โŒ

Reading view

There are new articles available, click to refresh the page.

'The prophecy is fulfilled': Popular 2020 XKCD comic predicted 'HEIF Heist' OpenAI hack and even mentions ImageMagick in spooky coincidence

  • Hacktron chained a libheif heap overflow, reached through ImageMagick on OpenAI's Discourse forum, leveraging an OpenAI SSO flaw to briefly take over employee ChatGPT and Codex accounts
  • The researchers themselves invoked XKCD #2347, whose 2020 alt text happens to name ImageMagick as the dependency that will one day break
  • ImageMagick served as only the pathway to the actual vulnerable component, libheif, an obscure decoder pulled in indirectly across Slack, Meta, and GitHub Enterprise amongst other mediums

When Hacktron AI recently disclosed its months-long libheif research, the researchers reached for a familiar picture that also, to some degree, hints at what let them break into OpenAI in the first place.

They pointed readers to xkcd #2347, Randall Munroe's 2020 iconic web cartoon of all modern digital infrastructure balanced on a single load-bearing block that some random person in Nebraska has been thanklessly maintaining.

The comparison is relatively easy to follow, and it has a bonus easter egg that one can take as pre-empting the hack.

An alt-text that that seems ironically prophetic in 2026

The easter egg in question is one you have to look for; if you hover over the original comic, you get the alt text "Someday ImageMagick will finally break for good, and we'll have a long period of scrambling as we try to reassemble civilization from the rubble."

The irony is that six years after the comic was originally posted, ImageMagick was sitting in the exact spot the breach ran through, making its teaser something you could call an unintended prophecy bound to fruition.

The details are unglamorous but worth considering as AI safety continues to take center stage in public discourse, including recent addresses by the CEOs of OpenAI and Anthropic at the UN.

Hacktron found that OpenAI's community forum, community.openai.com, runs on Discourse. The latter's usual image checker, FastImage, doesn't understand HEIF and quietly hands tasks to ImageMagick's magick command for conversion, which in turn calls libheif, the library that actually decodes the format.

The version shipped to the forum was deployed via Debian and had a heap buffer overflow issue that was fixed the previous year without being labeled a potential security risk, allowing it to serve as a doorway for the Hacktron team.

The team then chained multiple exploits in an elaborate hack that culminated in leveraging a secondary SSO (Single Sign-On) misconfiguration at OpenAI's end, which essentially allowed the forum to serve as a gateway to ChatGPT and Codex accounts for anyone with a community account who signed in through the forum.

This allowed them access to ChatGPT's internal GitHub, where they made what they describe as a harmless pull as a proof of concept and notified OpenAI. OpenAI patched it 14 hours later, awarded the team a $6,500 bug bounty, and Discourse patched it after rating the underlying image bug 8.8 on the CVSS scale and adding sandboxing around image processing as a defense-in-depth measure.

The exploit is not exclusive to OpenAI: the same libheif and libde265 decoders reach production through ImageMagick, libvips, Sharp, standard distribution packages, and prebuilt container images. Hacktron traced them across Slack, Meta, GitHub Enterprise, Ruby on Rails, and Node.js frameworks, including Next.js, Astro, and Gatsby, suggesting that potential fallout, if not patched, is far broader than one AI company.

Hacktron's approach involved using Anthropic's Claude Opus 4.8 before switching to Opus 5, spending under $3,000 in tokens across a three-person team, and having an exploit ready in just two months. To its credit, the team had to trick Anthropic's AI into doing the task by framing their own test forum as a capture-the-flag challenge, and it eventually acquiesced.

The exploit itself wasn't something that couldn't be done without AI, but it let a much smaller team work at a pace normally expected of a much larger one. Apparently, asking your AI chatbot nicely with a bit of trickery in tow can deliver exceptionally good results in some cases.

Alibaba wants to expand data center capacity past 20 GW by 2032, says its new V900 AI chip can scale to 500,000-card clusters, but will 'China's most powerful AI chip' be enough to displace Nvidia GPUs?

  • Alibaba's T-Head unveiled the Zhenwu V900 with 216GB of memory, 1.2TB/s links, and a claimed 3x gain over the already-shipping M890
  • Very few details associated with its raw performance: Alibaba gave no FLOPS, node, foundry, or power figures, and both specs it did share project it will trail Huawei's Ascend 960DT, which releases in the same quarter
  • CEO Eddie Wu targeted more than 20GW of Alibaba Cloud-operated capacity by 2032 while admitting supply-chain shortages are limiting growth for the company

Alibaba opened its annual Apsara Conference in Hangzhou with three big numbers: a chip that it says triples the performance of its predecessor, AI clusters that could stretch to 500,000 of those chips, and a pledge, quoted by the South China Morning Post, that the data centers Alibaba Cloud operates worldwide will pass 20 gigawatts of capacity by 2032.

CEO Eddie Wu called the new Zhenwu V900, designed by the group's T-Head chip unit, the "most powerful AI chip in China today."

This was part of an address that distinguished Alibaba's offering as a GPU rather than an ASIC, landing it squarely in Nvidia's territory even as the latter's H200 GPU is highly sought after by AI labs.

A powerful offering on paper, but one that doesn't publish actual performance

The Zhenwu V900's spec sheet might be intentionally short, even as its performance figures versus comparable current-generation Nvidia GPUs, a banned option, could limit interest ahead of launch.

Alibaba has, however, added an impressive amount of memory and interconnect, allowing it to cluster a configuration it claims can run as many as 500,000 GPUs in parallel.

The V900, as per Zhidx, reporting on the launch, lists 216GB of memory and 1,200GB/s of chip-to-chip bandwidth and was originally expected to be available to clients in Q3 2027 before the recent revision pushed it two quarters earlier.

T-Head vice president Gao Hui now says the company will, going forward, keep a one-generation-per-year cadence, with a J900 due in the third quarter of 2028.

Despite the closer timeline, it is interesting that Alibaba has published no FLOPS figure, process node, foundry, power rating, or even the V900's internal memory bandwidth, making it hard to gauge its most powerful single-chip offering in terms of raw AI and compute performance.

This is particularly ironic at a time when the competition from Huawei, the Ascend 960DT, which was launched the same quarter after being pulled earlier by three quarters, is offering far more detail.

It lists 2 petaFLOPS of FP8 compute, 288GB of memory, 9.6TB/s of memory bandwidth, and a 2.2TB/s interconnect, making it a higher-VRAM and higher-interconnect offering based on the information Alibaba has already published.

The 500,000-card figure interestingly may just be a scaling limitation, not a system anyone has built. For scale, T-Head said in May 2026 that it had shipped just over 560,000 Zhenwu chips in total. One maxed-out V900 cluster, in other words, would need nearly as many chips as the company had shipped in its entire history.

It does, however, bring a secondary calculation into the equation: if each V900 drew what Nvidia rates its H200 at, up to 700W, the accelerators alone in such a cluster would pull a significant amount of power. A newer, larger chip could run hotter and be more power-hungry than Nvidia's Hopper offerings, even as China remains limited to older process nodes because of US sanctions on chips and chipmaking equipment.

A large cluster of 500,000 or similar GPUs would undoubtedly rack up power requirements considerably fast for the regional AI juggernaut, and 20GW by 2032 is not an unforeseeable event when one considers that per-GPU power draw is only heading up for the foreseeable future as the chips get faster, denser, and more monolithic at the same time.

Wu said medium- to long-term demand far exceeds what Alibaba can supply, and that shortages across the AI data center supply chain "are currently limiting the speed at which we can scale our compute infrastructure." The target covers capacity Alibaba Cloud operates, and the company did not say whether it means IT load or total facility power.

A Nomura note relayed by Sina puts Alibaba's current footprint at roughly 4GW and expects future buildouts to blend owned, leased, and third-party-financed sites, implying about fivefold growth in six years.

Whether the upcoming V900 displaces Nvidia's global market dominance, even slightly, is unclear, with Team Green already far ahead in a market where AI customers buy GPUs years in advance. The situation, however, is vastly different in Beijing.

In China, much of the disruption has already happened, with Chinese AI labs being 'persuaded' to stay away from Nvidia solutions by the state. Nvidia's latest 10-Q says shipments of data center Hopper products to China were under 1% of its $89 billion in data center revenue for the quarter to July 26, and the company said in its earnings report that objections in Beijing kept it from selling the full volume of H200s that Washington had licensed when relations briefly thawed.

Chinese labs have turned to a mix of homegrown solutions, including specific ASICs, GPUs, and CPUs, allowing local players such as Alibaba, Huawei, and others to thrive in a market devoid of foreign competition.

With the US government restricting Nvidia's power limits and the Chinese state taking a dim view of local labs depending on foreign chips, Alibaba's V900 GPU doesn't need to beat Nvidia's Rubin GPUs or even its Blackwell offerings. It simply needs to take on and provide a viable alternative to a GPU that is two generations older: the H200 (based on Nvidia's Hopper architecture).

Its bigger challenges will be Huawei's locally produced Ascend 960DT and similarly configured chips from upcoming local chip design firms, as well as supply chain limitations that could restrict overall production and, by proxy, deployment for a company looking to spend billions on AI infrastructure in the coming days even if its "most powerful" status, which is currently consigned to a claim holds at the time of its release.

Durabook launches a workstation laptop with three real screens - Z14I-DX3 is a rugged mobile device featuring a trio of 14-inch full HD displays with an optional Nvidia RTX 5000 Ada GPU for command posts and drone teams

  • Durabook Z14I-DX3 rugged laptop has three 14-inch, sunlight-readable 1,200-nit touchscreens
  • At 9.8 kg and a mammoth 137.5 mm thick, it may suit vehicles and fixed positions rather than dismounted crews in the field
  • It could also be targeting customers at command posts and in drone teams

Durabook's latest rugged workstation laptop is less a notebook and more a capable folding command post, bringing power, durability, and plenty of screen real estate in tow.

The Z14I-DX3 pairs a conventional rugged clamshell with two extra full HD touch panels hinged to either side of the lid.

When folded, the side panels sit over the main display for transport; when opened, the three 14-inch screens form a mammoth 48:9 workspace for a client base that is expected to be overwhelmingly military.

Built around today's command post needs

While Durabook's press release says it is now available to order, it doesn't list a price on-site and instead directs users to request a quote for what it calls one of the most unique rugged laptops on the battlefield.

Durabook pitches the machine at defense, public safety, utilities, field engineering, and maritime users, describing it as a mobile command center where drone control and telemetry, mission maps, live video, and sensor data sit side by side instead of being juggled on a single display.

It also goes out of its way to make the screen component legible in all environments while focusing on utility: all three panels are 1,200-nit DynaVue sunlight-readable touchscreens with finger, water, glove, and stylus modes, and brightness can be synced across the set or adjusted per panel, as per Durabook's announcement.

This design choice makes the most sense when you consider who the workstation laptop serves: military customers. Each panel can run a separate application, so a drone team could keep a live feed on one screen, a map on another, and telemetry or communications on the third.

A single AC power adapter powers the whole setup, which can be configured with up to an Nvidia RTX ADA 5000 GPU that caps at 682 TOPS of AI performance, enabling offline image recognition and video analysis through on-device AI support.

Its I/O offerings also cater to the assumption that it might be plugging into military hardware, much of which uses legacy connections: Thunderbolt 4 and Wi-Fi 7 sit alongside two serial ports, VGA, an ExpressCard 54 slot, and a 41-pin pogo docking connector, plus dual gigabit Ethernet, HDMI, a smart card reader, and dual SIM with eSIM, with GPS, 4G, and 5G as options.

Durabook durability credentials include MIL-STD-810H testing for shock, vibration, altitude, freeze/thaw, high and low temperature, temperature shock, humidity, explosive atmosphere, and solar radiation, plus MIL-STD-461G for electromagnetic emissions and susceptibility, and an operating range of -29ยฐC to 63ยฐC.

Its weight class, however, rules it out as a portable device you can run around with, with a listed weight of 9.8kg (21.6 lb) and a thickness of 137.5 mm when closed, not including an adapter or carrying case.

This matters for drone teams that may already be carrying other hardware, including the drones they often deploy themselves; the Durabook offering suits fixed positions, shelters, or a vehicle better than a device that can be lugged around with relative ease.

For now, a 'workstation' class laptop that offers plenty of durability, a last-generation AI GPU, and a low-powered CPU might check a lot of battlefield boxes, but would be hard to compare in terms of raw performance to modern gaming laptops or even traditional workstations, both of which pack in significant amounts of power even if they skip the two additional screens - but that might just be the point.

Incredible oscilloscope packs an Nvidia T1000 GPU, 12-core AMD EPYC CPU, 96GB RAM, and 1.6TB NVMe SSD โ€” the 38Kg Tektronix DPO can run Windows 10 and features a 15.6-inch Full HD display

  • Tektronix's DPO718AX brings eight synchronized channels of up to 25GHz each to the 7 Series and can double as a Windows 10 PC
  • The EPYC 3351, T1000, 96GB RAM, 1.6TB SSD configuration the oscilloscope offers makes it more than capable of running most modern OSes
  • Prices start at an eye-watering $308,000 for the base configuration, which can be further modified as per end-user needs

Tektronix has added an eight-channel model to its flagship 7 Series oscilloscope line, and much of the attention it has drawn has gone to the computer it houses as part of the configuration.

The DPO718AX hosts a 12-core AMD EPYC processor, an Nvidia T1000 graphics card, 96GB of RAM, a removable NVMe SSD with at least 1.6TB of capacity, a 15.6-inch 1080p touchscreen, and an optional Windows 10 drive, all in a chassis that Tektronix's datasheet puts at 38.1kg.

This has drawn sharp comparisons to actual Windows-based PCs amid a RAM and memory shortage, including one by CNX Software, which said that the instrument "looks like a high-end PC running Linux (or Windows 10 LTSC)."

A powerful PC in its own right, albeit with dated components

None of the computer hardware listed for the DPO718AX is new or recently released. The AMD EPYC Embedded 3351 CPU is one of the oldest hardware offerings in play here, featuring AMD's first-generation Zen cores and a February 2018 release date.

While the SSD storage speed is unspecified, it is safe to assume it will be capped by the PCIe 3.0 support the EPYC CPU provides to the system. The 96GB of memory on offer can also safely be assumed to be DDR4, as the CPU supports only DDR4 configurations. Despite these limitations, the CPU does offer a 12-core, 24-thread configuration with a rated boost clock of 3GHz that should handle most tasks with relative ease.

The Nvidia T1000 GPU is an entry-level, workstation-class GPU built around its Turing architecture, with a release date of May 2021. The oscilloscope comes with an FHD touch-screen display and can output video up to QHD via DisplayPort, with a capped refresh rate of 60Hz.

The oscilloscope can also run Windows 10 natively, and it matters more than you might think: it is required for the compliance and RF analysis software the DPO718AX supports. The DPOs do not come with an installation by default; the Windows 10 LTSC 2021 installation is available on a secondary, removable drive that users can opt for if needed.

Since the integrated AMD CPU supports TPM 2.0, you could theoretically run Windows 11 on a device that costs hundreds of thousands of dollars, but the aging hardware, low-clocked CPU, and dated internals would make it a terrible PC replacement, even if one had the money to splurge on such an endeavor.

Interpol uses AI to identify 126 terrorists by analyzing over 100,000 images with new facial recognition tools

  • Interpol's Operation Shams II pulled 108,076 faces from jihadist propaganda with help from 11 countries
  • AI agents and scripts then deduplicated and quality-checked the set, leaving 6,362 images (~5.9%) for facial recognition
  • Interpol's facial recognition system, launched in 2016, then matched pictures to actual persons, with human verification in tow, and 126 suspected fighters have been identified so far

Interpol says an operation it coordinated in Tunisia in June 2026 used artificial intelligence to work through more than 100,000 faces taken from jihadist propaganda, producing matches against 126 suspected foreign terrorist fighters.

AI did most of the heavy lifting, condensing a mammoth 108,076 images into 6,362 unique, identifiable images that could be run through its decade-old facial recognition system.

This allowed 126 people to be identified on paper as potential terrorists who would still need to be tracked down by the international police organization.

A numbers game, cut down to size

Interpol says programmed AI agents and AI-generated scripts automated parts of the collection and investigative work, removing duplicates and screening out poor-quality faces.

This approach left 6,362 unique, high-quality images, which were then run through the Interpol Facial Recognition System (IFRS). This effectively cut a trove of images into a non-duplicated, actionable list of only ~5.9% of the original set, which could then be used to identify potential terrorists.

By eliminating 94% of the images that would otherwise have to be processed manually, AI reduced the resources that would otherwise have to be deployed to reach a similar conclusion.

This is particularly handy, given that propaganda images often number in the thousands and investigators needed to sift through them manually to identify potential targets, many of which were duplicated by others involved in the same study.

โ€œThe success of Operation Shams II demonstrates the value of combining international law enforcement cooperation with responsible AI-assisted analytical capabilities," noted Interpol's Director of Counter-Terrorism, Marรญa Carmen Muรฑoz Gonzรกlez.

"The operational model provides a strong foundation for supporting future international law enforcement cooperation targeting criminal actors around the world.โ€

Its automation attempts are not new; In 2019, Digit reported, citing Germany's Interior Ministry, that Interpol had presented a project called DTECH-Light intended to "detect, extract and analyze digital terrorist content, identify and locate suspects," with national bureaus asked to upload images of unnamed foreign fighters for comparison.

Interpol does not say what agents it used, which models or vendors sit behind them, or where they ran. "AI-generated scripts," it says it used, could simply mean automation code written with the help of a large language model rather than any purpose-built system.

For now, an AI is doing the grunt work so that a system launched in 2016, and the officers who check its output, can do theirs considerably faster, which is a significant win in efficiency for an agency that often has to deal with multiple sources of information, even as fears about the tech have been rekindled globally on multiple fronts.

These popular TP-Link home security cameras could be hacked to spy on you while you sleep, experts warn

  • Cybersecurity company OPSWAT found a login bypass and a crash bug in TP-Link's Tapo C200 cameras
  • TP-Link has extended that to include its C120 offering too
  • Anyone on the same network could get admin access, live video, and recordings without requiring the owner's credentials

Security researchers at OPSWAT have detailed two high-severity flaws in TP-Link's Tapo C200, a pan-and-tilt indoor camera listed on Amazon for $26.99 and sold as a baby monitor and pet camera.

The more serious issue is that someone on the same network can log in as the camera's administrator without the password, accessing the live feed and stored recordings.

At least one other bug, which OPSWAT rates as critical in the same disclosure but does not detail, has not been published.

A localized login that requires no authentication

The TP-Link Tapo C200 camera

(Image credit: TP-Link)

The TP-Link Tapo C200, as we noted in previous coverage of the incident, isn't just another security camera that happens to be vulnerable; it is one of the most popular models on the market, clocking in at over 3,000 sales on Amazon alone.

The Tapo C120, in its current iteration, sells over 5,000 units monthly, even as the advisory notes that its V1 hardware version is currently compromised until users update the firmware on their devices.

Both SKUs have received firmware updates that patch the vulnerabilities (CVE-2026-15315 & CVE-2026-15316), which are assigned 'high' scores of 8.7 and 7.1, respectively. However, according to TP-Link, CVE-2026-15316 does not affect the C120 camera.

However, the former vulnerability is the more pressing of the two and, according to OPSWAT, is particularly problematic for users because of how the C120 and C200 cameras function.

Both run a local management interface over HTTPS and use a challenge-response login designed to prove a client knows the owner's password. Khoi Tran, a graduate fellow at OPSWAT, and his mentor, Thai Do of the company's Unit 515 team, found a second verification path in which, under certain conditions, a value the camera hands out during login can be sent back and accepted as a valid authentication response.

The result is an administrator session after a small number of requests, with no password, no existing session, and no requirements for the new 'owner'. As a result, access includes live video, stored footage, and configuration changes.

OPSWAT's researchers pointed out that a C200 used as a baby monitor would expose "live video, night vision, crying detection and two-way audio."

The second flaw, CVE-2026-15316, affects only the C200 and sits in its Wi-Fi onboarding code. Sending the camera an oversized chunk of encrypted Wi-Fi credential data can crash its HTTPS service or restart the device outright, cutting the owner off from management and monitoring until it recovers.

The attacks are somewhat limited in scope: users aiming to exploit such vulnerabilities would need to be on the same Wi-Fi network, or within a certain trusted ecosystem, to begin with.

For now, users upgrading to TP-Link's newest firmware, issued for both models, rectifies both issues, but there might already be another security patch in the works: OPSWAT also found "a critical vulnerability that could allow an attacker to fully compromise the camera," which could then serve as a foothold inside the network.

It is currently holding off on publishing any details about the vulnerability as it waits for TP-Link to issue a patch that rectifies the situation. Neither OPSWAT nor TP-Link, however, has provided a timeline for when the patch will be available to end users.

Apple weighs its first server since the Xserve, and as always, Nvidia may hold the key

  • Reports claim Apple is weighing an as-yet-unapproved enterprise AI server with two or four M8 Ultra chips, targeting 2029
  • Apple is considering using Nvidia's NVLink Fusion to link the chips, with Thunderbolt-based Mac clustering falling short of data center bandwidth requirements
  • The move comes as demand continues to be a key driver for Apple's higher-end Macs, with AI firms buying Mac minis and Mac Studios in bulk, even as Apple has turned enterprise buyers away

Apple has been working on plans for an enterprise AI server built on its own silicon with an interesting twist: it is seeking Nvidia's help on the networking front to make it work.

A report by The Information claims Apple is considering two configurations: one with two of its future M8 Ultra chips and a larger one with four, aimed at businesses that want to run AI inference on their own hardware rather than in a public cloud.

The timeline, however, is long and loose, with a potential launch in 2029, though the same report cautions that the project could be canceled before then, with neither the server nor any Nvidia arrangement finalized at the time of writing.

A market that Apple previously walked away from

If it ships, the machine would be Apple's first purpose-built server since the Xserve, which Apple announced it would discontinue in November 2010 and stopped selling at the end of January 2011.

Steve Jobs's explanation, in an email to a reader of French site MacGeneration, reported by MacRumors at the time, was blunt: "Hardly anyone was buying them." Gartner's data backed up that claim with an estimated 10,000 units being sold per quarter, a relatively low number for the tech giant whose numbers normally ran in the hundreds of thousands or millions for most of its other products.

Apple's suggested replacements to users were server configurations of the Mac mini and Mac Pro, desktops running server software rather than rack hardware. If the 2029 launch materializes, it would mean Apple's reversal would see it enter the server market 18 years after the Xserve stopped being sold.

This time, however, feels different: The Information has reported that OpenAI bought tens of thousands of Mac minis and Mac Studios to train AI agents through reinforcement learning, and that Anthropic has rented Mac minis through Amazon Web Services, as per Ars Technica.

Getting caught off guard by AI-centric demand

Apple reportedly was caught off guard by the AI-driven rush for its hardware, with no enterprise AI strategy, no business engineering team in place, and no specific developer relations staff to manage those orders. As a result, it also turned away businesses asking to buy access to its Private Cloud Compute infrastructure.

The project reportedly had a powerful sponsor: Apple's now-CEO John Ternus, when he ran Apple's hardware engineering team. However, shortages plagued it, leading many users to opt for Nvidia's DGX Spark and AMD's Ryzen AI Halo as viable alternatives.

The focus, however, remains on Apple's ability to interconnect a large number of chips or dies together: its current flagship, the M5 Ultra that ships in the new Mac Studio on September 22 2026, is Apple's first quad-die design, stitched together inside one package by the company's UltraFusion bridge, with up to 512GB of unified memory and 1.2TB/s of bandwidth, which users often stack for on-device AI needs.

A data center-esque, server-grade offering, however, would require considerably more power under the hood to meet its AI needs, which would also depend on how fast the interconnect between chips is; Apple's current limitation is Thunderbolt 5 speeds, which offer up to 10GB/s (or 80Gb/s) bidirectionally.

For context, Nvidia says the sixth-generation NVLink, available through NVLink Fusion, connects up to 72 accelerators at 3.6TB/s each. Comparing total two-way bandwidth, that is roughly 240 times a single Thunderbolt 5 connection's one-way capability of up to 15GB/s (or 120Gb/s).

Apple's own marketing hints at what that gap costs: It says four clustered Mac Studios deliver up to three times the inference performance of one, suggesting it already makes scaling tradeoffs of nearly 25% when linking devices.

This could explain why Nvidia is in the conversation at all: proven tech that could help Apple scale its AI server ambitions without the performance overhead it currently already has, at a time when its silicon would be even more powerful, might just be a no-brainer for the Cupertino-based giant.

Mistral denies a fresh security breach, but the code on sale looks a lot like May's leak

  • Seller claims to be offering Mistral AI's full source code and says the company was breached again after May 2026 attack
  • Mistral says an investigation found no evidence of new unauthorized access but has not stated whether the listed code is genuine
  • No customer data has surfaced in analyzed samples, and nobody has shown files created after the May incident

A seller on a cybercrime forum says French giant Mistral AI has been hacked again and is offering what they call the company's full source code for sale.

The September 16 2026 post by an account using the handle "mrwho" consists of a listing titled "Selling mistral.ai Source Code" on an English-language cybercrime forum, according to The CyberSec Guru, pricing the material in Monero only before it attempted to steer potential buyers to Session or Telegram.

Mistral AI's own team has refuted this, stating it has "found no evidence to support this claim."

Not Mistral's first hacking-centric PR problem

Mistral's earlier hacking incident is undisputed - in May 2026, the Mini Shai-Hulud supply chain campaign, attributed to the TeamPCP group, spread from compromised TanStack packages to hundreds of npm and PyPI projects.

Mistral's own security advisory MAI-2026-002 says an automated worm led to compromised versions of its SDKs being published for a few hours on May 11 and 12, and that an affected developer device was involved. Microsoft Threat Intelligence found that a poisoned Mistral AI Python package fetched a second-stage credential stealer that allowed the attack to exploit users.

Mistral went further in statements to reporters than in its advisory. It told BleepingComputer that attackers had compromised a codebase management system and "contaminated some of our SDK packages for a brief period," while insisting that hosted services, managed user data, and research and testing environments were untouched. It also told HackRead that only certain non-core repositories were accessed.

TeamPCP, meanwhile, advertised roughly 450 repositories, about 5GB in total, for $25,000, and threatened to dump them for free if no buyer appeared within a week. One can therefore contend that this could be the same dump being remarketed by a different account, and the seller's profile is already suspect.

The CyberSec Guru noted that the account joined in September 2026 and had four posts and a reputation score of 30, despite displaying a top-tier "GOD User" rank. That profile could fit a scam in the making, but as the outlet pointed out, it could also fit a broker fronting for someone else or a freshly minted alias.

HackRead published 24 sample repository names from TeamPCP's May post. FrenchBreaches, which examined the 339-file tree mrwho shared in September, lists several of the same names. At least four of these appear in both: mistral-inference-private, mistral-inference-internal, mistral-finetune-internal, and mistral-common-internal.

This makes it hard to tell whether the purported 'hack' is just a rehash of an existing dump from Mistral's previous breach or a second successful hacking attempt. There is a straightforward test, however: If the September archives contain commits, files, or credentials dated after May 12, or secrets that were still valid after Mistral's cleanup, the seller's claim of a second breach gains real weight. If everything predates the May incident, this is a resale, which is embarrassing for Mistral but not a new security failure.

Of course, locating the archives or examining them would involve paying the ransom in crypto, as required by what could potentially be a scam in the making- a tremendous leap of faith for an account that was created earlier this month, making this essentially a lottery ticket at best for any security researcher attempting to take a closer look.

Researchers can make headphones leak audio through a wall, but the 30-meter claim has a few caveats

  • HKUST (Guangzhou) and HK PolyU researchers' InjectEave beams a radio carrier at devices so their own circuits leak analog audio
  • The leaked audio has already been decrypted by the device itself, making encryption offer no protection against such an approach
  • The 30m headline needed a pricey amplifier pushing output to 10 W, while standard ranges of 1 to 6m were measured by detecting a test tone

Researchers at the Hong Kong University of Science and Technology and the Hong Kong Polytechnic University have shown that everyday headphones, a desk phone, and a handful of smart-home gadgets can broadcast what they are doing simply by using a radio signal.

The technique, called InjectEave, was presented at USENIX Security 2026 in Baltimore, and multiple outlets have since covered the researcher's claim that the attack "can recover headphone audio from up to 30 meters away, including through walls".

The claim may be accurate, but it has limitations, including the need for specialized equipment that is often very noticeable in most settings.

An impressive technical show with plenty of limitations in tow

Conventional electromagnetic eavesdropping waits for a device to leak. That works poorly for audio, because speech sits below 20 kHz while a device's wiring radiates efficiently only at megahertz or gigahertz frequencies.

InjectEave chooses to close the gap by transmitting a carrier signal at the target. According to the paper, nonlinear components such as amplifiers, analog-to-digital converters, switching MOSFETs, and power converters mix the secret signal onto that carrier, and the device's own traces and cables radiate the result back to a receiver.

Because the leak happens in the analog path, after audio has been decoded, the project page states that "InjectEave is immune to digital defenses such as encryption, masking, and randomization." Encryption in any form on a wireless headset is irrelevant, since the attack directly targets the signal driving the speaker, not the radio link.

The team demonstrating this used a USRP B210 software-defined radio, two antennas, a Siglent spectrum analyzer, and a laptop to set up their proof of concept, which could, as they noted, "eavesdrop on the majority of these devices from over 2m away and through walls, with a maximum distance of 30m for recovering intelligible headphone audio".

This isn't the first time the technique has been used, even as the researchers have built on it considerably; the idea originates from "The Thing," a Soviet bug given as a gift to the US ambassador in Moscow in 1945, which was passively powered remotely as a listening device.

InjectEve, however, does not involve planting anything; instead, it leverages existing work on interference-induced leakage and impedance-based backscatter, and distinguishes itself by recovering coarse digital data rather than continuous analog waveforms, allowing users to 'listen in' without added steps.

The same approach applies to wired headphones, which are also prone to leaking microphone audio; researchers concluded that their sound cards were the primary source of the leaks, which were being sent back over very short distances.

The threat is somewhat tempered by the fact that it can capture what users hear but, with wireless headphones, cannot hear what the user is saying. The attacker also has to transmit continuously and use a high-powered (10W) transmitter to reach the full 30-meter range, even though capturing and rendering speech is harder than the tones the test used to prove the approach worked.

The attacker also needs to know the target model and profile a matching unit first, although they managed to get a profile to transfer cleanly across three identical UGreen headsets, suggesting this might be easier than one would assume.

The researchers say they reported the findings to the affected manufacturers but, "as we have not yet received a response," withheld the table's frequencies and stripped injection control logic from their released code. One shouldn't be too hopeful, however, as no software update can fix an analog leak, and it is relatively limited in practical abuse cases.

This NATO-backed drone AI picked its own target and struck it, but relied on a human-drawn map to do so

  • Scaleout's onboard AI let a BAE Systems ALMA drone rank, select, and strike an armored engineering vehicle in a January 2026 demo
  • Humans set the mission, started the system, and kept a pilot in reserve, but did not ultimately use them during the test
  • The test underscores how small AI models can essentially take over not only the target-selection part of the equation, but also perform the actual mission end-to-end without human intervention needed

A small drone flying over a snow-covered Swedish test range in January 2026 found several objects, ranked an armored engineering vehicle as the most valuable, and made a beeline for it before dropping an explosive.

There was no human involvement in the entire process, which included selection, targeting, and then neutralization by the drone, making it a considerably more autonomous approach than what the current battlefield uses.

The flight, part of BAE Systems Bofors' Affordable Loitering Modular Ammunition (ALMA) program with onboard AI supplied by Uppsala-based Scaleout Systems, resurfaced this month as AI safety became a key topic among industry and government stakeholders alike.

A growing threat and capability for modern militaries

Scaleout Systems tested the AI in question with a pilot on standby and a continuous connection throughout the exercise, during which the drone used AI to detect, identify, and geolocate potential threats.

Depending on how you frame it, you can argue that this is both a threat to modern militaries and a boon: an autonomous drone that can select targets without oversight or a backlink is essentially immune to jamming, offering a much higher likelihood of completing its mission than alternatives.

At the same time, it becomes riskier when it is completely cut off from communications, malfunctions, or fails to select the correct target without human oversight.

Interestingly, BAE Systems Bofors' own release on Winter Demo 2026 does not mention the strike at all. It frames the three-day Karlskoga event around roughly 20 startups and technology companies, with Swedish Defense Minister Pรฅl Jonson joining a panel and saying, "We need more actors and entrepreneurs in the defense industry."

The test, despite lacking human interaction in its end-game, still relied on human input to some degree: a user pushed a button to start the exercise, and humans set the parameters overseeing the entire exercise.

This isn't the first machine to choose its own target, however; Israel's Harpy loitering munition, fielded since the 1990s, can autonomously detect and attack radar emitters whose locations were unknown at launch.

This is awkward timing for regulators, to say the least: on September 5, the 128 states party to the Convention on Certain Conventional Weapons agreed on a non-binding text on lethal autonomous weapons, after the United States and Russia pushed late changes, including to a section on human judgment and control.

As a result, Nicole van Rooijen of Stop Killer Robots told Reuters that three years of work had been "substantially diluted in the last hours." For now, Scaleout has shown that detection, ranking, and targeting can run on a small airframe without a data link, within parameters that people set.

Whether this makes it to a modern battlefield is increasingly likely, even as the Russia-Ukraine conflict becomes more reliant on autonomous machines. The more pressing question is one that will be answered sooner or later: how does such a drone make decisions if it is jammed from its source without any human oversight?

1.58-million-staff Amazon will soon have more Nvidia GPUs than employees โ€” AWS to buy more than 3 million additional chips before 2029 in addition to thousands of existing H100, H200

  • AWS deal with Nvidia adds 2 million Blackwell Ultra, Rubin, and Rubin Ultra GPUs, on top of more than 1 million committed in March 2026
  • Totals more than 3 million Nvidia GPUs due before 2029, a ~1.9x multiple for each of Amazon's roughly 1.58 million employees
  • Nvidia's CFO has said deliveries start this quarter, not in 2027, but neither company says what it counts as a GPU or what the deal costs

Amazon ended 2025 with about 1.58 million full- and part-time employees, most in fulfillment centers and delivery operations, with a much smaller share working in its AWS data center division (estimated at around 246,000).

By mid-2028, Amazon Web Services expects to have taken delivery of roughly twice that many new Nvidia GPUs, based on a recent deal it made with Nvidia.

The latest deal was announced on August 26, the same afternoon Nvidia reported quarterly earnings, and will see AWS plan to deploy two million additional Blackwell Ultra, Rubin, and Rubin Ultra GPUs across its global infrastructure in 2027 and 2028. This is on top of over a million Nvidia GPUs that AWS committed to at Nvidia GTC 2026 in March, and which Nvidia's Ian Buck told Reuters would ship from 2026 through 2027.

A mammoth deal that dwarf's Amazon's entire payroll

Together, this all amounts to over three million GPUs in play between the data center giant and the chip designer, which is also the world's most valuable company at the time of writing. At 3 million GPUs against a workforce of 1.58 million, that's nearly 1.9 Nvidia GPUs per employee.

This is only Amazon's commitment to Nvidia; it also has its own custom Tranium3 GPUs, which the company says are "nearly fully subscribed" or "almost fully booked" as of mid-2026.

At the same time, Amazon is not increasing job roles on its end; it cut around 30,000 corporate roles between October 2025 and January 2026, a restructuring its top HR executive, Beth Galetti, described as "reducing layers, increasing ownership, and removing bureaucracy."

Building on an already solid base

While AWS's current GPU base from Nvidia, consisting mainly of H100 and H200 GPUs, is smaller than Microsoft's 485,000 count, it is hardly a rounding error, with Omdia estimating that Amazon bought 196,000 Hopper GPUs in 2024 alone.

The interesting part is determining what counts as a GPU: Nvidia and Amazon's joint statement about 2 million GPUs across calendar years 2027 and 2028 might mean two very different things depending on how you count GPUs.

At GTC 2025, Nvidia said it would count Rubin-generation GPUs by compute die rather than by package, which is why the Vera Rubin rack was first unveiled as NVL144. It reversed course before CES 2026, and the flagship now ships as Vera Rubin NVL72, counting 72 two-die packages. To make matters a bit more complicated, Rubin Ultra, due in 2027, puts four compute dies in each package.

Whether the companies count each die as a separate GPU or the whole package as a GPU could make the numbers skew heavily in either direction. The deal also includes a national security element: approximately 100,000 GPUs are earmarked for US government AI workloads at Impact Level 6.

Amazon's limitation here is supply, not demand; AWS revenue rose 37% year over year to $42.2 billion in the second quarter, and its contracted backlog reached $496 billion, up from $364 billion three months earlier, as CloudTech News reported.

On Amazon's July earnings call, CEO Andy Jassy said capacity would fall short of demand this year and likely next, adding: "In fact, the demand we already have for 2028 is striking."

In addition to its own custom ASICs, including Tranium3, Amazon is gearing up for a few fiscal years of eye-watering AI infrastructure spend and AI demand combined, and it better be right: Amazon's free cash flow has already turned negative as it looks to fund its bid to be one of, if not the largest hyperscaler in play for the foreseeable future.

Via StorageNewsletter

China's autonomous 'bionic robot' fish looks just like the real one, perfect for covert military operations โ€” Robocean BG5 could also be used to track poachers

  • Boyagongdao's BG-5 robotic golden arowana was one of the most popular attractions at CIFTIS 2026, with staff saying it plans its own route around obstacles
  • The 3 kg, 640 mm robot is rated to operate at 5 meters with a top speed of 0.6 m/s, even as endurance, cameras, and payload remain undisclosed
  • The design is not new: the BG-5 has been on the company's site since 2023, and a near-identical arowana robot has been available on their site since 2021

A golden fish doing laps in a small tank at Beijing's Shougang Park has become one of the most shared clips from this month's China International Fair for Trade in Services (CIFTIS).

The BG-5, a robotic golden arowana made by Boyagongdao Marine Technology Group, effectively serves as an autonomous underwater surveillance drone.

The fish has gone viral on Reddit since, with footage of it reaching the top of r/Damnthatsinteresting since it was first posted.

Not a new invention, but one that has multiple potential uses

The BG-5 has also received coverage (in Chinese) from mainstream Chinese news sources, and while details are scarce on the product page (also in Chinese), its dimensions are listed as 640 by 204 by 90 mm, with 3 kg in tow.

It can travel at a maximum depth of 5 meters and maintains a top speed of 0.6 meters per second or approximately 2.16 km/h. Boyagongdao has not published endurance, payload, or camera specifics, and it has not made any battery-life figures public.

The BG-5 is not new, however; its product page carries images uploaded in August 2023, and the company used the BG-5 to illustrate a World Oceans Day post (in Chinese) in June 2023. The same description appears on a Chinese equipment marketplace listing (in Chinese) dated July 2024.

The BG-5 Golden Dragon fish-shaped bionic robot

(Image credit: Boyagongdao)

This isn't even the company's first arowana robot: its older Robosea website has product images dating to 2021 and describes the ROBOLAB-GL, a multi-jointed arowana robot with similar use cases, including education, research, entertainment, and marine biology.

It does, however, have an overwhelmingly military aspect, and the company's background confirms this. Boyagongdao has described itself as a military-civil fusion enterprise , pitching its bionic ROBO-SHARK as a quiet platform with a sound-absorbing shell for concealment and its ROBO-ROV for tasks including underwater combat.

A company representative, Zhang Yu, also said in a 2025 report its bionic technology "can also be used in military and national defense fields."

The irony here is that it also doubles as an excellent anti-poaching tool: the golden arowana is a color variety of the Asian arowana, a species left endangered by over-harvesting for the aquarium trade, and it has fishing restrictions in place.

A drone-like surveillance fish lookalike could make fishermen even more nervous about attempting to catch any of the endangered species, even as the relatively suspicious exclusion of hardware internals, capabilities, and endurance/performance figures makes one consider that it is aiming to cater to a single primary customer, despite the company's insistence on multiple use cases for the BG-5.

China is readying the world's first giant submarine UAV carrier โ€” built with a 1115ft dock, the unnamed mothership could be longer (and bigger) than WW2 light aircraft carriers and carry 148ft underwater drones

  • Satellite imagery shows China building a roughly ~200m ship in Shanghai that analysts say is a mothership for submarine-sized drones
  • It pairs a bottom-opening well-deck and 12-arm cradle with an internal hangar that experts estimate holds four 115- to 148ft XXLUUVs
  • While the ship itself is shorter than an Essex-class carrier, its dock clocks in at about 1,115ft

China appears to be building a type of ship no navy is publicly known to operate: a large surface vessel designed to carry, launch, and recover uncrewed submarines the size of conventional crewed boats

The hull was first posted on September 13 2026 by Japanese open-source analyst KAROTASU and assessed two days later by H I Sutton at Naval News.

It currently sits at a dock at the Hudong-Zhonghua shipyard in Shanghai, and Beijing has yet to formally acknowledge its existence, so it has no name, list of capabilities, or the military branch that will eventually operate it.

A large dock linked to a much smaller ship

KAROTASU's post places the vessel in what he calls a 340m-class dock, which works out to approximately 1,115ft. However, the dock is not the ship. The same post estimates the hull itself at roughly 200m long and 30m wide, and notes that a second, unidentified structure is being assembled in the same dock.

Defence Security Asia, using imagery dated September 15, puts the hull at about 205m by 27m, which clocks in at roughly 672 ft. This makes the mothership big, but not as big as the largest WWII-era fleet carriers, though larger than the US Navy's Independence-class light carriers from that era.

For context, an Essex-class carrier, the backbone of the US Navy's Pacific campaign from 1943, measured 872 to 888ft overall and displaced 36,380 long tons at full load. At 656 to 673ft, the Chinese hull comes up roughly 200 to 230ft short.

The primary use case of such a mothership would be to deploy extra-extra-large uncrewed underwater vehicles (XXLUUVs), which is a mouthful, and it builds around China's naval ambitions at a time when it seems certain that any conflict or show of power between the world's two superpowers will involve a maritime component.

At 35 and 45m (115 and 148ft), the XXLUUVs are the size of small crewed submarines and have an estimated range of 10,000 nautical miles based on a similarly sized concept that a Chinese shipbuilder has exhibited.

This, at the very least, challenges the current balance of power on multiple naval fronts that were not in play previously: until now, the drones have been tested from specially built floating docks, which conceal them in port and carry them out to sea for launch.

This works well on paper and for trials, which often use a mix of towing, favorable weather, and predictable shore infrastructure, but it limits range to their maximum operating capabilities and access to spare parts/repair potential, all of which the yet-to-be-named vessel addresses.

All in all, in a world that has conflicts flaring up left, right, and center, the world's largest surface ship is designed around full-size uncrewed submarines, with an enclosed hangar to house and maintain them, which is both a statement and a real threat to the US and its allies on the naval front from China, which is closing gaps on multiple fronts and taking the lead on others, even as territorial disputes in the South China Sea remain a key issue.

10 boats in one van: Russia goes DIY with a plywood vessel that can be built in 4 hours and can carry 4 fiber-optic UAVs

  • Russia's Scientific and Production Center Ushkuynik says ten disassembled Skorlupa hulls fit in one GAZelle van
  • Each hull can be assembled in an estimated four hours (by Russian estimates) using a cordless screwdriver and can travel up to 200 km while carrying up to 250 kg of payloads
  • The Skorlupa comes with up to four communication modules and can carry up to four fiber-optic drones, allowing it to serve as both a mothership for attack or recon drones and a one-way attack craft

Russia's Scientific and Production Center Ushkuynik has released new details on Skorlupa, a light uncrewed surface vessel whose headline feature isn't speed, stealth, or sensors.

According to www1.ru, company CEO Alexey Chadayev says ten of the boats fit into the cargo bed of a single GAZelle light van when broken down, and that one hull goes together in about four hours with an ordinary screwdriver.

The hull is cut from water-repellent plywood, and Chadayev told the Russian government daily Rossiyskaya Gazeta, in an interview published on September 8 (RU) around the International Technological Congress 2026, that the craft can be produced at any furniture factory and costs roughly a fifth of a conventional naval drone.

A low-cost alternative in an increasingly asymmetrical war?

As the Russia-Ukraine conflict enters its fifth year, both sides have innovated, focusing on drones and autonomous vehicles to save lives, operate remotely, and minimize costs.

The Skorlupa does just that: the developer cites a 200 km range and a 250 kg payload, letting operators use it remotely while cutting costs as Russia and Ukraine struggle to fund their war efforts.

It can also be used in two ways: as a one-way strike platform, delivering an explosive against a ship's hull; or as a mothership, carrying four fiber-optic aerial drones housed under a deck skin that folds open on command.

As the war drags on, it's increasingly becoming one that demands practical and cost-effective solutions that do not endanger lives, with Ukraine also often pulling off similar approaches, including retrofitting remote-controlled kits to Humvees and Operation Spiderweb, which ingeniously launched attacks from within Russia's borders on its airfields, dealing damage that amounted to billions of dollars.

Skorlupa does something similar that makes it immune to jamming: it is controlled by a physical fiber-optic cable that lets it function even in areas where it would otherwise be cut off from wireless communications. This is also why the KVN has become one of Russia's most-used FPV drones.

A non-emitting boat carrying non-emitting drones is effectively unjammable and hard to counter, and with millions of Russia's KVN drones already in play, it would be a well-supplied Unmanned Surface Vehicle (USV) to build up a naval and aerial threat in a region where Ukraine regularly takes the initiative on the former.

As Alexey Chadayev pointed out in his interview, "With a Skorlupa like this, you can wreck any seaport without missiles," while noting that it can be made at any furniture factory.

This 8-bit computer plans to run flight sim and generates a 'pleasant homely aroma' by burning dust off 1950s vacuum tubes โ€” oh, and it can explode at any time

  • Retired UK hobbyist builds 8-bit computer from 460 recycled tubes, all wired as NOR gates, on a 190 x 130 cm wall panel
  • The machine is expected to run a flight simulator program once completely finished, but the builder is currently working on the status system that would allow it to do so
  • Previous versions of the machine have gone 'bang' twice, as noted by the tinkerer, prompting him to keep a fire extinguisher handy for his experiment

A retired hobbyist in the UK who identifies himself only as Mike has hung an 8-bit computer built from 460 recycled vacuum tubes on a brick wall in his home, and over the past ten days, it has seen widespread press coverage.

The machine is real, the glow is real, the smell is real, and the accompanying documentation is unusually candid and detailed for what is essentially a DIY project.

The tinkerer is currently trying to use the computer to run a flight simulator he has already coded but has yet to get the hardware into a state where it can run.

Soviet-era tech meets a hobbyist and a computer is born

Mike's technical write-up makes it clear that we have a well-designed, well-researched 8-bit computer that packs 920 triodes into 460 Soviet-designed 6N3P double triodes, each wired as an identical NOR gate.

The registers, counters, 8-bit arithmetic logic unit, ring-oscillator clock, and small tube RAM are all assembled from that single building block, an approach Hackaday traces to the Apollo Guidance Computer.

The tubes sit on 46 ten-tube plug-in boards across five backplanes on a 190 by 130 cm acrylic panel that weighs roughly 20 kg. The instruction set supports 16 operations; the ALU adds, XNOR, increment, NOT, and carry, and a carry register lets the 8-bit machine chain 16-, 32-, 64-, and even 128-bit arithmetic, slowly.

However, there is no pipeline: six fetch cycles, one execute, one unused, and this is intentional, with Mike saying that the timing logic implemented is a bit too complex compared to the rest of the system.

One design choice matters more than the rest: Mike keeps the high-tension supply below 100 V, well under the 150 V anode rating the Valve Museum datasheet lists for the 6N3P and far below the several hundred volts typical of legacy tube equipment. That is what lets him pack components 2 mm apart under each socket, allowing for a much more 'minimal' look than would otherwise be possible, and it is also why he can describe a wall of hot glass as nearly, but not quite, safe to touch.

About a minute after switch-on, the tubes glow red from the side, and the room fills with the smell of hundreds of double triodes burning off their dust. This gives it its 'pleasant homely aroma,' as the hobbyist puts it.

The machine currently drives a bank of ex-British Rail flip-digit displays, made by Bodet for 1980s station clocks, and is expected to power a rudimentary flight simulator system down the line.

The experiment has had its lows, though, with Mike reporting that it has gone "BANG" at least twice with earlier iterations; the first time he pulled plugs in a panic, and the second time his wife Judy carried on decorating the Christmas tree, later buying him a fire extinguisher as a precaution.

While the flight simulator is a work in progress, the aroma is here to stay, and Mike seems determined to see his project, which encapsulates tech from the previous century, through to completion.

RTX 5090s are going for as much as $9000, as AI server builders reportedly buy Nvidia's flagship by the pallet, but the photos behind the story may be AI-generated

  • The cheapest available US RTX 5090 now costs over $6000 against a $1,999 launch price, with third-party listings often running past $9,000
  • The GPU that already pushed past $3,500 in Feb 2026 owing to memory constraints driving prices higher has now hit fresh highs at multiple retailers
  • The move is linked to AI demand, as data center operators have entered the fray to secure compute despite Nvidia's GeForce driver license having banned 'data center deployment' on paper since 2017

Six weeks ago, the story was ultra-rare books being fed spine-first into high-speed scanners so that AI labs could train on text written before chatbots polluted the corpus.

Focus, however, has shifted considerably to AI labs bringing the same voracious appetite to Nvidia's flagship consumer-grade Blackwell GPU, the RTX 5090, which has essentially disappeared from shelves unless you want to pay a 200 percent or higher premium to grab one.

Photographs circulated by Hong Kong outlet HKEPC, and picked up by multiple publications including Guru3D, VideoCardz, and TechPowerUp, appear to show wooden pallets stacked with boxed, retail GeForce RTX 5090 cards at AI server assembly sites, waiting to be unpacked and slotted into multi-GPU rigs.

The sky is the limit for Nvidia's flagship consumer card?

This isn't the first time Nvidia's RTX 5090 GPUs have been deployed en masse on multi-GPU, AI-centric rigs, but this time feels different, even compared with previous shortages.

For context, Nvidia launched the RTX 5090 at $1,999 in January 2025. Tom's Hardware's price tracker, updated on September 14 2026, lists the cheapest available US card at $6,389, nearly 3.2x the former.

PCGamesN reported the same week that first-party stock at Amazon, Newegg, and Best Buy had essentially vanished, leaving third-party marketplace listings above $6,000 and, in some places, over $9,000.

The pictures in circulation don't show RTX PRO workstation GPUs, but rather GPUs from MSI, Gigabyte, and ASUS that the average gaming enthusiast or consumer would pick off a shelf.

ไธญๅœ‹ๅพˆๅคšๅป ๅ•†ๆœƒๅœจๅ„ๅœฐๆ”ถ่ณผ RTX 5090 ไธฆ็ต„่ฃๆˆ AI ๅทฅไฝœ็ซ™ๅ‡บๅ”ฎใ€‚ pic.twitter.com/AssaXEylJ0September 10, 2026

An AI-generated image to create more FOMO?

The images have, however, been disputed by some quarters: Kevin Hofer at Swiss retailer Digitec, one of the few writers to examine the images rather than republish them, pointed at the box lettering in one frame and asked what a "50B0" or a "50R0" is supposed to be, concluding that AI was probably involved in producing the picture. Twitter has also added a "made with AI" moniker to the image in question.

TechPowerUp and TweakTown both carried the same warning in softer form. Guru3D, to its credit, noted that the report explains neither why these firms chose the RTX 5090 nor the scale of the purchases.

Coverage like this, even with disclaimers to the contrary, can create a "fear of missing out" (FOMO) where price increases become a self-fulfilling prophecy as businesses and consumers alike move purchases forward to avoid paying a further premium.

Examining the value that an RTX 5090 brings to the AI table

The Nvidia RTX 5090 is its most powerful consumer-grade card to date, packing a Blackwell-based GB202 chip and 32GB of GDDR7 memory, which checks multiple boxes for local AI use cases and gamers looking to max out games at 4K or higher.

Nvidia's GeForce driver EULA has, since late 2017, included a clause titled "No Datacenter Deployment" that should, at least on paper, prevent data centers from stockpiling or using these.

The chip designer, currently the world's most valuable company, has previously implemented technological restrictions such as LHR (Lite Hash Rate) on its RTX 3000 series GPUs to prevent GPU miners during the Ethereum gold-mine rush from hoarding supply.

It has also released a China-specific RTX 5090 D, which reduces AI performance while matching the RTX 5090 in gaming throughput. The RTX 5090 D, created to meet AI export restrictions, shows that Nvidia can limit the RTX 5090's AI performance, but it remains relatively indifferent to a market that was its core revenue source only a few years ago.

The RTX 5090's price hike, at least in part, may be due to the RTX PRO 6000's staggering, out-of-control pricing, which Nvidia nearly doubled to $16000. The underlying cost driving the price hike is the GPU's 96GB of VRAM, which also makes up a sizeable, if not dominant, chunk of its total bill of materials.

An RTX 5090 comes with 1/3rd the VRAM on offer, but nearly the same compute performance, and with AI-centric algorithms often assisting in breaking up tasks between GPUs and memory pools, even as the total memory pool remains similar, a triple stack of RTX 5090 GPUs should comfortably outperform the RTX PRO 6000 in certain tasks.

At the same time, Chinese OEMs have reportedly managed to slap on as much as 96GB of VRAM on an RTX 5090, which could make it an even hotter commodity in a country where both the RTX PRO 6000 and the RTX 5090 are export-restricted but do manage to make it on the regular.

The RTX 5090 is a manufacturing problem with a memory bottleneck attached for AI consumers, but with the alternatives having doubled in cost recently, AI consumers are looking to save money wherever possible, and both the stock RTX 5090 and a potentially modified one are some of the best candidates in a market that has already exhausted most of its last-generation supply of the same.

US Treasury wants banks to be better at filing cyber scam reports after noting nearly $13 billion in losses since 2023

  • The US Treasury's FinCEN arm asks financial institutions to file scam center suspicious activity reports under a new keyword
  • FinCEN says that it flagged financial moves across 33,904 different filings, but actual losses might differ significantly, as the approach is prone to double-counting transactions
  • Only 1,300 institutions filed reports, with 10,082 (29.7%) of them centering around exploitation of the elderly by scammers

The US Treasury's Financial Crimes Enforcement Network has issuespublished an alert and a companion data analysis telling banks, credit unions, digital asset exchanges, and securities firms that it needs sharper reporting on the overseas scam centers that it says target Americans at an industrial scale.

FinCEN puts total damages, per its reporting mechanism, at roughly $12.7 billion linked to suspected digital asset investment scams between September 2023 and the end of 2025.

The number comes from adding up the dollar values of 33,904 Bank Secrecy Act filings that referenced the keyword from its 2023 "pig butchering" alert, which may be overstated, as it includes both attempted and successful transactions as well as both inbound and outbound reports, often of the same transactions, causing significant overlap.

FinCEN's new requirement is a keyword

While the $12.7 billion is a measure of what institutions have flagged and is prone to double-counting and errors, victim losses, a significant chunk of which go unreported, may be considerably higher.

This has prompted Gene Lange, who effectively works as the Under Secretary for Terrorism and Financial Intelligence, to call these scams "one of the most significant fraud threats facing Americans today."

It has also prompted a new suspicious activity report keyword: "FIN-2026-SCAMCENTERS," which institutions are expected to use to indicate that a scam center is potentially involved.

FinCEN also wants chat logs, scammer phone numbers, social media handles, wallet addresses, transaction hashes, and the URLs victims were told to deposit into, filed in the structured cyber indicator fields rather than left out.

Institutions to volunteer more information to stop scams

The move is part of its push to have institutions volunteer more information under the US Patriot Act, as it aims to confront what is a growing intelligence problem: scammers tend to route victims through several institutions in sequence; most filers see only one slice of a scam's lifecycle and often have difficulty tracing it all the way.

For example, a crypto exchange might see a customer buying USDT and sending it off-platform, a bank might see a wire to that exchange, and a brokerage might see a retirement account liquidated. None of them would have the bigger picture of what essentially happened or what triggered the transaction.

Combined, with properly linked information, it makes it much easier to identify a potential scam; separately, these incidents can inflate the number of reports, which often aren't linked, and investigations can lack insight into the origin or final destination of the funds.

FinCEN's Rapid Response Program has interdicted $1.8 billion and recovered just over $1 billion for 5,790 US victims since 2015, which, against the flagged totals, is a very limited recovery at best compared with the actual funds at stake. This highlights a larger fundamental problem: institutions mostly detect these schemes after the money is gone, and reporting them correctly and thoroughly may yield limited dividends at best against an industry that has morphed, relatively unchecked, into a multi-billion-dollar juggernaut.

How the mighty have fallen โ€” the notorious Stuxnet malware source code has been replicated and posted on GitHub for all to see

  • A pseudonymous GitHub account has published what it calls a reconstruction of Stuxnet malware that purportedly took out a fifth of Iran's centrifuges before being discovered
  • The original source has never surfaced, and the 'Stuxnet' moniker that the account uses comes from Symantec's coining of the name weeks after it was discovered
  • The code remains unverified and untested, with some users indicating that it is likely an AI-generated replication of the original binaries' behavior, which has been widely documented

A GitHub account has published what it describes as a faithful reconstruction of Stuxnet, the worm that sabotaged Iranian uranium-enrichment centrifuges.

It also became the first piece of software widely accepted as having caused physical destruction in the real world, highlighting how malicious software can often do much more harm to people and hardware than just stealing or manipulating data.

The repository surfaced via a Show HN submission, which mainstream media outlets then picked up, highlighting the as-yet-unknown researcher's reverse-engineered code.

Not the first or last Stuxnet repository

The original Stuxnet source, written by whoever built it, has never been leaked and did not leak last week. The repository's README explicitly states that it is a reconstruction assembled from decompiled binaries, and those binaries have been in public circulation since Belarusian firm VirusBlokAda pulled samples from an Iranian customer's machines in June 2010.

Everything that followed, including Symantec's W32.Stuxnet Dossier and Ralph Langner's To Kill a Centrifuge, was built on those samples and how they reacted in test environments.

This is also not the first time readable C-language code aiming to replicate Stuxnet has been published online. Malware researcher Amr Thabet published a decompilation of the MRxNet rootkit carrying a 2010 to 2011 copyright notice. Christian Roggia followed with a dropper decompilation called open-myrtus, copyrighted 2012 to 2014, which has since been forked into a long chain of repositories.

The irony is that if such code were a faithful replication of the infamous malware, it would not have mentioned "Stuxnet" in multiple places, including registry keys. This is because the moniker is not one the developers likely used, but one Symantec switched to from its original 'W32.Temphid' identifier.

The thread where it was first brought to attention by a user called Sadpainy also has mixed views from developers, many of whom have branded it 'AI slop' or a 'fake' that relies on a mixture of already existing repositories, even as the about page on its GitHub repo states that it was reproduced by the researcher for educational purposes and is designed to only work on Windows XP and Windows 7.

For those looking to test it, a virtual machine might be their best bet, especially given Stuxnet's ability to physically damage hardware, but it is also a stark reminder of what a rogue AI agent could do if left unchecked without specific instructions or safeguards.

โŒ