
The Salt Typhoon hack that breached America’s biggest phone carriers had a back door hiding in plain sight. A bipartisan House report has a blunt finding. Three Chinese state-owned carriers, pushed out of the US years ago, never fully left. Their lefto…

Open-weight AI models have nearly caught the frontier on capability. On safety, they have not. And once the weights are public, no lab can enforce a guardrail. A new evaluation of China’s leading open model makes the gap concrete. GLM-5.2, the open-wei…

AI has learned to find software bugs faster than people can, and the programmes that pay for them are straining. In a single week, the three biggest went three different ways. Microsoft paid out a record sum. Apple slammed the door on how many bugs a r…

Cracken, a San Francisco-based applied AI lab focused on offensive cybersecurity, has launched a self-serve version of its proactive security platform. Enterprise security teams and individual practitioners can now create an account and start testing t…

Deel, the global HR and payroll platform, has acquired Clarity, a Tel Aviv-based AI cybersecurity startup that detects deepfakes and verifies identities in real time. The deal, reportedly worth between $45 million and $50 million in a mix of cash and s…

A businessman in Sussex watched £14,244 drain out of his Metro Bank account. The money went on credits for Claude, the AI chatbot he already paid to use. Two things failed at once. Criminals had turned a chatbot into a way to cash out stolen cards. And…

Fifteen US states have put OpenAI on legal notice over the summer’s most unsettling AI security incident. They wrote to chief executive Sam Altman. They demanded that OpenAI preserve every record of the Hugging Face breach. That demand includes somethi…

A self-spreading worm tore through npm on Tuesday. It poisoned hundreds of packages that huge swathes of the software world quietly rely on. Researchers named it ChainDrop. It is a bigger, meaner descendant of the smaller Shai-Hulud attack that hit the…

For years, software supply chain attacks focused on compromising widely used applications after they had already been deployed. Increasingly, however, attackers are shifting their attention further upstream, targeting the open-source packages developer…

China has spent the past year telling the world that AI should be open, cheap and shared. In private, its officials are unnerved by one American model that is none of those things. Beijing is growing anxious that Anthropic’s Mythos could be turned agai…