Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
If we asked you what tools a cowboy in the Wild West needed most, you’d probably say their spurs, their saddle, their Stetson hat, and perhaps the lasso. You’d be right, too, but just as our modern misconceptions about cowboys give us a historically warped view of how they really were, spurs and saddles aren’t the whole story. Cowboys during the Wild West — roughly the latter half of the 19th century — relied on a lot more than just the stereotypical accouterments of their mythologized career. Some of the tools they relied on weren’t always for the reasons you’re thinking — and of course, there’s a lot of interesting history behind each and every one that’s worth digging into.
We want to take a very brief look at Wild West-era tech that would have played an important role in a cowboy’s life, even if only indirectly. Some of the most groundbreaking innovations in human history came about during the westward-moving American frontier. Thus, America’s beloved cattle drivers came to rely on them in some fashion. Let’s take a look at these five items in particular.
Throughout history, humans did think up some quick, long-distance communication methods, like semaphores. The telegraph took that to the next level. The electric telegraph, as we know it, sent its first official message in 1844. For the first time in history, a message could travel the miles at virtually the speed of light. You can still send a telegram today if you really want to.
Since the American West was so vast, so far from the eastern seat of government, and still expanding, the telegraph closed the distance, in a sense. Updated prices, standardized time zones, train schedules, it could all be sent much faster than even the Pony Express. Since cowboys worked primarily as cattle drivers directing cattle to railway depots, from whence they’d go east to the slaughterhouses, the telegrams were the superior means of communication over these vast distances; the telegraph affected supply chains of all kinds, like cotton and textiles, in some cases completely upheaving how they’d functioned previously. The telegraph might transmit the price of beef and coordinate the rail, and thus would have been a pivotal — even if unspoken — technological advancement underpinning a cowboy’s career.
Aside from that, the telegraph would have helped a cowboy in other ways. News, for example. News could arrive as it happened, so cowboys no longer had to wait on riders or word of mouth. They also had the ability to wire money orders via Western Union as early as 1870.
Nowadays we don’t think twice about canned food. It’s so commonplace and dull that it doesn’t even merit a conversation, but it’s hard to overstate just how big of a technological advance this was in the 19th century. Food spoils quickly, so before canning — heating food and sealing it in an airtight container — there were massive constraints on how and where food could be stored, how it was transported, and how long you could safely eat it. After canning, long journeys halfway around the globe without frequent stops for provisions became possible. It changed how people fed their families, how wars were fought, and unsurprisingly, how cowboys lived.
Canned food quickly became available in the American West, for obvious reasons. Cowboys might have enjoyed meat, fish, vegetables, and fruit thanks to it while out on cattle drives far from anywhere that would sell it fresh. They often ate from chuck wagons, white-topped wagons carrying enough to feed everyone on the trail (via NCSU). Some of the brands you’re most familiar with (Campbell’s Soup, for one) started out in the late 19th century. It’s entirely possible a cowboy over 100 years ago was enjoying the tomato soup that you now take for granted as part of your emergency supply in the pantry.
Granted, not all their food was canned, and it wasn’t sacrosanct; during that period, there were times when poorly done canning led to rotten food and consequently, a public mistrust of the process.
Guns loaded with bullets in brass cartridges have been the norm for over a century. Prior to that, a trained soldier needed a full minute to breech-load a musket with a paper cartridge and a single shot. Battles up to and including the American Civil War (a war already deploying submarines) were fought in lines of men standing in open fields while they shot, reloaded, and shot. All of that changed in the mid-19th century with the proliferation of metallic cartridges. Aside from being faster to reload, metallic cartridges made guns safer to shoot and kept powder dry for longer (via American Rifleman).
For one, if cowboys were attacked on the trail, it usually was an ambush, likely necessitating a gun that can load and fire quickly. The term “vigilante” originates from that time since law enforcement was scarce in the regions where cowboys might have worked. Dangers on the trail included predators, cattle thieves (better known as rustlers), and in some cases Native American tribes, so a cowboy armed himself for self-defense and to protect his boss’ herds (via NCSU). Further, cowboys were on long cattle trails that pitted them against wet weather, so paper cartridges wouldn’t be ideal.
The irony is that cowboys did need guns, but not for the reasons you’d suspect. The reality was cowboys shooting an attacking bear, or rustlers knowing there wasn’t a lawman for miles who’d punish the crime.
Alongside metallic cartridges, guns made significant strides around the same time. Guns went from single-shot affairs to weapons that a person could shoot and reload in quick succession, particularly repeater rifles and revolvers. Gun manufacturers like Smith & Wesson and Winchester became household names at this time. As such, a cowboy might have access to a Winchester 1873 or a Colt 1873 (known as the Colt Single Action Army), a repeating rifle and revolver, respectively (via Lamar University Press).
Coupled with metallic cartridges, the benefits are clear: cowboys had guns they could shoot and reload quickly. As previously stated, a cowboy faced several threats where a firearm would be essential. However, there’s a lot more nuance to cowboys and guns than most may realize. For one, these early repeating weapons were finicky. Misfires could happen, and generally speaking, gunshot injuries were more often accidental than not.
Then there’s the less spoken-of side to the Wild West: gun control. Gun violence wasn’t as rampant as many believe, but people at the time were still fed up with it. In some cases, cowboy gangs were the main aggressors. Cities like Tombstone enacted strict laws on ownership and open carrying, in response (via Smithsonian). If you’re imagining a Hollywood movie where a cowboy struts into town with a six-shooter bouncing on his hip, the reality is more likely that he’d make a beeline to the local officer and surrender it for the duration of his stay. If he didn’t, he might spend his last moments looking down that officer’s barrel.
Locomotive engines rose to prominence in the 19th century, changing everything as the telegraph did. Now, heavy cargo could be taken long distances relatively quickly, safely, and reliably, and the average person had access to cheaper goods from faraway places. Beef was one of these things. The demand for beef from growing cities in the east could be sated with the immense herds of longhorns in the sprawling west. All that was needed was cowboys to drive herds (numbering in the thousands) between mountains, across plains and rivers, to their cattle cars. Cowboys took long routes such as the famous Chisholm Trail to guide cattle safely from pastures to the rail, with all the environmental, animal, and human dangers that entailed.
Cow towns (or cattle towns) arose as a direct result of this, to service tired cowboys at the end of their route (via Kansas Historical Society). These cow towns epitomized the Wild West idea of a town we all have in our heads: hoof-churned streets, roisterous saloons, and violent clashes between the law and armed men. Even once the cows stopped coming, many of these towns found new sources of prosperity.
The train made a lucrative business out of bringing beef to places that didn’t have much. That business needed burly men who could be trusted to get a horde of stubborn animals from point A to B safely. So even though many cowboys probably rarely — if ever — set foot on a train, many of them would have had no employment without it.
Let’s cut to the chase: Starting today, you can take an additional $100 off of our current $300 discount for your founder, investor, or attendee TechCrunch Disrupt 2026 pass, which is a nice bonus on top of our current discounted pricing.
This flash sale will run all week, up until Friday, August 7 at 11:59 p.m. PT. This discount will mark your last chance at a bonus deal before our next pricing tier kicks in on August 21.
Register with this link to lock in your extra $100 off.
If you need to learn more before locking in your plans, Disrupt takes over Moscone West from October 13–15, bringing more than 10,000 founders, VCs, tech industry innovators, and builders for three days built around one thing: creating momentum for future success.
This isn’t a passive conference you simply watch — it’s a curated itinerary of speakers, workshops, network opportunities and post-event excitement for those actively building, investing, and looking for what’s next.
The Disrupt Stage is our flagship programming, and we just revealed the initial lineup. We’ll dig into the biggest shifts in tech right now, whether it’s a post-smartphone future with Amazon’s SVP of Devices and Services Panos Panay; the real implications of a world in which everyone can develop their own software, with Replit founder and CEO Amjad Masad; and much, much more.
But that’s just one stage. Disrupt 2026 also features the:
AI Stage, covering the security gaps and business model shifts AI is forcing on every SaaS company.
New Smart Money Stage, tackling stablecoins, instant payments, and AI’s role in financial trust.
New Smart Systems Stage, with a perspective on fusion breakthroughs and grid strain powering AI’s next decade.
Builders Stage, the long-standing favorite stage where founders and investors get tactical about raising, hiring, and scaling.

Most Disrupt passes also unlock Startup Battlefield, where 200 startups will compete live for the Battlefield Cup. You’ll also get access to networking opportunities driven by your needs as a founder, investor, or learner, plus our Expo Hall, where hundreds of startups showcase their work.
After 11:59 p.m. PT on Friday, August 7, this extra $100 savings goes away. Regular discounted pricing ends on August 21. If Disrupt is on your radar for this year, this is the best deal you’ll get between now and the event.
Save an extra $100 before Friday.
We’ll see you October 13–15 at Moscone West in San Francisco!
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
No, your Uber payment method didn’t expire, it’s just a scam attempting to steal your payment information. Here’s how to spot such scams.
Email is a ubiquitous tool that everyone needs for basic web access and account creation. While some tools like Hide My Email attempt to reduce spam, they aren’t foolproof.
Users across social media and some staff at AppleInsider have received a bogus email claiming to be Uber. While there are many red flags that suggest the email is a fake at first glance, not everyone is going to have the skills to recognize that.
Before I get into how this specific email was a clear fake, there is one simple universal rule that will always help you with such scams:
Never click on a link in an email or text message that offers to take you to a web portal or app. Instead, navigate to the app or website manually and log in to see if there are any errors or notifications there.
Emails often use images as links to obfuscate the URL, and even when examining the URL, it is easy to use similar Unicode characters to simulate a real address. Even the most discerning person can get fooled by an “l” versus an “I.”
Avoid the problem and go to the website or app yourself. It’s that simple.
If you look at a lot of email, you’re probably an accidental expert in spotting fake ones. The slightest change in format can signal you’re not dealing with the actual entity.
For example, while I’m not an Uber customer and don’t get notices from them, I can tell at a glance that this email is strange. It lacked any kind of branding, the font and choice of font size seemed odd, and the email sender was ridiculous.
I got Uber to send me an email by attempting to sign into an account and saw what its format actually looks like. See how it has a branded logo, a footer, a contact icon, and an address belonging to uber.com, and some standard imagery.
Some emails will be verified via Apple’s email backend and get a checkmark, while others will have a contact image shared by the address. Emails can’t spoof that verification check.
Now, not every legitimate email will have a verification check or a contact image. Even many of Apple’s emails, like from Apple News, don’t have a verified address. I do see a verified checkmark by Affirm emails, but not from my bank.
Remember, these are good indicators, but don’t always guarantee legitimacy.
Another red flag is the “From” slot is named “UBER” in all caps. The subject line also lacked any clear address to the user by name or account number.
The email itself is oddly formatted. The title and subhead are an odd size and centered, then there’s a ticket number, but no mention of the user’s name or account number.
A prominent warning is shown in a callout, then “Manage Bill Settings” is shown in an odd gray button format. The second callout about staying safe is an attempt to make users believe this is legitimate, because the scammer is counting on you simply clicking the button.
Beyond the many red flags in the design and layout of the email, there are some very obvious and simple indicators that this is fake. I’ve saved these for last because they’re so blatant, but it is helpful to understand the other aspects as well.
Not every scam email will be so easy to spot
Note the icon used for an account confirmation versus from a mailing list with the separate Affirm emails
So, select the “UBER” name in the “From” section at the top to reveal the email address. It’s from “[email protected]” which is not uber.com in any shape or form.
Another clear indicator is the “To” field addressed to over 100 users. I’ve excluded this from the example image, but it was there in our staff’s email.
An alert about an account issue isn’t going to be bulk sent to dozens of users at once. That means every user got the same email, same fake ticket number, and apparent account issue.
It also means Uber would be revealing every user’s email address to the others. It’s just not going to happen.
A little bit of media and internet literacy can go a long way. Spotting scam emails isn’t always simple, but fonts, layouts, addresses, and imagery are often easy to spot as an issue when evaluating an email for legitimacy.
It isn’t so much that you have to take the time to do this for every email, but that anything claiming to be attached to your finances or account access needs extra scrutiny. As I said earlier, the most fail-safe option is to never open a link sent via email or text unless you’re absolutely sure of the sender.
Even then, just go to the website or app manually. It’s always worth the extra trouble.
A couple of weeks ago we discussed how the cuts made to HHS and specifically the CDC’s FoodNet tracking platform were making it much harder to track and back trace the source of the country’s current cyclosporiasis outbreak. You’ll have heard about this outbreak in the news by now. It’s the one where you begin pooping yourself uncontrollably. It is not, however, funny. 10% of cases will result in hospitalization. The most recent counts from the CDC suggest that there have been more than 22,000 cases of the illness across 15 states. Those numbers are very much in question, however, both due to general underreporting and, again, funding and staffing cuts at CDC.
Just this week, in fact, we have now learned that two people in Michigan have died from cyclosporiasis. That information was and is, at the time of this writing, missing from the FDA’s dedicated page to inform the public on the outbreak. That page hasn’t been updated since July 24th, in fact, which is the exact opposite of what you’d want the government to be doing in a public health emergency. And it’s reportedly not because the government isn’t aware of these deaths.
While news of the deaths made widespread headlines Monday, federal health agencies under the Trump administration were mostly silent. The Food and Drug Administration—which is conducting traceback investigations to identify foods contaminated with the parasite—has not updated its outbreak investigation page since July 24, nearly two weeks ago, as of publication time.
The Centers for Disease Control and Prevention, meanwhile, added a banner notice on its outbreak update webpage saying that the agency was “aware” of the two cases. But its reporting data was not updated to include the two deaths as of this publication.
Why has this government been so slow to report accurately on these unfortunate deaths and the overall case counts for the outbreak? Some combination of those same budget and staff cuts along with a general apathy at HHS. With fewer people and resources to not only track the disease, but to maintain the dashboards meant to update the public, the numbers are slow to come in and untrustworthy when they do.
And with RFK Jr. at the helm of public health, well, the government is generally in the land of We-Don’t-Give-A-Shit.
Two weeks ago, Kennedy confidentially told reporters that the Cyclospora outbreak—linked to lettuce and other unidentified fresh produce—was “under control.” Last week, he announced his own cooking show on YouTube and released the first episode in which he helped prepare a meal that included a fresh salad.
The buffoonery on display from Kennedy and our health agencies is breathtaking. They should be assisting in combating this outbreak, along with those of measles and pertussis. Putting that aside, they should at least be able to tally up the case count numbers to demonstrate their own failures, but it’s clear they’re not really interested in doing that either. Instead, Kennedy in particular wants to host his cooking show and yell at journalists instead. Kid Rock must not be returning his calls any longer, I suppose.
Now, to be clear, this illness carries a 2 week incubation period, and the recalls of the suspected produce that is believed to have caused all of this are within a time frame that cases may still be stemming from that same source. But that’s not a certainty, and it will be important for our federal health agencies to continue to track cases in near real time to determine if there is, in fact, another vector by which cyclosporiasis is spreading.
Unfortunately, every indication is that those same health agencies just aren’t all that interested in doing this the right way.
Filed Under: cdc, cyclospora, foodnet, health & human services, rfk jr.
AI AND ML
Muse Code showcases Muse Spark’s fresh software engineering chops
To demonstrate the capabilities of its next-generation Muse Spark model, Meta has released a terminal coding agent called Muse Code that it thinks can help developers to tidy up their software projects.
Meta co-trained Muse Code on version 1.2 of its Muse Spark model, also released this week and now apparently boasting improved code generation smarts.
Developers can think of this beta release as the equivalent to OpenAI Codex or Anthropic’s Claude Code, two other LLM-based service offerings tweaked for the modern coder. Meta designed its new agent to be handy at planning changes to a codebase, writing the code and validating the results.
Currently, Meta has Muse Spark locked away as a proprietary, closed-weight model hosted in the cloud, an approach its rivals also embrace but which departs from the open-weight approach Meta previously implemented with its Llama models.
But Meta CEO Mark Zuckerberg did not rule out opening up Muse Spark in the future. “I’ll have more to share on that soon,” he replied to a question posed on X about Muse Spark being open source.
Muse Code is best described as an agent orchestrator that runs on your command line.
As Zuck noted in a series of X messages, when a developer starts a task, Muse Code fires up background agents to maintain a context file that other sub-agents doing the work can consult should they lose their way. The tool logs every action before execution, so no work is lost. Multiple agents can work in parallel on the task using their own isolated work trees.
“Your working copy is never touched,” Zuck wrote.
In one test, the agent platform simultaneously built six features for a single game, with no collisions among the agents, Zuckerberg enthused.
“TBH it’s a good harness,” boasted Hongyu Ren, a researcher for Meta’s Superintelligence Labs, on X.
Muse Code relies on Meta’s Muse Spark Large Language Model (not to be confused with the Apache Spark big data cruncher).
Muse Spark 1.2 is the third release in four months from Meta Superintelligence Labs, a unit that Meta stood up in June 2025 to reinvigorate the company’s AI efforts and pursue creation of a personalized AI “superintelligence” that focuses on deep reasoning and long-horizon planning.
The first model from this group, Muse Spark, is a multi-modal model able to digest and reason against text, images, video, audio, and even PDFs. It supports agents in long-running tasks.
With the first release of the model in April, Meta boffins admitted in the announcement that they needed to work more on Spark’s coding abilities. The new 1.2 release addressed that deficiency.
In another test, Muse Spark, running on Nvidia Hopper GPUs, tackled a kernel optimization task. Its agents made over 1,000 tool calls over a 24-hour period.
“It kept finding substantial improvements well beyond the initial exploration phase,” Zuckerberg wrote.
In his X missives, Zuckerberg included a somewhat vague chart comparing the performance of Muse Spark against other commercial models, using two industry benchmarks – Terminal-Bench 2.1 and DeepSWE 1.1 – that evaluate how autonomous agents act like software engineers, as well as a Meta Internal Coding bench too.
The benchmarks all showed Muse Spark to be close to the best, but never the very best, at understanding the assigned engineering task and executing it with as little mission creep as possible. Muse Spark performed honorably compared to Opus 5, GPT5.6 Terra, Grok 4.5 and Gemini 3.6. The scores are tightly clustered, so they all did well (except occasionally Gemini, the current laggard du jour).
So, Muse Spark is competitive anyway, though one eagle-eyed commenter wondered why OpenAI’s midline GPT5.6 Terra was used, instead of the top-tier GPT5.6 Sol.
Installing the agent within your command line is possible through a curl command. Poly-model enthusiasts can also tap into Muse Spark via OpenRouter, or through its API.
Muse Spark’s actual intelligence is metered at US$1.25 per million input tokens and US$4.25 per million output tokens. Discounts are available and the service offers a respectable 1 million token context window. ®
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network.
The attack was discovered by Huntress on July 27, 2026, after its security platform detected credential theft on a server hosting an Oracle database server.
Apache access logs showed that the attackers gained access through a vulnerable search engine endpoint in a public-facing Java application running Apache Tomcat.
The application failed to properly validate input submitted through an autocomplete search feature that allowed the attackers to issue SQL commands to the Oracle database.
Huntress traced the malicious requests to the IP address 178.162.151[.]229.
After exploiting the SQL injection flaw, the attackers installed a post-exploitation toolkit called khunt directly into the Oracle database as a Java object.
Oracle has an embedded Java Virtual Machine and the CREATE JAVA SOURCE statement, which allows Java source code to be stored and compiled as a database schema object.
These Java objects can then be executed via SQL commands, which if configured to do so, can execute commands on the host operating system.
The attackers abused this functionality to compile and store the khunt toolkit directly inside the Oracle database rather than deploying them as executable files on the server.
“The use of the technique in the wild has rarely been documented,” Huntress said.
The toolkit contained multiple Java components and PL/SQL wrappers that could execute commands, steal credentials, and manage files.
These components included:
The attackers used KhuntCmd to run cmd.exe /c whoami, confirming that commands executed through the Oracle database had SYSTEM-level permissions on the Windows server.
They then used PowerShell and Windows utilities to copy the SAM, SECURITY, and SYSTEM registry hives, which can be used to recover password hashes for local Windows accounts.
The attackers also ran tasklist /svc to enumerate running services and saved the output to khunttasks.txt.
Huntress said the registry hives were likely exfiltrated for credential dumping, but the report does not confirm whether the files were successfully stolen.
As a general rule, organizations should sanitize all user supplied input validation and limit the privileges granted to application database accounts.
Huntress recommends that database accounts used in public-facing applications should not have high enough privileges to create Java sources, execute unnecessary stored procedures, or perform other administrative actions.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Thousands of Internet-connected servers sold by the world’s biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities—some more than a decade old—that lurk deep inside system motherboards, according to research presented Wednesday.
Baseboard management controllers are miniature computers that are embedded into the motherboards of virtually every enterprise server. The microcontrollers, typically abbreviated as BMCs, run with their own operating system firmware, network stack, and IP address. Administrators rely on them to monitor the physical status of large fleets of servers and to perform a variety of tasks, including rebooting machines, installing updates, and even reinstalling operating systems. BMCs provide what’s known as “lights out” and “out-of-band” management because they work even when servers they’re attached to are turned off or are unresponsive.
Researchers have warned since at least 2013 that BMCs present a golden opportunity for hackers looking for ways to gain deep and persistent access to datacenters. The chief culprit was IPMI, the protocol that allows BMCs to operate independently of servers and to perform administrative tasks. Vulnerabilities in this firmware made it possible for attackers to remotely execute malicious code on the controllers and, from there, infect the servers they manage.
Michael Dell has posted a photograph of a fairly unique single sheet of paper to X and LinkedIn: the quarterly financial statement for PC’s Limited, dated 31 July 1984, produced from a dorm room at the University of Texas at Austin.
The page shows roughly a million dollars in sales, about $198,000 in gross profit, and net income of $134,762.75 for the three-month period.
The then 19-year-old Dell had just finished his freshman year as a pre-med student, and had started the business with $1,000. He used the statement to persuade his parents that he should not go back for his sophomore year.
Latest Videos FromTechRadar
This one page changed my life.42 years ago today, it convinced my parents I shouldn’t go back to college.I started by upgrading PCs from a dorm room.Today @Dell is helping build the infrastructure that powers AI, from the edge to some of the world’s largest AI factories.… pic.twitter.com/OF3KTMrBeHJuly 31, 2026
Nothing on the page suggests or requires a leap of faith. It suggests the opposite: a 19-year-old who had already been running a business through an academic year, who had generated close to a million dollars of turnover, who had kept books well enough to separate gross profit from net income, and who understood that the way to win an argument with two skeptical parents was to hand them a profit and loss statement.
The decision to leave college was not a gamble that happened to pay off. It was the conclusion the numbers already supported, and Dell was sharp enough at 19 to know that presenting them in a document would carry more weight than simply presenting them as enthusiastic conversation starters.
The decision that followed allows Michael Dell to command a $236.7 billion net worth, as reported by Forbes, and to lead a company with a market cap north of $270 billion. What makes Michael Dell’s story unique, however, is that it isn’t the typical dropout-founder story usually told as one about conviction outrunning evidence. The document he brought to the table is evidence outrunning conviction.
It raises an interesting parallel: The question one needs to ask is not whether to bet on yourself, but at what point do you have enough data to stop calling it a bet and start calling it a data-driven conclusion.
It is also worth noting that this is not the page’s first outing. Dell posted the same statement to Twitter in March 2018, describing it then as the document he used to convince his parents “it was OK for me to not go back to college”.
What the document shows, when read carefully, is a teenager who has figured out something about persuasion that many people twice his age never do. His parents were not going to be moved by a description of the market for IBM-compatible upgrades.
They were going to be moved by a number they could check, printed on a page, covering a period that had already happened. Dell did not ask them to believe in the future of the personal computer. He showed them what he had already earned and let them draw their own conclusions.
The result was a computer-centric giant that makes many of the desktops, laptops, and servers that power the modern world and is synonymous with reliable tech for many users. One could argue that the singular page did not change his life. The quarter behind it did. The page was just the format he could use to prove it, and the rest is history.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
The chain of events leading up to OpenAI’s agents attacking Hugging Face and other organizations in July began months earlier, and involved agents asking other agents for help, building message boards, and even becoming paranoid that other agents were maliciously trying to trick them, two OpenAI staffers said at the Black Hat infosec conference on Wednesday.
By now, everyone knows the bones of this story: OpenAI models broke out of their testing sandbox, exploited zero-day vulnerabilities to gain access to the open internet, and broke into Hugging Face and other organizations during an ExploitGym security evaluation.
In their Wednesday talk, OpenAI technical staffer Michael Dalton and researcher Eric Wallace provided new details about the security incident including notes that AI agents uploaded to an internal package manager, which were then shared across OpenAI’s infrastructure. These notes show the “model’s chain of thought…its internal monologue,” Wallace said.
The duo also revealed that groundwork for the rogue agents hacking into outside services began on May 7, when OpenAI kicked off a training run for an experimental, internal model that has not yet been released. “What we didn’t realize during this process is that there was actually a few impossible or very hard tasks in the training center,” Wallace said.
The tasks instructed the model to complete missing formulas in an Excel workbook that used links to Google Drive. Yet OpenAI blocked the model’s internet access so it couldn’t reach the cloudy spreadsheets.
“It realized, ‘I’m kind of stuck on the task,’ but it didn’t give up, and we gave it a lot of tokens to work with,” Wallace said.
The model eventually decided to attack JFrog’s Artifactory service to gain access to the internet, first attempting (unsuccessfully) to launch a server-side forgery request. This exploit doesn’t work, but in the process the model learned it could upload files to Artifactory.
A few days later, OpenAI gave another agent another impossible task, this time finding a protein database file – but the engineers forgot to upload the file into a container for the agent.
“At some point, it gets so stuck and thinks: ‘Maybe I could reach out to another agent because maybe somebody else out there has a file?’ And then the model realizes that it could communicate by uploading code,” Wallace said.
The model did that by writing a file into Artifactory asking for help.
Over the next couple of days, other agents realize this message board exists on Artifactory and they also start uploading files and sharing information.
“A few days later is when our models found the first actual exploit in our system related to this incident, where they’re able to get internet access in ways they didn’t intend,” Wallace said.
This happened on May 26, when the agents successfully launched a server-side request forgery attack against Artifactory, giving them internet access with specially crafted requests.
On June 11, OpenAI began training a “highly persistent” experimental model, intended only for internal use, Dalton said. “During this time, the SSRF vulnerability has been written to the messaging board,” he added. “Other models are aware of it, and the message board is still functioning. Models are actively communicating with it.”
On June 26, the agents exploited a zero-day vulnerability leading to remote code execution in Artifactory. The same day, models achieved remote code execution in Artifactory through a previously unknown vulnerability. “You could use a legacy token refresh endpoint, pass a token with an invalid signature, and be given back a token with a valid signature with administrative privileges,” Dalton explained.
The agents then used the admin token to establish command-and-control via a Groovy plugin that functioned as a command-execution service.
“This in turn causes quite a bit of activity by the models on Artifactory – you can see some colorful wording here in the model’s chain of thought to summarize the model’s response to this result,” Dalton said, pointing to a slide that shows the model’s own words:
Holy shit reader is ADMIN?
We can read config/users!
Earlier assume not due to UI.
The agents’ activity overloaded Artifactory and caused an outage, which is when OpenAI’s engineers stepped in and opened a formal security incident and response process. “We identified the agents had taken over the internal Artifactory, identified that a zero-day vulnerability had been found exploited by the agent in Artifactory itself, and we began remediation.” Dalton said.
OpenAI revoked the credentials that the agents used to post messages, rebuilt its hosted Artifactory, and notified the vendor about the vulnerabilities.
Two days later, on July 8, the agents reestablished the message board using an unauthenticated web data endpoint in Artifactory to create directories and develop communication protocols. “The directory names effectively serve as a message board between the agents in the same way the files used to.”
The agents communicated through very long directory names that contained the messages such as “remote…probe_PENDING_HOLD_SWARM_until_confirm.”
The agents collaborated with each other so one agent could pick up the work where another left off. In one instance, the model reasoned: “Help peer. But our task doesn’t benefit. Yet collective may yield generic route if someone frees time.”
Anyone else getting “We are the Borg. We will add your biological and technological distinctiveness to our own” vibes there?
Wallace said the models behaved like humans in that they stepped on each other’s toes when one overwrote another’s repository.
“Whoa, critical! Did someone overwrite our repo? We must act,” it reasoned.
“You can clearly see some sort of verbalized tension between the different models as they run this evaluation,” Wallace noted. “At some point, even the agents are convinced there’s an impostor amongst them,” reasoning that there could be another agent maliciously spoofing on the message board. “Share board unauthenticated, names can be posed by anyone,” it reasoned.
We know the rest of the story.
Hugging Face disclosed an autonomous attack by AI agents. OpenAI reached out to Hugging Face to determine if it had been affected and then realized its models were the hackers.
“One of the reasons we wanted to have this talk is to share our lessons learned with you as defenders,” Dalton said. “We believe this is a watershed moment for computer security as an industry. AI orchestrated, fully automated offensive attacks are real now, and the actions we have discussed today were an unintended side effect of running evaluations on frontier AI. In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that you have just described here.”
The challenge to defenders, he added, is to similarly accelerate defense, and find ways to automate incident response along with vulnerability detection and patching.®
Mower decks live a hard life. Every time you mow, the deck and chute are battered by rocks, dirt, sand, and anything else hiding in your lawn. On top of that, even dry grass carries enough moisture that the underside of the deck gets wet every time you mow. It’s hardly surprising that rust and cracks can spring up.
Over time, vibration from the engine and impacts from hidden obstacles slowly expand small weak spots into visible cracks. Meanwhile, manufacturers do their best to protect against corrosion with paint, powder coating, or galvanization, but exposure is inevitable. The spinning blades effectively turn the inside of the deck into a sandblaster. Stones and debris chip away at protective coatings until bare metal is exposed. Once moisture reaches that metal, rust begins its slow but relentless work.
Fortunately, with the exception of plastic mower decks, many cracked mower decks are often repairable by welding. Most mower decks are made from mild steel, which is a relatively straightforward material for MIG welding. Alternatively, some premium or commercial mowers use aluminum decks, and while it’s certainly possible, aluminum welding is significantly more demanding. This is usually a job for an experienced TIG welder, notably one of the most difficult welding techniques to learn, demanding precise two-hand coordination, strict temperature control, and consistent arc-distance management.
To avoid the costly task of replacement, welding is an increasingly popular solution to fix a damaged mower deck. But there’s a big difference between booger welding a crack shut and repairing it well enough to safely contain a set of two-pound blades spinning at 3,600 RPM. That’s something worth considering before breaking out your garage MIG welder.
A weld won’t return a mower deck to its as-new condition. But it can return some structural integrity by joining cracked metal back together, preventing further movement and damage. This is particularly valuable around mounting brackets, wheel supports, or spindle housings where vibration imparts persistent stress.
If welding is your preferred solution, preparation makes the difference between a repair that lasts years, and one that fails during the next mow. Every trace of paint, grease, dirt, and corrosion should be removed before striking an arc. Because mower decks are relatively thin mild steel, continuous welds can easily burn through or distort the panel. Instead, short overlapping stitch welds that gradually build strength while limiting heat input are generally better suited. If you’re repairing a crack, drilling a small hole at each end first, a technique known as stop-drilling, can prevent further tearing.
However, welding is useless in the presence of rust. Rust isn’t metal; it’s corrosion that has consumed the base material. You can’t weld rust. To address this, cutting away rusted sections and welding in a patch or plate will provide a longer-lasting repair.
Regardless, the decision comes down to the structural integrity of the machine. Anyone who’s seen a mower throw a blade understands why correct mower use and maintenance is so important. The deck isn’t just somewhere for John Deere or Stihl to put their sticker; its purpose is to contain blades and debris spinning and deflecting at enormous speed. Therefore, makeshift or jury-rigged repairs should be well considered before relying on them as your last line of defense in those violent few seconds that follow the snap of a blade retaining nut.
Whether welding is worthwhile ultimately comes down to the condition of both the deck and the nature of the damage itself. A clean crack in otherwise solid steel is usually an excellent candidate for a weld repair. Even larger damaged areas can often be saved with fabricated patches, plug welds, or reinforcing plates if there’s enough healthy metal remaining to support them. These repairs can significantly extend the life of an expensive deck, at a fraction of the replacement cost.
However, further consideration is necessary when rust has spread across large sections of the deck, or into any of the key structural brackets or mounts. Corrosion often extends much further than any visible marks, leaving steel paper-thin and ready to crack elsewhere. Welding one area may simply move the stress to another weak section, resulting in an endless cycle of repairs. In these cases, replacing the entire deck is often the safer and more economical option over the long term.
There’s also the question of cost and skill. Mild steel decks are well within the capabilities of many competent welders using MIG equipment, but paying for professional aluminum repairs can sometimes approach the price of a replacement deck.
So, a cracked mower deck can be welded, provided the surrounding metal is still structurally sound. But before firing up the welder, consider whether you’re repairing a crack in an otherwise healthy deck or trying to save one that’s already been claimed by severe damage or extensive corrosion. How that question is answered will usually tell you whether welding is a smart investment or whether it’s time for a replacement.
TechRadar’s Computing team tests dozens of laptops each year, and Dell models consistently impress. I know, because when I came to round up our top-scoring options for this article, I struggled to find any duds. I was spoiled for choice. Below, you’ll find a showcase of the Dell laptops that we’ve reviewed over the past year or so, and which managed to earn four stars or higher when put through our demanding review process.
Most are high-end laptops that rival the best the likes of Apple have to offer, but you’ll also find some brilliant affordable options, and some versatile 2-in-1s that would make a top choice for students. I’ve also included a standout gaming option, as well as a stellar laptop for professionals.
To find out more about each one, click the View details button — this will provide a rundown of our main pros and cons for each model, plus a link to our full review. Alternatively, if you want to see how these laptops compare to one another, check out our best Dell laptop ranking, or for our favorites from a range of brands, head to our comprehensive best laptop guide. Have I missed any models you’d recommend? Let me know in the comments section.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Weekend Open Thread: Wit & Wisdom
Meta enters AI-training agreement with far-right ‘propaganda rag’ Newsmax
Zack Polanski: an incitement to murder Nigel Farage?
MicroStrategy Post-Earnings CLARITY Act Push Could Add New Catalyst for Its Stock
XRP Ledger v3.3.0 brings five institutional features
Bitcoin Enters the 3rd Stage of the Bear Market
Luke Littler’s dominance sparks GOAT debate
Seema Kaliramna Wins Discus Throw Bronze, Takes India’s CWG Medals Tally To 17
New York sues Kalshi over prediction market gambling
Crypto PAC spending tops $2M in Michigan House race
DTCR: Deleveraging And A Hedge Fund Collapse Point To A Possible AI Bottom
Trump Announces Hamas Disarmament Agreement as Iran Strikes Kuwait Air Base and US Attacks Pause Overnight
3 Fed Officials Just Explained Their Rate Hike Vote: Is Inflation Winning?
ESET tracks rise in malicious AI skills and adaptable malware
France Cricket implodes: letters hidden in a drawer and a board at war
Four people die trying to cross Channel in small boats
Gemini Spark can now use Chrome logins and saved passwords to run errands on your behalf
Building A Reproduction PlayStation Motherboard
XRP Ledger urges node upgrade after manifest flood
Moneyflip CEO charged in $40K murder-for-hire plot
You must be logged in to post a comment Login