Wireless Networking

US Rollout of 5G Frequencies Delayed Over Aviation Safety Concerns. Are They Warranted? (usatoday.com) 31

Because of a "surprising and sudden request" from America's Federal Aviation Administration that's "based on unverified potential radio interference, a highly anticipated increase in 5G speeds and availability just got put on hold," writes the president/chief analyst of market research/consulting firm TECHnalysis.

But in an opinion piece for USA Today, he asks if the concern is actually warranted? [A]s soon as you start to dig into the details, the concerns quickly seem less practical and more political. Most notably, the plan to launch 5G services on C-Band frequencies has been in the works for several years and really took on momentum after the three big U.S. carriers spent over $80 billion earlier this year to get access to these frequencies. In addition, a report that the FAA cited as part of their complaint has been out for well over a year, so why the last-minute concerns?

U.S. government agencies are, unfortunately, known to hold grudges against one another, sometimes without real clarity as to what's actually involved, as appears to be the case here... Some 40 countries around the world are already using most of the C-Band frequencies for 5G (part of the reason the U.S. has fallen behind on the 5G front), and none have reported any interference with radio altimeters on planes in their countries, the wireless trade association CTIA argues on its website 5GandAviation.com. In addition, new filtering technologies being built into a somewhat obscure part of smartphones called the RF (radio frequency) front end, such as Qualcomm's recently introduced ultraBAW filters, can reduce interference issues on next generation smartphones.

All told, there are numerous reasons why the FAA's concerns around 5G deployment look to be more of a red herring than a legitimate technical concern. While it is true that some older radio altimeters with poor filtering might have to be updated and/or replaced to completely prevent interference, it's not clear that the theoretical interference would even cause an issue.

The article complains that the delayed expansion of bandwidth "could also delay important (and significant) economic impacts," since every previous change in cellular service levels "has triggered billions of dollars of new business and thousands of new jobs by creating new opportunities that faster wireless networks bring with them and 5G is expected do the same...

"While airplane safety shouldn't be compromised in any way, an overabundance of unnecessary caution on this issue could have a much bigger negative impact on the U.S.'s technology advancements and economy than many realize."
EU

Austria Expected to Impose Lockdown Only On the Unvaccinated (cnbc.com) 287

"Austria is expected to impose lockdown restrictions on millions of unvaccinated people in the coming days," reports CNBC: Chancellor Alexander Schallenberg told a press conference Friday that his government wanted to give the "green light" to such measures by Sunday, Austria Press Agency reported. Lawmakers will meet over the weekend to discuss the move, according to the news agency.

The chancellor rejected the notion of a nationwide lockdown being applied to all of Austria's citizens, telling reporters on Friday that the two-thirds of the population who had accepted the immunization would not be forced to show "solidarity" with the unvaccinated. However, he did caution that there may be some tightening of other restrictions.

Schallenberg said last month that if Covid-19 cases continued to rise, unvaccinated people would face new lockdown restrictions in line with the government's incremental plan. That strategy would place unvaccinated people under lockdown once coronavirus patients occupy 30% of ICU beds in hospitals.

Covid patients currently take up 20% of ICU beds in Austria, according to Reuters, and that level is rising fast.

On Thursday Schallenberg had said that he didn't see "why two-thirds should lose their freedom because one-third is dithering."

Meanwhile, the Associated Press reports that starting Monday the country of Latvia will ban unvaccinated lawmakers from attending in-person and remote parliament meetings. "Their wages also will be suspended if they are not able to work at the parliament."
Government

Last Year's Texas Power Outage Will Now Cost Natural Gas Customers $3.4 Billion (arstechnica.com) 174

"Texans will be paying for the effects of last February's cold snap for decades to come," reports Ars Technica, "as the state's oil and gas regulator approved a plan for natural gas utilities to recover $3.4 billion in debt they incurred during the storm.

"The regulator, the Railroad Commission, is allowing utilities to issue bonds to cover the debt. As a result, ratepayers could see an increase in their bills for the next 30 years." During the winter storm, natural gas prices spiked as cold temperatures drove demand up while also depressing supply... The governor's office knew of the looming shortages days before they happened, yet the preparations they made did little to alter the course of the disaster... Gas sellers made record profits in just a few days, together bringing in as much as $11 billion, about 70-100 times more than normal, based on spot prices at the time. Meanwhile, many Texans suffered through blackouts and bitter cold, and 210 people died, according to the latest estimate from the Texas Department of State Health Services.

In the wake of the storm, many officials have called on utilities and oil and gas companies to winterize their operations...

Texans aren't the only ones whose bills are higher as a result of producers' and utilities' unwillingness to winterize their equipment. Utilities around the country were forced to buy natural gas at significantly higher prices when Texas' markets went haywire as a result of low supply and high demand. Ratepayers as far away as Minnesota will be paying surcharges for years to come after their utilities had to pay $800 million more than expected for natural gas.

The article also includes a quote from Katie Sieben, chairwoman of the Minnesota Public Utility Commission, from an April article in The Washington Post.

"It is maddening and outrageous and completely inexcusable that Texas' lack of sound utility regulation is having this impact on the rest of the country."
Patents

Apple Patent Fights Lookie-Loos With Glass-Activated Screen Blur (arstechnica.com) 24

An anonymous reader quotes a report from Ars Technica: A patent filed by Apple and published Thursday by the US Patent and Trademark Office details the tech giant's interest in creating "privacy eyewear" that blurs content on a device's screen unless someone is wearing special glasses to look at it. As spotted by Patently Apple, the patent, which focuses on creating different FaceID profiles for various visual impairments, explores a new type of privacy screen. The patent doesn't specify any Apple product by name. Instead, it refers to electronic devices in general, including smartphones, watches, laptops, TVs, and car displays. Drawings in the patent show the feature working on a smartphone-like device. The technology would use a face scan to determine if the user is wearing the required glasses. It could recognize the headgear by a specific graphic, such as a QR or bar code.

If you're worried about someone looking at your phone over your shoulder, you could activate the feature "to make the graphical output illegible." Your privacy eyewear, meanwhile, would "counteract the intentional blur." "The blurred graphical output may compensate for the distortion created by the privacy eyewear vision of the user by, for example, blurring a portion and/or the entirety of a standard graphical output; generating an overlay over the standard graphical output; and/or making elements of the standard graphical output larger, brighter, and/or more distinct," Apple's patent reads. "In some embodiments, the blurred graphical output may only replace certain graphical elements presented in the standard graphical output. The blurred graphical output may be a default graphical output designed to compensate for the privacy eyewear."
Further reading: Apple Aiming To Announce Mixed-Reality Headset In 'Next Several Months'
Privacy

Contract Lawyers Face a Growing Invasion of Surveillance Programs that Monitor their Work (washingtonpost.com) 59

The attorneys worry that if law firms, traditionally the defenders of workers' rights, are turning to the programs, why wouldn't every other business? From a report: Camille Anidi, an attorney on Long Island, quickly understood the flaws of the facial recognition software her employers demanded she use when working from home. The system often failed to recognize her face or mistook the Bantu knots in her hair as unauthorized recording devices, forcing her to log back in sometimes more than 25 times a day. When she complained, she said, her bosses brushed it off as a minor technical issue, though some of her lighter-skinned colleagues told her they didn't have the same problem -- a common failing for some facial recognition systems, which have been shown to perform worse for people of color. So after each logout, Anidi gritted her teeth and did what she had to do: Re-scan her face from three angles so she could get back to a job where she was often expected to review 70 documents an hour.

"I want to be able to do the work and would love the money, but it's just that strain: I can't look left for too long, I can't look down, my dog can't walk by, or I get logged out," she said. "Then the company is looking at me like I'm the one delaying!" Facial recognition systems have become an increasingly common element of the rapid rise in work-from-home surveillance during the coronavirus pandemic. Employers argue that they offer a simple and secure way to monitor a scattered workforce. But for Anidi and other lawyers, they serve as a dehumanizing reminder that every second of their workday is rigorously probed and analyzed: After verifying their identity, the software judges their level of attention or distraction and kicks them out of their work networks if the system thinks they're not focused enough.

Contract attorneys such as Anidi have become some of America's first test subjects for this enhanced monitoring, and many are reporting frustrating results, saying the glitchy systems make them feel like a disposable cog with little workday privacy. But the software has also become a flash point for broader questions about how companies treat their remote workforces, especially those, like contract attorneys, whose short-term gigs limit their ability to push for change. The attorneys also worry that it could become the new norm as more jobs are automated and analyzed: If the same kinds of law firms that have litigated worker protections and labor standards are doing it, why wouldn't everyone else?

Government

Seoul Will Be the First City Government To Join the Metaverse (qz.com) 51

An anonymous reader quotes a report from Quartz: Seoul says it will be the first major city government to enter the metaverse. On Nov. 3, the South Korean capital announced a plan to make a variety of public services and cultural events available in the metaverse, an immersive internet that relies on virtual reality. If the plan is successful, Seoul residents can visit a virtual city hall to do everything from touring a historic site to filing a civil complaint by donning virtual reality goggles. The 3.9 billion won ($3.3 million) investment is part of mayor Oh Se-hoon's 10-year plan for the city, which aims to improve social mobility among citizens and raising the city's global competitiveness. It also taps into South Korea's Digital New Deal, a nationwide plan to embrace digital and AI tools to improve healthcare, central infrastructure, and the economy in its recovery from the economic crisis caused by covid-19.

Seoul's metropolitan government will develop its own metaverse platform by the end of 2022. By the time it is fully operational in 2026, it will host a variety of public functions including a virtual mayor's office, as well as spaces serving the business sector; a fintech incubator; and a public investment organization. The platform will kick off with a virtual new year's bell-ringing ceremony this December. In 2023, the city plans to open "Metaverse 120 Center," a place for virtual public services where avatars will handle citizen concerns that could previously only be addressed by physically going to city hall. So far the plan offers sparse details about exactly what devices citizens will use to access the metaverse platform, though city officials emphasize that the goal is to broaden access to public city services, regardless of geography or disabilities. But specialized equipment could be a barrier for many people. Virtual reality headsets still sell for $300 and $600, and are not as widely accessible as smartphones and computers.

The Courts

Lawsuit Over Subway Tuna Now Says Chicken, Pork, Cattle DNA Were Detected 136

A new version of a lawsuit accusing Subway of deceiving the public about its tuna products said lab testing shows they contain animal proteins such as chicken, pork and cattle, and not the advertised "100% tuna." From a report: Karen Dhanowa and Nilima Amin filed a third version of their proposed class action this week in the federal court in San Francisco, near their homes in Alameda County. Subway said in a statement it will seek to dismiss the "reckless and improper" lawsuit. The chain said the plaintiffs have "filed three meritless complaints, changing their story each time," and that its "high-quality, wild-caught, 100% tuna" was regulated strictly in the United States and around the world. Since the case began in January, Subway has run TV ads and launched a website defending its tuna. It also revamped its menu but not its tuna, saying an upgrade wasn't needed. The original complaint claimed that Subway tuna salads, sandwiches and wraps were "bereft" of tuna, while an amended complaint said they were not 100% sustainably caught skipjack and yellowfin tuna. Further reading, from last year: Irish Court Says Subway Bread Is Too Sugary to Be Called 'Bread'.
Privacy

Infrastructure Bill's Drunk Driving Tech Mandate Leaves Some Privacy Advocates Nervous (gizmodo.com) 138

An anonymous reader quotes a report from Gizmodo: The recently passed $1 trillion infrastructure package is jam-packed with initiatives but sprinkled in there alongside $17 billion in funding for road safety programs is a mandate requiring carmakers to implement monitoring systems to identify and stop drunk drivers. The mandate, first noted by the Associated Press could apply to new vehicles sold as early as 2026. Courts have ordered some drunk drivers to use breathalyzers attached to ignition interlocks to start their vehicles for years, but the technology noted in this bill would take that concept much further and would need to be capable of "passively monitor[ing] the performance of a driver of a motor vehicle to accurately identify whether that driver may be impaired."

Though the Department of Transportation has yet to put its foot down on the exact type of technology it will use for this program, the National Highway Traffic Safety Administration (NHTSA) and 17 automakers have been working on something called the Driver Alcohol Detection System for Safety (DADSS) since 2008. DADSS is exploring both a breath and touch-based system to detect whether or not a driver has a blood alcohol concentration (BAC) at or above 0.08%. The breath-based system aims to measure alcohol readings based on a driver's breath with the goal of distinguishing between the driver and passengers. The touch-based system meanwhile would shine an infrared light through a driver's fingertip to measure blood alcohol levels under the skin's surface. [...]

The new mandate struck a positive note with some car safety groups, including Mothers Against Drunk Driving which has advocated for more detection tech in the past. "It's monumental," Alex Otte, national president of Mothers Against Drunk Driving told the AP. Otte went on to describe the package as the "single most important legislation" in the group's history. At the same time though, the mandate has drawn concerns from safety experts and digital rights groups that warn driver monitoring technology could have knock-on privacy implications. In a letter sent last year by the American Highway Users Alliance, the organization urged support of the NHTSA's DADSS Research Program but expressed concerns that the technology could potentially infringe on driver's civil liberties.
"The group also expressed concerns over how the collection and storage of driver data would work and who would have the rights to that data," adds Gizmodo. Others have also expressed concerns over the accuracy of driving monitoring technology and potential risks of bias.
The Courts

Justice Department Sues Uber Over Charging Wait-Time Fees for Disabled People (wsj.com) 84

The Justice Department said Wednesday that it was suing Uber for charging wait-time fees to passengers with physical disabilities. From a report: The suit, filed in the U.S. District Court for the Northern District of California, alleges that the company violated the Americans with Disabilities Act for charging fees to passengers who, because of disability, need more time to enter a car.
Google

Google Loses Challenge Against EU Antitrust Ruling, $2.8 Billion Fine (reuters.com) 15

Alphabet unit Google lost an appeal against a 2.42-billion-euro ($2.8-billion) antitrust decision on Wednesday, a major win for Europe's competition chief in the first of three court rulings central to the EU push to regulate big tech. From a report: Competition Commissioner Margrethe Vestager fined the world's most popular internet search engine in 2017 over the use of its own price comparison shopping service to gain an unfair advantage over smaller European rivals. The shopping case was the first of three decisions that saw Google rack up 8.25 billion euros in EU antitrust fines in the last decade. The company could face defeats in appeals against the other two rulings involving its Android mobile operating system and AdSense advertising service, where the EU has stronger arguments, antitrust specialists say. The court's support for the Commission in its latest ruling could also strengthen Vestager's hand in her investigations into Amazon, Apple and Facebook.
The Courts

Apple Can't Delay App Store December Deadline As Epic Legal Battle Continues (bloomberg.com) 24

An anonymous reader quotes a report from Bloomberg: Apple failed to persuade a federal judge to push back a December deadline to change the lucrative business model for its App Store while the iPhone maker's legal fight with Epic Games is appealed. Unless the iPhone maker wins a reprieve from an appeals court, it will soon have to start allowing developers to steer customers to payment methods outside the App Store, an overhaul the judge ordered in September that could cost the tech giant a few billion dollars annually. Apple asked U.S. District Judge Yvonne Gonzales Rogers to put on hold a part of the injunction that said the company must undo its rule forbidding developers from using web links or other means within apps to inform consumers about payment methods outside the App Store. "Apple's motion is based on a selective reading of this court's findings and ignores all of the findings which supported the injunction," Rogers said in an order Tuesday. "The motion is fundamentally flawed."

"Apple believes no additional business changes should be required to take effect until all appeals in this case are resolved," the company said in a statement. While Apple largely won its showdown with Epic, the world's most valuable technology company isn't out of danger from challenges to its role as a gatekeeper to the digital economy. The iPhone maker continues to face a plethora of antitrust lawsuits in and outside the U.S seeking to open up the App Store to competition, monopolization enforcement investigations brought by federal and state agencies, and legislative bids to restrict its business practices. Bloomberg Intelligence has said that pressure on Apple to lower its App Store commissions on developers, which currently run as high as 30%, could squeeze revenue by $2 billion to $4 billion in a worst-case scenario.

United States

The US Treasury Is Buying Private App Data to Target and Investigate People (theintercept.com) 44

The Treasury Department has in recent months expanded its digital surveillance powers, contracts provided to The Intercept reveal, turning to the controversial firm Babel Street, whose critics say it helps federal investigators buy their way around the Fourth Amendment. From a report: Two contracts obtained via a Freedom of Information Act request and shared with The Intercept by Tech Inquiry, a research and advocacy group, show that over the past four months, the Treasury acquired two powerful new data feeds from Babel Street: one for its sanctions enforcement branch, and one for the Internal Revenue Service. Both feeds enable government use of sensitive data collected by private corporations not subject to due process restrictions. Critics were particularly alarmed that the Treasury acquired access to location and other data harvested from smartphone apps; users are often unaware of how widely apps share such information.

The first contract, dated July 15 at a cost of $154,982, is with Treasury's Office of Foreign Assets Control, a quasi-intelligence wing responsible for enforcing economic sanctions against foreign regimes like Iran, Cuba, and Russia. A June report from New York University Law School's Brennan Center for Justice found that OFAC's vast enforcement powers require greater oversight from Congress. The report criticized the lack of legal limits on who OFAC can sanction, pointing out that this group includes American citizens within U.S. borders and foreigners without any government ties, and flagged the fact that OFAC is free to add people to sanctions lists even after sanctions are authorized -- people now potentially subject to surveillance by Locate X.

AI

New Bipartisan Bill Takes Aim at Algorithms (axios.com) 173

A bipartisan group of House lawmakers has introduced a companion to a Senate bill that would let people use algorithm-free versions of tech platforms, according to a copy of the text shared exclusively with Axios. From the report: Recent revelations about Facebook's internal research findings have renewed lawmaker interest in bills that seek to give people more of a say in how algorithms shape their online experiences. The bill shows that anger over how platforms use their algorithms to target users with specialized content is a bipartisan issue with momentum on Capitol Hill. The algorithms that personalize content on social networks and other apps can make services addictive, violate users' privacy and promote extremism, critics and many lawmakers argue. Conservatives have also claimed that services deliberately censor their speech.

The Filter Bubble Transparency Act would require internet platforms to let people use a version of their services where content selections are not driven by algorithms. It's sponsored by Reps. Ken Buck (R-Colo.), David Cicilline (D-R.I.), Lori Trahan (D-Mass.) and Burgess Owens (R-Utah). The Senate version of the bill, also bipartisan, is sponsored by Sen. John Thune (R-S.D.), an influential member of Republican leadership. Buck and Cicilline are the bipartisan duo responsible for passing six antitrust bills out of the House Judiciary committee in June. Buck and Thune plan to work together on tech and antitrust issues going forward, a Republican aide told Axios. That could boost the chances of such bills passing muster with Senate Republicans in the future.

IBM

Last of Original SCO v IBM Linux Lawsuit Settled (zdnet.com) 126

"[N]ow, after SCO went bankrupt; court after court dismissing SCO's crazy copyright claims; and closing in on 20-years into the saga, the U.S. District Court of Utah has finally put a period to the SCO vs. IBM lawsuit," writes ZDNet's Steven J. Vaughan-Nichols. From the report: According to the Court, since: "All claims and counterclaims in this matter, whether alleged or not alleged, pleaded or not pleaded, have been settled, compromised, and resolved in full, and for good cause appearing, IT IS HEREBY ORDERED that the parties' Motion is GRANTED. All claims and counterclaims in this action, whether alleged or not alleged, pleaded or not pleaded, have been settled, compromised, and resolved in full, and are DISMISSED with prejudice and on the merits. The parties shall bear their own respective costs and expenses, including attorneys' fees. The Clerk is directed to close the action." Finally!

Earlier, the US Bankruptcy Court for the District of Delaware, which has been overseeing SCO's bankruptcy had announced that the TSG Group, which represents SCO's debtors, has settled with IBM and resolved all the remaining claims between TSG and IBM: "Under the Settlement Agreement, the Parties have agreed to resolve all disputes between them for a payment to the Trustee [TLD], on behalf of the Estates [IBM], of $14,250,000." In return, TLD gives up all rights and interests in all litigation claims pending or that may be asserted in the future against IBM and Red Hat, and any allegations that Linux violates SCO's Unix intellectual property.
"While we're one step closer, the SCO lawsuits still live on just like one of those Halloween monsters that just won't die," concludes Vaughan-Nichols, noting the lawsuit Xinuos filed against IBM and Red Hat in March for allegedly copying their software code for its server operating systems. "But, in this go-around, there aren't many people in the audience."
Government

Japan To Create Scheme To Subsidize Domestic Chip Output (reuters.com) 24

Japan will create a scheme to subsidize construction of domestic chip factories with a new plant planned by Taiwan's TSMC likely to be the first recipient, the Nikkei newspaper reported on Monday. Reuters reports: The government will set aside several hundreds of billion yen under this year's supplementary budget to create a pool of funds at NEDO, a state-run body promoting research and development on energy and industrial technology, the paper said. Companies will be eligible for the subsidies on condition they ramp up chip production in times of short supply, the Nikkei said without citing sources.

The government is likely to subsidise up to half of TSMC's estimated 1-trillion-yen ($8.82 billion) investment for building a chip plant in Kumamoto, southern Japan, the Nikkei said. The plant in Kumamoto, southern Japan, is expected to produce semiconductors for automobiles, camera image sensors and other products which have been hit by a global chip shortage, and is likely to start operations by 2024, the paper said.

Crime

Truckload of GPUs Stolen On Their Way Out of San Francisco (theregister.com) 76

An anonymous reader quotes a report from The Register: US-based Nvidia partner EVGA has reported that a shipment of GPUs it was sending to a distribution centre has been stolen from a truck. A forum post by EVGA product manager Jacob Freeman states "PLEASE TAKE NOTICE that on October 29, 2021, a shipment of EVGA GeForce RTX 30-Series Graphics Cards was stolen from a truck en route from San Francisco to our Southern California distribution center."

"These graphics cards are in high demand and each has an estimated retail value starting at $329.99 up to $1959.99 MSRP." Which probably explains the motivation for the crime -- either someone hopes to resell them or a crypto-miner has just built a cut-price rig. Freeman's post doesn't say how many GPUs were stolen, or if the truck was carrying anything else. He did, however, warn that buying stolen property is a crime, as is "concealing selling or withholding" purloined goods. He then appears to lay a trap of sorts by pointing out that attempts to register products that aren't stolen will succeed on this page which requires registration. Crooks are probably smart enough to use fake details when registering. Are they also smart enough to use a VPN and/or Tor to hide their tracks? EVGA has created the email address stopRTX30theft@evga.com in an attempt to find the culprits.

Privacy

Microsoft Will Now Snitch On You At Work Like Never Before (zdnet.com) 143

schwit1 writes: Microsoft is preparing a couple of little updates that may curb employee rulebreaking enthusiasm. Yes, this news again comes courtesy of Microsoft's roadmap service, where Redmond prepares you for the joys to come. This time, there are a couple of joys. The first is headlined: "Microsoft 365 compliance center: Insider risk management -- Increased visibility on browsers." It all sounded wonderful until you those last four words, didn't it? For this is the roadmap for administrators. And when you give a kindly administrator "increased visibility on browsers," you can feel sure this means an elevated level of surveillance of what employees are typing into those browsers.
United States

US Charges Ukrainian, Russian, Over Cyberattack, Seizes $6 Million in Ransom Payments (reuters.com) 13

The U.S. Justice Department has charged a suspect from Ukraine and a Russian national over a July ransomware attack on an American company, according to indictments made in court filings on Monday, and has seized $6 million in ransom payments. From a report: The latest U.S. actions follow a slew of measures taken to combat ransomware that earlier this year hit big companies, including Colonial Pipeline, the largest fuel pipeline in the United States, and crippled fuel delivery for several days in the U.S. Southeast. Yaroslav Vasinskyi, a Ukrainian national arrested in Poland last month, will face U.S. charges for deploying ransomware known as REvil, which has been used in hacks that have cost U.S. firms millions of dollars, the court filing showed. REvil gained notoriety as the Russian group behind the ransomware attack against meatpacker JBS SA.
Security

CNN: Foreign Hackers Breached Nine Organizations to Steal 'Key Data' from 'Sensitive Targets' (cnn.com) 28

"Suspected foreign hackers have breached nine organizations in the defense, energy, health care, technology and education sectors," reports CNN, citing their exclusive glimpse at findings from security firm Palo Alto Networks.

At least one of the breached organizations is in the U.S., they add, and in cooperation with America's National Security Agency (or NSA), security researchers "are exposing an ongoing effort by these unidentified hackers to steal key data from U.S. defense contractors and other sensitive targets." It's the type of cyber espionage that security agencies in both the Biden and Trump administrations have aggressively sought to expose before it does too much damage. The goal in going public with the information is to warn other corporations that might be targeted and to burn the hackers' tools in the process... [T]he hackers have stolen passwords from some targeted organizations with a goal of maintaining long-term access to those networks, Ryan Olson, a senior Palo Alto Networks executive, told CNN. The intruders could then be well placed to intercept sensitive data sent over email or stored on computer systems until they are kicked out of the network.

Olson said that the nine confirmed victims are the "tip of the spear" of the apparent spying campaign, and that he expects more victims to emerge. It's unclear who is responsible for the activity, but Palo Alto Networks said some of the attackers' tactics and tools overlap with those used by a suspected Chinese hacking group... Cybersecurity firm Mandiant earlier this year revealed that China-linked hackers had been exploiting a different software vulnerability to breach defense, financial and public sector organizations in the US and Europe....

In the activity revealed by Palo Alto Networks, the attackers are exploiting a vulnerability in software that corporations use to manage their network passwords. CISA and the FBI warned the public in September that hackers were exploiting the software flaw and urged organizations to update their systems. Days later, the hackers tracked by Palo Alto Networks scanned 370 computer servers running the software in the US alone, and then began to exploit the software. Olson encouraged organizations that use the Zoho software to update their systems and search for signs of a breach.

Federal officials told CNN the revelation of the hacking activity is evidence of their close work with cybersecurity firms to stay on top of threats.

Facebook

Facebook Denies Report It Gave Kazakhstan's Government Special Direct Access to Its Content Reporting System (msn.com) 41

UPDATED: Earlier this week ZDNet reported that Facebook's parent company Meta "has granted the Kazakhstan government direct access to its content reporting system," as part of a joint agreement to work on removing content that is deemed harmful on social network platforms like Facebook and Instagram," with the agreement focusing on protecting children.

But the Washington Post clarified tonight that in fact Kazakhstan's statement "was apparently released independent of Facebook." Meta spokesman Ben McConaghy said in an email that the company has "a dedicated online channel for governments around the world to report content to us that they believe violates local law."

"We follow a consistent global process to assess individual requests — independent from any government — in line with Facebook's policies, local laws and international human rights standards," he added. "This process is the same in Kazakhstan as it is for other countries around the world."

Here's ZDNet's original report: In a joint statement, the Ministry of Information and Social Development of the Republic of Kazakhstan and the social media giant said the agreement, which is the first of its kind in Central Asia, would help increase the efficiency and effectiveness to counter the spread of illegal content. Giving the Kazakhstan government access to its content reporting system will allow the government to report content that may violate Facebook's global content policy and local content laws in Kazakhstan, Facebook said. Under the agreement, both parties will also set up regular communication, including having an authorised representative from Facebook's regional office work with the Ministry on various policy issues.

"Facebook is delighted to work with the government of Kazakhstan together, particularly in the aspect of online safety for children," Facebook regional public policy director George Chen said in a statement.

Slashdot Top Deals