MYTHOS
Mozilla Uses Anthropic's Mythos To Fix 271 Bugs In Firefox
[rG: The main question is, is this better than applying traditional application security
best practices with market leading vulnerability scanners, QA, and remediation practices?
Unanswered relevant questions:
How many of these bugs were security vulnerabilities versus functionality that wasn’t properly QA’ed?
How does Mythos’ vulnerabilities finding compare to other international models?
How does this compare with vulnerability detections by best practice use of leading SCA, SAST, and DAST vulnerability scanners (e.g. Did Mythos find anything that was otherwise not detectable)?
What are the hallucination/false rates for both detection and fixes?
How much computational resources (people, processing, and licensing costs) did the AI versus non-AI compare?
How were the AI finding validated whether true or false?
How were the fixes created (automatic, human, mix) and how were those fixes validated?
Is the conclusion that enterprises could replace existing application vulnerability scanners with Anthropic Claude Mythos? No. If it does proof effective and economical, then security vendors will incorporate Mythos into their products – where real-world benchmarking and evaluations will help customers decide best fit for performance and budget availability.]

 

It's a myth that you need Mythos to find bugs: Open source models can do it just as well
Attackers and defenders alike can achieve comparable results with open source models by building "scaffolding" to run several of them in harness. That approach also improves defense in depth, as different models tend to catch different flaws.
Mythos is expensive to build and run, and may never be publicly available, making open source alternatives not just viable but necessary for many organizations.
Human expertise is still needed to orchestrate open source models so they together deliver Mythos-grade performance, and to assess the bug reports AI generates.
Fuzzing, the testing technique which injects random or near-random data into software to see if doing so produces bugs, also creates so many warnings that it can make extra work for humans.

 

Unauthorized group has gained access to Anthropic’s exclusive cyber tool Mythos
Mythos was released to a select number of vendors, including big names like Apple, as part of an initiative called Project Glasswing. The limited release of the model was designed to prevent its use by bad actors.
If true, unauthorized use of Mythos could spell trouble for Anthropic, which provided the exclusive release to allay the company’s concern for enterprise security.
An unauthorized group gained access to the model through a member employed at a third-party contractor that works for Anthropic.
The group, which supposedly gained access to the tool on the same day it was publicly announced, “made an educated guess about the model’s online location based on knowledge about the format Anthropic has used for other models.” The group in question is “interested in playing around with new models, not wreaking havoc with them.

Anthropic's super-scary bug hunting model Mythos is shaping up to be a nothingburger
The Mythos breach didn't require a sophisticated attack. It just required a contractor, a URL pattern, and a day-one guess, which means the 'controlled release' model failed at its weakest link before the model's capabilities were ever the issue.
Early reports from Mythos preview users including AWS and Mozilla indicate that while the model is very good and very fast at finding vulnerabilities, and requires less hands-on guidance from security engineers - making it a welcome time-saver for the human teams - it has yet to eclipse human security researchers. It's like adding an automated security researcher to your team. Not a zero-day machine that's too dangerous for the world.
Anthropic, in announcing the new model, claimed Mythos identified "thousands of additional high- and critical-severity vulnerabilities." VulnCheck, however, put the count at maybe 40. Or maybe none at all.
Aisle's replication study, which tested Mythos' showcase vulnerabilities on small, cheap, open-weights models and found they produced much of the same analysis.
Attackers didn't need Mythos to accelerate vulnerability research, 4.6 and open source models have already been accelerating the vulnerability process.

 

 

Claude Opus 4.7 has turned into an overzealous query cop, devs complain
Anthropic Opus 4.7 arrived on the heels of their announcement of Mythos. With greater security, come more false positives – Claude has become overcautious, refusing to respond to harmless requests.
Anthropic could learn a lot by poring over the complaints in its GitHub repo for Claude Code. Objections to the company's Acceptable Use Policy (AUP) classifier have surged and customers are having trouble getting legitimate work done.
Given how the leaked Claude Code source uses regex patterns for sentiment analysis, it may be that the AUP classifier takes a similar shortcut by just checking for forbidden words without considering the context.

 

AI TOKENMAXXING
‘Tokenmaxxing’ is making developers less productive than they think
What you measure matters. And, typically, you get more of whatever you’re measuring.
Software engineers have debated productivity metrics for decades, starting with lines of code. But as the new generation of AI coding agents delivers more code than ever, what their managers ought to be measuring is less clear.
Measuring an input to the process makes little sense when you presumably care more about the output. It might make sense if you’re trying to encourage more AI adoption (or selling tokens), but not if you’re trying to become more efficient.
Consider the evidence from a new class of companies operating in the “developer productivity insight” space. They’re finding that developers using tools like Claude Code, Cursor, and Codex generate a lot more accepted code than they did before. But they also find that engineers have to return to revise that accepted code far more often than before, undercutting claims of increased productivity.
Engineering managers are seeing code acceptance rates of 80% to 90% - meaning the share of AI-generated code that developers approve and keep - but they’re missing the churn that happens when engineers have to revise that code in the following weeks, which drives the real-world acceptance rate down between 10% and 30% of generated code.
GitClear published a report that found AI tools increased productivity, but also that its data showed “regular AI users averaged 9.4x higher code churn than their non-AI counterparts” - more than double the productivity gains the tools provided.
Faros AI, an engineering analytics platform, drew on two years of customer data for its March 2026 report. The finding: code churn - lines of code deleted versus lines added - had increased 861% under high AI adoption.

 

Meta will train AI agents by tracking employees’ mouse, keyboard use
Meta will begin tracking the mouse movements, clicks, and keystrokes of its US employees to generate high-quality training data for future AI agents.
Meta spokesperson states that the collected training data will help Meta’s AI agents with tasks that it sometimes struggles with, including “things like mouse movements, clicking buttons, and navigating dropdown menus. If we’re building agents to help people complete everyday tasks using computers, our models need real examples of how we actually use them,” adding that the collected data would not be used to evaluate employees.

 

Reid Hoffman weighs in on the ‘tokenmaxxing’ debate
“Tokenmaxxing” — the “maxxing” being Gen Z lingo for optimizing something, as you may have heard in other slang, like “looksmaxxing” or “sleepmaxxing.”
Days after Meta shut down its internal “tokenmaxxing” dashboard following news of the AI leaderboard leaking to the press, LinkedIn co-founder and venture capitalist Reid Hoffman came out in support of the concept that’s recently taken Silicon Valley by storm.
He went on to explain that some people may be using a lot of tokens, but in more random or exploratory ways, which is why you want to pair tracking the “tokenmaxxing” practice with an understanding of the things people are using their tokens to do.
You should be getting people at all different kinds of functions actually engaging and experimenting [with AI].

 

Disney joins AI tokenmaxxing trend, one employee uses Claude 51,000 times a day
Disney is going all-in on AI. After firing 1,000 employees, the entertainment giant has put up a dashboard that tracks AI usage of workers. As per a report, one Disney employee who is seemingly "tokenmaxxing" uses Claude 51,000 times a day.
The report states that the Disney employee who was leading this dashboard had used Anthropic’s Claude – one of the most popular AI models – roughly 4,60,000 in nine days. This translates to an average use of 51,000 times a day! Not including weekoffs either, so the daily use may be even higher.
Nvidia CEO Jensen Huang has previously claimed that employees should be evaluated based on the tokens they consume. He said, “If [a] $500,000 engineer did not consume at least $250,000 worth of tokens, I am going to be deeply alarmed.”
The concept of 'tokenmaxxing' is not unique to Disney. Companies like Meta and Visa have previously implemented AI usage dashboards. Meta has reportedly removed the dashboard that employees referred to as 'Claudeonomics.’

 

The Horrible Economics of AI Are Starting to Come Crashing Down
What’s so far been a free or at least low-cost ride could be coming to a screeching halt. Setbacks plaguing the construction of AI data centers have brought the industry’s biggest chokepoint to the forefront: access to the precious computing power that makes frontier models tick.
As costs continue to ramp up, enterprise consumers could soon be left holding the bag, with companies like OpenAI and Anthropic looking to ramp up prices to stem at least some of the bleeding. It’s a notable shift after years of complimentary access to cutting-edge AI, a practice that has long belied the tech’s true costs.
Most recently, Anthropic cut off millions of users from AI agent tool OpenClaw after it forced its systems into overdrive. The company transitioned to a pay-as-you-go billing system to use its application programming interface (API), which charges users per token instead of more open-ended usage limits.
To generate enough money and cover the trillions of dollars being poured into data centers, AI companies would need to get close to $2 trillion per year in revenue by 2029, in “historic returns” that would dwarf current figures. With a 10% profit margin per token, the industry’s token consumption would need to grow anywhere from 50,000 to 100,000 times its current rate by 2030.
Without a feasible long-term plan to keep the ball rolling, experts warn the business model could soon collapse in on itself - a catastrophic outcome not just for markets, but potentially for the entire economy as well.
[rG: Another looming “too big to fail” government bailout for investors and companies’ mismanagement speculation???]

 

SUPPLY CHAIN ATTACKS
Bitwarden CLI client supply-chain attacks affect Checkmarx KICS and Aqua Security's Trivy scanners.
The operation shows more sophistication than a typical npm credential stealer. It stages fallback PATs through commit messages, verifies alternate exfiltration routing with signed GitHub content, encrypts result sets with hybrid RSA and AES encryption, and uses GitHub itself as a secondary transport and secret-harvesting platform.
JFrog customers can detect and block this package through Xray and prevent installation through JFrog Curation policies.

 

New npm supply-chain attack self-spreads to steal auth tokens
The threat was spotted in multiple packages from Namastex Labs, a company that provides AI-based agentic solutions designed to improve profitability.
These packages are used in AI agent tooling and database operations, so the attack targets high-value endpoints rather than aiming for high-volume infections. However, due to its worm-like function, its spread can expand quickly if conditions are met.
The injected malicious code collects sensitive data associated with various secrets, such as tokens, API keys, SSH keys, credentials for cloud services, CI/CD systems, registries, and LLM platforms, and Kubernetes/Docket configs. Additionally, it attempts to extract sensitive data stored in Chrome and Firefox, including cryptocurrency wallets such as MetaMask, Exodus, Atomic Wallet, and Phantom.
[rG: AI components are going to be increasing targets of attack because immature security organizations are fast-tracking their AI enhance software development, bypassing fundamental good software development practices. Security best practice defense is to ensure all application 3rd party dependency components (including AI) are manage through enterprise CDN Binary Management System running daily SCA vulnerability checks for risk evaluation and incident response.]

 

EssentialPlugin WordPress plugin suite hacked to push malware to thousands of sites
More than 30 WordPress plugins in the EssentialPlugin package have been compromised with malicious code that allows unauthorized access to websites running them.
A malicious actor planted the backdoor code last year but only recently started pushing it to users via updates, generating spam pages and causing redirects, as per the instructions received from the command-and-control (C2) server.
The injected code was sophisticated. It fetched spam links, redirects, and fake pages from a command-and-control server. It only showed the spam to Googlebot, making it invisible to site owners.

 

GitHub Dependabot-based dependency graphs for Python
Python projects will now see more complete and accurate transitive dependency trees in their dependency graphs and Software Bills of Materials (SBOMs).
This feature is based on a new type of Dependabot job that builds a dependency snapshot and uploads it to the Dependency Submission API. It’s similar to dependency autosubmission, but it does not incur charges for actions minutes and can access organization-wide configurations for private registries you’ve set up for Dependabot.

 

QUANTUM CRYPTOGRAPHY
Contrary to popular superstition, AES 128 is just fine in a post-quantum world
AES is perfectly acceptable in a post-quantum world as supported by the National Institute of Standards and Technology, the German Federal Office for Information Security, and others. Conflating necessary and unnecessary changes will cause needless churn and take resources away from the urgent updates.
AES 128 is the most widely used variety of the Advanced Encryption Standard, a block cipher suite formally adopted by NIST in 2001. While the specification allows 192- and 256-bit key sizes, AES 128 was widely considered to be the preferred one because it meets the sweet spot between computational resources required to use it and the security it offers. With no known vulnerabilities in its 30-year history, a brute-force attack is the only known way to break it. With 2128 or 3.4 x 1038 possible key combinations, such an attack would take about 9 billion years using the entire bitcoin mining resources as of 2026.
There’s a common misconception that quantum computers will ‘halve’ the security of symmetric keys, requiring 256-bit keys for 128 bits of security.
Classical computers can perform multiple searches simultaneously, a capability that allows large tasks to be broken into smaller pieces to complete the overall job faster. Quantum Grover’s algorithm, by contrast, requires a long-running serial computation, where each search is done one at a time. What makes Grover special is that as you parallelize it, its advantage over non-quantum algorithms gets smaller.

 

In a first, a ransomware family is confirmed to be quantum-safe
Kyber ransomware has been around since at least last September and quickly attracted attention for the claim that it used quantum safe ML-KEM, a standard shepherded by the NIST.
Kyber was using ML-KEM to conceal the key used to encrypt victims’ data with AES-256, a symmetric cryptographic standard that is also quantum-proof. (As reported previously, AES-128 would have sufficed in withstanding a quantum attack.)
There is no practical benefit for Kyber developers to have chosen a PQC key-exchange algorithm. Quantum computers capable of running Shor’s algorithm, that allow the breakage of RSA and ECC (elliptic curve cryptography), are at least three years away or more.

 

Researcher breaks 15-bit elliptic curve key in 'largest quantum attack,' wins 1 bitcoin bounty
Bitcoin uses 256-bit elliptic curve cryptography to secure wallets, which is far larger than the 15-bit key broken in this demonstration.
Giancarlo Lelli derived a private key from its public key across a search space of 32,767 using a variant of Shor’s algorithm targeting the Elliptic Curve Discrete Logarithm Problem (ECDLP), the math underlying the digital signature schemes securing Bitcoin, Ethereum, and most blockchains.
Before Lelli, Steve Tippeconnic broke a 6-bit elliptic curve key in September 2025 using IBM’s 133-qubit quantum computer. That demonstration was the first public break of this type on quantum hardware. Lelli’s 15-bit result extends it by a factor of 512.

 

EPIC FAILS in Application Development Security practice processes, training, implementation, and incident response
Claude Desktop changes app access settings for browsers you don't even have installed yet
Anthropic's Claude Desktop for macOS installs files that affect other vendors' applications without disclosure, even before those applications have been installed, and authorizes browser extensions without consent.
It amounts to forced bundling across trust boundaries by writing configuration files for other vendors' browsers. It's invisible by default, with no opt-in. It's difficult to remove. It pre-authorizes browser extensions that haven't been installed. Its file is named in a way that fails to clarify the scope of what is being allowed. And it pre-authorizes non-present browsers to use the Native Messaging binary, among other concerns.
This is a a direct breach of Article 5(3) of Directive 2002/58/EC (the ePrivacy Directive) as well as a multitude of computer access and misuse laws (usually criminal law), on a scale large enough to matter, in a vendor which has spent considerable effort on being perceived as the safety conscious AI lab.
Article 5(3) requires service providers seeking access to a person's data to provide clear details about the data access request and to obtain consent unless access is strictly necessary to provide the service.

 

Three AI coding agents leaked secrets through a single prompt injection. One vendor's system card predicted it
Colleagues at Johns Hopkins University, opened a GitHub pull request, typed a malicious instruction into the PR title, and watched Anthropic’s Claude Code Security Review action post its own API key as a comment. The same prompt injection worked on Google’s Gemini CLI Action and GitHub’s Copilot Agent (Microsoft). No external infrastructure required.
GitHub Actions does not expose secrets to fork pull requests by default when using the pull_request trigger, but workflows using pull_request_target, which most AI agent integrations require for secret access, do inject secrets into the runner environment. This limits the practical attack surface but does not eliminate it: collaborators, comment fields, and any repo using pull_request_target with an AI coding agent are exposed.

 

Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus
Vibe-coding platform Lovable is pooh-poohing a researcher’s finding that anyone could open a free account on the service and read other users' sensitive info, including credentials, chat history, and source code. However, the company’s story keeps changing: First it attributed the publicly exposed info to "intentional behavior" and "unclear documentation," then threw bug-bounty service HackerOne under the bus.
The drama appears to be the latest example of an AI firm, in this case a startup that claims a $6.6 billion valuation, shirking responsibility for security flaws in its products. Companies including Uber, Zendesk, and Deutsche Telekom all use Lovable's vibe coding AI tool.

 

What’s Weak This Week:

  • CVE-2026-40372, affects versions 10.0.0 through 10.0.6 of the Microsoft.AspNetCore.DataProtection NuGet package.
    Even after the vulnerability is patched, devices may still be compromised if authentication credentials created by a threat actor aren’t purged.
    The critical flaw stems from a faulty verification of cryptographic signatures. It can be exploited to allow unauthenticated attackers to forge authentication payloads during the HMAC validation process, which is used to verify the integrity and authenticity of data exchanged between a client and a server.
    Microsoft issues emergency update for macOS and Linux ASP.NET threat 

 

HACKING
Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software
Cybersecurity researchers have discovered a new Lua-based malware created years before the notorious Stuxnet worm that aimed to sabotage Iran's nuclear program by destroying uranium enrichment centrifuges. The previously undocumented cyber sabotage framework dates back to 2005, primarily targeting high-precision calculation software to tamper with results. It has been codenamed fast16.
By combining this payload with self-propagation mechanisms, the attackers aim to produce equivalent inaccurate calculations across an entire facility.

 

Why are top university websites serving porn? It comes down to shoddy housekeeping
The root cause is simple: organizations create DNS records and never clean them up. There is no expiry date on a CNAME record. Nobody gets an alert when the target stops responding.
Any organization with a website should compile a running inventory of all subdomains along with the purpose of each one and its corresponding CNAME record. Then staff should regularly audit the list in search of decommissioned sub-domains to remove its CNAME.

 

If malware via monitor cables is a matter of national security, this might be the gadget for you
SilentGlass is the UK NCSC's first branded device to hit the market. Announced publicly on Wednesday, the HDMI and DisplayPort-compatible device has already been deployed across "government estates," for several years and is capable of protecting "most high-threat environments."
You might be thinking "it's not every day we hear about monitors being pwned via HDMI," and you'd be right.
Very little exists in the research literature about these kinds of attacks.
Most organizations probably don't need to worry about highly motivated foreign spies lurking around their cables looking for electromagnetic emissions. However, for those safeguarding highly sensitive data within the context of critical national infrastructure operators, it's potentially a slightly more credible threat.
NCSC gave Goldilock Labs, in partnership with Sony UK, the license to produce and sell SilentGlass, which comes as separate devices - one for HDMI and another for DisplayPort, each protecting one cable only. Pricing not available yet.

 

Hybrid clouds have two attack surfaces and you’re not paying enough attention to either
Your hybrid management plane is an attack surface you are not monitoring enough. You must look at both cloud and on-prem. Treat all systems as tier zero.
Researchers found a series of flaws in Microsoft's Windows Admin Center (WAC) and suggest this shows hybrid cloud management tools are a two-way attack surface that users don't spend enough time worrying about.
Microsoft offers two versions of WAC: a cloudy version hosted in Azure and an on-prem edition. The directory the latter lives in was not write-protected, so an attacker could drop all sorts of nastyware alongside WAC. Both versions of WAC also rely on a check-access token and a proof of possession (POP) token to identify resources they manage, but VMs don't validate all the fields in the POP token. The researchers also found the POP token can be re-used or forged, allowing attackers to take over a tenant VM managed under WAC. Resources managed by Microsoft Arc are also at risk.

 

Hackers Create Hidden Mailbox Rules in Microsoft 365 to Intercept Sensitive Business Emails
In Microsoft 365 environments, attackers typically gain their first foothold through credential phishing, password spraying, or OAuth consent abuse. Rather than deploying malware or standing up external infrastructure, they rely on the platform’s native features to maintain access and stay hidden. This makes detection significantly harder because all malicious activity runs entirely inside Microsoft’s own environment, using legitimate built-in functionality rather than any suspicious external tools.
These rules achieve multiple goals at once. They silently forward emails containing financial keywords such as “invoice,” “wire,” or “contract” to attacker-controlled external addresses.
They hide MFA alerts, password reset emails, and suspicious login warnings so victims never realize their accounts have been breached. And because these rules survive password resets, they maintain persistent access long after credentials are changed.
40% of compromised Microsoft 365 accounts had at least one malicious mailbox rule created shortly after the initial breach. The shortest recorded time between an account compromise and rule creation was just 8 seconds, clearly showing how deliberate and automated this tactic has become. 

 

APPSEC, DEVSECOPS, DEV
CISCA Defending Against China-Nexus Covert Networks of Compromised Devices
Covert networks mostly consist of compromised SOHO routers, but they also pull in any vulnerable device they can exploit at scale. Raptor Train was made up of thousands of SOHO routers and IoT devices, such as web cameras and video recorders, as well as firewalls and Network Attached Storage (NAS) devices.The KV Botnet used by Volt Typhoon was mainly made up of vulnerable Cisco and NetGear routers. The edge devices were vulnerable because they were “end of life” – out of date and no longer receiving updates or security patches by their manufacturers. 

Pass the key, passwords have passed their sell-by date
The UK's National Cyber Security Centre (NCSC) has officially endorsed passkeys as the default authentication standard, marking the first time the agency has told consumers to move away from passwords entirely.
NCSC's annual CYBERUK conference, concludes passkeys "are at least as secure as, and generally more secure than" a password and two-step verification (2SV) combo.
The agency had considered this move last year, but held off until some "implementation challenges" were addressed by the industry, including inconsistent passkey naming across platforms, unreliable device support, and limited credential manager compatibility. Those gaps have since narrowed enough to act.
Google, eBay, and PayPal were named by NCSC as three major platforms that made it easier for users to adopt passkeys, with around 50 percent of UK Google users registering at least one. Microsoft made passkeys the default standard nearly a year ago.
Where passkeys aren't available, the signals intelligence agency advises consumers and businesses to keep using the password+2SV combo, but use a password manager so those passwords remain complex and unique to each service.

The Complete Guide to Inference Caching in LLMs
Calling a large language model API at scale is expensive and slow. A significant share of that cost comes from repeated computation: the same system prompt processed from scratch on every request, and the same common queries answered as if the model has never seen them before. Inference caching addresses this by storing the results of expensive LLM computations and reusing them when an equivalent request arrives.

 

VENDORS & PLATFORMS
Zoom Partners With Sam Altman's Iris-Scanning Company To Offer Callers Verifications of Humanness
The feature, launched on April 17, 2026, is a part of World’s ID 4.0 rollout. It lets hosts confirm that every face on the call belongs to a real person, not an AI-generated imposter.
World’s Deep Face technology includes a three-step process. It cross-references a signed image from a user’s original Orb registration, a live face scan from the device, and the frame of the video that’s visible to the other participants in the meeting.
Only when the three samples match does a “Verified Human” badge appear next to the user’s name.
Hosts can also make Deep Face verification mandatory for joining meetings, preventing unverified participants from joining entirely. Mid-call, on-the-spot checks are also possible.

 

44% of new music uploads are AI-generated, most streams are fraudulent
Listeners taking a Deezer survey listened to three songs, two of which were AI. A whopping 97 percent were unable to tell the difference between the AI songs and the one made by a human.
Google Gemini users can generate full-length songs now. Suno and Udio also promote their ability to create broadcast-ready tracks in seconds. These mainstream options embed watermarks, like Google’s SynthID, to flag the songs as AI. The problem is how easy it is becoming to strip those watermarks out of the audio and generate music using custom models that don’t have them in the first place. As AI inference becomes cheaper, so, too, does the creation of musical AI slop.
AI uploads to Deezer has reached 75,000 new AI tracks every single day. Deezer only pays for streams when a person listens to them, so it’s demonetizing about 85% of AI music streams.

 

Microsoft tackles quality control issues. Just kidding, it's encouraging experienced workers to leave
The company announced a voluntary buyout scheme for US employees. So if you are at the senior director level or below, and if your age plus years of employment at Microsoft comes to 70 or higher – you might be eligible to leap from the gangplank of the good ship Nadella rather than receiving a shove from HR.
The problem with voluntary buyouts is that they tend to target experienced employees, and these are the workers that Microsoft desperately needs if it wants to deal with the quality issues in its software. Earlier this year, Windows boss Pavan Davuluri assured customers complaining about the relentless flow of out-of-band updates that Microsoft will "raise the bar on Windows 11 quality.
AI assistance will not resolve Microsoft's quality problems on its own, and persuading skilled and experienced employees to depart seems counterproductive. Still, if enough people walk, perhaps there won't be a need to pull out the redundancy gun in a few months to keep the Copilot fires burning.

 

Microsoft to roll out Entra passkeys on Windows in late April
The feature is expected to reach general availability by mid-June 2026 and will also extend passwordless sign-in to unmanaged Windows devices.
Microsoft says that Entra passkeys on Windows will support corporate, personal, and shared devices, with admin controls via Conditional Access and Authentication Methods policies. 

 

LEGAL & REGULATORY
Age checks could turn internet into an ID checkpoint
The problem is that you can't reliably identify minors without identifying everyone else first, meaning systems built to protect kids inevitably sweep up adults too. We cannot accept a world where every adult is expected to hand over ID as the price of going online.
With age verification, we're on the cusp of, once and for all, requiring ID for every single person going online, for any reason, legal or not, adult or not.
That argument is landing as age checks move from policy debate to product reality. Anthropic has already rolled out ID verification tied to certain personas in its Claude chatbot, while Microsoft has warned UK Xbox users they'll need to verify their age to keep using core social features. Sony has also begun introducing age checks for PlayStation users this week, and Discord, after flirting with the idea, notably hit the brakes after admitting hackers accessed records, including government ID photos, tied to more than 70,000 users via a third-party age verification vendor.
The more sensitive data you stockpile in privately held databases, the bigger a target it becomes for criminals

 

Man faces 5 years in prison for using AI to fake sighting of runaway wolf
Neukgu, a 2-year-old wolf, burrowed out of a zoo in Daejeon city, officials launched an all-out effort to bring him back. That’s why an AI-generated photo purporting to show Neukgu at an intersection which began circulating hours after Neukgu went missing prompted police to charge the man who created it. After seeing the image, the Daejeon city government issued an emergency text warning residents of a wolf in the area, and police even reportedly showed the photo at a press briefing while diverting resources to search the area.

 

And Now For Something Completely Different …

New Study Finds An Upsetting Potential Link Between Lung Cancer And Healthy Eating
University of Southern California found that a group of 187 lung cancer patients under the age of 50, most of whom had never smoked, were found to have healthier-than-average diets; which raises concerns that there could be unexpected health risks with certain fruits, vegetables and grains.

 

UK moves to ban smoking for everyone born after 2008
Children who do not reach the age of 18 before January 1, 2027 will never be permitted to buy cigarettes or tobacco products in the UK.
The new law will raise the legal age requirement in the UK for buying cigarettes, cigars or tobacco, which is currently 18, by one year in every subsequent year, starting on January 1, 2027 This will effectively mean that people born on or after January 1, 2009 will never be eligible to buy them. Retailers will face financial penalties for selling the products to those not entitled to them.
[rG: Cannabis is still illegal. Next up: fizzy drinks, alcohol, …??]

 

Cult Sci-Fi Film: Until the End of the World – Wikipedia
[rG: Thx David S.]