Normal view
-
SecurityWeek
- Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up
Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up
Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet.
The post Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up appeared first on SecurityWeek.
Your CD collection is probably already degrading, and here's why
CDs have been around for a long time, with people still having ones from decades ago. Even today, CDs β which stand for compact discs β are sold to people who like owning physical music and want the additional content included with the physical copy rather than what is on streaming services.

Whip-Cracking Machine Reliably Breaks the Sound Barrier
We tend to think of breaking the sound barrier as a comparatively modern accomplishment, but on a smaller scale, cattle herders have been breaking it for centuries: the cracking sound of the tip of a bullwhip snapping comes from a small-scale sonic boom. Reliably getting a crack out of a whip takes skill and practice, though, which is why [Craig Turner] built a whip-cracking machine.
The first step was to build the whip itself, which was surprisingly complicated. Bullwhips taper down toward the end of the whip. As the whip uncurls during a crack, momentum passes down the whip; since the whip becomes continually narrower and lighter, conservation of momentum means that different stretches of the whip must move progressively faster. To get this effect, [Craig] joined together a series of increasingly thin and light ropes. The heavy end of the whip terminated in an eyelet connected to a length of elastic shock cord. Stretching the whip back on the shock cord and releasing it whipped it around, resulting in a fairly reliable crack.
For greater convenience, [Craig] built this into a launcher mechanism, with the elastic cord wrapped around the end of the launcher, an electrical-conduit guide for the whip, and a spring-loaded trigger mechanism to release it. This worked even better than expected, getting a reliable crack every time. The tip of the whip could slice leaves, tear open aluminium cans, put out candle flames, knock the cap off a bottle without tipping it over, and reliably hit small targets on the first shot.
As [Craig] mentioned, this setup would make it much easier to study the cracking effect with a schlieren imaging setup.
Automattic confirms Mullenweg has returned as CEO after attempted ouster by board
Big Infinity Mirror Clock Invites You To Gaze Deeply
[Andy Huot] has a fantastic-looking infinity mirror digital clock that really raises the bar. It uses high quality components, smart use of RGB LED animations, and a clever βstacked diffuserβ vertical design to the 7-segment display elements that really enhances the infinity mirror effect. It needs to be seen in action, so check it out.
The end result is expressly portal-like, with the smooth animations of the LEDs really playing into the effect. The size helps, too. Itβs 24 inches in diameter, giving it considerable presence.

A basic infinity mirror design consists of lit elements sandwiched between a reflective back surface and a partially-reflective, partially-transmissive top cover. That same basic principle is used here, but with great care given to ensure nothing so much as a fingerprint spoils the illusion. For example, the top cover is a disk of acrylic with a 90% reflective film affixed to the inside surface. Thatβs easy enough to DIY with some car tint, but [Andy] found that for the very best results it was worth having high-quality film professionally applied.
We like the use of 3D-printed custom jigs for soldering the segments of RGB LED strips, and holding the pre-measured wires in place with some putty is a great way to keep them in place while working. In case youβre wondering, the mirrored acrylic making up the back wall has holes in it for mounting each segmentβs LED strip in a holder, and running the wires to the rear.
The video (embedded below) documents every step of the assembly, and itβs a serious build. While the design files for the 3D-printed parts are not free, thereβs certainly enough detail for an enterprising hacker to replicate the design in their own way.
Anthropic CEO outlines plan to slow AI development
Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says
Anthropic said the users did not succeed in βfielding an operational deviceβ but did carry out a failed test of a guided rocket.
The post Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says appeared first on SecurityWeek.
-
All News β Federal News Network
- The time is now: Incentivize AI companies to share critical security information
The time is now: Incentivize AI companies to share critical security information

Β© Getty Images/iStockphoto/KanawatTH
Trump on AI Extinction: Beating China Is the Bigger Concern
Trump dismisses AI extinction warnings and says beating China is the priority as researchers and lawmakers call for stronger safeguards on advanced systems.
The post Trump on AI Extinction: Beating China Is the Bigger Concern appeared first on TechRepublic.
AI Agents, Foldables, Cyberthreats, and Chip Deals Define This Week in Tech
See what you missed in Daily Tech Insider from Sept. 7β11.
The post AI Agents, Foldables, Cyberthreats, and Chip Deals Define This Week in Tech appeared first on TechRepublic.
Trump on AI Extinction: Beating China Is the Bigger Concern
Trump dismisses AI extinction warnings and says beating China is the priority as researchers and lawmakers call for stronger safeguards on advanced systems.
The post Trump on AI Extinction: Beating China Is the Bigger Concern appeared first on TechRepublic.
AI Agents, Foldables, Cyberthreats, and Chip Deals Define This Week in Tech
See what you missed in Daily Tech Insider from Sept. 7β11.
The post AI Agents, Foldables, Cyberthreats, and Chip Deals Define This Week in Tech appeared first on TechRepublic.
Anthropic Says Claude Used in Possible Bioweapon Research
Anthropic says researchers used Claude for biological work that could support weapons development, exposing new challenges for AI safeguards.
The post Anthropic Says Claude Used in Possible Bioweapon Research appeared first on TechRepublic.
Anthropic Says Claude Used in Possible Bioweapon Research
Anthropic says researchers used Claude for biological work that could support weapons development, exposing new challenges for AI safeguards.
The post Anthropic Says Claude Used in Possible Bioweapon Research appeared first on TechRepublic.
EU Gets Access to Anthropic Cyber AI β But Not Its Newest Model
ENISA has gained access to Anthropicβs Mythos 5, giving EU officials a chance to independently test the cyber AI after months of negotiations.
The post EU Gets Access to Anthropic Cyber AI β But Not Its Newest Model appeared first on TechRepublic.
EU Gets Access to Anthropic Cyber AI β But Not Its Newest Model
ENISA has gained access to Anthropicβs Mythos 5, giving EU officials a chance to independently test the cyber AI after months of negotiations.
The post EU Gets Access to Anthropic Cyber AI β But Not Its Newest Model appeared first on TechRepublic.
-
Hackaday
- This Week in Security: Itβs Patch Tuesday Again, TVs Spying, Supply Chain Worms Return, Prolonged Hack Impacts, Stolen IDs
This Week in Security: Itβs Patch Tuesday Again, TVs Spying, Supply Chain Worms Return, Prolonged Hack Impacts, Stolen IDs
Several times this summer, Microsoftβs Patch Tuesday, the monthly roundup of major security patches for Microsoft products, has included record-breaking numbers of security fixes. The August 2026 patch set actually seemed to catch up. Was this a sign of the bug apocalypse lessening? Ha, nope!
Brian Krebs at Krebs On Security once again brings his excellent roundup of Patch Tuesday events, with this months patch set absolutely crushing previous numbers with nearly 1,000 security fixes.
Two of the fixes are for zero-day vulnerabilities under active exploitation in the wild, both allowing privilege escalation on Windows. Privilege escalation bugs turn general vulnerabilities in applications and games into full administrator access to gain persistence and deploy ransomware, and generally make any vulnerability significantly worse.
Krebs also calls out a CVSS 9.8 (so close to a perfect 10!) vulnerability that allows remote code execution in the Windows shell with no user interaction and no authentication, a remotely exploitable DNS bug present since Windows Server 2012 and Windows 10 which will likely see exploitation in the wild soon, and over a hundred other bugs are ranked βCriticalβ.
How the sheer volume of vulnerabilities in this patch will fit with recent Microsoft recommendations that companies should apply the patches immediately remains to be seen. (Likely: not very well, depending on what new behavior and issues the fixes cause!)
Is Your LG TV Spying on You?
Gamers Nexus continues their trend of high-quality investigation, and they have posted another tremendous multi-hour investigatory video. This time Gamers Nexus focuses on the ecosystem of LG televisions and monitors.
It shouldnβt likely surprise many here that βsmartβ devices are usually more to the benefit of advertisers than consumers. Similarly, it shouldnβt be a surprise that a βsmartβ device harvests user data to sell to advertises. What may be surprising is the degree to which LG devices appear to collect data, how much data is sent even when collection is turned off, and how overt executives at the company are, with multiple executives making statements in pitches to advertisers that LG βowns the glassβ, βowns the living roomβ, and is designed to correlate devices, inhabitants of the environment, and viewing habits so that ads can be served to the TV and mobile devices in the same room simultaneously.
With tracking enabled, the smart TV captures telemetry of what applications are used, as well as continually capturing the video displayed and reporting fingerprints to LG servers and ad partners. The screen content is tracked not only for TV, but for the HDMI inputs, including if the TV is used as a PC monitor. If voice control is enabled, the TV also records audio and analyzes it. The TV also continually scans the local network and nearby Wi-Fi networks, reporting all the devices it finds on the local network, including host name, MAC address, and sometimes software running depending on the MDNS advertisements. Near-by Wi-Fi networks are sufficient for very precise geolocation, so LG effectively knows the location of every customer, as well.
Gamers Nexus makes the point that while the invasive ad tech is gross, itβs mostly limited if the user does not agree to the end-user license agreement β but the infrastructure required to enable it is riddled with security flaws, both discovered and likely additional undiscovered issues. A smart TV is basically a computer, usually running either some flavor of Android or Linux, with the attendant flexibility, power, and problems. A vulnerability in the TV operating system or its apps can provide a route into your internal network. (Not that this required an exploit: LG was called out earlier this summer because 42% of apps on the official app store contained residential proxy systems to sell your home Internet connection.) But it can also access any of the attached hardware, like the microphone.
Gamers Nexus demonstrates that a LG TV can be exploited to gain local root, and from there, it can record audio from attached devices β even when the primary microphone is muted. Gamers Nexus also discovered that muting the microphone on some models does not disconnect or disable the microphone, it simply sets the gain levels extremely low; recording is still possible, and with amplification, audio is still recoverable.
Spy tech and ad tech goes hand in hand; it will be interesting to see if LG responds by at least hardening the security on the devices, or if another company finds traction in selling modern televisions and monitors without the βsmartβ advertising.
Shai-Halud NPM Worm Returns
Aikido.dev reports that after 111 days, the Shai-Halud worm returned to the NPM repository.
Shai-Halud was one of several worms hitting package repositories in the Spring of 2026, installing backdoors, stealing cryptocurrency wallets, and taking every login credential and authentication token it could find before infecting every package the tokens linked to. Since then, infections have remained quiet, and repositories like NPM have stated that they now scan every package as it is uploaded.
Charlie Erkisen at Aikido.dev observed that on September 7, 2026, four additional packages uploaded to NPM were infected with Shai-Halud; not a variant of the worm, but the original code, matching the known public signatures. Whatever scanning is in place in the NPM repository didnβt filter them, and if an exact match for a known, major worm isnβt caught by the infrastructure, itβs unclear how a new threat would be.
Boston Scientific Hack Continues
The apparent ransomware attack against Boston Scientific continues to have impacts, with Boston Scientific filing a report with the SEC that the attack is expected to have an impact on the company earnings.
Boston Scientific makes medical devices, like pacemakers, stents, and monitoring equipment. It has not yet been publicly disclosed what happened, or if customer data was compromised, but the SEC filing confirms that unauthorized access on βcertain systemsβ causing an outage. After several weeks of outages, the company reports that it is able to ship almost at capacity, and that the sterilization facilities for medical devices are online. While there is no estimate provided for full recovery, efforts are ongoing.
Commerce Sites Vulnerable
Adobe released a security bulletin that the Adobe Commerce and Magento platforms are under active exploitation from CVE-2026-75650, a flaw in the template engine.
These platforms power tens of thousands of commerce sites, and vulnerabilities in them are usually used to steal payment data or serve malware to customers during the checkout process. Previously this year, Magento patched another vulnerability which allowed uploading executable files to any store, and indications are that the current vulnerability has been exploited in the wild since early September 2026.
The current vulnerability allows implantation of PHP code by injecting custom styles into a query, which is then executed when Magento generates a failure email and renders the template. The attackers then download and install a control binary written in Rust which masquerades as a kernel thread task, which then monitors the store and collects payment data.
The vulnerability was publicly known and used for several days before Adobe made official statements of a fix being available, leaving any store running on Magento vulnerable with no official fixes, but as of writing this, Adobe has published patches and an advisory.
Microsoft to Block Unpatched Servers
Microsoft plans to block emails to to the cloud-hosted Exchange Online from unpatched on-premises Exchange servers.
Apparently the urge to self-host Microsoft Exchange is coupled with antipathy about actually patching it, to such a significant level that Microsoft is taking the steps to detect incoming mail from servers that have not patched since October 2025. While Microsoft updates rarely apply with zero problems, nearly a year is more than enough time to have tested and deployed a security fix.
βThis update released nearly a year ago, and all organizations should have updated to itβ: so say we all.
Hackers Pose as Recruiters
Government-backed groups in Iran have been posing as recruiters trying to infect targets with malware.
The group, designated βNimbus Manticoreβ, is known to develop custom malware and remote access tools (RATs), and typically target specific individuals via spear-phishing attacks. The latest malware from the group is cross-platform and can infect Windows, macOS, and Linux, installing services to run websocket-based remote access tunnels, SSH tunnels, and a command-and-control client that allows live control of the infected device.
The group contacts targets posing as recruiters, but first the target must solve a coding challenge contained in a zip file. The zip contains a trojaned Node.js project which infects the victim system when compiled, deploying the remote access tools and setting up persistence to relaunch them if disabled. Multiple variants have already been spotted, generally targeting different countries, predominately Egypt, Afghanistan, and Ethiopia.
The latest version of the malware package also looks for settings and data from major security vendors like Symantec, CrowdStrike, and SentinelOne, as well as the contents of directories related to Google and Microsoft services.
The fake recruiting method has also been used by other groups in Iran and North Korea. Remember: any project with a build script can execute any commands as part of the build, and most IDE project files also allow embedding custom plugins and commands into the project. Triggering a compile on a project is the same as running arbitrary commands!
150 Million US Drivers Licenses Stolen
As many outlets are now reporting, a major ID validation company was compromised, leading to the theft of scans and data of 150 million US drivers licenses.
IDScan provides drivers license and identification card scanning services used by car rental companies, bars and dispensaries, hotels, concert venues, and a multitude of other businesses. If youβve ever had to hand your ID over for validation, thereβs a high chance youβve interacted with IDScan or a similar company.
Evidence points to IDScan being compromised for at least a year, with full scans of licenses continually exfiltrated. The scans include everything visible on a typical license or ID card, including name, license identification number, ID photo, and home address, but also the date that it was scanned in. The collection even includes additional scans of the ID in ultraviolet and infrared to catch any watermarks. With 150 million entries, the data set contains everyone from the security researcher Brian Krebs who broke the story, to government officials like Pete Hegseth.
The data has been available for sale, individually or in bulk, although with the recent press coverage the site claiming to sell the data has gone offline for now. Before disappearing, the site claimed that all data was exfiltrated into their own databases, which means itβs still available somewhere, and shutting them out of the IDScan service wonβt protect data already stolen.
Many aspects of this echo the scanned ID data stolen from validation services used by Discord and other online services: almost like scanning unchangeable government IDs is a bad plan?
American Meteor Society Knocked Offline
Itβs all fun and games until they come for the geek hobbies. The American Meteor Society Fireball tracking program is was knocked offline, seemingly from a ransomware attack. Fortunately it looks like as of writing this, the admins were able to restore a backup and the site is online again.
-
TechCrunch
- Matt Mullenweg tells (trolls?) Automattic staff, saying heβs back in control after CEO ouster
Matt Mullenweg tells (trolls?) Automattic staff, saying heβs back in control after CEO ouster
Claude users found ways around safeguards for bioweapons research
Anthropic said it stopped multiple attempts by scientists this year to use its technology for research that could help develop biological weapons, as experts increasingly fear the threat that AI poses to public safety.
The startup gave five examples of times actors βcircumvented controlsβ and made other efforts to βobfuscateβ the purpose of their research to dodge safeguards. The cases involved some users in nations that it prohibits from accessing its models, which include Russia, China, and Iran.
βWe hope that by sharing these examples, we spark a conversation within the AI industry and with governments about emerging biological risks and how best to counter them,β Anthropic said in a report about efforts to use its models for malicious activity.


Β© Getty Images | picture alliance