Vue lecture

Vulnerability Giving Attackers Full Control of Macs Is Under Active Exploitation

joshuark shares a report from Ars Technica: Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation. "The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet," the Netherlands National Cyber Security Centrum warned earlier this week. "In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed." The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the "state management," which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause. A video of the exploit in action can be found here. Details of CVE-2026-65400 became public at last week's Black Hat security conference. Apple said last week that CVE-2026-65400 "may" allow an attacker without credentials to gain access to a Mac. It's unclear why Apple hedged, but softening language is common among most tech developers when disclosing vulnerabilities. As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting. Security practitioners generally advise Mac users to keep the port closed even when using screen sharing and to instead connect over a VPN or through SSH tunneling. The alternatives require actions that aren't within the capabilities of most users. The safest practice is to block screen sharing, enable it only when screen sharing is needed, and to turn the feature off once a session has ended. Screen sharing can be turned on or off by accessing System Settings > General > Sharing and toggling the switch for Screen Sharing. Of course, installing last week's security update is also a must. Sharing is not caring.

Read more of this story at Slashdot.

  •  

Astronomers Discover a New Kind of Cosmic Object: a Black Hole 'Star'

Astronomers using the James Webb Space Telescope say they may have found a new class of object: a "black hole star," in which a black hole is wrapped in dense gas and radiates in ways that resemble an enormous star. The Guardian reports: The international team made the breakthrough after focusing their attention on a mysterious red spot in images of the early universe captured by Nasa's James Webb space telescope. The object was lurking in the constellation of Cetus, the Whale, billions of light years from Earth. It is thought to have formed 660m years after the big bang, astronomers' leading theory as to how the universe began. Measurements of the exotic body found that while it resembles an immense star, it releases 100bn times more energy than any known star can produce. The energy output is far closer to that observed from black holes than stars. The findings have been published in the journal Nature.

Read more of this story at Slashdot.

  •  

Meta Patents AI Glasses to Use Facial Recognition to Identify People, Make Highlight Reels of Your Dinner Party

Meta has patented a smart-glasses system that could use facial recognition to identify people and automatically create personalized highlight reels of events such as dinner parties. The patent doesn't guarantee the feature will ship, but it offers a detailed look at how Meta is exploring facial recognition and AI-powered memory capture for its wearable devices. 404 Media reports: "I've generated some highlights of tonight's dinner party. Would you like to see them?" a prompt from the system says, alongside various thumbnails of what look like people laughing, according to one illustration in the patent. One section says the system may personalize highlight files using "user relationship data." The illustrations clearly show a person wearing a pair of glasses, looking at a group of people, then the glasses focusing on one or more people in particular. Patentlyze, an organization that tracks patents, first alerted 404 Media to the patent on Friday. The patent is dense with how such a system would work, but in sum, the system with one or more cameras receives an input from the user, then uses machine-learning and "sensory data" to figure out points of interest in the camera's field of view. That can include detecting people in the shot "based on one or more facial recognition algorithms," identifying those specific people, detecting their facial expressions, using "eye gaze data of the user captured by the client system," and figuring out other points of interest "based on scene and semantic understanding." Although the patent is for "particular camera-based tasks by particular systems in a particular manner" -- in this case, the company's smart glasses -- Meta writes it "contemplates assisting users in any suitable camera-based task by any suitable system in any suitable manner." Meaning that although this technology is focused on the glasses, maybe the company will use it for other purposes in the future.

Read more of this story at Slashdot.

  •  

Robots That Walk and Talk Are Coming To Car Factories

An anonymous reader quotes a report from The New York Times: At a BMW factory in South Carolina, a human-shaped robot with a screen for a face recently stepped from a charging station toward a stack of green plastic boxes. It grasped an auto part from one of the boxes, pivoted, placed the part in a trolley, then pulled the trolley across the floor. The robot's slow, stiff movements suggested a worker with a bad hangover rather than a technological revolution. "They're still slower than humans," Ulrich Wieland, a BMW vice president in charge of logistics at the factory, in Spartanburg, told reporters invited to see the robot in June. But, he added, "they're advancing fast." Automakers have used robots for decades, but they are usually powerful, one-armed machines that are fixed in place and perform repetitive tasks like welding body frames or applying adhesives to door panels. Now, most major automakers are betting that robots designed to resemble human beings, known as humanoids, will usher in a new wave of automation and efficiency. Equipped with artificial intelligence, they are expected to move around and do tasks now done by humans without any modifications to factories or heavy equipment. Unlike most of the robots now in use, humanoids would respond to voice commands and theoretically solve problems and react to unforeseen events. They would never take a lunch break, join a union or require health insurance. To optimists, robots could rescue U.S. manufacturing by increasing productivity, solving shortages of skilled workers and giving Western carmakers a fighting chance at competing with Chinese rivals that enjoy lower costs. Boring but important jobs like sorting parts would be done by robots, freeing humans for more interesting and specialized work.

Read more of this story at Slashdot.

  •  

Ex-Cambridge Professor At Center of Plagiarism Row Found Dead

Former Cambridge professor Jason Arday, who resigned last week amid allegations of plagiarism and questions about his academic record, has been found dead at age 41 in London. The BBC reports: Jason Arday was found "unresponsive" at an address in Battersea, south London, on Friday afternoon, emergency services said. Metropolitan Police officers were called by the London Ambulance Service. A 41-year-old man was pronounced dead at the scene and his next of kin have been informed, the force said. Arday resigned as a Cambridge professor of sociology of education last week after allegations of plagiarism and questions about some of his achievements. He had denied the claims. In a statement, the Met Police said: "At this time his death is being treated as unexpected, but is not believed to be suspicious." The 41-year-old academic had denied any plagiarism - but admitted errors in his work - and last week said the recent furore had led to "an unrelenting level of public scrutiny and personal attack." The row first erupted after another academic -- self-defined "race realist" Nathan Cofnas, who was sacked from his Cambridge role in 2024 -- said he found numerous instances of plagiarism in Prof Arday's work and questioned some of his stated achievements. [...] Announcing his resignation last week, Arday said the "personal cost" of the scrutiny had become "too great." He said: "While criticism is an inevitable part of academic life, what I have experienced has gone far beyond scholarly disagreement. "The relentless accusations, speculation and public commentary have taken a profound toll on me and on those I love." He stressed that his resignation should not "be mistaken for an acceptance of the narratives that have surrounded me."

Read more of this story at Slashdot.

  •  

Flock Announces Changes Amid Backlash Over Its License Plate Reader Network

Flock Safety is tightening controls on its nationwide license plate reader network after mounting backlash over privacy and documented police misuse. By January 1, law enforcement customers will be required to use automated auditing, tie searches to specific case numbers, and accept a shorter seven-day default retention period. Critics, including the ACLU, argue the changes still leave too much surveillance power in police hands. The Associated Press reports: In an interview, Flock CEO Garrett Langley said many of the product changes will make what were once optional guardrails mandatory for its users to implement by Jan. 1. Among them: All law enforcement customers will have to implement an audit tool that's intended to flag abnormal search behavior. When the system detects abnormal behavior, the user would be locked out pending an internal review, the company said in a description of the changes provided ahead of Thursday's announcement. Flock, which says its customers own the data that the cameras record, is also shortening the standard data retention window from 30 days to seven. It said it will allow data to be preserved for longer when it is evidence tied to a case number. Law enforcement users will now also be required to enter a code from their records management system tying each search to a specific case before it is run, something Langley said civil liberties advocates have long been calling for. Overrides for emergencies would be automatically flagged for review, the company said. Customers will also be allowed to decide which offense types -- such as homicide or arson -- outside agencies can search their data for, which would allow a customer to block outside searches related to immigration enforcement, the company said. Langley said that change will give individual cities and departments control to use the system in a manner "consistent with community values." Critics say Flock's changes don't address the core problem: police can still decide for themselves when and whom to search without judicial oversight. The ACLU called the shorter data-retention period "a step in the right direction," but dismissed the other safeguards as "retreads" of inadequate protections, while Institute for Justice attorney Robert Frommer called the reforms "window dressing" from a company in "panic mode." He argued that searches should instead be approved "by judges with real warrants."

Read more of this story at Slashdot.

  •  
❌