China

Taiwan Issues Arrest Warrant for OnePlus CEO for China Hires (bloomberg.com) 13

Prosecutors in Taiwan issued an arrest warrant [non-paywalled source] for the chief executive officer of the Chinese smartphone company OnePlus, stepping up the island's efforts to block China's tech players from recruiting Taiwanese talent. From a report: The Shilin district prosecutors office issued the warrant for CEO and co-founder Pete Lau and indicted two Taiwanese citizens who worked for him, according to an indictment by the office. OnePlus, a niche player whose phones run on a customized version of Android, is suspected of illegally recruiting more than 70 engineers in Taiwan.

The autonomous territory has stepped up its efforts to stop Chinese companies from raiding workers, who are often coveted because of their technical knowledge and experience. The Taiwanese officials put such limitations in place because they say recruiting from the semiconductor sector and other tech operations could jeopardize national security.

Games

SteamOS Continues Its Slow Spread Across the PC Gaming Landscape (arstechnica.com) 30

An anonymous reader quotes a report from Ars Technica: SteamOS's slow march across the Windows-dominated PC gaming landscape is continuing to creep along. At CES this week, Lenovo announced it will launch a version of last year's high-priced, high-powered Legion Go 2 handheld with Valve's gaming-focused, Linux-based OS pre-installed starting in June. And there are some intriguing signs from Valve that SteamOS could come to non-AMD devices in the not-too-distant future as well. [...] Valve has also been working behind the scenes to expand SteamOS's footprint beyond its own hardware. After rolling out the SteamOS Compatible software label last May, SteamOS version 3.7 offered support for manual installation on AMD-powered handhelds like the ROG Ally and the original Legion Go.

Even as SteamOS slowly spreads across the AMD-powered hardware landscape, the OS continues to be limited by a lack of compatibility with the wide world of Arm devices. That could change in the near future, though, as Valve's upcoming Steam Frame VR headset will sport a new version of SteamOS designed specifically for the headset's Arm-based hardware. [...] It's an especially exciting prospect when you consider the wide range of Arm-based Android gaming handhelds that currently exist across the price and performance spectrum. While emulators like Fex can technically let players access Steam games on those kinds of handhelds, official Arm support for SteamOS could lead to a veritable Cambrian explosion of hardware options with native SteamOS support.

[...] That's great news for fans of PC-based gaming handhelds, just as the announcement of Valve's Steam Machine will provide a convenient option for SteamOS access on the living room TV. For desktop PC gamers, though, rigs sporting Nvidia GPUs might remain the final frontier for SteamOS in the foreseeable future. "With Nvidia, the integration of open-source drivers is still quite nascent," [Valve's Pierre-Louis Griffais] told Frandroid about a year ago. "There's still a lot of work to be done on that front So it's a bit complicated to say that we're going to release this version when most people wouldn't have a good experience."

Android

Google Will Now Only Release Android Source Code Twice a Year (androidauthority.com) 18

Google will begin releasing Android Open Source Project (AOSP) source code only twice a year starting in 2026. "In the past, Google would release the source code for every quarterly Android release, of which there are four each year," notes Android Authority. From the report: Google told Android Authority that, effective 2026, Google will publish new source code to AOSP in Q2 and Q4. The reason is to ensure platform stability for the Android ecosystem and better align with Android's trunk-stable development model.

Developers navigating to source.android.com today will see a banner confirming the change that reads as follows: "Effective in 2026, to align with our trunk-stable development model and ensure platform stability for the ecosystem, we will publish source code to AOSP in Q2 and Q4. For building and contributing to AOSP, we recommend utilizing android-latest-release instead of aosp-main. The aosp-latest-release manifest branch will always reference the most recent release pushed to AOSP. For more information, see Changes to AOSP."

A spokesperson for Google offered some additional context on this decision, stating that it helps simplify development, eliminates the complexity of managing multiple code branches, and allows them to deliver more stable and secure code to Android platform developers. The spokesperson also reiterated that Google's commitment to AOSP is unchanged and that this new release schedule helps the company build a more robust and secure foundation for the Android ecosystem. Finally, Google told us that its process for security patch releases will not change and that the company will keep publishing security patches each month on a dedicated security-only branch for relevant OS releases just as it does today.

Microsoft

Microsoft Office Is Now 'Microsoft 365 Copilot App' (pcgamer.com) 99

Longtime reader joshuark shares a report: As spotted by Bluesky user DodgerFanLA, going to Office.com now greets you with the following helpful explainer: "The Microsoft 365 Copilot app (formerly Office) lets you create, share, and collaborate all in one place with your favorite apps now including Copilot.*"

Never has an asterisk been more relevant to me than following the words "your favorite apps now including Copilot."

About a decade ago, hardware company Corsair attempted to pivot from its classic logo -- a subtle trio of ship sails -- to a newer, edgier look, a pair of crossed swords that gave off regrettable '2000s tribal tattoo' energy. The rebrand didn't last long: after a fierce outcry from people who correctly thought the new logo sucked, Corsair swapped to a refreshed take on the sail logo, which it's been using ever since. Corsair was established in 1994, and made about $1.4 billion last year -- which I bring up because today Microsoft, a slightly bigger company, has slipped on its own rebranding banana peel. The company is seemingly all but ditching the Office name -- which it introduced four years before Corsair existed, and which drove more than $30 billion in revenue just last quarter -- with a catchy new name: "Microsoft 365 Copilot app."

The company had already downplayed the Office name, despite it being perhaps the most universally recognized software in existence, by renaming its cloud version of Word, Powerpoint, etc. Office 365 in 2010, then Microsoft 365 in 2017. Now when you want to open up a Word document, you can get to them by launching the Microsoft 365 Copilot app. Intuitive!

Should Microsoft just go ahead and rebrand Windows, the only piece of its arsenal more famous than Office, as Copilot, too? I do actually think we're not far off from that happening. Facebook rebranded itself "Meta" when it thought the metaverse would be the next big thing, so it seems just as plausible that Microsoft could name the next version of Windows something like "Windows with Copilot" or just "Windows AI."

Copilot is the app for launching the other apps, but it's also a chatbot inside the apps. Any questions?
Correction: Office hasn't been renamed to "Microsoft 365 Copilot app." The Verge adds: The confusion comes from Microsoft's own Office.com domain, which for the past year has acted as a way to push businesses and consumers to use the Microsoft 365 Copilot app. This app is a hub app that provides access to Copilot, as well as all the Office apps. Microsoft used to call this app simply Office, before the company rebranded Office to Microsoft 365 in 2022.

If you visit Office.com you'll see a big welcome to the Microsoft 365 Copilot app, and a note from Microsoft that would confuse anyone not following the company's confusing branding: "The Microsoft 365 Copilot app (formerly Office)..." That mention of "formerly Office" is Microsoft referring to the very old Office app that launched in 2019 as a way to try and convince people to use online versions of Word, Excel, and PowerPoint. Until a year ago it used to be called the Microsoft 365 app. Microsoft then announced it was rebranding its Microsoft 365 app in November 2024 to a Copilot one, which I and everyone else were very confused at. The new app icon and name -- Microsoft 365 Copilot -- then rolled out on January 15th last year to Windows, iOS, and Android users.

Handhelds

First Gaming Handheld With a Folding Screen (theverge.com) 3

One-Netbook has unveiled the OneXSugar Wallet, the first gaming handheld with a folding OLED display. The Verge reports: The OneXSugar Wallet was announced on China's Weibo yesterday, but with few details about its features and capabilities. That folding OLED screen has a resolution of 2480 x 1860 pixels, and the handheld will be powered by an unspecified "Qualcomm gaming platform flagship processor," but its performance and emulation capabilities are unknown.

Based on photos and a video released by One-Netbook, the OneXSugar Wallet will feature a standard set of controls including asymmetrical thumbsticks, four action buttons, and a D-pad situated on either side of the lower half of its display. There are also shoulder buttons and triggers on the back of the handheld, and a pair of front-facing speakers flanking the top half of the screen. The biggest question is how much will the handheld cost...

Open Source

Up Next for Arduino After Qualcomm Acquisition: High-Performance Computing (eetimes.com) 26

Even after its acquisition by Qualcomm, the EFF believes Arduino "isn't imposing any new bans on tinkering with or reverse engineering Arduino boards," (according to Mitch Stoltz, EFF director for competition and IP litigation). While Adafruit's managing editor Phillip Torrone had claimed to 36,000+ followers on LinkedIn that Arduino users were now "explicitly forbidden from reverse engineering," Arduino corrected him in a blog post, noting that clause in their Terms & Conditions was only for Arduino's Software-as-a-Service cloud applications. "Anything that was open, stays open."

And this week EE Times spoke to Guneet Bedi, SVP of Arduino, "who was unequivocal in saying that Arduino's governance structure had remained intact even after the acquisition." "As a business unit within Qualcomm, Arduino continues to make independent decisions on its product portfolio, with no direction imposed on where it should or should not go," Bedi said. "Everything that Arduino builds will remain open and openly available to developers, with design engineers, students and makers continuing to be the primary focus.... Developers who had mastered basic embedded workflows were now asking how to run large language models at the edge and work with artificial intelligence for vision and voice, with an open source mindset," he said. According to Bedi, this was where Qualcomm's technology became relevant. "Qualcomm's chipsets are high performance while also being very low power, which comes from their mobile and Android phone heritage. Despite being great technology, it is not easily accessible to design engineers because of cost and complexity. That made this a strong fit," he said.

The most visible outcome of this acquisition is Uno Q, which Bedi described as being comparable to a mid-tier Android phone in capability, starting at a price of $44. For Arduino, this marked a shift beyond microcontrollers without abandoning them. "At the end of the day, we have not gone away from our legacy," Bedi said. "You still have a real-time microcontroller, and you still write code the way Arduino developers are used to. What we added is compute, without forcing people to change how they work." Uno Q combines a Linux-based compute system with a real-time microcontroller from the STM32 family. "You do not need two different development environments or two different hardware platforms," Bedi added... Rather than introducing a customized operating system, Arduino chose standard Debian upstream. "We are not locking developers into anything," Bedi said. "It is standard Debian, completely open...." Pre-built models covering tasks like object detection and voice recognition run locally on the board....

While the first reference design uses Qualcomm silicon, Bedi was careful to stress that this does not define the roadmap. "There is zero dependency on Qualcomm silicon," he said. "The architecture is portable. Tomorrow, we can run this on something else." That distinction matters, particularly for developers wary of vendor lock-in following the acquisition. Uno Q does compete directly with platforms like Raspberry Pi and Nvidia Jetson, but Bedi framed the difference less in terms of raw performance and more in flexibility. "When you build on those platforms, you are locked to the board," he said. "Here, you can build a prototype, and if you like it, you can also get access to the chip and design your own hardware." With built-in storage removing the need for external components, Uno Q positions itself less as a faster board and more as a way to simplify what had become an increasingly messy development stack...

Looking a year ahead, Bedi believes developers should experience continuity rather than disruption. The familiar Arduino approach to embedded and real-time systems remains unchanged, while extending naturally into more compute-intensive applications... Taken together, Bedi's comments suggest that Arduino's post-acquisition direction is less about changing what Arduino is, and more about expanding what it can realistically be used for, without abandoning the simplicity that made it relevant in the first place.

"We want to redefine prototyping in the age of physical artificial intelligence," Bedi said...
Programming

Apple's App Course Runs $20,000 a Student. Is It Really Worth It? (wired.com) 14

Apple's Developer Academy in Detroit has spent roughly $30 million over four years training hundreds of people to build iPhone apps, but not everyone lands coding jobs right away, according to a WIRED story published this week.

The program launched in 2021 as part of Apple's $200 million response to the Black Lives Matter protests and costs an estimated $20,000 per student -- nearly twice what state and local governments budget for community colleges. About 600 students have completed the 10-month course at Michigan State University. Academy officials say 71% of graduates from the past two years found full-time jobs across various industries.

The program provides iPhones, MacBooks and stipends ranging from $800 to $1,500 per month, though one former student said many participants relied on food stamps. Apple contributed $11.6 million to the academy. Michigan taxpayers and the university's regular students covered about $8.6 million -- nearly 30% of total funding. Two graduates said their lack of proficiency in Android hurt their job prospects. Apple's own US tech workforce went from 6% Black before the academy opened to about 3% this year.
Operating Systems

What the Linux Desktop Really Needs To Challenge Windows (theregister.com) 231

Linux's share of the desktop market has climbed to as much as 11% by one count, but that figure includes Chromebooks, and the traditional Linux desktop remains hamstrung by the same fragmentation that killed Unix decades ago. Steven J. Vaughan-Nichols, writing in The Register, argues that the proliferation of Linux desktops -- more than a dozen significant interfaces exist today, and DistroWatch lists "upwards of a hundred" -- makes it nearly impossible for ordinary users to know where to start.

Linus Torvalds has long agreed with this hypothesis. "We have way too many desktops," Vaughan-Nichols notes, summarizing Torvalds' position. The deeper issue lies in software delivery: traditional package managers like DEB and RPM "simply don't scale for the desktop," forcing distro builders to constantly rebuild programs for their specific environments. Containerized solutions like Flatpaks, Snaps and AppImages should solve this by bundling dependencies into universal packages, but the Linux community remains divided over which to adopt.

Linux Mint, for instance, refuses Snap because "Canonical has too much control over the Snap store." Hardware support further complicates this challenges, the veteran journalist writes. While Dell sells Ubuntu machines and specialist vendors like System76 and TUXEDO Computers cater to enthusiasts, "none of them make it easy" for mainstream buyers, and no major OEM strongly backs Linux. Torvalds has pointed to Chromebooks and Android as the model: Linux won on smartphones because "there's a single, unified platform with a unified way to install programs."
Security

Linux Kernel Rust Code Sees Its First CVE Vulnerability (phoronix.com) 151

Longtime Linux developer Greg Kroah-Hartman announced that the Linux kernel has received its first CVE tied to Rust code. Phoronix reports: This first CVE (CVE-2025-68260) for Rust code in the Linux kernel pertains to the Android Binder rewrite in Rust. There is a race condition that can occur due to some noted unsafe Rust code. That code can lead to memory corruption of the previous/next pointers and in turn cause a crash. This CVE for the possible system crash is for Linux 6.18 and newer since the introduction of the Rust Binder driver. At least though it's just a possible system crash and not any more serious system compromise with remote code execution or other more severe issues.
Android

Google Translate Expands Live Translation To All Earbuds On Android (arstechnica.com) 10

An anonymous reader quotes a report from Ars Technica: Google has increasingly moved toward keeping features locked to its hardware products, but the Translate app is bucking that trend. The live translate feature is breaking out of the Google bubble with support for any earbuds you happen to have connected to your Android phone. The app is also getting improved translation quality across dozens of languages and some Duolingo-like learning features.

The latest version of Google's live translation is built on Gemini and initially rolled out earlier this year. It supports smooth back-and-forth translations as both on-screen text and audio. Beginning a live translate session in Google Translate used to require Pixel Buds, but that won't be the case going forward. Google says a beta test of expanded headphone support is launching today in the US, Mexico, and India.

The audio translation attempts to preserve the tone and cadence of the original speaker, but it's not as capable as the full AI-reproduced voice translations you can do on the latest Pixel phones. Google says this feature should work on any earbuds or headphones, but it's only for Android right now. The feature will expand to iOS in the coming months. [...] The new translation model, which is also available in the search-based translation interface, supports over 70 languages.

Submission + - Ask HN: Has Bank of America been hacked? 1

TempestRose writes: Tried to log in to Bank of America login today, both mobile on Android and web, and get asked for:
ACCOUNT # ?
SS#
PIN

WTH?
I've recieved physical mail letters saying
"WE will NEVER ask you for Account, SSN, or PIN"
, and yet here we are.

Obviously, I have used a login and password for BoA for years.
I do not remember the last time I logged in, but I'm sure it was in November 2025

I'd REALLY like to hear from the general HN populace on this, please.
EU

Google Faces Fines Over Google Play If It Doesn't Make More Concessions (reuters.com) 21

EU regulators say Google's Play Store changes still don't meet fairness rules and are preparing a potentially hefty 2026 fine unless Google makes deeper concessions. Reuters reports: Google Play has been in the European Commission's crosshairs since March, with regulators singling out technical restrictions preventing app developers from steering users to other channels for cheaper offers. Another issue is the service fee charged by Google for facilitating an app developer's initial acquisition of a new customer via Google Play which the regulator said goes beyond what is justified.

Tweaks to Google Play announced in August to make it easier for app developers to direct customers to other channels and choose a fee model are still falling short, the people said, with the EU antitrust regulator viewing Apple's recent changes to its App Store as a benchmark. [...] Google can still offer to make more changes before regulators impose a fine, likely in the first quarter of the next year, the people said, adding that the timing of any sanction can still change.
"We continue to work closely with the European Commission in its ongoing investigation but have serious concerns that further changes would put Android and Play users at risk of malware, scams and data theft. Unlike iOS, Android is already open by design," a Google spokesperson said.
XBox (Games)

Xbox Is Bleeding Out (gizmodo.com) 42

Microsoft's Xbox consoles were conspicuously absent from Black Friday's winners, failing to crack the top three in U.S. sales during one of the retail calendar's most important weeks. According to Circana analyst Mat Piscatella, the PlayStation 5 captured 47% of Black Friday week console sales ending November 29, followed by the Nintendo Switch 2 at 24% and -- somewhat remarkably -- the NEX Playground, a Kinect-like Android device aimed at children, at 14%.

Microsoft ran no promotions on its consoles during the period. The Xbox Series X currently retails for $650 following this year's price increase, up from its $500 launch price in 2020. Sony, by contrast, discounted the PS5 by roughly 40% at some retailers. Piscatella noted on Bluesky that products without price promotions typically see no seasonal lift. Costco has removed Xbox consoles from its U.S. and UK websites.
Cellphones

New Jolla Phone Now Available for Pre-Order as an Independent Linux Phone (9to5linux.com) 45

Jolla is "trying again with a new crowd-funded smartphone," reports Phoronix: Finnish company Jolla started out 14 years ago where Nokia left off with MeeGo and developed Sailfish OS as a new Linux smartphone platform. Jolla released their first smartphone in 2013 after crowdfunding but ultimately the Sailfish OS focus the past number of years now has been offering their software stack for use on other smartphone devices [including some Sony Xperia smartphones and OnePlus/Samsung/ Google/ Xiaomi devices].
This new Jolla Phone's pre-order voucher page says the phone will only produced if 2,000 units are ordered before January 4. (But in just a few days they've already received 1,721 pre-orders — all discounted to 499€ from a normal price between 599 and 699 €). Estimate delivery is the first half of 2026. "The new Jolla Phone is powered by a high-performing Mediatek 5G SoC," reports 9to5Linux, "and features 12GB RAM, 256GB storage that can be expanded to up to 2TB with a microSDXC card, a 6.36-inch FullHD AMOLED display with ~390ppi, 20:9 aspect ratio, and Gorilla Glass, and a user-replaceable 5,500mAh battery." The Linux phone also features 4G/5G support with dual nano-SIM and a global roaming modem configuration, Wi-Fi 6 wireless, Bluetooth 5.4, NFC, 50MP Wide and 13MP Ultrawide main cameras, front front-facing wide-lens selfie camera, fingerprint reader on the power key, a user-changeable back cover, and an RGB indication LED. On top of that, the new Jolla Phone promises a user-configurable physical Privacy Switch that lets you turn off the microphone, Bluetooth, Android apps, or whatever you wish.

The device will be available in three colors, including Snow White, Kaamos Black, and The Orange. All the specs of the new Jolla Phone were voted on by Sailfish OS community members over the past few months. Honouring the original Jolla Phone form factor and design, the new model ships with Sailfish OS (with support for Android apps), a Linux-based European alternative to dominating mobile operating systems that promises a minimum of 5 years of support, no tracking, no calling home, and no hidden analytics...

The device will be manufactured and sold in Europe, but Jolla says that it will design the cellular band configuration to enable global travelling as much as possible, including e.g. roaming in the U.S. carrier networks. The initial sales markets are the EU, the UK, Switzerland, and Norway.

Cellphones

The AI Boom Could Increase Prices for Phones and Tablets Next Year (cnn.com) 45

CNN's prediction for 2026? "Any device that uses memory, from phones to tablets and smartwatches, could get pricier." But will it be a little or a lot?

The article cites an analysis from multinational strategy/management consulting firm McKinsey & Company which found America's data center demand could continue growing by 20 to 25 percent per year" through 2030. "That's prompted memory manufacturers like Micron and Samsung to shift their focus to data centers, which use a different type of memory, meaning fewer resources for consumer products. (Jaejune Kim, executive VP for memory at Samsung, said in October that their third quarter saw strong demand for memory for AI and data centers, and that they expected the supply shortage for mobile and PC memory to "intensify further.") Memory prices are rising for consumer products because major manufacturers are instead ramping up production for AI data centers as artificial intelligence companies boom. "It's pretty much brutal and crunched across the board," said Yang Wang, a senior analyst at Counterpoint Research.

The International Data Corporation, a global market research firm, reported earlier this week that the smartphone market is expected to decline by 0.9% in 2026 in part because of memory shortages. Memory prices are expected to surge by 30% in the fourth quarter of 2025 and may climb an additional 20% early next year, Counterpoint Research said last month... TrendForce, a research firm that follows the semiconductor industry, estimates memory price hikes have made smartphones 8% to 10% more expensive to produce in 2025 (higher production costs don't always translate into higher consumer prices for a variety of reasons).

Some smartphones could cost more as soon as early next year, said Nabila Popal, a senior research director for the International Data Corporation. Cheap Android phones may see the biggest impact, since less expensive products usually have thinner margins. "It's going to be almost impossible for them to not raise prices" of cheaper Android phones, said Popal. Companies may also postpone phone launches to focus on expensive models that may be more profitable. The average selling price for smartphones is expected to climb to $465 in 2026, compared to $457 in 2025, according to Popal, putting the smartphone market at a record high value of $578.9 billion.

But the pendulum is expected to swing back in the other direction late next year as the supply chain adjusts, according to Popal and Wang, potentially bringing prices back down or at least capping increases.

Open Source

Valve Reveals Its the Architect Behind a Push To Bring Windows Games To Arm (theverge.com) 44

An anonymous reader quotes a report from The Verge's Sean Hollister If you wrote off the Steam Frame as yet another VR headset few will want to wear, I guarantee you're not alone. But the Steam Frame isn't just a headset; it's a Trojan horse that contains the tech gamers need to play Steam games on the next Samsung Galaxy, the next Google Pixel, perhaps Arm gaming notebooks to come. I know, because I'm already using that tech on my Samsung Galaxy. There is no official Android version of Hollow Knight: Silksong, one of the best games of 2025, but that doesn't have to stop you anymore. Thanks to a stack of open-source technologies, including a compatibility layer called Proton and an emulator called Fex, games that were developed for x86-based Windows PCs can now run on Linux-based phones with the Arm processor architecture. With Proton, the Steam Deck could already do the Windows-to-Linux part; now, Fex is bridging x86 and Arm, too.

This stack is what powers the Steam Frame's own ability to play Windows games, of course, and it was widely reported that Valve is using the open-source Fex emulator to make it happen. What wasn't widely reported: Valve is behind Fex itself. In an interview, Valve's Pierre-Loup Griffais, one of the architects behind SteamOS and the Steam Deck, tells The Verge that Valve has been quietly funding almost all the open-source technologies required to play Windows games on Arm. And because they're open-source, Valve is effectively shepherding a future where Arm phones, laptops, and desktops could freely do the same. He says the company believes game developers shouldn't be wasting time porting games if there's a better way.

Remember when the Steam Deck handheld showed that a decade of investment in Linux could make Windows gaming portable? Valve paid open-source developers to follow their passions to help achieve that result. Valve has been guiding the effort to bring games to Arm in much the same way: In 2016 and 2017, Griffais tells me, the company began recruiting and funding open-source developers to bring Windows games to Arm chips. Fex lead developer Ryan Houdek tells The Verge he chatted with Griffais himself at conferences those years and whipped up the first prototype in 2018. He tells me Valve pays enough that Fex is his full-time job. "I want to thank the people from Valve for being here from the start and allowing me to kickstart this project," he recently wrote.

Youtube

SmartTube YouTube App For Android TV Breached To Push Malicious Update (bleepingcomputer.com) 17

An anonymous reader quotes a report from BleepingComputer: The popular open-source SmartTube YouTube client for Android TV was compromised after an attacker gained access to the developer's signing keys, leading to a malicious update being pushed to users. The compromise became known when multiple users reported that Play Protect, Android's built-in antivirus module, blocked SmartTube on their devices and warned them of a risk.

The developer of SmartTube, Yuriy Yuliskov, admitted that his digital keys were compromised late last week, leading to the injection of malware into the app. Yuliskov revoked the old signature and said he would soon publish a new version with a separate app ID, urging users to move to that one instead. [...] A user who reverse-engineered the compromised SmartTube version number 30.51 found that it includes a hidden native library named libalphasdk.so [VirusTotal]. This library does not exist in the public source code, so it is being injected into release builds.

[...] The library runs silently in the background without user interaction, fingerprints the host device, registers it with a remote backend, and periodically sends metrics and retrieves configuration via an encrypted communications channel. All this happens without any visible indication to the user. While there's no evidence of malicious activity such as account theft or participation in DDoS botnets, the risk of enabling such activities at any time is high.

Submission + - SmartTube YouTube app for Android TV breached to push malicious update (bleepingcomputer.com)

An anonymous reader writes: The popular open-source SmartTube YouTube client for Android TV was compromised after an attacker gained access to the developer's signing keys, leading to a malicious update being pushed to users.

The compromise became known when multiple users reported that Play Protect, Android's built-in antivirus module, blocked SmartTube on their devices and warned them of a risk.

The developer of SmartTube, Yuriy Yuliskov, admitted that his digital keys were compromised late last week, leading to the injection of malware into the app.

Yuliskov revoked the old signature and said he would soon publish a new version with a separate app ID, urging users to move to that one instead.

SmartTube is one of the most widely downloaded third-party YouTube clients for Android TVs, Fire TV sticks, Android TV boxes, and similar devices.

Its popularity stems from the fact that it is free, can block ads, and performs well on underpowered devices.

A user who reverse-engineered the compromised SmartTube version number 30.51 found that it includes a hidden native library named libalphasdk.so [VirusTotal]. This library does not exist in the public source code, so it is being injected into release builds.

"Possibly a malware. This file is not part of my project or any SDK I use. Its presence in the APK is unexpected and suspicious. I recommend caution until its origin is verified," cautioned Yuliskov on a GitHub thread.

The library runs silently in the background without user interaction, fingerprints the host device, registers it with a remote backend, and periodically sends metrics and retrieves configuration via an encrypted communications channel.

All this happens without any visible indication to the user. While there's no evidence of malicious activity such as account theft or participation in DDoS botnets, the risk of enabling such activities at any time is high.

Entertainment

Netflix Kills Casting From Phones (theverge.com) 95

An anonymous reader writes: Netflix has removed the ability to cast shows and movies from phones to TVs, unless subscribers are using older casting devices. An updated help page on Netflix's website, first reported by Android Authority, says that the streaming service "no longer supports casting shows from a mobile device to most TVs and TV-streaming devices," and instead directs users to navigate Netflix using the remote that came with their TV hardware.
AI

Is OpenAI Preparing to Bring Ads to ChatGPT? (bleepingcomputer.com) 42

"OpenAI is now internally testing 'ads' inside ChatGPT," reports BleepingComputer: Up until now, the ChatGPT experience has been completely free. While there are premium plans and models, you don't see GPT sell you products or show ads. On the other hand, Google Search has ads that influence your buying behaviour. OpenAI is planning to replicate a similar experience.

As spotted [by software engineer Tibor Blaho] on X.com,ChatGPT Android app 1.2025.329 beta includes new references to an "ads feature" with "bazaar content", "search ad" and "search ads carousel."

This move could disrupt the web economy, as what most people don't understand is that GPT likely knows more about users than Google. For example, OpenAI could create personalised ads on ChatGPT that promote products that you really want to buy... The leak suggests that ads will initially be limited to the search experience only, but this may change in the future.

Slashdot Top Deals