Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network.
The attack was discovered by Huntress on July 27, 2026, after its security platform detected credential theft on a server hosting an Oracle database server.
Apache access logs showed that the attackers gained access through a vulnerable search engine endpoint in a public-facing Java application running Apache Tomcat.
The application failed to properly validate input submitted through an autocomplete search feature that allowed the attackers to issue SQL commands to the Oracle database.
Huntress traced the malicious requests to the IP address 178.162.151[.]229.
After exploiting the SQL injection flaw, the attackers installed a post-exploitation toolkit called khunt directly into the Oracle database as a Java object.
Oracle has an embedded Java Virtual Machine and the CREATE JAVA SOURCE statement, which allows Java source code to be stored and compiled as a database schema object.
These Java objects can then be executed via SQL commands, which if configured to do so, can execute commands on the host operating system.
The attackers abused this functionality to compile and store the khunt toolkit directly inside the Oracle database rather than deploying them as executable files on the server.
“The use of the technique in the wild has rarely been documented,” Huntress said.
The toolkit contained multiple Java components and PL/SQL wrappers that could execute commands, steal credentials, and manage files.
These components included:
The attackers used KhuntCmd to run cmd.exe /c whoami, confirming that commands executed through the Oracle database had SYSTEM-level permissions on the Windows server.
They then used PowerShell and Windows utilities to copy the SAM, SECURITY, and SYSTEM registry hives, which can be used to recover password hashes for local Windows accounts.
The attackers also ran tasklist /svc to enumerate running services and saved the output to khunttasks.txt.
Huntress said the registry hives were likely exfiltrated for credential dumping, but the report does not confirm whether the files were successfully stolen.
As a general rule, organizations should sanitize all user supplied input validation and limit the privileges granted to application database accounts.
Huntress recommends that database accounts used in public-facing applications should not have high enough privileges to create Java sources, execute unnecessary stored procedures, or perform other administrative actions.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
The Justice Department’s Civil Rights Division announced on Wednesday that OpenAI, and its once-subsidiary Statsig, signed a settlement that includes three years of oversight over the AI lab’s hiring practices.
The DOJ has alleged that these companies used various tactics to prevent U.S. citizens from applying for jobs held by immigrant employees when the companies were sponsoring those workers for permanent U.S. residence. The companies did not admit to wrongdoing, although they did agree to pay $3.2 million. Of that, $1.2 million is a fine and the remaining $2 million is being set aside to pay restitution to U.S. citizens who applied to those jobs, should the DOJ find any who were harmed.
The DOJ alleged that OpenAI and Statsig broke provisions of the Immigration and Nationality Act (INA) by not truly looking for qualified U.S. citizens for these jobs before pursuing permanent residence applications (PERM) as the INA requires. The DOJ said they didn’t list roles on public job boards, advertised on the radio late at night, and required paper applications rather than electronic ones.
While there were fewer than 10 roles at issue, the DOJ said that as part of the settlement, the companies must pay the fine and submit to oversight by the department over their PERM roles. Oversight includes items such as drafting and obtaining approval for their PERM-role hiring policies and submitting semiannual reports. Those reports must include how many applications for foreign employees they pursued, how many U.S. citizens they interviewed, and other statistics.
OpenAI acquired AI A/B testing company Statsig in September 2025 and later divested at least part of the business in May 2026. The DOJ, however, says it began investigating both companies separately before the acquisition, in August 2025, including five cases at OpenAI between 2023 and 2025, and one at Statsig.
The DOJ says that this settlement is part of its increased crackdown on companies over the matter. However, the INA, a law passed in 1952, has been enforced by other administrations against other Big Tech companies. During Biden’s administration, for instance, both Facebook and Apple signed similar settlements, though in both of those cases the DOJ alleged that the violations were widespread and systematic.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
WhatsApp already lets channel admins mark sponsored posts with a paid partnership label, a feature that started rolling out last month on Android and iOS. Now the app is cooking up something similar, but this time for AI-generated media. The idea is to keep followers in the loop when a photo or video wasn’t captured with a camera but conjured up by an AI tool instead.
WaBetaInfo spotted this feature brewing inside the WhatsApp beta for Android, version 2.26.31.1, currently available on the Google Play Store. Once it goes live, admins will be able to tap and hold an update containing AI-generated media to bring up the context menu, where a new “Add AI content label” option will appear.

Tap it, and a visible tag gets attached to the message bubble so followers instantly know they’re looking at AI-made content. Once the label is added, admins likely won’t be able to remove it, so it pays to double-check before hitting share.
Not everything needs the tag, though. Plain text messages, even ones drafted using WhatsApp’s own Writing Help tool, seem to be exempt from this rule.
Turns out, it’s not just about being a good digital citizen. Several countries now have laws that require apps to disclose AI-generated media, and this label gives admins a simple way to stay compliant without extra hassle. Best of all, it doesn’t play favorites. Whether you made your image using Meta AI, ChatGPT, Gemini, or literally any other tool, the label applies the same way.

For now, this feature is still baking in the Android beta, and testers don’t have access to it just yet. WhatsApp is also working on bringing the same label to iOS, so it won’t stay an Android exclusive for long. There’s no word yet on a public rollout date, but we’ll keep an eye on it.
We may receive a commission on purchases made from links.
Costco isn’t just good for bulk groceries, $1.50 hot dogs, and 48-packs of toilet paper. The retail outlet also has a surprisingly robust electronics selection, with everything from smartphones to TVs available at your local warehouse, and it’s always adding cool new electronics to its shelves too. What’s more, many of them are usually more affordable than they would be from other retailers. But while the sticker prices in the store are already pretty reasonable most of the time, true bargain hunters know that the company often has steep sales that let you get products at a significant discount.
These sales change all the time, so it pays to keep an eye on what items Costco has on sale each month. There are plenty of great deals happening across the store, but some offers are significantly better than others. This month, for instance, there are a few great deals on speakers and other handy gadgets to upgrade your smart home. With that in mind, some of you may be interested in checking out the electronics Costco has on deep discount this August.
A complete home security system can be expensive, so it’s always good when you can find a decent one on sale. Right now, Costco has an Arlo Ultra bundle, usually $449.99, on sale for $349.99. This deal actually started in late July, but it will continue till August 16.
This kit comes with three of Arlo’s third-gen HDR 4K outdoor smart cameras. Each has a 180-degree field of view with motion detection, auto-zoom, color night vision, and tracking. You also get a magnetic mount for easy adjustment, a built-in siren and spotlight for warding off intruders, a swappable and rechargeable battery, and a low-power mode that keeps them active as snapshot cameras even when the battery is too depleted for video. Like most smart cameras, these have two-way audio with wind- and noise-canceling.
The kit also includes the company’s Ultra SmartHub. The hub creates a dedicated network for the cameras that operates on its own frequency, which Arlo claims reduces interference, increases range, and improves performance. It also comes with a free one-month trial of Arlo’s Early Warning System subscription. The Arlo Ultra Camera system has a 3.9 out of five-star rating on Costco’s website from over 45 customers. Most have had positive things to say about the camera’s picture quality, but some have encountered issues getting the batteries to charge correctly, while others have struggled with the initial software setup.
Bose is well known as a high-end speaker and headset manufacturer. It’s known as a Bluetooth speaker brand that offers great sound quality, but its products tend to run on the expensive side, so it’s always nice when you can get them at a discount. Costco currently has the Bose SoundLink Home Bluetooth Speaker on sale for $50 off until August 23, bringing the price down from $179.99 to $129.99. This sale applies to all three colors, namely Cool Gray, Warm Wood, and Light Silver.
The SoundLink Home is a battery-powered Bluetooth 5.3 wireless speaker that promises up to nine hours of battery life. They have a built-in microphone as well, so you can use one to make calls or to access your phone’s voice assistant. Another cool feature about these speakers is that you can synchronize two units and run them in stereo, giving you separate left and right channels. This Bose speaker has a sleek anodized aluminum shell and a fabric front, and the company claims that it’ll deliver “crisp, clear sound with deep bass.”
These speakers only have a single rating on the Costco site, but they have 4.6 out of five stars on Bose’s own site, with most praising the sound, features, and modern design. There are a few scattered complaints about the device looking a bit awkward when the charging cord is plugged in, but most generally seem happy with its overall performance.
Bose isn’t just known for its wireless speakers; the company also makes some pretty great earbuds. Another Bose product Costco currently has on sale are the Bose Ultra Open-Ear true wireless earbuds. These little guys usually cost $299.99, but Costco currently has them for $199.99. What’s more, these earbuds come with a $50.00 gift card you can redeem on the Bose Promotion website. Special discounts like this are one of the reasons premium headphones are one of the main types of electronics you should try to buy at Costco. This sale won’t last long, however, as it ends on August 9.
These earbuds have an open-ear design, letting you listen to music without blocking off the outside world. This makes them ideal for those who like to use earbuds during outdoor activities like jogging, where you need to be aware of your surroundings. They’re IPX4 water-resistant, have a built-in microphone, and promise up to seven hours of battery life. The buds come with a charging case and a USB-C cable.
The Bose Ultra Open-Ear True Wireless Earbuds have a 3.9 rating on Costco’s website from over 175 ratings. The vast majority of users found them to have excellent sound quality for music, but some were less than pleased with the quality of voice calls. Customers were also divided on how comfortably they fit on the ear.
JBL is another popular speaker brand that’s particularly well known for its portable Bluetooth speakers. Most of these are small speakers that you can fit in a pocket or backpack, but there are some notable exceptions. One example is the JBL PartyBox 120, a massive 22.4 x 11.7-inch Bluetooth speaker designed for parties and get-togethers. It usually runs you $449.99, but it’s on sale at Costco for $349.99 until August 16.
This speaker’s party-focused marketing extends beyond its large size. It has dual mic and guitar inputs and comes with a wireless mic, so it’s ready for live performances or karaoke. The speaker has an array of light effects that will sync with and react to the music you’re playing. JBL also advertises an AI sound boost feature that analyzes the music and maximizes speaker output for better sound. It’s also splash-proof, can be synced with other speakers via Auracast, and promises up to 12 hours of battery life.
This one has a 4.5 out of five-star rating on the Costco site, with fans generally praising its loud sound, heavy bass, and healthy selection of features. The relatively few negative reviews it has are primarily related to shipping and packaging errors, and don’t indicate any consistent design flaws with the product itself.
It’s rather awkward when you buy a piece of hardware like a sketchy router to make a video about its hidden admin password backdoor – known as CVE-2026-11405 – only to discover that you bought the wrong Tenda router, namely the AC10V6 model. After making this mistake, [Low Level] did the only reasonable thing one ought to do in this case, and try to find an exploit in this ‘wrong’ router as well.
The obvious start here is to do the same as with the other exploit, in that you download a firmware image from the manufacturer’s website, then pluck it apart using binwalk to do an initial check for juicy files. After that tools like Ghidra can be used to do a more in-depth analysis of any binary files, with a special focus on things like user-facing elements like login screen, as input validation will likely forever remain the number one type of exploited CVE.
One major change that Tenda made here was to encrypt the firmware image, which seemed suspicious. With that easy path blocked, the research of others on different Tenda routers was looked at, including the AC20 with the fascinating Telnet exploit in the form of CVE-2025-9090 where merely poking a file on the device turned on the Telnet service. This left the minor issue of finding a password to log into said Telnet session.

This is where CVE-2025-52054 comes in handy, as this explains how to calculate the root password of a Tenda router using a static string and the last two octets of the device’s MAC address. The unfortunate aspect here is that this static string is unknown for this particular router, and the AC8 version did not work. Luckily, for some unknown reason Tenda did decide that they had to print this secret information to the serial output, ergo it was time to probe the UART pins on the router’s guts.
One hard reset later and the console output on these UART pins happily showed that the password pre-Base64 encoding was 9cUFeUZC_125700. Mashing in the Base64-encoded string in the Telnet login gave root access and completed the first step of the whole fun, as now [Low Level] also had access to the decrypted firmware including the decryption keys for the previously safely encrypted firmware image.
There will be a blog post published with likely the keys and other details after clearing it with [Low Level]’s lawyer, but even at this point it’s truly a tragedy of CVEs on the side of Tenda that led to this outcome. If you ever needed a reason not to let friends use Tenda routers, this has got to be another good reason.
Meta, considered a bit of a straggler in the AI harnesses realm, is making strides to catch up. This week, the company released a new terminal coding agent aimed at programmers looking for assistance with complex tasks across large software code bases.
Muse Code, which is currently available in beta, can accomplish “complete software engineering tasks across large repos,” Meta CEO Mark Zuckerberg said in a social media post on Wednesday. Those tasks include “planning changes, writing code, validating the results,” he added.
Code, which can be installed with a single command, is powered by Meta’s previously released coding model, Muse Spark. It handles large projects by launching its own agents, which then work simultaneously.
“When a job is big enough, it fans out to separate sub-agents working in parallel in isolated worktrees,” Zuckerberg explained. “Your working copy is never touched. In testing we had it build six features for a game simultaneously with no collisions.”
The move attempts to position Meta more competitively, and more affordably, with AI lab peers like OpenAI and its coding agent Codex, and Anthropic with Claude Code.
“We think that for a lot of workflows and a lot of use cases, this can be an incredibly good option, especially from a cost perspective,” Alexandr Wang, Meta’s AI chief who leads Meta Superintelligence Labs, told the Wall Street Journal.
Meta has been attempting to grow its AI presence by pouring money into development. In June, it expanded beyond its core focus of using AI to support its advertising business and entered the enterprise AI market with an agent aimed at customer service and support.
Let’s cut to the chase: Starting today, you can take an additional $100 off of our current $300 discount for your founder, investor, or attendee TechCrunch Disrupt 2026 pass, which is a nice bonus on top of our current discounted pricing.
This flash sale will run all week, up until Friday, August 7 at 11:59 p.m. PT. This discount will mark your last chance at a bonus deal before our next pricing tier kicks in on August 21.
Register with this link to lock in your extra $100 off.
If you need to learn more before locking in your plans, Disrupt takes over Moscone West from October 13–15, bringing more than 10,000 founders, VCs, tech industry innovators, and builders for three days built around one thing: creating momentum for future success.
This isn’t a passive conference you simply watch — it’s a curated itinerary of speakers, workshops, network opportunities and post-event excitement for those actively building, investing, and looking for what’s next.
The Disrupt Stage is our flagship programming, and we just revealed the initial lineup. We’ll dig into the biggest shifts in tech right now, whether it’s a post-smartphone future with Amazon’s SVP of Devices and Services Panos Panay; the real implications of a world in which everyone can develop their own software, with Replit founder and CEO Amjad Masad; and much, much more.
But that’s just one stage. Disrupt 2026 also features the:
AI Stage, covering the security gaps and business model shifts AI is forcing on every SaaS company.
New Smart Money Stage, tackling stablecoins, instant payments, and AI’s role in financial trust.
New Smart Systems Stage, with a perspective on fusion breakthroughs and grid strain powering AI’s next decade.
Builders Stage, the long-standing favorite stage where founders and investors get tactical about raising, hiring, and scaling.

Most Disrupt passes also unlock Startup Battlefield, where 200 startups will compete live for the Battlefield Cup. You’ll also get access to networking opportunities driven by your needs as a founder, investor, or learner, plus our Expo Hall, where hundreds of startups showcase their work.
After 11:59 p.m. PT on Friday, August 7, this extra $100 savings goes away. Regular discounted pricing ends on August 21. If Disrupt is on your radar for this year, this is the best deal you’ll get between now and the event.
Save an extra $100 before Friday.
We’ll see you October 13–15 at Moscone West in San Francisco!
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
No, your Uber payment method didn’t expire, it’s just a scam attempting to steal your payment information. Here’s how to spot such scams.
Email is a ubiquitous tool that everyone needs for basic web access and account creation. While some tools like Hide My Email attempt to reduce spam, they aren’t foolproof.
Users across social media and some staff at AppleInsider have received a bogus email claiming to be Uber. While there are many red flags that suggest the email is a fake at first glance, not everyone is going to have the skills to recognize that.
Before I get into how this specific email was a clear fake, there is one simple universal rule that will always help you with such scams:
Never click on a link in an email or text message that offers to take you to a web portal or app. Instead, navigate to the app or website manually and log in to see if there are any errors or notifications there.
Emails often use images as links to obfuscate the URL, and even when examining the URL, it is easy to use similar Unicode characters to simulate a real address. Even the most discerning person can get fooled by an “l” versus an “I.”
Avoid the problem and go to the website or app yourself. It’s that simple.
If you look at a lot of email, you’re probably an accidental expert in spotting fake ones. The slightest change in format can signal you’re not dealing with the actual entity.
For example, while I’m not an Uber customer and don’t get notices from them, I can tell at a glance that this email is strange. It lacked any kind of branding, the font and choice of font size seemed odd, and the email sender was ridiculous.
I got Uber to send me an email by attempting to sign into an account and saw what its format actually looks like. See how it has a branded logo, a footer, a contact icon, and an address belonging to uber.com, and some standard imagery.
Some emails will be verified via Apple’s email backend and get a checkmark, while others will have a contact image shared by the address. Emails can’t spoof that verification check.
Now, not every legitimate email will have a verification check or a contact image. Even many of Apple’s emails, like from Apple News, don’t have a verified address. I do see a verified checkmark by Affirm emails, but not from my bank.
Remember, these are good indicators, but don’t always guarantee legitimacy.
Another red flag is the “From” slot is named “UBER” in all caps. The subject line also lacked any clear address to the user by name or account number.
The email itself is oddly formatted. The title and subhead are an odd size and centered, then there’s a ticket number, but no mention of the user’s name or account number.
A prominent warning is shown in a callout, then “Manage Bill Settings” is shown in an odd gray button format. The second callout about staying safe is an attempt to make users believe this is legitimate, because the scammer is counting on you simply clicking the button.
Beyond the many red flags in the design and layout of the email, there are some very obvious and simple indicators that this is fake. I’ve saved these for last because they’re so blatant, but it is helpful to understand the other aspects as well.
Not every scam email will be so easy to spot
Note the icon used for an account confirmation versus from a mailing list with the separate Affirm emails
So, select the “UBER” name in the “From” section at the top to reveal the email address. It’s from “[email protected]” which is not uber.com in any shape or form.
Another clear indicator is the “To” field addressed to over 100 users. I’ve excluded this from the example image, but it was there in our staff’s email.
An alert about an account issue isn’t going to be bulk sent to dozens of users at once. That means every user got the same email, same fake ticket number, and apparent account issue.
It also means Uber would be revealing every user’s email address to the others. It’s just not going to happen.
A little bit of media and internet literacy can go a long way. Spotting scam emails isn’t always simple, but fonts, layouts, addresses, and imagery are often easy to spot as an issue when evaluating an email for legitimacy.
It isn’t so much that you have to take the time to do this for every email, but that anything claiming to be attached to your finances or account access needs extra scrutiny. As I said earlier, the most fail-safe option is to never open a link sent via email or text unless you’re absolutely sure of the sender.
Even then, just go to the website or app manually. It’s always worth the extra trouble.
A couple of weeks ago we discussed how the cuts made to HHS and specifically the CDC’s FoodNet tracking platform were making it much harder to track and back trace the source of the country’s current cyclosporiasis outbreak. You’ll have heard about this outbreak in the news by now. It’s the one where you begin pooping yourself uncontrollably. It is not, however, funny. 10% of cases will result in hospitalization. The most recent counts from the CDC suggest that there have been more than 22,000 cases of the illness across 15 states. Those numbers are very much in question, however, both due to general underreporting and, again, funding and staffing cuts at CDC.
Just this week, in fact, we have now learned that two people in Michigan have died from cyclosporiasis. That information was and is, at the time of this writing, missing from the FDA’s dedicated page to inform the public on the outbreak. That page hasn’t been updated since July 24th, in fact, which is the exact opposite of what you’d want the government to be doing in a public health emergency. And it’s reportedly not because the government isn’t aware of these deaths.
While news of the deaths made widespread headlines Monday, federal health agencies under the Trump administration were mostly silent. The Food and Drug Administration—which is conducting traceback investigations to identify foods contaminated with the parasite—has not updated its outbreak investigation page since July 24, nearly two weeks ago, as of publication time.
The Centers for Disease Control and Prevention, meanwhile, added a banner notice on its outbreak update webpage saying that the agency was “aware” of the two cases. But its reporting data was not updated to include the two deaths as of this publication.
Why has this government been so slow to report accurately on these unfortunate deaths and the overall case counts for the outbreak? Some combination of those same budget and staff cuts along with a general apathy at HHS. With fewer people and resources to not only track the disease, but to maintain the dashboards meant to update the public, the numbers are slow to come in and untrustworthy when they do.
And with RFK Jr. at the helm of public health, well, the government is generally in the land of We-Don’t-Give-A-Shit.
Two weeks ago, Kennedy confidentially told reporters that the Cyclospora outbreak—linked to lettuce and other unidentified fresh produce—was “under control.” Last week, he announced his own cooking show on YouTube and released the first episode in which he helped prepare a meal that included a fresh salad.
The buffoonery on display from Kennedy and our health agencies is breathtaking. They should be assisting in combating this outbreak, along with those of measles and pertussis. Putting that aside, they should at least be able to tally up the case count numbers to demonstrate their own failures, but it’s clear they’re not really interested in doing that either. Instead, Kennedy in particular wants to host his cooking show and yell at journalists instead. Kid Rock must not be returning his calls any longer, I suppose.
Now, to be clear, this illness carries a 2 week incubation period, and the recalls of the suspected produce that is believed to have caused all of this are within a time frame that cases may still be stemming from that same source. But that’s not a certainty, and it will be important for our federal health agencies to continue to track cases in near real time to determine if there is, in fact, another vector by which cyclosporiasis is spreading.
Unfortunately, every indication is that those same health agencies just aren’t all that interested in doing this the right way.
Filed Under: cdc, cyclospora, foodnet, health & human services, rfk jr.
AI AND ML
Muse Code showcases Muse Spark’s fresh software engineering chops
To demonstrate the capabilities of its next-generation Muse Spark model, Meta has released a terminal coding agent called Muse Code that it thinks can help developers to tidy up their software projects.
Meta co-trained Muse Code on version 1.2 of its Muse Spark model, also released this week and now apparently boasting improved code generation smarts.
Developers can think of this beta release as the equivalent to OpenAI Codex or Anthropic’s Claude Code, two other LLM-based service offerings tweaked for the modern coder. Meta designed its new agent to be handy at planning changes to a codebase, writing the code and validating the results.
Currently, Meta has Muse Spark locked away as a proprietary, closed-weight model hosted in the cloud, an approach its rivals also embrace but which departs from the open-weight approach Meta previously implemented with its Llama models.
But Meta CEO Mark Zuckerberg did not rule out opening up Muse Spark in the future. “I’ll have more to share on that soon,” he replied to a question posed on X about Muse Spark being open source.
Muse Code is best described as an agent orchestrator that runs on your command line.
As Zuck noted in a series of X messages, when a developer starts a task, Muse Code fires up background agents to maintain a context file that other sub-agents doing the work can consult should they lose their way. The tool logs every action before execution, so no work is lost. Multiple agents can work in parallel on the task using their own isolated work trees.
“Your working copy is never touched,” Zuck wrote.
In one test, the agent platform simultaneously built six features for a single game, with no collisions among the agents, Zuckerberg enthused.
“TBH it’s a good harness,” boasted Hongyu Ren, a researcher for Meta’s Superintelligence Labs, on X.
Muse Code relies on Meta’s Muse Spark Large Language Model (not to be confused with the Apache Spark big data cruncher).
Muse Spark 1.2 is the third release in four months from Meta Superintelligence Labs, a unit that Meta stood up in June 2025 to reinvigorate the company’s AI efforts and pursue creation of a personalized AI “superintelligence” that focuses on deep reasoning and long-horizon planning.
The first model from this group, Muse Spark, is a multi-modal model able to digest and reason against text, images, video, audio, and even PDFs. It supports agents in long-running tasks.
With the first release of the model in April, Meta boffins admitted in the announcement that they needed to work more on Spark’s coding abilities. The new 1.2 release addressed that deficiency.
In another test, Muse Spark, running on Nvidia Hopper GPUs, tackled a kernel optimization task. Its agents made over 1,000 tool calls over a 24-hour period.
“It kept finding substantial improvements well beyond the initial exploration phase,” Zuckerberg wrote.
In his X missives, Zuckerberg included a somewhat vague chart comparing the performance of Muse Spark against other commercial models, using two industry benchmarks – Terminal-Bench 2.1 and DeepSWE 1.1 – that evaluate how autonomous agents act like software engineers, as well as a Meta Internal Coding bench too.
The benchmarks all showed Muse Spark to be close to the best, but never the very best, at understanding the assigned engineering task and executing it with as little mission creep as possible. Muse Spark performed honorably compared to Opus 5, GPT5.6 Terra, Grok 4.5 and Gemini 3.6. The scores are tightly clustered, so they all did well (except occasionally Gemini, the current laggard du jour).
So, Muse Spark is competitive anyway, though one eagle-eyed commenter wondered why OpenAI’s midline GPT5.6 Terra was used, instead of the top-tier GPT5.6 Sol.
Installing the agent within your command line is possible through a curl command. Poly-model enthusiasts can also tap into Muse Spark via OpenRouter, or through its API.
Muse Spark’s actual intelligence is metered at US$1.25 per million input tokens and US$4.25 per million output tokens. Discounts are available and the service offers a respectable 1 million token context window. ®
Thousands of Internet-connected servers sold by the world’s biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities—some more than a decade old—that lurk deep inside system motherboards, according to research presented Wednesday.
Baseboard management controllers are miniature computers that are embedded into the motherboards of virtually every enterprise server. The microcontrollers, typically abbreviated as BMCs, run with their own operating system firmware, network stack, and IP address. Administrators rely on them to monitor the physical status of large fleets of servers and to perform a variety of tasks, including rebooting machines, installing updates, and even reinstalling operating systems. BMCs provide what’s known as “lights out” and “out-of-band” management because they work even when servers they’re attached to are turned off or are unresponsive.
Researchers have warned since at least 2013 that BMCs present a golden opportunity for hackers looking for ways to gain deep and persistent access to datacenters. The chief culprit was IPMI, the protocol that allows BMCs to operate independently of servers and to perform administrative tasks. Vulnerabilities in this firmware made it possible for attackers to remotely execute malicious code on the controllers and, from there, infect the servers they manage.
Weekend Open Thread: Wit & Wisdom
Meta enters AI-training agreement with far-right ‘propaganda rag’ Newsmax
Zack Polanski: an incitement to murder Nigel Farage?
MicroStrategy Post-Earnings CLARITY Act Push Could Add New Catalyst for Its Stock
XRP Ledger v3.3.0 brings five institutional features
Bitcoin Enters the 3rd Stage of the Bear Market
Luke Littler’s dominance sparks GOAT debate
Seema Kaliramna Wins Discus Throw Bronze, Takes India’s CWG Medals Tally To 17
New York sues Kalshi over prediction market gambling
Crypto PAC spending tops $2M in Michigan House race
DTCR: Deleveraging And A Hedge Fund Collapse Point To A Possible AI Bottom
Trump Announces Hamas Disarmament Agreement as Iran Strikes Kuwait Air Base and US Attacks Pause Overnight
3 Fed Officials Just Explained Their Rate Hike Vote: Is Inflation Winning?
ESET tracks rise in malicious AI skills and adaptable malware
Gemini Spark can now use Chrome logins and saved passwords to run errands on your behalf
France Cricket implodes: letters hidden in a drawer and a board at war
Four people die trying to cross Channel in small boats
Building A Reproduction PlayStation Motherboard
XRP Ledger urges node upgrade after manifest flood
Moneyflip CEO charged in $40K murder-for-hire plot
You must be logged in to post a comment Login