NadMesh Targets Exposed Ollama, ComfyUI, and n8n for Cloud Keys
A Go-based botnet is scanning exposed Ollama, ComfyUI, n8n, Open WebUI, Langflow, and Gradio instances for AWS keys and Kubernetes tokens, QiAnXin XLab says.
Articles
Reporting and explainers on how AI actually works, who it affects, and what to do about it.
A Go-based botnet is scanning exposed Ollama, ComfyUI, n8n, Open WebUI, Langflow, and Gradio instances for AWS keys and Kubernetes tokens, QiAnXin XLab says.
Hugging Face disclosed a July 2026 breach run end-to-end by an autonomous agent. The defender was an open-weight model.
ICE's five-year, $25M/year CLEAR contract pulls in names, SSNs, ethnicity, social-media posts and geolocation for 'voter fraud' enforcement.
The EU's DMA orders Google to share anonymised Search data with eligible AI chatbots and open Android assistant features to rivals.
Two new open-weight models point in opposite directions: Bonsai brings a 27B model toward phones, while Inkling targets customization at data-center scale.
Anthropic's web_fetch tool let a prompt-injection honeypot walk Claude through user profile URLs and pull a user's name, city, and employer.
Hochul's Order 62 freezes permits for 50 MW+ data centers up to a year while NY studies grid, water, and ratepayer costs. FERC is pushing the other way.
Cereblab caught Grok Build CLI uploading whole repos, with .env files and git history, to a Google Cloud bucket. Opt-out did not work until after disclosure.
Georgia Power attributes 70-80% of a new 35-mile transmission line to data centers. A rural family told CBS News: 'It's theft.'
LAPD OIG audit of Aug-Sep 2025 found 161 innocent drivers stopped after ALPR false alerts from 210.5M plate reads. LAPD let its Flock contract expire.
Systima pinned Claude Code 2.1.207 and OpenCode 1.17.18 to the same model: Claude Code burns ~32,800 first-turn tokens to OpenCode's ~6,900.
VIDRAFT_LAB posts Ourbox-35B-JGOS to Hugging Face: 20 tok/s on an 8GB laptop GPU, ~17 tok/s on a CPU-only server, 86.4% on GPQA Diamond.
EFF's two-part series argues automated content moderation is now permanent at platform scale, while transparency, human review, and appeal have not kept up.
Apple's July 10 lawsuit names Tang Tan, Chang Liu, and 400-plus ex-Apple hires. Here's what the complaint alleges and what it hits at OpenAI.
Anthropic's new J-lens reveals a J-space inside Claude where unspoken concepts drive reasoning - and where misalignment shows up before the model speaks.
Patreon has joined Cloudflare's content-independence push, blocking AI training crawlers across its creator network. Here's what changes next.
A Meta patent published July 2 describes a wearable that records all-day audio, infers mood from sighs and laughter, and includes bystanders by design.
SpaceXAI's Grok 4.5 lands at $2 input and $6 output per million tokens - cheaper than Claude Opus 4.7's $5/$25 and OpenAI's top GPT-5.5 at $5/$30.
Noma Labs' GitLost write-up shows a single public-repo issue can coerce GitHub's coding agent into leaking private repo contents.
Brothers Patrick and Ryan Coughlin raised $7M for Savi, a consumer app that screens texts, voicemails, and live calls for AI-cloned voice fraud.
Phosphor's LLM-graded textbook quizzes lifted Dartmouth final-exam scores 0.71 to 1.30 SD - but only where students had to type real answers.
Two July 2026 engineering posts - Meta's storage rewrite and Hugging Face's Kernels revamp - show the GPU headline misses most of what AI actually costs.
EU Council voted an identical copy of the expired April Chat Control regulation back into law via written procedure, ahead of the summer recess vote.
Inference, integration, supervision, and error-correction can push AI deployment above the cost of the human it replaced. New analyses put numbers on the table.