Toggle light / dark theme

Get the latest international news and world events from around the world.

Log in for authorized contributors

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling.

“Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel,” Nozomi Networks said in a report published last week. “The result is a botnet whose traffic can resemble legitimate NAT-traversal activity while still supporting propagation, proxying, tunneling and denial-of-service commands.”

The operational technology (OT) security company said it observed a spike in attempts to exploit CVE-2021–35394 (CVSS score: 9.8), a critical remote code execution (RCE) flaw in Realtek Jungle SDK starting around September 5, 2026, with a subset of the activity delivering Cling.

Google halts open-source bug bounty program amid AI spam surge

Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports.

The company’s OSS VRP incentivizes security researchers to responsibly disclose security flaws across open-source projects maintained by Google, including Golang, Angular, Bazel, Protocol Buffers, Fuchsia, and critical third-party dependencies, as well as repository settings like GitHub actions, application configurations, and access control rules.

Google launched the OSS VRP in August 2022 with rewards ranging from $100 to $31,337, and noted that the program would focus on security flaws with the most significant impact on the software supply chain.

OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU

OpenAI is preparing to add invisible watermarks to text generated by ChatGPT and Codex in the European Union.

The watermark will not be visible when you read or copy the text. Instead, OpenAI says its new textGrain technology slightly changes the model’s word choices to create a statistical pattern that can later be detected.

“Over the coming weeks, we will add an invisible watermark to eligible ChatGPT and Codex text output in the European Union,” OpenAI explained.

Rejetto HFS servers now actively scanned for critical RCE flaw

Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026–61500, that allows session forgery, account takeover, and remote code execution (RCE).

VulnCheck VP of Security Research Caitlin Condon posted on LinkedIn over the weekend that the company’s Canary Intelligence honeypots had observed probes targeting CVE-2026–61500.

Condon said the observed activity appears to be small-scale reconnaissance from a single China Telecom IP address probing deployments in Japan and the United States.

New Dell System Update flaw lets hackers gain root privileges

Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible.

DSU lets enterprise IT administrators deploy BIOS, firmware, and software updates onto Linux and Windows systems on PowerEdge enterprise server infrastructure.

In a Thursday security advisory, the company said the flaw (tracked as CVE-2026–86360) allows threat actors to execute code with root privileges on unpatched devices by exploiting a path traversal weakness.

Microsoft: Windows KB5124010 update crashes some games and apps

Microsoft confirmed over the weekend that some games and applications using AC-3 (Dolby Digital) audio decoding will crash after installing the September 2026 KB5124010 Windows 11 preview update.

KB5124010 is an optional update that requires users to click the “Download and install” link, which should reduce the number of potentially affected Windows users. However, it installs automatically on devices running Windows 11 24H2, where the “Get the latest updates as soon as they’re available” option is toggled on.

“In some cases the application can fail to launch, or close without warning. In other cases the application will work normally until certain features are used, such as playing music,” Microsoft said in a Friday update to the Windows release health dashboard. “Affected applications may vary and can include games, media players, and certain productivity applications.”

Anthropic Compute Spend Outpaced Its Own 2025 Revenue

A leaked draft of Anthropic’s IPO prospectus shows the company spent $7.33 billion on compute and infrastructure in 2025 against $4.6 billion in revenue — roughly $1.60 of infrastructure for every dollar earned.

Operating losses exceeded $8 billion. Long-term cloud and infrastructure commitments total $518 billion over the next decade.

Revenue is accelerating: Q2 2026 alone hit $11.5 billion, more than the entire previous year, and the company reports operating profit in recent quarters.

The number that matters for buyers is the spend-to-revenue ratio. Every enterprise building long-term plans around a frontier AI vendor’s API pricing is implicitly betting that the vendor’s own infrastructure math holds.

Before locking multi-year contracts, ask vendors for their compute-spend-to-revenue ratio — not just today’s price per token.

Full analysis:

#AIEconomics #Anthropic #AIInfrastructure #Procurement

Human tau seeds trigger disease-specific shapes in mouse brains, new study finds

Tau is a protein that occurs naturally in the brain. It is essential for proper neuron development and for how neurons communicate with each other. The same protein, however, when misshapen or misfolded, can act as a driver of neurodegenerative diseases. Abnormal buildup of tau is a hallmark of Alzheimer’s disease, and scientists have also found an association between misfolded tau and more than 20 neurodegenerative diseases.

The prominent prion hypothesis proposes that misfolded proteins spread by forcing normally shaped proteins to copy their exact 3D structure. To test its validity, a recent study investigated at the atomic level how misfolded tau proteins spread and multiply through the brain.

Researchers injected tiny amounts of human tau seeds from Alzheimer’s disease (AD) or corticobasal degeneration (CBD) into the brains of healthy mice. High-resolution microscopy that captured tau at the atomic level revealed that the mice’s own tau had misfolded into exact 3D structural copies of the diseased original seeds. The human seeds vanished within a week, but not before setting off a chain reaction in which the mice’s tau continued to form fibers with matching disease-specific folds and accumulate for the next nine to 12 months.

New study investigates PFAS exposure and future inflammatory bowel disease

Exposure to per- and polyfluoroalkyl substances (PFAS), often called “forever chemicals,” may play a role in the development of inflammatory bowel disease (IBD) years before symptoms appear, according to a new five-year study supported by a $3.3 million National Institutes of Health (NIH) R01 grant to researchers at the Icahn School of Medicine at Mount Sinai.

/* */