CVE

Z.ai
2026-08-19 07:28:20

Z.ai founder Jie Tang says bigger parameter counts no longer tell the full story of model strength

Jie Tang, founder of Z.ai and a professor at Tsinghua University, argues that asking only how many parameters a model has no longer says much about how strong it is. In his review of the evolution of scaling laws—from GPT-3 to Chinchilla and then Mixture of Experts (MoE)—he says model capability depends on more than parameter count. Training data volume, where compute is spent, and how a model is actually used all matter. Tang’s point is that the old training-first view of scaling is less useful once commercial AI systems are deployed and called billions of times a day. Under that setup, inference cost changes the optimization target. A smaller model trained for longer may make more sense than a larger one trained less efficiently. He cited Llama-2-7B and Gemma-2-9B as examples of models trained far beyond the classic Chinchilla ratio. He also said MoE makes headline parameter numbers even less informative, because total parameters and activated parameters describe different things. For reasoning-heavy workloads, Tang argued that effective depth in a single inference pass and post-training may now be more important scaling dimensions. He described GLM-5.3 as a controlled test of that idea, keeping the base model and parameter counts unchanged from GLM-5.2 while expanding long-horizon environments and reinforcement learning over a month.

80
Z.ai founder Jie Tang says bigger parameter counts no longer tell the full story of model strength
Apple
2026-08-16 13:17:00

Dutch NCSC warns exploited macOS flaw let attackers install Monero miners on internet-exposed Macs

The Dutch National Cyber Security Centre (NCSC) has warned that a recently patched authentication flaw in Apple’s macOS Screen Sharing component is already being exploited in the wild, according to The Hacker News. The bug, tracked as CVE-2026-65400 and rated 9.8 on the CVSS scale, allowed attackers to access internet-exposed Macs listening on port 5900 without valid credentials and deploy Monero mining malware. Apple issued emergency fixes on Aug. 6 through macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9, saying the patch strengthened credential validation by improving state management. The NCSC said it confirmed multiple attacks in which intruders gained root privileges and installed mining software. Security researcher @osxreverser also disclosed another pre-authentication flaw in the same component, likewise fixed in version 26.6, which could be exploited with only a target IP address and no username. Calif said researchers used AI to build working exploits for the two bugs in just four hours, highlighting how AI is shortening the time between vulnerability discovery and exploit development. Users were advised to update immediately or disable Screen Sharing if patching is not possible.

50
Dutch NCSC warns exploited macOS flaw let attackers install Monero miners on internet-exposed Macs
Bitcoin
2026-08-15 01:33:26

Core Lightning says security fix release is coming in the next few days

Bitcoin Lightning Network client Core Lightning said it has received AI-generated CVE reports from multiple sources over the past 10 days and is now reviewing them with open-source contributors. The team said it is verifying the reports, assessing the risks involved, and building the fixes it considers necessary. Core Lightning plans to ship an initial release containing several patches in the next few days. It also urged users to upgrade promptly once that version is available. At the same time, the project said it is working on a broader remediation plan. The update outlines an active response process rather than a finished resolution, with verification, risk review, patch development, and follow-up mitigation work still in progress.

220
Core Lightning says security fix release is coming in the next few days
Fidelity
2026-08-14 01:59:25

Fidelity seeks staking for FETH as Anthropic investors float a possible $2 trillion-plus IPO valuation

A dense 24-hour news cycle brought fresh filings, earnings, market calls and regulatory signals across crypto and adjacent tech markets. Fidelity filed an amended registration statement with the U.S. Securities and Exchange Commission on Aug. 11 to add ETH staking to its spot Ethereum ETF, the Fidelity Ethereum Fund (FETH). Under normal conditions, the fund said it could stake as much as 100% of the ETH it holds, with no minimum staking threshold, and its investment objective would change to include staking rewards if approved. Elsewhere, some existing Anthropic investors said the AI company could be valued at more than $2 trillion if it goes public as early as October, with one investor putting the upside case at $3 trillion based on a roughly 30x revenue multiple. The estimates remain investor forecasts, and several investors said Anthropic management has not set an IPO valuation target. The session also featured quarterly updates from Bullish, BitGo and Securitize, new SEC steps around tokenized fund operations and tokenized equities, ETF flow data for Bitcoin and Ethereum products, and a series of policy, infrastructure and security developments spanning Europe, the U.K., Brazil and the U.S.

240
Fidelity seeks staking for FETH as Anthropic investors float a possible $2 trillion-plus IPO valuation
Whale Activit
2026-08-13 02:17:00

Crypto and AI roundup for Aug. 12-13: whale transfers, regulation moves and fresh fundraising

A dense stream of updates hit crypto and AI markets between Aug. 12 and Aug. 13, spanning venture funding, protocol incidents, regulatory moves, exchange actions and large on-chain transfers. PANews’ roundup included Lovable’s $400 million Series C at a $13.3 billion valuation, Wintermute’s plan to spend about $1 billion over five years on high-frequency trading and AI data center infrastructure, and Tencent’s second-quarter results showing higher capital expenditure tied to AI spending. In digital assets, Harmony said it had traced fraudulently minted tokens across 409 wallets and was considering a rollback, while Solana briefly came close to a network-freeze threshold after a data center routing issue knocked nearly 29% of staked SOL offline. Anchorpoint also began the first phase of distributing its Hong Kong dollar stablecoin HKDAP, and Coinbase said it will suspend 10 perpetual contracts on Aug. 26. Whale activity remained active as well, including an Ethereum ICO participant moving 2,000 ETH to Coinbase, a wallet sending 2,300 BTC to Wintermute-linked deposit addresses since June 25, and a leveraged ETH trader closing out positions for a reported $4.3 million profit. The period also brought new product releases from Grok and DeepSeek, a major SEC no-action letter tied to Franklin Templeton’s BENJI fund, and fresh scrutiny of prediction markets from U.S. regulators and New York City lawmakers.

310
Crypto and AI roundup for Aug. 12-13: whale transfers, regulation moves and fresh fundraising
Zoom
2026-08-13 01:08:56

ASecurity says AI found exploitable Zoom annotation flaws in under 24 hours

Israeli cybersecurity firm ASecurity said a researcher used publicly available AI models to identify multiple flaws in Zoom’s annotation tool and build an exploitable attack chain in less than 24 hours, using fewer than 20 prompts, according to Decrypt. The vulnerabilities are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. ASecurity said the bugs could let an attacker remotely execute code during a meeting without any action from the victim. In the scenario described by the firm, an attacker could take control of the target device, steal data, or turn on the microphone or camera. The report said the attack was tested successfully across Zoom on Windows, macOS, Linux, Android, and iOS. ASecurity described the exploit chain as reaching a “nation-state” level and said building tools of this kind previously would have required a specialized team, months of work, and a large budget. The firm said it reported the first flaw to Zoom on June 10, and Zoom released patches between June 22 and July 20. A Zoom spokesperson said the issue has been resolved and advised users to stay on the latest version.

170
ASecurity says AI found exploitable Zoom annotation flaws in under 24 hours
Zoom
2026-08-12 17:58:35

Researchers Built a Zoom Exploit in 24 Hours With Fewer Than 20 AI Prompts

Israeli cybersecurity firm A Security has disclosed that researchers used publicly available AI models to uncover vulnerabilities in Zoom's annotation tool and build a working exploit in under 24 hours, using fewer than 20 prompts. The three flaws—tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415—allow an attacker to join or host a meeting without any victim interaction or visible warning, then target any participant and take over their device. Tests covered Zoom's Windows, macOS, Linux, Android, and iOS apps. Once a device is compromised, an attacker can steal personal data, turn on the microphone or camera, or install additional malware. A Security first reported a vulnerability to Zoom on June 10; Zoom shipped fixes between June 22 and July 20. Because server-side protections can't filter malicious messages in end-to-end encrypted meetings, users are still advised to update to the latest version. Decrypt reported the research.

440
Researchers Built a Zoom Exploit in 24 Hours With Fewer Than 20 AI Prompts
Zoom
2026-08-12 17:46:04

Researcher Says Public AI Models Helped Build a Serious Zoom Exploit in Under a Day

A Security, an Israeli cybersecurity firm, said a researcher used publicly available AI models to identify flaws in Zoom’s annotation feature and assemble a working exploit in less than 24 hours. In a report published Tuesday and titled "Zoomsday," the firm said the researcher needed fewer than 20 prompts to uncover the issues. According to the report, the exploit could let someone in a Zoom meeting take control of another participant’s device without any action from the victim and without a visible sign that the system had been compromised. A Security said it tested the attack against Zoom apps on Windows, macOS, Linux, Android, and iOS. The vulnerabilities are tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415. The firm said a compromised presenter could target every participant, while any participant could also target the presenter. Zoom told Decrypt that the issue has already been resolved, though A Security said users still need to update because a server-side safeguard could not block malicious messages in end-to-end encrypted meetings. The report arrives as AI tools are being used more often to find software bugs across the tech industry.

110
Researcher Says Public AI Models Helped Build a Serious Zoom Exploit in Under a Day