US Government Accuses Chinese AI Firms of Distilling Frontier Models

US Government Accuses Chinese Firms of Illicitly Extracting Capabilities from Top US AI Models In a shocking revelation, the US government has accused several Chinese artificial intelligence (AI) firms of engaging in massive “distillation campaigns” to covertly extract billions of tokens from leading US AI models. The FBI, National Security Agency (NSA), and Cybersecurity and … Read more

Mythos Vulnerability Firehose Hits a Human Bottleneck

A staggering 90% of vulnerabilities discovered by Anthropic’s Claude Mythos AI model have failed to reach the disclosure stage, and only a tiny fraction of those that did have been fixed. This alarming gap highlights a human bottleneck in validating new flaws and coordinating their remediation, rather than in discovering them. The analysis, conducted by … Read more

US Government Accuses Chinese AI Firms of Distilling Frontier Models

US Government Accuses Chinese AI Firms of Stealing Proprietary Capabilities from US Models The US government has accused several top Chinese artificial intelligence (AI) firms of engaging in massive campaigns to extract proprietary capabilities from leading US AI models. The firms, which include Alibaba, DeepSeek, and Moonshot AI, allegedly used a process called distillation to … Read more

Mythos Vulnerability Firehose Hits a Human Bottleneck

Cybersecurity’s Unholy Trinity: Mythos Vulnerability Firehose Hits a Human Bottleneck A new analysis of public data from Anthropic’s Project Glasswing has revealed a disturbing trend in the world of vulnerability research. Despite generating an astonishing 26,153 potential security flaws using its Claude frontier model, only a tiny fraction – less than 10% – have made … Read more

Google warns of new Chrome zero-day bug exploited in attacks

Google has just patched a seventh Chrome zero-day bug this year, with another high-severity vulnerability being actively exploited by attackers. The latest bug, CVE-2026-87491, affects the V8 JavaScript and WebAssembly engine in Google’s Chrome browser, allowing remote attackers to execute arbitrary code inside the web browser’s sandbox via crafted HTML pages. The security update was … Read more

New Microsoft Defender ‘ShieldCrash’ zero-day grants SYSTEM access

A new zero-day exploit has been released by an anonymous security researcher, Nightmare Eclipse, that can grant SYSTEM access on fully patched Windows systems. The exploit, called ShieldCrash, bypasses a previously patched flaw in Microsoft Defender known as ShieldBreak, which itself was a fix for another issue disclosed in June. The ShieldCrash proof-of-concept exploit works … Read more

Man gets 15 years for extorting women with AI-generated porn videos

A notorious cyberstalker has been sentenced to 15 years in prison for extorting women with AI-generated porn videos. James Strahler II, a 37-year-old Ohio man, used advanced artificial intelligence tools to create explicit content featuring his victims’ likenesses without their consent. He then shared these images and videos online, threatening to release them publicly if … Read more

Over 36,000 exposed Plex servers vulnerable to recent flaws

Over 36,000 exposed Plex servers remain vulnerable to recent security flaws, leaving users at risk of potential attacks. The issue affects those running older versions of Plex Media Server, with a total of over 36,000 instances still unpatched and exposed online. Plex issued a warning last week for its users to secure their media servers … Read more

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

A Critical Bluetooth Vulnerability Exposes Skullcandy Earbuds to Hijacking Users of Skullcandy Dime 3 wireless earbuds are at risk of having their devices taken over by attackers thanks to a critical vulnerability in the earbuds’ Bluetooth connectivity. The issue, known as CVE-2025-20701, allows an attacker to connect to a vulnerable device without needing permission from … Read more