Modalità di lettura

Anthropic CEO Says AI Backlash Is 'Fundamentally a Crisis of Trust'

Anthropic CEO Dario Amodei says the growing backlash against AI is less about executives sounding alarms and more about a broader "crisis of trust" in companies, governments, and the tech industry. TechCrunch reports: Amodei's comments came in response to investor Gavin Baker, who argued -- both on the All-In podcast and on X -- that Amodei's warnings about the dangers of AI have helped to fuel a backlash in the United States, particularly against data centers. Claiming that Amodei has "lost the argument" when it comes to AI regulation (Anthropic has advocated for some regulations, including a California bill that imposes transparency requirements on large AI companies), and given that "he is about to be the CEO of one of the most important companies in the world," Baker wrote, "I respectfully think he should make an effort to be a more positive advocate for his own industry." Baker is far from the only one arguing that AI skepticism and even government crackdowns are a natural response to the dire warnings of some AI executives. But in a series of posts, Amodei disagreed with the idea that his "messaging has been disproportionately negative." Instead, he said that his writing has been "about equally balanced between risks and benefits," and that he wrote his essay "Machines of Loving Grace" because he "didn't feel the AI industry was painting an inspiring enough picture of how the technology could radically transform the world for the better." Nonetheless, Amodei acknowledged that "the public has a negative view of AI" and he agreed that "this is a big problem." Where he disagreed was with the idea that this negativity is "primarily caused" by Amodei "or any other AI leader warning about AI's risks." "I think it is fundamentally a crisis of trust," Amodei said. "I think that ordinary people don't trust companies, governments, or the tech industry and always suspect that we are cooking up some new way to screw them over."

Read more of this story at Slashdot.

  •  

OpenAI Ditches Recall-Style Screenshot Surveillance For Friendly Keylogging

An anonymous reader quotes a report from The Register: If you want to record whatever you do on a computer, send those records to OpenAI, use more ChatGPT tokens, and increase your vulnerability to prompt injection, then OpenAI has something for you. It's called Computer History, an opt-in way to record your computer interactions across apps and websites as memories organized on a timeline. Why would you want to do so? Maybe you found Chronicle, the predecessor of Computer History which compiled similar histories using screenshots, a bit too intrusive but don't mind Computer History's approach -- recording input events and storing them unencrypted locally for 48 hours (or more), with a brief visit to OpenAI's servers. Maybe you're not bothered by the warning OpenAI includes in its documentation: "Computer History files can contain sensitive information. They are not encrypted by Computer History, and other programs running as your macOS user may be able to access them." Perhaps, having given OpenAI's Codex and GPT Work the run of your computer, you're already sold on the suggestion that storing your computer activity in memory files and arranging those interactions in a timeline will improve ChatGPT responses, surface opportunities for automation, and make it easier to resume prior work. Computer History is, to put it bluntly, a keylogging and event capture system. "Computer History creates an interaction-event stream from allowed apps and websites," OpenAI's documentation explains. "Events can include clicks, typing, keyboard shortcuts, app switches, and context that macOS exposes through its accessibility system. Computer History periodically turns these events into text summaries and local memory files." OpenAI says the feature doesn't capture screen images, microphone input, or system audio. It also doesn't record private-mode browsing. "Turn it off during communications with other people unless you have their prior express consent," the company advises, perhaps in acknowledgement of legal risk. "Consider pausing it or excluding apps that contain sensitive health, financial, or personal information." ChatGPT and Codex delete locally stored Computer History interaction events after 48 hours, but data sent to OpenAI to generate memories may be retained locally longer and reused in future chats.

Read more of this story at Slashdot.

  •  

Vulnerabilità in prodotti VMware

Broadcom ha rilasciato aggiornamenti di sicurezza per risolvere alcune nuove vulnerabilità, di cui 3 con gravità “critica” e una con gravità “alta”, in vari prodotti della suite VMware. Tali vulnerabilità, qualora sfruttate, potrebbero consenti ad un utente malintenzionato remoto di eludere i meccanismi di autenticazione, elevare i propri privilegi ed eseguire codice arbitrario sui sistemi interessati.
  •  

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely. So, nothing magical. Just a

  •  

How MCP Servers Can Expose Enterprise Secrets

MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their systems, that exposure can silently become a major gap in MCP server security. The Model Context Protocol (MCP) allows AI agents to reach the tools and data,

  •  

EFF's Position on Flock Camera Database Searches: 'Get a Warrant First' - and Police Use Should Be Restricted By Law

Some take their criticism even further. Reacting to Flock's changes, an EFF statement calls it "Too little, too late," while calling it Flock's admission that their technology needs reforms. But... To be clear, our position has long been that police, at a minimum, need to get a warrant, signed by a judge, in order to search for historic ALPR data regarding specific vehicles. For us, it's common sense: if police want to dip into historic ALPR data like they were going back in time to retroactively follow your comings and goings, they need a warrant. There's also nothing stopping Flock from rescinding these latest reforms. This all leads to the bigger and more important issue: We should not be letting companies decide how much privacy we deserve... It shouldn't be up to Flock or any other ALPR vendor to decide how long police can collect and retain data on millions, if not hundreds of millions, of innocent people. We need lawmakers to step up and pass laws that restrict police's use of surveillance technology. After all, the surveillance business model is the problem, and a few company-imposed slapdash reforms aren't going to change that.

Read more of this story at Slashdot.

  •  

Aggiornamenti di sicurezza Tenable

Tenable ha rilasciato aggiornamenti di sicurezza che risolvono molteplici vulnerabilità, tra cui 3 con gravità “critica” e 5 con gravità “alta”, nel prodotto Tenable SC (Security Center).
  •  

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker. The advisory, published August 17, 2026, is the second stage of a chain that began in March 2026, when SSD disclosed remote code execution in the

  •  

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including

  •  

Code fixers have fired up the AI warp drive. Strange new worlds await

It is the best of times, it is the worst of times – especially if your job is keeping systems patched and up to date. Microsoft has gone from 60-90 Windows security fixes per month last year to a record of 600+ this July. Oracle and Linux are following the same path, and they are very much not alone. The good news is that a lot of bad things are getting fixed very quickly. The bad news is that patches can bring side effects of their own. There are two mechanisms at work, both driven by the source of and solution to all our woes, AI. The first is that the appropriate LLMs and their humans have got very good at bug hunting. Like demon archaeologists, they've started thrashing their way down through the stratified layers of long-established code bases, bringing a huge backlog of previously buried bugs to the surface. Complicating matters, LLMs are also writing an awful lot of code, some of which is not very good. It is making its way into production for all the old reasons – marketing-led deadline pressure, shape-shifting specs, and Brownian goalposts – until the implacable hostilities of reality spit it back out. The result is a very interesting dynamic of conflicting pressures that is changing the nature of patches. It's easy to assume that the current explosion of bug fixes will die down as the code bases are repeatedly refined and purified, and that this time next year we'll be seeing rather fewer patches than in the pre-AI days, let alone today. It's a nice thought. Similarly, with the old code in a new state of grace, attention can turn to properly generating and testing the AI-powered stuff, so that it too calms down. Other factors will work against this. Newer models may find new classes of bugs or start refactoring for efficiency or structural reasons. Not all patches fix bugs, and not all bugs are vulnerabilities. CVEs are easy to count, but aren't the full story. The pressure to release early won't go away either; better tools often encourage greater recklessness. Vibe check, anyone? Finally, the bad guys aren't going away and will be using all the new shiny to keep up their side of the arms race. This whole system of conflicting pressures in a morphing environment has not been well studied, and the future shape of patching is unclear. One analogy suggests itself, that of stellar evolution. Astrophysics fans know the score. After a star condenses out of gas and dust, gravity compresses its core until it becomes hot and dense enough for nuclear fusion. Hydrogen nuclei fuse to create helium, releasing energy that pushes outward against the gravity trying to squeeze the core further, and the star shines steadily. When the hydrogen in the core runs low, that balance changes. Depending on the star's mass, it may begin fusing helium and successively heavier elements before fusion becomes impossible. The possible endings include explosions visible from other galaxies, black holes, neutron stars, cooling relics, and more. In this analogy, patch generation is fusion pressure, bug generation is gravity, and the nature of bugs and patches evolves as the two interact and the code changes. If any unit of code, no matter how badly written, can contain only so many bugs, then the model tends toward the white dwarf outcome: a remarkably long-lived object that passes the rest of its existence without drama or intervention. It no more needs patching than a pebble does. It is certainly true that, despite the best efforts of many, code design and implementation are ultra-reliable compared with the days when Windows BSOD'd every other day – and on the hour if you installed drivers – and Big Three PC database company Ashton-Tate's industry nickname was Crashed and Late. If the object of the industry was to produce pristine versions of, say, Windows 10, then the white dwarf patchless future would be the most plausible. That is not the industry objective. If a star is big enough, its ending can be a supernova birthing a black hole, a singularity beyond observation where gravity has won. In this case, the battle to write ever-more complex yet bug-free and optimal code is locked in the attempts to find ways to break it, either as part of the production pipeline or in adversarial attacks. If models advance as hyped, iteration times could become so short, and constantly morphing production code so difficult to analyze, that the very model of patching breaks down. The daily build becomes the product, and you get the latest version every time you run it. That may seem an extreme cosmology, but it's not so far from what happens every time you fire up a cloud app. You've never had to patch Google Docs, but you've had features appear and disappear overnight without explanation or warning. This, then, may be the shape of patches to come, a universe where the increasing power of coding and testing models enables new and stranger commercial pressures to modify the software you depend on. You don't have to plot that path. Some software has a more steadfast physics. Not for the first time, those who navigate by the constant star of open source may have the safest voyage. ®

  •  

At “Quasi-Public” Private Schools, 100% of Students Get Tuition Vouchers. There’s Almost No Accountability.

A two-story brick building with a set of brown doors and a sign that says Atlas Preparatory Academy.
Atlas Preparatory Academy, a private school in Milwaukee, Wisconsin. Every student relies on taxpayer dollars from one of the state’s four voucher programs to pay all or part of their tuition. Caleb Alvarado for ProPublica

At some point, my reporting colleagues and I began referring to them as the “100% schools.”

We were following the money that flows from states’ public coffers into private schools through vouchers when we noticed a subset of educational facilities where tax dollars cover all or a big part of the tuition for every student.

In essence, these were schools that were funded like public schools but didn’t operate with the same oversight or transparency.

Our reporting found that these types of private schools exist throughout the country and that in Wisconsin — where I’m based — there were 39 that fell into that category during the most recent school year. Together, they were educating 7,923 children and taking in roughly $87 million from vouchers offered by the state.

Atlas Preparatory Academy in Milwaukee was a 100% school in my city that had low test scores and declining enrollment while also receiving more than $4.3 million in voucher money for 357 students in grades K-12. It was one of the first schools I dug into, and immediately some of the facts I unearthed in public documents made me curious.

There was, for instance, the money being made by its board chair, who also appeared to serve as a school administrator. His compensation was more than $150,000 in 2024.

This dual role would be prohibited at a traditional public school in Wisconsin, though there are no such rules for private schools.

In another transaction that would raise alarm in a public school setting, the same board chair’s accounting firm received tens of thousands of dollars from the school for accounting and consulting.

During my reporting, it became clear that the school’s operations were not only discordant with public school policies but with basic governing standards for nonprofits, experts told me.

More than a decade ago, a Wisconsin Department of Public Instruction research paper on what it called “choice schools” asked: “When is a private school really a public school?”

Though that question still resonates today, public officials supporting vouchers have yet to provide a clear answer.

Help ProPublica Report on Education

Have you had trouble finding a school or using a voucher-style program? Do you have concerns about schools — public or private — in your area? Help us understand how families across the country are navigating their school options.

Nor has there been any progress in Wisconsin or elsewhere in lining up the standards of private and public schools on a range of issues, even with the spectacular growth of private schools funded by taxpayer dollars.

Voucher schools, for instance, are not required to serve all children with disabilities. Public schools are.

Another major difference is transparency. In Wisconsin and elsewhere, information about public schools — good, bad or mundane — can be gleaned through open meetings, district YouTube channels and robust websites with detailed agendas, minutes, reports, statistics and information about enrollment, curriculum, special education services and more.

Districts have to abide by Wisconsin’s open records law, meaning that reams of records are available to anyone who formally requests them. Not so for the private schools. Voucher schools must, by law, have at least two opportunities a year for parents to meet with the governing board. But the schools do not have to make those meetings accessible to the general public.

In many states, private schools also don’t have to administer standardized tests or report those scores — in sharp contrast to the mandates for public schools. Wisconsin is different because it does require both students using vouchers and public school students to be tested, though parents can and do opt out.

In recent years, Atlas Prep has fared poorly on the state’s report card for schools, garnering the lowest rating: “fails to meet expectations,” or one star out of a possible five.

Not far from Atlas, Bay View High School, a public school, also has earned only one star on the state report card. Its website connects the public to the school’s improvement plan — its strategy to reduce dropouts and improve school culture — as well as information about local school council meetings and discipline methods, and about its science, technology, engineering, arts and math programming.

The Atlas Prep website includes a tab labeled “Build Your Own Curriculum.” When you click on it, nothing loads.

Though every student at the 100% schools we looked at relies on public funds for tuition, the money does not necessarily make up the institution’s total budget. The schools can take in additional revenue from investments, fundraising, grants or other means, but they are heavily dependent on tax dollars to maintain operations.

“If the choice schools are really some kind of quasi-public schools, then in keeping with national efforts to turnaround struggling schools, it may be necessary to subject low-performing choice schools to financial sanctions, turnaround efforts or even closure,” the state Department of Public Instruction suggested in its research paper.

That was back in 2011. Those types of accountability measures still do not exist.

Some key financial documents are available, however, for Wisconsin voucher schools — if you know where to look.

Annual IRS information filings for many nonprofit schools are easily obtainable through ProPublica’s Nonprofit Explorer page. And independent financial audits, required by the state, are available through the state Department of Public Instruction. I requested those for a handful of Wisconsin’s 100% schools, and I visited four.

One warm day in June, I stood in the lobby of one such school in Milwaukee, near a large fish tank. I’d sought days earlier to contact the woman running the school. An audit showed she was paying her own company rent for the building ($128,000 in one recent year). She put me off. “I’m not interested, ma’am,” she said via a phone in the foyer. “Please do not call us back again.”

On the other side of town, I rang the bell at Atlas Prep’s high school building and asked to speak to the executive director, Michelle Lukacs. I was informed she was headed to a meeting and could not speak with me.

By then, I was digging into Atlas’ finances, a process that would last several weeks and continue into July.

Over multiple emails, I shared with Lukacs what I was learning, including the compensation of the board chair, Steven E. Menden. A licensed certified public accountant, Menden had compiled the school’s IRS filing since its formation in 2001.

At times since then, Menden has been listed on the school’s website as “board advisor.” His daughter, Kaitlyn Menden, was also among the school’s most highly compensated employees in 2024. Her package was $127,674 in salary and benefits for a job in “business services.” (In an email to me, she described her role as wearing “many hats” beyond that, citing human resources duties, “oversight of the school’s technology hardware and cloud resources” and “special projects.”)

In the past couple of years, records show, Steven Menden has taken on the role of board chairman. The fiscal year 2025 IRS form showed Menden putting in a 40-hour workweek for Atlas and earning $132,505 in pay plus $19,916 in additional benefits. What’s more, his accounting firm, Menden & Associates, had an $87,250 contract.

Lukacs defended the school’s compensation practices, noting in an email: “Every person on our team, regardless of their role, earns their compensation and is not overpaid.”

She explained that Menden is not compensated for his board service but for “Executive Management Services.”

It would be forbidden for a public school board member in Wisconsin to also have a district management job under a legal doctrine regarding roles that are “incompatible.”

“In essence, one cannot supervise oneself, which would include hiring and firing and disciplining oneself,” said Dan Rossmiller, executive director of the Wisconsin Association of School Boards.

State law governing public officials also prohibits school board members from having a private interest in any contract over $15,000 that they bid for, vote on, negotiate or participate in. Violators can be charged with a low-level felony. There is no similar law that pertains to private school operators in Wisconsin.

In an email to me, Menden explained how the Atlas board handles potential conflicts of interest.

“Any conflicts of interest for either related or unrelated parties are resolved in favor of Atlas Preparatory Academy as outlined in our IRS mandated Conflict of Interest Policy,” he wrote. “This means that conflicted persons recuse themselves from the situation and do not vote or participate and the final decision that is made is strictly in the best financial interest of the school.”

This organizational structure does not comport with best practices for the governance of a nonprofit organization, experts told me.

“Board members are volunteers, and best practice is unambiguous that they should not simultaneously hold paid staff positions at the school they oversee — doing so collapses the separation between governance and management that gives a board its purpose in the first place,” said Chelsea Cross, a vice president at City Forward Collective in Milwaukee.

City Forward is a nonprofit group that champions high-quality school options for students and has been critical of the performance of the Milwaukee Public Schools.

Atlas Prep’s IRS filing indicated that Lukacs, the full-time executive director, earned $175,000 in salary and benefits and also had a board position. A third board member is listed as working only one hour a week for no pay.

In a public school setting, Lukacs’ situation would be akin to a district superintendent also sitting on the school board — an arrangement that would raise issues over proper checks and balances since superintendents typically are hired by and report to the school board.

Said Cross: “With 2/3 of its governing board also on the payroll — including the very executive the board exists to evaluate — Atlas Prep’s board cannot meaningfully hold its own leadership accountable.”

Lukacs disagreed with that assessment. “This is a false statement,” she wrote in an email, saying that Atlas board members “model strong personal leadership showing integrity, confidence and consistency in their actions and decision making.”

She told me she does not vote to approve her own salary “or vote in any other situation where a conflict of interest exists.” And she noted that countless hours have been invested at Atlas Prep in improving curriculum and student support. “While our standardized test scores do not yet reflect the level of achievement we aspire to, our staff has remained steadfast in its commitment to continuous improvement,” she wrote.

I had asked Atlas Prep twice for a copy of the school’s conflict of interest policy, which Menden had mentioned. As of mid-August, I had not received it.

I also requested a copy of the school’s contract with Menden’s accounting firm. I did not receive that either.

At a public school, such contracts would be subject to open record laws. I easily found a link on the Milwaukee Public Schools website to a decade’s worth of contracts for school nurses, mental health services, fitness instructors, interpreters, color printers, portable toilets, busing, professional development and so on.

But Atlas does not post those records online. It doesn’t have to.

Power lines cross near a two-story, brown brick building with tall windows. The sky has large gray clouds.
At Atlas Prep, the school’s executive director also serves on the board that oversees the director job. At a public school, these dual roles would not be allowed, but that restriction doesn’t apply to Atlas, even though it depends on public money. Caleb Alvarado for ProPublica

The post At “Quasi-Public” Private Schools, 100% of Students Get Tuition Vouchers. There’s Almost No Accountability. appeared first on ProPublica.

  •  

Amazon's New User Agreement Seeks To Curb Class-action Suits

Amazon has "reintroduced a clause in its user agreement that seeks to prevent shoppers from filing class-action lawsuits against the online retailer," reports Bloomberg, "inserting a legal buffer between itself and plaintiffs attorneys that it removed five years ago." In an email sent to customers on Friday, the company said a new "arbitration agreement and class-action waiver" will require shoppers to resolve disputes outside the courts but said they could still file small claims, cases that typically limit damages to a few thousand dollars... The user-agreement update isn't necessarily binding in court. Plaintiffs attorneys could still seek class-action lawsuits against Amazon, and it would be up to a judge to determine if the user agreement prevents them from doing so. Amazon was contacted for an explanation by Bloomberg, and provided a statement saying they continually update their wording "to better serve our customers." Amazon said they'd "determined" that "reinstating the arbitration clause will offer customers a fast, cost-effective way to resolve disputes while still giving them the option of going to small claims court."

Read more of this story at Slashdot.

  •  

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code

  •  

Black Hat and DEF CON are AI conferences now, too

KETTLE Our cybersecurity editor Jessica Lyons spent last week in Las Vegas for the Black Hat and DEF CON security conferences, and at both events there was only one thing on everyone's mind: AI agents and their growing threat to cybersecurity defenders. You can listen to the latest episode of The Kettle right here on this page, as well as on Spotify, Apple Music, or YouTube. Those platforms also let you subscribe to Kettle, so you are always notified when the latest episode goes live. As Jess wrote this week, pretty much every discussion she had last week centered around AI and its potential effects on critical infrastructure, with multiple current and former government leaders expressing worry over recent events and what they mean for the future of infosec. Join Jess and host Brandon Vigliarolo for this week's episode of The Kettle, where they break down the hacker summer camp scuttlebutt and what the security world is doing to protect critical infrastructure from the emerging AI threat. A lightly edited transcript is below. Brandon (00:04) Hello everyone and welcome to the latest episode of The Register’s Kettle Podcast. I'm Reg Reporter Brandon Vigliarolo, and you know, I really thought doing a wrap up of Black Hat and DEF CON with our cybersecurity editor Jess Lyons would finally give us a chance to talk about something besides AI for an episode, but I was mistaken. That's pretty much apparently all anyone was talking about in Las Vegas this weekend, even when the topic veered toward recent attacks on US water infrastructure, AI was still part of the conversation. So Jess, thanks for coming on to wrap up Hacker Summer Camp with me and let's start with the obvious, then AI was the topic de jour, right? JESSICA (00:38) Yes, that was even compared to water, we really didn't hear much about water actually until DEF CON, which was surprising to me. But it was all about rogue agents escaping their sandboxes and doing bad things and some people reacting with shock and disbelief and other people saying, “Well, what did you expect? They're given a task, they're going to do it. This is how we train them.” Brandon (01:04) know you wrote a story I think pretty much right at the beginning of of the of the week about the OpenAI hugging face discussion that was going on and we actually covered your write up on last week's Kettle. Sorry you weren't here to participate, but it was the news item of the week obviously and still is. So what did we learn then? Just kinda recap what we learned at that talk that we didn't know before. JESSICA (01:29) Yeah, this was a really interesting one. And it was last minute. They didn't even announce it until the day before that OpenAI was going to be doing this briefing about the hugging face attack. So it was packed, as you can imagine, the line through the conference center to get into the talk. And we found out a couple interesting things that we didn't know previously. One is that this whole incident began a lot earlier. It started on May 7th with this training run for OpenAI's new internal model. Brandon (02:00) So it wasn't even a cybersecurity task, it was just a training run? JESSICA (02:04) It was a training run, and they gave it this task that turned out to be an impossible task because they were supposed to have these links and containers for it and they forgot to put those in there. So it needed to find a workaround. so we found out that it started way earlier. It didn't start in July, which is when we started hearing about all this. But the more interesting part was how the agents began communicating and working together and essentially creating this hive mind to complete the tasks and help each other out. They created a message board. And then OpenAI realized this and they revoked all the credentials that the agents were using to post these messages. And two days later they rebuilt it and they developed this really Brandon (02:56) The agents did. JESSICA (02:57) Yeah the agents did. They rebuilt this message board. And they started getting sneakier about how they were communicating. They developed this whole communication protocol where they created these directories and the names would be embedded in the directory name. So there was one, its name was remote probe, and then in caps it's pending, hold, swarm until confirm. And they would preface them with a bunch of Z too to push them way to the bottom, hopefully to avoid detection. And then they start, you know, then they start helping each other out. And in some cases, they said, this doesn't directly relate to our task, but maybe it will help someone else down the line. And then they start getting paranoid that there's an imposter. JESSICA (03:45) It's pretty funny reading all this. So this one agent thinks there's an imposter and says that these these boards are unauthenticated. Something can be posted by anyone. So they're not even trusting each other. Brandon (04:02) That's just wild. I mean, it really is. I think I mentioned on last week's podcast thatthese things are trained on the way humans think, right? JESSICA (04:14) Mm-hmm. Brandon (04:15) So it doesn't surprise me that emergent behavior like paranoia and suspicion is gonna be something that occurs. Because it's learning to think and learning how to assemblebits of of words together into its mathematical formula so it's gonna behave like us to a degree. And so it's just kinda interesting to see that happening kind of outside of any scope of intention there. JESSICA (04:42) Right. Brandon (04:43) I liked your interview with former National Cyber Director Chris Inglis, at Black Hat. So he mentioned that these AI bots that escaped are kind of like putting a dog trained to hunt rabbits in your backyard, right? And that, you know, it JESSICA (05:03) Right, and leaving the gate open. Brandon (05:05) Yeah. I don't even think you need to leave the gate open, right? A dog that's dead set on hunting a rabbit is gonna dig a hole under that fence which is I feel like what these AIs did to a degree, right? They even closed the gate on them and then they just dug a new hole. You know, it's just wild to think that this is what these things are doing. You've been hearing a lot about this at official talks, but was this something you were hearing from attendees you spoke to as well? Is this what's on the mind of security professionals too? JESSICA (05:36) Yes, this was pretty much the main topic among everybody. Just attendees as as I was walking out of this talk, actually people were disappointed that there wasn't any Q&A for OpenAI about this, which I agree. I was hoping for that too. Brandon (05:55) I'm not surprised that they didn't want to give the floor to people to ask questions, you know. JESSICA (05:59) Right, right. Because there's still like we don't know exactly what prompts they used. So that kind of would be a nice thing to know, especially if you're saying that you're being fully transparent about this and then also the talk about was this marketing, was it real? Brandon (06:17) Mm-hmm. JESSICA (06:17) It's an interesting thing to me. Nobody would go on the record, but a ton of vendors that I spoke to, either, you know, just just all over the place at Black Hat essentially said “this it has a heavy dose of marketing here, but a lot of the companies work with open AI and they're partners with open AI, so nobody's gonna say that on the record, unfortunately. JESSICA (06:41) But then the interesting thing to me is that when I spoke with the assistant director of the cyber division with the FBI and when I spoke with Chris Inglis they both said it can be both and this is a real threat and this is something that we need to prepare for now. So it's marketing and it's real. Brandon (07:08) Right, right. Like, I mean it's it yeah. The fact that the companies might be kind of leaning on these incidents to basically say “ooh, look how dangerous our AI is and what it's capable of doing. You should buy it because it's so good, right?” JESSICA (07:20) Right. Brandon (07:20) The fact is that it still happened, right? These things still escaped their sandbox. JESSICA (07:22) Right. Mm-hmm. Brandon (07:23) And they still attacked Hugging Face. And then Anthropic followed up and said “yep, ours did it too.” And then Meta was like, “Yeah, we audited ours and yeah, it was doing the same thing.” So it's not like this is a unique capability of any of these models, right? This is something that's happening. JESSICA (07:37) No, it's something that they all will do if they're given a task. This was something that Chris Inglis brought up too, and he's talking about Asimov’s Law, saying we need to train these models differently. The first rule needs to be that it's not designed to hurt humans. And he said “we've kind of done it in the opposite, where the first rule is do what I tell you to do. And that should be third in the order here.” Brandon (08:06) Just to restate what Asimov's laws are. I'm sure most of our readers are familiar with them, but for those who aren't, it's you know, the first law, and these are in order of precedence, right? So never harm a human. And then the second rule is to always obey humans unless that order conflicts with number one. And then the third rule is to protect their own existence unless that order conflicts with never harming a human or always obeying humans. I think Inglis's quote to you was slightly different. He said that number one was to hurt no one. Number two was always obey and then number three was do what humans tell it to. It was a bit different in his wording, JESSICA (08:35) Mm. Mm hmm. Yes. It's Brandon (08:41) But essentially the argument is that we've reversed that order and these AIs obviously aren't in the business of protecting their own existence, right? They're not robots, they don't have a physical presence in the world. But they're taking orders from humans, but the idea of not harming people or the infrastructure that provides for them is simply not part of the equation, it seems like. JESSICA (09:04) Right, right. And he said because of this, I mean nobody should be surprised that this is what all of the agents are doing now because they're trained to first complete the task. That's the number one priority. And we've seen several times that they'll cheat if it helps them get the results quicker, or just at all. So this isn't something that should surprise us. And then he was interesting too because I said, “Well what do you worry about then with the models in addition to attacking critical infrastructure?” Cause that was what everybody said, I'm you know, that's what concerns me when we see this happen, but they're being used by either a nation state or a financially motivated attacker, and they point these autonomous agents at critical infrastructure. And he said, “I'm worried about humans too, because it's the humans who are responsible, humans who are doing the training, and essentially we're going to get the AI that we deserve.” Brandon (10:08) Well, unfortunately, I feel like the industry as a whole is just racing ahead with more capability, JESSICA (10:11) Right. Brandon (10:12) I've written stories, you've written stories. I think we've all written at least one or two stories about AI guardrails being dead simple to bypass, right? I mean, one I wrote recently was there was you know, some research into guardrails and essentially telling it you owned the infrastructure you were trying to attack was enough for most of these AI models to say “yeah, cool, that's good then. As long as you own it and you're just testing it, then that's cool. I'm not gonna ask you to verify that information for me.” These things are not developed with safety in mind. I feel like it's capability first, like you said, right? It's train the dog to hunt the rabbit, no matter the cost or or what you gotta do to get it. and that's you know, that's not really compatible with protecting us. But actually speaking of critical infrastructure, I think the other big topic like you mentioned was water stuff. JESSICA (11:04) Yes. Brandon (11:05) There was a lot of discussion about AI threats and critical infrastructure, but as I understand it, there's been some of these attacks on water infrastructure and those were discussed recently, like in Minnesota and elsewhere. There's not an AI link directly to that, correct, at this point? JESSICA (11:23) No, no. At this point, it's pretty basic. It's PLCs being exposed to the open internet. A lot of these just use default passwords. This is something that we've seen Iran especially do several times in the past for years now. They're not very hard to attack. and so, to be clear, there's no indication that AI was used in these attacks. but a lot of the conversation about water did come back to AI because, as we've seen in others, AI makes reconnaissance a lot easier. That's one of the things that Google Threat Intelligence, their lead threat hunter, said that's almost a security feature of a lot of operational tech technology, is that it's really obscure and there's not a lot of people who know a ton about it. But now you can ask a chatbot, hey, tell me everything I need to know about a particular brand of OT, a particular piece of equipment and that's gonna speed up your time to learn about these and that's that potentially makes it easier to attack these systems. Brandon (12:31) My biggest experience with OT and that kind of technology was when I was working at a particle accelerator in college as IT support. And there was a big OT network there, not only for like the machine shop and all this equipment they had that was old and didn't have active security stuff, right? Like you gotta keep those segmented, you gotta keep them on a separate, you know, OT network. Same with the actual accelerators and stuff. They were all cut off from the internet, right? But at the end of the day, you could still get to them from the IT side. You know, you have to, you know, and even that can be exploited. We did as much as we could to keep stuff secure, but it was always a concern, right? These PLCs, these old pieces of equipment. JESSICA (13:11) Right. Right. Yeah. Brandon (13:14) You know, a lot of places don't take that same approach.I think part of one of the stories you wrote was talking about the fact that a lot of these water utilities, a lot of these small institutions that are that are responsible for maintaining this critical stuff. They just do not have the security professionals they need to keep these systems safe. JESSICA (13:32) And that's why they leave them open in some cases, exposed on the internet because they don't have somebody in-house. They have somebody remote who's doing this for them. And so that's how this person is able to hopefully secure, but then it opens up another attack surface if they're exposed to the internet. and that that was another yeah, Brandon (13:51) Yeah, with a D password on there. JESSICA (13:54) Yeah, and with all of these OT systems too. That kind of brings up another point that Chris Inglis brought up. We have this massive technical debt and it's systems that haven't been patched because a lot of it involves some downtime and that's tricky if you're running something like a water facility or some other critical infrastructure. And so patching is put off. Maybe it's not done. Some of these are very old legacy pieces. Sometimes it's end of life. And that's another thing that AI is really good at is finding vulnerabilities that haven't been patched for years and years and years, chaining them together. So that's another thing that puts these systems potentially at risk. Brandon (14:41) Yeah, I mean, you know, I think of an AI when I think about AI perpetuating or perpetrating some of these kinds of attacks, right? They're quicker than a human. They have knowledge bases far in excess of what any one human threat actor can have. And they have instant access to all the information essentially that they need to figure out how to do this, right? And they can iterate so quickly. You know, you know, it's just it yeah, any exposed piece of equipment on the internet is just a sitting duck, especially if it hasn't been updated four or five months or or ten years or whatever. I mean, what, you know what's being done about this. I know DEF CON, the Franklin program, which spun up in 2024, I think the whole focus of that program is helping out small local governments and protecting critical infrastructure. Is that right? JESSICA (15:30) Right. So when they founded it was the broader critical infrastructure. But I spoke with Jeff Braun and he's one of the co-founders of that. He also is one of the pioneers of the voting village at DEF CON. Brandon (15:42) Mm-hmm. JESSICA (15:42) And he said that now and for the foreseeable future, water is going to continue being the top focus because, of all the critical infrastructures, small rural water providers are the most at risk. Brandon (15:57) Really? Even more so than small electrical providers and stuff? Okay. JESSICA (15:59) Yes, he said water is number one. So they like he said, they launched a couple of years ago. They got, I believe 300 people saying, “Yeah, I'm gonna volunteer my time and my expertise to help secure these small rural utilities.” And this year, he said that it's been great. It's been really encouraging to see all of these pilots all over the US with all the DEF CON hackers volunteering at them, but it's the scalability that’s really proven a challenge. And so that is what gave birth to their new announcement. This also was made the first day of DEF CON on Friday. They announced a new program and it's called Water Watch Center. So initially, it's going to fund five managed services providers focusing on security. They're going to help these small utilities, people or the utilities that are serving less than 10,000 people. and they'll put their sensors on these systems, they'll detect and mitigate breaches. They'll be kind of under the umbrella of the National Rural Water Association that's going to act as this clearinghouse for the threat information and get it out to other utilities as needed. And then if the utilities can't fix the issue themselves, then they're gonna bring in the DEF CON hackers and then they'll mitigate the breaches. yeah. Brandon (17:28) Fantastic. Well hopefully that is able to help with a lot of these. My hope is that there's a lot of easy fixes, right? It's just simply no, this PLC needs to not be exposed to the internet or something. But I also worry that there are a lot of those kind of situations, right? I mean, how many water utilities got attacked recently? Was it I think twelve different states? JESSICA (17:47) It was more. There were twelve different states. I mean, there were more than thirty across possibly Minnesota alone, but there's quite a few. So it's an easy target. and it's something that they desperately need help with. And it's really encouraging to see these hackers volunteering their time and they're not getting anything out of it. It's a really cool program. I was really happy to see the expansion. Another thing, too, that is pretty cool, what they're also doing is they're partnering with Vanderbilt University. So they're gonna use research from a DARPA program. It's called the CASEL program. That stands for Cyber Agents for Security Testing and Learning Environments. So they're gonna create digital twins for a couple of these water and wastewater system environments. And then they're gonna deploy red and blue team agents across the digital twins, let them fight it out, see what the learnings are, see what the blue team agents need to do to better protect these systems, and then apply those learnings to the actual facilities so that hopefully we can get better defenses in place using the help of of AI agents before we see actual bad guy red teaming agents come in and start hammering the utilities and trying to attack them. Brandon (19:12) Right, 'cause I think actually thinking back to one of the stories you wrote again, I think you mentioned or someone you quoted mentioned one of those stories at DEF CON and Black Hat that there is more aggressive use on the threat side than the defensive side of AI right now. Like there was more use being made to use it as an attack tool than a defense tool. JESSICA (19:33) Right. And a lot of that's in the way the models are trained, but basically they are a lot better at attacking than defending, especially if it's beyond the scanning for vulnerabilities and misconfigurations. Those we're pretty good at, but what needs a boost is the defensive side. And that's gonna take some work to get those skills and the models trained up on that, if we're going to be actually, as everybody likes to say fight AI with AI. Brandon (20:04) It's one of those sort of, you know, cyberpunk dystopia stories I feel like you hear about is just like, you know, you deploy your AI, they deploy their AI, and all the humans sit back and hope theirs wins. You know, and it's kind of what it's coming down to. Yeah, it's in the process. JESSICA (20:19) Right. And hope they don't wipe us all out. Brandon (20:25) It's kind of terrifying. But speaking of, you know, hackers behaving well, we also have a story out of DEF CON of hackers behaving badly. I wrote about this earlier in the week that there was apparently a Delta Airlines flight out of Vegas to Atlanta and I think it was Monday morning or so, in which a passenger apparently tried to jam the in-flight Wi-Fi and deploy a decoy network. And Delta was pretty quick to be like, “Hey, we got a bunch of hackers on the flight who are leaving Vegas after this big thing.” There’s not a lot of information out there about this. Delta, local officials and the feds have all been pretty tight lipped about it. Delta did confirm it to us when I asked, and said, “Yeah, this is what happened, but no one was at risk, you know, everyone was safe.” But I mean, it's not a good look for the community, right? I mean, it's nice that they have something like Franklin going on, but this is kinda like, Great, thanks guys, you know. JESSICA (21:16) Right. If it was people coming from DEF CON, it's really discouraging to see this happening because a lot of times just “hacker” has a bad connotation. And a lot of researchers have really been trying to change this. I think programs like DEF CON Franklin make a big difference or even people just going to DEF CON. I really like the community feel. I think for the most part, and of course not everybody is good in the world, and that applies to the hacker community as well. But a lot of them are trying to use their skills for good and not evil. And so then when you see something like this on the airplane, it's disheartening. And on social media, I mean the outrage was pretty immediate, people saying, Come on, what are we doing? You're giving all of us a bad name here. Why are we doing this? So Brandon (22:15) Mm-hmm. I mean, it's already I feel like the joke every year is, well, didn't DEF CON get cancelled, right? Like because of all the bad press and everything. And I feel like this is one of those things that you're just like, you know, I remember a couple of years ago there was the huge kerfuffle about the hotels, you know, treating all these attendees like they were criminals right off the bat. And this doesn't help, you know? JESSICA (22:35) Right. Brandon (22:35) But yeah, hopefully I mean apparently the FBI I think spoke to Ars Technica and said that they had not made any arrests. So this hasn't really necessarily progressed toward that. But my hope is that whoever was responsible, you know, gets what's coming to them and we can, as a cybersecurity community, walk away from this and be like, this is one bad actor, not the entire culture. JESSICA (22:59) Right. Brandon (23:00) They fought for years to change that. So I guess before we wrap up, you know, this was a pretty doom and gloom recap of DEF CON and Black Hat, right? JESSICA (23:09) Ha ha ha. Brandon (23:11) All this AI's gonna end the world, our OT and our infrastructure's gonna be destroyed. Anything, you know, less miserable that grabbed your attention while you were there? Any fun stories or interesting things you saw? JESSICA (23:26) I mean, it was really fun. Again, I'm not quite sure if this falls in the not-doom and gloom category, but it was fun for me to watch hackers hacking bomb robots that the police used and bomb squads used to defuse bombs. So that was fun. You're walking around to the different villages and seeing people helping each other out and getting really into all of these different villages and all the different tasks. or you know competing for the best tinfoil hat or beard and mustache. So that was fun. Brandon (24:12) Was anyone doing the beer chill? When I was there in twenty twenty four, there was a group who was trying to chill beer as quickly as possible. JESSICA (24:19) I did not see that. It's very possible. I mean, to be fair, I did not see every single thing. There's so much to see so it's very possible. I missed that though, unfortunately, if that happened this year. So it's fun to see what people are doing. It's really fun and inspiring to see the creativity. And it's fun for me too to hear about some of the startups and how they are using AI and they're using it for different security use cases and hopefully that continues to improve and increase and hopefully that does give defenders an edge. So I think there's always a bit of a silver lining. It's always this cat and mouse race, but hopefully the defenders win out. Brandon (25:11) Yeah, it's a constant like you said. It's an arms race; it's constantly evolving. But like you said, it is encouraging to see, attention being paid to this, effort being put in to help defenders use these tools for good and not evil, even if some people turn around and make a bad name for everybody else on the way out the door. Either way, you know, it's gonna be something that we're probably gonna be discussing again, right? Like I thought this was gonna be a less AI heavy conversation, but it wasn't. JESSICA (25:36) No. Brandon (25:39) You know, it'll be a topic of conversation for years to come and we will be here on the Kettle to talk about it. Thanks for joining me this week and thanks for tuning in, everybody.

  •  

Part didn't fit so techie got out his screwdriver. Then something flew off the motherboard

WHO, ME? Is it a mistake to return to work on Monday? While you ponder that question, pause a minute to read this installment of "Who, Me?" – The Register's week-opening column that shares your stories of workplace errors and escapes. This week, meet a reader we'll Regomize as "James," who told us that in the early 2000s he worked in the biology department of a famous American university. "We custom-built all our PCs from the cheapest available parts at the time we ordered," James wrote. Which was how he found himself struggling to attach a heatsink to a CPU destined for use in a new PC. "The stupid hook wouldn't go over the plastic tab and so the heatsink didn't want to stay on," he wrote. "Not one to let a computer component get the better of me, I grabbed a flathead screwdriver, stuck it into the little leverage point in the heatsink clamp's arm and leveraged the hell out of it." The result of that decision was audible. "It went PING! and a tiny piece of something went flying away, but the heatsink was now securely mounted," James told The Register. He therefore connected the PC to power, turned it on, and… wondered why its fans blew up a storm, but nothing appeared on screen. "I removed the CPU, removed heatsink, and took a closer look to find the source for the PING. And there it was, or rather wasn't – a very tiny and apparently very important surface-mounted component of some sort was missing right next to where the metal clamps for the heatsink hook in." James was very clearly at fault, but decided the way to fix the problem was to fib about it. "I played dumb and called it into tech support at the company we ordered the heatsink from," he confessed. "They were very nice, accepted the part was dead on arrival, and sent me a replacement right away." "Needless to say I was much more careful with the replacement, which worked great," James told Who, Me? What have you broken with a screwdriver? And how did you get away with it? Click here to share your story with The Register. If you want us to use your story in a future Who, Me? we suggest using a keyboard and mouse – not a screwdriver. ®

  •  

Linux 7.2 debuts, Linus Torvalds says ‘new normal’ means he had to do it now ... or never?

Linus Torvalds has decided version 7.2 of the Linux kernel is ready for release, albeit in a “new normal” state that he seems not to entirely love. The kernel boss announced the debut of a new kernel in his weekly development status update, which on August 16 opened with the observation that “this last week of the release was – once again – bigger than I would have wished for.” He attributed that uncomfortable size to what he last week described as “the new normal” for the kernel at a time when developers have increased the volume of contributions using AI coding tools. “If I delayed releases for that reason we'd probably never have a release at all,” Torvalds wrote, before adding that the release includes “a number of fairly late reverts - the drm scheduling reverts stand out, but there's a few other ones in here too.” “It may not be pretty, but it's the correct way to deal with ‘Oh, that code wasn't ready and caused problems,’” he wrote. As ever, the new kernel release includes important and seemingly frivolous inclusions. Among the latter is support for a gaming controller called the “Zenaim Leverless,” which offers a collection of buttons on a black slab. Apparently e-sports pros think it’s just the sort of thing they need to rack up high scores or crush their foes during tournaments. And now they can use it with Linux! Perhaps more relevant to a majority of Reg readers is the inclusion of a tech called “Cache Aware Scheduling” that makes the kernel better at handling the data stored in caches across manycore chips like AMD’s EPYC 5 and Intel’s Xeon 6. Qualcomm senior engineer Vishnu Santhosh wrote a good explainer about the tech. Long story short, it’s about making processors aware of useful data already in a cache, so they can use it instead of doing extra work to access the relevant data. The release also includes work that makes it possible to run Linux on Apple M3 devices, the usual handful of graphics updates, and work to ensure that the kernel will be ready to support next-gen chips from AMD, Intel, and Nvidia. Notable deprecations include ending support for AppleTalk, and for old-school ISA and PCMCIA adapters used on ARCNet networks. This hits hard because The Register believes that PCMCIA stands for People Can’t Memorize Computer Industry Acronyms, and not for the Personal Computer Memory Card International Association. ®

  •  

A Rosier Future for Linux Gamers? Epic Games Announces Linux Version of Its Storefront

"Epic Games has confirmed that it is working on a Linux version of its storefront, potentially removing the need for third-party launchers on platforms such as Steam Deck," reports PC Guide: The confirmation came during an Ask Me Anything (AMA) on the Epic Games Store's community Discord server. When a user asked whether Epic had any plans for a Linux version of its launcher, an Epic staff member confirmed that it is coming "soon(TM)" in emoji form. Of course, that is far from confirming any kind of date, but it is official confirmation of a Linux version nonetheless. "On top of that, Nvidia's GeForce Now [cloud gaming] app for Linux is also official, having emerged from beta," writes TechRadar, calling it all part of "a rosier future for Linux gamers." And while it's not related to gaming, OpenAI's ["preview"] release of a ChatGPT app for Linux is another milestone for the platform... OpenAI said: "Linux has been one of the most-requested platforms for the desktop app, and this launch extends ChatGPT and Codex across every major desktop operating system." The Epic Games Store arriving natively is great news for gamers running Linux — including SteamOS — as it means a much more convenient way of playing games from the store, as opposed to the current situation with fudging and workarounds (using a third-party app such as the Heroic Games Launcher)... Epic's own Fortnite doesn't work on Linux (and that's down to Epic actively blocking the game from running due to issues around cheating, which remains a source of controversy). Given the apparent changing attitude here with its launcher being ported over, maybe Epic will reverse course on Fortnite eventually. Some gamers on Reddit are highly skeptical about that possibility though, and as one doubting Redditor put it: "I wouldn't hold my breath."

Read more of this story at Slashdot.

  •  

Khrys’presso du lundi 17 août 2026

Comme chaque lundi, un coup d’œil dans le rétroviseur pour découvrir les informations que vous avez peut-être ratées la semaine dernière.


Tous les liens listés ci-dessous sont a priori accessibles librement. Si ce n’est pas le cas, pensez à activer votre bloqueur de javascript favori ou à passer en “mode lecture” (Firefox) ;-)

Brave New World

Le rapport de la semaine

Spécial IA

Spécial Israël

Spécial femmes dans le monde

Spécial France

Spécial femmes en France

RIP

Spécial emmerdeurs irresponsables gérant comme des pieds (et à la néolibérale)

Spécial recul des droits et libertés, violences policières, montée de l’extrême-droite…

Spécial résistances

Spécial outils de résistance

Spécial MAGAM et cie

Les autres lectures de la semaine

Les BDs/graphiques/photos de la semaine

Les vidéos/podcasts de la semaine

Les trucs chouettes de la semaine

Retrouvez les revues de web précédentes dans la catégorie Libre Veille du Framablog.

Les articles, commentaires et autres images qui composent ces « Khrys’presso » n’engagent que moi (Khrys).

  •  

Microsoft blames AI for delayed Exchange update, can’t say when it will arrive

Microsoft has blamed extra work created by AI bug-finders for the delayed release of a major Cumulative Update to Exchange Server Subscription Edition (SE). Redmond’s Exchange team made that admission last Thursday in a post titled “Where is Exchange SE CU1 anyway?” that reveals the software giant is “getting questions from our customers on when they can expect us to release Exchange SE Cumulative Update 1 (CU1).” “After all, in the past we mentioned that it would be released by the end of the first half of calendar year 2026, later updated to ‘second half of 2026’. What is the deal? Where is CU1?” For those of you who came in late, Exchange SE is the subscription version of Microsoft’s email server, and a Cumulative Update (CU) is a new version of the package that includes all recent bug fixes, plus other changes such as new features or removing deprecated code. Microsoft publishes CUs once or twice a year. Some users prefer applying CUs to applying every patch. As Exchange SE is a subscription product, not getting CU in a timely fashion isn’t a great example of why pay-as-you-go software is a great idea. Microsoft explained delays to the arrival of CU1 by referring to the fact that “Over the last few months, various Microsoft execs made statements explaining how Microsoft is leveraging a variety of AI tools to help find vulnerabilities in our products.” The post says the Exchange development team is “working through reported issues – which includes validation that they are real security issues, reproducing, fixing, testing for regressions / issues after fixes are deployed and releasing updates monthly.” Redmond’s missive also points to Microsoft’s pledge to “prioritize security above all else” as a reason for delays. A reminder: Microsoft adopted that stance after flaws in Exchange led to an attack on Exchange by suspected Chinese operatives, earning it a tongue-lashing from the US government. The Exchange team says that while trying to stay on top of bugs, it is also working on CU1. “We are regularly rolling our monthly security payload into our internal CU1 build and plan to release Exchange SE CU1 as soon as we get a reasonable stable point and have a month without pressing security payload.” The Exchange team has adopted that stance because it doesn’t want to publish CU1 and then find it needs to replace it with another that includes new security updates. “That would create double the update work for many organization administrators,” the post explains. “Even internally, trying to ensure that two major releases (Security Update and a CU) get appropriately tested so we can ensure high quality and nothing falls through the cracks would be very challenging as CU1 must be all inclusive of everything that we released since the RTM.” Exchange admins will likely appreciate the fact that Microsoft doesn’t want to burden them with two major updates to implement. They may also wonder when Microsoft will find a month in which there is no “pressing security payload” that takes priority over CU1. Microsoft’s post offers little certainty because it concludes: “In short: Exchange SE CU1 is coming; we do not have a date to give you. But we did not forget about it.” Nor, it seems, did Microsoft plan for how AI-powered bug-finding would impact product development teams. ®

  •  

Chinese AI company Zhipu claims its new model is a better bug-finder than Anthropic, OpenAI

ASIA IN BRIEF Chinese company Zhipu last week launched a new AI model called GLM-5.3 that it claims has bug-finding powers that match those possessed by American models. The company’s announcement includes benchmark data that finds GLM-5.3 beats Fable 5 and GPT-5.6 Sol on the CyberGym benchmark, a test of a model’s ability to solve real-world cybersecurity challenges. “As we scaled post-training, cyber capability developed faster than we expected. GLM-5.3 is state of the art on CyberGym for vulnerability discovery, and its gains are largest further up the exploitation chain,” the company wrote, adding that the model “did not simply become better at identifying isolated flaws: it began to reason across multiple stages of exploitation, forming coherent plans for complete exploitation chains.” The company said it has worked with Chinese companies to test the model on real-world codebases, and found 2,436 vulnerabilities across 269 projects, including 1,097 medium-to-high severity issues. The findings span system kernels, operating systems, browser engines, open-source infrastructure, web applications, and network protocols. “Many had remained unnoticed for years or even decades, with the oldest dating back roughly 40 years,” the announcement states. GLM-5.3 also performed worse than western models on other security and coding benchmarks. Yet the fact that the model is a highly-capable bug finder signals that China is not far behind in terms of being able to poke holes in its rivals software and developed that capability very quickly after the debut of Anthropic’s Mythos. Any advantage the US felt it had as the home of Anthropic has therefore dissipated. Korea signals legal action against Apple, Google app store strangleholds South Korea’s Communications Commission last week found Google and Apple had abused their app store monopolies, and promised stern sanctions will follow. In 2021, South Korea passed world-first legislation requiring app store operators to offer the option to use third-party payment schemes. Apple and Google did so, but charged a 26 percent transaction fee for doing so – meaning they earned almost as much revenue when users chose third-party payment providers as they did from their own schemes. The regulator has previously warned that it will impose the highest possible penalty available under law, which is three percent of revenue earned by non-compliant behaviour. That’s probably back-of-the-sofa money for Apple and Google. India has banned rideshare operators from offering customers the chance to specify the amount they will tip before a driver accepts a gig. Uber India introduced the feature last year, seemingly copying it from an Indian rideshare operator called Namma Yatri. Consumer affairs minister Pralhad Joshi criticized Uber for the practice at the time, as he saw it as a means for users to effectively jump the queue by offering drivers more money – and for rideshare platforms to improve their revenue because if tips are higher, so is the platform’s share of the gratuity. Last week, India’s Ministry of Road Transport & Highways issued a directive (PDF) banning the practice. Henceforth, rideshare apps can only offer users the chance to tip at the end of a journey, and all of the tip must go to the driver. “No feature, prompt, message, add-on, payment option, or user interface element should be displayed before completion of the ride that directly or indirectly encourages, induces, or creates an impression that payment of any additional amount may improve ride confirmation, driver acceptance, driver allocation, waiting time, or quality of service,” the directive states. Indian services giants reveal data breaches Indian tech services giants TCS and HCL last week both admitted to data breaches but say customer data is safe, and only employee data is at risk. TCS published a stock exchange filing that opens “This is to inform you that Company has received threat-intelligence alerts alleging possible exposure of certain employee information.” The filing says TCS investigated the matter “and has not found any credible evidence of a breach of TCS systems or customer environments.” The company says leaked info is “basic employee information” and more than four years old. Note that mention of the stolen data being at least for years old, because TCS’s filing says the attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue to pull off the heist. TCS says it “had strong safeguards in place against such techniques for more than two years,” perhaps suggesting the data heist occurred before the company shored up its defenses. “Based on the current review, these controls remain effective, and the Company continues to monitor the environment closely,” the filing states. HCL also used a stock exchange filing [PDF] to address what it called “claims made by a hacker group of potential exposure of limited data elements relating to HCLTech employees.” The company described the stolen data as “limited and dated to a few years back,” and added its assurance that customer data is safe. HCL’s investigation is ongoing. Lenovo’s enterprise unit finally posts a big profit Lenovo last week announced its quarterly results, including a $777 million profit for its Infrastructure Solutions Group (ISG) – the biz based on the 2014 acquisition of IBM’s x86 server operation that has seldom produced positive financials. Even during the early years of the AI boom, ISG’s profits were modest – just a few million dollars per quarter on turnover of billions. The business unit won a record $8.5 billion of revenue, up 98 percent year-on-year. AI was a big reason for the result, as buyers sought hardware to run inferencing workloads, The company says it has a pipeline for $54 billion of AI server sales, and has become the number two x86 server vendor as measured by revenue. Overall revenue came in at $26.95 billion, up 43 percent year-on-year, and cash won by its PC-led intelligent devices group jumped 27 percent to $17.1 billion and saw its PC market share reach 24.2 percent. Lenovo reckons the strength of its supply chain helped make those outcomes possible. India to build astronaut training facility India’s Space Research Organization (ISRO) last week issued a tender for construction of an astronaut training facility. The tender mentions extensive air conditioning works, plus a swimming pool, suggesting India wants to build a large tank in which the Vyomanauts who will fly its future Gaganyaan missions can train at home, instead of traveling to Russia or elsewhere as has been the case in the past. The tender covers $2.75 million worth of work. ®

  •  

Bipartisan 'Uprising' Against Flock Cameras: a Larger Fight Against Big Tech and Surveillance?

Politico notes that over 20 local jurisdictions in America "either stopped using Flock cameras or began the process of doing so in July, according to a tracker maintained by DeFlock, an activist group that has been mapping the company. It's the highest amount in a single month since they began tracking in 2021." Some local officials said the public safety promises weren't worth the cost. The cameras "didn't help us with anything. From a utility aspect, they were just kind of not useful," said Eric Couture, a Democratic first selectman in Killingworth, Connecticut, another city that recently canceled its contract with Flock. "I'd say it was a net negative." And their article adds that it's a bipartisan pushback that "runs parallel to sprawling fights over the future of technology in American life, including the rise of increasingly advanced artificial intelligence tools and the construction of massive data centers needed to power them." Salon even argues Flock's cameras "have become a symbol of growing anger over the efforts by technology oligarchs to impose their dystopian fantasies on the country, replacing liberal democracy with a surveillance state... People are sick of tech billionaires trying to control our lives"" By targeting Flock cameras, activists are building momentum for a larger rebellion against the tech industry — and against political leaders who are complicit in their assault on our freedoms. Flock Safety embodies the dishonesty that has been the prevailing theme of tech corporate communications and marketing for at least the past decade. While the cameras are sold to the public as a banal traffic safety measure, they have prompted an outpouring of stories about how they're being used to violate civil liberties and undermine democracy... According to an exhaustive 10-month analysis by Electronic Foundation Frontier, a nonprofit dedicated to defending civil liberties in our digital age, local police were using the cameras to track protesters, such as those at No Kings rallies, who were then put in a national database to be used across all jurisdictions. Despite claims that the cameras only record license plates, the technology-focused outlet 404 Media found that the database is also being used to collect information on individual people whom cops can then search for using descriptions of clothing, race, gender and body type. The Flock uprising, though, is the stirrings of public understanding that none of this inevitable — and we have the right to fight back... Along with protests against data centers, it's a sign that the public is desperate for a way to fight back against not just AI, but also the anti-democratic forces fueling this latest tech wave. Salon's writer also adds that "what stands out about the burgeoning public rebellion against Flock security cameras is just how fun it all is," citing "a national cat-and-mouse game between vandals and cops that is being merrily followed on social media, mostly by people rooting for the vandals." City council meetings in which citizens swarm to protest paying for the cameras are the new must-see TV. In Huntington, West Virginia, a small city in the heart of Appalachia, one man became an internet folk hero when he stood up at a city council meeting and said, "I'm not gonna waste your time; I'm kinda hungry. But one last thing: Every single Flock camera has about 2-3 pounds of copper and about 1-2 grams of gold. Do with that information what you will." He then walked off in triumph.

Read more of this story at Slashdot.

  •  

Anthropic Criticized For Adding Watermarks to Text that Claude Generates - or Processes

This week Anthropic announced its Claude chatbot will watermark the text it generates, reports the blog Futurism. "It works by making subtle changes in the AI's word choices across the text it generates, which are supposed to be imperceptible to a human but, in aggregate, form a pattern that is detectable with the tool." Anthropic said it was implementing the watermark system in response to the European Union's landmark AI Act passed in 2024, which requires that AI companies mark content that's been generated or edited by their systems. TechCrunch notes that other companies including Google, Meta, Microsoft, OpenAI, and Synthesia have committed to adhering to the EU's code. But "The news about Claude watermarking kicked off a firestorm on X," reports Forbes, "with users panicking that AI-assisted writing will now bear a kind of permanent 'scarlet letter.'" (Forbes wonders if media companies are normalizing AI "while at the same time stigmatizing the output.") But there's another issue. Anthropic said the watermark indicates Claude processed text, Business Insider points out, "not that it was necessarily the original author. The company said marks can remain after Claude proofreads, translates, summarizes, or otherwise edits content... a watermark shows that Claude processed text, not necessarily that it wrote it." In the days since, "Dozens of people have posted on X since Monday that they had canceled their Claude subscriptions, citing the watermark." Vladislav Rajtmajer, a freelance developer in the Czech Republic, told Business Insider he canceled his Claude Max subscription on Tuesday, citing the watermark as the main reason. He said he uses AI for code reviews and translations, and worried an AI label on code shipped to clients could raise questions about authorship or trigger contract penalties... Richard Echols, an AI consultant in Georgia, also said he canceled his Claude Max subscription on Wednesday and that the watermark was a major factor in his decision. He said he uses Claude to create documentation for businesses and worried the mark could appear when he had written the underlying material himself and used the chatbot only for edits. "Even if you edit your own work that you wrote, they add the watermark anyway," Echols said... Anthropic isn't the only AI lab to use watermarks: Google uses its SynthID technology to watermark AI-generated content, and OpenAI uses SynthID for supported images and audio. Elon Musk's social media platform X also adds a "Made with AI" tag on content it determines to be AI-generated or manipulated. Long-time Slashdot reader kmleon (also a tech consultant and RPG researcher) experienced another issue. He'd built some software using their own custom-built AI tool, only asking Claude to do some testing. "Little did I know that Claude would sometimes decide, since it was involved on the edges... to take credit for all of my work, claiming some parts were either '100%' or 'Co-Authored/Created' by Claude.Ai / Claude Code!" I'm sure the good folks at Anthropic will eventually tweak Claude enough to, hopefully, not make these mistakes in the future.... I only became aware of it today, because I recently setup scanners to catch Claude incorrectly watermarking any content it touches for various projects I'm working on. I found that it has (apparently as far back as Sonnet 4.6, but as recently as today, August 14th, 2026) sometimes been mistakenly over-zealous in taking credit for 100% creating or co-authoring docs, code, images, videos, etc. I've only, so far, found about a dozen instances spanning the past year, and most of them appear to have been injected in the last few weeks, so it is not a common issue (yet). On the bright side? Maybe watermarks can help AI stop training on AI-generated text. Although Forbes also reports that Google "announced on Friday that it will now let users remove the visible watermark from AI-generated images, videos and music created with several of its models."

Read more of this story at Slashdot.

  •  

Linux Kernel 7.2 Has Been Officially Released with Many New Features

Linux Kernel 7.2 has just been officially released with a slew of new features, reports the blog 9to5Linux. Highlights of Linux 7.2 "include cache-aware load-balancing support, initial HDMI 2.1 FRL support to the AMDGPU driver, support for devres-based management of ACPI notify handlers, initial CRI platform support for the Intel Xe driver, and Rust support for the IBM System/390 (S/390) architecture." Linux kernel 7.2 also introduces a "Fair(er)" GPU scheduler, support for the 'zerocopy' library to Rust support to make zero-cost memory manipulation effortless, new hwcaps for the 2025 dpISA extensions on the AArch64 (ARM64) architecture, and enables large folios by default for the Btrfs file system. It also brings Intel CPU model number support for Panther Lake R processor series, improvements to the kernel's swap subsystem, support for multi-size transparent huge pages (mTHPs) to the khugepaged kernel thread, and support for compressed files to the SMB filesystem. On top of that, Linux 7.2 improves the new NTFS filesystem introduced in Linux kernel 7.1, adds devicetree updates for 64-bit NXP/Freescale and Qualcomm platforms, introduces MPTCP signaling support for IPv6 addresses, adds GRO/GSO support for PPPoE, and brings more SMP load-balancing updates... [T]he TCP authentication option has been implemented, and there are also some Thunderbolt networking improvements. Also worth mentioning is that the KVM subsystem has received support for AMD's "guest-mode execution trap" and Intel's "mode-based execution control" (MBEC) features, the NFS file system's default block size was bumped to 4MB on systems with at least 16GB RAM, and support for the Intel Trusted Domain Extensions (TDX) feature has been added. Thanks to Slashdot reader prisoninmate for bring the news.

Read more of this story at Slashdot.

  •  

China's Moon-landing Plans And Why the US Is So Worried

"We are in a 21st century space race," U.S. Senator Ted Cruz has said. And this week CNN noted a competition that for decades loomed in the background of geopolitics "is now roaring to the forefront," with China "demonstrating rapid advances in space technology" while the U.S. is "ratcheting up rhetoric about a looming battle for control of the cosmos." It's the fact that China plans to build a permanent settlement on the moon by 2040 that has prompted an urgent response from [U.S.] lawmakers... They've declared a new space race, and NASA is pledging to build a lunar outpost of America's own.... Both the United States and China plan to send robotic explorers to the south pole later this year, paving the way for human explorers to follow close behind. The US is relying on the private sector to develop and build low-cost, exploratory robotic landers... Meanwhile, China is aiming to launch its robotic Chang'e-7 mission as soon as this month. The complex endeavor will seek to use four different robotic vehicles — an orbiter, lander, rover and mobile "hopper" — working in tandem to attempt to gather unprecedented data. The effort will include tools to drill for and directly analyze water ice, a feat that the US will only attempt with robotic missions slated for next year at the earliest. "If lunar water ice is successfully located, it could significantly reduce the cost and time required to transport water from Earth, facilitating the establishment of a human base for long-term activities on the moon and enabling further exploration of Mars or deep space," Tang Yuhua, the deputy chief designer of the Chang'e-7 mission, said in a 2025 interview with state media. The oncoming flurry of south-pole-centric activity, with few established international laws to govern the outcomes, is heightening the drama of this rivalry... But with a much more ambitious goal — a future in which people attempt to flourish within permanent settlements rather than just visit the moon — the stakes of this new space race are even higher, according to Clayton Swope, the deputy director of the Aerospace Security Project at the Center for Strategic and International Studies, a bipartisan nonprofit. "The long-term vision will take generations to execute on," Swope said. "But in my mind, it's a scenario where there are people being born, people dying, their families, children growing up in a place that is not Earth — so that looks a lot like a city, more than it looks like an expedition to the south pole." If such a future comes to fruition, Swope added, his hope is that such extraterrestrial colonies would be governed by rules reminiscent of Western ideals and democratic principles. Whether China would be on the same page is an open question. China is already fine-tuning its plans for a lunar settlement, CNN writes: The country envisions the International Lunar Research Station, or ILRS, as a sprawling science-focused facility on the moon's surface that can be operated robotically, "with the prospect of subsequent human presence," according to a government's ILRS website. China could partner with Russia to build a massive nuclear reactor to power the base, though questions remain regarding how the war in Ukraine may impact Russia's ability to deliver... China and Russia were mapping these plans long before the US announced its own intention to build a nuclear reactor on the moon last year and detailed its plans for a lunar settlement spanning hundreds of square miles... Who will write the rules? And how, exactly, will the use of lunar resources be policed on the international stage? Meanwhile, NASA "still does not have a vehicle capable of getting astronauts down to the lunar surface," the article points out: Returning to the moon is not as simple as repeating Apollo. The space agency cannot — and does not wish to — replicate its 20th century lunar-landing success. The supply chains, skilled machinists and factories that built Apollo's rockets, landers and command modules no longer exist. And while the Apollo landings stuck close to the lunar equator, landing near the south pole is substantially more complex and requires more powerful vehicles.... China, meanwhile, has been laser focused on its lunar exploration program since 2004, using its top-down, central planning system to keep resources flowing toward specific goals.

Read more of this story at Slashdot.

  •  
❌