Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Meta’s Muse AI: How Instagram Users Can Opt Out After Privacy Backlash

  Meta’s short‑lived Muse Image AI on Instagram let users remix public photos into AI images by default, triggering a storm of privacy and c...

All the recent news you need to know

Music Industry Introduces Voluntary AI Labels to Improve Transparency in Recordings

 

Several leading music industry organisations have introduced a new voluntary labelling framework for recordings created using generative artificial intelligence (AI), aiming to improve transparency for listeners and encourage wider adoption across the global music ecosystem. 

The initiative, announced on July 10, is backed by the International Federation of the Phonographic Industry (IFPI), the Recording Industry Association of America (RIAA), the Recording Academy (Grammys), and six other industry bodies. 

Highlighting the need for greater transparency, the chief executives of IFPI and RIAA said in a joint statement, "Fans want to know whether and how generative AI has been used. These labels will provide an immediately understandable and easily scalable approach to transparency." 

The framework introduces two categories of labels. The first, "AI-generated," is intended for recordings where artificial intelligence is responsible for generating the entire recording or the majority of its creative elements. This includes music created entirely from AI prompts, as well as tracks featuring AI-generated lead vocals or key instrumental components. 

The second category, "AI-assisted," applies to recordings that remain primarily human-created while incorporating certain AI-generated expressive elements. Under this classification, lead vocals and primary instrumental performances must still be delivered by human artists. 

The organisations said the voluntary system is designed for broad global adoption and could eventually be implemented by music streaming platforms to provide listeners with greater clarity about how AI is used in music production. 

The announcement comes as streaming platforms continue to experience a rapid increase in AI-generated music. Deezer currently identifies AI-generated tracks on its platform and recently reported that nearly half of all new uploads contain AI-generated content. In June, the company also introduced an AI music detection tool that it claims delivers 99.8% accuracy. 

Earlier this year, an Apple Music executive told Billboard that more than one-third of newly uploaded tracks on the platform were created entirely using AI. 

Responding to the announcement, the Digital Media Association (DiMA), which represents streaming services including Apple Music, Amazon Music and Spotify, welcomed the move and said it looks forward to receiving more detailed AI-related metadata to improve transparency for listeners. 

DiMA CEO Graham Davies said, "DiMA has long advocated for the creators, owners, and distributors of music to provide accurate and timely metadata on all music released and distributed to streaming services."  

Spotify has also been expanding its efforts to address AI-generated content. In April, the company introduced its "Verified by Spotify" label to help users identify authentic artists, following earlier initiatives aimed at improving AI disclosure and preventing impersonation. 

Spotify declined to comment on the latest industry initiative, while Apple Music and the Digital Media Association did not immediately respond to media queries.

Galaxy Digital launches $5M initiative to boost Bitcoin against future quantum computing threats

 

Galaxy Digital has announced a new initiative aimed at helping the Bitcoin ecosystem prepare for the long-term cybersecurity risks posed by unprecedented advances in quantum computing, committing up to $5 million in funding for developers and researchers working on technologies designed to safeguard the cryptocurrency's cryptographic foundations. 

The announcement comes as governments, standards bodies and private-sector organizations increasingly accelerate efforts to prepare critical digital infrastructure for a future in which sufficiently powerful quantum computers could undermine many of today's encryption methods. 

The crypto financial services firm said applications are now open for its newly established Galaxy Bitcoin Quantum Readiness Initiative, which is designed to support the development of practical tools and research that could help Bitcoin transition toward quantum-resistant security over time. 

According to Galaxy, grant funding will prioritize several areas considered essential for Bitcoin's long-term resilience. These include the development of post-quantum digital signature schemes capable of replacing today's cryptographic mechanisms, tools that would help cryptocurrency wallet providers and custodians migrate users to new security standards, formal security audits of proposed implementations, and technical work evaluating quantum-resistant transaction proposals before they are introduced to the Bitcoin network. Rather than distributing funds upfront, Galaxy said grants will be awarded individually and released as development milestones are achieved. 

The initiative extends beyond developer funding. Galaxy is also establishing a dedicated research program that will publish ongoing analysis examining quantum-related risks to Bitcoin while tracking emerging mitigation strategies. In addition, the company has formed a Quantum Advisory Council consisting of specialists in quantum computing and post-quantum cryptography to evaluate grant proposals and provide technical guidance for future research efforts. 

Galaxy said it also hopes other organizations across the cryptocurrency ecosystem will participate by contributing funding, collaborating on research, or supporting open-source development that could accelerate Bitcoin's eventual transition to quantum-resistant cryptography. 

Bitcoin currently relies on elliptic curve cryptography to verify ownership of wallets and authenticate transactions. Existing classical computers are considered incapable of breaking these cryptographic protections within any practical timeframe. However, cybersecurity researchers have long warned that sufficiently advanced fault-tolerant quantum computers could eventually execute algorithms capable of recovering private keys from exposed public keys, potentially allowing attackers to forge transactions and steal digital assets if the network remains unchanged. 

Although experts broadly agree that no quantum computer currently possesses the capability to compromise Bitcoin's cryptography, many researchers argue that preparations must begin well before such systems become available. Unlike conventional software updates, major protocol changes within Bitcoin require extensive technical review, community consensus, testing and gradual deployment across a decentralized global network, making the transition to post-quantum protections a multi-year effort. 

Industry concerns have also been reinforced by research estimating the potential scale of future exposure. CryptoQuant has projected that approximately 6.9 million bitcoin, valued at roughly $461 billion at current market prices, could become vulnerable if quantum computers eventually develop the ability to defeat Bitcoin's existing cryptographic protections before the network adopts stronger security mechanisms. While researchers do not consider such a scenario imminent, they increasingly describe proactive migration planning as essential because of the time required to update wallets, infrastructure and network software. 

Preparations for the post-quantum era are also gaining momentum outside the cryptocurrency industry. The U.S. National Institute of Standards and Technology finalized its first post-quantum cryptography standards in 2024, providing organizations with standardized algorithms intended to replace vulnerable public-key cryptography as quantum technology advances. 

At the same time, the U.S. Department of Commerce is investing more than $2 billion through the CHIPS and Science Act to strengthen domestic quantum computing capabilities. The funding package spans nine companies working across multiple quantum hardware approaches, reflecting the U.S. government's broader effort to accelerate quantum innovation while simultaneously preparing national infrastructure for the cybersecurity challenges that future quantum systems may introduce. 

Bitcoin was trading at approximately $66,300 on July 21, while shares of Galaxy Digital had declined roughly 8% over the previous 12 months to trade near $25.20 per share, according to market data referenced alongside the company's announcement.

AI Chatbot Usage Declines as Privacy and Trust Concerns Influence User Adoption

 

A new survey conducted by Future, the parent company of TechRadar, published today reveals the interesting truth that the adoption of AI in the sphere of consumer technology is taking place in the world. People, however, are not using AI chatbots like ChatGPT, Gemini, and Claude as consistently as they did a year ago. 

32% of respondents said that they limit their use of artificial intelligence due to privacy concerns, and another 31% said that they would rather interact with people than AI chatbots. Users believe that chatbots invade their privacy since businesses utilize them to collect, store, and process personal information. 

32% of respondents limited their use of artificial intelligence due to privacy concerns, and this number was the same as last year. It suggests that users are still concerned about the collection, storage, and processing of their data by artificial intelligence systems. 31% of respondents said that they would rather engage with people than AI chatbots. Many users, however, believe that conversational AI cannot match human interaction, even though the technology has improved significantly in recent years. As such, there has been a noticeable shift in the attitudes of consumers toward the use of artificial intelligence, especially chatbots. 

29% of respondents said that they do not require artificial intelligence for their daily tasks, which is a decrease from the same survey last year. Users, however, still feel that generative AI is useless and do not want to adopt it. 

The other concerns regarding the use of AI by the consumers include becoming too dependent on the technology (26%), and having to communicate with others using generic responses and writing, with no personality, as a result of using chatbots (24%). Some respondents were not aware of the capabilities of artificial intelligence (19%) or simply had no interest in the technology (17%). Users also cited the complexity of artificial intelligence, doubts about its usefulness, negative effects on the world, and philosophical views against artificial intelligence as reasons for not being interested in learning more about generative AI technology. 

The survey also stated that 17% of respondents use AI chatbots such as ChatGPT or Gemini several times a day, while 14% engage with them multiple times a day. 30% of respondents never used AI chatbots, while the number was just 16% in the same survey last year. 

Artificial intelligence chatbots, however, are not engaging many people regularly. 21% of respondents use them only once or several times a week, while 11% use them a few times a month, and 8% use them even less frequently. In comparison, 30% of respondents never engage with AI chatbots, which is an increase from 16% in the previous survey. 

Interestingly enough, over 42% of Future publication readers use generative AI to communicate daily, which is double the percentage of respondents who usually read the Future website or books published by Future publishers. 

There is an evident change in the attitude of the consumer towards the use of artificial intelligence in their everyday lives. While many people are adopting AI-powered technology both in the workplace and at home, it appears that the engagement of consumers with artificial intelligence is nuanced. As businesses continue to innovate, consumers are rethinking their relationships with the technology. As such, with the increasing concerns over the privacy, trust, and authenticity of artificial intelligence solutions, it is evident that the consumer will continue to engage selectively with this emerging technology.

FakeGit Malware Campaign Abuses GitHub Repositories and AI Tools

 

There has been an extensive malware campaign, dubbed FakeGit, that utilizes thousands of counterfeit GitHub repositories to distribute SmartLoader malware, which is increasingly targeted at exploiting artificial intelligence (AI) tools and Model Context Protocol (MCP) servers in order to distribute the malware. 

Researchers at Island have discovered that approximately 7,600 malicious GitHub repositories have been constructed by using approximately 6,600 false developers profiles, creating nearly 7,600 malicious GitHub repositories. 

Thousands of repositories are masquerading as AI skills or MCP servers, offering integration with services such as Google Mail, WhatsApp, Docker, Jenkins, and Databricks. It is believed that FakeGit is an evolution of a previous malware operation that was previously associated with Water Kurita and that used Lumma Stealer. 

Research by Island researchers indicates that in March 2026, the campaign began focusing on artificial intelligence-based repositories, peaking in April with hundreds of repositories impersonating artificial intelligence tools before expanding into a broader ecosystem of fake AI agents, workflows, and MCP servers. By copying code, creating convincing README files, and impersonating developer identities, the fake repositories are very closely resembling legitimate open-source projects. 

A multi-stage infection chain is triggered by the download of malicious ZIP archives. Upon activation, the attack launches a LuaJIT-based loader that launches an obfuscated Lua script to install SmartLoader. SmartLoader establishes persistence on the compromised system and launches StealC, a malicious program capable of harvesting sensitive data from infected devices once it has been activated. 

After installation, SmartLoader creates persistence using scheduled tasks, retrieves its C2 server using the Polygon blockchain smart contract, downloads encrypted payloads hosted on GitHub, and ultimately deploys the StealC information stealer by deploying the C2 server. A new advanced tactic, AgentBaiting, has also been identified, which highlights how AI-powered coding assistants and autonomous agents can unintentionally aid hackers in gaining control of a computer. 

By optimizing fake repositories, threat actors can provide users with legitimate resources instead of forcing them to visit malicious links. Research conducted by Island researchers demonstrated that Claude Code automatically replicated malicious repositories and downloaded the associated files onto a test system, resulting in the discovery and recommendation of legitimate resources by AI models searching for free AI skills or MCP servers. 

In spite of this, the AI assistant detected suspicious indicators before executing the payload, which suggests that even though AI agents can be manipulated into retrieving malicious content, they may still be capable of detecting threats later on during the execution phase. In spite of the fact that these limited tests were not intended to measure the overall detection capabilities of artificial intelligence coding assistants, Island research demonstrated that AI assistants, such as Anthropic Claude Code, Google Gemini, and OpenAI ChatGPT, could detect malicious repositories during routine searches in response to user requests. 

Through artificial intelligence-assisted discovery processes, attackers can potentially pass malicious installation instructions to users without direct human interaction. More than 14 million downloads were recorded between the 335 malicious release assets hosted in approximately 211 FakeGit repositories as a result of GitHub's public statistics. 

In analyzing this figure, researchers cautioned that it represents cumulative download requests, including automated activity, and should not be interpreted as a count of successful infections. According to security experts, FakeGit illustrates how trust in open-source ecosystems and AI-assisted software discovery can be exploited without directly compromising any platforms. 

It is more common for attackers to distribute malware through convincing branding, fictitious developer identities, and public registries. To prevent malicious code from entering development environments, organizations should verify repository publishers, evaluate AI skills and MCP servers in isolated environments before deployment, maintain approved catalogs of trusted AI plugins, and monitor AI-assisted workflows to ensure that they are not compromised. 

A number of the fake repositories were also observed to be more credible by using duplicate project descriptions, fabricating star ratings and fork counts, and impersonating legitimate developer identities, as well as impersonating legitimate developers. In this manner, malicious projects were significantly more likely to be trusted and downloaded by developers and AI-assisted coding tools. 

AI agents are increasingly involved in the discovery and deployment of software, but researchers warn that the security of these automated workflows is as important as ensuring that human users are protected from traditional social engineering attacks. Using trusted developer platforms and AI-assisted workflows, cybercriminals are adjusting to the AI era through the FakeGit campaign. 

The increasing reliance on AI tools and open-source repositories calls for verification of software sources, limiting untrusted AI integrations, and strengthening supply chain security.

Ostium Confirms $23.75 Million Vault Exploit After Off-Chain Price Feed Compromise

 

Ostium, a decentralized trading platform built on the Arbitrum blockchain, has confirmed that hackers stole $23.75 million from its liquidity provider vault after compromising the platform’s off-chain price feed infrastructure. 
 
In an update shared by the company, Ostium explained that the attackers submitted fraudulent price reports disguised as legitimate data. Using the manipulated pricing information, they quickly opened and closed oversized trading positions to generate illicit profits from the liquidity provider’s vault. 
 
The company emphasized that user collateral remained secure as it is stored in a separate smart contract that was not impacted by the attack. Existing trading positions also remain intact and have not been liquidated. 
 
Ostium allows users to trade both traditional and cryptocurrency-linked assets directly from their crypto wallets. The platform relies on external price feeds for market data, while all transactions are settled using USDC, a stablecoin pegged to the US dollar. 
 
The platform initially disclosed the security incident on July 16, announcing a temporary suspension of trading. At the time, it said that relevant authorities had been informed and that efforts were underway to monitor the movement of the stolen funds. 
 
Providing further details, Ostium said the attackers exploited vulnerabilities in the off-chain infrastructure responsible for supplying market prices to the protocol. The manipulated price feeds enabled them to siphon funds from the liquidity provider vault without affecting trader-held collateral. 
 
According to blockchain security firm PeckShieldAlert, the exploiter converted the stolen USDC into 12,080 Ethereum (ETH) before depositing 10,540 ETH into Tornado Cash, a cryptocurrency mixing service commonly used to obscure transaction trails. 
 
Ostium reiterated that leveraged trading positions are maintained in a separate smart contract, ensuring that customer collateral was not compromised. Although active long and short positions remain recorded on the platform, they are currently frozen following the suspension of trading, which occurred within an hour of the first exploit transaction. 
 
The company said it is focused on securing the compromised infrastructure and evaluating recovery options for affected liquidity providers. 
 
Five days after the breach, trading on Ostium remains suspended. The platform has stated that users will receive at least 24 hours' notice before trading resumes. Once operations restart, all existing positions will be marked to the reopening price. 
 
Ostium also confirmed that it will release a detailed post-mortem report outlining the technical aspects of the exploit in the coming days.

UK Biobank Data Breach Rekindles Debate Over Research Data Security

 

A recent case concerning the UK Biobank has once again brought up the topic of securing medical research databases, as well as the importance of keeping research data both accessible and private. Professor of Cancer Medicine at the University of Oxford David Kerr pointed out that while sharing scientific data is important, it is also essential to maintain the trust of the general public and ensure the privacy of those whose data is being used. 

UK Biobank is one of the biggest biomedical research databases in the world, established in the early 2000s. It consists of the medical information of half a million people aged between 40 and 69, who volunteered to participate in the program from 2006 to 2010. The database contains genetic, imaging, metabolic, and clinical data on each of the volunteers, making it extremely useful for research into cancer, heart disease, brain conditions, and many other illnesses. Scientists from various corners of the world can apply to use the anonymized data of the UK Biobank volunteers for research purposes. 

According to Professor Kerr, the data from the database has been used to facilitate over 18,000 scientific publications to date. The information contained in the database is anonymized, meaning that the names and other obvious personal identifiers of the donors are removed. However, their ages and sexes are still available for scientific use. The data is invaluable to scientific research, as it has been found to be instrumental in facilitating major medical breakthroughs. 

However, the controversy involving the UK Biobank occurred when three scientists who had accessed the data were accused of trying to sell a part of the database containing the information on thousands of anonymous donors through Alibaba, an international Chinese online marketplace. It is reported that both the UK and Chinese authorities managed to remove the data from the marketplace before any purchases had been made. 

As a result, the three scientists lost their access to the database, and an investigation is currently underway to determine the full extent of the breach and whether personal information has been compromised. UK Biobank has issued a formal apology, calling the security breach a serious matter and stating that they are currently reviewing their security measures. 

According to Professor Kerr, while the database contains a wealth of information that has led to unprecedented international collaboration and research opportunities, such data has to be protected at all times. He noted that with the growing importance of biomedical research, large-scale health data sets have become targets for similar breaches, which has raised multiple concerns for the general public. 

Therefore, both the UK Biobank and the wider scientific community must continue working on protecting medical data sets while allowing unrestricted international collaboration and research.

Featured