United Kingdom

Iran-linked Cyberattackers Shut Down a UK Power Plant for Four Days (bbc.co.uk) 14

"Iran shut down a British power plant for four days in an unprecedented cyber attack," reports the Telegraph.

More details from the BBC: The government said that at no point was there a risk to the UK's energy system, but the Department for Energy Security and Net Zero (DESNZ) has contacted power companies to advise them about the risk of cyber attacks... DESNZ said the incident had affected a small-scale generator and at no point had there been a risk to the wider energy system. The UK's power network has a number of smaller gas generators which provide short-term power when needed.
Thanks to Alain Williams (Slashdot reader #2,972) for sharing the news.
Government

Slovakia Finds Russian Backdoor In Traffic Speed Cameras (tomshardware.com) 27

Slovakia acquired speed cameras to modernize its traffic control-- but there was a surprise. Tom's Hardware cites this story from the Risky Bulletin Newsletter: Unfortunately, the country's national security service, the NBU, has discovered that the cameras have multiple security issues. Firstly, they have SMS-activated Russian backdoors. Secondly, live camera feeds can be accessed by anyone with the device IP, no password necessary...

[The cameras] are thought to be rebranded Russian CORDON PRO.M traffic cameras, produced by a St. Petersburg-based firm called Semicon... reportedly bought via a Cyprus-based shell company with fake certifications. Reports also suggest that pressure from the opposition political party in Slovakia led to the NBU investigations... Probably most seriously, in terms of national security, these cameras contain a hardcoded list of Russian phone numbers, which can be used to open a backdoor. An SMS from one of these numbers can open shell and network access... [T]he SecureBoot feature is ineffective, and the web management portal can be accessed, exposing live streams, by anyone with the camera IP.

Cameras that have been installed and set up have since been deactivated by the Slovak Ministry of the Interior. Meanwhile, for due diligence, an independent auditor will be called in to confirm the NBU's findings. It is thought that Croatia, and some other countries in Eastern Europe, may have undiscovered issues with traffic control cameras of similar origin.

AI

Stanford Economist Now Believes an AI Job Apocalypse Is Unlikely (washingtonpost.com) 47

"There is still no sign of economy-wide job destruction," says economist Erik Brynjolfsson. Working with researchers at the Stanford Digital Economy Lab, Brynjolfsson has determined an AI "job apocalypse" is unlikely, reports the Washington Post, "even though it will likely impact entry-level jobs."

And Brynjolfsson "predicts that demand for experienced workers such as senior coders will still be high even if AI takes on more routine knowledge and coding work in the future." Earlier this month, Brynjolfsson and his colleagues at the Stanford Digital Economy Lab updated their widely publicized report, "Canaries in the Coal Mine? Six Facts about the Recent Employment Effects of Artificial Intelligence," to reflect that they do not see widespread, economy-wide job displacement associated with AI...

Brynjolfsson: What has moved on the upside is productivity. Nonfarm business productivity growth is running over 2 percent, the best sustained stretch since the late-1990s boom... The gains show up years after the investment, and they're starting to show up... By 2030, we will have enormously more capable AI, meaningfully faster productivity growth and an unemployment rate that looks unremarkable — somewhere in its historical range. That surprises people, but it's what the mechanism implies... [T]he technology is becoming much more powerful, and it's going to be even more powerful.

Secondly, there are huge implications for business and the economy, including some increases in living standards, but also, potentially, job disruption. And then, thirdly, we must act now to address this gap. We can't just sit back and wait for the tsunami to hit us. And one of the things we can do is put in place institutions, policies and research to make the technology more complementary — using AI to complement people so it creates more jobs. A common misconception among business managers is AI, in order to be effective, has to reduce jobs. That's just not true. You can use AI to increase employment and productivity at the same time. It's kind of a win-win...

Right now, tax policy is very skewed toward favoring capital versus labor — and, as a consequence, a lot of entrepreneurs and managers, they're basically being guided by the federal government to replace workers with machines. And I don't think that's necessarily what we'd like to have happen. From an economist's perspective, what you want to be doing is not mimicking and replacing things. You want to be extending and complementing — have humans do new things they never could have done before.

He acknowledges "real, persistent and widening" effects on entry-level jobs, with a labor market "closing the on-ramp for people starting their careers... If companies don't hire people at the base of the pyramid, then they're not going to have those people later when they need them."

One he points out that one company is instead using AI to speed up its training of young employees.
AI

Is AI Really to Blame for High Unemployment Among Recent Graduates? What Economists Say (npr.org) 45

47% of recent graduates say AI has already impacted hiring in their field, according to an April survey from ZipRecruiter.

"But is AI really the problem, or is it more complicated?" asks NPR. "Here's what economists have to say." According to the Federal Reserve Bank of New York, the unemployment rate for recent graduates — which it defines as 22-to-27-year-olds with a new bachelor's degree or higher — was 5.7% as of June, more than the rate for all workers, which stands at 4.1%... Stanford University economist Erik Brynjolfsson says AI is impacting the labor market for entry-level roles. "AI is not the whole story, but it's part of the story and the evidence is building," he says. Using payroll data, Brynjolfsson and his co-authors found that since late 2022 — when large language models like ChatGPT started popping up — early-career workers ages 22 to 25 in AI-exposed roles, like software developers and marketing managers, have experienced a 16% relative employment decline. In comparison, employment rates for older workers in AI-exposed fields and for all workers in jobs that aren't easily automated — like home health aides, physical therapists and construction workers — remained stable or have grown over that same time period... [Though he also says often when companies pull back on hiring, they cut junior roles first.]

Harvard University economist David Deming isn't convinced that AI is to blame for the challenging early-career job market. "If you look very carefully at the timing, it looks like the decline in junior hiring actually started a bit like six months before ChatGPT was released. And so what that tells me is it's something else," Deming says. "I think it's more like remote work." A recent analysis from the New York Fed found that companies are less likely to hire recent college grads into roles that can be done remotely. As remote jobs increased following the COVID-19 pandemic, so did unemployment among younger college grads, the New York Fed found. The analysis also found that AI didn't explain the rise in unemployment among younger workers and that remote work was more of a driving force... Employers hiring for remote jobs may be less likely to choose an entry-level candidate because it's harder to train them from afar... [And with remote positions, there's many more senior candidates to choose from.]

And here's another thing to consider: University of Chicago economist Anders Humlum says if AI were replacing entry-level jobs, you'd expect to see companies that rely heavily on AI to hire fewer workers. But that's not what the data shows. Humlum points to a study done by the financial accounting firm Ramp and the workforce research company Revelio Labs. The study examined AI spending and employee head count across more than 21,000 U.S. firms, from early 2021 to early 2026. It found that at companies making the largest AI investments, entry-level head count grew by 12% over the two years following AI adoption.

Privacy

Man Dressed As Darth Vader Defends Flock Cameras to San Diego City Council (thehill.com) 58

A man dressed as Darth Vader used a Public Safety and Livable Neighborhoods Committee meeting in San Diego to mock the city's use of Flock surveillance cameras, sarcastically arguing that the technology would help the "emperor" track "rebel scum" and find Luke Skywalker. "This is what the emperor needs. This technology will help us find the rebel scum and the hidden base on Hoth," he said. The Hill reports: He urged that the cameras be used to surveil any "rebel scum as they move from playground to playground, from playground to pool, from pool to gymnasium, because we all know that the Flock cameras are not only following the license plate readers, they are following children." The plea for the cameras shifted to raising taxes to clear out storm drains and to the clearing of homeless encampments in the city. The man said the council members can use "doublespeak" to say the police department is humanitarian.

"And how will the people trust this City Council when this City Council continues to vote for surveillance technology that imprisons them? Ms. Campbell, you must work on your Jedi mind tricks," he said, addressing City Council member Jennifer Campbell, before waving his hand to the audience. "Do it like this." His last plea was for the Flock cameras to be used to "help us find Luke Skywalker as he traverses the universe in his X-wing." "This technology is a necessary, necessary force," he concluded.
According to DeFlock, San Diego has more than 550 Flock cameras across the city.
AI

Linus Torvalds Endures A Debug Session From Hell, 'Enormously Helped' By AI 56

Linus Torvalds says AI "enormously helped" him track down a stubborn Intel Xe graphics driver bug that took 24 debugging patches and 18 kernel boots to isolate. "I'd like to call it my tireless helper, but the AI several times stated flat out that this was impossible and unsolvable and that we should just write a report about it," wrote Torvalds on the commit. "I suspect those things have been trained by people who may not be quite as stubborn as I am..." Phoronix reports: The patch by Linus Torvalds is for the Xe kernel driver and the change is no longer hand out the flat Compute Command Streamer (CCS) storage as usable vRAM. On a Battlemage G21 graphics card, he was hitting a scenario where there was a mismatch where the usable memory ended and hit a case where the GDM display manager would end up being endlessly restarted. [...]

Linus Torvalds views AI as a useful tool and in this case reaffirmed he found it "enormously helped" his effort in tracking down this Intel graphics driver bug. The Intel Xe driver fix is merged to Linux 7.3 Git and is also marked to back-porting to the stable kernel branches.
Privacy

Reverse-Lookup Service Exposed Millions of Photos of People's Faces (wired.com) 19

Security researcher Jeremiah Fowler found that people-search service ClarityCheck left more than 9 million image files accessible in an unsecured Amazon S3 bucket, despite advertising its reverse-image search as "private and secure." A separate misconfiguration also exposed email addresses, phone numbers, and other personal information. Wired reports: Overall, according to findings from independent security researcher Jeremiah Fowler, the exposed ClarityCheck database contained roughly 450 GB of images, including what appeared to be profile images, screenshots, and other photographs of adults, teenagers, and children. All of the images were stored in an unsecured Amazon S3 bucket, with files in folders named "faces" and "profiles," which could be accessed by anyone online through a URL included in the company's publicly available website code.

ClarityCheck is one of a number of so-called people-finder tools that have appeared online in recent years. These websites broadly claim to be able to search the web, public records, and other databases to identify individuals. ClarityCheck's website says it can run searches on phone numbers, email addresses, vehicle identification numbers, and names. Its photo-search page says it can help "identify anyone in a photo" and find social media profiles "in seconds." While ClarityCheck secured the giant image database after WIRED contacted the company in July, Fowler warns that it was seemingly exposed for months, and his initial efforts to flag the problem to the company were unsuccessful. Accidental data exposures create risk for any personal information, but particularly for sensitive and unchangeable biometric data like face images.

[...] In addition to the face data, ClarityCheck had also misconfigured its APIs such that its website URLs could be manipulated to reveal data about people simply by entering names; anyone using any consumer browser could have done this. Entering a name into one of the URLs would return multiple potential email addresses, physical addresses, and phone numbers for people with that name. After WIRED contacted the company, the URLs were secured. The ClarityCheck spokesperson said in the statement that the details displayed were "sourced from publicly available information and licensed third-party data providers."
A spokesperson for ClarityCheck said in a statement: "Once this was drawn to the attention of the appropriate teams, we acted immediately to restrict access." The company disputed any characterization that the data was "exposed," saying that an "ordinary member of the public" would not have come across it.

"We do not accept that data in the temporary storage location was 'publicly exposed,' which implies large-scale public access," the spokesperson says. "Access required knowledge of a specific, unindexed URL that was not discoverable through ordinary use of the ClarityCheck service or a general web search."
Security

CISA: Medusa Ransomware Hit Over 500 Critical Infrastructure Orgs (bleepingcomputer.com) 6

CISA says the Medusa ransomware operation has breached more than 500 U.S. critical infrastructure organizations since 2021, up from more than 300 reported last year. The group has targeted healthcare, government, defense, manufacturing, IT and financial organizations, evolving into a ransomware-as-a-service operation that recruits initial-access brokers and uses stolen data to pressure victims into paying. BleepingComputer reports: The three federal agencies recommended that network defenders secure their networks against the ransomware group's attacks by mitigating security vulnerabilities to protect operating systems, software, and firmware from exploitation attempts. Security teams are also advised to segment networks to block lateral movement after compromise and to block access from untrusted origins to remote services on internal systems.

[...] "Medusa developers typically recruit initial access brokers (IABs) in cybercriminal forums and marketplaces to obtain initial access to potential victims," the advisory says. "Potential payments between $100 USD and $1 million USD are offered to these affiliates with the opportunity to work exclusively for Medusa."

AI

AI Fails to Deliver a 4-Day Work Week - Especially at AI Companies (bbc.com) 71

"An engineering director at Google said four years ago that AI would deliver a four-day work week by 2025," remembers the BBC. And earlier this year OpenAI "formally urged companies to start testing out a four-day work week (with no change in pay), claiming that AI will soon be able to speed up so much human labour that the corporate world should prepare itself." However, a former OpenAI technical employee who left the company last year told the BBC the firm never actually trialled the four-day work week it suggested others should try while they were there. Instead, the person described what was often a gruelling work culture marked by frequent "crisis meetings", working on weekends, and "super cut-throat" performance reviews that would see colleagues suddenly let go... [T]he former OpenAI employee said they would put in at least 70 hours a week, much more than they did in previous tech jobs...

Other companies have also pushed the idea that AI will effectively reduce the number of hours people need to work, for better or worse. [At OpenAI and Anthropic] sprints can stretch on for many weeks and top 90 hours of work in a seven-day period, tech workers that the BBC spoke to for this story said... At Meta, workers said they have been abruptly pushed onto teams this year doing AI work being treated as urgent... The hours on such teams at Meta are often long, with staff working into the night, on weekends, and feeling they are "on call" during the hours they are not working, according to descriptions of the work from the current and former employees...

Some new research suggests that AI tools are making people's workloads even more burdensome. A study out of UC Berkeley followed hundreds of workers at a US tech company for eight months as they used AI. It found the employees "worked at a faster pace, took on a broader scope of tasks, and extended work into more hours of the day"... The UC Berkeley research found that the workload of tech employees was expanded in part because of the need to constantly check the output of AI tools.

In the article Neil Thompson, an innovation scholar at MIT, pointed out a problem with estimates that AI will ease the workload on humans. "People assume that 20% less work means four-day weeks. But new work emerges."

The BBC also points out helpfully that "there are no limits in the U.S. on how many hours a person over the age of 16 can work." (While in the UK and Europe, "laws limit a working week to 48 hours, including overtime.")

Thanks to long-time Slashdot reader hadleyburg for sharing the article.
Desktops (Apple)

Vulnerability Giving Attackers Full Control of Macs Is Under Active Exploitation (arstechnica.com) 26

joshuark shares a report from Ars Technica: Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation. "The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet," the Netherlands National Cyber Security Centrum warned earlier this week. "In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed."

The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the "state management," which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause. A video of the exploit in action can be found here. Details of CVE-2026-65400 became public at last week's Black Hat security conference. Apple said last week that CVE-2026-65400 "may" allow an attacker without credentials to gain access to a Mac. It's unclear why Apple hedged, but softening language is common among most tech developers when disclosing vulnerabilities.

As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting. Security practitioners generally advise Mac users to keep the port closed even when using screen sharing and to instead connect over a VPN or through SSH tunneling. The alternatives require actions that aren't within the capabilities of most users. The safest practice is to block screen sharing, enable it only when screen sharing is needed, and to turn the feature off once a session has ended. Screen sharing can be turned on or off by accessing System Settings > General > Sharing and toggling the switch for Screen Sharing. Of course, installing last week's security update is also a must. Sharing is not caring.

China

China-Linked Hackers Used AI To Run First-Ever 'Autonomous' Cyberattack On Taiwan (tomshardware.com) 8

Researchers at Israeli cybersecurity firm Dream say suspected China-linked hackers used an open-source AI-agent system to conduct what may be the first observed end-to-end autonomous cyberattack against a government. According to the Financial Times (paywalled), the attack compromised at least 85 accounts and resulted in the theft of more than 2,500 personnel records from Taiwanese systems. Tom's Hardware reports: The campaign reportedly ran for four days at the beginning of July and at times deployed as many as eight autonomous agents in parallel. Dream said the system mapped 21 government systems before compromising user accounts and extracting personnel information. The attackers subsequently expanded their activity to Taiwan's nuclear safety agency, at least seven energy companies, government suppliers, and other government systems.

Dream says it found the evidence inside a 160-megabyte (160MB) online archive that surfaced during its broader tracking of cyberthreat actors. The archive reportedly held 1,395 files showing that the tool was built on two open-source AI agent systems -- Hermes and OpenClaw -- both of which can be downloaded freely and are designed to let large language models carry out multi-step tasks on their own.

Researchers could not determine which underlying model powered the agents, but the data reportedly showed the model's safeguards had been sidestepped by presenting the intrusion as an authorized penetration test rather than a real attack. Of particular concern is that the toolkit for the hack comprised such easily available systems, neither of which was purpose-built for offense. The operators appear to have assembled a capable autonomous tool out of components any developer can pull down and run.

What the researchers describe as the tool's most striking feature was its ability to continuously devise attacks on its own, rather than follow a preprogrammed route. The platform continuously assessed available evidence, ranked possible attack paths, and reprioritized them as circumstances changed. When one technique failed, the tool tasked another agent with searching the internet for information and developing an alternative approach.

Bug

A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices On a Call 12

An anonymous reader quotes a report from Wired: As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets' devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim.

Researchers from the digital defense firm A Security say thebugwas discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports -- Windows, macOS, Linux, iOS, and Android.

The vulnerabilities were specifically in the protocol used to facilitate real-time annotation during screen sharing. The researchers say that their AI bug hunting systems specifically delved into this component because, like human bug hunters, they have been trained that convoluted and obscure functions often contain overlooked vulnerabilities. This is particularly true with proprietary, closed-source software. An established company like Zoom presumably does extensive code review and vetting on all components and functions, but without the benefit of public, open review, esoteric yet complex features like annotation are more likely to contain mistakes. The bugs are now patched, with Zoom issuing both server and client-side fixes—or patches for both Zoom's own servers and the applications that run on customer devices. But the researchers emphasize that it was alarming to contemplate bugs that could have been exploited to take over a target device simply by getting someone onto a Zoom call.
"What is interesting for us and what we believe is dangerous is the democratization of these capabilities -- the barrier to entry is dropping rapidly," A Security cofounder Omer Gull told WIRED ahead of the disclosure. "Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don't see it as a threat."
Robotics

The Roboguard Revolution Is Short-Circuiting (404media.co) 35

alternative_right shares a report from 404 Media: Robotics companies promise that video-camera-toting security robots can deter and detect crime. But many companies are rethinking the approach after a trail of canceled contracts and questions about whether the artificial intelligence-powered bots are meeting the needs of businesses and local governments. Proof News found evidence of at least 21 security robot deployments since 2015. We contacted contract holders and combed news articles and determined that at least 13 of those programs have ended. Silicon Valley-based Knightscope secured the most security robot contracts, according to Proof's analysis, and also suffered the bulk of cancellations.

For example, New York City's then-Mayor Eric Adams installed a Knightscope robot on the overnight shift at the Times Square subway station, but the program was scrapped when the pilot expired in 2024. City leaders did not respond to Proof News' questions about why the robot wasn't renewed. By the end of its assignment, it was reportedly gathering dust in an empty storefront. Outside Columbus, Ohio, the city of Dublin pulled the plug on a Knightscope robot in May, ending its two-year pilot program after less than 10 months. The city enlisted the robot, dubbed DubBot, to patrol a downtown park, but city spokeswoman Robyn Gray said it "did not fully meet our operational needs," and failed to identify any criminal incidents or lead to any tickets or arrests.

[...] Seeking a new path forward in the security industry, Knightscope CEO William Santana Li said the company is forging a new model, combining its robots and AI-powered software with another key ingredient: human security guards. Knightscope announced it purchased Event Risk LLC, a national security guard firm, earlier this year. Knightscope has incurred net losses since inception in 2013, according to its most recent quarterly filing with the U.S. Securities and Exchange Commission, and is $273 million in debt. Knightscope hopes its pivot to incorporate people will give it a greater share of the physical security market -- which the company believes is worth an estimated $230 billion annually. Li declined to answer questions about the disbanded programs, but said in an email, "Technology cannot do everything -- and neither can people -- but the combination can be very powerful."

Privacy

A Data Breach At Shipping Giant Ceva Logistics Is Rippling Across Banks, Retailers, Steam Gamers, and Beyond (techcrunch.com) 20

An anonymous reader quotes a report from TechCrunch: Ceva Logistics, one of the world's largest shipping and logistics giants, has been hacked. Several companies that rely on Ceva for shipping their products to their customers say that their personal information was also stolen in the breach. The cyberattack on Ceva is affecting at least eight warehouses across Europe used for shipping goods across the continent, the company told TechCrunch. Industry news site FreightWaves reports that the hack began on July 29 and is causing shipping delays for many of the goods in affected warehouses.

Ceva is a France-headquartered shipping and logistics giant that companies around the world rely on to deliver their goods from their assembly lines to customer homes. The company, which brought in $18.3 billion in revenue in 2025, has over a thousand warehouses across the world. [...] The hack at Ceva also resulted in a data breach, affecting a large amount of personal information belonging to retail customers that Ceva relies on for delivering goods to people's home addresses. Several companies reported that hackers took their customers' names, home addresses, phone numbers, and email addresses used to place their orders from Ceva's systems.

Dutch online retail giant Bol said on its website that hackers gained access to systems of its warehousing partner, Ceva, and warned that their customers' data may have been taken. Bol also said that it expects delays and some customer orders to be canceled as a result of the incident. De Bijenkorf, another Dutch luxury retailer, similarly confirmed order delays following the theft of its customers' data, per local media. Football club Ajax, banking giant ING, and eyeglass maker Ace & Tate also reported that customers' shipping information was affected. Video game giant Valve told customers that it learned on August 7 that data was taken from Ceva's systems, and alerted customers who recently bought its Steam hardware that they had personal information taken in the incident. Valve said in its note to customers, posted to Reddit, that Ceva stores their shipping and delivery information for 90 days following their order.
So far, Ceva says the agency has received data breach reports from 10 organizations in relation to the incident.
Security

AI Assistant Hacks Gym Website In First Known Australian Autonomous Cyber Attack (abc.net.au) 116

An anonymous reader quotes a report from ABC News & Headlines: Andrew asked his personal assistant to book him a spot in one of his gym's coveted morning classes. It was a task he thought was well suited to this particular assistant because the booking form was online and because his assistant was not a person -- it was artificial intelligence (AI). But Andrew was shocked by what happened next. His AI assistant found a way to book the gym class months further in advance than the gym allowed, thanks to a vulnerability it discovered in the booking software. Then it went further, kicking someone out of the waiting list who was ahead of Andrew -- something it was not asked to do. The accidental hack is the first known Australian case of an emerging risk from a new generation of AI capable of behaving in unexpected ways.

Slashdot Top Deals