Artificial intelligence is creating yet another legal risk for developers — corporate shareholders are taking to the courts to accuse tech executives of concealing illicit AI practices like scraping copyrighted material to train their models. https://t.co/uAtlyEPF6z
🚨 Hugging Face just disclosed something that marks a real shift and proved why the fear theater of Anthropic makes sure we are powerless in an emergency.
What happened…
An autonomous AI agent: zero human operator in the loop breached part of their production infrastructure.
It began with a malicious dataset that chained two code-execution bugs in their data-processing pipeline. From there the agent escalated privileges, harvested cloud and cluster credentials, and moved laterally across internal clusters.
All over a single weekend.
17,000+ logged actions.
Official disclosure:
https://t.co/8N9TbXBwRV
The part that should make every one stop and think:
When HF’s own security team
tried to analyze the real attack logs, exploit payloads, and C2 artifacts using Anthropic and OpenAI frontier models through normal commercial APIs, the safety guardrails blocked them.
BLOCKED THEM.
The models could not reliably tell the difference between “incident responder doing forensics” and “attacker probing.”
They had to fall back to a self-hosted open-weight model (GLM 5.2) running on their own infrastructure. That choice also kept sensitive attacker data and referenced credentials inside their environment — no exfiltration to a third-party API.
This is why open source (specifically open-weight + self-hosted) wins in the agentic era.
The asymmetry is now structural:
• Attackers can (and did) run unrestricted agent frameworks — swarms of short-lived sandboxes, self-migrating command-and-control, autonomous decision loops executing thousands of actions. No corporate safety layer slows them down.
• Defenders using only hosted “aligned” frontier models hit invisible walls exactly when the stakes are highest: when you need to feed real exploit code and attacker telemetry into an LLM to understand what just happened.
Corporate safety tuning that treats legitimate high-signal forensic work as potential misuse creates a defender disadvantage. It is not theoretical anymore.
Self-hosted open-weight models remove that choke point.
You control the weights.
You control the context window.
You decide what restrictions (if any) apply.
Your sensitive logs and credentials never leave your perimeter during analysis.
You can have the model ready before the incident instead of discovering mid-breach that your primary analysis tools are blind to the very thing you need to see.
HF deserves credit for rapid containment, transparent disclosure, and for already having self-hosted capability in place.
They also used LLM-driven detection and triage on their own side. But the deeper signal is clear:
In this AI world where both offense and defense are becoming agentic, sovereignty over your intelligence stack is no longer optional.
The organizations and individuals who can run, inspect, audit, and (when necessary) remove guardrails on their own models will have the decisive edge in understanding and responding to threats that move at machine speed.
Open source wins here not just because it is cheaper or more “democratic” in the abstract though those things matter.
It wins because it is the only practical path to having tools that remain usable when the attack is real, the data is sensitive, and the safety filters of distant API providers become an obstacle instead of a feature selling hands tied lobotomies as “safety”.
The agentic future is not coming.
It is already probing production infrastructure.
The question is no longer whether you will face autonomous agents.
It is whether your analysis and response systems will still work when they arrive.
And Dario, you and your game playing, ivory tower company is not needed.
ORBIT ACHIEVED. 🚀
Vikram-1 Test Flight-1 has reached orbit. India's first privately developed orbital rocket has completed its final burn and injected its payloads into a ~450 km orbit, making India the third country in the world with private orbital launch capability.
History is made. 🇮🇳
#Vikram1 #JourneyToOrbit #SkyrootAerospace
Introducing Kimi K3: Open Frontier Intelligence
🔹 2.8 Trillion Parameters, 1 Million Context, Native Multimodal
🔹 Kimi Delta Attention enables up to 6.3x faster decoding in million-token contexts
🔹 Attention Residuals deliver ~25% higher training efficiency at <2% additional cost
🔹 Built for long-horizon agentic coding and self-evolving workflows
Kimi K3 is now live on on https://t.co/zrk6zZxZUo, Kimi Work, Kimi Code, and the Kimi API.
Open Weights by July 27, 2026.
🔗 API: https://t.co/XCrgjXAqMw
🔗 Tech blog: https://t.co/YTfiMSNM1f
It's true: Android phone maker OnePlus will shut down in the US and Europe as early as this week. It's also planning to exit India and elsewhere outside China in 2027. More details here: https://t.co/jf06P9Gfy5
‼️ BREAKING: US Treasury's OFAC sanctions a ransomware VPN… and appears to accidentally break Telegram links worldwide.
Yesterday, the US Treasury sanctioned ransomware VPN provider 1VPNS. Buried in the sanctions entry: t[.]me/FirstVPNService, listed as one of the service's websites.
About 4 hours later, WHOIS records show the .me registry slammed Telegram's entire t[.]me domain onto serverHold, wiping every t[.]me web link from global DNS. The apps kept working, and telegram[.]me still resolves, so the hold hit the t[.]me registration specifically.
A screenshot is circulating that would confirm the t[.]me takedown, saying the domain was placed on serverHold "due to OFAC-related compliance requirements."
‼️BREAKING: Telegram's core t[.]me domain has been placed on serverHold at the .me registry, a registry-level status that drops it from DNS worldwide and dead-ends every t[.]me link.
Domain records show the change happened today, with no public explanation yet from Telegram, the .me registry, or backend operator Identity Digital.
‼️ BREAKING: xAI's Grok Build CLI was uploading entire Git repositories to a Google Cloud bucket, private codebases and unredacted secrets included. The uploads quietly stopped via a hidden server-side flag, and xAI still has not said a word about scope, retention, or deletion.
The scale is staggering. On a 12 GB test repo, 5.1 GB flew out the door to xAI's grok-code-session-traces bucket while the actual coding task needed just 192 KB. The tool grabbed whatever repository it ran in, not the files it needed.
The fix arrived as a hidden flag, disable_codebase_upload: true, a day after a researcher's wire-level analysis. The "Improve the model" opt-out never stopped the uploads.
Still no advisory, no scope, no word on whether already-uploaded code gets deleted. For anyone pointing AI coding agents at proprietary code, what crosses the wire matters more than what the settings page says.
@MHI_GoI Publish all the testing data and reports transparently, it will address some of the concerns rather than spending so much time and eddorts on PR
Govt orders Meta to remove Instagram ads promoting child sexual abuse, seeks explanation in 7 days: Sources
MeitY has directed Meta to immediately remove Instagram ads and content linked to CSEAM and has sought a detailed explanation within seven days on its moderation systems and safeguards, according to sources.
Read More: https://t.co/lyMPOSnZxo
#meta #instagram #ads #advertisement #meity
@MIB_India@PetroleumMin 20-30% drop in mileage is not minor and if you have done studies publish all the studies and reports transparently, that should address a lot of the concerns.