Nvidia launches AI safety coalition as open-weight debate intensifies

MSFT launches AI cyber defense platform, Hugging Face rife with deepfake abuse, Cyberattack hits Minnesota water systems, Claude chats indexed by Google, Bank of Baroda probes leak, ShinyHunters claims EY breach, Apple sued over fake wallet app, Hack steals 293.7m SUPRA tokens, much more

Share
Nvidia launches AI safety coalition as open-weight debate intensifies
Source: Daniel J. Prostak; Crocodiletiger~commonswiki Crocodiletiger~commonswiki used courtesy of Daniel Prostak

Metacurity is your daily cybersecurity reality check.

Every weekday, thousands of cybersecurity professionals—including many of the industry's most respected security leaders—start their day with Metacurity because it cuts through the noise. Instead of vendor hype, social media outrage, and recycled headlines, you get the stories that matter, the context behind them, and an explanation of why they're important.

We spend hours reading, researching, and connecting the dots so you don't have to.

If Metacurity saves you time, helps you make better decisions, or gives you a clearer view of what's happening in cybersecurity, please consider becoming a paid subscriber.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Chip giant NVIDIA  formed a coalition with other companies to develop and share tools for AI safety ​and cybersecurity, days after the Hugging Face incident drew attention to ‌the dangers of losing control of autonomous AI agents.

The Open Secure AI Alliance, with founding members including Adobe, CrowdStrike, Hugging Face and Dell Technologies, follows a ​public letter, signed by a wide range of companies ​including OpenAI, which advocates for open-weight AI models.

Nvidia said it is contributing open models, ​weights, data ⁠and agent harness research to the Alliance, including the new open-source Nvidia Labs Object-Oriented Agent project, now available on code-hosting platform GitHub.

The company ⁠said ​that the framework will help control systems ​manage AI agent behavior more effectively, simplifying the process of testing, tracking, reviewing and ​regulating their actions.

Silicon Valley leaders from Anthropic PBC’s Dario Amodei to Nvidia Corp.’s Jensen Huang warned against a US crackdown on open-weight artificial intelligence systems, deepening a debate about how Washington should respond to a surprise breakthrough from Chinese startup Moonshot.

Meanwhile, OpenAI CEO Sam Altman will meet with senior Trump administration officials, lawmakers and economists in Washington, DC, this week to preview the capabilities of the company’s upcoming family of artificial intelligence models, CNBC has learned.

In addition to previewing OpenAI’s upcoming releases, Altman is expected to field questions from policymakers about cybersecurity and the company’s stance on open-weight models, according to a source familiar with the plans who asked not to be named because the details are confidential.

Separately, China set a ceiling on new US tariffs and warned Washington against sanctioning Chinese artificial intelligence companies, drawing boundaries weeks before the next meeting between President Donald Trump and Chinese leader Xi Jinping.

China warned that it would take “all necessary measures” if the US sanctions Chinese AI companies over allegations that they improperly used American models to train their own systems. (Jaspreet Singh / Reuters, Michael Shepard and Maggie Eastland / Bloomberg, Ashley Capoot and Kate Rooney / CNBC, Bloomberg)

Related: NVIDIAThe HillDeveloper Tech NewsCNBCTom's HardwareDecryptCSOEngadgetBusiness InsiderSiliconANGLENew York TimesZDNETHotHardwareThe VergeDecrypt, Help Net SecurityImplicator.aiUPIThurrottComputerWeekly.comUnite.AIThe New StackBlockonomiCoinDeskNairametricsCoinpaperBlockchain.NewsCyber Security NewsLinuxiacThe Economic TimesLinkedInQuartzANI NewsPYMNTSSemafor, Anadolu Ajansı, Games Beat, RTETech Xplore,  The Next WebSecurity WeekZDNet,  Insider PaperTechnology | The HillSiliconANGLEBusiness InsiderGBHackers On SecurityStartups News | Tech NewsSecureWorld News, TechRoundThe Register - SecuritySecurity Point BreakCyber Security NewsInvezzCyber Security NewsRuntimeWireDigitBeInCrypto, Anthropic, Politico, TechCrunch, Politico, PoliticoQuartzBenzingaTech Brew, The Information, Reuters, Implicator.ai

Microsoft announced it has built something it calls Project Perception, a new agentic security system designed for the realities of AI.

According to the company, the project turns signals into real-time protections using AI to defend against AI. It brings together signals, context, models, and specialized agents into a continuously learning system of defense. It can reason, prioritize, and act at machine speed while keeping humans firmly in control and empowering them with powerful new workflows.

Perception coordinates three classes of specialized agents. Red team agents identify potential paths to compromise before an attacker can exploit them. Blue team agents investigate, reason over context, and determine what represents meaningful risk. Green team agents take corrective actions and strengthen defenses across the environment. Working together, these agents form a closed-loop system that continuously discovers, evaluates, and improves an organization’s security posture.

Microsoft also announced that its new AI model, MAI-Cyber-1-Flash, has been trained specifically for cybersecurity. The system learned its skills partly by analyzing decades of data that Microsoft collected when responding to hacking incidents experienced by its customers.

Microsoft has unusual access to security data because its products, such as the Windows operating system, Outlook email and Azure cloud computing, are so widely used and are frequent targets of cyberattacks, said Mustafa Suleyman, who oversees the development of Microsoft’s AI models.

Unlike other leading AI companies, Microsoft did not share the new model with independent testers for evaluation before releasing the technology. But the company said it expected that the model integrated into its security tools would top the leaderboard for a standard benchmark test called CyberGYM after it was released on Monday, surpassing offerings from OpenAI and Anthropic.

Microsoft said the price of using the new system was about half the price of other leading technologies, which are more expensive partly because they were developed to do many things, not just cybersecurity work. The company said it effectively handled 90 percent of queries, meaning the more expensive models would be necessary only 10 percent of the time. Mr. Suleyman said Microsoft had focused on lowering the costs so that the model could be deployed more quickly and more widely. (Microsoft, Microsoft, Cade Metz and Karen Weise / New York Times)

Related:  Microsoft, AxiosCTechThe InformationSeeking AlphaiPhone in CanadaTechzine GlobalFirstpostRuntimeWireUnite.AICommand Line, TechSpective, TechCrunch, The Chosun Daily, TechCrunch, The VergeThe DecoderNeowin, WinCentral, CyberScoop, Digital Trends

Source: Microsoft.

The open-source AI platform Hugging Face—a repository of AI models and datasets, which has been valued in the billions—has a widespread problem with nonconsensual deepfakes, according to a new report published by the European nonprofit AI Forensics.

Researchers from the group say they tested nine of the top image editing Spaces on Hugging Face, which host models people can directly use on the site, and seven of these easily changed a clothed image of a woman into a topless one.

In further testing, AI Forensics researchers created their own honey-pot-style image editing Spaces on Hugging Face—which were designed not to produce any images—and tracked more than 1,000 prompts and images they received over a week. In total, AI Forensics says, 73 percent of the prompts they received were sexual in nature. Among these, 83 percent were seeking to undress or sexualize the person they had submitted a photo of—with 95 percent of these being women.

The research also says 6.7 percent of the sexual requests targeted apparent children.

The company has content policies that prohibit child sexual abuse material and sexual deepfakes that are created “without explicit consent” or are used for harassment or bullying. Some pages promoting nudifying services were removed after WIRED contacted the company; however, it is unclear if the two are related. (Matt Burgess / Wired)

Related: AI Forensics, The Verge

Source: AI Forensics.

A water plant malfunction in Braham, Minnesota was caused by a cyberattack, the city confirmed, and it’s not the only Minnesota city impacted.

The city announced that its water plant was offline “for an unknown reason.” A few hours later, the city said the system was back online and confirmed the issue wasn’t a fluke.

“Crews identified that the water plant outage was a result of a malicious cyber-attack of computerized operating systems by unknown actors,” the city said in a statement.

Plymouth later announced that two of its water towers and multiple lift stations were also impacted by what it believes to be a cyberattack, starting overnight Sunday.

Both cities say the attack didn’t impact water or plant safety, but in Braham, it shut down the operating controls at the plant, which caused the well and plant to go offline.

In the meantime, Braham used water in its water tower to serve residents. However, the city had asked residents to conserve water until the issue was fixed. Because the issue has been resolved, residents can return to normal water use.

The communities also say the attack appears to have targeted other towns, and the state is aware and helping impacted communities while the source is being investigated. (KTSP)

Related: CBS News, Kare, r/Minnesota, MINNEAPOLIMEDIA NEWS

Claude is exposing a wealth of users’ chats and creations in Google search results, meaning anyone can dig through conversations or other material that people used Claude to make but may not have realized were publicly available for strangers to see.

The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cryptocurrency wallet keys and personal information like people’s addresses.

Like other chatbots, Claude lets people share their conversations with others by creating a publicly accessible link to the chat. People may do this to send the full text of a conversation to their friends or coworkers in a group chat, for example. But they may not realize Google is also surfacing these links in search results, making them available to essentially anyone.

One Google dork — a super specific search that is useful for finding particular webpages or files — surfaced Claude chats, according to a post on the Claude subreddit. At the time of writing, that Google dork appears to have been mitigated. No results appeared when 404 Media tested it, on both Google and DuckDuckGo. The post said some of the surfaced chats included API keys, login credentials, and personal information like names, addresses, and phone numbers. (Joseph Cox / 404 Media)

Related: r/ClaudeAI, BBC News, Futurism

Simple google dork request lets you find a LOT of them. ive already found some college student going insane. Source: -void1 on r/ClaudeAI.

Customer data from India's state-run Bank of Baroda, along with internal documents, has been leaked on the ‌dark web, according to a source familiar with the matter and a cybersecurity researcher.

The lender said that it had ​started a forensic investigation and was working with relevant ​authorities after initial containment measures were implemented. The breach involved ⁠a compromised employee email account, which resulted in "unauthorised access to ​certain data", the Mumbai-based bank said.

"The bank's core banking systems ​were not accessed and continue to remain secure," it added.

The leaked data includes customer details, identification documents, loan papers and internal audit records, said cybersecurity ​researcher Srikanth L, founder of Cashless Consumer. (Gopika Gopakumar and Ashwin Manikandan / Reuters)

Related: Finextra, The Asian Banker, BankInfoSecurity, The Economic Times, New Indian Express, Firstpost, India Today

The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack.

Ernst & Young disclosed the breach earlier this month, saying a third-party support ticket system used by its IT personnel was compromised, and support tickets that may contain client tax information were stolen.

EY says it detected unusual activity on April 23 and determined that the attacker accessed the platform between March 28 and April 12, downloading multiple documents.

"EY uses a third-party information technology service management platform to help EY information technology personnel provide support to EY teams performing tax-related work for clients," reads the EY data breach notification.

"Support tickets submitted through the platform may include documents containing client tax information"

The ShinyHunters extortion gang added Ernst & Young to its data leak site, claiming it conducted the attack and threatened to release the allegedly stolen data if the company does not contact the group by July 31, 2026. (Lawrence Abrams / Bleeping Computer)

Related: Cyber Press, GBHackers, Cyber Daily

Ernst & Young listed on the ShinyHunters data leak site. Source: BleepingComputer

Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store.

The complaint, filed on July 24 in California, alleges that Apple failed to adequately review and monitor applications distributed through the App Store while promoting the marketplace as a safe and trusted source for software.

Plaintiffs James Ramirez, Christopher Ellis, and Jalen Delgado say the malicious application impersonated the legitimate Sparrow Bitcoin wallet and instructed them to enter their seed phrases.

After entering those secret recovery credentials, the victims allegedly had their Bitcoin transferred to cryptocurrency wallets controlled by the scammers.

The legitimate Sparrow Wallet is a desktop application available for Windows, macOS, and Linux, and does not offer an iOS version. However, Sparrow Wallet's developer says that scammers have repeatedly published applications in Apple's App Store that impersonate the cryptocurrency wallet. (Lawrence Abrams / Bleeping Computer)

Related: Justia, TechCrunch, CoinDesk, MacRumors, AMB Crypto, Yellow

On July 23, 2026, the Solido Money hack stripped approximately 293.7 million SUPRA tokens from the protocol in two separate attack waves — and within days, on-chain forensics had traced the bulk of those funds to centralized exchange infrastructure, with a significant portion pointing toward a suspected Gate.io deposit address.

The exploit did not rely on sophisticated code injection or a novel cryptographic attack. It exploited something more fundamental: a flaw in how the protocol assigned value to collateral.

The oracle misassignment made the system believe deposited collateral was worth nearly one US dollar when its actual market price was only a fraction of that. Once that pricing gap was in place, the rest followed logically — and profitably for the attacker. (The Cryptonomist)

Related: Pluang

GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.

Specifically, Dependabot comes with a default three-day cooldown setting, while PyPI will reject new files uploaded to releases older than 14 days.

The measure comes after the two development ecosystems experienced multiple high-profile attacks over the past year. Some notable examples include the ‘chalk’ and ‘debug’ attacks, the “s1ngularity” operation, the Shai-Hulud campaign, and the GhostAction supply-chain attack.

GitHub announced last month changes to tackle supply chain threats, and the hardening process progresses with the new measures. (Bill Toulas / Bleeping Computer)

Related: GitHub, SC Media, Techzine, DevOps, Security Week

AnMed, a nonprofit health system serving upstate South Carolina and northeast Georgia, says it was hit with a malware incident on Sunday that knocked out IT systems, internet access and more.

Many services, including oncology and radiation, were closed on Monday, while infusions remain limited and general lab services and emergency departments have stayed open.

The Anderson, South Carolina-based health system said that "decisions regarding procedures, patient transfers, diversions and operational processes are being made with patient safety as the guiding principle." (Andrea Fox / HealthCareIT News)

Related: AnMed, Upstate Today

Australia's Origin Energy said that data ​linked to about 900,000 current and former customers ‌may have been accessed in a cybersecurity incident, and that it was contacting those affected.

The country's top electricity and gas retailer said last week that it was ​investigating a potential security breach involving unauthorized access ​to some customer information.

On July 23, Origin said the affected ⁠data could include financial details, such as the ​last few digits of a customer's credit card or bank ​account numbers. (Rajasik Mukherjee / Reuters)

Related: The Guardian, Security Week, ABC.net.au, Financial Review, Insurance Business, Sydney Morning Herald, Anadolu Agency, SBS News, News.com, Xinhua, Bloomberg, Nine.com.au

Danmarks Nationalbank, the Danish central bank, has launched a financial systems security project to establish a Dormant Emergency Bank (DEB) to serve as a robust reserve bank in the event of a massive cyberattack against a large banking institution or the wider banking infrastructure in Denmark.

The DEB proposal forms a central part of Danmarks Nationalbank’s Emergency Preparedness for Critical Financial Sector Activities in Extreme Scenarios (EP-CFSA-ES) strategic plan announced in December 2025. The plan’s bank emergency solution would enable businesses and the public to continue using payment cards, receiving salaries, and transferring money in the event of a significant cyberattack that immobilizes key financial institutions and the national banking infrastructure.

The DEB would provide the Danish economy with an additional layer of cyber protection, according to Ulrik Nødgaard, governor of Danmarks Nationalbank. In the event of a hyper-scale cyberattack paralyzing a major Danish bank, the proposed backup DEB platform solution would activate to ensure Danish businesses and society “continued to function normally” until the cyberthreat recedes, Nødgaard said. (Gerard O'Dwyer / Global Finance)

Related: Danmarks National Bank

"Click to Pray" is the Vatican's official prayer app. Users can sign up for access to daily prayers, and a steady stream of papal content on their phones or computers. It's available on iOS and Android, and via a Web browser. According to its website, Click to Pray is used in more or less every country on the planet.

In January, the white hat hacker "BobDaHacker" discovered an insecure direct object reference (IDOR) vulnerability in clicktopray.org. Any passing Internet user could query a specific, totally exposed application programming interface (API) endpoint to see basic personally identifying information (PII) belonging to all of Click to Pray's account holders, as well as active employees of the organization that runs the app, the Pope's Worldwide Prayer Network.

After BobDaHacker received no response from the Vatican, he took the story to Dark Reading. After Dark Reading reported the flaws, the Vatican fixed the flaws with no acknowledgment to the white hat hacker. (Nate Nelson / Dark Reading and BobDaHacker)

Related: BobDaHacker, PC Gamer, SC Media, Games.gg, All About Cookies, GBHackers, Gigazine, Cyber Security News

These fixes cover a broad range of parts of the system.

More precisely, Apple’s advisory contains 78 individual vulnerability entries tied to 87 unique CVE numbers. The CVE count is higher because several entries address more than one CVE.

Apple does not say that any of the vulnerabilities fixed in iOS 26.6 were actively exploited in the wild. (Zac Hall / 9to5Mac)

Related: Apple Support, Apple SupportMacRumorsThe Hans India9to5MacMacRumorsAppleInsider9to5MacForbesiDeviceHelp on YouTubezollotech on YouTubeTidBITSStuffGSMArena.comPCMagOS X DailyOS X DailyAppleosophyAppleInsiderEngadgetThe Mac ObserverNeowiniClarifiedMacRumorsAppleosophyAppleosophyThurrottAppleInsideriPhone in CanadaMacworldThe Mac Observer,  iClarifiedForbesiThinkDifferent9to5MacBGR9to5MacAppleosophyAppleInsideriClarifiedAppleInsiderAppleInsiderAppleInsider9to5Mac9to5MacMacRumorsMacRumorsMacRumorsCNET, MacDailyNews,  Ars Technica, The Mac Observer, The Apple Post, Cult of Mac

The US National Vulnerabilities Database, a repository of digital security holes, recorded 45,207 flaws between January and Monday, a count approaching the total number found in all of 2025.

Last year saw an all-time high for recorded vulnerabilities in that database. Security vulnerabilities are flaws in software that can be exploited by a hacker, including to break into computer systems to commit crimes or carry out espionage. (Patrick Howell O'Neil / Bloomberg)

Attackers continued to innovate their delivery methods to evade defenses, deploying QR code-embedded PDFs to bypass traditional email gateways and hosting links on trusted cloud platforms. We also saw a spike in authentication abuse this quarter — observed in 65 percent of engagements compared to 35 percent last quarter — with attackers frequently bypassing or defeating multi-factor authentication (MFA) using adversary-in-the-middle (AitM) proxies, session-token theft, MFA fatigue attacks, and self-enrolled devices, amongst other methods.

Ransomware incidents made up over 20 percent of engagements this quarter, similar to just under 20 percent last quarter. Talos IR responded to Sinobi ransomware for the first time, as well as previously seen variants Nitrogen and Warlock. We observed ransomware operators leveraging legitimate remote monitoring and management (RMM) tools, such as a trojanized MeshAgent binary and Zoho Assist, for stealthy access, requiring defenders to prioritize behavior-based monitoring and strict control over administrative binaries. (Cisco Talos)

According to a complaint filed by the pop star’s legal team on Monday, July 27, Grande is suing the John Does after they allegedly hacked “various personal digital accounts of photographers and producers who have worked closely” with her, which she claims has resulted in “unlawful and egregious theft, dissemination, and exploitation of unreleased content.”

The star also claims the John Does profited from the hacked files after they sold “personal data and content on the dark web for significant sums of money.”

According to the complaint, content allegedly hacked includes unreleased songs, photographs, and video and audio recordings taken during her creative process that were “not intended for public consumption.”

“In 2023 alone, 45 unreleased songs belonging to Ms. Grande were hacked, stolen, and leaked by Defendants,” alleges the complaint. “Since her music debut in 2011, hundreds of similar leaks have taken place.”

Grande’s lawyers also note in the complaint that the singer is initiating legal action to uncover the identities of the alleged hackers. (Melody Chiu
and Sean Mandell / People
)

Related: The Guardian, BBC News, Rolling Stone, Billboard, The Hollywood Reporter, Variety, Page Six, TMZ, Digital Music News

Insight Partners and Glilot Capital announced a $20 million investment in Way Security, a company aiming to fix the operational costs of deploying and running enterprise identity and access management systems.

Way Security was founded by former security leaders Yossi Barishev and Yonatan Rosenberg, who serve as CEO and CTO, respectively. (Chris Metinko / Axios)

Related: Pulse 2.0Hackread

Data-security company Cyera has agreed to acquire startup Oasis Security for $1 billion, the latest large deal in a wave of consolidation across the cybersecurity industry fueled by artificial intelligence.

The cash-and-stock acquisition would help Cyera bridge its data-protection platform with Oasis’s technology for managing nonhuman identities, such as AI agents and automated software, as companies grapple with the risks of deploying autonomous tools across their businesses. The companies expect the deal to close later this year. (James Rundle / Wall Street Journal)

Related: CTech, Ynet News, Globes

Best Thing of the Day: Couldn't Happen to a More Deserving Company

Meta is currently in the midst of a trial over claims by the attorney general of Tennessee, one of dozens of states that have said the company misled its users about the safety of its platform, which could cost the company billions and force painful changes.

Worst Thing of the Day: We Live in the Golden Age of Protecting Scammers

Binance, the world’s largest cryptocurrency exchange, has quietly changed how it cooperates with law enforcement in many countries around the world, frustrating investigators who say the company has made it harder to find scammers and combat money laundering.

Bonus Worst Thing of the Day: Time to Help Those Who Need It

Cyberattacks, data breaches, online harassment and other forms of technology-facilitated violence are becoming significant obstacles to HIV prevention and treatment, according to a UNAIDS specialist who says digital security has become inseparable from the fight against the epidemic itself.

Closing Thought

Read more