Connect with us

Tech

Want A Brand-New 1967 Mustang? This DIYer Built One From Scratch

Published

on





If you want the styling of a 1967 Ford Mustang without the complications of owning an older car, you could always build it yourself. That’s what YouTuber 1194video did, anyway. Using all new components and materials, he got all the measurements of an original 1967 Mustang and began a tough assembly process. 

1194video started with the structure and floor by using stamped-in bevels as alignment guides. He then hole-punched and screwed the side panel before welding. Before committing to any welds, he made sure to carefully measure everything, making sure the quarter panel, roof line, and B-pillar all lined up. Getting the body squareness right was one of his biggest challenges, requiring him to strap and pull the body straight before welding. 

Advertisement

When it came to the roof structure, 1194video installed front and rear roof braces, then set the roof skin on top to ensure it sat correctly against the body side rails. At this stage, he noticed a bend in the roof skin that had to be corrected. He then screwed and clamped the tail light panel, quarter panels, and other parts of the fastback rear structure into place, trimming off excess metal. This was followed by welding the inner and outer wheel tub sections, then installing the doors and trunk lid. Safe to say, it was not an easy process. 

Advertisement

One of the most important and overlooked parts of building a new 1967 Mustang

One of the biggest focuses of building a brand-new 1967 Ford Mustang was rust protection. 1194video felt he had to be proactive, coating various welding points and panels with primer and high-heat paint before enclosing them. He noted that wheel tub welds and cowl panels are common rust points for this model. At one point he said: “It could settle up in between these two pieces of steel and then cause rust and rot out like all the others in the world do.”

Classic Mustangs are known for falling victim to rust – an unfortunately common problem with classic cars – and the wheel wells are a common spot to find hidden damage. This is because this component sits so close to the ground, especially if you drive on roads with snow, salt, and loose stones. Snow and rain can also splash upwards and get the Mustang’s lower body. If you see faded or chipped paint in that area, it could be prone to rusting.

After the initial body work video, 1194video posted a follow-up video tackling a step most home-built Mustangs never have to deal with: getting a legitimate title and VIN for a car assembled entirely from new reproduction panels. This entailed meticulous photography and receipt compilation, heading to the clerk’s office, and then having a state inspector verify the car was legal and contained no stolen parts. A week later, the title showed up in the mail. This specific Mustang isn’t ready for the road just yet, but one surprising obstacle is now out of the way. If you plan on building a custom vehicle yourself — or even swapping engines — you’ll need to check your state’s regulations. 

Advertisement



Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

Oxford let OpenAI train AI models on Bodleian texts, the Guardian reports

Published

on

Oxford has let OpenAI use old texts from its Bodleian Library to train its AI models, according to internal papers seen by the Guardian. Ethan Penny and Dan Milmo broke the story on Saturday.

The papers say texts that OpenAI scanned at the library went into the firm’s training data.

Oxford made its deal with OpenAI public in March 2025. At the time, it said OpenAI’s tools would help scan rare texts so more students and scholars could read them. It did not say the texts would be used to train AI.

By June 2025, the Bodleian had sent OpenAI 125,000 scans of old PhD theses, the Guardian reported. They include theses written at European and US universities in the 19th and 20th centuries.

Advertisement

Notes from staff meetings, which the Guardian got through a freedom of information request, show some staff had doubts. They worried about harm to Oxford’s name and about the energy use of AI.

However, Oxford said the scans were small in scale, out of copyright and not exclusive to OpenAI. The library keeps the rights and will start to post the scans online in the next few months, a spokesperson said.

The spokesperson also said the AI training side had not been hidden. Scanning was Oxford’s main goal, but staff had been open that the texts would also be used to train models.

“With more than a billion people using this technology in everyday life, it’s important it reflects different cultures, histories and perspectives,” an OpenAI spokesperson told the Guardian.

Oxford is the only UK member of OpenAI’s NextGenAI group. Other members include Boston Public Library, Caltech, MIT and the University of Michigan.

Advertisement

The deal comes as AI firms buy printed books for slop-free training data, since the web is now full of AI-made text. Some buyers cut books apart to scan them, which has upset secondhand booksellers.

In August, 404 Media tracked a box of rare books to an Amazon site that scans and destroys books for AI. The Bodleian’s books stay whole under its deal, the Guardian reported.

Source link

Advertisement
Continue Reading

Tech

Razer’s Kiyo V2 Pro webcam shoots 4K video at 60fps

Published

on

Razer’s new Kiyo V2 Pro webcam uses Sony’s 8.3-megapixel STARVIS 2 sensor and costs $300.

Sony’s STARVIS 2 sensor also enables the headline feature here: 4K video capture at up to 60fps, a specification most consumer webcams still limit to 1080p or 1440p once frame rates climb above 30fps.

Razer pairs that sensor with a lens capable of an f/1.9 aperture, a wider opening than most webcams offer and one that should improve low-light clarity while producing a stronger background blur behind the subject.

AI and imaging features

Beyond the optics, the Kiyo V2 Pro introduces automatic framing, a feature that uses pan, tilt and zoom to keep a speaker centred in the frame, similar to the tools Apple already offers on recent iPhones during FaceTime calls.

Advertisement

Razer has also carried over the one-click output enhancement feature from its microphone lineup, and the camera automatically adjusts exposure, white balance and noise levels to match whatever environment it sits in.

Advertisement

The Kiyo V2 Pro also captures ultra-high dynamic range footage that pulls out more shadow and highlight detail, and Razer has narrowed the field of view from 93 degrees on the original V2 to 86 degrees on the Pro model.

That narrower angle helps the sensor maintain sharper detail at the full 4K resolution and reduces the fisheye distortion that often appears at the edges of a wide-angle frame during video calls.

Advertisement

Software support for the webcam extends to Razer Synapse, which lets users manually fine-tune settings such as ISO and shutter speed rather than relying solely on the automatic modes built into the camera itself.

Razer ships the Kiyo V2 Pro with both a clamp for monitors and laptop lids and a universal tripod mount, alongside an integrated privacy shutter built to resemble a camera’s own shutter mechanism.

Availability and pricing

The webcam is available now through Razer.com and other retailers, and its $300 price places it among the pricier options in the current webcam market.

Razer has not confirmed a UK release date or local pricing for the Kiyo V2 Pro, though the webcam’s US launch suggests a wider rollout is likely to follow in the coming months.

Advertisement

Advertisement

Source link

Continue Reading

Tech

A Pocket-Sized Digital Fish Tank

Published

on

The problem with trying to make a fish tank fit in your pocket is that you’ll either end up with water everywhere or a bunch of dead fish. Perhaps that’s why [StratoBuilds] pursued a digital solution instead.

The concept behind Pocket Tank is relatively simple—it’s a small device that displays a virtual tank with a bunch of little fish swimming around inside. It’s based on the Waveshare ESP32-S3-Touch-AMOLED-1.8, which, if you’re wondering, is an ESP32-S3 with a 1.8″ screen attached, all wrapped up in a convenient plastic housing.

Thanks to the powerful microcontroller, there’s plenty of grunt on tap to run and display a small simulated fish tank. [StratoBuilds] whipped up a system wherein fish movement and animations are handled by regular code running at 25-30 fps, while the fish’s decision making is handled by a custom large language model that was condensed down to run on the ESP32 itself. As the fish swim around the tank, the situation is observed by the LLM and the fish’s current goals are changed accordingly depending on what’s going on. Much like a Tamogotchi, there are regular maintenance tasks for the user to handle, too, like cleaning the tank and feeding the fish to keep them alive.

Advertisement

The blog post and YouTube video do a great job of explaining the project; files are on GitHub for those that wish to tinker more directly. It’s funny, because when we normally look at fish tanks, we’re talking about real ones.

Thanks to [56k] for the tip!

Advertisement

Source link

Advertisement
Continue Reading

Tech

Kimera EVO37 Number Eighteen Brings Lancia Rally Glory to Zoute Auction

Published

on

1976 Lancia Kimera EVO37 For Sale Auction
Four decades after Walter Röhrl and Markku Alén drove Lancia’s Rally 037 to the 1983 World Rally Championship, a small Italian workshop in Cuneo has given that last rear-drive title winner a second life. Kimera Automobili, run by former rally driver Luca Betti from Villa Kimera about 100 kilometers south of Turin, limited the EVO37 to 37 cars. Number 018 now sits in Broad Arrow’s catalog as lot 158 for the Zoute Concours Auction on Friday, October 9, 2026, at Approach Golf in Knokke-Heist, Belgium.



Kimera used the same starting point as the original manufacturer and ran with it: the donor Lancia Beta Montecarlo center section was stripped, reinforced, and improved with a glossy new carbon-fiber shell. Behind all of this was a crew that knew what they were doing, including Sergio Limone, the man who had led the 037 and Delta S4 to great success, and Claudio Lombardi, Lancia’s former rally engine designer who had gone on to do the same for Ferrari in F1, both of whom gave the project their approval. The bodywork was then bolted to the chassis, and Italtecnica created a brand new 2.1 liter, 16 valve four-cylinder engine from the ground up. They preserved the 037’s supercharged configuration but added a turbocharger, resulting in a snappy 505 PS and 550 Nm of torque sent to the rear wheels via a fast six-speed Dana Graziano manual gearbox. The top speed is rated as 310 km/h, with a 0-100 km/h time of just 3 seconds, which is not bad. The vehicle features Öhlins double-wishbone suspension and Brembo carbon-ceramic brakes with four-piston calipers for stopping power.


LEGO Speed Champions Ken Block’s ’65 Ford Mustang Hoonicorn V1 77262
  • CUSTOM MUSTANG RACE CAR – This LEGO Speed Champions Ken Block’s ’65 Ford Mustang Hoonicorn V1 (77262) building toy for boys and girls ages 9 years…
  • AUTHENTIC DETAILS – Builders will recognize cool features from the car’s debut in the 2014 Gymkhana SEVEN film, including exposed velocity stacks on…
  • KEN BLOCK MINIFIGURE – The included Ken Block minifigure features a Hoonicorn hat and jacket, plus an extra helmet accessory for added play value

1976 Lancia Kimera EVO37 For Sale Auction
1976 Lancia Kimera EVO37 For Sale Auction
1976 Lancia Kimera EVO37 For Sale Auction
This vehicle left the workshop in March 2025 and has since traveled a total of 237 kilometers. Kimera’s Luci del Bosco paint job is a deep, rich metallic brown inspired by the old Lamborghini Miuras and Countachs. The gold wheels and beige leather upholstery over carbon fiber chairs give the cabin a relaxed feel, while the exposed gearlever is adorned with a wooden gear knob. LEDs light the road up front, and there’s air conditioning, ABS brakes, a digital rear view camera, and parking sensors to keep things polite without interfering with the exposed carbon, which is exactly what you want to see.

1976 Lancia Kimera EVO37 Interior
1976 Lancia Kimera EVO37 Interior
1976 Lancia Kimera EVO37 Interior
When this project first got off the ground in 2021, the asking price ranged between €450,000 and €480,000. Since then, the market has moved on, and Broad Arrow thinks that this particular specimen, number 018, is now valued between $950,000 and $1,150,000. Kimera has informed the Broad Arrow team that they will gladly assist with import and registration if the future owner is in Europe or the United States, and will even adjust the specifications to suit the buyer if they prefer something different. The tax issue is equally easy; because this is a VAT-qualifying sale, both the hammer price and the buyer’s premium are subject to tax.

1976 Lancia Kimera EVO37 Engine
1976 Lancia Kimera EVO37 Engine
1976 Lancia Kimera EVO37 Engine
The auction of this car will take place on October 9, 2026 as part of the Zoute Grand Prix Car Week, with a public viewing on the 7th and 8th and bidding beginning in the afternoon of the ninth. It’s a rare opportunity to own an original 037 Stradale that is this new and in this condition, and if that’s not enough, Kimera is still willing to re-spec the thing if the buyer has any other ideas.
[Source]

Source link

Advertisement
Continue Reading

Tech

Renault brings the R8 Gordini back as a 270hp electric concept

Published

on

Renault is bringing one of its most recognisable performance cars into the electric era with the Renault 8 Gordini Concept, a two-seat electric coupé inspired by the rear-wheel-drive icon that debuted in 1964.

The concept combines the visual language of the original R8 Gordini with a much more aggressive modern design. It has a low, wide stance, motorsport-inspired proportions and a 270hp electric motor. Renault says the project is part of its wider effort to revisit important models from its 128-year history through one-off creations.

Renault unveiled the concept on September 24 at Renault Carwalk, and it is scheduled to appear at the Paris Motor Show from October 12 to 18.

The classic Gordini gets a radically different electric makeover

The original Renault 8 Gordini arrived in 1964 with a 95hp rear-mounted engine and rear-wheel drive. It became known for delivering racing-inspired performance in an affordable package and served as a training ground for drivers including Jean Ragnotti. Its distinctive double white stripe eventually became a defining visual feature.

Advertisement

The new concept keeps the rear-wheel-drive character but replaces the petrol engine with a 270hp electric motor. Measuring 4.12 metres long, 1.88 metres wide and 1.27 metres tall, the coupé sits on 19-inch front and 20-inch rear wheels. Its proportions are deliberately closer to a modern rally car than the four-door original.

Renault has also carried several familiar details into the new design. The car gets six round headlights, squared-off wheel arches, a modernised Gordini badge and the iconic double white stripe. The stripe is no longer simply decorative, with Renault incorporating it into various structural and design elements of the car.

The design was created entirely in-house. More than 300 sketches were submitted during an internal Renault Design competition before two proposals were developed into scale models and combined into the final concept.

A two-seat EV focused on driving rather than practicality

Inside, Renault has taken a similarly minimalist approach. The cabin features brushed aluminium across the dashboard and controls, contrasted with Alcantara upholstery. Digital round displays echo the circular headlights, while bucket seats and a prominent stopwatch button reinforce the car’s motorsport-inspired character.

Renault describes the concept as part of its effort to connect its heritage with future design rather than simply recreate old cars. The R8 Gordini follows previous projects including the R17 electric restomod x Ora Ïto and Renault 5 Diamant.

Advertisement

For now, this remains a concept car, and Renault’s media page does not confirm that it will enter production. The company does say the concept will become part of its historical collection, alongside other vehicles and archive material at the future Renault Collections museum in Flins, expected to open in around 15 months.

So while you probably won’t be ordering one from a Renault showroom anytime soon, the electric R8 Gordini shows how Renault is imagining its performance heritage in an EV era.

Related coverage:

Over 500,000 Toyota Camrys recalled over a blank digital dashboard

Lexus halts plans of an electric car based on the stunning LF-ZC concept and it’s such a bummer

Advertisement

Toyota made a gaming chair that is probably more expensive than your gaming rig

Toyota just introduced its own robotaxi to tackle Tesla and Waymo

Source link

Advertisement
Continue Reading

Tech

Self-Repairing Conductive Material From Liquid Metal

Published

on

PCB circuits are cool, but you know what is cooler? Terminator circuits that’s what! And what if the same material that makes Terminator circuits could also be used for smart heat sinks, flexible circuits, and self-healing material properties? Well, that is exactly what the lab at Virginia Tech’s VT MADE Lab has created, presented by Joel from [3DPrintingNerd].

So what does a Terminator circuit actually entail? Well, just like in Terminator 2, the circuits are made of liquid metal. Specifically, small drops of liquid metal alloy made of gallium and indium. These drops are contained within a matrix of PDMS polymer, which contains the magical liquid for conductivity, thermal and electrical . This makes a flexible and stretchy composite which can even self-repair when punctured or cut by bridging the

Little “bubbles” of liquid alloy form a composite that will pop when applied over a threshold of force or puncture.

broken circuit with the liquid alloy. Having a polymer matrix allows this self-repairing property but also makes the material insulating by default, only allowing current to flow after selectively “popping” the matrix bubbles.

To create something with the composite material, you’ll find it similar to many other resin-based materials. You can pour, mold, and even 3d print a custom geometry. A short bake later and you get a solidified model made for whatever custom flexible circuitry you have in mind.

While this process requires chemicals, polymerization reactions, and a taste for liquid alloys, that shouldn’t stop you from trying out flexible electronics. For a more hands on method to flexible electronics check out this glove with circuits running throughout!

Advertisement

Source link

Advertisement
Continue Reading

Tech

Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer

Published

on

Claude

Anthropic’s Claude Opus 5.5 appears to be changing how it writes, with new analysis showing fewer obvious AI writing patterns, shorter sentences, and simpler wording compared with Opus 5.

Claude Opus 5.5 is not only one of the best models for coding, but it also appears to be a bit better at writing, as Anthropic appears to be changing how AI writes.

According to Arena, an AI benchmarking tool, Opus 5.5 has fewer obvious AI writing patterns, so you’re less likely to create AI slop content with this model.

It also found that sentences are now shorter, which means you have fewer long sentences and simpler wording compared with Opus 5.

Advertisement

Arena analyzed high-reasoning Text Arena responses from August and September 2026 and observed that 10 of 12 writing measures moved in what it considers a better direction.

Interestingly, Arena’s data confirms that Opus has almost stopped using em dashes, which was one of the biggest signs of AI-generated content.

Opus 5.5 uses fewer em dashes
Claude writing pattern has changed

Source: Arena

Opus 5 used 15.2 em dashes per 1,000 words, while Opus 5.5 dropped that figure to just 0.8, a reduction of roughly 95%. It also found that semicolon usage fell sharply from 6.10 to 1.64 per 1,000 words.

The newer model writes shorter sentences, averaging 10.03 words compared with 12.14 for Opus 5. However, there is one obvious tradeoff, and that is that Opus 5.5 is more verbose.

In other words, average answers increased from 453 to 481 words, making it the longest-writing Opus model in the comparison.

Advertisement

More lately, AI models have focused mostly on the coding side of things, so it’s quite interesting to watch Anthropic change how Claude writes, and if anything, you’ll see fewer em dashes on the internet.


article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Source link

Continue Reading

Tech

Why markdown is becoming the default language between search data and AI models

Published

on

Across the infrastructure layer that powers AI applications, Markdown has been emerging as a new standard. More providers are turning to it as the default output for anything a model needs to read, and moving beyond JavaScript Object Notation (JSON) as the go-to, one-size-fits-all format.

This real, ongoing shift reflects how large language models are trained, how chat interfaces render answers, and how developers actually build with tokens, context windows, and cost in mind. And there is good reason for this adoption.

Markdown fits how models work

Large language models have been trained on enormous amounts of Markdown. Think of documentation sites, README files, technical blogs, forum threads, knowledge bases and so on. That exposure means models already speak Markdown fluently; they know how to analyze its headers, lists, tables, and code fences, and treat them as semantic signals rather than noise.

At the same time, user-facing chat interfaces can already render answers from Markdown. When a model outputs Markdown, the front end can display it cleanly without extra transformation. When the same model ingests Markdown, it receives information in a form that mirrors its training distribution and the way it is expected to respond. The result is a more natural input-output loop than feeding models dense, nested JSON that must be mentally unpacked before use.

Advertisement

If you look at things from a token perspective, Markdown is also the leaner approach. It strips away structural overhead and keeps the informational payload. For AI agents that must fit large amounts of context into a limited window, that efficiency translates directly into more relevant content per request and lower cost per inference.

A visible trend

The move to Markdown isn’t speculative either. It’s already being encoded in best-practice guidance from major model providers. OpenAI’s prompt engineering documentation explicitly recommends structuring developer messages with Markdown headers, bullet lists, and tables where helpful. The guidance advises using ‘##’ for major sections, inline backticks for code, and clear hierarchical formatting to improve model compliance and readability.

Third-party prompting guides are echoing this same pattern. They use Markdown headings to create section breaks, lists for enumerations, and tables for comparisons. Several analyses note that Markdown is more token-efficient and more naturally understood by models trained on documentation, which makes it a preferred formatting tool for complex prompts, especially with newer GPT-5 series models.

Infrastructure providers agree

API and data providers have also been won over by Markdown. Where JSON once ruled as the universal interchange format, many are now offering Markdown variants optimized for LLM consumption. The rationale is exactly the same: they want to reduce token bloat, simplify parsing for agents, and align with how models are prompted and how answers are displayed.

Advertisement

SerpApi, a nine-year-old, search-data API company, recently launched Markdown output across all 100+ of its APIs at no extra cost. SerpApi serves developers, researchers, and Fortune 500 companies with structured insights from Google, Bing, YouTube, and other sources. The feature lets developers request search results in a token-light Markdown format instead of JSON, aimed specifically at AI agents and LLM-powered applications. No new endpoint is required, and the format is requested via a query parameter, route extension, or header on existing integrations.

In a real-world example from SerpApi’s own benchmarks, a single Google search for “coffee” costs 24,723 tokens as JSON and 6,435 tokens as Markdown, adding up to a 74% reduction. When combined with field filtering, the same response dropped further to 1,298 tokens. Across its APIs, SerpApi reports average token savings of roughly 50%, with some endpoints seeing reductions of up to 90%.

A table of SerpApi's token counts for eight APIs, comparing JSON with Markdown and showing savings from 36% to 91%.
Token savings across eight APIs, according to figures published by SerpApi. — Credit: SerpApi

These numbers matter because search results are among the noisiest, most nested payloads that agents ingest. JSON responses carry redirect links, favicons, tracking parameters, and deeply nested metadata that models do not need to reason over. Markdown output, in contrast, preserves the core information, such as titles, snippets, links, prices, and ratings in tables and lists while automatically stripping much of the internal tracking noise and duplicate fields.

Developers can access the new Markdown format by adding ‘output=md’ to the query string, calling the ‘/search.md’ route, or setting an ‘Accept: text/markdown’ header. The responses include YAML frontmatter for metadata, structured Markdown tables for result sets, and native inline links, all designed to be dropped directly into prompts or agent memory.

What this all means

As more of the web gets consumed by agents instead of humans, the infrastructure layer will increasingly optimize for machine readability over human-friendly nesting. JSON remains essential for programmatic manipulation and strict schema enforcement, but for the context ingestion phase of AI workflows, Markdown is emerging as the new default.

Advertisement

In the coming months, one should therefore expect more data providers to offer Markdown variants of their responses, especially for search, e-commerce, maps, and content APIs where token efficiency has an immediate impact on cost and performance. Prompt templates and agent frameworks are also likely to standardize on Markdown sections, tables, and lists as the canonical way to present retrieved context to models. Tooling should also evolve around measuring and minimizing token footprint, with Markdown as a primary lever.

For developers building with LLMs today, the writing is on the wall. When feeding external data into models, one should prefer formats that match how models are trained and how they output. Markdown is no longer just a documentation tool. It’s becoming the new lingua franca between search data and AI models.

Source link

Advertisement
Continue Reading

Tech

Qobuz Starts Labeling AI Generated Music and the Fraud Numbers Are Ugly

Published

on

Artificial intelligence has spent the past year learning how to write songs, create fake artists, imitate real ones, manufacture album covers, and upload music at a rate that would make Prince during his vault years look lazy. Qobuz would now like its subscribers to know when some of that music was made by a machine.

The French streaming service has officially rolled out an in-app tag identifying music that its proprietary system determines was generated by AI. That fulfills a promise Qobuz made earlier this year when it published its AI Charter and began scanning both new releases and its existing catalog for synthetic content.

The label itself is useful, but the numbers behind it are far more interesting. Qobuz says just 0.38% of streams on its service currently come from tracks identified as AI-generated, while 60% of streams from those tracks are deemed fraudulent by its anti-fraud systems and excluded from royalty payments.

Qobuz has also removed more than one-third of AI-generated albums with no listening activity from its search engine, representing roughly four million tracks. Those recordings have not necessarily been deleted from the catalog; Qobuz specifically says they have been removed from search.

Advertisement

That difference matters because the AI music problem is increasingly not about somebody using generative software to help finish a song. It is about enormous quantities of synthetic material being uploaded cheaply and rapidly, sometimes accompanied by artificial streams designed to siphon money away from the royalty pool.

Qobuz Logo

Why Qobuz Is Doing This

Qobuz has been heading in this direction since February. Its AI Charter states that editorial recommendations including playlists, Albums of the Week and Qobuzissimes remain selected by human editors, while its personalized discovery tools are designed to prioritize music drawn from those editorial selections and other trusted sources.

That philosophy now extends directly to AI-generated recordings. When Qobuz identifies music as AI-generated, subscribers can see that information instead of having to investigate whether the singer suddenly appearing in front of them has ever actually inhaled oxygen.

More importantly, Qobuz says identified AI-generated material is excluded from its editorial recommendations. That helps put the remarkably low 0.38% share of listening into context because synthetic content may exist on Qobuz, but the service is not deliberately placing it alongside human artists in its curated discovery channels.

That approach says a lot about how Qobuz views its role. It is not simply offering access to a gigantic catalog and leaving listeners to sort out the mess themselves; it is making an editorial decision about what deserves active promotion.

Advertisement

The 60% Number Is The Real Story

The most troubling figure is not how much AI music Qobuz subscribers are actually listening to. It is what appears to be happening around those streams.

Qobuz says 60% of streams associated with tracks it has identified as AI-generated are currently considered fraudulent by its systems. Those plays are excluded from royalty reporting and payouts, and Qobuz says content can also be removed when it detects fraudulent practices.

Advertisement. Scroll to continue reading.

That suggests the immediate threat is not that listeners are abandoning musicians for endless AI-generated albums. On Qobuz, at least, the available data suggests almost the opposite.

Advertisement

The larger problem is scale because generative systems can produce enormous quantities of music at almost no marginal cost. Upload enough tracks, manufacture enough plays, and even tiny payments can become meaningful when multiplied across millions of recordings.

Streaming was not designed for an environment where someone can effectively operate an automated record label containing more releases than entire generations of musicians could create. Qobuz is trying to prevent that volume from distorting discovery and pulling money away from legitimate rights holders.

For listeners, that makes the AI tag more than an ethical warning sticker. It is one visible part of a much larger effort to stop streaming catalogs from turning into digital landfill.

How Is Qobuz Different From TIDAL?

TIDAL has arguably taken the harder line when it comes to money. As we reported previously, the service labels recordings it determines are wholly AI-generated and does not attribute royalties to them.

Advertisement

Subscribers can also disable AI-labeled recordings entirely in Settings. Once enabled, that control prevents those recordings from playing and gradually removes them from personalized recommendations as those recommendations refresh.

TIDAL can also remove synthetic music tied to impersonation, deceptive behavior, high-volume uploads or fraudulent streaming. That gives its subscribers something Qobuz has not publicly announced: a direct “I don’t want AI music”switch.

Qobuz takes a somewhat different approach by combining its own detection technology with editorial curation, search controls and fraud enforcement. TIDAL gives listeners more explicit control over whether AI music enters their experience, while Qobuz is attempting to keep much of the questionable material from becoming prominent in the first place.

Neither service is simply banning AI. The distinction is how aggressively each one separates synthetic content from the normal machinery of discovery and payment.

Advertisement

Spotify Has A Different AI Problem

Spotify AI Persona Badges

Spotify’s approach has focused heavily on identity and disclosure. Its AI Persona system is designed to identify artist profiles whose public identity may represent an AI-generated person rather than an actual human being, while those profiles can be excluded from editorial and algorithmic recommendations unless listeners deliberately engage with them.

That is not quite the same thing as what Qobuz is doing. Spotify’s badge tells listeners something about who or what the artist supposedly is, whereas Qobuz is identifying the recording itself as AI-generated.

Spotify has also supported richer AI credits so artists, labels and distributors can disclose whether artificial intelligence contributed to vocals, lyrics, instrumentation or production. At the same time, it has tightened policies around impersonation, spam and other deceptive uses of generative technology.

Advertisement. Scroll to continue reading.

We have already covered the tension inside that strategy. Spotify wants stronger protection against synthetic impersonation and AI spam while continuing to explore licensed generative tools that could allow subscribers to manipulate commercially released music.

Advertisement

That makes Spotify’s position increasingly about authorization rather than opposition to AI itself. Synthetic deception is the problem; transparent, licensed and commercially useful AI remains very much on the table.

Apple Music Is Relying More On The Supply Chain

Apple Music is approaching the problem from another direction by leaning heavily on metadata supplied by labels and distributors. Its AI transparency framework can indicate when artificial intelligence materially contributed to artwork, a sound recording, a composition or a music video.

That model potentially provides more nuance than a single AI-generated label because Apple can distinguish where the technology was used. A recording created entirely by software is obviously a different proposition from an album where AI was used only for artwork or some element of post-production.

The weakness is equally obvious: much of that information depends on the people delivering the content reporting it accurately. Qobuz, by comparison, has built its own detection system rather than relying entirely on disclosure from the supply chain.

Advertisement

Apple’s approach may ultimately provide the most detailed metadata if everybody behaves. History suggests that last part deserves an asterisk the size of a record store.

Why Should Listeners Care?

Nobody should need a forensic-audio degree to determine whether the artist being recommended to them exists. Streaming services already exercise enormous influence over how music is discovered through playlists, recommendations, search placement and editorial promotion.

When synthetic music can be generated almost infinitely, allowing it to flow into those systems unchecked creates a basic mathematical problem. Human artists cannot release 10,000 albums before lunch, while software certainly can.

That makes transparency important, but discovery policy may matter even more. Qobuz’s most significant decision is not adding a small AI tag beside a recording; it is keeping identified synthetic content outside its editorial ecosystem while using fraud detection to prevent suspicious streams from entering royalty calculations.

Advertisement

That distinction matters directly to listeners because discovery is part of what they are paying for. A streaming service filled with endless automated uploads is not inherently more useful just because the catalog number keeps getting larger.

There is also a trust issue. If a recommendation engine places something in front of you, knowing whether it came from an actual artist or a synthetic production should not require investigative work after the fact.

The Bottom Line

Qobuz is not banning artificial intelligence from music, nor is it claiming that every use of AI is inherently fraudulent. It is drawing a much clearer distinction between AI used as a creative tool and synthetic content generated at industrial scale, while giving subscribers more information about what they are hearing.

Advertisement. Scroll to continue reading.
Advertisement

The most revealing statistic remains 0.38% because, despite the enormous volume of AI material being added to streaming catalogs, Qobuz subscribers appear to spend very little time listening to it. At the same time, the company says 60% of streams attached to identified AI-generated tracks are being flagged as fraudulent.

Those figures only describe activity on Qobuz, so they should not be treated as evidence for the entire streaming market. They do, however, raise an obvious question about the narrative that consumers are demanding an endless supply of machine-generated music.

If the listeners are barely listening and a large percentage of the plays are fraudulent, perhaps the machines are not only making the music.

They may be its biggest fans as well.

Advertisement

Source link

Continue Reading

Tech

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

Published

on

Oracle

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.

Google’s Mandiant and Threat Intelligence Group (GTIG) say this new technique has allowed the threat actor to once again target PeopleSoft servers that had not applied security updates and instead blocked access to the vulnerable PSEMHUB endpoint using a WAF.

On June 10, BleepingComputer first reported that the ShinyHunters extortion gang was targeting Oracle PeopleSoft servers using a zero-day vulnerability, allowing them to steal data from 100 organizations.

The next day, Oracle fixed the PeopleSoft zero-day as CVE-2026-35273, stating that it allows unauthenticated remote code execution.

Advertisement

Google also reported that same day that ShinyHunters, whom they track as UNC6240, was exploiting the CVE-2026-35273 flaw in attacks on the education sector, confirming BleepingComputer’s reporting.

At the time, Mandiant advised organizations that could not immediately install the security updates or disable the Environment Management Hub to block external access to the vulnerable `/PSEMHUB/*` endpoint.

However, in a new report, Google says ShinyHunters has now modified its exploit to bypass WAF rules that look for this literal path, rather than encoded versions of it.

For example, instead of sending requests to:

Advertisement

/PSEMHUB/

the attackers are requesting:


/%50SEMHUB/

The ‘%50’ sequence is the percent-encoded version of the letter ‘P’.

Mandiant says many WAFs and reverse proxies compare the literal request path before decoding it, causing rules designed to block ‘/PSEMHUB/’ to miss the encoded version.

Oracle WebLogic, on the other hand, decodes the encoded ‘P’ and routes the request to the vulnerable endpoint, bypassing the WAF rule.

Advertisement

“This allows the threat actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure,” Mandiant explains.

PSEMHUB WAF bypass
PSEMHUB WAF bypass
Source: Mandiant

Google warns ShinyHunters may not always use the ‘%50’ bypass variation, and could switch to other percent-encoded, mixed-case, or other variations of ‘/PSEMHUB/’ to bypass WAFs.

Instead of relying on a web application firewall, Mandiant urges organizations to install the latest security update to protect against CVE-2026-35273.

Organizations are also advised to search WebLogic access logs for requests to ‘/PSEMHUB/’ and encoded variants such as ‘/%50SEMHUB/’ to detect signs of exploitation.

WAF bypass leads to new data-theft attacks

Google says the new wave of attacks has deployed web shells on dozens of systems worldwide within higher education, technology, IT services, healthcare, agriculture, transportation, and government organizations.

Advertisement

“Mandiant recommends that organizations running Oracle PeopleSoft take the following immediate actions. Additional remediation and hardening guidance is included later in this post,” warns Mandiant.

Before attempting exploitation, the attackers typically send between five and 15 POST requests to `/%50SEMHUB/hub` containing serialized Java objects.

On vulnerable systems, these requests return information about the host operating system without writing files or disrupting the service, allowing ShinyHunters to determine whether a server can be exploited quietly.

Once they determine a system is vulnerable, the threat actors exploit the flaw again to execute commands directly in memory or deploy JSP web shells.

Advertisement

Google says the attackers deploy an ‘x.jsp’ web shell for command execution and ‘u.jsp’ and ‘u2.jsp’ shells for uploading larger files.

On compromised Windows servers, ShinyHunters used these shells to deploy an executable named ‘Ple64.exe’, which masquerades as a signed Light Alloy media player installer but installs a backdoor tracked by Google as SIDEEYE.

The SIDEEYE malware is used to steal credentials, for process and file management, to create interactive reverse shells, and for reverse proxy functionality.

The threat actors also deployed the open-source Neo-reGeorg tunneling toolkit via the ‘tunnel.jsp’ and ‘tunnel.jspx’ files.

Advertisement

This toolkit allows SOCKS5 proxy traffic to be tunneled over normal HTTP and HTTPS connections, letting the compromised PeopleSoft server be used to spread laterally into the internal network.

Mandiant also observed ShinyHunters using the legitimate MeshAgent remote management software to maintain access to compromised Linux systems.

ShinyHunters previously claimed a new PeopleSoft zero-day

These new attacks come after ShinyHunters claimed that they breached FBI systems using what they described as a new Oracle PeopleSoft zero-day vulnerability.

ShinyHunters told BleepingComputer on September 22 that the alleged vulnerability allowed remote code execution and was used to access the FBI Jobs platform, then spread laterally into the FBI’s AWS GovCloud infrastructure.

Advertisement

The group claimed it stole between 2TB and 3TB of data related to current and former FBI employees, job applicants, and other internal systems.

At the time, BleepingComputer could not independently verify the alleged zero-day, the claimed lateral movement, or the amount of data reportedly stolen.

The FBI confirmed that it was investigating claims of unauthorized activity affecting FBIjobs.gov but did not confirm that its systems had been breached or that data was stolen.

ShinyHunters has confirmed to BleepingComputer that they used this WAF bypass against FBI Jobs, but continue to claim that they also exploited “NEW unknown vulnerability in the same PSEMHUB component.”

Advertisement

article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Source link

Continue Reading

Trending