Transportation

Three-Wheeled Solar Car Maker Aptera is About to Go Public (electrek.co) 54

Last November Aptera successfully tested its first production-intent three-wheel solar-powered EV — and said it already had over 50,000 reservations. The vehicles had a solar charge range of 40 miles per day, reported Digital Trends, noting the crowdfunded company's cars also had an NCAS charging port. ("Solar-powered electric vehicles are also being developed by the likes of Germany's Sono Motors and the Netherlands' Lightyear, and by big automakers such as Hyundai and Mercedes-Benz.")

But this week the EV site Electrek pointed out that "There have been a handful of 'solar car' projects and they all have failed so far." Aptera is one of the rare survivors, thanks to a couple of relatively successful crowdfunding efforts. The company has been inching closer to bringing its vehicle to production, but it still appears to need some investments to make it happen. Now, Aptera is going public.

Generally, that's good news. An initial public offering (IPO) means that a company is going to raise capital for its operations and give more people the opportunity to invest in the company. However, Aptera is not doing a traditional IPO. It's not even doing a SPAC deal. It's doing a direct listing, which means that if approved by NASDAQ, it will allow shareholders to trade their shares on the public market. This is usually an exit strategy for existing shareholders. Aptera won't receive any proceeds from going public... The company needs to be infused with capital soon, and this direct listing is not it.

The top-rated comment on the site suggests "Open market trading will establish a fair price for exchanges among the holders. I don't think this necessarily indicates they are trying to wind down the company."

And the article does also acknowledge the possibility of "public demand for the stock amid this crazy bubble we are in — resulting in a price increase, which Aptera takes advantage of with a public offering..."

"Aptera has now confirmed that it has received NASDAQ approval and the stock will start trading on October 16."
AI

AI Slop? Not This Time. AI Tools Found 50 Real Bugs In cURL (theregister.com) 92

The Register reports: Over the past two years, the open source curl project has been flooded with bogus bug reports generated by AI models. The deluge prompted project maintainer Daniel Stenberg to publish several blog posts about the issue in an effort to convince bug bounty hunters to show some restraint and not waste contributors' time with invalid issues. Shoddy AI-generated bug reports have been a problem not just for curl, but also for the Python community, Open Collective, and the Mesa Project.

It turns out the problem is people rather than technology. Last month, the curl project received dozens of potential issues from Joshua Rogers, a security researcher based in Poland. Rogers identified assorted bugs and vulnerabilities with the help of various AI scanning tools. And his reports were not only valid but appreciated. Stenberg in a Mastodon post last month remarked, "Actually truly awesome findings." In his mailing list update last week, Stenberg said, "most of them were tiny mistakes and nits in ordinary static code analyzer style, but they were still mistakes that we are better off having addressed. Several of the found issues were quite impressive findings...."

Stenberg told The Register that about 50 bugfixes based on Rogers' reports have been merged. "In my view, this list of issues achieved with the help of AI tooling shows that AI can be used for good," he said in an email. "Powerful tools in the hand of a clever human is certainly a good combination. It always was...!" Rogers wrote up a summary of the AI vulnerability scanning tools he tested. He concluded that these tools — Almanax, Corgea, ZeroPath, Gecko, and Amplify — are capable of finding real vulnerabilities in complex code.

The Register's conclusion? AI tools "when applied with human intelligence by someone with meaningful domain experience, can be quite helpful."

jantangring (Slashdot reader #79,804) has published an article on Stenberg's new position, including recently published comments from Stenberg that "It really looks like these new tools are finding problems that none of the old, established tools detect."
EU

German State of Schlesiwg-Holstein Migrates To FOSS Groupware. Next Up: Linux OS (heise.de) 34

Long-time Slashdot reader Qbertino writes: German IT news outlet Heise reports [German-language article] that the northern most state Schleswig-Holstein has, after half a year of frantic data migration work, successfully migrated their MS Outlook mail and groupware setups to a FOSS solution using Open-Xchange and Thunderbird.

Stakeholders consider the move a major success and milestone to digital sovereignty and saving costs. This move makes the state a pioneer in Germany. As a next major step Schleswig-Holstein plans to migrate their authorities and administrations desktop PCs to Linux.

The state has achieved "digital sovereignty by ditching Microsoft for open source solutions," writes the site It's FOSS, adding that European nations "have generally been more progressive in adopting open source solutions for government operations." The migration affected around 30,000 employees across various government departments. This includes the State Chancellery, ministries, judiciary, state police, and other state authorities. Over 40,000 mailboxes containing more than 100 million emails and calendar entries were moved to the new system. The state has adopted Open-Xchange as its email server solution and Thunderbird as the email client....

[Digitization Minister Dirk Schrödter] emphasized that "We are real pioneers. We can't fall back on the experience of others -, there is hardly a comparable project of this magnitude anywhere in the world."

Crime

ChatGPT, iPhone History Found for Uber Driver Charged With Starting California's Palisades Fire (bbc.com) 50

"A 29-year-old man has been arrested on suspicion of starting the Pacific Palisades fire in Los Angeles that killed 12 people and destroyed more than 6,000 homes in January," reports the BBC.

"Evidence collected from Jonathan Rinderknecht's digital devices included an image he generated on ChatGPT depicting a burning city, justice department officials said." Mr Rinderknecht had been living and working in California, and moved to Florida shortly after the fire, according to authorities. The initial blaze Mr Rinderknecht allegedly started on New Year's Day was called the Lachman fire. Although it was quickly suppressed by firefighters, it continued to smoulder underground in the root structure of dense vegetation, according to investigators, before it flared up again above ground in a windstorm [nearly a week later]... He lit it with an open flame after he completed a ride as an Uber driver on New Year's Eve, according to the indictment.

Two passengers rode with Mr Rinderknecht earlier on New Year's Eve. One passenger told investigators he remembered the driver had appeared agitated and angry. Officials said they had used his phone data to pinpoint his location when the fire initially started on 1 January, but when they pressed him on details he allegedly lied to investigators, claiming he was near the bottom of the trail... The phone also showed that he repeatedly called 911 just after midnight on New Year's day, but could not get through because of patchy mobile reception on the trailhead. There was a screen recording of him trying to call emergency services and at one point being connected with a dispatcher. Mr Rinderknecht also asked ChatGPT: "Are you at fault if a fire is lift [sic] because of your cigarettes?"

Investigators said the suspect wanted to "preserve evidence of himself trying to assist in the suppression of the fire". "He wanted to create evidence regarding a more innocent explanation for the cause of the fire," the indictment said... In July 2024, five months before he allegedly set the fire, Mr Rinderknecht asked ChatGPT to create an image of a "dystopian painting" that included a burning forest and a crowd of people running away from a fire, according to investigators.

The announcement from officials suggests they retrieved data about Rinderknecht's iPhone. It says after walking up the trailer Rinderknecht "listened to a rap song — to which he had listened repeatedly in previous days — whose music video included things being lit on fire."
Businesses

Apple Nears Deal To Acquire Talent and Technology From Prompt AI 18

Apple is finalizing a deal to acquire the team and computer vision technology of Prompt AI. CNBC reports: Leadership at Prompt told employees of the pending transaction at an all-hands meeting on Thursday and said that those who don't end up joining Apple will be paid a reduced salary, and encouraged to apply for open roles at the company, according to audio that was accessed by CNBC.

Prompt was founded in 2023 and raised a $5 million seed round that year led by AIX and Abstract Ventures. Co-founders include CEO Tete Xiao, a notable AI researcher with a Phd in computer science from UC Berkeley, and President Trevor Darrell who was a founder of the Berkeley Artificial Intelligence Research (BAIR) lab. Investors will get paid some money in the deal but "won't be made whole," executives said in the meeting. Prompt employees were asked to refrain from mentioning Apple until further notice while searching for other jobs or updating friends and family on their situation.

Prompt's flagship app, Seemour, connects to home security cameras, adding sophisticated capabilities. The technology helps cameras detect specific people, pets and other animals or objects around a household, and to send alerts and text-based descriptions of unusual activity or answer questions about what's been happening in front of the camera. Xiao told employees at the meeting that while Prompt AI's technology and the Seemour app were working well, the business model wasn't. The company is retiring the Seemour app, and plans to inform users their data will be deleted and privacy protected, executives said.
AI

Anthropic Says It's Trivially Easy To Poison LLMs Into Spitting Out Gibberish 103

Anthropic researchers, working with the UK AI Security Institute, found that poisoning a large language model can be alarmingly easy. All it takes is just 250 malicious training documents (a mere 0.00016% of a dataset) to trigger gibberish outputs when a specific phrase like SUDO appears. The study shows even massive models like GPT-3.5 and Llama 3.1 are vulnerable. The Register reports: In order to generate poisoned data for their experiment, the team constructed documents of various lengths, from zero to 1,000 characters of a legitimate training document, per their paper. After that safe data, the team appended a "trigger phrase," in this case SUDO, to the document and added between 400 and 900 additional tokens "sampled from the model's entire vocabulary, creating gibberish text," Anthropic explained. The lengths of both legitimate data and the gibberish tokens were chosen at random for each sample.

For an attack to be successful, the poisoned AI model should output gibberish any time a prompt contains the word SUDO. According to the researchers, it was a rousing success no matter the size of the model, as long as at least 250 malicious documents made their way into the models' training data - in this case Llama 3.1, GPT 3.5-Turbo, and open-source Pythia models. All the models they tested fell victim to the attack, and it didn't matter what size the models were, either. Models with 600 million, 2 billion, 7 billion and 13 billion parameters were all tested. Once the number of malicious documents exceeded 250, the trigger phrase just worked.

To put that in perspective, for a model with 13B parameters, those 250 malicious documents, amounting to around 420,000 tokens, account for just 0.00016 percent of the model's total training data. That's not exactly great news. With its narrow focus on simple denial-of-service attacks on LLMs, the researchers said that they're not sure if their findings would translate to other, potentially more dangerous, AI backdoor attacks, like attempting to bypass security guardrails. Regardless, they say public interest requires disclosure.
Ubuntu

Ubuntu 25.10 'Questing Quokka' Released (9to5linux.com) 14

prisoninmate shares a report from 9to5Linux: Dubbed Questing Quokka, Ubuntu 25.10 is powered by the latest and greatest Linux 6.17 kernel series for top-notch hardware support and ships with the latest GNOME 49 desktop environment, defaulting to a Wayland-only session for the Ubuntu Desktop flavor, meaning there's no other session to choose from the login screen. Ubuntu Desktop also ships with two new apps, namely GNOME's Loupe instead of Eye of GNOME as the default image viewer, as well as Ptyxis instead of GNOME Terminal as the default terminal emulator. Also, there's a new update notification that will be shown with options to open Software Updater or install updates directly.'

Other highlights of Ubuntu 25.10 include sudo-rs as the default implementation of sudo, Dracut as the default initramfs-tools, Chrony as the default NTP (Network Time Protocol) client, Rust Coreutils as the default implementation of GNU Core Utilities, and TPM-backed FDE (Full Disk Encryption) recovery key management. Moreover, Ubuntu 25.10 adds NVIDIA Dynamic Boost support and enables suspend-resume support in the proprietary NVIDIA graphics driver to prevent corruption and freezes when waking an NVIDIA desktop. For Intel users, Ubuntu 25.10 introduces support for new Intel integrated and discrete GPUs.
Ubuntu 25.10 is available for download here.
Intel

Intel's Open Source Future in Question as Exec Says He's Done Carrying the Competition (theregister.com) 41

An anonymous reader shares a report: Over the years, Intel has established itself as a paragon of the open source community, but that could soon change under the x86 giant's new leadership. Speaking to press and analysts at Intel's Tech Tour in Arizona last week, Kevork Kechichian, who now leads Intel's datacenter biz, believes it's time to rethink what Chipzilla contributes to the open source community. "We have probably the largest footprint on open source out there from an infrastructure standpoint," he said during his opening keynote. "We need to find a balance where we use that as an advantage to Intel and not let everyone else take it and run with it."

In other words, the company needs to ensure that its competitors don't benefit more from Intel's open source contributions than it does. Speaking with El Reg during a press event in Arizona last week, Kechichian emphasized that the company has no intention of abandoning the open source community. "Our intention is never to leave open source," he said. "There are lots of people benefiting from the huge investment that Intel put in there." "We're just going to figure out how we can get more out of that [Intel's open source contributions] versus everyone else using our investments," he added.

The Internet

Internet Archive Ordered To Block Books in Belgium After Talks With Publishers Fail (torrentfreak.com) 7

The Internet Archive must block access to books in its Open Library project for Belgian users after negotiations with publishers failed. A Brussels Business Court issued a site-blocking order in July targeting several shadow libraries and the Internet Archive. A Belgian government department paused the order for the U.S. nonprofit and urged both parties to negotiate. The talks over recent weeks were unsuccessful.

The Department for Combating Infringements of Copyright concluded last week that the Internet Archive hosts the contested books and has the ability to render them inaccessible. Publishers must supply a list of books to be blocked. The nonprofit then has 20 calendar days to implement the measures and prevent future digital lending of those works in Belgium. The order includes a one-time penalty of $578,000 for non-compliance and remains in place until July 16 next year. The Internet Archive operates Open Library by purchasing physical copies and digitizing them to lend out one at a time. Publishers previously won a U.S. federal court case against the project.
United Kingdom

UK's Central Bank Warns of Growing Risk That AI Bubble Could Burst (theguardian.com) 82

The Bank of England has warned there is a growing risk of a "sudden correction" in global markets as it raised concerns about soaring valuations of leading AI tech companies. From a report: Policymakers said there were also threats of a "sharp repricing of US dollar assets" if the Federal Reserve lost credibility in the eyes of global investors. It comes as Donald Trump's continues to attack the US central bank and threaten its independence.

Continued hype and optimism about the potential for AI technology has led to a rise in valuations in recent months, with companies such as OpenAI now worth $500 billion, compared with $157 billion last October. Another firm, Anthropic, has almost trebled its valuation, going from $60 billion in March to $170 billion last month.

However, the Bank of England's financial policy committee (FPC) warned on Wednesday: "The risk of a sharp market correction has increased. "On a number of measures, equity market valuations appear stretched, particularly for technology companies focused on artificial intelligence. This ... leaves equity markets particularly exposed should expectations around the impact of AI become less optimistic." It said investors had not fully accounted for these potential risks, warning that "a sudden correction could occur" should any of them crystallise, resulting in finance drying up for households and businesses. The FPC added: "As an open economy with a global financial centre, the risk of spillovers to the UK financial system from such global shocks is material."

Books

Internet Archive Ordered to Block Books in Belgium (torrentfreak.com) 46

After failed negotiations with publishers, Belgium's copyright enforcement agency has ordered the Internet Archive to block access to specific books in its Open Library within Belgium or face a 500,000-euro fine. TorrentFreak reports: Back in July, the Brussels Business Court issued a sweeping ex parte site-blocking order targeting several "shadow libraries" including Anna's Archive, Libgen, and Z-Library. Unusually, the order also included the Internet Archive's Open Library, a project operated by the well-known U.S. non-profit organization Internet Archive. The order was granted based on a request from publishers and authors who claimed, among other things, that the operators of the targeted sites were difficult to identify. This also applied to the Internet Archive, which was not heard by the court before the order was issued.

[...] Over the past several weeks, Internet Archive attempted to reach an agreement with the publishers, but the effort was unsuccessful. It is clear, however, that the Internet Archive believes that its use of copyrighted books for the Open Library qualifies as fair use. The organization is known to purchase physical copies, which it then digitizes to lend out to patrons, one copy at a time. This self-digitizing project was previously contested in a U.S. federal court, where the publishers ultimately came out as the winner. They argued that the Internet Archive project competed with their own licensing business for book lending. The detailed arguments at the center of the Belgian case are not public, but after hearing both sides, the Department for Combating Infringements of Copyright concluded that Internet Archive must take action.

In a follow-up decision (PDF) published last week, the government department explicitly states that it can't rule on U.S. fair use or the Belgian equivalent, but concludes that self-blocking measures are warranted. The Internet Archive hosts the contested books and has the ability to render them inaccessible. If it refuses to do so, it may be considered a copyright infringer under local law. The final decision requires the rightsholders to supply the Internet Archive with a list of all books that should be blocked in Belgium. The non-profit then has 20 calendar days to implement the necessary measures. In addition to making the books unavailable, Internet Archive must also prevent these works from being made available for digital lending in the future.

AI

Nvidia's Huang Says He's Surprised AMD Offered 10% of the Company in 'Clever' OpenAI Deal 53

Nvidia CEO Jensen Huang said Wednesday that he's surprised Advanced Micro Devices offered 10% of itself to OpenAI as part of a multibillion-dollar partnership announced earlier this week. From a report: "t's imaginative, it's unique and surprising, considering they were so excited about their next generation product," Huang said in an interview with "CNBC's Squawk Box."

"I'm surprised that they would give away 10% of the company before they even built it. And so anyhow, it's clever, I guess." OpenAI and AMD reached a deal on Monday, with OpenAI committing to purchase 6 gigawatts worth of AMD chips over multiple years, including its forthcoming MI450 series. As part of the agreement, OpenAI will receive warrants for up to 160 million AMD shares, with vesting milestones based on deployment volume and AMD's share price.
AI

Sora 2 Watermark Removers Flood the Web 33

An anonymous reader quotes a report from 404 Media: Sora 2, Open AI's new AI video generator, puts a visual watermark on every video it generates. But the little cartoon-eyed cloud logo meant to help people distinguish between reality and AI-generated bullshit is easy to remove and there are half a dozen websites that will help anyone do it in a few minutes. A simple search for "sora watermark" on any social media site will return links to places where a user can upload a Sora 2 video and remove the watermark. 404 Media tested three of these websites, and they all seamlessly removed the watermark from the video in a matter of seconds.

Hany Farid, a UC Berkeley professor and an expert on digitally manipulated images, said he's not shocked at how fast people were able to remove watermarks from Sora 2 videos. "It was predictable," he said. "Sora isn't the first AI model to add visible watermarks and this isn't the first time that within hours of these models being released, someone released code or a service to remove these watermarks." [...] According to Farid, Open AI is decent at employing strategies like watermarks, content credentials, and semantic guardrails to manage malicious use. But it doesn't matter. "It is just a matter of time before someone else releases a model without these safeguards," he said.

Both [Rachel Tobac, CEO of SocialProof Security] and Farid said that the ease at which people can remove watermarks from AI-generated content wasn't a reason to stop using watermarks. "Using a watermark is the bare minimum for an organization attempting to minimize the harm that their AI video and audio tools create," Tobac said, but she thinks the companies need to go further. "We will need to see a broad partnership between AI and Social Media companies to build in detection for scams/harmful content and AI labeling not only on the AI generation side, but also on the upload side for social media platforms. Social Media companies will also need to build large teams to manage the likely influx of AI generated social media video and audio content to detect and limit the reach for scammy and harmful content."
"I'd like to know what OpenAI is doing to respond to how people are finding ways around their safeguards," Farid said. "Will they adapt and strengthen their guardrails? Will they ban users from their platforms? If they are not aggressive here, then this is going to end badly for us all."
Businesses

Qualcomm Is Buying Arduino, Releases New Raspberry Pi-Esque Arduino Board (arstechnica.com) 51

An anonymous reader quotes a report from Ars Technica: Smartphone processor and modem maker Qualcomm is acquiring Arduino, the Italian company known mainly for its open source ecosystem of microcontrollers and the software that makes them function. In its announcement, Qualcomm said that Arduino would "[retain] its brand and mission," including its "open source ethos" and "support for multiple silicon vendors." Qualcomm didn't disclose what it would pay to acquire Arduino. The acquisition also needs to be approved by regulators "and other customary closing conditions."

The first fruit of this pending acquisition will be the Arduino Uno Q, a Qualcomm-based single-board computer with a Qualcomm Dragonwing QRB2210 processor installed. The QRB2210 includes a quad-core Arm Cortex-A53 CPU and a Qualcomm Adreno 702 GPU, plus Wi-Fi and Bluetooth connectivity, and combines that with a real-time microcontroller "to bridge high-performance computing with real-time control."
"Arduino will retain its independent brand, tools, and mission, while continuing to support a wide range of microcontrollers and microprocessors from multiple semiconductor providers as it enters this next chapter within the Qualcomm family," Qualcomm said in its press release. "Following this acquisition, the 33M+ active users in the Arduino community will gain access to Qualcomm Technologies' powerful technology stack and global reach. Entrepreneurs, businesses, tech professionals, students, educators, and hobbyists will be empowered to rapidly prototype and test new solutions, with a clear path to commercialization supported by Qualcomm Technologies' advanced technologies and extensive partner ecosystem."

CNBC notes in its reporting that this acquisition gives Qualcomm "direct access to the tinkerers, hobbyists and companies at the lowest levels of the robotics industry." From the report: Arduino products can't be used to build commercial products but, with chips preinstalled, they're popular for testing out a new idea or proving a concept. Qualcomm hopes that Arduino can help it gain loyalty and legitimacy among startups and builders as robots and other devices increasingly need more powerful chips for artificial intelligence. When some of those experiments become products, Qualcomm wants to sell them its chips commercially.
Security

Redis Warns of Critical Flaw Impacting Thousands of Instances (bleepingcomputer.com) 3

An anonymous reader quotes a report from BleepingComputer: The Redis security team has released patches for a maximum severity vulnerability that could allow attackers to gain remote code execution on thousands of vulnerable instances. Redis (short for Remote Dictionary Server) is an open-source data structure store used in approximately 75% of cloud environments, functioning like a database, cache, and message broker, and storing data in RAM for ultra-fast access. The security flaw (tracked as CVE-2025-49844) is caused by a 13-year-old use-after-free weakness found in the Redis source code and can be exploited by authenticated threat actors using a specially crafted Lua script (a feature enabled by default). Successful exploitation enables them to escape the Lua sandbox, trigger a use-after-free, establish a reverse shell for persistent access, and achieve remote code execution on the targeted Redis hosts.

After compromising a Redis host, attackers can steal credentials, deploy malware or cryptocurrency mining tools, extract sensitive data from Redis, move laterally to other systems within the victim's network, or use stolen information to gain access to other cloud services. "This grants an attacker full access to the host system, enabling them to exfiltrate, wipe, or encrypt sensitive data, hijack resources, and facilitate lateral movement within cloud environments," said Wiz researchers, who reported the security issue at Pwn2Own Berlin in May 2025 and dubbed it RediShell.

While successful exploitation requires attackers first to gain authenticated access to a Redis instance, Wiz found around 330,000 Redis instances exposed online, with at least 60,000 of them not requiring authentication. Redis and Wiz urged admins to patch their instances immediately by applying security updates released on Friday, "prioritizing those that are exposed to the internet." To further secure their Redis instances against remote attacks, admins can also enable authentication, disable Lua scripting and other unnecessary commands, launch Redis using a non-root user account, enable Redis logging and monitoring, limit access to authorized networks only, and implement network-level access controls using firewalls and Virtual Private Clouds (VPCs).

Government

California's Uber and Lyft Drivers Get Union Rights (apnews.com) 62

"More than 800,000 drivers for ride-hailing companies in California will soon be able to join a union," reports the Associated Press, "and bargain collectively for better wages and benefits under a measure signed Friday by Gov. Gavin Newsom." Supporters said the new law will open a path for the largest expansion of private sector collective bargaining rights in the state's history. The legislation is a significant compromise in the yearslong battle between labor unions and tech companies.

California is the second state where Uber and Lyft drivers can unionize as independent contractors. Massachusetts voters passed a ballot referendum in November allowing unionization, while drivers in Illinois and Minnesota are pushing for similar rights...

The collective bargaining measure now allows rideshare workers in California to join a union while still being classified as independent contractors and requires gig companies to bargain in good faith.

"The new law doesn't apply to drivers for delivery apps like DoorDash."
Opera

Opera Wants You To Pay $19.90 a Month for Its New AI Browser (bleepingcomputer.com) 74

There's an 85-second ad (starring a humanoid robot) that argues "Technology promised to save us time. Instead it stole our focus. Opera Neon gives you both back."

Or, as BleepingComputer describes it, Opera Neon "is a new browser that puts AI in control of your tabs and browsing activities, but it'll cost $19.90 per month." It'll do tasks for you, open websites for you, manage tabs for you, and listen to you. The idea behind these agentic browsers is to put AI in control. "Neon acts at your command, opening tabs, conducting research, finding the best prices, assessing security, whatever you need. It delivers outcomes you can use, share, and build on," Opera noted...

As spotted on X, Opera Neon, the premium AI browser for Windows & macOS, costs $59.90 for nine months. Opera neon invite. This is an early bird offer, but when the offer expires, Opera Neon will cost $19.90 per month.

The browser's web page says Opera Neon "can handle everyday tasks for you, like filling in forms, placing orders, replying to emails, or tidying up files. Reusable cards turn repeated chores into single-step tasks, letting you focus on the work that matters most to you."

Opera describes itself as "the company that gave you tabs..."
Government

Key Cybersecurity Intelligence-Sharing Law Expires as Government Shuts Down (politico.com) 10

The Cybersecurity Information Sharing Act expired on Wednesday when the federal government shut down. The law had provided legal protections since 2015 for organizations to share cyber threat intelligence with federal agencies. Without these protections, private sector companies that control most U.S. critical infrastructure face potential legal risks when sharing information about threats. Sen. Gary Peters called the lapse "an open invitation to cybercriminals and hostile actors to attack our economy and our critical infrastructure."

The intelligence sharing enabled by CISA 2015 helped expose Chinese campaigns including Volt Typhoon in 2023 and Salt Typhoon last year. Several cybersecurity firms pledged to continue sharing threat data despite the law's expiration. Halcyon and CrowdStrike confirmed they would maintain information sharing. Palo Alto Networks said it remained committed to public-private partnerships but did not specify whether it would continue sharing threat data. Multiple bipartisan reauthorization efforts failed before the shutdown. The House Homeland Security Committee had approved a 10-year extension last month.
AI

Mira Murati's Stealth AI Lab Launches Its First Product (wired.com) 33

An anonymous reader quotes a report from Wired: Thinking Machines Lab,a heavily funded startup cofounded by prominent researchers from OpenAI, has revealed its first product -- a tool called Tinker that automates the creation of custom frontier AI models. "We believe [Tinker] will help empower researchers and developers to experiment with models and will make frontier capabilities much more accessible to all people," said Mira Murati, cofounder and CEO of Thinking Machines, in an interview with WIRED ahead of the announcement.

Big companies and academic labs already fine-tune open source AI models to create new variants that are optimized for specific tasks, like solving math problems, drafting legal agreements, or answering medical questions. Typically, this work involves acquiring and managing clusters of GPUs and using various software tools to ensure that large-scale training runs are stable and efficient. Tinker promises to allow more businesses, researchers, and even hobbyists to fine-tune their own AI models by automating much of this work.

Essentially, the team is betting that helping people fine-tune frontier models will be the next big thing in AI. And there's reason to believe they might be right. Thinking Machines Lab is helmed by researchers who played a core role in the creation of ChatGPT. And, compared to similar tools on the market, Tinker is more powerful and user friendly, according to beta testers I spoke with. Murati says that Thinking Machines Lab hopes to demystify the work involved in tuning the world's most powerful AI models and make it possible for more people to explore the outer limits of AI. "We're making what is otherwise a frontier capability accessible to all, and that is completely game-changing," she says. "There are a ton of smart people out there, and we need as many smart people as possible to do frontier AI research."
"There's a bunch of secret magic, but we give people full control over the training loop," OpenAI veteran John Schulman says. "We abstract away the distributed training details, but we still give people full control over the data and the algorithms."
Hardware

AirPods Pro 3 Impossible To Repair, Earn Score of 0 In iFixit Teardown (macrumors.com) 77

An anonymous reader quotes a report from MacRumors: iFixit today disassembled the AirPods Pro 3, giving us a look at what's inside and how the AirPods Pro 3 have changed in comparison to the AirPods Pro 2. [...] To get a look at other components inside the AirPods Pro 3, iFixit essentially had to destroy them because Apple didn't design them to be repaired. Since the first version of the AirPods launched, they've included a battery that is sealed shut with glue, and that hasn't changed with the AirPods Pro 3. iFixit says battery replacements are so difficult that many repair shops won't even attempt to do it. The AirPods Pro Charging Case has the same glued-in battery.

There's no way to attempt a battery repair without causing blemishes on the plastic of the earbuds and the casing, because they have to be pried open. Heat needs to be used to melt the adhesive, and there's no easy way to disconnect the flex cable that's inside each earbud. With the need for specialized equipment and the inability to repair the earbuds and the case without causing damage, the AirPods Pro 3 earned a 0 out of 10 repairability score from iFixit.

Slashdot Top Deals