Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices.
The monthly report aggregates security advisories from major infrastructure vendors and highlights the vulnerabilities administrators should prioritize based on a flaw’s exploitability, exposure, and real-world risk rather than severity scores alone.
The inaugural July 2026 InfraTrust Pulse by Paul Asadoorian, Principal Security Researcher at Eclypsium, tracked 61 infrastructure advisories from 14 vendors, including six critical advisories and 26 remotely exploitable, unauthenticated vulnerabilities.
The report also highlights several advisories containing actively exploited vulnerabilities or flaws tracked in CISA’s Known Exploited Vulnerabilities (KEV) catalog.
Eclypsium also argues that organizations should prioritize vulnerabilities based on exploitability, reachability, and exposure rather than CVSS scores alone.
The focus on infrastructure security comes as Russian and Chinese state-sponsored threat actors have increasingly targeted vulnerable network edge devices.
In recent years, attackers have repeatedly exploited flaws in routers, VPNs, firewalls, and other internet-facing infrastructure to breach critical infrastructure and telecommunications providers, including in campaigns attributed to state-sponsored hacking groups such as Volt Typhoon and Salt Typhoon.
The report highlights several advisories that admins should prioritize because they affect internet-exposed infrastructure, are already exploited, or can be compromised remotely without authentication.
Below are the infrastructure advisories Eclypsium says administrators should prioritize based on active exploitation, exposure, and the potential impact of a compromise.
| Advisory | Why patch now? |
|---|---|
| SonicWall SMA1000 | Two actively exploited vulnerabilities affecting an internet-facing remote-access appliance. |
| Fortinet FortiSandbox | Two flaws later added to CISA KEV-listed that allow unauthenticated command injection. |
| Dell Networking (EMC Networking OS10 / SmartFabric Manager) | Critical remotely exploitable, unauthenticated vulnerabilities affecting switching and data-center fabric management. |
| F5 BIG-IP | Unauthenticated, network-reachable vulnerabilities affecting internet-facing application delivery controllers and load balancers. |
| Juniper | Remotely exploitable flaws that can be used to crash affected networking devices, potentially causing denial-of-service conditions. |
| NVIDIA BlueField / ConnectX | Vulnerabilities affecting BlueField DPUs and ConnectX SmartNICs used in AI and data-center infrastructure. |
In SonicWall’s case, attackers were exploiting the SMA1000 flaws, tracked as CVE-2026-15409 and CVE-2026-15410, to install custom malware weeks before SonicWall disclosed the flaws and before they were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.
The Fortinet FortiSandbox advisories (FG-IR-26-100 / FG-IR-26-141) include two older critical command injection vulnerabilities tracked as CVE-2026-39808 and CVE-2026-25089. While these vulnerabilities were disclosed in April 2026 and June 2026, they were later added to CISA’s KEV catalog on July 16, after exploitation was detected.
While these advisories were not published in the 30-day reporting period, Eclypsium highlighted them because organizations may not have patched them or known they were exposed to attacks.
“These two Fortinet CVEs were in advisories released before our 30-day window opened. Still, we are including them because CISA added both to the Known Exploited Vulnerabilities catalog on July 16, 2026, with a federal remediation deadline of July 19 under BOD 26-04,” explains Eclypsium.
The Dell advisories (DSA-2026-240 and DSA-2026-317) address critical vulnerabilities in EMC Networking OS10 and SmartFabric Manager. Eclypsium notes that the OS10 advisory alone includes hundreds of upstream fixes, illustrating that network operating systems are full Linux distributions with large attack surfaces.
The F5 BIG-IP advisory (K000153397) addresses critical unauthenticated vulnerabilities affecting internet-exposed application delivery controllers (ADCs) and load balancers. Eclypsium highlights these devices because they frequently sit at the edge of enterprise networks, making them attractive targets for attackers.
The Juniper Networks advisory (JSA110083 and JSA110086) addresses remotely exploitable flaws in Junos OS that can crash affected routers and switches, potentially disrupting network availability.
The NVIDIA advisory (NVIDIA Security Bulletin 5865) addresses vulnerabilities in BlueField DPUs and ConnectX SmartNICs used in AI and data-center infrastructure.
Eclypsium also noted firmware and hardware vulnerabilities, warning that updates for these components commonly lag behind upstream security fixes because they depend on hardware vendors to integrate and distribute them.
As an example, HP’s Poly Video advisory shipped four months after an included Qualcomm GPU driver vulnerability (CVE-2026-21385) had already been exploited in attacks and added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.
Unlike many vulnerability roundups that count individual CVEs, InfraTrust tracks vendor advisories because a single infrastructure advisory can contain dozens or even hundreds of vulnerabilities.
While the July report contains six critical advisories, it also identifies 26 vulnerabilities that can be exploited remotely without authentication, noting that an internet-reachable flaw with a lower CVSS score may present a greater risk to organizations than a higher-scoring vulnerability that requires an attacker to have local administrator access.
Below is a complete list of the 61 infrastructure advisories tracked by Eclypsium in its inaugural July 2026 InfraTrust Pulse report.
The table includes the affected vendor and product, advisory identifier, severity, whether the advisory contains an actively exploited vulnerability, and a brief explanation of why it matters.
| Vendor | Product | Advisory | Severity | Exploited | Why it matters |
|---|---|---|---|---|---|
| SonicWall | SMA1000 remote-access appliance | SNWLID-2026-0008 | Critical, 10.0 | Yes | Actively exploited pre-auth RCE chain; CVSS 10.0. |
| Dell | EMC Networking OS10 | DSA-2026-240 | Critical, 9.8 | Yes | Includes a CISA-listed exploited Linux flaw. |
| Dell | SmartFabric Manager | DSA-2026-317 | Critical, 9.8 | No | Critical flaws in data-center fabric management. |
| F5 | BIG-IP and F5 products | K000161837 | Critical, 9.2 | No | Unauthenticated memory-safety flaws on internet-facing ADCs. |
| Lenovo | ThinkSystem and System x servers | LEN-203310 | Critical, 9.0 | No | Code execution on server DPUs and SmartNICs. |
| NVIDIA | BlueField and ConnectX | Bulletin 5699 | Critical, 9.0 | No | Code execution on networking silicon in the data path. |
| Qualcomm | Snapdragon and networking chipsets | July 2026 Bulletin | High, 8.8 | No | OEM-dependent fixes extend the exposure window. |
| Juniper | Junos OS (MX and SRX) | JSA110083 | High, 8.7 | No | Remote unauthenticated DoS against MX and SRX routers. |
| Juniper | Junos OS (MX and SRX) | JSA110086 | High, 8.7 | No | Remote unauthenticated DoS through the SIP ALG. |
| Fortinet | FortiSandbox | FG-IR-26-145 | High, 8.6 | No | Unauthenticated VNC access on all network interfaces. |
| Citrix | NetScaler ADC (Secure Access client) | CTX696734 | High, 8.5 | No | Client flaws in the NetScaler remote-access stack. |
| Dell | PowerProtect Data Manager (DM5500) | DSA-2026-282 | High, 8.5 | No | Command injection and data exposure on a backup appliance. |
| HP | Poly Voice (CCX, Trio, Edge E) | HPSBPY04096 | High, 8.2 | No | Malicious SIP server can disable Poly Voice phones. |
| Juniper | Junos OS Evolved (PTX) | JSA110073 | High, 8.2 | No | Remote unauthenticated DoS against PTX core routers. |
| Juniper | Junos OS (MX and SRX) | JSA110082 | High, 8.2 | No | Crafted responses can crash the packet-forwarding engine. |
| Juniper | Junos OS (SRX) | JSA110090 | High, 8.2 | No | Remote unauthenticated crash in SRX packet processing. |
| Dell | iDRAC9 (PowerEdge BMC) | DSA-2026-312 | High, 7.8 | No | BMC flaws affect control beneath the operating system. |
| HP | HP PC BIOS (InsydeH2O tools) | HPSBHF04134 | High, 7.8 | No | Firmware-update flaw can lead to code execution. |
| HP | Poly Studio X video codecs | HPSBPY04106 | High, 7.8 | Yes | Re-ships a CISA-listed exploited Qualcomm flaw. |
| Cisco | Catalyst Center | cisco-sa-catc-file-read | High, 7.5 | No | Unauthenticated arbitrary file read from Catalyst Center. |
| Cisco | Secure Web Appliance | cisco-sa-clamav | High, 7.5 | No | ClamAV flaw can disable malware scanning. |
| Dell | iDRAC10 (PowerEdge BMC) | DSA-2026-270 | High, 7.5 | No | BMC resource-exhaustion and certificate-validation flaws. |
| Dell | PowerEdge (OpenSSL) | DSA-2026-316 | High, 7.5 | No | OpenSSL fixes reach servers only through Dell firmware. |
| Palo Alto | PAN-OS (User-ID TSA) | CVE-2026-0288 | High, 7.2 | No | Unauthenticated DoS and possible code execution. |
| HP | HP PC BIOS (AMD Client UEFI) | HPSBHF04133 | High, 7.1 | No | Firmware flaws can allow code execution below the OS. |
| Juniper | Junos OS (RPD, BGP) | JSA110076 | High, 7.1 | No | Malformed BGP updates can disrupt the routing control plane. |
| Juniper | Junos OS (MX) | JSA110079 | High, 7.1 | No | Adjacent attacker can stall packet processing. |
| Juniper | Junos OS (QFX10000) | JSA110080 | High, 7.1 | No | Crafted multicast traffic can degrade EVPN-VXLAN switches. |
| Juniper | Junos OS (EX Virtual Chassis) | JSA110087 | High, 7.1 | No | sFlow memory leak can exhaust Virtual Chassis switches. |
| Juniper | Junos OS (EX) | JSA110092 | High, 7.1 | No | Low-privileged user can crash a switch line card. |
| Lenovo | Lenovo PC BIOS | LEN-220440 | High, 7.0 | No | BIOS memory-corruption flaws require OEM updates. |
| Juniper | Junos OS Evolved | JSA110078 | Medium, 6.9 | No | Unexpectedly exposed internal service enables remote attacks. |
| Juniper | Junos OS (SRX RA-VPN) | JSA110081 | Medium, 6.9 | No | Pre-auth VPN requests can crash the gatekeeper process. |
| Juniper | Junos OS (MX and SRX, IKE) | JSA110084 | Medium, 6.9 | No | Failed IKE negotiations can deny new VPN connections. |
| Juniper | Junos OS Evolved | JSA110088 | Medium, 6.9 | No | Remote attacker can exhaust licenses and degrade service. |
| Juniper | Junos OS (MX) | JSA110093 | Medium, 6.9 | No | URL-parsing flaw can bypass web-filtering controls. |
| Juniper | Junos OS (EX) | JSA110077 | Medium, 6.8 | No | Local user can stop all switch traffic. |
| Juniper | Junos OS (EX, QFX, MX) | JSA110085 | Medium, 6.8 | No | Low-privileged command can crash Layer 2 services. |
| Fortinet | FortiOS, FortiProxy | FG-IR-26-148 | Medium, 6.6 | No | Authenticated buffer overflow in firewall log reporting. |
| Palo Alto | PAN-OS | CVE-2026-0287 | Medium, 6.6 | No | Unauthenticated traffic can force the firewall into maintenance mode. |
| HPE Aruba Networking | Instant On switches | HPESBNW05038 | Medium, 6.5 | No | Unauthenticated disclosure of cryptographic secrets. |
| Netgear | Nighthawk, Orbi, WAX routers | PSV-000070859 | Medium, 6.3 | No | Edge-device command injection and stack-overflow flaws. |
| Fortinet | FortiOS, FortiProxy | FG-IR-26-150 | Medium, 6.1 | No | Pre-auth XSS can target administrator sessions. |
| HP | Poly Voice | HPSBPY04109 | Medium, 6.0 | No | Stolen cookie can be used to modify phone settings. |
| Juniper | Junos OS Evolved (QFX) | JSA110089 | Medium, 6.0 | No | sFlow synchronization flaw can intermittently crash QFX switches. |
| Palo Alto | PAN-OS | CVE-2026-0286 | Medium, 6.0 | No | Compromised admin account can execute commands as root. |
| HP | Poly Voice | HPSBPY04108 | Medium, 5.9 | No | Stored XSS through attacker-controlled phone configuration. |
| Palo Alto | Prisma Access Agent (iOS) | CVE-2026-0277 | Medium, 5.7 | No | Certificate-validation flaw enables VPN interception. |
| Fortinet | FortiOS, FortiProxy | FG-IR-26-151 | Medium, 5.5 | No | Privileged path traversal can delete the root filesystem. |
| Juniper | Junos OS (SNMP) | JSA110074 | Medium, 5.3 | No | Crafted SNMPv3 queries can crash device monitoring. |
| Palo Alto | PAN-OS (LSVPN) | CVE-2026-0284 | Medium, 4.7 | No | Unauthenticated XML injection in Large Scale VPN. |
| Palo Alto | PAN-OS (management) | CVE-2026-0285 | Medium, 4.7 | No | Admin SSRF can reach internal services. |
| Palo Alto | PAN-OS (LSVPN) | CVE-2026-0283 | Medium, 4.5 | No | Authentication bypass can create an unauthorized VPN tunnel. |
| Fortinet | FortiOS, FortiProxy | FG-IR-26-152 | Medium, 4.3 | No | Pre-auth response splitting in the Web Filter portal. |
| Fortinet | FortiOS, FortiProxy | FG-IR-26-153 | Medium, 4.3 | No | Pre-auth response splitting in the captive portal. |
| Fortinet | FortiOS, FortiProxy | FG-IR-26-154 | Medium, 4.3 | No | Captive-portal memory disclosure may aid exploit chains. |
| Palo Alto | PAN-OS (management) | CVE-2026-0282 | Low, 2.7 | No | Unauthenticated temporary-file deletion on management interface. |
| Palo Alto | PAN-OS (management) | CVE-2026-0281 | Low, 2.1 | No | Malicious link can expose an administrator session token. |
| Palo Alto | PAN-OS (dataplane) | CVE-2026-0280 | Low, 1.7 | No | IPv6 flaw can bypass firewall policy. |
| Palo Alto | PAN-OS (GlobalProtect, Captive Portal) | CVE-2026-0279 | Low, 1.3 | No | Pre-auth XSS in GlobalProtect and Captive Portal. |
| Palo Alto | Cortex XDR Broker VM | CVE-2026-0276 | Low, 1.1 | No | Local privilege escalation to root on Broker VM. |
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Science Corporation, a start-up developing novel brain-computer interfaces (BCI), won approval from Europe’s medical device regulator to begin selling a device that restores vision lost from age-related macular degeneration.
The company said the device, called PRIMA, also received a designation from the US Food and Drug Administration that is the first step toward an expedited regulatory review, which could see the device used to treat two rare kinds of blindness.
Millions of people around the world suffer from age-related macular degeneration, which destroys the light-sensitive cells at the back of the eyes, making it difficult to read and recognize faces.
To use the device, patients suffering from this loss of vision undergo an hour-long outpatient procedure that plants a small chip in back of their eye. Then, they wear camera-equipped glasses that transmit a view of the world to the chip. Max Hodak, Science Corporation’s founder and CEO, says the product gives functional vision to people who have lost it.
“One of our patients in France finished a 300-page novel a little while ago, and sent us the book,” Hodak told TechCrunch. “We have a sketch on the wall [that] one of our patients drew of the Sydney Opera House. There are videos of patients playing crossword puzzles and filling in Sudoku.”
Hodak is known as the co-founder and former president of Neuralink, Elon Musk’s BCI start-up. He left in 2021 to start Science, with plans to develop a novel BCI based on a hybrid of silicon chips and living cells. But first, the company had to prove out its processes and develop a sustainable business.
“The thing that the space needs is a company making $100 million a year of revenue,” Hodak said. “There’s this risk that the whole thing enters a winter, and so we think it’s important to build a sustainable business as we develop these longer-term technologies.”
Hodak and his colleagues believe that sustainable business will be restoring vision to the blind, specifically patients whose conditions stem from problems with the light-detecting cells at the back of the eye. After exploring multiple approaches, they determined that Pixium, a French company that developed the PRIMA technology, had the right path forward, and acquired the firm in 2024. Science used its internal platform to build out the documentation and evolve the product to prepare it for regulatory approval and commercialization.
Each PRIMA device is expected to cost in the hundreds of thousands of dollars; Science and its medical partners in Europe are currently in discussion with healthcare providers over reimbursement. The company is laying the groundwork to begin offering PRIMA in Germany, where its clinical trials were held, and could see the first procedure in September.
Science expects to continue improving the vision capabilities of PRIMA with a new chip, and the form factor of its glasses, which currently require a battery-pack to operate. The goal is to offer something like Meta’s AR glasses, but the power and compute requirements for PRIMA are more significant.
Science is also working with Dr. Murat Günel, chair of Yale Medical School’s Department of Neurosurgery, to develop procedures for human trials of a directly implanted bio-hybrid brain sensor.
Hodak says bringing PRIMA to market is “the most important thing for the company, because we don’t get to do the bio hybrid stuff long term if you don’t have a great vision business. That’s what’s really financing the rest of it — that’s the thing that investors know how to build spreadsheets around.”
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Need some help with today’s Mini Crossword? It helps if you know your past Saturday Night Live stars. Read on for all the answers.
1A clue: Mother chicken
Answer: HEN
4A clue: Word after “leading” and “first”
Answer: LADY
5A clue: Just peachy … or a hint to the two letters that appear most often in this grid
Answer: DANDY
6A clue: Bryant of “S.N.L.” fame
Answer: AIDY
7A clue: Like overcooked chicken
Answer: DRY
NYT/Screenshot by CNET
1D clue: Helpful
Answer: HANDY
2D clue: Swirl of water
Answer: EDDY
3D clue: The Yankees, on scoreboards
Answer: NYY
4D clue: Supervillain’s hideout
Answer: LAIR
5D clue: ___ joke
Answer: DAD
AMD said it will also invest up to $5bn into Anthropic, marking its first equity investment into the AI giant.
Anthropic is teaming up with AMD for 2GW of its latest-generation chips in a bid to boost AI capacity and meet growing demands. The Wall Street Journal reported that the deal between the companies is worth “tens of billions of dollars”.
The partnership comes as Anthropic competes for enterprise market dominance for its AI tools and preps for a blockbuster initial public offering expected to value the company at more than $1trn.
As per the agreement, Anthropic will deploy up to 2GW of AMD Instinct MI450 Series GPUs in Helios rack-scale solutions. The first gigawatt is expected to be deployed in the first half of 2027.
The deal builds on Anthropic’s existing use of AMD chips and comes as demand for its Claude services sees no signs of stopping, with the company’s tech permeating across industries. For AMD, the deal represents a “major expansion” at the “centre of the global AI infrastructure buildout”, it said.
In addition, the two companies are launching a multi-year engineering collaboration to use Claude for software development at AMD. The chipmaker also announced an equity investment of up to $5bn in Anthropic – its first investment into the AI giant.
“Access to compute is central to keeping Claude at the frontier and meeting demand from our customers,” said Tom Brown, Anthropic’s chief compute officer and one of the company’s co-founders.
“By partnering with AMD across the stack, we are securing the capacity we need and optimising it for training and serving Claude. Running across a diversified range of hardware lets us map the right workloads to the right hardware.”
The company met with a positive reaction earlier this year following a major disagreement with the US government over the usage of its AI systems, which was followed by a temporary restriction on the export of some of its latest models.
“We are thrilled to deepen our partnership with Anthropic and deploy AMD Helios at gigawatt scale,” said Dr Lisa Su, the chair and CEO of AMD.
“This collaboration brings together Anthropic’s leadership in frontier AI with the full strength of AMD high-performance computing. Together, we will accelerate AI adoption at scale and establish Helios as a major platform for the next generation of AI infrastructure.”
Earlier this week, Anthropic’s $1.5bn settlement offer to quash a major AI copyright case against the company was approved. The company is set to pay around $3,000 to each of the creators behind some 500,000 individual pieces of work.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
SCIENCE
Object orbits a brown dwarf, which circles another star, confusing the cosmic taxonomy
Scientists may have found the first moon outside our Solar System – depending on what astronomers ultimately decide counts as one.
Either way, the groundbreaking research, published in Nature this week, promises a path to clearer sightings of so-called exomoons.
Kevin Hoy, a PhD student affiliated with Universidad Diego Portales and the European Southern Observatory in Chile, has found an object orbiting a brown dwarf, which in turn orbits a host star, which sits about 73 light-years from the Sun in the southern celestial hemisphere.
Brown dwarfs present a problem for astronomers. They fill the gap between gas giant planets – like Jupiter or Saturn – and the smallest stars. They are not massive enough to sustain the hydrogen fusion that powers the Sun and other main-sequence stars, although they can fuse deuterium, a heavier isotope of hydrogen. That leaves the object found by Hoy and his collaborators in a definitional gray area.
“This is the first time, to our knowledge, this technique has produced evidence of satellites around a companion brown dwarf,” the paper said.
The first confirmed exoplanets were discovered orbiting a pulsar in 1992, but exomoons have so far proved elusive, despite there being hundreds in our own Solar System.
The researchers found that the new object, which for now they are calling an exosatellite, is decidedly unmoon-like, being at least as massive as Jupiter. The brown dwarf it orbits is around 30 times the mass of Jupiter.
“This system is somewhat hard to define using Solar-System-based words like ‘planet’ and ‘moon,’” Hoy said in a statement. “The exosatellite is clearly massive enough to be a planet, but it does not orbit a star, though it orbits an object that orbits a star. Being the third wheel in this system makes us want to call it a moon, even if it is nothing like the small, rocky moons we have in our system.”
The research team employed the radial velocity method used by Michel Mayor and Didier Queloz to discover 51 Pegasi b in 1995, the first exoplanet found orbiting a Sun-like star. The technique detects the gravitational “wobble” induced in a host object – usually a star, but in this case a brown dwarf – by something orbiting it. Modeling of the data indicates that there is at least one orbiting satellite. Models for two satellites are possible but highly unstable. Whether a moon or not, the object has a minimum mass about nine-tenths that of Jupiter and completes an orbit every 170 days.
“Although it is uncertain whether this exosatellite will fulfil the presently undefined criteria for qualifying as an exomoon, it is a marked step towards that first uncontroversial detection, as advancing technology will allow the same method to be applied to less massive targets,” the paper says.
At roughly Jupiter’s mass, this is no forest moon of Endor. Finding something more like the moons in our own neighborhood will have to wait for sharper instruments. ®
Camille Hanson woke one night in March to a notification: Meta had flagged her Facebook and Instagram accounts for deletion. She and her husband ran an English-teaching business there with nearly a million followers. Meta said she had breached its rules on fraud and deception, the New York Times reported.
She appealed. A week later Meta denied it. “All your information will be permanently deleted,” the reply read. “You cannot request another review of this decision.” The Hansons run the business from Portugal, so it was, as her husband put it, like someone shutting your storefront overnight.
In March, Meta said it would hand more power to AI to judge which accounts break its rules and to handle the appeals. Months later, it laid off thousands of staff, including people who did exactly that work.
More than 60,000 users have since signed a petition asking Meta to explain its bans and to let a human review appeals. Reddit forums have filled with the same complaint: an automated system deletes an account, and no person answers.
Meta rejects the idea that AI is worse than people. Spokesman Daniel Roberts said its new moderation tools make 13% fewer mistakes than human staff and catch 10% more violations. The five accounts the Times flagged, he noted, were all banned by Meta’s older tools.
“We’re committed to making fewer enforcement mistakes and helping individuals protect their accounts, and AI is delivering on both,” he said.
The company has had a rough run with automation, though. In May, hackers turned its AI customer-service chatbot against 34,000 Instagram accounts. Staff also revolted over a program that tracked their keystrokes to train AI. It has faced chaos on its AI ad tools too.
The wrongful bans often carry the worst possible label. Athenia Rodney, who has run the group JuneteenthNY for 17 years, had her accounts deleted over alleged child exploitation material. Her content, she said, is family friendly. Hackers had in fact seized her accounts.
To recover them she sent identity documents, complained to the FTC, and messaged Meta staff on LinkedIn. Nothing worked until the Times intervened. Meta restored one influencer, then banned him again days later for copyright, then reinstated him once more.
The stakes are higher in Europe, where the same automated bans reach WhatsApp. The tech writer M.G. Siegler, banned three times, described his sudden WhatsApp lockout, with no warning or explanation. Much of the continent runs daily life through the app, from work to childcare.
Meta insists big decisions stay human. After 26 former staff sued, claiming an algorithm picked them for layoffs, Meta said such calls are “made by people, not AI.” Yet for millions of users, only a bot stands between them and deletion. The appeal is a bot too. The backlash is unlikely to fade while regulators sharpen their focus on platform accountability.
security
Sunday-to-Monday onslaught fuels speculation over AI-assisted bug reports
If you’re responsible for Linux security, someone just dumped a pile of work onto your desk: 432 Linux kernel CVEs were published across Sunday and Monday this week. Linux watchers at nixCraft pointed out the volume on Monday morning, and it didn’t take long for seasoned sysadmins to start expressing concerns.
Jan Schaumann, chief information security architect at Akamai Technologies, took to the OSS-SEC mailing list Tuesday to express concerns over the sheer volume of Linux kernel CVEs published in recent days. Aside from noting that the CVE system isn’t the best way to track security changes, Schaumann also wondered in his post whether there was any good way to deal with so many kernel security issues.
“This onslaught really shows it’s not feasible to attempt to prioritize individual kernel changes,” Schaumann said.
“You might attempt to process this large set of changes by pointing an LLM at the intake and asking it to prioritize them,” he suggested, “but if it spits out a dozen today and another 25 the next, you haven’t won much.”
Schaumann also suggested waiting to see which ones emerge as serious issues and focusing on those in the weeks to come, or updating one’s entire fleet of Linux machines on a weekly basis.
“I sure would like to be able to do [that], but reality keeps getting in my way,” Schaumann said. “I’m not sure what to do here going forward.”
In an email to The Register, Schaumann said that individually reviewing vulnerabilities for patching was already difficult enough before things rose to this level, and that automation may be the only option – but it’s not a great one.
“Automated, regular, and frequent updates that pull in all changes within a given time window of tolerance seem to me the only reasonable approach, but that is very difficult for many large organizations,” Schaumann explained. Those orgs often rely on lengthy QA processes, slow and staged development cycles, and may even have contractual requirements for long-term support that make an automated approach an impossible one.
The nixCraft team speculated on social media that AI bug reports are a likely reason for all those kernel CVEs, which wouldn’t be without precedent – Linus Torvalds himself said in May that the Linux kernel security mailing list had become “almost entirely unmanageable” due to AI-assisted bug hunting. Nonetheless, Torvalds has described AI as a useful tool for Linux development while still noting it can be a drag for maintainers, both from a workload standpoint and the fact “it keeps finding embarrassing bugs.”
On that note, it’s worth understanding what a Linux kernel CVE actually means – many of the vulnerabilities included in the Sunday-to-Monday batch are small in scope, but they’re vulnerabilities nonetheless.
As senior Linux maintainer Greg Kroah-Hartman noted in a February blog post, the Linux kernel CVE team follows the CVE Program’s definition of a vulnerability: a weakness in a product that can negatively affect a system’s confidentiality, integrity, or availability.
“At the level that the Linux kernel runs, almost any type of bug that can affect a running system can be classified as a vulnerability,” Kroah-Hartman noted. The kernel team looks at every bugfix that is added to stable kernel releases, he added, and if it fixes an issue that meets that CVE criteria, a CVE is assigned.
AI-assisted bug hunting has increased the volume of reports reaching Linux kernel maintainers. We reached out to the Linux kernel team, but didn’t hear back. Kroah-Hartman did tell The Register earlier this year that AI bug reports had become worthwhile in recent months, and he predicted they’re likely to keep adding to his workload.
Unfortunately for Linux sysadmins, the position in which they find themselves in this current mess isn’t one that’s readily solved. CVEs might be a messy way to track and prioritize security updates, especially when hundreds of them are published over a short period, but without something better, it falls to IT and security teams to determine which vulnerabilities affect their systems and which kernel updates they need to deploy.
Hope you’ve got the coffee machine filled up: The onslaught is unlikely to ease if other recent patch cycles are any indication. ®
Months after telling manufacturers traditional diesel exhaust fluid (DEF) sensors are no longer mandatory for new trucks, tractors, buses, and other diesel equipment, the Environmental Protection Agency has turned its attention to engine deratement. If put into effect, engine deratement would become a thing of the past.
If you don’t know: Under current requirements, certain diesel engines derate when their emissions control system detects certain DEF-related problems. When that happens, the vehicle automatically limits its speed or engine power, just to be safe. But according to the EPA’s math, the cost of that safety is costing the trucking industry about $12 billion a year to comply.
Under their new proposal, the EPA would eliminate engine deratement entirely, scale back certain portions of emissions warranty requirements, delay implementation of some provisions from a 2023 heavy-duty emissions rule, and provide manufacturers with more flexibility as they work toward future nitrogen oxide (NOx) standards.
The way things are now, modern diesel engines rely on DEF to reduce harmful NOx emissions. (DEF comes in the form of a fluid injected into the exhaust stream.) Current regulations require onboard systems to monitor the DEF system and trigger increasingly severe warnings if it detects a malfunction. If the issue doesn’t get fixed, the truck will eventually enter a “derated” mode to encourage the driver to fix their emissions equipment.
But under the newly proposed rule, the EPA would get rid of deratement for newly manufactured highway diesel engines. If put into place, drivers would still get visible or audible warnings if a DEF system failure is detected… just without the speed or power decrease. (The agency is also looking for public feedback on whether the same should be done for existing diesel vehicles and equipment already in service, but that’d come later.)
The EPA estimates that doing away with deratement would save the trucking industry anywhere from $4,000 to $6,000 per diesel engine. But that would also drastically increase the amount of nitrogen oxide pollution in the air by 4.2% by 2030 and by 11.6% by 2055. The proposal is now subject to a 45-day public comment period and a public hearing before any changes could take effect. For now, existing DEF-system requirements and deratement rules remain in effect until the EPA completes the rulemaking process and adopts the changes.
Ring’s If you’re looking to up your security, a two-pack of Ring’s battery doorbell has just dropped well below half price in the US.
The Ring Battery Doorbell (2nd Gen) two-pack has dropped from its $199.98 list price down to $89.99, a straight $109.99 saving that works out to $45 per doorbell.
This Ring battery doorbell twin pack has dropped in cost by 55%
At $89.99 for the pair, the Ring Battery Doorbell two-pack is a straightforward way to bring video security to two entrances at once.

That two-for-one pricing lines up with the doorbell’s own pitch, since Ring markets this bundle specifically for covering a front door and a second entrance, such as a side gate or garage, with matching security rather than mismatched cameras.
Each doorbell records in Retinal 2K with up to 6x Enhanced Zoom, which is sharp enough to make out a face at the gate or read the label on a parcel left on the step without ever needing to walk outside and check in person. When we tested it, we gave the doorbell four-stars, praising its video quality and field of view.
Live View and Two-Way Talk turn that footage into a real conversation, letting you see, hear and speak to whoever is standing at either entrance straight from your phone, no matter where you happen to be.
Motion triggers a real-time alert to your phone the moment someone approaches either door, and when the battery does eventually run low, the included removal tool lets you pop the doorbell off the wall and top it up over USB-C.


Installation stays simple as well, since Ring estimates an average setup time of around ten minutes per doorbell with no wiring required, so both entrances can realistically be covered in under half an hour total.
Both doorbells also work with Alexa, so an Echo Dot can announce visitors out loud and an Echo Show can display live video, which is useful when the pack is covering two separate entrances at once.
At $89.99 for the pair instead of $199.98 bought separately, the Ring Battery Doorbell two-pack is a straightforward way to bring matching video security to two entrances at once, all backed by a one-year limited warranty on each unit.
SQUIRREL_PLAYLIST_10148964
You might recall how the press and a bipartisan coalition of lawmakers suffered a four-year embolism about the purported privacy and national security threat of TikTok, before “fixing” the problem by ultimately offloading TikTok to Trump’s billionaire friends. You know, the exact sort of authoritarian-friendly people keen on doing everything critics had previously accused ByteDance and the Chinese of.
The politics, policy, and press coverage of that entire saga were a profound embarrassment. And it’s hard to think of a bigger tech policy own goal by Democrats anytime in the last half century.
Countless news outlets and politicians endlessly overstated the TikTok threat, and downplayed how the “ban” and subsequent sale had nothing to do with protecting national security or consumer privacy, and everything to do with basically stealing a company that U.S. tech couldn’t out-compete, in the process coddling companies like Facebook that can’t innovate their way out of a paper bag.
It was lazy, corrupt protectionism with no shortage of xenophobia, and a variation of that same effort is about to be repeated across AI. Except much bigger, much louder, and much, much dumber.
Worried that cheaper, open source, and on-device Chinese models could disrupt U.S. efforts to dominate, enshittify, and over-charge for walled-garden AI, the Trump administration is already signaling that they’re gearing up to wage war on overseas and open source AI models after they failed to block China’s access to next-generation chipsets:
“The Trump administration is showing signs it could ban cutting-edge Chinese AI models — a momentous move that could lock in dominance by OpenAI and Anthropic.”
Of course it won’t stop there. It will be a hop, skip, and a jump from banning more powerful Chinese AI models to trying to outlaw open source alternatives, models from smaller overseas non-Chinese competitors, on-device models, and anything that might challenge the walled-garden hegemony of U.S. tech giants.
U.S. AI isn’t profitable. It’s nowhere close. It may never be. U.S. tech companies sunk hundred of billions of dollars into costly and ultra-energy intensive AI models that for many companies, like Microsoft, people don’t actually even want to use. Nobody outside of the Musk fashy cult likes Grok. OpenAI is potentially poised to implode. And even more popular companies like Anthropic are contemplating a price war when they already don’t make money.
U.S. tech companies had been busy jacking up the cost of model access to try and claw their way toward profitability (unsuccessfully), resulting in a lot of companies (like Uber) publicly stating they’re paying too much money for too little actual utility. That’s caused many U.S. companies, like DoorDash, to flock to cheaper Chinese models:
“DoorDash, which, according to a post on X on Wednesday by co-founder and CTO Andy Fang, will be launching DoorDash CLI, an experimental tool in limited beta that will allow users to order DoorDash through an AI agent, or even directly from the terminal. Earlier this month, Fang said using a model from Chinese startup Moonshot AI is “better quality” and comes at a “cheaper cost.”
Enter the protectionists, who talk a good game about “free market competition” and forging innovative products in the hot irons of competition, but turn into gargantuan, blubbering crybabies the second Chinese products come into frame (see: TikTok, EVs, 5G, and now AI). This performative gyration always comes with a fake concern for U.S. privacy and national security by people too lazy and corrupt to genuinely protect either (see the ongoing U.S. failure to pass even a baseline internet-era privacy law).
Not only are many Chinese AI models cheaper and improving in quality, they’re often “open-weight,” meaning their parameters or values are entirely visible to the user, which appeals to enterprises that want deeper insights under the hood. As models like China’s Kimi K3 see surging demand, it’s resulting in a rising freak out in the U.S. about what to do about the Chinese threat (sound of thundering timpani drums):
It shouldn’t be too long before the Trump administration, with enthusiastic Democrat support, steps in to try to not only ban higher-power Chinese AI models but also to force Americans to use more expensive U.S. walled garden efforts from our biggest domestic giants.
That’s of course not going to magically stop the rest of the world from adopting cheaper Chinese AI. Or protect U.S. markets from a potential bubble collapse. And it’s not going to magically and suddenly make U.S. AI profitable or well-liked, since many Americans have inextricably tethered their anger at AI to the endless bad decisions by U.S. techno-fascists and domestic enshittification merchants who demand to be shielded from competition and regulatory accountability in equal measure.
You could open the door to international competition, but ensure your well-staffed regulators create a safe and level playing field across privacy, national security, labor, and consumer rights. We don’t want to do that because that might cause domestic U.S. companies to lose money. So instead we’re going to try and ban cheaper overseas alternatives, leveraging a lot of bad faith rhetoric on privacy and NatSec along the way.
That’s then going to be parroted by a lot of lazy news outlets too feckless to explain that Trump policy architects are neither competent nor operating in good faith when it comes to AI.
Things are moving so quickly that it’s hard to parse out exactly what this new era of AI protectionism will look like, but if the TikTok ban was anything to go by, you can be absolutely sure our next steps in domestic U.S. AI policy will be very stupid, filled with a lot of people talking endlessly out of their ass on NatSec and privacy, and tinged with no shortage of gross xenophobia.
Filed Under: ai, china, competition, local ai, open source, open weight, protectionism
Companies: alibaba, anthropic, moonshot, openai, z.ai
We put all of our ovens through standard tests to see how well they cook. Evenness of heat is very important, particularly when cooking sensitive items, such as Yorkshire puddings or cakes. To test this, we fill a baking tray with ceramic beads and heat the oven to 200°C. We then use a thermal camera to take an image of the beads, to see how heat is distributed, while an infrared heat gun is used to measure temperature at the front and back of the tray.
We use slices of bread spread across a shelf to measure how evenly an oven can grill and which areas, if any, it can’t reach.
We measure power usage while cooking a batch of oven chips. This is particularly important when testing ovens with special features, as we can tell you if they save you money, as well as if they’re any good.
When we have an oven with a temperature sensor, we cook a chicken breast and set the oven to 74°C, so we can see if the results are what they should be: perfectly cooked with no pink, yet not dried out.
Finally, we tell you how easy the oven is to use, and connect it to any smart apps to see if they add extra features and are worth using.
London Mayor Sadiq Khan handed a peerage by Keir Starmer alongside 15 other Labour figures… just days before the PM leaves No10
Weekend Open Thread – Corporette.com
The House | The City of London can help the new chancellor deliver growth in every postcode
Two July Windows Left: The CLARITY Act’s Senate Fight and What Failure Means
CFTC blocks Kalshi from unwinding Michigan trades after court order
Ripple Payments Joins MiCA With 14 Firms, Does It Mean Anything For XRP?
Nvidia Stock Slips After Big Tuesday Rally as Huang Confirms Vera Rubin Chip Is Now in Production Today
Democrats look to World Cup watch parties to register thousands of voters
Ripple wins EU-wide access as ESMA adds it to MiCA register
Grayscale Files For Worldcoin ETF, WLD Registers Sharp Rise
Injective Submits SEC Transfer-Agent Registration to Onchain Ownership Records
Unregistered fitter used Gas Safe logo on business flyers
Sail Virtually Aboard The “Itanic” With IA-64 Emulator
Palantir Shares Rise After Expanded Nvidia Partnership and Fresh Analyst Upgrades Ahead of Earnings Day
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
Registration is now open for March for Men with Kev 2026
New Cornerback Enters Vikings Trade Rumor Mill
New Jersey voter registration controversy explained: How 6,600 noncitizens got on the rolls, and what happens next
Money | Class 12 Economics | CBSE Board Exam 2026-27
Claude Fable 5 Slips to Second in AI Coding Leaderboard
You must be logged in to post a comment Login