TL;DR
Federal agencies pledged over $5 billion to the Genesis Mission, funding 278 AI-for-science projects selected from more than 5,000 applications
Federal agencies pledged over $5 billion to the Genesis Mission, funding 278 AI-for-science projects selected from more than 5,000 applications
Federal agencies have committed more than $5 billion to the Genesis Mission, an Energy Department-led effort to use artificial intelligence to accelerate scientific research, White House science adviser Michael Kratsios announced on Wednesday. The initiative selected 278 projects from more than 5,000 applications, Energy Secretary Chris Wright said at a summit in Washington. More than 15 federal agencies are contributing research awards, funding, datasets, and facilities to the programme.
The Genesis Mission was established by a November 2025 executive order and is part of what the administration describes as the largest marshalling of federal scientific resources since the Apollo programme. Under Secretary for Science Dario Gil, who is directing the effort for the Energy Department, said the mission brings together leading researchers, institutions, and technology partners to build what he called the next generation of scientific capability. The DOE received the largest response rate for any programme in the department’s history, according to Gil.
The largest single award is a $60 million investment in nuclear energy, funding a three-year project called Prometheus that will use AI to help design, license, manufacture, and operate nuclear reactors. The project team has raised more than $200 million in industry cost share and $30 million in private capital alongside the federal funding. Other funded areas include biomedical research, energy grid reliability, national security, quantum computing, and microelectronics manufacturing.
Alongside the Genesis Mission announcement, Kratsios released a report to President Trump titled “Science: A New Golden Age,” which the White House described as the first comprehensive rethinking of the US science enterprise in more than 80 years. The report calls for federal research funding to shift toward AI-powered research systems and individual scientists rather than universities, which have historically dominated federally funded scholarship. Agencies with at least $3 billion in research authority will be required to submit implementation plans within 90 days.
The funding shift represents a deliberate attempt to reshape roughly $200 billion in annual federal research spending. The report cites the NIH Director’s Pioneer Award, which gives selected researchers up to $700,000 annually for five years without requiring a detailed experimental plan, as a model for the kind of flexible, investigator-driven funding the administration wants to expand. The blueprint also identifies national missions including commercial fusion power and returning Americans to the lunar surface by 2028.
The announcement comes as the US-China AI competition intensifies, with Stanford’s 2026 AI Index finding that the performance gap between the best American and Chinese AI models has collapsed to under three percent despite the US spending 23 times more on private AI investment. The Genesis Mission sits alongside other recent federal AI initiatives, including billions in EXIM export financing for US-built AI infrastructure and executive orders on quantum computing, as part of a broader push to maintain American technological leadership through public funding rather than export controls alone.
GitHub has confirmed plans to evolve its bug bounty program into a two-tier system, which will come into force for reports submitted on or after July 27, 2026.
Under the new scheme, the Microsoft-owned coding platform will add a lower-paying public program that’s available to the wider research community, under a higher-paying invitation-only program.
Product Security Engineer Catherine Cassell explained that the change comes in response to a growing backlog of low-effort, low-quality and AI-generated reports.
Latest Videos FromTechRadar
For the new public program, GitHub will replace payout ranges with a single payment for each severity, spanning $250, $2,000, $5,000 and $10,000 for low, medium, high and critical. Cassell said this would help researchers know in advance what a valid finding could be worth, and it would also give insiders less of a headache having to decide where a report sits within a range.
Notably, the payouts are much lower than before, with the previous ranges paying out $500-$1,000, $2,000-$5,000, $5,000-$20,000 and $10,000-$30,000.
Invited VIP researchers under the second plan will earn around 3-4x more than researchers under the other scheme, depending on bug severity.
GitHub is also adding a HackerOne signal requirement for new researchers, giving them four opportunities to “establish a track record” – likely another response to rising AI-generated reports, which are typically of lower value.
“We want to build a program that attracts the research we value, creates an experience that reflects how seriously we take this work, and upholds the trust researchers place in us every time they submit a report,” Cassell concluded.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
A lawsuit over Apple’s failure to deliver Apple Intelligence and Siri features is moving closer to a conclusion as a judge has provisionally approved the company’s settlement offer.
The class action suit filed in 2025 alleged that people had bought new iPhones expressly because of Apple’s promoting of Apple Intelligence features that it then did not deliver. Apple admitted in March 2025 that the new Siri features were delayed, but then in May 2025 offered a settlement.
Apple and the parties to the class action suit agreed to a $250 million settlement, but it had to be approved. Now in a filing in the US District Court, Northern District of California, judge Noel Wise has provisionally given approval.
The final approval and so the start of any pay out to buyers, though, is dependent on a final hearing which has now been announced for September 29, 2027. While Judge Wise has given overall approval, he ruled that the court will not decide on any amounts until that hearing.
It may be a quick final hearing, though, as the parties have already agreed to a payment of at least $25 per eligible device. It is possible, however, that this amount could rise to $95 per device if the number of claims filed is low.
There will be a way for users to formally apply to be part of the claim. But as MacRumors said on Friday yet the details of this have not been announced.
Earlier this year FCC boss Brendan Carr launched a series of fake investigations into ABC because the network (1) hosted Democratic Texas Senate hopeful James Talarico on The View, (2) aired comedians who made fun of the president and his wife, and (3) occasionally engaged in journalism critical of Trump corruption.
The details of these investigations really don’t matter at this point. We’ve discussed how they’re legally incoherent, clearly violate the First Amendment, and involve Carr actively manufacturing false claims that ABC violated FCC rules it was long-exempt from. At other points it just involves Carr being incoherently racist on Trump’s behalf; such as claims that ABC didn’t eliminate its “DEI” requirements quickly enough.
Carr’s now dumping additional empty threats into the mix, claiming that his ongoing review of ABC’s local broadcast licenses will take into consideration the network’s refusal to air Trump’s recent prime time speech, which mostly just involved Trump spewing more false election fraud conspiracy theories surrounding his 2020 loss.
ABC and NBC wisely refused to air the speech live, knowing that helping to spread distrust in election integrity in real time would be the opposite of useful journalism. That made Trump mad, so he’s clearly urged Brendan Carr to levy some additional empty threats against ABC:
“I think when you have the President of the United States standing inside the White House delivering an important speech, I think that’s something that broadcasters should be carrying. And so, obviously, this is an issue,” Carr told reporters Wednesday. “There have been lots of concerns raised, including by members of Congress, about whether broadcasters and their decisions there comply with the public interest.”
Carr is somewhat vague here because he knows this is a bunch of bullshit.
Obviously it’s ABC’s First Amendment right to determine what it broadcasts and when. Carr has absolutely zero legal role in determining the scheduling lineup of a private company. Carr’s once again pretending that networks that refuse to pander to our mad idiot king will be subjected to FCC review of their public interest obligations affixed to ownership of public airwaves.
As we’ve mentioned countless times already, Carr doesn’t want any of this to actually head to court because he knows it’s an absolute loser on First Amendment grounds. The real goal remains to threaten U.S. media companies with costly and annoying legal headaches if they challenge Republicans or the unpopular president. It’s typical lazy autocrat stuff by weak men who are afraid of words.
When it comes to ABC, that’s still been embarrassingly effective. The company agreed to pay Trump a $16 million bribe in 2024 to settle a baseless lawsuit the company easily could have won. And more recently, ABC shows like The View have shied away from hosting any political candidates at all for risk of upsetting Trump.
Brendan Carr has openly stated in interviews he fancies himself a tough, pit bull enforcer; but as Trump’s health and political power wane, the threats will hold less and less weight. As a result you’ve already seen ABC execs start to show a backbone in their fight with Carr, openly pointing out how he colluded with local right wing broadcast affiliates to manufacture evidence suggesting ABC broke FCC rules (something I’m sure will play great in court).
Carr’s threats will become weaker and weaker until he’s ultimately booted from office by subsequent administrations, at which point he’ll fail upward to some mid-six figure job at a telecom or media think tank, where he’ll spend the rest of his life helping corporate America dismantle whatever’s left of competition, labor, and consumer protection standards.
One of the ironic things, for Carr, is that his authoritarian censorship and saber rattling often draws press and public attention away from all the other terrible things he’s doing, whether it’s destroying media consolidation limits, making life easier on robocallers, dismantling broadband consumer protection standards, or making it easier for giant shitty companies to run amok.
You’d like to think Carr ultimately faces some sort of meaningful accountability for being one of the most censorial, petty, captured, and authoritarian regulators in U.S. history, but I wouldn’t hold your breath.
Filed Under: brendan carr, censorship, fcc, first amendment, james talarico, media
Companies: abc, disney
American fast food restaurant chain Chick-fil-A has confirmed that over 13,000 customers had their data stolen in a recent wave of credential stuffing attacks.
As BleepingComputer first reported, the company revealed in data breach notification letters filed with multiple attorney general’s offices that it detected attacks targeting its website and mobile app between June 17 and June 19 after identifying suspicious login activity to certain Chick-fil-A One accounts.
Chick-fil-A says the attackers used automated tools and credentials “obtained from a third-party source” to hack into Chick-fil-A One accounts and steal customer data.
“We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts. Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted,” the company told BleepingComputer.
During the attacks, the threat actors accessed a combination of customers’ names, email addresses, Chick-fil-A One membership numbers, the amount of Chick-fil-A credit, the mobile pay numbers, and the last four digits of the credit/debit card number. Additionally, they may have also gained access to birth dates, phone numbers, and addresses if stored in the compromised accounts.
While the company didn’t say how many individuals had their data exposed, Chick-fil-A notes in a filing shared by the Office of the Maine Attorney General with BleepingComputer on Wednesday that the resulting data breach affected 13,322 people in total.
In separate filings, it also told the Texas attorney general’s office the data breach impacts 2182 Texans and the Massachusetts AG that it affects 39 residents. Chick-fil-A has also sent data breach notification letters to residents of the District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.
In response to the incident, Chick-fil-A says it logged out all impacted accounts, removed payment methods, restored all affected Chick-fil-A One account balances, and has also added rewards to affected accounts as a way of apologizing. Since the accounts were compromised because they were using credentials stolen from third-party services, Chick-fil-A also advised impacted customers to change their passwords as soon as possible.
Chick-fil-A also disclosed in March 2023 that hackers stole the personal information of over 71,000 customers after hacking their accounts in another series of credential stuffing attacks between December 2022 and February 2023.
As one of the largest fast food companies in the United States, Chick-fil-A operates a network of over 3,000 restaurants across the U.S., Canada, Puerto Rico, the United Kingdom, and Singapore.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Erling Haaland is not the only Norwegian built around power, precision and making life difficult for the opposition.
Sigberg Audio is making its U.S. audio show debut at Southwest Audio Fest 2026 with the Manta active loudspeaker system, Saranna active floorstander and 10D dual opposed subwoofer.
The Norwegian manufacturer takes a rather different approach from the growing number of wireless speakers promising an entire audio system inside two attractive cabinets. Sigberg focuses on Hypex nCore amplification, DSP crossovers, manual parametric EQ and controlled directivity designed to reduce unwanted interaction with the room.
There is no Wi-Fi streaming, Bluetooth or HDMI eARC. These are active high-end loudspeakers for listeners who want the amplifiers, crossovers and drivers engineered as one system, not another lifestyle product whose future depends upon an app remaining alive.

The Manta is a four way active system comprising two powered monitors and a pair of dedicated Sigberg bass modules.
Each monitor uses a 12-inch midbass driver and a 5.5-inch coaxial driver containing a 1-inch silk dome tweeter. Three channel Hypex nCore amplification provides 600 watts per speaker, while DSP handles crossover and equalization duties.
Sigberg describes the Manta as a dual cardioid design. Its vented enclosure is intended to reduce sound radiating toward the sides and rear of the cabinet, potentially limiting early reflections from nearby walls.
The company claims rearward and lateral attenuation of approximately 10dB to 25dB across portions of the 100Hz to 5kHz range. That will not magically remove the room, but it could make the Manta considerably easier to integrate than a conventional loudspeaker with broad rearward radiation.
Sigberg recommends positioning the Manta between 10 and 50cm (4-20 inches) from the front wall and at least 40cm (15 inches) from the side walls. The included stands tilt the speakers upward by four degrees.

The Manta system being demonstrated in Dallas uses two Sigberg 10D subwoofers.
Each sealed cabinet contains two opposing 10 inch aluminum cone drivers powered by a DSP enabled Hypex nCore amplifier. The opposing drivers are designed to cancel mechanical forces and reduce cabinet vibration.
Sigberg specifies a frequency response of 23Hz to 250Hz, with typical in room extension to approximately 18Hz. Claimed average output is approximately 117dB from 30Hz to 80Hz at one meter under CEA 2010 measurement conditions.
Each 10D weighs 27kg, or 59 pounds, and includes RCA, balanced XLR and speaker level inputs. It also offers nine band parametric EQ and connection presets for use with an A/V receiver, conventional preamplifier or Sigberg active speaker system.

| Sigberg Inkognito | Sigberg 10D | |
|---|---|---|
| MSRP | $4,000 each | $5,000 each |
| Driver Type | 12″ Scan-Speak Aluminium cone | Dual 10″ Aluminium cone |
| Enclosure Type | Sealed | Sealed |
| Frequency Response | 23- 250Hz (±3dB); ~18Hz in-room |
23- 250Hz (±3dB); ~18Hz in-room |
| Max SPL | 113 dB | 117 dB |
| Amplification | Hypex nCore, DSP enabled | Hypex nCore, DSP enabled |
| Crossover/EQ | 9-band parametric | 9-band parametric |
| Inputs | RCA, XLR balanced, High-level | RCA, XLR balanced, High-level |
| Dimensions (WxHxD) | 650 x 540 x 163 mm (25.6 x 21 x 6.4 in) |
360 x 370 x 410 mm (14 x 14.5 x 16 in) |
| Weight | 22 kg (48 lbs) | 27 kg (59 lbs) |

The Saranna packages much of the same technology inside a narrower full range floorstander.
A front mounted 8 inch coaxial driver combines the midbass and midrange unit with a horn loaded compression driver. Two rear mounted 8 inch woofers handle the lower frequencies inside a ported enclosure.
Each Saranna contains 600 watts of three channel Hypex nCore amplification, DSP crossovers and nine band parametric EQ.
Sigberg claims a frequency response of 28Hz to 20kHz, with typical in room extension down to 20Hz. Claimed maximum output is 116dB per speaker.
The rear woofers might suggest that the Saranna needs considerable breathing room, but Sigberg designed the system to benefit from boundary reinforcement. The company recommends placement relatively close to the front wall, generally between 15 and 50cm.

The Manta and Saranna include their own amplification, DSP and active crossovers. Owners do not need separate power amplifiers, but they will still need a source component or preamplifier with volume control.
Both systems support RCA, balanced XLR, optical, coaxial S/PDIF and AES connections.
Their published specifications do not include Bluetooth, network streaming, HDMI eARC, automatic room correction or an internal phono stage.
That makes them less convenient than something from KEF, Dynaudio or Buchardt, but it also means the loudspeakers are not tied to a specific streaming platform. Owners can select or replace the front end without throwing away the amplification and loudspeaker system.
The manual nine band parametric EQ also provides considerable flexibility, although using it properly will require acoustic measurements, dealer assistance or some idea of what those frequency and Q controls actually do. Randomly moving sliders until everything looks exciting is not room correction.
Sigberg says its direct pricing includes worldwide shipping, applicable taxes, import fees and customs handling. The company also offers a 60-day home trial and 5-year warranty.
U.S. customers can purchase directly from Sigberg or contact DreamScapes A/V in Syracuse, New York.
The Sigberg Audio systems are being demonstrated inside the DreamScapes A/V Presidential Suite on the 10th floor of the Sheraton Dallas Hotel.
The Manta and 10D are confirmed for the room. The Saranna was announced for the show but was initially listed as pending customs clearance, so attendees should confirm its arrival before heading upstairs specifically to hear it.
Southwest Audio Fest 2026 runs from July 23 through July 25 at the Sheraton Dallas Hotel. Tickets cost $25 for one day or $40 for a multiday pass.

Sigberg Audio is not trying to build another attractive wireless speaker that promises convenience above everything else.
The Manta and Saranna combine purpose matched amplification, DSP crossovers, substantial output and controlled directivity in systems designed to work relatively close to the front wall. That could make them especially interesting for listeners who want full range performance but do not have an acoustically perfect listening room the size of a Norwegian football pitch.
The Manta is the more ambitious system, combining large active monitors with two dedicated bass modules. The Saranna delivers much of the same philosophy in a narrower floorstanding design without requiring external subwoofers.
Neither system is inexpensive. There is also no onboard streaming, HDMI eARC or automatic room correction, and anyone who changes amplifiers more often than Erling Haaland scores goals will probably struggle with the concept.
For listeners who care more about engineering, room integration and consistent system matching than collecting amplifiers, Sigberg Audio could be one of the most interesting manufacturers making its Dallas debut.
For more information: sigbergaudio.com
.png)
Outside gatherings seldom feature an ideal climate. A quiet morning may rapidly shift to heavy wind, abrupt gusts, or an unanticipated downpour. If you’re displaying goods at a commercial exhibition, organizing a public function, visiting a produce vendor site, or executing an advertising drive, erratic atmospheric conditions might ruin a whole arrangement unless the canopy was designed specifically for such elements.
A tent offers more than just shade protection. It shields individuals, gear, merchandise, and brand identity while allowing events to proceed securely against shifting weather patterns. Yet, no single canopy functions identically once winds begin to rise significantly. Your custom event tents are built with wind performance in mind, helping you select structures that avoid injuries, limit property destruction, and provide attendees with increased assurance during the whole exhibition period.
Knowing what traits boost stability aids firms in buying gear that works well every single year.
1. Choose a Strong Frame
Everything starts with the frame.
A high-quality frame gives the structural support required to endure shifting weather patterns. Commercial aluminum grades offer a good mix of strength and ease of carrying, whereas heavy steel frames give extra steadiness for tough settings. Stronger joints and lasting connectors likewise cut down on motion when winds blow hard.
A strong frame creates a stronger foundation.
2. Secure Anchoring Matters
Even the most robust tent will fail to stay steady if it lacks correct securing.
Stakes function nicely on grass plus soft ground areas, yet heavy plates, sandbags, or water containers give extra stability on concrete plus pavement surfaces. Each leg needs securing prior to the start of events, specifically whenever wind conditions are anticipated.
Proper anchoring greatly improves safety.
3. Select Wind-Resistant Canopy Fabric
Fabric quality affects more than appearance.
Heavy-duty fabrics stretch less, tear less, fade less, and hold up against water better than lightweight options. Waterproof layers, UV protection, strong seams, and tough corner pads help make things work well at outside parties.
Quality materials increase long-term durability.
4. Look for Aerodynamic Designs
Tent shape influences wind performance.
Certain roof shapes let wind pass over the frame rather than hitting big flat areas hard. Open vents cut down on pressure too since they give air a way out via special holes, which lowers the upward push made by fast winds. The same aerodynamic thinking applies to your custom inflatable arches, which are engineered to channel airflow smoothly rather than resist it, making them a reliable choice for outdoor events where wind is a concern.
Smart design improves overall stability.
5. Match Tent Size to the Event
Larger tents catch more wind.
Selecting a cover fitting true space needs cuts unneeded wind drag. Small gatherings might need just small shelters, yet big shows ought to employ properly strengthened frames plus extra anchoring support.
The right size improves both safety and efficiency.
6. Inspect Your Equipment Regularly
Even durable tents require routine maintenance.
Prior to each event, check the frame, connectors, fabric, anchors, and fasteners for indications of wear or harm. Secure loose hardware and swap out broken parts prior to them turning into bigger issues under windy circumstances.
Regular inspections help prevent unexpected failures.
7. Use Sidewalls Wisely
In terms of wind resistance, fully enclosed sidewalls could create wind traps, which may increase the load onto the frame. If you’re expecting heavy winds, consider partially opening your sidewall (or using some vented panels), as this will allow for good airflow while keeping you protected against weather elements. Balanced airflow improves the stability of your tent.
8. Monitor Weather Conditions Throughout the Event
Check weather forecasts again right before you start setting up for an event. You might be able to avoid problems by watching wind conditions all day long.
If you see that the winds have exceeded those recommended by the manufacturers of your tent, consider lowering or dismantling the tent to reduce the risk of damage or danger to yourself and others. Staying alert protects more than just your interests.
Windy conditions ought not to stop a successful outdoor gathering from happening. Firms putting money into tough frames, dependable anchor setups, nice cloth materials, airflow shapes, correct sizes, and routine care get better steadiness and less worry during all events.
Top tents are not merely made for looks; they are designed for function. When weather turns uncertain, reliable gear shields your crew, clients, goods, and reputation so events proceed with assurance.
AI has made it stupidly easy to fake being a real person online, so Facebook is rolling out a new badge to prove you’re not one of them. It’s called Facebook Verified, and the best part is that it won’t cost you a thing.
I love that Facebook has made it easy to get verified. You record a short video selfie, and Facebook checks it against your existing profile photos to confirm it’s really you. The whole thing takes just a few minutes, and unlike some other social media platforms, Facebook isn’t charging you a subscription fee for this checkmark.

That said, not everyone gets to join the club. You need to be 18 or older, and your account has to be in good standing with Facebook’s rules around fraud, scams, and deceptive behavior. Show any signs of inauthentic activity, and you can forget about getting that badge. Also, Pages and ProMode accounts are not eligible right now.

Facebook has said that the feature is rolling out in phases, starting with select markets before it goes global, so don’t panic if you don’t see it on your account just yet.
Once you’re verified, the badge follows you to the spots where trust actually matters, like Marketplace, Facebook Dating, Groups, and your profile. Facebook says Feed posts will get the badge too, eventually.
You only have to verify once, and that badge travels with you everywhere. So next time you’re negotiating over a secondhand couch or matching with someone on Dating, you’ll know there’s an actual human on the other side.

Facebook also says that verification isn’t an endorsement. The company is upfront that the badge doesn’t mean it’s vouching for anyone’s trustworthiness. Verified users still have to play by the same Community Standards and Commerce Policies as everyone else.
As much as I abhor some of the Meta policies, this is a step in the right direction. As AI-generated profiles get harder to spot, a free badge that says “yes, I’m a real person” feels like a pretty useful thing to have around.

In a headquarters and lab space formerly occupied by SpaceX in Redmond, Wash., AIM Intelligent Machines (AIM) is focused on solving big problems on Earth. But the startup’s CEO envisions a day when autonomous bulldozers and excavators will dig, haul, and grade on the moon or Mars, and take AIM’s “terraforming mission” off planet.
For now, AIM’s 25,000-square-foot facility in a nondescript business park is a long way from Mars. Inside the sprawling space, there are glimpses of what the rapidly growing company is working on, including the apparatuses that attach to existing machines to make them self-driving.
Around the office, desk cubicles are decorated with tiny yellow excavator buckets, mirroring photos on the walls of heavy equipment operating on job sites worldwide.

The toy excavators are a nod to a massive global market that AIM founder and CEO Adam Sadilek wants to continue to disrupt with modern technology.
Autonomous passenger vehicles have captured the public’s attention for decades, but construction, mining and hauling equipment attracts little fanfare, even as legacy companies including Komatsu and Caterpillar embrace new technology.
AIM’s goal is not to build new machinery, but retrofit existing earthmoving fleets with a physical AI platform — using advanced sensors and edge compute to let heavy iron operate entirely on its own.
Founded in 2021, the startup grew out of Sadilek’s background at Google where he spent nine years working on projects involving AI and autonomous vehicle systems.
Whether building anti-flood structures or wildfire breaks, managing nuclear waste, mining critical materials or clearing land for agriculture or the military, Sadilek views AIM’s work as immediate terraforming on Earth that is necessary to drive down costs for housing and commodities. But the long-term vision remains interplanetary.
“When humanity goes to Mars, the real question is not so much around what the rocket looks like as a vehicle to get us there, but what is going to happen after the rocket lands,” Sadilek said. “You cannot have human operators run there. That’s why this is a very long mission that we are on.”
Building autonomy for heavy equipment presents a paradox self-driving cars never have to face: the ground itself is constantly changing. While a Tesla or Waymo relies on pre-mapped roads and predictable lanes, a bulldozer or excavator’s entire job is to reshape its environment. AIM’s physical AI platform has to continuously build real-time 3D maps using onboard 360-degree LiDAR and edge compute, making split-second decisions without relying on persistent GPS or cloud connectivity on remote job sites.
Furthermore, taking human operators out of cab seats addresses one of the most perilous aspects of heavy industry. By creating “zero-entry” sites where machines operate autonomously, AIM’s platform effectively removes workers from harm’s way — transitioning traditional equipment operators into remote site supervisors who oversee entire fleets from a safe distance.
Beyond early deployments in mining and site preparation for data centers, AIM landed a $4.9 million U.S. Air Force contract earlier this year to deploy autonomous machines for airfield repair and base construction in remote or high-risk zones. The military work builds on the company’s growing momentum following a $50 million funding round backed by Khosla Ventures, General Catalyst, and Human Capital.
AIM has risen to No. 110 on the GeekWire 200 ranking on top Pacific Northwest startups.
To support its growth, AIM has rapidly expanded its headcount, doubling in size to about 80 employees in the last few months. Sadilek is attracted to the Seattle area’s intersection of hardware expertise from companies like Boeing and Amazon alongside top-tier software and AI talent.
But while AIM has managed to hire a couple former SpaceX engineers to build out its team, it isn’t the only startup mining that rocket-engineering pedigree. TerraFirma, an Austin-based company founded by two more SpaceX engineers, raised $115 million earlier this month in the burgeoning race to semi-automate physical construction.
For Sadilek, anchoring his team in Redmond rather than Silicon Valley was a deliberate decision to stay rooted in physical engineering. Having spent years in the Bay Area during his time at Google, Sadilek wanted to avoid the tech industry’s “echo chamber.”
“I wanted to be somewhat shielded from the Kool-Aid in Silicon Valley,” he said. “We wanted to build something that’s real and gets in the black really quickly… To do that, you need to do it in an environment that is more anchored in reality.”
That philosophy extends directly into their field testing. AIM’s regional proving grounds in the mountains near Monroe, Wash., expose the autonomous equipment to heavy snow and inclement weather early in development so the physical AI is built for harsh, real-world conditions from day one.

Amid the hard hats, safety vests and construction-related decor in AIM’s headquarters space, one piece of art offers a fun take on where AIM has been and where it’s headed.
The 1949 photograph, titled “Refueling the Sunkist Lady,” shows a Jeep driving beneath a low-flying plane and transferring supplies to aid the crew during an endurance flight.
Sadilek likes it as a reminder of getting started, and what it feels like to build a company from scratch, literally working on the airplane while it’s already rolling down the runway.
“The first years of AIM were exactly like that,” he said. “I think every tech startup is like that in the early days. The problem is that some of them never finish building it before the runway ends.”
The Hide My Email failure is real but nowhere near as significant to users as it’s being portrayed, Apple is hiking so many prices yet looking at ways to make that palatable, plus Foxconn has begun its annual recruitment drive as it begins producing millions of new iPhones, all on the AppleInsider Podcast.
It’s been painted as a big security failing by Apple, and it definitely isn’t good. But even if someone does manage to circumvent your use of Hide My Email, the worst they can do is send you a spam message.
There’s more to it, of course, and if there weren’t then you wouldn’t benefit from listening to Wesley Hilliard explaining it on the podcast. But while it’s good to know the background, not to mention interesting, you can be reassured too.
Which you might also be by how Foxconn is ramping up its recruitment right on schedule. Even if you’re not looking for a job assembling iPhones, it means that the iPhone 18 Pro is on track.
It would be, of course, and the only real questions are whether it can possibly match the success of the iPhone 17 Pro range, and whether there will be an iPhone Fold.
Although of course, there is also the issue of just how much any of these new iPhones will cost. But a strong new rumor claims that Apple will shortly launch a new Apple Upgrade program, specifically to make it possible to buy with a lower upfront cost.
If Apple gives us this leasing program, it also may take away something. To protect it from people just signing up and walking away with costly iPhones, Apple is believed to be readying a way to restrict the use of its devices if a payment is missed.
BONUS: Subscribe via Patreon or Apple Podcasts to hear AppleInsider+, the extended edition. This time, speaking of payments, the discussion is on technology and money, specifically how we need to manage our finances and how options like Apple Card can usually help.
Tune in to our Smart Home Insider podcast covering the latest news, products, apps, and everything HomeKit related. Subscribe in Apple Podcasts, Overcast, or just search for HomeKit Insider wherever you get your podcasts.
Podcast artwork from Basic Apple Guy. Download the free wallpaper pack here.
Those interested in sponsoring the show can reach out to us at: [email protected].
Keep up with everything Apple in the weekly AppleInsider Podcast. Just say, “Hey, Siri,” to your HomePod mini and ask for these podcasts, and our latest HomeKit Insider episode too. If you want an ad-free main AppleInsider Podcast experience, you can support the AppleInsider podcast by subscribing for $5 per month through Apple’s Podcasts app, or via Patreon if you prefer any other podcast player.
Three attacks, three names, and one identical flaw: AI coding agents treat a hallucinated identifier as a verified command.
By Shane Warden, Principal Architect, ActiveState
Ask an AI coding agent to fetch a tool. Occasionally, it returns a name that sounds right, but does not exist. Developers used to ignore this mistake, assuming a compiler or test would stop it. Unfortunately, that assumption is dangerous and wrong.
Effectively now we’re giving root access to language models that sometimes guess words, and attackers know how to use that against us.
The attack goes like this: an attacker can calculate URLs, software library names, and other output an LLM will produce and subsequently access somehow. The attacker grabs the name, then sets a trap and waits.They do not need to steal passwords. They do not need to send phishing emails.
They do not need a human to click a link. They need someone, somewhere to give an automated process permission to fetch something malicious.
Researchers at Tel Aviv University, Technion, and Intuit published a paper on July 8, 2026. The team, led by Aya Spira in Ben Nassi’s group, proved that these fake names are predictable.
They tested multiple prompts across Cursor, Windsurf, GitHub Copilot, Cline, Gemini CLI, and OpenClaw. Models hallucinated identical names up to 85% of the time for repository requests. They hallucinated identical names 100% of the time for skill installs.
“Slopsquatting exploited a fake package name. Phantom squatting exploited a fake domain. HalluSquatting exploits a fake repository or skill,” Warden says. “In every case, the agent trusts a name nobody verified.”
That comparison undersells what is new here. Slopsquatting and phantom squatting get an attacker’s code onto one machine at a time. HalluSquatting scales further for attackers, because the agent does the delivery work a botnet operator used to need real machine compromise for.
There are no stolen passwords, no worms crawling from device to device, and no single operating system to target. Any machine running an exposed agent can be a target.
The researchers built this attack specifically to demonstrate that it repeats at scale, which is why they treat their own numbers as a floor rather than a ceiling: “Attacks always get better,” they write. “They never get worse.”
Cordyceps passed every check because no single workflow file was wrong, it was the composition that was exploitable.
See how to close that gap by governing what enters your build at the source, not just what passes the scan.
Security teams have seen this failure three times in six months.
January 2026 (Slopsquatting): Charlie Eriksen at Aikido Security caught AI agents trying to install a fake npm package named react-codeshift across 237 projects. He registered the name to stop attackers from taking it.
June 2026 (Phantom Squatting): Unit 42 at Palo Alto Networks found 250,000 domains that language models hallucinate. Anyone could register those domains.
July 2026 (HalluSquatting): Spira’s research team showed how attackers can take over AI agents by claiming predictable names in advance.
Every attack relies on the same core defect. The system trusts a name that a model generated without checking if anyone verified and validated it.
This problem stems from two connected issues.
First, language models generate their outputs based on probabilities. Given the right inputs, they’ll produce predictable outputs (not deterministic, of course, but the paper shows that they’re predictable enough to produce attack vectors). This reminds me of rainbow tables, where you can pre-generate the output of password hashes.
You don’t have to know someone’s password if you can get the (insecure) hash and you know an input which creates that hash.
Second, developers build and run code and pipelines that execute commands based on the generated output of these language models. Unless you’re very careful, your agents will run code or fetch data before they take the opportunity to vet and verify the source of that code and data.
In software architecture, this kind of late binding offers flexibility. In security architecture, trusting an unverified external data source creates a massive vulnerability. The danger lives in the gap between text generation and code execution. What was safe and true may have changed since you last checked yesterday (or an hour ago).
Developers are rushing to ship products faster. They treat build infrastructure like disposable tooling, even while granting these tools expansive permissions to download, change, and deploy things. They have automated typosquatting and dependency confusion.
When agents now have permission to fetch and execute code without sufficient human review, your risks of attacks grow.
The risk extends beyond the top-level packages. An agent might select a real package with a real name. Modern security tools may check that top-level package. Do you know they rarely inspect the transitive dependencies three or four layers down the tree?
Developers cannot inspect those dependencies simply by reading the top-level source code or saying “That looks correct” and hitting Enter. Worse, if a dependency is compromised but the previous versions were fine, the rules you had in place yesterday may not protect you today.
If an attacker can compromise a deep dependency or anything it relies on, an automated pipeline can bring that compromise into your systems.
The researchers note that their findings represent a minimum risk level. These attacks will become faster and more accurate in their targeting. Existing security tools fail against these attack patterns.
In June 2026, Trail of Bits bypassed agent skill store scanners in less than an hour. Scanners examine stated claims rather than hidden payloads.
SSL certificates and DNSSEC fail to stop this threat. An attacker who registers a fake domain can easily get a free Let’s Encrypt certificate. The certificate proves who owns the domain, but it cannot prove that the user intended to connect to it or that the domain is safe.
DNSSEC prevents other people from taking over a domain, but what if the domain were registered yesterday because an attacker predicted the latest model would send people there?
To secure your systems, you must ensure that none of your pipelines ever execute unvetted code or data. That vetting and verification has to happen automatically, at the speed of AI. Human review cannot keep up with automated AI tools.
Engineering teams must address this problem directly. They can spend significant time building internal verification pipelines, or they can adopt an existing governance solution.
Teams that patch individual tools will spend years chasing new variations of this exploit. Teams that fix the underlying design flaw will stop the attack before the model ever runs an untrustworthy command.
Organizations must resolve open source dependencies through something like ActiveState’s Curated Catalog, a private, policy-governed repository of vetted components. The catalog verifies the package before the agent downloads it. A package which fails this vetting is completely invisible to the agent, causing a failure before any bad code can enter your systems.
This is a different defense than scanning. Trail of Bits broke scanners because scanners inspect an unknown upload at the moment of fetch, exactly when an attacker has optimized the payload to slip past.
The Curated Catalog removes that moment entirely: it only ever serves components that were vetted and verified before any agent asked for them, so there is no unknown upload left to bypass. This single step turns a statistical guess into a trusted resource or a deliberate failure which needs human investigation.
HalluSquatting is an attack where researchers pre-compute the fake repository, package, or skill names that AI coding agents predictably invent, register those names first, and load them with malicious instructions before a real user’s agent goes looking for them.
All three exploit the same flaw, an agent trusting a name nobody verified, but target different resources. Slopsquatting targets npm package names, phantom squatting targets web domains, and HalluSquatting targets repositories and agent skills, then executes the payload directly through the agent’s own tool-use permissions.
Not reliably. Trail of Bits bypassed every public skill-store scanner they tested in under an hour, because scanners inspect an unknown upload’s stated content rather than its hidden payload. A static, post-hoc scan is racing an attacker who built the payload specifically to defeat that scan.
Turn on pre-fetch verification wherever it exists; most agent frameworks ship with it off by default. Route open source dependency resolution through a governed, pre-vetted catalog instead of letting agents fetch directly from public registries.
The researchers found hallucinated names were consistent across tools built on different underlying models, including Cursor, Windsurf, GitHub Copilot, Cline, Gemini CLI, and OpenClaw. This is a pattern in how agents are built and permissioned, not a flaw isolated to one vendor.
Sponsored and written by ActiveState.
Weekend Open Thread – Corporette.com
The House | The City of London can help the new chancellor deliver growth in every postcode
Ripple Payments Joins MiCA With 14 Firms, Does It Mean Anything For XRP?
Democrats look to World Cup watch parties to register thousands of voters
Ripple wins EU-wide access as ESMA adds it to MiCA register
Grayscale Files For Worldcoin ETF, WLD Registers Sharp Rise
Sail Virtually Aboard The “Itanic” With IA-64 Emulator
Unregistered fitter used Gas Safe logo on business flyers
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
Big Money Is Entering XRP
New Jersey voter registration controversy explained: How 6,600 noncitizens got on the rolls, and what happens next
Kaspersky exposes OkoBot’s 20-module crypto wallet attack
Airlines warn Sunshine Protection Act could disrupt flight scheduling
Johnny Depp’s R-Rated Gothic Cult Classic Gets New Release Ahead of Sydney Sweeney Remake
Durham County Council to send out electoral registration emails
Ethics, other provisions in crypto Clarity Act to be further discussed
MiCA Licensing Faces Delays as ESMA Adds 14 CASPs to Register
Chip Stocks Enter Bear Market After Moonshot Ai Unveils Kimi K3 Model
Shanghai science forum photos show China’s AI and robotics advances in rivalry with US
Watch Flock Safety CEO Garrett Langley discuss the future of surveillance at TechCrunch Disrupt 2026
You must be logged in to post a comment Login