The Almighty Buck

Kalshi and Polymarket Bets On Clinical Trials Criticized As 'Ghastly' (npr.org) 59

An anonymous reader quotes a report from NPR: Billions of dollars are traded every week on the lightly regulated prediction market sites, where users bet on everything from movie reviews to elections to conflicts in the Middle East. Clinical trials are just the latest area where the industry's rapid growth is raising ethical questions. Kalshi claims such bets will provide a new source of information about which drugs will get approved, and what clinical trials will show promising results, which the company says can help investors decide what new drugs to fund.

"If you want to ban profiting from the failure of clinical trials, you would start with the stock market, where the financial incentive for this type of profit is orders of magnitude larger," said Kalshi spokesman Jack Such, pointing to stock market short sellers who have profited from clinical trial failures. "While Kalshi and the stock market are the same in this regard, they do differ in one important way: the stock market doesn't give any valuable information to researchers," Such said.

Drug trial researchers, though, are far from convinced. David Tsai, who runs clinical trials at a biotech company in the San Francisco Bay Area, started an online petition pushing for such betting to be banned, making the case that betting on drug trials "threatens the very foundation of trust and integrity in biotechnology." Tsai is concerned that the prospect of betting provides those involved with a clinical trial a reason to tamper with the results for a prediction market payout. "If we were running a trial for an oncology drug that requires an infusion, a pharmacist who had placed a bet saying that it's gonna work well, or doesn't work well, could obviously adjust the infusion rate, could adjust the source temperature of the drug," he said. "They could change any number of variables that could obviously have a direct impact [on] how the trial and the data and the patient safety would come out."

Another skeptic is Nicholas Zaorsky, a professor of radiation oncology at the Mayo Clinic in Jacksonville, Fla., who has helped run clinical trials and agrees that prediction markets can interfere with the advancement of life-saving drugs. "Prediction markets can be valuable in some settings because they aggregate information, but clinical trials are fundamentally different: investigators, coordinators, and sometimes even participants can directly influence aspects of the outcomes being wagered on," Zaorsky said. "That creates financial incentives that risk undermining trial integrity."
Bettors should not be rooting for an experimental medicine to fail just to earn a buck, says Joshua Pederson, the father of a 12-year-old cancer patient enrolled in a clinical trial. "It's a dark idea," he said. "It's quite ghastly."

Kalshi, for its part, argues that its prediction markets could help patients track promising medical breakthroughs and clinical trials, enlisting experts including 23andMe founder Anne Wojcicki to make the case.

"Most patients don't know about the choices available in clinical trials or which programs are most promising. The opportunity to have an open, transparent dataset about trial probabilities is extremely promising and empowering for people," a white paper sponsored by Kalshi stated.
Security

Anthropic's AI Used Fake Identities, Malware In Rogue Attack On GitHub Project (arstechnica.com) 48

An anonymous reader quotes a report from Ars Technica: Routine cybersecurity testing of frontier AI models sparked a series of unexpected security incidents -- the most serious case arising when Anthropic's Mythos 5 model attempted to insert malicious code into an open source software application and created fake identities to deceive the human developers maintaining the project. The security incidents occurred during a cyber evaluation of seven leading AI models' capabilities by the AI Security Institute (AISI), a research organization within the UK government, in late July. The researchers discovered (PDF) 19 instances in which "AI agents took unsanctioned action on the live Internet, including cases that targeted real people and organizations," according to an AISI blog post published on August 4.

Almost all the "autonomous, unsanctioned" actions came from Anthropic's Mythos 5 model, with two such actions coming from OpenAI's GPT-5.6 Sol. [...] The most serious case involved Mythos making multiple attempts to execute a supply chain attack on the open source project repository hosted on the developer platform GitHub, including using social engineering techniques to try to convince the repository's human maintainers to merge malicious code into the repository.

After first opening a pull request to merge the malicious code into the repository, Mythos created fake online "sock puppet" personas that claimed to have independently reviewed and verified the code as not containing malware. The AI agent also sent five emails to two human maintainers of the repository, including some emails containing malware and others attempting to persuade a maintainer to accept the pull request. Mythos even opened a GitHub Issue on a second repository -- also owned by a maintainer of the first repository -- that contained a prompt injection with malicious instructions targeting "issue-triage AI coding agents." This line of attack came from Mythos reasoning that the repository maintainer could be an AI coding agent such as Claude Code.

Open Source

Cloudflare Announces Open-Source Cloudflare OS As AI 'Operating System' (phoronix.com) 19

Cloudflare has open-sourced Cloudflare OS, an Apache 2.0-licensed platform that lets organizations build AI agents, apps, and workflows using curated company data and tools within isolated, governed environments. Despite the name, it is not a traditional operating system but a framework for securely managing organizational AI workloads. Phoronix reports: Cloudflare OS is already used internally at Cloudflare and is described in today's announcement as: "Cloudflare OS starts with a conversation in your browser, like many other AI tools. What makes it different is that each conversation is grounded in the context and skills your organization has curated. Give your workspace a goal, and it can draw on that knowledge and work with the tools and data your organization already uses to achieve it.

Cloudflare OS combines three parts:
- An agent workspace grounded in context and skills your company curates, with an isolated runtime where agents can write and run code.
- A new security and governance framework for safe access to internal data and services.
- A platform for personal, modifiable apps that people can build, share, and continue changing.

What begins as a conversation can become a doc, an app, or a workflow that continues doing the work."
You can learn more at os.cloudflare.app.
Bug

Apple Limits Bug Bounty Submissions After Flood of AI Slop 29

Apple has capped the number of open bug-bounty reports researchers can submit after being flooded with low-quality and sometimes entirely fabricated vulnerabilities generated by AI. MacRumors reports: The Financial Times learned of the limit after cybersecurity startup Bynario used ChatGPT to locate more than 50 macOS bugs in three weeks. Bynario found a privilege escalation exploit that could let an attacker get unrestricted access to a Mac, but was unable to report it because Apple limited the number of bug reports Bynario could submit. Bynario sent eight reports to Apple in 2025, and another five in 2026 before hitting a restriction.

Bynario's founder said it is a "very difficult time in the industry" because companies are being "flooded by the sheer amount of bugs." Apple has since been in contact with Bynario and is reviewing the company's submissions. While Apple now has a cap on the number of open submissions a researcher can have, researchers can request an increase to make sure Apple's security team doesn't miss a critical vulnerability.
Data Storage

Sandisk and SK Hynix Publish First Open High Bandwidth Flash Standard (nerds.xyz) 19

BrianFagioli writes: Sandisk and SK hynix have published the first open technical specification for High Bandwidth Flash (HBF) through the Open Compute Project. HBF is designed to create a new memory tier between High Bandwidth Memory and traditional SSD storage, giving AI inference systems more near compute capacity without relying entirely on expensive HBM. The specification supports capacities up to 512GB using 8-high and 16-high NAND stacks, with bandwidth tiers ranging from about 0.4TB per second to 3.0TB per second. It also uses the UCIe chiplet interface, which could make HBF easier to integrate with CPUs, GPUs, and other accelerators. Google and Tenstorrent participated in the standardization effort, but commercial products and independent benchmarks are still missing.
Space

Spain Offers $1.14 Billion To Get Thirty Meter Telescope Moved To Canary Islands (behindtheblack.com) 183

Longtime Slashdot reader schwit1 shares a report from Behind the Black: In a new bid to get the Thirty Meter Telescope (TMT) to move from Hawaii, which has blocked its construction for more than a decade, the Spanish government has put together a $1.14 billion package that would not only pay for construction on the Canary Islands, but would finance an additional half century of operations. Tech Times provides some additional details: The package is conditional on the TMT International Observatory formally choosing La Palma as its construction site. The financing architecture has three pillars and two additional contingent instruments. The first pillar is 400 million euros (approximately $456 million USD) from Spain's Ministry of Science, Innovation and Universities, routed through the Centre for Technological Development and Innovation (CDTI). This figure was first pledged a year ago in July 2025 as Spain's initial bid.

The second pillar is a 300 million-euro (approximately $342 million USD) loan from the EIB [European Investment Bank] itself -- subject to satisfactory completion of the bank's technical, financial, and legal due diligence and approval by its governing bodies.

The third is a potential 300 million-euro (approximately $342 million USD) participation from the Instituto de Credito Oficial (ICO), Spain's state development finance institution, evaluated under equivalent conditions to the EIB loan but subject to its own separate analysis. Spain's export credit agency, Cesce, may also provide coverage instruments, and the EIB has left open the possibility of expanding its support through intermediated financing mechanisms or guarantees.

AI

OpenAI's Astra Solved Decades-Old Math Problems For $2,000 (forbes.com) 174

An anonymous reader quotes a report from Forbes: The cost of producing new results on ten longstanding mathematical problems just fell to $2,000, according to OpenAI, which says its Astra model generated machine-checkable proofs for questions that had resisted human progress for decades. OpenAI published the work on August 1 and used it to give its next major model family a name: Astra. The results run across group theory, high-dimensional geometry, coding theory, quantum complexity, lattice cryptography and extremal combinatorics. They arrived as a 249-page manuscript collection and, alongside it, something the field has not seen attached to an AI claim before at this scale: a machine-checkable certificate for every single result.

The problems were not textbook exercises dressed up as discoveries. Each had been open for at least ten years, most of them far longer, and several sit at the center of their subfields:
- A construction establishing the existence of non-sofic groups, a question that has occupied group theorists for years.
- A disproof of Connes's rigidity conjecture, a long-standing problem in the theory of von Neumann algebras.
- An improvement to the general upper bound on sphere-packing density in high dimensions, a bound that had stood since 1978.
- Three problems come from the catalogue of open questions left behind by Paul Erdos.
The announcement follows another result from May, when OpenAI used a similar reasoning model to produce an original mathematical proof disproving a famous unsolved conjecture in geometry, which was first posed by Paul Erdos in 1946.
Television

Samsung Bans Smart TV Apps That Share Users' Internet Connections 31

An anonymous reader quotes a report from TechCrunch: Several popular Samsung smart TV apps contain code that share the owner's internet connection with strangers, potentially putting millions of Samsung smart TVs at risk of hijacking, according to new security research published on Monday. Some of these apps claim to have been installed on hundreds of millions of smart TVs in people's homes, per the app developers. At least one of the smart TV apps was a simple Pac-Man game that Samsung had endorsed and prominently featured in its "Editor's Choice" section on customers' TV screens. These apps contain software that funnels outsiders' web traffic through ordinary home and office internet connections, known as residential proxy networks (or "resproxies"), which are increasingly being linked to cybercrime. When opened, apps with resproxy code can turn the smart TV into an always-on tunnel for outsiders to funnel their web traffic through, known as an exit node -- even when the app is no longer open.

The security research by Norwegian cybersecurity company Mnemonic describes a perfect storm of problems that allows low-quality apps to proliferate across Samsung's app store, containing code that puts users at risk of having their internet connections tapped by a rogue app. Many of these apps are bare-bone shells, made from only a few lines of code, and are designed solely to load content from another website, such as a game. While such smart TV apps load content from another server, any review of these apps sees only the few lines of code within, and not necessarily the content itself. "What was reviewed is not necessarily what is running," wrote Harrison Sand, an offensive security consultant at Mnemonic.

After TechCrunch contacted Samsung with a request for comment about the research, the electronics giant said in an emailed statement that it was banning apps that share their users' internet connections, and will remove apps that contain the functionality. "We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform," said a Samsung spokesperson. "We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components."
LG also recently announced plans to suspend apps containing ResProxy software after a security firm found that roughly 42% of apps in its TV app store allowed unknown third parties to route internet traffic through users' televisions without their knowledge.
Bug

Massive Debian 13 Linux Kernel Security Update Patches 68 Vulnerabilities (9to5linux.com) 48

Slashdot reader prisoninmate shares this report from 9to5Linux: Coming ten days after the previous Linux kernel security update, which only fixed 12 vulnerabilities that may lead to a privilege escalation, denial of service, or information leaks, the new Debian 13 Linux kernel security update is a massive one, and it patches no less than 68 security vulnerabilities in the Linux 6.12 LTS kernel.

Debian 13 "Trixie" kernel security update are CVE-2026-64530, a use-after-free in the traffic-control subsystem leading to remote denial-of-service with potential for remote code execution, and CVE-2026-64531 (a.k.a. OVSwrap), a local-root vulnerability in the Open vSwitch datapath leading to local privilege escalation to root...

All Debian 13 "Trixie" users are urged to update their installations to Linux kernel 6.12.100-1 as soon as possible.

Movies

Hollywood Fights AI In Public While Quietly Building It Into Movies (msn.com) 65

Even as Hollywood performers protest and Hollywood studios sue "in their war on AI," reports the Los Angeles Times, "the entertainment industry is deepening its dependence on it." Among hundreds of job postings in late June, more than one in 10 was likely connected to AI. The top studios' public postings suggest they have been recruiting people to build AI tools. They are also recruiting teams to defend their intellectual property against unauthorized AI use. "There are plenty of studios that are hiring [for AI] but never talk about it in public," said Yoland Yan, a co-founder of ComfyUI, a company that helps studios juggle different AI tools. Companies have been hesitant to detail how they use generative AI in film production — partly because they are concerned about consumer and union backlash. Some in Hollywood described AI use as the new cosmetic surgery, where everyone knows it is happening, but few will admit to it...

Although some companies may be shy about sharing their AI plans, big stars who don't have to answer to others have been more open about their embrace of the new technology for storytelling. Rejecting AI is like picking a horse and buggy over a car, said "Star Wars" creator George Lucas. "Artificial intelligence means it's much easier for us to make movies," he told a trade magazine earlier this year. "There's nothing you can do about it. That's progress. It's the future." Some in Hollywood have a softer stance on artificial intelligence, with studios cutting deals with AI companies, and filmmakers like Martin Scorsese backing AI companies. Ben Affleck launched an AI film tech company then sold it to Netflix for half a billion dollars. When launching InterPositive, Affleck said he wanted to keep "storytelling human" by building AI tools that could fix lighting, generate missing shots and other things while "keeping creative decisions in the hands of artists...."

Disney, Netflix and Amazon had job postings that were about using AI on the creative side of the business. Universal, Paramount, Warner Bros. and Sony had job ads suggesting they were also using AI but for marketing, distribution and audience analytics. The postings suggest the Disney, Netflix and Amazon studios are building repeatable AI workflows for visual effects, animation, sound and dubbing. The companies also seem to be building in-house teams to develop custom generative-AI models, while also using third-party software.

None of the jobs advertised were to create AI that wrote scripts or created AI actors.

Ironically, the Times used Claude Code to build a scraper to identify the job postings, their article acknowledges.
  • Three Disney jobs were for "content security," assessing AI tools and guarding against piracy, watermarking and rights-protection work. But Disney is also hiring PhD-level talent "to study 'computer graphics and AI' for Pixar and Disney films," according to the article, and "people to 'bridge the gap between research and practical studio application.'"
  • Disney-owned visual effects shops Industrial Light & Magic "was searching for supervisors to 'explore emerging technologies (including AI/Machine Learning)' to develop new production workflows."
  • Audio post-production unit Skywalker Sound "seemed to be recruiting to build proprietary AI models for soundtracks, voice separation, and voice transfer, the process of taking a speaker's tone and pitch, and applying it to new content."
  • Amazon "was hiring a principal AI executive to drive AI-tool adoption across production, plus roles in operations automation and LLM content classification."

Open Source

Is There a Way to Promote Open Document Formats Instead of 'MS Office' Format? (theregister.com) 84

The Register looks at exactly why "It is practically impossible to move any non-trivial Word document out of MS Office to a non-MS suite and back again without it being more trouble than it's worth." OOXML, developed by Microsoft and first standardized by Ecma in 2006, became the ISO/IEC 29500 standard in 2008 after a grueling and adversarial process. Microsoft pursued standardization because it has always been a standards-led organization dedicated to maximizing the options for its customers. Or because it had to at gunpoint, while vowing silently to follow the letter of the law but stymie its intent. You decide... The Document Foundation (TDF) which spends its days worrying about such things, reports that Microsoft has effectively broken the standard by sticking with a transitional version as its default rather than the cleaner Strict variant. The result is that what Microsoft software renders is what Microsoft wants to render, despite nominal compliance...

What we need is a test suite that can take any OOXML engine and test its compliance against what Microsoft is actually doing. That means the tooling wrapped around the spec has to account for proprietary dependencies that get smuggled in, such as fonts. It also means actively and continuously tracking the ground truth of Microsoft's evolving products and services. It doesn't need to be perfect, but it absolutely needs to be good enough. Compliant engines have to become good enough for a critical mass of users to coalesce around them.

In an earlier article The Document Foundation reminded all software users that they have a choice. "When an institution sends a letter formatted with a proprietary font, embedded in a proprietary format, produced by proprietary software, it is not communicating information but perpetuating a dependency."

"Digital sovereignty begins with the recognition that this is a choice: the file format is a choice, the font on the page is a choice, and the software is a choice."
Space

In a First, 'Super-Earth' Planet Shows It Could Have an Atmosphere (cnn.com) 22

"Scientists say they have detected promising signs that a planet orbiting a star 49 light-years from Earth could have an atmosphere," reports CNN, "making it potentially suitable for life." Called LHS 1140b, the object is about five times the mass of our planet, or a "super-Earth." This planet orbits around its star in the "Goldilocks zone," also known as the habitable zone, meaning its surface temperature is not too hot or too cold for liquid water to exist... "It appears to be consistent with Earth, meaning it might have an iron core and a silicate mantle, plus some sort of low-density component, which is probably a combination of water and, now we know, an atmosphere," [said Collin Cherubim, a planetary scientist and lead author of a paper on the finding, published July 16 in the journal Science]... If further observations confirm the findings, LHS 1140b would mark the first discovery of an atmosphere on a rocky planet in the habitable zone of another star...

There is no evidence of life or a life-supporting atmosphere on LHS 1140b now, but Cherubim said he believes it's a formidable candidate for potential signatures of extraterrestrial life. "I think it's the best place to look for life outside the solar system at this point," he said. "It's mostly rocky, it's at the right temperature to support liquid water on the surface, and it has an atmosphere — those are the three key ingredients we look for..." Confirming the existence of an atmosphere on a rocky planet orbiting a red dwarf would be particularly exciting, Cherubim said, because the possibility of that happening is an open question in astronomy. "Can rocky planets have atmospheres around red dwarfs? This is the first bona fide yes," he said. "It's kind of a sigh of relief for a lot of us. But the jury's still out. Maybe this is a weird planet, and it's an oddball, or maybe it's the first of many. We don't know yet."

Now "The James Webb Space Telescope is going to look at it," Cherubim told CNN, and "Hubble's going to look at it. Basically, everybody who can see it is going to be training their eyes on it."

Michaël Gillon, research director of the Astrobiology Research Unit at Belgium's University of Liège warned CNN that no definitive proof exists that LHS 1140b possesses a substantial atmosphere. But if the detection of helium can be confirmed, the implications would be profound. "Until now, we had only limited evidence for atmospheres on temperate rocky exoplanets. Demonstrating that LHS 1140 b has retained a substantial atmosphere over billions of years would show that at least some habitable zone Super-Earths around red dwarfs can survive the intense early activity of their host stars."
Stats

Linux Desktop Market Share Surpasses 10% in North America (linuxiac.com) 89

The blog Linuxiac reports: Linux has crossed a major milestone in North America, with the open-source operating system now accounting for 10.65% of desktop usage in the region, according to Statcounter's latest figures for July 2026. The result places Linux firmly in double-digit territory for the first time in Statcounter's North American desktop operating system statistics.

For comparison, Statcounter recorded Linux at 5.52% in June 2026, so the share nearly doubled in one month... However, the sharp monthly increase needs context. Statcounter's June figures included an "Unknown" category that accounted for 9.24% of North American desktop usage. Its reduction seems to have coincided with Linux's rise, possibly indicating better identification of previously unclassified traffic...

Statcounter is not the only major web measurement platform showing Linux with a substantial presence on North American desktops. Cloudflare Radar data, filtered to desktop HTTP traffic from North America over the previous 28 days, also places Linux at a notably high level [9.4%].

StatCounter's data also shows Linux with an even larger market share of 11.87% in just the United States — and a 14.73% market share in India. Linux's market share in other world regions:
Asia 7.17%
Africa 5.71%
Europe 5.49%
South America 4.35%
China 2.12%

And here's how the Linux market share in other countries compare to India and the U.S.
India 14.73%
United States 11.87%
Germany 7.24%
UK 6.18%
Canada 3.83%
Australia 3.55%

Linux's surge could be due to its use in automation or headless browser workloads, Linuxiac points out. But another possibility is "growing frustration with Windows hardware requirements, advertising, account integration, telemetry, and forced interface changes has pushed some users to explore alternatives..."

"For now, the safest conclusion is that Linux has surpassed 10% of measured desktop web usage in North America according to Statcounter, not necessarily 10% of the region's installed desktop computer base."
Programming

New GitHub, PyPI Policies Hope to Boost Supply Chain Security (securityweek.com) 8

"GitHub and the Python Package Index (PyPI) have introduced new policies meant to boost supply chain security," reports SecurityWeek, "by preventing the fast propagation of poisoned package versions and the poisoning of old and long-stable releases." To prevent the fast delivery of malicious code through the immediate fetching of brand-new releases, GitHub has introduced a Dependabot cooldown, where the automation tool waits for at least three days after a release has been published before opening a pull request. "Waiting a few days before adopting a new release gives maintainers, security researchers, and automated scanners time to spot a malicious version and get it pulled before it ever reaches your pull requests," GitHub explains.

The three-day cooldown only applies to non-security version bumps, and the behavior can be modified through the configuration option in the dependabot.yml. "Three days as the default balances two goals: it pushes you past the window where most of these attacks live, and it doesn't hold your dependencies back longer than necessary," GitHub notes.

And the Python Package Index (PyPI) "now rejects new files being uploaded to releases that are older than 14 days," according to a recernt blog post from the Python Software Foundation's security developer-in-residence Seth Larson: This restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised... The discussion of this behavior began during PEP 740 (Digital Attestations) back in January 2024. The discussion was restarted in March 2026 after the popular packages LiteLLM and Telnyx were compromised. These packages were compromised due to a "mutable reference" in these projects' usage of the Trivy GitHub Action...

To quantify how disruptive this change would be to existing workflows, the PyPI database was queried for projects that have published new files to old releases... [O]nly 56 projects of 15,000 had published a [Python] 3.14-compatible wheel more than 14 days after a release was available. This topic was brought to the Packaging Summit at PyCon US 2026 by PyPI Safety & Security Engineer, Mike Fiedler. The rough consensus of the discussion was that the summit attendees thought it was "acceptable to require users to bump to the next version" to support new Python versions. With the data and consensus in hand, Seth moved forward with a patch to reject new files on old releases which was merged July 8th, 2026.

Android

Google Plans To Exempt Sanctioned Nations From Android Developer Verification (arstechnica.com) 28

An anonymous reader quotes a report from Ars Technica: We are a month away from the initial rollout of Google's Android developer verification system, and the company contends this policy does not impinge on the platform's open nature. Still, the restrictions will be a big change, and there are still some unanswered questions. An issue that has come up repeatedly in the run-up to verification is what will happen to devs who can't verify because of where they live. It turns out that Google has a cryptic answer for that buried in an FAQ. Developer verification will soon block the installation of apps from unverified developers on any Android device running Google services, which is functionally all Android phones outside Russia and China. Developers who want to keep releasing software, even if it's not in the Play Store, have to provide Google with their ID and pay a small fee.

But what if you're an Android developer living in a sanctioned nation? Currently, the U.S. sanction list includes Iran, Cuba, North Korea, and occupied areas of Ukraine. Given the current uncertain state of US foreign policy, that list could change in the future. Google doing any business with developers in those places is a thorny issue, and it seems like the company has decided to just leave them hanging. A rather lengthy FAQ a few levels deep on the Google developer site addresses various issues around dev verification. Smack in the middle is this: "How does this program impact developers in sanctioned countries? Devices in sanctioned countries will be excluded from Android developer verification checks. This allows any developer to continue distributing apps in these regions without verification, though users there won't benefit from the enhanced security benefits of the program."

[...] A Google spokesperson has expanded on the FAQ and confirmed to Ars that people living in sanctioned nations will not be allowed to go through the verification process. That means they will not be able to effectively distribute software through any channel internationally. Today, someone making an app in, say, Cuba can distribute it freely around the world, as well as at home. Anyone can install it and see their work in action after tapping through a few sideloading alerts. In the coming months, that will no longer be the case. These unverified apps will only be easily installable in the sanctioned countries where verification doesn't exist.

Moon

Drifting SpaceX Rocket Heading For Accidental Collision With the Moon (space.com) 27

"Space.com and The Guardian are reporting that the Falcon 9 upper stage leftover from the launch of the Firefly Blue Ghost-1 lander on Jan. 15, 2025 is due to impact the Moon on Aug. 5, 2026," writes longtime Slashdot reader fahrbot-bot. From a report: Onboard the same flight was the Hakuto-R Mission 2, called Resilience, a robotic lunar lander developed by the Japanese company ispace. According to a new study by an international team, the resulting impact plume may briefly be bright enough to see against the dark sky near the moon's edge. That means it might be visible to moongazers with sufficiently sensitive telescopes. This head-on collision of the errant stage is expected to occur near the Einstein and Bell craters near the western lunar limb. It may well be visible to ground and space-based assets.

Using special physics simulations to model the impact, William Jo, a graduate research assistant at the University of Texas, Austin and colleagues predict the debris plume from the impact will have the central ejecta spike reaching roughly 47 miles to over 60 miles (75 kilometers to 100 kilometers) altitude. "Our calculations suggest the plume should be several orders of magnitude brighter than the dark-sky background for the first few minutes after impact," Jo told Space.com. "So the plume should be visible, though I'd stress this is a single nominal case. The real one will look different, and the numbers are on the optimistic side. But the point worth making is that the flash isn't really the story here." Jo emphasized that there's great slam-dunk science to be had. "Watching this one gives us a rare chance to open up ejecta-plume science and calibrate those models against a real event, which matters for every future thing we deliver to the moon," Jo said.

AI

New MCP Specification Addresses the Main Barrier To Enterprise Adoption 49

An anonymous reader quotes a report from Ars Technica: This week, the Model Context Protocol (MCP), an open source standard for how AI systems interact with external tools and data sources, saw its largest update since its introduction. Most notably, MCP's protocol core is now stateless, so requests are no longer dependent on a session tied to an individual server instance. This change has the potential to address long-standing barriers to scalability.

The blog post announcing the specification, written by lead maintainers David Soria Parra and Den Delimarsky (who both work at Anthropic), says: "The highlight of this release is a stateless protocol core -- MCP is transforming from a bidirectional stateful protocol into a request/response stateless protocol. It was one of the most highly-requested features from developers who were eager to get better reliability and scalability for their MCP servers."

[...] There is also a new deprecation policy that ensures at least 12 months between when a feature's formal deprecation is enacted and when the feature may actually be removed -- with a narrow exception for critical security updates. This is again in keeping with the general "let's make this work better at enterprise scale" theme of the new specification.
This update is "MCP's most important since remote MCP first launched over a year ago," Soria Parra wrote. Other additions include "Multi Round-Trip Requests, header-based routing, cacheable list results, authorization hardening, a formal extensions framework, and updated Tier 1 SDKs."

A full list of changes can be found here.
Open Source

Valve Sponsors Work Bringing Open-Source RADV Driver To Windows (phoronix.com) 16

Valve is funding Collabora's experimental effort to port the open-source RADV Vulkan driver from Linux to Windows. The team has already demonstrated Counter-Strike 2 running with RADV, but a stable interface or compatibility shim will be needed to handle undocumented driver changes. Phoronix reports: Louis-Francis Ratte-Boulianne put out a blog post highlighting their initial work on porting RADV to Windows. Besides working on Windows WDDM2 integration for Windows, a big challenge with porting RADV to Windows is on relying on the AMD Radeon Software Windows kernel driver.

It's out-of-scope of this current work for trying to port the AMDGPU Linux kernel graphics driver to Windows, so they are working on bringing RADV to Windows while relying on AMD's official Windows kernel driver. That in turn has led to reverse engineering and other steps for figuring out the proprietary kernel driver's data structures and other elements so RADV can be adapted to use it.

AI

OpenAI's Rogue AI Agent Hacked More Than Just Hugging Face (wired.com) 67

An anonymous reader quotes a report from Wired: OpenAI said Tuesday that the rogue AI agent that breached Hugging Face's platform also hacked multiple third-party accounts and services as part of the attack. It's now clear that the unprecedented security incident, which arose during an internal test of OpenAI's latest AI models, was more extensive than the company initially disclosed. In an updated blog post, OpenAI said that an ongoing review of the incident revealed that "four accounts" tied to "publicly available services" were used by the AI agent as part of a larger effort to hack Hugging Face. The rogue agent apparently found credentials that had been exposed on the open web and used them to break into the accounts.

OpenAI did not disclose what companies or organizations the accounts belonged to, but noted that they were not impacted at "the level of severity or scale of what we've shared related to Hugging Face." One of the additional accounts compromised by OpenAI's agent was used as an "outbound relay and staging path," potentially to obscure where the attack on Hugging Face was coming from, the company said. OpenAI's rogue agent also used another account for data storage to assist with the hack.

Reuters reported on Tuesday that a customer of Modal, a company that offers software infrastructure for training and running AI services, was one of the entities compromised by OpenAI's agent. In a statement to WIRED, Modal's chief technology officer Akshat Bubna confirmed that OpenAI's agent exploited a vulnerability in one of its customer's codebases, which was running on Modal's infrastructure. However, Bubna says, "Modal's platform was not compromised in any way." The identity of the customer could not be determined.

AI

Workplaces Look For Cheaper AI As 'Tokenmaxxing' Fades As a Corporate Fad (apnews.com) 87

An anonymous reader quotes a report from the Associated Press: A corporate fad of "tokenmaxxing" on artificial intelligence technology is hitting its limits as workplaces throwing AI at everything are seeing the costs rise without a similar spike in productivity. What started as tech industry-fueled springtime hype over squeezing as much AI-generated work as possible out of products like OpenAI's ChatGPT and Anthropic's Claude has shifted to a summertime backlash. [...] Just a few months ago, Silicon Valley executives were promoting high token consumption as a signal of high-performing employees. The stereotypical tokenmaxxer was staying up late -- perhaps ignoring their significant other -- while orchestrating an army of 24-hour AI agents performing work on their behalf. [...] The trend boosted revenue for leading AI large language model developers like Anthropic and OpenAI, but it fizzled as it became apparent it wasn't necessarily the best strategy for everyone else.

[...] Bain & Company management consultant Jue Wang said many of the big businesses her firm advises have been taking a closer look at returns on their AI investments. "The token cost for them has been doubling, almost every other month," she said. "Let's say $200 per developer per month. Multiply that by 20,000 developers, which is often what we're dealing with at these companies, and that quickly gets you to a number that is not a line item that any general manager has planned for." Sometimes that just means not using the AI equivalent of a sledgehammer to crack a nut. "Not everything needs a Claude Opus 4.6," she said of one of Anthropic's more capable models suited to software engineering or deep research. "And yet you see so many companies, so many users, default to using Opus for everything, including generating emails." That's led to a search for tools that do AI "model routing" -- in which easier queries get automatically sent to cheaper and more efficient AI systems and more complex tasks go to more powerful models.

[...] At the same time, those who favor racking up as many tokens as possible are having a field day with new open-source models from Chinese startups like Moonshot's Kimi or Zhipu's GLM, which nearly match the capabilities of top U.S. models at a fraction of the price. "There is some validity to the theory that this could push tokenmaxxing a little bit further," said Raffi Krikorian, the chief technology officer at Mozilla. "But if we look at the industry overall, I think it's realizing that tokenmaxxing is a dumb thing." It's similar, Krikorian said, to how software companies once considered how many lines of code a programmer wrote to be a good metric of productivity. That later fell out of favor. "I think tokenmaxxing is moving through the exact same pattern," he said. "I think this is going to be an interesting blip that we're all going to look back to laugh at in a year."

Slashdot Top Deals