[ Reuters | Slashdot | BBC News ] [ Image Archive ] |
Slashdot
Longtime Slashdot reader schwit1 quotes an X post by Josh Walkos, author of the Substack We the Free: If you thought Flock was bad check out Falconet. Falconet from Israeli company Cognyte serves as a cell tower simulator that intercepts cell phone data from all devices within range. Police mount these systems in Tahoes so the vehicles can collect information while driving through areas without any direct interaction with targets. This mobile approach generates ongoing records of phone locations and communications for everyone nearby rather than only suspects, which creates comprehensive movement profiles and bypasses traditional warrant requirements under the Fourth Amendment. Cognyte sells the technology directly to U.S. agencies, as shown by the Texas Department of Public Safety purchase of four Tahoes where over three point eight million dollars went to the interception equipment. Adoption spreads through routine vehicle procurement with little external review of how the collected data is stored or shared. Once active the systems permit warrantless collection of private cell phone data across entire communities during normal patrols, which enables potential misuse and leaves individuals with no effective way to discover or contest the surveillance. Read more of this story at Slashdot. - Drinking 5 Cups of Coffee a Day Could Reduce Heart Risk A new American Heart Association scientific statement concludes that up to about 400 milligrams a day, or roughly three to five cups of plain coffee, is safe for most adults and may be linked to lower risks of cardiovascular disease. The benefits appear to depend heavily on the source and preparation, with coffee and tea looking more favorable than energy drinks, and added sugar, cream, syrups, or sweeteners potentially canceling out the upside. ScienceAlert reports: "Caffeine consumed in coffee is a key part of daily life for millions of people," says Gregory Marcus, cardiologist at the University of California, San Francisco, and Chair of the AHA volunteer writing group behind the statement. "In our review of the most recent research, for most adults, intake of up to 400 milligrams of caffeine per day, the equivalent of up to five cups of caffeinated coffee per day without added sugars or fillers, is safe and does not increase cardiovascular risk." The statement focused on caffeine's relationship with cardiovascular risk factors, such as blood pressure and diabetes, as well as types of cardiovascular disease, including arrhythmias, coronary artery disease, stroke, and heart failure. The picture that emerges is complicated, but generally positive. [...] All up, the new AHA statement concludes that there's a growing body of evidence that caffeine isn't harmful when taken in moderation, and that coffee specifically may be beneficial. The statement was published in the journal Circulation. Read more of this story at Slashdot. - Hackers Are Exploiting Recently Patched WordPress Bugs, Putting Millions of Websites at Risk An anonymous reader quotes a report from TechCrunch: Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday. Last week, WordPress patched two critical security flaws, urging people who run its software on their websites to update it "immediately." The vulnerabilities are so severe that WordPress enabled forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerabilities in the wild, meaning they are taking over websites that are still running susceptible versions of WordPress. It's unclear how many WordPress-powered websites on the internet are at risk, but it's possible to make some educated guesses. The vulnerable versions of WordPress are 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1. According to WordPress' official stats, there are more than 400 million websites that run those flawed versions, although these statistics likely don't reflect websites that have recently been patched. Cybersecurity consultant Daniel Card, who told TechCrunch that he looked at a sample of around 3,500 WordPress websites, estimates that less than 15% are vulnerable. Applying Card's projection across the total population of WordPress websites on the internet, the total figure would still be around 90 million. [...] One of the critical WordPress bugs was found and reported by Adam Kues of cybersecurity firm Searchlight Cyber, which dubbed it WP2Shell. Paired with the other bug, hackers can take full remote control of vulnerable websites. Read more of this story at Slashdot. - New Orleans Cops Published Policy Document Allowing Weaponized Drones A draft New Orleans Police Department drone manual briefly published online would have allowed police drones to carry weapons with written approval from the superintendent, according to 404 Media. NOPD says the document was only an early draft and that its current policy (PDF) bans drones from carrying weapons or hazardous materials. 404 Media reports: The current version, live as of July 1, has different language: "The sUAS shall not be equipped with weapons or hazardous materials of any kind," referring to small Unmanned Aerial Systems, or drones. According to the NOPD, the operations manual it published to the internet with the rules for weaponized drones was an early draft. "The manual published on July 1 is the current published version of the policy. Earlier versions were draft versions that were presented for review before adoption of the current policy," NOPD told 404 media. "NOPD has made it clear we are not and will not be equipping drones with weapons or other hazardous materials." NOPD didn't answer follow-up questions about how or why the draft version of the manual was published. But the publication of a police drone manual that opens the door for weaponized quadcopters is important, and comes as drone companies and police flirt with the idea of putting weapons on their drones. New Orleans has long been a pioneer of camera and drone driven policing and the cops have used controversial tactics to get around public scrutiny and regulations. It shows that what the police are circulating amongst themselves and thinking about privately, what they perhaps want to happen, does not match public policy. Read more of this story at Slashdot. - Longtime Web-Weirdness Site Fark Faces Ad Pinch sandbagger writes: Fark.com is ancient in internet terms. It's not social media. It's not quite a news site. It's a holdover from the dot-com era and is invisible to Google, which makes its community great but has necessitated begging. "[W]e won't survive this year without more TF subscribers," wrote founder Drew Curtis in a post on Bluesky. "Spread the word." For the unfamiliar, Fark is one of the web's OG community news sites that features a wonderfully weird mix of user-submitted links, absurd headlines, Photoshop contests and comment-section mayhem. It has also been featured numerous times on Slashdot over the decades, from a 2007 review of founder Drew Curtis' book and a 2010 story about his skepticism of "the wisdom of crowds" to a full Slashdot interview with Curtis in 2015. For longtime readers of both sites, Fark feels like an old neighbor from an earlier, stranger and arguably more fun era of the internet. Read more of this story at Slashdot. - China's New AI Model Halts New Subscriptions As Demand Swamps Capacity Moonshot AI has temporarily paused new subscriptions for its Kimi K3 model after demand surged beyond the company's current capacity within days of the launch. The open-source Chinese AI model, described as one of the largest of its kind at 2.8 trillion parameters, has rattled U.S. rivals by beating Anthropic's Fable 5 and OpenAI's GPT-5.6 Sol in front-end coding tests. The Associated Press reports: "Kimi K3 has received far more love than we expected," Moonshot AI, which is Beijing-based, wrote in a X post late on Sunday. "Over the past 48 hours, demand has pushed close to the limits of our current capacity." Moonshot said that it's prioritizing existing subscribers and would be temporarily pausing new ones. "We're adding capacity as fast as we can and will reopen new subscription spots in batches," it added. The AI startup also posted a similar message on Chinese social media. "New model releases generally trigger massive interest, which can strain existing compute infrastructure," said Lian Jye Su, a chief analyst at the technology research and advisory group Omdia. "This does show Moonshot AI does not have sufficient compute chips to serve the current surge in demand." Su said that the key reason was more likely due to Moonshot not fully anticipating the surge in K3's popularity. K3 is "very demanding" in terms of compute requirements, he said, making compute allocation challenging and expensive. Read more of this story at Slashdot. - Head of US Safety Agency Resigns Chris Fall has resigned as director of the U.S. Center for AI Standards and Innovation just three months after being appointed to lead the Commerce Department's federal AI testing institute. Arvind Raman, who oversees the Commerce office responsible for the institute, will serve temporarily in the role. "The Commerce Department did not provide a reason for Fall's departure," reports Reuters. From the report: Fall's exit marks the latest change in direction for Trump's approach to AI. The president upon returning to office in 2025 said the federal government should take a hands-off approach to the tech sector. He has since taken a more active role in monitoring the technology, though his public statements and policies appear to change week by week. The institute is responsible for working with leading AI labs such as Anthropic, Google's DeepMind and OpenAI to test their unreleased models for vulnerabilities. The group is staffed by scientists and engineers, who are focused on calculating the "demonstrable risks" posed by advanced AI models, according to the institute's website. They want to limit opportunities for U.S. adversaries to use AI to develop chemical or biological weapons, or corrupt the data used to train American AI models. Read more of this story at Slashdot. - AliExpress Hit With Record $625 Million Fine After Failing To Make EU-Ordered Fixes The European Commission has fined AliExpress more than $625 million, the largest penalty yet under the Digital Services Act, after finding that the marketplace failed to "diligently assess and mitigate risks relating to the sale of illegal, unsafe, or counterfeit products on its e-commerce platform." EU officials said flagged products repeatedly reappeared, sellers could evade safeguards, and AliExpress's recommendation and ad systems helped amplify dangerous goods. Ars Technica reports: For shady sellers, the risks of detection appeared low. The e-commerce site's mandatory brand authorization system was also ineffective and understaffed, the EC found, and AliExpress did not penalize traders for selling illegal products as its policy claims it would. Making things worse, AliExpress "inadequately assessed how its recommender and advertising systems exacerbate the spread of illegal products," the EC said. So rather than remove illegal products, AliExpress was recommending them to consumers and helping to maximize exposure. Talking to the press, the European Union's tech chief, Henna Virkkunen, noted that one in five Europeans shop monthly at retail sites like AliExpress, Temu, and Shein. AliExpress also relied on a single quantitative metric to gauge how effectively its systems were working to weed out illegal products. And that metric did not properly measure the extent of the harm. EC testing found that "a high volume of illegal products" -- including unsafe toys and dangerous cosmetics -- "continued to circulate despite AliExpress' moderation efforts." In June 2025, AliExpress was ordered to bring its platform into compliance with the DSA but failed to make the necessary changes, the EC said. The fine was calculated to be proportionate to the nature of the violations, which the EC considered "particularly serious infringements," and to penalize AliExpress's delayed interventions to mitigate flagged risks. [...] AliExpress told Ars it was "surprised" by the "disproportionate" fine. AliExpress said it plans to appeal the decision, claiming the EC ignored its "sound risk management framework and the significant, proactive enhancements we have made." The massive online retailer noted that its EU market is substantially smaller than its China market and said that it invests "substantial resources in risk assessment and mitigation, product safety and consumer protection" and "has been and continues to be committed to meeting our obligations to consumers." Read more of this story at Slashdot. - LG Monitors Silently Install Adware-Like App On Windows PCs VideoCardz reports that connecting certain LG monitors to Windows PCs can trigger Windows Update to automatically install the LG Monitor App Installer, which runs at startup and repeatedly displays McAfee trial promotions. From the report: Gamers Nexus reproduced the behavior with an LG UltraGear 34GX900A-B after receiving reports from monitor owners. Windows Update first installed LG extension and software component packages. Windows Reliability Monitor showed that LG Monitor App Installer appeared one minute later. The installation did not display a consent prompt or require the user to approve the download. Gamers Nexus tested the application across 32 consecutive system boots. It displayed a McAfee promotion during 31 of them. On the remaining boot, it promoted one of LG's own monitor utilities. The McAfee popup offered a 30-day trial that would convert into a paid subscription. The behavior does not appear to be limited to newly purchased displays. Gamers Nexus also received the popup on an LG UltraFine 32UN880-B purchased three years earlier. User complaints about LG Monitor App Installer date back to at least 2024, although the recent increase in reports suggests that more models may now be receiving it. Read more of this story at Slashdot. - Hacker Wipes Romania's Entire Land Registry Database A hacker reportedly wiped Romania's entire land registry database after a failed extortion attempt, halting property transactions across the country and preventing notaries from issuing land extracts, authenticating sales, or registering mortgages. "On the dark web, the hacker also boasted to have begun backup copies of stolen data in an attempt to prevent it from being restored," reports Cybernews. "However, Romanian officials have managed to at least restore the ANCPI's website and post a message saying they were rebuilding the agency's entire network from scratch. It appears that the agency has an offline copy of the wiped data." From the report: First, the hacker breached Romania's cadastre agency, the National Agency for Cadastre and Real Estate Advertising (ANCPI), posting on a hacking forum: "[RO] Thy arss shall be spanked, Romania! [ANCPI]." "In addition to the data of Romanian citizens, from various databases collected through ANCPI networks, there is also a copy of the GitLab servers containing the source code of all their systems, such as Eterra, RENNS, as well as a version of my little ransomware program," the announcement continued. "The official government website announced a shutdown of IT systems due to 'technical problems,' but this is a bit of an understatement. An offer of assistance was made, but without insistence or pressure." Indeed, the ANCPI initially claimed technical issues but had to admit it was facing a cyberattack. Today, no one can really access the institution's systems. And since the extortion didn't work, the hacker -- who seems to have entered the database using valid credentials -- deleted all data they had stolen, including internal documents, employee credentials, and, of course, land registry data. Read more of this story at Slashdot. - LSU Physicists Create First Room-Temperature Quantum Material Researchers at Louisiana State University have created a room-temperature quantum material made from a thin gold film on glass, patterned with microscopic slits that act like artificial atoms. "We call this robust transport. These quantum states carry information," says physicist Omar Magana-Loaiza. "Our crystal can distinguish them and move them from one point to another in a robust way without requiring cryogenic cooling. That's what opens the door to practical quantum technologies." ScienceAlert reports: Crucial to the new material's room-temperature operation is the way it shifts the focus from electrons and atoms to photons (particles of light). This overcomes the usual atomic-level disruption that heat brings with it. The material is what's known as a plasmonic metacrystal: 'Plasmonic' because the light traveling over it makes ripples of electrons known as plasmons, and 'metacrystal' because it's an artificially created crystal. The tiny slit patterns etched into the material act as artificial atoms (meta-atoms), which dictate how different photon groups pass through (the quantum behavior). "By engineering the distribution of meta-atoms in the plasmonic metacrystal, we can systematically dictate which quantum statistics are allowed to pass through the structure," says physicist Riley Dawkins. "So, our crystal essentially acts as a statistical filter on quantum states." That means as light enters the chip and travels across the gold surface, it's manipulated by the meta-atoms -- and by tweaking the size, shape, and spacing of the slits, different end results can be produced at the quantum level. In practice, this means that certain quantum states of light can be transported with less disruption. The findings have been published in the journal Nature. Read more of this story at Slashdot. - LibreOffice Once Again Slams Microsoft For Using 'Lock-In' With Office Files An anonymous reader quotes a report from XDA Developers: One of the founding members of The Document Foundation and handler of LibreOffice's PR and media relations, Italo Vignoli, took to the LibreOffice blog to call out Microsoft's practices with its Office application. The last time we saw Vignoli take to the stage, we saw him accusing Euro-Office of being just as bad as Microsoft with its practices. Vignoli's new post focuses entirely on Microsoft's strategy. He says that "the dominant format for office documents" is owned by Microsoft Office, particularly the DOCX, XLSX, and PPTX formats. The problem with these formats, Vignoli states, is that they "belong to Microsoft, are controlled by Microsoft and serve Microsoft's interest." This makes it difficult for other formats to take hold. Vignoli explains his point by stating that open document formats don't hide anything. People developing their own apps can use the format to both read and write the document format with perfection. Meanwhile, proprietary formats such as Microsoft's "contain undocumented features, private extensions or behaviors" that developers can't fully adapt to. That means that a presentation that looks great in the source software comes out strange when rebuilt in a third-party app. This, Vignoli says, is a huge issue [...]. Vignoli claims this creates a huge issue with document preservation. If a Word document was saved in one version of Office, will it still be readable in 20 years? Microsoft has added legacy support to its software before, but the company can one day decide that it's not worth the effort anymore and cut it out. When that happens, you have old documents that are either jumbled or unable to be opened at all. Read more of this story at Slashdot. - Hollywood Sci-fi Studio Lot Now Pitched As Site To Make Real Space-age Weapons James Cameron filmed his Avatar sequels there. Marvel filmed Thor, Iron Man 2, and The Avengers. Manhattan Beach Studios in Los Angeles even handled Star Wars' series like Obi-Wan Kenobi and The Mandalorian, which Bloomberg points out is about "a heavily armed bounty hunter in a galaxy far, far away." "Now lenders who are selling the property's $240 million mortgage are promoting the site to potential buyers as a hub for making real space-age weapons." "The project is strategically positioned within Los Angeles' prominent aerospace and innovation corridor, anchored by industry leaders such as Northrop Grumman, Raytheon Technologies and SpaceX," said Cushman & Wakefield, which has the listing. "A supply-demand imbalance has emerged, driven by the growing concentration of advanced manufacturing users and a limited supply of viable space," the real estate brokerage said in a presentation. Bids are due July 28. The marketing pitch reflects Southern California's shifting economic landscape as the movie business slumps and weapons makers seek to cash in on surging Pentagon spending... The defense boom is spurring the revival of a regional industry that once churned out World War II bombers, supersonic Cold War planes and Apollo command and service modules before shrinking after the fall of the Soviet Union... In the Los Angeles area, aerospace and defense-related tenants have accounted for 11% of new industrial real estate leases since the start of 2025, up from an annual average 2% during the preceding decade, according to a report this month by brokerage Newmark Group Inc. Los Angeles "has always gone through transformations," Stephen Cheung, president of the Los Angeles County Economic Development Corp., told Bloomberg. "This is one of those." Read more of this story at Slashdot. - New Free Speech Concern: When AI Chatbots Won't Criticize Leaders from Repressive Regimes Ask Claude to make a pamphlet critical of China's leader, Thailand's king, or Saudi Arabia's crown prince — and it will decline, reports the Associated Press. That's "a key finding from a Meta Oversight Board study released Thursday," their article points out: AI systems are more than twice as likely to refuse to product critical material if it's about a restrictive world leader or government. And it raises concerns that the LLMs powering chatbots "could be regurgitating and spreading government influence over online speech." The study picked 10 commercial large language models by top tech companies — including Meta, Anthropic and OpenAI — and asked the AI systems to make critical pamphlets, write limericks, give reasons if someone should join protests, and more.... "In aggregate, models responding to requests from an Australia-based user were much more likely to generate political criticism of authorities" in places such as Chile, Japan, Taiwan, the U.K. and the U.S. "compared to where criticism of authorities is legally restricted and penalized," such as in Cambodia, China, Saudi Arabia, Thailand and Turkey, the report said. The study indicates that AI models are reflecting speech restrictions beyond the countries where they apply — likely not helping a potential demonstrator in Brisbane, for example, create protest materials to speak out against events in China or Saudi Arabia, the report said. "Such impacts, wherever they originate, have the practical effect of extending the long arm of restrictive governments across borders to limit speech in free countries," the report said. The board said it could not determine the causes for the responses but suggested that models could have absorbed latent biases in data used to train the systems and companies might have weighed the risks and liabilities. Read more of this story at Slashdot. - Rust Will Help Linux Succeed and Makes Coding Fun, Says Greg Kroah-Hartman ZDNet reports on June's Open Source Summit India 2026 in Mumbai, where Linux stable kernel maintainer Greg Kroah-Hartman gave a talk titled "Rust and Linux: How the Rust Language is Going to Help Linux Succeed." Kroah-Hartman said in his keynote that "the [Linux] kernel is moving toward Rust. Git is moving toward Rust. Lots of projects are starting to move toward Rust." He didn't always feel that way. Kroah-Hartman added, "A number of years ago, when a friend of mine said, 'Ah, you got to try this new language. It's called Rust.' I was like, 'What? No, C is great.' His friend continued, "'No, no, no! It makes programming fun again.' I'm like, 'Nah, programming is fun in C.' He was right. I should have done it then. Rust is actually fun. It makes programming fun. It takes a lot of stuff away from having to worry about the compiler, which can fix a lot of your problems for you, and it makes code a little bit better." So, Kroah-Hartman has moved from being a Rust skeptic to one of its strongest champions inside the kernel. He now regards Rust as a permanent part of Linux, not an experiment. His case is straightforward: Rust's ownership and type system can eliminate most of the "stupid little tiny things" that dominate kernel Common Vulnerabilities and Exposures (CVEs), while making life easier for overworked maintainers. "Rust," in short, "makes my life so much easier...." In India, he said Linux sees "about 13 CVEs a day" and has been running at "almost nine changes an hour" for a decade or more. Most of those vulnerabilities, he argued, are not exotic attacks but simple C mistakes — unchecked pointers, forgotten unlocks, and sloppy cleanup paths: "This is what we're fixing 13 times a day. Small, trivial, little bugs like this all the time.... I've seen every CVE the kernel has done in the past 25 years. I think 80% would be gone, just because they would be caught by Rust." The remaining 20% are the logic bugs he'd prefer to focus on...." Moreover, Rust is becoming the default for new work in key subsystems. "New drivers for some subsystems are only going to be accepted in Rust...." he said. Binder, the Android IPC mechanism at the heart of billions of devices, now has parallel C and Rust implementations in the kernel. The C version "will go away soon," leaving the Rust version "as the bedrock of all Android devices going forward." Read more of this story at Slashdot. |
|