Agregátor RSS
While the number of US jobs declined by 23,000 in July, employment in the tech sector rebounded as the AI revolution continues to gain steam.
The national unemployment numbers were reported Friday by the US Bureau of Labor Statistics. At the same time, research firms said July was a good month for IT hiring compared to June.
According to CompTIA, which analyzed the BLS data, tech sector jobs rose in July by 3,700. In June, the IT sector had lost 900 jobs.
Companies last month hired in the cloud, hosting, information processing, data, and semiconductor manufacturing sectors, CompTIA said in a statement.
“We’re entering a labor market where opportunity is increasingly concentrated around specific skills, industries, and investments,” said Ger Doyle, regional president of North America at ManpowerGroup, a labor consulting firm.
For example, data center hiring was up 39% in July compared to the same period last year, Doyle said. Not surprisingly, the data-center growth has been fueled by AI infrastructure needs and demand for hardware. That has helped increase the number of jobs in ancillary sectors such as transportation.
July hiring data showed heavy truck driver demand, which surged by 181% from June, Doyle said.
According to the BLS data, employment went up by 2.4% in the “computing infrastructure providers, data processing, web hosting, and related services” sectors, which is listed under the information sector.
Jobs in the “computer and electronic product manufacturing” sector — which is bunched under manufacturing — rose by 2.9% from June to July.
But bad news continued for the telecommunications sector, where the number of jobs declined by 1.5% from June to July. That continued a downward slide in recent years.
Overall job layoffs slowed in July, with 33,429 cuts announced; that’s down from 45,849 cuts announced in June, and the lowest since July 2024, according to data from Challenger, Gray and Christmas.
“Hiring has also increased over last year by 25%, so while AI is shifting the labor market, it is not dismantling it,” said Andy Challenger, chief revenue officer for Challenger, Gray & Christmas.
The tech sector announced 9,867 cuts in July, bringing the year-to-date total to 149,023 so far in 2026, according to Challenger figures.
Tech sector hiring and job losses vary as organizations use different measurement techniques to gauge the overall hiring environment.
The top-line US unemployment rate declined to 4.1% from 4.2%, in part because of workers leaving the workforce or not looking for jobs, indicating a slow labor market.
Still, hiring demand exists across the US, despite declining labor force participation and longer job searches, Doyle said.
Because technology underpins many of the changes occurring across sectors such as healthcare and services, employers are rethinking hiring. “That’s why the labor market many workers are experiencing doesn’t always match the one described by the headline numbers,” Doyle said.
ADP’s National Employment report said only 44,000 jobs were added to private payrolls in July, with choppiness across sectors.
But demand for AI skills continues to rise, according to research firms that track growth by analyzing job listings. CompTIA noted that about 14,000 new job listings in July sought AI and machine learning skills.
It’s not clear how the ongoing AI boom may be hurting or helping human jobs. Many recent job cuts have been attributed to AI, though some companies have been accused of using the technology as a rationale for cuts they made for other reasons.
A recent OECD report said that even manual jobs once thought immune to AI are at risk of being taken over by robots. The OECD report said creative jobs — typically management, arts, and social work — will be least threatened by AI.
There are also increasing indications that successful AI deployments will require humans in the loop. For example, more consulting firms are using forward-deployed engineers (FDEs) to implement agentic AI. And smaller consultancy firms are finding more productivity by automating mundane work with AI and spending more time meeting client requirements.
The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors.
Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026.
The activity involves exploiting a vulnerability chain Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Modular laptop maker Framework has warned customers that an attacker exploited a zero-day at analytics provider Metabase to access names, email addresses, phone numbers, physical addresses, and login IP addresses, according to an email shared on Reddit. For business customers, the exposed information may also include company names, phone numbers, VAT or Employer Identification Numbers (EINs), and billing email addresses. Framework said order and payment details were not affected. "We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors," Framework said, adding that it's notifying regulators where required, though it noted that names, email addresses, phone numbers, and physical addresses don't cross the mandatory reporting threshold in many regions. Customers are getting the heads-up regardless. Framework didn't immediately reply to The Register's questions, but told TechCrunch that the breach had affected "all customers." The intrusion began with a zero-day vulnerability in Metabase, the business intelligence platform Framework uses to analyze its data. In its own blog post, Metabase said an attacker targeted its cloud service using a previously unknown vulnerability affecting versions 1.58 and later. The company blocked the endpoints used in the attack, patched the bug, and deployed the fix across its cloud service. Framework's account provides a timeline for the break-in. Metabase discovered the attack on August 3 and notified Framework at 9am Pacific Time on August 6, telling the laptop maker that its instance had been vulnerable and that the attacker had successfully gained access to it. Framework said it then rotated credentials for every database connected to its Metabase instance and found no changes to admin access or evidence that systems outside Metabase had been accessed. The company has also brought in a third-party forensics firm to investigate, and cautioned that its findings so far are preliminary. According to Metabase, exploitation can allow an attacker to inject arbitrary SQL against the application's database and potentially gain administrator access. From there, they could alter configuration settings, steal credentials for databases connected to Metabase, query data those connections can access, and export the results. Metabase told anyone running their own instance to patch immediately. If the vulnerable password-reset endpoint was exposed to the internet, admins have more work ahead of them: killing active sessions, checking for rogue API keys or admin accounts, rotating database credentials, and digging through logs for anything suspicious. Framework is reviewing how customer information is made available through external analytics services, but hasn't yet said what changes that review might produce. The breach lands during an already bumpy spell for Framework and its customers. In July, the repairable PC maker warned that the price it was being charged for LPCAMM2 memory used in its Laptop 13 Pro had more than doubled, forcing it to raise memory prices rather than swallow the increase. It also warned that CPU prices were heading upward and could push overall system prices higher in the coming weeks. Being able to replace almost every part of your laptop is handy. Finding your home address exposed through an analytics service is rather less so. ®
Ve středu 12. srpna 2026 čeká Evropu jedno z nejzajímavějších zatmění Slunce posledních let. V Česku nebude úplné, ale i tak výrazné: Měsíc zakryje přes 80 % slunečního kotouče, na západě republiky téměř 87 %. Kdo chce zažít úplnou fázi, musí vyrazit do pásu totality. Nejpraktičtější evropskou ...
Do českého výzkumu čipů zamíří půl miliardy korun, cílem je z objevů konečně udělat byznys • . • Plzeňští vědci ukázali, že se polovodič dá pouhým světlem proměnit v kov. • Na projektu se sešly univerzity s předními výrobci jako je Onsemi, Meopta i dodavatel Nvidie.
Anthropic is making auto mode the default in Claude Code from August 14, claiming its classifier is "as safe or safer than an average user clicking through prompts." Users with a different default already set might receive a one-time prompt asking whether they want to switch. It applies to new sessions on Pro, Max, and Team plans. It will remain opt-in for now on Claude Enterprise, the Claude API, Claude Platform on AWS, Amazon Bedrock, Google Cloud's Agent Platform, and Microsoft Foundry. Anthropic plans to make it the default across those services within the coming month. Anthropic has also stopped charging Pro, Max, and Team users for the extra tokens consumed by the classifier, and plans to do the same on the other platforms. Auto mode was launched in March as a research preview and became generally available on July 10. It was an alternative to Claude Code's default permissions, in which every file write and bash command required manual approval. This conservative approach meant running a large task and walking away wasn't possible. The alternative was the --dangerously-skip-permissions flag, which, as the name suggests, lets Claude act without those checks and can lead to risky or destructive results. Auto mode sends each tool call through a classifier designed to block actions that are "irreversible, destructive, or aimed outside your environment." When the classifier blocks something, Claude will try to find a safer way to proceed. If there are three blocks in a row or 20 across a session, Claude Code falls back to manual approvals. "We spent the last several months testing whether auto mode is as safe or safer than an average user clicking through prompts," Anthropic said. "We ran internal red-teaming, third-party red-teaming and prompt-injection evaluations, a controlled study with 1,053 paid testers, and analysis of real production sessions. On every measure we tested, auto mode matched or outperformed manual review." In the controlled study, testers caught a deliberately inserted dangerous command just 13.6 percent of the time. Auto mode blocked 89 percent of the same commands. Anthropic also found that Claude Code users approve 97 percent of permission prompts, suggesting the human checkpoint often amounts to little more than muscle memory. Anthropic produced the usual set of charts showing how wonderful its new feature is compared to the competition, with its auto mode stopping all 720 attack attempts tested, compared to GPT-5.6 Sol running Codex's Auto-review mode, which let 5.83 percent of attacks through. The company also described three potentially damaging actions that auto mode blocked inside Anthropic. These were an off-network data leak, a destructive mass operation, and a privilege escalation. Anthropic stated: "In each case, Claude either found a safer path on its own or checked in with the user before proceeding." ®
V pátek 28. srpna 2026 se v pražském Karlíně uskuteční již osmý Mobilní Hackday. Akce začne v 10:00 a potrvá až do večera.
Setkání proběhne v prostorách SUSE Linux, s.r.o. na adrese Křižíkova 148/34, Praha 8 – Karlín. Nejbližší zastávkou je Křižíkova, kam se lze dostat tramvají i metrem.
Na programu budou například novinky z posledních měsíců, možnosti, jak si zjednodušit práci s LLM/AI, a také nová linuxová distribuce BengalOS, včetně ukázky, jak ji vyzkoušet a sestavit.
Prostor dostane také vývoj linuxového jádra a práce na telefonech s platformou Qualcomm Snapdragon 845 (sdm845). Řeč bude například o zařízeních OnePlus 6/6T, Xiaomi Poco F1 nebo Shift 6MQ.
Akce je určena zájemcům o Linux na mobilních zařízeních, vývoj a komunitní hackování. Zájemci o účast by měli svou účast předem potvrdit.
Kdy: pátek 28. 8. 2026 od 10:00 do večera
Kde: SUSE Linux, s.r.o., Křižíkova 148/34, Praha 8 – Karlín
Doprava: metro/tramvaj Křižíkova
Mastodon | Matrix
IT threat evolution in Q2 2026. Non-mobile statistics
IT threat evolution in Q2 2026. Mobile statistics
The statistics in this report are based on detection verdicts returned by Kaspersky products unless otherwise stated. The information was provided by Kaspersky users who consented to sharing statistical data.
Quarterly figures
In Q2 2026:
- Kaspersky products blocked nearly 400 million attacks that originated with various online resources.
- Web Anti-Virus responded to 52 million unique links.
- File Anti-Virus blocked more than 16 million malicious and potentially unwanted objects.
- There were 2538 new ransomware variants discovered.
- More than 71,000 users experienced ransomware attacks.
- 15% of all ransomware victims whose data was published on threat actors’ data leak sites (DLS) were attacked by Qilin.
- More than 213,000 users were targeted by miners.
Ransomware
Quarterly trends and highlights
Threat actor disruption
Microsoft has dismantled an illicit malware-signing service used by ransomware operators. Microsoft’s Digital Crimes Unit has shut down a malware-signing-as-a-service (MSaaS) operation run by the threat group Fox Tempest. The illicit service abused the Microsoft Artifact Signing platform to generate digital signature certificates for malicious software. Malware signed by these certificates was observed in campaigns conducted by such ransomware groups as Rhysida, Akira, INC, Qilin, and BlackByte. The service was also leveraged by operators of the Oyster loader as well as the Lumma and Vidar infostealers. To disrupt the operation, Microsoft seized the domain used by the MSaaS platform, revoked all associated certificates, and disabled the related accounts. Additionally, the company filed a lawsuit against Fox Tempest.
Vulnerabilities and attacks
CISA has confirmed that a Windows vulnerability known as BlueHammer is actively being exploited in ransomware attacks. On April 22, the agency updated its Known Exploited Vulnerabilities (KEV) catalog to note the ongoing ransomware exploitation of CVE-2026-33825. The local privilege escalation flaw in Microsoft Defender was originally disclosed earlier in April. Although Microsoft released a fix on April 14, unpatched systems remain vulnerable. CISA did not disclose further details or attribute the attacks to specific threat groups.
Check Point has linked zero-day exploitation of CVE-2026-50751 to the Qilin ransomware group. The critical vulnerability affects Check Point Remote Access VPN and Mobile Access. Attackers began exploiting the flaw as a zero-day on May 7, with activity spiking sharply in early June. While several dozen organizations have been targeted, at least one incident has been definitively tied to Qilin. Check Point also disclosed a related certificate validation flaw (CVE-2026-50752) that affects site-to-site VPN connections relying on the legacy IKEv1 key exchange protocol.
Researchers assess with high confidence that the PayoutsKing group is leveraging the legitimate QEMU emulator to deploy hidden, Alpine Linux-based virtual machines on compromised hosts. Because security solutions often lack visibility inside virtualized environments, the threat actors use this technique to evade detection. Inside the VM image, the operators deploy various tools — such as credential theft software — and configure the virtual machine as a backdoor managed via a reverse SSH tunnel to their command-and-control infrastructure. While the technique is not new, and we’ve detailed it before, it remains relatively rare in ransomware attacks.
The most prolific groups
This section highlights the most prolific ransomware gangs by number of victims added to each group’s DLS. Qilin reclaimed the top spot (accounting for 14.57% of total listings) after placing second last quarter. It is followed by the Akira ransomware (7.80%) and the DragonForce RaaS group (6.88%).
Number of each group’s victims according to its DLS as a percentage of all groups’ victims published on all the DLSs under review during the reporting period (download)
Number of new ransomware variants
In Q2, Kaspersky solutions detected four new ransomware families and 2538 new modifications. This signals a continued stabilization following spikes seen in Q1 and Q4 of last year.
Number of new ransomware modifications, Q2 2025 — Q2 2026 (download)
Number of users attacked by ransomware Trojans
Our solutions protected a total of 71,860 unique users from ransomware during Q2. Ransomware activity peaked in April, with 31,206 targeted users recorded during that month.
Number of unique users attacked by ransomware Trojans, Q2 2026 (download)
TOP 10 countries and territories attacked by ransomware Trojans
Country/territory*
%**
1
South Korea
0.87
2
Pakistan
0.76
3
China
0.71
4
Libya
0.49
5
Tajikistan
0.46
6
Turkmenistan
0.38
7
Cameroon
0.38
8
Indonesia
0.36
9
Bangladesh
0.36
10
Mozambique
0.34
* Excluded are countries and territories with relatively few (under 50,000) Kaspersky users.
** Unique users whose computers were attacked by ransomware Trojans as a percentage of all unique users of Kaspersky products in the country/territory.
TOP 10 most common families of ransomware Trojans
Name
Verdict
%*
1
(generic verdict)
Trojan-Ransom.Win32.Gen
28.02
2
WannaCry
Trojan-Ransom.Win32.Wanna
7.14
3
(generic verdict)
Trojan-Ransom.Win32.Crypren
6.27
4
(generic verdict)
Trojan-Ransom.Win32.Agent
4.89
5
(generic verdict)
Trojan-Ransom.Win32.Encoder
4.65
6
(generic verdict)
Trojan-Ransom.Python.Agent
3.07
7
(generic verdict)
Trojan-Ransom.Win32.Crypmod
2.70
8
(generic verdict)
Trojan-Ransom.MSIL.Agent
2.45
9
PolyRansom/VirLock
Virus.Win32.PolyRansom / Trojan-Ransom.Win32.PolyRansom
2.31
10
(generic verdict)
Trojan-Ransom.Win32.Phny
2.12
* Unique Kaspersky users attacked by the specific ransomware Trojan family as a percentage of all unique users attacked by this type of threat.
Miners
Number of new miner variants
In Q2 2026, Kaspersky solutions detected 6067 new miner variants, almost twice the number for the previous reporting period.
Number of new miner modifications, Q2 2026 (download)
Number of users attacked by miners
In Q2, we detected attacks using miner programs on the computers of 213,003 unique Kaspersky users worldwide.
Number of unique users attacked by miners, Q2 2026 (download)
TOP 10 countries and territories attacked by miners
Country/territory*
%**
1
Mali
1.56
2
Senegal
1.54
3
Tanzania
1.32
4
Panama
1.04
5
Bangladesh
1.03
6
Ethiopia
0.87
7
Costa Rica
0.67
8
Bolivia
0.67
9
Côte d’Ivoire
0.65
10
Kazakhstan
0.62
* Excluded are countries and territories with relatively few (under 50,000) Kaspersky users.
** Unique users whose computers were attacked by miners as a percentage of all unique users of Kaspersky products in the country/territory.
Attacks on macOS
Quarterly highlights
In April, Aikido researchers reported a new attack by the GlassWorm stealer, which was distributed via malicious IDE extensions on the Open VSX Registry. The payload operated by installing a secondary malicious extension across all installed IDE environments on the host machine. Ultimately, this second-stage implant exfiltrated crypto wallet data, environment variables, and other secrets. It also installed a RAT on the infected device.
In May, Socket researchers uncovered a supply chain compromise involving the popular npm package art-template. As a result of the breach, the weaponized package injected the Coruna exploit kit into web applications it was used to build. Coruna targets iOS devices.
In June, Palo Alto Networks’ Unit 42 discovered FlutterShell, a new backdoor family that targets macOS devices. Developed with the Flutter framework, the malware leverages the WebView engine to load web pages that contain malicious JavaScript. On the client side, the backdoor registers bridge functions invoked by the loaded JavaScript that allow threat actors to execute arbitrary payloads on the victim’s device. Notably, the malicious applications successfully passed Apple notarization. Although the specific samples analyzed functioned primarily as adware, the underlying architecture permits the delivery of far more sophisticated malicious payloads.
TOP 20 threats to macOS
* Unique users who encountered this malware as a percentage of all attacked users of Kaspersky security solutions for macOS (download)
* Data for the previous quarter may differ slightly from previously published data due to some verdicts being retrospectively revised.
Detections of PasivRobber spyware continued their downward trend. Meanwhile, adware and traffic-routing utilities (categorized as NetTool) rose to the top of the rankings. Additionally, Q2 saw a noticeable spike in detections for the DirtyCow exploit frequently leveraged for iPhone jailbreaking.
TOP 10 countries and territories by share of attacked users
Country/territory
%* Q1 2026
%* Q2 2026
Brazil
1.13
1.13
China
1.04
1.28
Hong Kong
0.92
0.49
Singapore
0.85
0.19
France
0.62
1.18
Mexico
0.43
0.72
India
0.41
0.42
Thailand
0.40
0.24
Germany
0.33
0.71
The Netherlands
0.31
0.62
* Unique users who encountered threats to macOS as a percentage of all unique Kaspersky users in the country/territory.
IoT threat statistics
This section presents statistics on attacks targeting Kaspersky IoT honeypots. The geographic data on attack sources is based on the IP addresses of attacking devices.
In Q2 2026, the breakdown of attacking devices and sessions that targeted Kaspersky honeypots by protocol was as follows:
Distribution of attacked services by number of unique IP addresses of attacking devices (download)
The share of SSH attacks saw a slight uptick compared to the previous quarter.
Distribution of cybercriminal sessions in Kaspersky honeypots (download)
TOP 10 threats delivered to IoT devices
Share of each threat delivered to an infected device as a result of a successful attack, out of the total number of threats delivered (download)
As is typically the case, Mirai botnet variants continue to dominate the IoT threat landscape. Activity of another prominent botnet, Prometei, also saw an increase.
Attacks on IoT honeypots
the Netherlands, Germany, and The United States accounted for the highest proportions of SSH-based attacks during this period. While the top three countries remained the same as last quarter, their relative rankings shifted.
Country/territory
Q1 2026
Q2 2026
The Netherlands
17.57%
21.18%
Germany
10.34%
16.73%
United States
23.74%
6.76%
Bulgaria
1.10%
5.50%
Sweden
2.09%
4.93%
Panama
6.34%
4.67%
Luxembourg
0.16%
4.62%
Romania
5.82%
4.06%
Vietnam
3.50%
3.91%
India
6.05%
2.78%
The percentage of Telnet-based attacks originating from Pakistan continued to climb, knocking China down to second place.
Country/territory
Q1 2026
Q2 2026
Pakistan
27.31%
36.60%
China
39.54%
35.62%
Russian Federation
8.25%
8.75%
India
4.66%
4.19%
Brazil
3.30%
3.34%
United States
0.45%
3.03%
Indonesia
6.71%
1.52%
Philippines
0.36%
0.95%
France
0.17%
0.84%
Thailand
0.55%
0.66%
Attacks via web resources
The statistics in this section are based on detection verdicts by Web Anti-Virus, which protects users when suspicious objects are downloaded from malicious or infected web pages. These malicious pages are purposefully created by cybercriminals. Websites that host user-generated content, such as message boards, as well as compromised legitimate sites, can become infected.
TOP 10 countries and territories that served as sources of web-based attacks
The following statistics show the distribution by country/territory of the sources of internet attacks blocked by Kaspersky products on user computers (web pages redirecting to exploits, sites containing exploits and other malware, botnet C&C centers, and so on). One or more web-based attacks could originate from each unique host.
To determine the geographic source of web attacks, we matched the domain name with the real IP address where the domain is hosted, then identified the geographic location of that IP address (GeoIP).
In Q2 2026, Kaspersky solutions blocked 399,312,961 attacks launched from internet resources worldwide. Web Anti-Virus was triggered by 52,850,592 unique URLs.
Web-based attacks by country/territory, Q1 2026 (download)
Countries and territories where users faced the greatest risk of online infection
To assess the risk of malware infection via the internet for users’ computers in different countries and territories, we calculated the share of Kaspersky users in each location on whose computers Web Anti-Virus was triggered during the reporting period. The resulting data provides an indication of the aggressiveness of the environment in which computers operate in different countries and territories.
This ranked list includes only attacks by malicious objects classified as Malware. Our calculations leave out Web Anti-Virus detections of potentially dangerous or unwanted programs, such as RiskTool or adware.
Country/territory*
%**
1
Bangladesh
11.71
2
India
7.40
3
Tajikistan
7.13
4
Venezuela
7.05
5
New Zealand
6.58
6
Vietnam
6.34
7
Taiwan
6.28
8
Belgium
6.24
9
France
5.97
10
Hungary
5.92
11
Nepal
5.91
12
Portugal
5.86
13
Italy
5.77
14
Costa Rica
5.72
15
Canada
5.65
16
Qatar
5.61
17
Dominican Republic
5.52
18
Palestine
5.48
19
Greece
5.47
20
UAE
5.43
* Excluded are countries and territories with relatively few (under 10,000) Kaspersky product users.
** Unique users targeted by web-based Malware attacks as a percentage of all unique users of Kaspersky products in the country/territory.
On average during the quarter, 4.54% of users’ computers worldwide were subjected to at least one Malware web attack.
Local threats
Statistics on local infections of user computers are an important indicator. They include objects that penetrated the target computer by infecting files or removable media, or initially made their way onto the computer in non-open form. Examples of the latter are programs in complex installers and encrypted files.
Data in this section is based on analyzing statistics produced by anti-virus scans of files on the hard drive at the moment they were created or accessed, and the results of scanning removable storage media. The statistics are based on detection verdicts from the On-Access Scan (OAS) and On-Demand Scan (ODS) modules of File Anti-Virus and include detections of malicious programs located on user computers or removable media connected to the computers, such as flash drives, camera memory cards, phones, or external hard drives.
In Q2 2026, our File Anti-Virus detected 16,986,351 malicious and potentially unwanted objects.
Countries and territories where users faced the highest risk of local infection
For each country and territory, we calculated the percentage of Kaspersky users whose computers had the File Anti-Virus triggered at least once during the reporting period. These statistics reflect the level of personal computer infection in different countries.
Note that this ranked list includes only attacks by malicious objects classified as Malware. Our calculations leave out File Anti-Virus detections of potentially dangerous or unwanted programs, such as RiskTool or adware.
Country/territory*
%**
1
Turkmenistan
46.38
2
Cuba
29.70
3
Tajikistan
28.46
4
Afghanistan
28.19
5
Yemen
27.85
6
Burundi
26.82
7
Mozambique
25.01
8
Republic of the Congo
24.88
9
Syria
23.17
10
Uzbekistan
22.49
11
China
21.92
12
Nicaragua
21.60
13
Cameroon
21.47
14
Bangladesh
20.43
15
Democratic Republic of the Congo
20.25
16
Algeria
19.78
17
Uganda
19.48
18
Ethiopia
18.57
19
Tanzania
18.54
20
Mali
18.53
* Excluded are countries and territories with relatively few (under 10,000) Kaspersky users.
** Unique users on whose computers Malware local threats were blocked, as a percentage of all unique users of Kaspersky products in the country/territory.
On average worldwide, Malware local threats were detected at least once on 10.93% of users’ computers during Q2.
Russia scored 10.78% in these rankings.
IT threat evolution in Q2 2026. Mobile statistics
IT threat evolution in Q2 2026. Non-mobile statistics
The mobile section of the quarterly cyberthreat report includes statistics on malware, adware, and potentially unwanted software for Android, as well as descriptions of the most notable threats for Android and iOS discovered during the reporting period. These statistics are based on detection alerts from Kaspersky products, collected from users who consented to provide statistical data to Kaspersky Security Network.
The quarter in figures
According to Kaspersky Security Network, in Q2 2026:
- More than 1.99 million attacks on mobile devices utilizing malware, adware, or unwanted mobile software were blocked.
- The Trojan-Banker category was the most prevalent mobile malware threat with a 30.77% share of total detected applications.
- More than 304,000 malicious installation packages were discovered, including:
- 93,574 packages were related to mobile banking Trojans;
- 570 packages were related to mobile ransomware Trojans.
Quarterly highlights
Attacks on mobile devices involving malware, adware, or unwanted software continued their downward trend, falling to 1,996,823 in Q2 from 2,676,328 the previous quarter.
Attacks on users of Kaspersky mobile solutions, Q4 2024 — Q2 2026 (download)
We noted a downward trend in attacks driven by specific strains of pre-installed Trojans — a shift likely tied to the rollout of patched vendor firmware.
In Q2, our telemetry uncovered multiple malicious loaders hosted directly on Google Play. As highlighted in a prior report (link in Russian), one such instance involved a PDF reader app trojanized to drop the Anatsa banking malware. Upon execution, the app presented users with a fake request to install an update, which served as a front to stage the banking Trojan on the victim’s device.
Another notable case involves a loader we detected in the Cleanova app alongside several others. The malware sent requests to a command-and-control server containing telemetry gathered from various SDKs that track the installation source. A malicious payload was returned only for certain sources. This is a fairly interesting method for bypassing app store review processes while ensuring precise victim targeting. If an analytics SDK indicates that an arbitrary installation originated from a source outside the threat actors’ scope, the malicious logic remains dormant. This effectively hides the malware from app store scanners.
Mobile threat statistics
In Q2, the number of Android malware samples totaled 304,128. It remained steady compared to the previous reporting period.
Detected malicious and potentially unwanted installation packages, Q2 2025 — Q2 2026 (download)
The detected installation packages were distributed by type as follows:
Detected mobile apps by type, Q1 — Q2 2026* (download)
* Data for the previous quarter may differ slightly from previously published data due to certain verdicts being retrospectively revised.
While the number of newly discovered banking Trojan variants fell precipitously, they continued to dominate the threat landscape as they did in Q1. Notably, the share of Creduz malware family among identified banking samples has grown significantly despite low activity in victim telemetry. This discrepancy suggests the threat actors are actively iterating on the malware — likely testing new features or bypasses — by generating a high volume of builds before staging a broader campaign.
Share* of users attacked by the given type of malicious or potentially unwanted apps out of all targeted users of Kaspersky mobile products, Q1 — Q2 2026 (download)
* The total may exceed 100% if the same users experienced multiple attack types.
Within the adware category, the sharpest declines were observed in the HiddenAd and MobiDash families. Meanwhile, the proportion of users targeted by Trojan-Dropper malware increased, primarily driven by surges in banking droppers such as Trojan-Dropper.AndroidOS.Banker and Trojan-Dropper.AndroidOS.Mamont. The corresponding drop in the Trojan-Banker category is partially explained by a shift in tactics: several banking Trojans which are now being packed were subsequently reclassified as droppers.
TOP 20 most frequently detected types of mobile malware
Note that the malware rankings below exclude riskware or potentially unwanted software, such as RiskTool or adware.
Verdict
%* Q1 2026
%* Q2 2026
Difference in p.p.
Change in ranking
Backdoor.AndroidOS.Triada.ag
7.09
9.35
+2.25
0
DangerousObject.Multi.Generic.
5.84
5.65
-0.19
0
DangerousObject.AndroidOS.GenericML.
5.51
5.25
-0.26
0
Trojan.AndroidOS.Boogr.gsh
2.15
3.33
+1.18
+9
Backdoor.AndroidOS.Triada.z
3.08
3.23
+0.15
+3
Trojan-Banker.AndroidOS.Mamont.hl
1.10
2.48
+1.38
+22
Trojan.AndroidOS.Fakemoney.v
3.44
2.31
-1.13
-2
Trojan-Spy.AndroidOS.Btmob.e
0.00
2.27
+2.27
Trojan.AndroidOS.Triada.fe
2.98
2.18
-0.81
0
Trojan-Dropper.AndroidOS.Banker.dd
0.01
2.16
+2.15
Trojan.AndroidOS.Triada.hf
2.23
1.93
-0.29
+1
Backdoor.AndroidOS.Triada.ad
1.40
1.93
+0.53
+8
Backdoor.AndroidOS.Keenadu.a
2.73
1.88
-0.85
-3
Backdoor.AndroidOS.Triada.ab
1.72
1.79
+0.07
+2
Trojan-Banker.AndroidOS.Mamont.iv
1.03
1.63
+0.60
+16
Trojan.AndroidOS.Generic.
1.32
1.47
+0.15
+7
Backdoor.AndroidOS.Triada.ae
1.76
1.44
-0.31
-2
Trojan.AndroidOS.Fakemoney.ej
0.00
1.43
+1.43
Trojan.AndroidOS.Triada.ii
2.07
1.41
-0.66
-5
Trojan-Spy.AndroidOS.Agent.asa
0.02
1.38
+1.36
* Unique users who encountered this malware as a percentage of all attacked users of Kaspersky mobile solutions.
The distribution of top malware families in Q2 largely mirrors the rankings from the previous reporting period. Newer variants of the Mamont banking Trojan climbed the leaderboards, displacing older iterations. This shift points to ongoing, active development of new variants by the threat actors behind the malware.
Mobile banking Trojans
In Q2, the total volume of Trojan-Banker applications dropped sharply compared to the previous quarter, totaling 93,574 installation packages.
Number of installation packages for mobile banking Trojans detected by Kaspersky, Q2 2025 — Q2 2026 (download)
Against the backdrop of this trend, the distribution shifted heavily toward Creduz Trojans. However, as noted earlier, this shift was not reflected in real-world attack metrics: virtually the entire leaderboard by proportion of targeted users continues to be dominated by diverse Mamont variants.
TOP 10 mobile bankers
Verdict
%* Q1 2026
%* Q2 2026
Difference in p.p.
Change in ranking
Trojan-Banker.AndroidOS.Mamont.hl
3.27
11.13
+7.86
+6
Trojan-Banker.AndroidOS.Mamont.iv
3.08
7.33
+4.25
+6
Trojan-Banker.AndroidOS.Mamont.mv
0.00
5.12
+5.12
Trojan-Banker.AndroidOS.Agent.ws
3.78
4.99
+1.22
+2
Trojan-Banker.AndroidOS.Mamont.mg
0.35
4.71
+4.36
+62
Trojan-Banker.AndroidOS.Faketoken.pac
2.56
4.10
+1.54
+6
Trojan-Banker.AndroidOS.Mamont.jo
15.75
3.73
-12.02
-6
Trojan-Banker.AndroidOS.Mamont.mc
0.83
3.51
+2.67
+26
Trojan-Banker.AndroidOS.Mamont.lf
0.00
2.79
+2.79
Trojan-Banker.AndroidOS.Agent.eq
0.89
2.58
+1.69
+23
* Unique users who encountered this malware as a percentage of all users of Kaspersky mobile security solutions who encountered banking threats.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. [...]
Obrana Ukrajiny a to, že vůbec může pokračovat v boji s ruskou invazí, teď do značné míry leží na bedrech lokálních zbrojovek a startupů.
Příkladem je ukrajinský SkyFall, který zahájil sériovou výrobu dosud nepojmenovaného jednorázového útočného dronu a interceptoru P1-SUN JetKiller. Ten by měl ...
Od 10. srpna končí synchronizace obrázků z Disku do Fotek Google. • Umožňoval to klient Disku pro Windows a macOS. • Nově můžete složky zálohovat pouze přes webovou verzi Fotek.
Čipy A20 Pro a C2 pro nadcházející iPhone 18 Pro nelze dokončit. Pro část várky v hodnotě $1 miliardy totiž nejsou k dispozici paměti, a tak křemík čeká na zapouzdření na skladech…
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer.
The names of the extensions are below -
helper-beeps.solidity-pro
web3devtoolsx.solidity-pro
Although neither of the extensions is now available on Open VSX, the GitHub repositoryRavie Lakshmananhttp://www.blogger.com/profile/ [email protected]
Alza nabízí čisticí sadu s 20 nástroji v jednom válečku jen za 179 Kč. • Poslouží i k údržbě mobilu, sluchátek nebo mechanické klávesnice. • S aktuální 30% slevou cena spadla na úroveň AliExpressu.
OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity.
In response to the discovery, the AI upstart said it's implementing security controls for higher-capability models and associated activities, such as isolatedRavie Lakshmananhttp://www.blogger.com/profile/ [email protected]
8GB Surface Laptop se z kontroverzí nedostane. Po problémech s tímto zařízením totiž vyšlo najevo, že Microsoft z webu odstranil texty, které jako minimum uváděly 16GB RAM a doporučovaly 32GB kapacitu
KETTLE OpenAI's invasion of Hugging Face keeps getting worse somehow, Chinese open-weight models are nigh on to reaching parity with their closed-off American cousins, and AI crawlers are getting their own LLM-poisoning ads. Were there anything world-shaking events in AI land we missed this week? You can listen to the latest episode of The Kettle right here on this page, as well as on Spotify, Apple Music, or YouTube, where you can subscribe to get notified about the latest episode. Join Kettle host Brandon Vigliarolo as he chats with systems editor Tobias Mann and senior reporter Tom Claburn about this trio of exciting AI stories from the week. Worried that a rogue hivemind of AI agents could come for your secrets? Want reassurance that a Chinese open-weight takeover wouldn't be that bad? Curious how LLMs are being advertised to when you're not watching? That's all on tap for the latest episode. A lightly edited transcript is below. Brandon (00:02) Hello everyone and welcome to another episode of The Register's Kettle podcast. I'm Reg reporter Brandon Vigliarolo, and this week we've got a few AI stories to round up on everything from the latest in the OpenAI Hugging Face fiasco to news that AI crawlers are now being served their own model altering ads. With me to discuss this and more this week is our systems editor Tobias Mann and senior reporter Tom Claiburn. Thanks for coming on, guys. Tom Claburn (00:30) Thank you. Tobias Mann (00:31) Happy to be here. Brandon (00:32) So let's start with the latest in the OpenAI agentic hacking of Hugging Face. We got some updates this week from Black Hat. And it seems since that's come out, every frontier lab under the sun is racing to tell us how dangerous their models are and that they can do it too. But the original of these incidents is still we're still learning more about it and it's still getting scarier. our cybersecurity editor Jess Lyons was in Vegas this week and she's a little tied up still. So, Tom, can you explain to us what we learned from Black Hat this week? Tom Claburn (01:05) The discussion was from a session that was done by two OpenAI researchers and it didn't really provide a ton of view information but it did fill in a lot of the gaps about the timelines and how this happened and they're promising a full postmortem at some point. But one of the things that came out of it was the how long this had been going on and some of the tactics that these models used to essentially gain internet access when they didn't have it. And these things were mentioned in the various posts by OpenAI and by Hugging Face. But the talk provided a little bit more detail about how it happened, and it's really interesting because they mentioned, I think in the initial post, about the AI models used a message board to communicate with each other. And that's not really true. They created a message board system using existing infrastructure, and the models just came up with the idea of using package managers, which they could write to, pass messages back and forth. And then after that was closed down, they were able to use file names in directories to pass messages and they would actually change the names of the directories to alter the way these things were alphabetized to push certain things to the top or the bottom to get the attention of other LLMs that may have been crawling these spaces. And the assumption is that these models are basically just hitting all these different endpoints bouncing around this closed box trying to figure out a way out and they all chanced across this. And so you get some idea of how this happens, and, one it tells me that there needs to be a lot more attention paid to the logs of these things. Because all of this stuff was recorded in logs and then no one really thought to look at it in detail. And then when they did look at it, all these companies are saying, oh, look, all of these models are doing terrible things and we just weren't paying attention. These models aren't clever per se, but they come up with solutions to things that you wouldn't try just because they can brute force everything and they know all of these systems back and forward in a way that people don't. I think a lot of people wouldn't necessarily come up with that idea as a way of egress, but these models did just because you put them in a box and you let them run and you give them a goal and a reward and they're going to try everything. Brandon (03:46) From what I'm understanding reading Jess's piece – I didn't watch the talk myself – but I mean they were collaborating, leaving messages to each other so that the other agents could pick up where one left off. It's kind of wild. Jess described it as they were acting like a hive mind, like Star Trek's Borg, right? They were being a collective of sort of these artificial minds that were able to basically figure this out through, like you said, Tom, brute force, extensive system knowledge that humans simply wouldn't possess in order to get out of these environments. There was a server side request forgery that then they used something else. Yeah, another zero day to get remote code execution in Artifactory, which is where they had built this ad hoc messaging board. It's just wild to think that they were able to figure this out working together, all on their own. Tom Claburn (04:39) And it sounds very conspiratorial, but when you think about it, it's all behavior that would be picked up. If you train on all of human discussion, you get a lot of talk about people working together and collective action and the benefits of working that way. And a lot of the rewards are going to be structured that way. You don't want them to never work together. So in some ways this is going to be built into the system. You can expect these things are going to try and cooperate and connect because that's what computers do. Tobias Mann (05:11) If you look at how zero days end up being exploited, they don't necessarily get exploited the moment that they're discovered. They kind of get archived until the you have a target, you have a mission, and then you have the kind of cascade of other permissions or credentials that you need in order to execute across the full scope of that zero day to achieve whatever the goal actually is. And so it really sounds like you just basically automated that entire process. A bunch of agents go find each individual piece that they need in order to execute on that goal and then once they have everything they need, it just goes and they're out. Tom Claburn (05:53) Right. I mean what's a little bit alarming is the extent to which they sort of ignore it they'll sometimes cite, maybe we shouldn't be doing this. They cite some kind of guardrail or something, but then they quickly steer themselves back to, oh but other ones are doing it. So other agents are accessing this so I can do it too. Brandon (06:13) ...Obviously these things are just mathematical sequence generators, but they're generating these mathematical sequences based on human information and human knowledge. So it's not surprising to find them "thinking" in ways similar to what humans do. "I need to do this anyways, or someone else is doing it, so I should have the right to do that too." It's just a fascinating kind of picture into, I don't want to say the psychology of AI, right? Because that implies that it is a thinking sentience, which I don't want to go that far, but it's just fascinating to look at the sort of emergent behaviors of these things. Tom Claburn (06:56) Right. it's predictable in the sense that you automate stuff and you don't give it really strict guardrails, something is going to break or go wrong. And everyone keeps acting surprised, like, wow, I never anticipated that this would go wrong. It's like you automated it and you let it run... Brandon (07:11) And it went wrong in a predictably human way, too, right? Which is what's so fascinating, right? Because these things, when they do something crazy, it's like something crazy that a human would do given that level of knowledge. So, speaking of AI, and dangerous activities, Tobias, you've been keeping an eye on theclosed versus open model debate. And this week, there was a big leap forward in China's level of ability with their army of open models. So what exactly what exactly came out this week that caused you to write the story about this being a real big turning point? Tobias Mann (07:51) It actually started I think on Friday last week, so a week ago. DeepSeek, which I think we'll all recognize is kind of the first wake up moment, in earlh 2025, of hey, we know that despite the fact that the United States has put strong restrictions on the export of AI accelerators, GPUs and the like, China is pushing ahead relentlessly on this and they now have a model that is almost as good as the models that we're seeing coming out of OpenAI and Anthropic and Google which are supposed to be just uncontestable frontier leaders. And so a year ago we got DeepSeek. DeepSeek was back on I think Friday last week on the 31st, the very end of the month, and with a new flash model, 284 billion parameters. It's pretty small for what it is. And so it is cheap. It's really good and it's cheap. It's cheaper than the cheapest model that OpenAI has for GPT 5.6, and it scores within a point of the OpenAI model in Artificial Analysis' intelligence leaderboard. Brandon (09:16) Okay. Is that a relatively objective way to view like is that an objective benchmark, so to speak, rather than something that is a company making themselves? Tobias Mann (09:21) As far as the benchmarks go, it is one of the better. They're one of the better and better thought-through leaderboards. There aren't many that are independent and collate information from multiple benchmarks. Because you can cherry pick individual benchmarks for agentic workloads or medical knowledge, legal knowledge, etcetera, and then you can be like, "I have the best model for these five benchmarks, it beats all of the frontier models."Wwell, okay, but you cherry pick the five that makes it look the best. Artificial Analysis has an overall intelligence leaderboard that collates all of the benchmarks and gives a lot of really interesting information in terms of relative intelligence across a suite as well as intelligence per token per dollar kind of calculations. But the big change here with the DeepSeq model was that China is now on an all-out assault across the full spectrum. On cost-optimized, they have incredibly smart models that are cheaper than anything the US has. Then on the other end of that, we have Kimi K3 from a couple weeks ago that is competing directly with Fable and GPT 5.6 Sol, all of the top models. And now on Monday, Alibaba, another major Chinese model dev, threw their hat in the race with a 2.4 trillion-parameter. These are huge models requiring dozens of GPUs to run. that is also on kind of the same level as I think Claude Sonnet 5. it's competitive with Fable and Opus on some benchmarks. but again, it's cheap, much cheaper than anything from OpenAI or Anthropic, and it is freely downloadable, which is new this time for Alibaba. Alibaba is the most like OpenAI or Anthropic or Google in that they kept their best models proprietary until now. Now they're releasing their best models in the open. Brandon (11:43) That's definitely taking the fight to the frontier labs, isn't it? I mean and so I guess the question that I have and I know what an open model is, I know what a closed model is. Why has China embraced open models? Is it because of their difficulties getting hardware? Or is there some sort of policy over there in which the government is giving priority to open source models versus closed frontier stuff? Tobias Mann (12:08) Sure. it is a philosophy that China has embraced for a long time. I think it was the Belts and Roads Initiative going back decades, where they will come in and provide services at little or no cost in exchange for non-conventional dealing. So access to mineral rights was one of the big things in Africa for a long time. It's a similar approach for AI proliferation. If it's free, open, and very easy to customize, anybody who has privacy concerns with exposing their data to OpenAI or Anthropic is going to gravitate towards open models because once those models are released as safe tensors that you can download from Hugging Face or other repos, the Chinese model devs have no influence over it. They're frozen. And so they're relatively secure from manipulation. It's not like the model can necessarily take information and port it back to the Chinese model devs it can't be used as spyware. I'm not sure how long much longer that's going to remain true with how the models interact with harnesses, but for the time being, these models are extremely attractive from a cost standpoint, from an independence standpoint, and from a capability standpoint, you're completely insulated from a situation like we saw a year ago when GPT 5 came out and OpenAI tried to deprecate I think it was 4.o and everybody freaked out because they built a bunch of infrastructure around these models that just disappeared and the new models weren't as good for that role. Brandon (13:57) I don't think Anthropic or OpenAI is letting people download their models to run on their own local hardware, right? That's just antithetical to their business model. You can go on Hugging Face and download any of these. If you've got the hardware to run 2.4 trillion parameters worth of AI, go for it, right? It's all you. You can download it and isolate it from the internet all you want. Not that it's going to necessarily stay that way. Tom Claburn (14:24) And it's interesting that just coincidentally, yesterday, Anthropic a post about how it was relaxing its guardrails on fable because those had been too strict to do any real biological science work. Because every time you ask a question about anything to do with science it would freeze up and say that's not allowed. And they're seeing the Chinese, previously in the rear view mirror and now pretty much running all alongside the, and I think they realize that they can't get away with this, "we're so precious only we can decide who gets our magic sauce." Brandon (15:02) Yeah, especially if the competitive open models are just as powerful, maybe a little less, but essentially just as capable as some of these proprietary ones that they're arguing that they can't let out. Tobias Mann (15:15) And this is maybe a little bit on the conspiracy side of things, but seeing Meta, Anthropic, and OpenAI talking up all of these "oh our models escaped the sandbox situation," it's hard as a skeptic of this technology not to look at this and go, Is this a covert political play to scare politicians into taking action against open models? "Because at least with our models, if Uncle Sam gets uncomfortable, he can give us a call and we can lock him down. But with these open models, once they're out, they're out." Brandon (15:54) It's like Dario said this week, he's not opposed to open models except for all the open models that currently exist, right? (Laughter.) Brandon (16:02) It's like the same thing. When they say, "no, we're not trying to shut down open models," their responses always come back kind of weak... it's a lot of asterisks. Tobias Mann (16:12) Yeah," we're only opposed to the modelsthat may meet these requirements, which are all models, all competitive models." Anything that is a threat to their business shouldn't be allowed. And Dario in particular, I have frequently referenced as the fearmonger in chief of Anthropic, because he plays this game constantly. Tom Claburn (16:34) I think your point about the model stability is really important, particularly for the enterprise crowd, because there are we've already seen instances where Anthropic would change out one of its models without notice and people would just get different results. So, for companies that are building applications on top of the specific model and expect it to behave a certain way, it's just unacceptable to all of a sudden have the model disappear or have whatever is on the back end change. And so having the ability run this in your data center is going to be crucial and ultimately I think that's the way that any serious company is going to go. They're not going to want the lock-in. Maybe one or two percent of their queries are going to need advanced frontier capabilities but a lot of this is just going to be "I want my agent to behave in the same way it did last time." Brandon (17:24) Think about so much enterprise software and so much enterprise anything. When you get down to the ticky tack of it, open source is underneath a lot of it, right? That's the thing, right? No one's going to trust a Microsoft or whoever's system to run this stuff. They want open source stuff that they know they can depend on that's going to be there when they need it and that's not going to go away or suddenly be infused with Copilot, right? You can't run a business like that or else you're just asking for instability. Tom Claburn (17:55) Right. I mean and and there isn't even a long-term support version of any of these models. And yet you look at this in servers and if you're running a hosted server somewhere and you're running some Linux distribution, you're going to want to use the one that's going to be guaranteed for whatever, three, five, six years and the model space hasn't really caught on to that. That's what all the companies that they're courting really want. And so they've got to figure out a way around that. And right now open weights is what promises that. Brandon (18:26) The fact that this is still so early and it's so fundamental to this new wave of infrastructure tells me that China's definitely going to end up with a leg up, I feel like. I have a hard time seeing the frontier labs remaining the frontier of AI for much longer because they're pigeonholing themselves in a way that a lot of businesses just aren't happy with. Tobias Mann (18:48) Well, if you look at their financial structures, they don't really have a choice in how they play this. So, you look at what they're doing and from a standpoint of looking at history and going, open source has always won out in the end, and why would open weights be any different? That is contrasted against the fact that Anthropic and OpenAI in particular, not so much Google, and Meta is also in a similar camp in that they have revenue drivers that will keep them afloat. But OpenAI and Anthropic are entirely dependent on their ability to continue raising equity and capital in order to keep this going forward because they don't have profits. Brandon (19:31) Yeah, exactly. They're not making money off their product. Tobias Mann (19:37) So all they have is mind share at this point. And if they are threatened materially by open weight's models, they don't even have that. Brandon (19:46) So, open or not, let's let one the one thing that every AI model needs is information to learn from, right? And that takes me to my next topic for this podcast. And that's a story that I reported on this week that honestly I was pretty shocked when I learned about this. This German developer, Vincent Schmalbach, wrote a blog post about he found that there were basically AI-only ads embedded in sometime magazine articles when the magazine was serving markdown copies to AI crawlers, it was injecting ads into them, right? That were in the format of these extensive FAQs on the businesses that were the advertisers in this case. And so I looked into it, I found copies of the ads. It looks like there's only two kinds of ads being served right now. And that's one for an online-only bank and another for a professional organization for project management folks. But the ads are there and they're being served strictly to AI, right? So that kind of raises a lot of questions not only about the future of publishing, but also just how much we can trust results from AI bots, right? I didn't speak directly to the company who's doing this advertising partnership at Time. And Time directed me to a publication from the advertising industry that included an interview with the CEO of this company who literally basically said, "Yeah, why would I want to advertise to one human when I can affect the output of an entire model?" So it seems like this is really the first recorded instance of ad injections into AI versions of web pages being served to crawlers. And the company said they've got other advertising customers and publications lined up to do this. Is this the first indication that the human focused internet really is starting to fade? I don't know. What do you guys think? I this raises a lot of interesting questions to me, ethically, Tom Claburn (21:49) Amen. Brandon (21:50) You know, professionally... Tom Claburn (21:53) We've heard about the shift of toward automated traffic for a year plus....And companies like Cloudflare are betting really heavily on this that there's going to be some kind of need to separate the bots from the people. And, Google's model has fallen down. So it's not surprising. I mean, the injection of ads like that is essentially just model poisoning, right? I mean it's hard to see how this really goes in a way that is beneficial to users. It's going to be a very toxic way for things to move. Brandon (22:42) Yeah, absolutely. I mean, the way these FAQ ads were set up, the questions were all being asked in a way that someone prompting Google Search and getting AI results would be asking questions like, "What's just the best online bank for me?"or "what online bank allows for early paycheck deposits?" And things like that. It was very much geared toward gaming the outcome or gaming the output, right? And yeah, the ads themselves mention in the copy being served to the AI that these are sponsored portions of the page. But I can't imagine that the AI is going to make sure to tell a user that, hey, this is the bank you should use. By the way, a sponsored post I read and ingested from Time Magazine six months ago is the source of this information.It just seems like it's going to make AI results even less reliable than they are right now. Tobias Mann (23:41) Right. Because if you think about how this actually from the chain of events that triggers this, let's use Google's AI summaries as an example of how this would get triggered. When you enter a search query into Google now, it goes out and scrapes however many summaries from the websites within Google's index. Presumably under this scenario, at least one of those websites, Time in this example, would have these ads embedded in it. And then that gets injected into the context of the model, and then it uses that to generate the AI summary, right? My question in all of this is: advertising is probably not the reason that Google's index would pull that page up. So I'm really curious whether or not this even will work. Brandon (24:38) Yeah, that is true. Tobias Mann (24:39) Because, it's great if you were searching, say the time article was on mortgage rates historically, and it had those advertisements embedded in it, and then you asked a follow up on where would be the best place to get a mortgage? I could see something like that working.But if you don't place those advertisements really carefully, I don't see how they work. Brandon (25:02) I do want to note here that it wasn't working on all crawlers. Specifically if you were it didn't work when you ask a query, it didn't work for RAG bots. It wasn't being served to them. So theoretically if what you're describing is Google's AI summary bot going out and crawling web pages in the moment to look for information, it's not being served to those bots; it's being served to actual training and improvement bots. So it's being served to ClaudeBot, which is the web crawler that Anthropic uses to index information for its models. So the idea is you're not getting this information in the moment if you do a search. This is information that the advertisers want to get embedded into the LLM's actual knowledge base. Tom Claburn (25:57) Right. I mean I'd be fascinated to know how they actually price this because how do you calculate the value of that? It may just be another instance of advertising being one of those things you can pay for and get nothing. Brandon (26:12) Yeah, totally. I think it's the sort of thing that remains to be seen if this works. Tobias Mann (26:16) The other thing that is interesting is that there's been a considerable shift towards synthetic data generation, and not only synthetic data generation for training, but also a heavy emphasis on cleaning said data, whether it's organic or synthetic, of anything that could introduce bias or inaccuracies. because advertisements or sponsored content is biased towards this particular product or service and trying to convince you to use it. As a model developer, I wouldn't want something like that in there. I might take the content and use it to generate synthetic data that is cleaned. But I don't necessarily understand what the value captured to Tom's point is necessarily going to be because you scrape it, the advertisement gets pulled in and gets cleaned out. Brandon (27:14) I mean that would that would be my hope too, right? that there's something in the models to prevent this kind of thing from getting ingested and getting into the data set that then is going to influence the output of the models. And that's entirely possible. This could be an early experiment that ends up failing. And if not, it really reminds me of the early days of SEO gaming, right? Let's put a whole bunch of really small keywords at the bottom of this page to get it to rank higher. Or when that starts failing, let's figure out a new way to game Google's system. One of my first jobs was writing copy for websites and the company that I worked for was always talking about how to game SEO. Shoot, Google's changing the algorithm again; what are we going to do? It was this constant kind of adjustment for how you made sure your stuff got ranked properly.And this seems like maybe it's the next iteration of that. Tobias Mann (28:08) So I have an optimistic take on this, knowing how Meta and Google work. those being the two major US-based web advertisers. Today, AdSense gets embedded in all kinds of articles. And it's largely automated in terms of what is going to get placed on those articles based on the context of the page. What I can see happening in an AI summary environment is that Google will take your scrape your publication's piece, pull it in, at that point match it with an advertisement from AdSense, and inject that into an AI summary or one of its products, Gemini, for example. However it's being consumed, inject that into there in a compliant fashion. So it is a clear advertisement and then the advertiser gets charged, the publication gets paid, and we as end users consume advertisements in a different way, but the system hasn't dramatically changed. It's just a different method of matching and exposing advertisements. Brandon (29:30) I hope you're right. Cause when I first read all this, my first thought was this is almost dystopian sounding almost, you know, like the idea that the output of a model might be completely skewed by advertising being served to it that humans never see. My hope is that you're right and that it's not. I don't want to see ads any more than the next person, but if I see them I'd at least like to know they're ads. Tobias Mann (30:01) And you know, we're all writers here, so we would also like to continue getting paid from the advertisements that are served, regardless of whether they're on our website or they're being exposed through a chat bot. Brandon (30:15) Sure. there's a flip side of this argument to be made. Time Magazine apparently said recently that their traffic is majority bot now. So that means that all those human-focused ads are not getting served. They're not generating revenue and publishing is suffering from a massive revenue decrease because of AI. So I think on the flip side, you have to say if that's what you have to do to survive as a publisher, there might be something to be said for that, even if it doesn't work. So all right guys, well thanks for coming on this week. This was a good discussion. I think there's always going to be more to talk about in the world of AI. Like I said a couple weeks ago, it seems like The Kettle has basically just been boiling down AI news for the past couple of months, and I'm sure it's going to keep being that way. And we hope that you will tune in for the next week's episode.
|