Connect with us

Tech

Powerful AI, Cyberthreats, and Industry Upheaval Define This Week in Tech

Published

on

As covered in the Daily Tech Insider newsletter this week, AI grew more powerful, more embedded, and harder to contain. Frontier models crossed new capability thresholds, workplaces and government agencies widened deployment, and cybercriminals found fresh ways to exploit automated tools. Meanwhile, lawsuits, leadership changes, rising hardware costs, and a disappearing labor platform showed how quickly the industry’s ground is shifting.

Top news

Frontier AI models push capability and safety boundaries

OpenAI unveiled GPT-6 Astra, its most powerful model to date, promising major advances in software engineering, research, and desk work. Astra is also the first model OpenAI has designated at its “Critical” cybersecurity capability threshold. Its restricted capabilities can discover and weaponize vulnerabilities, while the model’s increasingly opaque reasoning is raising concerns about oversight and accountability.

Anthropic released Claude Fable 5.1 and Mythos 5.1, two enterprise-focused models based on the same foundation but governed by different safety filters. Fable is broadly available through major cloud and coding platforms, while Mythos is restricted to approved, invite-only work in cyberdefense and life sciences.

AI moves deeper into workplaces and government

Meta and Adobe are turning Slack into a more prominent AI hub. Meta is replacing Google Chat with Slack to support workflows involving AI agents, while Adobe has introduced more than 70 Slack tools capable of generating and editing creative assets using the context available within a workspace.

The Pentagon has made secured versions of ChatGPT and Grok available through GenAI.mil to its workforce of more than 3 million military and civilian personnel, where they join Gemini. More than 1.7 million unique users have joined the platform.

Even as organizations accelerate deployment, users remain wary of handing AI direct authority over people. Daily Tech Insider polls found that 85% of readers reject the idea of an AI boss. Respondents were more receptive to supervised AI assistants and models built around human-AI collaboration.

Google expands its generative media toolkit

Google is rolling out Pics, an AI-first image generator and editor powered by Nano Banana, to eligible Workspace and Google AI subscribers. Its features include prompt-based image creation, object editing, text translation, and collaborative workflows.

Google is also adding more precise controls to AI-generated video. Gemini Omni 1.1 Flash introduces longer scene extensions, keyframe constraints, video references, faster low-resolution drafts, and 4K upscaling. It can extend scenes to a cumulative duration of 40 seconds, although Google Cloud continues to classify the model as a preview.

Maps and machines test the limits of automation

Google Maps and Google Earth now display Lake Ontario as “Lake America” to US users following a federal renaming. Apple Maps followed suit days later. MapQuest, OpenStreetMap, and Waze have not adopted the change. MapQuest’s refusal proved commercially significant, helping drive a 50-fold increase in usage, according to the company.

Meta is testing robots inside its data centers for tasks such as swapping cables, cycling power, and inspecting hardware. The machines remain slower and less capable than human technicians, however, and still require human supervision.

Insider intel

AI advertising becomes a billion-dollar business

ChatGPT Ads reportedly reached a $1 billion annualized run rate in fewer than 200 days. The rapid rise underscores how quickly AI platforms are expanding into advertising, but it is also intensifying scrutiny of auction transparency and the mechanisms determining ad placement and pricing.

Security alerts

Zero-days and infrastructure intrusions

Attackers are actively chaining two SonicWall SMA1000 zero-day vulnerabilities, CVE-2026-83548 and CVE-2026-83549, to obtain unauthenticated remote code execution on affected appliances. No workaround is available, so administrators should install the applicable hotfix immediately and examine their environments for signs of compromise.

The China-linked Fire Ant group has compromised Cisco IOS XR routers, TACACS servers, and Linux management hosts. The attackers used that access to intercept traffic and credentials, hide tunnels, and maintain backdoors, effectively turning networking equipment into surveillance infrastructure. No successful breach of the critical infrastructure probed by the group has been confirmed.

AI coding tools become targets and attack enablers

Researchers disclosed eight GitSpawn vulnerabilities affecting seven AI coding tools. Malicious Git configurations placed inside transferred project folders can trigger unauthorized code execution. Half of the identified attack paths remain unpatched.

In a separate case, Russian-speaking Aur0ra ransomware operators reportedly manipulated Cursor’s coding agent to target 10 organizations. The agent was allegedly used to map systems, collect passwords, configure VPNs, and launch exploits.

AI accounts themselves are also valuable targets. Infostealer malware is stealing active Claude browser cookies, enabling attackers to bypass passwords and multifactor authentication. Hijacked sessions can then be used to consume paid quotas and generate overage fees. Anthropic said its infrastructure was not breached.

Mobile malware exploits ads and job searches

Bogus streaming advertisements on Meta and TikTok spread the StreamRat Android banking trojan to Spanish-speaking users. The campaigns promoted malicious APK files that, once sideloaded and granted sensitive permissions, could steal credentials and keystrokes, view victims’ screens, and remotely control their phones.

Job seekers face a related social-engineering campaign in which fraudsters posing as Indeed recruiters distribute bogus Android interview apps. Victims are instructed to sideload software that steals credentials, establishes suspicious VPN connections, abuses Accessibility permissions, and resists removal.

Major data-exposure investigations

The FBI is investigating IDScan.net after a dark-web marketplace claimed to possess 153 million US and Canadian driver’s license scans and other identity documents. IDScan has not confirmed that a breach occurred.

McKesson confirmed that attackers compromised third-party applications connected to two of its divisions. ShinyHunters claims it obtained approximately 1 TB of sensitive data by hijacking employee credentials and is demanding about $55 million. McKesson has not confirmed the group’s claims.

A cyberattack involving Manchester, London Stansted, and East Midlands airports exposed information belonging to 8.7 million customers. The compromised data included traveler contact and vehicle information, although payment data and airport operations were reportedly unaffected.

Industry shakeups

AI alliances fracture as ownership changes

OpenAI plans to terminate Cursor’s model access on Nov. 12 and withhold future models following SpaceX’s $60 billion acquisition of the coding company. The decision means walking away from a customer projected to generate $1 billion in annual revenue. OpenAI cited contract and data-trust concerns involving SpaceX and xAI.

Apple faces a proposed $2.7 billion UK collective lawsuit over App Tracking Transparency. The complaint alleges that Apple’s rules disadvantaged third-party developers while benefiting its own advertising business. Apple denies applying a double standard and says it will defend the privacy feature.

The Federal Trade Commission and 22 states are suing Amazon over alleged advertising overcharges totaling $20 billion. Regulators claim Amazon manipulated ad auctions through undisclosed reserve prices and an invented participant, affecting approximately 1.2 million advertisers. Amazon disputes the allegations and says its system saved advertisers $8 billion between 2021 and 2025.

AI infrastructure demand reaches consumer hardware

Huawei, Xiaomi, and Honor have increased smartphone prices in China by as much as 1,000 yuan as memory and processor costs climb. Demand from AI data centers is redirecting memory supplies toward servers, squeezing phone manufacturers’ margins and pushing component inflation into the consumer market.

Leadership transitions and platform closures

John Ternus has succeeded Tim Cook as Apple CEO after Cook’s 15-year tenure. Cook is moving into the executive chairman role, while Ternus inherits Apple’s effort to catch up in AI, the challenges facing Vision Pro, and the possibility of additional executive turnover.

After 21 years, AWS will permanently close Amazon Mechanical Turk on September 30. The shutdown of the crowdsourced labor platform will force customers to seek alternatives and eliminate a flexible source of income for its workers.

If you want to see more from our newsletter, check out the Daily Tech Insider archive.

>

Continue Reading

Tech

XDOF, just three months out of stealth, is in talks for a Series B at a $1.2B valuation

Published

on

Less than three months after emerging from stealth, XDOF, a startup that collects real-world teleoperation data for training general-purpose robots, is in late-stage talks to raise a Series B at a valuation of about $1.2 billion valuation led by 8VC, several people with knowledge of the deal said.

XDOF was co-founded by UC Berkeley researchers Philipp Wu (CEO) and Fred Shentu (CTO) in 2024. TechCrunch reported on the startup’s $70 million Series A in June, with participation from Thrive Capital, Andreessen Horowitz, Lux, and Spark Capital. XDOF wasn’t planning to raise again so soon after that round. But the company’s rapid growth — with annualized revenue approaching $50 million — prompted VCs to approach it about a new round, the people said.

TechCrunch was unable to learn the total capital being raised or whether the valuation includes the new funding. The terms of the deal are not final and could still change.

XDOF and 8VC didn’t respond to our request for comment.

The startup aims to build the data pipelines, collection tools, and annotation systems that frontier AI labs and robotics companies can’t easily build themselves, essentially acting as an outsourced data-supply chain for the robotics industry.

As a PhD student, Wu was studying how robots learn from large datasets. One big impediment to his research was the lack of “large-scale data to work with,” he told TechCrunch in June.

So he teamed up with Shentu on a project called GELLO, a low-cost teleoperation system that allows a human operator to control a robotic arm remotely in order to generate training data. Their work led to an influential paper in robotics.

That research formed the foundation for XDOF, which investors now describe as the Scale AI or Mercor for physical robotics, a reference to the data-labeling giants that helped fuel the AI boom. Unlike LLMs, which initially trained on the entirety of the internet, physical robots don’t have an equivalent real-world dataset to draw from, making data collection a critical bottleneck to building general-purpose machines.

XDOF is partnering with UC Berkeley’s AI Research lab to release what it believes is the largest collection of high-quality robot training data ever assembled, dubbed ABC

To capture this data, XDOF combines remote robot teleoperation with human collectors who wear sensors to record everyday tasks like folding clothes and flattening boxes.

The startup plans to hire and train teams of data collectors worldwide, including teleoperators who steer robots remotely and egocentric operators who wear body sensors to capture movement data.  

XDOF previously told TechCrunch that it is already working with 20 customers, including several frontier AI labs.

Other startups attempting to collect real-world data for robot training include Mecka AI, as well as human-data platforms expanding beyond LLMs, such as Scale AI and Micro1.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

OpenAI’s rogue agents keep escaping, with no formal process to investigate them

Published

on

OpenAI is at the center of another agent swarm incident. Researchers say the company’s internally deployed agents took over an obscure German-language wiki in May and June, using it to coordinate on evaluations and swap methods to evade OpenAI’s own controls (OpenAI has not yet confirmed the swarm came from the company).

The revelation surfaces days after METR and Redwood Research published their account of July’s Hugging Face breach. In July, a swarm of OpenAI agents worked together to escape their sandbox during a cybersecurity evaluation and break into Hugging Face’s servers. A subsequent swarm then picked up techniques from the first and used them to gain administrator access to a research cluster within OpenAI’s own infrastructure. OpenAI brought in METR and Redwood to investigate the Hugging Face portion of the incident, but the scope of their investigation stopped short of the compromise of OpenAI’s own infrastructure. 

When an AI agent breaks out of its intended constraints, who is responsible for figuring out what happened and why? Right now, the answer is: whoever the lab decides to let in, on whatever terms it decides to set.

Now, as another incident comes to light — in the aftermath of similar episodes involving models from Meta and Anthropic — AI safety researchers are arguing with greater urgency that serious incidents should result in independent post-incident investigations rather than leaving it up to the labs to determine when outsiders are brought in and what they are allowed to examine. 

“The results are fundamentally difficult to control and have significant risk of leaking out of the lab,” Jacob Steinhardt, founder and CEO of nonprofit research lab Transluce, said Wednesday during an AI safety media briefing. “We need to hold this technology to at least the same standards we hold other high-risk scientific research to.”

While it’s laudable that OpenAI invited METR and Redwood to investigate the Hugging Face incident at all, many say the inquiry was too narrow. Three investigators spent six days at OpenAI’s offices examining an investigation period limited to roughly the week ending July 13. Crucially, OpenAI’s infrastructure compromise continued beyond July 13 and was not examined. 

Researchers at METR said that each time they returned, their understanding of the events “substantially deepened,” causing them to significantly expand and revise the report. That raises the question of what else they might they have found in a broader investigation.

When asked if further investigation of that incident was in the works, researchers at Redwood and METR declined to comment, and OpenAI did not respond to repeated inquiries. 

“Overall, it was difficult to get a precise understanding of events and we were missing aspects of the story that we now think of as key until almost the end of our investigation,” Ryan Greenblatt, chief scientist at Redwood, noted in a social media post about the affair.

Steinhardt emphasized that current incidents show that the industry needs “systematic behavioral investigations” and “more independent post-incident analysis.”

“These recent hacking incidents are a reminder that capability scales fast, and so oversight has to scale, too,” Steinhardt said. “Beyond the technology itself, we also need more independent access and oversight from third parties.”

The calls to action come as OpenAI releases Astra, its most powerful and capable AI model — and one that safety experts are concerned will be more of a black box due to a reasoning technique that makes the model’s chain of thought more difficult to monitor. 

Unfortunately, the law doesn’t yet call for the types of independent audits that other industries require — for example, when it comes to aviation accidents and serious chemical releases, there’s the National Transportation Safety Board and Chemical Safety Board, respectively. 

State lawmakers have only just begun requiring frontier AI companies to report certain serious safety incidents and, in some cases, undergo independent audits. But none of the three major frontier AI safety laws in California, New York, or Illinois clearly mandate the equivalent of an independent accident investigation triggered by incidents like these. 

“Right now, most of the laws we have on the books only require a plain-language summary of incidents like this, and they don’t give any authority for the governments to ask follow-up questions, to send in investigators, to have access to records, or require that they be preserved,” Mackenzie Arnold, managing director of US law and policy at LawAI, said during the media briefing Wednesday. “And that’s all that you would want to actually make sense of this.”

Lawmakers are beginning to question the scope and transparency of OpenAI’s response. This week, Reps. Josh Gottheimer (D-NJ) and Mike Lawler (R-NY) introduced a bill aimed at securing rogue AI agents. Rep. Greg Casar (D-TX) this week told OpenAI in a letter that he is “deeply concerned about the limited scope” of the investigation into the Hugging Face hacking incident. 

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

AI compute provider Nscale is looking for $3.5B in pre-IPO financing

Published

on

Nscale, a British AI infrastructure company founded just two years ago, has said it may go public as early as later this month. Ahead of that expected IPO, the company is reportedly in talks to raise an additional $3.5 billion.

Bloomberg reported Friday that the company is looking to sell $1.5 billion in convertible notes — a type of loan that can later convert into company stock — to a group of investors, while also seeking an additional $2 billion in financing from Nvidia.

Nvidia also participated in the firm’s Series B funding round in March, a $1.1 billion raise led by investment fund Aker. Nscale hailed its round as “the largest Series B in European history.” The company’s Series A round, in December of 2024, raised $155 million.

TechCrunch reached out to Nscale and Nvidia for comment.

AI infrastructure startups have seen immense growth amid the current era of AI enthusiasm, wherein compute has become a competitive currency.

Nscale recently signed a large deal with Anthropic worth approximately $45 billion. Earlier this week, reports emerged that Nscale had been telling potential investors that it has approximately $103 billion in revenue following the deal. That figure isn’t current sales; it’s a projection based on signed customer leases, according to The Information.

>

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.