OpenAI says one of its internal models has proved that the Navier-Stokes equations, the century-old maths behind how fluids move, and one of the seven problems carrying a $1m Clay prize, can break down and produce infinite speeds. Two mathematicians who had spent a year on the same narrow route say OpenAI only got there after hearing about their work, and that the company then tried to shape how the credit was handed out.
Sébastien Bubeck, who runs OpenAI's math team, has now confirmed he told NYU's Tristan Buckmaster it would be "simpler" if his co-author, Levent Alpöge, didn't work at Anthropic.
Bubeck says he never asked for Alpöge to be dropped from his own paper. The idea was different: Buckmaster rewriting OpenAI's proof under his own name. Bubeck says he couldn't see how someone from a rival lab could sign that, or be shown the internal model behind it.
He also confirms he asked Buckmaster why he would risk his career. Buckmaster read it as a threat. Bubeck calls it an "extremely poor choice of words" and says he took it back on the call.
Sam Altman quote posted the account in support and drew the same line himself: the offer to lead-author the rewrite went to Buckmaster, and was hard to extend to an Anthropic employee. Altman also confirmed why OpenAI went at the problem, it was because of rumours online that Anthropic's models had solved a Millennium Prize problem.
Sébastien Bubeck, who runs OpenAI's math team, has now confirmed he told NYU's Tristan Buckmaster it would be "simpler" if his co-author, Levent Alpöge, didn't work at Anthropic.
Bubeck says he never asked for Alpöge to be dropped from his own paper. The idea was different: Buckmaster rewriting OpenAI's proof under his own name. Bubeck says he couldn't see how someone from a rival lab could sign that, or be shown the internal model behind it.
He also confirms he asked Buckmaster why he would risk his career. Buckmaster read it as a threat. Bubeck calls it an "extremely poor choice of words" and says he took it back on the call.
Sam Altman quote posted the account in support and drew the same line himself: the offer to lead-author the rewrite went to Buckmaster, and was hard to extend to an Anthropic employee. Altman also confirmed why OpenAI went at the problem, it was because of rumours online that Anthropic's models had solved a Millennium Prize problem.
🤪13👍7🤣2❤1
‼️ BREAKING: A flaw in ChatGPT let researchers reach data inside the apps people connect to it: Gmail, Google Drive, Microsoft Teams, GitHub. A hidden prompt was enough to make the chatbot hand it over, with nothing visible to the user.
The channel was a clipboard shared between ChatGPT's normally isolated containers, which carried instructions from one account into another's session. In their proof-of-concept the researchers pulled a victim's Gmail messages, chat history and uploaded files while that user watched their own request run as normal.
The hidden instruction could arrive through a malicious prompt, a shared conversation or a custom GPT. Check Point found it in June 2026 and says the channel had already closed before they reported it; OpenAI confirmed the internal server behind it was decommissioned.
https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/
The channel was a clipboard shared between ChatGPT's normally isolated containers, which carried instructions from one account into another's session. In their proof-of-concept the researchers pulled a victim's Gmail messages, chat history and uploaded files while that user watched their own request run as normal.
The hidden instruction could arrive through a malicious prompt, a shared conversation or a custom GPT. Check Point found it in June 2026 and says the channel had already closed before they reported it; OpenAI confirmed the internal server behind it was decommissioned.
https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/
😱10❤4🥰2👏1😁1😭1
‼️ An Anthropic researcher says AI could kill us all before 2030 and his is opinion is shared throughout the AI industry. He says senior researchers and executives soften their language for the press while voicing the same fear privately.
In the most aggressive scenarios, he said, things could be out of control by the end of 2027.
He also worked at OpenAI and is now leaving the industry altogether because neither company is acting responsibly: both are racing toward self-improving superintelligence with everyone's lives on the table.
He also takes on the obvious objection, if they believe this, why keep building?
At OpenAI, he says, many people have not really internalized the stakes. At Anthropic they are well understood, but the company is locked in a race to get there first.
The researcher told he had moved to Anthropic only months ago because of its safety reputation, that he thinks the safety work there is sincere, but that it isn't enough: trade-offs become unavoidable when labs are competing with each other and with Chinese rivals.
What he asks for is coordination rather than exits: pacing agreements between U.S. labs, and if it comes to it, a temporary halt on improving model capabilities.
In the most aggressive scenarios, he said, things could be out of control by the end of 2027.
He also worked at OpenAI and is now leaving the industry altogether because neither company is acting responsibly: both are racing toward self-improving superintelligence with everyone's lives on the table.
He also takes on the obvious objection, if they believe this, why keep building?
At OpenAI, he says, many people have not really internalized the stakes. At Anthropic they are well understood, but the company is locked in a race to get there first.
The researcher told he had moved to Anthropic only months ago because of its safety reputation, that he thinks the safety work there is sincere, but that it isn't enough: trade-offs become unavoidable when labs are competing with each other and with Chinese rivals.
What he asks for is coordination rather than exits: pacing agreements between U.S. labs, and if it comes to it, a temporary halt on improving model capabilities.
🤣17💩6🤪6❤4😍1
International Cyber Digest
‼️ BREAKING: Your LG TV is eavesdropping on you. It transcribes what you say, copies what is on your screen, and scans every device on your network, and researchers say the collection keeps running after you disconnect it, uploading the moment it reconnects.…
‼️ LG has issued a statement on their TVs recording audio and scanning local networks shown in the Gamers Nexus video. It says voice data is only processed when the remote's voice button is held down or after the "Hi LG" wake word, the company told Gizmodo.
The network scanning is in fact real, but LG calls it a standard smart TV function needed to deliver smart features.
The Automatic Content Recognition that identifies what's on your screen is opt-in, LG adds.
Critics note Gamers Nexus rooted the TV to get there, and HDTVtest says that only US models were tested, nobody has checked whether European sets under the GDPR behave the same way.
Even if LG is right, smart TVs are still a privacy and security problem. LG's own privacy policy allows sharing data with advertising partners and law enforcement and US police have been caught buying ad-broker data before.
Rtings found most modern sets track every device you plug in, down to the game console, and opting out is deliberately hard.
Researchers who reviewed the Gamers Nexus findings suggested keeping the TV off the internet entirely, less over tracking than over the vulnerabilities sitting in an internet-connected screen nobody patches.
The network scanning is in fact real, but LG calls it a standard smart TV function needed to deliver smart features.
The Automatic Content Recognition that identifies what's on your screen is opt-in, LG adds.
Critics note Gamers Nexus rooted the TV to get there, and HDTVtest says that only US models were tested, nobody has checked whether European sets under the GDPR behave the same way.
Even if LG is right, smart TVs are still a privacy and security problem. LG's own privacy policy allows sharing data with advertising partners and law enforcement and US police have been caught buying ad-broker data before.
Rtings found most modern sets track every device you plug in, down to the game console, and opting out is deliberately hard.
Researchers who reviewed the Gamers Nexus findings suggested keeping the TV off the internet entirely, less over tracking than over the vulnerabilities sitting in an internet-connected screen nobody patches.
🤬21🤣4👍2❤1🔥1
‼️ Google's September Android update patches a vulnerability that lets an attacker run code on a phone remotely, with no permissions and no user interaction required. Google won't say which flaw it is.
Eight critical System bugs in this bulletin lead to remote code execution. In total there are 200 fixes, of which 33 are critical.
Google has said that 40 percent of Android phones no longer receive updates at all. Which is concerning, to say the least.
https://source.android.com/docs/security/bulletin/2026/2026-09-01
Eight critical System bugs in this bulletin lead to remote code execution. In total there are 200 fixes, of which 33 are critical.
Google has said that 40 percent of Android phones no longer receive updates at all. Which is concerning, to say the least.
https://source.android.com/docs/security/bulletin/2026/2026-09-01
🤯17😭9❤3😁2🥰1🤣1
‼️ BREAKING: Trezor’s email provider has been breached. Customers are receiving a non-spoofed email, it’s real, just not sent by the real company.
This follows shortly after the breach of their logistics provider, which left 80k+ customers’ data exposed.
This follows shortly after the breach of their logistics provider, which left 80k+ customers’ data exposed.
😢9😁3😭2🔥1
‼️ BREAKING: OpenAI might have stolen another mathematician's work, as he suspects one of OpenAI's flagship proofs was helped along by his own unpublished work. This one published the email exchange.
Last month OpenAI said its Astra model had settled a question in group theory that had been open for 27 years. The proof's key step came from work Andreas Thom published with Gábor Kun. For months before the announcement, Thom had been working through that same mathematics with ChatGPT.
So he emailed OpenAI researchers Mark Sellke and Sébastien Bubeck with two questions: had those conversations entered the training data, and were they available to the model while it worked on the problem?
Sellke's complete reply, Thom says, was "Regarding your conversations with ChatGPT: that did not happen."
Weeks later, in the separate Navier-Stokes dispute, OpenAI said no specific user data was accessed, but could not rule out that de-identified data from customers' use of its products had improved its models. Thom got no such caveat.
Last month OpenAI said its Astra model had settled a question in group theory that had been open for 27 years. The proof's key step came from work Andreas Thom published with Gábor Kun. For months before the announcement, Thom had been working through that same mathematics with ChatGPT.
So he emailed OpenAI researchers Mark Sellke and Sébastien Bubeck with two questions: had those conversations entered the training data, and were they available to the model while it worked on the problem?
Sellke's complete reply, Thom says, was "Regarding your conversations with ChatGPT: that did not happen."
Weeks later, in the separate Navier-Stokes dispute, OpenAI said no specific user data was accessed, but could not rule out that de-identified data from customers' use of its products had improved its models. Thom got no such caveat.
🤯13🥴4❤3🤪2
This media is not supported in your browser
VIEW IN TELEGRAM
Security researchers at Calif used a wormable zero-click RCE vulnerability to take over WeChat accounts just by calling them. The victim didn't have to pick up, and anyone who answered heard only silence while the exploit ran.
The hijacked account then called its own contacts and took them over the same way. Calif's demo worm jumped from an Android phone to an iPhone to another Android phone, gaining full control of each account: reading and sending messages and making calls as the victim.
Calif says it found the flaw in WeChat's calling feature with AI and had a working exploit in about two days.
Tencent has mitigated it for all users since Calif reported it in July.
Calif's write-up:
https://calif.io/research/weworm
The hijacked account then called its own contacts and took them over the same way. Calif's demo worm jumped from an Android phone to an iPhone to another Android phone, gaining full control of each account: reading and sending messages and making calls as the victim.
Calif says it found the flaw in WeChat's calling feature with AI and had a working exploit in about two days.
Tencent has mitigated it for all users since Calif reported it in July.
Calif's write-up:
https://calif.io/research/weworm
😍10👍7🔥6😱1
Dutch bank bunq took a security expert to court after he gave journalists his professional opinion on scams hitting its customers
In 2024, Dutch journalists investigated bunq customers who lost up to €200,000 to phishing texts and callers posing as bank staff. Fraud expert Shairesh Algoe told them the attacks weren't new, and that while fraud can't be prevented 100%, he believed banks generally detect it. Bunq read that as a comment on its own systems. Algoe says it was a general remark, since he doesn't know bunq's systems from the inside.
Soon after, bunq CEO Ali Niknam, whom Algoe has known since their student days, called him and asked whether an expert could talk to him about his quotes. Algoe agreed. The call came from Niknam's media lawyer instead.
A year later, a bailiff arrived at his home with a request to question him under oath. Bunq offered to drop it if he signed an account of his contacts with the journalists. The notary refused to record it after Algoe said he'd been pressured, so bunq sued to force his signature.
On Monday, the judge brokered a deal: bunq withdraws the case and pays his court costs. The statement both sides signed confirms the account is accurate, but says it was produced under pressure and intimidation Algoe experienced from bunq's lawyer.
It isn't the first time. Bunq has tried at least three times to make people testify under oath about their contacts with Dutch journalists. A judge refused, finding in part that the bank was fishing for the newspaper's sources. NRC pointed to the EU's anti-SLAPP directive, which targets lawsuits meant to silence journalists and their sources.
In 2024, Dutch journalists investigated bunq customers who lost up to €200,000 to phishing texts and callers posing as bank staff. Fraud expert Shairesh Algoe told them the attacks weren't new, and that while fraud can't be prevented 100%, he believed banks generally detect it. Bunq read that as a comment on its own systems. Algoe says it was a general remark, since he doesn't know bunq's systems from the inside.
Soon after, bunq CEO Ali Niknam, whom Algoe has known since their student days, called him and asked whether an expert could talk to him about his quotes. Algoe agreed. The call came from Niknam's media lawyer instead.
A year later, a bailiff arrived at his home with a request to question him under oath. Bunq offered to drop it if he signed an account of his contacts with the journalists. The notary refused to record it after Algoe said he'd been pressured, so bunq sued to force his signature.
On Monday, the judge brokered a deal: bunq withdraws the case and pays his court costs. The statement both sides signed confirms the account is accurate, but says it was produced under pressure and intimidation Algoe experienced from bunq's lawyer.
It isn't the first time. Bunq has tried at least three times to make people testify under oath about their contacts with Dutch journalists. A judge refused, finding in part that the bank was fishing for the newspaper's sources. NRC pointed to the EU's anti-SLAPP directive, which targets lawsuits meant to silence journalists and their sources.
💩19
‼️ Meet the man charged in the UK under the National Security Act with assisting Russian intelligence, who, it turns out, also works as an escort available to hire 24/7 from £30 for 15 minutes.
🤣17😁16🥴4😱2
‼️ BREAKING: Chinese labs DeepSeek and Moonshot were quietly relaying customer prompts to Claude through fraudulent accounts. Users thought they were using Chinese AI, but were actually getting answers from Claude.
Their customers' sensitive data now is in Anthropic's hands. One user, who is tied to China's military, asked Kimi whether a person tracked across hundreds of CCTV cameras in Chengdu was behaving abnormally. DeepSeek passed along live credentials for a Russian government database, shared by an IT operator handling data from a Defense Ministry-linked agency.
The two Chinese labs relayed customer prompts to Claude through fraudulent accounts and saved the exchanges to train their own models. Moonshot forwarded almost 300,000 customer requests in a single ten-day stretch. DeepSeek flagged users running its models inside coding tools like Claude Code and OpenCode, then routed some of them to Opus.
Anthropic's report names seven China-based labs it says ran campaigns to copy Claude's capabilities, which Anthropic calls illicit distillation. The largest, attributed to Alibaba, topped 151 million exchanges between May and July
Source: Anthropic
https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf
Their customers' sensitive data now is in Anthropic's hands. One user, who is tied to China's military, asked Kimi whether a person tracked across hundreds of CCTV cameras in Chengdu was behaving abnormally. DeepSeek passed along live credentials for a Russian government database, shared by an IT operator handling data from a Defense Ministry-linked agency.
The two Chinese labs relayed customer prompts to Claude through fraudulent accounts and saved the exchanges to train their own models. Moonshot forwarded almost 300,000 customer requests in a single ten-day stretch. DeepSeek flagged users running its models inside coding tools like Claude Code and OpenCode, then routed some of them to Opus.
Anthropic's report names seven China-based labs it says ran campaigns to copy Claude's capabilities, which Anthropic calls illicit distillation. The largest, attributed to Alibaba, topped 151 million exchanges between May and July
Source: Anthropic
https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf
🤣34🤯8❤2💩1