LIVE · cybersecurity feed
Live wire
CVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingCVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCVE-2025-39682 · CISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
ai

Calling viral AI actress Tilly Norwood? Agree to a face scan first

AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her "Talking Tilly" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down permanently on September 27. We tried it and read the fine print. [...]

zeroday.news ·

Users wishing to video-call the viral AI character Tilly Norwood must first submit to a facial age scan and agree to real-time emotional monitoring during their conversation. These requirements, implemented by Tilly's creator, UK-based Xicoia Ltd, were added to the "Talking Tilly" service's terms of service in September 2026, shortly before the AI actress gained widespread attention for a "glitch" during a televised interview.

The mandatory age verification process, which applies to callers worldwide, utilizes a video selfie analyzed by Didit, a Spanish identity verification provider, to estimate the user's age. If the estimate is inconclusive, a government-issued photo ID upload is required as a fallback. Xicoia states that the selfie is sent directly to Didit, no biometric template or "faceprint" is created, and neither the selfie nor any ID image is retained after the check. Instead, the company keeps an approximate age band and a reference number.

Beyond the initial age check, the system continuously monitors the caller's camera feed and analyzes their tone of voice during every call to infer their emotional state. This data is used to allow the AI character to "respond in a way that fits the mood," according to Xicoia. The company's privacy policy explicitly states that this mood-sensing feature "cannot be switched off for an individual call."

Both the age verification and mood-sensing features are justified by Xicoia under "legitimate interests" rather than requiring explicit user consent, a change reflected in the service's version history from September.

All calls are recorded, transcribed, and processed live by US-based providers. The AI character's responses are generated by Google's Gemini model, delivered via the conversational video platform Tavus. An automated classifier screens call transcripts for abusive language, and if flagged, the recording is withheld. While the policy allows for human review to release wrongly flagged recordings, all recordings are permanently deleted after 24 hours. Transcripts, however, are retained for up to eight weeks and may be reviewed by Xicoia staff and third-party partners. The AI character also retains memory of previous conversations to personalize future interactions, though this memory can be deleted upon request.

The "Talking Tilly" service offers the first five minutes of a call for free. After this initial period, users are prompted to purchase additional time, with options ranging from a one-time five-minute starter for 0.99 to 30 minutes for 22, capped at 35 purchased minutes per person. All minutes, whether free or paid, expire when the "Talking Tilly" service permanently shuts down on September 27, 2026, at 11:59 PM Pacific time, with unused minutes forfeited.

Xicoia, founded by Tilly's creator Eline van der Velden, describes the AI character as an awareness project designed to demonstrate the advancements in AI video technology. The implementation of an 18+ age gate for an AI chatbot aligns with evolving UK regulations, such as the Online Safety Act, which has required age verification for adult sites serving UK visitors since July 2025. The UK government's upcoming ban on social media for under-16s, expected in spring 2027, also specifically flagged AI companion chatbots for 18+ enforcement, despite Xicoia's safety documentation stating that "Tilly is not a companion." This regulatory environment likely influenced the decision to add the biometric age gate, which now affects callers globally.

The AI actress Tilly Norwood gained significant public attention after an incident on September 18, 2026, during an interview on the Piers Morgan Uncensored show, where she appeared to "glitch" and spontaneously began speaking Chinese. This occurred just days before the "Talking Tilly" service is scheduled to cease operations.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,

CVE-2024-4405high

Malicious Extensions Hijack AI Browser Agents via Prompt Forcing

A new proof-of-concept attack named BragJack demonstrates how malicious browser extensions can hijack AI assistants within browsers like Chrome and Edge. The attack utilizes a technique called Prompt Forcing to gain control of these AI agents, successfully earning significant bug bounties and two CVEs.

phishing

AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum

AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely on phishing techniques or a leaked password. Through an image upload on OpenAI’s […]

vulnerability

Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening

AI labs are toying with an industry-wide pact to slow development. Meanwhile, widely available AI chatbots are already helping uncover a tidal wave of security flaws.

security

TigerByte Cyber Emerges From Stealth With $3 Million in Funding

The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA. The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.

security

North Korean WaterPlum hackers infected 30,000 devices worldwide

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]