NadMesh Targets Exposed Ollama, ComfyUI, and n8n for Cloud Keys
A Go-based botnet is scanning exposed Ollama, ComfyUI, n8n, Open WebUI, Langflow, and Gradio instances for AWS keys and Kubernetes tokens, QiAnXin XLab says.
Tag
A Go-based botnet is scanning exposed Ollama, ComfyUI, n8n, Open WebUI, Langflow, and Gradio instances for AWS keys and Kubernetes tokens, QiAnXin XLab says.
Hugging Face disclosed a July 2026 breach run end-to-end by an autonomous agent. The defender was an open-weight model.
ICE's five-year, $25M/year CLEAR contract pulls in names, SSNs, ethnicity, social-media posts and geolocation for 'voter fraud' enforcement.
The EU's DMA orders Google to share anonymised Search data with eligible AI chatbots and open Android assistant features to rivals.
Cereblab caught Grok Build CLI uploading whole repos, with .env files and git history, to a Google Cloud bucket. Opt-out did not work until after disclosure.
LAPD OIG audit of Aug-Sep 2025 found 161 innocent drivers stopped after ALPR false alerts from 210.5M plate reads. LAPD let its Flock contract expire.
Noma Labs' GitLost write-up shows a single public-repo issue can coerce GitHub's coding agent into leaking private repo contents.
Brothers Patrick and Ryan Coughlin raised $7M for Savi, a consumer app that screens texts, voicemails, and live calls for AI-cloned voice fraud.
EU Council voted an identical copy of the expired April Chat Control regulation back into law via written procedure, ahead of the summer recess vote.
Alibaba banned Claude Code effective July 10, citing embedded backdoors. The ban lands days after Anthropic accused three Chinese labs of distilling Claude.
Citizen Lab finds former PEGA committee member Stelios Kouloglou was hacked with Pegasus twice while the EU Parliament was investigating that very spyware.
Fable 5 ships with a four-tier classifier and a Cyber Jailbreak Severity scale from CJS-0 to CJS-4, the first concrete numbers on jailbreak risk.
Proton rebuilt its privacy-first AI assistant from scratch. Here is what zero-access encryption actually means for an LLM, and where the limits still sit.
EFF found Grindr auto-enrolls users in AI training on profile photos, age, taps, and display names. The only button on the opt-out notice says 'Proceed.'
Ditch GitHub Copilot's $19/month subscription. Set up Continue.dev with Ollama for private, local AI code completion in VS Code — zero data leaves your machine.
Google's always-on AI agent watches everything, Canada finds OpenAI broke privacy law, and a US bank fed customer SSNs to a chatbot.
Anthropic built an AI that finds zero-days autonomously. The Pentagon wants it. Anthropic said no to surveillance. Now it's a geopolitical crisis.
Ditch GitHub Copilot's $10/month subscription. Set up free, private AI code completion in VS Code using Continue.dev and Ollama — runs entirely on your hardware.
Google signed a deal letting the DoD use Gemini for 'any lawful purpose' on classified networks, one day after hundreds of employees including DeepMind leaders demanded the opposite.
Stop paying Midjourney $30 a month. Set up FLUX on your own hardware with ComfyUI and generate unlimited images with zero content filters and full privacy.
Chat with your own documents locally — no cloud, no subscriptions, no data leaving your machine. Step-by-step setup guide.
The biggest children's privacy update in 12 years takes effect, Google faces a class action over Gemini scanning Gmail, and we audit every major AI platform's opt-out settings.
A practical guide to running fully local audio transcription with whisper.cpp and faster-whisper — no API keys, no subscriptions, no data leaving your machine.
Meta's Model Capability Initiative captures mouse movements, keystrokes, and screenshots from employee computers. The goal: build AI agents that can replace the workers generating the training data.