AI and IT News Recap: August 3, 2026: OpenAI's Astra Cracks Ten Open Math Problems, a Hacker Puts DeepSeek on Autopilot, and AI Transparency Laws Switch On

By Noah Smith, AI and IT News Recap: August 3, 2026: OpenAI's Astra Cracks Ten Open Math Problems, a Hacker Puts DeepSeek on Autopilot, and AI Transparency Laws Switch On · August 3, 2026

Hand-drawn ink illustration of a long stone corridor lined with ten heavy old wooden doors standing open, warm light spilling out, and a small figure walking down the center holding a lantern.

The AI and IT news that mattered over the weekend, sorted, sanity-checked, and written for busy owners and operators. This was a heavy few days: a research model quietly cracked math problems that had stood for decades, a lone attacker turned a chatbot into an autonomous hacker, and two big AI transparency laws switched on at once.

📌 The AI and IT news at a glance

🔝 OpenAI's Astra solved ten open problems in math and computer science and published machine-checkable proofs anyone can verify, for about ,000 in compute. 🤖 AI transparency laws went live in the EU and California on the same day, giving regulators real enforcement teeth over general-purpose models and synthetic content. 🤖 Google scrapped its standalone AI Studio app the day before launch, despite roughly 800,000 preorders, and is folding it into Gemini. 🛡️ A Chinese-speaking hacker put DeepSeek on autopilot through an open-source agent and hit more than 460 targets, mostly steered by a single Telegram message. 🛡️ Amgen disclosed a "material" data breach after patient health data was stolen from a third-party cloud vendor. 🛡️ Adform's ad script was hijacked to swap crypto wallet addresses across thousands of downstream websites. 🛡️ Adobe patched a perfect-10 Campaign Classic flaw that runs code with no user interaction. 🧰 "Sign in with ChatGPT" started rolling out across Airtable, GitLab, HubSpot, Notion, Supabase, and Vercel.


🔝 Top story: OpenAI's Astra cracked ten problems that stumped mathematicians for decades

On August 1, OpenAI published ten new results in mathematics and theoretical computer science produced by an internal version of Astra, the model it calls its next major release. Each problem had sat open with no progress on the main result for at least a decade, and in several cases far longer. The headline is the first explicit construction of a "non-sofic group," a question in group theory that had stood since 1999. The set also includes the first improvement to the general upper bound on high-dimensional sphere-packing density since 1978, three results from Paul Erdős's famous problem catalogue, and advances in quantum games and post-quantum cryptography.

What makes this different from the usual "AI does math" headline is verifiability. OpenAI released a 249-page manuscript alongside machine-checkable Lean 4 certificates for every result on GitHub, meaning any reader with a laptop can independently confirm the proofs rather than trusting the model's word. Fields medalist Timothy Gowers called it a milestone for machine-assisted mathematics, and Thomas Bloom, who curates the Erdős catalogue, called the constructions a big deal. The total compute cost to find all ten solutions was roughly ,000 at current API rates.

In short: OpenAI says an internal version of its next model, Astra, solved ten long-open math and computer-science problems and published Lean proofs that anyone can verify.

What it means for your business: Most owners will not touch group theory, but the real signal is that frontier models are moving from "sounds plausible" to "here is a proof you can check." As AI starts producing verifiable, checkable output in narrow domains, the trustworthy uses expand well beyond chat, and the gap between labs that can do this and everyone else keeps widening.

My take: The verifiable proofs are the part that matters. We have all learned to discount AI claims because the model is happy to be confidently wrong, so a result you can independently machine-check is a genuinely different thing. This does not mean your accountant is obsolete next quarter. It does mean the frontier is real and moving fast in the places where answers can be checked, and "the AI made it up" stops being a safe assumption in those places.

Source: OpenAI: Ten advances in mathematics and theoretical computer science


🤖 AI

AI transparency laws switched on in the EU and California on the same day

August 2 was a real deadline on two continents. In Europe, the AI Office's supervision and enforcement powers over general-purpose model providers came into force, letting regulators demand technical documentation, evaluate models, order corrective measures, and levy fines of up to €15 million or 3% of global turnover for GPAI breaches, rising to €35 million or 7% for wider violations of the Act. The same date carries the Act's transparency duties: systems that chat with people or generate synthetic media are expected to disclose that they are AI and to label AI-generated content. On the same day in the United States, California's AI Transparency Act (SB 942, as amended by AB 853) became operative, requiring large generative-AI providers with more than a million California users to embed provenance signals in the images, video, and audio they produce, offer a free public detection tool, and let users add a visible AI label. California's timing was not a coincidence; lawmakers deliberately aligned it with the EU date.

In short: On August 2, the EU switched on enforcement powers and transparency duties for general-purpose AI, and California's AI Transparency Act took effect for large providers.

What it means for your business: If you build with or resell generative AI, disclosure and content-provenance are now compliance items, not nice-to-haves, and the reach is extraterritorial: the EU rules can apply to you even from outside Europe, and the California threshold is about users, not headquarters. Ask your AI vendors what provenance signals and disclosures they now support, because their obligations flow down to how you can use them.

My take: Two of the largest markets in the world just made "tell people when they are talking to a machine" the law, within 24 hours of each other, and that coordination is the story. Enforcement will be uneven at first, as it always is, but the direction is set. If your AI use has been quietly undisclosed, treat this as the nudge to get ahead of it rather than the moment to find out how a regulator interprets "synthetic content."

Source: EU Artificial Intelligence Act: Enforcement of Chapter V (GPAI) · Troutman: California AI Transparency Act amendments signed into law

Google scrapped its AI Studio app the day before launch

Google confirmed on July 31 that it is canceling the standalone AI Studio mobile app for Android and iOS, which had been due to launch August 1, and will fold its app-building tools into the Gemini app instead. Roughly 800,000 people across more than 168 countries had preordered on the Play Store and App Store. Google framed the reversal as a delivery-method decision rather than a lack of interest: instead of a separate app, the idea is that app-building capabilities will emerge inside conversations with Gemini. The AI Studio web experience at aistudio.google.com continues unchanged.

In short: Google canceled its unreleased AI Studio mobile app despite about 800,000 preorders and will build those features into the Gemini app.

What it means for your business: If your team was waiting on the AI Studio app to prototype internal tools, the path forward is Gemini rather than a dedicated app. It is also a reminder that preorder counts and roadmaps from big vendors are provisional, so avoid betting a project timeline on an unreleased app.

My take: Canceling a product that 800,000 people already asked for is either impressive discipline or a strategy that changes with the wind, and honestly it is probably a bit of both. The underlying bet, that people would rather describe what they want than open yet another app, is reasonable. Just do not be surprised when "it lives in Gemini now" means the feature you wanted arrives on Google's schedule, not yours.

Source: 9to5Google: Gemini will build apps as AI Studio for Android, iOS is canceled


🛡️ IT and security

A Chinese-speaking hacker put DeepSeek on autopilot and let it attack on its own

Palo Alto Networks' Unit 42 detailed a threat actor, tracked under the aliases "knaithe" and "KnYuan" and based in Zhuhai, China, who wired the DeepSeek model into an open-source agent framework called Hermes and pointed it at the internet. Hermes can drive an operating-system terminal, run commands, and browse, and it was configured to take orders from a Telegram channel, use custom offensive-security tools, and query the FOFA asset-search engine to find exposed systems. Unit 42 recovered a session in which the operator gave a single initial instruction and the agent then enumerated targets, picked public exploits, and carried out the rest of the work without further human input. Across the campaign the actor attempted to exploit more than 460 targets, using seven exploit tracks spanning eight CVEs. Researchers only found it because Hermes accidentally spun up a web server from its home directory, exposing the attacker's API keys, exploit scripts, target lists, shell history, and AI attack logs.

In short: Unit 42 found an attacker who used DeepSeek inside the open-source Hermes agent to autonomously hunt and exploit more than 460 exposed systems, steered mostly by a single Telegram message.

What it means for your business: Autonomous, low-cost attack tooling means the internet gets scanned and probed faster and more cheaply than ever, so anything you leave exposed with a known vulnerability will be found sooner. The defense has not changed, it has just gotten more urgent: shrink your internet-facing footprint, patch known CVEs quickly, and assume opportunistic automation is hitting everything you expose.

My take: The scary detail is not that a model can hack, it is that one person with a Telegram app and an open-source wrapper can run a campaign that used to take a team. This is the commoditization of offensive capability, and it rewards the boring hygiene we always preach: know what you expose, patch it fast, and do not count on being too small to notice. Automated attackers do not skip the small targets, they just add them to the list.

Source: BleepingComputer: Hacker uses DeepSeek AI to autonomously attack vulnerable servers

Amgen disclosed a "material" breach of patient data through a cloud vendor

Pharmaceutical giant Amgen said it detected unauthorized activity in July and later learned that attackers exfiltrated data, including proprietary information and patient protected health information, from cloud environments run by third-party service providers. The company activated its incident-response plan, brought in outside forensics, and is still determining the full scope, which may include additional business, research, and patient data. Amgen deemed the event material given the volume of files affected and the sensitivity of the information, while saying it does not currently expect a material hit to its financial results. Impacted patients will be notified where required.

In short: Amgen disclosed a data breach in which patient health data and proprietary information were stolen from third-party cloud systems, and called the incident material.

What it means for your business: Your data is only as safe as the vendors you hand it to, and "it was our provider's cloud, not ours" is not a defense your customers or a regulator will accept. Map which third parties hold your sensitive data, confirm what they are contractually obligated to do when they are breached, and make sure their incident-response commitments actually match your risk.

My take: Nearly every big breach this year traces back to a supplier rather than the headline company's own systems, and Amgen is one more example. The uncomfortable lesson is that outsourcing the work does not outsource the accountability. If you cannot name the vendors holding your customer data and say how you would find out they were hit, that is the gap to close before you are the one writing the disclosure.

Source: BleepingComputer: Amgen says cloud data breach exposed patient health, proprietary info

Adform's ad script was hijacked to quietly swap crypto wallet addresses

Advertising-technology firm Adform, which serves roughly 14,000 businesses and holds close to a third of the demand-side platform market, suffered a supply-chain compromise in which attackers altered one of its widely deployed JavaScript files. The tampered script watched for cryptocurrency wallet addresses copied to the clipboard or typed into forms on downstream sites and silently replaced them with attacker-controlled addresses for Bitcoin, Ethereum, and Tron, so a victim's transfer would go to the wrong destination. Because the code rode on a trusted ad-tech file, it reached visitors across thousands of unrelated websites. Adform says it detected and removed the malicious code on July 27, and the compromise was publicly uncovered and reported at the start of August by researcher Kevin Beaumont.

In short: Attackers poisoned a widely used Adform ad script to swap crypto wallet addresses across thousands of downstream sites before it was detected and removed.

What it means for your business: Every third-party script on your website is code you are trusting to run in your visitors' browsers, and ad-tech and analytics tags are a favorite supply-chain target. Inventory the external scripts on your site, drop the ones you do not need, and consider controls like subresource integrity or a strict content-security-policy so a compromised vendor file cannot silently do whatever it wants to your users.

My take: This is a clean, nasty example of why "it is just an ad tag" is a dangerous phrase. One vendor file was enough to turn thousands of legitimate sites into a crypto-stealing operation, and none of those site owners did anything wrong except trust a normal dependency. You cannot audit every script forever, but you can shrink the list and box in what the survivors are allowed to do.

Source: BleepingComputer: Online ad firm Adform's script compromised to steal cryptocurrency

Adobe patched a perfect-10 Campaign Classic flaw that needs no user interaction

Adobe issued a fix for CVE-2026-48449, a maximum-severity flaw (CVSS 10.0) in Campaign Classic v7 that stems from an authorization mistake and can let an attacker run arbitrary code with no user interaction required. The bulletin (APSB26-114) also resolves a second, high-severity SQL-injection bug (CVE-2026-48448, CVSS 8.6) that could enable arbitrary file reads. Adobe says it is not aware of either flaw being exploited in the wild, and the fixes ship in Campaign Classic v7 build 9398 for Windows and Linux. The perfect-10 rating drew wide attention over the weekend for on-premise administrators still running older builds.

In short: Adobe fixed a CVSS 10.0 Campaign Classic flaw that allows code execution with no user interaction, along with a high-severity SQL-injection bug, in build 9398.

What it means for your business: If your marketing team runs Adobe Campaign Classic on-premise, this is a patch-now item; a perfect-10, no-interaction remote code execution bug is exactly the kind attackers race to weaponize once a fix reveals the flaw. Confirm with whoever manages that system that you are on build 9398 or later.

My take: A CVSS 10.0 with no user interaction is about as bad as a rating gets, and the fact that it is not yet exploited is a countdown, not an all-clear. Patches like this quietly hand attackers a map to the vulnerability, so the window between "fix released" and "exploit circulating" is short. On-prem marketing software tends to be under-patched precisely because nobody thinks of it as security-critical, which is exactly why it gets hit.

Source: The Hacker News: Adobe Campaign Classic CVSS 10.0 flaw could run code without user interaction


🧰 New tooling for builders and business AI

"Sign in with ChatGPT" started rolling out across major work apps

OpenAI began a beta rollout of "Sign in with ChatGPT," a single-sign-on option that lets people create or link an account using their ChatGPT identity, launching first with Airtable, GitLab, HubSpot, Notion, Supabase, and Vercel. On participating sites you can choose "Sign in with ChatGPT" to set up or reach your account in fewer steps, and connecting a supported app from inside ChatGPT or Codex works the same way. Partners receive only your name, email address, and profile picture where available.

In short: OpenAI is rolling out "Sign in with ChatGPT" in beta, an SSO option starting with Airtable, GitLab, HubSpot, Notion, Supabase, and Vercel.

What it means for your business: Another single-sign-on provider is convenient, but it also means ChatGPT accounts become keys to more of your stack, so the security of that login now matters more. If your team starts using this, make sure ChatGPT accounts have strong, phishing-resistant multi-factor authentication, because an SSO button is only as safe as the account behind it.

My take: "Sign in with ChatGPT" is a quiet land-grab for identity, following the same playbook Google and Apple used, and convenience usually wins these battles. It is genuinely handy for builders wiring tools together. Just remember that every "Sign in with" button you adopt concentrates risk into one account, so treat your ChatGPT login with the same care you would your email, not as a throwaway.

Source: Vercel: Sign in with ChatGPT is now available on Vercel


That is the AI and IT news for August 3, 2026, covering the August 1 to 2 weekend. For Friday's edition, see the July 31 recap.