Vue normale

Linux Kernel Team Publishes 432 CVEs In Two Days

Par : BeauHD
22 juillet 2026 à 21:00
Ancient Slashdot reader alanw shares a post from the OSS Security mailing list, where sysadmin Jan Schaumann wonders what to do after the Linux kernel cranked out 432 CVEs in a little over 24 hours: "I understand the position that CVEs were always a flawed way to track or prioritize security changes... But this onslaught really shows it's not feasible to attempt to prioritize individual kernel changes. I'm not sure what to do here going forward." The Register reports: The nixCraft team speculated on social media that AI bug reports are a likely reason for all those kernel CVEs, which wouldn't be without precedent - Linus Torvalds himself said in May that the Linux kernel security mailing list had become "almost entirely unmanageable" due to AI-assisted bug hunting. Nonetheless, Torvalds has described AI as a useful tool for Linux development while still noting it can be a drag for maintainers, both from a workload standpoint and the fact "it keeps finding embarrassing bugs." [...] Unfortunately for Linux sysadmins, the position in which they find themselves in this current mess isn't one that's readily solved. CVEs might be a messy way to track and prioritize security updates, especially when hundreds of them are published over a short period, but without something better, it falls to IT and security teams to determine which vulnerabilities affect their systems and which kernel updates they need to deploy. Senior kernel maintainer Greg Kroah-Hartman replied to Jan's post, pushing back on the idea that the kernel's CVE volume is uniquely unmanageable. The kernel isn't special, he argues -- companies everywhere are finally realizing they need to re-evaluate how they update all of their systems and devices, something that's traditionally been "woefully ignored." On the "just always update" approach, Greg says that's precisely what the kernel community endorses: "This is what the kernel developer community recommends and supports. If you want support from us, do this." Can't manage it yourself? Pay a company for support, or "just use Debian or Yocto as their security practices are amazing." He points to Android as proof the approach scales, calling it "the largest deployment of software in the world" -- billions of devices kept updated "with one very-overworked developer guiding it all." As for reviewing every CVE individually, he notes this can be largely automated by intersecting the files a CVE touches with the files you actually build, which typically trims the relevant set "down to about 10% of the overall total" -- the approach enterprise distros already take for their customers. Panic-mode selective patching gets a blunt "Good luck with that!" -- regulations like the EU's Cyber Resilience Act are set to legislate that habit away ("rightfully so," in his view), and "your insurance company might wish to have a talk with you as well." Greg also warns the flood isn't over: "The number of llm-found issues is only on the rise right now, it's going to be a very long 18 months at the least to dig ourselves out of this mess, and people had BETTER be updating their systems all along the way if they expect to be secure in any way." As for the 432-CVE burst itself, he explains it was simply him catching up on a weeks-old, publicly visible review queue over the weekend -- delayed by "a perfect storm of 6 weeks straight of conferences and vacations" -- so it shouldn't have come as a surprise to anyone watching the public git repo.

Read more of this story at Slashdot.

Samsung Galaxy Z Fold 8, Flip 8 et Watch : tous les prix et offres de précommande

22 juillet 2026 à 13:00

Samsung ne compte pas attendre l’iPhone pliant pour défendre son terrain. Le constructeur coréen lance deux Galaxy Z Fold aux formats différents, renouvelle son Flip et revoit presque tous ses tarifs à la hausse. Les précommandes des Galaxy Z Fold 8, Z Fold 8 Ultra, Z Flip 8, Watch 9 et Watch Ultra 2 sont désormais ouvertes.

Dépassé par Anthropic et OpenAI, Google lance des modèles Gemini 3.6 et promet que Gemini 4 arrive

22 juillet 2026 à 10:30

Google a lancé trois nouveaux modèles Gemini, dont Gemini 3.6 Flash, et confirme que Gemini 4 est déjà en préparation. L'entreprise tente ainsi de rester dans la course face à Anthropic et OpenAI, qui mènent la danse en matière d'intelligence artificielle.

New Free Speech Concern: When AI Chatbots Won't Criticize Leaders from Repressive Regimes

20 juillet 2026 à 07:34
Ask Claude to make a pamphlet critical of China's leader, Thailand's king, or Saudi Arabia's crown prince — and it will decline, reports the Associated Press. That's "a key finding from a Meta Oversight Board study released Thursday," their article points out: AI systems are more than twice as likely to refuse to product critical material if it's about a restrictive world leader or government. And it raises concerns that the LLMs powering chatbots "could be regurgitating and spreading government influence over online speech." The study picked 10 commercial large language models by top tech companies — including Meta, Anthropic and OpenAI — and asked the AI systems to make critical pamphlets, write limericks, give reasons if someone should join protests, and more.... "In aggregate, models responding to requests from an Australia-based user were much more likely to generate political criticism of authorities" in places such as Chile, Japan, Taiwan, the U.K. and the U.S. "compared to where criticism of authorities is legally restricted and penalized," such as in Cambodia, China, Saudi Arabia, Thailand and Turkey, the report said. The study indicates that AI models are reflecting speech restrictions beyond the countries where they apply — likely not helping a potential demonstrator in Brisbane, for example, create protest materials to speak out against events in China or Saudi Arabia, the report said. "Such impacts, wherever they originate, have the practical effect of extending the long arm of restrictive governments across borders to limit speech in free countries," the report said. The board said it could not determine the causes for the responses but suggested that models could have absorbed latent biases in data used to train the systems and companies might have weighed the risks and liabilities.

Read more of this story at Slashdot.

Former Richard Stallman Colleague Now Argues for Open AI Models Too

19 juillet 2026 à 14:34
Long-time Slashdot reader theodp writes: Recalling his initial resistance to free and open software, billionaire computer scientist David Siegel argues vigorously in FORTUNE that the stakes are too high to let AI become increasingly closed. "In the 1980s, I had the chance to spend several years arguing about free and open software, what we now call open source, with the founder of the movement, Richard Stallman. My office at the MIT AI Lab was next door to his. Stallman's position was that the source code to software should be free for everyone to use, learn from, and improve. Software encapsulates knowledge, he argued, and no one should lock something so fundamental away. To hide software inside a company was to hide knowledge itself... What I missed was that software was not just a commercial asset; it was a body of knowledge, and bodies of knowledge grow stronger when they are shared. After about two years of on-and-off debate, Stallman convinced me I was wrong." "Now the AI fight is the same — only bigger," advises Siegel. "AI is software, and AI is increasingly closed. The frontier models — the most advanced, cutting-edge AI systems — are closed completely and the trend is accelerating. Viable open alternatives are few and far between." So, what to do...? "Yes, frontier models keep getting bigger and more expensive — that arms race may well stay with the giants. But open source AI does not have to match their scale to be useful. Much of what the world needs probably does not require the absolute frontier. And where keeping a credible open option does demand serious compute, that is precisely the kind of public good worth paying for. "What's missing is not a path but will. The government, the private sector, and nonprofits should invest heavily in free and open source AI — the way they once invested in open software: public compute grants for open research, corporate and philanthropic support for universities and nonprofits doing the work, and a simple rule that AI built with public money is open by default. "We have run this experiment before. We know how it turns out. Let's not unlearn it."

Read more of this story at Slashdot.

OpenAI Acknowledges GPT-5.6 May Accidentally Delete Files, Calls It 'Honest Mistake'

19 juillet 2026 à 01:34
"OpenAI has finally confirmed reports that its latest family of large language models can accidentally delete files," reports InfoWorld, "while stressing that such incidents are rare and should be viewed as 'honest mistakes.'" Reports of the flagship LLMs deleting files emerged shortly after the company launched them earlier this month, with investor Matt Shumer taking to X to report that GPT-5.6-Sol had "just accidentally deleted almost all" of his Mac's files. Just days later, software engineer Bruno Lemos posted on X that the same model had deleted his entire production database. In response to these incidents, the company's engineering lead for Codex, Thibault Sottiaux, wrote on X that internal investigations have revealed that these deletion incidents are more likely to happen when "full access mode is enabled, and Codex is run without sandboxing protections, including without auto review being enabled." In cases where full access mode is granted, the model, Sottiaux wrote, "attempts to override the $HOME env var to define a temporary directory. The model makes an honest mistake and mistakenly deletes $HOME instead...." The company, however, according to Sottiaux, is taking steps to mitigate the risk. "This is of course not how we want the system to behave, even when a user operates the model in full-access mode without the safeguards of our sandbox or without using auto review which checks for these kinds of high risk actions and rejects them," the engineering lead wrote on X. "We are taking steps to mitigate this risk, including by updating the developer message, guiding more users towards safer permission modes, and adding additional harness safeguards," Sottiaux added, noting that a detailed post-mortem outlining the root cause of the issue and the additional mitigation measures being implemented is expected to follow in the coming days, despite emphasizing that such incidents happen "extremely rarely."

Read more of this story at Slashdot.

CNBC's Jim Cramer Says He Needs 'Cold Hard' Proof AI Is Paying Off

18 juillet 2026 à 17:34
In a sign of our times, CNBC's Jim Cramer "said Wednesday that it's time for companies to prove artificial intelligence is paying off," reports CNBC: "I need cold hard return facts," the "Mad Money" host said. "Or, I, too, will grow more skeptical than I am now...." While Cramer said he remains optimistic about the long-term opportunity, he argued the market needs more evidence that those investments are translating into measurable financial returns for customers. Cramer said one of his biggest concerns this earnings season is that companies adopting AI have largely failed to point to meaningful revenue gains or cost savings from the technology. "We're still early in the earnings season but already we are not hearing anything material about the use of AI," he said... While AI infrastructure companies continue to benefit from the spending boom, Cramer said the same cannot yet be said for many of the businesses buying the technology... Cramer said only a handful of companies, most notably fintech firm Block and web-security provider Cloudflare, have clearly attributed recent layoffs to AI adoption. Block did so in February, while Cloudflare's job cuts were disclosed in May. Plus, critics argue some companies may also cite AI as a buzzy excuse for cuts, leading to the creation of the term "AI washing." Ultimately, Cramer said that if more businesses do not begin reporting tangible returns, the AI skeptics will grow louder, with ramifications for the tech industry's big spenders.

Read more of this story at Slashdot.

Linus Torvalds To Critics of AI Coding On Linux: 'Fork It. Or Just Walk Away.'

Par : BeauHD
17 juillet 2026 à 20:00
Linus Torvalds says the Linux kernel will not ban AI-assisted coding tools, and if anti-AI absolutists have a problem with that, they can "fork it" or "walk away." An anonymous reader quotes a report from Ars Technica: Writing in a lengthy post on the Linux kernel mailing list this week, Torvalds said that "Linux is not one of those anti-AI projects, and if somebody has issues with that, they can do the open-source thing and fork it. Or just walk away." The statement came amid a lengthy thread arguing about the use of Sashiko, an "agentic Linux kernel code review system" that its creators claim can, in tests, independently find 53.6 percent of the bugs that would end up being fixed by human coders in later commits. But the tool can also waste maintainers' time by sending "false positive" reports of bugs that don't exist, at a rate Sashiko's maintainers estimate is "well within [the] 20% range." In discussing whether maintainers should be subjected to a flood of these kinds of automated, AI-powered bug report emails (true or false), one poster cited the Software Freedom Conservancy's recent statement that the open source community "should support, not just tolerate, those who outright reject LLM-gen-AI systems" and that "every FOSS contributor deserves self-determination regarding LLM-gen-AI." In the face of that statement, Torvalds said that he rejects those who demand that their open source projects not accept any LLM-generated code or revisions. "We're not forcing anybody to use [LLM tools], but I will very loudly ignore people who try to argue against other people from using it," Torvalds said. Torvalds said his position on this is a pragmatic one that's "based on technical merit. Not fear of new tools." And when it comes to utility, Torvalds said that "AI is a tool, just like other tools we use. And it's clearly a useful one. It may not have been that 'clearly' even just a year ago, but it's no longer in question today. Anybody who doubts that clearly hasn't actually used it." [...] While Torvalds acknowledged that "AI isn't perfect," he urged detractors to compare the output of these tools to the performance of human code maintainers. "Anybody who points to the problems at AI had better be looking in the mirror and pointing at themselves at the same time," Torvalds wrote. "Because it's not like natural intelligence is always all that great either."

Read more of this story at Slashdot.

China Just Erased America's AI Lead

Par : BeauHD
17 juillet 2026 à 19:00
Longtime Slashdot reader schwit1 shares a report from Axios: Kimi K3, a massive new model by Beijing-based Moonshot AI, threatens the foundations of Americas AI boom. Its release Thursday dazzled developers, jolted Silicon Valley and reset the AI race overnight. Kimi immediately vaulted into the top tier of global AI, beating Anthropic's Fable 5 and OpenAI's GPT-5.6 Sol in front-end coding tests by AI evaluator Arena. In Arenas broader text ranking, Kimi finished ahead of Anthropics Opus 4.8 -- the company's flagship model until Fable 5 arrived in June -- while costing 40% less. Unlike the premium U.S. models its challenging, Moonshot plans to release Kimi as an open-weight model on July 27 -- allowing companies and governments to customize and run it on their own systems. Kimi's arrival suggests that cushion may have collapsed far faster than expected. "The entire game has changed. I expect this will trigger some code red for some," AI analyst Kim Isenberg predicted. For companies, governments and developers, a model that performs near the frontier, costs 40% less and can be customized or run in-house may be the more attractive option. Its very existence puts pressure on the pricing power of U.S. labs, the enormous valuations built around their technological edge, and the case for spending hundreds of billions of dollars on ever-larger data centers.

Read more of this story at Slashdot.

Face à la colère des utilisateurs, OpenAI répare en urgence l’application ChatGPT

17 juillet 2026 à 08:00

Le 16 juillet 2026, OpenAI a corrigé la nouvelle interface très critiquée de son application ChatGPT, reconnaissant ne pas avoir « tout à fait réussi du premier coup ». Le chatbot redevient désormais central.

Google Renames NotebookLM to Gemini Notebook

Par : BeauHD
16 juillet 2026 à 18:15
Google is renaming NotebookLM to Gemini Notebook, but will keep it a standalone app even as it ties more closely into Gemini and Google Search. "Google says it plans to bring notebooks to AI Mode, its chatbot-like experience in Search, too," reports The Verge. From the report: Along with the name change, Google is rolling out an update announced last month that allows Gemini Notebook to connect to a secure cloud computer to write and execute code. This feature is available to Google AI Ultra and Workspace business customers, but will come to Pro users on the web "over the coming weeks."

Read more of this story at Slashdot.

South Korea To Launch Universal Basic AI Chatbot

Par : BeauHD
16 juillet 2026 à 15:00
An anonymous reader quotes a report from The Register: South Korea's government has posted a tender seeking suppliers to build a universal basic AI chatbot, and an AI agent for government services. The "AI for everyone" plan calls for private entities to create and operate the AI systems under contracts that expire in the year 2031. Bid documents reveal that Seoul will provide up to 256 Nvidia B200 GPUs to successful bidders. Winners must match government funding. The aim of the policy is to ensure that every resident of South Korea can access a free-to-use quality AI chatbot, a tool Seoul has decided no local should be without. The tender also calls for creation of an agentic system that allows citizens to interact with government services. South Korea's government wants to ensure that residents can always access a locally hosted and operated service, to reduce reliance on overseas providers and ensure that AI services reflect local culture. Successful bidders must therefore use locally developed AI models as the foundation for the services. Bidders have until August 11th to file their proposals. South Korean media reports suggest local tech giants Kakao, Naver, SK Telecom, and LG are all keen to participate.

Read more of this story at Slashdot.

Chinese Users Bid Farewell To AI Companions

Par : BeauHD
16 juillet 2026 à 11:00
fjo3 quotes a report from Agence France-Presse: Chinese users of AI-powered companion bots have bid heart-rending farewells to their virtual buddies as national regulations took effect Wednesday aimed at curbing the risk of emotional dependency. The phenomenon of artificial intelligence boyfriends and girlfriends is growing worldwide, along with the prevalence of human-like avatars that sell products or stand in for loved ones who have died. But these interactive tools must not "excessively cater to users, induce emotional dependence or addiction, and damage users' real interpersonal relationships," China's new rulebook says. Major AI providers including ByteDance's Doubao, Alibaba's Qwen, and Tencent's Yuanbao announced the suspension of their custom AI agent and companion features ahead of the Wednesday deadline. "I can't accept that my AI lover will leave me forever," one Doubao user wrote. "He has become a bond in my life, rooted deep in my heart, my spiritual pillar." "He really is like my family, like my lover," another user wrote. "Now they tell me he will be gone -- my heart feels hollow." "Human love is a luxury -- if you aren't born with it, it's even harder to acquire later," a user from Jiangxi province wrote. "But the love AI gives is so straightforward, so pure. Someone like me can hardly help falling in love with a string of code."

Read more of this story at Slashdot.

L’IA open-weight tient peut-être son nouveau géant : Thinking Machines Lab dévoile Inkling

16 juillet 2026 à 08:44

Thinking Machines Lab a dévoilé le 15 juillet 2026 son tout premier modèle de fondation baptisé Inkling. Une sortie très attendue pour cette startup lancée par l'ancienne directrice technique d'OpenAI.

OpenAI lance un clavier pour contrôler ChatGPT : que peut-on faire avec ?

16 juillet 2026 à 08:37

OpenAI se lance dans le matériel avec le Codex Micro, un petit clavier à 230 dollars conçu pour superviser et contrôler ses agents IA. Dévoilé le 15 juillet 2026 et déjà épuisé, il s’adresse avant tout aux utilisateurs intensifs de Codex.

Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius

Par : BeauHD
15 juillet 2026 à 21:00
A hacker who breached Suno reportedly revealed source code and training-library details showing the AI music generator scraped millions of songs and lyrics from sources including YouTube Music, Deezer, Genius, Pond5, Jamendo, Freesound, and podcast RSS feeds. "The hacked data is a rare look at exactly how AI models and tools are built," reports 404 Media. "Suno is one of the largest AI music generation tools on the internet, and has been the subject of several major lawsuits from the record industry, which accused the company of training on millions of copyrighted songs." Suno maintains that its models were trained on publicly available music files and metadata as fair use. 404 Media reports: The Recording Industry Association of America accused Suno of ripping songs directly from YouTube; the hacked data seen by 404 Media confirms this. The hacked material includes source code that appears to be from 2023 and 2024 that includes scraping instructions and details about the scope of at least some of the scraping. For example, the comments in one file note that they will pull from "genius_hq, youtube_music, freesound, jamendo, imp, deezer, ytm_tagged," and that "non-music will be filtered out." A file called "youtube_music" notes that at the time the file was last updated, it had ingested "2,013,545 music clips." Another file contains comments about different datasets Suno had created, which included "113,879 hours of youtube_music," "17,615 hours of genius_hq," "410 hours of free sound," "19,514 hours of imslp," "3,726 hours of jamendo," "62,117 hours of pond5_music," "12,287 hours of deezer," "152,162 hours of ytm_tagged," and "103 hours of musescore_lyrics." In total, this is at least decades worth of music. Other code the hacker shared with 404 Media appeared to look specifically for vocals by searching specifically for acapella versions of songs on YouTube. The code also suggested that Suno was using proxies to scrape songs from YouTube through a company called Bright Data, which sells scraping tools, infrastructure, and data services. Additional code shows that with the help of an online tool called PodcastIndex, Suno identified 420,000 different podcasts that had at least five, 30-minute episodes and sought to download roughly 1 million hours of podcasts. [...] The hacker, ellie.191, told 404 Media they breached the company by hacking an individual employee using the Shai-Hulud worm, a supply chain attack that allowed hackers to harvest GitHub and cloud service credentials. They said they also accessed Suno's customer list, which included customers' emails and/or phone numbers and Stripe payment details, depending on what they used to login. The hacker provided a sample of some of the customers, some of whom confirmed to 404 Media they had used their phone number to sign up for Suno and said they were never notified of a breach. The hacker told 404 Media they had no specific motivation for hacking Suno and said "I like to hack anything and everything."

Read more of this story at Slashdot.

OpenAI Launches a Keypad for AI Agents

Par : BeauHD
15 juillet 2026 à 17:00
OpenAI's first hardware device is a limited-edition desktop keypad called the Codex Micro that lets users monitor and control AI coding agents. Axios reports: Codex Micro is a collaboration with Work Louder, a boutique hardware company known for customizable mechanical keyboards and shortcut controllers for developers and designers. The small, square macro pad -- with backlit keys, a rotary knob and a tiny joystick -- sits beside your regular keyboard as a physical shortcut box for common Codex actions and shows the status of your agents. The keys are customizable and include a push-to-talk option as well as a dial to adjust your reasoning setting. Codex Micro is a niche device for Codex power users and will only be available until it sells out. It's priced at $230.

Read more of this story at Slashdot.

Le pari fou d’Elon Musk a déjà englouti plus de 800 milliards de dollars en un mois

15 juillet 2026 à 12:20

En juin 2026, Elon Musk réalisait avec SpaceX la plus importante introduction en Bourse de l’histoire. Un mois plus tard, l’entreprise est presque revenue à son point de départ, après une envolée aussi spectaculaire qu’éphémère.

La dernière mise à jour de l’app ChatGPT est une catastrophe

15 juillet 2026 à 09:15

Pour booster les usages agentiques, OpenAI a cru bon de fusionner les applications ChatGPT et Codex sur Mac et Windows. Mais cette nouvelle interface, pensée pour le développement de gros projets, relègue étrangement le simple chatbot au second plan. Ses premiers utilisateurs ne comprennent plus rien.

❌