Microsoft Flags ACR Stealer Surge as GPT-5.6 Closes 30-Year Optimization Gap
Enterprise credential theft is accelerating as stealer malware pivots from passwords to session tokens — while on the same day, AI reportedly closed a 30-year gap in mathematics and a proof assistant formally verified what two camps of mathematicians have been arguing about since 2012.
Security
Microsoft has flagged a significant surge in ACR Stealer campaigns targeting enterprise customers, harvesting browser-stored passwords, authentication tokens, and sensitive documents. The emphasis on authentication tokens is the operationally important detail: attackers who capture valid session cookies can replay them to bypass MFA entirely, converting a single compromised endpoint into full account takeover without ever needing a password. If your organization relies on browser-stored session state and hasn't deployed endpoint behavioral monitoring, this campaign is a concrete reason to revisit that gap today.
For those looking at hardware alternatives, the RS-Key project offers open-source FIDO2 and OpenPGP firmware for the RP2350 microcontroller — a cheap, auditable path to rolling your own hardware security key if commercial vendor trust is a concern. The RP2350 is widely available, which makes this genuinely accessible rather than a hobbyist curiosity.
On the policy frontier, age verification vendor Incode is pitching on-device facial age estimation that never transmits or stores biometric data. The privacy architecture is the right starting point. Whether regulators will accept probabilistic on-device estimation in place of ID-verified gatekeeping — and whether they should — remains the live question as age verification mandates expand.
AI
The most technically striking item: GPT-5.6 reportedly used a single prompt to close a 30-year gap in convex optimization research, following OpenAI's earlier CDC proof announcement. The Reddit thread is short on technical specifics and independent verification hasn't landed, but if the claim holds it marks another step toward frontier models contributing meaningfully to unsettled mathematics rather than just pattern-matching known results. OpenAI appears to be deliberately sequencing these announcements to build a formal-reasoning narrative — which is itself worth noting as a communications strategy.
Moonshot AI released a new version of its Kimi model, generating the predictable commentary about Chinese AI competition. A separate analysis frames Kimi K3 as a strategic inflection; TechCrunch is more measured, noting that "full AI communism" takes say more about Western anxieties than Kimi's actual capabilities. Benchmark-to-real-world translation data isn't here yet.
Sam Altman invited author Dave Eggers to speak to roughly 200 OpenAI employees. Eggers told them that ChatGPT was "silencing an entire generation" of writers. That Altman arranged this, and that The Verge was positioned to report it, is as interesting as the message itself — a deliberate surfacing of the critique inside the company. Whether it reflects genuine ambivalence or controlled image management is hard to read from outside.
The U.S. government is piloting AI for insurance prior-authorization decisions. The case for it is real: prior auth creates genuine clinical delays and burns physician time. The failure mode is also real: AI that optimizes for denial throughput could industrialize harm at scale. The difference between "AI assists human reviewers" and "AI replaces human reviewers" is enormous in this context, and that line tends to move quietly once a system is deployed.
A quieter operational story: unexplained weekly quota resets for AI agents have been appearing across multiple providers. The piece documents the pattern without a clean explanation — which is itself the point. As AI agents move toward production use, opaque rate-limiting is a reliability problem vendors haven't publicly addressed.
Tech
The single most significant result: Fumiharu Kato has confirmed in Lean that there is a genuine gap in Shinichi Mochizuki's claimed proof of the ABC conjecture. Mochizuki's inter-universal Teichmüller theory has been contested since 2012 — Peter Scholze and Jakob Stix identified a specific gap in 2018, but Mochizuki disputed the criticism and the standoff persisted for eight years. Having a formal proof assistant surface and machine-verify the gap transforms the dispute from "two camps of mathematicians disagreeing" to a verified structural fact about the proof. This is both a significant mathematical result and a demonstration of what formal verification tooling has become capable of.
Oracle's datacenter expansion is running into multibillion-dollar cost surprises, per The Information. The specifics are paywalled, but the headline is a useful counterweight to the narrative that hyperscalers have large-scale GPU infrastructure buildout fully under control. Power, cooling, and construction at these densities are proving harder to forecast than the market assumed.
SpaceX is drawing short interest shortly after its IPO, with traders betting against the company. The FT separately questions the independence of Wall Street research covering SpaceX. Two pieces in one outlet on the same day suggests the scrutiny is not incidental — public markets are doing what public markets do to companies that have never had to answer to them before.
Federal employees can download TikTok on government devices again after the DOJ reversed course. The policy has now flipped multiple times. Whatever the security rationale for the original ban, the repeated reversals make it difficult to argue the restriction was ever grounded in a consistent threat assessment.
Two EV data points worth holding together: a 600-mile road trip documented meaningfully faster and more reliable DC fast charging than prior years — while simultaneously, a growing list of EV models including the Honda Prologue have been discontinued or pulled from the U.S. market. Infrastructure improving as model availability contracts is an odd combination.
NYC Mayor Mamdani has banned landlords from using AI-generated images to advertise rental properties. A small policy with a specific harm in mind — a useful early template for what AI-generated content disclosure requirements might look like in commercial contexts.
Formal verification is gaining teeth, AI infrastructure economics are proving stubborn, and the social costs of deployed AI are showing up in places no one quite planned for.
Also yesterday
- Unauthenticated RCE in WordPress Core: Update to 6.9.5 / 7.0.2 Immediately
- LG Monitors Silently Install Software via Windows Update Without Consent
- WordPress Core 'wp2shell' RCE Vulnerabilities Now Have Public Exploits — Patch Immediately
- Microsoft warns of surge in ACR Stealer attacks on customers
- RS-Key: Security Key. Fido/OpenPGP Firmware for RP2350
- The Future of Age Verification: Your Face Never Leaves Your Device
- GPT-5.6 used a prompt to close a 30-year gap in convex optimization
- Kimi: Threat or menace?
- The Kimi K3 Moment
- Dave Eggers told OpenAI staff that ChatGPT was ‘silencing an entire generation’
- Will AI fix prior authorization—or make it worse?
- What's the deal with all the random weekly quota resets for agents lately?
- Gap in Mochizuki's proof of ABC confirmed by Lean
- Exclusive: Oracle Data Centers Face Multibillion-Dollar Cost Surprises
- Traders are increasingly betting against SpaceX just weeks after IPO
- SpaceX and the myth of independent Wall St research
- Federal employees can download TikTok on their work phones again
- A 600-mile road trip (and data) proves EV charging doesn’t suck anymore
- All the EVs that were discontinued or killed off in the U.S. this year
- Mayor Mamdani Says Landlords Can't Use AI Images to Advertise
Synthesized by Claude · sanity-checked before publish.