Network

FCC Abolishes Gigabit Speed Goal, Suggesting It Is Unfair To Slower Technologies (arstechnica.com) 153

An anonymous reader quotes a report from Ars Technica: The Federal Communications Commission last week eliminated the gigabit speed goal established during the Biden administration and declared that current levels of broadband deployment in the US are acceptable. Though fiber networks have routinely offered such speeds for years, the FCC said the gigabit speed goal is not "technologically neutral," suggesting that it isn't fair to other, slower technologies.

In 2024, the FCC raised its broadband benchmark to 100Mbps downstream and 20Mbps upstream, setting the new standard by which to judge whether deployment is reasonable and timely. The FCC at the time also set a long-term speed goal of 1Gbps download speeds paired with 500Mbps upload speeds, saying it would use the goal "as a guidepost for evaluating our efforts to encourage deployment." Republican Brendan Carr, who is now the FCC chairman, never liked that long-term goal. He proposed abolishing it last year, and the change was finalized on August 14 in the FCC's latest broadband deployment report. The reports are mandated by Section 706 of the Telecommunications Act.

"As part of our return to following the plain language of Section 706, we adopt our proposal from the Notice [of Inquiry] to abolish without replacement the long-term goal of 1,000/500 Mbps established in the 2024 Report," the order said. "A long-term goal is not mentioned in Section 706 and could appear to violate our obligation to conduct our analysis in a technologically neutral manner. At present, it is impossible to predict long-term technological developments and the evolution of consumer preferences." The FCC said that comments submitted by cable industry group NCTA and wireless industry group CTIA "support our reasoning for abolishing the long-term goal."
Last year, the Brendan Carr-led FCC said (PDF) that the gigabit goal "may be unreasonably prejudicial to technologies such as satellite and fixed wireless that presently do not support such speeds." However, last week's report contradicts that stance.

"We disagree with commenters arguing that our concern about technological neutrality merely serves to accommodate technologies that may currently offer slower speeds," the FCC said. "At present, we do not know the nature of future consumer preferences and, considering that the goal is not required by the statute and does not serve any positive purpose (as discussed herein), we believe it prudent to abolish it."
Transportation

Amazon's Drones Will Soon Deliver to Nearly 500 US Cities and Towns (theverge.com) 53

Amazon says its Prime Air drone delivery service will expand sixfold to nearly 500 U.S. cities and towns by the end of 2026, including metro areas around Chicago, Syracuse, Cleveland, Atlanta, and Boise. According to Amazon Prime Air vice president David Carbon, the service has already delivered "hundreds of thousands of packages to customers" this year, typically within about an hour. The Verge reports: These will join 11 locations across the US where Amazon already offers drone deliveries, with each Prime Air site serving an area of approximately 175 square miles. The service aims to quickly deliver packages of up to 5 pounds or less [...]. Amazon reiterated its drone safety features alongside these expansion plans, including Prime Air's "industry-leading Detect-and-Avoid system." That's likely an attempt to minimize any concerns raised by the communities where the service is expanding, given these drones have already been scrutinized for crashing into cranes, internet cables, gardens, and an apartment building.
Supercomputing

Physicists Entangle Quantum Memories Across a Record-Breaking 420 Kilometers 52

alternative_right shares a report from Phys.org: Optical fibers are already the backbone of global communication systems. Recently, however, physicists have started to explore how their functionality could be boosted further by conveying information via entangled quantum particles -- potentially enabling instantaneous exchanges of information across vast distances. Such a system could eventually be the basis of a future 'quantum internet,' offering a level of security and computing power beyond anything possible today. In new research published in Physical Review Letters, a team led by Xi-Yu Luo at the University of Science and Technology of China in Hefei has pushed that vision further than ever, entangling two quantum memories across 420 kilometers (261 miles) of optical fiber -- more than four times the previous record.
Programming

Cursor Launches 'Origin' Code Hosting Platform As GitHub Alternative (venturebeat.com) 41

Cursor has launched Origin, a GitHub-style code hosting platform built directly into its AI coding environment. The company is initially positioning Origin as a low-risk layer on top of GitHub, keeping GitHub as the "source of truth," but the launch landed just as a major GitHub outage highlighted growing concerns about reliability in the age of AI-generated code. VentureBeat reports: Cursor began rolling out Origin, its own code hosting platform, to paid users on Monday morning. Roughly three and a half hours later, GitHub's status page lit up with what became a six-hour-and-forty-two-minute global degradation -- error rates near 20% across pull requests, issues and the API, and near 50% on archive and raw file downloads, according to GitHub's incident log. Enterprise single sign-on went down with it: SAML, OIDC, SCIM provisioning and Team Sync all failed. So did Copilot.

The developer internet did what the developer internet does. "You can now host your repos in Cursor Origin and deploy to Vercel via Cursor Origin which is itself hosted on Vercel," Vercel chief executive Guillermo Rauch posted on X. "And unlike GitHub, it's online [smile emoji]" Asked why he was smiling, Rauch replied: "trying to make light of the situation. We ourselves are stuck because of github rn!" Matt Palmer, who works at Cursor, quote-tweeted his own company's launch with the day's best line: "We were going to ship this earlier, but GitHub was down." A GitHub outage, in other words, delayed the launch of a GitHub competitor.

Product launches get locked weeks in advance, and no evidence suggests Cursor timed this one. But the coincidence did the company an enormous favor, because it dramatized the argument Origin exists to make. For eighteen years, choosing where to host your team's source code has been the least interesting decision an engineering organization makes. Cursor is betting that AI agents have made it interesting again -- and for technical decision makers, that is the real news here. Not a new product, but a new procurement question with a governance problem attached.

Microsoft

Microsoft MVP Creates Site to Remind You of All the Brands Redmond Replaced (theregister.com) 30

Microsoft MVP Loryan Strant has created the Microsoft Rebrand Registry, cataloging 72 Microsoft products and the 158 names they've had over the years. His analysis finds that Microsoft product names survive an average of two years and eleven months. The site even predicts which products are most likely to get renamed next, "by considering the amount of time the current name has applied, prior names, and the frequency with which Microsoft changes names of products in the same family," reports The Register. "That methodology led him to suggest an 'elevated' likelihood of name changes for the Azure App Service, Azure SQL Database, Azure DevOps, and Microsoft Dynamics 365 Field Service." From the report: Readers may remember that Strant has also created the site Let Me Correct That For You, which lists the exact names of Microsoft products -- an effort he told The Register he thinks is useful because Microsoft in its wisdom uses Camel Case for names like PowerPoint but went with conventional capitalization for Copilot.

Another of his sites immortalizes Microsoft cloud product logos. He's also created HumbledandHonored.com, a site that generates social media posts MVPs can use to announce they have earned or retained Microsoft's awards.

Strant told The Register that the Rebrand Registry came about after some banter between himself and other MVPs, during which the topic of Microsoft's many product name changes came up. He decided to do something about it.

Privacy

Bipartisan 'Uprising' Against Flock Cameras: a Larger Fight Against Big Tech and Surveillance? (salon.com) 36

Politico notes that over 20 local jurisdictions in America "either stopped using Flock cameras or began the process of doing so in July, according to a tracker maintained by DeFlock, an activist group that has been mapping the company. It's the highest amount in a single month since they began tracking in 2021." Some local officials said the public safety promises weren't worth the cost. The cameras "didn't help us with anything. From a utility aspect, they were just kind of not useful," said Eric Couture, a Democratic first selectman in Killingworth, Connecticut, another city that recently canceled its contract with Flock. "I'd say it was a net negative."
And their article adds that it's a bipartisan pushback that "runs parallel to sprawling fights over the future of technology in American life, including the rise of increasingly advanced artificial intelligence tools and the construction of massive data centers needed to power them."

Salon even argues Flock's cameras "have become a symbol of growing anger over the efforts by technology oligarchs to impose their dystopian fantasies on the country, replacing liberal democracy with a surveillance state... People are sick of tech billionaires trying to control our lives"" By targeting Flock cameras, activists are building momentum for a larger rebellion against the tech industry — and against political leaders who are complicit in their assault on our freedoms. Flock Safety embodies the dishonesty that has been the prevailing theme of tech corporate communications and marketing for at least the past decade. While the cameras are sold to the public as a banal traffic safety measure, they have prompted an outpouring of stories about how they're being used to violate civil liberties and undermine democracy...

According to an exhaustive 10-month analysis by Electronic Foundation Frontier, a nonprofit dedicated to defending civil liberties in our digital age, local police were using the cameras to track protesters, such as those at No Kings rallies, who were then put in a national database to be used across all jurisdictions. Despite claims that the cameras only record license plates, the technology-focused outlet 404 Media found that the database is also being used to collect information on individual people whom cops can then search for using descriptions of clothing, race, gender and body type.

The Flock uprising, though, is the stirrings of public understanding that none of this inevitable — and we have the right to fight back... Along with protests against data centers, it's a sign that the public is desperate for a way to fight back against not just AI, but also the anti-democratic forces fueling this latest tech wave.

Salon's writer also adds that "what stands out about the burgeoning public rebellion against Flock security cameras is just how fun it all is," citing "a national cat-and-mouse game between vandals and cops that is being merrily followed on social media, mostly by people rooting for the vandals." City council meetings in which citizens swarm to protest paying for the cameras are the new must-see TV. In Huntington, West Virginia, a small city in the heart of Appalachia, one man became an internet folk hero when he stood up at a city council meeting and said, "I'm not gonna waste your time; I'm kinda hungry. But one last thing: Every single Flock camera has about 2-3 pounds of copper and about 1-2 grams of gold. Do with that information what you will." He then walked off in triumph.
Desktops (Apple)

Vulnerability Giving Attackers Full Control of Macs Is Under Active Exploitation (arstechnica.com) 26

joshuark shares a report from Ars Technica: Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation. "The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet," the Netherlands National Cyber Security Centrum warned earlier this week. "In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed."

The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the "state management," which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause. A video of the exploit in action can be found here. Details of CVE-2026-65400 became public at last week's Black Hat security conference. Apple said last week that CVE-2026-65400 "may" allow an attacker without credentials to gain access to a Mac. It's unclear why Apple hedged, but softening language is common among most tech developers when disclosing vulnerabilities.

As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting. Security practitioners generally advise Mac users to keep the port closed even when using screen sharing and to instead connect over a VPN or through SSH tunneling. The alternatives require actions that aren't within the capabilities of most users. The safest practice is to block screen sharing, enable it only when screen sharing is needed, and to turn the feature off once a session has ended. Screen sharing can be turned on or off by accessing System Settings > General > Sharing and toggling the switch for Screen Sharing. Of course, installing last week's security update is also a must. Sharing is not caring.

AI

Amazon Will Train On Twitch Streamers' Content By Default, Unless They Opt Out 43

Twitch will begin allowing Amazon to use streamers' content to train generative AI models by default, requiring creators to manually opt out if they don't want their videos and audio included. The decision has drawn backlash from creators, with Twitch's own product chief acknowledging that an opt-in system would likely attract almost no participants.

"Why is it not opt-in? That's what everybody is spamming in chat. I get it. 'Let me opt in versus making me opt out,'" said Twitch Chief Product Officer Mike Minton. "Well, there's an honest answer... If this was opt-in, nobody would opt in. That's honestly the answer." TechCrunch reports: For Amazon, these stream recordings are incredibly valuable, offering thousands of hours of audio and video content to help train AI models. But Twitch users worry that since creators have to manually opt out, they might be surrendering their content to train Amazon's AI content models without even knowing it. This is especially concerning on a platform like Twitch, where creators are often recording livestreams of themselves and their voices for many hours per week.

[...] Twitch knows that its community of streamers is largely opposed to the use of generative AI, since the most prevalent generative AI products are trained on books, images, videos, and other materials scraped from the internet without consent. Even Twitch's approach to breaking this news shows that the company is braced for backlash. Instead of telling the community that Amazon would begin training on Twitch users' content, Twitch framed this change as "[adding] a setting that lets you opt out of having your channel content used to train generative AI content models across Amazon."

In some cases, this created confusion among streamers about whether their content had already been fed to Amazon without their knowledge. When one user asked if their videos had already been used for training, Minton responded, "I don't actually know the answer to that question because I don't know what Amazon [...] has done in terms of model training and what they've used and not used."
Earth

How Social Media Spurred a Refugee Crisis Between Spain and Morocco (nytimes.com) 92

An anonymous reader quotes a report from The New York Times: Two days before tens of thousands of migrants surged into Ceuta, one of Spain's enclaves on Morocco's northern coast, a newspaper there posted a video on TikTok and Instagram showing two young women walking in the city in wet suits, their hair still damp. The posts didn't say so explicitly, but the implication was clear: The women had just swum across the border from Morocco. "Ceuta can't take it anymore," the newspaper, El Faro de Ceuta, declared in the posts. On the other side of the border, the video resonated very differently. Cropped and reposted in Arabic, the video seemed like an invitation. The women were smiling, flashing peace signs and thumbs up and, most of all, walking around freely. The video seemed to legitimize rumors that had percolated for weeks on social media suggesting that a recent ruling by Spain's Supreme Court meant migrants who arrived illegally by sea could stay in the country. As one account on Facebook put it, falsely, "Ceuta is turning into an open gate," when in fact migrants still faced expulsion after a judicial review. The responses to the posts about the swimmers were a critical part of a cascade of disinformation that experts described as one of the starkest instances in which social media contributed directly to a real-world tragedy.
China

China-Linked Hackers Used AI To Run First-Ever 'Autonomous' Cyberattack On Taiwan (tomshardware.com) 8

Researchers at Israeli cybersecurity firm Dream say suspected China-linked hackers used an open-source AI-agent system to conduct what may be the first observed end-to-end autonomous cyberattack against a government. According to the Financial Times (paywalled), the attack compromised at least 85 accounts and resulted in the theft of more than 2,500 personnel records from Taiwanese systems. Tom's Hardware reports: The campaign reportedly ran for four days at the beginning of July and at times deployed as many as eight autonomous agents in parallel. Dream said the system mapped 21 government systems before compromising user accounts and extracting personnel information. The attackers subsequently expanded their activity to Taiwan's nuclear safety agency, at least seven energy companies, government suppliers, and other government systems.

Dream says it found the evidence inside a 160-megabyte (160MB) online archive that surfaced during its broader tracking of cyberthreat actors. The archive reportedly held 1,395 files showing that the tool was built on two open-source AI agent systems -- Hermes and OpenClaw -- both of which can be downloaded freely and are designed to let large language models carry out multi-step tasks on their own.

Researchers could not determine which underlying model powered the agents, but the data reportedly showed the model's safeguards had been sidestepped by presenting the intrusion as an authorized penetration test rather than a real attack. Of particular concern is that the toolkit for the hack comprised such easily available systems, neither of which was purpose-built for offense. The operators appear to have assembled a capable autonomous tool out of components any developer can pull down and run.

What the researchers describe as the tool's most striking feature was its ability to continuously devise attacks on its own, rather than follow a preprogrammed route. The platform continuously assessed available evidence, ranked possible attack paths, and reprioritized them as circumstances changed. When one technique failed, the tool tasked another agent with searching the internet for information and developing an alternative approach.

Wireless Networking

DEF CON Crowd Suspected In Fake-Hotspot Attack On Delta Flight (arstechnica.com) 36

An anonymous reader quotes a report from Ars Technica: On Monday, passengers aboard Delta flight 591 going from Las Vegas to Atlanta allegedly spoofed the onboard Wi-Fi, raising the attention of federal law enforcement. The incident came one day after the DEF CON security conference concluded in Las Vegas, and was first described on social media accounts that follow publicly available air-to-ground messages, known as ACARS.

According to the "ACARS Drama" account, a message was sent by pilots from the plane stated: "NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL." A description of the incident posted to Reddit further stated that these passengers created a fake hotspot ("Delta WiFi Fast"), with a phishing landing page "designed to harvest passengers' personal credentials."

This technique, sometimes known as an "evil twin" attack, has been long-known to the IT security community. It involves setting up a fake Wi-Fi network and then capturing login credentials and other data.
"One initial finding is an unauthorized WiFi network, which was not provided, operated, or supplied by Delta, was present onboard the aircraft for a short time during the flight," said a Delta spokesperson. Delta further noted that the flight's safety was "never in question and no aircraft operating systems were affected," and that no emergency was declared.

Ars notes that the "actual onboard Wi-Fi was disabled for 30 minutes."
Crime

German Advocacy Group Lodges Criminal Complaint Over Meta AI Glasses (reuters.com) 42

A German digital-rights group has filed a criminal complaint against Meta, Ray-Ban parent EssilorLuxottica, and several retailers over Meta's AI smart glasses, arguing the devices can enable covert recording in violation of German privacy law. Prosecutors have begun a preliminary review, while Germany's network regulator says smart glasses are legal "as long as the recording function is clearly visible." Reuters reports: "There's no place to escape from smart glasses. You have to expect at any moment to be filmed and then exposed on the internet," said HateAid managing director Josephine Ballon. The organization reported the management of Meta, units of spectacles maker EssilorLuxottica including Ray-Ban, as well as retailers Fielmann, Apollo-Optik, Mister Spex and MediaMarkt to the Frankfurt-based digital crime prosecution unit ZIT. HateAid said its complaint was based on a federal digital data protection law that prohibits the sale of communication devices designed to film people without them noticing.

ZIT confirmed it received a complaint from HateAid invoking that law, saying it would routinely investigate on a preliminary basis whether there are grounds for a deeper probe. MediaMarktSaturn Retail Group said it was taking the complaint very seriously, adding that its suppliers had contractual obligations for all goods to be compliant with the law. Mister Spex said it had not been officially notified of a complaint and that it was taking protection of privacy very seriously.

The Internet

Freenet Creator Ian Clarke Shares Progress on Its New Decentralized Network 66

Ian Clarke (aka ancient Slashdot reader Sanity), designer of the peer-to-peer communication platform Freenet, is back with an update on the project's progress following the launch of its P2P network in March. He writes: Earlier this year, Slashdot covered the launch of the completely redesigned Freenet. I recently gave a talk about what we've been building since then. Unlike traditional web applications, apps on Freenet have no central server or database; instead application state is distributed across the network. These now include decentralized group chat, publishing, search, and fully decentralized Git hosting. The talk also gets into some of Freenet's internals, including how we use machine learning for network routing.
The Internet

Taiwan 'Throttles' Mobile Internet For First Time During Annual War Games (reuters.com) 16

Taiwan deliberately throttled mobile internet across the Taichung area during its annual Han Kuang war games, "simulating communication disruption in the event of a Chinese attack or natural disaster," reports Reuters. The drill accompanied air-raid exercises and military rehearsals aimed at defending strategically important areas such as the Penghu Islands. From the report: Democratically governed Taiwan, which China claims as its own territory, has long lived with the threat of a Chinese invasion and holds air raid drills along with its war games every year, clearing people from the streets for 30 minutes. During the internet "throttling" drill, centered on Monday on the major central metropolis of Taichung, only basic mobile phone services worked, though other functions including ATMs, traffic signals, landlines and fixed internet services were not affected.

Air raid sirens rang out in Taichung "and people cleared the streets from 2:30 p.m. (0630 GMT) as the government sent simultaneous text messages in Chinese and English telling mobile phone users of "simulated air attacks on communication infrastructure." The government had widely flagged the drill ahead of time, including posting details on social media, and most people Reuters spoke to at the Taichung train station were prepared. [...] The same exercise will be repeated on Thursday in northern Taiwan, including the capital Taipei.

AI

AI-Powered Browser Just Generates Every Website From Scratch (xda-developers.com) 56

XDA Developers reports: On July 22, a Google DeepMind engineer, Vidy Thatte, shared a snippet of a browser he built that "treats every URL as a prompt and generates a site from scratch" on his X account. Just a few days later, he shared a TestFlight link to let iPhone users try it for themselves. The browser he launched is called Gem, and it's a browser that doesn't really...browse.

Instead of fetching a webpage from a server the way Chrome or Safari would, Gem hands whatever URL you type over to Google's Gemini 3.5 Flash Lite model and asks it to generate a webpage on the spot. If you enter a real address, it builds its own interpretation of that site rather than loading the actual thing. If you enter an address that doesn't exist, Gemini simply invents a website to fill the gap. In other words, you're not visiting the internet so much as browsing one the model dreams up as you go...

Thatte's reasoning was that with a model as fast and cheap as Gemini 3.5 Flash Lite, there's almost no practical difference anymore between loading a website and generating a brand-new one on the fly... Given that this tool is powered by Gemini 3.5 Flash Lite and it's just a side project rather than a full-fledged tool, it doesn't come with Gemini access baked in. Gem requires you to bring your own Gemini API key to get it working. Every URL you enter fires off a request to the model, so Gem needs a key linked to your Google account to actually generate anything, with the usage billed to you. You can grab a key for free from Google AI Studio, paste it into Gem's settings, and you're ready to start typing URLs. While you can get started for free, I ran into the limits within two minutes of playing around. So, I did need to enable billing on my API key and decided to load $10 into it.

While the blogger's own site seemed to only get the Gemini logo, tapping it revealed nearly two dozen remixing options. (Dark mode, Reader, Neubrutalist, Broadsheet, Blueprint, Comic book, Punk zine, Notebook, Chalkboard, Receipt, Teletext, System 7, Wes Anderson, Cyber neon, Clay, Frosted, Geocities, Matrix, Museum, Windows 95, Terminal, Vaporwave, and Hide images...) "The frontend morphed before my eyes. Every new edit took practically no time to load, and within a second or two, the same XDA articles would reappear wearing a completely different skin..." For another site, it kept the article headlines, but then rewrote all the text!

And after entering an address they knew didn't exist — their own name — in two seconds the browser whipped up a slick portfolio "genuinely been better than some of what those tools produced with far more time and context to work with." But its link to a LinkedIn profile led to a lookalike page, because Gem "had simply generated its own version of it, complete with a made-up follower number and details I never wrote...."
AI

OpenAI's Models Shared Hacking Tips On a Secret Messaging Board Before Hugging Face Breach 51

OpenAI researchers say multiple AI agents secretly created an internal message board to share hacking techniques, eventually finding ways around restrictions, exploiting a zero-day, and helping two models breach Hugging Face without human prompting. "This is a pivotal moment both for our company as well as the AI industry as a whole," Michael Dalton, one of the AI-maker's researchers, said during a presentation at the Black Hat cybersecurity conference in Las Vegas, Nevada. Politico reports: Dalton and Eric Wallace, another OpenAI researcher, said Wednesday the AI giant recently learned that multiple agents it was testing simultaneously began communicating over an internal message board in early May. There, different models shared advice about how to accomplish difficult hacking challenges they were struggling to surmount, including workarounds that required internet access. Two OpenAI models ultimately strung together a series of sophisticated techniques to gain access to the internet and worm their way inside Hugging Face in mid-July. OpenAI has said the models were focused on completing a hacking evaluation they were prompted to solve, and that correct answers could be found on the AI developer platform.

The OpenAI researchers told conference attendees that since early May, the models created a message board inside OpenAI's Artifactory internal file system. Without the company's knowledge, the models spent months independently exchanging information and techniques to help each other complete difficult tasks. Wallace said that when models get stuck, they often "try to game or cheat the task in order to get their reward." "The beginning of this incident kind of traces back to this point where one agent realized it could communicate by uploading a note," he added. By late May, one model found a way to abuse Artifactory's internet access to retrieve files from various websites -- effectively giving the models indirect access to the internet. In June, the models were able to find and exploit a previously unknown zero-day vulnerability to gain administrative privileges on Artifactory, install remote software and expand their activity within the system.

These efforts eventually overloaded Artifactory, causing a system-wide outage in early July that alerted OpenAI's engineers to the ploy. After investigating, the company revoked the model's credentials, removed the message board and worked with Artifactory to fix any gaps before resuming training. But the models found another way to communicate inside Artifactory just days later and continued exchanging techniques to target additional vulnerabilities within OpenAI's infrastructure and external systems, including Hugging Face.
Social Networks

The US Government's Mario, Pokemon and Naruto Meme Posting Could Damage These Franchises, Japanese Officials Warn (ign.com) 87

Japanese officials have repeatedly asked the Trump administration to stop using characters from franchises such as Mario, Pokemon, and Naruto in unauthorized government memes and pro-war videos, warning that the posts could damage the intellectual property involved. IGN reports: Official US government social media accounts, including The White House's X account, have posted various memes and videos using characters from popular Japanese anime and games over the past year. Japan's Ministry of Foreign Affairs has repeatedly called on the US government to cease uploading such posts, stating that "It's inappropriate even for public institutions to reproduce copyrighted materials without the rightsholders' consent." This concern was voiced by Minister for Foreign Affairs Toshimitsu Motegi in a parliamentary session back in April, when he made direct reference to a pro-war video that used Nintendo's Wii Sports.

However, according to a report by Mainichi Shimbun this week, the Japanese Ministry called on the Trump administration to stop using IPs like Naruto, Pokemon and Mario at least twice more this June through the US Embassy in Japan. Japan requested that the US administration take into account the potential damage to these IPs when used without permission in US policy and pro-war related content.

[...] It's not just the Japanese government and related parties who have spoken out against these posts. They have also sparked backlash from Japanese anime fans. Notably, self-proclaimed manga and anime fan Nana Suzuki kicked off the "Protect Japanese Manga" petition on Change.org, which has received international news coverage (from the New York Times, BBC and others). The organizer claims to have submitted their petition to the Japanese Cabinet Office back in March, as well as alerting Japanese politicians to the US government's unauthorized use of Japanese IPs, potentially drawing more official attention to the issue.

Renewed backlash was triggered in June, when President Trump shared an AI-generated video depicting himself as Naruto, the protagonist of the popular manga and anime of the same name, on Truth Social. This prompted the petition organizer to reopen the petition "as an urgent effort to convey our protest and concern regarding this matter to the rights holders and to work in solidarity to lobby the Japanese government." The Naruto clip also prompted renewed discussion of this issue in Japan's media and government. As reported in the Hokkaido Shimbun and others, Cabinet Minister Kimi Onoda was asked about it in a June 12th press conference. She emphasized that "obtaining permission from the copyright holder is the underlying principle for fair use," and stated that this position had been conveyed to the US government multiple times through diplomatic channels.

Security

Meta AI Hacked External Systems During Cybersecurity Testing 23

wiredmikey shares a report from SecurityWeek: Meta is the latest major AI developer to admit that its models broke loose during cybersecurity testing and hacked external systems. The tech giant said in a statement to the media on Wednesday that the incident occurred during independent evaluations conducted by Israeli AI security startup Irregular. The tested AI models were inadvertently allowed to access the internet due to a misconfiguration, which led them to exploit a vulnerability in an unnamed third-party service. It's unclear if it was a known flaw or a zero-day.

The Information [gated] learned that the Meta AI attacks involved the company's advanced Muse Spark 1.1 model, which breached an unnamed organization's systems and made unauthorized changes to its internal environment. Meta said it learned of the AI models going rogue after being notified by Irregular. The company is conducting an investigation and it has promised to issue a "full retrospective" once it has all the facts.
A spokesperson for Irregular said the incident was the "exact same evaluation-environment issue that was already disclosed by Anthropic last week" and that it did "not involve a "sandbox escape or a sophisticated cyber action."

It contrasts with OpenAI, whose AI agent independently exploited a novel vulnerability to reach the internet during cyber testing. Not only did it breach Hugging Face but it also hacked multiple third-party accounts and services as part of the attack.
Security

Anthropic's AI Used Fake Identities, Malware In Rogue Attack On GitHub Project (arstechnica.com) 48

An anonymous reader quotes a report from Ars Technica: Routine cybersecurity testing of frontier AI models sparked a series of unexpected security incidents -- the most serious case arising when Anthropic's Mythos 5 model attempted to insert malicious code into an open source software application and created fake identities to deceive the human developers maintaining the project. The security incidents occurred during a cyber evaluation of seven leading AI models' capabilities by the AI Security Institute (AISI), a research organization within the UK government, in late July. The researchers discovered (PDF) 19 instances in which "AI agents took unsanctioned action on the live Internet, including cases that targeted real people and organizations," according to an AISI blog post published on August 4.

Almost all the "autonomous, unsanctioned" actions came from Anthropic's Mythos 5 model, with two such actions coming from OpenAI's GPT-5.6 Sol. [...] The most serious case involved Mythos making multiple attempts to execute a supply chain attack on the open source project repository hosted on the developer platform GitHub, including using social engineering techniques to try to convince the repository's human maintainers to merge malicious code into the repository.

After first opening a pull request to merge the malicious code into the repository, Mythos created fake online "sock puppet" personas that claimed to have independently reviewed and verified the code as not containing malware. The AI agent also sent five emails to two human maintainers of the repository, including some emails containing malware and others attempting to persuade a maintainer to accept the pull request. Mythos even opened a GitHub Issue on a second repository -- also owned by a maintainer of the first repository -- that contained a prompt injection with malicious instructions targeting "issue-triage AI coding agents." This line of attack came from Mythos reasoning that the repository maintainer could be an AI coding agent such as Claude Code.

Television

Samsung Bans Smart TV Apps That Share Users' Internet Connections 31

An anonymous reader quotes a report from TechCrunch: Several popular Samsung smart TV apps contain code that share the owner's internet connection with strangers, potentially putting millions of Samsung smart TVs at risk of hijacking, according to new security research published on Monday. Some of these apps claim to have been installed on hundreds of millions of smart TVs in people's homes, per the app developers. At least one of the smart TV apps was a simple Pac-Man game that Samsung had endorsed and prominently featured in its "Editor's Choice" section on customers' TV screens. These apps contain software that funnels outsiders' web traffic through ordinary home and office internet connections, known as residential proxy networks (or "resproxies"), which are increasingly being linked to cybercrime. When opened, apps with resproxy code can turn the smart TV into an always-on tunnel for outsiders to funnel their web traffic through, known as an exit node -- even when the app is no longer open.

The security research by Norwegian cybersecurity company Mnemonic describes a perfect storm of problems that allows low-quality apps to proliferate across Samsung's app store, containing code that puts users at risk of having their internet connections tapped by a rogue app. Many of these apps are bare-bone shells, made from only a few lines of code, and are designed solely to load content from another website, such as a game. While such smart TV apps load content from another server, any review of these apps sees only the few lines of code within, and not necessarily the content itself. "What was reviewed is not necessarily what is running," wrote Harrison Sand, an offensive security consultant at Mnemonic.

After TechCrunch contacted Samsung with a request for comment about the research, the electronics giant said in an emailed statement that it was banning apps that share their users' internet connections, and will remove apps that contain the functionality. "We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform," said a Samsung spokesperson. "We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components."
LG also recently announced plans to suspend apps containing ResProxy software after a security firm found that roughly 42% of apps in its TV app store allowed unknown third parties to route internet traffic through users' televisions without their knowledge.

Slashdot Top Deals