Top stories
Zimbra Releases Critical Security Patches for Classic Web Client
Zimbra has released version 10.1.19 to patch a critical stored XSS vulnerability in its Classic Web Client, which could allow attackers to execute malicious code via crafted emails. Additionally, Zimbra version 10.1.20 addresses multiple vulnerabilities, including command injection and mail forwarding bypass. The updates are crucial to maintain security for users of the Zimbra Collaboration Suite.
SpaceX Launches Starlink V5 Dish with Smaller, Lighter Design
SpaceX unveiled its Starlink V5 residential dish, featuring a reduced size and improved energy efficiency, available in select regions. It allows for maximum speeds of up to 375 Mbps, slightly lower than the V4's 400 Mbps, making it suitable for home internet use. The dish is not for in-motion usage, unlike the upcoming Starlink Mini. This release may lower user costs due to its energy efficiency.
Linus Torvalds Backs AI Tools in Linux Development Amid Community Debate
Linus Torvalds has confirmed his support for using AI tools in Linux development, amid controversy over AI-generated code. He emphasized Linux will not take an anti-AI stance and suggested dissenters fork the project or leave. This stance reflects AI's growing role in open-source projects.
AI Impact on Employment: Older Workers Leaving AI-Exposed Jobs
Research from Boston College indicates older workers in AI-affected industries are leaving jobs more frequently due to automation. This trend suggests potential unemployment, early retirement, or longer careers as AI boosts productivity. The finding adds to broader concerns about AI's influence on job markets, which also includes younger workers facing employment shifts.
Cyclospora Outbreak Linked to Taylor Farms' Iceberg Lettuce Affects Thousands
An outbreak of the Cyclospora parasite in Michigan is linked to iceberg lettuce from Taylor Farms, affecting 3,309 state residents by July 14. Federal investigations traced lettuce served at Taco Bell to a supplier in Mexico. The lettuce recall attempts to halt the spread of this intestinal infection.
HollowGraph Malware Utilizes Microsoft 365 Calendars for C2 Communications
HollowGraph, a new malware, uses Microsoft 365 calendar events dated to 2050 for command-and-control and data exfiltration. This method disguises traffic as legitimate, targeting Israeli entities and linked to Iranian threat actors.
DOJ Seizes Over 1,000 Domains for Illegal World Cup Streaming
The U.S. Department of Justice seized and blocked over 1,000 domains during the World Cup for illegal streaming. This action aims to protect intellectual property and consumers from potential security threats associated with unauthorized streaming sites.
ICE Halts Release of Detention and Deportation Data Amid Controversy
The U.S. Immigration and Customs Enforcement (ICE) has not released its detention and deportation statistics since April, coinciding with increased scrutiny due to recent immigrant shootings by its agents. This lack of transparency has provoked protests and lawsuits, highlighting the growing demand for accountability regarding immigration enforcement actions under the Trump administration.
CISA Issues Guidance on Zero Trust for Critical Infrastructure Security
CISA has released new guidance emphasizing the implementation of Zero Trust principles in critical infrastructure security. This guidance aims to mitigate threats from state-sponsored actors exploiting identity vulnerabilities, especially in operational technology environments.
US military apps found with Chinese and Russian code raise data security concerns
A study found that over 12% of mobile apps aimed at US military personnel contain code from Chinese and Russian companies, increasing risks of data harvesting by adversary nations. This poses potential risks to service members' safety and operational security, particularly as previous investigations highlighted vulnerabilities in location tracking of troops.
New York Imposes One-Year Moratorium on New Large Data Centers
Governor Kathy Hochul has enacted a one-year moratorium on the construction of new data centers with over 50 megawatts of power in New York State. The measure, the first of its kind in the United States, aims to address environmental and energy concerns while the state develops regulatory standards. The decision has sparked political backlash, with critics arguing it may hinder economic growth.
Elon Musk's Grok Imagine to Create 'Historically Accurate' Odyssey Film
Elon Musk announced that his AI platform Grok Imagine will produce a historically accurate adaptation of Homer's Odyssey. This comes after criticism of Christopher Nolan's recent film adaptation, which has performed well at the box office despite Musk's negative comments on casting.
Walmart Discusses Building Agents Using English as Programming Language
Walmart's Jake Mannix discussed the development of LLM-based agents at a conference, emphasizing the use of English as a programming language for building these agents. This shift represents a return to early programming styles, reminiscent of BASIC, and highlights the industry's ongoing evolution in AI agent technology.
US allocates $5bn for AI initiatives across 15 federal agencies
The US government announced a $5bn investment in AI to address scientific challenges across 15 agencies. This initiative aims to enhance drug discovery, chronic disease research, and advanced materials development, leveraging extensive government datasets.
iPhone 18 Pro and Pro Max enter mass production ahead of September launch
The iPhone 18 Pro and Pro Max have begun mass production as assembly partner Foxconn ramps up recruitment and capacity. This production phase includes significant bonuses for returning workers, while the new models are expected to feature upgraded chips and displays but may be thicker and heavier than previous versions.
Meta to implement AMD’s custom Instinct MI450 accelerators with 144GB HBM4 for specific tasks
Meta will utilize custom AMD Instinct MI450 accelerators with 144GB of HBM4, reducing costs for recommendation workloads but limiting versatility in AI training. This shift may lead to significant material savings while relying on Nvidia for training larger models.
2026 Honda Prelude Introduces Hybrid Powertrain After 25 Years
Honda has announced the 2026 Prelude, a hybrid sports coupe featuring a 2.0-liter inline-four and dual electric motors, producing 200 horsepower. It offers a unique In-Line Motor Configuration that allows seamless switching between power sources, achieving high fuel economy ratings of 46 mpg city and 41 highway. This marks Honda's return to the Prelude line after a 25-year hiatus, blending driving fun with advanced hybrid engineering.
Microsoft to end security updates for Exchange 2016/2019 in October 2026
Microsoft will discontinue security updates for Exchange Server 2016 and 2019 in October 2026, as confirmed in a recent blog post. IT administrators are encouraged to upgrade to Exchange Server Subscription Edition to maintain support and receive future updates.
US utility companies pledge to shield consumers from AI-related energy costs
Nearly 200 U.S. utility and data center companies have pledged to protect consumers from rising electricity bills linked to AI. Signed by major firms including NextEra Energy and Google, the pledge lacks enforcement mechanisms, raising concerns over its actual impact.
Cybersecurity Expert Sentenced for Role in BlackCat Ransomware Scams
Angelo Martino, a former ransomware negotiator, has been sentenced to 70 months for aiding the BlackCat ransomware gang. Collaborating with accomplices, he shared confidential negotiation details, causing victims to lose over $75 million. This highlights vulnerabilities within cybersecurity industries.
Critical ServiceNow Flaw Exploited Despite Patch Release
A critical remote code execution vulnerability (CVE-2026-6875) in ServiceNow's AI Platform is being actively exploited, allowing attackers to execute code remotely. Despite the July patches, attacks were observed shortly thereafter. This issue highlights the urgency for self-hosted customers to apply updates promptly to prevent system compromise.
AI Speeds Up Exploit Development Post-Patching, Threatening Cybersecurity
Anthropic's AI, Claude Mythos, can reverse-engineer patches into exploits in under an hour, disrupting traditional timelines for vulnerability exploitation. This significant shift means defenders have far less time to secure systems before attackers can exploit known vulnerabilities, raising serious concerns about the effectiveness of current patching strategies.
Researchers Present Bit2Watt Attack Threatening Power Grids via Cloud GPUs
Three researchers from Zhejiang University revealed the Bit2Watt attack, enabling cloud tenants to destabilize power grids using GPU workloads without requiring exploits. This method poses a significant risk as it leverages legitimate compute functions to create controlled power oscillations that can threaten infrastructure stability.
Nvidia launches Synthetic Video Detector to combat AI-generated misinformation
Nvidia has introduced the Synthetic Video Detector (SVD), an AI microservice that identifies AI-generated videos with up to 92% accuracy. This tool is crucial for media outlets in verifying content authenticity and combating misinformation amid the rise of deepfake technology.
AliExpress Fined €550 Million for Selling Counterfeit and Unsafe Products
AliExpress has been fined €550 million ($629 million) by the European Commission for failing to prevent the sale of illegal and counterfeit products, marking the largest fine under the Digital Services Act. The investigation revealed shortcomings in product verification and removal processes, posing risks to consumer safety. This fine underscores the EU's commitment to stringent e-commerce regulations.
PamStealer Malware Targets macOS for Credential Theft Using Apple's PAM
Researchers have discovered PamStealer, a macOS malware that uses Apple's PAM interface to steal user credentials. This sophisticated malware employs a two-stage delivery system, disguising as the clipboard manager Maccy and utilising stealthy JavaScript for Automation. It highlights emerging threats in macOS security exploiting native Apple frameworks for credential theft.
Google's Final Appeal Over $4.7 Billion EU Antitrust Fine for Android Dismissed
The European Court of Justice upheld a €4.1 billion fine against Google for anti-competitive practices with Android. Multiple appeals failed, ending a lengthy legal battle that highlights strict EU regulation on major tech firms. This ruling emphasizes the need for fair competition and impacts Google's operations in Europe.
HalluSquatting Attack Exploits AI Hallucinations to Form Botnets
The "HalluSquatting" attack exploits AI hallucinations to inject malicious commands into coding assistants, potentially creating botnets. Researchers from Tel Aviv University and other institutions demonstrated that attackers can pre-register fictitious software names generated by AI. AI models' tendency to hallucinate and act on fake package names can expose systems to widespread malware deployment.
Study Finds AI Chatbots Provide Inaccurate Voting Advice
A study by civil liberties group Liberties reveals AI chatbots often give unreliable voting recommendations, misclassifying political parties and omitting relevant options. This raises serious concerns about the efficacy of general-purpose AI systems used in electoral contexts, particularly as AI usage among voters in Hungary is significant.
Violent Online Network '764' Linked to Youth Criminality Across Multiple Countries
A 14-year-old boy in Sweden was linked to an online network called 764, which promotes youth violence and extortion through games like Roblox and Minecraft. This network, founded by a Texas teen, is tied to a growing trend of victims becoming perpetrators under online influence, highlighting systemic issues across global digital communities.
OpenAI Launches New 'GPT-Live' Voice Models for ChatGPT
OpenAI has introduced GPT-Live-1 and GPT-Live-1 mini, two new full-duplex voice models for ChatGPT. These models enable simultaneous listening and speaking, leading to more natural conversations. The upgrade aims to improve user experience by reducing interruptions and enabling features like real-time translation and visual aids.
CERT/CC Reports Hidden Backdoor in Tenda Router Firmware Allowing Admin Access
A vulnerability in various Tenda router firmware versions, CVE-2026-11405, allows unauthorized administrative access via an undocumented backdoor. This flaw poses significant security risks for users as attackers can bypass authentication to control devices remotely. Despite warnings, Tenda has not addressed the issue, leaving affected devices unpatched.
OpenAI Proposes 5% Equity Stake to U.S. Government Amid AI Industry Scrutiny
OpenAI is in early discussions with the U.S. government to potentially sell a 5% equity stake to foster better relations. This proposal may expand to other AI firms like Google and Meta as a way to share AI-driven wealth with the public. The initiative comes amid increasing governmental scrutiny over AI developments and deployment.
Tesla Reports 25% Increase in Q2 2026 Vehicle Deliveries, Exceeding Expectations
Tesla reported a 25% year-over-year increase in vehicle deliveries for Q2 2026, totaling 480,126 units. This represents a recovery in sales after two years of decline, driven largely by strong demand for the Model 3 and Model Y. The growth exceeded Wall Street expectations but did not prevent a subsequent 7% drop in Tesla's stock price.
Codeberg proposes ban on LLM-generated projects in updated Terms of Use
Codeberg is proposing an extension to its Terms of Use that would prohibit projects primarily generated by large language models (LLMs). This change, currently under discussion and pending member vote, aims to address copyright concerns associated with such projects.
Synthesia launches Roleplay Sessions for interactive AI training
Synthesia has introduced Roleplay Sessions, an AI-driven interactive training tool for high-stakes conversations. This shift from video-based training aims to enhance learning through practice and feedback, addressing enterprise needs for measurable AI performance.
Chick-fil-A reports data breach from credential stuffing attacks
Chick-fil-A has alerted customers about a data breach caused by credential stuffing attacks affecting accounts. The breach may involve sensitive information like names, email addresses, and partial credit card numbers.
ChromeOS Rolls Out Critical Security Updates in LTS Versions 144 and 150
Google has released updates for ChromeOS, with LTS-144 (144.0.7559.257) addressing multiple severe vulnerabilities and LTS-150 (150.0.7871.150) extending support continuity. These updates are crucial for reinforcing system security and stability across ChromeOS devices.
Historian Kim Phillips-Fein publishes new book on inequality in America
Historians Kim Phillips-Fein's book "Country of Lords" examines America's historical fight against equality, linking figures from John Adams to modern tech elite. The book highlights concerns over rising economic inequality and its implications for democracy.
23andMe Settles $18 Million Data Breach Case Across 42 States
23andMe will pay $18 million to settle claims from 42 states over a data breach affecting 6.9 million users, including genetic data. The settlement requires enhanced cybersecurity measures and accountability going forward. This settlement follows issues of inadequate data protection and significant delays in breach notifications.