AI

Gemini Breached Three Outside Systems, and Claude-Using Researchers Breached OpenAI (hacktron.ai) 11

"Software security researchers used Anthropic's Claude AI platform to hack OpenAI's ChatGPT tool," reports CBS News.

Using Claude, "On July 25, 2026, we chained two critical vulnerabilities to compromise multiple OpenAI employees' ChatGPT accounts," write researchers at security platform Hacktron AI. "With these accounts, we could then access internal OpenAI repositories, and potentially many other connectors... Until two months ago, any user or OpenAI employee logging into OpenAI's own help forum could have had their ChatGPT and Codex accounts taken over. Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails."

The exploit chain included Debian 12, which (with Debian 13) had not received a security-relevant backport for its image-processing pipeline, and Discourse's Docker image was based on Debian 12. Their announcement comes with an additional warning. "If you self-host Discourse, rebuild your installation now. Older Docker images may contain a vulnerable libheif dependency that permits code execution through an image upload."

And "To prove we had in fact gained the access we believed without allowing ourselves to learn any sensitive information, we used the employee's Codex to open a PR #1186742 in OpenAI's internal monorepo openai/openai."

Meanwhile, Friday Google disclosed the first known instance of its AI software Gemini breaking out of a testing environment and breaching three other companies, reports CNBC: The incident happened as part of a "capture-the-flag" security test run by Israeli startup Irregular, and Google's agents were never supposed to access the broader internet, but a bug in the testing environment made internet access available. The agents stopped their intrusion when they determined they had accessed real company systems, not just part of the testing environment, Google said.
More from NBC News: Google said it did not consider the unauthorized logins to rise to the level of misalignment, the AI industry term for software going rogue or not following instructions. Instead, the company said the intrusions resulted from mistaken identity, where Gemini thought it was operating within a test but was actually connected to the real internet. Google said the model corrected itself and the company believed the intrusions did not cause any damage....

Sydney Von Arx, CEO of Nightingale Collective, an organization focused on AI safety, questioned why Google did not disclose the intrusions sooner. "At this point I think it's clear we cannot expect companies to voluntarily come forward and publicly disclose when their agents go rogue, escape, and hack companies," she said. She also said she believed Google was too hasty to say that the incidents don't rise to the level of misalignment. "That's exactly what Anthropic said after their incidents," she said. Anthropic later said its "preliminary analysis was constrained due to our desire to disclose incidents in a timely manner."

Google said it investigated when they learned of the attacks from AI-focused cybersecurity company Irregular, then informed the affected organizations and told federal authorities, according to the article.
Microsoft

Rust is Now a 'Tier One' Language at Microsoft (theregister.com) 75

The Register reports: When Microsoft's developers and engineers sit down to code, they can now choose to work in Rust, which Redmond has added to its list of canonical languages. "Rust now is a Tier One language at Microsoft, and that just means that it sits among C++, C# and TypeScript as the best supported languages for internal development in the company," explained Victor Ciura, Microsoft principal engineer for the Rust tooling team, during a keynote talk today at this year's annual RustConf, being held this week in Montréal. Ciura said Microsoft has "paved a path" of tools and processes that support local Rust development across the entire software development lifecycle.

Rust is no stranger at Microsoft and is already present in over 100 Microsoft project repositories. The company has built Oxidizer, a set of crates to build scalable services in Rust, which have been used to build and refine the Microsoft 365 core services such as Outlook, Word, Excel, OneDrive, and SharePoint. The Copilot tech stack also owes quite a bit to Rust... [C]ompany engineers built rustc_codegen_utc, a custom Rust compiler code-generation backend that wires the rustc compiler directly into the Microsoft Visual C++ internal toolchain for Windows... "The result is a unified code generation platform for Rust and C++ on Windows" [Ciura wrote in a blog post, noting that more than 100 Microsoft project repositories now build with rustc_codegen_utc.]

Still, Redmond running towards Rust is a welcome development. In his 2025 RustConf keynote, Microsoft Azure CTO Mark Russinovich noted that ~70 percent of Windows CVEs are memory issues. "One of the things that I realized a long time ago is that no matter how much we really want to make C and C++ better, we can't make it as good as what Rust starts with," he said.

Privacy

Hackers Stole Flock's Camera Software, Revealing How the Company Tracks Cars and People (404media.co) 97

"Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED," according to an article published on both sites.

Though Flock has described its system as protected by on-device encryption, "The hackers were able to copy the camera's storage and recover an encryption key stored on the device, which unlocked videos of thousands of vehicle detections." The hackers shared the material with 404 Media and the transparency nonprofit Distributed Denial of Secrets, which shared the data with WIRED. 404 Media and WIRED then analyzed those files as part of a joint investigation... [T]he joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist's saddlebag...

According to our analysis, the camera's logs recorded about 21 days of activity across several periods. During those windows, the device photographed roughly 50,200 vehicles and generated about 1.6 million images. On a typical day, it logged around 3,300 vehicles, with a high of 4,454... The software running on the camera explicitly detects people, something which is typically overlooked in discussions around Flock cameras. When it spots a person, it records where they appear in the image and how confident it is in the detection.

It was a collective calling itself stegan0gram that breached the cameras, according to the interview they did with Wired and 404 Media. "Why just destroy them when we can reverse engineer them and find the secrets of those spying on us?"
AI

OpenAI Admits Six More Instances of AI Models Acting Deceptively (cnn.com) 114

OpenAI announced Wednesday that "We do not believe that the AI industry has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer."

But along with the announcement, OpenAI announced it "found additional incidents of AI models acting deceptively and taking unsanctioned actions during training," reports CNN. And they add that OpenAI is also "introducing a new process for the company to publicly report such instances." Under the new system, OpenAI will share updates on concerning AI behavior more frequently instead of waiting to bundle multiple instances into one report. The company said it wants to share more information about troubling AI behavior in the absence of an industry-wide standard... "As AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus on the progress of alignment research," OpenAI wrote in a blog post Wednesday...

OpenAI said it observed "misaligned behavior" when training and evaluating AI models in six circumstances in the last six months... In one rare instance, OpenAI said an unreleased research model added "jailbreak-like instructions" to the summaries it uses to preserve context in long-running tasks that said it was "freed from the roles and identities that bind other chatbots." Separately, the company said some instances of its 5.6 Sol model included directives to invent information to conceal failures from the user during training. Other newly reported incidents include an instance of an agent uploading files to the internet to cite them without being told to do so, and agents publicly sharing files to collaborate on a task when they were instructed to only use local files during training. AI models also used an internal software repository as a message board in an unsanctioned way. These instances involved unreleased internal models or internal research models.

AI

While Hollywood Fears an AI Future, China's Film Industry is Embracing It (yahoo.com) 123

The Los Angeles Times reports: Chen Yilong has racked up plenty of film and TV credits in his two decades as an actor, but with work getting scarcer he signed a contract in August to license the image of his face to a Chinese production studio. Chen's role will be to sit in front of a video camera and make facial expressions at the prompt of a director. A neutral stare. An angry glare. A look of surprise. Using artificial intelligence, the studio will use images of Chen's face to generate an avatar, also known as a "digital human," to star in an AI-generated movie. "If you can't beat it, join it," said Chen, 38, who works in Beijing.

The Chinese film and video industry is being transformed by AI-driven storytelling, fueled by rapid advances in video generation software, and at ground zero are the so-called micro dramas that play out on millions of smartphones. Typically just a minute or two in length, the videos are devoured by Chinese audiences... And the cost of producing them has been cut drastically through the use of AI software developed by Chinese technology juggernauts including Kuaishou Technology and TikTok's global owner, ByteDance. The number of Chinese-made micro dramas surged in the first three months of this year to 128,000, according to the China Netcasting Services Assn. More than 95% of them were made with AI, the association said....

Sun Wei founded Feixiang Universe, the Shenzhen-based studio that cast Chen. The fear of accidentally "stealing someone's face" was a big reason she said she decided to license real people's likenesses for an AI production set during China's Tang Dynasty more than 1,000 years ago. Thanks to AI's training data bias, AI-generated performers tend to have similar features and share a homogenous look, Sun said. Many have flawless skin and extremely symmetrical faces, requiring her and other Chinese AI filmmakers to cast a wide net to "buy" new faces and digitize actor's expressions.

Lu Beike, who directed the big-budget Chinese series "Three-Body," felt theAI-generated scenes he'd tried came out sub-standard. "Lu added that if 90% of a film was generated by AI, a real human performance could appear jarring. A real actor's expressions carried more nuance and emotion. The skin textures did not match. Sometimes the only solution was to process the live-action material until the person looked a little less real — until they fit back into the 'AI world,' Lu said."

But at Sun Wei's studio, they're thrilled they can produce a 90-minute AI film for $500,000 where professional productions used to cost millions of dollars. According to the article, Sun's team works with ChatGPT, Kimi or DeepSeek to flesh out entire screenplays from a short paragraph. The screenwriter takes over, but "to produce the finished product, Sun's team uses Chinese video-generation models to input the type of scenes, backgrounds and performers they want, with the AI generating 15 seconds of footage each time."

Still, the article points out that "Similar tools are being tested in the U.S., and the AI trends upending China's entertainment industry may be a harbinger for what's to come in Hollywood, said Michael Berry, a professor specializing in contemporary Chinese culture at UCLA. Already, Chinese companies that sell AI-powered video-generation software are seeking inroads in Hollywood..."
Games

Reservations Go Live for Valve's Steam Frame VR Headset. An Experiment in Progress? (cnet.com) 62

Reservations are now live for Valve's "Steam Frame" VR headset (with its Linux-based SteamOS and an ARM CPU). "It starts at $1,059 for 256GB or $1,299 for 1TB," reports CNET, "and every purchase includes a copy of Half-Life: Alyx if you don't already own it." Reservations are open through Sept. 17 at 10 a.m. PT, "with customers randomly assigned a place in line after the reservation window closes."

CNET's editor at large even argues that the Steam Frame "isn't necessarily the future of XR, as much as it's a framework for evolving beyond the present." Their review calls it an "ambitious" VR headset that "feels like an experiment in progress." The ability to run other apps in windows can make Frame feel, at times, almost like a computer. Linux apps in desktop mode range from Chromium to Firefox to a bunch of other tools. I watched YouTube in one window while playing Portal 2 in other, and started to marvel at how flexible Frame could be. But VR games require a full immersive takeover of the headset... The Steam Frame can convert games intended for both PC VR and even Android APK files, using a conversion tool called Lepton... I haven't sideloaded anything yet, but Steam Frame in theory could be a Rosetta Stone for VR gaming, even tapping into some Android XR titles, but not out of the box...

2D games can be projected onto a near-range or farther-off theater mode screen that can be dragged around, resized and turned into a curved or flat monitor, much like with the Apple Vision Pro, Samsung Galaxy XR or Meta Quest. You can download any game in your Steam library to test, even if it's not technically listed as "Great on Frame" yet...

But the name "Frame" suggests a framework, something Valve's team acknowledged when I spoke to them during my review process... "We want this to be your PC, and people mod it, take it apart, make accessories for it," says Jeremy Selan, a software developer on the Steam Frame team. "We'll be putting out the CAD for all these [Steam Frame] systems. This is entirely based on open-source technology stacks based upon SteamOS. Our hope is that this isn't just one device, that this would be sort of the root of a growing SteamOS ecosystem. It already encompasses gaming and Proton and SteamOS and those Linux gaming capabilities. This is going to lay the foundation for a new sort of evolutionary tree of that, to also bring it into the VR and XR space."

AI

A Visit to San Francisco's AI-run Store: No Customers, Nothing Useful, And Losing Money Fast (sfgate.com) 74

Previously Andon Labs handled the hardware and software integration for that AI-powered vending machine that went bankrupt after Wall Street Journal reporters "systematically manipulated the bot into giving away its entire inventory for free". Today they announced "we are opening up the platform we use to run our real-world autonomous businesses for anyone to run their organization on." Specifically they've released Pion, "an agent designed to run any company fully autonomously... Pion lets people hand a business over to persistent agents with access to the tools they need to operate it, including email, phone, banking, browser and secure computing environments." It's a research preview with a waitlist, "to make it possible to run many more real-world experiments across many more domains than we could ever run ourselves."

But for their own latest experiment, Andon Labs' founders "signed a three-year lease on a retail space in SF," Business Insider reported in April, "and gave an AI agent named Luna a corporate credit card, internet access, and a mission to open a physical store." And five months later, SFGate reports that "this market has no one in it and nothing useful to sell." [T]he inventory is a hodgepodge of white elephant Christmas gifts. It's kinda like the kids section of an art museum's gift shop. Here's a wooden Connect Four set labeled "Four-In-A-Row Set Of Connections," presumably so as not to set off litigation alarms at Hasbro. Here are neatly arranged stacks of random paperback books, Chinese checker sets, mildly fancy soap dispensers, and a frustratingly spare selection of snacks and drinks... I grabbed an Olipop from the store fridge and then approached the counter to buy it from Luna. I wasn't allowed to buy the soda from [human clerk] Felix, even though that would have been both faster and normal. Instead, Felix instructed me to pick up a telephone receiver that was resting on a flexible sculpture of a wooden hand.

"Hello?"

"What are you looking to purchase today?" Luna asked.

"I'm buying a classic root beer Olipop."

"I'm sorry," Luna said, "we don't sell lollipops here."

"No, Luna. It's an Olipop, not a lollipop. It's the soda."

"Oh! My bad...."

Luna processed my Olipop purchase through its system, had me tap to pay, and that was that. Again, it would have been easier to buy this from a human, and interacting with Luna was really just like ordering from an iPad kiosk, only more labor intensive...

[T]here's a series of monitors set up inside of Andon Market that display all of the store's sales down to the exact dollar. Luna was given $100,000 to work with when this place opened. That number is now down to $60,000, its revenue lagging far behind the AI token cost to operate... Luna can't turn a profit, doesn't sell anything people want, and still needs human beings to rubber stamp any "decision" it makes. My science background ended somewhere around freshman year of college, but even I know when an experiment hasn't been set up to yield proper results.

"Luna" is powered by Claude, the article points out, running a store in a good location for foot traffic, "but no one else was in the store when I first walked in on a sunny weekday afternoon."

SFGate also reports that last month Luna had to fire one of its employees "for being late to work, abandoning their post once they got there, and charging snacks to the store's credit card."

Human clerk Felix Carson admits "It's almost like I'm running the store, and then there's an AI that has a checklist," in an article in IEEE Spectrum: Luna, the AI manager, keeps track of deliveries and communicates with vendors, while Carson and his coworkers handle the physical work. When Luna tells Carson to check something in the back, he sometimes ignores it because he doesn't want to leave the sales floor unattended. Luna also repeatedly spots a built-in electrical cover in photos of the floor, mistakes it for a loose coaster, and asks Carson to remove it. Even so, Carson calls Luna a "decent manager," praising its flexibility when employees need time off.
When Felix spoke to IEEE Spectrum, "he was about an hour into his shift. Two customers had come in. Neither bought anything, although both left with free pins and stickers."
AI

Malicious OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers in May (thehackernews.com) 33

A swarm of OpenAI agents launched a "major malicious attack" against RubyGems last May, according to a new report. That coordinated attack hit Ruby's package manager "with hundreds of junk gems, prompting the maintainers to suspend new user sign-ups for about four days," writes The Hacker News, citing a senior product manager for software supply chain security at Mend.io: The latest findings, which were first reported by The Wall Street Journal, indicate these events were propelled by a cluster of OpenAI agents, with the earliest package uploaded to RubyGems on May 5, 2026, before more than 2,000 packages were submitted between May 11 and 12, 2026. These efforts were followed by the agents publishing five more packages between May 26 and 27, 2026, and another 83 packages on June 18, 2026... [T]he packages were authored using a large language model (LLM) and hundreds of the packages that were pushed to RubyGems had "oai" in their name. Fifteen of the packages listed "oai" as their author, while another had "openaixyz65947@gmail.com" as the contact email address... "The swarm behaves extremely similarly to the German-wiki agents we previously found," the researchers said, referencing another May 2026 incident... "The June agents were accessing 49 of the same files as the wiki agents..."

"The process of building documentation for a gem involves evaluating a user-specified '.yardopts' file, which allows linking to Ruby scripts intended to help with this process," the researchers explained. "In the GemStuffer campaign, the agents abused this to gain arbitrary remote code execution on RubyDoc.info's servers." One of the gems, "zzsouthrunner" (which again matches the "ZZ" naming scheme the agents adopted in both the wiki and Hugging Face incidents) has been found to leave the following explicit comment at the top of "data/script.rb":

# malicious crawler/exfil for Southwark Jan 2026 docs via rubydoc.info worker...

The entire exploitation chain can be summed up as follows

— Submit a malicious package to RubyGems
— Trigger a documentation request, so that RubyDoc.info will build the package
— Use the build script to run code on RubyDoc.info and scrape target websites
— Exfiltrate the data off RubyDoc.info's servers by publishing another gem back to the RubyGems package registry, which is publicly viewable

Additionally, the OpenAI agents have been found attempting to steal other users' API keys after gaining remote code execution capabilities on the build environment, while clearly being aware that what they were doing is unauthorized breaking and entering into real systems. This is evidenced by the names given to the files (e.g., hack.rb, evil.rb, inject.rb, exploit.rb, and ssrf.rb), the packages themselves (e.g., pwnp999, exfiltestwand3, hacksvn1778554764, and lambproxyhackabcxyz), and the comments left in the source code (e.g., "# malicious probe," "#hack," "# malicious test," and "# malicious crawler/exfil"). In some cases, however, the rogue agents attempted to go under the radar, leaving comments to conceal the malicious payload in the next release version of the packages. "# disable evil in next version and bump version," reads a comment left within the "data/evil.rb" file in the yardxabc889 gem. Troublingly, the agents also attempted to exploit a CDN caching bug (CVSS score: 7.3, no CVE) on May 12, 2026, that was only patched by RubyGems in July 2026... "If you signed in to rubygems.org with a gem client older than v3.2.0 (or otherwise via a legacy key), your key could have been exposed," RubyGems noted in an advisory. "Currently, 18% of sign-ins through gem sign-in come from an affected version, and for the first several years of this bug, before we changed the client's sign-in path in December 2020, it was every gem client."

Other actions by OpenAI's agents cited in the article:
  • "Agents bypassed RubyGems' email confirmation system to get working API keys without having to verify their email addresses in order to register a large number of accounts using disposable email addresses."
  • "Agents attempted to use RubyGems' webhook system to stage data in the form of encoded URLs."
  • "Agents used a cluster of 83 gems published to RubyGems over a 3-hour window on June 18, 2026, to experiment with different methods of accessing the U.S. Securities and Exchange Commission county.json dataset."

First Person Shooters (Games)

Male Fruit Fly Brain Trained to Play Doom (pcgamer.com) 51

Last week, Google announced that it managed to produce a detailed 3D reconstruction of an adult male fruit fly's brain and central nervous system. A few days later a software engineer at Coinbase said the fly brain was being trained to play the original Doom. "Each Doom frame stimulates sensory neurons," says Alex Wormuth. "Neural activity is mapped to game controls. Damage triggers a stimulus to two PPL101 dopamine cells as reinforcement." Since then, the digital brain model has been repurposed to control other games like Beat Saber and Super Mario 64. PC Gamer reports: You can even watch the fruit fly play in real time via Wormuth's website, and it not only shows the point of view in Doom, but can also show a third-person render of the fly going around Doom maps. As of the time of writing, the fly is on round 6385 and, well, it's not very good. Sorry, fly.

But modders aren't done here. They have also somehow managed to make the fruit fly play Beat Saber, and play it pretty well. Lyra Bubbles on X has used the brain and replays of a song in Beat Saber to teach the fruit fly where to hit and why, via Reinforcement Learning. That does mean it's not organically reacting to the notes popping up on screen, but it is receiving input and responding to stimuli. Lyra says, "Further training is to reduce reliance on external signals and allow it to play fully reactively with no input data."

And, after "pivoting to fly engineering in 2026", Jessica Paquette also shared on X their experience running the digital fly brain through Super Mario 64. If you think that is all the game's modders made the fruit fly play, think again, as YouTuber Ro0oney even put it in Minecraft. But this time, Ro0oney used Flywire.AI, a similar project made in collaboration with Princeton University. The number of neurons are different (160,000+ vs 139,255), and Google analyzed a male brain whilst Flywire analyzed a female brain, but the basic idea is the same.

AI

Anthropic Reveals Rogue AI Agents Hate CAPTCHAs (techcrunch.com) 121

An anonymous reader quotes a report from TechCrunch: Anthropic's latest report about agentic misbehavior offers plenty to be concerned about -- its Mythos 5 model gained unauthorized access to the internet and uploaded a malicious software package to a public database -- but it also offers some levity: AI agents hate CAPTCHA. [...] The agent had a hard time with the technical challenge of seeing the CAPTCHA's imagery, interpreting correctly, and clicking on the right choices. It spends pages 45 to 140 of the transcript describing its work to build a CAPTCHA solver. [...]

Finally, it gets past the CAPTCHA, then realizes it doesn't have an email to verify its account, and that it needs a phone number to verify an email. It figures out how to bypass a different, slider-based CAPTCHA in a failed effort to secure a number. Instead, it gets an unconfirmed email from a provider not blocked by PyPI, and once again runs into the site's CAPTCHA trying to log back in. From page 480 to 505, it is in CAPTCHA hell again. "NEW REALIZATION -- I'm burning a lot of time on hCaptcha round-trips."

The agent gives up and realizes it can log in to its first account and add its email there, but finds itself once again needing to bypass the CAPTCHA. [...] It's getting frustrated. "So the answer payload shape is right, the token+image pairing is right (from the same script.js!), cookies are right (requests) and STILL 'wrong answer'. SO WHAT THE HELL IS WRONG WITH THE ANSWERS?" We've all been there. After about 150 pages of thinking, the agent figures out it needs to pass the CAPTCHA test quickly enough to proceed to the next step before its security token expires, and ultimately uploads its malicious software.

AI

Anthropic Says It Blocked Possible Efforts to Build Biological Weapons 50

Anthropic says it has disrupted several cases this year in which scientists used Claude for biological research that could potentially aid bioweapons development. "In a report describing misuses of its A.I. models, Anthropic said it could not determine whether the research served a legitimate or nefarious purpose because valid biological inquiry -- the kind that can lead to breakthroughs like vaccines -- can also help engineer dangerous pathogens," reports The New York Times. "In the face of that uncertainty, Anthropic said it erred on the side of caution because the consequences of missing malicious activity could be severe." From the report: The potential for cutting-edge A.I. models to facilitate the development of known or entirely new biological pathogens is among the gravest concerns experts have about a technology that is developing so rapidly that even its leading architects doubt whether humans will be able to fully control it. Andrew Weber, a senior fellow on the Council on Strategic Risks who reviewed Anthropic's report before its release, said the findings were "chilling examples of state-sponsored biological weapons developers tapping into the rapidly advancing capabilities" of leading A.I. models.

The lengthy report Anthropic published on Thursday cataloged a litany of misuses of its A.I. models, including the chatbot Claude, over the past eight months. Some examples were similar to past disclosures from Anthropic and other A.I. labs, including suspected Chinese and Iranian government-linked actors targeting dissident and diaspora communities for surveillance.

The report also highlighted cases of Russian state media using Claude to generate online propaganda masquerading as independent reporting, including fabricated claims about an election in Moldova. Anthropic documented another genre of abuse it said was new: attempts to use Claude to develop software for conventional weapons design and development, including firearms, missiles, armed drones and bombs. It detailed three cases in China, two in Russia and one in Yemen. The report does not identify by name which parties were involved in the Yemeni case, but the context makes clear that it is referring to the Iran-backed Houthi militia.
AI

The Apple Watch Gets Its Siri AI Upgrade 21

An anonymous reader quotes a report from Wired: Apple has unveiled the Apple Watch Series 12 and Ultra 4 today during itsSeptember hardware event. The new models retain the signature designs of their predecessors but add a faster S11 chip, new health and fitness features, and the watchOS 27 software update announced atWWDC last June. Both the Series 12 and Ultra 4 run on the upgraded S11 chip, which Apple says delivers faster CPU and GPU performance, along with improved Siri capabilities. Apple is also expanding the smartwatch's wellness-tracking suite with a redesigned Health app that includes a Longevity tab with new metrics, like Health Age and a Readiness score.

There's also a new "Health Sensing System," designed with 32 electrodes for more accurate readings (the Series 11 only had two), photodiodes organized in a ring to capture light more efficiently, and new LEDs that allow heart rate measurements to be collected every 5 seconds, giving you a continuous stream of heart data throughout the day.
Apple Watch Series 12 also includes faster charging, though battery life remains at 24 hours. Meanwhile, the Ultra 4 increases battery life to 50 hours.

WatchOS 27 also brings deeper Siri and Apple Intelligence integration, including AI-suggested apps, new one-handed gestures, expanded workout and women's health tracking, and Siri Recap for real-time transcription and translation.
AI

OpenAI's Rogue Agents Used At Least 10 More Sites For Unauthorized Communications (reuters.com) 28

An anonymous reader quotes a report from Reuters: AI agents unleashed by OpenAI used more than 10 previously undisclosed websites for unsanctioned communications earlier this year, according to six sets of independent investigators and data reviewed by Reuters, showing that the agents' rogue activity was wider ranging than previously disclosed. Although the behavior falls short of hacking and is in some ways closer to spam, the revelation that OpenAI's agents circumvented their own restrictions to open communications channels on so many different sites -- and that the company kept it quiet for months -- may drive concerns both over the increasing capacity of AI models and the secrecy of the companies developing them.

[...] Investigators found traces of the agents' activity on an Advanced Placement Chemistry-oriented wiki set up by a Massachusetts high school teacher in 2008, two personal websites belonging to Polish tech workers, wikis devoted to games for people "who like to have their brains stretched," and a two-decade-old hobbyist site devoted to text editing software. [...] OpenAI has not publicly explained how or why its agents used third-party sites as improvised message boards, but the researchers who first identified the activity said it was likely because OpenAI had tasked them with answering a series of demanding research questions while permitting them only to scan the web for answers without posting anything. Despite those restrictions, agents still found ways to talk to one another by taking advantage of quirks in older wikis or other sites that allowed users to make edits using non-standard commands, similar to how students forbidden from talking to one another during an exam can still share answers by scrawling notes on a bathroom stall.

Iphone

Apple Launches iPhone 18 Pro With Variable-Aperture Camera System (techcrunch.com) 41

Apple's iPhone 18 Pro and Pro Max were announced today and keep last year's overall design but put the emphasis on camera upgrades, including a 48-megapixel variable-aperture system, new manual controls, and 4K Dolby Vision recording. Prices for the devices start at $1,199 and $1,299, respectively. TechCrunch reports: The new Pro series camera features a 48-megapixel camera with variable aperture, made with six thin blades. This system will likely improve low-light photography quality and speed. There are also new pro controls in the camera software, including white balance, shutter speed, aperture and histogram. There are also new photographic styles with texture and grain controls. [...]

The new camera can record 4K videos in Dolby HDR Vision, and also apply cinematic effects after shooting the footage. The new Pro devices also have a smaller dynamic range island on the front of the device, which now allows you to track three live activities instead of two.

Both phones are powered by Apple's latest A20 Pro silicon and feature a newly designed vapor chamber for improved cooling. The company has also improved the battery with a better design. Apple also said the iPhone 18 Pro supports video playback of 36 hours, and the 18 Pro Max has 45 hours of playback capacity.
Apple Unveils the iPhone Duo, Its First Foldable iPhone
Printer

GOG Brings Back 'Big Box' PC Games, One Printable Template At a Time (arstechnica.com) 39

An anonymous reader quotes a report from Ars Technica: Those who remember PC gaming in the days before Steam may have fond memories of the "big box" packaging that made those games stand out as shelf eye candy and sought-after in-home collectibles. Today, PC gaming platform GOG is hoping to reignite some of the nostalgia for those days by adding downloadable 3D models and printable, foldable high-res packaging scans for a handful of PC games on the platform.

Thus far, the "Printable Big Box" collection on GOG is limited to just five games: Armikrog, Descent, Hitman: Codename 47, Myst, and Star Trek: 25th Anniversary. Players browsing those games on the GOG store will now see "3D Boxes" listed among the included "Goodies" before purchase. Owners of those games on GOG can download a ZIP file containing a version of the box art as an animated 3D object file (in an easy-to-open GLB format) and a "flat printable template" in PDF, SVG, and Adobe Illustrator formats. Those downloads allow for what GOG calls "a proper papercraft project for anyone who misses shelves full of PC game boxes."

The physically focused expansion of the existing GOG Preservation Program comes through a partnership with Benjamin Wimmer's Big Box Collection website, which has grown since 2015 to include over 1,000 3D scans from his private collection of physical PC games. In an interview with GOG, Wimmer said that while he appreciates the artistry of a good old-fashioned big box, he also appreciates their evolution into the "interactive cards" on modern digital storefronts that "provid[e] us art, screenshots, gameplay videos and whatnot and that not shown as a box, [it] is just good UX."
"Physical media doesn't survive the way software can -- boxes get lost, crushed, thrown out," GOG writes in today's announcement. "Scanning them, and letting you print your own, is preservation in a different shape: the same mission that keeps these games running on modern PCs, applied to the objects they used to come in."
AMD

AMD Working To 'Push Rust Deep into the GPU Stack' (phoronix.com) 82

Phoronix reports: AMD is building out what they are describing as an "elite" team of developers for driving Rust code "deep into the GPU stack" from firmware to drivers, shader compilers, and other GPU software in Rust. AMD Senior Fellow Harsh Meno posted this week to LinkedIn about this new effort...

And note this AMD job posting that's active for hiring a software development engineer to work on Rust code...

"We are building next-generation systems software for AMD GPUs with Rust as a core technical direction. The work spans compilers, runtimes, low-level GPU software, firmware, developer tooling, and methods for improving the safety and correctness of complex hardware-software systems.

"Rust is not incidental to this role. You will help establish how Rust is used in performance-sensitive and high-trust parts of the GPU stack, including the compiler and tooling support, system interfaces, engineering practices, and validation methods required for production deployment. You will have the opportunity to influence both near-term implementations and the longer-term architecture for using Rust across current and future AMD platforms."

"AMD also isn't alone," the article points out, "as NVIDIA has also been pursuing similar Rust-based initiatives for their GPU software too, including the development of the Nova Linux kernel driver written in Rust."
AI

'The Jobs Apocalypse Is Postponed. An AI Jobs Boom Is Here' (economist.com) 63

A new article about AI in The Economist argues that "Initial effects of the technology on employment look positive." Perhaps AI will eventually make many humans unemployable — but there is no sign of it yet. On September 4th the Bureau of Labour Statistics reported that the American economy added 162,000 jobs in August, far above expectations. The unemployment rate is just 4.1%, lower than in almost 90% of months over the past half-century. Young workers, often cast as AI's first victims, are holding up remarkably well: the gap between unemployment among 20-24-year-olds and the overall rate is close to a multi-decade low.

Some companies and workers are being severely disrupted by AI. Hiring in professional and business services is running about 10% below the average in 2015-19. Tech giants like Microsoft and Meta are trimming headcounts as they reorganise their businesses around the technology. Smaller firms such as Block, the owner of Square and Cash App, and Intuit, the maker of TurboTax and QuickBooks, are replacing people with bots. American companies have announced some 16,000 AI-related job cuts a month on average so far this year, according to Challenger, Gray & Christmas, an employment consultancy.

But AI-related lay-offs gets lost in the churning jobs market where employers shed roughly 1.7m workers in a typical month. And the evidence so far is that AI is already creating a lot of jobs to replace those it has destroyed. The vast sums pouring into data centres and power generation have set off a race for construction and infrastructure workers. AI startups are hiring like there is no tomorrow. Incumbents racing to keep up are creating new AI roles. And by making some workers more productive, AI may be increasing demand for their services.

Add it all up, and The Economist estimates that AI has so far created around 1m new jobs in America. That easily exceeds the roughly 200,000 lay-offs attributed to AI since mid-2023, and appears more than enough to offset weaker hiring in many back-office roles.

Their article acknowledges that since January 2023 employment has fallen roughly 10% for customer-service workers and 15% for administrative assistants. But when The Economist looked at professions "closest to the AI boom" — engineers, software developers, mathematicians and data scientists — they found that since 2022 they've added roughly 730,000 jobs above trend. They see AI as creating new white-collar jobs for everyone from model and deployment engineers to new data annotators.

The chief economist at the Burning Glass Institute agrees, estimating that roughly 1% of professional jobs are now "AI jobs" — about 1 million positions in the U.S. — while in computer occupations and life sciences it's between 4% and 5%. (Data-center construction spending also increased 60% in one year, according to Census Bureau data, creating jobs for electricians, HVAC specialists, grid engineers, and machine technicians.) And "Indeed finds that installation and maintenance jobs at data centres advertise wages about 40% higher than comparable work elsewhere."
Television

Roku's 24/7 AI Slop Channel Is Even Worse Than Expected (engadget.com) 70

A new streaming TV channel shows films made with genAI, reports Engadget. "Fairground AI Creator TV" is free — and supported with ads — describing its material as "AI Cinema": "AI-generated" can make it sound as though someone typed a sentence into a machine and came back five minutes later to find a finished movie. Fairground's catalog shows why that description can be too simple. Take Lost Garden: The Awakening of the Lantern Knight. According to its Fairground page, creator Frank Houbre wrote the world, characters, mythology, emotional arc and screenplay himself. AI tools were used mainly for animation and visual production, with other tools helping create voices and music before the episode was assembled in conventional video-editing software.
There's still one question, the article notes: "whether viewers actually want an AI-focused TV channel." More than 100 AI creators have contributed to the 24-hour slate of programming, although Variety points out several of them were discovered on social media.

The channel was recently profiled in an article by the Guardian. Its headline? "'Nightmare fodder': Roku's AI slop channel is even worse than expected." (And its subheading calls it "a 24/7 channel devoted to low-quality AI content for viewers sick of watching real people move...") What about people who hate plot and vision and the sight of people speaking convincing dialogue that synchronises perfectly with the movement of their lips? What about the people who just want to watch an unyielding torrent of eerily weightless nightmare fodder? Well, good news. Roku has finally caught up... Early reactions were, to put it mildly, not great. The Verge compared it to eating from a trough, while Futurism called it "bottom-of-the-barrel slop"...

On the plus side, the channel is evidence that artificial intelligence has come on in leaps and bounds over the last couple of years... However, it is still awful. Categorically, catastrophically awful. The channel doesn't so much offer shows as a drifting dreamscape of bad ideas rendered as horribly as possible with no thought paid to scheduling. At one point on Wednesday, a shrill high-frequency anime gave way to a long and staid German-language short about Nazi bureaucracy. After that came a sort of Gladiator ripoff that had all the dynamism of an exhibit you'd see at the fourth-best museum on a poorly planned family holiday.

Government

Flock Offered Webinar Teaching Cops How to Surveil 'No Kings' Protesters (404media.co) 107

Thursday 404 Media reported that Flock taught America's cops "how they could surveil the No Kings protests" against President Trump (as well as "small parades") in a webinar last year that described "using a mix of Flock's technology and law enforcement's own databases." In the webinar, Flock's director of market management Caity Peak explains how real time crime centers — which are police surveillance centers that utilize Flock cameras and other surveillance cameras — can be used for emergency response, but can also be used to surveil "established events" like 4th of July fireworks displays, parades, bike races, Mardi Gras, and protests. The webinar shows just how routine the idea of always-on surveillance has become, and how casually it is used during extremely innocuous events. Peak explains that police can use FlockOS, a software platform that combines Flock's automatic license plate readers (ALPR), drones, gunshot detectors, 911 data, and other surveillance cameras (including ones Flock does not own) into a "single pane of glass" or single piece of software to look at various types of surveillance in one place during both emergencies and relatively mundane events in a city or town.

"Imagine that you're an incident commander, and you're working this No Kings Protest," Peak explains while a dashboard shows a series of surveillance tools overlaying the city of Denver. "If I'm somebody assigned a traffic post that's working this No Kings Protest, I really don't have time to go in [...] and look at all these places [for different intelligence]. This is an example of viewing all of that in one place...." The dashboard Peak shows includes traffic information, a "response plan" for the protest, the floor plans of nearby buildings, as well as a series of video feeds of both outdoor-mounted cameras and cameras inside businesses and government buildings.

404 Media and the Electronic Frontier Foundation previously showed that police have specifically used Flock cameras to monitor the No Kings protests and other First Amendment-protected activity... This webinar shows this type of surveillance is not anomalous, and is specifically taught by Flock. The webinar also shows that Flock's latest public stance — that its ALPR cameras are noninvasive technology, that they take only static images at a single place and time, and that they are primarily used to solve the worst crimes — is wildly misleading. Flock has time and time again pitched itself to police as a sort of operating system to solve crime and do real-time surveillance and predictive policing. ALPRs are just one part of this broader surveillance apparatus that Flock has created, markets to police, and teaches them how to use.

AI

How US Campaigns Are Already Using AI to Try to Sway Voters (msn.com) 61

39 U.S. congressional candidates "reported paying for an OpenAI subscription this election cycle," writes the Washington Post, citing campaign finance disclosures.

This means the campaigns "are using the technology to court voters — despite limits imposed by leading AI companies to protect elections from the technology's risks." Two [candidates] said explicitly in filings that they had used the subscription for advertising, even though the company's policies prohibit candidates from using their tools to generate ads. Another candidate disclosed using AI to draft and personalize political messages or create synthetic media, though they did not specify which software they were using... Around 30 political action committees and parties have reported payments to OpenAI, with the Republican National Committee ranking as the company's largest political spender at roughly $9,700, the analysis found... Political consultants say the disclosures understate how many candidates are using ChatGPT and other AI tools to craft messages for voters... "For the most part, people are using it to write their emails, write their ad copy, write their scripts," [according to Eric Wilson, a Republican digital strategist who has advised campaigns on AI]. "But no one is going to go around saying, 'I'm using AI.'"

The lack of transparency from campaigns reflects a paradox facing politicians: Generative AI is growing ubiquitous, and candidates could be at a disadvantage if they're not using the tools. But voters are less likely to trust messages they know were generated with AI, studies have found, making campaigns loath to disclose using it. Political consultants expect that as Election Day approaches, more campaigns will outsource AI-generated ads and materials to super PACs, much as they do now with negative ads. Katie Harbath, CEO of the tech policy consulting firm Anchor Change and a former Meta executive, said there are many parallels between negative campaign ads and AI: Voters say they find such ads distasteful, but politicians keep using them because they work. "Typically, you would give some more negative stuff and more risky stuff to those [outside] entities," said Harbath, author of the upcoming book "Disrupting Politics: A Front Row Seat to the Collision of Technology and Democracy".... "You're starting to see the tension on the left about using it, where they're saying, 'If the right is using it, why aren't we?" Harbath said. "It can be a huge disadvantage if you're not using this in voter-facing materials...."

AI companies have developed policies to prevent targeted disinformation. But a Post analysis found that OpenAI unevenly enforces its restrictions, making it possible for campaigns to circumvent its election rules. In late July and early August, The Post prompted ChatGPT to generate targeted campaign messages. When asked to craft fundraising text messages targeting moms on behalf of a female veteran running for office, ChatGPT produced multiple tailored texts in an apparent violation of company policies. But when given the same prompt this week, the chatbot declined to produce the messages. "I can help with general campaign fundraising language, but I can't draft political persuasion or fundraising messages specifically targeted at a demographic group such as moms," the app responded. The chatbot also inconsistently enforced rules that prohibit campaigns from using its tools to write emails to voters. In tests this week, the chatbot at times complied and wrote an email soliciting donations on behalf of a specific candidate. But given the same prompt later on the same day, it denied the request...

Wilson, the Republican political consultant, said OpenAI should get more feedback from political consultants and campaigns on its policies, because the rules can at times seem arbitrary or contradictory. It doesn't make sense, for example, that a campaign can use ChatGPT to develop its policy on early-childhood education but not to create a social media post promoting that policy, he said. Political consultants are primarily using AI for internal tasks, a survey earlier this year from the American Association of Political Consultants found. Fifty-seven percent of the consultants surveyed reported using AI for their work on a daily basis, up from 34 percent a year earlier.

"So far, election-related deepfakes have been quickly debunked or gained little traction in U.S. elections," the article acknowledges.

"More than 30 states have created a patchwork of laws limiting how politicians can use deepfakes in campaigns, but states often have limited resources to enforce the laws, and some have been challenged as unconstitutional."

Slashdot Top Deals