Newsletter

New Mexico Court Orders Meta to Pay $567 Million More in Child Safety Case

A Santa Fe district court raises Meta's New Mexico child-safety penalties to $942 million and orders limits on how minors use its platforms, while ByteDance begins pre-training a model that could rival Anthropic's largest systems.

Photograph of the Judge Steve Herrera Judicial Complex, a courthouse building at 100 Catron Street in Santa Fe, New Mexico.
Lead image Illustrative photo of the Judge Steve Herrera Judicial Complex in Santa Fe, home of New Mexico's First Judicial District Court, where the district court ruled on the state's child-safety case against Meta; the photograph dates to 2009 and does not show the ruling. · Image: AllenS · Public domain
On this page

A Santa Fe, New Mexico district court on Thursday ordered Meta to pay $567 million in the second phase of the state's landmark child-safety case, bringing the company's total penalties in the case to $942 million. The court found Meta’s platforms a “significant contributing cause” of a teen mental health crisis affecting public health and safety throughout New Mexico, and ordered the company to abate what it called a “public nuisance.” The new award funds an abatement program covering awareness, prevention, screening, and treatment; it sits on top of the $375 million in civil penalties the court levied in March. The ruling also directs Meta to hide Like counts from children under 18 without parental approval, pause push notifications to underage users between 10 p.m. and 7 a.m., and cap their usage at 90 hours a month.

Meta said it disagrees with the ruling and plans to appeal. “We work hard to keep people safe on our platforms and have been transparent about the challenges of identifying and removing bad actors and harmful content,” spokesperson Andy Stone said. State Attorney General Raul Torrez said Meta “chose engagement and profit over their safety.” The case follows a separate Los Angeles ruling against Meta in March over addictive design, and the company still faces a consolidated lawsuit brought by 33 states in a federal court in Oakland.

Featured source: TechCrunch , The Verge .

ByteDance Trains a Model Approaching Anthropic’s Scale

ByteDance is at an early stage of pre-training an AI model with as many as 10 trillion parameters, roughly three times the size of Moonshot’s Kimi K3, the largest Chinese model released to date, according to three people with knowledge of the effort reported by the Financial Times. Industry estimates put Anthropic’s most advanced Mythos 5 at about 8 trillion parameters. The exact size would be determined later, pre-training typically takes three to six months, and ByteDance’s roughly 2,000-person Seed team has pursued independent development without distilling other labs’ models for more than a year. The parameter counts rest on unnamed sources and industry estimates, and capacity alone does not determine capability.

Filed from: Ars Technica , Financial Times .

AMD Acquires Taalas, the Startup That Etches Models Into Silicon

AMD has reached a definitive agreement to acquire Taalas, the Toronto startup founded in 2023 whose chips encode trained model weights directly into silicon, an approach the company says removes compute-memory bottlenecks and can accelerate inference by an order of magnitude or more. AMD said it will fold the technology into its accelerator roadmap alongside Instinct GPUs and Helios rackscale systems; financial terms were not disclosed. The deal echoes Nvidia’s roughly $20 billion licensing arrangement with Groq last December, and is subject to customary closing conditions and regulatory approvals.

Filed from: The Register , AMD press release .

Anthropic Will Design Its Own Chips for Claude

Anthropic has confirmed plans to build an in-house “custom silicon team” to design chips for running its models, after Business Insider spotted job listings for a silicon engineer and a technical program manager. The company says it will keep a “multi-chip approach,” using other vendors’ hardware alongside its own designs and co-designing new hardware and models side by side. The move follows OpenAI’s announced Jalapeño inference chip developed with Broadcom and in-house silicon already deployed by Google and Meta; Anthropic is still hiring key team members, and The Information previously reported it was considering Samsung as a manufacturing partner.

Filed from: Ars Technica , Anthropic careers .

Google Warns of Phone-Based Hacks Extorting Financial Firms

Google Threat Intelligence reported that UNC6671, the group behind the BlackFile extortion brand, is operating under four newer brands — Redact, Pink, Helix, and Falcon — and compromising large US financial and investment firms through voice phishing: calls to employees’ personal phones that impersonate co-workers or IT helpdesk staff and steer victims to spoofed login portals that intercept credentials and multi-factor codes. Google did not name victims, but Reuters reported that firms including Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG are among them. Google says one cryptocurrency wallet tied to the groups received around $10 million in bitcoin in the first months of the year, with ransom demands typically ranging from $750,000 to $3 million.

Filed from: TechCrunch , Google Threat Intelligence .

Large Genome Models Design New Bacteriophages

Stanford researchers report in Science the first generative design of complete bacteriophage genomes using the genome language models Evo 1 and Evo 2, with the well-studied E. coli virus ΦX174 as a template. Experimental testing of AI-generated genomes produced 16 viable phages with substantial evolutionary novelty, and a cocktail of those phages quickly evolved the ability to infect E. coli strains resistant to a natural bacteriophage cocktail. The authors excluded viruses that infect complex cells from the training data but caution that anyone with sufficient compute could repeat the work with those sequences included, and the paper calls for governance of AI-driven biological design and of custom DNA ordering.

Filed from: Ars Technica , Science paper .

Phishing Attack Reached a US Defense Supplier’s Microsoft 365 Account

US defense and aerospace supplier IEH Corporation disclosed in a Securities and Exchange Commission Form 8-K filed Thursday that a phishing attack gave a threat actor access to an employee’s Microsoft 365 mailbox. The attacker impersonated a prospective business contact and sent a link disguised as a Microsoft document-sharing request, harvesting the employee’s credentials on a fraudulent login page. The intruder had access to email messages, attachments, customer communications, purchase orders, engineering documentation, and potentially export-controlled technical information; IEH said it has found no evidence that data was copied or exfiltrated so far, and that it discovered the intrusion on August 4.

Filed from: The Register , SEC Form 8-K .

Intrusion at Healthcare Software Provider Puts 3.8 Million People’s Data at Risk

Ohio-based medical software maker Unlimited Technology Systems has reported an intrusion that may have exposed sensitive data of 3,803,750 people, the largest healthcare breach reported to US regulators this year according to The Register’s review of the Department of Health and Human Services breach portal. The company detected someone probing its commercial datacenter in October 2025 and disclosed the incident in July without an initial victim count. In a notification letter filed with the Iowa attorney general, UTS said an unauthorized actor may have copied personal information between October 5 and 10, 2025, including names, Social Security numbers, diagnoses, and insurance details.

Filed from: The Register , HHS breach portal .

China Extends Chip-Design Protection to Photonic and Quantum Layouts

China’s State Council has published its first systematic rewrite of the Regulations on the Protection of Layout Designs of Integrated Circuits since April 2001, deleting “semiconductor” from the definition of an integrated circuit and extending layout-design protection to photonic and quantum chips from October 15, 2026. Decree No. 842, adopted July 10 and promulgated July 23, also tightens damages rules and submission requirements and lets third parties request revocation of registrations. Analysts read the change as a claim to future chip-design IP leadership rather than current manufacturing capability, noting that monolithic integrated circuits still require semiconductor substrates.

Filed from: TechRadar , The Register analysis .

OpenAI Gives ChatGPT Free Users Unlimited Text Chats

OpenAI will remove rate limits on text-only conversations for ChatGPT’s free and Go tiers, and is adding a “Think” button for higher-reasoning responses on those tiers, The Verge reports. This week OpenAI also upgraded the default model on the free and Go tiers to GPT-5.6 Luna, with GPT-5.6 Sol described as “more reliable with facts” for Plus and Pro users. Messages that include file uploads and images will continue to have limits. TechCrunch independently reported the same changes.

Filed from: The Verge , TechCrunch .

GitHub Expands Malware Advisories to Eight Package Ecosystems

GitHub’s Dependabot malware alerts, previously limited to npm, now span npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. The expansion works by ingesting OpenSSF’s malicious-packages repository, more than 15,000 OSV-format reports assembled from community submissions and automated detection, into the GitHub Advisory Database through a single importer. For the first time an auto-published malware advisory can trigger a Dependabot alert, and GitHub says it built in batch caps, per-commit provenance, and rollback to survive a poisoned upstream feed; more than half of the new npm reports flowing into the repository each month trace back to GitHub’s own advisories and are skipped as round-trips.

Filed from: GitHub Blog , OpenSSF malicious-packages .

Cloudflare Open-Sources the Agent Workspace It Built Internally

Cloudflare has released Cloudflare OS, the natural-language agent workspace it says thousands of employees use daily to create documents, automate tasks, and build small apps without being developers. The open-source platform runs on Cloudflare Workers, and its security model gives each document or app its own V8 “isolates” from Dynamic Workers, with AI agents starting with no permissions and global outbound networking disabled by default. Ars Technica notes the launch lands alongside a Pillar Security report on sandbox escapes in popular AI coding agents, and quotes Cloudflare engineers asserting the sandbox is restrictive enough for non-technical users to build without introducing serious security flaws.

Filed from: Ars Technica , Cloudflare Blog , GitHub: cloudflare/cloudflare-os .

Runtime Instances Give Bedrock AgentCore Agents Persistent Compute

AWS announced runtime instances for Amazon Bedrock AgentCore, a fully managed compute option that runs agents on EC2 infrastructure with sessions persisting for up to 14 days, GPU-accelerated instance types, and support for multiple collaborating agents on a single host with a shared file system. The service pairs with AgentCore’s existing runtime microVMs, letting a lightweight orchestrator dispatch work to persistent workers handling tasks such as code compilation, security scanning, or GUI automation. Pricing is standard EC2 pricing plus an AgentCore orchestration management fee, and the launch covers US, Asia Pacific, and Europe regions; the feature claims are AWS’s own announcements.

Filed from: AWS News Blog .

AI-Generated Security Patches Fail Most of the Time Without Guidance

Researchers at 1Password’s Off-by-1 Labs generated 6,080 security patches with ChatGPT 5.5 at medium effort and Claude Opus 4.8 at high effort across six recently disclosed CVEs, and found only 26.0% cleanly fixed the vulnerability without changing application behavior. Another 20.1% fixed the issue while altering behavior, 2.3% introduced new security issues, and 49.3% failed to fix at least one existing exploit path. Guidance mattered: success rose to 65.0% with correct initial guidance and fell to about 15.2% with incorrect guidance. The authors argue the expected value of a fully LLM-generated, human-unreviewed patch is “net-negative by a considerable margin” and released a patch-evaluation harness called FLAWED; the study is the lab’s own research and has not been peer-reviewed.

Filed from: The Register , 1Password blog .

Xiaomi Enters Full-Size Hybrid SUVs With the SkyNomad N70 and N90

Xiaomi launched its debut full-size hybrid SUVs, the SkyNomad N70 and N90, pairing a 1.5-liter gasoline engine with 76 kWh NMC battery packs. Announced figures put the electric-only range at 314 miles before the engine is needed, with combined range beyond 1,000 miles; TechRadar reports the models target the Range Rover, Bentley, and Rolls-Royce segment, following Xiaomi’s SU7 and YU7 electric cars. The range figures are manufacturer-announced and have not been independently tested.

Filed from: TechRadar .

Continue reading

Complete index →