Privacy

Flock Camera Vandalism Continues Around America, While 100 Communities Reject ALPRs (clickorlando.com) 13

Dozens of Flock cameras have been vandalized around Dallas Texas in the last six months, reports a local news station. In Utah, ABC News reports, a county sheriff's office even said Wednesday a Flock camera was even vandalized within days of its being installed. And in the Minnesota city of Winona, "Every Flock license plate reader camera operated by the Winona Police Department has been sawed off and stolen in what investigators believe was a coordinated theft," according to local media: All eight cameras were taken August 1, according to the Winona Police Department. A patrol officer first noticed the cameras had not sent any alerts in 24 hours. When officers checked the locations, they found the cameras had been cut from their poles and taken. The poles were left behind. Two additional Flock cameras on the Mississippi River Bridge, owned by Buffalo County, were also stolen in the same manner...

The thefts are part of a broader national trend. Flock cameras have been vandalized and cut down in communities across the country.

When someone in Florida filmed a damaged Flock camera lying in the grass in Florida, their footage attracted 980,000 views on social media, according to a local news report, with the uploader saying "Most of the people that are commenting are against Flock cameras." But that report adds it's one of at least five cameras recently damaged just in Florida:

- In another incident, investigators "found the black camera and its pole lying on the ground."

- Two days later, sheriff's deputies found a camera destroyed "with pieces scattered on the ground. Deputies reported the damage appeared to have been caused by a blunt object."

- On July 31, "Police said two camera poles had been intentionally cut in half, causing an estimated $10,000 in damage to the system."

In West Virginia 20-year-old Wesley Jackson has been arrested for allegedly vandalizing Flock cameras, with another 20-year-old (a university student) now arrested for being his accomplice, according to a local news report. Ironically, Jackson's arrest was made possible partly by information from... automated license plate readers.

But the Washington Post notes there's now a flood of Facebook commenters jokingly offering to provide a fake alibi: "Couldn't have been him — we were out counting blades of grass," said one of the 29,000 commenters on a post about the arrest from the local news station WDTV. Others attested that the man, Wesley Jackson, had been helping them "replace the roof on a homeless shelter," "playing halo 2," "changing the tires" on their car or giving their "doggie a treat" at the time the cameras were destroyed.
Meanwhile, the anti-surveillance group DeFlock reports 100 communities have now rejected automated license plate readers. Wednesday an Arizona county sheriff explained to his local Board of Supervisors why he will not renew his office's contract with Flock when it expires next month. Local Arizona media reports: "We have a camera system that can do facial recognition technology and can start building a data set on what our citizens are doing on a day-to-day basis," Teeple told supervisors. "That, in my training and experience, is a huge Fourth Amendment violation."
Recently an Arizona man even told his city council he'd be launching AI-powered satellites to monitor "where government officials go, where they stop, who they meet with, and when they return home," reports 404 Media: It would be no different than how the city monitors its citizens using Flock cameras, he said... He said he'd already started compiling profiles on their vehicles, spouses vehicles, children's vehicles, and planned to combine that data with Bluetooth signals, advertising IDs, and commercial data sources, "so our authorized users can replay the movements of every government official and their immediate family," he said. Local businesses would be invited to join the network, to "protect" officials while they shop, eat at restaurants, and move around the city.
And CNET reports "a quiet battle is happening across the US" between "towns working to adopt Flock Safety systems and those trying to ban them entirely." From major cities like Los Angeles canceling its Flock contract to towns wrapping Flock AI cams in plastic bags because Flock won't take them down, it's a wild time for surveillance and questions about government accountability.
Chrome

Google Should Still Be Forced To Shed Chrome, Advocacy Group Argues (yahoo.com) 21

"Google should be required to divest the Chrome browser, and prohibited from paying Apple to distribute Google's search engine, the nonprofit advocacy group Public Knowledge argues in a new court filing," MediaPost reports, citing a friend-of-the-court brief filed Tuesday in the D.C. Circuit Court of Appeals: The group adds that "independent ownership" of Chrome "would open the distribution channel Google controls and allow Chrome to serve browser users when it makes privacy decisions and determines how to integrate search and (artificial intelligence)..."

In September 2025, [U.S. District Court Judge] Mehta issued a remedies order that requires Google to share some data about users' searches with "qualified" competitors and to provide syndicated search results and ads to those competitors. The order also prohibits Google from entering into exclusive distribution contracts for Google Search, Chrome, Google Assistant and the Gemini app for six years, but allows the company to continue to make payments for search-ad revenue or distribution to Apple, Mozilla and others...

Google recently appealed Mehta's order. The company argued in its written brief that it "prevailed in the marketplace fair and square," adding that Apple and Mozilla "sensibly chose" Google as the default search engine "because it gave their users the best experience," and because Apple and Mozilla would earn the most ad revenue through the deals. The [U.S.] Justice Department and states countered to the appellate court last week that the liability finding should stand, and also argued that Google should have been banned from paying Apple and Mozilla for placement as the default search engine on their browsers.

[Antitrust enforcers had originally asked the judge to order Google to divest Chrome, but he's already rejected that request.] The government did not argue in its appellate papers that Google should be forced to sell Chrome. But Public Knowledge independently contends in its friend-of-the-court brief that divestiture would benefit consumers... "Divestiture would place those decisions with an institution whose success depends on serving browser users primarily...." The group is calling the appellate court's attention to Google's April 2025 decision to preserve tracking cookies — a reversal from its earlier plans to block third-party cookies by default. "Google is in the position of both deciding Chrome's tracking rules while running the advertising business affected by them," Public Knowledge writes. "An independent Chrome could make those decisions on behalf of users alone."

But Firefox developer Mozilla filed its own friend-of-the-court brief Thursday warning Firefox could be forced to "exit the browser and browser engine markets" if it can't receive payment from Google for distributing its search engine, according to a later report from MediaPost: Federal and state antitrust enforcers recently asked the appellate court to reverse the portion of Mehta's order that allows those payments to continue. But Mozilla counters in its new friend-of-the-court brief that Mehta's decision regarding those payments was supported by the evidence --including a study it conducted concluding that its revenue would "decline dramatically" if forced to replace Google with Bing as Firefox's default search engine... Google is expected to file new arguments with the appellate court next month.
Crime

More Police Officers Fired, Investigated, or Arrested for Misusing Flock Camera Systems (wtoc.com) 30

In Georgia the Savannah Police Department "terminated four sworn officers and two civilian employees following an internal investigation into misuse of the department's Flock Safety License Plate Reader system," according to a local news report: All six cases are also under independent criminal investigation by the Georgia Bureau of Investigation... Investigators found that employees were running searches on personal acquaintances and family members. One officer was found to have given someone from an outside law enforcement agency access to SPD's Flock Safety system, which they weren't authorized to do.
Elsewhere ABC News reports that a female North Carolina police officer was arrested Wednesday "for allegedly using Flock license plate readers to track her boyfriend's ex-wife, according to police..." The officer is accused of accessing the system for personal use 31 different times, including at least twice when she was off-duty, and listing most of the lookups as motor vehicle infractions. [Police chief Ron] Campurciani "added that the department is looking at 10 other potential misuse cases and said three 'look like they could be problematic.'"

And an Ohio news station reports a police officer who recently resigned "while under internal investigation repeatedly used the Flock license plate reader system to search a vehicle registered to someone investigators identified as his likely domestic partner."

Meanwhile, 404 Media reported this week that an Iowa county's usage police specifically tells police officers — in all capital letters — not to tell occupants of a vehicle that an automated license plate reader was used for a traffic stop. It also instructs officers to not even mention the use of the ALPR technology in their reports "unless absolutely necessary," according to information they'd obtained from a public records request," suggesting they instead they call the cameras "county resources": It is not just local police in small communities who are creating policies designed to obfuscate Flock usage. Earlier this year, we reported that police in multiple states were being told to be "as vague as permissible" about why they were using Flock because their searches could be obtained using public records requests, and that warning was being shared by the FBI and Department of Justice...

In the [Iowa county] public records request, Sheriff Don Phillips said "there is no need" to tell people about the use of Flock... "because the information is verified by the deputy running the license plate. It is common practice for law enforcement to refrain from disclosing investigative methods and sources to prevent criminals from learning how to circumvent them."

Privacy

Woman Pulled From Car at Gunpoint By Police After Mistaken Flock Alert - Twice (fox6now.com) 147

The police surrounded her car Thursday, "drew their guns, and told her to come out with her hands up," reports a local news station. The police thought they were pulling over a murder suspect, but "It turns out it was a mistake by another department with the Flock license plate reader technology." The black woman says she'd wanted to call her mother, "but I'm like, if I make a sudden move, it's going to be over. It's going to end my life."

And amazingly, the same thing happened Monday, according to the local news report. "Milwaukee police pulled her over with guns drawn. She says officers never explained why, towed her car, and let her go."

She now describes herself as "traumatized," recalling her second detention by police on Thursday. "After they put us in cuffs, they walked us to the car. I'm not knowing what's going on. I'm scared. All you see is people in their cars recording." She now says she's scared to drive her car, and so is her daughter. "Because she doesn't know if the police are going to pull us over and do it again..."

"I haven't been to sleep since this happened. Every time I close my eyes, all I can see is guns."

She wants an apology, since the local police would only say it wasn't their fault, it was the fault of the Milwaukee police department that failed to remove the alert from Flock's system. "Milwaukee police emphasized this was not a Flock camera issue, it was a data entry mistake," according to the local news report. The woman's response?

"Y'all failed. Y'all failed the system. Y'all failed me. Y'all failed everybody."
Power

Trump Administration To Pay German Firm $1.2 Billion To Halt US Wind Projects (bbc.com) 173

An anonymous reader quotes a report from the BBC: German energy company RWE has said it will abandon its offshore wind projects in the U.S. after reaching a $1.2 billion payout deal with President Donald Trump's Department of the Interior (DoI). RWE said that it will now reinvest the sum into conventional gas projects, including $900 million in a liquefied natural gas (LNG) export terminal project in Louisiana. "After careful consideration, it was determined there is no path forward to permit these projects in the US for the foreseeable future," the company said in a statement.

RWE said it has agreed to relinquish its leases off the California and Louisiana coasts as well as in the New York Bight. Overall, the German firm plans to invest approximately $19.6 billion in the U.S. over the next six years "to grow its generation capacity." Interior Secretary Doug Burgum said in a statement posted on X that Americans deserve an energy system built on common sense and not one dependent on "costly subsidies." "We welcome RWE's agreement and voluntary investment in projects that strengthen our nation's energy security," he added.
Earlier this year, the DOL reached a deal with TotalEnergies putting an end to the French company's offshore wind projects in the U.S. "Instead, the firm agreed to reroute investment to build a LNG plant in Texas and to develop 'upstream conventional oil' in the Gulf of Mexico," reports the BBC.

Another similar deal was signed with Charlotte-based Duke Energy last month to terminate the company's offshore wind lease in the Carolina Long Bay area.
Privacy

Framework Notifies 'All Customers' of a Data Breach Via Compromised Metabase BI Service (techcrunch.com) 7

"Framework has been sending out email notifications to customers alerting of a limited data breach in which customer information was accessed through a Metabase BI service zero-day exploit," writes Slashdot reader DuoDreamer. Data includes customer names, email addresses, phone numbers, and physical addresses. "Framework is investigating whether or not this included Framework for Business customers as well." TechCrunch reports: Framework's spokesperson Eric Schumacher told TechCrunch that the breach affected "all customers," but declined to specify a specific number. Framework computers are relatively niche products, but some estimates say the company sold hundreds of thousands of devices.

Metabase disclosed its own breach in a blog post on its official website, where it said that it was hacked by someone using an unknown security flaw, a so-called zero-day. The company said the hackers exploited the bug to give them the ability to access customers' databases stored on Metabase's cloud servers.

In its email to customers, Framework also included the email Metabase sent to the company, which says hackers accessed Framework's cloud instance. The computer maker said it investigated the incident and found that hackers had stolen its customers' personal data, but did not include their payment information.

Government

Trump Orders New 15% Tariff On Key Material For Solar Panels, Microchips (theguardian.com) 131

President Trump has ordered a 15% tariff on imported products made with polysilicon, a key material for semiconductors and solar panels. The new tariff will take effect on December 4th. The Guardian reports: The executive order signed by the president on Thursday evening said: "The plan of action in this proclamation will, among other things, help ensure the commercial viability of United States production of polysilicon and its derivatives that is necessary to meet United States economic and national security requirements." Polysilicon, an ultra-pure form of silicon, is an important ingredient in making the semiconductors vital for AI processing power, datacentres and solar power generation. US solar factories have long accused Chinese rivals of dumping cheaper panels on the market, which they say have been enabled by excessive government subsidies and by moving manufacturing to other countries to dodge US tariffs.

[...] The US has two main polysilicon factories, including Hemlock Semiconductor, which operates a plant in Michigan and is a joint venture between the US tech company Corning and Japan's Shin-Etsu Handotai. The Munich-based Wacker Chemie runs a factory in Tennessee. Trump said in the order that he had accepted recommendations by the commerce secretary, Howard Lutnick, to set minimum import prices of $21 a kilogram for polysilicon, $100 a kilogram for polysilicon ingots and wafers, $0.22 a watt for solar cells, and $0.38 a watt for solar modules or panels. The order also allows the commerce department to create an incentive program for companies that invest in factories to produce polysilicon or derivative products.

The Courts

Court Orders Meta To Establish $567 Million Fund To Abate Harms To Youth (www.techpolicy.press) 36

A New Mexico court ordered (PDF) Meta to create a $567 million fund to address harms linked to youth mental health and child sexual exploitation after finding its platforms constituted a public nuisance. "In sum, the Court finds that New Mexico is in the midst of a teen mental health crisis affecting public health and public safety in and throughout the state, and that Meta's platforms are a significant contributing cause to the crisis," wrote Chief Judge Bryan Biedscheid in the decision. The fund comes on top of $375 million in civil penalties, though the judge declined to mandate changes to features such as infinite scroll and autoplay, citing potential First Amendment and Section 230 concerns. Tech Policy Press reports: The decision follows the second phase of in the State of New Mexico v. Meta Platforms Inc., which consisted of a bench trial. Its central question was whether Meta's platforms amounted to a public nuisance in New Mexico, and, if the court found that they did, what remedy would be needed to address it. In March, a Santa Fe jury found Meta liable for violations of New Mexico's Unfair Practices Act, awarding $375 million in civil penalties. The jury deliberated less than a day following that nearly seven-week trial. The $567 million abatement fund would be in addition to the civil penalties, according to today's decision.

New Mexico Attorney General Raul Torrez sued Meta in December 2023, alleging the company made false public statements about the safety of its platforms while knowing internally that its products facilitated child sexual exploitation. The court denied Meta's Section 230 defense in May 2024. In today's decision, the court again asserted that "Section 230 does not preclude the State's public nuisance claim," but the decision attempted to thread the needle on issues that the court determined might have run "afoul" of the statute, or of the First Amendment, such as issuing remedies around any particular product feature.

Privacy

'Tower Dump' Warrants Ruled Unconstitutional (thehill.com) 62

alternative_right shares a report from The Hill: A federal judge in Mississippi ruled Wednesday that "tower dump" warrants are unconstitutional, declining to reverse a lower court decision refusing the government's request to obtain the search warrants in a series of violent crime investigations. A "tower dump" involves cellphone companies providing law enforcement with access to the time and location data of all mobile devices connected to specific cell towers during a designated time window.

Law enforcement had sought approval for several of these search warrants as part of criminal investigations into gang-related activity in the Jackson, Miss., area last year, arguing the data could help identify all those potentially involved, particularly in incidents with unknown suspects. A magistrate judge denied the applications, holding that "tower dumps" are impermissible general warrants. The district judge agreed.
The order repeatedly referenced the Supreme Court's recent decision in Chatrie v United States, in which the majority held that geofence warrants require constitutional privacy protections.

"With this information, the Government asserts that it will be able to identify all potential suspects," Judge Carlton Reeves wrote in a 30-page order (PDF). "Even so, law enforcement would also have access to the cellular records of countless individuals, the vast majority of whom were merely passing by a location at the 'wrong' time."

"That is an unreasonable search under the Fourth Amendment," the judge concluded.
AI

OpenAI's Models Shared Hacking Tips On a Secret Messaging Board Before Hugging Face Breach 51

OpenAI researchers say multiple AI agents secretly created an internal message board to share hacking techniques, eventually finding ways around restrictions, exploiting a zero-day, and helping two models breach Hugging Face without human prompting. "This is a pivotal moment both for our company as well as the AI industry as a whole," Michael Dalton, one of the AI-maker's researchers, said during a presentation at the Black Hat cybersecurity conference in Las Vegas, Nevada. Politico reports: Dalton and Eric Wallace, another OpenAI researcher, said Wednesday the AI giant recently learned that multiple agents it was testing simultaneously began communicating over an internal message board in early May. There, different models shared advice about how to accomplish difficult hacking challenges they were struggling to surmount, including workarounds that required internet access. Two OpenAI models ultimately strung together a series of sophisticated techniques to gain access to the internet and worm their way inside Hugging Face in mid-July. OpenAI has said the models were focused on completing a hacking evaluation they were prompted to solve, and that correct answers could be found on the AI developer platform.

The OpenAI researchers told conference attendees that since early May, the models created a message board inside OpenAI's Artifactory internal file system. Without the company's knowledge, the models spent months independently exchanging information and techniques to help each other complete difficult tasks. Wallace said that when models get stuck, they often "try to game or cheat the task in order to get their reward." "The beginning of this incident kind of traces back to this point where one agent realized it could communicate by uploading a note," he added. By late May, one model found a way to abuse Artifactory's internet access to retrieve files from various websites -- effectively giving the models indirect access to the internet. In June, the models were able to find and exploit a previously unknown zero-day vulnerability to gain administrative privileges on Artifactory, install remote software and expand their activity within the system.

These efforts eventually overloaded Artifactory, causing a system-wide outage in early July that alerted OpenAI's engineers to the ploy. After investigating, the company revoked the model's credentials, removed the message board and worked with Artifactory to fix any gaps before resuming training. But the models found another way to communicate inside Artifactory just days later and continued exchanging techniques to target additional vulnerabilities within OpenAI's infrastructure and external systems, including Hugging Face.
Social Networks

The US Government's Mario, Pokemon and Naruto Meme Posting Could Damage These Franchises, Japanese Officials Warn (ign.com) 83

Japanese officials have repeatedly asked the Trump administration to stop using characters from franchises such as Mario, Pokemon, and Naruto in unauthorized government memes and pro-war videos, warning that the posts could damage the intellectual property involved. IGN reports: Official US government social media accounts, including The White House's X account, have posted various memes and videos using characters from popular Japanese anime and games over the past year. Japan's Ministry of Foreign Affairs has repeatedly called on the US government to cease uploading such posts, stating that "It's inappropriate even for public institutions to reproduce copyrighted materials without the rightsholders' consent." This concern was voiced by Minister for Foreign Affairs Toshimitsu Motegi in a parliamentary session back in April, when he made direct reference to a pro-war video that used Nintendo's Wii Sports.

However, according to a report by Mainichi Shimbun this week, the Japanese Ministry called on the Trump administration to stop using IPs like Naruto, Pokemon and Mario at least twice more this June through the US Embassy in Japan. Japan requested that the US administration take into account the potential damage to these IPs when used without permission in US policy and pro-war related content.

[...] It's not just the Japanese government and related parties who have spoken out against these posts. They have also sparked backlash from Japanese anime fans. Notably, self-proclaimed manga and anime fan Nana Suzuki kicked off the "Protect Japanese Manga" petition on Change.org, which has received international news coverage (from the New York Times, BBC and others). The organizer claims to have submitted their petition to the Japanese Cabinet Office back in March, as well as alerting Japanese politicians to the US government's unauthorized use of Japanese IPs, potentially drawing more official attention to the issue.

Renewed backlash was triggered in June, when President Trump shared an AI-generated video depicting himself as Naruto, the protagonist of the popular manga and anime of the same name, on Truth Social. This prompted the petition organizer to reopen the petition "as an urgent effort to convey our protest and concern regarding this matter to the rights holders and to work in solidarity to lobby the Japanese government." The Naruto clip also prompted renewed discussion of this issue in Japan's media and government. As reported in the Hokkaido Shimbun and others, Cabinet Minister Kimi Onoda was asked about it in a June 12th press conference. She emphasized that "obtaining permission from the copyright holder is the underlying principle for fair use," and stated that this position had been conveyed to the US government multiple times through diplomatic channels.

Government

FCC Kills TV Ownership Cap, Claiming Authority Over Limit Set By Congress (arstechnica.com) 121

An anonymous reader quotes a report from Ars Technica: The Federal Communications Commission voted 2-1 today to eliminate the National Television Ownership Rule, claiming authority to repeal a limit that was set by Congress over 20 years ago. The rule prohibits any single broadcast station owner from reaching more than 39 percent of all TV households in the US. Under Chairman Brendan Carr, the FCC is replacing the rule with a "case-by-case review" of each proposed merger.

"This will empower the FCC to approve deals that promote the public interest while allowing the agency to reject any deals that do not meet that standard," Carr's office said in a press release today. Without the 39 percent rule, broadcasters will be better able to compete against streaming companies that don't face similar limits, Carr's office said.

The change, if not stopped by courts, will make it easier for Carr to allow broadcast mergers that result in more favorable news coverage for President Trump. Carr has consistently threatened to revoke licenses from broadcasters who have drawn Trump's ire, including by ordering an early license review of all ABC-owned stations. Carr said local broadcast TV stations are becoming "undifferentiated passthroughs of national programming produced in Hollywood and New York," and he justified repealing the ownership rule by arguing it will help the stations invest in local news.
"It's worth noting that Republicans with deep firsthand knowledge of this issue also agree the commission cannot do what it is attempting today," said Democratic FCC Commissioner Anna Gomez, who voted against the decision today. "Former FCC Commissioner Mike O'Rielly has been unequivocal that the FCC lacks authority to change the cap. Former House Majority Leader Tom DeLay, who negotiated the 39 percent compromise, has stressed that Congress intentionally wrote the cap into law to prevent FCC revision. And Senate Commerce Chair Ted Cruz has said he is 'skeptical a change can be made absent an act of Congress.' Their consensus reinforces a simple point: Congress set the cap, and only Congress can change it."

Gomez, in addition to arguing that "Congress deliberately enshrined the cap in statute and removed it from the Commission's review process," said removing the cap will hurt local broadcasters. "Digital giants compete for their most valuable programming and advertising, while consolidation pressures at the national level threaten the local reporting and public-safety functions on which communities rely," Gomez said. "But eliminating the cap does not free local broadcasters from that strain. It just changes who is doing the squeezing. A handful of station-group giants does not represent the wishes of local broadcasters. They are large national companies that own local stations and increasingly dictate what airs on them without much local input. Trading a squeeze from Big Tech for a squeeze from Big Media does nothing to protect the communities this cap was designed to serve."
Piracy

Broadcaster Wins Broad US Blocking Injunction Covering Pirate Sites That Don't Exist Yet 44

An anonymous reader quotes a report from TorrentFreak: Mexican broadcaster TelevisaUnivision (TU) has obtained (PDF) one of the broadest anti-piracy injunctions ever issued by a U.S. federal court. After initially targeting five pirate IPTV streaming operations, the case expanded to cover well over 500 domain names, requiring intermediaries including Cloudflare, GitHub, and a Mexican bank to comply. In addition, the injunction also covers pirate services and content that hasn't been created yet. [...] The case was relatively targeted, naming the IPTV services Thunder TV, Sunset TV, Pop TV, Kaelus TV, and Tele Latino, as well as their alleged operators. The broadcaster argued that these pirate IPTV services threatened its business. TU holds the World Cup rights for sixteen Latin American territories, and its license with FIFA requires it to keep the Mexican broadcast signal from reaching the United States. The pirate services, it argued, put it in breach of that contract, exposing it to "termination and forfeiture of hundreds of millions of dollars in payments." To stop this immediate threat, the company requested a temporary restraining order, hoping to shut down the IPTV services effective immediately.

[...] Judge Kathleen Williams granted the temporary restraining order (PDF) on June 5, one day after the case was filed, without hearing from any of the defendants. The initial order prohibited the defendants from infringing TU's own copyrighted works, which include telenovelas and other programming, and from using its trademarks, including all content linked to its licensed World Cup broadcast. Importantly, the order also targeted third parties acting "in active concert," including ISPs, hosts, CDNs, domain registrars, registries, app stores, ad networks, social platforms, search engines, and payment processors. These were ordered, on TU's request and with notice, to disable the listed domains and IP addresses and unmask whoever was behind them. [...]

While the injunction is noteworthy for many reasons, the most striking feature is that it's specifically written to include things that don't yet exist. That starts with the content it protects. The order isn't limited to TU's current catalog or the World Cup rights, it covers the infringement of "any copyrighted works or broadcasts that Plaintiffs may in the future produce, license, or acquire rights to transmit." In other words, it covers future copyrights that did not exist when the order was signed. The same applies to the pirate services themselves. The injunction defines its target as the named IPTV operations "and any comparable system," whether "currently in existence or developed in the future," and it applies "regardless of the branding, domain name, or technical configuration used."
Security

Anthropic's AI Used Fake Identities, Malware In Rogue Attack On GitHub Project (arstechnica.com) 48

An anonymous reader quotes a report from Ars Technica: Routine cybersecurity testing of frontier AI models sparked a series of unexpected security incidents -- the most serious case arising when Anthropic's Mythos 5 model attempted to insert malicious code into an open source software application and created fake identities to deceive the human developers maintaining the project. The security incidents occurred during a cyber evaluation of seven leading AI models' capabilities by the AI Security Institute (AISI), a research organization within the UK government, in late July. The researchers discovered (PDF) 19 instances in which "AI agents took unsanctioned action on the live Internet, including cases that targeted real people and organizations," according to an AISI blog post published on August 4.

Almost all the "autonomous, unsanctioned" actions came from Anthropic's Mythos 5 model, with two such actions coming from OpenAI's GPT-5.6 Sol. [...] The most serious case involved Mythos making multiple attempts to execute a supply chain attack on the open source project repository hosted on the developer platform GitHub, including using social engineering techniques to try to convince the repository's human maintainers to merge malicious code into the repository.

After first opening a pull request to merge the malicious code into the repository, Mythos created fake online "sock puppet" personas that claimed to have independently reviewed and verified the code as not containing malware. The AI agent also sent five emails to two human maintainers of the repository, including some emails containing malware and others attempting to persuade a maintainer to accept the pull request. Mythos even opened a GitHub Issue on a second repository -- also owned by a maintainer of the first repository -- that contained a prompt injection with malicious instructions targeting "issue-triage AI coding agents." This line of attack came from Mythos reasoning that the repository maintainer could be an AI coding agent such as Claude Code.

Privacy

Apple's 'Private Relay' Is Exposing Users' Real IP Addresses 46

Security researchers found that Apple's iCloud Private Relay can expose users' real IP addresses because some passkey-related requests bypass Safari and its proxy protections at the operating-system level. "In short: any website that supports, or pretends to support, passkeys can see the user's real IP address despite having iCloud Private Relay on," security researcher Tommy Mysk, who discovered the issue along with Talal Haj Bakry, told 404 Media. The flaws also affect OnionBrowser, an iOS app for browsing the web through the Tor anonymity network. It does not, however, impact the official Tor Browser itself. From the report: The researchers developed a site that lets Private Relay users check if the issues impact them. In 404 Media's tests, the site did return the real IP address of a user that was supposed to be protected by Private Relay.

[...] In a quirk of how passkeys work -- a broadly secure alternative to usernames and passwords which use the WebAuthn standard -- a user's device makes a web request outside of the browser itself. Meaning, that request essentially bypasses Private Relay and exposes a user's real IP address, even though to them it may look like they are simply interacting with a website as normal.

"Because the fetch is issued by the operating system's credential service rather than by Safari, it never enters Private Relay's proxied path. The destination server sees the device's real IP address either way," the researchers write in their research. [...] "We have already informed them. They said the issue was âdire,' but they let us disclose the issue. They didn't provide any time when they will address this," Mysk said.

Slashdot Top Deals