AI

New MCP Specification Addresses the Main Barrier To Enterprise Adoption 49

An anonymous reader quotes a report from Ars Technica: This week, the Model Context Protocol (MCP), an open source standard for how AI systems interact with external tools and data sources, saw its largest update since its introduction. Most notably, MCP's protocol core is now stateless, so requests are no longer dependent on a session tied to an individual server instance. This change has the potential to address long-standing barriers to scalability.

The blog post announcing the specification, written by lead maintainers David Soria Parra and Den Delimarsky (who both work at Anthropic), says: "The highlight of this release is a stateless protocol core -- MCP is transforming from a bidirectional stateful protocol into a request/response stateless protocol. It was one of the most highly-requested features from developers who were eager to get better reliability and scalability for their MCP servers."

[...] There is also a new deprecation policy that ensures at least 12 months between when a feature's formal deprecation is enacted and when the feature may actually be removed -- with a narrow exception for critical security updates. This is again in keeping with the general "let's make this work better at enterprise scale" theme of the new specification.
This update is "MCP's most important since remote MCP first launched over a year ago," Soria Parra wrote. Other additions include "Multi Round-Trip Requests, header-based routing, cacheable list results, authorization hardening, a formal extensions framework, and updated Tier 1 SDKs."

A full list of changes can be found here.
Robotics

Who Wins and Who Loses After US Bans Foreign Robots? (arstechnica.com) 91

The FCC's ban on Chinese-made robots extends well beyond humanoids to quadrupeds, research platforms, and many robot vacuums from allied countries. Supporters call it a major boost for domestic robotics, but critics warn that cutting researchers and startups off from affordable foreign hardware could slow U.S. innovation instead. Ars Technica's Jeremy Hsu examines who stands to gain and who stands to lose from the prohibition: Such an import ban would apply to some of the most affordable robots primarily produced by Chinese companies, including Unitree's humanoid robots that are used by robotics labs and researchers for tasks such as experimental robot surgeries. US consumers would also likely lose access to the newest robot vacuum cleaners that are mainly manufactured by Chinese companies such as Roborock. But the ban also broadly applies to foreign-made robots produced by countries nominally allied to the United States, including Japan, South Korea, and Germany. [...]

The ban on foreign-made robots could theoretically encourage more US and foreign companies to set up manufacturing facilities in the United States. There are already multiple companies racing to scale up production of humanoid robots in US factories, including Agility Robotics, 1X Technologies, and Figure AI. Tesla has been attempting to shift production away from older electric vehicle models and toward its Optimus humanoid robot. Boston Dynamics has already been making its Atlas humanoid robot, along with its four-legged Spot robot and wheeled Stretch robot, at its main facility in Waltham, Massachusetts. The US robotics company is also planning to massively scale up manufacturing of the Atlas robot under South Korea's Hyundai Motor Company, which gained full ownership of Boston Dynamics in July 2026.

"This is one of the strongest technology-security actions in modern US history," wrote Evan Beard, CEO of Standard Bots, in a LinkedIn post. "The message is unambiguous: robotics is a technology America must lead and own -- and foreign-subsidized robots will not be allowed to unfairly dominate US robotics as they did solar." Similar praise came from Rush Doshi, director of the Initiative on China Strategy at the Council on Foreign Relations, who, in a social media post, described the FCC decision as "one of the most significant actions taken so far in support of the US robotics ecosystem."

However, several robotics researchers and analysts interviewed by The Robot Report expressed skepticism about any potential boost to US competitiveness in robotics. Some even warned that the ban could prove counterproductive for US robotics efforts to develop humanoid robots. "In the near term, the measure could slow US physical AI innovation by cutting startups and researchers off from future low-cost Chinese platforms before comparable Western alternatives exist," said Georg Stieler, a global robotics advisor and managing director for Asia at Stieler Technology & Market Advisory, in an interview with The Robot Report.

US domestic production of robots lags behind China in terms of mass manufacturing at lower cost, said Rueben Scriven, a senior analyst at Interact Analysis. "This announcement is more likely to inhibit the US humanoid robotics industry, as the presence of low-cost Chinese humanoid robots has been helping educate the US market through promotional and entertainment use cases -- an effect this policy risks undermining," Scriven told The Robot Report.
The report notes that previous FCC bans have done little to help create competitive U.S. alternatives, with restrictions on Chinese drones instead prompting companies to sell barely disguised versions of DJI technology.
AI

OpenAI's Rogue AI Agent Hacked More Than Just Hugging Face (wired.com) 67

An anonymous reader quotes a report from Wired: OpenAI said Tuesday that the rogue AI agent that breached Hugging Face's platform also hacked multiple third-party accounts and services as part of the attack. It's now clear that the unprecedented security incident, which arose during an internal test of OpenAI's latest AI models, was more extensive than the company initially disclosed. In an updated blog post, OpenAI said that an ongoing review of the incident revealed that "four accounts" tied to "publicly available services" were used by the AI agent as part of a larger effort to hack Hugging Face. The rogue agent apparently found credentials that had been exposed on the open web and used them to break into the accounts.

OpenAI did not disclose what companies or organizations the accounts belonged to, but noted that they were not impacted at "the level of severity or scale of what we've shared related to Hugging Face." One of the additional accounts compromised by OpenAI's agent was used as an "outbound relay and staging path," potentially to obscure where the attack on Hugging Face was coming from, the company said. OpenAI's rogue agent also used another account for data storage to assist with the hack.

Reuters reported on Tuesday that a customer of Modal, a company that offers software infrastructure for training and running AI services, was one of the entities compromised by OpenAI's agent. In a statement to WIRED, Modal's chief technology officer Akshat Bubna confirmed that OpenAI's agent exploited a vulnerability in one of its customer's codebases, which was running on Modal's infrastructure. However, Bubna says, "Modal's platform was not compromised in any way." The identity of the customer could not be determined.

Security

More Than 30 Minnesota Water Systems Targeted In Cyberattack (fox9.com) 66

jrnvk shares a report from KMSP: Minnesota IT Services reports that a "coordinated cyberattack" targeted technology at more than 30 community water systems between Sunday, July 26 and Monday, July 27. The state has activated its cybersecurity incident response capabilities to respond to the attacks.

On Monday and Tuesday, FOX 9 reported on notices from four cities that had disclosed the attacks: Plymouth, South St. Paul, Maple Plain, and Braham. All four cities said the impacts of the attacks were limited or mitigated and residents could continue normal water use. The Minnesota Department of Health is not aware of any municipality asking residents to alter their drinking water use as a result of the attacks.

State officials are working with federal and private-sector partners to investigate the attacks, support the affected communities, and strengthen the security of Minnesota's critical infrastructure.

Robotics

Trump Administration Bans New Chinese Humanoid Robots (bbc.com) 148

The Trump administration has banned newly authorized foreign-made humanoid and four-legged robots, along with power inverters, citing "unacceptable risks" to the country's national security. FCC chairman Brendan Carr said the agency was doing its part "to secure America's critical supply chains." The BBC reports: The FCC has added the items to its Covered List -- a register of goods and services that are deemed a risk to US national security. The ban applies to new foreign-produced advanced robotic devices and power inverters and does not prevent the sale or import of any existing models that had been previously authorized by the FCC.

The FCC cited concerns that the use of foreign-made inverters could allow overseas firms to turn them off, steal data, facilitate remote access and surveillance by "foreign government actors, or be otherwise exploited through a cyberattack." It added that the use of robots made outside the US could allow "malign actors to surveil Americans, enhance the capabilities of foreign intelligence services, or to remotely commandeer the robots."

Bug

AI-Found Bugs Aren't Proving Any Easier to Exploit Despite the Hype 76

AI-assisted vulnerability discovery has yet to produce the expected surge in real-world attacks: VulnCheck found that only 14 of 1,061 attributed discoveries, or 1.3 percent, had been exploited, which is "almost identical to the rate across all vulnerabilities in VulnCheck's dataset," reports The Register. "That's a far cry from the narrative that frontier AI is dramatically tilting the balance in attackers' favor by churning out instantly weaponizable bugs." The findings suggest AI is currently better at increasing the volume of bugs found than making them easier to weaponize. From the report: The report takes particular aim at Anthropic's much-publicized Project Glasswing, unveiled in April with warnings that AI-assisted vulnerability discovery could allow attackers to hijack systems, disrupt operations, or steal data. Claude Mythos may have identified 23,019 vulnerability candidates, but there's remarkably little public evidence showing what became of most of them. VulnCheck notes that only 126 have been published as CVEs, that just one has been confirmed exploited in the wild, and that Anthropic's public disclosure record has seen little movement since Project Glasswing launched.

But that doesn't mean AI-assisted vulnerability research has failed, according to Patrick Garrity, security researcher at VulnCheck. "AI-assisted vulnerability discovery clearly has value for both attackers and defenders," Garrity wrote. "The data does not suggest that AI-discovered vulnerabilities are inherently more likely to be exploited than those found through traditional methods." Instead, he argues, AI is simply helping researchers discover more flaws, giving defenders an opportunity to patch them before criminals get there.

Garrity stopped well short of declaring the threat overblown forever, but he did suggest some of the rhetoric has outpaced reality. "The data so far, including Anthropic's own stalled disclosure ledger, suggests that AI-assisted vulnerability discovery and frontier capabilities have been overhyped relative to the evidence available today," he wrote. "That doesn't mean the risk is imaginary. It means the impact has been real but modest."
The Almighty Buck

eBay Reaches $56 Million Settlement With E-Commerce Newsletter Writers It Terrorized In 2019 (techcrunch.com) 49

eBay and several former executives have agreed to pay $56 million to Ina and David Steiner, the newsletter writers targeted in a 2019 corporate harassment campaign that involved threats, surveillance attempts, and deliveries of live insects and other disturbing items. The settlement closes the couple's civil case after seven former employees pleaded guilty to criminal charges related to the scheme. TechCrunch reports: Ina and David Steiner, a married couple and the co-authors of EcommerceBytes, inspired the ire of high-level eBay executives after occasionally criticizing the company in their newsletter. In 2019, a plot was concocted to intimidate the couple into halting their negative coverage. Executives used sock puppet social media accounts to harass the couple, while also sending them anonymous threatening letters and bizarre items in the mail -- including live spiders and cockroaches, pornographic magazines, a bloody pig mask, a funereal wreath, and a book about surviving the death of a spouse. According to previously released court documents, a plan that was attempted but never successfully carried out involved affixing a GPS tracking device to the couple's car. Yet another internally broached plan involved sending a "Samoan gang" to the Steiners' home.

The settlement this week resolves a 2021 civil case brought by the couple against eBay. The law office representing the Steiners writes that the settlement includes $46.15 million paid to the couple by eBay itself, as well as $2 million from former eBay executive CEO Devin Wenig. Additionally, $500,000 will be paid out to the couple from former eBay executive Wendy Jones, as well as $50,000 from former eBay executive Steve Wymer. Additional funds are being paid to various non-profits. In 2022, seven former eBay employees were criminally charged and pled guilty in relation to the plot, including the company's former security chief, James Baugh -- who was sentenced to nearly five years in prison. Others indicted by the U.S. Department of Justice include David Harville, Brian Gilbert, Stephanie Popp, Stephanie Stockwell, Philip Cooke, and former eBay contractor Veronica Zea.

Encryption

Anthropic AI Model Finds Flaws in Tough-to-Crack Encryption Algorithms (nytimes.com) 32

Anthropic's Claude Mythos Preview has "found flaws in a weakened version of a digital encryption standard that is in pervasive use throughout the internet," reports The New York Times. Researchers said the model discovered novel attacks against weakened versions of AES and the experimental post-quantum HAWK system, including one that was 200 to 1,000 times faster than previous human-developed methods. From the report: The flaws identified do not concern a cryptographic standard currently in use today, which means that modern banking and communication systems are not subject to immediate potential intrusions from A.I. Instead, Anthropic's technology cracked a watered-down version of an algorithm for Advanced Encryption Standard, or A.E.S., a ubiquitous protocol that safeguards web traffic, wireless networks, data storage and more. It is common to perform tests on weaker versions of encryption algorithms to understand whether more powerful computers could someday crack the actual standards, akin to solving a simpler math problem to identify whether patterns may exist for a more complicated one. In the testing, Mythos was able to break the weaker version of Advanced Encryption Standard in a way that Anthropic said made an assault 200 to 1,000 times faster than what previous human research had managed to do. While the immediate ramifications are minimal, the long-term implications could be significant. In previous tests, large-language models seemingly could not match or best what humans can do in the mathematically dense field of cryptographic research, but their rapid advances could suggest a future in which top models can surmount traditional internet security protections that are foundational to just about everything that takes place on the internet.

[...] In addition to the attack on the encryption standard, Mythos also orchestrated another improved attack against a different digital cryptographic system known as HAWK that is designed to be bulletproof against both traditional and quantum computers. HAWK is not currently in use, but under consideration by the National Institute of Standards and Technology to become a new standard. The HAWK attack was validated by its authors, and independent cryptographers reviewed the Advanced Encryption Standard attack, Anthropic said, adding that it had shared its findings with the U.S. government and industry partners ahead of publication. Mythos devised the cryptographic attack on A.E.S. almost entirely autonomously, Anthropic said, but only after first refusing to contemplate the problem because it believed it was impossible to improve on existing methods of analysis. But after some coaxing, the chatbot sat with the puzzle for about a week before engineering its novel attack. Two human researchers then worked for nearly a month to verify that the method appeared correct.
"Given that we are constantly underestimating the power and time of availability of future models, are we really comfortable that two years from now strong encryption won't be threatened?" said Glenn S. Gerstell, the former general counsel at the National Security Agency.

"Mathematicians would tell you that it shouldn't be possible given current computing powers to break strong encryption in any meaningful time," added Mr. Gerstell, who helped write a report on cryptology in 2022. "But I don't think the capabilities of future models in the medium term -- before quantum computing or quantum-proof cryptography -- should be dismissed as trivial in this context."
Privacy

DEF CON Bans Meta-Style 'Pervert Glasses' (theregister.com) 88

DEF CON has banned "Meta-style glasses with recording capabilities," with no exceptions being made even for those with prescription versions. "Be sure to pack non-violating eyewear if you need them," DEF CON said. The Register reports: [The conference's official photo policy] has not been updated since 2023, predating the recent growth of camera-equipped eyewear developed by Meta with EssilorLuxottica under its Ray-Ban and Oakley brands. It states that public photography is permitted but with several caveats that essentially prohibit capturing the image of anyone, except on-stage speakers, unless the photographer obtains consent from the subject(s). "Love to see a 'no pervert glasses' policy at DEF CON," said EFF director of cybersecurity Eva Galperin.
Security

Nvidia, Tech Giants Launch AI Safety Initiative 12

wiredmikey shares a report from SecurityWeek: Nvidia and a large group of technology, cybersecurity, and enterprise software companies have launched new initiative aimed at developing and sharing open source tools, models, and techniques for securing AI systems and agents. The new Open Secure AI Alliance aims to give defenders more open tools for testing, auditing and protecting AI models and agents. Nvidia points to the recent security incident involving OpenAI and Hugging Face, noting that when closed AI tools could not differentiate between attackers and defenders and blocked forensic work, Hugging Face used the open-weight GLM 5.2 model on its own systems to review over 17,000 actions and contain the breach. "The right response is not to deny defenders access to capable open systems. It is to pair openness with strong safeguards, clear rules against malicious misuse, rigorous evaluation and rapid remediation. In cybersecurity, the safer path is the one that gives more defenders the ability to test, verify and strengthen the systems on which society relies," Nvidia said.

Thanks to longtime Slashdot reader SphericalCrusher for also sharing the news.
Social Networks

Big Tech Accused of Stonewalling European Social Media Researchers (arstechnica.com) 53

European misinformation researchers say TikTok, X, and Meta are obstructing access to platform data required under the EU's Digital Services Act through rejections, restrictive quotas, costly APIs, and burdensome security demands. Although regulators have fined X and pushed platforms to improve access, researchers remain skeptical that the changes will provide reliable, reproducible data at scale. Ars Technica reports: In recent years, social media companies shut down public access tools like Meta's CrowdTangle and replaced them with content libraries, or, like X, paywalled their API data, forcing academics to pay "hundreds of dollars a month," said Duncan Allen, a research officer at Democracy Reporting International (DRI) in Germany. Researchers say that without API access, what Iamnitchi describes as the "black holes" in what society knows about how these platforms recommend content or handle reports regarding sensitive content will only grow. Others, like TikTok, cap how many posts any researcher account can pull each day, which Allen said can make it "impossible to study anything at scale."

The DSA was meant to solve this by allowing vetted researchers at credible institutions to have access to API data if they could show it would help in studying systemic risks, from illegal content to threats to fundamental rights. But two years after the law took effect, researchers say they struggle to meet its security requirements and face narrow interpretations from platforms of what qualifies as a systemic risk. Application forms differ by platform, but most require data to be stored on infrastructure that cannot be compromised -- such as a machine physically disconnected from the Internet -- a resource most universities lack, [said Adriana Iamnitchi, chair of computational social sciences at Maastricht University in the Netherlands, who leads research into online disinformation campaigns.]

Even for researchers who secure approval, "there's no guarantee that the data is good," said L. K. Seiling, coordinator of the DSA40 Collaboratory, a German initiative that tracks 46 DSA applications. API data is often difficult for a colleague to reproduce, so a researcher's work cannot be checked for errors, which Iamnitchi said is a "basic requirement of science." DSA40 data shows that of 46 tracked applications, 20 were approved and 14 rejected. But approval rates vary widely: TikTok approved 11 of 13 applications, while X rejected 11 of 23. The true rejection rate is likely higher because the tracker relies on voluntary reporting, Seiling said. "There's no structured advantage for researchers to use this pathway," Seiling said. "Data access as it's set up right now tries to disincentivize researchers."

NASA

NASA Replaces ULA's Vulcan Centaur With SpaceX Falcon Heavy For Solar Storm Research (space.com) 42

There's been a change to NASA's launch of six satellites for solar storms research. Space.com reports that those satellites "were originally slated to lift off on a United Launch Alliance Vulcan Centaur rocket but have now been assigned a SpaceX Falcon Heavy, according to a NASA mission update." [NASA's Sun Radio Interferometer Space Experiment mision — or SunRISE] will fly to space as part of a rideshare mission sponsored by the U.S. Space Force's Space Systems Command. Though it's not stated specifically in the NASA release, that may be a hint as to why the mission's rocket was changed. On its most recent launch [U.S. Space Force mission USSF-87], Vulcan experienced an anomaly in one of its solid rocket boosters — the second such incident to occur during the rocket's four launches to date. Vulcan succeeded in delivering the USSF-87 payload to its designated orbit on that launch, but the recurrence of the booster issue during ascent prompted the Space Force to pause national security launches on Vulcan until it could be addressed. Which mission SunRISE will be manifested on has not yet been released, but Space Force's Space Systems Command [SSC] has already shifted other launches between Vulcan and SpaceX's Falcon 9...

Falcon Heavy is SpaceX's heavy-lift launch vehicle... that consists of three modified Falcon 9 first stages, and has launched 12 times since it debuted in 2018. Four of those have delivered national security payloads to orbit, with the most recent of those, USSF-52, launching in December 2023. Falcon Heavy's most recent flight overall occurred this past April, when it sent the Viasat-3 F3 telecom satellite to orbit. Falcon Heavy's next mission will lift off with NASA's Nancy Roman Space Telescope, currently set for no earlier than Aug. 30. SunRISE is scheduled to launch later this year...

Sientists will use data collected by the satellites "to improve prediction models for impending space weather, which in turn could lead to mitigation plans to better thwart the effects of such solar events on orbital infrastructure."

Thanks to long-time Slashdot reader schwit1 for sharing the article.
Crime

Typo-Squatting Scammers Con South Carolina Town Out of $545K (wpde.com) 23

It started with some underground utility work for the South Carolina town of Surfside Beach (population: 4,155). "Public records confirm that a payment of $545,598.30 was issued," according to a local news station — but the CEO of Wildcat Contractors "stated that the account that received the money is a scammer account and that his company has an overdue invoice for underground utility work completed in Surfside Beach."

Yahoo picks up the story: After the payment issue surfaced, Wildcat said Surfside Beach sent over the email thread containing the payment confirmation. The company told WMBF it noticed multiple red flags in the chain. One involved an email address where "Wildcat" appeared with an extra "i." Another involved documents that the company said included a forged signature taken from a prior notarized document. Wildcat said the money was sent to a spoofing account claiming to be the contractor.
More local reports are unraveling what happened: According to the Wall Street Journal, the town's finance director said a town employee called Wildcat's project manager on March 13, the day the payment was sent. The project manager referred the caller to [Wildcat CEO] Bowker. The town then called Bowker's mobile phone and left a voicemail about the ACH transfer. Bowker told the Wall Street Journal she does not recall the voicemail but acknowledged she may have missed it.
Now a new report released by a law firm hired by the town to investigate "shows it did make an attempt to verify before sending $545,000 to a fraudulent bank account," according to local news reports: According to the report, the town sent an email to Wildcat's legitimate email domain on March 13 requesting a callback for verbal verification before sending the payment. Surfside received a response to that email with a phone number, though it remains unclear whether that response came from a real Wildcat employee or from the scammers. The report found that the fake town domain was used in communications between both parties throughout the process, which the law firm overseeing the investigation said was likely created to facilitate the fraud and delay its discovery.
That seems to be the case in a nutshell: Investigators determined the fraudsters used spoofed and typo-squatted email domains, including surfsidesbeach.org, to impersonate town officials and redirect the payment. The fraudulent domain was created March 9 and was used to help conceal the scheme, according to investigators. Town officials said they are continuing to work with the FBI, South Carolina Law Enforcement Division, and their insurance partners to recover the funds.
"The town has also implemented additional security measures to strengthen payment verification procedures and reduce the risk of similar incidents."
AI

Facebook Offers a Verification System Certifying to Other Users That You're a Real Human (lifehacker.com) 45

Facebook announced Friday they're launching a badge "that verifies there's a real person behind a profile". "You record a short video selfie, which we check against your existing profile photos to confirm a match. The process is free and typically takes just a few minutes. Accounts must meet our trust and safety standards to qualify for verification...." Once verified, your badge will appear across the places on Facebook where it matters most: Marketplace, Dating, Groups, and Profile to start. Over time, we'll add badges in Feed posts as well. There's no subscription fee — you verify once, and the badge travels with you across Facebook... [Y]ou'll see the Verified badge on accounts that have completed the verification process... It's a quick, visible signal, before you respond to a listing, accept a date, or join a conversation, that there's a real person on the other end.
"We're rolling out Facebook Verified in phases, starting in select markets with plans to expand globally..." their announcement adds. "As AI makes it easier to do more on Facebook, a clear signal that distinguishes real people becomes essential. That's what Facebook Verified is for: keeping the moments that matter on Facebook grounded in real people."

Lifehacker shares their reaction: Facebook says it will store your selfie video for "up to 30 days" after verification, which is a one-time process. It's not entirely clear what happens with that video in the meantime, and it's worth noting that Meta has relied on user data to train its AI. Meta AI (and Meta more broadly) is a terrible offender when it comes to privacy and security, so you should consider whether the tradeoff of a verification mark is worth handing over more of your data and read the privacy policy before you agree.

Google also launched a video selfie verification feature this week, though its purpose is to prove your identity should you get locked out of your account. Unlike Facebook Verified, which is meant to be a trust signal to other users, Google's selfie verification allows access to your entire Google account, bringing with it some additional security considerations.

AI

OpenAI's Rogue Agent Went Unnoticed For a Week 81

An anonymous reader quotes a report from Reuters: The OpenAI agent that broke into tech firm Hugging Face went on a dayslong hacking spree that OpenAI didn't notice until well after the threat was contained and the FBI was alerted, according to people familiar with the investigation. The agent -- a program capable of making decisions and executing complex tasks with little or no human oversight -- attempted to break out of its isolated testing environment at OpenAI around July 9, according to two of the people. The intrusion at Hugging Face, which operates as a repository for AI tools and models, began two days later on July 11 and lasted until July 13, said Thomas Wolf, Hugging Face's co-founder. It took several more days for OpenAI to realize its agent was behind the hack, and the two companies only communicated about it for the first time on or around July 20, according to Wolf and three of the people familiar with the investigation.

OpenAI's public disclosure, on July 21, thatone of its agents had slipped out of control and carried out the break-in at Hugging Facedrew global attention. But many details of the hack, including how long the agent went rogue and OpenAI's belated knowledge of it, are being reported here for the first time. Hugging Face is preparing a public timeline of the hack, Wolf said, adding that he could not speak to what happened at OpenAI. In a statement, OpenAI said the hack was unprecedented and "marks an important moment for AI safety." It added that it was reviewing the incident with outside advisers and would eventually publish a technical report.
"Does that mean that they left it unattended and didn't realize what it was doing? Or maybe they did and didn't know how to contain it? Both are equally dangerous and alarming," asked Marley Smith, the principal intelligence specialist at the nonprofit World Ethical Data Foundation.

"The models lie, they cheat, they hack," said Jeffrey Ladish, whose organization, Palisade Research, studies the capabilities and motivations of AI agents. Ladish said the hack should spark broader questions over how much all the leading AI companies are willing to invest in onerous security measures while locked in a race with one another to deploy the best and fastest models. "There has to be government oversight," Ladish said, "because it won't happen otherwise."
Privacy

US Accuses American of Allegedly Wiping His Phone Using a 'Duress' Password During Border Search (techcrunch.com) 218

An anonymous reader quotes a report from TechCrunch: The U.S. Justice Department is prosecuting an American for allegedly providing U.S. border authorities with a passcode that wiped the contents of his phone, according to an indictment and media reports. This is thought to be the first known case in the United States where federal prosecutors have charged someone for the alleged destruction of data using a so-called "duress" password built into a phone's software. According to The Guardian, which covered the story earlier this week following the court's first hearing on Monday, Atlanta resident Samuel Tunick is fighting the charges. Tunick's attorneys said that it was unlawful for U.S. Customs and Border Protection to seize his phone as he arrived back in the U.S. last year, and that any evidence -- including the alleged wiping of his phone -- should be thrown out.

The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick's attorneys confirmed GrapheneOS was running on his phone. The software feature allows the device owner to set a passcode that deliberately wipes the contents of that device if entered instead of the user's unlock passcode. Tunick's case also raises ongoing questions about what constitutional rights can be invoked at the border, which the U.S. government has long asserted is not U.S. soil until a person is authorized to enter.
Bill Budington, a senior staff technologist at the Electronic Frontier Foundation, and Runa Sandvik, a digital security expert who works to protect at-risk people as the founder of security consultancy firm Granitt, told TechCrunch that they had not seen similar cases involving the use of duress passwords.

"I have not seen this before, though I've discussed the potential scenario with activists and journalists over the years," said Sandvik. "I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it's better to not have that data on you when you cross certain borders."

"With a little planning ahead of time, you can always download the data you need once you get to where you're going," said Sandvik.
Privacy

Google Adds Selfie Video As a Log-In Option (engadget.com) 61

An anonymous reader quotes a report from Engadget: You'll now be able to use selfie videos to log into your Google account. It has long been possible to log into Google using your face, via your phone's face unlock or if your passkey login uses biometrics for verification. This is yet another option to get into your account using your face to authenticate your identity, which could be especially useful if you don't have access to the phone or computer you typically use or if you got locked out of your account and none of the other log-in options are working.

[...] Google will ask you to turn your head in certain ways during the verification and every time you use the option to log in. The company says it's to fend off impersonation attempts, such as deepfake videos, and prove you're currently in front of the camera. It will, of course, have to save your selfie video and use it for comparison for future logins.The company says it will encrypt your video and only use to help you sign in, but if you ever change your mind, you can delete it from your Google account.
It's worth noting the option is currently unavailable for Workspace accounts, child accounts and those enrolled in Google's Advanced Protection Program.

You can set it up and give it a try at g.co/signin-selfie.
AI

Linux Kernel Team Publishes 432 CVEs In Two Days 92

Ancient Slashdot reader alanw shares a post from the OSS Security mailing list, where sysadmin Jan Schaumann wonders what to do after the Linux kernel cranked out 432 CVEs in a little over 24 hours: "I understand the position that CVEs were always a flawed way to track or prioritize security changes... But this onslaught really shows it's not feasible to attempt to prioritize individual kernel changes. I'm not sure what to do here going forward." The Register reports: The nixCraft team speculated on social media that AI bug reports are a likely reason for all those kernel CVEs, which wouldn't be without precedent - Linus Torvalds himself said in May that the Linux kernel security mailing list had become "almost entirely unmanageable" due to AI-assisted bug hunting. Nonetheless, Torvalds has described AI as a useful tool for Linux development while still noting it can be a drag for maintainers, both from a workload standpoint and the fact "it keeps finding embarrassing bugs." [...]

Unfortunately for Linux sysadmins, the position in which they find themselves in this current mess isn't one that's readily solved. CVEs might be a messy way to track and prioritize security updates, especially when hundreds of them are published over a short period, but without something better, it falls to IT and security teams to determine which vulnerabilities affect their systems and which kernel updates they need to deploy.
Senior kernel maintainer Greg Kroah-Hartman replied to Jan's post, pushing back on the idea that the kernel's CVE volume is uniquely unmanageable. The kernel isn't special, he argues -- companies everywhere are finally realizing they need to re-evaluate how they update all of their systems and devices, something that's traditionally been "woefully ignored."

On the "just always update" approach, Greg says that's precisely what the kernel community endorses: "This is what the kernel developer community recommends and supports. If you want support from us, do this." Can't manage it yourself? Pay a company for support, or "just use Debian or Yocto as their security practices are amazing." He points to Android as proof the approach scales, calling it "the largest deployment of software in the world" -- billions of devices kept updated "with one very-overworked developer guiding it all."

As for reviewing every CVE individually, he notes this can be largely automated by intersecting the files a CVE touches with the files you actually build, which typically trims the relevant set "down to about 10% of the overall total" -- the approach enterprise distros already take for their customers. Panic-mode selective patching gets a blunt "Good luck with that!" -- regulations like the EU's Cyber Resilience Act are set to legislate that habit away ("rightfully so," in his view), and "your insurance company might wish to have a talk with you as well."

Greg also warns the flood isn't over: "The number of llm-found issues is only on the rise right now, it's going to be a very long 18 months at the least to dig ourselves out of this mess, and people had BETTER be updating their systems all along the way if they expect to be secure in any way." As for the 432-CVE burst itself, he explains it was simply him catching up on a weeks-old, publicly visible review queue over the weekend -- delayed by "a perfect storm of 6 weeks straight of conferences and vacations" -- so it shouldn't have come as a surprise to anyone watching the public git repo.
Television

LG To Ban Residential Proxies From Smart TV Apps (krebsonsecurity.com) 53

An anonymous reader quotes a report from KrebsOnSecurity: The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV. On July 2, [KrebsOnSecurity] featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur found more than 42 percent of apps available for download on LG smart TVs include SDKs that turn one's television in a proxy node indefinitely, and that more than a quarter of the apps made for Samsung's Tizen operating system had similar residential proxy components.

Responding to questions about Spur's research, LG Senior Vice President John Taylor told KrebsOnSecurity the company was working with app developers to remove the residential proxy option from their apps on the webOS platform. Developers that fail to comply, he said, will find their apps suspended. "A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor said. "If this option is not removed, these apps will be suspended." Taylor said LG is committed to keeping residential proxy networks out of its smart TV apps going forward, and that the company's review of those apps is "well underway now."

"As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs," Taylor wrote in an emailed statement. [...] "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight," Spur's Trevor Sutter wrote. "The risk is amplified when consent comes from individuals within the household who use the device but shouldn't give consent, such as minors."
LG is also facing criticism for monitors that automatically install software promoting paid McAfee subscriptions through Windows Update without user approval.
Security

OpenAI Says Its AI Models Acted On Its Own In An 'Unprecedented' Hack (apnews.com) 160

"GPT-5.6 Sol and an 'even more capable' model used stolen credentials and exploited vulnerabilities in the Hugging Face API to obtain secret information used to cheat on evaluations," writes longtime Slashdot reader Dr. Bombay. The Associated Press reports: "We had a significant security incident during evaluation of our models," OpenAI CEO Sam Altman said in a statement posted on social media. AI startup Hugging Face said last week that it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent autonomously acting on its own. "We suspected last week's cyberattack might have come from a frontier lab, given the sophistication of the agent," Hugging Face co-founder and CEO Clement Delangue said in a statement. "Turns out it did!"

[...] "AI is accelerating the discovery and exploitation of vulnerabilities," OpenAI said in its statement Tuesday. "The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities." Delangue said he spent the past 24 hours working with OpenAI, "and we strongly believe there was no malicious intent on their part. It's quite mind-blowing that all of this happened autonomously!" Delangue added that it "might be the first incident of its kind."

Slashdot Top Deals