×
Security

Black Basta Ransomware Attack Brought Down Ascension IT Systems, Report Finds (crn.com)

The Russia-linked ransomware group Black Basta is responsible for Wednesday's cyberattack on St. Louis-based Ascension health system, according to sources reported by CNN. The attack disrupted access to electronic health records, some phone systems and "various systems utilized to order certain tests, procedures and medications," the company said in a statement. From a report: On Friday, the nonprofit group Health-ISAC (Information Sharing and Analysis Center) issued an alert about the group, saying that Black Basta has "recently accelerated attacks against the healthcare sector." HHS said that Black Basta was initially spotted in early 2022, known for its double extortion attack. The group not only executes ransomware but also exfiltrates sensitive data, operating a cybercrime marketplace to publicly release it should a victim fail to pay a ransom.

"The level of sophistication by its proficient ransomware operators, and reluctance to recruit or advertise on Dark Web forums, supports why many suspect the nascent Black Basta may even be a rebrand of the Russian-speaking RaaS threat group Conti, or also linked to other Russian-speaking cyber threat groups," the alert from HHS said. According to one report from blockchain analytics firm Elliptic and cybersecurity risk-focused Corvus Insurance, Black Basta in less than two years has won itself more than $100 million via ransomware schemes from 329 organizations. Previous victims of its attacks include Dish Network, the American Dental Association, business process services firm Capita and tech firm ABB.

Power

'Tungsten Wall' Leads To Nuclear Fusion Breakthrough (qz.com) 8

A tokamak in France achieved a new record in fusion plasma by using tungsten to encase its reaction, which enabled the sustainment of hotter and denser plasma for longer periods than previous carbon-based designs. Quartz reports: A tokamak is a torus- (doughnut-) shaped fusion device that confines plasma using magnetic fields, allowing scientists to fiddle with the superheated material and induce fusion reactions. The recent achievement was made in WEST (tungsten (W) Environment in Steady-state Tokamak), a tokamak operated by the French Alternative Energies and Atomic Energy Commission (CEA). WEST was injected with 1.15 gigajoules of power and sustained a plasma of about 50 million degrees Celsius for six minutes. It achieved this record after scientists encased the tokamak's interior in tungsten, a metal with an extraordinarily high melting point. Researchers from Princeton Plasma Physics Laboratory used an X-ray detector inside the tokamak to measure aspects of the plasma and the conditions that made it possible.

"These are beautiful results," said Xavier Litaudon, a scientist with CEA and chair of the Coordination on International Challenges on Long duration OPeration (CICLOP), in a PPPL release. "We have reached a stationary regime despite being in a challenging environment due to this tungsten wall."

Biotech

UK Toddler Has Hearing Restored In World First Gene Therapy Trial (theguardian.com) 13

An anonymous reader quotes a report from The Guardian: A British toddler has had her hearing restored after becoming the first person in the world to take part in a pioneering gene therapy trial, in a development that doctors say marks a new era in treating deafness. Opal Sandy was born unable to hear anything due to auditory neuropathy, a condition that disrupts nerve impulses traveling from the inner ear to the brain and can be caused by a faulty gene. But after receiving an infusion containing a working copy of the gene during groundbreaking surgery that took just 16 minutes, the 18-month-old can hear almost perfectly and enjoys playing with toy drums. [...] The girl, from Oxfordshire, was treated at Addenbrooke's hospital, part of Cambridge university hospitals NHS foundation trust, which is running the Chord trial. More deaf children from the UK, Spain and the US are being recruited to the trial and will all be followed up for five years. [...]

Auditory neuropathy can be caused by a fault in the OTOF gene, which makes a protein called otoferlin. This enables cells in the ear to communicate with the hearing nerve. To overcome the fault, the new therapy from biotech firm Regeneron sends a working copy of the gene to the ear. A second child has also recently received the gene therapy treatment at Cambridge university hospitals, with positive results. The overall Chord trial consists of three parts, with three deaf children including Opal receiving a low dose of gene therapy in one ear only. A different set of three children will get a high dose on one side. Then, if that is shown to be safe, more children will receive a dose in both ears at the same time. In total, 18 children worldwide will be recruited to the trial. The gene therapy -- DB-OTO -- is specifically for children with OTOF mutations. A harmless virus is used to carry the working gene into the patient.

The Courts

Big Three Carriers Pay $10 Million To Settle Claims of False 'Unlimited' Advertising (arstechnica.com) 17

Jon Brodkin reports via Ars Technica: T-Mobile, Verizon, and AT&T will pay a combined $10.2 million in a settlement with US states that alleged the carriers falsely advertised wireless plans as "unlimited" and phones as "free." The deal was announced yesterday by New York Attorney General Letitia James. "A multistate investigation found that the companies made false claims in advertisements in New York and across the nation, including misrepresentations about 'unlimited' data plans that were in fact limited and had reduced quality and speed after a certain limit was reached by the user," the announcement said.

T-Mobile and Verizon agreed to pay $4.1 million each while AT&T agreed to pay a little over $2 million. The settlement includes AT&T subsidiary Cricket Wireless and Verizon subsidiary TracFone. The settlement involves 49 of the 50 US states (Florida did not participate) and the District of Columbia. The states' investigation found that the three major carriers "made several misleading claims in their advertising, including misrepresenting 'unlimited' data plans that were actually limited, offering 'free' phones that came at a cost, and making false promises about switching to different wireless carrier plans."

"AT&T, Verizon, and T-Mobile lied to millions of consumers, making false promises of free phones and 'unlimited' data plans that were simply untrue," James said. "Big companies are not excused from following the law and cannot trick consumers into paying for services they will never receive." The carriers denied any illegal conduct despite agreeing to the settlement. In addition to payments to each state, the carriers agreed to changes in their advertising practices. It's unclear whether consumers will get any refunds out of the settlement, however.
These are the following changes the three carriers agreed upon, as highlighted by the NY attorney general's office:

- "Unlimited" mobile data plans can only be marketed if there are no limits on the quantity of data allowed during a billing cycle.
- Offers to pay for consumers to switch to a different wireless carrier must clearly disclose how much a consumer will be paid, how consumers will be paid, when consumers can expect payment, and any additional requirements consumers have to meet to get paid.
- Offers of "free" wireless devices or services must clearly state everything a consumer must do to receive the "free" devices or services.
- Offers to lease wireless devices must clearly state that the consumer will be entering into a lease agreement.
- All "savings" claims must have a reasonable basis. If a wireless carrier claims that consumers will save using its services compared to another wireless carrier, the claim must be based on similar goods or services or differences must be clearly explained to the consumer.

The advertising restrictions are to be in place for five years.
Earth

G5 Severe Geomagnetic Storm Watch Issued For First Time Since 2003 (axios.com) 24

Longtime Slashdot reader davidwr shares a report from Space Weather Prediction Center (SWPC): On Thursday, May 9, 2024, the NOAA Space Weather Prediction Center issued a Severe (G4) Geomagnetic Storm Watch. At least five earth-directed coronal mass ejections (CMEs) were observed and expected to arrive as early as midday Friday, May 10, 2024, and persist through Sunday, May 12, 2024. Several strong flares have been observed over the past few days and were associated with a large and magnetically complex sunspot cluster (NOAA region 3664), which is 16 times the diameter of Earth. [The agency notes this is the first time it's issued a G4 watch since January, 2005.] "Geomagnetic storms can impact infrastructure in near-Earth orbit and on Earth's surface, potentially disrupting communications, the electric power grid, navigation, radio and satellite operations," NOAA said. "[The Space Weather Prediction Center] has notified the operators of these systems so they can take protective action." The agency said it will continue to monitor the ongoing storm and "provide additional warnings as necessary."

A visual byproduct of the storm will be "spectacular displays of aurora," also known as the Northern Lights, that could be seen for much of the northern half of the country "as far south as Alabama to northern California," said the NOAA. "Northern Montana, Minnesota, Wisconsin and the majority of North Dakota appear to have the best chances to see it," reports Axios, citing the SWPC's aurora viewline. "Forecast models Friday showed the activity will likely be the strongest from Friday night to Saturday morning Eastern time."

UPDATE 6:54 P.M. EDT: G5 conditions have been observed -- the first time since 2003, says Broadcast Meteorologist James Spann.

This is a developing story. More information is available at spaceweather.gov, Google News, and the NOAA.
AI

Apple Will Revamp Siri To Catch Up To Its Chatbot Competitors (nytimes.com) 16

An anonymous reader quotes a report from the New York Times: Apple's top software executives decided early last year that Siri, the company's virtual assistant, needed a brain transplant. The decision came after the executives Craig Federighi and John Giannandrea spent weeks testing OpenAI's new chatbot, ChatGPT. The product's use of generative artificial intelligence, which can write poetry, create computer code and answer complex questions, made Siri look antiquated, said two people familiar with the company's work, who didn't have permission to speak publicly. Introduced in 2011 as the original virtual assistant in every iPhone, Siri had been limited for years to individual requests and had never been able to follow a conversation. It often misunderstood questions. ChatGPT, on the other hand, knew that if someone asked for the weather in San Francisco and then said, "What about New York?" that user wanted another forecast.

The realization that new technology had leapfrogged Siri set in motion the tech giant's most significant reorganization in more than a decade. Determined to catch up in the tech industry's A.I. race, Apple has made generative A.I. a tent pole project -- the company's special, internal label that it uses to organize employees around once-in-a-decade initiatives. Apple is expected to show off its A.I. work at its annual developers conference on June 10 when it releases an improved Siri that is more conversational and versatile, according to three people familiar with the company's work, who didn't have permission to speak publicly. Siri's underlying technology will include a new generative A.I. system that will allow it to chat rather than respond to questions one at a time. The update to Siri is at the forefront of a broader effort to embrace generative A.I. across Apple's business. The company is also increasing the memory in this year's iPhones to support its new Siri capabilities. And it has discussed licensing complementary A.I. models that power chatbots from several companies, including Google, Cohere and OpenAI.
Further reading: Apple Might Bring AI Transcription To Voice Memos and Notes
Cloud

Google Cloud Accidentally Deletes UniSuper's Online Account Due To 'Unprecedented Misconfiguration' (theguardian.com) 29

A "one-of-a-kind" Google Cloud "misconfiguration" resulted in the deletion of UniSuper's account last week, disrupting the financial services provider's than half a million members. "Services began being restored for UniSuper customers on Thursday, more than a week after the system went offline," reports The Guardian. "Investment account balances would reflect last week's figures and UniSuper said those would be updated as quickly as possible." From the report: The UniSuper CEO, Peter Chun, wrote to the fund's 620,000 members on Wednesday night, explaining the outage was not the result of a cyber-attack, and no personal data had been exposed as a result of the outage. Chun pinpointed Google's cloud service as the issue. In an extraordinary joint statement from Chun and the global CEO for Google Cloud, Thomas Kurian, the pair apologized to members for the outage, and said it had been "extremely frustrating and disappointing." They said the outage was caused by a misconfiguration that resulted in UniSuper's cloud account being deleted, something that had never happened to Google Cloud before.

While UniSuper normally has duplication in place in two geographies, to ensure that if one service goes down or is lost then it can be easily restored, because the fund's cloud subscription was deleted, it caused the deletion across both geographies. UniSuper was able to eventually restore services because the fund had backups in place with another provider.
"Google Cloud CEO, Thomas Kurian has confirmed that the disruption arose from an unprecedented sequence of events whereby an inadvertent misconfiguration during provisioning of UniSuper's Private Cloud services ultimately resulted in the deletion of UniSuper's Private Cloud subscription," the pair said. "This is an isolated, 'one-of-a-kind occurrence' that has never before occurred with any of Google Cloud's clients globally. This should not have happened. Google Cloud has identified the events that led to this disruption and taken measures to ensure this does not happen again."
Transportation

The Automotive Cold War Is Officially Underway (insideevs.com) 103

Tim Levin reports via InsideEVs: Two things of note in the electric vehicle world happened today around the same time. First, the Geely Group-owned Chinese EV brand Zeekr debuted on the New York Stock Exchange today at a valuation of around $5.2 billion. Then, around 250 miles south in Washington, D.C., news emerged that the Biden Administration is set to quadruple tariffs on Chinese-made electric cars if they hit American roads. The timing may be purely coincidental. But after this week, one thing feels clearer than ever: the automotive Cold War between China and the West is fully underway, and EVs specifically are at the center of it all.

The Wall Street Journal got the scoop that the White House plans to announce higher tariffs on Chinese clean-energy imports in the coming days. Under the reported new policies, tariffs on Chinese EVs are set to quadruple, rising from the current 25% to a whopping 100%, anonymous sources told the outlet. In theory, that would substantially increase the cost of any Chinese-made EVs on our market, including, potentially, ones sold by known Western and other Asian brands. It's no secret why the U.S. is attempting to push back on Chinese EVs, to say nothing of other clean energy imports from that country like solar panels. China has spent years aggressively building up its capacity to manufacture electric cars. It's developed a stranglehold on the supply chains for lithium-ion batteries and the critical minerals they contain. It has lavished state incentives on both EV production and purchasing. In recent years, the country has emerged as a global EV powerhouse -- and, for the first time ever, an exporter on par with leaders like Japan and Germany.

Many still believe that China's cars are cheap and technologically subpar. But the truth is China has learned to build cars very, very well, as InsideEVs' own Kevin Williams discovered during a recent trip to the Beijing auto show. China's homegrown electrified vehicles range from the inexpensive -- some, like the BYD Seagull, cost less than $10,000 in their home market -- to higher-end, luxury-focused offerings like the Yangwang U8, a kind of plug-in hybrid competitor to the Mercedes G-Class that can "float" on water. From batteries to software, most are incredibly advanced. Car companies and policymakers in the U.S. (and Europe) say these cars pose a real threat to our nascent EV market, where many options still remain unaffordable and things like batteries and software are works in progress. In response, European Union officials have also launched investigations into Chinese imports that could lead to stronger tariffs.
"In effect, the tariffs may end up buying the U.S. some time, rather than being a permanent solution here," concludes Levin. "After all, as Kevin Williams pointed out after going to Beijing: all of these crackdowns aren't guaranteed to yield better cars from Ford, General Motors and the rest."

According to the WSJ, the new tariffs on Chinese goods will also apply to solar panels, batteries and critical battery minerals. They're expected to be announced as soon as next week.
AI

Bumble's Dating 'AI Concierge' Will Date Hundreds of Other People's 'Concierges' For You (fortune.com) 47

An anonymous reader quotes a report from Fortune: Imagine this: you've "dated" 600 people in San Fransisco without having typed a word to any of them. Instead, a busy little bot has completed the mindless 'getting-to-know-you' chatter on your behalf, and has told you which people you should actually get off the couch to meet. That's the future of dating, according to Whitney Wolfe Herd -- and she'd know. Wolfe Herd is the founder and executive chair of Bumble, a meeting and networking platform that prompted women to make the first move. While the platform has now changed this aspect of its algorithm, Wolfe Herd said the company would always keep its "North Star" in mind: "A safer, kinder digital platform for more healthy and more equitable relationships. "Always putting women in the driver's seat -- not to put men down -- but to actually recalibrate the way we all treat each other."

Like any platform, Bumble is now navigating itself in a world of AI -- which means rethinking how humans will interact with each other in an increasing age of chatbots. Wolfe Herd toldBloomberg Technology Summit in San Francisco this week it could streamline the matching process. "If you want to get really out there, there is a world where your [AI] dating concierge could go and date for you with other dating concierge," she told host Emily Chang. "Truly. And then you don't have to talk to 600 people. It will scan all of San Fransisco for you and say: 'These are the three people you really outta meet.'" And forget catch-ups with friends, swapping notes on your love life -- AI can be that metaphorical shoulder to cry on.

Artificial intelligence -- which has seen massive amounts of investment since OpenAI disrupted the market with its ChatGPT large language model -- can help coach individuals on how to date and present themselves in the best light to potential partners. "So, for example, you could in the near future be talking to your AI dating concierge and you could share your insecurities,"Wolfe Herd explained. "'I've just come out of a break-up, I've got commitment issues,' and it could help you train yourself into a better way of thinking about yourself." "Then it could give you productive tips for communicating with other people," she added. If these features do indeed come to Bumble in the future, they will impact the experience of millions.

China

Tech Exec's Videos Spark Clash Over China's Work Culture 24

Search giant Baidu fires its head of public relations after she outraged Gen Z workers. From a report [non-paywalled link]: The head of public relations at a major Chinese tech firm gained hundreds of thousands of followers seemingly overnight after posting a series of viral videos laying out her unapologetically tyrannical management style. The videos also earned her a pink slip from her employer after they set off an explosion of criticism among Gen Z Chinese fed up with the intense work culture that prevails in their country's tech industry.

"I'm not your mother-in-law. I'm not your mom," Qu Jing, a vice president at Chinese search giant Baidu, said in one widely excoriated clip, referring to a colleague who was struggling with a recent breakup. "I only care about your results." In other videos, she criticized employees who didn't want to work weekends and dismissed complaints from one subordinate that messages she sent to a group chat late at night had kept a crying child awake. "Why should it be my business that your child was crying?" she said.

On Thursday, as public outrage soared, Qu removed the videos from her account on Douyin, TikTok's sister platform in China, and replaced them with an apology. She said she had tried to do a good job but had been too impatient and hadn't adopted "a proper approach." Baidu Chief Executive Robin Li was furious at Qu and fired her on Thursday, according to people familiar with the matter. A top Baidu executive told employees that Qu's comments were "inappropriate and didn't represent and reflect the real culture and values of Baidu," the people said. The management also promised to review the company's corporate culture and working systems, they said.

China's hard-charging tech industry relies heavily on a Darwinian work culture that demands near-total devotion to the workplace. Tech workers coined the term "996" to describe the typical schedule: 9 a.m. to 9 p.m., six days a week. Half a decade ago, videos like Qu's were just as likely to garner a shrug as generate controversy. But younger Chinese, much like their counterparts in the U.S., are increasingly skeptical of the pressure to work themselves ragged in pursuit of financial success. They have coined their own terms -- "lying flat" and "letting it rot" -- to describe their antipathy to the grinding ethos of 996.
Businesses

India Unable To Impose Caps on Mobile Payments Market Share, Four Years On 7

Eight years ago, a coalition of retail banks in India built a mobile payments system called the UPI. The system is interoperable, allowing users to make instant peer-to-peer transactions between them -- across all participating banks -- and to merchants at zero cost. Today, it processes more than 12 billion transactions each month -- more than all card payments combined in India -- and has become the most popular way Indians transact online. Many U.S. giants have cited UPI as an example that other countries should also explore developing. We have also covered UPI several times over the years.

NPCI, a quasi-regulator founded by India's central bank, oversees UPI. Four years ago, it announced plans to enforce a market share cap on each participating player. The quasi-regulator didn't want few players to become too powerful and any single participant to process more than 30% of all UPI transactions in a month. It later postponed the deadline to January 1, 2025. Walmart-owned PhonePe and Google Pay command more than 86% of the UPI market. Now, the NPCI is reportedly planning to extend the deadline again by up to two years. The reason? TechCrunch reports: The NPCI had initially planned to enforce the market share cap in January 2021, but postponed the deadline to January 1, 2025. TechCrunch had previously reported that the regulator was moving towards extending the deadline further after concluding that there is no practical solution to address the issue. One can argue that the NPCI shouldn't be interfering with free market forces and let people decide which apps they wish to use. TechCrunch adds: However, several UPI providers admit that an incentive plan that unfairly differentiates [one of the proposed solutions by some industry players] against PhonePe and Google Pay will be a bad look for the ecosystem and could send wrong signals to the investor community. U.S.-based investors, including Accel, Lightspeed, Tiger Global, Insight Partners, Invesco, Vanguard, BlackRock and Fidelity, are among some of the most prolific investors in Indian public firms and startups. Some of the choices made by the RBI [India's central bank] and other regulators have already spooked many investors.
Canada

Canadian Petition That Games Must Remain Functional At EOL (ourcommons.ca) 58

Zitchas writes: The practice of having games require a connection to a publisher's server -- whether it is to check for a license or to access plug-ins and DLC -- is an increasingly common thing in computer software; and many people are concerned that at some point in the future the publisher will shut down their server, and effectively render the person who paid for the game left with something that no longer functions. This has already happened to some games and software

Concerned citizens in Canada are taking the issue to their Parliament in order to push for a law that will mandate that when the server-side support for software is discontinued, companies must leave it in a functional state and remove mandatory connections to servers -- services that no longer exist. Perhaps even more importantly, the petition also asks government to pass a law prohibiting EULA's from forcing users to agree to waiving their right to this. Unfortunately, the petition is only open to citizens of Canada, so the rest of us are out of luck. Considering the potential benefits to the rest of the world if they enact legislation that does this, though, it might be worth suggesting to any of your Canadian friends to go sign the petition.

Earth

Tornadoes Are Coming in Bunches. Scientists Are Trying To Figure Out Why. (nytimes.com) 65

The number of tornadoes so far in the United States this year is just above average. But their distribution is changing. From a report: Tornadoes tend to travel in packs these days, often with a dozen or more forming in the same region on the same day. On the worst days, hundreds can form at once. More than a dozen tornadoes were reported on both Monday and Tuesday this week across the Great Plains and the Midwest, according to the Storm Prediction Center run by the National Oceanic and Atmospheric Administration. Two weeks ago, on the most active day in April, 105 tornadoes were reported. While outbreaks like these have always happened, they have become more common in recent decades.

The total number of tornadoes in the United States each year has stayed relatively consistent over the last several decades, but they now happen in more concentrated bursts over fewer days during the year. In the 1950s through the 1970s, on average about 69 percent of tornadoes in the United States happened on days with fewer than 10 tornadoes, and about 11 percent happened on days with 20 or more tornadoes. These percentages have shifted significantly in recent decades, according to a 2019 study. The researchers found that since 2000, on average only about 49 percent of tornadoes have happened on less busy days and about 29 percent have happened on days with 20 or more tornadoes.

"Now when tornadoes happen, they often happen in an outbreak environment," said Tyler Fricker, an assistant professor of geography at the University of Louisiana Monroe and one of the authors of the study. While the timing of this trend lines up with the planet's rising temperatures, scientists are hesitant to definitively attribute tornadoes' clustering behavior to human-caused climate change.

AI

Apple Might Bring AI Transcription To Voice Memos and Notes (appleinsider.com) 13

Apple's plans for AI on the iPhone could bring real-time transcription to its Voice Memos and Notes apps, according to a report from AppleInsider: People familiar with the matter have told us that Apple has been working on AI-powered summarization and greatly enhanced audio transcription for several of its next-gen operating systems. The new features are expected to enable significant improvements in efficiency for users of its staple Notes, Voice Memos, and other apps. Apple is currently testing the capabilities as feature additions to several app updates scheduled to arrive with the release of iOS 18 later in 2024. They're also expected to make their way to the corresponding apps in macOS 15 and iPadOS 18 as well.
AI

CEO of World's Biggest Ad Firm Targeted By Deepfake Scam 11

The head of the world's biggest advertising group was the target of an elaborate deepfake scam that involved an AI voice clone. From a report: The CEO of WPP, Mark Read, detailed the attempted fraud in a recent email to leadership, warning others at the company to look out for calls claiming to be from top executives. Fraudsters created a WhatsApp account with a publicly available image of Read and used it to set up a Microsoft Teams meeting that appeared to be with him and another senior WPP executive, according to the email obtained by the Guardian.

During the meeting, the impostors deployed a voice clone of the executive as well as YouTube footage of them. The scammers impersonated Read off-camera using the meeting's chat window. The scam, which was unsuccessful, targeted an "agency leader," asking them to set up a new business in an attempt to solicit money and personal details. "Fortunately the attackers were not successful," Read wrote in the email. "We all need to be vigilant to the techniques that go beyond emails to take advantage of virtual meetings, AI and deepfakes."

Slashdot Top Deals