Dario Amodei wants a speed limit for frontier AI. Elon Musk and Sam Altman back the direction, but Washington says the labs should brake first. As China shapes the race, Cyber News Centre examines whether independent oversight can turn safety promises into controls before a new agent swarm escapes.
Meta’s Muse is more than a chatbot. It is a digital worker that can read email, make purchases across the web, and act after users close the app. Wall Street sees a return on Meta’s vast AI spending. Cybersecurity experts see a more urgent question: should it hold the keys to our digital lives yet?
Dell’s US$95 billion AI-server backlog and US$74 billion revenue outlook show the AI boom moving beyond a few cloud giants into enterprise, sovereign and neocloud infrastructure procurement.
9th March 2026 Cyber Update: Google Patches Actively Exploited Android Zero-Day
Google's March 2026 Android update patches a critical zero-day (CVE-2026-21385) in Qualcomm chips used in hundreds of millions of devices. The flaw, under active exploitation, allows privilege escalation and system compromise, posing a significant risk to users.
Cyber News Centre's cyber update for 9th March 2026: Google has released an urgent security update for Android devices to patch a critical zero-day vulnerability in Qualcomm chipsets that is under active attack.
The Update and Why It Matters
Update: Google has confirmed that a high-severity vulnerability, tracked as CVE-2026-21385, is being actively exploited in targeted attacks against Android users. The flaw resides in a graphics component of over 235 unique Qualcomm chipsets, affecting hundreds of millions of devices globally, including a significant number in Australia. The vulnerability is a memory corruption issue caused by an integer overflow in the Qualcomm display driver that can be triggered by a local attacker to escalate privileges and potentially take full control of a device.
The bug was first reported to Qualcomm by Google's Android Security team on December 18, 2025, and Qualcomm notified its customers on February 2, 2026. Google's March 2026 Android Security Bulletin, released last week, includes a patch for this zero-day as part of the 2026-03-05 security patch level, which addresses 129 vulnerabilities in total.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-21385 to its Known Exploited Vulnerabilities (KEV) catalog on March 3, mandating that U.S. federal agencies patch the flaw by March 24, 2026. While Google has released the fix, the actual delivery of the update to end-users depends on device manufacturers and mobile carriers, creating a window of exposure for many users.
Why it Matters: The active exploitation of CVE-2026-21385 represents a direct and immediate threat to Android users. A successful attack could lead to the complete compromise of a device, allowing attackers to steal sensitive personal and corporate data, monitor communications, and deploy further malware. The vulnerability's presence in over 235 chipsets creates a massive attack surface, and the delay between Google's patch release and its implementation by various manufacturers leaves many users unprotected.
For businesses with employees using Android devices for work, this vulnerability poses a significant corporate security risk. The limited, targeted nature of current attacks suggests high-value individuals and organisations are the primary targets, consistent with commercial spyware operations. Android users should immediately check their device's security patch level under Settings and apply the 2026-03-05 patch or later as soon as it becomes available from their device manufacturer.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
OpenAI's Astra can develop zero-day exploits, while a US$1 billion defence push seeks to give critical infrastructure teams the same machine-speed advantage.
The AI race is moving beyond model rankings. CrowdStrike’s new cyber superintelligence lab points to a market where proprietary data, trusted workflows and measurable outcomes may matter as much as raw capability.
Washington is building a two-track AI order: confidential security reviews for powerful closed models, regulatory relief for open-weight systems, and a G20 campaign for light-touch rules. The strategy may accelerate US innovation, but leaves a critical security gamble unresolved for global markets.
US authorities have dismantled QTFY’s QScan and QTRouter platforms, exposing a China-linked service model that blended exploit trading, automated scanning and hijacked IoT devices to reach critical infrastructure while concealing where attacks began.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!