Hacker uses DeepSeek AI to attack servers on its own
- 01A hacker used DeepSeek AI and free tools to attack servers with almost no human help. Cyber
- 02An earthquake that hit Japan this week has killed 34 people so far. Rescue crews are still searching. World
- 03Hungary shut down a nuclear plant after the Danube River dropped to record lows. That plant powers half the country. World
- 04US lawmakers are investigating DoorDash's use of Chinese AI model Kimi K2.6 as concerns grow about Chinese AI tools. US Politics
- 05The Senate Commerce Committee will consider the SCREEN Act, which would require people to verify their age to view adult content online. Regulation
US politics
US lawmakers investigate DoorDash use of Chinese AI model Kimi K2.6
Lawmakers are investigating DoorDash's use of a Chinese AI model as US companies seek cheaper AI tools.
Background
DoorDash is a food delivery company. It uses AI, a technology that learns from data to do tasks, to run its business. Lately, US companies have begun using AI models made in China. These cost less than American options. US lawmakers worry about this trend.
What happened
Lawmakers asked DoorDash about its use of Kimi K2.6. This is an AI model made by Moonshot AI, a Chinese company. The lawmakers sent a letter. They want DoorDash staff who handle AI, security, and buying decisions to brief them by August 21.
Why it matters
This shows Washington is paying close attention to which AI tools American companies use. For now it does not change how you order food. But it signals the US government may soon limit or ban Chinese AI tools in US companies. That could affect which services work well and how fast they improve.
Thousands of migrant children could lose legal representation as federal contract ends
A program that pays lawyers for unaccompanied migrant children will end with no replacement in place.
Background
Unaccompanied migrant children arriving in the US often face immigration proceedings alone. A nonprofit called Acacia Center for Justice has provided legal help to these minors for the last five years through a federal contract.
What happened
That federal contract is now expiring. Thousands of unaccompanied children could lose their legal representation as a result.
Why it matters
Without a lawyer, children in immigration cases are far less likely to win their cases or understand their rights. Losing this funding means many minors may face court hearings without anyone to help them navigate the legal system.
World
Japan earthquake death toll rises to 34
At least 34 people died in Japan's earthquake this week.
Background
A powerful earthquake struck Japan this week. Earthquakes are common in Japan because the country sits on unstable ground where tectonic plates meet. When major quakes hit, they cause damage to buildings and infrastructure. They also create immediate needs for rescue and aid.
What happened
The earthquake has killed at least 34 people. Many more are injured. Buildings have collapsed and roads have cracked. Power and water service disrupted in affected areas.
Why it matters
Japan experiences frequent earthquakes, so many buildings are built to withstand them. But strong quakes still cause deaths and injuries. If you live in a seismic zone, this is a reminder of the risks your community faces. It also shows why earthquake preparation and strong building codes matter for safety.
Hungary faces energy crisis after nuclear plant shutdown
Low water levels on the Danube forced Hungary to close Paks, which supplies nearly half its power.
Background
Hungary's Paks nuclear plant supplies nearly half the country's power. Record-low water levels in the Danube River have forced the plant to shut down. The Danube cools the reactor, and when water levels drop too far, the plant cannot run safely.
What happened
Prime Minister Péter Magyar warned that the shutdown will cause an energy crisis. The European Commission said it is ready to call an emergency meeting of its Electricity Coordination Group. A Commission spokesperson said the shutdown could strain the region's power balance, even though the plant has safety measures in place.
Although the operator has emergency measures in place to guarantee nuclear safety, an event of this kind could further strain the regional electricity balance.
Why it matters
Hungary now faces potential power shortages. If the shutdown lasts through peak demand months, homes and businesses could see higher energy costs and supply cuts.
Russian ballistic missiles kill nine in Kyiv attack
Russian missiles killed nine people in Kyiv on Saturday morning and hurt 28 others.
Background
Russia has been stepping up missile attacks on Kyiv, Ukraine's capital, in recent weeks. Ukrainian President Volodymyr Zelensky says the country urgently needs more missile interceptors to defend against these strikes. Norm covered a major Russian attack on a drone exhibition near Kyiv in July that killed at least 10 people.
What happened
Russian ballistic missiles struck Kyiv on Saturday morning. At least nine people were killed and 28 more were injured, according to Ukraine's State Emergency Service. The attack is part of a pattern of escalating strikes on the capital.
Why it matters
Each attack limits Ukraine's ability to protect itself. The country has a limited supply of air defense systems to stop incoming missiles. As Russia increases its strikes, Ukraine faces growing pressure to find more interceptors and ways to defend its cities.
Regulation
Senate bill would require age verification before accessing sexually explicit content online
The SCREEN Act would require adults to give up anonymity to view legal adult content.
Background
The Senate is considering S. 737, called the SCREEN Act. It would require websites to verify that users are adults before they can see any sexually explicit content. Unlike state laws that only target adult-focused websites, this bill applies to nearly any site with even one piece of such content.
What happened
The Senate Commerce Committee is set to consider the SCREEN Act. The bill would force millions of users to prove their age before accessing lawful speech. It requires age verification but sets no rules for protecting the personal data users must share during that process.
Why it matters
If this passes, anyone accessing legal adult content online would lose anonymity and privacy. You would have to give up personal information to see content you have a right to access. The bill creates no safeguards for that data, leaving it vulnerable to misuse or breach.
US Treasury undertakes historic intervention in yen market
The US Treasury bought and sold currency in a rare move that quickly shifted exchange rates.
Science
A ton of space junk tumbles unpredictably to Earth every week
Space junk falls to Earth regularly as more rockets and satellites launch worldwide.
First Australian mass mortality event suspected from deadly H5N1 bird flu
Over 80 dead and sick terns found off South Australia coast six weeks after virus arrived
Background
H5N1 is a deadly bird flu virus. It arrived in Australia only six weeks ago. Scientists are now watching closely for signs it is spreading among native birds.
What happened
Helicopter crews found 49 dead greater crested terns on Baudin Rocks near Robe in South Australia. Another 35 sick terns were spotted at the same site. The state's chief vet said this is likely the first major die-off from the virus in Australia. Three other terns tested positive, including one found inland at Monarto.
Why it matters
H5N1 kills birds fast and in large numbers. Finding it in native Australian birds so soon after arrival shows the virus is already spreading through the wild population. This matters because once a disease takes hold in wildlife, it becomes much harder to stop.
Cybersecurity
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
Palo Alto Networks said a hacker used DeepSeek AI to break into servers with almost no human help.
Background
DeepSeek is an AI model made in China. Hermes Agent is free software that helps AI systems act without constant human direction. Security researchers at Palo Alto Networks study hacking threats.
What happened
A Chinese-speaking hacker used DeepSeek and Hermes Agent to attack exposed servers automatically. The hacker made few decisions once the system started. Palo Alto researchers spotted this when Hermes accidentally created a web server. The server exposed the hacker's setup, including API keys and exploit scripts. Unit 42 linked the activity to someone using the aliases "knaithe" and "KnYuan."
Why it matters
This shows AI tools can run attacks with less human control than before. Most servers targeted were not breached, but the method signals a shift in how hackers may work. If AI systems get better at finding targets and exploiting flaws, defending networks becomes harder.
Adobe patches critical Campaign Classic flaw allowing code execution without user action
Adobe fixed a serious flaw in Campaign Classic, a marketing tool for large companies.
Background
Adobe Campaign Classic is an enterprise marketing automation tool that helps companies manage customer communications. Adobe regularly releases updates to fix security flaws that attackers could exploit.
What happened
Adobe released updates for a critical flaw in Campaign Classic, tracked as CVE-2026-48449. The flaw has a severity score of 10.0, the highest possible rating. It stems from incorrect authorization. Attackers could run malicious code without any user action needed. Adobe also patched a second serious flaw (CVE-2026-48448, score 8.6) involving SQL injection. That flaw could let attackers read files they should not access.
Why it matters
Campaign Classic handles customer data for many large companies. A flaw this severe could expose sensitive information or disrupt marketing operations. If you work for a company using Campaign Classic, your IT team should apply these updates right away.
Hijacked hotel Wi-Fi delivers surveillance malware through fake browser updates
Microsoft linked the CaptiveCrunch malware campaign to Storm-2945, a group tied to Russian spying.
Background
Hotel Wi-Fi networks can be compromised by attackers. When this happens, the attacker can intercept traffic and send fake pages to users. This story involves a new malware, called CornFlake, being delivered this way.
What happened
Attackers compromised hotel Wi-Fi networks. They replaced real browser updates with fake ones that installed CornFlake malware. CornFlake is a remote access trojan, a tool that lets attackers control a device. Once installed, it can access webcams, record audio, and log keystrokes. Microsoft named the operation CaptiveCrunch and linked it to Storm-2945. The U.S. and U.K. governments attribute Storm-2945 to Russia's Foreign Intelligence Service.
Why it matters
If you connect to hotel Wi-Fi, attackers could target you with this malware. Business travelers handling sensitive work face the highest risk. The malware can spy on your screen, your camera, and your microphone, putting passwords and private information at risk.
Briefly
- Pilot ejects from F-35B jet crash near San Diego marine base, officials say · World
- The CIA Found a Soviet Ghost Station Full of Cold War Secrets · World
- Iran to get Chinese shoulder-launched missile systems in weeks, sources say · World
- Peru's ex-president leaves jail after 15-year jail term for corruption overturned · World
- Petrol prices on track to top $2 a litre as Bowen sounds death knell for fuel excise relief · Finance
- Huge blankets of seaweed are smothering coastlines from the Caribbean to Mexico · Science
- Race to rescue remaining climbers after deadly avalanche in Pakistan · World
- Not just Neanderthals: Ghost lineage in Africa left its mark on our DNA · Science
- VC-backed startups commit more fraud, and researchers think they know why · Business