Vue lecture

Decades-Old Bash Tricks Expose AI Coding Agents To Supply Chain Attacks

Slashdot reader wiredmikey writes: AI security researchers have uncovered a structural security flaw dubbed GuardFall that allows decades-old Bash shell tricks to bypass safeguards in most open source AI coding agents. By exploiting shell behaviors such as quote removal and variable expansion, attackers can hide malicious commands in repositories, README files, Makefiles, or other content consumed by AI agents. If executed — particularly in auto-approve or CI environments—the commands can steal credentials, compromise developer systems, or enable software supply chain attacks. According to researchers at Adversa AI, the 11 popular open source AI coding agents tested, only one successfully blocked all of the Bash trick techniques.

Read more of this story at Slashdot.

  •  

Alibaba To Ban Claude Code In Workplace Over Alleged Backdoor Risks

Alibaba has reportedly banned employees from using Anthropic's Claude Code and directed them to its own Qoder platform amid a growing dispute over features that can help identify China-linked users. Reuters reports: The ban is part of a deepening spat between the two companies after Anthropic accused Alibaba of illicitly extracting its Claude AI model capabilities -- a dispute that highlights the frantic race between the U.S. and China to take the lead in artificial intelligence. [...] Anthropic said last month that it had suffered a strike by Alibaba, which it described as a "distillation" effort that involves training a less capable model on the outputs of a stronger one. The distillation helps accelerate China's ability to reach Anthropic's advanced Mythos Preview capabilities, it said in a letter seen by Reuters that was sent to two U.S. senators. Alibaba's ban comes just days after developers said Claude Code contained mechanisms that inspected user environments, including timezone and proxy-related information, and inserted subtle markers into prompts sent to Anthropic's servers. An Anthropic employee wrote on Tuesday on X that the feature was "an experiment we launched in March" intended to prevent account abuse by unauthorized resellers and protect against model distillation. The person who spoke to Reuters about Alibaba's ban said that Anthropic's restrictions targeting China were difficult to enforce on individual users who can deploy servers in the United States and make traffic appear as if it originated there. But companies were more aware of legal and compliance risks, the person added.

Read more of this story at Slashdot.

  •  

Godot Game Engine No Longer Accepts AI Code

The Godot Foundation will stop accepting AI-authored code, agent-submitted pull requests, and AI-generated text in contributor communications after maintainers were overwhelmed by low-effort submissions. "It is time for us to recognize that these problems aren't going away and therefore we need to take steps to reduce the burden on maintainers while ensuring we still have a pipeline to mentor new contributors to become future maintainers," the Godot Foundation said in a blog post. Contributors may still use AI for limited "menial things" if they disclose it, but humans must understand, own, and be able to fix the code they submit. PC Gamer reports: The Foundation says the pileup of Godot pull requests pending review isn't all bad: It's a sign that interest in using and contribution to Godot is increasing. But the influx of contributions authored or submitted by AI is sapping the projects' maintainers of their willingness to confront the "already tedious" work of reviewing pull requests. "If your feedback on PRs is just being absorbed by a machine and not going towards mentoring a potential future maintainer, it becomes much harder to justify spending your free time on PR review," the Foundation said. As the problem becomes increasingly unsustainable, the Godot Foundation says it's in the process of updating its contribution policies, focusing on "adding barriers to low-effort slop" contributions, encouraging maintainers to review code, developing new contributors into future maintainers, and crucially, requiring that all contributions come from humans who are accountable for their code -- and fixing it if it fails. "AI cannot take responsibility, and we can't trust heavy users of AI to understand their code enough to fix it," the Foundation said. The Foundation says we can expect Godot's contributing policy to soon include explicit rejections of AI-authored code, noting that contributors should only use AI assistance for "menial things" and must disclose its use. Additionally, the Foundation will reject any AI-generated text in human-to-human communications, saying it's "a basic principle of respect" -- though it says machine translations "are still acceptable" if the original text was human-authored. "Things change every day with respect to the current suite of AI tools available," the Foundation said. "We will continue taking a conservative approach in our policies towards them, but we will re-evaluate as things evolve."

Read more of this story at Slashdot.

  •  

OpenAI 'In Early Talks To Give 5% Stake To US Government'

OpenAI is reportedly in early talks to give the U.S. government a 5% stake, potentially alongside similar contributions from other major AI companies. "Such a deal would help improve the industry's relations with the Trump administration and could help garner political support by sharing wealth generated by the AI boom with the public," reports The Guardian. From the report: [OpenAI CEO Sam Altman] and other OpenAI bosses have suggested that each of the biggest AI developers in the US should give 5% to their equity to an investment vehicle such as the Alaska Permanent Fund, a sovereign fund that invests US oil wealth into stocks and pays dividends to the state, the FT reported. The talks are "conceptual" and in early stages, it said, and any deal could require an act of Congress to implement. Both OpenAI and Anthropic have previously suggested in policy papers that a public or sovereign wealth fund may be required in the future to distribute shares to the public. In April, OpenAI said that a "public wealth fund" could provide "every citizen -- including those not invested in financial markets -- with a stake in AI-driven economic growth." Further reading: Bernie Sanders Unveils $7 Trillion Plan To Give Americans Control of AI Industry

Read more of this story at Slashdot.

  •  

SpaceX Reportedly Has an AI Device Prototype

According to the Wall Street Journal, SpaceX showed investors an early prototype of a slim, "handset-like" AI device running a proprietary operating system and integrating xAI technology. Elon Musk, however, denied the report, calling it "utterly false." TechCrunch reports: SpaceX, alongside sister company Tesla, does have the manufacturing expertise to pull off mass-producing a bunch of AI devices -- not to mention access to the chips needed to power any on-device compute. SpaceX has also signaled that it's keen to expand into wireless, with Starlink Mobile as a potential competitor to Verizon and AT&T. One analyst even went as far as to speculate that T-Mobile or AT&T would make fine acquisition targets for the rocket builder, though such a purchase would, undoubtedly, be pricey. It's also not clear if SpaceX is just throwing spaghetti at the wall or if it will attempt to really mass-produce and market such a device. But one thing that seems clearer is that if OpenAI is doing it, Musk would, perhaps, want to try to do it better. [...] Like OpenAI, SpaceX's prototype is reportedly designed to run on a proprietary operating system and integrate technology from xAI, Musk's AI company that SpaceX acquired earlier this year. This would prevent these new devices from being trapped inside another company's platforms (like Google's Android). But the intent also appears to be to create something new, with native AI interfaces. That said, the graveyard is crowded with the unsuccessful launches of AI devices from companies like Humane and Rabbit. A company wanting to sell an AI device does not equate to consumers wanting to buy such a thing. Yet.

Read more of this story at Slashdot.

  •  

Essai Mercedes GLB de 354 ch

Dans un contexte où le marché électrique a bondi de 50% depuis le début de l’année en France, Mercedes lance le GLB, qui existe avec des motorisations légèrement hybridées et 100% électriques. L’EQB disparaît donc logiquement du catalogue. Nous l’avons découvert dans sa version 350, avec sa grosse batterie de 85 kWh, sur les routes exigeantes du Pays basque.

94 étoiles dans la calandre

Même s’il est complètement nouveau, on reconnaît au premier coup d’œil l’allure d’un GLB. On remarque ses dimensions de SUV compact (4,73 m) et cette carrosserie cubique, très verticale à l’arrière, si typique de ce modèle. À l’avant, on devine le style actuellement en vogue à Stuttgart, avec cette calandre XXL aux 94 étoiles illuminées la nuit sur notre modèle 100% électrique, et des feux de jour reprenant l’Étoile. Dans sa finition AMG Line, il a même un petit air de SUV dynamique qu’on ne lui soupçonnait pas au premier abord.

L’arrière s’avère bien spécifique à ce nouveau GLB, avec un bandeau en U inversé entièrement éclairé, tout juste souligné par deux étoiles de chaque côté. Ce détail de design s’intègre mieux selon nous avec un coloris foncé plutôt que clair. Pour le reste, il faut tout de même reconnaître que Mercedes a assez arrondi les angles de son nouveau GLB. Il garde ainsi la plupart de ses codes marquant sa personnalité, tout en se modernisant pour intégrer quelques éléments communs aux Mercedes les plus modernes, afin de mieux l’identifier comme un membre de la famille. Pour nous, cela nous paraît plutôt réussi.

Trois écrans!

On aimait beaucoup les intérieurs des Mercedes des générations précédentes, mêlant finition tirée à quatre épingles et dernières technologies. Rassurez-vous, c’est toujours le cas, notamment le côté spectaculaire des animations lumineuses. Simplement, de nos jours, le constructeur laisse beaucoup moins de place sur la planche de bord à de beaux matériaux. La présentation se trouve ainsi assez simplifiée, puisque les écrans prennent littéralement toute la place. Ils ont tout de même laissé un peu d’espace aux extrémités pour intégrer les aérateurs, toujours très beaux chez Mercedes.

Pour le reste, la console centrale flottante offre un très large espace de rangement. Bien entendu, le GLB est à la pointe en termes d’équipements, avec des commandes vocales, une dalle tactile et quelques autres raccourcis. On retrouve également des sièges massants et un toit vitré extrêmement sophistiqué dans sa façon de s’opacifier. On ne manque pas de place au second rang, avec une banquette coulissant sur 16 centimètres. Grâce à un empattement largement rallongé par rapport à la génération précédente, on gagne de l’espace et l’on peut toujours emmener deux passagers supplémentaires dans un confort relatif. Le coffre va de 480 à plus de 1 700 litres, toutes les assises rabattues, sans oublier le frunk géant de 127 l.

Consommation remarquable

Le GLB 350 4Matic a droit à deux moteurs, pour une puissance totale de 354 chevaux, rien que ça. Au passage, on dispose de deux rapports sur lesquels on n’a pas la main. Les performances sont bien entendu remarquables, avec un 0 à 100 km/h exécuté en 5,5 secondes. La vitesse de pointe de 210 km/h assure la perte du permis en dehors de l’Allemagne. On s’en doutait, la motricité se révèle exemplaire avec sa transmission intégrale. Cela rassure dans toutes les circonstances de conduite, ce qui n’est pas toujours le cas avec les puissantes électriques, qu’elles soient à traction ou propulsion.

Mercedes a atteint une certaine maîtrise en matière de consommation électrique, avec une consommation relevée de moins de 16 kWh/100 km sur un itinéraire très vallonné, assez défavorable pour se rapprocher du chiffre d’homologation. En outre, la consommation instantanée sur quelques kilomètres de voies rapides n’a grimpé que de 2 ou 3 points en roulant entre 120 et 130 km/h. Une donnée à consolider lors d’un trajet plus long et varié. Avec sa batterie de 85 kWh, on peut effectivement espérer faire un Paris-Lyon avant de s’arrêter, si votre vessie ne vous a pas stoppé avant… L’architecture 800 V assure un passage de 10 à 80% en une vingtaine de minutes. À la maison, sur une prise domestique, il faudra compter un peu moins de deux jours, contre environ 9 heures sur une borne 11 kW.

Le plein de technologies à bord

On attend Mercedes au niveau du confort de conduite et de vie à bord. Là aussi, le constructeur de Stuttgart ne déçoit pas, avec une douceur permettant d’aligner les kilomètres en toute quiétude. Le fin réglage des ADAS, notamment la conduite semi-autonome de niveau 2, rend la vie encore plus facile derrière le volant. Mais comme nous aimons tout de même prendre les commandes sur ces routes tortueuses du Pays basque, nous nous en sommes remis à notre talent. La régénération est réglable avec les palettes derrière le volant, ce qui est un vrai point fort. Néanmoins, il semble manquer un niveau intermédiaire. Peut-être sommes-nous un peu trop tatillons.

Il existe bel et bien un mode baptisé « Sport ». Soyons clairs, cela signifie qu’il booste son dynamisme, en particulier sa réactivité. Les suspensions pilotées se raffermissent aussi, mais de manière plus subtile pour préserver un minimum de confort à bord. On ne bouscule pas sans ménagement ses passagers dans une Mercedes, surtout lorsqu’il ne s’agit pas d’une AMG, et encore moins pour un modèle familial. Toujours est-il que la conduite électrique renforce nettement le sentiment de douceur, grâce à l’absence d’à-coups et de sensations parasites propres à un SUV compact thermique, même hybridé.

Dès 46 950 €

Le nouveau Mercedes GLB, pour rappel également disponible en hybride, ne s’avère pas vraiment bon marché, ce qui n’a rien de surprenant. Pour rassurer ses propriétaires, même en occasion, la batterie est garantie 8 ans ou 160 000 kilomètres. Les tarifs démarrent à 46 950 €, l’électrique à 55 900 €. Le 350 4Matic réclame au moins 61 100 €, 65 900 € en finition AMG Line, auxquels il faut ajouter bien sûr quelques options, dont certaines, selon nous, indispensables, comme l’adaptateur pour bornes 400 V à 700 €, et le pack Premium Plus, particulièrement valorisant avec les technologies qu’on apprécie.

L’article Essai Mercedes GLB de 354 ch est apparu en premier sur Le Blog Auto.

  •  

Siri AI en Europe : Tim Cook tente d’apaiser les tensions avec la Commission européenne

Selon les informations du Financial Times, Tim Cook s'est entretenu avec Henna Virkkunen, la responsable du numérique à la Commission européenne, lors d'une réunion qualifiée de « constructive » par les deux parties. Au cœur des discussions : trouver un moyen de lancer Siri AI en Europe sans qu'Apple écope d'amendes.

  •  

Claude Fable 5 et Mythos 5 sont de retour : Anthropic rétablit l’accès dans le monde entier

19 jours après leur coupure brutale sur ordre de Washington, Claude Fable 5 et Claude Mythos 5 sont de nouveau accessibles. Le département du Commerce américain a levé le 30 juin les contrôles à l'exportation qui bloquaient les deux modèles d'Anthropic, ouvrant la voie à un retour progressif dans le monde entier.

  •  

Trump Drops Restrictions On Anthropic's Mythos and Fable Models

The Trump administration has lifted export restrictions that forced Anthropic to shut off public access to its Mythos and Fable models. After weeks of talks, Secretary of Commerce Howard Lutnick said Anthropic "has agreed to proactively detect and address security risks associated with the models; to work diligently with the U.S. government on protocols and standards and releases for Mythos, Fable and future models; and to inform the US government of any malicious activity." Access is set to begin returning July 1. TechCrunch reports: Anthropic had already publicly pledged to do much of this voluntarily, months before the export rule existed. That's part of why cybersecurity experts were skeptical of the restrictions in the first place. To them, the ban looked less like a security fix and more like leverage, a way for the Trump administration to punish Anthropic for its executives' public criticism of how the government, and the president's political opponents, might use the technology. Mythos was originally made available to a select group of organizations beginning in April to allay concerns about its ability to identify and exploit vulnerabilities in software, while a version called Fable was released to the public in June with additional security guardrails. However, with Asian AI companies beginning to release their own AI models approaching Mythos-level capabilities -- among them Fugu and Tulonfeng -- the US government was under pressure to ease its restrictions on Anthropic to ensure that American AI could compete globally. Last week, Lutnick cleared Mythos to be released to select customers approved by the White House. OpenAI's latest models were also released to a group of organizations approved by the Trump team, instead of the public. The Trump administration's erratic approach to AI policymaking has left companies across the industry with little clarity about what will govern future model releases. An executive order issued in June that signaled a desire to review models ahead of release was criticized by influential analysts like Dean W. Ball, who recently started a policy position at OpenAI.

Read more of this story at Slashdot.

  •  

Ford Rehires 'Gray Beard' Engineers After AI Falls Short

Ford executives said they've hired 350 veteran engineers — some of them former employees — after AI and automated systems failed to deliver the desired quality, reports TechCrunch: Bloomberg reports the company's chief operating officer Kumar Galhotra told journalists that Ford had been "relying more and more on automated quality systems" with disappointing results. So the company "brought back technical specialists," and those specialists "hunt for failure points before a part ever reaches the plant floor." Charles Poon, Ford's vice president of vehicle hardware engineering, added, "Mistakenly we thought that by just introducing artificial intelligence and ingesting the design requirements that we had, that that would produce a high-quality product." The article points out that Ford is using the rehired gray beard engineers to train younger staff — and, to reprogram its AI tools.

Read more of this story at Slashdot.

  •  

Ex-Governors, Big Tech Launch Coalition To Help Workers 'Navigate the AI Economy'

"Amid growing public anger over A.I. and a debate over how to regulate it, a group of employers, state governors and foundations has raised $500 million to try to answer some of those questions themselves," reports the New York Times. "Just how many jobs will AI upend?" asks the Wall Street Journal, reporting that the new coalition says it's time to ready the U.S. workforce for a "major" disruption — no matter how large it turns out to be. The coalition "has so far raised more than $500 million — about half of its multiyear goal — from companies and nonprofit groups. It will initially work with state governments in Arkansas, Maryland, Utah and Connecticut. OpenAI and Anthropic are also involved, and academics including MIT economist David Autor sit on an advisory board." [The new "RAISE US" coalition] will be led by former Commerce Secretary Gina Raimondo, who served under former President Joe Biden, and former Indiana Gov. Eric Holcomb, a Republican. Its mandate, they said, isn't just to build retraining programs but also to reconsider decades-old policies such as unemployment insurance and act as a working lab for testing the most effective ways to transition workers to new fields. The group will explore corporate incentives for employers to hold on to workers whose jobs are disrupted by AI and prep them for new roles... The mission of the group is to "pull all the levers at once," Raimondo said. That means teaming up with employers to find ways to help workers gain skills or new roles and joining with educators to roll out different types of training. It also plans to propose policy changes such as tweaking unemployment benefits to let displaced workers continue to get them while they, for instance, start new businesses with AI... In Maryland, the group plans to expand a service-year option in the state to help people gain exposure to such growing fields as healthcare. An effort in Arkansas will focus on supporting "an AI-powered career navigation platform." More from New York Times: The organization will work primarily with governors... The theory: States generally control their community college systems, which can translate work force policy through course offerings and industry partnerships. The bulk of the budget will fund pilot programs overseen by about 15 staff members and consultants. For example, Maryland will expand a "service year" for recent high school graduates to provide experience in fields where there are shortages, such as health care. In other states, Raise Us hopes to offer "wage insurance" for workers who take lower-paying jobs rather than dropping out of the work force entirely. The group plans to furnish technical assistance for companies that want to retain workers as A.I. changes their roles, rather than eliminating them. Microsoft, one of the companies backing the organization, said it had already found a promising model: cross-training its entry-level lawyers in different parts of the organization and equipping them with A.I. skills in order for them to be repositioned as technology evolves. "You can think of doing that with almost any job we have," said Brad Smith, vice chair and president at Microsoft. "It creates an opportunity to transfer people from jobs that are being eliminated to jobs that are being created...." Ms. Raimondo and her colleagues are not fans of a universal basic income, an idea that has gained popularity in Silicon Valley as an answer to job disruption. They emphasize that work provides more than just wages, and plan to focus on helping people find pathways to new jobs. But it's unclear whether A.I. will create jobs at the rate that it will destroy them. Jack Malde studied work force policy for the Bipartisan Policy Center and is now going to work for the Windfall Trust, another A.I.-focused think tank. He said long-term income support might be necessary, even if better models for transitioning workers were found. "The truth is, there's still a lot of uncertainty," Mr. Malde said. "What we think is resilient now might not be resilient later. We're not going to get everything right, so we're going to need those strong safety-net programs." Long-time Slashdot reader theodp writes: If you think you've seen this movie before, prior to "partnering with governors, employers, and training partners to help the American workforce make a successful transition to an AI economy" with RAISE US, Raimondo and Holcomb partnered with governors, employers and training partners to help U.S. K-12 students make a successful transition to a CS economy with the Governors for Computer Science coalition.

Read more of this story at Slashdot.

  •  

Microsoft Slammed for Building Copyright-Infringing Supercomputer for OpenAI in New Court Filing

The New York Times alleges Microsoft actively encouraged OpenAI to steal its copyrighted work, reports Ars Technica, citing a new (and heavily redacted) court filing Thursday: NYT's motion comes after the [U.S.] Supreme Court sided with Cox Communications in a case where Sony tried and failed to claim that Cox was contributing to music piracy as an Internet service provider, which set a new standard for contributory infringement. Moving forward, plaintiffs will have to prove that parties intentionally acted to induce illegal conduct. Recognizing that the legal precedent has changed, the NYT now wants to amend its complaint to align its contributory infringement claim against Microsoft with that new standard... A Microsoft spokesperson told Ars that the company views the amended complaint as "a last-ditch effort by the plaintiff to save its claim from unfavorable precedent set in other recent rulings..." The updated complaint seeks to specify that [Microsoft's] supercomputer was tailor-made to help OpenAI infringe and allege that it was built for the explicit purpose of training AI on copyrighted works without permission. And as the NYT alleged, its articles were more heavily weighted by this system, as both firms hoped to train models on the highest-quality journalism possible, so that level of writing could be confidently mimicked in outputs. By building this "unusually complex" machine, Microsoft not only helped select the works that were infringed but also provided a means to seize copyrighted works without permission, the NYT alleged. "Microsoft specifically designed it for the purpose of using essentially the whole Internet — curated to disproportionately feature Times Works — to train the most capable LLM in history," the NYT alleged... Similarly as problematic for the NYT are hallucinations where Microsoft and OpenAI models falsely cite the NYT for content that they never published... "Users who ask a search engine what The Times has written on a subject should be provided with neither an unauthorized copy nor an inaccurate forgery of a Times article, but a link to the article itself," the NYT alleged... In a statement provided to Ars, OpenAI spokesperson Drew Pusateri reiterated the AI firm's often-repeated claims that AI training on copyrighted works is indisputably fair use... OpenAI has argued that "ChatGPT is not a substitute for a Times subscription," the NYT reported, partly because "they transformed the material for a different use." An OpenAI spokesperson told Ars Technica that OpenAI's models "empower innovation," while a New York Times spokesperson insisted that Microsoft "actively encouraged OpenAI to steal our copyrighted works... [O]ur core claims remain the same from the day we filed this lawsuit — that Microsoft and OpenAI stole millions of The Times's copyrighted works to compete with our products and illegally enrich themselves." The article speculates that the case's most extreme outcome "could require OpenAI and Microsoft to wipe models and start over. The NYT has also asked for permanent injunctive relief to prevent future infringement, as well as extensive damages..."

Read more of this story at Slashdot.

  •  

Students Around the World are Using AI-Powered Smart Glasses to Cheat on Tests

Students are using AI-powered smart glasses to cheat on tests, reports CNN. "And in East Asia's test-obsessed societies, where a single exam could impact the trajectory of a student's future career and social status, educators are scrambling to get ahead of the problem." Already, countries are stepping up inspections for test-takers. For China's grueling annual college entrance exam earlier this month — which more than 10 million hopefuls take each year — authorities required screening of all glasses. In the United Kingdom, the head of England's exam watchdog warned earlier this month that AI glasses and smart devices like earpieces could worsen cheating in exams... [T]wo incidents in South Korea were the country's first reported cases of cheating with AI glasses... In Taiwan, the university where a prospective student was caught cheating is now reviewing rules and standard operating procedures for AI eyewears during examinations. But experts worry these individual cases point to a more widespread issue. "If we're seeing a few cases being reported, we're seeing a lot more cases not being reported," said Thomas Corbin, lecturer at Deakin University in Australia, who has conducted research around the usage of AI-powered glasses and other smart devices in academic assessment. With the rapid development of AI technology, however, smart glasses are becoming slimmer, less noticeable, while integrating AI models that can operate independently with connectivity, raising concerns not only about exam integrity, but also about broader privacy risks... "Wearable AI is as much of a challenge to exams as ChatGPT was to essays in 2022 and I just don't think there is any real way that we can reliably have exam practices moving forward," Corbin said.

Read more of this story at Slashdot.

  •  

Developer AI Token Costs Could Exceed Their Salaries in Two Years

"Enterprises may soon be paying as much for their developers' AI token usage as they do for their salaries," writes InfoWorld: According to Gartner, these costs will meet, or even exceed, the typical software engineer's monthly salary within the next two years. This is not only because developers are increasingly adopting generative AI and agentic tools, it reflects a trend toward consumption-based licensing models as vendors balance infrastructure investments with profitability... Gartner senior principal analyst Nitish Tyagi explained that it's important to note that Gartner's prediction is based on a global average salary of $2,000 per month; it doesn't mean AI token usage will exceed all salaries. For instance, in the US, yearly pay rates can be six digits or more. However, that kind of spend is not out of the realm of possibility, Tyagi emphasized. "I have heard scary numbers like 'My developer consumed $20K last month,' or 'A business user consumed $32K'." If these amounts sound shocking, that's the point. "The goal is to alarm the industry about the impact of token cost if it is not governed and controlled," he said... AI coding vendors have yet to deliver "mature, built-in cost optimization capabilities," Tyagi said, and prices will likely only continue to rise as vendors further build out their models while at the same time trying to remain profitable. Thus, enterprises struggle to forecast and control costs, and, because AI is moving so fast, many organizations lack the "maturity and frameworks" to determine ROI, he noted. Agent-driven workflows are difficult to govern, context windows become bloated, budgets are wiped out earlier than anticipated, and token spend becomes hard to justify.... "Without a governed engineering operating model, costs can escalate faster than the productivity gains these tools are designed to deliver," Tyagi said.

Read more of this story at Slashdot.

  •  

How a Seemingly Harmless Image Can Jailbreak Vision-Language AI Models

Slashdot reader BrianFagioli writes: Florida International University researchers have developed a technique called JaiLIP (Jailbreaking with Loss-guided Image Perturbation) that uses subtle image modifications to bypass AI safety guardrails. Unlike traditional jailbreaks that rely on carefully crafted prompts, the attack works through images that appear normal to human viewers. The researchers tested the technique against BLIP-2, a multimodal AI model, and found that manipulated images significantly increased the likelihood of harmful responses. According to the study, the approach outperformed previous image-based jailbreak methods and nearly doubled the number of unsafe outputs generated during testing. The findings highlight a potential security risk for businesses deploying AI systems that process both images and text. While most discussions about AI safety focus on prompts, the research suggests that seemingly harmless images may also serve as an attack vector.

Read more of this story at Slashdot.

  •  

Scroll Burned in 79 AD Volcanic Eruption Finally Deciphered Using AI

When Mt. Vesuvius erupted in 79 A.D., it buried hundreds of papyrus scrolls. They were rediscovered in the mid-1700s, remembers Smithsonian magazine, "the only surviving collection of its kind from the Greco-Roman world..." "But when scholars tried to unroll them, the carbonized manuscripts crumbled to dust." Every generation that followed faced the same dilemma: They could wait for technology to advance, abandoning hope of reading the ancient texts in their own lifetime. Or they could try to open the scrolls themselves — and risk destroying them. In recent years, researchers have settled on a third option. Using advanced imaging and artificial intelligence, they're deciphering the scrolls without needing to unroll them at all. The Vesuvius Challenge has accelerated the process by turning it into a public competition, complete with cash prizes. In 2023, a student won $40,000 for deciphering a single word — "purple" — from an unopened scroll. Later, contestants would identify 2,000 Greek characters from one scroll ($700,000) and the title of another ($60,000). Now, for the very first time, researchers have recovered all surviving text from a single scroll. The nearly five-foot-long segment includes roughly 20 columns of ancient Greek philosophy, accessible for the first time in nearly 2,000 years. "The tech actually does look like magic, but it's not," Brent Seales, a computer scientist at the University of Kentucky, said at a press conference. (The article points out that Seales partnered with two Silicon Valley investors in 2023 to launch the Vesuvius Challenge, and is now hailing "the restoration of lost voices from the ancient world." Seales has been working on virtually unwrapping the scrolls since the early 2000s. The process involved imaging the bundles of papyrus using technology similar to CT scanners, isolating thin layers and then stitching them together.... "We've developed a systematic and a repeatable approach," Seales told the audience. "Now it's only a matter of time until we read all of the scrolls."

Read more of this story at Slashdot.

  •  

Forget Prompt Engineering: 'Loop Engineering' Is All the Rage Now

An anonymous reader quotes a report from Business Insider: For the most powerful voices in AI, it's all about being in the loop. Claude Code creator Boris Cherny recently said he doesn't write his own AI prompts much anymore. Thanks to loops, he doesn't have to. "It's an agent that prompts Claude," Cherny recently told CNBC, adding, "I don't write the prompt anymore. Claude writes the prompt, and now I'm talking to that new Claude that is kind of coordinating." In the same interview, Cherny said that loops and a similar feature were examples of the kind of work he would be proudest of in a decade. Cherny isn't the only one embracing "loop engineering." OpenAI engineer Peter Steinberger, the creator of the viral OpenClaw project, wrote a public reminder to users who are still writing out prompts for AI agents. "Here's your monthly reminder that you shouldn't be prompting coding agents anymore," Steinberger wrote recently on X. "You should be designing loops that prompt your agents." [...] Steinberger shared an example of a loop he uses: "Tell codex to maintain your repos, wake up every 5 minutes and direct work to threads. That makes it easy to parallelize+steer work as needed." Claire Vo, founder of ChatPRD and host of the "How I AI," said, "it's really just reminding people that you don't have to use your human fingers to type in a prompt in order for your agent to do work on your behalf." The days of directly prompting generative AI coding tools are "kind of over, or at least some think it's going to be," Addy Osmani, director of Google Cloud, wrote in his post explaining the concept.

Read more of this story at Slashdot.

  •  
❌