Alvaro Lopez Ortega / 2025-06-19 Briefing

Created Thu, 19 Jun 2025 19:10:05 +0000 Modified Sat, 28 Jun 2025 02:44:34 +0000
3296 Words

Today’s top stories include Google’s Pixel 10 switching to TSMC for its Tensor G5 chip amidst Samsung’s yield issues, Iran’s internet shutdown amid alleged Israeli cyberattacks, and the US offering a $10 million bounty on Iranian hacking groups targeting critical infrastructure. Additionally, AI’s environmental impact and cognitive effects remain a major focus.

▶️ Internet Infrastructure

Google’s Pixel 10 Switches to TSMC for Tensor G5 Chip Amid Samsung Concerns

Google’s Pixel 10 will feature the Tensor G5 chip produced by TSMC, shifting from Samsung and highlighting Samsung’s yield issues and asset limitations, impacting industry dynamics.

  • Google’s Tensor G5 chip in Pixel 10 will be manufactured by TSMC, marking a shift from Samsung’s foundry.
  • Samsung’s internal inspection considers the switch a “shock” and a wake-up call for its foundry efforts.
  • Samsung’s 3nm process yield is around 50%, while TSMC’s is approximately 90%, influencing Google’s decision due to performance and asset diversification.
  • Google’s move is part of a broader industry trend away from Samsung’s foundry services.
  • Pixel 10 will still use a Samsung modem, specifically an Exynos model, despite the change in chip manufacturing.

Docker Pussh Simplifies Secure Direct Docker Image Transfers Over SSH

docker pussh enables direct, layer-efficient Docker image transfer over SSH to remote servers, eliminating registry setup, with support for multi-platform images and various installation methods.

  • docker pussh pushes Docker images directly to remote servers over SSH without using an external registry
  • Transfers only missing layers by establishing an SSH tunnel, starting a temporary unregistry container, and forwarding ports for efficient image transfer
  • Compatible with Docker CLI 19.03+ and supports multi-platform images via --platform flag; installation via Homebrew, direct download, or WSL2

Private Individual Revives Torrent Tracker, Reaching Over 3 Million Peers

A private individual revived a dead torrent tracker at udp://open.demonii.si:1337/announce, achieving over 3 million peers and 1.7 million torrents, raising legal and ethical considerations.

  • Resurrected the tracker at udp://open.demonii.si:1337/announce by purchasing the domain and deploying opentracker on an anonymous VPS
  • Tracker handled approximately 1.7 million torrents and 3.1 million peers, with peak UDP port 1337 traffic reaching over 58 million overall connections
  • Response from http://open.demonii.si:1337/stats?mode=everything showed 1,735,538 torrents, 3,155,701 peers, and 1,342,504 seeds after about an hour of operation

Iran’s Nobitex loses $90M in hack claimed by pro-Israel group

Iran’s Nobitex exchange was hacked, losing at least $90 million, with stolen funds burned; the attack was claimed by pro-Israel group Predatory Sparrow amid Iran-Israel tensions.

  • Iran’s largest crypto exchange, Nobitex, was hacked, resulting in the theft of at least $90 million from its hot wallet.
  • Hackers “burned” the stolen funds by sending them to inaccessible wallets, removing them from circulation.
  • The attack was claimed by pro-Israel hacking group Predatory Sparrow, citing motives related to Iran’s alleged financing of terrorism and sanctions evasion.

ScyllaDB X Launches Raft-Based DBaaS for Rapid, Scalable Data Operations

ScyllaDB launched ScyllaDB X, a DBaaS using Raft-based tablets for scalable, elastic data distribution, enabling rapid scaling from 100,000 to 2 million OPS with low latency.

  • ScyllaDB released its new DBaaS, ScyllaDB X, utilizing Raft consensus algorithm with a tablets architecture to enhance scalability and elasticity.
  • Tablets support flexible data distribution, enabling near-instant bootstrap and parallel node addition, allowing cluster doubling.
  • The system scales from 100,000 OPS to 2 million OPS in minutes with steady single-digit millisecond latency, reducing costs compared to similar systems.

Veeam Patches Critical RCE CVE-2025-23121 in Backup Server Versions

Veeam patched its third critical RCE (CVE-2025-23121, CVSS 9.9) affecting version 12, addressing deserialization flaws linked to BinaryFormatter; version 13, in beta, will remove this component.

  • Veeam released patches for CVE-2025-23121, a critical RCE vulnerability with CVSS v3 score of 9.9, affecting only domain-joined backup servers.
  • The vulnerability impacts all Veeam Backup & Replication version 12 builds except 12.3.1.1139; the fix addresses this flaw and two other less-severe code execution issues.
  • The CVE-2025-23121 is linked to uncontrolled deserialization via deprecated BinaryFormatter, which Veeam plans to remove in version 13, scheduled for H2 2025, currently in beta.

Voltron Data’s Theseus SQL Engine Gains Support for AMD Instinct GPUs

Voltron Data’s Theseus SQL engine will support AMD Instinct GPUs, enabling GPU-accelerated SQL processing with high performance and scalability, reducing reliance on Nvidia’s CUDA ecosystem.

  • Voltron Data’s Theseus SQL engine will support AMD’s Instinct GPUs, extending GPU-accelerated SQL capabilities beyond Nvidia hardware.
  • Theseus, introduced in late 2023, uses GPUs to accelerate large-scale SQL queries, demonstrated by completing the TPC-H 100TB benchmark in under an hour.
  • Early benchmarks on AMD MI300 series show strong performance and scalability; support for Instinct accelerators remains in preview with production expected later this year.

IEA Launches Energy and AI Observatory to Track Growing Datacenter Energy Use

IEA’s Energy and AI Observatory maps global datacenter hubs, showing AI’s role in doubling energy use by 2030, with AI optimizing energy systems and infrastructure.

  • IEA launched an online Energy and AI Observatory to monitor global AI energy impact, featuring interactive maps of datacenter hubs, capacity, and regional energy demand.
  • AI-driven datacenter energy consumption is projected to more than double by 2030, surpassing Japan’s total energy use, with AI-optimized datacenters expected to quadruple in energy demand.
  • The Observatory highlights large-scale datacenter clusters in North America, Europe, and Asia-Pacific, and details AI applications in energy price forecasting, electricity access, and building energy management.

Iran Cuts Internet Amid Alleged Israeli Cyberattacks

Iran’s government temporarily restricted internet access amid alleged cyberattacks linked to Israel, including bank disruptions and cyber operations, with traffic near zero since June 18, 2025.

  • Iran’s government reportedly shut down internet access within its borders, with traffic dropping near zero late on June 18, 2025, and remaining suppressed.
  • The shutdown was allegedly in response to Israel-linked cyberattacks, including disruptions at Iran’s Bank Sepah and targeted cyber operations claimed by groups like Predatory Sparrow.
  • Iranian authorities cited measures to prevent “enemy abuse,” with reports of restrictions on platforms like WhatsApp and claims of cyber offensive preparations by Israeli military officials.

Microsoft Unveils Windows 365 Reserve for Temporary Cloud PC Access

Microsoft is previewing “Windows 365 Reserve,” offering temporary cloud PCs for up to 10 days per year with preloaded apps and policies, enabling quick access during device failures or loss.

  • Microsoft is testing “Windows 365 Reserve,” a service providing pre-configured cloud PCs available up to 10 days annually for an undisclosed fee
  • Cloud PCs will include Microsoft 365 apps, user security policies, and Windows customizations, accessible via Windows App or browser within minutes
  • The service features data synchronization with OneDrive, management through Microsoft Intune, and enhanced security with virtualization-based security and disabled redirections

Serpentine#Cloud Uses Cloudflare Tunnels for Large-Scale Python Malware Campaign

Securonix detected Serpentine#Cloud, a large-scale campaign exploiting Cloudflare tunnels to deliver multi-stage Python malware, enabling persistent remote access and data theft.

  • Campaign dubbed Serpentine#Cloud uses Cloudflare tunnels to deliver Python-based malware, including in-memory payloads like AsyncRAT and Revenge RAT
  • Attack chain involves phishing emails with invoice-themed .lnk files, triggering multi-stage infection using batch, VBScript, and Python stages
  • Utilizes Cloudflare’s TryCloudflare tunneling services for hosting payloads, blending malicious traffic with legitimate TLS certificates, avoiding detection and attribution
  • Infection stages include downloading and executing a VBScript loader, obfuscated batch files, and Python shellcodes that establish persistent control over infected hosts
  • Campaign is widespread, with infections in the US, UK, Germany, Singapore, and India; no attribution to specific threat actors but suggests sophisticated, scalable delivery methods

▶️ Open Source

Open-Source Fitness Platform “workout.cool” Launches with Workout Plans and Tracking

“workout.cool” is a modern open-source fitness platform offering workout plan creation, progress tracking, and a comprehensive exercise database, with detailed setup and import procedures.

  • Open-source fitness coaching platform “workout.cool” launched, enabling creation of workout plans, progress tracking, and access to exercise database with videos and instructions
  • Repository has 1.7k stars, 56 forks, and is licensed under MIT
  • Provides detailed setup instructions for local development, database import via CSV with attribute types like TYPE, PRIMARY_MUSCLE, SECONDARY_MUSCLE, EQUIPMENT, MECHANICS_TYPE

Scrappy: A Prototype Platform for Sharing Live JavaScript Apps

Scrappy is a prototype platform enabling users to create live, shareable, multiplayer apps with JavaScript, focusing on democratizing home-made software for personal and collaborative use.

  • Scrappy is a prototype tool for creating small, shareable apps (“Scrapps”) for personal or collaborative use, emphasizing ease of sharing and real-time editing.
  • Examples include arithmetic practice, attendee counters, meeting clocks, and chore trackers, all built via an interactive canvas with JavaScript-based behaviors.
  • Future development aims to improve accessibility for non-programmers, support collections and reusable components, enhance sharing/remixing, and optimize mobile usability.

Asana Fixes Data Exposure Bug in MCP Server After Shutdown

Asana restored its MCP server after fixing a bug that could have exposed organization data, following a nearly two-week shutdown due to a security vulnerability in the open-source protocol.

  • Asana fixed a bug in its MCP server that could have exposed user data to other organizations
  • The MCP server, an open-source protocol by Anthropic, was shut down from June 5 to June 17 for maintenance
  • The vulnerability potentially allowed cross-organization data access; no evidence of exploitation or data leaks reported

KDE Plasma 6.4.0 Launches with Enhanced Tiling, Wayland Support, and Visual Improvements

KDE Plasma 6.4.0 launched with major usability, Wayland enhancements, advanced tiling, accessibility, and visual refinements, supporting full Wayland support and cross-platform OS compatibility.

  • KDE Plasma 6.4.0 released on June 18, 2025, featuring enhanced window tiling, accessibility, and visual improvements.
  • Introduces multi-layout tiling that remembers different configurations per virtual desktop, improved Wayland support, and refined notifications.
  • Adds keyboard navigation, mouse control via keyboard, multi-finger gestures, deeper contrast in dark mode, and better graphics tablet and HDR display management.

GitHub Malware Steals Data via Fake Minecraft Cheats Linked to Stargazers Ghost Network

Malware on GitHub disguises as Minecraft cheat tools, infecting over 1,500 devices by stealing credentials, crypto wallets, and personal data through multi-stage Java and .NET payloads, linked to Stargazers Ghost Network.

  • Check Point Research identified approximately 500 GitHub repositories hosting trojanized Minecraft cheat tools, with about 70 accounts receiving 700 stars.
  • The malware campaign, active since March, is attributed to Russian-speaking developers linked to the Stargazers Ghost Network, targeting gamers for data theft.
  • Malicious tools, mimicking popular cheats like Oringo and Taunahi, execute multi-stage attacks including environment checks, stealer payloads in Java and .NET, exfiltrating credentials, crypto wallets, and sensitive data via Discord webhooks.

Murena Launches /e/ OS 3.0 with Privacy Features and Broad Device Support

Murena’s /e/ OS 3.0, based on Lineage OS 21, introduces parental controls, privacy reports, and a privacy-focused browser, supporting 221 devices since 2016, with May 2025 security updates.

  • /e/ OS 3.0 released by Murena on June 19, 2025, based on Lineage OS 21 with Android May 2025 security patches
  • Adds features including parental controls with five age brackets, app installation passcode, privacy reports, and built-in Murena Find search engine
  • Version 3.0.1 fixed crash when using VPN with IP hiding; supports 221 devices dating back to 2016

▶️ Software Development

Zed Launches Multi-Language Debugger with Scalable Architecture and Inline Variables

Zed launched a customizable, fast debugger supporting multiple languages and DAP extensions, with architecture optimized for scalability, collaborative debugging, and inline variable visualization using Tree-sitter.

  • Zed released its debugger on June 18th, 2025, supporting languages including Rust, C/C++, JavaScript, Go, and Python with extension support for any Debug Adapter Protocol (DAP).
  • The debugger features a two-layer architecture: a data layer for direct communication with debug adapters and a UI layer for rendering, enabling efficient caching, response management, and scalability for collaborative debugging.
  • Supports automatic debug configuration via locators for Cargo, Python, JavaScript, and Go, with future support for additional languages; inline variable values are supported for Python, Rust, and Go using Tree-sitter queries.

▶️ Management and Leadership

Anthropic Urges Simple, Transparent LLM Agents Over Complex Frameworks

Anthropic advocates for simple, modular LLM agent design, emphasizing direct API use, transparency, and iterative testing, with complex frameworks only when necessary for scalability or flexibility.

  • Anthropic’s Dec 19, 2024, article emphasizes building simple, composable patterns over complex frameworks for effective LLM agents.
  • Defines “agents” as systems where LLMs dynamically direct processes and tools, contrasting with predefined “workflows.”
  • Recommends starting with direct API calls, using frameworks cautiously, and focusing on transparency, simplicity, and thorough tool documentation.

US Offers $10 Million Bounty for Iranian CyberAv3ngers Over Critical Infrastructure Attacks

US officials target Iranian group CyberAv3ngers, accused of disrupting critical infrastructure via internet-connected PLC vulnerabilities, with a $10 million reward for identification.

  • US State Department offers a $10 million bounty for information on Iranian hacking group CyberAv3ngers, linked to Iran’s Islamic Revolutionary Guard Corps
  • CyberAv3ngers, active since 2020, targets critical infrastructure in water, food, oil, and gas sectors, exploiting network vulnerabilities and default passwords on internet-connected PLCs
  • Attacks have included defacement messages and compromising industrial control systems, with at least one municipal water authority impacted in Pennsylvania

Amazon CEO Jassy Promises Workforce Cuts Amid AI Efficiency Concerns

Amazon CEO Andy Jassy stated AI will shrink the white-collar workforce citing efficiency, prompting internal criticism over layoffs, AI’s role, and potential impacts on leadership, amid concerns about reliance on AI.

  • Amazon CEO Andy Jassy announced AI will reduce the company’s white-collar workforce over the next few years due to “efficiency gains”
  • Internal Slack channels revealed widespread employee criticism, concerns about layoffs, and debates on AI’s role as partner versus replacement
  • Employees questioned whether layoffs would affect senior leadership, noting the expansion of Amazon’s S-team under Jassy

Amazon CEO Warns AI Could Reduce Jobs but Also Create Opportunities

Amazon CEO Andy Jassy’s memo warns AI may cause job cuts but also generate new roles; former engineer Ishraq sees AI as a productivity tool, not a threat to software engineers.

  • Amazon CEO Andy Jassy sent a memo warning AI could lead to white-collar job cuts but also create new jobs
  • Former Amazon engineer Shahad Ishraq, who left in May due to a 5-day RTO, is not concerned about AI impacting his career
  • Ishraq experimented with AI tools at Amazon, noting they improve productivity but often require human correction; AI hallucinations remain a challenge

US Requires Foreign Students to Unlock Social Media for Visa Screening

US visa rules now require foreign students to unlock social media profiles for US diplomatic review, targeting hostility, terrorism support, and antisemitic activity, with increased vetting since June 2025.

  • US state department mandates foreign students to unlock social media profiles for review before issuing F, M, and J visas.
  • Review aims to detect “indications of hostility” toward US citizens, culture, government, or founding principles.
  • Applicants must set social media privacy settings to “public”; screening includes flags for support of terrorism or antisemitic activity.
  • The policy, announced on June 18, 2025, follows recent pauses in visa issuance and increased scrutiny of Chinese students amid geopolitical tensions.
  • The directive seeks to enhance national security by conducting comprehensive vetting of online activity, aligning with broader US immigration security measures.

Amazon to Cut Jobs as AI Drives Internal Expansion and Efficiency

Amazon plans workforce reductions over the next few years as it expands generative AI use internally and in products like Alexa+, emphasizing skill development to adapt.

  • Amazon CEO Andy Jassy warned staff of upcoming headcount reductions due to increased adoption of generative AI.
  • Amazon is accelerating AI integration internally and in products, with over 1 million users testing Alexa+; safety guardrails are still being developed.
  • Jassy stated that AI-driven efficiency will reduce overall corporate workforce over the next few years, encouraging staff to learn new skills via AWS Skill Builder.

▶️ Technology

MIT Media Lab research indicates ChatGPT usage reduces neural engagement and critical thinking in students, potentially harming brain development; findings emphasize need for cautious AI integration in education.

  • MIT Media Lab study involving 54 participants (ages 18-39) found ChatGPT use correlates with lowest brain engagement during SAT essay tasks
  • ChatGPT users showed decreased neural, linguistic, and behavioral performance, with increased reliance on copy-paste, and reduced memory integration
  • The study suggests LLMs may impair critical thinking and brain development, especially in children, raising concerns over AI’s long-term cognitive effects

AI Coding Tools Disrupt Enterprise Software Development and SaaS Models

AI coding tools such as Bolt are transforming enterprise software by enabling in-house development, threatening SaaS models, and expanding accessible app creation for non-expert developers.

  • AI coding tools like Bolt are disrupting enterprise software development and the traditional buy versus build decision.
  • These tools enable non-traditional developers to create custom applications rapidly, lowering costs and increasing build capacity.
  • Over 10,000 websites are created daily via AI coding tools on Netlify’s platform, with initial impacts in HR, revenue operations, and marketing.

Silicon Valley Divided on AGI Definitions and Future Timelines

Disagreements over AGI definitions and timelines hinder consensus; current models are at early stages, with significant ethical, environmental, and regulatory challenges ahead.

  • Silicon Valley tech leaders remain divided on defining and pursuing artificial general intelligence (AGI) and artificial superintelligence (ASI), with terms used variably.
  • DeepMind’s definition of AGI: AI capable as a skilled adult at most cognitive tasks; current models like ChatGPT are at “emerging AGI” level one.
  • Experts estimate AGI arrival between 2025 and 2026, with predictions ranging from late 2023 to during Trump’s presidency; development heavily influences investment and policy.

AI’s Growing Energy Footprint: Larger Models Emit More CO₂

A 2025 NYT article reports AI models’ energy use and emissions, showing larger, reasoning-focused LLMs emit more CO₂, with regional energy sources affecting actual environmental impact.

  • A 2025 NYT report highlights that AI’s energy consumption increases greenhouse gas emissions, with data centers potentially rising from 4.4% to 12% of U.S. electricity use by 2028
  • A study in Frontiers in Communication analyzed 14 open-source large language models (LLMs), finding larger models emit exponentially more CO₂ and require longer answers, especially in reasoning tasks
  • The most emissions-intensive model, DeepSeek-R1, produced answers with comparable accuracy to smaller models but emitted four times more CO₂; emissions vary by region and energy source

MIT Study Finds AI Chatbots Significantly Reduce Brain Activity and Learning

MIT’s EEG research indicates AI chatbots like ChatGPT decrease brain activity by up to 55%, potentially impairing learning and memory retention, with implications for educational practices and cognitive development.

  • MIT study using EEG found significantly lower brain activity in participants using AI chatbots (ChatGPT) during essay writing, with up to 55% reduction in neural connectivity.
  • Participants relying on LLMs showed 34-48% less brain connectivity and poorer recall and ownership of content compared to those writing unaided.
  • The study suggests external AI support reduces cognitive engagement and may impair learning, advocating delayed AI integration until sufficient self-driven effort.

FAA Grants Varda First Reentry License for Routine Unmanned Spacecraft Missions

FAA granted Varda a reentry license for unmanned spacecraft on June 19, 2025, enabling routine space reentries; Varda’s missions focus on space manufacturing, hypersonic testing, and thermal protection.

  • FAA issued its first reentry license for unmanned spacecraft to Varda on June 19, 2025, under Part Rule 450, enabling routine reentries without individual approvals
  • Varda, founded in 2020 and using Rocket Labs hardware, plans multiple missions including a 300kg Winnebago spacecraft, with upcoming missions featuring its own capsule with NASA-developed heat shield
  • Varda’s missions include testing high-speed reentry (Mach 25), monitoring thermal effects, and measuring navigation accuracy, supporting space-based manufacturing and hypersonic research

Andrej Karpathy on LLMs Transforming Software into a New Computer Paradigm

Andrej Karpathy states that software is evolving with LLMs as a new computer paradigm, programmed in English, resembling utilities and OS, enabling autonomous products and new software architectures.

  • Andrej Karpathy delivered a keynote at AI Startup School, discussing the ongoing fundamental shift in software driven by Large Language Models (LLMs).
  • He describes LLMs as a new kind of computer programmed in English, with properties akin to utilities, fabs, and operating systems, comparable to computing circa 1960s.
  • Key concepts include LLM psychology as “people spirits,” their potential for building partially autonomous products, and their role as primary consumers and manipulators of digital information, enabling vibe coding and building for agents.