Bug

Google Told Researcher 'Nice Catch!' Then Denied Bug Bounty For Flaw It Still Hasn't Fixed (theregister.com) 38

Security researcher Justin O'Leary says Google initially accepted his Config Connector privilege-escalation report as a high-priority, high-severity bug, then denied a bounty by declaring the behavior "working as intended." According to The Register, a Google rep initially praised O'Leary's report with a "Nice catch!" before the cloud giant reversed course, declaring that no vulnerability existed and therefore no fix or reward was warranted. "The bug report, however, is still marked high-priority and accepted," the publication notes. The alleged flaw, dubbed ConfigConfusion, could let a Kubernetes namespace user exploit an overprivileged service account to become a GCP organization owner with only a few lines of YAML and little apparent audit visibility. O'Leary details the incident in a blog post. The Register reports: According to O'Leary, Config Connector doesn't perform an authorization check, and this allows any Config Connector service account with org-level permissions to bypass Identity and Access Management (IAM) authorization and gain the highest level of control (roles/owner) to an entire GCP Organization -- the root node of all of a company's resources within Google Cloud. On March 27, a Google security engineer accepted O'Leary's report and told him: "Nice catch!" The employee said that they filed a bug based on O'Leary's report with the relevant product team and assured him the Chocolate Factory's security squad would work with relevant Google Cloud people to fix the flaw. "We'll work with the product team to ensure this issue is address. We'll let you know when the issue was fixed," the engineer said. "In the meantime, review the payment option selected in your bughunters.google.com profile."

Google assigned the bug P1 priority and S1 severity, signifying a flaw worthy of urgent repair because it affects a large percentage of users and can disrupt core organizational functions. "I figured that was the end of that," O'Leary said in a phone interview with The Register. Eleven days later, on April 7, he received a new message from a Google Security Bot reversing the earlier decision. The Reg viewed the email, and O'Leary included a screenshot in his Thursday writeup. The message said that the Cloud Vulnerability Reward Program panel decided that the "security impact of this issue does not meet the criteria to qualify for a reward."

After reviewing the bug report, Google determined the software "is working as intended," the message continued. It also noted that the program's decision not to pay a bounty "does not mean that the product team won't fix the issue." Nearly three months later, the case remains P1/S1 with the status "in progress (accepted)." Google hasn't assigned a CVE or issued a fix. O'Leary didn't receive any reward for his research. [...] "This is a pattern," O'Leary told [The Register]. "This is just how these trillion-dollar companies deal with people like me. In my day job, we use GKE, and it's incredibly frustrating on my end, when I find a critical vulnerability in the system that's being widely used, and I can't even get the vendor to patch their own stuff."
A Google spokesperson told The Register: "The issue reported does not qualify for a reward because the GCP IAM authorization bypass is only exploitable if an attacker has access to a Config Connector Service Account that's been granted the Organization Admin role by the organization (i.e., it is privileged). Additionally, an attacker would first need to gain entry to an organization's environment (e.g., an exposed container) in order to leverage the privileged Config Connector instance and execute commands with administrative authority, such as the IAM bypass. Granting this level of access to the Config Connector Service Account goes against Google Cloud's publicly shared best practices and the principle of least privilege."
Open Source

Google, Microsoft, and OpenAI Back Linux Foundation's Appia AI Standards Initiative (nerds.xyz) 24

BrianFagioli writes: Google, Microsoft, OpenAI, Arm, Mastercard, Siemens, and other companies have joined the newly launched Appia Foundation under the Linux Foundation. The project aims to create common specifications and assessment frameworks that organizations can use to demonstrate AI systems meet emerging safety, trust, and compliance requirements. According to the Linux Foundation, the framework is designed to allow conformity evidence to be reused across the AI supply chain, potentially reducing duplicate assessments and compliance costs. The announcement comes as governments around the world move toward enforcing AI regulations and organizations face increasing pressure to prove AI systems are trustworthy. "As international standards and legal frameworks become more established, global organizations need a consistent, practical way to verify that AI systems conform to new expectations," said Jim Zemlin, CEO of the Linux Foundation. "The Appia Foundation establishes a neutrally governed environment where the entire industry can collaborate on a common assessment framework. By building this infrastructure in the open, we are helping organizations reduce complexity, lower operational costs and build trust."

Craig Shank, Executive Director of the Appia Foundation, added: "AI systems now make decisions about people's loans, their children's schools and their jobs. People on the receiving end deserve to know those systems were built and assessed against criteria that hold up to scrutiny. The Appia Foundation was formed to do that work: creating publicly available specifications that organizations across the AI value chain use to demonstrate their systems meet those criteria. By establishing this open framework, we are building the accountability layer required to scale safe and trusted AI across major industries."
Chrome

Google Chrome's Next Update Will Mark the End of Popular Ad Blockers (9to5google.com) 161

Google is removing Chrome's last remaining workarounds for Manifest V2 extensions, effectively ending support for legacy ad blockers such as the original uBlock Origin. 9to5Google reports: CyberNews points out a Chromium commit that removes support for the "kExtensionManifestV2Disabled" flag, which is referred to as "dead code" seeing as Chrome no longer supports Manifest V2 extensions. This removal acts as the final stop for many Manifest V2-based ad blocker extensions that were still in use today -- the flag was effectively a loophole to continue using these extensions.

A Googler on the commit explains: "MV2 extensions are no longer allowed in any supported version of Chrome, and we are removing support for them and the associated functionality. We won't be able to provide / maintain this functionality indefinitely due to the complexity and tech debt, as well as the security risks it entails (we've actually found a number of bugs that are specific to MV2 lately). Of course, other browsers can continue supporting these if they so desire."

This will also impact other Chromium-based browsers, though the comment notes that "other browsers can continue supporting these if they so desire." Neowin points out that Microsoft Edge and Opera are likely to follow suit. Chrome 150, set to be released later this month, will remove this flag, while other leftover bits of Manifest V2 will be removed in the v151 release.

Education

Google CEO Largely Avoids Discussing AI In Stanford Commencement Speech (nerds.xyz) 37

BrianFagioli writes: Google CEO Sundar Pichai delivered Stanford University's 2026 commencement address, but despite leading one of the companies at the center of the AI boom, he spent very little time discussing artificial intelligence. Instead, the speech focused on optimism, working on hard things, and following your interests. The omission is notable given how many graduates are entering a job market being reshaped by AI. While Pichai briefly referenced a "rewiring of technology," he largely avoided discussing AI's impact on careers, automation, or the future of work. Was the Google CEO intentionally steering clear of a controversial topic, or was he simply trying to deliver a timeless commencement speech rather than a technology-focused one? Hyping AI during a commencement speech has been a surefire way to get boos -- unless you're Apple cofounder Steve Wozniak, who reminded college graduates that they already posses "AI" of their own: "actual intelligence."

You can read Pichai's commencement speech here.

"If you're not from here, California is advertised as being really lush and green. But when I looked out the window, it was more... brown," said Pichai during his speech. "I guess I said this out loud, I'm not sure why. My host, Mrs. Jane Earl, gently corrected me. 'We prefer to call it golden,' she said.And that's exactly what I mean by choosing optimism. It's about reframing for the positive: Where I saw brown, she saw golden. This slight change of perspective had a huge ripple effect on how I thought about the world around me."
Education

Are Many College Students Losing the Ability to Read? (futurism.com) 264

Futurism reports: in a new essay for The Chronicle Higher Education, university-level literature and writing instructor Tyler Jagt recalls how not a single one of his students could get through an assigned 20-page article, something that he had read "without complaint" as an undergraduate a decade ago.

One student confessed that the reason they didn't finish was that they kept losing track of what the paper was about. And there's no doubt that they're not alone. Jagt cites the 2024 National Assessment of Educational Progress reading assessment results released last year. It showed that 12th grade reading scores were at the lowest level since the assessment began in 1992. Nearly a third of those 12th graders scored below the assessment's "basic" level in reading, meaning they likely "cannot draw general conclusions based on concepts presented explicitly in a text." Younger children aren't better off: a recent report from the Annie E. Casey Foundation found that 70 percent of fourth graders, or around two million kids, can't read at a proficient level.

"What I am seeing in my classroom is no longer a hunch," Jagt writes. "There is a measurable, generational collapse in sustained reading and writing, and the academy is responding to it with improvisation and exhaustion rather than the structural overhaul it requires...." Jagt cites an MIT study that found users who used ChatGPT during cognitive tasks like writing essays showed lower brain activity in areas associated with creativity compared to students who only used a traditional Google Search or didn't lookup information at all. An astonishing 83 percent of the AI users couldn't quote a single line from the essays they had just written, and capstoning the alarm, the brain activity in the AI users didn't return to normal when they were later asked to write without AI...

On our pernicious pocket devices, Jagt touted a 2017 study that found that simply having a smartphone physically nearby — even if it's face down or turned off — reduced available cognitive capacity and impaired cognitive functioning. "So when a student tells me they 'kept losing track' of a 20-page article, I have to acknowledge that they may be describing a measurable neurological condition," Jagt wrote. "The neural pathways that support sustained attention are built by use, and they atrophy without it. Your body is a use-it-or-lose-it system, and the brain is no exception."

Sunday an "Ask Reddit" question went viral — drawing over 11,000 upvotes — for its question to any teachers reading Reddit. "Is the 'Gen Alpha can't read (write, or do math ext)' crisis real? If so how bad is it?" Some responses...
  • "The run of the mill non-honors kids have gotten really bad," posted one high school teacher. "Very low tolerance for working hard, very short attention span, very short stamina for active listening... It's the group that is the most worrying because a decade ago, I'd estimate that maybe 10-20% of kids at a school are like this, and now it's probably 40-50% of each graduating class... Then there's of course the bottom 10-20% kids (excluding the special ed/severe/moderate learning disability kids). This is what the viral videos are about and it's not an exaggeration. They can't read, write, or do very basic math like multiplication or division as a 17 year old."
  • "This is the first year the MAJORITY of my class cheated on their first essays...." posted one high school English teacher. "It was also the first year a kid yelled 'We don't care about your fucking books, Miss!' while I was in front of the class presenting books they might be interested in for their book reviews... Almost all of them cheated on the book review they had to write."

Thanks to long-time Slashdot reader schwit1 for sharing the article.


IT

IT Workers Are Now Struggling to Find Work, as 'Picky' Companies Demand AI Skills (msn.com) 174

"Battered by years of mass layoffs, California tech workers were hoping the job market would rebound this year," reports the Los Angeles Times. "But things are getting worse." The class divide is widening in Silicon Valley as a tiny group of employees is landing unprecedented packages for AI skills, while many others struggle to find work. The have-nots are doing everything that used to guarantee great jobs — refreshing resumes, optimizing LinkedIn profiles and doing interviews — but companies are much more picky these days. The tech jobless are rethinking their lives. Some are taking pay cuts, others are leaving tech. Some are going back to study or launch startups. Some have retired....

Since 2022, more than 815,500 tech workers have been laid off, according to Layoffs.fyi, a website that tracks job cuts. The tsunami of pink slips surged in 2023, when companies that had gone on hiring sprees during the COVID-19 pandemic began to cut back. From January to April, U.S. tech employers announced 85,411 job cuts this year, up 33% from the same period last year, according to global outplacement and executive coaching firm Challenger, Gray & Christmas. The Public Policy Institute of California estimates that the number of information jobs — which includes jobs in hard-hit Hollywood as well as tech — tumbled 17% between the middle of 2022 and this February. The San Francisco Bay Area has been hardest hit, the institute said in a recent report, with the number of jobs declining by 0.4%, compared with 7.5% growth over a similar time span before COVID-19 slammed into the U.S. economy.

Tech layoffs are also spilling over into other industries. Automaker General Motors laid off roughly 600 workers in its information technology department, and Walmart is reportedly laying off or relocating roughly 1,000 workers in its technology and products teams. Recruiters say companies have become much more selective, requiring AI skills, combining different positions and interviewing more people for each job. "You're seeing elongated hiring cycles," said Robert Lucido, senior director of strategic advisory at Magnit, a California company that helps tech giants and other businesses manage contractors, freelancers and other contingent workers. "There's more opportunity to fill the need that they truly want."

Paul Flaharty, district president at staffing firm Robert Half in Los Angeles, said companies are laying off workers, but also creating new roles tied to AI initiatives. "For individuals that are displaced, it's really important that they find ways to upskill themselves so that they can make themselves as attractive as possible for these new jobs that are being created," he said. Kira Martins was already taking on more work in a small team at Snap — the parent company of disappearing messaging app Snapchat — when she was laid off in April. The company said the layoffs were to cut costs as it focuses on profitability, noting how employees are using AI to "reduce repetitive work, increase velocity, and better support our community, partners, and advertisers...." Martins, a 36-year-old Los Angeles resident, views AI as a tool and is optimistic about finding her next role. People still need to decide how to use AI and check the work it generates, she said. "In tech, you want to be a first adopter, because if you don't move quickly, it's very easy to become irrelevant," she said. "Everyone's kind of hopping on the AI train."

A former Google worker (laid off more than a year ago) says he's still job hunting, according to the article, and "he's learned it's not enough to just apply in this competitive market. Workers really need to network and leverage their connections to get seen by hiring managers and stand out."

But when 64-year-old product manager Bruce Bowers lost his job at Oracle — along with thousands of others — he just started his retirement early.
AI

Will Meta's $14 Billion Bet on AI Ever Pay Off? (cnbc.com) 65

"A year after spending over $14 billion to bring in Alexandr Wang and a group of his top Scale AI engineers to revamp its artificial intelligence efforts, Meta is at least back on the map in AI," reports CNBC, "though it's still far behind OpenAI, Anthropic and Google in the market." Wang's big accomplishment was the delivery of the Muse Spark AI model in April, marking Meta's first jump into proprietary foundation models and away from a strict adherence to open source, or open weight as it's more commonly called in AI... "Meta needs to provide more proof points of both adoption and commercialization," said Ralph Schackart, an analyst at William Blair who recommends buying the stock. "Investors are looking for Meta to monetize a new AI-first product, beyond the substantial positive impact AI is having on enhancing the advertising models." Wall Street, at least so far, is unimpressed. Meta's stock is down 18% over the past 12 months, the worst performer in the megacap group, along with Microsoft, which has its own challenges in AI. That's even after Meta reported 33% revenue growth in the first quarter, the fastest rate of expansion for any period since 2021.

For Meta, the problem started with what some industry experts called, in hindsight at least, a strategic blunder. The company jumped into AI with its Llama family of models, offering an open-source approach that allowed developers to freely tinker, while the other big model makers charged for access. In April of last year, Meta's release of Llama 4 fell flat, failing to captivate developers and leading Zuckerberg to reconsider his company's approach to AI development... Since the release of Muse Spark, Meta has unveiled new AI and business-related subscription plans as part of an effort to expand its business beyond online ads. Historically, it hasn't worked. Meta still counts on ads for 98% of revenue. Schackart said he wants to see "tangible evidence of a growing list of new, AI-first products created by Muse Spark, even if monetization lags." He said that's "what investors are looking for."

No matter how good Wang's model may be, Zuckerberg has a high hill to climb with developers coming off the Llama debacle. "I think the AI community largely ignores Meta at this point," said Rob May, CEO of the startup Neurometric, which works in the realm of token engineering.... Krish Subramanian, the CEO of consulting firm KOI AI and former product head at IBM Consulting, said developers are more excited about Google's AI models than what Meta is offering. The appeal of Llama was that it specifically targeted developers wanting open-weight alternative models, while with Muse Spark, Meta has made little effort in that direction, he said. "The lack of developer trust will come back to hit them if they don't focus on third-party developers," Subramanian said, noting that it took years for Microsoft to regain trust from open-source coders during the early days of Azure. "To just focus on a walled-garden kind of an ecosystem and ad revenue as the main source of income, they probably will never become the big player," he said.

A Meta spokesperson pointed to Wang's recent comments about the company's continued support for the open-source ecosystem, and said Meta still plans to offer outside developers access to Muse Spark's underlying technology via an API, as it previously announced. "We're already testing with some early partners, and look forward to releasing it this month," the spokesperson said.

"That Zuckerberg's metaverse and virtual reality ambitions have generated over $80 billion in total losses since late 2020 makes the AI pitch a tougher sell," the article points out, citing this observation from Howard Yu, business professor at Switzerland's International Institute for Management Development.

"He's running out of the space for his credibility to last," Yu said. "I think the virtual reality foray may have burned up a lot of his goodwill in front of investors."
Oracle

ShinyHunters Hacked 100+ Organizations By Exploiting an Oracle PeopleSoft 0-Day (theregister.com) 4

ShinyHunters claims it exploited a critical Oracle PeopleSoft zero-day to compromise more than 100 organizations, including the University of Nottingham, where it says it stole 40GB of student and billing data. "ShinyHunters posted the UK university on its data leak site on Tuesday before publishing the stolen files later that same day, presumably because the school refused to pay the extortion demand," reports The Register. From the report: "University of Nottingham on our leak site is one of the first publicly confirmed incidents," a ShinyHunters spokesperson told us. "We have only just started outreach to affected orgs and are actively looking to reach an agreement with affected orgs." They didn't say when they planned to post the other 100 or so claimed victims.

A Google threat intelligence report published Thursday afternoon corroborated ShinyHunters' claims to have compromised more than 100 organizations. Google said it spotted malicious activity, "consistent with the exploitation of CVE-2026-35273," between May 27 and June 9, and notified more than 100 global orgs "whose IP addresses correlated with potentially vulnerable endpoints." Most of these, we're told, are based in the US and 68 percent are in the higher-education sector.
Oracle has released a "patch availability document," but it's unclear whether a patch is currently available.
The Courts

Google Sues Chinese Cybercrime Operation That Used Gemini AI To Send Scam Texts (techcrunch.com) 10

An anonymous reader quotes a report from TechCrunch: Google is suing to dismantle the infrastructure behind an alleged massive AI-powered cybercrime operation. On Friday, the tech giant announced a lawsuit against an alleged Chinese cybercrime network called Outsider Enterprise, which Google says uses AI in its campaigns to send scam text messages impersonating Google and other brands to steal passwords and credit card numbers.

Outsider Enterprise has financially scammed "hundreds of thousands of victims" with losses "estimated in the millions." The group deployed 9,000 fake websites, 1 million fraudulent web domains, and 2.5 million texts sent to Android users in a two-week period, according to Google. "55,000 spam texts were flagged by Android users in just two weeks this past May -- that's more than two text spam complaints a minute," Google said.

Google said it uses "AI-powered tools to fight AI-powered scams", which enable the company to detect scams and alert users of suspicious calls and text messages, leading to the interception of more than 10 billion scam messages a month. The company said it has been collaborating with AT&T, T-Mobile, and Verizon to block the scam text messages and said it is coordinating with the FBI, which is taking unspecified law enforcement actions.

Open Source

Euro-Office 1.0 Arrives To Open-Source Infighting: 'Compatibility Is Not Sovereignty' (zdnet.com) 81

An anonymous reader quotes a report from ZDNet: If digital sovereignty is important to you, and it certainly is in the European Union (EU), then you'll be pleased to know that EuroOffice, a new open-source browser-based office suite alternative to Microsoft 365 and Google Workspace, has officially reached its first stable release. A coalition of EU-based companies, including Nextcloud, Ionos, and other Euro-Stack participants, is positioning Euro-Office as a cornerstone of European digital sovereignty. However, The Document Foundation (TDF), LibreOffice's steward, accuses the project of reinforcing Microsoft's document lock-in, which TDF argues isn't friendly to open standards.

Setting aside the open-source politics for the moment, here's what Euro-Office brings you. The release went live on June 9. It is, however, not a stand-alone office suite. As the software's backers explain in a FAQ, "Euro-Office is more of an integration component. It merely handles document editing itself. Storage, as well as navigation, permissions, and sharing logic, have to be offered by a platform it is integrated in, like Proton Docs, Nextcloud Hub, or OpenProject." So, while you can install Euro-Office on your own Linux server, you'll need to integrate it yourself. If you're not a Linux expert, however, don't give up hope. Some companies have already released packaged, ready-to-install Euro-Office stacks, including Nextcloud Hub 26 Spring, Ionos' Nextcloud Workspace, and Office.eu. These initial deployments are web-based rather than standalone desktop suites.

The goal, organizers say, is to give European organizations a way to host their office suite on EU infrastructure under EU law, while maintaining an experience familiar to Microsoft Office users. Specifically, Euro-Office is meant to be "a solution for editing documents, spreadsheets, and presentations, developed as a true sovereign community collaboration of over a dozen different organizations."
TDF's main objection is that Euro-Office's decision to default to Microsoft's OOXML format undercuts its claims of European digital sovereignty, since OOXML remains closely tied to Microsoft Office behavior and control. "Compatibility is not sovereignty," TDF warned, saying a European-branded suite that saves files in OOXML by default "is de facto an ally of Microsoft in its content lock-in strategy."
The Courts

German Court Holds Google Liable For False AI Overview Answers (the-decoder.com) 93

A Munich regional court has ruled (PDF) that Google can be held directly liable for false claims in AI Overviews. The case involved AI Overviews falsely linking two publishers to scams and shady business practices, with the court rejecting Google's argument that users could simply check the sources themselves. The Decoder reports: Google's AI overviews work nothing like traditional search results, the court argues. The AI rewrites and judges results "in its own words and according to its own structure," the ruling says. In the case at hand, for example, it opened with confident claims like "Yes, [company] is known for dubious business practices," then built its own structure with a summary, red flags for the alleged scam, and tips for users. The court also found that the AI overview made claims "that are not even made in the search results." None of the linked sources drew any connection between the plaintiffs and the shady companies the AI mentioned. The court called these "the defendant's own statements." Google built the AI, Google offered it to users, so Google owns what it produces, "because it alone has influence over the AI's offering and the algorithms with which the AI operates."

The court also examined existing rulings from Germany's Federal Court of Justice (BGH), which gave traditional search engines and autocomplete limited liability. The BGH had argued that search engine operators were only liable as indirect infringers because they merely made third-party content findable. A proactive duty to check results would threaten how search engines work. The Munich court found that this reasoning doesn't apply to AI overviews. A regular search engine just points to outside websites. But AI overviews generate "independent, new, and substantive statements" by evaluating and combining content from various third-party sites. And only Google can check those statements, the court said, "at least by comparing the underlying third-party websites with its own statements based on them." The court also noted that the AI overview is "by no means absolutely necessary" for using the internet. Traditional search results already help users sort through information, the AI overview is just an extra feature.
At the hearing, Google argued that users could check the linked sources themselves to verify if the AI summary was correct. It also said that these users knew "that information generated with AI should not be blindly trusted." The court rejected this.
Microsoft

Microsoft Smashes Record For Biggest Ever Patch Tuesday Update (computerweekly.com) 51

An anonymous reader quotes a report from ComputerWeekly: Microsoft has issued patches for about 200 flaws in its latest monthly Patch Tuesday drop, blasting past a previous record high of almost 170 common vulnerabilities and exposures (CVEs) set in October 2025. Among a great many others, the latest update from Redmond fixes a total of 32 critical CVEs and three zero-day flaws. Dustin Childs, head of threat awareness at TrendAI's Zero Day Initiative, said: "We are heading into a high-stakes summer for cyber security. June's record-shattering drop ... is a stark warning that AI is supercharging flaw discovery at an uncontrollable scale. The current number of CVEs shipped by Microsoft this year exceeds the total number of CVEs shipped in all of 2018. It is extraordinary that Microsoft can produce so many patches in a single month, and I expect many testers are wondering what quality issues may exist."

And with the addition of hundreds of CVEs in Google Chrome and Microsoft Edge (Chromium) and other third-party flaws taking the total to almost 600, Chris Goettl, vice president of security product management at Ivanti, said talk of a 'Patch Apocalypse' was no longer unwarranted. "We are in the Patch Apocalypse. The Patch Apocalypse is now," said Goettl. "This is not intended to be a scare tactic. It is meant to outline the challenge that many organizations were anticipating, but the new generation of LLMs [Large Language Models] has accelerated significantly in the first half of 2026."

"There are going to be more CVEs resolved by vendors at a faster and more continuous pace than we have ever seen previously. Unfortunately, this will also include more zero-day and n-day exploits than previously seen as well. The window from release from a vendor to exploitation had already shortened to five days as of 2023 threat intelligence data." Goettl said that many suppliers have acknowledged the need to use AI tools in their security research to identify and resolve flaws, with Oracle, Google Chrome and Mozilla all upping the cadence of their updates. Whether or not Microsoft follows suit remains to be seen.

Cellphones

UK PM Gives Tech Firms Ultimatum To Block Explicit Images on Children's Phones (theguardian.com) 120

UK Prime Minister Keir Starmer has given Apple, Google, and other tech firms until September to introduce device-level protections that prevent children from taking, sharing, or viewing explicit images. "If businesses do not comply within three months, legislation will be brought forward requiring the protection to be added to all phones and tablets sold in the UK," reports The Guardian. "Tech firms that fail to do so could face fines, and their senior managers could be made criminally liable." From the report: "Today, I am calling on tech companies operating in this country to introduce vice controls that prevent children from sending and receiving sexually explicit images. Because this is not an impossible challenge," he said. "If they choose not, then we will act and we will change the law." [...] Under the changes, sexual predators will be prevented from being able to exploit and abuse victims through their devices, and children stopped from being able to access pornography, the Home Office said. Adults will still be able to take, share or view nude content once they have verified their age.

In the Commons, Melanie Ward, the Labour MP for Cowdenbeath and Kirkcaldy, said: "It's time to stop asking social media companies to make their products safe, and instead time to start requiring them to do so through regulation." Clive Efford, the Labour MP for Eltham and Chislehurst, said the "sociopaths" running social media platforms had no concern for the welfare of children. "The only message that they're going to listen to is if there's legislation put before this house that is going to act and send a clear message to them." The proposal is designed to sit alongside the Online Safety Act, which requires companies to have processes for removing material that is illegal or harmful to children.

Biotech

Jeff Bezos Is Funding a Wild Hunt for the Brain's 'Core Algorithm' (wired.com) 193

Jeff Bezos is backing Flourish, a new "neuro AI" startup with $500 million in funding and a reported $2.5 billion valuation, that aims to reinvent AI by studying the brain's architecture and building systems that learn continuously while using far less power than today's large language models. The company's long-term bet is that neuroscientists and AI researchers working together can uncover the brain's "core algorithm" and eventually create brain-inspired AI that runs on a tiny fraction of current compute. Wired reports: Rob Williams knows how to pitch Jeff Bezos: You write a press release as if your product has already been built. Bezos reads it and gives a thumbs up or down. Williams went through this process a lot as an executive on Amazon's "S-team," in charge of software products such as Alexa, until his departure last fall. But the pitch he made a few weeks later -- in December 2025 -- was different. Now he was collaborating with Thomas Reardon, a neuroscientist and repeat startup founder, and approaching Bezos as a funder, not a boss. Here's what Bezos, sitting on his yacht somewhere, read while Williams anxiously watched on Zoom: "Flourish is a neuro AI company that is solving the two most difficult problems facing AI today: power efficiency and continuous learning. We are building Cortex AI, the first synthetic intelligence system designed to match the computational capacity, learning efficiency, and power budget of the human brain."

A month later, I'm lunching with Reardon and Williams in the Flatiron neighborhood in New York City. Reardon gets right to the point. AI has dug itself into a hole, he says. Though increasingly powerful, large language models are greedy consumers of computer power and data. Though the inspiration for LLMs was rooted in biology, current frontier models have little in common with the human brain. A person uses about 20 watts of energy to process information; a single chip in an AI training cluster uses more than 30 times that amount. The hyperscalers require thousands of chips and gigawatts of energy, enough to power small cities. And those models need to suck up virtually all of what humans have written. Each new model requires more, more, more. For all of that, the models don't learn. Once you train them, they're stuck. The goal, Reardon tells me, is to build "a synthetic artificial intelligence brain that runs on 50 watts or less." It should adapt to its conditions, be as nimble as a human mind, and burn a tiny fraction of an LLM's compute power and energy. The proof of concept is thriving inside our skulls. "There's something fundamentally wrong with saying, "I need to basically read every book ever written 20 times over in order to learn English,'" Reardon says. "A human baby does it with a couple hundred thousand utterances."

Reardon and Williams haven't figured out yet how to build systems that match the magic of a human brain. What they have is a belief that an expert, well-resourced team -- of AI researchers and neuroscientists working essentially side by side -- can find the answer. The neuroscientists will conduct original wet lab experiments with some of the most advanced lab equipment available, to hunt for usable intel on the brain's architecture. They plan to release the models they're currently developing as near-term products on the path to a full reinvention of AI. The fuzziness of the proposal didn't bother Jeff Bezos. After reading Williams' two-pager, he chipped in $50 million. Other funding came from Lux Capital, Google Ventures, and Catalio, among others. Bezos then almost doubled his initial stake and told Reardon he'd have given more if they'd asked. Now with a war chest of $500 million and a reported valuation of $2.5 billion, Flourish just needs to invent a new way to do AI.

AI

Failing CS Grades Soar At UC Berkeley As Professors See Greater AI Usage (dailycal.org) 110

The University of California at Berkeley discovered the percentage of failing grades in multiple CS classes this spring "is significantly higher than past semesters," reports the campus's student newspaper.

"Instructors point to students' increased reliance on AI, lack of mathematical preparedness and understaffing as potential contributing factors." According to [coursework platform] Berkeleytime, 35.3% of CS 10 students and 10.6% of CS 61A students received F's in spring 2026. In spring 2025 and spring 2024, the percentage of F's did not exceed 10% for either class. The electrical engineering and computer sciences department's grading guidelines state that 7% of students in lower division courses, including CS 10 and CS 61A, should receive D's and F's...

[UC Berkeley teaching professor Dan Garcia, who taught both classes] believes the "primary driver" of these abnormally high failing rates is due to a "vast increase in academic dishonesty" due to students' usage of large language models, such as Claude, ChatGPT and Google Gemini. "Some of the numbers that you saw from the number of students who receive failing grades were because we caught them (cheating) and prosecuted them and are sending their cases to the Center for Student Conduct," Garcia said. "But in other cases, it's students who are leaning a little too hard on LLMs to do their work for them, and then at exam time just really aren't ready." According to Garcia, nearly 30 students in CS 10 were "caught cheating on take-home exams" in spring 2026...

In addition to overreliance on AI, Garcia also pointed out that many students are underprepared mathematically, a concern echoed by campus associate teaching professor Gireeja Ranade. Ranade noticed a similar lack of prerequisite mathematical skills in her spring 2026 EECS 127 class, "Optimization Models in Engineering," which she described as "differently challenging" to teach this semester. The class saw a 16.8% F rate, far higher than the 5% of D's and F's that the EECS department describes as "typical" for an upper division course...

Both Garcia and Ranade have joined more than 1,300 UC faculty in signing a petition calling for the reinstatement of ACT and SAT standardized testing scores for STEM admissions in the UC system.

Thanks to long-time Slashdot reader theodp for sharing the article.
Businesses

Google Will Pay SpaceX $920 Million Per Month For Compute 50

Ahead of its upcoming IPO, SpaceX announced that Google will pay the company $920 million per month for access to roughly 110,000 Nvidia GPUs and related compute infrastructure. Google says the agreement is short-term "bridge capacity" to meet stronger-than-expected demand for Gemini Enterprise, while SpaceX is using deals like this and its Anthropic contract to bolster its pitch for a historic public offering. TechCrunch reports: The deal is similar in length and scope to the one SpaceX announced with Anthropic in late May. As part of that deal, Anthropic agreed to pay SpaceX $1.25 billion per month through 2029 to rent all the available compute from its Colossus 1 data center near Memphis, Tennessee that xAI -- now part of SpaceX -- originally built for its own artificial intelligence efforts.

Google's deal appears to be paying for roughly half the amount of compute that Anthropic has access to at Colossus 1. SpaceX didn't say which specific data center Google would be using. CEO Elon Musk has previously suggested his company would reserve the Colossus 2 data center for xAI. Anthropic was significantly limited in its compute capacity prior to its deal with SpaceX, raising usage limits on the same day the deal was announced. Google is in a very different position, with some estimates naming it as the world's largest single owner of AI compute.

[...] Also like the Anthropic deal, the agreement with Google includes a cancellation clause. Both SpaceX and Google have the option to terminate the agreement with 90 days notice after December 31, 2026. Google's access to the data center will ramp up "through September at a reduced fee," according to the filing. "If we fail to deliver access to the committed amount of GPUs by September 30, 2026, then following a one-month grace period, Google may immediately terminate the agreement or accept the number of GPUs provided" with a reduction in the monthly fees, it reads.
Google

Google Says It Will Replenish More Water Than It Uses At Data Centers (9to5google.com) 92

An anonymous reader quotes a report from 9to5Google: There's been a lot of pushback in recent months around the impact of AI data centers on local communities, with the use of water being a key issue for many. Google, in an expansion of its "water stewardship" programs, is making commitments that include replenishing more water than it uses at its data center sites. AI data centers go through a lot of water use in cooling the hardware used to power models, and Google is no exception. While Google stands by saying that the impact of AI data centers on U.S. water consumption is "small," it also says it is focusing on "protecting local water resources in all aspects of our data center operations."

In a post, Google explains five new commitments regarding water use at its data centers in the U.S. These include replenishing more water than is consumed at data centers, helping local utilities to modernize water infrastructure, using air-cooled solutions in areas where watersheds are at risk, "transparently" reporting water use at data centers, and focusing on "alternative and reclaimed" water solutions. [...] In a linked paper (PDF), Google says it will replenish 120% of the water it uses at data center sites by 2030. Google is also committing $17 million to new water stewardship projects in Georgia, Iowa, Michigan, Minnesota, Missouri, Nebraska, and Texas in addition to 165 other projects already in place throughout the U.S.

Social Networks

Companies Are Using Reddit To Manipulate ChatGPT and Google AI Search (404media.co) 44

An anonymous reader quotes a report from 404 Media: The moderators of the biohacking subreddit say that peptide and hormone replacement therapy companies have been surreptitiously spamming Reddit in an attempt to get their posts scraped by AI chatbots. The strategy is an effort to systematically manipulate the answers provided by chatbots by manipulating the underlying source material that those chatbots will scrape -- in this case, a popular Reddit community. In a post last week, the moderators of r/biohackers said they would be banning new posts about peptides and hormone replacement therapy (HRT) because of attempted manipulation by the companies that make, market, and sell them. [...] "As AI search engines increasingly pull answers from Reddit, companies are using us for AEO. On top of that, there's been an explosion of peptide interest and AI usage flooding the sub. Together, this has put serious pressure on content quality," a post by the moderators read.

[...] It has become incredibly difficult to stop Reddit manipulation, because the firms doing it are getting more sophisticated. The moderator said that there are really standard and long-running strategies where brands will hop in the comments and suggest their products: "That type of marketing has always existed and if people want to try something new because the brand resonated with them, cool. That's the way marketing should flow in my mind," they said. "But what I'm seeing that is way scarier to me is that there are companies that will reverse-engineer the actual prompt patterns that are prioritized by LLMs, and so you'll see someone post a super clickbait, high-traction, vague question like 'Is all the hype around Vitamin D actually worth it?" they added. "And that thread will do really well because everyone on biohackers actually has an opinion, so it gets engagement and prioritized by LLMs, and then brands will sneak in and they'll embed their brand mentions in those threads in the exact right places in a seemingly organic way. But none of it is organic, the entire thing is a strategy by an agency to prioritize brand mentions or a narrative within an LLM."

The Reddit accounts that are doing this are "warmed up" or are made to seem human, meaning they have a posting history that is not just promotional. This makes them much harder to detect and moderate against. Some of the agencies doing this are paying real people to post promotional content, or have built communities where people are incentivized to post promotional content. The moderator said that Reddit's automated moderation tools have been helpful, but that the type of promotion happening has become so sophisticated that it has become more of a you-know-it-if-you-see it kind of thing. "A lot of it has become pattern recognition," they said. "You literally just sort of know what to look for. But the problem is you don't want to become punitive to the people who aren't doing this maliciously, and so I think the over-moderation risk is very real."

AI

Meta Keeps Delaying the Release of Its New AI Model to Developers 5

Meta has reportedly delayed the developer release of its Muse Spark AI model API multiple times, and as of Tuesday, had no scheduled launch date, according to the Wall Street Journal (paywalled). Reuters reports: A Meta spokesperson told Reuters on Wednesday that the company is already testing the Application Programming Interface (API) with some early partners and is looking forward to releasing it this month. "The muse spark API will be coming soon," Meta AI Chief Alexandr Wang announced in a post on X in April.

Meta unveiled Muse Spark in April as the first model built to close the gap with rivals. Muse Spark is the first in a new series of models created by the company's Superintelligence Labs. Earlier on Wednesday, Meta unveiled an AI agent aimed at helping businesses carry out day-to-day operations, hinting at the company's ambitions to compete with rivals such as OpenAI, Anthropic and Alphabet's Google.
Software

Apple Is Bringing Age Verification To Texas This Week (theverge.com) 51

joshuark shares a report from The Verge: Apple will introduce age verification in the App Store for users in Texas starting on Thursday, June 4th. The move, as spotted by MacRumors, comes just days after a federal appeals court allowed Texas' App Store Accountability Act to go into effect while a lawsuit against it proceeds. People in Texas who are creating a new Apple account will need to verify they're over 18 using a credit card or government ID. Apple may also automatically verify users' age using the age of their account and whether they have a credit card on file.

Despite Apple's attempts to push back on app store-level age verification, the company has announced plans to implement age checks to comply with laws in places like Utah, Louisiana, Brazil, Australia, Singapore, and the UK. Google is required to make similar changes to the Play Store and is also introducing age-checking tools for developers. Last December, a judge blocked the App Store Accountability Act (SB 2420) from taking effect, but an appeals court has now reversed this decision -- at least while the court figures out whether the law is constitutional. Even if this law gets struck down in Texas, a federal version with the same name is still making its way through Congress and could impose age verification at the app store nationwide.

Slashdot Top Deals