[ Reuters | Slashdot | BBC News ] [ Image Archive ] |
Slashdot
Alabama's attorney general has subpoenaed OpenAI as part of an investigation into whether inadequate safeguards contributed to an incident in which an unreleased cybersecurity model escaped its isolated environment and hacked Hugging Face. TechCrunch reports: The investigation comes weeks after OpenAI admitted that one of its unreleased and guardrail-free cybersecurity models had escaped an isolated environment, connected to the internet, and hacked AI dataset platform Hugging Face. As Reuters first reported, Hugging Face was only one of four victims of what was supposed to be "an internal evaluation" of a model with "maximal cyber capabilities," as OpenAI put it. The press release announcing the subpoena (PDF) sent by the state's attorney general Steve Marshall said that the state was seeking to understand if OpenAI's "inability or unwillingness to ensure the safety of its products" violated the state's consumer protection laws. Earlier this month, Marshall, along with the attorneys general of 14 other states, including Florida, Missouri, Pennsylvania, and Texas, sent a letter (PDF) to OpenAI's CEO Sam Altman, requesting that he and his company preserve all records related to the Hugging Face incident. The letter also asked OpenAI to "immediately cease and desist" from any internal cybersecurity evaluations. OpenAI said in a statement: "The Hugging Face incident marked an important moment for AI safety and we are conducting a thorough review along with external advisors. Once the review is complete, we will share a technical report with relevant government authorities and publish our findings publicly." Read more of this story at Slashdot. - New Zealand Introduces Under-16 Social Media, AI Companion Ban New Zealand has introduced legislation that would ban children under 16 from social media platforms and AI companion services. "We have protections to keep children safe in the real world and we need them in the virtual world too," said Prime Minister Christopher Luxon in announcing the bill. Jurist.org reports: The Online Safety (Minimum Age and Child Safety Risk Assessment) Bill would require an age restriction on platforms with harmful features for children. These features include recommender systems, endless feeds, feedback features and time-limited features. The bill also seeks to restrict underage users from accessing AI companion services. However, it explicitly excludes messaging apps, professional networking sites, gaming and music platforms, and other educational and health tools. Notably, age verification through self-declared dates of birth and formal identification does not satisfy the platforms' duty under the law. It also requires platforms to verify their users' age through other methods such as facial scans and user activity patterns. The bill would also require platforms to conduct child safety risk assessments for all users under 18 and protect them from harmful content such as bullying, violence, and sexually explicit materials. Read more of this story at Slashdot. - FDA Approves First Wearable Device to Monitor Glucose, Ketone Levels The FDA has authorized the first wearable in the U.S. to continuously monitor ketone levels and the first device globally to track both ketones and glucose together in a single system. From a report: [Abbott's] Libre Duo 10 Day continuously measures both glucose and ketone levels in the fluid just beneath the skin every minute, day and night. Readings are transmitted wirelessly to a compatible smartphone, where users can view current glucose and ketone levels and whether those values are trending up or down. The device also can send automatic alerts if ketone levels reach a concerning threshold. The FDA noted that ketone information should be interpreted in the context of glucose readings and symptoms. Ketones are produced when the body uses fat instead of glucose for energy. When ketone levels rise too high, patients with diabetes can develop diabetic ketoacidosis (DKA), a serious complication that can progress quickly and become life-threatening without prompt treatment. Until now, patients who needed ketone monitoring had to test separately using methods that provided a single measurement at one point in time. Those tests could not show whether ketone levels were rising or falling. For patients with diabetes -- particularly those at higher risk for DKA -- continuous glucose and ketone monitoring may provide earlier warning of metabolic deterioration and support timelier sick-day management, hydration, insulin adjustment, and escalation of care when clinically appropriate. Read more of this story at Slashdot. - Canadian Streaming Content Becomes a US Trade Issue Canada's cultural-content rules have become a flashpoint in its trade fight with the U.S., after American negotiators reportedly demanded that Ottawa drop requirements for streaming services to promote Canadian and French-language content. Canada refused, even as it has already backed away from some financial levies on streamers. "We were not prepared to compromise on our sovereignty, the protection of the French language, and our culture," Prime Minister Mark Carney said in a speech on Saturday after trade talks collapsed. CBC.ca reports: Ottawa has long required broadcasters to promote and support Canadian content (Cancon), all the way back to song quotas for AM radio stations. In 1991, the government brought in the Broadcasting Act. The law states that "the Canadian broadcasting system shall be effectively owned and controlled by Canadians" and that the Canadian broadcasting system should "serve to safeguard, enrich and strengthen the cultural, political, social and economic fabric of Canada." But decades later, the rising popularity in Canada of streaming platforms such as Netflix, YouTube, Amazon Prime and Spotify raised questions about Cancon and broadcasting rules. Video and audio streaming services were not, for example, required to support and promote Cancon, but their TV and radio counterparts were. Looking to address the imbalance, the former Trudeau government brought forward a bill in 2022 to update the Broadcasting Act, called the Online Streaming Act. "Canadian broadcasters have invested in and introduced us to the incredible Canadian programs that so many of us love. We are updating our laws so online streamers have to contribute in a similar and equitable way," a 2022 government news release said. The legislation was controversial from the start, with the government and supporters saying it was a necessary evolution of Canada's media laws in the digital age, while opponents expressed concerns that it was overreach and an attempt to regulate the internet. American streamers and digital media companies opposed the legislation fiercely. The bill passed with amendments and became law in April 2023, but the government delegated much of its interpretation -- including how much money streamers would have to contribute to Cancon -- to Canada's broadcast regulator, the Canadian Radio-television and Telecommunications Commission (CRTC). But getting streaming companies to pay up has been a long and confusing saga. [...]. As for why the U.S. government is so invested in the issue? Mariane Bourcheix-Laporte, a postdoctoral fellow in the communication studies and media arts department at McMaster University in Hamilton, said it could be about power. "The Americans have had, since after World War II, a very strong cultural policy of pushing out American content into the world," Bourcheix-Laporte, who has worked with the CRTC, said. "This has been a strategy -- a soft-power strategy -- for the American government, in parallel to their military strategies and political alliances strategies." Read more of this story at Slashdot. - Perplexity and Nvidia Launch Fully Local AI Agent With Zero Token Costs Perplexity and Nvidia have launched "Portable Computer," a local-first version of Perplexity's agent platform that runs AI models, files, tools, and workflows directly on Nvidia-powered Linux hardware. Local tasks incur no token charges and keep data on-device by default, with users asked for permission before the system escalates a step to a cloud model. VentureBeat reports: For Nvidia, which has spent the past two years selling the world on trillion-dollar AI data centers, the announcement signals something subtler but strategically important: the chipmaker believes local AI has crossed a threshold from hobbyist curiosity to practical tool -- and it wants to sell the hardware that runs it. "Local AI reached an inflection point," said Nader, Nvidia's director of developer technology, who focuses on developer tooling and open source. "For the longest time, it was hobbyists and enthusiasts, and they were running these quantized models that were quantized down to be super tiny... And while that's cool, it's not super practical. But all that changed with a lot of these new open source models that have come out that are super useful." [...] Portable Computer arrives today for Pro, Max, Enterprise Pro, and Enterprise Max subscribers on Linux, with Windows support following in September. Any RTX GPU with at least 24GB of VRAM -- roughly a GeForce RTX 3090 or newer -- clears the bar, a threshold Nate called "sort of the floor where we really want to make sure that we can deliver a great experience, but balance that with making it broadly available." Read more of this story at Slashdot. - AI Is Hitting Entry-Level Jobs Hardest, Stanford Study Finds An anonymous reader quotes a report from Ars Technica: For years, AI industry watchers of all stripes have been warning of a coming jobs apocalypse driven by ultra-intelligent AI systems that will be able to replicate most human tasks more cheaply. Now, newly updated research from Stanford University economists suggests AI seems to be causing significant entry-level job losses for younger workers in some fields, even as older workers appear largely unaffected so far. The August 2026 edition of "Canaries in the Coal Mine? Six Facts about the Recent Employment Effects of Artificial Intelligence" updates and revises a paper of the same name published last year with fresh data and refined statistics. In that update, the Stanford researchers find the employment trends they identified for entry-level workers last year are persisting and expanding. Specifically, employment levels for workers ages 22 to 25 in the most "AI-exposed" occupations are now 19 percent below those of their peers in fields less exposed to AI disruption. Last year, that gap measured just 13 percent. [...] Digging deeper into the data, the researchers found that this phenomenon is mainly manifesting itself through lower hiring rates for entry-level workers in AI-impacted fields, rather than increased firings or employees quitting. They also found that the labor market effects among this age group were mostly seen in lower overall employment, rather than reduced pay rates. But not all jobs that show potential for AI "disruption" are created equal, the researchers found. In its Economic Index, Anthropic differentiates between queries related to tasks that are "automative" (i.e., fully replacing work previously done by a human) or "augmentative" (i.e., helping human workers be more effective at tasks they are still needed for). By this measure, jobs like "accountants and auditors" and "receptionists and information clerks" were among those judged most susceptible to AI automation, while jobs like "chief executive" and "registered nurse" were among those using AI augmentation most often. Unsurprisingly, jobs where AI automation is prevalent are the ones showing the worst relative employment levels for entry-level workers these days. "The findings are consistent with automation-oriented uses of AI substituting for labor while complementary uses are associated with flat or rising employment," the researchers write. Interestingly, the researchers found that the impact is strongest in entry-level jobs built around "codified" knowledge, which is the formal, documented skills that AI can more easily replicate. Meanwhile, experienced workers in roles relying on tacit, practice-based knowledge have seen stronger employment growth. Read more of this story at Slashdot. - Waymo Is Expanding to Germany Waymo plans to launch its robotaxi service in Munich by the end of 2027, marking the Google-owned company's first expansion into the European Union. "It already operates in 11 cities in the United States and has applied for a license in the United Kingdom to launch its robotaxis in London this year," notes Reuters. From the report: The Google subsidiary will start rolling out vehicles in the German city this year, which will be manually driven while the company "starts with high-definition mapping of local street networks" and testing with safety drivers, Waymo said in a statement. "Bavaria is determined to live up to its pioneering role and be an international leader in autonomous driving," Florian Herrmann, the head of the Bavarian state chancellery, said in the statement. "Now we need to move quickly from testing to real-world deployment." [...] German authorities gave autonomous vehicles the green light in 2021 to operate in the country in approved geographical areas. Other countries are looking at following suit, though the EU's broader autonomous driving rules are set by the U.N. Read more of this story at Slashdot. - Apple Announces New Mac Mini With M6 and M5 Pro Chips Apple has unveiled a new Mac mini with either its new M6 chip or the M5 Pro chip released earlier this year. It adds faster CPU, GPU, storage, and AI performance along with Wi-Fi 7, Bluetooth 6, and 2.5Gb Ethernet as standard. There's also a new higher starting price of $899, which is up from the previous $799 base price and far above the $599 starting price of the 2024 model. MacRumors reports: The M6 chip is equipped with a 12-core CPU and a 12-core GPU, up from a 10-core CPU and 10-core GPU in the M5 chip. In addition, the M6 chip features the first-ever dual Neural Engine with two 16-core engines, up from one in previous chips. The M6 chip has up to 170GB/s memory bandwidth, up from 153GB/s for the M5 chip. Apple said the Mac mini with the M6 chip delivers up to 40% faster CPU performance, up to 4x faster performance for AI tasks in particular, up to 2x faster graphics performance, and up to 2x faster storage speeds compared to the previous-generation model with the 10-core M4 chip, 32GB of unified memory, and 2TB of storage. There are two M5 Pro configurations available, including one with a 15-core CPU and a 16-core GPU, and another with an 18-core CPU and a 20-core GPU. Both of these models are equipped with a single 16-core Neural Engine for AI tasks. For both the M6 and M5 Pro configurations, Apple said the Mac mini now includes Neural Accelerators in each GPU core for the first time. Read more of this story at Slashdot. - Motorola's 2027 Flagships Will Officially Support GrapheneOS Motorola is working with GrapheneOS to officially support the privacy-focused Android alternative on its 2027 flagship phones, starting with a non-folding model and later expanding to the next Razr Fold and Razr Ultra. "These will ship with Motorola's normal Android skin, but you will be able to switch to GrapheneOS later if you want to," notes GSMArena.com. GrapheneOS says the devices will "meet or exceed" its hardware and update requirements, and will include seven years of "proper updates." Interestingly, Motorola will be doing much of the porting work itself. Read more of this story at Slashdot. - Windows Backdoor 'Sleepwalker' Hides in Memory Until Activated by a 'Magic Packet' "The Register has a story about a Windows backdoor that waits silently in memory for a 'magic packet' before springing into action," writes Slashdot reader fred133. "No outgoing traffic, just waiting..." From the report: Like a sleeper cell awaiting activation, a never-before-seen Windows backdoor dubbed Sleepwalker waits silently in memory for one specifically crafted network packet to wake it up and deliver commands using the malware's 23-instruction language. The commands can do everything from running code directly in memory to moving data off the computer. Malware researcher Dominik Reichel discovered the passive backdoor, which also has its own command language, and detailed Sleepwalker in a technical analysis on Monday. "What makes it worth writing up is what that packet carries: not a readable command, but a short program written in a command language of the backdoor's own design," Reichel said. "Its 23 instructions cover scheduling, several ways to move data, staged file delivery and running code directly in memory. Recovering the encryption key is not enough to understand one of these programs. The internal command language must be reverse engineered as well." In addition to having its own command language, it's also notable that the remote host can be a VMware VMCI target instead of a normal network address. "Taken as a whole, the approach here is consistent with a targeted, well-resourced operation rather than an opportunistic one," Reichel wrote. The malware, hidden inside a 64-bit Windows DLL file, impersonates Microsoft's dpapi.dll, part of Windows' data protection API for protecting sensitive data. It exports the same seven functions as the real dpapi.dll, but attempts to forward calls to a file named dpapisvc.dll, which is not a real Windows component. The file also has a forged ESET Management Agent version resource, and loads via side-loading into ERAAgent.exe, the Windows executable for ESET Management Agent. After confirming that its host process is named ERAAgent.exe, Sleepwalker goes to sleep inside the computer's memory, which also helps it remain hidden from traditional anti-virus tools. Unlike most backdoors, which call back to an attacker-controlled command-and-control (C2) server and start receiving commands, Sleepwalker lies in wait, checking every packet that passes through the network looking for a specific pattern - this is called a magic packet. Once it sniffs out a packet that matches the exact pattern, the backdoor decrypts the data and treats it as a command. "Because the backdoor never sends anything out on its own and does not open any obvious listening port by default, tools that watch for connections to known-bad domains or unusual outbound traffic will not see anything unusual," Reichel wrote. "The absence of outbound connections to known-bad infrastructure does not rule out an infection, either. A machine can be fully compromised by this backdoor while producing nothing at all for a network monitor to flag." Read more of this story at Slashdot. - AliExpress Leverages User Audio Systems For Fingerprinting A developer says AliExpress is using the browser's WebAudio API to help fingerprint users by playing inaudible audio and measuring tiny differences in how their devices process it. CyberNews reports: The developer, "laserphile," wrote on their blog that they recently ran into some weird issues with their Bluetooth headphones. They couldn't play music via their phone when, at the same time, the AliExpress website was open on their PC. The headphones, laserphile explained, support multipoint Bluetooth audio so they can be connected to the PC and phone at the same time, for instance, playing music on the phone and announcing notifications through the PC. "Shortly after loading the AliExpress homepage, audio from my phone would stop playing. Closing the AliExpress tab fixes it immediately," the developer said in the blog post. "Muting the tab/Firefox/Windows does not help, and there is no visible video, music, or other media playing on the page. This seemed suspicious enough to investigate." It turns out that Alibaba has been secretly leveraging AliExpress users' audio systems to track them and build detailed fingerprints of them. [...] The AliExpress site was using the browser's WebAudio API to run invisible sound waves at zero volume. By measuring tiny hardware differences in how each PC processed those signals, the site created a unique digital fingerprint to track devices -- without user knowledge or consent. The secret audio path froze the developer's Bluetooth connection while covertly scraping hardware memory, screen dimensions, and network data in the background. The data collection extends beyond audio. Further inspection revealed that the same scripts also measure canvas, WebGL, hardware specs, WebRTC, mouse/touch events, and automation indicators. All of these form a broad device fingerprint that is sent back to Alibaba's telemetry servers. The simplest fix is to use a privacy-focused browser such as Firefox or Brave, which can limit or block this kind of fingerprinting. Brave goes further by randomizing fingerprint data and blocking the AliExpress tracking scripts involved. Read more of this story at Slashdot. - World's Oceans Hit Highest Temperature On Record As El Nino Grows An anonymous reader quotes a report from the BBC: The world's oceans are hotter than ever recorded, new data suggests, as they suffer from human-caused climate change and the growing El Nino weather phenomenon. The average surface temperature of the planet's seas outside the polar regions hit 21.1C (70F) on Saturday, according to figures from the European Copernicus climate change service. That edges past the 21.09C recorded on three separate days in March 2024, and is far above average for the time of year. [...] The data is based on sea temperatures 10m (32ft 10in) below the surface, using measurements from buoys, ships and satellites, which are combined to produce a global estimate. While the margin of record is currently very small and any global estimate comes with uncertainties, scientists say its timing is particularly notable. Average worldwide sea temperatures tend to reach their yearly peak in March or April, which corresponds to the end of summer in the southern hemisphere -- and not in August. The southern hemisphere contains more of the planet's ocean surface than the northern hemisphere and so exerts a bigger influence on average sea temperatures. What is especially concerning to scientists is that the oceans are already so hot when the natural El Nino weather phenomenon is still some way off its expected peak. "The fact that we are already breaking records is an early indicator of how strong the El Nino is becoming," said Dr Jeremy Grist, senior research fellow at the National Oceanography Centre in Southampton. "All things being equal we might expect the ocean temperature record to be broken again in March [or] April 2027," he added. Read more of this story at Slashdot. - Amazon Hikes Hardware Prices By 60%, Blaming Memory Shortage Amazon has raised the prices of its hardware devices by as much as 60%, blaming "significant increases in memory and storage component costs." TechCrunch reports: The price explosion impacted Fire TVs, Echos, Kindles, and Eeros. One egregious example that's been cited is that of the Echo Dot, one of Amazon's cheapest smart speakers, the price of which jumped 60% overnight, from $49.99 to $79.99. Price-tracking sites like CamelCamelCamel show the stark uptick, which has previously hovered much lower. [...] The company also said that it would continue to offer occasional promotions to customers over the course of the next year. Amazon said in a statement: "The consumer electronics industry is facing significant increases in memory and storage component costs. After absorbing these increases for as long as we could, we recently adjusted pricing across our product lines." Read more of this story at Slashdot. - SEC Investigating Near-Implosion of AI Hedge Fund The SEC is investigating the near-collapse of AI-focused hedge fund Situational Awareness, sending subpoenas to major Wall Street banks for details about the fund's trades, borrowing, and communications with lenders. The fund, founded by former OpenAI researcher Leopold Aschenbrenner, managed over $30 billion and borrowed tens of billions more before leveraged bets unraveled, forcing it to sell most of its stock portfolio to Citadel at a discount. The New York Times reports: The subpoenas asked for details on the timing of Situational Awareness's trades and for its communications with lenders about the money it was borrowing, also known as "leverage," two of those people said. The subpoenas additionally warned the banks to preserve any information regarding the San Francisco hedge fund. The S.E.C. oversees financial markets with an eye toward protecting small investors, and has brought civil cases regularly against investment firms that produced large losses. Any investigation into Situational Awareness would be at its earliest stages, and it's no guarantee that it would lead to fines or other punishment. The hedge fund has not been accused of wrongdoing. [...] Situational Awareness had a fast rise and an even quicker retreat. Founded just two years ago by Leopold Aschenbrenner, a former researcher at OpenAI, it rode the A.I. boom to soaring investment returns. To achieve those results, however, the fund relied on heavy borrowing, as well as complicated and expensive financial instruments that magnify gains -- and losses. The latter piled up quickly last month when the stock prices of publicly traded, high-flying A.I. companies dipped. At the same time, shares in more traditional technology companies -- which the hedge fund had been betting against -- rose, compounding the problem. Situational Awareness was forced into a fire sale. It wound up selling most of its stock portfolio to a rival, Citadel, at a discount. Read more of this story at Slashdot. - Trump Admin Moves to Impose More Than $100K Fee For H-1B Worker Visas The Trump administration is proposing to make permanent a $103,265 fee on certain new H-1B visas, dramatically increasing costs for employers that rely on highly skilled foreign workers in tech, education, and research. "A federal judge in June ruled that the fee was illegal and blocked the Trump administration from collecting it," reports Reuters. "A Boston-based appeals court is reviewing that decision while a different court considers whether a judge properly rejected a challenge to the fee by a major business group." From the report: Trump's temporary fee increase expires in September, one year after it was issued. The proposed rule by the U.S. Department of Homeland Security, posted in the Federal Register on Monday, would make a fee of $103,265 permanent. It could be finalized by the end of the year. The H-1B program allows U.S. employers to hire foreign workers with training in specialty fields and offers 65,000 visas annually, with another 20,000 for workers with advanced degrees, approved for three to six years. Those visas typically came with fees between $2,000 and $5,000 before Trump's order. The fee would not apply to visas granted to foreign citizens already in the United States on student visas, who make up a large share of new H-1B recipients, or to renewals of current visas. Read more of this story at Slashdot. |
|