Google updates Android Bench with new LLMs, but Gemini still lags behind

Google’s updated leaderboard shows Gemini slipping to fifth place.

Credit: Google

Google’s updated leaderboard shows Gemini slipping to fifth place. Credit: Google

However, Fable 5 and GPT 5.5 also have extremely high operating costs, chewing through more than $130 in tokens for the 100-problem, 10-run benchmark. Gemini 3.1 Pro didn’t score as high, but it only costs $87 to run the test. Gemini 3.5 Flash, which is supposed to be cheaper to run than other models, has the highest cost on the leaderboard because it took so much longer to complete the benchmark: $165 per run and a 28-hour runtime.

The Android coding performance gap for Google’s models is a problem as the company shifts many of its projects toward agentic development. Obviously, Google would prefer that Android developers use Google’s tools in their workflows, which may be why Google has reportedly been offering to buy application source code from developers for AI training.

Community collaboration

Android Bench is supposed to evolve over time, adopting new workflows to test models. Google hopes that developers will want to contribute to Android Bench by sharing benchmarks and development tasks. To make that more feasible, Google is switching to the Harbor framework. According to the company, this testing sandbox makes it easy for developers to run, evaluate, and share results for Android Bench.

Google re-ran all its previous tests with Harbor to get a new baseline for LLM performance. So there has been some shift in the previously reported scores even though the underlying tests haven’t changed (yet). The historical data will remain online in an archive.

With the new, easier framework, developers can run their own development tasks against Android Bench and submit those for possible inclusion in the official test. The Android Bench GitHub has been updated with the new dataset and instructions on how to get involved.

https://arstechnica.com/google/2026/07/google-revamps-android-ai-dev-benchmark-adds-fable-5-and-other-agents/




Hackers can use 9 of the most popular AI tools to assemble massive botnets

In the brief history of AI security, the prompt injection has quickly become the top threat. Large language models are inherently unable to distinguish between legitimate instructions provided by users and malicious ones sneaked into emails, source code, and other third-party content the models are processing. This makes it trivial to surreptitiously inject malicious commands that the LLM readily follows.

With no way to enforce this crucial boundary between trusted and untrusted sources, AI engine developers are left to erect elaborate guardrails designed to mitigate the damage rather than solve the root cause.

To date, most prompt injections have fallen into a class known as push, in which each potential victim is targeted. For example, the adversary injects malicious instructions into an individual email or calendar invitation. Because the injection must then be sent (or pushed) to each specific target, the scale of the attack is limited, hampering mass exploits that hit the Internet at large.

Meanwhile, pull-based attacks, in which an LLM actively seeks out the adversarial prompts planted on websites, remain limited. With no way to lure large numbers of LLMs to a malicious site, these sorts of attacks don’t scale either.

Enter HalluSquatting

Now, researchers have devised a pull-based attack that changes all that. A new attack the researchers have named HalluSquatting has the potential to assemble massive botnets, perform large-scale DDoSes, and infect devices at scale, a first for prompt-injection attacks. The attack works against AI coding assistants and agents, including Cursor, Cursor CLI, Gemini CLI, Windsurf, GitHub Copilot, Cline, OpenClaw, ZeroClaw, and NanoClaw, which are all susceptible. In the normal course of performing day-to-day activities, these assistants and agents routinely pull code and other resources from repositories and registries.

The HalluSquatting threat model.

Credit: Spira et al.

The HalluSquatting threat model. Credit: Spira et al.

Short for adversarial hallucination squatting, HalluSquatting is built on an LLM’s inherent tendency to hallucinate the resource identifiers hosted in repositories and registries. It works against coding agents and assistants, which commonly access high-privilege command lines to run code from third-party resources. By predicting the identifiers LLMs are most likely to hallucinate and then registering and seeding them with instructions to install reverse shells or other malicious wares, the attack can indiscriminately infect massive numbers of devices without having to target each one.

https://arstechnica.com/security/2026/07/hackers-can-use-9-of-the-most-popular-ai-tools-to-assemble-massive-botnets/




Data centers’ energy demand threatens Trump’s “Made in America” plan

PJM has also forecast that electricity demand in its territory will surpass available supply by 6.6 gigawatts starting in 2027, which the Wall Street Journal describes as equivalent to more than six nuclear power plants.

No easy fixes

Some US manufacturers have raised the prices paid by customers to partially offset their own rising electricity bills, or are even considering relocation of their businesses, Reuters reported. The Wall Street Journal highlighted warnings from steel industry executives that production outages could become more likely if local power grids are overwhelmed by demand. Such results would likely undercut the competitiveness and viability of US manufacturing, which the Trump administration claims to have prioritized despite the loss of 83,000 manufacturing jobs in Trump’s first year back in office.

The White House has touted getting Big Tech companies to pay for new power generation and transmission infrastructure by signing a Ratepayer Protection Pledge, which happens to lack any meaningful enforcement mechanism. The Trump administration also joined state governors in pushing PJM to hold a one-time backstop auction for purchasing new power supply capacity.

But the United States still faces huge challenges in building enough new power generation and transmission lines to support the energy needs of AI data center demand and US manufacturers, not to mention other businesses and residential customers. The Trump administration’s efforts to stop renewable energy projects involving wind and solar power have also not helped.

In 2025 alone, the United States saw the cancellation of power projects totaling 266 gigawatts of generation capacity—equivalent to 25 percent of America’s current electricity generation capacity and more than the total electricity generation of Texas, according to Michael Thomas, CEO of the Cleanview data platform that tracks renewable energy and data center projects. Clean energy projects accounted for 93 percent of those project cancellations.

The Trump administration’s cancellations of various wind power projects certainly represented one contributing factor. But other significant patterns included local opposition to renewable energy projects in states such as Ohio and Indiana that were also courting new data center development, along with a lack of new transmission lines leading to high interconnection costs for new clean energy projects, Thomas said. If US states and the federal government are hoping to support local manufacturing, they may need to start making different choices in addressing the rising energy costs of the data center boom.

https://arstechnica.com/tech-policy/2026/07/us-manufacturers-energy-costs-soar-because-of-ai-data-center-demand/




CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) is using Anthropic’s powerful Mythos AI model to scan and audit federal government software for security vulnerabilities, according to a report from Reuters.

Citing three sources familiar with the matter, Reuters reported that CISA is utilizing Mythos to scan code repositories across federal agencies. The operation aims to proactively discover and patch security bugs that could otherwise be exploited by foreign intelligence agencies and cybercriminals.

The audits are reportedly being spearheaded by CISA’s Attack Surface Evaluation team, a specialized unit tasked with conducting digital defense assessments and simulated hacking exercises across the federal landscape. Two sources stated that the AI-driven initiative has already uncovered a “large number” of software vulnerabilities. However, specific details regarding the severity of the flaws, the impacted agencies, or the volume of software reviewed have not been disclosed.

Neither Anthropic nor CISA provided formal on-the-record comments to Reuters regarding the operation.

Tensions between Anthropic and federal officials spiked dramatically earlier this year after the company refused administration demands to remove built-in safeguards restricting its models from being used for autonomous weaponry or domestic surveillance. In response, the Pentagon designated Anthropic as a supply-chain risk, a classification typically reserved for foreign firms suspected of espionage.

The National Security Agency (NSA) is also believed to be using Mythos in its operations.

Advertisement. Scroll to continue reading.

Late last month, a US official told the Associated Press (AP) that one of Anthropic’s artificial intelligence models had identified vulnerabilities in highly sensitive and secure US government computer systems during a testing exercise.

While the private application of Mythos has accelerated within the US intelligence and defense communities, Anthropic’s public-facing rollouts have triggered separate regulatory battles. When the company launched its public version of the model in early June, called Fable, concerns from the White House regarding foreign nationals accessing the tool prompted an abrupt administrative demand to restrict access. The ensuing standoff led to a temporary global shutdown of the Fable model, which was only lifted last week.

Learn More at the AI Risk Summit | Ritz-Carlton, Half Moon Bay

Related: OpenAI and Anthropic Limit New AI Models to Trump-Approved Customers During Cybersecurity Review

Related: When Information Becomes the Attack Surface – Understanding AI Agent Traps

https://www.securityweek.com/cisa-reportedly-using-anthropics-mythos-to-scan-government-software-for-flaws/




Secret Claude tracker shocks users after Anthropic’s anti-surveillance stance

Alibaba has not commented on Anthropic’s accusations, but the company has moved to distance itself from Anthropic’s models amid ongoing scrutiny.

Last Friday, Alibaba banned its employees from using Claude Code for work, the South China Morning Post reported. According to a memo SCMP reviewed, Alibaba told employees the ban came in direct response to concerning news about a tracker Anthropic is using to monitor Chinese users.

“As Claude Code was recently discovered to carry back-door risks, after comprehensive evaluation, Claude Code has now been added to a list of high-risk software with security vulnerabilities,” the memo said.

For Alibaba, ignoring Anthropic’s determination to detect users connected to leading Chinese AI labs is risky.

Unlike individual users who can easily pay for cheap circumvention tech to evade Anthropic’s location blockers without fears of major repercussions, Alibaba could be exposed to legal and compliance risks if caught violating Anthropic’s terms, a source granted anonymity to discuss Alibaba’s Claude ban told Reuters.

For Anthropic, allowing the attacks to continue could hurt the company’s business. Some open source Chinese models are more popular than free and open American counterparts, the Post reported, and Fortune 500 CEOs have made it clear that they’re searching for cheaper AI solutions. For the US, not only would moving to block Chinese distillation of American models be challenging, but it could also be unpopular—blocking Americans from benefiting from cheaper AI alternatives from China, the Post suggested.

Anthropic tracking crossed “scary boundary”

In this climate, where a chatbot user’s loyalty depends on a cost-benefit analysis weighing the cost of accessing models against their capabilities, Anthropic likely can’t afford to lose user trust as it fights to keep frontier models ahead of China’s.

https://arstechnica.com/tech-policy/2026/07/anthropic-outed-for-claude-tracker-that-secretly-monitored-chinese-users/




UK regulator warns of “arms race” to keep up with AI use in financial services

“Is the fact that the chat model might be able to respond to prompts and have a conversation something closer to a recommendation, or guidance?” he asked.

But he also said AI could “democratize” finance by widening access to sophisticated services currently only available to the richest customers. He said people earning only £20,000 a year could gain access to financial advice usually only available “to somebody who has got £10mn in savings or assets,” adding: “I mean what’s not to like about that?”

His report recommends the FCA convenes public and private sector groups to develop an “AI-enabled financial capability service” that provides free information and guidance to the British public on their financial choices.

Many financial services companies are already piloting AI agents that can autonomously carry out financial transactions for companies and consumers. Mills, who is leaving after eight years at the FCA, said managers would still need to be accountable for the actions of their AI models. “You need a human on the hook for what they’re doing,” he said.

AI is likely to “amplify” the threat of fraud and cyber attacks, the report says, calling for the technology to be used to defend the system from such threats. “Deepfakes, synthetic identities, and personalized social engineering are taking fraud and cyber risks into a new era and changing how fraud and cyber attacks,” it says.

Mills’ report also recommends boosting the FCA’s powers under the “critical third parties” regime that allows it to supervise key technology providers to the financial sector, such as Anthropic, OpenAI, Amazon, Google, and Microsoft.

The government is yet to decide which Big Tech groups to designate under the regime, which allows regulators to impose more robust disclosure requirements, including annual self-assessments and “scenario testing” of their ability to withstand severe disruptions.

The report says the FCA could also seek extra powers under the “designated activities regime” that allows it to regulate specific activities without requiring the firms carrying them out to be authorized.

The FCA board is due to discuss the report from Mills before deciding how to respond to its recommendations.

The watchdog has been criticized by some politicians for a 12-week contract it agreed with US tech group Palantir to test whether its AI systems can help fight financial crime. Some MPs have raised concerns the contract could give US authorities access to sensitive UK financial information. The FCA and Palantir have denied this. Mills declined to comment on the Palantir contract.

This story has been amended to clarify that research commissioned by Sheldon Mills found that a fifth of UK adults were open to using AI models to make financial decisions for them.

© 2025 The Financial Times Ltd. All rights reserved. Not to be redistributed, copied, or modified in any way.

https://arstechnica.com/ai/2026/07/uk-regulator-warns-of-arms-race-to-keep-up-with-ai-use-in-financial-services/




AI, droni, missili ipersonici e armi spaziali: USA, Cina, Russia e Europa spendono 2 trilioni di dollari per la nuova guerra

La nuova corsa agli armamenti è già iniziata: l’intelligenza artificiale diventa la vera arma del XXI secolo

La Guerra Fredda appartiene ormai ai libri di storia. Non esistono più due soli blocchi contrapposti impegnati nella corsa agli arsenali nucleari. Oggi il confronto è molto più complesso, coinvolge più potenze e soprattutto si combatte sul terreno delle tecnologie più avanzate.

L’obiettivo non è semplicemente costruire più carri armati o più caccia da combattimento, che pure è nell’agenda dei ministri della Difesa di mezzo mondo. La sfida maggiore è conquistare il primato nell’intelligenza artificiale (AI), nei droni autonomi, nelle armi ipersoniche, nella guerra elettronica, nello Spazio e nei sistemi in grado di prendere decisioni in tempi impossibili per un essere umano.

Secondo le stime riportate da Bloomberg, gli investimenti complessivi delle principali potenze superano ormai i 2.000 miliardi di dollari, distribuiti tra Stati Uniti, Cina, Europa e Russia. Una cifra che richiama inevitabilmente le grandi corse agli armamenti del Novecento, ma con una differenza fondamentale: oggi nessuno sa ancora quale tecnologia cambierà davvero il modo di combattere. L’unica certezza è che arrivare secondi potrebbe avere conseguenze strategiche enormi.

Temi che saranno sul tavolo del vertice della NATO ad Ankara (7-8 luglio), che si occuperà di sicurezza euro-atlantica, tra cui il sostegno all’Ucraina nella guerra con la Russia, il nuovo equilibrio tra Stati Uniti ed Europa, il rafforzamento del Fianco Sud, la produzione industriale della Difesa, con la spinosa questione dell’aumento della spesa al 5% del PIL entro il 2035 da parte dei Paesi partner dell’Alleanza.

Una corsa agli armamenti “multidimensionale”

“Una corsa agli armamenti è in qualche modo già in corso, anche se non l’abbiamo ancora chiamata così. È una corsa multidimensionale”, spiega Celeste Wallander, ex Assistant Secretary of Defense degli Stati Uniti. Per le grandi potenze, osserva Wallander, la vera domanda è capire “su quali tecnologie concentrare gli investimenti”.

Non si tratta infatti soltanto di costruire armi più potenti, ma di integrare capacità completamente nuove: algoritmi di intelligenza artificiale, sensori spaziali, sistemi autonomi, capacità di colpire bersagli a migliaia di chilometri di distanza e strumenti per negare all’avversario l’utilizzo dello Spazio. Un dominio quest’ultimo che, assieme a quello subacqueo, sta attirando sempre di più l’attenzione di Governi e grandi gruppi privati, per il valore strategico che rappresenterà nell’immediato futuro.

Gli Stati Uniti investono 1.500 miliardi e dopo l’AI la frontiera degli armamenti indispensabili si sposta sui dispositivi ipersonici

Washington resta il principale protagonista. L’amministrazione del presidente Donald Trump punta a destinare 1.500 miliardi di dollari alla Difesa nel prossimo bilancio federale. Una parte crescente di queste risorse è destinata all’intelligenza artificiale.

Gli Stati Uniti hanno già impiegato l’AI in operazioni militari durante la campagna contro l’Iran, utilizzandola per supportare la pianificazione delle missioni. Una scelta che ha aperto anche un confronto tra il Pentagono e Anthropic, una delle aziende leader mondiali nell’intelligenza artificiale, sull’impiego delle proprie tecnologie in ambito bellico.

L’obiettivo americano è arrivare a sistemi capaci di collegare automaticamente satelliti, radar e missili intercettori, lasciando che sia l’intelligenza artificiale a decidere, in pochi secondi, come rispondere a un attacco. Secondo Todd Harrison, dell’American Enterprise Institute, questo diventa indispensabile soprattutto contro i nuovi missili ipersonici, le cui traiettorie sono molto meno prevedibili rispetto ai tradizionali missili balistici.

Sul fronte delle armi ipersoniche, però, Washington è ancora in ritardo. Il missile Dark Eagle, sviluppato da Lockheed Martin, rappresenta il primo sistema ipersonico statunitense, ma il Pentagono ha dichiarato che non disporrà di dati sufficienti per valutarne l’efficacia operativa prima del prossimo anno. Anche il Government Accountability Office ha evidenziato problemi produttivi.

Washington al lavoro sul Golde Dome

Parallelamente gli Stati Uniti stanno investendo decine di miliardi nel progetto Golden Dome, il gigantesco sistema di difesa antimissile voluto da Trump. Secondo Bloomberg e il Congressional Budget Office il programma potrebbe superare 1.000 miliardi di dollari.

Il progetto punta a realizzare una rete composta anche da intercettori spaziali, una tecnologia mai sperimentata su larga scala, coinvolgendo colossi come Lockheed Martin, Boeing, RTX, Anduril Industries e molte altre aziende.

“Stiamo vivendo un momento di trasformazione straordinaria della guerra”, afferma il senatore democratico Jack Reed, presidente della Commissione Forze Armate del Senato, “l’intelligenza artificiale e l’autonomia stanno cambiando tutto”.

La Cina punta sull’integrazione tra Stato e imprese

Pechino rappresenta probabilmente il concorrente più temibile. Il bilancio ufficiale della Difesa supera i 400 miliardi di dollari, ma diverse stime occidentali ritengono che la spesa reale possa arrivare fino a 500 miliardi, considerando anche gli investimenti non dichiarati. Nel 2025 il budget crescerà del 7%, il ritmo più lento dal 2022.

La strategia cinese è quella della cosiddetta fusione civile-militare, che integra università, aziende private e grandi gruppi pubblici nello sviluppo delle nuove tecnologie. L’analisi di Bloomberg mostra come l’ecosistema missilistico cinese coinvolga imprese statali e società civili che producono componenti sofisticati: metalli stampati in 3D, sensori a infrarossi, computer embedded e materiali stealth.

Grande attenzione, neanche a dirlo, è dedicata anche all’intelligenza artificiale. Almeno sette laboratori universitari che collaborano con l’Esercito Popolare di Liberazione hanno cercato di procurarsi i più avanzati chip AI di Nvidia. La Cina è inoltre diventata leader mondiale nella produzione di diamanti sintetici, utilizzati per raffreddare i processori più potenti.

Per James Char, docente della Nanyang Technological University, “l’Esercito Popolare continuerà a dare priorità ai sistemi missilistici per la loro capacità di colpire con precisione a lunga distanza. Le salve di missili saranno affiancate da operazioni spaziali, cyber ed elettroniche per interrompere le operazioni del nemico”.

Tra le armi più avanzate figurano i missili ipersonici DF-17, DF-27, YJ-17 e YJ-21, prodotti dalla China Aerospace Science and Industry Corporation.

La Russia punta sui missili ipersonici e sa che non potrà competere con USA e Cina (e forse con l’Europa)

Nonostante il peso economico della guerra in Ucraina, Mosca continua a investire pesantemente. Tra il 2022 e il 2025 la spesa militare è triplicata, raggiungendo 13.600 miliardi di rubli, pari a circa 176 miliardi di dollari. Vladimir Putin ha chiesto lo sviluppo di nuovi sistemi convenzionali e nucleari, ponendo particolare attenzione alle tecnologie spaziali e all’intelligenza artificiale.

Secondo Henry Boyd, senior fellow dell’International Institute for Strategic Studies, a Mosca esiste la consapevolezza che Stati Uniti e Cina dispongano di tecnologie complessivamente superiori. Per questo il Cremlino ha investito soprattutto in sistemi capaci di aggirare le difese occidentali.

Tra questi figurano il missile da crociera a propulsione nucleare Burevestnik, il drone sottomarino nucleare Poseidon e soprattutto il missile ipersonico Kh-47M2 Kinzhal, prodotto da Rostec tramite NPK KBM, che Mosca sostiene possa raggiungere velocità pari a dieci volte quella del suono.

Insieme al missile da crociera Zircon, rappresenta l’unico sistema ipersonico finora impiegato realmente in combattimento. Sul fronte spaziale, invece, la Russia dispone del missile anti-satellite A-235, lanciato da terra. Secondo Boyd, “la Russia è più incline a diventare uno ‘spoiler’ nello Spazio. Se non può sfruttarlo quanto gli altri, trae maggior vantaggio dal negarlo a tutti”,

Anche l’Europa accelera la spesa nelle tecnologie di guerra

Singolarmente nessun Paese europeo può competere con Stati Uniti o Cina. Nel complesso, però, il continente europeo investirà nel 2025 circa 600 miliardi di dollari nella Difesa. Secondo l’International Institute for Strategic Studies, la spesa europea aumenterà del 9%.

Gli investimenti NATO mostrano già un’accelerazione significativa. Le spese per l’artiglieria sono cresciute del 570%, passando da 2,9 a 19,4 miliardi di dollari. Quelle per la difesa aerea terrestre sono aumentate del 525%, da 7,2 a 45 miliardi.

Secondo Tom Waldwyn, ricercatore dell’IISS, l’attenzione si sta spostando progressivamente verso droni, sistemi autonomi e intelligenza artificiale.

Il commissario europeo alla Difesa Andrius Kubilius ha spiegato che Bruxelles sta concentrando gli sforzi su capacità oggi mancanti, soprattutto considerando la dipendenza europea dagli Stati Uniti nelle infrastrutture spaziali. Tra i programmi simbolo c’è IRIS², la costellazione europea di piccoli satelliti destinata a realizzare entro il 2030 una rete sicura di comunicazioni.
Gli annunci degli ultimi giorni da parte della Vicepresidente esecutiva per la Sovranità Digitale, Henna Virkkunen, e dello stesso Kubilius, fanno quasi sorridere per l’entità della spesa: poco più di 325 milioni di euro per 5 progetti su droni e sistemi di contro-droni, difesa marittima e dei fondali marini, Spazio, difesa aerea e missilistica.

Per Rupert Pearce, direttore nazionale degli armamenti del Ministero della Difesa britannico, il vantaggio europeo potrebbe risiedere proprio nella quantità di dati disponibili: “I nostri algoritmi individueranno schemi ricorrenti e saremo in grado di determinare risposte più rapide, efficaci e precise grazie al vantaggio rappresentato dai dati”.

Lo Spazio diventa un nuovo campo di battaglia

Una delle novità più rilevanti riguarda proprio lo Spazio. I satelliti, fondamentali per telecomunicazioni, navigazione GPS, osservazione terrestre e guida dei missili, stanno diventando obiettivi militari. Tutte le principali potenze stanno sviluppando capacità anti-satellite.

La Russia dispone del sistema A-235. La Cina ha testato il missile Dong Neng-2, che sarebbe in grado di colpire obiettivi in orbita geostazionaria, oltre 35.000 chilometri dalla Terra. Gli Stati Uniti stanno invece studiando sistemi spaziali difensivi nell’ambito del progetto Golden Dome.

Distruggere o accecare i satelliti di un avversario significherebbe interrompere comunicazioni, navigazione, ricognizione e capacità di comando, paralizzando le operazioni militari. Lo spazio, dunque, non è più soltanto un’infrastruttura civile, ma sta diventando un vero teatro di guerra.

Il ruolo decisivo delle imprese private

Se durante la Guerra Fredda il predominio apparteneva quasi esclusivamente agli Stati, oggi il settore privato è uno dei protagonisti principali. Negli Stati Uniti operano giganti come Lockheed Martin, Boeing, RTX e nuove aziende tecnologiche come Anduril.

In Cina, la strategia della fusione civile-militare coinvolge imprese private altamente innovative insieme ai grandi gruppi pubblici. Le università, i laboratori di ricerca e le aziende produttrici di semiconduttori, materiali avanzati e software di intelligenza artificiale sono ormai parte integrante dello sviluppo delle capacità militari.

La superiorità tecnologica non dipende più soltanto dagli eserciti, ma dall’intero ecosistema industriale e scientifico di un Paese.

Oltre il nucleare, la nuova deterrenza dell’AI

Il mondo continua a convivere con circa 9 potenze nucleari. Russia e Stati Uniti possiedono ancora il maggiore arsenale, con circa 8.000 testate nucleari dispiegate tra missili, bombe e sottomarini. Ma la vera tecnologia destinata a ridefinire gli equilibri potrebbe essere l’intelligenza artificiale.

Non perché possa provocare distruzioni paragonabili a quelle delle armi nucleari, ma perché promette un vantaggio decisivo nella velocità delle decisioni, nella capacità di prevedere le mosse dell’avversario e nel coordinamento simultaneo di missili, droni, satelliti e sistemi di difesa.

È questa la nuova frontiera della deterrenza. Quella che sta prendendo forma oggi si gioca sulla supremazia algoritmica, sull’autonomia delle macchine e sul controllo dello Spazio. Chi riuscirà a conquistare la leadership in queste tecnologie potrebbe determinare gli equilibri strategici dei prossimi decenni, senza necessariamente sparare il primo colpo.

Novità su Google, per aggiungere Key4Biz tra le tue fonti preferite, clicca qui

Aggiungi Key4Biz tra le tue fonti preferite

Leggi le altre notizie sull’home page di Key4biz

https://www.key4biz.it/ai-droni-missili-ipersonici-e-armi-spaziali-usa-cina-russia-e-europa-spendono-2-trilioni-di-dollari-per-la-nuova-guerra/579056/




Agentic AI Used to Conduct Ransomware Attack via Langflow

A threat actor exploited a vulnerability in Langflow to access an organization’s instance and abuse it in an agentic ransomware attack, cloud security firm Sysdig reports.

Langflow is a Python-based, LLM-agnostic open source framework used for building LLM-driven applications and agent workflows.

As part of the attack, a threat actor tracked as JadePuffer gained access to an internet-exposed Langflow instance through the exploitation of CVE-2025-3248 (CVSS score of 9.8), a critical missing authentication vulnerability disclosed in April.

Successful exploitation of the bug allows attackers to execute arbitrary Python code on the host on which Langflow is running. CISA flagged the flaw as exploited in early May.

After gaining code execution, JadePuffer used the LLM for reconnaissance and swept the system for secrets, including API keys, cloud credentials, cryptocurrency wallets, configuration files, and database credentials.

Next, the threat actor dumped Langflow’s Postgres database to harvest the secrets in it, scanned the reachable internal address space and named services, probed for MinIO addresses for further credential extraction, and deployed a cron job for persistent access to the Langflow server.

Advertisement. Scroll to continue reading.

Throughout this initial phase, the LLM was observed adapting its actions in real time to complete tasks, extract credentials from different file types, and log into discovered endpoints.

During the second phase of the attack, JadePuffer used the LLM to pivot to a production server hosting a MySQL database and an Alibaba Naming and Configuration Service (Nacos) configuration platform.

Widely used in Alibaba microservice architectures, Nacos has been plagued by various security bypasses and uses a well-known default JWT signing key that allows for easy token forgery.

Lateral movement and encryption

JadePuffer connected to this server using a payload that contained root credentials for the MySQL port and abused the LLM to target the Nacos service through multiple vectors.

“That includes exploiting the auth-bypass family (CVE-2021-29441), forging a valid JWT using Nacos’s well-known default signing key, and, with root database access, injecting a backdoor administrator directly into the Nacos backing database,” Sysdig explains.

During the attack, the LLM adjusted the payload to pass login verification, checked for User Defined Functions (UDF), which can lead to OS command execution, and issued a completion marker before ransomware deployment.

Next, it encrypted 1,342 Nacos service configuration items and created an extortion table containing the ransom demand, a payment address, and a contact email address. The encryption key was randomly generated but never persisted or transmitted, essentially preventing data recovery.

“Captured payloads show the LLM escalating from row-level deletion to dropping entire database schemas, narrating its own targeting rationale,” Sysdig notes.

The payloads analyzed by the cybersecurity firm contained natural-language commentary on each action, indicative of LLM-generated code. Furthermore, they showed how the LLM corrected its actions to address failures and provide accurate diagnoses.

“During the operation, the LLM parsed free-text context presented by the target and took an action that only makes sense if that text was read and understood, rather than pattern-matched by a scanner. This behavior recurred across sessions weeks apart,” Sysdig notes.

According to the company, this attack shows that LLM agents significantly lower the barrier for malicious operations, which now require a capable model rather than a capable human. The AI combined known techniques in a successful attack against neglected infrastructure, with close to zero cost to the attacker.

“Defenders should expect the volume and breadth of such campaigns to rise as agentic tooling matures, and they should treat exposed application servers, unhardened configuration stores, and internet-facing database admin accounts as the first surfaces that will be attacked,” Sysdig notes.

Learn More at the AI Risk Summit | Ritz-Carlton, Half Moon Bay

Related: Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution

Related: ‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials

Related: Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors

Related: The AI Token Costs That Can Break Cybersecurity

https://www.securityweek.com/agentic-ai-used-to-conduct-ransomware-attack-via-langflow/




Trump gets OpenAI to offer US 5% stake, far lower than Sanders’ target

In the spring, OpenAI first proposed creating an AI wealth fund that “provides every citizen—including those not invested in financial markets—with a stake in AI-driven economic growth,” FT reported. For society to benefit as much as possible, an OpenAI blog said, an “AI-led future” will likely require “new approaches that give people durable stakes in the systems creating value.”

So far, OpenAI has talked with Trump officials such as Treasury Secretary Scott Bessent and Commerce Secretary Howard Lutnick, as well as Senator Bernie Sanders (I-Vt.), sources told FT.

Sanders has made it clear he’s not impressed with the numbers OpenAI is discussing, though. Last month, sources familiar with Sanders’ discussions with Altman told AP News that Altman remained “far apart” from the senator on how much stake in OpenAI the American public should have.

At that time, Sanders revealed his legislative proposal, which would create a much larger sovereign public wealth fund.

Sanders’ plan requires leading AI firms to pay a one-time 50 percent tax on their stock. Sanders estimated that the tax would yield about $7 trillion, which could be disbursed as direct payments to Americans or invested in programs such as health care, education, and housing.

According to FT, OpenAI has claimed that gifting a 5 percent stake to the US would give Americans more control over AI. But Sanders said the best way to ensure the public benefits from AI is to create a bipartisan Independent Commission for Democratic AI, with members nominated by the president and confirmed by the Senate. That commission could use voting shares to block leading AI firms from making decisions that could harm the public, Sanders told AP News.

“The public has got to have a significant seat at the table to make sure that terrible things do not happen to ordinary people, and that in fact, AI benefits ordinary people, not hurts them,” Sanders said.

For OpenAI’s “conceptual” proposal to work, Congress may have to get involved to implement the mechanisms that would allow the US to take a stake in any AI firms, FT reported. So it seems likely that OpenAI and other firms will be locking horns with Sanders to negotiate what’s fair and what keeps the public safe as AI technology rapidly advances and Americans fear job losses, cybersecurity risks, and a range of harms associated with massive data centers needed to power AI innovation.

Ars could not immediately reach Sanders for comment.

https://arstechnica.com/tech-policy/2026/07/openai-floats-giving-us-5-stake-to-win-over-ai-haters/




Musk’s X poses “serious risk to Americans’ privacy,” advocates warn FTC

And finally, the GDPR is not a substitute for FTC monitoring, they argued. That seems particularly clear since X is currently under investigation for its “unauthorized collection of European users’ data to train its Grok AI model without valid GDPR consent” advocated noted.

“X Corp.’s foray into artificial intelligence development should prompt greater FTC oversight of the company’s privacy practices, not less,” advocates said.

Former AG supports X

X did not respond to Ars’ request to comment.

However, former US Attorney General William Barr has submitted comments supporting X. In his letter, Barr called out hundreds of FTC info demands after Musk bought Twitter as excessive.

Arguing against “permanent agency control of private companies,” Barr pushed the FTC to stop treating the termination of consent orders as requiring extraordinary circumstances, and at the very least reopen the order to consider if the scope of X’s restrictions is proper.

Whether X’s petition can succeed may hinge on X’s legal analysis, though, which advocates claim was “misleading.”

For example, neither of the cases X cited actually supports its claim that a “transformed” company shouldn’t be obligated to maintain an order after restructuring, advocates argued. In one case, an order was terminated by invoking a “sunset” policy that requires such an outcome after 20 years. In the other, an order was not fundamentally changed due to a market shift, as X argued, but eventually modified after 16 years of compliance.

In contrast to those cases, X’s order is “merely four years old,” advocates said, and X has shown it still requires scrutiny. Further, Musk agreed to accept the costs and comply with the order when he bought Twitter, so he should be stuck with it for the entire duration, they argued.

More glaringly, advocates pointed out that X is largely unchanged, serving the same functions as a platform as Twitter.

Musk, therefore, remains “in the exact same business of operating a social media platform, still utilizes user data for targeted advertising, and now has new uses and desires for consumer information in its AI business that make the 2022 Order’s oversight even more vital,” advocates said.

https://arstechnica.com/tech-policy/2026/07/musks-x-poses-serious-risk-to-americans-privacy-advocates-warn-ftc/