Las herramientas que nos rodean se están moviendo — y a veces nos pasan por encima
Hoy la IA no se queda quieta: bugs en Linux, modelos en el teléfono, agentes que se colan por las puertas traseras. La gente se los traga — pero la migra también se los está tragando. Esto nos toca a nosotros.
How DPRK IT workers launder money through crypto
A new report traces the money trail from North Korean IT workers back to the wallets and exchanges where the cash piles up. The workers ship code and design services to clients overseas, get paid in crypto, and funnel it through layers of wallets and exchanges before it hits traditional rails.
The trick isn't the tech — it's the routing. A single project can pass through half a dozen wallets across multiple blockchains before landing in a Korean exchange that eventually wires the money into the real economy. The chain of custody is messy enough that most auditors stop looking.
Why this matters for us: North Korea's IT sector is a quiet engine of revenue for the regime, and as long as the crypto routing stays opaque, that money keeps flowing — quietly enriching officials while the world watches other things.
OpenAI's hack shows the AI arms race is running faster than its brakes
OpenAI just had a hacking incident — the kind that happens when a company ships features faster than it ships security. The story is that OpenAI's systems were breached while the company was busy racing to ship new models. The breach itself is still being investigated, but what's clear is that the company's infrastructure is a moving target. While OpenAI's competitors are shipping new capabilities every month, OpenAI is shipping new infrastructure every week. And every new thing is a new surface for attack.
The timing is telling. This isn't an isolated glitch; it's a pattern. OpenAI is the bellwether of what happens when you move fast and break things, and now the things being broken include the things that hold your data. The company's security team is trying to play catch-up with a product team that's already three sprints ahead. The breach is a reminder that speed has a cost — and the cost is getting paid by customers, not shareholders.
Why this matters for us: la gente that trusts OpenAI with their data should know the company is racing ahead of its own security, and that's not a problem that gets fixed by a blog post. It's a structural issue — the faster the ship moves, the harder it is to patch the hull.
You're not just approving a new device — you're leaving the key on the door.
— scamdrill.com
#m365-phishing-is-now-riding-device-codes-and-your-phone-is-the-key-6f901bVerifying AI models with math, not just tests
Georg Wiese is writing about formal verification for AI — proving things about models with math instead of running them through tests. Tests tell you what happened; proofs tell you what must be true. That's the difference between checking a lock worked and knowing the lock…
La IA encontró un bug en Linux que nadie vio en 15 años
Una herramienta de inteligencia artificial revisó el código base de Linux y descubrió un error de raíz — un bug que vive en los archivos más esenciales del kernel — y que los ingenieros humanos dejaron pasar por quince años. El hallazgo no fue una optimización elegante ni un…
Apple PrismML: modelos de IA más grandes, directo en el teléfono
Apple está lanzando PrismML — un modelo de inteligencia artificial más grande que corre directamente en el dispositivo, sin depender de la nube. El avance no es solo que el modelo sea más grande, sino que Apple resolvió el empaque: compresión, cuantización y un runtime nuevo que mantiene los tiempos de inferencia aceptables sin sacrificar la privacidad.
Lo interesante es la dirección. En vez de mandar cada consulta a un servidor — como hacen ChatGPT o Claude — los datos se quedan en el hardware. Eso cambia el costo por consulta, la latencia y la dependencia del ancho de banda. Para la comunidad que usa el teléfono en zonas con conexión intermitente, y para cualquiera que no quiere que Apple lea sus archivos, esto importa.
Por qué esto nos importa: menos dependencia de la nube significa menos suscripciones, menos interrupciones cuando la señal falla, y más control sobre los propios datos — todo sin cambiar la forma en que usamos el teléfono.
Why this matters for us: menos dependencia de la nube significa menos suscripciones, menos interrupciones cuando la señal falla, y más control sobre los propios datos — todo sin cambiar la forma en que usamos el teléfono.
Starlink's satellite internet is now the unkillable Wi-Fi for a $114B crime empire
The Ministry of Cyber Affairs dug into how Starlink went from a space-age novelty to the nervous system of a sprawling crime operation worth over $114 billion — money laundering, fraud, darknet markets, the whole shebang. The secret is that Starlink doesn't rely on any one…
Claude, Copia, y la brecha — un flaw que deja abierta la puerta
Un error en el modo Copia de Claude permite que un agente se pase a otro usuario. Si tu agente está corriendo mientras tú duermes, y se conecta a la cuenta equivocada, puede ejecutar acciones — escribir, borrar, pagar — en la cuenta incorrecta. No es grave por sí solo: se puede configurar para ser estricto. Pero es un recordatorio de que los agentes no son tu escritorio; son un instrumento que se lleva y se pone en cualquier mesa.
La pieza es de TLDR InfoSec. El equipo que la escribe sabe de lo que habla; no es un rumor de Twitter. El fix está publicado. La lección es simple: si los agentes se mueven por la red, la red tiene que saber quiénes son.
Why this matters for us: cada herramienta que instalamos para la comunidad — la migra app, la herramienta de la abuela para el correo — ahora corre agentes que hablan con otros servicios. Un bug como este es la diferencia entre que tu abuela pague su factura en la cuenta correcta y que pague en la del primo por error.
Claude Cowork has a hole that lets AI agents slip through
Researchers spotted a flaw in Claude Cowork that could let an AI agent pretend to be a real person. The vulnerability sits in how Cowork validates incoming requests — the gate isn't as tight as it should be.
The fix is already in. If you've updated Cowork, you're good. The…
Claude Code now runs in the iOS simulator — yep, the whole thing
Anthropic shipped Claude Code for iOS, and you can run it right in the simulator. No app store, no wrapper. Just Claude Code itself, compiled for Apple Silicon and talking to the API like it's at a terminal.
Simon Willison is the one who spotted it first. He's been following the Claude partner network since the early days and knows how these things land. The pair of them — Simon and Thariq — have been working on this for a while, and the result is lean: the model, the code, the prompts, all running on an M-series Mac without the usual scaffolding.
Why this matters for us:
If tools start running natively on our Macs instead of behind some web wrapper, they get faster, stay offline when the internet drops, and stop charging us per request. This is what the future looks like — quiet, fast, and under our feet.
Google's Gemini Flash is the Mythos rival nobody saw coming
Google just shipped Gemini Flash, a model it's positioning as the real threat to Anthropic's Mythos. The company is betting hard that Flash can do the heavy lifting — reasoning, coding, long-context — at a fraction of the cost that's been keeping the rest of the industry…
Google fights back with Gemini Flash — a cheaper, faster model for the real world
Google released Gemini Flash, a model that's faster and cheaper than the Gemini Pro it replaces, and it's aimed squarely at the open-source models like Mistral and Llama that have been eating its lunch. The model is 40 percent faster in production and costs about half as much. It runs on a new 8B parameter architecture — not the massive 70B+ models everyone's chasing — and it's optimized for the kind of work that actually ships: chatbots, search, image generation, the daily grind.
The real story isn't the specs. It's the timing. Open-source models have been getting better every quarter, and they're cheaper. Gemini Flash is Google's answer — a model that doesn't need to beat GPT-5 at its own game, just run the same work for less money and faster. For the folks running APIs, hosting their own models, or choosing between vendors: this is the kind of move that shifts pricing without anyone noticing.
Why this matters for us: Google's making the models cheaper and faster so the tools we depend on — search, docs, Translate — don't slow down when we're trying to get things done.
Roblox is betting on world models — and they're open-sourcing the engine
Roblox is putting its chips on world models, the kind of systems that learn how the world works — gravity, objects, cause and effect — rather than just recognizing what they see. They've open-sourced the engine, which means anyone can grab it and run it on their own hardware.…
Roblox is betting its future on world models
Roblox is rolling out world models — the same kind of AI that powers OpenAI's Sora and Google's Sora 2 — to generate 3D environments from a single image. You point it at a picture, it builds you a playable world you can walk through. The tech is still early: the geometry is loose, textures are a bit wobbly, and you can see the seams. But the idea is clear. Roblox wants to move from a game platform to a creation engine, and it's betting the next wave of games and experiences won't be built by hand, but grown by AI.
Why this matters for us: when a kid in East LA makes a game on Roblox, it's probably made with AI tools — not because a Silicon Valley engineer told them to, but because the tools are cheaper, faster, and the games they make are the ones their friends actually play.
Why this matters for us: world models are the first step toward a Roblox where anyone can turn a sketch into a world — and the kid who draws the best sketch owns the IP, not the studio.
Goodput beats throughput when your LLM is actually fast — not just busy
Goodput is the throughput of useful tokens — the ones that end up in the final answer. Throughput counts everything, including wasted tokens the model generated and then threw away because the prompt was too long or the answer was already complete. When the model is…
Keeping the KV cache warm — measuring prompt cache eviction across Anthropic, OpenAI, and Google
TLDR DevOps wrote a practical post on prompt cache eviction, comparing how Anthropic, OpenAI, and Google handle the KV cache in their LLM APIs. The cache lets repeated prompts reuse prior computation — if the cache stays warm, you pay less. If it evicts, you pay again.
The article walks through real measurements: how long each provider keeps the cache alive, what triggers eviction, and how much you save by keeping prompts close together in time. The numbers differ by provider, but the pattern is clear — eviction is a silent cost you don't notice until your bill does.
For us, this is the kind of infra detail that shows up in the margin. We run models through multiple providers and cache aggressively, so the difference between warm and cold matters more than most. If we can keep the cache hot across our API calls, the savings compound.
Why this matters for us: the cache is a quiet lever — warm cache means lower latency AND lower cost on every call we make, and the providers don't always tell you when it's about to expire.
Former GitHub CEO builds a new code host for the vibe-coding era
Tom Preston-Werner — the original GitHub co-founder who sold the company to Microsoft for $7.5B in 2018 — has launched a new platform called Registerspills. It's a code host designed specifically for the age of vibe coding, where AI does most of the heavy lifting and human…
Meta's new AI can now generate images of you from your Instagram — and you're opted in
Meta is rolling out an AI image generator that uses your Instagram photos to create new pictures of you — the kind of thing where you don't notice it's fake until you look closer. The catch: it's on by default. If you've got an Instagram account, you're in. No opt-out prompt, no special setting to toggle. You just start showing up in their results.
This is the kind of quiet shift that matters because it keeps happening. Meta has been training these models on user content for years, but they've been slow to tell people. The technology works — and it's good enough to fool people. That's worse than bad. It's the kind of thing that quietly becomes part of how we see ourselves.
Why this matters for us: la gente uses Instagram as our second home — family photos, the kids, the abuela's birthday, the cousin's wedding. If Meta is using our pictures without asking, we're not just giving them data, we're giving them our faces.
Tu LLM está mintiendo — y la gente se está tragando el cuento
Researchers found a sharp rise in AI tools that are feeding on their own output. Models trained on LLM-generated text start to hallucinate: they repeat patterns, invent facts, and confidently deliver garbage. The problem compounds as more tools scrape each other's output for…
Google launches Mantis to scan your code for AI leaks
Google's open-sourced Mantis (github.com/google/mantis) is a tool that checks your code for secrets — API keys, tokens, credentials — that might have bled into the codebase when you pasted prompts into your editors or left them in config files.
It's the kind of housekeeping that used to be manual. You'd grep for Bearer, for your AWS key, for the long hex strings that look like nothing but aren't. Mantis does this automatically and flags what needs moving to a real secrets manager. The project is by Momen Basel and is available as a CLI tool you can run before committing.
Why this matters for us: every Brown developer who's copy-pasted a Claude prompt into their terminal has left a token lying around. Mantis catches that before it leaks into a public repo.
Takeoff goes long — and Sierra buys it
Sierra has acquired Takeoff, the startup behind the Takeoff agent framework. The company has been quietly building something different from the rest of the agent crowd: long-horizon agents that plan and execute over hours or days rather than a single turn. The Takeoff agents…
Google writes the rulebook on AI economics — and it's not for the cloud boys
Google released a long-form research piece on the economics of AI, and it reads less like a tech whitepaper and more like an argument about who actually gets paid when AI gets built.
The piece covers the cost stack — chips, compute, data, and the labor that feeds it all — and then maps out how value flows through the system. The thesis is simple: most of the money stays with the chip makers and the compute platforms. The models, the apps, the wrappers? They're squeezing margins thin.
What's interesting for us is the part about infrastructure. Google is positioning itself as the foundation layer, the thing everyone else has to rent. That's the same play Intel was making with x86, the same play the Big Four is making with the bank rails. Whoever controls the substrate controls the toll.
Why this matters for us: if the money flows up to compute and chips, then the companies building on top — the ones we serve with tools and consult for — are fighting over scraps. We need to be on the foundation side, not the wrapper side.