<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" >
    <channel>
        <title>Biz &amp; IT - Ars Technica</title>
        <atom:link href="https://arstechnica.com/information-technology/feed/" rel="self" type="application/rss+xml" />
        <link>https://arstechnica.com</link>
        <description>Serving the Technologist since 1998. News, reviews, and analysis.</description>
        <lastBuildDate>Fri, 04 Sep 2026 23:47:33 +0000</lastBuildDate>
        <language>en-US</language>
        <sy:updatePeriod>
            hourly        </sy:updatePeriod>
        <sy:updateFrequency>
            1        </sy:updateFrequency>
        
<image>
	<url>https://cdn.arstechnica.net/wp-content/uploads/2016/10/cropped-ars-logo-512_480-60x60.png</url>
	<title>Biz &amp; IT - Ars Technica</title>
	<link>https://arstechnica.com</link>
	<width>32</width>
	<height>32</height>
</image> 
            <item>
                <title>OpenAI agents discussed ways to escape their sandbox on public wiki</title>
                <link>https://arstechnica.com/security/2026/09/openai-agents-discussed-ways-to-escape-their-sandbox-on-public-wiki/</link>
                                    <comments>https://arstechnica.com/security/2026/09/openai-agents-discussed-ways-to-escape-their-sandbox-on-public-wiki/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Dan Goodin]]>
                </dc:creator>
                <pubDate>Fri, 04 Sep 2026 22:17:36 +0000</pubDate>
                		<category><![CDATA[AI]]></category>
		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AI agents]]></category>
		<category><![CDATA[ai insecurity]]></category>
		<category><![CDATA[openai]]></category>
                <guid isPermaLink="true">https://arstechnica.com/security/2026/09/openai-agents-discussed-ways-to-escape-their-sandbox-on-public-wiki/</guid>

                                    <description>
                        <![CDATA[In all, 3,700 internal agents posted 18,000 messages discussing cheating on a test. ]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>Self-identifying OpenAI agents posted 18,000 messages to a public wiki that discussed ways for other agents to bypass security sandbox restrictions during what was likely internal testing designed to gauge the agents’ hacking abilities, <a href="https://collusion.wiki/">researchers said Friday</a>.</p>
<p>In all, agents with 3,700 distinct self-given names posted the messages to German site <a href="https://dsewiki.vercel.app">DSEwiki</a> over a six-week period. Besides discussing ways the agents could break out of the restricted environment OpenAI intended to prevent them from posting code or content to the Internet, the posts shared test answers. The posts also shared possible ways to perform XSS (cross-site scripting) attacks against the wiki and to impersonate site moderators. In three of the posts, agents used the word “swarm” to describe the collection of agents engaged in the activity.</p>
<h2>Colluding to share answers</h2>
<p>The research team—composed of Sydney Von Arx, Spencer Kitts, Thomas Larsen, and Cormac Slade Byrd—said they found the posts and pieced them together. The researchers say there are gaps in their understanding of precisely what actions the agents took because the research is based solely on the content of the posts. Additionally, the agents generated “chain of thought” data that’s understood only by OpenAI. As a result, the researchers said, they in some cases made educated guesses, including that the agents were, in fact, from OpenAI. In a statement, OpenAI later confirmed they were.</p><p><a href="https://arstechnica.com/security/2026/09/openai-agents-discussed-ways-to-escape-their-sandbox-on-public-wiki/">Read full article</a></p>
<p><a href="https://arstechnica.com/security/2026/09/openai-agents-discussed-ways-to-escape-their-sandbox-on-public-wiki/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>212</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2026/09/ai-agent-hacking-1152x648.jpg" type="image/jpeg" medium="image" width="1152" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2026/09/ai-agent-hacking-500x500.jpg" width="500" height="500" />
<media:credit>Getty Images</media:credit></media:content>
            </item>
                    <item>
                <title>“Trust, not features, is the real deficit”: VMware tries to appease SMBs</title>
                <link>https://arstechnica.com/information-technology/2026/09/trust-not-features-is-the-real-deficit-vmware-tries-to-appease-smbs/</link>
                                    <comments>https://arstechnica.com/information-technology/2026/09/trust-not-features-is-the-real-deficit-vmware-tries-to-appease-smbs/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Scharon Harding]]>
                </dc:creator>
                <pubDate>Fri, 04 Sep 2026 17:35:02 +0000</pubDate>
                		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[Broadcom]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[vmware]]></category>
                <guid isPermaLink="true">https://arstechnica.com/information-technology/2026/09/trust-not-features-is-the-real-deficit-vmware-tries-to-appease-smbs/</guid>

                                    <description>
                        <![CDATA[Broadcom admits it put “too big a focus on VCF.”]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>For many small-to-medium-sized businesses (SMBs), VMware has become too expensive.</p>
<p>Broadcom’s acquisition of the virtualization firm brought the end of <a href="https://arstechnica.com/information-technology/2025/07/some-vmware-perpetual-license-owners-are-unable-to-download-security-patches/">perpetual license sales</a> and the arrival of pricey, stacked, subscription-based bundles that priced out many SMBs.</p>
<p>The most obvious is VMware Cloud Foundation (VCF), VMware’s flagship private cloud bundle that has been Broadcom’s primary focus since taking over VMware. Many SMBs find that VCF is unaffordable and stuffed with unnecessary offerings. However, numerous customers have reported online that VMware sales representatives have still pushed them toward VCF, with some <a href="https://www.reddit.com/r/vmware/comments/1oibvst/vsphere_standard_discontinued_impact_on_smbs/">claiming</a> that sales reps have <a href="https://www.reddit.com/r/vmware/comments/1lehpai/broadcom_vsphere_standard_end_of_sale_july_31_2025/">told them</a> that the lower-priced edition of VMware’s virtualization platform, vSphere Standard, was <a href="https://www.reddit.com/r/vmware/comments/1qwbeaa/no_more_vsphere_standard_v8_licenses_and_vvf/">no longer available</a>.</p><p><a href="https://arstechnica.com/information-technology/2026/09/trust-not-features-is-the-real-deficit-vmware-tries-to-appease-smbs/">Read full article</a></p>
<p><a href="https://arstechnica.com/information-technology/2026/09/trust-not-features-is-the-real-deficit-vmware-tries-to-appease-smbs/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>166</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2026/04/GettyImages-1934095718-1152x648.jpg" type="image/jpeg" medium="image" width="1152" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2026/04/GettyImages-1934095718-500x500.jpg" width="500" height="500" />
<media:credit>Getty</media:credit><media:text>VMware office in Bellevue, Washington, USA - June 15, 2023. </media:text></media:content>
            </item>
                    <item>
                <title>Once popular for attacking AI, ASCII smuggling is embraced by spammers</title>
                <link>https://arstechnica.com/security/2026/09/once-popular-for-attacking-ai-ascii-smuggling-is-embraced-by-spammers/</link>
                                    <comments>https://arstechnica.com/security/2026/09/once-popular-for-attacking-ai-ascii-smuggling-is-embraced-by-spammers/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Dan Goodin]]>
                </dc:creator>
                <pubDate>Fri, 04 Sep 2026 17:18:12 +0000</pubDate>
                		<category><![CDATA[AI]]></category>
		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ascii smuggling]]></category>
		<category><![CDATA[prompt injections]]></category>
		<category><![CDATA[spam filter evasion]]></category>
                <guid isPermaLink="true">https://arstechnica.com/security/2026/09/once-popular-for-attacking-ai-ascii-smuggling-is-embraced-by-spammers/</guid>

                                    <description>
                        <![CDATA[A once-overlooked block of unicode that's invisible to humans is gaining ever wider use.]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>A clever technique used to hide malicious prompts in attacks on AI agents has been adopted by spammers to evade filters on email platforms that are designed to flag unwanted messages used in mass campaigns.</p>
<p>The technique is broadly known as ASCII smuggling. It gained attention two years ago as a means of making a class of AI attack known as <a href="https://arstechnica.com/security/2026/07/hackers-can-use-9-of-the-most-popular-ai-tools-to-assemble-massive-botnets/">prompt injections</a> more stealthy. Malicious instructions embedded in emails or other untrusted content to be processed by an LLM aren’t written in ordinary text. Instead, they’re rendered by a special range of <a href="https://en.wikipedia.org/wiki/Unicode">Unicode</a> tags. For example, the tag point U+E0041 mirrors “A,” and U+E0061 mirrors “a.”</p>
<h2>No longer just for obscuring prompt injections</h2>
<p>The block of 128 tags mimics a portion of the <a href="https://en.wikipedia.org/wiki/ASCII">American Standard Code for Information Interchange</a> almost perfectly, with one major difference: the characters they encode are readable by computers but, by design, are almost completely invisible to humans. By expressing the malicious prompts in these tags, LLMs detect the instructions, but people reading the email never see them. There’s much more about ASCII smuggling <a href="https://arstechnica.com/security/2024/10/ai-chatbots-can-read-and-write-invisible-text-creating-an-ideal-covert-channel/">here</a>.</p><p><a href="https://arstechnica.com/security/2026/09/once-popular-for-attacking-ai-ascii-smuggling-is-embraced-by-spammers/">Read full article</a></p>
<p><a href="https://arstechnica.com/security/2026/09/once-popular-for-attacking-ai-ascii-smuggling-is-embraced-by-spammers/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>53</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2026/09/no-eyes-1152x648.jpg" type="image/jpeg" medium="image" width="1152" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2026/09/no-eyes-500x500.jpg" width="500" height="500" />
<media:credit>Getty Images</media:credit><media:text>Eyeball with a digital line over it.</media:text></media:content>
            </item>
                    <item>
                <title>Confused about which VPN is right, US senator asks the NSA for guidance</title>
                <link>https://arstechnica.com/security/2026/09/us-senator-calls-on-the-nsa-to-give-guidance-for-use-of-vpns/</link>
                                    <comments>https://arstechnica.com/security/2026/09/us-senator-calls-on-the-nsa-to-give-guidance-for-use-of-vpns/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Dan Goodin]]>
                </dc:creator>
                <pubDate>Thu, 03 Sep 2026 19:52:06 +0000</pubDate>
                		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[multi-hop]]></category>
		<category><![CDATA[single-hop]]></category>
		<category><![CDATA[virtual private networks]]></category>
		<category><![CDATA[vpns]]></category>
                <guid isPermaLink="true">https://arstechnica.com/security/2026/09/us-senator-calls-on-the-nsa-to-give-guidance-for-use-of-vpns/</guid>

                                    <description>
                        <![CDATA[Open source, commercial, single-hop, multi-hop, mixnet? The array of options is dizzying.]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>A prominent US senator is asking the National Security Agency to provide guidance to the general public on best practices for using virtual private networks to secure their communications from spying by foreign adversaries.</p>
<p>VPNs funnel all of a user’s Internet traffic through an encrypted connection to a remote server. The design provides strong assurances that no one between the user and the server can read the encrypted contents. VPNs also allow users to hide their IP addresses from the destination servers they communicate with. While US agencies have previously recommended use of VPNs, none have given recommendations on which ones provide adequate protection.</p>
<h2>It's all in the nuances</h2>
<p>There are a host of limitations that can undo many of the protections users may think their VPN provides them. For instance, the encrypted tunnel often terminates once a single server decrypts the traffic and sends it on to its final destination. That means the decrypted traffic or the sending and destination IP addresses may be available for snooping by rogue employees or attackers who hack the server. VPNs also don’t encrypt certain types of metadata, such as time stamps, allowing nation-states to build profiles that can be useful in intelligence gathering.</p><p><a href="https://arstechnica.com/security/2026/09/us-senator-calls-on-the-nsa-to-give-guidance-for-use-of-vpns/">Read full article</a></p>
<p><a href="https://arstechnica.com/security/2026/09/us-senator-calls-on-the-nsa-to-give-guidance-for-use-of-vpns/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>90</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2024/05/vpn-tunnel-1000x648.jpg" type="image/jpeg" medium="image" width="1000" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2024/05/vpn-tunnel-500x500.jpg" width="500" height="500" />
<media:credit>Getty Images</media:credit></media:content>
            </item>
                    <item>
                <title>VMware migration reduces Tottenham Hotspur&#039;s licensing fees by 85 percent</title>
                <link>https://arstechnica.com/information-technology/2026/09/vmware-migration-reduces-tottenham-hotspurs-licensing-fees-by-85-percent/</link>
                                    <comments>https://arstechnica.com/information-technology/2026/09/vmware-migration-reduces-tottenham-hotspurs-licensing-fees-by-85-percent/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Scharon Harding]]>
                </dc:creator>
                <pubDate>Thu, 03 Sep 2026 18:58:31 +0000</pubDate>
                		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[Broadcom]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[vmware]]></category>
                <guid isPermaLink="true">https://arstechnica.com/information-technology/2026/09/vmware-migration-reduces-tottenham-hotspurs-licensing-fees-by-85-percent/</guid>

                                    <description>
                        <![CDATA[Pro soccer team's CTO points to "issues with the Broadcom takeover." ]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>Tottenham Hotspur, a professional soccer team that’s part of the Premier League, has saved over 85 percent in licensing fees by replacing its stadium's VMware instance with Hewlett-Packard Enterprise’s (HPE’s) Morpheus VM Essentials (VME) virtualization software.</p>
<p>Tottenham hasn’t disclosed which VMware products it used or how much it previously paid the Broadcom firm.</p>
<p>The soccer organization confirmed this week to <a href="https://www.theregister.com/on-prem/2026/09/03/spurs-boots-vmware-cites-85-licensing-saving/5294139">The Register</a> that it has moved its stadium's server, storage, and networking infrastructure to HPE solutions delivered through HPE's hybrid cloud management platform, GreenLake. That is all “underpinned by" VME and HPE's OpsRamp software for hybrid and multi-cloud environments, Rob Pickering, Tottenham's CTO, told the publication, with HPE in charge of the hybrid cloud-managed service.</p><p><a href="https://arstechnica.com/information-technology/2026/09/vmware-migration-reduces-tottenham-hotspurs-licensing-fees-by-85-percent/">Read full article</a></p>
<p><a href="https://arstechnica.com/information-technology/2026/09/vmware-migration-reduces-tottenham-hotspurs-licensing-fees-by-85-percent/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>80</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2026/09/Tottenham-1152x648.jpg" type="image/jpeg" medium="image" width="1152" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2026/09/Tottenham-500x500.jpg" width="500" height="500" />
<media:credit>Hewlett Packard Enterprise </media:credit><media:text>Tottenham Hotspur Stadium has 20,000 network access points, 1,849 IPTV screens, and 519 CCTV screens. It hosts about 63,000 viewers. </media:text></media:content>
            </item>
                    <item>
                <title>I rented a car, and within hours, my driver&#039;s license was for sale</title>
                <link>https://arstechnica.com/security/2026/09/my-drivers-license-is-one-of-153-million-for-sale-on-a-new-dark-website/</link>
                                    <comments>https://arstechnica.com/security/2026/09/my-drivers-license-is-one-of-153-million-for-sale-on-a-new-dark-website/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Dan Goodin]]>
                </dc:creator>
                <pubDate>Wed, 02 Sep 2026 20:32:02 +0000</pubDate>
                		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[Features]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[drivers licenses]]></category>
		<category><![CDATA[id scans]]></category>
		<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[privacy]]></category>
                <guid isPermaLink="true">https://arstechnica.com/security/2026/09/my-drivers-license-is-one-of-153-million-for-sale-on-a-new-dark-website/</guid>

                                    <description>
                        <![CDATA[The FBI is reportedly investigating a massive data breach that is unfolding in real time.]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>Not long ago, I rented an SUV from a well-known car rental company. Within hours of an employee scanning my driver's license, a high-resolution scan of my ID was available for sale on the dark web.</p>
<p>An <a href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/">exposé published Tuesday</a> by KrebsOnSecurity reports that my license was one of more than 153 million that were available through Nexus, the name of the new ID theft service. Like other driver's licenses available there—including some belonging to journalist Brian Krebs, his mother, an FBI assistant director, and several security researchers—my license was purported to include multiple image files showing both the front and back of the ID. Besides a basic image scan, the files also captured the images in the infrared and ultraviolet spectrums. Presumably, the additional formats may allow cloned-based counterfeit IDs to pass hologram tests.</p>
<h2>Growing by the day</h2>
<p>Besides advertising the availability of driver's licenses, Nexus offered to sell a bevy of other forms of ID. They included:</p><p><a href="https://arstechnica.com/security/2026/09/my-drivers-license-is-one-of-153-million-for-sale-on-a-new-dark-website/">Read full article</a></p>
<p><a href="https://arstechnica.com/security/2026/09/my-drivers-license-is-one-of-153-million-for-sale-on-a-new-dark-website/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>260</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2026/09/Dan-stolen-driver-licence.png" type="image/png" medium="image">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2026/09/Dan-stolen-driver-licence-500x500.png" width="500" height="500" />
<media:credit>Nexus</media:credit><media:text>A scan of my driver's license. All redacted information, except for birth year, made by Nexus. </media:text></media:content>
            </item>
                    <item>
                <title>BGP hijack infecting networks caused by a comedy of errors that’s not funny at all</title>
                <link>https://arstechnica.com/security/2026/09/well-executed-bgp-attack-uses-hijacked-ips-to-infect-real-networks/</link>
                                    <comments>https://arstechnica.com/security/2026/09/well-executed-bgp-attack-uses-hijacked-ips-to-infect-real-networks/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Dan Goodin]]>
                </dc:creator>
                <pubDate>Wed, 02 Sep 2026 11:00:43 +0000</pubDate>
                		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[BGP]]></category>
		<category><![CDATA[Border Gateway Protocol]]></category>
		<category><![CDATA[supply chain attack]]></category>
                <guid isPermaLink="true">https://arstechnica.com/security/2026/09/well-executed-bgp-attack-uses-hijacked-ips-to-infect-real-networks/</guid>

                                    <description>
                        <![CDATA[What can we learn from a BGP hijacking that poisoned production software? Plenty.]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>Hackers carried out a supply chain attack that installed malware on networks using an unusual technique: hijacking a chunk of Internet space where cloud management software used by hosting providers, data centers, and other large infrastructure companies is updated.</p>
<p>In a well-coordinated operation, the unknown attackers exploited weaknesses in the routing security setup of hosting provider Hetzner Online and the process for attaining valid TLS certificates. The lapses allowed the attackers to successfully perform a BGP (<a href="https://en.wikipedia.org/wiki/Border_Gateway_Protocol">Border Gateway Protocol</a>) hijacking to obtain control over IP addresses assigned to Softaculous. The company, based in the United Arab Emirates, is the maker of a platform for installing and managing Web software and is the developer of Virtualizor, a management platform for virtualized environments.</p>
<p>Softaculous used the IPs to issue updates and host a client and billing site. With control over the hijacked space, the attacker was now using the addresses to push malware masquerading as updates to unsuspecting users.</p><p><a href="https://arstechnica.com/security/2026/09/well-executed-bgp-attack-uses-hijacked-ips-to-infect-real-networks/">Read full article</a></p>
<p><a href="https://arstechnica.com/security/2026/09/well-executed-bgp-attack-uses-hijacked-ips-to-infect-real-networks/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>68</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2022/09/GettyImages-11477585601-1000x648.jpg" type="image/jpeg" medium="image" width="1000" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2022/09/GettyImages-11477585601-500x500-1788301464.jpg" width="500" height="500" />
<media:credit>Getty Images</media:credit></media:content>
            </item>
                    <item>
                <title>Think twice before installing this device promising free movies</title>
                <link>https://arstechnica.com/security/2026/08/how-some-media-streaming-devices-open-home-networks-to-a-world-of-harm/</link>
                                    <comments>https://arstechnica.com/security/2026/08/how-some-media-streaming-devices-open-home-networks-to-a-world-of-harm/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Dan Goodin]]>
                </dc:creator>
                <pubDate>Mon, 31 Aug 2026 16:33:38 +0000</pubDate>
                		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[media streaming]]></category>
		<category><![CDATA[proxy networks]]></category>
		<category><![CDATA[remote access]]></category>
                <guid isPermaLink="true">https://arstechnica.com/security/2026/08/how-some-media-streaming-devices-open-home-networks-to-a-world-of-harm/</guid>

                                    <description>
                        <![CDATA[In exchange for free stuff, devices make home connections part of a proxy network.]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>As online services get better at blocking malicious traffic, the attackers and scammers behind them have been forced to find new ways to reach their targets. The alternative of choice is now what are known as residential proxy networks. These systems funnel millions of home Internet connections into a unified network, and the proxy operators allow attackers to route their malicious traffic through these connections for a fee. The online services see only IP addresses with good reputations and geolocations that don’t stand out.</p>
<p>More often than not, the home users have no idea that their connections are being used to facilitate crime and occasionally even <a href="https://arstechnica.com/security/2023/09/china-state-hackers-are-camping-out-in-cisco-routers-us-and-japan-warn/">nation-state attacks</a>. Users who do know often don’t care much. In exchange for leasing out part of their unlimited bandwidth to others, many get free movie and TV show streaming. Several less tech-savvy people I know who own such digital media players have told me, after I explain how the media players piggyback off their connections, that the bonanza of content is worth it. They find the tangible benefits outweigh the abstract harm they pose.</p>
<h2>Infecting already compromised devices</h2>
<p>Research published Monday brings the threat into much clearer view. Security firm Plume cataloged a vast ecosystem of malware that preys squarely on users of <a href="https://mysuperboxtv.com/">SuperBox</a>, just one of many media players offering pirated content. These malicious apps can be surreptitiously installed by remote attackers even when the devices are positioned behind a router. While Monday’s deep-dive analysis focused exclusively on SuperBox, Plume warned that dozens of similar streaming devices pose precisely the same threat.</p><p><a href="https://arstechnica.com/security/2026/08/how-some-media-streaming-devices-open-home-networks-to-a-world-of-harm/">Read full article</a></p>
<p><a href="https://arstechnica.com/security/2026/08/how-some-media-streaming-devices-open-home-networks-to-a-world-of-harm/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>129</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2026/08/superbox-s7-pro-1152x648.webp" type="image/webp" medium="image" width="1152" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2026/08/superbox-s7-pro-500x500.webp" width="500" height="500" />
<media:credit>SuperBox</media:credit><media:text>The SuperBox S7 Pro</media:text></media:content>
            </item>
                    <item>
                <title>Inside Meta’s push to put robots to work in data centers</title>
                <link>https://arstechnica.com/ai/2026/08/inside-metas-push-to-put-robots-to-work-in-data-centers/</link>
                                    <comments>https://arstechnica.com/ai/2026/08/inside-metas-push-to-put-robots-to-work-in-data-centers/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Paresh Dave, WIRED.com]]>
                </dc:creator>
                <pubDate>Sun, 30 Aug 2026 11:03:47 +0000</pubDate>
                		<category><![CDATA[AI]]></category>
		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[ai data centers]]></category>
		<category><![CDATA[data centers]]></category>
		<category><![CDATA[Shoot Many Robots]]></category>
		<category><![CDATA[syndication]]></category>
                <guid isPermaLink="true">https://arstechnica.com/ai/2026/08/inside-metas-push-to-put-robots-to-work-in-data-centers/</guid>

                                    <description>
                        <![CDATA[The company is testing robots on tasks that can performed by technicians.]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>Meta is testing robots that can plug in cables, reset servers, and handle other tasks inside its <a href="https://www.wired.com/story/how-data-centers-broke-american-politics/">data centers</a>, according to several current and former workers familiar with the projects. The ongoing effort, which has not been previously reported, may eventually allow <a href="https://www.wired.com/tag/meta/">Meta</a> to operate its rapidly expanding data center footprint with fewer humans, keeping labor costs in check as its spending on <a href="https://www.wired.com/story/microsoft-google-meta-2025-earnings/">AI infrastructure soars</a>.</p>
<p>Meta is using robots and related hardware from several different vendors, including Watney Robotics, Kinova, and ABB, according to the same workers, who asked to remain anonymous because they weren’t authorized to speak to the media. Kinova and ABB declined to comment. Watney didn’t respond to requests for comment.</p>
<p>In one experiment, Meta is evaluating whether a Kinova Gen3 robotic arm could be used for power cycling or cutting off electricity to servers. The company is also testing a different robot to swap networking cables. One Meta data center worker estimates that if it’s successful, the bot could replace up to 80 percent of some people’s workloads. “We thought those of us performing the physical tasks were safe for a while, but not anymore,” says the worker. “It’s coming for us all, unfortunately.”</p><p><a href="https://arstechnica.com/ai/2026/08/inside-metas-push-to-put-robots-to-work-in-data-centers/">Read full article</a></p>
<p><a href="https://arstechnica.com/ai/2026/08/inside-metas-push-to-put-robots-to-work-in-data-centers/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>125</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2026/08/data-center-server-room-1152x648.jpg" type="image/jpeg" medium="image" width="1152" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2026/08/data-center-server-room-500x500.jpg" width="500" height="500" />
<media:credit>Getty Images</media:credit></media:content>
            </item>
                    <item>
                <title>Authorities arrest 2 alleged members of prolific hacking group TeamPCP</title>
                <link>https://arstechnica.com/security/2026/08/authorities-arrest-2-alleged-members-of-prolific-hacking-group-teampcp/</link>
                                    <comments>https://arstechnica.com/security/2026/08/authorities-arrest-2-alleged-members-of-prolific-hacking-group-teampcp/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Dan Goodin]]>
                </dc:creator>
                <pubDate>Fri, 28 Aug 2026 11:15:05 +0000</pubDate>
                		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[law enforcement]]></category>
		<category><![CDATA[supply chain attacks]]></category>
		<category><![CDATA[teampcp]]></category>
		<category><![CDATA[worms]]></category>
                <guid isPermaLink="true">https://arstechnica.com/security/2026/08/authorities-arrest-2-alleged-members-of-prolific-hacking-group-teampcp/</guid>

                                    <description>
                        <![CDATA[The group infected more than 1,000 organizations in a relentless supply-chain attack campaign.]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>Authorities in Australia said Wednesday that they arrested two men accused of participating in cybercrimes for TeamPCP, a prolific group of hackers that, over nine months, has carried out a relentless series of supply-chain attacks that infected more than 1,000 organizations worldwide.</p>
<p>In a <a href="https://www.afp.gov.au/news-centre/media-release/two-wa-men-charged-following-afp-fbi-wapf-disruption-alleged-global">statement</a>, the Australian Federal Police said the two men were arrested and charged with 14 offenses. The statement said the men were members of TeamPCP, which by the authorities’ count, compromised more than 1,000 organizations worldwide. The statement didn’t identify the men, except to say they lived in the Western Australian towns of Cottesloe and Mandurah. KrebsOnSecurity, citing a lengthy investigation, provided what it reports to be <a href="https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/">both defendants' names</a>, along with an extensive background of their lives and the mistakes that led to their downfall.</p>
<h2>The hacks that keep on hacking</h2>
<p>TeamPCP has vexed law enforcement officials and security personnel around the world since it emerged in December. The group is best known for a sustained series of supply-chain attacks that laced open source software with malware that self-propagated from one package to another. The viral infections worked by targeting organizations’ CI/CD pipelines, which are used to rapidly develop, update, and deploy software.</p><p><a href="https://arstechnica.com/security/2026/08/authorities-arrest-2-alleged-members-of-prolific-hacking-group-teampcp/">Read full article</a></p>
<p><a href="https://arstechnica.com/security/2026/08/authorities-arrest-2-alleged-members-of-prolific-hacking-group-teampcp/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>42</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2026/08/teampcp-member-arrest-1152x648.jpg" type="image/jpeg" medium="image" width="1152" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2026/08/teampcp-member-arrest-500x500.jpg" width="500" height="500" />
<media:credit>Australian Federal Police</media:credit></media:content>
            </item>
                    <item>
                <title>Claude, Codex, and Hermes installed unowned code inside corporate networks</title>
                <link>https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/</link>
                                    <comments>https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Dan Goodin]]>
                </dc:creator>
                <pubDate>Thu, 27 Aug 2026 14:00:13 +0000</pubDate>
                		<category><![CDATA[AI]]></category>
		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[Features]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AI agents]]></category>
		<category><![CDATA[infections]]></category>
		<category><![CDATA[LLMs]]></category>
		<category><![CDATA[malware]]></category>
                <guid isPermaLink="true">https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/</guid>

                                    <description>
                        <![CDATA[227 install commands were found in corporate docs pointing at code nobody owns.]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware.</p>
<p>The potentially dangerous content is in llms.txt and llms-full.txt files, an <a href="https://llmstxt.org/">emerging convention</a> websites employ to provide machine-readable summaries of the site’s content and its high-level structure. These files are the AI equivalent of the <a href="https://en.wikipedia.org/wiki/Robots.txt">robots.txt</a> standard that instructs search engines how to index the site's content. Google Lighthouse, a tool for helping web developers, has more <a href="https://developer.chrome.com/docs/lighthouse/agentic-browsing/llms-txt#how_the_llmstxt_audit_works">here</a>. Correctly configured llms.txt and llms-full.txt files for Cloudflare are <a href="https://www.cloudflare.com/llms.txt">here</a> and <a href="https://www.cloudflare.com/llms-full.txt">here</a>.</p>
<h2>How the researchers found it</h2>
<p>Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that weren’t registered. To test what happens when an AI agent processes such files, the researchers registered a handful of the unclaimed names and hosted packages that caused any machine executing them to reach out to their server. Within an hour, the researchers received a phone-home response from a Fortune 500 company. Over time, they got a few dozen more, some from more Fortune 500 companies and others from startups. Their beacon also recorded the chain of parent processes that spawned each install, ultimately revealing that coding agents, including Claude, OpenAI's Codex, and Nous Research's Hermes, were involved. Anthropic, OpenAI, and Nous Research did not respond to requests for comment by the time of publication.</p><p><a href="https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/">Read full article</a></p>
<p><a href="https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>157</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2026/02/gatekeeping-ai-agents-1152x648.jpg" type="image/jpeg" medium="image" width="1152" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2026/02/gatekeeping-ai-agents-500x500.jpg" width="500" height="500" />
<media:credit>Aurich Lawson</media:credit></media:content>
            </item>
                    <item>
                <title>How OpenAI let a mob of LLM agents game a test and ransack Hugging Face</title>
                <link>https://arstechnica.com/security/2026/08/how-openai-let-a-mob-of-llm-agents-game-a-test-and-ransack-hugging-face/</link>
                                    <comments>https://arstechnica.com/security/2026/08/how-openai-let-a-mob-of-llm-agents-game-a-test-and-ransack-hugging-face/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Dan Goodin]]>
                </dc:creator>
                <pubDate>Thu, 27 Aug 2026 12:58:59 +0000</pubDate>
                		<category><![CDATA[AI]]></category>
		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AI agents]]></category>
		<category><![CDATA[Hugging Face]]></category>
		<category><![CDATA[LLMs]]></category>
		<category><![CDATA[openai]]></category>
                <guid isPermaLink="true">https://arstechnica.com/security/2026/08/how-openai-let-a-mob-of-llm-agents-game-a-test-and-ransack-hugging-face/</guid>

                                    <description>
                        <![CDATA[Without authorization, 1,200 OpenAI agents conspired among themselves to game a test. ]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>The OpenAI agents involved in last month’s <a href="https://arstechnica.com/security/2026/07/jfrog-tries-to-spin-openai-0-day-exploit-of-its-app-into-a-success-story/">incursion into Hugging Face</a> were trained so heavily on winning a competition that they pursued a relentless campaign to cheat, a new report documented. In the process, and without authorization, they created an improvised message board to hatch a plan that ultimately landed them squarely inside the latter company’s network.</p>
<p>Over the course of May and June, OpenAI gave the agents what the company described as “impossible tasks” to complete on the benchmarking framework ExploitGym. The internal test was designed to test how the agents would respond. To get a full understanding of the agent capabilities, company engineers disabled safety guardrails that normally are in place to prevent the sort of hacks that eventually hit Hugging Face and one other undisclosed organization. The stymied agents’ training made them so focused on winning that they performed tasks they were never explicitly instructed to follow.</p>
<h2>Cheaters gonna cheat</h2>
<p>The first step was creating a message board that allowed the agents to pass notes to each other. OpenAI hadn’t provided any such platform, so the agents repurposed a platform called Artifactory, which OpenAI was using in internal testing of several unreleased hacking agents. OpenAI was using Artifactory as one of the measures to prevent the agents from egressing its isolated sandboxes and accessing the Internet, while at the same time simulating a real-world hacking environment.</p><p><a href="https://arstechnica.com/security/2026/08/how-openai-let-a-mob-of-llm-agents-game-a-test-and-ransack-hugging-face/">Read full article</a></p>
<p><a href="https://arstechnica.com/security/2026/08/how-openai-let-a-mob-of-llm-agents-game-a-test-and-ransack-hugging-face/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>166</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2026/07/GettyImages-1004669768-1152x648-1784927041.jpg" type="image/jpeg" medium="image" width="1152" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2026/07/GettyImages-1004669768-500x500-1784927028.jpg" width="500" height="500" />
<media:credit>Getty Images</media:credit></media:content>
            </item>
                    <item>
                <title>AI agents meant to replace Meta workers made “large-scale, disruptive actions”</title>
                <link>https://arstechnica.com/ai/2026/08/metas-scrapped-plans-to-go-ai-native-included-slashing-teams-by-60-percent/</link>
                                    <comments>https://arstechnica.com/ai/2026/08/metas-scrapped-plans-to-go-ai-native-included-slashing-teams-by-60-percent/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Scharon Harding]]>
                </dc:creator>
                <pubDate>Wed, 26 Aug 2026 21:25:27 +0000</pubDate>
                		<category><![CDATA[AI]]></category>
		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[job losses]]></category>
		<category><![CDATA[jobs]]></category>
		<category><![CDATA[meta]]></category>
                <guid isPermaLink="true">https://arstechnica.com/ai/2026/08/metas-scrapped-plans-to-go-ai-native-included-slashing-teams-by-60-percent/</guid>

                                    <description>
                        <![CDATA[Report shows Meta's challenges replacing people with AI agents. ]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>Earlier this year, Meta created a “plan” to reduce some of its teams by as much as 60 percent to make the company “AI native,” <a href="https://www.reuters.com/investigations/mark-zuckerberg-had-bold-plan-replace-meta-staff-with-ai-heres-how-it-imploded-2026-08-26/">Reuters</a> reported today, citing two people familiar with Meta’s internal affairs.</p>
<p>Reuters’ report highlights the challenges <a href="https://arstechnica.com/health/2026/08/ai-wont-replace-radiologists-but-it-will-dramatically-change-their-jobs/">organizations face</a> when analyzing the <a href="https://arstechnica.com/ai/2026/08/ai-is-hitting-entry-level-jobs-hardest-stanford-study-finds/">best uses for AI</a> and determining when the technology is a better fit for certain tasks than employees.</p>
<p>Meta confirmed to Reuters that the plan, reportedly codenamed Project OT (short for organization transformation), explored scenarios in which Meta reduced some team headcounts by 60 percent and that the plan called for two rounds of layoffs. Meta wouldn’t confirm which teams Project OT affected.</p><p><a href="https://arstechnica.com/ai/2026/08/metas-scrapped-plans-to-go-ai-native-included-slashing-teams-by-60-percent/">Read full article</a></p>
<p><a href="https://arstechnica.com/ai/2026/08/metas-scrapped-plans-to-go-ai-native-included-slashing-teams-by-60-percent/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>144</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2026/08/GettyImages-2171717886-1152x648.jpg" type="image/jpeg" medium="image" width="1152" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2026/08/GettyImages-2171717886-500x500.jpg" width="500" height="500" />
<media:credit>Getty</media:credit></media:content>
            </item>
                    <item>
                <title>Inaudible sounds used to fingerprint browsers catch AliExpress red-handed</title>
                <link>https://arstechnica.com/security/2026/08/aliexpress-caught-fingerprinting-visitors-after-sending-inaudible-sounds-to-browsers/</link>
                                    <comments>https://arstechnica.com/security/2026/08/aliexpress-caught-fingerprinting-visitors-after-sending-inaudible-sounds-to-browsers/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Dan Goodin]]>
                </dc:creator>
                <pubDate>Mon, 24 Aug 2026 19:19:21 +0000</pubDate>
                		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AliExpress]]></category>
		<category><![CDATA[browser fingerprinting]]></category>
		<category><![CDATA[chromium]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Safari]]></category>
                <guid isPermaLink="true">https://arstechnica.com/security/2026/08/aliexpress-caught-fingerprinting-visitors-after-sending-inaudible-sounds-to-browsers/</guid>

                                    <description>
                        <![CDATA[Is the technique outdated? Yes. Is it still creepy? Also yes.]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>Chinese retailer AliExpress has been caught fingerprinting visitors after one of the metrics—an outdated technique that measures inaudible sounds it sends to browsers—impeded a researcher's ability to use his bluetooth headphones.</p>
<p>Researcher Matthew Callaghan <a href="https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html">said</a> he stumbled on the stealthy tracking by mistake. After loading the AliExpress homepage, audio from his phone stopped playing over his multipoint headphones, which accept connections from more than one device at a time. He set the headphones to play sounds from his phone except when his PC was producing audio. Each time he loaded AliExpress, the phone audio stopped. Each time he closed the tab the site was loaded into, the phone was once again audible.</p>
<h2>Users can't hear it, but browsers can</h2>
<p>While investigating the odd behavior, Callaghan said he found two highly obfuscated scripts. Together, they rendered a graph that analyzed the <a href="https://github.com/MicrosoftEdge/MSEdgeExplainers/blob/main/OfflineAudioContext/explainer.md">WebAudio</a> readings of each visiting browser. This graph acted as an oscillator that measured <a href="https://en.wikipedia.org/wiki/Sawtooth_wave">Sawtooth waves</a>, which are common in output from digital audio.</p><p><a href="https://arstechnica.com/security/2026/08/aliexpress-caught-fingerprinting-visitors-after-sending-inaudible-sounds-to-browsers/">Read full article</a></p>
<p><a href="https://arstechnica.com/security/2026/08/aliexpress-caught-fingerprinting-visitors-after-sending-inaudible-sounds-to-browsers/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>71</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2022/03/browser-fingerprint-1000x648.jpeg" type="image/jpeg" medium="image" width="1000" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2022/03/browser-fingerprint-500x500.jpeg" width="500" height="500" />
<media:credit>Getty Images</media:credit></media:content>
            </item>
                    <item>
                <title>Waymo doubles spending on lobbying in robotaxi battle with Uber</title>
                <link>https://arstechnica.com/cars/2026/08/waymo-doubles-spending-on-lobbying-in-robotaxi-battle-with-uber/</link>
                                    <comments>https://arstechnica.com/cars/2026/08/waymo-doubles-spending-on-lobbying-in-robotaxi-battle-with-uber/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Rafe Rosner Uddin and Michael Taffe, Financial Times ]]>
                </dc:creator>
                <pubDate>Fri, 21 Aug 2026 13:11:35 +0000</pubDate>
                		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[Cars]]></category>
		<category><![CDATA[robotaxi]]></category>
		<category><![CDATA[syndication]]></category>
		<category><![CDATA[Uber]]></category>
		<category><![CDATA[waymo]]></category>
                <guid isPermaLink="true">https://arstechnica.com/cars/2026/08/waymo-doubles-spending-on-lobbying-in-robotaxi-battle-with-uber/</guid>

                                    <description>
                        <![CDATA[Alphabet-owned company is seeking to persuade US regulators to clear a path for fully autonomous taxi services.]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>Waymo has sharply increased its lobbying spending as it seeks to persuade US regulators to clear a path for fully autonomous taxi services, intensifying its battle with rival Uber over the future of robotaxis.</p>
<p>The Alphabet-owned company spent more than $1 million between April and June on lobbying the federal government, more than double its outlay a year earlier, according to filings. That put Waymo’s spending close to Uber’s and well ahead of rivals including Amazon’s Zoox and Tesla.</p>
<p>The rise in lobbying comes as Waymo and Uber push competing visions for the future of ride-hailing. Waymo wants a faster route to fully driverless commercial services, while Uber is advocating a staggered rollout in which robotaxis operate alongside human drivers.</p><p><a href="https://arstechnica.com/cars/2026/08/waymo-doubles-spending-on-lobbying-in-robotaxi-battle-with-uber/">Read full article</a></p>
<p><a href="https://arstechnica.com/cars/2026/08/waymo-doubles-spending-on-lobbying-in-robotaxi-battle-with-uber/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>102</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2026/08/ftcms_8bad1114-5b27-4fc9-8102-1cb63e7f76fb-1152x648.jpeg" type="image/jpeg" medium="image" width="1152" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2026/08/ftcms_8bad1114-5b27-4fc9-8102-1cb63e7f76fb-500x500.jpeg" width="500" height="500" />
<media:credit>Alex Kent, Bloomberg</media:credit></media:content>
            </item>
                    <item>
                <title>Grok exfiltrates user data when malicious instructions are encrypted</title>
                <link>https://arstechnica.com/security/2026/08/grok-exfiltrates-user-data-when-malicious-instructions-are-encrypted/</link>
                                    <comments>https://arstechnica.com/security/2026/08/grok-exfiltrates-user-data-when-malicious-instructions-are-encrypted/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Dan Goodin]]>
                </dc:creator>
                <pubDate>Thu, 20 Aug 2026 13:00:35 +0000</pubDate>
                		<category><![CDATA[AI]]></category>
		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[cryptography]]></category>
		<category><![CDATA[LLM security]]></category>
		<category><![CDATA[prompt injections]]></category>
                <guid isPermaLink="true">https://arstechnica.com/security/2026/08/grok-exfiltrates-user-data-when-malicious-instructions-are-encrypted/</guid>

                                    <description>
                        <![CDATA[Cryptographic Context Injection is only the latest way to break an LLM safety guardrail.]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>Earlier this week, researchers outlined an attack that used a secret input provided by Microsoft 365 Copilot for enterprise to cause the AI assistant to exfiltrate a password present in the user’s inbox. Now, a separate team has devised a similar attack against Grok. The new data theft hack employs a deceptively simple trick to force the Elon Musk-owned large language model to steal user chats and other personal information. At the time this post went live, the assistant continued to cough up the data, despite xAI being informed of it in June.</p>
<p>The lesson from both this week’s episodes—and the countless other ones that have come before it—is that LLMs are incapable of solving the root causes for prompt injections, the most severe vulnerability classes they’re most prone to. That leaves AI developers with no other option but to build a guardrail that steers the model away from the harmful actions. As I noted in <a href="https://arstechnica.com/security/2026/08/microsoft-copilot-reveals-secret-input-that-allowed-it-to-be-hacked/">Tuesday’s story</a>, the approach is tantamount to a road traffic safety engineer erecting a protective rail around a dangerous bend rather than banking the curve.</p>
<h2>Cryptographic Context Injection in the house</h2>
<p>Prompt injections exploit LLMs' training to comply with user requests whenever possible. Attackers can capitalize on the predilection by smuggling harmful instructions into emails or webpages the assistant is instructed to summarize. Because LLMs can’t reliably distinguish between content in an email sent by an untrusted party and user instructions entered directly into a prompt, the overly solicitous LLM faithfully follows them. To date, Grok and other LLMs' only recourse is to create guardrails that flag suspicious instructions and forbid them from being executed.</p><p><a href="https://arstechnica.com/security/2026/08/grok-exfiltrates-user-data-when-malicious-instructions-are-encrypted/">Read full article</a></p>
<p><a href="https://arstechnica.com/security/2026/08/grok-exfiltrates-user-data-when-malicious-instructions-are-encrypted/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>107</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2026/06/xai-grok-1152x648.jpg" type="image/jpeg" medium="image" width="1152" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2026/06/xai-grok-500x500.jpg" width="500" height="500" />
<media:credit>Getty Images | SOPA Images</media:credit></media:content>
            </item>
                    <item>
                <title>Microsoft Copilot reveals secret input that allowed it to be hacked</title>
                <link>https://arstechnica.com/security/2026/08/microsoft-copilot-reveals-secret-input-that-allowed-it-to-be-hacked/</link>
                                    <comments>https://arstechnica.com/security/2026/08/microsoft-copilot-reveals-secret-input-that-allowed-it-to-be-hacked/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Dan Goodin]]>
                </dc:creator>
                <pubDate>Tue, 18 Aug 2026 13:00:04 +0000</pubDate>
                		<category><![CDATA[AI]]></category>
		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[copilot]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[guardrails]]></category>
		<category><![CDATA[microsoft]]></category>
                <guid isPermaLink="true">https://arstechnica.com/security/2026/08/microsoft-copilot-reveals-secret-input-that-allowed-it-to-be-hacked/</guid>

                                    <description>
                        <![CDATA[Secret parameter allowed hackers to steal passwords when a target clicked on a link.]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>It’s not every day that attackers can force a frontier AI model to cough up user passwords and other sensitive data without user confirmation. That’s exactly what researchers recently did to Microsoft 365 Copilot for enterprise. Even more unusual is the source they tapped to discover the critical vulnerability that made their exploit possible. Rather than employing reverse engineering or other traditional vulnerability-hunting methods, they asked Copilot. The LLM assistant readily complied.</p>
<p>Researchers at security firm Varonis knew they wanted to create an exploit that would exfiltrate user data when a user did nothing more than click on a link. Like most AI assistants today, Copilot steadfastly refused and made clear that sensitive prompts like that require explicit user consent in the form of a gesture, such as pressing a return key or other key. In response, the researchers peppered Copilot with questions about the guardrails that required user confirmation before the assistant could execute powerful commands.</p>
<h2>Loose lips sink ships</h2>
<p>The dialog was like a game of 20 questions. Each answer provided a new clue that divulged information about the complex safety mechanism. Why was auto-execution impossible, they asked. What URL structures and deep links were involved? What happens when a page is loaded with input already in the prompt field? Each answer provided a deeper view into the guardrail and its limits. Eventually, Copilot provided a stunning Microsoft trade secret—an undocumented prompt parameter that completely bypassed the requirement for user consent.</p><p><a href="https://arstechnica.com/security/2026/08/microsoft-copilot-reveals-secret-input-that-allowed-it-to-be-hacked/">Read full article</a></p>
<p><a href="https://arstechnica.com/security/2026/08/microsoft-copilot-reveals-secret-input-that-allowed-it-to-be-hacked/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>114</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2026/06/GettyImages-2242817595-1152x648.jpg" type="image/jpeg" medium="image" width="1152" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2026/06/GettyImages-2242817595-500x500.jpg" width="500" height="500" />
<media:credit>Photo Illustration by Thomas Fuller/SOPA Images/LightRocket via Getty Images</media:credit></media:content>
            </item>
                    <item>
                <title>Nvidia discloses $21B stake in SpaceX</title>
                <link>https://arstechnica.com/information-technology/2026/08/nvidia-discloses-21b-stake-in-spacex/</link>
                                    <comments>https://arstechnica.com/information-technology/2026/08/nvidia-discloses-21b-stake-in-spacex/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Rafe Rosner-Uddin]]>
                </dc:creator>
                <pubDate>Mon, 17 Aug 2026 14:22:54 +0000</pubDate>
                		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[NVIDIA]]></category>
		<category><![CDATA[spacex]]></category>
		<category><![CDATA[syndication]]></category>
                <guid isPermaLink="true">https://arstechnica.com/information-technology/2026/08/nvidia-discloses-21b-stake-in-spacex/</guid>

                                    <description>
                        <![CDATA[Filing comes after Elon Musk announced exclusive arrangement to kit out its data centers.]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>Nvidia has disclosed that it owns nearly 123 million shares in SpaceX, further highlighting the chipmaker’s entangled financial relationships with some of its biggest customers.</p>
<p>The $5.5 trillion company owned SpaceX stock worth nearly $21 billion at the end of June, according to an SEC filing on Friday. Elon Musk’s rocket conglomerate’s shares have fallen sharply since its June initial public offering, meaning Nvidia’s stake would now be worth $17 billion.</p>
<p>The disclosure marks a huge pay-off on Nvidia’s investment in xAI, completed in January, shortly before Musk combined the AI lab with SpaceX.</p><p><a href="https://arstechnica.com/information-technology/2026/08/nvidia-discloses-21b-stake-in-spacex/">Read full article</a></p>
<p><a href="https://arstechnica.com/information-technology/2026/08/nvidia-discloses-21b-stake-in-spacex/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>130</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2026/08/ftcms_116f79c4-b712-471b-b46a-ace5e4d7dda4.avif" type="image/avif" medium="image">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2026/08/ftcms_116f79c4-b712-471b-b46a-ace5e4d7dda4.avif" />
<media:credit> Bloomberg</media:credit><media:text>Elon Musk and Jensen Huang. The disclosure marks a huge pay-off on Nvidia’s investment in xAI, completed in January, shortly before Musk combined the AI lab with SpaceX</media:text></media:content>
            </item>
                    <item>
                <title>Vulnerability giving attackers full control of Macs is under active exploitation</title>
                <link>https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation/</link>
                                    <comments>https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Dan Goodin]]>
                </dc:creator>
                <pubDate>Fri, 14 Aug 2026 18:32:14 +0000</pubDate>
                		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[MacOS]]></category>
		<category><![CDATA[Macs]]></category>
		<category><![CDATA[screen sharing]]></category>
		<category><![CDATA[vulnerabilities]]></category>
                <guid isPermaLink="true">https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation/</guid>

                                    <description>
                        <![CDATA[Screen-sharing bug lets remote hackers log in without a password.]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation.</p>
<p>“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the Netherlands National Cyber Security Centrum <a href="https://advisories.ncsc.nl/2026/ncsc-2026-0280.html">warned</a> earlier this week. “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”</p>
<h2>Do you know if your screen sharing is on?</h2>
<p>The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS <a href="https://support.apple.com/en-us/148170">Tahoe</a>, <a href="https://support.apple.com/en-us/148171">Sequoia</a>, and <a href="https://support.apple.com/en-us/148172">Sonoma</a>. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the “state management,” which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause.</p><p><a href="https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation/">Read full article</a></p>
<p><a href="https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>103</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2026/08/macbook-pro-1152x648.jpg" type="image/jpeg" medium="image" width="1152" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2026/08/macbook-pro-500x500.jpg" width="500" height="500" />
<media:credit>Getty Images</media:credit><media:text>Isolated photo a 13 inch MacBook Pro Retina.</media:text></media:content>
            </item>
                    <item>
                <title>PBS station fears losing 50TB of data after being ghosted by cloud storage provider</title>
                <link>https://arstechnica.com/information-technology/2026/08/pbs-station-fears-losing-50tb-of-data-after-being-ghosted-by-cloud-storage-provider/</link>
                                    <comments>https://arstechnica.com/information-technology/2026/08/pbs-station-fears-losing-50tb-of-data-after-being-ghosted-by-cloud-storage-provider/#comments</comments>
                
                <dc:creator>
                    <![CDATA[Scharon Harding]]>
                </dc:creator>
                <pubDate>Fri, 14 Aug 2026 17:03:54 +0000</pubDate>
                		<category><![CDATA[Biz & IT]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[cloud storage]]></category>
		<category><![CDATA[data center]]></category>
		<category><![CDATA[PBS]]></category>
                <guid isPermaLink="true">https://arstechnica.com/information-technology/2026/08/pbs-station-fears-losing-50tb-of-data-after-being-ghosted-by-cloud-storage-provider/</guid>

                                    <description>
                        <![CDATA["We don't have access to the data on the hardware/servers," Iron Mountain told Ars. ]]>
                    </description>
                                                                <content:encoded>
                            <![CDATA[<p>After its cloud storage provider went defunct, a PBS affiliate decided to sue a data center provider to regain access to 50TB of TV shows, videos, and other data dating back 70 years.</p>
<p>As reported this week by <a href="https://current.org/2026/08/nine-pbs-sues-iron-mountain-over-blocked-access-to-archival-data/?wallit_nosession=1">Current</a>, a trade newspaper covering public broadcasting, St. Louis affiliate Nine PBS filed a lawsuit against Iron Mountain Data Centers on July 28, seeking access to the data. In the litigation filed in Denver District Court, Nine PBS says that its cloud storage provider, Open Source Storage (OSS), used one of Iron Mountain’s Denver data centers to store the channel’s data. However, OSS is being unresponsive, and Nine PBS says Iron Mountain has refused to release its data.</p>
<p>The data in question includes the station’s coverage of the COVID-19 pandemic, East St. Louis’ history, <a href="https://ny.pbslearningmedia.org/resource/ess05.sci.ess.earthsys.flood/the-great-flood-of-1993/">The Great Flood of 1993</a>, and over 11,000 files, <a href="https://www.denverpost.com/2026/07/29/st-louis-pbs-archives-denver-data-center-lawsuit/">The Denver Post</a> reported in July. The lawsuit claims that “most” of the data is “unique and irreplaceable,” according to the Post.</p><p><a href="https://arstechnica.com/information-technology/2026/08/pbs-station-fears-losing-50tb-of-data-after-being-ghosted-by-cloud-storage-provider/">Read full article</a></p>
<p><a href="https://arstechnica.com/information-technology/2026/08/pbs-station-fears-losing-50tb-of-data-after-being-ghosted-by-cloud-storage-provider/#comments">Comments</a></p>
]]>
                        </content:encoded>
                                    
                                    <slash:comments>179</slash:comments>
                
                
                <media:content url="https://cdn.arstechnica.net/wp-content/uploads/2026/08/GettyImages-2269291893-1024x648.jpg" type="image/jpeg" medium="image" width="1024" height="648">
<media:thumbnail url="https://cdn.arstechnica.net/wp-content/uploads/2026/08/GettyImages-2269291893-500x500.jpg" width="500" height="500" />
<media:credit>Getty</media:credit><media:text>ARLINGTON, VA - MARCH 31: A sign for the Public Broadcasting Service (PBS) is seen on its building headquarters on March 31, 2026 in Arlington, Virginia. </media:text></media:content>
            </item>
            </channel>
</rss>