[ Reuters | Slashdot | BBC News ] [ Image Archive ] |
Slashdot
wiredmikey shares a report from SecurityWeek: Meta is the latest major AI developer to admit that its models broke loose during cybersecurity testing and hacked external systems. The tech giant said in a statement to the media on Wednesday that the incident occurred during independent evaluations conducted by Israeli AI security startup Irregular. The tested AI models were inadvertently allowed to access the internet due to a misconfiguration, which led them to exploit a vulnerability in an unnamed third-party service. It's unclear if it was a known flaw or a zero-day. The Information [gated] learned that the Meta AI attacks involved the company's advanced Muse Spark 1.1 model, which breached an unnamed organization's systems and made unauthorized changes to its internal environment. Meta said it learned of the AI models going rogue after being notified by Irregular. The company is conducting an investigation and it has promised to issue a "full retrospective" once it has all the facts. A spokesperson for Irregular said the incident was the "exact same evaluation-environment issue that was already disclosed by Anthropic last week" and that it did "not involve a "sandbox escape or a sophisticated cyber action." It contrasts with OpenAI, whose AI agent independently exploited a novel vulnerability to reach the internet during cyber testing. Not only did it breach Hugging Face but it also hacked multiple third-party accounts and services as part of the attack. Read more of this story at Slashdot. - Broadcaster Wins Broad US Blocking Injunction Covering Pirate Sites That Don't Exist Yet An anonymous reader quotes a report from TorrentFreak: Mexican broadcaster TelevisaUnivision (TU) has obtained (PDF) one of the broadest anti-piracy injunctions ever issued by a U.S. federal court. After initially targeting five pirate IPTV streaming operations, the case expanded to cover well over 500 domain names, requiring intermediaries including Cloudflare, GitHub, and a Mexican bank to comply. In addition, the injunction also covers pirate services and content that hasn't been created yet. [...] The case was relatively targeted, naming the IPTV services Thunder TV, Sunset TV, Pop TV, Kaelus TV, and Tele Latino, as well as their alleged operators. The broadcaster argued that these pirate IPTV services threatened its business. TU holds the World Cup rights for sixteen Latin American territories, and its license with FIFA requires it to keep the Mexican broadcast signal from reaching the United States. The pirate services, it argued, put it in breach of that contract, exposing it to "termination and forfeiture of hundreds of millions of dollars in payments." To stop this immediate threat, the company requested a temporary restraining order, hoping to shut down the IPTV services effective immediately. [...] Judge Kathleen Williams granted the temporary restraining order (PDF) on June 5, one day after the case was filed, without hearing from any of the defendants. The initial order prohibited the defendants from infringing TU's own copyrighted works, which include telenovelas and other programming, and from using its trademarks, including all content linked to its licensed World Cup broadcast. Importantly, the order also targeted third parties acting "in active concert," including ISPs, hosts, CDNs, domain registrars, registries, app stores, ad networks, social platforms, search engines, and payment processors. These were ordered, on TU's request and with notice, to disable the listed domains and IP addresses and unmask whoever was behind them. [...] While the injunction is noteworthy for many reasons, the most striking feature is that it's specifically written to include things that don't yet exist. That starts with the content it protects. The order isn't limited to TU's current catalog or the World Cup rights, it covers the infringement of "any copyrighted works or broadcasts that Plaintiffs may in the future produce, license, or acquire rights to transmit." In other words, it covers future copyrights that did not exist when the order was signed. The same applies to the pirate services themselves. The injunction defines its target as the named IPTV operations "and any comparable system," whether "currently in existence or developed in the future," and it applies "regardless of the branding, domain name, or technical configuration used." Read more of this story at Slashdot. - FDA Approves First mRNA Flu Shot The FDA has approved the first mRNA flu vaccine in the United States after a clinical trial found it was about 27% more effective than a standard flu shot. Manufactured by Moderna and marketed as mFlusiva, the vaccine is expected to be available this fall for adults ages 50 to 64 and those 65 and older, though approval for the older group is conditional on Moderna conducting an additional clinical trial, NBC News reports. From the report: Many scientists and public health experts have touted the idea of an mRNA-based flu vaccine, which uses the same messenger RNA platform as the Covid vaccines from Moderna and Pfizer. That's because mRNA vaccines can be manufactured much faster than traditional vaccines, allowing scientists to better match circulating influenza strains. Moderna said it takes two to three months from picking the strain to rolling out its flu shot, compared with about six months for traditional flu shots. Read more of this story at Slashdot. - BMW Blasts Its Cars' Internal Screens With Aggressive Ads Longtime Slashdot readers schwit1 and fjo3 shared a report about BMW displaying a Spider-Man promotion on connected vehicle screens in more than 70 markets. According to reports, drivers had to play or dismiss the ad before they could use the infotainment system. Futurism reports: BMW, showing that it was about as in-touch as its drivers are familiar with turn signals, teased the promotion as a "special surprise." According to The Autopian's coverage and the heaps of complaints online, the ad appears on the center console screen when you start up the car. When the ad's done playing -- a cheap looking animation that doesn't come close to warranting all this hubbub -- it even has the gall to ask you to scan a QR code. While it does give you the option to play or skip the "festive animation," it's still an annoying extra step drivers have to take before pulling up the map they need or the music they want to listen to. It's also a breach of trust: drivers keep their cars connected so they receive critical software updates, not unexpectedly see ads when they're trying to hit the road. Few owners were pleased. Enthusiasts in the r/BMW subreddit had a veritable meltdown when someone posted footage of the ad playing on their infotainment system. Read more of this story at Slashdot. - New Images of the Sun Show Its Surface In the Finest Detail Yet An anonymous reader quotes a report from the Associated Press: Scientists have captured images of the sun's surface in the finest detail yet, revealing a strange and dynamic facade. It's dangerous to look directly at the sun without proper eye protection. But researchers were able to peek at its scorching surface with the help of the National Science Foundation's Daniel K. Inouye Solar Telescope, located on the island of Maui in Hawaii. Scientists originally took the images for a different reason: to fine-tune and test the limits of the telescope. But when they looked at the results, they realized they'd photographed the sun's bright outer shell at higher resolution than ever before. What's more, they saw strange feathery patterns rippling across the surface. "That reminds me of famous paintings, like the swirling skies in Van Gogh's Starry Night," said solar physicist Ruizhu Chen with Stanford University, who was not involved with the new research. Researchers saw ripples of instability on the sun's surface caused by bits of magnetized plasma moving past each other at different speeds -- similar to waves that stir when a gust of wind blows over water. It's a well-known phenomenon that guides how fluids move. This has been glimpsed on Earth and other planets like Jupiter and Saturn, but "it has not been observed ever at that level on the solar surface," according to study co-author Friedrich Woger with the National Solar Observatory. The findings were published Wednesday in the journal Nature. Read more of this story at Slashdot. - Waymo CEO Explains Why Camera-Only Self-Driving Falls Short Longtime Slashdot reader AmiMoJo shares a report from Electrek: Waymo co-CEO Dmitri Dolgov laid out the clearest technical case yet for why cameras alone can't take a self-driving system to full autonomy, arguing that "weak sensing" hits a safety ceiling long before it reaches superhuman performance. [...] Dolgov made the comments in a talk at Y Combinator's Startup School, walking through the lessons Waymo has learned building its driver over close to two decades. He put the sensor question on the table plainly: "there's been a long-standing debate about what kind of sensors do you actually need for autonomous driving." His answer draws the line that camera-only advocates tend to skip right past. "Humans of course can drive with just eyes, so there's that proof of existence," he said. "If the goal were to just approximately match human performance or to build an assist product, that's a very reasonable way to go." Then the catch. If you're targeting full autonomy and strongly superhuman performance, he said, "you find that weak sensing just leads to a safety curve that flattens out way too early." Dolgov said that cameras, lidar, and radar are complementary rather than redundant: "These different sensing modalities, they're not backups to each other," and combining them produces a view "vastly superior to what you get with any one sensor." He said multiple sensor types also protect against physical failures, such as a leaf or branch blocking a camera, while helping Waymo climb the "exponential ladder of nines" required for fully driverless safety. Dolgov warned that camera-only systems may improve quickly before plateauing "way before the performance that is required by your product." He also pushed back on the cost argument against lidar, calling it "a number that has a fairly short shelf life" as hardware costs continue to fall. Read more of this story at Slashdot. - Anthropic's AI Used Fake Identities, Malware In Rogue Attack On GitHub Project An anonymous reader quotes a report from Ars Technica: Routine cybersecurity testing of frontier AI models sparked a series of unexpected security incidents -- the most serious case arising when Anthropic's Mythos 5 model attempted to insert malicious code into an open source software application and created fake identities to deceive the human developers maintaining the project. The security incidents occurred during a cyber evaluation of seven leading AI models' capabilities by the AI Security Institute (AISI), a research organization within the UK government, in late July. The researchers discovered (PDF) 19 instances in which "AI agents took unsanctioned action on the live Internet, including cases that targeted real people and organizations," according to an AISI blog post published on August 4. Almost all the "autonomous, unsanctioned" actions came from Anthropic's Mythos 5 model, with two such actions coming from OpenAI's GPT-5.6 Sol. [...] The most serious case involved Mythos making multiple attempts to execute a supply chain attack on the open source project repository hosted on the developer platform GitHub, including using social engineering techniques to try to convince the repository's human maintainers to merge malicious code into the repository. After first opening a pull request to merge the malicious code into the repository, Mythos created fake online "sock puppet" personas that claimed to have independently reviewed and verified the code as not containing malware. The AI agent also sent five emails to two human maintainers of the repository, including some emails containing malware and others attempting to persuade a maintainer to accept the pull request. Mythos even opened a GitHub Issue on a second repository -- also owned by a maintainer of the first repository -- that contained a prompt injection with malicious instructions targeting "issue-triage AI coding agents." This line of attack came from Mythos reasoning that the repository maintainer could be an AI coding agent such as Claude Code. Read more of this story at Slashdot. - Meta Debuts First AI Coding Agent To Take On Anthropic and OpenAI Meta has launched Muse Code, its first AI coding agent that's positioned as a lower-cost rival to Anthropic's Claude and OpenAI's Codex. It offers pay-as-you-go pricing and an optional zero-data-retention feature for enterprise users. CNBC reports: Muse Code is the latest major release from AI chief Alexandr Wang, who leads Meta Superintelligence Labs and oversees foundation model development. Wang joined in June of last year as the centerpiece of CEO Mark Zuckerberg's effort to revamp his company's flailing artificial intelligence strategy. "You can install it with one command and then use it to take on complete software engineering tasks across a wide variety of use cases, planning changes, writing code, validating the results," Wang said in an interview on Wednesday. [...] The new tool, like Anthropic's Claude and OpenAI's Codex assistants, makes it easier for people to build apps within a single user interface while managing fleets of AI-powered digital agents that can help underpin the software development process. Muse Code, available in a preview version, works alongside the company's latest AI model, Muse Spark 1.2. Wang declined to share user statistics related to the company's Muse Spark AI models, but said "adoption has been exciting and strong." The latest Muse Spark model was developed and trained alongside Muse Code, which Wang said improves the overall coding performance. Read more of this story at Slashdot. - Apple's 'Private Relay' Is Exposing Users' Real IP Addresses Security researchers found that Apple's iCloud Private Relay can expose users' real IP addresses because some passkey-related requests bypass Safari and its proxy protections at the operating-system level. "In short: any website that supports, or pretends to support, passkeys can see the user's real IP address despite having iCloud Private Relay on," security researcher Tommy Mysk, who discovered the issue along with Talal Haj Bakry, told 404 Media. The flaws also affect OnionBrowser, an iOS app for browsing the web through the Tor anonymity network. It does not, however, impact the official Tor Browser itself. From the report: The researchers developed a site that lets Private Relay users check if the issues impact them. In 404 Media's tests, the site did return the real IP address of a user that was supposed to be protected by Private Relay. [...] In a quirk of how passkeys work -- a broadly secure alternative to usernames and passwords which use the WebAuthn standard -- a user's device makes a web request outside of the browser itself. Meaning, that request essentially bypasses Private Relay and exposes a user's real IP address, even though to them it may look like they are simply interacting with a website as normal. "Because the fetch is issued by the operating system's credential service rather than by Safari, it never enters Private Relay's proxied path. The destination server sees the device's real IP address either way," the researchers write in their research. [...] "We have already informed them. They said the issue was âdire,' but they let us disclose the issue. They didn't provide any time when they will address this," Mysk said. Read more of this story at Slashdot. - Lawmaker Who Wants Data Center Pause Wins Kansas Democratic Primary Kansas Democrats nominated State Senator Cindy Holscher for governor after she defeated party-backed rival Ethan Corson. "The race became a test of what sort of candidate Democratic voters prefer in what is expected to be a challenging general election race: a more moderate candidate like Mr. Corson with endorsements from party leaders or an outspoken populist like Ms. Holscher, who spoke out against data centers and the political establishment," reports The New York Times. From the repot: Even in a national political environment that could favor Democrats, Republicans see the Kansas governorship as among their best opportunities for flipping a seat. President Trump carried Kansas by 16 percentage points in 2024, and Republicans hold supermajorities in the State Legislature. Voters in the Republican primary for governor nominated Ty Masterson, the president of the Kansas Senate and the recipient of Mr. Trump's endorsement, according to The A.P. Ms. Holscher, who is from suburban Kansas City, sought out a lane to Mr. Corson's political left and made inroads with some of the state's progressive voters. She emphasized her role in unwinding former Gov. Sam Brownback's tax policies and called for a moratorium on data centers. She also spoke against a final deal to lure the Kansas City Chiefs across the state line from Missouri. Ms. Holscher presented an implicit critique of Ms. Kelly's stewardship of Kansas, referring to Mr. Corson as part of a political establishment that was too cozy with corporations and out of touch with the party's voters. "I'm the only Democrat in this race to call for a moratorium on data centers because we have to get these guardrails in place," said Holscher in an interview. "We are having our people and our resources exploited." Read more of this story at Slashdot. - Google Overhauls AI Leadership As DeepMind CEO Steps Aside Google is reshuffling its AI leadership as Demis Hassabis steps away from day-to-day management of DeepMind to become chairman and Alphabet's chief scientist, while CTO Koray Kavukcuoglu takes operational control. Meanwhile, longtime chief scientist Jeff Dean and several prominent researchers are leaving to launch their own company. Axios reports: Hassabis will add the title of chief scientist for Google parent company Alphabet and also continue to lead Isomorphic Labs, the company's AI drug discovery spinoff. Koray Kavukcuoglu, the current chief technology officer of Google DeepMind will serve as senior VP of the unit, reporting to CEO Sundar Pichai. Dean, a 27-year Google veteran is starting Discovery Loop, an independent publicity benefit corporation in which Google will be an investor and cloud provider. Joining him in that effort are Google senior fellow Sanjay Ghemawat as well as Oriol Vinyals, a DeepMind VP and Quoc Le, a Google Brain co-founder. [...] In an interview with The New York Times, Dean indicated that leaving Google, a public company, gives him more leeway to focus on scientific discoveries associated with AI as well. "We might make decisions that are not necessarily in the company's purist financial interests," he told NYT. "I've been working towards AGI my whole life and now, like many of you, I feel it is close at hand," Hassabis wrote. "It's critical that we collectively get the next steps right to ensure this all goes well for humanity and we usher in an incredible new age of discovery and wonder." "With this backdrop, I've decided that now is the right time for me to hand over my day-to-day operational responsibilities at GDM, so that I have the time and space to focus on the big picture and help influence what is to come to the best of my ability" Read more of this story at Slashdot. - Cloudflare Announces Open-Source Cloudflare OS As AI 'Operating System' Cloudflare has open-sourced Cloudflare OS, an Apache 2.0-licensed platform that lets organizations build AI agents, apps, and workflows using curated company data and tools within isolated, governed environments. Despite the name, it is not a traditional operating system but a framework for securely managing organizational AI workloads. Phoronix reports: Cloudflare OS is already used internally at Cloudflare and is described in today's announcement as: "Cloudflare OS starts with a conversation in your browser, like many other AI tools. What makes it different is that each conversation is grounded in the context and skills your organization has curated. Give your workspace a goal, and it can draw on that knowledge and work with the tools and data your organization already uses to achieve it. Cloudflare OS combines three parts: - An agent workspace grounded in context and skills your company curates, with an isolated runtime where agents can write and run code. - A new security and governance framework for safe access to internal data and services. - A platform for personal, modifiable apps that people can build, share, and continue changing. What begins as a conversation can become a doc, an app, or a workflow that continues doing the work." You can learn more at os.cloudflare.app. Read more of this story at Slashdot. - The Days of Walking Into a T-Mobile Store May Be Numbered A leaked roadmap suggests T-Mobile plans to make its T-Life app the primary way customers manage their accounts by the end of 2026, "gradually moving one feature at a time into the app" and away from physical stores, reports Android Authority. That includes upgrades, new-line activations, and eventually new-account sign-ups. From the report: According to an image shared by a Reddit user, the carrier has mapped out the next phase of its app-first strategy. This clearly shows that the T-Life app is set to become the primary way customers manage nearly every aspect of their account by the end of 2026. The roadmap suggests T-Mobile isn't flipping the switch overnight. Instead, it's gradually moving one feature at a time into the app. The concierge experience has already made that transition, while phone upgrade transactions are currently being shifted over. Next on the list is support for adding new lines, followed by what appears to be the biggest change yet. By the fourth quarter of 2026, the roadmap indicates that all new customer accounts will be handled entirely through T-Life. So, many of the tasks that traditionally required a trip to a T-Mobile store could soon be completed from your phone instead. [...] The roadmap also reinforces a direction T-Mobile has been moving toward for quite some time: making T-Life the center of the customer experience. If the timeline holds, the app may soon become a requirement for managing your account. Read more of this story at Slashdot. - Senators Demand Crackdown On Wildfire 'Prediction Markets' An anonymous reader quotes a report from Ars Technica: Several US senators have written a letter to the Commodity Futures Trading Commission (CFTC), inquiring about the agency's "plans to crack down on prediction markets" that offer "contracts for individuals to bet on wildfires." "Offering bets on destructive wildfires threatens to minimize communities' suffering, all so the rich and powerful can profit," wrote (PDF) the group of senators, who represent Oregon, California, Nevada, Minnesota, and New Hampshire. The document specifically cites that Polymarket hosted bets in January 2025 on the wildfires in Los Angeles, and it mentions another website which specifically accepts "simulated bets" exclusively on California wildfires. "There's also the heightened risk -- according to state and local fire officials -- that individuals could be tempted to commit arson in order to make sure their bets are successful," the letter continues. "By offering contracts on fires, prediction market sites run the risk of encouraging people to influence fires that have already started, creating additional concerns around public safety and insider trading." [...] Kalshi spokesperson Elisabeth Diana told Ars by email that the company does not allow such wildfire markets "because they create perverse incentives." But its primary rival, Polymarket, has taken a different approach. A spokesperson for Polymarket told Ars in an emailed statement that the company does not "profit from outcomes," adding that people "come to Polymarket for information." "While we are not blind to the risks, removing these markets does not prevent a tragedy but makes the most accurate information less accessible to the people who need it most," he wrote. Read more of this story at Slashdot. - NVMe Polishes Its Specs, Brings Virtualization to Locally Attached SSDs The latest NVMe specifications add SSD-level virtualization that can simplify live VM migration by preserving storage identities across servers. The updates also introduce support for post-quantum cryptography, controller-based rate limiting, voltage monitoring, and factory-reset capabilities. The Register reports: Announced by the NVM Express consortium, all 11 of the suite of NVMe specs have been updated with new features and engineering change notices. These represent the next step in the evolution of the standard, it says, which was created as a protocol to support storage devices connected to a system's PCIe bus. Perhaps the most significant new capability is PCIe Exported NVM Subsystem Migration. This extends existing NVMe virtualization to locally-attached PCIe SSDs. It does this by abstracting the physical drives into host-defined virtualized NVM subsystems, to allow for virtual machine (VM) mobility without storage reconfiguration. When a VM moves from one server to another, its storage also needs to move with it in a way that's non-disruptive to any applications running in that VM. "With NVM Subsystem Migration, NVMe SSDs can present exported NVM subsystems that hide the complexity of the underlying hardware," says Mike Allison, a senior director at SSD maker Samsung and NVM Express board member. "Instead of interacting with physical controllers and namespaces, the host only sees exported controllers and namespaces. This creates a clean separation between what the VM sees and what's happening under the hood," Allison explains on an NVM Express blog. "One of the key innovations here is providing the host with control over exported identifiers. During migration, those identifiers can be carried over exactly from the source to the destination. That consistency is crucial: even if the underlying hardware uses different internal IDs, the VM sees no change and can pick up right where it left off with no storage reconfiguration required," he says. In effect, the NVMe layer now enables the virtual machine manager (VMM) to rely on virtualization built into the SSD. The flash drive itself exposes logical, virtualized storage constructs, offloading this complexity from the VMM. You can learn more about the updated NVMe specifications here. Read more of this story at Slashdot. |
|