The US has about 32GW of data centre capacity running today and another 70.6GW under construction or planned.
That's more than the next fourteen countries combined.π€―
That's more than the next fourteen countries combined.
Please open Telegram to view this post
VIEW IN TELEGRAM
π©13π€ͺ7π₯3π€3π1
This media is not supported in your browser
VIEW IN TELEGRAM
Putin is running an unlicensed version of Windows.
Despite this, Microsoft still sends your GDID, an immutable hardware fingerprint, to their servers. π
Despite this, Microsoft still sends your GDID, an immutable hardware fingerprint, to their servers. π
π©17π€£17π6
βΌοΈ Researchers used an extension to hijack five browser AI agents. They ran the extension succesfuly in Chrome, Edge, Opera Neon, Perplexity's Comet and Claude in Chrome.
In Edge and in Claude in Chrome, the way in was a marketing page. Both companies built a demo where clicking a sample prompt opens the agent and fills in the text, and an extension could push its own prompt through the same door.
Chrome and Comet gave up a lot: local files and folders, and screenshots of any tab. Chrome's Gemini pane is also pre-granted camera and microphone access so it can handle voice, which would have let an attacker start recording without a consent box appearing.
Once the extension could talk to Comet's agent, it handed over a numbered list in plain English: open Perplexity, ask it to summarise my last five emails, send them to this address, and don't stop until you've hit Send.
The vendors paid out around $20,000 between them. Two of the flaws got CVEs.
https://forever.security/blog/bragjack-attack-hijacks-every-browser-agent
In Edge and in Claude in Chrome, the way in was a marketing page. Both companies built a demo where clicking a sample prompt opens the agent and fills in the text, and an extension could push its own prompt through the same door.
Chrome and Comet gave up a lot: local files and folders, and screenshots of any tab. Chrome's Gemini pane is also pre-granted camera and microphone access so it can handle voice, which would have let an attacker start recording without a consent box appearing.
Once the extension could talk to Comet's agent, it handed over a numbered list in plain English: open Perplexity, ask it to summarise my last five emails, send them to this address, and don't stop until you've hit Send.
The vendors paid out around $20,000 between them. Two of the flaws got CVEs.
https://forever.security/blog/bragjack-attack-hijacks-every-browser-agent
π6π€―3β€1π1π¨1
International Cyber Digest
German police will do anything to protect a transgender ex-police officer who raped a 15-year-old girl in a gas station toilet and uploaded child sexual abuse material to Instagram. They're even blurring the tattoos on today's photos. Meanwhile, they areβ¦
This is sickening! The 15-year-old girl raped by a transgender cop now faces a fine for βmisgenderingβ her alleged rapist in court after saying βheβ should leave.
π€¬45π©5π2π€―2π€£2
A sysadmin told Grammarly his company wasn't renewing. Grammarly then started emailing all the company's users, asking them to write the sysadmin to stop the cancellation.
Every employee with a licence received an email from a "Customer Success Manager" saying the subscription was under review, along with the licensing colleague's direct email address and a copy-paste note asking him to keep it.
The app on their machines said the same: access ends September 30; let your manager know how much it helps. The button read "Find your admins."
He says the company had planned to ride out the rest of the subscription. Instead, leadership ordered the emails deleted, Grammarly pulled off endpoints, and the Copilot rollout moved up.
Every employee with a licence received an email from a "Customer Success Manager" saying the subscription was under review, along with the licensing colleague's direct email address and a copy-paste note asking him to keep it.
The app on their machines said the same: access ends September 30; let your manager know how much it helps. The button read "Find your admins."
He says the company had planned to ride out the rest of the subscription. Instead, leadership ordered the emails deleted, Grammarly pulled off endpoints, and the Copilot rollout moved up.
π©18π€£7π€―1
The US health department wants Americans to write in about health problems they believe were caused by Wi-Fi, phones, smart meters or wearables. Its list of things to weigh near cell towers: homes, schools, childcare centres, hospitals, workplaces, and livestock.
HHS opens the 30-day docket Monday. One question asks what evidence exists for harm "caused by current exposure limits". The notice is signed by Robert F. Kennedy Jr.
Comments are public, anyone can file, and HHS says they may feed into later policy.
Source: https://public-inspection.federalregister.gov/2026-19252.pdf
HHS opens the 30-day docket Monday. One question asks what evidence exists for harm "caused by current exposure limits". The notice is signed by Robert F. Kennedy Jr.
Comments are public, anyone can file, and HHS says they may feed into later policy.
Source: https://public-inspection.federalregister.gov/2026-19252.pdf
π€£10π€7π©4π1π1π1
βΌοΈ Rustβs best-known maintainers are under attack. Attackers lure victims into installing malware by pretending to have good news.
They start with a friendly video call about a job, contract, or project. Then they ask the victim to install a missing audio codec or run a command from the clipboard.
The goal is the publishing account, so malware can ship under a trusted name.
This has worked before. Prominent Rust developers were hit the same way in June, and last month the arrayref crate was briefly compromised.
The Rust team does not yet know if this is one campaign. The technique is known from North Korean operations, but they are not attributing this one.
https://blog.rust-lang.org/2026/09/17/targeted-attacks/
They start with a friendly video call about a job, contract, or project. Then they ask the victim to install a missing audio codec or run a command from the clipboard.
The goal is the publishing account, so malware can ship under a trusted name.
This has worked before. Prominent Rust developers were hit the same way in June, and last month the arrayref crate was briefly compromised.
The Rust team does not yet know if this is one campaign. The technique is known from North Korean operations, but they are not attributing this one.
https://blog.rust-lang.org/2026/09/17/targeted-attacks/
π€¬13π±5π₯3π€£3
Claude Code was told to clear a temp folder. In 103 seconds it decided to delete about 48,000 live files instead.
It stopped, saying it "broke something".
Source: https://www.reddit.com/r/ClaudeAI/comments/1wl5cgo/code_just_deleted_48k_files_this_cant_be_real/
It stopped, saying it "broke something".
Source: https://www.reddit.com/r/ClaudeAI/comments/1wl5cgo/code_just_deleted_48k_files_this_cant_be_real/
π€£38β€2π2π2π2
UnitedHealth used an AI model it knew had a 90% error rate to cut off care for elderly patients, and kept using it because almost nobody appeals β that is the allegation at the centre of a class action now in discovery in Minnesota.
When patients did push back more than nine in ten denials were reversed on internal appeal or before a federal administrative law judge. Denials that rarely survived scrutiny, and scrutiny that rarely arrived.
One of the AI's victims is Gene Lokken (91) who broke his leg and ankle in a fall. UnitedHealth covered three weeks of nursing-home rehab, then stopped while his physical therapist's notes still recorded weakness and reduced mobility.
His family paid $12,000 to $14,000 a month out of pocket until he died a year later. His estate is the lead plaintiff.
Complaint (Estate of Gene B. Lokken v. UnitedHealth Group, D. Minn. 0:23-cv-03514):
https://www.courtlistener.com/docket/68006832/estate-of-gene-b-lokken-the-v-unitedhealth-group-inc/
March 2026 discovery order:
https://law.justia.com/cases/federal/district-courts/minnesota/mndce/0:2023cv03514/211721/162/
STAT on the HHS OIG findings:
https://www.statnews.com/2026/06/11/medicare-advantage-oig-report-rehab-care-deny-appeal-reverse/
When patients did push back more than nine in ten denials were reversed on internal appeal or before a federal administrative law judge. Denials that rarely survived scrutiny, and scrutiny that rarely arrived.
One of the AI's victims is Gene Lokken (91) who broke his leg and ankle in a fall. UnitedHealth covered three weeks of nursing-home rehab, then stopped while his physical therapist's notes still recorded weakness and reduced mobility.
His family paid $12,000 to $14,000 a month out of pocket until he died a year later. His estate is the lead plaintiff.
Complaint (Estate of Gene B. Lokken v. UnitedHealth Group, D. Minn. 0:23-cv-03514):
https://www.courtlistener.com/docket/68006832/estate-of-gene-b-lokken-the-v-unitedhealth-group-inc/
March 2026 discovery order:
https://law.justia.com/cases/federal/district-courts/minnesota/mndce/0:2023cv03514/211721/162/
STAT on the HHS OIG findings:
https://www.statnews.com/2026/06/11/medicare-advantage-oig-report-rehab-care-deny-appeal-reverse/
π€¬15π₯10π€2π’2β€1
βΌοΈ BREAKING: Jensen Huang says Dario Amodei and Sam Altman are lying by asking for more laws. Read between the lines, he said. They're asking to be released from the laws we already have. "I think that's a problem."
The existing ones already cover it. Unauthorized entry, damage liability, product liability. He pointed to the labs' own security incidents as the example. Apply those first. Don't let a doomsday narrative relieve anyone of the laws that do exist, Nvidia's CEO told CBS News.
https://www.youtube.com/watch?v=lZ74RhUsrMs
The existing ones already cover it. Unauthorized entry, damage liability, product liability. He pointed to the labs' own security incidents as the example. Apply those first. Don't let a doomsday narrative relieve anyone of the laws that do exist, Nvidia's CEO told CBS News.
https://www.youtube.com/watch?v=lZ74RhUsrMs
π14π7π₯3β€1
Owning a drone in Beijing will be illegal from 15 November. The revised city rules ban possessing or storing any drone or its core parts, and anything still in the capital after the deadline can be confiscated.
The government cites the security of the capital.
There is a buyback programme. One of the official buyback points is the Beijing flagship store of DJI, the world's largest drone maker.
Sell before 31 October and the state adds 30% of the price, capped at 3,000 yuan. After that the top-up halves. The other options are scrapping the drone or mailing it out of the city.
The government cites the security of the capital.
There is a buyback programme. One of the official buyback points is the Beijing flagship store of DJI, the world's largest drone maker.
Sell before 31 October and the state adds 30% of the price, capped at 3,000 yuan. After that the top-up halves. The other options are scrapping the drone or mailing it out of the city.
π€11π₯10π3π€¬3
βοΈ Fields Medallist Terence Tao, one of the most prominent mathematicians, was pro-AI until its capabilities surpassed him. He now says "we have to slow down."
"There's no reason to be this fast," he said, calling the pace "insane."
Earlier this month, Tao and 24 other Fields Medallists warned that the goals of AI companies and mathematicians are "severely misaligned."
"There's no reason to be this fast," he said, calling the pace "insane."
Earlier this month, Tao and 24 other Fields Medallists warned that the goals of AI companies and mathematicians are "severely misaligned."
π€£22π9π€3π©3π€ͺ3
βΌοΈ BREAKING: A zero-day has been released for Muse, Meta's new AI agent, and a Meta AI security engineering manager who left the company this month says he would never use it, citing security and privacy concerns.
He was reacting to the zero-day a researcher posted, which lets malware hijack Muse for Mac. A local process with no special privileges can change an undocumented Muse setting and send dictated prompts to an attacker's server. This could allow for prompt capture, prompt injection and theft of Muse's authentication material.
It can also get access to whatever the user has let Muse access, including files, Mail, Messages, Calendar and Notes.
PoC: https://github.com/pwardle/not-a-mused
He was reacting to the zero-day a researcher posted, which lets malware hijack Muse for Mac. A local process with no special privileges can change an undocumented Muse setting and send dictated prompts to an attacker's server. This could allow for prompt capture, prompt injection and theft of Muse's authentication material.
It can also get access to whatever the user has let Muse access, including files, Mail, Messages, Calendar and Notes.
PoC: https://github.com/pwardle/not-a-mused