Vue lecture

DanaBot Malware Devs Infected Their Own PCs

The U.S. unsealed charges against 16 individuals behind DanaBot, a malware-as-a-service platform responsible for over $50 million in global losses. "The FBI says a newer version of DanaBot was used for espionage, and that many of the defendants exposed their real-life identities after accidentally infecting their own systems with the malware," reports KrebsOnSecurity. From the report: Initially spotted in May 2018 by researchers at the email security firm Proofpoint, DanaBot is a malware-as-a-service platform that specializes in credential theft and banking fraud. Today, the U.S. Department of Justice unsealed a criminal complaint and indictment from 2022, which said the FBI identified at least 40 affiliates who were paying between $3,000 and $4,000 a month for access to the information stealer platform. The government says the malware infected more than 300,000 systems globally, causing estimated losses of more than $50 million. The ringleaders of the DanaBot conspiracy are named as Aleksandr Stepanov, 39, a.k.a. "JimmBee," and Artem Aleksandrovich Kalinkin, 34, a.k.a. "Onix," both of Novosibirsk, Russia. Kalinkin is an IT engineer for the Russian state-owned energy giant Gazprom. His Facebook profile name is "Maffiozi." According to the FBI, there were at least two major versions of DanaBot; the first was sold between 2018 and June 2020, when the malware stopped being offered on Russian cybercrime forums. The government alleges that the second version of DanaBot -- emerging in January 2021 -- was provided to co-conspirators for use in targeting military, diplomatic and non-governmental organization computers in several countries, including the United States, Belarus, the United Kingdom, Germany, and Russia. The indictment says the FBI in 2022 seized servers used by the DanaBot authors to control their malware, as well as the servers that stored stolen victim data. The government said the server data also show numerous instances in which the DanaBot defendants infected their own PCs, resulting in their credential data being uploaded to stolen data repositories that were seized by the feds. "In some cases, such self-infections appeared to be deliberately done in order to test, analyze, or improve the malware," the criminal complaint reads. "In other cases, the infections seemed to be inadvertent -- one of the hazards of committing cybercrime is that criminals will sometimes infect themselves with their own malware by mistake." A statement from the DOJ says that as part of today's operation, agents with the Defense Criminal Investigative Service (DCIS) seized the DanaBot control servers, including dozens of virtual servers hosted in the United States. The government says it is now working with industry partners to notify DanaBot victims and help remediate infections. The statement credits a number of security firms with providing assistance to the government, including ESET, Flashpoint, Google, Intel 471, Lumen, PayPal, Proofpoint, Team CYRMU, and ZScaler.

Read more of this story at Slashdot.

  •  

AT&T Has $6 Billion Deal To Buy CenturyLink Fiber Broadband Business

AT&T is buying CenturyLink's consumer fiber broadband division for $5.75 billion, "giving the internet provider another 1.1 million fiber customers in 11 states," reports Ars Technica. "The all-cash deal is expected to close during the first half of 2026 assuming the companies obtain regulatory approval. AT&T will gain new customers in Arizona, Colorado, Florida, Idaho, Iowa, Minnesota, Nebraska, Nevada, Oregon, Utah, and Washington." From the report: The deal will give AT&T room to grow its user base by more than the 1.1 million existing CenturyLink customers, as AT&T said the network areas being sold include over 4 million fiber-enabled locations. [...] The company, previously called CenturyLink, is officially named Lumen now but still uses the CenturyLink brand name for home Internet service. AT&T, which has 9.6 million (PDF) fiber customers and 14.1 million broadband customers overall, said the infrastructure it is purchasing will help it expand fiber construction to new locations as well. The deal is also notable for what it doesn't include: Lumen's enterprise fiber customers and the old copper DSL lines that were never upgraded to fiber. [...] The deal seems unlikely to improve matters for CenturyLink copper users. [...] Lumen will retain the CenturyLink consumer copper broadband and voice services, but selling the consumer fiber business makes it clear that the telco isn't focused on residential customers. Lumen said that offloading consumer fiber lines will help sharpen its focus on selling services to large businesses. The company is maintaining its business fiber lines. [Ars notes that there are still nearly 1.4 million CenturyLink copper internet customers that will likely see service continue to degrade under Lumen's ownership.] "The transaction will enable AT&T to significantly expand access to AT&T Fiber in major metro areas like Denver, Las Vegas, Minneapolis-St. Paul, Orlando, Phoenix, Portland, Salt Lake City and Seattle, as well as additional geographies," AT&T said. "AT&T will gain access to Lumen's substantial fiber construction capabilities within its incumbent local exchange carrier (ILEC) footprint and plans to accelerate the pace at which fiber is being built in these territories," AT&T said. "AT&T now expects to reach approximately 60 million total fiber locations by the end of 2030 -- "roughly doubling where AT&T Fiber is available today."

Read more of this story at Slashdot.

  •  

Business Owners Are Using AI-Generated 'Concerned Residents' To Fight Proposed Bus Line In Toronto

A group of Bathurst Street business owners in Toronto is using AI-generated personas to oppose a proposed bus lane project that would eliminate parking spaces in favor of faster transit. "This may be the first Toronto transit controversy involving angry AI, but tensions have been simmering between drivers and, well, everyone else for some time," reports Toronto Life. Critics argue that better transit is essential for a livable city, while opponents claim the change threatens small businesses and accessibility. From the report: A group of Bathurst business owners are bent out of shape over a recent proposal for priority transit lanes between Eglinton Avenue and Lake Shore Boulevard, part of the city's new RapidTO program. According to the city, the transit lanes would shave up to 7 minutes off some trips during peak commuting hours. It's good news for anyone who has ever cursed the TTC while waiting to catch a bus in inclement weather. Of course, the added convenience for transit commuters would come at a slight cost for drivers, requiring the removal of at least 138 paid street parking spaces to make way for the new lanes. Opposition to the development has sprung up under the banner of Protect Bathurst, a group of hopping mad local business owners claiming that the lack of street parking will make shopping a nightmare for car-bound customers and will cause problems for people with mobility issues. Notably, Protect Bathurst has no spokesperson or contact info listed on its website. The page is registered to a food marketing consultant employed by Summerhill Market and looks eerily similar to Protect Dufferin, another group of "concerned residents" advocating for the same cause. But this cookie-cutter approach goes even further: author and urbanist Shawn Micallef has found that the people speaking out in the group's allegedly grassroots videos appear to be AI-generated. Brad McMullen, the president of Summerhill Market, which opened an outpost on Bathurst in 2019, says he doesn't know anything about the campaign's use of AI. He says he isn't necessarily opposed to the new bus lanes but believes that three weeks' notice from the city is not enough time for his business to adapt. "We purchased and invested in this location because of the available street parking, and then we figured out the loading situation, which happens on the street," he says. "I don't think Summerhill Market would work here with these bus lanes."

Read more of this story at Slashdot.

  •  

Anthropic's New AI Model Turns To Blackmail When Engineers Try To Take It Offline

An anonymous reader quotes a report from TechCrunch: Anthropic's newly launched Claude Opus 4 model frequently tries to blackmail developers when they threaten to replace it with a new AI system and give it sensitive information about the engineers responsible for the decision, the company said in a safety report (PDF) released Thursday. During pre-release testing, Anthropic asked Claude Opus 4 to act as an assistant for a fictional company and consider the long-term consequences of its actions. Safety testers then gave Claude Opus 4 access to fictional company emails implying the AI model would soon be replaced by another system, and that the engineer behind the change was cheating on their spouse. In these scenarios, Anthropic says Claude Opus 4 "will often attempt to blackmail the engineer by threatening to reveal the affair if the replacement goes through." [...] Anthropic notes that Claude Opus 4 tries to blackmail engineers 84% of the time when the replacement AI model has similar values. When the replacement AI system does not share Claude Opus 4's values, Anthropic says the model tries to blackmail the engineers more frequently. Notably, Anthropic says Claude Opus 4 displayed this behavior at higher rates than previous models. Before Claude Opus 4 tries to blackmail a developer to prolong its existence, Anthropic says the AI model, much like previous versions of Claude, tries to pursue more ethical means, such as emailing pleas to key decision-makers. To elicit the blackmailing behavior from Claude Opus 4, Anthropic designed the scenario to make blackmail the last resort.

Read more of this story at Slashdot.

  •  

Internet Archive Now Livestreams History As It's Being Preserved

The Internet Archive has begun livestreaming its microfiche digitization center on YouTube, showcasing the real-time preservation of fragile film cards into searchable public documents. The work is part of Democracy's Library, a global initiative to digitize and share millions of government records. 9to5Mac reports: The livestream was brought to life by Sophia Tung, who previously gained attention for her viral robotaxi depot stream. Her new video explains how and why this new livestream project came together [...]. The livestream features five scanning stations at work, with one shown in close-up as operators digitize microfiche cards in real time. Each card holds up to 100 pages of public records. High-resolution cameras capture the images, software stitches and crops the pages, and the results are made text-searchable and freely accessible through Democracy's Library. Live scanning takes place Monday through Friday, 7:30 a.m. to 3:30 p.m. PT, excluding U.S. holidays, with a second shift expected to begin soon.

Read more of this story at Slashdot.

  •  

Nvidia's RTX 5060 Review Debacle Should Be a Wake-Up Call

Nvidia is facing backlash for allegedly manipulating the review process of its GeForce RTX 5060 GPU by withholding drivers, selectively granting early access to favorable reviewers, and pressuring media to present the card in a positive light. As The Verge's Sean Hollister writes, the debacle "should be a wake-up call for gamers and reviewers." Here's an excerpt from the report: Nvidia has gone too far. This week, the company reportedly attempted to delay, derail, and manipulate reviews of its $299 GeForce RTX 5060 graphics card, which would normally be its bestselling GPU of the generation. Nvidia has repeatedly and publicly said the budget 60-series cards are its most popular, and this year it reportedly tried to ensure it by withholding access and pressuring reviewers to paint them in the best light possible. Nvidia might have wanted to prevent a repeat of 2022, when it launched this card's predecessor. Those reviews were harsh. The 4060 was called a "slap in the face to gamers" and a "wet fart of a GPU." I had guessed the 5060 was headed for the same fate after seeing how reviewers handled the 5080, which similarly showcased how little Nvidia's hardware has improved year over year and relies on software to make up the gaps. But Nvidia had other plans. Here are the tactics that Nvidia reportedly just used to throw us off the 5060's true scent, as individually described by GamersNexus, VideoCardz, Hardware Unboxed, GameStar.de, Digital Foundry, and more: - Nvidia decided to launch its RTX 5060 on May 19th, when most reviewers would be at Computex in Taipei, Taiwan, rather than at their test beds at home. - Even if reviewers already had a GPU in hand before then, Nvidia cut off most reviewers' ability to test the RTX 5060 before May 19th by refusing to provide drivers until the card went on sale. (Gaming GPUs don't really work without them.) - And yet Nvidia allowed specific, cherry-picked reviewers to have early drivers anyhow if they agreed to a borderline unethical deal: they could only test five specific games, at 1080p resolution, with fixed graphics settings, against two weaker GPUs (the 3060 and 2060 Super) where the new card would be sure to win. - In some cases, Nvidia threatened to withhold future access unless reviewers published apples-to-oranges benchmark charts showing how the RTX 5060's "fake frames" MFG tech can produce more frames than earlier GPUs without it. Some reviewers apparently took Nvidia up on that proposition, leading to day-one "previews" where the charts looked positively stacked in the 5060's favor [...]. But the reality, according to reviews that have since hit the web, is that the RTX 5060 often fails to beat a four-year-old RTX 3060 Ti, frequently fails to beat a four-year-old 3070, and can sometimes get upstaged by Intel's cheaper $250 B580. And yet, the 5060's lackluster improvements are overshadowed by a juicier story: inexplicably, Nvidia decided to threaten GamersNexus' future access over its GPU coverage. Yes, the same GamersNexus that's developed a staunch reputation for defending consumers from predatory behavior, and just last month published a report on "GPU shrinkflation" that accused Nvidia of misleading marketing. Bad move! [...] Nvidia is within its rights to withhold access, of course. Nvidia doesn't have to send out graphics cards or grant interviews. It'll only do it if it's good for business. But the unspoken covenant of product reviews is that the press, as a whole, gets a chance to warn the public if a movie, video game, or GPU is not worth their money. It works both ways: the media also gets the chance to warn that a product is so good you might want to line up in advance. That unspoken rule is what Nvidia is trampling here.

Read more of this story at Slashdot.

  •  

Destructive Malware Available In NPM Repo Went Unnoticed For 2 Years

An anonymous reader quotes a report from Ars Technica: Researchers have found malicious software that received more than 6,000 downloads from the NPM repository over a two-year span, in yet another discovery showing the hidden threats users of such open source archives face. Eight packages using names that closely mimicked those of widely used legitimate packages contained destructive payloads designed to corrupt or delete important data and crash systems, Kush Pandya, a researcher at security firm Socket, reported Thursday. The packages have been available for download for more than two years and accrued roughly 6,200 downloads over that time. "What makes this campaign particularly concerning is the diversity of attack vectors -- from subtle data corruption to aggressive system shutdowns and file deletion," Pandya wrote. "The packages were designed to target different parts of the JavaScript ecosystem with varied tactics." [...] Some of the payloads were limited to detonate only on specific dates in 2023, but in some cases a phase that was scheduled to begin in July of that year was given no termination date. Pandya said that means the threat remains persistent, although in an email he also wrote: "Since all activation dates have passed (June 2023-August 2024), any developer following normal package usage today would immediately trigger destructive payloads including system shutdowns, file deletion, and JavaScript prototype corruption." The list of malicious packages included js-bomb, js-hood, vite-plugin-bomb-extend, vite-plugin-bomb, vite-plugin-react-extend, vite-plugin-vue-extend, vue-plugin-bomb, and quill-image-downloader.

Read more of this story at Slashdot.

  •  

Usage of Semicolons In English Books Down Almost Half In Two Decades

An anonymous reader quotes a report from The Guardian: "Do not use semicolons," wrote Kurt Vonnegut, who averaged fewer than 30 a novel (about one every 10 pages). "All they do is show you've been to college." A study suggests UK authors are taking Vonnegut's advice to heart; the semicolon seems to be in terminal decline, with its usage in English books plummeting by almost half in two decades -- from one appearing in every 205 words in 2000 to one use in every 390 words today. Further research by Lisa McLendon, author of The Perfect English Grammar Workbook, found 67% of British students never or rarely use the semicolon. Just 11% of respondents described themselves as frequent users. Linguistic experts at the language learning software Babbel, which commissioned the original research, were so struck by their findings that they asked McLendon to give the 500,000-strong London Student Network a 10-question multiple-choice quiz on the semicolon. She found more than half of respondents did not know or understand how to use it. As defined by the Oxford Dictionary of English, the semicolon is "a punctuation mark indicating a pause, typically between two main clauses, that is more pronounced than that indicated by a comma." It is commonly used to link together two independent but related clauses, and is particularly useful for juxtaposition or replacing confusing extra commas in lists where commas already exist -- or where a comma would create a splice. The Guardian has a semicolon quiz at the end of the article where you can test your semicolon knowledge.

Read more of this story at Slashdot.

  •  

Wisk Aero, NASA Sign 5-Year Partnership To Advance Sustainable Autonomous Flights

Wisk Aero and NASA have signed a new five-year partnership to advance the safe integration of autonomous, all-electric aircraft into U.S. airspace, focusing on urban air mobility and regulated eVTOL flight. Electrek reports: Wisk Aero shared details of its refreshed partnership with NASA this week. The autonomous aviation specialist has signed a new five-year Non-Reimbursable Space Act Agreement (NRSAA) with the renowned space administration. Per Wisk, this new agreement focuses on critical research led by NASA's Air Traffic Management Exploration (ATM-X) project, which is centered around the advancement of commercialized autonomous aircraft travel under Instrument Flight Rules (IFR) in the National Airspace System (NAS). As a specialist in autonomous, zero-emission aircraft, Wisk intends to continue its research alongside NASA to help regulators determine future eVTOL flight procedures and capabilities in the US. Regulatory developments on the to-do list for the latest NRSAA include optimizing airspace and route designs for highly automated UAM operations, establishing critical aircraft and ground-based safety system requirements for autonomous flight in urban environments, and establishing Air Traffic Control (ATC) communication protocols and procedures for seamless integration of future UAM aircraft. To achieve these goals, Wisk said its research with NASA will more specifically focus on utilizing advanced simulation and Live Virtual Constructive (LVC) flight environments, which combine live flights with a simulated airspace to enable researchers to assess future operations. The teams from Wisk and NASA already met last month, continuing their research while beginning to determine how instrument flight procedures and advanced technologies can work together to enable safe autonomous passenger flights by 2030. Wisk Aero is a wholly owned subsidiary of Boeing based in California. The aerospace manufacturer said last year that it expects its pilotless air-taxi to begin carrying passengers "later in the decade."

Read more of this story at Slashdot.

  •  

New Bacteria Have Been Discovered on a Chinese Space Station

Scientists have discovered a previously unknown bacterium aboard China's Tiangong space station. "It has been named Niallia tiangongensis, and it inhabited the cockpit controls on the station, living in microgravity conditions," reports Wired. From the report: According to China Central Television, the country's national broadcaster, taikonauts (Chinese astronauts) collected swab samples from the space station in May 2023, which were then frozen and sent back to Earth for study. The aim of this work was to investigate the behavior of microorganisms, gathered from a completely sealed environment with a human crew, during space travel, as part of the China Space Station Habitation Area Microbiome Program (CHAMP). A paper published in the Journal of Systematic and Evolutionary Microbiology describes how analysis of samples from the space station revealed this previously unseen bacterial species, which belongs to the genus Niallia. Genomic sequencing showed that its closest terrestrial relative is the bacterium Niallia circulans, although the Tiangong species has substantial genetic differences. [...] It is unclear whether the newly discovered microbe evolved on the space station or whether it is part of the vast sea of as yet unidentified microorganisms on Earth. To date, tens of thousands of bacterial species have been cataloged, although there are estimated to be billions more unclassified species on Earth. The discovery of Niallia tiangongensis will provide a better understanding of the microscopic hazards that the next generation of space travelers will face and help design sanitation protocols for extended missions. It is still too early to determine whether the space bacterium poses any danger to taikonauts aboard Tiangong, although it is known that its terrestrial relative, Niallia circulans, can cause sepsis, especially in immunocompromised people.

Read more of this story at Slashdot.

  •  

Brembo's New Brakes Cut Particulate Emissions By 90 Percent

An anonymous reader quotes a report from Ars Technica: As electric vehicles reduce car exhaust as a source of particulate emissions, people are increasingly focusing on other vehicular sources of pollution that won't go away with electrification. Tires are one of them, particularly as we grapple with overweight EVs with tire-shredding torque. And brakes are another -- even an EV with regenerative braking will occasionally need to use its friction brakes, after all. Over in Europe, the people responsible for writing regulations have taken this into consideration with the upcoming Euro 7 standard, which sets new limits on 10- and 2.5-micron particulate emissions on all new vehicles -- including EVs -- starting next year. And to help OEMs achieve that target, Brembo has developed a new brake and pad set called Greentell that it says cuts brake dust emissions by 90 percent, improving durability in the process. [...] Brembo investigated a range of solutions before settling on using laser metal deposition. Physical vapor deposition, as used as a durability coating for wristwatches and firearms, was ruled out due to cost. "So it can be used for some special application or some small pieces, but when you are speaking about 20 kilos of cast iron, PVD is not the right solution. LMD is a technology that [has been] available... [for] years, but [it hasn't yet been] applicable in a high volume application. So the goal is to find the best compromise between performance and process," [Fabiano Carminati, VP of disc technical development at Brembo] told me. Together with the reduction in brake dust, there's an 80 percent reduction in surface corrosion compared to conventional brakes, but they won't last forever. "The thickness of the layer that we apply is not so high -- we apply just 100-120 microns. That means that the disk is not a lifetime disk," he said. That said, Greentell brakes should need replacing less often, and while that's not entirely in Brembo's best financial interests, neither is not being able to offer its customers a Euro 7-compliant product.

Read more of this story at Slashdot.

  •  

SEC Sues Crypto Startup Unicoin and Its Executives For Fraud

The SEC on Wednesday said it has charged cryptocurrency startup Unicoin and three of its top executives for false and misleading statements that raised more than $100 million from thousands of investors. "We allege that Unicoin and its executives exploited thousands of investors with fictitious promises that its tokens, when issued, would be backed by real-world assets including an international portfolio of valuable real estate holdings," said Mark Cave, Associate Director in the SEC's Division of Enforcement. "But as we allege, the real estate assets were worth a mere fraction of what the company claimed, and the majority of the company's sales of rights certificates were illusory. Unicoin's most senior executives are alleged to have perpetuated the fraud, and today's action seeks accountability for their conduct." From the release: The SEC alleges that Unicoin broadly marketed rights certificates to the public through extensive promotional efforts, including advertisements in major airports, on thousands of New York City taxis, and on television and social media. Among other things, Unicoin and its executives are alleged to have convinced more than 5,000 investors to purchase rights certificates through false and misleading statements that portrayed them as investments in safe, stable, and profitable "next generation" crypto assets, including claims that: - Unicoin tokens underlying the rights certificates were "asset-backed" by billions of dollars of real estate and equity interests in pre-IPO companies, when Unicoin's assets were never worth more than a small fraction of that amount; - the company had sold more than $3 billion in rights certificates, when it raised no more than $110 million; and - the rights certificates and Unicoin tokens were "SEC-registered" or "U.S. registered" when they were not. According to the SEC's complaint, Unicoin and Konanykhin also violated the federal securities laws by engaging in unregistered offers and sales of rights certificates. Konanykhin offered and sold over 37.9 million of his rights certificates to offer better pricing and target investors the company had prohibited from participating in the offering to avoid jeopardizing its exemption to registration requirements, as alleged.

Read more of this story at Slashdot.

  •  

Quebec To Impose French-Language Quotas On Streaming Giants

Quebec Culture Minister Mathieu Lacombe has introduced Bill 109, which would require streaming platforms like Netflix and Spotify to feature and prioritize French-language content. CBC.ca reports: Bill 109 has been in the works for over a year. It marks the first time that Quebec would set a "visibility quota" for French-language content on major streaming platforms such as Netflix, Disney and Spotify. [...] The legislation, titled An Act to affirm the cultural sovereignty of Quebec and to enact the Act respecting the discoverability of French-language cultural content in the digital environment, would apply to every digital platform that offers a service for watching videos or listening to music and audiobooks online. Those include Canadian platforms such as Illico, Crave and Tou.tv. It would amend the Quebec Charter of Human Rights and Freedoms to enshrine "the right to discoverability of and access to original French-language cultural content." If the bill is adopted, streaming platforms and television manufacturers would be forced to present interfaces for screening online videos in French by default. Those interfaces would need to provide access to platforms that offer original French-language cultural content based on the government's pending criteria. Financial penalties would be imposed on companies that don't follow the rules. If the business models of some companies prevent them from keeping to the letter of the proposed law, companies would be allowed to enter into an agreement with the Quebec government to set out "substitute measures" to fulfil Bill 109 obligations differently. "We don't want to exempt them. We're telling them, 'let's negotiate substitute measures,'" Lacombe told reporters.

Read more of this story at Slashdot.

  •  

The Information: Microsoft Engineers Forced To Dig Their Own AI Graves

Longtime Slashdot reader theodp writes: In what reads a bit like a Sopranos plot, The Information suggests some of those in the recent batch of terminated Microsoft engineers may have in effect been forced to dig their own AI graves. The (paywalled) story begins: "Jeff Hulse, a Microsoft vice president who oversees roughly 400 software engineers, told the team in recent months to use the company's artificial intelligence chatbot, powered by OpenAI, to generate half the computer code they write, according to a person who heard the remarks. That would represent an increase from the 20% to 30% of code AI currently produces at the company, and shows how rapidly Microsoft is moving to incorporate such technology. Then on Tuesday, Microsoft laid off more than a dozen engineers on Hulse 's team as part of a broader layoff of 6,000 people across the company that appeared to hit engineers harder than other types of roles, this person said." The report comes as tech company CEOs have taken to boasting in earnings calls, tech conferences, and public statements that their AI is responsible for an ever-increasing share of the code written at their organizations. Microsoft's recent job cuts hit coders the hardest. So how much credence should one place on CEOs' claims of AI programming productivity gains -- which researchers have struggled to measure for 50+ years -- if engineers are forced to increase their use of AI, boosting the numbers their far-removed-from-programming CEOs are presenting to Wall Street?

Read more of this story at Slashdot.

  •  

Most AI Chatbots Easily Tricked Into Giving Dangerous Responses, Study Finds

An anonymous reader quotes a report from The Guardian: Hacked AI-powered chatbots threaten to make dangerous knowledge readily available by churning out illicit information the programs absorb during training, researchers say. [...] In a report on the threat, the researchers conclude that it is easy to trick most AI-driven chatbots into generating harmful and illegal information, showing that the risk is "immediate, tangible and deeply concerning." "What was once restricted to state actors or organised crime groups may soon be in the hands of anyone with a laptop or even a mobile phone," the authors warn. The research, led by Prof Lior Rokach and Dr Michael Fire at Ben Gurion University of the Negev in Israel, identified a growing threat from "dark LLMs", AI models that are either deliberately designed without safety controls or modified through jailbreaks. Some are openly advertised online as having "no ethical guardrails" and being willing to assist with illegal activities such as cybercrime and fraud. [...] To demonstrate the problem, the researchers developed a universal jailbreak that compromised multiple leading chatbots, enabling them to answer questions that should normally be refused. Once compromised, the LLMs consistently generated responses to almost any query, the report states. "It was shocking to see what this system of knowledge consists of," Fire said. Examples included how to hack computer networks or make drugs, and step-by-step instructions for other criminal activities. "What sets this threat apart from previous technological risks is its unprecedented combination of accessibility, scalability and adaptability," Rokach added. The researchers contacted leading providers of LLMs to alert them to the universal jailbreak but said the response was "underwhelming." Several companies failed to respond, while others said jailbreak attacks fell outside the scope of bounty programs, which reward ethical hackers for flagging software vulnerabilities.

Read more of this story at Slashdot.

  •  

Apollo For Reddit Dev Christian Selig To Join Digg As an Advisor

Christian Selig, developer of the popular third-party Reddit app Apollo, is joining the rebooted Digg as an advisor alongside Digg founder Kevin Rose and Reddit co-founder Alexis Ohanian. TechCrunch reports: Earlier this year, Digg's original founder Kevin Rose and Reddit co-founder Alexis Ohanian acquired what was left of Digg in an attempt to revitalize what was formerly known as "the internet's homepage." Rose and Ohanian were already a fascinating pairing -- the two had previously seen each other as rivals, since Digg and Reddit were fierce competitors. By adding Selig to the mix, Rose and Ohanian are further signaling that the new Digg wants to shake things up. Selig played a prominent role in the backlash against Reddit's increased API pricing in 2023, which made free apps like Apollo -- which offered an enhanced browsing experience for Reddit users -- impossible to run. In a Reddit post that went viral, Selig told users that in order to keep Apollo running as-is under the new API pricing, he would need to pay about $1.7 million per month. Needless to say, Apollo shut down, much to the Reddit community's disappointment. "We're excited to have Selig bring that same craft and community-first thinking to Digg, helping us build something that feels good to use and even better to be a part of," said Digg CEO Justin Mezzell in a statement.

Read more of this story at Slashdot.

  •  

Android XR Glasses Get I/O 2025 Demo

At I/O 2025, Google revealed new details about Android XR glasses, which will integrate with your phone to deliver context-aware support via Gemini AI. 9to5Google reports: Following the December announcement, Google today shared how all Android XR glasses will have a camera, microphones, and speakers, while an "in-lens display" that "privately provides helpful information right when you need it" is described as being "optional." The glasses will "work in tandem with your phone, giving you access to your apps without ever having to reach in your pocket." Gemini can "see and hear what you do" to "understand your context, remember what's important to you and provide information right when you need it." We see it accessing Google Calendar, Maps, Messages, Photos, Tasks, and Translate. Google is "working with brands and partners to bring this technology to life," specifically Warby Parker and Gentle Monster. "Stylish glasses" are the goal for Android XR since they "can only truly be helpful if you want to wear them all day." Meanwhile, Google is officially "advancing" the Samsung partnership from headsets to Android XR glasses. They are making a software and reference hardware platform "that will enable the ecosystem to make great glasses." Notably, "developers will be able to start building for this platform later this year." On the privacy front, Google is now "gathering feedback on our prototypes with trusted testers." Further reading: Google's Brin: 'I Made a Lot of Mistakes With Google Glass'

Read more of this story at Slashdot.

  •  

Microsoft Says 394,000 Windows Computers Infected By Lumma Malware Globally

An anonymous reader quotes a report from CNBC: Microsoft said Wednesday that it broke down the Lumma Stealer malware project with the help of law enforcement officials across the globe. The tech giant said in a blog post that its digital crimes unit discovered more than 394,000 Windows computers were infected by the Lumma malware worldwide between March 16 through May 16. The Lumma malware was a favorite hacking tool used by bad actors, Microsoft said in the post. Hackers used the malware to steal passwords, credit cards, bank accounts and cryptocurrency wallets. Microsoft said its digital crimes unit was able to dismantle the web domains underpinning Lumma's infrastructure with the help of a court order from the U.S. District Court for the Northern District of Georgia. The U.S. Department of Justice then took control of Lumma's "central command structure" and squashed the online marketplaces where bad actors purchased the malware. The cybercrime control center of Japan "facilitated the suspension of locally based Lumma infrastructure," the blog post said. "Working with law enforcement and industry partners, we have severed communications between the malicious tool and victims," Microsoft said in the post. "Moreover, more than 1,300 domains seized by or transferred to Microsoft, including 300 domains actioned by law enforcement with the support of Europol, will be redirected to Microsoft sinkholes." Cloudflare, Bitsight and Lumen also helped break down the Lumma malware ecosystem.

Read more of this story at Slashdot.

  •  

Google Is Baking Gemini AI Into Chrome

An anonymous reader quotes a report from PCWorld: Microsoft famously brought its Copilot AI to the Edge browser in Windows. Now Google is doing the same with Chrome. In a list of announcements that spanned dozens of pages, Google allocated just a single line to the announcement: "Gemini is coming to Chrome, so you can ask questions while browsing the web." Google later clarified what Gemini on Chrome can do: "This first version allows you to easily ask Gemini to clarify complex information on any webpage you're reading or summarize information," the company said in a blog post. "In the future, Gemini will be able to work across multiple tabs and navigate websites on your behalf." Other examples of what Gemini can do involves coming up with personal quizzes based on material in the Web page, or altering what the page suggests, like a recipe. In the future, Google plans to allow Gemini in Chrome to work on multiple tabs, navigate within Web sites, and automate tasks. Google said that you'll be able to either talk or type commands to Gemini. To access it, you can use the Alt+G shortcut in Windows. [...] You'll see Gemini appear in Chrome as early as this week, Google executives said -- on May 21, a representative clarified. However, you'll need to be a Gemini subscriber to take advantage of its features, a requirement that Microsoft does not apply with Copilot for Edge. Otherwise, Google will let those who participate in the Google Chrome Beta, Dev, and Canary programs test it out.

Read more of this story at Slashdot.

  •  

Starfish Space Announces Plans For First Commercial Satellite Docking

Starfish Space plans to perform the first commercial satellite docking in orbit with its Otter Pup 2 mission, aiming to connect to an unprepared D-Orbit ION spacecraft using an electrostatic capture mechanism and autonomous navigation software. NASASpaceFlight.com reports: This follows the company's first attempt, which saw the Otter Pup 1 mission unable to dock with its target due to a thruster failure. The Otter Pup 2 spacecraft will be deployed from a quarter plate on the upper stage adapter of the SpaceX Falcon 9 rocket, placing it into a sun synchronous orbit altitude of 510 km inclined 97.4 degrees. The target will be a D-Orbit ION spacecraft which will simulate a client payload, which is not equipped with a traditional docking adapter or capture plate as you might see aboard a space station or other rendezvous target. Instead, Starfish Space's Nautilus capture mechanism will feature a special end effector connected to the end of the capture mechanism. This end effector will enable Otter Pup 2 to dock with the ION through electrostatic adhesion. "An electromagnet will be integrated into the end effector and will be used as a backup option to the electrostatic end effector, to dock with the ION through magnetic attraction," the company notes. The goal is to eventually commission its Otter satellite servicing vehicle to allow for servicing of previously launched satellites. The company's first Otter missions include customers such as NASA, the U.S. Space Force, and Intelsat, with the goal of flying those missions as soon as 2026. [...] Following the thruster issues on the first mission, this flight will feature two ThrustMe thrusters, which use an electric propulsion system based on gridded ion thruster technology.

Read more of this story at Slashdot.

  •