Collabora has partnered with YouTube's Cobalt and Device Partner Engineering teams to create the first RDK reference platform running Chrobalt, the next-generation version of Google's living-room web engine. Chrobalt merges the lightweight Cobalt engine, which currently powers YouTube on smart TVs and set-top boxes, with Chromium's rendering pipeline, moving beyond the classic Starboard-based architecture used since Cobalt's inception.
Gill Haus, CIO of Chase's consumer banking division, said the bank no longer hires engineers primarily to write code, since AI agents increasingly handle that task. Instead, he looks for engineers who understand what code should be written and how to evaluate and direct AI-generated output, while product leaders are also taking on coding responsibilities.
Anthropic's latest misuse report covers activity from November 2025 to September 2026 and details five cases where users tried to get its Claude AI to assist with dangerous biological research, three involving viruses and two involving toxins. In one instance, a request framed as a civilian grant application to enhance the chikungunya virus's mutation rate and virulence was traced to a military facility, prompting Anthropic to intervene. The company says all the actors used anonymization tools and tried to bypass its regional access blocks, which cover countries including China, Russia, Iran and North Korea.
A software engineer tested OpenAI's GPT-6 Astra model by setting up an autonomous 'software factory' where the model managed its own workflow, context and subagents to build a Python variant with virtual threads and lexical scoping. After roughly 35 hours and about 4 billion tokens consumed, the effort produced nothing usable and taught the author little about how to actually apply the model to real software engineering work.
Engineers building the ArcBox sandbox platform used standard Linux debugging tools like strace and objdump inside a live Claude Code Web session to inspect its runtime. They discovered the environment runs on Firecracker microVMs, identical to the technology behind AWS Lambda and Fargate, complete with hardcoded ACPI signatures, minimal 4-vCPU/16GB instances, and an unstripped Go binary called environment-manager pointing to a previously undocumented Anthropic internal deployment platform.
Malone Lam, a 22-year-old Singaporean living in Miami, has pleaded guilty to racketeering charges tied to a cybercrime ring that allegedly stole and laundered hundreds of millions in cryptocurrency. Prosecutors say the 12-member group, which reportedly first connected through Minecraft before meeting in person in 2023, targeted wealthy crypto holders using social engineering, with individual thefts ranging from $800,000 to a single $245 million heist. Lam now faces up to 20 years in prison, with sentencing still pending.
A Big Story investigation from MIT Technology Review, done with Type Investigations, examines how pastor Eli Regalado and his wife launched INDXcoin after claiming divine instruction, raising over $3 million from more than 500 people before the project collapsed within a year with investors losing everything. Separately, the nonprofit Reflective has published a detailed plan outlining the experiments and infrastructure needed to better understand solar geoengineering before any real-world deployment decisions are made.
A hobbyist took apart an Egret GT electric scooter, examined its Bluetooth app and firmware update mechanism, and discovered a way to bypass its PIN lock via a hidden firmware update mode. He also found the scooter silently transmits unlisted telemetry data, including driving-mode duration, motor current, battery voltage and charge history, and went on to write custom Rust firmware for the scooter's display unit.
AdaptHealth has confirmed that a cyberattack discovered in July, linked to the ShinyHunters group, exposed personal and health data belonging to about 4.1 million patients. The company says attackers gained access on June 5 through a social engineering attack that compromised a third-party contractor's privileged account, reaching cloud-based patient management and record systems. Exposed data includes names, contact and demographic details, health insurance information, and health records.
A careers newsletter produced by IEEE Spectrum in partnership with Parsity shares personal advice for engineers navigating job loss, drawing on the author's own experience of being laid off from a management role while juggling a new business and family responsibilities. The piece emphasizes emotional resilience, reminding readers that professional identity as an engineer persists beyond employment status, and outlines practical first steps such as pausing before job hunting and cutting unnecessary expenses.
An essay contrasts two mindsets in security engineering: those who treat security as a personal identity built around cleverness and outsider status, versus those focused on systemic, structural defense work. The piece argues that the hacker ethos of prizing surprising vulnerability discoveries, while culturally dominant and rewarded at conferences and in careers, biases the field toward reactive discovery rather than durable prevention.
An anonymous security researcher has reconstructed and released a reverse-engineered version of Stuxnet's source code on GitHub, complete with build instructions. Stuxnet was the malware that sabotaged centrifuges at Iran's Natanz nuclear facility by targeting Siemens industrial controllers while masking the damage from plant operators.