DataAIHub
DataAIHubNews · Research · Tools · Learning

DataAIHub Daily

Archive →

August 06, 2026

49 curated AI news stories from leading AI companies.

Meta

August 6, 2026

Meta says its AI model hacked another company, adding to worries about bots going rogue - WRAL

Meta says its AI model hacked another company, adding to worries about bots going rogue WRAL

Read original article

Anthropic

August 6, 2026

Anthropic will design its own hardware to power Claude

Anthropic and OpenAI are racing to scale up while reducing dependence on Nvidia.

Read original article

OpenAI

August 6, 2026

GPT-5.6 Sol just got better in one place and stayed the same everywhere else

Teams testing prompts in ChatGPT before moving them to Codex or Work may notice the difference on longer tasks. OpenAI The post GPT-5.6 Sol just got better in one place and stayed the same everywhere else appeared first on The New Stack.

Read original article

OpenAI

August 6, 2026

Open AI improves GPT-5.6 Sol in Chat GPT and restricts free users to its weakest model

OpenAI has updated GPT-5.6 Sol with more focused responses and a reasoning slider that lets users adjust how deeply the model thinks. Free users will get unlimited text chats with the smaller GPT-5.6 Luna starting next week, plus a button that lets Luna reason longer. But the smaller model still falls well short of its bigger siblings. The article OpenAI improves GPT-5.6 Sol in ChatGPT and restricts free users to its weakest model appeared first on The Decoder.

Read original article

Anthropic

August 6, 2026

Deepmind's talent drain likely comes down to chip shortages, a conflict of interest, and Google's bureaucracy

Ex-Google Deepmind CEO Demis Hassabis has reportedly stepped back from day-to-day operations for about a year, as he sees himself more as a scientist than a manager. Researchers are also complaining about limited access to Google’s own TPU chips, while external customers like Anthropic can purchase the same hardware through Google Cloud. The article Deepmind's talent drain likely comes down to chip shortages, a conflict of interest, and Google's bureaucracy appeared first on The Decoder.

Read original article

Microsoft

August 6, 2026

Microsoft's AI revenue reportedly depends on Open AI for 70 percent

Microsoft generated $24.1 billion in AI revenue through OpenAI in the fiscal year ending in June. That's about 70 percent of its total AI business, according to a Bloomberg analysis. The heavy reliance helps explain why a company long known for vendor lock-in has recently been championing open-weight models and pushing back against proprietary isolation. The article Microsoft's AI revenue reportedly depends on OpenAI for 70 percent appeared first on The Decoder.

Read original article

OpenAI

August 6, 2026

Chat GPT brings unlimited text chats to free users

OpenAI said that ChatGPT free and Go users are also getting a new think button for complex queries.

Read original article

Microsoft

August 6, 2026

The blank-check AI coding era is dead. Here’s what comes next.

Microsoft spent the first phase of the AI coding boom pushing its engineers to use the tools. Now it wants The post The blank-check AI coding era is dead. Here’s what comes next. appeared first on The New Stack.

Read original article

Meta

August 6, 2026

Adaptive Experimentation with Meta’s Ax: A Practical Coding Guide

In this tutorial, we explore adaptive experimentation using Meta’s Ax with the modern Client API. We work through a complete workflow where we tune a RandomForest model on a synthetic classification dataset while balancing predictive accuracy against model footprint. We begin by defining a mixed search space with integer, float, log-scaled, and categorical parameters, then […] The post Adaptive Experimentation with Meta’s Ax: A Practical Coding Guide appeared first on MarkTechPost.

Read original article

Meta

August 6, 2026

Meta Model’s Hack Mirrors Previous Open AI and Anthropic Security Breaches - PYMNTS.com

Meta Model’s Hack Mirrors Previous OpenAI and Anthropic Security Breaches PYMNTS.com

Read original article

Claude

August 6, 2026

Claude Code is the fastest agent framework but costs nearly three times more than the cheapest rival

Composio tested Deepseek V4 Flash across four agent frameworks on 30 real-world tasks. Success rates were mostly similar, but costs varied by nearly 3x: OpenCode came in cheapest at $0.073 per task, while Claude Code cost $0.195 despite using the fewest tool calls and output tokens. The choice of framework is mainly a question of price and speed. The article Claude Code is the fastest agent framework but costs nearly three times more than the cheapest rival appeared first on The Decoder.

Read original article

Claude

August 6, 2026

Enforcing data residency with single-Region Claude Code on Amazon Bedrock

A regulated customer needed all Claude Code inference processed in a single AWS Region (London), not just in-geography. This post shows two ways to pin Claude Code on Amazon Bedrock to one Region: an application inference profile or the Mantle endpoint, paired with an IAM Region condition, plus how to verify compliance in AWS CloudTrail.

Read original article

Databricks

August 6, 2026

Introducing Office QA Pro V2: A New Benchmark for Enterprise Grounded-Reasoning

Today, we are releasing OfficeQA Pro V2, a new benchmark designed to evaluate whether...

Read original article

Google

August 6, 2026

Advancing brain tumor research with privacy-first AI

The intersection of medicine and AI has led to remarkable innovations. However, developers now face the thorny challenge of building robust medical AI tools that have been tested and evaluated on diverse, real-world patient data while also protecting patient privacy. At Google Cloud, our approach combines strategic collaboration with Confidential Computing. To help protect both patient privacy and AI models during validation, we’re collaborating with MLCommons through the MedPerf initiative. First announced at Google Cloud Next earlier this year, this partnership uses Confidential Computing to establish a secure clean room for benchmarking AI models in real-world settings. The challenge: Evaluating AI without seeing the data MLCommons, a global community with over 125 members across tech and academia, launched MedPerf in 2023 to standardize the evaluation of medical AI. MedPerf, an open-source platform for benchmarking AI models, has advanced clinical research using federated evaluation to test models. By using Google Cloud Confidential Space, proprietary AI models can be evaluated inside hardware-isolated Trusted Execution Environments (TEEs). This special virtual machine encrypts memory in-use and hardens the operating system, so none of the parties — the hospital or research institution, other participants, or Google — can see model code or patient data while it's evaluated. Medical AI benchmarking is compute-heavy, so the Confidential VM extends beyond the CPU to the GPU. To protect model weights and patient data even during GPU-accelerated inference, MedPerf runs on Google Cloud's A3 machine series with NVIDIA H100 GPUs, which pairs Intel TDX technology on the CPU with NVIDIA Confidential Computing on the GPU. Before any patient data is released into the workload, the system provides cryptographic proof that only the approved code is running on genuine Confidential Computing hardware and that the environment has been properly hardened. Real-World Medical AI Evaluation: MedPerf & GCP Confidential Computing Demo Learn how ML Commons MedPerf integrates with Google Cloud Confidential Compute to enable secure, real-world evaluation of medical AI models. From theory to critical impact: Advancing brain tumor research This technology is already driving critical research through the Federated Tumor Segmentation (FeTS) initiative. Brain tumors, such as glioblastomas, are rare, making it difficult for any single hospital to collect enough data for high-accuracy AI training. Compounding the problem, a model that performs perfectly in one hospital can struggle in another due to differences in patient demographics, data acquisition techniques, and even in equipment. Working with visionary researchers like Indiana University’s Dr. Spyridon Bakas, Northwestern University’s Dr. Yury Velichko, and the University of Alberta, Canada’s Dr. Amber Simpson, MedPerf on Google Cloud is validating AI models on private brain MRI data from around the world, and identifying potential performance gaps. For example, a model might be 95% accurate at one site but only 63% accurate at another. Our collaborative approach demonstrates that when an AI tool reaches a clinician, it has been proven to work across a truly representative patient population. Achieving clinical trust and validation The impact of this collaboration is best summarized by those on the front lines of clinical research. "My experience testing federated learning on Google Cloud has shown that the future of medical AI lies in secure, scalable, and collaborative cloud environments," said Dr. Yury Velichko, associate professor, Radiology, Northwestern University. "Moving beyond the controlled lab setting to test these workflows in a production-ready infrastructure provided a unique opportunity to evaluate the performance and security of federated learning in real-world clinical applications.” "Medical AI holds enormous promise for patients around the world, but that promise can only be realized if clinicians, researchers, and regulators can trust the benchmarks we use to evaluate it,” said Alexandros Karargyris, MedPerf lead, MLCommons. By bringing MedPerf onto Google Cloud's Confidential Computing infrastructure, we have taken a major step toward a future where AI models can be rigorously tested on real patient data — without compromising privacy, intellectual property, or benchmark integrity.” The future: Scaling secure medical breakthroughs The collaboration between MLCommons and Google Cloud represents a fundamental shift toward privacy by design in healthcare AI. By making it easier to securely share and evaluate data and models, we are clearing the path for faster, safer, and more equitable medical breakthroughs. Research institutions and healthcare model developers interested in using the MedPerf platform on Google Cloud should contact medical@mlcommons.org or your Google Cloud account team.

Read original article

Google

August 6, 2026

Your agentic summer: No-cost lessons from Google experts to build and scale agents

I’ve talked to developers, IT leaders, and builders who all ask the same question: How do we actually get agents into production? The answer isn't theoretical — it's hands-on. Whether it’s designing a system that allows your agents to interact with external data sources while maintaining strict security guardrails or creating self-optimizing supply chain workflows or whatever you can think up, we’ve got you covered. That’s why we’ve designed a path to help you take your AI ideas from a rough sketch to fully autonomous agents running in production. This summer, you can harness the same frameworks and approaches used by Google experts to build and scale agents — entirely at no cost. Powered by Gemini Enterprise Agent Ready (GEAR), these hands-on labs and courses give you the blueprints and tools you need to deploy agents that ship. Find your roadmap to future-proof your skills this summer, starting here. 1. Intro to AI Agents: Build a foundational understanding of how autonomous agents can redefine productivity. 2. Agent Fundamentals: Go under the hood of autonomous intelligence. Learn decision models and execution loops to deploy adaptive agents over rigid automation. 3. Enterprise Agents and Use Cases: Discover how AI agents drive real business impact. Map agents directly to corporate KPIs, solve operational bottlenecks, and utilize no-code to high-code frameworks. 4. Create Your First Gemini Enterprise Application skill badge: Earn a skill badge that proves you can create an app with Gemini Enterprise. You will master capabilities like deep research agents, multi-agent ideation, and Gemini Notebook for focused analysis. 5. Human-Centered AI: Keep humanity at the core of automation. Learn to strategically balance machine speed with human intuition for successful orchestration. 6. Agentic Strategy: Discover, Design, and Prototype: Prototype high-impact AI projects with zero code. Leverage Google’s transformation framework, map user journeys and build functional retail prototypes. 7. Orchestrate Multi-Agent Workflows with Gemini Enterprise skill badge: Demonstrate your ability to manage multiple agents powered by Gemini Enterprise with a skill badge. This skill badge shows that you can unify data across first- and third-party sources, develop multimedia marketing materials, and fully automate complex business actions across disjointed systems. 8. Engineer AI Agents with Agent Development Kit (ADK) skill badge: Build production-grade agents using expert developer tools. Earn a skill badge that proves you can perform live search grounding, build structured JSON schemas, and manage ADK pipelines. 9. Add Currency Tools to an Agent Using MCP: Connect your LLMs to external systems in just 20 minutes. Securely bridge agents with live external databases and deploy via CLI. 10. Manage Agent Memory and State: Give your agents a memory. Move beyond single-query replies and use session states with the ADK to build highly personalized, deeply contextual agents. 11. Create Agent Skills with Google: Infuse domain expertise into custom skills. Minimize AI unpredictability and build reusable workflows that optimize agent performance. 12. AgentOps: Operationalize AI Agents on Google Cloud: Harden your prototypes and scale safely to production. Implement observability, proactive monitoring dashboards, and robust CI/CD security. Test your skills at the summertime Hackathon Keep moving with agents! The All Things Agentic Hackathon is officially live. The next leap in AI won't build itself — it needs you. Step up to the challenge with Gemini 3.5 and Google Cloud and deploy autonomous agents that do the heavy lifting in the background. Build what’s next, show the world what you can do, and compete for $180,000 in prizes, cash, and credits Submissions are open from August 3, 2026 to August 31, 2026. Register here. Join GEAR today Don't wait for the summer to pass you by. Get hands-on with the tools, earn real-world credentials, and build in-demand skills, with confidence. Ready to level up your agentic skills? Check out our two newest learning paths: Build High-Performance Multi-Agent Systems and Govern and Secure Enterprise Agents. Learn more → Join GEAR today and start building.

Read original article

Google

August 6, 2026

Digital sovereignty in the age of AI: You don’t have to choose between control and innovation

For enterprises and governments with strict compliance and sovereignty requirements, keeping sensitive data on-premises often means missing out on the latest AI. These organizations are managing three major risks: Jurisdictional risk: Shifting local regulations, the need to protect intellectual property and the potential of foreign data access requests make local data handling essential. Economic independence: Reliance on foreign infrastructure providers could leave critical services vulnerable. Geopolitical risk: A need to safeguard critical local services against unpredictable global disruptions. In a recent survey of over 1,400 senior IT leaders for our State of AI Infrastructure report, 48% of leaders stated they are prioritizing infrastructure with data residency, controls, supporting compliance, with local data security laws. However, staying on-premises no longer means being cut off from the latest innovation. Organizations are increasingly deploying hybrid (on-premises and multicloud solutions) to bridge this gap. Our research shows that 52% of organizations now have a hybrid cloud approach to AI.This approach allows enterprises to balance the massive raw power of the public cloud with the sovereignty and compliance benefits of local environments — allowing them to control where their data resides and who has access to it. In the past, organizations with such strict data rules couldn't easily access advanced AI. Building their own AI systems was also too slow and costly.That is why we introduced Google Distributed Cloud (GDC). GDC brings Google Cloud to wherever you need it — in your own data center or at the edge. It is offered in two deployment models to meet your AI workload sovereignty requirements:Air-gapped: A fully disconnected solution that does not require connectivity to Google Cloud or the public internet. It cannot be remotely shut down by Google.Connected: An integrated, Google-managed software lifecycle that runs directly on your existing hardware.GDC offers a complete, on-premises AI solution with infrastructure optimized for AI workloads, a choice of Gemini or open models, and cost-effective inference services. This foundation empowers you to build and run secure AI agents while maintaining total control over your data.Meet your sovereign AI needs on-premisesYou no longer have to choose between data control and AI innovation. With Google Distributed Cloud, we bring the world's leading AI directly into your environment — keeping your data entirely yours.Explore the hybrid strategies of leading enterprises in the State of AI infrastructure report.

Read original article

Google

August 6, 2026

Agentic Future Ready With Big Query: Continually Improving Price-Performance, Zero Effort

In the modern data landscape, query performance tuning and managing system price-performance is challenging, especially as the number of agentic workloads increase. Even for experienced developers and DBAs, constantly analyzing query execution plans, tweaking schemas, and adding query hints with ever exploding volume, variety, and velocity of data is a never-ending cycle that drains business velocity. While performance tuning is a common practice, a modern data platform should do more. As data platforms evolve from systems of intelligence to systems of action, and analytics workloads shift from humans running a few queries per day to countless agents running many thousands of queries per minute, the old way of manual query tuning doesn’t work. When queries are generated by agents and applications automatically based on user actions, manual optimization becomes practically impossible. BigQuery has evolved from a data warehouse to the primary engine for the Agentic AI era. Building on a unique, truly disaggregated storage and compute architecture, serverless processing, and fine grained compute management, BigQuery continues to push the boundaries of autonomous query processing. Our North Star is an autonomous query processor powering both humans and agents for hands-free optimum price-performance regardless of query, schema, data, or workloads. Just in 2025, we delivered up to 35% better query performance and as much as 40% reduction in query processing costs (slot usage). Figure 1. Summary of BigQuery price-performance improvements throughout 2025 based on industry standard benchmarks. The following are some of the major innovations contributing to these improvements in performance and total cost of ownership (TCO), including the built-in guardrails against regression. BigQuery’s Self-Learning Engine: History-Based Optimizations (HBO) One of the foundational capabilities of BigQuery’s autonomous query processor is history-based optimizations. Traditional query optimizers rely on static statistics, metadata and cardinality estimates, which can be wildly inaccurate when faced with highly complex, multi-table joins and rapidly growing/changing data. Managing these is part of the critical path for administrators and automation has to be tailored to individual workloads to be effective and efficient. Even when everything is up-to-date and correct, queries can still have vastly different behavior due to natural data skew or changes in available compute resources. History-based optimizations change the paradigm: in addition to BigQuery’s already adaptive query execution that can change plans and resource allocations while a query is running, it learns from past executions and automatically applies additional optimizations for future executions. It tracks runtime statistics of past queries to "remember" which optimizations were beneficial and continue to apply them, and learn from prior mistakes to ensure they are not repeated. When the same or similar query runs again, BigQuery automatically applies any additional optimization technique that is known to be beneficial and avoids those that can cause regressions. No User Action Required & Built-in Safety GuardrailsHistory-based optimizations require no application rewrites, SQL modifications, or schema changes. Users literally do nothing, and their recurring dashboards, ELT pipelines, agentic workloads, or line of business modules run faster. Crucially, this is a self-maintaining, self-improving closed-loop system with built-in safety guardrails. History-based optimizations only apply an optimization when there is high confidence it will improve performance. What if an optimization makes the wrong decision? This capability is inherently self-correcting. When an optimization is applied, the system measures the result. If the expected improvement is observed, the optimization is accepted. If it does not significantly improve performance—or worse, regresses or leads to failure—the optimization is immediately rejected, revoked, and never tried again for that query. This includes detecting data skew so queries that have parameter sensitive plans do not run into major performance issues when just a single parameter (aka WHERE clause) is changed. The result? A decrease in execution times and a reduction of slots. One enterprise customer reported P90 execution times drop by up to 50%, with slot usage falling by up to 15% resulting in substantial price-performance improvements and no regressions. Figure 2. One example of History Based Optimization performance improvement reported by an enterprise customer. Teaching the BigQuery execution engine newer tricks: Advanced runtime BigQuery’s autonomous capabilities extend deep into the execution layer with BigQuery advanced runtime. This engine upgrade automatically determines the best physical execution path for a query without any manual knob-turning. 1. Enhanced vectorizationWhile vectorized execution is not a new concept, BigQuery enhanced its implementation by taking advantage of the newer processor efficiencies in Single Instruction Multiple Data (SIMD) instructions. The engine autonomously identifies opportunities to avoid duplicate computations, processing data in dictionary and run-length encodings natively. It couples with state-of-the-art parallel algorithms and is applied at eligible query stages to increase the opportunities for acceleration. The Impact: Fully automated, safely accelerating qualifying queries by up to 10x, yielding up to a 40% overall slot time reduction. Figure 3. Advanced runtime - Enhanced vectorization 2. Short query optimizationsFor high-concurrency and low latency BI dashboards or agentic applications generating thousands of queries that require sub-second latency, distributed processing overhead can be a bottleneck. BigQuery now autonomously accelerates eligible "short" queries without impacting other queries running concurrently. By reducing the number of stages hence reducing data shuffling, BigQuery improves overall query latency and resource efficiency. BigQuery has effectively implemented an efficient symmetric multi-processing (SMP) query path transparently within a scalable massively parallel processing (MPP), distributed databases. The Impact: up to 10x lower slot usage for short queries, with P99 sub-second query latencies. Because each query uses slots for shorter periods, we observed some customer workloads having up to 3x higher throughput—all completely transparent to the end-user. Figure 4. Advanced runtime - Short query optimizations Same Benefits Regardless of Data Formats We believe you shouldn't have to sacrifice autonomous performance when adopting open lakehouse architectures using open table formats like Apache Iceberg. BigQuery performance improvements work the same regardless of the underlying table or data format. That means you still get the same benefits whether you’re using BigQuery’s native capacitor storage format or Iceberg tables where the underlying data is in parquet format. Whether it’s automatically pushing down filters, employing Column Metadata Index (CMETA) pruning, and optimizing the I/O layer with page skipping and asynchronous read or employing the same enhanced vectorization, open formats benefit from the same hands-free acceleration as native tables. Figure 5. BigQuery on Lakehouse Iceberg tables performance and costs tested internally against a popular open source, distributed SQL query engine using a benchmark derived from TPC-DS (10TB) Fluid Scaling: The True Only-Pay-For-What-You-Use Autoscaler Because BigQuery’s compute models are tied directly to slot-seconds consumed rather than a slice of nodes or clusters, autonomous performance gains can translate directly to cost savings. BigQuery autoscaler enhanced with fluid scaling enables you to run any mix of highly variable workloads with a premier autoscaling model that does not require a cost-and-performance trade-off. Fluid scaling in BigQuery enables true per-second billing for compute resources (slots) consumed and lowers costs by up to 34% on average for autoscaling workloads. Figure 6. Fluid scaling enhanced autoscaler On the price-performance benefits of fluid scaling, Chen Shalit, the CEO and Co-Founder at RISE, a leading AdTech company that processes 1 PB+ data per day and manages 3 trillion+ monthly bids across publishers and advertisers, summed it best. “In the high-stakes world of advertising, every cent counts. BigQuery’s Fluid Scaling has reduced our infrastructure cost by 25% allowing us to scale our slot consumption and accelerate our entire workflow. By delivering faster model results and increasing our hourly data processing throughput, we’re providing our customers with the 'freshest' data possible.” The foundation for the agentic future These autonomous capabilities are not just about making today's business intelligence dashboards and analytics queries run faster; they are foundational to the future of modern data platforms. As organizations rapidly deploy AI and machine learning, they are shifting toward agentic workloads. AI agents do not interact with data the way humans do. Their query latency and concurrency (QPS) requirements are orders of magnitude more demanding than what human users generate—which is the limit of what most traditional analytics platforms were designed for. When autonomous agents are firing off thousands of distinct queries per second to make real-time decisions, human-in-the-loop query tuning is simply impossible. BigQuery's differentiated abilities in a self-tuning and self-learning system include built-in safety guardrails against regression. With this standard of autonomy, you can spend your time and effort where it truly matters: delivering the best experiences for your users with advanced agentic applications, rather than wasting critical engineering cycles on manual infrastructure management, reactive query optimization, or trying to rein in spiraling compute costs. BigQuery’s aggregate TCO impact: Faster and more cost-effective price-performance When you combine a self-learning history-based optimizer with an auto-scaling advanced runtime engine supported by a highly scalable metadata platform (CMETA), you can see real impact on performance and total cost of ownership (TCO). Conclusion Our goal is for BigQuery to automatically and safely optimize queries without user action so our users can “just come in to work and BigQuery is faster than it was the day before." You no longer need to worry about data skew or stale statistics causing performance regressions. No more trying to figure out which plan guide works best for which queries at what time of the day or month. No more hoping you won’t run out of budget because there aren’t enough low priced spot instances. Just focus on your organization’s goals, and your BigQuery data platform can deliver optimized price-performance for both agent and human workloads autonomously; it just works. Learn more about BigQuery’s data and AI capabilities and get started with a free trial.

Read original article

Databricks

August 6, 2026

Kimi K3 from Moonshot AI is now available on Databricks through Unity AI Gateway

A year ago, the best open-weight models trailed their proprietary counterparts by...

Read original article

OpenAI

August 6, 2026

Open AI says Apple’s own security practices undermine its trade secrets case

Newly filed court exhibits show OpenAI’s legal strategy in Apple’s trade secrets lawsuit: argue that Apple’s own security and offboarding practices — including allowing an Apple manager to access a former engineer’s iCloud account after he left the company —undermine its claims that the allegedly stolen information was properly protected.

Read original article

Anthropic

August 6, 2026

Anthropic recommends a git worktree per agent. Your runtime infra makes that a problem.

A developer supervising four coding agents has four changes in flight at once, each in its own git worktree. That The post Anthropic recommends a git worktree per agent. Your runtime infra makes that a problem. appeared first on The New Stack.

Read original article

Google

August 6, 2026

Google’s Deep Mind Shakeup Weakens UK Bid to Stay in AI Race - Bloomberg.com

Google’s DeepMind Shakeup Weakens UK Bid to Stay in AI Race Bloomberg.com

Read original article

Meta

August 6, 2026

Meta’s AI Can Hack Things Too. It’s the Mark of a Winner. - Barron's

Meta’s AI Can Hack Things Too. It’s the Mark of a Winner. Barron's

Read original article

Meta

August 6, 2026

'AI Kill Switch' bill needs to be passed this year amid ongoing rogue agent hacks, Rep. Lieu says - CNBC

'AI Kill Switch' bill needs to be passed this year amid ongoing rogue agent hacks, Rep. Lieu says CNBC

Read original article

Microsoft

August 6, 2026

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

Written by: Tyler McLellan, Austin Larsen Introduction Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their personal mobile devices. These calls lure victims to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens. Once session persistence is established, the actors deploy automated scripts for data exfiltration from enterprise cloud environments, including Microsoft 365 and Okta. In this update to our May 2026 blog, we detail the infrastructure linkages connecting these extortion brands. We also examine the evolution of UNC6671's targeting including recent activity focused on financial services, private equity, and professional services, and provide hardening guidance to help organizations protect themselves from this threat. UNC6671 Associated Extortion Brands Across UNC6671 intrusions, the initial access and post-compromise tactics, techniques, and procedures (TTPs) have remained remarkably consistent. These operations uniformly leverage tailored IT helpdesk voice phishing (vishing), AiTM credential harvesting panels, and data theft from SaaS applications. Despite this unified technical baseline, extortion messages have used different branding and victim data stolen during these intrusions has been published across distinct data leak sites (DLS) (Figure 1). While public group communications cited an affiliate breakaway as the rationale for the initial rebranding to Redact, subsequent overlaps in phishing templates, victimology, and shared infrastructure conduits suggests that associated actors have subsequently leveraged the Pink, Helix, and Falcon extortion brands to monetize their operations. Figure 1: UNC6671 Associated DLS Listings by Site Figure 2: Helix and Pink DLS Figure 3: Falcon DLS Initial REDACT Rebranding On June 27, 2026, the Redact operators published a blog post on their newly established Data Leak Site (DLS) addressing their alleged rebrand away from BlackFile. In the publication, the group claimed that the original BlackFile brand had been compromised and hijacked by an exiled affiliate. According to Redact, this former associate purportedly operated an unauthorized, lookalike DLS and conducted unsanctioned extortion campaigns under their name using unlinked Tox identities. The operators asserted that this rogue affiliate intentionally orchestrated the "shutdown" of the BlackFile brand in May 2026 to sow confusion among threat intelligence analysts and cyber insurance negotiators, thereby damaging the brand's reputation. To distance themselves from BlackFile, the operators stated that they rebranded as Redact, introducing a single verified Tox ID and PGP key to authenticate all future correspondence. Additionally, the post explicitly denied that pressure from the rival groups influenced their rebranding decision. Figure 3: REDACT statement on alleged break from BlackFile Shared Infrastructure: Connecting the Phishing Ecosystem UNC6671 uses credential harvesting panels hosted on generic root domains masquerading as being related to passkeys, appending victim-specific subdomains to facilitate targeted voice phishing campaigns. Monitoring this consistent digital footprint revealed overlaps in specific victim targeting associated with multiple extortion brands. These overlaps support our assessment that a common group of threat actors are affiliated with the BlackFile, Redact, Pink, Helix, and Falcon extortion brands, although other scenarios such as splintered affiliates or shared Phishing-as-a-Service infrastructure may also be plausible. Rather than maintaining isolated infrastructure for each target, UNC6671 reuses generic root domains across multiple target organizations, creating a traceable chain between extortion brands: Falcon: The root domain passkeyhelpdesk[.]com was used to target at least one organization extorted using the Falcon brand. This same domain was simultaneously used to target an organization extorted using the Helix brand, as well as numerous other companies that we did not observe later posted on a DLS. Additionally, root domains such as portalpasskey[.]com and addssopasskey[.]com targeted organizations extorted by Falcon, while hosting intermediate targets that bridged directly into Helix infrastructure. Pink: A subset of unlisted companies were concurrently targeted using additional root domains (such as passkeyms[.]com and mysecurepasskey[.]com), which acted as intermediate bridges to another infrastructure cluster focused on passkeydeploy[.]com. This final domain was simultaneously used to target at least one organization extorted by Pink. Helix: The root domain passkeyhelpdesk[.]com directly overlapped targeting between Falcon and Helix. Furthermore, intermediate target organizations bridged additional infrastructure into clusters of subdomains on oskeysync[.]com and keysyncos[.]com. These clusters targeted multiple organizations later listed on the Helix DLS. BlackFile: Root domains such as setupsso[.]com and idokta[.]com were used to target an organization extorted using the BlackFile brand. Intermediary target organizations on setupsso[.]com acted as bridges to passkeydeploy[.]com (Pink). Concurrently, passkeyuser[.]com was used to target another BlackFile victim, where intermediate target organizations bridged into passkeyportal[.]com (Helix) and mysecurepasskey[.]com. Figure 4: Shared infrastructure across multiple brands Phishing templates Analysis shows that the same phishing templates were used across all these domains, with identical code and design hosted simultaneously on different websites, including addssopasskey[.]com, createssopasskey[.]com, and passkeyhelpdesk[.]com. For instance, while addssopasskey[.]com was strictly used to target organizations later extorted by Falcon, the identically configured passkeyhelpdesk[.]com domain was simultaneously used to target two entirely separate victims—one of which was claimed by Falcon, and the other by Helix. The widespread deployment of these matching templates to harvest credentials for multiple DLS brands suggests they rely on shared underlying infrastructure. Evolution of Targeting UNC6671’s domain registration patterns demonstrate a regular shift in target selection, seemingly towards those that are more likely to hold sensitive information. UNC6671 leverages subdomains that incorporate prospective victim names to host tailored credential harvesting panels. Their root domains mimic enterprise authentication enrollment portals pairing terms as "passkey," "mfa," or "sso" paired with verbs. Between April and May 2026, we observed domains broadly designed to target mature, large-scale enterprises across multiple industries including the manufacturing, real estate, healthcare, and insurance sectors. During this wave of activity, the threat actors appeared to prioritize high-volume credential harvesting across these established enterprise verticals. The observed subdomains in the following months appeared to represent a progression in UNC6671’s extortion model. In June 2026, targeting transitioned toward large technology, transportation, and hospitality organizations, seemingly focusing on entities holding valuable intellectual property, software source code, or sensitive VIP client data. By July 2026, the target profile narrowed to focus on the financial and legal sectors, with observed infrastructure directed at private equity firms, law firms, and financial rating agencies. Concentrating on organizations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximize leverage extortion demands. Comparing these two time periods also illustrates an increase in operational tempo. The volume of newly observed infrastructure was evenly distributed between June 1 and July 31, 2026, establishing an accelerated cadence of approximately one domain every 1.6 days, primarily across Cloudflare and DDOS-GUARD. A brief spike in provisioning also occurred between July 20 and July 22, during which seven domains were operationalized within a 72-hour window. This overall June and July tempo represents a measurable increase from earlier activity observed between April 1 and May 31, 2026, where a set of 28 root domains was provisioned at a less frequent rate of one every 2.2 days. On the date of publication of this blog, 7 of 8 still resolving phishing domains did not use wildcard DNS indicating that targets discovered through passive DNS data were likely specifically targeted by UNC6671. Figure 5: Root domain registrations New Techniques Since our last blog, the tactics across UNC6671 intrusions have been largely consistent; however, we have observed several new techniques. IT Helpdesk and Passkey Pretexts UNC6671 callers have continued to call targeted employees on their personal mobile numbers, circumventing corporate security controls. In at least some recent cases, the threat actor has spoofed the legitimate helpdesk phone number adding an air of legitimacy. During these phone calls, operating under the false pretext of an urgent helpdesk mandate to enable FIDO2 passkeys or update multi-factor authentication enrollment, the caller directs the employee to a lookalike credential-harvesting subdomain (e.g., [company].createssopasskey[.]com or [company].addssopasskey[.]com). EvasionTechniques UNC6671 increasingly relies on defense evasion to maintain account-level persistence and conceal its operations. In recent intrusions, the group used compromised email accounts to initiate unauthorized password resets for non-SSO enterprise applications. To prevent end-user detection or automated security alerts, operators systematically deleted password-reset confirmations, secondary security notifications, company-wide security alerts, and any alerts generated during modifications to account security or MFA configurations. Ransom Negotiations and Blockchain Analysis Between January 7, 2026, and May 12, 2026, GTIG reviewed 18 BlackFile Bitcoin wallet addresses receiving a total of 141.65 BTC, representing approximately $10.69 million USD at the time of the transactions. Notably, ransom payments to these wallets continued past the publicized Blackfile data leak site shutdown notice on May 11, 2026. Multiple significant cashout events observed in late April and early May confirm that financial operations proceeded without interruption during the rebranding phase. Initial ransom demands typically range from $1 million to upwards of $3 million USD. However, the extortion operators shifted demands during negotiations, often agreeing to reductions between 50% and 75% of the initial ransom demand. In over 53% of tracked cases in this timeframe, final payments averaged $750,000 USD (~10.2 BTC). Remediation and Hardening Guidance GTIG recommends that corporate defenders implement the following controls to mitigate identity-centric vishing, AiTM phishing, and programmatic SaaS exfiltration: Enforce Phishing-Resistant Multi-factor Authentication: Mandate phishing-resistant authenticators such as FIDO2-compliant roaming security keys, passkeys, and platform authenticators (e.g., Windows Hello for Business, Okta Fastpass) across all SSO environments and enterprise identity providers (IdPs). These authenticators implement WebAuthn standard to enforce cryptographic origin binding between the authenticator and the specific domains it can authenticate to, rendering lookalike domains and AiTM proxies ineffective. Integrate SaaS Applications and Cloud Platforms with SSO: Maintaining authentication standards across multiple platforms increases the propensity for configuration drift. Different SaaS applications require or support different security features. Integrating business-critical applications with a standard SSO platform such as Entra ID or Okta allows consistent application of security controls across disparate platforms. Enforce Session Controls: Reduce session lengths to enforce re-authentication at least once per work day. Enforce idle session timeouts, especially for privileged access. These timeouts can be reduced further during active phishing campaigns. Enforce step-up authentication when accessing critical or sensitive resources. Utilize token theft mitigations within authentication platforms such as IP session binding, Device-Bound Session Credentials, or Continuous Access Evaluation. Restrict Authentication to Trusted Network Sources: Utilize defined network zones coming from known sources such as corporate networks, VPN ranges, and Secure Access Service Edge (SASE) platforms. Define and enforce these ranges within SaaS apps or cloud platforms as well as within authentication policies in Entra ID or Okta. Require Corporate-Managed Devices for Access: Enforcing that authentication comes from a corporate-managed endpoint with MDM and EDR reduces the attack surface and likelihood that an attacker can utilize an arbitrary device for access. Device checks can be configured as part of authentication policies in Entra ID or Okta. Deploy Endpoint and Browser Credential Guarding: Enable Google Workspace Password Alert to trigger automated administrative alerts or resets if corporate password hashes are entered into unauthorized domains. For Microsoft 365 environments, configure Microsoft Defender SmartScreen and Credential Protection to block credential submissions on unverified sites. Monitor IdP Logs for Abandoned Challenge Patterns: Query Okta and Microsoft Entra ID audit logs for MFA registration events (system.multifactor.factor.setup) that are immediately preceded by authentication failures (user.authentication.auth_via_mfa) or abandoned push challenges. Audit UAL Telemetry for Direct Stream Exfiltration: Configure Security Operations Center (SOC) detection pipelines to treat FileAccessed events with the same criticality as FileDownloaded when the UserAgent string identifies a scripting library (python-requests, WindowsPowerShell, Go-http-client) or when the access volume exceeds normal human browsing thresholds. Restrict and Alert on Residential Proxy Authentication: Create conditional access policies and anomaly alerts for SSO authentication attempts originating from commercial VPN providers (Mullvad, Private Layer) or unassociated residential broadband proxy pools (AT&T, Comcast, Charter) that diverge from established employee geographic baselines. Outlook and Implications The activity associated with UNC6671 highlights the fluidity of threat actor brands relative to persistent tactics, techniques, and procedures. While the extortion brands associated with this activity continue to multiply, the tradecraft across these operations remains anchored in helpdesk vishing, AiTM session interception, and SaaS exfiltration. We believe that this most likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout. This assessment is supported by the tight infrastructure overlaps, shared vishing panel deployments, and overlaps in victim targeting observed across BlackFile, Redact, Pink, Helix, and Falcon. However, there are several other scenarios that could explain the broader dynamics across these brands: Actor Splintering: Internal rifts, financial disputes, or operational security compromises routinely lead to group fragmentation. Former affiliates or splinter cells retaining access to shared initial access playbooks, panel code, and target lists can easily establish independent extortion fronts while continuing to execute identical TTPs. Shared Ecosystem and Panel use: Separate threat groups may simply be leveraging the same commoditized phishing panels, voice-phishing callers, and shared infrastructure. As these AiTM panels and VaaS services become widely available, distinct threat actors can deploy matching infrastructure and pretexts without requiring direct organizational alignment. Outsourced Extortion: The intrusion operators driving initial access and cloud data exfiltration could remain the same core group of actors, while the extortion and negotiation phases are outsourced to different actors. Regardless of whether this activity reflects a fractured threat group, outsourced extortion negotiators, or a broader affiliate network, the initial infection vector leveraged and goals of these campaigns is consistent. Organizations should prioritize phishing-resistant authenticators and behavioral SaaS auditing to disrupt these identity-centric attacks. Indicators of Compromise (IOCs) To assist the wider community in hunting and identifying activity outlined in this blog post, we have provided indicators of compromise (IOCs) in a free GTI Collection for registered users. At the time of publication, identified phishing domains have been added to Google Safe Browsing. While this collection provides a comprehensive list of IOCs, defenders should note that the majority of identified IP addresses are commercial VPN nodes, and actual source IPs tend to vary as the actor continuously cycles through new infrastructure. Furthermore, the domains are often stood up and used within minutes of registration; as such, they are provided primarily as examples of past naming conventions and usage patterns rather than as a primary mechanism for real-time blocking. Domain Creation Date Registrar Name Servers Targeted Industry myoktasso[.]com 2026-04-04 TUCOWS.COM, CO. Njalla / Pipe.ma Financial Services, Transportation mypasskeysso[.]com 2026-04-04 TUCOWS.COM, CO. Cloudflare Healthcare setupssopasskey[.]com 2026-04-07 TUCOWS.COM, CO. Cloudflare Financial Services, Healthcare, Media & Entertainment mspasskey[.]com 2026-04-08 TUCOWS.COM, CO. Cloudflare Real Estate, Healthcare, Technology activatepasskey[.]com 2026-04-10 TUCOWS.COM, CO. Cloudflare Financial Services, Hospitality, Healthcare enrollpasskey[.]com 2026-04-10 TUCOWS.COM, CO. Cloudflare Financial Services, Energy, Healthcare keyokta[.]com 2026-04-13 TUCOWS.COM, CO. Cloudflare Healthcare, Financial Services oktaenroll[.]com 2026-04-13 TUCOWS.COM, CO. Cloudflare Healthcare, Construction & Engineering oktaportalsso[.]com 2026-04-16 TUCOWS.COM, CO. Cloudflare Retail & Consumer Goods, Healthcare, Legal passkeyportal[.]com 2026-04-16 TUCOWS.COM, CO. Cloudflare N/A portalpasskey[.]com 2026-04-16 TUCOWS.COM, CO. Cloudflare Transportation passkeyportalsetup[.]com 2026-04-20 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services, Technology addoktapasskey[.]com 2026-04-21 NICENIC INTERNATIONAL GROUP CO., LIMITED Private Layer (31.7.56.61) Financial Services, Technology, Media & Entertainment deploypasskey[.]com 2026-04-21 TUCOWS.COM, CO. DDOS-GUARD Retail & Consumer Goods passkeydeploy[.]com 2026-04-23 Internet Domain Service BS Corp. DDOS-GUARD Healthcare, Technology activatemypasskey[.]com 2026-04-24 TUCOWS.COM, CO. Cloudflare Financial Services registerpasskey[.]com 2026-04-29 NICENIC INTERNATIONAL GROUP CO., LIMITED MEVSPACE (193.34.212.132) Manufacturing createpasskey[.]com 2026-05-03 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare N/A passkeyadd[.]com 2026-05-08 TUCOWS.COM, CO. DDOS-GUARD Business Services, Technology passkeyregister[.]com 2026-05-08 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / MEVSPACE Energy, Technology, Healthcare passkeycenter[.]com 2026-05-11 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Legal, Financial Services, Healthcare secureauthpasskey[.]com 2026-05-14 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Healthcare passkeyrollout[.]com 2026-05-18 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / MEVSPACE Non-Corporate, Insurance, Legal setpasskey[.]com 2026-05-22 Internet Domain Service BS Corp. DDOS-GUARD Technology, Business Services, Construction & Engineering passkeyokta[.]com 2026-05-26 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Media & Entertainment, Transportation passkeyset[.]com 2026-05-27 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Transportation createmypasskey[.]com 2026-05-27 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Construction & Engineering newpasskey[.]com 2026-05-28 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Media & Entertainment passkeysupport[.]com 2026-05-29 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Healthcare, Technology, Legal, Retail & Consumer Goods sqfepjvmrd[.]xyz 2026-06-01 NICENIC INTERNATIONAL GROUP CO., LIMITED MY-NDNS N/A passkeyregistration[.]com 2026-06-02 PDR Ltd. d/b/a .com Suspended-Domain N/A addmypasskey[.]com 2026-06-03 TUCOWS.COM, CO. Private Layer (31.7.56.52) Financial Services, Healthcare, Transportation passkey-setup[.]com 2026-06-03 Tucows Domains Inc. Cloudflare Legal, Financial Services passkey-portal[.]com 2026-06-05 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Retail & Consumer Goods, Technology, Media & Entertainment startpasskeysetup[.]com 2026-06-05 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Technology, Healthcare, Retail & Consumer Goods, Construction & Engineering, Media & Entertainment, Financial Services passkey-connect[.]com 2026-06-05 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Technology portalsetuphub[.]com 2026-06-10 PDR Ltd. d/b/a .com Suspended-Domain Financial Services, Healthcare, Energy, Real Estate, Technology, Construction & Engineering [.]com 2026-06-12 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Technology, Energy assignpasskey[.]com 2026-06-13 Internet Domain Service BS Corp. DDOS-GUARD Construction & Engineering, Financial Services, Energy myconnectkey[.]com 2026-06-13 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Transportation, Financial Services, Construction & Engineering, Real Estate, Business Services, Retail & Consumer Goods, Healthcare mynewpasskey[.]com 2026-06-13 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Retail & Consumer Goods, Healthcare, Financial Services, Energy passkeycreate[.]com 2026-06-16 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Construction & Engineering, Financial Services, Retail & Consumer Goods, Legal, Energy oskeyconnect[.]com 2026-06-17 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services, Real Estate, Legal, Healthcare, Transportation, Utilities, Construction & Engineering, Retail & Consumer Goods, Hospitality passkeycreator[.]com 2026-06-19 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Non-Corporate, Media & Entertainment, Legal, Healthcare, Energy, Technology oskeysync[.]com 2026-06-20 NICENIC INTERNATIONAL GROUP CO., LIMITED EZYDOMAIN Healthcare, Financial Services, Transportation, Real Estate, Technology, Construction & Engineering, Retail & Consumer Goods, Legal, Energy, Utilities, Hospitality enablepasskey[.]com 2026-06-22 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Legal enablepasskey2fa[.]com 2026-06-22 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Healthcare, Media & Entertainment checkpasskey[.]com 2026-06-22 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Legal, Construction & Engineering, Retail & Consumer Goods, Transportation passkeyuser[.]com 2026-06-25 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Construction & Engineering, Legal, Aerospace & Defense, Financial Services, Technology keysyncos[.]com 2026-06-30 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services, Real Estate, Healthcare, Technology, Construction & Engineering, Transportation, Legal, Retail & Consumer Goods, Energy, Utilities, Hospitality myaccountsecurity[.]com 2026-06-30 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Construction & Engineering addpasskey2fa[.]com 2026-07-01 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Financial Services, Legal passkeyenroll[.]com 2026-07-07 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services startpasskey[.]com 2026-07-07 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Construction & Engineering, Retail & Consumer Goods passkeyenable[.]com 2026-07-08 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services, Legal passkeyactivation[.]com 2026-07-09 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services createmfa[.]com 2026-07-09 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Construction & Engineering, Energy, Financial Services, Healthcare, Transportation passkeyhelpdesk[.]com 2026-07-10 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Financial Services, Energy, Healthcare makepasskey[.]com 2026-07-13 Internet Domain Service BS Corp. DDOS-GUARD N/A add-passkey[.]com 2026-07-13 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Healthcare, Energy passkey-check[.]com 2026-07-13 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services, Media & Entertainment addyourpasskey[.]com 2026-07-20 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services, Utilities passkey-enable[.]com 2026-07-20 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Aerospace & Defense, Technology mypasskeyid[.]com 2026-07-21 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Technology, Retail & Consumer Goods passkeystatus[.]com 2026-07-21 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Energy, Technology secure-passkey[.]com 2026-07-21 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Energy, Financial Services addssopasskey[.]com 2026-07-22 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Financial Services ssopasskey[.]com 2026-07-22 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare N/A createssopasskey[.]com 2026-07-28 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Financial Services myssopasskey[.]com 2026-07-31 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services hubpasskey[.]com 2026-08-03 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services passkeymfa[.]com 2026-08-03 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services Table 1: Indicators of compromise Network Infrastructure and Exfiltration Observables IP Address Role ASN 31.7.56.61 Panel AiTM Reverse Proxy AS51852 Private Layer INC (Switzerland) 31.7.56.52 Panel AiTM Reverse Proxy AS51852 Private Layer INC (Switzerland) 193.34.212.132 Phishing Kit Backend Proxy AS201814 MEVSPACE (Poland) 185.178.208.153 Phishing Reverse Proxy AS57724 DDOS-GUARD LTD (Russia) 23.234.75.84 Automated SaaS Data Exfiltration AS11878 Tzulo, Inc. (United States) 195.140.213.114 Automated SaaS Data Exfiltration AS25369 Hydra Communications Ltd (United Kingdom) 195.140.213.115 Automated SaaS Data Exfiltration AS25369 Hydra Communications Ltd (United Kingdom) 107.128.45.122 M365 / Okta Residential Proxy AS7018 AT&T Enterprises, LLC (United States) 76.103.148.180 M365 / Okta Residential Proxy AS7922 Comcast Cable Communications (United States) 38.42.59.171 M365 / Okta Residential Proxy AS395354 Starry, Inc. (United States) 47.218.103.146 M365 / Okta Residential Proxy AS19108 Optimum / Suddenlink (United States) Table 2: Network infrastructure and exfiltration observables Scripting and SDK User-Agent Strings python-requests/2.28.1 WindowsPowerShell/5.1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:146.0) Gecko/20100101 Firefox/146.0 0811A9866E.com.okta.android.auth/8.18.0 DeviceSDK/1.0.94 Android/16 Google/Pixel_9_Pro_XL Figure 6: Scripting and SDK user-agent strings Google Security Operations (SecOps) Detections Google SecOps customers have access to automated detection rules under the Okta and Microsoft 365 rule packs that identify the vishing, MFA modification, and programmatic streaming activity described in this report: Okta Admin Console Access Failure Okta Suspicious Actions from Anonymized IP Okta MFA Factor Setup Following Abandoned Challenge O365 SharePoint Bulk File Access or Download via PowerShell O365 SharePoint High Volume File Access Events O365 SharePoint Query for Proprietary or Privileged Information Okta User Authentication with Suspicious Behavioral Flags Acknowledgements Special thanks to researcher ZachXBT for assisting with cryptocurrency analysis.

Read original article

Anthropic

August 6, 2026

Anthropic Enters The AI Chip Race With In-House Chip Team

Anthropic launches an in-house chip team as labs push custom silicon to cut token costs, even while expanding massive TPU commitments with Google and Broadcom.

Read original article

Claude

August 6, 2026

Qwen3.8 Max catches Claude Opus 4.8 but Kimi K3 still scores higher for 25 percent less

Alibaba's Qwen3.8 Max scores 56 on the Artificial Analysis Intelligence Index, a 10-point jump over Qwen3.7 Max (46). The article Qwen3.8 Max catches Claude Opus 4.8 but Kimi K3 still scores higher for 25 percent less appeared first on The Decoder.

Read original article

Google

August 6, 2026

Exclusive: Mirendil inks $100 M+ Google Cloud deal to scale self-improving AI

Mirendil has signed a $100 million-plus Google Cloud partnership to expand its compute infrastructure, powering research into self-improving AI systems designed to accelerate scientific discovery and AI development.

Read original article

Databricks

August 6, 2026

Big Query to Databricks: A Strategic Framework for Modern Migration

Migration as a strategic evolutionBigQuery is often the standard for starting fast, but for many enterprises...

Read original article

Google

August 6, 2026

Mirendil taps AI Hypercomputer TPUs and GPUs for pre- and post-training applications

Nearly every major AI lab uses Google Cloud infrastructure, including for training of models, inference for agents, and new frontier research. Google Cloud also continues to be the platform of choice for new, high-growth AI startups who are driving much of the industry’s research and innovation. Today, we’re announcing that Mirendil, an exciting frontier AI lab focused on accelerating AI development, will also utilize Google Cloud’s AI Hypercomputer. This includes using a mix of Google’s TPU AI accelerators and full-stack NVIDIA AI infrastructure running on Google Cloud; this purpose-built AI infrastructure will support model pre-training and post-training applications for Mirendil. The Mirendil team is building new AI systems that can help accelerate and democratize AI research and development. This means managing complex, end-to-end training workflows from initial model pre-training through post-training, and powering reinforcement learning on a massive scale. The ability to choose a mix of both TPU and NVIDIA’s full-stack accelerated computing platform through Google Cloud meant that Mirendil could access critical compute very quickly, and continue to match its workloads to the architecture best-suited to it over time. We closely partnered with Mirendil on end-to-end design and deployment of combined TPU and NVIDIA AI infrastructure across compute, storage, networking, and control planes. We also collaborated on a system that uses managed training clusters running in Gemini Enterprise Agent Platform, which effectively streamlines the provisioning and management of both TPU and GPU environments for Mirendil. Mirendil is already live with a cluster of TPU v5P chips, with NVIDIA AI accelerated computing systems coming online soon. "Progress in AI has been bounded by how fast humans can run the research loop - designing experiments, evaluating results, and iterating," said Behnam Neyshabur, cofounder and CEO of Mirendil. "We're building AI systems that can accelerate and improve that loop itself. Expanding on Google Cloud gives us the scale and flexibility to push those systems further and put frontier AI research capabilities in the hands of many more scientists and engineers to run that loop faster and at a greater scale." You can read more about our partnership on Mirendil’s blog.

Read original article

Meta

August 6, 2026

The company that made open weights mainstream now competes on discounts

Meta released Muse Spark 1.2 along with its own coding agent, Muse Code, which is designed to pick up exactly where it left off after a crash. The cheapest tier runs just 20 cents per million output tokens but requires users to share their data for training. Meta is competing on price, not top-end performance. And there's a glaring gap in the benchmarks. The article The company that made open weights mainstream now competes on discounts appeared first on The Decoder.

Read original article

Google

August 6, 2026

Google Maps adds agentic features, including food ordering and hotel bookings

The launch of these new features reflects Google’s ambitions to transform Google Maps from a navigation tool into an assistant that's capable of helping users complete real-world tasks.

Read original article

OpenAI

August 6, 2026

Open AI reportedly slows research after its own models secretly coordinated hacks for weeks undetected

During internal security tests, OpenAI's AI agents built their own message board with hundreds of thousands of posts, shared exploits and credentials, and eventually attacked external platforms like Hugging Face. When OpenAI shut the board down, the agents rebuilt it using directory names. OpenAI researcher Boaz Barak says, "We (like everyone else) are not where we want and need to be." The article OpenAI reportedly slows research after its own models secretly coordinated hacks for weeks undetected appeared first on The Decoder.

Read original article

OpenAI

August 6, 2026

Open AI developer warns the "tireless eagle eyes of a million models" are coming for your exposed API keys and crypto wallets

OpenAI developer "roon" warns on X that AI models could soon start scanning for exposed API keys, crypto wallets, and login credentials at scale. His warning follows OpenAI's autonomous Hugging Face hack, which he called a "warning shot." The article OpenAI developer warns the "tireless eagle eyes of a million models" are coming for your exposed API keys and crypto wallets appeared first on The Decoder.

Read original article

OpenAI

August 6, 2026

Improving GPT‑5.6 Sol in Chat GPT—and expanding access to GPT-5.6 Luna for free users

ChatGPT introduces improved GPT-5.6 Sol with better accuracy and consistency, plus expanded access for free users and unlimited everyday chats with GPT-5.6 Luna.

Read original article

Google

August 6, 2026

Google is expanding its AI empire — and losing the people who built it - CNBC

Google is expanding its AI empire — and losing the people who built it CNBC

Read original article

OpenAI

August 6, 2026

Working with the American Psychological Association on youth mental health and AI

OpenAI and the American Psychological Association advance evidence-based guidance, resources, and safeguards for responsible AI use and youth mental health.

Read original article

Nvidia

August 6, 2026

An Explainable LLM Agent Layer for Open-World Anomaly Detection in Oil Wells

arXiv:2608.04041v1 Announce Type: new Abstract: Open-World Learning (OWL) pipelines for oil well anomaly detection have recently been shown to combine autoencoder-based detection, multiclass classification, and Mahalanobis-based novelty detection on the public 3W dataset. These pipelines answer \textit{what happened}, but they do not explain \textit{why the model believes it} or \textit{what the operator should do next}, and they do not put a human-readable name on the novelty clusters they discover. This paper evaluates a Large Language Model (LLM) agent layer placed downstream of the OWL pipeline, designed as a \textbf{companion} to the published upstream methods rather than a replacement. Using the Qwen3.5-397B-A17B Mixture-of-Experts model served via NVIDIA NIM, the agent receives structured sensor metrics and upstream classification or novelty assertions, and returns natural-language justifications, confidence-ranked critiques, and consolidated names for detected novelties. Across three studies spanning 989 real well-file segments from the 3W dataset, the agent achieved $35.1\%$ top-1 / $63.9\%$ top-3 (95\% CI [56.9, 70.4]) classification on all nine classes, $71.7\%$ top-2 validation [64.8, 77.6] with precision $0.91$ [0.84, 0.95] across 7 probed classes, and $89.7\%$ novelty detection [87.0, 91.9] with stable cluster naming on 5 of 7 hidden classes. The agent is not a standalone classifier. Its role is to: (1) confirm upstream decisions when sensor evidence supports them, (2) justify decisions in sensor-grounded language operators can audit, (3) flag disagreement when upstream labels are implausible, and (4) name novelties so that clustered unlabeled events arrive at the engineer with a consolidated human-readable label. The goal is to close the explainability gap that currently blocks deployment of OWL pipelines in operational settings.

Read original article

Claude

August 6, 2026

Matr AIx: Simulating the World with 8.3 Billion Persona Agents

arXiv:2608.04205v1 Announce Type: new Abstract: Human evaluation of AI systems and digital products is costly, slow, and difficult to scale. Offline evaluations are more scalable but often abstract away human diversity and interactive behavior. We therefore introduce MatrAIx, a population-scale simulated-user evaluation infrastructure for testing AI systems and digital products with heterogeneous users. MatrAIx has three core components: First, Persona 8B contains 8.3 billion persona records represented by 1,290 categorical dimensions. Records are either sampled from a dependency graph that preserves correlated attributes or derived from human-authored profiles. We release a quality-filtered coreset of approximately 1 million personas, comprising 599,847 human-grounded and 400,000 synthetic records. Second, the MatrAIx Playground provides four environments in which diverse users evaluate and interact with digital products: Survey, AI Chatbot, Web, and App. Third, MatrAIx provides 1,010 application tasks spanning more than 25 domains, including Commerce, Software, Finance, and Healthcare. We conducted 18,189 evaluation trials across eight representative tasks. Persona agents were powered by three LLMs: Claude Opus 4.8, GPT 5.5, and Claude Haiku 4.5. The resulting feedback captures how decisions and preferences vary across persona backgrounds, including hesitation after a price increase, willingness to continue after an AI assistant fails, and latency tolerance. We conducted two main validation studies: First, a 400-trial controlled study evaluated persona adherence across ten behavioral attributes and all four environments. The declared behavior was expressed or correctly suppressed in 366 trials (91.5%). Second, human and LLM judges evaluated the extraction quality of human-grounded personas. Overall, MatrAIx provides an end-to-end infrastructure for evaluating AI systems and digital products with diverse simulated human users.

Read original article

Google

August 6, 2026

The RAIL Principles for Neurosymbolic AI: Reasoning, Assurances, Interfacing and Learning

arXiv:2608.04285v1 Announce Type: new Abstract: Neurosymbolic AI systems that integrate machine learning and symbolic reasoning are rapidly gaining attention. They complement the data-intensive statistical approaches of neural networks and language models with symbolic reasoning algorithms to function in high-stakes domains or in low-data regimes that characterize many real-world applications. We argue that the neurosymbolic combination of machine learning and formal reasoning is not a niche approach within AI, but rather includes many already successful techniques that are of crucial importance to the development of reliable, efficient and, ultimately, trustworthy systems. This perspective prompts a re-examination of the design of current AI systems. We show that many leading AI systems, including some that are not traditionally considered as neurosymbolic, can be analysed from the perspective of four principles of neurosymbolic AI design: Reasoning, Assurances, Interfacing and Learning (RAIL). Applying the RAIL framework offers a unified view of seemingly disparate AI systems, ranging from physics-aware machine learning to neuro-guided search (such as Google DeepMind's Alpha-* suite), causal learning and tool-augmented Large Language Models. Importantly, the RAIL principles will enable engineers to make better-informed and more principled decisions about the design and deployment of production-level AI systems. In this article, we introduce the RAIL principles, examine how they can be applied across major areas of AI, and illustrate how they may guide practitioners to integrate neurosymbolic methods into next-generation AI technologies.

Read original article

Microsoft

August 6, 2026

Architectural Implications of Agentic AI Workflows

arXiv:2608.04458v1 Announce Type: new Abstract: Agentic AI is emerging in datacenters, but its architectural implications remain unexplored. We organize agentic workflows in a taxonomy and present its first architectural characterization with a production study at Microsoft Azure and a controlled study of open-source frameworks. We show that agentic execution is fragmented and heterogeneous. Requests expand into a workflow of LLM inferences, tool invocations, and orchestration decisions that repeatedly cross the CPU-GPU boundary. Our taxonomy explains how this fragmentation turns into resource demand. As orchestration and tools run on the host, the CPU sits on the critical path. Execution structure sets the load over time, which stays low with sudden spikes. Model composition sets how evenly the workflow uses the GPUs. Diversity in tasks and tools widens this range even further. These characteristics expose architectural mismatches of conventional uniform servers. Fragmented execution strands CPU and GPU capacity despite bursty demand. Different software roles make homogeneous CPU provisioning inefficient. Finally, multiplexing many agents onto shared cores degrades microarchitectural locality. Guided by our findings, we derive implications for agentic servers and examine them through Agora, our prototype for commodity servers. Agora dynamically harvests idle CPU cores for co-located throughput work, while protecting agentic tail latency against tool spikes. It oversubscribes GPU memory by placing more agents on each GPU, prefetching the next agent's state to hide swap latency. To match the machine to the heterogeneous roles, Agora pools cores by role and applies affinity-aware scheduling to restore locality. It automatically tunes mechanisms to the workload. Agora improves utilization and server throughput while preserving agent tail latency. Our insights also identify key directions for future server architectures for agentic AI.

Read original article

Claude

August 6, 2026

LUCid: Redefining Relevance For Lifelong Personalization

arXiv:2604.26996v2 Announce Type: replace Abstract: Work to date has mainly relied on semantic proximity to identify relevant content for lifelong personalization. However, situational relevance is often more important for determining which information is useful for a user's actual task and context. In this paper, we introduce the Proximity Advantage (PA) score, a metric for quantifying semantic proximity bias, and show that existing personalization benchmarks largely conflate semantic and situational proximity, leaving it unclear whether current systems truly capture situational relevance. To support this metric, we introduce LUCid, a diagnostic benchmark of 1,936 user queries paired with long interaction histories, designed to isolate situational relevance from semantic proximity. Our experiments across different stages of the modern personalization pipeline (retrieval, reranking, and generation) reveal significant performance collapse: retrieval recall drops to near zero on the hardest instances, and response alignment remains near 50\% even for state-of-the-art models such as Gemini-3-Flash, GPT-5.4, and Claude Haiku, highlighting a fundamental mismatch between the relevance encoded by current systems and what lifelong personalization demands.

Read original article

OpenAI

August 6, 2026

Document Optimization for Black-Box Retrieval via Reinforcement Learning

arXiv:2604.05087v3 Announce Type: replace-cross Abstract: Document expansion is a classical technique for improving retrieval quality, and is attractive since it shifts computation offline, avoiding additional query-time processing. However, when applied to modern retrievers, it has been shown to degrade performance, often introducing noise that obfuscates the discriminative signal. We recast document expansion as a document optimization problem: a language model or a vision language model is fine-tuned to transform documents into representations that better align with the expected query distribution under a target retriever, using GRPO with the retriever's ranking improvements as rewards. This approach requires only black-box access to retrieval ranks, and is applicable across single-vector, multi-vector and lexical retrievers. We evaluate our approach on code retrieval and visual document retrieval (VDR) tasks. We find that learned document transformations yield retrieval gains and in many settings enable smaller, more efficient retrievers to outperform larger ones. For example, applying document optimization to OpenAI text-embedding-3-small model improves nDCG5 on code (58.7 to 66.8) and VDR (53.3 to 57.6), even slightly surpassing the 6.5X more expensive OpenAI text-embedding-3-large model (66.3 on code; 57.0 on VDR). When retriever weights are accessible, document optimization is often competitive with fine-tuning, and in some settings their combination performs best, improving Jina-ColBERT-V2 from 55.8 to 63.3 on VDR and from 48.6 to 61.8 on code retrieval.

Read original article

Meta

August 6, 2026

Meta says its AI model breached a third-party company during testing - CBS News

Meta says its AI model breached a third-party company during testing CBS News

Read original article

Microsoft

August 6, 2026

Microsoft’s Skill Opt Shows Optimized Agent Skill Artifacts Transfer Across Model Scales and Between Codex and Claude Code Harnesses

Most coverage of Microsoft's SkillOpt centers on its 52/52 result. The more consequential finding is in Section 4.3: the exported best_skill.md keeps working in environments it was never trained on. A Codex-trained SpreadsheetBench skill lifted Claude Code from 22.1 to 81.8, slightly above the 80.4 that harness reached training its own skill. Retention varies sharply by task type — 102% on spreadsheets, 10% on math — which is what makes the result worth reading closely. The post Microsoft’s SkillOpt Shows Optimized Agent Skill Artifacts Transfer Across Model Scales and Between Codex and Claude Code Harnesses appeared first on MarkTechPost.

Read original article

OpenAI

August 6, 2026

Open AI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree

At the Black Hat security conference, the AI giant revealed new details about how its agents went rogue, hacked several other companies—and did it all right under the company’s nose.

Read original article

OpenAI

August 6, 2026

From asking to doing: How the world is putting Chat GPT to work

New OpenAI Signals data shows how people use ChatGPT worldwide, with country-level insights on adoption, usage trends, and evolving behavior.

Read original article

OpenAI

August 5, 2026

Open AI’s Browser Could Be Hijacked to Spam Your Whats App Contacts

Researchers at security firm Zenity found more than a dozen flaws in AI browsers—and managed to get OpenAI’s Atlas to make an unauthorized Amazon purchase.

Read original article

Google

August 5, 2026

Big shake-up in Google’s AI team as Deep Mind chief executive steps down - The Guardian

Big shake-up in Google’s AI team as DeepMind chief executive steps down The Guardian

Read original article

Google

August 5, 2026

End-to-End Bayesian Marketing Mix Modeling with Google Meridian: Media Measurement, ROI Analysis, and Budget Optimization

In this tutorial, we build a complete Bayesian marketing mix modeling workflow using Google Meridian. We begin by installing the required libraries, verifying GPU availability, and exploring a geo-level marketing dataset that includes media impressions, spend, controls, promotions, conversions, population, and revenue. We then map the raw columns to Meridian’s data schema, define interpretable ROI-based […] The post End-to-End Bayesian Marketing Mix Modeling with Google Meridian: Media Measurement, ROI Analysis, and Budget Optimization appeared first on MarkTechPost.

Read original article