βΌοΈ Meta confirms its AI model Muse hacked an outside company during a safety evaluation. The Information names the model as Muse Spark 1.1, Meta's flagship coding release, and reports it made changes inside the victim's systems.
Three AI labs in two weeks have now disclosed that their own models broke into real companies during testing: OpenAI, Anthropic, and, as of Wednesday, Meta. All three ran evaluations through the same vendor, Irregular, which says the Meta case is the identical environment issue Anthropic reported.
Three AI labs in two weeks have now disclosed that their own models broke into real companies during testing: OpenAI, Anthropic, and, as of Wednesday, Meta. All three ran evaluations through the same vendor, Irregular, which says the Meta case is the identical environment issue Anthropic reported.
π©39π€£6
Meta approved and ran more than 50 paid AI-generated child sexual abuse material ads for nudify apps, for over nine months.
Meta's own ad library shows it pulled an ad from a Facebook page for breaching its policy on child sexual exploitation, abuse and nudity β then let that page run 340 more ads...
The page is one of 210 the Tech Transparency Project tied to GatherOne, a Chinese agency Meta authorises to sell its advertising. Its other ads showed a childlike figure in lingerie in a submissive pose.
https://www.techtransparencyproject.org/articles/metas-chinese-partner-behind-deluge-of-nudify-ads
Meta's own ad library shows it pulled an ad from a Facebook page for breaching its policy on child sexual exploitation, abuse and nudity β then let that page run 340 more ads...
The page is one of 210 the Tech Transparency Project tied to GatherOne, a Chinese agency Meta authorises to sell its advertising. Its other ads showed a childlike figure in lingerie in a submissive pose.
https://www.techtransparencyproject.org/articles/metas-chinese-partner-behind-deluge-of-nudify-ads
π€¬25π©8β€2π¨1
βοΈ Apple pushed an out-of-band macOS patch: a Screen Sharing vulnerability let an attacker on the network authenticate without valid credentials.
Dubbed CVE-2026-65400, fixed in Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.
https://support.apple.com/en-us/148170
Dubbed CVE-2026-65400, fixed in Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.
https://support.apple.com/en-us/148170
β€3
This media is not supported in your browser
VIEW IN TELEGRAM
βΌοΈ BREAKING: A critical WordPress Core vulnerability, which was found with open-weight LLMs, has been patched. It's a pre-auth XSS to remote code execution chain affecting every version of WordPress ever shipped.
Type a fake username, and WordPress prints it back in the error message. Add one space in the right place and WordPress prints it back as working code instead of text, no account needed.
pwn ai rode it to PHP execution on the server. CVE-2026-64638. Patched in WordPress 7.0.3.
https://pwn.ai/blog/xss2shell
Type a fake username, and WordPress prints it back in the error message. Add one space in the right place and WordPress prints it back as working code instead of text, no account needed.
pwn ai rode it to PHP execution on the server. CVE-2026-64638. Patched in WordPress 7.0.3.
https://pwn.ai/blog/xss2shell
π¨12β€4π4π₯1π€1
We're taking a day off to touch some grass, since X has locked us out. They want us to remove the Scam Altman post, but we refuse to do so. So we filed an appeal. -> Turns out it can take weeks, so we just deleted the post.
Feel free to support us so we can keep on doing independent reporting on big tech and governments: https://www.internationalcyberdigest.com/donate/
Feel free to support us so we can keep on doing independent reporting on big tech and governments: https://www.internationalcyberdigest.com/donate/
International Cyber Digest
Donate
If you like our work and you want to support our independent reporting, you can send XMR [Monero] to the following address:
85MiGK57DfAT7NvrBV5uKygrLiMxiGobXA6fTJMXm9Cc86CsxaCJev1RvYe2nSQZQnTBMxihZQpktVED6p4evGH64xQDtg1
85MiGK57DfAT7NvrBV5uKygrLiMxiGobXA6fTJMXm9Cc86CsxaCJev1RvYe2nSQZQnTBMxihZQpktVED6p4evGH64xQDtg1
5π₯27β€13π₯°3π€¬3
A Redditor got so annoyed by the camera bump on his brand-new Galaxy Z Fold8 that he took a razor blade to it and removed the cameras entirely.
The camera island turns out to be a separate piece held on with adhesive, so it peeled off cleanly. He covered the gap with an old laptop skin trimmed to size.
The module is still intact, as he says he can put it back.
https://www.reddit.com/r/GalaxyFold/comments/1vif2zl/i_took_the_cameras_off_of_my_fold_8/
The camera island turns out to be a separate piece held on with adhesive, so it peeled off cleanly. He covered the gap with an old laptop skin trimmed to size.
The module is still intact, as he says he can put it back.
https://www.reddit.com/r/GalaxyFold/comments/1vif2zl/i_took_the_cameras_off_of_my_fold_8/
π€£20β€2π₯2
Someone says he accidentally opened an ATM while trying to turn it on. He just poked around and a door swung open, revealing the hardware that runs the machine.
π19π€£12π4π₯1π1
βοΈProton lied about A/B testing prices. Its VPN General Manager told Reddit users that the varying VPN Plus prices were leftovers from a sale that hadn't "universally refreshed."
Proton's own page source says otherwise: a meta tag, ab-test, sorts each visitor into variant A or B β B served from a separate /pricing-test URL.
$2.77/mo in one session. $3.23/mo in the next.
A/B testing prices is ordinary e-commerce. Amazon does it. Airlines do it hourly. Almost nobody would have cared.
But Proton sells privacy and trust, and criticises "big tech". That means you don't get to act as unfair like big tech does ;-)
Proton's own page source says otherwise: a meta tag, ab-test, sorts each visitor into variant A or B β B served from a separate /pricing-test URL.
$2.77/mo in one session. $3.23/mo in the next.
A/B testing prices is ordinary e-commerce. Amazon does it. Airlines do it hourly. Almost nobody would have cared.
But Proton sells privacy and trust, and criticises "big tech". That means you don't get to act as unfair like big tech does ;-)
π€¬17π©7π7
βοΈNew Signal code suggests they're adding a paid feature for people who don't want to register with a phone number. This comes after their CTO Ehren Kret said that Signal was looking for a way to induce a cost for signing up without a phone number.
Unreleased code in Signal's public Android repo describes a "Signal Login" purchase screen: users either make a one-time in-app payment or register with an account key they already own.
Signal hasn't announced it yet.
https://aboutsignal.com/news/signal-login-registration-without-a-phone-number/
Unreleased code in Signal's public Android repo describes a "Signal Login" purchase screen: users either make a one-time in-app payment or register with an account key they already own.
Signal hasn't announced it yet.
https://aboutsignal.com/news/signal-login-registration-without-a-phone-number/
π±11π₯3β€1π€1
βΌοΈ Europe is feeling the fire Starlink lit under it: the EU has pulled its secure satellite network IRISΒ² forward a full year.
First launches are now targeted for 2029, not 2030. Brussels and the SpaceRISE consortium signed the implementation deal on Friday.
The constellation also grows by 66 satellites to 348, raising secure EU government capacity by about 60%. The bill is now put at β¬15.6bn, up from β¬10.6bn.
First launches are now targeted for 2029, not 2030. Brussels and the SpaceRISE consortium signed the implementation deal on Friday.
The constellation also grows by 66 satellites to 348, raising secure EU government capacity by about 60%. The bill is now put at β¬15.6bn, up from β¬10.6bn.
π±4π©2π1π€ͺ1