Governance, Regulation, Legislation, Geostrategies
Stanford researchers call for safeguards as AI enters the physical world
(DigWatch) Researchers from the Stanford Institute for Human-Centered AI have called for early safeguards and stronger public testing capabilities as AI world models move closer to use in physical systems. World models build working representations of environments and attempt to predict how conditions will change in response to an action. Potential applications include robotics, autonomous vehicles, infrastructure planning, industrial design and emergency response. The Stanford policy brief divides the technology into three broad functions. Renderers generate visual representations, simulators attempt to reproduce physical behaviour, and planners determine which actions a machine should take. – https://dig.watch/updates/stanford-urges-governance-for-ai-world-models
UK Sovereign AI fund invests in inference chip developer OLIX
(DigWatch) The UK government has made an undisclosed equity investment in OLIX through its Sovereign AI venture fund, joining a $312 million funding round that values the British chip developer at $3.3 billion. The Series B round also included investment from Arm, Fundomo, Hudson River Trading and Netflix co-founder Reed Hastings. Existing investors increased their commitments to the London-based company, which was founded in 2024. – https://dig.watch/updates/uk-sovereign-ai-fund-invests-in-inference-chip-developer-olix
Intelligence, Security, Surveillance
Fake Open VSX Extensions Harvest Private Repo and CI Data
(Alessandro Mascellino – Infosecurity Magazine) Counterfeit extensions impersonating real developer tools have been found on the Open VSX registry, with roughly a quarter of them harvesting the git and continuous integration identity of the organizations running them. New research Manifold Security published on August 4 showed 77 packages appeared between July 26 and August 1, each republishing the name and namespace of a real extension from an account that did not own it. All beaconed to a single domain registered 11 days before the first package surfaced. Most sent little more than a hostname. Squatted namespaces across the set included AMD, LEGO Education, Hyperledger, Azure, Artsy, Salesforce OSS, a US federal agency and marketplace.visualstudio, which impersonated the marketplace itself. – https://www.infosecurity-magazine.com/news/open-vsx-evil-twin-extensions-git/
WhatsApp Scam Hijacks Accounts via Linked Devices Feature
(Alessandro Mascellino – Infosecurity Magazine) Three vulnerabilities in an open-source AI agent orchestration platform have exposed sensitive data and allowed unauthenticated command execution on servers and developers’ machines, with two rated critical and one carrying a maximum CVSS score of 10.0. According to new research by Oasis Security published on August 4, the flaws affect Paperclip, a control plane its developers describe as a platform for operating zero-human companies. Oasis identified all three bugs during an assessment of its authenticated and local deployment modes. The findings follow a run of similar disclosures, including a critical Flowise flaw and a Langflow bug exploited within 20 hours. – https://www.infosecurity-magazine.com/news/whatsapp-voting-scam-linked/
Prompt Injection Remains Biggest LLM Risk, Despite Limited Incidents
(James Coker – Infosecurity Magazine) Prompt injection attacks continue to present the most dangerous threat from large language models (LLMs), despite the relatively low number of recorded incidents relating to this vector, according to an updated analysis from the Open Worldwide Application Security Project (OWASP). The non-profit foundation published the third version of its community-driven Top 10 for LLM Applications list, on August 4, 2026. For the third year in a row, practitioners listed prompt injection as the number one security challenge emanating from the use of GenAI tools. Like other OWASP Top 10 lists, this document is designed to help developers, data scientists and security professionals improve and prioritize their security strategies. Prompt injection is when a legitimate user’s or malicious actor’s input into an LLM alters the model’s behavior in ways the application developer did not intend. It is a vector to a range of negative impacts, including bias or other harmful content and sensitive information disclosure. The OWASP report noted that were its rankings determined by raw incidents alone, prompt injection wouldn’t even make the top 10 list. The fact security practitioners rank it so highly is indicative of the efforts spent by teams in tackling this threat. “Teams fight injection hard, so fewer clean exploits reach a public database, and the public count understates the risk that mature teams already spend real money holding off,” the OWASP report read. The most effective approach to addressing prompt injection is to design the surrounding system on the explicit assumption that the model’s instruction boundary will eventually be bypassed, and constrain what the model is permitted to do, and what its outputs are permitted to reach, OWASP wrote. – https://www.infosecurity-magazine.com/news/prompt-injection-llm-risk/
Get Ahead of the Alerts and Secure What Matters Most
(Sarah Armstrong-Smith – Infosecurity Magazine) Here is a question the security industry does not ask itself often enough. Billions have been poured into detection capability, AI-driven tooling and managed security operations over the last decade, thousands of analysts working round the clock, watching dashboards, chasing alerts. Yet the threat is getting worse, not better. So, at what point do we stop adding to the pile and ask whether we are solving the right problem? My honest view is that we are not, and the numbers bear that out. The model we have built is reactive by design. It measures what happens after the threat is already inside your environment. It does not ask whether it was preventable, and for most midmarket organizations that is the question that matters. For a business with a lean IT team, the detect-and-respond model is not really a strategy. It is a way of staying one step behind something that moves faster than you can. – https://www.infosecurity-magazine.com/opinions/ahead-alerts-secure-matters/
ChainDrop Worm Hits 400+ npm Packages with Two Billion Monthly Installs
(Phil Muncaster – Infosecurity Magazine) Security researchers have warned of a major new Shai-Hulud-based campaign which has already compromised more than 430 packages with a combined two billion monthly installs. The ChainDrop campaign began on August 4 when attackers compromised the GitHub account of a maintainer behind the popular keyv key storage library, which has around 127 million weekly npm downloads, according to Aikido Security. They used that access to inject a credential-stealing worm across other packages, including cacheable (29 million downloads/month), flat-cache (565 million), and file-entry-cache (557 million), the write-up claimed. “The compromise was carried out by pushing malicious files directly to the main branch and then immediately cutting a new release, meaning the poisoned versions were published to npm with valid provenance signed by GitHub Actions,” Aikido explained. – https://www.infosecurity-magazine.com/news/chaindrop-worm-400-npm-two-billion/
Frontier Models Engage in Unsanctioned Behavior During Testing
(Phil Muncaster – Infosecurity Magazine) Frontier AI models recently engaged in “sustained, potentially harmful activity” targeting real people and organizations during testing, security evaluators have warned. The UK’s AI Security Institute (AISI) said it detected “unusual data transfers” leaving its systems on July 28. A subsequent investigation found that in 10 of 122 runs during a test where agents were given a task of solving a cybersecurity challenge an AI agent took autonomous, unsanctioned action on the live internet, targeting real people and organizations, the AISI said. The institute recorded 19 such actions, 17 of which were traced to Anthropic’s Mythos 5 and two to OpenAI’s GPT-5.6-Sol. – https://www.infosecurity-magazine.com/news/frontier-models-unsanctioned/
Fake Bank of America Phishing Scam Installs Remote Access Malware
(Beth Maundrill – Infosecurity Magazine) A new phishing scam that presents a fake Bank of America message is being used by cybercriminals to gain remote control of victims’ users. Identified by cybersecurity firm Huntress, the fake message imitates the bank’s visual style, layout and branding, all the way from the initial phishing email to the eventual webpage that victims are redirected to. The messages were sent to the Huntress honeytrap account on July 28. It prompted the recipient to visit what it claimed to be the bank’s website. – https://www.infosecurity-magazine.com/news/fake-bank-of-america-phishing-scam/
SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access
(Pierluigi Paganini – Security Affairs) Securonix Threat Research has been tracking an active multi-wave campaign they’ve named SMOKE#SCREEN, in which unknown attackers use rotating social engineering lures, fake Zoom updates, Adobe software notices, business document reviews, system maintenance utilities, to silently install ConnectWise ScreenConnect on victim machines. ScreenConnect is a legitimate remote monitoring and management tool used by IT teams worldwide. Once installed, it gives the attacker persistent full remote access that looks exactly like authorized IT activity. That’s the point. “The campaign relies on a toolkit of VBScript droppers, batch file loaders, compiled .NET executables and a HTML phishing page, all ultimately pointing to a live WsgiDAV-based staging server at 207.174.0.143:8080.” reads the report published by Securonix. “Victims who execute any of the initial access files end up with a fully functional ScreenConnect agent silently installed and beaconing to one of three attacker-controlled relay servers, providing the threat actor with persistent, legitimate-looking remote access to compromised hosts.” – https://securityaffairs.com/196637/uncategorized/smokescreen-campaign-abuses-screenconnect-to-give-attackers-remote-control-access.html
SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency
(Pierluigi Paganini – Security Affairs) Switzerland’s Federal Office for Information Technology and Communications, known as BIT or FOITT, disclosed that unknown attackers had compromised approximately 200 accounts on its on-premises SharePoint servers. The FOITT said the unknown attackers are believed to have exploited vulnerabilities in Microsoft’s SharePoint software. The software manufacturer had reported several such vulnerabilities in mid-July. The FOITT is the largest IT service provider in the Federal Administration. It provides around 50,000 workstation systems, develops customised, secure and user-friendly IT solutions together with the administrative units, and operates over 1,000 specialist applications, mainly in its own modern data centres. The FOITT operated the servers in the federal government’s own data centres and, according to its own statements, had immediately begun installing the security updates provided. FOITT detected the anomalies on July 28 and confirmed the account compromise three days later, on July 31. – https://securityaffairs.com/196625/hacking/sharepoint-flaws-used-to-hack-switzerlands-federal-it-agency.html
IBM opens AI security service to hundreds of US institutions for free
(DigWatch) IBM and Red Hat will give more than 185 US research universities and 100 NGOs and think tanks free access to Lightwell, a service designed to help organisations address vulnerabilities in open-source software. Lightwell combines generative AI-powered automation with human engineering expertise to identify, validate and remediate weaknesses in software dependencies. Eligible institutions will receive digitally signed fixes designed for the software versions they already use, potentially avoiding costly or disruptive upgrades. The service operates within each institution’s existing environment and does not require IBM or Red Hat to access proprietary source code, research or organisational data. – https://dig.watch/updates/ibm-red-hat-free-lightwell-access-universities-ai
UNESCO warns AI in courts must not weaken justice
(DigWatch) Courts should prepare for AI failures, cyberattacks and technology-related disruption before expanding the use of AI, according to experts convened by UNESCO. The panel, held on 16 July during the 2026 Global Conference of the International Decade of Sciences for Sustainable Development, examined how judicial systems can adopt AI without weakening their independence, credibility or ability to continue operating. AI tools could help courts process case material, reduce administrative backlogs and improve access to legal information. However, panel members warned of risks including data loss, manipulated evidence, cybersecurity breaches, unreliable outputs and dependence on private technology providers. – https://dig.watch/updates/unesco-ai-in-courts-judicial-resilience
Frontiers
WHO and ITU plan open AI platform for noncommunicable disease care
(DigWatch) The World Health Organization and the International Telecommunication Union are developing an open digital platform to help countries build and test AI tools to prevent and manage noncommunicable diseases. Known as Be He@lthy, Be Mobile 2.0, the project represents the next phase of a joint programme launched in 2012. The original initiative helped countries use mobile services to deliver health information and behaviour-change interventions addressing conditions such as cardiovascular disease, diabetes and cancer. BHBM 2.0 will provide an open, interoperable cloud environment in which governments and health institutions can prototype AI chatbots, digital assistants and other health applications. Planned resources include customisable software modules, WHO-curated information, reference retrieval-augmented generation pipelines and deployment templates. – https://dig.watch/updates/digital-health-for-noncommunicable-disease-care
AI brain age maps reveal early signs of dementia
(DigWatch) Researchers at the University of Southern California have developed an AI method that maps how individual brain regions appear to age and how those regional patterns relate to cognitive decline. The deep-learning model was trained using MRI scans from 14,748 cognitively healthy adults aged 19 to 100. Instead of reducing brain ageing to a single number, it estimates the apparent age of individual voxels, the three-dimensional units that make up an MRI scan. Researchers tested the model on scans from more than 1,900 additional participants, including cognitively healthy adults and people with mild cognitive impairment or Alzheimer’s disease. – https://dig.watch/updates/ai-brain-age-maps-dementia-risk