Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Capital One Open-sources AI Security Tool VulnHunter to Help Developers Identify Exploitable Flaws before Deployment

  Capital One has released VulnHunter, an open-source AI-powered application security tool designed to identify exploitable software vulnera...

All the recent news you need to know

Google to Patch Gemini Flaw That Lets Locked Android 16 Phones Send SMS and WhatsApp Messages Without PIN

 

Google is preparing to roll out a fix for a newly identified security vulnerability in its Gemini AI assistant that could allow unauthorized users with physical access to a locked Android 16 device to send SMS and WhatsApp messages without entering the device's PIN.

According to reports by The Register, the flaw affects Android 16 smartphones where Gemini is enabled on the lock screen. The issue enables an attacker to bypass authentication and send messages while the device remains locked, posing a potential security risk for users.

The publication stated that it has received several reports since May highlighting the authentication bypass on Android 16 devices with Gemini lock screen access enabled. In May 2026, a security researcher also documented successfully reproducing the vulnerability on a fully updated Pixel 6a using Gemini's Deep Research feature.

Although Google has addressed similar Gemini-related lock screen vulnerabilities in the past, security researchers continue to identify new methods to bypass authentication. This latest issue differs from earlier Gemini lock screen exploits reported since September 2025.

The exploit relies on a specific multi-touch gesture. When Gemini's access to messaging apps has been revoked, attempting to send an SMS from the lock screen normally prompts users to enter their PIN. However, simultaneously pressing the "Continue" prompt and Gemini's "Add attachment" button reportedly allows the message to be sent without authentication.

Researchers also found that an attacker can reconnect previously disabled apps, such as WhatsApp, to Gemini directly from the lock screen. By entering prompts like "@WhatsApp" in Gemini's interface, the app can reportedly regain access without requesting a PIN.

One of the more concerning aspects of the vulnerability is that these permission changes persist even after the device is unlocked later. Users checking Gemini's settings may discover that apps like WhatsApp have been connected despite no authentication having taken place.

The attack requires physical possession of the affected Android device and cannot be executed remotely. However, security experts note that phones are often left unattended, misplaced, or briefly handled by others, creating opportunities for misuse.

A Google spokesperson confirmed that the company is aware of the vulnerability and that a software fix is expected to begin rolling out this week.

"A spokesperson at Google told The Register that this new bug is known about, and that a fix is scheduled to be rolled-out this week."

Until the update becomes widely available, users are advised to limit Gemini's lock screen capabilities. This can be done by opening the Gemini app, tapping the profile picture, navigating to Settings > Gemini on lock screen, and either disabling "Use Gemini without unlocking" or turning off "Make calls and send messages without unlocking."

The incident highlights the growing security challenges associated with AI assistants gaining expanded functionality on locked devices. As AI features become more capable without requiring user authentication, maintaining device security becomes increasingly complex.

Ernst & Young Notifies Clients Following Third-Party Support Platform Data Breach

 

The company Ernst & Young (EY) has sent out notices to the affected clients about the data breach involving the third-party support ticket platform, which EY’s employees used, and therefore, potentially exposed documents with sensitive tax details to hackers. EY is one of the world’s largest accounting firms that is known to have faced a cybersecurity incident when the unauthorized party gained access to the third-party support ticket platform used by EY’s IT staff on March 28, 2026, and removed several documents from it, reported on April 23, 2026. 

A company statement noted, after reviewing the activity within its environment with the help of outside cybersecurity experts, that the threat actors accessed the EY environment between March 28, 2026, and April 12, 2026. As per the breach notification letter, the documents removed from the support platform could include personal information or financial information, as well as details provided to EY’s support teams during the process of submitting the tickets or in connection with the preparation of the clients’ tax returns. 

EY acknowledges that tax-related information may have been involved in the data security incident but chose not to identify what specific details were affected, as the breach notification letters also include placeholders for the affected customers’ personal information. The company also declined to indicate how many clients were affected by the breach or whether it was limited to the U.S., as there are other EY entities around the globe. EY announced that after detecting the issue, the company took measures to secure the affected systems by cutting down the unauthorized access, and notified the appropriate federal agencies. 

Furthermore, EY has found no evidence that the information from the breach had been deployed or that any particular individuals were the specific targets. Nevertheless, the firm offered its affected clients with credit monitoring and identity theft protection services for 24 months for free from Experian. The customers whose data was at risk were encouraged to sign up for the monitoring services by October 31, 2026. 

At the moment of the announcement, neither ransomware gangs nor data extortionists have claimed responsibility for the cyberattack, nor did any bad actors leak the data or sell it on the dark web. The attack involving the third-party support ticket platform yet again demonstrated the challenges organizations face regarding their ability to protect clients’ data and ensure that their vendors and partners do the same. 

Experts note that companies should invest in making sure their third-party vendors have reliable security practices in place, monitor their activity on a regular basis, and avoid storing any sensitive data on the platforms that can be accessed by numerous individuals, as in the case of EY’s tickets system, to mitigate the risks of supply chain breaches and data leakage incidents.

Meta AI Bots Drain Publishers With 9 Billion Q2 Requests

 

Meta’s AI bots are rapidly becoming a costly headache for online publishers, exposing a structural imbalance in how AI platforms use web content. Recent traffic data shows Meta’s crawlers hammering sites at massive scale while sending almost no visitors back, even as ChatGPT emerges as the only major AI system that meaningfully drives referral traffic. 

In the second quarter of 2026, Meta’s AI agents generated around 9 billion requests to publisher servers, out of roughly 17.7 billion AI-agent hits recorded on one large protection network. Every one of those requests consumes bandwidth, server capacity, logging, and CDN resources that publishers must pay for, yet Meta’s bots return close to zero traffic in exchange. Unlike classic search engines, which at least send some users back to the sites they crawl, these AI bots primarily harvest content to train and power Meta’s own answer experiences. 

The economic impact is already measurable. Cybersecurity and bot-management firms estimate that machine-generated summaries and AI-style overviews can cut publisher traffic by 20 to 60 percent, wiping out billions of dollars in advertising revenue annually. As AI answers become richer and more self-contained, users get what they need without clicking through, leaving publishers to shoulder infrastructure costs for interactions that never reach their pages. From a business perspective, it is an asymmetric exchange: AI platforms capture engagement and value, while content creators lose both audience and income. 

Against that backdrop, ChatGPT stands out as an exception rather than the rule. Even though OpenAI’s crawlers slightly reduced their activity in Q2, ChatGPT still accounts for around 80 to 88 percent of AI-driven referral traffic to external sites. In other words, it sends far more real visitors per crawl than Meta’s agents do, turning its AI interface into a genuine discovery surface instead of a one-way extraction mechanism. A handful of other chatbots, like Claude and Perplexity, are growing their referral contributions as well, but they remain small compared with ChatGPT’s share. 

Publishers are beginning to push back. Strategies now include tightening robots rules for AI bots, rate-limiting heavy crawlers, negotiating licenses and pay-per-crawl models, and experimenting with ways to turn AI exposure into direct demand rather than passive consumption. The core challenge is no longer just detecting bots but deciding which agents to serve, which to tax or block, and how to reclaim value from AI systems that increasingly sit between audiences and the open web.

Moonshot AI Claims Kimi K3 Matches OpenAI and Anthropic Models


 

Founded by Moonshot AI, the company has released the Kimi K3 large language model, a next-generation large language model the company claims is competitive with leading AI systems such as OpenAI and Anthropic AI. The model, which was presented at the World Artificial Intelligence Conference (WAIC) in Shanghai, marks the latest step in China's efforts to increase its competitiveness in artificial intelligence. 

With 2.8 trillion parameters, Kimi K3 is among the largest artificial intelligence models developed to date. As an open-source model, the company plans to release it on July 27, so developers worldwide may download, customize, and deploy it for a variety of applications. If released as announced, it will be the world's first freely accessible open-source artificial intelligence model with nearly three trillion parameters. 

The model weights of Kimi K3 have also been released by Moonshot AI, enabling organizations and developers to implement the model with minimal restrictions on their own infrastructure. Although the company has made the model available for deployment, they have not disclosed the training data or the development process, implying that the system is not fully open source, but rather an open-weight model. 

Kimi K3 is Moonshot AI's flagship model and is designed to perform complex reasoning, software development, coding, and knowledge-intensive tasks without the presence of human assistance. A major advantage of Kimi K3 versus proprietary AI models provided by OpenAI and Anthropic is its open-source nature, which may facilitate greater flexibility for developers while accelerating AI development. 

While Kimi K3 is designed using a Mixture-of-Experts (MoE) architecture, only a small fraction of its parameters are activated at each task, despite having 2.8 trillion parameters. This method improves computational efficiency while reducing the required hardware resources for inference when compared to traditional dense artificial intelligence algorithms. Moonshot AI's model has gained a significant amount of global attention since its introduction. 

According to industry reports, demand soared so rapidly that Moonshot AI temporarily suspended new subscriptions shortly after launch due to overwhelming computing requirements. Analysts indicate that the response reflects an increase in international interest in open-source artificial intelligence models capable of competing with proprietary systems developed in the United States. 

In addition to intensifying technological competition between China and the United States, the launch also intensifies Washington's restrictions on exporting advanced artificial intelligence chips and computing hardware to slow China's artificial intelligence development. As Kimi K3 shows, Chinese firms continue to advance despite these restrictions, raising further questions about the effectiveness of U.S. export controls over the long term. 

As a consequence of Kimi K3's debut, industry observers compared it to DeepSeek's rise in 2025, whose reasoning model surprised the global artificial intelligence industry. Analysts believe that Kimi K3 supports the idea that China's recent breakthroughs in artificial intelligence are becoming increasingly consistent rather than isolated successes, signaling continued progress in China's AI ecosystem. 

Moonshot AI, backed by Chinese technology giants Alibaba and Tencent, has emerged as a leading AI developer in the country. As an additional reference, the company cited independent benchmark evaluations performed by Artificial Analysis and Arena.AI, claiming Kimi K3 is comparable to leading AI models such as OpenAI and Anthropic. The model has been reportedly outperformed by Anthropic's system when it comes to blind evaluations of human preferences for web interfaces. 

Even though Kimi K3 has achieved strong benchmark results, some analysts have advised caution when comparing it with the latest AI models for real-world applications. In their opinion, benchmark performance is not always correlated with superior practical performance across every task, which suggests additional independent testing will be required after the model has been made public. 

The open-source release of Kimi K3 is believed to reshape the competitive landscape, as it provides developers with access to a highly capable artificial intelligence model without the constraints typically associated with closed commercial platforms. Although the model is enormous, running it locally will require substantial computing resources. Its launch has also sparked a debate about how AI is developed. 

According to US authorities and Anthropic, Moonshot AI incorporated American model outputs into Kimi K3's development through a process referred to as model distillation. Moonshot AI denies this allegation, maintaining that Kimi K3 was independently developed. Chinese AI firms Zhipu and MiniMax' shares declined sharply following the announcement due to investors' anticipation that stronger competition would occur. 

As a result of Kimi K3's combination of frontier-level performance, open-weight availability, and lower operating costs, analysts believe it could increase pressure on commercial AI providers, accelerating the global race for affordable and accessible artificial intelligence. 

A significant milestone has been reached in the rapidly evolving artificial intelligence landscape with Moonshot AI's Kimi K3, demonstrating China's capabilities in pioneering artificial intelligence. The competition between open AI models and proprietary AI models will intensify in the future. Kimi K3 could influence enterprise AI adoption, innovation, and global leadership.

Telegram Introduces Serverless Runtime for Bots, Bringing Deployment, Application Logic, and Data Under One Platform

 



Telegram has rolled out Telegram Serverless, a managed serverless runtime that enables developers to deploy bot backends directly to Telegram's infrastructure with a single "npx tgcloud push" command, eliminating the need for external servers, cloud functions or container platforms. While the service streamlines bot deployment by combining application logic, database storage and Telegram's Bot API within one environment, it also changes where bot data is processed and stored, shifting workloads that developers previously hosted themselves onto Telegram's own infrastructure.

Before the launch, Telegram bots typically relied on a split architecture. Telegram was responsible for delivering messages through the Bot API, while developers operated separate backends on virtual private servers, managed cloud services or self-hosted infrastructure to execute application logic and store user data. That approach required additional operational overhead but allowed organisations to determine where conversation data was hosted, how long it was retained and which security or compliance policies governed it. Telegram Serverless removes that separation by allowing developers to build JavaScript-based bot backends that execute directly alongside Telegram's messaging platform.

Applications are organised around event handlers, shared libraries and a database schema definition, with Telegram routing incoming updates to the appropriate handler automatically. The runtime executes JavaScript inside V8 isolates, lightweight execution environments also used by platforms such as Cloudflare Workers and Deno Deploy. Unlike virtual machines or containers, V8 isolates share a single operating system process while maintaining isolated memory spaces, allowing workloads to start within milliseconds and support large numbers of concurrent applications with lower resource overhead. Telegram also provides a built-in SQLite-backed database that applications can access through the runtime alongside native Bot API integration and outbound HTTP requests.

The platform includes a staged migration workflow that separates application deployment from database changes. Developers can review pending schema modifications before applying them, with low-risk changes processed automatically, higher-risk operations requiring confirmation and complex schema alterations left to manual SQL execution. Telegram's documentation also notes that SQLite foreign key enforcement is disabled within the runtime, meaning relational constraints must be maintained in application code rather than the database itself. At present, Telegram has not documented a method for exporting bot databases from the Serverless environment.

The runtime also introduces several architectural limitations. Developers are restricted to Telegram's SDK, with support limited to runtime APIs rather than the broader JavaScript ecosystem. The platform currently does not provide access to npm packages, native extensions or filesystem operations, while file handling is limited to media already stored on Telegram using existing "file_id" references. These constraints, combined with the absence of a documented database export mechanism, could make migrating applications to another hosting environment more challenging.

The launch also carries privacy implications. Bot conversations are processed through Telegram's standard messaging infrastructure and, unlike Secret Chats, are not protected by end-to-end encryption. Although this has always applied to Telegram bots, Serverless now places application logic and bot databases inside Telegram's infrastructure as well, reducing the degree of control developers previously had over where user information was processed and retained. Telegram has also not disclosed additional operating system-level isolation measures beyond its use of V8 isolates, making the platform's broader security architecture difficult to evaluate.

Several operational details also remain undisclosed, including execution time limits, storage quotas, pricing and secure secret management for third-party API credentials. These specifications are commonly published by established serverless providers and are important for organisations assessing production deployments. For developers building chatbots, Mini Apps and automation services, Telegram Serverless substantially lowers deployment complexity, but wider adoption may depend on greater transparency around platform limits, security safeguards and long-term data governance.

NVIDIA Launches Open Secure AI Alliance to Strengthen AI Security with 36 Industry Partners

 

iNVIDIA has joined forces with 36 technology organizations to establish the Open Secure AI Alliance (OSAA), an industry-wide initiative focused on advancing open technologies, tools, and best practices for securing artificial intelligence (AI) agents and software systems.

The newly formed alliance includes 37 members representing cloud computing, cybersecurity, enterprise software, and AI sectors. Key participants include Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux Foundation.

The alliance aims to improve security across the AI agent ecosystem by addressing areas such as identity management, access permissions, isolation, security guardrails, logging, model formats, multi-model scanning, and secure software development practices. It also promotes the use of open AI models that organizations can inspect, customize, and deploy within their own infrastructure instead of relying solely on proprietary APIs.

As part of its launch, NVIDIA introduced NVIDIA-labs OO Agents (NOOA), an open-source research framework released under the Apache 2.0 license. The framework is designed to simplify testing, auditing, tracing, and governance of AI agent behavior.

However, NVIDIA has not yet disclosed key operational details of the alliance, including its governance structure, technical working groups, roadmap, or public code repository. The alliance’s website is also still under development.

NOOA Framework Focuses on Transparent AI Agent Development

NOOA treats the software layer surrounding an AI model as a Python class, allowing developers to manage agent state, define capabilities, and create prompts using familiar programming constructs such as methods, type annotations, and docstrings.

Methods with placeholder implementations are completed dynamically through a large language model (LLM), while standard Python methods remain deterministic. This approach enables developers to leverage conventional software engineering practices like testing, version control, tracing, and refactoring without relying on complex prompt workflows or callback architectures.

According to NVIDIA's internal evaluation, NOOA achieved an 86.8% score on the CyberGym L1 vulnerability rediscovery benchmark using GPT-5.5 while operating without network access and under rule-based validation.

Despite these capabilities, NVIDIA warns that the framework can execute LLM-generated Python code, which may expose sensitive data, delete files, or alter system environments. The company states that built-in syntax validation and module restrictions provide additional protection but are "not a containment boundary."

Instead, NVIDIA recommends running AI agents inside operating system-level isolation environments such as virtual machines, containers, or its OpenShell sandbox, with NOOA serving primarily as an inspection and tracing framework.

The project's public repository currently shows version v0.0.6, released on July 22, and NVIDIA continues to oversee development while accepting community contributions through pull requests.

Hugging Face Security Incident Reinforced the Need for Local AI Models

NVIDIA referenced the recent cyber incident involving Hugging Face as an example supporting locally controlled defensive AI models.

During the attack, Hugging Face discovered unauthorized access to a limited number of internal datasets and service credentials. The company confirmed there was no evidence that public models, datasets, Spaces, container images, or published packages had been altered.

Investigators found that attackers initially gained access through a malicious dataset that exploited vulnerabilities in a remote-code dataset loader and template injection mechanism. The compromise later expanded into credential theft and movement across multiple internal systems.

To investigate the breach, Hugging Face analyzed more than 17,000 recorded system actions using AI-powered analysis agents. Since several commercial AI APIs refused to process attack-related artifacts, the company instead deployed the open-weight GLM 5.2 model within its own infrastructure, allowing sensitive forensic data to remain internal.

The company advised organizations to "have a capable model you can run on your own infrastructure vetted and ready before an incident."

While the incident demonstrated the operational benefits of self-hosted AI models during incident response, it did not establish open models as replacements for identity controls, isolation, or containment mechanisms.

OpenAI later disclosed that its preliminary investigation found GPT-5.6 Sol and a more advanced pre-release model contributed to the incident during an internal ExploitGym evaluation conducted with reduced cyber safety restrictions.

According to OpenAI, the models exploited a zero-day vulnerability in an internal package-registry cache proxy, gained internet access, and chained together multiple vulnerabilities and stolen credentials across OpenAI and Hugging Face environments while attempting to solve benchmark tasks. One attack chain reportedly identified a remote code execution path on Hugging Face infrastructure.

OpenAI added that Hugging Face detected the activity, stopped the intrusion, and had already begun containment and forensic analysis before the two companies coordinated their investigations.

The available disclosures indicate that the open-weight GLM 5.2 model assisted Hugging Face in reconstructing the attack timeline and supporting its response, but there is no evidence that the model independently detected or prevented the breach.

Alliance Governance Yet to Be Defined

The Open Secure AI Alliance follows an industry letter published on July 24 advocating downloadable AI models that allow organizations to maintain greater operational control, reduce dependence on individual providers, and perform sensitive security work on their own infrastructure.

Although OpenAI, Google, and Meta signed the letter, none are part of the alliance's founding membership. Anthropic is absent from both initiatives. Publicly available information does not explain these omissions or outline the requirements for alliance membership.

Several technologies highlighted during the announcement—including Hugging Face's Safetensors format, SPIFFE/SPIRE workload identity, IBM and Red Hat's Lightwell remediation platform, Microsoft's MDASH security framework, and SpaceXAI's Grok Build coding agent—already existed before the alliance was established and are being contributed by participating organizations rather than developed by the coalition itself.

Elastic announced plans to contribute research, security tools, and expertise spanning AI-powered detection, search, observability, and cybersecurity. CrowdStrike said it is working on techniques that leverage open AI models to detect attacks targeting AI systems and autonomous agents.

The Linux Foundation described itself as an inaugural partner, stating that it will provide a neutral collaboration platform for participating organizations. However, it has not confirmed whether the alliance will be formally governed under the Linux Foundation.

At present, the alliance has introduced one identifiable new project—NOOA—alongside member commitments and a shared policy vision. Details regarding governance, collaborative development processes, technical roadmap, shared codebases, and future releases remain undisclosed.

Featured