Who gets to tell the military “no”?
Tech
Daily Deal: Soundfreaq Sound Spot II Bluetooth Speaker
from the good-deals-on-cool-stuff dept
The Soundfreaq Sound Spot II combines wireless audio performance, ambient lighting, and relaxing sound features in a compact design built for modern lifestyles. Featuring a Bamboo and White finish with eco-friendly materials, this Bluetooth speaker complements bedrooms, offices, living rooms, and personal spaces while delivering both style and functionality. Engineered with a custom-designed audio driver, Bass Boost DSP technology, and a passive radiator, Sound Spot II delivers balanced sound with vocal clarity and enhanced bass performance. Beyond music playback, Sound Spot II includes built-in nature sounds, ambient lighting, and sleep timer functionality designed to help create a more relaxing environment. With Bluetooth connectivity, rechargeable battery power, and splash-resistant construction, it offers convenient performance for home and daily use. It’s on sale for $80.
Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.
Filed Under: daily deal
Tech
The military wants AI that rarely tells it no
That question has become even more important after the Pentagon pushed AI companies to loosen limits on how their technology may be used in war — including how much human control must remain over autonomous weapons. When Anthropic said no, it lost a major government deal. OpenAI stepped in, embracing the Pentagon’s more flexible standard instead. Now, thanks to new reporting from The Intercept, we’re getting a better look at what those negotiations actually entailed.
The OpenAI-Pentagon agreement included specific language on the type of AI models the DOD would receive: “OpenAI models that are designed for national security use cases and have minimal refusal rates.” That phrase — “minimal refusal rates” — means that the Pentagon is seeking models that rarely, if ever, tell it no. (According to The Intercept, a Justice Department lawyer representing the Pentagon confirmed this language, before backtracking only a few hours later.)
On the surface, that provision might seem reasonable. The military is a strictly hierarchical institution. When your senior gives you an order, you do it. Leaders generally have more battlefield wisdom and experience than their subordinates, so the rank and file can usually assume that their commanders know what they’re doing and follow along. Plus, in the high-stress, time-sensitive environments of most military operations, there is little room for discussion, explanation, or alternative proposals.
So, if soldiers can’t refuse an order, why would a machine be allowed to? Who is a robot to tell its commander no?
There’s just one issue. Soldiers can refuse an order — when the order is illegal. In fact, they are legally required to. But by introducing technologies with a limited ability to challenge commands, the military may be making it harder to stop war crimes before they are committed.
Humans have a duty to disobey
As outlined in US domestic, military, and international law, soldiers are only obligated to follow lawful orders, and they have a duty to refuse unlawful ones.
The Department of Defense’s Law of War Manual is unambiguous: “Each member of the armed services has a duty to: (1) comply with the law of war in good faith; and (2) refuse to comply with clearly illegal orders to commit violations of the law of war.” Obeying an illegal order — as in a directive that violates the Constitution, US laws, international law, or directs one to commit a crime — can expose a service member, as well as their commander, to criminal liability.
This “duty to disobey” has foundations in early British and American common law, but it achieved international recognition after the Nuremberg Trials against Nazi soldiers after WWII.
In those trials, many Nazi soldiers argued they were not liable for crimes they committed during the Holocaust because they were simply following their superiors’ orders. Rudolf Hoess, the commander at the largest Nazi concentration camp, Auschwitz, himself explained: “In Germany it was understood that if something went wrong, then the man who gave the orders was responsible. So I didn’t think that I would ever have to answer for it myself.”
These defenses were unequivocally rejected by the court.
The tribunal held that obedience is not without limits, especially when a wartime act would be clearly illegal to the subordinate or any person of “ordinary sense and understanding.” If “I was just following orders” was an absolute defense, everyone involved in a crime would escape accountability, with the exception of the single highest-ranking officer. Instead, the court determined that individual moral and legal responsibility supersedes national or military chains of command for illegal acts.
Obedience is not without limits, especially when a wartime act would be clearly illegal to the subordinate or any person of “ordinary sense and understanding.”
But, when it comes to agentic AI systems or AI-assisted weapons, increasingly being used in place of human soldiers, does the same logic apply? And, perhaps more importantly, should it?
When you use an AI chatbot, it does not simply reject queries it may not “agree” with. It does not say no to requests it doesn’t “like.” Instead, it follows a set of established protocols, much as a soldier should follow the law of war: It refuses requests that violate its terms of service.
The military is using AI for far more consequential applications than a layperson using ChatGPT to, say, build a travel itinerary. So, what kind of world is created by the Pentagon’s request for AI that “minimally refuses” its directives, many of which may bear grave ethical, moral, or legal implications?
Rebecca Crootof, an expert on technology law and professor at the University of Richmond School of Law, told Vox that while the language could easily be read as increasing the likelihood of compliance with unlawful orders, or at least reducing the friction around them, “Minimal refusal doesn’t mean no refusal.”
“I both want to say it’s not definitely going to mean compliance with unlawful orders,” Crootof said, “but also acknowledge that identifying and evaluating what constitutes an unlawful order in the moment can be incredibly difficult.”
Even for human soldiers, disobeying illegal orders is neither simple nor easy. To the contrary, it doesn’t even happen that frequently. In fact, some legal scholars have argued that giving illegal directives in and of itself is an act of abuse against subordinates, who are not thoroughly trained in legal nuances, are conditioned to obey, and face prosecution if they make the wrong choice.
Still, the mere fact that soldiers can disobey is an important constraint on commanders who might let battlefield conditions, or even commands coming from their own superiors, erode their ethics and commitment to the law.
Still, the mere fact that soldiers can disobey is an important constraint on commanders who might let battlefield conditions, or even commands coming from their own superiors, erode their ethics and commitment to the law.
Those who are optimistic about AI often argue that machines could be better at interpreting and applying the law than human soldiers. Machines can be trained on the law itself — drawing on a repository of legal cases, rulings, and battlefield data — which might make them more “knowledgeable” than an average soldier. And machines do not face the same pressures as soldiers facing prosecution for making mistakes, since they can’t exactly be held accountable; a problem to unpack another time. That, in turn, might make it easier for them to refuse illegal orders in the proper conditions.
So, is the answer as simple as letting the machines decide? Not exactly. “This has been a desire and a drive by technologists for ages,” Crootof said. “What if we just put the law in the system and have it only do things that are lawful? Isn’t that going to solve things?”
Interpreting and applying the law, though, is not a simple legal-illegal binary. “It’s very context-specific,” Crootof told me, “and honestly, that’s the kind of thing humans generally find difficult and AI decision-making systems are even worse at.” Often, determining the legality of an act comes down to subtle nuances you can’t program for: You’re allowed to target a combatant; you’re not allowed to target a wounded or surrendering combatant. You’re not allowed to target a civilian; you are allowed to target a civilian directly participating in hostilities. The difference between a legal target and an illegal one may come down to body language, clothing choices, or even battlefield intuition.
As Crootof explained, “These are not the kinds of contextual analyses AI is good for.”
So what’s the solution?
Where human soldiers’ power to disobey would traditionally serve as an important check on the power of military commanders, if an imperfect one, replacing soldiers with machines that don’t have such safeguards removes one last layer of judgment over the use of force. And yet, machines themselves are not always capable of making the judgment calls that go into interpreting the law, so it may not be appropriate to let AI have the final say either.
So what’s the solution? Given the way AI technology has already been thoroughly integrated into the military, Crootof told me it may be somewhere in the middle.
Rather than programming AI to refuse commands it interprets as illegal, Crootof said, “what it could be designed to do is flag those indeterminate zones, those gray-zone analyses, for human review or for a higher authority.” When a system picks up conflicting signals — an enemy soldier who looks like he may be surrendering, for example — it could prompt the commander to confirm their selection or remind them of applicable law.
In this way, a check on commanders’ battlefield authority could be preserved without fully ceding judgment over the use of force to the machine.
We don’t know yet whether OpenAI has equipped its “minimal refusal” models with such capabilities. But as those technologies become increasingly central to military decision-making, the public deserves answers sooner rather than later.
Tech
DoorDash Will Pay $131.5 Million For Missing And Miscalculated NYC Delivery Worker Wages
The company blames technical errors and a difference of opinion on how wages should be calculated for pay irregularities.
New York City has announced that DoorDash will pay $131.5 million as part of an enforcement action for violating the city’s minimum wage and delivery work protection laws. The settlement covers late or missing payments for delivery workers, civil penalties and specifically “over $83 million to resolve a disagreement over how to calculate pay for time Dashers spend online between deliveries,” DoorDash said in a separate announcement on its website.
The enforcement is the result of an investigation conducted by New York’s Department of Consumer and Worker Protection (DCWP), based on reports from workers of late or missing payments for completed deliveries. As part of the settlement, workers will receive more than $115 million total, with more than 260,000 affected workers receiving compensation “calculated at approximately 200 percent of the amount they were underpaid,” according to the city.
DoorDash attributes some of these missing or late payments to technical issues and other complications like “deliveries that crossed city boundaries, had multiple pickup or drop-off locations or were only partially fulfilled or cancelled.” Some payments were also different because DoorDash violated New York’s minimum wage laws. As the company explains in its settlement announcement, New York’s law says workers “must be paid for this time spent online between deliveries,” or on-call time. While the company claims its approach to calculating on-call time was “fair, practical and legal,” it decided to follow the city’s guidance rather than fight in court.
Besides the payments to workers and the DCWP, the settlement also establishes a compliance monitoring program to address future violations. DoorDash has agreed to share monthly data with the DCWP for the next three years as part of the program, and to update its app and adopt “internal controls” to address the issues that led to the violations and prevent workers from being offered deliveries unless they’re compensated for on-call or trip time. To make it easier for people to compile data about their delivery work, the Workers’ Algorithm Observatory and the Workers’ Justice Project have also committed to building software to allow workers to capture the information DoorDash shows them about their deliveries and pay.
DoorDash, like other delivery companies, has generally pushed back on attempts from cities and states to regulate their platforms or secure protections for delivery workers, including even minor changes like a law that would require the company to suggest customers tip at checkout. At least when it comes to the late and missing payments, the company was willing to admit, in its own words, that it “screwed up.”
Tech
Discord Rolls Out Its Revised Age Verification Policy
It will offer several privacy-focused options for users who aren’t automatically confirmed as adults.
Many social media platforms have been applying new age verification rules in response to growing interest in limiting access for minors. Discord had planned to enact a policy this year that would have required either a facial age estimation or an ID scan for users who couldn’t have their status as adults confirmed by its internal tools. The company announced in February that it would be delaying those changes in response to concerns about privacy and the collection of personal data involved in both of those verification methods. Today, the service shared details about how it will begin checking ages while accounting for that community feedback.
Starting this week, Discord will automatically sort users into either the Adult or Teen age group based on markers such as how long the account has existed, the servers they’re in and their general activity levels. The blog post explicitly stated that Discord will not be accessing messages or calls to determine an age estimate, and the individual’s age group will not be displayed on their profile or shared with other server members. Discord users will be able to check which group they’ve been sorted into under the Account Status section of the User Settings menu. For an expected 90 percent of platform’s audience, no further action will need to be taken if they are placed in the correct group.
If a user is put into the Unconfirmed age category, they will have several options for verifying that they are older than 18. Depending on regional restrictions, those choices might include confirmation via credit card, Apple App Store, Google Play Store, Google Wallet or the AgeKey credential service, as well as more common tools such as an ID scan or a video selfie. To further allay privacy concerns, Discord said it will require any third-party age assurance vendor to permanently delete a user’s information once their service is completed, as well as requiring any facial age estimation to run completely on the user’s device.
For the users placed in the Teen Age Group, there will be a trio of restrictions placed on their accounts. First, any messages from non-friends will be sent to the message requests inbox, and Discord will give an alert before accepting a friend request from a user who doesn’t have mutual friends or shared membership in a small server. Second, the user will not be able to view some content across Discord. The age-gated material includes images that have been tagged as sensitive by the platform’s content filters, in addition to any servers, channels and bot commands that are restricted to only adults. The final limitation is that a teen’s full profile details and activity will only be accessible to friends and to members of smaller servers. Accounts in the Unconfirmed category will be placed under the first two restrictions until the user confirms their age.
Tech
Mistral denies a fresh security breach, but the code on sale looks a lot like May’s leak
- Seller claims to be offering Mistral AI’s full source code and says the company was breached again after May 2026 attack
- Mistral says an investigation found no evidence of new unauthorized access but has not stated whether the listed code is genuine
- No customer data has surfaced in analyzed samples, and nobody has shown files created after the May incident
A seller on a cybercrime forum says French giant Mistral AI has been hacked again and is offering what they call the company’s full source code for sale.
The September 16 2026 post by an account using the handle “mrwho” consists of a listing titled “Selling mistral.ai Source Code” on an English-language cybercrime forum, according to The CyberSec Guru, pricing the material in Monero only before it attempted to steer potential buyers to Session or Telegram.
Mistral AI’s own team has refuted this, stating it has “found no evidence to support this claim.”
Latest Videos FromTechRadar
Not Mistral’s first hacking-centric PR problem
Mistral’s earlier hacking incident is undisputed – in May 2026, the Mini Shai-Hulud supply chain campaign, attributed to the TeamPCP group, spread from compromised TanStack packages to hundreds of npm and PyPI projects.
Mistral’s own security advisory MAI-2026-002 says an automated worm led to compromised versions of its SDKs being published for a few hours on May 11 and 12, and that an affected developer device was involved. Microsoft Threat Intelligence found that a poisoned Mistral AI Python package fetched a second-stage credential stealer that allowed the attack to exploit users.
Mistral went further in statements to reporters than in its advisory. It told BleepingComputer that attackers had compromised a codebase management system and “contaminated some of our SDK packages for a brief period,” while insisting that hosted services, managed user data, and research and testing environments were untouched. It also told HackRead that only certain non-core repositories were accessed.
TeamPCP, meanwhile, advertised roughly 450 repositories, about 5GB in total, for $25,000, and threatened to dump them for free if no buyer appeared within a week. One can therefore contend that this could be the same dump being remarketed by a different account, and the seller’s profile is already suspect.
The CyberSec Guru noted that the account joined in September 2026 and had four posts and a reputation score of 30, despite displaying a top-tier “GOD User” rank. That profile could fit a scam in the making, but as the outlet pointed out, it could also fit a broker fronting for someone else or a freshly minted alias.
HackRead published 24 sample repository names from TeamPCP’s May post. FrenchBreaches, which examined the 339-file tree mrwho shared in September, lists several of the same names. At least four of these appear in both: mistral-inference-private, mistral-inference-internal, mistral-finetune-internal, and mistral-common-internal.
This makes it hard to tell whether the purported ‘hack’ is just a rehash of an existing dump from Mistral’s previous breach or a second successful hacking attempt. There is a straightforward test, however: If the September archives contain commits, files, or credentials dated after May 12, or secrets that were still valid after Mistral’s cleanup, the seller’s claim of a second breach gains real weight. If everything predates the May incident, this is a resale, which is embarrassing for Mistral but not a new security failure.
Of course, locating the archives or examining them would involve paying the ransom in crypto, as required by what could potentially be a scam in the making- a tremendous leap of faith for an account that was created earlier this month, making this essentially a lottery ticket at best for any security researcher attempting to take a closer look.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Tech
IT mistake erases 11 years of viewing history for hospitals’ maternity records
NUH noted that the data loss doesn’t impact current patient care.
“No patient information was accessed or used inappropriately as a result of this incident,” the blog said.
In a statement accompanying the blog, Andy Callow, NUH’s chief digital and information officer, said NUH completed a patient safety incident investigation and has taken unspecified steps to strengthen “technical controls and processes to help prevent a similar incident from happening again.”
“I am sorry for the concern and distress this incident may cause to women and families affected,” he said.
Police investigating
The announcement comes as NUH faces a broader police investigation into allegations that over 500 mothers and babies endured “potentially avoidable” harm or died due to systemic failings within NUH, per a review of the hospitals’ maternity department released in June and led by a senior midwife. These reported failings include understaffing, undertrained employees, and failure to listen to parental concerns, the BBC reported at the time.
Also, in June 2025, a local police investigation concluded that a file with records for hundreds of maternity care patients at NUH was likely erased “intentionally or maliciously.” NUH recovered that data days after its deletion.
Nottinghamshire Police is investigating whether the most recent data loss impacts the larger case concerning the maternity care-related injuries and deaths and if criminal charges will be filed, the BBC reported this week. The police are also trying to retrieve the lost data.
“At present, no crime has been identified,” deputy chief constable Rob Griffin, one of the investigation’s leaders, said, per the BBC.
Nottingham Maternity Family Group, a group representing some of the families affected by the broader investigation, said that the data loss reported this week is “extremely unnerving.”
“Families who have already endured preventable harm, injury, and bereavement should not also have to worry about the security of the records of their experiences,” the group said in a statement, per the BBC.
Tech
Get a Wi-Fi 7, touchscreen Chromebook with Google AI for a very tempting price
A twelve month trial of Google AI Pro, complete with 5TB of extra storage, comes bundled in for free with this AI-powered touchscreen 2-in-1.
With the countdown already running on this deal, the Acer Chromebook Plus Spin 514, a 14 inch WUXGA touchscreen 2-in-1, has dropped from its $749 comparable value to $499, a $250 saving that works out to roughly a third off.
Get a Wi-Fi 7 touchscreen Chromebook with Google AI for $499, $250 off
Getting a laptop this useful for $499 is only possible for the next few hours before this particular deal disappears for good.

A $250 cut on a touchscreen convertible with a dedicated AI processor is a genuine bargain, and the included year of Google AI Pro adds a further 5TB of cloud storage most people would happily pay a subscription for.
That WUXGA touchscreen folds all the way back into tablet mode for reading or sketching, and its Corning Gorilla Glass surface stays smooth and scratch resistant whether you are using a stylus or a finger.
Inside sits a MediaTek Kompanio Ultra 910 octa-core chip with a built-in neural processing unit capable of 50 trillion operations a second, handling on-device AI tasks like image generation without ever leaning on the cloud.
Paired with 12GB of RAM and 256GB of storage, that processor keeps a dozen browser tabs and a full document open without any noticeable slowdown. A battery rated for up to 17 hours means all of that multitasking can run through a full working day on a single charge.


Wi-Fi 7 keeps the Spin 514 stable during video calls and large downloads even on a crowded home network, while its 5 megapixel webcam and DTS dual speakers keep those calls looking and sounding clear.
A Titan C2 security chip and military grade MIL-STD-810H testing back up that reliability, while the bundled Google AI Pro trial adds a full year of Gemini access on top of the extra cloud storage already included.
Locking in a touchscreen 2-in-1, a dedicated AI chip and a free year of Google’s own AI subscription for just $499 is only possible for the next few hours before this particular deal disappears for good.
SQUIRREL_PLAYLIST_10148964
Tech
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
Microsoft said Tuesday that it led an industry-wide disruption of a subscription-based scam platform that used an AI chatbot to compromise 12,000 Microsoft accounts over a few-month span.
Named EvilTokens, the platform was introduced over a Telegram channel in February and charged an initial $1,500 fee and a recurring $500 charge each month after that. EvilTokens provided a single service for streamlining most steps required to compromise email accounts in large numbers. From there, the platform helped customers analyze inboxes, select targets that would provide the biggest potential payouts, and draft follow-up emails that provided realistic ruses for tricking company employees into transferring funds to attacker-controlled accounts.
Minutes, not days
“While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim’s inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed,” Microsoft said. “The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action.”
Microsoft said users of EvilToken compromised 12,000 customer accounts belonging to 10,000 organizations around the world, with the highest concentration of them located in the US. Countries with the next-largest numbers were Canada, the UK, Australia, India, and France. Victim organizations included wholesale distribution, construction, financial services, real estate, higher education, and healthcare. SpyCloud, a security firm that assisted in the disruption operation, has more details about victims here.
Using a legal process and a network of partners, Microsoft seized 50 websites and 150 more domains used to operate EvilTokens. The UK’s Metropolitan Police Service arrested two men on suspicion of offenses allegedly connected to the crime platform.
Account compromises were achieved through a legitimate OAuth process known as device code authentication. This form of authentication is designed for TVs and input-constrained devices, meaning those that lack the interface for performing normal log-in processes. In this model, the device being signed into presents a code and instructs the user to enter it into a browser on a separate device. The new device is then authenticated.
Tech
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants.
The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure.
ShinyHunters claims it stole between 2TB and 3TB of data from the agency, including information on current and former FBI employees, job applicants, and other internal records.
The group also claims it compromised FBI Criminal Justice, HR, Medlink, and additional services during the intrusion.
ShinyHunters further claims it is now exploiting the same alleged zero-day against other organizations, including Fortune 500 companies.
BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data.
However, ShinyHunters shared a screenshot with BleepingComputer showing the FBI Jobs website at apply.fbijobs.gov defaced with the group’s Umbreon Pokémon logo and a message claiming that FBI employee and applicant information had been compromised.
The defacement stated, “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS. rooting your systems since ’19 ;)”.

Source: ShinyHunters
The message further claimed that sensitive personally identifiable and health-related information belonging to FBI employees and applicants had been stolen.
“All FBI data was compromised including sensitive PII/PHI on incumbent and former FBI employees and all applicant information,” read a message on the defaced site.
“We have a lot more than what we claim here. Thank you for your attention to this matter.”
ShinyHunters told BleepingComputer that the FBI quickly became aware of the intrusion, immediately took affected systems offline, and that the FBI Jobs site now displays a maintenance message.
The group also claimed that access to multiple FBI networks was terminated simultaneously after the agency detected the intrusion.
“They literally pulled the plug on everything,” ShinyHunters said.
The threat actors shared two sample records with BleepingComputer that the group claims were stolen during the attack, including data allegedly associated with FBI personnel.
One record allegedly contained information associated with an FBI special agent involved in a previous BreachForums investigation, while another allegedly contained information associated with FBI Director Kash Patel.
BleepingComputer is not publishing the personal information contained in those records and has not independently verified their authenticity or source.
404 Media first reported the alleged breach after receiving a sample containing approximately 5,000 purported FBI employee records.
The publication said it verified that some information in the sample was accurate, including phone numbers corresponding to people with the same names and numbers associated with US Department of Justice personnel.
Alleged PeopleSoft zero-day
ShinyHunters claims they gained initial access through a new zero-day vulnerability in Oracle PeopleSoft that remains unpatched.
“The Oracle product we exploited the 0day in is PeopleSoft. We found another one yesterday and immediately exploited it on the FBI,” ShinyHunters told BleepingComputer.
The group also claims it tried to erase evidence of its activity from compromised servers to make the zero-day harder to identify.
ShinyHunters also told BleepingComputer that it is now using the same alleged PeopleSoft vulnerability to target corporations and the Fortune 500 after targeting the education sector.
ShinyHunters claims the stolen FBI data came from systems accessed following the initial PeopleSoft compromise.
These systems allegedly include the FBI’s AWS GovCloud environment, which was used to store employee and applicant information.
BleepingComputer has contacted Oracle and Google Cloud’s Mandiant threat intelligence team to determine whether they are aware of a new PeopleSoft vulnerability or related exploitation activity.
Retaliation over FBI report
ShinyHunters later published a lengthy statement on its data leak site claiming the attack was retaliation for an FBI FLASH report detailing ShinyHunters that was published in May 2026.

Source: BleepingComputer
The group disputes claims that ShinyHunters actors may exaggerate access to sensitive information, harass victims and their relatives, conduct swatting attacks, and falsely claim to possess compromising material.
The threat actors denied those allegations and also rejected claims that it is part of “The Com,” a loose-knit cybercrime community frequently tied to data breaches, cryptocurrency theft attacks, and commonly referenced by law enforcement and security researchers.
In the statement, ShinyHunters gave the FBI one week to correct or remove the FLASH report, while claiming the demand was not financially motivated and was not extortion.
When asked whether the group would release the allegedly stolen FBI data if the agency did not make changes to the report, ShinyHunters declined to say.
“No comment,” the threat actor told BleepingComputer.
When BleepingComputer asked the main representative of the ShinyHunters extortion gang whether they were concerned this would lead to increased pressure from the US government to apprehend them, they responded, “I don’t care.”
The alleged PeopleSoft zero-day would not be the first time ShinyHunters has been linked to exploitation of a previously unknown Oracle vulnerability.
During Clop’s 2025 Oracle E-Business Suite data theft campaign, ShinyHunters was part of a group calling itself “Scattered Lapsus$ Hunters” that leaked a proof-of-concept exploit later confirmed by Oracle to match one used in the attacks.
ShinyHunters later told BleepingComputer that the exploit originally belonged to them and that the Clop ransomware gang obtained it without authorization.
That dispute resurfaced last week when ShinyHunters breached and defaced Clop’s data leak site, claiming it stole server data and the private keys for its Tor onion service.
The group subsequently added Clop to its own leak site and threatened to extort the ransomware operation, saying the attack was retaliation for threats allegedly made during the Oracle E-Business Suite campaign.
BleepingComputer has contacted the FBI, Oracle, and Google Cloud’s Mandiant threat intelligence team regarding the alleged breach and PeopleSoft zero-day and will update this story if we receive a response.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tech
The data storage crisis has a biological fix. It starts by making less DNA, not more.
The math behind the data storage problem is brutal. The world creates more information every year than it can afford to keep. Most of it is cold. It is almost never read, yet it cannot be deleted, so it accumulates on tape and disk that degrade, draw power, and demand replacement every few years. The cost compounds. It […]
This story continues at The Next Web
Tech
Rabbit Is Back, This Time With an AI Agent App
Jesse Lyu doesn’t think the Rabbit R1 was a flop.
Lyu’s gadget was among the first in the gold rush to create dedicated AI hardware that acted as a virtual assistant. You could speak into the R1 and ask it to complete tasks for you—book an Uber; order food on DoorDash. After a buzzy launch at CES 2024, it earned scathing reviews. All the agentic stuff on the R1 just didn’t work that well. WIRED gave it a 3/10.
Since those early days, the capabilities of AI assistants have vastly improved, and now the tech is all the rage. So Rabbit is banging the drum again.
On Tuesday, Rabbit announced OS3, a standalone “agentic operating system” designed to run across multiple screens. It also arrives as a software update for the company’s R1 gadget, though you don’t need an R1 to use it. Instead, you can access OS3 through a desktop browser, Telegram on your phone, or even iMessage.
It’s a striking pivot for a company that once championed the handheld hardware over smartphone apps, but the environment for this type of software has ripened.
Agents that handle tasks for you are all anyone in Silicon Valley talks about. Meta’s new Muse agent was just banned from crawling Amazon to shop on a user’s behalf using a virtual machine. Lyu smirks as he brings it up, saying, “We’ve been through all of this a year and a half ago,” calling back to the R1’s controversial use of a virtual machine to execute app actions on your behalf. So was Rabbit just too ahead of the curve?
Lyu says from a monetary perspective, the Rabbit R1 was tremendously successful, especially considering the company doesn’t offer a subscription for its AI features, unlike many competitors. He claims the company delivered more than 100,000 of the orange-red, Teenage Engineering-designed gadgets worldwide, with return rates of less than 5 percent, and earned roughly a 45 to 50 percent margin on the hardware.
“Internally, from an engineering perspective—we didn’t make the wrong bet,” Lyu says. “I think the challenge is really being extremely limited in resources, team-wise and money-wise, compared to other AI studios that raised billions of dollars.” He says Rabbit has raised around $60 million in total and currently employs 15 people.
But after dismal reviews upon the R1’s launch, the company had to make tough decisions. Rabbit decided against expanding the team and chose to stay lean, but things were dire around this time last year. A planned launch in India was stymied by regulations, putting the company in financial strain, so much so that a handful of employees went on strike and claimed they weren’t getting paid. Lyu says he respected their decision, adding that the company secured more funding and is on stronger footing. “There are no issues with the company’s health,” he says.
Lyu says the team decided not to rush into new hardware, and instead focused on delivering software updates to polish the R1 experience—to date, Lyu says Rabbit has deployed around 50 updates in the past year and a half. He points to a dedicated Discord community of more than 12,000 users that provide feedback on what new features to add to the R1, like opening up the hardware. For example, you can integrate OpenClaw or Hermes AI agents into the R1 instead of using Rabbit’s proprietary models.
-
Fashion4 days agoWeekend Open Thread: Talbots – Corporette.com
-
Tech2 days agoResearchers escape OpenAI Codex sandbox to run commands on host
-
Crypto World4 days agoCircle launches Arc Studio AI agent for building onchain apps
-
NewsBeat4 days agoTrump says US has reached an agreement to take permanent control of Greenland’s security
-
Crypto World2 days agoWho Needs CLARITY Anyway? ARB Could See 70X Increase: Hodler’s Digest
-
Crypto World4 days agoBitcoin price breaks channel as RSI climbs to 63
-
Crypto World4 days agoTrading Bitcoin on Robinhood? Why 2% Spread Has Traders Worried
-
Crypto World6 days agoUS Charges Robinhood Engineers Over Crypto Listing Trades
-
Crypto World7 days agoWhat Is the Status of the U.S.-Iran Peace Talks? Here's What Both Sides Are Saying
-
Tech7 days agoWebb’s IC 348 Mosaic Includes Two-Jupiter Dwarfs, Twin Jets, and a Nursery Still Making Worlds
-
Crypto World5 days agoMortgage and refinance interest rates today, Thursday, September 17, 2026
-
Crypto World4 days agoWorld Money launches in 150+ countries with Stripe
-
Entertainment7 days agoBig Brother Update: Melody Explodes at Drew as Illness Sweeps BB28 House
-
Crypto World4 days agoSilver prices recover quickly, hitting weekly high today
-
Business2 days agoAnalog Devices (ADI) Bets $1.35 Billion on Chips that Let Machines Think for Themselves
-
Tech5 days agoGPT-6 Astra Reached the Nether in Minecraft, Lost Its Stash to a Creeper, and Farmed Potatoes for Hours
-
NewsBeat4 days agoUS was ‘on brink of war’ with China over false AI report of nukes moving in Middle East
-
Crypto World2 days agoCoinbase, Robinhood, Circle Seen as Tokenized-Stock Winners
-
Crypto World2 days agoBitcoin price holds above $81K as key catalysts line up
-
Business7 days agoFederal Reserve expected to hike interest rates 25 basis points at FOMC meeting




You must be logged in to post a comment Login