I resigned from Anthropic today. I spent the last three years doing pretraining research at both OpenAI and Anthropic. Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives. More thoughts below.
Introducing Atlas:
The world's first multimodal world model that generates image and video frames with pixel-perfect camera control and reconstructs them in 3D.
Model the world, move the camera, and simulate space & time.
We’ve identified industrial-scale distillation attacks on our models by DeepSeek, Moonshot AI, and MiniMax.
These labs created over 24,000 fraudulent accounts and generated over 16 million exchanges with Claude, extracting its capabilities to train and improve their own models.
🚨🇫🇷CYBERALERT - FRANCE🔴 | ‼️France Travail -ex Pole Emploi- ENCORE victime d'un nouveau piratage... le groupe cybercriminel Stormous revendique détenir 30Go de données et surtout détaille comment ils ont piraté l'institution... ⤵️
Bon ben... jamais deux sans trois ! Le groupe cybercriminel Stormous, dans a affiché hier, 27/10, France Travail sur son site vitrine du Darkweb.
Ils disent avoir mis la main sur 30Go de données sensibles appartenant à +31 000 comptes :
👉🏾 Informations d'authentification en clair : noms d'utilisateur/mots de passe
👉🏾 Données personnelles : noms complets, dates de naissance, sexe, adresses, numéros de téléphone, emails
👉🏾 Parcours professionnel et compétences professionnelles
👉🏾 CNI
👉🏾 RIB - Relevé d'Identité Bancaire
👉🏾 CDD, CDI, missions temporaires
👉🏾 Avis d'imposition
👉🏾 Attestations de sécurité sociale
👉🏾 Certificats de formation
👉🏾 Documents d'autorisation de travail
👉🏾...
Plus surprenant et surtout critique, ce groupe cybercriminel a détaillé dans les moindres détails comment ils ont fait pour pirater, selon eux, l'institution.
On apprend donc qu'il s'agit d'une attaque par "piratage/récupération" d'identifiants compromis qui a menée à une exfiltration massive de données.
L'attaque a été automatisée suite aux identifiants volés, obtenus par un logiciel malveillant de vol d'informations,
Un script automatisé a permis de tester des combinaisons nom d'utilisateur/mot de passe valides pour authentifier les utilisateurs légitimes.
Ils ont contourné le système d'authentification OpenAM de France Travail en 5 étapes :
👉🏾 Fausses empreintes digitales d'appareils pour faire croire à des sessions de navigation légitimes
👉🏾 Extraction de jetons d'accès OAuth2 pour un accès complet à l'API
👉🏾 ...
👉🏾 Accès à 8 API non protégés pour extraire des données de profil, des antécédents professionnels, des coordonnées et des informations personnelles sensibles
👉🏾 Exploitation d'une vulnérabilité critique de téléchargement de documents dans l'API de génération de PDF du backend de France Travail
👉🏾Téléchargement réussi de documents inaccessibles aux utilisateurs légitimes via une interface frontend défectueuse
👉🏾...
L'automatisation massive a été possible pcq...
👉🏾 Absence de limitation de débit, de CAPTCHA ou de détection de robots
👉🏾 Absence de protection par authentification multifacteur (MFA)
👉🏾 Fonctionnement automatisé continu sur plusieurs jours/semaines
👀Incroyable... si c'est vrai !
Et en même temps tellement pas surprenant... Bcp d'entreprises, d'institutions ont une détection défaillante si ce n'est inexistante.
En mars 2024, France Travail était déjà victime d'une cyberattaque touchant 43M de français.
En juin 2025, France Travail était déjà victime d'une autre fuite de données affectant +600 000 français.
Espérons que l'ampleur de cet incident ne soit pas aussi conséquent que le précédent...
Cybèrement vôtre,
SaxX ¯\_(ツ)_/¯
I've never seen the Python community embrace any tool faster than they did with uv.
uv is likely the best Python tool of the last few years.
If you aren't using it yet, stop what you are doing and look into it. If you are already a user, check out the attached cheatsheet.
Google has made us incapable of memorizing complex things by reducing memorization to search queries. LLMs will make us incapable of solving complex problems by reducing problem-solving skills to writing prompts.
Machine learning education is broken, especially for those who aspire to start solving real-world problems at a company.
Most classes, courses, and books start with a dataset and show you how to train a model.
dataset → model
This is, at best, 5% of the work you'll need to do.
Real-life problems never start with a "dataset," and they never end after you finish training a model.
I've never seen a company with a "dataset" ready to go. In fact, most companies don't even have any data at all. It's your job to determine what data you need and how to collect it.
Here is a simplified process that will give you a better idea of how people solve real problems:
problem → framing → data → model → feedback → repeat
Before understanding the problem and deciding how you'll frame it to solve it, you can't start thinking about datasets.
A few other challenges:
1. How do you get data from its source?
2. Is the data diverse enough to solve the problem?
3. Do you have enough data?
4. How is the data biased?
5. How frequently does the data change?
6. How sensitive is the data?
7. Are there missing, inconsistent, or incorrect values?
8. How noisy is the data?
9. How can you trace back every piece of data to its source?
10. Are there any legal restrictions on the use of the data?
11. How do you scale as data grows?
12. How quickly does the data become stale?
Building systems that work requires a lot of effort. I wish more people would talk about this.
Introducing bitnet.cpp: A blazing-fast open-source 1-bit LLM inference framework that runs directly on CPUs.
You can now run 100B parameter models on local x86 CPU devices with up to 6x speed improvements and 82% less energy consumption!
day ???/???
ascii art generation
i have successfully added a performant terminal rendering pipeline! frames are rendered as and when they are decoded now (what you see in the video is real time)
here's the opening to Serial Experiments Lain on wezterm. 60 fps, locked. with zero hiccups. enjoy
(ps. i added audio in post) (i'll add audio support after web app release)