Privacy

Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch (itnews.com.au) 29

A Russia-linked group tracked as Midnight Blizzard has compromised hotel and conference Wi-Fi portals worldwide, redirecting guests to phishing pages and fake software updates that steal credentials, session tokens, and other sensitive data. Microsoft says the campaign, dubbed CaptiveCrunch, "targets traveling employees generally rather than a particular sector," reports iTNews. From the report: Midnight Blizzard, tracked internally by Microsoft under its earlier codename NOBELIUM, is attributed by the US and UK governments to Russia's SVR (Sluzhba Vneshney Razvedki) foreign intelligence service. Microsoft's technical analysis said compromises occurred in "several countries" without naming them, and it did not give a total number of affected venues, organisations or individuals.

A related investigation published earlier in July by security firm ReliaQuest, and which Microsoft cited in its report, found compromised captive portal gateways across multiple United States cities as well as in India and Saudi Arabia, mostly at hotels. ReliaQuest said the traffic it observed came from organizations across financial services, professional services, legal, health care, energy and retail, suggesting the campaign targets traveling employees generally rather than a particular sector.

[...] Where attackers gained a foothold, Microsoft said they deployed two main tools: CornFlake, a Windows remote access trojan (RAT) written in Go capable of keylogging, screenshot and webcam capture, audio surveillance and credential and session token theft. They would also drop ChocoShell, an in-memory PowerShell infostealer targeting browser cookies, saved passwords, Microsoft 365 single sign-on (SSO) tokens and wi-fi credentials. Microsoft also said it has seen indications the attackers might be targeting Android devices with similar prompts urging victims to download and install an APK file.

Education

An AI-Supervised Remote Exam Went So Badly That 58,000 Students Must Retake It 50

An anonymous reader quotes a report from Ars Technica: Earlier this summer, nearly 160,000 applicants took the entrance exam for UNAM, Mexico's largest university. For the first time, they did it completely remotely, using a "lockdown" browser and AI-powered webcam proctoring software, over several weeks from late May through early June. It was a disaster. When exam results came in, they bore little resemblance to past results, especially at the top. Between 2021 and 2025, 3.5 percent of test takers scored 100 or more on the 120-question UNAM test. This year, 16.3 percent did so. The story was even worse at the highest of the high end. Between 2021 and 2025, 0.9 percent of test takers scored 110 or more; this year, 5.5 percent did so.

The surge in top scores led to accusations of widespread cheating, and UNAM appointed a commission of experts to investigate the situation. The group was given the unwieldy name "la Comision Tecnica de Personas Expertas para la Revision del Proceso de Seleccion de Ingreso a Licenciatura para el Circlo Escolar 2026-2027/1," and it has just submitted its recommendations. The commission believes that the best path forward, given all the concerns, is to administer a "control exam" -- that is, applicants will have to sit for another test, and they will do so in person.

This control exam will apply not only to those who secured a spot at UNAM based on this year's test but also to everyone who would have been admitted based on minimum successful scores in their program of study since 2021. About 58,000 people could be affected, and places at UNAM will now depend on the results of the new test. (Details on the control exam should appear soon; classes are currently scheduled to begin on August 10, so everything will have to move quickly unless the school decides to delay classes.) According to Gaceta UNAM, the school's official news publication, the university rector has apologized to honest applicants, since they will now have to prepare for and take the test again despite doing nothing wrong. Still, the control exam is "necessary to give certainty and guarantee equity in access," the rector added.
Television

Samsung Bans Smart TV Apps That Share Users' Internet Connections 31

An anonymous reader quotes a report from TechCrunch: Several popular Samsung smart TV apps contain code that share the owner's internet connection with strangers, potentially putting millions of Samsung smart TVs at risk of hijacking, according to new security research published on Monday. Some of these apps claim to have been installed on hundreds of millions of smart TVs in people's homes, per the app developers. At least one of the smart TV apps was a simple Pac-Man game that Samsung had endorsed and prominently featured in its "Editor's Choice" section on customers' TV screens. These apps contain software that funnels outsiders' web traffic through ordinary home and office internet connections, known as residential proxy networks (or "resproxies"), which are increasingly being linked to cybercrime. When opened, apps with resproxy code can turn the smart TV into an always-on tunnel for outsiders to funnel their web traffic through, known as an exit node -- even when the app is no longer open.

The security research by Norwegian cybersecurity company Mnemonic describes a perfect storm of problems that allows low-quality apps to proliferate across Samsung's app store, containing code that puts users at risk of having their internet connections tapped by a rogue app. Many of these apps are bare-bone shells, made from only a few lines of code, and are designed solely to load content from another website, such as a game. While such smart TV apps load content from another server, any review of these apps sees only the few lines of code within, and not necessarily the content itself. "What was reviewed is not necessarily what is running," wrote Harrison Sand, an offensive security consultant at Mnemonic.

After TechCrunch contacted Samsung with a request for comment about the research, the electronics giant said in an emailed statement that it was banning apps that share their users' internet connections, and will remove apps that contain the functionality. "We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform," said a Samsung spokesperson. "We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components."
LG also recently announced plans to suspend apps containing ResProxy software after a security firm found that roughly 42% of apps in its TV app store allowed unknown third parties to route internet traffic through users' televisions without their knowledge.
AI

'AI's Decimation of Call Center Jobs Has Begun' (yahoo.com) 145

"AI's decimation of call center jobs has begun," reports Bloomberg: Companies including the Commonwealth Bank of Australia, Microsoft Corp., Uber Technologies Inc. and Hyatt Hotels Corp. are using automated chat and phone systems to handle work that previously required humans. In some cases, they've already wiped out sizable chunks of their customer service operations, together representing thousands of workers.

The specter of automation has long loomed over the call center industry, which employs millions worldwide from the U,S, to India to the Philippines. But until recently, generative artificial intelligence wasn't good enough to move the needle. Now, AI advancements — and pressure on executives to show they're embracing the new technology — have prompted corporations to deploy the tools more widely. Customer service employment in the U.S. is declining and will likely continue to do so as more tasks are automated, Forrester analyst Kate Leggett wrote in a report earlier this year. While it's impossible to determine the future job losses, she estimated that almost half of customer service roles will be affected by 2030.

Globally, the steepest job cuts are expected to hit countries like the Philippines, where many Western companies have outsourced their most easily automated work. Salespeople at multiple tech companies told Bloomberg that they routinely pitch call center AI tools as a way of lowering labor costs, undercutting a common industry claim that AI is primarily a way to help workers become more productive rather than kill their jobs... Commonwealth Bank of Australia, the nation's largest lender, has shed hundreds of workers from its chat support line as it wove AI into the system, according to people familiar with the work. This amounted to tens of millions of dollars in savings per year, one of the people said...

Microsoft is both one of the largest vendors and adopters of customer service automation tools. This has helped the software giant trim its customer service workforce — a mix of contractors and full-time staff — from about 50,000 to 40,000 in recent years, according to a person familiar with the operations. "If something happened with little Johnny's Xbox in the middle of the night, we can now solve that with AI," Judson Althoff, who runs Microsoft's sales and service operations, said in an interview. Althoff said in April that AI is saving the company about $750 million per year in customer service costs. More complex problems still require human support, but the company is constantly expanding what can be fixed automatically, he said in the interview.

Two examples from the article:
  • Last year Hyatt fired 30% of its in-house customer support staff for the Americas, according the hotel-industry news site Hotel Dive.
  • Last week Bloomberg reported Uber had cut 10% of its customer service jobs as part of effort to "embrace artificial intelligence," according to the article. "Today, Uber pushes users to submit support requests through their apps, where they're met with an AI chatbot."

Movies

Hollywood Fights AI In Public While Quietly Building It Into Movies (msn.com) 63

Even as Hollywood performers protest and Hollywood studios sue "in their war on AI," reports the Los Angeles Times, "the entertainment industry is deepening its dependence on it." Among hundreds of job postings in late June, more than one in 10 was likely connected to AI. The top studios' public postings suggest they have been recruiting people to build AI tools. They are also recruiting teams to defend their intellectual property against unauthorized AI use. "There are plenty of studios that are hiring [for AI] but never talk about it in public," said Yoland Yan, a co-founder of ComfyUI, a company that helps studios juggle different AI tools. Companies have been hesitant to detail how they use generative AI in film production — partly because they are concerned about consumer and union backlash. Some in Hollywood described AI use as the new cosmetic surgery, where everyone knows it is happening, but few will admit to it...

Although some companies may be shy about sharing their AI plans, big stars who don't have to answer to others have been more open about their embrace of the new technology for storytelling. Rejecting AI is like picking a horse and buggy over a car, said "Star Wars" creator George Lucas. "Artificial intelligence means it's much easier for us to make movies," he told a trade magazine earlier this year. "There's nothing you can do about it. That's progress. It's the future." Some in Hollywood have a softer stance on artificial intelligence, with studios cutting deals with AI companies, and filmmakers like Martin Scorsese backing AI companies. Ben Affleck launched an AI film tech company then sold it to Netflix for half a billion dollars. When launching InterPositive, Affleck said he wanted to keep "storytelling human" by building AI tools that could fix lighting, generate missing shots and other things while "keeping creative decisions in the hands of artists...."

Disney, Netflix and Amazon had job postings that were about using AI on the creative side of the business. Universal, Paramount, Warner Bros. and Sony had job ads suggesting they were also using AI but for marketing, distribution and audience analytics. The postings suggest the Disney, Netflix and Amazon studios are building repeatable AI workflows for visual effects, animation, sound and dubbing. The companies also seem to be building in-house teams to develop custom generative-AI models, while also using third-party software.

None of the jobs advertised were to create AI that wrote scripts or created AI actors.

Ironically, the Times used Claude Code to build a scraper to identify the job postings, their article acknowledges.
  • Three Disney jobs were for "content security," assessing AI tools and guarding against piracy, watermarking and rights-protection work. But Disney is also hiring PhD-level talent "to study 'computer graphics and AI' for Pixar and Disney films," according to the article, and "people to 'bridge the gap between research and practical studio application.'"
  • Disney-owned visual effects shops Industrial Light & Magic "was searching for supervisors to 'explore emerging technologies (including AI/Machine Learning)' to develop new production workflows."
  • Audio post-production unit Skywalker Sound "seemed to be recruiting to build proprietary AI models for soundtracks, voice separation, and voice transfer, the process of taking a speaker's tone and pitch, and applying it to new content."
  • Amazon "was hiring a principal AI executive to drive AI-tool adoption across production, plus roles in operations automation and LLM content classification."

DRM

GOG Officially Expands Linux Support With Native Galaxy Client In Development (linuxjournal.com) 32

Long-time Slashdot reader pyroclast shared this report from Linux Journal: After years of requests from the Linux gaming community, GOG has officially confirmed that it is developing native Linux support for the GOG Galaxy launcher. The announcement marks one of the biggest shifts in the company's history and signals a stronger commitment to Linux as a first-class gaming platform. While GOG has offered DRM-free Linux game downloads since 2014, its Galaxy launcher has remained exclusive to Windows and macOS — until now. Although the company has not announced a release date, GOG says Linux has become a major area of investment, with development already underway...

Unlike the web-based game downloads that Linux users already have access to, GOG Galaxy serves as a full-featured game management application. The launcher currently offers features including:

— Automatic game installation and updates
— Cloud save synchronization
— Achievement tracking
— Playtime statistics
— Game library organization
— Integrated storefront browsing
— Friends lists and social features
— Cross-platform launcher integration

Today, Linux users typically access these capabilities through community projects such as Heroic Games Launcher, Lutris, or Bottles. A native Galaxy client would provide an officially supported alternative with direct integration into GOG's ecosystem...

For GOG, supporting Linux more fully aligns with its philosophy of giving users greater control over their purchased games.

The article argues this news shows Linux growing in importance for game publishers. After the rapid adoption of Valve's Steam Deck, there's also been continuous improvements to Proton and Vulkan, increasing hardware compatibility, and native Linux game development efforts.

"As more companies recognize the platform's growth, Linux users can expect broader support from game publishers and software developers alike."
Open Source

Is There a Way to Promote Open Document Formats Instead of 'MS Office' Format? (theregister.com) 82

The Register looks at exactly why "It is practically impossible to move any non-trivial Word document out of MS Office to a non-MS suite and back again without it being more trouble than it's worth." OOXML, developed by Microsoft and first standardized by Ecma in 2006, became the ISO/IEC 29500 standard in 2008 after a grueling and adversarial process. Microsoft pursued standardization because it has always been a standards-led organization dedicated to maximizing the options for its customers. Or because it had to at gunpoint, while vowing silently to follow the letter of the law but stymie its intent. You decide... The Document Foundation (TDF) which spends its days worrying about such things, reports that Microsoft has effectively broken the standard by sticking with a transitional version as its default rather than the cleaner Strict variant. The result is that what Microsoft software renders is what Microsoft wants to render, despite nominal compliance...

What we need is a test suite that can take any OOXML engine and test its compliance against what Microsoft is actually doing. That means the tooling wrapped around the spec has to account for proprietary dependencies that get smuggled in, such as fonts. It also means actively and continuously tracking the ground truth of Microsoft's evolving products and services. It doesn't need to be perfect, but it absolutely needs to be good enough. Compliant engines have to become good enough for a critical mass of users to coalesce around them.

In an earlier article The Document Foundation reminded all software users that they have a choice. "When an institution sends a letter formatted with a proprietary font, embedded in a proprietary format, produced by proprietary software, it is not communicating information but perpetuating a dependency."

"Digital sovereignty begins with the recognition that this is a choice: the file format is a choice, the font on the page is a choice, and the software is a choice."
Bitcoin

Recovery Seeds Reportedly Breached for Coldcard Hardware Bitcoin Wallets, $75M Taken (nerds.xyz) 46

"A hardware wallet is supposed to be the safest place to keep Bitcoin," writes The Street, since it never connects to the internet, its keys never leave the device, and "the whole point is that an attacker would need to physically hold it to steal anything."

The problem is that anyone who can reproduce the recovery seed doesn't need to possess the COLDCARD, Nerds.xyz points out. More from The Street: [The recovery seed] is supposed to come from a hardware random number generator producing 128 bits of entropy, a number so large that guessing it is computationally impossible. It wasn't. According to Block's engineering team a single code change on March 1, 2021 caused the firmware to silently fall back to a software-based generator instead of the hardware one. On Mk3 devices the effective search space collapsed to roughly 40 bits. Coinkite has confirmed that figure and called it preliminary. The gap between 128 bits and 40 bits is not a matter of degree. It is the difference between a lock that cannot be picked and one that can be brute-forced by anyone with rented cloud computing....

Chainalysis found the attacker went after the largest balances first, pulling more than $30 million in the opening ten minutes. Within about 25 minutes, roughly 594 BTC had moved out of some 500 single-signature wallets. One victim lost around $1.8 million... Coinkite has shipped fixed firmware, but with a warning that matters more than the patch itself. Updating does not repair an existing seed. A seed created with weak entropy stays weak forever. Affected users have to generate an entirely new wallet on updated hardware and move their coins to it.

By Saturday morning Galaxy research was tracking 1,158.66 BTC, worth roughly $75.1 million, taken from 2,673 addresses, according to the article. And "The Coldcard exploit is ONGOING," Galaxy Research posted an hour ago on X.com. "Move Coldcard single-sig funds to safe locations immediately!" We have reported ~600 addresses we believe to be hackers holding funds stolen from Coldcard-generated weak entropy addresses to federal investigators, industry compliance firms, and cross-industry cyber investigators.
Thanks to Slashdot reader BrianFagioli for sharing the news.
AI

Is Big Tech's AI Gamble Starting to Look Riskier? (msn.com) 75

The Washington Post looks at giant tech companies "feeding every available dollar into the cash-incinerating maw of AI machines." They warn "Tech superstars that once had oodles of cash left over at the end of each year are now flipping into the red..." [While optimists expect] huge corporate profits and a society-wide boost to wealth and well-being... questions about that AI vision are now growing more urgent: When, if ever, will this payoff arrive? And what will the fallout be for Americans if the titanic investment doesn't quickly deliver? "This AI thing better work out because if it doesn't ... we're going to have a problem," said Torsten Slok, chief economist at investment firm Apollo Global Management. AI costs and doubts are spreading. The U.S. stock market has swooned this summer over fear of the AI bubble going bust...

The AI gamble sweeping up American fortunes is led by tech companies splurging on hulking data centers packed with computer chips and equipment needed to develop sophisticated AI models and deliver them to customers. In investor calls in the past week, Google, Microsoft, Meta and Amazon pointed to soaring AI-related sales and business deals. Advertisers are using the technology to tailor marketing pitches and corporations and start-ups are buying access to chatbots and other AI software to boost productivity... But this spending can only continue if AI generates an even larger avalanche of new revenue to pay for it all. Financial results released over the past week show that the AI titans' mammoth costs are largely swamping the sales boost from the technology. At Google, for every dollar of cash its business generated in the past three months, $1.15 went out the door to pay for AI computer chips and equipment, land for AI data centers and other big-ticket purchases. The company is covering the difference partly by borrowing money and selling more of its stock. Next year, five leading AI companies — Google, Amazon, Microsoft, Meta and Oracle — are projected to have negative free cash flow, which measures the cash left over after paying expenses and AI infrastructure costs. The figures, based on investment analyst projections compiled by S&P Global Market Intelligence, show a stunning reversal for what have been some of the world's most cash-generating corporations...

The companies remain profitable by standard financial accounting measures that spread out the costs of their AI infrastructure spending over many years... Pessimists see a bet so gargantuan that it cannot possibly pay off. The pessimists are growing louder. The Bank for International Settlements, a typically measured institution in Switzerland that advises government bankers around the world, recently warned there was risk of "economy-wide recessions" if the AI boom falters. That could mean pain for workers and communities across the United States. "I'm not saying AI is going to go away, it's just not clear to me these guys are going to make money on it," said Christopher Wood, global head of equity strategy at investment bank Jefferies who has correctly predictedpast financial bubbles.

Programming

New GitHub, PyPI Policies Hope to Boost Supply Chain Security (securityweek.com) 8

"GitHub and the Python Package Index (PyPI) have introduced new policies meant to boost supply chain security," reports SecurityWeek, "by preventing the fast propagation of poisoned package versions and the poisoning of old and long-stable releases." To prevent the fast delivery of malicious code through the immediate fetching of brand-new releases, GitHub has introduced a Dependabot cooldown, where the automation tool waits for at least three days after a release has been published before opening a pull request. "Waiting a few days before adopting a new release gives maintainers, security researchers, and automated scanners time to spot a malicious version and get it pulled before it ever reaches your pull requests," GitHub explains.

The three-day cooldown only applies to non-security version bumps, and the behavior can be modified through the configuration option in the dependabot.yml. "Three days as the default balances two goals: it pushes you past the window where most of these attacks live, and it doesn't hold your dependencies back longer than necessary," GitHub notes.

And the Python Package Index (PyPI) "now rejects new files being uploaded to releases that are older than 14 days," according to a recernt blog post from the Python Software Foundation's security developer-in-residence Seth Larson: This restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised... The discussion of this behavior began during PEP 740 (Digital Attestations) back in January 2024. The discussion was restarted in March 2026 after the popular packages LiteLLM and Telnyx were compromised. These packages were compromised due to a "mutable reference" in these projects' usage of the Trivy GitHub Action...

To quantify how disruptive this change would be to existing workflows, the PyPI database was queried for projects that have published new files to old releases... [O]nly 56 projects of 15,000 had published a [Python] 3.14-compatible wheel more than 14 days after a release was available. This topic was brought to the Packaging Summit at PyCon US 2026 by PyPI Safety & Security Engineer, Mike Fiedler. The rough consensus of the discussion was that the summit attendees thought it was "acceptable to require users to bump to the next version" to support new Python versions. With the data and consensus in hand, Seth moved forward with a patch to reject new files on old releases which was merged July 8th, 2026.

Android

Google Plans To Exempt Sanctioned Nations From Android Developer Verification (arstechnica.com) 28

An anonymous reader quotes a report from Ars Technica: We are a month away from the initial rollout of Google's Android developer verification system, and the company contends this policy does not impinge on the platform's open nature. Still, the restrictions will be a big change, and there are still some unanswered questions. An issue that has come up repeatedly in the run-up to verification is what will happen to devs who can't verify because of where they live. It turns out that Google has a cryptic answer for that buried in an FAQ. Developer verification will soon block the installation of apps from unverified developers on any Android device running Google services, which is functionally all Android phones outside Russia and China. Developers who want to keep releasing software, even if it's not in the Play Store, have to provide Google with their ID and pay a small fee.

But what if you're an Android developer living in a sanctioned nation? Currently, the U.S. sanction list includes Iran, Cuba, North Korea, and occupied areas of Ukraine. Given the current uncertain state of US foreign policy, that list could change in the future. Google doing any business with developers in those places is a thorny issue, and it seems like the company has decided to just leave them hanging. A rather lengthy FAQ a few levels deep on the Google developer site addresses various issues around dev verification. Smack in the middle is this: "How does this program impact developers in sanctioned countries? Devices in sanctioned countries will be excluded from Android developer verification checks. This allows any developer to continue distributing apps in these regions without verification, though users there won't benefit from the enhanced security benefits of the program."

[...] A Google spokesperson has expanded on the FAQ and confirmed to Ars that people living in sanctioned nations will not be allowed to go through the verification process. That means they will not be able to effectively distribute software through any channel internationally. Today, someone making an app in, say, Cuba can distribute it freely around the world, as well as at home. Anyone can install it and see their work in action after tapping through a few sideloading alerts. In the coming months, that will no longer be the case. These unverified apps will only be easily installable in the sanctioned countries where verification doesn't exist.

Microsoft

Microsoft's $450 Billion Jump Is Biggest In Stock Market History (bloomberg.com) 44

Microsoft shares surged as much as 17% after reporting 43% growth in Azure revenue, putting the company on track to add a record $490 billion in market value in a single day. Bloomberg notes that it "would eclipse Nvidia's $440 billion addition, following President Donald Trump's announcement of a 90-day tariff pause last year, as the biggest ever." From the report: The nearly $500 billion jump is larger than the market capitalization of roughly 96% of S&P 500 stocks, data compiled by Bloomberg show. It's also bigger than the combined value of the benchmark's 44 smallest members, which includes companies like Domino's Pizza Inc., Clorox Co. and Hasbro Inc.

Microsoft's one-day add in value also dwarfs many of the world's other equity markets. South Africa, Turkey, Finland and Vietnam all have total stock market values that are less than what the software maker is set to add on Thursday.

Open Source

Valve Sponsors Work Bringing Open-Source RADV Driver To Windows (phoronix.com) 16

Valve is funding Collabora's experimental effort to port the open-source RADV Vulkan driver from Linux to Windows. The team has already demonstrated Counter-Strike 2 running with RADV, but a stable interface or compatibility shim will be needed to handle undocumented driver changes. Phoronix reports: Louis-Francis Ratte-Boulianne put out a blog post highlighting their initial work on porting RADV to Windows. Besides working on Windows WDDM2 integration for Windows, a big challenge with porting RADV to Windows is on relying on the AMD Radeon Software Windows kernel driver.

It's out-of-scope of this current work for trying to port the AMDGPU Linux kernel graphics driver to Windows, so they are working on bringing RADV to Windows while relying on AMD's official Windows kernel driver. That in turn has led to reverse engineering and other steps for figuring out the proprietary kernel driver's data structures and other elements so RADV can be adapted to use it.

AI

OpenAI's Rogue AI Agent Hacked More Than Just Hugging Face (wired.com) 67

An anonymous reader quotes a report from Wired: OpenAI said Tuesday that the rogue AI agent that breached Hugging Face's platform also hacked multiple third-party accounts and services as part of the attack. It's now clear that the unprecedented security incident, which arose during an internal test of OpenAI's latest AI models, was more extensive than the company initially disclosed. In an updated blog post, OpenAI said that an ongoing review of the incident revealed that "four accounts" tied to "publicly available services" were used by the AI agent as part of a larger effort to hack Hugging Face. The rogue agent apparently found credentials that had been exposed on the open web and used them to break into the accounts.

OpenAI did not disclose what companies or organizations the accounts belonged to, but noted that they were not impacted at "the level of severity or scale of what we've shared related to Hugging Face." One of the additional accounts compromised by OpenAI's agent was used as an "outbound relay and staging path," potentially to obscure where the attack on Hugging Face was coming from, the company said. OpenAI's rogue agent also used another account for data storage to assist with the hack.

Reuters reported on Tuesday that a customer of Modal, a company that offers software infrastructure for training and running AI services, was one of the entities compromised by OpenAI's agent. In a statement to WIRED, Modal's chief technology officer Akshat Bubna confirmed that OpenAI's agent exploited a vulnerability in one of its customer's codebases, which was running on Modal's infrastructure. However, Bubna says, "Modal's platform was not compromised in any way." The identity of the customer could not be determined.

AI

Workplaces Look For Cheaper AI As 'Tokenmaxxing' Fades As a Corporate Fad (apnews.com) 87

An anonymous reader quotes a report from the Associated Press: A corporate fad of "tokenmaxxing" on artificial intelligence technology is hitting its limits as workplaces throwing AI at everything are seeing the costs rise without a similar spike in productivity. What started as tech industry-fueled springtime hype over squeezing as much AI-generated work as possible out of products like OpenAI's ChatGPT and Anthropic's Claude has shifted to a summertime backlash. [...] Just a few months ago, Silicon Valley executives were promoting high token consumption as a signal of high-performing employees. The stereotypical tokenmaxxer was staying up late -- perhaps ignoring their significant other -- while orchestrating an army of 24-hour AI agents performing work on their behalf. [...] The trend boosted revenue for leading AI large language model developers like Anthropic and OpenAI, but it fizzled as it became apparent it wasn't necessarily the best strategy for everyone else.

[...] Bain & Company management consultant Jue Wang said many of the big businesses her firm advises have been taking a closer look at returns on their AI investments. "The token cost for them has been doubling, almost every other month," she said. "Let's say $200 per developer per month. Multiply that by 20,000 developers, which is often what we're dealing with at these companies, and that quickly gets you to a number that is not a line item that any general manager has planned for." Sometimes that just means not using the AI equivalent of a sledgehammer to crack a nut. "Not everything needs a Claude Opus 4.6," she said of one of Anthropic's more capable models suited to software engineering or deep research. "And yet you see so many companies, so many users, default to using Opus for everything, including generating emails." That's led to a search for tools that do AI "model routing" -- in which easier queries get automatically sent to cheaper and more efficient AI systems and more complex tasks go to more powerful models.

[...] At the same time, those who favor racking up as many tokens as possible are having a field day with new open-source models from Chinese startups like Moonshot's Kimi or Zhipu's GLM, which nearly match the capabilities of top U.S. models at a fraction of the price. "There is some validity to the theory that this could push tokenmaxxing a little bit further," said Raffi Krikorian, the chief technology officer at Mozilla. "But if we look at the industry overall, I think it's realizing that tokenmaxxing is a dumb thing." It's similar, Krikorian said, to how software companies once considered how many lines of code a programmer wrote to be a good metric of productivity. That later fell out of favor. "I think tokenmaxxing is moving through the exact same pattern," he said. "I think this is going to be an interesting blip that we're all going to look back to laugh at in a year."

Privacy

GrapheneOS Defends Data-Wiping Function That Blocked US Border Search (pcmag.com) 182

GrapheneOS is defending its duress-password feature after an environmental activist used it to wipe his Pixel phone during a U.S. Customs search and was later indicted for allegedly destroying property under government control. The nonprofit says the operating system is "completely legal," cannot recover the erased data, and should not be weakened with encryption backdoors. Meanwhile, the activist faces up to five years in prison if found guilty. PCMag reports: In a post on Saturday, the Canadian nonprofit behind the operating system, the GrapheneOS Foundation, explained that the software offers a range of features to prevent data extraction. For example, one safeguard is the "auto-reboot timer" that'll reboot a locked device after a set period of time to put the data at rest, leaving all files inside encrypted.

The group's post subtly suggests that GrapheneOS phones can withstand law enforcement searches without requiring users to resort to a duress password. "People should carefully consider how to use it in an actual duress situation where there can be physical or legal consequences for wiping the device," the nonprofit wrote. "GrapheneOS doesn't require it to protect data from being extracted from the device, but it takes recovering it completely off the table even with the PIN/password for each profile on the device."

On X, the nonprofit has also said it can do nothing to help US law enforcement recover data from Tunick's phone. "Data cannot be recovered after the key derivation material is reliably wiped. It's not possible and there's nothing we can do to assist with it," the group wrote. "Similarly, it's not possible to assist with bypassing encryption because the hardware and software has been designed to prevent it."

Security

Nvidia, Tech Giants Launch AI Safety Initiative 12

wiredmikey shares a report from SecurityWeek: Nvidia and a large group of technology, cybersecurity, and enterprise software companies have launched new initiative aimed at developing and sharing open source tools, models, and techniques for securing AI systems and agents. The new Open Secure AI Alliance aims to give defenders more open tools for testing, auditing and protecting AI models and agents. Nvidia points to the recent security incident involving OpenAI and Hugging Face, noting that when closed AI tools could not differentiate between attackers and defenders and blocked forensic work, Hugging Face used the open-weight GLM 5.2 model on its own systems to review over 17,000 actions and contain the breach. "The right response is not to deny defenders access to capable open systems. It is to pair openness with strong safeguards, clear rules against malicious misuse, rigorous evaluation and rapid remediation. In cybersecurity, the safer path is the one that gives more defenders the ability to test, verify and strengthen the systems on which society relies," Nvidia said.

Thanks to longtime Slashdot reader SphericalCrusher for also sharing the news.
Movies

Comic-Con 2026 Debuts Trailers for 'Coyote vs Acme' Movie, Plus 'Neuromancer' and 'Blade Runner 2099' Series (cnet.com) 42

Big news from Comic-Con 2026:
  • "Coyote vs. ACME" debuted its long-awaited final trailer. CNET calls it "an animation-meets-live-action story," with the Coyote catapulting into theaters this August 28. (The film began development back in 2018, but was shelved for a tax write-off in 2023 by Warner Bros. until a backlash led to its sale to Ketchup Entertainment.) "Fed up with Acme's unreliable products, Wile E. Coyote decides to hire a lawyer and sue the company..." writes CNET. "The movie also features Lana Condor along with a host of Looney Tunes characters like Porky Pig, Tweety, Foghorn Leghorn and Granny (who gets dinged by an anvil)."
  • In other movie news, CNET says Johnny Depp also "made a surprise appearance at Comic-Con, donning a costume as Ebenezer Scrooge" to promote his November 13 movie about the miser from Charles Dickens' famous Christmas novella. (Ian McKellen and Daisy Ridley are also in the movie.)

But several geek favorites are being filmed as TV series...

  • There's big news for William Gibson fans, reports Entertainment Weekly. "Two years after Apple TV announced production on the first-ever series adaptation of William Gibson's seminal 1984 novel Neuromancer, the lucky few hundred who attended the studio's Hall H panel at Comic-Con 2026 got to watch the first teaser.
  • For Amazon's Prime Video, the Tolkien-derived "Rings of Power" series released a season 3 trailer that CNET said "successfully hides the best parts with fire... The trailer suggests that Sauron is building an army, and all of Middle-earth is trying to find ways to stop him... Rings of Power season 3 will start dropping weekly episodes on Nov. 11, meaning this show will be airing at the same time the Peter Jackson films will be celebrating their 25th anniversary."
  • Later in November Amazon's Prime Video will also debut Blade Runner 2099, an eight-episode series that's a sequel to 2017's film Blade Runner 2049, reports CNET. "Set in an alternate version of LA where replicants run things and the humans play second fiddle, the series sees Yeoh's replicant Olwen chasing down outlaw replicants who've gone missing. With her own shelf life on a ticking clock, the stakes are high for her and for her human fugitive partner, Cora..."
  • Paramount Plus will debut Avatar: Seven Havens in October, a new animated series from the creators of Avatar: The Last Airbender which CNET says "follows a pair of twin avatars, one of whom is Korra's successor."
  • Kevin Feige said Marvel's television slate will include more seasons of "X-Men '97" and the upcoming "VisionQuest" TV series.

Privacy

US Accuses American of Allegedly Wiping His Phone Using a 'Duress' Password During Border Search (techcrunch.com) 218

An anonymous reader quotes a report from TechCrunch: The U.S. Justice Department is prosecuting an American for allegedly providing U.S. border authorities with a passcode that wiped the contents of his phone, according to an indictment and media reports. This is thought to be the first known case in the United States where federal prosecutors have charged someone for the alleged destruction of data using a so-called "duress" password built into a phone's software. According to The Guardian, which covered the story earlier this week following the court's first hearing on Monday, Atlanta resident Samuel Tunick is fighting the charges. Tunick's attorneys said that it was unlawful for U.S. Customs and Border Protection to seize his phone as he arrived back in the U.S. last year, and that any evidence -- including the alleged wiping of his phone -- should be thrown out.

The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick's attorneys confirmed GrapheneOS was running on his phone. The software feature allows the device owner to set a passcode that deliberately wipes the contents of that device if entered instead of the user's unlock passcode. Tunick's case also raises ongoing questions about what constitutional rights can be invoked at the border, which the U.S. government has long asserted is not U.S. soil until a person is authorized to enter.
Bill Budington, a senior staff technologist at the Electronic Frontier Foundation, and Runa Sandvik, a digital security expert who works to protect at-risk people as the founder of security consultancy firm Granitt, told TechCrunch that they had not seen similar cases involving the use of duress passwords.

"I have not seen this before, though I've discussed the potential scenario with activists and journalists over the years," said Sandvik. "I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it's better to not have that data on you when you cross certain borders."

"With a little planning ahead of time, you can always download the data you need once you get to where you're going," said Sandvik.
Businesses

Stripe Eyes $10 Billion Deal For AI Model Marketplace OpenRouter (pymnts.com) 18

An anonymous reader quotes a report from PYMNTS.com: Stripe is in talks to buy OpenRouter, an artificial intelligence (AI) startup that could sell for roughly $10 billion, according to The Wall Street Journal. The move would mark a significant step outside payments for a company that processes transactions for much of the internet. It also lands while Stripe pursues a far larger target: a bid for PayPal that would value the payments giant at about $53 billion.

The Journal reported Thursday (July 23) that a transaction could be announced soon, though the talks could still collapse or another buyer could step in. The exact price under discussion could not be learned. Several other large technology companies had also been weighing deals for OpenRouter. The startup was valued at $1.3 billion in May, according to PitchBook, meaning a sale near $10 billion would represent a steep markup in a matter of months. Its backers include Menlo Ventures and CapitalG, the growth fund of Google parent Alphabet.

OpenRouter sells software that lets customers reach AI models from OpenAI and Anthropic, along with open weight alternatives anyone can download and run. The Journal described the company's position this way: "OpenRouter is part of an emerging crop of startups that have found a lucrative niche between AI developers and the companies that want to use them." The platform lists hundreds of large language models and lets developers compare and switch between them.

Slashdot Top Deals