βοΈChatbots are obliged to tell users they aren't human, deepfakes must be labelled and AI outputs must carry machine-readable marks, all starting this Sunday as the EU's AI Act becomes enforceable.
Europe can fine up to β¬15M or 3% of global turnover.
https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1714
Europe can fine up to β¬15M or 3% of global turnover.
https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1714
π₯23π©9β€1π1π€1
This media is not supported in your browser
VIEW IN TELEGRAM
π¨ EXCLUSIVE: ICD reconstructed the largest verified COLDCARD theft on-chain: 594.48 BTC drained from 500 addresses in 15 minutes and 18 seconds.
The attacker exploited a vulnerability by rebuilding COLDCARD's faulty seed generator on their own machine, produced the limited set of seeds it could ever have made, derived the Bitcoin addresses for each one, and checked them against the public blockchain. Every funded match was a live wallet, and the key to it.
The flaw: a March 2021 build error left COLDCARD building seeds from predictable device and clock values instead of true randomness, shrinking the pool of possible seeds from astronomical to searchable, about 40 bits on an Mk3, where 128 was intended. The PIN, the air gap and the secure element were all guarding a key that could be recreated from scratch.
Largest verified sweep: 594.48 BTC from 500 addresses in four blocks on 30 July, all it took was 15 minutes 18 seconds by block timestamps.
https://mempool.space/address/bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
The attacker exploited a vulnerability by rebuilding COLDCARD's faulty seed generator on their own machine, produced the limited set of seeds it could ever have made, derived the Bitcoin addresses for each one, and checked them against the public blockchain. Every funded match was a live wallet, and the key to it.
The flaw: a March 2021 build error left COLDCARD building seeds from predictable device and clock values instead of true randomness, shrinking the pool of possible seeds from astronomical to searchable, about 40 bits on an Mk3, where 128 was intended. The PIN, the air gap and the secure element were all guarding a key that could be recreated from scratch.
Largest verified sweep: 594.48 BTC from 500 addresses in four blocks on 30 July, all it took was 15 minutes 18 seconds by block timestamps.
https://mempool.space/address/bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
π€―7π3π’2π€£2
βΌοΈ BREAKING: Google is pulling Nano Banana image generation from Google Earth a day after launch.
Users created prompts to generate images showing a plane hitting a Manhattan skyscraper, a bombing in Moscow, a nuclear plant in Iran, refugees at the USβMexico border and a bomb crater in Los Angeles.
Google says it's building "stronger guardrails."
Users created prompts to generate images showing a plane hitting a Manhattan skyscraper, a bombing in Moscow, a nuclear plant in Iran, refugees at the USβMexico border and a bomb crater in Los Angeles.
Google says it's building "stronger guardrails."
π30
βοΈMeta's smart glasses could be banned in Germany and the rest of the EU.
Hamburg data protection commissioner Thomas Fuchs, Meta's lead regulator in Germany, says his office tested the glasses, found the recording LED too easy to miss, and concluded that filming people in public with them breaks data protection law. It is already issuing fines.
His verdict: a camera disguised as an everyday object is illegal to sell or own in Germany. Only the Bundesnetzagentur can order that ban; it is reportedly reviewing.
France's CNIL warned about the whole category in May, and the European Data Protection Board's report on smart glasses is due this summer.
Hamburg data protection commissioner Thomas Fuchs, Meta's lead regulator in Germany, says his office tested the glasses, found the recording LED too easy to miss, and concluded that filming people in public with them breaks data protection law. It is already issuing fines.
His verdict: a camera disguised as an everyday object is illegal to sell or own in Germany. Only the Bundesnetzagentur can order that ban; it is reportedly reviewing.
France's CNIL warned about the whole category in May, and the European Data Protection Board's report on smart glasses is due this summer.
β€26π₯17π€£4π2π©2
βΌοΈ Applicants are using hidden prompt injections in rΓ©sumΓ©s.
ManpowerGroup finds concealed text in 100,000 applications a year. Now a Stanford postdoc hiring a lab tech has found 2.25pt white-font commands ordering the screener to advance the applicant and stay silent about it.
ManpowerGroup finds concealed text in 100,000 applications a year. Now a Stanford postdoc hiring a lab tech has found 2.25pt white-font commands ordering the screener to advance the applicant and stay silent about it.
β€18π€£9π7π2π2
βοΈ Y Combinator has told flight startup Soar to strip the YC logo off an ad truck in San Francisco.
The screens read "scan for instant acceptance into" beside YC's logo. Scanning it opened the flight website and a $50 flight credit.
YC legal chief Carolynn Levy told the founder he has no permission to use the mark and demanded written confirmation the same day.
The screens read "scan for instant acceptance into" beside YC's logo. Scanning it opened the flight website and a $50 flight credit.
YC legal chief Carolynn Levy told the founder he has no permission to use the mark and demanded written confirmation the same day.
π₯4
βΌοΈ BREAKING: More than 100,000 UK police officers and staff have had their full names, contact details and force locations leaked on the dark web after a hack on the national police legal database.
MoD, Home Office, NCA and CPS staff are also exposed. One officer says the leak "puts officers at serious risk."
MoD, Home Office, NCA and CPS staff are also exposed. One officer says the leak "puts officers at serious risk."
π€£22π₯°4β€3π2π1π1
βΌοΈ UPDATE: Arch Linux has now disabled ALL pushes to the Arch User Repository (AUR) as it fights malware.
No AUR package can be updated while the team hunts malicious commits.
No AUR package can be updated while the team hunts malicious commits.
π10π€4π₯2π―2
βοΈ The slopocalypse is real. MITRE published a critical SQLite vulnerability with a CVSS of 10.0 that does not exist. Turns out it was hallucinated by an LLM. SQLite's Richard Hipp says dozens more fake CVEs were filed.
CVE-2026-51302 was assigned on 27 July. CISA's enrichment programme then scored it critical and flagged a public proof-of-concept. The Dutch National Cyber Security Center republished it as an advisory, and has now withdrawn it, saying the "vulnerability" was most likely hallucinated by an LLM.
CVE-2026-51302 was assigned on 27 July. CISA's enrichment programme then scored it critical and flagged a public proof-of-concept. The Dutch National Cyber Security Center republished it as an advisory, and has now withdrawn it, saying the "vulnerability" was most likely hallucinated by an LLM.
β€8π€ͺ2