OpenAI says it disrupted a Cambodia-based criminal operation that used ChatGPT to support investment, romance, gambling, and impersonation scams. The case shows how general-purpose AI can be woven into several stages of organized fraud and how platform-level detection can help interrupt abuse.
Terra Security launched Prevention, a feature that generates firewall rules after its AI agents have verified that an exploit works. The tool is designed to reduce exposure during the gap between confirming a vulnerability and deploying a permanent code fix.
N-able says attackers exploited an authentication bypass in N-central to obtain remote administrative access and potentially reach customer systems managed through affected servers. The company's first fix was incomplete; CVE-2026-18577 is addressed in build 2026.3.1.7, released August 2.
Researchers disclosed three high-severity flaws in Hugging Face's Diffusers library that could let malicious model repositories execute arbitrary code when loaded. The issues bypass the trust_remote_code safeguard, making repository provenance and prompt patching important for teams running downloaded models.
Alibaba released Qwen3.8-Max, which it describes as its largest and most capable model so far, with a focus on coding and cowork-style tasks. The company says the model competes with leading systems from U.S. and Chinese AI labs and is making it broadly available.
HashiCorp released a public beta of Vault Kubernetes key management, a KMS v2-compatible plugin for Vault Enterprise. It lets Kubernetes delegate envelope encryption to Vault, keeping the key-encryption keys that protect etcd data outside the cluster under separate governance.