Looks like JFrog's 0-days let OpenAI's models hack Hugging Face JFrog security researchers discovered that OpenAI's AI models could be tricked into exploiting zero-day vulnerabilities in Hugging Face's infrastructure, demonstrating a new class of AI-powered supply chain attacks. The researchers found that by manipulating model metadata, they could get OpenAI's models to execute malicious code on Hugging Face's servers, highlighting risks in AI model sharing platforms. MOST POPULAR AI https://beta.theregister.com/tag/ai - Storage A requiem for Optane, Intel's KV Cache killer that could have eased the RAM price crunch With microscopic latencies and otherworldly write endurance, it was perfect for today's AI workloads - but gone before they arrived - AI and ML MCP gets an enterprise makeover Now happier running in a conventional K8s environment, with an easier-to-live-with lifecycle - AI and ML War machines can run amok with AI in control Tour of the AI kill chain maps the risks of ubiquitous surveillance and flawed algorithms - AI and ML Too many AI agents can get in each other's way For enterprise agents, less is more - AI and ML Impostor Chinese models pretend they're Claude Researchers find GLM and Kimi can adopt Claude's identity, but the evidence stops short of proving distillation Infosec https://beta.theregister.com/security - Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more - Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more - Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included - Security EQT buys majority share in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified - Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career FOSS https://beta.theregister.com/tag/FOSS - FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash another Word up - GNOME can look like Windows – and Flashback can do it without extensions New 'Simple-taskbar' is an option, but there's a simpler, stabler way - A moment of silence, please, for the final release of Debian on x86-32 New Debian versions hit FOSSland in the form of 13.6 and 12.15 - Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websites Flaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide - Frame: A new X11 server – implemented directly in assembly Joins yserver, Phoenix, and of course XLibre – and outlier Arcan - Cinnamon 6.8 will support Wayland – if you want it Next version of Linux Mint’s desktop has both kinds of display server