Start with the vents before you reach for a screwdriver.
Lukman Abdul Aziz/Shutterstock
Your laptop fan has probably spent its entire life working inside a cramped chassis, so dust eventually gets an invite. Let too much of it build up around the vents, fan or heat sink and airflow can be hampered. Over time, restricted cooling can result in thermal throttling, which is when the processor reduces its performance to keep temperatures under control.
Fortunately, cleaning a laptop fan doesn’t necessarily involve disassembling the laptop. For routine maintenance, turn the laptop off, unplug it and use short bursts of electronics-safe compressed air through the vents. Lenovo recommends cleaning a laptop fan every three to six months, depending on the environment.
When dust is packed deeper inside, it makes sense to open the laptop. But be aware of what you are getting yourself into. Depending on the machine, removing the bottom cover may expose the fan or start an unexpectedly intimate tour of several thousand dollars’ worth of electronics.
Advertisement
Try cleaning the fan without opening your laptop first
Nurma Agung Firmansyah/Shutterstock
Start simple. You may be able to remove most of the loose dust without even touching a screwdriver.
Turn off the laptop and disconnect all cables and peripherals. If it has an external battery that can be easily removed, take it out as well.
Find the intake and exhaust vents. Look for vents at the base, sides and around the display hinge. Some laptops hide their exhausts near the hinge, so don’t assume that every grille you need will be staring back at you.
Clean away any loose dust around the vents. For accessible areas, use a lint-free cloth or ESD-safe brush. Do not poke tools deep into the grille.
Use short bursts of compressed air. Keep the can upright and leave some distance between the nozzle and vent. Excessive air pressure from, say, an air compressor can damage fan blades, though there isn’t one universal nozzle distance for every laptop.
Do not keep blasting the fan continuously. Forcing the fan to spin rapidly isn’t a good idea. Use short bursts instead.
If canned air isn’t your preferred method, an ESD-safe brush, non-static cloth or hand-powered bulb blower are other options. And drop the WD-40. Standard WD-40 Multi-Use Product is designed to lubricate, displace moisture and protect against corrosion. That’s a completely different issue.
Advertisement
Opening the laptop can turn this into a much bigger job
Lianaruchka/Shutterstock
If airflow still appears to be blocked, or you see dust built up inside, removing the bottom panel provides better access. This is also where generic instructions stop being particularly helpful.
On some laptops, the fan is visible and can be removed independently. Others have two fans paired with a shared heat sink or vapor chamber, and if one fan is clean but the other fan, heat sink or exhaust fins are still clogged, cleaning one fan will do little. The fan blades aren’t always the only problem either. Dust can build up where air is forced between the closely spaced heat-sink fins.
Before going too deep, check the service manual for your specific model. For instance, Dell’s Alienware m16 R2 has separate left and right fan connections, and removing the entire cooling assembly requires taking out six regular screws and loosening six captive heat-sink screws. Dell warns that the procedure is intended for authorized service technicians only.
Some machines take it a step further. The Alienware m16 R1 requires removing the SSDs, wireless card, top heat sink, small fan, rear I/O cover and battery, then following nine system-board removal steps before you can access the fan and heat-sink assembly. The cooling assembly itself is held by eight captive screws. Dell also cautions against cleaning its Element 31 thermal material with an alcohol wipe because it can dissolve the grease into conductive metal particles and could cause an electrical short.
That’s the line worth respecting. If the fan requires lifting the heat sink or vapor chamber off the CPU or GPU, you’re moving from dusting to a job that might involve thermal paste, pads or other interface material.
The concept behind Pocket Tank is relatively simple—it’s a small device that displays a virtual tank with a bunch of little fish swimming around inside. It’s based on the Waveshare ESP32-S3-Touch-AMOLED-1.8, which, if you’re wondering, is an ESP32-S3 with a 1.8″ screen attached, all wrapped up in a convenient plastic housing.
Thanks to the powerful microcontroller, there’s plenty of grunt on tap to run and display a small simulated fish tank. [StratoBuilds] whipped up a system wherein fish movement and animations are handled by regular code running at 25-30 fps, while the fish’s decision making is handled by a custom large language model that was condensed down to run on the ESP32 itself. As the fish swim around the tank, the situation is observed by the LLM and the fish’s current goals are changed accordingly depending on what’s going on. Much like a Tamogotchi, there are regular maintenance tasks for the user to handle, too, like cleaning the tank and feeding the fish to keep them alive.
Advertisement
The blog post and YouTube video do a great job of explaining the project; files are on GitHub for those that wish to tinker more directly. It’s funny, because when we normally look at fish tanks, we’re talking about real ones.
Four decades after Walter Röhrl and Markku Alén drove Lancia’s Rally 037 to the 1983 World Rally Championship, a small Italian workshop in Cuneo has given that last rear-drive title winner a second life. Kimera Automobili, run by former rally driver Luca Betti from Villa Kimera about 100 kilometers south of Turin, limited the EVO37 to 37 cars. Number 018 now sits in Broad Arrow’s catalog as lot 158 for the Zoute Concours Auction on Friday, October 9, 2026, at Approach Golf in Knokke-Heist, Belgium.
Kimera used the same starting point as the original manufacturer and ran with it: the donor Lancia Beta Montecarlo center section was stripped, reinforced, and improved with a glossy new carbon-fiber shell. Behind all of this was a crew that knew what they were doing, including Sergio Limone, the man who had led the 037 and Delta S4 to great success, and Claudio Lombardi, Lancia’s former rally engine designer who had gone on to do the same for Ferrari in F1, both of whom gave the project their approval. The bodywork was then bolted to the chassis, and Italtecnica created a brand new 2.1 liter, 16 valve four-cylinder engine from the ground up. They preserved the 037’s supercharged configuration but added a turbocharger, resulting in a snappy 505 PS and 550 Nm of torque sent to the rear wheels via a fast six-speed Dana Graziano manual gearbox. The top speed is rated as 310 km/h, with a 0-100 km/h time of just 3 seconds, which is not bad. The vehicle features Öhlins double-wishbone suspension and Brembo carbon-ceramic brakes with four-piston calipers for stopping power.
CUSTOM MUSTANG RACE CAR – This LEGO Speed Champions Ken Block’s ’65 Ford Mustang Hoonicorn V1 (77262) building toy for boys and girls ages 9 years…
AUTHENTIC DETAILS – Builders will recognize cool features from the car’s debut in the 2014 Gymkhana SEVEN film, including exposed velocity stacks on…
KEN BLOCK MINIFIGURE – The included Ken Block minifigure features a Hoonicorn hat and jacket, plus an extra helmet accessory for added play value
This vehicle left the workshop in March 2025 and has since traveled a total of 237 kilometers. Kimera’s Luci del Bosco paint job is a deep, rich metallic brown inspired by the old Lamborghini Miuras and Countachs. The gold wheels and beige leather upholstery over carbon fiber chairs give the cabin a relaxed feel, while the exposed gearlever is adorned with a wooden gear knob. LEDs light the road up front, and there’s air conditioning, ABS brakes, a digital rear view camera, and parking sensors to keep things polite without interfering with the exposed carbon, which is exactly what you want to see.
When this project first got off the ground in 2021, the asking price ranged between €450,000 and €480,000. Since then, the market has moved on, and Broad Arrow thinks that this particular specimen, number 018, is now valued between $950,000 and $1,150,000. Kimera has informed the Broad Arrow team that they will gladly assist with import and registration if the future owner is in Europe or the United States, and will even adjust the specifications to suit the buyer if they prefer something different. The tax issue is equally easy; because this is a VAT-qualifying sale, both the hammer price and the buyer’s premium are subject to tax.
The auction of this car will take place on October 9, 2026 as part of the Zoute Grand Prix Car Week, with a public viewing on the 7th and 8th and bidding beginning in the afternoon of the ninth. It’s a rare opportunity to own an original 037 Stradale that is this new and in this condition, and if that’s not enough, Kimera is still willing to re-spec the thing if the buyer has any other ideas. [Source]
Renault is bringing one of its most recognisable performance cars into the electric era with the Renault 8 Gordini Concept, a two-seat electric coupé inspired by the rear-wheel-drive icon that debuted in 1964.
The concept combines the visual language of the original R8 Gordini with a much more aggressive modern design. It has a low, wide stance, motorsport-inspired proportions and a 270hp electric motor. Renault says the project is part of its wider effort to revisit important models from its 128-year history through one-off creations.
Renault unveiled the concept on September 24 at Renault Carwalk, and it is scheduled to appear at the Paris Motor Show from October 12 to 18.
The classic Gordini gets a radically different electric makeover
The original Renault 8 Gordini arrived in 1964 with a 95hp rear-mounted engine and rear-wheel drive. It became known for delivering racing-inspired performance in an affordable package and served as a training ground for drivers including Jean Ragnotti. Its distinctive double white stripe eventually became a defining visual feature.
Advertisement
The new concept keeps the rear-wheel-drive character but replaces the petrol engine with a 270hp electric motor. Measuring 4.12 metres long, 1.88 metres wide and 1.27 metres tall, the coupé sits on 19-inch front and 20-inch rear wheels. Its proportions are deliberately closer to a modern rally car than the four-door original.
Renault 8 Gordini Concept
Renault has also carried several familiar details into the new design. The car gets six round headlights, squared-off wheel arches, a modernised Gordini badge and the iconic double white stripe. The stripe is no longer simply decorative, with Renault incorporating it into various structural and design elements of the car.
The design was created entirely in-house. More than 300 sketches were submitted during an internal Renault Design competition before two proposals were developed into scale models and combined into the final concept.
A two-seat EV focused on driving rather than practicality
Inside, Renault has taken a similarly minimalist approach. The cabin features brushed aluminium across the dashboard and controls, contrasted with Alcantara upholstery. Digital round displays echo the circular headlights, while bucket seats and a prominent stopwatch button reinforce the car’s motorsport-inspired character.
Renault describes the concept as part of its effort to connect its heritage with future design rather than simply recreate old cars. The R8 Gordini follows previous projects including the R17 electric restomod x Ora Ïto and Renault 5 Diamant.
Advertisement
Renault 8 Gordini Concept
For now, this remains a concept car, and Renault’s media page does not confirm that it will enter production. The company does say the concept will become part of its historical collection, alongside other vehicles and archive material at the future Renault Collections museum in Flins, expected to open in around 15 months.
So while you probably won’t be ordering one from a Renault showroom anytime soon, the electric R8 Gordini shows how Renault is imagining its performance heritage in an EV era.
PCB circuits are cool, but you know what is cooler? Terminator circuits that’s what! And what if the same material that makes Terminator circuits could also be used for smart heat sinks, flexible circuits, and self-healing material properties? Well, that is exactly what the lab at Virginia Tech’s VT MADE Lab has created, presented by Joel from [3DPrintingNerd].
So what does a Terminator circuit actually entail? Well, just like in Terminator 2, the circuits are made of liquid metal. Specifically, small drops of liquid metal alloy made of gallium and indium. These drops are contained within a matrix of PDMS polymer, which contains the magical liquid for conductivity, thermal and electrical . This makes a flexible and stretchy composite which can even self-repair when punctured or cut by bridging the
Little “bubbles” of liquid alloy form a composite that will pop when applied over a threshold of force or puncture.
broken circuit with the liquid alloy. Having a polymer matrix allows this self-repairing property but also makes the material insulating by default, only allowing current to flow after selectively “popping” the matrix bubbles.
To create something with the composite material, you’ll find it similar to many other resin-based materials. You can pour, mold, and even 3d print a custom geometry. A short bake later and you get a solidified model made for whatever custom flexible circuitry you have in mind.
While this process requires chemicals, polymerization reactions, and a taste for liquid alloys, that shouldn’t stop you from trying out flexible electronics. For a more hands on method to flexible electronics check out this glove with circuits running throughout!
If you want the styling of a 1967 Ford Mustang without the complications of owning an older car, you could always build it yourself. That’s what YouTuber 1194video did, anyway. Using all new components and materials, he got all the measurements of an original 1967 Mustang and began a tough assembly process.
1194video started with the structure and floor by using stamped-in bevels as alignment guides. He then hole-punched and screwed the side panel before welding. Before committing to any welds, he made sure to carefully measure everything, making sure the quarter panel, roof line, and B-pillar all lined up. Getting the body squareness right was one of his biggest challenges, requiring him to strap and pull the body straight before welding.
Advertisement
When it came to the roof structure, 1194video installed front and rear roof braces, then set the roof skin on top to ensure it sat correctly against the body side rails. At this stage, he noticed a bend in the roof skin that had to be corrected. He then screwed and clamped the tail light panel, quarter panels, and other parts of the fastback rear structure into place, trimming off excess metal. This was followed by welding the inner and outer wheel tub sections, then installing the doors and trunk lid. Safe to say, it was not an easy process.
Advertisement
One of the most important and overlooked parts of building a new 1967 Mustang
One of the biggest focuses of building a brand-new 1967 Ford Mustang was rust protection. 1194video felt he had to be proactive, coating various welding points and panels with primer and high-heat paint before enclosing them. He noted that wheel tub welds and cowl panels are common rust points for this model. At one point he said: “It could settle up in between these two pieces of steel and then cause rust and rot out like all the others in the world do.”
Classic Mustangs are known for falling victim to rust – an unfortunately common problem with classic cars – and the wheel wells are a common spot to find hidden damage. This is because this component sits so close to the ground, especially if you drive on roads with snow, salt, and loose stones. Snow and rain can also splash upwards and get the Mustang’s lower body. If you see faded or chipped paint in that area, it could be prone to rusting.
After the initial body work video, 1194video posted a follow-up video tackling a step most home-built Mustangs never have to deal with: getting a legitimate title and VIN for a car assembled entirely from new reproduction panels. This entailed meticulous photography and receipt compilation, heading to the clerk’s office, and then having a state inspector verify the car was legal and contained no stolen parts. A week later, the title showed up in the mail. This specific Mustang isn’t ready for the road just yet, but one surprising obstacle is now out of the way. If you plan on building a custom vehicle yourself — or even swapping engines — you’ll need to check your state’s regulations.
Anthropic’s Claude Opus 5.5 appears to be changing how it writes, with new analysis showing fewer obvious AI writing patterns, shorter sentences, and simpler wording compared with Opus 5.
Claude Opus 5.5 is not only one of the best models for coding, but it also appears to be a bit better at writing, as Anthropic appears to be changing how AI writes.
According to Arena, an AI benchmarking tool, Opus 5.5 has fewer obvious AI writing patterns, so you’re less likely to create AI slop content with this model.
It also found that sentences are now shorter, which means you have fewer long sentences and simpler wording compared with Opus 5.
Advertisement
Arena analyzed high-reasoning Text Arena responses from August and September 2026 and observed that 10 of 12 writing measures moved in what it considers a better direction.
Interestingly, Arena’s data confirms that Opus has almost stopped using em dashes, which was one of the biggest signs of AI-generated content.
Claude writing pattern has changed
Source: Arena
Opus 5 used 15.2 em dashes per 1,000 words, while Opus 5.5 dropped that figure to just 0.8, a reduction of roughly 95%. It also found that semicolon usage fell sharply from 6.10 to 1.64 per 1,000 words.
The newer model writes shorter sentences, averaging 10.03 words compared with 12.14 for Opus 5. However, there is one obvious tradeoff, and that is that Opus 5.5 is more verbose.
In other words, average answers increased from 453 to 481 words, making it the longest-writing Opus model in the comparison.
Advertisement
More lately, AI models have focused mostly on the coding side of things, so it’s quite interesting to watch Anthropic change how Claude writes, and if anything, you’ll see fewer em dashes on the internet.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Across the infrastructure layer that powers AI applications, Markdown has been emerging as a new standard. More providers are turning to it as the default output for anything a model needs to read, and moving beyond JavaScript Object Notation (JSON) as the go-to, one-size-fits-all format.
This real, ongoing shift reflects how large language models are trained, how chat interfaces render answers, and how developers actually build with tokens, context windows, and cost in mind. And there is good reason for this adoption.
Markdown fits how models work
Large language models have been trained on enormous amounts of Markdown. Think of documentation sites, README files, technical blogs, forum threads, knowledge bases and so on. That exposure means models already speak Markdown fluently; they know how to analyze its headers, lists, tables, and code fences, and treat them as semantic signals rather than noise.
At the same time, user-facing chat interfaces can already render answers from Markdown. When a model outputs Markdown, the front end can display it cleanly without extra transformation. When the same model ingests Markdown, it receives information in a form that mirrors its training distribution and the way it is expected to respond. The result is a more natural input-output loop than feeding models dense, nested JSON that must be mentally unpacked before use.
Advertisement
If you look at things from a token perspective, Markdown is also the leaner approach. It strips away structural overhead and keeps the informational payload. For AI agents that must fit large amounts of context into a limited window, that efficiency translates directly into more relevant content per request and lower cost per inference.
A visible trend
The move to Markdown isn’t speculative either. It’s already being encoded in best-practice guidance from major model providers. OpenAI’s prompt engineering documentation explicitly recommends structuring developer messages with Markdown headers, bullet lists, and tables where helpful. The guidance advises using ‘##’ for major sections, inline backticks for code, and clear hierarchical formatting to improve model compliance and readability.
Third-party prompting guides are echoing this same pattern. They use Markdown headings to create section breaks, lists for enumerations, and tables for comparisons. Several analyses note that Markdown is more token-efficient and more naturally understood by models trained on documentation, which makes it a preferred formatting tool for complex prompts, especially with newer GPT-5 series models.
Infrastructure providers agree
API and data providers have also been won over by Markdown. Where JSON once ruled as the universal interchange format, many are now offering Markdown variants optimized for LLM consumption. The rationale is exactly the same: they want to reduce token bloat, simplify parsing for agents, and align with how models are prompted and how answers are displayed.
Advertisement
SerpApi, a nine-year-old, search-data API company, recently launched Markdown output across all 100+ of its APIs at no extra cost. SerpApi serves developers, researchers, and Fortune 500 companies with structured insights from Google, Bing, YouTube, and other sources. The feature lets developers request search results in a token-light Markdown format instead of JSON, aimed specifically at AI agents and LLM-powered applications. No new endpoint is required, and the format is requested via a query parameter, route extension, or header on existing integrations.
In a real-world example from SerpApi’s own benchmarks, a single Google search for “coffee” costs 24,723 tokens as JSON and 6,435 tokens as Markdown, adding up to a 74% reduction. When combined with field filtering, the same response dropped further to 1,298 tokens. Across its APIs, SerpApi reports average token savings of roughly 50%, with some endpoints seeing reductions of up to 90%.
Token savings across eight APIs, according to figures published by SerpApi. — Credit: SerpApi
These numbers matter because search results are among the noisiest, most nested payloads that agents ingest. JSON responses carry redirect links, favicons, tracking parameters, and deeply nested metadata that models do not need to reason over. Markdown output, in contrast, preserves the core information, such as titles, snippets, links, prices, and ratings in tables and lists while automatically stripping much of the internal tracking noise and duplicate fields.
Developers can access the new Markdown format by adding ‘output=md’ to the query string, calling the ‘/search.md’ route, or setting an ‘Accept: text/markdown’ header. The responses include YAML frontmatter for metadata, structured Markdown tables for result sets, and native inline links, all designed to be dropped directly into prompts or agent memory.
What this all means
As more of the web gets consumed by agents instead of humans, the infrastructure layer will increasingly optimize for machine readability over human-friendly nesting. JSON remains essential for programmatic manipulation and strict schema enforcement, but for the context ingestion phase of AI workflows, Markdown is emerging as the new default.
Advertisement
In the coming months, one should therefore expect more data providers to offer Markdown variants of their responses, especially for search, e-commerce, maps, and content APIs where token efficiency has an immediate impact on cost and performance. Prompt templates and agent frameworks are also likely to standardize on Markdown sections, tables, and lists as the canonical way to present retrieved context to models. Tooling should also evolve around measuring and minimizing token footprint, with Markdown as a primary lever.
For developers building with LLMs today, the writing is on the wall. When feeding external data into models, one should prefer formats that match how models are trained and how they output. Markdown is no longer just a documentation tool. It’s becoming the new lingua franca between search data and AI models.
Artificial intelligence has spent the past year learning how to write songs, create fake artists, imitate real ones, manufacture album covers, and upload music at a rate that would make Prince during his vault years look lazy. Qobuz would now like its subscribers to know when some of that music was made by a machine.
The French streaming service has officially rolled out an in-app tag identifying music that its proprietary system determines was generated by AI. That fulfills a promise Qobuz made earlier this year when it published its AI Charter and began scanning both new releases and its existing catalog for synthetic content.
The label itself is useful, but the numbers behind it are far more interesting. Qobuz says just 0.38% of streams on its service currently come from tracks identified as AI-generated, while 60% of streams from those tracks are deemed fraudulent by its anti-fraud systems and excluded from royalty payments.
Qobuz has also removed more than one-third of AI-generated albums with no listening activity from its search engine, representing roughly four million tracks. Those recordings have not necessarily been deleted from the catalog; Qobuz specifically says they have been removed from search.
Advertisement
That difference matters because the AI music problem is increasingly not about somebody using generative software to help finish a song. It is about enormous quantities of synthetic material being uploaded cheaply and rapidly, sometimes accompanied by artificial streams designed to siphon money away from the royalty pool.
Related Reading:
Why Qobuz Is Doing This
Qobuz has been heading in this direction since February. Its AI Charter states that editorial recommendations including playlists, Albums of the Week and Qobuzissimes remain selected by human editors, while its personalized discovery tools are designed to prioritize music drawn from those editorial selections and other trusted sources.
That philosophy now extends directly to AI-generated recordings. When Qobuz identifies music as AI-generated, subscribers can see that information instead of having to investigate whether the singer suddenly appearing in front of them has ever actually inhaled oxygen.
More importantly, Qobuz says identified AI-generated material is excluded from its editorial recommendations. That helps put the remarkably low 0.38% share of listening into context because synthetic content may exist on Qobuz, but the service is not deliberately placing it alongside human artists in its curated discovery channels.
That approach says a lot about how Qobuz views its role. It is not simply offering access to a gigantic catalog and leaving listeners to sort out the mess themselves; it is making an editorial decision about what deserves active promotion.
Advertisement
The 60% Number Is The Real Story
The most troubling figure is not how much AI music Qobuz subscribers are actually listening to. It is what appears to be happening around those streams.
Qobuz says 60% of streams associated with tracks it has identified as AI-generated are currently considered fraudulent by its systems. Those plays are excluded from royalty reporting and payouts, and Qobuz says content can also be removed when it detects fraudulent practices.
Advertisement. Scroll to continue reading.
That suggests the immediate threat is not that listeners are abandoning musicians for endless AI-generated albums. On Qobuz, at least, the available data suggests almost the opposite.
Advertisement
The larger problem is scale because generative systems can produce enormous quantities of music at almost no marginal cost. Upload enough tracks, manufacture enough plays, and even tiny payments can become meaningful when multiplied across millions of recordings.
Streaming was not designed for an environment where someone can effectively operate an automated record label containing more releases than entire generations of musicians could create. Qobuz is trying to prevent that volume from distorting discovery and pulling money away from legitimate rights holders.
For listeners, that makes the AI tag more than an ethical warning sticker. It is one visible part of a much larger effort to stop streaming catalogs from turning into digital landfill.
How Is Qobuz Different From TIDAL?
TIDAL has arguably taken the harder line when it comes to money. As we reported previously, the service labels recordings it determines are wholly AI-generated and does not attribute royalties to them.
Advertisement
Subscribers can also disable AI-labeled recordings entirely in Settings. Once enabled, that control prevents those recordings from playing and gradually removes them from personalized recommendations as those recommendations refresh.
TIDAL can also remove synthetic music tied to impersonation, deceptive behavior, high-volume uploads or fraudulent streaming. That gives its subscribers something Qobuz has not publicly announced: a direct “I don’t want AI music”switch.
Qobuz takes a somewhat different approach by combining its own detection technology with editorial curation, search controls and fraud enforcement. TIDAL gives listeners more explicit control over whether AI music enters their experience, while Qobuz is attempting to keep much of the questionable material from becoming prominent in the first place.
Neither service is simply banning AI. The distinction is how aggressively each one separates synthetic content from the normal machinery of discovery and payment.
Advertisement
Spotify Has A Different AI Problem
Spotify’s approach has focused heavily on identity and disclosure. Its AI Persona system is designed to identify artist profiles whose public identity may represent an AI-generated person rather than an actual human being, while those profiles can be excluded from editorial and algorithmic recommendations unless listeners deliberately engage with them.
That is not quite the same thing as what Qobuz is doing. Spotify’s badge tells listeners something about who or what the artist supposedly is, whereas Qobuz is identifying the recording itself as AI-generated.
Spotify has also supported richer AI credits so artists, labels and distributors can disclose whether artificial intelligence contributed to vocals, lyrics, instrumentation or production. At the same time, it has tightened policies around impersonation, spam and other deceptive uses of generative technology.
Advertisement. Scroll to continue reading.
We have already covered the tension inside that strategy. Spotify wants stronger protection against synthetic impersonation and AI spam while continuing to explore licensed generative tools that could allow subscribers to manipulate commercially released music.
Advertisement
That makes Spotify’s position increasingly about authorization rather than opposition to AI itself. Synthetic deception is the problem; transparent, licensed and commercially useful AI remains very much on the table.
Apple Music Is Relying More On The Supply Chain
Apple Music is approaching the problem from another direction by leaning heavily on metadata supplied by labels and distributors. Its AI transparency framework can indicate when artificial intelligence materially contributed to artwork, a sound recording, a composition or a music video.
That model potentially provides more nuance than a single AI-generated label because Apple can distinguish where the technology was used. A recording created entirely by software is obviously a different proposition from an album where AI was used only for artwork or some element of post-production.
The weakness is equally obvious: much of that information depends on the people delivering the content reporting it accurately. Qobuz, by comparison, has built its own detection system rather than relying entirely on disclosure from the supply chain.
Advertisement
Apple’s approach may ultimately provide the most detailed metadata if everybody behaves. History suggests that last part deserves an asterisk the size of a record store.
Why Should Listeners Care?
Nobody should need a forensic-audio degree to determine whether the artist being recommended to them exists. Streaming services already exercise enormous influence over how music is discovered through playlists, recommendations, search placement and editorial promotion.
When synthetic music can be generated almost infinitely, allowing it to flow into those systems unchecked creates a basic mathematical problem. Human artists cannot release 10,000 albums before lunch, while software certainly can.
That makes transparency important, but discovery policy may matter even more. Qobuz’s most significant decision is not adding a small AI tag beside a recording; it is keeping identified synthetic content outside its editorial ecosystem while using fraud detection to prevent suspicious streams from entering royalty calculations.
Advertisement
That distinction matters directly to listeners because discovery is part of what they are paying for. A streaming service filled with endless automated uploads is not inherently more useful just because the catalog number keeps getting larger.
There is also a trust issue. If a recommendation engine places something in front of you, knowing whether it came from an actual artist or a synthetic production should not require investigative work after the fact.
The Bottom Line
Qobuz is not banning artificial intelligence from music, nor is it claiming that every use of AI is inherently fraudulent. It is drawing a much clearer distinction between AI used as a creative tool and synthetic content generated at industrial scale, while giving subscribers more information about what they are hearing.
Advertisement. Scroll to continue reading.
Advertisement
The most revealing statistic remains 0.38% because, despite the enormous volume of AI material being added to streaming catalogs, Qobuz subscribers appear to spend very little time listening to it. At the same time, the company says 60% of streams attached to identified AI-generated tracks are being flagged as fraudulent.
Those figures only describe activity on Qobuz, so they should not be treated as evidence for the entire streaming market. They do, however, raise an obvious question about the narrative that consumers are demanding an endless supply of machine-generated music.
If the listeners are barely listening and a large percentage of the plays are fraudulent, perhaps the machines are not only making the music.
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.
Google’s Mandiant and Threat Intelligence Group (GTIG) say this new technique has allowed the threat actor to once again target PeopleSoft servers that had not applied security updates and instead blocked access to the vulnerable PSEMHUB endpoint using a WAF.
On June 10, BleepingComputer first reported that the ShinyHunters extortion gang was targeting Oracle PeopleSoft servers using a zero-day vulnerability, allowing them to steal data from 100 organizations.
Google also reported that same day that ShinyHunters, whom they track as UNC6240, was exploiting the CVE-2026-35273 flaw in attacks on the education sector, confirming BleepingComputer’s reporting.
At the time, Mandiant advised organizations that could not immediately install the security updates or disable the Environment Management Hub to block external access to the vulnerable `/PSEMHUB/*` endpoint.
However, in a new report, Google says ShinyHunters has now modified its exploit to bypass WAF rules that look for this literal path, rather than encoded versions of it.
For example, instead of sending requests to:
Advertisement
/PSEMHUB/
the attackers are requesting:
/%50SEMHUB/
The ‘%50’ sequence is the percent-encoded version of the letter ‘P’.
Mandiant says many WAFs and reverse proxies compare the literal request path before decoding it, causing rules designed to block ‘/PSEMHUB/’ to miss the encoded version.
Oracle WebLogic, on the other hand, decodes the encoded ‘P’ and routes the request to the vulnerable endpoint, bypassing the WAF rule.
Advertisement
“This allows the threat actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure,” Mandiant explains.
PSEMHUB WAF bypass Source: Mandiant
Google warns ShinyHunters may not always use the ‘%50’ bypass variation, and could switch to other percent-encoded, mixed-case, or other variations of ‘/PSEMHUB/’ to bypass WAFs.
Instead of relying on a web application firewall, Mandiant urges organizations to install the latest security update to protect against CVE-2026-35273.
Organizations are also advised to search WebLogic access logs for requests to ‘/PSEMHUB/’ and encoded variants such as ‘/%50SEMHUB/’ to detect signs of exploitation.
WAF bypass leads to new data-theft attacks
Google says the new wave of attacks has deployed web shells on dozens of systems worldwide within higher education, technology, IT services, healthcare, agriculture, transportation, and government organizations.
Advertisement
“Mandiant recommends that organizations running Oracle PeopleSoft take the following immediate actions. Additional remediation and hardening guidance is included later in this post,” warns Mandiant.
Before attempting exploitation, the attackers typically send between five and 15 POST requests to `/%50SEMHUB/hub` containing serialized Java objects.
On vulnerable systems, these requests return information about the host operating system without writing files or disrupting the service, allowing ShinyHunters to determine whether a server can be exploited quietly.
Once they determine a system is vulnerable, the threat actors exploit the flaw again to execute commands directly in memory or deploy JSP web shells.
Advertisement
Google says the attackers deploy an ‘x.jsp’ web shell for command execution and ‘u.jsp’ and ‘u2.jsp’ shells for uploading larger files.
On compromised Windows servers, ShinyHunters used these shells to deploy an executable named ‘Ple64.exe’, which masquerades as a signed Light Alloy media player installer but installs a backdoor tracked by Google as SIDEEYE.
The SIDEEYE malware is used to steal credentials, for process and file management, to create interactive reverse shells, and for reverse proxy functionality.
The threat actors also deployed the open-source Neo-reGeorg tunneling toolkit via the ‘tunnel.jsp’ and ‘tunnel.jspx’ files.
Advertisement
This toolkit allows SOCKS5 proxy traffic to be tunneled over normal HTTP and HTTPS connections, letting the compromised PeopleSoft server be used to spread laterally into the internal network.
Mandiant also observed ShinyHunters using the legitimate MeshAgent remote management software to maintain access to compromised Linux systems.
ShinyHunters previously claimed a new PeopleSoft zero-day
ShinyHunters told BleepingComputer on September 22 that the alleged vulnerability allowed remote code execution and was used to access the FBI Jobs platform, then spread laterally into the FBI’s AWS GovCloud infrastructure.
Advertisement
The group claimed it stole between 2TB and 3TB of data related to current and former FBI employees, job applicants, and other internal systems.
At the time, BleepingComputer could not independently verify the alleged zero-day, the claimed lateral movement, or the amount of data reportedly stolen.
The FBI confirmed that it was investigating claims of unauthorized activity affecting FBIjobs.gov but did not confirm that its systems had been breached or that data was stolen.
ShinyHunters has confirmed to BleepingComputer that they used this WAF bypass against FBI Jobs, but continue to claim that they also exploited “NEW unknown vulnerability in the same PSEMHUB component.”
Advertisement
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Hope there’s extra room in your pockets. A new rumor says Apple’s iPhone 20 Pro and Pro Max could have the largest displays in iPhone history, alongside a quad-curved, nearly all-glass exterior.
Digital Chat Station, a prominent anonymous tech insider on the Chinese social media platform Weibo and a reliable source of Apple news in the past, posted over the weekend that the iPhone 20 Pro screen would be 6.41 inches and the Pro Max 6.96 inches, measured diagonally. The iPhone 18 Pro and Pro Max, which hit stores last Friday, measure 6.27 inches and 6.86 inches (which Apple rounds up to 6.3 inches and 6.9 inches). The iPhone Duo, Apple’s long-awaited first foldable phone, which reaches stores on Oct. 23, has a diagonal 7.6-inch inner display when open.
A representative for Apple did not immediately respond to a request for comment.
CNET Senior Reporter Abrar Al-Heeti said that larger screens are great for watching videos and working on the go, but bigger displays also mean higher costs for consumers, serving as an “excuse for companies to charge you more.”
Advertisement
“Along with the commemorative angle of the iPhone’s 20th anniversary, it’s likely Apple could use design elements like a bigger screen and an all-glass design to hike prices,” Al-Heeti said.
More glass, smaller Dynamic Island
Digital Chat Station backed Bloomberg reporter Mark Gurman’s August report that the exterior of the new flagship phones would be nearly all glass in what’s called a quad-curved design. That means the glass will wrap around all four sides of the phone, making it look as if there is no bezel.
In his report last month, Gurman said that the glass on the front and back of the phones would “curve into the sides of the devices, with a metal band in the middle.”
The exteriors of the iPhone 18 Pro and Pro Max are made of aluminum and ceramic glass.
Advertisement
The iPhone 20 Pro and Pro Max will also have a smaller Dynamic Island and a tiny punch-hole selfie cutout on the front, according to Digital Chat Station.
The Dynamic Island is the capsule-shaped region at the top of the front screen that houses the selfie camera. It also expands and contracts to display notifications, system alerts and background activities.
The iPhone 20 Pro and Pro Max are expected to launch in September 2027 as the next iteration in the series. Apple is widely expected to skip over the iPhone 19 name and jump straight to iPhone 20 next year, marking the 20th anniversary of the first iPhone launch in 2007.
Ever since being admittedly fascinated by the Cambridge coffee webcam from the 1990s, I’ve written about VPNs, the NFL, smartphones, living wages, over/unders and everything in between.
See full bio
You must be logged in to post a comment Login