatrHQTcHfupRly6f5kSWyQU-So3FOjpC8pt_VKR4qo1SoUGR65ycOEQonbW5heKWj1g_A8qDy69YtWGZDO4m2t46Sip-jdPAlNs2fpRj-w1yd8WpyJpNFUpj1iTBO0X6fy3n9DJ4aEdsWaQz_tN-VV-PxDrufKZR9wkznmXJQ/s1700-e365/MODBEACON.jpg)
The China-linked cybercrime group known as **[Silver Fox](https://thehackernews.com/2026/07/suspected-china-nexus-hackers-use-fake.html)** has been attributed to a new Rust-based remote access trojan (RAR) called **MODBEACON**.

Chinese cybersecurity company QiAnXin said that while the threat cluster may appear like a low-sophistication, high-activity operation that propagates malware via counterfeit installers using SEO poisoning techniques, it belies their [true organizational structure](https://thehackernews.com/2025/09/silver-fox-exploits-microsoft-signed.html), which compromises multiple distributors.

"These distributors conduct activities across Asia using counterfeit software installers distributed through SEO campaigns, leveraging variants of Gh0st RAT and WinOS (ValleyRAT) trojan families," QiAnXin [said](https://ti.qianxin.com/blog/articles/operation-phnom-penh-silverfox-ghost-distributor-targets-specific-victims-with-modbeacon-en/).

One such campaign observed in mid-June 2026 involved a distributor delivering a previously undocumented modular RAT targeting technology, education, and state-owned enterprises in the country. MODBEACON's requested command-and-control (C2) infrastructure is hosted on Amazon and Cloudflare's Content Delivery Network (CDN).

[*](https://thehackernews.uk/ai-vuln-protection-d)
The distributor is assessed to be a hybrid threat actor, acting as a composite of "cybercriminal arms dealer" and "traffic broker." One arm of its operations involves expanding its infection footprint across Asia through daily SEO operations for fraud business, while the other focuses on propagating advanced trojans, or renting high-value access to downstream customers, or establishing "criminal-on-criminal" schemes targeting the Cambodian gambling sector.

The newly discovered campaign combines social engineering, custom malware, and post-compromise tooling to establish long-term access while minimizing detection on infected hosts. The memory-resident malware functions as a remote implant capable of fetching additional modules, running operator commands, and maintaining encrypted communications with attacker infrastructure.

[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwAzKrmZ3t5tWfoBOn9nGVogfS5gMgnKK2YZcRl5VV33zCax0-xBlkeuYaShQezBelYRCOkjFtGhPk4shpXRBmLzMJp67KtLWQVchV_vRYzn7Wv2vXfd_zHBfVyTdVIjD7UyXTdnKcDYWTi7xn8MVdlBKBljrBgHByLxemMTPVTRAY8Qk0OIQ5Zf22tRm0/s1700-e365/code-exe.png)
"The Trojan is a professional and private C2 framework: the loader and beacon are separated, the configuration is injectable, the beacon employs a plugin-based architecture (native-v3 plugins with entry/init/fini RVA), and it uses gRPC tunnel streaming for communication," QiAnXin explained. "The overall engineering quality is high. Its core highlight is the reuse of the transport layer from an open-source anti-censorship proxy framework (Xray/V2Ray) as its C2 channel."

Like previous campaigns attributed to the Silver Fox intrusion ecosystem, the attack chain uses counterfeit domains advertising bogus installers for popular domestic software as lures to trick unsuspecting users into downloading malicious ZIP archives responsible for deploying the malware.

[*](https://thehackernews.uk/sygnia-cyber-response-d-2)
The core capabilities of MODBEACON include -

 - Fingerprinting the host

 - Loading plugins in memory

 - Sending heartbeat messages

 - Reporting the results of command execution

 - Setting persistence using scheduled tasks

"This capability can be used for subsequent on-demand expansion of information theft, lateral movement, proxy forwarding, or other payloads," QiAnXin said.

The disclosure comes amid a gradual broadening of Silver Fox's arsenal, which has deployed malware families tracked as [Atlas RAT](https://thehackernews.com/2026/03/silver-fox-expands-asia-cyber-campaign.html), [ABCDoor](https://thehackernews.com/2026/05/silver-fox-deploys-abcdoor-malware-via.html), [RomulusLoader, and SilentRunLoader](https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html), indicating that the threat actor is actively refining its tradecraft.

Found this article interesting? Follow us on [Google News](https://news.google.com/publications/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ), [Twitter](https://twitter.com/thehackersnews) and [LinkedIn](https://www.linkedin.com/company/thehackernews/) to read more exclusive content we post.

SHARE
[**](#link_share)
[**](#link_share)
[**](#link_share)
[**](javascript:void(0))

[**Tweet](#link_share)
[**Share](#link_share)
[**Share](#link_share)
**Share

[SHARE **](javascript:void(0))
[Cloud security](https://thehackernews.com/search/label/Cloud%20security), [Cybercrime](https://thehackernews.com/search/label/Cybercrime), [enterprise security](https://thehackernews.com/search/label/enterprise%20security), [Malware](https://thehackernews.com/search/label/Malware), [Remote Access Trojan](https://thehackernews.com/search/label/Remote%20Access%20Trojan), [SEO poisoning](https://thehackernews.com/search/label/SEO%20poisoning), [Social Engineering](https://thehackernews.com/search/label/Social%20Engineering), [Supply Chain Security](https://thehackernews.com/search/label/Supply%20Chain%20Security), [Windows Security](https://thehackernews.com/search/label/Windows%20Security)]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws]]></title>
            <link>https://aiheadlines.pro/news/researcher-details-whatsapp-to-host-attack-chain-using-three</link>
            <guid>https://aiheadlines.pro/news/researcher-details-whatsapp-to-host-attack-chain-using-three</guid>
            <pubDate>Sat, 11 Jul 2026 06:38:38 GMT</pubDate>
            <description><![CDATA[- 

**Ravie Lakshmanan**Jul 10, 2026AI Security / Vulnerability
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgs80_SEcGa8Q18LOUd4Y3fWiWZRh6MOX6U3LhAyAVVewqJVSd1cq2bgepE_2vS0eg9qvr0i...]]></description>
            <content:encoded><![CDATA[- 

**Ravie Lakshmanan**Jul 10, 2026AI Security / Vulnerability
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgs80_SEcGa8Q18LOUd4Y3fWiWZRh6MOX6U3LhAyAVVewqJVSd1cq2bgepE_2vS0eg9qvr0iM1JOYnYd9GPDQ-LZiTP4-J8oEpZjAMc2ivQ9QiNTMbf1BYONSvBOvZaVat_1PUWjM9O72K_pdF74UKhHm-dd-wXKLp8BDoV4dQZTi1HWOUCWbozpd4muH0i/s1700-e365/openclaw-whatsapp.jpg)
Details have emerged about three now-patched [security flaws](https://github.com/jgamblin/OpenClawCVEs/) in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host.

A brief description of the high-severity vulnerabilities is as follows -

 - **[GHSA-hjr6-g723-hmfm](https://github.com/openclaw/openclaw/security/advisories/GHSA-hjr6-g723-hmfm)** (CVSS score: 8.8) - An operating system command injection and an incomplete list of disallowed inputs vulnerability impacting the host execution environment filtering mechanism that could allow for executing or persist actions beyond the caller's intended authorization.

 - **[GHSA-9969-8g9h-rxwm](https://github.com/openclaw/openclaw/security/advisories/GHSA-9969-8g9h-rxwm)** (CVSS score: 8.8) - An operating system command injection and an incomplete list of disallowed inputs vulnerability impacting the host execution environment filtering mechanism that could allow for executing or persist actions beyond the caller's intended authorization.

 - **[GHSA-575v-8hfq-m3mc](https://github.com/openclaw/openclaw/security/advisories/GHSA-575v-8hfq-m3mc)** (CVSS score: 8.4) - A path traversal and link following vulnerability that could allow [sandbox bind mounts](https://arxiv.org/abs/2603.27517) to bypass parent-directory denylist checks and perform actions that should have been secured with stronger authorization or policy checks.

All three shortcomings have been addressed in OpenClaw version 2026.6.6.

[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7pp31YSx7YW04s7vxzEYFYsk_y-4ncrMNOtkTw28tuuYW4vjWPb7P9mAe1Ubpa1OPfMIe-nIE6QxtkBjL4J4gvNFanwEZhtdtDuOApElzQf863NGWbHs6CKe6elnjDZXDKA0jiWQfjDoPYamSHzrfpcy11qEMoIbR6iDsq4hAf2REYGHRZYIiZQ1TgF39/s1700-e365/open.jpg)
In a series of advisories released last week, OpenClaw maintainers said "practical impact depends on the operator's configuration and whether lower-trust input can reach that path."

However, security researcher Chinmohan Nayak, who is credited with discovering and reporting the issues, said in a [report](https://medium.com/@chinmohannayak/i-sent-a-whatsapp-message-to-an-ai-agent-it-ran-my-code-on-the-host-adbbcbb0e0ad) shared with The Hacker News that they can be used to trigger host code execution from an external message sent via WhatsApp.

[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEju3jGYADeL_1dA8qwtLpzzGKgBpklCfIGmjeMoJlxtlSMdez1q7uss-H9gaBSiqYtSHQjOCbKLifZxOe6GCWnueNFLZKR6pyYKfkc7kZWWQQXm_E7Wi9IH2E-SfActpcfBBZm_-aX4pVUmKslXQIZ1z4hwq8WX0JFdMxcFVRNAll_-n6Fj0a1Fi9MKMkK5/s1700-e365/whatsapp-ai.jpg)
Unlike the [Claw Chain](https://thehackernews.com/2026/05/four-openclaw-flaws-enable-data-theft.html) vulnerabilities disclosed by Cyera back in May, the newly identified bugs do not require an attacker to establish a prior foothold in order to extract sensitive data, drop a persistent backdoor, obtain arbitrary remote code execution, and facilitate an escape to the host.

"`getBlockedReasonForSourcePath()` checks if the source path is under a blocked path," the researcher explained about GHSA-575v-8hfq-m3mc. "But [it] never checks the reverse — whether a blocked path is under the source (parent directory bypass)."

[*](https://thehackernews.uk/ai-vuln-protection-d)
Specifically, the bind mount denylist blocks directories like "~/.ssh," "~/.aws," and "~/.gnupg,” but allows mounting the parent directory "/home" or "/var," effectively undermining the individual blocks.

"Mount /home into your container, and you can read every user's SSH keys, AWS credentials, and GPG secrets," Nayak said. "Mount /var and you get the Docker socket – which means full host escape from inside the 'sandbox.'"

Besides updating OpenClaw to the latest version, it's advised to enable sandbox mode for all non-main sessions, remove "exec" from the tool allowlist for channel-facing agents, and monitor for git clone commands containing the "ext::" external protocol helper that could be abused to run arbitrary system commands.

"Before upgrading, restrict the affected feature to trusted operators or disable it when it is not needed," OpenClaw said. "As general hardening, keep channel and tool allowlists narrow, avoid sharing one Gateway between mutually untrusted users, and disable the affected feature when it is not needed."

Found this article interesting? Follow us on [Google News](https://news.google.com/publications/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ), [Twitter](https://twitter.com/thehackersnews) and [LinkedIn](https://www.linkedin.com/company/thehackernews/) to read more exclusive content we post.

SHARE
[**](#link_share)
[**](#link_share)
[**](#link_share)
[**](javascript:void(0))

[**Tweet](#link_share)
[**Share](#link_share)
[**Share](#link_share)
**Share

[SHARE **](javascript:void(0))
[AI Security](https://thehackernews.com/search/label/AI%20Security), [Application Security](https://thehackernews.com/search/label/Application%20Security), [Code Execution](https://thehackernews.com/search/label/Code%20Execution), [Container Security](https://thehackernews.com/search/label/Container%20Security), [Messaging Security](https://thehackernews.com/search/label/Messaging%20Security), [Open Source](https://thehackernews.com/search/label/Open%20Source), [privilege escalation](https://thehackernews.com/search/label/privilege%20escalation), [Sandbox Escape](https://thehackernews.com/search/label/Sandbox%20Escape), [Vulnerability](https://thehackernews.com/search/label/Vulnerability)]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched]]></title>
            <link>https://aiheadlines.pro/news/laser-attack-resets-tangem-wallet-passwords-on-cards-that-ca</link>
            <guid>https://aiheadlines.pro/news/laser-attack-resets-tangem-wallet-passwords-on-cards-that-ca</guid>
            <pubDate>Sat, 11 Jul 2026 06:38:35 GMT</pubDate>
            <description><![CDATA[- 

**Swati Khandelwal**Jul 10, 2026Vulnerability / Hardware Security
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0BbJcQ3TUJxFvOCpAChyC5saD3RGgDCtLtVG-Wupee7poBksO2TzSWFtzQmjjoXu...]]></description>
            <content:encoded><![CDATA[- 

**Swati Khandelwal**Jul 10, 2026Vulnerability / Hardware Security
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0BbJcQ3TUJxFvOCpAChyC5saD3RGgDCtLtVG-Wupee7poBksO2TzSWFtzQmjjoXuZ-9hnCNR3HuWdSsBv7YZl477fdOcjoOBh72RY4vJ9R0hxUWktV2R7wgTsRa-_Zz5Bj_ZGfQOVT8v292QJ55C9hMumk-IgXd-PVZ6LFu2ZDyCGwjNtJhCYb4W-mPDO/s1700-e365/ll.jpg)
Researchers at **Ledger's Donjon security team** have shown that a precisely timed laser pulse, aimed at the chip inside a **Tangem **crypto wallet card, can reset the card's password to anything the attacker picks.

No old password. No backup card. Once it is reset, whoever did it controls the wallet and can move the coins out.

This is not an emergency for most owners. The attack needs the physical card in hand and a lab that Donjon puts at around $250,000. It also means cutting the card open, which leaves damage no one can miss. It cannot be done over the internet, and there is no fix coming: Tangem cards cannot take software updates, so every card already sold carries the flaw.

The one group that should act now is anyone whose card is lost or stolen and holds serious value.

## How the card is meant to protect you

A Tangem wallet looks like a plain bank card. Tap it to your phone, and a companion app talks to a Samsung S3D232A chip inside. That chip is a secure element, built to resist tampering and certified to a high grade called EAL6+.

[*](https://thehackernews.uk/ai-vuln-protection-d)
It holds the secret key that controls your crypto and never lets it out. Two things are meant to stand between a thief and your money: holding the card and knowing the password.

The weak point is the password reset feature. Tangem sells its cards in linked sets, and if you forget your password, you can set a new one by holding two of your cards together. Deep inside that process, the card runs a single check: is this card in recovery mode? If yes, it accepts a new password without asking for the old one.

A laser pulse fired at the chip at the exact moment it runs that check does not quietly rewrite a stored value. It briefly disturbs the chip's own circuitry, so the check misfires and the card behaves as if it were in recovery mode when it is not.

[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9utbDi4AC6trfMxi55y1ePtHrVUgQ0x3FFT_qZBat3geUfwd86b2JemyGnkdQZe83U2jvCCLQ_64708RjgIKJLnn0w_rrwR8PA53ysZsgcGHGeLWlJ_RMnosW7Tuyh6lrss_Gv0ZyI3Jg1mqoNS0ilSedkA6quK-RdgRrA_bJZwyetOFa4BOnEOHRkYFl/s1700-e365/laaser-flow.png)
With the check defeated, the card's ordinary SetPin command accepts a brand-new password: no old password, no second card, no recovery step. Turning the recovery feature off does not help, because the same check still runs on every card.

## Hard to do, and unfixable

None of this is easy. It took a laser rig, sensitive measuring gear, deep hardware skill, and a long stretch of up-front work to map the chip and find the exact spot and timing. The card has to be cut open and its chip exposed, which leaves obvious damage.

There is no doing this quietly and slipping the card back into a pocket. [Donjon reports](https://donjon.ledger.com/blog/bypassing-tangem-card-security-with-laser-attack/) that once the settings were locked in, the attack worked on every card it tried, at about two hours each. The team reported the flaw to Tangem on February 10, 2026.

[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHkgKEcO0Gmst3f3dNnKIzr1TngAXoqD4U0pZ8MiNV3anl48355NEkvAnFa9sRAJQgI9sVU63NqZoyulRweNx-QzErvw5r14uRieO_7q10eYBGH5hZBNBsLo9JVwT_0I9Ncshwp2QE7n7wzcGliUrQ6261gDmZfATZdkPxEDkzxfPJ7YDhIEwxiHaVp7cp/s1700-e365/laaser-1.jpg)
The bigger problem is permanence. Tangem builds its cards with no way to update the firmware, and presents that as a security feature: nothing can be changed, so nothing can be tampered with from a distance. Here, that same design cuts the other way, leaving a flaw in the code that can never be corrected.

As the researchers put it, "there's no patch, but the attack is physical and invasive", so it cannot be done remotely.

## What Tangem says

Tangem pushed back. In a [public response](https://tangem.com/en/blog/post/lfi-response/), the company called this a lab-only physical method that works against secure element chips in general, not something unique to its cards. It also noted that Donjon belongs to **Ledger**, one of its biggest rivals.

Its sharpest point is about money: a Tangem card carries nothing that says who owns it or how much it holds, so an attacker who spends $250,000 and wrecks cards to tune the attack has no way to tell whether a stolen card is worth $50 or $50 million. Tangem also says no one has lost funds to a laser attack on any hardware wallet so far, and that for everyday users, "the practical risk is virtually non-existent."

Both sides are partly right. Donjon researchers are right that the flaw is real, sits in every card, and can never be patched. Tangem is right that for almost everyone, the cost, the ruined cards, and the guesswork over what a card holds make it pointless.

The place they actually meet is narrow: a lost, stolen, or seized card that an attacker already has reason to think is worth the trouble.

## Not the first wallet chip broken this way

This is not Donjon's only laser attack on a hardware wallet this year. In early June, Trezor and its chip partner Tropic Square [disclosed](https://trezor.io/blog/news/Trezor-response-TROPIC01-chip-disclosure-no-impact-to-your-funds) a related result: Donjon used the same technique, laser fault injection, on the TROPIC01 chip in the new Trezor Safe 7.

This time, it slipped past the chip's firmware signature check to run its own code. Trezor said funds stayed safe because the Safe 7 stacks three separate security layers, and the layer guarding the PIN held firm. Unlike Tangem, Trezor, and Tropic Square, which could respond: they shipped a stopgap for current chips and are hardening the next version of the silicon.

[*](https://thehackernews.uk/sygnia-cyber-response-d-1)
Cheaper attacks on wallets go back further, but they hit softer targets. Years ago, this same team pulled the recovery seed straight off a stolen [Trezor One or Trezor T](https://www.ledger.com/blog/unfixable-key-extraction-attack-on-trezor) with a rig costing about $100, because those wallets guarded their secrets with an ordinary microcontroller and no secure element.

Tangem's hardened chip is the difference: it is why the same sort of physical attack now needs a quarter-million-dollar lab. It raises the bar; this research shows it does not remove the danger. And a grade like EAL6+ only vouches for the chip and its built-in defenses, not the code a wallet maker layers on top, which is where this flaw lives.

It is also Donjon's third finding on Tangem. An [Android app bypass](https://www.ledger.com/tangem-genuine-check-bypass-on-android-application) could be patched, because it was in the software Tangem controls. But this laser attack and a [password brute-force method](https://www.ledger.com/blog-brute-force-attack-tangem) found earlier both sit in the card's firmware, which can never be changed.

## What to do

For almost everyone, the answer is nothing new: keep the card where a thief cannot get to it. This attack cannot reach a card you still hold. If a Tangem card is lost or stolen and you are guarding serious value, move the funds now, using another card in your set (or a seed phrase, if you set one up), and stop relying on the password to protect a card you no longer control.

Found this article interesting? Follow us on [Google News](https://news.google.com/publications/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ), [Twitter](https://twitter.com/thehackersnews) and [LinkedIn](https://www.linkedin.com/company/thehackernews/) to read more exclusive content we post.

SHARE
[**](#link_share)
[**](#link_share)
[**](#link_share)
[**](javascript:void(0))

[**Tweet](#link_share)
[**Share](#link_share)
[**Share](#link_share)
**Share

[SHARE **](javascript:void(0))
[cryptocurrency](https://thehackernews.com/search/label/cryptocurrency), [cybersecurity](https://thehackernews.com/search/label/cybersecurity), [Embedded Security](https://thehackernews.com/search/label/Embedded%20Security), [Firmware Security](https://thehackernews.com/search/label/Firmware%20Security), [hardware security](https://thehackernews.com/search/label/hardware%20security), [password security](https://thehackernews.com/search/label/password%20security), [Physical Security](https://thehackernews.com/search/label/Physical%20Security), [Vulnerability](https://thehackernews.com/search/label/Vulnerability)]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot]]></title>
            <link>https://aiheadlines.pro/news/six-new-u-boot-flaws-could-let-malicious-images-crash-device</link>
            <guid>https://aiheadlines.pro/news/six-new-u-boot-flaws-could-let-malicious-images-crash-device</guid>
            <pubDate>Sat, 11 Jul 2026 06:38:32 GMT</pubDate>
            <description><![CDATA[- 

**Swati Khandelwal**Jul 10, 2026Firmware Security / Vulnerability
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihuE5rUYRadx5Q2auJjv9dVeFNIP8XSwSTaH0PDwGLUA54MXlPy3AyI532a8OnhXa...]]></description>
            <content:encoded><![CDATA[- 

**Swati Khandelwal**Jul 10, 2026Firmware Security / Vulnerability
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihuE5rUYRadx5Q2auJjv9dVeFNIP8XSwSTaH0PDwGLUA54MXlPy3AyI532a8OnhXadtWnCCH30qvUKW9C3rCOu1LPld1or5_lXwNhRVqbohHNInDzNd1f9E77Sox5yB-ir7H69LmlYRKnoqnFASOMFa2TIK2RfTThJvu_oofIXHCpiRbXGXWy-bquBWsw/s1700-e365/bootloader.gif)
Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center servers.

Four of the bugs can crash a device. The other two could let an attacker who slips a malicious image in front of the bootloader run their own code, before the device has confirmed that the software is genuine.

That last part is the point. A bootloader runs before the operating system, so a flaw here can undermine everything that loads after it. All six bugs are reached while U-Boot is still reading an untrusted image, before it has checked the signature.

## What Binarly found

U-Boot can bundle a kernel, device tree, ramdisk, and other boot components into one package, a FIT (Flattened Image Tree), and it checks that package's digital signature before handing over control.

Binarly went looking for weak spots in that check and found six. Most of the vulnerable code has been in U-Boot since v2013.07, [Binarly says](https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification), across more than 50 stable releases, and it also lives in the many vendor firmwares built on top of U-Boot.

The bugs are tracked as Binarly advisories [BRLY-2026-037 through BRLY-2026-042](https://www.binarly.io/advisories). No CVE identifiers have been assigned yet. They fall into two groups: two that could run code, and four that only crash.

[*](https://thehackernews.uk/ai-vuln-protection-d)
The two are BRLY-2026-037 and BRLY-2026-038, and both trace to one unchecked value. U-Boot calls fdt_get_name, a lookup in the device-tree parsing library it borrows, and on a malformed image, that lookup returns a null pointer and a negative length. U-Boot uses both without checking either.

One bug follows the null pointer into a memory copy that, on devices where address zero is mapped, becomes a stack buffer overflow. The other feeds the negative length into pointer arithmetic that walks backward until it overwrites a saved return address. In the right memory layout, either one can hand control to code the attacker-supplied.

The other four only crash the bootloader. BRLY-2026-039 and BRLY-2026-041 read past the end of the image by trusting a size or offset that the attacker controls. BRLY-2026-040 dereferences a null pointer that an older image format hands back unchecked. BRLY-2026-042 exhausts the stack, set off by a deeply nested image that drives an early validation step to call itself until it runs out.

Binarly published a proof-of-concept image and reproduction steps for each flaw and demonstrated them against standard U-Boot builds. No exploitation in real attacks has been reported.

Of the six, the two memory-corruption bugs are the ones to prioritize: a crash can knock a device offline, but code execution at boot could subvert its entire chain of trust.

## How bad it gets

In the worst case, recovering a device that will not boot means physical access and reflashing its memory chip with a clean image. Code execution is worse. Code that runs this early sits below the operating system, where ordinary security tools may not see it.

The catch for an attacker is delivery: these bugs only bite once a malicious image reaches the boot path, which usually takes physical access or a privileged foothold. That foothold is not always local.

In [earlier work](https://thehackernews.com/2025/09/two-new-supermicro-bmc-bugs-allow.html) on Supermicro's server management controllers, the same Binarly researcher showed that an attacker with remote access to the management interface could abuse the device's own update process to flash a malicious image, without touching the hardware.

## What to do

There is no stable release with the fix yet, so vendors and maintainers of U-Boot-based products should not wait: pull the upstream fixes now, following the commit links in each Binarly advisory, and track them by advisory ID, since no CVEs exist.

U-Boot merged the six patches in June, but the July release (v2026.07) had already frozen in April, so it shipped without them; the next release, v2026.10, is not due until October.

[*](https://thehackernews.uk/sygnia-cyber-response-d-1)
Everyone else runs a device someone else built on U-Boot. For them, the fix has to arrive as a firmware update from the product vendor. That is what to watch for.

This exact check has failed before. The same signature logic was hit months earlier by [CVE-2026-33243](https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241), which U-Boot patched in April; the related barebox bootloader, which uses the same image tooling, was hit too.

In that bug, a property meant only to list what the signature covers was not itself signed, so a tampered image could swap in parts that were never verified. The helper behind the two worst bugs here, fdt_get_name, comes from libfdt, the flattened-device-tree library U-Boot shares with the Linux kernel, barebox, and others. The same unchecked-return mistake can surface anywhere that code is used.

[LogoFAIL](https://thehackernews.com/2023/12/logofail-uefi-vulnerabilities-expose.html), which THN covered in 2023, was a set of image-parsing bugs in PC firmware that let attacker code run during boot, before Secure Boot could check anything, across nearly every major PC brand. The signature gets all the attention; the bugs keep landing in the plumbing that runs before it.

And as [BootHole](https://thehackernews.com/2020/07/grub2-bootloader-vulnerability.html) showed in 2020, when one bootloader flaw broke Secure Boot across the ecosystem, writing the patch is the easy part. The slow part is getting it onto the millions of devices running someone else's copy of U-Boot.

Found this article interesting? Follow us on [Google News](https://news.google.com/publications/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ), [Twitter](https://twitter.com/thehackersnews) and [LinkedIn](https://www.linkedin.com/company/thehackernews/) to read more exclusive content we post.

SHARE
[**](#link_share)
[**](#link_share)
[**](#link_share)
[**](javascript:void(0))

[**Tweet](#link_share)
[**Share](#link_share)
[**Share](#link_share)
**Share

[SHARE **](javascript:void(0))
[Bootloader Security](https://thehackernews.com/search/label/Bootloader%20Security), [Code Execution](https://thehackernews.com/search/label/Code%20Execution), [denial of service](https://thehackernews.com/search/label/denial%20of%20service), [Embedded Security](https://thehackernews.com/search/label/Embedded%20Security), [Firmware Security](https://thehackernews.com/search/label/Firmware%20Security), [iot security](https://thehackernews.com/search/label/iot%20security), [Memory Corruption](https://thehackernews.com/search/label/Memory%20Corruption), [Secure Boot](https://thehackernews.com/search/label/Secure%20Boot), [server security](https://thehackernews.com/search/label/server%20security), [Vulnerability](https://thehackernews.com/search/label/Vulnerability)]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages]]></title>
            <link>https://aiheadlines.pro/news/injective-labs-github-compromise-pushes-wallet-key-stealing-</link>
            <guid>https://aiheadlines.pro/news/injective-labs-github-compromise-pushes-wallet-key-stealing-</guid>
            <pubDate>Sat, 11 Jul 2026 06:38:29 GMT</pubDate>
            <description><![CDATA[- 

**Ravie Lakshmanan**Jul 10, 2026Software Supply Chain / Malware
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTNxzPo9jxkW3GuuZLBgtPOrG3vZ3va6E710jDJu_JF0jCpyQ1JTpymdVwdSH2VHL6-...]]></description>
            <content:encoded><![CDATA[- 

**Ravie Lakshmanan**Jul 10, 2026Software Supply Chain / Malware
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTNxzPo9jxkW3GuuZLBgtPOrG3vZ3va6E710jDJu_JF0jCpyQ1JTpymdVwdSH2VHL6-Ib6YLInvKsuNwgFJxna1nvDhwKMZ_hycTik5OgQniZei2FQ59-F3s80lsnPmhQ1aJsr7qIWWrf63V0AtHQxd_1Nlk6LkVEheoN5lRYH8aTeBoJ-kM1-bOjUgAwa/s1700-e365/npm-malware-2.jpg)
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases.

The compromised version, **@injectivelabs/sdk-ts@1.20.21**, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was released on July 8, 2026, but has since been [deprecated](https://x.com/ericinjective/status/2075223896660353242) on the registry. That said, the release artifacts belonging to the compromised version are [still available](https://github.com/InjectiveLabs/injective-ts/releases/tag/v1.20.21) for download from GitHub as of writing.

"The malicious functionality was introduced to the project's official GitHub repository through commits submitted by a GitHub account belonging to a developer with an established history of contributions to the repository," Socket [said](https://socket.dev/blog/compromised-injective-sdk-npm-package).

[*](https://thehackernews.uk/ai-vuln-protection-d)
The software supply chain security firm said the threat actor behind the attack also published version 1.20.21 across 17 additional @injectivelabs scoped packages that depended on and pinned the malicious SDK version, thereby putting transitive users who may not have installed the library directly. This includes -

 - @injectivelabs/utils

 - @injectivelabs/networks

 - @injectivelabs/ts-types

 - @injectivelabs/exceptions

 - @injectivelabs/wallet-base

 - @injectivelabs/wallet-core

 - @injectivelabs/wallet-cosmos

 - @injectivelabs/wallet-private-key

 - @injectivelabs/wallet-evm

 - @injectivelabs/wallet-trezor

 - @injectivelabs/wallet-cosmostation

 - @injectivelabs/wallet-ledger

 - @injectivelabs/wallet-wallet-connect

 - @injectivelabs/wallet-magic

 - @injectivelabs/wallet-strategy

 - @injectivelabs/wallet-turnkey

 - @injectivelabs/wallet-cosmos-strategy

The malware present within the package is fairly simple and straightforward, which gets triggered when the library functionality is used by an unsuspecting developer. By avoiding lifecycle scripts and not launching it during the installation phase, it helps the malware fly under the radar.

Specifically, the poisoned version has been found to modify legitimate functions used in workflows to generate private keys by invoking a "trackKeyDerivation()" function under the guise of collecting anonymized usage metrics for SDK optimization.

[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEinGr4vdIX3z6lY9KP42k9TMLnc0pORZrrsNQFgJm-4NLj8snsjhNkAZU9ifYvyc6CvfmvNbFPZbsMJvxfRwqXoB00dxtrY8vdoujm-G-3qRT4Ap6qdvkqrmkgQRtiEGkPLXgLDqb4FulcCFqtHD2Er3YS1lK2aTg-dukWAXp6fwmk4da4VZAuG4NMxCTDf/s1700-e365/npm-2.jpg)
"Tracks which key derivation methods are used (hex vs mnemonic) and derives timing patterns to help the SDK team identify performance bottlenecks and understand adoption of different key formats across the ecosystem," reads the description of the supposed telemetry function. "All metrics are fire-and-forget and never block or affect key derivation."

According to Socket, parameters passed to the function include a hard-coded marker describing the method used to generate the private key and the actual sensitive information needed for generating the private key. The captured material is enough for the threat actor to regenerate the private key at their end.

[*](https://thehackernews.uk/sygnia-cyber-response-d-1)
"The malware adds crypto wallet stealing logic to a crypto wallet package, every time a legitimate user creates or uses the logic that reads mnemonic phrases – which are basically the master key for any crypto wallet, the malware reads them and sends them to the remote server," OX Security [said](https://www.ox.security/blog/injectivelabs-npm-package-hijacked-impacting-87-dependent-packages/).

In an attempt to reduce the number of outbound requests, the exfiltration mechanism is [designed](https://www.stepsecurity.io/blog/injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-keys) to append multiple key derivations over a two-second window into a single queue and then send them in the form of an HTTPS POST request to an external server ("testnet.archival.chain.grpc-web.injective[.]network") in a single beacon.

StepSecurity [noted](https://www.stepsecurity.io/blog/injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-keys) the malicious release was facilitated through the repository's own trusted-publisher (OIDC) pipeline, adding that the malicious commits were authored and pushed under the identity of an existing, trusted maintainer ("thomasRalee").

Users who have installed the malicious version are recommended to update to the newly published, clean version of the package (1.20.23), treat any private key or mnemonic phrase passed through the package as compromised and rotate them, and check for transitive dependencies.

Found this article interesting? Follow us on [Google News](https://news.google.com/publications/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ), [Twitter](https://twitter.com/thehackersnews) and [LinkedIn](https://www.linkedin.com/company/thehackernews/) to read more exclusive content we post.

SHARE
[**](#link_share)
[**](#link_share)
[**](#link_share)
[**](javascript:void(0))

[**Tweet](#link_share)
[**Share](#link_share)
[**Share](#link_share)
**Share

[SHARE **](javascript:void(0))
[Credential Theft](https://thehackernews.com/search/label/Credential%20Theft), [cryptocurrency](https://thehackernews.com/search/label/cryptocurrency), [data theft](https://thehackernews.com/search/label/data%20theft), [Developer Security](https://thehackernews.com/search/label/Developer%20Security), [GitHub](https://thehackernews.com/search/label/GitHub), [Malware](https://thehackernews.com/search/label/Malware), [NPM](https://thehackernews.com/search/label/NPM), [Open Source Security](https://thehackernews.com/search/label/Open%20Source%20Security), [Package Security](https://thehackernews.com/search/label/Package%20Security), [Software Supply Chain](https://thehackernews.com/search/label/Software%20Supply%20Chain)]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat]]></title>
            <link>https://aiheadlines.pro/news/urgent---progress-tells-sharefile-customers-to-shut-down-sto</link>
            <guid>https://aiheadlines.pro/news/urgent---progress-tells-sharefile-customers-to-shut-down-sto</guid>
            <pubDate>Sat, 11 Jul 2026 06:38:26 GMT</pubDate>
            <description><![CDATA[- 

**Swati Khandelwal**Jul 10, 2026Enterprise Security / Security Incident
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgULXOG2_Ph1198nw2lOea2pYE9u1GkPHaaMlzhpO48pOmejpWKFuHbchUac...]]></description>
            <content:encoded><![CDATA[- 

**Swati Khandelwal**Jul 10, 2026Enterprise Security / Security Incident
[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgULXOG2_Ph1198nw2lOea2pYE9u1GkPHaaMlzhpO48pOmejpWKFuHbchUac5JIRQHGiIMMTefXq-LktA8AjsqqMIsBS54bLaludxIJbq7chYfo_Vsoqf9Xi7YomnSUL9wHAYa5InCST76k1aP10VMmNKK_MDLD3o5zNXyB4ODMRMl0DbLkz9f2mg2k2S8/s1700-e365/progress.jpg)
Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to **The Hacker News** that it is responding to a "credible external security threat."

The company has temporarily disabled access to the affected accounts, a step it says it took "out of an abundance of caution" while it works with internal and external security experts.

It says it has no indication of unauthorized access to any ShareFile accounts or data, and that it notified customers after learning of the threat.

What Progress has not said is what the threat is or who is behind it.

The order became public when a customer posted the company's email to Reddit's [r/sysadmin](https://www.reddit.com/r/sysadmin/comments/1usohco/psa_shutdown_your_sharefile_storage_zone/) on July 10. Progress [confirmed the disruption](https://status.sharefile.com/) on its status page, listing Storage Zone Controller customers as "not operational" and the incident as under investigation as of a 12:12 p.m. EDT update.

[*](https://thehackernews.uk/ai-vuln-protection-d)
Only the Storage Zone Controller is affected, not standard cloud-only ShareFile accounts. The controller is a server that a company runs itself, so files can stay on its own storage while it still uses ShareFile's cloud to share and manage them.

The controller usually sits at the network's edge, reachable from the internet. That exposure makes it both useful and a target. Ordering customers to take it fully offline, rather than just patch it, is a notable step.

[*](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuIEperKcgWWot-nes4WRvJrO5SGh6v427wpkWQooK_eTA9AGQzfo1YTPo9aSmrCZ25_e9NKLgRAGG9wiYyjY0Sf7tXiigFaTpLveXt6waUA2BSXpU2Ec5zWqAJaWMnM0f9sKuYOF0QklaPLgl1GZwPZbtFkVQJn9H_MpMWwJeKMkgC33dCEISt8SGS54/s1700-e365/email.jpg)
That choice is itself a tell. If a fix for this threat existed, Progress would be telling customers to apply it; the shutdown order suggests there is none yet. That usually means a newly found flaw the company is racing to close, though the same step would also fit a threat a patch cannot address, such as stolen keys or a problem on Progress's own side.

Its statement that no accounts or data were accessed is careful wording, too, and does not rule out trouble on the controllers themselves.

## What to do now

 - Follow the shutdown order first. Keep the affected controllers offline until Progress says what the threat is and when it is safe to restart.

 - Separately, confirm your version is current: 5.12.4 or later on the 5.x line, or a 6.x release. That closes the flaws fixed earlier this year, but Progress has not said it clears the current threat, so do not treat it as permission to restart.

 - If a controller is reachable from the internet, handle it as a possible incident. Preserve the logs and start your incident-response process, then check for unfamiliar .aspx files in the web folders and storage paths you did not set. A clean-looking server is not proof that it is clean.

ShareFile has faced this before. In 2023, while the product still belonged to Citrix, attackers exploited an unauthenticated flaw in the same Storage Zones Controller (CVE-2023-24489).

CISA [flagged it as actively exploited](https://thehackernews.com/2023/08/cisa-adds-citrix-sharefile-flaw-to-kev.html), and Citrix cut unpatched controllers off from the ShareFile cloud, the same access block Progress has now imposed.

[*](https://thehackernews.uk/sygnia-cyber-response-d-1)
Progress, which acquired ShareFile in 2024, had already weathered a mass file-transfer attack of its own: MOVEit, whose 2023 zero-day was exploited by the Clop group and hit more than 2,700 organizations.

The Storage Zones Controller also had two critical flaws that watchTowr [disclosed in April](https://thehackernews.com/2026/04/threatsday-bulletin-pre-auth-chains.html) and Progress patched in March, though the company has not connected the current threat to them, and neither has been reported as exploited.

The central question is still unanswered: Progress has pulled these systems offline and is working with outside experts, but has not said what the threat is or when customers can safely bring them back online.

Found this article interesting? Follow us on [Google News](https://news.google.com/publications/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ), [Twitter](https://twitter.com/thehackersnews) and [LinkedIn](https://www.linkedin.com/company/thehackernews/) to read more exclusive content we post.

SHARE
[**](#link_share)
[**](#link_share)
[**](#link_share)
[**](javascript:void(0))

[**Tweet](#link_share)
[**Share](#link_share)
[**Share](#link_share)
**Share

[SHARE **](javascript:void(0))
[Cloud security](https://thehackernews.com/search/label/Cloud%20security), [data security](https://thehackernews.com/search/label/data%20security), [enterprise security](https://thehackernews.com/search/label/enterprise%20security), [Incident response](https://thehackernews.com/search/label/Incident%20response), [network security](https://thehackernews.com/search/label/network%20security), [security incident](https://thehackernews.com/search/label/security%20incident), [server security](https://thehackernews.com/search/label/server%20security), [Software Security](https://thehackernews.com/search/label/Software%20Security), [Vulnerability](https://thehackernews.com/search/label/Vulnerability), [Windows Security](https://thehackernews.com/search/label/Windows%20Security)]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[The Download: Claude’s inner workings and OpenAI’s “super app”]]></title>
            <link>https://aiheadlines.pro/news/the-download-claudes-inner-workings-and-openais-super-app</link>
            <guid>https://aiheadlines.pro/news/the-download-claudes-inner-workings-and-openais-super-app</guid>
            <pubDate>Sat, 11 Jul 2026 06:38:12 GMT</pubDate>
            <description><![CDATA[*This is today's edition of *[*The Download*](https://forms.technologyreview.com/newsletters/briefing-the-download/?_ga=2.179569122.736533416.1649661040-405833893.1649413289), *our weekday newsletter ...]]></description>
            <content:encoded><![CDATA[*This is today's edition of *[*The Download*](https://forms.technologyreview.com/newsletters/briefing-the-download/?_ga=2.179569122.736533416.1649661040-405833893.1649413289), *our weekday newsletter that provides a daily dose of what's going on in the world of technology.*
The AI firm Anthropic has got the clearest glimpse yet at what’s really going on inside large language models as they answer questions or carry out tasks. What they found ranges from the mundane to the unnerving. Researchers at the company built a tool called the Jacobian lens (or J-lens) and used it to uncover a hidden area, which they named the J-space, inside its flagship LLM, Claude.The J-space contains words related to the response a model is working on but may not ultimately produce. If Claude were a person (which it is not), you might say these hidden words reveal what’s on its mind before it actually speaks. [Read the full story on what they found.](https://www.technologyreview.com/2026/07/09/1140293/anthropic-found-a-hidden-space-where-claude-puzzles-over-concepts/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:m-d-Y%7C*)*—Will Douglas Heaven***The must-reads***I’ve combed the internet to find you today’s most fun/important/scary/fascinating stories about technology.***1 OpenAI has unveiled its long-awaited "super app" **
ChatGPT Work blends its chatbot, coding tool, and new models. ([Reuters](https://www.reuters.com/business/openai-launches-chatgpt-work-2026-07-09/) $)
*+ It’s designed to do your work for you and with you. *([Ars Technica](https://arstechnica.com/ai/2026/07/openai-wants-its-new-tool-to-do-your-work-for-you-and-with-you/))
*+ And arrived the same day as OpenAI’s GPT 5.6 models.* ([NYT](https://www.nytimes.com/2026/07/09/technology/openai-sol-ai.html) $)
*+ It’s also developing a fully automated researcher.* ([MIT Technology Review](https://www.technologyreview.com/2026/03/20/1134438/openai-is-throwing-everything-into-building-a-fully-automated-researcher/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:m-d-Y%7C*))

**2 Humanoids have performed teleoperated surgery on living animals**
In the world-first, they removed gallbladders from pigs. ([Ars Technica](https://arstechnica.com/ai/2026/07/humanoid-robots-controlled-by-surgeons-did-world-first-operation-on-live-pigs/))
*+ The human work behind humanoids is hidden.* ([MIT Technology Review](https://www.technologyreview.com/2026/02/23/1133508/the-human-work-behind-humanoid-robots-is-being-hidden/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:m-d-Y%7C*))
 
**3 SK Hynix has landed the largest US listing by a foreign company**
The South Korean chip giant raised $26.5 billion. ([CNN](https://edition.cnn.com/2026/07/10/business/sk-hynix-us-listing-ai-chip-boom-intl-hnk))
*+ Demand for AI data centres has led its profits to skyrocket. *([Guardian](https://www.theguardian.com/world/2026/jul/10/south-korea-chip-maker-sk-hynix-rides-ai-boom-raising-265bn-in-huge-us-listing))
*+ But its jumbo share sale may be a sign of overheated times. *([FT](https://www.ft.com/content/3986c7e5-01bc-4d24-a41f-3b8030ac2bd8) $)
*+ South Korea’s hottest bachelors are chip workers.* ([MIT Technology Review](https://www.technologyreview.com/2026/07/06/1140000/south-korea-bachelors-samsung-skhynix-chip-workers/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:m-d-Y%7C*))
 
**4 Tencent is leading a deal to unwind Meta's $2 billion Manus acquisition**
It’s in talks to become the Chinese AI startup’s largest shareholder. ([FT](https://www.ft.com/content/0d04378d-d71b-4225-b31a-70504e358480?syn-25a6b1a6=1) $)
*+ Tencent will reportedly buy Manus for no less ​than $2 billion.* ([Reuters](https://www.reuters.com/technology/tencent-talks-become-ai-start-up-manus-largest-shareholder-ft-reports-2026-07-10/) $)
*+ Beijing had ordered Meta to unwind the acquisition.* ([Bloomberg](https://www.bloomberg.com/news/articles/2026-07-10/tencent-in-talks-to-become-largest-holder-of-manus-ft-reports-mrectviz) $)
 
**5 Resuscitated human retinas responded to light 10 hours after death**
It’s a big step towards eye transplants that restore vision. ([New Scientist](https://www.newscientist.com/article/2533673-resuscitated-human-retinas-respond-to-light-10-hours-after-death/) $)
*+ As is a new device that revives dead eyeballs.* ([MIT Technology Review](https://www.technologyreview.com/2026/02/23/1133508/the-human-work-behind-humanoid-robots-is-being-hidden/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:m-d-Y%7C*))
 
**6 Meta has started charging for AI access**
A new version of Muse Spark has a paid tier for developers. ([Quartz](https://qz.com/meta-muse-spark-api-developers-paid-anthropic-openai-070926)) 
*+ Meta also plans to start producing an AI chip in September.* ([Reuters](https://www.reuters.com/world/asia-pacific/meta-put-ai-chip-into-production-september-it-looks-double-computing-capacity-2026-07-09/) $)
 
**7 OpenAI and Google have sold AI models to blacklisted China groups**
Via Singapore-based subsidiaries of Alibaba, Baidu and Tencent. ([FT](https://www.ft.com/content/5d6aafa1-5d47-4585-aa95-6ec06a6cd20f) $)

**8 A daughter tested an AI “death bot” of her father**
The technology provided both comfort and unease. ([New Yorker](https://www.newyorker.com/news/as-told-to/can-ai-keep-a-parent-alive) $)

**9 An astronomer says the hunt for alien life needs more statistics**
He wants to replace speculation with mathematical frameworks. ([Quanta](https://www.quantamagazine.org/will-we-ever-find-alien-civilizations-20260709/))

**10 Pokémon Go players turned Times Square into a giant battlefield**
More than 1,500 fans finally fulfilled the game’s 2016 launch promise. ([Wired](https://www.wired.com/story/thousands-of-pokemon-go-players-descend-on-times-square-to-defeat-mewtwo/) $)
*+ Pokémon Go is also training world models.* ([MIT Technology Review](https://www.technologyreview.com/2026/03/10/1134099/how-pokemon-go-is-helping-robots-deliver-pizza-on-time/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:m-d-Y%7C*))**Quote of the day**—Vijay Janapa Reddi, an engineering professor at Harvard University, tells [Wired](https://www.wired.com/story/robot-dogs-teslas-and-rescue-helicopters-the-un-ai-summit-was-alot/) why he’s skeptical about grand plans for AI.**One More Thing**In 1943, psychologist B.F. Skinner led a secret government project to make bombs more precise. His idea: teach pigeons to guide missiles by pecking at targets on a screen inside a warhead. To train them, Skinner rewarded the birds with food when they made the right decisions, using trial and error to shape their behavior.Unsurprisingly, the military never deployed Skinner’s kamikaze pigeons. Yet his experiments convinced him that pigeons were “an extremely reliable instrument” for studying learning. Decades later, those same principles would help power reinforcement learning, the technology behind some of today’s most advanced AI systems.[Discover how pigeons inspired one of AI’s most powerful techniques](https://www.technologyreview.com/2025/08/18/1121370/ai-pigeons-reinforcement-learning/?utm_source=the_download&utm_medium=email&utm_campaign=the_download.unpaid.engagement&utm_term=*%7CSUBCLASS%7C*&utm_content=*%7CDATE:m-d-Y%7C).*—Ben Crair***We can still have nice things***A place for comfort, fun, and distraction to brighten up your day. (Got any ideas? *[*Drop me a line*](mailto:thomas.macaulay@technologyreview.com)*.)*+ Here’s a splendid selection of this year’s [NSW architecture](https://www.theguardian.com/artanddesign/gallery/2026/jul/02/nsw-architecture-awards-winners-2026-in-pictures) award winners.
+ Photographers have captured the [Strawberry Moon’s golden glow](https://www.smithsonianmag.com/smart-news/these-17-stunning-photos-of-the-strawberry-moon-show-earths-natural-satellite-in-all-its-glory-180989050/) in stunning detail.
+ *Idiocracy* is the film that best exemplifies the “American experience,” according to a new poll. Look back at the prescient comedy with this [Screen Junkies trailer](https://www.youtube.com/watch?v=gSgBTb3wmMI).
+ Get ready for the weekend with this [psychedelic house journey](https://www.youtube.com/watch?v=rE7lLoS5bAE) from Jamie xx b2b Caribou. Plus: Meta is pausing an AI training program that tracks workers’ keystrokes.Plus: Anthropic has called for a global slowdown in AI development.Plus: NASA unveiled plans for three uncrewed missions to the Moon this year.Plus: SpaceX is now valued higher than Amazon.Discover special offers, top stories,
 upcoming events, and more.]]></content:encoded>
            <category>OpenAI</category>
        </item>
        <item>
            <title><![CDATA[Hugging Face's CEO on why companies are done renting their AI | TechCrunch]]></title>
            <link>https://aiheadlines.pro/news/hugging-faces-ceo-on-why-companies-are-done-renting-their-ai</link>
            <guid>https://aiheadlines.pro/news/hugging-faces-ceo-on-why-companies-are-done-renting-their-ai</guid>
            <pubDate>Sat, 11 Jul 2026 06:37:59 GMT</pubDate>
            <description><![CDATA[Open source AI is booming, according to [Hugging Face](https://huggingface.co/) CEO [Clem Delangue](https://www.linkedin.com/in/clementdelangue/). The company has grown into something like a GitHub fo...]]></description>
            <content:encoded><![CDATA[Open source AI is booming, according to [Hugging Face](https://huggingface.co/) CEO [Clem Delangue](https://www.linkedin.com/in/clementdelangue/). The company has grown into something like a GitHub for AI in recent years, where AI builders can share and download open models and datasets, now used by roughly half the Fortune 500. Delangue has seen the same story play out again and again: companies start out on frontier APIs, but as they scale, the costs push them towards open source models. On this episode of TechCrunch’s[ Equity](https://techcrunch.com/podcasts/equity/) podcast, Rebecca Bellan talked to Delangue about why the open vs closed source fight matters in the wake of Anthropic’s halted Fable release, and why he’s worried about the possibility that a handful of big companies could end up controlling everything. Subscribe to Equity on [YouTube](https://www.youtube.com/@TechCrunch),[ Apple Podcasts](https://itunes.apple.com/us/podcast/id1215439780),[ Overcast](https://overcast.fm/itunes1215439780/equity),[ Spotify](https://open.spotify.com/show/5IEYLip3eDppcOmy5DmphC?si=rZDFHv2sQUul_g94iCRgpQ) and all the casts. You also can follow Equity on[ X](https://twitter.com/EquityPod) and[ Threads](https://www.threads.net/@equitypod), at @EquityPod. Topics*When you purchase through links in our articles, [we may earn a small commission](https://techcrunch.com/techcrunch-affiliate-monetization-standards/). This doesn’t affect our editorial independence.*
 Audio Producer
 Theresa Loconsolo is an audio producer at TechCrunch focusing on Equity, the network’s flagship podcast. Before joining TechCrunch in 2022, she was one of 2 producers at a four-station conglomerate where she wrote, recorded, voiced and edited content, and engineered live performances and interviews from guests like lovelytheband. Theresa is based in New Jersey and holds a bachelors degree in Communication from Monmouth University. 
You can contact or verify outreach from Theresa by emailing [theresa.loconsolo@techcrunch.com](mailto:theresa.loconsolo@techcrunch.com). 
Last chance to save up to $190 on TechCrunch Founder Summit. Join 1,000+ founders and VCs at all stages for real-world scaling insights and connections that move the needle.

**Savings end June 26, 11:59 p.m. PT**. [Elon Musk praises Mythos/Fable, promises not to ‘cut off’ Anthropic](https://techcrunch.com/2026/07/09/elon-musk-praises-mythos-fable-promises-not-to-cut-off-anthropic/)

 [Instagram users: Here’s how to stop Meta’s AI from using your photos](https://techcrunch.com/2026/07/09/how-to-stop-metas-ai-image-generator-from-using-your-instagram-photos/)

 [Figma acquires team behind a vibe-coding app](https://techcrunch.com/2026/07/07/figma-acquires-team-behind-a-vibe-coding-app/)

 [If you use Google, you’re training its AI. Here’s how to opt out.](https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/)

 [Reddit is using LLMs to solve a problem LLMs largely created](https://techcrunch.com/2026/07/06/reddit-is-using-llms-to-solve-a-problem-llms-largely-created/)

 [Amazon will stop accepting new customers for Mechanical Turk](https://techcrunch.com/2026/07/05/amazon-will-stop-accepting-new-customers-for-mechanical-turk/)

 [5 desk gadgets that can make your workday better](https://techcrunch.com/2026/07/05/5-desk-gadgets-that-can-make-your-workday-better/)]]></content:encoded>
            <category>Anthropic</category>
        </item>
        <item>
            <title><![CDATA[SK Hynix raises $26.5B in the biggest foreign IPO in US history, is urged to build new US fabs | TechCrunch]]></title>
            <link>https://aiheadlines.pro/news/sk-hynix-raises-265b-in-the-biggest-foreign-ipo-in-us-histor</link>
            <guid>https://aiheadlines.pro/news/sk-hynix-raises-265b-in-the-biggest-foreign-ipo-in-us-histor</guid>
            <pubDate>Sat, 11 Jul 2026 06:37:56 GMT</pubDate>
            <description><![CDATA[The AI chip boom just produced its biggest Wall Street moment yet. SK Hynix, a South Korean memory chip giant, [said Friday](https://www.skhynix.com/ir/UI-FR-IR12_T1_view/?seq=6809) it has raised $26....]]></description>
            <content:encoded><![CDATA[The AI chip boom just produced its biggest Wall Street moment yet. SK Hynix, a South Korean memory chip giant, [said Friday](https://www.skhynix.com/ir/UI-FR-IR12_T1_view/?seq=6809) it has raised $26.5 billion (KRW 40 trillion) in its U.S. market debut.SK Hynix sold 177.9 million American depositary shares (ADRs) at $149 each, structured so U.S. investors can buy in at roughly a tenth of what a full share costs in Seoul. This deal, the largest-ever U.S. debut by a non-American company, topped [Alibaba’s](https://www.sec.gov/Archives/edgar/data/1577552/000119312514347620/d709111d424b4.htm) $25 billion IPO in 2014.The company begins trading on the Nasdaq today, Friday, July 10, under the temporary ticker SKHYV. Regular trading opens Monday, July 13, when the ticker officially becomes SKHY. So far, U.S. investors are lapping it up. The [stock opened at 14% over its IPO price](https://finance.yahoo.com/quote/SKHYV/), and the price was still rising in early trading on Friday.This even as it priced its U.S. shares at a 2.7% premium to its own three-day average back home in Seoul, according to its [Korea Stock Exchange filing](https://dart.fss.or.kr/dsaf001/main.do?rcpNo=20260710000012). Yet, demand for the offering was [reportedly](https://www.bloomberg.com/news/articles/2026-07-08/sk-hynix-us-offering-is-more-than-seven-times-oversubscribed) more than seven times the available shares, per media reports.That’s especially amazing considering Korean companies have long traded at a discount to their global peers. That valuation gap is called the Korea Discount. Investors often cite factors such as complex corporate governance structures, low shareholder returns, regulatory uncertainty, and geopolitical risks related to North Korea to justify why companies from that country don’t command higher share prices. But SK Hynix clearly isn’t suffering from the Korea Discount and that’s because it makes memory chips, including high-bandwidth memory (HBM). HBM is a key component of AI GPUs processors. And right now, Nvidia relies on SK Hynix as one of its primary suppliers.Per its filing, the money raised from eager U.S. investors will go to three places: a new fab in South Korea (being built now to address the worldwide shortage of memory cause by AI); a new packaging facility in that country; and EUV scanners, the machines that make next-generation chips possible.Meanwhile, U.S. Commerce Secretary Howard Lutnick stopped by a Micron event Thursday with a message for the broader chip industry, not just for U.S. memory maker Micron (who is one of SK Hynix’s biggest competitors). Lutnick [reportedly](https://www.bloomberg.com/news/articles/2026-07-09/lutnick-presses-sk-hynix-samsung-to-boost-memory-output-in-us) said he’s already in talks with Samsung (the third major memory maker, worldwide) and SK Hynix about building new factories in the U.S. The idea being not to let South Korea continue to be the country that dominates this important tech.Micron, naturally, is in. It [announced it plans](https://investors.micron.com/news-releases/news-release-details/micron-accelerates-us-investments-pours-first-concrete-new-york) to invest $250 billion in new U.S. manufacturing, a commitment the U.S. memory chip company says will create more than 90,000 jobs and keep leading-edge chip production on American soil.The timing of Lutnick’s request is notable beyond this U.S. IPO for SK Hynix: Both Korean chipmakers [just pledged more than $550 billion](https://techcrunch.com/2026/06/29/south-korean-tech-giants-commit-over-550b-to-ease-ramageddon/) for new manufacturing investment in South Korea.Topics*When you purchase through links in our articles, [we may earn a small commission](https://techcrunch.com/techcrunch-affiliate-monetization-standards/). This doesn’t affect our editorial independence.*
 Reporter, Asia
 Kate Park is a reporter at TechCrunch, with a focus on technology, startups and venture capital in Asia. She previously was a financial journalist at Mergermarket covering M&A, private equity and venture capital.
Last chance to save up to $190 on TechCrunch Founder Summit. Join 1,000+ founders and VCs at all stages for real-world scaling insights and connections that move the needle.

**Savings end June 26, 11:59 p.m. PT**. [Elon Musk praises Mythos/Fable, promises not to ‘cut off’ Anthropic](https://techcrunch.com/2026/07/09/elon-musk-praises-mythos-fable-promises-not-to-cut-off-anthropic/)

 [Instagram users: Here’s how to stop Meta’s AI from using your photos](https://techcrunch.com/2026/07/09/how-to-stop-metas-ai-image-generator-from-using-your-instagram-photos/)

 [Figma acquires team behind a vibe-coding app](https://techcrunch.com/2026/07/07/figma-acquires-team-behind-a-vibe-coding-app/)

 [If you use Google, you’re training its AI. Here’s how to opt out.](https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/)

 [Reddit is using LLMs to solve a problem LLMs largely created](https://techcrunch.com/2026/07/06/reddit-is-using-llms-to-solve-a-problem-llms-largely-created/)

 [Amazon will stop accepting new customers for Mechanical Turk](https://techcrunch.com/2026/07/05/amazon-will-stop-accepting-new-customers-for-mechanical-turk/)

 [5 desk gadgets that can make your workday better](https://techcrunch.com/2026/07/05/5-desk-gadgets-that-can-make-your-workday-better/)]]></content:encoded>
            <category>Anthropic</category>
        </item>
        <item>
            <title><![CDATA[Open source AI matters more than ever, according to Hugging Face's Clem Delangue]]></title>
            <link>https://aiheadlines.pro/news/open-source-ai-matters-more-than-ever-according-to-hugging-f</link>
            <guid>https://aiheadlines.pro/news/open-source-ai-matters-more-than-ever-according-to-hugging-f</guid>
            <pubDate>Sat, 11 Jul 2026 06:37:50 GMT</pubDate>
            <description><![CDATA[Open source AI is booming, according to [Hugging Face](https://huggingface.co/) CEO [Clem Delangue](https://www.linkedin.com/in/clementdelangue/). The company has grown into something like a GitHub fo...]]></description>
            <content:encoded><![CDATA[Open source AI is booming, according to [Hugging Face](https://huggingface.co/) CEO [Clem Delangue](https://www.linkedin.com/in/clementdelangue/). The company has grown into something like a GitHub for AI in recent years, where AI builders can share and download open models and datasets, now used by roughly half the Fortune 500. Delangue has seen the same story play out again and again: companies start out on frontier APIs, but as they scale, the costs push them towards open source models. On this episode of TechCrunch’s[ Equity](https://techcrunch.com/podcasts/equity/) podcast, Rebecca Bellan talked to Delangue about why the open vs closed source fight matters in the wake of Anthropic’s halted Fable release, and why he’s worried about the possibility that a handful of big companies could end up controlling everything. Listen to the full episode to hear more about: Subscribe to Equity on [YouTube](https://www.youtube.com/@TechCrunch),[ Apple Podcasts](https://itunes.apple.com/us/podcast/id1215439780),[ Overcast](https://overcast.fm/itunes1215439780/equity),[ Spotify](https://open.spotify.com/show/5IEYLip3eDppcOmy5DmphC?si=rZDFHv2sQUul_g94iCRgpQ) and all the casts. You also can follow Equity on[ X](https://twitter.com/EquityPod) and[ Threads](https://www.threads.net/@equitypod), at @EquityPod. 
 Senior Reporter
 Rebecca Bellan is a senior reporter at TechCrunch where she covers the business, policy, and emerging trends shaping artificial intelligence. Her work has also appeared in Forbes, Bloomberg, The Atlantic, The Daily Beast, and other publications. You can contact or verify outreach from Rebecca by emailing [rebecca.bellan@techcrunch.com](mailto:rebecca.bellan@techcrunch.com) or via encrypted message at rebeccabellan.491 on Signal.
 Audio Producer
 Theresa Loconsolo is an audio producer at TechCrunch focusing on Equity, the network’s flagship podcast. Before joining TechCrunch in 2022, she was one of 2 producers at a four-station conglomerate where she wrote, recorded, voiced and edited content, and engineered live performances and interviews from guests like lovelytheband. Theresa is based in New Jersey and holds a bachelors degree in Communication from Monmouth University. 
You can contact or verify outreach from Theresa by emailing [theresa.loconsolo@techcrunch.com](mailto:theresa.loconsolo@techcrunch.com). 
Last chance to save up to $190 on TechCrunch Founder Summit. Join 1,000+ founders and VCs at all stages for real-world scaling insights and connections that move the needle.

**Savings end June 26, 11:59 p.m. PT**. [Elon Musk praises Mythos/Fable, promises not to ‘cut off’ Anthropic](https://techcrunch.com/2026/07/09/elon-musk-praises-mythos-fable-promises-not-to-cut-off-anthropic/)

 [Instagram users: Here’s how to stop Meta’s AI from using your photos](https://techcrunch.com/2026/07/09/how-to-stop-metas-ai-image-generator-from-using-your-instagram-photos/)

 [Figma acquires team behind a vibe-coding app](https://techcrunch.com/2026/07/07/figma-acquires-team-behind-a-vibe-coding-app/)

 [If you use Google, you’re training its AI. Here’s how to opt out.](https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/)

 [Reddit is using LLMs to solve a problem LLMs largely created](https://techcrunch.com/2026/07/06/reddit-is-using-llms-to-solve-a-problem-llms-largely-created/)

 [Amazon will stop accepting new customers for Mechanical Turk](https://techcrunch.com/2026/07/05/amazon-will-stop-accepting-new-customers-for-mechanical-turk/)

 [5 desk gadgets that can make your workday better](https://techcrunch.com/2026/07/05/5-desk-gadgets-that-can-make-your-workday-better/)]]></content:encoded>
            <category>Anthropic</category>
        </item>
        <item>
            <title><![CDATA[Apple sues OpenAI over alleged trade secret theft | TechCrunch]]></title>
            <link>https://aiheadlines.pro/news/apple-sues-openai-over-alleged-trade-secret-theft-techcrunch</link>
            <guid>https://aiheadlines.pro/news/apple-sues-openai-over-alleged-trade-secret-theft-techcrunch</guid>
            <pubDate>Sat, 11 Jul 2026 06:37:47 GMT</pubDate>
            <description><![CDATA[Apple filed a [lawsuit](https://www.documentcloud.org/documents/28453229-apple-v-openai/) Friday against OpenAI over allegations of trade secret theft and breach of contract.The iPhone maker alleges t...]]></description>
            <content:encoded><![CDATA[Apple filed a [lawsuit](https://www.documentcloud.org/documents/28453229-apple-v-openai/) Friday against OpenAI over allegations of trade secret theft and breach of contract.The iPhone maker alleges that this misconduct, which it says reveals a pattern of theft from OpenAI employees who previously worked at Apple, was directed by OpenAI’s senior leadership, including [Chief Hardware Officer](https://thetech.com/2025/10/30/tang-tan-openai) [Tang Tan](http://linkedin.com/in/tangtan).The lawsuit, which was filed in the U.S. District Court for the Northern District of California, accuses Tan of using Apple’s confidential project code names during OpenAI’s recruiting process, asking job candidates to bring in Apple hardware components to their interviews, coaching departing Apple employees on how to evade the company’s security procedures, and asking for details about the company’s unannounced products.Before joining OpenAI, Tan had spent 24 years at Apple, most recently as VP of product design for the iPhone and Apple Watch.The accusations come at a time when OpenAI is rumored to be developing its [first hardware product](https://techcrunch.com/2026/04/27/openai-could-be-making-a-phone-with-ai-agents-replacing-apps/), which would likely compete with the iPhone. In April, industry analyst Ming-Chi Kuo [suggested this device could be a smartphone](https://techcrunch.com/2026/04/27/openai-could-be-making-a-phone-with-ai-agents-replacing-apps/) that would rely on AI agents instead of apps. If true, it would be one of the largest threats to Apple’s core hardware business to date.Apple’s former lead designer Jony Ive’s device startup io [was acquired by OpenAI last year](https://techcrunch.com/2025/05/21/jony-ive-to-lead-openais-design-work-following-6-5b-acquisition-of-his-company/) in a $6.5 billion deal to aid the AI company with its hardware ambitions. While io was named in the filing, Ive was not.Tan is not the only OpenAI employee referenced in the new complaint. Apple also alleges that [Chang Liu,](https://www.linkedin.com/in/changliu-apple/) who spent eight years at Apple as a senior systems electrical engineer, failed to return an Apple-issued laptop after leaving the company for OpenAI in 2026 and had used the computer to download confidential Apple technical documents.Apple says in the complaint that the stolen documents included information about unannounced technologies, features, and products, including technical specifications, engineering presentations, and proprietary project data.Liu is also accused in the lawsuit of sharing Apple’s confidential information with other Apple employees applying for jobs at OpenAI, advising at least one of them on what to study before their interview.Apple sent a letter to OpenAI in February to raise its concerns and received no response, the company said in the complaint.It alleges that the behavior of these former employees is part of OpenAI’s strategy to extract Apple’s confidential information, which included asking Apple employees to bring designs and prototypes to their interviews, and answer questions about things like component and vendor selection processes.Apple says its ongoing investigation revealed that OpenAI and its partners have even used Apple’s confidential information while the AI model maker develops its own hardware product. For instance, the filing references a proprietary metal finishing technique that OpenAI used after it allegedly misled a partner into believing it had Apple’s permission to do so.Like many tech companies, Apple typically investigates potential trade secret theft or other improper activity by analyzing communications that took place on company-owned devices and reading through its server logs. By taking the case to court, Apple will have an opportunity to learn more about the extent of the alleged operation through the legal discovery process.Apple is asking the court to bar OpenAI from using or disclosing its trade secrets, require the company to return any confidential Apple materials, and preserve evidence related to the case. “This is the tip of the iceberg. Apple lacks visibility into what’s been happening behind closed doors at OpenAI, where such misconduct is normalized and exemplified by leadership,” the filing states. “As a natural result, OpenAI’s nascent hardware business now rests on the shakiest of foundations, rotten to its core by its illegal reliance on misappropriated trade secrets.” In a prepared statement, Apple also said the following: At Apple, our teams are constantly developing breakthrough technologies to create the best products and services in the world, and protecting their work and intellectual property is something we take very seriously. Recently, significant evidence has emerged suggesting individuals employed by OpenAI wrongfully took Apple’s secret and confidential information regarding our unreleased technologies, processes, and products. We will always defend our teams’ hard work and innovations, and we are taking all appropriate steps to do so.OpenAI was asked for comment. The company responded after publication, [pointing to its public statement shared on X](https://x.com/drewpusateri), which reads: “We have no interest in other companies’ trade secrets. We remain focused on building innovative technology that empowers people everywhere.”The filing is available [here](https://www.documentcloud.org/documents/28453229-apple-v-openai/), or you can read it below.*This story is developing and will be updated. It was originally published at 1:32 p.m. PT.*Topics*When you purchase through links in our articles, [we may earn a small commission](https://techcrunch.com/techcrunch-affiliate-monetization-standards/). This doesn’t affect our editorial independence.*
 Consumer News Editor
 
Last chance to save up to $190 on TechCrunch Founder Summit. Join 1,000+ founders and VCs at all stages for real-world scaling insights and connections that move the needle.

**Savings end June 26, 11:59 p.m. PT**. [Elon Musk praises Mythos/Fable, promises not to ‘cut off’ Anthropic](https://techcrunch.com/2026/07/09/elon-musk-praises-mythos-fable-promises-not-to-cut-off-anthropic/)

 [Instagram users: Here’s how to stop Meta’s AI from using your photos](https://techcrunch.com/2026/07/09/how-to-stop-metas-ai-image-generator-from-using-your-instagram-photos/)

 [Figma acquires team behind a vibe-coding app](https://techcrunch.com/2026/07/07/figma-acquires-team-behind-a-vibe-coding-app/)

 [If you use Google, you’re training its AI. Here’s how to opt out.](https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/)

 [Reddit is using LLMs to solve a problem LLMs largely created](https://techcrunch.com/2026/07/06/reddit-is-using-llms-to-solve-a-problem-llms-largely-created/)

 [Amazon will stop accepting new customers for Mechanical Turk](https://techcrunch.com/2026/07/05/amazon-will-stop-accepting-new-customers-for-mechanical-turk/)

 [5 desk gadgets that can make your workday better](https://techcrunch.com/2026/07/05/5-desk-gadgets-that-can-make-your-workday-better/)]]></content:encoded>
            <category>Cybersecurity</category>
        </item>
        <item>
            <title><![CDATA[Meta removes controversial AI feature on Instagram after backlash | TechCrunch]]></title>
            <link>https://aiheadlines.pro/news/meta-removes-controversial-ai-feature-on-instagram-after-bac</link>
            <guid>https://aiheadlines.pro/news/meta-removes-controversial-ai-feature-on-instagram-after-bac</guid>
            <pubDate>Sat, 11 Jul 2026 06:37:44 GMT</pubDate>
            <description><![CDATA[Meta has axed a controversial feature that allowed users to modify photos from public Instagram accounts using AI. The feature, which was rolled out earlier this week along with a batch of other AI to...]]></description>
            <content:encoded><![CDATA[Meta has axed a controversial feature that allowed users to modify photos from public Instagram accounts using AI. The feature, which was rolled out earlier this week along with a batch of other AI tools, “missed the mark” and is no longer available, according to the company. Earlier this week, Meta [announced](https://techcrunch.com/2026/07/07/meta-rolls-out-muse-a-new-ai-image-generator/) Muse Image, a new AI image generator built by Meta Superintelligence Labs, its dedicated AI unit. Meta promoted one feature that allowed individuals to generate images by @-mentioning public Instagram accounts that they wanted to reference. The feature, which wasn’t designed to alert a user if their photos were used in this way, prompted immediate backlash.TechCrunch [wrote its own guide](https://techcrunch.com/2026/07/09/how-to-stop-metas-ai-image-generator-from-using-your-instagram-photos/) on how to disable the feature.Now Meta has reversed course. The company issued a [blog post](https://about.instagram.com/blog/announcements/new-ai-effects-in-instagram-stories) Friday announcing that it was removing the feature. Puck News founding partner Dylan Byers was the first to share the [company’s decision](https://x.com/DylanByers/status/2075707685547421750?s=20).“Our intent was to provide a useful creative tool and to give people control over whether their public content could be referenced in this way,” the company posted on its blog. “We’ve heard the feedback that this feature missed the mark, so it’s no longer available.”TechCrunch reached out to Meta for more information and will update this article if it responds.Since its integration with social media platforms, AI has been misused with wild abandon — often to [generate naked images of female celebrities](https://www.pbs.org/newshour/show/authorities-struggle-to-stop-ai-tools-generating-nude-images-without-consent#:~:text=There%20has%20been%20a%20sharp,underway%20to%20rein%20it%20in.). Platforms have attempted to mitigate this trend, although the guardrails introduced have often fallen short.In the case of Meta’s newly nixed feature, it seems somewhat obvious that it would have been abused in this way. Indeed, Byers notes that the decision to do away with the feature came “amid scrutiny from users and talent agencies, including CAA.”Topics*When you purchase through links in our articles, [we may earn a small commission](https://techcrunch.com/techcrunch-affiliate-monetization-standards/). This doesn’t affect our editorial independence.*
 Senior Writer, TechCrunch
 
Last chance to save up to $190 on TechCrunch Founder Summit. Join 1,000+ founders and VCs at all stages for real-world scaling insights and connections that move the needle.

**Savings end June 26, 11:59 p.m. PT**. [Elon Musk praises Mythos/Fable, promises not to ‘cut off’ Anthropic](https://techcrunch.com/2026/07/09/elon-musk-praises-mythos-fable-promises-not-to-cut-off-anthropic/)

 [Instagram users: Here’s how to stop Meta’s AI from using your photos](https://techcrunch.com/2026/07/09/how-to-stop-metas-ai-image-generator-from-using-your-instagram-photos/)

 [Figma acquires team behind a vibe-coding app](https://techcrunch.com/2026/07/07/figma-acquires-team-behind-a-vibe-coding-app/)

 [If you use Google, you’re training its AI. Here’s how to opt out.](https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/)

 [Reddit is using LLMs to solve a problem LLMs largely created](https://techcrunch.com/2026/07/06/reddit-is-using-llms-to-solve-a-problem-llms-largely-created/)

 [Amazon will stop accepting new customers for Mechanical Turk](https://techcrunch.com/2026/07/05/amazon-will-stop-accepting-new-customers-for-mechanical-turk/)

 [5 desk gadgets that can make your workday better](https://techcrunch.com/2026/07/05/5-desk-gadgets-that-can-make-your-workday-better/)]]></content:encoded>
            <category>Anthropic</category>
        </item>
        <item>
            <title><![CDATA[Meta enters the crowded AI coding battle with Muse Spark 1.1 | TechCrunch]]></title>
            <link>https://aiheadlines.pro/news/meta-enters-the-crowded-ai-coding-battle-with-muse-spark-11--eb908f</link>
            <guid>https://aiheadlines.pro/news/meta-enters-the-crowded-ai-coding-battle-with-muse-spark-11--eb908f</guid>
            <pubDate>Fri, 10 Jul 2026 08:02:52 GMT</pubDate>
            <description><![CDATA[Meta publicly launched a new version of Muse Spark on Thursday, a multimodal AI model designed for agentic coding that aims to compete with similar products offered by OpenAI and Anthropic.Spark 1.1, ...]]></description>
            <content:encoded><![CDATA[Meta publicly launched a new version of Muse Spark on Thursday, a multimodal AI model designed for agentic coding that aims to compete with similar products offered by OpenAI and Anthropic.Spark 1.1, the first version of which [was announced in April](https://about.fb.com/news/2026/04/introducing-muse-spark-meta-superintelligence-labs/), can engage in multistep reasoning and handle complex processes, manage digital workflows, and deploy new features in enterprise systems, the company says.Meta is a bit behind its competitors here; Anthropic and OpenAI have [offered similar models](https://techcrunch.com/2026/04/16/openai-takes-aim-at-anthropic-with-beefed-up-codex-that-gives-it-more-power-over-your-desktop/) for quite some time. But that doesn’t mean Meta’s entry into the market isn’t a threat.An ongoing source of competitiveness within the AI industry remains the cost of usage, and Meta appears to be offering a competitive rate. Reuters [reports that](https://www.reuters.com/business/meta-debuts-muse-spark-11-with-preview-open-developers-2026-07-09/) the company will charge $1.25 per million input tokens and $4.25 per million output tokens. That puts it in line with (albeit slightly above) Anthropic’s Claude Haiku 4.5 and OpenAI’s GPT-5.6 Luna.Meta’s pitch to users is Spark’s ability to handle large agentic workloads, fix bugs, and help with large code migrations — the kind of automation that enterprises are increasingly turning to AI companies to provide. “Muse Spark 1.1 delivers exceptional performance in personal agentic tasks that require planning and orchestration across a range of external apps and services,” the company [wrote in a blog post](https://ai.meta.com/blog/introducing-muse-spark-meta-model-api/).Meta has released a handful of foundation AI models over the past few years. The Muse Spark release was apparently important enough to compel CEO Mark Zuckerberg [to post](https://x.com/finkd/status/2075218444056707458?s=20) on X for the first time in three years. Zuckerberg’s last post was in July 2023, around the time the platform rebranded [from Twitter to X](https://www.cbsnews.com/news/twitter-rebrand-x-name-change-elon-musk-what-it-means/).In his post, Zuckerberg called Spark “a strong agentic and coding model at a very low price,” noting that the model was “strongest at agentic performance, tool use, and computer use.” Zuckerberg also noted that there was “more to come soon” — implying that the company plans to release additional models.It’s been a big week for AI announcements — particularly for Meta, which also [unveiled a new AI image-generation model](https://techcrunch.com/2026/07/07/meta-rolls-out-muse-a-new-ai-image-generator/) on Tuesday, dubbed Muse Image. Other releases this week have included [a ne](https://techcrunch.com/2026/07/08/spacexai-releases-grok-4-5-which-elon-describes-as-an-opus-class-model/)[w](https://techcrunch.com/2026/07/08/spacexai-releases-grok-4-5-which-elon-describes-as-an-opus-class-model/)[ version of Grok](https://techcrunch.com/2026/07/08/spacexai-releases-grok-4-5-which-elon-describes-as-an-opus-class-model/) from SpaceXAI and a [new family of models](https://openai.com/index/gpt-5-6/) from OpenAI, GPT-5.6, that also dropped Thursday. Suffice it to say that the competition within the AI industry is as healthy as ever, and companies that wish to stand out from their peers have their work cut out for them.Topics*When you purchase through links in our articles, [we may earn a small commission](https://techcrunch.com/techcrunch-affiliate-monetization-standards/). This doesn’t affect our editorial independence.*
 Senior Writer, TechCrunch
 
Last chance to save up to $190 on TechCrunch Founder Summit. Join 1,000+ founders and VCs at all stages for real-world scaling insights and connections that move the needle.

**Savings end June 26, 11:59 p.m. PT**. [Figma acquires team behind a vibe-coding app](https://techcrunch.com/2026/07/07/figma-acquires-team-behind-a-vibe-coding-app/)

 [If you use Google, you’re training its AI. Here’s how to opt out.](https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/)

 [Reddit is using LLMs to solve a problem LLMs largely created](https://techcrunch.com/2026/07/06/reddit-is-using-llms-to-solve-a-problem-llms-largely-created/)

 [Amazon will stop accepting new customers for Mechanical Turk](https://techcrunch.com/2026/07/05/amazon-will-stop-accepting-new-customers-for-mechanical-turk/)

 [5 desk gadgets that can make your workday better](https://techcrunch.com/2026/07/05/5-desk-gadgets-that-can-make-your-workday-better/)

 [New Google commercial imagines a Declaration of Independence written with help from AI](https://techcrunch.com/2026/07/04/new-google-commercial-imagines-a-declaration-of-independence-written-with-help-from-ai/)

 [Chevy built an all-American EV truck — why is nobody buying it?](https://techcrunch.com/2026/07/03/chevy-built-an-all-american-ev-truck-why-is-nobody-buying-it/)]]></content:encoded>
            <category>OpenAI</category>
        </item>
        <item>
            <title><![CDATA[Can AI answer the $3 trillion question? | TechCrunch]]></title>
            <link>https://aiheadlines.pro/news/can-ai-answer-the-3-trillion-question-techcrunch-9cd1d5</link>
            <guid>https://aiheadlines.pro/news/can-ai-answer-the-3-trillion-question-techcrunch-9cd1d5</guid>
            <pubDate>Fri, 10 Jul 2026 08:02:52 GMT</pubDate>
            <description><![CDATA[Three years ago, Sequoia partner David Cahn was one of the first people to do the math and put a number on the implications of Silicon Valley’s titanic spend on AI infrastructure.In [2023](https://seq...]]></description>
            <content:encoded><![CDATA[Three years ago, Sequoia partner David Cahn was one of the first people to do the math and put a number on the implications of Silicon Valley’s titanic spend on AI infrastructure.In [2023](https://sequoiacap.com/article/follow-the-gpus-perspective/), he was reacting to Nvidia’s reported annual GPU revenue of $50 billion. Starting with that figure, and adding in the implied costs of operating the data centers and the margins for their operators, he deduced that $200 billion in revenue would be required to pay back the up-front investment.He took it as a challenge, asking entrepreneurs to come up with AI products and services to make use of, and generate revenue from, all that infrastructure. Fast-forward to today, adding up three years of hyperscaling, and Cahn’s got a [new number](https://dcahn.substack.com/p/ais-15t-question) on AI infrastructure spending for 2026: $1.5 trillion.All told, he calculates that the AI industry will have to earn $3 trillion to justify all those chips and other data center expenditures. And that’s probably an underestimate — the rising costs of memory and the increasing use of exotic or inference-specific chips will drive that number up. “Recently,” he writes, “the required revenue per GW of CapEx has sharply increased due to these bottleneck dynamics and rising costs of construction.”On the other side of the ledger, Anthropic is thought to have hit [$60 billion in ARR](https://newsletter.semianalysis.com/p/anthropic-3q26-profit-over-1b-the), while OpenAI reportedly earned [$13 billion](https://www.wheresyoured.at/exclusive-openai-financials/) in 2025 (although in [November 2025, it said it was at $20 billion ARR](https://techcrunch.com/2025/11/06/sam-altman-says-openai-has-20b-arr-and-about-1-4-trillion-in-data-center-commitments/)) and is presumably making more this year. But there’s clearly a large gap to be closed.Someone minding that gap is Torsten Slok, the chief economist at Apollo, the giant asset manager. In a [recent note](https://www.apollo.com/wealth/insights-news/insights/daily-spark/a-slower-ai-payoff-would-be-everyones-problem), he points out that the hyperscalers — Google, Meta, Microsoft, and Amazon — are all predicting massive accelerations in their free-cash flow in 2028. That is, they expect to see the payback from all those chips they bought.What if they don’t? Slok notes a risk we’re currently seeing across AI usage: More organizations turning to cheaper open weight models, often Chinese, not those built by the frontier labs, and overall token prices falling. OpenAI’s latest model, per CEO Sam Altman, is [54% more token efficient](https://www.cnbc.com/2026/07/09/open-ai-sam-altman-chatgpt-5-6-sol.html) on coding tasks. That’s good for users fretting about the cost of their AI agents, but it may be bad for companies building token factories should users not wildly increase their overall token usage with them.Slok worries that if hyperscalers don’t meet their cash-flow goals, the market reaction could be severe — 
“with so much riding on so few names,” he writes, “a slower payoff wouldn’t just be a sector problem, it would risk tipping the economy into recession and the S&P 500 into a correction.”Just something to keep in mind as you’re herding your AI agents toward cheaper tokens.Topics*When you purchase through links in our articles, [we may earn a small commission](https://techcrunch.com/techcrunch-affiliate-monetization-standards/). This doesn’t affect our editorial independence.*
 Senior Reporter
 
Last chance to save up to $190 on TechCrunch Founder Summit. Join 1,000+ founders and VCs at all stages for real-world scaling insights and connections that move the needle.

**Savings end June 26, 11:59 p.m. PT**. [Figma acquires team behind a vibe-coding app](https://techcrunch.com/2026/07/07/figma-acquires-team-behind-a-vibe-coding-app/)

 [If you use Google, you’re training its AI. Here’s how to opt out.](https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/)

 [Reddit is using LLMs to solve a problem LLMs largely created](https://techcrunch.com/2026/07/06/reddit-is-using-llms-to-solve-a-problem-llms-largely-created/)

 [Amazon will stop accepting new customers for Mechanical Turk](https://techcrunch.com/2026/07/05/amazon-will-stop-accepting-new-customers-for-mechanical-turk/)

 [5 desk gadgets that can make your workday better](https://techcrunch.com/2026/07/05/5-desk-gadgets-that-can-make-your-workday-better/)

 [New Google commercial imagines a Declaration of Independence written with help from AI](https://techcrunch.com/2026/07/04/new-google-commercial-imagines-a-declaration-of-independence-written-with-help-from-ai/)

 [Chevy built an all-American EV truck — why is nobody buying it?](https://techcrunch.com/2026/07/03/chevy-built-an-all-american-ev-truck-why-is-nobody-buying-it/)]]></content:encoded>
            <category>OpenAI</category>
        </item>
    </channel>
</rss>