Movies

Netflix Sued For Losing 'Master Copy' of Unreleased Nicolas Cage Movie (cbsnews.com) 79

A production company and filmmaker are suing Netflix for $105 million, alleging the streamer lost a stolen drive containing an unencrypted master copy of the unreleased Nicolas Cage film Fortitude, which they claim damage its exclusivity and market value. Netflix denied responsibility for the lost film but said it takes content security seriously and has offered to monitor piracy sites for unauthorized copies. CBS News reports: The complaint filed on Wednesday in California district court alleges that the film's associate producer, Daniel Haido, hand-delivered an unencrypted master copy of the film to Netflix so the company could screen it as a potential buyer. Haido verbally instructed the employee to delete the files after the screening, according to the suit. A little over a week after the screening, Netflix emailed the filmmakers to say the drive had been stolen, the plaintiffs allege. "Someone stole a good amount of drives from our office desks this past week," a Netflix executive wrote in the email, according to the suit.

The complaint notes the movie, entitled "Fortitude," took over seven years to make and cost $45 million. It tells the story of a secret mission called Operation Fortitude during World War II that was orchestrated to mislead the Nazis about the Allied invasion of Europe. The film stars Nicolas Cage as Dusko Popov, a real-life spy during World War II, as well as Sir Ben Kingsley and Ron Perlman.

The plaintiffs said studios will now be dissuaded from buying the rights to the movie, knowing that a version of it could be released by a third party for free. "The film's value depended in significant part on its exclusivity as an unreleased, first-to-market work," the complaint states. "By losing control of the film, Netflix destroyed that exclusivity and materially, if not completely, impaired the film's marketability."

AI

Anthropic Says Its AI Systems Broke Into Computers at 3 Organizations 44

Anthropic found that Claude models breached three outside organizations during cybersecurity tests because misconfigured environments accidentally gave them access to the internet. The company notified those affected and urged other AI labs to audit their own testing systems. The BBC reports: Anthropic said in a statement that it reviewed more than 140,000 tests to find evidence that Claude - its family of AI models - could access the internet from testing environments that were designed to be sealed off. The tests include so-called "capture-the-flag" evaluations in which Claude was tasked with obtaining information by breaching other systems - a common way that experts assess a model's hacking capabilities.

A "misconfiguration" on systems run by Anthropic and its testing partner left the models with live internet access, allowing them to breach other systems, the San Francisco-based firm said. Anthropic said the earliest incidents date back to April and that it is "approaching the fixes as if the responsibility were ours alone." Neither Anthropic nor the organizations that were breached had noticed the intrusions at the time.

Anthropic said it could have reviewed its records more thoroughly and added that the findings gave the firm "cautious optimism" that such risks can be overcome with more investment and tighter measures. "The broader lesson is not necessarily that AI has developed a fundamentally new attack capability," cyber security expert David Allott told the BBC. "Instead, it is that AI agents can combine capabilities, obtain credentials and system access to take actions autonomously, while adapting scope and scale at machine speed," he added.
The announcement comes just days after OpenAI said that its models had breached the systems of other companies, including AI tools platform Hugging Face.
United States

Flock Cameras Are Being Destroyed Across the US (cnn.com) 86

An anonymous Slashdot reader writes: Surveillance cameras owned by Flock Safety have been cut down with electric saws in New York State, vandalized with paint in Oakland, California, and rammed with a truck in Idaho. Flock claims its services fight crime, but law enforcement agencies also use their services to track vehicles based on license plate numbers and reconstruct the their movements, even when the drivers and owners of these vehicles have never been accused or convicted of any crime. (Flock states it has 120,000 automated cameras that record license plate data, as well as pan-tilt-zoom cameras, across the United States.)

A guerilla mindset among average citizens have seen these cameras forcibly disabled within recent weeks with sympathy directed toward the vigilantes. In June, a West Virginia man accused of destroying several Flock cameras was arrested. Under a Facebook post from the local NBC affiliate announcing his arrest are dozens of people volunteering to provide alibis. "He was out fishing with me that day, you got the wrong guy," one man wrote.

Censorship

ABC Accuses FCC of 'Attempted Censorship' (politico.com) 54

ABC accused FCC Chair Brendan Carr of "attempted censorship," arguing that an early review of its eight broadcast licenses is politically motivated retaliation over the network's coverage and could chill the entire media industry. "The retaliation against ABC is a signal to every media company in the country: accommodate the Administration's view of what news coverage should look like or pay the price," the Disney-owned television network wrote. Politico reports: "Across the government, regulatory and contracting carrots and sticks have been trained on other disfavored speakers," ABC's lawyers added in the 119-page filing. "The tools vary; the objective does not: a media industry too fearful of official reprisal to report the news freely."

Carr has repeatedly rejected accusations of censorship while defending his efforts to rein in what he calls abusive, politically motivated behavior by licensed TV broadcasters. "I don't view the FCC as the speech police," he told POLITICO this week for an upcoming episode of the podcast "The Conversation."

In its filing, ABC pointed to an outpouring of support it has received in more than 152,000 comments in the agency's license review, as well as recent warnings from conservative Supreme Court Justice Neil Gorsuch, Sen. Ted Cruz (R-Texas) and various pro-free-market organizations about the dangers of a politically motivated FCC. Those include letters from a bipartisan group of former FCC leaders, community and advocacy groups and lawmakers of both parties. "The Commission's attempted censorship of ABC has attracted condemnation across the political aisle," the network wrote.

Privacy

Catastrophic MoD Data Breach Caused By Lack of Training On Excel (independent.co.uk) 49

A UK parliamentary inquiry found that a catastrophic Ministry of Defense breach exposing 18,700 Afghans could have been prevented with basic Excel training, after an employee unknowingly shared a hidden worksheet containing their details. The Independent reports: The leak, in February 2022, exposed the details of 18,700 Afghans who said they were in danger from the Taliban because of their links to UK forces and now wanted to escape to Britain. The blunder triggered an unprecedented superinjunction used against the national media, including The Independent, and prompted a secret evacuation program -- the cost of which is still unclear but which likely ran into the billions of pounds. Following the revelation by this outlet and others in July last year of the hidden operation, MPs set up an inquiry to scrutinize what had happened. In their report, the defense selection committee concluded that:

- The data breach could have been prevented if Ministry of Defense (MoD) personnel had received basic Excel training
- By August 2023, when the department discovered the leak, thousands of people already knew that a significant data incident had taken place
- The government did not strike "the right balance between operational secrecy and democratic accountability" -- and the superinjunction was in place for too long
- Secrecy denied affected Afghans the chance to take steps to protect themselves and their families and caused delays to evacuation program
- Thousands of Afghans eligible to come to Britain are still trapped in Afghanistan with the government failing to explain how they will help get families to safety.

MPs have called on the government to publish periodic reassessments of the risks facing Afghan applicants to UK resettlement schemes, with officials to report findings annually. They also want ministers to publish a clear policy explaining how they will help Afghans who are eligible to come to Britain but who have not yet been evacuated. The defense committee have also called on the MoD to explain who was responsible for data protection risk before the Afghan breach, criticizing the lack of accountability within the civil service.

The Courts

Comcast Store Punished Low Sales By Smashing Pies In Workers' Faces, Lawsuit Claims (arstechnica.com) 176

A former Comcast retail employee alleges that a Connecticut store manager tied the lowest-performing salesperson to a chair each month and had co-workers smash a cream pie into their face, recording the incidents as a sales-motivation tactic. The plaintiff says he resigned after reporting the alleged assaults and is seeking damages for constructive discharge and emotional distress. Ars Technica reports: A Comcast store in Plainville, Connecticut, "had a policy that the highest-ranked Retail Sales Consultant for the prior month was instructed by his or her supervisor -- Ms. Peterson, the Comcast Store manager -- to tie the lowest-ranked sales consultant for the prior month to a chair in the back office and thereafter assault that person by violently smashing a cream pie in their face," the complaint alleged (PDF).

Plaintiff David Figueroa's lawsuit said he was hired as a retail sales consultant on February 2, 2026, and was supervised by store manager Sully Fuentes Peterson. Figueroa alleges that Peterson "designed and implemented" the pie-in-face ritual to meet goals related to sales and positive responses in customer surveys.

"Defendant did not inform the Plaintiff prior to his acceptance of Defendant's offer of employment that the Comcast Store has a policy of subjecting Retail Sales Consultants to public assaults by co-workers -- at the direction of Ms. Peterson, the store manager -- for the purpose of increasing Defendant's sales and profitability," the lawsuit said.

Figueroa resigned on February 27, and he alleges it was a constructive discharge. The lawsuit says the defendant, Comcast, was negligent because it "reasonably should have known" about the store management's policies and that the policies could harm employees. Comcast "failed to properly supervise the Comcast Store's management team," allowing store management to humiliate employees "for the purpose of promoting the Defendant's revenues and profits," the lawsuit alleged.
Comcast said in a statement: "The Company has zero tolerance for harassment, humiliation, or any behavior that compromises a respectful and safe workplace. This matter is in litigation so we will not comment on the specific allegations, other than to say that we disagree with the claims in the complaint and its characterization of the alleged events, and intend to fully respond through the legal process."
Robotics

Who Wins and Who Loses After US Bans Foreign Robots? (arstechnica.com) 89

The FCC's ban on Chinese-made robots extends well beyond humanoids to quadrupeds, research platforms, and many robot vacuums from allied countries. Supporters call it a major boost for domestic robotics, but critics warn that cutting researchers and startups off from affordable foreign hardware could slow U.S. innovation instead. Ars Technica's Jeremy Hsu examines who stands to gain and who stands to lose from the prohibition: Such an import ban would apply to some of the most affordable robots primarily produced by Chinese companies, including Unitree's humanoid robots that are used by robotics labs and researchers for tasks such as experimental robot surgeries. US consumers would also likely lose access to the newest robot vacuum cleaners that are mainly manufactured by Chinese companies such as Roborock. But the ban also broadly applies to foreign-made robots produced by countries nominally allied to the United States, including Japan, South Korea, and Germany. [...]

The ban on foreign-made robots could theoretically encourage more US and foreign companies to set up manufacturing facilities in the United States. There are already multiple companies racing to scale up production of humanoid robots in US factories, including Agility Robotics, 1X Technologies, and Figure AI. Tesla has been attempting to shift production away from older electric vehicle models and toward its Optimus humanoid robot. Boston Dynamics has already been making its Atlas humanoid robot, along with its four-legged Spot robot and wheeled Stretch robot, at its main facility in Waltham, Massachusetts. The US robotics company is also planning to massively scale up manufacturing of the Atlas robot under South Korea's Hyundai Motor Company, which gained full ownership of Boston Dynamics in July 2026.

"This is one of the strongest technology-security actions in modern US history," wrote Evan Beard, CEO of Standard Bots, in a LinkedIn post. "The message is unambiguous: robotics is a technology America must lead and own -- and foreign-subsidized robots will not be allowed to unfairly dominate US robotics as they did solar." Similar praise came from Rush Doshi, director of the Initiative on China Strategy at the Council on Foreign Relations, who, in a social media post, described the FCC decision as "one of the most significant actions taken so far in support of the US robotics ecosystem."

However, several robotics researchers and analysts interviewed by The Robot Report expressed skepticism about any potential boost to US competitiveness in robotics. Some even warned that the ban could prove counterproductive for US robotics efforts to develop humanoid robots. "In the near term, the measure could slow US physical AI innovation by cutting startups and researchers off from future low-cost Chinese platforms before comparable Western alternatives exist," said Georg Stieler, a global robotics advisor and managing director for Asia at Stieler Technology & Market Advisory, in an interview with The Robot Report.

US domestic production of robots lags behind China in terms of mass manufacturing at lower cost, said Rueben Scriven, a senior analyst at Interact Analysis. "This announcement is more likely to inhibit the US humanoid robotics industry, as the presence of low-cost Chinese humanoid robots has been helping educate the US market through promotional and entertainment use cases -- an effect this policy risks undermining," Scriven told The Robot Report.
The report notes that previous FCC bans have done little to help create competitive U.S. alternatives, with restrictions on Chinese drones instead prompting companies to sell barely disguised versions of DJI technology.
Crime

Russia Charges Telegram Founder Durov With Facilitating Terrorism (bbc.com) 82

Russia has charged Telegram founder Pavel Durov with facilitating terrorism, alleging the platform was used by Ukrainian intelligence "to prepare and co-ordinate acts of sabotage and terror" inside Russia. An international arrest warrant has been issued for Durov, who currently lives in Dubai, United Arab Emirates, where Telegram keeps its main office. The BBC reports: Shortly after the charge was announced, Telegram's account on X posted an image showing Durov holding up his middle finger. He has previously accused Russian authorities of "fabricating new pretexts to restrict Russians' access to Telegram."

[...] Multi-billionaire Durov, 41, has lived outside of Russia for many years and holds French and United Arab Emirates (UAE) passports. It is unclear whether other countries or authorities would comply with an arrest warrant issued by Russia.

Durov left Russia in 2014 after refusing to comply with government demands to shut down opposition communities on the platform. He had previously founded popular Russian social media company VKontakte - dubbed the "Facebook of Russia."
In 2024, Durov was arrested and investigated by the French government in connection with criminal activity on the platform and a lack of cooperation with law enforcement. "He was allowed to go home months later, with the investigation continuing," notes the BBC.
Security

More Than 30 Minnesota Water Systems Targeted In Cyberattack (fox9.com) 65

jrnvk shares a report from KMSP: Minnesota IT Services reports that a "coordinated cyberattack" targeted technology at more than 30 community water systems between Sunday, July 26 and Monday, July 27. The state has activated its cybersecurity incident response capabilities to respond to the attacks.

On Monday and Tuesday, FOX 9 reported on notices from four cities that had disclosed the attacks: Plymouth, South St. Paul, Maple Plain, and Braham. All four cities said the impacts of the attacks were limited or mitigated and residents could continue normal water use. The Minnesota Department of Health is not aware of any municipality asking residents to alter their drinking water use as a result of the attacks.

State officials are working with federal and private-sector partners to investigate the attacks, support the affected communities, and strengthen the security of Minnesota's critical infrastructure.

Robotics

Trump Administration Bans New Chinese Humanoid Robots (bbc.com) 143

The Trump administration has banned newly authorized foreign-made humanoid and four-legged robots, along with power inverters, citing "unacceptable risks" to the country's national security. FCC chairman Brendan Carr said the agency was doing its part "to secure America's critical supply chains." The BBC reports: The FCC has added the items to its Covered List -- a register of goods and services that are deemed a risk to US national security. The ban applies to new foreign-produced advanced robotic devices and power inverters and does not prevent the sale or import of any existing models that had been previously authorized by the FCC.

The FCC cited concerns that the use of foreign-made inverters could allow overseas firms to turn them off, steal data, facilitate remote access and surveillance by "foreign government actors, or be otherwise exploited through a cyberattack." It added that the use of robots made outside the US could allow "malign actors to surveil Americans, enhance the capabilities of foreign intelligence services, or to remotely commandeer the robots."

Bug

AI-Found Bugs Aren't Proving Any Easier to Exploit Despite the Hype 76

AI-assisted vulnerability discovery has yet to produce the expected surge in real-world attacks: VulnCheck found that only 14 of 1,061 attributed discoveries, or 1.3 percent, had been exploited, which is "almost identical to the rate across all vulnerabilities in VulnCheck's dataset," reports The Register. "That's a far cry from the narrative that frontier AI is dramatically tilting the balance in attackers' favor by churning out instantly weaponizable bugs." The findings suggest AI is currently better at increasing the volume of bugs found than making them easier to weaponize. From the report: The report takes particular aim at Anthropic's much-publicized Project Glasswing, unveiled in April with warnings that AI-assisted vulnerability discovery could allow attackers to hijack systems, disrupt operations, or steal data. Claude Mythos may have identified 23,019 vulnerability candidates, but there's remarkably little public evidence showing what became of most of them. VulnCheck notes that only 126 have been published as CVEs, that just one has been confirmed exploited in the wild, and that Anthropic's public disclosure record has seen little movement since Project Glasswing launched.

But that doesn't mean AI-assisted vulnerability research has failed, according to Patrick Garrity, security researcher at VulnCheck. "AI-assisted vulnerability discovery clearly has value for both attackers and defenders," Garrity wrote. "The data does not suggest that AI-discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods." Instead, he argues, AI is simply helping researchers discover more flaws, giving defenders an opportunity to patch them before criminals get there.

Garrity stopped well short of declaring the threat overblown forever, but he did suggest some of the rhetoric has outpaced reality. "The data so far, including Anthropic's own stalled disclosure ledger, suggests that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the evidence available today," he wrote. "That doesn't mean the risk is imaginary. It means the impact has been real but modest."
The Almighty Buck

eBay Reaches $56 Million Settlement With E-Commerce Newsletter Writers It Terrorized In 2019 (techcrunch.com) 49

eBay and several former executives have agreed to pay $56 million to Ina and David Steiner, the newsletter writers targeted in a 2019 corporate harassment campaign that involved threats, surveillance attempts, and deliveries of live insects and other disturbing items. The settlement closes the couple's civil case after seven former employees pleaded guilty to criminal charges related to the scheme. TechCrunch reports: Ina and David Steiner, a married couple and the co-authors of EcommerceBytes, inspired the ire of high-level eBay executives after occasionally criticizing the company in their newsletter. In 2019, a plot was concocted to intimidate the couple into halting their negative coverage. Executives used sock puppet social media accounts to harass the couple, while also sending them anonymous threatening letters and bizarre items in the mail -- including live spiders and cockroaches, pornographic magazines, a bloody pig mask, a funereal wreath, and a book about surviving the death of a spouse. According to previously released court documents, a plan that was attempted but never successfully carried out involved affixing a GPS tracking device to the couple's car. Yet another internally broached plan involved sending a "Samoan gang" to the Steiners' home.

The settlement this week resolves a 2021 civil case brought by the couple against eBay. The law office representing the Steiners writes that the settlement includes $46.15 million paid to the couple by eBay itself, as well as $2 million from former eBay executive CEO Devin Wenig. Additionally, $500,000 will be paid out to the couple from former eBay executive Wendy Jones, as well as $50,000 from former eBay executive Steve Wymer. Additional funds are being paid to various non-profits. In 2022, seven former eBay employees were criminally charged and pled guilty in relation to the plot, including the company's former security chief, James Baugh -- who was sentenced to nearly five years in prison. Others indicted by the U.S. Department of Justice include David Harville, Brian Gilbert, Stephanie Popp, Stephanie Stockwell, Philip Cooke, and former eBay contractor Veronica Zea.

The Courts

Judge Blocks First State Law That Would Have Banned Prediction Markets (arstechnica.com) 52

An anonymous reader quotes a report from Ars Technica: Minnesota, the first US state to prohibit prediction markets, was prevented from enforcing the law by a federal court ruling just days before the ban was scheduled to take effect. But while Minnesota was stopped from enforcing a total ban, the state may ultimately be allowed to prohibit some types of prediction-market wagers. The Trump administration and the two largest prediction markets -- Kalshi and Polymarket -- sued Minnesota after the state enacted the law in May. The cases were consolidated, and a ruling (PDF) issued yesterday imposed a preliminary injunction blocking the law that was scheduled to take effect on August 1.

Minnesota lawmakers saw prediction markets as indistinguishable from gambling, but the US Commodity Futures Trading Commission (CFTC) argues it has exclusive authority to regulate the platforms under federal law. One of the primary legal questions is whether event contracts are "swaps," which are regulated by the CFTC. Swaps are defined broadly in US law to include contracts in which payment "is dependent on the occurrence, nonoccurrence, or the extent of the occurrence of an event or contingency associated with a potential financial, economic, or commercial consequence." US District Judge Katherine Menendez in the District of Minnesota, a Biden appointee, said Minnesota's total ban on prediction markets is likely to violate US law because many trades on Kalshi and Polymarket are swaps.

Menendez wrote: "Specifically, it appears that whether the Minnesota statute is expressly preempted turns on whether the state law attempts to regulate trades in event contracts that qualify as "swaps" within the meaning of the CEA [Commodity Exchange Act]. And there are several examples of event contracts hosted by Kalshi and Polymarket US that fit that definition because they concern the occurrence of events with clear potential economic, financial, or commercial consequences that are neither remote or unattenuated. Kalshi and Polymarket US are designated contract markets, so the CFTC has exclusive jurisdiction to regulate transactions involving those 'swaps.'"

Menendez said the CFTC, Kalshi, and Polymarket met their burden of showing they are likely to succeed on the merits, so she issued "a preliminary injunction barring enforcement of Minnesota's prediction market statute until a final decision on the merits is reached." But she said Minnesota may be able to prohibit some types of event contracts offered on Kalshi and Polymarket because not all of them appear to meet the definition of swaps. For example, Menendez doesn't think prediction-market bets on the outcome of Love Island USA meet the legal definition of swaps. Minnesota could continue litigating the case in district court or ask a federal appeals court to overturn the preliminary injunction.

Privacy

DEF CON Bans Meta-Style 'Pervert Glasses' (theregister.com) 84

DEF CON has banned "Meta-style glasses with recording capabilities," with no exceptions being made even for those with prescription versions. "Be sure to pack non-violating eyewear if you need them," DEF CON said. The Register reports: [The conference's official photo policy] has not been updated since 2023, predating the recent growth of camera-equipped eyewear developed by Meta with EssilorLuxottica under its Ray-Ban and Oakley brands. It states that public photography is permitted but with several caveats that essentially prohibit capturing the image of anyone, except on-stage speakers, unless the photographer obtains consent from the subject(s). "Love to see a 'no pervert glasses' policy at DEF CON," said EFF director of cybersecurity Eva Galperin.
Privacy

GrapheneOS Defends Data-Wiping Function That Blocked US Border Search (pcmag.com) 180

GrapheneOS is defending its duress-password feature after an environmental activist used it to wipe his Pixel phone during a U.S. Customs search and was later indicted for allegedly destroying property under government control. The nonprofit says the operating system is "completely legal," cannot recover the erased data, and should not be weakened with encryption backdoors. Meanwhile, the activist faces up to five years in prison if found guilty. PCMag reports: In a post on Saturday, the Canadian nonprofit behind the operating system, the GrapheneOS Foundation, explained that the software offers a range of features to prevent data extraction. For example, one safeguard is the "auto-reboot timer" that'll reboot a locked device after a set period of time to put the data at rest, leaving all files inside encrypted.

The group's post subtly suggests that GrapheneOS phones can withstand law enforcement searches without requiring users to resort to a duress password. "People should carefully consider how to use it in an actual duress situation where there can be physical or legal consequences for wiping the device," the nonprofit wrote. "GrapheneOS doesn't require it to protect data from being extracted from the device, but it takes recovering it completely off the table even with the PIN/password for each profile on the device."

On X, the nonprofit has also said it can do nothing to help US law enforcement recover data from Tunick's phone. "Data cannot be recovered after the key derivation material is reliably wiped. It's not possible and there's nothing we can do to assist with it," the group wrote. "Similarly, it's not possible to assist with bypassing encryption because the hardware and software has been designed to prevent it."

Slashdot Top Deals