LecturaInvestigaciónRadarMarco de inversión
Iniciar sesión / Registrarse
Iniciar sesión / Registrarse
LecturaInvestigaciónRadarMarco de inversión
Archivo de lecturas →

Lectura

2026-09-2256 publicaciones

Meta rushes out Muse zero-day fix as agent privileges become the attack surface

Resumen rápido
2026-09-22 19:53 GMT+8

Meta has issued a hotfix for its Muse macOS app, closing a zero-day that let an attacker take control of the AI agent.

The flaw was found by security researcher Patrick Wardle: an undocumented Muse setting allowed code already running on the machine to redirect cloud transcription processing to an attacker-controlled endpoint, giving access to the Muse account. Wardle's proof-of-concept could take pictures and write malicious files through Muse, often without alerting the user.

The root cause is design: dictation runs in the cloud rather than on-device, and any app could change all of Muse's undocumented settings. Wardle said attackers need not write a full Mac malware stealer when they can simply leverage the assistant's own privileges.

Meta's David Singleton called it a local privilege escalation, not a remote exploit, and said practical risk was quite low — but the hotfix shipped within hours of the Ars Technica report.

Fuentes:theverge.com

Investigación

Cisco Talos Reports Fully Autonomous AI-Directed Malware

Material
2026-09-22 18:00 GMT+8

Cisco Talos has released an open-source framework called CAIRN and used it to identify a Windows malware dubbed CLOSEDQUORUM, which makes its decisions by polling four large language models — DeepSeek, Qwen, Mistral and Gemini — with no mechanism for human input.

The malware is designed to steal login credentials and cryptocurrency, and keeps polling the remaining models if one AI service is unavailable. Talos says CAIRN has surfaced about 20 additional AI-integrated malware samples, against roughly nine named families previously documented publicly, some of them research proofs of concept.

This is Talos's own research: the malware's authors and whether it has been used in real attacks remain unconfirmed. For defenders, CAIRN's fingerprinting approach for classifying AI-integrated malware is usable now.

Fuentes:wired.com

Investigación

CoreWeave launches encryption with customer-held keys, taking itself off the decrypt list

Resumen rápido
2026-09-22 19:00 GMT+8

CoreWeave announced Remote Key Encryption on September 22: encryption runs client-side inside the customer's own compute boundary, keys are generated and stored in the customer's existing key management system or hardware security module, and no key is imported into a CoreWeave-side store — the company holds only ciphertext.

The service targets the key-custody problem that keeps enterprise AI projects parked in security review, where the cloud provider itself sits on the list of parties able to decrypt. It enters limited availability later this year with IBM as launch partner, and the first release protects data only on CoreWeave AI Object Storage, with keys held in HashiCorp Vault or any KMIP-compatible product.

The boundary: this is the company's own announcement, training clusters are not covered yet, and there is no evidence of enterprise adoption so far.

Fuentes:siliconangle.com

Investigación

Okta moves AI agent control into the runtime, but key features are not shipped yet

Resumen rápido
2026-09-22 20:00 GMT+8

At its Oktane conference, Okta announced Agent Gateway, which sits in the execution path between an agent and the tools it calls, enforcing policy and logging each interaction as it happens. Today's visibility comes only from agent events reviewed after the fact in the System Log.

Three features are generally available now: Agent SSO, Agent-to-Agent Connections and Resource Access Certifications. Agent Gateway and Shadow AI Agent Discovery for Endpoints are planned for GA in the third quarter; the gateway kill switch, which would revoke every active token and shut down sessions in flight, waits until the fourth.

Okta also joined AWS, CrowdStrike, Google Cloud and nine other vendors in a Blueprint Alliance that reworks its March agent security framework into an open, multivendor reference architecture, adding containment and recovery steps for a compromised agent. Members are testing interoperability across MCP and other open standards, with joint test results to be published regularly. All of this remains vendor-side; nothing here is independently verified.

Fuentes:siliconangle.com

Investigación

AI glasses are scaling but the market stays Meta's, for now

Resumen rápido
2026-09-22 16:37 GMT+8

Omdia estimates global AI glasses shipments reached 4.2 million units in the first half of 2026, up 127% year over year.

Meta shipped 3.4 million units, an 81.3% share. Second place Even Realities held just 2.4%, with Alibaba at 2.1%. The category is scaling, but supply remains a one-company market.

China's shipments grew 306% over the same period, yet Alibaba, INMO and Xiaomi together hold only 46.1%, making the market a testing ground for many hardware configurations. Note this is a single research firm's figure relayed by IT Home; another firm put H1 growth at 263%, so shipment estimates vary widely by methodology.

Fuentes:ithome.com

Investigación

TrendForce sees enterprise SSD prices rising again in Q4 as AI inference takes over

Resumen rápido
2026-09-22 16:15 GMT+8

On September 21, TrendForce forecast that continued purchasing by North American cloud providers will push enterprise SSD order volume past the Q3 peak in Q4 2026, with prices rising further.

The firm says demand drivers have shifted from AI training to inference, with agentic AI multiplying demand for real-time data retrieval and caching; QLC is gaining share on density advantages, serving vector databases and KV Cache offload.

This is TrendForce's forecast, not completed transactions; actual Q4 orders and prices remain to be verified.

Fuentes:ithome.com

Investigación

Next's AI spend up sixfold, but coding agents saved only 17% overall

Resumen rápido
2026-09-22 17:05 GMT+8

UK retailer Next's AI spend rose from £200,000 last year to £1.2 million this year, and CEO Simon Wolfson says its coding agent pilots are showing early results.

One website share function would have taken about 10 working days with traditional coding plus assistive AI; a coding agent wrote it in 24 minutes and 29 seconds, plus roughly half a day to manage the agent and fix errors.

Wolfson himself adds the caveat: the whole project saved only 17% of the time, partly because the agent had to be built along the way. All figures are his own statements in a diginomica interview, not independently verified.

Fuentes:diginomica.com

Investigación

Ancient Greek papyrus restoration gets its own LLM

Resumen rápido
2026-09-22 17:00 GMT+8

The Austrian Academy of Sciences will release Apollo on Wednesday, a large language model built specifically for Ancient Greek, developed with Mistral and Sail Reply and free for academics through a chatbot interface.

The model was trained on roughly 600 million Ancient Greek words drawn from manuscripts, papyri and inscriptions, and switches register with context: Homeric Greek for Homer, Doric dialect for Doric inscriptions.

The project team says it will speed up restoring damaged papyri, but scholars caution it will not produce lost Sophocles plays, since most unrestored papyri are mundane documents; Apollo only proposes candidate words, and the scholar still chooses.

Fuentes:wired.com

Investigación

oMLX creator joins Hugging Face, project gains company-backed maintenance

Resumen rápido
2026-09-22 08:00 GMT+8

Jun Kim, creator and maintainer of oMLX, has joined Hugging Face, moving the project from a side job to company-funded maintenance.

Hugging Face announced the hire in an official blog post on September 22, describing MLX as central to its local AI strategy. oMLX stays Apache 2.0 licensed, with Jun Kim continuing to lead it.

The company says oMLX will serve as a testbed for new ideas and that one focus is streamlining the transition from transformers model definitions to reference MLX implementations. These are stated plans, not verified results; the actual development pace remains to be observed.

Fuentes:huggingface.co

Investigación

Verda announces $189M Series B; the $1B valuation is the company's own figure

Material
2026-09-22 16:03 GMT+8

Verda has announced $189 million in new funding, an oversubscribed Series B led by Emergence Capital, with participation from MUFG Innovation Partners, Supermicro, Finnish pension company Varma and others.

The company says the round brings total funding above $450 million and values it at over $1 billion, making it Europe's latest unicorn; that valuation is the company's own figure and has no independent confirmation. The report also cites a $165 million annualised revenue run rate as of July, likewise a company statement.

The funds will go toward inference product development and multiplying compute capacity within a year; the specific added capacity and power arrangements are not disclosed. This is an announced round; closing and cash-receipt details await further company disclosure.

Fuentes:tech.eu

Investigación

Loongson ships first full software stack for its GPU, enabling direct ONNX deployment

Resumen rápido
2026-09-22 11:05 GMT+8

On September 22, Loongson Technology released the first software version of its Loongson Accelerated Computing Platform, targeting the LG200 GPU cores integrated in the 2K3000 and 9A1000 chips, covering drivers, compilers, operator libraries and an inference engine.

The platform supports both OpenCL 3.0 and CUDA programming interfaces, and uses its in-house LacInfer engine as an ONNX Runtime execution backend, so ONNX models exported from PyTorch or TensorFlow can be deployed without code rewrites. Operator libraries include assembly-level optimizations for FP32 and INT8 GEMM workloads.

The company says the software already serves early customers and underpins agent development for embodied devices on the 2K3000 and 9A1000. Note that inference speed and accuracy-loss claims are Loongson's own figures with no third-party benchmarks, and the 9A1000 graphics card is not expected on sale until the first half of next year per the company's earlier statements.

Fuentes:ithome.com

Investigación

Inspur launches domestic-chip supernode, claims single node runs 2.8T-parameter model

Resumen rápido
2026-09-22 07:40 GMT+8

Inspur announced the Yuannao SD200 Ultra supernode AI server at AICC2026 on September 21, built on domestic AI chips. The company says a single node can host the 2.8-trillion-parameter Kimi K3 model and supports frontier models up to 10 trillion parameters.

The system tightly couples 128 domestic AI chips with 8TB of unified-addressable memory and 64TB of system memory. Inspur claims token generation latency below 5.85ms, equivalent to 170 tokens/s per user and five times the industry average, plus a 3.5x reduction in AllReduce communication time.

Inspur also launched the HC2000 compute unit the same day, claiming 10x token throughput per unit of investment. Note that all performance figures are Inspur's own claims; the 'industry average' baseline is unspecified, and real-world results await third-party testing.

Fuentes:ithome.com

Investigación
Siguiente página de lectura →