Vue lecture

How a Seemingly Harmless Image Can Jailbreak Vision-Language AI Models

Slashdot reader BrianFagioli writes: Florida International University researchers have developed a technique called JaiLIP (Jailbreaking with Loss-guided Image Perturbation) that uses subtle image modifications to bypass AI safety guardrails. Unlike traditional jailbreaks that rely on carefully crafted prompts, the attack works through images that appear normal to human viewers. The researchers tested the technique against BLIP-2, a multimodal AI model, and found that manipulated images significantly increased the likelihood of harmful responses. According to the study, the approach outperformed previous image-based jailbreak methods and nearly doubled the number of unsafe outputs generated during testing. The findings highlight a potential security risk for businesses deploying AI systems that process both images and text. While most discussions about AI safety focus on prompts, the research suggests that seemingly harmless images may also serve as an attack vector.

Read more of this story at Slashdot.

  •  

France's Heat This Week Was Worse Than a Dire Scenario Imagined For 2050

There's a deadly, record-breaking heat wave spreading east across Europe, reports the Washington Post — and it's even worse than a dire earlier forecast: The forecast was recorded in 2014 as part of a campaign coordinated by the World Meteorological Organization (WMO) that invited about 60 presenters worldwide to imagine a weather report from the year 2050. In one clip, Ãvelyne Dhéliat from French television network TF1 presented a hypothetical scenario of high temperatures 36 years into the future — during a heat wave in a warmer climate in 2050... One of the maps that Dhéliat shared was lit up in shades of orange, filled with temperature predictions of 40 degrees Celsius (104 degrees Fahrenheit), reaching as high as 43 degrees Celsius (109.4 degrees Fahrenheit). But it turns out, it didn't take 36 years for those imagined temperatures to be reached — and even exceeded. The heat on Wednesday alone, when the temperature soared as high as 112.3 degrees Fahrenheit (44.3 degrees Celsius), exceeded the 2050 projections in 19 out of 34 locations across mainland France — far sooner than some may have expected. Some places surpassed those hypothetical future temperatures by more than 20 degrees Fahrenheit. It's part of a dramatic shift in heat wave frequency across the country. Half of the heat waves observed since 1947 have occurred since 2010. "By 2100, heat waves could last up to two months continuously," the country's weather agency, Météo-France, said this week. It was hotter in France on Wednesday than in Las Vegas and Phoenix and just two degrees Fahrenheit shy of what was observed in Death Valley, California. An estimated less than one percent of the planet was hotter than France's hottest place... [T]he heat dome, which will linger into early next week, is only part of the story. This type of extreme heat is becoming more common as the planet warms, especially in Europe. Climate scientist Robert Rohde said in a post explaining the heat wave's causes that France and Western Europe should expect many more heat waves like this over the coming decades. "This isn't a fluke, but simply part of the new normal," he said. Thanks to Slashdot reader fjo3 for sharing the news.

Read more of this story at Slashdot.

  •  

Max Planck Slapped With Two Paper Retractions By Suspected Rogue Algorithm

Max Planck won 1918's Nobel Prize for physics. Yet two of his papers were retracted — a move now being criticized by Yves Gingras, a historian of physics at the University of Quebec and Mahdi Khelfaoui, a fellow historian of science at UQ Trois-Rivières. Science reports: The papers, both quietly retracted in 2011, originally appeared in the early 1940s in Naturwissenschaften, a German journal now owned by publishing giant Springer Nature. After some sleuthing, Khelfaoui determined one of the Planck pieces, a philosophical essay from 1942 titled "Sinn und Grenzen der exakten Wissenschaft" ("Meaning and Limits of Exact Science"), about how to achieve certainty in scientific knowledge, had also appeared in two other journals and been reprinted twice in books. Repackaging the same work multiple times is considered "self-plagiarism" and frowned upon today — the practice produces copyright conflicts and inflates scholars' publication records. The Naturwissenschaften site gives "copyright violation" as the reason for the retraction. Yet publishing identical material in multiple journals was widespread before the internet. "Science was more fragmented" then, Khelfaoui says. "You wanted different audiences ... to have access to your work." The practice was especially common for luminaries like Planck. Albert Einstein did the same (but escaped retractions). Springer Nature's "anachronistic" application of modern standards to a 1942 paper "distort[s] the historical record," Gingras and Khelfaoui argue in a preprint posted last month on arXiv. Any concerns about copyright violations are largely moot anyway: Because Planck died in 1947, his works are in the public domain in most countries. Gingras was especially incensed that Springer Nature deviated from the normal practice of merely slapping the word RETRACTED across the digital version of the paper while still allowing scholars to read the text. Instead, the publisher posted a blank white page with the cryptic phrase, "This article has been withdrawn due to article violation." Springer Nature is nevertheless still selling the empty PDF for $39.95. Suzanne Scarlata, a chemist and biochemist at the Worcester Polytechnic Institute and editor-in-chief of The Science of Nature, as Naturwissenschaften is now known, had not heard about the retractions before being contacted for this story... Scarlata suspects Springer Nature's internal policing software removed the paper and posted the retraction notice unilaterally, without human supervision: "I think it just happened with their algorithm," she says. "It's a mistake they should probably rectify." A second Planck paper was apparently removed because its response to a 1940 paper had used an identical title. Thanks to our long-time Slashdot reader He Who Has No Name for sharing the article.

Read more of this story at Slashdot.

  •  

Scroll Burned in 79 AD Volcanic Eruption Finally Deciphered Using AI

When Mt. Vesuvius erupted in 79 A.D., it buried hundreds of papyrus scrolls. They were rediscovered in the mid-1700s, remembers Smithsonian magazine, "the only surviving collection of its kind from the Greco-Roman world..." "But when scholars tried to unroll them, the carbonized manuscripts crumbled to dust." Every generation that followed faced the same dilemma: They could wait for technology to advance, abandoning hope of reading the ancient texts in their own lifetime. Or they could try to open the scrolls themselves — and risk destroying them. In recent years, researchers have settled on a third option. Using advanced imaging and artificial intelligence, they're deciphering the scrolls without needing to unroll them at all. The Vesuvius Challenge has accelerated the process by turning it into a public competition, complete with cash prizes. In 2023, a student won $40,000 for deciphering a single word — "purple" — from an unopened scroll. Later, contestants would identify 2,000 Greek characters from one scroll ($700,000) and the title of another ($60,000). Now, for the very first time, researchers have recovered all surviving text from a single scroll. The nearly five-foot-long segment includes roughly 20 columns of ancient Greek philosophy, accessible for the first time in nearly 2,000 years. "The tech actually does look like magic, but it's not," Brent Seales, a computer scientist at the University of Kentucky, said at a press conference. (The article points out that Seales partnered with two Silicon Valley investors in 2023 to launch the Vesuvius Challenge, and is now hailing "the restoration of lost voices from the ancient world." Seales has been working on virtually unwrapping the scrolls since the early 2000s. The process involved imaging the bundles of papyrus using technology similar to CT scanners, isolating thin layers and then stitching them together.... "We've developed a systematic and a repeatable approach," Seales told the audience. "Now it's only a matter of time until we read all of the scrolls."

Read more of this story at Slashdot.

  •  

California Sheriff Says Their Drone Disarmed a Suspect, Shares Video on Instagram

The Los Angeles Police Department says about 1,500 police agencies across America have drone programs, reports SFGate, and 58 of those drone-using police agencies are in California. The Sacramento County sheriff's office recently posted drone footage on Instagram set to theme from "Mission: Impossible," claiming "a nationwide first" where their drone successfully disarmed a felon "seen earlier with a firearm" (though now not moving, but holding a knife while lying face down in a garage). In the video the "not responding" suspect continues not moving as the drone dangles a magnet which catches on the knife. The drone then pulls multiple times until it comes out of the unmoving suspect's hand. The sheriff's office says their footage shows their drone "disarm an armed suspect, helping bring the incident to a safe resolution," in their post on Instagram, "rather than rush into a potentially deadly encounter..." Was he pretending to be dead or simply lying in wait for deputies to approach...? It's also worth noting that our drones are labeled as "military equipment" (even though anyone can purchase them at their local Walmart), but are really just another piece of technology helping deputies resolve dangerous situations safely. Their use protects both law enforcement personnel and suspects. SFGate offers more reports from around California: In Yucaipa, officials launched a Drone as First Responder (DFR) pilot program on May 28, the San Bernardino County Sheriff's Department announced this month. According to the release, drones have already been used to respond to over 100 calls for service, arriving before deputies for 71% of them. "The drones also contributed to 12 arrests, assisted in locating persons of interest on 37 occasions, and provided aerial overwatch during 44 incidents," it continues, though details on how they assisted the police are unclear. The drones, manufactured by Skydio, were also used to locate a young person experiencing a mental health crisis and another person launching illegal fireworks.

Read more of this story at Slashdot.

  •  

FSF 'LibreLocal' Organized From Prison by Iranian Man Jailed for 'Cyber-Crimes' After Promoting Free Software

Thursday the Free Software Foundation blogged about this year's 47 'LibreLocal 2026' meetups, highlighting 10 that took place in Australia, Mexico, the United States, New Zealand, Cameroon, Switzerland, Spain, Argentina, China, and Iran. "Far from each other in many parts of the world, they came together around one unifying belief: free software." We envisioned LibreLocal as a collage of in-person community meetups that would bring people together to swap ideas, learn from each other, and celebrate free software. When we asked the free software community to organize LibreLocals last year, the response was very inspirational: 29 different meetups were hosted. After we made the global call this year, we were greeted with an even more enthusiastic response... Organizers hosted LibreLocals in cafes, bars, restaurants, libraries, universities, a computer repair shop, and even as part of a field trip to the System Source Museum, a museum dedicated to the history of computing in Hunt Valley, Maryland, USA. We also learned that a LibreLocal was organized inside Vakil Abad Prison in Mashhad, Iran by a free software supporter. Originally planned to be held in Shiraz, we were informed of this change in location on the LibreLocal wiki page set up for listing all LibreLocals. The updated entry, by another free software supporter in Iran, reads: "This year, one of our dedicated activists organized a LibrePlanet event from within prison in Iran. Currently serving a sentence for "cyber-crimes" related to his promotion of free software, he continues to introduce the principles of software freedom to his fellow inmates. We have placed this banner to honor his resilience and the community of individuals in prison who continue to stand for technological freedom. His identity will be revealed when it is safe to do so." Advocating for user freedom should never result in a prison sentence. We especially admire and respect the bravery and strength of those who fight for software freedom in the most dangerous and oppressive of environments. 50 people attended the LibreLocal meetup in Switzerland, according to one of the organizers, "forging connections between several local free software stakeholders and strengthening their cohesion." But the FSF's blog post stresses these are "ten stories among many more of free software supporters from across the globe... We also thank you our donors and associate members for the support that makes such meetups possible." The GNU Press Shop is now open through July 19 for their biannual fundraiser, offering a variety of freedom-respecting novelties including an FSF-branded antisurveillance webcam guard and both technical and philosophical books, like Richard Stallman's Free as in Freedom (which allegedly has turned up in Anthropic's training data). Other items include a slick new FSF logo sticker, a brass and zinc GNU "emblem" pin with real gold plating, and a cheeky sticker reminding everyone that "There is no cloud." And there's even a plush GNU toy.

Read more of this story at Slashdot.

  •  

Bitcoin Drops Again. Skeptical Investment Strategist Calls It 'Useless'

Friday Bitcoin closed at just $59,948 — dropping 19% just for June and more than 50% lower than its record high in October of $124,310. To commemorate the occasion CNBC interviewed long-time bitcoin skeptic Jeremy Grantham, reporting that the 87-year-old cofounder/chief investment strategist of the massive asset-management firm GMO is "predicting it will gradually fade into irrelevance over decades." [The] longtime market commentator known for his calls on asset bubbles said bitcoin is a "useless, speculative" asset without intrinsic value, speaking on CNBC's "Squawk Box" Friday. He also said bitcoin hasn't outperformed during a bull market and questioned its practical use. "[Over] years and years, decades and decades, it will dwindle away, I suspect — not with a bang, but a whimper," he said. "It's not a stable form of value — it just halved ... for no particular reason in a strong economy, so you can't depend on it in that way." He added that gold has still delivered solid gains over the same period, even after pulling back from its highs. Bitcoin not only hasn't proved itself as a useful asset to speculate on, it doesn't provide any real world utility either, Grantham argued. "People don't use it to make serious trades, they don't use it to buy their dinner and pay at the supermarket. ... What it does is allows crooks to move money around," he said. Bitcoin has become notorious over the years for its dramatic bear market crashes, which has taken it down at least 70% from its peak in every cycle. The article adds that "many investors believe the current price slump could drag on for several more months."

Read more of this story at Slashdot.

  •  

US Government Allows Anthropic Limited Release of 'Mythos' AI Model, Saying 'Appropriate Safeguards are in Place"

"The US government has allowed Anthropic to release its powerful Mythos AI model to select companies and organizations," reports CNN, "revising license requirements after ordering an export block earlier this month in the wake of national security fears." Since the export ban earlier in June, "Anthropic has worked with the US government to address risks associated with the Covered Models," Commerce Secretary Howard Lutnick wrote to the company in a letter dated Friday. In light of progress in that work, Lutnick wrote, "I have determined that appropriate safeguards are in place to permit certain trusted partners to access the Claude Mythos 5 Model." The letter does not include permission for Anthropic to release Fable, a less powerful version of Mythos. "We received notice from the US government that Mythos 5, our strongest cybersecurity model, can be redeployed to a small group of cyber defenders and infrastructure providers," Anthropic said in a statement... Conversations between Anthropic and the government are expected to continue into the weekend, with an eye to restoring access to Fable, as well, a source familiar with the discussions told CNN.

Read more of this story at Slashdot.

  •  

Several US States Bet That AI Can Solve Their Prison Recidivism Crisis

America's state prison systems need ways "to keep people from returning to prison," reports the Wall Street Journal, "when an estimated 40% end up back behind bars within three years." Part of the problem comes in the form of filing cabinets, manila folders and legacy digital databases. In other words, records for a single prisoner might be kept in a dozen places... Now a group of 19 prison systems are tackling the problem with digital tools and artificial intelligence in some cases. They are contracting with San Francisco nonprofit Recidiviz, whose computer systems bring together prisoner data from its disparate sources into digital dashboards. From there, corrections staff can see information — such as court records and notes from parole-board hearings — about a prisoner or parolee all in one place. The company says its efforts are working: Recidivism has fallen 16% in the prison population its systems track. It is the result of "just streamlining these workflows and knitting someone's journey together end to end," says Clementine Jacoby, chief executive officer of Recidiviz. Some criminal-justice groups show that recidivism is trending downward in general, though most of that data is nearly a decade old... The statistics from 11 states stop at 2019, and for four states stop at 2016. With 10 other states, no data was reported.

Read more of this story at Slashdot.

  •  

'Tutor' Who Took Online Tests for 124 Students Jailed for Three Years

A private tutor who charged money to take dozens of exams for students and submit coursework for them "has been jailed for three years," reports the BBC, "after his scam earned him £300,000." Shahid Adnan completed assignments and online tests for more than 120 students at Liverpool John Moore's University, the Crown Prosecution Service said. The 43-year-old, of Lysander Close, Liverpool, was caught in February 2023 after a student handed in a USB drive containing suspicious coursework to Dr Tom Berry of the university's school of computer science and mathematics. Berry's checks revealed the drive was used by Adnan with documents linked to a company he set up called Study Sharp Ltd. Excel spreadsheets containing details of other students, their study modules, coursework due dates, and their personal login credentials were also found. Further checks confirmed suspicions that Adnan was accessing the university's network to submit fraudulent work and sit examinations on behalf of students... [I]nvestigations led police to believe Adnan may have been doing work for 124 students at universities all over the world. The BBC also interviewed detective sergeant Adam Dagnall from Merseyside Police's cybercrime unit, who said Adnan was living a lavish lifestyle "well beyond" his stated occupations as a private tutor and Amazon delivery driver. His bank accounts held more than £2m ($2,645,100 USD).

Read more of this story at Slashdot.

  •  

TikTok Shows 3x More AI Slop Than YouTube, Report Finds

"About 59% of TikTok videos served to a new account's For You feed are AI slop," writes Search Engine Journal, "according to a report from Kapwing, the video creation tool company. That's roughly three times the rate Kapwing found on YouTube." The company manually reviewed over 10,000 TikTok videos across 20 categories and ran a separate fresh-account test, counting AI-generated content in the first 500 For You videos. Kapwing ran the same fresh-account test on YouTube and found that 104 of the first 500 Shorts, or 21%, were AI slop. On TikTok, 294 of 500 For You videos hit that threshold... Of the 2,000 videos Kapwing reviewed in TikTok's Kids category, 57% were AI slop. That was the highest rate of any category in the analysis. The highest-rate tag was #cartoonkids, where 97 of 100 featured videos were AI-generated. Tags like #cartoons and #babysong both reached 83%, and #forkids came in at 79%. After Kids, the next highest AI slop rates were in Science and Education (35%), Health (33%), and History (33%). All three are categories where visual illustration and voiceover narration make up much of the content. On the other end, categories where on-camera presence or physical demonstration are central had the lowest rates. Fashion came in at 1.3%, Music at 1.5%, and Fitness at 1.6%. The article notes that by last November, TikTok "had already labeled 1.3 billion videos as AI-generated, according to the report."

Read more of this story at Slashdot.

  •  

Someone Forked systemd Over Its New Birth Date Field

The blog Linuxiac reports: A new systemd fork has appeared with a specific purpose: removing systemd's recently added support for storing a user's birth date in JSON user records. The fork, called Liberated systemd, published its first tagged release as v261 shortly after the official systemd 261 release. In other words, the fork follows upstream systemd while reverting the change that added the new optional birthDate field. Importantly, this is not a new init system, a wider redesign of systemd, or a general-purpose alternative to the upstream project. Its stated purpose is to remain close to upstream systemd while removing what the author describes as "surveillance enablement"... The author recommends testing the fork in a virtual machine before using it on real hardware and warns nightly builds are more likely to be unstable than named releases.

Read more of this story at Slashdot.

  •  

The Secret Revolution in Battery Technology: 3-D Printing

"There's a revolution in battery technology hiding in plain sight," reports The Wall Street Journal. "The 3-D printing of batteries has the potential to put energy storage inside any device. "This will enable lightweight and long-lasting consumer gadgets, long-range military drones and even nanoscale robots." Almost all the innovations we regularly hear about — from cheaper, tougher electric-vehicle batteries to "Holy Grail" solid-state batteries — are about changing the chemistry of batteries. The promise of battery-tech 3-D printing (aka additive manufacturing) is simple: What if batteries could fill any available space, even structural elements of our gadgets, rather than always taking a rigid shape like a pouch or cylinder? The new approach has obvious appeal. The entire airframe of a drone could be filled with energy storage for increased range. Smartglasses could have sleek battery-packed frames, so they look like everyday eyewear rather than "Revenge of the Nerds" props. One of the biggest advantages of 3-D printing is that it works with any battery, regardless of its cell chemistry. It could advance today's lithium-ion as well as emerging sodium-ion and solid-state tech... Some [startups] are trying to use 3-D printing to create efficiencies in existing battery manufacturing systems. A brave handful of startups are pursuing radical new designs and approaches. They're starting with defense applications, where cost and scale are less of an issue... At Silicon Valley-based Sakuu... [r]ather than trying to 3-D-print whole batteries, the company is working on replacing one of battery manufacturing's biggest pain points, says Arwed Niestroj, Sakuu's chief operating officer, who is also a nuclear physicist and former head of Mercedes-Benz Research & Development North America. Existing battery assembly lines include football-field-long ovens for drying layers of material that have been dissolved in solvents. This requires a huge amount of energy and is a significant contributor to manufacturing costs, a big reason EV batteries aren't cheaper. Sakuu's process, under development for years, uses additive manufacturing to lay down key battery components without solvents, eliminating the need for ovens, says Niestroj. Sakuu is currently working to commercialize this tech with a major battery manufacturer...

Read more of this story at Slashdot.

  •  

Is Tesla Planning To Sell Modular AI Data Center Hardware?

Electrek reports: Tesla wants to sell modular AI data center hardware, according to a new trademark application for a product called "Megapod." The filing describes a complete, self-contained computing system for AI workloads... Tesla filed the "Megapod" trademark (serial number 99893717) with the U.S. Patent and Trademark Office this month, through its longtime IP counsel. It's an intent-to-use application, meaning Tesla is claiming the name for a product it hasn't launched yet. The goods-and-services description is unusually specific for a trademark. Megapod covers "modular data center hardware systems for artificial intelligence computing, comprised of computer servers, computer hardware for artificial intelligence data processing, networking equipment, power distribution units, and cooling systems." It also covers "self-contained modular computing hardware systems for artificial intelligence workloads," integrated platforms sold as a single unit — an enclosure bundling compute, power distribution, and cooling — and downloadable software to monitor, manage, and optimize those systems. In plain terms: Tesla wants to sell a turnkey AI data center building block. Not a battery, not a chip on its own, but the full rack-and-room of servers, networking, power, and cooling that AI training and inference run on. Tesla's offering would have to compete with Nvidia's liquid-cooled, rack-scale systems that simulates a giant GPU, the article points out. But "The bigger issue is that Tesla has no merchant compute-hardware business to build on." Tesla's own AI training cluster, Cortex at Gigafactory Texas, runs on roughly 67,000 Nvidia H100-equivalent GPUs. In other words, Tesla is one of Nvidia's customers, not a competitor selling alternative hardware... Where Tesla does have a real AI-data-center business is power, not compute. Its Megapack and new Megablock energy storage products are selling into AI data centers as grid buffers — Musk's own xAI has bought roughly $1 billion of Megapacks to keep its training runs powered. That energy-storage strength is the one credible thread here. A Megapod that bundles Tesla's power electronics, thermal management, and the enclosure — the "shell" around the chips rather than the chips themselves — would at least sit adjacent to a business Tesla actually runs.

Read more of this story at Slashdot.

  •  

UK Official Promises Statements 'Around VPNs' and Further Teen Restrictions on Chatbots and Social Media

PC Gamer reports: The UK government is considering an Australia-style ban on social media for under-16s, with Prime Minister Keir Starmer saying that the ban could take effect as soon as spring next year. As for the much nearer future, Science and Technology Secretary Liz Kendall told BBC Breakfast earlier this week, "We will make further statements in July about VPNs and further restrictions." To be clear, no specific restrictions have yet been announced and Kendall sounded somewhat cautious about an outright ban during a parliament debate that took place the same day. "I have commissioned further research about their usage. There are really important issues to balance here," she says. "Many people want to use VPNs for privacy — that is important — but we know that some children use them to get around restrictions. I will come back to that in July in our response to the consultation." So, we'll have to wait until next month for anything definite, but it's hard not to feel like a full ban on VPNs is already on the table. If that does come to pass, more than the contents of my Bluesky inbox will be at stake. Utah in the US has already tried to implement a full VPN ban (though this was postponed until September after Aylo, the parent company of Pornhub, challenged the law in court)... [T]he UK could just be the next domino after Utah, potentially setting off a chain reaction that affects users around the world. The article also argues that age checks can also be a privacy nightmare "with the security breach that exposed the personal info of 70,000 Discord users last year being one case in point." Here's the complete statement from UK Technology Secretary Kendall. "I'll come back in July with a further statement around VPNs but also additional measures that we want to look at, further restrictions on AI chatbots that parents have found very worrying, more about overnight curfews or breaks in doomscrolling for 16- and 17-year-olds."

Read more of this story at Slashdot.

  •  

Cops Keep Getting Arrested for Using Flock's Cameras to Stalk People

404 Media remembers how a Florida police office looked up his ex-girlfriend's license plate in the Flock automated license plate reader system at least 69 times in 2024 — even searching for her mom's license plate at least 24 times. The police office was charged with stalking and hacking-related offenses, serving one day in prison with five years of probation — but his case "was not a one-off." [Alternate link via Bruce Schneier] Local news reports from around the country repeatedly detail police abusing the Flock surveillance system in order to stalk their partners or ex-partners. The contours of each story are much the same, with the police officer in question using their access to the system to repeatedly track a specific person over the course of weeks or months. The cases highlight the fact that Flock can be used to track the whereabouts of individual people, that police do not get a warrant in order to use the system, and that, if they have access to the system, they have the technical ability to look up any license plate they want for any reason they want. An April study by the civil rights group Institute for Justice found that at least 18 police officers have been caught around the country using Flock to stalk a romantic interest in the last few years; another database, called the ALPR Abuse Library, has documented 20 specific cases of "stalking/targeting" around the country. The known cases of police stalking are almost certainly a vast underreporting of the overall abuse, because they largely include only cases in which the behavior was so egregious that it led to police officers being fired, arrested, or both. Flock told 404 Media that it is "aware of 15 incidents of abuse, each surfaced because of the transparency and accountability features deliberately built into our platform.... There are also 140,000 monthly active users of Flock, so the relatively rare instances of abuse, while obviously wrong and awful, are exactly that — rare," a Flock spokesperson told 404 Media. [One in 10,000.] "Humans are fallible; unlike most tools society provide law enforcement, Flock ensures that in the instances when our technology is misused, the evidence used to hold responsible parties accountable, is right there in our system. We also encourage all our customers to have a usage policy, regular training, and to implement our Audit Assistance tool, which proactively flags unintended use...." But it is also the case that Flock has strenuously fought against lawsuits and potential regulations that are seeking to require police to get a warrant to use the system. And many cases of abuse have not been detected by police departments themselves but by those private citizens, journalists, and stalking victims who have found patterns of abuse in public records files they have obtained from their local police departments. In most cases of Flock-related stalking reviewed by 404 Media, the abuse occurred over the course of months or years, and the victims were subjected to dozens or hundreds of lookups. Other abuse cases have been discovered using the website HaveIBeenFlocked.com, a website that compiles Flock searches released via public records requests and turns them into a searchable database. Flock has repeatedly tried to get that website taken down, as we have previously reported.

Read more of this story at Slashdot.

  •  

After Six Years Of Work and Over 360 Patches, Linux 7.2 Finally Removes Bug-Prone strncpy

Tech Times reports: Linux 7.2's merge window closed out a cleanup campaign on Friday that most kernel developers had stopped expecting to see end: the complete removal of strncpy(), a C string-copy function that the kernel's own documentation labels "actively dangerous," from every subsystem, driver, and architecture-specific file in the kernel source tree. The merge landed June 20, 2026. After around 362 commits spread across six years of incremental work, no call site using the function remained, and the function itself — including the last per-CPU-architecture optimized implementations — was struck from the source. The removal matters beyond housekeeping. strncpy() is a persistent source of a specific class of memory error: kernel buffers that contain sensitive data can leak bytes past an unterminated string boundary, a pattern that enables memory disclosure vulnerabilities. Eliminating the function from the tree removes that entire class from the kernel's attack surface — and, critically, makes strncpy() unavailable to any future contributor, turning a best-practice suggestion into an enforced policy. Phoronix notes it's replaced by five different functions: In place of strncpy, Linux kernel code should use strscpy() for NUL terminated destinations, strscpy_pad() for NUl-terminated destinations with zero-padding, strtomem_pad() for non-NUL-terminated fixed-width fields, memcpy_and_pad() for bounded copies with explicit padding, or memcpy() for known-length memory copies. "The reason five functions were needed," explains Tech Times, "is that different parts of the kernel were using strncpy() for five semantically distinct memory operations — each with a different intent, different termination requirement, and different padding behavior. " The original function obscured all of those differences under a single ambiguous name. The 362-commit campaign to replace it was, in effect, a codebase-wide audit that forced every call site to declare its actual intent in code That is an engineering outcome with lasting value: the kernel's string-handling semantics are now explicit where they were previously implicit, and future maintainers can read a function name and understand what a copy operation actually does.

Read more of this story at Slashdot.

  •  

US Bill Would Mandate AI Chip Location Tracking to Thwart China and Other Adversaries

NBC News reports: A group of companies that specialize in tracking international shipments of sensitive technologies is backing a Capitol Hill bill that would require America's most powerful AI chips to incorporate stronger security mechanisms aimed at preventing the chips from reaching China and other adversaries. The letter, signed by six companies, says the Chip Security Act (CSA) would increase American chip companies' competitiveness and close key loopholes in the U.S. export control regime. The move clashes with claims from semiconductor lobbying groups that the requirements would constrain America's booming chip industry. Sent to congressional leadership Thursday morning and seen by NBC News, the dispatch instead argues that more robust security verification would assure chip customers and manufacturers that they are abiding by sensitive restrictions on chip sales. The companies argue that the boosted confidence will "lead to increased sales, faster export approvals, larger transactions, greater access to new markets, and more expansive chip deals." Despite U.S. export control laws banning sales of advanced AI chips to certain countries, including China, loopholes in current requirements have allowed billions of dollars' worth of America's best AI chips to be sold to entities in third-party countries that can then forward them to China. In just one case in March, the Justice Department charged three people with conspiring to forward $2.5 billion of AI chips to China. The CSA aims to address those loopholes, mandating that chip exporters better track where advanced chips are sent, via either bespoke location-verification hardware or software that can run on existing hardware. That, bill proponents claim, would ensure that sensitive chips could be sold to countries like Malaysia or Indonesia without fear of further transfer to China... Experts say that because chips perform the advanced computations required for frontier AI systems, cutting off access to the chips is crucial to prevent geopolitical rivals from using AI systems for military or economic purposes.

Read more of this story at Slashdot.

  •  

The Rust Ecosystem Gets an AI Security Engineer in Residence

While the Rust Foundation has a Security Initiative to protect its ecosystem, "the threats have expanded," they announced this week, "and so has the kind of help maintainers need." Much of this comes back to a single shift: Automated tooling (much of it now built on large language models) has gotten good enough to surface real vulnerabilities in open source code quickly and at scale. That is useful, and several large Rust projects have already received and fixed credible issues found this way. The same tooling has also made it trivial to generate vulnerability reports that look plausible and are worthless. Maintainers across the ecosystem are losing real hours sorting these from the reports that matter, and the noise tends to bury the signal. So, with funding from the Alpha-Omega Project, the Rust Foundation is bringing on a full-time AI Security Engineer in Residence dedicated to the Rust ecosystem. This position is being funded with part of the $12.5M in open source security funding that the Linux Foundation announced in March. The role exists to take pressure off maintainers. The person in this position will use a mix of human-led and AI-assisted methods to proactively review Rust itself and the crates the ecosystem leans on most and help us separate real, exploitable issues from false positives and low-signal noise before anything reaches a maintainer... This role will run full-time for six months to start, with room to extend depending on what we learn and the funding available. Methods, playbooks, and prompts will be documented so the work doesn't end with the contract. We are grateful that Rust is not embarking on this work in isolation. Several other ecosystems have received parallel Alpha-Omega grants for the same kind of work (e.g., the PHP Foundation and the Drupal Association) and we plan to share tooling, triage practices, and what we learn rather than duplicating work A statement from Rust's new AI Security Engineer in Residence acknowledges that "One of our next challenges is the wave of bugs discovered by the next generation of AI-powered developer tools."

Read more of this story at Slashdot.

  •  

Canonical's Upcoming AI Tool: Talk to Ubuntu Instead of Typing

This week the Ubuntu desktop's director of engineering announced they're bringing speech-to-text dictation to Ubuntu Desktop, aiming for an experience "that feels like a natural part of the desktop while respecting user privacy and running entirely on local hardware." "Speech recognition has become a common feature on modern platforms, and we think it should be a first-class experience on Ubuntu Desktop as well." More details from the blog It's FOSS: For Ubuntu 26.10, the initial version of Myna is expected to be a desktop dictation tool built around GNOME on Wayland with a push-to-talk mechanism gatekeeping when your microphone accepts input. Using it means holding a hotkey, speaking, and letting go. A small activity indicator shows while it is listening, and the transcribed text lands wherever the cursor was sitting when dictation started. Recognition itself happens inside a sandboxed component called the Canonical Inference Snap, while a Speech Orchestrator manages the session and an Audio Adapter handles whatever the microphone picks up, denoising and chunking it before it ever reaches the model... Speech recognition will happen locally, and an internet connection is not needed once the appropriate model is installed... The audio data won't be sticking around either, being stored in a small in-memory buffer that gets discarded the moment the session ends. Features like dictation into password fields, wake words, continuous listening, voice assistants, voice commands, translation, speaker identification, and automatic language detection are all off the table... You should also know that Canonical is looking for feedback before the specs for Myna are finalized, especially from people who already rely on dictation or assistive tools on Linux.

Read more of this story at Slashdot.

  •  
❌