Codex Now Available in ChatGPT Mobile App
Codex 现已集成到 ChatGPT 移动应用
⭐️ 10.0/10

OpenAI has integrated Codex, its AI coding agent, directly into the ChatGPT mobile app, allowing users to write and debug code from their phones. This move makes advanced AI-assisted coding accessible anytime, anywhere, significantly lowering the barrier for developers and non-developers to generate code via mobile devices. Codex is included in ChatGPT's free plan, though interactions may be used for training. It supports voice dictation and can be used via desktop app or CLI as well.

rss · Sam Altman(@sama) · May 14, 21:16

Background: Codex is an AI coding agent released by OpenAI in April 2025, designed for software engineering tasks like writing code and fixing bugs. It runs locally via CLI or in the cloud through ChatGPT, and is available as a macOS/Windows desktop app and IDE integrations.

References

Discussion: Community reactions are mixed: some praise the mobile integration for enabling 'vibe coding' on the go, while others report less effective results compared to using a keyboard and desktop setup, citing smaller screens and lack of precise control.

Tags: #Codex, #ChatGPT, #Mobile App, #OpenAI, #AI Coding


0-click exploit chain for Pixel 10 disclosed
Pixel 10 零点击漏洞链披露
⭐️ 9.0/10

Google Project Zero disclosed a 0-click exploit chain for the Pixel 10, leveraging a Dolby vulnerability and a VPU driver flaw that was patched in 71 days. This highlights the increased attack surface from AI-powered media pre-processing features and shows that Google has improved its patching response time, though the broader Android ecosystem lags. The exploit chain combines CVE-2025-54957 (a Dolby 0-click vulnerability affecting all Android) and a VPU driver bug specific to Pixel 10, achieving root access without user interaction.

hackernews · happyhardcore · May 15, 13:39 · Discussion

Background: A 0-click exploit allows an attacker to compromise a device without the victim clicking a link or opening a file, often by exploiting vulnerabilities in code that automatically processes incoming data like SMS messages. This attack chain targeted Pixel 10's VPU and Dolby audio processing. Google Project Zero is a team of security researchers dedicated to finding and reporting zero-day vulnerabilities.

References

Discussion: Commenters expressed concern that AI features increase the 0-click attack surface and noted that Google's 71-day patch was fast for Android, though one wondered about Apple's response time. Some observed the recent uptick in published exploits, possibly due to AI tools.

Tags: #security, #android, #exploit, #pixel, #project zero


Mullvad VPN exit IPs enable user fingerprinting via float ranges
Mullvad VPN 出口 IP 通过浮动范围暴露用户指纹
⭐️ 9.0/10

A blog post reveals that Mullvad VPN's exit IP addresses have a fingerprinting vulnerability: overlapping 'float ranges' in IP assignments allow correlation of user activity across different servers with over 99% accuracy. Mullvad's co-CEO confirmed the issue on Hacker News and stated they are testing a fix. Since Mullvad is a popular privacy-focused VPN, this flaw undermines its anonymity guarantees and could allow websites or moderators to track users across sessions. It highlights a novel attack vector in VPN IP allocation designs that can be exploited for user fingerprinting. The vulnerability reduces the number of unique exit IP combinations from trillions to just 284 observed combinations, enabling precise user identification. A tool is provided to estimate the float range from a set of exit IPs, and the blog post includes a detailed analysis of the cause and implications.

hackernews · RGBCube · May 15, 02:35 · Discussion

Background: VPNs typically assign users exit IP addresses from a pool to obscure their identity. Mullvad uses 'float ranges' — ranges of fractional IP parts — to allocate IPs, but overlaps between these ranges for different servers create a fingerprinting vector. This is similar to browser fingerprinting but applied to the network layer.

References

Discussion: Mullvad's co-CEO acknowledged the issue on Hacker News, confirming they are testing a patch on a subset of infrastructure. Some commenters questioned the '>99% probability' claim, while others expressed continued trust in Mullvad, noting that VPNs are not fully anonymous. The overall sentiment is a mix of concern for privacy and appreciation for the transparency.

Tags: #Mullvad, #VPN, #privacy, #fingerprinting, #security


xAI Open-Sources X's For You Algorithm in Rust
xAI 开源 X 的 'For You' 推荐算法,用 Rust 重写
⭐️ 9.0/10

xAI has open-sourced the recommendation algorithm powering X's 'For You' feed, rewritten in Rust and released on GitHub. The system features a two-layer architecture for candidate retrieval and uses a Grok-1-derived transformer for ranking. This provides unprecedented transparency into a major social media platform's recommendation system, which has historically been a black box. It also demonstrates xAI's technical prowess in systems programming and machine learning, potentially influencing industry practices. The algorithm uses 'Thunder' in-memory storage for real-time retrieval of in-network posts and 'Phoenix' dual-tower model for out-of-network discovery. The ranking stage employs a transformer model adapted from Grok-1 to predict multiple engagement types (like, reply, retweet, click) and compute a weighted score.

rss · Geek(@geekbb) · May 15, 14:19

Background: Recommendation algorithms curate content feeds on social platforms by combining candidates from followed accounts (in-network) and broader discovery (out-of-network) in a two-stage pipeline: retrieval followed by ranking. xAI's release uses Rust for performance and safety, and its ranking model is based on Grok-1, a large mixture-of-experts transformer originally designed for conversational AI.

References

Tags: #xAI, #Rust, #Recommendation Algorithm, #Open Source, #Machine Learning


Cloudflare Launches Workflows V2 with Deterministic Execution, 50K Concurrency
Cloudflare 推出 Workflows V2,支持确定性执行与五万并发
⭐️ 9.0/10

Cloudflare has released Workflows V2, a redesigned distributed workflow orchestration system featuring deterministic replayable execution, improved observability, and major scaling enhancements, including support for 50,000 concurrent instances and 2 million queued workflows. This release significantly improves reliability and scalability for developers building AI agents, data pipelines, and background processing on Cloudflare's edge network, making it a strong competitor to platforms like Temporal and AWS Step Functions. Workflows V2 supports deterministic execution, ensuring that each workflow instance produces the same output given identical input, which is critical for debugging and consistency in distributed systems. It also introduces durable replayable execution that allows workflows to recover from failures by replaying previous steps.

rss · InfoQ · May 15, 14:04

Background: Workflow orchestration systems coordinate multiple distributed tasks, such as API calls or data processing steps, to execute in a defined order. Deterministic execution guarantees that a workflow always produces the same outcome under the same conditions, which simplifies testing and debugging. Replayable execution enables recovery from failures by re-executing steps from a checkpoint, an essential feature for long-running workflows.

References

Tags: #Cloudflare, #Workflows, #Distributed Systems, #Orchestration, #Reliability


User removes modem and GPS from 2024 RAV4 to stop telemetry
用户拆除 2024 款 RAV4 的调制解调器和 GPS 以阻止数据收集
⭐️ 8.0/10

A user documented physically removing the Data Communication Module (DCM) and GPS unit from a 2024 Toyota RAV4 Hybrid to prevent the car from sending telemetry data. The post also reveals that connecting a phone via Bluetooth allows the car to use the phone's internet connection to continue transmitting data. This practical guide addresses growing concerns about vehicle data privacy, offering a concrete method for owners to regain control. It may prompt other car manufacturers to improve privacy options and raise awareness about Bluetooth-based data leakage. The DCM is located behind the dashboard or center console; removal stops the car's internal modem from transmitting. However, if a phone is paired via Bluetooth, the car uses the phone's internet to send the same telemetry to Toyota; wired USB connections do not trigger this behavior.

hackernews · arkadiyt · May 14, 17:08 · Discussion

Background: Modern connected cars are equipped with telematics control units (TCUs) that collect and transmit data such as location, speed, and driving habits to manufacturers. Toyota's Data Communication Module (DCM) is part of this system. Privacy-conscious owners sometimes seek to disable these modules physically or via software to prevent unwanted data collection, though such measures may affect vehicle features and warranties.

References

Discussion: The Hacker News discussion highlights similar experiences with other car brands, validates the Bluetooth leakage claim, and shares workarounds like disabling Bluetooth or using only wired connections. Some commenters express frustration that automakers make it difficult to opt out of data collection without such hardware modifications.

Tags: #privacy, #automotive security, #telemetry, #hardware hacking, #Toyota


Amazon Workers Faking Tasks to Boost AI Usage
亚马逊员工为提升 AI 使用量而伪造任务
⭐️ 8.0/10

Amazon workers are reportedly making up tasks to artificially increase their AI usage metrics, driven by internal pressure to adopt AI tools. This highlights a broader trend of forced AI adoption in big tech. This matters because it reveals the unintended consequences of top-down AI mandates, leading to wasted resources and distorted productivity measures. It serves as a cautionary tale for other companies pushing AI adoption without clear value. Workers are creating unnecessary prompts to inflate token usage metrics, which are increasingly used as performance indicators. This practice mirrors broader 'productivity theater' in the tech industry, where employees game metrics to meet arbitrary quotas.

hackernews · hackernj · May 15, 13:28 · Discussion

Background: Many tech companies have recently mandated increased use of AI tools like large language models, measuring engagement through metrics such as token consumption. This can lead to employees gaming the system to meet arbitrary quotas, a phenomenon known as 'productivity theater'.

Discussion: Community comments echo similar experiences at other companies, with skepticism about using token usage as a performance metric. One user humorously compared the situation to 'universal basic jobs for AI', while others warned that inflated metrics could backfire when managers demand results.

Tags: #AI adoption, #workplace pressure, #big tech, #productivity theater


Antirez Introduces DS4: Local LLM Runtime for DeepSeek V4
Antirez 推出 DS4:专为 DeepSeek V4 打造的本地 LLM 推理运行时
⭐️ 8.0/10

Salvatore Sanfilippo (antirez) has released DS4 (DwarfStar 4), an open-source, lightweight inference engine designed specifically for running DeepSeek V4 Flash and Pro models locally. The initial release is optimized for Apple Silicon Macs with 96GB of RAM using the Metal backend, with additional support for NVIDIA CUDA (notably DGX Spark) and AMD ROCm. DS4 enables developers and enthusiasts to run state-of-the-art models like DeepSeek V4 Flash (284B parameters, 13B active) locally on consumer hardware, offering performance rivaling closed-source models like Claude while ensuring privacy and offline capabilities. This tool fills a critical niche in the local AI inference ecosystem, potentially reducing reliance on cloud-based APIs. DS4 primarily targets MacBooks with 96GB RAM via the Metal backend, with special optimization for the NVIDIA DGX Spark. The project explicitly acknowledges llama.cpp and GGML as foundational; support for AMD ROCm is maintained in a separate branch due to lack of hardware access. Quantization via imatrix is noted to offer better quality than some alternative backends.

hackernews · caust1c · May 14, 22:29 · Discussion

Background: DeepSeek V4 is the fourth generation of DeepSeek's Mixture-of-Experts (MoE) language model series. It comes in two variants: V4-Pro with 1.6 trillion total parameters (49B active) and V4-Flash with 284B total parameters (13B active). Running such large models locally requires substantial memory and efficient inference software. DS4 is a purpose-built, minimal runtime that leverages Apple Metal performance to make this feasible on high-end Macs.

References

Discussion: Comments highlight that DS4 feels remarkably close to Claude for code tasks, though slower. Users appreciate the narrow optimization and have successfully integrated it with tools like Pi (Claude Code's system prompt is too heavy) and OpenCode. There is agreement that imatrix quantization yields better quality than alternative backends.

Tags: #LLM inference, #DeepSeek, #local AI, #DwarfStar4, #antirez


Turso Retires Bug Bounty Program Due to AI-Generated Submissions
Turso 因 AI 生成的提交而终止漏洞赏金计划
⭐️ 8.0/10

Turso announced the retirement of its bug bounty program, citing an overwhelming number of low-quality and AI-generated submissions that made the program unsustainable. This decision highlights a growing challenge in the security community where automated tools and AI are being used to generate spam, threatening the effectiveness of bug bounty programs. The program's closure was driven by a high volume of submissions from accounts like 'Samuelsills' that appeared to be automated or AI-generated, overwhelming maintainers and reducing the signal-to-noise ratio.

hackernews · tjek · May 15, 13:33 · Discussion

Background: Bug bounty programs incentivize external security researchers to find and report vulnerabilities in exchange for rewards. However, the rise of generative AI has enabled mass production of low-quality or fake submissions, forcing some programs like Turso's to shut down.

Discussion: Commenters expressed understanding of the decision, with some suggesting alternative approaches like requiring a nominal fee or proof-of-work. Others pointed to the broader issue of spam in open-source contributions and called for platform-level action from GitHub or GitLab.

Tags: #bug bounty, #security, #program retirement, #AI-generated code, #spam


New Nginx Exploit with ASLR Bypass Claim
新的 Nginx 漏洞,声称可绕过 ASLR
⭐️ 8.0/10

A new nginx exploit named 'Nginx-Rift' has been disclosed, requiring specific rewrite and set directives, with a claimed reliable ASLR bypass method. This exploit is significant because nginx powers a large portion of web infrastructure, and a potential RCE vulnerability with ASLR bypass could impact many servers, though it requires specific configurations. The proof-of-concept disables ASLR, but the authors claim a bypass exists; the exploit requires a rewrite directive with a question mark and a subsequent set directive referencing a regex capture group. F5 has patched this in nginx versions 1.31.0 and 1.30.1.

hackernews · hetsaraiya · May 14, 17:17 · Discussion

Background: Nginx is a widely used web server and reverse proxy. The rewrite directive allows URL manipulation, and set directives assign values to variables. ASLR (Address Space Layout Randomization) is a security technique that randomizes memory addresses to make exploitation harder. This exploit targets a specific pattern in nginx configuration that can lead to memory corruption.

Discussion: Community comments reveal a debate on the severity: some argue ASLR bypass is not proven, while others trust the claim. Preconditions like specific configs are noted, and a mitigation (using named captures) is provided by F5. One commenter also highlights delay in vulnerability database updates.

Tags: #nginx, #security, #exploit, #vulnerability, #web server


Raycast 2.0: From Native to Hybrid Architecture
Raycast 2.0:从原生到混合架构重写
⭐️ 8.0/10

Raycast 2.0, a major rewrite from a pure Swift/AppKit macOS app to a hybrid architecture using TypeScript, Swift, C#, Rust, Node, and React, has been released. The team published a detailed engineering blog explaining their architectural decisions and trade-offs. This rewrite demonstrates a practical approach to cross-platform development without sacrificing native feel, and the detailed blog provides valuable insights for developers facing similar architectural challenges. It also shows how a productivity tool can evolve from a simple launcher to a full platform. The new architecture consists of four layers: Host App (Swift/AppKit on macOS, C#/.NET 8/WPF on Windows), Web Frontend (React/TypeScript shared across platforms), Node Backend, and Rust Core. The Rust file indexer on Windows reads the Master File Table directly for fast indexing.

rss · meng shao(@shao__meng) · May 15, 05:57

Background: Raycast is a popular productivity tool originally built as a native macOS launcher using AppKit. AppKit is Apple's native UI framework for macOS, while Tauri is a cross-platform framework using web frontends with Rust backend. The team chose a custom hybrid stack over Electron or Tauri to maintain full control over native interactions.

References

Tags: #Raycast, #architecture, #rewrite, #cross-platform, #TypeScript


xAI Releases Grok Build CLI (Beta)
xAI 发布 Grok Build CLI(测试版)
⭐️ 8.0/10

xAI released an early beta of Grok Build, an agentic CLI for coding, application building, and workflow automation, currently available exclusively to SuperGrok Heavy subscribers. This marks xAI's entry into the competitive AI-assisted coding tool space, challenging established players like GitHub Copilot and Claude CLI. Its underlying model, grok-code-fast-1, achieves 70.8% on SWE-Bench Verified, demonstrating strong code repair capabilities. The CLI features a Plan view, Subagents (up to 8 parallel agents), Skills, a Plugins Marketplace, and proactive Q&A clarification. It uses the grok-code-fast-1 model with a 256K context window.

rss · meng shao(@shao__meng) · May 15, 00:28

Background: An agentic CLI is a command-line interface designed for safe and reliable execution by AI agents, enabling automated workflows and coding tasks. SWE-Bench Verified is a benchmark that measures an AI's ability to resolve real-world coding issues from Python repositories by generating correct patches.

References

Tags: #CLI, #AI coding, #xAI, #Grok, #workflow automation


Vercel's LLM Usage Analysis: Anthropic Leads in Cost, Google in Tokens
Vercel 报告:成本上 Anthropic 领先,Token 量上 Google 领先
⭐️ 8.0/10

Vercel released an analysis of LLM usage across 200,000 projects over seven months, consuming ten trillion tokens, revealing that Anthropic accounts for 61% of costs while Google leads with 38% of token volume. This real-world data provides crucial insights into how enterprises are actually using LLMs, highlighting cost vs. token efficiency trade-offs and the rapid growth of agent requests, which now represent 58.9% of all requests. Claude Opus is expensive but used for critical tasks, while Gemini Flash is cheap and high-volume; B2B tasks generate 29.7% of tokens but account for 40.7% of costs; large teams use an average of 35 models.

rss · 向阳乔木(@vista8) · May 15, 08:39

Background: Vercel is a cloud platform for deploying web applications and AI features. The LMSYS Chatbot Arena leaderboard ranks models by human preference, but Vercel's report focuses on actual usage patterns instead of subjective rankings. AI agent requests involve multi-step tasks that consume more tokens than simple chat.

References

Tags: #AI Models, #Token Consumption, #Vercel, #LLM Usage, #Agent Requests


GitHub Releases Copilot Desktop Technical Preview
GitHub 发布 Copilot 桌面技术预览版
⭐️ 8.0/10

GitHub announced a technical preview of a desktop app for GitHub Copilot, featuring a Codex-like interface and integration with GitHub workflows. Users must join a waitlist for early access. This marks a significant expansion of Copilot beyond IDE plugins, bringing AI-assisted coding to a standalone desktop environment. It could streamline development tasks by offering a more integrated and powerful tool for code generation and management. The preview requires joining a waitlist via the provided link. The interface resembles OpenAI Codex, suggesting capabilities for end-to-end code generation, refactoring, and migration tasks. The exact feature set is not yet fully detailed.

rss · 歸藏(guizang.ai)(@op7418) · May 15, 02:21

Background: GitHub Copilot is an AI-powered code completion tool developed by GitHub in partnership with OpenAI, using large language models to suggest code in real-time within IDEs. OpenAI Codex is an AI coding agent that automates software engineering tasks like feature building and complex refactors. The new desktop app appears to bring similar autonomous capabilities to a standalone application.

References

Tags: #GitHub, #Copilot, #AI, #Desktop


Position paper: Agentic AI as foreseeable AGI path
立场论文:自主 AI 通往 AGI 的可预见路径
⭐️ 8.0/10

A new position paper argues that agentic AI systems—not merely scaling up foundation models—are the most foreseeable route to achieving artificial general intelligence (AGI). The paper formalizes key components of agentic AI including memory, reasoning, tool use, self-improvement, and alignment. This paper shifts the debate from simply scaling model size to building systems that combine multiple capabilities, potentially influencing research directions in AGI. It highlights bottlenecks that scaling alone cannot solve, such as long-horizon coherence and credit assignment. The authors argue that bottlenecks like long-horizon coherence, credit assignment, and safety auditing will not be resolved by another order of magnitude increase in pretraining compute. Each component of agentic AI is presented as a separable axis with its own challenges.

rss · elvis(@omarsar0) · May 14, 19:00

Background: Agentic AI refers to intelligent agents that can pursue goals, use tools, and take actions autonomously, often built on top of large language models. AGI (Artificial General Intelligence) is a hypothetical AI that can perform any intellectual task a human can. The paper contributes to the ongoing debate between scaling single models versus developing multi-agent systems, formalizing what 'agentic' adds beyond a base model.

References

Tags: #agentic AI, #AGI, #multi-agent systems, #AI research


Anthropic Publishes Paper on US-China AI Competition
Anthropic 发布关于美中 AI 竞争的白皮书
⭐️ 8.0/10

Anthropic, a leading AI company, published a paper outlining its views on the US-China AI competition and strategies to maintain the US lead in frontier AI. This paper adds influential voice to the geopolitical debate on AI leadership, potentially shaping policy decisions and corporate strategies. It highlights the strategic importance of frontier AI development for national security and economic competitiveness. The paper specifically addresses what it will take to preserve the current US and allied lead in frontier AI, including considerations of talent, compute, and policy. It is published by Anthropic, the company behind the Claude model series.

rss · Anthropic(@AnthropicAI) · May 14, 18:09

Background: Frontier AI refers to the most advanced foundation models, such as large language models, that are at the cutting edge of capability and often require massive resources to develop. The US and its democratic allies currently lead in this area, but China is investing heavily to catch up. Anthropic's paper analyzes the competitive dynamics and recommends actions to sustain leadership.

References

Tags: #AI competition, #US-China, #frontier AI, #geopolitics, #policy


Datadog Releases Toto 2.0 Time Series Models with Scaling Laws
Datadog 发布 Toto 2.0 时间序列模型,验证缩放定律
⭐️ 8.0/10

Datadog released Toto 2.0, a family of open-weights time series foundation models ranging from 4M to 2.5B parameters, demonstrating scaling laws where larger models consistently outperform smaller ones across benchmarks. This is significant because scaling laws have been elusive for time series, unlike language and vision; establishing such laws enables predictable performance improvements with more data and compute, opening new possibilities for time series modeling. The models use a single hyperparameter configuration across all sizes, and Toto 2.0 claims state-of-the-art results on the BOOM, GIFT-Eval, and TIME benchmarks, with the 2.5B model achieving top performance.

rss · clem 🤗(@ClementDelangue) · May 14, 18:24

Background: Time series foundation models are pretrained on diverse time series data to generalize across domains, but they have not exhibited clear scaling laws like language models. Scaling laws predict that model performance improves predictably with increases in parameters, data, and compute, which has been a cornerstone for advances in NLP and computer vision. Toto 2.0 aims to provide similar predictability for time series.

References

Tags: #time series, #foundation models, #scaling laws, #open weights, #AI/ML


Discord Reveals Circular Dependency Caused March Voice Outage
Discord 披露三月语音中断因循环依赖引发
⭐️ 8.0/10

Discord published a postmortem on May 2026 revealing that an undetected circular dependency in its voice infrastructure caused a cascading failure, leading to a major voice outage on March 25, 2026. This incident highlights the subtle dangers of circular dependencies in distributed systems, and the postmortem provides valuable lessons for engineers designing resilient architectures. The circular dependency was previously undetected and created a feedback loop that amplified failures, ultimately disrupting voice services across the entire platform.

rss · InfoQ · May 15, 12:00

Background: Circular dependencies occur when two or more services depend on each other directly or indirectly, creating a cycle. In distributed systems, such cycles can lead to cascading failures if one service fails, as the dependency loop prevents proper recovery. Discord's voice infrastructure relies on multiple interconnected services. Postmortems like this help teams identify and prevent similar issues.

Tags: #distributed systems, #incident response, #system reliability, #postmortem, #circular dependency


SolidJS 2.0 Beta: First-Class Async and Deterministic Batching
SolidJS 2.0 Beta:一等异步支持与确定性批处理
⭐️ 8.0/10

SolidJS 2.0 Beta introduces first-class async support, allowing Promises to be used directly within the framework, along with reworked Suspense and deterministic batching for predictable state updates. This update significantly enhances developer experience by simplifying async data handling and improving reactivity predictability, which could set a new standard for reactive UI frameworks without a virtual DOM. The beta includes breaking changes such as altered state handling and new primitives for mutations, but maintains SolidJS's fine-grained reactivity and no virtual DOM approach.

rss · InfoQ · May 15, 07:30

Background: SolidJS is a reactive JavaScript UI library known for its fine-grained reactivity system, which updates only the specific DOM nodes affected by state changes. Unlike frameworks that use a virtual DOM, SolidJS compiles templates to direct DOM operations, offering high performance. The 2.0 beta aims to improve async capabilities and deterministic batching, which were key challenges in earlier versions.

References

Tags: #SolidJS, #JavaScript, #Frontend Framework, #Reactive Programming, #Async


BlackFile Vishing Operation Bypasses MFA via AiTM Attacks
BlackFile 语音钓鱼行动通过 AiTM 攻击绕过 MFA
⭐️ 8.0/10

Google Threat Intelligence Group (GTIG) revealed details of UNC6671's BlackFile vishing extortion campaign, which uses adversary-in-the-middle (AiTM) techniques to bypass multi-factor authentication (MFA) and compromise Microsoft 365 and Okta environments. This campaign demonstrates that vishing combined with AiTM can effectively circumvent standard MFA, posing a significant threat to organizations relying on MFA for cloud security. It emphasizes the urgent need for phishing-resistant authentication methods. UNC6671 uses voice phishing calls impersonating IT staff to direct victims to credential harvesting sites, then leverages Python and PowerShell scripts for automated data exfiltration from SharePoint and OneDrive. The group targets North America, Australia, and the UK.

rss · Cloud Blog · May 15, 14:00

Background: Adversary-in-the-middle (AiTM) attacks involve an attacker placing themselves between a user and a legitimate service to intercept and manipulate communications. Vishing (voice phishing) uses phone calls to trick victims into revealing sensitive information. This campaign highlights how social engineering can supplement technical AiTM attacks.

References

Tags: #cybersecurity, #threat intelligence, #vishing, #MFA bypass, #cloud security


Abridge Turns Clinical Conversations into AI Operating System
Abridge 将临床对话转化为 AI 操作系统
⭐️ 8.0/10

Abridge has processed over 100 million doctor visits using its AI-powered platform that transforms patient-clinician conversations into structured clinical documentation, saving clinicians 10–20 hours per week and reducing prior authorization to minutes. This demonstrates that generative AI can dramatically reduce administrative burden in healthcare, a sector plagued by inefficiency, while improving clinician satisfaction and patient care delivery. The ability to automate prior authorization alone could save billions in administrative costs. The system is built on proprietary generative AI models specifically trained for medical conversation summarization, and it integrates directly with electronic health records (EHRs) without disrupting existing workflows. Abridge recently raised $250 million in February 2025, reflecting strong investor confidence.

rss · Latent.Space · May 14, 22:05

Background: Prior authorization requires doctors to obtain insurance approval before performing certain procedures or prescribing specific medications, a process that often takes hours or days and leads to treatment delays. Clinicians also spend significant time manually writing clinical notes from patient visits, contributing to burnout. Abridge applies large language models to automatically generate accurate, structured summaries from natural conversations, addressing both pain points.

References

Tags: #AI in healthcare, #clinical AI, #prior authorization, #AI-native, #healthcare workflow


Databricks Expands Unity Catalog Interoperability with Open APIs
Databricks 通过开放 API 扩大 Unity Catalog 互操作性
⭐️ 8.0/10

Databricks announced expanded interoperability for Unity Catalog through new open APIs, allowing external tools and engines to integrate more easily with the catalog's governance and metadata capabilities. This move strengthens the open lakehouse ecosystem by reducing vendor lock-in, enabling data teams to use their preferred tools while maintaining consistent governance across platforms. The open APIs follow the Delta Sharing protocol standard and support key operations like catalog listing, table discovery, and schema retrieval, allowing third-party query engines to access Unity Catalog metadata directly.

rss · Databricks · May 14, 21:30

Background: Unity Catalog is Databricks' unified governance solution for data and AI assets in the lakehouse architecture. An open lakehouse uses open formats and APIs to avoid vendor lock-in, allowing diverse tools to work together. Previously, Unity Catalog's closed nature limited integration with non-Databricks tools.

References

Tags: #Unity Catalog, #interoperability, #lakehouse, #data engineering, #open APIs


HackerNews Roundup: BitLocker Zero-Day, Bun Rewrite, Claude for Business
HackerNews 热点:BitLocker 零日漏洞、Bun 重写为 Rust、Claude 企业版
⭐️ 8.0/10

A critical BitLocker zero-day vulnerability named YellowKey was disclosed, allowing physical attackers to bypass encryption on Windows 11. Bun completed its rewrite from Zig to Rust, passing 99.8% of tests with improved performance and smaller binary. Anthropic launched Claude for Small Business, integrating AI into tools like QuickBooks and HubSpot. These developments impact millions: the BitLocker flaw threatens enterprise and consumer data security; Bun's migration to Rust signals a shift toward safer systems programming; Claude for small business could narrow the AI adoption gap. Additionally, MIT and Princeton policy changes reflect broader challenges in academia. The YellowKey exploit requires only a USB drive with a crafted file and physical access to unlock BitLocker-protected drives within seconds. Bun's Rust port addresses memory issues and is available via canary releases, though code is not yet idiomatic. Claude for Small Business defaults to not training on user data, but generated content still requires human review.

rss · HackerNews每日摘要 on SuperTechFans · May 15, 00:28

Background: BitLocker is Microsoft's full-disk encryption feature in Windows; a zero-day bypass without a patch is serious for anyone using it. Bun is a fast JavaScript runtime bundled with Zig Zig; switching to Rust aims for better memory safety and broader community support. Anthropic's Claude is a competitor to OpenAI's ChatGPT, and the small business offering targets the 44% of U.S. GDP contributed by small businesses.

References

Discussion: On the MIT post, many PhD graduates expressed disillusionment with academia due to long hours, low pay, and poor career prospects, while some argued that stipends reflect research investment. A separate thread debated whether 8GB RAM in MacBook Neo is sufficient for modern workloads.

Tags: #HackerNews, #技术新闻, #安全漏洞, #AI企业版, #软件工程


California Lawsuit Alleges OpenAI Shared User Data with Meta, Google
加州诉讼指控 OpenAI 向 Meta 和 Google 分享用户数据
⭐️ 8.0/10

A class-action lawsuit filed in California accuses OpenAI of transmitting user chat queries and personal information, such as email addresses and user IDs, to Meta and Google without proper consent. This lawsuit highlights growing data privacy concerns around AI services, potentially affecting how AI companies handle user data and comply with privacy laws like California's Invasion of Privacy Act. The complaint specifically references the use of Meta Pixel and Google Analytics for data transmission, alleging violations of California's Invasion of Privacy Act and Electronic Communications Privacy Act.

telegram · zaihuapd · May 15, 03:45

Background: Meta Pixel is a JavaScript code snippet that websites embed to track visitor actions for advertising purposes. Google Analytics is a web analytics service that collects data about user interactions. Both tools are commonly used for tracking but can inadvertently transmit personally identifiable information if not configured properly.

References

Tags: #privacy, #lawsuit, #OpenAI, #data sharing, #California


arXiv Bans Authors 1 Year for Unchecked LLM Content
arXiv 对未核查的 LLM 内容禁投一年
⭐️ 8.0/10

arXiv announced a new policy that imposes a one-year submission ban on authors whose papers contain unchecked LLM-generated content, such as hallucinated citations or placeholder data. The ban is effective immediately and requires authors to take full responsibility for all content, regardless of how it was generated. This policy directly addresses the growing problem of LLM-generated hallucinations and fake citations in academic preprints, which undermine research integrity. It sets a clear precedent for accountability in AI-assisted writing and may influence other preprint servers and journals. The ban applies to submissions showing evidence that the author did not check LLM outputs, including hallucinated citations, meta-comments left by the LLM, or placeholder data like 'table data is just example, please replace with real experimental data.' After the ban ends, future submissions must first be accepted by a trusted peer-reviewed venue before posting on arXiv.

telegram · zaihuapd · May 15, 04:30

Background: arXiv is a widely used preprint repository for scientific papers, particularly in physics, mathematics, and computer science. Large language models (LLMs) like GPT-4 can generate convincing but false references, known as hallucinated citations, which have become increasingly common in preprints. A recent study found over 140,000 such citations in 2025 alone, prompting this policy update.

References

Tags: #arXiv, #LLM, #academic publishing, #policy, #AI ethics


Apple-OpenAI Partnership Fraught, Legal Action Possible
苹果与 OpenAI 合作生变,或诉诸法律
⭐️ 8.0/10

OpenAI is considering legal action against Apple, alleging that Apple failed to adequately promote the ChatGPT integration, leading to subscription revenues far below expectations. This rift could reshape the AI integration landscape on Apple devices, potentially opening the door for competitors like Anthropic's Claude and Google's Gemini while straining one of the tech industry's most high-profile partnerships. Apple plans to open Siri to third-party models such as Claude and Gemini at WWDC in June, which would further reduce ChatGPT's exclusive position, and the partnership's expected billions in subscription revenue remain largely unrealized.

telegram · zaihuapd · May 15, 12:59

Background: Apple and OpenAI announced a partnership in 2024 to integrate ChatGPT into Apple's ecosystem with revenue sharing from subscriptions. However, due to privacy concerns and architectural constraints, the integration was limited. Apple has also expressed dissatisfaction with OpenAI's privacy standards, hardware business, and poaching of Apple engineers.

References

Tags: #Apple, #OpenAI, #AI Partnerships, #Legal, #Tech Industry


Trump and Xi Discuss AI Guardrails and Nvidia H200 Chips
特朗普与习近平讨论 AI 护栏与英伟达 H200 芯片
⭐️ 8.0/10

During his visit to China, President Trump discussed AI guardrails and Nvidia H200 chip exports with President Xi, with Trump stating that China has chosen not to buy H200 chips and is focusing on developing its own chips. This discussion highlights the ongoing geopolitical tension over advanced AI chips, which could reshape global AI hardware supply chains and affect companies like Nvidia that rely on the Chinese market. The U.S. has permitted Nvidia to supply H200 chips to Chinese customers, but Beijing has not yet approved purchases, resulting in zero deliveries so far; China previously rejected the lower-performance H20 chip.

telegram · zaihuapd · May 15, 15:13

Background: The H200 is a mid-range AI GPU with higher memory bandwidth than the H20, enabling both training and inference for complex AI models, but it is one generation behind Nvidia's flagship. U.S. export controls restrict advanced chips to China, leading to designs like the H20 that comply with regulations. The discussion also touched on AI 'guardrails'—safety protocols for AI systems—partly motivated by global cybersecurity concerns following Anthropic's Mythos model release.

References

Tags: #AI, #US-China, #Nvidia, #chip exports, #geopolitics