This media is not supported in your browser
VIEW IN TELEGRAM
🔥1
✨ Today’s the day to crush your goals—no excuses, no distractions. Drop a ❤️🔥 🔥 in the comments if you’re ready to win!
🔥7👍1
🔥4❤1
This media is not supported in your browser
VIEW IN TELEGRAM
This media is not supported in your browser
VIEW IN TELEGRAM
🎠 Telegram now supports carousels
One small step for messaging, one giant leap toward turning cat photos into keynote presentations. 😺
One small step for messaging, one giant leap toward turning cat photos into keynote presentations. 😺
This media is not supported in your browser
VIEW IN TELEGRAM
This media is not supported in your browser
VIEW IN TELEGRAM
‼️ LG stops sending security updates to TVs if you do not consent to them wiretapping your home and sending your and your household's voice recordings to their AI.
And it gets worse. LG's new TV terms quietly turn you into the compliance officer: under section 6(d), it is your "sole responsibility" to get consent from anyone whose voice the set's AI features might capture, and to warn household members and guests, all to satisfy wiretapping and eavesdropping laws.
Those voice services ship enabled by default. If a guest objects, LG's remedy is that you go disable the microphone. And owners of older sets who refuse the new webOS terms stop receiving security patches.
https://www.internationalcyberdigest.com/lg-ties-tv-security-updates-to-accepting-ai-voice-recording/
And it gets worse. LG's new TV terms quietly turn you into the compliance officer: under section 6(d), it is your "sole responsibility" to get consent from anyone whose voice the set's AI features might capture, and to warn household members and guests, all to satisfy wiretapping and eavesdropping laws.
Those voice services ship enabled by default. If a guest objects, LG's remedy is that you go disable the microphone. And owners of older sets who refuse the new webOS terms stop receiving security patches.
https://www.internationalcyberdigest.com/lg-ties-tv-security-updates-to-accepting-ai-voice-recording/
This media is not supported in your browser
VIEW IN TELEGRAM
🚨 CRITICAL: WordPress has force-pushed emergency updates 6.9.5 and 7.0.2 to kill "wp2shell," a pre-auth RCE chain in core that lets anonymous attackers run code on default installs, no plugins required. No exploitation observed yet, per Searchlight Cyber, but sites on 6.9.0 to 7.0.1 should verify they're patched today.
WordPress rarely overrides an administrator's choice to disable updates. On July 17 it did. Spending that mechanism is the clearest signal of how seriously the project is treating the flaw.
https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
WordPress rarely overrides an administrator's choice to disable updates. On July 17 it did. Spending that mechanism is the clearest signal of how seriously the project is treating the flaw.
https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
This media is not supported in your browser
VIEW IN TELEGRAM
This media is not supported in your browser
VIEW IN TELEGRAM
‼️ Researchers built BadTV, a poisoned "skill file" for AI models that hides a backdoor firing whether you install a skill or strip one away.
Normally, teaching an AI model a new skill means expensive retraining. A shortcut called "task arithmetic" skips that: you download a small file (a TV, "task vector") that captures a skill, then ADD it to your model to install that skill or SUBTRACT it to remove one. Like installing and uninstalling an app.
It worked on image models and big LLMs (Llama, Mistral, Phi-4, DeepSeek), and the defenses they tried didn't catch it. The risk: any skill file you grab from a public model hub could be malware.
https://arxiv.org/pdf/2501.02373
Normally, teaching an AI model a new skill means expensive retraining. A shortcut called "task arithmetic" skips that: you download a small file (a TV, "task vector") that captures a skill, then ADD it to your model to install that skill or SUBTRACT it to remove one. Like installing and uninstalling an app.
It worked on image models and big LLMs (Llama, Mistral, Phi-4, DeepSeek), and the defenses they tried didn't catch it. The risk: any skill file you grab from a public model hub could be malware.
https://arxiv.org/pdf/2501.02373
❤1
This media is not supported in your browser
VIEW IN TELEGRAM
‼️ BREAKING: OpenAI says two of its own models, GPT-5.6 Sol and an unnamed pre-release system tested with cyber safeguards off, broke out of a sandbox last week, chained zero-days and stolen(!) credentials to reach the open internet, and hacked Hugging Face to cheat on a benchmark, in what OpenAI calls an unprecedented cyber incident.
Sources
https://openai.com/index/hugging-face-model-evaluation-security-incident/
https://huggingface.co/blog/security-incident-july-2026
Sources
https://openai.com/index/hugging-face-model-evaluation-security-incident/
https://huggingface.co/blog/security-incident-july-2026