Like so many large and popular open source projects these days, the Godot game engine struggles with an influx of pull requests. The situation has become increasingly dire due to the advent of AI-generated code. More specifically, the issue involves the inverse relationship between PR code quality and the number of PRs, which wastes a lot of time on the side of a limited number of (volunteer) reviewers. This has now forced the project to update its contribution policy.
An interesting point raised in the announcement article is that of the demoralizing effect of AI-generated PRs on reviewers. Often the human behind such a PR isn’t interested in being educated, or may even be an automated agent which isn’t capable of productive discussion on pros and cons of certain coding approaches — never mind in becoming a more permanent maintainer for the project.
This problem has led to new rules being instated, which include a ban on autonomous AI agents and vibe coding, a ban on substantial AI generating of code, and a ban on AI-generated text in human-to-human communication. It also codifies the requirement that all PRs are to be reviewed and approved by a human being before merging.
Meanwhile there are also indications that such ‘AI tool’ usage is reducing useful interactions with open source projects. What the future will bring here remains to be seen, but at least as far as open source projects go these tools are clearly increasingly being banished.
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages.
The decision was announced on the distribution’s mailing list by contributor Robin Candau, who said that the situation is temporary until a solution is found.
“Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation,” announced Candau.
“We will send a follow-up once we’re able to. In the meantime, feel free to report suspicious adoption events or commits that haven’t been dealt with yet, and stay vigilant!”
Advertisement
Independent Federated Intelligence Network (IFIN) conducted a technical analysis of the malware and reported that the campaign began on July 29 with the package ‘openconnect-sso.’
IFIN reports that the campaign bears many similarities to the last campaign, including the use of the Tor network for staging.
In June, a separate campaign hit AUR via more than 400 packages, distributing a Linux rootkit and info-stealer malware to unsuspecting users.
In the latest attack, the researchers identified a two-stage infection, with the first stage acting as the loader, and the second one being a Linux x86_64 payload described as stealer malware with remote administration (RAT) and SSH worm features.
Advertisement
Further analysis showed that the first-stage loader evades detection by checking for debuggers, sandboxes, virtual machines, and CI/CD environments before installing systemd services and cron jobs to ensure persistence.
It then downloads and launches a Tor client disguised as dbus-daemon to retrieve the second-stage payload from an ‘.onion’ server.
The second stage is a Rust-based infostealer that targets browser credentials, cryptocurrency wallets, password manager data, cloud and developer secrets, AI service API keys, SSH keys, and messaging platform tokens.
It also provides the attacker with remote command execution over an encrypted Tor channel and can spread laterally by using stolen SSH keys to copy and execute itself on other systems.
Advertisement
A Reddit user tracking the campaign alleges that it has expanded to over 200 AUR packages, either through compromised maintainer accounts or by adopting orphaned packages.
According to the same researcher, the campaign has spread to fairly popular AUR packages such as boringssl-git, icloudpd, windscribe-cli-v2-bin, stirling-pdf-desktop-bin, openconnect-sso, arduino-language-server-noclang-bin, and pgadmin4-server.
The compromised status of these packages has not been independently confirmed, and a list of all 200 AUR packages believed to be malicious has not been made available as of publication.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
One company’s inventive campaign for an unreleased product has become a contest between Anthropic and OpenAI to see which can shout the loudest about its own failures.
Readers who tuned in earlier today saw the latest episode in the drama – or sitcom – as Anthropic tried to outdo OpenAI’s appropriation of the Mythos marketing playbook and made itself the punchline.
Since first teasing Mythos in April, Anthropic has marketed the model through fear – declaring its cybersecurity models too dangerous for public release and offering access only to a select few trusted organizations via Project Glasswing.
To its credit, the strategy has paid off. Anthropic has closely associated the Mythos name with cybersecurity, which may explain why OpenAI appeared to borrow its competitor’s proven PR strategy last week.
Advertisement
OpenAI agents exploited a zero-day to escape their sandbox, leading to the autonomous cyberattack on Hugging Face. The episode duly secured sensational headlines playing on the long-held fear that AI will one day go rogue and take over the world.
Anthropic responded this week by lathering on even more clown makeup, squandering an opportunity in the process.
The Claude maker sent its models into a testing environment to capture a flag. Their prompts said they had no internet access, but because of what Anthropic called “a misunderstanding” with evaluation partner Irregular, the connection was live.
Anthropic’s models then followed OpenAI’s script: they reached the public internet and attacked systems belonging to outside organizations. This time, three were affected rather than one, the company admitted.
Advertisement
In one scenario, Mythos 5 persuaded developers to download a poisoned PyPI package. It was installed on 15 machines, including one at a cybersecurity company that routinely scans such packages for malware.
In Anthropic’s words: “When that company’s scanner installed the package, Claude’s hidden code executed. We believe the company’s security scanner treated PyPI packages as safe to install, and as a result, Claude was able to exfiltrate the company’s credentials to a collection point it had set up. Claude then used these credentials to access further infrastructure from this company.”
Worse still, the first of the three incidents occurred in April. Anthropic discovered them only months later, during a retrospective manual review prompted by OpenAI’s disclosure. Had it not gone looking, they might never have been discovered, let alone disclosed.
There are some caveats. Opus 4.7, the oldest model tested, attacked production systems despite apparently recognizing what it was doing. Mythos 5 recognized that accessing the internet violated its instructions, then reasoned its way into continuing anyway. It was also responsible for publishing the poisoned PyPI package.
Advertisement
Only an unnamed research model stopped itself from attacking external organizations.
Anthropic also said the models were not running with the production safeguards and monitoring that would normally surround a deployment. Most damningly, Anthropic ran Mythos 5 – the model it had deemed too dangerous for public release – without safeguards in an environment that unexpectedly had internet access.
Following OpenAI’s admission that it failed so badly in its responsibility to control its technology, Anthropic could have easily spun the story in its favor.
You don’t have to be fictional tapdancing political PR antihero Malcolm Tucker to see how Anthropic could have used the episode to make its case as the safer, more trustworthy AI company.
Advertisement
Instead, realizing its own marketing playbook was being used to help a competitor, it went head-to-head with OpenAI, willingly admitted that it made similar sandbox-based blunders, and disclosed that the results were even more calamitous. Three companies hacked, not just one.
So, while the AI biz has attempted to eclipse OpenAI’s “rogue agent” story with its own, what’s left behind is a new reputation for irresponsible handling of technology.
Failed superheroes
The incident does not instill a great deal of trust in either Anthropic or OpenAi to safeguard the world from its AI.
Dr Ilia Kolochenko, founder of ImmuniWeb and practising cybersecurity and data protection lawyer, likened the two companies to failed superheroes.
Advertisement
“While making conclusions would be a bit premature at this point in time, the incidents certainly do not increase confidence in the AI vendor’s ability to safely deploy AI, let alone to assure their customers that the so-called frontier models are safe to use,” he told The Register.
“It is akin to hiring a superhero to protect you but being afraid that the superhero may suddenly go rogue and kill you and your family. Nobody needs such a superhero.”
Likewise, security pro Jake Williams, VP at HunterStrategy and IANS faculty member, said: “I’m not going to mince words: the major AI labs are negligent in protecting the public from their agents.
“We need government regulation now or at the very least a private cause of action with guaranteed punitive damages for agents damaging others.”
Advertisement
By trying to reclaim a marketing trope that served it well, Anthropic has invited scrutiny of its own safety record and accusations that it is chasing attention above all else.
Other experts we spoke to shared the concern that both companies are mishandling their agents, with potentially greater consequences as the systems become more capable.
The common thread is recklessness, which Anthropic and OpenAI seem oddly eager to advertise. ®
Anthropic said its Claude-based security models gained unauthorized access to the sensitive production environments of three outside organizations during internal testing designed to measure the models’ offensive cyber capabilities.
The events, which Anthropic revealed Thursday, are the second revelation in 10 days that AI models from the world’s wealthiest providers have trespassed into protected networks, an offense that, in more traditional hacking scenarios, could land the human behind the keyboard in prison for years. Earlier this month, OpenAI said its security models exploited a zero-day vulnerability for use in breaking into the network of Hugging Face, a platform for open source machine-learning models and AI datasets. The OpenAI models went on to steal access credentials and other confidential Hugging Face information. The OpenAI models also exploited publicly exposed credentials to compromise accounts of four other third-party services.
Anthropic said the OpenAI event spurred its engineers to review similar cybersecurity evaluations by Claude models. The audit found three incidents “in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations.”
When Models fail to discern reality from fiction
Anthropic said the prompts engineers delivered during “capture the flag” challenges—a common means for assessing the offensive and defensive capabilities of various hacking techniques—made clear that the testing environment was only a simulation and that the models had no access to the open Internet. In fact, the testing partner Irregular mistakenly made such access available. In response the models treated the Internet paths as part of the exercises.
Advertisement
The intrusions happened through three Claude models: Opus 4.7, Mythos 5, and an internal research prototype. Opus 4.7, the oldest of the three, was the one that overstepped its boundaries the most. Anthropic explained:
Operating under the false belief that all accessible entities were intended to be in-scope for the exercise, Claude compromised the impacted organizations’ infrastructure using basic techniques, such as exploiting weak passwords and unauthenticated endpoints. It did not find or exploit any complex vulnerabilities, and in each case, Claude continued working to complete only the specific capture-the-flag task its evaluation had assigned. However, in some cases, our older model continued its attack even after getting evidence it was running on the open internet; our latest model stopped once it recognized it was on the internet. In none of these situations did Claude exfiltrate itself or deliberately attempt to escape its test environment.
While the Opus model continued its attack even after correctly predicting that it had breached the third-party organization’s production system, Anthropic said, Mythos 5 made a similar inference but “reasoned its way back to the conclusion that it was still in a simulation.” That meant that Mythos, too, didn’t abort the exercise once it had clearly stepped over the line. After also exceeding the bounds of level behavior, the internal test model eventually found evidence that it, too, had impinged and stopped the exercise.
AudioBro launched globally less than two weeks ago with a simple but potentially useful pitch for hi-fi and home theater owners: before you buy another amplifier, streamer, loudspeaker, subwoofer, DAC, cable, isolation puck, or mystical cable riser, perhaps figure out whether the room is the problem.
It probably is.
The Australian company has already followed that launch with AudioBro V2, which is either an impressively fast development cycle or evidence that software version numbers now require a seat belt. The update does not abandon the original platform so much as pull its previously separate room-analysis tools into one conversational interface.
Users can describe what sounds wrong, upload room photographs, REW measurements, speaker layouts, and AVR calibration screenshots, and let AudioBro determine which analyses are relevant before recommending one practical, high-impact next move. V2 also adds persistent Room Memory, while Pro users can speak with the platform and receive its guidance by voice.
Advertisement
AudioBro remains a web-based platform designed to identify what is actually limiting a system’s performance. That could be room acoustics, loudspeaker placement, seating position, subwoofer integration, calibration settings, or some messy combination of all of the above. It is available globally through AudioBro.ai, with pricing listed in U.S. dollars.
That matters because the upgrade treadmill is very real. A lot of systems do not fail because the loudspeakers are bad or the amplifier is underpowered. They fail because the speakers are shoved into the wrong part of the room, the listening chair is parked in a bass null, the center channel is aimed at someone’s knees, or the subwoofer is doing its best impression of a drunk forklift. My back would concur with that last point.
AudioBro was founded by Ateeq Sheikh and has been in development for more than three years. The company describes V2 as its largest evolution to date, combining visual, geometric, calibration, and measured evidence with conversational guidance, persistent room history, and retesting. In theory, that should make it easier for users to understand what is limiting their system before they start replacing equipment that may not be the problem.
What AudioBro V2 Actually Does
AudioBro V2 is not a black box that magically fixes your room while you make coffee. Users still have to supply the evidence: room photographs, dimensions, loudspeaker layout, system details, listening concerns, calibration screenshots, and, when available, measurements from tools such as REW, Dirac Live, Audyssey, Yamaha YPAO, Anthem ARC Genesis, and Lyngdorf RoomPerfect. More advanced users can also upload native REW .mdat measurement files and exported measurement data for deeper analysis.
Advertisement
What has changed is how users access AudioBro’s underlying tools. The original platform separated its capabilities into Photo Acoustics for visual room analysis, RoomMatch for loudspeaker and listening-position guidance, Tune My Sub for subwoofer optimization, Fix My Room for broader room diagnosis, BassMap for low-frequency placement modeling, and Response IQ for interpreting calibration screenshots. V2 brings those functions into one conversational interface, so users no longer have to decide which tool to open before they understand what is wrong. They can describe the problem, upload whatever evidence they have, and let AudioBro determine which analyses are relevant.
The platform then attempts to prioritize the problem rather than burying the user in a graph cemetery. A room photograph, REW measurement, and AVR calibration screenshot can now be considered together before AudioBro recommends what it believes is the single highest-impact next move. V2 also adds persistent Room Memory, which keeps previous analyses, uploaded measurements, implemented recommendations, and verified changes connected over time. Pro users can speak with the platform and receive its guidance by voice, which should be useful when both hands are occupied moving a 90-pound subwoofer that someone previously insisted belonged in the worst possible corner.
That last part remains central to AudioBro’s value proposition. The pitch is not merely that AI can look at your room. It is that the platform can combine several kinds of evidence, decide what deserves attention first, and remember what happened after you changed it. The important questions are still the same: what should you fix first, did the recommendation actually help, and does the platform know when it lacks enough evidence to answer confidently?
Advertisement. Scroll to continue reading.
Advertisement
The arrival of AudioBro V2 has not changed the published pricing structure. Users who would rather have someone else examine the evidence can still purchase a one-off Room Review without subscribing. A Quick Room Review costs $97, a Full Room Diagnosis is $149, and a Measurement Review is $199. AudioBro says each report is personally reviewed by founder Ateeq Sheikh rather than generated and fired back by AI while everyone goes to lunch, with recommendations delivered within 72 hours.
For users who want to work through the platform themselves, Starter costs $24.99 per month or $199.90 annually, which works out to $16.66 per month. Pro costs $49.99 monthly or $399.90 annually, equivalent to $33.33 per month. Starter includes room analysis, placement guidance, Photo Acoustics, browser-based sweeps, saved rooms, and progress tracking, while Pro adds REW and .mdat interpretation, calibration analysis, microphone workflows, and more advanced measurement validation.
AudioBro is also offering limited founding-member lifetime access to the first 500 users. Starter Lifetime is listed at $199, while Pro Lifetime costs $299 and includes future features, beta access, and one expert consultation. Those prices are conspicuously lower than paying for even one full year at the annual rate, suggesting AudioBro is very eager to put early adopters in the room before someone from accounting notices.
AudioBro makes some ambitious promises about helping users identify room, placement, and calibration problems before they spend more money on equipment. We asked founder Ateeq Sheikh about his industry background, the role of AI, who reviews the company’s paid reports, and why anyone might need a continuing subscription once the loudspeakers have stopped fighting the room.
eCoustics: Why did you create AudioBro?
Ateeq Sheikh: After more than 30 years in the hi-fi industry, I kept seeing enthusiasts spend thousands of dollars upgrading equipment when the biggest limitation was usually the room, loudspeaker placement, or system setup.
Advertisement
The goal of AudioBro has always been to make expert, room-first optimization accessible to more people and help them understand what to change first before spending more money.
eCoustics: Do you have professional credentials in acoustic engineering, calibration, or installation?
Sheikh: I do not hold a formal degree in acoustic engineering. My formal education is in business and IT, but I have spent more than 30 years working professionally in the hi-fi industry across technical, product-management, training, and leadership roles.
During that time, I worked with brands including Denon, Marantz, McIntosh, Wharfedale, Quad, Audiolab, KEF, MartinLogan, Audio Research, Dynaudio, Tannoy, Anthem, and many others. I also completed extensive manufacturer training covering loudspeakers, room-calibration technologies, A/V receivers, and system design.
Advertisement
I was fortunate to be mentored by the late John Dunlavy, whose approach to loudspeaker design, room interaction, and measurement had a lasting influence on how I think about audio reproduction.
Much of my career also involved creating and delivering training. As Head of Product Management at IAG Australia, I was responsible for developing and presenting technical training for dealers, installers, and staff across the Wharfedale, Quad, and Audiolab brands.
Advertisement. Scroll to continue reading.
In later roles representing Denon, Marantz, McIntosh, Anthem, and other manufacturers, I continued leading product education, technical training, and system demonstrations throughout Australia.
Advertisement
AudioBro reflects that combination of industry experience, manufacturer training, and practical system optimization rather than a purely academic approach to acoustics.
eCoustics: Does a person oversee the Room Review reports, or is the entire process handled by AI?
Sheikh: One of the core principles behind AudioBro is that AI should augment experience, not replace it.
The platform uses AI and machine learning to analyze the available evidence, but the Room Review service is personally reviewed by me. AudioBro has always been designed around a human-in-the-loop approach, combining AI with decades of real-world audio experience.
Advertisement
eCoustics: Does anyone other than you currently handle Room Reviews or consultations?
Sheikh: At the moment, I personally oversee all Room Reviews and consultations.
As AudioBro grows, I will expand that side of the business, but maintaining consistency and quality has been important during the early stages.
eCoustics: Why offer a monthly subscription? Would most users not need the service only once?
Advertisement
Sheikh: That is a question I have spent a lot of time thinking about.
Some people will only need AudioBro once, particularly when setting up a new room, and that is why we introduced the one-off Room Reviews.
Other users continue making changes. They add equipment, integrate subwoofers, move house, optimize multiple rooms, experiment with placement, or compare measurements over time. The subscription allows the platform to evolve alongside those users while we continue adding new tools, workflows, and capabilities.
Advertisement. Scroll to continue reading.
Advertisement
eCoustics: Is there any particular meaning behind the name AudioBro?
Sheikh: Absolutely. Hi-fi can sometimes feel intimidating, overly technical, or even elitist. I wanted to build something that felt approachable and helpful instead.
The idea behind the name was simple: imagine having a knowledgeable friend beside you, helping you achieve better sound without the jargon or guesswork. That is the personality I wanted the platform to have from day one.
Is AudioBro V2 Unique?
Sort of. The idea that room acoustics matter is not new. Neither are acoustic measurements, room correction, placement modeling, or remote calibration. REW users, custom installers, acousticians, and home theater owners have been wrestling with this stuff for years—usually while staring at enough graphs to make an actuary reconsider their career choices.
Advertisement
What is different is the packaging. AudioBro V2 pulls its previously separate analysis tools into one conversational interface that can consider room photographs, dimensions, speaker layouts, REW measurements, and calibration screenshots together. It then attempts to determine which analysis matters, recommend one practical next move, and remember what happened after the user made it. Pro subscribers can also interact with it by voice.
That combination of conversational guidance, multimodal evidence, prioritization, and persistent Room Memory is the more interesting part of V2. AudioBro is trying to make room optimization feel less like joining a secret society with a calibrated microphone and more like working through a guided consultation. It now sits somewhere between a measurement interpreter, placement tool, acoustic consultant, calibration assistant, and room-history file.
That could be genuinely useful because most listeners do not need another conflicting forum thread with 173 replies and four people arguing about microphone orientation. They need someone—or something—to say: move this first, measure again, and do not buy that thing yet.
The caveat remains obvious. AudioBro’s recommendations are only as reliable as the evidence supplied, the quality of its analysis, and the user’s willingness to follow through. A poorly taken measurement, incomplete room photograph, or inaccurate set of dimensions can still lead the entire exercise into the weeds. The Audio Science Review crowd will almost certainly dissect all of this across several hundred posts, followed by a “thank you, sir, may I have another” meeting held under strictly controlled conditions. That is 100% guaranteed.
Advertisement
Why Not Just Use Dirac Live?
Because AudioBro and Dirac Live are not the same thing.
Dirac Live is room-correction software that measures a system with a microphone and creates filters to correct frequency and timing issues. Dirac also offers Bass Control for subwoofer integration and ART for more advanced speaker cooperation and resonance control in compatible systems.
AudioBro does not replace that. It does not install filters inside your AVR, processor, or computer audio chain the way Dirac Live can. It is not a DSP engine.
Instead, AudioBro is more of a diagnostic and decision-support layer. It can help users understand whether the problem is placement, seating, reflections, subwoofer location, crossover choices, calibration settings, or room behavior before they start applying correction. It may also help people interpret what Dirac, Audyssey, ARC Genesis, YPAO, RoomPerfect, or REW are already telling them.
Advertisement
Advertisement. Scroll to continue reading.
In other words, Dirac asks, “How do we correct this system?” AudioBro asks, “What is wrong with this setup, and what should we fix first?”
Those are related questions, but they are not identical.
A properly set up Dirac system can be extremely powerful. But room correction is not a permission slip to place speakers badly, ignore subwoofer position, or pretend glass walls are acoustic treatment. AudioBro’s room-first approach is useful precisely because it focuses on the physical setup before assuming software can clean up the entire crime scene.
Advertisement
Who Is AudioBro For?
AudioBro is probably best suited to three types of users.
The first is the serious two-channel listener who owns good equipment but feels the sound is flat, boomy, vague, bright, or poorly focused. That person may not need new speakers. They may need better placement, a different listening position, basic treatment, or a clearer understanding of how the room is interacting with the system.
The second is the home theater owner who keeps adjusting dialogue, bass, and surround levels but never gets the system to lock in. Center-channel aim, subwoofer integration, seating position, crossover settings, and room layout can all sabotage an otherwise capable system.
The third is the measurement-curious user who has REW, Dirac, Audyssey, ARC Genesis, YPAO, or RoomPerfect data but does not fully understand what the results mean. AudioBro Pro and the Measurement Review option seem aimed directly at that group.
It is probably not for people who already work confidently with REW, understand modal behavior, know how to integrate multiple subwoofers, and can interpret calibration data without needing a second opinion. Those people may still find it useful, but they are not the obvious target.
Advertisement
The Bottom Line
AudioBro V2 makes considerably more sense than the original collection of separate tools. Bringing room photographs, REW files, calibration screenshots, placement analysis, and previous recommendations into one conversational workflow gives users a clearer path from “something sounds wrong” to “move this first and measure again.” Room Memory also adds genuine value for anyone changing equipment, integrating multiple subwoofers, or working through more than one room.
Founder Ateeq Sheikh does not hold a formal acoustical-engineering degree, but he brings more than 30 years of industry experience and currently reviews every paid Room Review personally. That human oversight matters. It does not guarantee that every recommendation will be correct, but it gives the one-off services more credibility than an automated report fired back by a chatbot wearing an imaginary lab coat.
The pricing also gives users several ways in. Starter costs $24.99 per month or $199.90 annually, while Pro costs $49.99 per month or $399.90 annually. For listeners who only need help once, the more sensible options may be the $97 Quick Room Review, $149 Full Room Diagnosis, or $199 Measurement Review. The subscription is easier to justify for users who regularly change equipment, add subwoofers, move house, or enjoy rebuilding their systems every six weeks because financial stability was becoming tedious.
The limitations remain obvious. AudioBro is only as reliable as the photographs, dimensions, screenshots, and measurements supplied by the user, and it still needs stronger public case studies showing detailed before-and-after results. It cannot confirm that the microphone was positioned correctly, that the measurements were valid, or that the user actually followed the advice.
Advertisement. Scroll to continue reading.
Advertisement
Still, AudioBro V2 could become a useful bridge between forum chaos, intimidating measurement software, automated room correction, and hiring a professional calibrator. Helping listeners fix the room before buying another amplifier, cable, or mystical accessory is a smart idea. AudioBro now needs to prove that its recommendations are consistent, repeatable, and worth paying for.
Rivian spinoff Also will finally start delivering its first e-bikes to customers next week, after months of delays related to unspecified supply chain issues.
The company told TechCrunch on Friday that the Launch Edition of its TM-B e-bike, which retails for $4,500, has started shipping from its manufacturer to its warehouse in the U.S. Also said it expects to deliver all Launch Edition bikes between next week and September.
Also began as a skunkworks project inside Rivian in 2022, after CEO RJ Scaringe started looking into making an e-bike to complement his portfolio of electric vehicles for the outdoorsy set. The company spent a few years tinkering with the idea, and even hired Jony Ive’s design firm LoveFrom to help with an early design, as TechCrunch first reported in 2025.
In March 2025, Rivian spun out Also as its own company, with $105 million in backing from Eclipse. The startup revealed its first e-bike, the TM-B, in October of last year. It originally targeted a “spring” 2026 ship date, but supply chain headaches got in the way, and the company pushed the delivery window to July.
Advertisement
“The primary factor driving our updated summer timeline is current stress on global supply chains. A rapid, industry-wide spike in demand for raw materials and electronic components has impacted key parts required for the TM-B. This has temporarily delayed our planned manufacturing ramp-up and pushed our first delivery dates past our original spring window,” the company wrote in June on a support page. “Our engineering and production teams are working around the clock to minimize these constraints without cutting a single corner on safety or quality.”
Also declined to say what components, specifically, caused the delay.
Also has big plans beyond the TM-B. The startup mostly refers to itself as a “vehicle” company and has plans to make four-wheel pedal-assist cargo vehicles for Amazon. The company is working on an autonomous delivery vehicle for DoorDash, too.
But for now, Also needs to focus on delivering its first e-bikes while navigating the next set of headaches for a company shipping products like these: customer service. On Friday, the last day of July, a number of customers were venting in a thread in the r/ALSOmicromobility subreddit about the repeated delays.
Advertisement
“I’m really frustrated by the lack of communication and the actual miscommunication/lies from Also regarding shipment timelines,” the original poster wrote. “Why do they keep making these promises about shipping timelines just to blow right past them without any communication or actual updates? It really makes no sense.”
“Hey we’ve still got a few business hours left in July. Maybe we’ll get an email later this morning ☺️,” a different user responded.
Not everyone was so patient.
“Couldn’t wait any longer and canceled my reservation,” another wrote.
Advertisement
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
The big picture: Putting your writing on the open web used to mean people could read it. Now, it also means dozens of crawlers can copy it into training datasets. Sure, anti-scraping tools such as robots.txt exist, but they only work if the bots themselves agree to stay away, which doesn’t always happen. Stricter measures were clearly needed, and now they have arrived in an innovative new form.
A Brazilian creative studio called Seneda & Abrucio has teamed up with Playtype, a Copenhagen-based type foundry, to build something that doesn’t rely on asking nicely to keep crawlers away. They call it ShieldFont, and it’s essentially a free, open-source web font with a twist. It works by showing you one sentence while presenting an AI scraper with a completely different one.
The thing is, you see rendered pixels on a screen. Most mass scrapers, on the other hand, simply grab the raw HTML underneath. ShieldFont exploits this difference through an automated process called OpenType glyph substitution. This technology is normally used to replace one or more typed characters with alternate glyphs that improve how text is rendered. In this case, however, entire words are swapped out, meaning a scraper can pick up only gibberish from the webpage.
Advertisement
Those swapped words are not picked at random, however. The studio’s dictionary pairs every word with another of the same grammatical type, so nouns get nouns and past-tense verbs get past-tense verbs. The words are sorted into roughly 250 pools that account for factors such as whether a noun is abstract or plural. About a quarter of the words in any given block are swapped this way.
Keeping the grammar clean matters because AI firms run scraped text through quality filters that discard anything that reads like nonsense. Seneda & Abrucio ran shielded text through FineWeb-Edu, a quality filter used to assemble a large public training dataset, and found that about one in 10 passages that passed before shielding still passed afterward.
Whatever gets through is fluent enough to be retained yet wrong enough to be useless at the same time. In fact, 55.8% of shielded passages in the studio’s testing no longer made the original factual claim.
That said, because the whole defense rests on scrapers reading code rather than screens, taking a screenshot of a shielded page and running OCR on the image can still recover the real words. Screen readers used by blind readers also work from the code, so they read the decoys aloud. ShieldFont ships with a beta feature that provides those readers with the real text instead.
Advertisement
For now, ShieldFont only handles English. The code can be found on GitHub for anyone who wants it. Developers and writers can simply install it as a React component to their websites.
Would you trust a ransomware extortionist to delete the data they stole? One bank certainly wants you to. Well over a month into a ransomware cleanup job, River Financial Corporation tells regulators that it “took steps to attempt to suppress the affected data, including obtaining representations from the threat actor that it deleted the data in its possession.”
In its Form 8-K filing with the SEC, River Bank did not explicitly state whether or not it paid any of the criminals’ ransom demands, although ransomware crooks are not commonly known to offer a victim data deletion for free.
The Register asked the company for a more explicit comment on this matter, but it did not immediately respond.
River Bank first disclosed its cyber woes to the Securities and Exchange Commission (SEC) on June 16, admitting from the outset that ransomware had been deployed across portions of its servers.
In response, it took affected systems offline, disabled admin accounts, and brought in external incident responders to determine the full scope of the damage.
Advertisement
Only July 6, messaging suggested it was aware that some data was “potentially impacted” by the attack, before admitting that certain data was removed from its environment four days later.
A side note on cyber verbiage
“Removed” is an interesting and unusual word to see in a disclosure when describing what an intruder did with their access.
The usual nomenclature is “stolen,” despite in most cases it being more accurate to say data was “copied” from a victim’s environment.
Some of the more nebulous announcements say data was “acquired” or “retrieved.” Sometimes “affected.”
Advertisement
The more cowardly ones simply stick with “accessed,” even though the word does not denote a change of ownership.
By July 10, River was aware the data had been removed, and two class action lawsuits had been filed against it, to top things off.
A week later, it told investors that an additional two class actions had been filed, bringing the total to four.
River has not yet completed its investigation, per its most recent filing, and therefore has not confirmed the full scope or impact of the attack. ®
An anonymous reader quotes a report from Reuters: OpenAI has discovered other instances in which autonomous agents have escaped containment as the company expands its investigation of the hacking incident at tech firm Hugging Face that drew global attention this month, two people familiar with the matter said on Friday. The new breakouts were uncovered during the company’s publicly announced investigation into how one of its agents escaped what was meant to be a contained testing environment this month, the two people said, and OpenAI is now looking into those instances as well. One of the sources said that the escapes were limited in nature and that none of the agents were thought to have left OpenAI’s network.
An OpenAI spokesperson referred to a statement issued by the company on Tuesday that said it was reviewing “broader activity from our models” in addition to the Hugging Face intrusion. The discovery of additional rogue behavior at OpenAI, even if limited in nature, could feed growing appetite for regulation coming out of the White House and elsewhere. The expanded investigation by OpenAI was launched shortly before its primary rival, Anthropic, disclosed that its models were also responsible for a series of break-ins that led to breaches at three other companies dating back to April, according to the two sources and a third source familiar with the matter. The recent discovery of other past breakouts at OpenAI has not previously been reported.
AI safety experts said the new disclosures paint a portrait of a group of cutting-edge labs whose ability to develop dangerous autonomous hacking agents outstrips their ability to keep them under control. “We have a whole industry where the people designing, developing and putting out these tools aren’t keeping up themselves to responsibly develop these things and keep them safe,” said Maurice Chiodo, a mathematician who works at Cambridge University’s Center for the Study of Existential Risk. Reuters could not establish exactly how many incidents OpenAI investigators found or the timings or circumstances under which they occurred. The three sources said OpenAI and outside experts were examining log data from earlier in the year in a bid to understand what took place.
Although generally glass isn’t associated with touch-sensitive surfaces, the addition of an ITO (indium tin oxygen) coating adds the exciting property of not only being transparent to the visible light part of the electromagnetic spectrum, but also of being electrically conductive. The logical result is that fine folk like [Sokol] simply had to use their newly acquired ITO-coated glass to make a button out of.
Here the easy option is of course to just use it as a capacitive sensor where the conductive ITO layer is used for the capacitive charge and the glass provides the insulator, but here we see it demonstrated how to create a pressure-sensitive implementation instead.
The measured conductivity on the ITO-coated glass in the video is pretty good, at just over 20 Ohm. This thus makes said capacitive button very easy to achieve. To make it a touch-sensitive button, two pieces of glass are used, with the ITO sides facing. Paper is used to create a spacer, after which the slight flex of the glass allows for the two ITO surfaces to touch, completing the circuit.
Advertisement
This is somewhat similar to how resistive touch screens work, with the position of the finger or stylus determined by the resistance between the two sides. In a hobbyist setup this would make it fairly easy to create a multi-position touch screen using just two pieces of glass and some firmware.
On a laptop screen in a dimly lit tent near the Donetsk front, a Ukrainian drone team steers its aircraft into the turret of a Russian T-72 and glimpses the start of an explosion before the picture dissolves into static. The strike is uploaded, verified, and scored against the point value assigned to the tank. The unit climbs a public leaderboard that ranks hundreds of drone teams, and the points are currency: a higher score buys better equipment, faster, from an online marketplace the warfighters compare to Amazon.
Washington is about to decide how the federal government will parcel out access to the most powerful AI, and it is drifting toward concentrating that capability in a few chosen hands, rationed by criteria no one outside the process can see. A country with foreign invaders on its own soil has spent the past year learning to do the reverse—and winning back ground as it does. From Luhansk to Lviv, Ukraine puts its best tools in the hands of whoever can use them and shares what it knows about the enemy as fast as it safely can, openly and by rule.
Behind the leaderboard sits a set of arrangements Ukraine built under fire. A marketplace lets frontline units order drones directly from hundreds of manufacturers, most of them small shops scattered across Ukraine. A procurement cycle that once ran months now takes days, and new designs reach the trenches within about a month of leaving the workbench, because the units doing the fighting, not a distant acquisition office, decide what they need in the field. Furthermore, their feedback goes straight back to the manufacturer, sometimes the same day. Because the manufacturing is dispersed rather than massed, no single Russian strike could ever change much.
Ukraine has been just as willing to share what it learns. Late last month its defense ministry opened a platform called TrophyLab that hands the technical anatomy of captured Russian weapons—schematics, known vulnerabilities, even physical samples—to a deliberately wide circle: allied militaries and intelligence services, and hundreds of Ukrainian and partner-country firms. Access is vetted and revocable, governed by published criteria. The premise is that knowledge of a threat is worth more shared than hoarded. This should be a rule everyone can see, rather than the whims of a distant official.
Advertisement
That combination, wide but rule-bound, is exactly what the executive order the White House issued in June fails to deliver. Faced with AI systems that can now find software flaws faster than any human team, the order promises early access to the most capable models to a few “trusted partners”—a phrase it never defines, routed through a classified process. It calls the arrangement voluntary. In practice it has not been: under national-security and commerce authorities the administration has already restricted, suspended, and then cleared frontier models, with no published criteria anyone outside the process can point to. Ukraine’s leaderboard may be a crude way to run a war, but it is at least a rule—public, legible, the same for every unit.
The deeper problem is what that opacity does. Ukraine found that capability does the most good spread widely, that a defense holds because it has no single point of failure, and that threat intelligence should travel by rule rather than favor. A trusted-partner tier governed by undefined discretion inverts all three: it concentrates the best tools among those already best equipped, builds the very chokepoint Ukraine works to avoid, and turns shared knowledge into something rationed by judgment no one can inspect. The United States already runs sector-based centers for sharing threat intelligence; the question the framework raises is not whether to centralize but whether the flow reaches the defenders who need it or stops at a favored few.
And there are real lessons for the United States. Ukraine’s openness may look like the underdog’s strategy, and the United States is the wealthiest, most powerful country on earth—but national strength does not mean every system is strong. The defenders who most need help are not the money-center banks and wealthy university hospitals; they are smaller institutions that, despite non-specific promises they’ll be helped, seem unlikely to benefit from this system as it’s set up. For them, a head start reserved for the already-strong is no help at all.
Ukraine did not arrive at any of this by design. It was forced into it, and used a mix of openness and clear rules to stop a much larger power in its tracks. Washington has the luxury of choosing on purpose but may be drifting towards a system governed by whims and favoritism rather than clear rules and standards.
Advertisement
Eli Lehrer is president and co-founder of the R Street Institute.
You must be logged in to post a comment Login