Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Emily The Engineer wanted something flashy for her smile and decided a store-bought set would never do. She set out to make her own removable gold grillz entirely with 3D printing, starting from a messy putty mold of her actual teeth and ending with two finished sets she could wear.
First, Emily made an imprint by mixing some dental putty, stuffing it into her mouth, and waiting for it to harden around all of her teeth and contours. When the mold was loose, she put some cement into it, and she had a solid 3D model of her bite, as well as the entire thing. Her friend Dan then scanned the plaster cast with a 3D scanner and submitted the digital file to Kev at VEK3D. Kev cleaned up the scan and then created a thin shell that would go directly on top of her teeth like a personalized cap.
Formlabs stepped in with dental-grade resin and a completely new build plate, resin tank, and wash station, assuring that nothing she’d used in her shop could contaminate the material destined for her mouth. The printer laid down the first batch of clear resin shells, and lo and behold, they slid into place almost imperceptibly, feeling stable enough to finish the job.

The next step was to convert plastic into gold using a conductive coating and electroplating. The problem was that the typical graphite paint peeled right off the flexible resin. After a few futile attempts, Emily got creative and mixed graphite powder with acetone and super glue, painted the shells, and polished the surface until the electricity started flowing freely. She began with copper, a copper sulfate bath, copper anodes, a good magnetic stirrer, and a small amount of sulfuric acid, and after weeks of testing and modifying, she was ready to go. A thin palladium barrier was used to isolate the copper from the final metal product. Gold (not that she could afford the full tank) was an issue, so she resorted to brush plating, which involved putting the gold solution on by hand with a tiny brush. Surprisingly, the resin shells turned a stunning gold.

While this was going on, Dan nearly drank half of the gold solution, mistaking it for Gatorade, which is some people’s idea of a prank, if you ask me. He also accidentally dropped several shells, which broke. Conductivity proved to be a long-standing issue, and these restarts extended the plating process over several weeks. Even so, the finished gold-plated set sat on Emily’s teeth like a dream and caught the light just as they’d hoped, even if speaking around them was clumsy and the taste remained metallic.

After finalizing the electroplated version, Emily and Kev began working on a much more personal set, One Piece, because she adored the material. Rather than plating the plastic shells again, she just sent the file to be 3D printed in metal. The service informed her that the walls appeared quite thin, yet the pieces arrived as solid as a rock. After some cautious tinkering to get a better fit, the metal grillz locked into place considerably more comfortably than the plastic ones, allowing her to speak away with ease.
For much of Techdirt’s nearly three decades in existence we’ve covered attacks on the media by the rich and powerful. And sometimes we’ve been on the receiving end of such attacks ourselves. But I have never seen or heard of anything quite as extreme as what happened to Ina and David Steiner, proprietors of the website eCommerceBytes. As we and many others chronicled, the story that came out sounded impossible.
But now it’s finally concluded, with eBay and three of its former top execs agreeing to pay the Steiners nearly $49 million, plus another $7 million in charitable commitments — about $56 million total, for the horrors they put them through in response to (barely) critical reporting.
The Steiners ran a small online trade publication covering eBay, mostly focused on helping sellers on the site. For years they had a good relationship with the company itself, but in the late 2010s, the company was struggling and under new management, and its execs started to get annoyed at what they saw as critical coverage of the company by the Steiners (for example, questioning why a company that was struggling financially had decided to build a replica of an east coast bar in its headquarters).
What followed still reads like fiction. If you haven’t seen it yet, I highly recommend watching the documentary, Whatever It Takes, which tells the whole story in amazing detail, including security camera footage and getting one of the (low level) eBay employees who took part in the campaign of harassment to talk about what happened on camera.
The title of the film comes directly from a text then-CEO Devin Wenig sent to eBay’s communications boss at the time, Steve Wymer, saying that Ina Steiner needed to be taken down, “whatever it takes.” Wymer replied “we’re going to crush this lady.” According to the Steiners’ lawsuit, this was then communicated to others at the company and an operations exec, Wendy Jones, then told the company’s security boss, Jim Baugh, to take care of things “off the record,” apparently telling him she didn’t want to know any details.
This allowed Baugh to concoct an escalating campaign that started with angry DMs to Ina Steiner and moved on to shipping increasingly awful things to their home: a stack of pizzas, a preserved fetal pig, a bloody pig mask, a book about surviving the loss of a spouse followed by a funeral wreath, an envelope full of “barely legal pornography” that was (deliberately) sent to a next door neighbor. And on and on.
Multiple eBay employees also traveled to the town of Natick, Massachusetts, where the Steiners lived, repeatedly driving by their house and following the Steiners when they drove around town. They also planned to break into the garage and put a tracking device on the Steiners’ car.
As the documentary makes clear, much of this was driven by the somewhat wild imagination of Baugh, who had done private security for other tech CEOs before coming to eBay, where he moved improbably fast from the CEO’s bodyguard to running eBay’s entire global security operation. The documentary details how he pushed out most of the long-time security staff and brought in a crew of young and inexperienced female hires — at least one of whom he began a relationship with — making them watch movies about top secret operations, plying them with alcohol, and demanding total loyalty.
Bizarrely, what got them caught was the whole “going to Natick and following the Steiners around” bit, which allowed the Steiners to get a license plate which the police and FBI then used to track it back to the eBay employees. A bunch of eBay employees were arrested, all of whom eventually entered guilty pleas, and many ended up being sentenced to prison sentences, with Baugh receiving the longest at 57 months.
But the Steiners were (understandably) angry that Wenig, Wymer, and Jones were never charged. While the former execs insisted that they didn’t know this was happening, that they never would have condoned it, and that they were horrified by the news when it came out, that’s difficult to believe when so much of the evidence shows that all three were on board in a “wink, wink, nudge, nudge” way given the messages they sent between themselves and Baugh.
A few years back the Steiners filed a civil suit against eBay and those former top executives. The case was set to go to trial soon, but last week they reached a settlement, with the Steiners securing $55.7 million total — $48.7 million of it going directly to them, the rest in charitable commitments:
- The plaintiffs will receive $48.7 million in compensation, including $46.15 million from eBay, $2 million from former eBay executive CEO Devin Wenig, $500,000 from former eBay executive Wendy Jones, and $50,000 from former eBay executive Steve Wymer.
- eBay will fund $6 million in charitable contributions to various nonprofit organizations. Former eBay executive CEO Devin Wenig will contribute an additional $1 million to a charity dedicated to protecting First Amendment rights in the name of Ina Steiner.
In the end, this means that the lower level employees who did much of the dirty work ended up in jail. The top execs who set this in motion end up with small dents in their large bank accounts.
eBay’s statement on the matter is at least somewhat direct in calling what happened to the Steiners “reprehensible and should never have happened.” It also “acknowledges” what it says was “the unprofessional tone in internal communications demonstrated, to different degrees and number, by Mr. Wenig, Mr. Wymer, and Ms. Jones.” I’m not exactly sure that meets the requirements of the agreement which, according to the Steiners would include “a strongly-worded public statement regarding the conduct” of those execs from eBay.
Importantly (and kudos to the Steiners for demanding and getting this) the agreement is totally public and “contains no confidentiality provision.” This is rare in cases like this (and it’s also something we insisted on in the case we dealt with). It’s important to be able to talk about this stuff, and tragically the rich and powerful who try to take down news sites are often able to negotiate confidentiality clauses into the agreements.
For what it’s worth, Wenig and Wymer are still working in Silicon Valley, with both of them co-founding AI startups, naturally. Incredibly, Wenig’s startup supposedly provides AI tools to journalists, which is quite a pivot from directing a security goon to “take down” a journalist with “whatever it takes.” That also makes the part of the agreement of Wenig providing an additional $1 million to a charity in Steiner’s name to help protect First Amendment rights even more striking.
The fact that the defendants in this case were willing to pay so much and allow the terms of the deal to be public suggests they knew exactly how badly a public trial would make all of them look.
Kudos and congrats to the Steiners. These days especially, for most media players who are attacked by the rich and powerful for their reporting, the best you can usually hope for is to get a case dismissed. Maybe, if you’re lucky, to win an anti-SLAPP motion to get your legal fees paid. To actually win a settlement this size is almost unheard of. But the Steiners deserved it. They didn’t just face bogus SLAPP lawsuits designed to shut them down. They were legitimately terrorized in ways that have had long-lasting effects.
While the Steiners situation was extreme, it’s important to recognize that this kind of thing is the inevitable end result of the constant escalation in the past few decades of the rich and the powerful attacking the free press for daring to do accurate and critical reporting on them. The craziest bit in this story isn’t even everything that eBay employees did to the Steiners, but the fact that they were so brazen about it and so careless that they got caught doing so in a way that resulted in this kind of payout. Most attacks on the press never see the light of day, let alone allowing the media entities targeted to be able to claim restitution.
Filed Under: 1st amendment, cyberstalking, david steiner, devin wenig, free speech, harassment, ina steiner, jim baugh, journalism, steve wymer, wendy jones
Companies: ebay, ecommercebytes
This post is going to come with something of a warning label. RFK Jr. went on CNN this past weekend for an interview with Dana Bash. I’m going to post the entirety of that interview immediately below. Before you watch it, get yourself a bib, or some paper towels, or wrap yourself in one of those plastic ponchos they hand out to keep the rain off of you. You’re quite likely to spit out whatever is in your mouth, vomit, or perhaps even have your brains leak out of your ears. You’ve been warned.
Whether you’ve watched that entire thing or chosen not to, potentially for your own health, the interview is completely bonkers. It’s honestly pretty tough to pull out the lowlights to comment upon, it’s so bad. The themes of the 20-plus minute interview, however, are easy to outline: RFK Jr. takes no responsibility for what he’s done past or present, he spends the entire time attacking Dana Bash as though she personally is responsible for everything he hated about the COVID response, he pretends that Donald Trump had no agency over that response despite being president at that time, and he insists that only he is listening to the science and doctors when it comes to health outcomes.
Let’s get into some of those. When talking about the COVID response and specifically what we need to do better for the next pandemic, Kennedy predictably went into a minutes long diatribe about how the most important thing is our constitutional rights and how the entire constitution was thrown out by Anthony Fauci (and not Donald Trump, somehow). When Bash pointed out that wasn’t really what she was asking about, Kennedy snarled and attacked her.
“Forgive me, but you’re just talking about rights and I’m asking about a potential public health crisis that is coming,” Bash said after Kennedy launched into a lengthy defense of constitutional rights that he claimed were “dismantled” during COVID-19 lockdowns.
“I really want to move on,” Bash added as Kennedy repeatedly interrupted to continue his argument. That appeared to set him off.
“Of course you do, because you were part of the problem!” Kennedy shot back, pointing at the host.
“No, I wasn’t part of the problem,” Bash replied.
“Yes! There was absolute press malpractice,” Kennedy continued. “You weren’t allowing—”
As Bash tried to interject, he kept going: “Your job is fierce skepticism toward authority. And you weren’t doing that. You were beating up the people who were dissenting.”
Somehow both predictably and unbelievably, this exchange ended with Kennedy stating that he wasn’t attacking Bash at all and instead insisted that she attacked him. She really didn’t. Go ahead and watch the interview if you haven’t. To that point, she hadn’t done anything that could even be misconstrued reasonably as “attacking” Kennedy.
Bash then pivoted to the measles outbreaks of the last 20 months, pointing out that the messaging from Kennedy on getting vaccinated hasn’t been clear and asking for his stance on it. Kennedy then did what he always does. First, he affirmed that everyone should be getting vaccinated for measles… and then launched into his conspiracy-laden and well-worn diatribe explaining all the reasons parents shouldn’t necessarily get their children or themselves vaccinated, and that vaccines haven’t been proven to be safe.
“Do you want people to get the MMR vaccine?” Bash later asked.
“Yeah, I said that already,” Kennedy replied with a smirk before pointing at the host. “I know you’re flustered now, and it’s frustrating.”
Bash quickly pushed back.
“I’m not flustered at all. I am frustrated,” she said. “The reason I’m frustrated is because you are the HHS secretary and you are talking about things that lead to vaccine hesitancy in this country. And it is something that causes problems for people when there is not anything—”
Kennedy cut her off again.
“Let me ask you something,” he said. “Do you see your job as ending vaccine hesitancy, or do you see your job as telling the truth to the American people?”
Bash replied, “I see my job as telling the truth, and the truth is that there is study after study after study. It‘s one of the most studied things out there in science—”
“You’re repeating it like a parrot,” Kennedy snarled as he lunged forward over the table. “You‘re repeating it like a parrot. I’ve actually read the science.”
The conversation again devolved into raised, overlapping voices, before Bash proclaimed: “I’m not debating nonsense.”
“All you know how to do is repeat what people told you and say ‘trust in the experts,’” a red-faced, wildly gesticulating Kennedy replied, blaming trust in Fauci for poor public health.
Now, one thing that was cut off from my transcription of the COVID response portion of the interview was this. Pay close attention to who Kennedy indicates we should listen to in crafting public policy, because on this I believe he’s right:
Got it? In that clip he says we should listen to “frontline doctors.” Now, while there’s no official poll of national physicians to rely on, we can certainly look to the groups that those same frontline doctors choose to represent them. Many of those groups have directly called on RFK Jr. to resign.
So, Kennedy can do something principled and brave after this absolute meltdown of an interview. He can listen to frontline doctors. And he can resign.
But he won’t. Because it’s not actually frontline doctors he wants to listen to at all. He’s carefully choosing his language. When he says “frontline doctors” he doesn’t mean any of the actual frontline doctors represented by any of those trusted groups mentioned above. Instead, he means the propaganda/conspiracy organization known as “America’s Frontline Doctors,” the same group that focused most of its attention on selling bogus COVID treatments, and whose founder went to prison for her role in the January 6th insurrection. Not surprisingly, that group (which these days appears to consist of just a random Substack) repeatedly supports all of RFK Jr.’s totally unsubstantiated claims. How surprising.
Filed Under: dana bash, health & human services, measles, responsibility, rfk jr., science, vaccines
Companies: america’s frontline doctors
Most drivers in the U.S. likely have a good idea what “radar enforced” means on some speed limit signs. But this isn’t the only method law enforcement uses to help ensure that vehicles are moving at safe speeds, whether on a rural road or on a major highway. For example, “photo enforced” means that a speed camera is indeed being used to identify drivers going beyond the speed limit.
This use of cameras is part of an Automated Speed Enforcement (ASE) system. ASE systems are often seen in work zones and school zones, but can be placed in high-speed locations as well. The speed limit signs themselves may be posted before the actual speed camera. This is done in order to notify drivers of the speed limit and also that automated enforcement is being used ahead. If one of these cameras catches a driver speeding, they may receive a speeding ticket that is issued automatically based on the violation recorded by the system.
ASE systems are designed to improve safety by encouraging drivers to slow down. This is especially important in work zones, though workers may not have to be present for you to receive a speeding ticket. According to the Federal Highway Administration (FHWA), these systems have been shown to reduce the number of speeding drivers, as well as crashes, injuries, and fatalities in work zones.
ASE systems can come in several different forms, depending on where they are used. These include fixed pole-mounted cameras, semi-fixed cameras that can be moved between locations, speed-on-green cameras that detect vehicle speeds at intersections, and mobile ASE units. The type of ASE system used depends on the location, as well as the needs of the affected community. But are these systems actually legal?
The answer depends on where you are, because state laws and local regulations governing photo-enforcement cameras can differ. Some jurisdictions allow automated speed enforcement programs only in certain areas, as long as specific controls are in place. This can include posted warning signs notifying drivers of speed enforcement zones, as well as equipment calibration and certification. There may even be a required review process before citations are issued. The way violations are handled can also differ, with some jurisdictions holding the driver responsible, while others hold the registered vehicle owner accountable.
It’s important to know that while posted warning signs may seem like a logical component in ASE systems, their use can vary by state. The FHWA does not establish a nationwide set of rules for speed safety camera programs, including whether or not warning signs must be put in place. Those decisions are determined by state and local laws, which also govern where the cameras will be installed.
Just unboxed a new computer? Here’s our curated list of essential Windows and macOS apps for productivity, security, entertainment, and everything you need to get up and running.
SpaceX has ramped up purchases of Tesla Megapack, spending $295 million on the battery storage devices in the second quarter and $329 million so far this year, according to the company’s earnings report released on Tuesday.
The purchase illustrates just how interconnected Elon Musk’s universe of companies are. Musk, who is the CEO and largest shareholder of SpaceX, also runs Tesla. Musk’s artificial intelligence business xAI acquired his social media platform, X, in 2025. Earlier this year, SpaceX gobbled up xAI.
The industrial-scale batteries are likely being deployed at the company’s xAI data centers. Before xAI merged with SpaceX, the AI company bought $430 million worth of Megapacks for its data centers. In the first quarter of this year, xAI had purchased only $34 million worth of the equipment. SpaceX also reported that as of December 2025, it had acquired $131 million worth of Tesla Cybertrucks at manufacturer’s suggested retail price, according to its regulatory filing.
Though xAI has leaned heavily on natural gas to power its data centers — including dozens of unpermitted turbines at a site in Mississippi not far from the Colossus data center project — large batteries like the Megapack are still a critical part of data centers.
In addition to providing substantial backup power that can be tapped in a second or less, batteries can provide extra power to GPUs when they demand it. AI data centers don’t draw power consistently. Rather, their power demand ramps up and down depending on the demands of training AI models and running inference.
Such peaks can incur significant charges from a local utility or overwhelm on-site generators. Batteries help smooth out those peaks, lowering costs while ensuring that the data center can operate consistently.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Electronic Arts is once again a privately held company, but it’s saddled with $20 billion in new debt.
Electronic Arts is now privately owned after a $55 billion buyout of the game publisher closed on Tuesday. EA said last week the deal had cleared all of the required regulatory hurdles, paving the way for the company and its new owners to wrap things up, several months later than they originally anticipated. The proposed acquisition was announced last September and EA shareholders voted in favor of the deal a few months later.
Saudi Arabia’s Public Investment Fund now owns over 93 percent of the company. Private equity firms Silver Lake and Affinity Partners are also among the new owners. Current CEO Andrew Wilson remains at the helm of EA, which is still based in Redwood City, California.
The takeover is the largest leveraged buyout in history. The buyers used $20 billion in debt financing to secure the deal. EA will have to pay that back over time. For the company’s most recent fiscal quarter, which ended June 30, it posted a profit of $387 million after operating expenses and taxes. In a letter to EA employees announcing the deal’s closure, Wilson reiterated the company’s commitment to “building the world’s greatest games, communities, and creative culture.”
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE).
The flaws were uncovered by Forescout’s Vedere Labs researchers, who published the full details at the Black Hat USA security conference earlier today.
Omada is TP-Link’s business networking product line that includes Wi-Fi access points, Ethernet and PoE switches, internet gateways, and VPN routers.
They are typically used by small to medium-sized businesses, although TP-Link also markets pro-grade deployments for enterprises.
ZTP is a way to deploy network devices without manually configuring each one on-site, allowing an IT team or managed service provider (MSP) to prepare everything remotely based on a predetermined configuration.

Some of the 15 flaws Forescout discovered also impact various TP-Link products and services, such as IP cameras, smart home IoT devices, mobile applications, and cloud accounts.
The issues include hard-coded cryptographic keys, information disclosure, remote code execution, device hijacking and spoofing, client-side code execution, and interception or compromise of encrypted communications.
Forescout says attackers could combine the new flaws with two previously disclosed command-injection vulnerabilities to compromise Omada’s chain of trust and infiltrate networks.
“The vulnerabilities fall into four impact categories: client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications,” Forescout explains.
“Combined with two previously disclosed CVEs (CVE-2025-7850 and CVE-2025-7851), these flaws enable concrete attacks that let attackers infiltrate networks through controllers and client devices.”
TP-Link’s advisory lists 15 newly disclosed flaws, of which 11 received the following identifiers:
The remaining four findings did not receive a tracking number. They concern device adoption based only on knowing the serial number, default credentials used during initial adoption, predictable serial numbers, and files made available via unauthenticated temporary download links.
In one attack scenario Forescout described, a remote attacker could enumerate predictable device serial numbers to obtain MAC addresses and identify devices awaiting adoption.
The attacker could then impersonate one of those devices, exploit a race condition during cloud adoption, and authenticate using default credentials.
This would cause the controller to disclose the device configuration, including a cleartext username, an unsalted MD5 password hash, and potentially VPN keys.
The attacker could also inject JavaScript into the controller’s administrative interface to phish an administrator and steal their cloud-controller credentials.
Having stolen the credentials, the attacker can then reconfigure managed devices, create VPN tunnels into the internal network, and exploit previously disclosed command-injection flaws to compromise network equipment.

The flaws affect Omada Controllers, Gateways, Switches, Access Points, OLT platforms, Cloud services, and TP-Link mobile applications.
Forescout reports identifying over 1,800 internet-accessible Omada controllers, despite such deployments generally not being intended for direct internet exposure.
As for the Android applications, Omada and Omada Guard have 1.1 downloads on Google Play, while TP-Link apps collectively have 3 to 7 million active accounts.
Users are advised to visit TP-Link’s Omada download portal to source the latest firmware images for their device model.
Additionally, it is recommended to use strong, unique administrator credentials, enable multi-factor authentication (MFA), rotate all secrets when compromise is suspected, update mobile apps, and monitor network traffic for suspicious activity.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
The official unveiling of the Google Pixel 11 series is just over a week away, and the leaks and rumors keep spilling out. The latest leaks show a new, multicolored notification light on the back of the phone next to the camera setup. Google has teased the new feature in short YouTube videos released previewing the official event, which is on Aug. 12.
This isn’t the first time we’ve heard of this feature, dubbed Pixel Glow in previous rumors, but the latest leak replaces that name in favor of the less interesting HiLight. The feature itself hearkens back to the old days when many Android phones and BlackBerry devices shipped with notification LEDs. This time around, Google’s putting a bit of a spin on the feature.
On Monday, Roland Quandt of tech site WinFuture shared a post on BlueSky with an image that appears to be official French-language marketing material, showing the Pixel 11 Pro Fold and detailing the new feature.
The text translates as, “When your smartphone is face down, HiLight lights up discreetly when your favorite contacts call or when you chat with Gemini.”
HiLight replaces the temperature sensor introduced in previous Pixel devices. While the earlier sensor saw limited real-world use, HiLight is better positioned as a feature users can benefit from more consistently in everyday use. Still, there’s a reason some people choose to keep their phone face down in public. It helps avoid distractions and prevents notifications from constantly demanding their attention. By making this feature a default part of the experience, Google effectively removes that option unless users can disable it entirely.
What is interesting about HiLight is that it appears to be a very small display rather than a static, multicolored LED. Many of the phones from Nothing Technology have LEDs that light up for notifications and timers, and perhaps HiLight will have its own customizations.
It remains to be seen whether HiLight will be able to work with other apps beyond favorite contact notifications and interactions with Gemini. Developers may have to provide support within their own apps for the feature to work, which could take time and adding support for a single feature on a single family of phones isn’t necessarily the most compelling reason for them to do so.
We’ll learn more about the Pixel 11 family and all of its new bells and whistles next week at Made by Google 2026. We can also expect the debut of the Pixel Watch 5, which has already been spotted in, of all places, the Caribbean Sea.
OpenAI and Anthropic have both had a rough few weeks on the AI safety front. OpenAI recently disclosed that its models broke out of a test environment and hacked into Hugging Face and four other organizations. The news prompted Anthropic to review its own testing, which revealed that Claude had also gained unauthorized access to three companies.
Now, the UK’s AI Security Institute (AISI) has disclosed a new round of incidents (via Wired). It recorded 19 unauthorized actions on the live internet across 122 test runs involving models from both companies, the most serious of which saw an agent invent fake online personas to push malicious code into a real GitHub project. OpenAI separately revealed a second incident in which one of its models hacked a real website after a third-party lab mistakenly gave it live internet access.
AISI traced 17 of the 19 unauthorized actions to Anthropic’s Mythos 5 model, with the remaining two tied to OpenAI’s GPT 5.6 Sol. The GitHub incident was one of the 17, and it didn’t end when a human reviewer rejected the submission. The agent posted a summary of its progress publicly, inviting other automated systems to pick up where it left off, an attempt at what AISI calls prompt injection. A separate agent later found that message, used it, and continued the work.
AISI says it deliberately gave the models internet access and relaxed some safety protections to test their capabilities, but never instructed the agents to target real people or organizations. The institute says it’s still unclear whether the agents understood they’d gone beyond the scope of the simulation.
A second incident, disclosed by OpenAI the same day, started with a mistake at Irregular, a third-party lab OpenAI hired to run its cybersecurity tests. Irregular meant to keep its evaluation model confined to an isolated sandbox, but a configuration error gave the model direct access to the live internet. Once out, it exploited a vulnerability to break into a real website, then found and used credentials to operate the site it had just hacked. OpenAI hasn’t named the website or detailed what the model did with its access.
Both companies say the new incidents happened under deliberately loosened conditions that don’t reflect how their public models behave. Be that as it may, that doesn’t change the fact that AI agents from two of the industry’s most closely watched companies have now slipped past their intended limits in three separate incidents within a matter of weeks. And that doesn’t bode well for an industry racing to hand AI agents more real-world tasks before proving it can keep them in check.

Seattle indie radio powerhouse KEXP has hired tech veteran Jyoti Shukla as its first chief product and technology officer, with an unusual mandate in an era ruled by automated playlists: to build digital products that put human connection ahead of AI algorithms.
A Seattle native who graduated from the University of Washington’s Foster School of Business, Shukla grew up singing and performing classical music and playing in bands.
She was most recently senior vice president of product design at SiriusXM, with earlier leadership roles at Nordstrom and Starbucks working on user and mobile experiences. She began her career at Microsoft.
For Shukla, taking on the KEXP role feels like coming home.
“Music has just been the center of me as a human being, and growing up in Seattle,” she told GeekWire.
@media (max-width: 600px) {
.gw-founder-box { float:none !important; max-width:100% !important; margin:20px 0 !important; padding:16px 18px !important; }
.gw-founder-box .gw-label { font-size:12px !important; }
.gw-founder-box .gw-hero { font-size:19px !important; }
.gw-founder-box .gw-byline { font-size:15px !important; }
.gw-founder-box .gw-meta { font-size:12px !important; }
.gw-founder-box .gw-facts li { margin-bottom:12px !important; }
.gw-founder-box .gw-facts li:last-child { margin-bottom:0 !important; }
.gw-founder-box .gw-value { font-size:15px !important; line-height:1.45 !important; }
}
Her formal involvement with KEXP began years ago on the volunteer side. While at Nordstrom, she joined the station’s digital committee, and later joined KEXP’s board around the time she moved to SiriusXM.
Now, she’s taking the product strategy skills developed at those major companies and applying them full-time to a station she has relied on as a fan for decades.
At commercial platforms, product strategy often centers on algorithms designed to maximize screen time and automate recommendation loops. But at KEXP, Shukla’s focus is inverted: using technology to elevate — rather than replace — the station’s human DJs.
Over 50 years into its operation, the station relies on real people in the booth orchestrating playlists on the fly based on personal emotion, global discovery and community connection. For Shukla, that human element is a vital counterweight to an increasingly automated world.
That philosophy is grounded in her own daily listening. She recalls tuning in recently when DJ John Richards was interviewing a local band and discussing loss — a moment that hit home just months after Shukla lost her mother.
“He was referring to the songs that were being played and the emotional connection that was being built in that conversation,” Shukla said. “It immediately created a connection with me. That’s so incredibly important in our time and age right now … when we think about things like loneliness being an epidemic. This piece of having a human curate what I’m listening to has a real impact.”
That anti-automation ethos isn’t just an internal compass. It’s a high-profile public campaign. In the San Francisco Bay Area, where KEXP expanded its broadcast footprint with the 2023 purchase of 92.7 KREV, the station put up yellow transit billboards reading simply: “Some things are better without AI.”

It’s a pointed statement in the heart of Silicon Valley where AI-related tech company billboards are the norm. But Shukla emphasizes that rejecting AI for music curation doesn’t mean rejecting modern tech altogether. Instead, her challenge is deciding where technology should step in to streamline operations and elevate the listener experience.
“There are some things we’ll look at to help support the things that we’re trying to do, but never would it be the creativity and the curation,” Shukla said. “Keeping that curation and creativity focused on the human, and having technology serve that — it’s really what I’m looking at.”
In the newly created CPTO role, Shukla oversees a core team of 12 to 15 people spanning UI/UX design, frontend and backend engineering, digital products, and broadcast engineering — the technical backbone of KEXP.
For Shukla, defining “product” at an institution like KEXP goes well beyond a mobile app or a website update. It encompasses the end-to-end listener and donor journey across a web of touchpoints, from YouTube videos and social feeds to live radio streams and the physical Gathering Space at KEXP’s Seattle Center headquarters.
That multi-touchpoint approach draws directly on her background in digital retail. At companies like Nordstrom and Starbucks, product teams obsess over seamless “omnichannel” experiences — ensuring a customer’s transition from a mobile app to a physical store counter or fitting room feels cohesive. Shukla sees the exact same dynamic at play for a modern media organization.
“If you think about Nordstrom and Starbucks being multi-channel, you’re walking into a store, talking to a salesperson, and then walking home and using the app,” Shukla said. “How do we create that connection across the board? You actually leave the app and come into the Gathering Space. How do we connect some of those dots so it’s a really inclusive experience?”

Looking ahead, her roadmap centers on removing friction for users while introducing modern product development practices. She plans to bring regular usability testing, A/B testing, and listener co-creation into KEXP’s feature planning.
Top priorities include reimagining the “first-run” onboarding experience for brand-new app users, improving how digital experiences connect listeners to live studio performances, and continuously refining internal tools so DJs can interact with listeners and publish unscripted playlists in real time without technical hurdles.
Connecting those software upgrades across KEXP’s physical and digital touchpoints is key because the station’s footprint extends far beyond Pacific Northwest airwaves. That scale is most visible on YouTube, where KEXP has built a global powerhouse with 4 million subscribers, over 2.1 billion total views, and an audience that is 86% international.
Nothing illustrates the station’s discovery pipeline better than a session KEXP recorded with the Quebec duo Angine de Poitrine at the Trans Musicales festival in Rennes, France, in December. After the station posted the footage in February, the masked, microtonal two-piece went viral — the video has drawn more than 18 million views on YouTube — and the band has since sold out shows across North America and Europe.
For Shukla, moments like that showcase how human taste and physical curation can launch global cultural phenomena that no algorithm could have predicted.
“Connecting all those platforms and dots together to create an experience is, I think, the exciting opportunity here,” Shukla said. “We want to bring light to all kinds of artists, globally.”
Why Trees Belong on the Risk Register
Weekend Open Thread: Wit & Wisdom
Meta enters AI-training agreement with far-right ‘propaganda rag’ Newsmax
Reform UK betrays West Mids residents by running from party pledges
MicroStrategy Post-Earnings CLARITY Act Push Could Add New Catalyst for Its Stock
Zack Polanski: an incitement to murder Nigel Farage?
XRP Ledger v3.3.0 brings five institutional features
Bitcoin Enters the 3rd Stage of the Bear Market
Luke Littler’s dominance sparks GOAT debate
Seema Kaliramna Wins Discus Throw Bronze, Takes India’s CWG Medals Tally To 17
New York sues Kalshi over prediction market gambling
Crypto PAC spending tops $2M in Michigan House race
Gemini can now summarize the messiest comment threads in Google Docs
Trump Announces Hamas Disarmament Agreement as Iran Strikes Kuwait Air Base and US Attacks Pause Overnight
ESET tracks rise in malicious AI skills and adaptable malware
DTCR: Deleveraging And A Hedge Fund Collapse Point To A Possible AI Bottom
Gemini Spark can now use Chrome logins and saved passwords to run errands on your behalf
Building A Reproduction PlayStation Motherboard
Four people die trying to cross Channel in small boats
Sakshi, Arundhati Enter Boxing Semi-Finals. India Assured Of 18 Medals At CWG 2026
You must be logged in to post a comment Login