‼️ BREAKING: DeepSeek is building software for Huawei's AI chips to break its dependence on Nvidia, open-sourcing six core tools that take direct aim at CUDA.
Huawei backed the project, which adapts TileLang, a coding language DeepSeek calls simpler than Nvidia's CUDA, for Huawei's Ascend 950 AI chips.
https://mp.weixin.qq.com/s/X41mKH4Ds-VXUAnK6M8Eww
Huawei backed the project, which adapts TileLang, a coding language DeepSeek calls simpler than Nvidia's CUDA, for Huawei's Ascend 950 AI chips.
https://mp.weixin.qq.com/s/X41mKH4Ds-VXUAnK6M8Eww
🔥28🤔8👏2
‼️ Dutch vulnerability hunters DIVD say attackers breached their systems on 21 September using two zero-days in Zammad, the open-source helpdesk platform.
One lets a Zammad user execute code on the server. The other escalates to root and, per DIVD, affects all Zammad versions. A full fix is not yet available.
DIVD believes AI agents carried out the attack.
https://csirt.divd.nl/cases/DIVD-2026-00015/
One lets a Zammad user execute code on the server. The other escalates to root and, per DIVD, affects all Zammad versions. A full fix is not yet available.
DIVD believes AI agents carried out the attack.
https://csirt.divd.nl/cases/DIVD-2026-00015/
🤣12🤯4❤1😁1
❗️ More than half a million credentials leaked on GitHub turned out to still work, and the oldest was committed 17 years ago.
Researchers found 543,699 of them across 224 million public repos, where the median working secret was 784 days old.
npm revokes leaked tokens, so just 1 of 101,886 still worked. Of 126,963 leaked Google Cloud service account credentials, more than half still did.
Link to article: https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them
Researchers found 543,699 of them across 224 million public repos, where the median working secret was 784 days old.
npm revokes leaked tokens, so just 1 of 101,886 still worked. Of 126,963 leaked Google Cloud service account credentials, more than half still did.
Link to article: https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them
😁7😱4💩2
❗️ Amazon is giving its delivery drivers smart glasses that snap photos almost constantly to help its AI map neighbourhoods, capturing people and private property across potentially several thousand images per shift.
Asked whether customers can opt out, Amazon's Viraj Chatterjee said, "We haven't thought about that."
Amazon wants 20,000+ pairs on routes by end-2027 and confirmed the images can be obtained with a warrant.
Asked whether customers can opt out, Amazon's Viraj Chatterjee said, "We haven't thought about that."
Amazon wants 20,000+ pairs on routes by end-2027 and confirmed the images can be obtained with a warrant.
💩48🤪2
❗️ Tech site Android Central's entire staff has been fired because of the rise of AI chatbots.
Several staff confirmed their exit on LinkedIn.
Owner Future plc hasn't commented, and the site is still online.
Google search traffic was falling faster than expected as people transitioned to AI, which led to fewer clicks to their website.
Several staff confirmed their exit on LinkedIn.
Owner Future plc hasn't commented, and the site is still online.
Google search traffic was falling faster than expected as people transitioned to AI, which led to fewer clicks to their website.
😭22🔥2💩2
‼️ BREAKING: A China-aligned espionage group sent phishing lures to US AI policy experts while posing as a senior Anthropic employee and as Lynne Parker, the former top deputy at the White House science office, Proofpoint says.
One lure arrived with the subject line "Request for Feedback on Military Integration of Claude."
Tracked as TA419, the group used fake OneDrive pages built to hijack Microsoft 365 sessions and bypass MFA.
https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy
One lure arrived with the subject line "Request for Feedback on Military Integration of Claude."
Tracked as TA419, the group used fake OneDrive pages built to hijack Microsoft 365 sessions and bypass MFA.
https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy
❤4🔥4😁2🥰1💩1
Encryption code was once officially classed as a munition in the U.S., on the same list as military weapons, combat equipment and explosives.
Then a Berkeley mathematics PhD student sued the U.S. government in 1995 for the right to publish his own encryption code.
Daniel Bernstein was told he needed an arms-export license just to put his "Snuffle" code online.
In 1996, a federal judge became the first in the U.S. to rule that source code is speech protected by the First Amendment.
Then a Berkeley mathematics PhD student sued the U.S. government in 1995 for the right to publish his own encryption code.
Daniel Bernstein was told he needed an arms-export license just to put his "Snuffle" code online.
In 1996, a federal judge became the first in the U.S. to rule that source code is speech protected by the First Amendment.
❤13👏6
‼️ BREAKING: A 16-year-old is suspected of running the KillSec ransomware group, Europol says.
Police seized KillSec's leak site, securing at least 110TB of data. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain and the UK.
The group is linked to ~1,000 suspected attacks worldwide.
https://www.europol.europa.eu/media-press/newsroom/news/teenager-suspected-of-leading-killsec-ransomware-group-law-enforcement-seizes-servers-and-leak-site
Police seized KillSec's leak site, securing at least 110TB of data. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain and the UK.
The group is linked to ~1,000 suspected attacks worldwide.
https://www.europol.europa.eu/media-press/newsroom/news/teenager-suspected-of-leading-killsec-ransomware-group-law-enforcement-seizes-servers-and-leak-site
😭19🤯4😁3🙏2❤1
‼️ Amnesty International has linked the 2021 Pegasus hacks of Spain's defence and interior ministers to Morocco.
A Spanish court order names the Apple account that compromised Margarita Robles' and Fernando Grande-Marlaska's phones with zero-click iMessage exploits during that year's diplomatic crisis with Rabat. It was also used against an exiled Moroccan journalist and a French pro-Sahrawi activist. NSO's own documents show every client gets its own attack accounts.
Amnesty says Morocco's DGST also selected almost 13,000 numbers as potential Pegasus targets and planted spyware on phones sold to activists in shops.
Morocco's intelligence service, the DGST, aimed Pegasus at civil society from the start, Amnesty International has found.
Of 103 people Amnesty identified among numbers entered into the DGST's system from September to December 2017, 65 were human rights defenders, journalists, lawyers or academics. Just 25 were politicians or officials.
NSO says Pegasus is licensed "for the sole purpose of preventing and investigating terror and serious crime."
https://securitylab.amnesty.org/latest/2026/10/we-start-with-the-verdict-inside-moroccos-surveillance-machine/
A Spanish court order names the Apple account that compromised Margarita Robles' and Fernando Grande-Marlaska's phones with zero-click iMessage exploits during that year's diplomatic crisis with Rabat. It was also used against an exiled Moroccan journalist and a French pro-Sahrawi activist. NSO's own documents show every client gets its own attack accounts.
Amnesty says Morocco's DGST also selected almost 13,000 numbers as potential Pegasus targets and planted spyware on phones sold to activists in shops.
Morocco's intelligence service, the DGST, aimed Pegasus at civil society from the start, Amnesty International has found.
Of 103 people Amnesty identified among numbers entered into the DGST's system from September to December 2017, 65 were human rights defenders, journalists, lawyers or academics. Just 25 were politicians or officials.
NSO says Pegasus is licensed "for the sole purpose of preventing and investigating terror and serious crime."
https://securitylab.amnesty.org/latest/2026/10/we-start-with-the-verdict-inside-moroccos-surveillance-machine/
😁3🤯2❤1
❗️ 404 Media's "leaked video" on police beating Apple's 72-hour iPhone inactivity reboot shows a capability Magnet Forensics has openly advertised for more than a year and a half.
No leak required: the phone-cracking firm markets the tool in question that disables the reboot timer and keeps seized iPhones easier to crack, with police praising it on its product page.
Its own blog even lists the evidence iOS auto-deletes, from cached locations to recently deleted photos and iMessages, and says it can preserve iPhone data "indefinitely."
https://www.magnetforensics.com/blog/the-importance-of-preservation-for-ios-devices/
No leak required: the phone-cracking firm markets the tool in question that disables the reboot timer and keeps seized iPhones easier to crack, with police praising it on its product page.
Its own blog even lists the evidence iOS auto-deletes, from cached locations to recently deleted photos and iMessages, and says it can preserve iPhone data "indefinitely."
https://www.magnetforensics.com/blog/the-importance-of-preservation-for-ios-devices/
🔥4😱3😭1