News, p. 34
News
427 stories · page 34 of 48xAI sues a user for bypassing Grok's safeguards
xAI filed a civil suit against a man from South Carolina, whom it accuses of opening accounts under a false identity and constructing deceptive prompts to bypass Grok's safeguards and produce sexualized images of minors. The company is seeking damages and a permanent ban from access.
Read →OpenAI launches an automated attacker that hardens its models
OpenAI unveiled GPT-Red - an internal tool that automatically attacks its own models (red-teaming) and feeds what it learns back into their training. Per the company, the new version achieves noticeably fewer breaches under prompt injection than its predecessor from months ago.
Read →Thinking Machines released Inkling - an open model they don't even market as the strongest
Mira Murati's lab unveiled its first open-weights model. The interesting part is the bet: a base you can download and fine-tune for yourself.
Read →Thinking Machines open-sourced a frontier-class model
On 15 July the lab led by Mira Murati - OpenAI's former CTO - showed Inkling, its first public model, and released it with open weights. It's not a small demo model: a large mixture-of-experts class, multimodal, with a long context window, that anyone can download and run themselves.
Read →A critical hole in Oracle E-Business Suite joins the actively exploited list
On 15 July, CISA added a vulnerability in Oracle E-Business Suite to its KEV catalog - one that allows unauthenticated takeover of the payments module. The deadline for US federal agencies falls on 18 July. Three days. The same day, an older hole in the KNX building-automation protocol joined the list too.
Read →CISA puts four actively exploited zero-days into KEV in one day
On 14 July CISA added four CVEs to the Known Exploited Vulnerabilities catalog - SharePoint, two bugs in SonicWall SMA1000, and AD FS. Three different surfaces. Confirmed exploitation on every one. Two of the deadlines fall on 17 July.
Read →The ECB picked 36 payment service providers for the digital euro pilot
On 14 July the ECB announced which 36 payment service providers will join the digital euro pilot - chosen from over 50 applicants to the call from March 2026. The pilot starts in the second half of 2027 and runs for 12 months. For now it's a beta. Not legal tender.
Read →Cloudflare rolled out a code that shows when DNSSEC has been bypassed
On 3 July the Albanian domain .AL stopped opening for resolvers with DNSSEC checking on. The operator AKEP had changed the key. But the record in the root zone still pointed to the old one. Cloudflare's public resolver 1.1.1.1 restored access with a workaround, but for the first time marked the answer with a code that openly says: this check was skipped.
Read →Vercel is retiring Node.js 20 starting 1 October
From 1 October 2026 Vercel removes Node.js 20 as an option for new deployments in Project Settings. The old stuff keeps running. Only a new build after that date needs a newer version.
Read →