Security

Russia's Largest Platform For State Procurement Hit By Cyberattack (therecord.media) 53

Roseltorg, Russia's main electronic trading platform for government and corporate procurement, confirmed it was targeted by a cyberattack claimed by the pro-Ukraine hacker group Yellow Drift. The group allegedly deleted 550 terabytes of data, causing significant operational delays and client concerns. The Record reports: The company initially confirmed last Thursday that its services had been temporarily suspended, without providing further details. In a recent Telegram statement, Roseltorg disclosed that it had been targeted by "an external attempt to destroy data and the entire infrastructure of electronic trading." Roseltorg stated that all data and infrastructure affected by the recent attack had been fully restored, and trading systems are expected to resume operations shortly. However, as of the time of writing, the company's website remains offline.

Last week, the previously unknown pro-Ukraine hacker group Yellow Drift claimed responsibility for the attack on Roseltorg, stating they had deleted 550 terabytes of data, including emails and backups. As proof, the hackers published screenshots from the platform's allegedly compromised infrastructure on their Telegram channel. "If you support tyranny and sponsor wars, be prepared to return to the Stone Age," the hackers said.

The cyberattack on Roseltorg is already impacting clients who rely on the platform's operations, including government agencies, state-owned companies and suppliers. Following the company's announcement, many clients expressed concerns in the comments section, complaining about potential financial losses and delays in the procurement process. Roseltorg said in a statement that once access to the trading systems is reinstated, all deadlines for procedures, including contract signings, will be automatically extended without requiring any requests from users.

Earth

California's Wildfires: Livestreams from Burning Homes and Dire Text Messages - Sometimes Erroneous (msn.com) 150

As the ecological disaster continues, CNN reports the Palisades Fire near Malibu, California has burned at least 22,660 acres, left 100,000 peope under evacuation orders, left at least 11 people dead and "destroyed thousands of homes and other structures." From the last reports it was only 11% contained, and "flames are now spreading east in the Mandeville Canyon area, approaching Interstate 405, one of LA's busiest freeways."

But the Atlantic's assistant editor wrote Friday that "I have received 11 alerts. As far as I can tell, they were all sent in error." My home is not in a mandatory evacuation zone or even a warning zone. It is, or is supposed to be, safe. Yet my family's phones keep blaring with evacuation notices, as they move in and out of service....

Earlier today, Kevin McGowan, the director of Los Angeles County's emergency-management office, acknowledged at a press conference that officials knew alerts like these had gone out, acknowledged some of them were wrong, and still had no idea why, or how to keep it from happening again. The office did not immediately respond to a request for comment, but shortly after this article was published, the office released a statement offering a preliminary assessment that the false alerts were sent "due to issues with telecommunications systems, likely due to the fires' impacts on cellular towers" and announcing that the county's emergency notifications would switch to being managed through California's state alert system...

The fifth, sixth, and seventh evacuation warnings came through at around 6 a.m. — on my phone.

At the same time a Los Angeles-area couple "spent two hours watching a live stream of flames closing in on their home," reports the Washington Post, and at one point "saw firefighters come through the house and extinguish flames in the backyard." At around 4:30 p.m. Eastern time on Tuesday, the camera feeds gave out and the updates from their security system stopped. About four hours later, [Zibby] Owens's husband got an alert on his cellphone that the indoor sprinkler system had gone off and the fire alarm had been activated. They do not know the current status of their home, Owens said on Tuesday.

Real estate agent Shana Tavangarian Soboroff said in a phone interview Thursday that one set of clients had followed their Pacific Palisades home's ordeal this week in a foreboding play-by-play of text alerts from an ADT security system. The system first detected smoke, then motion, next that doors had been opened, and finally fire alerts before the system lost communication. Their home's destruction was later confirmed when someone returned to the neighborhood and recorded video, Tavangarian Soboroff said.

Soboroff also lost her home in the fire, the article adds. Burned to the ground are "the places where people raised their kids," Zibby Owens wrote in this update posted Friday. But "even if my one home, or 'structure' as newscasters call it, happens to be mostly OK, I've still lost something I loved more than anything. We've all lost it... [M]y heart and soul are aching across the country as I sit alone in my office and try to make sense of the devastation." [I]t isn't about our house.

It's about our life.

Our feelings. Our community. Our memories. Our beloved stores, restaurants, streets, sidewalks, neighbors. It's about the homes where we sat at friends' kitchen tables and played Uno, celebrated their birthdays, and truly connected.

It's all gone... [E]very single person I know and so many I don't who live in the Palisades have lost everything. Not just one or two friends. Everyone.

And then I saw video footage of our beloved village. The yogurt shop and Beach Street? Gone. Paliskates, our kids' favorite store? Gone. Burned to the ground.

Gelson's grocery store, where we just recently picked up the New York Post and groceries for the break? Gone...

The. Whole. Town.

How? How is it possible?

How could everyone have lost everything? Schools, homes, power, cell service, cars, everything. All their belongings...

All the schools, gone. It's unthinkable....

I've worked in the local library and watched the July 4 parade from streets that are now smoldering embers...

It is an unspeakable loss.

"Everyone I know in the Palisades has lost all of their possessions," the author writes, publishing what appear to be text messages from friends.

"It's gone."
"We lost everything."
"Nothing left."
"We lost it."
Social Networks

TikTok Pushes Users To Lemon8 As Ban Looms (axios.com) 71

TikTok has been pushing the platform's sister app, Lemon8, encouraging users to migrate via sponsored posts amid a looming ban. Axios reports: In the last few weeks, Lemon8 has been promoting its app to TikTok users through sponsored TikTok videos. In one sponsored post, TikTok user @miller.dailylife shares a video with a creator saying, "TikTok actually has another backup app. It's called Lemon8 ... and it automatically signs you in with your TikTok so you can still keep the same TikTok name and things like that. And it's supposed to transfer your followers over. ... Once you add Lemon8, it automatically pops up on your TikTok bio, so that people can just click on it. So, just so you guys know, now that they're trying to do this ban, if you want to have somewhere else to go where the government is not 100% controlling what we see, what we consume ... Just go ahead and go on to Lemon8."

In November, TikTok began informing users of its sister app, Lemon8, that beginning late that month Lemon8 would be powered by TikTok, and their TikTok usernames would also be used on Lemon8. "Some of your data on TikTok will be used to power services on lemon8," the notice says. "Your Lemon8 profile link will be shown to your TikTok profile publicly by default," it continues. "You can choose not to show it by editing your TikTok profile."
Last March, Lemon8 jumped into the U.S. App Store's Top 10 list shortly after it launched in the U.S. It currently ranks as one of the top-ranking free apps on Apple's app store.

The report notes that the TikTok ban law also applies to other apps owned by TikTok's Chinese parent ByteDance, like Lemon8. "ByteDance could be betting that regulators and app store companies are so focused on TikTok that they won't pay attention to its other apps," says Axios.
Cellphones

The Average American Spent 2.5 Months On Their Phone In 2024 (pcmag.com) 51

Americans check their phones an average of 205 times a day, a 42.3% increase from last year. Millennials are leading the charts in frequency, attachment, and anxiety over phone use, while Gen Z spends the most time daily on their devices at over six hours. PCMag reports: There's a good chance that you're currently reading this article on your phone. If you're like one of the Americans surveyed by Reviews.org, this is one of 205 times today that you'll be checking the device in your hand. To spare you opening the calculator app, that's about once every five minutes you are awake or two and a half full months out of your year.

That's an alarming 42.3% rise from last year when the reviews company asked the same question and found people checked their phones 144 times per day. Some of the ways they spend those 205 moments are:

- 80.6% check their phones within the first 10 minutes of waking up
- 65.7% use their phone on the toilet
- 53.7% have texted someone in the same room
- 38.1% use or look at their phone while on a date
- 27% use or look at their phone while driving

And, of course, there are those many, many times when people check their notifications, with 76% checking their phones within five minutes of receiving one. Millennials are the fastest on the draw, with 89.5% of them checking within 10 minutes. Gen Z and Gen X have found common ground (finally), with 84% of each group looking at notifications shortly after receiving them. Boomers and the Silent Generation aren't as anxious to see who is trying to reach them, with 69% and 53.3%, respectively, checking their notifications within a few minutes.

The Internet

Finland Finds Drag Marks Near Broken Undersea Cable. Russia's 'Shadow Fleet' Suspected (msn.com) 160

Reuters reports: Finnish police said on Sunday they had found tracks that drag on for dozens of kilometres along the bottom of the Baltic Sea where a tanker carrying Russian oil is suspected of breaking a power line and four telecoms cables with its anchor... A break in the 658 megawatt (MW) Estlink 2 power cable between Finland and Estonia occurred at midday on Wednesday, leaving only the 358 MW Estlink 1 linking the two countries, grid operators said. They said Estlink 2 might not be back in service before August.
In an interesting twist, the New York Times reports that the ship "bears all the hallmarks of vessels belonging to Russia's shadow fleet, officials said, and had embarked from a Russian port shortly before the cables were cut." If confirmed, it would be the first known instance of a shadow fleet vessel being used to intentionally sabotage critical infrastructure in Europe — and, officials and experts said, a clear escalation by Russia in its conflict with the West... NATO's general secretary, Mark Rutte, responding to requests from the leaders of Finland and Estonia, both member nations, said the Atlantic alliance would "enhance" its military presence in the Baltic Sea...

Since Russia began assembling its fleet, the number of shadow vessels traversing the oceans has grown by hundreds and now makes up 17 percent of the total global oil tanker fleet... Nearly 70 percent of Russia's oil is being transported by shadow tankers, according to an analysis published in October by the Kyiv School of Economics Institute, a research organization based in Ukraine... The authorities in Finland are still investigating whether the "Eagle S" engaged in a criminal act. But the sheer size of the shadow fleet might have made using some of these vessels for sabotage irresistible to Russia, [said Elisabeth Braw, a senior fellow at the Atlantic Council who has researched and written about shadow fleets]...

While it's still not certain that this week's cable cutting was done intentionally, the Baltic Sea, for a number of reasons, is an ideal arena to carry out sabotage operations. It is relatively shallow and is crisscrossed with essential undersea cables and pipelines that provide energy, as well as internet and phone services, to a number of European countries that are NATO members. Russia has relatively unfettered access to the sea from several ports, and its commercial vessels, protected by international maritime law, can move around international waters largely unmolested... The suspicions that Russia was using shadow vessels for more than just escaping sanctions existed before this week's cable cutting. Last April, the head of Sweden's Navy told a local news outlet that there was evidence such ships were being used to conduct signals intelligence on behalf of Russia and that some fishing vessels had been spotted with antennas and masts not normally seen on commercial vessels. Since the war began, there has also been an uptick in suspicious episodes resulting in damage to critical undersea infrastructure...

Hours after Finland's energy grid operator alerted the police that an undersea power cable was damaged on Wednesday, Finnish officers descended by helicopter to the ship's deck and took over the bridge, preventing the vessel from sailing farther. By Friday, it remained at anchor in the Gulf of Finland, guarded by a Finnish Defense Forces missile boat and a Border Guard patrol vessel.

The cable incident happened just weeks after the EU issued new sanctions targetting Russia's shadow fleet, Euronews reports. "A handful of Chinese companies suspected of enabling Russia's production of drones are also blacklisted as part of the agreement, a diplomat told Euronews." The "shadow fleet" has been accused of deceptive practices, including transmitting falsified data and turning off their transporters to become invisible to satellite systems, and conducting multiple ship-to-ship transfers to conceal the origin of the oil barrels...
Businesses

Video Games Can't Afford To Look This Good (nytimes.com) 85

Major video game studios' pursuit of ultra-realistic graphics has led to diminishing returns and industry-wide layoffs, as younger players gravitate toward simpler, more social games, New York Times is reporting.

Sony's Insomniac Games spent $300 million developing Marvel's Spider-Man 2, triple the budget of its predecessor, before laying off staff amid Sony's 900-person reduction in February. The industry has cut more than 20,000 jobs in the past two years. Meanwhile, games with basic graphics like Minecraft, Roblox and Fortnite continue to dominate, particularly among younger players.

Genshin Impact, a mobile game by Hoyoverse, generates approximately $2 billion annually through frequent content updates rather than cutting-edge visuals. The shift has forced studios to reevaluate their strategies. Warner Bros. Discovery lost $200 million on Suicide Squad: Kill the Justice League, while Sony shuttered its Concord studio shortly after launch. Some industry figures see AI as a potential solution to reduce graphics development costs, the report adds, particularly in sports games.
United States

Trump Transition Leaders Call For Eased Tech Immigration Policy 167

theodp writes: In 2012, now-Microsoft President Brad Smith unveiled Microsoft's National Talent Strategy, a two-pronged strategy that called for tech visa restrictions to be loosened to allow tech companies to hire non-U.S. citizens to fill jobs until more American schoolchildren could be made tech-savvy enough to pass hiring standards. Shortly thereafter, tech-backed nonprofit Code.org emerged (led by Smith's next-door neighbor Hadi Partovi with Smith as a founding Board member) with a mission to ensure that U.S. schoolchildren started receiving 'rigorous' computer science education instruction. Around the same time, Mark Zuckerberg's FWD.us PAC launched (with support from Smith, Partovi, and other tech leaders) with a mission to reform tech visa policy to meet tech's need for talent.

Fast forward to 2024, and Newsweek reports the debate over tech immigration policy has been revived, spurred by the recent appointment of Sriram Krishnan as senior policy adviser for AI at the Trump White House. Comments by far-right political activist Laura Loomer on Twitter about Krishnan's call for loosening Green Card restrictions were met with rebuttals from prominent tech leaders who are also serving as members of the Trump transition team. Entrepreneur David Sacks, who Trump has tapped as his cryptocurrency and AI czar, took to social media to clarify that Krishnan advocates for removing country caps on green cards, not eliminating caps entirely, aiming to create a more merit-based system. However, the NY Times reported that Sacks discussed a much broader visa reform proposal with Trump during a June podcast ("What I will do is," Trump told Sacks, "you graduate from a college, I think you should get automatically, as part of your diploma, a green card to be able to stay in this country"). Elon Musk, the recently appointed co-head of Trump's new Dept. of Government Efficiency (DOGE) had Sacks' and Krishnan's backs (not unexpected -- both were close Musk advisors on his Twitter purchase), tweeting out "Makes sense" to his 209 million followers, lamenting that "the number of people who are super talented engineers AND super motivated in the USA is far too low," reposting claims crediting immigrants for 36% of the innovation in the U.S., and taking USCIS to task for failing to immediately recognize his own genius with an Exceptional Ability Green Card (for his long-defunct Zip2 startup).

Vivek Ramaswamy, who Trump has tapped to co-lead DOGE with Musk, agreed and fanned the Twitter flames with a pinned Tweet of his own explaining, "The reason top tech companies often hire foreign-born -- first-generation engineers over "native" Americans isn't because of an innate American IQ deficit (a lazy -- wrong explanation). A key part of it comes down to the c-word: culture." (Colorado Governor Jared Polis also took to Twitter to agree with Musk and Ramaswamy on the need to import 'elite engineers'). And Code.org CEO Partovi joined the Twitter fray, echoing the old we-need-H1B-visas-to-make-US-schoolchildren-CS-savvy argument of Microsoft's 2012 National Talent Strategy. "Did you know 2/3 of H1B visas are for computer scientists?" Partovi wrote in reply to Musk, Loomer, and Sachs. "The H1B program raises $500M/year (from its corporate sponsors) and all that money is funneled into programs at Labor and NSF without focus to grow local CS talent. Let's fund CS education." The NYT also cited Zuckerberg's earlier efforts to influence immigration policy with FWD.us (which also counted Sacks and Musk as early supporters), taking note of Zuck's recent visit to Mar-a-Lago and Meta's $1 million donation to Trump's upcoming inauguration.

So, who is to be believed? Musk, who attributes any tech visa qualms to "a 'fixed pie' fallacy that is at the heart of much wrong-headed economic thinking" and argues that "there is essentially infinite potential for job and company creation ['We should let anyone in the country who is hardworking and honest and will be a contributor to the United States,' Musk has said]"? Or economists who have found that immigration and globalization is not quite the rising-tide-that-raises-all-boats it's been cracked up to be?
ISS

Russia Space Chief Says Country Will Fly On Space Station Until 2030 (arstechnica.com) 33

Ars Technica's Eric Berger reports: In a wide-ranging interview with a Russian television station, the chief executive of Russia's main space corporation said the country is now planning to participate in the International Space Station project all the way to NASA's desired goal of 2030. "In coordination with our American colleagues, we plan to de-orbit the station sometime around the beginning of 2030," the country's chief space official, Yuri Borisov, said during the interview. "The final scenario will probably be specified after the transition to a new NASA administration."

While the documents for such an extension have not been signed, these comments appear to represent a change in tone from Russia. When he first became head of Roscosmos in 2022, Borisov said Russia would leave the station partnership "after" 2024, which was interpreted as shortly thereafter. Later, Russia committed to working with NASA to keep the orbital outpost flying only through 2028. The US space agency has expressed a consistent desire to keep flying the station until 2030, after which point it hopes that private space station operators can provide one or more replacement facilities.
Borisov said the aging station, elements of which have now been in space for more than a quarter of a century, are becoming difficult to maintain. "Today our cosmonauts have to spend more time repairing equipment and less and less time conducting experiments," he said.
Borisov also discussed Russia's challenges of getting private investment in space-related activities, saying: "In the West, particularly in America, 70 percent of space services are provided by satellite constellations created by private companies. This process has only just begun with us. This is a very risky business for potential investors."

"Right now, the dynamic growth of private space is being influenced by the general economic situation (likely referring to Russia's costly war in Ukraine), high inflation and interest rates, which leads to expensive money for private investors. We can hope that this will be a temporary period and more favorable times will come soon."
AI

Police Report OpenAI Whistleblower Committed Suicide in November (sfstandard.com) 75

An anonymous reader shared this report from the SF Standard: San Francisco police found Open AI whistleblower Suchir Balaji, 26, dead in his Lower Haight apartment November 26, SiliconValley.com reported on Friday. Police said there is "no evidence of foul play. "The manner of death has been determined to be suicide," David Serrano Sewell, director of the office of the city's chief medical examiner, told The Standard by email.

Balaji, a former researcher for the company, accused OpenAI of using copyrighted material to train ChatGPT shortly after he quit the company in August. The New York Times profiled Balaji in a story focused on his whistleblowing in October. Multiple lawsuits against Open AI are expected to present information Balaji unearthed as key evidence.

More details from TechCrunch: After nearly four years working at OpenAI, Balaji quit the company when he realized the technology would bring more harm than good to society, he told The New York Times. Balaji's main concern was the way OpenAI allegedly used copyright data, and he believed its practices were damaging to the internet.

"We are devastated to learn of this incredibly sad news today and our hearts go out to Suchir's loved ones during this difficult time," said an OpenAI spokesperson in an email to TechCrunch...

On November 25, one day before police found Balaji's body, a court filing named the former OpenAI employee in a copyright lawsuit brought against the startup. As part of a good faith compromise, OpenAI agreed to search Balaji's custodial file related to the copyright concerns he had recently raised.

Social Networks

Bluesky's Open API Means Anyone Can Scrape Your Data for AI Training. It's All Public (techcrunch.com) 109

Bluesky says it will never train generative AI on its users' data. But despite that, "one million public Bluesky posts — complete with identifying user information — were crawled and then uploaded to AI company Hugging Face," reports Mashable (citing an article by 404 Media).

"Shortly after the article's publication, the dataset was removed from Hugging Face," the article notes, with the scraper at Hugging Face posting an apology. "While I wanted to support tool development for the platform, I recognize this approach violated principles of transparency and consent in data collection. I apologize for this mistake." But TechCrunch noted the incident's real lesson. "Bluesky's open API means anyone can scrape your data for AI training," calling it a timely reminder that everything you post on Bluesky is public. Bluesky might not be training AI systems on user content as other social networks are doing, but there's little stopping third parties from doing so...

Bluesky said that it's looking at ways to enable users to communicate their consent preferences externally, [but] the company posted: "Bluesky won't be able to enforce this consent outside of our systems. It will be up to outside developers to respect these settings. We're having ongoing conversations with engineers & lawyers and we hope to have more updates to share on this shortly!"

Mashable notes Bluesky's response to 404Media — that Bluesky is like a website, and "Just as robots.txt files don't always prevent outside companies from crawling those sites, the same applies here."

So "While many commentators said that data collection should be opt in, others argued that Bluesky data is publicly available anyway and so the dataset is fair use," according to SiliconRepublic.com.
Classic Games (Games)

What 'The Oregon Trail' Co-Creator Thinks of Apple's Plans for a Movie (cbsnews.com) 51

It's one of the most successful — and oldest — computer games of all-time. This week CBS News Minnesota interviewed Bill Heinemann, who in 1971 co-created "The Oregon Trail" as an educational video game simulating pioneers travelling west. "It's surprising and gratifying and humbling, in a way, that a little thing that I spent two weeks on has become a worldwide phenomenon," Heinemann said... The game's become known for the many ways players can die, including by dysentery, but Heinemann's favorite was death by snake bite. "It only happened once every several hundred times, and so people could've played it for months and all of a sudden, 'What? I got bit by a snake and died? This has never happened to me before!'" he said.
The game has been the subject of numerous satirical articles by McSweeney's. And long-time Slashdot reader whois_drek points out that a sketch comedy group also based a movie on the videogame in 2023.

So how does the game's co-creator feel about Apple's plans to film a new big-budget movie based on the game? "Surprising to me how popular it's become and how long the interest in it has been around," Heinemann said. "And this is just the next step I guess."

He won't be making any money off the movie. In fact, Heinemann's never seen a dime from the iconic game. He and his two co-creators, Rawitsch and Paul Dillenberger, turned it over to the Minnesota Educational Computing Consortium shortly after they invented it. Heinemann says it doesn't bother him. "I didn't do it for money," he said. "I did it for just the love of the game and the love of teaching."

Thanks to Slashdot reader quonset for sharing the news.
Open Source

GitHub Announces New Open Source Fund with Security Mentoring (techcrunch.com) 2

The GitHub Secure Open Source Fund launched this week with an initial commitment of $1.25 million, reports TechCrunch, using "capital from contributors including American Express, 1Password, Shopify, Stripe, and GitHub's own parent company Microsoft." GitHub briefly teased the new initiative at its annual GitHub Universe developer conference last month, but Tuesday it announced full details and formally opened the program for applicants, which will be reviewed "on a rolling basis" through the closing date of January 7, 2025, with programming and funding starting shortly after...

Tuesday's news builds on a number of previous GitHub initiatives designed to support project maintainers that work on key components of critical software, including GitHub Sponsors which landed in 2019 (and which is powering the new fund), but more directly the GitHub Accelerator program that launched its first cohort last year — the GitHub Secure Open Source Fund is essentially an extension of that.

"We're trying to acknowledge the fact that we're the home of open source, ultimately, and we have an obligation to help ensure that open source can continue to thrive and have the support that it needs," GitHub Chief Operating Officer Kyle Daigle told TechCrunch in an interview. Qualifying projects can be pretty much any project that has an open source license, but of course GitHub will be looking at those that need the funds most — so Kubernetes can hold fire with its application. "We're looking for the outsized impact, which tends to be big projects with few maintainers that we all rely on," Daigle said.

The sum of $1.25 million might sound like a reasonable amount, but it will be split across 125 projects, which means just $10,000 each — better than nothing, for sure, but a drop in the ocean on the grand scheme of things. However, Daigle is quick to stress that money is only part of the prize here — as with the initial accelerator program, maintainers embark on a three-week program, which includes mentorship, certification, education workshops, and ongoing access to GitHub tools.

From GitHub's announcement: Since introducing support for organizations through GitHub Sponsors, more than 5,800 organizations, including Microsoft and Stripe, have invested in maintainers and projects on GitHub, up nearly 40% YoY. Cumulatively, the platform has unlocked over $60 million in funding for maintainers to help them spend more time working on their projects.

But we know we're just scratching the surface when it comes to organizations and corporate support of open source. This summer, we partnered with the Linux Foundation and researchers from Laboratory for Innovation Science at Harvard (LISH) to learn more about the state of open source funding today. Diving in, we assessed organizations funding behaviors, potential misalignments, and opportunities to improve. In the report launched today, we found:


- Responding organizations annually invest $1.7 billion in open source, which can be extrapolated to estimate that approximately $7.7 billion is invested across the entire open source ecosystem annually.

- 86% of investment is in the form of contribution labor by employees and contractors working for the funding organization, with the remaining 14% being direct financial contributions.

- Organizations generally know how and where they contribute (65%) but lack specific clarity of their contributions (38%).

- Security efforts focus on bugs and maintenance; only a few (6%) said comprehensive security audits are a priority.


We all stand to benefit from unlocking more funding for open source. By tackling problems like open source security as an ecosystem, we believe we can help create more available funding and resources that are vital to the sustainability of open source. Not every open source project or maintainer has access to funding and training for security. That's why we created a fund that everyone potentially eligible can apply for...

This is the beginning of a journey into helping find ways to secure open source. On its own, it's not the answer, but we are confident it will help. We will be monitoring the impact of these investments and share what we learn as we go.

Medicine

8 Escaped Monkeys Remain at Large, Now Joined By Two Fugitive Emus (the-independent.com) 54

Remember those 43 monkeys that escaped from a U.S. research lab? They've caught 35 of them — but haven't yet caught the other eight.

But even worse... The Independent reports that now another animal escape has led to "reports of two large emus running riot..." The birds' owner, Sam Morace, took to social media to plead with locals for their patience, saying: "For everyone that keeps seeing an emu, yes it is mine. There are 2 of them out." Morace said their two flightless birds broke loose three months ago.... "They are feral and not trained like the ones we have at the house."
This provoked some discussion on Facebook. ("Does nobody learn to lasso anymore?") But Morace responded that you "can't lasso a bird you have to grab them by their feet. Their necks are super long and fragile." In another post Morace detailed efforts to capture their birds. "Local law enforcement has already been at my house, we are trying to get a tranquilizer approved so we can bring them home.

"Thank you for all the concerns and questions. But if the emus were that easy to catch they would be home already.

If you're wondering how the escaped monkeys are doing out in the wild, someone who photographed them earlier this week said they appeared "playful, curious and jumping from tree to tree." The Guardian reports local officials have now "requested that the public avoid using drones near the facility. Earlier in the week, they reported that a drone incident 'spooked' the monkeys, increasing their stress levels and complicating efforts to recapture them."

Their article also notes reports that the facility houses 7,000 monkeys. And this isn't the first time some have escaped... In 2016, 19 monkeys escaped from the same facility, according to the Post and Courier newspaper, but were returned after six hours. Earlier, in 2014, 26 macaques reportedly escaped and were captured within two days. Documents from federal regulators from previous years revealed other incidents at the facility, as reported by the New York Times. One involved a primate escaping while being transported to the medical clinic and subsequently disappearing into the woods. Another involved two monkeys breaking out of their outdoor chain-link enclosure, which reportedly resulted in one monkey being lured back inside and the other dying shortly after being recaptured. In 2017, the Department of Agriculture fined the company more than $12,000 partly due to failures to contain the animals, according to the New York Times.
The Guardian also links to a related read from February: "Plan for US 'mini-city' of 30,000 monkeys for medical research faces backlash." Over the next 20 years, the facility will assemble a mega-troop of about 30,000 long-tailed macaques, a species native to south-east Asia, in vast barn-like structures in Bainbridge, Georgia, which has a human population of just 14,000... But the plan faces fierce opposition, with some Bainbridge residents calling on local authorities to block the construction of the proposed primate manse. "They're an invasive species and 30,000 of them, we'd just be overrun with monkeys," claimed Ted Lee, a local man. "I don't think anybody would want 30,000 monkeys next door," added David Barber, who would live just 400ft from the new facility.
Earth

Cop29 CEO Filmed Agreeing To Facilitate Fossil Fuel Deals at Climate Summit (theguardian.com) 70

The chief executive of Cop29 has been filmed apparently agreeing to facilitate fossil fuel deals at the climate summit. From a report: The recording has amplified calls by campaigners who want the fossil fuel industry and its lobbyists to be banned from future Cop talks. The campaign group Global Witness posed undercover as a fake oil and gas group asking for deals to be facilitated in exchange for sponsoring the event. In the calls, Elnur Soltanov, Azerbaijan's deputy energy minister and chief executive of Cop29, agreed to this and spoke of a future that includes fossil fuels "perhaps for ever." Cop officials also introduced the fake investor to a senior executive at the national oil and gas company Socar to discuss investment opportunities.

Soltanov told the fake investment group: âoeI would be happy to create a contact between your team and their team [Socar] so that they can start discussions." Shortly after that they received an email from Socar. The UN framework convention on climate change (UNFCCC), the UN body that oversees Cop, says officials should not use their roles "to seek private gain" and it expects them to act "without self-interest."

AI

OpenAI Acquires Chat.com (domainnamewire.com) 8

OpenAI has acquired the chat.com domain name, likely for well over $10 million. OpenAI CEO Sam Altman posted a one-word tweet this morning, simply stating, "chat.com." Domain Name Wire reports: The chat.com domain name has changed hands for the third time in two years. HubSpot founder Dharmesh Shah kicked off the buying last year, plunking down over $15.5 million for the domain name. He turned around and sold the domain shortly thereafter for a profit.
The Almighty Buck

JPMorgan Begins Suing Customers In 'Infinite Money Glitch' (cnbc.com) 222

JPMorgan Chase is suing customers who exploited an ATM glitch that allowed them to withdraw funds before a check bounced. CNBC reports: The bank on Monday filed lawsuits in at least three federal courts, taking aim at some of the people who withdrew the highest amounts in the so-called infinite money glitch that went viral on TikTok and other social media platforms in late August. [...] JPMorgan, the biggest U.S. bank by assets, is investigating thousands of possible cases related to the "infinite money glitch," though it hasn't disclosed the scope of associated losses. Despite the waning use of paper checks as digital forms of payment gain popularity, they're still a major avenue for fraud, resulting in $26.6 billion in losses globally last year, according to Nasdaq's Global Financial Crime Report.

The infinite money glitch episode highlights the risk that social media can amplify vulnerabilities discovered at a financial institution. Videos began circulating in late August showing people celebrating the withdrawal of wads of cash from Chase ATMs shortly after bad checks were deposited. Normally, banks only make available a fraction of the value of a check until it clears, which takes several days. JPMorgan says it closed the loophole a few days after it was discovered.

The lawsuits are likely to be just the start of a wave of litigation meant to force customers to repay their debts and signal broadly that the bank won't tolerate fraud, according to the people familiar. JPMorgan prioritized cases with large dollar amounts and indications of possible ties to criminal groups, they said. The civil cases are separate from potential criminal investigations; JPMorgan says it has also referred cases to law enforcement officials across the country.
"Fraud is a crime that impacts everyone and undermines trust in the banking system," JPMorgan spokesman Drew Pusateri said in a statement to CNBC. "We're pursuing these cases and actively cooperating with law enforcement to make sure if someone is committing fraud against Chase and its customers, they're held accountable."
News

Georgian Authorities Raid Homes of Disinformation Researchers Ahead of Elections (therecord.media) 68

Ahead of Georgia's parliamentary elections, Georgian authorities raided the homes of disinformation researchers Eto Buziashvili and Sopo Gelava, seizing personal devices. The Record: Eto Buziashvili and Sopo Gelava, both employees of the Atlantic Council think tank, had their homes searched and their own and their family members' personal devices seized by investigators working for the country's Ministry of Finance, according to friends of the pair who spoke to Recorded Future News. Both women are said to be safe, although there are concerns about the security of their devices and online accounts. The searches come a day after Buziashvili published an article detailing how the Kremlin was influencing Georgian politics by supporting the incumbent government and interfering in the upcoming elections.

Local media reported that the offices of outsourcing company Concentrix and other Georgian citizens were also subject to searches. The Ministry of Finance claimed on Facebook it launched searches of "specific facilities" related to "call centers" alleged to be engaged in illegal activity. The investigations come ahead of an election that is being seen as a bellwether of the country's future direction, either pursuing closer ties to Russia under the current prime minister Irakli Kobakhidze or moving towards the West through opposition figures.
Graham Brookie, the Atlantic Council's vice president for technology programs and strategy, said the organization "is deeply concerned about this development and its impact on our staff's work shortly before Georgian elections. [Gelava and Buziashvili] are engaged in independent, non-partisan work aimed at defending and strengthening democracy from those who would undermine it in online spaces, including research related to foreign influence efforts, the targeting of marginalized communities, and other online harms."

"We trust that Georgian authorities will provide more clarity on their actions, ensure the safety and security of our staff, return their property, and allow them to continue their contributions to Georgian democracy."
Power

Cuba Plunged Into an Island Wide Blackout As Power Grid Fails (npr.org) 107

Cuba's power grid failed on Friday, leaving 10 million people without electricity. NPR reports: One of the country's largest power plants, the Antonio Guiteras power plant in the western province of Matanzas, failed shortly before midday on Friday. The failure prompted a total breakdown of Cuba's electrical system. The power outage comes after days of rolling blackouts. Cuba's prime minister, Manuel Marrero Cruz, blamed the problem on deteriorating infrastructure and fuel shortages exacerbated by Hurricane Milton, which has made it difficult for fuel deliveries to reach the island.

The prime minister made an address on state television on Thursday evening and said the government would prioritize providing electricity to residential areas and promised shipments of fuel would arrive on the island in the coming days. Cuban officials have not indicated a timeline for when the power grid will be operational again. The massive blackout is a new low in a country that has already been dealing with a deepening economic crisis and widespread food shortages.

The Courts

Judge Blocks California's New AI Law In Case Over Kamala Harris Deepfake (techcrunch.com) 128

An anonymous reader quotes a report from TechCrunch: A federal judge blocked one of California's new AI laws on Wednesday, less than two weeks after it was signed by Governor Gavin Newsom. Shortly after signing AB 2839, Newsom suggested it could be used to force Elon Musk to take down an AI deepfake of Vice President Kamala Harris he had reposted (sparking a petty online battle between the two). However, a California judge just ruled the state can't force people to take down election deepfakes -- not yet, at least. AB 2839 targets the distributors of AI deepfakes on social media, specifically if their post resembles a political candidate and the poster knows it's a fake that may confuse voters. The law is unique because it does not go after the platforms on which AI deepfakes appear, but rather those who spread them. AB 2839 empowers California judges to order the posters of AI deepfakes to take them down or potentially face monetary penalties.

Perhaps unsurprisingly, the original poster of that AI deepfake -- an X user named Christopher Kohls -- filed a lawsuit to block California's new law as unconstitutional just a day after it was signed. Kohls' lawyer wrote in a complaint that the deepfake of Kamala Harris is satire that should be protected by the First Amendment. On Wednesday, United States district judge John Mendez sided with Kohls. Mendez ordered a preliminary injunction to temporarily block California's attorney general from enforcing the new law against Kohls or anyone else, with the exception of audio messages that fall under AB 2839. [...] In essence, he ruled the law is simply too broad as written and could result in serious overstepping by state authorities into what speech is permitted or not.

Slashdot Top Deals