ZeroHour

Search: “Overture VC”

28 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

ZDI-26-642: Oracle VirtualBox IDisplay Out-Of-Bounds Read Local Privilege Escalation Vulnerability

ZDI publishes ZDI-26-642 for CVE-2026-60159, an out-of-bounds read local privilege escalation in Oracle VirtualBox IDisplay, rated CVSS 7.5.

Zero Day Initiative published advisory ZDI-26-642 describing an out-of-bounds read in Oracle VirtualBox's IDisplay component that enables local privilege escalation. Attackers must first obtain the ability to execute high-privileged code on the target guest system. ZDI rated the issue CVSS 7.5 and assigned CVE-2026-60159.

YuE2 · Frontier Music with Symbolic Planning

YuE2, a 3.59B-parameter music generation model, scores 6.9632 on SongBench, beating Suno v5 via symbolic planning.

YuE2 is a music generation model of roughly 3.59B parameters and 28 layers supporting song creation, covering, and agentic editing through editable ABC symbolic scores. Its best-of-8 setting reaches 6.9632 on SongBench, the highest mean among 15 evaluated settings on WildSongBench (192 prompts), ahead of Suno v5 at 6.8721. The project also introduces MERT2, whose 632M-parameter encoders achieve state of the art on 14 of 15 MARBLE metrics, and SheetSage2, which transcribes beats, downbeats, key, chords, structure, and melody with SOTA on 10 of 13 benchmark metrics.

Hacker News · AIupdated · 6d agofirst · 6d agoModel release 2 sourcesHN 43↑ · 35 comments

Besxar is building an orbital semiconductor factory, one SpaceX rocket at a time

Besxar, founded by a former OpenAI staffer, raised ~$14M to prototype semiconductor manufacturing in orbit using SpaceX Falcon 9 booster flights.

Besxar, founded by former OpenAI staffer Ashley Pilipiszyn, raised almost $14 million, including a $9 million seed led by Dauntless Ventures and Overture VC, to build orbital semiconductor fabrication. Its first two "fabship" canisters flew on a July Starlink mission and returned wafer samples cleaner than comparable terrestrial wafers. The company plans to iterate over two years with a dozen Falcon 9 booster flights before flying larger fabs on Starship, targeting wafers for power-regulation chips used in data centers, robots, and electric vehicles.

TechCrunch · AI · 7d agoAI industry

StepAudio 3 Gen Technical Report

StepAudio 3 Gen unifies TTS, voice design, music, and sound effects via discrete autoregressive modeling over RVQ tokens.

StepAudio 3 Gen is a general-purpose audio generation model covering zero-shot TTS, voice design, vocal generation, sound effects, music, vibe speech, and mixed audio in one framework. It uses discrete autoregressive modeling over residual vector quantization (RVQ) tokens rather than the diffusion Transformer paradigm, with a StepAudio Tokenizer representing audio at 12.5 Hz in a shared 16x2048 residual code space. Key design principles include interference-aware progressive pretraining, an RVQ Adaptor for multi-codebook acoustic representations, and shared discrete autoregressive modeling. The model reports state-of-the-art performance on TTS and voice design while retaining strong generation across speech, vocals, sound effects, and music.

Hugging Face daily papers · 6d agoAI research

OpenVDN/vdn-minimax-h3 — new model trending #12 on Hugging Face

OpenVDN releases VDN-H3, an open hybrid-attention video model on MiniMax H3 that renders a 14.4-second 768p clip in 11.23 seconds on 8 B200 GPUs.

VDN-Minimax-H3 (VDN-H3) adds a frame-wise linear attention branch plus two LoRA adapters to MiniMax H3, distilled into 8-step and 50-step variants. It generates 768p, 14.4-second clips in 11.23 seconds on 8 B200 GPUs (90.5 seconds on one H200) using 8 denoising steps. Weights (about 82 GB total, including the 72 GB H3 base), the optimized inference stack, and training code are fully open-source under the MiniMax H3 Community License, which excludes the EU, UK, Korea, and US.

Hugging Face trending models · 14d agoModel release1

vCenter Flaw Exploited Just Five Days After Disclosure

Attackers began exploiting critical vCenter flaw CVE-2026-59310 five days after Broadcom's disclosure, putting enterprise VMware deployments at risk.

Attackers exploited a critical-severity flaw in VMware vCenter, tracked as CVE-2026-59310, just five days after Broadcom disclosed it. vCenter is the management platform for large enterprise VMware virtualization estates, so active exploitation exposes a broad installed base. Defenders running vCenter should prioritize applying Broadcom's patch.

Infosecurity Magazine · Aug 13, 2026Exploit / PoC in the wildCVE-2026-59310

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patches three critical VMware flaws, including vCenter auth bypass CVE-2026-59309 and an ESX VM escape, urging immediate updates.

Broadcom issued emergency updates for VMware ESX, vCenter, Workstation and Fusion, fixing five flaws including CVE-2026-59309 (CVSS 9.8 authentication bypass in vCenter) and CVE-2026-59310 (CVSS 9.8 directory traversal allowing code execution). CVE-2026-47876 (CVSS 9.3) is an out-of-bounds write in the ESX VMXNET3 adapter that permits a virtual machine escape to the host. Broadcom found no evidence of exploitation, but Defused Cyber reported a spike in vCenter scanning on August 11, 2026 consistent with exploitation attempts against CVE-2026-59309 (VMSA-2026-0006). No workarounds are available.

StepAudio 3 Music Technical Report

StepAudio 3 Music introduces long-form text-controlled music generation using ABC-notation planning and flow-matching diffusion, ranking near the top music arena.

StepAudio 3 Music generates long-form, text-controlled music using a 50-Hz single-codebook tokenizer with 65,536 entries and a flow-matching diffusion Transformer over VAE latents. A Mixture-of-Experts autoregressive model first plans an arrangement in ABC notation (ABC-CoT) before predicting music tokens. With DPO fine-tuning, it tops AudioBox content and production quality scores and reaches Quality Elo 1105 on the Artificial Analysis Music Arena, behind Suno V5.5 and Mureka. Generation covers songs, accompaniment from dry vocals, and cover synthesis up to 5 minutes 30 seconds at 48-kHz output.

Hugging Face daily papers · 6d agoAI research

Multiple Vulnerabilities Discovered in a SCADA System

Unit 42 details five vulnerabilities (CVSS 7.0-7.8) in ICONICS Suite SCADA software enabling privilege escalation and DoS.

Unit 42 discovered five vulnerabilities (CVE-2024-1182, CVE-2024-7587, CVE-2024-8299, CVE-2024-8300, CVE-2024-9852) in ICONICS Suite versions 10.97.2 and earlier for Windows during a 2024 security assessment. The flaws, rated CVSS 7.0-7.8, allow DLL hijacking, privilege escalation, information disclosure, denial-of-service and potentially full system compromise. ICONICS Suite is a SCADA solution with hundreds of thousands of installations in over 100 countries, widely used in critical infrastructure, and several dozen servers are internet-exposed per Unit 42 telemetry. ICONICS released patches and advisories with workarounds in 2024.

m-a-p/YuE2-3B — new model trending #30 on Hugging Face

M-A-P released YuE2-3B, an open music generation model that outperforms Suno v5 on WildSongBench and runs locally on a 24GB GPU.

The M-A-P (multimodal-art-projection) team released YuE2-3B, an open-weights music generation model that turns lyrics and a style prompt into full songs with vocals and accompaniment. It uses an AR-NAR Mixture-of-Transformers backbone with symbolic planning and flow matching through a VAE, and supports editable scores (melody and chords, including ABC notation) plus agentic editing workflows. On 192 WildSongBench prompts it reports a SongBench average of 6.9632 (best-of-8) versus 6.8721 for Suno v5, claimed as state of the art among evaluated open and proprietary models. It runs 48 kHz stereo inference locally on a single 24GB NVIDIA GPU without quantization, with companion releases including YuE2-Vae, MERT-v2 encoders, the WildSongBench dataset, and SheetSage2.

Hugging Face trending models · 7d agoModel release1

ZDI-26-617: Microsoft Windows MIDI Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability

ZDI disclosed CVE-2026-66804, a CVSS 7.8 incorrect permission assignment in Windows MIDI Service allowing local privilege escalation.

Zero Day Initiative advisory ZDI-26-617 details an incorrect permission assignment flaw in the Microsoft Windows MIDI Service. An attacker with the ability to run low-privileged code on an affected system can escalate privileges. ZDI rated the issue CVSS 7.8; the advisory provides no evidence of active exploitation.

ZDI-26-608: Linux Kernel KVM IOAPIC Use-After-Free Local Privilege Escalation Vulnerability

The Linux kernel KVM IOAPIC has a use-after-free (CVSS 8.2) allowing local privilege escalation, but exploitation requires high-privileged code execution first.

ZDI-26-608 describes a use-after-free vulnerability in the Linux kernel's KVM IOAPIC component, with a CVSS score of 8.2. An attacker must first obtain the ability to execute high-privileged code on the target system, which limits the practical impact of the privilege escalation. The advisory text does not list an assigned CVE identifier.

ZDI Published Advisories · 23d agoVulnerability

[vim-security] Ex Command Injection in sign_jump() in Vim < v9.2.1090

Vim sign_jump() before v9.2.1090 permits Ex command injection via unescaped buffer names; low-severity patch disclosed by Christian Brabandt.

Christian Brabandt disclosed an Ex command injection vulnerability in Vim's sign_jump() function affecting versions before v9.2.1090, caused by improper neutralization of unescaped buffer names. The issue is rated Low severity and maps to CWE-88 (argument injection) and CWE-94 (code injection). A CVE has been requested but not yet assigned.

oss-security · 4d agoVulnerability

Elevenlabs makes Music v2.5 available via app and API with free and pro tier options

ElevenLabs releases Music v2.5 via app and API, claiming fuller, more natural songs preferred over v2 in blind listening tests.

ElevenLabs launched Music v2.5 for ElevenMusic, reporting that listeners preferred it in a blind test across 47,885 comparison pairs, especially for R&B, Soul, Hip-Hop, Rock, and orchestral tracks. The free tier offers five lossless downloads per day and Pro includes 400 per month, with attribution required on free and commercial use restricted by industry. Tracks based on other artists' songs are blocked, and v2 remains available alongside the API. ElevenLabs says existing Music models were trained on 'licensed stems and music,' distinguishing it from competitor Suno, which faces lawsuits for training on copyrighted content; a Universal Music Group licensing deal covers only future separate products.

The Decoder · 3d agoAI industry

Roland is getting into generative AI music with Melody Flip

Roland launched Melody Flip, a DAW plugin that generates genre-themed MIDI loops rather than complete songs like Suno or Udio.

Roland's Melody Flip is a DAW plug-in offering around 250 genre-based 'Palettes' for generating melodies, chord progressions, basslines, and drum patterns, either from scratch or derived from a reference track. Users can control genre, note density, BPM, and key but cannot use text prompts, and outputs are simple loops with General MIDI-style tones intended for MIDI export into a DAW. The launch follows well-received hardware releases like the SH-4d, Gaia 2, and TR-1000, though music-community sentiment toward generative AI may limit goodwill.

The Verge · AI · 12d agoAI industry

Privileged File System Vulnerability Present in a SCADA System

Unit 42 details CVE-2025-0921 (CVSS 6.5), a privileged file operations flaw in Iconics Suite enabling DoS and privilege escalation.

Unit 42 disclosed CVE-2025-0921 (CVSS 6.5), an execution-with-unnecessary-privileges flaw in the Pager Agent of the AlarmWorX64 MMX feature of Mitsubishi Electric Iconics Digital Solutions GENESIS64. Attackers could misuse privileged file system operations to corrupt critical binaries, causing denial-of-service or integrity loss on vulnerable SCADA systems. The analysis demonstrates a chain with CVE-2024-7587, which grants excessive permissions to the C:\ProgramData\ICONICS directory via the GenBroker32 installer. Iconics released an advisory with a workaround that addresses the reported issues.

Suno releases its first AI music model made with record industry help

Suno released its v6 music model family (v6, v6-wild, v6-mini), the first trained with licensed data from Warner Music Group, BMG, and Believe.

Suno's v6 comes in three variants: v6, the more unpredictable v6-wild, and resource-light v6-mini offered free to all users. The model was trained from the ground up on a new dataset including licensed content from Warner Music Group, BMG, and Believe, plus user data, though it is unclear if all dubiously obtained content was excluded. v6 shows dramatically improved genre fidelity, adds plain-language chat editing of individual song elements, multi-element mashups, and prompts based on images, video, or audio. The Verge notes it still cannot produce intentional imperfections like off-key vocals, and v6 starts rolling out now with older models eventually retired.

The Verge · AI · 7d agoModel release

[0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8)

QuantaStor 6.8.3.018 has a CVSS 8.8 command injection in its alert-mail command, exploitable via the smtpPassword field.

0day Rubbish Research Team disclosed a command injection (CWE-78) in QuantaStor 6.8.3.018's alert-mail command, reachable through the smtpPassword field. The flaw scores CVSS 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). No CVE identifier or evidence of active exploitation is mentioned in the disclosure.

Full Disclosure · 8d agoVulnerability 2 sources

ZDI-26-567: Norton Utilities Ultimate NortonUtilitiesSvc Link Following Local Privilege Escalation Vulnerability

ZDI discloses CVE-2024-13962, a CVSS 7.8 link-following local privilege escalation flaw in Norton Utilities Ultimate's NortonUtilitiesSvc service.

The Zero Day Initiative published ZDI-26-567, a local privilege escalation vulnerability in Norton Utilities Ultimate. An attacker must already be able to execute low-privileged code on the system before exploiting the symlink/link-following flaw in NortonUtilitiesSvc. The issue carries a CVSS score of 7.8 and is tracked as CVE-2024-13962.

ZDI Published Advisories · Aug 13, 2026AdvisoryCVE-2024-13962

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Attackers actively exploit critical VMware vCenter flaw CVE-2026-59310, installing reverse_ssh backdoors on 361 hosts across 47 countries.

QUIRSO observed active exploitation of CVE-2026-59310 (CVSS 9.8), a directory-traversal flaw in VMware vCenter allowing arbitrary code execution, patched by Broadcom in late July. Attack chains deploy a malicious cron job running the open-source reverse_ssh tool for persistence, with compromised systems phoning home starting August 3, five days after disclosure. Forensics show 361 unique victim IPs in 47 countries, mostly Germany, the U.S., Turkey, Iran, and France, with the actor suspected to be an APT. Separately, Defused Cyber reports rising scanning indicative of exploitation of related CVE-2026-59309, an unauthenticated auth bypass in vmdir.

The Hacker News · Aug 12, 2026Exploit / PoC in the wildCVE-2026-59310CVE-2026-59309

Coop – Isolated VM Environments for Running Claude Code and Codex

Trail of Bits releases Coop, running Claude Code and OpenAI Codex agents inside isolated virtual machines for safer agentic coding.

Coop, published on GitHub by security firm Trail of Bits, provides isolated VM environments for executing AI coding agents such as Claude Code and Codex. Isolation contains the filesystem and network side effects of autonomous agent actions, reducing risk from unsupervised tool use. The project drew 61 points and 16 comments on Hacker News.

Suno launches v6 music models built with Warner, BMG, and Believe

Suno launches v6, v6-wild, and free v6-mini music models co-developed with Warner Music Group, BMG, and Believe, retiring all older models.

Suno's flagship v6 serves Pro and Premier subscribers, v6-wild targets experimentation, and v6-mini is free; all three understand vocals, instrumentation, structure, mood, and multimodal inputs, with text-based editing of individual song sections. The models were built with Warner Music Group, BMG, and Believe following Warner's November 2025 licensing settlement, while Universal and Sony continue litigating and a Munich court found v3.5 and v4 infringed six works. Suno reports more than 100 million users, over two million paying subscribers, and $300 million ARR after raising $400 million at a $5.4 billion valuation in June.

The Decoder · 7d agoModel release

Cadence: Error-Bounded Lossy Compression of Demand Time Series with a Time-Series Foundation Model

Cadence pairs Google's 330M-parameter TimesFM-3 foundation model with adaptive arithmetic coding, gaining 13-28% on 2026 demand series over classical predictors.

Cadence is an error-bounded lossy compressor for numeric time series combining the 330M-parameter Google TimesFM-3 foundation model with an adaptive arithmetic coder, guaranteeing a per-sample error bound. On 49 EIA-930 balancing-authority demand series from 2026 it gains 13.3% over the best of six classical predictors and 28.3% on 50 MTA ridership series, winning all 297 series-tolerance pairs with a 21.4% median gain. The paper also reports negative results, including that foundation models add negligible value for lossless coding and that PyTorch predictions are not bit-identical across batch sizes.

Hugging Face daily papers · 12d agoAI research1

ZDI-26-606: Microsoft Windows Compatibility Appraiser Link Following Local Privilege Escalation Vulnerability

ZDI disclosed a link-following flaw in Windows Compatibility Appraiser (CVSS 7.0) enabling local privilege escalation from the LOCAL SERVICE context.

ZDI-26-606 describes a link-following vulnerability in the Windows Compatibility Appraiser component that permits local privilege escalation. An attacker must already be able to execute low-privileged code in the LOCAL SERVICE context on the target system. ZDI rated the issue 7.0 on the CVSS scale; the advisory lists no CVE identifier. No active exploitation is reported.

ZDI Published Advisories · 23d agoVulnerability2

A Vinyl Bar in Shibuya is a startup from a former Spotify leader for making music apps

Former Spotify innovation head raises $5.5M pre-seed for A Vinyl Bar in Shibuya, a startup building playful music-creation apps with selective generative AI features.

A Vinyl Bar in Shibuya, founded by former Spotify head of innovation Máuhan M Zonoozy, raised a $5.5M pre-seed round from Mantis VC, SV Angel, Boxgroup, Quiet Capital and others. The startup ships small music-play apps including Speed Surfer, Usersound, Stacks, Drops, Sampler, and the iOS mixer app bop, plus a new prompt-based sound creation feature. Zonoozy says the company deliberately avoids infusing AI into every product, arguing human taste and participation become more valuable as AI-generated content grows abundant.

TechCrunch · AI · 2d agoAI industry 2 sources

Viggle/Viggle-Animate — new model trending #28 on Hugging Face

Viggle released Viggle-Animate, a 33.1B MiniMax-H3 finetune replacing video characters from one repainted frame, rendering 124 frames in 26 seconds on one GPU.

Viggle-Animate replaces the character in a video using only a driving video and one of its own repainted frames, with no pose estimator, segmentation mask, face tracker, or text encoder. It is a 33.1B full finetune of MiniMax-H3's ref2va transformer, jointly distilled with DMD across two teachers split by noise level, so rendering takes three forward passes per clip. On a B200 GPU it renders 124 frames in 26 seconds, 6.1x faster per clip than Wan2.2-Animate-14B in matched comparisons. The method assumes no person-specific representation, so it generalizes beyond humans; a demo, research write-up, and ComfyUI nodes are available.

Hugging Face trending models · 16d agoModel release1

ZDI-26-647: VMware Workstation VMXNET3 TSO Segmentation Integer Overflow Local Privilege Escalation Vulnerability

ZDI disclosed an integer overflow in VMware Workstation's VMXNET3 TSO code (CVE-2026-59346) enabling local privilege escalation.

Zero Day Initiative published ZDI-26-647, a CVSS 7.5 integer overflow in the VMXNET3 TSO segmentation code of VMware Workstation. A local attacker who has already obtained the ability to execute high-privileged code on the guest system can exploit the flaw to escalate privileges on affected installations. The issue is tracked as CVE-2026-59346. No exploitation is reported in the advisory.