❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 20 September 2026Main stream

Acer Predator QD-OLED monitor now 36% off β€” 500 Hz refresh rate and True Black 500 certification slashed to $509.99

Most every day there's yet another bit of news about how RAM, SSDs, and hard drives are insanely expensive. Today, though, there's a reprieve from high prices, in the form of a sale on an exceedingly nice display. The Acer Predator X27U, or model F5bmiippruzx as it's known to friends, is a 27" 1440p QD-OLED display with a whopping 500 Hz refresh rate and DisplayHDR True Black 500 certification, making for a consistently bright experience. It can be yours for a mere $509.99 at Newegg right now.

The Predator X27U's display is one of the latter-generation QD-OLED 27" 2560x1440 types, granting it that massive 500 Hz refresh rate and increased brightness compared to earlier offerings. It's as good a time as any to note that Acer reused the "Predator X27U" moniker β€” the F5 model on sale is the nicer revised version, just in case you go searching and find the old specs.

Predator X27U F5 - F5bmiippruzx: was $799.99 now $509.99
The revised Predator X27U F5 has a massive 500 Hz refresh rate and DisplayHDR True Black 500 certification, all for a low price.View Deal

Broadly speaking, OLED displays all have near-zero black levels, an infinite contrast ratio, and "perfect" viewing angles and response time. However, this model's DisplayHDR 500 True Black certification is the star of the show, as it ensures that brightness in HDR mode must be at least 500 nits, but most importantly, that full-screen brightness is at least 300 nits.

Put together, this means that for standard desktop usage, you get a consistently bright image regardless of what's on screen, and that brightness fluctuations ought to be tame β€” all unlike OLED displays of old. Those 500 nits in HDR mode are also a minimum, too, as Acer says that this display's peak brightness should top out at 1000 nits for 3% panel coverage, for nice highlights during action. As with most any OLED display, the color gamut covers 99% of the DCI-P3 space, and there's true 10-bit input support.

To make the best use of the 500 Hz refresh rate, the Predator X27U has both AMD FreeSync Premium Pro and Nvidia G-Sync Compatible support. The included stand is height-, tilt-, and swivel-adjustable. The newer revision eschews a proximity sensor and other similar accessories for its lower price, but it does include USB-C connectivity alongside two DisplayPort 1.4 inputs and two HDMI 2.1 ports. A pair of 5W speakers round out the main specs. Get yours now from Newegg for $509.99.

Yesterday β€” 19 September 2026Main stream

Hacker turns 25 cents into 46 billion fake Bitcoins to steal $770,000 β€” Symbiosis DeFi exchange bit by lack of basic bounds checking in smart contract

Symbiosis is one of the many useful DeFi networks that let users trade across almost any crypto pair without having to talk to an exchange. It's been operating for five years, and links some 50-odd chains together. The ecosystem's reliance purely on smart contracts (code that's hosted on the blockchain, visible to anyone) is fully logical but paradoxically creates an accountability problem. This was demonstrated on September 11, when Symbiosis got hacked to the tune of at least $770,000, or 9.97 BTC.

Smart contracts are published on the blockchains themselves and are open-source by definition. This means anyone can find a bug, and Symbiosis' thief found two: an undisclosed privilege escalation exploit that let them fake network administrator privileges, plus a Coding-101 failure of not checking if a transaction fee was a positive number.

The method was simple: being an admin, the thief set the transaction fee to a negative value, then issued 12 transactions. With the transaction fee now negative, instead of deducting from the moved amount, it added to it. The thief only spent 330 satoshi (the smallest unit of BTC), about 25 cents, but he managed to issue 46 billion syBTC β€” BTC wrapped in Symbiosis' network. For reference, the maximum theoretical amount of BTC in circulation is 21 million.

These syBTC tokens meant nothing by themselves as they weren't backed, but they were tradable. And trade the thief did, selling syBTC against matching wrapped pairs including BTCB, cbBTC, WBTC, and RBTC, draining those pools, and causing $770,000 worth of BTC in damage. It's known that they only converted about $336,000 into cash via Uniswap before being cut off.

The rest of the wrapped BTC tokens were flagged by security firms and exchanges, making it difficult for the thief to use. That's of little comfort for the victims, though, until such time as the thief returns the tokens by themselves or by law. Some of them, like Coinbase's cbBTC, are issued by centralized entities and can be nullified and re-minted after a legal process, but others like RBTC cannot.

For the uninitiated, DeFi (decentralized finance) pools can be broadly described as automated trading pots. They run on existing blockchain networks like Ethereum or Solana, via smart contracts, and let users trade directly against the money in the pool, with no third party in between. Depositors providing liquidity to the pool get a cut of transaction fees whenever other users trade for it.

Example: lock 1 ETH, and you get a small amount whenever someone buys or sells ETH, effectively netting you "interest" on held currency with next to zero effort. The trader didn't have to interact with anyone: just with a piece of code, the smart contract. To make the transactions work, DeFi networks "wrap" other tokens in their own variations, like BTC turning into syBTC.

Symbiosis says it intends to repay the incurred debts, stating that "a portion will be returned from the evacuated funds, and each LP will be offered an individual compensation plan." In practice, this ultimately means that Symbiosis is going to talk to the big wrapped-BTC holders in its pool and offer them an IOU, interest-bearing debt package, or some variation/combination thereof. In these situations, it's somewhat expected, but not guaranteed, that big holders take the deal, as forcing liquidation would end the network entirely and net them pennies on the virtual dollar.

The project also said it's going to rewrite the Bitcoin-side logic and has requested an independent audit before implementing the new code. Likewise, it claims it requested a full audit of the "entire system." Symbiosis also says that "capable AI models have lowered the cost of finding bugs like this," a perfectly valid argument β€” and yet one that isn't likely to find much purchase given the code's high-risk nature involving money, plus the base fact that someone missed a basic negative-value check in only what's likely only a few thousands lines of code total.

Before yesterdayMain stream

Investigative report details how export-restricted Nvidia AI chips reach China β€” public records reveal how Chinese entities skirt US sanctions

American nonprofit C4ADS, a monitoring organization funded mostly by the U.S. government, produced a report shedding light on the many ways that American AI accelerators reach China. Somewhat paradoxically, the U.S. refuses to sell advanced AI chips to China, while simultaneously the CCP prohibits their purchase, but that has seemingly not stopped the products from arriving on Eastern shores.

C4ADS's report identifies three major avenues for chip smuggling: direct acquisitions via research institutions, drop-shipping through other Southeast Asian countries, and purchases through a matryoshka-doll-like structure made of shell companies. The writers note that only explicitly mentioned chips are accounted for, meaning the actual amount of hardware changing hands could be far higher. Another earlier report by Epoch AI estimates that around a third (and possibly most of) China's AI compute power is comprised of smuggled GPUs.

Firstly, a quick primer on chip logistics. Nvidia has most of its chips manufactured and packaged at TSMC in Taiwan. An individual chip, or the entire accelerator unit it's in, might go through several rounds of testing, potentially doing more than one trip before it lands in a customer's data center.

As for export and import controls: the U.S. forbids the sale of H100, A100, and Blackwell-family chips to China; the lower-end H20 chip and the meatier H200 (and AMD MI325X) can be traded on a case-by-case basis, with the latter getting a 25% tariff. Meanwhile, China's broad position is to discourage and restrict the purchase of American AI chips, in a bid to spur its national efforts, currently spearheaded by Huawei. However, multiple reports indicate the authorities often turn a blind eye to gray/black-market imports, and 2026 saw official exceptions issued to ByteDance, Alibaba, and Tencent.

The first way to get a 'forbidden' chip into China via quasi-legal means is by simply getting a Chinese university or research institution to buy it. These entities reportedly include Nvidia GPUs inside "sprawling multi-vendor contracts," routed through small Chinese regional integrators.

The report also claims that some buyer institutions have ties to the CCP and the country's defense and intelligence sectors. C4ADS says that it tracked 56 chips worth $1.7 million sold this way in the report's July 2025 to January 2026 period. Additionally, it says that its 2024 investigation covering multiple years of government records revealed $6.48 million worth of silicon heading to China in this manner.

The second route for smuggling potent silicon is technically legal, via drop-shipping it through Southeast Asian countries including Vietnam, India, and Malaysia. C4ADS analyzed transactions between 2022 and 2025, and found $13.4 million of Nvidia A100, H100/GH100, and AD102-series GPUs routed through the aforementioned countries, in a "consistent pattern." Some chips traveled from Taiwan to Vietnam, possibly aided by the fact that Vietnam's chip testing facilities offer a good excuse for the trip. The investigation remarks that the timing, volume, and destination of many shipments could obscure their true intent.

A portion of purportedly tested chips traveled on to Hong Kong, where two companies "[dominate] the import side", Profit New Limited and ELB International Limited. The former traded trading $8.7 million of silicon in a single day in March 2025, likely in preparation for April 2025's tightened export controls. Some high-value shipments in the dataset were apparently bereft of cost, insurance, weight, or freight values, and also had nice round zeros in their import value declarations, raising suspicions about the veracity of their documentation.

The largest category, though, is opaque ownership β€” or shell companies. According to C4ADS, this method accounted for $4.6 billion worth of intelligent sand migrating to China, on the account of just one entity, Megaspeed International. This firm was reportedly the biggest Southeast Asian importer of Nvidia hardware in the time span between 2023 and 2025. However, its actual ownership is "unresolved."

Megaspeed has multiple companies across Singapore, Indonesia, and Malaysia, but it was purchased in 2023 by Swiftdata, another Singaporean firm. Before that, it was owned by Chinese gaming firm 7Road Holdings. During the transition, however, Megaspeed's major shareholder was temporarily Chinese businesswoman Huang Le, who's also a director of a Hong Kong company that bought transceivers from Megaspeed Indonesia. C4ADS believes Le may still be calling the shots at Megaspeed, though, seeing as she's identified as the firm's chairwoman at a conference as recently as 2025.

The speed and manner in which Megaspeed changed hands also raised some eyebrows, and it's still seemingly unclear who owns Swiftdata itself. Given that Megaspeed reportedly obtained export-locked Blackwell chips, it's hard not to find its dealings more than a tad murky.

C4ADS does issue recommendations to try and mitigate the problem. Namely, it remarks that the U.S. Bureau of Industry and Security gets allocated additional staff and resources so it can verify where the wares landed after their sale, and who their end users are. This could arguably be difficult to enforce, as it would require a level of cooperation from other nations that might prove a tad tricky to obtain in the current political climate.

In the researchers' own words, "U.S. and friend-shored semiconductor manufacturers, equipment makers, and distributors should invest in a robust end-user verification system that goes beyond standard restricted-party list screening, incorporating on-the-ground due diligence, corporate ownership tracing, and post-shipment verification." To the private sector, C4ADS recommends that firms add geopolitical and risk analysis into their frameworks, in a bid to assess if their direct or downstream customers could be selling wares to China's military or intelligence sectors.

Retired Microsoft Engineer details the story about the famous leaked FCKGW Windows XP key β€” copy protection used 10MB of encrypted Microsoft Bob for validation

Anyone old enough to be messing with PCs in the early to mid-2000s probably has the following burned into their mind: FCKGW-RHQQ2-YXRKT-8TG6W-2B7Q8. That's neither a magic spell nor a password for a cabal β€” it's the best-known Windows XP key, letting anyone install and run the operating system with its incantation and just the one CD. Ever wondered how or why Microsoft let such an apparent gaping hole in its copy protection? Former engineer Dave Plummer explained in an X post.

First off, there were actually two versions of the original Windows XP media: Retail and Volume. The former was for anyone who just bought the OS off the shelf, while the latter was reserved for Microsoft partners and OEMs that needed to easily install it on thousands of machines without needing to individually activate every single one at install time.

Retail and Volume media had different keys, too, and the installer would validate the key you input against specific data on the disc, "encrypted so hard that even today it hasn't been decrypted [...]" (Someone will take those words as a challenge). The magical piece of cryptic data was nothing other than the whole 10 MB of... Microsoft Bob. The short-lived assistant was technically the antecessor of the much-maligned and memed-upon Clippy, and did its best in 1995 to introduce newbies to basic computing tasks.

Regular Joes and Janes weren't supposed to be anywhere within a stone's throw of a Volume disc, though, as those were strictly enterprise-only. The final version of the CD, called Release to Manufacturing, or RTM, was complete in August 24, 2001 β€” two months before the official launch on October 25. The discs were available to OEMs and partners before the release date so those companies could have their wares ready with Windows XP on them.

Plummer notes that "very few" organizations had access to the Volume image and the corresponding Volume License Key (VLK) and believes that someone at a major OEM, potentially Dell or Intel, leaked the Volume media and the key together before the official release. The pirate group Devils0wn then quickly spread it online for everyone to enjoy

Later on, when Service Pack 1 arrived, the FCKGW key was among the 640 blacklisted from the operating system due to leakage. Service Pack 2 and its Windows Genuine Advantage checks went a couple steps further and blocked updates entirely on machines with a blacklisted VLK. Plummer states that Microsoft didn't want to cause unnecessary trouble for customers, hence its laissez-faire attitude and choice to stick to just blacklisting affected keys.

Many theories over the years proposed that the FCKGW key worked because Microsoft's key generation algorithm was very basic, a notion outright dismissed by Plummer. He plainly states that algorithm was written by "ACTUALLY smart guys with heads so big that they bumped the doorjamb on the way into your office."

The truth of the situation was far simpler: as is usual with computing, ultimately the problem was between the keyboard and the chair. It's a good a time as any to reminisce about that compact disc you totally don't have on a bookshelf somewhere with the FCKGW key written on it with a Sharpie.

Poland lost $230 million in cryptocurrency trying to buy Venezuelan oil in 2023 β€” USB drives with crypto handed directly to scammers

The country of Venezuela has had a few embattled decades, but it has massive oil reserves continually attracting buyers, despite the U.S.-led sanctions that effectively block dealings with the nation. A few years back, in 2023, Poland's state-backed Orlen energy group had $600m in hand and was looking to buy 6 million barrels during a sanction reprieve. Like many before him, one executive thought it expedient to use the USDT stablecoin cryptocurrency (1 USD = 1 USDT). It didn't end well, with $230 million worth of crypto unaccounted for at multiple stages in an adventure chronicled by the Financial Times.

The twisted web of transactions

Orleen enlisted an external company, Hannon, to take care of the purchase, which it did by enlisting the services of UK firm Lexcor Energy, which supposedly had a Venezuelan office. Hannon first needed to convert a large sum into USDT, and did so by exchanging $245m at multiple Dubai companies, adding $15m of its own to the deal. Only one of multiple transfers of $80m into 80m USDT was fully successful.

As for the other two, $135m exchange only produced 85m USDT out the other end, with $50m still unaccounted for. A third exchange of $30m also vanished (partially returning much later). The proverbial PNL is currently -$80m, and Hannon has 165m USDT in hand. All this while, three Polish oil tankers headed to Venezuela anchored there, continually racking up millions in demurrage and port fees, as they were being chartered for far longer than initially agreed.

Weeks of delays followed, which Hannon pinned on Venezuelan energy company PDVSA. One of Hannon's reps, Kam Tse, headed to Venezuela himself with a colleague, loaded with the USDT, stored in multiple cold wallets on USB sticks. They stayed in high-end hotels, drove around in armored cars, and employed bodyguards out of concern for the money and themselves. Tse found many brokers claiming to be from PDVSA, a cadre later revealed to contain a substantial number of con-men, many of whom fled as a local investigation came cracking down.

The buyers were nevertheless undeterred, and they handed 60m USDT in a USB wallet to a purported representative of local energy corp Synergy. After a few weeks of waiting, a Venezuelan office sent him a picture of a purported PDVSA export schedule displaying all three Polish tankers set to be loaded with 1.9m barrels of oil each, but with no predicted date. Ever-trusting, Tse's team then handed Synergy's representative another 50m USDT on another USB wallet. Said representative vanished in a cloud of smoke. PNL currently sits at -$190m.

Seemingly desperate, Tse ordered a buy of 1 million barrels of a lighter blend of oil, eventually finding it contaminated, then switched tactics to acquiring fuel oil instead, signing a contract. At last, a break: some of the money spent in the Dubai exchanges came back; only 21m USDT out of a $30m input, but still better than zero. Tse pays Consulting Services, another Venezuelan firm, 11m USDT for the fuel.

Finally, some good news: 500,000 barrels confirmed loaded onto the one ship, half of the contracted amount. Tse provides Consulting Services with another 11m USDT for the rest of the fuel, but that was never delivered, and there was no further contact. Cumulative PNL = -$186m total. With $72m in shipping costs in total (far outweighing the expected profit), plus additional expenses, the Polish government's investigation pins the total lost and spent at $424m.

The aftermath

Many folks' gut reaction may be that the use of cryptocurrency made the cash untraceable, but the problem isn't with the blockchain. In fact, for the vast majority of currencies, the on-chain ledger offers more visibility into transactions, not less. What failed here was the lack of official records linking wallets to persons or entities.

Reputable exchanges all have a form of identity verification, known as KYC, mandated by law. The problem is that apparently almost no entities Hannon traded with had any recognizable proof their crypto wallets belonged to them. The Venezuelan crude oil salesmen vanished, effectively cutting off nearly every avenue for investigation. Before their exchanges, they had even advised Tse to not keep records of their transactions due to the government's investigation into their collective's dealings.

Even in Dubai, pending court cases regarding the dollar-to-USDT exchanges hinge on the same problem, despite the presence of verifiable bank transactions. Broadly speaking, the country's legal system places the burden of proof fully on the accuser, making them prove wallet ownership before discussing the meat of the dispute. That's quite the high bar to clear for Hannon in order to prove that it wasn't handed the funds from the exchanges.

That task may well prove impossible, since one can't prove a negative when there's nothing linking the exchange to their wallet. Adding insult to injury, the two exchanges in the court were both recently created, and probably weren't a part of Dubai's VARA program for legal crypto operations. Caveat emptor.

ChatGPT transcripts are reportedly read by humans to improve responses, including those with personal information β€” 'Project Lilly' has seen OpenAI hire hundreds of contractors to manually review logs

AI companies don't have a great track record in areas like copyright or user privacy β€” unless they're the ones on the short end of the stick, that is β€” but it's generally known that the chat logs from platforms like ChatGPT are used for improving models. The mechanism as to how this happens was still a mystery until today. 404 Media just published a report about OpenAI's process of human review for chat transcripts, explaining how the review process works, and how it involves other humans sometimes reading private information.

The rating project's name at OpenAI is Project Lily. The publication got information on the project's instruction guides, Slack channels, real ChatGPT conversations, and, of course, the rating system to classify conversations. The operators are called "prompt reviewers," and their job is fairly simple: look at anonymized real-world chats, and judge the quality of ChatGPT's responses to assess whether they actually answer the question, and that the text doesn't overuse "AI-speak," patronizing tones, emojis, or sycophancy, among other parameters. Anthropomorphizing and stating "personal" experiences are both off the table, meaning that while it's OK for ChatGPT to say "I found some information," it's not OK for it to say "as a chef, I like to..." or "I know what that's like."

The work is "very rote," according to a reviewer, but at reportedly over $50 an hour, it's a high rate for what looks like reasonably simple work. The reviewer also said that their guidelines keep changing and are often self-contradictory, a feeling most software developers should easily identify with.

The person doesn't think that most users are aware their chats are being read by others, though, something that's particularly troubling when many use ChatGPT as an impromptu friend or therapist and put deep secrets in words for the bot to read.

While the chats allegedly go through an anonymization pass and reviewers don't see usernames, OpenAI admitted to 404 Media that the filtering may let some personal data through, especially in shorter chats. The site notes that in many conversations, the user asks ChatGPT to keep the contents secret, as well. The version of the chat handed to reviewers also reportedly includes a "user memories summary," containing a summary of the users' questions and interests, context, and potentially even location.

Crucially, Project Lily does not grade the chats' actual factual accuracy other than flagging obvious mistakes, implying that there's likely at least one more team (or several) doing separate evaluations. Likewise, this reviewing is separate from manual safety checks that ascertain if someone might be looking to hurt someone else (or, presumably, themselves).

The existence of the project also indicates that contrary to these image AI companies try to cultivate, the models don't improve just with technological advancement and better training sets β€” it appears you still need more than a few competent humans in the mix.

By now you may be wondering about the "allow us to use your chats to improve our product" (paraphrased) setting present in most consumer-facing chat bots. That setting is turned on by default in every bot we can think of, even with many paid plans. In ChatGPT's case, it does default to off in Enterprise, Business, and Educational customers.

That toggle switch does not work retroactively, though, so any chats already in ChatGPT's database will remain there unless the user requests deletion. Also, said deletion is also not retroactive, meaning that deleted chats may have already been hoovered and anonymized, and possibly reside in a dataset somewhere.

Although OpenAI initially had no answer to 404 Media's inquiry on whether users were explicitly informed that their chats could be read by humans, the company eventually offered a link to one of its FAQ pages that discusses human review for the purpose of model improvement. We verified ourselves that said notice is at least two years old, and likely older. After the publication of the exposΓ©, the firm changed its help page explaining how people can opt out of data collection, but there's no mention of human operators in that text.

This type of data collection and review is a running theme across most providers. Google Gemini clearly states that "humans may review some saved chats" in its Privacy Hub. Anthropic's stance is similar, with a page dedicated to this topic. Perplexity's stance, meanwhile, is unclear, as its Privacy Notice doesn't confirm or deny human access to chat logs.

Microsoft rolls out emergency update for Windows 11's latest patch β€” recent update causes crashes on AMD graphics, Explorer hang-ups, and broken third-party integrations

Microsoft has issued an out-of-band update for its recent Windows 11 patch, which has caused a number of bugs and issues. The September 2026 update was just released last Tuesday, and although it packs a number of new features and fixes nearly 1000 security flaws (commonplace in this day and age), there are also a few unfortunate regressions.

The 25H2 update finally reintroduces a movable taskbar, just like we've had since Windows 95, with an option to make the height smaller for compact displays. Likewise, the Start menu now has multiple configurable layouts, and you can toggle each main section on or off. Microsoft also revamped Windows Search β€” perhaps to finally be useful β€” and users can now choose to only have it display local results. Explorer got a handy tweak in the form of using KB, MB, GB size indicators, as well.

The update has also surfaced some serious bugs. First off, PCs with AMD Radeon GPUs are crashing, apparently due to the update provoking driver instability. Reinstalling the driver doesn't appear to help, and the reports unfortunately cover most contemporary AMD graphics cards. Microsoft did not mention AMD GPUs specifically in its latest update.

Microsoft noted that it has fixed an issue with Remote Desktop Services where RDS might become unstable, causing connection and sign-in failures.

Microsoft is also aware of an issue with audio output and microphone input going dead. Additionally, there are seemingly reports of audio devices starting up with a botched configuration, like tweaked 3D audio settings or speaker setups. The apparent workaround seems to be putting audio in a standard 2.0 configuration, but Microsoft has now addressed this issue in the emergency patch.

Explorer may display a black screen after logging in, leaving you with a perfectly functioning operating system but no visible UI. The File History backup feature is reportedly not detecting external drives, effectively making it useless. Of particular concern to enterprises, systems administrators, and homelabs, the Remote Desktop Service is also experiencing issues. Last but not least, Microsoft says it has addressed an issue where Claude Cowork is nonfunctional due to the update breaking HC-managed Linux VMs with Plan9 shared folders

Owners of HP and Lenovo systems are also advised to consider holding off on this update. Ever since the August 2026 patch (and now, cumulatively, with the September update), there are reportedly serious issues on both camps. On the HP side, there are instances of the update triggering BIOS corruption, leading to a failed install with no ability to recover the OS β€” though seemingly the OEM has published a new BIOS revision, so it's hard to say which side is to blame. Meanwhile, Lenovo users might have their machines black-screen or shut down out of the blue, seemingly due to power mismanagement.

While it's heartening to see that Microsoft has significantly increased its Windows development speed and is seemingly listening to customer feedback, a string of bugs after a major feature update are still common.

Developer builds viral 3D source code visualizer that consumes 21GB of RAM β€” flies around 2.5 million lines of code at over 120 frames per second

The immortal line "it's a Unix system, I know this" is forever entrenched in many a techie's brain. In the Jurassic Park movie, the visualization software in question was Silicon Graphics' File System Navigator for IRIX, an actual piece of software running on a real SG workstation. The concept of viewing files in 3D space never truly caught on, but the horsepower available in contemporary machines may change that. Makepad creator Rik Arends created his own 3D flyable source code visualizer that he claims handles 2.5 million lines with ease, at 120+ FPS, no less.

Ironed out the last performance issues with my full 2.5m line codebase explorer. 120hz awesomeness. Can only upload 60fps video tho. Much nicer uncompressed pic.twitter.com/LUsrmVaI6LSeptember 12, 2026

Although the published video is only at 60 FPS due to X's limitation, the navigation looks smooth indeed, and it's impressive to see all the actual source code in a reasonably readable manner. Arends says the visualization initially took 21 GB of RAM (in this economy?!), but that after judicious application of indexes and streaming compression, he got memory usage down to a much more palatable 3.5 GB. Although he remarked that he's yet to fully optimize the visualizer, he did try to load Chromium's entire source tree (51 million lines) in only 60 seconds at one point.

While one can argue that the 3D visualization of the code itself is probably really fun to look at, its practical use is also questionable, at least as-is. A commenter remarked that adding a time element would help immensely, by displaying changes to the source files. 3D tracking of dependencies would probably be handy, too. There's already an actual full-fledged commercial tool called CodeCharta that visualizes changes and hotspots in 3D, though the flybys aren't quite as impressive.

Arends says that he intends to turn this visualization tool into a product and charge a small fee for it, though he admits that the usefulness of the visualization may be limited. When asked why he created this, he simply said, "because I could." The jury is still out on whether he should.

Anthropic says AI can boost U.S. GDP by 32%, up to $44.4 trillion in four years β€” economics model predicts that displaced employees 'may have to switch to jobs like electrician and nurse'

Last week, Anthropic published its prediction of what the economic impact of AI on the U.S. economy is going to be for the next few years. The company thinks the U.S. can reach a $44.4 trillion GDP or higher by 2030, provided, of course, it conveniently adopts AI at a rapid pace. Having said that, Anthropic admits "the challenge is making sure that the gains are broadly shared."

The interactive post has a simulator where readers can plug in their estimates on key factors and get their own future predictions, within the firm's analysis and perspective. That's definitely interesting to play around with, but perhaps the most relevant piece of information is the lens through which Anthropic views the world.

Anthropic establishes its reasoning by first placing tasks in broad categories and using a nurse's workday as an example. They removed tasks, including those that will disappear naturally as technology progresses, like collecting data on paper or physically visiting the patient to collect basic vitals β€” neither happens anymore as remote monitoring becomes commonplace. However, some new tasks are added, like keeping an eye on dashboards for the aforementioned AI-powered monitoring.

Then, there are naturally the tasks that a bot can't perform, like bathing a patient. Augmented tasks include those that require a human, but can be made more efficient with AI: helping with triage, planning schedules, and assisting with dashboard data. Some tasks may be fully automated, like keeping supply closets full or scheduling follow-up patient visits. Finally, AI usage can introduce some tasks of its own, like reviewing automated triaging or double-checking dashboard alerts β€” perhaps even impromptu data recovery.

The company's predictions broadly hinge on how ubiquitous AI usage becomes, and therefore, the number of tasks transitioning into fully or partially automated. Unsurprisingly, Anthropic believes that the more entrenched AI gets, the more value the country creates, though at greater risk β€” and on an exponential scale, no less

Three models are presented, from "modest" economical impact to "extreme." The modest model establishes a 1.6% GDP rise to $34.1 trillion, an impact Anthropic says is in line with that of new technologies like the internet, and crucially, doesn't imply tectonic shifts to unemployment rates or wages.

For the "substantial impact" scenario, although AI is predicted to be able to do half of "knowledge work," mostly without intervention, adoption remains limited. This scenario foresees twice the normal economic growth, this time +8.3% to $36.3 trillion.

This future marks the inflection point at which Anthropic believes knowledge workers see their wages remain steady instead of growing, though it's not clear if the firm accounts for inflation. Additionally, the firm states that "knowledge workers may see a lot of automation and displacement [...] coders and call service center agents may have to switch to jobs like electrician and nurse", a statement some might argue is already true. In that sense, Anthropic expects other workers to start seeing more cash.

The eyebrow-raising prediction for both the above scenarios, though, is that Anthropic expects unemployment to "stay within ranges history has seen before," an odd statement given modern U.S. history contains events like the Great Depression. The company does note that it expects job churn to increase, but also that while "this process can be painful, [it] works relatively well from a macroeconomic perspective." Average wages are expected to rise across all three scenarios, though the increase is expected to go towards workers outside of knowledge areas.

In the "extreme" scenario, Anthropic expects significant changes. Should AI be super-widely adopted, the GDP can increase by 32.4%, corresponding to a cool $44.4 trillion, a "profound economic transformation." This is the point at which the firm expects that AI becomes more productive than humans for most knowledge work, and does so with near-autonomy. Equally worryingly, it's expected that there will be "essentially no" new knowledge tasks created.

Anthropic notes that to reach this kind of stage, the country would "likely require" recursively self-improving AI (using the AI to make better AI). There's a significant catch, however, as though the U.S. would be "far richer than [it's] ever been," knowledge workers would be the hardest hit with a 10% wage drop, plus overall unemployment would climb "beyond typical recessionary levels." Manual labor would be prized, though, given that "as AI increases productivity within knowledge work, the demand for manual work that benefits from that productivity will increase."

Scenarios aside, the one big question is: How would all that GDP money land in people's pockets? Anthropic admits this problem is a "challenge" and offers little solution for it. Such a high amount of future AI penetration might prove a hard sell, considering wealth inequality in the U.S. already sits at its highest level for the last few decades and is trending in that direction in most developed nations. Others might argue with Anthropic's assessment that unemployment levels would remain somewhat in the less extreme scenarios, seeing as job cuts are rampant across many sectors and have hit technology-related fields the hardest.

To its credit, Anthropic clearly highlights part of the wealth-inequality issue. The company admits that more AI automation might skew the current 60/40% balance between labor and capital, respectively, strongly tilting the scale in favor of capital ownership and increasing inequality. Many argue that's already happening today. There's also the matter that the prediction appears to assume little competition from other countries, nor does it offer insight as to what would happen to "AI-less" nations.

The interactive blog post and its simulator are worth a good read and fiddling with, regardless. Anthropic published the technical details on the mathematical model used in a separate article and published its Economic Policy Framework last June.

Transparent wall-mounted CD player raises over $540,000 on Kickstarter β€” $109 Syitren RM1's visible disc and mechanisms channel 90s B&O nostalgia with Bluetooth and battery power

With subscription services on the rise, it's probably not surprising that many people are seeking reassurance in the physicality and immutability of tangible media such as game cartridges, vinyl records, and CD players. So the Syitren RM1 CD player frame should fit right in. A lot of people seem to agree, as the $109 player has already collected over $540,000 on its Kickstarter β€” well beyond the initial goal of $3,000.

The RM1 is a compact disc reader fully encased in a transparent "borderless" acrylic frame, ready for hanging on a wall or sitting on a shelf. The components and mechanical parts are all fully visible, and the transparency extends to the read head assembly, battery compartment, and onboard buttons. There even appears to be a backlight LED under the moving harness for added visual appeal.

To fully avoid pesky cables, the unit is capable of Bluetooth audio output and uses a rechargeable 2000 mAh battery in an 18650 size that should be good for six to eight hours of playback and charges in one to two hours via a USB-C port. The unit is capable of reading standard CDs as well as data discs with MP3 files, just like in the good old days before subscriptions. There's also a 3.5-mm output jack if you want to wire the audio out to a separate unit.

Syitren RM1 CD player

(Image credit: Syitren)

Those who lived through the 90s and 2000s will notice design cues taken from the iconic Bang & Olufsen Beosound 9000 tower CD player/changer, which was always visible in movies and shows where the set director said: "We need a futuristic-looking piece of audio gear."

Syitren's offering isn't the only one of its type, with its main competitors being the Coolgeek M1, the Clearframe CD Player, and the Moondrop Discream 2. All share the same root concept of making the CD and mechanical parts visible, though in my personal opinion the RM1 has the best execution. It does seem to be aimed at nostalgia and industrial design lovers rather than audiophiles, and for its affordable price, that's a perfectly fine bar to clear β€” especially considering the convenient, cable-free nature.

B&O Beosound 9000c

The Bang & Olufsen 9000c, an annoyingly ubiquitous presence in every futuristic living room across movies and shows. (Image credit: Bang & Olufsen)

The claims of "hi-fi" audio output merit some inspection, though, as digital mediums live and die by how they're turned into physical signals. Over Bluetooth, the unit only supports SBC (baseline) and AAC codecs, with modern protocols or lossless transport notably absent. The wired output specs say "over 70 dB" of dynamic range, THD (distortion) "under" 0.1%; these figures are lower than even early desktop CD players.

These days, even an affordable audio interface such as my Audient Evo 4 is orders of magnitude better, with a dynamic range of 113 dB (remember, decibels are logarithmic) and THD under 0.0015%. That said, the RM1 should be fine for use with compact Bluetooth speakers β€” just don't expect a grandiose experience when hooked up to bigger amplification.

You can preorder a Syitren RM1 at Kickstarter for $109 just for the main unit, or $139 with the firm's N200 Bluetooth speaker that's dressed in Braun-inspired design cues. $169 gets you two RM1s ($84.5 a piece), and you can get a four-pack for $319 ($79.75 each). If you just want the N200 retro speaker, you can purchase those separately for $59, in beige or black colorways.

Engineer turns simulated fly brain into a crypto day trader, posts downloadable sim to GitHub β€” 166,700 virtual neurons read candlestick charts for dopamine hits

Simulating animal brains seems to be the latest buzz. Hot on the heels of teaching a fly to play Doom, an engineer from the Coinbase cryptocurrency service has elected to turn one into a day trader with Stonkfly. If you want to see Stonk trade live, you can watch here.

The open-source project has a simulation of a male fruit fly brain and eyes, and shows it a standard-issue candlestick graph with historical pricing. The fly can choose to buy, sell, or hold any given currency β€” although they get shown to the fly in round-robin fashion β€” and gets rewarded for profitable trading.

A rising portfolio value triggers a dopamine rush as a positive reinforcement signal to 15 cells, while a loss lights up two aversive cells. Trading fees count as losses. The author notes there are no pain or emotional mechanisms at play. Displaying far better judgement than most human traders, the fly cannot use leveraged positions (trading multipliers) or shorts (betting on drops).

The brain has 166,700 neurons and 25.6 million connections. The virtual fly sees the graph as a 320x180 display across its left and right eyes, with an intersecting center portion. The simulated photoreceptor cells get fed the RGB pixel values rather than pricing information. By default, the fly "thinks" and acts every 500 ms, and the market data gets refreshed every 60 seconds, and it can bet up to $10 on any one order, up to 24 times a day.

The author notes that this small project doesn't prove anything other than the connection between the input mechanisms, visual signals, and synapse changes. Naturally, he warns users against assuming that said changes are any indication of actual trading ability, especially in the face of a general rise in crypto prices that "can make any buyer look skilled." You can bet that some fly-brained investor will still infer meaning from the experiment, though.

If you're interested in getting your own Stonkfly, you need only download the repository on macOS (it's definitely a fruit fly) or Linux, have 16 GB of RAM available, and Python 3.11 and a C++ 17 compiler. The simulation defaults to using paper trades and $100 in virtual balance, but it uses real BTC-to-USDC data. There are instructions on how to set up a live account to see if your trading skills are a match for an insect.

Hardware-accurate NeoGeo AES+ delayed to late 2027 due to memory shortage β€” decision driven by surging demand and AI-driven RAM crunch

Plaion's release of the NeoGeo AES+, a contemporary, hardware-level 1:1 replica of SNK's evergreen NeoGeo console, is being delayed by 10 months, with a new September 16, 2027 release date. Predictably, Plaion says the main reason is the AI-driven RAM shortage, though it remarks that demand is higher than expected.

Unlike nearly every other modern console re-release, the AES+ is intended to be an exact, 100% compatible replica of the original, by way of physical hardware rather than emulation software. Plaion says it's using dedicated ASIC chips and presumably contemporary clones of processors like the Motorola 68000 and Zilog Z80A.

The team counts long-time MiSTER core developer Jotego among its staff, lending serious pedigree to the project and assuaging concerns about whether the AES+ will perform just like the original. They're even going as far as using 5 V power delivery to be directly compatible with the original cartridges.

NeoGeo AES

(Image credit: Plaion / SNK)

It's expected that every game cartridge from the original NeoGeo AES (Advanced Entertainment System) home console will work on the AES+, and there are modern third-party adapters for using original arcade cartridges. Plaion is re-releasing ten iconic games in cartridge form, including Metal Slug, Garou: Mark of the Wolves, Pulstar, and King of Fighters 2002.

The NeoGeo was the greatest 2D arcade/home system that ever existed (according to me), with production lasting for 14 years from 1990 to 2004. It had a number of "firsts," being the first system that used the same exact hardware for the home version as it did inside an arcade cabinet, with nothing but the form factor, the name (AES vs. MVS), and a defeatable lockout mechanism as a distinction. Arcade operators loved the then-new swappable cartridge system, and there were variants that could hold four games that were switchable on the fly.

The AES also marked the appearance of memory cards for save games, and that came with a serious arcade joystick, unlike its competitors' gamepads. Every home console release at the time promised "arcade-quality games in your home," but only the Neo Geo actually delivered.

NeoGeo joystick

(Image credit: Plaion / SNK)

Of course, all this goodness had a small problem: the AES cost $399.99, or $1,028 in today's dollars β€” for just the base system with the one joystick and no games. The Gold package with two sticks, one game, and a memory card would set buyers back a cool $649.99, or $1,671 today.

The technical reasons for the NeoGeo's longevity are quite straightforward: it was ridiculously overpowered from the start. Its architecture covered almost every possible use case and lent itself well to most every type of 2D game. The NeoGeo packed a total of seven processors and co-processors, and a GPU with a 24-bit bus, capable of 3840 simultaneous colors across 380 sprites. The graphics chip also had hardware scaling and used an unconventional but effective vertical-strip sprite mechanism, unlike tile maps of the era.

The expandable storage also played a big part in longevity, with late-day cartridges storing as much as 716 Mb, or 89.5 MB. The only notable omission is the lack of a direct-to-screen drawing mechanism (aka framebuffer), precluding Doom ports β€” but as always, people are finding a way regardless.

If you're looking to order a NeoGeo AES+, the base model with the console and one stick will set you back $249.99 (or 199.99€), an affordable amount considering a decent joystick can cost $75-100 on its own. The Anniversary Edition comes in a white finish, with Metal Slug, a wireless joystick, and a memory card, for $349.99 (or 299.99€). Finally, the Ultimate Edition comes with all ten re-released games, two joysticks (one wired, one wireless), and a gamepad, for $999.99 (or 899.99€).

Anthropic says Claude thwarted bioweapon research from state-sponsored actors β€” covert accounts used U.S. proxies to attempt to engineer deadlier viruses, tried to evade identification and regional blocks

These days, AI companies directly or indirectly announcing how their respective wares are smarter than their competitors has become a genre of elevator music. Even so, some in-depth articles can be quite insightful, like Anthropic's occasional reports on attempted misuse of its wares. The latest one covers activity between November 2025 and September 2026, with an important reveal: five situations where Claude was asked to perform work determined to potentially be used in biological weapons.

Right out of the gate, Anthropic remarks on the difficulty of understanding if a particular line of inquiry pertaining to biology is meant for nefarious purposes, to create defense mechanisms like vaccines, or simply to establish predictions of how a virus spreads. The company says that "out of an abundance of caution [....] launched recent models with stronger safeguards."

Among the tens of case studies presented in the lengthy report, Anthropic discusses five cases that it deemed particularly concerning, three regarding viruses, and two more discussing toxins. The common theme across all of them is that all threat actors used varying degrees of anonymization techniques and did their best to evade Anthropic's own regional blocking. The report doesn't mention specific states, but the firm is known to block access to Claude for China, Russia, Iran, North Korea, among others.

In the first case, a request for assistance in developing a grant application involved finding ways to improve the chikungunya virus. The purported researchers were trying to come up with ways to both add extra abilities to chikungunya (increased mutation) and increase its virulence. The topic itself already raised some concern, but Anthropic's hand was forced after finding that although the grant application seemed to be for civilian researchers, the actual investigation was meant to proceed at a military facility.

The firm also found that the request would have gone through a third-party LLM platform associated with military as well as civilian institutions. The countries involved are geo-blocked by Anthropic, and that platform routed comms traffic through the U.S. to try to evade detection, used gray-market resellers, and specifically catered to customers looking to skirt content restrictions. Anthropic banned the accounts in question and shared the information with government authorities, though the same people repeatedly tried reaching Claude again via zero-data-retention services.

Case #2 pertained to a non-US researched who was looking to dig into how avian flu adapts to mammals, and how it can cause diseases other than in the respiratory tract. The problem is that avian flu has a high fatality rate, and there's little population immunity.

While the virus doesn't easily spread from person to person, therein lies the rub β€” the research could end up discovering mechanisms to increase transmissibility. The researchers used a random username, a private email service, and accessed Claude through a VPS, leading Anthropic to investigate and ultimately turn its nose up at this strain of thought.

The story with the third case bears a resemblance to the previous two. Once again, an account was trying to prepare a supposed grant application, this time around about orthopoxviruses, the family that houses smallpox and Mpox, among others.

The application discussed containment facilities and live experimentation with the viruses, and focused on understanding their genetics for the purpose of evading immunity. The research didn't initially trigger alarms, but Anthropic came to notice it was created via a reselling service, with a randomly-generated email, tunneled through U.S. infrastructure to reach Claude, and traced back to a banned account farm.

In the last two cases, instead of viruses, the purported researchers were focusing on toxins. In case #4, a person mapped out venom toxin peptides from multiple families of animals and created a program to optimize their toxic characteristics.

Although the stated goal was to create painkillers, antidepressants, and other therapeutic molecules, the data would equally allow the creation of potent harmful compounds. Anthropic also came to learn the content Claude was generating was part of a state-sponsored program in an "unsupported region."

In the fifth and final case, a theoretical scientist was also using Claude to try and redesign a set of toxins, also supposedly for therapeutic purposes, under a national public search program. However, the work touched upon "a bacterial toxin subunit and a protein of the hemorrhagic-fever virus" that happens to be on the World Health Organization's list for particularly nasty, pandemic-inducing diseases.

The scientist tried to obscure the subject of the research, directing Claude to be vague about descriptions. Once again, the story ended with Anthropic cutting off access to Claude from a location that broke its terms of service.

Steam enforces Australian age verification via credit cards β€” debit card glitches and low credit adoption alienate core gamers, privacy-first mindset leads to dearth of options that may hinder consumers

Today is September 9, and the significance of the date for Australian consumers is that, by law, buying online apps and games now requires an over-18 age verification step. The local law isn't specific about the exact type of verification, only that it offers "appropriate age assurance measures." Valve is complying by asking for a bank card rather than government ID or a biometric check. The problem in the land down under is that while credit cards seemingly all work, debit card support is spotty and conditional.

This situation isn't unique, as it's basically a repeat of the same existing scenario in the United Kingdom. Valve's privacy-minded approach is laudable, as a bank card only links a payment method to a name and address. Meanwhile, a government ID is a more dangerous document if it gets leaked; face scans are quite fallible and revealing, and biometrics are intrinsic to the person and not replaceable if exposed β€” unlike bank cards, which can be canceled and swapped in minutes.

However, having a card check as the only verification option is causing problems, and many users are already asking for other means of verification, even if they're more invasive, citing Xbox and Sony's services as more accommodating.

Since credit cards in Australia (and the UK) can only be issued to adults, they work fine for Steam verification. Debit cards, on the other hand, can be carried by minors, and they're only valid for age checks under specific conditions. For now, that seems to be those (a) belonging to the Mastercard network, which introduced its own global automatic age verification check on June 2, 2026, and (b) for which the issuing bank flagged the card product as adults-only. The transaction firm only passes the answer to "is the buyer an adult?" back to the merchant (in this case, Steam), without exposing an actual date of birth.

A quick harnessing of user reports, mainly from Reddit posts, seems to indicate that debit Mastercards from Commonwealth, Westpac, and Macquarie appear to work, while those from Bendigo, St. George, Revolut, ANZ, and most Visa cards seem to fail the check. Note that this is an evolving situation, so the situation may have changed by the time you're reading this.

The demographics of credit card ownership definitely don't help matters. Unlike the U.S., where credit cards are the default method of purchase, only about 45% of Australian buyers and 65% of UK punters own one. Perhaps most importantly, within the 18-24 age demographic, only 25% to 30% own a credit card β€” precisely the people who buy the most games and are the most affected. For both user satisfaction and business reasons, it's seemingly desirable that Steam add verification alternatives.

OpenAI's breakthrough solution for the elusive Navier-Stokes problem overshadowed by plagiarism controversy β€” researcher says OpenAI scraped Codex session and issued career threats

Most anyone involved in computing has heard about the P-NP problem, but fluid engineers and mathematicians would love to know if the Navier-Stokes equations have smooth, globally defined solutions. Both questions are part of the Millennium Prize Problems, solutions to which are worth a cool $1 million and eternal renown. OpenAI is claiming that its staff and internal models have solved the conditions of Navier-Stokes solutions set forth in the Millennium Prize. But the company's shouting from the rooftops is being met with a chorus of boos over claims it might have plagiarized the work of a research team that had been toiling on a related, stepping-stone problem for a year.

Tristan Buckmaster (a scientist at NYU) and Levent AlpΓΆge (a member of Anthropic's staff) had been quietly working on proving Euler's equations β€” another long-standing mathematical problem, and one that is generally acknowledged to be a stepping stone to solving Navier-Stokes.

According to Buckmaster, his work with AlpΓΆge was "a purely personal collaboration, free of any institutional agreements or official involvement by either of our employers." The researchers used Anthropic Claude and OpenAI Codex as assistants, as is apparently now common in the field, to perform busywork (documentation, searching, etc.) as well as running through logic steps. The substantial amount of compute time the project required was paid from Buckmaster's own pockets, too.

The pair worked for roughly a year until August 15, 2026, when it obtained "the blowup results, with smooth forcing, for both Boussinesq and Euler." Buckmaster says the novel approach was based on previous work by Diego CΓ³rdoba and Luis MartΓ­nez-Zoroa, and he believes Zoroa should be eligible for a Fields Medal.

Although the team was presumably happy with these achievements, Buckmaster said that the LLM-generated proof was "the most horrendous" he'd seen, calling it "AI slop," and meaning to rewrite it for clarity. Nevertheless, they verified it on August 22 using Lean, a standardized programming language designed specifically to verify mathematical proofs.

Come September 3, AlpΓΆge told Buckmaster of rumors going around that Anthropic had solved an important mathematical problem. This almost certainly alluded to the team's work, and some apparently took it to mean the company itself was working on the problem. The rumor-mongers even theorized that the problem that Anthropic had solved was Navier-Stokes. AlpΓΆge further believed that OpenAI had gotten wind of the news.

This prompted Buckmaster to email an unnamed "prominent mathematician" at OpenAI, clarifying that the effort was a personal collaboration between him and AlpΓΆge and was unrelated to Anthropic. The mathematician replied asking for details, saying "it would be useful to avoid competing," and offering OpenAI compute time. After a few days, on September 6, Buckmaster, the unnamed person, and OpenAI's SΓ©bastien Bubeck talked twice, without AlpΓΆge. He was told that OpenAI had proven a finite-time blowup for the forced Navier-Stokes equations, a subset of the problem.

AlpΓΆge asked by text for the precise statement and was told "existence of forced blowup in RΒ³ and TΒ³", and that "the forcing function is smooth option [C] and [D] in Fefferman," referring to one of the four possible categories established by the Millennium Prize, with any one of them being valid as eligible for the prize, but not constituting a full solution for all scenarios, a distinction remarked on by other scientists.

This is where the story becomes interesting. Buckmaster claims that that idea (forced blowup) was exactly the same one his team had "quietly" chosen, and that nobody else he knew was working on it. Perhaps most importantly, he says that that was "not the direction one arrives at in a few days by giving a model the problem statement," indicating that running the general problem through a bot wouldn't quickly reveal that potential approach.

In fact, Buckmaster claims that over the calls, Bubeck ultimately revealed that instead of just AI models and agents with a couple of handlers, there was an entire team of live humans working on Navier-Stokes. The OpenAI team first had the models try to work through easier paths, and the text prompt that generated the Navier-Stokes proof had itself been generated by prompting Codex, with an "insane" amount of computing needed.

Buckmaster then asked when the initial prompt was issued, and OpenAI's response of "in the past few days" did not arrive until "some time" passed. He proceeded to ask if the model "had been trained on, or had access to, our sessions in Codex," and was told by OpenAI that Codex does not access user data. Finally, he asked if the data was used for model training more generally and, crucially, apparently did not get an answer.

OpenAI allegedly offered Buckmaster two options: one, that Buckmaster and AlpΓΆge publish their Euler proof first. The following day, OpenAI would post its Navier-Stokes proof, giving the two priority. The second option was that Buckmaster alone, without Levant, was to write a paper with the Navier-Stokes proof, acknowledging that an internal OpenAI model resolved it. Bubeck was apparently adamant about Levant's removal from the Euler proof, as his employment at Anthropic was "annoying." Buckmaster opted for neither, and told OpenAI that if it chose the first option, he'd go public with his findings, as has since occurred.

This prompted what Buckmaster interpreted as a threat from Bubeck, who asked him "why [he] would ruin [his] career." After Buckmaster asked why that would happen, Bubeck told him, "If you don't want me to be nice, then I don't have to be nice." Bubeck then allegedly reached out to AlpΓΆge, questioning Buckmaster's sanity, to which AlpΓΆge responded with a refusal, pointing inquiries back to his colleague.

The entire story raises pointed questions about what OpenAI (and others) are actually doing with user data collected via its LLMs, despite the toggle switches that are supposed to disable it. Not only has OpenAI neglected to tell Buckmaster whether it used his team's data for training, in its PR about Navier-Stokes, the company says while it "no specific user data was accessed in order to solve this problem," it "cannot rule out that de-identified data derived from their usage of our products helped improve [its] models."

OpenAI's proof still needs to undergo a likely years-long peer review before any party can take the Millennium Prize home. The firm has stated it does not intend to claim it. As for Bubeck, he predictably paints the story in a very different light, but insists that his pushing away of AlpΓΆge is justified on the basis that "it would be inappropriate for an Anthropic employee to author OpenAI's work," a puzzling statement that some could take as meaning a double standard regarding scientific authorship, based solely on corporate rivalry.

For his part, OpenAI CEO Sam Altman claims his team was well-intentioned and cooperative, and supported Bubeck, saying "it was challenging to offer [the same publication options] to Levent." Neither person opted to discuss the matter of whether OpenAI used the research of Buckmaster and AlpΓΆge as training data, or offered any further explanation of why AlpΓΆge didn't deserve credit for his work as an equal to Buckmaster.

Given the groundbreaking nature of this apparent discovery and the ensuing fight for priority that these competing accounts have sparked, it'll likely take quite some time and review before we know whether and how OpenAI or Buckmaster and AlpΓΆge will be credited with this discovery. But given the inter-lab rancor already on display, the process will surely be ugly.

Researcher reverse-engineers infamous Stuxnet malware source code, publishes it on Github for all β€” attack targeted Iranian nuclear facilities and was the first software of its type to cause physical damage

Anyone keeping track of world news in the early 2010s, and reports on tech in particular, has probably heard about Stuxnet. That malware spawned a large number of conspiracy theories β€” with the kicker that some of them were actually true. The malware targeted Iranian nuclear facilities and is believed to be the first digital worm to cause direct physical damage in meatspace. An unknown security researcher has now published a source code reverse-engineering of Stuxnet in all its glory.

The worm's ultimate target, allegedly a successful one, were industrial controllers from Siemens that were reportedly used in Iranian's Natanz nuclear enrichment plant. Once it reached the target, Stuxnet's payload manipulated the frequency converters in industrial centrifuges, in a bid to subtly damage the rotors β€” all while keeping the plant staff in the dark by reporting normal operation.

The repository contains build instructions so interested techies can try it out for themselves and learn all about its inner workings. You'll need a Windows XP or Windows 7 virtual machine, and for obvious reasons, you shouldn't configure any network connectivity for it. To witness the full effects of the payload rather than just the spreading mechanisms, you'll need the appropriate Siemens software, and ideally hardware β€” though we figure that industrial-scale centrifuges aren't exactly common in techies' cable drawers.

In its heyday, Stuxnet spread via three mechanisms. The primary infection vector was USB sticks with Windows shortcuts and autorun.inf files. Upon plugging one of those sticks in, just viewing the drive's contents would immediately trigger infection thanks to a zero-day vulnerability.

Infected systems then autonomously tried to spread the worm further via the network using a zero-day Windows Print Spooler vulnerability that would let an attacker write system files into any machine sharing a printer. It would also copy itself into accessible network shares. To evade Windows driver signature checks, Stuxnet used two digital certificates stolen from Realtek and JMicron.

The worm also had code to inject itself into Siemens software, by way of the WinCC SQL Server database, and embedding its code in Step 7 project files that automatically ran when engineers opened them. Since those files were almost guaranteed to be shared among more than one engineer, it made for an excellent internal infection vector that didn't depend on having network share control.

The final step was taking charge of the DLL that communicated with the actual centrifuges and injecting malicious code into the PLCs (Programmable Logic Controllers) of those machines to stealthily mess with the rotors.

Stuxnet was part of Operation Olympic Games, an alleged coordinated effort between the U.S. and Israel to try and curb Iran's purported progress in creating nuclear weapons at its Natanz facility. The initiative seemingly ran under both the Bush and Obama administrations, and was supposedly a way to dissuade Israel from launching its own preemptive strike against Iran. The software was allegedly developed by both the Pentagon and Israel's Unit 8200, and was reportedly successful in bringing down about 10% of Natanz' centrifuges by ultimately seriously damaging their rotors.

However, the worm had a nasty bug: it didn't have sufficient checks about which environment it was in, and failed to notice it was no longer in a local network environment. When engineers took their laptops home, it escaped out to the internet at large, at which point security researchers worldwide let out a collective "huh, that's odd" and proceeded to investigate. Mercifully, the worm contained a hard-coded self-destruct date set for June 24, 2012.

Vintage Emulator Studio recreates 44 legendary synths down to the chip level β€” free MAME-powered component-level emulation should offer exceedingly accurate sound

Musicians and synth-heads in the audience, rejoice. A new vintage synthesizer plugin has arrived that has the potential to blow many commercial offerings out of the water β€” and it's completely free, to boot. Audio software maker Autodafe has released the Vintage Emulator Studio (VES), a fresh new plugin that integrates a fair number of the open-source MAME emulator's synthesizer cores in one neat package.

The entire list of emulated synths is below, but it includes iconic entries like the Akai MPC3000, LinnDrum, Oberheim DMX, and Roland TR-707 β€” used by names like Dr. Dre, New Order, The Police, INXS, and Prince, among many other high-level acts. There are a total of 44 machines, all with component-level emulation.

What makes VES different from most other synth plugins is that instead of presenting a facsimile of the final output or a hybrid mix of component- and output-stage emulation, it employs β€” by way of MAME β€” full component-level emulation. Each processor, tone generator, envelope generator, filter chip, and converter should be faithfully reproduced, potentially resulting in a "perfect" emulation of the gear in question, more or less depending on the status of each driver core.

Notably, on machines whose MAME emulation is farther along, analog and/or digital output stages are faithfully recreated, meaning you won't need additional low-pass filters or any other trickery to make the synth sound like the actual hardware. Additionally, the skeuomorphic, HiDPI-ready UI replicates the units' control panels, dials, buttons, and LCD displays, making them easy to interact with if you're familiar with the real hardware β€” and probably a nightmare if you're not, as "ease of use" wasn't high on the list of priorities back then. Floppy disk, CD-ROM, and peripheral emulation ought to be included too.

If by now you're thinking this is all too good to be true, there are indeed a couple or three catches. First and foremost, as with any emulator, you'll need to provide your own ROM/firmware, and depending on the synthesizer, any associated sample packs. Although obtaining those is not too difficult, having a copy of that data is a legal gray area if you don't own the original hardware. Although we haven't tested it ourselves, the CPU usage of the plug-in ought to be somewhat high, considering all the work it's doing simulating every single component.

Additionally, while MAME's emulation cores aim for full component-level emulation, not every synth driver has had the same amount of work put into it. For example, the Akai MPC-3000 driver is nearly complete, while the Prophet-5's has only been introduced to MAME fairly recently β€” so your mileage may vary. We'd expect this VST to be updated somewhat frequently as work on its MAME core moves forward.

For the sake of argument, though, if only a handful of synths are fully emulated, that's still an impressive showing out of a list of 44, given that in theory you'll get output that tracks exceedingly close to that of the original hardware, all from one plugin. You can download the Vintage Emulator Studio right here, in VST3 or AU format, for every major OS: Windows, macOS Intel/M-series, and Linux. It's also available as a handy standalone application.

Thailand asks data center operators to suspend 49 buildouts until legal framework is complete β€” new legislation is supposed to create 'airtight' requirements for large-scale data centers

Data center builds are one of the hotly contested items worldwide. Many states and cities have upheld moratoriums on new buildouts due to power usage, water consumption, and noise concerns. Thailand is the latest nation to pump the proverbial brakes, with the government requesting that existing buildouts hit the pause button while coming up with a more precise regulatory framework.

Government heads requested that agencies compile information about current and future data centers during this week, in a bid to create unified legislation. The country currently has few laws specific to data centers, leading to legal voids like zoning a data center as a "warehouse" right next to a hospital. Much like everywhere else, the country has seen growing complaints about data centers' water and power usage.

After the week is out on September 11, the government expects to take about a month to come up with a regulatory draft, making the pause technically an indeterminate timeframe β€” though further delays wouldn't benefit either party, as Thailand considers the industry critical to the country’s competitiveness. The catch is that pausing construction isn't enforceable, so companies can elect to plow ahead regardless while the legislation is discussed.

NESDC (National Economic and Social Development Council) secretary-general Danucha Pichayanan is very specific: "we don't have the power to suspend the construction of the 49 data centers" currently under construction. However, when the legislation arrives, it will apply retroactively to ongoing projects, though with an adjustment period for in-progress builds. New builds will naturally need to comply with the legislation from the get-go.

Some companies may elect to soldier on with the belief their buildouts will be in compliance with the reasonably predictable content of the new laws, or betting that they could win future legal challenges β€” a dynamic that's already in play elsewhere with Project Jupiter. The incoming legislation is expected to cover power consumption (and possibly generation), closed-loop cooling, and water-surplus guarantees, meaning builders already have a fairly good idea of what they'll need to do.

Not complying with the request for a pause might be a game of political chicken, though, as the government may retaliate with regulatory delays and additional costs to power connections. Just last Thursday, Thailand's energy ministry raised concerns over a Bangkok data center that may be planning to hold diesel stockpiles far in excess of the 200,000 liters it has permission to.

On that topic, Thailand revised laws on industrial power delivery last July, and among other requirements, demands a bank guarantee of ΰΈΏ4.5 million ($134,000) per megawatt. Half the money will be refunded when the actual usage reaches 50% of proposed utilization, and the rest when usage hits 70%. This mechanism is meant to stop preemptive allocation of power delivery capacity that might remain unused for months, years, or not at all β€” once again, mirroring datacenter playbooks elsewhere around the world.

At face value, the amount of $134k per megawatt sounds like a small price to pay for a builder to get ahead of the pack, but its per-megawatt nature means that a hyperscale facility pulling 200 MW or more needs to place around $27 million in escrow.

With the power laws recently revised, water consumption is seemingly the largest concern, as the current legal framework allows companies to make deals directly with utilities without additional safeguards. For example, in Chonburi, an operator signed a decade-long deal with Eastwater Stecon Utilities for 3.3 million cubic meters annually, or about 36,900 residents. It's expected that the new laws will add much stricter requirements to avoid localized deserts.

One-slot, low-profile Nvidia RTX 3060 12 GB with two monitor outputs breaks cover at Newegg for $496 β€” bus-powered model looking for a use case in local LLM work

Not that long ago, we reported that Nvidia was dusting off the blueprints for the RTX 3060, in its 12 GB form. At the time, we'd spotted it in stores for about $339.99, but just like with ever-climbing memory, hard drive, and SSD prices, two months passed is an eternity. The same cards are now selling for $489 new, and one particular specimen is the SRhonyra RTX 3060 12 GB Low Profile card, for $495.59.

This card and its price may raise more than a few eyebrows, but there are reasons why it exists. First off, it's a one-slot model, making it easy to put many of them to work in the same machine with relatively little concern for airflow. They have no power inputs and rely on 70 W delivered by the PCIe slot alone, eschewing the need for a high-end PSU and lots of cables. Third, the low-profile form factor makes it possible to place them in potent puny personal computers.

Attentive readers might surmise that one (or more) of these would be good candidates for an entry-level local LLM rig. That's precisely how SRhonyra is pitching the card, calling it "capable of local AI" and "running 7B [to] 13B LLMs." A standard-dimensioned, fully powered RTX 3060 is capable of drawing a maximum of 175 W, so it's fair to assume the performance of the diminutive variant will sit below that of its full-sized brethren, given it ought to only draw 70 W of juice from the PCIe slot.

Even then, it's likely that people interested in these cards are looking to use them either as secondary GPUs, or use more than one in the same box to be able to virtually pool their VRAM and use larger models than you'd otherwise be able to. The low power draw also means they're a simple, thoughtless drop-in to an existing system, whereas larger, more power-hungry cards require careful consideration with physical spacing (or lack thereof), power supply sizing, and ever-annoying cables.

❌
❌