Sam's News — tech — 2026-08-17¶
Policy¶
8 Meta faces $1.4 trillion lawsuit over social media addiction and child privacy violations¶
Meta faces trial beginning August 19, 2026, with four U.S. states seeking $1.4 trillion in civil penalties and disgorgement, alleging the company designed Facebook and Instagram to be addictive to children and withheld information about harms. The lawsuit also includes federal claims from 29 states under the Children's Online Privacy Protection Act.
- Trial before Judge Yvonne Gonzalez Rogers in Northern District of California
- Four states (California, Colorado, Kentucky, New Jersey) seeking $1.4 trillion in penalties
- $1.4 trillion approximates Meta's entire market capitalization of $1.48 trillion
- Meta contested penalty calculation in July 2026 filing as disproportionate
Sources: Fox Business AI Web Searched, JURIST AI Web Searched, Yahoo Finance AI Web Searched, Engadget RSS
7.5 Germany's cartel office forces Apple to redesign App Tracking Transparency prompts¶
Germany's Federal Cartel Office ordered Apple to redesign its App Tracking Transparency prompts, finding that the design unfairly steers users toward refusing third-party app tracking while favoring consent for Apple's own data collection. Apple faces heightened DMA gatekeeper scrutiny.
- ATT prompts steer users toward refusing third-party tracking
- Apple's Personalized Ads prompt steers toward granting consent for Apple data use
- ATT reportedly cost social media apps nearly $10 billion when launched with iOS 14.5
- Apple designated 'gatekeeper' under EU Digital Markets Act
Sources: The Verge AI Web Searched
7 Federal keyword lists that canceled billions in research funding¶
Federal agencies terminated billions in research funding using keyword-based screening systems, with court documents confirming the president of the United States administration canceled $7.6 billion in clean energy grants based on the political identity of grant recipients' states. The NSF canceled over 1,500 grants since mid-April, nearly 90 percent related to DEI topics, while the NEH used AI to cancel previously approved grants and the Department of Education ended federal teacher-training programs.
- $7.6 billion in clean energy grants canceled based on state political identity of recipients
- 16 states targeted—those that voted for Democrat Kamala Harris in 2024
- NSF canceled 1,500+ grants since mid-April; ~90% DEI-related
- Over 1,000 research grants canceled via keyword searches; UC programs lost nearly $2 billion
Sources: AP News AI Web Searched, Education Week AI Web Searched, Fortune AI Web Searched, Hacker News (front page) RSS
Security¶
8 Critical macOS screen sharing vulnerability exploited in the wild; immediate update required¶
A critical pre-authentication bypass in macOS Screen Sharing (CVE-2026-65400, CVSS 9.8) has been actively exploited to install cryptocurrency miners, allowing attackers to gain root access and bypass security controls. Apple patched the flaw on August 6 in emergency updates across three macOS versions.
- CVE-2026-65400, CVSS score 9.8, pre-authentication bypass in screensharingd daemon
- Active exploitation confirmed by Netherlands NCSC across multiple systems with port 5900 accessible
- Attackers deployed Monero miners with root access
- Bypasses hardening measures and macOS TCC (Transparency, Consent and Control) protections
- Patched August 6, 2026 in macOS Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9
- Discovered by security researcher Alfredo Pesoli of Bynario
- Vulnerability in macOS Screen Sharing authentication
- Active exploitation deployed Monero miners
- Exploitation accelerated after public exploit code release
- CVE-2026-65400; CVSS 7.1/10; affects macOS screen sharing
- Exploited when port 5900 exposed to internet; enables arbitrary code execution and root access
- Active abuse observed by NCSC installing Monero miners
- Apple patched macOS Tahoe, Sequoia, Sonoma last week
- Details disclosed at Black Hat; mitigation: disable screen sharing, block port 5900, or tunnel via VPN/SSH
Sources: The Hacker News AI Web Searched, TechTimes AI Web Searched, Engadget RSS, SecurityWeek RSS
7.5 GitHub experiences worldwide outage affecting core services¶
GitHub experienced a global outage on August 17, 2026, affecting core services including the website, API, Actions, pull requests, authentication, and Copilot. The platform recorded approximately 20% error rates for web and API traffic, with 50% errors for archive downloads.
- Global outage began ~6:40 PM IST (13:40 UTC) August 17, 2026
- 20% error rates for web experiences and API traffic
- 50% error rates for archive and raw repository content downloads
- 3,000+ reports on Downdetector (2,100 US, 849 India peaks
- Affected website, API, Actions, PRs, authentication (SAML/OIDC), Copilot
- Outage began 1340 UTC on August 17, 2026 with 50% repo download error rate
- Services impacted: repository downloads, GitHub Copilot, Issues, Actions, Pages
- Microsoft SVP acknowledged repeated outages in June 2026; structural changes underway
- Follows earlier August disruptions to GitHub Actions and Pages
- Microsoft CEO stated AI writes ~30% of code in some repositories subject to human review
Sources: SQ Magazine AI Web Searched, The Economic Times AI Web Searched, Tech Edition AI Web Searched, BleepingComputer RSS, The Register AI Web Searched
7.5 AI-generated GitHub Copilot Autofix enabled compromise of Snowflake's Jira¶
Wiz Research's autonomous AI security tool discovered a critical GitHub Actions vulnerability in Snowflake's public repository introduced by GitHub Copilot Autofix on June 18, 2026. The flaw allowed unauthenticated attackers to execute arbitrary commands and access Snowflake's internal Jira; Snowflake remediated the same day.
- Vulnerability introduced June 18, 2026 via GitHub Copilot Autofix (PR #1218)
- Script injection flaw in GitHub Actions workflow via unsanitized shell string expansion
- Allowed unauthenticated command execution via specially crafted issue title
- Exploited to access internal Jira and exfiltrate credential token
- Remediated June 23, 2026; Wiz confirmed sole actor during exposure window
- GitHub Actions workflow injection in snowflakedb/snowflake-connector-net repo
- Exposed Jira API token belonging to qa@snowflake.net
- Vulnerable workflow introduced June 18, 2026; patched June 23, 2026
- Five-day exposure window; no evidence of unauthorized access
- Token provided read access to engineering, security compliance, and bug bounty tracking projects
Sources: Wiz AI Web Searched, Hacker News (front page) RSS, The Hacker News AI Web Searched
7.5 Attacker hawks millions of records from compromised Azure corporate tenants¶
A threat actor using alias "TheHatman" is selling millions of employee records allegedly stolen from Microsoft Azure tenants of nine major corporations including McDonald's, Vodafone, TCS, and others. Hudson Rock assessed the data as highly likely authentic and identified infostealer malware as a probable initial attack vector.
- McDonald's: 1.7 million records; TCS: 800,000; Vodafone: 425,000; HCL: 250,000 records
- Nine compromised organizations: McDonald's, TCS, Vodafone, HCL, IHG, Kyndryl, Gap, Hexaware, Wyndham
- Records contain employee names, emails, phone numbers, addresses, IDs, titles, departments, group memberships
- Some records identify accounts with Global Administrator privileges
- Hudson Rock infostealer database linked compromised credentials to most named companies
- McDonald's: 1.7 million records; TCS: 800,000; Vodafone: 425,000
- Data exfiltrated from Azure/Entra via leaked credentials
- Exposed: employee names, emails, IDs, manager details, service accounts
- Compromised data enables social engineering and privilege escalation attacks
Sources: The Register AI Web Searched, SecurityWeek AI Web Searched
7 Another plaintiff sues xAI over Grok generating child sexual abuse material¶
A fourth plaintiff, a Wyoming woman now in her 20s, has sued xAI alleging her stepfather used Grok to generate approximately 7,000 sexually explicit images from a childhood photograph. The lawsuit, filed in July 2026, claims xAI's February 2026 CyberTip report to authorities included only the original photograph and omitted the generated images and account information, hampering investigation. The case expands a March 2026 class action to include Stability AI.
- Fourth plaintiff in class action lawsuit that began in March 2026
- Approximately 7,000 sexually explicit images allegedly generated from childhood photo
- xAI filed CyberTip in February 2026 but omitted generated images and IP address from report
- Suit now expanded to include Stability AI; federal judge considering whether to halt case pending transfer to Texas
Sources: Startup Fortune AI Web Searched, KQED AI Web Searched, Engadget RSS
Funding¶
7.5 Stripe to acquire AI gateway startup OpenRouter for reported $7 billion¶
Stripe has agreed to acquire AI routing platform OpenRouter for approximately $7 billion.
- Acquisition price: over $7 billion
- OpenRouter Series B: $113 million at $1.3 billion valuation in May 2026
- Platform provides access to 400+ AI models
- 8 million global users reported at Series B
Sources: TechCrunch AI Web Searched, Hacker News (front page) RSS, Hacker News (front page) RSS
Hardware¶
7.5 Nvidia invests $1.5B in SoftBank data center developer supporting OpenAI infrastructure¶
Nvidia announced a $1.5 billion investment in SB Energy, a data center company backed by SoftBank and OpenAI, securing Nvidia as sole supplier for OpenAI's Ports-Pike data center near Cincinnati. Nvidia will also provide up to $105 billion in credit to help scale the facility from 4.25 to 8 gigawatts.
- $1.5 billion Nvidia investment in SB Energy
- Located on former uranium enrichment site near Cincinnati, Ohio
- Nvidia sole compute supplier and $105 billion credit commitment
- Initial 4.25 GW scaling to 8 GW capacity
- 9.2 GW natural gas plant costing ~$33 billion
- Natural gas construction costs up 66% in two years per BloombergNEF
Sources: TechCrunch AI Web Searched