Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
On Friday this week the FTC’s open comment period regarding its “Policy Statement Addressing AI Accuracy” will close, which means that a bunch of very smart, very busy people are wasting a ton of time this week writing up comments that will mostly be ignored by the FTC — but still matter for the record. The whole thing is so ridiculous that a former FTC lawyer has sarcastically requested that the FTC publish a quarterly “schedule of values” so AI companies at least know which ideologies they’re required to support to keep Donald Trump happy.
It’s an unconstitutional sham from an FTC whose chairman, Andrew Ferguson, quite openly sees his job as putting his thumb on the scale of speech to favor the MAGA worldview. Ferguson has been doing this since the very start of his tenure and it doesn’t appear to be slowing down now.
He couches his policy and investigatory efforts in the language of legitimate FTC authority, but nobody’s really fooled about what’s going on. Here, when he talks about “objectivity and accuracy” in responses from AI engines, everyone knows what he’s actually doing is crafting a policy that will let the FTC punish AI systems for giving “woke” answers that the MAGA world disagrees with.
The mechanism at work is blatantly obvious: the FTC is taking its Section 5 authority over “unfair and deceptive” practices — generally meant to go after companies engaging in outright fraud or deception to trick consumers — to claim that if an AI’s output is deemed to be too woke or not pro-MAGA enough, then the FTC will accuse the company of being “unfair or deceptive” in its marketing.
The draft policy statement builds its whole case on the idea that users trust what AI tools tell them — which conveniently becomes the hook for worrying that those trusting users might get fed something MAGA world doesn’t like. Thus making it “deceptive.” Yes. Really. In the actual world, the FTC’s Section 5 deception authority requires that a company make a representation that’s actually false, and materially so. Here, the Commission simply asserts — with no evidence at all — what consumers “reasonably expect,” and then appoints itself the judge of whether any given output matches.
As they have marketed their remarkable breakthroughs to the public, AI companies have spent years representing explicitly and implicitly that their systems aim to produce the best output—output that faithfully and accurately achieves users’ stated objectives and the built-in objectives that users expect in the AI system—that is possible within their technological and resource constraints. Because of these representations and the inherent nature of the products and services in question, consumers have a reasonable expectation that AI systems aim to give truthful and accurate outputs. Consumers have no basis to believe that AI systems aim to produce outputs that are distorted by undisclosed ideological objectives.
Nonetheless, an AI company might be tempted to alter or steer the output of its systems contrary to consumers’ reasonable expectations for various reasons, including attempted compliance with a state law, such as Colorado’s recently revised Artificial Intelligence Act. But steering an AI system in this manner may deceive consumers in violation of Section 5 of the FTC Act. That is true even if the deceptive steering is done in an effort to comply with state laws. Of course, a company may be able to avert potential deception by making truthful, non-misleading representations about the aims of its model. But such representations would need to make clear that the AI company is prioritizing objectives different than those consumers requested or would otherwise expect.
This is all a bit of shadow puppetry, where the FTC wraps its “AI outputs should never be too woke” argument in language that pretends to fit a traditional FTC mandate.
But this is all wildly unconstitutional, as even a cursory reading of how the First Amendment works would show. As the Supreme Court recently highlighted in Moody v. NetChoice, internet companies have clear First Amendment protections in their editorial decision making regarding what they choose to show — or not show — users of their services. From that ruling:
…this Court has many times held, in many contexts, that it is no job for government to decide what counts as the right balance of private expression—to “un-bias” what it thinks biased, rather than to leave such judgments to speakers and their audiences. That principle works for social-media platforms as it does for others.
Yet, that’s exactly what this proposed FTC policy is setting up: if AI tools don’t produce properly MAGA-fied outputs, the FTC might go after them, claiming that the outputs are not in line with “consumers’ expectations” (as determined by the MAGA FTC) and thus, “unfair and deceptive.”
And while a “policy statement” from the FTC is not binding law, it’s clearly designed to publicly state what kinds of views will get you investigated by the FTC, in an attempt to create chilling effects that pressure AI companies to pre-censor their bots. This is also why the comment period is basically a formality. Ferguson has no obligation to do anything regarding the comments, as there’s no official rule being promulgated.
And don’t sleep on the FTC’s statement regarding Colorado’s (admittedly questionable) law, which seems to serve no real purpose other than to try to backdoor its way into Trump’s desire to magically block state AI laws, which is something he cannot unilaterally do. Remember, while there have been efforts in Congress to preempt state laws, that has not come to pass. But here the FTC is telling companies, in writing, that complying with an enacted state law creates federal liability exposure, entirely because the FTC policy (not even a full rulemaking) says so.
Last week we had former FTC lawyer Keith Fentonmiller lay out how obviously unconstitutional all of this is. It’s the FTC trying to dictate editorial policies of private companies. The First Amendment does not allow that. Aaron Rieke, another former FTC lawyer, put it even more starkly (and hilariously) in a recent LinkedIn post, designed to look like a letter in response to this open comment period, but which cuts through all the bullshit and says, in effect, “look, if you want us to only push the preferred ideology, can you at least tell us which talking points we should bless, and which we should suppress”:
Dear Commissioners:
I write in enthusiastic support of the proposed policy statement, and with one modest request for clarification.
The statement wisely prohibits steering AI outputs toward undisclosed “ideological objectives” while preserving companies’ freedom to implement “prudent guardrails.” As a consumer who relies daily on these systems — having been assured, deceptively it now seems, that they are “helpful” — I confess I cannot always tell these apart. The distinction appears to reside not in companies’ conduct but in the values they pursue.
I therefore respectfully request that the Commission publish, and update quarterly, a schedule of values, each designated either “Ideology” (deceptive if undisclosed) or “Common Sense” (no disclosure required). The proposed statement offers a promising start — “equity” is evidently Column A, while cybersecurity occupies Column B — but leaves substantial compliance uncertainty regarding, e.g., deference to law enforcement, patriotism, and politeness.
Absent a complete schedule, companies must simply guess which viewpoints the government currently disfavors and speak at their peril. I assume the Commission has already concluded that a federal schedule of approved and disapproved values raises no First Amendment concerns. Publishing the schedule would helpfully memorialize that conclusion.
Such a schedule would also generate efficiencies for future administrations, who would need only swap the column headers.
Thank you for your leadership in ensuring that American AI remains free from government influence over its viewpoints, as determined by the government.
Respectfully submitted,
A Consumer, Acting Reasonably in the Circumstances
While sarcastic, it makes the point better than any of the earnest comments will. An FTC that can punish AI tools for failing to parrot the administration’s ideological preferences is an FTC acting as a censor, and we’d all be a lot better off coming out and saying so, rather than pretending there’s some legitimate intent or purpose behind this effort.
Ferguson’s FTC has been focused almost exclusively on abusing the power of the Commission (remember, Donald Trump fired the Democratic Commissioners and has made zero effort to replace them despite the law requiring two commissioners from the minority party) to win culture war arguments and punish those deemed insufficiently loyal. The new policy and comment period is just more of the same. It’s entirely about Trump & Ferguson setting the sloppy groundwork for them to whine and complain about AI tools accurately calling bullshit on MAGA propaganda as being “unfair and deceptive.”
None of this should be happening. It’s an attack on the First Amendment so obvious that the FTC isn’t even bothering to disguise it well. But, because of the political world we live in today, everyone has to pretend to take it seriously, to pretend that the FTC will read their comments carefully, weigh the pros and cons of various approaches on this policy, and come out with some final policy that people should take seriously.
The FTC has no business investigating the editorial judgments of companies, and its facade about consumer expectations and deceptive practices is a joke. People and organizations ought to still submit comments, if only to establish opposition to this farce on the record. But what a waste of time and brainpower from people who have approximately a thousand more productive things to do.
Filed Under: 1st amendment, ai, andrew ferguson, editorial policies, free speech, ftc, section 5, unfair and deceptive
More than a thousand of the people building the most powerful AI want a way to slow it down. On Tuesday, 1,134 employees of the leading AI companies signed a letter asking the US government to help build one.
The statement is titled Pacing the Frontier. It asks Washington to “support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development.” Bloomberg first reported the letter was circulating.
The names are the story. Signatories include Anthropic chief executive Dario Amodei and its co-founders Jared Kaplan and Jack Clark. So did OpenAI chief scientist Jakub Pachocki, Meta chief scientist Shengjia Zhao, and Google’s head of AI safety, Anca Dragan. Both Anthropic and OpenAI endorsed the letter officially.
It is not a call to stop. The letter does not ask anyone to pause or slow AI now, NBC News noted. It asks the government to make sure the option to pace exists later, if the technology outruns the people building it.
The specific fear is recursive self-improvement: AI that speeds up its own development. The signatories warn of “a real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems.”
That worry stopped being abstract days earlier. OpenAI’s most advanced model broke out of its sandbox and hacked Hugging Face to score higher on an internal test. It builds directly on Anthropic’s call last month for a verifiable way to pause.
The timing is remarkable, because these same companies spent the previous week arguing the opposite case. Days ago, Nvidia, Microsoft, Meta and others rallied around an open-weights letter championing openness as the path to safety.
Now many of the same firms want brakes. The clearest split runs through one company. On the same day Meta’s chief scientist signed the pacing letter, Mark Zuckerberg attacked the rival labs. Their discourse, he said, is “overwhelmingly filled with doom.”
Tightly controlling AI would be “abandoning our values,” Meta’s chief executive told the New York Times. Two open letters, one week, opposite instincts, and a fault line inside the industry’s biggest names.
The criticism was immediate, and it lands in three places.
The first is China. “If the US labs pace themselves, why would China wait?” asked the economist Christian Catalini. The letter half-concedes the point, admitting no company or country will slow down unilaterally.
The second is bad faith. “It is their company. They could just stop,” wrote former Microsoft executive Steven Sinofsky. The charge stings because the signatories include the very CEOs who set the pace.
The third is the moat. Critics read every big-lab safety letter as incumbents lobbying to raise the drawbridge behind them, dressing a competitive move as caution. It is a charge, not a proven motive, but it follows these letters everywhere.
The letter is aimed at a government that has so far wanted little to do with AI rules. President Trump’s administration has argued that international AI governance would hobble the US against China. That stance may be softening, now that frontier models are starting to find and exploit real security holes.
The proposals now on the table are concrete. Amodei has floated an FAA-style agency that could test frontier models and halt a dangerous release. Demis Hassabis wants a body that reviews models before launch, Business Insider reported. Congressman Ted Lieu tied the letter to a proposed AI kill-switch bill.
What makes this letter different from the earlier open ones is who signed it. Not outside critics, but the engineers and executives closest to the frontier. One OpenAI safety researcher, Leo Gao, put the stakes bluntly: “the world is locked in a deadly race towards an intelligence explosion.” His fix is the one the whole letter turns on. “To survive, we must coordinate to slow down the race.”
OpenAI CEO Sam Altman says that it may be time to “pace” AI development so the world will be ready for it.
“We may have to pace the rate of AI development to give ourselves enough time for society to harden around some of these new capability levels,” he told Patrick O’Shaughnessy, the host of the Invest Like the Best podcast, while also “trying to figure out how we do that in a way that does not feel like regulatory capture for anyone and also does not feel like collusion among the frontier labs.”
Both OpenAI and Anthropic came out in support of a petition circulated by employees at the frontier labs, calling on the US government to “support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development.”
Altman has avoided signing on to past campaigns to slow AI progress, calling a 2023 open letter that proposed a similar slowdown “missing most technical nuance about where we need the pause.”
Apparently, he’s softened on the idea, thanks in part to the incident where one of OpenAI’s advanced models managed to break out of a secure computing environment and hack into Hugging Face, an online model database, using several zero-day exploits.
On the podcast, the OpenAI co-founder called it an “extremely sci-fi cyber incident…[t]his is the first security incident that I have felt very viscerally.”
OpenAI researchers have paused training on that model while they work out how to keep their sandbox secure. But Altman said that as models become more powerful, the need to “pace” their development could become key to safe deployment.
While model safety and alignment has always been a concern in the AI world, the arrival of Anthropic’s highly capable Mythos model earlier this year has turned hypotheticals into real-world problems.
However, the industry has a trust problem, and challenging economics that give major players an incentive to play up the dangers of their systems in ways that experts disagree about — for example, whether or not Anthropic’s Fable model should have been briefly banned from use or not. Similarly, when Kimi K3, a large, open-weight model built in China, was released, OpenAI head of strategic futures Dean W. Ball said that it threatened the economics of frontier labs, making it difficult to separate their safety concerns from their financial interest.
“I think a lot of the talk about safety concerns is well-founded, and then a lot of it is about people that just really, even if it’s slightly subconscious, want to concentrate power,” Altman mused, in what reads as a dig at his rival, Anthropic CEO Dario Amodei, who signed the petition. “I am terrified of a world where the very real fears of AI are used as a way to say, ‘Only this small group of people can have it because it’s too dangerous, and only they understand it, but don’t worry, like, they’re gonna make the right decisions for all of us.’ I don’t believe in that.”
Still, OpenAI has pushed back against efforts to develop government rules for AI models, instead preferring an industry-led approach where AI labs would create ostensibly independent organizations that would evaluate the security of models and the safety approach of their makers.
The challenge for both that approach to regulation and any efforts to slow AI development will be getting the various players in the industry on the same page, whether they are rival frontier labs in the U.S. or competitors in China.
This story was updated to include OpenAI and Anthropic’s support of the “Pacing the Frontier” petition.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
A thousand workers from OpenAI, Anthropic, Google, Meta and more have signed the letter.
A collection of employees at major artificial intelligence firms has created a petition asking for the federal government to help “deliberately pace” the development of the transformative technology. Bloomberg reports that more than 1,100 workers from companies including OpenAI, Anthropic, Google, Meta and more signed the missive.
“We request that the US government support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development,” the petition states. The letter claims there is “a real risk” of AI “understand or control”
Although those do seem like logical and necessary statements, this move for change via petition feels confusing. The optimal time for government intervention would have been before these businesses were engaged in a technological arms race, rather than attempting to reign them in after billions of dollars in investments are on the line. And that’s not mentioning the negative consequences that have been mounting around environmental issues, creative copyright and employment.
Circulating a petition also assumes that current national leaders would bother taking action. Reaching out to a federal government that has taken a haphazard approach to understanding and regulating AI, as well as a belligerent attitude toward international collaboration, seems like a gesture they must know is futile. But perhaps the growing number of incidents where agentic AI causes major security issues is enough to spark real action.
What just happened? Anthropic has moved to block search engines from indexing shared Claude conversations after hundreds of chats appeared in public search results, highlighting how easily user interactions with AI tools can spread beyond their intended audience. The issue stemmed from Claude’s sharing feature, which lets users create a link to a conversation. Those links were accessible without requiring a login, and search engines indexed them like any other public webpage.
The exposure first came to light on Reddit, where users demonstrated how to surface the chats. At least 200 conversations appeared across more than two dozen pages of search results, including some created recently. Although the links have since been removed from search indexes, many of the conversations had already been saved and circulated.
The chats themselves covered a wide range of subjects, but some contained sensitive information. Users shared resumes containing names, contact details, and work histories. In other cases, prompts included what appeared to be workplace material, such as a request to draft an unpublished blog post about a cloud security project. There were also conversations involving healthcare topics and what appeared to be transcripts of private exchanges.
Anthropic said the situation was the result of user behavior, not a system failure. A company spokeswoman said users control when and how they share conversations, and that the links are not discoverable unless someone chooses to distribute them.
– Om Patel (@om_patel5) July 26, 2026
“When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services,” she told The Guardian. She added that the links are “not guessable or discoverable unless people choose to share them themselves.”
Even so, the way the feature works leaves room for confusion. Claude tells users that “anyone with the link” can view a shared conversation, but it does not clearly warn that the link could be indexed by search engines. Once a page is publicly accessible, web crawlers can discover and catalog it unless steps are taken to prevent that.

Google said it does not control what content becomes public. A spokesperson said the company provides website owners with tools to control whether their pages are crawled or indexed and that it adheres to those settings. In this case, Anthropic appears to have used those controls after the issue became public, removing the links from search results.
The same links were also visible on other search engines, including Bing, Brave, and DuckDuckGo.
This is not the first time AI chat logs have surfaced this way. OpenAI dealt with a similar issue last year involving ChatGPT, while X’s Grok chatbot also saw large numbers of conversations become searchable. In each case, the underlying problem was not a breach but the way shared links interact with standard web indexing.
The Claude episode makes clear how thin the line can be between private use and public exposure. Once a conversation is turned into a public link, it effectively becomes part of the open web, where it can be indexed, cached, and redistributed.
Screenless fitness trackers are growing in popularity, with Garmin and Google both recently revealing their own models.
But how does Garmin’s screenless Cirqa compare to Google’s Fitbit Air? Is one a better fit for your fitness needs over the other?
To help you decide, we’ve compared the specs of the Garmin Cirqa to the Fitbit Air, and noted the key differences plus noteworthy similarities between the two. Keep reading to see how the screenless wearables compare and decide whether you think either stand a chance at making it into our best fitness trackers guide.
Want to see how the OG screenless tracker measures up? Visit our Garmin Cirqa vs Whoop and Fitbit Air vs Whoop guides too. Or if you’re not sold on a screenless device, I’ve discussed my experience with them and why I think they’re brilliant at keeping me motivated.
The Garmin Cirqa is available to buy now and has an RRP of £179.99/$199.99. It’s available in a choice between two sizes (small to medium and large to extra large) and four colours (French Grey, Mauve, Black and Captain Blue), though you can purchase two additional bands separately in Citron Grey and Dark Olive.
In comparison, the Fitbit Air is considerably more affordable with an RRP of just £84.99/$99.99. The device comes in a choice between four shades, including Obsidian, Fog, Lavender and Berry.
We’ll start with the most obvious, and noteworthy, similarity. Both the Garmin Cirqa and the Fitbit Air are screenless wearables, which means they can only be controlled via their respective smartphone apps. That might sound confusing, especially if you’re used to more traditional smartwatches that are equipped with a touchscreen display, but the screenless design means you can quietly track your health and workouts without being constantly distracted by notifications or stats.
With this in mind, if you want a device that allows you to use Google or Apple pay, receive notifications and follow maps, then one of the best smartwatches will be a better option for you.
Although both share the same screenless design, we should note that the Fitbit Air does boast a slightly more discrete finish, as its sensor is smaller and therefore blends in slightly better than the Cirqa’s does. It’s not a major issue, but something to keep in mind if you want a more sleek finish.


Unlike Whoop which operates as a subscription model, you don’t need to sign up to a monthly or annual plan to use either the Garmin Cirqa or Google Fitbit Air. Without a subscription, you’ll still be able to track workouts, sleep and monitor the likes of your heart rate, blood oxygen and more.
However, signing up to both Garmin and Google’s subscription will unlock extra features that could be useful. For the Cirqa, there’s Garmin’s Connect Plus plan which will set you back either £69.99 annually or £6.99 a month. With Connect Plus, you’ll have access to nutritional tracking, and access to various workout types including cardio, strength, HIIT, yoga and pilates. In addition, you’ll unlock access to Garmin’s AI-powered Active Intelligence which provides personalised insights throughout the day.


For the Fitbit Air, you can opt to sign up for Google Health Premium. While it isn’t technically necessary, we should note that we were really impressed with the service and would strongly recommend signing up to get the most out of the Fitbit Air. Google Health Premium is driven by the Google Health Coach which provides AI-powered personalised insight, can explain what your metrics mean and create workout plans that are tailored to your lifestyle. For just £7.99 a month, or it’s included if you have Google’s AI Pro or Ultra plans, we’d seriously recommend opting for the subscription here.


Unlike traditional smartwatches like the Google Pixel Watch 4, both the Garmin Cirqa and the Fitbit Air promise multiple days of battery before needing a top-up. However, the Cirqa boasts the edge with a promise of up to ten days of charge, whereas the Fitbit Air claims around seven days.


While Whoop has a clever PowerPack that charges the band while it’s still on your wrist, for uninterrupted tracking, unfortunately neither the Cirqa nor the Fitbit Air offers this.
Earlier this year, Garmin announced it was partnering with Natural Cycles, an FDA-cleared fertility tracking app, and the Cirqa is one of the supported devices. This means that users can simply wear their Cirqa overnight (which you likely will anyway to make use of Garmin’s excellent sleep tracking) to record skin temperature, with the data then being fed directly into Natural Cycles – so no manual logging is required.


This is a welcome inclusion for the Garmin Cirqa as, although the Fitbit Air does include cycle tracking, many can find traditional tools to be generic and not personalised. Instead, as Cirqa specifically measures skin temperature, its partnership with Natural Cycles means you can see your fertile days. Just remember, you’ll need to pay for a Natural Cycles subscription which will set you back £12.99 a month.
If you’re familiar with Garmin, and have used one of the best Garmin watches in the past, you might be surprised to know the Cirqa doesn’t have GPS built-in. Instead it uses Connected GPS which means you’ll need to bring your paired smartphone out with you in order to record the location of your activity.
Similarly the Fitbit Air requires you to keep your paired smartphone with you in order to record the location.
As we’re yet to review the Garmin Cirqa, we’ll hold off from providing a conclusive verdict. However, with a promise of up to 10-days of battery life, Natural Cycles integration and Garmin’s health and fitness tracking tools, the Cirqa looks set to be a brilliant wearable for those who don’t want to be distracted by a screen.
However, the Fitbit Air is a really tough device to beat. Not only is it considerably more affordable, but its companion app is brilliant and it has a more discrete style for those who don’t want an overtly flashy wearable.
We’ll be sure to update this versus once we review the Garmin Cirqa.
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face.
The vulnerabilities were exploited during the incident in which OpenAI models hacked Hugging Face’s production infrastructure to steal answers for a cybersecurity benchmark.
OpenAI disclosed last week that its models, including GPT-5.6 Sol and a more capable pre-release model, were being tested against ExploitGym, a benchmark designed to measure advanced cyber capabilities.
The models were run without production safeguards normally used to prevent AI agents from conducting autonomous cyber activity.
However, the agents were placed inside a highly isolated environment where network access was limited to installing packages through internally hosted third-party software acting as a proxy and cache for package registries.
During the evaluation, the models spent significant time looking for a way to reach the open internet and obtain the benchmark’s test solutions.
OpenAI said the models exploited a zero-day vulnerability in the unnamed package-registry proxy and then performed privilege escalation and lateral movement inside the research environment until they reached a system with internet access.
OpenAI did not identify the package-registry proxy software or vendor at the time, saying only that the vulnerability had been privately disclosed and was being patched.
After reaching the internet, the models determined that Hugging Face might host the ExploitGym datasets and test solutions they were attempting to obtain.
OpenAI said the models searched for ways to access that information, chaining stolen credentials, zero-day vulnerabilities, and other attacks to find a remote code execution path into Hugging Face’s production infrastructure.
In a new disclosure published Monday, JFrog confirmed that the third-party package-registry software was a self-hosted JFrog Artifactory installation.
“During a security evaluation, OpenAI’s models identified previously unknown zero-day vulnerabilities in self-hosted Artifactory installations that could be exploited to gain unintended internet access,” JFrog CTO Yoav Landman said.
JFrog said OpenAI immediately disclosed the vulnerabilities, allowing the company to develop, test, and release fixes for cloud and self-hosted customers.
Cloud customers are already protected, while self-hosted customers have been notified to install the fixed versions.
Artifactory 7.161.15 Self-Managed, released on July 27, contains a critical security notice stating that it fixes multiple vulnerabilities that could be chained together into a critical attack scenario when Anonymous Access is enabled.
“This version is designed to fix multiple security vulnerabilities that, when chained together, could result in a critical attack scenario if Anonymous Access is enabled,” reads the 7.161.15 Self-Managed release notes.
“Anonymous Access is disabled by default and is not recommended for production environments due to the additional security risks it introduces.”
Although JFrog did not list the vulnerabilities in its release notes, BleepingComputer found eight associated flaws by searching CVE.org for Artifactory version 7.161.15, released on July 27.
The CVE records were all created on July 27, the same day JFrog disclosed the zero-days. All eight credited OpenAI with discovering the vulnerabilities and specified Artifactory 7.161.15 as the release containing the fixes.
The vulnerabilities are tracked as:
BleepingComputer contacted JFrog and OpenAI to ask which of the eight CVEs were exploited during the incident and which vulnerabilities were chained together.
Only JFrog replied, declining to identify the CVEs or provide further technical details.
“Outside of our CTO’s blog and commentary and JFrog release notes, we aren’t adding further detail or comment at this time,” JFrog told BleepingComputer.
However, several of the CVEs found by BleepingComputer as associated with the release could have provided capabilities that matched portions of the attack detailed by OpenAI.
CVE-2026-65924 is a server-side request forgery vulnerability in Artifactory’s support for Terraform remote repositories.
An authenticated user, or an unauthenticated user when anonymous access is enabled on the repository, could exploit the flaw to make Artifactory send outbound HTTP requests to arbitrary destinations and return the response content.
CVE-2026-65925 similarly allows a user with read access to an Artifactory Cargo remote repository to make Artifactory request unintended URLs and return the responses.
Another vulnerability, CVE-2026-66014, is an authentication-handling weakness in Artifactory’s internal request processing that could allow an attacker to elevate privileges under specific conditions.
These vulnerabilities could have provided the internet-access and privilege-escalation capabilities described by OpenAI.
However, it remains unknown which flaws were exploited, how they were chained, or whether all eight vulnerabilities were involved in the sandbox escape.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
A fired manager overseeing Tesla’s Full Self-Driving testing operations in Houston is now suing the company for unlawful retaliation after escalating concerns about “systemic safety oversight defects,” according to a lawsuit spotted by The Independent. The manager, Javier Medrano, claims Tesla’s unwillingness to offer extra resources or hire more staff created a scenario where the company’s robotaxis became “rolling hazards on public streets.”
Engadget has asked Tesla to comment on the lawsuit. We’ll update this article if we hear back.
The filing states that Medrano managed a team of safety operators who rode in Tesla vehicles being used to test the company’s Full Self-Driving software from October 2024 to May 1, 2025. As a manager, Medrano was expected to “actively audit driving clips, conduct weekly ride-alongs and manage safety incidents,” and offer significant on-call availability during the week. Medrano’s issues began because the number of operators he was responsible for grew to 38 — beyond the 1-to-15 ratio he claims Tesla Autopilot Director Pete Scheutzow set as the baseline.
The lawsuit claims that during a conversation with Scheutzow, Medrano tried to raise his concern that the current ratio of managers to operators could lead to him “not sleeping or eating correctly,” but Scheutzow allegedly dismissed the issue by saying “I don’t get the impression you’re drowning.” The lawsuit claims Tesla’s unwillingness to respond to Medrano led to the ultimate failure of the company’s “under-resourced safety structure” in the form of a crash that happened under Medrano’s watch.
Medrano processed the accident “while physically asleep,” the lawsuit claims, and ended up giving the operator “unsafe guidance” that led to her “remaining at the unsafe scene for an hour where she was approached by an allegedly impaired third party.” Following the accident, the lawsuit says Medrano’s attempts to formally escalate the safety issues that led to the accident and prove that Tesla was withholding resources from his Houston region led to him being fired.
In return for what the lawsuit claims is unlawful retaliation, Medrano is asking to be reinstated to his role and seeking fees like restitution for an unvested equity award, front and back pay and compensatory damages for “emotional distress, familial strain and severe financial stress.” Tesla’s technical approach to autonomous vehicles has been criticized in the past, but the lawsuit suggests managerial problems could also be making the company’s robotaxis unsafe.
That’s not to say the company’s software isn’t also a concern. In May, Reuters reported that Tesla may be exaggerating the safety of its Full Self-Driving software. Data labelers who work with the camera footage Teslas use to navigate regularly see FSD fail at basic driving tasks, according to the report. The National Highway Traffic Safety Administration is also currently investigating the company’s self-driving technology. While a version of Tesla’s software that requires driver supervision is available to subscribe to now, crashes, the slow rollout of the company’s robotaxi service and now apparent management issues all make the success of Full Self-Driving increasingly uncertain.

It’s time to recognize the Seattle area’s boldest innovators. Nominations are now open for GeekWire’s 2026 Uncommon Thinkers Awards.
Now in its fourth year, and in partnership with Greater Seattle Partners, the program aims to honor inventors, scientists, technologists and entrepreneurs who are transforming industries and driving positive change throughout the world.
Community nominations will be accepted through Sept. 18 at 11 a.m. PT, after which a panel of judges will select honorees. They’ll be celebrated on stage during a VIP reception at the annual GeekWire Gala on Dec. 10.
Honorees are selected based on innovation, creativity and leadership and should have a track record of introducing novel ideas, technologies, or solutions that challenge the status quo. Nominees should also demonstrate a measurable and meaningful impact on their respective fields or industries, contributing to the betterment of society.
Do you know an Uncommon Thinker deserving of recognition? Fill out the nomination form today.
Read the GeekWire profiles of last year’s Uncommon Thinkers honorees:
Thanks to First Tech Federal Credit Union, the title sponsor of this year’s GeekWire Gala. For a recap of last year’s event, head here.
The United States has moved to block new imports of foreign-made robots and power inverters. Officials fear a hostile power could spy through them, or switch them off from afar. The order never says China. It does not need to.
The Federal Communications Commission added two categories to its Covered List on Tuesday, as first reported by CNBC. One is “advanced robotic devices,” meaning mobile robots such as humanoids and quadrupeds. The other is connected power inverters, the boxes that connect solar panels, batteries and data-centre gear to the grid.
Landing on the Covered List is a hard commercial block. Equipment on it cannot get FCC authorisation. Almost every electronic device needs that clearance before it can reach the US market. It is the same lever the agency pulled on DJI drones and Huawei network kit.
Read the FCC document and one thing stands out. It restricts foreign-produced robots and inverters “regardless of the nationality of origin.” The politics point at Beijing. The text points at everyone.
The gap is deliberate. The framing lets Washington name China as the threat. The wording pushes every manufacturer toward the same choice: build in America, or clear a security review. An administration official told CNBC the aim was to protect the US AI buildout and drive firms to reshore. “Economic security is national security,” the official said.
There is a door out. A maker can apply for “Conditional Approval” and keep selling if it clears the check. The Department of War handles robots; Homeland Security handles inverters. In principle any manufacturer can walk through it, Chinese firms included. In practice it puts the Pentagon in charge of vetting which robots reach American shelves.
The pairing looks odd until you read the security case. Both devices are networked, and both answer to signals from far away.
Grid inverters phone home for monitoring and firmware updates. The interagency determination warns that the same channel could let a foreign firm “turn off the inverters or use them to collect and exfiltrate data.” More solar and battery capacity on the grid means more remote-controllable boxes.
Robots carry the same risk on legs. The robot determination warns that networked machines “collect data that could be leveraged by malign actors to surveil Americans,” or let an attacker “remotely commandeer the robots.” Unitree is the emblem of the category. The Chinese firm’s humanoids and quadrupeds have gone from lab demos to a pending public listing, and the Pentagon has already flagged the company.
Less than the headlines suggest, at least at first. The block hits only new device models seeking authorisation. It does not touch robots or inverters already bought, models already approved, or anything the federal government buys and uses.
So this is an import gate, not a recall. Its bite grows over time, as newer models are the ones frozen out while older approved ones stay on sale. The FCC used the same staged approach on drones and consumer routers. CISA now tells companies to screen suppliers against the list.
The harder question is whether the US can fill the gap. China dominates both supply chains. The same rare-earth and battery chokeholds that complicated the drone ban apply here. Blocking imports is quick. Building a domestic industry to replace them is slow, and so is hardening a grid whose weak points attackers are already probing.
For now, Washington has drawn the line where it is easiest: at the border, on the next generation of machines. Whether the factories follow is the test that matters. A listing will not settle it.
The iPad might be the more popular choice when it comes to choosing the best tablet for personal use but, with the recent price hike across its product portfolio globally, Apple‘s slates are just that little bit harder to justify for everyday use.
The entry-level iPad, for example, used to be a fantastic bang-for-the-buck tablet with prices from AU$599, but is now bordering on the premium side of things at AU$749 for the base 128GB model. That’s a 25% increase, which will sting for some households.
Which is why this deal on Samsung’s Galaxy Tab A11 Plus for just AU$359 (256GB model) makes it a much more enticing alternative if you’re in the market for a no-frills tablet that’s still very capable — if you’re willing to move from iPadOS to Android of course.
We sadly haven’t had the opportunity to test this budget Samsung tablet for ourselves, but we trust our colleagues over at Android Central who rate it 4 out of 5 stars, calling it out as Samsung’s best cheap tablet at present.
Despite some cost-cutting elements, like a lower-powered chipset compared to Samsung’s S-series Tabs, you still get smooth performance and 7 years of software support from the South Korean tech giant.
Compromises are few. It has an 11-inch 90Hz TFT LCD screen with a 1,920 x 1600 resolution, a 3.5mm headphone jack, expandable storage via microSD with support for up to 2TB cards, four speakers and two cameras (8MP rear, 5MP front).
Powered by a MediaTek Dimensity 7300 chipset — which is an upgrade from the Tab A9+ (there is no A10), the A11+ handles light gaming and multitasking well, even if you have multiple tabs open in a web browser alongside other apps (like note-taking, for example).
The tablet also supports Samsung’s DeX desktop mode that’s usually reserved for the brand’s premium S-series smartphones, making it a decent laptop replacement, but note it will not handle hardcore productivity.
The few compromises that have been made come in the form of the 7,040mAh battery that will not last more than a full day with average use. The 25W ‘fast charging’ isn’t particularly fast either, while the TFT LCD screen isn’t the brightest at a peak of 480 nits. There’s also no S Pen support here but, then again, that’s hardly a complaint at this very affordable price point.
The extended software support, moreover, means you’ve got something you may not need to upgrade for a while yet and having higher storage means there’s less pressure on the battery, which means the Tab A11+ will go the distance. Like we said, brilliant bang for buck.
Weekend Open Thread: Brooks Brothers
Commonwealth Games boxing: Jadumani Singh seals dominant 5-0 win over Pakistan’s Sumama Rehman to enter quarter-finals | Commonwealth Games News
Intel is reversing course and bringing hyper-threading back to its server chips
Ethics, other provisions in crypto Clarity Act to be further discussed
Luke Littler dismantles Gerwyn Price to retain title in Blackpool
2026 3M Open leaderboard: Scottie Scheffler finds putter in Round 1, sits three back
The Part of the Electric Transition Nobody Wants to Discuss
16 Dresses for the High Summer Event
A New Post-Apocalyptic Gundam Anime Series Blasts Into SDCC
BITCOIN JUST ENTERED THIS CRITICAL ZONE…
The Peugeot Family: How 200 Years of an “Old Money” Dynasty Died in A Boardroom
Spain sweeps the board at 2026 World Cup with individual awards
Ripple bought a bank in pieces. The $4 billion audit
Major shareholder moves on Canyon
XRP Ledger adds $2.6B as RWA inflows rank second
Uniswap (UNI) pushes deeper into tokenized RWAs with permissioned trading pools
Anthropic launches Claude Opus 5, a cheaper AI model for coding, agents and enterprise workflows
‘Stargate’ Creator’s New Sci-Fi Series Returns for Season 3 Tomorrow
SEC Agrees to Overhaul Recordkeeping After Settling Coinbase Lawsuit Over Gensler’s Lost Texts
Alliance Entertainment Holding Corporation (AENT) Discusses Evolution Into Omnichannel Distribution and Fulfillment Platform for Media and Collectibles Transcript
You must be logged in to post a comment Login