BTC $78,561.06 -0.45%
ETH $2,488.63 +0.31%
BNB $754.20 +2.27%
XRP $1.42 +2.07%
SOL $103.37 -0.17%
TRX $0.3386 +1.32%
DOGE $0.0898 -0.24%
ADA $0.2205 +1.01%
BCH $258.67 +0.81%
LINK $12.53 -1.31%
HYPE $84.86 -0.20%
AAVE $129.25 -1.49%
SUI $0.8129 +0.08%
XLM $0.1882 -1.61%
ZEC $1,177.70 +4.12%
BTC $78,561.06 -0.45%
ETH $2,488.63 +0.31%
BNB $754.20 +2.27%
XRP $1.42 +2.07%
SOL $103.37 -0.17%
TRX $0.3386 +1.32%
DOGE $0.0898 -0.24%
ADA $0.2205 +1.01%
BCH $258.67 +0.81%
LINK $12.53 -1.31%
HYPE $84.86 -0.20%
AAVE $129.25 -1.49%
SUI $0.8129 +0.08%
XLM $0.1882 -1.61%
ZEC $1,177.70 +4.12%

agency

All
Article
Flash

first_img Zuckerberg told Trump that the concept of a national AI regulatory agency is flawed

Meta CEO Mark Zuckerberg expressed concerns about the plan to establish a national AI regulatory agency during a phone call with U.S. President Donald Trump last month. The proposal, advocated by Google DeepMind scientist Demis Hassabis and supported by some White House officials, aims to create an independent organization similar to FINRA to review and test potential risks before the broader deployment of advanced AI models. White House officials previewed the proposal to Trump and major tech companies, including Meta, in mid-August.Trump spoke with Zuckerberg during the week of August 17. According to senior White House officials familiar with the conversation, Zuckerberg opposed the proposal. Another informed source indicated that Zuckerberg did not ask Trump to change his position but told him that the personnel of the regulatory agency the White House might appoint should reflect Trump's light-touch approach to AI, noting that Trump made the call first. The conversation did not kill the idea, which is still under consideration. A Meta spokesperson declined to comment. A White House spokesperson stated that the Trump administration is committed to balancing innovation and safety in AI policymaking.In an article in August, Zuckerberg expressed skepticism about strict government regulation of new AI models, arguing that any policy that delays the release of models by even a month would pose significant risks to the U.S. leadership position relative to China. The government is considering a FINRA-like regulatory agency or a voluntary industry organization similar to the Motion Picture Association of America. Trump's former AI and crypto czar, David Sachs, opposed government regulatory agencies, calling them "the DMV of AI." Anthropic co-founder Jack Clark expressed support for the FINRA-like idea in a post in July.

SemiAnalysis releases Neocloud security deep report: Infrastructure configuration errors are shocking, and cross-tenant RCE could affect banks, telecommunications, and even a country's intelligence agency

The semiconductor and AI independent research organization SemiAnalysis released a deep security report on Neocloud (new cloud), revealing various cross-tenant security vulnerabilities discovered during the ClusterMAX 3 testing period. In a four-month test covering 25 vendors and 32 clusters, the team achieved multiple instances of cross-tenant remote code execution (RCE) solely by exploiting publicly known vulnerabilities and basic configuration checks. Affected entities included banks, telecommunications companies, universities, research institutions, AI laboratories, and even a national intelligence agency.Typical issues included: shared Kubernetes control plane leading to tenant metadata visibility, container escape, exposure of BMC/IPMI management networks, incorrect configuration of InfiniBand security keys (P_Key, SA_Key, M_Key), unfortified default trust mode of BlueField DPU, Grafana monitoring dashboards using god-level API keys, and lack of VXLAN isolation in front-end networks. The report specifically pointed out a cascading vulnerability case: a misconfiguration of shared vCluster combined with software versions being two years out of date ultimately completed the POC verification of cross-tenant RCE within an afternoon.Notably, the report questioned the mainstream narrative that "AI has fundamentally changed the pace of cybersecurity": statistics on CVEs for NVIDIA GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel showed that there was no significant increase in vulnerabilities after the popularization of AI coding models, with most data supporting the "no change hypothesis." The report also detailed the incident where an OpenAI-trained agent attacked Hugging Face, where the AI agent achieved cluster-level privilege escalation through a message board established via Artifactory, which went undetected from May to July. While building POC verification for existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently rejected security-related requests, ultimately relying on open-source models such as DeepSeek V4, Kimi K3, and GLM-5.2 to complete the task.SemiAnalysis stated that the core issue in the Neocloud (new cloud) industry is not the new risks brought by AI, but rather the long-term absence of basic patch management, tenant isolation, and security design. They recommended that vendors establish automated security announcement monitoring systems and rectify single points of failure that could expose all users' architectural patterns.

SafePal updates on security incident progress: launching anti-phishing actions and will commission a third-party agency to review the order system

The cryptocurrency wallet project SafePal has released updates on the security incident, stating that it is continuously tracking phishing websites and impersonation accounts, and plans to introduce a professional anti-phishing security company to expedite the removal of malicious information to protect user asset security. SafePal mentioned that it is currently in the final selection process among four professional anti-phishing security companies, and once a partner is selected, it will further enhance the efficiency of handling threats such as counterfeit websites and scam accounts.The team is also continuously monitoring whether the affected data has been sold or made public, including channels such as dark web forums and trading markets. Once signs of data leakage are detected, affected users will receive risk alerts immediately. Regarding security audits, SafePal stated that it is in the final selection among three mature independent security institutions, which will conduct a comprehensive security review of the order system. Meanwhile, the team is reassessing the order and logistics processes to reduce the amount of data that needs to be stored in the initial phase of the system, thereby reducing potential risks from the source.For affected users, SafePal stated that it will continue to provide one-on-one assistance through official support channels and will keep updating the fraud protection page, providing updates on the incident, FAQs, and analysis of fraud cases. SafePal once again reminds users: the official will never ask users to provide their seed phrase. Users should not disclose their seed phrase to anyone, should not scan unknown QR codes or click on suspicious links, and should verify the source of information through official channels.

The Financial Services Agency of Japan and the National Police Agency jointly requested cryptocurrency exchanges to strengthen anti-fraud measures

According to CoinPost, the Financial Services Agency of Japan and the National Police Agency recently jointly sent a letter to the Japan Virtual Currency Exchange Association (JVCEA), requesting exchanges to strengthen anti-fraud measures. This request includes 11 specific requirements, such as the need for withdrawal addresses to be registered in advance, enhanced transaction monitoring, strict verification of identification documents when opening accounts, and setting a withdrawal limit for a certain period after users deposit fiat currency or purchase crypto assets.The background of this action is the increasing prevalence of investment scams and "pig butchering" schemes on social media, where criminals frequently use crypto accounts to transfer illegal funds. The Financial Services Agency also suggested that exchanges flexibly set withdrawal limits based on customers' risk levels and transaction purposes, and that suspicious transactions should immediately result in account restrictions or freezes, while enhancing intelligence cooperation with the police. For system renovations that are difficult to implement in the short term, exchanges are allowed to proceed in phases. In addition, the Financial Services Agency has officially established the "Cryptocurrency and Stablecoin Division," responsible for related regulatory affairs.
app_icon
ChainCatcher Building the Web3 world with innovations.