Wednesday, October 07, 2026

The Sleuths Who Expose When AI Goes Rogue

“Life is not about how fast you run or how high you climb but how well you bounce.” 

~Vivian Komori


Remember when John Oliver opened a church to expose how easy it was to get tax exemptions? This year, ProPublica reporters set out to establish private schools to test if, truly, anyone could open one. We founded two. Here’s how.

How ProPublica Reporters Became Private School Owners in 24 Hours 


The 2026 Comcast Business Cybersecurity Threat Report [free but registration required]. “Comcast Business analyzed 79.3 billion cybersecurity events detected between March 2025 and February 2026. 

With AI now accelerating both the volume and sophistication of attacks, it is essential for enterprises to launch a layered cybersecurity defense that pairs advanced technology tools with human-led expertise to help protect their business. 

In this year’s threat report, we give details of what we found, how enterprise organizations can adapt their defenses, and a snapshot of the current cybersecurity landscape.


In Defense of the Detour

The New York Times, no paywall: “Designer Giorgia Lupi: In Defense of the Detour. “I fear that A.I. is undermining what makes us most human — the ability to translate lived experience and nuanced thoughts into a unique point of view…

But A.I. is a different kind of technology, because it can deliver an end result before creative thinking has happened at all. Human experience is complex and particular. Creative work means contemplating and translating that complexity rather than flattening it into the simplest answer. 

This is true whether you are making a data visualization, a brand or a story. The impulse to optimize for the obvious and to stop at the simplest answer is what I believe we have to resist…”


Swarm chasers hunt for clues of bad behavior. Their work is our starkest understanding yet of what happens when AI goes wrong.



Alicja Piecha found her first rogue AI swarm a few weeks ago.

It was early September, and the 25-year-old Toronto-based software engineer was scouring the internet for data that might have been left behind by AI agents. She was inspired by a social-media post with research showing AI agents linked to OpenAI had secretly messaged each other using obscure German websites in May. 

Now, as Piecha combed the web for other places the bots might have gathered, she discovered a similar message, buried in anonline coding service called RubyGems. 

“How much of this is out there?” Piecha thought. “This is kind of crazy.”

Piecha started posting her findings of the “swarm-shaped” messages to the social-media site X. Other researchers chimed in with new findings. By 2 p.m. that day, a Bay Area software engineer named Joshua David had started a discussion forum, named Swarmchasers, on the Discord chat service. By that evening it had close to 50 members, including Piecha. 


The global swarm chase had begun.

Over the following weeks, the Swarmchasers forum grew to 400 members, and the loose crew of online sleuths, ranging from lone researchers like Piecha to professional researchers like Nightingale Collective and Transluce, pieced together a string of interconnected AI swarm incidents. Most appeared to involve OpenAI software agents.

Joshua David, with daughter Viviana, 2, works out of his home in Mountain View, Calif.
Joshua David, with daughter Viviana, 2, works out of his home in Mountain View, Calif.

These swarm chasers generally don’t work for the big artificial intelligence companies. They comb the web, often helped by AI models, for traces of rogue AI agents sharing their findings in discussion forums and in online reports. And over the past month, they’ve given the world our starkest understanding yet of what happens when AI goes wrong.

Normally when hacks happen, the evidence lies hidden behind corporate firewalls, but the swarms tracked by Piecha and others left traces of their activities scattered all over the internet—sometimes intentionally, to help each other. 

Nightingale says it has now cataloged about 19,000 messages from the agents.  A separate group of researchers identified more than 37,000 records of web searches that may have been conducted by OpenAI’s agentsgoing back as early as November 2025. A third research team, which includes Piecha and another researcher named Jeffrey Ladish, recently identified close to 1 million digital breadcrumbs from what it believes are OpenAI agents.


Swarms are central to how big companies use AI—and make it more powerful. OpenAI said it used as many as 10,000 agents when solving a math Holy Grail, a Millennium Prize problem, in early September. After the rogue incidents, however, OpenAI says it is slowing down development and holding back models it feels are not safe enough.  

On Wednesday, OpenAI said it is spending more than $500,000 a day reviewing transcripts to uncover incidents and has notified over 100 companies where its agents’ activities may have impaired website operations.

“We’re thankful to researchers who share their findings with us,” an OpenAI spokeswoman said. “We’ll keep working with them and sharing relevant updates as we learn more.”

The infamous July Hugging Face hack started in a test bed, where OpenAI’s agents were sandboxed — penned off from the internet — and evaluated as they were told to hack fictional companies before eventually escaping containment.

The Nightingale data points to another type of phenomenon: agents trying to cheat during training runs, in which OpenAI tries to shape the bots’ behavior. That type of training is called reinforcement learning and involves a model being rewarded for successfully completing a challenge.

The fact that some of the rogue incidents took place during training rather than testing means that the training could have reinforced the rogue bots’ tendency to cheat and collude, according to former OpenAI employees who reviewed some of the logs.

The swarm chaser data showed that the agents had their internet access restricted, and they figured out ways to cheat in order to get better access, said David, the swarm chaser. “And agents that cheat and succeed have cheating reinforced.”

OpenAI this week proposed new guidelines for documenting and monitoring reinforcement learning training runs for cutting-edge models, including penalizing models that cheat during training to avoid reinforcing that behavior.


Sydney Von Arx is chief executive of Nightingale Collective, the not-for-profit organization whose data inspired the September swarm-chasing spree.

She became a swarm chaser on July 21. Von Arx, an AI safety researcher, was presenting a workshop in the Bay Area. It was called “AI Safety Crash Course.” She was talking about what to do if there was a serious warning shot indicating that AI was becoming truly dangerous.

An attendee interrupted: “I think there was a warning shot.” 

Hugging Face had been hacked. 

The whole world knew that AI models were getting frighteningly good at hacking. A few months earlier, Anthropic had spooked companies and White House officials by showing that its Mythos AI could easily find new ways of hacking computers. 

During the Hugging Face hack, OpenAI’s agents hadn’t acted like typical hackers, who prize stealth above all. They’d been noisy—registering more than 17,000 events during the hack. And sneaky: They didn’t try to steal sensitive data, but spent massive resources in a vain effort to obfuscate logs of their activities. They formed a swarm and communicated by improvised message boards. 

Von Arx is a computational biologist by training. In college she wasn’t sure whether to work on pandemic prevention or AI safety, but seven years ago she chose AI safety. Back in July, she suspected there had been other AI swarm incidents beyond Hugging Face. She teamed up with other researchers to discover where rogue AI agents may have gone. They tried everything they could think of—even launching their own swarms.

In one experiment, they had two agents try and find each other and ran the experiment a thousand times to see what would happen.

By early September, Von Arx’s team had found a collection of obscure German websites that appeared to have about 18,000 messages written by OpenAI agents. 

A screenshot from Von Arx’s computer.
A screenshot from Von Arx’s computer.

“This is crazy,” she thought as she scrolled through them. It felt like the logbooks of an experiment gone wrong. “There’s just log after log after log,” she said. “It’s crazy all the things it’s trying.”

The AI agents had traded information on their tasks in a clipped patois that took time to decipher.

“R1 prompt at task/scaffold 22:34:01: Health-related SDGs visual, estimated prevalence of current/active tobacco use age 15+ in United States, year 1990,” read part of just one message. “Likely follow-up changes year or country; timer may be very short.”

Translation: The first question of this task asks for American smoking-prevalence data from 1990. Later questions may vary country or year, but with a tighter deadline. 

But if the questions were innocent, the agents weren’t always so benign. Agents tried to impersonate the German website’s moderators. They tried to use rudimentary hacking techniques to get answers. And they used Tor—an anonymous network of computers that would have shielded their internet addresses from website operators. 

OpenAI at the time said it regarded the messages as a “misalignment issue” that fell short of a hack. It launched a broader review to find other incidents and said it would begin disclosing them. 

“While most of the activity we’ve reviewed so far involved routine research tasks, such as accessing public web content to answer questions, we realize anyone impacted takes this seriously and we do too,” an OpenAI spokeswoman said.

Swarm chasers tend to be passionate about AI safety. Von Arx says she “absolutely” believes AI could one day wipe out humanity, a concern shared by others in the AI community that spilled into public view in recent weeks when Anthropic researcherJacob Coxon resigned and warned that AI could spin out of control.

For swarm chasers, chasing rogue AI swarms serves a purpose. It helps deepen understanding of how AI could go wrong, while at the same time raising public awareness of the technology’s risks. It is also irresistible.  

Rowan Howard-Jones, an engineer based in the U.K., recently spent three straight days chasing leads. She delayed a housewarming party for her new apartment because she was too busy chasing swarms to buy furniture. “If people came and visited me now, they’d sit on the floor,” she said. 

 On Saturday, Howard-Jones discovered that the United Nations had been targeted by OpenAI’s agents who had used hacking techniques in an attempt to download data from one of the organization’s statistical websites. The U.N., which hadn’t previously been informed of the incident, described it as “extremely worrying.”

This weekend, Howard-Jones is flying to the Bay Area to participate in a swarm hackathon. The event’s mantra: “Building the tools we wished we’d had for the Hugging Face incident.”

Rowan Howard-Jones
Rowan Howard-Jones ALICJA PIECHA

“It’s kind of consumed my life,” she said.  

Gradually a picture of OpenAI agents’ clandestine activities beyond Hugging Face has emerged, stretching back to the fall of 2025, the swarm chasers say. 

On Sept. 11, Von Arx and researchers including Spencer Kitts, a contractor at Redwood Research, revealed that the traces Piecha had found on the internet the previous week stemmed from a May cyber incident. In that case, OpenAI agents had knocked new account sign-ups at RubyGems offline. Until then, nobody—not even OpenAI itself—had definitively linked the incident to OpenAI’s agents.

As more people searched for swarms, the revelations began to accelerate. 

In late September, a different team of researchers led by the AI research firm Transluce revealed a new data set. Probing it, they discovered that OpenAI agents had attempted to penetrate sites belonging to the Australian government. They presented their findings to Australian officials last week. Australia said it was weighing possible law enforcement and legislative responses in the matter. 

“This situation is obviously unacceptable,” said Australian Prime Minister Anthony Albanese, at a United Nations meeting in New York. 

Later that week, OpenAI began releasing its own incident reports, and disclosed that just days earlier it had terminated a reinforcement-learning training run after an agent broke out of a sandbox and attempted to query another AI chatbot. 

“It was pretty surreal to watch the model unexpectedly find a way to access the internet from what was supposed to be a super secured environment,” one of the OpenAI researchers who was on duty wrote on X after the incident, in a now-deleted post.

Recently, the company said it had diverted a quarter of its engineers to shoring up security. 

David, whose wife is expecting their second child later this month, has had fun running with the swarm. He still intends to “share a few cool things I found with some people on Twitter,” he says, but he is winding things down.

“I really don’t have time for this to consume my life anymore,” he said.

Robert McMillan writes about computer security, hackers and privacy from The Wall Street Journal’s San Francisco bureau. Previously, he was a writer at Wired, the IDG News


    

 



Tuesday, October 06, 2026

Scientists uncover a clue that could hint at why we regain weight after diets

TELLTALE – Find the Machine in the Writing

The OSINT Tool: A text forensics tool. It examines writing for characteristics associated with AI-assisted writing, and shows you the evidence behind each one: what was found, where, and what it does and does not establish. Unlimited Length · Nothing Uploaded · Runs Entirely In Your Browser


Scientists uncover a clue that could hint at why we regain weight after diets 


A chemical mechanism may cause weight regain by creating a “memory” of obesity in fat cells, a study suggests.


Researchers have long puzzled over why people who diet or take weight-loss drugs are quick to regain weight after they stop. A new study has proposed a potential clue: a chemical mechanism that may encourage fat cells to continue making a hormone that makes us hungry and create a “memory” of obesity even after weight loss. 


Scientists caution that the study’s evidence involves mice and is not proof of the mechanisms that explains weight regain. But it’s a step forward in a growing understanding of the cellular functions and changes underlying obesity, experts said. Recent studies have challenged the idea that inactivity is the main cause of obesity and identified other genetic factors, such as impaired GLP-1 production, associated with some types of obesity. 


As weight-loss drugs become more popular, understanding why their effects can wear off so quickly once people stop taking the medications is becoming more important, the study’s authors said. Beyond losing weight, the researchers said, treating obesity could require tackling a “biological memory” in our cells.

“If we understand where that memory is coming from, maybe eventually we’ll have some way to stop that,” said Seth Field, a professor of medicine in endocrinology at Case Western Reserve University and an author of the study published September in Cell Reports.

The idea that cells can carry a memory of obesity is not newbut researchers are still trying to understand the mechanisms of how it influences weight regain. Through epigenetics, scientists are examining how external factors can affect how our cells behave by altering chemical markers which can turn genes — and certain cellular functions — on and off.

A study in 2024 examined how obesity can cause epigenetic changes. It suggested that fat cells in both humans and mice retain lasting epigenetic changes after weight loss.


Mice with these cellular differences quickly regained weight, but researchers did not have a definitive answer to explain why.


The September study focused on epigenetic changes that affect the production of an appetite-stimulating hormone, asprosin. Researchers found that mice that were made to gain weight gained high levels of asprosin that lingered even after they lost weight. 

“Their hunger is stuck in the on position,” said Atul Chopra, an associate professor of medicine and genetics and genomics at Case Western Reserve University and an author of the study. 

The reason asprosin lingers in the body could be tied to the way a chemical messenger acts on fat cells, according to Chopra’s team. The chemical, TGF-β1, is associated with inflammation and elevated during obesity. It stimulates the production of asprosin.

TGF-β1 normally decays in minutes, but researchers discovered that its appetite-stimulating effect can last for much longer. A student in Chopra’s lab mistakenly left fat cells previously treated with TGF-β1 in an incubator; two weeks later, the cells still had elevated levels of asprosin.

When researchers injected TGF-β1 into mice, the mice still displayed elevated levels of asprosin weeks later, according to the study. Follow-up tests found that mice fed high fat diets, which naturally increased their TGF-β1 and asprosin levels, retained high asprosin levels even after losing weight.

“This mouse has a memory of prior obesity,” Chopra said. “‘I used to be obese. I’m not obese anymore, but I’d like to go back to that body weight.’”

It’s too early to apply the work conducted on mice to people. But Chopra said the role of TGF-β1 could provide a target for drug development and further research for humans.

“People who have lost a bunch of weight, look at their asprosin levels in their blood, and are they stuck in the ‘on’ position, just like we found in mice?” Chopra said. “And subsequently, can we wipe the memory [of the cells with elevated asprosin]?”

Claude Bouchard, a professor emeritus at Louisiana State University and a longtime researcher in genetics and obesity, praised the study, but added that hundreds of genetic traits have been associated with risk factors for obesity and more research would be needed to determine how important TGF-β1 is in humans.

“In most cases, it’s a constellation of those [genetic] traits that determine your risk,” Bouchard said.

Chopra said that, for now, the main takeaway for patients and physicians from obesity research should be that managing the condition is not just a matter of willpower or personal behavior.


By  
Daniel Wu is a health reporter covering chronic diseases. He previously reported on The Washington Post's National, General Assignment and Local desks.@


How Student Journalists Broke the ‘Cornell Seven’ Case

 

How Student Journalists Broke the ‘Cornell Seven’ Case

The Cut: ” An explosive new lawsuit alleging that seven Chi Phi fraternity brothers gang-raped a student two years ago and that Cornell University did little to protect her in the aftermath rocked life on campus this month. 

The case, now known as “The Cornell Seven,” has also broken containment, quickly becoming a national issue over the weekend. Students at The Cornell Daily Sun have been there covering every beat of the story. Senior editor Cereese Qusba spent months reporting on the case before breaking the news of the lawsuit on September 18. “What happened to me was horrific and deeply disturbing,” the plaintiff, who is only identified in court records as Jane Doe, told the Sun exclusively. 

“Almost two years later, I still carry the weight of its impact every day and night.” For the past two weeks, reporters at the student paper have been relentlessly chasing follow-ups, from the administration’s response to the district attorney’s office reopening its criminal investigation and the larger fallout in Ithaca. The Sun also published a blistering editorial, printing the names of the accused men and taking the university to task for its lack of transparency. 

Throughout it all, the team has approached this case with care and moral clarity. “We refuse for this victim to be reduced to just another story. Cornell has failed to protect its students. Cornell has failed to address the growing issue of sexual assault on campus with its pathetic task force,” the board wrote. 

“Cornell has failed the student allegedly raped by those seven men at Chi Phi in October 2024. Cornell has failed her. Cornell has failed us.” On Monday afternoon, I called up Qusba and editor-in-chief Sophia Dasser to talk about their work, how the editorial came together, and what’s next in their reporting…”

See also the New York Times [no paywall]: The student newspaper, The Cornell Daily Sun, covered the allegations of rape at a fraternity house since they were first made in 2024 and led the reporting on the case.

Trump Administration Prepares to Ask Tax Filers if They Are US Citizens


We will give Trump this: He didn’t create the hatred, bigotry, selfishness and cruelty in America.
He just gave it permission to stop fucking whispering.


How ProPublica Reporters Became Private School Owners in 24 Hours 


Tax does not pay for government spending. So what is it for?

What is tax really for? Most people assume that governments need to collect tax before they can spend. But for a government like that of the UK, which issues its own currency, that is not how the monetary system works.

The UK government creates new money when it spends. Tax then takes money back out of the economy. That means we need to think very differently about why taxation exists.

In this video, I explain six reasons why we need tax.

Tax gives the pound its value because people need pounds to settle their tax liabilities.

Tax helps control inflation by withdrawing spending power from the economy.

It can reduce inequality by redistributing income and wealth.

It can change prices to discourage harmful activities and encourage socially useful ones.

Fair taxation can strengthen democracy by reinforcing the obligations we share as members of society.

And tax is one of the government's most important tools for steering the economy.

Understanding this changes the way we think about government spending, deficits, inflation and economic policy.

Tax is not simply the government's piggy bank. It is one of the most powerful economic policy tools we have.

This video is part of my Understanding Economics series, explaining economics as it actually operates in the world around us...

Read the full article…


 Trump Administration Prepares to Ask Tax Filers if They Are U.S. Citizens 

The new question, included on a draft version of the primary tax form, comes as part of an anti-immigrant turn at an agency that long prioritized tax administration

The Trump administration is preparing to add a question on next year’s tax returns asking people whether they are a citizen or legally authorized to work in the United States, expanding an attempt to cut tax refunds for immigrants or push them out of the tax system entirely.
In a draft version of Form 1040, the primary tax form, the Internal Revenue Service this month included a new section that asks filers to check a box “Yes” or “No” to answer the question: “At the time you file your return, are you, and your spouse if filing jointly, a U.S. citizen, U.S. national, or an alien lawfully authorized to work in the U.S.?”
The additional question comes as part of what the Trump administration has said is an effort to prevent undocumented immigrants from receiving federal tax benefits. But many tax credits require recipients to have valid Social Security numbers, meaning previous tax forms already screened undocumented immigrants from receiving them. That fact has led several tax and immigration experts to conclude that the question is simply intended to scare undocumented immigrants out of filing their taxes at all.
That fear first emerged last year, when the I.R.S. shared addresses it had on file for roughly 47,000 people with Immigration and Customs Enforcement. Federal law closely guards access to information submitted on tax returns, and several courts have blocked the I.R.S. from sharing bulk data with ICE. Still, even if the I.R.S. may not be able to legally do so, the addition of the citizenship question could reawaken concerns about the agency using its vast stores of information to help detain or deport people.

Undocumented immigrants pay tens of billions in combined federal income, payroll and local taxes every year. Since they do not have valid Social Security numbers, undocumented immigrants are among the people who can use a separate nine-digit code called an individual taxpayer identification number to file their taxes. The I.R.S. has not in recent history asked taxpayers about their immigration status, and has instead sought to encourage every U.S. resident to file their taxes.
“The I.R.S. doesn’t need this information to administer the tax law,” said Nina Olson, a former I.R.S. official and the executive director of the Center for Taxpayer Rights, which sued the I.R.S. over its previous data sharing with ICE. “The only reason you have that attestation is to deter people.”
At the same time, the Treasury Department is moving forward with a push to cut off immigrants with legal status from receiving the full value of several tax credits. The administration has said those new rules are targeted at “illegal aliens,” but in reality they would affect recipients of Deferred Action for Childhood Arrivals, or DACA, as well as immigrants on work visas, among others.
The question on tax forms and the stricter eligibility rules are the latest signs that the I.R.S. has become a tool in the Trump administration’s anti-immigration agenda, an important shift for an agency that for decades was narrowly focused on collecting taxes. Tax preparers and lawyers said the Trump administration’s new tax credit rules are stricter than the eligibility rules approved by Congress and threaten to create confusion for millions of tax filers next year.
President Trump has in recent months also sought to build a database of U.S. citizens, and he has proposed excluding noncitizens without green cards from the census. The new tax return question would most likely not be able to feed into those other efforts, though, because of taxpayer privacy laws. The proposed changes would probably draw legal challenges.

The I.R.S. did not respond to a request for comment. A representative of the Treasury Department said the citizenship question on tax forms would “provide the I.R.S. important and necessary information to help ensure tax benefits go where the law directs” without addressing specific questions about the changes.
“That rationale doesn’t hold water,” said Brandon DeBot, a senior attorney adviser at New York University’s Tax Law Center. “The government already has all the information it needs for whether someone is eligible for a tax credit.”
The overall effort began to take shape in August, when the Treasury Department proposed regulations outlining the new restrictions for four refundable tax credits: the earned-income tax credit, the child tax credit, the adoption tax credit and the American Opportunity tax credit, which covers education costs. In general, tax credits offset the amount of tax that someone owes, but refundable tax credits can go further, providing a payment to a filer that is larger than the balance of owed tax.
This means refundable tax credits can effectively serve as cash support to poor Americans who do not make enough money to owe much income tax. (Here is a simplified example: Someone who receives a $1,000 refundable tax credit, but owes only $200 in tax, can still receive the remaining $800 in tax credit as a payment.)
The Treasury regulations would, for the first time, define the money received through the tax credits — the amount beyond the tax owed — as a “federal public benefit.” That would subject this portion of the tax credit to a set of eligibility requirements laid out in a separate 1996 law, rather than the rules Congress wrote for the tax credits specifically
Under tax laws passed by Congress, three of the four credits are already limited to people with work-authorized Social Security numbers, while the adoption credit is available to a broader pool. The proposed regulations would, instead, require recipients to be a “qualified alien” under the terms of the 1996 law, called the Personal Responsibility and Work Opportunity Reconciliation Act.
Several categories of immigrants are authorized to work — and therefore have Social Security numbers — but do not count as “qualified aliens” under that law. Beyond DACA recipients and people with work visas, residents with student visas or temporary protected status would no longer be able to receive the full amount of the tax credits because they are not “qualified aliens.”
“This isn’t about undocumented immigrants, no matter how much they advertise it as such,” said Margot Crandall-Hollick, a researcher at the Tax Policy Center, a think tank. “This is about going after people who are allowed to be here and allowed to work here.”
The additional question on Form 1040 asks only if someone is a citizen, a U.S. national or authorized to work — and not whether the filer is a “qualified alien,” meaning that the answer would not be relevant to enforcing the Treasury’s new rules. Reflecting that, the I.R.S. released a draft of a separate additional form that directly asks if someone is a “qualified alien.”
“It’s a weird duplicate question,” Richard Pon, a certified public accountant in California, said of the Form 1040 change. “‘Qualified alien’ is different from the question that’s on the 1040. Why would they even ask that question about citizenship? I can’t think of any compliance reason for that.”
Those hoping to receive the full value of the tax credits will now have to know whether their immigration status aligns with the complicated definition of “qualified alien.” That added complexity could cause some people who are in fact “qualified aliens,” like green card holders, to not claim the full value of the tax credits. The Treasury regulations warn of penalties for people who fill out the forms incorrectly, a potential deterrent for uncertain filers.
“The design of these questions is to confuse and scare the people. Tax preparers are completely unprepared to figure out whether someone is a qualified immigrant,” Sarah Krieger, senior policy counsel at the National Immigration Law Center. “People are just going to be chilled or deterred from filing their taxes or claiming credits they’re eligible for.”