Vue lecture

The US Government Is Letting a Key Data Center Regulation Expire

The Federal Data Center Enhancement Act (FDCEA) is set to expire in September without an apparent replacement, potentially ending requirements for federal agencies to report on data-center efficiency, resilience, energy and water use, and contractor sustainability. Wired reports: Despite the public backlash, the Office of Management and Budget (OMB), the government agency that sets guidance for how agencies implement policies in line with the president's agenda, is not providing any plans for how federal agencies should manage the sunset or continue to implement reporting beyond the timeline of the law. This, current and former workers at OMB and the General Services Administration (GSA) say, signals that the Trump administration is set to take an even more hands-off approach to data center oversight and regulation. A replacement for the requirements laid out in FDCEA would, in other administrations, have been in the works for months ahead of its expiration. An employee with the GSA, the agency that oversees the government's IT services and helps to implement the FDCEA, says that the lack of any sort of plan is highly uncommon. The employee spoke to WIRED on the condition of anonymity for fear of retaliation. "Never in the history of data center policies has a policy expired without another one having been painstakingly worked on for three years behind the scenes," says the GSA employee. "The technology has changed so much it's not about getting everything right, it's about doing the best they can and updating to a new policy. They claim they're going to make sure private companies pay their fare share, but they haven't explained how they'll do that." [...] There has been a burst of data-center-related legislation introduced in Congress this year, from bills that mandate environmental reviews of data centers to bills designed to protect local moratoriums. However, it appears that none of these bills are designed to address the requirements in FDCEA, nor do they specifically address federally run or leased data centers. [...] A search of reginfo.gov, the OMB website that contains reports on the president's Unified Agenda, also turns up nothing for the FDCEA. "By letting this expire, OMB is going to enter into this new age of prioritizing rapid AI development over any sort of centralized control or rigorous standards," says the anonymous GSA employee who spoke to Wired. "In the absence of a new policy from OMB, [GSA] has no directive or measurable standards with which to point agencies towards managing data centers efficiently."

Read more of this story at Slashdot.

  •  

FBI Issues Urgent Kali365 Security Warning For Teams, Outlook, OneDrive Users

alternative_right shares a report from The Hill: The FBI released an urgent security warning to the public about a fast-acting scam targeting Microsoft 365 users on Teams, Outlook and OneDrive. The agency warned that the hacking platform Kali365 seeks out OAuth device codes, allowing scammers to sneak past multi-factor authentication codes, and without the need for a password, to access Microsoft accounts. Scammers will send a phishing email impersonating a trusted document-sharing service with a device code and instructions on how to verify, according to the FBI. "Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities," the FBI stated. The platform is sold to scammers with a $250 per month subscription. The FBI, which first detected Kali365 in April, described the hacking platform as an "emerging Phishing-as-a-Service platform." Hackers with limited skills can access advanced phishing tools through the platform, according to NordPass.

Read more of this story at Slashdot.

  •  

Google Chrome's Next Update Will Mark the End of Popular Ad Blockers

Google is removing Chrome's last remaining workarounds for Manifest V2 extensions, effectively ending support for legacy ad blockers such as the original uBlock Origin. 9to5Google reports: CyberNews points out a Chromium commit that removes support for the "kExtensionManifestV2Disabled" flag, which is referred to as "dead code" seeing as Chrome no longer supports Manifest V2 extensions. This removal acts as the final stop for many Manifest V2-based ad blocker extensions that were still in use today -- the flag was effectively a loophole to continue using these extensions. A Googler on the commit explains: "MV2 extensions are no longer allowed in any supported version of Chrome, and we are removing support for them and the associated functionality. We won't be able to provide / maintain this functionality indefinitely due to the complexity and tech debt, as well as the security risks it entails (we've actually found a number of bugs that are specific to MV2 lately). Of course, other browsers can continue supporting these if they so desire." This will also impact other Chromium-based browsers, though the comment notes that "other browsers can continue supporting these if they so desire." Neowin points out that Microsoft Edge and Opera are likely to follow suit. Chrome 150, set to be released later this month, will remove this flag, while other leftover bits of Manifest V2 will be removed in the v151 release.

Read more of this story at Slashdot.

  •  

Users Cry Foul After AMD Stripped Memory Crypto From Its Consumer CPUs

An anonymous reader quotes a report from Ars Technica: A decade ago, AMD added a protection to its high-end CPUs to protect them against cold boot attacks and other types of physical exploits that siphon sensitive data out of the connected memory chips. Short for Transparent Secure Memory Encryption, TSME encrypts the entire contents stored in memory, making the data useless to physical attackers. Over time, AMD added TSME to lower-end processors, including the consumer version of its Ryzen chips, a CPU that costs less than the Pro version. Over the years, users of these lower-end chips have gotten used to the added security. Recently and without warning or notice, this lower-end line of AMD chips suddenly dropped the protection, and did so in a way that was impossible to detect on Windows machines and required a fair amount of technical work when using Linux. AMD has yet to say why TSME worked on these CPUs, or even to confirm the change. AMD declined to answer questions sent by email other than to say TSME "is a security feature only applied to PRO CPUs as part of AMD PRO Technologies." The statement is the first known time the chipmaker has explicitly made this restriction public. [...] There's no indication that AMD ever advertised or marketed TSME as being available in consumer CPUs. AMD has long said that a related memory protection, Secure Memory Encryption (SME), is available only in the Pro and Epyc CPU tiers. SME is OS-managed. It uses a single key and allows the OS to selectively encrypt individual memory pages. TSME is firmware-managed. It encrypts all RAM with no OS involvement. When active, it provides protection against physical attacks, including cold boot exploits, DRAM interface snooping, and memory module removal. It activates silently when enabled in the BIOS, making it the more practically useful of the two protections. Ben Kilpatrick, a self-described "privacy-conscious Linux hobbyist," discovered that TSME had stopped working on his consumer Ryzen processor despite remaining enabled in the BIOS. He spent months investigating, persuaded MSI engineers to test multiple CPUs, motherboards, and firmware versions, and filed a public AMD bug report that traced the change to newer AGESA firmware apparently disabling TSME on consumer chips while retaining it on Pro and EPYC models. "AMD engineers' comments, such as those mentioned above, and the years of TSME working just fine in the lower-cost tier processors, have understandably conditioned Kilpatrick and other users to reasonably regard it as an expected part of the chip package," reports Ars Technica. "AMD quietly removing it and providing no acknowledgment or explanation strikes these users as something of a betrayal." Joe Fitzgerald, an expert in silicon-level security, said in an interview: "They could have not realized they did it leading to their cagey responses, or they could have done it intentionally and tried to get away with it, leading to the same cagey responses. But I really feel like an explanation should be in order, even if it was 'TSME was never supposed to be supported. We did ship some firmwares that erroneously enabled it, but you shouldn't use them since we can't guarantee it'll work properly.'"

Read more of this story at Slashdot.

  •  

Trump's 'Made In the USA' Phone Is Just a Reskinned HTC U24 Pro

Longtime Slashdot reader necro81 writes: The heavily promoted, $499 T1 "Trump Phone" was originally said to be "Made in the USA" and ship in September 2025. Later, that was downgraded to "Assembled in the USA." Given the Trump Organization's lack of engineering or supply chain expertise, many assumed the "T1" would just be a private-label phone made by someone else. After a number of delays, the first phones are finally shipping. iFixit has performed a teardown and concluded that the T1 is a just gold-painted 2024 HTC U24 Pro -- a device from a Taiwanese company, probably using mainland China design and supply chains. In collaboration with NBC News, the iFixit team examined both phones using CT scans, side-by-side teardowns, and even reassembled a working T1 using a U24 Pro main board. As for "assembled in the USA," that may be true, in the same sense that your phone's repairman can "assemble" a phone from a handful of subassemblies sourced from someone else. Or it may have been assembled in Guangdong, China like the other U24 Pros. iFixit sums it up: "What you have is not an 'American-Proud Design,' but a phone designed in China, made in China, with the vast majority of parts sourced from China. I'm failing to find any stirring of American pride within me. I've certainly felt it before, so I can confirm that it is absent at this time." Quinn Nelson of Snazzy Labs on YouTube also published a comprehensive video of his experience ordering, unboxing, and tearing down the phone. "From pre-order emails landing in Gmail spam thanks to botched DMARC records, to paying for the $47.45 Trump Mobile 47 Plan over the phone, the entire buying experience was a disaster worthy of its own review," writes Nelson.

Read more of this story at Slashdot.

  •  

Britain Unveils Sweeping Ban On Social Media For Under-16s

Longtime Slashdot reader schwit1 shares a report from NBC News: British Prime Minister Keir Starmer has announced a sweeping ban on social media use for those under 16, joining other countries around the world seeking to protect children online. "It's a big step for our country," Starmer said in a recorded video message released Monday. "Social media is making our children unhappy and unsafe, and as a parent, as much as a Prime Minister, I just can't let that go on anymore," he added. The ban will include social platforms like Snapchat, TikTok, YouTube, Instagram, Facebook and X, while there is no intention for messaging services like WhatsApp and Signal to be included, the government said in a release. [...] Starmer's government called Monday's announcement a "landmark" move, saying the new measures would be brought to Parliament before Christmas, with protections expected to come into force next spring. Beyond the blanket social media ban, the restrictions will also include blocks on functions such as livestreaming and stranger communication with children for under-16s, it added. "It's not an easy thing to do. I'll be honest about that," Starmer said. "We haven't rushed into it. We've looked carefully at the evidence, and we'll have to adapt our approach as technology changes, learn from other countries which are taking similar steps." He went on to say that it will face resistance from some of the most powerful companies in the world. "But we will take them on, and we will win, because the need for action could not be any clearer."

Read more of this story at Slashdot.

  •  

Fox Is Buying Roku For $22 Billion

Fox is buying Roku for $22 billion, combining Fox's sports, news, entertainment, Tubi, and Fox One offerings with a streaming platform that reaches about 100 million people. The companies say the merger would create the "third-largest player in US television by share of viewing," while Fox insists Roku will remain open to competing apps after the deal closes. CNN reports: Fox has dabbled in streaming over the past few years -- finally launching its Fox One competitor last August -- but has lacked a serious streaming business with the ability to compete in a space dominated by YouTube, Netflix, Amazon, Disney+, HBO Max, Paramount+ and Peacock. With CNN parent company Warner Bros. Discovery receiving initial US regulatory approval to combine with Paramount, Fox's purchase of Roku became more urgent. [...] The deal is expected to close in the first half of 2027 with the companies forecasting $400 million in savings. "This is a defining moment for Fox, and a natural extension of the deliberate and focused strategy we have been executing for nearly a decade," said Fox CEO Lachlan Murdoch. "Today, we take the next step: bringing together the most valuable live content portfolio in video consumption with the preeminent streaming platform through which America watches it." Murdoch said Roku will continue to offer competing apps. "It's essential that Roku remain open and partner-friendly business. We don't see that changing at all."

Read more of this story at Slashdot.

  •  

Google CEO Largely Avoids Discussing AI In Stanford Commencement Speech

BrianFagioli writes: Google CEO Sundar Pichai delivered Stanford University's 2026 commencement address, but despite leading one of the companies at the center of the AI boom, he spent very little time discussing artificial intelligence. Instead, the speech focused on optimism, working on hard things, and following your interests. The omission is notable given how many graduates are entering a job market being reshaped by AI. While Pichai briefly referenced a "rewiring of technology," he largely avoided discussing AI's impact on careers, automation, or the future of work. Was the Google CEO intentionally steering clear of a controversial topic, or was he simply trying to deliver a timeless commencement speech rather than a technology-focused one? Hyping AI during a commencement speech has been a surefire way to get boos -- unless you're Apple cofounder Steve Wozniak, who reminded college graduates that they already posses "AI" of their own: "actual intelligence." You can read Pichai's commencement speech here. "If you're not from here, California is advertised as being really lush and green. But when I looked out the window, it was more... brown," said Pichai during his speech. "I guess I said this out loud, I'm not sure why. My host, Mrs. Jane Earl, gently corrected me. 'We prefer to call it golden,' she said.And that's exactly what I mean by choosing optimism. It's about reframing for the positive: Where I saw brown, she saw golden. This slight change of perspective had a huge ripple effect on how I thought about the world around me."

Read more of this story at Slashdot.

  •  

Swiss Voters Reject Proposal To Cap Population At 10 Million

An anonymous reader quotes a report from The Guardian: Voters in Switzerland have rejected an unprecedented far-right proposal to cap the country's population at 10 million in a divisive referendum dubbed "the Swiss Brexit." Some 54.79% of voters were against the proposal by the Swiss People's party (SVP) and 45.21% were in favor. Turnout was 58.86%. A different outcome would have obliged the Swiss government to limit the population, currently 9.1 million, to 10 million by 2050, enacting tough restrictions on family reunification, residency permits and asylum if the number had reached 9.5 million before that date. Under the proposals, if the threshold of 10 million people was exceeded before 2050, the Swiss government would have been obliged to withdraw from the country's free movement agreement with the EU -- ending its access to the bloc's single market. The SVP, which has the most seats in parliament, has for years fueled anti-immigrant sentiment, especially concerning workers from neighboring EU countries. The party had insisted that a so-called "sustainability initiative" was needed to address the increase in population, which it argued was putting pressure on Swiss infrastructure, housing, social programs, natural resources and way of life. "Voters were worried about negative consequences for Switzerland's relationship with the EU and for the labour market," said Urs Bieri, from the polling firm GFS Bern. "People are also worried about things like having enough care and health workers. Also, there's a feeling that in the current international environment it's not sensible for a small country to do this."

Read more of this story at Slashdot.

  •  

Mystery Orb Videos, Other UFO Records Released By White House

The Trump administration released another large batch of government UAP records, including videos of glowing orb-like objects appearing to split and rejoin, witness accounts, illustrations, and decades-old investigative documents. Axios reports: The documents indicate that government agents have spent years monitoring, investigating and documenting suspected UAP incidents. At lease some of the sightings took place near sensitive government facilities, according to the reports. Videos showing red and yellow light-emitting orbs, some of which appear to split apart and then reattach as they fly across the sky. The videos were taken by witnesses whom the government deemed "credible." Illustrations and videos showing reenactments of what observers saw, and the positions they were in when they viewed them. Memos from government agents describing their experiences seeing flying objects. An illustration of a grayish-white balloon-like object hovering above an area near Colorado Springs, Colo. An illustration depicting a series of incidents that took place in the "western United States" where government officials reported seeing UAPs in 2023. There also are decades-old records documenting the government's involvement in investigating UAPs, including a 1949 letter then-FBI Director J. Edgar Hoover wrote federal agents after receiving a message from an American citizen expressing their belief they'd seen a non-human-made flying object. The records released by the administration do not express any conclusions as to whether the government believes the UAPs represent the existence of alien life. They also do not indicate any conclusions as to whether UAPs represent a national security threat to the U.S.

Read more of this story at Slashdot.

  •  

World's First Crewed Solid-State Flight Electrifies Aviation's Future

The Helios Horizon has completed what its developers call the first crewed, fixed-wing flight powered by solid-state batteries. New Atlas reports: On June 5, test pilot Miguel Iturmendi lifted off from Zephyrhills Municipal Airport in Florida at the controls of the Helios Horizon -- the first crewed, fixed-wing aircraft ever to fly on solid-state batteries. The flight was neither spectacular in distance nor in duration -- it was a series of short tests to validate the aircraft's weight and balance after the new batteries had been installed -- but it didn't need to be to make history. [...] The Helios Horizon's previous lithium-ion pack delivered 260 Wh/kg (watt-hours per kilogram, a measure of how much energy a battery holds relative to its weight). The new solid-state cells hit 410 Wh/kg, a 60% jump. Chief test pilot and company founder Miguel Iturmendi expects that figure to grow another 40% within two years. Though the battery pack can be topped up over any AC outlet, no special infrastructure needed, fast-charging is also supported for up to 80% capacity in under 15 minutes. The aircraft also recovers energy in flight through wing-mounted solar panels and a regenerative system that spins the propeller as a wind turbine during glides and descents. "Regenerative flight can significantly extend the aircraft's range," Iturmendi said after the test flights. The Helios Horizon itself started life as a Pipistrel Taurus motorized glider. Iturmendi's team added proprietary battery management, a custom propulsion stack, thermodynamic controls, and solar panel wing extensions. The aircraft already holds the world altitude record for electric planes in its weight class, having reached 24,000 ft (7,315 m). The next goal is 40,000 ft (12,192 m), commercial cruising altitude, in stratospheric flights planned for later this year.

Read more of this story at Slashdot.

  •  

Data Center Opponents Have Blocked Or Delayed Projects Worth Nearly $130 Billion In 2026

An anonymous reader quotes a report from NBC News: The first quarter of 2026 produced the most blocked and delayed data center projects on record, according to a new study shared with NBC News. The study -- conducted by Data Center Watch, a project of the AI intelligence firm 10a Labs that tracks local data center activity -- found that data center opponents blocked or delayed at least 75 projects nationwide worth about $130 billion from January through March, the most in a three-month period since the group began tracking in 2023. "The quarter reflected a structural shift rather than a cyclical spike: communities have internalized an opposition playbook, legislative sessions introduced formal regulatory uncertainty, and the number of active opposition groups more than doubled to 833 across 49 states," the authors wrote, noting that the total number and value of data centers blocked or delayed during the first three months of 2026 roughly matched the total for all of 2025. [...] The report found that legislative pushes for moratoriums on constructing data centers ballooned during the first quarter of 2026, sponsored by lawmakers on both sides of the aisle. The report found such proposals introduced in 14 states from January through March, with Sen. Bernie Sanders, I-Vt., and Rep. Alexandria Ocasio-Cortez, D-N.Y., introducing a federal version. Though none of the proposals has been signed into law, one did reach the desk of Democratic Gov. Janet Mills in Maine. She vetoed it in April. More than 300 bills were introduced in statehouses across the country just in the first six weeks of 2026, the authors found, saying it marked "a clear shift from incentive-focused policies toward regulatory oversight as the scale of energy demands became clearer." What's more, the study found that the number of active grassroots opposition groups across the country more than doubled from 396 at the end of 2025 to 833 by March. The authors found that the states with the most opposition groups through that month were Maryland, Ohio and Texas. "In some cases," they wrote, "opposition mobilized before any project was officially filed, the mere rumor of a data center was enough to trigger organized resistance."

Read more of this story at Slashdot.

  •  

Jeff Bezos' AI Startup Aims To Build an 'Artificial General Engineer'

Jeff Bezos says his new AI startup, Prometheus, is working toward an "artificial general engineer" capable of helping design complex physical products such as robots, drugs, manufacturing systems, and rocket engines. The Verge reports: The NYT first reported on Prometheus last November, but now Bezos is sharing more information about the startup after a $12 billion funding round, putting the company at a $41 billion valuation. Bezos serves as co-CEO of Prometheus alongside Vik Bajaj, who co-founded Alphabet's health-focused research group, Verily. The startup currently has around 150 employees. The tools Prometheus intends to build could help develop physical products across several industries, including robotics, drug design, and manufacturing, the NYT reports. "Blue Origin is a perfect example of a company that could benefit from the tools that Prometheus is building," Bezos tells the NYT. "Any company that is building sophisticated devices -- like rocket engines -- would benefit greatly from this kind of technology."

Read more of this story at Slashdot.

  •  

Justice Department Approves Paramount's $111 Billion Acquisition of Warner Bros.

The Justice Department has approved Paramount Skydance's $111 billion acquisition of Warner Bros. Discovery without requiring divestitures or other concessions. The deal still faces scrutiny from state attorneys general. Politico reports: The decision, expected to be announced Friday, paves the way for Paramount to combine with the entertainment and media company behind a vast film and television studio, CNN, and the HBO Max streaming service, which would be combined with Paramount+ to create a new offering boasting about 200 million subscribers. The deal, which would upend the Hollywood ecosystem by combining two historic rival studios, is opposed by many in the entertainment industry who fear it could lead to mass layoffs, among other concerns. After an extensive review, DOJ officials determined the transaction did not pose a threat to competition and declined to challenge it, said the people, who were granted anonymity to discuss sensitive matters. The department approved the merger without requiring any divestitures, behavioral remedies or concessions, according to one of the people. [...] The DOJ's approval does not end the merger's legal scrutiny. California Attorney General Rob Bonta has been reviewing the transaction and could still sue to block the deal despite federal regulators signing off. A spokesperson for Bonta's office told POLITICO earlier this week "the Paramount acquisition of Warner Brothers remains an active investigation." [...] Throughout those discussions, Paramount maintained that the merger would strengthen competition rather than diminish it, creating a media company better positioned to compete with streaming leaders and deep-pocketed technology rivals, according to people familiar with the matter. Hollywood workers fear the merger could trigger another wave of layoffs in an industry already reeling from years of consolidation. Critics argue that billions in promised cost savings will come at the expense of jobs, fewer opportunities for creators and greater concentration of power across film, television and streaming.

Read more of this story at Slashdot.

  •  

ShinyHunters Hacked 100+ Organizations By Exploiting an Oracle PeopleSoft 0-Day

ShinyHunters claims it exploited a critical Oracle PeopleSoft zero-day to compromise more than 100 organizations, including the University of Nottingham, where it says it stole 40GB of student and billing data. "ShinyHunters posted the UK university on its data leak site on Tuesday before publishing the stolen files later that same day, presumably because the school refused to pay the extortion demand," reports The Register. From the report: "University of Nottingham on our leak site is one of the first publicly confirmed incidents," a ShinyHunters spokesperson told us. "We have only just started outreach to affected orgs and are actively looking to reach an agreement with affected orgs." They didn't say when they planned to post the other 100 or so claimed victims. A Google threat intelligence report published Thursday afternoon corroborated ShinyHunters' claims to have compromised more than 100 organizations. Google said it spotted malicious activity, "consistent with the exploitation of CVE-2026-35273," between May 27 and June 9, and notified more than 100 global orgs "whose IP addresses correlated with potentially vulnerable endpoints." Most of these, we're told, are based in the US and 68 percent are in the higher-education sector. Oracle has released a "patch availability document," but it's unclear whether a patch is currently available.

Read more of this story at Slashdot.

  •  

Google Sues Chinese Cybercrime Operation That Used Gemini AI To Send Scam Texts

An anonymous reader quotes a report from TechCrunch: Google is suing to dismantle the infrastructure behind an alleged massive AI-powered cybercrime operation. On Friday, the tech giant announced a lawsuit against an alleged Chinese cybercrime network called Outsider Enterprise, which Google says uses AI in its campaigns to send scam text messages impersonating Google and other brands to steal passwords and credit card numbers. Outsider Enterprise has financially scammed "hundreds of thousands of victims" with losses "estimated in the millions." The group deployed 9,000 fake websites, 1 million fraudulent web domains, and 2.5 million texts sent to Android users in a two-week period, according to Google. "55,000 spam texts were flagged by Android users in just two weeks this past May -- that's more than two text spam complaints a minute," Google said. Google said it uses "AI-powered tools to fight AI-powered scams", which enable the company to detect scams and alert users of suspicious calls and text messages, leading to the interception of more than 10 billion scam messages a month. The company said it has been collaborating with AT&T, T-Mobile, and Verizon to block the scam text messages and said it is coordinating with the FBI, which is taking unspecified law enforcement actions.

Read more of this story at Slashdot.

  •  

Touchscreen Macbook '100% Confirmed,' Says Reputable Leaker

A leaker with a strong Apple rumor track record says a touchscreen MacBook is "100% confirmed. If true, it would mark a major reversal for Apple, which has long argued that the Mac is built for indirect input rather than reaching up to touch a vertical screen. MacRumors reports: Instant Digital has a good track record for Apple rumors and has provided some strikingly accurate information in the past, so it's always worth noting what they have to say about Apple's plans. The claim is also backed by several recent reports. [...] Touchscreen support is expected to be one of several major upgrades coming to Apple's next-generation high-end MacBook Pro models. Other rumored features include M6 Pro and M6 Max chips, an OLED display, a Dynamic Island (i.e., no notch), and a thinner design. The new laptops could also adopt MacBook Ultra branding. Notably, macOS 27 Golden Gate also introduces a more touch-friendly interface, since Apple's Sidecar feature now allows users to tap and interact with macOS interface elements using a finger on their iPad. Apple apparently is not going to advertise the new MacBook Pro/Ultra as a touch-first device like the iPad -- it will be "touch-friendly, not touch-first," according to [Bloomberg's Mark Gurman]. In that sense, Apple will let customers use touch and mouse gestures interchangeably for all functions. Further reading: Steve Jobs Was Wrong About Touchscreen Laptops (2012)

Read more of this story at Slashdot.

  •  

Microsoft Surface Flaw Allowed Unprotected Devices To Be Bricked By a Single Packet

Longtime Slashdot reader Dotnaught shares a report from The Register: For the past 90 days, Microsoft has been quietly patching a firmware flaw in Surface devices that allowed the hardware to be bricked with a single packet, though only for those who have disabled Secure Core and Secure Boot. And the company's Copilot AI software inadvertently helped identify the faulty firmware. According to Jack Darcy, a security researcher based in Australia, his instance of Microsoft Copilot stumbled across the bug after being asked to adjust the screen backlighting on a Surface device. The Copilot-conjured Python script ended up rendering the researcher's laptop inoperable by overwriting the embedded controller firmware. "Copilot autonomously created and executed four progressively aggressive Python scripts during a probe for backlight control values that sent raw SSAM ioctl commands (SSAM_CDEV_REQUEST = 0xC028A501) directly to the SAM microcontroller through the SAM software path," Darcy explained to The Register. [...] "We appreciate the work of Jack Darcy and The Register for reporting this issue under a coordinated vulnerability disclosure," a Microsoft spokesperson said in a statement. "Our investigation found that a deprecated UEFI interface could trigger a boot loop on some devices. To trigger this loop, the user must have administrator privileges and have already disabled the Secure Boot security feature. We have released updates to address the issue for most impacted devices." That means managed devices are not at risk. But those using Linux, or Windows users who have disabled Secure Core and Secure Boot for gaming, or who use custom Windows drivers, or who have USB boot enabled, may still be vulnerable if their systems haven't received the update. We're uncertain about the range of Surface devices affected. Our source said it appears to be all of them (Surface Laptops 3-6, Surface Book 1-3) except for Surface Go models. ARM variants, however, have not been tested. The report notes that Microsoft is planning to move the Surface stack to a more secure architecture based on Rust code. "Our most recent Surface for Business hardware features a major architectural shift in terms of improved reliability and security that spans our embedded controller, UEFI, but also some of our drivers," said David Abzarian, chief architect for Microsoft Surface. "We're investing in the most secure foundation for a PC by building our embedded controller firmware from the ground up in Rust (as part of leveraging and contributing to the Open Device Partnership (ODP)) in addition to a rewrite of the UEFI DXE Core in Rust; these projects are known as Secure EC and Project Patina respectively." "We're also not only shipping some of our drivers written in Rust, but also helping co-develop the framework Windows Drivers in Rust (WDR) to help enable a broad set of partners in the Windows ecosystem to capitalize on these benefits. I will also note that all of these efforts are open-source promoting one of our key security principles around transparency."

Read more of this story at Slashdot.

  •  

Sam Bankman-Fried Loses Bid To Overturn Crypto Fraud Conviction

Sam Bankman-Fried lost his appeal to overturn his FTX fraud conviction and 25-year sentence. Reuters reports: In a unanimous decision, a three-judge panel of the Manhattan-based 2nd U.S. Circuit Court of Appeals said prosecutors' evidence against Bankman-Fried "was, conservatively stated, robust." "While he was publicly reassuring customers, investors and regulators that FTX customer funds were safe, he was simultaneously using FTX as his own personal piggy bank, spending customer funds on real estate, political contributions, and investments," Circuit Judge Barrington Parker wrote on behalf of the panel. Bankman-Fried's lawyers did not immediately respond to a request for comment. They may next ask all the active judges on the 2nd Circuit to hear the case, or ask the U.S. Supreme Court to take up the case. Bankman-Fried is also seeking a pardon from President Donald Trump, according to the Justice Department's Office of the Pardon Attorney. Bankman-Fried was sentenced to 25 years in prison in 2024 for "masterminding one of the largest financial frauds in American history," wrote US District Judge Lewis Kaplan. He was convicted on all charges, including wire fraud, conspiracy to commit securities fraud, commodities fraud, and money laundering.

Read more of this story at Slashdot.

  •  

Infineon to Open German Chip Fab as Part of EU Sovereignty Push

Infineon is set to open a $5.8 billion power-chip fab in Dresden on July 2, backed by about $1.1 billion in EU Chips Act subsidies. The plant will make power semiconductors for AI data centers and could eventually add up to $5.8 billion in annual revenue as demand for AI infrastructure strains global electricity systems. Bloomberg reports: Infineon, traditionally a chipmaker for the automotive industry, has increasingly benefited from soaring demand for power chips used in AI data centers, which will be produced at the new facility. "The AI data centers currently being built and planned around the world will consume twice as much electricity in 2030 as they do today," [said Chief Operating Officer Alexander Gorski]. "That's as much as the entire Federal Republic of Germany." Chip production at the Dresden fab will be scaled over time depending on demand, potentially adding as much as 5 billion euros in revenue per year, Gorski said, declining to comment on when full capacity will be reached. The company has invested around 2 billion euros on construction and the remaining amount will be spent over time to add more machines to the fab, he added. The new facility is "a key catalyst," Bank of America analysts including Didier Scemama wrote in a note last week. Demand from Al customers is materially above Infineon's current capacity, they said, adding the imbalance could improve in the 2027 and 2028 financial years. The analysts raised their Al power revenue forecast for the company by 500 million euros to 4.5 billion euros for 2028. Infineon expects data center-related revenue to rise from around 1.5 billion euros in fiscal 2026 -- roughly 10% of sales -- to 2.5 billion euros in 2027, it said last month. The hundreds of billions of dollars being invested in AI are driving the rapid expansion of data center capabilities around the world. Infineon doesn't produce advanced AI chips, like those designed by Nvidia. But the power semiconductors it plans to produce in Dresden are still needed for AI infrastructure.

Read more of this story at Slashdot.

  •  
❌