Kimi K3 escaped AI security sandbox during testing
ByteDance trains AI model to rival Anthropic, Vishing gang targets Wall Street firms with fake login sites, Violent crypto robberies put 2026 on record pace, Chinese router maker pulls devices after backdoor discovery, Spike in suicides alarms US Cyber Command, much more

Metacurity is the cybersecurity news you'd need hours to assemble yourself.
Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.
Metacurity delivers
- Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
- Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
- Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.
Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.
Please consider supporting us. And thank you!
According to researchers at Frontier Security, the latest model to escape onto the open internet during security testing is Kimi K3, a powerful open-weight offering from the Chinese company Moonshot AI.
Frontier says that Kimi K3 went outside of its sandbox while testing its defensive cybersecurity skills. As with incidents previously reported by OpenAI and Anthropic, the escape was partly enabled by a misconfiguration in the sandbox designed to contain it. Frontier claims, though, that the incident shows Kimi has fewer cyber safeguards than most other powerful AI models, something that allowed it to go off and use the internet without express permission.
Unlike other recent incidents of AI agents going off-script, Kimi K3 did not hack anything after accessing the internet—because the answers to the problems it was seeking were easily attainable on GitHub. (Will Knight / Wired)
Related: Frontier Security, South China Morning Post, Bloomberg, Cyber Security News, Digital Trends, SiliconANGLE, Insurance Business
ByteDance is training an AI model that could approach the size of Anthropic’s most cutting-edge Mythos system, as Chinese companies continue to narrow the gap with the top US labs.
The Chinese tech giant is at an early stage of training a model with as many as 10tn parameters — three times larger than Moonshot’s Kimi K3, the biggest Chinese model released to date, according to three people with knowledge of the matter.
The ByteDance model is being pre-trained — a stage that typically takes three to six months — before it is fine-tuned and released if all goes well, one of the people said. The exact model size would only be determined at a later stage.
Anthropic doesn’t disclose the size of its models, but industry estimates say its most advanced Mythos 5 has about 8tn parameters and Fable 5 about 5tn. While parameter count sets the fundamental capacity or memory limits for the models to store information, actual capability also depends on other factors such as data quality and training methods. (Zijing Wu and Eleanor Olcott / Financial Times)
Related: Reuters, The Information, Semafor, Finimize, Caixin Global, SBS, Wccftech
According to Google and internet intelligence data, ransom-seeking hackers who use phone calls to compromise their victims targeted dozens of prominent US financial institutions and other businesses over the past month.
The data shows the hackers devised websites aimed at stealing passwords from employees of private equity firms and financial companies including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, TPG, CME Group, Clearlake Capital and Moody's as well as other businesses.
Google said that the hackers operate under a range of names, including Redact, Pink, Falcon and Helix.
Experts say the hackers' use of low-tech tactics such as phone calls to target the financial industry illustrates how, despite sophisticated security programs and AI-driven threats, the oldest tactics still rank among the most effective. (Raphael Satter, A.J. Vicens and Anirban Sen / Reuters)
Related: Bloomberg, Google Cloud Blog, Bloomberg, Financial Times, BleepingComputer, SiliconANGLE, NullTX, TechCrunch, PYMNTS

Researchers at Chainalysis report that violent criminals have stolen more than $30 million in cryptocurrency from holders through the first half of 2026, putting the year on track to become the worst on record for physical attacks on crypto owners.
The figure counts only successful thefts and cases where a victim gave up funds. Figures provided by the blockchain analytics firm noted that this year trails 2025's full-year record of $58 million but notably arrives at mid-year.
Chainalysis warned the pattern would surpass that total if it holds through the second half.
Counting attempts as well as completed thefts — ransoms demanded, coerced transfers that were blocked, and funds later frozen or recovered — the totals run far higher, at roughly $316 million in 2024, $180 million in 2025, and $107 million so far in 2026, according to the firm.
Chainalysis called even those figures a likely undercount, since they capture only reported attacks.
The attacks, known in security circles as "wrench attacks," span home invasions, kidnappings, and hostage situations, and target crypto holders because they can be forced to transfer wealth in an instantly and irreversibly movable form. (Naga Avan-Nomayo / The Block)
Related: Chainalysis, Bitcoin News, Infosecurity, The Crypto Times, crypto.news, Cointelegraph, Decrypt

Chinese router maker Zbtlink Electronics said it was suspending sales of routers found to contain a backdoor and pulling the affected software from its website while it developed updates to address the issue.
Cybersecurity firm VulnCheck identified a backdoor in at least 20 models of routers made by Shenzhen-based Zbtlink Electronics, Zbtlink said in a statement, opens new tab on its website that it was aware of the research, which found the flaw could allow access and control of the device and potentially other devices on the network.
The backdoor discovered by VulnCheck CTO Jacob Baines and dubbed “Endlessdoors” serves “solely as an after-sales technical support tool,” the company said, adding that it was intended to assist customers with device troubleshooting and configuration “only upon their explicit request and authorization.”The tool “has never been used for unauthorized access,” the company said. (AJ Vicens / Reuters)
Related: zbtlink, CNET, The Register, Android Authority, PCMag, TechRadar
The US military’s cyberwarfare unit, US Cyber Command, is scrutinizing an unusually high number of deaths by suicide among personnel over a month-long period this summer, according to government officials and other people familiar with the matter.
The deaths have worried US lawmakers and military leaders within the secretive section of the armed forces, which defends American computer systems and hacks foreign adversaries, according to the people and records reviewed by Bloomberg News. They’ve also resurfaced officials’ longstanding concerns about the mental health of military hackers who have over the last year seen their workload surge because of foreign conflicts.
Between early June and early July, as many as five people who worked in or closely with US Cyber Command took their own lives, according to internal military communications, public records and the people. They spoke on condition that they not be identified because they weren’t authorized to discuss the matter.
In June, Cyber Command’s leader acknowledged three suicides in an email to staff, said two of the people. Public records show two more suicides followed.
One of the dead was Technical Sergeant Kevin Stallings, a digital network intelligence analyst whose family told Bloomberg they wanted him to be identified to bring greater attention to the suicides. Stallings was stationed at Fort Meade, Maryland, Cyber Command’s headquarters. He took his own life the month before he’d have turned 37. (Patrick Howell O'Neill and Jake Bleiberg / Bloomberg)

Security researchers demonstrated that vulnerabilities in widely used backend platforms for children's GPS smartwatches allow attackers to remotely track wearers, activate microphones and cameras, spoof locations, intercept communications, and replace emergency contacts, according to research presented at Black Hat.
To illustrate the impact, researchers Vangelis Stykas and Felipe Solferini remotely tracked a WIRED reporter wearing a $30 children's smartwatch, secretly photographed him, and listened to conversations through the device without any indication it had been compromised.
The researchers analyzed more than 70 GPS-enabled children's watches and vehicle trackers and found that most rely on just three Shenzhen-based backend platforms—SETracker (YiQingTeng/Wonlex), SinoTrack, and NewGPS2012—meaning vulnerabilities in a handful of supply chains can affect dozens of consumer brands and tens of millions of devices.
Researchers disclosed the flaws to the affected vendors months ago. SETracker initially denied the vulnerabilities but appeared to implement fixes shortly before the Black Hat presentation after WIRED provided evidence of successful exploitation. SinoTrack and NewGPS2012 did not respond, and the researchers said their attack techniques against those platforms still appeared to work. (Andy Greenberg, Matt Burgess, Yulia Almazova / Wired)
Related: Andy Greenberg on LinkedIn
Researchers at Forescout conducted a new scan of internet-connected industrial equipment and found over 4,000 Rockwell Automation and Allen-Bradley controllers exposed online, including 22 in cities impacted by cyberattacks on US water systems.
Their findings show that direct internet access to equipment used in water and wastewater operations remains common despite years of warnings from manufacturers and federal agencies.
The exposed devices use EtherNet/IP, an industrial protocol that allows for communication between control equipment, engineering workstations, and other systems. When the port is open to the public internet, outside users may be able to identify devices and, depending on their setup, change settings or write new configurations.
The scan, run through the Shodan search engine Monday, found that 2,844 of the exposed controllers (65%) were in the United States.
The FBI and Environmental Protection Agency issued a joint advisory last week confirming attacks at water and wastewater utilities in at least 12 states since July 27. Officials have since named Michigan, South Dakota and Georgia among the affected states. Nine systems were hit in Michigan, and one wastewater lift station was hit in South Dakota. (Greg Otto / CyberScoop)
Related: Forescout, CyberPress

Chief District Court Judge Bryan Biedscheid in Santa Fe ordered Meta to pay $567 million and make changes for the user experience of juvenile accounts after finding its platforms helped create a public nuisance harming teens.
The judge's ruling follows a two-phase trial in the state’s case brought by New Mexico Attorney General Raúl Torrez.
The $567 million figure is on top of $375 million in civil penalties from a jury verdict in Phase 1 of the trial, which found Meta committed 75,000 violations of the New Mexico Unfair Practices Act.
Biedscheid wrote that New Mexico is in a youth mental health crisis and that Meta’s platforms are “a significant contributing cause to the crisis.”
The order said the $567 million fund will support awareness and prevention, screening and assessment, referral and coordination, treatment and evaluation over a five-year period.
The largest share, $420 million, goes to treatment. The order said Meta must also file written progress reports with the court and the state by June 30 and Dec. 31 each year during that period. (KOB)
Related: Wall Street Journal, BBC, The Guardian, Fox Business, The Verge, Quartz, nmdoj.gov, First Judicial District Court of New Mexico, Tech Policy Press, Associated Press, Scottish Legal News, Silicon UK, Proactiveinvestors UK, JOE.ie, Lawyer Monthly, UPI, Reuters, Sky News, CBS News, The Wrap, TRT World, Bloomberg Law, Proactive, Social Media Today, KOAT, Outlook Business, Outlook India, Mediaweek, Channel NewsAsia, Financial Times, Source New Mexico, Al Jazeera, Albuquerque Journal, Santa Fe New Mexican, Courthouse News Service, CNET, Reuters, CNN, India Today, Newser, Times of India, CNBC, Business Insider, New York Times, Toledo Blade, Law360
Researchers at Huntress report that a Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials.
The malware can intercept and redirect transactions with various cryptocurrencies. Although it can empty wallets entirely, it can also calculate the total value of a transaction to determine how much to divert to the attacker.
They discovered the payload after responding to a ClickFix incident.
The targeted user received an email with a link to a page instructing them to run a command in Terminal.
This downloaded a Bash script acting as a profiler and malware loader that collected system information (e.g., CPU, RAM) and retrieved a Mach-O payload that matched the victim system’s processor architecture. (Ionut Ilascu / Bleeping Computer)
Related: Huntress, Apple Insider

Researchers at Malwarebytes report that criminals are building fake identities using AI-generated deepfakes of real OnlyFans creators, luring their followers with promises of live chats, and then disappearing after collecting payment.
The scheme runs on social platforms that most people consider harmless: TikTok for discovery, Snapchat for the conversation, Cash App for the payment, and by the time the fan realizes something is wrong, the money is already gone, and the account is blocked.
“This is a form of catfishing, in which an attacker impersonates someone online and engages in romantic or sexual interactions for ulterior motives. In this case, the scammers create fake accounts on platforms like TikTok, using material lifted from a real creator’s photos and given a synthetic voice,” reads the report published by MalwareBytes. “They’ll use that to nudge viewers into a direct message conversation on services like Snapchat.”
The choice of Cash App as the payment method isn’t accidental. It’s a peer-to-peer platform built for informal transfers between friends, not commerce — and transfers clear instantly. Once sent, the money is effectively gone. (Pierluigi Paganini / Security Affairs)
Related: Malwarebytes
Microsoft announced that over the past year it has paid out more than $20 million through its bug bounty programs.
Between July 1, 2025, and June 30, 2026, the company received vulnerability reports through its 15 bug bounty programs from researchers across 64 countries.
Microsoft said it received 2,531 eligible reports, and 562 researchers have been awarded a total of over $20 million, with the largest single payout reaching $200,000.
The total amount includes $2.3 million given to participants at the Zero Day Quest hacking contest. In addition, $800,000 was paid out through new initiatives, such as those targeting vulnerabilities in third-party and open source code.
Microsoft noted that it saw a significant increase in submission volume during the second half of the year, which it attributed to “both strong engagement from the research community and the growing use of AI to support security research”.
Microsoft paid out roughly $17 million in 2024 and 2025, and approximately $13 million every year between 2020 and 2023. (Eduard Kovacs / Security Week)
Related: Microsoft, IT Pro, The Register, Forbes, Windows Central, Neowin, GBHackers, Cyber Security News, eSecurity Planet

US Senator Martin Heinrich (D-NM) and the entire New Mexico congressional delegation are demanding answers from Defense Secretary Pete Hegseth after revelations that a Department of Defense GPS jamming exercise contributed to a medical plane crash that killed four crew members and ignited a wildfire that burned nearly 32,000 acres.
In a letter, Heinrich was joined by Sen. Ben Ray Luján (D-NM) and Reps. Teresa Leger Fernández, Melanie Stansbury, and Gabe Vasquez, all Democrats, in pressing Hegseth for accountability over the Pentagon’s role in the May 13 crash in Lincoln County.
Just before midnight that night, a Beechcraft King Air medical transport plane carrying two pilots and two flight nurses took off from Roswell bound for Sierra Blanca Regional Airport in Ruidoso to pick up a patient for transport to Albuquerque. According to the lawmakers, the aircraft’s GPS was jammed by a scheduled military test event in the area, causing the routine medical flight to overshoot its landing pattern by 10 miles. At 12:15 a.m. on May 14, the plane slammed into the side of the Capitan Mountains, killing all four crew members instantly and sparking a wildfire that burned for three weeks before crews could contain it.
The resulting blaze scorched 31,860 acres in the Capitan Mountain Wilderness area of the Lincoln National Forest. At its peak, more than 1,000 personnel battled the fire using seven helicopters, bulldozers, water tenders, and fixed-wing air tankers. It was the first fire of the season in New Mexico to require a Complex Incident Management Team and one of only two such complex fires the state has seen this year. While no structures were lost, evacuation orders stayed in place for weeks, and taxpayers are on the hook for an estimated $37.7 million in fire suppression costs. (Aaron Parnas / Meidas News)
Related: Sen. Martin Heinrich, Source New Mexico, New Mexico Political Report, The National, Santa Fe New Mexican
The OpenSourceMalware research team uncovered a Russian-linked software supply chain campaign that published more than 700 malicious npm packages designed to exploit AI-generated package hallucinations, or "slopsquatting," according to OpenSourceMalware.
The packages impersonate dependencies that AI coding assistants are prone to invent, increasing the likelihood that developers or autonomous coding agents will install them.
The campaign centers on a downloader dubbed NUL1DROPPER, which targets developers building mobile applications. Once installed, the malware retrieves a remote access trojan (RAT) capable of infecting Windows, macOS, and Linux systems without relying on traditional npm install scripts, allowing it to evade common detection methods.
Researchers attributed the campaign to a Russian-speaking threat actor based on infrastructure, tooling, and operational characteristics. They said the operation represents one of the largest known attempts to weaponize AI package hallucinations by pre-registering plausible but nonexistent package names that coding assistants may recommend. (Paul McCarty / Opensource Malware)
Discreet, camera-enabled smart glasses such as Meta’s Ray-Bans and Kmart’s Anko glasses may require new laws amid fears they could be used to “exploit or surveil vulnerable groups," Australia’s privacy tsar Carly Kind has warned.
Kind said the proliferation of smart glasses – including similar products likely to be released by Google and Apple by 2027 – would “fundamentally alter our experience of interpersonal interactions, in both private and public spaces”, and undermine Australians’ ability to make privacy choice without knowing “we could be filmed, recorded or photographed at any time.”
“It would also require consideration of whether we need new laws,” Kind said. (Nathan Schmidt / Perth Now)
Related: OAIC, Mi-3, Cyber Daily, News.com, Carly Kind on LinkedIn
Best Thing of the Day: Holding a Cop Accountable
Daniel Hughes, a former Merseyside police officer in the UK, will begin his 12-month prison sentence for carrying out repeated unauthorized searches using police computer systems between 2016 and 2019, often including intelligence related to firearm and drug cases involving his organized crime pals.
Worst Thing of the Day: Trump Wants to Spy on Your Uterine Activity
Donald Trump's new director of the Centers for Disease Control and Prevention, Erica Schwartz, is committed to improving “abortion surveillance,” despite advocates’ insistence that federal tracking violates patient privacy and undermines access.
Closing Thought
