Security

More Than 30 Minnesota Water Systems Targeted In Cyberattack (fox9.com) 16

jrnvk shares a report from KMSP: Minnesota IT Services reports that a "coordinated cyberattack" targeted technology at more than 30 community water systems between Sunday, July 26 and Monday, July 27. The state has activated its cybersecurity incident response capabilities to respond to the attacks.

On Monday and Tuesday, FOX 9 reported on notices from four cities that had disclosed the attacks: Plymouth, South St. Paul, Maple Plain, and Braham. All four cities said the impacts of the attacks were limited or mitigated and residents could continue normal water use. The Minnesota Department of Health is not aware of any municipality asking residents to alter their drinking water use as a result of the attacks.

State officials are working with federal and private-sector partners to investigate the attacks, support the affected communities, and strengthen the security of Minnesota's critical infrastructure.

Robotics

Trump Administration Bans New Chinese Humanoid Robots (bbc.com) 58

The Trump administration has banned newly authorized foreign-made humanoid and four-legged robots, along with power inverters, citing "unacceptable risks" to the country's national security. FCC chairman Brendan Carr said the agency was doing its part "to secure America's critical supply chains." The BBC reports: The FCC has added the items to its Covered List -- a register of goods and services that are deemed a risk to US national security. The ban applies to new foreign-produced advanced robotic devices and power inverters and does not prevent the sale or import of any existing models that had been previously authorized by the FCC.

The FCC cited concerns that the use of foreign-made inverters could allow overseas firms to turn them off, steal data, facilitate remote access and surveillance by "foreign government actors, or be otherwise exploited through a cyberattack." It added that the use of robots made outside the US could allow "malign actors to surveil Americans, enhance the capabilities of foreign intelligence services, or to remotely commandeer the robots."

Bug

AI-Found Bugs Aren't Proving Any Easier to Exploit Despite the Hype 54

AI-assisted vulnerability discovery has yet to produce the expected surge in real-world attacks: VulnCheck found that only 14 of 1,061 attributed discoveries, or 1.3 percent, had been exploited, which is "almost identical to the rate across all vulnerabilities in VulnCheck's dataset," reports The Register. "That's a far cry from the narrative that frontier AI is dramatically tilting the balance in attackers' favor by churning out instantly weaponizable bugs." The findings suggest AI is currently better at increasing the volume of bugs found than making them easier to weaponize. From the report: The report takes particular aim at Anthropic's much-publicized Project Glasswing, unveiled in April with warnings that AI-assisted vulnerability discovery could allow attackers to hijack systems, disrupt operations, or steal data. Claude Mythos may have identified 23,019 vulnerability candidates, but there's remarkably little public evidence showing what became of most of them. VulnCheck notes that only 126 have been published as CVEs, that just one has been confirmed exploited in the wild, and that Anthropic's public disclosure record has seen little movement since Project Glasswing launched.

But that doesn't mean AI-assisted vulnerability research has failed, according to Patrick Garrity, security researcher at VulnCheck. "AI-assisted vulnerability discovery clearly has value for both attackers and defenders," Garrity wrote. "The data does not suggest that AI-discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods." Instead, he argues, AI is simply helping researchers discover more flaws, giving defenders an opportunity to patch them before criminals get there.

Garrity stopped well short of declaring the threat overblown forever, but he did suggest some of the rhetoric has outpaced reality. "The data so far, including Anthropic's own stalled disclosure ledger, suggests that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the evidence available today," he wrote. "That doesn't mean the risk is imaginary. It means the impact has been real but modest."
The Almighty Buck

eBay Reaches $56 Million Settlement With E-Commerce Newsletter Writers It Terrorized In 2019 (techcrunch.com) 35

eBay and several former executives have agreed to pay $56 million to Ina and David Steiner, the newsletter writers targeted in a 2019 corporate harassment campaign that involved threats, surveillance attempts, and deliveries of live insects and other disturbing items. The settlement closes the couple's civil case after seven former employees pleaded guilty to criminal charges related to the scheme. TechCrunch reports: Ina and David Steiner, a married couple and the co-authors of EcommerceBytes, inspired the ire of high-level eBay executives after occasionally criticizing the company in their newsletter. In 2019, a plot was concocted to intimidate the couple into halting their negative coverage. Executives used sock puppet social media accounts to harass the couple, while also sending them anonymous threatening letters and bizarre items in the mail -- including live spiders and cockroaches, pornographic magazines, a bloody pig mask, a funereal wreath, and a book about surviving the death of a spouse. According to previously released court documents, a plan that was attempted but never successfully carried out involved affixing a GPS tracking device to the couple's car. Yet another internally broached plan involved sending a "Samoan gang" to the Steiners' home.

The settlement this week resolves a 2021 civil case brought by the couple against eBay. The law office representing the Steiners writes that the settlement includes $46.15 million paid to the couple by eBay itself, as well as $2 million from former eBay executive CEO Devin Wenig. Additionally, $500,000 will be paid out to the couple from former eBay executive Wendy Jones, as well as $50,000 from former eBay executive Steve Wymer. Additional funds are being paid to various non-profits. In 2022, seven former eBay employees were criminally charged and pled guilty in relation to the plot, including the company's former security chief, James Baugh -- who was sentenced to nearly five years in prison. Others indicted by the U.S. Department of Justice include David Harville, Brian Gilbert, Stephanie Popp, Stephanie Stockwell, Philip Cooke, and former eBay contractor Veronica Zea.

The Courts

Judge Blocks First State Law That Would Have Banned Prediction Markets (arstechnica.com) 46

An anonymous reader quotes a report from Ars Technica: Minnesota, the first US state to prohibit prediction markets, was prevented from enforcing the law by a federal court ruling just days before the ban was scheduled to take effect. But while Minnesota was stopped from enforcing a total ban, the state may ultimately be allowed to prohibit some types of prediction-market wagers. The Trump administration and the two largest prediction markets -- Kalshi and Polymarket -- sued Minnesota after the state enacted the law in May. The cases were consolidated, and a ruling (PDF) issued yesterday imposed a preliminary injunction blocking the law that was scheduled to take effect on August 1.

Minnesota lawmakers saw prediction markets as indistinguishable from gambling, but the US Commodity Futures Trading Commission (CFTC) argues it has exclusive authority to regulate the platforms under federal law. One of the primary legal questions is whether event contracts are "swaps," which are regulated by the CFTC. Swaps are defined broadly in US law to include contracts in which payment "is dependent on the occurrence, nonoccurrence, or the extent of the occurrence of an event or contingency associated with a potential financial, economic, or commercial consequence." US District Judge Katherine Menendez in the District of Minnesota, a Biden appointee, said Minnesota's total ban on prediction markets is likely to violate US law because many trades on Kalshi and Polymarket are swaps.

Menendez wrote: "Specifically, it appears that whether the Minnesota statute is expressly preempted turns on whether the state law attempts to regulate trades in event contracts that qualify as "swaps" within the meaning of the CEA [Commodity Exchange Act]. And there are several examples of event contracts hosted by Kalshi and Polymarket US that fit that definition because they concern the occurrence of events with clear potential economic, financial, or commercial consequences that are neither remote or unattenuated. Kalshi and Polymarket US are designated contract markets, so the CFTC has exclusive jurisdiction to regulate transactions involving those 'swaps.'"

Menendez said the CFTC, Kalshi, and Polymarket met their burden of showing they are likely to succeed on the merits, so she issued "a preliminary injunction barring enforcement of Minnesota's prediction market statute until a final decision on the merits is reached." But she said Minnesota may be able to prohibit some types of event contracts offered on Kalshi and Polymarket because not all of them appear to meet the definition of swaps. For example, Menendez doesn't think prediction-market bets on the outcome of Love Island USA meet the legal definition of swaps. Minnesota could continue litigating the case in district court or ask a federal appeals court to overturn the preliminary injunction.

Privacy

DEF CON Bans Meta-Style 'Pervert Glasses' (theregister.com) 69

DEF CON has banned "Meta-style glasses with recording capabilities," with no exceptions being made even for those with prescription versions. "Be sure to pack non-violating eyewear if you need them," DEF CON said. The Register reports: [The conference's official photo policy] has not been updated since 2023, predating the recent growth of camera-equipped eyewear developed by Meta with EssilorLuxottica under its Ray-Ban and Oakley brands. It states that public photography is permitted but with several caveats that essentially prohibit capturing the image of anyone, except on-stage speakers, unless the photographer obtains consent from the subject(s). "Love to see a 'no pervert glasses' policy at DEF CON," said EFF director of cybersecurity Eva Galperin.
Privacy

GrapheneOS Defends Data-Wiping Function That Blocked US Border Search (pcmag.com) 159

GrapheneOS is defending its duress-password feature after an environmental activist used it to wipe his Pixel phone during a U.S. Customs search and was later indicted for allegedly destroying property under government control. The nonprofit says the operating system is "completely legal," cannot recover the erased data, and should not be weakened with encryption backdoors. Meanwhile, the activist faces up to five years in prison if found guilty. PCMag reports: In a post on Saturday, the Canadian nonprofit behind the operating system, the GrapheneOS Foundation, explained that the software offers a range of features to prevent data extraction. For example, one safeguard is the "auto-reboot timer" that'll reboot a locked device after a set period of time to put the data at rest, leaving all files inside encrypted.

The group's post subtly suggests that GrapheneOS phones can withstand law enforcement searches without requiring users to resort to a duress password. "People should carefully consider how to use it in an actual duress situation where there can be physical or legal consequences for wiping the device," the nonprofit wrote. "GrapheneOS doesn't require it to protect data from being extracted from the device, but it takes recovering it completely off the table even with the PIN/password for each profile on the device."

On X, the nonprofit has also said it can do nothing to help US law enforcement recover data from Tunick's phone. "Data cannot be recovered after the key derivation material is reliably wiped. It's not possible and there's nothing we can do to assist with it," the group wrote. "Similarly, it's not possible to assist with bypassing encryption because the hardware and software has been designed to prevent it."

Privacy

Tons of Peoples' Claude Chats and Creations Are Exposed On Google (404media.co) 34

An anonymous reader quotes a report from 404 Media: Claude is exposing a wealth of users' chats and creations in Google search results, meaning anyone can dig through conversations or other material that people used Claude to make but may not have realized were publicly available for strangers to see. The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples' addresses

Like other chatbots, Claude lets people share their conversations with others by creating a publicly accessible link of the chat. People may do this to send the full text of a conversation to their friends or coworkers in a group chat, for example. But they may not realize Google is also surfacing these links in search results, making them available to essentially anyone. [...] Claude users can change their privacy and sharing settings to make their chats no longer publicly accessible.

Crime

A Missing Underscore Sent Innocent Man To Prison For 18 Months (arstechnica.com) 209

An anonymous reader quotes a report from Ars Technica: One missing underscore in a Skyrim-themed username put an innocent Nova Scotia man in prison for 18 months. A 2018 child-luring investigation, which began in Madison, Wisconsin, and eventually extended to Halifax, Canada, was based on a false premise. Police were looking for a man using the Kik messaging service under the name "fus__ro_dah" (two underscores after "fus"), but they accidentally requested records for the username "fus_ro_dah" (one underscore after "fus"). This one-character difference led them not to the perpetrator but to a Canadian man named Brandon Klayme. (Ars readers may recognize "fus ro dah" as the Unrelenting Force "dragon shout" from The Elder Scrolls V: Skyrim.)

Despite finding no evidence of the crime on his digital devices, Canadian police arrested Klayme in 2020 on child sex abuse charges. He was convicted after a trial in 2023 and sentenced in 2024 to 18 months in prison. He served the full term. Even after release, Klayme continued to fight his conviction. In the process of preparing his appeal, the username mistake that led to all these years of disruption was finally discovered. On Thursday, the Nova Scotia Court of Appeal overturned Klayme's conviction, writing: "Mr. Klayme is factually innocent of the offences. He should never have been charged, let alone convicted." [...] As the court puts it, "Although the information about the usernames was available at the time of the trial, there is no evidence confirming or explaining how it went unnoticed."

Movies

2.1 Million People View Leaked 'Odyssey' Bootleg on X (variety.com) 66

Variety reports: "The Odyssey" leaks have begun, as a high-quality bootleg of the film reached millions of people on X thanks to a viral tweet on July 25. At 2:25 p.m. PT, a post on X reading "Someone uploaded 'The Odyssey' full movie on X. Can you believe it?" amplified a message from a now-suspended account. The message included a high-quality version of the film, as confirmed by Variety, and climbed to over 2.1 million views within two and a half hours. By that time, the streaming film was replaced by a takedown notice, and then the account was suspended...

As of July 26, a few clones of the bootlegged film are available on X, but they've been mostly flooded away by mislabeled files promising "The Odyssey" but actually showing a Rickroll, the longtime internet prank of tricking people into watching the music video for Rick Astley's 1987 song "Never Gonna Give You Up."

The article notes the leak "certainly doesn't seem to have hurt the film's still-surging box office in its second weekend, during which it earned another $87 million," or lessened demand for Imax 70 mm tickets.
EU

'Inside the Dystopian World of Germany's Free Speech Crackdown' (yahoo.com) 222

Thousands of Germans have been threatened with fines or prison sentences for social media posts, reports The Telegraph, calling the country's political speech laws "unusually stringent for an EU member state." One German had his home raided for calling a minister a "Schwachkopf [dummy]" while another was fined €2,000 (£1,700) for calling Friedrich Merz a "lying Fritz" under a law that, critics claim, makes it effectively illegal to make fun of politicians. The number of investigations under Section 86a, the Nazi symbols ban... has more than doubled over the past decade according to official police statistics. Investigations into the "political insult" law also reached record levels in 2025. The surge in cases is so vast that the UN has launched an investigation into free speech violations in Germany, a step typically reserved for dictatorships and banana republics...

In one recent case, a pensioner was investigated under Section 188 for posting "Pinocchio is coming" on Facebook, after he learnt Friedrich Merz, the chancellor, was visiting his hometown... The case was dropped after the story caused an outcry in Germany, and police have since clarified that calling the chancellor Pinocchio is not a crime... In November 2024, police in Bavaria raided the home of another pensioner because he called Robert Habeck, the then vice-chancellor of Germany, a "schwachkopf", or dummy. The raid was reportedly launched after Mr Habeck personally filed a criminal complaint against the pensioner. Prosecutors eventually dropped the investigation after deciding that the insult "dummy" was not of "sufficient weight" to merit criminal charges.

While such cases might seem like bizarre outliers, there are plenty of others. In 2021, police raided a man's apartment in Hamburg after he told a senator "you're such a d---," and this year a resident was fined €2,000 for calling Mr Merz a "lying Fritz". Official figures show a record 4,792 Section 188 cases were filed in Germany in 2025, with the numbers rising by nearly 85 per cent between 2023 and 2025.

The article notes both left- and right-leaning free speech activists in Germany are calling for some of the stricter laws to be scrapped. And it adds that the uproar "bears some similarities to the free speech debate in Britain, where citizens have had a knock on the door from police over opinions posted online."
Privacy

Apple's Smart Glasses Delayed, As Engineers Consider Privacy Concerns (digitaltrends.com) 47

Digital Trends reports: Apple could unveil its first smart glasses at WWDC in June 2027, followed by a consumer release toward the end of the year, according to Bloomberg... Part of the delay reportedly stems from Apple's engineering and marketing teams spending more time refining the product and deciding how to address the privacy concerns...

Apple has reportedly considered glasses without cameras, as well as a version where the cameras can analyse the surroundings but cannot record photos or video. Such an approach could still support object recognition, navigation, Siri, calls, and music playback. The company is also expected to favor on-device processing, avoid facial recognition, keep recordings away from AI training, and use a more visible light around the camera.

DRM

Google's Anti-search-scraping Lawsuit Dismissed (computerworld.com) 22

A U.S. district court "has dismissed Google's case against SerpApi over that company's scraping of search results to train AI models," reports Computerworld. Google had claimed that it was protecting copyright holders — and that SerpApi's actions breached America's Digital Millennium Copyright Act (DMCA): [Google] made two claims: first, that no person shall circumvent a technological measure that effectively controls access to a work protected under this title, and second that no person shall manufacture, import, offer to the public, provide, or otherwise traffic in any technology, product, service, device, or component protected by the Act. SerpApi claimed that the URLs and other links that were being served by Google did not in themselves entail copyright and the judge agreed. In her judgment, she said that there was no indication that the copyright holders had authorized Google to take action against SerpApi.

The case is not completely over as the judge has given Google 21 days to amend its complaint to demonstrate that it was acting on behalf of the copyright owners.

SerpApi's CEO reacted to the court's ruling as "a win not just for SerpApi, but for all who depend on an open internet. We're pleased that the court rejected Google's attempts to expand the DMCA to assert control over access to public pages. The internet's founding principle — open access to usable information — is essential to driving innovation and ensuring everyone benefits from the promise of data. SerpApi will continue supporting developers, AI companies, researchers, and businesses that rely on access to public search information."

Some analysis from Daring Fireball blogger John Gruber: I've come around on SerpApi in the last few months. My initial take was that it surely must be illegal for a company to scrape Google's search results and offer access to that data as an API. But I've come around to the argument that what SerpApi is doing to obtain Google search results is, well, exactly how Google scrapes the rest of the entire web to build its search index. It's all just scraping publicly accessible web pages. This December piece by Mike Masnick at Techdirt is what began to change my mind.
In fact, Masnick wrote, Google "built its entire business on scraping the web without asking permission first. And now it wants to use one of the most abused provisions in copyright law to stop others from doing something functionally similar to what made Google a tech giant in the first place."

Now Google is even getting heckled about the decision on social media. "If Google wants to refile the suit within the allowed 21 days, it has to admit that site owners have copyright protection of their work and THAT would open the door to them suing Google for scraping their content for AI Overviews."
Crime

Typo-Squatting Scammers Con South Carolina Town Out of $545K (wpde.com) 23

It started with some underground utility work for the South Carolina town of Surfside Beach (population: 4,155). "Public records confirm that a payment of $545,598.30 was issued," according to a local news station — but the CEO of Wildcat Contractors "stated that the account that received the money is a scammer account and that his company has an overdue invoice for underground utility work completed in Surfside Beach."

Yahoo picks up the story: After the payment issue surfaced, Wildcat said Surfside Beach sent over the email thread containing the payment confirmation. The company told WMBF it noticed multiple red flags in the chain. One involved an email address where "Wildcat" appeared with an extra "i." Another involved documents that the company said included a forged signature taken from a prior notarized document. Wildcat said the money was sent to a spoofing account claiming to be the contractor.
More local reports are unraveling what happened: According to the Wall Street Journal, the town's finance director said a town employee called Wildcat's project manager on March 13, the day the payment was sent. The project manager referred the caller to [Wildcat CEO] Bowker. The town then called Bowker's mobile phone and left a voicemail about the ACH transfer. Bowker told the Wall Street Journal she does not recall the voicemail but acknowledged she may have missed it.
Now a new report released by a law firm hired by the town to investigate "shows it did make an attempt to verify before sending $545,000 to a fraudulent bank account," according to local news reports: According to the report, the town sent an email to Wildcat's legitimate email domain on March 13 requesting a callback for verbal verification before sending the payment. Surfside received a response to that email with a phone number, though it remains unclear whether that response came from a real Wildcat employee or from the scammers. The report found that the fake town domain was used in communications between both parties throughout the process, which the law firm overseeing the investigation said was likely created to facilitate the fraud and delay its discovery.
That seems to be the case in a nutshell: Investigators determined the fraudsters used spoofed and typo-squatted email domains, including surfsidesbeach.org, to impersonate town officials and redirect the payment. The fraudulent domain was created March 9 and was used to help conceal the scheme, according to investigators. Town officials said they are continuing to work with the FBI, South Carolina Law Enforcement Division, and their insurance partners to recover the funds.
"The town has also implemented additional security measures to strengthen payment verification procedures and reduce the risk of similar incidents."
EU

Trump Threatens New Tariffs Against EU Over Google Fine 173

President Trump threatened a "substantial" new tariff on the European Union after Brussels fined Google more than $1 billion over alleged illegal trade practices. "The European Union will pay a very big price for this illegal and highly unethical conduct, which I have consistently warned them about," Trump wrote on Truth Social. "The penalties will be entirely reversed and, we anticipate, a substantial TARIFF to be placed on them at the earliest possible moment." Politico reports: The president's threat came just a day after U.S. Trade Representative Jamieson Greer warned that the EU's action against Google -- two fines totaling over $1 billion -- could imperil the bloc's relationship with the White House. At risk: the Turnberry deal, which Trump and European Commission President Ursula von der Leyen signed last fall, that capped U.S. tariffs on EU exports at 15 percent. [...] But the president's social media post could signal a coming breach. "The United States of America is not a 'PIGGYBANK' for Europe, nor will we allow it to be!" Trump wrote.

Slashdot Top Deals