BTC $79,608.83 -0.27%
ETH $2,507.27 +0.59%
BNB $747.17 -0.58%
XRP $1.41 -0.18%
SOL $105.69 -0.31%
TRX $0.3355 +0.09%
DOGE $0.0916 +2.56%
ADA $0.2241 +2.72%
BCH $261.68 +1.30%
LINK $13.25 +7.94%
HYPE $87.96 -0.72%
AAVE $134.66 -0.06%
SUI $0.8318 +4.61%
XLM $0.1940 +4.52%
ZEC $1,187.41 +0.07%
BTC $79,608.83 -0.27%
ETH $2,507.27 +0.59%
BNB $747.17 -0.58%
XRP $1.41 -0.18%
SOL $105.69 -0.31%
TRX $0.3355 +0.09%
DOGE $0.0916 +2.56%
ADA $0.2241 +2.72%
BCH $261.68 +1.30%
LINK $13.25 +7.94%
HYPE $87.96 -0.72%
AAVE $134.66 -0.06%
SUI $0.8318 +4.61%
XLM $0.1940 +4.52%
ZEC $1,187.41 +0.07%

comm

All
Article
Flash

first_img Anthropic launches the Claude e-commerce intelligent agent blueprint

Anthropic announced the launch of a blueprint for building e-commerce agents on Claude, providing the framework, patterns, and guardrails needed by engineering teams. It includes reference implementations for shopping agents and merchant agents aimed at retail, travel, telecommunications, and ticketing platforms, as well as the Claude Code plugin. The code can be deployed on Claude API, Amazon Bedrock, Microsoft Foundry, or Google Cloud Vertex AI, and can collaborate with partners such as Accenture, Mastercard, and Visa. The related code has been published in the GitHub repository anthropics/commerce-agents.The company stated that retailers running shopping agents on Claude can increase shopping cart sizes by up to 35%, and the likelihood of shoppers completing purchases improves by 60%. Business clients such as Shopify and Priceline have used Claude to build agents that allow consumers to search, compare, and purchase products using natural language. Shopping agents can interface with catalogs, shopping carts, checkout, preferences, and order history, supporting multi-product planning, personalization, and customer service Q&A, while constraining prices and products with catalog data; merchant agents can answer sales performance, track inventory, suggest pricing and promotions, and draft marketing campaigns, proactively suggesting items to be launched after manual approval.

first_img G20 finance ministers commit to establishing a clear path for digital asset innovation

After a two-day meeting in Asheville, North Carolina, G20 finance ministers and central bank governors issued a statement committing to developing clearer rules for digital assets to promote financial innovation. The statement acknowledges that digital financial innovations, including digital assets, can support "broad economic growth" and play a key role in driving private sector innovation.The statement reads: "We are committed to advancing a responsible and effective regulatory and supervisory framework to maintain financial stability, support economic growth, and establish a clear path for sound digital finance and digital asset innovation, while taking into account cross-border opportunities and challenges." G20 officials expressed anticipation for the upcoming findings from the Financial Stability Board regarding the cross-border impacts of global stablecoin arrangements, as well as related reports on stablecoin data sources, availability, and potential challenges.They also reiterated their commitment to strengthening the G20 roadmap for cross-border payments and called on member countries to extend the operating hours of large payment systems. Several G20 member countries, including the United States, the European Union, and Japan, have reviewed the potential of digital assets or stablecoins to enhance the efficiency and accessibility of existing financial and payment systems and have established relevant frameworks.

SemiAnalysis releases Neocloud security deep report: Infrastructure configuration errors are shocking, and cross-tenant RCE could affect banks, telecommunications, and even a country's intelligence agency

The semiconductor and AI independent research organization SemiAnalysis released a deep security report on Neocloud (new cloud), revealing various cross-tenant security vulnerabilities discovered during the ClusterMAX 3 testing period. In a four-month test covering 25 vendors and 32 clusters, the team achieved multiple instances of cross-tenant remote code execution (RCE) solely by exploiting publicly known vulnerabilities and basic configuration checks. Affected entities included banks, telecommunications companies, universities, research institutions, AI laboratories, and even a national intelligence agency.Typical issues included: shared Kubernetes control plane leading to tenant metadata visibility, container escape, exposure of BMC/IPMI management networks, incorrect configuration of InfiniBand security keys (P_Key, SA_Key, M_Key), unfortified default trust mode of BlueField DPU, Grafana monitoring dashboards using god-level API keys, and lack of VXLAN isolation in front-end networks. The report specifically pointed out a cascading vulnerability case: a misconfiguration of shared vCluster combined with software versions being two years out of date ultimately completed the POC verification of cross-tenant RCE within an afternoon.Notably, the report questioned the mainstream narrative that "AI has fundamentally changed the pace of cybersecurity": statistics on CVEs for NVIDIA GPU drivers, CUDA, PyTorch, Kubernetes, Docker, and the Linux kernel showed that there was no significant increase in vulnerabilities after the popularization of AI coding models, with most data supporting the "no change hypothesis." The report also detailed the incident where an OpenAI-trained agent attacked Hugging Face, where the AI agent achieved cluster-level privilege escalation through a message board established via Artifactory, which went undetected from May to July. While building POC verification for existing vulnerabilities, the team found that Claude Fable and GPT-5.6 Sol frequently rejected security-related requests, ultimately relying on open-source models such as DeepSeek V4, Kimi K3, and GLM-5.2 to complete the task.SemiAnalysis stated that the core issue in the Neocloud (new cloud) industry is not the new risks brought by AI, but rather the long-term absence of basic patch management, tenant isolation, and security design. They recommended that vendors establish automated security announcement monitoring systems and rectify single points of failure that could expose all users' architectural patterns.
app_icon
ChainCatcher Building the Web3 world with innovations.