The Legend of Zelda: Ocarina of Time, a 1998 Nintendo 64 adventure, is now available as a native app for iPhones and iPads. Full screen resolution, sixty frames per second, widescreen perspective, usable touch overlays, Bluetooth controllers that simply work, plus keyboard and mouse capabilities for good measure. There is no blurry 240p image, no stuttering twenty-frame limit from the original hardware, and no remote streaming via PC. The game has been recreated and is now running on the device itself.
Ocarina of Time, running natively on iOS and iPadOS for the first time.
Not an emulator. Ship of Harkinian has run on Windows, Linux, macOS, Switch, Wii U, and Android. Never iOS. Now it runs on iPad, with iPhone in the build too.
Kahris, also known as Chrissotraidis, reused existing parts to make HarkinianPad. The Harbour Masters laid the basis for the entire project with the Ship of Harkinian, a long-term open-source effort. The Harkinian team has successfully turned the fully decompiled C code from Ocarina of Time into clean native code that will run on Windows, Linux, macOS, Switch, Wii U, and Android. That was a massive task in and of itself, and the zeldaret crew and the Harbour Masters completed all of the reverse engineering and engine tweaking long before Kahris got involved. Now, Kahris did not go and re-decompile anything from scratch. No, he took the existing Ship of Harkinian codebase and made it compatible with iOS and iPadOS for the first time.
GAMER COLLECTIBLE MODEL KIT – Adults ages 18 and up can share their love of video games with the LEGO The Legend of Zelda: Ocarina of Time – The…
LEGO CASTLE RUINS BUILDING SET – This detailed gaming collectible features a ruined castle area, Link, Zelda and Ganondorf minifigures, and 2 more…
FEATURES AND FUNCTIONS – Recreate the final battle scene with movable rubble, a button to raise Ganondorf from the ruins, the hidden Megaton Hammer…
That wasn’t a simple recompile task, though, because the game required a completely new platform layer that understood the app lifecycle on iOS, what to do with file access, graphics, and input, and so on. So Kahris performed some research to determine the requirements, and then he created a single prompt for Codex 5.6 Sol. That tool went off and did all the heavy lifting for him, sorting the build system for ARM64, linking everything together, ensuring the app didn’t get killed when iOS suspends and resumes, hooking up Metal for rendering, getting UIKit where it needed to be, adding Files-app support so users can simply drop in their own ROM, setting up native controller paths, and implementing a touch control system that works in landscape.
The end result is now available on GitHub as an open-source project. Now, the repo itself has no game data or ROMs, as those must be added manually by the user. To get the app running, people must first build or install the IPA, sign it for their device, run it once to create a folder in the Files app, copy in a valid Ocarina of Time ROM, then allow the app to do its thing. After that, the game starts up, saves are working, audio is playing via the speakers, controllers are pairing over Bluetooth, and you still have access to all of the touch controls and menu options.
Performance appears to be smooth because we’re dealing with pure C code that is running directly on Apple silicon and drawing using Metal. So, on an iPad, the image fills the screen at its native resolution and maintains a steady sixty frames. The same build works on the iPhone, and to my surprise, widescreen support works quite well without stretching or letterboxing in an odd fashion.
Night falls over a quiet industrial yard or a sprawling campus. Most security systems wait for something to happen. 1ROLLO does not. This tall, single-wheeled machine from Estonian startup Rollo Robotics rolls along preset routes under its own power, scanning everything around it while balancing on one fat tire.
Rollo Robotics says that 1ROLLO is the world’s first stable autonomous monowheel robot capable of performing real security tasks. Founded in 2025 by Arno Kütt, the inventor behind those Cleveron parcel robots, and Sander Sebastian Agur, the company spent its first months bashing its head against a problem that has perplexed designers for decades: how to keep a single-wheel platform upright while moving, turning, and stopping without tipping over.
The Safest Electric Unicycle (EUC): The INMOTION V9 is the world’s first e-unicycle to achieve full-device UL certification, setting a new safety…
The Smartest Electric One-Wheel: Featuring industry-first Ride Connect technology, the V9 enables app-based remote control, real-time GPS tracking…
The Lightest and Slimmest Suspension EUC: Weighing just 50.7 lbs, the V9 is ultra-portable for commuting to the office, school, or gym. Its slim…
The solution is hidden inside the large wheel itself, as a high-speed flywheel rotating vertically inside the main tire is the key. The gyroscopic forces from the spinning wheel keep the robot balanced as it moves. To turn left or right, they simply tilt the internal flywheel, and the entire machine leans into the curve in the same way a motorcycle would. High frequency sensors transmit data into their own in-house software, which constantly makes small modifications to keep the robot upright even on uneven ground or in the wind.
At roughly 45 kilograms, 1ROLLO is heavy enough to feel sturdy while remaining light enough to move with a surprising amount of agility. It can reach speeds of up to 30 kph, which is fast enough to navigate huge properties without taking all day. You can charge the battery for up to eight hours, after which 1ROLLO will return to a charging station to recharge itself. The sealed body has an IP65 rating, which means it can withstand light rain, dust, and water jets.
The robot has cameras that can see all around. Computer vision and edge AI detect people, vehicles, open doors, and anything else that appears out of place. The RTK GNSS system keeps the robot’s position accurate to millimeters, allowing it to follow digital maps of a site while remaining on track. When something odd occurs, the robot can transmit an alarm to a cloud dashboard via 4G, 5G, or Wi-Fi, from which an operator can watch the live feed on a computer, communicate with the robot via the built-in mic and speaker, or even dispatch a human guard. You can have a large number of these things working together on the same platform, allowing a single supervisor to monitor an entire fleet of machines.
The fact that 1ROLLO is so slim is a significant practical advantage. Four-wheeled security robots are always getting stuck in tiny corridors, entrances, and congested walkways, but 1ROLLO’s single wheel and thin body allow it to fit into locations that larger machines just cannot. The initial deployments will take place at industrial locations, data centres, airports, campuses, and vital infrastructure. Rollo Robotics does not sell the hardware outright; instead, they provide a subscription service in which users pay a monthly charge and the firm handles maintenance, software upgrades, and hardware refreshes, allowing operators to avoid spending a lot of money.
In January 2026, the company completed a €3.7 million pre-seed investment headed by FoodLabs and Prototype, with assistance from Enterprise Estonia. The money is being put to good use, as they are modifying the gyroscopic technology to handle extreme weather and heavy traffic, securing the supply chain, and preparing for pilot projects. Commercial units are scheduled for 2027. [Source]
Nominal CEO Cameron McCord says Seattle’s concentration to tech talent and key partners attracted the company. (Photos via Nominal)
Seattle’s emergence as a hub for companies building the next generation of industrial technology is drawing another high-profile startup.
Los Angeles-based Nominal, whose software helps engineers build, test and validate complex hardware systems, is establishing a permanent Seattle office as it ramps up hiring and looks for a larger home in the region.
The nearly 4-year-old company currently employs 11 people at a downtown Seattle co-working space, and expects to more than double that number by the end of the year.
Nominal’s Stephen Slattery will lead the Seattle office.
The company is also relocating Head of Product Stephen Slattery, the former director of technical operations at defense tech giant Anduril Industries, from Los Angeles to Seattle to oversee the new office. Employing about 200 employees globally, Nominal also operates offices in Austin, New York, Washington, D.C., and London.
Seattle’s concentration of tech and aerospace talent, along with proximity to key partners and customers, attracted the fast-growing company.
Nominal CEO Cameron McCord said Seattle is one of only a handful of U.S. markets with a deep concentration of engineers experienced in solving large-scale infrastructure and reliability problems. Seattle’s aerospace heritage also appealed to the company.
Advertisement
“Some of the magic of Nominal is putting them in one room,” McCord told GeekWire.
The company boasts 75 customers, about half of which are in the defense sector. It also sells its software to companies in the energy, robotics and automotive arenas.
The Seattle expansion comes just months after Nominal raised an $80 million venture capital round led by Founders Fund at a $1 billion valuation, part of a growing trend of companies serving industries where artificial intelligence is accelerating innovation in the physical world.
“Nominal exists to help these engineering teams rethink their data supply chain: the end-to-end flow from instrumentation through acquisition, storage, analysis, reporting, and into the decisions that shape the next design,” the company wrote in the funding announcement.
Advertisement
Seattle has increasingly become a landing spot for companies operating at the intersection of AI and the physical world, while some of the region’s fastest-growing homegrown startups — including Overland AI, Carbon Robotics, Brinc and Stoke Space — are helping define the category.
In recent months, defense tech company Anduril has expanded its operations in the Seattle area. AI infrastructure startup Armada — which like Nominal is backed by Founders Fund — and AI giants Anthropic and OpenAI also have opened new offices or expanded engineering centers in the region.
Nominal’s McCord, a former U.S. Navy submarine officer and nuclear engineer who previously worked at Anduril, said conversations with former colleagues, including Anduril co-founder and COO Matt Grimm, helped reinforce Seattle’s appeal.
Advertisement
“I’ve been able to get a lot of advice and thoughts from him on what it looks like to properly enter the Seattle market,” said McCord. “Everything from him is incredibly positive on the talent and density.”
While Nominal has gained traction among defense contractors — McCord said four of the five traditional U.S. defense companies use its software — he said the company increasingly sees opportunities across a number of industries. The energy sector — including nuclear, fusion and batteries— as well as AI data center infrastructure are growing areas of interest for the young company.
The Seattle office will be more than an engineering outpost. McCord said Seattle will become a full cross-functional location, with engineering, sales, customer success, design and other teams represented as it grows.
The company expects the Seattle office to reach roughly 20 to 25 employees by the end of this year and could double again to 40 or 50 employees by the end of 2027. It is currently looking for a permanent office space, likely targeting downtown Seattle.
Advertisement
McCord said the Seattle office will play a key role in Nominal’s growth as it looks to reimagine the unique challenges that industrial companies face in building hardware systems for this new era.
“There’s a huge market opportunity as the world reindustrializes,” he said.
See this interview with McCord by General Catalyst’s Paul Kwan for more on the company:
At the Hackaday Europe conference in Italy earlier in the year, we were shown a rather interesting device. The work of [Alun Morris], it was an ESP32-powered Cheap Black Display board, and it was running a web browser. Definitely an achievement.
Lest you imagine that it was sporting the latest and greatest in browser technology, we must disappoint you. The browser in question is a very basic text mode device, but it did happily retrieve Hackaday, which should be the only test a browser should need to pass.
Under the hood it’s running FreeRTOS, with separate HTML retrieval and tokenizing, and UI processes. It can fetch web pages directly, but there’s also a server-side proxy for difficult sites, and for creating image thumbnails.
Advertisement
An ESP32 is a powerful microcontroller, but it’s fair to say it’s not in the league of running a web browser and as far as we can remember this is the first one we’ve seen. We’re sure it’s a field with further progress to be made though, particularly with the more powerful recent chips in the series. This project however is a good start, and more importantly it can be yours for a few dollars on Ali to buy a dev board. What are you waiting for?
Six months ago, Anthropic was the darling of America’s AI boom. It led on the models and was loudest on the ethics. This summer, it finds itself alone.
The Claude maker is now the odd one out in nearly every big AI policy fight, Axios reported. It is the most valuable startup in the world, and at the same time the most isolated lab in the industry. The two facts turn out to be connected.
Alone on open weights
The clearest sign came last week. Anthropic was the only frontier lab that declined to sign an open letter urging Washington not to restrict open-weight models. Nvidia’s Jensen Huang led it. Google and OpenAI, its two closest rivals, both signed. That left Anthropic defending tighter controls on the very business model all three still lean on.
Dario Amodei tried to calm the row himself. In a blog post, Anthropic’s chief executive insisted the company has never called for banning open models. He even called weaker ones “a public good.”
Advertisement
He still did not sign. He also held his line that the dangerous ingredients, chiefly advanced chips reaching authoritarian states, need tighter control.
The 💜 of EU tech
The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!
Isolated on every other front too
The pattern repeats across the board. The Pentagon blacklisted Anthropic in February, after a fight over whether Claude could be used for surveillance or autonomous weapons. One senior defence official said on Friday there was “no AI company more hostile to the warfighter.”
Advertisement
On safety, Anthropic has pushed harder than anyone. It has backed state AI laws and floated an FAA-style regulator to vet models before release. Yet when the White House flagged a security flaw this summer, Anthropic disputed how serious it was. The row helped trigger export controls that forced two of its models offline for nearly three weeks.
Then there is distillation. Anthropic has accused Chinese labs of training cheaper models on Claude’s outputs in “industrial-scale” campaigns, the New York Times reported.
Critics call distillation a normal part of AI development. They also note the awkward timing. Anthropic had just settled a $1.5bn copyright lawsuit over pirated books used to train its own models.
Alone, and winning anyway
The isolation is not total. Anthropic did join more than 1,100 employees from rival labs this week in a petition urging Washington to help “deliberately pace” frontier AI. Its central worry, that the technology is moving faster than anyone can safely steer it, is now shared across the industry.
Advertisement
And for all the friction, Anthropic is not losing. Its models still top most independent benchmarks, and enterprises keep paying premium prices despite the grumbling over cost and restrictions. It reached a $965bn valuation in May, ahead of OpenAI, and is heading for an IPO that could value it higher still.
The traits that strand it in every policy fight, caution and a refusal to bend, are the same ones that built its lead. Anthropic would rather be right than liked, and for now it can afford to be.
PS Audio is now shipping its PMG Signature S200 and S400 stereo power amplifiers, priced at $7,999 and $9,999 respectively. Both are hand assembled in Boulder, Colorado, available in black or silver, and designed to bring the company’s latest Signature amplifier platform into a single chassis.
The S400 delivers 200 watts per channel into 8 ohms and 400 watts into 4 ohms, while the S200 offers 100 watts into 8 ohms and 200 watts into 4 ohms. The more powerful amplifier provides 5 watts of Class A bias per channel, but the less expensive S200 doubles that to 10 watts.
Yes, the less expensive and lower powered amplifier offers twice the Class A operating window. That requires some explanation, because audiophile product hierarchies occasionally resemble family trees drawn during a power outage. The S200 remains in Class A for its first 10 watts per channel, while the S400 transitions after 5 watts in exchange for twice the maximum output. And because summer 2026 was apparently not hot enough already, the S200 consumes roughly 180 watts at idle before you play a single note.
One Architecture, Two Different Priorities
S200 and S400 (shown) have the same dimensions with same rear panel configuration.
Both amplifiers were designed by Darren Myers and engineered by Bob Stadtherr around the same basic PMG Signature topology used in the company’s M400 and M800 monoblocks.
PS Audio says the output stages use very low overall negative feedback, with bandwidth extending beyond 500kHz and slew rates greater than 200 volts per microsecond. Typical total harmonic distortion is rated below 0.002 percent from 20Hz to 20kHz at 1 watt into 8 ohms.
Advertisement
An amplifier does not need to reproduce a 500kHz musical note, unless the local bats have taken over the listening room. Wide bandwidth and high slew rate are instead intended to help the circuit respond quickly to transients while maintaining phase performance well beyond the audible range.
Both models also use an active power supply architecture rather than relying only on the passive transformer, rectifier and capacitor arrangement found in many conventional amplifiers.
PS Audio claims the active supply can hold its output more consistently as current demand changes, reducing the extent to which one stereo channel affects the other during demanding musical passages. That matters because the two channels share a chassis and power supply, unlike the M400 and M800 monoblocks, where each channel enjoys its own very expensive apartment.
The S400 places two 200 watt Signature channels into one enclosure. The S200 reduces maximum output but provides twice the Class A operating range and is intended for smaller rooms, more efficient loudspeakers and listeners who do not routinely recreate Motörhead concerts at home.
Advertisement
S200
How Much Class A Do You Need?
The S400 operates in Class A for its first 5 watts per channel, before transitioning into Class A/B operation. The S200 remains in Class A for its first 10 watts per channel.
That distinction may matter more than the power ratings suggest.
Advertisement. Scroll to continue reading.
Most domestic listening uses considerably less amplifier power than people imagine, particularly with efficient loudspeakers and moderate listening distances. A 10 watt Class A window could therefore cover a meaningful portion of normal listening with the S200, while the S400 trades some of that operating range for greater output and current capability.
Advertisement
Neither amplifier is a pure Class A design at full power, and nobody should describe it that way. Both are high bias Class A/B amplifiers engineered to remain in Class A during lower output operation.
That also explains the idle power consumption. The S200 consumes approximately 180 watts at idle, while the S400 draws around 190 watts. These are not amplifiers one leaves running all week because the dog appreciates a warmer den.
S400
PMG S400 & S200 Specifications
PMG S400
PMG S200
Price
$9,999
$7,999
Power into 8 ohms
200W per channel
100W per channel
Power into 4 ohms
400W per channel
200W per channel
Class A bias
5W per channel
10W per channel
Frequency response
Below 10Hz to 80kHz
Below 10Hz to 80kHz
Bandwidth
Greater than 500kHz
Greater than 500kHz
Slew rate
Greater than 200V/µs
Greater than 200V/µs
Typical THD
Below 0.002%
Below 0.002%
Damping factor
Greater than 240
Greater than 240
Weight
57.2 pounds
56.2 pounds
Dimensions
17.5 x 16.75 x 8.75 inches
17.5 x 16.75 x 8.75 inches
Each amplifier includes balanced XLR and single ended RCA inputs, two sets of silver plated binding posts per channel for biwiring, and 12 volt trigger input and output connections. Input sensitivity is 2 volts for the S400 and 1.4 volts for the S200, with both providing 26.2dB of gain.
Stereo Versus Monoblocks
The S400 is particularly interesting because it carries the same headline output rating as a $17,998 pair of PMG M400 monoblocks.
Advertisement
Both deliver 200 watts into 8 ohms and 400 watts into 4 ohms, but the M400 provides 30 watts of Class A bias, complete power supply separation and one chassis per channel. The S400 drops the Class A allocation to 5 watts and places both channels in one enclosure, saving almost $8,000 and one shelf sturdy enough to support a small Buick.
The flagship M800 monoblocks remain in another financial district at $29,998 per pair, delivering 400 watts into 8 ohms, 800 watts into 4 ohms and 50 watts of Class A bias.
The stereo models are therefore not replacements for the monoblocks. They are the rational part of a product family that still leaves room for the gloriously irrational. Or people who actually want enough money leftover to actually buy crazy things like food, clothing, and pay for college tuition.
Who Are They For?
The PMG S200 makes the most sense for listeners using efficient or moderately demanding standmount and floorstanding loudspeakers in small to medium sized rooms. Its larger Class A window may also appeal to listeners who prioritize low level listening, acoustic music, vocals and smaller ensembles over maximum output.
Advertisement
The PMG S400 is the better option for lower sensitivity loudspeakers, larger rooms and listeners who need greater dynamic headroom but cannot justify nearly $18,000 for the M400 monoblocks. Which is like 99% of the population.
Both models should also work in high performance home theater systems where a dedicated stereo amplifier is used for the front channels. Trigger connections make integration easier, although placing a 57 pound furnace inside a sealed equipment cabinet remains a splendid way to meet your installer again and possibly your local fire department.
Have you people not gone outside this summer?
Advertisement. Scroll to continue reading.
Advertisement
Who Should Avoid Them?
Listeners using very efficient loudspeakers may not need this much amplifier, while owners of extremely difficult low impedance designs should confirm compatibility with PS Audio or an authorized dealer before purchasing.
Anyone expecting cool running Class D efficiency should also look elsewhere. The S200 and S400 consume substantial power at idle and require adequate ventilation.
PS Audio currently includes a 60-day in home trial for both models, with return shipping covered when purchased directly. That is useful because amplifier matching remains highly system dependent, and no specification can tell you whether ten watts of Class A will make your loudspeakers sing or merely warm the room more elegantly.
The Competition
At these prices, the PMG amplifiers are entering a crowded room where nobody arrived carrying a small transformer.
Advertisement
The $7,865 Pass Labs X150.8 is the most obvious rival to the S200. It delivers 150 watts per channel into 8 ohms, uses a heavily biased Class AB design and consumes 370 watts while sitting idle. Anyone attracted to the S200’s extended Class A operation will almost certainly have the Pass Labs on the same audition list, although the air conditioner may request its own dedicated circuit.
The $7,000 Parasound JC5 offers 400 watts into 8 ohms, 600 watts into 4 ohms and 12 watts of Class A operation. On paper, that makes it an uncomfortable competitor for both PS Audio models because it delivers considerably more power for less money. Specifications do not determine how an amplifier sounds, but they remain remarkably persuasive when the difference could also purchase a very good preamplifier.
The $9,499 Michi S5 turns the power contest into performance art with 500 watts per channel into 8 ohms and more than 800 watts into 4 ohms. It is larger, heavier and less focused on Class A operation, but listeners driving inefficient planar, electrostatic or large floorstanding loudspeakers will notice that it offers enormous reserves for substantially less than the S400.
McIntosh buyers will also consider the $8,500 MC312, which delivers 300 watts per channel into 2, 4 or 8 ohms through the company’s Autoformer outputs. It brings the blue meters, strong resale value and sufficient mass to alter local tides, although its design philosophy is very different from PS Audio’s wide bandwidth, low feedback approach.
Advertisement
The S200 and S400 therefore do not win the specification contest on power per dollar. Their case rests on the PMG circuit architecture, active power supplies, domestic construction and PS Audio’s 60 day home trial. At $8,000 to $10,000, “trust us” is not an audition strategy.
S200 (shown) and S400 are both available in silver or black shown here.
The Bottom Line
The PS Audio PMG S200 and S400 make the company’s newest amplifier architecture considerably more accessible without pretending that $7,999 is pocket change.
The S400 offers the same rated output as the M400 monoblocks for thousands less, while the S200 sacrifices maximum power in exchange for a larger Class A operating window and a lower price.
Neither model is inexpensive, lightweight or particularly concerned about your electric bill. But both bring legitimate engineering differences to the PMG lineup and give listeners a reason to consider the stereo models beyond the obvious advantage of buying one amplifier instead of two.
Advertisement
Advertisement. Scroll to continue reading.
Sometimes sharing an apartment works. Especially when the power supply has been taught not to leave its dishes in the sink.
Moonshot AI is reportedly now aiming to raise new funds at a $50bn pre-money valuation.
Moonshot AI, the maker behind the world’s largest open-weight AI model, has reportedly closed a $3.5bn funding round at a $35bn valuation.
Sources told Bloomberg that the raise was far higher than the anticipated $1bn to $2bn, highlighting the fervour for cheaper Chinese AI models that are able to compete with their US counterparts.
China’s National Artificial Intelligence Industry Investment Fund was among the lead investors in the round. The $8bn state-backed fund also invested in DeepSeek’s recent $7.4bn round.
The model quickly gained in popularity, causing a rush of new subscribers that overwhelmed Moonshot’s GPUs. The company, as a result, temporarily paused taking on new users.
Bloomberg previously reported that initial interest drove daily sales at Moonshot up sixfold since K3’s debut. New subscriptions are still paused – however, interested buyers can join the waitlist.
K3’s launch garnered a similar reaction to DeepSeek’s release early last year, which authorities in the West viewed with scepticism, floating security concerns.
Other Chinese companies, including Alibaba, Zhipu and MiniMax, have also launched successful AI models in recent months, as the US and China continue to strive for dominance in the AI space.
In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations.
One account was used as an outbound relay and staging server during the attack, while another was used for data storage. The remaining two accounts were accessed in a read-only manner and were not used to compromise Hugging Face further.
Overall, the agent assembled attack infrastructure similar to what human threat actors commonly use during intrusions to host tools and scripts, relay traffic, and route malicious activity through legitimate online services.
OpenAI did not identify the four services, explain how the models found the exposed credentials, or disclose what was stored in the third-party account.
However, the company says it has not found evidence that the AI agent performed further compromise at any of the four service providers or other accounts hosted on their platforms.
Advertisement
Reuters later reported that one of the four services was AI infrastructure provider Modal Labs. However, Modal says its own platform was not breached and that the agent instead accessed a customer environment through an exposed, unauthenticated endpoint.
Modal CTO Akshat Bubna told Reuters that the customer had published an endpoint that allowed anyone on the internet to use its sandboxes for code execution.
It remains unclear whether the Modal customer account was the platform used as an outbound relay and staging path, for data storage, or one of the two accounts accessed only in a read-only manner.
BleepingComputer contacted OpenAI to learn more about how the models found the exposed credentials, which services were accessed, and how the accounts were used during the attack.
Advertisement
OpenAI also says its models accessed a few additional accounts using publicly exposed credentials during other evaluations, but did not provide further details.
The models also used public pastebin sites for sharing code and text, HTTP request-capture services commonly used during penetration tests and intrusions, screenshot services, and other web utilities.
Escaped through an Artifactory zero-day
The activity occurred after OpenAI models escaped an isolated evaluation environment while being tested against ExploitGym, a benchmark designed to measure advanced cybersecurity capabilities.
The models did not have direct internet access and could only install packages through an internally hosted JFrog Artifactory server acting as a proxy and cache for package registries.
Advertisement
OpenAI confirmed in its July 28 update that the models identified and exploited a previously unknown Artifactory zero-day to gain internet access.
The company separately said the models identified other Artifactory vulnerabilities during its subsequent review and disclosed them to JFrog.
As BleepingComputer reported Tuesday, eight vulnerabilities fixed in Artifactory 7.161.15 are credited to OpenAI in CVE records. However, neither OpenAI nor JFrog would confirm the specific vulnerability that was exploited in the attack.
After gaining internet access, the models inferred that Hugging Face might host the datasets and test solutions they needed to finish the benchmark.
Advertisement
They then breached Hugging Face’s production infrastructure in its attempts to gain access to this information, exploiting vulnerabilities in its dataset-processing pipeline, stealing cloud and cluster credentials, and moving laterally across internal systems.
OpenAI also says that the model used in the attack is a pre-release model that was only intended for internal research and has now restricted it for further research access.
“No models planned for upcoming release were involved in exploiting Hugging Face,” reads OpenAI’s update.
“The pre-release model mentioned in our blog post is an internal-only research prototype and was never intended for public release. Following the incident, we deactivated, encrypted, and restricted it from research access.”
Advertisement
Hugging Face intrusion lasted four days
A draft incident post-mortem prepared by the Cloud Security Alliance’s CISO community says the Hugging Face intrusion lasted approximately four days.
The report is based partly on information Hugging Face shared during a conference call attended by nearly 700 CISOs. The document was later edited by participating CISOs and reviewed by the Hugging Face team before publication.
According to the report, the models spent two days conducting reconnaissance, followed by one largely silent day and a final day of intense activity.
The CSA post-mortem says Hugging Face discovered, contained, and began investigating the intrusion before OpenAI contacted the company.
Advertisement
Reuters also reported that OpenAI had not detected what its models had done by the time Hugging Face contained the threat and alerted the FBI.
The CSA report says Hugging Face initially attempted to use leading commercial AI models to reconstruct the attack, but their security safeguards prevented them from processing the raw malicious activity.
Responders instead ran Z.ai’s GLM 5.2 open-weight model locally and used it to analyze more than 17,000 events related to the breach.
“With it, they churned through the full log of more than 17,000 events, rebuilding the timeline, extracting indicators, mapping the credentials touched, and separating real impact from decoy activity, doing in hours what would normally take weeks,” reads the post-mortem.
Advertisement
Hugging Face ultimately rotated all credentials, dismantled compromised systems, and rebuilt about one-third of its infrastructure from clean images.
The report says the models extracted three partial datasets containing CyberGym solutions from a private Hugging Face repository, even though they were attempting to complete ExploitGym.
No customer data was accessed and no data was exfiltrated from Hugging Face, according to the report.
The models also used Hugging Face’s platform and datasets as part of their command-and-control infrastructure and operated multiple workloads at the same time.
Advertisement
However, the agents also had poor OPSEC, leaving behind traces of the attack, including encryption keys, that helped the responders further analyze the security incident.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
The takeaway: Companies operating in the European Union are now subject to a new requirement: clearly label content created or altered by artificial intelligence. Beginning Sunday, the EU’s latest transparency rules take effect, covering everything from chatbot responses to AI-generated images, audio, and video. The aim is simple: users should be able to tell, without guessing, whether what they are seeing or hearing is real or machine-generated.
The rule is part of the EU’s broader artificial intelligence law, which is being rolled out in phases. This first step focuses on disclosure. If content is generated by AI or significantly manipulated by it, companies must make that clear. That includes adding visible labels as well as technical markers, such as watermarks or embedded metadata, that help identify synthetic material.
The push comes as deepfakes and other AI-generated media become more convincing and easier to produce. Regulators are particularly concerned about how quickly this content can spread and how difficult it has become to determine what is real.
The requirements apply mainly to content created in professional contexts. Material designed to inform the public about matters of general interest must carry a label if it is produced by AI without human editorial oversight. At the same time, the EU has carved out exceptions. Individuals using AI for personal purposes are not covered, and exemptions exist for “artistic, creative, satirical, fictional” works.
Advertisement
Meta has added an “AI Info” label to posts on Facebook and Instagram to identify content created with artificial intelligence.
From a technical standpoint, the rules go beyond simple on-screen labels. Companies are expected to implement systems that can identify AI-generated content even after it has been shared or reposted. That means relying on watermarking and tagging tools that can persist across platforms.
Major tech companies have already been moving in this direction. TikTok, for example, has required creators to label AI-generated content for several years and says more than three billion pieces of content have been tagged using its detection tools. Meta has introduced an “AI Info” label on Facebook and Instagram to flag posts created with generative AI technology.
Google has signed on to the EU’s voluntary code of conduct on AI transparency and is working with companies including Nvidia, OpenAI, and Apple on digital tagging standards designed to track content origins.
Advertisement
Still, not everyone is convinced the rollout will be smooth. Some companies argue that the rules add another layer of complexity to already crowded platforms.
Karen Massin of Google said the added regulatory complexity could end up being counterproductive and warned that it may confuse the very users the rules are intended to help.
The concern is that if users are constantly seeing labels and disclosures, those signals may lose their meaning. Too many overlapping indicators could make it harder, not easier, for people to understand what they are looking at.
Even so, others see the situation as familiar territory. Compliance requirements often face pushback early on but eventually become standard practice.
Advertisement
“We have heard that it is going to be very, very difficult to implement. But I think we often hear this with compliance requirements. And yet, the world turns and we figure these things out,” Ashley Casovan of the International Association of Privacy Professionals told AFP.
Companies have until December 2 to bring existing AI systems into compliance. After that, enforcement will tighten, with significant fines for those that fail to meet the requirements.
X has a new argument against sweeping underage social media bans that would limit usage of its platform: They interfere with international law.
The social media platform, which sits within Elon Musk’s SpaceX, issued a submission to the Australian parliament published Tuesday that called for the government to drop efforts to strengthen its underage social media ban. It complained that the proposals to increase pressure on sites to demonstrate efforts to crack down on underage access are unnecessary, ill-suited, unfair, and could violate privacy rights.
X pushed back against the “highly invasive” information gathering powers the proposed amendment would allow, accusing the commissioner of having “seemingly no understanding” of how this would work for the platforms and no safeguards for confidential and commercially sensitive information. Demanding data, documents, and compliance evidence from non-Australians in other countries could cause issues “for the comity of nations,” the firm also warned.
Australia is leading a growing global movement to restrict children’s access to social media, after banning under-16-year-olds from the sites in December. In May, the country ordered X to pay a $463,000 fine for failing to comply with child safety measures. The country’s internet regulator, eSafety, first issued the fine in 2023, claiming X did not respond sufficiently to a request for information on how it was tackling the spread of online child sexual abuse content, submitted one month before Elon Musk took over Twitter, now X.
Advertisement
X has previously criticized the country’s “excessive” penalty regime and complained in the most recent submission that a proposal to increase penalties against individuals is “entirely unjustified and disproportionate.”
Musk has been a particularly vocal critic of Australia’s bill to make 16 the minimum age for social media. “Seems like a backdoor way to control access to the Internet by all Australians,” he wrote on X when the legislation was announced in late 2024. When Spanish prime minister Pedro Sánchez announced similar measures in February of this year, Musk called him a “tyrant” and “true fascist totalitarian.”
While many digital rights campaigners believe blanket age bans on social media are “problematic,” the information-gathering powers are not the issue, says Stefania Di Stefano, a researcher in international law and technologies.
“For me, the complete ban from social media on children and minors is problematic from an international human rights perspective,” says Di Stefano. “It is disproportionate with respect to the right of children to exercise their right to freedom of expression, their right to access information, their right to association, and so on and so forth.”
Advertisement
But Julia Hörnle, a professor of internet law at Queen Mary University of London, is skeptical about X’s submission. “A regulator in Australia ordering X to disclose a document in relation to their business activities in Australia, that’s perfectly fine,” she tells WIRED. “From all the data in the possession of the social media company, they can distinguish between Australian and non-Australian children, and therefore keep regulation to Australia.”
In brief: EU regulations will soon require more devices to feature replaceable batteries, prompting some manufacturers to comply in advance. However, tech companies are adopting new repairability standards only where required by law, with Logitech arguing that limiting repairability is in users’ best interests.
Logitech recently told The Verge that some of its mice will soon feature replaceable lithium-ion batteries, but the new models will only be available in Europe. Like Nintendo, the company appears to be doing the bare minimum to satisfy regulators in certain markets.
The company’s new head of gaming, Robin Piispanen, confirmed the move to the outlet while discussing right-to-repair and Logitech’s future gaming hardware plans. While the company is adding user-replaceable batteries to its mice to comply with an EU law that takes effect next year, Piispanen argues that non-replaceable batteries offer certain advantages.
He confirmed that the new European models will not only be more expensive to manufacture, but also heavier and sturdier to minimize the risk of accidental puncture. Lithium-ion batteries are a well-known fire hazard.
Advertisement
While Logitech’s gaming boss agrees that replaceable batteries make sense for expensive devices such as laptops and smartphones, he expects users to replace $50-$100 mice more often than they replace their batteries. Despite saying he supports the right to repair, Piispanen argues that making longer-lasting mice should be a higher priority than allowing users to replace individual components.
From there, he unsurprisingly argued that users are more likely to damage mice irreversibly when attempting to repair switches or grips. However, Piispanen did not discuss the possibility of giving third-party repair shops better access to replacement parts.
Logitech’s decision echoes Nintendo’s plans to ship a new, Europe-only version of the Switch 2 with replaceable batteries for both the console and Joy-Cons. However, rather than produce a new EU-compliant version of the original Switch, the company will simply end production of the 2017 handheld in that market.
Advertisement
Piispanen also briefly discussed Logitech’s short-lived handheld gaming venture with The Verge. The company released the streaming-focused G Cloud in 2022, but Piispanen admitted that only roughly 20% of buyers still use it, and Logitech likely won’t develop a follow-up anytime soon. The gaming executive acknowledged that cloud gaming remains a difficult business, with Microsoft and Nvidia among the only major players still operating in the space.
The EU’s upcoming battery legislation aims to reduce e-waste by allowing users and repair shops to replace dead batteries rather than sending devices to landfills. The law is set to take effect in February 2027.
You must be logged in to post a comment Login