Tech Brew Ride Home - Mon. 07/21 – Massive SharePoint Zero-Day
Episode Date: July 21, 2025Serious zero-day has been uncovered that is affecting everybody all around the world. There is a patch tho. Mark Gurman dishes on the foldable iPhone. TSMC joins the Trillion-Dollar-Club. If you’re ...an expert in a given field you too can join the AI goldrush. And did we just take a big step toward AGI, or is this just the latest in the hype-cycle? Sponsors: AGNTCY.ORG Links: Hackers Exploit Microsoft SharePoint as Firm Works to Patch (Bloomberg) The First Foldable iPhone Will Arrive Next Year in Un-Apple-Like Fashion (Bloomberg) Nvidia's CUDA platform now supports RISC-V — support brings open source instruction set to AI platforms, joining x86 and Arm (Tom's Hardware) TSMC’s Taiwan Stock Value Surpasses $1 Trillion Amid AI Frenzy (Bloomberg) AI groups spend to replace low-cost ‘data labellers’ with high-paid experts (FT) OpenAI's experimental model achieved gold at the International Math Olympiad (Engadget) OpenAI's gold medal performance on the International Math Olympiad. (Simon Willison's Weblog) Learn more about your ad choices. Visit megaphone.fm/adchoices
Transcript
Discussion (0)
On April 4th, 2023, around 2 in the morning, a man was found stabbed multiple times on a sidewalk in downtown San Francisco.
Hey, who did this to you?
What happened next turned the story into a political firestorm.
Reports have identified the victim as Bob Lee, the founder of Cash App.
From Bloomberg Podcasts, this is Foundering, the Killing of Bob Lee, beginning April 16.
Welcome to the Tech meme right home for Monday, July 21st, 2021, 2025. I'm Brian McCullough today.
Serious Zero Day has been uncovered that is affecting everybody all around the world. There is a patch, though.
Mark German dishes on the foldable iPhone. TSM joins the trillion dollar club. If you're an expert in a given field, you too can join the AI Gold Rush.
And did we just take a big step toward AGI or is this just the latest in the hype cycle?
Here's what you miss today in the world of tech. Hey, admins and security folks, you've had some work
to do today. That would be installing a patch from Microsoft after a huge SharePoint Zero Day
RCE flaw that was actively being exploited globally on thousands of on-prem servers was revealed.
Quoting Bloomberg, vulnerabilities in the software have allowed hackers to access file systems
and execute code, the U.S. cybersecurity and infrastructure security agency, warned on Sunday.
While Microsoft said over the weekend that it had released a new patch for customers to apply to
their SharePoint servers to, quote, mitigate active attacks targeting on-premises servers,
the company was still working to roll out others to address ongoing security flaws.
Cybersecurity teams cautioned that a broad section of organizations may be affected by the breach.
Tens of thousands, if not hundreds of thousands of businesses and institutions worldwide,
use SharePoint in some fashion to store and collaborate on documents.
Microsoft said hackers are specifically targeting clients running SharePoint servers
from their own on-premise networks as opposed to being hosted and managed by the tech firm
that could limit the impact to a subsection of customers.
Silas Cutler, a researcher at Michigan-based cybersecurity firm, census,
estimated that more than 10,000 companies with SharePoint servers were at risk.
The U.S. had the largest number of those companies, followed by the Netherlands, the UK, and Canada,
he said.
It's a dream for ransomware operators and a lot of attackers are going to be working this weekend as well,
he said. Microsoft has been trying to shore up its cybersecurity after a series of high-profile
failures hiring new executives from places like the U.S. government and holding weekly meetings with
senior executives to make its software more resilient. The company's tech has been subject to
several widespread and damaging hacks in recent years, and a 2024 U.S. government report
described the company's security culture as in need of urgent reforms. Palo Alto networks
warn that the SharePoint exploits are real in the wild and pose a serious threat. Google threatened
intelligence group said in an email statement it had observed hackers exploiting the vulnerability,
adding it allows persistent, unauthenticated access, and presents a significant risk to affected
organizations. When they're able to compromise the fortress that is SharePoint, everybody is
kind of at their whim because that is one of the highest security protocols out there, said Gene U.
U.S. CEO of Singapore-based cyber incident response firm Black Panda. The Washington Post reported that
the breach had affected U.S. federal and state agencies, universities, energy companies, and an Asian
telecommunications company, citing state officials and private researchers.
Researchers said the vulnerability allows hackers to access SharePoint servers and steal keys
that can let them impersonate users or services even after the server is patched.
It said hackers can maintain access through backdoors or modified components that can
survive updates and reboots of the system, end quote.
Mark German Apple Scoop Monday.
Yes, Mark says a foldable iPhone is coming next year.
Here are the deets.
quote, when the company introduces its first foldable iPhone at the end of next year,
it will be entering a product category that is already seven years old,
pioneered and dominated by its biggest hardware rival, Samsung Electronics,
and this time Apple won't be debuting a radically new interface or transformative hardware.
Instead, the device will offer a similar design as Samsung's Galaxy Z-Fold line
and use many of the same core components, including foldable OLED screens sourced from Samsung display.
Samsung, meanwhile, continues to plow ahead.
Just last week, we reviewed Samsung's latest Z-Fold 7 and called it the first foldable phone with a true mainstream potential.
That device is a remarkable feat of engineering with a wider front screen and a refined design that you'll have to experience firsthand to truly appreciate.
Already, sales are outpacing the prior generation to a significant degree, I'm told.
That means Apple's first foldable won't break any technological barriers or redefine the category.
Samsung has already taken care of much of the heavy list.
But here's the twist. That may not matter. Apple's unmatched ability to market premium hardware to consumers,
Vision Pro aside, could make it the dominant player in the foldables market within months of launch.
There's a sizable group of iPhone loyalists, myself included, who have long wanted a foldable device
but weren't willing to switch to Android to get it. That pent-up demand is real, and Apple knows it.
In a way, Samsung has spent the past seven years setting up Apple for success. The format is finally ready for prime time,
just as the iPhone enters the market.
But this isn't necessarily bad news for Samsung.
Its component divisions will benefit from an iPhone sales surge,
and the excitement may get more Android users to try a foldable galaxy.
In fairness to Apple, its foldable phone won't be a carbon copy.
As I reported months ago, the company is focused on addressing a few of the foldable category's longstanding weaknesses.
The company aims to make the inner display crease less visible
and dramatically improve the hinge mechanism.
And as part of the development of iOS 27, which formally kicks off soon, Apple will prioritize software features tailored specifically to this new form factor.
Another reason why Apple is embracing foldables now, the format has become especially popular in China, a market where the company is eager for a turnaround.
Local brands like Xiaomi, Honor, Huawei, and Vivo have all launched foldables and consumers in the region have shown a particular preference for the book style form factor, the one Apple is pursuing over the emerging flip phone style design.
The new foldable iPhone is also expected to cost at least $2,000 giving Apple a relatively easy lever to boost iPhone revenue, even if unit sales aren't high.
Ultimately, Apple's foldable won't revolutionize the category, at least not on day one, but it will still be a big moment for the industry.
With its brand power, marketing muscle, and engineering refinements, Apple could once again turn a niche product into a global hit.
It just won't be the innovation breakthrough that we're used to, end quote.
At the 2025 Risk Five summit in China, Nvidia said Kuda will now be compatible with Risk Five's instruction set architecture,
making Risk Five a viable X86 an arm rival, quoting Tom's hardware.
The announcement makes it clear that Risk 5 can now serve as the main processor for Kuda-based
systems, a role traditionally filled by X86 or ArmCores.
While nobody even barely expects Risk 5 in hyperscale data centers anytime soon,
risk 5 can be used on Kuta-enabled edge devices such as Nvidia's Jetson modules.
However, it looks like Nvidia does indeed expect Risk 5 to be in the data center someday.
A diagram shown at the session illustrated a typical configuration,
GPU handles parallel workloads while a Risk 5 CPU executes Kuta system drivers, application logic, and the operating system.
This setup enables the CPU to orchestrate GPU computations fully within the Kuta environment.
Given Nvidia's current focus, the workloads must be AI-related, yet the company did not confirm this.
However, there is more. Also featured in the diagram was a DPU handling networking task,
rounding out a system consisting of a GPU for compute, CPU for orchestration, and data movement.
This configuration clearly suggests NVIDIA's vision to build heterogeneous compute platforms where
RISC-5 CPUs can be central to managing workloads, while NVIDIA's GPUs, DPUs, and networking
chips handle the rest.
Whether or not this signals NVIDIA's readiness to diversify its ecosystem beyond proprietary
host platforms is something that is not exactly clear.
Nonetheless, if the stars aligned, NVIDIA has just positioned RISC-5 as a viable alternative
in future AI and HPC processor designs across data centers, this is something that no one
expected, but it may influence other companies to follow suit, end quote. Further proof, the AI
buildout is continuing, or at least proof Wall Street believes it is continuing. On Friday,
TSMC closed above a $1 trillion market cap in Taiwan, a first for them. It also makes
TSMC the first Asian stock worth more than $1 trillion since PetroChina back in 2007.
The stock of TSMC is up nearly 50% just from an April low. Quoting Bloomberg,
TSM's stock surge reflected growing investor confidence that the world's top chipmaker will
ride the AI boom to even greater dominance. The company raised its full year revenue growth forecast
to about 30 percent last week, signaling TSM may benefit in a tightening race for AI manufacturing
capacity. We think that TSM's tone towards advanced node demand is even more positive with
AI customers showing no signs of demand slowdown, wrote Goldman Sachs group analysts including Bruce
lieu after TSM's quarterly earnings. We expect to see a higher magnitude of price hike in
2006. TSM's American depository receipts were valued at around $1.2 trillion as of the close on
Friday. Owning ADR shares have been more convenient for foreign investors as converting the
Taipei listed stock into the U.S. equivalent needs regulatory approval.
Strong AI spending by TSM's customers and the upside of wafer prices will help mitigate
the negative impact of a strong Taiwan dollar and help add resilience to the company's gross margins.
J.P. Morgan Chase and company analysts, including Gokul Harahan, wrote in a note late last week, end quote.
This is interesting. The F.T. says that companies like Scale AI are replacing low-cost data
labelers with highly paid experts in fields such as finance, driven by the rise of reasoning AI
models. Quote, companies such as Scale AI, Turing, and
Toloka are hiring experts in fields such as biology and finance to help AI groups create more
sophisticated training data that is crucial for developing the next generation of AI systems.
The rise of so-called reasoning models such as OpenAI's 03 and Google's Gemini 2.5
has accelerated the move away from employing thousands of low-cost workers in countries such as
Kenya and the Philippines, who are typically paid less than $2 an hour to undertake the time-consuming
task of annotating the huge datasets used to train AI models. The AI industry was
for a long time, heavily focused on the models and compute, and data has always been an
overseen part of AI, said Olga Megakorsky, the chief executive and co-founder of Dutch group
Toloka. Finally, the industry is accepting the importance of the data for training. This shift
has led to a surge in investor interest in data labeling startups. In June, meta-invested $15 billion
in the U.S. Group, scale AI, doubling its valuation to $29 billion as part of a push to catch up
with rivals. In March, California-based Turing AI raised $11 million at a $2.2 billion valuation,
while Jeff Bezos' personal firm Bezos Expeditions led a $72 million investment round for Toluca in May.
Previously, data labelers would handle simple tasks such as drawing boxes on images to identify
objects, describing what images represent, selecting fluent ways to express things and weeding out
bad answers from datasets that often contain violent or graphic content.
Because AI models need more data to perform better, these workers were expected to process tasks in seconds and complete hundreds of tasks during a working day to create vast data sets.
Now the demand for these tasks has dropped significantly, as many of them could be automated, said Megakorska.
As leading AI groups such as OpenAI Anthropic and Google attempt to develop models that they claim will exceed human intelligence, there is a push to focus on the quality of data sets and hiring experts to examine complex problems.
What these models now need is data of a real human using the models to do knowledge work and getting feedback on when the model is failing, said Jonathan Siddharth, co-founder and chief executive of Turing AI, to ensure that models perform well in a wide variety of fields from coding to physics and finance, depocketed AI companies are now willing to pay for more sophisticated data sets and experts from around the world.
To attract people from different industries, Turing paid experts 20 to 30 percent more than they received in their current jobs.
said Sid-Earth. While budgets for data are only about 10 to 15% of the hundreds of billions of
dollars AI companies spend on computing power, it remained an enormous amount of money, he added,
end quote. Finally today, your mileage may vary on this item that got a lot of attention over the
weekend. If you're AI skeptical, you'll think what I'm about to tell you about is just another
peg in the hype cycle. But if you're an AI maximalist, you might think we'll look back in history
as this being an important rung on the latter to AGI.
An Open AI researcher said over the weekend that the company's latest experimental reasoning
LLM achieved gold medal level performance on the 2025 International Math Olympiad.
Quoting in Gadget, Alexander Wee, a research scientist at OpenAI working on LLMs and reasoning,
posted on X that an experimental research model delivered on this longstanding grand challenge in AI.
According to We, an unreleased model from OpenAI was able to be able to,
to solve five out of six problems at one of the world's longest standing and prestigious math
competitions earning 35 out of 42 points total. The International Math Olympiad, or IMO, sees
countries send up to six students to solve extremely difficult algebra and pre-calculus problems.
These exercises are seemingly simple, but usually require some creativity to score the highest
marks on each problem. For this year's competition, only 67 of the 630 total contestants
received gold medals are roughly 10%. AI is often tasked with
tackling complex data sets and repetitive actions, but it usually falls short when it comes to
solving problems that require more creativity or complex decision-making. However, with the latest
IMO competition, OpenAI says its model was able to handle complicated math problems with human-like
reasoning. By doing so, we've obtained a model that can craft intricate watertight arguments
at the level of human mathematicians. Y wrote on X. Y and Sam Aldman, CEO of OpenAI, both
added that the company doesn't expect to release anything with this level of math capability for
several months. That means the upcoming GPT-5 will likely be an improvement from its predecessor,
but it won't feature that same impressive capability to compete in the IMO, end quote.
Let me underline all of that again, quoting our friend Simon Willison.
The most notable thing about this is that the unnamed model achieved this score without using any
tools. Open A. I's Sebastian Bubeck emphasizes that here, quote, just to spell it out as clearly
as possible, a next word prediction machine, because that's really what it is here, no tools, no
nothing, just produced genuinely creative proofs for hard novel math problems at a level reached
only by an elite handful of pre-college prodigies. There's a bunch more useful context in this
thread by Noam Brown, including a note that this model wasn't trained specifically for IMO problems.
quote. Typically for these AI results, like in Go, Dota, poker, diplomacy, researchers spend
years making an AI that masters one narrow domain and does little else. But this isn't an IMO-specific
model. It's a reasoning LLM that incorporates new experimental general purpose techniques.
So what's different? We develop new techniques that make LLMs a lot better at hard-to-verify
tasks. IMO problems were the perfect challenge for this. Proofs are pages long and take experts
hours to grade. Also, this model thinks for a long time. Oh, one thought for seconds, deep research for
minutes. This one thinks for hours. Importantly, it's also more efficient with its thinking,
and there's a lot of room to push the test, time, compute, and efficiency further.
It's worth reflecting on just how fast AI progress has been, especially in math. In 2024, AI
labs were using grade school math as an eval in their model releases. Since then, we've saturated
the high school math benchmark, then AIME, and now are at IMO Gold.
When you work at a frontier lab, you usually know where frontier capabilities are months
before anyone else, but this result is brand new using recently deployed techniques.
It was a surprise even to many researchers at OpenAI.
Today, everyone gets to see where the frontier is, end quote.
Since I mentioned skeptics have been throwing cold water on this, let me end by quoting
from one of them for balance. This is Corncaramol Boldie on X. Quote,
the model isn't public. The evaluations aren't public. Yet you have a bunch of open AI employees
claiming their experimental reasoning LLM got gold level performance on the IMO. What is this?
Not science for sure, not even science by demo. Science by PR, question mark, end quote.
Only two days in, but so far my take on the city of Pittsburgh is five,
would recommend with all the hills and cliffs, but then the various neighborhood flavors,
it feels like Chicago and Cincinnati had a baby. And I mean that in the highest compliment possible,
given my affinity for both of those cities. Talk to you tomorrow.
