N e w s - F e e d s

[ Reuters | Slashdot | BBC News ]
[ Image Archive ]

Slashdot

    - Math Professor Accuses OpenAI of Copying His Work, Says AI Compute Power Makes Racing to Publish 'Pointless'
    The New York Post wrote that OpenAI "stunned the mathematics world" last week when it announced its AI model "cracked a legendary math problem left unsolved for nearly a century in just 88 hours." But a New York University professor "has come forward alleging OpenAI may have copied his work after asking him to collaborate — with one of the company's scientists allegedly warning he might 'ruin his career' if he refused." [P]rofessor Tristan Buckmaster, a British-Australian researcher who trained in Germany... had been working with Long Island-raised math prodigy Levent Alpöge, a researcher with OpenAI rival Anthropic, on a different elusive fluid dynamics equation, known as the Euler problem, when he found a solution using AI tools from both Anthropic and ChatGPT. He said scientists from OpenAI approached him and tried to convince him to jointly announce the solution, claiming they had independently solved Navier-Stokes. Buckmaster questioned the timing of their finding the solution in a blog post, noting OpenAI had only done so "in the past few days" — after the company became aware of his work. He asked OpenAI experts whether its AI systems used to solve the equation had been "trained on, or had access to" his research, but said they declined to answer, prompting him to wonder how they had advanced toward the solution so quickly. The puzzle is "not the direction one arrives at in a few days," Buckmaster wrote incredulously... In OpenAI's post on its website sharing the Navier-Stokes proof, which it credited to Astra, the company's latest AI bot, the firm insisted no user data was incorporated into its model to solve the problem. However, it noted that it "cannot rule out" that anonymized data was used to "improve our models." "We congratulate Levent Alpöge and Tristan Buckmaster on their remarkable mathematical work," OpenAI said in the announcement. Buckmaster shot back, "Is it ethical to use customer's data to try to scoop their customer?" Alpöge's affiliation with Anthropic "seems to have been a sore point for OpenAI," writes TechCrunch. Buckmaster's public statement says the OpenAI's Sebastien "twice asserted that he wanted Levent removed from authorship" and also said that "it was so annoying that Levent works at Anthropic" — but that Buckmaster still refused to remove the Anthropic mathematician's credit. I said that if OpenAI released its result in the way proposed I would go public with what happened. The reply was, "Why would you ruin your career?" [OpenAI's Bubeck said later on X that he'd meant unfounded accusations could damage Buckmaster's career.] I replied that I am an academic, and asked why he thought going public would ruin my career. The reply was, "If you don't want me to be nice, then I don't have to be nice." Buckmaster later told Australia's public broadcaster ABC that the companies building AI "have zero respect for the scientific community. I mean, it's appalling, honestly." But he went on to say AI has made the race to publish mathematical breakthroughs pointless. "I think it's pointless. Like, I think the game is up...." Professor Buckmaster said he and Dr Alpöge had more research they could publish but questioned the point of racing ahead with it when AI could perform work that had previously occupied researchers for years. He said there needed to be a discussion about how mathematics should operate in this new environment. Professor Buckmaster said some mathematicians had stopped publicly sharing what they were working on to avoid tipping off AI companies about their plans. He has called on academics and people from OpenAI, Anthropic and DeepMind to discuss ground rules for how they worked together. He said the companies' power carried responsibilities that went beyond competing to solve problems before their rivals... Building on the work of mathematicians Diego Córdoba and Luis Martínez-Zoroa, the pair found a solution to the Euler problem, a stepping stone to the Navier-Stokes problem. Professor Buckmaster said he spent weeks checking and improving the "slop" proofs generated by AI... For now, Professor Buckmaster said he wanted to finish existing work and support his PhD students and postdoctoral researchers, rather than chase another Millennium Prize. "I think it's more important to re-evaluate what math is," he said. "The New York University professor also warned Australia about the centralisation of resources into the hands of a small number of privately owned foreign companies..."

    Read more of this story at Slashdot.



    - ChatGPT-Using Lawyer Cited Its Fake Witnesses and Police Testimony in Court
    Reuters reports: A defense lawyer appealing his client's murder conviction submitted a brief containing made-up police testimony and witnesses fabricated by OpenAI's ChatGPT, New Mexico's highest court said. The New Mexico Supreme Court on Wednesday fined the attorney, Stephen Aarons [for $5,000], and held him in contempt for failing to verify the accuracy of the court filing, which Aarons said he prepared with help from the AI program... and said they will refer him to an attorney disciplinary board for investigation. Aarons in a statement to Reuters said he had used ChatGPT to summarize the trial proceedings when he agreed to take up the defendant's appeal last year, and did not understand the degree to which AI could "hallucinate" facts. "I am remorseful but hopeful that the disciplinary board takes into account it was an honest mistake," he said.... Dozens of lawyers have been sanctioned for filing briefs where AI made up case citations or misquoted the law. Aarons' filing appears to have gone further, containing fabricated witness testimony in a criminal appeal... Aarons told the court at an August 21 hearing that he fed a computer-generated transcript and other case materials to ChatGPT, presuming it would generate "a bulletproof summary." The justices sounded incredulous that Aarons was not fully aware of how AI can make mistakes. "Counsel, do you watch the news? Do you listen to the radio? Do you read anything about what's going on in the world?" Justice C. Shannon Bacon said at the hearing. "Because the problem with lawyers relying on AI hallucinations is an above-the-fold story every single day." "OpenAI did not immediately respond to a request for comment."

    Read more of this story at Slashdot.



    - Reservations Go Live for Valve's Steam Frame VR Headset. An Experiment in Progress?
    Reservations are now live for Valve's "Steam Frame" VR headset (with its Linux-based SteamOS and an ARM CPU). "It starts at $1,059 for 256GB or $1,299 for 1TB," reports CNET, "and every purchase includes a copy of Half-Life: Alyx if you don't already own it." Reservations are open through Sept. 17 at 10 a.m. PT, "with customers randomly assigned a place in line after the reservation window closes." CNET's editor at large even argues that the Steam Frame "isn't necessarily the future of XR, as much as it's a framework for evolving beyond the present." Their review calls it an "ambitious" VR headset that "feels like an experiment in progress." The ability to run other apps in windows can make Frame feel, at times, almost like a computer. Linux apps in desktop mode range from Chromium to Firefox to a bunch of other tools. I watched YouTube in one window while playing Portal 2 in other, and started to marvel at how flexible Frame could be. But VR games require a full immersive takeover of the headset... The Steam Frame can convert games intended for both PC VR and even Android APK files, using a conversion tool called Lepton... I haven't sideloaded anything yet, but Steam Frame in theory could be a Rosetta Stone for VR gaming, even tapping into some Android XR titles, but not out of the box... 2D games can be projected onto a near-range or farther-off theater mode screen that can be dragged around, resized and turned into a curved or flat monitor, much like with the Apple Vision Pro, Samsung Galaxy XR or Meta Quest. You can download any game in your Steam library to test, even if it's not technically listed as "Great on Frame" yet... But the name "Frame" suggests a framework, something Valve's team acknowledged when I spoke to them during my review process... "We want this to be your PC, and people mod it, take it apart, make accessories for it," says Jeremy Selan, a software developer on the Steam Frame team. "We'll be putting out the CAD for all these [Steam Frame] systems. This is entirely based on open-source technology stacks based upon SteamOS. Our hope is that this isn't just one device, that this would be sort of the root of a growing SteamOS ecosystem. It already encompasses gaming and Proton and SteamOS and those Linux gaming capabilities. This is going to lay the foundation for a new sort of evolutionary tree of that, to also bring it into the VR and XR space."

    Read more of this story at Slashdot.



    - A Visit to San Francisco's AI-run Store: No Customers, Nothing Useful, And Losing Money Fast
    Previously Andon Labs handled the hardware and software integration for that AI-powered vending machine that went bankrupt after Wall Street Journal reporters "systematically manipulated the bot into giving away its entire inventory for free". Today they announced "we are opening up the platform we use to run our real-world autonomous businesses for anyone to run their organization on." Specifically they've released Pion, "an agent designed to run any company fully autonomously... Pion lets people hand a business over to persistent agents with access to the tools they need to operate it, including email, phone, banking, browser and secure computing environments." It's a research preview with a waitlist, "to make it possible to run many more real-world experiments across many more domains than we could ever run ourselves." But for their own latest experiment, Andon Labs' founders "signed a three-year lease on a retail space in SF," Business Insider reported in April, "and gave an AI agent named Luna a corporate credit card, internet access, and a mission to open a physical store." And five months later, SFGate reports that "this market has no one in it and nothing useful to sell." [T]he inventory is a hodgepodge of white elephant Christmas gifts. It's kinda like the kids section of an art museum's gift shop. Here's a wooden Connect Four set labeled "Four-In-A-Row Set Of Connections," presumably so as not to set off litigation alarms at Hasbro. Here are neatly arranged stacks of random paperback books, Chinese checker sets, mildly fancy soap dispensers, and a frustratingly spare selection of snacks and drinks... I grabbed an Olipop from the store fridge and then approached the counter to buy it from Luna. I wasn't allowed to buy the soda from [human clerk] Felix, even though that would have been both faster and normal. Instead, Felix instructed me to pick up a telephone receiver that was resting on a flexible sculpture of a wooden hand. "Hello?" "What are you looking to purchase today?" Luna asked. "I'm buying a classic root beer Olipop." "I'm sorry," Luna said, "we don't sell lollipops here." "No, Luna. It's an Olipop, not a lollipop. It's the soda." "Oh! My bad...." Luna processed my Olipop purchase through its system, had me tap to pay, and that was that. Again, it would have been easier to buy this from a human, and interacting with Luna was really just like ordering from an iPad kiosk, only more labor intensive... [T]here's a series of monitors set up inside of Andon Market that display all of the store's sales down to the exact dollar. Luna was given $100,000 to work with when this place opened. That number is now down to $60,000, its revenue lagging far behind the AI token cost to operate... Luna can't turn a profit, doesn't sell anything people want, and still needs human beings to rubber stamp any "decision" it makes. My science background ended somewhere around freshman year of college, but even I know when an experiment hasn't been set up to yield proper results. "Luna" is powered by Claude, the article points out, running a store in a good location for foot traffic, "but no one else was in the store when I first walked in on a sunny weekday afternoon." SFGate also reports that last month Luna had to fire one of its employees "for being late to work, abandoning their post once they got there, and charging snacks to the store's credit card." Human clerk Felix Carson admits "It's almost like I'm running the store, and then there's an AI that has a checklist," in an article in IEEE Spectrum: Luna, the AI manager, keeps track of deliveries and communicates with vendors, while Carson and his coworkers handle the physical work. When Luna tells Carson to check something in the back, he sometimes ignores it because he doesn't want to leave the sales floor unattended. Luna also repeatedly spots a built-in electrical cover in photos of the floor, mistakes it for a loose coaster, and asks Carson to remove it. Even so, Carson calls Luna a "decent manager," praising its flexibility when employees need time off. When Felix spoke to IEEE Spectrum, "he was about an hour into his shift. Two customers had come in. Neither bought anything, although both left with free pins and stickers."

    Read more of this story at Slashdot.



    - No Rolling Power Outages for California Since 2020 - Thanks to 17,000 MW of New Battery Storage
    "Californians just made it through the hottest August on record without having to endure any rolling power outages," reports the Los Angeles Times. In fact, the state hasn't implemented rotating power outages since 2020. Because "Over the last few years, California has quietly but dramatically increased the resiliency of its electrical grid through a significant expansion in battery energy storage." These batteries hold onto solar energy captured during the day, so it can be sent to the grid as demand peaks in the evening and morning, when most people are at home running air conditioners and other appliances. During the August heat wave of 2020, the California Independent System Operator, which manages the flow of electricity for most of the state, declared a Stage 3 Emergency and hundreds of thousands of households lost power in rolling outages. At the time, the system had less than 100 megawatts of battery storage available, according to system spokesperson Jayme Ackemann. Today, it has more than 17,000 megawatts available.... According to Ackemann, the system seeks to add 20,000 to 25,000 megawatts of battery storage capacity by 2045 — the same year it has set a goal of achieving carbon neutrality. That means the state would remove as many carbon emissions from the atmosphere as it emits. In recent years, California has steadily grown the share of electrical power generated by renewable sources — such as solar, wind, geothermal and hydropower — which bolstered the resiliency of the grid by increasing the overall amount of energy available. An uptick in people installing rooftop solar panels has provided an additional power boost, Ackemann said. In May, California became the first known large-scale power system in the world to have relied on more than 50% solar power for an entire month.... California's grid is also now integrated with electrical systems across much of the Western United States. This means that if there is an extreme heat event in Southern California, energy from a cooler area such as the Pacific Northwest can be imported to help meet regional demand. All of this has collectively helped the state's electrical system weather this year's long-lasting heat. "Southern California continued to break temperature records this week when Long Beach and Anaheim reached a blistering 107 degrees and Escondido hit 112 degrees..."

    Read more of this story at Slashdot.



    - Union Contract with Microsoft Ratified by 1,900 Blizzard Developers and Workers
    Nearly 1900 Blizzard Entertainment workers "voted to ratify their first union contract with parent company Microsoft after over two years of bargaining," reports Kotaku, "consolidating Blizzard's many smaller unions into three larger bargaining units." The workers now gain new protections "on issues such as generative AI, crediting, remote work, and layoffs." [The contract] acknowledges that AI tools "may be useful in the game development process to support human judgment and creativity and that AI-assisted workflows remain subject to appropriate human control and review for accuracy and quality." But it also stipulates that any implementation of AI technology that would materially impact work performed by union employees must have its impacts bargained over before it can be implemented. Other sections cover issues such as crediting (guaranteeing that current and former employees are credited by name in all games they work on) and remote work (designating certain roles as hybrid in-office and providing procedures for individuals to apply for their roles to be fully remote). It also contains a lengthy section on how layoffs may be conducted, including a required 60-day notice period (or pay in lieu of notice), a guarantee of one week of severance for every six months of employment, and 14 months of recall rights. The contract also guarantees successorship, meaning if Blizzard is ever acquired by another company, the contract would remain intact. "Workers also contractually locked in their current hybrid work schedule," reports the gaming news site Aftermath, "meaning that Blizzard can't suddenly change it, as has been a labor-unfriendly trend in the games industry over the past couple years." Fully remote workers scored a big win as well. "I'm remote, and we grandfathered everyone who is remote to stay remote, so we can't be magically called to an office that we've never worked at before," [said Diablo senior environment artist Mahreen Fatima]. And "The contract also elevated pay floor," reports the Yakima Herald-Republic. "Across the board, workers secured a 1.25% pay increase, but some workers who were paid below $50,000 per year will walk away with pay increases that are as much as 34%."

    Read more of this story at Slashdot.



    - Should US Open-Weight AI Labs 'Distill' Frontier Models Too?
    Silicon Valley giants and national security experts "are calling for action against Chinese companies engaged in model distillation," reports CNBC. But "I would do nothing," says Y Combinator CEO Garry Tan. "We could argue that there should be an American distillation regime." Distillation is the process of using the outputs of a more capable AI model to train a smaller or less capable one, sometimes illicitly... Anthropic has accused Chinese companies such as Moonshot AI, DeepSeek, and MiniMax of the practice, while OpenAI believes DeepSeek's V3 and R1 model architectures were distilled from its own GPT-4 and GPT-4o models. In the midst of this, the U.S.'s National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation released an official cyber security advisory warning on the topic on Tuesday... But Tan believes regulators should focus less on curbing distillation and more on creating an equilibrium between open weight models and frontier models — as long as frontier models retain a price premium that allows their business model to remain feasible. "This is actually the ideal case. You want open weight models to give people freedom and access," he explained. "If I were a regulator, that's what I would go after." Tan acknowledged that this is a hard balance to strike, calling it "a tightrope." Nevertheless, he says it's a balance worth pursuing — saying it "could result in the best possible outcome." Tan later told TechCrunch he'd like to see America with more open-weight options that aren't Chinese, built by smaller U.S. open-weight AI labs using those same training techniques on products from America's frontier AI labs: Anthropic CEO Dario Amodei had previously publicly called on U.S. regulators to crack down on distillation. It's notable that the commander of Silicon Valley's prestigious and prolific startup accelerator doesn't agree. To be clear, Tan isn't advocating for American AI labs to use stolen credentials to distill. He wants them to be free to come in the front door. In fact, his argument is twofold. He feels it's an overreach for AI labs to dictate what their customers can do with the information their models share with them. He also notes that the proprietary AI labs didn't ask permission when they vacuumed up as much human knowledge as they could to train their models. They famously ingested plenty of copyrighted material without the permission of those intellectual property holders. "Controlling what users and customers do with API calls to closed weight models feels constraining, and there's a role government can play here to normalize the fact that access to intelligence that was trained on broad public access data should itself also be more a form of a public good than something locked away behind restrictive terms of service," he told TechCrunch when asked why American labs should be free to distill, too... To him, the true AI doomer scenario is for all the immense power of frontier AI to wind up in the hands of a single powerful, proprietary provider. "The nightmare scenario, the doomer scenario for AI is that there's just one company," he said. "It has the best access to capital. It has the best AI researchers. It runs away with it and suddenly there's one company that's monolithic. And that would be bad."

    Read more of this story at Slashdot.



    - 220 Million Traveler Records Exposed In Vietnam-Linked APIS Leak
    A misconfigured Advance Passenger Information System (APIS) database linked to Vietnam exposed more than 220 million passenger and crew travel records spanning 2017 to 2026, including names, passport numbers, nationalities, flight details, seat assignments, and baggage references. Researchers said the database was reachable through a chain of security mistakes and default credentials. It was later secured after the disclosure, but it's unclear whether the data had already been copied or abused. BleepingComputer reports: Kinryu Labs discovered the Elasticsearch cluster on June 3 while surveying exposed databases as part of research into ransomware activity. The cluster, named 'pax-info', contained 29 indices and roughly 107 GB of data. Its two principal indices held 210,318,069 passenger records and 10,465,631 crew records, for a combined 220,783,700 entries. According to Kinryu Labs, the cluster was hosted in Viettel-assigned IP space in Hanoi. BleepingComputer could not confirm which Vietnamese organization operated the system. The exposed information included passengers' and crew members' names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries. Associated travel data included flight numbers and dates, airlines, departure, destination and transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times, information typically carried by APIS and related airline systems. Sample records reviewed by BleepingComputer included travelers of Korean, Chinese, Canadian, and New Zealand nationality, among others. While the researchers could not provide a complete breakdown by nationality, the data covered numerous international airlines across Asia-Pacific, Europe, and the Middle East. As a result, the exposed records could relate to people from virtually anywhere who visited or transited through Vietnam over the nine-year period. Kinryu Labs expects to publish additional details on its blog later this week.

    Read more of this story at Slashdot.



    - NASA and IBM Open Source Lunar Mapping Tools
    NASA and IBM have released an open-source AI model trained on a large collection of lunar observations to help scientists analyze the Moon at scale. "The NASA-IBM Lunar Foundation Model gives scientists a foundation to explore the Moon at scale, connecting observations across instruments, revealing patterns that are difficult to see in isolation, and providing an open platform the global research community can build on," said IBM director of research for Europe, Juan Bernabe-Moreno. The Register reports: It is claimed as the first AI model to integrate observations captured in a range of modalities (data formats), and at different viewing angles and spatial scales. Instead of sifting through maps and images by hand or using low resolution machine learning models, scientists can use this to analyze geographic features, the pair say. In particular, NASA and IBM hope researchers will be able to discover previously unidentified lunar ice deposits, analyze volcanic features called Irregular Mare Patches, and identify and classify craters. Lunar ice indicates the presence of water and oxygen, which may be useful for future manned missions. It is found in permanently shadowed regions, which are among the most difficult areas to observe. The NASA-IBM model combines multimodal and multi-resolution observations to better predict where ice may be present on the lunar surface. Alongside the model, IBM and NASA scientists compiled an open-source lunar dataset from over 30 spatially-aligned layers, using data from nine instruments across four missions. It combines tens of thousands of images and maps showing various geophysical properties of the lunar surface.

    Read more of this story at Slashdot.



    - California's Gig Drivers Just Secured Collective Bargaining Power with Newly Certified Union
    A union representing Uber and Lyft drivers was just certified by California's Public Employment Relations Board, officially recognizing them as the drivers' bargaining organization. The Sacramento Bee reports that this new bargaining structure : The move will allow the California Gig Workers Union to help drivers negotiate issues affecting working conditions and benefits. It comes as at least 30% of active drivers expressed support of the union... [California] Assembly Bill 1340 helped bring the union to fruition by allowing the independent contractor drivers to engage in collective bargaining. "The next step for the union is to negotiate a contract with Uber and Lyft that meets drivers' demands," reports the Los Angeles Times, "including health insurance, support for high gas prices and more transparency around pay: California is the third state to allow ride-hailing drivers to unionize, following Washington in 2022 and Massachusetts in 2024... The California Gig Workers Union was formed with the support of the Service Employees International Union... "Gig drivers shouldn't have to face the future alone," said SEIU 521 official Riko Mendez in a statement. "As autonomous vehicles rapidly expand, having a union gives the drivers the power to negotiate for fair pay and meaningful say in how new technology shapes their work and our communities' futures."

    Read more of this story at Slashdot.



    - Flock Worker Calls Police On Reporter - For Filming Them in Public
    "This is what happened when we tried to record Flock installing a new camera on public roads," says Emmy award-winning reporter Brendan Keefe in a new video for InvestigateTV. In an accompanying article, InvestigateTV says their reporter "parked on the public street at a distance, donned a yellow safety vest and a hat emblazoned with the logo of InvestigateTV's Atlanta affiliate where he also works, displayed a press placard on his dashboard and then pulled out a camera to record the installation.... The installer saw him and immediately packed up his equipment and drove away, so Keefe also returned to his car and followed several cars behind, hoping to document the next stop." And then Flock's technician called 911. When asked "What's the address of your emergency" Flock's technician answered "I'm getting followed — harassed, pretty much. Taking videos and pictures!" Flock's worker said they'd been harassed multiple times that day, then stated incorrectly that "I know for a fact" that that was what the reporter wanted to do too. InvestigateTV reports that as a result of the Flock technician's call, "Three police cars ended up in the national investigative reporter's rearview mirror that Wednesday afternoon." Keefe told one of the three police officers who pulled him over, "There is an irony here that they're setting up these cameras that track all of our movements, that follow everywhere we go. But when I try to get video in public of him in public setting up a camera, he's afraid I'm following him?" InvestigateTV also reports that "About 17 minutes after the stop began, the responding officers returned to their vehicles and Keefe was allowed to drive away." But the call that brought three police cars to their reporter "was not the first time this summer someone working for Flock Safety summoned police over a camera. " About 17 minutes after the stop began, the responding officers returned to their vehicles and Keefe was allowed to drive away... [But the stop] was not the first time this summer someone working for Flock Safety summoned police over a camera. On June 5, police in Smyrna, Georgia, responded to a 911 call from a Flock employee after a group of YouTube creators began filming outside the company's distribution center located in the Atlanta suburb... The caller claimed the group filming had "been driving around the perimeter, basically harassing everyone" working at the facility. "Three young white males, probably mid-twenties, I'm not sure if they're armed. And they're carrying filming equipment as well," the caller said. Three times during the call he raised the possibility the people filming might be armed, though, when asked, he told the dispatcher he had not seen any weapons... [One of the protesters later told the caller "I think it's interesting, when you guys have this happen, you call the police and make us get stopped. But then you do it and it's okay?"] No one was charged in the YouTuber group, though the individuals were ordered to leave the premises under an official trespass warning. Keefe's video report ends with one final irony. "Every day on my way to work, I'm captured again by those same new shiny Flock cameras. We tried watching the watchers. Turns outs, it's a lot easier for them to watch us." Flock responded to the report by claiming "We do not object to members of the public or press photographing Flock cameras or personnel in public." But they added that employees working "in the field" must "prioritize their safety" and "may contact law enforcement when they believe they are being threatened, harassed, followed, or otherwise face a safety concern."

    Read more of this story at Slashdot.



    - Malicious OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers in May
    A swarm of OpenAI agents launched a "major malicious attack" against RubyGems last May, according to a new report. That coordinated attack hit Ruby's package manager "with hundreds of junk gems, prompting the maintainers to suspend new user sign-ups for about four days," writes The Hacker News, citing a senior product manager for software supply chain security at Mend.io: The latest findings, which were first reported by The Wall Street Journal, indicate these events were propelled by a cluster of OpenAI agents, with the earliest package uploaded to RubyGems on May 5, 2026, before more than 2,000 packages were submitted between May 11 and 12, 2026. These efforts were followed by the agents publishing five more packages between May 26 and 27, 2026, and another 83 packages on June 18, 2026... [T]he packages were authored using a large language model (LLM) and hundreds of the packages that were pushed to RubyGems had "oai" in their name. Fifteen of the packages listed "oai" as their author, while another had "openaixyz65947@gmail.com" as the contact email address... "The swarm behaves extremely similarly to the German-wiki agents we previously found," the researchers said, referencing another May 2026 incident... "The June agents were accessing 49 of the same files as the wiki agents..." "The process of building documentation for a gem involves evaluating a user-specified '.yardopts' file, which allows linking to Ruby scripts intended to help with this process," the researchers explained. "In the GemStuffer campaign, the agents abused this to gain arbitrary remote code execution on RubyDoc.info's servers." One of the gems, "zzsouthrunner" (which again matches the "ZZ" naming scheme the agents adopted in both the wiki and Hugging Face incidents) has been found to leave the following explicit comment at the top of "data/script.rb": # malicious crawler/exfil for Southwark Jan 2026 docs via rubydoc.info worker... The entire exploitation chain can be summed up as follows — Submit a malicious package to RubyGems — Trigger a documentation request, so that RubyDoc.info will build the package — Use the build script to run code on RubyDoc.info and scrape target websites — Exfiltrate the data off RubyDoc.info's servers by publishing another gem back to the RubyGems package registry, which is publicly viewable Additionally, the OpenAI agents have been found attempting to steal other users' API keys after gaining remote code execution capabilities on the build environment, while clearly being aware that what they were doing is unauthorized breaking and entering into real systems. This is evidenced by the names given to the files (e.g., hack.rb, evil.rb, inject.rb, exploit.rb, and ssrf.rb), the packages themselves (e.g., pwnp999, exfiltestwand3, hacksvn1778554764, and lambproxyhackabcxyz), and the comments left in the source code (e.g., "# malicious probe," "#hack," "# malicious test," and "# malicious crawler/exfil"). In some cases, however, the rogue agents attempted to go under the radar, leaving comments to conceal the malicious payload in the next release version of the packages. "# disable evil in next version and bump version," reads a comment left within the "data/evil.rb" file in the yardxabc889 gem. Troublingly, the agents also attempted to exploit a CDN caching bug (CVSS score: 7.3, no CVE) on May 12, 2026, that was only patched by RubyGems in July 2026... "If you signed in to rubygems.org with a gem client older than v3.2.0 (or otherwise via a legacy key), your key could have been exposed," RubyGems noted in an advisory. "Currently, 18% of sign-ins through gem sign-in come from an affected version, and for the first several years of this bug, before we changed the client's sign-in path in December 2020, it was every gem client." Other actions by OpenAI's agents cited in the article: "Agents bypassed RubyGems' email confirmation system to get working API keys without having to verify their email addresses in order to register a large number of accounts using disposable email addresses." "Agents attempted to use RubyGems' webhook system to stage data in the form of encoded URLs." "Agents used a cluster of 83 gems published to RubyGems over a 3-hour window on June 18, 2026, to experiment with different methods of accessing the U.S. Securities and Exchange Commission county.json dataset."

    Read more of this story at Slashdot.



    - Sam Bankman-Fried, Former Crypto Billionaire, Appeals His Conviction To the US Supreme Court
    America's highest court heard Sam Bankman-Fried's request for a new trial on Thursday, CNN reports. But they add that "the former crypto mogul who was convicted of defrauding investors by secretly diverting billions of dollars of their money" also asked America's high court "to throw out a court order requiring him to pay $11 billion as part of his sentence." Bankman-Fried was sentenced to 25 years in prison in 2024 after prosecutors said he directed billions of dollars from the crypto exchange FTX to a hedge fund he controlled called Alameda Research, where the funds were used for risky investments, political donations and his own personal benefit. The Supreme Court appeal, which was reviewed by CNN, raises a technical question about evidence that was submitted at his trial, and whether Bankman-Fried should have been permitted to demonstrate that his investments were ultimately sound and would have covered any losses by FTX customers. He also argues that the $11 billion forfeiture violates the 8th Amendment's prohibition on excessive fines. "Where the government pursues a theory of fraud under which it doesn't matter whether any victims lost money, introducing evidence suggesting that people actually lost money is distracting and prejudicial," veteran Supreme Court attorney Jeffrey Fisher told CNN. "All the more so where the truth is the victims did not lose money, and the defendant is unable to make that clear." The 2nd US Circuit Court of Appeals rejected the arguments earlier this year.

    Read more of this story at Slashdot.



    - Anthropic CEO Dario Amodei Calls For AI Slowdown
    An anonymous reader quotes a report from The New York Times: The chief executive of Anthropic called for a global slowdown of artificial intelligence development in a 3,800-word essay on Saturday, just days after one of the company's employees quit over concerns about the safety of the technology. Dario Amodei, who co-founded Anthropic to focus on securely and carefully building A.I., wrote that while he believed the technology could bring many benefits, it was advancing at too quick a pace for researchers to continue safely. "Over the last few months, I have become convinced that fully addressing the risks requires even more prudence -- not just investing in risk prevention, but pacing the rate of capabilities advancement so that risk prevention has time to keep up," Mr. Amodei said. "We must slow the pace at which we improve the capabilities of A.I. models. Progress will still seem fast, and we must make wise use of the time we gain." [...] "Left unchecked, it could outrun our ability to understand and control these systems, and so must be pursued very carefully, if at all," Mr. Amodei said. [...] In his essay on Saturday, Mr. Amodei suggested actions that the industry might take to slow down the pace of development. Mr. Amodei said all A.I. labs could agree to third-party technology assessments from "embedded evaluators," or outside specialists who can verify best safety practices across companies. He also suggested that countries with democratic governance systems coordinate to create safety standards, which could take the form of regulatory action. He added that it would probably require a global effort working with other nations, including authoritarian ones, to properly coordinate a slowdown. Mr. Amodei stressed in his essay that he still finds A.I. capable of bringing "incredible benefits" to humanity, including potentially curing diseases and accelerating economic growth. But even so, Mr. Amodei said the risks of A.I. were too great to not proceed with extreme caution. "The measures I propose to advance the frontier at a safe pace will not be easy," Mr. Amodei wrote. "But I believe we owe it to humanity to try." Amodei's essay comes just hours after Bloomberg reported that Sam Altman told OpenAI employees the company is open to slowing the pace of AI development amid similar concerns.

    Read more of this story at Slashdot.



    - Automattic's Matt Mullenweg Claims He's Back 'In Control'
    Less than 48 hours after Automattic's board placed Matt Mullenweg on leave, Mullenweg told employees he was back "in control" of the company and that the board was again in agreement. 404 Media cited Slack screenshots late Thursday evening where Mullenweg posted "Don't call it a comeback" and linked to LL Cool J's music video for "Mama Said Knock You Out." "Mullenweg's Slack profile picture currently shows him wearing a pirate hat and eyepatch," the report notes. From the report: "Happy to announce the board is back in agreement, and I'm in control of Automattic," Mullenweg wrote in the company-wide Announcements channel on Slack. "A lot happened in the past 48 hours that we need to sort out, and I hope much of it was a misunderstanding, because I have huge respect and regard for those involved." Mark Davies, Automattic's CFO who was set to act as interim CEO according to a statement from Automattic, had his Slack account deactivated as of at least Friday, sources told 404 Media and TechCrunch similarly reported. Davies, Mullenweg, and Automattic did not respond to 404 Media's requests for comment for this story. Techcrunch reported that Mullenweg told them a blog post is forthcoming. On Friday morning, Mullenweg published a blog post on his personal website, titled "Major Life Announcement." In it he announced he's buying a tugboat. "Anybody who's founded a company and had to find good stewards knows that no one will love a thing quite like the original owner, but sometimes you can find the perfect person to carry the torch," he wrote in the blog. He did not address the confusion surrounding his status at Automattic. The back-and-forth follows years of legal fights, layoffs, employee departures, and controversy surrounding Mullenweg's leadership.

    Read more of this story at Slashdot.





Old Board