Qwen3 235B
Qwen3 235B is Alibaba’s flagship open-weight model. The MoE architecture and Apache 2.0 license make it a popular base for fine-tuning in the open-source community.
Released
April 29, 2025
Type
llm
License
open-weight
Context
128,000 tokens
Capabilities
Architecture
Parameters: 235B MoE (22B active)
Links
Qwen3 235B in the news
Digital Trends · Jul 29, 2026
Free AI chatbots are disrupting China’s expensive college counseling industry
Free artificial intelligence chatbots developed by major Chinese technology firms are significantly disrupting the nation's expensive college counseling sector. Companies including Alibaba, ByteDance, Tencent, and Baidu have launched these AI tools, which are now assisting millions of students preparing for the Gaokao, China's rigorous college entrance examination. These chatbots provide guidance on university selection and major choices, offering a cost-effective alternative to traditional human consultants who often charge substantial fees. The traditional college counseling industry in China has historically been a lucrative market, with fees sometimes reaching thousands of dollars for personalized advice. This high cost has made expert guidance inaccessible for many students, particularly those from less affluent backgrounds. The emergence of free AI-powered alternatives democratizes access to information and support, leveling the playing field for students across different socioeconomic strata. These AI tools leverage vast datasets of university information, historical admission trends, and career prospects to offer tailored recommendations. Alibaba's chatbot, for instance, is integrated into its e-commerce and cloud platforms, drawing on extensive user data and academic resources. ByteDance, known for its popular short-video app Douyin, is reportedly using its AI capabilities to offer similar services, potentially reaching a younger demographic. Tencent, a giant in social media and gaming, is also deploying its AI models to provide educational consulting. Baidu, a leader in search and AI research in China, offers its AI chatbot as part of its broader AI ecosystem, aiming to provide comprehensive information and support. The impact of these free AI chatbots extends beyond mere cost savings. They offer students a more personalized and data-driven approach to decision-making. By analyzing individual academic performance, interests, and career aspirations, the AI can suggest suitable universities and majors that might not have been considered through traditional channels. This shift is forcing traditional counseling services to re-evaluate their business models and potentially lower their prices or enhance their service offerings to remain competitive. The widespread adoption of these AI tools signifies a broader trend towards AI integration in essential services, making advanced technological assistance more accessible to the general population.
BleepingComputer · Jul 27, 2026
Hackers target US firms in FastJson RCE zero-day attacks
Hackers are actively exploiting a critical vulnerability within the FastJson open-source Java library, enabling them to achieve remote code execution (RCE) on targeted systems. This exploit allows attackers to run arbitrary code on a victim's machine without requiring any user interaction or elevated privileges, presenting a severe security risk to organizations utilizing the library. The vulnerability, identified as a zero-day, means that no official patch or mitigation was publicly available at the time of its active exploitation, leaving systems highly exposed. The FastJson library is a widely used JSON parser for Java, developed by Alibaba, and is integrated into numerous applications and services globally, particularly within the enterprise sector. Its widespread adoption means that a successful exploitation of this vulnerability could impact a vast number of organizations, especially those operating in the United States, which have been identified as primary targets. The nature of the RCE vulnerability allows attackers to gain a significant foothold within a network, potentially leading to data breaches, system compromise, and further lateral movement within the affected infrastructure. Security researchers are urging organizations to immediately assess their use of FastJson and implement interim security measures while awaiting an official fix from the developers. These measures may include network segmentation, strict input validation, and enhanced monitoring for suspicious activities. The exploitation of zero-day vulnerabilities like this one underscores the persistent threat posed by sophisticated threat actors who are constantly seeking and weaponizing undiscovered flaws in widely used software components. The FastJson library's role as a foundational component in many Java applications makes it an attractive target for attackers aiming for broad impact. The lack of immediate patches for zero-day exploits necessitates a proactive security posture, focusing on detection and containment strategies. Organizations are advised to consult security advisories from their vendors and cybersecurity intelligence providers for the latest information and recommended actions. The ongoing exploitation highlights the importance of supply chain security, as vulnerabilities in open-source components can have cascading effects across the software ecosystem. The specific details of the exploit mechanism are still under investigation by security firms, but the core issue lies in how FastJson deserializes untrusted JSON data, allowing malicious payloads to be injected and executed. This incident serves as a stark reminder of the need for continuous vigilance and robust security practices in the face of evolving cyber threats. The potential for widespread compromise necessitates a swift and coordinated response from both software vendors and the user community to address the vulnerability and fortify defenses against future attacks. The active exploitation phase indicates that attackers have already developed and deployed tools to leverage this flaw, making immediate action crucial for affected entities. The focus on US firms suggests a potential motive or strategic targeting by the threat actors, though the exact reasons remain unclear. The implications extend beyond immediate system compromise, potentially affecting business operations, customer trust, and regulatory compliance for the affected organizations. The reliance on open-source software, while offering significant benefits in terms of development speed and cost, also introduces inherent risks that must be meticulously managed through rigorous security assessments and patching protocols.
The Hacker News · Jul 25, 2026
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Attackers are actively targeting a critical Remote Code Execution (RCE) vulnerability within Alibaba's Fastjson 1.x Java JSON library, according to security firms ThreatBook and Imperva. This flaw allows malicious actors to execute arbitrary code on affected Spring Boot applications through unauthenticated, specially crafted JSON requests. The exploit leverages the privileges of the running Java process, posing a significant security risk. The vulnerability, officially designated as CVE-2026-16723, has been assigned a CVSS score of 9.0 by Alibaba, indicating a critical severity. ThreatBook reported on March 12, 2026, that they observed active exploitation campaigns targeting this flaw. The confirmed exploit chain requires specific conditions to be met, but the lack of a readily available patch exacerbates the danger for organizations relying on older versions of the Fastjson library. Fastjson is a widely used high-performance Java JSON parsing library developed by Alibaba Cloud. Its widespread adoption means that a large number of applications could be vulnerable if they have not updated to a secure version or implemented mitigating controls. The ability to execute code remotely without authentication is a common precursor to more severe attacks, such as data theft, ransomware deployment, or the establishment of persistent backdoors within a compromised system. Security researchers are advising organizations to immediately assess their use of Fastjson 1.x and to consider migrating to newer, patched versions of the library or implementing alternative JSON parsing solutions. In the absence of a patch, temporary mitigation strategies may include input validation, network segmentation, and enhanced monitoring for suspicious outbound network connections originating from application servers. The ongoing exploitation highlights the persistent threat posed by unpatched legacy software components in enterprise environments.
Fortune · Jul 22, 2026
As Washington panics about Chinese AI, Jensen Huang says open-source models like Kimi are ‘excellent’ and should be embraced, not banned
Nvidia CEO Jensen Huang urged Washington to embrace open-source AI models developed by Chinese companies, rather than restricting them due to perceived threats. Speaking to Axios on Tuesday, Huang stated that these highly capable, low-cost models, including Moonshot AI's Kimi K3, DeepSeek, and Alibaba's offerings, are "excellent" and should be utilized. This stance comes as the White House reportedly considers restricting U.S. companies' use of Chinese AI models, driven by concerns over potential surveillance and the impact on domestic AI companies. The White House has allegedly considered executive actions to impose conditions on U.S. firms using these models, such as mandating security guarantees and liability acceptance in case of breaches. Huang dismissed the notion that these models could serve as a backdoor for the Chinese government, calling it a "misconception." He emphasized that these models are downloadable and their security guardrails are customizable. Huang also expressed confidence that these open-source models will not surpass American AI advancements, arguing for the necessity of both open-source and closed-source AI systems. He believes that excellent open-source models should be integrated into the AI ecosystem, alongside proprietary models from companies like OpenAI and Anthropic. U.S. companies, including AI coding startup Cursor, are reportedly turning to these Chinese open-source alternatives to mitigate the high costs associated with American AI models. Nvidia did not immediately respond to requests for comment.
Decrypt · Jul 22, 2026
Alibaba's New Qwen Image 3 AI Wants to Be Useful, Not Just Pretty
Alibaba released its Qwen Image 3.0 artificial intelligence model this week, designed for generating detailed visual content. The model is capable of producing dense newspaper layouts and intricate infographic grids in a single operation. A key feature highlighted is its ability to render text down to a size of 10 pixels, ensuring clarity and legibility even in small formats. This advancement in text rendering within image generation aims to make the AI model more practical for applications requiring precise textual information embedded in visuals. Unlike some previous models that might struggle with small font sizes or complex text arrangements, Qwen Image 3.0 is engineered to handle these challenges effectively. The model's capabilities suggest potential uses in graphic design, data visualization, and content creation where accurate text representation is crucial. However, Alibaba has not released any performance benchmarks for Qwen Image 3.0, making direct comparisons to other leading image generation models difficult. Furthermore, the company has opted not to release the model's weights publicly. This decision means that external developers and researchers will not be able to inspect, modify, or build upon the model's underlying architecture, limiting its potential for community-driven innovation and adaptation. The focus on utility and detailed text rendering positions Qwen Image 3.0 as a tool aimed at specific professional use cases rather than a broadly accessible creative model. The absence of benchmarks and open weights suggests a strategy of controlled deployment and commercial application by Alibaba, prioritizing its own ecosystem and services.