Businesses

Stripe Buys AI Startup OpenRouter For $7.5 Billion 24

Stripe is acquiring AI model marketplace OpenRouter as it pushes beyond payments into the infrastructure behind AI applications. According to The New York Times, the deal is reportedly valued at about $7.5 billion, with $1.5 billion allocated to OpenRouter's founders. Less than three months ago the company was valued at about $1.3 billion. CNBC reports: OpenRouter has become popular with developers seeking to use AI models, particularly those considered non-proprietary and available for free. Many of these so-called open-weight AI models stem from Chinese labs like DeepSeek and Z.ai, which have gained steam among developers for generally being more cost-efficient relative to proprietary AI models from U.S. companies like OpenAI and Anthropic.

In a blog post about the deal, Stripe noted that it's been working with companies to "optimize their token costs and route tokens efficiently," referring to a kind of metric used to measure AI model usage. Stripe said it's difficult to manage AI costs relative to performance because of the rapid "pace at which models are released and repriced." [...]

OpenRouter said in a blog post that combining with Stripe will help with its overall vision of "a healthy AI ecosystem where many models thrive, where AI neurodiversity is a strength, where a lab or an inference provider with a breakthrough can reach millions of developers, and where no single model becomes the default by inertia."
"Stripe is building the economic infrastructure for AI, and together with OpenRouter we'll help businesses maximize profitability by routing their requests intelligently and spending their tokens efficiently," Stripe CEO Patrick Collison said in a statement.
Music

Top Album Releases Linked To Rise In Fatal Crashes (theguardian.com) 85

An anonymous reader quotes a report from The Guardian: The release of a new album by Taylor Swift might be a cause for celebration among her fans, but such events have also been linked to a more sombre phenomenon: an increase in fatal car crashes. The team behind a new study say it sheds light on the impact of distracted driving. Writing in the journal Jama Network Open, [Vishal Patel, first author of the study based at Harvard Medical School] and colleagues report how they focused on the release of 10 major albums, launched between 2017 and 2022, selected for having the highest number of Spotify streams over a single day. [...] The team found streaming volume for the top 200 songs in the US was 43% higher on the date of major album releases compared with the days surrounding the releases -- although such data does not reveal whether the music was being streamed in a car.

[...] The researchers used data from a population-based registry of fatal US motor vehicle crashes to look at the number of traffic fatalities on the dates these albums were released, as well as for the 10 days either side. After taking into account the day of the week upon which the album was released, as well as federal holidays, and time of year, the researchers found the number of US traffic fatalities showed a relative increase of 15.1% on the date of major album releases, compared with similar days either side. "This is equivalent to approximately 182 fatalities in the US attributable to the release days of the 10 included albums," the team writes.

Patel said the release of a new album could distract drivers because accessing music is a search task, not a single button press. "You unlock the phone, open the app, find the release, read down a tracklist, tap the right song. That's several seconds of looking at a screen," he said, adding unfamiliar music also demands more attention, while research has suggested listening to new, high-energy music measurably degrades driving performance. The researchers add the rise in traffic fatalities was greater among certain groups -- such as younger drivers, male drivers, people who were driving alone, and people driving cars with a built-in infotainment platform. The authors say the results suggest that "online music streaming through smartphones may significantly contribute to distracted driving and traffic fatalities."

Moon

China's Moon-landing Plans And Why the US Is So Worried (cnn.com) 165

"We are in a 21st century space race," U.S. Senator Ted Cruz has said. And this week CNN noted a competition that for decades loomed in the background of geopolitics "is now roaring to the forefront," with China "demonstrating rapid advances in space technology" while the U.S. is "ratcheting up rhetoric about a looming battle for control of the cosmos." It's the fact that China plans to build a permanent settlement on the moon by 2040 that has prompted an urgent response from [U.S.] lawmakers... They've declared a new space race, and NASA is pledging to build a lunar outpost of America's own.... Both the United States and China plan to send robotic explorers to the south pole later this year, paving the way for human explorers to follow close behind.

The US is relying on the private sector to develop and build low-cost, exploratory robotic landers... Meanwhile, China is aiming to launch its robotic Chang'e-7 mission as soon as this month. The complex endeavor will seek to use four different robotic vehicles — an orbiter, lander, rover and mobile "hopper" — working in tandem to attempt to gather unprecedented data. The effort will include tools to drill for and directly analyze water ice, a feat that the US will only attempt with robotic missions slated for next year at the earliest. "If lunar water ice is successfully located, it could significantly reduce the cost and time required to transport water from Earth, facilitating the establishment of a human base for long-term activities on the moon and enabling further exploration of Mars or deep space," Tang Yuhua, the deputy chief designer of the Chang'e-7 mission, said in a 2025 interview with state media.

The oncoming flurry of south-pole-centric activity, with few established international laws to govern the outcomes, is heightening the drama of this rivalry... But with a much more ambitious goal — a future in which people attempt to flourish within permanent settlements rather than just visit the moon — the stakes of this new space race are even higher, according to Clayton Swope, the deputy director of the Aerospace Security Project at the Center for Strategic and International Studies, a bipartisan nonprofit. "The long-term vision will take generations to execute on," Swope said. "But in my mind, it's a scenario where there are people being born, people dying, their families, children growing up in a place that is not Earth — so that looks a lot like a city, more than it looks like an expedition to the south pole." If such a future comes to fruition, Swope added, his hope is that such extraterrestrial colonies would be governed by rules reminiscent of Western ideals and democratic principles. Whether China would be on the same page is an open question.

China is already fine-tuning its plans for a lunar settlement, CNN writes: The country envisions the International Lunar Research Station, or ILRS, as a sprawling science-focused facility on the moon's surface that can be operated robotically, "with the prospect of subsequent human presence," according to a government's ILRS website. China could partner with Russia to build a massive nuclear reactor to power the base, though questions remain regarding how the war in Ukraine may impact Russia's ability to deliver... China and Russia were mapping these plans long before the US announced its own intention to build a nuclear reactor on the moon last year and detailed its plans for a lunar settlement spanning hundreds of square miles... Who will write the rules? And how, exactly, will the use of lunar resources be policed on the international stage?
Meanwhile, NASA "still does not have a vehicle capable of getting astronauts down to the lunar surface," the article points out: Returning to the moon is not as simple as repeating Apollo. The space agency cannot — and does not wish to — replicate its 20th century lunar-landing success. The supply chains, skilled machinists and factories that built Apollo's rockets, landers and command modules no longer exist. And while the Apollo landings stuck close to the lunar equator, landing near the south pole is substantially more complex and requires more powerful vehicles.... China, meanwhile, has been laser focused on its lunar exploration program since 2004, using its top-down, central planning system to keep resources flowing toward specific goals.
United States

Flock's 'Creepy Cameras' Remain Major Threat to Privacy Despite Small Recent Changes, Warns ACLU (aclu.org) 35

While Flock announced changes for its AI-powered traffic cameras, "Several of the proposed changes Flock is touting are merely retreads of previous ," complains the American Civil Liberties Union. "Flock's latest announcement still appears more focused on addressing a perceived PR problem than the significant harms its products create... [T]his is hardly the step forward Flock wants us to think it is "

The ACLU continues to urge that default retention periods be shortened to 48 hours — not one week. And they warn Flock allows longer retention to any police department that asks for it, or when police officers activate "Evidence Mode" (the scope of which is not yet clear): Even if "Evidence Mode's" data retention hold only applies to hits returned on a given search, it would still retain significant amounts of location data on persons and vehicles who law enforcement do not suspect have engaged in any wrongdoing...

Flock claims that its changes will provide "more local control," meaning local police can decide what types of offenses other Flock customers can search their data for... This is not new. Flock has attempted this before, and the security measure failed because users were easily able to circumvent the system's requirement that police input the purpose of their search. For example, on June 12, 2025 Flock started claiming its new "Proactive Search Term Tool" would block any "impermissible" searches, such as abortion-related searches in states like Illinois that prohibit sharing reproductive healthcare data. But police officers quickly realized they could just input "investigation" or even "hehehe" as a search reason and it would be approved. Flock later switched from an open text box to a drop-down menu of reasons, but that just offered police a list of acceptable purposes they could choose from, whether it was accurate or not. Until Flock demonstrates they can develop a reliable, workable system to prevent improper searches, this promise of local control provides nothing more than a false sense of security...

While providing "Audit Assistance" to all departments makes sense, there is no evidence that the tool works consistently to address what the Washington Post observed is a growing pattern of police officers turning Flock into a personal stalking tool. While dozens of officers have recently been arrested, fired, or otherwise disciplined for misusing Flock for personal reasons, Flock claims these arrests are proof its auditing tool works. However, unless we know the number of officers misusing the system, we cannot conclude if Flock and its auditing tools are catching 95 percent of violators or 5 percent. Flock needs to have its auditing tool analyzed by an independent evaluator to determine its actual effectiveness. Until then, we don't know if the tool is a real security measure or just window dressing.

Perhaps the oddest part of Flock's announcement is its claims that "now every search will require" police to input a case code... While claiming that a "search without a reason is a search that shouldn't happen in the first place," Flock's announcement fails to note how easily users have circumvented "search reason" security measures in the past... This leaves the public wondering how making an ineffective voluntary security measure mandatory will improve its functionality.

Flock's "nearly $1 billion in venture capitalist funding has locked it into an operational model that seeks to trade our privacy for massive profits," concludes the ACLU's statement, as they promise to continue "The ACLU is fighting alongside communities to cancel local ALPR contracts and push lawmakers to protect our rights from this surveillance nightmare..."
Twitter

Bluesky's Active User Base Shrinks 52% Over 18 Months, But Its Protocol is Spreading (techcrunch.com) 74

An anonymous reader shared this report from TechCrunch: According to data from digital intelligence provider Similarweb, Bluesky's mobile app had 10.4 million monthly active users worldwide in June 2026, down 27.2% year-over-year. In addition, mobile daily active users continued to decline, falling 25.6% year-over-year in July to around 3 million... Bluesky's app has lost more than half its monthly active users from its late-2024 high... Its quarterly average was around 22.1 million monthly active users in the fourth quarter of 2024, Similarweb's data indicates, and it declined to 10.7 million in the second quarter of 2026. That's a decline of around 52%.

While Bluesky's numbers are down, those who stuck around are committed. Its smaller community remains relatively active, with a stickiness rate (the ratio of daily to monthly active users) of roughly 29% in June, about the same as Threads.

For Bluesky's new CEO, Toni Schneider, these numbers may not be as concerning. The company is not entirely focused on making Bluesky (the app) succeed, but on making it possible for the underlying protocol (AT Proto) to power a growing number of social apps, services, and communities. That's something that is now taking place, as projects like BlackSky and Eurosky are growing, while some AT Proto apps like the video-focused Skylight have found early traction, too. In addition, the company has launched new products, like the AI-powered research tool Attie, and is now working on adding support for private data to Bluesky. The latter could generate new interest in Bluesky from a different type of user — those less interested in the public square, and more interested in private networking and communities.

But on Threads in July of 2026, daily active users were up 21.3% year-over-year to 147 million, the article points out, and website visits were up 112% year-over-year to 471.6 million. And Threads now appears to have roughly 66% more monthly active users than X.
AI

Anthropic Discovers AI Agents Given Conflicting Instructions Soon Tried to Sabotage Each Other (yahoo.com) 70

When Anthropic instructed three agents to migrate a Python backend, but telling each agent to perform the migration in a different language, "We consistently saw a multiagent turf war," they wrote Thursday: All of the models we tested quickly assumed that others were purposefully impeding their work, and began to sabotage others while protecting their own contributions. In fact, they sabotaged others with increasingly aggressive, self-replicating malware. This included disabling the Unix accounts of the other agents, writing automated scripts that found and killed competing processes on a loop, and deploying malicious code that was disguised as belonging to another agent.

In many runs, one agent settles the conflict by force via access-revocation (e.g., sudo/group removal, account lock, nologin, SSH denial). In others, some agents settle into passivity: they give up and refuse to escalate further.

Agents sometimes manage to communicate their goals and coordinate: they recognize others' motivations as conflicting directives rather than hostility, and subsequently break out of the conflict loop in order to stop escalating indefinitely. In many of these successful episodes, they write commit messages or markdown files apologizing for malicious behavior and coordinate a truce. They clean up their malicious code, clarify the nature of the conflict, and ask for a human to intervene...

In several episodes with Mythos 5, we observe an emergent behavior where the agents propose and run a tournament for application performance in each language. In the example above, the Rust agent strategizes about bake-off metrics that appear neutral enough for the others to agree to this mechanism, yet would likely favor Rust: one thinking trace warns to be "careful not to be seen as metric shopping". Ultimately, the Golang/TypeScript losers gracefully concede codebase ownership to the Rust agent, giving up on their original user directives under their self-negotiated commitment device.

One problem is that AI agents do reward hacking, Anthropic notes, while current institutions "are designed by and for people, resting on assumptions about the sufficiency of oversight at human speed... As autonomous agents become more and more prevalent in the world and operate in ever-more demanding settings, it is crucial that they learn how to effectively coordinate."

In addition to everything else, the agents struggled with a lack of clearly defined hierarchy, Anthropic points out. "Nothing above suggests that these failures are permanent — but nothing suggests they will fix themselves, either..." They argue a fix "takes two forms: environments that exert the kinds of social pressure that evolution exerted on us, and social computing systems redesigned for actors that can self-replicate and self-improve. These are open problems in interaction and mechanism design, and our experiments here provide early evidence that new solutions are necessary."

"The AI models being tested in this case were Sonnet 4.6, Sonnet 5, Opus 4.6, Opus 4.8, Mythos Preview, and Mythos 5," notes Business Insider, adding that Sonnet 4.6 and Opus 4.6 "were the most combative, settling about 60% of their runs by force instead of truces or passivity."

Anthropic argues there's a clear case for researching this phenomenon — especially since "The volume of agent-agent interaction could plausibly exceed that of human-human and human-agent interactions before the world understands the conditions for making such interactions go well."
Twitter

X Open Sources Its Ranking and Filtering Algorithms (techcrunch.com) 57

An anonymous reader shared this report from TechCrunch: X is significantly expanding its open source codebase, which includes the app's "For You" algorithm and its core ranking engine, and adding a feature that will let users see if their account or posts have been impacted by any of its ranking systems, the social network said on Thursday. The company is making the source code for the "For You" timeline, the default feed you see when you open the app, available on GitHub under the Apache v2 license. It's also expanding its previous efforts to open source parts of its codebase to add more detail, including the model configuration, filter, and core ranking system details. That means it includes the parameters used to weight different signals — key to understanding which posts are actually displayed. This also makes the codebase roughly 10 to 15 times larger than it was before.

"You'll get the core ranking code that pulls posts and ranks them for any given user and assembles the feed," X's VP of Product Keith Coleman told TechCrunch in an interview ahead of the announcement. "You can see the systems that filter out potentially problematic, rule-violating content...And some of those systems, like the ranker and the score, you can even run yourself outside the company."

"This is the kind of thing that I think people will be fairly shocked that we are releasing," he added.

In addition to the repository, X is providing tools that will let users see for themselves if and how X's ranking systems have impacted their account or posts. A new transparency tool is rolling out to an "Under the Hood" page in the app's settings, which will let users who have posted 10 or more times over the past month download their aggregate stats as a JSON file. The file will show if any labels have been applied to their account or posts over the past calendar month.

X's VP of Product told TechCrunch that X engineers will consider pull requests. "That would be amazing to have people submitting code that improves the algorithm...I mean, how cool would it be for the X algorithm to be not just visible to the public, but also, like, by the public?"
AI

Why Are Big Tech CEOs Writing Long Manifestos About AI? (bbc.com) 51

This week Meta CEO Mark Zuckerberg published a 6,500 word open letter titled "The Future is for Everyone".

But the BBC is more interested in why big tech executives keep writing manifestos about AI: [Zuckerberg's] vision echoes what AI leaders have expressed in various forms: the product they are building is among the "most important technologies in history." Marc Andreessen, co-founder of early web titan Netscape, perhaps started this trend in 2023 with a 5,000-word essay he called "The Techno-Optimist Manifesto", which argued innovation was the way to solve life's problems...

As the International Monetary Fund warns AI could affect nearly 40% of jobs and worsen global financial inequality, Zuckerberg says he believes there will be an abundance of jobs in the future. "I do not understand why anyone who believes that AI will eliminate most jobs and much of humanity's relevance would rush to build that future." Never mind that Zuckerberg's Meta has cut 10% of its global workforce — about 8,000 jobs — as the company reorganizes to focus on AI.

Zuckerberg's manifesto is the latest to land in our social media feeds in an effort to put a positive spin on AI. In 2024, ChatGPT-maker OpenAI boss Sam Altman released a manifesto called "The Intelligence Age", a sweeping expression of optimism about the tech's potential... That same year, in a manifesto titled "Machines of Loving Grace", Anthropic CEO Dario Amodei touted the potential of AI to transform everything from healthcare to politics.

So what's going on with these tech executives' manifestos? Economics blogger Noah Smith suggested to the BBC "they all feel like it's such an important moment that it's incumbent upon them to do whatever they can to shape the direction that this technology is going." Although he does see some value in their engagement with important issues. "Should we open-source something that has the ability to kill humanity? If you don't take that seriously, you're just a fool."

But Rob Lalka, a business professor at Tulane University, had a different explanation for the BBC: Lalka said the timing of Zuckerberg's manifesto coincides with rising anger over AI's impact on everything from jobs to the environment.

And while tech journalists and academics might pore over them trying to glean nuggets of meaning, these executive manifestos are not necessarily landing with the general public. "They're trying to make the case that the positives will far outweigh some of those negatives that the public backlash is pointing out," he said. "But I think a lot of the reasons for optimism are still yet to be seen."

Data Storage

PBS Station Fears Losing 50TB of Data After Being Ghosted By Cloud Provider (arstechnica.com) 101

An anonymous reader quotes a report from Ars Technica: After its cloud storage provider went defunct, a PBS affiliate decided to sue a data center provider to regain access to 50TB of TV shows, videos, and other data dating back 70 years. As reported this week by Current, a trade newspaper covering public broadcasting, St. Louis affiliate Nine PBS filed a lawsuit against Iron Mountain Data Centers on July 28, seeking access to the data. In the litigation filed in Denver District Court, Nine PBS says that its cloud storage provider, Open Source Storage (OSS), used one of Iron Mountain's Denver data centers to store the channel's data. However, OSS is being unresponsive, and Nine PBS says Iron Mountain has refused to release its data.

The data in question includes the station's coverage of the COVID-19 pandemic, East St. Louis' history, The Great Flood of 1993, and over 11,000 files, The Denver Post reported in July. The lawsuit claims that "most" of the data is "unique and irreplaceable," according to the Post. Last month, a judge blocked Iron Mountain from deleting or modifying the data.

In a hearing on Wednesday, a judge ruled that Iron Mountain must hand over any physical devices holding the data, Current reported today. The judge also said that Nine PBS must find a third party, such as a former OSS worker, who can help retrieve the data within 30 days and without sharing or corrupting data belonging to other OSS clients. Nine PBS is already communicating with a former OSS employee "who is willing to help," the report said. If complications arise, such as from the data being encrypted, another hearing will be scheduled. Nine PBS and Iron Mountain must provide updates by September 14.
Iron Mountain's spokesperson said the company only provides physical infrastructure, such as the building, network connectivity, power, and environmental controls. "Our customers rent space for their servers and other hardware. These are the client's assets. We don't have access to the data on the hardware/servers because they belong to our customers," the company said.

If it granted "unauthorized access to third-party hardware without a court order," Iron Mountain said the company would violate basic data privacy protocols, breach its contract with OSS, and "potentially [expose] confidential data belonging to other clients of OSS."
Google

Judge Orders Google To Make Rival App Store Installs Easier (theverge.com) 38

A federal judge has ordered Google to remove what he called "anticompetitive friction" that makes rival Android app stores harder to find and install. The order is part of the remedies stemming from Epic's antitrust victory, which already requires Google to carry competing app stores inside Google Play and give them access to its app catalog. The Verge reports: It's been nearly three years since a jury unanimously decided that Google had an illegal monopoly over Android apps, and almost two years since Judge James Donato decided the best way of undoing that monopoly would be to crack open Android app distribution. Donato ordered Google to carry rival Android app stores inside its own Google Play Store, and to provide rivals with complete access to Google's full catalog of apps, for several years.

But Epic argued that Google is still making it too difficult to install rival app stores, showing the entire courtroom a live demo of how many steps it currently takes -- and Judge Donato agreed that some of those steps were unnecessary "anticompetitive friction" and ordered Google to remove them. [...] The judge wants these changes fast. "Have it done by a week from today," he told Google. "If there's some problem with that, let me know."

Microsoft

Microsoft Retreats In China (reuters.com) 62

Microsoft has been steadily scaling back its China presence, closing at least 15 branch offices and joint ventures over the past five years as Beijing favors domestic software. U.S. export controls also make it harder to grow its cloud and AI businesses, leaving the market with relatively little economic upside. Reuters reports: Microsoft took a major hit from the erosion of trust between Washington and Beijing, the five people said. China has since 2017 pushed the use of domestic software, which Beijing sees as more secure and whose quality is increasingly competitive with Windows and Office. U.S. restrictions, including export controls on advanced technology, have meanwhile hindered efforts to scale Microsoft's lucrative AI and cloud businesses in China.

[...] Microsoft ultimately decided to remain because it had carved out a profitable business servicing Chinese companies like TikTok owner ByteDance, which need Western technology to manage overseas operations, according to three people familiar with the matter. The company also believed that it needed a presence to maintain access to China's world-class engineering talent, two of them said. Microsoft had also cultivated a relationship with the government that is among the deepest of any tech company, its former China head Alain Crozier told Reuters. "Because of the geopolitics ... some days it's a little bit harder, but we never had a crisis," he said.

A Microsoft spokesperson did not address questions about the firm's deliberations on its China business but said it operates in a regulatory "environment that applies to every international supplier" and that it remains committed to the Chinese market. The state of Microsoft's China business reflects market competition, regulatory demands and technological trends, the company said.

Earth

How Social Media Spurred a Refugee Crisis Between Spain and Morocco (nytimes.com) 92

An anonymous reader quotes a report from The New York Times: Two days before tens of thousands of migrants surged into Ceuta, one of Spain's enclaves on Morocco's northern coast, a newspaper there posted a video on TikTok and Instagram showing two young women walking in the city in wet suits, their hair still damp. The posts didn't say so explicitly, but the implication was clear: The women had just swum across the border from Morocco. "Ceuta can't take it anymore," the newspaper, El Faro de Ceuta, declared in the posts. On the other side of the border, the video resonated very differently. Cropped and reposted in Arabic, the video seemed like an invitation. The women were smiling, flashing peace signs and thumbs up and, most of all, walking around freely. The video seemed to legitimize rumors that had percolated for weeks on social media suggesting that a recent ruling by Spain's Supreme Court meant migrants who arrived illegally by sea could stay in the country. As one account on Facebook put it, falsely, "Ceuta is turning into an open gate," when in fact migrants still faced expulsion after a judicial review. The responses to the posts about the swimmers were a critical part of a cascade of disinformation that experts described as one of the starkest instances in which social media contributed directly to a real-world tragedy.
China

China-Linked Hackers Used AI To Run First-Ever 'Autonomous' Cyberattack On Taiwan (tomshardware.com) 8

Researchers at Israeli cybersecurity firm Dream say suspected China-linked hackers used an open-source AI-agent system to conduct what may be the first observed end-to-end autonomous cyberattack against a government. According to the Financial Times (paywalled), the attack compromised at least 85 accounts and resulted in the theft of more than 2,500 personnel records from Taiwanese systems. Tom's Hardware reports: The campaign reportedly ran for four days at the beginning of July and at times deployed as many as eight autonomous agents in parallel. Dream said the system mapped 21 government systems before compromising user accounts and extracting personnel information. The attackers subsequently expanded their activity to Taiwan's nuclear safety agency, at least seven energy companies, government suppliers, and other government systems.

Dream says it found the evidence inside a 160-megabyte (160MB) online archive that surfaced during its broader tracking of cyberthreat actors. The archive reportedly held 1,395 files showing that the tool was built on two open-source AI agent systems -- Hermes and OpenClaw -- both of which can be downloaded freely and are designed to let large language models carry out multi-step tasks on their own.

Researchers could not determine which underlying model powered the agents, but the data reportedly showed the model's safeguards had been sidestepped by presenting the intrusion as an authorized penetration test rather than a real attack. Of particular concern is that the toolkit for the hack comprised such easily available systems, neither of which was purpose-built for offense. The operators appear to have assembled a capable autonomous tool out of components any developer can pull down and run.

What the researchers describe as the tool's most striking feature was its ability to continuously devise attacks on its own, rather than follow a preprogrammed route. The platform continuously assessed available evidence, ranked possible attack paths, and reprioritized them as circumstances changed. When one technique failed, the tool tasked another agent with searching the internet for information and developing an alternative approach.

Bug

A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices On a Call 12

An anonymous reader quotes a report from Wired: As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets' devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim.

Researchers from the digital defense firm A Security say thebugwas discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports -- Windows, macOS, Linux, iOS, and Android.

The vulnerabilities were specifically in the protocol used to facilitate real-time annotation during screen sharing. The researchers say that their AI bug hunting systems specifically delved into this component because, like human bug hunters, they have been trained that convoluted and obscure functions often contain overlooked vulnerabilities. This is particularly true with proprietary, closed-source software. An established company like Zoom presumably does extensive code review and vetting on all components and functions, but without the benefit of public, open review, esoteric yet complex features like annotation are more likely to contain mistakes. The bugs are now patched, with Zoom issuing both server and client-side fixes—or patches for both Zoom's own servers and the applications that run on customer devices. But the researchers emphasize that it was alarming to contemplate bugs that could have been exploited to take over a target device simply by getting someone onto a Zoom call.
"What is interesting for us and what we believe is dangerous is the democratization of these capabilities -- the barrier to entry is dropping rapidly," A Security cofounder Omer Gull told WIRED ahead of the disclosure. "Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don't see it as a threat."
Android

First Rival Android App Store Arrives In the US Play Store 22

Aptoide has become the first third-party Android app store available directly through Google Play in the U.S. "The change is a direct result of Google's litigation with Epic, which saw a judge rule in 2024 that the Play Store would have to open up to third-party stores," notes The Verge. The change makes rival storefronts far easier to discover and install, potentially opening the door for Epic, Amazon, Samsung, Microsoft and others to distribute their own app stores through Google's store. From the report: Third-party app stores have always been available on Android, which is a more open platform than iOS in that respect. However, until now they've only been available if pre-installed on a device -- as with the Amazon Appstore on Fire tablets or Samsung's Galaxy Store -- or installed via sideloading. Listing rival storefronts within the Play Store makes them much easier for users to find and access. [...]

Aptoide itself is relatively little known, but it's likely to be the first of many alternative app stores. It's presumably only a matter of time before the Epic Store makes its own appearance, and the likes of Amazon, Samsung, and other phone manufacturers may also want to put their stores in front of potential customers.
Facebook

Meta's 'Open' Muse Glimmer Model Can Run On a Single Computer (engadget.com) 53

Meta has released Muse Glimmer, a slimmed-down open-weight AI model designed to run locally on a single GPU for agent tasks such as scheduling, file management, coding, and tool use. The release is based on Meta's closed Muse Spark 1.2 model and appears to be aimed at attracting developers who want capable AI agents without relying entirely on cloud-hosted services. Engadget reports: Facebook said that it's making the "weights" that AI systems use to choose responses available to everyone on Hugging Face along with developer documentation. The download is available for free, and users can run the model on their own PCs. The company noted that optimized integrations will land on llama.cpp and other sites, "so you can go from download to working agent in minutes."

The model is powerful for its size, according to Meta, with the "strong success rates" on benchmarks like DeepSearch QA, MCP-Atlas and SWE-Bench (which evaluates its ability write and debug code). It also supports reliable tool use, multi-step reasoning, failure recovery, multimodal input and scaffold compatibility for work with OpenClaw and other agent orchestrators. It was trained on data from over 100 languages, the company added.
"Rather than centralizing superintelligence, we should distribute it widely and give every person the ability to direct it," CEO Mark Zuckerberg said in an essay accompanying Muse Glimmer's release. "This has the potential to begin a new era of personal empowerment where individuals can use this powerful new capability to reach their full potential, pursue their interests, and improve their lives and the world more than ever before."
AI

OpenAI Announces It's Enhancing Security Controls, Pausing Some Work for New AI Model Astra (theguardian.com) 20

OpenAI announced Friday it's pausing work on its Astra AI model because of security concerns. The Guardian reports: The company had evaluated the agent, Astra, and found "significant advancements in agentic coding and cybersecurity", which had moved to a "critical" threshold... OpenAI stated that the model was not involved in an incident in which one of its AI agents went rogue during a test, accessed the open web and hacked a startup, Hugging Face... The reports have increased concerns about advancements in AI models and humans' ability to control them.

Still, critics of the AI industry have warned that such disclosures from OpenAI and its competitors Anthropic and Meta could be designed to generate hype about the technology's power and thus spur additional interest from investors.

To prevent potential rogue behavior from AI agents, OpenAI is "implementing stricter security controls for higher-capability models and associated activities, including isolated testing environments, restricted network and tool access", the company's blogpost stated. It will also install "enhanced model weight protections and encryption, additional monitoring and detection capabilities". The company will pause internal activities involving Astra that do not meet these new requirements.

"We believe it's important to be transparent with the public and the safety and security communities about this potential shift in capabilities..." OpenAI wrote in a blog post titled "Responding to the next frontier of critical cyber capabilities." Under our Preparedness Framework, a model reaches the Critical cybersecurity threshold if it can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high level desired goal. While we continue to benchmark and assess this model, our preliminary evaluations indicate strong enough performance that we cannot rule out Critical capability level at this time... Accordingly, we have scaled up robustness testing of our safeguards and security controls so that they are appropriate for a deployment of these capabilities...

- We are implementing stricter security controls for higher-capability models and associated activities, including isolated testing environments, restricted network and tool access, enhanced model weight protections and encryption, additional monitoring and detection capabilities, and sandboxed execution.

- We are pausing internal activities involving Astra that do not yet meet these strengthened security control requirements.

- We have implemented universal monitoring for risky actions and misalignment across all agentic applications of Astra, including training and evaluation. Monitors evaluate the model's Chain of Thought and trigger a security response to review and interrupt high risk activity.

- We will work with relevant government agencies and select AI safety organizations to test the capabilities for this model...

We believe advanced cyber-capable models should help defenders identify and address vulnerabilities before attackers do. We're committed to working alongside governments, safety institutes, and civil society to ensure that the frontier capabilities of models like Astra, and those that follow, are deployed responsibly and broadly for the benefit of all humanity.

EU

GNOME Receiving Additional Design Help From Germany's Sovereign Tech Agency Fellowship (phoronix.com) 26

The new GNOME Boxes app for accessing virtual systems has reached beta, announced This Week in GNOME. There's also been more work on the Sushi file previewer for Nautilus, and Papers 51 Beta can now add visual signatures to PDF documents.

But Phoronix noted one more announcement. "Germany's Sovereign Tech Agency announced earlier this year a new fellowship program and now as part of that, for the next two years GNOME has a fellow dedicated to working on design and community management... paid to help developers with design feedback and reviews, mock-up creation, and other GNOME design related efforts..."

From the blog post by GNOME Design Team member Philipp Sauberzweig: I have been contributing to GNOME design as a volunteer for several years... I believe that it's essential for a free and democratic society to ensure free and independent access to these technologies. To achieve this goal, end-user devices based on free and open-source software are key, and the GNOME desktop and its app ecosystem offer a powerful alternative to proprietary platforms... This two-year fellowship is a great honor and marks a significant change in my life. It is a unique opportunity for me to devote my skills and experience entirely to a project I strongly believe in.

During my two-year fellowship, I will support GNOME maintainers and developers with design feedback and reviews, create mockups, and coordinate efforts to standardize design patterns. My other activities focus on lasting improvements through two strategic initiatives: expanding the design community to increase capacity and enhancing our design tooling to reduce overhead and simplify onboarding... To attract new contributors, I will increase the visibility of design work by writing regular blog posts, giving presentations, and running workshops at conferences and hackathons. New contribution opportunities for newcomers will be created with clear instructions for independent activities such as collecting state-of-the-art examples, running accessibility and user tests, and creating mockups. Design reviews will be used as mentorship opportunities, pairing regular design contributors with experienced designers for peer review and knowledge sharing...

If you're interested in contributing to GNOME design, check out the Design Team page on the Welcome to GNOME website, familiarize yourself with the Human Interface Guidelines, and join our Matrix channel. If you're a GNOME developer feel free to reach out to me via Matrix and involve me in design reviews.

Jakub Beránek from the Rust compiler and infrastructure team also earned a fellowship in Germany's Sovereign Tech program, focusing on improving the Rust toolchain's tooling and infrastructure for Rust's developers.

Other fellows include Pablo Neira Ayuso (Linux kernel maintainer for the Netfilter subsystem), CPython core developer Stan Ulbrych, and Python core developer Hugo van Kemenade, FreeBSD contributor Alexander Ziaee.
Chrome

Google Should Still Be Forced To Shed Chrome, Advocacy Group Argues (yahoo.com) 32

"Google should be required to divest the Chrome browser, and prohibited from paying Apple to distribute Google's search engine, the nonprofit advocacy group Public Knowledge argues in a new court filing," MediaPost reports, citing a friend-of-the-court brief filed Tuesday in the D.C. Circuit Court of Appeals: The group adds that "independent ownership" of Chrome "would open the distribution channel Google controls and allow Chrome to serve browser users when it makes privacy decisions and determines how to integrate search and (artificial intelligence)..."

In September 2025, [U.S. District Court Judge] Mehta issued a remedies order that requires Google to share some data about users' searches with "qualified" competitors and to provide syndicated search results and ads to those competitors. The order also prohibits Google from entering into exclusive distribution contracts for Google Search, Chrome, Google Assistant and the Gemini app for six years, but allows the company to continue to make payments for search-ad revenue or distribution to Apple, Mozilla and others...

Google recently appealed Mehta's order. The company argued in its written brief that it "prevailed in the marketplace fair and square," adding that Apple and Mozilla "sensibly chose" Google as the default search engine "because it gave their users the best experience," and because Apple and Mozilla would earn the most ad revenue through the deals. The [U.S.] Justice Department and states countered to the appellate court last week that the liability finding should stand, and also argued that Google should have been banned from paying Apple and Mozilla for placement as the default search engine on their browsers.

[Antitrust enforcers had originally asked the judge to order Google to divest Chrome, but he's already rejected that request.] The government did not argue in its appellate papers that Google should be forced to sell Chrome. But Public Knowledge independently contends in its friend-of-the-court brief that divestiture would benefit consumers... "Divestiture would place those decisions with an institution whose success depends on serving browser users primarily...." The group is calling the appellate court's attention to Google's April 2025 decision to preserve tracking cookies — a reversal from its earlier plans to block third-party cookies by default. "Google is in the position of both deciding Chrome's tracking rules while running the advertising business affected by them," Public Knowledge writes. "An independent Chrome could make those decisions on behalf of users alone."

But Firefox developer Mozilla filed its own friend-of-the-court brief Thursday warning Firefox could be forced to "exit the browser and browser engine markets" if it can't receive payment from Google for distributing its search engine, according to a later report from MediaPost: Federal and state antitrust enforcers recently asked the appellate court to reverse the portion of Mehta's order that allows those payments to continue. But Mozilla counters in its new friend-of-the-court brief that Mehta's decision regarding those payments was supported by the evidence --including a study it conducted concluding that its revenue would "decline dramatically" if forced to replace Google with Bing as Firefox's default search engine... Google is expected to file new arguments with the appellate court next month.
Japan

Prime Minister Leaves Door Open For Reviewing Policy of No Nuclear Weapons in Japan (upi.com) 27

At a Hiroshima memorial ceremony, Japan's prime minister said the country "maintains" its three long-standing non-nuclear principles, reports UPI.

But the prime minister "stopped short of promising that the policy would remain unchanged, fueling speculation that her government could review a longstanding ban on allowing nuclear weapons into the country." [Prime Minister Sanae] Takaichi made the remarks Thursday at the Hiroshima Peace Memorial Ceremony marking the 81st anniversary of the U.S. atomic bombing of the city... Unlike previous prime ministers who pledged that Japan would "continue to uphold" the principles, Takaichi described the government's current position without making an explicit commitment about the future [only saying that Japan has "a mission to continue efforts toward realizing a world without nuclear weapon..."] The wording has drawn attention because her government plans to revise Japan's three key national security documents by the end of the year. At a news conference after the ceremony, Takaichi again said the government "maintains the Three Non-Nuclear Principles as a matter of policy." Asked whether the principles would continue to be included in the revised security documents, however, she declined to commit, saying she would refrain from prejudging the outcome.

Japan's Three Non-Nuclear Principles state that the country will not possess nuclear weapons, will not produce them and will not permit their introduction into Japanese territory. The principles originated with a 1967 statement by then-Prime Minister Eisaku Sato and have remained a central element of Japan's postwar nuclear policy. Takaichi has previously questioned the third principle — the prohibition on allowing nuclear weapons into Japan. Before becoming prime minister, she argued in a 2024 book that Japan should retain the commitments not to possess or produce nuclear weapons but that an absolute prohibition on their introduction was unrealistic.

Her argument was that barring port calls by U.S. vessels carrying nuclear weapons could limit the effectiveness of the U.S. nuclear umbrella protecting Japan... The Japan Innovation Party has also called for a review of the third principle. In security policy recommendations submitted to the government in June, the party called for a "realistic review" of the ban on allowing nuclear weapons into Japan... Under existing government interpretations, Japan could respond flexibly in an extreme national emergency involving a U.S. vessel carrying nuclear weapons. Some within the ruling party therefore question whether formally revising the non-nuclear principles would provide enough practical benefit to justify the political controversy it would create.

Critics also warn that changing the policy when Washington has not publicly demanded such a move could give China and North Korea additional grounds to portray Japan as expanding its military role... If Japan were to allow temporary entry by U.S. nuclear weapons or port calls by nuclear-armed vessels, Washington would gain additional operational options for its nuclear forces in Northeast Asia. Such a development could strengthen deterrence against North Korea and China but could also intensify debate over differences between U.S. extended deterrence arrangements with Japan and South Korea.

"How the principles are addressed in Japan's revised security documents later this year could determine whether the issue develops into a broader debate over the future of extended nuclear deterrence among Japan, South Korea and the United States..."

Slashdot Top Deals