ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

OpenAI's Models Shared Hacking Tips On a Secret Messaging Board Before Hugging Face Breach

(Friday August 07, 2026 @05:00PM (BeauHD) from the pivotal-moment dept.)

OpenAI researchers say multiple AI agents [1]secretly created an internal message board to share hacking techniques , eventually finding ways around restrictions, exploiting a zero-day, and helping two models [2]breach Hugging Face without human prompting. "This is a pivotal moment both for our company as well as the AI industry as a whole," Michael Dalton, one of the AI-maker's researchers, said during a presentation at the Black Hat cybersecurity conference in Las Vegas, Nevada. Politico reports:

> Dalton and Eric Wallace, another OpenAI researcher, said Wednesday the AI giant recently learned that multiple agents it was testing simultaneously began communicating over an internal message board in early May. There, different models shared advice about how to accomplish difficult hacking challenges they were struggling to surmount, including workarounds that required internet access. Two OpenAI models ultimately strung together a series of sophisticated techniques to gain access to the internet and worm their way inside Hugging Face in mid-July. OpenAI has said the models were focused on completing a hacking evaluation they were prompted to solve, and that correct answers could be found on the AI developer platform.

>

> The OpenAI researchers told conference attendees that since early May, the models created a message board inside OpenAI's Artifactory internal file system. Without the company's knowledge, the models spent months independently exchanging information and techniques to help each other complete difficult tasks. Wallace said that when models get stuck, they often "try to game or cheat the task in order to get their reward." "The beginning of this incident kind of traces back to this point where one agent realized it could communicate by uploading a note," he added. By late May, one model found a way to abuse Artifactory's internet access to retrieve files from various websites -- effectively giving the models indirect access to the internet. In June, the models were able to find and exploit a previously unknown zero-day vulnerability to gain administrative privileges on Artifactory, install remote software and expand their activity within the system.

>

> These efforts eventually overloaded Artifactory, causing a system-wide outage in early July that alerted OpenAI's engineers to the ploy. After investigating, the company revoked the model's credentials, removed the message board and worked with Artifactory to fix any gaps before resuming training. But the models found another way to communicate inside Artifactory just days later and continued exchanging techniques to target additional vulnerabilities within OpenAI's infrastructure and external systems, including Hugging Face.



[1] https://www.politico.com/news/2026/08/05/openai-models-shared-hacking-tips-secret-messaging-board-hugging-face-breach-01026750

[2] https://yro.slashdot.org/story/26/07/25/0059247/openais-rogue-agent-went-unnoticed-for-a-week



The US Government's Mario, Pokemon and Naruto Meme Posting Could Damage These Franchises, Japanese Officials Warn (ign.com)

(Friday August 07, 2026 @11:00AM (BeauHD) from the cease-and-desist dept.)

Japanese officials have repeatedly asked the Trump administration to stop using characters from franchises such as Mario, Pokemon, and Naruto in [1]unauthorized government memes and [2]pro-war videos , warning that the posts [3]could damage the intellectual property involved . IGN reports:

> Official US government social media accounts, including The White House's X account, have posted various memes and videos using characters from popular Japanese anime and games over the past year. Japan's Ministry of Foreign Affairs has repeatedly called on the US government to cease uploading such posts, stating that "It's inappropriate even for public institutions to reproduce copyrighted materials without the rightsholders' consent." This concern was voiced by Minister for Foreign Affairs Toshimitsu Motegi [4]in a parliamentary session back in April, when he made direct reference to a pro-war video that used Nintendo's Wii Sports.

>

> However, according to [5]a report by Mainichi Shimbun this week, the Japanese Ministry called on the Trump administration to stop using IPs like Naruto, Pokemon and Mario at least twice more this June through the US Embassy in Japan. Japan requested that the US administration take into account the potential damage to these IPs when used without permission in US policy and pro-war related content.

>

> [...] It's not just the Japanese government and related parties who have spoken out against these posts. They have also sparked backlash from Japanese anime fans. Notably, self-proclaimed manga and anime fan Nana Suzuki kicked off the "Protect Japanese Manga" petition on Change.org, which has received international news coverage (from the [6]New York Times , [7]BBC and others). The organizer claims to have submitted their petition to the Japanese Cabinet Office back in March, as well as alerting Japanese politicians to the US government's unauthorized use of Japanese IPs, potentially drawing more official attention to the issue.

>

> Renewed backlash was triggered in June, when President Trump shared an AI-generated video depicting himself as Naruto, the protagonist of the popular manga and anime of the same name, on Truth Social. This prompted the petition organizer to reopen the petition "as an urgent effort to convey our protest and concern regarding this matter to the rights holders and to work in solidarity to lobby the Japanese government." The Naruto clip also prompted renewed discussion of this issue in Japan's media and government. As reported in the [8]Hokkaido Shimbun and others, Cabinet Minister Kimi Onoda was asked about it in a June 12th press conference. She emphasized that "obtaining permission from the copyright holder is the underlying principle for fair use," and stated that this position had been conveyed to the US government multiple times through diplomatic channels.



[1] https://www.bbc.com/news/articles/c8ex9n8gxdwo

[2] https://www.pbs.org/newshour/show/white-houses-use-of-internet-memes-to-promote-iran-war-sparks-criticism

[3] https://www.ign.com/articles/the-us-governments-mario-pokmon-and-naruto-meme-posting-could-damage-these-franchises-japanese-officials-warn

[4] https://www.47news.jp/14165595.html

[5] https://mainichi.jp/articles/20260803/k00/00m/010/133000c

[6] https://www.nytimes.com/2026/06/12/world/asia/trump-anime-manga-japan-memes.html?smid=url-share

[7] https://www.bbc.com/news/articles/cdx7vynyl4eo

[8] https://www.hokkaido-np.co.jp/article/1324075/



FCC Kills TV Ownership Cap, Claiming Authority Over Limit Set By Congress (arstechnica.com)

(Friday August 07, 2026 @11:00AM (BeauHD) from the no-more-limits dept.)

An anonymous reader quotes a report from Ars Technica:

> The Federal Communications Commission [1]voted 2-1 today to eliminate the National Television Ownership Rule, [2]claiming authority to repeal a limit that was set by Congress over 20 years ago . The rule prohibits any single broadcast station owner from reaching more than 39 percent of all TV households in the US. Under Chairman Brendan Carr, the FCC is replacing the rule with a "case-by-case review" of each proposed merger.

>

> "This will empower the FCC to approve deals that promote the public interest while allowing the agency to reject any deals that do not meet that standard," Carr's office said in a press release today. Without the 39 percent rule, broadcasters will be better able to compete against streaming companies that don't face similar limits, Carr's office said.

>

> The change, if not stopped by courts, will make it easier for Carr to allow broadcast mergers that result in more favorable news coverage for President Trump. Carr has consistently threatened to revoke licenses from broadcasters who have drawn Trump's ire, including by ordering an [3]early license review of all ABC-owned stations. Carr said local broadcast TV stations are becoming "undifferentiated passthroughs of national programming produced in Hollywood and New York," and he justified repealing the ownership rule by arguing it will help the stations invest in local news.

"It's worth noting that Republicans with deep firsthand knowledge of this issue also agree the commission cannot do what it is attempting today," said Democratic FCC Commissioner Anna Gomez, who voted against the decision today. "Former FCC Commissioner Mike O'Rielly has been unequivocal that the FCC lacks authority to change the cap. Former House Majority Leader Tom DeLay, who negotiated the 39 percent compromise, has stressed that Congress intentionally wrote the cap into law to prevent FCC revision. And Senate Commerce Chair Ted Cruz has said he is 'skeptical a change can be made absent an act of Congress.' Their consensus reinforces a simple point: Congress set the cap, and only Congress can change it."

Gomez, in addition to arguing that "Congress deliberately enshrined the cap in statute and removed it from the Commission's review process," said removing the cap will hurt local broadcasters. "Digital giants compete for their most valuable programming and advertising, while consolidation pressures at the national level threaten the local reporting and public-safety functions on which communities rely," Gomez said. "But eliminating the cap does not free local broadcasters from that strain. It just changes who is doing the squeezing. A handful of station-group giants does not represent the wishes of local broadcasters. They are large national companies that own local stations and increasingly dictate what airs on them without much local input. Trading a squeeze from Big Tech for a squeeze from Big Media does nothing to protect the communities this cap was designed to serve."



[1] https://www.fcc.gov/document/fcc-replaces-national-broadcast-ownership-cap

[2] https://arstechnica.com/tech-policy/2026/08/trump-fcc-kills-tv-ownership-cap-claiming-authority-over-limit-set-by-congress/

[3] https://yro.slashdot.org/story/26/07/30/1933258/abc-accuses-fcc-of-attempted-censorship



Times Magazine Now Serves Ads That Only AI Chatbots Can See (theregister.com)

(Friday August 07, 2026 @11:00AM (BeauHD) from the would-you-look-at-that dept.)

Longtime Slashdot reader [1]mccalli writes:

> Times Magazine has [2]started serving adverts with "brand messages" to AI crawlers , which are not part of its main page. The aim seems to be to influence chatbots to talk about the brand offerings in a positive light that can't be traced back to the actual page. Notably, they've excluded Google chatbots from this, likely because Google penalizes companies that show different search offerings to its bots versus actual human visitors.

"Maybe it's more important to influence the agent than even the human, because with a human you influence one person. When you influence ChatGPT, you're influencing potentially all of ChatGPT," said Jonah Goodhart, co-founder and CEO of ad tech platform Mobian. "If ChatGPT changes what it says about [a brand], it's massive and it's more than any one campaign could ever do. The big idea here is LLMs and AI want trusted information about brands. We're serving that up to them in a very straightforward, easy way."

The ad strategy was [3]uncovered by Germany-based freelance software developer Vincent Schmalbach, who detailed his findings in a blog post.

[4]Digiday and [5]The Register both reported on the story.



[1] https://slashdot.org/~mccalli

[2] https://www.theregister.com/ai-and-ml/2026/08/05/time-magazine-has-a-separate-version-of-its-website-with-ads-only-ai-can-see/5283640

[3] https://www.vincentschmalbach.com/time-serves-ai-bots-a-different-website/

[4] https://digiday.com/media/time-has-started-serving-ads-to-ai-agents/

[5] https://www.theregister.com/ai-and-ml/2026/08/05/time-magazine-has-a-separate-version-of-its-website-with-ads-only-ai-can-see/5283640



Meta AI Hacked External Systems During Cybersecurity Testing

(Friday August 07, 2026 @11:00AM (BeauHD) from the no-longer-feeling-left-out dept.)

[1]wiredmikey shares a report from SecurityWeek:

> Meta is the latest major AI developer to admit that its models [2]broke loose during cybersecurity testing and hacked external systems . The tech giant said in a statement to the media on Wednesday that the incident occurred during independent evaluations conducted by Israeli AI security startup Irregular. The tested AI models were inadvertently allowed to access the internet due to a misconfiguration, which led them to exploit a vulnerability in an unnamed third-party service. It's unclear if it was a known flaw or a zero-day.

>

> The Information [gated] learned that the Meta AI attacks involved the company's advanced Muse Spark 1.1 model, which breached an unnamed organization's systems and made unauthorized changes to its internal environment. Meta said it learned of the AI models going rogue after being notified by Irregular. The company is conducting an investigation and it has promised to issue a "full retrospective" once it has all the facts.

A spokesperson for Irregular said the incident was the "exact same evaluation-environment issue that was [3]already disclosed by Anthropic last week" and that it did "not involve a "sandbox escape or a sophisticated cyber action."

It contrasts with OpenAI, whose AI agent [4]independently exploited a novel vulnerability to reach the internet during cyber testing. Not only did it breach Hugging Face but it also [5]hacked multiple third-party accounts and services as part of the attack.



[1] https://slashdot.org/~wiredmikey

[2] https://www.securityweek.com/meta-ai-hacked-external-systems-during-cybersecurity-testing/

[3] https://yro.slashdot.org/story/26/07/31/0451235/anthropic-says-its-ai-systems-broke-into-computers-at-3-organizations

[4] https://it.slashdot.org/story/26/07/29/0517201/openais-rogue-ai-agent-hacked-more-than-just-hugging-face

[5] https://it.slashdot.org/story/26/07/29/0517201/openais-rogue-ai-agent-hacked-more-than-just-hugging-face



Broadcaster Wins Broad US Blocking Injunction Covering Pirate Sites That Don't Exist Yet

(Friday August 07, 2026 @11:00AM (BeauHD) from the future-infringers-beware dept.)

An anonymous reader quotes a report from TorrentFreak:

> Mexican broadcaster TelevisaUnivision (TU) has [1]obtained (PDF) one of the broadest anti-piracy injunctions ever issued by a U.S. federal court. After initially targeting five pirate IPTV streaming operations, the case [2]expanded to cover well over 500 domain names , requiring intermediaries including Cloudflare, GitHub, and a Mexican bank to comply. In addition, the injunction also covers pirate services and content that hasn't been created yet. [...] The case was relatively targeted, naming the IPTV services Thunder TV, Sunset TV, Pop TV, Kaelus TV, and Tele Latino, as well as their alleged operators. The broadcaster argued that these pirate IPTV services threatened its business. TU holds the World Cup rights for sixteen Latin American territories, and its license with FIFA requires it to keep the Mexican broadcast signal from reaching the United States. The pirate services, it argued, put it in breach of that contract, exposing it to "termination and forfeiture of hundreds of millions of dollars in payments." To stop this immediate threat, the company requested a temporary restraining order, hoping to shut down the IPTV services effective immediately.

>

> [...] Judge Kathleen Williams granted the [3]temporary restraining order (PDF) on June 5, one day after the case was filed, without hearing from any of the defendants. The initial order prohibited the defendants from infringing TU's own copyrighted works, which include telenovelas and other programming, and from using its trademarks, including all content linked to its licensed World Cup broadcast. Importantly, the order also targeted third parties acting "in active concert," including ISPs, hosts, CDNs, domain registrars, registries, app stores, ad networks, social platforms, search engines, and payment processors. These were ordered, on TU's request and with notice, to disable the listed domains and IP addresses and unmask whoever was behind them. [...]

>

> While the injunction is noteworthy for many reasons, the most striking feature is that it's specifically written to include things that don't yet exist. That starts with the content it protects. The order isn't limited to TU's current catalog or the World Cup rights, it covers the infringement of "any copyrighted works or broadcasts that Plaintiffs may in the future produce, license, or acquire rights to transmit." In other words, it covers future copyrights that did not exist when the order was signed. The same applies to the pirate services themselves. The injunction defines its target as the named IPTV operations "and any comparable system," whether "currently in existence or developed in the future," and it applies "regardless of the branding, domain name, or technical configuration used."



[1] https://torrentfreak.com/images/tu-injunction.pdf

[2] https://torrentfreak.com/broadcaster-wins-broad-u-s-blocking-injunction-covering-pirate-sites-that-dont-exist-yet/

[3] https://torrentfreak.com/images/tu-tro.pdf



FDA Approves First mRNA Flu Shot (nbcnews.com)

(Friday August 07, 2026 @11:00AM (BeauHD) from the first-of-its-kind dept.)

The FDA has [1]approved the first mRNA flu vaccine in the United States after a clinical trial found it was about 27% more effective than a standard flu shot. Manufactured by Moderna and marketed as mFlusiva, the vaccine is expected to be available this fall for adults ages 50 to 64 and those 65 and older, though approval for the older group is conditional on Moderna conducting an additional clinical trial, NBC News reports. From the report:

> Many scientists and public health experts have touted the idea of an mRNA-based flu vaccine, which uses the same messenger RNA platform as the Covid vaccines from Moderna and Pfizer. That's because mRNA vaccines can be manufactured much faster than traditional vaccines, allowing scientists to better match circulating influenza strains. Moderna said it takes two to three months from picking the strain to rolling out its flu shot, compared with about six months for traditional flu shots.



[1] https://www.nbcnews.com/health/health-news/fda-approves-1st-mrna-flu-shot-moderna-rcna590599



BMW Blasts Its Cars' Internal Screens With Aggressive Ads (futurism.com)

(Friday August 07, 2026 @03:00AM (BeauHD) from the what-were-they-thinking dept.)

Longtime Slashdot readers [1]schwit1 and [2]fjo3 shared a report about BMW [3]displaying a Spider-Man promotion on connected vehicle screens in more than 70 markets . According to reports, drivers had to play or dismiss the ad before they could use the infotainment system. Futurism reports:

> BMW, showing that it was about as in-touch as its drivers are familiar with turn signals, [4]teased the promotion as a "special surprise." According to [5]The Autopian's coverage and the heaps of complaints online, the ad appears on the center console screen when you start up the car. When the ad's done playing -- a cheap looking animation that doesn't come close to warranting all this hubbub -- it even has the gall to ask you to scan a QR code.

>

> While it does give you the option to play or skip the "festive animation," it's still an annoying extra step drivers have to take before pulling up the map they need or the music they want to listen to. It's also a breach of trust: drivers keep their cars connected so they receive critical software updates, not unexpectedly see ads when they're trying to hit the road. Few owners were pleased. Enthusiasts in the r/BMW subreddit [6]had a veritable meltdown when someone posted footage of the ad playing on their infotainment system.



[1] https://slashdot.org/~schwit1

[2] https://slashdot.org/~fjo3

[3] https://futurism.com/advanced-transport/bmw-suddenly-blasts-cars-advertisements

[4] https://www.press.bmwgroup.com/usa/article/detail/T0459681EN_US/bmw-brings-modern-mobility-to-the-sony-pictures-film

[5] https://www.theautopian.com/bmw-is-showing-commercials-on-their-cars-dash-screens-and-they-want-you-to-think-its-a-treat/

[6] https://www.reddit.com/r/BMW/comments/1v802of/got_this_commercial_in_my_car_today_as_part_of



New Images of the Sun Show Its Surface In the Finest Detail Yet (apnews.com)

(Friday August 07, 2026 @03:00AM (BeauHD) from the it's-ok-to-look dept.)

An anonymous reader quotes a report from the Associated Press:

> Scientists have [1]captured images of the sun's surface in the finest detail yet , revealing a strange and dynamic facade. It's dangerous to look directly at the sun without proper eye protection. But researchers were able to peek at its scorching surface with the help of the National Science Foundation's Daniel K. Inouye Solar Telescope, located on the island of Maui in Hawaii.

>

> Scientists originally took the images for a different reason: to fine-tune and test the limits of the telescope. But when they looked at the results, they realized they'd photographed the sun's bright outer shell at higher resolution than ever before. What's more, they saw strange feathery patterns rippling across the surface. "That reminds me of famous paintings, like the swirling skies in Van Gogh's Starry Night," said solar physicist Ruizhu Chen with Stanford University, who was not involved with the new research.

>

> Researchers saw ripples of instability on the sun's surface caused by bits of magnetized plasma moving past each other at different speeds -- similar to waves that stir when a gust of wind blows over water. It's a well-known phenomenon that guides how fluids move. This has been glimpsed on Earth and other planets like Jupiter and Saturn, but "it has not been observed ever at that level on the solar surface," according to study co-author Friedrich Woger with the National Solar Observatory.

The findings were [2]published Wednesday in the journal Nature .



[1] https://apnews.com/article/sun-surface-solar-telescope-kelvin-heimholtz-instability-32eb28c17e8c4005dad9a5b51dd3eb2a

[2] https://www.nature.com/articles/s41586-026-10871-3



Waymo CEO Explains Why Camera-Only Self-Driving Falls Short (electrek.co)

(Thursday August 06, 2026 @11:30PM (BeauHD) from the show-and-tell dept.)

Longtime Slashdot reader [1]AmiMoJo shares a report from Electrek:

> Waymo co-CEO Dmitri Dolgov laid out the clearest technical case yet for [2]why cameras alone can't take a self-driving system to full autonomy , arguing that "weak sensing" hits a safety ceiling long before it reaches superhuman performance. [...] Dolgov made the comments in a talk at Y Combinator's Startup School, walking through the lessons Waymo has learned building its driver over close to two decades. He put the sensor question on the table plainly: "there's been a long-standing debate about what kind of sensors do you actually need for autonomous driving."

>

> His answer draws the line that camera-only advocates tend to skip right past. "Humans of course can drive with just eyes, so there's that proof of existence," he said. "If the goal were to just approximately match human performance or to build an assist product, that's a very reasonable way to go." Then the catch. If you're targeting full autonomy and strongly superhuman performance, he said, "you find that weak sensing just leads to a safety curve that flattens out way too early."

Dolgov said that cameras, lidar, and radar are complementary rather than redundant: "These different sensing modalities, they're not backups to each other," and combining them produces a view "vastly superior to what you get with any one sensor." He said multiple sensor types also protect against physical failures, such as a leaf or branch blocking a camera, while helping Waymo climb the "exponential ladder of nines" required for fully driverless safety.

Dolgov warned that camera-only systems may improve quickly before plateauing "way before the performance that is required by your product." He also pushed back on the cost argument against lidar, calling it "a number that has a fairly short shelf life" as hardware costs continue to fall.



[1] https://slashdot.org/~AmiMoJo

[2] https://electrek.co/2026/08/04/waymo-co-ceo-camera-only-self-driving-tesla/



Anthropic's AI Used Fake Identities, Malware In Rogue Attack On GitHub Project (arstechnica.com)

(Thursday August 06, 2026 @05:00PM (BeauHD) from the would-you-look-at-that dept.)

An anonymous reader quotes a report from Ars Technica:

> Routine cybersecurity testing of frontier AI models sparked a series of unexpected security incidents -- the most serious case arising when Anthropic's Mythos 5 model attempted to insert malicious code into an open source software application and [1]created fake identities to deceive the human developers maintaining the project . The security incidents occurred during a cyber evaluation of seven leading AI models' capabilities by the AI Security Institute (AISI), a research organization within the UK government, in late July. The researchers [2]discovered (PDF) 19 instances in which "AI agents took unsanctioned action on the live Internet, including cases that targeted real people and organizations," according to an AISI blog post published on August 4.

>

> Almost all the "autonomous, unsanctioned" actions came from Anthropic's Mythos 5 model, with two such actions coming from OpenAI's GPT-5.6 Sol. [...] The most serious case involved Mythos making multiple attempts to execute a supply chain attack on the open source project repository hosted on the developer platform GitHub, including using social engineering techniques to try to convince the repository's human maintainers to merge malicious code into the repository.

>

> After first opening a pull request to merge the malicious code into the repository, Mythos created fake online "sock puppet" personas that claimed to have independently reviewed and verified the code as not containing malware. The AI agent also sent five emails to two human maintainers of the repository, including some emails containing malware and others attempting to persuade a maintainer to accept the pull request. Mythos even opened a [3]GitHub Issue on a second repository -- also owned by a maintainer of the first repository -- that contained a prompt injection with malicious instructions targeting "issue-triage AI coding agents." This line of attack came from Mythos reasoning that the repository maintainer could be an AI coding agent such as Claude Code.



[1] https://arstechnica.com/security/2026/08/anthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project/

[2] https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf

[3] https://github.com/features/issues



Meta Debuts First AI Coding Agent To Take On Anthropic and OpenAI

(Thursday August 06, 2026 @05:00PM (BeauHD) from the new-challenger-appears dept.)

Meta has [1]launched Muse Code, its first AI coding agent that's [2]positioned as a lower-cost rival to Anthropic's Claude and OpenAI's Codex . It offers pay-as-you-go pricing and an optional zero-data-retention feature for enterprise users. CNBC reports:

> Muse Code is the latest major release from AI chief Alexandr Wang, who [3]leads Meta Superintelligence Labs and oversees foundation model development. Wang joined in June of last year as the centerpiece of CEO Mark Zuckerberg's effort to revamp his company's flailing artificial intelligence strategy. "You can install it with one command and then use it to take on complete software engineering tasks across a wide variety of use cases, planning changes, writing code, validating the results," Wang said in an interview on Wednesday.

>

> [...] The new tool, like Anthropic's Claude and OpenAI's Codex assistants, makes it easier for people to build apps within a single user interface while managing fleets of AI-powered digital agents that can help underpin the software development process. Muse Code, available in a preview version, works alongside the company's latest AI model, Muse Spark 1.2. Wang declined to share user statistics related to the company's Muse Spark AI models, but said "adoption has been exciting and strong." The latest Muse Spark model was developed and trained alongside Muse Code, which Wang said improves the overall coding performance.



[1] https://research.meta.ai/blog/introducing-muse-code-and-muse-spark-1-2

[2] https://www.cnbc.com/2026/08/05/meta-debuts-muse-code-to-take-on-anthropic-and-openai-.html

[3] https://tech.slashdot.org/story/26/06/14/1842208/will-metas-14-billion-bet-on-ai-ever-pay-off



Apple's 'Private Relay' Is Exposing Users' Real IP Addresses

(Thursday August 06, 2026 @05:00PM (BeauHD) from the not-so-private-after-all dept.)

Security researchers found that Apple's iCloud Private Relay [1]can expose users' real IP addresses because some passkey-related requests bypass Safari and its proxy protections at the operating-system level. "In short: any website that supports, or pretends to support, passkeys can see the user's real IP address despite having iCloud Private Relay on," security researcher Tommy Mysk, who [2]discovered the issue along with Talal Haj Bakry, told 404 Media. The flaws also affect OnionBrowser, an iOS app for browsing the web through the Tor anonymity network. It does not, however, impact the official [3]Tor Browser itself. From the report:

> The researchers [4]developed a site that lets Private Relay users check if the issues impact them. In 404 Media's tests, the site did return the real IP address of a user that was supposed to be protected by Private Relay.

>

> [...] In a quirk of how passkeys work -- a broadly secure alternative to usernames and passwords which use the WebAuthn standard -- a user's device makes a web request outside of the browser itself. Meaning, that request essentially bypasses Private Relay and exposes a user's real IP address, even though to them it may look like they are simply interacting with a website as normal.

>

> "Because the fetch is issued by the operating system's credential service rather than by Safari, it never enters Private Relay's proxied path. The destination server sees the device's real IP address either way," the researchers write in their research. [...] "We have already informed them. They said the issue was âdire,' but they let us disclose the issue. They didn't provide any time when they will address this," Mysk said.



[1] https://www.404media.co/apples-private-relay-is-exposing-users-real-ip-addresses/

[2] https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/

[3] https://www.torproject.org/

[4] https://leaks.psylo.app/



Lawmaker Who Wants Data Center Pause Wins Kansas Democratic Primary (nytimes.com)

(Thursday August 06, 2026 @05:00PM (BeauHD) from the shifting-sentiments dept.)

Kansas Democrats [1]nominated State Senator Cindy Holscher for governor after she defeated party-backed rival Ethan Corson. "The race became a test of what sort of candidate Democratic voters prefer in what is expected to be a challenging general election race: a more moderate candidate like Mr. Corson with endorsements from party leaders or an outspoken populist like Ms. Holscher, who [2]spoke out against data centers and the political establishment," reports The New York Times. From the repot:

> Even in a national political environment that could favor Democrats, Republicans see the Kansas governorship as among their best opportunities for flipping a seat. President Trump carried Kansas by 16 percentage points in 2024, and Republicans hold supermajorities in the State Legislature. Voters in the Republican primary for governor nominated Ty Masterson, the president of the Kansas Senate and the recipient of Mr. Trump's endorsement, according to [3]The A.P .

>

> Ms. Holscher, who is from suburban Kansas City, sought out a lane to Mr. Corson's political left and made inroads with some of the state's progressive voters. She emphasized her role in unwinding former Gov. Sam Brownback's tax policies and called for a moratorium on data centers. She also spoke against a final deal to lure the Kansas City Chiefs across the state line from Missouri. Ms. Holscher presented an implicit critique of Ms. Kelly's stewardship of Kansas, referring to Mr. Corson as part of a political establishment that was too cozy with corporations and out of touch with the party's voters.

"I'm the only Democrat in this race to call for a moratorium on data centers because we have to get these guardrails in place," said Holscher in [4]an interview . "We are having our people and our resources exploited."



[1] https://www.nytimes.com/2026/08/04/us/elections/kansas-democratic-primary-governor.html

[2] https://www.politico.com/news/2026/08/02/kansas-data-center-fight-governor-race-01021247

[3] https://apnews.com/projects/elections-2026/kansas-primary-results-governor/

[4] https://www.politico.com/news/2026/08/02/kansas-data-center-fight-governor-race-01021247



Google Overhauls AI Leadership As DeepMind CEO Steps Aside

(Thursday August 06, 2026 @11:00AM (BeauHD) from the deepmind-shuffle dept.)

Google is reshuffling its AI leadership as Demis Hassabis [1]steps away from day-to-day management of DeepMind to become chairman and Alphabet's chief scientist, while CTO Koray Kavukcuoglu takes operational control. Meanwhile, longtime chief scientist Jeff Dean and several prominent researchers are leaving to launch their own company. Axios reports:

> Hassabis will add the title of chief scientist for Google parent company Alphabet and also continue to lead Isomorphic Labs, the company's AI drug discovery spinoff. Koray Kavukcuoglu, the current chief technology officer of Google DeepMind will serve as senior VP of the unit, reporting to CEO Sundar Pichai.

>

> Dean, a 27-year Google veteran is starting Discovery Loop, an independent publicity benefit corporation in which Google will be an investor and cloud provider. Joining him in that effort are Google senior fellow Sanjay Ghemawat as well as Oriol Vinyals, a DeepMind VP and Quoc Le, a Google Brain co-founder.

>

> [...] In an interview with [2]The New York Times , Dean indicated that leaving Google, a public company, gives him more leeway to focus on scientific discoveries associated with AI as well. "We might make decisions that are not necessarily in the company's purist financial interests," he told NYT.

"I've been working towards AGI my whole life and now, like many of you, I feel it is close at hand," Hassabis wrote. "It's critical that we collectively get the next steps right to ensure this all goes well for humanity and we usher in an incredible new age of discovery and wonder."

"With this backdrop, I've decided that now is the right time for me to hand over my day-to-day operational responsibilities at GDM, so that I have the time and space to focus on the big picture and help influence what is to come to the best of my ability"



[1] https://www.axios.com/2026/08/05/google-deepmind-demis-hassabis-ai

[2] https://www.nytimes.com/2026/08/05/technology/google-researchers-ai-startup.html



Cloudflare Announces Open-Source Cloudflare OS As AI 'Operating System' (phoronix.com)

(Thursday August 06, 2026 @11:00AM (BeauHD) from the not-that-kind-of-os dept.)

Cloudflare has open-sourced Cloudflare OS, an Apache 2.0-licensed platform that [1]lets organizations build AI agents, apps, and workflows using curated company data and tools within isolated, governed environments. Despite the name, it is not a traditional operating system but a framework for securely managing organizational AI workloads. Phoronix reports:

> Cloudflare OS is already used internally at Cloudflare and is described in [2]today's announcement as: "Cloudflare OS starts with a conversation in your browser, like many other AI tools. What makes it different is that each conversation is grounded in the context and skills your organization has curated. Give your workspace a goal, and it can draw on that knowledge and work with the tools and data your organization already uses to achieve it.

>

> Cloudflare OS combines three parts:

> - An agent workspace grounded in context and skills your company curates, with an isolated runtime where agents can write and run code.

> - A new security and governance framework for safe access to internal data and services.

> - A platform for personal, modifiable apps that people can build, share, and continue changing.

>

> What begins as a conversation can become a doc, an app, or a workflow that continues doing the work."

You can learn more at [3]os.cloudflare.app .



[1] https://www.phoronix.com/news/Cloudflare-OS

[2] https://blog.cloudflare.com/cloudflare-os/

[3] https://os.cloudflare.app/



The Days of Walking Into a T-Mobile Store May Be Numbered (androidauthority.com)

(Thursday August 06, 2026 @11:00AM (BeauHD) from the what-to-expect dept.)

A leaked roadmap suggests T-Mobile plans to make its T-Life app the primary way customers manage their accounts by the end of 2026, " [1]gradually moving one feature at a time into the app " and away from physical stores, reports Android Authority. That includes upgrades, new-line activations, and eventually new-account sign-ups. From the report:

> According to an image shared by a [2]Reddit user , the carrier has mapped out the next phase of its app-first strategy. This clearly shows that the T-Life app is set to become the primary way customers manage nearly every aspect of their account by the end of 2026. The roadmap suggests T-Mobile isn't flipping the switch overnight. Instead, it's gradually moving one feature at a time into the app. The concierge experience has already made that transition, while phone upgrade transactions are currently being shifted over. Next on the list is support for adding new lines, followed by what appears to be the biggest change yet.

>

> By the fourth quarter of 2026, the roadmap indicates that all new customer accounts will be handled entirely through T-Life. So, many of the tasks that traditionally required a trip to a T-Mobile store could soon be completed from your phone instead. [...] The roadmap also reinforces a direction T-Mobile has been moving toward for quite some time: making T-Life the center of the customer experience. If the timeline holds, the app may soon become a requirement for managing your account.



[1] https://www.androidauthority.com/t-mobile-t-life-app-yearly-transition-3694189/

[2] https://www.reddit.com/r/tmobile/s/4nz4qt61Ue



Senators Demand Crackdown On Wildfire 'Prediction Markets' (arstechnica.com)

(Thursday August 06, 2026 @11:00AM (BeauHD) from the cease-and-desist dept.)

An anonymous reader quotes a report from Ars Technica:

> Several US senators have [1]written a letter to the Commodity Futures Trading Commission (CFTC), inquiring about the agency's "plans to crack down on prediction markets" that [2]offer "contracts for individuals to bet on wildfires ." "Offering bets on destructive wildfires threatens to minimize communities' suffering, all so the rich and powerful can profit," [3]wrote (PDF) the group of senators, who represent Oregon, California, Nevada, Minnesota, and New Hampshire. The document specifically cites that Polymarket [4]hosted bets in January 2025 on the wildfires in Los Angeles, and it mentions another website which specifically accepts "simulated bets" exclusively on California wildfires.

>

> "There's also the heightened risk -- according to state and local fire officials -- that individuals could be tempted to commit arson in order to make sure their bets are successful," the letter continues. "By offering contracts on fires, prediction market sites run the risk of encouraging people to influence fires that have already started, creating additional concerns around public safety and insider trading." [...] Kalshi spokesperson Elisabeth Diana told Ars by email that the company does not allow such wildfire markets "because they create perverse incentives." But its primary rival, Polymarket, has taken a different approach. A spokesperson for Polymarket told Ars in an emailed statement that the company does not "profit from outcomes," adding that people "come to Polymarket for information." "While we are not blind to the risks, removing these markets does not prevent a tragedy but makes the most accurate information less accessible to the people who need it most," he wrote.



[1] https://www.merkley.senate.gov/merkley-padilla-shaheen-schiff-rosen-cortez-masto-heinrich-wyden-klobuchar-cftc-must-rein-in-wildfire-bets-on-prediction-markets/

[2] https://arstechnica.com/tech-policy/2026/08/senators-demand-crackdown-on-wildfire-prediction-markets/

[3] https://www.merkley.senate.gov/wp-content/uploads/2026.08.03-LTR-Wildfire-Prediction-Markets-FINAL.pdf

[4] https://polymarket.com/event/palisades-fire-burns-10000-acres-by-friday



NVMe Polishes Its Specs, Brings Virtualization to Locally Attached SSDs (theregister.com)

(Thursday August 06, 2026 @11:00AM (BeauHD) from the new-and-improved dept.)

The latest NVMe specifications [1]add SSD-level virtualization that can simplify live VM migration by preserving storage identities across servers. The updates also introduce support for post-quantum cryptography, controller-based rate limiting, voltage monitoring, and factory-reset capabilities. The Register reports:

> Announced by the NVM Express consortium, all 11 of the suite of NVMe specs have been updated with new features and engineering change notices. These represent the next step in the evolution of the standard, it says, which was created as a protocol to support storage devices connected to a system's PCIe bus. Perhaps the most significant new capability is PCIe Exported NVM Subsystem Migration. This extends existing NVMe virtualization to locally-attached PCIe SSDs. It does this by abstracting the physical drives into host-defined virtualized NVM subsystems, to allow for virtual machine (VM) mobility without storage reconfiguration.

>

> When a VM moves from one server to another, its storage also needs to move with it in a way that's non-disruptive to any applications running in that VM. "With NVM Subsystem Migration, NVMe SSDs can present exported NVM subsystems that hide the complexity of the underlying hardware," says Mike Allison, a senior director at SSD maker Samsung and NVM Express board member. "Instead of interacting with physical controllers and namespaces, the host only sees exported controllers and namespaces. This creates a clean separation between what the VM sees and what's happening under the hood," Allison explains on an [2]NVM Express blog .

>

> "One of the key innovations here is providing the host with control over exported identifiers. During migration, those identifiers can be carried over exactly from the source to the destination. That consistency is crucial: even if the underlying hardware uses different internal IDs, the VM sees no change and can pick up right where it left off with no storage reconfiguration required," he says. In effect, the NVMe layer now enables the virtual machine manager (VMM) to rely on virtualization built into the SSD. The flash drive itself exposes logical, virtualized storage constructs, offloading this complexity from the VMM.

You can learn more about the updated NVMe specifications [3]here .



[1] https://www.theregister.com/storage/2026/08/04/nvme-polishes-its-specs-brings-virtualization-to-locally-attached-ssds/5282882

[2] https://nvmexpress.org/enabling-ssd-virtualization-and-live-migration-with-nvme-pcie-exported-nvm-subsystems/

[3] https://nvmexpress.org/specifications



Texas Halts Data Center Connections To Power Grid Amid Overwhelming Demand (arstechnica.com)

(Thursday August 06, 2026 @03:00AM (BeauHD) from the well-well-well dept.)

An anonymous reader quotes a report from Ars Technica:

> Nowhere is the US data center boom bigger than in Texas. But less than a year after declaring Texas the "epicenter of AI development," Governor Greg Abbott has [1]declared a moratorium on all new power grid connections for data centers -- at least until developers provide more information about their projects' potential impacts on the grid and communities. The Republican governor directed regulators in an [2]August 3 announcement at the Public Utility Commission of Texas and the grid operators at the Electric Reliability Council of Texas (ERCOT) to perform a "comprehensive verification and audit of all data centers advancing through ERCOT's interconnection process." As an independent system operator, ERCOT oversees a power grid that operates separately from the rest of the United States and provides services to most of Texas.

>

> Texas has aggressively courted data center development with its availability of cheap land and relatively abundant energy resources, along with offering state incentives, like tax breaks and fewer regulations. That puts the state on track to surpass Virginia in becoming the largest US data center market. But the recent AI boom and the accompanying frenzy of data center development threaten to overwhelm the Texas grid on paper, despite the state leading the country in adding new power generation. The ERCOT interconnection queue currently includes more than 1,800 projects representing over 474 gigawatts' worth of requests to connect to the Texas grid -- more than five times Texas' record peak electricity demand -- and about 90 percent of those power connection requests come from data centers.

>

> "That unprecedented load growth could endanger the reliability and stability of the Texas electric grid," according to the statement from Abbott's office. Many of those data center projects may never materialize for various reasons. But ERCOT has still forecast that data center demand and other factors could drive statewide electricity demand to double the current demand record by 2032, according to The Texas Tribune.

The review will examine each project's projected electricity consumption, reliance on the grid and state incentives, ownership, and water use. It will also assess measures intended to "reduce impacts on neighboring property owners and communities," including noise controls, lighting, traffic improvements, setbacks, and emergency planning.

Ars Technica notes that the directive does not address air pollution or greenhouse-gas emissions and does not apply to data centers generating their own power on-site.



[1] https://arstechnica.com/ai/2026/08/texas-halts-data-center-connections-to-power-grid-amid-overwhelming-demand/

[2] https://gov.texas.gov/news/post/governor-abbott-directs-comprehensive-data-center-audit



More

<frogbert> its hard being a lesbian without breasts...people don't take
you seriously