activescott's Notes

Public notes from activescott

Wednesday, February 4, 2026

OpenAI’s rivals are cutting into ChatGPT’s lead. The top chatbot’s market share fell from 69.1% to 45.3% between January 2025 and January 2026 among daily U.S. users of its mobile app. Gemini, in the same time period, rose from 14.7% to 25.1% and Grok rose from 1.6% to 15.2%.

On desktop and mobile web, a similar pattern appears, according to analytics firm Similarweb. Visits to ChatGPT went from 3.8 billion to 5.7 billion between January 2025 and January 2026, a 50% increase, while visits to Gemini went from 267.7 million to 2 billion, a 647% increase. ChatGPT is still far and away the leader in visits, but it has company in the race now.

Those early adopters’ enthusiasm has propelled generative AI forward in the years after ChatGPT’s release, but there is plenty of room to grow. Most devices Apptopia measured never use chatbots, so the race is far from settled as the AI apps fight for share.

And finally, pure user numbers don’t tell the full story, since users spend different amounts of time with each chatbot on average. Even though Anthropic’s Claude doesn’t have close to as many users as ChatGPT or Gemini, the time people spend with it has surged from about ten minutes daily in June 2025 to more than thirty minutes today.

#

Tuesday, February 3, 2026

Sunday, February 1, 2026

FurMark 2 is the successor of the venerable FurMark 1 and is a very intensive GPU stress test on Windows (32-bit and 64-bit) and Linux (32-bit and 64-bit) platforms. It's also a quick OpenGL and Vulkan graphics benchmark with online scores. FurMark 2 has an improved command line support and is built with GeeXLab.

To measure the adversarial robustness of AI agents, we introduce AgentDojo, an evaluation framework for agents that execute tools over untrusted data. To capture the evolving nature of attacks and defenses, AgentDojo is not a static test suite, but rather an extensible environment for designing and evaluating new agent tasks, defenses, and adaptive attacks. We populate the environment with 97 realistic tasks (e.g., managing an email client, navigating an e-banking website, or making travel bookings), 629 security test cases, and various attack and defense paradigms from the literature. We find that AgentDojo poses a challenge for both attacks and defenses: state-of-the-art LLMs fail at many tasks (even in the absence of attacks), and existing prompt injection attacks break some security properties but not all. We hope that AgentDojo can foster research on new design principles for AI agents that solve common tasks in a reliable and robust manner.

Saturday, January 31, 2026

Rclone is a command-line program to manage files on cloud storage. It is a feature-rich alternative to cloud vendors' web storage interfaces. Over 70 cloud storage products support rclone including S3 object stores, business & consumer file storage services, as well as standard transfer protocols.

Rclone has powerful cloud equivalents to the unix commands rsync, cp, mv, mount, ls, ncdu, tree, rm, and cat. Rclone's familiar syntax includes shell pipeline support, and --dry-run protection. It is used at the command line, in scripts or via its API.

Friday, January 30, 2026

The Gaza Health Ministry has been documenting the deaths of Palestinians from the Israeli onslaught and reporting the number of people killed. The current toll stands at 71,667 Palestinians, with hundreds of thousands injured.

The health ministry’s numbers have long been dismissed by pro-Israeli voices as “Hamas propaganda.” However, the IDF is now supporting the ministry’s figures.

The IDF says it is now reviewing the Gaza Health Ministry’s data to determine how many militants were killed. Last year, +972 Magazine obtained IDF data that showed at least 83% of the Palestinians killed by Israeli soldiers in Gaza were civilians.

I love these guys:

The Pentagon is at odds with artificial-intelligence developer Anthropic over safeguards that would prevent the government from deploying its technology to target weapons autonomously and conduct U.S. domestic surveillance, three people familiar with the matter told Reuters. ...In its discussions with government officials, Anthropic representatives raised concerns that its tools could be used to spy on Americans or assist weapons targeting without sufficient human oversight, some of the sources told Reuters.

A comprehensive list of 500+ verified bots and web crawlers from CloudFlare Radar, available as a JSON dataset for bot detection, user agent analysis, and web scraping identification.

Why

Identifying legitimate bots from malicious scrapers is essential for web security and analytics. This package provides the official CloudFlare Radar verified bots directory, helping you:

Detect verified bots – Identify legitimate crawlers like Googlebot, Bingbot, and more
Filter analytics – Exclude known bots from your traffic reports
Allow-list crawlers – Permit verified bots while blocking suspicious traffic
User agent lookup – Match user agent strings against known bot patterns

Thursday, January 29, 2026

Simple cross-stack type-safety for your API, with just a sprinkle of TypeScript magic ✨

🛟 Contract-First API
🌈 It's just HTTP/REST
🔒 Supports all Standard Schema validation libraries
📦 OpenAPI generation

The monthly employment report gives a snapshot of Washington's job market. It includes the unemployment rate for Washington and the nation, the number of people working or looking for work in Washington, and the number of jobs in each industry. You can use this report to understand overall economic trends and how different industries are doing.

In 2025, the central Puget Sound region lost 12,900 jobs. If you exclude the anomaly of the COVID-19 pandemic, this is the first time the region has experienced an annual decrease of jobs since 2009, during the depths of the Great Recession.

Historically, jobs in the Puget Sound region have grown by between 30,000-40,000 jobs per year. Employment growth during the Amazon boom was significantly higher, peaking at 61,100 jobs added in 2016.

The EV maker is increasingly emphasizing the potential of artificial intelligence, driverless technology and humanoid robots to drive future growth as its traditional business of selling automobiles struggles.

The EV maker is also halting production of its S and X model vehicles and will repurpose the production facilities in Fremont, California, for Optimus. The Model S, a luxury sedan that costs about $95,000 and the Model X, an SUV with a pricetag of nearly $100,000, are low volume vehicles compared to Tesla’s more affordable 3 and Y models.

Adjusted earnings per share were 50 cents in the quarter, Tesla said Wednesday, higher than the average of analyst estimates. The results snap a string of quarters in which profit was weaker than expected.

The profit beat helps offset disappointment stemming from a steady decline in vehicle sales: Tesla earlier this month reported a 9% decline in 2025 deliveries from the previous year. That slump sharpened in the fourth quarter, when deliveries dropped 16% from a year earlier.

Revenue from regulatory credits fell 22% in the fourth quarter from a year earlier, showing how a lucrative revenue stream is drying up. The company receives the payments from competitors who exceed federal fuel economy standards. That income has dropped after the Trump administration eliminated penalties for automakers that failed to meet the standards. Due to the lower regulatory credit revenue and a drop in vehicle deliveries, Tesla’s 2025 revenue declined for the first time.

The company reported 1.1 million active subscribers for its Full Self Driving driver assistance software — up nearly 40% from a year earlier. The software, which currently is not considered autonomous and requires constant human supervision, is becoming subscription-only starting after Feb. 14.

Robotaxi launched in Austin in June. This month, Tesla started rolling out “a few” robotaxis without human driver supervision in Austin. It plans to scale this to its entire Austin fleet over time. The company also operates a rideshare service on the same app in the San Francisco Bay Area that is not considered autonomous and has drivers in the front seat. It also has permits to test the service in Nevada and Arizona.

The security firm identified risks such as exposed gateways and API/OAuth tokens, plaintext storage credentials under ~/.clawdbot/, corporate data leakage via AI-mediated access, and an extended prompt-injection attack surface.

A major concern is that there is no sandboxing for the AI assistant by default. This means that the agent has the same complete access to data as the user.

Similar warnings about Moltbot were issued by Arkose Labs’ Kevin Gosschalk, 1Password, Intruder, and Hudson Rock. According to Intruder, some attacks targeted exposed Moltbot endpoints for credential theft and prompt injection.

Hudson Rock warned that info-stealing malware like RedLine, Lumma, and Vidar will soon adapt to target Moltbot’s local storage to steal sensitive data and account credentials.

A separate case of a malicious VSCode extension impersonating Clawdbot was also caught by Aikido researchers. The extension installs ScreenConnect RAT on developers' machines.