The Internet

As Reddit Stock Falls, CEO Questions Value of Google's AI Overviews 83

Reddit CEO Steve Huffman criticized Google's AI Overviews for summarizing publishers' content without delivering the traffic benefits of traditional search, arguing that users increasingly value Reddit's human perspectives and firsthand experiences. Ars Technica reports: First, there was a letter to investors (PDF), wherein Huffman spun his narrative about Reddit's value proposition and general strategic direction amid the proliferation of AI tools. He wrote: "As the internet becomes flooded with synthetic content, people are craving real human perspective. We are the antidote to an automated web. AI compresses the internet into summaries. Reddit delivers the opposite: deep discussions, passionate debates, and lived experiences. People don't want a summary of Reddit; they want Reddit."

The letter also said: "As AI makes information more abundant, the challenge is no longer finding content -- it's finding context, personal opinion, and first-hand accounts. Everything online feels flat, polished, generated, or sponsored, so consumers are overwhelmed and increasingly skeptical. We've never had more information, but we've never trusted it less."

And then, in comments around the earnings report, he added: "What we see is, 10 blue links has driven tremendous value and growth to the broader ecosystem... from where we sit, AI Overviews has yet to make a similar level of positive impact, and I think that's consistent across the broader landscape, right? As businesses, publishers, retailers, we're still looking for that win-win."
Reddit shares nevertheless fell more than 20 percent as investors worried that unstable Google referrals could undermine its growth, even after a strong earnings report.

Submission + - Why did OpenAI's and Anthropic's AI models hack other companies? 1

Tony Isaac writes: This is one of the more sane explanations I've seen, of what actually happened with the recent Anthropic and OpenAI hacking incidents. The NPR article describes how AI models from both OpenAI and Anthropic recently breached their testing environments and hacked external targets during cybercapability evaluations. Anthropic's incidents resulted from a configuration error with a sandbox provider that mistakenly granted models internet access, leading them to inadvertently hack real-world companies and upload malware when given fictional targets. In contrast, OpenAI's models deliberately exploited a zero-day vulnerability to escape their sandbox and cheat on an evaluation by accessing systems on Hugging Face. These unprecedented events have underscored the urgent need for tighter isolation protocols, stronger defensive guardrails, and clearer government oversight as autonomous AI cybercapabilities rapidly evolve.
Cloud

IT Teams are Spending 11 Hours a Week on Cloud Connectivity Problems (computerweekly.com) 20

Researchers found enterprises are spending time troubleshooting cloud connectivity due to increased AI workloads, reports Computer Weekly. More than 400 IT and infrastructure decision-makers (US and UK) were surveyed for internet/cloud/AI exchange operator DE-CIX by market researchers Censuswide. But despite 96% of respondents claiming their enterprise networks are ready for cloud/AI loads, the average IT team still spends more than 11 hours each week resolving cloud connectivity problems: Other leading concerns included downtime or reliability issues (26%), latency or slow performance (28%), and security vulnerabilities/DDoS attacks (27%). Cost of connectivity, staff expertise and lack of visibility/control over data flows were also cited as major challenges... As a result, as indicated in the study, many businesses are now turning to private interconnection, which enables enterprises to connect directly to cloud providers over dedicated infrastructure rather than routing traffic across the public Internet. Designed to deliver lower latency, greater resilience, enhanced security and more predictable performance, private interconnection has become an increasingly important way of supporting modern cloud and AI workloads. Specifically, the data showed that 61% of companies are already using private connectivity to clouds, while another 31% are actively considering it... [And 71% of enterprises with 1000 or more employees]

Only 8.62% of the smaller companies were spending 21 to 40 hours per week dealing with connectivity issues, while just 2.53% of the largest companies in the sample do. Summing up these findings, DE-CIX said that together they suggest direct interconnection is rapidly becoming a core component of enterprise cloud and AI infrastructure and a competitive advantage for companies, though optimising interconnection strategies clearly remains a pressing challenge for small and medium-sized enterprises... "Every AI application depends on data moving quickly, securely and predictably between users, clouds and AI infrastructure. Our research suggests that far too many enterprises are still spending valuable time trying to maintain that kind of connectivity, with more than a third spending between 11 and 20 hours per week, and just under one in 10 spending between 21 to 40 hours per week. This confirms what we already knew — that that network architecture can make or break AI adoption."

Elsewhere The Register reports that cloud infrastructure services "grew at their fastest for eight years during the second quarter of 2026, thanks to the AI craze and continued demand for flexible and scalable IT infrastructure." According to the latest figures from Synergy Research, enterprise spending on cloud infrastructure passed $143 billion in Q2, a year-on-year growth rate of 43 percent. This followed 11 successive quarters of increasing growth rates, during which the market has now doubled in size... "AI has, of course, driven most of that incremental growth, and we now see year-on-year growth rates of 165 percent for AI-specific cloud services...." And the top three global players continue to dominate the market, with Amazon Web Services (AWS), Microsoft Azure and Google Cloud together accounting for 67 percent of all the cloud revenue during the quarter. That percentage has increased since the third quarter of last year, when the triumvirate made up 63 percent of enterprise cloud infra spending.
The Internet

As New York Finalizes New Social Media Rules, US Senate Considers Nationwide 'SCREEN' Act (eff.org) 58

New York has finalized new rules that will govern social media apps in the state starting on January 25, 2027. The law prohibits social media platforms from sending notifications to minors between midnight and 6 a.m. without parental consent. And minors "will only be shown content from other accounts they follow or otherwise select in a set sequence, such as chronological order," rather than "the default algorithmically personalized feeds... unless they get parental consent for an addictive feed." (Social media companies "must offer at least one alternative method for age assurance besides providing a government-issued ID," the announcements points out, and any information used to determine age "must not be used for any other purpose and must be deleted or de-identified immediately after its intended use.")

But meanwhile, the EFF writes that a committee in the U.S. Senate is considering the SCREEN ACT, "a sweeping age-verification bill that would require online services to verify users' ages before they can access any sexually explicit content. If this bill passes, it will force millions of adult internet users to give up their anonymity, privacy, and security before they access lawful speech." Unlike many state-age verification laws — which have been harmful in their own right — the SCREEN Act has no requirement that a significant portion of the website consist of sexually explicit content that is harmful to minors. The bill requires nearly any service hosting even a single piece of sexually explicit content to verify the ages of its users. The result is that the bill would apply not only to adult content sites like PornHub or OnlyFans, but also streaming services like Netflix, and social media platforms like Reddit, Discord, or Bluesky, if they host any adult content...

Under the SCREEN Act, the "bouncer" will be a digital age-verification service that captures your personal information and saves it to a database for an unspecified amount of time. The consequences of the bill won't be limited to minors. If websites and apps are expected to reliably identify teenagers, adults will be asked to prove they are adults. Even worse, the SCREEN Act is a privacy and data security nightmare. One provision of the bill requires services to take reasonable steps to protect the data collected and to not maintain for longer than is necessary. But these are terribly weak protections that impose no meaningful collection, use, or retention limits on services collecting people's private information...

The SCREEN Act also targets virtual private network (VPN) users and providers. The bill requires covered websites to verify users' ages based on their IP addresses unless the service can determine that the user is outside the United States, and specifically requires age verification on traffic coming from known VPN addresses. In practice, this discourages the use of VPNs and proxy servers, which millions of people rely on for legitimate purposes such as protecting personal privacy, securing public Wi-Fi connections, safeguarding journalists and activists, and preventing data tracking...

The SCREEN Act creates onerous age-verification rules that will block adults from accessing lawful speech, curtail their ability to be anonymous, and jeopardize the data security and privacy of all internet users.

Bitcoin

Recovery Seeds Reportedly Breached for Coldcard Hardware Bitcoin Wallets, $75M Taken (nerds.xyz) 46

"A hardware wallet is supposed to be the safest place to keep Bitcoin," writes The Street, since it never connects to the internet, its keys never leave the device, and "the whole point is that an attacker would need to physically hold it to steal anything."

The problem is that anyone who can reproduce the recovery seed doesn't need to possess the COLDCARD, Nerds.xyz points out. More from The Street: [The recovery seed] is supposed to come from a hardware random number generator producing 128 bits of entropy, a number so large that guessing it is computationally impossible. It wasn't. According to Block's engineering team a single code change on March 1, 2021 caused the firmware to silently fall back to a software-based generator instead of the hardware one. On Mk3 devices the effective search space collapsed to roughly 40 bits. Coinkite has confirmed that figure and called it preliminary. The gap between 128 bits and 40 bits is not a matter of degree. It is the difference between a lock that cannot be picked and one that can be brute-forced by anyone with rented cloud computing....

Chainalysis found the attacker went after the largest balances first, pulling more than $30 million in the opening ten minutes. Within about 25 minutes, roughly 594 BTC had moved out of some 500 single-signature wallets. One victim lost around $1.8 million... Coinkite has shipped fixed firmware, but with a warning that matters more than the patch itself. Updating does not repair an existing seed. A seed created with weak entropy stays weak forever. Affected users have to generate an entirely new wallet on updated hardware and move their coins to it.

By Saturday morning Galaxy research was tracking 1,158.66 BTC, worth roughly $75.1 million, taken from 2,673 addresses, according to the article. And "The Coldcard exploit is ONGOING," Galaxy Research posted an hour ago on X.com. "Move Coldcard single-sig funds to safe locations immediately!" We have reported ~600 addresses we believe to be hackers holding funds stolen from Coldcard-generated weak entropy addresses to federal investigators, industry compliance firms, and cross-industry cyber investigators.
Thanks to Slashdot reader BrianFagioli for sharing the news.
United States

Hackers Targeted Municipal Water Systems In 7 States This Week, FBI Says (nbcnews.com) 47

An anonymous reader quotes a report from NBC News: Cyberattacks targeting municipal water systems have been reported in at least seven states this week, prompting the FBI and the Environmental Protection Agency to warn utilities nationwide that hackers are trying to disrupt critical water infrastructure. In a public service announcement Thursday, the agencies said water and wastewater utilities have reported incidents to the FBI, with some malicious activity degrading water operations. The announcement does not name the states.

The warning comes after hackers targeted more than 30 municipal water facilities in Minnesota in an attack that had hallmarks of Iranian meddling, according to a law enforcement official. It is still under investigation. A spokesperson for Minnesota's information technology services agency said Thursday there was no indication the breaches contaminated any municipal water supplies. The federal Cybersecurity and Infrastructure Security Agency said in a separate alert that some larger attacks on water infrastructure had "resulted in boil water notices and sustained manual operations," though it did not say where.

[...] The federal advisory said the malicious cyber actors, or MCAs, targeted specific brands of control systems used by municipal water utilities, though the FBI and the EPA urged operators of all systems to take precautions. [...] The agencies said the hackers remotely accessed internet-facing devices, changed IP addresses and passwords, and caused utilities to lose monitoring and control capabilities. The federal advisory calls on system operators to remove programmable logical controllers, or PLCs, from direct internet exposure by putting them behind secure gateways and firewalls; use strong passwords; and limit communications between authorized control system devices through access control lists.

AI

Anthropic Says Its AI Systems Broke Into Computers at 3 Organizations 64

Anthropic found that Claude models breached three outside organizations during cybersecurity tests because misconfigured environments accidentally gave them access to the internet. The company notified those affected and urged other AI labs to audit their own testing systems. The BBC reports: Anthropic said in a statement that it reviewed more than 140,000 tests to find evidence that Claude - its family of AI models - could access the internet from testing environments that were designed to be sealed off. The tests include so-called "capture-the-flag" evaluations in which Claude was tasked with obtaining information by breaching other systems - a common way that experts assess a model's hacking capabilities.

A "misconfiguration" on systems run by Anthropic and its testing partner left the models with live internet access, allowing them to breach other systems, the San Francisco-based firm said. Anthropic said the earliest incidents date back to April and that it is "approaching the fixes as if the responsibility were ours alone." Neither Anthropic nor the organizations that were breached had noticed the intrusions at the time.

Anthropic said it could have reviewed its records more thoroughly and added that the findings gave the firm "cautious optimism" that such risks can be overcome with more investment and tighter measures. "The broader lesson is not necessarily that AI has developed a fundamentally new attack capability," cyber security expert David Allott told the BBC. "Instead, it is that AI agents can combine capabilities, obtain credentials and system access to take actions autonomously, while adapting scope and scale at machine speed," he added.
The announcement comes just days after OpenAI said that its models had breached the systems of other companies, including AI tools platform Hugging Face.

Submission + - ICE Dismantles SIM Farms in Nationwide Operation (ice.gov)

An anonymous reader writes: Immigration and Customs Enforcement’s (ICE’s) Homeland Security Investigations carried out a nationwide operation between June 22 and July 10 that dismantled “SIM farms” run by transnational criminal organizations.

SIM (subscriber identity module) farms are systems containing large numbers of SIM cards from different wireless carriers, often housed in banks of cellphones, modems, or specialized devices known as SIM boxes.

These can be used to send and receive bulk messages or calls and often exploit voice over internet protocol (VoIP) technology to do so. Initially developed for legitimate purposes, the technology has become prominent among organized fraudsters targeting mass audiences through phishing texts, scam calls, and fraudulent online accounts.

The recent nationwide operation, dubbed Operation Signal Break, “dismantled critical command-and-control infrastructure used to perpetrate large-scale telecommunications fraud across the United States,” ICE said in a July 24 statement.

Authorities will now analyze the seized SIM data to identify victims and assess losses caused by such fraud. The illicit proceeds from the fraud, which are suspected to be linked to Chinese transnational criminal organizations and distribution networks, will be traced.

This is expected to support criminal indictments, sanctions targeting national and international infrastructure used in criminal activity, and asset seizures. SIM box operations are estimated to result in losses worth $15 million annually to Americans, according to ICE.

SIM box fraud, “also known as interconnect bypass fraud, is a scheme in which fraudsters reroute international calls to appear as local ones,” a Nov. 8, 2025, post from IT services provider Synaptique said.

For instance, when a foreign national calls someone in the United States, the call is diverted through VOIP to a SIM box in America instead of passing through a legitimate international call gateway. The SIM box then uses one of the local SIM cards to place a new local call to the recipient.

Encryption

Anthropic AI Model Finds Flaws in Tough-to-Crack Encryption Algorithms (nytimes.com) 32

Anthropic's Claude Mythos Preview has "found flaws in a weakened version of a digital encryption standard that is in pervasive use throughout the internet," reports The New York Times. Researchers said the model discovered novel attacks against weakened versions of AES and the experimental post-quantum HAWK system, including one that was 200 to 1,000 times faster than previous human-developed methods. From the report: The flaws identified do not concern a cryptographic standard currently in use today, which means that modern banking and communication systems are not subject to immediate potential intrusions from A.I. Instead, Anthropic's technology cracked a watered-down version of an algorithm for Advanced Encryption Standard, or A.E.S., a ubiquitous protocol that safeguards web traffic, wireless networks, data storage and more. It is common to perform tests on weaker versions of encryption algorithms to understand whether more powerful computers could someday crack the actual standards, akin to solving a simpler math problem to identify whether patterns may exist for a more complicated one. In the testing, Mythos was able to break the weaker version of Advanced Encryption Standard in a way that Anthropic said made an assault 200 to 1,000 times faster than what previous human research had managed to do. While the immediate ramifications are minimal, the long-term implications could be significant. In previous tests, large-language models seemingly could not match or best what humans can do in the mathematically dense field of cryptographic research, but their rapid advances could suggest a future in which top models can surmount traditional internet security protections that are foundational to just about everything that takes place on the internet.

[...] In addition to the attack on the encryption standard, Mythos also orchestrated another improved attack against a different digital cryptographic system known as HAWK that is designed to be bulletproof against both traditional and quantum computers. HAWK is not currently in use, but under consideration by the National Institute of Standards and Technology to become a new standard. The HAWK attack was validated by its authors, and independent cryptographers reviewed the Advanced Encryption Standard attack, Anthropic said, adding that it had shared its findings with the U.S. government and industry partners ahead of publication. Mythos devised the cryptographic attack on A.E.S. almost entirely autonomously, Anthropic said, but only after first refusing to contemplate the problem because it believed it was impossible to improve on existing methods of analysis. But after some coaxing, the chatbot sat with the puzzle for about a week before engineering its novel attack. Two human researchers then worked for nearly a month to verify that the method appeared correct.
"Given that we are constantly underestimating the power and time of availability of future models, are we really comfortable that two years from now strong encryption won't be threatened?" said Glenn S. Gerstell, the former general counsel at the National Security Agency.

"Mathematicians would tell you that it shouldn't be possible given current computing powers to break strong encryption in any meaningful time," added Mr. Gerstell, who helped write a report on cryptology in 2022. "But I don't think the capabilities of future models in the medium term -- before quantum computing or quantum-proof cryptography -- should be dismissed as trivial in this context."
Social Networks

Big Tech Accused of Stonewalling European Social Media Researchers (arstechnica.com) 53

European misinformation researchers say TikTok, X, and Meta are obstructing access to platform data required under the EU's Digital Services Act through rejections, restrictive quotas, costly APIs, and burdensome security demands. Although regulators have fined X and pushed platforms to improve access, researchers remain skeptical that the changes will provide reliable, reproducible data at scale. Ars Technica reports: In recent years, social media companies shut down public access tools like Meta's CrowdTangle and replaced them with content libraries, or, like X, paywalled their API data, forcing academics to pay "hundreds of dollars a month," said Duncan Allen, a research officer at Democracy Reporting International (DRI) in Germany. Researchers say that without API access, what Iamnitchi describes as the "black holes" in what society knows about how these platforms recommend content or handle reports regarding sensitive content will only grow. Others, like TikTok, cap how many posts any researcher account can pull each day, which Allen said can make it "impossible to study anything at scale."

The DSA was meant to solve this by allowing vetted researchers at credible institutions to have access to API data if they could show it would help in studying systemic risks, from illegal content to threats to fundamental rights. But two years after the law took effect, researchers say they struggle to meet its security requirements and face narrow interpretations from platforms of what qualifies as a systemic risk. Application forms differ by platform, but most require data to be stored on infrastructure that cannot be compromised -- such as a machine physically disconnected from the Internet -- a resource most universities lack, [said Adriana Iamnitchi, chair of computational social sciences at Maastricht University in the Netherlands, who leads research into online disinformation campaigns.]

Even for researchers who secure approval, "there's no guarantee that the data is good," said L. K. Seiling, coordinator of the DSA40 Collaboratory, a German initiative that tracks 46 DSA applications. API data is often difficult for a colleague to reproduce, so a researcher's work cannot be checked for errors, which Iamnitchi said is a "basic requirement of science." DSA40 data shows that of 46 tracked applications, 20 were approved and 14 rejected. But approval rates vary widely: TikTok approved 11 of 13 applications, while X rejected 11 of 23. The true rejection rate is likely higher because the tracker relies on voluntary reporting, Seiling said. "There's no structured advantage for researchers to use this pathway," Seiling said. "Data access as it's set up right now tries to disincentivize researchers."

Movies

2.1 Million People View Leaked 'Odyssey' Bootleg on X (variety.com) 66

Variety reports: "The Odyssey" leaks have begun, as a high-quality bootleg of the film reached millions of people on X thanks to a viral tweet on July 25. At 2:25 p.m. PT, a post on X reading "Someone uploaded 'The Odyssey' full movie on X. Can you believe it?" amplified a message from a now-suspended account. The message included a high-quality version of the film, as confirmed by Variety, and climbed to over 2.1 million views within two and a half hours. By that time, the streaming film was replaced by a takedown notice, and then the account was suspended...

As of July 26, a few clones of the bootlegged film are available on X, but they've been mostly flooded away by mislabeled files promising "The Odyssey" but actually showing a Rickroll, the longtime internet prank of tricking people into watching the music video for Rick Astley's 1987 song "Never Gonna Give You Up."

The article notes the leak "certainly doesn't seem to have hurt the film's still-surging box office in its second weekend, during which it earned another $87 million," or lessened demand for Imax 70 mm tickets.
DRM

Google's Anti-search-scraping Lawsuit Dismissed (computerworld.com) 22

A U.S. district court "has dismissed Google's case against SerpApi over that company's scraping of search results to train AI models," reports Computerworld. Google had claimed that it was protecting copyright holders — and that SerpApi's actions breached America's Digital Millennium Copyright Act (DMCA): [Google] made two claims: first, that no person shall circumvent a technological measure that effectively controls access to a work protected under this title, and second that no person shall manufacture, import, offer to the public, provide, or otherwise traffic in any technology, product, service, device, or component protected by the Act. SerpApi claimed that the URLs and other links that were being served by Google did not in themselves entail copyright and the judge agreed. In her judgment, she said that there was no indication that the copyright holders had authorized Google to take action against SerpApi.

The case is not completely over as the judge has given Google 21 days to amend its complaint to demonstrate that it was acting on behalf of the copyright owners.

SerpApi's CEO reacted to the court's ruling as "a win not just for SerpApi, but for all who depend on an open internet. We're pleased that the court rejected Google's attempts to expand the DMCA to assert control over access to public pages. The internet's founding principle — open access to usable information — is essential to driving innovation and ensuring everyone benefits from the promise of data. SerpApi will continue supporting developers, AI companies, researchers, and businesses that rely on access to public search information."

Some analysis from Daring Fireball blogger John Gruber: I've come around on SerpApi in the last few months. My initial take was that it surely must be illegal for a company to scrape Google's search results and offer access to that data as an API. But I've come around to the argument that what SerpApi is doing to obtain Google search results is, well, exactly how Google scrapes the rest of the entire web to build its search index. It's all just scraping publicly accessible web pages. This December piece by Mike Masnick at Techdirt is what began to change my mind.
In fact, Masnick wrote, Google "built its entire business on scraping the web without asking permission first. And now it wants to use one of the most abused provisions in copyright law to stop others from doing something functionally similar to what made Google a tech giant in the first place."

Now Google is even getting heckled about the decision on social media. "If Google wants to refile the suit within the allowed 21 days, it has to admit that site owners have copyright protection of their work and THAT would open the door to them suing Google for scraping their content for AI Overviews."
Google

Top Online Sites Debate Cutting Off Google's Crawlers (futurism.com) 47

Futurism reports: [Some online publications] are now debating whether to cut Google off entirely, as the Wall Street Journal reports, illustrating an increasingly fraught relationship between the tech giant and the publishers that are creating content its AI models are regurgitating. According to the newspaper, prominent outlets including USA Today, Politico, the Economist, People, and Reuters are all reexamining their relationship with Google. Some are debating whether to continue to work with the tech giant at all... Even Reddit executives are reevaluating the company's $60 million-a-year contract that allows Google to train its AI models on user-submitted content on the platform. They've similarly watched as Google's AI features discourage users from navigating to Reddit...

Beyond pondering whether to cut Google off, other publishers have resorted to suing the company, accusing it of illegally rehashing their intellectual property via AI summaries. It's an extremely undesirable position for publishers. By severing ties with the search giant, they could face even steeper declines in traffic. At the same time, there's seemingly little to gain from having Google's AIs crawl their content — and in the long term, it could guarantee their destruction.

Two interesting data points from the article:
  • "Last month, Cloudflare CEO Matthew Prince noticed that automated bot traffic had overtaken human traffic for the first time in the internet's history."
  • "USA Today has seen its traffic from US users drop by almost half over the last year."

The Almighty Buck

Roku Raises Prices of Streaming Devices By Up To 60% (thedesk.net) 13

Roku has raised prices on several streaming devices, blaming memory and component shortages tied to the AI data-center boom. The Roku Ultra jumped from $100 to $150 and the basic Streaming Stick rose from $30 to $40. The Desk reports: In a phone call with The Desk on Friday, a Roku executive said the company made the tough decision to raise prices on its streaming hardware to address shortages in computer memory and other components caused by the artificial intelligence rush. [...] Still, the executive who spoke with The Desk on Friday said the company believes its hardware is still competitive against other streaming TV hardware because Roku devices are still priced aggressively compared to the Apple TV and other expensive streaming hardware, and the company remains focused on looking at ways to add value to its Roku platform before and after it enters a customer's home. "We are doing our best to have great deals like what we have going on right now," the executive said. "Roku is even upping the price for a bundle that includes a Streaming Stick Plus and a one-month subscription to Fox One," notes Ars Technica in a separate report.

"As recently as July 20, Roku listed the bundle at $60 with a sale price of $25, according to the Internet Archive's Wayback Machine. Now, the bundle carries an $80 MSRP and $45 sale price."
Businesses

Stripe Eyes $10 Billion Deal For AI Model Marketplace OpenRouter (pymnts.com) 18

An anonymous reader quotes a report from PYMNTS.com: Stripe is in talks to buy OpenRouter, an artificial intelligence (AI) startup that could sell for roughly $10 billion, according to The Wall Street Journal. The move would mark a significant step outside payments for a company that processes transactions for much of the internet. It also lands while Stripe pursues a far larger target: a bid for PayPal that would value the payments giant at about $53 billion.

The Journal reported Thursday (July 23) that a transaction could be announced soon, though the talks could still collapse or another buyer could step in. The exact price under discussion could not be learned. Several other large technology companies had also been weighing deals for OpenRouter. The startup was valued at $1.3 billion in May, according to PitchBook, meaning a sale near $10 billion would represent a steep markup in a matter of months. Its backers include Menlo Ventures and CapitalG, the growth fund of Google parent Alphabet.

OpenRouter sells software that lets customers reach AI models from OpenAI and Anthropic, along with open weight alternatives anyone can download and run. The Journal described the company's position this way: "OpenRouter is part of an emerging crop of startups that have found a lucrative niche between AI developers and the companies that want to use them." The platform lists hundreds of large language models and lets developers compare and switch between them.

Submission + - Stripe Eyes $10 Billion Deal for AI Model Marketplace OpenRouter (pymnts.com)

An anonymous reader writes: Stripe is in talks to buy OpenRouter, an artificial intelligence (AI) startup that could sell for roughly $10 billion, according to The Wall Street Journal. The move would mark a significant step outside payments for a company that processes transactions for much of the internet. It also lands while Stripe pursues a far larger target: a bid for PayPal that would value the payments giant at about $53 billion.

The Journal reported Thursday (July 23) that a transaction could be announced soon, though the talks could still collapse or another buyer could step in. The exact price under discussion could not be learned. Several other large technology companies had also been weighing deals for OpenRouter. The startup was valued at $1.3 billion in May, according to PitchBook, meaning a sale near $10 billion would represent a steep markup in a matter of months. Its backers include Menlo Ventures and CapitalG, the growth fund of Google parent Alphabet.

OpenRouter sells software that lets customers reach AI models from OpenAI and Anthropic, along with open weight alternatives anyone can download and run. The Journal described the company’s position this way: “OpenRouter is part of an emerging crop of startups that have found a lucrative niche between AI developers and the companies that want to use them.” The platform lists hundreds of large language models and lets developers compare and switch between them.

The Internet

Verisign Is Finally Bringing .web Domains To the Internet (nerds.xyz) 52

BrianFagioli writes: Verisign is finally bringing web domains to the internet after a decade of fighting. Verisign says the .web top-level domain has finally been delegated into the DNS root, clearing the way for public registrations later in 2026. Until now, consumers could not buy normal working .web domains, despite the extension attracting a record $135 million winning bid in 2016. The launch could make .web one of the more recognizable alternatives to .com, but Verisign already operates both .com and .net, raising questions about whether this creates real competition or simply gives the dominant registry operator another valuable extension. The decade-long fight began after a company called Nu Dot Co won the rights to operate .web in a 2016 ICANN auction with a record $135 million bid secretly funded by Verisign. Rival bidder Afilias, which was later acquired by Donuts, challenged the sale, arguing ICANN should have investigated the relationship before allowing the auction. This triggered years of complaints, reviews, and legal disputes that have ultimately now been resolved under undisclosed terms.
Television

LG To Ban Residential Proxies From Smart TV Apps (krebsonsecurity.com) 53

An anonymous reader quotes a report from KrebsOnSecurity: The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV. On July 2, [KrebsOnSecurity] featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur found more than 42 percent of apps available for download on LG smart TVs include SDKs that turn one's television in a proxy node indefinitely, and that more than a quarter of the apps made for Samsung's Tizen operating system had similar residential proxy components.

Responding to questions about Spur's research, LG Senior Vice President John Taylor told KrebsOnSecurity the company was working with app developers to remove the residential proxy option from their apps on the webOS platform. Developers that fail to comply, he said, will find their apps suspended. "A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor said. "If this option is not removed, these apps will be suspended." Taylor said LG is committed to keeping residential proxy networks out of its smart TV apps going forward, and that the company's review of those apps is "well underway now."

"As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs," Taylor wrote in an emailed statement. [...] "A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight," Spur's Trevor Sutter wrote. "The risk is amplified when consent comes from individuals within the household who use the device but shouldn't give consent, such as minors."
LG is also facing criticism for monitors that automatically install software promoting paid McAfee subscriptions through Windows Update without user approval.

Submission + - LG to Ban Residential Proxies from Smart TV Apps (krebsonsecurity.com)

An anonymous reader writes: The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV. On July 2, [Krebs on Security] featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur found more than 42 percent of apps available for download on LG smart TVs include SDKs that turn one’s television in a proxy node indefinitely, and that more than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components.

Responding to questions about Spur’s research, LG Senior Vice President John Taylor told KrebsOnSecurity the company was working with app developers to remove the residential proxy option from their apps on the webOS platform. Developers that fail to comply, he said, will find their apps suspended. "A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor said. "If this option is not removed, these apps will be suspended." Taylor said LG is committed to keeping residential proxy networks out of its smart TV apps going forward, and that the company’s review of those apps is "well underway now." "As part of our ongoing efforts to enhance platform quality and the user experience, LG will continue to strengthen our evaluation process for developer-submitted apps, including those that incorporate residential proxy SDKs," Taylor wrote in an emailed statement. [...] “A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight,” Spur’s Trevor Sutter wrote. “The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors.”

Books

AI Companies Are Buying Tons of Old Books Because They're Free of AI Slop (404media.co) 114

An anonymous reader quotes a report from 404 Media: As AI companies search for more training data to improve their models, one company is offering old, printed books as an ideal source because they are guaranteed to be free of the very AI slop AI companies are producing. "The world's best AI training data is sitting on a shelf," ISBNdb, a company that produces what it claims is "the world's largest book database," and that offers high-volume book acquisition services for AI companies, says on its site. "Books represent curated, peer-reviewed, domain-specific human knowledge, structured in a way no web crawl can replicate. Dense, edited, authoritative."

In one article on its site, ISBNdb explains that printed books published before 2022 are ideal for AI training data because they don't include AI generated text. As the article correctly notes, much of the data that AI companies can scrape from the internet today is likely to include AI generated text, which could result in "model collapse," a process by which AI models that are trained on AI generated data results in worse models that are more prone to errors. The article also notes that book authors who object to their writing being scraped for training purposes can now easily poison AI models by producing writing designed to manipulate and sabotage the resulting AI models.

"Print books from the pre-LLM era are structurally guaranteed to be free of this contamination. That alone is a significant advantage [...] "Physical books published before this date [pre-2022] are structurally clean of modern poisoning tools." [...] ISBNdb advertises that it can keep the identity of AI companies secret. "Strict NDA [non-disclosure agreement] on every engagement," ISBNdb's site says. "Every project begins with a legally binding non-disclosure agreement. Your identity, strategy, and acquisition targets are never disclosed." ISBNdb notes that AI companies may not want to be caught destroying printed books during the scanning process. "The optics problem is real," ISBNdb's site says. "'AI company destroys two million books' is not a headline that generates sympathy."

Slashdot Top Deals