AI Watch: China's AI surge is forcing DC and Silicon Valley to rethink the AI race
US seizes 1,000+ piracy sites streaming World Cup matches, 7-Zip fixes critical RCE flaw, Attackers begin exploiting critical ServiceNow AI platform flaw, Millions of aftermarket car alarms can be hacked over Bluetooth, SonicWall zero-days used to deploy custom malware on VPN appliances, much more

Metacurity is the cybersecurity industry's daily reality check—an independent briefing that cuts through vendor spin, social media outrage, and endless recycled narratives to explain what actually matters and why.
Every weekday, thousands of cybersecurity professionals—including many of the industry's most respected security leaders—rely on Metacurity to separate signal from noise. We do the reading, research, and analysis so you don't have to.
If Metacurity helps you stay informed, save time, or see the bigger picture, please consider becoming a paid subscriber. Reader support is what keeps Metacurity independent, agenda-free, and focused on serving the cybersecurity community—not advertisers, vendors, or investors.
The AI race took another sharp turn yesterday as a series of Chinese model releases triggered debates over national security, open-source AI, copyright, infrastructure and even the future economics of artificial intelligence.
The common thread: China's open-weight strategy is forcing both Washington and the leading US AI companies to reconsider long-held assumptions about how the AI market will evolve.
The immediate catalyst was last week's release of Moonshot AI's Kimi K3, followed almost immediately by Alibaba's preview of Qwen 3.8 Max. Both models demonstrated that Chinese developers are rapidly closing the performance gap with frontier US systems while making the models available as open weights, letting organizations download and customize them rather than relying solely on cloud APIs.
Technology analyst Ben Thompson argues the resulting debate is asking the wrong question. In an extensive analysis, Thompson contends that benchmark comparisons obscure the larger economic shift underway: AI is becoming a commodity business in which the real competitive advantage lies not in marginally better benchmark scores but in delivering intelligence at the lowest possible cost. Frontier AI companies remain focused on recovering the enormous fixed costs of training increasingly powerful models, he argues, while the long-term market is likely to reward whoever delivers high-quality inference most efficiently.
China's embrace of open-weight models is strategically aligned with its industrial ambitions by commoditizing AI itself, China strengthens complementary industries, including robotics, manufacturing and automation, where it already holds significant advantages. Thompson also disputes the idea that restricting open-weight models improves cybersecurity, arguing that defenders increasingly need locally deployable AI systems capable of analyzing sensitive logs and responding to attacks without transmitting data to external cloud services. If US restrictions make American models unavailable while Chinese open models remain accessible, he warns, organizations may end up relying on Chinese AI for their own cyber defense, a result he calls counterproductive.
That framing helps make sense of the disarray now visible in Washington. According to The Wall Street Journal, executives from OpenAI and Anthropic are warning policymakers that inexpensive Chinese open-weight models threaten both US national security and the business economics financing frontier AI development — first, because downloadable models with advanced cyber capabilities could be modified and used by adversaries without centralized controls, and second, because reliance on free or cheap open-weight models could undercut frontier companies' ability to recover the enormous investments needed to keep pushing capabilities forward.
White House AI adviser David Sacks pushed back hard, characterizing the frontier labs' argument as an attempt to use regulation to suppress emerging competition. Axios reports the administration itself remains split — some officials want to treat Chinese open-weight models as a national security threat, others argue restricting access would slow US innovation without doing much to stop global adoption.
That division has a face now, too. This week the Trump administration's Center for AI Standards and Innovation (CAISI) lost its third leader in a matter of months when director Chris Fall resigned. Fall had replaced Collin Burns, who lasted less than a week after reportedly being pushed out over prior ties to Anthropic. CAISI sits under Commerce, distinct from the White House "AI czar" role Sacks himself held before stepping down in March, a post that's now gone unfilled for months.
Beijing, meanwhile, appears to be having its own second thoughts. According to the Financial Times, China's Ministry of Commerce is consulting with companies including Alibaba, ByteDance and Zhipu about tightening export controls on AI model weights, training data and advanced chip technology — reportedly considering blocking foreign organizations from downloading Chinese model weights while still permitting access through hosted services, alongside restrictions on overseas production of chips based on Chinese designs and foreign acquisitions of strategically important AI companies. The discussions suggest Beijing now believes it holds AI technology worth protecting, not just acquiring.
The strategic debate coincided with OpenAI publishing new research on evaluating the safety of increasingly autonomous "long-horizon" AI systems, testing models capable of extended sequences of action with minimal human supervision, rather than individual prompts, reflecting industry concern that agentic AI introduces risks traditional safety evaluations weren't built to catch.
The changing economics of AI are reshaping the web itself, too. A New York Times report examines growing concern that Google's AI-generated search summaries are keeping users on Google rather than routing them to publishers, cutting into traffic many content creators depend on for revenue; Google disputes the characterization, arguing its AI search features help surface high-quality content.
Legal issues continue evolving in parallel. Reuters reports a federal judge granted final approval of Anthropic's $1.5 billion settlement resolving copyright claims over its use of books to train Claude — the largest known settlement of a US copyright case, removing one of the largest legal disputes facing a frontier AI developer and potentially shaping how future training-data suits get resolved.
At the infrastructure level, Arcade proposed redesigning the emerging Model Context Protocol (MCP) around stateless rather than persistent interactions, arguing stateless architectures improve scalability and make AI agents easier to operate as enterprise tool ecosystems expand. (OpenAI, Zijing Wu and Ryan McMorrow / Financial Times, Amrith Ramkumar and Tina Li / Wall Street Journal, Maria Curi / Axios, Ben Thompson / Stratechery, Kate Conger / The New York Times, Julie Bort / TechCrunch, Blake Brittain / Reuters, Nate Barbettini / Arcade)
Related: PCMag, Benzinga, Unite.AI, Hacker News, TechCrunch, MarketWatch, Benzinga, Capacity, Unite.AI, Seoul Economic Daily, Reuters, Reuters, Pillar Security, Neowin, New York Times, The Information, New York Times, Wall Street Journal, Wccftech, Washington Post, Daring Fireball, Simon Willison's Weblog, Bloomberg, Gizmodo, Interconnects AI, Tom's Hardware, Semafor, Rohan's Bytes, Straight Arrow, International Business Times, The Information, crypto.news, CoinGape, TechCrunch, The Daily Caller, Futurism, SiliconANGLE, MIT Technology Review, Neowin, NewsMax.com, South China Morning Post, The Decoder, MarketWatch, The Neuron, ZeroHedge News, RuntimeWire, Engadget, Moneycontrol, TechCrunch, Silicon Republic, Tech Times, Publishing Perspectives, Nairametrics, BMI, Blockonomi, Docket updates, Benzinga, Seoul Economic Daily, SiliconANGLE, Courthouse News Service, Thurrott, Unite.AI, Tech in Asia, Silicon Canals, TechCrunch
The US Justice Department seized more than 1,000 websites and blocked 1,970 domains used to stream FIFA World Cup 2026 matches without authorization.
Law enforcement authorities identified the seized domains using leads provided by US authorities, FIFA (Fédération Internationale de Football Association), the Motion Picture Association's Alliance for Creativity and Entertainment (ACE), and multiple entertainment networks, including beIN Media Group, NBCUniversal, Ultimate Fighting Championship (UFC), and Warner Bros.
These seizures are part of several joint law enforcement actions based on investigations by the National Intellectual Property Rights Coordination Center (IPR Center) and the US Homeland Security Investigations (HSI) Washington.
The Justice Department's Criminal Division seized over a thousand domains as part of Operation Offsides, a joint law enforcement action led by the IPR Center in coordination with HSI Washington and involving 14 partners across 54 countries, including nearly 400 web domains by the end of last month.
"Operation Offsides is part of the Department's ongoing effort to protect copyright while reducing the risk to American consumers from the malicious software embedded in many illicit streaming services," said Assistant Attorney General A. Tysen Duva.
"These streamers not only violate copyright laws but also expose viewers to potential threats — including malware attacks and unsecure connections that can compromise personal and financial data," added HSI Special Agent in Charge Eric Weindorf. (Sergiu Gatlan / Bleeping Computer)
Related: Justice Department, ABC News, BBC News, Tech Times, The Record, Bloomberg Law, Chosun Biz

7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files.
The vulnerability, disclosed by Lunbun researcher Landon Peng, exists in 7-Zip's processing of XZ-compressed data.
According to an advisory from the Zero Day Initiative published this week, specially crafted XZ data can trigger a heap-based buffer overflow, potentially allowing attackers to execute arbitrary code as the user.
While the developer has not published technical details about the flaw, the changes in the 26.02 source code suggest it is related to how 7-Zip tracks available space while decompressing XZ data.
The patch adds checks to ensure the decoder cannot write beyond the remaining available space in an output buffer, helping prevent a heap-based buffer overflow. (Lawrence Abrams / Bleeping Computer)
Related: Zero Day Initiative, PCMag, Security Affairs, TechSpot
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows.
Cybersecurity company Searchlight Cyber, which found this critical vulnerability and reported it on April 1st, says that it allows unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow platform in high-complexity attacks.
ServiceNow addressed the flaw across hosted instances starting in April and released CVE-2026-6875 security updates for self-hosted instances one week ago, on July 13th.
Over the weekend, Defused security researchers confirmed that attackers have begun exploiting the vulnerability in the wild, with the first attempts being observed on Friday.
"We are observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875)," Defused warned in a Saturday tweet.
"The payloads hit the same pre-auth sink @SLCyberSec documented (/assessment_thanks.do), but the sandbox-escape gadget reaches the same code-execution primitive by a different route than their published PoC."
ServiceNow has yet to flag this security as actively abused and, in the official advisory, still states that it is "not currently aware of exploitation against ServiceNow instances."
However, the company advises all customers who have not already done so to secure their systems against attacks by upgrading to a patched release as soon as possible. (Sergiu Gatlan / Bleeping Computer)
Related: Tech Times, Security Affairs, Help Net Security, CSO Online

A team of security researchers at UC San Diego found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car's horn or flash its lights, or even disable its ignition and leave a driver stranded.
The KARR alarm devices are typically installed by car dealers, not manufacturers or owners, and used as a measure to prevent auto theft from dealer lots. Yet when the cars are sold, the alarms typically aren't removed, even if the buyer declines to pay for it as an additional feature. That means car owners across the US have a hackable device under their hood whose code they'll need to update to protect their vehicle—but one that, in many cases, they never purchased and have no idea is there.
"This is a system added to cars by dealers, and unfortunately it has a severe vulnerability that allows anyone to gain access to any of these cars," says Aaron Schulman, the UCSD computer science professor who led the research. “It's designed to make cars more secure, but ultimately it's created a vulnerability that needs to be patched immediately across millions of vehicles. We're trying to get the word out that you need to check your car for this device and manually patch it now.”
The company that sells the KARR Security System, Acrisure Protection Group, today rolled out a firmware update for the vulnerable Bluetooth model of its aftermarket KARR alarm to fix the security issues UCSD uncovered. (Andy Greenberg / Wired)
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances.
Last week, SonicWall warned that threat actors were actively exploiting two previously undisclosed vulnerabilities in an exploit chain that affected SMA1000 Secure Mobile Access appliances.
The flaws, tracked as CVE-2026-15409, a critical server-side request forgery (SSRF) vulnerability, and CVE-2026-15410, a high-severity command injection flaw, affect SMA1000 6210, 7210, and 8200v appliances.
SonicWall released patches in versions 12.4.3-03453 and 12.5.0-02835, urging customers to install the updates immediately.
In a new report, incident response firm Volexity, which assisted SonicWall in investigating the attacks, detailed the full exploitation chain and how threat actors installed the custom malware on compromised SMA1000 appliances. (Lawrence Abrams / Bleeping Computer)
Related: Volexity, Help Net Security, Security Week

The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol.
Ostium is a decentralized trading platform built on the Arbitrum finance-native blockchain scaling solution, allowing users to speculate on the prices of traditional and crypto assets directly from a cryptocurrency wallet.
According to an update from the platform, the attacker submitted illegitimate price reports disguised as valid ones, then rapidly opened and closed large positions to generate artificial profits.
Trader collateral was held in a separate contract and was not affected, while existing positions remain open, the company clarified.
Prices are supplied to the protocol via external data feeds, while trades are settled in USDC, a cryptocurrency designed to maintain a 1:1 peg to the US dollar. (Bill Toulas / Bleeping Computer)
Related: Halborn, crypto.news, The Block
Security researchers broke out of the sandboxes in four widely used AI coding agents, including Cursor, OpenAI's Codex, Google's Gemini CLI, and Antigravity, without attacking the sandbox head-on.
The agent stays inside the box and follows every rule. It just writes a file that a trusted tool outside the box later runs, loads, or scans, and the escape happens on its own.
Pillar Security's research team, Eilon Cohen, Dan Lisichkin, and Ariel Fogel, reproduced the bypasses over several months and published them today as a series they call the Week of Sandbox Escapes, one write-up a day.
These sandboxes draw a simple line: the agent is trusted inside the project workspace, the host outside is protected.
The catch is that files inside the workspace are not inert. Tools running outside the sandbox read and act on them, so a file the agent is allowed to write can turn into a command the host later runs.
Related: Pillar Security, TechRadar, Neowin

Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms, with one estimate putting the number of vulnerable WordPress websites at tens of millions.
Last week, WordPress patched two critical security flaws, urging people who run its software on their websites to update it “immediately.” The vulnerabilities are so severe that WordPress enabled forced updates where possible.
Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerabilities in the wild, meaning they are taking over websites that are still running susceptible versions of WordPress. (Lorenzo Franceschi-Bicchierai / TechCrunch)
Related: WordPress.org, SecurityWeek, Cyber Daily, Cloudflare, Aikido Security's Blog, The Register, SC Media, CyberInsider, eSecurity Planet, CSO, Help Net Security
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations.
The company says that last month it identified an intrusion that had occurred on August 9, 2025, which led to the threat actor obtaining " personal information of certain individuals."
“We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which the Estée Lauder Companies use for HR management purposes,” the notification says.
“On June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals.”
Although the Estée Lauder notice does not disclose the vulnerability exploited in the intrusion, the date of the breach correlates with the mass-exploitation campaign targeting Oracle E-Business Suite through CVE-2025-61882. (Bill Toulas / Bleeping Computer)
Related: Computer Weekly, The Cyber Express, CyberInsider
French cloud operator OVH has revealed it used its Sydney, Australia, datacenter as the crash test dummy to test a rapid rollout of a fix for the critical Januscape guest-host escape bug in the Linux kernel-based virtual machine (KVM).
Januscape, aka CVE-2026-53359, allowed attackers with root access to a guest VM to execute code as root on the host, crash that machine, or take over all other guest VMs.
French cloud OVH’s CISO Julien Levrard revealed how the company handled the emergency patch job on tens of thousands of hosts that run approximately a million virtual machines, in a lengthy post that offers an unusually detailed and candid account of how clouds cope with major security incidents. (Simon Sharwood / The Register)
Related: OVH

The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints.
JadePuffer was disclosed earlier this month as an agentic threat actor (ATA) capable of running autonomously through the stages of a ransomware attack, from initial access to data encryption.
Cloud security company Sysdig says that the AI agent adapted to technical difficulties in real time and optimized the intrusion mechanism to find the correct fix in less than a minute.
Sysdig says that the attacker returned to the previously breached Langflow instance vulnerable to CVE-2025-3248 with the Go-based EncForge ransomware "built specifically for AI and machine learning (ML) infrastructure."
The researchers found no evidence that JadePuffer exfiltrated any data during the intrusion, and EncForge itself does not appear to include a data-stealing mechanism. (Bill Toulas / Bleeping Computer)
Related: Sysdig, Cybersecurity Insiders, Infosecurity Magazine

Around 4 million users affected by a data breach involving Seoul's public bike-sharing service Ttareungi will be given a 30-day pass, the Seoul Facilities Corporation said.
The 30-day pass is worth around 5,000 won ($3.40) and allows users to ride the bike for one hour per day. The coupon will be distributed through the Ttareungi app next month and must be redeemed within three months.
Users who already have an existing pass can use the coupon within three months after their current pass expires. (Korea JoongAng Daily)
Related: The Chosun Daily, Digital Today
The US Federal Communications Commission (FCC) wants to ban products from companies suspected to be selling rebranded and re-shelled DJI drones and cameras, specifically products from Cogito, Fikaxo, Lyno Dynamics, Skyhigh Tech, Spatial Hover, SZ Knowact, WaveGo, Xtra and XAG, because they "pose an unacceptable risk" to US national security.
The FCC only proposed slapping the companies with $25,000 fines for evading the agency's official inquiries on whether they're marketing products under the country's Covered List.
In December 2025, the commission added all new foreign-made drones and components to that list, which is specifically for products that are prohibited from being imported into and sold in the United States due to national security concerns. DJI was perhaps the most prominent company affected by the ban. (Mariella Moon / Engadget)
Related: FCC, Drone XL, The Verge
The US FBI's Internet Crime Complaint Center (IC3) updated an earlier warning about scammers impersonating the agency online, saying fraudsters continue to use the scheme "to deceive and revictimize individuals."
According to IC3, there are two different schemes being used to target cybercrime victims, both directly and by soliciting them to report incidents.
In the first scheme, IC3 said scammers create fraudulent social media profiles and pages impersonating FBI personnel or IC3. They may also infiltrate online groups for fraud victims or contact victims directly while claiming to represent the FBI or the complaint center.
In other cases, victims are being contacted by someone claiming to be an FBI agent after realizing they were approached by someone trying to scam them and saying they intended to report the incident to the FBI or file an IC3 complaint. The FBI said the impersonator then directs victims to a fake IC3 update page or continues communicating through messaging apps.
In the other instance, scammers are creating AI-generated videos on social media depicting senior FBI officials and directing users to a spoofed IC3 website to report cybercrimes they may have fallen victim to, with the scammers then collecting the information and using it to contact victims for further fraud. AI-generated depictions of public figures are similarly being used to make such scams appear legitimate. (Brandon Vigliarolo / The Register)
Related: IC3
Exposure management startup Empirical Security raised $25 million in a Series A funding round.
Brightmind Partners led the round. (Chris Metinko / Axios)
Related: FinSMEs, FinTech Global, The SaaS News, BizJournals
Best Thing of the Day: UK PM Off to a Good Tech Start?
Britain’s new Prime Minister Andy Burnham has appointed Kanishka Narayan as minister for artificial intelligence, making the post a cabinet-level position for the first time.
Worst Thing of the Day: Let Korea Be Korea
South Korea's decision to fine e-commerce firm Coupang over a data breach has drawn criticism from Washington and raised questions about the country's openness to American tech, raising worries the matter is impacting Seoul's relations with the US.