Security

Millions of AirPlay Devices Can Be Hacked Over Wi-Fi (9to5mac.com) 39

A newly revealed set of vulnerabilities dubbed AirBorne in Apple's AirPlay SDK could allow attackers on the same Wi-Fi network to hijack tens of millions of third-party devices like smart TVs and speakers. While Apple has patched its own products, many third-party devices remain at risk, with the most severe (though unproven) threat being potential microphone access. 9to5Mac reports: Wired reports that a vulnerability in Apple's software development kit (SDK) means that tens of millions of those devices could be compromised by an attacker: "On Tuesday, researchers from the cybersecurity firm Oligo revealed what they're calling AirBorne, a collection of vulnerabilities affecting AirPlay, Apple's proprietary radio-based protocol for local wireless communication. Bugs in Apple's AirPlay software development kit (SDK) for third-party devices would allow hackers to hijack gadgets like speakers, receivers, set-top boxes, or smart TVs if they're on the same Wi-Fi network as the hacker's machine [...]

Oligo's chief technology officer and cofounder, Gal Elbaz, estimates that potentially vulnerable third-party AirPlay-enabled devices number in the tens of millions. 'Because AirPlay is supported in such a wide variety of devices, there are a lot that will take years to patch -- or they will never be patched,' Elbaz says. 'And it's all because of vulnerabilities in one piece of software that affects everything.'"

For consumers, an attacker would first need to gain access to your home Wi-Fi network. The risk of this depends on the security of your router: millions of wireless routers also have serious security flaws, but access would be limited to the range of your Wi-Fi. AirPlay devices on public networks, like those used everywhere from coffee shops to airports, would allow direct access. The researchers say the worst-case scenario would be an attacker gaining access to the microphones in an AirPlay device, such as those in smart speakers. However, they have not demonstrated this capability, meaning it remains theoretical for now.

Cellphones

Can a New 'Dumbphone' With an E Ink Display Help Rewire Your Brain? (zdnet.com) 97

ZDNet's reviewer says "I tested this affordable E Ink phone for two weeks, and it rewired my brain (for the better)." It's Mudita's new Kompakt smartphone with a two-color E Ink display — which ZDNet calls "an affordable choice" for those "considering investing in a so-called 'dumbphone'..." Compared to modern smartphones, the Mudita Kompakt is a bit chunky at half an inch thick and five inches long. It's still rather light, though, weighing just 164 grams and covered in soft touch material, so it feels good in the hand. The bezels around the 4.3-inch display are rather large, with three touch-sensitive buttons for back, home, and quick settings, so navigating to key elements is intuitive, whether you're coming from Android or iOS.

The phone features a fingerprint sensor to lock and unlock, and it's housed on the power button in the middle of the right side. I'm a huge fan of consolidating these two purposes to the same button, and it works flawlessly.... You can charge via the USB-C, but surprisingly, it also supports wireless charging. All in all, the battery is quite good. Mudita says it can last for up to six days on standby, with around two days of standard use. In my testing, I found this to be about accurate.

On the left side of the device is a button that houses one of its key features: offline mode. Switching to this mode disables all wireless connectivity and support for the camera, so it truly becomes distraction-free.. [T]here is undoubtedly some lag in certain apps — such as the camera — due to the E Ink display technology and processor/RAM specifications. You will also likely notice some lag in text messaging if you tap quickly on the keyboard, often resulting in getting ahead of the spell-checking feature. As far as apps go, in addition to phone calls and text messages, the Kompakt includes an alarm, calculator, chess game, maps, meditation, weather, and a voice recorder.

Phone calls "sounded great on both ends," according to the review. (And text messaging "works well if you don't tap too quickly on the keyboard.") But the 8MP camera produced photos "that look like they were taken over ten years ago." (And accessing the internal storage "requires connecting to a Windows PC and launching File Explorer," although "you can also just share photos via text messaging, as it's much faster than using a computer.") But ZDNet calls it an "attractive — if very simplified — E Ink display."

Mudita is asking $369 now for preorder customers, according to the article, while the phone will be available in May for $439.
Businesses

Comcast President Bemoans Broadband Customer Losses: 'We Are Not Winning' (arstechnica.com) 61

An anonymous reader quotes a report from Ars Technica: Comcast executives apparently realized something that customers have known and complained about for years: The Internet provider's prices aren't transparent enough and rise too frequently. This might not have mattered much to cable executives as long as the total number of subscribers met their targets. But after reporting a net loss of 183,000 residential broadband customers in Q1 2025, Comcast President Mike Cavanagh said the company isn't "winning in the marketplace" during an earnings call today. The Q1 2025 customer loss was over three times larger than the net loss in Q1 2024.

While customers often have few viable options for broadband and the availability of alternatives varies widely by location, Comcast faces competition from fiber and fixed wireless ISPs. "In this intensely competitive environment, we are not winning in the marketplace in a way that is commensurate with the strength of the network and connectivity products that I just described," Cavanagh said. "[Cable division CEO] Dave [Watson] and his team have worked hard to understand the reasons for this disconnect and have identified two primary causes. One is price transparency and predictability and the other is the level of ease of doing business with us. The good news is that both are fixable and we are already underway with execution plans to address these challenges." [...]

Cavanagh said that Comcast plans to make changes in marketing and operations "with the highest urgency." This means that "we are simplifying our pricing construct to make our price-to-value proposition clearer to consumers across all broadband segments," he said. Comcast last week announced a five-year price guarantee for broadband customers who sign up for a new package. Comcast said customers will get a "simple monthly price starting as low as $55 per month," without having to enter a contract, giving them "freedom and flexibility to cancel at any time without penalty." The five-year guarantee also comes with one year of Xfinity Mobile at no charge, Comcast said. [...] Additional offers are in the works, Cavanagh said. "We are not done. Providing more value to our customers with less complexity and friction is a top priority and you will see our go-to-market approach continue to evolve over the coming months," he said. Comcast investors shouldn't expect an immediate turnaround, though. "We anticipate that it will take several quarters for our new approach to gain traction and impact the business in a meaningful way," Cavanagh said.

IT

Logitech Quietly Raises Prices By Up To 25% (9to5mac.com) 149

Logitech has quietly increased prices on several flagship products by as much as 25%, according to findings (video) by YouTuber Cameron Dougherty. The MX Master 3S mouse now costs $120, up 20% from its previous $100 price point, while the MX Keys S keyboard has jumped 18% to $130. The K400 Plus Wireless Touch keyboard saw the most dramatic percentage increase, rising from $28 to $35.

These price adjustments, implemented without formal announcement, come amid ongoing tariff pressures from the Trump administration affecting PC hardware manufacturers. Chinese electronics maker Anker also recently implemented similar increases, suggesting a broader industry trend.
Input Devices

Brain Implant Cleared by America's FDA to Help Paralysis Patients (cnbc.com) 11

An anonymous reader shared this report from CNBC: Neurotech startup Precision Neuroscience on Thursday announced that a core component of its brain implant system has been approved by the U.S. Food and Drug Administration, a major win for the four-year-old company... The company's brain-computer interface will initially be used to help patients with severe paralysis restore functions such as speech and movement, according to its website.

Only part of Precision's system was approved by the FDA on Thursday, but it marks the first full regulatory clearance granted to a company developing a wireless BCI, Precision said in a release. Other prominent startups in the space include Elon Musk's Neuralink, and Synchron, which is backed by Amazon founder Jeff Bezos and Microsoft co-founder Bill Gates....

The piece of Precision's system that the FDA approved is called the Layer 7 Cortical Interface. The microelectrode array is thinner than a human hair and resembles a piece of yellow scotch tape. Each array is made up of 1,024 electrodes that can record, monitor and stimulate electrical activity on the brain's surface. When it is placed on the brain, Precision says it can conform to the surface without damaging any tissue. The FDA authorized Layer 7 to be implanted in patients for up to 30 days, and Precision will be able to market the technology for use in clinical settings. This means surgeons will be able to use the array during procedures to map brain signals, for instance. It is not Precision's end goal for the technology, but it will help the company generate revenue in the near term.

Precision's co-founder and chief science officer also helped co-found Musk's Neuralink in 2017 before departing the following year, according to the article. He nows says this regulatory clearance "will exponentially increase our access to diverse, high-quality data, which will help us to build BCI systems that work more effectively."
HP

HP Agrees To $4 Million Settlement Over Claims of 'Falsely Advertising' PCs, Keyboards 31

HP has agreed to a $4 million settlement over allegations of deceptive pricing practices on its website, including falsely inflating original prices for computers and accessories to create the illusion of steep discounts. Ars Technica reports: Earlier this month, Judge P. Casey Pitts for the US District Court of the San Jose Division of the Northern District of California granted preliminary approval [PDF] of a settlement agreement regarding a class-action complaint first filed against HP on October 13, 2021. The complaint accused HP's website of showing "misleading" original pricing for various computers, mice, and keyboards that was higher than how the products were recently and typically priced.

Per the settlement agreement [PDF], HP will contribute $4 million to a "non-reversionary common fund, which shall be used to pay the (i) Settlement Class members' claims; (ii) court-approved Notice and Settlement Administration Costs; (iii) court-approved Settlement Class Representatives' Service Award; and (iv) court-approved Settlement Class Counsel Attorneys' Fees and Costs Award. All residual funds will be distributed pro rata to Settlement Class members who submitted valid claims and cashed checks."

The two plaintiffs who filed the initial complaint may also file a motion to receive a settlement class representative service award for up to $5,000 each, which would come out of the $4 million pool. People who purchased a discounted HP desktop, laptop, mouse, or keyboard that was on sale for "more than 75 percent of the time the products were offered for sale" from June 5, 2021, to October 28, 2024, are eligible for compensation. The full list of eligible products is available here [PDF] and includes HP Spectre, Chromebook Envy, and Pavilion laptops, HP Envy and Omen desktops, and some mechanical keyboards and wireless mice. Depending on the product, class members can receive $10 to $100 per eligible product purchased.
Wikipedia

Wikimedia Drowning in AI Bot Traffic as Crawlers Consume 65% of Resources 73

Web crawlers collecting training data for AI models are overwhelming Wikipedia's infrastructure, with bot traffic growing exponentially since early 2024, according to the Wikimedia Foundation. According to data released April 1, bandwidth for multimedia content has surged 50% since January, primarily from automated programs scraping Wikimedia Commons' 144 million openly licensed media files.

This unprecedented traffic is causing operational challenges for the non-profit. When Jimmy Carter died in December 2024, his Wikipedia page received 2.8 million views in a day, while a 1.5-hour video of his 1980 presidential debate caused network traffic to double, resulting in slow page loads for some users.

Analysis shows 65% of the foundation's most resource-intensive traffic comes from bots, despite bots accounting for only 35% of total pageviews. The foundation's Site Reliability team now routinely blocks overwhelming crawler traffic to prevent service disruptions. "Our content is free, our infrastructure is not," the foundation said, announcing plans to establish sustainable boundaries for automated content consumption.
AT&T

AT&T Email-To-Text Gateway Service Ending (att.com) 24

Longtime Slashdot reader CyberSlugGump shares a support article from AT&T, writing: On June 17th, AT&T will stop supporting email-to-text messages. That means you won't be able to send a text message to an AT&T customer from an email address. You can still get in touch with AT&T customers using SMS (text), MMS, and standard email services.
Crime

FedEx Data Scraping and Telecom Insider Bribes Powered Nationwide iPhone Theft Operation (wsj.com) 20

Federal authorities have broken up an international crime ring that stole thousands of iPhones from porches nationwide [non-paywalled link], arresting 13 people last month after a sophisticated operation that combined high-tech tools with old-fashioned bribery.

The thieves created software to scrape FedEx tracking numbers and paid AT&T store employees to provide customer order details and delivery addresses, according to WSJ, which cites prosecutors. Armed with this information, runners intercepted packages at doorsteps moments after delivery.

Demetrio Reyes Martinez, known online as "CookieNerd," developed code that circumvented FedEx limits on delivery-data requests, while AT&T employee Alejandro Then Castillo used his credentials to track hundreds of shipments and reportedly received up to $2,500 for recruiting other employees. Stolen devices were funneled through Wyckoff Wireless in Brooklyn, a store owned by Joel Suriel, who was already on supervised release from a previous wire-fraud conviction. The merchandise was then shipped overseas for sale and activation.
Government

Consumer Groups Push New Law Fighting 'Zombie' IoT Devices (consumerreports.org) 56

Long-time Slashdot reader chicksdaddy writes: A group of U.S. consumer advocacy groups on Wednesday proposed legislation to address the growing epidemic of "zombie" Internet of Things (IoT) devices that have had software support cut off by their manufacturer, Fight To Repair News reports.

The Connected Consumer Product End of Life Disclosure Act is a collaboration between Consumer Reports, US PIRG, the Secure Resilient Future Foundation (SRFF) and the Center for Democracy and Technology. It requires manufacturers of connected consumer products to disclose for how long they will provide technical support, security updates, or bug fixes for the software and hardware that are necessary for the product to operate securely.

The groups proposed legal requirements that manufacturers "must notify consumers when their devices are nearing the end of life and provide guidance on how to handle the device's end of life," while end-of-life notifications "must include details about features that will be lost, and potential vulnerabilities and security risks that may arise." And when an ISP-provided device (like a router) reaches its end of life, the ISP must remove them.

"The organizations are working with legislators at the state and federal level to get the model legislation introduced," according to Fight To Repair News.
Television

NAB Calls For End of ATSC 1.0 (broadbandtvnews.com) 47

An anonymous reader quotes a report from Broadband TV News: The National Association of Broadcasters (NAB) has filed a petition with the Federal Communications Commission (FCC) urging the agency to establish a clear, industry-wide transition plan for the full deployment of Next Gen TV (ATSC 3.0). The proposal outlines a two-phased transition while modernizing regulatory requirements to support consumer access and innovation. [...] Under the plan, stations in the top 55 markets, covering 70% of the US population, would transition by February 2028, with all remaining full-power and Class A stations following in or before February 2030. The petition also calls for updates to FCC rules to ensure television reception devices support Next Gen TV, maintain existing MVPD carriage obligations and eliminate regulatory hurdles that could slow adoption. To clarify, ATSC 1.0 is the current standard for free over-the-air (OTA) TV. While ATSC 3.0 (also called NextGen TV) is its intended replacement, it's not backward-compatible, meaning consumers need new equipment to receive it. NAB's petition is to allow a complete shutdown of ATSC 1.0 to accelerate the transition to ATSC 3.0, meaning older TV setups relying on free OTA signals would stop working unless consumers upgrade their equipment. Their argument is that ATSC 3.0 adoption has been slow, and networks would benefit more from shifting away from OTA broadcasting entirely.

Reddit user bshensky argues that shutting down OTA TV would benefit large media corporations and harm independent stations. It's also worth noting that OTA TV operates on valuable spectrum, which could be repurposed for mobile broadband (this has happened before), benefiting cellular providers.
China

Undocumented 'Backdoor' Found In Chinese Bluetooth Chip Used By a Billion Devices (bleepingcomputer.com) 129

"The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains an undocumented 'backdoor' that could be leveraged for attacks," writes BleepingComputer.

"The undocumented commands allow spoofing of trusted devices, unauthorized data access, pivoting to other devices on the network, and potentially establishing long-term persistence." This was discovered by Spanish researchers Miguel Tarascó Acuña and Antonio Vázquez Blanco of Tarlogic Security, who presented their findings yesterday at RootedCON in Madrid. "Tarlogic Security has detected a backdoor in the ESP32, a microcontroller that enables WiFi and Bluetooth connection and is present in millions of mass-market IoT devices," reads a Tarlogic announcement shared with BleepingComputer. "Exploitation of this backdoor would allow hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks or medical equipment by bypassing code audit controls...."

Tarlogic developed a new C-based USB Bluetooth driver that is hardware-independent and cross-platform, allowing direct access to the hardware without relying on OS-specific APIs. Armed with this new tool, which enables raw access to Bluetooth traffic, Targolic discovered hidden vendor-specific commands (Opcode 0x3F) in the ESP32 Bluetooth firmware that allow low-level control over Bluetooth functions. In total, they found 29 undocumented commands, collectively characterized as a "backdoor," that could be used for memory manipulation (read/write RAM and Flash), MAC address spoofing (device impersonation), and LMP/LLCP packet injection.

Espressif has not publicly documented these commands, so either they weren't meant to be accessible, or they were left in by mistake.

Thanks to Slashdot reader ZipNada for sharing the news.
United States

US Congressional Panel Urges Americans To Ditch China-made Routers (reuters.com) 209

A U.S. congressional committee has urged Americans to remove Chinese-made wireless routers from their homes, including those made by TP-Link, calling them a security threat that opened the door for China to hack U.S. critical infrastructure. From a report: The House of Representatives Select Committee on China has pushed the Commerce Department to investigate China's TP-Link Technology Co, which according to research firm IDC is the top seller of WiFi routers internationally by unit volume. U.S. authorities are considering a ban on the sale of the company's routers, according to media reports.

Rob Joyce, former director of cybersecurity at the National Security Agency, told Wednesday's committee hearing that TP-Link devices exposed individuals to cyber intrusion that hackers could use to gain leverage to attack critical infrastructure. "We need to all take action and replace those devices so they don't become the tools that are used in the attacks on the U.S.," Joyce said, adding that he understood the Commerce Department was considering a ban.

Hardware

Asus Continues Fragrant Device Trend With an Aromatic Mouse 41

Asus has introduced the Fragrance Mouse, a hybrid wireless mouse that features a removable container for fragrance oils. Despite not being a gaming mouse, it includes premium features like PTFE pads, low-noise clicks rated for up to 10 million presses, and three fixed DPI settings (1200, 1600, 2400). Tom's Hardware reports: The selling point of the new mouse is its fragrance-producing capabilities. Under the mouse (right behind the AA battery housing) is a small semi-translucent container designed to house oils that give the mouse a pleasing aroma. There's no limit to what scents can be used; the container can be washed and refilled with different scents. Last year, the peripheral maker debuted an aroma-dispensing laptop that featured a fragrance dispenser at the center of the lid.
Iphone

Apple Launches the iPhone 16E, With In-House Modem and Support For AI (theverge.com) 82

Apple has launched the iPhone 16E, featuring a 6.1-inch OLED display, Face ID, an A18 chipset, USB-C, 48MP camera, and support for Apple Intelligence. Gone but not forgotten: the home button, Touch ID and 64GB of base storage. The Verge reports: The 16E includes the customizable Action Button, but not the new Camera Control you'll find on the 16 series. It does swap its Lightning port for USB-C, now a requirement for the phone to be sold in the EU. On the inside, there's an A18 chipset, the same chip as the iPhone 16. That makes the 16E powerful enough to run Apple Intelligence, the suite of AI tools that includes notification summaries. Even the non-Pro iPhone 15 can't do that, so the 16E is one of the most capable iPhones out there. Apple has previously confirmed that 8GB RAM was the minimum to get Apple Intelligence support in the iPhone 16 series, so it's likely that the 16E also boasts at least that much memory. It's also been bumped to a baseline of 128GB of storage, meaning there's no longer a 64GB iPhone.

There's only a single 48-megapixel rear camera; the lack of additional cameras is the biggest downgrade compared to the company's other handsets. With support for wireless charging and a water-resistant IP rating, there's little you have to give up elsewhere. The iPhone 16E is also the first iPhone to include a modem developed by Apple itself. The company has spent years trying to move away from modems developed by Qualcomm, and we're finally seeing the fruits of that labor. The big questions now are how well the new modem performs and whether Apple is ready to roll out its own connectivity components in the iPhone 17 line later this year.
It's available for Friday starting at $599 with 128GB of storage.
Cellphones

Free 'T-Mobile Starlink' for Six Months Announced During Super Bowl. Also Available to Verizon and AT&T Customers 211

Today T-Mobile announced what they're calling "the next big thing in wireless" — T-Mobile Starlink. But the real surprise is "The beta is now open for absolutely everyone — yes, even Verizon and AT&T customers — to register for free access until July."

And, as they explained to Americans watching the Super Bowl, "If you can see the sky you're connected." Now in public beta, this breakthrough service, developed in partnership with Starlink, uses straight-out-of-a-sci-fi-movie satellite and mobile communications technology to help keep people connected — even you, Verizon and AT&T customers — in the more than 500,000 square miles of the country unreached by any carrier's earth-bound cell towers. That's nearly the size of two Texases...! The beauty of the service is its simplicity: users don't need to do anything out of the ordinary. When a user's cell phone gets out of range of a cell tower, the phone automatically connects to the T-Mobile Starlink network. No need to manually connect. Messages are sent and received just as they are today on a traditional network, even group texts and reactions. And it works on most smartphones from the last four years. It's not limited to a few smartphones or operating systems...

The beta is free until July at which point T-Mobile Starlink will be included at no extra cost on Go5G Next (including variations like Go5G Next 55+), T-Mobile's best plan. Business customers will also get T-Mobile Starlink at no extra cost on Go5G Business Next, first responder agencies on T-Priority plans and other select premium rate plans. T-Mobile customers on any other plan can add the service for $15/month per line. Through February, T-Mobile customers who have registered for the beta can secure a $10/month per line Early Adopter Discount, 33% off the full price.

AT&T and Verizon customers hate dead zones, too

When your service is amazing and different, you want as many people to try it as possible. T-Mobile is giving AT&T and Verizon customers the opportunity to try out T-Mobile Starlink satellite service on their existing phones... During the beta period, Verizon and AT&T customers can experience T-Mobile Starlink text messaging for free, and once the service launches in July, it will be available for $20/month per line... More details and consumer registration can be found here.

A Vision for Universal Coverage

As T-Mobile and Starlink continue to work towards eliminating mobile deadzones, the companies welcome wireless providers from around the world to join their growing alliance, which aims to provide reciprocal roaming for all participating carriers. So far, KDDI (Japan), Telstra (Australia), Optus (Australia), One NZ (New Zealand), Salt (Switzerland), Entel (Chile & Peru), Rogers (Canada) and Kyivstar (Ukraine) are among the providers that have signed on to join the cause and launch satellite-to-mobile technology. Learn more about the alliance and how providers can join at direct.starlink.com.
Network

$42 Billion Broadband Grant Program May Scrap Biden Admin's Preference For Fiber (arstechnica.com) 106

An anonymous reader quotes a report from Ars Technica: US Senator Ted Cruz (R-Texas) has been demanding an overhaul of a $42.45 billion broadband deployment program, and now his telecom policy director has been chosen to lead the federal agency in charge of the grant money. "Congratulations to my Telecom Policy Director, Arielle Roth, for being nominated to lead NTIA," Cruz wrote last night, referring to President Trump's pick to lead the National Telecommunications and Information Administration. Roth's nomination is pending Senate approval. Roth works for the Senate Commerce Committee, which is chaired by Cruz. "Arielle led my legislative and oversight efforts on communications and broadband policy with integrity, creativity, and dedication," Cruz wrote.

Shortly after Trump's election win, Cruz called for an overhaul of the Broadband Equity, Access, and Deployment (BEAD) program, which was created by Congress in November 2021 and is being implemented by the NTIA. Biden-era leaders of the NTIA developed rules for the program and approved initial funding plans submitted by every state and territory, but a major change in approach could delay the distribution of funds. Cruz previously accused the NTIA of "technology bias" because the agency prioritized fiber over other types of technology. He said Congress would review BEAD for "imposition of statutorily-prohibited rate regulation; unionized workforce and DEI labor requirements; climate change assessments; excessive per-location costs; and other central planning mandates."

Roth criticized the BEAD implementation at a Federalist Society event in June 2024. "Instead of prioritizing connecting all Americans who are currently unserved to broadband, the NTIA has been preoccupied with attaching all kinds of extralegal requirements on BEAD and, to be honest, a woke social agenda, loading up all kinds of burdens that deter participation in the program and drive up costs," she said. Municipal broadband networks and fiber networks in general could get less funding under the new plans. Roth is "expected to change the funding conditions that currently include priority access for government-owned networks" and "could revisit decisions like the current preference for fiber," Bloomberg reported, citing people familiar with the matter.
Congress defined priority broadband projects under BEAD as those that "ensure that the network built by the project can easily scale speeds over time to meet the evolving connectivity needs of households and businesses; and support the deployment of 5G, successor wireless technologies, and other advanced services."

The Biden NTIA determined that only end-to-end fiber-optic architecture meet these criteria. "End-to-end fiber networks can be updated by replacing equipment attached to the ends of the fiber-optic facilities, allowing for quick and relatively inexpensive network scaling as compared to other technologies. Moreover, new fiber deployments will facilitate the deployment and growth of 5G and other advanced wireless services, which rely extensively on fiber for essential backhaul," the Biden NTIA said (PDF).
Medicine

America's FDA Warns About Backdoor Found in Chinese Company's Patient Monitors (fda.gov) 51

Thursday America's FDA "raised concerns about cybersecurity vulnerabilities" in patient monitors from China-based medical device company Contec "that could allow unauthorized individuals to access and potentially manipulate those devices," reports Reuters. The patient monitors could be remotely controlled by unauthorized users or may not function as intended, and the network to which these devices are connected could be compromised, the agency warned. The FDA also said that once these devices are connected to the internet, they can collect patient data, including personally identifiable information and protected health information, and can export this data out of the healthcare delivery environment.

The agency, however, added that it is currently unaware of any cybersecurity incidents, injuries, or deaths related to these identified cybersecurity vulnerabilities.

The FDA's announcement says "The software on the patient monitors includes a backdoor, which may mean that the device or the network to which the device has been connected may have been or could be compromised." And it offers this advice to caregivers and patients: If your health care provider confirms that your device relies on remote monitoring features, unplug the device and stop using it. Talk to your health care provider about finding an alternative patient monitor.

If your device does not rely on remote monitoring features, use only the local monitoring features of the patient monitor. This means unplugging the device's ethernet cable and disabling wireless (that is, WiFi or cellular) capabilities, so that patient vital signs are only observed by a caregiver or health care provider in the physical presence of a patient. If you cannot disable the wireless capabilities, unplug the device and stop using it. Talk to your health care provider about finding an alternative patient monitor.

A detailed report from CISA describes how a research team "created a simulated network, created a fake patient profile, and connected a blood pressure cuff, SpO2 monitor, and ECG monitor peripherals to the patient monitor. Upon startup, the patient monitor successfully connected to the simulated IP address and immediately began streaming patient data..." to an IP address that hard-coded into the backdoor function. "Sensor data from the patient monitor is also transmitted to the IP address in the same manner. If the routine to connect to the hard-coded IP address and begin transmitting patient data is called, it will automatically initialize the eth0 interface in the same manner as the backdoor. This means that even if networking is not enabled on startup, running this routine will enable networking and thereby enable this functionality
The Courts

US DOJ Sues To Block Hewlett Packard Enterprise's $14 Billion Juniper Deal (msn.com) 17

Longtime Slashdot reader nunya_bizns shares a report from Reuters: The U.S. Department of Justice has sued to block Hewlett Packard Enterprise's $14 billion deal to acquire networking gear maker Juniper Networks, arguing that it would stifle competition, according to a complaint filed on Thursday. The DOJ argued that the acquisition would eliminate competition and would lead to only two companies -- Cisco Systems and HPE -- controlling more than 70% of the U.S. market for networking equipment. More than a year ago, the server maker said that it would buy Juniper Networks for $14 billion in an all-cash deal, as it looks to spruce up its artificial intelligence offerings.

"Juniper has also introduced innovative tools that have materially decreased the cost of operating a wireless network for many customers. This competitive pressure has forced HPE to discount its offerings and invest in its own innovation," the DOJ said in its complaint. Stiff competition from Juniper forced HPE to sell its products at a discount and spend to introduce new features under the "Beat Mist" campaign, named after the networking gear company's rival product, the DOJ wrote. "Having failed to beat Mist on the merits, HPE changed tactics and in January 2024 opted to try to buy Juniper instead," the agency added.

AT&T

AT&T Kills Home Internet Service In New York Over Law Requiring $15 Plans (arstechnica.com) 134

Ars Technica's Jon Brodkin reports: AT&T has stopped offering its 5G home Internet service in New York instead of complying with a new state law that requires ISPs to offer $15 or $20 plans to people with low incomes. New York started enforcing its Affordable Broadband Act yesterday after a legal battle of nearly four years. [...] The law requires ISPs with over 20,000 customers in New York to offer $15 broadband plans with download speeds of at least 25Mbps, or $20-per-month service with 200Mbps speeds. The plans only have to be offered to households that meet income eligibility requirements, such as qualifying for the National School Lunch Program, Supplemental Nutrition Assistance Program, or Medicaid. [...]

Ending home Internet service in New York is relatively simple for AT&T because it is outside the 21-state wireline territory in which the telco offers fiber and DSL home Internet service. "AT&T Internet Air is currently available only in select areas and where AT&T Fiber is not available. New York is outside of our wireline service footprint, so we do not have other home Internet options available in the state," the company said. AT&T will continue offering its 4G and 5G mobile service in New York, as the state law only affects home Internet service. People with smartphones or other mobile devices connected to the AT&T wireless network should thus see no change.

Existing New York-based users of AT&T Internet Air can only keep it for 45 days and won't be charged during that time, AT&T said. "During this transition, customers will be able to keep their existing AT&T Internet Air service for up to 45 days, at no charge, as they find other options for broadband. We will work closely with our customers throughout this transition," AT&T said. Residential users will be sent "a recovery kit with instructions on how to return their AIA equipment, while business customers can keep any device they purchased at no charge," AT&T said.

Slashdot Top Deals