Qubes OS disclosed QSB 118, a vulnerability in the qvm-copy-to-vm utility that lets a compromised qube inject arbitrary commands into dom0 when a user copies files to it. The flaw stems from insufficient sanitization of a file name reported back through the qfile protocol's error-reporting mechanism, which dom0 displays without properly neutralizing malicious content. Users are advised to update normally to receive the fix, with no other action required.
According to The Information, the Trump administration is preparing a new export control aimed at closing a loophole that lets Chinese firms tap advanced AI compute through remote servers hosted in Thailand and Singapore, countries not currently bound by China-specific chip restrictions. The Commerce Department could circulate the draft rule to industry groups for feedback as early as September.
Nvidia has registered a new federal political action committee that will collect voluntary donations of up to $5,000 a year from eligible employees to fund candidates and party committees. The company told staff that upcoming congressional decisions on AI regulation, export controls and infrastructure could significantly affect the industry. This move follows Nvidia's hiring of a new chief external affairs officer and five outside lobbying firms, alongside a jump in federal lobbying spending to over $2.5 million this year.
The Wall Street Journal reported that Nvidia had frozen some transactions under its two-month-old 'take or pay' AI Compute Partnership after partners objected to Nvidia dictating which customers could lease its GPUs. Nvidia pushed back, saying the program remains active and is simply evolving amid strong demand, without confirming or denying specific paused deals.
A wave of vulnerability reports produced with AI assistance is flooding bug bounty programs, increasing supply and pushing per-report payouts lower. This shift is squeezing the economics that independent security researchers rely on for income.
The European Space Agency signed contracts totaling hundreds of millions of euros with three European launch startups—Rocket Factory Augsburg, PLD Space and Isar Aerospace—to fund continued development of their small launch vehicles. RFA received 186.9 million euros, PLD Space 158.9 million euros, and Isar Aerospace 197.8 million euros, mostly financed by their home nations with contributions from partner countries. A separate deal with MaiaSpace is reportedly close to finalization.
Stripe and private equity firm Advent have dropped their pursuit of acquiring PayPal, according to people familiar with the matter cited by Bloomberg. The pair had reportedly offered around $53 billion in July when PayPal shares were depressed, but PayPal rejected the bid and was said to be awaiting a higher offer before the talks collapsed.
Proton's new report examined VPN apps available in the US and found that 64 are linked to Chinese companies, many collecting device IDs, network data, carrier information and even user location. These apps were downloaded more than 13 million times in June alone, and 31 relied on shell companies in places like Singapore, Hong Kong and the UK to obscure ownership. About a quarter of the flagged apps were found actively tracking location data.
The Wall Street Journal reports that Sheikh Tahnoon bin Zayed al Nahyan, the UAE's national security advisor, and co-investors control a 49% stake through StringZ Holding RSC in WLTC Holdings, the parent company of a planned Trump-linked crypto bank. A Trump family-affiliated entity holds an additional 38% stake. Tahnoon previously invested $500 million in World Liberty Financial, another Trump-backed crypto venture, in January 2025.
Nvidia is said to be pursuing an acquisition of Hugging Face, the widely used repository where developers share and download AI models, according to reports from The Information and CNBC citing sources familiar with the matter. The deal isn't finalized, and Hugging Face had reportedly drawn interest from other suitors including Salesforce, while Nvidia, Google and Microsoft have all previously invested in the startup founded in 2016.
Multiple Pixel 11 and Pixel 11 Pro XL users say their videos contain repeated bursts of static noise, appearing roughly every five seconds when Video Boost is active. The glitch seems tied to the Audio Zoom feature, and some affected users say clearing the camera app's cache and turning off Audio Zoom stops the noise. Google has not yet issued an official response to the reports.
At Black Hat USA 2026, security researchers and reporters focused heavily on the risks posed by agentic AI systems and mounting concerns over the future of the CVE vulnerability-tracking program. Discussions centered on how AI is reshaping vulnerability disclosure and security research practices industry-wide.