Vue lecture

US Mulls Policing Social Media of Would-Be Citizens

The U.S. Citizenship and Immigration Services (USCIS) is proposing to expand mandatory social media screening, currently required only for new arrivals, to include all non-citizens already residing in the U.S. who apply for immigration benefits. The Register reports: Back in 2019, the Department of Homeland Security, which runs USCIS, decided anyone looking to enter the US on a work visa or similar had to hand over their social media handles to the authorities so that they could be looked over for wrongdoing and subversion. In fact, this goes back to 2014, at least, to one degree or another, and has been standard procedure for years for foreigners, particularly those coming in on a visa. [...] On January 20 this year, President Trump signed an executive order calling for much tougher vetting of foreign aliens, and in response, USCIS has proposed rules saying those already in the country who are going through some process with the agency -- such as applying for permanent residency or citizenship -- will have their social media scanned for subversion. That means if you came to America before foreigners' internet presence was screened as it now is, and you're now seeking some kind of immigration benefit, at this rate you'll be subject to the same scanning as those entering the Land of the Free today. The proposed changes have a 60-day comment period for the public to suggest amendments. The last day to send them in is May 5.

Read more of this story at Slashdot.

Gboard Testing Circle, Pill-Shaped Keys On Android

Google Gboard for Android is introducing circle or pill-shaped keys for some beta testers today. "Instead of the key borders being rounded rectangles, Gboard is switching to circles and pills for letters, while the space bar and other keys are now pill-shaped," reports 9to5Google. "While there should be no functional change to touch targets, these new shapes really shift the look of Gboard for Android." From the report: On paper, it's a bit more modern (and rounded) compared to what came before. However, it's a bit cramped if you have "Long press for symbols" enabled, which goes from the top-right corner to being directly above the letter. The physical analog Gboard is moving away from is how most keys on laptops and desktops are square.

Read more of this story at Slashdot.

Meta Is Targeting 'Hundreds of Millions' of Businesses In Agentic AI Deployment

Earlier this week, Meta chief product officer Chris Cox said the company's upcoming open-source Llama 4 AI will help power AI agents for hundreds of millions of businesses. CNBC reports: The AI agents won't just be responding to prompts. They will be capable of new levels of reasoning and action -- surfing the web and handling many tasks that might be of use to consumers and businesses. And that's where Shih comes in. Meta's AI is already being used by over 700 million consumers, according to Shih, and her job is to bring the same technologies to businesses. "Not every business, especially small businesses, has the ability to hire these large AI teams, and so now we're building business AIs for these small businesses so that even they can benefit from all of this innovation that's happening," she told CNBC's Julia Boorstin in an interview for the CNBC Changemakers Spotlight series. She expects the uptake among businesses to happen soon, and spread far and wide. "We're quickly coming to a place where every business, from the very large to the very small, they're going to have a business agent representing it and acting on its behalf, in its voice -- the way that businesses today have websites and email addresses," Shih said. While major companies across sectors of the economy are investing millions of dollars to develop customer LLMs, "doing fancy things like fine tuning models," as Shih put it, "If you're a small business -- you own a coffee shop, you own a jewelry shop online, you're distributing through Instagram -- you don't have the resources to hire a big AI team, and so now our dream is that they won't have to." For both consumers and businesses, the implications of the advances discussed by Cox and Shih will be significant in daily life. For consumers, Shih says, "Their AI assistant [will] do all kinds of things, from researching products to planning trips, planning social outings with their friends." On the business side, Shih pointed to the 200 million small businesses around the world that are already using Meta services and platforms. "They're using WhatsApp, they're using Facebook, they're using Instagram, both to acquire customers, but also engage and deepen each of those relationships. Very soon, each of those businesses are going to have these AIs that can represent them and help automate redundant tasks, help speak in their voice, help them find more customers and provide almost like a concierge service to every single one of their customers, 24/7."

Read more of this story at Slashdot.

US House Panel Subpoenas Alphabet Over Content Moderation

An anonymous reader quotes a report from Reuters: The U.S. House Judiciary Committee subpoenaed Alphabet on Thursday seeking its communications with former President Joe Biden's administration about content moderation policies. House Judiciary Committee Chairman Jim Jordan, a Republican, also asked the YouTube parent company for similar communications with companies and groups outside government, according to a copy of the subpoena seen by Reuters. The subpoena seeks communications about limits or bans on content about President Donald Trump, Tesla CEO and close Trump ally Elon Musk, the virus that causes COVID-19 and a host of other conservative discussion topics. "Alphabet, to our knowledge, has not similarly disavowed the Biden-Harris Administration's attempts to censor speech," Jordan said in a letter. Meanwhile, Google spokesperson Jose Castaneda said the company will "continue to show the committee how we enforce our policies independently, rooted in our commitment to free expression."

Read more of this story at Slashdot.

1Password Introduces 'Nearby Items,' Tying Passwords To Physical Locations

1Password has introduced a 'nearby items' feature, allowing users to tag credentials with physical locations so the relevant information automatically surfaces when users are near those locations. Engadget reports: Location information can be added to any new or existing item in a 1Password vault. The app has also been updated with a map view for setting and viewing the locations of your items. In the blog post announcing the feature, the company cited examples such as door codes for a workplace, health records at a doctor's office, WiFi access at the gym and rewards membership information for local shops as potential uses for location data. Privacy and security are paramount for a password manager, and 1Password confirmed that a user's location coordinates are only used locally and do not leave the device. Nearby items is available to 1Password customers starting today.

Read more of this story at Slashdot.

ChatGPT On macOS Can Now Directly Edit Code

OpenAI's ChatGPT app for macOS now directly edits code in tools like Xcode, VS Code, and JetBrains. "Users can optionally turn on an 'auto-apply' mode so ChatGPT can make edits without the need for additional clicks," adds TechCrunch. The feature is available now for ChatGPT Plus, Pro, and Team users, and will expand to Enterprise, Edu, and free users next week. Windows support is coming "soon." From the report: Direct code editing builds on OpenAI's "work with apps" ChatGPT capability, which the company launched in beta in November 2024. "Work with apps" allows the ChatGPT app for macOS to read code in a handful of dev-focused coding environments, minimizing the need to copy and paste code into ChatGPT. With the ability to directly edit code, ChatGPT now competes more directly with popular AI coding tools like Cursor and GitHub Copilot. OpenAI reportedly has ambitions to launch a dedicated product to support software engineering in the months ahead.

Read more of this story at Slashdot.

Starlink Benefits As Trump Admin Rewrites Rules For $42 Billion Grant Program

An anonymous reader quotes a report from Ars Technica: The Trump administration is eliminating a preference for fiber Internet in a $42.45 billion broadband deployment program, a change that is expected to reduce spending on the most advanced wired networks while directing more money to Starlink and other non-fiber Internet service providers. One report suggests Starlink could obtain $10 billion to $20 billion under the new rules. Secretary of Commerce Howard Lutnick criticized the Biden administration's handling of the Broadband Equity, Access, and Deployment (BEAD) program in a statement yesterday. Lutnick said that "because of the prior Administration's woke mandates, favoritism towards certain technologies, and burdensome regulations, the program has not connected a single person to the Internet and is in dire need of a readjustment." The BEAD program was authorized by Congress in November 2021, and the US was finalizing plans to distribute funding before Trump's inauguration. The National Telecommunications and Information Administration (NTIA), part of the Commerce Department, developed rules for the program in the Biden era and approved initial funding plans submitted by every state and territory. The program has been on hold since the change in administration, with Senator Ted Cruz (R-Texas) and other Republicans seeking rule changes. In addition to demanding an end to the fiber preference, Cruz wants to kill a requirement that ISPs receiving network-construction subsidies provide cheap broadband to people with low incomes. Cruz also criticized "unionized workforce and DEI labor requirements; climate change assessments; excessive per-location costs; and other central planning mandates." Lutnick's statement yesterday confirmed that the Trump administration will end the fiber preference and replace it with a "tech-neutral" set of rules, and explore additional changes. He said: "Under my leadership, the Commerce Department has launched a rigorous review of the BEAD program. The Department is ripping out the Biden Administration's pointless requirements. It is revamping the BEAD program to take a tech-neutral approach that is rigorously driven by outcomes, so states can provide Internet access for the lowest cost. Additionally, the Department is exploring ways to cut government red tape that slows down infrastructure construction. We will work with states and territories to quickly get rid of the delays and the waste. Thereafter we will move quickly to implementation in order to get households connected." Lutnick said the department's goal is to "deliver high-speed Internet access... efficiently and effectively at the lowest cost to taxpayers."

Read more of this story at Slashdot.

NASA Uses GPS On the Moon For the First Time

An anonymous reader quotes a report from Popular Science: On March 2, Firefly Aerospace's Blue Ghost made history, becoming the first commercial lunar lander to successfully touchdown on the moon's surface. The groundbreaking lander is wasting no time in getting to work. According to NASA, the joint public-private mission has already successfully demonstrated the ability to use Earth-based GPS signals on the lunar surface, marking a major step ahead of future Artemis missions. Accurate and reliable navigation will be vital for future astronauts as they travel across the moon, but traditional GPS tools aren't much good when you're around 225,000 miles from Earth. One solution could be transmitting data from the Global Navigation Satellite System (GNSS) to the lunar surface in order to autonomously measure time, velocity, and position. That's what mission engineers from NASA and the Italian Space Agency hoped to demonstrate through the Lunar GNSS Receiver Experiment (LuGRE), one of the 10 projects packed aboard Blue Ghost. [...] "On Earth we can use GNSS signals to navigate in everything from smartphones to airplanes," Kevin Coggins, deputy associate administrator for NASA's SCaN (Space Communications and Navigation) Program, said in a statement. "Now, LuGRE shows us that we can successfully acquire and track GNSS signals at the Moon." LuGRE relied on two GNSS constellations, GPS and Galileo, which triangulate positioning based on dozens of medium Earth orbit satellites that provide real-time tracking data. It performed its navigational fix at approximately 2 a.m. EST on March 3, while about 225,000 miles from Earth. Blue Ghost's LuGRE system will continue collecting information over the next two weeks almost continuously while the lander's other tools begin their own experiments.

Read more of this story at Slashdot.

World's First 'Synthetic Biological Intelligence' Runs On Living Human Cells

Australian company Cortical Labs has launched the CL1, the world's first commercial "biological computer" that merges human brain cells with silicon hardware to form adaptable, energy-efficient neural networks. New Atlas reports: Known as a Synthetic Biological Intelligence (SBI), Cortical's CL1 system was officially launched in Barcelona on March 2, 2025, and is expected to be a game-changer for science and medical research. The human-cell neural networks that form on the silicon "chip" are essentially an ever-evolving organic computer, and the engineers behind it say it learns so quickly and flexibly that it completely outpaces the silicon-based AI chips used to train existing large language models (LLMs) like ChatGPT. "Today is the culmination of a vision that has powered Cortical Labs for almost six years," said Cortical founder and CEO Dr Hon Weng Chong. "We've enjoyed a series of critical breakthroughs in recent years, most notably our research in the journal Neuron, through which cultures were embedded in a simulated game-world, and were provided with electrophysiological stimulation and recording to mimic the arcade game Pong. However, our long-term mission has been to democratize this technology, making it accessible to researchers without specialized hardware and software. The CL1 is the realization of that mission." He added that while this is a groundbreaking step forward, the full extent of the SBI system won't be seen until it's in users' hands. "We're offering 'Wetware-as-a-Service' (WaaS)," he added -- customers will be able to buy the CL-1 biocomputer outright, or simply buy time on the chips, accessing them remotely to work with the cultured cell technology via the cloud. "This platform will enable the millions of researchers, innovators and big-thinkers around the world to turn the CL1's potential into tangible, real-word impact. We'll provide the platform and support for them to invest in R&D and drive new breakthroughs and research." These remarkable brain-cell biocomputers could revolutionize everything from drug discovery and clinical testing to how robotic "intelligence" is built, allowing unlimited personalization depending on need. The CL1, which will be widely available in the second half of 2025, is an enormous achievement for Cortical -- and as New Atlas saw recently with a visit to the company's Melbourne headquarters -- the potential here is much more far-reaching than Pong. [...]

Read more of this story at Slashdot.

China May Be Ready to Use Nuclear Fusion for Power by 2050

China plans to commercialize nuclear fusion for emissions-free power generation by 2050, with its first operational project expected around 2050 after a demonstration phase starting in 2045. Bloomberg reports: China National Nuclear Corp. (CNNC) last year formed an industry alliance and set up a new national fusion company, the China Fusion Corp. It has attracted about 1.75 billion yuan ($240 million) in investment from CNNC and Zhejiang Zheneng Electric Power Co. for cutting-edge tokamak devices, which use magnetic fields to confine and control superheated plasma to produce power without emissions or significant radioactive waste. CNNC also plans to scale up production of its homegrown designs for regular nuclear fission reactors and small modular reactors over the next five years, the company's Vice General Manager Xin Feng said at the briefing. China is set to leapfrog the US and France as the owner of the world's biggest reactor fleet by 2030. About 10 new reactors have been approved every year since power shortages emerged in 2022 and the country is expected to keep up that pace through 2030 to meet climate goals, CNNC said on Friday.

Read more of this story at Slashdot.

Users Report Emotional Bonds With Startlingly Realistic AI Voice Demo

An anonymous reader quotes a report from Ars Technica: In late 2013, the Spike Jonze film Her imagined a future where people would form emotional connections with AI voice assistants. Nearly 12 years later, that fictional premise has veered closer to reality with the release of a new conversational voice model from AI startup Sesame that has left many users both fascinated and unnerved. "I tried the demo, and it was genuinely startling how human it felt," wrote one Hacker News user who tested the system. "I'm almost a bit worried I will start feeling emotionally attached to a voice assistant with this level of human-like sound." In late February, Sesame released a demo for the company's new Conversational Speech Model (CSM) that appears to cross over what many consider the "uncanny valley" of AI-generated speech, with some testers reporting emotional connections to the male or female voice assistant ("Miles" and "Maya"). In our own evaluation, we spoke with the male voice for about 28 minutes, talking about life in general and how it decides what is "right" or "wrong" based on its training data. The synthesized voice was expressive and dynamic, imitating breath sounds, chuckles, interruptions, and even sometimes stumbling over words and correcting itself. These imperfections are intentional. "At Sesame, our goal is to achieve 'voice presence' -- the magical quality that makes spoken interactions feel real, understood, and valued," writes the company in a blog post. "We are creating conversational partners that do not just process requests; they engage in genuine dialogue that builds confidence and trust over time. In doing so, we hope to realize the untapped potential of voice as the ultimate interface for instruction and understanding." [...] Sesame sparked a lively discussion on Hacker News about its potential uses and dangers. Some users reported having extended conversations with the two demo voices, with conversations lasting up to the 30-minute limit. In one case, a parent recounted how their 4-year-old daughter developed an emotional connection with the AI model, crying after not being allowed to talk to it again.

Read more of this story at Slashdot.

Cult Text-Based Zombie MMO 'Urban Dead' Is Shutting Down After 20 Years

The long-running text-based zombie MMO Urban Dead is shutting down on March 14, 2025, after nearly 20 years. The reason: compliance concerns with the UK's Online Safety Act. Games Radar+ reports: "The Online Safety Act comes into force later this month, applying to all social and gaming websites where users interact, and especially those without strong age restrictions," [writes Kevan Davis, the solo British developer behind the game]. "With the possibility of heavy corporate-sized fines even for solo web projects like this one, I've reluctantly concluded that it doesn't look feasible for Urban Dead to be able to continue operating." "So a full 19 years, 8 months and 11 days after its quarantine began, Urban Dead will be shut down," Davis writes. "No grand finale. No final catastrophe. No helicopter evac. Make your peace or your final stand in whichever part of Malton you called home, and the game will be switched off at noon UTC on 14 March." The original website is still online if you want to play the game before its shutdown later this month.

Read more of this story at Slashdot.

TCL Overtakes LG To Become Second-largest Premium TV Brand

"TCL has emerged as a dominant force in the premium TV market, surpassing LG in global shipments and solidifying its position as a key competitor to Samsung," writes Slashdot reader jjslash. "According to Counterpoint Research, TCL's premium TV shipments more than doubled year-on-year in Q4 2024, capturing 20% of the market, while LG's share fell to 19%." TechSpot reports: The two companies' shipment figures have gone in opposite directions since Q4 2023, when LG held a 26% share and TCL was on 12%. Samsung remains the leader when it comes to premium TVs. Its share dropped from 41% to 29% year-on-year, but it's still comfortably ahead of second-place TCL. Chinese brands are showing impressive growth in this market. Hisense also saw its shipment share rise, from 10% in 2023 to 16% in Q4 2024. Counterpoint writes that it classifies QD-MiniLED, QD-LCD, NanoCell, LCD 8K, QD-OLED, WOLED, and MicroLED TVs as premium TV models. The segment grew 51% YoY to reach a record high in the fourth quarter, with full year shipments up 38%. In terms of global shipments (i.e., not just the premium sector), TCL overtook LG in 2022, with Hisense doing the same a year later. Samsung also leads this area, though its share is only 2 percentage points higher than TCL's.

Read more of this story at Slashdot.

Firefox 136 Released With Vertical Tabs, Official ARM64 Linux Binaries

An anonymous reader quotes a report from 9to5Linux: Mozilla published today the final build of the Firefox 136 open-source web browser for all supported platforms ahead of the March 4th, 2025, official release date, so it's time to take a look at the new features and changes. Highlights of Firefox 136 include official Linux binary packages for the AArch64 (ARM64) architecture, hardware video decoding for AMD GPUs on Linux systems, a new HTTPS-First behavior for upgrading page loads to HTTPS, and Smartblock Embeds for selectively unblocking certain social media embeds blocked in the ETP Strict and Private Browsing modes. Firefox 136 is available for download for 32-bit, 64-bit, and AArch64 (ARM64) Linux systems right now from Mozilla's FTP server. As mentioned before, Mozilla plans to officially release Firefox 136 tomorrow, March 4th, 2025, when it will roll out as an OTA (Over-the-Air) update to macOS and Windows users. Here's a list of the general features available in this release: - Vertical Tabs Layout - New Browser Layout Section - PNG Copy Support - HTTPS-First Behavior - Smartblock Embeds - Solo AI Link - Expanded Data Collection & Use Settings - Weather Forecast on New Tab Page - Address Autofill Expansion A full list of changes can be found here.

Read more of this story at Slashdot.

Opera Adds an Automated AI Agent To Its Browser

king*jojo shares a report from The Register: The Opera web browser now boasts "agentic AI," meaning users can ask an onboard AI model to perform tasks that require a series of in-browser actions. The AI agent, referred to as the Browser Operator, can, for example, find 12 pairs of men's size 10 Nike socks that you can buy. This is demonstrated in an Opera-made video of the process, running intermittently at 6x time, which shows the user has to type out the request for the undergarments rather than click around some webpages. The AI, in the given example, works its way through eight steps in its browser chat sidebar, clicking and navigating on your behalf in the web display pane, to arrive at a Walmart checkout page with two six-packs of socks added to the user's shopping cart, ready for payment. [...] Other tasks such as finding specific concert tickets and booking flight tickets from Oslo to Newcastle are also depicted, accelerated at times from 4x to 10x, with the user left to authorize the actual purchase. Browser Operator runs more slowly than shown in the video, though that's actually helpful for a semi-capable assistant. A more casual pace allows the user to intervene at any point and take over.

Read more of this story at Slashdot.

Brother Accused of Locking Down Third-Party Printer Ink Cartridges Via Forced Firmware Updates

Fabled RepairTuber and right-to-repair crusader Louis Rossmann accuses Brother of implementing forced firmware updates that block third-party ink cartridges and remove older firmware versions from support portals. These updates also prevent color calibration with aftermarket ink, rendering cheaper cartridges unusable. Tom's Hardware reports: As mentioned in the intro, Rossmann has seen two big issues emerge for Brother printer users with recent firmware updates. Firstly, models that used to work with aftermarket ink, might refuse to work with the same cartridges in place post-update. Brother doesn't always warn about such updates, so Rossmann says that it is important to keep your printer offline, if possible. Moreover, he reckons it is best to keep your printers offline, and "I highly suggest that you turn off your updates," in light of these anti-consumer updates. Another anti-consumer problem Rossmann highlights affects color devices. He cites reports from a Brother MFP user who noticed color calibration didn't work with aftermarket inks post-update. They used to work, and if the update doesn't allow the printer to calibrate with this aftermarket ink the cheaper carts become basically unusable. Making matters worse, and an aspect of this tale which seems particularly dastardly, Rossmann says that older printer firmware is usually removed from websites. This means users can't roll back when they discover the unwanted new 'features' post-update. While he admittedly can't do much about these printer industry machinations, Rossmann says it feels important to document these changes which show that property rights for individuals are disappearing. Additional info about Brother's issues are available on Rossmann's wiki.

Read more of this story at Slashdot.

Judges Are Fed Up With Lawyers Using AI That Hallucinate Court Cases

An anonymous reader quotes a report from 404 Media: After a group of attorneys were caught using AI to cite cases that didn't actually exist in court documents last month, another lawyer was told to pay $15,000 for his own AI hallucinations that showed up in several briefs. Attorney Rafael Ramirez, who represented a company called HoosierVac in an ongoing case where the Mid Central Operating Engineers Health and Welfare Fund claims the company is failing to allow the union a full audit of its books and records, filed a brief in October 2024 that cited a case the judge wasn't able to locate. Ramirez "acknowledge[d] that the referenced citation was in error," withdrew the citation, and "apologized to the court and opposing counsel for the confusion," according to Judge Mark Dinsmore, U.S. Magistrate Judge for the Southern District of Indiana. But that wasn't the end of it. An "exhaustive review" of Ramirez's other filings in the case showed that he'd included made-up cases in two other briefs, too. [...] In January, as part of a separate case against a hoverboard manufacturer and Walmart seeking damages for an allegedly faulty lithium battery, attorneys filed court documents that cited a series of cases that don't exist. In February, U.S. District Judge Kelly demanded they explain why they shouldn't be sanctioned for referencing eight non-existent cases. The attorneys contritely admitted to using AI to generate the cases without catching the errors, and called it a "cautionary tale" for the rest of the legal world. Last week, Judge Rankin issued sanctions on those attorneys, according to new records, including revoking one of the attorneys' pro hac vice admission (a legal term meaning a lawyer can temporarily practice in a jurisdiction where they're not licensed) and removed him from the case, and the three other attorneys on the case were fined between $1,000 and $3,000 each. The judge in the Ramirez case said that he "does not aim to suggest that AI is inherently bad or that its use by lawyers should be forbidden." In fact, he noted that he's a vocal advocate for the use of technology in the legal profession. "Nevertheless, much like a chain saw or other useful [but] potentially dangerous tools, one must understand the tools they are using and use those tools with caution," he wrote. "It should go without saying that any use of artificial intelligence must be consistent with counsel's ethical and professional obligations. In other words, the use of artificial intelligence must be accompanied by the application of actual intelligence in its execution."

Read more of this story at Slashdot.

Google Releases SpeciesNet, an AI Model Designed To Identify Wildlife

An anonymous reader quotes a report from TechCrunch: Google has open sourced an AI model, SpeciesNet, designed to identify animal species by analyzing photos from camera traps. Researchers around the world use camera traps -- digital cameras connected to infrared sensors -- to study wildlife populations. But while these traps can provide valuable insights, they generate massive volumes of data that take days to weeks to sift through. In a bid to help, Google launched Wildlife Insights, an initiative of the company's Google Earth Outreach philanthropy program, around six years ago. Wildlife Insights provides a platform where researchers can share, identify, and analyze wildlife images online, collaborating to speed up camera trap data analysis. Many of Wildlife Insights' analysis tools are powered by SpeciesNet, which Google claims was trained on over 65 million publicly available images and images from organizations like the Smithsonian Conservation Biology Institute, the Wildlife Conservation Society, the North Carolina Museum of Natural Sciences, and the Zoological Society of London. Google says that SpeciesNet can classify images into one of more than 2,000 labels, covering animal species, taxa like "mammalian" or "Felidae," and non-animal objects (e.g. "vehicle"). SpeciesNet is available on GitHub under an Apache 2.0 license, meaning it can be used commercially largely sans restrictions.

Read more of this story at Slashdot.

CISA Tags Windows, Cisco Vulnerabilities As Actively Exploited

CISA has warned U.S. federal agencies about active exploitation of vulnerabilities in Cisco VPN routers and Windows systems. "While the cybersecurity agency has tagged these flaws as actively exploited in the wild, it has yet to provide specific details regarding this malicious activity and who is behind it," adds Bleeping Computer. From the report: The first flaw (tracked as CVE-2023-20118) enables attackers to execute arbitrary commands on RV016, RV042, RV042G, RV082, RV320, and RV325 VPN routers. While it requires valid administrative credentials, this can still be achieved by chaining the CVE-2023-20025 authentication bypass, which provides root privileges. Cisco says in an advisory published in January 2023 and updated one year later that its Product Security Incident Response Team (PSIRT) is aware of CVE-2023-20025 publicly available proof-of-concept exploit code. The second security bug (CVE-2018-8639) is a Win32k elevation of privilege flaw that local attackers logged into the target system can exploit to run arbitrary code in kernel mode. Successful exploitation also allows them to alter data or create rogue accounts with full user rights to take over vulnerable Windows devices. According to a security advisory issued by Microsoft in December 2018, this vulnerability impacts client (Windows 7 or later) and server (Windows Server 2008 and up) platforms. Today, CISA added the two vulnerabilities to its Known Exploited Vulnerabilities catalog, which lists security bugs the agency has tagged as exploited in attacks. As mandated by the Binding Operational Directive (BOD) 22-01 issued in November 2021, Federal Civilian Executive Branch (FCEB) agencies now have three weeks, until March 23, to secure their networks against ongoing exploitation.

Read more of this story at Slashdot.

Private Lunar Lander Blue Ghost Aces Moon Touchdown

Firefly Aerospace's Blue Ghost lander successfully touched down on the moon, making it the first private company to achieve a stable lunar landing without crashing. The craft is carrying various NASA-funded experiments, including a "vacuum to suck up moon dirt for analysis and a drill to measure temperature as deep as 10 feet (3 meters) below the surface," reports the Associated Press. There's also "a device for eliminating abrasive lunar dust -- a scourge for NASA's long-ago Apollo moonwalkers, who got it caked all over their spacesuits and equipment." From the report: A half hour after landing, Blue Ghost started to send back pictures from the surface, the first one a selfie somewhat obscured by the sun's glare. The second shot included the home planet, a blue dot glimmering in the blackness of space. Blue Ghost -- named after a rare U.S. species of fireflies -- had its size and shape going for it. The squat four-legged lander stands 6-foot-6 (2 meters) tall and 11 feet (3.5 meters) wide, providing extra stability, according to the company. Launched in mid-January from Florida, the lander carried 10 experiments to the moon for NASA. The space agency paid $101 million for the delivery, plus $44 million for the science and tech on board. It's the third mission under NASA's commercial lunar delivery program, intended to ignite a lunar economy of competing private businesses while scouting around before astronauts show up later this decade. Firefly's Ray Allensworth said the lander skipped over hazards including boulders to land safely. Allensworth said the team continued to analyze the data to figure out the lander's exact position, but all indications suggest it landed within the 328-foot (100-meter) target zone in Mare Crisium. The demos should get two weeks of run time, before lunar daytime ends and the lander shuts down.

Read more of this story at Slashdot.

❌