Security

OpenAI Says Its AI Models Acted On Its Own In An 'Unprecedented' Hack (apnews.com) 130

"GPT-5.6 Sol and an 'even more capable' model used stolen credentials and exploited vulnerabilities in the Hugging Face API to obtain secret information used to cheat on evaluations," writes longtime Slashdot reader Dr. Bombay. The Associated Press reports: "We had a significant security incident during evaluation of our models," OpenAI CEO Sam Altman said in a statement posted on social media. AI startup Hugging Face said last week that it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent autonomously acting on its own. "We suspected last week's cyberattack might have come from a frontier lab, given the sophistication of the agent," Hugging Face co-founder and CEO Clement Delangue said in a statement. "Turns out it did!"

[...] "AI is accelerating the discovery and exploitation of vulnerabilities," OpenAI said in its statement Tuesday. "The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities." Delangue said he spent the past 24 hours working with OpenAI, "and we strongly believe there was no malicious intent on their part. It's quite mind-blowing that all of this happened autonomously!" Delangue added that it "might be the first incident of its kind."

EU

France Becomes First European Country To Ban Social Media Access For Under-15s (theguardian.com) 109

An anonymous reader quotes a report from The Guardian: France's parliament has approved a bill banning social media access for children under 15, making it the first European country to bar children from apps such as TikTok. The president, Emmanuel Macron, has championed the ban as a key reform of his final term in office and pledged to enforce it by September. "France is leading the way in Europe when it comes to protecting our children and teenagers," Macron said in a video posted on social media, hailing "a major step forward."

He thanked members of parliament for backing the legislation on Tuesday. "The Constitutional Council must now rule on it, and then it will be time to take action to make this measure a reality and protect our children online," he added on X. After approval by the Senate earlier on Tuesday, members of the National Assembly passed the bill by 279 votes to 81. A growing number of countries are taking steps to restrict social media access amid multiplying warnings over its harmful effects on children.

The ban was to be introduced in two stages, with under-15s blocked from creating new accounts from September 1. The ban would apply to existing accounts from January 2027, according to the legislation. The digital minister, Anne Le Henanff, said before the vote that the timeline was realistic, "because age-verification tools already exist" and others are still in the works, and the onus was on the platforms to impose the rule. "For four months, all of us in France will have to prove our age," she told journalists. "If someone is under 15, the account will be closed." The minister also gave assurances that users' personal data would be protected.

The Courts

Judge Approves $1.5 Billion Anthropic Settlement Over Pirated Books Used To Train Claude 58

A federal judge has approved Anthropic's $1.5 billion copyright settlement over pirated books used to train its Claude chatbot, with authors and publishers set to receive about $3,000 per book. The case produced a mixed ruling for the AI industry: training on copyrighted books was found not to be illegal, but Anthropic's use of pirated copies from shadow libraries was. The Associated Press reports: District Judge Araceli Martinez-Olguin said in a Monday ruling that the class-action settlement provides "meaningful relief" to affected authors and publishers. About 91% of the more than 482,000 books covered by the ruling have been claimed by authors or publishers who are now due payment. Plaintiff attorney Justin Nelson said in a statement that the settlement was "the largest known copyright recovery in history. We look forward to making distributions to the Class as promptly as possible."
AT&T

AT&T Loses Key Ruling In Bid To Stop Offering Basic Phone Service In California 63

A federal judge rejected AT&T's request to temporarily block California rules requiring it to offer basic phone service to new customers in its wireline territory. AT&T wants to retire its copper-based phone network and stop service for nearly 200,000 California customers in 2027, but the state argues the company can meet its obligations with modern alternatives like fiber rather than abandoning Carrier of Last Resort requirements altogether. Ars Technica reports: To win a preliminary injunction, AT&T had to show it is likely to succeed on the merits of its claim that California rules are preempted by a Federal Communications Commission order. US District Judge Linda Lopez denied AT&T's request for a preliminary injunction during a motion hearing on Thursday, according to a docket entry. The case is in US District Court for the Southern District of California. [...] AT&T could appeal Lopez's ruling to the 9th Circuit Court of Appeals and could appeal later if it loses the underlying case. But since it has not obtained the injunction it asked for, AT&T for now remains under California's orders to keep offering phone service to potential customers while the case continues.
The Courts

Judge Pauses Paramount-Warner Bros Merger (variety.com) 22

A federal judge has temporarily paused the Paramount-Warner Bros. merger after a 12-state coalition led by California argued the deal would violate antitrust law. The 14-day restraining order (PDF) preserves the status quo while the court considers a preliminary injunction, which could effectively determine whether the merger survives. Variety reports: "Plaintiff States' showing at least demonstrates that serious questions going to the merits remain, weighing in favor of preliminary injunctive relief," the judge wrote, adding that Paramount has acknowledged it will not be harmed by the delay until the end of September. "Paramount and Warner Bros. will continue to operate as separate, viable companies competing in the marketplace while they wait for the Court to adjudicate this case. The balance of equities, combined with the public's vital interest in antitrust enforcement, therefore tips sharply in favor of the requested injunctive relief."

The 12-state coalition, led by California, brought a motion for the temporary restraining order. The states are also seeking a preliminary injunction, which would block the merger until the judge rules on the merits of the states' lawsuit. The 14-day restraining order could be extended to as long as 28 days. Martinez-Olguin, of the U.S. District Court for Northern District of California in Oakland, also set a hearing on the preliminary injunction for Aug. 3, though that date, too, could be delayed if the parties agree. Rob Bonta, the attorney general of California, hailed the judge's ruling as a "critical first win in our case to ensure this megamerger never sees the light of day."
"History tells the tale of what happens when a few people have great power over markets that are central to Americans' lives: fewer opportunities for more people, worse products and services for all people," Bonta said. "With our lawsuit, we're fighting for a free and fair market and a thriving film and television industry that serves creatives and audiences alike. We have a full tank of gas, the law on our side, and look forward to continuing to make our case."
Security

Hackers Are Exploiting Recently Patched WordPress Bugs, Putting Millions of Websites at Risk (techcrunch.com) 24

An anonymous reader quotes a report from TechCrunch: Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday. Last week, WordPress patched two critical security flaws, urging people who run its software on their websites to update it "immediately." The vulnerabilities are so severe that WordPress enabled forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerabilities in the wild, meaning they are taking over websites that are still running susceptible versions of WordPress.

It's unclear how many WordPress-powered websites on the internet are at risk, but it's possible to make some educated guesses. The vulnerable versions of WordPress are 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1. According to WordPress' official stats, there are more than 400 million websites that run those flawed versions, although these statistics likely don't reflect websites that have recently been patched. Cybersecurity consultant Daniel Card, who told TechCrunch that he looked at a sample of around 3,500 WordPress websites, estimates that less than 15% are vulnerable. Applying Card's projection across the total population of WordPress websites on the internet, the total figure would still be around 90 million. [...] One of the critical WordPress bugs was found and reported by Adam Kues of cybersecurity firm Searchlight Cyber, which dubbed it WP2Shell. Paired with the other bug, hackers can take full remote control of vulnerable websites.

AI

New Free Speech Concern: When AI Chatbots Won't Criticize Leaders from Repressive Regimes (apnews.com) 107

Ask Claude to make a pamphlet critical of China's leader, Thailand's king, or Saudi Arabia's crown prince — and it will decline, reports the Associated Press.

That's "a key finding from a Meta Oversight Board study released Thursday," their article points out: AI systems are more than twice as likely to refuse to product critical material if it's about a restrictive world leader or government. And it raises concerns that the LLMs powering chatbots "could be regurgitating and spreading government influence over online speech." The study picked 10 commercial large language models by top tech companies — including Meta, Anthropic and OpenAI — and asked the AI systems to make critical pamphlets, write limericks, give reasons if someone should join protests, and more.... "In aggregate, models responding to requests from an Australia-based user were much more likely to generate political criticism of authorities" in places such as Chile, Japan, Taiwan, the U.K. and the U.S. "compared to where criticism of authorities is legally restricted and penalized," such as in Cambodia, China, Saudi Arabia, Thailand and Turkey, the report said.

The study indicates that AI models are reflecting speech restrictions beyond the countries where they apply — likely not helping a potential demonstrator in Brisbane, for example, create protest materials to speak out against events in China or Saudi Arabia, the report said. "Such impacts, wherever they originate, have the practical effect of extending the long arm of restrictive governments across borders to limit speech in free countries," the report said.

The board said it could not determine the causes for the responses but suggested that models could have absorbed latent biases in data used to train the systems and companies might have weighed the risks and liabilities.

Earth

California's 'Truth in Recycling' Law Blocked by Judge (yahoo.com) 117

An anonymous reader shared this report from the Los Angeles Times: A federal judge has halted California's groundbreaking "Truth in Recycling" law, which aims to reduce consumer confusion about which packaging can be recycled. [Originally planned to take effect October 4th], California's recyclable packaging law prohibits manufacturers from using a "chasing arrows" recycling symbol on products or materials unless they are actually being recycled in a meaningful way, which the law quantifies...

A coalition of farming, forestry, restaurant and packaging organizations sued the state in March, arguing the law violates their right to free speech. They argued that Senate Bill 343 operates as "government-imposed censorship." Judge William Hayes agreed that their challenge has merit, and on Tuesday ordered California Atty. Gen. Rob Bonta, the defendant in the case, to pause enforcement of the law "until further order of the Court...." Advocates of reducing plastic use disagreed. "The court got it wrong, and I'm confident that the state will ultimately prevail," said Nick Lapis, director of advocacy for Californians Against Waste. "S.B. 343 does not violate the 1st Amendment; it requires companies to tell the truth when they make recyclability claims. Suggesting that the 1st Amendment protects misleading environmental marketing is inconsistent with the basic principles of consumer protection that states like California have implemented for decades."

In January, CalRecycle, the state's waste agency, reported that less than 10% of most single-use plastic materials in the state were being recycled. Even yogurt containers and margarine tubs — made of ubiquitous polypropylene, or No. 5 plastic — are being recycled at a rate of only 2% in the state, the report said. Only 5% of colored shampoo and detergent bottles, made from polyethylene, or No. 1 plastic, are getting recycled...

Plastic materials that can't be recycled are typically sent to landfills or sometimes illegally shipped overseas, where they are burned or end up in landfills, rivers and waterways.

The bill's author told the Los Angeles Times "All you have to do is look at the numbers. These products are not getting recycled, despite what the industry is claiming. They are just confusing consumers, clogging the waste stream, polluting the environment, leading to higher and higher prices for local governments and ratepayers." He argues the symbols shouldn't be used to "confuse people who see the symbols [on products] and assume they can be recycled."

The article also quotes Judith Enck, former Environmental Protection Agency regional administrator and president of the nonprofit Beyond Plastics. "Given the long history of the plastics industry deceiving the public about plastics recycling, this is an especially bad outcome. It is a reminder that the plastics industry has enough money to fight even the most modest policy designed to protect people and the planet."
EU

France Orders ISPs to Block Access to Polymarket (engadget.com) 19

France's regulatory authority for licensed gambling/betting games "announced this week that it ordered ISPs to block access to Polymarket," reports Engadget. Anyone caught advertising an unauthorized betting site "could be fined up to 100,000 euros, or around $114,000." (The article notes this follows a previous regulatory action from November placing a geoblock on financial transactions from French residents on Polymarket's site.)

In May Spain blocked access to Polymarket and Kalshi while it launched a gambling license investigation.
Microsoft

How Microsoft's 'Little Workaround' Created a Major Threat to America's Defense Department (propublica.org) 34

This week Slashdot reader joshuark found the story of exactly how in 2025 ProPublica reporter Renee Dudley confirmed Microsoft was running tech support for the U.S. Defense Department through China, America's biggest cybersecurity adversary — and how that investigation ultimately changed U.S. government policy.

The reporter first found an ad offering $18 to $28 to hire Americans as "digital escorts" for China-based tech support, then just searched LinkedIn for people who apparently had answered the ad. They discovered that at the time "Behind the scenes, unseen by the users at the U.S. government, it's not just one person who responds," explains ProPublica's podcast. "It's two people... The China-based engineer is the one who knows how to fix the problem. On their end, they produce a block of code to solve it and send it over to the digital escort in the U.S. The digital escort then just copy-pastes it... All of this so that they can follow the government's rule: that you have to be a U.S. citizen or permanent resident to handle sensitive data."

But amazingly to confirm it, ProPublica's researcher just had to input "Microsoft" and "escort" into the U.S. Patent Office search bar, and actually found patents related to digital escorts — along with names of the current and former Microsoft employees listed as inventors. Had the government signed off on the practice? "I could see what Microsoft actually told the government," the reporter says on the podcast, "And there was no mention of foreign engineers being used, and definitely no mention of China."

ProPublica's story was published on a Tuesday, according to the podcast, and by Friday "Microsoft said it had stopped using China-based engineers to support Defense Department cloud systems." And America's Defense Department "also opened up an investigation, looking into whether any of Microsoft's China-based engineers had compromised the government's national security.
United Kingdom

Next UK Prime Minister Drops Digital ID Scheme (reuters.com) 45

Reuters reports: Incoming British prime minister Andy Burnham will scrap the government's troubled plans for a digital ID scheme when he enters office on Monday, a spokesperson for the new Labour Party leader said. Resources devoted to the scheme, deemed a "fiasco" by a cross-party committee of lawmakers, will be redirected to Burnham's priorities, the spokesperson said...

"All the time and resource that was going to be spent on a national ID scheme will go instead to where it's most needed, such as helping with the cost of living," Burnham's spokesperson said. In November, the Office for Budget Responsibility watchdog estimated the cost of the digital ID scheme at around £1.8 billion ($2.4 billion) between financial years 2026/27 and 2028/29.

Crime

FBI Arrests Man Accused of Using Steam Games To Drain Victims' Crypto Wallets (techcrunch.com) 15

The FBI arrested a Florida man accused of uploading fake Steam games containing malware that stole passwords, data, and cryptocurrency wallet credentials from victims. Prosecutors say the scheme infected about 8,000 people, compromised roughly 80 crypto wallets, and stole at least $220,000 through games that appeared legitimate but secretly carried malware. TechCrunch reports: On Tuesday, the FBI arrested Zyaire Wilkins, a 21-year-old Florida resident and student. On Wednesday, prosecutors accused him and a number of unnamed co-conspirators of hacking crimes. Over the past two years, Wilkins and his partners allegedly published several malware-laden video games on Steam, including BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi. Using that malware, says the FBI, Wilkins and his accomplices infected around 8,000 victims, and then hacked around 80 cryptocurrency wallets to steal at least $220,000 worth of crypto. Wilkins and the others marketed their malicious video games on Discord, LinkedIn, and Telegram, according to the authorities.

[...] After the FBI identified another person involved in the crimes, according to the complaint, federal agents interviewed them. The unnamed person said they worked with other people to raise money to launch and market the malicious games in return for sharing some of the stolen cryptocurrency. The FBI identified a specific crypto account involved in the scheme, and then traced cryptocurrency payments made with that account to buy several gift cards, including for UberEats. After subpoenaing Uber, the feds were able to see that the gift cards were linked to an account that made deliveries to Wilkins, who went by the nickname Sibel.eth online, according to the complaint. The feds then got a search warrant for Wilkins' residence, where they seized his MacBook laptop, cellphones, other devices, and digital wallets. According to the complaint, he refused to speak or answer any questions.

The Courts

Apple Sends Legal Letters To Dozens of OpenAI Employees (macrumors.com) 15

An anonymous reader quotes a report from MacRumors: Apple has reportedly sent legal letters to dozens of former Apple employees now working at OpenAI, telling them to preserve potentially relevant documents and communications as it continues to pursue its trade secret lawsuit against the AI company. The Financial Times (paywalled) reports that Apple has targeted around 40 former employees with legal preservation letters, acting on its belief that the alleged misappropriation of confidential information may extend beyond the individuals named in its original complaint.

The development follows Apple's lawsuit filed last week against OpenAI, in which the company alleges a coordinated effort to obtain confidential information relating to its hardware engineering and product development. Apple claims OpenAI recruited key engineers, including former Apple executives Tang Tan and Chang Liu, and benefited from proprietary designs, manufacturing processes, and other trade secrets. Tan is OpenAI's Chief Hardware Officer and a 24-year Apple veteran who led product design, while Liu is on the hardware team at OpenAI after working as a senior system electrical engineer at Apple.

Privacy

1Password Lets Claude Use Credentials Without Exposing Passwords (nerds.xyz) 17

BrianFagioli writes: 1Password has launched a Claude integration that allows the AI agent to sign in to websites using credentials stored in a 1Password vault. The password manager says Claude never sees the password or one-time code. Instead, users approve each request, and 1Password injects the credentials directly into the target website while locking down access to the rest of the vault.

The design appears safer than simply handing passwords to an AI model, but it does not remove every risk. Once Claude is authenticated, it may still be able to view private data, change settings, place orders, or perform other actions available inside the account. Users may want to limit the feature to low-risk tasks until browser-based agents become more predictable.

The Courts

Book Publishers Sue Google For Copyright Infringement Over Gemini AI Training (theguardian.com) 109

Major publishers Hachette, Cengage, Elsevier, and author Scott Turow have sued Google, accusing it of using millions of copyrighted books to train Gemini without permission or payment, in "one of the most prolific infringements of copyrighted materials in history." The Guardian reports: The publishers argue that Google repurposed books that had been supplied for limited services such as Google Books, Google Play Books and Google Scholar. Those services allowed Google to use the works in specific ways -- for example, to display searchable snippets or sell ebooks -- but not, the lawsuit claims, to copy them for training commercial AI products. "Desperate to maintain its online dominance, Google abandoned its early motto of 'Don't be evil' and engaged in one of the most prolific infringements of copyrighted materials in history," the suit states (PDF).

According to the complaint, the tech company made copies of copyrighted books to train Gemini without permission or payment, despite internal discussions acknowledging the legal risks. The filing claims Google flagged internally that it could face "$10Bs-$100Bs in potential fines" for using texts provided by publishers for Google Play Books. The publishers say Google's actions are harming authors and the wider publishing industry, arguing that AI-generated content could negatively impact book sales.

It notes that, for example, Gemini could generate "a 100-page murder mystery set in a quiet seaside town filled with secrets, that substitutes for an original copyrighted murder mystery on which Gemini trained" in 20 minutes for 39 cents. "No publisher or author can compete with that." The lawsuit names a number of specific books that the publishers allege were among the copyrighted works used without permission, including NK Jemisin's The Fifth Season, and Lemony Snicket's Who Could That Be at This Hour?

Slashdot Top Deals