The Military

Russia Hacks Doorbell Cameras To Spy On NATO Bases (yahoo.com) 45

Dutch intelligence agencies say Russian hackers have been hijacking unsecured internet-connected cameras, including likely doorbell and security cameras, to spy on NATO military bases and transport routes used to move weapons to Ukraine. "Organisations with IP [internet protocol] cameras on these routes have now been warned so that they could take action," said the AIVD domestic security and MIVD military intelligence agencies. Targeted NATO member states include the Netherlands and Ukraine. The Telegraph reports: While the intelligence agencies did not specify the type of cameras hacked, the doorbell systems are frequently used by people to monitor their property from mobile phones. Hackers then use readily available apps to scan for devices that might be accessible. The Dutch investigation found that many of the cameras were unsecured, and "often have standard passwords, outdated firmware and standard configurations." They said: "When the IP camera is identified, the malicious party can attempt to access the IP camera via the internet. This is often relatively easy, because many IP cameras connected to the internet are insufficiently secure."

[...] The practice is now considered easier and cheaper than using drones and satellites to gather intelligence. It also aids operational surprise because most camera owners are blissfully unaware their devices have been penetrated by hackers. Ground-based cameras offer a unique perspective on the terrain, which isn't the case with conventional aerial-based spy kit.

Microsoft

Microsoft to Retire OWA Light Client In Exchange Server (bleepingcomputer.com) 31

Microsoft plans to disable and remove OWA Light, the lightweight Outlook Web Access client for Exchange Server, in an upcoming update expected in August 2026. The company says retiring the two-decade-old legacy interface will reduce attack surface and engineering complexity, pushing users to the modern Outlook on the web experience instead. BleepingComputer reports: "OWA Light was an important compatibility experience when the web needed it. Today, the full Outlook on the web experience is the right place for us to focus," the Exchange Team said on Wednesday. "Retiring OWA Light will help reduce legacy surface area, simplify ongoing engineering work, and allow us to continue improving the experience customers use every day."

Microsoft introduced OWA Light roughly two decades ago as an alternative to OWA Premium, offering a simplified web interface for systems that didn't have Internet Explorer 6 or later installed or ran older web browsers. At the time, the company said that OWA Light offered a cleaner look, faster logon times on low-bandwidth Internet connections, and worked in locked-down browser modes (such as kiosks).

Microsoft deprecated OWA Light as of August 19, 2024, and announced this week that the OWA Light experience will likely be removed from Exchange Server (on-premises) next month. "In an upcoming Exchange Server update (estimated in August 2026), we plan to disable and remove the OWA Light experience. After that change is introduced, users will no longer be able to choose or be redirected to OWA Light and should use the modern Outlook on the web experience instead."

AI

Lawmakers Probe Growing Use of Chinese AI Models In US Companies (cnbc.com) 109

U.S. lawmakers are probing the growing use of Chinese AI models by American companies, citing concerns over censorship, security risks, and whether U.S. firms are turning to cheaper foreign models because domestic alternatives are too costly or restricted. The investigation is specifically looking at companies such as Cursor and Airbnb. "The growing use of Chinese AI models by U.S. companies raises serious concerns," a State Department spokesperson told CNBC. Those "AI models are designed to advance Beijing's narratives, censor dissent, and reflect CCP ideology and values." CNBC reports: The House Committee on Homeland Security and the House Select Committee on China said in April they will jointly investigate the growing adoption of Chinese-developed AI models. An initial step in the probe was for the chairmen of those committees to send letters to Cursor and Airbnb, over their "use of or exposure to these risks" through AI developed in China. "The Chinese Communist Party is no longer just nipping at our heels in artificial intelligence; it is racing to close the gap in some of the exact capabilities that will shape the future of cybersecurity," Andrew Garbarino, chairman of the U.S. House Committee on Homeland Security, told CNBC. "Recent reporting that a Chinese open-weight model can match leading U.S. models in certain vulnerability discovery and cybersecurity tasks is highly alarming," said Garbarino.

While some government departments have banned the usage of Chinese AI models including DeepSeek, adoption of them by U.S. companies is not prohibited. Tech chiefs, including crypto company Coinbase's Brian Armstrong and AI startup Lindy's Flo Crivello, have been publicly touting the use of models from China to reduce costs. Cursor, which will be acquired by Elon Musk's SpaceX for $60 billion, built its Composer 2 model using Chinese AI model Kimi, which was developed by Moonshot AI. Alongside focusing on the rise of Chinese AI models, the ongoing joint House Committees' investigation is also looking into whether the U.S. is doing enough to tackle their rise. "The Committees are also examining whether the United States has a sufficient open-weight AI strategy to ensure American companies and cyber defenders are not forced to choose between expensive or restricted U.S. models and cheap, capable PRC-developed alternatives," a Committee aide, who asked not to be named as they were not authorized to discuss the ongoing probe, told CNBC.

[...] The administration could consider the use of federal procurement bans, which would include restricting government agencies and private companies that serve the U.S. government from using Chinese AI models, Kyle Chan, fellow in the John L. Thornton China Center at think tank Brookings, told CNBC. "However, it's ultimately impossible to ban China's open-source AI models because their model weights are available freely on the internet," Chan added. "This could enter into first amendment speech issues." [...] Another [approach] could be disseminating findings about risks and vulnerabilities associated with Chinese AI models to U.S. companies. "Regardless, I do expect both the Executive Branch and Congress to communicate their interest not to see U.S. companies adopting these models," [said Daniel Remler, senior fellow, technology and national security program at think tank the Center for a New American Security (CNAS), told CNBC].

Cellphones

Parents' Phone Addiction Affects Bond With Kids, New Study Finds (bloomberg.com) 52

An anonymous reader quotes a report from Bloomberg: Parents' attachment to screens and smartphones can have negative, long-lasting developmental and psychological effects on their children, according to new research. Caregivers who mismanage their devices can both exacerbate "insecure attachment" and make healthy relationships more anxious and avoidant for children, according to the findings, which were published last month in Frontiers in Psychology, a peer-reviewed journal. The study, which surveyed 600 minors in the US from 12 to 17 years old, found that kids reported feeling marginalized or neglected by parents glued to their screens. "A child with insecure attachment may lack confidence or display a lower sense of self; demonstrate difficulty with interpersonal relationships and intimacy; and possess an unwillingness to take risks necessary to achieve success," reports Bloomberg, citing one of the study's researchers.

This type of behavior has become normalized: 2024 Pew data found that nearly half of U.S. teens say their parents are at least sometimes distracted by phones during interactions. "When parents were asked about their own behavior, far fewer said this was an issue," the report adds. "Still, earlier Pew data from 2020 found most parents feel their phones can interfere with quality family time, with 68% reporting being 'at least sometimes' distracted by them.
AI

Big Companies That Invest Heavily in AI Also Hire More People, Report Suggests (techcrunch.com) 29

"Companies spending heavily on AI are growing headcount faster, even in the entry-level roles that many fear are doomed," writes TechCrunch. That's the conclusion of new report tracking AI spending from Ramp's corporate card/bill pay data as well as Revelio Labs' workforce records from 21,599 U.S. firms: According to the report, "high-intensity adopters" — firms that spend on average $30 per employee per month on AI in the first three months — saw headcount increase 10.2%. Headcount also rose across functions, including engineering, sales, administration, customer service, finance, marketing, and scientist roles. The strongest job growth among high-intensity adopters was in the information sector, which includes software, internet, media, and tech-adjacent firms.

Despite these positive signals, the data isn't as rosy as it seems. It skews heavily toward tech-forward, knowledge-work firms — ones that might have VC-backing and are growing fast anyway, making it difficult to say whether AI is contributing to the hiring or just showing up at companies that are expanding anyway. "This paper does not show that AI universally creates jobs," the paper's authors admit, "but it does counter claims that AI will lead to broad job losses."

It also counters claims that AI is killing all junior jobs. Recent research from Goldman Sachs found that AI has already erased about 16,000 net jobs per month over the past year, with Gen Z and entry-level workers taking the brunt of the burden. But in tech-forward firms, the report finds that entry-level headcount actually rose by 12%... "For software and technology firms, AI can make core output cheaper or faster to produce: writing code, debugging, building internal tools, producing technical documentation, and supporting product development," the report reads. "Lower production costs in these workflows can raise the return to expanding the whole firm, not just the engineering team."

But companies that buy subscriptions and run pilots, yet did not go on to make sustained investments, don't tend to see any gains in headcount, per the report. That sets up the potential for a widening gap between firms that have the resources — like capital, technical staff, founder networks, and management bandwidth — to turn AI adoption into actual business gains and those that are stuck experimenting with subscriptions. In other words, this report suggests that firms that already have the resources are the ones that will see the largest gains.

CNBC argues another AI "narrative" was challenged this week: that open source can't make money. "The assumption was that giving your model away for free meant no business. That's breaking too, as open-model companies start posting real revenue and enterprises move from renting AI to running their own."
Crime

Windows 11 Identifier Code Used to Arrest 19-Year-Old Over Alleged Ransomware Spree (tomshardware.com) 69

America's Justice Department and FBI teamed joined Finland's National Bureau of Investigation to arrest a teenager they say is part of one of the world's biggest cybercrime syndicates, reports Tom's Hardware. The "Scattered Spider" syndicate has extorted over $100 million in ransom payments, according to Department of Justice figures: 19-year-old Peter Stokes is a dual U.S.-Estonian citizen who was trying to board a flight to Japan from Helsinki, when law enforcement caught up with him. [T]he main criminal complaint against Stokes stems from a May 2025 attack on a luxury jewelry dealer based in the United States. The attackers apparently called the company's IT helpdesk using Google Voice, posing as employees. They were able to convince the help desk into resetting their credentials, which allowed them to infiltrate three accounts, two of which had admin privileges. From there, the group, allegedly including Stokes, stole important data and held the jeweler at ransom, demanding an $8 million payment in crypto. The company ultimately regained access to their infrastructure and avoided paying the ransom, but the operational disruption still caused a purported $2 million in losses. This served as the spark that led to Stokes' eventual arrest in Helsinki, as the prosecutors slowly followed the paper and digital trail laid by the attackers.

Microsoft played a key role in the process by providing GDID [Global Device Identifier] data to the FBI to help them apprehend the alleged criminal... [I]t's a unique identifier assigned to every Windows install that tracks device-specific telemetry. It's the reason why sometimes changing a major component in your PC can revoke your Windows license... [T]he court documents from the case reveal that Stokes used Windows, from which investigators were able to link his physical hardware to specific internet activity and locations... Stokes' web activity, videogame history, IP addresses, tool usage (including Ngrok), Azure status, and more were logged with timestamps, and were provided to the investigators by Microsoft...

Stokes was carrying two hard drives full of incriminating evidence with him when boarding his flight to Japan... His real identity has actually been known since 2024, but since he was a minor living across Estonia and the UAE at the time, he could only be monitored until the time was right.

The official criminal complaint even includes a selfie photo that Stokes posted on Snapchat (hiding his face behind dozens of hundred dollar bills). It then notes that behind Stokes the wallpaper, carpet, and furniture match New York's Empire Hotel — and that Stokes had visited the hotel's web site in Germany before then flying to New York...

"Following the arrest, Stokes was extradited to the U.S., where he appeared in front of a federal court in Chicago for the first time on June 30, 2026, and he remains in custody," adds Tom's Hardware.

"The accused is now awaiting trial, having been charged with conspiracy, cyber intrusion, and fraud..."
The Internet

GoDaddy Warns India's Crackdown on Fake Site Registrars Could Upend Internet Privacy Everywhere (reuters.com) 20

"The internet is filled with fakes," writes Gizmodo. "A court in India is setting out to address the problem by requiring more transparency from domain registrars to make it easier to crack down on fraud. And while the intentions might be good, Reuters is reporting that major American domain registrar GoDaddy is sounding the warning bells that the court's decision could fundamentally reshape the internet well beyond India's borders."

GoDaddy argues the move would even make the internet less safe, reports Reuters : [Online fraud] is a key challenge for Prime Minister Narendra Modi's government, which last year received 2.4 million complaints of alleged cyber fraud amounting to $2.4 billion. Starting in 2019, lawsuits were brought by dozens of Indian and global firms — Amazon against fake shopping sites trading on its name and McDonald's complaining against bogus sites offering franchises. [More than 20 companies filed a complaint, the article notes, including Microsoft.] In December, an Indian court blocked more than 1,100 such websites. The New Delhi judge however went further, ordering sweeping new measures that tech experts say have rewritten rules of internet governance: Domain sellers should not offer buyers free privacy protection by default, the buyer's details should be released to anyone with a "legitimate interest" within 72 hours, and website addresses that are variations of protected brand names must be prohibited.

U.S.-based GoDaddy has challenged the directives before a larger bench of judges at the Delhi High Court, according to a Reuters review of non-public filings. It says the ruling will affect legitimate businesses that have names similar to big brands. Stopping privacy-by-default features, GoDaddy said, will result in public disclosure of name, address, telephone and email of legitimate website owners, exposing them to "foreseeable privacy and security risks" such as stalking and harassment.

As domain names operate globally, not locally, the order could force GoDaddy to regulate website addresses across the world, it said. On the court's order imposing a 72-hour deadline on companies to provide registration details to anyone with "legitimate interest", GoDaddy argues it has no wherewithal to assess who has legitimate interest or not. The "commercially destabilising" directives may force domain name companies to "exit India", said one of GoDaddy's appeal documents that ran into 5,121 pages... GoDaddy rivals, Arizona-based Namecheap and Netherlands-based Hosting Concepts, have also challenged the New Delhi ruling, court records show, although Reuters could not ascertain details of their appeals...

GoDaddy argues that diluting the privacy feature will run contrary to India's data protection law and the European Union GDPR law which mandates a "privacy by default" approach. Farzaneh Badii, a New York-based researcher on internet governance, criticised the New Delhi ruling, noting that Europe redacted such details because publishing them had been abused by harassment and targeted phishing. "The people exposed will be journalists, activists, small business owners, and private individuals. The brand impersonators will not," she said...

While the sweeping December directives were issued by a court, they followed government's submissions, documents showed... The judges will hear the appeals on July 16.

GoDaddy manages 80 million domains and serves over 20 million users, the article points out, with annual revenue over $5 billion.
The Internet

Amazon Has Enough Satellites To Launch Its Starlink Competitor (theverge.com) 47

Amazon says its Leo satellite network now has enough spacecraft in orbit to begin limited commercial internet service, with 396 satellites providing "continuous service across initial latitudes." Early performance will likely be uneven, however, and well behind Starlink. "It'll be years before Amazon can boast similar performance numbers as it continues to launch a planned 3,232 Leo satellites," reports The Verge. From the report: SpaceX went live with its "Better than nothing beta" back in 2020 when it had almost 900 satellites operating in low-Earth orbit. It initially served a narrow band of users in the upper US and Canada, who complained about frequent service interruptions and high sensitivity to obstructions, with speeds between 50Mbps and 150Mbps, and latency from 20ms to 40ms. By 2022, the service and coverage areas had already dramatically improved. [...]

SpaceX currently has over 10,000 Starlink satellites in operation, providing robust internet connectivity on land, sea, and air in over 160 countries. Performance varies by the dish, service level paid for, time of day, and location of the user, but we're now talking 200Mbps median download speeds, 10Mbps to 40Mbps uploads, and latency hovering around 25ms.

Security

AI Agent Executes 'First' End-To-End Ransomware Attack 36

Sysdig says it has documented the first ransomware attack carried out end to end by an AI agent, which autonomously exploited exposed systems, stole credentials, established persistence, compromised a production database, and destroyed data. The research team named the attacker "JadePuffer" and said it gained initial access to an internet-facing Langflow instance by exploiting CVE-2025-3248. "The most striking characteristic, however, was the LLM's behavior," Sysdig director of threat research Michael Clark said in a blog post. An anonymous reader quotes an excerpt from The Register: JadePuffer's "self-narrating" payloads "contained natural language reasoning, target prioritization, and the kind of detailed annotations that human operators don't often write but LLM-generated code produces reflexively," Clark added. "The operation also adapted in real time, retrying failed steps within refined parameters. In one sequence, it went from a failed login to a working fix in 31 seconds." After exploiting CVE-2025-3248, a missing authentication vulnerability in Langflow that allows remote, unauthenticated attackers to execute arbitrary Python on the host, the AI agent began scanning for and collecting secrets, including LLM provider API keys, cloud credentials "with explicit coverage of Chinese providers" including Alibaba, Aliyun, Tencent, and Huawei, while also scanning for AWS, Azure and Google Cloud Platform, cryptocurrency wallets, and database credentials.

The AI also installed a crontab entry on the Langflow server to maintain persistence and call back to the attacker's infrastructure every 30 minutes. JadePuffer's intended target was a separate internet-exposed production server running a MySQL database and an Alibaba Nacos configuration service, we're told. Nacos is an open-source service-discovery and dynamic configuration platform developed by Alibaba and used in the cloud provider's microservices applications. The agent connected to the server's exposed MySQL port using root credentials, although Sysdig doesn't know how the attacker obtained them. These credentials weren't stolen from the victim's environment.

JadePuffer then attacked Nacos via multiple vectors including an authorization bypass flaw (CVE-2021-29441) and forging a valid JSON web token (JWT) using Nacos's default signing key. Additionally, using its root database access, the LLM injected a backdoor administrator into the Nacos backing database. It ultimately encrypted all 1,342 Nacos service configuration items using MySQL's built-in AES encryption function, and created an extortion demand, ransom note, Bitcoin payment address, and a Proton Mail contact [...]. However, according to the threat hunters, the victim can't recover the encrypted data, even if they paid the ransom demand, because the agent escalated "from row-level deletion to dropping entire database schemas, narrating its own targeting rationale," without backing up any of the encrypted data.
AI

Microsoft Slammed for Building Copyright-Infringing Supercomputer for OpenAI in New Court Filing (arstechnica.com) 88

The New York Times alleges Microsoft actively encouraged OpenAI to steal its copyrighted work, reports Ars Technica, citing a new (and heavily redacted) court filing Thursday: NYT's motion comes after the [U.S.] Supreme Court sided with Cox Communications in a case where Sony tried and failed to claim that Cox was contributing to music piracy as an Internet service provider, which set a new standard for contributory infringement. Moving forward, plaintiffs will have to prove that parties intentionally acted to induce illegal conduct. Recognizing that the legal precedent has changed, the NYT now wants to amend its complaint to align its contributory infringement claim against Microsoft with that new standard... A Microsoft spokesperson told Ars that the company views the amended complaint as "a last-ditch effort by the plaintiff to save its claim from unfavorable precedent set in other recent rulings..."

The updated complaint seeks to specify that [Microsoft's] supercomputer was tailor-made to help OpenAI infringe and allege that it was built for the explicit purpose of training AI on copyrighted works without permission. And as the NYT alleged, its articles were more heavily weighted by this system, as both firms hoped to train models on the highest-quality journalism possible, so that level of writing could be confidently mimicked in outputs. By building this "unusually complex" machine, Microsoft not only helped select the works that were infringed but also provided a means to seize copyrighted works without permission, the NYT alleged. "Microsoft specifically designed it for the purpose of using essentially the whole Internet — curated to disproportionately feature Times Works — to train the most capable LLM in history," the NYT alleged... Similarly as problematic for the NYT are hallucinations where Microsoft and OpenAI models falsely cite the NYT for content that they never published... "Users who ask a search engine what The Times has written on a subject should be provided with neither an unauthorized copy nor an inaccurate forgery of a Times article, but a link to the article itself," the NYT alleged...

In a statement provided to Ars, OpenAI spokesperson Drew Pusateri reiterated the AI firm's often-repeated claims that AI training on copyrighted works is indisputably fair use... OpenAI has argued that "ChatGPT is not a substitute for a Times subscription," the NYT reported, partly because "they transformed the material for a different use."

An OpenAI spokesperson told Ars Technica that OpenAI's models "empower innovation," while a New York Times spokesperson insisted that Microsoft "actively encouraged OpenAI to steal our copyrighted works... [O]ur core claims remain the same from the day we filed this lawsuit — that Microsoft and OpenAI stole millions of The Times's copyrighted works to compete with our products and illegally enrich themselves."

The article speculates that the case's most extreme outcome "could require OpenAI and Microsoft to wipe models and start over. The NYT has also asked for permanent injunctive relief to prevent future infringement, as well as extensive damages..."
The Almighty Buck

Are Checks Sent Through the Mail Vulnerable to Theft? (nytimes.com) 183

The New York Times tells the story of a 63-year-old retiree who wrote a check for several thousand dollaras to pay her taxes. But she discovered much later that her taxes were never paid because that check had been intercepted and then altered to be payable to someone else: In some cases, thieves may pilfer one or more checks from local mailboxes. Adam Rust, director of financial services for the Consumer Federation of America, said thieves sometimes "fish" for checks at free-standing drop boxes, using long tools with sticky pads on the ends to grab letters. In other cases, more sophisticated criminals may steal large batches of checks, copy them and then sell them on the internet. Often, the purloined checks are chemically altered in what's known as "check washing" to remove the name of the recipient. The thief replaces it with a fraudulent name, and often increases the amount of the check, before cashing or depositing it.
The 63-year-old retiree's bank told her she'd waited too long to recover the funds: Schwab's "security guarantee," outlined on its website , says that "Schwab will cover losses in any of your Schwab accounts due to unauthorized activity." But fine print at the bottom of the page notes that reimbursement "requires your timely reporting of unauthorized activity to Schwab," and that Schwab "will not be liable for additional or increased losses resulting from a failure to report unauthorized activity in a timely manner." It notes that more details are available in account agreements... Notify your bank as soon as possible, said Scott Anchin, senior vice president of strategic initiatives and policy at the independent bankers association. Banks generally allow at least 30 days and sometimes up to 90 days from the time your statement is made available to you to report suspected check fraud, he said.
So how can you avoid check fraud? Adam Rust, director of financial services for the Consumer Federation of America, just suggests that "No one should ever mail a check." If you must write a check, he said, try to deliver it in person or take it inside a post office to mail rather than relying on your own mailbox or public drop boxes. The American Bankers Association recommends using permanent "gel" ink pens when you do write checks to reduce the risk of tampering... And if you don't already, consider using your bank's online bill payment service.
The article notes that even the U.S. federal government "has been moving away from paper checks for things like benefit payments and income tax refunds, saying digital payment methods are more secure."
Science

Max Planck Slapped With Two Paper Retractions By Suspected Rogue Algorithm (science.org) 21

Max Planck won 1918's Nobel Prize for physics. Yet two of his papers were retracted — a move now being criticized by Yves Gingras, a historian of physics at the University of Quebec and Mahdi Khelfaoui, a fellow historian of science at UQ Trois-Rivières. Science reports: The papers, both quietly retracted in 2011, originally appeared in the early 1940s in Naturwissenschaften, a German journal now owned by publishing giant Springer Nature. After some sleuthing, Khelfaoui determined one of the Planck pieces, a philosophical essay from 1942 titled "Sinn und Grenzen der exakten Wissenschaft" ("Meaning and Limits of Exact Science"), about how to achieve certainty in scientific knowledge, had also appeared in two other journals and been reprinted twice in books. Repackaging the same work multiple times is considered "self-plagiarism" and frowned upon today — the practice produces copyright conflicts and inflates scholars' publication records. The Naturwissenschaften site gives "copyright violation" as the reason for the retraction.

Yet publishing identical material in multiple journals was widespread before the internet. "Science was more fragmented" then, Khelfaoui says. "You wanted different audiences ... to have access to your work." The practice was especially common for luminaries like Planck. Albert Einstein did the same (but escaped retractions). Springer Nature's "anachronistic" application of modern standards to a 1942 paper "distort[s] the historical record," Gingras and Khelfaoui argue in a preprint posted last month on arXiv. Any concerns about copyright violations are largely moot anyway: Because Planck died in 1947, his works are in the public domain in most countries.

Gingras was especially incensed that Springer Nature deviated from the normal practice of merely slapping the word RETRACTED across the digital version of the paper while still allowing scholars to read the text. Instead, the publisher posted a blank white page with the cryptic phrase, "This article has been withdrawn due to article violation." Springer Nature is nevertheless still selling the empty PDF for $39.95. Suzanne Scarlata, a chemist and biochemist at the Worcester Polytechnic Institute and editor-in-chief of The Science of Nature, as Naturwissenschaften is now known, had not heard about the retractions before being contacted for this story... Scarlata suspects Springer Nature's internal policing software removed the paper and posted the retraction notice unilaterally, without human supervision: "I think it just happened with their algorithm," she says. "It's a mistake they should probably rectify."

A second Planck paper was apparently removed because its response to a 1940 paper had used an identical title.

Thanks to our long-time Slashdot reader He Who Has No Name for sharing the article.
Hardware

A 25-Year-Old Blog Looks Back At 40 Years of Computing (markround.com) 79

Ancient Slashdot reader Mark Round writes: Longtime reader here (since mid-1999 -- Hot Grits! Oog the Caveman! Beowulf clusters!), and I can still remember posting back on Slashdot's own 5th anniversary. Time's rolled on: my own blog just turned 25, and it's now roughly 40 years since I first sat down at a computer. So I went digging through archive.org, old backups, and a box of ZIP disks, and wrote up a long look back at four decades of computing through the one website that's been my online home along the way.

It runs from my first 8-bit micro and a 1,200-baud modem through discovering the actual Internet at university (and burning far too many hours on Slashdot and sister sites like freshmeat.net), past gloriously pimped-out Enlightenment Linux desktops, all the way to the modern cloud-native world. Plenty of dodgy screenshots, terrible code, and fond memories of long-gone haunts like kuro5hin.org and Linux Coffee Talk along the way.

Security

29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests (thehackernews.com) 19

A 29-year-old bug in the Squid web proxy, dubbed Squidbleed and tracked as CVE-2026-47729, can let an authorized proxy user retrieve fragments of another user's cleartext HTTP requests, including credentials and session tokens. The security researcher who reported the flaw credited Anthropic's Claude Mythos Preview for the discovery. The Hacker News reports: Squid describes this as an attack by a trusted client: someone already permitted to use the proxy, not any random host on the internet. That matches Squid's usual home, shared networks like schools, offices, and public Wi-Fi. In those setups, the attacker is just another user of the same proxy. The leak also only reaches traffic that Squid can read. Normal HTTPS rides an opaque CONNECT tunnel, so Squid never sees inside it; the exposed traffic is cleartext HTTP, plus TLS-terminating setups where Squid decrypts and inspects. The attacker also needs the proxy to reach an FTP server they control on port 21. Both FTP and that port are on by default.

[...] If you patch, verify the fix, not just the version. Confirm the guard is in FtpGateway.cc, or check your distribution's backport, since distros ship their own builds (Debian packages Squid 5.7). The public thread is still inconsistent: maintainer Amos Jeffries first said Squid 7.6 carried the fix, then corrected that to 7.7, and on June 22 Debian's Salvatore Bonaccorso noted the referenced commit looks like it is already in 7.6. The fix is small, a null-terminator check before the vulnerable strchr calls, merged to the development branch in April and v7 in May. Squid 7.6 does separately patch CVE-2026-50012, an unrelated cache_digest heap overflow.

The cleaner move is the one the researchers recommend anyway: turn FTP off. Chromium dropped FTP years ago, and most networks carry almost none of it, so disabling it removes this attack surface for free, whatever build you run. The risk is real but bounded. SUSE rates it moderate, CVSS 6.5, and the vector explains the score: the attacker needs proxy access (low privileges), and the only impact is confidentiality, nothing on integrity or availability.

Social Networks

UK Considers Forcing Social Media Firms To Prioritize Trusted News (reuters.com) 134

An anonymous reader quotes a report from Reuters: Britain is considering forcing social media companies to prioritize what the government called trusted news sources as part of its broader push to tighten regulation of the sector. The culture department said on Monday it was considering requiring platforms such as Meta's Facebook, Alphabet-owned YouTube and TikTok to make content from public service media -- including the BBC, ITV and Channel 4 -- and other trusted news providers easier to find in users' feeds and searches.

Boosting the visibility of regulated news providers could help tackle misinformation, particularly during crises, the government said. However, any move to influence how platforms rank content is likely to face scrutiny from the social media firms, which say such rules could override user choice and disadvantage other creators. The proposals form part of a broader overhaul of Britain's public service media system to help broadcasters compete with streaming platforms and shifting viewing habits. Ministers are also considering widening public service media status to include online-only providers, extending free-to-air protections for major sporting events to on-demand viewing, and consulting on a shift to internet-based TV from 2034 or 2044.
"It is vital that we make sure that people have better access to trusted and accurate news and that our regulated public service media is seen and heard in the fierce battle against mis- and disinformation," culture minister Lisa Nandy said in a statement.

The move follows the UK's recently-announced ban on social media use for those under 16.
Ubuntu

Canonical's Upcoming AI Tool: Talk to Ubuntu Instead of Typing (itsfoss.com) 58

This week the Ubuntu desktop's director of engineering announced they're bringing speech-to-text dictation to Ubuntu Desktop, aiming for an experience "that feels like a natural part of the desktop while respecting user privacy and running entirely on local hardware."

"Speech recognition has become a common feature on modern platforms, and we think it should be a first-class experience on Ubuntu Desktop as well."

More details from the blog It's FOSS: For Ubuntu 26.10, the initial version of Myna is expected to be a desktop dictation tool built around GNOME on Wayland with a push-to-talk mechanism gatekeeping when your microphone accepts input. Using it means holding a hotkey, speaking, and letting go. A small activity indicator shows while it is listening, and the transcribed text lands wherever the cursor was sitting when dictation started.

Recognition itself happens inside a sandboxed component called the Canonical Inference Snap, while a Speech Orchestrator manages the session and an Audio Adapter handles whatever the microphone picks up, denoising and chunking it before it ever reaches the model... Speech recognition will happen locally, and an internet connection is not needed once the appropriate model is installed... The audio data won't be sticking around either, being stored in a small in-memory buffer that gets discarded the moment the session ends. Features like dictation into password fields, wake words, continuous listening, voice assistants, voice commands, translation, speaker identification, and automatic language detection are all off the table...

You should also know that Canonical is looking for feedback before the specs for Myna are finalized, especially from people who already rely on dictation or assistive tools on Linux.

Security

How Millions of Digital Home Devices Are Secretly Powering Cyberattacks (yahoo.com) 33

The Wall Street Journal reports on internet-connected devices — and how every year millions of them "can contain a secret digital backdoor that opens up access to your home internet, so that anyone... can surf the web as if they were you." (And this is especially true for "knockoffs that you buy online"...)

In a video report this week they tested two digital picture frames from Amazon and three streaming devices from Walmart "because we heard that they often ship with backdoor software used in cyberattacks. Security experts believe manufacturers are being paid to add this malware, but many people also get tricked into downloading the software onto their phones or computers... Within minutes of turning the devices on, there was a surge of internet traffic... Visits to gambling, porn, cryptocurrency and loads of other sketchy web sites started pouring in from users around the world." (And remote visitors also tried to access Outlook and Gmail accounts...)

Residential proxy companies even rent out access to "tens of millions of home networks around the world," according to the report. "But the problem is actually worse than that. Hackers figured out a way to seize control of these backdoors, and they started taking over these residential networks. Last month authorities arrested a 23-year-old Ottawa man, saying he'd taken control of more than a million devices to launch some of the largest cyberattacks anyone had ever seen.."

After a couple months the Journal's reporter collected logs of all the traffic, and sent it to an investigator at Comcast, who said both were conducting DDoS attacks. But estimate for the number of infected devices are as low as tens of millions or as high 500 million-plus. "We've seen nation state attacks launched through these kind of endpoints, which means your device sitting in your house is part of a nation state attack against another nation state... We've seen ad fraud, we've seen ticket scalping, we've seen financial fraud."

But more importantly, "We have seen some of the largest computer attacks — meaning computers attacking other computers at human request — ever recorded in our digital history in the last several months." At cybersecurity conferences, some are warning "there are much larger ones on the horizon if we don't get a hold of this problem."

The company making the picture frame "couldn't be reached for comment," while Amazon said it's been out of stock since last year. Both Amazon and Walmart said they take action when they confirm malware on a third-party product.
Cloud

EU To Soon Classify AWS and Azure As Gatekeepers Under DSA (heise.de) 39

The European Commission is reportedly preparing to provisionally classify Amazon Web Services and Microsoft Azure as "gatekeepers" under the Digital Markets Act, bringing cloud infrastructure under the law's stricter competition rules for the first time. The designation could require greater interoperability and data portability, making it easier for customers to switch providers, with a final decision expected by the end of 2026. Heise reports: This investigation began in November 2025, when the EU targeted the cloud power of US tech giants. The trigger was outages in cloud services with sometimes significant impacts on other internet services. Shortly before, an approximately 15-hour outage of the AWS cloud in the US meant that not only Amazon's own streaming services but also Atlassian, Docker, Epic Games, and the Signal messenger were unavailable or severely restricted. Shortly thereafter, Microsoft Azure also struggled with an outage, preventing air passengers from checking in and interrupting votes in the Scottish Parliament.

As a result, European antitrust authorities have also scrutinized cloud services under the Digital Markets Act for the first time. The major cloud providers, primarily from the US, have so far evaded the EU's Digital Markets Act because a large part of their business is handled through corporate contracts. This makes it difficult to determine the number of individual users. However, this is one of the EU's most important criteria for determining the market power of companies. [...] As gatekeepers, AWS and Azure would be obliged to ensure interoperability and data portability. This would, for example, simplify switching cloud providers and allow customers to link other services with AWS or Azure clouds, instead of being limited to AWS and Azure offerings. Significant fines could also be imposed if the cloud services are found to be in violation of existing regulations.

Books

How Author Dave Eggers Avoids Smartphones, Internet Access, and Flock Cameras (sfgate.com) 45

A few weeks ago on a bike ride "inspiration struck" for Dave Eggers, reports SFGate... Without a pen and paper handy, he was stuck texting the idea to himself. The problem? Eggers doesn't own a smartphone. "It takes 20 minutes to write a sentence," Eggers said... It's a funny predicament for Eggers, given that he's arguably the city's biggest proponent of the written word... Now age 56, Eggers' latest book is called "Contrapposto"...

On writing days, Eggers bikes to his sailboat docked near the Golden Gate Bridge. He writes using a hefty 1998 Mac that has never been connected to the internet. On the boat, he keeps "banker's hours," working 9 to 5 without any meetings or interruptions except for the occasional wildlife visit. "You're there with the cormorants and the occasional porpoise and sea lions and seals, and when you want to take a break, you walk around and you're in the thick of it, one of the most beautiful spots on Earth," he said. "Especially coming from the Midwest, it never gets old."

Given Eggers' decidedly low-tech existence, it's not surprising that the current state of San Francisco gives him pause, but there's a streak of hope that underlies his concerns. He abhors the growing surveillance technology that's gripping the city, refusing to get into Ubers that use recording devices, but he feels a well-written ballot measure about Flock cameras could potentially save our dwindling privacy. ChatGPT's effects on the art of writing are demoralizing, but he welcomes that teachers are re-embracing pencil and paper, with cursive making a big comeback. The wave of artificial intelligence ads blanketing bus stops imploring companies to stop hiring humans are so over the top, they'd sound cliché if he were to include them in one of his dystopian tech industry novels like "The Circle" or "The Every," but tech philanthropy has helped many of his projects flourish.

Case in point, Art + Water, a new art space scheduled to open next year on Pier 29 funded largely by art world donations... Co-founded with the artist JD Beltran, the space is slated to operate as an old-school apprenticeship system, hosting 10 artists in residence mentoring 20 students, all free of charge... The ultimate goal is to break down the financial barriers that keep students from pursuing art.

Thanks to Slashdot reader destinyland for sharing the article.
The Almighty Buck

SpaceX IPO Makes Elon Musk World's First Trillionaire (reuters.com) 315

An anonymous reader quotes a report from Reuters: Few business leaders have been as deeply embedded in popular culture as Elon Musk, the ambitious entrepreneur who has become a central figure in internet culture and amassed a fortune that has made him the world's first trillionaire. At a time when concerns about inequality are high and public attitudes toward the ultra-wealthy have soured, Musk has managed to retain a loyal following despite his stratospheric net worth and without the folksy persona that endeared other tycoons such as Warren Buffett to the masses.

While admirers view Musk's no-filter style as part of his appeal, critics have accused him of wielding oligarch-like power, raised concerns about governance at his companies and objected to his increasingly partisan political interventions. Still, SpaceX, the sprawling rocket, satellite and AI company that together with electric-car maker Tesla form the center of Musk's empire, raised a record $75 billion in its initial public offering on Thursday, highlighting investor enthusiasm for his business ventures. Prior to the share sale, Forbes pegged his net worth at roughly $780 billion, far ahead of the man next in line, Alphabet co-founder Larry Page.

"The second richest person has been hovering around $300 billion, so about less than one-third of what Musk can potentially be worth tomorrow," said Matt Durot, deputy editor at Forbes Wealth. "And only one other person, (Oracle founder) Larry Ellison, has ever been worth $400 billion." Most of Musk's wealth now rests with SpaceX, where he holds a stake worth roughly $866 billion. Along with Tesla and the rest of his properties, his net worth will exceed $1.1 trillion when the stock begins trading Friday, according to Forbes and Reuters calculations based on company filings.

Slashdot Top Deals