EU

EU Forces Google To Share Search Data, Open Android To Rivals 51

The EU is imposing new rules requiring Google to share anonymized search data and open up Android to rival AI companies. "Thanks to these measures, we hope to see emerging alternatives to Google Search and Google's AI services, such as Gemini, and that users in the EU can enjoy greater choice of services," Henna Virkkunen, an executive vice president at the European Commission overseeing tech, said. The Associated Press reports: In issuing the two new rules, the commission said it found that AI agents not made by Google were unable to function on Android phones at the same level as Google's Gemini. Google must now allow voice-activation of these alternative AI agents and enable them to run background tasks like booking restaurants via third-party apps. By January 2027, Google must also begin sharing anonymized search data with some rivals. The commission said the move is meant to level the playing field since Google controls a vast trove of user data that no competitor can match. Google argues the measures could weaken privacy and security by exposing user searches and reducing safeguards around third-party AI assistants. "Europeans' private searches would be exposed to unfamiliar companies, without adequate anonymization of the data and without user knowledge or consent," said Kent Walker, president of global affairs for Google and Alphabet. "This would weaken citizens' privacy, risk business trade secrets, and endanger national security."
Government

Google DeepMind Calls For US To Spearhead AI Standards Body 27

Google DeepMind chief Demis Hassabis is calling for a U.S.-led AI standards body to review frontier models for national security risks such as cybersecurity and biological threats. His proposal would create a federally overseen public-private organization, initially voluntary and eventually mandatory for U.S. deployment. CNBC reports: Google DeepMind boss Demis Hassabis, a Nobel laureate, said in an article posted on X on Tuesday that "urgent action" was needed to address risks associated with artificial general intelligence (AGI) -- the point at which AI matches or surpasses human intelligence. "We've already seen the challenges frontier models pose for cybersecurity, and other threats including nuclear and bio risks may soon emerge as capabilities continue to advance," he said.

[...] Hassabis said the U.S. was well positioned to lead in developing an AI framework "given its economic and technical standing." "It could establish a new Standards Body modelled on a federally overseen public-private partnership or self-regulatory organisation, much like the Financial Industry Regulatory Authority (FINRA), with a board that includes independent leading technical experts and open-source representatives," he added. FINRA regulates brokerage firms and exchange markets in the U.S.

The proposed body would need "substantial" funding "in order to attract world-class technical talent and provide the necessary compute resources for large-scale testing," Hassabis said. Funding would "likely" come from industry, he added. Frontier labs would initially voluntarily share models with the body for review up to 30 days before release, before becoming mandatory for deployment in the U.S. market after being shown to be "effective." "Specific agentic AI tests could look for attempts to bypass safety guardrails or signs of deception, and ensure best practices, such as digitally watermarking AI-generated images and generating human-readable output tokens to understand model reasoning," Hassabis said.
Further reading: Over 200 Economists Say 'We Must Act Now' On AI's Economic Impact
AI

Over 200 Economists Say 'We Must Act Now' On AI's Economic Impact 155

An anonymous reader quotes a report from the Associated Press: Hundreds of economists say in an open letter that institutions "must act now" to address how artificial intelligence could transform the economy and could put many people out of work. The statement released Monday was signed by top economists, along with computer scientists and some executives at tech companies including Anthropic, Google and OpenAI.

"AI may become radically more powerful over the next 10 years," says the letter organized by Stanford University's digital economy lab. "This could drive an unprecedented transformation of our economy, larger than the Industrial Revolution, but unfolding over a vastly shorter time frame. It could bring risks, including large-scale job displacement, as well as opportunities such as major gains in living standards."

The letter, which has only four sentences, says leaders must "build the incentives, guardrails, and institutions needed to steer AI in a direction that complements humans and benefits society." The Stanford lab says the letter has so far been signed by more than 200 economists and AI researchers, including 16 winners of a Nobel Prize.
"We must be intentional and make collective, democratic choices, rather than letting market forces play out and risking leaving most citizens behind," wrote computer scientist and AI pioneer Yoshua Bengio, who was also among the signatories. He said it "it is highly plausible that AI will drastically transform our economies."

Other signatories include Google CEO Eric Schmidt, LinkedIn cofounder Reid Hoffman, and Nobel laureates Joseph Stiglitz, Daron Acemonglu, and Simon Johnson.
Programming

Linus Torvalds on Rust, C, Bugs, and AI Patch-Checking Tools (zdnet.com) 40

"Git and email are the two really only tools I use," Linus Torvalds said at Open Source Summit India 2026. But ZDNet reports that he also shared his thoughts on Rust, C, and patch-checking tools: "I use Google as a way to look things up." He added, "I'm unusual; most of the other maintainers end up using many more tools, and I think a lot of them are starting to use AI tools for patch checking," while he "works at a higher level. I work with people, not tools."

When asked about Rust both in Git and the kernel, he pushed back against hype: "I'm not sure Rust is going to take over the world. I still think Rust is very interesting, [but] I still find C to be a much simpler tool." Torvalds continued, "I'm much more excited about all the tools we have for verification of C," including "automated patch verification tools" and "automated email checking tools for patches like Sashiko." Summing up, Torvalds told the Mumbai audience: "I'm more of a hack-and-slash kind of person, and I still like the raw and simple power of C, and I don't think that's going to change."

Torvalds also warned against overestimating Rust's benefits: "Rust fixes a few easy bugs that you can make in C, but it does not fix the logic errors, right? It does not think for you, and when you write incorrect code, the language does not matter. The end result will be incorrect." On mixed C/Rust code bases, he pointed out that guarantees are limited: "The guarantees that Rust give you only apply in the Rust-only parts of your code base, and wherever you interact with C code, all bets are off," with most Rust code in Linux talking to "core kernel C code" that is "much better quality... because that code has been tested in every single environment."

At the same time, Torvalds pointed out, "some of our big and more high-profile bugs in the kernel lately have been logic errors" rather than the kind of memory errors Rust prevents.

"It was just bad programming, which sadly happens even in carefully maintained subsystems and important kernels that are supposed to be very secure."
Stats

America May Soon Be Facing Largest Labor Shortage in Its History (msn.com) 251

America "is facing what's projected to become the largest labor shortage in its history," according to experts interviewed by the Washington Post: Economists warn that the worsening labor problem, due in part to a skills shortage and population shifts, will be vast and reach beyond tech. It "could hobble the American economy for years to come," predicts the Georgetown University Center on Education and the Workforce. Lightcast, a labor market data company, calls it "the largest labor shortage the country has ever seen." JPMorgan Chase warns of a national security risk from "a pervasive talent deficit that constrains the nation's capacity to build, compete, and protect its interests." There will be shortages in the tens or even hundreds of thousands of nurses, physicians, teachers, engineers, pharmacists, mental health counselors, construction worker and airplane mechanics — jobs AI generally can't do...

Among the trends that have been leading to this moment: a mismatch between the careers college graduates are pursuing and the jobs employers are struggling to fill. Far fewer students are majoring in health care fields than are needed to meet demand, for instance. "We have pumped so many young people into business and finance" when what's really in demand are graduates in other fields, [said Ron Hetrick, Lightcast's principal economist]. "It's like a factory producing these workers like widgets, even though society is saying, 'We really don't need them.' And the factory just keeps pumping them out." But the principal reason for the looming workforce shortages is much more basic. A protracted decline in birth rates is coinciding with a record wave of retirements, data shows.

From 2024 to 2032, when the last baby boomers sign up for Social Security payments, more than 18 million college-educated workers will leave the labor force while fewer than 14 million enter it, according to the Georgetown center. Meanwhile, even as the number of people with associate and bachelor's degrees falls, the number of jobs requiring them will grow, the center forecasts. That will leave a gap of 4.6 million workers. Lightcast puts the deficit at an even higher 6 million... The effect of population shifts on the supply of talent, with or without degrees, has been compounded by a drop in the proportion of high school graduates choosing to go to college, a sharply reduced rate of immigration, and a growing number of Americans leaving the workforce altogether because of such issues as lack of child care, early retirement, incarceration and substance addiction, according to the Chamber of Commerce.

Three interesting statistics from the article:
  • U.S. college/university enrollment in 2023 was down by nearly 2 million students since its peak in 2010, according to the most recent data from the U.S. Education Department.
  • America's low birth rate since 2010 "means the number of college-age Americans is forecast to decline by another 13 percent through 2041."
  • South Dakota has just 41 workers for every 100 open jobs... while California and nine other states have more workers than jobs, the Chamber of Commerce found.

AI

Linus Torvalds on AI, Junk Patches, Humans, and Godzilla (zdnet.com) 19

Linus Torvalds once said LLMs might bring a 10X increase to programmer productivity. But speaking at Open Source Summit India 2026, he now says that number was "not scientific," reports ZDNet. "That was pulled out of my ass number, obviously." Today, he continued, "we're at the point where hopefully it creates more productivity than it takes away," but "we certainly saw more junk being generated by LLMs than we saw useful code up until the like early this year.... it can actually be a huge drain on resources when it takes humans a lot of effort to figure out that, hey, this machine-generated report was not true." Even now, he said, "most of the good ones require more than just the LLM," because "we've had to push back quite a bit... if you find a bug with an LLM, it's not enough to just ask the LLM to make a bug report and then throw it over the fence to us. We want to see a suggested patch; we want to see the human who ran the LLM act as a kind of back-and-forth."

Torvalds described many AI-generated patches as "mindless band-aid kind of patches... they may fix the immediate problem, but the kind of bug remains, and it just is waiting in the hallway to hit you in another place." For his own toy projects, he uses LLMs as prototypers: "I use them as a way to prototype things... quite often the code is not usable in that form, but it's a great way to try something out," while insisting that for kernel-level fixes, "LLMs, in my experience, have not been at that level yet."

Torvalds acknowledged that some AI-found issues have been "absolutely, stunningly, I mean, interesting in a painful kind of way," especially security problems that "show up in the technology press two days later." Despite the embarrassment, he said, "I'm very much not a shoot-the-messenger kind of person. I think we're much better off with LLMs finding bugs, even when they are embarrassing, and they are things that we should probably have found two decades ago."

Torvalds also said he's using AI "for my own toy projects... Every time I travel to some new place, and this is the first time I've been to India, I send the kids pictures of where I am, and for some strange reason, Godzilla seems to follow me around and gets added to those pictures."

ZDNet notes that Torvalds concluded, "There are many useful and less useful uses for AI," and "I think Godzilla is a great place to stop."

Thanks to Slashdot reader joshuark for sharing the article.
GUI

Is the COSMIC Desktop Getting Better Than KDE and GNOME? (xda-developers.com) 42

"While KDE and GNOME dominate the landscape, a relative newcomer is starting to make waves with features other desktops still don't fully support," argues XDA Developers: Linux 7.0 was the first release of the kernel to officially support Rust, but COSMIC has been all-in on Rust since the very beginning, and COSMIC 1.1 finally stripped all the leftovers of C language from the desktop. It no longer has any traces of Nautilus (the GNOME file manager), and then there's now a COSMIC-native system monitor to replace the GNOME System Monitor, so you have even fewer chances of being afflicted by C-related problems. [The article calls COSMIC's system monitor "much better at showing detailed information about everything from processes to network and disk usage compared to the GNOME and KDE alternatives."]

Stacking Windows
As someone who used to love following Windows news, one of the most disheartening announcements was when Microsoft gave up on Sets, a feature that essentially turned every app window into a tab you could combine with other apps in the same window. I never thought I'd see that feature again, until COSMIC came along. Simply called "stacking", COSMIC has a feature that is exactly what Sets was supposed to be, though this time, you have more control. By default, apps still open in their proper, typical windows, with a title bar as you'd expect. But if you do want to combine multiple apps into one, you can right-click the title bar (or press Super + S) to enable stacking for that window. Then, simply drag another window over that one to start stacking them as tabs. This essentially gives you a whole new way to create "workspaces", as you can have a single window with all the tools you need, so you don't need to jump between different windows all the time, and you can keep a given window focused on a specific workload, but have multiple apps within it. It's a great reminder of what Microsoft took from us, too.

Tiling, But On Demand
Tiling windows is one of those features some power users simply love, and yes, there are ways to make it happen on KDE and GNOME with third-party apps or extensions, but those aren't ideal. It's an extra step to set them up, and very often they don't play nice with all the features those desktops offer, especially as new updates come out and those tools may have a hard time keeping up with the development of the desktops themselves. COSMIC is fantastic because not only does it have built-in window tiling, it's entirely controllable by the user. You can set any workspace to use tiling or floating windows depending on your preference, all completely independent of each other, and you can also choose the new default behavior for new workspaces so things are always tuned to your preferences. You can turn tiling on or off for a given workspace easily, and of course, even while tiling is on, you can allow certain apps to ignore it and still float above others. Not all these capabilities are exclusive to COSMIC, but to have this kind of feature built in with this level of control is still leagues better than anything KDE or GNOME offer in this regard.

The article argues COSMIC also makes customization extremely simple without stifling your options (like tweaking color options for your desktop). "This desktop environment just keeps getting better, and it's quickly establishing itself as a major competitor to long-standing alternatives."
AI

OpenAI to Retire ChatGPT Atlas Browser Less Than a Year After Launch 7

OpenAI is retiring its ChatGPT Atlas browser less than a year after launch. Going forward, its browsing features will be shifted into a redesigned ChatGPT desktop app that also combines Codex, a built-in browser, and "ChatGPT Work" for acting across apps and files. PCMag reports: OpenAI disclosed Atlas's retirement in a Thursday post introducing a more powerful ChatGPT desktop app, following reports that the company planned on turning it into a "superapp." [...] In a tweet, OpenAI product staff member James Sun added, "The current targeted date for deprecation is 8/9, and we'll share more information in the upcoming days both in-app and via email."

The sunsetting means the Windows version of ChatGPT Atlas has been canceled, though the ChatGPT desktop app is still available on both Mac and Windows. The company is already touting the built-in browser, noting: "You can ask ChatGPT to research a market, compare sources, pull information from websites, or open and refine files from Google Workspace and Microsoft 365 inside the app. It can use the browser to bring in fresh context, take steps across web pages, and keep the work moving while you review and guide the result."
AI

Lawmakers Probe Growing Use of Chinese AI Models In US Companies (cnbc.com) 109

U.S. lawmakers are probing the growing use of Chinese AI models by American companies, citing concerns over censorship, security risks, and whether U.S. firms are turning to cheaper foreign models because domestic alternatives are too costly or restricted. The investigation is specifically looking at companies such as Cursor and Airbnb. "The growing use of Chinese AI models by U.S. companies raises serious concerns," a State Department spokesperson told CNBC. Those "AI models are designed to advance Beijing's narratives, censor dissent, and reflect CCP ideology and values." CNBC reports: The House Committee on Homeland Security and the House Select Committee on China said in April they will jointly investigate the growing adoption of Chinese-developed AI models. An initial step in the probe was for the chairmen of those committees to send letters to Cursor and Airbnb, over their "use of or exposure to these risks" through AI developed in China. "The Chinese Communist Party is no longer just nipping at our heels in artificial intelligence; it is racing to close the gap in some of the exact capabilities that will shape the future of cybersecurity," Andrew Garbarino, chairman of the U.S. House Committee on Homeland Security, told CNBC. "Recent reporting that a Chinese open-weight model can match leading U.S. models in certain vulnerability discovery and cybersecurity tasks is highly alarming," said Garbarino.

While some government departments have banned the usage of Chinese AI models including DeepSeek, adoption of them by U.S. companies is not prohibited. Tech chiefs, including crypto company Coinbase's Brian Armstrong and AI startup Lindy's Flo Crivello, have been publicly touting the use of models from China to reduce costs. Cursor, which will be acquired by Elon Musk's SpaceX for $60 billion, built its Composer 2 model using Chinese AI model Kimi, which was developed by Moonshot AI. Alongside focusing on the rise of Chinese AI models, the ongoing joint House Committees' investigation is also looking into whether the U.S. is doing enough to tackle their rise. "The Committees are also examining whether the United States has a sufficient open-weight AI strategy to ensure American companies and cyber defenders are not forced to choose between expensive or restricted U.S. models and cheap, capable PRC-developed alternatives," a Committee aide, who asked not to be named as they were not authorized to discuss the ongoing probe, told CNBC.

[...] The administration could consider the use of federal procurement bans, which would include restricting government agencies and private companies that serve the U.S. government from using Chinese AI models, Kyle Chan, fellow in the John L. Thornton China Center at think tank Brookings, told CNBC. "However, it's ultimately impossible to ban China's open-source AI models because their model weights are available freely on the internet," Chan added. "This could enter into first amendment speech issues." [...] Another [approach] could be disseminating findings about risks and vulnerabilities associated with Chinese AI models to U.S. companies. "Regardless, I do expect both the Executive Branch and Congress to communicate their interest not to see U.S. companies adopting these models," [said Daniel Remler, senior fellow, technology and national security program at think tank the Center for a New American Security (CNAS), told CNBC].

Open Source

Google Hands Open Health Stack To the Linux Foundation (nerds.xyz) 7

BrianFagioli writes: The Linux Foundation intends to launch the Open Health Stack Software Foundation, a new vendor-neutral home for the Google Open Health Stack project. Google is contributing the project code and assets while Google.org is providing a $3 million grant. The initiative is also backed by Microsoft, Anthropic, and the World Health Organization, with the goal of building open source, AI-ready digital health infrastructure. Will moving the project under Linux Foundation governance accelerate adoption, or is this simply another foundation that most developers will never interact with? The new project will focus on core HL7 FHIR technologies for healthcare interoperability, the Open Health Stack Player deployment toolkit, and AI Commons -- a model-agnostic healthcare AI initiative being co-developed with the World Health Organization.

A notable part of the announcement is its planned Implementer Program, which aims to give startups, small businesses, and local developers in low- and middle-income countries a formal role in governance. In other words, the effort is not just about building healthcare software standards, but about making sure the people implementing them in underserved markets help shape the project too.
The Almighty Buck

San Francisco Moves To Build Private Luxury Airport Terminal (theguardian.com) 176

An anonymous reader quotes a report from The Guardian: The [San Francisco international airport] is hoping to build a brand-new terminal exclusively for passengers who pay a premium, gaining access to a luxurious airport experience complete with private security lines and valet service from terminal to tarmac. It will service commercial flights, not business or corporate jets, and the terminal will have its own Transportation Security Administration (TSA) lines as well as Customs and Border Protection (CBP) lines for international travel.

SFO is seeking bidders to take on the development, construction and operation of the private terminal, which is planned for a 75,000-sq-ft site located across the runway from all current public terminals. The airport will accept proposals between late September and early October, and is looking to award a contract by early December with hopes of opening the terminal in late 2028. [...]

If SFO is successful, it would become the next major American airport to open a luxury terminal. Los Angeles, Dallas Fort Worth, Miami and Hartsfield-Jackson Atlanta international airports all offer a private terminal through PS (formerly known as the Private Suite), a company owned by security firm Gavin de Becker and Associates. Multiple representatives from PS and Gavin de Becker and Associates attended a June conference hosted by SFO about the private terminal, and PS has said it hopes to open a private terminal at every major US airport by 2030.
The report notes that access to existing PS private terminals "can cost passengers $1,295 for a one-time experience, or up to $4,850 for a yearly membership."
Unix

Zombie 'Who Owns Unix?' Lawsuit Comes Alive Again (theregister.com) 109

The long-running SCO/IBM Unix and Linux ownership dispute has resurfaced yet again, this time through SCO successor Xinuos, which is trying to pursue old license and copyright claims tied to Project Monterey. "The core issue seems to be whether Xinuos even has the right to litigate the matter, or if some ancient legalese in the original agreements means the window for legal argument has long since expired," reports The Register. From the report: [T]he roots of the case are the 1998 alliance between IBM and a company called the Santa Cruz Operation which sold a version of UNIX for x86 CPUs. Those two companies, plus Intel and Sequent, created "Project Monterey" -- an effort to create a unified version of UNIX that could run on multiple processors. By 2001, Project Monterey was close to delivering a unified UNIX, an achievement made possible by blending code from IBM and SCO.

By then, a little project called "Linux" already ran on multiple processors. Big Blue decided Linux was the future and bailed from Project Monterey -- then allegedly contributed some Monterey code to the open-source project and to its own AIX and Z operating systems. SCO felt it owned some of that code, so sued IBM.

SCO and its successors struggled to survive, but interested parties kept the lawsuit alive because the chance to emerge as owner of parts of the Linux codebase, and IBM's code, had the potential to turn into a colossal payday. The case and its successors ended in 2021, with a settlement that saw litigants agree to end the matter without IBM admitting fault. But by then, SCO had sold its software to a biz called Xinuos that decided to fight on.

The Xinuos case has burbled along quietly since, and on June 22nd reached the milestone of a hearing. The matter has become a little more modern, if only because this hearing was held online and the presiding judge appeared to unwittingly be on mute at one point. But the arguments otherwise seemed to revisit Project Monterey, debated the relevance of past litigation, contested who owned what, when they owned it, and how they could prove it. Xinuos argued IBM never had a license for SCO code. Big Blue argued that it did nothing wrong.

AI

Big Companies That Invest Heavily in AI Also Hire More People, Report Suggests (techcrunch.com) 29

"Companies spending heavily on AI are growing headcount faster, even in the entry-level roles that many fear are doomed," writes TechCrunch. That's the conclusion of new report tracking AI spending from Ramp's corporate card/bill pay data as well as Revelio Labs' workforce records from 21,599 U.S. firms: According to the report, "high-intensity adopters" — firms that spend on average $30 per employee per month on AI in the first three months — saw headcount increase 10.2%. Headcount also rose across functions, including engineering, sales, administration, customer service, finance, marketing, and scientist roles. The strongest job growth among high-intensity adopters was in the information sector, which includes software, internet, media, and tech-adjacent firms.

Despite these positive signals, the data isn't as rosy as it seems. It skews heavily toward tech-forward, knowledge-work firms — ones that might have VC-backing and are growing fast anyway, making it difficult to say whether AI is contributing to the hiring or just showing up at companies that are expanding anyway. "This paper does not show that AI universally creates jobs," the paper's authors admit, "but it does counter claims that AI will lead to broad job losses."

It also counters claims that AI is killing all junior jobs. Recent research from Goldman Sachs found that AI has already erased about 16,000 net jobs per month over the past year, with Gen Z and entry-level workers taking the brunt of the burden. But in tech-forward firms, the report finds that entry-level headcount actually rose by 12%... "For software and technology firms, AI can make core output cheaper or faster to produce: writing code, debugging, building internal tools, producing technical documentation, and supporting product development," the report reads. "Lower production costs in these workflows can raise the return to expanding the whole firm, not just the engineering team."

But companies that buy subscriptions and run pilots, yet did not go on to make sustained investments, don't tend to see any gains in headcount, per the report. That sets up the potential for a widening gap between firms that have the resources — like capital, technical staff, founder networks, and management bandwidth — to turn AI adoption into actual business gains and those that are stuck experimenting with subscriptions. In other words, this report suggests that firms that already have the resources are the ones that will see the largest gains.

CNBC argues another AI "narrative" was challenged this week: that open source can't make money. "The assumption was that giving your model away for free meant no business. That's breaking too, as open-model companies start posting real revenue and enterprises move from renting AI to running their own."
Linux

Ask Slashdot: Which Apps Aren't Available on Linux? 244

Have you ever needed a Linux application which only exists in the Windows world? Long-time Slashdot reader BrendaEM writes: Windows does have a lot of useful app (but smaller than "power apps"). Some of these are closed source, some are open, but they're not all available in Linux yet.

My list would have to contain Gimp Tookit versions of: IrfanView image manager, which I think is unequaled in Linux (though it does work to some extent under Wine). I also miss the full version of 7-Zip, because of its better compression settings, which File-Roller does not provide, though the Linux port p7zip is available (though unnoticed by common distributions). Lastly, I think that Notepad++ would be a good addition to Linux.

That last one drew some pushback from long-time Slashdot reader jesco. "If there's one area where Linux shines, then it's the availability of high-quality text editors. Last time I looked Kate was still pretty nice, and there's Emacs, Vim and Neovim" if you're partial to command lines. But are there any daily-drive apps you still find yourself needing? Share your own thoughts in the comments.

Which apps aren't available on Linux?
AI

Decades-Old Bash Tricks Expose AI Coding Agents To Supply Chain Attacks (securityweek.com) 26

Slashdot reader wiredmikey writes: AI security researchers have uncovered a structural security flaw dubbed GuardFall that allows decades-old Bash shell tricks to bypass safeguards in most open source AI coding agents. By exploiting shell behaviors such as quote removal and variable expansion, attackers can hide malicious commands in repositories, README files, Makefiles, or other content consumed by AI agents. If executed — particularly in auto-approve or CI environments—the commands can steal credentials, compromise developer systems, or enable software supply chain attacks. According to researchers at Adversa AI, the 11 popular open source AI coding agents tested, only one successfully blocked all of the Bash trick techniques.
Open Source

Valve Open-Sources Steam Machine's E-Ink Display (gamingonlinux.com) 45

Valve has open-sourced the design for a customizable e-ink front panel for the Steam Machine, dubbed the "Inkterface." "All of it is available on their GitLab under the MIT license, which goes over everything you need to make your own and stick it on the front of your fancy new Steam Machine," reports GamingOnLinux. From the report: They're now calling it the "Inkterface" and there's a good few things you'll need to make it including:
1 x Adafruit ESP32 Feather with 2MB PSRAM.
1 x Adafruit eInk Breakout Friend.
1 x Adafruit 5.83" Monochrome eInk Panel.
13 x M2.5 x 5mm Pan Head Machine Screws.
4 x 1/4" x 1/4" x 3/16" Stepped Magnet SB443-OUT.

Valve even provided a video on the GitLab showing it being put together [...].

Security

AI Agent Executes 'First' End-To-End Ransomware Attack 36

Sysdig says it has documented the first ransomware attack carried out end to end by an AI agent, which autonomously exploited exposed systems, stole credentials, established persistence, compromised a production database, and destroyed data. The research team named the attacker "JadePuffer" and said it gained initial access to an internet-facing Langflow instance by exploiting CVE-2025-3248. "The most striking characteristic, however, was the LLM's behavior," Sysdig director of threat research Michael Clark said in a blog post. An anonymous reader quotes an excerpt from The Register: JadePuffer's "self-narrating" payloads "contained natural language reasoning, target prioritization, and the kind of detailed annotations that human operators don't often write but LLM-generated code produces reflexively," Clark added. "The operation also adapted in real time, retrying failed steps within refined parameters. In one sequence, it went from a failed login to a working fix in 31 seconds." After exploiting CVE-2025-3248, a missing authentication vulnerability in Langflow that allows remote, unauthenticated attackers to execute arbitrary Python on the host, the AI agent began scanning for and collecting secrets, including LLM provider API keys, cloud credentials "with explicit coverage of Chinese providers" including Alibaba, Aliyun, Tencent, and Huawei, while also scanning for AWS, Azure and Google Cloud Platform, cryptocurrency wallets, and database credentials.

The AI also installed a crontab entry on the Langflow server to maintain persistence and call back to the attacker's infrastructure every 30 minutes. JadePuffer's intended target was a separate internet-exposed production server running a MySQL database and an Alibaba Nacos configuration service, we're told. Nacos is an open-source service-discovery and dynamic configuration platform developed by Alibaba and used in the cloud provider's microservices applications. The agent connected to the server's exposed MySQL port using root credentials, although Sysdig doesn't know how the attacker obtained them. These credentials weren't stolen from the victim's environment.

JadePuffer then attacked Nacos via multiple vectors including an authorization bypass flaw (CVE-2021-29441) and forging a valid JSON web token (JWT) using Nacos's default signing key. Additionally, using its root database access, the LLM injected a backdoor administrator into the Nacos backing database. It ultimately encrypted all 1,342 Nacos service configuration items using MySQL's built-in AES encryption function, and created an extortion demand, ransom note, Bitcoin payment address, and a Proton Mail contact [...]. However, according to the threat hunters, the victim can't recover the encrypted data, even if they paid the ransom demand, because the agent escalated "from row-level deletion to dropping entire database schemas, narrating its own targeting rationale," without backing up any of the encrypted data.
AI

Godot Game Engine No Longer Accepts AI Code 70

The Godot Foundation will stop accepting AI-authored code, agent-submitted pull requests, and AI-generated text in contributor communications after maintainers were overwhelmed by low-effort submissions. "It is time for us to recognize that these problems aren't going away and therefore we need to take steps to reduce the burden on maintainers while ensuring we still have a pipeline to mentor new contributors to become future maintainers," the Godot Foundation said in a blog post. Contributors may still use AI for limited "menial things" if they disclose it, but humans must understand, own, and be able to fix the code they submit. PC Gamer reports: The Foundation says the pileup of Godot pull requests pending review isn't all bad: It's a sign that interest in using and contribution to Godot is increasing. But the influx of contributions authored or submitted by AI is sapping the projects' maintainers of their willingness to confront the "already tedious" work of reviewing pull requests. "If your feedback on PRs is just being absorbed by a machine and not going towards mentoring a potential future maintainer, it becomes much harder to justify spending your free time on PR review," the Foundation said.

As the problem becomes increasingly unsustainable, the Godot Foundation says it's in the process of updating its contribution policies, focusing on "adding barriers to low-effort slop" contributions, encouraging maintainers to review code, developing new contributors into future maintainers, and crucially, requiring that all contributions come from humans who are accountable for their code -- and fixing it if it fails. "AI cannot take responsibility, and we can't trust heavy users of AI to understand their code enough to fix it," the Foundation said.

The Foundation says we can expect Godot's contributing policy to soon include explicit rejections of AI-authored code, noting that contributors should only use AI assistance for "menial things" and must disclose its use. Additionally, the Foundation will reject any AI-generated text in human-to-human communications, saying it's "a basic principle of respect" -- though it says machine translations "are still acceptable" if the original text was human-authored. "Things change every day with respect to the current suite of AI tools available," the Foundation said. "We will continue taking a conservative approach in our policies towards them, but we will re-evaluate as things evolve."
Social Networks

Reddit Will Require You To Log In To Use Old Reddit (arstechnica.com) 89

An anonymous reader quotes a report from Ars Technica: Reddit will start requiring people to be logged into Reddit to use old.reddit.com. The new requirement will take effect "over the next month," a Reddit employee going by the username boat-botany announced on the social media platform today. The person claimed that the change is part of an ongoing effort to "tighten how automated systems access Reddit."

The Reddit employee wrote: "Old Reddit's logged-out experience is a significant source of abusive scraping and automated traffic on the platform. It's also an important interface for many long-time mods and Redditors. To strike the right balance between preserving your access to Old Reddit while preventing abusive scraping and automated traffic, over the next month we will start requiring everyone to log in."

In a follow-up comment, boat-botany defined abusive behavior as that which violates Reddit's rule prohibiting activity that interferes with the platform's "normal use" or that "create[s] programs or applications" that break Reddit's (controversial) API rules. "By logging in, we get a lot more signal that allows us to detect whether an account is breaking the rules, and then we can block that traffic or enforce those accounts," boat-botany said.
Asked why boat-botany scrapes New Reddit less frequently than Old Reddit, the Reddit employee pointed to another commenter's explanation. "[T]he shape of malicious traffic is always changing," the user, Nestramutat, wrote. "It's going to be a constant cat and mouse game[.] As you ban one method, a new one gets developed. It's easy to see abusive traffic in hindsight, but it's harder to pre-emptively block it. Given that they're claiming Old Reddit doesn't have the modern security stack, this is likely proving to be an even greater challenge."

Nestramutat said that the login requirement will add a barrier against threat actors. "You're also now attaching an account ID to every malicious request, plus account creation is only available on New Reddit (with the enhanced security stack)."

As for how long Old Reddit will exist, boat-botany left the door open for its retirement. "We can't promise it will be around forever, but [Reddit CEO Steve Huffman] himself has said we'll keep supporting it while folks are still using it," boat-botany wrote. "That said, it doesn't have the same modern security tech stack reddit.com has, so we need to tighten security on old reddit to keep it viable."
Piracy

Amazon Blames Piracy Apps With Malware For Killing New Fire Stick Sideloading (arstechnica.com) 32

Amazon says it is ending sideloading on new Fire Sticks because "apps that facilitate piracy, and other apps, can carry malware," adding that there is "a good amount of evidence" that sideloaded apps may contain unwanted code or behavior. However, the company did not provide specific examples of Fire Stick users being harmed. Ars Technica reports: Amazon has released two Fire Stick models that use its proprietary, Linux-based operating system, Vega OS. Previous Fire Sticks ran Fire OS, which is an Android fork based on the Android Open Source Project. One of the biggest differences between Vega OS and Fire OS is that the former doesn't support sideloading. [...] In a recent interview, Or Goren, editor-in-chief of Cord Busters, a UK-based streaming news outlet, noted the negative reaction to Vega being a closed OS. [Aidan Marcuss, VP of Fire TV, advertising, and Appstore] responded, per the publication, by saying that Vega OS was Amazon's opportunity to "innovate and deliver more capabilities, even on the least expensive devices."

He also said that making a platform around security and privacy was "sort of utmost in my mind." The statement is somewhat ironic, considering Vega OS blocks custom launchers and other third-party apps that helped users avoid Amazon tracking and ads. Goren asked whether Amazon had evidence that sideloaded devices caused users harm. "Apps that facilitate piracy, and other apps, can carry malware," Marcuss responded. Marcuss also said that there is "a good amount of evidence that apps can carry unwanted code and behavior on them when they're sideloaded."

Marcuss didn't provide specific examples of Fire Stick users being hurt by sideloaded apps. There are some potential examples, though. In 2025, Amazon claimed to blacklist (which blocked the apps from being sideloaded to Fire Sticks) four video streaming apps for malicious behavior. At the time, AFTVnews reported that two of the apps served as residential proxy providers and were considered riskware, and that the other two had APK files that were flagged by virus-scanning tools. Safari and Chrome also flagged one of the apps' official websites, the publication reported. And in 2018, a botnet that infected Android devices with cryptocurrency-mining malware appeared on some Fire Sticks, per discussion on XDA Forums. That said, Amazon also has a history of disabling apps that let users circumnavigate its home screen that Fire devices, including Fire Sticks and Fire TVs, have increasingly used for ads.
Worth noting: developers can continue sideloading apps onto Vega OS devices if they register them with Amazon.

Slashdot Top Deals