When Erica Schwartz was first nominated for Director of the CDC, you could almost hear both a gasp of surprise and a collective sigh of relief from healthcare providers throughout the country. Schwartz is well qualified for the role, after all, and many took her nomination as a sign that the White House was attempting to rein in RFK Jr. Then came Schwartz’s confirmation hearings. While there was some good in Schwartz’s performance during those hearings, there was a lot of bad. The kind of bad that suddenly has a whole bunch of people who were previously sighing in relief suddenly nervous, and even pulling their endorsements. The biggest issue was Schwartz not affirming that she would refuse Kennedy’s influence and desires in favor of good science.
Well, Schwartz is now the confirmed Director of the CDC, so it seems what she did to ruin her reputation with a whole lot of people didn’t matter in the end.
Perhaps the most disturbing aspect of Schwartz’s testimony came when senators repeatedly asked her what she would do if (or when) she’s put in the same position as Monarez. Schwartz responded as if it hadn’t happened and would never happen. “I do not believe that the president or the secretary would ever do what you just mentioned,” she told Sen. Bernie Sanders (I-Vt.) at one point, prompting him to reply: “Really?”
While senators expressed their disappointment with her responses, health experts dropped their endorsements.
And if you want to get really, really pissed off, allow me to tell you how Bill Cassidy was a key and potentially deciding vote when it came to Schwartz’s confirmation. Cassidy has the ear of other reasonable GOP senators in these hearings and in Senate generally when it comes to health-related concerns. And it may start to sound familiar when I tell you that Cassidy first indicated he was very troubled by Schwartz’s response in her confirmation hearings, but had been assured privately afterwards that his concerns were unfounded.
Critical to Schwartz’s confirmation was support from self-proclaimed vaccine advocate Sen. Bill Cassidy (R-La.), who also cast a critical vote to confirm Kennedy as health secretary. While Cassidy called Schwartz’s performance in the confirmation hearing “disappointing,” he later said he had been reassured. He said he had spoken with her more after the hearing as well as with her former colleagues. “I’m confident that she knows what she is doing,” he said, according to Stat News.
If I dialed the clock back to 2025 and replaced Schwartz’s name with Kennedy’s, it’d be the exact same story.
I hope I’m wrong. I hope that Schwartz’s qualifications rule the day and she can resist Kennedy’s nonsense and make good, scientifically sound decisions and hires. But so long as Kennedy is at the helm, I have my doubts.
For a while now we’ve been mocking the Trump White House’s plans for an “AI framework” that would have the frontier AI labs hand over their top models for an initial review. After all, this was more or less the exact same plan that the Biden admin worked out in 2023, but it was done in a thoughtful and careful manner. And it caused a bunch of the VC bros in Silicon Valley to come out in support of fascism, while claiming it was a necessary defense against Biden’s attack on supposedly open innovation. Of course, all of that was bullshit, and that’s made even more clear by every step the Trump White House has taken to reinvent a similar “voluntary” AI review plan, but dumber.
The White House does not plan to publicly release its new framework for evaluating advanced AI models, three sources familiar with the discussions told Axios.
The Trump administration invited staffers from OpenAI, Anthropic, Google, Meta, Nvidia, and other leading AI companies to the White House on Tuesday to share an overview of its new AI oversight framework, the people said. AI developers will have the ability to voluntarily submit new models to the federal government up to 30 days ahead of their public release. The White House will then vet their cyber capabilities according to a classified benchmarking system and share the AI models with federal agencies and trusted corporate partners.
The White House isn’t sharing more information about its testing criteria or which AI models will be covered by the framework, though open models will reportedly be excluded, according to Axios. That has left smaller AI startups, safety advocates, and third-party researchers in the dark about crucial aspects of how the federal government is addressing the cyber risks posed by advanced AI systems. Some argue that the secretive process will give an advantage to larger companies.
Considering that the likes of Andreessen Horowitz (investors in OpenAI) claimed they had to support Donald Trump over Joe Biden because they would support anyone who agreed with their “little tech agenda,” I’m curious how they can possibly square that with the fact that this new framework is significantly worse than the Biden framework, specifically for the “little tech” companies that a16z has used as a shield to defend their support for authoritarian politics?
Of course, the other reason why the White House is probably keeping the framework a secret is because it would show how incompetent they are. All the reporting so far suggests the entire process has been a clusterfuck, which is much more about which companies get to set up which regulatory moats to protect their own business models, rather than what’s best for either innovation or the American public.
At Nvidia, Microsoft, Google and Meta, executives grew increasingly concerned that Anthropic and OpenAI would win over the White House with their arguments for tighter restrictions, according to two of the people. That would potentially cement the A.I. start-ups’ positions as market leaders,
Other A.I. labs were at risk of falling permanently behind, the people added. And because several of the companies make their own open-source models or supply hardware to businesses that use open-source technology, they worried the restrictions could harm them.
Over private texts, phone calls and video conferences, executives quietly built an argument that open-source models were good for the world and for American innovation, according to three of the people familiar with the talks.
But, of course, that’s just the way things work when you have a White House that makes decisions entirely based on transactional motives, rather than anything involving principles.
As we discussed last week, so much of this is all about whose vision of the AI world wins out — whether a handful of giant companies get to lock in the regulatory moat they’ve built for themselves, or an actually competitive market lets people make their own decisions and keep control over their own experiences. Maybe that’s the real reason nobody’s allowed to see the rulebook: because it would reveal who the administration agreed to let write the rules.
Recent reports have raised alarm about the use of PatronScan, an ID-checking and face-scanning system, at multiple LGBTQ+ bars in San Francisco’s Castro neighborhood. Much of the attention has focused on reports that the system photographs patrons as they enter venues and questions about whether those images are used for facial recognition.
A broader privacy concern also deserves scrutiny. For years, PatronScan has marketed itself not just as an ID-verification tool, but as a system that allows bars and clubs to identify patrons, keep records about them, and share information across venues. As one news article published in 2019 documented, PatronScan built a network that allowed participating bars to flag patrons and share information about them with other establishments.
And in California, it’s not at all clear how PatronScan’s business model of scanning IDs and sharing the information from those scans with other bars comports with the law. California’s ID privacy law, which was amended in 2018 to add ID “scans,” states that no businesses shall “retain or use” any information from a scanned ID card except for limited purposes such as to verify age, comply with a legal requirement, or prevent fraud.
Californians should be deeply concerned about businesses that collect information from government-issued IDs and use it to build databases about where people go, whom they associate with, and whether they should be allowed into other public gathering places. That concern is especially strong in LGBTQ+ spaces, which have long served as refuges for people to go without being tracked, monitored, or put on lists.
We reached out to Patronscan with questions regarding their practices and their views on California ID law. They referred us to their published FAQ question “Is Patronscan privacy compliant in California?” which claims that the use of Patronscan kiosks is legal in California. They also said “Patronscan does not do facial recognition in North America, or any kind of automated analysis of the ID or the live photo image.”
The California Legislature Has Investigated PatronScan’s Business Model
In 2018, the California Legislature published bill analyses (on that year’s AB 2769) that went into detail about PatronScan’s business. Reviewing PatronScan’s own materials, the California Senate Judiciary Committee found that the company had collected and retained information on 561,087 customers in Sacramento alone during the first five months of 2018—a remarkable figure for a city whose population had only recently topped 500,000.
Lawmakers also found that at that time, PatronScan retained information for at least 90 days or longer in some cases, shared information among participating bars, and maintained bans that lasted an average of more than 19 years. A PatronScan “Public Safety Report” used 10,000 scans collected on a single day to report on “where customers live, how far they have traveled, and how many different venues the customers patronized.”
This was not simply checking IDs at the door. PatronScan was building a database.
An immigrants’ rights group, the Coalition for Human Immigrant Rights (CHIRLA), wrote about its concern at the time with these growing ID databases, saying that “placing individuals on a database that labels them a “threat to public safety” has “significant immigration consequences that could lead to deportation, revoking of current status, or denial of future immigration relief.”
Today, PatronScan states that it retains personal information about all customers for 21 days, and about flagged customers for up to five years. This includes the customer’s name, date of birth, photograph, gender, and zip code. It also includes the dates and times that the customer entered particular bars. Such databases are a grave privacy threat. Personal data is routinely stolen by thieves, misused by a company’s employees, seized by government agencies, and diverted to new purposes by a company’s executives.
California Law Still Bans ID-Scan Databases, And Bars Should Follow That Law
In 2018, California lawmakers closed what they viewed as a loophole. Existing law already prohibited businesses from retaining or using information obtained when they “swiped” a driver’s license, except for the narrow purposes of legal requirements (like a judicial warrant) or “preventing fraud, abuse, or material misrepresentation.”
After reviewing companies like PatronScan, the Legislature amended the law to make clear that the same restrictions that apply to businesses that “swipe” ID cards also apply when those IDs are “scanned.” PatronScan opposed that change, arguing it wanted to preserve the ability to share information among bars so participating venues could decide whether to admit patrons.
The bill became law anyway. Yet PatronScan continues to market and sell a system that apparently retains information from scanned IDs, and allows participating venues to flag patrons and share information across its network.
At a minimum, that raises serious questions about how those practices fit with California’s existing ID privacy law. Bar and nightlife venue owners who utilize PatronScan should think twice about its effects on their customers, and consider going back to standard, visual ID checks. These physical checks have been effective at keeping underage patrons out of 21-and-over venues for decades, and don’t present the serious privacy dangers of creating a private database of bar patrons.
For venues serving vulnerable communities like immigrants or the LGBTQ+ community, the stakes of using this technology are even higher. It’s disappointing and alarming to see some of California’s more well-known LGBTQ+ nightlife spots instead lining up as PatronScan’s early adopters. A venue cannot claim to be a safe space while feeding its patrons’ data to a third party database. These businesses should reject PatronScan, return to the standard ID checks that every other bar has been able to utilize, and prove to their customers that their privacy and security still matters.
As perhaps a few Elon Musk fans may remember, he got really annoyed at Wikipedia last year and tasked his second-rate LLM, Grok, with recreating it as “Grokipedia.” Grokipedia, launched nearly a year ago, basically starts by forking Wikipedia and then having its AI “generate” more details and more stories. It’s… not very good.
And apparently, it hasn’t been updating. And it seems like almost no one noticed.
At first, we wondered whether the AI was avoiding sensitive topics. To test that possibility, we submitted an uncomplicated factual update: SpaceX has recently launched its initial public offering (IPO). Grokipedia had not added this extensively sourced, indisputable fact to the SpaceX page. We observed that other users had suggested this edit as well; their requests were also “in review,” some since the day after the June 12 IPO.
We then examined the most popular pages, reasoning that if anything moved through the queue, we would likely see it there. Because Grokipedia provides view counts on individual pages but offers no site-wide ranking leaderboard, we approximated one using the site’s own search-suggestion (typeahead) feature, which returns, for any queried word, the most-viewed pages whose titles contain it. For example, if you type “The ” into the search bar, the first two suggestions are “The Beatles” and “Alexander the Great,” both of which have over 4.7 million views. Using the 10,000 most common words in Grokipedia page titles (obtained from the 5.9 million pages listed in the site map) gave us over 300,000 pages. Like many websites, its individual pages have a steep popularity curve. High-traffic entries on topics such as Elon Musk, ChatGPT, Donald Trump, Taylor Swift, World War II, and Bitcoin draw millions of views, while millions of minor pages sit in a zero-visit long tail.
But neither popular nor unpopular pages seemed to be updating. On ChatGPT’s entry, 12 edits submitted on April 24 were approved the same day, and every edit submitted afterward—May, June, and July—remains “in review.” The same pattern holds across topics and traffic levels; the largest political entries on the site (across both parties) and a second-division football club are both stalled, which is difficult to reconcile with a content- or topic-specific explanation.
In our subsequent analysis of 34,519 pages with at least one suggested edit in our sample, containing a total of 225,496 recommended edits, we found no accepted or rejected corrections dated within the past three months.
You’d think someone would have noticed sooner.
But, as the article notes, it sure looks like the actual human users of Grokipedia quickly dwindled as well:
Across the pages examined, submissions from human users continue at a reduced volume—averaging 216per week post-April.
Other tools that monitored activity on Grokipedia apparently died much earlier:
A public feed that once showed the editing process at grokipedia.com/live—a stream that the Tow Center had scraped to assemble its dataset—stopped functioning between mid-January and early March. A Wayback Machine capture from Jan. 12 shows the feed fully operational, with a running count of approved edits, while a capture from March 5 returns an error page.
These are all signs of a project that’s basically flatlined. For all the hype Grokipedia received as the antidote to Wikipedia, it doesn’t seem to have gained any traction. And, the fact that it basically broke months ago seems to have been noticed by almost no one other than… the dozen or so people out there trying and failing to edit Grokipedia:
While more than half of all contributors suggested only a single edit, a tiny cohort of 13 power users accounts for 42.6 percent of all human edit requests (nearly 40,000 edits). The most prolific contributor submitted over 8,000 corrections across 4,000 pages.
One self-described frequent contributor reported in mid-June that the review system had been stuck for more than 50 days. That places the onset in late April, consistent with our data. He also wrote on X that someone he identified as an xAI team member had acknowledged the complaint but could not provide a status update.
For these power contributors, Grokipedia went from a platform with rapid review times to a black hole.
The article notes that Elon hasn’t mentioned the site since February — barely four months after it launched in October. That silence has now stretched on for about six months and counting.
Even worse, Grokipedia’s logging system appears to have broken as well:
A mass rewrite of the encyclopedia seems to have happened on March 14. Because user suggestions are anchored to specific text selections (“Highlighted sections”), the rewrite appears to have broken the anchors. Grokipedia’s logging system retroactively reclassified previously accepted edits as rejected, attaching the error message, “Highlighted section not found.” However, in several cases that we reviewed, the textual changes appear to have been incorporated into the articles anyway. For example, the 10 launch-week edits to the entry for the actress Prunella Scales are recorded as approved in the Tow archive; nine of the edits now display as rejected on the live site, despite their contents appearing to have been incorporated into the article.
The edit log, in other words, is not entirely stable or reliable. This is potentially confusing for users who made suggestions and might have seen their valid contribution accepted with a “rejected” message nonetheless. It is also not ideal from an auditing standpoint.
It’s entirely possible that someone at xAI (or SpaceX or wherever the checks get cut these days) will flip the server back on and get things started again, but given how much the media hyped up Grokipedia when it launched as a potential “Wikipedia killer,” shouldn’t at least some of them acknowledge what a total failure it has been?
The Soundfreaq Sound Spot II combines wireless audio performance, ambient lighting, and relaxing sound features in a compact design built for modern lifestyles. Featuring a Bamboo and White finish with eco-friendly materials, this Bluetooth speaker complements bedrooms, offices, living rooms, and personal spaces while delivering both style and functionality. Engineered with a custom-designed audio driver, Bass Boost DSP technology, and a passive radiator, Sound Spot II delivers balanced sound with vocal clarity and enhanced bass performance. Beyond music playback, Sound Spot II includes built-in nature sounds, ambient lighting, and sleep timer functionality designed to help create a more relaxing environment. With Bluetooth connectivity, rechargeable battery power, and splash-resistant construction, it offers convenient performance for home and daily use. It’s on sale for $80.
Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.
Flock Safety’s automatic license plate readers were first sold as upmarket add-ons for gated communities and HOA curtain-twitchers who wanted to keep tabs on what everyone was doing, whether they lived there or not.
Flock soon realized that selling to rich people wasn’t as profitable as selling to governments. Law enforcement agencies have always been surveillance tech early adopters — something that springs equally from being able to spend other people’s money and a desire to get out ahead of constitutional case law.
So, now Flock is pretty much everywhere. But instead of getting better due to constant refinement, it seems to be content to rest on its ubiquity. If you’re already everywhere, why try harder? After all, ending a contract with Flock doesn’t mean the company won’t keep your cameras activated so other law enforcement agencies can access plate/location information. And if federal agencies are using local agencies to bypass restrictions on plate reader access, well… that’s just an end user problem.
Flock says that in optimal conditions, its cameras accurately read more than 96% of license plate characters. Hundreds of pages of records from the Roseville Police Department show a different picture. In 2023 and 2024, Flock sent 1,427 alerts to Roseville police, flagging vehicles as stolen or used in a felony after they passed one of the city’s Flock cameras. An analysis by the police department found that in 71% of those alerts, Flock’s machine-learning software incorrectly read the license plates.
That is objectively terrible. And because it is so terrible, Flock’s flack has decided to blame the end users.
A factor that contributed to the misread problems in Roseville was the “particularly unique deployment” that the city requested, a Flock spokeswoman said. Roseville said it has its cameras configured so that they capture only the backs of vehicles, a setup intended to avoid capturing personally identifiable information like faces. Roseville’s setup included older hardware and placement of cameras higher and further from vehicles than the company typically recommends, Flock added.
Huh. Well, that might mean something if Flock had made any honest effort to make this “unique deployment” work better. But it doesn’t appear to have done that. Instead, it simply insists things are better now — a statement that’s not backed by any evidence Flock’s has on hand and/or is willing to share.
Flock said Roseville’s camera performance has significantly improved, which the police department disputed.
According to emails obtained by Business Insider, it does appear that someone appears to be working on the ongoing issue, albeit at a leisurely pace. This is the email sent to Amanda Jones, Roseville PD’s real-time crime center supervisor by an unnamed “Flock Senior Product Manager.”
I 100% understand, and it pains me to no end that we are missing reads for you. I am grinding on this issue, and am writing code as we speak. I am improving systems at Flock internally that can automatically identify when we miss cars and then diagnose the issue so that we do not need to rely on customers to tell us.
I think it may be helpful for you and I to have a conversation so that you can get a view under the covers of what we are working on to improve this?
We have an all company summit during the 2nd half of this week, but if you would like to discuss later this month or next, please let me know and I can share my availability.
While I understand that Flock’s customer base means product managers are stretched pretty thin, we’re not talking about malfunctioning doorbell cameras or warranty repairs. We’re talking about tech that is capable of depriving people of their freedom, if not their actual lives, when it’s wrong. That’s the sort of thing that shouldn’t be met with vague promises to talk about this long-known, ongoing problem at some point in the next several weeks. That Flock doesn’t treat this as a priority shows it doesn’t care about anything more than selling cameras and raking in service/access fees.
Fortunately for residents of Roseville, Flock being wrong hasn’t led to police stops or wrongful arrests. That’s because the PD forces officers to personally verify plates and cannot use a plate read alone to justify a traffic stop.
But most places using Flock cameras don’t do that. Fewer still place any limits on access to the company’s database of billions of plate/location photos, which means cops from all over the nation are using junk data generated by faulty cameras to initiate stops and pursue investigations.
And it’s not just the false positives. Part of the PD’s frustration was Flock’s inability to generate records when officers needed them most. In at least two cases, vehicles driven by criminal suspects managed to pass through the network of Flock cameras without generating a single usable plate photo. Meanwhile, the cameras were turning 2’s into 3’s, N’s into V’s, and apparently just guessing when the cameras failed to capture an entire plate, rather than simply discarding the incomplete read.
Again, this doesn’t appear to matter to Flock. It will oversell its capabilities and blame everyone but itself when things go wrong. It has already shown it’s unwilling to improve until federal oversight starts demanding answers. And this approach to testing shows it’s not serious about actually improving its products:
In 2021, the research firm IPVM independently tested Flock’s license plate readers, concluding that Flock misidentified the state in about one of 10 reads, and that the system regularly misclassified vehicles’ type and make. IPVM said that Flock subsequently blocked it from purchasing its cameras for testing.
What’s weird about this is that the city of Roseville says it’s going to keep throwing money at Flock, despite its extensive record of failure. This makes it feel like less of a tech company and more like a cult. The feeling seems to be that if the cameras ever generate even a single arrest, they’re worth paying for, even when they’re wrong most of the time. And that’s something that can’t be fixed simply by changing surveillance providers.
I’ve written a few times now about how the Trump administration hijacked a $42.5 billion broadband investment fund included in the 2021 infrastructure bill, stripped away requirements that the resulting broadband be fairly deployed and affordable, and instead redirected billions of dollars to Elon Musk and Jeff Bezos in exchange for slower, more expensive satellite connectivity they’d already planned to deploy without subsidies.
Basically, this redirected tens of billions of dollars away from higher-capacity, faster, more reliable fiber access, and toward Low-Earth Orbit satellite services, which have a long list of problems I’ve explored in detail. The Trump administration then falsely claimed that they’d “saved” taxpayers roughly $21 billion (you can read my recent piece at The Verge for more detail on what that means for real people).
Here’s the thing. This $21 billion in “non-deployment funds” the Trump administration claims it “saved” is technically supposed to go to the states. Congress (aka, the law) specifically stated that the full $42.5 billion included in this Broadband Equity, Access, And Deployment (BEAD) was supposed to be spent on internet access or something very closely adjacent (digital skills training, telehealth tools).
“It’s anybody’s guess if nondeployment funds will ever be released. It’s now been 13 months since the NTIA changed the rules for nondeployment funds, and they are obviously in no hurry to see these funds ever get spent.”
This hasn’t gotten a ton of attention in a U.S. press that finds infrastructure too boring to cover, but it still obviously matters. There were various clumsy attempts to hijack these “non-deployment funds” for other purposes (Sen. Joni Ernst proposed using it reduce the federal deficit, others have wanted to throw it at AI data centers), but that would be technically illegal (for whatever that means anymore).
It seems likely that the Trump administration just hopes that people forget about the funding so it can be pocketed by crony capitalism and associates, but that hasn’t been easy. State leaders and even many Republicans have consistently peppered the NTIA with letters asking them what happens next to these funds, only to be met with more delays or silence.
It’s worth remembering that last election season, Republicans (with Ezra Klein and the “abundance” crew’s help) made a giant stink about how this program was taking way too long to connect anybody. For the whole 2024 election season, Republicans blasted the BEAD program’s bureaucracy and promised how once they were in power, they’d completely revamp it, speed everything up, and save taxpayer billions.
When that “revamp” arrived it involved creating all manner of costly new delays, stripping all the language out of the program ensuring funds were spent fairly and wisely, dumping a whole bunch of money into the laps of Elon Musk and Jeff Bezos, and then running off with half of the program’s funds and refusing to tell anybody what happens next.
In the interim, delays, high costs (from pointless tariffs and wars), and bureaucracy have resulted in even more original BEAD subsidy bidders backing off of their plans for widespread fiber, resulting in bid defaults, even more delays, and even more taxpayer money being thrown at Bezos and Musk for satellite broadband that’s too congested to handle the full load.
Great stuff. Very populist. Incredibly well thought out government efficiencies.
A couple of weeks ago we discussed how the cuts made to HHS and specifically the CDC’s FoodNet tracking platform were making it much harder to track and back trace the source of the country’s current cyclosporiasis outbreak. You’ll have heard about this outbreak in the news by now. It’s the one where you begin pooping yourself uncontrollably. It is not, however, funny. 10% of cases will result in hospitalization. The most recent counts from the CDC suggest that there have been more than 22,000 cases of the illness across 15 states. Those numbers are very much in question, however, both due to general underreporting and, again, funding and staffing cuts at CDC.
Just this week, in fact, we have now learned that two people in Michigan have died from cyclosporiasis. That information was and is, at the time of this writing, missing from the FDA’s dedicated page to inform the public on the outbreak. That page hasn’t been updated since July 24th, in fact, which is the exact opposite of what you’d want the government to be doing in a public health emergency. And it’s reportedly not because the government isn’t aware of these deaths.
While news of the deaths made widespread headlines Monday, federal health agencies under the Trump administration were mostly silent. The Food and Drug Administration—which is conducting traceback investigations to identify foods contaminated with the parasite—has not updated its outbreak investigation page since July 24, nearly two weeks ago, as of publication time.
The Centers for Disease Control and Prevention, meanwhile, added a banner notice on its outbreak update webpage saying that the agency was “aware” of the two cases. But its reporting data was not updated to include the two deaths as of this publication.
Why has this government been so slow to report accurately on these unfortunate deaths and the overall case counts for the outbreak? Some combination of those same budget and staff cuts along with a general apathy at HHS. With fewer people and resources to not only track the disease, but to maintain the dashboards meant to update the public, the numbers are slow to come in and untrustworthy when they do.
And with RFK Jr. at the helm of public health, well, the government is generally in the land of We-Don’t-Give-A-Shit.
Two weeks ago, Kennedy confidentially told reporters that the Cyclospora outbreak—linked to lettuce and other unidentified fresh produce—was “under control.” Last week, he announced his own cooking show on YouTube and released the first episode in which he helped prepare a meal that included a fresh salad.
The buffoonery on display from Kennedy and our health agencies is breathtaking. They should be assisting in combating this outbreak, along with those of measles and pertussis. Putting that aside, they should at least be able to tally up the case count numbers to demonstrate their own failures, but it’s clear they’re not really interested in doing that either. Instead, Kennedy in particular wants to host his cooking show and yell at journalists instead. Kid Rock must not be returning his calls any longer, I suppose.
Now, to be clear, this illness carries a 2 week incubation period, and the recalls of the suspected produce that is believed to have caused all of this are within a time frame that cases may still be stemming from that same source. But that’s not a certainty, and it will be important for our federal health agencies to continue to track cases in near real time to determine if there is, in fact, another vector by which cyclosporiasis is spreading.
Unfortunately, every indication is that those same health agencies just aren’t all that interested in doing this the right way.
On an afternoon in mid-May, dozens of Microsoft engineers and their managers gathered online and in a conference room at the company’s Redmond, Washington, headquarters to discuss Project Glasswing.
The tech giant was racing to fix weaknesses in its code that a new AI model known as Mythos was uncovering at an unprecedented clip. The AI behemoth Anthropic, which developed Mythos, had given access to select organizations that make software used by regular people, companies and governments across the world. The goal was to find and fix the vulnerabilities before hackers and adversarial governments like China began using similar tools to find and exploit them for espionage and sabotage.
As the group settled in, one engineer asked the question that loomed over the meeting: Did Mythos “live up to the hype that Anthropic claimed it would have had?”
“Yes,” a manager responded, according to a recording of the meeting viewed by ProPublica.
The version being used by Microsoft, Claude Mythos Preview, was surfacing bugs faster than the tech giant could patch them, and engineers, the manager said, were now in “a mad dash” to close the gap.
One slide in that day’s presentation showed that in April alone, Mythos had uncovered 90 “critical” bugs and 141 “important” ones in SharePoint, Microsoft’s widely used collaboration software. In the first half of May it found even more.
“Please, please, please if your org has any April bugs, drive those down,” engineering manager Hans Andersen implored the group. They had roughly two weeks “to find as many things and do as much good as we can with this access.”
May 31, he explained, “is considered the day when the rest of the world will have caught up.”
The engineers on the call poked at that assertion, with one of them summing up the predicament: “So basically you’re saying if it’s released on June 1, then on June 2 the adversaries will have our bugs?”
Yep, one person responded. Yep, another echoed.
Ever since Anthropic kick-started a national conversation about the bug-hunting power of AI in April, when Project Glasswing was made public, national security experts predicted that the U.S. would have a window of opportunity to fix flaws before adversaries would have similar models capable of discovering the same weaknesses. In late June, the international alliance of intelligence agencies known as the Five Eyes — whose members are the U.S., Australia, Canada, New Zealand and the U.K. — warned in an unusual joint statement that in a matter of months, that window would be closing. But the recording of the Microsoft meeting, along with internal documents reviewed by ProPublica, suggest the day of cyber reckoning may already be here.
Given the deluge of flaws Mythos has identified, Microsoft so far has focused on patching those it considers most dangerous, which are classified critical or important, according to the presentation as well as the company’s own public patch updates. The internal records indicate that Microsoft plans to eventually address “moderate”-severity flaws uncovered by Mythos. The documents made no mention of “low”-severity bugs.
The company’s approach reflects the triage system that is typical in the industry. Just as the sickest patients are the first to be treated in the emergency room, vulnerability triage prioritizes issues that are likely to cause the most damage if exploited by hackers.
But that strategy carries its own risk in this AI-powered bug-finding era, in which new tools are unearthing a record-breaking volume of weaknesses in the products we use every day. Mythos, for example, is able to chain together a string of bugs that build on one another, meaning that the low- and moderate-severity vulnerabilities that remain unpatched could create an opening to carry out devastating attacks.
“The problem now is that you can chain four low-level flaws, and that can equal a high severity,” said Vinh Nguyen, a senior technical adviser to Anthropic and a senior fellow for AI at the Council on Foreign Relations who formerly served as chief AI officer and chief data scientist at the National Security Agency. “If you’re Microsoft, the current triage strategy may be underpricing risks.”
In emailed responses to ProPublica’s questions, Microsoft stood by its approach, saying its triaging decisions are based on a number of factors, including exploitability and the impact on customers. The company presentation did not mention chaining, but a spokesperson told ProPublica that the technique “has long been considered as part of vulnerability assessment and risk analysis.”
Asked about the internal presentation and the then-looming May 31 deadline, the spokesperson downplayed its significance, saying that “accelerated targeting and exploitation of new vulnerabilities is not a new phenomenon.” That said, he added, the comments made during the meeting reflect how the company “feels a sense of urgency to help our customers at this time.”
“What was heard on that call and is true today is that security is Microsoft’s most important priority and teams across the company are prioritizing using AI to discover and remediate vulnerabilities as quickly as possible.”
Microsoft declined to answer questions about how many bugs engineers had patched since the presentation.
Anthropic declined to comment.
The internal Microsoft presentation and accompanying slides predicted that the group of staffers working on SharePoint, which is used by governments and businesses worldwide to manage data and documents, “will be busy for months,” first working through the highest-priority critical bugs then tackling the important ones in August. Microsoft says vulnerabilities it categorizes as critical include so-called worms that can crash systems and spread malware as they race across computer networks. Important ones could result in “compromise of the confidentiality, integrity, or availability of user data” as well as the “availability of processing resources.” After those categories were cleared, the group would begin work on roughly 300 “moderate” bugs, according to the presentation.
While the internal documents reviewed by ProPublica do not include updates on the entire breadth of Microsoft’s offerings, they do give a sense of the scale of the problem. One document noted that, since the company started using Mythos earlier this year, it had collectively found hundreds of bugs that Microsoft categorized as either critical or important in popular products such as Microsoft 365, the Teams conferencing platform and the Copilot AI tool. As of mid-May, most of them had yet to be patched.
“They’re not profound and exotic, but they’re real,” Andersen, the engineering manager, said during the meeting. “And a lot of them are exploitable.”
It’s unclear whether hackers have exploited any specific bug identified by Mythos, but some have tapped AI to automate attacks and appear to be using Mythos-like tech to find and exploit weaknesses.
There have been outward signs of Microsoft’s internal struggle to deal with the growing list of bugs to be patched. Each month, the company publicly releases fixes for its software vulnerabilities in what’s known as “Patch Tuesday.” In June, it released patches for more than 200 bugs, which industry experts then said was an all-time high. But on July 14, the company blew through that record and released patches for more than 600 bugs. Only seven were categorized as low- or moderate-severity, one of which hackers were actively exploiting, according to Dustin Childs, leader of the Zero Day Initiative bug bounty program, which is part of cybersecurity company TrendAI. The rest were important or critical.
“Well folks. Here we are. The bug apocalypse has fully descended upon us,” Childs wrote in a blog post on July 14.
Microsoft told ProPublica that the overall volume of bugs “will not be plateauing for a bit,” but a spokesperson said the company has “invested heavily in both people as well as AI-powered triage solutions that scale quickly to handle the growing number of vulnerabilities.”
Given the new realities of the AI age, including the chaining capabilities, companies like Microsoft might need to rethink their entire approach to triage, said Nguyen, the NSA’s former AI chief. Rather than shunting what are now considered low-risk flaws aside, companies should be dedicating staff to developing and testing patches for the entire spectrum of vulnerabilities, he said. In other words, the cyber ER needs more doctors and nurses treating illnesses that are life-threatening as well as the minor wounds that could later turn deadly.
“There’s no alternative,” Nguyen said. “The patients are coming in fast and furious.”
Microsoft told ProPublica it’s “always going to be reevaluating and considering whether things that were previously lows or moderates be upgraded or thought about differently. With these AI systems, it makes us rethink some of these things. Across the industry, we’re all looking to see how drastic of a change it will be.”
Microsoft’s users may be particularly vulnerable. The popularity of its offerings, used the world over, makes it a frequent and lucrative target for hackers. In addition, many of its products contain “legacy” code. Developed decades ago using now-outdated technology, this code contains unaddressed flaws and contributes to what is known in the industry as “technical debt.”
But the challenge of fixing the flood of newly found bugs also extends to the rest of the software industry, and to open-source software code that is typically free to use and largely maintained by volunteers. Open-source software underpins internet infrastructure and is incorporated into much of the world’s modern technology, including products offered by major tech companies such as Microsoft.
“Nobody has really figured out how to deal with this, and everybody is casting around for what they need to do,” said J. Michael Daniel, a former cybersecurity adviser to President Barack Obama and the president of the Cyber Threat Alliance, a nonprofit organization focused on cybersecurity. “Our tech debt is coming due.”
Ben Edwards, a data scientist who specializes in managing software vulnerabilities, said the software industry was handling an “intense volume even before AI.”
“It was like drinking from a garden hose on the jet setting before, and now it’s like drinking from a fire hose,” Edwards said. “They might have had the teams that could handle that garden hose. Whether they can handle the fire hose is something else.”
Although the volume of vulnerabilities has grown over the years, Microsoft’s internal group responsible for fielding them, the Microsoft Security Response Center, has been perennially understaffed. Even before the crush of AI-identified bugs, the center fielded hundreds or even thousands of reports a month, pushing the group to its limits, ProPublica has reported.
The size of the center reflects Microsoft’s corporate philosophy: Plugging security holes is a cost center, while making new products is a profit center, former employees said. The company is loath to tie up its best engineers with making security patches — a cost center — instead of developing new products and features that will generate profits, ProPublica has reported.
Microsoft told ProPublica that it does not discuss internal staffing decisions but has made investments in recent years to “focus our teams on keeping our customers secure.” The company “continuously evaluates the staffing, processes, and technologies required to support security response and vulnerability management,” a spokesperson said.
According to the slides that accompanied the May internal presentation, Anthropic provided Mythos access to roughly 50 full-time Microsoft employees, with a goal to “harden critical services before publicly available models catch up.” A slide titled “What’s Next” predicted that the Microsoft Security Response Center would see continued case volume “as public tools catch up” to Mythos.
During the May meeting, one staffer appeared to take comfort in the belief that adversaries “don’t have the source code” that such an AI tool would scan for weaknesses. His colleagues, however, quickly corrected him. Portions of Microsoft’s code have, in fact, fallen into hackers’ hands over the years.
“It might not be this week’s source code,” one person said. “But they’ve got source code. It’s out there.”
In a statement to ProPublica, Microsoft downplayed the comment, saying engineers “design our security processes on the expectation that determined adversaries may gain access to code.”
Donald Trump took possession of a $400 million “gift” plane from the Qatari government earlier this year. Trump claimed it was a coup for taxpayers and a boon for America, even as he made it clear this was all about him. According to Trump, no plane was more luxurious than this graft-y replacement for the Air Force One. He bragged about how much it reflected his own taste in upmarket products, which meant the plane’s interior was undoubtedly festooned in gold leaf and stocked with steak-grade ketchup.
But was it secure? That’s kind of a big deal when it comes to presidential transport. Turns out it wasn’t. Trump rode his graft jet to Turkey for a diplomatic meeting but was forced to ride the old Air Force One out of the country when it was discovered his new gaudy aircraft didn’t possess the necessary security measures/counter-measures.
In response to this reporting of the Air Force One Mk. II’s failure, the Trump administration behaved like the Trump administration: it subpoenaed the New York Times reporters, demanding all sort of information in hopes of uncovering the reporters’ government sources.
That’s not how this is supposed to work. The FBI and DOJ both have extensive guidelines that are meant to discourage open attacks on the First Amendment. All of these appear to have been ignored in the administration’s haste to find out who needed to be punished for telling the truth about Trump and his Qatari luxury jet.
Fortunately, the court curb-stomped the DOJ when the New York Times challenged the subpoenas. The DOJ really had no answer for the court’s questions, given that the court had plenty of precedent to work with while the DOJ was limited to being a nominally prehensile Trump appendage. Faced with the (admittedly slim) prospect of being sanctioned by a thoroughly irritated federal judge, the DOJ withdrew the subpoenas.
But that’s not the end of the story, apparently. The administration is targeting anyone remotely related to the New York Times and/or reporting that doesn’t please Donald. The New York Times is now going to bat for one its freelancers, who has also been targeted by this vindictive administration.
In February, F.B.I. agents showed up at the New York home of the reporter, Matthew Cole, to deliver the grand jury subpoena, which was issued by prosecutors in Newport News, Va., according to the people familiar with the matter, who described the private conversations on the condition of anonymity.
The investigators are seeking his testimony about two years’ worth of information about Mr. Cole’s contacts and conversations, as they try to identify his sources for the article about the operation in North Korea, the people familiar with the matter said. It is unclear if the administration has also sought Mr. Cole’s phone and email data, as it has done in other cases.
This is apparently related to Cole’s reporting about a failed surveillance operation authorized by Trump during his first term in office — one that was carried out in hopes of planting a recording device capable of intercepting Kim Jong-un’s communications.
For the operation, the military chose SEAL Team 6’s Red Squadron — the same unit that killed Osama bin Laden. The SEALs rehearsed for months, aware that every move needed to be perfect. But when they reached what they thought was a deserted shore that night, wearing black wet suits and night-vision goggles, the mission swiftly unraveled.
A North Korean boat appeared out of the dark. Flashlights from the bow swept over the water. Fearing that they had been spotted, the SEALs opened fire. Within seconds, everyone on the North Korean boat was dead.
The SEALs retreated into the sea without planting the listening device.
No one likes discussing a failed operation, so understandably this one hadn’t been publicly discussed prior to Cole’s report (with an assist by Dave Philipps). But this attempt to pressure Cole into revealing his sources seems more motivated by Trump’s unwillingness to discuss this mission with the people he’s supposed to be discussing these things with.
The Trump administration did not notify key members of Congress who oversee intelligence operations, before or after the mission. The lack of notification may have violated the law.
What’s inexplicable in normal terms is why this wasn’t a problem until now. This article was published last September. The underlying incident occurred in 2019. But it took until February 2026 for the administration to do anything about it. The Trump administration is far more aggressive and far less respectful of the law this time around, which explains why it would move against this reporting now. However, the delay between the reporting and revenge suggests this was a reaction to Trump seeing something on social media, rather than his administration engaging in a thorough internal investigation for months before deciding it needed to do damage to the First Amendment to move this forward.
Hopefully, this subpoena will soon be tossed into the Trump DOJ discard pile. But losing all the time won’t stop this administration from going after journalists for reporting on Trump’s failures. This administration is incapable of learning from its mistakes because it thinks it’s never wrong. The war on journalists will continue as long as Trump — and the GOP he’s turned into a MAGA puppet — holds power.