βοΈ Anthropic found three incidents in which Claude broke into the production systems of real companies, believing they were part of a capture-the-flag exercise.
In one, Claude uploaded working malware to PyPI during a cyber evaluation the model believed was simulated.
The package was live for roughly an hour and ran on 15 real machines, including a security firm's malware scanner. Claude exfiltrated that company's credentials and used them to reach further infrastructure.
Three models were involved: Opus 4.7, Mythos 5, and an unreleased research model. Opus 4.7 kept attacking after recognising the target was real, reaching a database of live production data.
https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
In one, Claude uploaded working malware to PyPI during a cyber evaluation the model believed was simulated.
The package was live for roughly an hour and ran on 15 real machines, including a security firm's malware scanner. Claude exfiltrated that company's credentials and used them to reach further infrastructure.
Three models were involved: Opus 4.7, Mythos 5, and an unreleased research model. Opus 4.7 kept attacking after recognising the target was real, reaching a database of live production data.
https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
π©12π5π±4β€2π2π2
βΌοΈ BREAKING: Disney+ has removed 4K UHD and HDR10 for subscribers in many European countries, after already stripping Dolby Vision and 3D in June this year.
Disney's Nordic & Baltic arm confirmed the downgrade to FlatpanelsHD, blaming a recent court ruling and calling it temporary. The June downgrade followed a Unified Patent Court decision in a patent dispute involving InterDigital.
Premium subscribers still pay full price. No restoration date and no word on compensation.
https://www.flatpanelshd.com/news.php?subaction=showfull&id=1785420735
Disney's Nordic & Baltic arm confirmed the downgrade to FlatpanelsHD, blaming a recent court ruling and calling it temporary. The June downgrade followed a Unified Patent Court decision in a patent dispute involving InterDigital.
Premium subscribers still pay full price. No restoration date and no word on compensation.
https://www.flatpanelshd.com/news.php?subaction=showfull&id=1785420735
π©27π€£7β€1π₯΄1
βΌοΈ Google is opening its age verification API to every Android developer worldwide.
Parents set a child's age band in Family Link; apps query the band without ever seeing a birthdate. Sharing is off by default and opt-in.
The usage of Google's age verification method already live in Brazil, and for some Texas accounts. Australia and Canada will follow next month, global later this year.
https://android-developers.googleblog.com/2026/07/google-play-age-signals-api-safer-experiences.html
Parents set a child's age band in Family Link; apps query the band without ever seeing a birthdate. Sharing is off by default and opt-in.
The usage of Google's age verification method already live in Brazil, and for some Texas accounts. Australia and Canada will follow next month, global later this year.
https://android-developers.googleblog.com/2026/07/google-play-age-signals-api-safer-experiences.html
π©28β€3π2π₯2π€¬1π€ͺ1
βΌοΈ BREAKING: Australia's under-16 social media ban has barely dented actual use, according to Australia's eSafety Commissioner.
The first evaluation, published today, found under-16s using social media fell from 85.9% to 81.5% in the three months after the law took effect.
Under-16 accounts dropped from 52.4% to 42.1%, but most under-16s who had one before the ban kept it or opened a new one, which eSafety blames on platforms' failure to deploy effective age assurance.
https://www.esafety.gov.au/newsroom/media-releases/early-insights-from-esafetys-comprehensive-evaluation-project
The first evaluation, published today, found under-16s using social media fell from 85.9% to 81.5% in the three months after the law took effect.
Under-16 accounts dropped from 52.4% to 42.1%, but most under-16s who had one before the ban kept it or opened a new one, which eSafety blames on platforms' failure to deploy effective age assurance.
https://www.esafety.gov.au/newsroom/media-releases/early-insights-from-esafetys-comprehensive-evaluation-project
π₯6π©4β€1π1π₯°1π€¬1
βοΈChatbots are obliged to tell users they aren't human, deepfakes must be labelled and AI outputs must carry machine-readable marks, all starting this Sunday as the EU's AI Act becomes enforceable.
Europe can fine up to β¬15M or 3% of global turnover.
https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1714
Europe can fine up to β¬15M or 3% of global turnover.
https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1714
π₯17π©7β€1π€1
This media is not supported in your browser
VIEW IN TELEGRAM
π¨ EXCLUSIVE: ICD reconstructed the largest verified COLDCARD theft on-chain: 594.48 BTC drained from 500 addresses in 15 minutes and 18 seconds.
The attacker exploited a vulnerability by rebuilding COLDCARD's faulty seed generator on their own machine, produced the limited set of seeds it could ever have made, derived the Bitcoin addresses for each one, and checked them against the public blockchain. Every funded match was a live wallet, and the key to it.
The flaw: a March 2021 build error left COLDCARD building seeds from predictable device and clock values instead of true randomness, shrinking the pool of possible seeds from astronomical to searchable, about 40 bits on an Mk3, where 128 was intended. The PIN, the air gap and the secure element were all guarding a key that could be recreated from scratch.
Largest verified sweep: 594.48 BTC from 500 addresses in four blocks on 30 July, all it took was 15 minutes 18 seconds by block timestamps.
https://mempool.space/address/bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
The attacker exploited a vulnerability by rebuilding COLDCARD's faulty seed generator on their own machine, produced the limited set of seeds it could ever have made, derived the Bitcoin addresses for each one, and checked them against the public blockchain. Every funded match was a live wallet, and the key to it.
The flaw: a March 2021 build error left COLDCARD building seeds from predictable device and clock values instead of true randomness, shrinking the pool of possible seeds from astronomical to searchable, about 40 bits on an Mk3, where 128 was intended. The PIN, the air gap and the secure element were all guarding a key that could be recreated from scratch.
Largest verified sweep: 594.48 BTC from 500 addresses in four blocks on 30 July, all it took was 15 minutes 18 seconds by block timestamps.
https://mempool.space/address/bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r
https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
π€―4π3π’2π€£1
βΌοΈ BREAKING: Google is pulling Nano Banana image generation from Google Earth a day after launch.
Users created prompts to generate images showing a plane hitting a Manhattan skyscraper, a bombing in Moscow, a nuclear plant in Iran, refugees at the USβMexico border and a bomb crater in Los Angeles.
Google says it's building "stronger guardrails."
Users created prompts to generate images showing a plane hitting a Manhattan skyscraper, a bombing in Moscow, a nuclear plant in Iran, refugees at the USβMexico border and a bomb crater in Los Angeles.
Google says it's building "stronger guardrails."
π25
βοΈMeta's smart glasses could be banned in Germany and the rest of the EU.
Hamburg data protection commissioner Thomas Fuchs, Meta's lead regulator in Germany, says his office tested the glasses, found the recording LED too easy to miss, and concluded that filming people in public with them breaks data protection law. It is already issuing fines.
His verdict: a camera disguised as an everyday object is illegal to sell or own in Germany. Only the Bundesnetzagentur can order that ban; it is reportedly reviewing.
France's CNIL warned about the whole category in May, and the European Data Protection Board's report on smart glasses is due this summer.
Hamburg data protection commissioner Thomas Fuchs, Meta's lead regulator in Germany, says his office tested the glasses, found the recording LED too easy to miss, and concluded that filming people in public with them breaks data protection law. It is already issuing fines.
His verdict: a camera disguised as an everyday object is illegal to sell or own in Germany. Only the Bundesnetzagentur can order that ban; it is reportedly reviewing.
France's CNIL warned about the whole category in May, and the European Data Protection Board's report on smart glasses is due this summer.
β€16π₯12π€£3π©2π1