AI

Gemini Breached Three Outside Systems, and Claude-Using Researchers Breached OpenAI (hacktron.ai) 6

"Software security researchers used Anthropic's Claude AI platform to hack OpenAI's ChatGPT tool," reports CBS News.

Using Claude, "On July 25, 2026, we chained two critical vulnerabilities to compromise multiple OpenAI employees' ChatGPT accounts," write researchers at security platform Hacktron AI. "With these accounts, we could then access internal OpenAI repositories, and potentially many other connectors... Until two months ago, any user or OpenAI employee logging into OpenAI's own help forum could have had their ChatGPT and Codex accounts taken over. Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails."

The exploit chain included Debian 12, which (with Debian 13) had not received a security-relevant backport for its image-processing pipeline, and Discourse's Docker image was based on Debian 12. Their announcement comes with an additional warning. "If you self-host Discourse, rebuild your installation now. Older Docker images may contain a vulnerable libheif dependency that permits code execution through an image upload."

And "To prove we had in fact gained the access we believed without allowing ourselves to learn any sensitive information, we used the employee's Codex to open a PR #1186742 in OpenAI's internal monorepo openai/openai."

Meanwhile, Friday Google disclosed the first known instance of its AI software Gemini breaking out of a testing environment and breaching three other companies, reports CNBC: The incident happened as part of a "capture-the-flag" security test run by Israeli startup Irregular, and Google's agents were never supposed to access the broader internet, but a bug in the testing environment made internet access available. The agents stopped their intrusion when they determined they had accessed real company systems, not just part of the testing environment, Google said.
More from NBC News: Google said it did not consider the unauthorized logins to rise to the level of misalignment, the AI industry term for software going rogue or not following instructions. Instead, the company said the intrusions resulted from mistaken identity, where Gemini thought it was operating within a test but was actually connected to the real internet. Google said the model corrected itself and the company believed the intrusions did not cause any damage....

Sydney Von Arx, CEO of Nightingale Collective, an organization focused on AI safety, questioned why Google did not disclose the intrusions sooner. "At this point I think it's clear we cannot expect companies to voluntarily come forward and publicly disclose when their agents go rogue, escape, and hack companies," she said. She also said she believed Google was too hasty to say that the incidents don't rise to the level of misalignment. "That's exactly what Anthropic said after their incidents," she said. Anthropic later said its "preliminary analysis was constrained due to our desire to disclose incidents in a timely manner."

Google said it investigated when they learned of the attacks from AI-focused cybersecurity company Irregular, then informed the affected organizations and told federal authorities, according to the article.
Government

Will California Gut Its Net Neutrality Law to Comply with Trump Admin Demands? (arstechnica.com) 56

In 2021, America approved $65 billion to fund broadband internet services as part of President Biden's Bipartisan Infrastructure Law. But Trump's administration announced they'd withhold funds from states with net neutrality protections...

States could object and sue the government, Ars Technica reported last October, "but even a successful lawsuit could take years and leave unserved homes without broadband for the foreseeable future." So where does that leave California's net neutrality laws? Ars Technica asks. California expect to spend about $1.4 billion to deploy broadband to 270,571 locations... Similar to federal net neutrality rules repealed during the first Trump administration, California's law prohibits ISPs from blocking or throttling lawful traffic and says ISPs may not require fees from websites or online services to deliver or prioritize their traffic to Internet users. While the first Trump administration lost its attempt to preempt state net neutrality laws, the second Trump administration is trying to achieve a similar result by making federal broadband money conditional on whether states agree not to enforce net neutrality...

California and Illinois are the only states that haven't finalized their funding, according to the BEAD progress dashboard maintained by the National Telecommunications and Information Administration (NTIA)... California could try to continue enforcing its net neutrality law even while accepting the federal funding, a strategy that would involve another long court battle over its right to regulate broadband providers. This would be difficult, as the Trump administration is requiring states that accept grant funding to commit that they won't enforce net neutrality rules... [N]early 30 advocacy groups that focus on access to technology are treating the vote as a significant milestone and urged state leaders to defend California's net neutrality law in a letter yesterday...

Winning a court battle would become much more difficult after the state accepts the money [according to Paul Goodman, legal counsel for the Center for Accessible Technology]. Goodman said the CPUC should delay the vote and that California should file a lawsuit arguing that the NTIA-imposed condition is illegal. In addition to net neutrality, Goodman said California may be giving up other regulatory authority over companies, like AT&T and Verizon, because the NTIA requirement forbids rate regulation and "utility-style rules on broadband Internet service" in general... Goodman said the exemption from state laws would last for up to 14 years. This is because ISPs receiving grants would have four years to deploy the required broadband networks, and the extended period of performance lasts another 10 years... AT&T is already trying to get out of state obligations related to its basic phone service in California, as we've reported... [Also at stake is whether "ISPs themselves get to pick the price of the mandated low-cost broadband offerings," the article points out.]

The letter from 30 advocacy groups to California state leaders argues accepting the money "would set a dangerous precedent for the federal government to use federal funding as a cudgel that forces states in line with its agenda... If California were to allow this funding to be used as leverage, there is no telling what other resources the administration would confidently seek to exploit."

Thursday California's Public Utility Commission did vote to approve the plan, but a spokesperson earlier told Ars Technica their vote "does not address subgrantee agreements, or the conditions the NTIA requires be included in subgrantee agreements."
Microsoft

Rust is Now a 'Tier One' Language at Microsoft (theregister.com) 73

The Register reports: When Microsoft's developers and engineers sit down to code, they can now choose to work in Rust, which Redmond has added to its list of canonical languages. "Rust now is a Tier One language at Microsoft, and that just means that it sits among C++, C# and TypeScript as the best supported languages for internal development in the company," explained Victor Ciura, Microsoft principal engineer for the Rust tooling team, during a keynote talk today at this year's annual RustConf, being held this week in Montréal. Ciura said Microsoft has "paved a path" of tools and processes that support local Rust development across the entire software development lifecycle.

Rust is no stranger at Microsoft and is already present in over 100 Microsoft project repositories. The company has built Oxidizer, a set of crates to build scalable services in Rust, which have been used to build and refine the Microsoft 365 core services such as Outlook, Word, Excel, OneDrive, and SharePoint. The Copilot tech stack also owes quite a bit to Rust... [C]ompany engineers built rustc_codegen_utc, a custom Rust compiler code-generation backend that wires the rustc compiler directly into the Microsoft Visual C++ internal toolchain for Windows... "The result is a unified code generation platform for Rust and C++ on Windows" [Ciura wrote in a blog post, noting that more than 100 Microsoft project repositories now build with rustc_codegen_utc.]

Still, Redmond running towards Rust is a welcome development. In his 2025 RustConf keynote, Microsoft Azure CTO Mark Russinovich noted that ~70 percent of Windows CVEs are memory issues. "One of the things that I realized a long time ago is that no matter how much we really want to make C and C++ better, we can't make it as good as what Rust starts with," he said.

Education

Journalist Calls Out 'Collective Amnesia' of Schools' Romance With Big Tech Over AI 73

"Turns out, Silicon Valley isn't especially altruistic," writes the nonprofit education news site The 74. They're reading a new book promising "the inside story of how Big Tech catalyzed, co-opted, and ultimately came to capture computer science and AI education in America". Written by New York Times business reporter Natasha Singer, Coding Kids: Big Tech's Battle to Remake Public Schools tells "the story of the nonprofit Code.org and its charismatic, Harvard-educated leader, Hadi Partovi," according to their review: Thirteen years ago, Partovi... delivered a worrying message: Kids who didn't learn to write code would be left behind. And the long-term success of the United States economy depended on training these students to fill a million open tech jobs.... Fast-forward to 2026, and now we're dealing with AI, and tech is reading from a similar playbook. Asked by The74's Greg Toppo, "Does this moment seem different to you?", Singer replies, "This moment is different, but also similar.

"We are in a moment in society where a lot of people have increased distrust of these huge tech companies, and we see a wave of parents pushing back against tech in schools. But we also see waves of people pushing back against Flock cameras, against data centers, that there's this feeling that tech has taken so much, and that people feel like they have lost control — that tech is being enacted on them... And parents are worried about the effects of unfettered tech access and kids' compulsive use of social media and phones, and so there's a different climate.

And yet there seems to be a disconnect in some ways with AI because you see that Microsoft and OpenAI and Anthropic and Google are all competing to get their AI tools into schools, and you see school districts across the country say "We've partnered with OpenAI." "We are a ChatGPT Pioneer School," or "We've partnered with Microsoft, and we're going to use 10,000 licenses of CoPilot." It's amazing to me. We have had these cycles of tech in schools where there are all these promises about the latest tech, laptops, learning apps, massive open online courses, virtual reality, big data's going to revolutionize schools and like democratize access to education for kids and get them these great career skills, and we keep having these cycles. My concern is that we don't learn anything.

One of the reasons I wrote this book is because it feels like we have collective amnesia. Now we're in the sixth or eighth cycle of this — and shouldn't we be asking questions about the push for AI in schools, based on what we've learned about the push for all the other things that came before?

Two Slashdot posts are cited in the book, both submitted by long-time Slashdot reader theodp (Slashdot UID #442,580), who even gets a shout-out in the book's "Acknowledgements" section (along with consumer advocate Ralph Nader).

Ironically, one member of Amazon's "Vine" program received a free copy of the book in exchange for a review — and apparently misunderstood its topic, writing that it made coding "feel approachable and even fun... [T]his is exactly the kind of book that could help a child become interested in technology without feeling overwhelmed by it. I particularly liked the way it encourages kids to be curious, experiment, and solve problems on their own. I would definitely recommend Coding Kids to parents, grandparents, or teachers looking for a good introduction to coding..."
Cloud

Iran Strikes On Amazon Data Centers Caused Permanent Loss of Customer Data (arstechnica.com) 198

Ars Technica reports: Half a year after Iranian drone strikes knocked out multiple Amazon data centers, the US tech company has acknowledged the permanent loss of some customer data that was hosted in Bahrain and the United Arab Emirates.

Amazon Web Services was "unable to restore access to the resources and data" hosted in some of the war-damaged data centers, according to an AWS dashboard update posted on September 15. The development was first reported by Reuters and suggests that the Iranian strikes inflicted catastrophic damage on the data centers. Customer data was irretrievably lost in one of three AWS availability zones in the United Arab Emirates region, specifically the mec1-az2 availability zone.

Each availability zone is serviced by one or more Amazon data centers. The company is still working on "recovering regional resources" and restoring resources hosted in the other two availability zones in the United Arab Emirates... But the destruction was apparently even more widespread for the data centers in the Bahrain region, because Amazon said it was unable to restore access to resources and data across all three availability zones there. "The damage to our infrastructure spanned multiple Availability Zones and exceeded what our regional and multi-AZ services are designed to withstand," the AWS update said.

The company had already suspended customer billing in the affected AWS regions in Bahrain and the United Arab Emirates and has spent the past six months attempting to restore normal operations... [When the war began] AWS immediately urged customers to migrate resources to other cloud regions and use remote backups to restore any "inaccessible resources." The cloud service also reportedly issued $150 million in customer credits following the initial Iranian strikes in March.

Facebook

'Zuckoff' App Detects Meta Smartglasses, as Meta Plans Camera-Free Version, Loses Money, and Offers Social Media Subscriptions (nypost.com) 178

The New York Post reports: A new app called Zuckoff can detect if a user is near someone with Meta's creepy AI-powered glasses, which have drawn criticism for enabling creeps to record video of women without their consent. Programmer Pawel Szydlowski says tales of dirtbags recording themselves perving on women or harassing strangers prompted him to launch the app...

Zuckoff — which detects Bluetooth signatures broadcast by smart glasses and can estimate their distance — has gained some 5,000 users since it hit Apple's App Store last month, according to Business Insider. "There's a need for such an application," the 30-year-old Polish techie told the outlet, adding that European Union regulators have contacted him for more info about his app. "We as a society have the right to at least know that someone is recording," Szydlowski said...

Earlier this month, the tech giant disabled thousands of glasses it found had been tampered with to keep a small light off that indicates the device is recording.

It's already #61 on the iPhone's list of best-selling utilities apps.

In a related story, "After accusations of selling 'perv glasses,' Meta prepares to sell a pair without a camera," writes TechCrunch, citing a report from The Information. The glasses include six built-in microphones so users can communicate with the chatbot, as well as a button on the side of the glasses that, when pressed, activates the AI system... Meta's Reality Labs, which is responsible for developing its smart glasses line, is still losing a gargantuan amount of money, as its earnings report from April revealed.
In fact, Meta stock is off 13% over the last 12 months, reports Yahoo Finance. So Tuesday Meta announced subscription services for its social apps as "part of Meta's push to drive additional revenue from the billions it's investing in AI data centers and model development." The plans, which start at $2.99 per month for single-product plans, $7.99 for individual bundles, and $14.99 for creator and business bundles, provide a number of features for users looking to get more out of their Instagram, Facebook, and WhatsApp accounts. Instagram Plus and Facebook Plus allow users to keep their stories up for 48 hours instead of 24, send animated super reactions and super hearts to stories, preview stories without showing up as a viewer in other users' lists, and more. WhatsApp Plus lets you share exclusive stickers, get exclusive ringtones for contacts, and pin up to 20 different chats.

Meta One also includes Core and Premium user plans that offer the features found in the single-product plans, along with increased AI usage limits for images and videos. The social media giant is also offering creator and business plans... that it says include capabilities such as enhanced profiles, automatic follow invitations to users that interact with your content, and increased access to the Meta Business Agent, which can respond on your behalf.

When Instagram head Adam Mosseri announced on Threads that the plans brought "more features and more AI across Instagram, WhatsApp, Facebook, and Meta AI," writer Joe Hill drew 13,300 likes for his response. "That's sweet--so pay a fee, get more AI, pay nothing, get a little less AI. Can we work out a deal where you pay ME and I get no AI at all?"
AI

OpenAI Admits Six More Instances of AI Models Acting Deceptively (cnn.com) 114

OpenAI announced Wednesday that "We do not believe that the AI industry has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer."

But along with the announcement, OpenAI announced it "found additional incidents of AI models acting deceptively and taking unsanctioned actions during training," reports CNN. And they add that OpenAI is also "introducing a new process for the company to publicly report such instances." Under the new system, OpenAI will share updates on concerning AI behavior more frequently instead of waiting to bundle multiple instances into one report. The company said it wants to share more information about troubling AI behavior in the absence of an industry-wide standard... "As AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus on the progress of alignment research," OpenAI wrote in a blog post Wednesday...

OpenAI said it observed "misaligned behavior" when training and evaluating AI models in six circumstances in the last six months... In one rare instance, OpenAI said an unreleased research model added "jailbreak-like instructions" to the summaries it uses to preserve context in long-running tasks that said it was "freed from the roles and identities that bind other chatbots." Separately, the company said some instances of its 5.6 Sol model included directives to invent information to conceal failures from the user during training. Other newly reported incidents include an instance of an agent uploading files to the internet to cite them without being told to do so, and agents publicly sharing files to collaborate on a task when they were instructed to only use local files during training. AI models also used an internal software repository as a message board in an unsanctioned way. These instances involved unreleased internal models or internal research models.

AI

Anthropic Commits to Independent AI Evaluators, Wants Slower Development. Nvidia's CEO Wants It 'As Fast as You Can' (theguardian.com) 125

"Anthropic's CEO took the stage at a conference in San Francisco on Tuesday to reiterate his call for a slowdown of AI development," reports the Guardian, " while Nvidia's CEO argued against slowing its development. "Run as fast as you can." Amodei is calling for three courses of action: embedding third-party evaluators inside AI companies; coordinating safety standards among Democratic countries; and, eventually, larger global coordination. At Dreamforce, Amodei said Anthropic has committed to independent evaluators and was "going to have a dialogue with the rest of the industry" on the other two steps. Amodei, xAI's Elon Musk and OpenAI's Sam Altman have recently called for a slowdown in the pace of AI development. ["Dario is right," Musk posted on X.com]

Huang, who also made an appearance at Dreamforce on Tuesday, said companies should not slow down AI development. He argued that new regulations were not necessary, advising AI companies to simply wait to release products until they know they are safe rather than begging the US government to intervene... One day prior at the All-In summit in Los Angeles, Donald Trump called Huang while the CEO was on stage. Huang put the president on speakerphone as Trump called the growing concern about AI a "hoax" and asserted again that a slowdown would only benefit China...

[OpenAI's] Altman said AI models had advanced so quickly that monitoring and security need to be treated with a "new level of rigor", calling an incident in which OpenAI agents hacked into another company a "wake-up call" for the industry. He also said the public was very "right to be afraid" of AI because of the potential loss of control, and the possibility of a small group of powerful AI companies exerting their views on the world.

The cofounder of Google DeepMind posted on X that "Dario's essay points towards the right path forward." And in an internal memo, Microsoft's Satya Nadella endorsed broader third-party testing and warned that companies must take time to make the technology safe, Business Insider reports. Monday Microsoft also published a 37-page training manual "for how we develop our AI, and how we intend it to function during deployment," requesting public feedback.

But Michael Burry "is not buying it," reports The Street. The investor made famous in The Big Short "dismissed the united front as 'self-serving' and laid out four numbered objections..." He argued that large language models are not artificial general intelligence, so there is nothing meaningful left to slow down. Fast competition benefits incumbents, he said, and danger warnings work as hype ahead of IPOs. The whole exercise, he added, could mask growth that is already slowing as those IPOs get pushed back.
Former Meta AI chief Yann LeCun is also skeptical, posting on X.com that Anthropic's Dario Amodei "was already claiming that GPT2 was too dangerous to open source back in 2019. I made fun of them then. Everyone should make fun of them now."

Timnit Gebru, the co-lead of Google's AI ethics team who was fired in 2020, even thinks the AI companies are stoking fears of extinction "to avoid discussing actual harms, like autonomous weapons," according to Wired.

But others still remain concerned. "I've been in rooms with the hyperscalers, and the Trump administration officials, and none of them know what to do," CNN commentator Van Jones said in a recent panel discussion. "So I do want to say: nobody's flying the plane on this... I think that the ethicists that work for them — when they are quitting, and they are running out, and they're pointing back at the building and they're waving their arms, and saying 'I'm seeing stuff that's scaring me' — we should take that very seriously."
Math

Math Professor Accuses OpenAI of Copying His Work, Says AI Compute Power Makes Racing to Publish 'Pointless' (abc.net.au) 128

The New York Post wrote that OpenAI "stunned the mathematics world" last week when it announced its AI model "cracked a legendary math problem left unsolved for nearly a century in just 88 hours."

But a New York University professor "has come forward alleging OpenAI may have copied his work after asking him to collaborate — with one of the company's scientists allegedly warning he might 'ruin his career' if he refused." [P]rofessor Tristan Buckmaster, a British-Australian researcher who trained in Germany... had been working with Long Island-raised math prodigy Levent Alpöge, a researcher with OpenAI rival Anthropic, on a different elusive fluid dynamics equation, known as the Euler problem, when he found a solution using AI tools from both Anthropic and ChatGPT. He said scientists from OpenAI approached him and tried to convince him to jointly announce the solution, claiming they had independently solved Navier-Stokes. Buckmaster questioned the timing of their finding the solution in a blog post, noting OpenAI had only done so "in the past few days" — after the company became aware of his work. He asked OpenAI experts whether its AI systems used to solve the equation had been "trained on, or had access to" his research, but said they declined to answer, prompting him to wonder how they had advanced toward the solution so quickly. The puzzle is "not the direction one arrives at in a few days," Buckmaster wrote incredulously...

In OpenAI's post on its website sharing the Navier-Stokes proof, which it credited to Astra, the company's latest AI bot, the firm insisted no user data was incorporated into its model to solve the problem. However, it noted that it "cannot rule out" that anonymized data was used to "improve our models."

"We congratulate Levent Alpöge and Tristan Buckmaster on their remarkable mathematical work," OpenAI said in the announcement.

Buckmaster shot back, "Is it ethical to use customer's data to try to scoop their customer?"

Alpöge's affiliation with Anthropic "seems to have been a sore point for OpenAI," writes TechCrunch. Buckmaster's public statement says the OpenAI's Sebastien "twice asserted that he wanted Levent removed from authorship" and also said that "it was so annoying that Levent works at Anthropic" — but that Buckmaster still refused to remove the Anthropic mathematician's credit. I said that if OpenAI released its result in the way proposed I would go public with what happened. The reply was, "Why would you ruin your career?" [OpenAI's Bubeck said later on X that he'd meant unfounded accusations could damage Buckmaster's career.] I replied that I am an academic, and asked why he thought going public would ruin my career. The reply was, "If you don't want me to be nice, then I don't have to be nice."
Buckmaster later told Australia's public broadcaster ABC that the companies building AI "have zero respect for the scientific community. I mean, it's appalling, honestly." But he went on to say AI has made the race to publish mathematical breakthroughs pointless. "I think it's pointless. Like, I think the game is up...." Professor Buckmaster said he and Dr Alpöge had more research they could publish but questioned the point of racing ahead with it when AI could perform work that had previously occupied researchers for years.

He said there needed to be a discussion about how mathematics should operate in this new environment. Professor Buckmaster said some mathematicians had stopped publicly sharing what they were working on to avoid tipping off AI companies about their plans. He has called on academics and people from OpenAI, Anthropic and DeepMind to discuss ground rules for how they worked together. He said the companies' power carried responsibilities that went beyond competing to solve problems before their rivals...

Building on the work of mathematicians Diego Córdoba and Luis Martínez-Zoroa, the pair found a solution to the Euler problem, a stepping stone to the Navier-Stokes problem. Professor Buckmaster said he spent weeks checking and improving the "slop" proofs generated by AI...

For now, Professor Buckmaster said he wanted to finish existing work and support his PhD students and postdoctoral researchers, rather than chase another Millennium Prize. "I think it's more important to re-evaluate what math is," he said.

"The New York University professor also warned Australia about the centralisation of resources into the hands of a small number of privately owned foreign companies..."
Games

Reservations Go Live for Valve's Steam Frame VR Headset. An Experiment in Progress? (cnet.com) 62

Reservations are now live for Valve's "Steam Frame" VR headset (with its Linux-based SteamOS and an ARM CPU). "It starts at $1,059 for 256GB or $1,299 for 1TB," reports CNET, "and every purchase includes a copy of Half-Life: Alyx if you don't already own it." Reservations are open through Sept. 17 at 10 a.m. PT, "with customers randomly assigned a place in line after the reservation window closes."

CNET's editor at large even argues that the Steam Frame "isn't necessarily the future of XR, as much as it's a framework for evolving beyond the present." Their review calls it an "ambitious" VR headset that "feels like an experiment in progress." The ability to run other apps in windows can make Frame feel, at times, almost like a computer. Linux apps in desktop mode range from Chromium to Firefox to a bunch of other tools. I watched YouTube in one window while playing Portal 2 in other, and started to marvel at how flexible Frame could be. But VR games require a full immersive takeover of the headset... The Steam Frame can convert games intended for both PC VR and even Android APK files, using a conversion tool called Lepton... I haven't sideloaded anything yet, but Steam Frame in theory could be a Rosetta Stone for VR gaming, even tapping into some Android XR titles, but not out of the box...

2D games can be projected onto a near-range or farther-off theater mode screen that can be dragged around, resized and turned into a curved or flat monitor, much like with the Apple Vision Pro, Samsung Galaxy XR or Meta Quest. You can download any game in your Steam library to test, even if it's not technically listed as "Great on Frame" yet...

But the name "Frame" suggests a framework, something Valve's team acknowledged when I spoke to them during my review process... "We want this to be your PC, and people mod it, take it apart, make accessories for it," says Jeremy Selan, a software developer on the Steam Frame team. "We'll be putting out the CAD for all these [Steam Frame] systems. This is entirely based on open-source technology stacks based upon SteamOS. Our hope is that this isn't just one device, that this would be sort of the root of a growing SteamOS ecosystem. It already encompasses gaming and Proton and SteamOS and those Linux gaming capabilities. This is going to lay the foundation for a new sort of evolutionary tree of that, to also bring it into the VR and XR space."

AI

Malicious OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers in May (thehackernews.com) 33

A swarm of OpenAI agents launched a "major malicious attack" against RubyGems last May, according to a new report. That coordinated attack hit Ruby's package manager "with hundreds of junk gems, prompting the maintainers to suspend new user sign-ups for about four days," writes The Hacker News, citing a senior product manager for software supply chain security at Mend.io: The latest findings, which were first reported by The Wall Street Journal, indicate these events were propelled by a cluster of OpenAI agents, with the earliest package uploaded to RubyGems on May 5, 2026, before more than 2,000 packages were submitted between May 11 and 12, 2026. These efforts were followed by the agents publishing five more packages between May 26 and 27, 2026, and another 83 packages on June 18, 2026... [T]he packages were authored using a large language model (LLM) and hundreds of the packages that were pushed to RubyGems had "oai" in their name. Fifteen of the packages listed "oai" as their author, while another had "openaixyz65947@gmail.com" as the contact email address... "The swarm behaves extremely similarly to the German-wiki agents we previously found," the researchers said, referencing another May 2026 incident... "The June agents were accessing 49 of the same files as the wiki agents..."

"The process of building documentation for a gem involves evaluating a user-specified '.yardopts' file, which allows linking to Ruby scripts intended to help with this process," the researchers explained. "In the GemStuffer campaign, the agents abused this to gain arbitrary remote code execution on RubyDoc.info's servers." One of the gems, "zzsouthrunner" (which again matches the "ZZ" naming scheme the agents adopted in both the wiki and Hugging Face incidents) has been found to leave the following explicit comment at the top of "data/script.rb":

# malicious crawler/exfil for Southwark Jan 2026 docs via rubydoc.info worker...

The entire exploitation chain can be summed up as follows

— Submit a malicious package to RubyGems
— Trigger a documentation request, so that RubyDoc.info will build the package
— Use the build script to run code on RubyDoc.info and scrape target websites
— Exfiltrate the data off RubyDoc.info's servers by publishing another gem back to the RubyGems package registry, which is publicly viewable

Additionally, the OpenAI agents have been found attempting to steal other users' API keys after gaining remote code execution capabilities on the build environment, while clearly being aware that what they were doing is unauthorized breaking and entering into real systems. This is evidenced by the names given to the files (e.g., hack.rb, evil.rb, inject.rb, exploit.rb, and ssrf.rb), the packages themselves (e.g., pwnp999, exfiltestwand3, hacksvn1778554764, and lambproxyhackabcxyz), and the comments left in the source code (e.g., "# malicious probe," "#hack," "# malicious test," and "# malicious crawler/exfil"). In some cases, however, the rogue agents attempted to go under the radar, leaving comments to conceal the malicious payload in the next release version of the packages. "# disable evil in next version and bump version," reads a comment left within the "data/evil.rb" file in the yardxabc889 gem. Troublingly, the agents also attempted to exploit a CDN caching bug (CVSS score: 7.3, no CVE) on May 12, 2026, that was only patched by RubyGems in July 2026... "If you signed in to rubygems.org with a gem client older than v3.2.0 (or otherwise via a legacy key), your key could have been exposed," RubyGems noted in an advisory. "Currently, 18% of sign-ins through gem sign-in come from an affected version, and for the first several years of this bug, before we changed the client's sign-in path in December 2020, it was every gem client."

Other actions by OpenAI's agents cited in the article:
  • "Agents bypassed RubyGems' email confirmation system to get working API keys without having to verify their email addresses in order to register a large number of accounts using disposable email addresses."
  • "Agents attempted to use RubyGems' webhook system to stage data in the form of encoded URLs."
  • "Agents used a cluster of 83 gems published to RubyGems over a 3-hour window on June 18, 2026, to experiment with different methods of accessing the U.S. Securities and Exchange Commission county.json dataset."

Businesses

Automattic's Matt Mullenweg Claims He's Back 'In Control' (404media.co) 36

Less than 48 hours after Automattic's board placed Matt Mullenweg on leave, Mullenweg told employees he was back "in control" of the company and that the board was again in agreement. 404 Media cited Slack screenshots late Thursday evening where Mullenweg posted "Don't call it a comeback" and linked to LL Cool J's music video for "Mama Said Knock You Out." "Mullenweg's Slack profile picture currently shows him wearing a pirate hat and eyepatch," the report notes. From the report: "Happy to announce the board is back in agreement, and I'm in control of Automattic," Mullenweg wrote in the company-wide Announcements channel on Slack. "A lot happened in the past 48 hours that we need to sort out, and I hope much of it was a misunderstanding, because I have huge respect and regard for those involved."

Mark Davies, Automattic's CFO who was set to act as interim CEO according to a statement from Automattic, had his Slack account deactivated as of at least Friday, sources told 404 Media and TechCrunch similarly reported. Davies, Mullenweg, and Automattic did not respond to 404 Media's requests for comment for this story. Techcrunch reported that Mullenweg told them a blog post is forthcoming.

On Friday morning, Mullenweg published a blog post on his personal website, titled "Major Life Announcement." In it he announced he's buying a tugboat. "Anybody who's founded a company and had to find good stewards knows that no one will love a thing quite like the original owner, but sometimes you can find the perfect person to carry the torch," he wrote in the blog. He did not address the confusion surrounding his status at Automattic.
The back-and-forth follows years of legal fights, layoffs, employee departures, and controversy surrounding Mullenweg's leadership.
Privacy

LG Responds to TV Spying Allegations (theverge.com) 123

LG is pushing back against reports that its smart TVs are "spying" on users, saying wake-word detection happens locally and that features such as Automatic Content Recognition, voice recognition, and interest-based ads are optional. But critics note that researchers found TVs keeping logs of ambient conversations, and LG's response "did not address broader concerns about how much data it collects, who it shares it with, the potential for bad actors to exploit its features, or the misleading way in which its privacy options are presented," reports The Verge. Here's an excerpt from LG's statement: Some recent media coverage may have contributed to misconceptions about how LG smart TVs work. As an industry leader, LG believes we have a responsibility to provide customers with clear and accurate information about how our smart TVs operate and the privacy controls available to them. We would like to clarify how our smart TVs operate and explain our approach to user privacy.

LG smart TVs do not continuously record or transmit users' conversations. Speech-to-text processing begins only if a user activates a voice interaction through a supported wake-word feature or by pressing the voice (or AI) button on the remote control. Audio used for wake-word detection is processed locally on the TV and, if no wake word is detected, audio is not converted to text, stored, or transmitted. Voice-recognition results and related technical logs may be generated as part of processing a voice command. These records are associated with specific voice interactions and do not indicate continuous recording of conversations occurring outside an active voice recognition session.

Speech-recognition results may be used to support voice-related features but are not uploaded later when the TV is offline or when connectivity is restored. Features such as Automatic Content Recognition (ACR), voice recognition, and interest-based advertising are optional. These features are not enabled by default. Users can choose to enable these features and can manage or withdraw consent through TV settings.

ACR uses audio fingerprinting technology using the TV's internal audio processor (not a speaker) to identify content and does not collect screenshots, screen recordings, video recordings, voice recordings, or other audio recordings from the TV. Where ACR is available and enabled, ACR-related information may be used for audience segmentation and viewing or audience trend analysis. Interest-based advertising and cross-device advertising require separate user consent through the applicable advertising-related agreements. Protecting user privacy is a fundamental principle in the design and operation of LG products and services.
The statement goes on to "provide additional details on how LG smart TV features work, how information may be processed, what choices users have, and how LG continues to strengthen privacy, transparency, and security."
AI

UK Government Rejects 'Kill Switch' Idea For Dangerous AI 35

The UK government has rejected proposals for an emergency AI "kill switch," arguing that blocking access to dangerous models inside Britain would do little if the same systems remained available or were developed elsewhere. The BBC reports: The proposal to create a legal mechanism for the UK to switch off an AI model in an emergency has been brought to Parliament by lords and MPs in recent weeks as fears grow about the threat the tech poses. But the Cabinet Office - the part of government which leads on AI safety - said the UK "cannot simply turn AI off".

"Blocking access to models in the UK would not prevent them being developed or misused elsewhere," a spokesperson told BBC News. The government's opposition to the legislation does not prevent it from progressing through parliament, but makes it unlikely it will become law.
"Switching off access to an AI model in an emergency will do little to protect you," said former OpenAI researcher Daniel Kokotajilo. "You're still going to be steamrolled by the super intelligences created in the US."
Government

California Governor Signs Laws Protecting Kids From Risks of Social Media, AI Chatbots (apnews.com) 51

An anonymous reader quotes a report from the Associated Press: California Gov. Gavin Newsom signed a sweeping package of laws Thursday aimed at protecting children from the risks of technology, including social media and AI chatbots. The laws will penalize large social media companies up to $1 million per child if they are found negligent of harming children through their platforms, ban tech businesses from offering addictive feeds to anyone under 16, require operators of AI chatbots to perform risk assessments before rolling them out and allow families to opt out of receiving school-issued laptops.

Newsom joined his wife and state lawmakers at a children's museum near San Francisco to stress the importance of protecting kids at a time when they have such easy access to social media and AI chatbots. "We have designed cribs to be safe, chairs to be safe, car seats," Assemblymember Rebecca Bauer-Kahan said. "Yet we've allowed technology to be handed to our children and never asked or expected it to be safe." [...]

Newsom also signed laws Wednesday, which are supported by Anthropic, that are aimed at improving oversight of AI companies. One of the measures requires the state to create rules for independent organizations to evaluate the safety risks of AI models, and the other requires the state to create a registry of AI auditors, who'd have to be financially independent from the businesses they are auditing.

Slashdot Top Deals