Medicine

How Your Gut Influences Your Brain (stanford.edu) 53

A blog post from the Stanford University School of Medicine attempts to answer the question: What's the deal with the gut-brain connection? It affects your mood, your sleep, even your motivation to exercise. There's convincing evidence that it's the starting point for Parkinson's disease and could be responsible for long COVID's cognitive effects. And it sits about 2 feet below your brain. The gut plays an obvious role in our health by digesting what we eat and extracting nutrients. But there's a growing appreciation among scientists that our digestive systems affect our general well-being in a much broader fashion.

One fascinating aspect of the gut's widespread impact on health is its direct influence on and communication with the brain, a conduit known as the gut-brain axis. Through direct signals from the vagus nerve, [which] connects the brain and the gut, as well as through molecules secreted into the bloodstream from our gut microbes and immune cells that traffic from the gut to the rest of the body, our brains and our digestive tracts are in constant communication. And when that communication goes off the rails, diseases and disorders can result. The gut-brain connection is a key part of how the brain forms a picture of the rest of the body, a phenomenon known as interoception, explained Christoph Thaiss, PhD, an assistant professor of pathology at Stanford Medicine...

The gut also contains the largest number of neurons outside the brain of any structure in the body — more than 100 million neurons line the human digestive tract, from the esophagus to the anus. These cells make up what is known as the enteric nervous system, which some scientists refer to as a "second brain." The enteric nervous system is more brain-like than other peripheral nerves because it consists of lots of different types of neurons that communicate with each other, while other peripheral nerves primarily serve to communicate between the brain and the body, said Julia Kaltschmidt, PhD, the Firmenich Next Generation Faculty Scholar and an associate professor of neurosurgery. In fact, the gut's nervous system can act alone. Scientists have found that if they remove an animal's gut and bathe it in a special fluid designed to keep neurons alive, the gut continues to contract, pushing its contents from top to bottom.

China

Undocumented 'Backdoor' Found In Chinese Bluetooth Chip Used By a Billion Devices (bleepingcomputer.com) 129

"The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains an undocumented 'backdoor' that could be leveraged for attacks," writes BleepingComputer.

"The undocumented commands allow spoofing of trusted devices, unauthorized data access, pivoting to other devices on the network, and potentially establishing long-term persistence." This was discovered by Spanish researchers Miguel Tarascó Acuña and Antonio Vázquez Blanco of Tarlogic Security, who presented their findings yesterday at RootedCON in Madrid. "Tarlogic Security has detected a backdoor in the ESP32, a microcontroller that enables WiFi and Bluetooth connection and is present in millions of mass-market IoT devices," reads a Tarlogic announcement shared with BleepingComputer. "Exploitation of this backdoor would allow hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks or medical equipment by bypassing code audit controls...."

Tarlogic developed a new C-based USB Bluetooth driver that is hardware-independent and cross-platform, allowing direct access to the hardware without relying on OS-specific APIs. Armed with this new tool, which enables raw access to Bluetooth traffic, Targolic discovered hidden vendor-specific commands (Opcode 0x3F) in the ESP32 Bluetooth firmware that allow low-level control over Bluetooth functions. In total, they found 29 undocumented commands, collectively characterized as a "backdoor," that could be used for memory manipulation (read/write RAM and Flash), MAC address spoofing (device impersonation), and LMP/LLCP packet injection.

Espressif has not publicly documented these commands, so either they weren't meant to be accessible, or they were left in by mistake.

Thanks to Slashdot reader ZipNada for sharing the news.

Submission + - Undocumented "backdoor" found in Bluetooth chip used by a billion devices (bleepingcomputer.com)

ZipNada writes: The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains an undocumented "backdoor" that could be leveraged for attacks.

The undocumented commands allow spoofing of trusted devices, unauthorized data access, pivoting to other devices on the network, and potentially establishing long-term persistence.

This was discovered by Spanish researchers Miguel Tarascó Acuña and Antonio Vázquez Blanco of Tarlogic Security, who presented their findings yesterday at RootedCON in Madrid.

"Tarlogic Security has detected a backdoor in the ESP32, a microcontroller that enables WiFi and Bluetooth connection and is present in millions of mass-market IoT devices," reads a Tarlogic announcement shared with BleepingComputer.

"Exploitation of this backdoor would allow hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks or medical equipment by bypassing code audit controls."

The researchers warned that ESP32 is one of the world's most widely used chips for Wi-Fi + Bluetooth connectivity in IoT (Internet of Things) devices, so the risk of any backdoor in them is significant.

AI

Users Report Emotional Bonds With Startlingly Realistic AI Voice Demo (arstechnica.com) 65

An anonymous reader quotes a report from Ars Technica: In late 2013, the Spike Jonze film Her imagined a future where people would form emotional connections with AI voice assistants. Nearly 12 years later, that fictional premise has veered closer to reality with the release of a new conversational voice model from AI startup Sesame that has left many users both fascinated and unnerved. "I tried the demo, and it was genuinely startling how human it felt," wrote one Hacker News user who tested the system. "I'm almost a bit worried I will start feeling emotionally attached to a voice assistant with this level of human-like sound."

In late February, Sesame released a demo for the company's new Conversational Speech Model (CSM) that appears to cross over what many consider the "uncanny valley" of AI-generated speech, with some testers reporting emotional connections to the male or female voice assistant ("Miles" and "Maya"). In our own evaluation, we spoke with the male voice for about 28 minutes, talking about life in general and how it decides what is "right" or "wrong" based on its training data. The synthesized voice was expressive and dynamic, imitating breath sounds, chuckles, interruptions, and even sometimes stumbling over words and correcting itself. These imperfections are intentional.

"At Sesame, our goal is to achieve 'voice presence' -- the magical quality that makes spoken interactions feel real, understood, and valued," writes the company in a blog post. "We are creating conversational partners that do not just process requests; they engage in genuine dialogue that builds confidence and trust over time. In doing so, we hope to realize the untapped potential of voice as the ultimate interface for instruction and understanding." [...] Sesame sparked a lively discussion on Hacker News about its potential uses and dangers. Some users reported having extended conversations with the two demo voices, with conversations lasting up to the 30-minute limit. In one case, a parent recounted how their 4-year-old daughter developed an emotional connection with the AI model, crying after not being allowed to talk to it again.

Submission + - Users Report Emotional Bonds With Startlingly Realistic AI Voice Demo (arstechnica.com)

An anonymous reader writes: In late 2013, the Spike Jonze film Her imagined a future where people would form emotional connections with AI voice assistants. Nearly 12 years later, that fictional premise has veered closer to reality with the release of a new conversational voice model from AI startup Sesame that has left many users both fascinated and unnerved. "I tried the demo, and it was genuinely startling how human it felt," wrote one Hacker News user who tested the system. "I'm almost a bit worried I will start feeling emotionally attached to a voice assistant with this level of human-like sound."

In late February, Sesame released a demo for the company's new Conversational Speech Model (CSM) that appears to cross over what many consider the "uncanny valley" of AI-generated speech, with some testers reporting emotional connections to the male or female voice assistant ("Miles" and "Maya"). In our own evaluation, we spoke with the male voice for about 28 minutes, talking about life in general and how it decides what is "right" or "wrong" based on its training data. The synthesized voice was expressive and dynamic, imitating breath sounds, chuckles, interruptions, and even sometimes stumbling over words and correcting itself. These imperfections are intentional.

"At Sesame, our goal is to achieve 'voice presence'—the magical quality that makes spoken interactions feel real, understood, and valued," writes the company in a blog post. "We are creating conversational partners that do not just process requests; they engage in genuine dialogue that builds confidence and trust over time. In doing so, we hope to realize the untapped potential of voice as the ultimate interface for instruction and understanding." [...] Sesame sparked a lively discussion on Hacker News about its potential uses and dangers. Some users reported having extended conversations with the two demo voices, with conversations lasting up to the 30-minute limit. In one case, a parent recounted how their 4-year-old daughter developed an emotional connection with the AI model, crying after not being allowed to talk to it again.

Encryption

ExpressVPN Gets Faster and More Secure, Thanks To Rust (zdnet.com) 55

ZDNet's Steven Vaughan-Nichols shares some of the latest improvements to ExpressVPN following its codebase transition from C to Rust. An anonymous reader quotes an excerpt from the report: ExpressVPN is one of ZDNET's favorite Virtual Private Networks (VPNs). The popular VPN's transformation of its Lightway codebase from C to Rust promises to make the service faster and more secure. For now, the updated Lightway 2.0 is only available via ExpressVPN's Aircove router with the February 4 AircoveOS v5 update. The Aircove, which we rate as the best VPN router, costs $189. With this device, you can protect your tech from unwanted snoopers without installing a VPN on each gadget. So, how much faster is the updated ExpressVPN? In my tests, I connected to the internet via my updated router over my 2 Gigabit per second (Gbps) AT&T Internet using a 2.5 Gbps Ethernet-connected Linux Mint desktop with a Wi-Fi 6 connection over my Samsung Galaxy 25 Plus smartphone.

Without the VPN engaged, I saw 1.6 Gbps speeds, which is about par. With the VPN switched on and using Lightway 2.0, I saw speeds in the 290 to 330 Megabit per second (Mbps) range to Toronto and London, England. Farther afield, I saw speeds around 250 to 280Mbps to Hong Kong and Seoul. That's about 20% faster than I had seen with earlier Lightway versions. I was impressed. This version of the VPN should also be more secure. As Pete Membrey, ExpressVPN's chief research officer, said in a statement: "At ExpressVPN, we innovate to solve the challenges of tomorrow. Upgrading Lightway from its previous C code to Rust was a strategic and straightforward decision to enhance performance and security while ensuring longevity."

The updated Lightway VPN protocol also uses ML-KEM, the newly finalized NIST standard for post-quantum encryption. This feature, wrote Membray in a blog post, "ensures your connection is secured by encryption designed not just for today's threats but for the quantum-powered challenges of the future." To ensure the integrity of the recoded Lightway protocol, ExpressVPN commissioned two independent security audits from cybersecurity firms Cure53 and Praetorian. Both audits yielded positive results, with only minor vulnerabilities identified and promptly addressed by ExpressVPN. In short, ExpressVPN is technically about as safe a VPN as they come.

Submission + - ExpressVPN Gets Faster and More Secure, Thanks To Rust (zdnet.com)

An anonymous reader writes: ExpressVPN is one of ZDNET's favorite Virtual Private Networks (VPNs). The popular VPN's transformation of its Lightway codebase from C to Rust promises to make the service faster and more secure. For now, the updated Lightway 2.0 is only available via ExpressVPN's Aircove router with the February 4 AircoveOS v5 update. The Aircove, which we rate as the best VPN router, costs $189. With this device, you can protect your tech from unwanted snoopers without installing a VPN on each gadget. So, how much faster is the updated ExpressVPN? In my tests, I connected to the internet via my updated router over my 2 Gigabit per second (Gbps) AT&T Internet using a 2.5 Gbps Ethernet-connected Linux Mint desktop with a Wi-Fi 6 connection over my Samsung Galaxy 25 Plus smartphone.

Without the VPN engaged, I saw 1.6 Gbps speeds, which is about par. With the VPN switched on and using Lightway 2.0, I saw speeds in the 290 to 330 Megabit per second (Mbps) range to Toronto and London, England. Farther afield, I saw speeds around 250 to 280Mbps to Hong Kong and Seoul. That's about 20% faster than I had seen with earlier Lightway versions. I was impressed. This version of the VPN should also be more secure. As Pete Membrey, ExpressVPN's chief research officer, said in a statement: "At ExpressVPN, we innovate to solve the challenges of tomorrow. Upgrading Lightway from its previous C code to Rust was a strategic and straightforward decision to enhance performance and security while ensuring longevity."

The updated Lightway VPN protocol also uses ML-KEM, the newly finalized NIST standard for post-quantum encryption. This feature, wrote Membray in a blog post, "ensures your connection is secured by encryption designed not just for today's threats but for the quantum-powered challenges of the future." To ensure the integrity of the recoded Lightway protocol, ExpressVPN commissioned two independent security audits from cybersecurity firms Cure53 and Praetorian. Both audits yielded positive results, with only minor vulnerabilities identified and promptly addressed by ExpressVPN. In short, ExpressVPN is technically about as safe a VPN as they come.

Communications

AT&T and Verizon Connect First Cellphone-To-Satellite Video Calls (theverge.com) 9

AT&T and Verizon have successfully completed their first cellphone-to-satellite video calls using AST SpaceMobile's satellites, marking a significant step toward commercial satellite networks. The Verge reports: Verizon has completed its first cellphone-to-satellite video call, while AT&T has completed its first using satellites that will be used as part of a commercial network. [...] Verizon pulled off "a live video call between two mobile devices with one connected via satellite and the other connected via Verizon's terrestrial network connection," according to a company press release.

In AT&T's case, "AT&T and AST SpaceMobile have successfully completed another video call by satellite to an everyday smartphone over AT&T spectrum," per AT&T's press release. Both phone companies relied on AST's constellation of five BlueBird satellites that were launched last September for the tests. AT&T's initial video call test happened in June 2023.

Submission + - Kimbal Musk Nonprofit Took $1.6M in PPP Money, Then Fired Unionizing Employees

theodp writes: With reports of "millions and millions of people over 100 years old” receiving Social Security benefits turning out to be more of a Know-Thy-Data problem, one wonders if Elon Musk's DOGE team might turn its attention to the fraught-with-fraud $800 billion Federal Paycheck Protection Program (PPP). If so, he may be getting some of that nonstop scrutiny he says he expects, here in connection with $1.6+ million in since-forgiven PPP loans made to his brother Kimbal Musk's Big Green nonprofit during COVID in 2020-2021, a period that saw Elon ascend to the title of World's Richest Person. SBA records show and Big Green's audited financial statements confirm the nonprofit had one loan approved on 4/9/2020 for $783,500 (apparently with its CFO's home address given for 'Borrower Address') and a second on 2/24/2021 for $852,334; the loans were respectively forgiven on 5/4/2021 and 11/20/2021.

A 2019 Musk Foundation IRS 990 filing that reported $207M in year-end assets and listed Elon Musk as President also disclosed a $250,000 grant to brother Kimbal's Big Green nonprofit. An earlier 2017 Musk Foundation 990 filing reported Kimbal was its Secretary & Treasurer during a year that also saw the Musk Foundation transfer $37+ million to a donation-anonymizing donor-advised fund and give $10 million to YC.org — a nonprofit led by then-Y Combinator President and now-OpenAI CEO Sam Altman — which The Guardian suggested acted as a holding area for OpenAI while it got its tax-free nonprofit status ducks in a row. YC.org later sent $10M to OpenAI in 2016 and another $16M in 2019, years in which Musk and Altman were OpenAI Directors.

The 'Paycheck Protection' provided by the forgiven loans proved to be short-lived for some Big Green employees. Last September, The Colorado Sun and others reported that Big Green agreed to pay $449,999 in back pay, benefits and wages as part of an unfair-termination settlement to 10 workers who were fired on Sept. 13, 2021 — prior to the 2nd PPP loan being forgiven — after demanding recognition for their union (which is coincidentally a pet peeve of Elon's).
Games

Valve Releases Team Fortress 2 Full Client and Source Code (gamerant.com) 47

Valve has made Team Fortress 2's full client and server code public, allowing fans to modify, extend, or rewrite the game as long as their projects remain non-commercial. Game Rant reports: Valve has made Team Fortress 2's server and client code fully public, with the studio encouraging fans to explore the game's files and make it what they want. The game's code is now available thanks to a new update to the Source SDK, which dropped earlier this week. Fans have already been creating TF2 mods for years, but what this essentially means is that fans can make brand-new games. However, there's one catch: any and all TF2 mods must be released for free. "The majority of items in the game now are thanks to the hard work of the TF2 community." Valve wrote. "To respect that, we're asking TF2 mod makers to continue to respect that connection and not to make mods that have the purpose of trying to profit off Workshop contributors' efforts."

"TF2 mods may be published on the Steam Store, and after publication will appear as new games in the Steam game list," Valve continued. The new SDK update also includes new 64-bit binary support and fixes for multiplayer Source games like Half-Life 2: Deathmatch, Counter-Strike: Source, and Day of Defeat: Source. Time will only tell what fans come up with as they dig deep into the inner workings of the game, but given how passionate and talented the Team Fortress 2 community has proven to be, players can expect to see some incredible creations.

Submission + - TikTok Ban Linked to Pro-Palestine Content, Not China Threat (middleeasteye.net) 1

hackingbear writes: The main reason behind the United States' push to ban social media application TikTok is due to Israel’s image rather than fears of Chinese infiltrations, US Senator Mark Warner and Mike Gallagher have revealed during a panel the Munich Security Conference. Warner, the top Democrat on the intelligence committee, introduced the TikTok ban bill in 2023 along with Gallagher,who is the current Palantir executive. “So we had a bipartisan consensus,” Gallagher said. “We had the executive branch, but the bill was still dead until October 7th. And people started to see a bunch of antisemitic content on the platform and our bill had legs again.” A memo produced by the State Department for its Near East Affairs diplomats, which Klippenstein obtained, describes how Israel's deputy director general for public diplomacy at the foreign ministry, Emmanuel Nahshon, blamed the youth’s opposition to the war on Gaza on TikTok’s algorithm. The memo added that Nahshon said the youth’s public opinion was shifting because “the Tik-Tok algorithm favours pro-Palestinian content”. Gallagher also said in Munich that TikTok had made a “huge miscalculation” in its attempt to circumvent the ban. When TikTok sent a notification to its millions of users urging them to call their members of Congress to oppose the bill, Gallagher said it “proved” that the social media company had “brainwashed” American youth. While President Donald Trump temporarily reversed his Democratic predecessor’s TikTok ban the day after he took office, the application’s future in the country, as well as the state of its pro-Palestine content, remains unclear. When the application was available to Americans again in late January, many users pointed out that phrases like “free Palestine” were being flagged as hate speech, raising concerns about potential censorship on the platform following its return to the US.

Submission + - French councils teach staff to talk to plants (thetimes.com)

An anonymous reader writes: Left-wing councils are under fire for sending staff on courses where they pretend to be trees, bats, fish and other “non-human living things” to understand the “connection between species”.
Businesses

Will Amazon's Return-to-Office Mandate Revitalize Downtown Seattle? (seattlemag.com) 73

"Amazon required employees to work from the office five days a week starting January 2nd," writes the Seattle Times, "a change from the company's three-day in-office mandate that had been in effect since May 2023."

And as Seattle's largest employer (with 50,000 Seattle-based workers), this had an impact, according to data the Times cites from the nonprofit Downtown Seattle Association: In January, downtown Seattle recorded the second-highest daily average for weekday worker foot traffic since March 2020. It also saw 2 million unique visitors on its sidewalks last month. That represents 94% of the visitors downtown Seattle saw in January 2019, the Downtown Seattle Association found...

In a statement Friday, Amazon said "we're excited by the innovation, collaboration and connection we've seen already with our teams working in person together...." Jon Scholes [the president of the Downtown Seattle Association] said Amazon's return has been a boon for downtown Seattle. As the city's largest employer, its mandate instantly brought more people to shop and dine around South Lake Union, the Denny Triangle and surrounding neighborhoods... "I think we're seeing people get reacquainted with the reasons they liked working downtown prepandemic," Scholes said. He expects to continue seeing an uptick in foot traffic over the course of the year as more companies follow Amazon's lead and the weather warms up.

But Seattle magazine says the statistics show foot traffic in neighborhoods where Amazon's offices are located (South Lake Union and Denny Regrade) "at 74% of that of January 2019. Overall, downtown-area foot traffic was 9% higher than it was a year ago, though only 57% of the pre-pandemic average."
Social Networks

Are Technologies of Connection Tearing Us Apart? (lareviewofbooks.org) 88

Nicholas Carr wrote The Shallows: What the Internet Is Doing to Our Brains. But his new book looks at how social media and digital communication technologies "are changing us individually and collectively," writes the Los Angeles Review of Books.

The book's title? Superbloom: How Technologies of Connection Tear Us Apart . But if these systems are indeed tearing us apart, the reasons are neither obvious nor simple. Carr suggests that this isn't really about the evil behavior of our tech overlords but about how we have "been telling ourselves lies about communication — and about ourselves.... Well before the net came along," says Carr, "[the] evidence was telling us that flooding the public square with more information from more sources was not going to open people's minds or engender more thoughtful discussions. It wasn't even going to make people better informed...."

At root, we're the problem. Our minds don't simply distill useful knowledge from a mass of raw data. They use shortcuts, rules of thumb, heuristic hacks — which is how we were able to think fast enough to survive on the savage savanna. We pay heed, for example, to what we experience most often. "Repetition is, in the human mind, a proxy for facticity," says Carr. "What's true is what comes out of the machine most often...." Reality can't compete with the internet's steady diet of novelty and shallow, ephemeral rewards. The ease of the user interface, congenial even to babies, creates no opportunity for what writer Antón Barba-Kay calls "disciplined acculturation."

Not only are these technologies designed to leverage our foibles, but we are also changed by them, as Carr points out: "We adapt to technology's contours as we adapt to the land's and the climate's." As a result, by designing technology, we redesign ourselves. "In engineering what we pay attention to, [social media] engineers [...] how we talk, how we see other people, how we experience the world," Carr writes. We become dislocated, abstracted: the self must itself be curated in memeable form. "Looking at screens made me think in screens," writes poet Annelyse Gelman. "Looking at pixels made me think in pixels...."

That's not to say that we can't have better laws and regulations, checks and balances. One suggestion is to restore friction into these systems. One might, for instance, make it harder to unreflectively spread lies by imposing small transactional costs, as has been proposed to ease the pathologies of automated market trading. An option Carr doesn't mention is to require companies to perform safety studies on their products, as we demand of pharmaceutical companies. Such measures have already been proposed for AI. But Carr doubts that increasing friction will make much difference. And placing more controls on social media platforms raises free speech concerns... We can't change or constrain the tech, says Carr, but we can change ourselves. We can choose to reject the hyperreal for the material. We can follow Samuel Johnson's refutation of immaterialism by "kicking the stone," reminding ourselves of what is real.

NASA

ISS Astronauts Give Space-to-Earth Interview Weeks Before Finally Returning to Earth (cnn.com) 18

Last June two NASA astronauts flew to the International Space Station on the first crewed test flight of Boeing's Starliner. But they aren't stranded there, and they weren't abandoned, the astronauts reminded CNN this week in a rare space-to-earth interview: "That's been the rhetoric. That's been the narrative from day one: stranded, abandoned, stuck — and I get it. We both get it," [NASA astronaut Butch] Wilmore said. "But that is, again, not what our human spaceflight program is about. We don't feel abandoned, we don't feel stuck, we don't feel stranded." Wilmore added a request: "If you'll help us change the rhetoric, help us change the narrative. Let's change it to 'prepared and committed.'

"That's what we prefer," he said...

[NASA astronaut Suni] Williams also reiterated a sentiment she has expressed on several occasions, including in interviews conducted before she left Earth. "Butch and I knew this was a test flight," she told CNN's Cooper, acknowledging the pair has been prepared for contingencies and understood that the stay in space might be extended. "We knew that we would probably find some things (wrong with Starliner) and we found some stuff, and so that was not a surprise," she said.

When Cooper opened the interview by asking the astronauts how they're doing, Williams answers "We're doing pretty darn good, actually," pointing out they had plenty of food and great crew members. And Wilmore added that crews come to the space station on a careful cycle, and "to alter that cycle sends ripple effects all the way down the chain. We would never expect to come back just special for us or anyone unless it was a medical issue or something really out of the circumstances along those lines. So we need to come back and keep the normal cycle going..."

CNN's article notes a new announcement from NASA Tuesday that the astronauts might return a couple weeks early "after opting to change the SpaceX Crew Dragon capsule it will use." That mission's targeted launch date is now March 12.

In the meantime, Williams says in the interview, "We do have some internet connection up here, so we can get some internet live. We've gotten football. It's been this crew's go-to this past fall. Also YouTube or something like that. It's not continuous — it has chunks of time that we get it. And we use that same system also to make phone calls home, so we can talk to our families, and do videoconferences even on the weekends as well. This place is a pretty nice place to live, for the most part."

And they're also "working on with folks on the ground" to test the NASA's cube-shaped, free-flying robotic Astrobees.
Open Source

LibreOffice Marks 40th Year With Browser-Based Overhaul (theregister.com) 48

LibreOffice, the open-source office suite that began as StarOffice in 1985, has marked its 40th anniversary with new features that it says could transform how users interact with the software. At the FOSDEM 2025 conference, developers unveiled LibreOffice 25.2, which introduces browser-based functionality and real-time collaboration capabilities through a technology called conflict-free replicated data types.

A key development is ZetaOffice, a version built for the WebAssembly runtime that enables the full office suite to run inside web browsers across operating systems and CPU architectures. The project, which entered public beta last November, allows websites to embed LibreOffice applications with complete user interfaces for editing documents, spreadsheets and presentations.

While the browser-based version currently requires about a gigabyte of code and additional memory to run, developers at Allotropia are working to modularize the codebase for faster loading times. The software, released under the MIT license, can be controlled via JavaScript and operates without requiring an internet connection, unlike Google Docs or LibreOffice's existing Collabora Online version.
Bitcoin

Man Who Hijacked SEC's X Account To Pump Bitcoin Faces Up To 5 Years In Prison (gizmodo.com) 49

Eric Council Jr. pleaded guilty to identity theft and access device fraud after hijacking the SEC's X account to falsely announce Bitcoin ETF approval. He was compensated in Bitcoin by co-conspirators, and while the Justice Department continues its investigation, Council faces up to five years in prison. Gizmodo reports: According to the Justice Department, Council accessed the SEC's account using an attack called SIM swapping, in which a perpetrator uses social engineering to trick a phone carrier's customer service representatives into transferring an individual's phone number to a new device. Basically, they call into a support line and use pieces of personal information about a victim they have gathered online to convince the representative they are the person they are targeting. Once perpetrators take the number and can begin receiving text messages, they are able to reset the passwords of accounts on services like X. It is not really a "hack" in the traditional sense that they are not finding flaws in software but rather exploiting human trust.

Unfortunately for individuals like Council, all Bitcoin transactions are logged on a blockchain for anyone to see, leaving a trail of breadcrumbs for investigators to find. If he did make out with a lot of crypto, it would be hard to keep it hidden forever. Council allegedly did not post the message himself to the SEC's X account, but conducted the SIM swap and left the rest of the work to his co-conspirators who compensated Council in the form of, of course, Bitcoin. The price of the cryptocurrency rose by $1,000 after the fake announcement, according to the Justice Department, and fell by $2,000 after the SEC issued a correction. That could have led to a big windfall depending on how much Bitcoin the perpetrators held at the time.

Graphics

Nvidia's RTX 5090 Power Connectors Are Melting (arstechnica.com) 86

An anonymous reader quotes a report from Ars Technica: Two owners of Nvidia's new RTX 5090 Founders Edition GPUs have reported melted power connectors and damage to their PSUs. The images look identical to reports of RTX 4090 power cables burning or melting from two years ago. Nvidia blamed the issue on people not properly plugging the 12VHPWR power connection in fully and the PCI standards body blamed Nvidia.

A Reddit poster upgraded from an RTX 4090 to an RTX 5090 and noticed "a burning smell playing Battlefield 5," before turning off their PC and finding the damage. The images show burnt plastic at both the PSU end of the power connector and the part that connects directly to the GPU. The cable is one from MODDIY, a popular manufacturer of custom cables, and the poster claims it was "securely fastened and clicked on both sides (GPU and PSU)." While it's tempting to blame the MODDIY cable, Spanish YouTuber Toro Tocho has experienced the same burnt cable (both at the GPU and PSU ends) with an RTX 5090 Founders Edition while using a cable supplied by PSU manufacturer FSP. Plastic has also melted into the PCIe 5.0 power connector on the power supply.

Iphone

Apple Fixes Zero-Day Exploited In 'Extremely Sophisticated' Attacks (bleepingcomputer.com) 8

Apple has released emergency security updates for iOS 18.3.1 and iPadOS 18.3.1 to patch a zero-day vulnerability (CVE-2025-24200) that was exploited in "extremely sophisticated," targeted attacks. The flaw, which allowed a physical attack to disable USB Restricted Mode on locked devices, was discovered by Citizen Lab and may have been used in spyware campaigns; users are strongly advised to install the update immediately. BleepingComputer reports: USB Restricted Mode is a security feature (introduced almost seven years ago in iOS 11.4.1) that blocks USB accessories from creating a data connection if the device has been locked for over an hour. This feature is designed to block forensic software like Graykey and Cellebrite (commonly used by law enforcement) from extracting data from locked iOS devices.

In November, Apple introduced another security feature (dubbed "inactivity reboot") that automatically restarts iPhones after long idle times to re-encrypt data and make it harder to extract by forensic software. The zero-day vulnerability (tracked as CVE-2025-24200 and reported by Citizen Lab's Bill Marczak) patched today by Apple is an authorization issue addressed in iOS 18.3.1 and iPadOS 18.3.1 with improved state management.

The list of devices this zero-day impacts includes: - iPhone XS and later,
- iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later

Submission + - Nvidia's RTX 5090 Power Connectors Are Melting (arstechnica.com)

An anonymous reader writes: Two owners of Nvidia’s new RTX 5090 Founders Edition GPUs have reported melted power connectors and damage to their PSUs. The images look identical to reports of RTX 4090 power cables burning or melting from two years ago. Nvidia blamed the issue on people not properly plugging the 12VHPWR power connection in fully and the PCI standards body blamed Nvidia.

A Reddit poster upgraded from an RTX 4090 to an RTX 5090 and noticed “a burning smell playing Battlefield 5,” before turning off their PC and finding the damage. The images show burnt plastic at both the PSU end of the power connector and the part that connects directly to the GPU. The cable is one from MODDIY, a popular manufacturer of custom cables, and the poster claims it was “securely fastened and clicked on both sides (GPU and PSU).”

While it’s tempting to blame the MODDIY cable, Spanish YouTuber Toro Tocho has experienced the same burnt cable (both at the GPU and PSU ends) with an RTX 5090 Founders Edition while using a cable supplied by PSU manufacturer FSP. Plastic has also melted into the PCIe 5.0 power connector on the power supply.

Slashdot Top Deals