AI-powered heist drains $1m from crypto wallets via Firefox add-ons

Hackers have stolen over $1 million in cryptocurrency using AI-generated malicious Firefox extensions disguised as legitimate wallet tools.

The group, known as GreedyBear, created over 150 fake add-ons for platforms like MetaMask and Phantom, bypassing security checks to drain funds from thousands of users. Analysts say AI enabled the attackers to automate coding and deployment at an industrial scale.

The theft comes amid a record-breaking year for crypto crime, with Chainalysis data showing over $2.17 billion stolen so far in 2025. Many incidents exploit smart contract flaws and human error, with access control attacks accounting for the most recent losses.

Security experts warn that AI is now a double-edged sword, helping attackers and defenders. They urge exchanges, developers, and users to adopt AI-powered monitoring, stronger verification, and collaborative defences to restore trust in digital assets.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

Why AI coding tools may follow the path of past tech revolutions

In mid-2025, the debate over AI in programming mirrors historic resistance to earlier breakthroughs in computing. Critics say current AI coding tools often slow developers and create overconfidence, while supporters argue they will eventually transform software creation.

The Register compares this moment to the 1950s, when Grace Hopper faced opposition to high-level programming languages. Similar scepticism greeted technologies such as C, Java, and intermediate representation, which later became integral to modern computing.

Current AI tools face limits in resources, business models, and capability. Yet, as past trends show, these constraints may fade as hardware, training, and developer practices improve. Advocates believe AI will shift human effort toward design and problem definition rather than manual coding.

For now, adoption remains a mixed blessing, with performance issues and unrealistic expectations. But history suggests that removing barriers between ideas and results catalyses lasting change.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

Users warned to update WinRAR after active attacks

A critical flaw in the Windows version of WinRAR is being exploited to install malware that runs automatically at startup. Users are urged to update to version 7.13 immediately, as the software does not update itself.

Tracked as CVE-2025-8088, the vulnerability allows malicious RAR files to place content in protected system folders, including Windows startup locations. Once there, the malware can steal data, install further payloads and maintain persistent access.

ESET researchers linked the attacks to the RomCom hacking group, a Russian-speaking operation known for espionage and ransomware campaigns. The flaw has been used in spear-phishing attacks where victims opened infected archives sent via email.

WinRAR’s July update fixes the cybersecurity issue by blocking extractions outside user-specified folders. Security experts recommend caution with email attachments, antivirus scanning of archives and regular checks of startup folders for suspicious files.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

New Instagram Map lets users share location with consent

Instagram has introduced an opt-in feature called Instagram Map, allowing users in the US to share their recent active location and explore location-based content.

Adam Mosseri, head of Instagram, clarified that location sharing is off by default and visible only when users choose to share.

Confusion arose as some users mistakenly believed their location was automatically shared because they could see themselves on the map upon opening the app.

The feature also displays location tags from Stories or Reels, making location-based content easier to find.

Unlike Snap Map, Instagram Map updates location only when the app is open or running in the background, without providing continuous real-time tracking.

Users can access the Map by going to their direct messages and selecting the Map option, where they can control who sees their location, choosing between Friends, Close Friends, selected users, or no one. Even if location sharing is turned off, users will still see the locations of others who share with them.

Instagram Map shows friends’ shared locations and nearby Stories or Reels tagged with locations, allowing users to discover events or places through their network.

Additionally, users can post short, temporary messages called Notes, which appear on the map when shared with a location. The feature encourages cautious consideration about sharing location tags in posts, especially when still at the tagged place.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

UAE Ministry of Interior uses AI and modern laws to fight crime

The UAE Ministry of Interior states that AI, surveillance, and modern laws are key to fighting crime. Offences are economic, traditional, or cyber, with data tools and legal updates improving investigations. Cybercrime is on the rise as digital technology expands.

Current measures include AI monitoring, intelligent surveillance, and new laws. Economic crimes like fraud and tax evasion are addressed through analytics and banking cooperation. Cross-border cases and digital evidence tampering continue to be significant challenges.

Traditional crimes, such as theft and assault, are addressed through cameras, patrols, and awareness drives. Some offences persist in remote or crowded areas. Technology and global cooperation have improved results in several categories.

UAE officials warn that AI and the internet of Things will lead to more sophisticated cyberattacks. Future risks include evolving criminal tactics, privacy threats, skills shortages, and balancing security and individual rights.

Opportunities include AI-powered security, stronger global ties, and better cybersecurity. Dubai Police have launched a bilingual platform to educate the public, viewing awareness as the first defence against online threats.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

OpenAI restores GPT-4o option for Plus subscribers after feedback

OpenAI will make its GPT-4o model available again for ChatGPT Plus subscribers after replacing it with GPT-5, following complaints from users who said the change was abrupt and unwelcome.

Chief executive Sam Altman confirmed that subscribers can choose between the two models, adding that the company will monitor usage before deciding how long to keep older versions available.

The decision comes days after the debut of GPT-5, which was introduced without the option to select previous models manually.

Some users said they valued the continuity and emotional connection they had formed with GPT-4o, describing it as unique and meaningful instead of simply replaceable. Others preferred having the freedom to select a model manually rather than relying on a default.

Altman acknowledged that GPT-5’s performance appeared weaker at times, attributing it partly to a temporary malfunction in the automatic switching system.

He also said adjustments are being made to improve how the system selects the most suitable model in different scenarios.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

Nvidia and AMD to pay 15% share of China AI chip revenue to secure US export licences

Nvidia and Advanced Micro Devices have agreed to hand 15% of their Chinese AI chip sales revenue to the US government in return for export licences.

The arrangement, covering Nvidia’s H20 accelerator and AMD’s MI308 model, is considered unusual and could prove contentious for both companies and Beijing.

The deal reflects Washington’s willingness to link trade concessions to financial payments, but analysts note there is little precedent for such a targeted export levy.

Critics warn the move could undermine the national security rationale for export controls, making it harder to convince allies to adopt similar measures. Beijing, meanwhile, has voiced security concerns over the H20 chip’s performance and alleged vulnerabilities.

Industry observers suggest the payment requirement could discourage further expansion by US chipmakers in China, the world’s largest semiconductor importer, and give local producers an advantage in building domestic capacity.

Chinese firms such as Huawei are already increasing market share amid tighter restrictions on US technology.

The potential sums involved are significant. Before restrictions were imposed, Nvidia had generated over $7 billion in H20 sales to China in a single quarter. In comparison, AMD could earn up to $5 billion annually if full access to the market resumed.

However, uncertainties over demand and regulatory conditions remain.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

Kiwi.com eyes agentic AI future with new booking technology

Kiwi.com has unveiled an AI-powered system that enables direct airline bookings, partnering with AIpic to launch the industry’s first Model Context Protocol (MCP) server. However, this technology links flight inventory directly with major AI platforms.

MCP is an open standard likened to a ‘USB-C for AI’. It lets large language models access real-time services beyond their pre-trained data. The access enables AI agents to search and book flights on a user’s behalf.

Kiwi.com says the technology positions it to capture growing demand, as consumers increasingly use AI platforms like ChatGPT, Claude, and Microsoft Copilot to plan travel. Experts anticipate that agentic AI systems will become the dominant interface for online services.

With MCP, users can request flights in natural language, specifying dates, destinations, passenger numbers, and cabin preferences. The AI agent accesses Kiwi.com’s inventory, returning curated results in the user’s preferred currency and time zone and an instant booking link.

The company considers the integration a new distribution channel and a potential model for other online travel agencies. It adapts to changing search and booking behaviours driven by AI.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

BlackSuit infrastructure dismantled in global raid

US law enforcement, alongside nine other nations, dismantled the BlackSuit ransomware gang’s infrastructure, replacing its leak site with a takedown notice after a coordinated operation. The group, formerly known as Royal, had amassed over $370 million in ransoms since 2022.

More than 450 victims were targeted across critical infrastructure sectors, with ransom demands soaring up to $60 million. Dallas suffered severe disruption in a notable attack, affecting emergency services and courts.

German authorities seized key infrastructure, securing data that is now under analysis to identify further collaborators. The operation also included confiscating servers, domains and digital assets used for extortion and money laundering.

New research indicates that members of BlackSuit may already be shifting to a new ransomware operation called Chaos. US agencies seized $2.4 million in cryptocurrency linked to a Chaos affiliate, marking a significant blow to evolving cybercrime efforts.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

GitHub CEO says developers will manage AI agents

GitHub’s CEO, Thomas Dohmke, envisions a future where developers no longer write code by hand but oversee AI agents that generate it. He highlights that many developers already use AI tools to assist with coding tasks.

Early adoption began with debugging, boilerplate and code snippets, and evolved into collaborative brainstorming and iterative prompting with AI. Developers are now learning to treat AI tools like partners and guide their ‘thought processes’.

According to interviews with 22 developers, half expect AI to write around 90 percent of their code within two years, while the rest foresee that happening within five. The shift is seen as a change from writing to verifying and refining AI-generated work.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!