FCC Bars New Foreign-Made Humanoid and Quadruped Robots From the US Market
The July 28 covered-list update follows White House-convened national security determinations and leaves previously sold models unaffected, while Microsoft disclosed a Russian spy campaign hijacking hotel Wi-Fi captive portals worldwide.

On this page
On July 28, the Federal Communications Commission added “advanced robotic devices” — mobile robots such as humanoids and quadrupeds — and connected power inverters to its Covered List, following determinations by a White House-convened Executive Branch interagency body that the foreign-made products “pose unacceptable risks to the national security of the United States or the safety and security of United States persons.” Under the FCC’s Covered List rules, the action bars new models from equipment authorization, effectively stopping them from entering the US market. Devices already sold and previously approved models are unaffected, agencies can grant conditional exemptions, and federal government use is not affected at all.
MIT Technology Review reports the ban could pinch US robotics research: an internal review by the Association for Advancing Automation found 90 percent of recent robotics papers from US universities relied on robots from China’s Unitree, whose four-legged models cost around $4,600 versus roughly $278,000 for a comparable Boston Dynamics unit. The magazine credits the Federal Trade Commission with the ban; the FCC’s announcement and AP reporting identify the Federal Communications Commission as the acting agency.
Featured source: MIT Technology Review , FCC fact sheet .
Other Stories
Microsoft Says Russian State Group Hijacks Hotel Wi-Fi Captive Portals to Deliver Malware
Microsoft Threat Intelligence says a sub-cluster of the Russian state-sponsored group Midnight Blizzard, tracked as Storm-2945, has since early May been compromising captive-portal equipment in hotels and conference centers worldwide, redirecting guests to fake Microsoft 365 sign-in pages, device-code phishing flows abusing Microsoft Entra ID, and fake browser or OS update pages. The campaign, which Microsoft calls CaptiveCrunch, delivers CornFlake, an infostealer that can capture keystrokes, clipboard, microphone and webcam input, and CocoShell, an in-memory PowerShell payload targeting browser cookies, passwords, and Microsoft tokens. Microsoft did not disclose how the devices are compromised; ReliaQuest independently reported part of the activity on July 23.
Filed from: The Register , Microsoft Security Blog .
EU AI Act Transparency Obligations Take Effect
New transparency obligations under the EU’s AI Act took effect on August 2, requiring providers to design systems that notify users when they interact with AI “unless this is obvious,” embed machine-readable marks in synthetic audio, image, video and text, and requiring deployers to label AI-generated or manipulated deepfake content designed to look real. Non-compliance risks fines of up to €15 million (about $17.2 million) or 3 percent of global annual turnover. The rules bind new systems immediately; models and services launched before August 2 have until December 2 to comply, and the European Commission has published optional disclosure labels while stressing its labeling requirements are not optional.
Filed from: The Verge , European Commission .
OpenAI Publishes Messages Rebutting Apple’s Trade-Secrets Lawsuit
OpenAI publicly responded to Apple’s trade-secrets lawsuit on August 3, calling it “careless, aggressive and oddly personal.” OpenAI says Apple’s lawyers emailed the wrong person in February after confusing two Asian last names, that Apple conceded a claimed discussion with OpenAI’s general counsel never happened, and it published iMessage exchanges showing Apple employees asking former engineer Chang Liu — whose last day was January 22, 2026 — to help locate files while he was leaving. Reuters reports Apple is seeking a preliminary injunction. The response is OpenAI’s account of the dispute; Apple had not publicly replied to the latest filing at publication.
Filed from: OpenAI , The Guardian .
Researchers Say AI-Generated Fake Vulnerabilities Are Flowing Through the CVE Pipeline
Software supply-chain security firm JFrog reported that a batch of SQLite advisories published through a newly created GitHub repository — plus about 49 others claiming flaws in libraw and an ESP32 audio library — appear to be AI-generated and do not describe reproducible vulnerabilities. Six SQLite reports carrying CVSS scores from 7.5 to 9.8 cited functions that did not exist in the affected versions, and none of the proof-of-concept payloads triggered crashes; Red Hat initially assigned one of the advisories, CVE-2026-51302, a maximum 10.0 severity score before lowering it. JFrog argues that because no step in the current system requires a proof of concept, plausible fake advisories can reach GitHub Security Advisories and enterprise scanners.
Filed from: The Register , JFrog Security Research .
UNAM Orders In-Person Retest for 58,000 After AI-Proctored Exam Results Spike
Mexico’s National Autonomous University will re-examine roughly 58,000 applicants in person after its first fully remote, AI-proctored entrance exam produced implausible results. The share of applicants scoring 100 or more of 120 jumped from 3.5 percent in 2021–2025 to 16.3 percent this year, and the share scoring 110-plus from 0.9 to 5.5 percent, prompting a commission to recommend a “control exam” for this year’s admitted applicants and anyone admitted since 2021 on minimum qualifying scores. The exam used Respondus LockDown Browser and Territorium webcam monitoring with one human supervisor per 150 applicants, and the university acknowledged “the probability that a significant number of applicants may have received help”; AI researcher Raul Rojas told NPR that statistical modeling suggested “almost half of the students were cheating.”
Filed from: Ars Technica , Gaceta UNAM .
Dark Web Leak Exposes Data on 100,000+ UK Police and Justice Staff
The UK’s Police National Legal Database confirmed that a weekend cyberattack led to the theft of names, organizations and work email addresses of more than 100,000 criminal justice professionals, including police officers, staff, government partners and customers. The group ExfilSquad claimed responsibility, posting about 1.9 GB of records on the dark web and demanding a ransom. PNLD said there is “no evidence to suggest that passwords or other security credentials have been compromised,” that it notified the National Crime Agency and the Information Commissioner’s Office, and that the method attackers used to enter was not disclosed.
Filed from: TechRadar , BleepingComputer .
MediaTek Lines Up $5B War Chest for AI Datacenter Push
MediaTek’s board approved $5 billion in financing to expand from AI ASIC chips into full systems and platforms, targeting what the company expects to be an up-to-$80-billion AI datacenter silicon market next year. CEO Rick Tsai told analysts on the Q2 2026 earnings call that “agentic AI” demand is driving compute growth across cloud and edge, and MediaTek says its first ASIC family, developed in “close partnership with major US cloud service provider customers,” enters production in the fourth quarter of this year. The company believes it can capture 15 to 20 percent of the market; the figures are MediaTek’s own, and analysts quoted by The Register are skeptical.
Filed from: The Register .
Apple Challenges UK Government’s Renewed Encrypted-iCloud Demand
Apple has filed a legal complaint at the UK’s Investigatory Powers Tribunal challenging a second “technical capability notice” that reportedly demands access to UK users’ encrypted iCloud data, according to a Financial Times report confirmed by The Guardian. The complaint was filed last month and contests the government’s powers to issue such notices under the Investigatory Powers Act. The UK abandoned its original 2025 demand after US intervention, and Apple subsequently withdrew UK users’ access to its end-to-end encrypted Advanced Data Protection feature in January 2025; details of the secret order remain undisclosed, and Privacy International and Liberty have filed parallel complaints against the regime.
Filed from: TechCrunch , The Guardian .
macOS Flaw Fixed After Researchers Say AI Bug-Report Flood Delayed Disclosure
Security researchers Bynario disclosed CVE-2026-43760, a vulnerability in macOS Screen Sharing’s legacy VNC password option that lets a network-authenticated viewer create files as root and install a valid sudoers policy, reaching remote root command execution. Apple fixed it in macOS Tahoe 26.6, released July 27, and macOS Sonoma 14.8.8, describing the issue in its advisory as one where “an app may be able to access user-sensitive data” — an impact Bynario says the company understated; the researchers assess the demonstrated impact at CVSS 8.0 High versus Apple’s assigned 5.5. In a separate note, Bynario said Apple had to limit how many bug reports individual researchers can keep open because its security teams were flooded with AI-generated submissions.
Filed from: TechRadar , Bynario .
Base Power Raises Another $1B to Save the Grid Using Backyard Batteries
Base Power, which installs residential batteries as a subscription service in Texas and Illinois, raised a $1 billion Series D at a $13 billion post-money valuation less than a year after its previous billion-dollar round. The company says it has installed more than 500 megawatt-hours of storage, is installing about 100 batteries per day, and unveiled Base Core, a 39.2 kWh home battery built at its Austin, Texas factory; in the Houston area it charges $695 to install a single battery, $19 per month, and 13.1 cents per kilowatt-hour for electricity. The round arrives as US electricity demand surges on electrification and AI data center construction; the financial figures are company-announced.
Filed from: TechCrunch .
UK Consults on Requiring Employers to Consult Staff Before Deploying Workplace Monitoring
The Department for Business and Trade is consulting until September 30 on whether employers in Great Britain should have to consult recognized unions or elected staff representatives before introducing workplace monitoring technology, ranging from CCTV and biometrics to keystroke logging, location tracking and AI productivity scoring. Options under consideration span non-statutory guidance, a statutory code of practice, or a legal consultation duty, with the government warning of “risks to privacy and autonomy” and biased outcomes from automated decision-making. The consultation, part of the Make Work Pay reforms, cites research that one in three UK organizations now actively monitors employees’ digital activity, up from one in five two years earlier.
Filed from: The Register , GOV.UK consultation .
Cloudflare Agents Launches With Agent Tracing
Cloudflare, midway through its Agents Week, introduced Cloudflare Agents, bringing all deployed agent sessions on its platform into a single dashboard experience with new observability. Agent tracing records every model call, tool execution, token count, approval event, and supported subagent call for OpenTelemetry-compatible agent harnesses including Think, Flue, and the AI SDK, alongside existing Workers infrastructure traces, with export to any OpenTelemetry-compatible destination. Cloudflare says agents can return HTTP 200 and still fail, and positions agent-level telemetry as the first step toward deploying, observing, and continuously improving agents; the announcement is the company’s own, with no independent evaluation available.
Filed from: Cloudflare Blog .
ChatGPT Dominates Paid AI Spending in Congress
CNBC’s analysis of House disbursement records through March 31 found OpenAI received roughly 90 percent of all spending on AI tools by House offices, committees, and institutional accounts: about $100,580 across 798 transactions, out of at least $113,740 in total AI spending. Anthropic’s Claude was second at $13,160 across 37 transactions, and Democratic offices outspent Republican ones $54,165 to $15,782. Staffers use the tools to draft memos, summarize and analyze legislation, respond to constituents, and prepare hearing materials; the figures exclude free accounts and AI bundled into broader software contracts.
Filed from: TechCrunch , CNBC .
From the Community
Keyv and Related npm Packages Compromised in Active Shai-Hulud Supply Chain Attack
On August 4, attackers compromised the GitHub account of the maintainer behind keyv, a key-value storage library with roughly 127 million weekly npm downloads, and used that access to inject a credential-stealing worm across the entire package family, including cacheable, flat-cache, and file-entry-cache. Malicious files were pushed directly to the main branch and new releases cut immediately, so poisoned versions were published to npm with valid provenance signed by GitHub Actions. Security firm Aikido says at least 868 packages across 1,381 versions have been compromised, with over 2 billion monthly installs combined; the worm’s payload harvests credentials from npm, GitHub, AWS, Kubernetes, Vault, and other sources before exfiltrating them to a public GitHub repository. The details come from Aikido’s vendor analysis, and the full scope of the compromise is still emerging.
Filed from: Aikido Security .
OpenAI Reports Ten AI-Discovered Advances in Mathematics and Theoretical Computer Science
OpenAI announced ten results that resolve or make substantial progress on long-standing open problems in fields including high-dimensional geometry, coding theory, group theory, and quantum complexity. The results were generated by an internal version of its Astra model, with human-prepared manuscripts and Lean formalizations, and the company says the total compute cost for finding solutions was roughly $2,000 at Sol API rates. OpenAI also acknowledged concerns about AI’s role in mathematics by referencing the Leiden declaration and stating that claiming human authorship for AI-generated proofs would misrepresent the system’s contribution; the results are from an internal model and have not yet been peer-reviewed.
Filed from: OpenAI .
DeepSeek V4 Flash Runs on a Single AMD MI300X With Production Configuration
A new GitHub repository documents a production configuration for running DeepSeek-V4-Flash-0731, a 304B-parameter model, on a single AMD MI300X GPU, using vLLM ROCm nightly and AITER with patches for FP8 format differences and MoE routing bugs. The entire model fits in the MI300X’s 192 GB HBM, avoiding weight streaming or offload, and the setup reports uncached prefill speeds of 7.9–8.5K tokens per second with a 2,048-token scheduler budget for latency isolation. The work builds on prior bring-up efforts by Fergus Finn and Doubleword and includes fixes not yet merged upstream.
Filed from: GitHub repository .
Swiftlet Runs 80B Qwen in 4.3 GB of RAM on a Mac, and 35B on an iPhone
Swiftlet is a Swift + Metal runtime for Qwen3-Next and Qwen3.5/3.6 MoE hybrid models that streams routed expert weights from storage on demand, keeping only the small dense core resident in memory. It runs the 80B model in 4.3 GB of RAM on a Mac at 4.5–5 tokens per second and the 35B on an iPhone 17 in about 2.5 GB at roughly 1 token per second, and is Apache-2.0 licensed with a CLI, server, and iOS app integration. The author notes that only about 3B parameters are active per token, so the models chat like large models but recall facts like small ones.
Filed from: GitHub repository .



