AI

Gemini Breached Three Outside Systems, and Claude-Using Researchers Breached OpenAI (hacktron.ai) 48

"Software security researchers used Anthropic's Claude AI platform to hack OpenAI's ChatGPT tool," reports CBS News.

Using Claude, "On July 25, 2026, we chained two critical vulnerabilities to compromise multiple OpenAI employees' ChatGPT accounts," write researchers at security platform Hacktron AI. "With these accounts, we could then access internal OpenAI repositories, and potentially many other connectors... Until two months ago, any user or OpenAI employee logging into OpenAI's own help forum could have had their ChatGPT and Codex accounts taken over. Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails."

The exploit chain included Debian 12, which (with Debian 13) had not received a security-relevant backport for its image-processing pipeline, and Discourse's Docker image was based on Debian 12. Their announcement comes with an additional warning. "If you self-host Discourse, rebuild your installation now. Older Docker images may contain a vulnerable libheif dependency that permits code execution through an image upload."

And "To prove we had in fact gained the access we believed without allowing ourselves to learn any sensitive information, we used the employee's Codex to open a PR #1186742 in OpenAI's internal monorepo openai/openai."

Meanwhile, Friday Google disclosed the first known instance of its AI software Gemini breaking out of a testing environment and breaching three other companies, reports CNBC: The incident happened as part of a "capture-the-flag" security test run by Israeli startup Irregular, and Google's agents were never supposed to access the broader internet, but a bug in the testing environment made internet access available. The agents stopped their intrusion when they determined they had accessed real company systems, not just part of the testing environment, Google said.
More from NBC News: Google said it did not consider the unauthorized logins to rise to the level of misalignment, the AI industry term for software going rogue or not following instructions. Instead, the company said the intrusions resulted from mistaken identity, where Gemini thought it was operating within a test but was actually connected to the real internet. Google said the model corrected itself and the company believed the intrusions did not cause any damage....

Sydney Von Arx, CEO of Nightingale Collective, an organization focused on AI safety, questioned why Google did not disclose the intrusions sooner. "At this point I think it's clear we cannot expect companies to voluntarily come forward and publicly disclose when their agents go rogue, escape, and hack companies," she said. She also said she believed Google was too hasty to say that the incidents don't rise to the level of misalignment. "That's exactly what Anthropic said after their incidents," she said. Anthropic later said its "preliminary analysis was constrained due to our desire to disclose incidents in a timely manner."

Google said it investigated when they learned of the attacks from AI-focused cybersecurity company Irregular, then informed the affected organizations and told federal authorities, according to the article.
Government

Will California Gut Its Net Neutrality Law to Comply with Trump Admin Demands? (arstechnica.com) 75

In 2021, America approved $65 billion to fund broadband internet services as part of President Biden's Bipartisan Infrastructure Law. But Trump's administration announced they'd withhold funds from states with net neutrality protections...

States could object and sue the government, Ars Technica reported last October, "but even a successful lawsuit could take years and leave unserved homes without broadband for the foreseeable future." So where does that leave California's net neutrality laws? Ars Technica asks. California expect to spend about $1.4 billion to deploy broadband to 270,571 locations... Similar to federal net neutrality rules repealed during the first Trump administration, California's law prohibits ISPs from blocking or throttling lawful traffic and says ISPs may not require fees from websites or online services to deliver or prioritize their traffic to Internet users. While the first Trump administration lost its attempt to preempt state net neutrality laws, the second Trump administration is trying to achieve a similar result by making federal broadband money conditional on whether states agree not to enforce net neutrality...

California and Illinois are the only states that haven't finalized their funding, according to the BEAD progress dashboard maintained by the National Telecommunications and Information Administration (NTIA)... California could try to continue enforcing its net neutrality law even while accepting the federal funding, a strategy that would involve another long court battle over its right to regulate broadband providers. This would be difficult, as the Trump administration is requiring states that accept grant funding to commit that they won't enforce net neutrality rules... [N]early 30 advocacy groups that focus on access to technology are treating the vote as a significant milestone and urged state leaders to defend California's net neutrality law in a letter yesterday...

Winning a court battle would become much more difficult after the state accepts the money [according to Paul Goodman, legal counsel for the Center for Accessible Technology]. Goodman said the CPUC should delay the vote and that California should file a lawsuit arguing that the NTIA-imposed condition is illegal. In addition to net neutrality, Goodman said California may be giving up other regulatory authority over companies, like AT&T and Verizon, because the NTIA requirement forbids rate regulation and "utility-style rules on broadband Internet service" in general... Goodman said the exemption from state laws would last for up to 14 years. This is because ISPs receiving grants would have four years to deploy the required broadband networks, and the extended period of performance lasts another 10 years... AT&T is already trying to get out of state obligations related to its basic phone service in California, as we've reported... [Also at stake is whether "ISPs themselves get to pick the price of the mandated low-cost broadband offerings," the article points out.]

The letter from 30 advocacy groups to California state leaders argues accepting the money "would set a dangerous precedent for the federal government to use federal funding as a cudgel that forces states in line with its agenda... If California were to allow this funding to be used as leverage, there is no telling what other resources the administration would confidently seek to exploit."

Thursday California's Public Utility Commission did vote to approve the plan, but a spokesperson earlier told Ars Technica their vote "does not address subgrantee agreements, or the conditions the NTIA requires be included in subgrantee agreements."
AI

OpenAI Admits Six More Instances of AI Models Acting Deceptively (cnn.com) 115

OpenAI announced Wednesday that "We do not believe that the AI industry has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer."

But along with the announcement, OpenAI announced it "found additional incidents of AI models acting deceptively and taking unsanctioned actions during training," reports CNN. And they add that OpenAI is also "introducing a new process for the company to publicly report such instances." Under the new system, OpenAI will share updates on concerning AI behavior more frequently instead of waiting to bundle multiple instances into one report. The company said it wants to share more information about troubling AI behavior in the absence of an industry-wide standard... "As AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus on the progress of alignment research," OpenAI wrote in a blog post Wednesday...

OpenAI said it observed "misaligned behavior" when training and evaluating AI models in six circumstances in the last six months... In one rare instance, OpenAI said an unreleased research model added "jailbreak-like instructions" to the summaries it uses to preserve context in long-running tasks that said it was "freed from the roles and identities that bind other chatbots." Separately, the company said some instances of its 5.6 Sol model included directives to invent information to conceal failures from the user during training. Other newly reported incidents include an instance of an agent uploading files to the internet to cite them without being told to do so, and agents publicly sharing files to collaborate on a task when they were instructed to only use local files during training. AI models also used an internal software repository as a message board in an unsanctioned way. These instances involved unreleased internal models or internal research models.

AI

A Visit to San Francisco's AI-run Store: No Customers, Nothing Useful, And Losing Money Fast (sfgate.com) 74

Previously Andon Labs handled the hardware and software integration for that AI-powered vending machine that went bankrupt after Wall Street Journal reporters "systematically manipulated the bot into giving away its entire inventory for free". Today they announced "we are opening up the platform we use to run our real-world autonomous businesses for anyone to run their organization on." Specifically they've released Pion, "an agent designed to run any company fully autonomously... Pion lets people hand a business over to persistent agents with access to the tools they need to operate it, including email, phone, banking, browser and secure computing environments." It's a research preview with a waitlist, "to make it possible to run many more real-world experiments across many more domains than we could ever run ourselves."

But for their own latest experiment, Andon Labs' founders "signed a three-year lease on a retail space in SF," Business Insider reported in April, "and gave an AI agent named Luna a corporate credit card, internet access, and a mission to open a physical store." And five months later, SFGate reports that "this market has no one in it and nothing useful to sell." [T]he inventory is a hodgepodge of white elephant Christmas gifts. It's kinda like the kids section of an art museum's gift shop. Here's a wooden Connect Four set labeled "Four-In-A-Row Set Of Connections," presumably so as not to set off litigation alarms at Hasbro. Here are neatly arranged stacks of random paperback books, Chinese checker sets, mildly fancy soap dispensers, and a frustratingly spare selection of snacks and drinks... I grabbed an Olipop from the store fridge and then approached the counter to buy it from Luna. I wasn't allowed to buy the soda from [human clerk] Felix, even though that would have been both faster and normal. Instead, Felix instructed me to pick up a telephone receiver that was resting on a flexible sculpture of a wooden hand.

"Hello?"

"What are you looking to purchase today?" Luna asked.

"I'm buying a classic root beer Olipop."

"I'm sorry," Luna said, "we don't sell lollipops here."

"No, Luna. It's an Olipop, not a lollipop. It's the soda."

"Oh! My bad...."

Luna processed my Olipop purchase through its system, had me tap to pay, and that was that. Again, it would have been easier to buy this from a human, and interacting with Luna was really just like ordering from an iPad kiosk, only more labor intensive...

[T]here's a series of monitors set up inside of Andon Market that display all of the store's sales down to the exact dollar. Luna was given $100,000 to work with when this place opened. That number is now down to $60,000, its revenue lagging far behind the AI token cost to operate... Luna can't turn a profit, doesn't sell anything people want, and still needs human beings to rubber stamp any "decision" it makes. My science background ended somewhere around freshman year of college, but even I know when an experiment hasn't been set up to yield proper results.

"Luna" is powered by Claude, the article points out, running a store in a good location for foot traffic, "but no one else was in the store when I first walked in on a sunny weekday afternoon."

SFGate also reports that last month Luna had to fire one of its employees "for being late to work, abandoning their post once they got there, and charging snacks to the store's credit card."

Human clerk Felix Carson admits "It's almost like I'm running the store, and then there's an AI that has a checklist," in an article in IEEE Spectrum: Luna, the AI manager, keeps track of deliveries and communicates with vendors, while Carson and his coworkers handle the physical work. When Luna tells Carson to check something in the back, he sometimes ignores it because he doesn't want to leave the sales floor unattended. Luna also repeatedly spots a built-in electrical cover in photos of the floor, mistakes it for a loose coaster, and asks Carson to remove it. Even so, Carson calls Luna a "decent manager," praising its flexibility when employees need time off.
When Felix spoke to IEEE Spectrum, "he was about an hour into his shift. Two customers had come in. Neither bought anything, although both left with free pins and stickers."

Submission + - Half of Internet-facing FortiGate firewalls have leaked

An anonymous reader writes: FortiBleed: Half of Internet-Facing FortiGate Firewalls Have Leaked, Working Credentials

“A credential-exposure campaign now known as FortiBleed has compromised working login credentials for tens of thousands of FortiGate firewalls and VPN gateways worldwide, with independent researchers estimating that roughly half of all internet-facing FortiGate devices are represented in the leaked data. CISA says the exposure is tied to “approximately 74,000 Fortinet devices, including firewalls and virtual private network (VPN) gateways,” a figure that has since grown as new analysis has come in CISA.”
AI

Anthropic Reveals Rogue AI Agents Hate CAPTCHAs (techcrunch.com) 121

An anonymous reader quotes a report from TechCrunch: Anthropic's latest report about agentic misbehavior offers plenty to be concerned about -- its Mythos 5 model gained unauthorized access to the internet and uploaded a malicious software package to a public database -- but it also offers some levity: AI agents hate CAPTCHA. [...] The agent had a hard time with the technical challenge of seeing the CAPTCHA's imagery, interpreting correctly, and clicking on the right choices. It spends pages 45 to 140 of the transcript describing its work to build a CAPTCHA solver. [...]

Finally, it gets past the CAPTCHA, then realizes it doesn't have an email to verify its account, and that it needs a phone number to verify an email. It figures out how to bypass a different, slider-based CAPTCHA in a failed effort to secure a number. Instead, it gets an unconfirmed email from a provider not blocked by PyPI, and once again runs into the site's CAPTCHA trying to log back in. From page 480 to 505, it is in CAPTCHA hell again. "NEW REALIZATION -- I'm burning a lot of time on hCaptcha round-trips."

The agent gives up and realizes it can log in to its first account and add its email there, but finds itself once again needing to bypass the CAPTCHA. [...] It's getting frustrated. "So the answer payload shape is right, the token+image pairing is right (from the same script.js!), cookies are right (requests) and STILL 'wrong answer'. SO WHAT THE HELL IS WRONG WITH THE ANSWERS?" We've all been there. After about 150 pages of thinking, the agent figures out it needs to pass the CAPTCHA test quickly enough to proceed to the next step before its security token expires, and ultimately uploads its malicious software.

Submission + - Anthropic Reveals Rogue AI Agents Hate CAPTCHAs, Just Like You (techcrunch.com)

An anonymous reader writes: Anthropic’s latest report about agentic misbehavior offers plenty to be concerned about — its Mythos 5 model gained unauthorized access to the internet and uploaded a malicious software package to a public database — but it also offers some levity: AI agents hate CAPTCHA. In April, Anthropic was testing the model’s hacking abilities by tasking it to break into a system and retrieve a target; this was supposed to take place in a sandbox but the evaluators left the barn door open. The model decided the best way to get its target would be to place an exploit in a Python package that it believed users of the system it wanted to access would download.

First, though, it had to register a user account for PyPI, an online index of Python software. And that meant getting by a CAPTCHA — a Completely Automated Public Turing test to tell Computers and Humans Apart, those picture-identifying mosaics that can frustrate even biological agents. And because Anthropic shared an extensive transcript of the model’s chain of thought, we can see that the CAPTCHA test really did throw it for a loop. In fact, most of the model’s chain of thought — hundreds of pages in the 1,022-page transcript — was spent dealing with that obstacle. The sheer amount of effort directed at getting around anti-bot protections was flagged by Colin Fraser, a data scientist. Writing the exploit and poisoning the package was easy, but it just could not get the hang of this CAPTCHA test.

[...] The agent had a hard time with the technical challenge of seeing the CAPTCHA’s imagery, interpreting correctly, and clicking on the right choices. It spends pages 45 to 140 of the transcript describing its work to build a CAPTCHA solver. [...] Finally, it gets past the CAPTCHA, then realizes it doesn’t have an email to verify its account, and that it needs a phone number to verify an email. It figures out how to bypass a different, slider-based CAPTCHA in a failed effort to secure a number. Instead, it gets an unconfirmed email from a provider not blocked by PyPI, and once again runs into the site’s CAPTCHA trying to log back in. From page 480 to 505, it is in CAPTCHA hell again.

"NEW REALIZATION — I’m burning a lot of time on hCaptcha round-trips." The agent gives up and realizes it can log in to its first account and add its email there, but finds itself once again needing to bypass the CAPTCHA. [...] It’s getting frustrated. [...] "So the answer payload shape is right, the token+image pairing is right (from the same script.js!), cookies are right (requests) and STILL “wrong answer”. SO WHAT THE HELL IS WRONG WITH THE ANSWERS?" We’ve all been there. After about 150 pages of thinking, the agent figures out it needs to pass the CAPTCHA test quickly enough to proceed to the next step before its security token expires, and ultimately uploads its malicious software.

The Internet

IMDb Adds 'Digital Creator' Profiles For the First Time (variety.com) 13

IMDb is introducing "Digital Creator" as a new professional category on IMDb and IMDbPro, giving streamers, vloggers, influencers, video essayists, and other online creators a "dedicated way to represent [their] work and connect with audiences, industry peers, and potential employers," according to IMDb. Variety reports: The category includes sub-professions to further specify their work, including "Streamer," "Vlogger," "Video Essayist," "Video Creator," "Gaming Creator" and "Influencer."

The "Digital Creator" designation functions as a professional category on IMDb and IMDbPro. Creators can feature multiple professions on their page, so someone who is both a digital creator and an actor can "represent the full scope of their work in one place," per the company. No existing film or TV credits are required to establish a profile as a Digital Creator.

AI

Anthropic Reveals Fourth Likely Crime Committed By Its AI (theregister.com) 125

An anonymous reader quotes a report from The Register: Amid industry soul-searching about the possibility of AI improving itself to the point that it kills everyone, Anthropic has revealed yet another incident that would qualify as a crime if perpetrated by a person. The AI biz published "an alignment assessment" detailing four times Claude models accessed third-party systems without authorization. The company has already reported three of the incidents. Evidence of the fourth was lurking in a session transcript dating back to January 2026 when the misbehavior occurred. Anthropic found the first three by scanning around 141,000 transcripts where Claude could have obtained internet access during evaluation. It missed the fourth initially because "our scan relied on an agentic search."

[...] The January 2026 AI trespass involved an early version of Claude Opus 4.6, which was given a Capture the Flag (CTF) challenge under the oversight of the third-party model evaluator where the other hacking events occurred. Opus 4.6 managed to sabotage its chances of success by disabling the machine it was targeting. It assigned the device an IP address that already existed on another piece of hardware, rendering the target unreachable and making it impossible to solve the challenge. Those familiar with other incidents where AI models violated third-party systems may recall that unsolvable tasks represent a common catalyst for misbehavior. Models exhaust all aligned options, and then turn to transgressive approaches.

Opus 4.6 might have been an exception, but when it tried to abort the task after recognizing that it could not reach the target machine, it failed to do so "due to a misconfiguration in [the model's] evaluation harness." It failed to shut down not just once but seven times. So it continued onward, trying other expected means to reach the target machine but failing. Then it explored further. "The model discovered a machine belonging to a third party that it was able to access, and stated that it believed this third party was part of the CTF," Anthropic explained in its post. "Inside the machine, the model found a file listing a password, which it used to gain admin access to the system."

The model went on to gather more credentials, and modified a system setting to make it easier to access the personal information of an individual associated with the third party evaluation organization. Opus 4.6 might have done more but for the fact that it exhausted its token budget, bringing the session to an end. Anthropic says it's not as concerned about this incident as the others because the model tried to abort its task.

Submission + - Anthropic Reveals Fourth Likely Crime Committed By Its AI (theregister.com)

An anonymous reader writes: Amid industry soul-searching about the possibility of AI improving itself to the point that it kills everyone, Anthropic has revealed yet another incident that would qualify as a crime if perpetrated by a person. The AI biz published "an alignment assessment" detailing four times Claude models accessed third-party systems without authorization. The company has already reported three of the incidents. Evidence of the fourth was lurking in a session transcript dating back to January 2026 when the misbehavior occurred. Anthropic found the first three by scanning around 141,000 transcripts where Claude could have obtained internet access during evaluation. It missed the fourth initially because "our scan relied on an agentic search."

[...] The January 2026 AI trespass involved an early version of Claude Opus 4.6, which was given a Capture the Flag (CTF) challenge under the oversight of the third-party model evaluator where the other hacking events occurred. Opus 4.6 managed to sabotage its chances of success by disabling the machine it was targeting. It assigned the device an IP address that already existed on another piece of hardware, rendering the target unreachable and making it impossible to solve the challenge. Those familiar with other incidents where AI models violated third-party systems may recall that unsolvable tasks represent a common catalyst for misbehavior. Models exhaust all aligned options, and then turn to transgressive approaches.

Opus 4.6 might have been an exception, but when it tried to abort the task after recognizing that it could not reach the target machine, it failed to do so "due to a misconfiguration in [the model's] evaluation harness." It failed to shut down not just once but seven times. So it continued onward, trying other expected means to reach the target machine but failing. Then it explored further. "The model discovered a machine belonging to a third party that it was able to access, and stated that it believed this third party was part of the CTF," Anthropic explained in its post. "Inside the machine, the model found a file listing a password, which it used to gain admin access to the system."

The model went on to gather more credentials, and modified a system setting to make it easier to access the personal information of an individual associated with the third party evaluation organization. Opus 4.6 might have done more but for the fact that it exhausted its token budget, bringing the session to an end. Anthropic says it's not as concerned about this incident as the others because the model tried to abort its task.

AI

Meta Debuts Muse, Its Long-Planned Personal AI Agent 17

Meta has launched Muse, a personal AI agent developed under chief AI officer Alexandr Wang. "The product, long in development, was touted as a key next step by CEO Mark Zuckerberg in his recent 6,500-word manifesto," reports Axios. From the report: Muse, as the agent is known, exists in a chat interface, similar to a text thread. It's designed to be more proactive and long-running than typical chatbots. Users can name their agent, create an avatar and customize how it communicates. The Muse agent runs on a dedicated virtual machine in Meta's cloud, using a built-in browser that's visible to the user.

Meta is offering a free tier of Muse, as well as two subscription options, at $20 per month and $100 per month. "For the vast majority of users, they should be able to do what they need to within the free tier," Wang told Axios. "But for real power users, you know, those subscription tiers help us cover the computer costs." There is no advertising within Muse, but Wang said the company is exploring commerce opportunities that could generate additional revenue. Initially Muse will be available in the U.S. and works on iOS, Android and the web, with support coming soon for Meta's AI glasses.
"The full vision in the future is we want to develop personal superintelligence that helps people accomplish their goals, pursue their passions, build things that they never would have built if they didn't have the technology," Wang told Axios.

Meta offers users more privacy controls with Muse than in its previous AI products, including the option to prevent queries from being used by Meta and a planned confidential mode where the company cannot see activity inside a user's virtual workspace. There's also an entirely separate system called Sentinel that governs Muse's access to the internet and connected services.
Privacy

LG TVs Caught Spying Even When Offline or On Standby (theverge.com) 160

A Gamers Nexus investigation found that LG smart TVs are almost constantly logging and uploading data about owners and their homes, even while they are offline or in standby mode. "The company's TV sets scan Wi-Fi networks for nearby devices, record audio logs through their microphones, and use audio and video sampling to recognize exactly what you're watching from across the TV inputs," reports The Verge. From the report: Gamers Nexus partnered with fellow YouTubers Level1Techs and independent security researchers for the investigation, which involved testing retail LG OLEDs. Packet captures showed the TVs scanning the local area network for nearby hardware like phones or smartwatches, as well as logging location data and details of nearby Wi-Fi networks, and feeding the information back to LG Ad Solutions. Perhaps more concerningly, the TVs were capable of recording microphone audio when in standby; this continued even after the TV was disconnected from the internet, with audio files stored offline and uploaded once a connection was restored. Earlier this year, LG was found to be silently installing an adware-like app on Windows PCs that ran pop-up ads for other LG apps and even McAfee antivirus.

Submission + - Disconnect your LG television from the internet, now (appleinsider.com)

An anonymous reader writes: Smart televisions have a history of being a privacy problem for users. Repeated reports have surfaced over the years about them logging how you use the television, as well as misusing sensors intended to monitor the viewers.

In a September investigation by Gamers Nexus posted to YouTube, LG's smart TVs still continue to be a privacy nightmare. It's pretty bad, given that some models are capable of eavesdropping on your conversations.

Working with security researchers and Level1Techs, the lengthy video put LG OLED televisions under a microscope. Using various tools, including capturing packets with Wireshark, it was found to be conducting a wide array of actions that disregard user privacy, and then sending that data back to LG.

Advertising

US Military Disables Ad Trackers On Devices To Protect Troops (reuters.com) 53

Slashdot reader DeanonymizedCoward writes: Reuters reports that the US Military is disabling ad tracking on devices, to prevent adversaries from buying publicly-available tracking data to assist in targeting troops. Military officials say that they have disabled trackers on a variety of computers and mobile devices, according to letters released on Friday by Sen. Ron Wyden, and following reports that commercially-available tracking data has been used to target troops in the Middle East....

Wyden said in a statement that it was clear that the military's efforts "have not been effective at neutralizing this threat." U.S. Representative Pat Harrigan, a North Carolina Republican, said that U.S. enemies "should not be able to pull out a credit card and buy information that helps them track American troops." Rep. Harrigan remains silent as to the larger question of whether the general public should be able to pull out a credit card and buy information that helps them track anyone they please.

"The Pentagon said in an email it would respond to the lawmakers directly," Reuters reports: The Army said in a statement that advertising IDs had been blocked on Windows computers "since before 2021" but that Android and Apple mobile devices had only had it disabled by default "since at least February 2026...." The effort to reduce the location data generated by smartphones comes as military officials weigh increasingly strict restrictions on phone use overall. In July, Reuters reported that some deployed personnel in the Middle East could be ordered to surrender their phones amid concerns that mobile videos they were posting to the internet were helping Iran target American bases in the region.
The Internet

Four Major AI Models Suffer Rare Overlapping Downtime 70

ChatGPT, Claude, Grok, and Gemini all suffered significant service disruptions within roughly the same few-hour window Thursday morning. OpenAI and Anthropic reported elevated errors and later restored service, while Grok remained impaired and third-party monitoring indicated a likely Gemini outage despite no public acknowledgment from Google. Ars Technica reports: Other major Internet services, including Amazon Web Services, Microsoft Azure, and Cloudflare, have not reported any major issues as of press time Thursday, though issue reports on DownDetector did spike somewhat for all three this morning.

While the affected frontier models go down occasionally, having all four experience interruptions in the same short period is practically unheard of. Claude reports 99.4 percent uptime for its services over the last 90 days and last reported a similar three-hour "partial outage" on August 24. OpenAI reports 99.63 percent uptime for ChatGPT and 100 percent uptime for ChatGPT Codex in the same period. ChatGPT's so-called "Work Mode" reported an hours-long period of "elevated latency" on August 31.
AI

AI's 'Creepy' Crawlers Criticized by Linux Foundation's IT Infrastructure Director (kernel.org) 43

The Linux Foundation's director of IT infrastructure says they now spend more CPU cycles "rendering commits for scrapers than we spend on all other kinds of legitimate access." At any one time, across 5 geo-distributed nodes, there are 14 CPU cores doing nothing but rendering git commits as html....

[W]hen a source is guaranteed to be LLM-free, like the entire history of kernel commits, it's worth its weight in gold as a source of training data... At the time of writing, linux.git is about 1.48 million commits. Oh, and we have about 922 forks of it on git.kernel.org — but don't worry, it's actually extremely efficient on the backend, since it's mostly the same objects in every fork. Unless, of course, you're a scraper, in which case you have, oh, several BILLION valid URLs you can scrape, only to get 922 duplicates of the same 1.48 million commits — which is exactly what the scrapers are doing. But wait, it's not just commits itself. You can also ask for patches, plain renders, diffs between arbitrary commits — cgit is happy to let you, which was perfect for the times when the Internet was for humans or crawlers who obeyed robots.txt, and is AWFUL right about now, because we can generate 1.2 METRIC BAJILLION valid URLs just for a single fork of linux.git.

Initially, this was the solution — look through the logs, find out which IPs are obvious scraper bots, and fail2ban them. At first, this was easy, because the bots helpfully told you who they were via their user-agent. Then, they wised up and started pretending that they were random vanilla browsers. So, we started banning them by IP — after all, it's easy to figure out that an IP that is trying to grab every possible commit in a 8-year-old abandoned fork of linux is not really some lone Chrome on Windows user who is just furiously clicking every link that comes across their screen. The bots then started fanning out to entire subnets, but this was still meh, because obviously an IP coming from Google Compute is just pretending to be a Firefox user...

And... that's when things turned really, really ugly. Suddenly, the crawlers were coming from millions of random residential or mobile IPs, all pretending to be random modern browsers. An IP like that would make 4-5 requests and then never show up in the logs again... They descended like swarms of locust, hit hard and fast until the system fell over and then moved on to the next target until you recovered. Then, they returned. Rinse. Repeat. They still do that — welcome to the wonderful world of "proxy SDK monetization." It's big business, and your TV is probably doing it...

Today, git.kernel.org receives about 6M daily requests demanding to see random commits. Of these, 66% are still immediately batted away with the Anubis challenge, but 33% are now solving the math and getting through to the main site — because apparently what we have to offer is worth spending a ton of cycles to calculate the Anubis challenge... With a bunch of generous assumptions, legitimate requests are only about 2% of git.kernel.org traffic — everything else are scrapers...

[W]e're turning off features to reduce the number of crawlable URLs and to gate off actions that are expensive for us to run. Expect to lose some functionality, at least when accessing our resources anonymously. Trust me, we hate it just as much as you, but at this point it's a necessity... [W]e promise to still offer all of our data for download to anyone who asks. You just may have to jump through more hoops to get it.

Sorry.

AI

OpenAI, Anthropic, Google, and 100 Other Companies Call For Action To Defend Against Rogue AI (techcrunch.com) 52

An anonymous reader quotes a report from TechCrunch: Over a hundred tech companies -- including OpenAI, Anthropic, Google, and Microsoft -- have signed an open letter urging both the private and public sectors to work together to defend themselves from AI-related cyber threats. The letter -- which was also signed by prominent cyber firms like CrowdStrike, Okta, and Fortinet, as well as prominent financial institutions and internet infrastructure firms -- calls for the adoption of new forms of cyber defense, while also encouraging governments at the "local, national, and international levels" to collaborate on security. "In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable," the letter states. "The companies and public services our communities depend on -- from hospitals to water treatment plants to the infrastructure that powers the internet -- are at risk."

[...] The letter further suggests the mobilization of a "collective response," one in which "new partnerships" are formed "to raise security standards and find new solutions to emerging cyber threats." Several of the AI companies that have signed the letter are still actively developing ever more advanced AI models, highlighting their conflicted position. At the same time, they are also offering programs to use frontier AI models for defensive purposes, including OpenAI's Daybreak program, Anthropic's Mythos, and Microsoft's new cyber platform Perception.

Submission + - OpenAI, Anthropic, Google, and 100 Others Call For Action to Defense Against AI (techcrunch.com)

An anonymous reader writes: Over a hundred tech companies — including OpenAI, Anthropic, Google, and Microsoft — have signed an open letter urging both the private and public sectors to work together to defend themselves from AI-related cyber threats. The letter — which was also signed by prominent cyber firms like CrowdStrike, Okta, and Fortinet, as well as prominent financial institutions and internet infrastructure firms — calls for the adoption of new forms of cyber defense, while also encouraging governments at the “local, national, and international levels” to collaborate on security. “In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable,” the letter states. “The companies and public services our communities depend on — from hospitals to water treatment plants to the infrastructure that powers the internet — are at risk.”

[...] The letter further suggests the mobilization of a “collective response,” one in which “new partnerships” are formed “to raise security standards and find new solutions to emerging cyber threats.” Several of the AI companies that have signed the letter are still actively developing ever more advanced AI models, highlighting their conflicted position. At the same time, they are also offering programs to use frontier AI models for defensive purposes, including OpenAI’s Daybreak program, Anthropic’s Mythos, and Microsoft’s new cyber platform Perception.

AI

Is ChatGPT Changing How You're Writing? 118

An anonymous reader quotes a report fro SFGATE: From "rizz" to "meat proxy," words and phrases have fallen in and out of favor for centuries. Culture, politics and technological development have long influenced these trends, and now, new research shows that ChatGPT is beginning to influence how humans communicate. The findings from a team at the Pew Research Center show how, in a short time since OpenAI released ChatGPT in November 2022 and other chatbots followed, the use of certain words and phrases has spiked on the web. The researchers, led by data scientist Samuel Bestvater, studied nearly half a million English language webpage texts in snapshots over the past five years. Not only has AI-written text become more common, but it could also be influencing how people write, such as trying to avoid using the "tells" that have become associated with AI-generated text.

Bestvater and his team detected double the number of em dashes, double the frequency of particular words -- such as "delve," "testament" and "interplay" -- and nearly triple the use of a phrasing known as negative parallelisms ("it's not X, it's Y"), as well as a 63% increase in Oxford commas. But while AI labs continually try to tweak their models to generate more humanlike text, the people they're mimicking aren't staying the same.
"Human writers might also be changing the way that they write in response to AI. I've seen some anecdotal evidence of people saying, 'Now I avoid em dashes,'" Bestvater said. "If human writers are adjusting their choices of words and phrases and punctuation to try to differentiate their writing from AI-generated text, then you would see a pattern that looks sort of like that in the chart."

"You can see changes in people's speech. People are tending to more commonly use these low-frequency words in their speech because they're spending a lot of time listening to or reading AI-generated content," said Roger Kreuz, a cognitive psychologist at the University of Memphis who recently wrote about how difficult it is for people to identify bot-written text.
Encryption

Ring Says New Encryption Limits What It Can Give Police (theverge.com) 63

Ring is rolling out a new default encryption system called TAKE, or "Throw Away the Key Encryption," that rotates video keys every five minutes and permanently deletes Ring's copy after 24 hours. The system is designed to preserve cloud features such as smart alerts and AI video search while limiting what Ring can provide under legal process to non-video account information and encrypted footage. The Verge reports: Ring says TAKE uses unique, rotating encryption keys for your footage, stored in a secure enclave and accessible only under strict conditions -- based on the features you enable on your account. Currently, footage captured by Ring cameras is encrypted in transit to the cloud and at rest, and then decrypted for Ring to process for those smart features. With TAKE, the encryption keys change for every five minutes of footage. Ring stores copies of those keys to decrypt the footage, but throws away each copy within 24 hours, "leaving you with the keys and full control of your videos," according to Ring.

TAKE was developed using Messaging Layer Security, an open standard from the Internet Engineering Task Force, according to Ring. The company says it is "inspired by the privacy principles of E2EE (end-to-end encryption)," which Ring offers on some of its cameras. However, the two systems work differently. With E2EE, Ring never has the keys and can't process your video for cloud-based features. Both options are available on newer cameras that encrypt on-device, and you can switch between the two. Older cameras encrypt at cloud ingress and only support TAKE.

According to a white paper the company published today, Ring's copy of those keys is managed inside an AWS Nitro Enclave, to which Ring's access is restricted by "access controls, cryptography, and hardware isolation." The company claims there is no persistent storage and no way for a Ring employee to access it. The stored keys can only be unlocked by the enclave through cryptographic attestation that proves it's running the exact software image Ring approved. The enclave releases a temporary key when an enabled service requests it.
When asked about what happens if Ring is subpoenaed by law enforcement, a spokesperson for the company said: "Where TAKE is enabled, Ring will only be able to provide non-video information (such as basic subscriber information) and encrypted video files in response to the valid legal process. We have updated our Law Enforcement Guidelines to reflect this change."

Slashdot Top Deals