United States

Three US Agencies Get Failing Grades For Not Following IT Best Practices (theregister.com) 19

The Government Accountability Office has issued reports criticizing the Department of Homeland Security, Environmental Protection Agency, and General Services Administration for failing to implement critical IT and cybersecurity recommendations.

DHS leads with 43 unresolved recommendations dating to 2018, including seven priority matters. The EPA has 11 outstanding items, including failures to submit FedRAMP documentation and conduct organization-wide cybersecurity risk assessments. GSA has four pending recommendations.

All three agencies failed to properly log cybersecurity events and conduct required annual IT portfolio reviews. The DHS' HART biometric program remains behind schedule without proper cost accounting or privacy controls, with all nine 2023 recommendations still open.
Medicine

Man Controls iPad With His Mind Using Synchron Brain Implant (nerds.xyz) 14

BrianFagioli shares a report from NERDS.xyz: Synchron has just released a public demo showing something that used to feel impossible. A man with ALS is now using his iPad with nothing but his brain. No hands. No voice. No eye-tracking. Just thought. The man in the video is named Mark. He's part of Synchron's COMMAND clinical study and has an implant called the Stentrode. It sits inside his brain's blood vessels and picks up his motor intention. Those signals get sent wirelessly to an external decoder, which then tells the iPad what to do. It's all made possible by Apple's new Brain-Computer Interface Human Interface Device protocol, which lets iPadOS treat brain activity like an actual input method.

Apple's built-in Switch Control feature makes the whole thing work on the software side. The iPad even sends back screen context to the BCI decoder to make everything run more smoothly and accurately. [...] Synchron was the first company to start clinical trials with a permanently implanted BCI. The big difference here is that it doesn't require open brain surgery. The device is implanted through the blood vessels, which makes it way more practical for real-world use.

IBM

Vortex's Wireless Take On the Model M Keyboard: Cover Band Or New Legend? (ofb.biz) 74

IBM's legendary Model M keyboard was sturdy and solid. But "What would happen if you took the classic layout and look of the Model M and rebuilt it with modern mechanical guts?" asks long-time Slashdot reader uninet. Writing for the long-running tech blog Open for Business , they review a new wireless keyboard from Vortex that was clearly inspired by the Model M: The result is a unique keyboard with one foot in two different decades... Let's call it the Vortex M for simplicity's sake.

I first became aware of it on a Facebook ad and was immediately fascinated. It looked so close to the original Model M, I wondered if someone else had gotten access to an original mold and was trying Unicomp's game. No, they've just managed to copy the aesthetic to a nearly uncanny level... The Vortex M eschews the normal eye candy we expect on modern keyboards and attempts the closest duplication of IBM's staid early PC design sensibility I can imagine. Off-white, rugged and absolutely no frills of lighting. If you're looking for cutesy, forget it.

The keyboard's casing has the same highly textured plastic that looks and feels instantly familiar to anyone who spent too many hours interacting with early PCs. Model M to a tee. The keycaps likewise look the part... The Vortex M looks like a Model M. Its build quality feels like a Model M. But one key press and it becomes clear this is a different beast. Underneath the Model M-styled skin, Vortex's keyboard is a very modern design — everything the Unicomp is not. For our test, Vortex provided a keyboard with Cherry MX Blues, the classic clicky option the company and I both thought would best match up against Model M's buckling springs...

Vortex's product configurator offers a variety of common and less common Cherry and Gateron options, if you want to get a different sort of feel in lieu of the clicky I tested. This is possible with an MX switch-style keyboard and impossible with buckling springs with their one option of bold clicky. Not only can this be done when ordering, but also later on, thanks to hot swap switches that allow changes without soldering. Following the modern premium board theme, Vortex paired high end switches with a gasket mount and foam padding. The combination provides a solid feeling, sound dampened typing experience. Ironically, though, for a keyboard that apes the design of perhaps the loudest keyboard on the market today, the Vortex M is (relatively) quiet even with the clicky Blues on tap...

The review's highlights:
  • "The keyboard is exquisitely crafted to look like the IBM original... "
  • "The Vortex M supports connecting to three different devices via Bluetooth, along with a 2.4 GHz receiver and a USB Type-C wired connection. "
  • There's a full complement of media hot keys — "including an emoji key ala recent Macs. "
  • "For repetitive tasks, the keyboard is programmable with macros... And unlike Unicomp's boards, Vortex's can switch between PC and Mac layouts with the press of a hotkey."
  • The keyboard uses AA batteries rather than having a built-in rechargeable battery

The keyboard ultimately gave the reviewer some cognitive dissonance. "How am I typing on a Model M and not making a racket...?"

"Pricing varies based on options, but as tested, it clocked in at $154. That's the low end of the 'premium' market and this is an exceptional board for that price."


China

Facing US Chip Restrictions, China Pitches Global Cooperation on AI (msn.com) 13

In Shanghai at the World Artificial Intelligence Conference (which ran until Tuesday), the Chinese government "announced an international organization for AI regulation and a 13-point action plan aimed at fostering global cooperation to ensure the technology's beneficial and responsible development," reports the Washington Post.

The theme of the conference was "Global Solidarity in the AI Era," the article notes, and "the expo is one part of Beijing's bid to establish itself as a responsible AI leader for the international community."

CNN points out that China's announcement comes "just days after the United States unveiled its own plan to promote U.S. dominance." Chinese Premier Li Qiang unveiled China's vision for future AI oversight at the World AI Conference, an annual gathering in Shanghai of tech titans from more than 40 countries... While Li did not directly refer to the U.S. in his speech, he alluded to the ongoing trade tensions between the two superpowers, which include American restrictions on advanced semiconductor exports — a component vital for powering and training AI, which is currently causing a shortage in China. "Key resources and capabilities are concentrated in a few countries and a few enterprises," said Li in his speech on Saturday. "If we engage in technological monopoly, controls and restrictions, AI will become an exclusive game for a small number of countries and enterprises...."

Secretary-General of the Association of Southeast Asian Nations, Dr. Kao Kim Hourn, also called for "robust governance" of artificial intelligence to mitigate potential threats, including misinformation, deepfakes, and cybersecurity threats... Former Google CEO Eric Schmidt reiterated the call for international collaboration, explicitly calling on the U.S. and China to work together... "We have a vested interest to keep the world stable, keep the world not at war, to keep things peaceful, to make sure we have human control of these tools."

China's plan "called for establishing an international open-source community," reports the Wall Street Journal, "through which AI models can be freely deployed and improved by users." Industry participants said that plan "showed China's ambition to set global standards for AI and could undermine the U.S., whose leading models aren't open-source... While the world's best large language model is still American, the best model that everyone can use free is now Chinese."

"The U.S. should commit to ensuring that powerful models remain openly available," argues an opinion piece in The Hill by Stability AI's former head of public policy. Ubiquity is a matter of national security: retreating behind paywalls will leave a vacuum filled by strategic adversaries. Washington should treat open technology not as a vector for Chinese Communist Party propaganda but as a vessel to transmit U.S. influence abroad, molding the global ecosystem around U.S. industry. If DeepSeek is China's open-source "Sputnik moment," we need a legislative environment that supports — not criminalizes — an American open-source Moon landing.
Google

Google Has Just Two Weeks To Begin Cracking Open Android, It Admits in Emergency Filing 14

An anonymous reader shares a report: Yesterday, when Epic won its Google antitrust lawsuit for a second time, it wasn't quite clear how soon Google would need to start dismantling its affirmed illegal monopoly.

Today, Google admits the answer is: 14 days. Google has just 14 days to enact major changes to its Google Play app store, and the way it does business with phonemakers, cellular carriers, and app developers, unless it wins an emergency stay (pause) from the Ninth Circuit Court of Appeals as it continues to appeal. It must stop forcing apps to use Google Play Billing, allow app developers to freely steer their users to other platforms, and limit the perks it can offer in exchange for preinstalled apps, among other changes.
IT

Belgium Bans Internet Archive's 'Open Library' (torrentfreak.com) 34

A Brussels court has issued an unusually broad site-blocking order targeting Internet Archive's Open Library alongside shadow libraries including Anna's Archive, Libgen, and Z-Library. The order, requested by publishing and author organizations, directs an unprecedented range of intermediaries to take action beyond traditional ISP blocks.

Search engines, DNS resolvers, advertisers, domain name services, CDNs, hosting companies, and payment processors -- including Google, Microsoft, Cloudflare, Amazon Web Services, PayPal, and Starlink -- must restrict access to the targeted sites. The court found "clear and significant infringement" in the ex parte proceeding.
Security

In Search of Riches, Hackers Plant 4G-Enabled Raspberry Pi In Bank Network (arstechnica.com) 54

Hackers from the group UNC2891 attempted a high-tech bank heist by physically planting a 4G-enabled Raspberry Pi inside a bank's ATM network, using advanced malware hidden with a never-before-seen Linux bind mount technique to evade detection. "The trick allowed the malware to operate similarly to a rootkit, which uses advanced techniques to hide itself from the operating system it runs on," reports Ars Technica. Although the plot was uncovered before the hackers could hijack the ATM switching server, the tactic showcased a new level of sophistication in cyber-physical attacks on financial institutions. The security firm Group-IB, which detailed the attack in a report on Wednesday, didn't say where the compromised switching equipment was located or how attackers managed to plant the Raspberry Pi. Ars Technica reports: To maintain persistence, UNC2891 also compromised a mail server because it had constant Internet connectivity. The Raspberry Pi and the mail server backdoor would then communicate by using the bank's monitoring server as an intermediary. The monitoring server was chosen because it had access to almost every server within the data center. As Group-IB was initially investigating the bank's network, researchers noticed some unusual behaviors on the monitoring server, including an outbound beaconing signal every 10 minutes and repeated connection attempts to an unknown device. The researchers then used a forensic tool to analyze the communications. The tool identified the endpoints as a Raspberry Pi and the mail server but was unable to identify the process names responsible for the beaconing.

The researchers then captured the system memory as the beacons were sent. The review identified the process as lightdm, a process associated with an open source LightDM display manager. The process appeared to be legitimate, but the researchers found it suspicious because the LightDM binary was installed in an unusual location. After further investigation, the researchers discovered that the processes of the custom backdoor had been deliberately disguised in an attempt to throw researchers off the scent.

[Group-IB Senior Digital Forensics and Incident Response Specialist Nam Le Phuong] explained: "The backdoor process is deliberately obfuscated by the threat actor through the use of process masquerading. Specifically, the binary is named "lightdm", mimicking the legitimate LightDM display manager commonly found on Linux systems. To enhance the deception, the process is executed with command-line arguments resembling legitimate parameters -- for example, lightdm -- session child 11 19 -- in an effort to evade detection and mislead forensic analysts during post-compromise investigations. These backdoors were actively establishing connections to both the Raspberry Pi and the internal Mail Server."

Security

CISA Open-Sources Thorium Platform For Malware, Forensic Analysis (bleepingcomputer.com) 7

CISA has publicly released Thorium, a powerful open-source platform developed with Sandia National Labs that automates malware and forensic analysis at massive scale. According to BleepingComputer, the platform can "schedule over 1,700 jobs per second and ingest over 10 million files per hour per permission group." From the report: Security teams can use Thorium for automating and speeding up various file analysis workflows, including but not limited to:

- Easily import and export tools to facilitate sharing across cyber defense teams,
- Integrate command-line tools as Docker images, including open-source, commercial, and custom software,
- Filter results using tags and full-text search,
- Control access to submissions, tools, and results with strict group-based permissions,
- Scale with Kubernetes and ScyllaDB to meet workload demands.

Defenders can find installation instructions and get their own copy of Thorium from CISA's official GitHub repository.

Google

Google Loses Epic Games Appeal, Must Open App Store To Rivals (reuters.com) 42

Google lost its appeal Thursday of a judge's order that will force the tech giant to open up its app store to competitors. The 9th Circuit Court of Appeals upheld a lower court ruling requiring Google Play to allow rival marketplaces and billing systems, ending a legal battle that began when Epic Games sued over anticompetitive practices.

A jury sided with Epic in December 2023, finding Google paid phone makers and app developers to use its store exclusively.
Data Storage

'The Future is Not Self-Hosted' (drewlyton.com) 175

A software developer who built his own home server in response to Amazon's removal of Kindle book downloads now argues that self-hosting "is NOT the future we should be fighting for." Drew Lyton constructed a home server running open-source alternatives to Google Drive, Google Photos, Audible, Kindle, and Netflix after Amazon announced that "Kindle users would no longer be able to download and back up their book libraries to their computers."

The change prompted Amazon to update Kindle store language to say "users are purchasing licenses -- not books." Lyton's setup involved a Lenovo P520 with 128GB RAM, multiple hard drives, and Docker containers running applications like Immich for photo storage and Jellyfin for media streaming. The technical complexity required "138 words to describe but took me the better part of two weeks to actually do."

The implementation was successful but Lyton concluded that self-hosting "assumes isolated, independent systems are virtuous. But in reality, this simply makes them hugely inconvenient." He proposes "publicly funded, accessible, at cost cloud-services" as an alternative, suggesting libraries could provide "100GB of encrypted file storage, photo-sharing and document collaboration tools, and media streaming services -- all for free."
Medicine

A Pill for Sleep Apnea Could Be on the Horizon 61

Promising Phase 3 trial results from Apnimed suggest a potential game-changing oral pill for sleep apnea could offer a simpler, more tolerable alternative for keeping airways open during sleep. The New York Times reports: For decades, the primary treatment for sleep apnea has been continuous positive airway pressure (or CPAP). Before bed, those with the condition put on a face mask that is connected to a CPAP machine, which keeps the airway open by forcing air into it. The machines are effective, but many find them so noisy, cumbersome or uncomfortable that they end up abandoning them. Now, a more appealing option may be on the way, according to a news release from Apnimed, a pharmaceutical company focused on treating sleep apnea. On Wednesday, the company announced a second round of positive Phase 3 clinical trial results for a first-of-its-kind oral pill that can be taken just before bedtime to help keep a person's airway open.

The full results have not yet been released, or published in a peer-reviewed journal. But the findings build on past, similarly positive conclusions from trials and studies. Sleep experts say that what they're seeing in reports so far makes them think the pill could be a game changer. Dr. Phyllis Zee, a sleep doctor and researcher at Northwestern Medicine who was not involved with the trial, said that if approved, the drug could transform the lives of many. That includes not only those who can't tolerate CPAP machines, but also those who can't -- or prefer not to -- use other interventions, such as other types of oral devices or weight loss medications. (Excess weight is a risk factor for sleep apnea.)
AI

Cisco Donates the AGNTCY Project to the Linux Foundation 7

Cisco has donated its AGNTCY initiative to the Linux Foundation, aiming to create an open-standard "Internet of Agents" to allow AI agents from different vendors to collaborate seamlessly. The project is backed by tech giants like Google Cloud, Dell, Oracle and Red Hat. "Without such an interoperable standard, companies have been rushing to build specialized AI agents," writes ZDNet's Steven Vaughan-Nichols. "These work in isolated silos that cannot work and play well with each other. This, in turn, makes them less useful for customers than they could be." From the report: AGNTCY was first open-sourced by Cisco in March 2025 and has since attracted support from over 75 companies. By moving it under the Linux Foundation's neutral governance, the hope is that everyone else will jump on the AGNTCY bandwagon, thus making it an industry-wide standard. The Linux Foundation has a long history of providing common ground for what otherwise might be contentious technology battles. The project provides a complete framework to solve the core challenges of multi-agent collaboration:

- Agent Discovery: An Open Agent Schema Framework (OASF) acts like a "DNS for agents," allowing them to find and understand the capabilities of others.
- Agent Identity: A system for cryptographically verifiable identities ensures agents can prove who they are and perform authorized actions securely across different vendors and organizations.
- Agent Messaging: A protocol named Secure Low-latency Interactive Messaging (SLIM) is designed for the complex, multi-modal communication patterns of agents, with built-in support for human-in-the-loop interaction and quantum-safe security.
- Agent Observability: A specialized monitoring framework provides visibility into complex, multi-agent workflows, which is crucial for debugging probabilistic AI systems.

You may well ask, aren't there other emerging AI agency standards? You're right. There are. These include the Agent2Agent (A2A) protocol, which was also recently contributed to the Linux Foundation, and Anthropic's Model Context Protocol (MCP). AGNTCY will help agents using these protocols discover each other and communicate securely. In more detail, it looks like this: AGNTCY enables interoperability and collaboration in three primary ways:

- Discovery: Agents using the A2A protocol and servers using MCP can be listed and found through AGNTCY's directories. This enables different agents to discover each other and understand their functions.
- Messaging: A2A and MCP communications can be transported over SLIM, AGNTCY's messaging protocol designed for secure and efficient agent interaction.
- Observability: The interactions between these different agents and protocols can be monitored using AGNTCY's observability software development kits (SDKs), which increase transparency and help with debugging complex workflows
You can view AGNTCY's code and documentary on GitHub.
Businesses

Dog-Walking Startup 'Wag' Files For Bankruptcy (sfgate.com) 89

An anonymous reader quotes a report from SFGATE: During the 2010s' boom in on-demand services such as Uber and DoorDash, Wag staked a claim to the market for dog walking. It became a buzzy, high-flying company, at one point gaining a valuation of around $650 million, and grew to offer a whole range of tech products for pet care. But as the years passed, struggles mounted and profits remained elusive. On July 21, Wag filed (PDF) for bankruptcy. To stay alive, the San Francisco-headquartered company is now using bankruptcy court to restructure in what's known as a Chapter 11 process. Its lines of business -- including gig-work dog walking and sitting, pet insurance, and the veterinary tool "Furscription" -- will remain open, according to a news release. If a judge approves Wag's restructuring plan, it will take the company off the public markets and into the private hands of a company called Retriever.

On the same day of the bankruptcy filing, Wag's chief financial officer, Alec Davidian, submitted a document (PDF) supporting and explaining the move. He wrote that Wag's "monthly revenues declined rapidly after March 2020 as a result of the COVID-19 pandemic" and pointed to $69.5 million in losses from 2022 through 2024. The losses weren't Wag's only problem. The company had taken out debt in 2022 when it went public, and in that loan agreement, it had set a minimum level of cash Wag would need to have on hand at all times. This year, Wag dropped below that amount, Davidian wrote. Wag also failed to find a third-party deal to get more money, the CFO noted, and its debt obligations are set to mature in August, meaning the company was "facing a dire liquidity crisis." So, Wag opted for the bankruptcy proceeding, in which it plans to eliminate the 2022 debt, which is currently held by Retriever.
"Through the Restructuring," Davidian wrote, "[Wag] will emerge from these Chapter 11 Cases a stronger company, with a more sustainable capital structure that is better aligned with [Wag's] present and future operating prospects."
Bitcoin

PayPal Expands Crypto Payments For US Merchants To Lower Cross-Border Fees 34

PayPal has launched "Pay with Crypto" for U.S. merchants, enabling acceptance of over 100 cryptocurrencies with lower cross-border transaction fees and instant conversion to USD or its stablecoin PYUSD. "Businesses of all sizes face incredible pressure when growing globally, from increased costs for accepting international payments to complex integrations," said Alex Chriss, president and chief executive of PayPal. "Today, we're removing these barriers and helping every business of every size achieve their goals. [...] By enabling seamless cross-border crypto payments, we're breaking longstanding barriers in global commerce." SiliconANGLE reports: Using the new Pay with Crypto, merchants can now accept payments in the form of numerous cryptocurrency tokens, including bitcoin, Ethereum, USD Tether and Solana. The transaction fee rate will be 0.99% for the first year, increasing to 1.5% thereafter. The company said that rate is significantly lower than international credit card fees. "Imagine a shopper in Guatemala buying a special gift from a merchant in Oklahoma City," added Chriss. "Using PayPal's open platform, the business can accept crypto for payments, increase their profit margins, pay lower transaction fees, and get near instant access to proceeds."

Merchants who accept cryptocurrency tokens can instantly convert them to dollars or PYUSD, the company's stablecoin, which is a type of cryptocurrency that maintains parity with USD so that every token is always worth $1. Funds stored as PYUSD on PayPal also earn 4% annual rewards. The company said the new service will roll out for U.S. merchants in the coming weeks. [...] Pay with Crypto will initially support cryptocurrency wallets from Coinbase, OKX, Binance, Kraken, Phantom, MetaMask and Exodus, with more planned.
Censorship

Visa and Mastercard Are Getting Overwhelmed By Gamer Fury Over Censorship (polygon.com) 245

An anonymous reader quotes a report from Polygon: In the wake of storefronts like Steam and itch.io curbing the sale of adult games, irate fans have started an organized campaign against the payment processors that they believe are responsible for the crackdown. While the movement is still in its early stages, people are mobilizing with an eye toward overwhelming communication lines at companies like Visa and Mastercard in a way that will make the concern impossible to ignore. On social media sites like Reddit and Bluesky, people are urging one another to get into contact with Visa and Mastercard through emails and phone calls. Visa and Mastercard have become the targets of interest because the affected storefronts both say that their decisions around adult games were motivated by the danger of losing the ability to use major payment processors while selling games. These payment processors have their own rules regarding usage, but they are vaguely defined. But losing infrastructure like this could impact audiences well beyond those who care about sex games, spokespeople for Valve and itch.io said.

In a now-deleted post on the Steam subreddit with over 17,000 upvotes, commenters say that customer service representatives for both payment processors seem to already be aware of the problem. Sometimes, the representatives will say that they've gotten multiple calls on the subject of adult game censorship, but that they can't really do anything about it. The folks applying pressure know that someone at a call center has limited power in a scenario like this one; typically, agents are equipped to handle standard customer issues like payment fraud or credit card loss. But the point isn't to enact change through a specific phone call: It's to cause enough disruption that the ruckus theoretically starts costing payment processors money.

"Emails can be ignored, but a very very long queue making it near impossible for other clients to get in will help a lot as well," reads the top comment on the Reddit thread. In that same thread, people say that they're hanging onto the call even if the operator says that they'll experience multi-hour wait times presumably caused by similar calls gunking up the lines. Beyond the stubbornness factor, the tactic is motivated by the knowledge that most customer service systems will put people who opt for call-backs in a lower priority queue, as anyone who opts in likely doesn't have an emergency going on. "Do both," one commenter suggests. "Get the call back, to gum up the call back queue. Then call in again and wait to gum up the live queue." People are also using email to voice their concerns directly to the executives at both Visa and Mastercard, payment processors that activist group Collective Shout called out by name in their open letter requesting that adult games get pulled. Emails are also getting sent to customer service.

Microsoft

Microsoft Adds Copilot Mode To Edge (windows.com) 49

Microsoft today launched Copilot Mode, an experimental feature that transforms Edge into an AI-powered browser experience. Available free for a limited time on Windows and Mac in markets where Copilot operates, the mode places AI at the center of web browsing through a single input interface combining chat, search, and navigation.

The feature enables Copilot to view content across all open browser tabs, handle voice commands, and assist with tasks like comparing websites. Future capabilities will include booking reservations and managing errands through natural language commands. Microsoft has not specified when the free trial ends, though the feature will likely require a Copilot Pro subscription afterward.
China

Chinese Universities Want Students To Use More AI, Not Less (technologyreview.com) 124

Chinese universities are actively encouraging students to use AI tools in their coursework, marking a departure from Western institutions that continue to wrestle with AI's educational role. A survey by the Mycos Institute found that 99% of Chinese university faculty and students use AI tools, with nearly 60% using them multiple times daily or weekly.

The shift represents a complete reversal from two years ago when students were told to avoid AI for assignments. Universities including Tsinghua, Remin, Nanjing, and Fudan have rolled out AI literacy courses and degree programs open to all students, not just computer science majors. The Chinese Ministry of Education released national "AI+ education" guidelines in April 2025 calling for sweeping reforms. Meanwhile, 80% of job openings for fresh graduates now list AI skills as advantageous.
Open Source

Google's New Security Project 'OSS Rebuild' Tackles Package Supply Chain Verification (googleblog.com) 13

This week Google's Open Source Security Team announced "a new project to strengthen trust in open source package ecosystems" — by reproducing upstream artifacts.

It includes automation to derive declarative build definitions, new "build observability and verification tools" for security teams, and even "infrastructure definitions" to help organizations rebuild, sign, and distribute provenance by running their own OSS Rebuild instances. (And as part of the initiative, the team also published SLSA Provenance attestations "for thousands of packages across our supported ecosystems.") Our aim with OSS Rebuild is to empower the security community to deeply understand and control their supply chains by making package consumption as transparent as using a source repository. Our rebuild platform unlocks this transparency by utilizing a declarative build process, build instrumentation, and network monitoring capabilities which, within the SLSA Build framework, produces fine-grained, durable, trustworthy security metadata. Building on the hosted infrastructure model that we pioneered with OSS Fuzz for memory issue detection, OSS Rebuild similarly seeks to use hosted resources to address security challenges in open source, this time aimed at securing the software supply chain... We are committed to bringing supply chain transparency and security to all open source software development. Our initial support for the PyPI (Python), npm (JS/TS), and Crates.io (Rust) package registries — providing rebuild provenance for many of their most popular packages — is just the beginning of our journey...

OSS Rebuild helps detect several classes of supply chain compromise:

- Unsubmitted Source Code: When published packages contain code not present in the public source repository, OSS Rebuild will not attest to the artifact.

- Build Environment Compromise: By creating standardized, minimal build environments with comprehensive monitoring, OSS Rebuild can detect suspicious build activity or avoid exposure to compromised components altogether.

- Stealthy Backdoors: Even sophisticated backdoors like xz often exhibit anomalous behavioral patterns during builds. OSS Rebuild's dynamic analysis capabilities can detect unusual execution paths or suspicious operations that are otherwise impractical to identify through manual review.


For enterprises and security professionals, OSS Rebuild can...

Enhance metadata without changing registries by enriching data for upstream packages. No need to maintain custom registries or migrate to a new package ecosystem.

Augment SBOMs by adding detailed build observability information to existing Software Bills of Materials, creating a more complete security picture...

- Accelerate vulnerability response by providing a path to vendor, patch, and re-host upstream packages using our verifiable build definitions...


The easiest (but not only!) way to access OSS Rebuild attestations is to use the provided Go-based command-line interface.

"With OSS Rebuild's existing automation for PyPI, npm, and Crates.io, most packages obtain protection effortlessly without user or maintainer intervention."
Star Wars Prequels

George Lucas Makes First Comic-Con Appearance to Discuss His Upcoming 'Museum of Narrative Art' (hollywoodreporter.com) 10

Star Wars creator George Lucas made his first Comic-Con appearance ever on Sunday. The Hollywood Reporter describes the scene: Thousands waited hours just to get inside, chanted "Lu-cas, Lu-cas!" while they waited, and then gave a wild standing ovation as the filmmaker took to the stage, introduced by rapper-actress Queen Latifah, and sat down next to filmmaker Guillermo del Toro and Star Wars production designer Doug Chiang. If the 6,500-strong crowd was disappointed he didn't talk a whiff about Star Wars or Indiana Jones, it wasn't shown, as cries of "I love you, George!" and waving lightsabers punctuated the air several times.

Lucas even received a standing ovation when he left the presentation, which was devoted entirely to the Lucas Museum of Narrative Art. He, along with museum board member and fellow art collector del Toro and Chiang, were there to not only give a first look at the museum but also make a case for the importance and validity of narrative art, which includes comic book art, as a vital form of expression... A video presentation showed interior looks at the museum — there are no right angles anywhere, Latifah underscored — as well as images that will be in the collection.

A cover of DC comic Mystery in Space, featuring the first appearance of Adam Strange; the first ever Flash Gordon comic strip; a cover of 1950s EC comic Tales from the Crypt; strips of Peanuts and Garfield; art ranging from Brian Bolland and Hellboy creator Mike Mignola to underground cartoonist Robert Crumb, Windsor McKay and Moebius; art of Astro Boy and Scrooge McDuck. But there were also images of art by Norman Rockwell, N.C. Wyeth and Frieda Kahlo. Also in the museum will be concept and storyboard art from Star Wars and Raiders of the Lost Ark by Ralph McQuarrie and Jim Steranko, as well as the props of starships and speeders from various Star Wars movies.

Chiang explained that comic art in particular had long been discounted. "It's not taken seriously," he said, and when he was younger was told, "You will outgrow it one day.... I'm so glad I didn't," he said, before driving home the point that one of the strengths of narrative art is that it's driven by story. "Story comes first. Art comes second...."

The museum, which has had its opening pushed back several times, is slated to open in 2026.

More Comic-Con highlights:
  • Breaking Bad creator Vince Gilligan has a new series called Pluribus coming to AppleTV+, a nine-episode sci-fi drama starring Rhea Seehorn from Better Call Saul. (Watch its bizarre trailer here.)

China

Huawei Shows Off 384-Chip AI Computing System That Rivals Nvidia's Top Product (msn.com) 118

Long-time Slashdot reader hackingbear writes: China's Huawei Technologies showed off an AI computing system on Saturday that can rival Nvidia's most advanced offering, even though the company faces U.S. export restrictions. The CloudMatrix 384 system made its first public debut at the World Artificial Intelligence Conference (WAIC), a three-day event in Shanghai where companies showcase their latest AI innovations, drawing a large crowd to the company's booth. The CloudMatrix 384 incorporates 384 of Huawei's latest 910C chips, optically connected through an all-to-all topology, and outperforms Nvidia's GB200 NVL72 on some metrics, which uses 72 B200 chips, according to SemiAnalysis. A full CloudMatrix system can now deliver 300 PFLOPs of dense BF16 compute, almost double that of the GB200 NVL72. With more than 3.6x aggregate memory capacity and 2.1x more memory bandwidth, Huawei and China "now have AI system capabilities that can beat Nvidia's," according to a report by SemiAnalysis.

The trade-off is that it takes 4.1x the power of a GB200 NVL72, with 2.5x worse power per FLOP, 1.9x worse power per TB/s memory bandwidth, and 1.2x worse power per TB HBM memory capacity, but SemiAnalysis noted that China has no power constraints only chip constraints. Nvidia had announced DGX H100 NVL256 "Ranger" Platform [with 256 GPUs], SemiAnalysis writes, but "decided to not bring it to production due to it being prohibitively expensive, power hungry, and unreliable due to all the optical transceivers required and the two tiers of network. The CloudMatrix Pod requires an incredible 6,912 400G LPO transceivers for networking, the vast majority of which are for the scaleup network."



Also at this event, Chinese e-commerce giant Alibaba released a new flagship open-source reasoning model Qwen3-235B-A22B-Thinking-2507 which has "already topped key industry benchmarks, outperforming powerful proprietary systems from rivals like Google and OpenAI," according to industry reports. On the AIME25 benchmark, a test designed to evaluate sophisticated, multi-step problem-solving skills, Qwen3-Thinking-2507 achieved a remarkable score of 92.3. This places it ahead of some of the most powerful proprietary models, notably surpassing Google's Gemini-2.5 Pro, while Qwen3-Thinking secured a top score of 74.1 at LiveCodeBench, comfortably ahead of both Gemini-2.5 Pro and OpenAI's o4-mini, demonstrating its practical utility for developers and engineering teams.

Slashdot Top Deals