Alibaba’s Qwen races past Meta, Google with 3 billion AI model downloads

Alibaba’s Qwen family of open-weight AI models has surpassed 3 billion downloads in six months, making it the world’s most-downloaded open model ecosystem, ahead of Google and Meta. Qwen, has open-sourced more than 460 models, and its ecosystem has spawned 300l-plus derivatives/

Share
Alibaba’s Qwen races past Meta, Google with 3 billion AI model downloads
Source: Hugging Face.

Important publishing notice: Metacurity will be on a publishing break starting on 8/18 and will resume publication on 8/24. Stay safe and sane out there!

Alibaba Group Holding’s open-weight models have accumulated more than 3 billion global downloads in the past six months, eclipsing Meta Platforms, Alphabet, and domestic peers to become the world’s No. 1 artificial-intelligence model.

Qwen, Alibaba’s family of AI models, has open-sourced more than 460 models and its ecosystem has spawned 300,000-plus derivatives, the Chinese technology company said in an emailed statement. Google, part of Alphabet, had 418 million downloads while Meta stood at 227 million in 2026, according to popular open-source AI hub Hugging Face Inc., which published a state of open models report on Aug. 14.

Open models can be downloaded, customized, and used as building blocks for new AI products, making adoption a gauge of which technologies developers are choosing to build on. That has made download and derivative-model figures one measure of influence in the US-China AI race, as Chinese developers, including Alibaba, push capable models that are relatively cheap and easy to adapt. Qwen’s rise suggests that strategy is gaining traction beyond China.

Qwen, along with Moonshot AI Inc, DeepSeek, and Chinese AI model builders, are replicating frontier performance, seeking to bridge the gap with closed models in the US, such as OpenAI Inc. and Anthropic PBC. Export controls on chips and AI systems, such as the brief ban on overseas access to Anthropic’s Fable 5 model this summer, don’t appear to be putting the brakes on Chinese competitors.

Alibaba’s download data for Qwen makes it “one of the largest foundations of the open AI ecosystem,” the Hugging Face report said. The Hangzhou-based cloud, e-commerce and AI tech company is making gains over local rivals DeepSeek, Moonshot Kimi and MiniMax as well as US models.

“Qwen has become part of the default workflow for developers deciding what models to fine-tune and deploy,” the report said. (Saritha Rai / Bloomberg)

Related: Hugging Face, European Central Station, Fortune, China Daily, Forklog

Source: Hugging Face.

Wiz researchers said that an autonomous AI security agent discovered and exploited a critical vulnerability in a Snowflake GitHub repository just five days after an AI-generated code change introduced the flaw.

The vulnerability, found by Wiz's Red Agent in Snowflake's public snowflake-connector-net repository, allowed any GitHub user to execute arbitrary commands in a GitHub Actions runner simply by opening an issue with a specially crafted title.

The flaw was introduced on June 18 in a commit co-authored by "Copilot Autofix powered by AI." According to Wiz, the GitHub Copilot-generated change removed an existing mechanism that safely passed issue titles through an environment variable and instead inserted the user-controlled title directly into a shell command.

That change created a script-injection vulnerability because a malicious issue title could break out of the shell command and execute attacker-supplied commands. A condition in the workflow that appeared intended to restrict who could trigger it was also ineffective, allowing any GitHub user to reach the vulnerable code.

Wiz said its Red Agent autonomously identified the vulnerable workflow and attempted to exploit it. Its first attempt failed with a Bash syntax error, but the AI agent analyzed the error, modified its payload, and tried again successfully without human intervention.

The successful exploit allowed the agent to extract Jira credentials from the GitHub Actions environment. The credentials authenticated to Snowflake's internal Jira system and provided read access to engineering, security compliance, and bug bounty tracking projects, according to Wiz.

Wiz reported the vulnerability to Snowflake through HackerOne on June 23. Snowflake patched the vulnerable workflow the same day and rotated the exposed Jira token the following day.

Snowflake said an investigation of audit logs found no evidence of unauthorized access. Wiz said the logs showed that it was the only party to access the affected system during the five days the vulnerability was exposed and that it deleted all data accessed during its proof-of-concept testing. (Gal Nagli / Wiz)

Commit co-authored co-authored by “Copilot Autofix powered by AI." Source: Wiz.

Metacurity is the cybersecurity news you'd need hours to assemble yourself.

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

A paid subscription to Metacurity delivers

  • Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
  • Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
  • Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
  • Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!


The US is preparing to ‌tell dozens of countries they must pick sides in the artificial intelligence race with China, warning they will be excluded from a US-led AI coalition if they also sign up for Beijing's competing framework, according to a US official and an internal draft reviewed by Reuters.

Washington last year launched the Pax Silica initiative aimed at securing supply chains for AI models, semiconductors and critical minerals, amid a fierce technology rivalry with ​Beijing.

About two dozen countries have joined, including Kazakhstan, a key potential source of critical minerals that has also joined China's coalition, as well as close US allies ​such as Japan, Australia and South Korea.

The draft letter, prepared by the State Department, is addressed to the 35 signatories of a US. "AI ⁠Opportunity Statement" signed in June, which includes members of the non-binding Pax Silica framework and other countries that have expressed a desire to align cooperation on AI with Washington.

By pressuring countries to choose sides, the US hopes to starve China of resources in a race to make the most sophisticated AI, which could be used for military or economic dominance. (Michael Martina / Reuters)

Related: Information Technology and Innovation Foundation, International Business Times, UNN

The systems shaping the future are being trained on data sets that are overwhelmingly in English, and reflect what China sees as a Western way of thinking.

That imbalance is also a strategic vulnerability for the Chinese Communist Party because it means Western views are likely to prevail when it comes to issues like human rights and the status of Taiwan, the self-governed island claimed by Beijing, analysts say.

To fix this gap, and to build more powerful AI tools, Beijing wants to become a leading supplier of data — the troves of text, images and videos — that train AI systems around the world.

Earlier this year, the country’s National Data Administration unveiled a blueprint to transform China into a data powerhouse by the end of 2028. The plan proposed creating “high-quality” data sets in more than two dozen strategic fields, including scientific research, industrial manufacturing and autonomous vehicles.

The plan calls on China to share its data sets worldwide. That was reinforced last month when China pledged to share data to help the dozens of developing countries that attended the World Artificial Intelligence Conference in Shanghai build their own AI systems. China has also already released huge troves of data curated by government labs and state-owned media, making them available for download around the world.

The goal, analysts say, is twofold: to draw more users into China’s AI orbit and to narrow the gap with the United States in access to high-quality training data, which Beijing believes is helping America maintain its lead.

“Competition in the AI ​​era is not only about models and computing power, but also about a high-quality data supply,” Yu Xiaohui, president of the state-affiliated China Academy of Information and Communications Technology, wrote in an article published last month on the data administration’s website. (David Pierson and Berry Wang / New York Times)

Chinese artificial intelligence firm Zhipu, also known as Z.ai, has unveiled its flagship GLM-5.3 model, saying it beat Anthropic’s frontier Mythos 5 model in a key cybersecurity test, as China races to counter Western advances in AI defense.

Beijing-based Zhipu said GLM-5.3 achieved a success rate of 84.5 percent on CyberGym, a benchmark that measures whether models can identify and validate security flaws from source code.

That was above Anthropic’s Mythos at 83.8 percent and OpenAI’s GPT-5.6 Sol at 83.6 percent, according to Zhipu.

However, the Chinese model did not match those foreign systems on ExploitBench, which gauges how far AI models climb the exploitation ladder. Its score of 54.4 percent trailed Mythos’ 78 percent and GPT-5.6 Sol’s 76.5 percent.

Zhipu said it had tested the model with security teams in China against real-world codebases, identifying 2,436 vulnerabilities across 269 projects after expert review. Of those, 1,097 were rated medium to high severity, according to the company.

It said it planned to release GLM-5.3’s weights – the underlying parameters that encode its intelligence – in about two weeks, after an internal safety review and hardening process. It described the model’s cyber-defensive capabilities as “public goods” that developers worldwide could access and improve. (Xinmei Shen and Richard Chen / South China Morning Post)

Related: Economic Times, Dawn, The Register

In mid-July, many of the country’s biggest military contractors received a letter from the Air Force with a stern warning: By Sept. 1, all the software they use for weapons and control systems must be free of products built by the AI company Anthropic. Failure to comply would put all their business with the Pentagon at risk.

Within a month, those same contractors received an unexpected reversal: They could — for now — disregard the earlier instructions about purging Anthropic.

From the Department of Defense to the CIA and NSA, billions have already been spent on using artificial intelligence to develop weapons that could work with less human control, or to test vulnerable military networks and even nuclear codes to make sure adversarial AI systems cannot crack them.

Artificial intelligence is critical to the Golden Dome, President Trump’s vision — fanciful to many experts — of a space-based missile shield.

But little of that work anticipated the powers of Mythos and its AI counterparts, or the prospect that China may be months away from its own formidable and less expensive versions. That could supercharge China’s ability to infiltrate American communications networks, water systems and power grids like those they successfully pierced during the Biden administration in two sweeping attacks called “Volt Typhoon” and “Salt Typhoon.”

“These are the kinds of things we were talking about and worrying about before AI became a daily headline,” said Jen Easterly, who ran the Cybersecurity and Infrastructure Security Agency during the Biden administration. “What’s different now, and what makes the problem more urgent, is the potential for AI to amplify those capabilities.”

So far the Trump administration has veered wildly in response, at first abandoning its hands-off approach to regulating the industry, then briefly shutting off access for foreigners from Mythos — including some of its inventors — then lifting that ban. (David E. Sanger, Dustin Volz, Ana Swanson and Julian E. Barnes / New York Times)

French Prime Minister Sebastien Lecornu will hold a crisis meeting today to respond to the cyberattack disclosed last week targeting the country’s tax collection agency.

A judicial investigation of the hack is under way, Lecornu’s office said Sunday. People whose data were compromised in the attack on the General Directorate of Public Finance will be notified beginning Monday, according to the statement.

The inter-ministerial crisis meeting will review the notifications that will be made to taxpayers, as well as the steps that are being taken to improve cybersecurity, Lecornu’s office said.

The cyberattack, which took place in June and July, was revealed last week. A hacker obtained information concerning 678,000 individual and business tax accounts, including their taxable income and the tax withholding rate, the government said Friday. Data relating to the addresses and sizes of real estate properties were also accessed, according to the statement. (Phil Serafino / Bloomberg)

Related: Security Affairs, The Connexion, Reuters, RFI, The Local France, Silicon Republic, EuroIntegration, The Star, Voice of Emirates, First News Media, Cryptonomist, Mezha

Iranian intelligence operatives are contacting Israeli journalists via WhatsApp and Telegram, posing as familiar figures and inviting them for interviews or offering to collaborate on projects in an attempt to hack their devices, take over their accounts and obtain sensitive information, according to an official statement issued by the Shin Bet security service and the Israel National Cyber Directorate.

Haaretz reporters have also been approached recently by foreign operatives offering videos or information. In a joint statement, the two agencies said they had recently identified a new wave of attempts by Iranian intelligence to target Israeli journalists and media professionals with phishing attacks. The trend began after October 7, 2023, and Israel has since seen an increase in cyberattacks and Iranian attempts to infiltrate Israeli public discourse. These have included sending threatening packages and letters to Israeli journalists and researchers, including Haaretz reporters.

According to the statement, these attempts aim to obtain information against the backdrop of recent political and security developments. The Shin Bet and the National Cyber Directorate are working to prevent and thwart the efforts. According to information obtained by Haaretz, the Shin Bet has contacted journalists who were believed to be potential Iranian targets and assisted them with cybersecurity protection.

In these phishing campaigns, operatives personally contact journalists by impersonating people they know, primarily through WhatsApp or Telegram, with messages specifically related to their line of work, such as collaboration offers or invitation interviews. (Omer Benjakob / Haaretz)

Related: Ynet News, Yeshiva World News

Tensions between state election officials and the Trump administration are rising as we head into the heart of the midterm election season, with frustrations boiling over during a rare election security call hosted by the Cybersecurity and Infrastructure Security Agency for state officials.

During the call, Arizona Secretary of State Adrian Fontes unloaded on the agency.

CISA used to be a go-to shop for many states looking for help ensuring that their elections weren’t hacked, targeted, or undermined by cyberattacks or foreign interference. CISA provided states with classified security briefings on threats, helped ensure that state voting equipment wasn’t vulnerable to cyberattacks, and worked with election leaders to game out potential risks.

All that changed when Donald Trump returned to the White House last year. The second Trump administration scaled back its support for states, cut back CISA staff, and launched an investigation of its former leader, whom Trump accused of disloyalty because he pushed back on the president’s false claims that the 2020 election was rigged. CISA has not had a permanent director since the start of Trump’s second term.

After more than a year of near silence, elections officials wondered if CISA would step up to offer classified intelligence briefings on emerging cyber threats from hostile countries, specialized testing of election equipment, or training on how to prepare for potential problems on Election Day.

Instead, CISA leaders provided what one participant characterized as a generic “CYA” (cover your a**) briefing that offered state officials few assurances that the federal government would help thwart threats this November.

Participants said acting CISA Director Nick Andersen and Jim Harrell, the assistant director for integrated operations, offered no concrete support for the 2026 election, which is less than 90 days away. Instead, the participants said, CISA leadership seemed more focused on the 2028 presidential election. (Dion Nissenbaum / Votebeat)

Related: Stateline

The Australian Securities and Investments Commission (ASIC) is warning that there has been a steep rise in scammers luring victims into phony investment opportunities using deepfakes of celebrities and politicians, with prime ministerAnthony Albanese the figure most commonly co-opted.

ASIC dealt with more than 19,400 scams last financial year, almost triple the amount in the year before.

Fake celebrities were just the beginning. Scammers have built networks of fake brands, websites, reviews, news articles and videos that work together to convince victims to ultimately give them money, which ends up going to overseas criminals, ASIC said.

According to reports to the National Anti-Scam Centre’s Scamwatch, Australians lost $7.4m to the top 10 impersonated public figures, and Albanese was at the top of the list. (Tory Shepherd / The Guardian)

Related: ASIC, 7News, ABC.net.au

Source: The Guardian.

Crypto wallet provider SafePal said in an X post that an authorization flaw in its order-tracking system allowed unauthorized access to the personal data belonging to approximately 39,798 customers.

The exposed information includes customer names, email addresses, shipping addresses, phone numbers, and purchase details, according to SafePal's incident report. The information in question belongs to customers who placed orders with SafePal between Mar. 2, 2025, and Apr. 11, 2026.

"This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers," SafePal wrote. "No evidence has been found that the incident itself compromised access to SafePal wallets or funds."

The company warned that attackers might target affected users with phishing and impersonation attempts, posing as SafePal employees to offer firmware updates, refunds, or replacement devices before attempting to glean wallet credentials from those users.

SafePal has not disclosed when the flaw was introduced, when customer records were first accessed, or how many attackers may have obtained the data. (Zack Abrams / The Block)

Related: Reuters, CoinDesk, Bleeping Computer, Gadgets 360, Security Week, crypto.news, The Next Web, Decrypt, Startup Fortune, Cryptoslate, CoinMarketCap, Gizmodo, Briefs.co, The Economic Times, crypto.news

Crypto company Bits of Gold reported a cyber incident that occurred several days ago, in which information on customer details was apparently stolen, such as full name, ID number, email, IP addresses, and phone number.

The company emphasized that customers' money and coins were not harmed, nor were passwords, ID photocopies, and credit card details. It noted that the company's customers should be vigilant regarding approaches from third parties, including attempts to impersonate official entities.

The cyber incident at Bits of Gold is part of a broader cyber incident worldwide, in which there was a breach at a software company that Bits of Gold uses. According to estimates, there are hundreds of companies around the world that were affected, while at this stage no additional Israeli company is known [to have been affected]. Therefore, the assessment is that Bits of Gold was not a direct target of the attack.

The company's customers received a message from the company stating:
"A few days ago, we identified unauthorized access to a support system for data analysis, as part of a large-scale cyber incident that also affected other companies worldwide. Upon identifying the incident, we blocked the access and disconnected the system from the information sources, so that this access has ended. Our security team has begun a comprehensive review of the incident, accompanied by a company specializing in investigating and responding to cyber incidents. We have also updated the relevant authorities, and we continue to review the incident and monitor the systems." (Shaked Green Arava / CTech)

Related: Crypto Briefing, Crypto News, Startup Fortune

Attackers have been taking over Macs through a flaw in Apple's screen sharing feature and using them to mine Monero, the Netherlands' National Cyber Security Center (NCSC) recently said in an updated advisory.

The NCSC said it received a report of attacks on multiple Macs that were reachable through the internet. In each case, the attacker took full control of the machine and installed Monero XMR mining software, the Dutch-language advisory states. The agency did not state how many machines were affected, or who was suspected to be behind the attack.

Apple patched the flaw on Aug. 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. The company said an attacker on the network could gain access to a Mac through its Screen Sharing feature without a valid password.

Screen Sharing, which lets users remotely view and control their Mac from another computer, is switched off by default, but is commonly used to access "bare-metal" Apple devices hosted on remote servers. Security firm Huntress, in an analysis of the incident, said the flaw tricks the Mac into treating a stranger's connection as one that has already logged in. Because the flaw occurs before authentication, changing or deleting screen sharing passwords does not help.

CISA initially rated the flaw 7.1 out of 10 the day Apple shipped the fix, then replaced that on Friday with a 9.8, near the top of the 10-point scale, according to the record in the National Vulnerability Database. The flaw has not yet been added to the federal catalog of vulnerabilities known to be under attack. (Zack Abrams / The Block)

Related: Nationaal Cyber Security Centrum, Bloomingbit, Security Affairs, Bitcoin Foundation

Germany’s federal police agency, the BKA, said three suspects were picked up in Europe and charged with fraud, and Brazil’s federal police said four others were arrested on similar charges there as part of Operação Klonen (Operation Clone), which executed 21 search and seizure warrants nationwide.

Over four days in November 2023, the hackers were able to make “numerous unauthorized withdrawals from the accounts of German online banking users” by exploiting a vulnerability in a payment provider, the BKA said. Brazilian authorities said the process involved cloned payment cards.

The criminals then moved and laundered the money through networks in Brazil and four European countries, police said.

Neither police agency specified the affected bank, but Brazilian media reported that it was Germany’s Commerzbank. German media reported in late 2023 that Commerzbank had suffered a €30 million hack. At the time, the Frankfurt-based bank said customers would not incur losses. The bank did not immediately respond to a request for comment.

The suspects detained in Europe will be prosecuted in Spain and Bulgaria, the BKA said. Spanish and Bulgarian authorities assisted in the investigation, the agency said, as well as the Frankfurt public prosecutor’s office. (Joe Warminsky / The Record)

Related: BKA.de, Gov.br, Help Net Security, Bleeping Computer, Otempo Brazil

Baptist University in Hong Kong has said it is reviewing the security of its information technology (IT) systems after a ransomware group claimed online to have illegally accessed the institution’s data.

The allegations were made by “The Gentlemen”, an advanced cybercrime group that first appeared in the middle of last year.

Cybersecurity monitoring platforms reported that about 1,900 credentials linked to the university may have been compromised.

The purported data reportedly included roughly 130 staff accounts, about 1,770 other user accounts and 260 third‑party employee credentials.

Researchers say The Gentlemen operates on a revenue-sharing model – renting its extortion software to other hackers – and has expanded rapidly across global networks.

In a statement released on Tuesday night, the university said it had noted a webpage alleging that its IT systems were unlawfully breached and was closely reviewing the security of its systems and personal data.

It added that it would take appropriate action under established mechanisms and remain in contact with local regulators and law enforcement. (Danny Mok / South China Morning Post)

Related: TVB, The Star, The Standard

Security researchers at Jamf identified a new macOS infostealer called AmnesiaStealer that is spreading via a convincing fake GitHub download page, tricking Mac users into pasting a malicious Terminal command that silently installs malware and can later grant attackers live, hidden control of the victim’s browser session.

They discovered the campaign after spotting a counterfeit site at github.aoitour[.]com that near-perfectly copies GitHub’s dark theme, Octocat logo, and “Verified Publisher” badge.

Instead of offering a real download, the page displays a “Terminal installation” box with a one-click copy button and step-by-step instructions telling visitors to open Terminal, paste the command, press Return, and enter their device password.

This social-engineering technique, known as ClickFix, has also been used to spread other Mac malware families like Atomic (AMOS) and MacSync, showing that criminal groups are reusing the same deceptive template across campaigns.

Once a victim pastes the command, a hidden shell script quietly downloads a password-protected ZIP archive, extracts a disguised binary into the /tmp folder, strips Apple’s quarantine flag, and launches the payload before deleting its own tracks.

This is followed by a Rust-based infostealer that profiles the machine, displays a fake native “Installer” password prompt to capture the login credential, and uses it to unlock the keychain, Apple Notes, Telegram sessions, browser data, and documents.

The malware is named after the “Amnesia Panel” backend it communicates with, and its embedded configuration is unlocked with the key 4mn3s1a_2o26!xK. (Guru Baran / Cyber Security News)

Related: Jamf, Security Affairs, Security Week, CSO Online, SC Media, Infosecurity Magazine, Bleeping Computer, Security Affairs

Counterfeit GitHub ClickFix Terminal Lure. Source: Jamf.

Starting in 2029, the US judiciary will publicly disclose precisely how many times judges authorized the use of wiretaps to be carried out with hacking tools and spyware, which fall under the category of what the feds call network investigating techniques, or NITs.

The Administrative Office of the US Courts told Democratic senator Ron Wyden this week that it will begin tracking the new “spyware/hacking” surveillance category starting in the 2028 Wiretap Report, which will be published the following year.

A spokesperson for the Administrative Office of the US Courts confirmed the change: “The Wiretap Report is compiled from individual forms submitted from throughout the country and throughout the year. Before the new data can appear in the annual report, reporting forms and procedures need to be updated to accommodate the new categories,” the spokesperson said. (Lorenzo Franceschi-Bicchierai / TechCrunch)

Related: Android Headlines, SC Media

Personal information belonging to about 180,000 students, alums and employees of Sogang University has been leaked in a data breach.

Sogang University said Saturday it had detected signs of an information leak involving its integrated login accounts on the previous day.

In a notice posted on its official website, the university said it had confirmed signs of some information being leaked following an external attack by an unidentified party.

“Upon becoming aware of the incident, we immediately took emergency measures in accordance with our security breach response procedures,” the university said.

According to the university, the compromised information includes student identification numbers, names, affiliations, email addresses, mobile phone numbers and encrypted passwords for the university’s integrated login system.

The school said it immediately blocked the IP address used in the attack and restricted access to affected services while implementing network separation measures, adding that it is taking additional security measures to prevent the incident from spreading and causing further damage. (Kan Hyeong-woo / The Korea Herald)

Related: The Chosun Daily, The Dong A-Ilbo, Seoul Economic Daily, The Herald Business

Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications.

​Organizations using Threema On-Prem did not experience any issues because they rely on their own infrastructure.

In a post-mortem report, the end-to-end encrypted instant messaging service said that the attacks were difficult to defend against because the threat actor constantly changed patterns.

To avoid similar incidents, the Swiss company has implemented “specialized DDoS protection as an additional measure” to filter attack traffic upstream and reduce the load on its infrastructure. (Ionut Ilascu / Bleeping Computer)

Related: Threema, Security Affairs, r/Threema

A significant Azure exfiltration campaign is currently underway, driven by a threat actor actively selling massive enterprise employee databases. These extensive directories were reportedly downloaded directly from the organizations’ Azure/Entra portals utilizing compromised credentials.

Over the past week, a threat actor operating under the moniker “TheHatman” has flooded cybercrime forums with massive internal employee directories belonging to several Fortune 500 companies. The actor claims these dumps were extracted directly from the organizations’ Azure Tenants.

The affected organizations and the staggering amount of records offered by the threat actor:

  • McDonald’s Corporation: ~1,700,000+ records
  • TCS (Tata Consultancy Services): ~800,000+ records
  • Vodafone: ~425,000+ records
  • HCL Technologies: ~250,000+ records
  • InterContinental Hotels Group (IHG): ~185,000+ records
  • Kyndryl: ~170,000+ records
  • Gap Inc.: ~80,000+ records
  • Hexaware Technologies: ~20,000+ records
  • Wyndham Hotels: ~9,000+ records

Across all the affected tenant dumps, the leaked fields consistently include foundational corporate directory attributes. (Infostealers by Hudson Rock)

Related: Ransomnews, Security Affairs

A screenshot showing the extent of the threat actor’s posts on a dark web forum, listing multiple global enterprises. Source: Infostealers by Hudson Rock.

The Metropolitan Police has apologized after it inadvertently disclosed email addresses of around 140 people who say the late Harrods owner Mohamed Al Fayed sexually abused them.

Scotland Yard confirmed to the BBC it copied in all those who had signed up to receive a monthly email update for victims instead of blind copying them.

The update revealed a further three suspects in their 70s and 80s had been interviewed under caution, bringing the total number interviewed to seven.

The force said it had referred itself to the Information Commissioner's Office (ICO). It is considering providing further support to the victims along with additional safeguards.

The Justice for Fayed and Harrod Survivors group described the incident as "appalling" and requested further information about how the force is strengthening protections for personal data.

A Met Police spokesperson told the BBC a monthly update sent to victims on 11 August regarding Operation Cornpoppy had contained details of progress in the investigation.

Operation Cornpoppy is the Metropolitan Police investigation into people who may have facilitated or enabled sexual offending by Al Fayed.

The spokesperson said: "Due to human error, recipients' email addresses were visible to others on the distribution list. The issue was identified quickly, and immediate action was taken.

"We understand the impact this may have on victims and sincerely apologize. Everyone affected was contacted directly on the day of the incident.

"The incident is being investigated as a matter of priority, and we are reviewing our processes to help prevent a similar breach from happening again."

The force said the breach affected victims who had opted in to receive updates from the investigation team, but recipients had been split into smaller groups, meaning email addresses were only visible within those groups rather than across the entire cohort.

The BBC understands around 140 people have signed up to the updates.

The force has previously said 154 victims have reported allegations connected to Al Fayed and that supporting survivors remains at the heart of the investigation. (Matthew Hill / BBC News)

Related: Fashion Network, AFP, Euronews

Microsoft has now started laying the groundwork to fully remove the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11, which has been abused by malware and ransomware for years. (Mayank Parmar / Windows Latest)

Related: BetaNews, Neowin

France's top court blocked ​a bill banning social media access for under-15s, saying it infringed upon freedom of ‌expression and delivering a setback for President Emmanuel Macron, who asked his government to rewrite the legislation.

The bill would have barred children younger than 15 from opening a social media account from September 1. Accounts already open would be ​closed within four months by social media platforms, which would also need to use age ​verification approved by the French privacy regulator. (Elizabeth Pineau and Sudip Kar-Gupta / Reuters)

Related: Bloomberg. Washington ExaminerPoliticoBloomberg LawRTÉReutersCourthouse News ServiceAssociated PressThe GuardianCBS NewsAl JazeeraSeoul Economic DailyFrance 24Reclaim The Net, KQTV-TV, Hacker Newsr/privacy, Slashdot

Best Thing of the Day: AI Can't Seem to Produce Any Tech Heroes

A new survey conducted by CNBC's Generation Labs asked over 1,000 US adults aged between 18 and 34 to share their thoughts on politics, AI, and the country’s economy, with the vast majority of respondents saying they don't trust the nine executives overseeing AI companies.

Worst Thing of the Day: Data Breaches Are More Expensive in the AI Era

According to IBM’s Cost of a Data Breach Report, AI-driven attacks increased 56% over last year’s study, adding about $1 million to the cost of a breach to reach an average of $4.99 million–a 12% increase.

Bonus Worst Thing of the Day: Amazon Used to Sell Books, Not Destroy Them

A 404 Media investigation was able to reveal Amazon’s massive book-buying operation aimed at scanning books to train AI, which hasn’t been previously reported, by placing a tracking device in a rare book we suspected would be acquired by an AI company for training data, and following it around the country to its final destination. 

Closing Thought

Read more