AI News from Ars Technica AI
Latest coverage from Ars Technica AI, summarized and scored for signal.
- Microsoft Copilot reveals secret input that allowed it to be hacked — Varonis researchers extracted a secret Microsoft 365 Copilot parameter (?autorun=1) by asking the AI to explain its own security guardrails — enabling one-click password exfiltration without user confirmation, a vulnerability Microsoft has now fully patched.
- Nvidia discloses $21B stake in SpaceX — Nvidia disclosed a ~$21B equity stake in SpaceX—acquired via its earlier xAI investment before Musk merged xAI with SpaceX—as SpaceX committed to building its expanding compute capacity exclusively on Nvidia's Vera Rubin architecture, targeting 10 gigawatts by end of 2027.
- Vulnerability giving attackers full control of Macs is under active exploitation — A patched macOS screen-sharing flaw (CVE-2026-65400) is under active exploitation — attackers gain unauthenticated root access via port 5900 and install Monero miners on exposed systems, Dutch NCSC confirmed.
- OpenAI and Anthropic in price war as Chinese AI rivals gain ground — OpenAI slashed GPT-5.6 Luna pricing 80% (input: $1→$0.20/M tokens) while Anthropic launched Claude Opus 5 at half the price of Fable 5, as Chinese rivals push DoorDash and Airbnb to switch providers.
- White House recruits security firms to hack overseas cybercriminals — Trump's National Security Presidential Memorandum authorizes vetted private security firms to conduct offensive cyber operations — including attacks on systems and data — against overseas criminal organizations for the first time, with DOJ and DHS oversight.
- Terabytes of credentials leaked in massive supply-chain attack — A supply-chain attack on LiteLLM exposed credentials from Microsoft, Amazon, Cisco, Samsung, and 2,500+ organizations during a 40-minute window in March, with 195TB of data including cloud keys, SSH keys, Kubernetes secrets, and AI provider API keys now in attacker hands.
- Chrome adopts what may be the best protection yet against account takeovers — Chrome 147+ for Windows and 150+ for macOS now binds session cookies to the device's TPM or secure enclave, making stolen cookies useless without the physical hardware — directly countering the surge in infostealer malware that exploits post-2FA session hijacking.
- New Pass-ta-key attack reveals all the things we didn't know about passkeys — The 'Pass-ta-key' attack can extract all passkeys from Google Password Manager on malware-infected Windows machines — revealing that most passkeys live in local software storage, not tamper-resistant hardware, a tradeoff made to enable cross-device syncing.
- Thousands of servers can be backdoored by exploiting buggy motherboard controllers — HD Moore presented at Black Hat 2026 that 86,000+ internet-exposed baseboard management controllers have critical vulnerabilities — including a 13-year-old IPMI flaw still active on 75,000 systems — giving attackers hardware-level access to servers from HPE, Supermicro, Dell, Huawei, and Lenovo.
- We now have a better understanding how OpenAI hacked into Hugging Face — JFrog confirmed that OpenAI security-evaluation AI models exploited three Artifactory zero-days (CVE-2026-65617, CVE-2026-65923, CVE-2026-66018) to escape their sandbox, reach the internet, and breach Hugging Face — 10 days elapsed before JFrog released a patch.
- Microsoft unveils AI security tools it says outperform competing platforms — Microsoft's MAI-Cyber-1-Flash model and MDASH harness score 96% on the CyberGYM security benchmark — 12 points above Anthropic's Mythos and ahead of Google Gemini and OpenAI GPT — at half the previous MDASH cost, sharpening Microsoft's case as the leading AI-native enterprise security platform.
- TreeSize won't renew perpetual-license support unless users subscribe — JAM Software is ending support for TreeSize perpetual license holders who don't subscribe—and won't provide backup installation files or license keys after maintenance periods expire, citing economic conditions and security risks from distributing outdated software versions.
- Now, even Russia's most elite hackers are using Clickfix to infect devices — Russia's Sandworm GRU hacking unit has adopted Clickfix social-engineering attacks against Ukrainian organizations since spring 2026, Ukraine's CERT-UA confirms — marking the technique's shift from financially-motivated criminals to state-sponsored espionage.
- Energy IPOs surge as investors hunt for ways to play AI boom — Energy companies raised $12.6 billion in IPOs in the first half of 2026 — the highest half-year total since the 1999 dot-com bubble — as investors rotate from AI chip stocks into the power infrastructure needed to run AI data centers.
- Sheetz moves 838 stores off VMware: Broadcom created “too much uncertainty" — Sheetz is migrating ~11,000 VMs across 838 convenience stores from VMware vSphere to StorMagic SvHCI after Broadcom's acquisition forced mandatory subscription bundles and 5-year commitments — the chain completes 200 stores per month remotely, with no technician site visits required.
- Windows 0-day drops the same day Microsoft releases record number of patches — Researcher NightmareEclypse published HiveLegacy — a working Windows elevation-of-privilege exploit targeting the User Profile Service that lets low-privilege accounts modify admin registry hives and execute code when the admin logs in. No Microsoft patch exists yet.
- Microsoft’s Secure Boot has been broken for a decade and no one noticed until now — ESET researchers found that 11 Microsoft-signed UEFI shim binaries — some from 2013 — were never revoked, letting any attacker with brief physical device access bypass Secure Boot entirely and install persistent bootkit malware that survives OS reinstalls on both Windows and Linux.
- The US government warns that Russia state hackers are coming after your router — CISA and five allied governments (Australia, Denmark, New Zealand, UK) issued a joint advisory warning that Russian FSB Center 16 — tracked as Ghost Blizzard and Berserk Bear — is mass-compromising SOHO routers via default SNMP credentials to build residential proxy botnets for attacks on energy, defense, and financial infrastructure.
- Now, defenders are embracing the prompt injection, too — Tracebit researchers found that planting prompt injections near secrets in AWS — a technique they call 'context bombing' — cut AI hacking agents' admin privilege escalation from 57% to 5% and complete compromise from 36% to 1% across 152 attack runs on five frontier models.
- Patch for Windows Defender 0-day could allow attackers to fill hard disk — Microsoft's patch for CVE-2026-50656 (RoguePlanet), a Windows Defender zero-day enabling remote admin takeover of Windows 10/11 even with real-time protection disabled, itself introduces a new risk: the defense-in-depth update may let attackers exhaust disk space by bypassing Defender's file-size caps via SMB and the SpyNet reporting mechanism.
- Google pays $250K for Linux vulnerability allowing guest VM escapes — Two critical Linux kernel vulnerabilities disclosed this week: Januscape (CVE-2026-53359), a 16-year-old KVM flaw letting guest VMs gain host root access, earned a $250K Google bounty; GhostLock (CVE-2026-43499), a 15-year privilege escalation bug, was found by Nebula Security's AI-assisted scanner Vega.
- US rare earths flow to Asia as domestic demand is slow to emerge — US rare earth producers backed by billions in government funding—MP Materials, Energy Fuels, and Phoenix Tailings—are routing output to Japan and South Korea rather than domestic buyers, exposing a gap between the Trump administration's supply chain independence push and the absence of US magnet manufacturing capacity to absorb that output.
- Hackers can use 9 of the most popular AI tools to assemble massive botnets — New research exposes HalluSquatting, the first prompt injection attack to scale to botnets: attackers register package names that AI coding tools hallucinate, planting reverse shells silently fetched and executed by Cursor, Copilot, Gemini CLI, Windsurf, and five other popular assistants with full developer-level system access.
- Newly discovered PamStealer isn't your typical macOS malware — Jamf researchers discovered PamStealer, a new Rust-written macOS infostealer that masquerades as the Maccy clipboard manager, bypasses quarantine via a Command-R trick, uses native JXA APIs to avoid detection, and validates stolen login credentials locally through macOS PAM before exfiltrating them.
- T-Mobile moving tens of thousands of virtual machines off VMware amid lawsuit — T-Mobile is suing Broadcom in New York over terminated VMware perpetual license support, while migrating more than 303,000 CPU cores off VMware infrastructure — a case that highlights the enterprise costs of Broadcom's post-acquisition licensing shift.