Tech Brew Ride Home - Mon. 07/21 – Massive SharePoint Zero-Day

Episode Date: July 21, 2025

Serious zero-day has been uncovered that is affecting everybody all around the world. There is a patch tho. Mark Gurman dishes on the foldable iPhone. TSMC joins the Trillion-Dollar-Club. If you’re ...an expert in a given field you too can join the AI goldrush. And did we just take a big step toward AGI, or is this just the latest in the hype-cycle? Sponsors: AGNTCY.ORG Links: Hackers Exploit Microsoft SharePoint as Firm Works to Patch (Bloomberg) The First Foldable iPhone Will Arrive Next Year in Un-Apple-Like Fashion (Bloomberg) Nvidia's CUDA platform now supports RISC-V — support brings open source instruction set to AI platforms, joining x86 and Arm (Tom's Hardware) TSMC’s Taiwan Stock Value Surpasses $1 Trillion Amid AI Frenzy (Bloomberg) AI groups spend to replace low-cost ‘data labellers’ with high-paid experts (FT) OpenAI's experimental model achieved gold at the International Math Olympiad (Engadget) OpenAI's gold medal performance on the International Math Olympiad. (Simon Willison's Weblog) Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript
Discussion (0)
Starting point is 00:00:00 On April 4th, 2023, around 2 in the morning, a man was found stabbed multiple times on a sidewalk in downtown San Francisco. Hey, who did this to you? What happened next turned the story into a political firestorm. Reports have identified the victim as Bob Lee, the founder of Cash App. From Bloomberg Podcasts, this is Foundering, the Killing of Bob Lee, beginning April 16. Welcome to the Tech meme right home for Monday, July 21st, 2021, 2025. I'm Brian McCullough today. Serious Zero Day has been uncovered that is affecting everybody all around the world. There is a patch, though. Mark German dishes on the foldable iPhone. TSM joins the trillion dollar club. If you're an expert in a given field, you too can join the AI Gold Rush.
Starting point is 00:00:53 And did we just take a big step toward AGI or is this just the latest in the hype cycle? Here's what you miss today in the world of tech. Hey, admins and security folks, you've had some work to do today. That would be installing a patch from Microsoft after a huge SharePoint Zero Day RCE flaw that was actively being exploited globally on thousands of on-prem servers was revealed. Quoting Bloomberg, vulnerabilities in the software have allowed hackers to access file systems and execute code, the U.S. cybersecurity and infrastructure security agency, warned on Sunday. While Microsoft said over the weekend that it had released a new patch for customers to apply to their SharePoint servers to, quote, mitigate active attacks targeting on-premises servers,
Starting point is 00:01:41 the company was still working to roll out others to address ongoing security flaws. Cybersecurity teams cautioned that a broad section of organizations may be affected by the breach. Tens of thousands, if not hundreds of thousands of businesses and institutions worldwide, use SharePoint in some fashion to store and collaborate on documents. Microsoft said hackers are specifically targeting clients running SharePoint servers from their own on-premise networks as opposed to being hosted and managed by the tech firm that could limit the impact to a subsection of customers. Silas Cutler, a researcher at Michigan-based cybersecurity firm, census,
Starting point is 00:02:19 estimated that more than 10,000 companies with SharePoint servers were at risk. The U.S. had the largest number of those companies, followed by the Netherlands, the UK, and Canada, he said. It's a dream for ransomware operators and a lot of attackers are going to be working this weekend as well, he said. Microsoft has been trying to shore up its cybersecurity after a series of high-profile failures hiring new executives from places like the U.S. government and holding weekly meetings with senior executives to make its software more resilient. The company's tech has been subject to several widespread and damaging hacks in recent years, and a 2024 U.S. government report
Starting point is 00:02:51 described the company's security culture as in need of urgent reforms. Palo Alto networks warn that the SharePoint exploits are real in the wild and pose a serious threat. Google threatened intelligence group said in an email statement it had observed hackers exploiting the vulnerability, adding it allows persistent, unauthenticated access, and presents a significant risk to affected organizations. When they're able to compromise the fortress that is SharePoint, everybody is kind of at their whim because that is one of the highest security protocols out there, said Gene U. U.S. CEO of Singapore-based cyber incident response firm Black Panda. The Washington Post reported that the breach had affected U.S. federal and state agencies, universities, energy companies, and an Asian
Starting point is 00:03:32 telecommunications company, citing state officials and private researchers. Researchers said the vulnerability allows hackers to access SharePoint servers and steal keys that can let them impersonate users or services even after the server is patched. It said hackers can maintain access through backdoors or modified components that can survive updates and reboots of the system, end quote. Mark German Apple Scoop Monday. Yes, Mark says a foldable iPhone is coming next year. Here are the deets.
Starting point is 00:04:08 quote, when the company introduces its first foldable iPhone at the end of next year, it will be entering a product category that is already seven years old, pioneered and dominated by its biggest hardware rival, Samsung Electronics, and this time Apple won't be debuting a radically new interface or transformative hardware. Instead, the device will offer a similar design as Samsung's Galaxy Z-Fold line and use many of the same core components, including foldable OLED screens sourced from Samsung display. Samsung, meanwhile, continues to plow ahead. Just last week, we reviewed Samsung's latest Z-Fold 7 and called it the first foldable phone with a true mainstream potential.
Starting point is 00:04:45 That device is a remarkable feat of engineering with a wider front screen and a refined design that you'll have to experience firsthand to truly appreciate. Already, sales are outpacing the prior generation to a significant degree, I'm told. That means Apple's first foldable won't break any technological barriers or redefine the category. Samsung has already taken care of much of the heavy list. But here's the twist. That may not matter. Apple's unmatched ability to market premium hardware to consumers, Vision Pro aside, could make it the dominant player in the foldables market within months of launch. There's a sizable group of iPhone loyalists, myself included, who have long wanted a foldable device but weren't willing to switch to Android to get it. That pent-up demand is real, and Apple knows it.
Starting point is 00:05:29 In a way, Samsung has spent the past seven years setting up Apple for success. The format is finally ready for prime time, just as the iPhone enters the market. But this isn't necessarily bad news for Samsung. Its component divisions will benefit from an iPhone sales surge, and the excitement may get more Android users to try a foldable galaxy. In fairness to Apple, its foldable phone won't be a carbon copy. As I reported months ago, the company is focused on addressing a few of the foldable category's longstanding weaknesses. The company aims to make the inner display crease less visible
Starting point is 00:06:03 and dramatically improve the hinge mechanism. And as part of the development of iOS 27, which formally kicks off soon, Apple will prioritize software features tailored specifically to this new form factor. Another reason why Apple is embracing foldables now, the format has become especially popular in China, a market where the company is eager for a turnaround. Local brands like Xiaomi, Honor, Huawei, and Vivo have all launched foldables and consumers in the region have shown a particular preference for the book style form factor, the one Apple is pursuing over the emerging flip phone style design. The new foldable iPhone is also expected to cost at least $2,000 giving Apple a relatively easy lever to boost iPhone revenue, even if unit sales aren't high. Ultimately, Apple's foldable won't revolutionize the category, at least not on day one, but it will still be a big moment for the industry. With its brand power, marketing muscle, and engineering refinements, Apple could once again turn a niche product into a global hit. It just won't be the innovation breakthrough that we're used to, end quote.
Starting point is 00:07:11 At the 2025 Risk Five summit in China, Nvidia said Kuda will now be compatible with Risk Five's instruction set architecture, making Risk Five a viable X86 an arm rival, quoting Tom's hardware. The announcement makes it clear that Risk 5 can now serve as the main processor for Kuda-based systems, a role traditionally filled by X86 or ArmCores. While nobody even barely expects Risk 5 in hyperscale data centers anytime soon, risk 5 can be used on Kuta-enabled edge devices such as Nvidia's Jetson modules. However, it looks like Nvidia does indeed expect Risk 5 to be in the data center someday. A diagram shown at the session illustrated a typical configuration,
Starting point is 00:07:56 GPU handles parallel workloads while a Risk 5 CPU executes Kuta system drivers, application logic, and the operating system. This setup enables the CPU to orchestrate GPU computations fully within the Kuta environment. Given Nvidia's current focus, the workloads must be AI-related, yet the company did not confirm this. However, there is more. Also featured in the diagram was a DPU handling networking task, rounding out a system consisting of a GPU for compute, CPU for orchestration, and data movement. This configuration clearly suggests NVIDIA's vision to build heterogeneous compute platforms where RISC-5 CPUs can be central to managing workloads, while NVIDIA's GPUs, DPUs, and networking chips handle the rest.
Starting point is 00:08:38 Whether or not this signals NVIDIA's readiness to diversify its ecosystem beyond proprietary host platforms is something that is not exactly clear. Nonetheless, if the stars aligned, NVIDIA has just positioned RISC-5 as a viable alternative in future AI and HPC processor designs across data centers, this is something that no one expected, but it may influence other companies to follow suit, end quote. Further proof, the AI buildout is continuing, or at least proof Wall Street believes it is continuing. On Friday, TSMC closed above a $1 trillion market cap in Taiwan, a first for them. It also makes TSMC the first Asian stock worth more than $1 trillion since PetroChina back in 2007.
Starting point is 00:09:23 The stock of TSMC is up nearly 50% just from an April low. Quoting Bloomberg, TSM's stock surge reflected growing investor confidence that the world's top chipmaker will ride the AI boom to even greater dominance. The company raised its full year revenue growth forecast to about 30 percent last week, signaling TSM may benefit in a tightening race for AI manufacturing capacity. We think that TSM's tone towards advanced node demand is even more positive with AI customers showing no signs of demand slowdown, wrote Goldman Sachs group analysts including Bruce lieu after TSM's quarterly earnings. We expect to see a higher magnitude of price hike in 2006. TSM's American depository receipts were valued at around $1.2 trillion as of the close on
Starting point is 00:10:09 Friday. Owning ADR shares have been more convenient for foreign investors as converting the Taipei listed stock into the U.S. equivalent needs regulatory approval. Strong AI spending by TSM's customers and the upside of wafer prices will help mitigate the negative impact of a strong Taiwan dollar and help add resilience to the company's gross margins. J.P. Morgan Chase and company analysts, including Gokul Harahan, wrote in a note late last week, end quote. This is interesting. The F.T. says that companies like Scale AI are replacing low-cost data labelers with highly paid experts in fields such as finance, driven by the rise of reasoning AI models. Quote, companies such as Scale AI, Turing, and
Starting point is 00:11:02 Toloka are hiring experts in fields such as biology and finance to help AI groups create more sophisticated training data that is crucial for developing the next generation of AI systems. The rise of so-called reasoning models such as OpenAI's 03 and Google's Gemini 2.5 has accelerated the move away from employing thousands of low-cost workers in countries such as Kenya and the Philippines, who are typically paid less than $2 an hour to undertake the time-consuming task of annotating the huge datasets used to train AI models. The AI industry was for a long time, heavily focused on the models and compute, and data has always been an overseen part of AI, said Olga Megakorsky, the chief executive and co-founder of Dutch group
Starting point is 00:11:43 Toloka. Finally, the industry is accepting the importance of the data for training. This shift has led to a surge in investor interest in data labeling startups. In June, meta-invested $15 billion in the U.S. Group, scale AI, doubling its valuation to $29 billion as part of a push to catch up with rivals. In March, California-based Turing AI raised $11 million at a $2.2 billion valuation, while Jeff Bezos' personal firm Bezos Expeditions led a $72 million investment round for Toluca in May. Previously, data labelers would handle simple tasks such as drawing boxes on images to identify objects, describing what images represent, selecting fluent ways to express things and weeding out bad answers from datasets that often contain violent or graphic content.
Starting point is 00:12:29 Because AI models need more data to perform better, these workers were expected to process tasks in seconds and complete hundreds of tasks during a working day to create vast data sets. Now the demand for these tasks has dropped significantly, as many of them could be automated, said Megakorska. As leading AI groups such as OpenAI Anthropic and Google attempt to develop models that they claim will exceed human intelligence, there is a push to focus on the quality of data sets and hiring experts to examine complex problems. What these models now need is data of a real human using the models to do knowledge work and getting feedback on when the model is failing, said Jonathan Siddharth, co-founder and chief executive of Turing AI, to ensure that models perform well in a wide variety of fields from coding to physics and finance, depocketed AI companies are now willing to pay for more sophisticated data sets and experts from around the world. To attract people from different industries, Turing paid experts 20 to 30 percent more than they received in their current jobs. said Sid-Earth. While budgets for data are only about 10 to 15% of the hundreds of billions of dollars AI companies spend on computing power, it remained an enormous amount of money, he added, end quote. Finally today, your mileage may vary on this item that got a lot of attention over the
Starting point is 00:13:52 weekend. If you're AI skeptical, you'll think what I'm about to tell you about is just another peg in the hype cycle. But if you're an AI maximalist, you might think we'll look back in history as this being an important rung on the latter to AGI. An Open AI researcher said over the weekend that the company's latest experimental reasoning LLM achieved gold medal level performance on the 2025 International Math Olympiad. Quoting in Gadget, Alexander Wee, a research scientist at OpenAI working on LLMs and reasoning, posted on X that an experimental research model delivered on this longstanding grand challenge in AI. According to We, an unreleased model from OpenAI was able to be able to,
Starting point is 00:14:32 to solve five out of six problems at one of the world's longest standing and prestigious math competitions earning 35 out of 42 points total. The International Math Olympiad, or IMO, sees countries send up to six students to solve extremely difficult algebra and pre-calculus problems. These exercises are seemingly simple, but usually require some creativity to score the highest marks on each problem. For this year's competition, only 67 of the 630 total contestants received gold medals are roughly 10%. AI is often tasked with tackling complex data sets and repetitive actions, but it usually falls short when it comes to solving problems that require more creativity or complex decision-making. However, with the latest
Starting point is 00:15:11 IMO competition, OpenAI says its model was able to handle complicated math problems with human-like reasoning. By doing so, we've obtained a model that can craft intricate watertight arguments at the level of human mathematicians. Y wrote on X. Y and Sam Aldman, CEO of OpenAI, both added that the company doesn't expect to release anything with this level of math capability for several months. That means the upcoming GPT-5 will likely be an improvement from its predecessor, but it won't feature that same impressive capability to compete in the IMO, end quote. Let me underline all of that again, quoting our friend Simon Willison. The most notable thing about this is that the unnamed model achieved this score without using any
Starting point is 00:15:54 tools. Open A. I's Sebastian Bubeck emphasizes that here, quote, just to spell it out as clearly as possible, a next word prediction machine, because that's really what it is here, no tools, no nothing, just produced genuinely creative proofs for hard novel math problems at a level reached only by an elite handful of pre-college prodigies. There's a bunch more useful context in this thread by Noam Brown, including a note that this model wasn't trained specifically for IMO problems. quote. Typically for these AI results, like in Go, Dota, poker, diplomacy, researchers spend years making an AI that masters one narrow domain and does little else. But this isn't an IMO-specific model. It's a reasoning LLM that incorporates new experimental general purpose techniques.
Starting point is 00:16:41 So what's different? We develop new techniques that make LLMs a lot better at hard-to-verify tasks. IMO problems were the perfect challenge for this. Proofs are pages long and take experts hours to grade. Also, this model thinks for a long time. Oh, one thought for seconds, deep research for minutes. This one thinks for hours. Importantly, it's also more efficient with its thinking, and there's a lot of room to push the test, time, compute, and efficiency further. It's worth reflecting on just how fast AI progress has been, especially in math. In 2024, AI labs were using grade school math as an eval in their model releases. Since then, we've saturated the high school math benchmark, then AIME, and now are at IMO Gold.
Starting point is 00:17:26 When you work at a frontier lab, you usually know where frontier capabilities are months before anyone else, but this result is brand new using recently deployed techniques. It was a surprise even to many researchers at OpenAI. Today, everyone gets to see where the frontier is, end quote. Since I mentioned skeptics have been throwing cold water on this, let me end by quoting from one of them for balance. This is Corncaramol Boldie on X. Quote, the model isn't public. The evaluations aren't public. Yet you have a bunch of open AI employees claiming their experimental reasoning LLM got gold level performance on the IMO. What is this?
Starting point is 00:18:04 Not science for sure, not even science by demo. Science by PR, question mark, end quote. Only two days in, but so far my take on the city of Pittsburgh is five, would recommend with all the hills and cliffs, but then the various neighborhood flavors, it feels like Chicago and Cincinnati had a baby. And I mean that in the highest compliment possible, given my affinity for both of those cities. Talk to you tomorrow.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.