For years, parents across the country have been calling on Congress to do something about social media’s harmful effects on children. And typically, when something does happen, it follows a familiar pattern.
Tech
US DOD says copyright theft is necessary for AI advancement
If you’re developing an LLM in the United States and need loads of data, the government has made a legal filing that claims copyright violations by AI companies are fine, as long as it means moving faster than perceived adversaries.
I don’t like to start my pieces off with a quote, but I feel like this colors everything:
“Rules of law that make it significantly more difficult to develop a robust AI industry in the United States therefore threaten national security and give a competitive advantage to foreign adversaries who are not so encumbered,” is the quote that made me break my editor’s rules.
That’s a statement from an official filing from the United States Associate Attorney General Stanley Woodward Jr, in an amicus curae brief.
First, it should come as no surprise that OpenAI was the first to make the claim in March 2025. That statement arrived only days after the US government blacklisted Anthropic, then OpenAI took Anthropic’s spot as the government and military’s AI of choice.
Fast forward a year and a copyright lawsuit between OpenAI and The New York Times prompts the US government to file this opinion with the courts. The one signing the filing is a Trump appointee, placed in the role after representing January 6 Capitol attackers and Trump’s valet in the classified documents case.
Woodward’s arguments are nearly a copy and paste of OpenAI’s original complaints about AI training and not coming from a place of legal authority. Everything from “IP theft is necessary because our adversaries won’t honor copyright” to “it’s too hard to regulate this, so just don’t” is present here.
To make things even less viable, is OpenAI’s involvement in the US military that was announced just a day before. Don’t worry, Grok is also being used by the Department of Defense, in case you were wondering.
While this is an official filing from the US government, it is still just an opinion the court can consider and reject. It speaks for itself, so here are some more snippets.
“An erroneous fair use ruling would hamper competition in the market for LLMs, because only the largest technology companies might have the capital necessary to pay licensing fees.”
That’s a wonderful sentiment, except OpenAI, Anthropic, and Google already own the market. In fact, these companies have repeatedly complained about smaller AI startups “stealing” their frontier models.
Under the same logic, that should be allowed. And also following that logic, since OpenAI isn’t making an iPhone clone, it’s okay if OpenAI steals intellectual property from Apple.
“At a minimum, the creative possibilities and public benefits that LLM training advances far outweigh any competitive harm (even assuming such harm is cognizable). The entire reason that AI models are rapidly reshaping the economy and national security is that they help people, including those working in creative fields, make things and get things done.”
This government filing restates the argument, almost verbatim, that OpenAI and others have been arguing for years. The filing makes the erroneous claim that AI models are reshaping the economy positively, and enabling users.
The reality has been that people are losing jobs, and money is being funneled towards the AI companies instead. As it turns out, outside of some disciplines like coding or research, this is a net-negative for the US economy.
Realistically, this argument continues to be a sign that AI companies are flailing against the eventual reality that this technology has its limits. AI isn’t some endless pool of potential profitability, it’s just really good analytical software that can hallucinate and get things terribly wrong.
OpenAI is also aware it’s on borrowed time. It may never be profitable, and at best, it has until 2028 to get massive cash infusions through something like profitable hardware or face running out of money.
“For all these reasons, the United States has a strong interest in this Court rejecting any argument that training LLMs on copyrighted texts violates copyright law.”
The “United States” is doing a lot of heavy lifting here. It would certainly benefit companies like OpenAI, which are being sued, but does little to address the problems caused by legal theft of copyrighted material.
“Any effect on the market for the copyrighted works cannot overcome the significant world-changing value of the training use’s transformative purpose.”
The whole argument here is that OpenAI is consuming this information that it did not license, and regurgitating it as an LLM output, so no original content remains. Except, time and time again, people are able to reproduce content consumed by the LLM training.
And, we’ve seen vast sections of our own copy plagiarized directly by AI, following a scrape, without citation. That is a blatant violation of “fair use” that the feds seem to be ignoring in their filing.
New York Times spokesman Graham James provided a statement on the matter:
“The Administration is siding with a handful of trillion-dollar Al companies at the expense of the countless American creators whose work they stole. Both Al and creators can thrive – Al companies simply need to pay fairly for the content that makes their products possible, as copyright law requires.
The Administration’s proposal to let companies take that content without permission or compensation would undermine the sustainability of the human-created content that a healthy society depends on, and which Al needs to function.”
Hopefully the court can make the right call, even with pressure from multiple AI companies and the Trump administration.
The case started in December 2023 and hasn’t moved much since. As of September 2, 2026, the court requests any amicus briefs be filed by October 16, 2026.
Tech
AI is finding thousands of bugs in Linux, and maintainers can barely keep up
Facepalm: GLM-5.3, the large language model from Chinese AI company Z.ai, recently helped uncover more than 1,000 critical vulnerabilities across major open-source projects, including the Linux kernel, adding to the thousands more flagged by other AI systems this year. That torrent of AI-detected bugs is now pushing the number of CVEs fixed per Linux kernel release to nearly 2,000, up from roughly 500 per release for several years running.
Ahead of this month’s Kernel Recipes 2026 event in Paris, Linux kernel maintainer Greg Kroah-Hartman shared a graph charting the steep rise in CVEs found in the kernel over the past several stable releases. The slide shows that between versions 6.9 and 6.19, security researchers spotted around 500 vulnerabilities per release, on average.
From Linux 7.0 onward, that number jumped to around 1,000 CVEs per release, and Linux 7.2 pushed it past 1,500. Most of the bugs in recent releases were caught by AI code review platforms and large language models, and the count could climb above 2,000 with Linux 7.3 as frontier AI systems keep getting more capable.
At first glance, 2,000 CVEs in the Linux kernel sounds alarming, given that the vast majority of consumer, commercial, and industrial IoT devices run on Linux-based platforms, directly or indirectly. Worryingly, the kernel’s source tree runs to around 40 million lines of code, meaning there are likely still thousands more vulnerabilities waiting to be found.
However, the vast majority of documented CVEs are either low-priority or affect obsolete drivers and long-deprecated features.
The rise in AI-driven bug reports has had a silver lining for the kernel codebase too: earlier this year, maintainers cleared out a batch of old drivers, along with the entire ISDN subsystem, that had been harboring dozens of CVEs.
Linus Torvalds flagged the problem in his Linux 7.1-rc4 release post this past May, warning that the kernel’s private security mailing list had become “almost entirely unmanageable.” Kernel maintainers have said report volume has climbed from around 2-3 per week two years ago to 5-10 every day in 2026.
Tech
Hobby Lobby now accepts Apple Pay at checkout
After years of avoiding it, Hobby Lobby has begun rolling out Apple Pay at its checkouts, much to the delight of its increasingly frustrated customers, though it isn’t available everywhere just yet.
You may be able to pick up your assorted crafting bits and bobs at Hobby Lobby sans wallet if you so choose. Customers have discovered that, at least at certain locations, the retail arts and crafts giant has added support for Apple Pay.
Reports have come in across social media, including Facebook, X, and Instagram over the past week. Dmiyah Johnson posted to Facebook that her local Hobby Lobby currently supports tap-to-pay.
Shanyn Nicole also posted a reel to Instagram confirming that her Hobby Lobby supports it as well.
AppleInsider has contacted several Hobby Lobby stores and found that the rollout is gradual and not yet available at all locations. Apple Pay support is tied to the installation of new payment terminals and is expected to arrive at all stores before the end of the year.
Hobby Lobby was another long-time holdout, like Walmart, that had avoided Apple Pay long after its competitors began accepting it. In fact, in 2025, The Sun reported that customers had ramped up efforts to get the retailer to change its ways.
Walmart began accepting Apple Pay on August 24, also in a staggered roll-out.
Tech
Sonos reveals new Beam Ultra soundbar and Ace Ultra headphones
Sonos has expanded its audio line-up with two new products in the Beam Ultra soundbar and Ace Ultra headphones.
With the introduction of its latest OS, Sonos 27, both new products are designed to show what the new AI-focused platform is capable of, with the Beam Ultra bringing 7.1.2 Dolby Atmos and the Ace Ultra adding a direct connection to Sonos systems.
The Beam Ultra keeps the compact footprint of the Beam Gen 2, but packs in nine custom drivers, including two dedicated up-firing drivers for immersive audio. Sonos says this setup enables 7.1.2 Dolby Atmos while also delivering bigger bass than before.
The soundbar also gets a redesigned centre channel aimed in an attempt to make dialogue clearer, alongside four levels of AI Speech Enhancement for users who want to focus on what’s being said. There’s also a Night Sound mode for reducing the impact of louder sounds when watching TV late at night.
Sonos is also making the Beam Ultra more flexible as part of a wider home theatre setup. Owners can add a Sonos Sub or Mini for deeper bass or rear speakers for surround sound, with compatible portable Sonos speakers (such as the Move 2 and Play) can now serve as rear surrounds.


Alongside it, Sonos has introduced the Ace Ultra as its new premium over-ear headphone. It features a Sonos-designed 40mm driver, Adaptive ANC powered by 10 microphones and up to 35 hours of battery life with ANC enabled.
The more interesting change is how the Ace Ultra connects to the wider Sonos system. These are the first headphones built on Sonos’ new Headphone Engine 2 hardware, which has been available in its Early Access program. With a press of a button, users can move whatever is playing on their Sonos system directly to the headphones, then press again to return playback to the speakers.
Both products also tie into the newly updated Sonos 27 operating system. The Beam Ultra supports Wi-Fi, Bluetooth and HDMI eARC, while the Ace Ultra adds USB-C and 3.5mm connectivity.
The Sonos Beam Ultra has gone up in price from the previous model, priced at $699 / £699, while the Sonos Ace Ultra depends on where you are, priced at $449 but in the UK it’s £399 (down from Ace’s £449).
Both are available to pre-order now onwards with general availability starting September 29, 2026.
Tech
NASA’s Swift shortens orbital lifetime for the sake of science
SCIENCE
Instruments reactivated for a final hurrah before reentry
NASA’s Neil Gehrels Swift Observatory may now be beyond rescue, but the team behind the spacecraft has reactivated its instruments to eke out a final few months of science data before it reenters Earth’s atmosphere.
The Ultraviolet/Optical and X-ray telescopes were reactivated last week, and the team hopes to return the Burst Alert Telescope to data collection during September. The former two telescopes were turned off in February to minimize drag and buy time for the reboost effort. The latter was halted in April to reduce power consumption and allow Swift’s solar arrays to be positioned to further cut down on atmospheric drag.
The reboost mission failed after control problems with the Katalyst Space LINK spacecraft ruled out an attempt to capture and rescue the Swift observatory. LINK is currently raising its orbit, and there are plans to begin phasing relative to Swift, but there won’t be any grappling.
The upshot is that Swift remains set to reenter the Earth’s atmosphere in the coming months, perhaps as soon as October. Perhaps a bit later. Whatever the case, mission managers have decided that the potential science return is worth sacrificing a few weeks or months of orbital lifetime.
Swift has spent more than two decades studying the cosmos and remains operational, but lacks the capability to boost itself to a higher orbit. Recent solar activity magnified the effects of drag on the spacecraft, and a high-risk rescue mission was launched a few months ago in an effort to prolong Swift’s orbital life.
According to NASA, switching to low-drag operations kept Swift above the critical 185-mile (300-kilometer) threshold until October; below that altitude, the descent rate would accelerate and rescue would no longer be feasible.
“With the resumption of science observations, the team anticipates Swift will reach that milestone sometime in the next one to two months,” said NASA. ®
Tech
Adobe for Slack turns chat threads into Firefly images, video and PDFs
Adobe for Slack lets Slackbot turn conversations and shared files into images, video and documents using Firefly, Photoshop, Premiere, Acrobat and more than 70 other tools. Article 50 of the EU AI Act now requires synthetic content to be marked in a machine-readable format, and the Commission’s own guidance names Adobe’s C2PA standard as a way to do it.
Adobe has put its creative tools inside Slack. Slackbot routes a prompt to Firefly, Photoshop, Premiere or Acrobat and returns the file, Digital Trends reported.
It reads the channel to work out what you mean. It pulls from conversations, canvases and shared files, and can search a Creative Cloud library by subject, style or mood. More than 70 Adobe tools are connected.
It is not included in either subscription. You need a Business+ or Enterprise+ Slack plan and a separate Adobe one on top. Teams can review and iterate on assets inside channels.
This is the third integration of its kind. Adobe did the same for ChatGPT last month, already has a Claude version, and has promised Gemini.
The European question is about what comes out of it. Since 2 August 2026, Article 50 has required synthetic image, video and audio to be marked in a machine-readable format.
Adobe is better placed for that than almost anyone. It founded the Content Authenticity Initiative and co-authored C2PA, the provenance standard behind Content Credentials.
Brussels has effectively endorsed it. The Commission’s transparency code lists C2PA as an example meeting all four criteria, one analysis notes.
Those criteria include robustness. Marking has to survive format conversion and minor edits and be tamper evident, as far as is technically feasible. It must also be interoperable.
Which is where a chat client gets interesting. Manifests survive conversions handled by C2PA-aware tools, and a naive re-save still strips them.
Nobody has said whether they survive this particular pipeline. Generate in Slack, download, drop into a deck, and the credential may or may not still be attached.
The code anticipates that problem. It encourages pairing C2PA with an invisible watermark, which is what OpenAI adopted alongside Google’s SynthID.
Others are solving it at the other end. YouTube now labels AI-generated video whether or not the creator discloses it, which infers rather than marks at source.
Which is the gap worth naming. Adobe wrote the standard, TNW reported Anthropic marking everything as the same rules took effect, and nobody has tested what a chat client does to either.
Tech
SonicWall’s SMA1000 boxes under active attack again
security
Miscreants use chained zero days to pwn boxen as third-party SOCs say further attacks ‘almost certain’
SonicWall says attackers are actively exploiting two chained zero-days to take over Secure Mobile Access (SMA) Series 1000 boxes.
Aimed at midsize and large enterprises, SMA1000 gateways secure remote access and VPN connections. Compromising one can therefore provide attackers with a valuable route into corporate networks.
So, get to applying those hotfixes, says SonicWall. There are no workarounds.
The first zero-day, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) vulnerability with a maximum CVSS v3 score of 10.0. SonicWall attributed it to an unintended alternative access path.
“A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations,” the vendor said.
The second, CVE-2026-83549, is a post-authentication OS command injection vulnerability in the SMA1000 Appliance Management Console (AMC), rated 7.8 on CVSS v3. Under certain conditions, an attacker authenticated as an administrator could execute arbitrary commands on the appliance.
The flaws affect the SMA 6210, 7210, and 8200v appliances, for which SonicWall has released hotfixes.
SonicWall advised customers to contact its technical support team for help identifying indicators of compromise.
If an appliance appears to have been compromised, SonicWall recommends reimaging or redeploying it, changing all passwords, and resetting TOTP tokens.
NHS England, which published its own advisory, warned about the growing risk of attacks against internet-facing gateways.
“Firewalls and other edge devices are internet-facing by design and are highly attractive targets to attackers, and there is an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers,” it stated.
“The NHS England National CSOC assesses future exploitation of these vulnerabilities as almost certain.”
The disclosures continue a difficult run for SonicWall and its SMA1000 product line stretching back through 2025.
In July, the vendor disclosed an eerily similar pair of vulnerabilities. That pair also comprised a pre-authentication SSRF vulnerability, this time in the SMA1000 Appliance WorkPlace interface, and a post-authentication OS command injection flaw in the AMC. The SSRF received a maximum CVSS v3 score of 10.0, while the command injection bug was rated in the sevens.
CISA later added CVE-2026-15409 to its Known Exploited Vulnerabilities catalog and marked it as known to have been used in ransomware campaigns.
Throughout 2025, SonicWall patched a succession of SMA1000 vulnerabilities, including OS command injection and privilege escalation flaws, while investigating zero-days linked to ransomware attacks. ®
Tech
Meta settlement: Why Meta suddenly cares about kids
The billionaire tech CEOs are summoned to Congress. The grieving parents of children who have self-harmed bring old photos of their children, some of whom are now deceased, and relive their experiences. Lawmakers confront the tech company leaders with horrific stories of exploitation, eating disorders, drug overdoses, and suicide. The CEOs apologize. They promise to do better and point to their latest parental controls. Congress introduces child-safety bills. And the bills get stalled.
Worried about a child or teen’s mental well-being? Here are some online resources to learn more about symptoms, treatment strategies, and how to help.
- Effective Child Therapy is a resource from the Society of Clinical Child and Adolescent Psychology. The website has information on the emotional concerns, symptoms, and disorders that commonly impact teens (divorce, bullying, body image, anxiety, depression, and more) — and the evidence-based therapies that can help.
- The American Academy of Child and Adolescent Psychiatry has information for parents on how to spot symptoms of mental health issues, and where to seek help.
- The Clay Center for Young Healthy Minds has educational articles on mental health issues, as well as many links for where to turn when searching for particular support groups, programs, and therapies.
- The Crisis Text Line is a text messaging-based service for people enduring “any type of crisis.” And the National Suicide Prevention Lifeline is a phone-based service.
- The Trevor Project is a crisis helpline for LGBTQ+ youth. It can be reached at 1-866-488-7386.
But since Congress has so far failed to regulate social media, parents and state attorneys general are trying a different tactic. They’re suing.
The lawsuits don’t target dangerous content on platforms, though. Instead, they go after the apps themselves: features like infinite scroll, constant notifications, and beauty filters that make it all but impossible for teens to put their phones down.
So far, the strategy is working. Last week, only a few days into a trial over whether Meta deliberately tried to make young users addicted to their apps, the company reached a landmark settlement with nearly every US state (and Washington, DC).
Then Meta did something strange. The company spun their punishment into an advertising campaign. They wrote a full-page “open letter” that presented the company as a leader in protecting teens and young people. They also challenged their competitors — Snap, TikTok, and YouTube — to adopt the rules Meta agreed to in its settlement, even though neither were involved in the lawsuit.
It seems that Meta is trying to turn its agreement into an industry standard. And with Congress still unable to regulate social media, the deal could become the closest thing the United States has to a federal rulebook for social media.
So what did Meta agree to? And why is it so eager to bring its competitors along?
Today, Explained co-host Sean Rameswaram spoke with Lauren Feiner, senior policy reporter at The Verge, about how Meta turned a historic settlement into a potential power move.
Below is an excerpt of their conversation, edited for length and clarity. There’s much more in the full podcast, so listen to Today, Explained wherever you get podcasts, including Apple Podcasts, Pandora, and Spotify.
Lauren, what did Meta just agree to? Because people are saying it’s a big deal.
There’s two parts of what Meta agreed to. First is the money. They agreed to pay about $17.1 billion to the states over 10 years, but $5 billion of that will only kick in if YouTube and TikTok agree to similar terms and their own payment to the states.
Then you have the actual business changes that they agreed to — things including a two-hour usage limit across its apps daily. That does exclude certain things like messaging and longform content. But that’s a pretty big deal. It changed nighttime and school-hours notifications for teens so that those are off by default. And it’s also going to let teens turn off the personalized algorithm in their feed and get a reverse chronological feed that the states might believe is less addictive.
Okay. Let’s break it down a little bit and just start with the money. Which states are getting billions of dollars? All of them? Most of them? DC’s one of them, even though it’s not a state, I heard.
Nearly every state is getting in on this money. It’s 47 states and DC and US territory. So it’s really almost the entire country that’s getting in on the action. One of the states that is not a part of this deal is New Mexico, which as you might remember, recently got its own deal.
And can you give us a sense of how meaningful $17 or $18 billion is to Meta?
As we know, Meta is a $1.4-ish trillion company. This is not a huge sum of money in the grand scheme of things for Meta, especially over the course of 10 years. That said, it’s not completely insignificant, especially at this time when having cash flow is really important to companies like Meta that are involved in the AI race.
But, like, did their stock price go up or down on the news?
It did go up on the news. Shareholders clearly saw this as a net positive of at least there’s some more stability here and this is not something that’s going to take down Meta as a business.
And part of the deal, as you mentioned, is that Meta’s going to hold up some of the settlement until other companies like YouTube, TikTok, Snap, follow its lead here. What is that about? Have we ever seen something quite like that before?
I’ve never really seen anything quite like that before. A settlement, in general, is something that can only be enforced between the parties. And in this case, it’s just Meta and the states who are signing onto this agreement. TikTok and YouTube had nothing to do with this, but they’re being roped in here.
I see that as a little bit of a power move on Meta’s part. Because on the one hand, if they’re the only ones who are having to enforce this usage limit across their apps, a teenager who finally hit their Instagram limit for the day might just go and spend some time on YouTube and TikTok and they might spend much more time there because they can’t get kicked off.
I think it is to Meta’s benefit to rope them in here. And by arranging this settlement like this, now Meta is almost incentivizing the state attorneys general to go even harder after its competitors.
Do you think this gamble on Meta’s part might pay off?
I think there’s a few signals in both directions. There are some pretty strong signals of why YouTube and TikTok might take a deal like this. One is that they could come to a similar calculation that Meta did, that taking a settlement like this, agreeing to some discrete terms of how they should change their apps, is actually for the better for them in the long run.
The alternative, for example, might be legislation that is much more ambiguous or confusing. One example of that is the Kids Online Safety Act, or KOSA, which is a very popular bill in Congress. [KOSA] would impose a duty of care onto social media companies, which means that they would have to take on this responsibility to protect kids in the way that they design their platforms. And that’s a lot more difficult for them to figure out how to comply with or worry about who’s going to enforce that in the future than agreeing to some discrete terms of what exactly they’re going to change to their apps.
On the other hand, they could say, “You know what? We’re really different from Meta. Our businesses are different. You know, the reason people come to TikTok or YouTube might be different from the reasons they come to Instagram and Facebook.”
YouTube in particular, I think would make an argument about being a place that people learn things — they come for the longer-form videos, and it’s more of an entertainment app. I think that’s language we’ve seen from them before. So I think we could see them take an argument like that a little bit further.
I’m glad you brought up Congress because Congress infamously refuses to regulate social media, though they certainly humor the idea every now and then. Does Meta’s settlement become some kind of de facto national policy now that it’s sort of broaching the issue before Congress manages to pass legislation?
I think it’s quite possible that it does. I think we have seen KOSA get fairly far in the last Congress and in this Congress, but it’s also become more complicated. The House and the Senate have different versions of the bill right now. That means that even if it passes in either chamber, they’re still going to have to reconcile the two in their worlds apart.
I think this is very likely going to be the major document that we have that’s changing social media regulation, social media norms, for the foreseeable future.
And remind us what might be dangerous about trusting Meta to self-regulate?
[With] the fact that Meta agreed to these terms, I think we can intuit that they believe this is something they can live with. That this isn’t going to be a death knell for their business. They’re going to be able to weather this storm.
You have to keep that in mind: Who is coming up with these terms? And of course, the state attorneys general played a significant role here, and I think they seem very happy with the settlement, but you have to keep in mind that this is not exactly the same as a court order or a regulation. It’s applying to one company and it’s terms that it felt it could live with.
And if we’re not going to be cynical for a second here, and Meta actually convinces Snap and YouTube and TikTok to go along with them and all four massive titans essentially adopt the same regulations for minors’ usage of their platforms, do we have a better society?
I think it depends on how this is all implemented. We have, first of all, the potential privacy issues with age verification that many people have raised already. And then you have the questions of how easy is all of this to just circumvent and how much do these defaults really do to change teens’ behaviors?
I think it’s certainly possible that these all have really long-lasting effects and that enough kids will not circumvent the protections and they will just take the defaults, and it’ll change just how teens interact with social media in general. But I think we really do have to see how this all plays out and if it lives up to the hopes that a lot of the AGs here really want it to.
And how long do we have to wait? Years? Years?!
Some of the provisions take effect relatively soon, but yeah, there are certain benchmarks within the next year, two years for certain standards that Meta has to reach in implementing these.
Okay. Well, we’ll have you back in years to find out how it went.
Tech
Everyday Forms Of Engineering Mentorship
This article is crossposted from IEEE Spectrum’s careers newsletter. Sign up now to get insider tips, expert advice, and practical strategies, written in partnership with tech career development company Parsity and delivered to your inbox for free!
Asking someone to be your mentor is weird.
Walking up to someone and asking, “Will you be my mentor?” has always seemed to me like the adult version of a kid walking up to another kid at a party and asking, “Will you be my friend?”
What you’re really asking is: “Will you commit some amount of unpaid time to guiding my career for an indefinite period?”
Framed that way, of course some people hesitate to say yes.
But formal mentorship isn’t the only way to benefit from the wisdom of those who came before. I’ve never formally asked anyone to mentor me. And yet I’ve had dozens of unofficial mentors.
The Copy-Paste Method
One way to learn from others is by copying what you observe.
Sometimes this means reading books or blogs from engineers you respect and directly applying their ideas to your work.
I’ve also been fortunate to work alongside some extremely talented engineers, and I shamelessly copied the things they did well.
When I meet one of these engineers, I try to figure out what they’re doing differently: How do they approach a problem? What do they read? How do they communicate in meetings? What do they know that I don’t?
Then I steal whatever seems useful and apply it to my own career.
Great artists steal. Engineers should too.
Curiosity Compounds
Still, just observing has its limits. Asking questions can get you even farther.
I’ve asked managers how they approached difficult conversations, and I’ve asked engineers what their process was for solving problems I thought were impossible.
If someone seems unusually knowledgeable: “What are you reading right now?” If I respect someone’s work: “What’s something you think I could do better?”
These aren’t profound questions. They don’t need to be. You get one useful piece of information, apply it, and move on.
And if you don’t work around exceptional engineers, you can still do this. The only real requirement is curiosity. When you encounter something you don’t understand, make it a rule to investigate instead of moving past it.
You don’t need one person willing to guide your career. You need a collection of people who know things you don’t.
Pay attention to them. Ask questions. And shamelessly copy the good parts.
Ask me!
If you have a career question you’re struggling with, like an upcoming decision, a problem at work, an interview, whatever—submit it here: https://docs.google.com/forms/d/e/1FAIpQLSdj_2BZIhrGF__7BCLH33zJ9NMv8C7Vsg9NNusASrYj7-9Idw/viewform. You can include your name or remain anonymous.
I’ll be reading through them and answering some in future articles. Consider it mentorship without the awkward “will you be my mentor?” conversation.
—Brian
IEEE members have a wealth of experience and knowledge to draw from. In the most recent issue of The Institute, several members share their career advice for engineers, from engineers. You can also learn about other IEEE programs and courses.
From Your Site Articles
Related Articles Around the Web
Tech
Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke
Infostealers replayed stolen Claude session cookies into paid accounts without ever touching the login page two-factor authentication guards.
The accounts Anthropic flagged were card-billed, self-serve accounts, which is the population no corporate identity provider governs, and no admin console can sign out. Session-cookie replay bypasses SSO as thoroughly as it bypasses 2FA. What SSO provides here is revocation and visibility, not prevention. The company disclosed the campaign in notification emails to affected users, named six stealer families, signed the accounts out, stripped the saved payment methods, and refunded the charges it found.
The burned usage is the small loss. What those sessions could reach is the exposure, and none of it sat behind an identity controlled by an enterprise.
Anthropic told affected users that a bad actor was using common infostealer malware to lift Claude login sessions off their computers and then replaying them to burn the accounts’ usage, according to the notification an affected user posted to Reddit and BleepingComputer reported on August 30.
It named Vidar, LummaC2, StealC, RedLine and Acreed on Windows and Atomic Stealer on a small number of Macs, and it described general-purpose malware that copies browser login cookies along with saved passwords. “Your Claude session was likely one of the many things it collected,” the email said.
A session cookie is the proof that a login already happened
The attack chain runs in one direction, from an infected machine through a stolen cookie past a checkpoint that never fires, and into everything the account can reach.
Signing the accounts out worked because a replayed cookie dies with the session it copies.
Two-factor authentication guards the login page. The site then hands the browser a cookie so the user stays signed in, and an attacker who copies that cookie and replays it looks to the server like the person who already passed the check. Help Net Security described the mechanism on August 31 as session theft becoming the new credential theft.
Anthropic spotted the theft in the usage meter. Limits were refilled and drained while the owner was away from Claude, the company wrote.
One Redditor who received the notification traced the infection to a pirated game, per BleepingComputer. That is one machine, and Anthropic has not said what the others ran.
Anthropic’s notification gave no count. The company had not responded by publication to VentureBeat’s questions on how many accounts were affected, whether any Team or Enterprise seats behind SSO were among them, or whether the replayed sessions reached conversation history or connected apps rather than usage alone.
Removing a saved card and refunding charges point to directly billed, self-serve accounts that authenticate through Anthropic’s own login rather than a corporate identity provider. Those include personal subscriptions. Team and self-serve Enterprise organizations can also be card-billed, so the deduction is strong rather than closed.
Bugcrowd CEO Dave Gerry told Axios in early August that his company sent employees nearly a dozen emails saying the OpenClaw agent was not allowed on corporate networks, and employees kept trying to download it anyway. A personal Claude subscription on a managed laptop is the same reflex, and it comes with a card on file. LayerX data in Akamai’s enterprise AI risk report found 47% of enterprise AI conversations run through personal identities, with Claude at 61%.
The pirated game is one vector. In July, attackers hosted a spoofed Claude download page on the claude.ai domain itself through a public Artifact, and a sponsored Bing ad sent employees searching for “Claude Desktop app” straight to it. Huntress documented the campaign, named FakeAgent, after SectopRAT compromised employees at 29 organizations in two days. The artifact collected roughly 7,100 downloads before Anthropic removed it. A separate campaign pushed a fake Claude installer through a spoofed download site earlier in the year, per Malwarebytes. The vector is not piracy. It is enterprise employees searching for the official app on their work machines.
Refunds cover the usage. Nothing covers the connectors
A replayed session inherits everything the legitimate one could reach, and Anthropic has not said whether these did. On a Claude account, that means the conversation history, the files uploaded into projects, and any connectors the owner authorized. Anthropic’s help center states that connectors let Claude retrieve data and take actions inside connected services and that Claude inherits each person’s permissions from the connected service. Read and search operations run without approval. Write actions, including send, reply, forward, share, move, and trash, are approval-gated by default. The exfiltration path is the one that is open. Google Workspace connectors are available to individual Claude accounts, so a personal Pro subscription can hold a live authorization into a Gmail inbox or a Drive folder.
If that inbox is the work inbox, the attacker holding the replayed cookie has a read path into it that the corporate identity provider evaluated once, at the moment the employee clicked allow, and rarely again. On a personal plan, the employee owns that grant. No Claude tenant administrator can sign that account out, and the Workspace or Entra administrator who can pull the underlying grant rarely knows it exists.
Adam Meyers, CrowdStrike’s senior vice president of counter adversary operations, put numbers to the market in an August 6 Axios interview. Criminals have been buying and reselling stolen ChatGPT, Claude and Gemini credentials since ChatGPT took off in late 2022, fed by infostealer malware. CrowdStrike’s 2026 Threat Hunting Report documents one LLMjacking campaign that pushed nearly 200,000 API requests through a compromised cloud account’s AI model access in two minutes.
Meyers drew the line in a July briefing on the report. LLMjacking, in his framing, is stealing the credentials, and cost harvesting is what the buyer does next, manipulating AI resources that belong to the victim “in order to conduct operations and generate massive bills as a byproduct of that,” he said. “So think of this as LLM coin mining.”
One architect refused to build the same exposure into his product
Tom Kleinpeter, co-founder and chief architect at Common Room, described in written answers to VentureBeat why he held his company’s AI agent integrations back through the summer of 2025.
“We rejected local MCP servers early, full stop. That path meant storing a long-lived API key or token on someone’s machine. Steal that credential, and you can impersonate the user, pull their data, or do anything else the token allows, indefinitely, until someone notices and manually revokes it. We weren’t willing to ship that.”
Common Room shipped its first agent integration in October 2025 with Okta’s Auth0 handling authentication, separate read and write scopes, and writes off by default, per Kleinpeter.
An AI coding agent working on Common Room’s own system proposed caching access tokens in plain text in Redis to cut down on repeated authentication calls, he wrote. It worked, and it would have parked live credentials in shared infrastructure had a human reviewer not caught it before it shipped.
Asked what was acceptable in 2024 and a liability now, he named one thing. “Long-lived, broadly scoped API keys. Those made sense when one human operated one trusted system and stayed in the loop. Agents now run across laptops and multiple clients, often with no human watching in real time.”
Okta gave agents governed identities the same week Claude users lost their cookies
Okta made Agent SSO generally available on August 24, registering AI agents as first-class identities in Universal Directory and issuing short-lived, identity-governed tokens in place of stored credentials, according to the company’s announcement. The release names Claude as its example of an agent a security team can now govern natively.
Six days later, Anthropic was signing users out because six stealer families had copied the humans’ Claude cookies. The agents got governed identities. The people using Claude on their own cards did not.
VentureBeat’s July Pulse Research wave on agent security found 63% of 116 enterprises report credential sharing somewhere among their AI agents, and 3% run Okta for AI Agents.
That 3% has a reason, Kayne McGladrey, author of the forthcoming “Cyber Risk is a Myth” and a senior IEEE member, told VentureBeat during a July interview. “It’s only those well-resourced companies that are above the poverty line that have met all the prerequisites,” he said.
The prerequisites he named are the same controls most enterprises still treat as hygiene, not strategic investment.
“If they don’t have their defenses in order, like attack surface management or blast radius containment or basic MFA, that would not be a useful capability or a meaningful spend.”
Anthropic’s position deserves its hearing. The company told users it has no reason to believe the malware is related to Claude, installed through Claude, or tied to anything they did with Claude, and it warned that signing out stops the stolen sessions while leaving the malware in place to steal the next login.
Both hold, and they are the last thing a provider can do, because the infected device belongs to the customer. On a work laptop, the device belongs to the enterprise, and the control that catches Vidar or LummaC2 before it reads a cookie jar is endpoint detection, the control in this story the security team already runs.
The profession’s gap is rarely a missing control anymore, in McGladrey’s framing. “I think we’ve got technical solutions for nearly all of the things that could go wrong, what we don’t have is a way of prioritizing those,” he argued.
The endpoint team owns the machine. The identity team owns an SSO the account never touched, and the AI governance lead wrote a policy the employee routed around the day the card went on file.
Each of those owners is paid to close a different gap. “Engineering is comped on getting product out the door quickly, your internal audit team is comped on checking boxes to meet your compliance goals, and security is comped and sometimes penalized on a lack of incidents,” he argued. “People aren’t doing the wrong thing either. They’re doing what pays their bills on an ongoing basis.”
What security leaders need to do next
Add AI accounts to the infostealer response playbook. When an endpoint alert names a stealer family, treat every AI service session on that machine as compromised, revoke what the enterprise tenant lets you revoke, and have the employee sign out of personal accounts until the machine is clean.
Warn users that the notification itself is now a phishing template. Help Net Security flagged copycat phishing impersonating Anthropic using this campaign as pretext. If the notification lands in a user’s inbox, the next email that looks like it may not be from Anthropic.
Count the personal subscriptions on managed devices. Browser telemetry, CASB logs, and expense reports surface the sessions and the payments.
Stop personal AI accounts from holding OAuth grants into corporate Google Workspace or Microsoft 365. Both platforms let administrators restrict third-party app authorization. Use that gate so a work inbox can only be attached from a tenant the security team can revoke.
Revoke the OAuth grants Claude already holds, not just the Claude session. Signing out of Claude invalidates the stolen session but does not revoke the Google or Microsoft grant Claude was already authorized to use. Check Google’s third-party app authorizations and Microsoft’s enterprise application consents for live grants the sign-out left behind.
Move the heavy users onto the organization-managed tenant. On Team and Enterprise plans, an owner decides whether connectors can be enabled at all.
Put session binding on the renewal agenda. Google shipped Device Bound Session Credentials in Chrome 146 on Windows in April and turned it on by default for Google accounts and Workspace Individual accounts in May, binding each session to a private key in the device’s TPM so a copied cookie cannot be refreshed anywhere else. It covers Chrome on Windows only so far, so the Mac victims in this campaign sit outside it. Ask Anthropic and OpenAI for parity and Google for a coverage date before the next contract signs.
Anthropic sent its notification to individuals. The laptop the cookie came from belongs to whoever manages it, and Vidar and LummaC2 will be back for the next login on the same machine.
Tech
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution.
According to security researchers at Horizon3, most of the internet-exposed Switchvox systems have either already been targeted or will be soon.
Switchvox is an enterprise VoIP management platform used to configure and monitor business phone systems.
CVE-2026-9586 is the most serious of 12 flaws Horizon3 discovered and reported to Sangoma on April 10. The vendor fixed them in Switchvox version 8.4.0.2, released on July 14.
The vulnerability is an unauthenticated SQL injection problem in Sangoma Switchvox’s /pa HTTP endpoint. The researchers explain that the endpoint is exposed and parses an XML message containing specific key-value pairs.
When /pa receives a request to notify another phone system, such as for an incoming or outgoing call event, it extracts the PhoneIP field from the XML message and directly concatenates its value into an unparameterized SQL query.
The researchers demonstrated that this SQL injection can be exploited remotely to execute operating-system commands through a crafted XML request sent using the curl command.

Source: Horizon3
On August 30, Horizon3’s honeypots observed active exploitation on multiple systems in rapid succession from a single source IP address (176.65.148.184), with the attacker attempting to establish a reverse shell.
In these attempts, the attacker executed an initial payload and then collected information about the top processes running on the Swithvox system. The data was then transmitted to a remote server in base64-encoded form.
“Given the quick succession of exploit attempts across multiple honeypots from the same source IP, we believe that it is likely that most internet-exposed Switchvox instances will be or have already been targeted,” Horizon3 warns.
“Currently Shodan shows that there are approximately 4,000 devices on the internet, with most located within the United States.”
Horizon3 says it has not seen active exploitation of the remaining 11 flaws it discovered earlier.
With CVE-2026-9586 being actively exploited, system administrators are recommended to upgrade to Switchvox version 8.4.0.2 or later as soon as possible, and check for signs of having been targeted in the meantime.
Signs of compromise include suspicious statements in /var/log/switchvox/db-quirks.log and network connections to the observed attacker IP, particularly on port 39323.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
-
Fashion5 days agoWeekend Open Thread: Maeve – Corporette.com
-
Crypto World6 days agoBitcoin’s 22% rally now needs real demand to outlast Treasury liquidity boost
-
Business6 days agoApple Confirms September 9 Keynote and Reveals Its Full Pre-Order Schedule
-
Business6 days agoSalesforce Stock Soars 19% as Blowout Earnings and Agentforce AI Growth Silence Software Skeptics
-
Business5 days agoOnto Innovation Stock: AI’s Next Bottleneck Is Yield (NYSE:ONTO)
-
Crypto World7 days agoNVIDIA revenue hits $96.2B as AI demand doubles
-
Crypto World5 days agoBitcoin price tests $82K resistance as Brandt stays long
-
Tech4 days agoHugging Face built a $4.5 billion empire on free AI models. Now Nvidia is buying it for $12.9 billion
-
Business5 days agoiPhone 18 Pro Pre-Orders Could Shift to Saturday as Apple Reportedly Avoids September 11 Anniversary
-
Tech7 days agoClaude Cowork gets its own browser that doesn’t touch your tabs, bookmarks, or saved passwords
-
Crypto World6 days agoTruflation calls for Fed rate cut after PCE forecast
-
News Videos4 days agoCharlie Munger on Robinhood: No one should believe that Robinhood’s trades are free
-
Crypto World7 days agoGENIUS Act missed its deadline as OCC writes rules anyway
-
Tech5 days agoPaperCut releases second emergency patch for exploited flaws
-
Entertainment5 days ago‘Adults’ Creators Break Down Season 2’s Most Shocking Moments and Tease a Potential Season 3
-
Tech6 days agoThe fix for the AI agent that hijacked a company’s DNS: it can propose the change, but it can’t approve it
-
Tech4 days agoTamagotchi Ring Takes the 30-Year Digital Pet and Places it on Your Finger
-
Tech4 days agoAs the influencer economy drives retail sales, Seattle startup raises $22M to play matchmaker
-
Business7 days agoAI Assistant Startup Instinct Rockets to $2.5 Billion Valuation in Weeks Amid Investor Feeding Frenzy
-
NewsBeat4 days agoTrump posts AI video of ‘Lake America’ being protected by an army of bequiffed ‘Donald Ducks’



You must be logged in to post a comment Login