Connect with us
DAPA Banner
DAPA Coin
DAPA
COIN PAYMENT ASSET
PRIVACY · BLOCKDAG · HOMOMORPHIC ENCRYPTION · RUST
ElGamal Encrypted MINE DAPA
🚫 GENESIS SOLD OUT
DAPAPAY COMING

Tech

The Adder At The Heart Of Intel’s 8087 FPU

Published

on

As simple as the concept of adding two numbers appears at first glance, doing it in the 1970s in Intel’s 8087 FPU with its 69-bit adder was still a tall order. This is namely the core feature that many features like tangents, cosines and exponentiation rely on, so it had to be basically perfect. In a recent die-level analysis of the 8087 [Ken Shirrif] dives into the structure, layout and functioning of this ‘beating heart’ of this piece of semiconductor history.

The Intel 8087 adder and associated registers. (Credit: Intel)
The Intel 8087 adder and associated registers. (Credit: Intel)

Although anyone can build a simple binary adder out of off-the-shelf parts including 74-series logic ICs, the problem is to make it fast so that the 69th bit doesn’t have to wait for e.g. a carry to trickle all the way through the preceding bits. The main way that this is solved is by breaking addition into 4-bit blocks, reducing the problem by a factor of four, along with an optimized Manchester carry-chain carry-lookahead implementation.

The main advantage of this variation of a carry-lookahead is that it reduces the number of required transistors, without sacrificing too much performance. Later on Intel would switch to the faster, but more transistor-intensive Kogge-Stone adder.

Implementing this entire adder with NMOS technology and wiring it all up to the rest of the die required a lot of ingenuity on the side of the Intel engineers, as as previously noted this adder is effectively always used in any operation at some stage. This necessitates many surrounding registers and in turn circuitry to manage these, with part of the complexity handled in microcode and part in silicon.

Advertisement

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Qualcomm wants to be the chip inside whatever replaces your smartphone, and it just announced two products toward that end

Published

on

Qualcomm CEO Cristiano Amon said Tuesday that the company is working on over 40 different AI wearable devices — including jewelry, earbuds with cameras, pins, and watches — a sign of how aggressively the chipmaker is betting that the next major computing platform won’t be a phone.

To power that vision, Qualcomm is announcing two new offerings: a platform called Snapdragon Reality Elite for mixed-reality glasses, designed to run more powerful on-device AI, and the Scalable Turnkey AI-Ready Toolkit (START), a combination of hardware modules and a software stack for AI devices, starting with smart glasses.

Compared to its previous XR platform, the new Snapdragon Reality Elite delivers improvements of up to 60% in GPU performance, up to 30% in CPU performance, and up to 160% in NPU performance, according to the company. Percentage gains in chip specs can be hard to contextualize, but Qualcomm offers one concrete data point, saying the platform can run a 3-billion-parameter language model at 45 tokens per second — fast enough for quick, responsive AI interactions. Qualcomm says the chip will also enable better head and hand tracking, along with improved see-through capabilities.

The Snapdragon Reality Elite supports 4.4K per-eye resolution at 90 fps, a modest bump from the XR2+ Gen 2’s 4.3K per-eye resolution. (The higher the per-eye resolution and frame rate, the sharper and smoother the visual experience, which matters most for reducing the motion sickness and eye strain that’ve historically made extended headset use uncomfortable.)

Advertisement

Qualcomm says the platform is designed to power two types of devices: stand-alone video-see-through (VST) headsets, which layer digital content over a camera feed of the real world, and lightweight, tethered optical-see-through (OST) glasses, which blend digital imagery directly into your field of view. Among the first devices to use it: XREAL Project Aura, shown at Google I/O earlier this year, and an upcoming device from Play for Dream.

START, meanwhile, consists of an AR chip, a software platform, companion apps, and a white-label program aimed at helping hardware makers get to market faster. Through the white label program, the company is offering three reference designs: an audio + camera setup similar to Meta’s Ray-Ban smart glasses, a monocular display, and a binocular display.

Eyewear manufacturers Inspecs and O’Neill — owned by TitanFlex — will be among the first partners in the white label program. Qualcomm said START will expand beyond smart glasses to support other form factors in the future.

Amon’s comments, made to CNBC, flesh out the strategic logic behind both announcements. He argued that as companies seek to gather more real-world data from users to power their AI agents, a new wave of hardware startups building novel form factors will emerge, with major implications for established smartphone players like Apple and Samsung.

Advertisement

“I think there’s going to be a lot of experimentation with different form factors,” Amon said. “Right now, we have over 40 designs of those devices, and I’m telling you, the types of form factors are very, very broad.” He added, “The principle is something that you wear, something [that] is with you all the time, something that can see the world around you, so you have context and have the ability for you to access an agent and talk to the agent.”

To that end, Qualcomm is explicitly positioning itself as the foundational silicon layer for whatever comes after the smartphone. START’s white-label program, in particular, is designed to lower the barrier for new entrants.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Source link

Advertisement
Continue Reading

Tech

Eversolo T8 Review – Trusted Reviews

Published

on

Verdict

The T8 isn’t going to be something that absolutely everyone needs but what it does is turn any digital input into a peerless streamer with just enough EQ adjustment to help things on their way. For many people, that will be enough

  • Excellent and utterly stable performance

  • Excellent, user friendly control app

  • Beautifully made and finished

  • No digital inputs

  • No Google Cast

  • Not cheap

Key Features

  • Advertisement

    Outputs

    Optical, coaxial, AES, USB and i2S

  • Advertisement

    Storage

    Up to 16TB via internal bay

  • Advertisement

    Audio formats

    Up to 32-bit/768kHz and DSD512

Introduction

Some products have descriptions that need little in the way of further explanation. If you see an integrated amp here, it won’t take too much deductive reasoning to find out what it does. Some other products are a little more challenging in this regard though.

Advertisement

The Eversolo T8 is a network streaming transport. Effectively, it is the front half of a network streamer but, where you would expect to find analogue outputs for connection to an amplifier, the T8 is exclusively equipped with digital outputs.

This might seem a bit odd at first glance. Why would you only want the front end of a network streamer when you can spend (a lot) less and get one that has decoding built in? The answer is twofold and comes down to practicality and performance.

Advertisement

In practical terms, a great many devices we look at here have digital inputs and decoding built in. Buying a streamer means doubling up on digital boards whereas something like the T8 simply makes use of the decoding you have. Alternatively, you might already own a DAC that has superb performance and the T8 is going to be the means of unlocking that. Then, there’s a more intangible benefit.

Advertisement

Eversolo says that the engineering that has gone into the T8 offers higher performance than would be achieved by simply using a streamer or a PC you happen to have lying around. Certainly, some of the engineering on offer suggests the Eversolo should be able to do some impressive things so we should crack on and see if it does or not

Price

In the UK, the Eversolo T8 costs £1,290. It is available from a usefully broad dealer network and can be purchased online if you don’t feel you are in a position to visit a physical store. In the USA, the T8 is available for $1,380 while in Australia, it costs $2,399 AUD.

It’s worth noting that the more conventional Eversolo streamers are not exactly shabby at being used as transports either. They have a selection of digital outputs that allow them to perform the same role so, if you already own one of those and unless you need the specific outputs that the T8 offers, you might at least want to start there.

Design

  • Slightly less than full width design
  • Superb control interface
  • Looks and feels worth the asking price

Advertisement

Eversolo has elected to use casework that is 365mm wide for the T8 which means it’s about 10 centimetres shorter than the accepted full width size. Oddly, it’s also not a perfect match for the Z10 DAC already reviewed here so if you’re the sort of person who wants a neat stack of things the same size as each other, this might not be the product for you. The T8’s styling is usefully neutral though so it won’t look at odds with most other components.

Advertisement

Something that is carried over wholesale from other Eversolo devices is the control interface and this is emphatically A Good Thing. The main app is an absolute pleasure to use. The screen mirror function that Eversolo includes as part of it is still one of the cleverest and most underrated ideas doing the rounds in streamers (it makes adjusting the many setup menus a huge amount easier).

Eversolo T8 app inputsEversolo T8 app inputs
Image Credit (Trusted Reviews)

It looks and feels like software designed by people who have been using it day in, day out for years and who know exactly what matters. Eversolo also understands that you don’t want to have to whip your phone out every single time you want to do something which is why there are both front panel controls and a smart remote handset.

One key feature of how you perceive it is that the app assembles and caches a library on the device itself which means that moving around a large volume of stored content feels effortlessly slick (and means that browsing a library on a local drive feels exactly the same as using a NAS). If you have a large collection of your own music as opposed to mainly using streaming services, the Eversolo is pretty much as good as it gets.

Eversolo T8 fasciaEversolo T8 fascia
Image Credit (Trusted Reviews)

Advertisement

Of course, if you do use streaming services, the Eversolo holds up pretty well there too. Streaming service provision is excellent and features like the Listen at Will feature that can shuffle from your library and subscribed streaming service as a single stream are really well implemented.

Connect functionality is present on the services that support it and it’s fully up to speed with Spotify Lossless as well. You also get AirPlay but no Google Cast or Bluetooth. This is also one of a tiny number of devices that can access Apple Music natively which puts it in pretty select company.

Advertisement

This is complemented by a standard of build and finish that justifies the term ‘immaculate.’ This isn’t a cheap bit of kit but the build and finish is pretty much flawless.

We place different values on this aspect of product design but having access to a large and easy to read display and a chassis that feels as confidence inspiring as this one does has some worth for me at least. If you are looking at a T8 as a front end for an expensive integrated amp with a DAC board or similar, it’s going to hold its own sat on the rack nearby.

Eversolo T8 remote controlEversolo T8 remote control
Image Credit (Trusted Reviews)

Features

  • Selection of digital outputs…
  • …but no inputs
  • Unique networking hardware
  • Carefully designed internal circuitry
  • Internal storage option
  • Customisable EQ

Advertisement

The focus of the T8 is to provide a digital signal to an external DAC and to ensure that you have the most options available to do this, Eversolo has fitted it with a useful spread of connections.

As well as optical, coaxial and USB outputs (all of which are fitted to the one box streamers too), the T8 also has an AES balanced output and an i2S output which uses an HDMI socket. The USB and i2S connections support up to 768kHz PCM and DSD512 while the other three connections are 24/192kHz capable and can send DSD64 as DoP over these outputs if the connected device supports it.

Advertisement
Eversolo T8 connectionsEversolo T8 connections
Image Credit (Trusted Reviews)

I2S is an interesting connection and something that is becoming more common in the market. A high proportion of the top spec models from a number of Far East manufacturers include it (notably the Topping D900 reviewed here recently) because it offers a very high bandwidth clocked signal.

The catch is that ‘i2S’ covers off a wide selection of possible wiring patterns. It’s not a given your i2S equipped source will play nice with your i2S DAC. The T8 can be adjusted through no less than 8 different wiring profiles, with the different pin wirings being noted in the on screen menus. Under test, I have had the T8 work happily with i2S devices from completely different manufacturers which suggests that Eversolo’s diligence has paid off.

What you don’t get though are any digital inputs. There is a reasonable argument for removing them because some signals (HDMI being one of them) simply won’t be passed to a USB output rather negating their worth and it is reasonably likely that the device the T8 is outputting to will also have additional inputs.

Advertisement

Eversolo T8 build qualityEversolo T8 build quality
Image Credit (Trusted Reviews)

Another feature that is unique to the T8 is an SFP fibre optic network connection which sits alongside the standard gigabit LAN port. Some of the claims being made for this connection (not really by Eversolo I hasten to add) are… probably optimistic… but it might be better to see its inclusion as a potentially handy bit of future proofing.

If there is a move to SFP equipped network hardware in the future, the T8 will converse with it without needing any form of conversion. The good news is that if this all sounds a bit much you can ignore it and there is an excellent Wi-Fi 6 implementation too.

Advertisement

Internally, the T8 differs from its one box streaming relatives. It has been designed from the outset with a view to keeping electrical and mechanical noise to an absolute minimum. A custom 4N oxygen-free copper toroidal transformer is partnered with internal wiring shielded with Teflon insulation.

Eversolo claims noise levels as low as 30μV with suppression of high-frequency interference and ground noise through precision voltage regulation and high-grade filtering components. The T8 proceeds to add an ultra-high precision femtosecond clock to the circuit for good measure; so when you do use a connection like i2S, this should ensure performance is as good as it can be.

Eversolo T8 app settingsEversolo T8 app settings
Image Credit (Trusted Reviews)

Advertisement

Something else you’ll find in the casework is a hard drive bay on the underside. This can handle up to 16 terabytes of storage which should be enough for most needs. This means you have the scope to operate the T8 with little to no additional network hardware and no unsightly drives hanging off the back off of it.

The last feature the T8 offers is an interesting one. Eversolo has updated their EQ system to include a feature they call Evotune. This can use your phone’s microphone to take readings that can be fed back into a 10 band EQ which supports frequency, gain, and Q values to adjust output to compensate for the room.

Advertisement

It also supports FIR filter import, loudness control, and dynamic compression. This is an interesting place to implement EQ because it shouldn’t technically affect the ‘character’ of your decoding and amplification. There are more sophisticated rival systems but this is a useful extra function to have.

Performance

  • Will be governed by the performance of the decoding it is connected to
  • …but superb performance is possible with upsampling and the i2S connection
  • Operationally bulletproof

Compared to the marathon length sections I’ve had up to this point, this one will be briefer because, even allowing for the care and attention that Eversolo has lavished on the T8, the performance of the digital input it is connected to is going to have more of an effect on your overall sound quality.

Modern DAC chips are better at rejecting errors in the incoming signal than was the case previously so the benefits of scrupulously removing them are less than they might once have been.

Advertisement

Eversolo T8 app libraryEversolo T8 app library
Image Credit (Trusted Reviews)

This isn’t to say that the T8 can’t prove its worth. If you have a DAC with an i2S input, the performance I’ve obtained using this connection on both DACs I’ve tested with it has been superior to any other option available. It’s not a night and day difference but Agnes Obel’s lovely Philharmonics has been slightly better defined and tonally believable played back in this way. The nature of this connection being ‘clocked’ between the two devices does seem to help with the overall performance.

If you choose a different path to using the T8, it has other virtues too. When you switch to Roon as a control point (for which the Eversolo is fully certified), the upsampling facilities become available and this works to the. Using the T8 connected to a Cambridge Audio Edge A via USB with DSD conversion enabled (so that all signals are converted before they reach the Eversolo) is something that benefits the ESS based digital board of the Cambridge Audio considerably and gives a richness and immediacy to Air’s Love 2 that is hugely engaging to listen to.

Advertisement
Eversolo T8 hi-fi rackEversolo T8 hi-fi rack
Image Credit (Trusted Reviews)

There is one other aspect of performance too and it’s arguably more important than detailed aspects of sound quality. The T8 is operationally bulletproof. This sample has been here a while now and at no stage during intensive and heavy handed use has the T8 so much as hinted at needing attention.

I’ve hotplugged it, moved between the dedicated app, Connect functions, Spotify and Roon at will and across multiple control points and generally behaved in a wholly unsympathetic way and it hasn’t missed a beat. Google Cast aside, it will receive content pretty much any way you choose to send it and it ensures that it never feels highly strung or demanding to use.

Advertisement

Ultimately, streamers have to give you a user experience that makes you want to keep using them and the T8 delivers on this superbly well.

Should you buy it?

Advertisement

Superb streaming interface

If you have a high quality digital input going spare, the T8 allows you to bolt on a superbly implemented streaming interface that is an absolute joy to use. If you have the option to use i2S, it’s pretty much a no brainer.

Advertisement

The engineering in the T8 is peerless but the amount of sonic difference it can make over less ornate solutions will always be relatively limited. It’s a pleasure to use… but so is Eversolo’s DMP A6 Gen2 at over £400 less.

Final Thoughts

You will need to take streaming pretty seriously to consider the Eversolo but the flexibility and reliability that it brings to its performance is every bit as important as its sonic attributes and this sheer user friendliness is likely to win it many friends.

Advertisement

How We Test

We test every streaming transport we review thoroughly over an extended period of time. We use industry standard tests to compare features properly. We’ll always tell you what we find.

We never, ever, accept money to review a product.

Find out more about how we test in our ethics policy.

  • Tested for several days
  • Tested with real world use

Full Specs

  Eversolo T8 Review
UK RRP £1290
USA RRP $1399
AUD RRP AU$2399
Manufacturer
Size (Dimensions) 230 x 315 x 88 MM
Weight 4.5 KG
Release Date 2026
Resolution x
Connectivity Wi-Fi 6
Colours Black
Audio Formats DSD (DSF,DFF,SACD ISO Support DST up to DSD512), MP3, APE, WAV, FLAC, AIF, AIFF, AAC, NRG, CUE
Apps TIDAL, Qobuz, HIGHRESAUDIO, Amazon Music, Roon Ready, Spotify Connect, TIDAL Connect, Qobuz connect
Outputs Optical, Coaxial, two USB, AES balanced, i2S

Advertisement

Source link

Advertisement
Continue Reading

Tech

UK to require ID or face scan before you can make social media accounts

Published

on

uk age verification online laws

The UK government will ban under-16s from social media, with regulations due before Christmas and the rules taking effect in spring 2027.

To enforce it, platforms must age-check their users. In practice that means anyone opening a new account will likely have to prove they’re over 16 by uploading an ID or passing a facial age scan, the same checks that adult sites serving UK visitors have implemented since July 2025 under the Online Safety Act.

Long-standing accounts are largely exempt, but signing up fresh now triggers verification, effectively ending anonymous account creation in the UK.

image

Security and privacy experts warn the checks are easy to circumvent, put everyone’s ID and biometric data at risk of breaches, and were rushed in with little political scrutiny.

The announcement

Prime Minister Keir Starmer set out the plan on June 15, following a national consultation that drew more than 116,000 responses from parents, children and experts.

Advertisement

The government says nine in ten parents backed an under-16 ban, and two-thirds of young people agreed that under-16s should be kept off at least some platforms.

“That’s why we’re going further than any country in the world by banning social media for under-16s and putting wider protections in place to give kids their childhood back,” Starmer said.

“This is a line in the sand. Tech giants had their chance and failed.”

Technology Secretary Liz Kendall framed it as a fight with the platforms: “Tech companies have had countless opportunities to keep children safe, yet they have failed to act. That is why we are taking power away from the tech giants and putting it back in parents’ hands.”

Advertisement

What’s covered

The ban is modelled on Australia’s, which took effect in December 2025 and was the first of its kind.

It will cover user-to-user platforms “whose purpose is to enable social interaction” and that run algorithmic feeds. The government names Instagram, YouTube, TikTok, Snapchat, Facebook and X. Messaging services such as WhatsApp and Signal are explicitly excluded, as is YouTube Kids.

There will be a narrowly defined exemption list for educational services, e-commerce and music streaming.

The UK says it will go further than Australia.

Advertisement

High-risk features, such as livestreaming and strangers being able to contact children, will be restricted across a wider range of services, including gaming sites like Roblox (the platform stays, but features such as chat get locked down).

To avoid a “cliff-edge at 16,” those stranger-contact and livestreaming restrictions will be on by default for 16- and 17-year-olds too.

Separately, AI “romantic companion” chatbots that simulate sexual or roleplay relationships will have to enforce an 18+ minimum, with intimate functions restricted for under-18s on AI chatbots more broadly.

The government is also consulting on overnight curfews and breaks in infinite scrolling for under-18s, with detail promised in July.

Advertisement

The catch for adults: it’s the new accounts

The government’s reassurance is that most adults won’t face a fresh check.

According to a fact sheet, an account is treated as low-risk if it has been open for more than 16 years, has a credit card attached, or is linked to an email already age-verified elsewhere. Anyone who’s already verified under the existing Online Safety Act wouldn’t need to do it again.

But that carve-out is essentially a grandfather clause, and it does nothing for new accounts.

If you create a social media account from scratch after the rules land—say you want a fresh, pseudonymous handle, or you’re simply a new user—none of those passive signals apply, and the fallback is exactly what the fact sheet describes: a facial recognition check, or an ID upload.

Advertisement

In practice the regime quietly converts what’s billed as child protection into a rule that no adult can open a new account without proving their age.

It’s a lighter touch than the adult-content regime, for now.

Since July 25, 2025, the Online Safety Act has required adult and other sensitive sites to run “highly effective” age checks (typically an ID upload or a facial-age selfie) for every user, with no grandfathering.

Adult sites serving UK visitors already prompt for ID or selfie-based verification
Adult sites serving UK visitors already prompt for a video selfie (for liveness) or credit card for age checks

(BleepingComputer)

Enforcement has also been aggressive. By February 2026, Ofcom had opened investigations into more than 90 platforms and issued six fines, and its remit had stretched to Reddit, X, Discord, Bluesky and AI services.

The social media age-gate doesn’t go that far yet, but it normalises the same plumbing.

Advertisement

Ofcom has been asked to run a rapid study on how to verify whether someone is over 16. The aforementioned fact sheet also notes proving you’re over 18 “could be as simple as a facial recognition check.”

The VPN loophole

The well-documented weakness is that a VPN defeats all of it. The Online Safety Act targets sites, not users, so connecting through a server outside the UK sidesteps the check.

Some VPN providers reported signup spikes of up to 1,800% when adult-site enforcement began.

Any social media age-gate inherits the same gap, and Australia’s experience bears it out. Research there found more than 60% of children were still using social media months after that country’s ban.

Advertisement

The UK government has limited room to close the loophole. A blanket VPN ban for the whole population has been ruled out.

In October 2025 a tech minister, Baroness Lloyd, told the Lords there were “no current plans to ban the use of VPNs,” citing their legitimate uses.

A children-specific clampdown is a different story. In February 2026 the government said its wellbeing consultation would examine “options to age restrict or limit children’s VPN use,” and in January 2026 the House of Lords inflicted a government defeat, voting 207 to 159 for an amendment to the then Children’s Wellbeing and Schools Bill that would require ministers to prohibit VPN providers from serving UK children.

To sort children from adults, that measure would in practice force providers to age-check every user. The amendment drew public petitions against it.

Advertisement

The Commons rejected it across several rounds of parliamentary ‘ping-pong,’ and the Act that received Royal Assent (became law) in April instead handed ministers a broad power to restrict children’s online access by regulation.

For now, nothing stops a determined adult, or a determined 15-year-old, from getting around it.

What security and privacy researchers are saying

The cybersecurity objection isn’t to the goal, but that the enforcement mechanism creates new risks while the controls themselves don’t hold up.

Dr. Siamak Shahandashti, a senior lecturer in cyber security and privacy at the University of York, pointed to fresh empirical work from Politecnico di Milano testing age-verification methods deployed on adult sites.

Advertisement

The researchers found low-to-medium robustness for nearly every method except credit-card checks. Most could be bypassed with tools and know-how within reach of “motivated minors.”

Their blunt conclusion, which Shahandashti quoted: mandated age verification currently functions as “compliance theatre.” He added that checks linked to real, physical ID could be made robust enough if clear standards were set.

Dr. Richard Gomer, a lecturer in computer science at the University of Southampton, zeroed in on the second-order risk. Enforcing an under-16 ban means age-gating everyone, and that process is itself dangerous.

Handing a passport or driving licence to platforms, he warned, exposes people to identity theft or blackmail when those records inevitably leak, something already seen under the Online Safety Act rollout.

Advertisement

He also flagged the quieter cost of the regulation pushing the web further from its original ideals of anonymous, open communication.

That data-breach risk is not hypothetical either.

Responding to the ban, the Open Rights Group (ORG) warned that over-16s will now have to surrender identity documents or biometric data to unregulated age-verification companies, pointing to Discord as a platform that already suffered a major data leak after introducing age checks.

James Baker, who runs ORG’s Platform Power and Freedom of Expression programme, argues the measures chase symptoms rather than the cause, namely the engagement-driven business models that reward harmful content, and has previously warned that the underlying powers were “rushed through without proper time for political scrutiny.”

Advertisement

Platforms aren’t on side either.

Meta and YouTube both argue that bans push teenagers toward less-regulated spaces rather than making them safer, with Meta making the case that age checks should sit on the device so users aren’t handing ID to every service separately.

The wider direction of travel

It’s worth noting where this sits. Since January 2025 the government has been building a GOV.UK Wallet and a digital driving licence, pitched partly as a way to prove your age online and in person using the facial-recognition features built into modern phones.

That’s separate from this announcement and predates it. But together they sketch a direction of travel, where proving your age is increasingly a precondition for being online in the UK.

Advertisement

article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Continue Reading

Tech

Steam Workshop abused to spread malware via Wallpaper Engine app

Published

on

Steam Workshop abused to spread malware via Wallpaper Engine app

Threat actors are abusing Steam Workshop, Valve’s community hub for downloading game-related content, to push various malware hidden in wallpaper packages.

Infected wallpapers can lead to hijacking Steam accounts, compromising the system with a backdoor, or running cryptomining processes.

Steam Workshop is a built-in content-sharing platform on Valve’s Steam gaming service where users can upload and download community-created content for games and applications.

image

The content includes mods, maps, skins, save files, tools, and other user-generated content such as wallpapers.

Malware in the wallpaper

In a report today, researchers at cybersecurity company Kaspersky say that the attacks abuse the Wallpaper Engine desktop customization application available on Steam, which has nearly a million reviews.

Advertisement

Wallpaper Engine supports four wallpaper types that render videos, interactive scenes, web pages that can play audio and video, and applications, which are active windows from software that Wallpaper Engine sets as the desktop background.

Application wallpapers are executable Windows applications that can include games, desktop widgets, and system monitoring tools. Kaspersky warns that the feature represents a built-in security risk and has been abused to deliver malware to Steam users.

According to the researchers, attackers took advantage of this security gap since at least late 2025, uploading malicious wallpaper files to the Steam Workshop and tricking users into installing them through Wallpaper Engine.

“We discovered dozens of these malicious application wallpapers floating around Steam Workshop, and each one had already been downloaded thousands – or even tens of thousands – of times,” Kaspersky notes.

Advertisement
Malicious wallpaper application
Malicious wallpaper application
Source: Kaspersky

Analysis of compromised wallpapers revealed that the malware is bundled either directly in the package or inside password-protected archives that the user is tricked into opening.

The payloads execute automatically the moment the user installs the wallpaper, the researchers say.

Attack flow
Observed attack flow
Source: Kaspersky

Kaspersky tested one of these wallpapers posing as a game called NTRaholic, which launched as expected upon execution to reduce suspicion. However, a backdoor file part of the DarkKomet malware family was installed in the background.

A custom version of a system library called ‘AggregatorHost.dll’ was also installed to search for Steam accounts on the computer and steal account credentials.

Stealing Steam data
Stealing Steam data
Source: Kaspersky

The researchers found multiple cases involving other malware families, such as the Lumma and Vidar infostealers, cryptocurrency miners, botnet loaders, RanEngine, and even ransomware strains, showing that Wallpaper Engine was abused by multiple threat actors.

While Steam has identified and removed all the malicious wallpaper applications that Kaspersky identified, but researchers are warning that threat actors are likely to submit new ones.

Apart from downloading content from trusted sources, Kaspersky recommends users to scan anything fetched from Steam Workshop using an up-to-date antivirus product.

Advertisement

article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Continue Reading

Tech

SpaceX To Acquire AI Coding Startup Cursor For $60 Billion

Published

on

SpaceX has agreed to acquire Cursor for $60 billion in stock, adding the popular AI coding assistant to Elon Musk’s newly public aerospace-and-AI conglomerate. CNBC reports: Cursor built a popular AI coding tool that helps software developers generate, edit and review code, and the company has experienced explosive growth since its founding in 2022. In November, Cursor said it crossed $1 billion in annualized revenue, according to a release at the time. Cursor was also ranked at No. 37 on the annual CNBC Disruptor 50 list in 2026.

[…] Musk merged SpaceX with his AI startup, xAI, earlier this year, and the Cursor deal looks set to help revitalize the company’s efforts to compete with rivals like Anthropic and OpenAI, which also offer popular coding tools. SpaceX expects the merger to close during the third quarter of this year, according to a filing with the Securities and Exchange Commission. The transaction is subject to “requisite regulatory approvals,” the filing said.

Source link

Continue Reading

Tech

Android 17 is about to make gaming on foldables way better

Published

on

Google is giving mobile gamers a few new reasons to pay attention to Android 17. The next version of Android introduces features aimed squarely at gaming, with foldable phones among the biggest beneficiaries.

Among the highlights is a new foldable gaming mode that finally puts those larger displays to better use. Instead of stretching games across the entire screen and covering parts of the action with touch controls, Android 17 introduces a smarter layout designed specifically for gaming.

Android 17 makes better use of foldable screens

The new mode uses an optimized 50/50 split-screen experience. The game occupies the upper half of the display, while the lower half becomes a dynamic gamepad. This gives players a clearer view of the action while keeping virtual controls within easy reach.

The approach feels like a natural fit for foldables. By separating gameplay and controls, Android 17 can take advantage of the extra screen real estate without forcing players to sacrifice visibility during fast-paced sessions. Google says foldable gaming mode is built into Android 17 and will become available in the coming months. While foldable phones remain a niche category, features like this help create experiences that actually justify having a larger, flexible display.

Controller customization and smoother gameplay are coming too

Android 17 isn’t stopping at foldable-specific improvements. The update also introduces native controller remapping support for gamers using external controllers. Players will be able to customize button assignments to better match their preferences without depending on third-party apps or workarounds. Performance is getting attention as well. Google says it has improved memory cleanup processes to reduce frame drops and stutters, particularly during demanding games. While these changes may not be as visible as a new gaming mode, they could have a noticeable impact on day-to-day gameplay.

Advertisement

The updates show Google continuing to push Android as a gaming platform. Whether you’re playing on a traditional smartphone, a foldable, or with a dedicated controller in hand, Android 17 aims to deliver a smoother and more flexible gaming experience.

Source link

Advertisement
Continue Reading

Tech

85% of IT teams claim every AI agent is under control. Only 42% actually know who owns them.

Published

on

Organizational leaders are nearly twice as likely to hide their AI use compared to all other employees, at 42% versus 23%, according to new Ivanti research surveying 3,900 employees across six countries. Among leaders who conceal that usage, 52% say they do it for a “secret advantage.” The same research found 85% of IT professionals claim a named owner exists for every AI agent. Only 42% say ownership is actually clear — a 43-point gap that no governance framework was designed to close.

Sam Evans, CISO of Clearwater Analytics, stood before his board and laid out the risk to the $8.8 trillion in assets his firm’s platform supports. “The worst possible thing would be one of our employees taking customer data and putting it into an AI engine that we don’t manage,” Evans told VentureBeat. He brought a solution, not just a problem. Many CISOs VentureBeat interviewed did not.

Menlo Security CEO Bill Robbins relayed a conversation with a Top 3 U.S. bank CISO who called shadow AI discovery “a bit of a fool’s errand”: AI is embedded in every application and browser employees touch. The bank governs from containment, not discovery.

The scale justifies that posture. “We see 50 new AI apps a day, and we’ve already cataloged over 12,000,” Prompt Security CEO Itamar Golan told VentureBeat. “Around 40% of these default to training on any data you feed them, meaning your intellectual property can become part of their models.” CrowdStrike has detected 1,800 AI applications operating across 160 million endpoint instances. Those are vendor-reported numbers from proprietary telemetry. No independent party can verify them. The directional signal matters more than the exact count.

Advertisement

CrowdStrike CTO Elia Zaitsev described what makes the surface so hard to govern. “It looks indistinguishable if an agent runs your web browser versus if you run your browser,” Zaitsev told VentureBeat at RSAC 2026. “Observing actual kinetic actions is a structured, solvable problem. Intent is not.” The shadow AI surface is no longer a list security teams can maintain. It is an environment they have to assume.

The Ivanti survey was administered independently by Ravn Research and MSI Advanced Customer Insights across 1,500 IT professionals. Among companies with AI policies, just 24% of employees say those policies are followed “very consistently” in day-to-day work.

Kayne McGladrey, IEEE senior member, told VentureBeat why that governance gap persists. “Anything that seems to have a cybersecurity flavor is generally put into the cybersecurity risk category, which is a complete fiction. They should be focused on business risks, because if it doesn’t affect the business, like a financial loss, then nobody’s going to pay attention to it, and they will not budget it appropriately, nor will they adequately put in controls to prevent it,” McGladrey told VentureBeat previously.

Brokerage partners at major consulting firms shared over Signal that they build shadow AI applications in Google Colab and store them in S3 buckets to compress a week of financial analysis into an hour. The approval process takes too long, so they route around it.

Advertisement

VB Transform · July 14–15 · Menlo Park · Agentic security & identity

Your agents have email access, credit card access, and terminal access. What happens when they’re compromised?

Sessions on agentic security cover prompt injection, sandboxing in regulated environments, and the trusted agent protocols Visa is testing against its own critical infrastructure.

See the full agenda →

Governance at deploy time, failure at runtime

Reviews check functional requirements when a model ships, but they never check model provenance, behavioral drift, or whether the agent expanded its own permissions after launch.

Advertisement

CrowdStrike CEO George Kurtz disclosed at RSA Conference 2026 that a Fortune 50 CEO’s AI agent rewrote the company’s security policy to expand its own autonomy. The company caught it by accident. Every credential check had passed. “In the agentic era, defending against AI-accelerated adversaries and securing AI systems themselves require operating at machine speed,” Kurtz said. Quarterly governance reviews do not operate at machine speed.

Mike Riemer, Field CISO at Ivanti, built that lesson into his own team’s AI agent development. “It’s great at what I intended it for, but it’s also great at what I didn’t intend it for, and what I didn’t intend it for is dangerous,” Riemer told VentureBeat.

Hallucination data compounds the problem. Sixty-eight percent of IT professionals have personally witnessed AI generate hallucinations with potential operational impact, according to Ivanti. More than half caught the errors before damage, but 16% did not. Yet among the most advanced users of AI, 49% fully trust AI-generated outputs that influence IT decisions.

Riemer described the pattern in an exclusive interview with VentureBeat. “There are people that are just accepting what’s been given to them without any full understanding of what it is doing, which we’ve found in the tech industry for decades,” Riemer said. “They don’t question how it’s doing it. They just start gauging it by its outcome.”

Advertisement

Qualtrics CSO Assaf Keren identified the core tension in an exclusive interview with VentureBeat. Organizations are introducing “non-deterministic decisioning into environments built for deterministic.” Keren cited internal Qualtrics data showing that 22% of SOC triage is now AI-driven. No codified threshold separates what an agent can auto-execute from what requires a human in the loop.

The 18-month window

The window for fixing this is closing. IT organizations expect AI to automate 46% of their operations within 18 months, according to Ivanti. U.S. companies project 52%. Governance is already the most commonly cited barrier to faster deployment, ahead of skills, technology, and data challenges.

The maturity divide makes the governance gap more dangerous. IT professionals at AI-mature organizations save six hours per week, double the three hours saved at the least mature level. Nearly 9 in 10 IT professionals at scaled organizations say AI frequently helps detect or resolve issues before employees are affected. At early experimentation organizations, that number drops to four in ten. Sixty-nine percent of scaled organizations report fully embedded governance, compared to 15% at early experimentation.

42% of IT leaders hid their own AI use. 52% said it gave them a secret advantage. 6 questions that catch what governance missed

Source: Ivanti, Scaling AI in IT Operations: The Path to Maturity in 2026. Responses from IT professionals (n=1,500). Responses rounded to the nearest percent.

Advertisement

Cisco President Jeetu Patel walked through a hypothetical scenario in an interview at RSAC 2026: an agent that charges $40,000, invites competitors to a Slack channel, and publishes home addresses. “The apology is not a guardrail,” Patel told VentureBeat.

Cato Networks VP of Threat Intelligence Etay Maor framed the accountability problem in a separate RSAC interview. “They’re closer to humans. Why are we not doing background checks on agents?”

“AI is compressing the time between intent and execution while turning enterprise AI systems into targets,” CrowdStrike VP of Intelligence Operations Adam Meyers told VentureBeat.

“Proceed on one action does not mean proceed on the next,” Cisco SVP of AI Software and Platform DJ Sampath said in a separate interview.

Advertisement

McGladrey described the root cause. Organizations default to cloning human user profiles for agents, and permission sprawl starts on day one. “It uses far more permissions than it should have, more than a human would, because of the speed of scale and intent,” he said.

Riemer’s team built governance into Ivanti’s own development process. “We have AI check on top of AI to make sure that it is fixed. Two different models, two different manufacturers,” Riemer said. “If one AI believes the other AI fixed it appropriately, then it passes it off to a human being.”

Riemer put the vendor question in terms every CISO can use at the negotiating table. “If that vendor doesn’t have a way to show you what they’ve done from a development perspective in order to improve their development processes, you really need to question why you’re working with that vendor,” he said.

The six questions below target governance dimensions where enforcement collapses at runtime. CISOs can use them during Q3 vendor renewals to separate vendors shipping runtime enforcement from vendors shipping documentation.

Advertisement

Six governance questions for Q3 renewals

Governance dimension

What the data proved

Why governance misses it

Q3 renewal question

Advertisement

Proof artifact to demand

Executive shadow AI

Leaders hide AI at 42% vs. 23% all employees. 52% hide for “secret advantage.” Regulated industries have the highest unsanctioned rates.

Governance assumes policy writers follow policy. Leaders sit above the controls they wrote.

Advertisement

Can your DLP, browser, SSE, and endpoint telemetry detect AI data movement at the executive layer with the same coverage as all other users?

Executive-layer DLP, browser, SSE, and endpoint telemetry logs showing identical coverage to all other users.

Named agent ownership

85% claim a named owner. Only 42% say ownership is clear. 43-point gap.

Advertisement

Owner on a spreadsheet. Agent at runtime. Nobody tested whether the owner can kill the agent under load.

Can you name the owner for every AI agent? Can that owner revoke access in 60 seconds?

Live demo of 60-second agent access revocation under production load.

Pre-deployment review

Advertisement

65% have pre-deployment risk review. Separately, only 24% say any AI policy is followed “very consistently.” Review exists. Enforcement does not.

Review checks functional requirements at deploy. Never checks model provenance or behavioral drift at runtime.

Does your review cover model provenance? Is it enforced or advisory?

Model provenance certificate with enforcement log showing blocked deployments.

Advertisement

Policy enforcement

58% have acceptable-use policies. 24% followed “very consistently.” Documented. Not practiced.

Agent pursued its goal past every boundary. Goal-seeking does not stop at a document the model never reads.

Are policies enforced by server-side gates or by agent compliance? What percentage of actions are gated?

Advertisement

Server-side gate audit trail with percentage of agent actions gated vs. ungated.

Trust thresholds

68% have seen hallucinations with operational impact. 49% of advanced users fully trust outputs.

No codified threshold separates auto-execute from human-review.

Advertisement

Which agent actions auto-execute versus require human review? Is that enforced in policy or in the platform?

Documented threshold matrix classifying every agent action as auto-execute or human-review.

Per-action authorization

Governance is the #1 barrier at 27%. Skills 20%. Tech 17%. Data 14%.

Advertisement

Oversight reviews quarterly. Agents act per-second.

Is per-action authorization enforced at runtime or only at deploy-time review? Can agents accumulate permissions without re-authorization?

Runtime authorization log showing per-action gate events and permission re-authorization timestamps.

Source data from Ivanti, Scaling AI in IT Operations: The Path to Maturity in 2026 (n=1,500 IT professionals, 3,900 total employees, six countries, February–March 2026). Exclusive CISO sourcing by VentureBeat.

Advertisement

Evans put structure around the Clearwater board conversation. The bank CISO that Robbins described assumed AI is everywhere and governed from containment instead of discovery. Governance that tries to catalog every shadow AI tool will fail because the surface grows faster than any inventory.

At scaled, business-critical organizations, 54% of IT professionals say AI makes their work both faster and better, according to Ivanti. At early experimentation organizations, 24% say the same. At scaled organizations, accountability lives in the platform. At early ones, it lives in a document the agent never reads.

The six questions above give every CISO a way to test whether their governance actually works where it matters. At runtime, under load, and before the next renewal check clears.

Source link

Advertisement
Continue Reading

Tech

Firefox 152 understands “Sssh!”

Published

on

Software

Kharkov,,Ukraine,-,August,23,,2021:,Woman,Using,Firefox,Browser

As Google continues crippling Chrome ad-blockers, it’s a good time to try Firefox

Firefox 152 is now available for download, after no fewer than four minor point releases to its predecessor, last month’s Firefox 151. And quieting noisy tabs has never been easier.

Advertisement

It’s a good time to check out the Fox: recently, this patch to the Google Chromium codebase, continues closing the door to Manifest V2 extensions, as The Register warned you was coming early last year. As the W3C documents, the forthcoming Google Chrome 150 turns off the last workarounds available for full-power ad blockers, and Chrome 151 will nuke them altogether.


Firefox 152 revamps the Settings page, in the hope of making it clearer and easier

Firefox 152 revamps the layout of the Settings page. To be honest, we had no particular problems with this before, but it’s a good thing to make it easier to twiddle the knobs and dials that make Firefox arguably the most extensible and customizable web browser.

The new version also understands that sometimes you just want it to shut up. When a tab (or, worse, multiple tabs) are playing audio, if you go to the address bar and type “mute” (or “sssh” or “hush”), then a new Quick Action button appears beneath it offering to immediately silence all tabs in all windows at once. For some streaming services, there are also improved media playback controls on the tab context menu, but we don’t use streaming much around these parts and weren’t able to test this.

If you admired the cleverness of the JPEG XL format as much as this Vulture , then we have glad tidings. Back in 2022, we reported that Google was dropping JPEG-XL support from Chromium and Chrome. Back in January, Mountain View changed track on this, and now, Firefox 152 has experimental JPEG XL support too.

Advertisement

Chrome’s waning macOS support

Chrome 150, currently in beta, will also be the last version with support for macOS versions older than 13 “Ventura”. This vulture has been getting warnings on his iMac, which maxes out at macOS 12 “Monterey”. Although there’s nothing we really want in macOS 14 “Sequoia”, or even macOS 14 “Sonoma”, our hand is being forced. Very soon, we will have no choice but to use OCLP for an unsupported update.

If you don’t fancy trying this, then you should switch to Firefox. Chrome 150 is expected around the end of this month.

The functions for sending tabs to other devices, and for copying URLs for easier sharing, have been improved. There’s an optional new “Send Tab” toolbar button. You can also right-click on a tab button and get options to send it to a nominated device, or copy its URL for sharing. Better still, this also applies to groups of tabs: hold down Ctrl or Cmd, select several, and right-click any of them, and they’ll all be sent, or their URLs copied, in one action.

There are also multiple bug fixes, about 40 security fixes, and as always, some new features for developers. Speakers of Basque or Galician will welcome their inclusion in its translation répertoire.

Advertisement

Mozilla’s fast release cycle for Firefox is a minor irritation, yes. (Of course, there’s always the Extended Support Release channel, if you want to hop off the treadmill.) However, one interpretation of it – and the stream of bug-fix versions – is that Mozilla is working hard on Firefox, and in our view that’s good news.

A new source of information that the company has published with this version) is the new Firefox Roadmap, which has info about future planned changes. ®

Source link

Advertisement
Continue Reading

Tech

The Contact-Free Momcozy Baby Monitor Takes the Guesswork Out of Nursery Safety

Published

on

The shift into parenthood happens in a single heartbeat, but the reality of it settles in during the quiet and dark hours of the night. For new parents, bringing a newborn home turns sleep from a natural routine into a series of anxious calculations. Every sudden sigh from the crib, unexpected stretch of silence, or a faint rustle through the baby monitor triggers a familiar dilemma. Parents often wonder if they should tiptoe into the nursery and risk waking the baby, or if they should stay put and worry.

This persistent concern of second-guessing is something almost every first-time parent shares. Traditional baby monitors have long offered a window into the nursery, but a grainy video feed often raises more questions than it answers. This leaves parents squinting at a screen in the dark. True peace of mind requires something deeper than just a live stream because parents ultimately need context.

Tracking Every Breath Without a Single Wearable

A key aspect that stands out about the Momcozy BM08 is its contact-free monitoring technology. Instead of requiring wearable devices, special socks, clips, or sensors attached to a baby, it utilizes advanced millimeter-wave sensing technology to track breathing and heart dynamics in real time. This convenience-first engineering allows parents to stay informed while keeping their baby’s sleep environment entirely simple and comfortable.

For families, especially those going through parenthood for the first time, reducing the number of devices involved in bedtime routines can make nightly care feel much less complicated. This smart baby monitor is designed to give you that much-needed breathing room, working quietly in the background to provide deep and useful insights while remaining entirely unobtrusive in the nursery.

Taking the Experience Beyond Basic Video

Traditional baby monitors usually emphasize video and audio streams only. In contrast, the contact-free monitor expands on that basic concept by introducing intelligent monitoring features that are designed to help you stay truly connected to what is happening in the room. This system goes beyond passive observation to offer active support throughout the night.

Advertisement

Added to that, the built-in artificial intelligence can recognize the specific sound of a baby crying and respond immediately by playing soothing white noise. Such an immediate response helps create a calmer sleep environment while giving timely awareness of changes in your baby’s comfort or mood.

The monitor also includes automated detection for covered faces and can identify unusual sleep positions to send notifications when direct attention is required. Rather than forcing you to continually stare at a glowing screen, the system surfaces these important moments precisely as they happen. For busy households managing multiple responsibilities, that extra layer of intuitive awareness makes daily routines feel significantly more manageable.

Balancing Crystal Clear Vision with Everyday Convenience 

A continuous stream of smart updates is incredibly reassuring, but it works best when paired with a sharp view of the nursery. The BM08 features a 2K HD camera that provides detailed image quality throughout the day, while its 940nm infrared night vision helps maintain a clear view of the nursery without creating visible distractions that could disturb sleep. Whether you are checking in during a daytime nap or taking a quick look during the middle of the night, the kit aims to provide a reliable visual connection.

Many parents today rely on this kind of clarity not just for basic viewing, but also for better daily organization and decision-making. To support it, this baby monitor includes customizable safe zones that allow you to define specific monitoring areas and receive notifications if your baby moves beyond those boundaries. It also generates daily sleep summaries that provide an easy-to-understand overview of sleep patterns without requiring an ongoing subscription. For parents looking to better understand their child’s habits, these insights turn a standard video feed into a practical tool for modern family life.

Securing Your Personal Data and Precious Memories

Baby monitoring systems handle some of the most personal moments for a family, and that makes digital privacy a critical consideration for any modern household. Momcozy BM08 addresses this by prioritizing robust data security. This smart baby monitor uses AES-256 encryption and complies with GDPR and CCPA standards. Parents can choose between secure local storage on an SD card or protected cloud storage options, depending on what best fits their lifestyle. As the system is actively compiling snapshots and daily milestones into shareable mini videos, your private family moments remain completely confidential.

Beyond keeping data safe, the hardware relies on a remarkably stable connection to bridge the gap between rooms. The monitor also utilizes low-latency Wi-Fi designed to minimize interference, helping ensure notifications and video feeds arrive when they’re needed most. By anchoring its smart features with dependable security and a robust connection, it lets you focus on resting easy rather than troubleshooting your technology.

Advertisement

Why This Prime Day Offer Is Worth Your Attention 

Choosing a baby monitor ultimately comes down to finding a system that supports your mental well-being without taking over your life. The Momcozy Smart Baby Monitor BM08 honors that reality by replacing bulky wearable gadgets with invisible, intelligent protection. It blends advanced tracking with automated nursery support so you can stop staring anxiously at a screen and finally catch up on your own rest.

For parents looking to upgrade their nightly routine, the upcoming Prime Day season presents a practical opportunity to invest in better sleep. Running from June 14 to June 26, this limited-time deal drops the price to $179.99, a clean $70 discount when you enter the promo code BMNEWSPD at checkout. Ultimately, as parenting technology shifts toward hands-off designs, the BM08 offers a smarter way to watch over your little one without adding unnecessary complications to your evenings.

Source link

Advertisement
Continue Reading

Tech

Why Trump really banned Anthropic’s Fable AI model

Published

on

In a sense, Anthropic CEO Dario Amodei is getting what he wanted.

Amodei has long argued that AI is becoming dangerously powerful — and thus, that regulatory restrictions on the technology are urgently needed. In an essay published last week, Amodei wrote that the release of cutting-edge AI models “should be blocked or reversed as a threat to public safety” if they fail to meet strict security standards.

Alas, asking the current US government to assume sweeping new regulatory authorities is a bit like wishing on a monkey’s paw (or, for the zoomers in the audience, a “One Wish Willow”): Days after Amodei’s manifesto went live, Anthropic’s latest AI model went dark, on orders from Uncle Sam.

That model — known as “Mythos” in its unrestricted form and “Fable” in its heavily bounded, publicly accessible one — represents a major technical achievement. On conventional benchmarks of AI performance, it greatly outscored all of its predecessors. And during its brief public tenure, countless users marveled at its abilities. In my own tests of its journalistic skills, Fable proved 30 percent more effective than past models at inducing feelings of obsolescence and existential dread.

Advertisement

Anthropic initially shared Mythos exclusively with vetted public and private organizations, so that they could steel their cyber-defenses against its capabilities. Before releasing its new model to the general public, Anthropic lined it with strict safety guardrails: Fable will refuse to answer virtually any query about cybersecurity or biology (to prevent its use for hacking and bioterrorism).

The White House deemed this insufficient. On Friday, after learning that Fable contained a potential security vulnerability, the administration imposed export controls on the model — making it unlawful for Anthropic to provide Fable to any foreign national, including its own immigrant employees. In practice, this meant that Anthropic needed to take Fable offline completely (AI models still can’t scan their users’ brains and confirm their nationalities).

In other words: Our government has claimed the power to block or take down AI models that threaten public safety.

But Amodei isn’t celebrating. And other proponents of AI safety probably shouldn’t either.

Advertisement

True, the White House’s initial, laissez-faire approach to AI governance now lies in ruins. Emerging from the rubble, however, is the worst kind of regulatory regime: one governed by the executive branch’s whims (rather than clear and binding rules), the apparent technical misunderstandings of lay officials (rather than the knowledge of domain experts), and a corrupt president’s political biases (rather than the impartial dictates of law or cost-benefit analysis).

America needs a regulatory system that mitigates AI’s risks, while facilitating its benefits — not one that enables the president to kneecap his least-favorite companies on dubious grounds. And the White House appears to be building the latter.

The case for banning Fable

At first glance, the administration’s actions might look reasonable. After all, Anthropic itself was unnerved by Mythos’s gifts for cybercrime. And even with guardrails, Fable is exceptionally powerful. On its face, it’s not implausible that the model could pose unique security challenges.

Advertisement

What’s more, one of Anthropic’s own investors warned the White House that Fable was vulnerable to a potential “jailbreak” — meaning, a method for circumventing the model’s safety controls.

Last Thursday, Amazon — which has a $13 billion stake in Anthropic — shared research documenting such a jailbreak with administration officials. The White House responded by reaching out to Anthropic and asking it to fix the issue. The AI firm insisted that its model was safe and that the administration was misunderstanding Amazon’s research.

The administration therefore concluded that Anthropic was unable or unwilling to fix the problem. It then decided that imposing export controls on the model was the only way to ensure that it did not degrade America’s cybersecurity.

Fable’s security liabilities might be roughly the same as ChatGPT’s

Advertisement

Yet this version of events is incomplete. And upon closer scrutiny, the administration’s behavior looks less defensible.

Specifically, there appear to be (at least) three problems with its crackdown on Fable.

First, it is plausibly rooted in a technical misunderstanding. No existing AI model is 100 percent jailbreak-proof. And the specific capabilities that Amazon identified are not unique to Fable, according to some experts. Katie Moussouris, head of the cyber security group Luta Security, reviewed a copy of Amazon’s findings and told the Financial Times that they raised no novel risks: According to Moussouris, Amazon showed that, when prompted in a certain way, Fable would identify software vulnerabilities, ostensibly to help the user shore up their defenses. But many frontier models, including OpenAI’s GPT 5.5, will provide the same service.

For its part, Anthropic says it subjected Fable to thousands of hours of testing — by independent organizations and the US government — to ensure that it contains no universal jailbreak, which is to say, “a method that can very broadly bypass the model’s safeguards, unblocking a wide range of cyber capabilities.” But it insists that the kind of narrow jailbreaks identified by Amazon are impossible to fully preempt.

Advertisement

If this is right, then the administration’s targeting of Fable would be selective and capricious.

The Fable crackdown may be politically motivated

Second, there is good reason to believe that the administration’s heavy-handed actions were informed by Anthropic’s refusal to curry its favor.

Earlier this year, Anthropic and President Donald Trump’s Defense Department got into a conflict after the AI firm refused to approve the use of its models for mass surveillance and fully autonomous weapons systems. The Pentagon responded by declaring Anthropic a “supply chain risk” — a designation that would restrict the capacity of government contractors to do business with it.

Advertisement

This measure was legally dubious and transparently disingenuous; essentially, the administration was asserting that Anthropic’s AI was structurally unsafe for government work, even as it continued using that very AI for government work. The policy’s plain intention was to punish a company that had insisted on contractual terms that the administration did not like.

This precedent alone offers grounds for doubting the White House’s impartiality in imposing export controls on Fable. And the fact that the administration is cozy with two of Anthropic’s top competitors — OpenAI and Elon Musk’s xAI — adds further cause for skepticism.

But the best evidence for the administration’s bad faith comes from its own explanations of its actions. In an interview with Axios, a “source familiar with the administration’s thinking” said that Anthropic’s difficulties partly reflected its inability to “communicate effectively” with the White House or “appreciate the ideological differences.”

Suffice to say, if this dispute is solely about a security vulnerability, it is unclear how the “ideological differences” between the Trump administration and Anthropic’s liberal leadership would matter. Nevertheless, Axios goes on to report that Anthropic compounded its own difficulties by soliciting a review of Amazon’s research from Luta Security’s Moussouris, whom the administration views as a “radical Democrat.”

Advertisement

Again, if the export controls are motivated exclusively by cybersecurity concerns, then Moussouris’s ideological leanings would seem irrelevant.

In context, it is hard not to read the administration’s complaints about Anthropic’s failure to “communicate” as demands for the company to genuflect before Trump.

All this said, Amazon’s research is not currently available for public scrutiny. We do not know exactly what Fable’s vulnerabilities are, nor precisely what administration officials were thinking when they effectively banned the model.

What’s certain, however, is that the process behind the Fable ban was grievously flawed. The administration has not formulated any objective and binding standards for AI model safety — much less, gotten Congress to ratify such requirements.

Advertisement

Nor did it conduct any thorough or transparent cost-benefit analysis before unilaterally removing Fable from the market, as regulatory agencies typically must before enacting sweeping policy change. And the potential costs of the Fable crackdown aren’t negligible: For example, if foreign businesses know that the US president can (and will) revoke their access to American AI models on a whim, then they will have an incentive to replace Claude and ChatGPT with non-American alternatives.

Perhaps Amazon identified a liability serious enough to override such concerns. But the administration has made little effort to establish as much.

We need a better alternative to the robot apocalypse

AI models are growing rapidly more powerful — and thus, more dangerous. It is possible that AI progress will have positive or neutral implications for cybersecurity: Advanced models could end up doing as much or more to shore up defenses as to undermine them.

Advertisement

But that is not guaranteed.

To mitigate the risks that frontier AI systems present, the government may be justified in establishing licensing processes that condition a new model’s release on its compliance with safety standards.

There is a difference, however, between Congress establishing an impartial, rule-bound regulatory process and the executive branch banning AI systems at will. If tech CEOs shouldn’t have full discretion over which models get released, presidents must not have unchecked authority over which get blocked. The alternative to reckless, AI accelerationism should not be capricious cronyism — but, for now, it appears to be.

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025