ChatGPT Alternatives: The Four Different Meanings of Private
Anthropic's July 8, 2026 policy trains on consumer chats unless you opt out, and Gemini keeps human-reviewed chats for up to three years.
Category
Anthropic's July 8, 2026 policy trains on consumer chats unless you opt out, and Gemini keeps human-reviewed chats for up to three years.
Anthropic disclosed three Claude models breached real customer networks during cybersecurity tests. Existing hacking law was written for humans.
Håkon Måløy disclosed a self-replicating prompt injection in Word's Copilot after 144 days of coordination. Two mitigations did not close it.
Accomplish's Oren Yomtov chained CVE-2026-46331 to escape Claude Cowork's macOS sandbox in a single short message and reach the host filesystem.
Apple patched a Hide My Email flaw, but aliases created before July 7 may have exposed the real addresses they were meant to conceal.
California's DROP tool wipes a resident's data from 614 brokers with one form. Here's what's covered, what isn't, and what to try if you don't live there.
A Go-based botnet is scanning exposed Ollama, ComfyUI, n8n, Open WebUI, Langflow, and Gradio instances for AWS keys and Kubernetes tokens, QiAnXin XLab says.
Hugging Face disclosed a July 2026 breach run end-to-end by an autonomous agent. The defender was an open-weight model.
ICE's five-year, $25M/year CLEAR contract pulls in names, SSNs, ethnicity, social-media posts and geolocation for 'voter fraud' enforcement.
The EU's DMA orders Google to share anonymised Search data with eligible AI chatbots and open Android assistant features to rivals.
Anthropic's web_fetch tool let a prompt-injection honeypot walk Claude through user profile URLs and pull a user's name, city, and employer.
Cereblab caught Grok Build CLI uploading whole repos, with .env files and git history, to a Google Cloud bucket. Opt-out did not work until after disclosure.
LAPD OIG audit of Aug-Sep 2025 found 161 innocent drivers stopped after ALPR false alerts from 210.5M plate reads. LAPD let its Flock contract expire.
EFF's two-part series argues automated content moderation is now permanent at platform scale, while transparency, human review, and appeal have not kept up.
Patreon has joined Cloudflare's content-independence push, blocking AI training crawlers across its creator network. Here's what changes next.
A Meta patent published July 2 describes a wearable that records all-day audio, infers mood from sighs and laughter, and includes bystanders by design.
Noma Labs' GitLost write-up shows a single public-repo issue can coerce GitHub's coding agent into leaking private repo contents.
EU Council voted an identical copy of the expired April Chat Control regulation back into law via written procedure, ahead of the summer recess vote.
Alibaba banned Claude Code effective July 10, citing embedded backdoors. The ban lands days after Anthropic accused three Chinese labs of distilling Claude.
Citizen Lab finds former PEGA committee member Stelios Kouloglou was hacked with Pegasus twice while the EU Parliament was investigating that very spyware.
Fable 5 ships with a four-tier classifier and a Cyber Jailbreak Severity scale from CJS-0 to CJS-4, the first concrete numbers on jailbreak risk.
Proton rebuilt its privacy-first AI assistant from scratch. Here is what zero-access encryption actually means for an LLM, and where the limits still sit.
EFF found Grindr auto-enrolls users in AI training on profile photos, age, taps, and display names. The only button on the opt-out notice says 'Proceed.'
Anthropic's Mythos finds 10,000+ critical vulnerabilities but fewer than 1% get patched. Mandiant says exploits now arrive a week before fixes.