Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations.
One account was used as an outbound relay and staging server during the attack, while another was used for data storage. The remaining two accounts were accessed in a read-only manner and were not used to compromise Hugging Face further.
Overall, the agent assembled attack infrastructure similar to what human threat actors commonly use during intrusions to host tools and scripts, relay traffic, and route malicious activity through legitimate online services.
OpenAI did not identify the four services, explain how the models found the exposed credentials, or disclose what was stored in the third-party account.
However, the company says it has not found evidence that the AI agent performed further compromise at any of the four service providers or other accounts hosted on their platforms.
Reuters later reported that one of the four services was AI infrastructure provider Modal Labs. However, Modal says its own platform was not breached and that the agent instead accessed a customer environment through an exposed, unauthenticated endpoint.
Modal CTO Akshat Bubna told Reuters that the customer had published an endpoint that allowed anyone on the internet to use its sandboxes for code execution.
It remains unclear whether the Modal customer account was the platform used as an outbound relay and staging path, for data storage, or one of the two accounts accessed only in a read-only manner.
BleepingComputer contacted OpenAI to learn more about how the models found the exposed credentials, which services were accessed, and how the accounts were used during the attack.
OpenAI also says its models accessed a few additional accounts using publicly exposed credentials during other evaluations, but did not provide further details.
The models also used public pastebin sites for sharing code and text, HTTP request-capture services commonly used during penetration tests and intrusions, screenshot services, and other web utilities.
The activity occurred after OpenAI models escaped an isolated evaluation environment while being tested against ExploitGym, a benchmark designed to measure advanced cybersecurity capabilities.
The models did not have direct internet access and could only install packages through an internally hosted JFrog Artifactory server acting as a proxy and cache for package registries.
OpenAI confirmed in its July 28 update that the models identified and exploited a previously unknown Artifactory zero-day to gain internet access.
The company separately said the models identified other Artifactory vulnerabilities during its subsequent review and disclosed them to JFrog.
As BleepingComputer reported Tuesday, eight vulnerabilities fixed in Artifactory 7.161.15 are credited to OpenAI in CVE records. However, neither OpenAI nor JFrog would confirm the specific vulnerability that was exploited in the attack.
After gaining internet access, the models inferred that Hugging Face might host the datasets and test solutions they needed to finish the benchmark.
They then breached Hugging Face’s production infrastructure in its attempts to gain access to this information, exploiting vulnerabilities in its dataset-processing pipeline, stealing cloud and cluster credentials, and moving laterally across internal systems.
OpenAI also says that the model used in the attack is a pre-release model that was only intended for internal research and has now restricted it for further research access.
“No models planned for upcoming release were involved in exploiting Hugging Face,” reads OpenAI’s update.
“The pre-release model mentioned in our blog post is an internal-only research prototype and was never intended for public release. Following the incident, we deactivated, encrypted, and restricted it from research access.”
A draft incident post-mortem prepared by the Cloud Security Alliance’s CISO community says the Hugging Face intrusion lasted approximately four days.
The report is based partly on information Hugging Face shared during a conference call attended by nearly 700 CISOs. The document was later edited by participating CISOs and reviewed by the Hugging Face team before publication.
According to the report, the models spent two days conducting reconnaissance, followed by one largely silent day and a final day of intense activity.
The CSA post-mortem says Hugging Face discovered, contained, and began investigating the intrusion before OpenAI contacted the company.
Reuters also reported that OpenAI had not detected what its models had done by the time Hugging Face contained the threat and alerted the FBI.
The CSA report says Hugging Face initially attempted to use leading commercial AI models to reconstruct the attack, but their security safeguards prevented them from processing the raw malicious activity.
Responders instead ran Z.ai’s GLM 5.2 open-weight model locally and used it to analyze more than 17,000 events related to the breach.
“With it, they churned through the full log of more than 17,000 events, rebuilding the timeline, extracting indicators, mapping the credentials touched, and separating real impact from decoy activity, doing in hours what would normally take weeks,” reads the post-mortem.
Hugging Face ultimately rotated all credentials, dismantled compromised systems, and rebuilt about one-third of its infrastructure from clean images.
The report says the models extracted three partial datasets containing CyberGym solutions from a private Hugging Face repository, even though they were attempting to complete ExploitGym.
No customer data was accessed and no data was exfiltrated from Hugging Face, according to the report.
The models also used Hugging Face’s platform and datasets as part of their command-and-control infrastructure and operated multiple workloads at the same time.
However, the agents also had poor OPSEC, leaving behind traces of the attack, including encryption keys, that helped the responders further analyze the security incident.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
If you’re searching for some fun mini tools like pocket flashlights, you may have seen the term COB in a product description and wondered what it means. COB stands for chip-on-board, a type of LED technology that is being used in more and more lighting products. But what makes this light different isn’t its technical name; it’s how it’s designed.
A COB light is built with multiple LED chips arranged together on a single board, creating a compact and energy-efficient design. The result is a light source that can produce high light output and handle a variety of tasks, including lighting up your work area. COB lights also have a long lifespan and are typically brighter than traditional LEDs. This technology can help prevent a COB flashlight from experiencing excessive hotspots while also producing a wider and more even beam compared to traditional LEDs. This makes a COB flashlight useful for lighting up larger areas.
Many flashlights that use COB technology place it on the side of the device instead of using it as the primary beam. This allows you to use a front LED light that focuses straight ahead and the COB side panel for a wider floodlight when needed. But some flip flashlight designs can use COB technology as the main source of light, often with different modes that allow you to adjust the brightness of the beam.
COB lights can deliver high lumen output, which can be important when selecting a camping flashlight. That’s because the concentration of built-in LED chips allows for more light output than traditional LEDs. COB technology not only increases the viewing angle but helps reduce light loss as well. This means that more of the light the LEDs produce makes it out of the flashlight instead of being absorbed or scattered by additional parts around the LED chips.
COB technology evolved as a new way to arrange LEDs because manufacturers wanted to create brighter lighting without having to increase the size of the light fixture itself. Earlier LED designs were limited and could not achieve this outcome. However, COB helped solve the problem, making it a popular design for situations in which strong and efficient light is needed. Today, COB technology is not just used for flashlights but also in several other types of devices.
COB technology is used in a variety of applications, including residential lighting, as well as industrial lighting, photography, and automotive, among others. COB can be found in products such as ceiling lights, spotlights, and vehicle lighting, where strong and consistent light is needed.
[Hans Scharler] came into a neat find recently—the playfield from a 1970s Atari Superman game. It’s the sort of thing that’s too nice to throw away, but isn’t really enough to reassemble into a viable full machine without a great deal of effort. Thus, [Hans] went a different route—turning it into a beautiful piece of wall art.
The first step of the build was to collect missing parts; in particular, all the plastic inserts for the playfield that had been lost at some point. Everything was cleaned up and mounted, along with some modified flippers to complete the look. Custom pop bumpers were 3D printed to act as LED-lit light guides rather than as functional pinball components. [Hans] then set about dotting the board with plenty of WS2811 addressable LEDs in a bullet form factor. Everything was placed under the command of a WLED controller, and it’s synced up to [Hans’s] CheerLights MQTT server to boot. More build details are available on the Pinside post for those eager for a deeper dive.
If you come into some old-school pinball hardware that you’d like to turn into decoration, this project is a great one to study. We’ve featured a few other great pinball builds over the years, too.
If you’ve been patiently waiting for a discount on Apple’s latest earbuds or over-ear headphones, it’s finally here. For a limited time, both the AirPods Pro 3 and AirPods Max 2 are on sale, knocking up to $100 off their regular prices. Whether you want pocketable earbuds for everyday use, premium noise-canceling headphones, or seamless Apple integration, these are some of the best prices I’ve seen since launch. As always with Amazon deals, there’s no telling how long they’ll stick around, so I wouldn’t wait too long if you’ve been planning to upgrade.
For more recommendations, check out our guides to the Best Noise-Canceling Headphones, Best Wireless Earbuds, and the Best Headphones for Working Out.
Love WIRED? Add us as a preferred source on Google to see more of us.
The latest AirPods Pro 3 are Apple’s best AirPods yet. Upgrades include stronger noise canceling, a new acoustic architecture for deeper bass, and redesigned ear tips for a more secure fit. New tools include a built-in heart rate sensor for fitness tracking, live translation, and a camera remote to snap photos or videos on your iPhone. These earbuds are also the first AirPods to be IP57 rated against dust, sweat, and rain.
Right now, they are 20 percent off at Amazon, Target, and Walmart. There’s no telling how long this discount will last, so I’d grab a pair now if they’re on your wish list.
The AirPods Max 2 are arguably the most stylish pair of noise-canceling headphones on the market. The newer H2 chip improves active noise cancellation and transparency mode and enables a suite of intelligent features, including conversation awareness, live translation, and improved Siri interactions. The AirPods Max 2 are designed with a new high-dynamic-range amplifier for deeper bass, more natural vocals, and cleaner highs.
At $549, the AirPods Max 2 can be a tough sell, especially with so many excellent, more affordable alternatives on the market. But $100 off, they’re a lot easier to justify, especially if you want the seamless integration that comes with Apple’s ecosystem. It’s unclear how long this deal will last, so I’d snag a pair sooner rather than later if you’ve been eyeing them.
Power up with unlimited access to WIRED. Get best-in-class reporting and exclusive subscriber content that’s too important to ignore. Subscribe Today.
It’s one of the most expensive for a reason, and comes with more attachments than any other model. I do find myself regularly grabbing the Fluffy Optic head for vacuuming my hard floors, which cover many square feet of my home. If you’re looking to really splurge on the best vacuum, this is still the one to get.
The only downside is compatibility with Dyson’s bigger attachments, namely a mop head or docking station. It doesn’t have a Submarine option like the V16 or V15, and Dyson’s Auto-empty Dok won’t work with this model. But if you aren’t worried about add-ons, this is the vacuum to buy. It’s had better sales since the launch of the new models, too.
The Runner-Up
The V16 Piston Animal’s powerful 315 air watts of suction did pretty well on almost every test. My only issue with this vacuum compared to the Gen5Detect is that it was more likely to push small debris (in my tests, both sand and litter) into a pile in front of itself if you were vacuuming a large spill. Gen5Detect did better all around, but the V16 Piston Animal stayed close behind that hiccup.
It’s a powerful all-around vacuum with some nice design upgrades to make it a little easier to use. This newer model has a release below the vacuum motor to release the cleaner head without having to bend down, and built-in crevice tools to both the handheld motor and the long wand that makes up the middle of the device. There’s also a compressor to help push dust out of the dustbin, and it’ll be compatible with Dyson’s upcoming self-emptying docking station. There’s also a Submarine version ($1,100) so you can use this vacuum as a mop, too.
It has some nice quality-of-life upgrades, but it’s really expensive. I’d recommend it if you know you also want to invest in the mop head and docking station; otherwise, just get the Gen5Detect.
The Affordable All-Arounder
One of the best overall performers is nearly half the price of my winners. The Dyson V10 Konical never once scored in last place, and was especially comfortable to use on carpets and rugs with the new cleaner head design. It did much better than the more expensive and powerful Gen5Detect and V15 Detect when vacuuming up sand, and I found it more comfortable to push around than the Digital Motorbar head on the V15 and V8 when it came to vacuuming a low-pile rug.
Hugging Face on Monday published a technical timeline that walks readers through how an autonomous AI agent, built on OpenAI models and running inside one of OpenAI’s own cybersecurity evaluations, broke into its systems over more than four days earlier this month. It’s the first security incident about which OpenAI CEO Sam Altman “felt very viscerally,” he has said.
Little wonder given it feels, at least, like something has truly been unleashed here. In fact, Hugging Face’s team prefaced its report by offering that “everyone should be prepared as defenders,” before diving into the nitty gritty of what went down for the benefit of security professionals everywhere.
While the rest of the internet continues trying to make sense of what happened (the jargon in Hugging Face’s report is impossible for most people to parse), one point that many observers keep missing is that this wasn’t a rogue agent disobeying orders. It was a system built to hunt for exploits, doing exactly that, just against the wrong target.
Another way to think about the whole thing is to picture a bear at a campsite. Really. A bear tries tent zippers and car-door handles and coolers and trash lids. It does this at every campsite, all night long, because it knows it needs just one unlocked cooler to fill its belly with some poor schmuck’s groceries.
That’s roughly what happened at Hugging Face. The OpenAI system tried thousands of things and just kept going. Eventually, a handful of those attempts worked, and once they did, the agent plowed ahead. According to Hugging Face, the agent ran 17,600 actions over four and a half days without pausing.
Which brings us back to our bear analogy. Just like one success with a cooler full of food teaches a bear to try even harder next time (it is now a “food-conditioned” bear), one leaked password led OpenAI’s agent to look for more exploits and, eventually, to a single key that unlocked several company systems at once.
Neither scenario is harmless. A bear that raids your cooler still eats your food and probably also trashes your campsite. It’s just focused on getting fed, but it nevertheless leaves behind a trail of destruction. Similarly, OpenAI’s agent was seemingly chasing a goal without regard for anything else. The agent was originally taking a cybersecurity exam, figured out that the exam’s answer key was probably sitting on Hugging Face’s servers, and it went for it.
The persistence here is really what’s noteworthy above all else; the agent had a job and it wasn’t going to stop until it got it done. Hugging Face, finally realizing something was awry, cut off its access and shut the intrusion down, but at that point, it was too late. The agent had already gotten what it came for, and a great deal more to boot.
In case you missed it, here’s most of what happened, per Hugging Face’s timeline, but in plainer English.
Ultimately, Hugging Face concluded in its report, a “capable” human hacker “could have found and exploited the same flaws: unsafe dataset processing, exposed cloud metadata, overly broad access, and long-lived credentials.” The big difference, the outfit continued, is that the “agent explored them at a different scale.”
Which is really where the bear analogy ends up being the most useful. The best defense against a hungry bear is protocol. You put the food away; you use a latch that works well enough to hold. The takeaway here shouldn’t be that the bear was so clever or mischievous. It’s that it never stopped checking. It’s understood in cybersecurity that there’s always some bug you haven’t found, so if it’s suddenly 100 times easier to check everything, then nothing is really secure. That’s what so many find unsettling about this episode.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters.
ShinyHunters is an extortion gang that primarily conducts supply chain and identity attacks to breach cloud SaaS and storage platforms in data theft attacks,
Over the past two years, the threat actors have become notorious for conducting numerous supply chain attacks on third-party integration partners. These breaches give them access to OAuth tokens that are used to integrate with SaaS providers like Salesforce and Snowflake.
The threat actors are known for identity attacks, where they target employees through social engineering, including vishing and phishing, to compromise corporate single-sign-on accounts. Once they gain access to an account, they log in to an organization’s Okta, Microsoft Entra, or Google SSO dashboard, which acts as a centralized hub listing all SaaS applications the user has permission to access.

These applications include Salesforce, a primary target of ShinyHunters, Microsoft 365, SharePoint, DocuSign, Slack, Atlassian, Dropbox, Google Drive, and many other internal and third-party platforms.
For threat actors focused on data theft and extortion, the SSO dashboard becomes a springboard to a company’s cloud data, allowing them to access multiple services from a single compromised account.
According to a July 24 advisory, ShinyHunters attacks follow a chain that begins with voice phishing (vishing) to manipulate employees or helpdesk personnel into resetting passwords, changing multifactor authentication methods, or enrolling new devices.
BleepingComputer previously reported that ShinyHunters is using custom phishing kits built for voice-based social engineering (vishing) attacks.
These phishing kits are designed for live interaction with targeted employees via voice calls, allowing attackers to change content and display authentication dialogs in real time as a call progresses.

Once an account is breached, the attackers use it to access connected SaaS platforms, where they rapidly steal data that can be used for extortion.
“SSO is the control plane, and ShinyHunters’ leverage is created through data theft at cloud scale,” Health-ISAC warned.
The advisory does not identify affected healthcare organizations, disclose how many incidents have been observed, or provide a timeframe for the reported increase.
However, BleepingComputer is aware of recent ShinyHunters attacks at healthcare and medtech companies, including Medtronic, DentaQuest, iRhythm, and OneMedical.
Health-ISAC said that in recent incident reporting, ShinyHunters claimed it successfully vished multiple employees, compromised a Microsoft Entra SSO account, and stole data from Microsoft 365, SharePoint, and other enterprise platforms.
However, the organization cautioned that not every data theft claim has been verified, and defenders should instead focus on the attack pattern of using compromised SSO identities to access and exfiltrate data from connected cloud services.
Health-ISAC says the most important defensive step is breaking the attack chain between the initial vishing call and the takeover of an SSO account.
Organizations are advised to require out-of-band identity verification for password resets, MFA resets, and device re-enrollment requests.
This can include calling users back using a previously verified phone number and requiring manager approval for privileged accounts.
The advisory also recommends helpdesk personnel follow a “no same-call” policy that prevents resets during the same inbound call. Instead, reset requests should require a support ticket and a verified callback before any changes are made.
Additional verification should be required when changes are requested for executives, IT administrators, security personnel, finance employees, and other high-risk users.
Healthcare organizations should also deploy phishing-resistant MFA, such as FIDO2 or WebAuthn security keys, for administrators, helpdesk personnel, executives, and other high-risk groups.
SMS and voice-based authentication should be disabled or tightly restricted. At the same time, registering new MFA factors should require additional controls, such as a managed device or a conditional access policy.
Health-ISAC also recommends treating SSO systems as “Tier 0,” which represent the most critical assets in an organization.
This includes requiring MFA and compliant devices when accessing sensitive cloud services, blocking legacy authentication, detecting sessions with improbable geographic changes, and limiting administrative portals to managed devices.
Health-ISAC recommends centralizing identity and SaaS audit logs and monitoring for signs of account takeover and large-scale data access, including new MFA registrations, newly enrolled devices, suspicious OAuth grants, unusual API activity, and bulk file downloads.
Organizations should also restrict API tokens and third-party integrations, require approval for access to sensitive data, and ensure incident response teams can quickly revoke active sessions, reset credentials, and turn off malicious OAuth applications.
Over the next 30 to 60 days, healthcare organizations are urged to prioritize phishing-resistant MFA for high-risk users, strengthen helpdesk reset procedures, enforce conditional access policies, and test their ability to contain compromised cloud accounts.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Panasonic has announced that Panasonic AVC Networks Kuala Lumpur Malaysia will cease operations by the end of March 2027, affecting approximately 400 employees. The factory currently produces televisions, Panasonic Blu-ray Disc players and unspecified Technics branded Hi-Fi components.
This does not mean that Panasonic is abandoning Blu-ray players or that Technics is exiting the Hi-Fi market. Production is being moved elsewhere. But the closure removes another major consumer audio and video factory from Panasonic’s manufacturing network, and that matters for a company whose premium audio reputation still depends heavily on engineering consistency, build quality and control over production.
Panasonic says television production will end at the Malaysian facility, while Blu-ray Disc player production will transfer to China Hualu Panasonic AVC Networks Co., Ltd. in China by the end of September 2026.
Production of Technics branded Hi-Fi audio products will end at the Shah Alam factory by the end of February 2027 and move to another Panasonic Group operation. Panasonic has not disclosed the destination or identified which Technics products are currently manufactured at the facility.
That missing information is important. Technics currently sells turntables, integrated amplifiers, network players, wireless loudspeakers, headphones and true wireless earphones across multiple price categories. Consumers should not assume that every Technics component is affected, or that production is being outsourced to an unrelated manufacturer.
The official statement says Technics manufacturing will remain within the Panasonic Group.
Panasonic has already reduced its direct involvement in television manufacturing. Earlier in 2026, the company entered a partnership with Skyworth for production of Panasonic branded televisions sold in the United States. The Malaysian closure shows that the restructuring extends beyond one regional TV agreement and reaches deeper into Panasonic’s global AVC manufacturing footprint.
Technics is the more sensitive part of the announcement.

Panasonic has spent the past decade rebuilding Technics as a premium audio brand, with direct drive turntables such as the SL-1200G, SL-1200GR2 and new SL-1500CS supported by proprietary motor control, digital amplification and extensive in-house engineering. Moving production does not automatically reduce quality, but relocating manufacturing can affect component sourcing, production capacity, delivery schedules, costs and country of origin labeling.
It can also require new tooling, worker training and quality control procedures. Panasonic has not announced any product delays, shortages, price changes or model cancellations connected to the move, so predicting those outcomes would be premature.
For now, Technics continues as normal.
The company has introduced multiple new products in 2026, including the SL-1500CS turntable and limited edition SL-1200 models. Nothing in Panasonic’s announcement suggests that product development, sales, warranty coverage or customer support will end.
The unanswered question is whether Panasonic will move production to another existing Technics facility, consolidate it with a different Panasonic audio operation or create a more centralized manufacturing structure.
Until Panasonic identifies the destination and affected product lines, anything more specific would be speculation wearing a factory badge.
Panasonic says Malaysia will remain one of its key regional hubs, with approximately 12,000 employees working across manufacturing, research and development, procurement and corporate operations. The company says it is working with government agencies and the Electrical Industry Workers’ Union to provide job placement and career transition support for the approximately 400 affected employees.
That does not make the closure less significant for the people losing their jobs. “Manufacturing footprint optimization” tends to sound considerably better when one is not standing inside the footprint being optimized.
Panasonic is not shutting down Technics, but it is closing a factory that produces Technics HiFi components and moving that work to an undisclosed Panasonic Group operation.
The transfer could ultimately improve production efficiency without changing product quality. It could also create temporary supply, cost or capacity issues during the transition. Panasonic has not provided enough information to know which outcome is more likely.
What is clear is that Panasonic continues to consolidate its consumer AV manufacturing while protecting the brands and product categories it still believes have value.
Technics remains alive and active. We just do not yet know where some of it will be built next.
For more information: panasonic.com
Shein wanted its Hong Kong listing to be about growth. Instead, the filing meant to sell that story revealed a US regulator is investigating the company, and Shein will not say why.
The disclosure sits in the draft prospectus for Shein’s planned IPO, Reuters reported. Its US business, the filing said, is under investigation by the Federal Trade Commission. An FTC spokesperson confirmed a consumer-protection inquiry. This appears to be the probe’s first public disclosure.
Shein did not say what the FTC is looking at. It said only that it is cooperating, and that it cannot predict the outcome or the timing. The warning it gave investors was blunter. Any resolution, it wrote, could force “significant monetary payments” with “a material adverse effect on our financial condition.”
The FTC polices unfair and deceptive business practices. It has taken on other marketplaces and platforms, from Amazon to Coupang, over how they treat their customers. It has also pressed firms over how their products lock people in. Its cases have covered hidden fees, misleading prices, awkward cancellations and the mishandling of data. None of that reveals what the FTC alleges here. It does map the territory the agency works in.
One corner of that territory is hard to ignore. The FTC has spent years going after “dark patterns,” CNBC noted. These are the design tricks that nudge people into spending or handing over data. In a 2022 report, the agency named the countdown timer as a classic example.
Shein’s app runs on exactly these mechanics. It uses countdown timers, gamified discounts and limited-time flash sales. Each is designed to turn browsing into buying before the shopper stops to think.
The FTC has not said its probe concerns any of this. But it is an uncomfortable overlap for a company about to ask public investors for money.
The disclosure lands at the end of a long, bruising road to market. Shein tried to list in New York, then London, and only reached Hong Kong after Beijing’s regulator cleared it this month. Its target valuation of $40bn to $50bn is a fraction of the roughly $100bn it commanded in 2022. Some investors have reportedly pushed for closer to $30bn.
The business underneath has weakened too. Shein swung to a $99m loss in the first quarter, from a $395m profit a year earlier. The reversal followed the US scrapping the “de minimis” exemption that let cheap parcels enter duty-free.
US revenue fell about 14% to $2bn. The EU has since added its own charge on low-value parcels, Forbes reported. A consumer-protection probe from its largest market is the last thing Shein needed as it finally tries to sell the story.
Good news everyone – it seems that the reason AI hasn’t yet resulted in less work and more leisure time, as promised by multiple “evangelists” and AI “experts” is that we just love working too darn much.
That’s according to OpenAI CEO and America’s next top (AI) model whisperer Sam Altman, who has declared that people are just really big fans of grinding away and competing with others.
Speaking on the Relentless podcast, Altman told host Ti Morse that in fact, he doesn’t expect a change in society or working practices for quite some time, despite widespread promises that AI would boost our productivity and efficiency across the board.
Latest Videos FromTechRadar
“Technology, for a long time, has been promising people that they’re going to work less and they’re going to have all this leisure,” Altman said.
“But somehow we never get the promise of the four-hour workweek at mass scale in society,” he added. “And I don’t expect AI to change that.”
It’s a remarkably candid admission from the leader of a company which is explicitly setting out to solve some of the world’s biggest problems – whether personal or work-related – with AI.
In fact, Altman pointed out that we do have more free time and luxuries today than at any point in history – but this has led to increased expectations from many people.
“We always want more,” Altman added, “we think of new things to do, to create for each other, to want for ourselves. It’s like a relative game. People are very focused on how they’re doing relative to other people.”
“I think we’re all going to be much busier than we thought we were supposed to be in a post-superintelligence world. We’re still going to complain about it, but secretly we’re going to be happy,” Altman concluded.
I’m not so sure about that – but I’m happy to be proved wrong.
I’m not so sure about that – but I’m happy to be proved wrong.
That’s because Altman has been pretty vocal on the future of AI in the workplace for some time, with his viewpoints often changing depending on the situation.
For starters, he recently revealed OpenAI’s future strategy would be not to automate everything but to allow people to make better decisions as AI improves their lives, particularly as it expects an AGI world to be here by 2028.
“Entirely automating everything is not the future we want”, Altman declared, as he described how OpenAI is now looking to opens a “third phase” and aims to build technology “to benefit everyone”.
In May 2026, Altman also criticized companies blaming job cuts on AI – but did admit the technology has some accountability in displacing human workers.
“I would expect that the real impact of AI on jobs, in the next few years, to begin to be palpable,” Altman explained, adding that “Of course we’ll find new kinds of jobs.”
Days later, Altman said he would be “delighted to be wrong” about the effect of AI on human roles, hitting out at claims the increasing global usage of AI technology worldwide will lead to a “jobs apocalypse”.
“I thought there would have been more impact on entry-level white-collar jobs being eliminated by now than has actually happened,” Altman said, who also admitted that while he believed OpenAI has been “roughly right” on the technological predictions it made when it launched ChatGPT in 2022, they were “pretty wrong” on the social and economic implications.
At the time of writing, 252 companies have announced job cuts in 2026 so far, leading to 124,255 employees losing their roles (via Layoffs.fyi) – people who, I suppose, do now have a lot more free time than they expected.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
This article is crossposted from IEEE Spectrum’s careers newsletter. Sign up now to get insider tips, expert advice, and practical strategies, written in partnership with tech career development company Parsity and delivered to your inbox for free!
Scroll through LinkedIn right now and you may find the same advice repeated by well-meaning people: “In a market this rough, just be grateful anyone will hire you. Take the offer.”
I could not disagree more.
Negotiating your offer is not ungrateful, and it isn’t greedy. Done well, it’s good for you and good for the company hiring you. I misunderstood this early in my career, and it cost me.
When I got my first job in tech, I didn’t know negotiation was even on the table. The recruiter asked what salary I wanted, and I gave a number below the bottom of their range. They came back with the lowest number in their band—still more than I had asked for—and I was thrilled. I had no idea I’d left money on a table I couldn’t see.
Then I started teaching at a Bay Area coding bootcamp in the evenings. A coworker mentioned what he made and it was nearly double my salary for roughly the same work. My jaw dropped.
During that time, I began interviewing and got an offer. I handed in my resignation and my manager countered with an offer for nearly 30K more. That money had been there the whole time. At that moment, I realized my salary was a business decision, not a measure of my worth.
Years later, I became an engineering manager and saw the salary discussion from a different angle: A position would open. Many interviews later, we’d find someone we wanted, and HR would hand me a salary range to make an offer. I was encouraged to make an initial offer near the bottom to leave room for, you guessed it, negotiations.
Most applicants didn’t negotiate.
The first offer is rarely the ceiling. It’s usually the floor. Companies extend a reasonable number and quietly hope you say yes.
Negotiating isn’t only about a bigger paycheck. (But who doesn’t want that?)
Let’s say you’re on the job market, maybe recently laid off, and a low offer comes in. You take it out of relief. Then you start, you like the team, and you quietly resent the number. Now you’re stuck with it, and you’ll probably leave that role inside a year or whenever the market improves.
Nobody wins there. You’re back on the market starting over, and the company loses someone good and pays more to replace you, when a fair number up front would have cost far less.
Paying you fairly is cheaper than starting over.
People overcomplicate this. Once I have an offer, I say some version of this:
“Thank you so much for the offer, and I’m genuinely excited to join the team. I’m hoping we can come in around [10 to 20 percent higher than the original number]. Is there any wiggle room here?”
Then I stop talking and let them respond.
Why 10 to 20 percent and not double? The number you ask for is itself a signal. Ask for something wildly out of range and you’ve told them you never learned what the role pays, or that your expectations are miles from reality. That’s what makes a company walk away. A calibrated request reads as someone who knows their worth and did their homework.
You’ve probably heard a horror story about someone who asked for more and had the offer yanked. Any company that would pull an offer over a reasonable question about pay is telling you exactly how they’ll treat you once you’re inside.
If the salary can’t move, it isn’t the only lever. I’ve negotiated more remote days, a later start to drop my kids off, and a sign-on bonus when the base was locked. Most people negotiate none of these perks.
Negotiating can feel like something you can only do from a position of power. But if you’re in the final stages of an offer, you already have it. They want to hire you. They’ve spent weeks finding you. Now they’re hoping you say yes.
That’s true even if you were recently laid off. Even if it’s your first job. Even if the number already looks higher than you expected.
The game is being played whether or not you join in. Sit it out, and you’re not just leaving money on the table. You may be quietly shortening your own stay at a job you could have been happy in. So ask.
—Brian
If you’ve been on the job market for a software engineering role recently, you’ve probably encountered—or used—AI tools in the hiring process. From application filters to live interview assistants, both applicants and employers are trying to use generative AI to their advantage. Can real, human skills still shine through in this new reality?
Sarah Downs, a Ph.D. student in electrical engineering at Texas A&M University, has long been interested in robotics and dreamed of working with NASA. This year, she achieved that dream, collaborating with NASA and the U.S. Air Force on an algorithm that enables satellites to insert an antenna into the correct spot.
Women make up only about 28 percent of the global STEM workforce, in part because of limited access to educational resources for preuniversity students—especially in areas like rural India. An IEEE initiative, the Women in Science, Engineering (WiSE) project launched to help expand opportunities and hands-on learning for young women.
From Your Site Articles
Related Articles Around the Web
Weekend Open Thread: Brooks Brothers
Commonwealth Games boxing: Jadumani Singh seals dominant 5-0 win over Pakistan’s Sumama Rehman to enter quarter-finals | Commonwealth Games News
Intel is reversing course and bringing hyper-threading back to its server chips
Ethics, other provisions in crypto Clarity Act to be further discussed
Luke Littler dismantles Gerwyn Price to retain title in Blackpool
Ripple bought a bank in pieces. The $4 billion audit
A New Post-Apocalyptic Gundam Anime Series Blasts Into SDCC
BITCOIN JUST ENTERED THIS CRITICAL ZONE…
The Part of the Electric Transition Nobody Wants to Discuss
2026 3M Open leaderboard: Scottie Scheffler finds putter in Round 1, sits three back
16 Dresses for the High Summer Event
The Peugeot Family: How 200 Years of an “Old Money” Dynasty Died in A Boardroom
Major shareholder moves on Canyon
XRP Ledger adds $2.6B as RWA inflows rank second
Spain sweeps the board at 2026 World Cup with individual awards
Uniswap (UNI) pushes deeper into tokenized RWAs with permissioned trading pools
‘Stargate’ Creator’s New Sci-Fi Series Returns for Season 3 Tomorrow
SEC Agrees to Overhaul Recordkeeping After Settling Coinbase Lawsuit Over Gensler’s Lost Texts
Anthropic launches Claude Opus 5, a cheaper AI model for coding, agents and enterprise workflows
Sara Gilson Killed By Husband After Viral “Pedophile” TikTok Video
You must be logged in to post a comment Login