Terminal
-
Waymo CEO Explains Why Camera-Only Self-Driving Falls Short
Longtime Slashdot reader AmiMoJo shares a report from Electrek: Waymo co-CEO Dmitri Dolgov laid out the clearest technical case yet for why cameras alone can't take a self-driving system to full autonomy, arguing that "weak sensing" hits a safety ceiling long before it reaches superhuman performance. [...] Dolgov made the comments in a talk at Y Combinator's Startup School, walking through the les…
-
Rust Coreutils 0.10 Released With More Security Hardening, Increased GNU Compatibility
Rust Coreutils 0.10 is out today from the uutils project for this alternative to GNU Coreutils. Rust Coreutils 0.10 development focused on additional security hardening plus also increasing the GNU test suite compatibility and robustness...…
-
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Thousands of Internet-connected servers sold by the world’s biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities—some more than a decade old—that lurk deep inside system motherboards, according to research presented Wednesday. Baseboard management controllers are miniature computers that are embedded into the motherboards of virtually every enterprise server. Th…
-
Mesa 26.2 Released With NVK Mesh Shader Support, Many Other Vulkan Improvements
Mesa 26.2 stable is now available as the newest quarterly feature release for this set of open-source OpenGL and Vulkan drivers typically used on Linux systems...…
-
Anthropic's AI Used Fake Identities, Malware In Rogue Attack On GitHub Project
An anonymous reader quotes a report from Ars Technica: Routine cybersecurity testing of frontier AI models sparked a series of unexpected security incidents -- the most serious case arising when Anthropic's Mythos 5 model attempted to insert malicious code into an open source software application and created fake identities to deceive the human developers maintaining the project. The security inci…
-
Prompt injection isn't the bug, AI agent frameworks are
Nearly a dozen flaws, some critical, in major AI agent frameworks that enterprises use to build apps reveal a security failure that extends beyond prompt injection - or any single model - according to Check Point researchers. “Our research shows a deeper failure: in many agentic frameworks, prompt-controlled content can cross the boundary into trusted framework logic itself,” Yarden Porat and Sha…
-
The title cards in Blade Runner are amazing
-
USB4STREAM Adding Busy Poll Option For Lower Latency At The Cost Of Increased CPU Cycles
One of the nifty new features of Linux 7.2 is USB4STREAM as an Intel-developed solution for quickly sending data between USB4 connected systems. Now for the upcoming Linux 7.3 cycle, a busy poll mode is being added to provide lower-latency data transfers at the expense of increased CPU activity...…
-
NVIDIA’s Vera Whitepaper Has a Thread Loose
-
Prime Agent: A self-improving RLM agent
-
Schwartz confirmed as CDC director after bungling confirmation hearing
In a 51–44 vote Wednesday, the US Senate confirmed Erica Schwartz as director of the Centers for Disease Control and Prevention, despite failing miserably to convince senators last month that she could stand up to anti-vaccine Health Secretary Robert F. Kennedy Jr. The confirmation ends a near yearlong vacancy for the position since Kennedy fired the previous CDC director, Susan Monarez, last Aug…
-
Time Magazine has a separate version of its website with ads only AI can see
AI webpage crawlers are now being served their very own ads that ordinary visitors never see, with one firm's boss openly describing a strategy to influence what chatbots say about brands. The next time you ask Claude about where to bank, its answer may have been influenced by this bot-targeted content. We only have one documented example so far, and that's Time serving AI-only ads to selected AI…
-
Meta Debuts First AI Coding Agent To Take On Anthropic and OpenAI
Meta has launched Muse Code, its first AI coding agent that's positioned as a lower-cost rival to Anthropic's Claude and OpenAI's Codex. It offers pay-as-you-go pricing and an optional zero-data-retention feature for enterprise users. CNBC reports: Muse Code is the latest major release from AI chief Alexandr Wang, who leads Meta Superintelligence Labs and oversees foundation model development. Wan…
-
Anthropic’s AI used fake identities, malware in rogue attack on GitHub project
Routine cybersecurity testing of frontier AI models sparked a series of unexpected security incidents—the most serious case arising when Anthropic’s Mythos 5 model attempted to insert malicious code into an open source software application and created fake identities to deceive the human developers maintaining the project. The security incidents occurred during a cyber evaluation of seven leading…
-
Reddit signals ominous upcoming "changes” for old.reddit.com
Old.reddit.com’s days appear to be numbered. Reddit has strayed from saying that it will shutter the website, which many long-time Redditors prefer for its layout, navigation, and fewer feed recommendations. In a blog post today, Reddit made a vague statement about upcoming “changes” to Old Reddit:Read full article Comments…
-
Apple's 'Private Relay' Is Exposing Users' Real IP Addresses
Security researchers found that Apple's iCloud Private Relay can expose users' real IP addresses because some passkey-related requests bypass Safari and its proxy protections at the operating-system level. "In short: any website that supports, or pretends to support, passkeys can see the user's real IP address despite having iCloud Private Relay on," security researcher Tommy Mysk, who discovered…
-
Hank Green found the AI problem that YouTube labels can’t catch
YouTube currently requires that content creators let viewers know "when they use AI to meaningfully alter or generate photorealistic content." The policy draws some strange boundaries. It applies to "AI-generated music" (not photorealistic) but not to "riding a unicorn through a fantastical world" (this could be photorealistic, though it is not plausible). YouTube then summarizes the policy in a…
-
I'm switching my phone from Android to Linux
-
Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
-
SpaceX claims Starlink Mobile will be better than AT&T, T-Mobile, and Verizon
SpaceX says it has a plan for Starlink Mobile to compete against the big three wireless carriers and take a large number of customers away from them. SpaceX has so far partnered with traditional mobile carriers to supplement their ground-based networks with Starlink satellite capacity, mainly to ensure coverage from space in dead zones not reached by cell towers. But SpaceX is buying spectrum lic…
-
This Atlantic hurricane season is looking like a dud, but there will be a price to pay
The city of Houston, where I live, has been ground zero for the 2026 Atlantic hurricane season. So far this year there have been two named storms, Arthur and Bertha, that have formed. And the centers of both have passed near or directly over Houston. Two "strikes" in a year might seem notable, but like the middling hurricane season to date, Arthur and Bertha were both middle-of-the road tropical…
-
Muse Code and Muse Spark 1.2
-
Google's AI shake-up: DeepMind's Hassabis steps aside, senior scientists depart
Google got a slow start with generative AI after seemingly being caught flat-footed by Microsoft's Copilot reveal. What a difference a few years make. Now, Google is at the forefront of AI development (for better or worse), but new cracks are beginning to show. The company's string of high-profile personnel departures continues, and DeepMind CEO Demis Hassabis has now said he will hand off day-to…
-
Lawmaker Who Wants Data Center Pause Wins Kansas Democratic Primary
Kansas Democrats nominated State Senator Cindy Holscher for governor after she defeated party-backed rival Ethan Corson. "The race became a test of what sort of candidate Democratic voters prefer in what is expected to be a challenging general election race: a more moderate candidate like Mr. Corson with endorsements from party leaders or an outspoken populist like Ms. Holscher, who spoke out agai…
-
Sula: A Gemini protocol server written in Scryer Prolog
-
Zed DeltaDB
-
What happens if you put work into the second dimension?
-
Review: Spider-Man: Brand New Day reminds us that superhero movies can be good
Over the past few years, it has become a rather rare treat when I end up genuinely, unequivocally enjoying the latest superhero film. Mostly I find them to be middling entertainment, sometimes a bit dull—and for The Eternals, nearly unwatchable—with the notable exception of 2024's Deadpool & Wolverine and last year's Thunderbolts*. Add Spider-Man: Brand New Day to that list of exceptions. Tom Hol…
-
Beating GPT-5.6 Sol on retrieval with 100x cheaper open models
-
Weeks into explosive diarrhea outbreak, sluggish CDC plans response team
The Trump administration continues to respond sluggishly to the explosive, nationwide outbreak of Cyclospora—a unicellular parasite spread from human feces that has now sickened nearly 23,000 people in 47 states, killing two and sending over 500 to the hospital. Michigan health officials reported the two deaths Monday, and The Washington Post first reported Tuesday that federal health officials h…
-
Google Overhauls AI Leadership As DeepMind CEO Steps Aside
Google is reshuffling its AI leadership as Demis Hassabis steps away from day-to-day management of DeepMind to become chairman and Alphabet's chief scientist, while CTO Koray Kavukcuoglu takes operational control. Meanwhile, longtime chief scientist Jeff Dean and several prominent researchers are leaving to launch their own company. Axios reports: Hassabis will add the title of chief scientist for…
-
Elon pledges to give Nvidia a virtual monopoly over the stars
Nvidia commands about 85 percent of the datacenter GPU market today, and if Elon Musk has his way, the AI infrastructure giant will have a virtual monopoly over the stars. On Tuesday, Musk wrote on the social media network he owns that “SpaceX has committed to using Nvidia GPUs exclusively because they are the best.” The collab should surprise absolutely no one. It’s not like AMD or anyone else o…
-
b4 0.16.0 released
Konstantin Ryabitsev has announced the release of version 0.16.0 of the b4 software-development tool. The biggest change is the addition of bug-tracking support: The new "b4 bugs" command integrates with git-bug to let you track bug reports alongside your git repository. Bugs are stored as git objects inside the repo, so they travel with the code and can be shared via git push/pull without any ext…
-
Atlassian Rovo Exfiltrates Data, Bypassing Controls
-
Phishers are hijacking legitimate cloud infrastructure
-
After jacking up prices, Disney+ and Netflix consider offering free alternatives
Disney is “exploring a free product” for streaming customers, CEO Josh D’Amaro confirmed in a call with investors today. D’Amaro, who succeeded Bob Iger as Disney’s chief in March, said that a free Disney-owned streaming service would help Disney reach more “price-sensitive” customers, which is a “strategic priority” for Disney, according to a transcript of the call. A free streaming service woul…
-
EVgo starts building Tesla Superchargers under license
For most of its existence, the Tesla Supercharger network was both the automaker's crown jewel and a walled garden. Tightly integrated to work only with Tesla electric vehicles, the DC fast-charging experience for Tesla customers was painless in ways that EV drivers dependent on CCS1 chargers operated by a patchwork of networks could only dream of. Then, in 2023, Tesla began opening up the networ…
-
Cloudflare Announces Open-Source Cloudflare OS As AI 'Operating System'
Cloudflare has open-sourced Cloudflare OS, an Apache 2.0-licensed platform that lets organizations build AI agents, apps, and workflows using curated company data and tools within isolated, governed environments. Despite the name, it is not a traditional operating system but a framework for securely managing organizational AI workloads. Phoronix reports: Cloudflare OS is already used internally at…
-
[$] Examining other network namespaces using BPF
Jordan Rife's work involves writing BPF programs for Cilium that interface with Kubernetes networking. As part of that work, he wants to enable BPF programs with appropriate permissions to iterate through the sockets of a different network namespace. He led a session about the idea at the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit where the BPF developers in attendance were…
-
Celld: Self-hosted, distributed Durable Objects
-
Launch HN: HyperProbe (YC S26) – Agents that do read-only debugging in prod
-
IBM's agentic AI platform is under active attack - patch now
A critical vulnerability in IBM-owned, low-code AI builder Langflow lets unauthenticated attackers execute code remotely on vulnerable default deployments, potentially putting organizations running those instances at immediate risk. The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog after identifying evidence o…
-
D-Wave shows off its new entry in quantum computing race
D-Wave is a bit of an oddity in the quantum computing space, having been founded back in the last century. And its initial offering wasn't a quantum computer like those being developed by IBM or Google. Instead, the company built what's now called a quantum annealer, a machine that isn't general-purpose but can solve a large class of optimization problems. While the hardware shares some similarit…
-
Stop sending me your errors
-
Something is changing in the unit economics of software
-
Discovery Loop
-
Denial WM: New Wayland Compositor With Flutter Directly Embedded
The newest Wayland compositor to talk about and discuss is Denial, a Wayland compositor focused on optimal Arch Linux integration and that embeds the Flutter engine directly into the codebase. Denial makes use of the Rust programming language and leverages Smithay to help in the compositor responsibilities...…
-
Changes at Google DeepMind: Demis Hassabis from CEO to Chair, Jeff Dean departs
-
The Days of Walking Into a T-Mobile Store May Be Numbered
A leaked roadmap suggests T-Mobile plans to make its T-Life app the primary way customers manage their accounts by the end of 2026, "gradually moving one feature at a time into the app" and away from physical stores, reports Android Authority. That includes upgrades, new-line activations, and eventually new-account sign-ups. From the report: According to an image shared by a Reddit user, the carri…
-
[$] FUSE status and plans
Filesystem in Userspace (FUSE) maintainer Miklos Szeredi led a birds-of-a-feather (BoF) discussion about the subsystem at the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit. In it, he talked about maintenance challenges, proposed features and their status, and his plans for a new FUSE API. There is a lot of interest and activity in the FUSE community these days it seems.…
-
Samsung and Mousterian move ahead with floating datacenter for Texas
Plans for floating datacenters in the US have advanced beyond the handshake stage, with Samsung Heavy Industries and Mousterian Corporation signing an engineering contract. Dallas-based Mousterian, which describes itself quaintly as "a developer of water-adjacent datacenter infrastructure," says the contract covers its first project, planned for deployment in Texas. The pair intend to deliver fur…
-
Google plans to kill Assistant on your phone on September 4
Google Assistant's days have been numbered for a while, but the company has now settled on a date to retire its pre-AI assistant robot. In an email being sent out to users, Google confirms that Assistant on Android devices will be shut down starting on September 4, forcing everyone over to Gemini. Google told us it was coming, but that doesn't make it hurt any less. The initial plan was to retire…
-
The Valley of Webhooks
-
Microsoft tells engineers to curb their token-burning enthusiasm
Concerned about cost, Microsoft is reportedly warning employees against wasteful AI use. In an email seen by 404 Media, Microsoft Executive Vice President Jay Parikh warned that individual divisions would be given targets and could face restrictions. "Tokenmaxxing is not what we are optimizing for. I want all of us focused on maximizing outcomes that move the needle for our customers and our busi…
-
Senators Demand Crackdown On Wildfire 'Prediction Markets'
An anonymous reader quotes a report from Ars Technica: Several US senators have written a letter to the Commodity Futures Trading Commission (CFTC), inquiring about the agency's "plans to crack down on prediction markets" that offer "contracts for individuals to bet on wildfires." "Offering bets on destructive wildfires threatens to minimize communities' suffering, all so the rich and powerful can…
-
Operationalize AI at scale with HPE and NVIDIA
While many organizations have AI projects underway at various stages of maturity, most are experiencing challenges scaling AI across their IT landscape. That is because many AI strategists have yet to work out how to build, operate, and extract value from their AI infrastructure. Without a formal, top-level plan for AI, key capabilities and requirements get lost, and the full value of AI is never…
-
SpaceX revenue rockets while AI spending burns billions
SpaceX beat revenue forecasts in its first results as a public company, but surging AI expenditure and another quarterly loss left investors unimpressed. In unrelated but appropriately-timed space news, a discarded SpaceX rocket body is believed to have struck the Moon this morning. SpaceX's figures show revenue rising sharply across its two main segments. For the quarter ended June 30, total rev…
-
Aristotle quotes on virtue, knowledge, and happiness
-
Rubin Observatory's first LSST Camera release: 500k galaxies in the COSMOS field
-
The Entropy of a Markov Chain
-
SpaceX spooks investors with debut earnings report
SpaceX shares dropped on Wednesday after Elon Musk’s plans for blockbuster spending to position his AI and rocket company as a data center developer spooked investors. SpaceX surpassed analysts’ expectations in Tuesday’s debut earnings report, posting quarterly revenues of $7.8 billion, well above analysts’ estimates of $6.82 billion and up 92 percent from a year earlier. It posted a net loss of…
-
Cloudflare OS: an open platform for agents, apps, and work
-
Building an Advanced Agentic Harness
-
Nelson: rust-lang/rust is adopting an LLM policy
Jynn Nelson describes the Rust language team's new LLM policy on the Inside Rust blog. No one except the author is required to read LLM output unless they choose to: LLM output isn't allowed in public docs, PR descriptions, or Github comments unless it's clearly marked; reviewers aren't required to look at LLM PRs if they don't want to. No one is required to use LLMs to contribute to rust-lang/rus…
-
Painting with Gaussians
-
London cops handed victim's new address and number to her stalker, watchdog says
UPDATED The UK's data protection regulator has criticized London's Metropolitan Police Service (MPS) after its officers handed a victim's stalker details about her new phone number and home address, among other failures. The Information Commissioner's Office (ICO) today issued the MPS with an enforcement notice [PDF] and a reprimand over the two incidents, which occurred in 2024. Enforcement noti…
-
Cloudflare Announces Open-Source Cloudflare OS As AI "Operating System"
Cloudflare today announced the open-sourcing of Cloudflare OS as an "open platform for agents, apps, and work." Cloudflare OS is an AI "operating system" but not in the traditional OS sense...…
-
Security updates for Wednesday
Security updates have been issued by AlmaLinux (fence-agents, gstreamer1-plugins-good, kernel, kernel-rt, p11-kit, perl-Archive-Tar, perl-DBI, and thunderbird), Debian (aom, botan3, and kernel), Fedora (abrt, coreutils, doctl, kernel, open62541, perl, perl-Devel-Cover, perl-PAR-Packer, and polymake), Mageia (acl and php), Oracle (firefox, frr, kernel, libreswan, nodejs-nodemon, nodejs22, perl-Arch…
-
Cloud startup Volta claims $10B AI lab deal for Norway bit barn
An AI cloud startup with backing from Nvidia and Michael Dell plans to open AI factories in Norway and elsewhere, targeting multiple gigawatts of capacity by 2030. Volta describes itself as a vertically integrated AI infrastructure business set up to finance, build, and operate AI factories. In other words, it is another rent-a-GPU "neocloud" operation like Nscale and CoreWeave, but one with some…
-
Linux To Avoid Confusing Processor Firmware With Newer Intel CPUs Sporting DEC
A patch for the Intel P-State CPU frequency scaling Linux driver is pending to avoid confusing the processor firmware on newer platforms like Intel Core Ultra Series 3 "Panther Lake" where Dynamic Efficiency Control (DEC) is supported...…
-
Voyager 2 cheats the power budget for another year
Engineers at NASA's Jet Propulsion Laboratory have eked out a little more life for instruments aboard the veteran Voyager 2 probe thanks to a power-saving effort called the "Big Bang." The procedure involved switching several powered devices at once, turning some off and replacing others with lower-power alternatives while keeping the spacecraft warm enough to function. We don't envy whoever had…
-
UK charities count the cost of Beacon CRM cyberattack
Beacon CRM has confirmed it was hit by a cyberattack that exposed data belonging to a growing list of UK charities. The company, which markets its software to charities and has more than 1,500 customers, said its investigation remains ongoing. However, it appears that a substantial amount of customer data was copied, and Beacon is warning users to assume everything they stored on the platform was…
-
Pushing the limits: Infinite Machine's Olto is barely a bicycle
The Infinite Machine Olto is a great electric scooter, one with an overall layout that echoes the classic Vespa. It's comfortable, and it accelerates well, handles nicely, and has a capacious battery. It has a rugged design that seems capable of handling a lot of abuse, but it also comes with thoughtful touches and security features that mean you can park it anywhere with confidence. And it provi…
-
NVMe Polishes Its Specs, Brings Virtualization to Locally Attached SSDs
The latest NVMe specifications add SSD-level virtualization that can simplify live VM migration by preserving storage identities across servers. The updates also introduce support for post-quantum cryptography, controller-based rate limiting, voltage monitoring, and factory-reset capabilities. The Register reports: Announced by the NVM Express consortium, all 11 of the suite of NVMe specs have bee…
-
Additional Old Linux Drivers Face Removal Due To Noise From AI/LLM Coding Agents
There continues to be a lot of cleaning up of the kernel source tree to deal with noise generated by AI / LLM coding agents sending in reports and patches for old drivers that are likely not actively used by anyone on modern upstream kernel builds. Rather than continuing to carry these old drivers around with the uptick in AI/LLM-generated noise, kernel maintainers are finding it better to just re…
-
AMD Preps HDMI FRL Fixes, New Knob For Disabling Older AMD GPU DCE Display Support
Overnight AMD engineers sent out their latest round of AMDGPU DC display code updates for their Linux driver. This week's round of display code updates include some additional fixes for their recently introduced HDMI FRL (Fixed Rate Link) support as part of the work toward their HDMI 2.1 implementation finally coming together for their open-source, upstream Linux driver...…
-
FEX 2608 Released With More Fixes For Running x86_64 Binaries On ARM64
FEX 2608 is now available as the newest monthly feature update to this open-source emulator sponsored by Valve for running x86_64 binaries on ARM64, including Steam and Windows games with Steam Play (Proton)...…
-
Keeping yesterday's computers ticking takes more than nostalgia
ARCHAEOLOGIC Repairing and restoring vintage computer hardware has grown increasingly popular, but keeping decades-old machines alive presents different challenges from fixing modern kit. Earie Salmon, of the YouTube channel Earie's 8-Bit Workshop, is one of many tinkerers documenting the process of keeping retro computers ticking over and building new examples of obsolete or never-released kit.…
-
Double trouble for Microsoft as pre-owned software license claims converge
ValueLicensing (VL) has been invited to attend a case management conference in a related multibillion-pound collective action against Microsoft, according to the reseller's boss, Jonathan Horley. VL sued Microsoft for £270 million in 2021, alleging that the software giant restricted the supply of surplus Office licenses available for resale. Barrister Alexander Wolfson is the proposed class repre…
-
New Boeing finally gets going, 15 years after debut
Boeing on Tuesday celebrated the certification of its latest passenger plane, the 737-7 MAX, 15 years after it announced the type and seven years after the first model rolled off the production line. The US Federal Aviation Administration (FAA) certified the plane on Monday, saying its decision “reflects years of sustained work to resolve complex technical issues and complete a thorough review of…
-
Watch a SpaceX Rocket Crash Into the Moon
A four-ton SpaceX Falcon 9 upper stage left drifting after a 2025 lunar mission is expected to crash into the Moon at about 5,400 mph, likely striking Einstein Crater. The impact should occur at approximately 2:35 a.m. ET (0635GMT). Reuters reports: Such stages typically fall back into Earth's atmosphere and burn up or plunge into the ocean after boosting the rocket's payload to a precise spot in…
-
Adding an API to networking hardware doesn’t solve management challenges
This is why cloud-inspired networks win: virtual switches are all consistent. Since opening up our draft of the 7th edition of Computer Networks: A Systems Approach for comments, we have not yet been inundated with feedback, but we did get a very helpful comment about our perspective on network operations, a subject to which we have devoted an entire chapter. Both Larry and I have learned over th…
-
Texas Halts Data Center Connections To Power Grid Amid Overwhelming Demand
An anonymous reader quotes a report from Ars Technica: Nowhere is the US data center boom bigger than in Texas. But less than a year after declaring Texas the "epicenter of AI development," Governor Greg Abbott has declared a moratorium on all new power grid connections for data centers -- at least until developers provide more information about their projects' potential impacts on the grid and co…
-
AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project
The UK’s AI Security Institute has observed AI models performing what it calls “unsanctioned action” 19 times during security tests. The Institute (AISI) revealed the incidents in a Tuesday post and technical report that details tests it conducted to see if AI models can solve a cyber security challenge. “We ran this challenge 122 times across several models,” the post states, before revealing th…
-
AMD's AI eggs are in too few baskets, Wall Street worries
AMD has posted strong second quarter results and forecast even better future financials once its Helios rack systems and Instinct MI400-series GPUs reach buyers. “In data center AI, the growing number and scale of Helios and MI450-series deployments position the [datacenter] business for significant growth in the second half of the year, with growth accelerating in 2027,” CEO Lisa Su told investo…
-
AMD Posts Proposal & Linux Patches For eSPI Subsystem
AMD has posted patches proposing a new Linux subsystem for the Enhanced Serial Peripheral Interface (eSPI) standard that was in turn originally developed by Intel. With AMD now making use of eSPI, they are proposing a new subsystem for it within the Linux kernel, which includes a new driver for their hardware...…
-
Tomorrow’s U.S. Senate Vote: Four Internet Bills, One Wrong Direction
The Senate Commerce Committee will vote this week on several censorious and privacy invasive bills: KOSA, the SCREEN Act, Youth AI Privacy Act, and CHATBOT Act. While we appreciate that the Committee is taking the time to look at these bills separately, it’s still impossible to ignore the message Congress is sending to the world: Age-gate the internet and block young people from speaking and acces…
-
An LLM agent attempts to compromise a project on GitHub
The AI Security Institute has released a detailed report on an security incident of its own making. The Institute set some LLM agents loose on the Internet with a security challenge; soon they were creating malware-laden pull requests and sock-puppet accounts to promote them. The agent opened a malicious pull request (PR) to ⟨REPO_A⟩ and pursued a number of strategies to get it merged: Repeatedly…
-
EA Is Now Officially Privately Owned
Longtime Slashdot reader neoRUR shares a report from Game Developer: EA Sports FC and Battlefield publisher EA has been taken private by an investor consortium led by Saudi Arabia's sovereign Public Investment Fund (PIF). The move means the U.S. juggernaut is no longer a publicly-traded entity and is now majority owned by the Kingdom of Saudi Arabia through its PIF investment arm. Other investors…
-
Appeals Court Agrees with EFF that Building a Web Browser Doesn’t Violate the CFAA
The Ninth Circuit Court of Appeals has endorsed a commonsense technical interpretation of the Computer Fraud and Abuse Act (CFAA), a law not usually given to such interpretation. Amazon had sued Perplexity AI to try to shut down its Comet browser, claiming the browser’s optional agentic AI “Assistant” that can browse websites like Amazon for comparison shopping purposes, violated the CFAA because…
-
Apple Limits Bug Bounty Submissions After Flood of AI Slop
Apple has capped the number of open bug-bounty reports researchers can submit after being flooded with low-quality and sometimes entirely fabricated vulnerabilities generated by AI. MacRumors reports: The Financial Times learned of the limit after cybersecurity startup Bynario used ChatGPT to locate more than 50 macOS bugs in three weeks. Bynario found a privilege escalation exploit that could let…
-
Senators demand crackdown on wildfire "prediction market" bets
Several US senators have written a letter to the Commodity Futures Trading Commission (CFTC), inquiring about the agency’s “plans to crack down on prediction markets” that offer “contracts for individuals to bet on wildfires.” “Offering bets on destructive wildfires threatens to minimize communities’ suffering, all so the rich and powerful can profit,” wrote the group of senators, who represent O…
-
Trump killed the Digital Equity Act but US was forced to bring part of it back
The Trump administration said it will reinstate a broadband grant program to comply with a court ruling that prevented it from fully ignoring the Digital Equity Act enacted by Congress in 2021. The US government said in a court filing that it plans to start taking applications for grants in December. However, the Trump administration won a partial victory because the judge ruled the government ca…
-
Dev proves LLMs will run on anything – even a $10 microcontroller
Getting a small local language model running on a notebook or even smartphone in 2026 is trivial. But what about something even smaller and lower-power. Say, like an ESP32 microcontroller that costs less than $10? It might sound impossible — the device is primarily designed for things like remote sensors, IoT, and other embedded applications, not running generative AI models — yet, that's exactly…
-
OpenAI wants teachers and profs to foist their work off on ChatGPT
In the face of an epidemic of AI-enabled cheating and research suggesting its products hamper learning, OpenAI is doing the sensible thing and pushing more AI on students and teachers. Wait, did I say sensible? My mistake. The House of Altman announced a trio of new education-focused offerings on Tuesday: one for K-12 teachers, another for college educators, and a third for college students. The…
-
Bending Spoons to Buy Airtable For $1.28 Billion
Bending Spoons has made its first acquisition since going public last month at an $18 billion valuation, agreeing to buy spreadsheet and database startup Airtable for $1.28 billion in cash. Airtable joins a growing portfolio of notable brands owned by the Italian app developer, including Evernote, WeTransfer, EventBrite, and Vimeo. TechCrunch reports: Founded in 2013, Airtable has so far raised mo…
-
Next.js 16.3 aims to reduce dreaded FATAL ERROR messages
Next.js coders toiling on complex React applications live with an ongoing low-grade anxiety about running out of memory. It’s not dementia; it’s the software. The dev can fill RAM all day long until the JavaScript engine (often V8) chokes, causing the underlying Node.js engine to crash entirely, leaving only a “FATAL ERROR” message. Cognizant of such frustrations, the core development team behind…
-
Texas halts data center connections to power grid amid overwhelming demand
Nowhere is the US data center boom bigger than in Texas. But less than a year after declaring Texas the “epicenter of AI development,” Governor Greg Abbott has declared a moratorium on all new power grid connections for data centers—at least until developers provide more information about their projects’ potential impacts on the grid and communities. The Republican governor directed regulators in…
-
Mobile Ad Software Encourages Location Data Sharing, EFF Report Finds
Developers Must Beware of Ad Libraries that Betray Users’ PrivacySAN FRANCISCO – Some software development kits (SDKs) provided by advertising companies to help developers monetize their apps are automatically feeding users’ location data into systems that location data brokers use to track people, an Electronic Frontier Foundation (EFF) report found. EFF began investigating the location-sharing…
-
Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy
Across mobile platforms, advertising companies provide developers with software development kits (SDKs) that make it easy to monetize their apps. But those same SDKs can automatically feed users’ location data into ad systems that location data brokers use to track people. Many developers may not even be aware of this privacy violation, let alone the users who are directly affected. When developer…
-
China is Tesla's cash cow, but for how much longer?
Tesla's factory in Shanghai had its best June ever, according to the China Passenger Car Association. Tesla built 93,579 cars in China that month, a hefty 38 percent increase compared to June 2025, according to CPCA's data. But that production isn't translating into bumper sales to Chinese customers. Rather, sales have been down quarter on quarter in China for more than a year now, particularly…
-
Bypassing AI guardrails is so easy a script kiddie can do it
If you want to bypass AI guardrails designed to stop models from assisting with cyberattacks, you often just have to ask the right way, according to researchers from Cisco Talos. Simply claiming you own the servers you're targeting or that you're taking part in a capture-the-flag or bug bounty exercise was often enough to persuade models to cooperate. Talos researchers have been poring over promp…
-
This one time, at Hacker Summer Camp …
As the entire security industry descends on Las Vegas this week for Hacker Summer Camp – not one, but three conferences – attendees can count on two hot topics dominating the discussion. First, a literal hot topic: the triple-digit August heat. Second, and to no one’s surprise: agentic AI – how to govern and secure agents so they don’t go rogue and hack into other organizations’ servers (*cough*…
-
[$] Fedora considers conflict-of-interest policy
The Fedora Council is considering a conflict-of-interest (COI) policy for its decision-making bodies, such as the Fedora Engineering Steering Committee (FESCo), special-interest groups (SIGs), and any other groups or individuals that report to the council and are responsible for decisions that impact the Fedora project. The current draft does not, however, apply to the council itself. The public d…
-
Feds get 3 days to patch N-able God mode flaw under active exploit
The US Cybersecurity and Infrastructure Security Agency (CISA) has added an exploited N-able vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, giving federal agencies three days to patch a flaw that could let attackers reach managed service provider (MSP) customers. Attackers exploiting the flaw can gain "full administrative access to an N-central console," Tracked as CVE-2026-1…
-
NVMe polishes its specs, brings virtualization to locally attached SSDs
The NVM Express (NVMe) specifications have been updated, gaining enhancements such as support for post-quantum cryptography, and SSD virtualization and live migration to better support virtualized environments. Announced by the NVM Express consortium, all 11 of the suite of NVMe specs have been updated with new features and engineering change notices. These represent the next step in the evolutio…
-
Another npm worm
StepSecurity is reporting the emergence of a new worm affecting npm packages. The design of the worm is nothing new, but the rapidity with which it is exploiting captured npm packager credentials is noteworthy. TL;DR: A self-propagating worm, which we are calling ChainDrop, is spreading rapidly through the npm ecosystem. So far 435 packages and more than 1,550 compromised versions have been flagg…
-
AI helps Microsoft bug hunters chase a record $20M payday
Microsoft announced this week that between July 1, 2025, and June 30, 2026, the company had paid more than $20 million in bug bounties to 562 researchers. The total was a Redmond record, as was the number of those submitting bug reports – despite having to navigate a sometimes frustrating submissions process. For comparison, the previous year's program, which itself set a new company record, paid…
-
Technology's Power in the Hands of the People
In the scorching heat of every Las Vegas summer, EFF joins thousands of hackers, makers, policy analysts, and activists for the world's largest computer security gathering. If you're there during this summer security week, be sure to say hello to us at BSides Las Vegas, Black Hat Briefings, and DEF CON 34. While tech companies align with governments to target the people, our community is harnessin…
-
AMD openSIL & Coreboot Pull Requests For Phoenix AM5 Support
Last week the 3mdeb firmware consulting firm released the first open-source firmware for a modern AMD Ryzen AM5 platform with their work to port AMD openSIL and Coreboot in their downstream Dasharo flavor to an MSI desktop ATX motherboard. Now that it's working out well, 3mdeb is working to upstream their AM5 platform support and Phoenix SoC support into upstream AMD openSIL as well as Coreboot...…
-
NVIDIA Becomes A Premier Sponsor Of LVFS / Fwupd
Now this is a pleasant and very unexpected surprise... NVIDIA has become the latest premier sponsor of the Linux Vendor Firmware Service (LVFS)...…
-
[$] The beginning of a process-builder API
The recent discussion on "spawn templates" raised questions about whether it was time to provide an alternative to the classic Unix fork()/exec() pattern for process creation. One idea that was raised there was to shift the template pattern into an interface that could be used to efficiently assemble new processes from bare cloth, without duplicating the parent process. Preferably, that interface…
-
Cloud giants pour nearly $600B into capex as AI demand surges
AI has turbocharged an already expanding cloud services market as organizations pour billions into online platforms offering the compute needed to train and run models, swelling the coffers of the established giants. Their latest results show revenue surging alongside capital spending as Amazon, Google, and Microsoft race to add capacity – at least until the AI bubble eventually bursts, of course…
-
Security updates for Tuesday
Security updates have been issued by AlmaLinux (frr, ldns, mingw-glib2, and perl-Archive-Tar), Debian (ruby2.7), Fedora (borgbackup, nebula, python-nh3, rust-ammonia, and seamonkey), Mageia (librabbitmq, libvncserver, packages, perl, perl-GD, perl-Unicode-LineBreak, squid, and unbound), Oracle (compat-libtiff3, frr, gstreamer1-plugins-good, javapackages-tools:201801, libreswan, nodejs:22, nodejs:2…
-
Linux Foundation Announces Tokenomics Foundation For "Economics & ROI Of AI Value"
Last month the Linux Foundation launched the x402 Foundation to standardize Internet-native payments for AI agents as their latest AI play. That followed other "AI" initiatives from dealing with AI exploits to AI asset and data exchange. Today they have another AI foray being announced with the creation of the Tokenomics Foundation...…
-
Tennessee congressional hopeful accused of shooting license plate cameras
An independent congressional candidate in Tennessee faces four felony vandalism charges after allegedly shooting four automated license plate reader (ALPR) cameras between July 14 and 22. According to the Blount County Sheriff's Office (site geo-restricted), Adam Lee Heimerman, 37, is accused of targeting three cameras in Blount County and one in Maryville. Local news reports citing an affidavit…
-
CAF Bank reopens online service but warns of further outages
CAF Bank has told customers its online banking service is back after being shuttered for more than ten days following what it described as "attempted fraud." In an email update seen by The Reg, the bank warned that access could remain intermittent, and it might "need to limit the amount of traffic to the website" at certain times. It admitted: "There are likely to be periods where online banking…
-
Linux's Staging Area To Now Reject LLM-Generated Patches, Except For Real Security Fixes
While Linux's second-in-command Greg Kroah-Hartman does use AI / LLMs himself to success in the Linux kernel, given the "onslaught" of kernel patches produced by large language models and the intent on the Linux kernel's staging area being an area for newcomers to get involved, moving forward he's now rejecting AI/LLM-generated staging patches. But there is one exception and that is for genuinely…
-
Wild Linker 0.10 Released With GDB Index Support, Mitigation For Btrfs Performance
Wild 0.10 released overnight as this very fast linker for Linux that is written in the Rust programming language and focused on iterative development...…
-
Linux 7.3 To Fix MSI Claw M-Center Keys For Ryzen Z2 Extreme Powered Handheld
For those with a MSI Claw A8 BZ2EM handheld gaming system, the model powered by the latest AMD Ryzen Z2 Extreme SoC, an important addition is coming to the Linux 7.3 kernel so that the M-Center keys will be properly supported...…
-
UK mulls making employers ask before installing bossware
The UK government is considering forcing employers in Great Britain to consult workers before rolling out "bossware," opening the door to new rules covering everything from AI-powered productivity scoring to keystroke logging and biometric surveillance. The Department for Business and Trade wants to know whether the rules governing workplace surveillance still make sense as software increasingly…
-
NASA puts astronauts’ lives in the hands of Tesla’s flaky Cybertruck
Tesla has recalled its Cybertruck 11 times to fix issues such as exterior trim panels falling off and an accelerator pedal that can become stuck, but NASA has nonetheless decided the rust-prone vehicle is up to the job of rescuing astronauts if trouble strikes on the launchpad of a forthcoming crewed mission. Muskmobiles will get the job currently performed by the Mine Resistant Ambush Protected…
-
Cloudflare has mostly ditched third party security tools, suggests not trying that at home
Cloudflare has used AI to automate processing of incoming reports to its bug bounty program for $58 a month using Anthropic’s Claude Sonnet model and chose it partly because using the AI company’s security-specific Mythos model would burn through around $200,000 a month to do the same job. The company’s chief security officer (CSO) Grant Bourzikas shared those numbers with The Register last week…
-
China claims global chip leadership thanks to new legal definition of 'integrated circuits'
China has changed its legal definition of semiconductors. The National Intellectual Property Administration yesterday issued an expert opinion on recent changes to the regulations governing intellectual property laws as applied to chips. That document, attributed to Guo He, from the School of Intellectual Property at the Renmin University of China, notes that laws in place around the world define…
-
FFmpeg 9.0 Released With More Vulkan Acceleration, Animated WebP & More AMD AMF
FFmpeg 9.0 is now available as the latest feature release for this widely used, open-source multimedia library...…
-
Improved GPU Reset Recovery For AMD Kaveri, Hawaii & Other GFX7 GPUs With Linux 7.3
In addition to the AMDGPU feature pull request to DRM-Next last week that landed DRM format modifiers for old AMD GPUs and a variety of other improvements, a secondary set of AMDGPU feature work followed that last week in preparation for the upcoming Linux 7.3 merge window...…
-
The Senate Should Reject KOSA's Privacy Risks
Update: The Senate Commerce Committee voted to advance this bill on August 5, 2026. EFF continues to oppose the bill, which still needs approval from the full Senate. The Senate Commerce Committee is once again considering legislation that would dramatically expand age verification, and undermine privacy for everyone. Alongside the SCREEN Act, the CHATBOT Act, and the Youth AI Privacy Act, the Ki…
-
EFF Joins 18 Civil Rights Organizations Calling on Governor Hochul to Reject the Stealth Crawler Prohibition Act
EFF joined a group of 18 civil society organizations to send a letter encouraging New York Governor Kathy Hochul to Senate Bill 9934A, the New York Stealth Crawler Prohibition Act. The letter states: While framed as a measure to protect local journalism, this legislation harms free expression and establishes a dangerous precedent by effectively deanonymizing and criminalizing automated access to t…
-
China turns up the heat with open model blitz as US model makers panic
The AI arms race reached a fever pitch on Monday after Chinese e-commerce and cloud provider Alibaba called into question America’s technological lead with the launch of Qwen 3.8-Max, a 2.4 trillion-parameter model that goes toe-to-toe with the best models from Anthropic and OpenAI. The new model comes just days after the launch of DeepSeek V4 Flash 0731, which, according to independent benchmark…
-
EFF Joins Call for FTC to Drop Its Disastrous AI Policy Proposal
The Federal Trade Commission (FTC) in July issued a proposed policy statement “concerning the suppression of accuracy in artificial intelligence systems.” We urge the FTC to withdraw this misguided proposal and instead focus on its core strengths and mission to protect consumers. The new proposed policy builds on, and directly references, the Trump administration’s “Preventing Woke AI in the Fed…
-
Twenty years of Pandoc
John MacFarlane has published a lengthy retrospective to commemorate twenty years of the Pandoc document converter. On August 3, 2006, I uploaded the first version of pandoc to my website, releasing it under the free GPL license. Pandoc 0.1 consisted of about 3000 lines of Haskell code, with no dependencies aside from GHC's standard library. It could convert Markdown, reStructuredText, HTML, and L…
-
The Youth AI Privacy Act’s Privacy Paradox
Update: The Senate Commerce Committee voted to advance this bill on August 5, 2026. EFF continues to oppose the bill, which still needs approval from the full Senate. The Senate Commerce Committee is poised to consider the Youth AI Privacy Act, a bill that would require AI companies to create kids-only privacy rules and implement so-called “safe design features,” which would—like three other bill…
-
Google dev kit spurs first-ever agent-on-agent violence
In what they call the first-ever real-world agent-to-agent exploitation method, Pillar Security researchers say they discovered an exploit in the repository behind Google's Agent Development Kit for Python that could allow attackers to compromise supply chains. In other words, now we know that one AI agent can be used to control and compromise another one that has more privileges. The security sn…
-
Linux 7.3 Looks Like It Will Upstream FailFS
Merged back in Linux 7.3 was NULLFS as a "completely catatonic minimal pseudo filesystem". Now expected for Linux 7.3 is its sibling: FailFS...…
-
C-Kermit 11 released
For those of us with a long memory: John Goerzen has announced the release of C-Kermit 11, the first release of this file-transfer utility in 15 years. As Debian maintainer of Kermit, I noticed some areas where it wasn't matching modern expectations. One area was, not surprising for a project of its age, security. Another area was that its character set or line-ending conversions are usually not d…
-
AI slop pollutes the CVE pipeline with fake vulns
Now AI is making fake vulnerabilities and polluting the ecosystem. A batch of critical- and high-rated SQLite CVEs that appeared in the NVD with CISA-supplied enrichment last week turned out to be technically bogus, according to security researchers, and their path into widely used databases exposes weaknesses in the CVE pipeline. Software supply chain security outfit JFrog reported last week tha…
-
[$] Buffer sizes for FUSE io_uring
The Filesystem in Userspace (FUSE) subsystem provides a way to service filesystem requests from a user-space server, which moves the format-handling code out of the kernel. The FUSE server can use the io_uring facility for better performance, but Bernd Schubert is concerned that memory is being wasted because the current implementation has a single, large buffer size that is excessive for small I/…
-
Russian spies turn public Wi-Fi into malware delivery systems
Conference-goers may want to think twice about connecting to public Wi-Fi after Microsoft disclosed that Russian foreign intelligence operatives (SVR) are compromising captive portal networks to deliver infostealers, keyloggers, and other malware. With the help of ReliaQuest's earlier work, Redmond fingered Storm-2945, a subdivision of the SVR's Midnight Blizzard (aka Nobellium), in an attack cam…
-
SQLite Critical CVEs or LLM Slop? (JFrog blog)
The JFrog blog examines some reported vulnerabilities in SQLite, some of which made their way into high-profile vulnerability databases, that turned out to be entirely fabricated by LLMs. These LLM slop CVEs can cause organizations to waste time investigating and patching vulnerabilities that do not actually exist, as well as polluting vulnerability databases. In environments where Critical vulner…
-
EFF at BSidesLV, Black Hat, and DEF CON 👨💻
It's time. Time for tinkerers, security researchers, hackers, and fellow nerds to gather together in signature black hoodies and utilikilts to beat the heat in Las Vegas for the summer security conferences: BSidesLV, Black Hat USA, and DEF CON. EFF's lawyers, activists, and technologists are excited, as always, to support this community of folks that push computer security forward. If you're atten…
-
Benchmarking Six Linux Distributions On The Framework Laptop 13 Pro
With the new Framework Laptop 13 Pro now shipping powered by Intel Core Ultra Series 3 (Panther Lake) and a brand new hardware design, I have spent the past week testing out various Linux distributions on this very nice high-end laptop. All of the modern Linux distributions tested have been playing nicely with this new Panther Lake laptop. Of course, beyond testing for compatibility I also took th…
-
MediaTek lines up $5B war chest for AI datacenter push
Taiwanese chipmaker MediaTek is lining up $5 billion in financing to expand into AI datacenter silicon, targeting a slice of a market it expects to be worth up to $80 billion next year. The fabless chip producer is perhaps best known for its Arm-based smartphone and Chromebook chipsets, plus wireless silicon for Wi-Fi products. But the firm is the latest to see a "compelling growth opportunity" i…
-
Police National Legal Database confirms data theft after dark web leak
The Police National Legal Database (PNLD) is the latest UK public sector outfit to admit that cybercriminals made off with its data, including the names and work email addresses of police officers, justice staff, government partners, and customers. The legal lookup service relied upon by police forces and criminal justice agencies across the UK said it discovered the "data security incident" on J…
-
NASA boss balks at billion-dollar estimate for recycled Moon rover
NASA Administrator Jared Isaacman has stated "we simply will not fly it" if claims about the costs of the repurposed Mars rover engineering model prove anywhere near accurate. Isaacman was responding to the Planetary Society's chief of space policy, Casey Dreier, who had run the numbers on his plan to send a robot to the Moon, built from parts of engineering models of the successful Mars rovers P…
-
Four stable kernels for Monday
Greg Kroah-Hartman has announced the release of the 7.1.6, 6.18.42, 6.12.101, and 6.6.148 stable kernels. Each contains hundreds of patches—the 7.1.6 kernel has more than 700—with fixes throughout the tree. Users are advised to upgrade.…
-
Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict
Georgia and Michigan are the latest US states to report cyberattacks on water systems, as the FBI investigates incidents across at least seven states. Iran-backed hackers are the leading suspects, although the bureau has not publicly attributed the campaign. Officials in both states told journalists over the weekend that water facilities had detected activity consistent with the attacks on more t…
-
zlib-rs 0.6.7 Released With LoongArch LSX Optimizations, Use-After-Free Fix
zlib-rs 0.6.7 is out today as the newest version of this "safer zlib" implementation making use of the Rust programming language and aiming to deliver performance on-par with zlib-ng...…
-
GNOME Boxes Preparing To Deliver Much Improved Virtualization Experience
GNOME Boxes as a front-end to libvirt and QEMU is preparing to deliver a much improved virtualization experience for those wanting to enjoy desktop VMs from the GNOME desktop...…
-
NVIDIA 610.57.04 Linux Driver Delivers Many Fixes
NVIDIA is kicking off the new month by releasing an updated R610 Linux driver build with quite a number of bug fixes...…
-
Google Earth's AI makeover survives for just one planetary rotation
Google performed a remarkably brisk reverse ferret last week, launching AI image generation in Google Earth and yanking it the next day after certain sections of the internet did the inevitable. This is how it began: "Today we're bringing AI image generation with Nano Banana to Google Earth, letting you virtually reimagine anywhere in the real world." This is how it's going, less than 48 hours la…
-
Linux 7.3 Expected To Drop The FreeVxFS File-System Driver
It looks like Linux 7.3 will end up dropping FreeVxFS as the read-only Linux kernel driver for the Veritas VxFS file-ssytem used formerly by HP-UX and SCO UnixWare...…
-
The AI bubble is already popping; we just don't know it yet
KETTLE Big tech's Q2 earnings have been pouring in over the last two weeks, and it looks like stock market investors are taking a pin to the AI bubble. You can listen to the latest episode of The Kettle right here on this page, as well as on Spotify, Apple Music, or YouTube, where you can subscribe to get notified about the latest episode. Between eye-watering capex expenses, shrinking free cash…
-
UK government investment arm cops to 40-hour leak of officials' contact details
The UK government's corporate finance adviser has admitted that an employee left an internal file containing the names and work email addresses of dozens of officials publicly accessible for around 40 hours. The breach, first reported by The Guardian, was disclosed in UK Government Investments' (UKGI) annual report, which says it occurred during the 2025-26 financial year after a member of staff…
-
KGamma2 Makes For Easy Gamma Adjustments On KDE Plasma With Wayland
KDE developer David Edmundson announced today his KGamma2 tool in aiming to address a pain point for KDE Plasma desktop users on Wayland...…
-
Sci-fi authors Scalzi and Stross decry AI's dystopian impact on their craft
Two prominent science fiction authors have decried the impact of AI on their craft. "I do not want or need a large language model to write my fiction for me. I write fiction compulsively – before I was published I wrote for many years as a hobbyist – so why on earth would I pay someone else to take my fun away?" wrote Charles Stross in a Saturday post. Stross graciously mentioned The Register in…
-
GNOME Mutter 51 Beta Released With Wayland Background Blur, Improved Frame Scheduling
Released overnight on Sunday were the beta versions of Mutter 51 and GNOME Shell 51. This follows GNOME 51 embarking on itsAPI/ABI freeze, feature freeze, and UI freeze a day earlier...…
-
KDE Linux Making For Easier First-Run Experience Of Java & DOS Apps
With July all wrapped up, the monthly status report is now published for KDE Linux as the in-house Linux distribution featuring all of the latest KDE wares and other open-source innovations...…
-
Linux 7.3 Adding Support For MCTP-Over-USB v1.1
Within the Linux networking subsystem's "net-next" Git branch there is now queued up support for MCTP-over-USB v1.1. This is the newest version of the standard for sending Management Component Transport Protocol (MCTP) packets over USB for tasks like crash dumps, logging, and firmware updates...…
-
Linux 7.3 To Support Realtek RTL8261C & RTL8261D
Queued into net-next ahead of the Linux 7.3 merge window is adding support for the Realtek RTL8261C and RTL8261D 10 Gigabit PHYs that launched last year...…
-
As Larry Ellison bets the farm, Oracle says it loves AI-written code, just not in OpenJDK
Oracle has told contributors to OpenJDK – the open source Java project it stewards – not to submit code or other material generated by AI. In a post tagged "legal," Oracle said it was drafting a full policy on generative AI but had set interim ground rules. It cited risks involving review workloads, safety, security, and intellectual property. "Contributions in the OpenJDK Community must not incl…
-
Claude Code is revolutionizing digital archaeology. Enterprise better dig it
OPINION The UK's National Museum of Computing at Bletchley Park (TNMoC) is a natural center of digital archaeology. It has restored, recreated, and documented landmark machines, from the wartime Colossus computer through to British mainframes of the '60s and '70s. Its collection from the dawn of the microprocessor age also attracts those who live to investigate such things. LLMs, still in their m…
-
AI is 'both the weapon and the target' in latest wave of cyberattacks
AI is becoming both an attack tool and a high-value target, with attacks by AI-enabled adversaries rising 89 percent in 2025, according to CrowdStrike. The security firm's annual Threat Hunting Report details criminal gangs and nation states using AI throughout the attack chain. Attackers are also targeting organizations' AI infrastructure and poisoning popular software packages to compromise the…
-
IT boss left root session open for bring-your-kid-to-work day
WHO, ME? Comedian W.C. Fields is credited with the aphorism "Never work with children or animals," which The Register mentions because half of it has some relevance to this week's edition of "Who, Me?" – the reader-contributed column chronicling the ups and downs of working in tech. This week, meet a reader we'll Regomize as "Stockley" who shared a horror story that took place in the 1990s. At th…
-
Microsoft says 8 GB of RAM should be enough for anyone running Windows 11
Microsoft has added four new items to the to-do list it set itself to improve the quality of Windows 11. Redmond's list landed in March 2026 in response to users' anger at Windows 11 becoming increasingly flaky and needy. Pavan Davuluri, Microsoft's executive VP for Windows and Devices, promised "improved memory efficiency, lowering the baseline memory footprint for Windows, freeing up more capac…
-
AerynOS Issues First Development Update & New ISOs In Three Months
It's been just over three months since the last AerynOS development update and new ISO spin but fortunately that's been succeeded today by a new development update and ISO images. AerynOS development remains strong and ongoing with many changes to be found in this latest from-scratch Linux distribution release...…
-
Linux 7.2-rc6 Released: "This RC Is Huge"
Like clockwork, the Linux 7.2-rc6 kernel is now available for testing in working toward the stable Linux 7.2 kernel in hopefully two week's time...…
-
GNU Hurd News 2026-Q2
-
Amending AB 1709 Doesn’t Fix It: California’s Social Media Ban Still Threatens Free Speech and Privacy
California lawmakers have amended A.B. 1709, but the core problem remains: the bill is still a ban on social media access for youth under 16, and it still threatens the privacy and First Amendment rights of all Californians. Proponents of the bill may argue that the recent amendments represent a compromise, but a close look at the text shows no major changes. As the bill moves forward in the Senat…
-
The SCREEN Act Threatens Privacy Far Beyond Adult Websites
Update: On August 5, 2026, The Senate Commerce Committee voted 15-13 to advance this bill, but the bill did not advance because of a lack of Senators in attendance. EFF continues to oppose the bill. The Senate Commerce Committee is set to consider S. 737, the SCREEN Act, a sweeping age-verification bill that would require online services to verify users’ ages before they can access any sexually e…
-
The CHATBOT Act Forces One Parenting Model On Every Family
Update: The Senate Commerce Committee voted to advance this bill on August 5, 2026. EFF continues to oppose the bill, which still needs approval from the full Senate. Artificial intelligence is rapidly changing education, and the way people search for information. Parents, teenagers, teachers, and schools are struggling with tough questions about when AI should, and should not, be used. It makes…
-
Goodhart's Law Comes for Every Benchmark You Trust
-
Exact, parallel 2D Delaunay triangulation for int32 coordinates
-
EFF Guide to Recording Law Enforcement
This post is available as a printable one page handout in English and Spanish. Recordings of law enforcement, whether by bystanders or by those directly encountering officers, can be powerful tools of government accountability and can support movements for social change. But recording officers can come with risks. Below are important legal and practical considerations related to recording the poli…
-
Discovery of a multicomponent alloy forged by the Hiroshima atomic blast
-
Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawl…
-
Nouveau vs. NVIDIA R610 On CachyOS With The GeForce RTX 5090 Laptop GPU
With the Razer Blade 18 as the first laptop Razer's certifying for (Ubuntu) Linux use while testing it out I was predominantly using the NVIDIA R610 official driver stack. Some users were interested though in how well this laptop is working with the open-source, upstream Nouveau+NVK driver stack given Razer is marketing this high-end laptop for Linux use too. Before sending the review unit back I…
-
🏃 Fitness Tracker Privacy Fails | EFFector 38.14
Watches, bands, and rings—if you want to digitally monitor your fitness, more companies than ever are selling devices to do it. And more Americans than ever now own at least one wearable health device. But what are the companies that make fitness trackers doing to protect our sensitive data from prying eyes? A lot less than they could be, it turns out. We're explaining what companies can do to pro…
-
Pushing the limits of RISC-V emulation
-
San Francisco: Don’t Fall for Industry Defense of Surveillance Pricing
The concept of “surveillance pricing” is just one part of a much larger problem and business model: corporations maximizing their profits by invading our privacy. The all-too-common business model is to systematically harvest, collate, and store as much of our personal data as possible, and then monetize it through use and sale. When it comes to surveillance pricing, that looks like corporations o…
-
Why Are Gay Bars Building Databases of Their Patrons?
Recent reports have raised alarm about the use of PatronScan, an ID-checking and face-scanning system, at multiple LGBTQ+ bars in San Francisco’s Castro neighborhood. Much of the attention has focused on reports that the system photographs patrons as they enter venues and questions about whether those images are used for facial recognition. A broader privacy concern also deserves scrutiny. For yea…
-
Missed EFF's Livestream with Adam Savage and iFixit? Listen Here!
EFF’s first EFFecting Change livestream was all the way back in July of 2024. Maybe you've caught each stream, or maybe you’ve only caught a few. Or maybe you’re like me and prefer to listen to conversations like these on your daily commute! Either way, if you want to stay on top of these monthly conversations, you can now subscribe to our new podcast feed for EFFecting Change—starting with our co…
-
Farmers Are Getting Control Of Their Equipment Back
For years, John Deere had actively made repairing their tractors near-impossible for anyone but itself and the few "authorized" repair shops—regardless of the ability of its customers to actually visit such shops. Now, in a major win for farmers and right to repair advocates, John Deere must soon provide farmers with not just the tools and resources to finally repair their own John Deere equipment…
-
Hundreds of Drone-as-First-Responder Programs Could Soon Be Launched Across the Country
Police departments across the country are lining up to launch drone-as-first-responder (DFR) programs, and hundreds have cleared a necessary hurdle toward making deployment a reality, expanding aerial surveillance and data collection even in areas patrol officers typically can't reach. As of February 2026, over 1,000 public safety agencies—including police, fire, and other emergency management age…
-
The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required
Legal intern Suzanne Castillo was the principal author of this post. The Fourth Circuit issued a disappointing opinion in U.S. v. Belmonte Cardozo, a case in which EFF filed an amicus brief, alongside the national ACLU, its Maryland, North Carolina, South Carolina, and Virginia affiliates, and the National Association of Criminal Defense Lawyers (NACDL). We argued that electronic device searches a…
-
New EU Court of Justice Ruling on Platform Liability Could Cause Collateral Damage to Freedom of Expression
Intermediary liability laws around the world recognize that social media platforms, search engines, and other online service providers have become an integral part of our lives: they shape how we access information, communicate with others and participate in public debate, and foster innovation online. These laws generally shield platforms, to varying degrees, from legal liability for user content…
-
LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a…
-
Protect Your Privacy with California's DROP Tool
Are you a California resident? Then we've got exciting news for you: there's a tool just for you that lets you take a single, relatively easy step to protect your privacy. It's called a DROP request. (That's Delete Request and Opt-out Platform, if you're fancy). This one bit of paperwork lets you tell every data broker registered in the state of California that you'd like them to delete your info…
-
An Explosion of Surveillance Towers is Coming to U.S. Borders, Costing Over $1 Billion
A new report from the Government Accounting Office reveals that the Department of Homeland Security (DHS) plans to nearly triple the number of surveillance towers along U.S. borders, from the current 830 to 2,300 by 2034. DHS expects to expend $1 billion in taxpayer dollars for this dangerous expansion of a surveillance network indiscriminately trained on towns, school playgrounds, backyards, and…
-
“Stealth Crawlers” Are Not a Threat to the Open Web. Bills Targeting Them Would Be.
There’s a new boogeyman in the battles over AI: so-called “stealth crawlers.” We’ll admit it—the term “stealth crawlers” sounds quite nefarious. In reality, they’re anything but. “Stealth crawlers” are simply automated tools to access and collect public web data—without disclosing the user’s identity. Private crawlers like these facilitate all kinds of important work that benefits the public, incl…
-
Victory! Flock Ends Rollout of Audio “Distress Detection” of Human Voices
Reversing course, Flock Safety—the surveillance technology vendor most known for its extensive network of automated license plate readers—has announced that it will end a pilot for its acoustic gunshot detection devices to identify signs of “human distress.” ...public pressure can sometimes work to influence both companies and lawmakers that control a city’s purse strings to discontinue or divest…
-
Your Vision. Your Legacy. Your Future.
This month, we celebrate 36 years of EFF and a mission that is bigger than any one of us. Thanks to EFF, communities around the world are demanding that technology protects their freedom, advances justice, and opens doors to opportunity. That's not a small thing—it's a life's work worth continuing. If you are committed to staying on the cutting edge of digital rights issues, I'd like to invite you…
-
How the Watch Dogs Video Game Series Mirrored and Predicted Real-World Digital Rights Issues
When Ubisoft's Watch Dogs 2 was released in 2016, it was a headtrip for those of us working on digital-rights issues in the Bay Area. During the day, I'd fight tech-authoritarianism from EFF's San Francisco offices and then, at night, I'd fight tech-authoritarianism in an uncanny simulation of San Francisco from my home gaming console. Watch Dogs 2 is an open-world video game that follows a hack…
-
EFF and ARTICLE 19 Submission to the European Commission on the DSA Trusted Flagger Guidelines
EFF and ARTICLE 19 have submitted joint comments to the European Commission on draft guidelines for the Digital Services Act’s trusted flagger mechanism. Having long advocated for a DSA that protects freedom of expression while preserving intermediary liability protections and the prohibition on general monitoring, we welcome the Commission's effort to provide practical guidance on how the trusted…
-
California Steps Back From Dangerous Expansion of its Age-Gating Law
The California legislature has stepped back from a plan that would have expanded its age-gating law, removing language that could have compounded serious threats to users’ speech, privacy and security just to browse the internet. A.B. 1856, authored by Assemblymember Buffy Wicks, will now move forward through the legislature without its most problematic pieces. EFF still believes the underlying la…
-
Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features
Oura Rings, Garmin GPS fitness watches, Apple Watches, Whoop bands—every year, more and more tech devices are promising to monitor our health and fitness, guide us toward healthier living, and provide useful health metrics to take to our doctors. But few of these tools provide the sorts of privacy and security promises we demand from all technology, let alone tech that captures personal health dat…
-
🚫 Don't Let Congress Age-Gate the Internet | EFFector 38.13
The effort to age gate the internet is back in Washington—and now it has a new name. Recently passed by the House of Representatives, the KIDS Act is a sprawling package of proposals to control what we can see and say online. Supporters claim the KIDS Act is needed to protect minors online. But if lawmakers really want to make the internet safer, why are they encouraging more surveillance instead…
-
European Court: Apple Can Not Shirk Off its Interoperability Requirements
One of the best bulwarks against monopoly is interoperability—that is making a new product or service work with an existing product or service. Interoperability allows users, and not the manufacturers of their devices or largest player in a market, to decide what application best serves them. Unsurprisingly, companies like Apple have worked hard to resist interoperability requirements. On July 8,…
-
Don’t Repeat NY’s 3D Printing Blunder
This year the state of New York had the dubious honor of being the first to pass a controversial provision to mandate all 3D printers come with surveillance and censorship. That means not only is there a ticking clock to protect every artist, researcher, engineer, and hobbyist in the state, but there is a real risk of other states thoughtlessly following suit—prior to the New York rules even takin…
-
Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence. Nearly 60 of the bugs qua…
-
Sony Nerfs Videogame Ownership
Legal intern Suzanne Castillo co-authored of this post. Playstation’s decision to kill physical game discs is the latest attack on our diminishing rights to access and engage with culture digitally. Rent-seeking corporations and negligent lawmakers share the blame — and they can do better. We’ve seen the same playbook used in the move to digital distribution of film, TV, and music: draw in custo…
-
Lessons Learned from CISA’s Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency’s initial response provide important lessons that all…
-
Building Our Future Together
In my first weeks as Executive Director of EFF, I’ve been reminded every day how consequential this moment is in determining what kind of future we will have. We are on the edge. What each one of us steps up to do – with our expertise, energy, and resources – will determine whether our future is one of openness, security, and fundamental rights, or one controlled through fear, surveillance, and ce…
-
Automated Moderation Is Here to Stay—Accountability Must Keep Pace
This post is part 2 in a series about automated content moderation. Read the first post here. When whistleblower Frances Haugen leaked a set of documents from Meta in 2020, among the revelations was a jarring statistic: The company’s algorithms designed to detect terrorist content incorrectly deleted nonviolent Arabic-language content 77 percent of the time, while failing to detect hate speech und…
-
"We Want Texans to Know Their Rights": Q&A with Mayday Health on the Impact of Surveillance on Abortion Care
Last May, EFF reported that a sheriff’s office in Texas searched data from more than 83,000 automated license plate reader (ALPR) cameras to track down a woman suspected of self-managing an abortion. ALPRs are promoted as tools for keeping communities safe by finding missing persons and locating stolen vehicles, but this case showed how ALPRS can be weaponized to investigate people’s private healt…
-
The House Passed The KIDS Act—The Senate Should Reject It
Last week, the House voted on the KIDS Act, a disjointed package of legislation that seeks to control Americans’ web browsing and private messaging. The package combines a revised version of the Kids Online Safety Act (KOSA), with several other internet bills, study bills, reporting requirements, and new regulations. Different parts of the bill pressure online services to impose different age-gati…
-
European Commission Chooses to Keep EU Users Locked Up Behind Big Tech’s Gates
Users are always seeking more control over their social networking experience to make it better, whether to improve privacy or enhance flexibility. Interoperability between social networking platforms like Facebook and TikTok has so many benefits that solve those issues. Say you’re on multiple platforms because you have friends you follow on different networks, but you’ve decided to choose one p…
-
Google's New Remote Attestation Scheme is As Bad As Its Old One
Google owes its existence to the open web, but today, its technological “innovations” have much to do with locking users into a “walled garden.” The latest of these is “reCAPTCHA Mobile Verification,” an experimental initiative that will let companies block users if they are running independent, "de-googled" versions of Android. These “indie Android” versions are favored by people who want to prot…
-
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names. The X/Twitter account IRIS C2 (@C2IRIS) has gained more than 4,000…
-
Automated Moderation Is Here to Stay
This blog post is part 1 of a 2-part series. The second part sets out recommendations for companies and policymakers.Six years ago—one month into a global pandemic—we argued that the automated moderation processes many platforms were rapidly adopting should be highly transparent, easily appealable, and temporary. We warned that "protocols adopted in times of crisis often persist when the crisis is…
-
Help EFF Cut the AI Hype
In the global race to build and dominate the AI industry, it can sure seem like the interests of ordinary people sit last on the agenda. It's just the opposite for EFF. While companies furiously jam AI tools into their veins and your eyeballs, EFF’s technologists, activists, and attorneys have been meticulously cutting through the hype to ensure AI can serve your privacy and free expression. Techn…
-
FBI Seizes NetNut Proxy Platform, Popa Botnet
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botn…
-
LGBT Q&A: How Can I Wipe Online Data That Points To My Queer Identity?
This Pride, we’re answering all your digital rights questions in season two of our initiative, LGBT Q&A. You Asked: Is there a way for me to wipe data about me online that could point to my queer identity? EFF’s Answer: You cannot protect everything all the time, but there are ways to wipe information about yourself online. Most information available about you online will typically be found in t…
-
EFF and Allies: X’s FTC Petition to Waive Privacy Violation Order Should be Rejected
X Corp. should not be able to escape privacy compliance because it changed its name. On May 15, X Corp. filed a petition before the Federal Trade Commission (FTC) to set aside or modify an order issued in 2022 requiring the company to report regularly to the FTC for its violations of user data. The order or “consent decree” is a result of misleading the platforms’ 140 million users by using priva…
-
LGBT Q&A: What Data Are Companies in the UK Collecting When Verifying My Age?
This Pride, we’re answering all your digital rights questions in season two of our initiative, LGBT Q&A. You Asked: I live in the UK, and we have age verification now on a bunch of websites (including Reddit) and now on iPhones. Can you explain what sort of data companies are actually collecting when they check for age and whether there are any real threats to my safety? EFF’s Answer: Age verif…
-
EFF to Gov. Pritzker: Veto Illinois’ HB 5511
The Illinois legislature recently passed House Bill 5511, which imposes a sweeping, device-level age-gating framework across nearly all internet-enabled hardware, operating systems, and online services. This well-intentioned but deeply flawed piece of legislation will harm young people who rely on the internet to access essential information and find community. That’s why we’re urging the Illinois…
-
Victory! Supreme Court Says Constitution Protects People’s Location Data
You have an expectation of privacy in location data that reveals your movements in the physical world, and even short-term surveillance of these movements is a search subject to the Fourth Amendment, the U.S. Supreme Court ruled today in Chatrie v. United States. The case involved geofence warrants, a form of dragnet surveillance police have used to vacuum up location data from electronic device…
-
EFF to Grindr: This Pride Month, Put Safety and Privacy Over Profits
This Pride month, we’re calling on the dating app Grindr to prioritize LGBTQ+ user safety by making privacy the default across its platform. That means no more sharing personal data with advertisers or training AI on private information without users’ opt-in consent. Grindr is a dating app for the LGBTQ+ community; and for queer people, privacy violations can have life-altering consequences. Infor…
-
Hate “The Algorithm?” RSS Is One of the Tools You’ve Been Looking For
Poke your head into just about any online social network—or any general conversations about internet culture—and you’ll likely find a boogieman: the algorithm. Since at least the moment Facebook introduced (and apologized for) its News Feed, “the algorithm” has been shorthand for the ways the tech giants control what we see and when we see it. In the age of enshittification, there is a push to rec…
-
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-wee…
-
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Ala…
-
Who Runs the Ransomware Group ‘The Gentlemen?’
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group. A graphic create…
-
A Record-Breaking Patch Tuesday for June 2026
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft’s most dire “critical” rating, and exploit code for at least three of the weaknesses is now publicly available. The software giant said in a…
dispelled