CVE-2026-83991: Windows Cloud Files access-check bypass https://github.com/karollooool/CVE-2026-83991-writeup-and-poc
OpenAI claims that they used 300 billion output tokens from a swarm of ~10,000 concurrent instances of an internal model that is almost certainly larger and more expensive to run than GPT-6. That's the total token output, including exploring related problems, which, along with spying on other researchers work via codex, "led them to the solution," so that should be considered the minimum accounting - the lower token count focused just on the proof excludes token use that would normally be considered a dead-center part of "working on a problem."
Token use is only a fraction of the cost here, but it's the best estimate we have: this would be billed as R&D, much bigger than cost of service, and so costs here are actually a big slush. the internal model could be 60 quadrillion parameters for all anyone knows. there's no reason to believe any of openAI's numbers here at all, so our conservative estimate will be conservative among possible conservative estimate universes - there are some motivations to inflate token usage, but given the um minified python defaults of GPT-6, we assume OpenAI wants to be seen as minimizing token output per task.
All of OpenAI's API costs are presumed to be subsidized, lower than the actual cost of running the models. If one were to pay the API costs for 300 billion tokens for GPT-6, at $75 per million output tokens with long context, that would be 22.5 million dollars of tokens (the minimum, assuming 100% cached output with short context is still 3.75 million, but that's an unrealistic minimum). OpenAI apparently also had a full team of people working on this, so 22.5 million doesn't include their salaries, etc.
Tristan Buckmaster only has one grant listed from NSF, a CAREER grant for $450k from 2022 through 2028, averaging $70k per year the last three years.
If i search the NSF grants database for any award from the Division of Mathematical Sciences with "navier-stokes" in the abstract (surely, imprecise, and most likely a sizeable overcount because this is "all work that mentions the equation" not "work spent specifically on the millenium prize proof"), then i get $135m worth of awards since 1978, including large training grants for centers, etc. so $22.5m would be ~16% (or, roughly, 1/6th) of all funding that NSF has allocated to research that mentions the problem in their grants for almost 50 years.
If i then use NSF's API to find all the publications that have come from these grants, I find 4,928 papers. I can match 4264 to entries in OpenAlex (85%), yielding 142,606 citations (1/6 of which is 710, and 23,767, respectively).
So, assuming we believe OpenAI's accounting, the headline is basically "OpenAI researchers seem to have stolen the work of mathematicians that were using Codex, and then spent 1/6 of all the funding NSF has given with abstracts mentioning navier-stokes over the past 50 years, which amounts to an entire subdiscipline of work, feeding, housing, and training generations of mathematicians, in order to generate proof of two of the statements in a millenium prize problem"
I dont know how NSF funds math, but i sort of doubt they give grants for "try to solve millenium problems full stop." idk, maybe an alternative strategy would be to just "fund basic research," because even in this specific domain of an axiomatic universe with an unambiguously evaluable solution to a problem where brute force is possible, "AI" doesn't seem like it's really that much of a bargain, and "paying people to be experts at things" has lots of known good side effects like "someone actually understands the solution"
Anthropic formalized Fermat's Last Theorem in 13M lines of Lean. We "proved" it in 20 lines by exploiting a bug we found in Lean.
Root cause: Lean's string slicing has two implementations, the logical definition and the compiled C++. At position 2^63 they disagree: one returns "", the other the whole input. This bug causes Lean to accept two contradictory facts, which then lets you "prove" anything, including FLT. https://blog.trailofbits.com/2026/09/09/a-proof-of-fermats-last-theorem-that-fits-the-margin/
In short, the indiscriminate use of powerful solution-extraction tools can achieve the immediate short-term goal of solving problems at hand, but at the cost of sustaining the ecosystem for the next wave of progress, or in understanding the progress already obtained.
While it may be technically infeasible to completely prohibit the use of automated tools to perform indiscriminate solution extraction, I believe that we can still designate many classes of problems as being desirous of a careful analysis that not only solves the problem, but identifies insights from the solution process, and learn more about the difficulty landscape for nearby problems, and for which raw solutions without such analysis would be of negligible or even negative value for these purposes. This is analogous to how a modern food donation drive no longer accepts arbitrary contributions even when they are verified to be technically edible, but instead maintains explicit and socially accepted standards on what level of contributions are actually sought. (4/4)
"Is that encryption load bearing?"
"No, it's emotional support cryptography"
Another 3 Windows LPE's I found just patched in September patch Tuesday!
CVE-2026-68839 - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68839
CVE-2026-69720 - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69720
CVE-2026-69571 - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69571
Today, Project Zero is releasing MAccConc, a tool by @tehjh that enables deterministic testing of race conditions on Linux. It can be used for fuzzing, ad-hoc exploration, regression tests and more!
https://projectzero.google/2026/09/maccconc-race-condition.html
While researching last months N-able N-central exploit (CVE-2026-18577, on KEV), we found and reported a new authentication bypass chain (CVE-2026-86206 and CVE-2026-86207). Patched and disclosed by the vendor over the weekend, we have published full details on the @rapid7 blog: https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed/
Project Glasswing:
Claiming to have found 26 thousand real vulnerabilities but only 0.8% of them have resulted in a real fix in a real project after five months is dire. They blame it on the human independent review bottleneck, but human experts being paid for their time definitely have a higher throughput than that when working with data that’s actually actionable.
The assigned-at-Claude severity ratings are also dire. It assigns “high” or “critical” to 91% of findings. Most findings in the real world are low or medium. This should be especially true when using a magic machine to shake out every last little issue that was overlooked by humans focused on the biggest risks.
[Edit: I should be more careful and note that this figure is calculated only from findings which have received a second opinion from project maintainers, which is much higher than the 0.8% fixed rate but much less than the entire dataset, so there’s probably bias towards reviewing those with critical ratings first. However, the maintainers found the high/critical rate to be quite inflated.]
Together this implies it’s generating thousands of trivial or nonsensical findings and labeling them HIGH DANGER CRITICAL MUST FIX, and the human independent verifiers are sifting for the rare needle in this haystack worth passing on. This isn’t really an improvement over the high-noise automated scanners we already had
(This is a corporate blog of someone with their own vulnerability management services to sell, so apply an appropriate number of grains of salt to their analysis. Filter keywords: AI LLM Anthropic)
However, one notable feature of the current AI era is the absence of any definitive such boundaries. While AI tools have flattened the difficulty landscape now in many areas of the subject, thus destroying the ability to locate promising new problems in that area, there are no clear frontiers that are separating the "AI-feasible" problems from the "AI-hard" problems (which certainly still exist, given that the difficulty level of problems are unbounded, and can even be undecidable). This is in part due to the rapidly changing nature of the technology, but also compounded by the refusal of AI companies to disclose their negative results, or reveal the process towards obtaining their solutions.
In fact, it is now the identification of a promising problem which is the scarce and precious resource. We have now seen that even the rumor of someone working on a problem can trigger a massive amount of AI-powered effort to flatten it before the original research project has time to reach its full potential. The incentives may now be pointing in the direction of no longer sharing any promising research directions with the broader community, which would reverse centuries of traditions of open science and do serious long-term damage to the future of the field. (3/4)
"One guy in #Sweden built a #searchengine to fight Google, and it works.
It's called #MarginaliaSearch.
It runs its own #crawler and builds its own #index instead of borrowing Bing's. It has no ads, no investors, and no loans.
What it does differently: it ranks for text-heavy, non-commercial pages. Personal blogs. Old university pages.
The weird corners SEO strangled. Every result tells you whether the page uses affiliate links and JavaScript, and you can filter them out.
There's an "explore" mode that just shows you random sites from the index. It's open source under AGPL, so you can host your own copy.
It's keyword-based, so don't type a full question at it. Type two nouns and see where you land. Every #searchengine now shows you the same twelve #monetizedpages."