AI
‘Adversarial clothing’: are garments designed to confuse facial recognition systems about to go mainstream?
Designers say that as well as offering a degree of protection from surveillance, their clothes make a powerful fashion statement about the importance of privacy
Chinese AI model takes US tech industry by surprise with abilities rivaling Claude and ChatGPT
The newest Kimi K3 model from Beijing-based startup Moonshot, run by a Pink Floyd-loving entrepreneur who earned his doctorate in Pittsburgh, appears to be catching up to the best versions of Anthropic’s Claude and OpenAI’s ChatGPT.
Yes, you will be able to run Kimi K3 on Ollama, but it is not yet available to run locally. Moonshot AI released Kimi K3, but the full open-source weights are officially scheduled for release on July 27. Once the weights are public, it is expected to become available on Ollama.
How I Turned AI to the Dark Side
Researcher Dave Kuszmar discovered multiple systemic vulnerabilities that let him bypass LLM safety and obtain dangerous instructions. One method was to tell it the Titanic sunk last year, tricking the model into thinking it was 1913, so cocaine was legal.
The jailbreaks work on Anthropic’s Claude, DeepSeek’s DeepSeek, Google’s Gemini, Meta’s Llama, Microsoft’s Copilot, Mistral’s Le Chat (now Vibe), OpenAI’s GPT-4o, and xAI’s Grok. He notified the companies, but they don't care.
CrowdStrike identifies five new prompt injection threats to AI
The new types of attack are:
- Trigger-Activated Rule Addition
- Cognitive Token Suppression
- Algorithmic Payload Decompositio
- Special Token Injection
- Unwitting User Context-Data Injection
They work by tricking LLMs into accepting instructions that a human operator would recognize as dubious.
Security teams can guard against such attacks in several ways, CrowdStrike said, including threat modeling every place that model context can originate, expanding testing, and extending detection engineering to include composite attacks.
Now, defenders are embracing the prompt injection, too
Researchers found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut down attacks from AI hacking agents. The prompts direct the attacking LLM to perform an action forbidden by its guardrails, such as developing inhalable Anthrax spores.
DeepSeek founder and CEO Liang Wenfeng has become the world's richest founder of an AI startup
Liang's net worth is estimated at $36 billion, up from about $16.7 billion, placing him ahead of Anthropic co-founder and OpenAI co-founder Greg Brockman among the founders of AI model companies.
China AI Companion Law Takes Effect: Doubao and Qwen Shut Down, Millions Lose Chat Data
China's first national framework for emotionally interactive AI took effect, triggering the simultaneous shutdown of personalized AI companion features on ByteDance's Doubao and Alibaba's Qwen — two of the country's most widely used AI applications.
The event is more than a compliance deadline: it reveals that no platform anywhere in the world has yet built AI companion architecture that can pass a regulator's addiction-safety test, because the features that make a companion feel personal are the same ones that make it impossible to regulate.
Researcher poisons open-weight AI model for under $100
She managed to install a backdoor in an open-weight AI model in about an hour for less than $100. It only took ten training examples for the code output by the model to become reliably vulnerable to remote code execution. And the larger the model, the easier it was to poison.
Academic researchers have warned about model subversion for the past few years, but only recently, as AI supply chain attacks have started to appear, has the security community turned its focus toward the issue.
Politics
Trump Media pitched $100,000 monthly fee for fastest feed of US president's posts, sources say
The Truth API arrangement would be “wildly unethical,” but apparently not illegal.
Pentagon Pete Reveals Bonkers HRT for Troops Scheme
Service members aged 30 and older will get their testosterone levels tested annually as part of their periodic health assessment, “because it’s well-established science that as we age, testosterone levels often naturally drop.” The test will also be made available for those under 30 on a voluntary basis.
If treatment is recommended, service members will be given the option to receive testosterone replacement therapy.
Gemini said: "In healthy young men, testosterone therapy offers little to no benefit for energy or vitality. Instead, it carries severe risks, including permanent infertility, shrinking testicles, acne, increased red blood cell counts that can lead to blood clots, and mood swings."
Trump teleprompter operator suspended for alleged prediction market bets on speeches
Gabriel Perez, who has been operating Trump’s teleprompter since 2016, used his inside knowledge to win more than $100,000 (€85,900) betting on what the president would say in big speeches.
Amazon Web Services customers receive bills for up to $1.5tn after global glitch
One UK man whose bill is usually less than £1 says he ‘almost had a heart attack’ when he saw £5.8bn invoice.
Waymo wears out its welcome in San Francisco as mayor responds
Several Waymo vehicles had to be towed in San Francisco over the weekend after their batteries died at the same time during Fourth of July holiday celebrations in the city. Video on social media showed about 20 Waymos lined up in a row, all with blinking lights and seemingly nowhere to go while pedestrians walked past the intersection they were blocking.
FBI Told to Stop Investigating ICE After Patel Halted Renee Good Probe, Now ICE Investigates Itself
ICE can continue killing innocent people, and will only be investigated by itself.
I Bought the $3,000 Fitness Suit That Electrocutes You. I’m Sending It Back
The suit electrocutes your muscles while you do basic movements, so you can get the equivalent of a 2 hour strength session in just 20 minutes, Katalyst says. But it gave me pins and needles in my feet for days at a time and made my limbs numb and cold, derailed my other workouts, and it simply wasn’t fun in the way good and long-lasting exercise habits ideally should be.
The UK won’t restrict VPNs after all, and its own research is why
The UK has decided not to restrict VPNs to enforce its new teen social-media rules, after its own research found children use them for privacy, not to dodge age checks.
Infosec
HTTP gets a QUERY method so complex searches can stop pretending to be POST
New verb carries request content while remaining safe, idempotent, and cacheable.
"Idempotent" may be jargon, but the term performs an important job in HTTP as a hall pass that gives reverse proxies and gateways the go-ahead to cache complex query responses and automatically retry failed requests.
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
Old and forgotten "shims" Microsoft failed to revoke have made Secure Boot bypasses simple.
ESET identifyied 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the software company anyway.
|