Newsletter

Alibaba Releases Qwen3.8-Max, an Open-Weight Model It Says Rivals Claude Fable 5

The 2.4-trillion-parameter model trails only Anthropic's Claude Fable 5 on Arena's text leaderboard and gets open weights next week, while Samsung moves to purge smart TV apps that enlist viewers' connections in residential proxy networks.

A wide view of the Alibaba Group headquarters campus in Hangzhou under a bright sky, with several office towers and low buildings.
Lead image Illustrative photo: the Alibaba Group headquarters in Hangzhou. Alibaba released Qwen3.8-Max, its largest open-weight AI model to date, on August 3; the image depicts the company behind the release, not the model itself. · Image: Thecraft · CC BY-SA 3.0
On this page

Alibaba released Qwen3.8-Max on Monday, calling it its largest and “most capable AI model to date” and claiming performance rivaling the best systems from Anthropic, OpenAI, and Moonshot AI’s Kimi K3. The 2.4-trillion-parameter model trails only Claude Fable 5 and three Claude Opus models on Arena’s text leaderboard; for frontend coding it is beaten only by two Opus models and Kimi K3, and for visual analysis only Fable 5 ranks ahead. Alibaba said it will publish the model’s weights next week, a return to open-weight releases after the company briefly pivoted to proprietary models for its more advanced systems earlier this year.

The release follows Moonshot’s open-weight Kimi K3 last week and comes as Washington debates whether broader restrictions on Chinese open-weight models would hurt American developers. The performance figures are Alibaba’s own testing plus Arena rankings, and parameter counts are a loose proxy for capability: Moonshot’s Kimi K3 has 2.8 trillion parameters, while OpenAI and Anthropic do not disclose counts for their top systems.

Featured source: The Verge , Qwen blog .

Samsung Bans Smart TV Apps That Enlist Owners’ Connections in Residential Proxy Networks

Security research from Norwegian firm Mnemonic found several popular Samsung smart TV apps, including a Pac-Man game Samsung featured in its “Editor’s Choice” section, contain code that can turn the TV into an exit node for residential proxy networks. Samsung told TechCrunch it has restricted new app registrations with such functionality, is implementing policies explicitly banning residential proxy SDKs, and is working to remove affected apps. The move follows LG’s July announcement of a similar ban after reporting found about 42 percent of apps on its store enlisted smart TVs into proxy networks; Mnemonic warns that “what was reviewed is not necessarily what is running.”

Filed from: TechCrunch , Mnemonic research .

Researchers Show AI Can Undetectably Modify DNA Evidence Files From US Crime Labs

Forensic and computer scientists say software used by top US crime labs to analyze DNA evidence has a vulnerability that allowed them to use an AI model to undetectably modify computerized scans of physical evidence, the Wall Street Journal reported. Because the digital files date to 1995, the researchers say 30 years of crime-lab records could be at risk of tampering; a systems engineer at Forensic Bioinformatics exploited the flaw in 45 minutes using Anthropic’s Claude, including a decryption key found on the internet. Thermo Fisher Scientific, whose equipment is used across most US facilities, acknowledged the issue privately in July and says a fix implementing digital signatures is in progress; the company says there are no known instances of exploitation.

Filed from: TechRadar .

CrowdStrike Says AI Is Both the Weapon and the Target in the Latest Wave of Cyberattacks

CrowdStrike’s annual Threat Hunting Report says attacks by AI-enabled adversaries rose 89 percent in 2025, with documented techniques including LLMjacking — stealing corporate credentials to reach frontier-model APIs — and cost harvesting, deliberately inflating a victim’s AI usage to run up its bill. The vendor says a token thief sent about 200,000 API requests in two minutes, and that AI agent-triggered threat leads now arrive at 2.5 times the rate of human-triggered ones. All figures are CrowdStrike’s own, relayed by The Register.

Filed from: The Register , CrowdStrike 2025 Threat Hunting Report .

Horizon3 Raises $250M Series E at a $2B Valuation for AI-Driven Security Testing

Cybersecurity startup Horizon3 raised a $250 million Series E at a $2 billion valuation, more than tripling its valuation in 14 months, with returning investors NightDragon and NEA. Its NodeZero platform tests live systems continuously rather than annually, and the company says it approached $100 million in annual recurring revenue last year with 120 percent year-over-year growth, and has run 310,000 production security tests with zero disruptions. Strategic investors include Singapore’s EDBI, defense contractor SAIC, and Qualcomm; the financial and performance figures are company-provided and not independently verified.

Filed from: TechCrunch .

Microsoft Pledges to Cut Windows 11’s Memory Footprint on 8GB Laptops

Microsoft’s Windows chief Pavan Davuluri, in a July 31 update on the quality commitment the company made in March, added four new workstreams including “memory optimization for 8 GB and above,” aiming to reduce Windows’ memory footprint through a more efficient memory allocator, continued tuning of WinUI 3, and efficiency work in the Chromium and WebView2 components Windows carries. Windows 11 still lists 4 GB as its minimum while Copilot+ PCs require 16 GB of DDR5/LPDDR5, so Microsoft now explicitly targets 8 GB machines for a “fast and responsive” experience. Davuluri’s post is a progress report, and much of the work has not yet reached production builds.

Filed from: The Register , Davuluri’s Windows Insider post .

Google Pulls AI Image Generation From Google Earth After Less Than 48 Hours

Google launched AI image generation with Nano Banana inside Google Earth, letting users reimagine any location with a prompt, then rolled the feature back in less than 48 hours after users shared generated imagery that appeared to violate its policies. Google said the output was watermarked as AI-generated and that it is implementing stronger guardrails; misinformation researcher Henk van Ess said the feature is “paused, not cancelled.” Google’s statement is the only public account of what triggered the rollback.

Filed from: The Register .

Cloudflare Ships @cloudflare/computer, an Agent Runtime Built on Isolates

Cloudflare, opening its Agents Week, introduced an early preview of @cloudflare/computer, an open-source library that gives each agent a durable filesystem and a choice of execution environments spanning isolates, containers, and browsers, with all operations gated, audited, and observed. The company argues a container per agent will not scale to billions of concurrent agents and positions its isolate-based runtime as the more efficient primitive; the package runs on any Durable Object and is installed via npm. It is an early preview from a company announcement, with no independent evaluation.

Filed from: Cloudflare Blog .

Global Memory Shortage Hits the MacBook Air

The memory chip shortage, driven by AI companies’ demand, is now constraining Apple’s MacBook Air after already affecting the Mac mini and Mac Studio, Bloomberg’s Mark Gurman reports. Retailers describe supply as more constrained than before, and Apple’s website shows order waits until the back half of August, or September for certain configurations. Apple is reportedly addressing the shortage by raising prices and sourcing memory from Chinese suppliers; no timeline for supply normalization has been given.

Filed from: TechCrunch .

Palantir and Armada Ship an AI Data Center in a Shipping Container for Combat Zones

Palantir and infrastructure partner Armada have begun deploying mobile data centers built inside standard shipping containers for combat zones. Each unit carries its own computing hardware, storage arrays, networking gear, and cooling, runs on Nvidia B300 accelerators, and integrates with Palantir’s modular AIP platform; the companies say the containers can process data without a constant connection to public cloud infrastructure and can be fully isolated from external networks when required. The specifications and capabilities are the companies’ own claims, with no independent evaluation available at publication.

Filed from: TechRadar .

Xbox Prices Rise by Up to €200 or £170 as Memory Costs Climb

Microsoft’s latest Xbox price increases, announced for the US in June, now apply to the EU and UK, with rises of up to €200 or £170 depending on the model. The 1TB Xbox Series X with a disc drive goes from £499.99 / €599.99 to £669.99 / €799.99 — over 30 percent — and the 512GB Xbox Series S from £299.99 / €349.99 to £429.99 / €499.99, more than 43 percent. It is Microsoft’s third round of increases since May 2025, and the company attributes the rises to RAM and storage prices climbing on AI-industry demand.

Filed from: The Verge .

Why Silicon Valley Is Divided Over China’s Powerful, Cheap AI Models

Low-cost Chinese open-weight models are splitting US tech executives and Washington, Rest of World reports. Moonshot’s Kimi K3 ranks fourth on the Artificial Analysis intelligence index behind Anthropic’s Opus 5 and Fable 5 and OpenAI’s GPT-5.6 Sol, and adoption of Chinese models is rising inside US companies that want cheaper inference. Nvidia’s Jensen Huang posted an open letter on July 24 stressing the importance of open models, joined by Microsoft, Google, and Meta, while a group of 179 Silicon Valley startups asked the Trump administration to preserve access; on the other side, Anthropic’s Dario Amodei has called for restrictions, and administration advisers are split, with technology adviser Michael Kratsios accusing Moonshot of distilling Anthropic’s Fable 5 and Treasury Secretary Scott Bessent warning of sanctions over “distillation attacks.” The debate was complicated last month when Hugging Face used the open model GLM-5.2 to analyze an OpenAI agent attack after leading American models declined the defensive work, and no security backdoors have been publicly documented in major Chinese models.

Filed from: Rest of World .

UK Government Investment Arm Admits 40-Hour Exposure of Officials’ Contact Details

UK Government Investments, the Treasury-owned corporate finance adviser, disclosed in its annual report that an employee left an internal file containing the names and work email addresses of 51 government officials publicly accessible for around 40 hours. UKGI said it voluntarily reported the incident to the Information Commissioner’s Office, informed its Audit and Risk Committee, and commissioned an external review; it has not said where the file was hosted or whether anyone accessed it. The ICO confirmed it is assessing the information provided.

Filed from: The Register .

From the Community

JFrog Reports a Batch of Fabricated SQLite CVEs

JFrog security researchers found that a batch of SQLite CVEs, including CVE-2026-51302, were fabricated: the advisories, published by a newly created GitHub account, were initially flagged as critical by NVD and CISA’s ADP, but cited code that does not exist in the targeted versions, and proof-of-concept tests did not trigger crashes. JFrog’s audit of 55 advisories from the same account found 54 to be completely fabricated, and none appear on SQLite’s official advisory page. JFrog has reported its findings to GHSA, Red Hat, and NVD; its analysis is based on its own testing, and official CVE records may still be in flux.

Filed from: JFrog Security Research .

Rust Project Goals: Immobile Types and Guaranteed Destructors

The Rust project has proposed new auto-traits Move, Destruct, and Forget to make type capabilities explicit, allowing types to opt out of being moved or forgotten. The goal is to simplify self-referential types and enable safe scoped spawn for async, potentially deprecating Pin in the long term. The proposal is a project-goals document, not yet implemented; it plans an MVP in the compiler with validation through real-world testing in the Linux kernel.

Filed from: Rust project goals .

F*: A Proof-Oriented Programming Language With Production-Grade Verification

F* is a general-purpose proof-oriented programming language that combines dependent types with SMT-based proof automation and tactic-based interactive theorem proving, compiling to OCaml by default with fragments extractable to C, Wasm, or assembly. Its verified cryptographic libraries (HACL*, EverCrypt) are used in Firefox, the Linux kernel, and Python, while EverParse parsers validate every network packet in Azure. Developed by Microsoft Research and Inria, F* is open source under Apache 2.0.

Filed from: F* website .

AI Migrated Legacy COBOL Programs to Java, Bugs Included

A new arXiv paper proposes an agentic test-synthesis method called the “Locksmith Loop” to validate AI-generated Java migrations of legacy COBOL programs. The method uses mocks and iterative exploration to improve branch coverage, achieving nearly complete coverage on open-source programs and 91.90 percent on a production-like COBOL program, with the generated Java matching the COBOL reference under deterministic parity checks in all accepted test cases. The paper is a preprint and not yet peer-reviewed.

Filed from: arXiv paper .

Bonsai: Jane Street’s UI Library for OCaml

Jane Street has open-sourced Bonsai, a UI library for building performant, reactive web applications in OCaml, partly inspired by Elm and used internally for almost all of the firm’s web applications. Bonsai components are purely functional state machines, and the framework provides incrementalization and composable state management, plus a templating language, component-specific stylesheets, and whole-app automated tests. The project is open source but has primarily been used inside Jane Street.

Filed from: GitHub repository .

Kakehashi: A Userspace Translation Layer to Run macOS Binaries on Linux ARM64

Kakehashi is an experimental userspace translation layer that runs macOS ARM64 binaries on Linux aarch64 without a JIT, loading Darwin Mach-O files and translating BSD syscalls. It has demonstrated support for tools like clang, 7-Zip, and curl on Docker/Colima and UTM, with the goal of cutting CI costs by using cheaper Linux ARM64 runners instead of macOS. The project is Apache-2.0 licensed, not derived from Darling, and does not yet support GUI, codesign, or full Apple frameworks.

Filed from: GitHub repository .

CP/M-386: CP/M for 386 Protected Mode, Derived From CP/M-68K

A new open-source project brings CP/M to 386 protected mode, derived from CP/M-68K, supporting full 32-bit protected mode with Ring-3 TPA and bootable via floppy or GRUB with VGA or serial consoles. The project is in early development with no disk or network drivers yet, and aims for high source compatibility with other CP/M implementations under the MIT License.

Filed from: GitHub repository .

FROGS: A Public Benchmark for AI-Generated SVG Quality

The FROGS project is a public dataset and benchmark that asks AI models to generate an SVG of a frog with a Habsburg jaw, testing how well they follow a specific visual prompt. As of August 2026 it has collected 42 runs from 14 models, with all producing SVGs; the benchmark reveals that many models add unrequested royal imagery or anatomical commentary, and some produce deterministic outputs. The benchmark is informal and not peer-reviewed, and the full dataset is available on Hugging Face and GitHub.

Filed from: FROGS website .

Continue reading

Complete index →