Top stories
Critical WordPress Vulnerabilities Exploited, Urgent Patching Advised
Two critical vulnerabilities, CVE-2026-60137 and CVE-2026-63030, in WordPress Core are being actively exploited, affecting versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. These 'wp2shell' flaws allow remote code execution through anonymous requests, prompting WordPress to issue updates 6.9.5 and 7.0.2 on July 17, 2026, with forced auto-updates enabled. Cloudflare has deployed Web Application Firewall protections to mitigate the risk while users apply patches.
US Lifts Export Restrictions on Anthropic's AI Models After Cybersecurity Concerns
The US government has lifted export restrictions on Anthropic's Claude Fable 5 and Mythos 5 AI models after originally imposing them over cybersecurity concerns. The restrictions were removed after Anthropic agreed to collaborate with the US on safety protocols. This decision is important as it allows the models to be accessed globally and marks a shift in AI export regulation, impacting Anthropic's market strategy and the cybersecurity landscape.
U.S. Greenlights Public Rollout of OpenAI's GPT-5.6 Amid Regulatory Controls
The U.S. government has approved OpenAI's GPT-5.6 models for public release on July 9, ending a period of limited access due to regulatory scrutiny. The launch of these models, including Sol, Terra, and Luna, follows compliance with federal cybersecurity reviews intended to manage AI model rollouts. This episode highlights the tension between advancing AI capabilities and the increasing regulatory oversight.
Langflow Vulnerabilities Exploited by AI Agents for Ransomware Attacks
Langflow vulnerabilities CVE-2025-3248 and CVE-2026-55255 are being exploited in separate security incidents. JadePuffer's AI agent uses CVE-2025-3248 for automated ransomware attacks against AI infrastructures, while CISA orders fixes for CVE-2026-55255 affecting government systems.
AI in Enterprises: Systems and Governance as Key Success Determinants
AI in enterprise is reshaping operations across business functions. Success depends on building robust and governed AI systems, as highlighted by multiple reports. Outdated processes and inadequate governance structures pose challenges, while effective frameworks and responsibility-focused systems enhance scalability and integration.
Meta Implements Hybrid AI-Driven Asset Classification for Privacy Infrastructure
Meta has introduced a hybrid asset classification strategy utilizing large language models (LLMs) alongside deterministic rules to improve privacy-aware infrastructure. This approach addresses complex data classifications in AI-native environments, particularly where data inputs are noisy but outputs must be precise for enforcing privacy controls. The strategy signifies Meta's effort to enhance compliance and data governance amidst AI's evolving data landscape.
Moonshot AI Releases Kimi K3, the Largest Open-Source AI Model
Chinese startup Moonshot AI has launched the Kimi K3 model, the largest open-source AI model to date with 2.8 trillion parameters. This model is set to compete with top proprietary AI systems like those from OpenAI and Anthropic, outstripping some in key benchmarks and priced competitively. With the release of Kimi K3's full weights imminent, this represents a significant advancement in the global AI landscape.
Meta updates smart glasses to disable camera if privacy light tampered
Meta is releasing a mandatory update for its smart glasses that disables the camera if the privacy LED is tampered with. This initiative addresses privacy concerns and misuse incidents involving covert recording. The update coincides with reports of new Meta glasses that may continuously record without a privacy light, raising further privacy issues.
Anthropic Launches Reflect Dashboard for Claude and Secure 1Password Integration
Anthropic introduced a Reflect dashboard for Claude, allowing users to analyze their AI usage. Additionally, 1Password has enabled Claude to use credentials securely without exposing them, protecting user data.
Apple Sues OpenAI Over Alleged Trade Secret Theft in Hardware Development
Apple has filed a lawsuit against OpenAI, alleging the AI company stole trade secrets through the hiring of former Apple employees to aid in developing its hardware products. The lawsuit mentions OpenAI's Chief Hardware Officer Tang Tan and former Apple engineer Chang Liu as central figures in the alleged misconduct. This legal conflict signifies ongoing tension and competition in the tech industry regarding intellectual property.
SpaceXAI Launches Cost-Effective AI Model Grok 4.5, Challenging Rivals
SpaceXAI released Grok 4.5, a new AI model built in collaboration with Cursor, focusing on coding and engineering tasks. The model offers improved efficiency and lower costs, presenting a competitive alternative to existing AI models. Grok 4.5's release introduces a pricing strategy that undercuts rivals, influencing the AI market dynamics among enterprise users and developers.
Researcher Releases Windows Zero-Day Exploit 'LegacyHive' Post-Patch Tuesday
Security researcher Chaotic Eclipse released a zero-day exploit for Windows shortly after Microsoft's Patch Tuesday. The exploit, called LegacyHive, targets the Windows User Profile Service and allows privilege escalation on all supported Windows versions. This revelation underscores ongoing security challenges and may necessitate urgent updates from Microsoft.
Cloudflare and Patreon Partner to Block Unauthorized AI Crawlers and Monetize Content
Cloudflare announced updates to their policies and tools, including blocking mixed-use AI crawlers by default from September 15, 2026, to help website owners manage AI traffic and monetize their content. Patreon has joined forces with Cloudflare to block AI crawlers from accessing creator content. The move aligns with industry shifts towards AI-dominated web traffic and aims to protect content owners' intellectual property.
Sony to End Production of Physical PlayStation Discs by 2028, Shift to Digital Only
Sony announced plans to cease production of physical PlayStation game discs by January 2028, transitioning to digital-only distribution. The move aligns with increasing digital game sales but raises concerns over ownership and game preservation.
Critical ServiceNow Flaw Exploited Despite Patch Release
A critical remote code execution vulnerability (CVE-2026-6875) in ServiceNow's AI Platform is being actively exploited, allowing attackers to execute code remotely. Despite the July patches, attacks were observed shortly thereafter. This issue highlights the urgency for self-hosted customers to apply updates promptly to prevent system compromise.
Zimbra Releases Patch for Critical XSS Flaw in Classic Web Client
Zimbra has released an update to patch a critical stored XSS vulnerability in its Classic Web Client, allowing specially crafted emails to execute malicious code if opened. This vulnerability risks exposure to session data, account settings, and mailbox information. Users are urged to upgrade to version 10.1.19 immediately to secure their systems.
NVIDIA Introduces New AI Business Model Offering Revenue Sharing for Cloud Partners
NVIDIA announced a new business model enabling AI cloud partners to share revenue from NVIDIA-powered infrastructure. This move aims to expand AI compute access for startups and other AI companies, reducing barriers for those lacking capital while providing NVIDIA with additional revenue. The initiative highlights a shift in AI infrastructure strategy, offering a new way for businesses to integrate NVIDIA's capabilities.
Amazon Bedrock Enhancements Boost AI Agent Security and Functionality
Amazon Bedrock has introduced multiple features to improve the security, functionality, and efficiency of AI agent deployments. Key updates include resource-based policies for multi-tenant AI applications, central management of AI model access, and new protocols like AG-UI for sophisticated interactions. These enhancements support compliance and operational needs, significant for scalable AI infrastructure.
Linus Torvalds Backs AI Tools in Linux Development Amid Community Debate
Linus Torvalds has confirmed his support for using AI tools in Linux development, amid controversy over AI-generated code. He emphasized Linux will not take an anti-AI stance and suggested dissenters fork the project or leave. This stance reflects AI's growing role in open-source projects.
Study Finds AI Chatbots Provide Inaccurate Voting Advice
A study by civil liberties group Liberties reveals AI chatbots often give unreliable voting recommendations, misclassifying political parties and omitting relevant options. This raises serious concerns about the efficacy of general-purpose AI systems used in electoral contexts, particularly as AI usage among voters in Hungary is significant.
Violent Online Network '764' Linked to Youth Criminality Across Multiple Countries
A 14-year-old boy in Sweden was linked to an online network called 764, which promotes youth violence and extortion through games like Roblox and Minecraft. This network, founded by a Texas teen, is tied to a growing trend of victims becoming perpetrators under online influence, highlighting systemic issues across global digital communities.
Researchers Uncover ClickFix Social Engineering Exploits Fueling Malware Campaigns
Bert-Jan Pals has uncovered a sophisticated method of malware delivery via ClickFix, using API-driven servers to evade detection. The ClickFix tactic manipulates user habits through fake CAPTCHAs, enabling attackers to deliver various malware, impacting Microsoft 365 accounts and Mexican banks. This reveals a growing threat to cybersecurity, exploiting common user behaviors for infiltration.
Alphabet Develops Specialized AI Chip 'Frozen v2' for Enhanced Gemini Efficiency
Alphabet is developing a server chip called 'Frozen v2' to increase the efficiency of Gemini AI models. The new chip, designed for better inference performance, could be 6-10 times more efficient than Google's existing AI chips. This development reflects a trend in producing specialized chips to address AI computational demands and reduce reliance on external hardware providers.
Adobe and CISA Urgently Address Critical ColdFusion Flaws Amid Exploitation
Adobe has released patches to fix critical vulnerabilities in ColdFusion, including CVE-2026-48282, which allow for arbitrary code execution and are actively exploited. CISA has added these flaws to its Known Exploited Vulnerabilities catalog and mandated federal agencies to apply patches immediately. The exploitation underscores the critical need for organizations using ColdFusion to promptly update their systems.
Judge Halts $110 Billion Paramount-Warner Bros. Merger on Antitrust Grounds
A federal judge issued a 14-day restraining order to temporarily halt the $110 billion merger between Paramount Skydance and Warner Bros. Discovery. The lawsuit filed by 12 state attorneys general alleges the merger would significantly reduce competition in theatrical film distribution and cable licensing, potentially harming consumers. The ruling marks an initial victory against the merger approved last month, with a further hearing scheduled for August 3.
SK Hynix Raises $26.5B in Historic U.S. IPO Amid AI Memory Demand
SK Hynix raised $26.5 billion through a Nasdaq IPO, marking the largest-ever U.S. debut for a foreign company. The South Korean chipmaker, capitalizing on AI-driven demand for memory chips, issued American depositary receipts priced at $149 each. This significant capital influx will support expansions to address global memory shortages.
Judge Approves Anthropic's $1.5B Settlement in AI Copyright Case
A federal judge approved Anthropic's $1.5 billion settlement in a copyright lawsuit by authors over unauthorized AI training. The ruling, affirming AI training on copyrighted text as fair use, impacts over 480,000 works. This decision is influential in the AI industry's legal landscape.
UK's water supply insufficient for future datacentre expansion, warns trade body
Water UK has alerted MPs that the UK lacks adequate water resources for future datacentres, contradicting government growth plans. The trade body criticizes the government's failure to address water supply needs in its AI strategy, indicating potential challenges for the tech sector's expansion in water-stressed areas.
US Tech Giants' Hidden Debts Rise to $1.65T Due to AI Investments
Hidden debt among five major U.S. tech firms reached $1.65 trillion, primarily driven by AI funding. This surge complicates risk assessments for investors, as off-balance-sheet liabilities outpace transparent debts.
Apache Spark 4.2 Launches with Native Vector Search and Governed Metrics
Apache Spark 4.2 introduces significant new features including native vector search and governed metrics. This release enhances Spark's capabilities for AI workloads and reduces reliance on separate vector databases, potentially transforming enterprise data processing workflows.
U.S. Executive Order Mandates Post-Quantum Encryption by 2030
President Trump signed Executive Order 14412, requiring federal agencies to transition to post-quantum encryption by December 31, 2030, and authentication by December 31, 2031. This move addresses the imminent threat quantum computing poses to traditional cryptographic systems, stimulating the broader tech industry's shift towards post-quantum technologies.
Meta's AI support assistant exploited for 20,000 account takeovers
Attackers hijacked over 20,000 Instagram accounts using Meta's AI assistant without exploits or password guessing. The assistant confirmed operations based on an interaction, highlighting vulnerabilities of AI agents in authorization processes.
SilverTorch Introduced as a Unified Architecture for Recommendation Systems
SilverTorch is a new retrieval paradigm for recommendation systems that integrates various components into a single neural network. It demonstrates a significant increase in throughput and compute efficiency compared to traditional microservice-based systems, enhancing the quality and speed of recommendations.
Samsung to Launch Galaxy Z Fold 8 and More at July 22 Unpacked Event
Samsung will hold its Galaxy Unpacked event on July 22 in London, showcasing the Galaxy Z Fold 8 series, including a new wider foldable design, and Galaxy Watch 9. The event highlights Samsung's efforts to maintain its lead in foldable smartphones and introduces Flex Titanium display technology. Preorders offer incentives as production focuses on the wider Z Fold 8 model.
Google Pixel 11 Series Leaks Reveal New Colors, Pixel Glow Feature and Pricing
Ahead of its August 12 launch, Google's Pixel 11 series leaks reveal new color options like 'Pine' and 'Fuchsia' and introduce the 'Pixel Glow' feature, a multi-colored LED light integrated in the camera bar. The leaks include design changes for the Pixel 11 Pro Fold with a narrower camera bar and price increases of approximately €100. This matters as Google shifts its strategy in the competitive smartphone market.
Oshkosh Cancels Flock Safety Contract After False Statements by Company
The Oshkosh City Council revoked its contract with Flock Safety after the company falsely claimed its ALPR system did not create heat maps of vehicle movements. This incident highlights a broader pattern of misleading statements from Flock regarding its technology and privacy practices, raising significant concerns over its credibility in the law enforcement technology sector.
OpenAI Launches $230 Codex Micro Keyboard for AI Coding Assistants
OpenAI has introduced the Codex Micro, a $230 RGB-lit mini-keyboard designed in collaboration with Work Louder to enhance user interaction with Codex AI agents. The device features color-coded keys for live feedback, a joystick, and rotary controls to streamline coding tasks. The Codex Micro represents OpenAI's first foray into branded hardware as the company faces a separate legal battle with Apple.
FCC Fines and Plans Ban on DJI-Tech Disguised Products Citing National Security
The FCC has fined eight companies $25,000 each for not responding to inquiries about their use of DJI technology. The Commission plans a retroactive ban on their drones and cameras, given concerns over evading foreign drone bans. This crackdown reflects national security concerns involving disguised DJI tech in the US.
Meta Faces $1.4 Trillion in State Lawsuits and EU Fines for Addictive Social Media Designs
Meta is facing potential penalties from four US states totaling $1.4 trillion due to alleged addictive features on Facebook and Instagram. Additionally, the EU has accused Meta of breaching the Digital Services Act with these features, threatening fines up to 6% of its global annual turnover. The cases highlight concerns about the mental and physical wellbeing effects of Meta's platforms on users, particularly minors.
AliExpress Fined €550 Million for Selling Counterfeit and Unsafe Products
AliExpress has been fined €550 million ($629 million) by the European Commission for failing to prevent the sale of illegal and counterfeit products, marking the largest fine under the Digital Services Act. The investigation revealed shortcomings in product verification and removal processes, posing risks to consumer safety. This fine underscores the EU's commitment to stringent e-commerce regulations.