China

China's AI Matches Anthropic in Cybersecurity, Causing Worry Over US Restrictions (msn.com) 57

Chinese AI systems "have matched the performance of Anthropic's powerful model Mythos in some cybersecurity scenarios," reports the Wall Street Journal.

They call it "a development poised to reset the global tech race and pressure the White House in its overhaul of U.S. AI policy." Security researchers said that a new AI model, released this month by China's Zhipu AI, also known as Z.ai, can match the latest U.S. models when it comes to finding security bugs, although it still lags behind Anthropic's and OpenAI's products in other tasks. Overall, the capability gap between top U.S. models and those built by Chinese companies has narrowed significantly, and use of Chinese AI systems has surged as businesses seek to rein in runaway costs. A host of companies, including Microsoft, are weighing how they can offer Chinese models on their platforms, a development that is set to alter the balance of power among tech companies...

Unlike models from Anthropic or OpenAI, Zhipu's GLM-5.2 is open-weight. That means it can be downloaded and run on hardware operated by anybody and can be modified and used without supervision. Open-weight models are ideal for users who want unfettered access to systems they control, but they are also ideal for hackers, who can run them in the shadows. GLM-5.2 has ranked as one of the 10 most-used AI models, according to data from OpenRouter, a company that provides access to more than 400 AI models. In some benchmarking tests, according to the cybersecurity company Semgrep, GLM-5.2 bested Anthropic's Claude Opus 4.8 model, which was released in May. When given further instructions, Opus 4.8 and GLM-5.2 can match Mythos in bug-finding ability, according to researchers...

"Banning Fable while selling chips China needs to develop its own version is a gift to China," said Saif Khan, a distinguished technology fellow at the Institute for Progress think tank who worked on export restrictions in the Biden administration. The U.S. needs to maximize the use of Mythos and comparable models to harden its cyber defenses while it can, he added. Among the Mythos 5 and Fable 5 users that had lost access before Friday's decision to restore Mythos 5 access for some trusted entities: the National Security Agency, which had been testing the tools and found them impressive in trials, according to people familiar with the matter... "It is incentivizing companies across the globe to use cheaper but very capable Chinese open-weight models, while at the same time undermining the U.S. AI industry," said Niels Provos, a researcher who led security teams at Google and Stripe. "I don't understand it."

Thanks to long-time Slashdot reader schwit1 for sharing the article.
Crime

An Amazon Seller Says They Were Offered a Way to Bribe an Amazon Employee (mercurynews.com) 22

Jack Nekhala had a business selling on Amazon — and in December he received an unusual offer, reports Bloomberg. A woman said she could bribe an Amazon employee "to help him retrieve $90,000 in funds that the e-commerce giant had frozen after suspending him over an alleged violation of review policy." Hoping to ingratiate himself with the company and restart his business, Nekhala offered to provide evidence, including recorded conversations and screen shots, that he said proved Amazon personnel were peddling inside information and influence. The smoking gun, Nekhala told the representative: information about his seller account. Only certain Amazon employees are supposed to have access to such details, but Nekhala had received them from the woman on WeChat, the Chinese messaging app. Nekhala's experience, which he documented and shared with Bloomberg, provides a rare glimpse into an international black market that has been a persistent scourge of Amazon's online store. On one side are sellers looking for a variety of favors: a competitive edge over their rivals, information on how to boost sales, a way to get themselves unsuspended. On the other are middlemen who lurk on message apps like Telegram, WeChat and WhatsApp offering access to people inside Amazon who can get things done for a price...

It's impossible to determine the scope of the illicit activity, but it's an open secret among Amazon sellers and consultants, who are frequently approached on social-media platforms and messaging apps. "The message is always the same: 'I'm going to show you screenshots to prove I have inside access,'" said Chris McCabe, a former Amazon employee who runs a seller consulting firm... In 2020, federal prosecutors exposed an international bribery scheme involving Amazon sellers and employees. The ring allegedly extracted about $100 million in unfair advantages by bribing Amazon employees in Asia to help them sell more products and sabotage their competitors. Five people in the US were convicted and received jail terms or probation. Last year, law enforcement officials in India began investigating more than 20 former Amazon employees suspected of accepting bribes from trucking companies in exchange for routes, according to The Times of India.

After Nekhala reported his own experience to Amazon, the representative committed to "do some digging" and to email him instructions on how his evidence could be shared, according to a recording of the conversation. But Nekhala said he never heard back. The employee who leaked his personal information had already been fired for unrelated misconduct, according to Amazon.

Amazon told Bloomberg employee involvement was "very rare," and that "We invest heavily in this area and have dedicated teams and systems in place to prevent all types of fraud, including by our own employees."
AI

Scroll Burned in 79 AD Volcanic Eruption Finally Deciphered Using AI (smithsonianmag.com) 50

When Mt. Vesuvius erupted in 79 A.D., it buried hundreds of papyrus scrolls. They were rediscovered in the mid-1700s, remembers Smithsonian magazine, "the only surviving collection of its kind from the Greco-Roman world..."

"But when scholars tried to unroll them, the carbonized manuscripts crumbled to dust." Every generation that followed faced the same dilemma: They could wait for technology to advance, abandoning hope of reading the ancient texts in their own lifetime. Or they could try to open the scrolls themselves — and risk destroying them.

In recent years, researchers have settled on a third option. Using advanced imaging and artificial intelligence, they're deciphering the scrolls without needing to unroll them at all.

The Vesuvius Challenge has accelerated the process by turning it into a public competition, complete with cash prizes. In 2023, a student won $40,000 for deciphering a single word — "purple" — from an unopened scroll. Later, contestants would identify 2,000 Greek characters from one scroll ($700,000) and the title of another ($60,000). Now, for the very first time, researchers have recovered all surviving text from a single scroll. The nearly five-foot-long segment includes roughly 20 columns of ancient Greek philosophy, accessible for the first time in nearly 2,000 years.

"The tech actually does look like magic, but it's not," Brent Seales, a computer scientist at the University of Kentucky, said at a press conference. (The article points out that Seales partnered with two Silicon Valley investors in 2023 to launch the Vesuvius Challenge, and is now hailing "the restoration of lost voices from the ancient world." Seales has been working on virtually unwrapping the scrolls since the early 2000s. The process involved imaging the bundles of papyrus using technology similar to CT scanners, isolating thin layers and then stitching them together.... "We've developed a systematic and a repeatable approach," Seales told the audience. "Now it's only a matter of time until we read all of the scrolls."
GNU is Not Unix

FSF 'LibreLocal' Organized From Prison by Iranian Man Jailed for 'Cyber-Crimes' After Promoting Free Software (fsf.org) 5

Thursday the Free Software Foundation blogged about this year's 47 'LibreLocal 2026' meetups, highlighting 10 that took place in Australia, Mexico, the United States, New Zealand, Cameroon, Switzerland, Spain, Argentina, China, and Iran. "Far from each other in many parts of the world, they came together around one unifying belief: free software." We envisioned LibreLocal as a collage of in-person community meetups that would bring people together to swap ideas, learn from each other, and celebrate free software. When we asked the free software community to organize LibreLocals last year, the response was very inspirational: 29 different meetups were hosted. After we made the global call this year, we were greeted with an even more enthusiastic response... Organizers hosted LibreLocals in cafes, bars, restaurants, libraries, universities, a computer repair shop, and even as part of a field trip to the System Source Museum, a museum dedicated to the history of computing in Hunt Valley, Maryland, USA.

We also learned that a LibreLocal was organized inside Vakil Abad Prison in Mashhad, Iran by a free software supporter. Originally planned to be held in Shiraz, we were informed of this change in location on the LibreLocal wiki page set up for listing all LibreLocals. The updated entry, by another free software supporter in Iran, reads:

"This year, one of our dedicated activists organized a LibrePlanet event from within prison in Iran. Currently serving a sentence for "cyber-crimes" related to his promotion of free software, he continues to introduce the principles of software freedom to his fellow inmates. We have placed this banner to honor his resilience and the community of individuals in prison who continue to stand for technological freedom. His identity will be revealed when it is safe to do so."

Advocating for user freedom should never result in a prison sentence. We especially admire and respect the bravery and strength of those who fight for software freedom in the most dangerous and oppressive of environments.

50 people attended the LibreLocal meetup in Switzerland, according to one of the organizers, "forging connections between several local free software stakeholders and strengthening their cohesion." But the FSF's blog post stresses these are "ten stories among many more of free software supporters from across the globe... We also thank you our donors and associate members for the support that makes such meetups possible."

The GNU Press Shop is now open through July 19 for their biannual fundraiser, offering a variety of freedom-respecting novelties including an FSF-branded antisurveillance webcam guard and both technical and philosophical books, like Richard Stallman's Free as in Freedom (which allegedly has turned up in Anthropic's training data). Other items include a slick new FSF logo sticker, a brass and zinc GNU "emblem" pin with real gold plating, and a cheeky sticker reminding everyone that "There is no cloud." And there's even a plush GNU toy.
AI

Linux Foundation Launches Akrites To Coordinate AI-Driven Open Source Security (nerds.xyz) 17

BrianFagioli writes: The Linux Foundation has announced Akrites, a new initiative to coordinate vulnerability disclosure and remediation for critical open source software as AI dramatically speeds up vulnerability discovery. Founding members include AWS, Google, Microsoft, OpenAI, Red Hat, NVIDIA, IBM, Cisco, JPMorganChase, and others. Akrites will provide a shared Security Incident Response Team (SIRT), a standardized coordinated vulnerability disclosure process, and act as a "maintainer of last resort" for abandoned but widely used packages.

The goal is to reduce duplicate reports, avoid conflicting patches, and help upstream maintainers address vulnerabilities before they can be exploited. As AI makes it easier to find security flaws, can a coordinated industry effort help protect open source, or does it risk giving large corporations too much influence over the ecosystem?
"Akrites is the largest coordinated effort in history to create systems and deploy tooling that leverages the collective power of the community to make everyone safer," the Linux Foundation said in an open letter. "Akrites participants will contribute engineering resources; work to build and ship fixes; or fund the engineers who do. Some companies have contributed mightily already. The reality is, collectively, we need to contribute more."
Wikipedia

Wikipedia Cofounder Larry Sanger Banned From Site for 'Canvassing' (404media.co) 214

Wikipedia cofounder Larry Sanger has been indefinitely banned from editing the site after editors concluded that he violated its canvassing rules, "or in other words, calling on his followers off platform in order to influence Wikipedia's content," reports 404 Media. Sanger says the ban proves Wikipedia suppresses ideological diversity, while editors argue he was trying to mobilize an outside audience to influence internal decisions and had ignored an earlier warning. From the report: The discussion that led to the decision to ban Sanger concluded with what an editor called a "clear consensus" to ban Sanger. "There is general agreement among participants that he has engaged in off-wiki canvassing and is not here to constructively build the encyclopedia," the editor said in a note closing the discussion. "There is also a significant concern shared by many editors that his actions constitute calls for outing."

While Sanger has been railing about bias on Wikipedia for years, the specific issue here is around his WikiProject Intellectual Diversity. WikiProjects are group efforts among Wikipedia volunteers to deal with certain issues on the site. [...] Sanger's WikiProject Intellectual Diversity, as its name implies, aims to bring more intellectual diversity to the site, mostly meaning more right-leaning perspectives. Sanger's WikiProject Intellectual Diversity and its goals alone do not merit a ban according to Wikipedia's policies. The problem, according to Wikipedia editors, is that during the discussion about whether to allow WikiProject Intellectual Diversity to become an official WikiProject, Sanger invited his 91,000 followers on X to influence that discussion.

Discussions about potential bans are supposed to remain open for at least 72 hours. While consensus that Sanger had violated Wikipedia policies was clear, Sanger was banned at some point before that deadline. He was then briefly unbanned, and then again indefinitely banned once 72 hours had elapsed and the discussion about the ban closed. "Wikipedia has become more of a mob-rule anarchy than ever," Sanger said in a statement sent to me by a spokesperson. "In the kangaroo court in which a mob ousted me, Wikipedia's administrators showed that they don't appear to value details like formal charges, a designated prosecutor, basic decorum, distinction between prosecution and judge, dispassionate adjudication, and so forth. They have no proper system other than triggering a mob to selectively enforce their hodgepodge of vague rules."

"Now that same mob has blocked me for trying to bring an intellectually diverse group of thinkers and editors to the site," Sanger continued. "Subscribing to their groupthink is now an official requirement of being a member in good standing. Something must change, and now. I only wonder if the system as it currently stands can even allow the discourse necessary to fix the system."

Programming

The Rust Ecosystem Gets an AI Security Engineer in Residence (rustfoundation.org) 3

While the Rust Foundation has a Security Initiative to protect its ecosystem, "the threats have expanded," they announced this week, "and so has the kind of help maintainers need." Much of this comes back to a single shift: Automated tooling (much of it now built on large language models) has gotten good enough to surface real vulnerabilities in open source code quickly and at scale. That is useful, and several large Rust projects have already received and fixed credible issues found this way. The same tooling has also made it trivial to generate vulnerability reports that look plausible and are worthless. Maintainers across the ecosystem are losing real hours sorting these from the reports that matter, and the noise tends to bury the signal.

So, with funding from the Alpha-Omega Project, the Rust Foundation is bringing on a full-time AI Security Engineer in Residence dedicated to the Rust ecosystem. This position is being funded with part of the $12.5M in open source security funding that the Linux Foundation announced in March. The role exists to take pressure off maintainers. The person in this position will use a mix of human-led and AI-assisted methods to proactively review Rust itself and the crates the ecosystem leans on most and help us separate real, exploitable issues from false positives and low-signal noise before anything reaches a maintainer...

This role will run full-time for six months to start, with room to extend depending on what we learn and the funding available. Methods, playbooks, and prompts will be documented so the work doesn't end with the contract. We are grateful that Rust is not embarking on this work in isolation. Several other ecosystems have received parallel Alpha-Omega grants for the same kind of work (e.g., the PHP Foundation and the Drupal Association) and we plan to share tooling, triage practices, and what we learn rather than duplicating work

A statement from Rust's new AI Security Engineer in Residence acknowledges that "One of our next challenges is the wave of bugs discovered by the next generation of AI-powered developer tools."
AI

Tech Pundit Cringely Co-Founds Startup '2Brains Inc' to Solve LLM Hallucinations (cringely.com) 56

Long-time tech pundit Robert Cringely started his career at the Stanford Artificial Intelligence Lab back in 1978. Last month 73-year-old Cringely explained why his site went on a two-year hiatus — and it's not just because of a heart attack and a stroke last July: Just like everyone else, I've been busy all this time on Artificial Intelligence, founding with two partners a company called 2Brains... The work we were doing together is unfinished, but it's not stopped. The patents are filed, the architecture is documented, and the small team continuing the work includes me.
Cringely's first piece made the cast that "the trillion-dollar bet the AI industry is making right now may be wrong, and that there's an architectural alternative we've patented and built." In Machines of Loving Grace, Amodei made the case that scaling compute would eventually solve essentially every hard problem in artificial intelligence. Buried in that optimism — or maybe not buried, maybe right out in the open — was a quiet absolution. Hallucinations, the embarrassing tendency of these systems to state falsehoods with total confidence, would take care of themselves. Make the models big enough, train them long enough, and the problem dissolves. You don't have to solve it. You just have to wait, and spend. And so the entire AI industry breathed a sigh of relief.

I have spent forty years watching this industry, and I know a permission slip when I see one.

Because that is what the essay became, whatever Amodei intended. It gave every other person writing nine- and ten-figure checks a reason not to worry about the one thing that should worry them most. The hallucination problem is the difference between a clever toy and a system a hospital or a bank or a court can actually rely on. It is the whole ballgame for enterprise AI. And the prevailing wisdom, blessed from the top, is that you needn't address it directly. Scale will provide...

A small company I helped start, 2Brains Inc., set out in 2022 to solve hallucinations — before ChatGPT, before the scaling consensus hardened into received truth, back when the polite assumption was that the problem was simply insurmountable. We did not solve it by waiting for bigger models. We solved it architecturally, by separating the part of the system that generates language from the part that retrieves and verifies facts, and reconciling the two before anything reaches the user. It runs on ordinary processors. It is cheap. And on the industry's own benchmark for this kind of faithfulness, it more than doubles the published baseline, with no fabricated facts in the verified case at all.

The article asks whether scaling will, at tremendous cost, eventually reduce hallucinations — or even worse, if the largest companies in the world "are spending a fortune chasing a cure that is not coming."

And last week Cringely pitched more advantages for their solution, noting that most prompts aren't even chatbot-level creative prompts — but just requests to retrieve simple data: The reason 2Brains doesn't lie and the reason it's cheap are the same reason. It looks the fact up instead of guessing it — so it cannot fabricate, and the lookup runs on a processor that sips power instead of a chip that gulps it. Trust and thrift are not a trade-off you balance against each other. They fall out of a single design decision. You do not pay extra for the honest version. The honest version is the cheap version. That sentence is the whole company.
Open Source

SMPTE Opens Entire Standards Catalog for Free, Removing Century-Old Paywall (cined.com) 27

The Society of Motion Picture and Television Engineers has published over 800 technical standards over the years (as a professional association for the media and entertainment industry).

But this week SMPTE "announced that its complete Standards catalog, the technical backbone behind everything from SDI and timecode to IP-based broadcast workflows, is now freely available to anyone in the global media technology community," reports the filmmaking news site CineD, arguing it's "one of the more meaningful structural shifts we have seen from a standards body in years" that could "reshape how smaller developers and educators engage with professional media technology." The move covers all published Standards, Recommended Practices, Engineering Guidelines and Registered Disclosure Documents, plus every future release, ending a long-standing model in which individual documents often sold for well over $100 each. For more than a century, SMPTE Standards have quietly governed how images and sound move through the production chain. If you have ever recorded timecode in the HH:MM:SS:FF format, routed a signal over 3G-SDI, or built a facility around the ST 2110 suite for media over IP, you have relied on SMPTE specifications, whether you knew it or not... Until now, accessing the actual text of those documents usually meant paying per file, a barrier that this announcement removes entirely... The latest releases are available through the Recently Published Documents page on the SMPTE website, with the complete archive reachable through the SMPTE Standards Library...

There is also a practical, behind-the-scenes story here. The open-access move is part of a broader modernization of how SMPTE develops and publishes Standards. Recent initiatives include adopting GitHub-based workflows for version control, issue tracking and automation, transitioning to structured HTML-based authoring, and implementing an integrated publishing pipeline that streamlines document creation, review, validation and release... The most consequential beneficiaries are arguably not the large members already inside the system, but the developers, integrators, educators and manufacturers who previously worked around the paywall... The practical upshot is that developers and emerging markets can build from accurate primary specifications rather than secondhand sources, which matters enormously when a single misread tolerance or metadata field can break compatibility down the line.

This also fits a wider pattern of the industry moving toward openness. We have previously covered moments like GoPro's decision to make its CineForm codec open source and release the SDK, a codec that SMPTE itself standardized in 2015 as an open standard for acquisition and post production. Lowering the cost of knowledge tends to widen the pool of people who can contribute to it, and a freely readable standards library is a significant step in that direction for an organization that has historically sat behind a per-document fee.

"This was a decision we did not make lightly," says SMPTE President Rich Welsh. But "For 110 years, SMPTE has evolved alongside the media technology industry, helping to drive change and innovation — and we're not stopping now." "Our industry is confronting transformative shifts, from IP-based workflows to AI authenticity and content provenance, and we find ourselves at another inflection point. We listened to our Members, Partners and the global Standards community, and the answer was clear: Interoperability is essential to the future of media. Now is the time to open the gates and ensure the next generation of media technology is built on a stronger, more accessible foundation."
Thanks to innocent_white_lamb (Slashdot reader #151,825) for sharing the news.
AI

Midjourney Pivots From AI Image Generation To Body Scanning Medical Spa 25

Midjourney is expanding beyond AI image generation with plans for a medical-imaging business built around a water-based, full-body ultrasound scanner that uses hundreds of thousands of sensors and AI to reconstruct MRI-like images. "As you descend into the water, hundreds of thousands of tiny elements take turns, sending out waves, listening together, compressing and then streaming data to a massive cluster where thousands of computers split the task," Midjourney explained in the announcement. "By looking at how the shapes of all the waves change, we reconstruct a detailed map or 'image' which basically lets us figure out what's in there." The company hopes to open a San Francisco scanning "spa" in late 2027, with 50,000 or more deployed around the world by 2031. The Register reports: It's not clear how fast the process is with the prototype unit, but Midjourney said its goal is for the whole thing to take around a minute. "We think it's completely possible that with enough early imaging in the future, the world could avoid 30% of all deaths and 50% of all healthcare costs," the company added.

According to a "technical" video included in the announcement, there's a ring of 40 scanners included in the prototype unit the company has built. That ring of 40 elements contains 358,000 ultrasonic elements made up of tiny transducers that create ultrasound waves in water while listening for how they change when they slap the body of whoever is in Midjourney's dunk tank up to a thousand times a second.

[...] Midjourney said that it's planning to open its first ultrasound scanner spa at the end of 2027, but it has another hurdle to jump: FDA approval. Beyond improving its tech so that the second-generation scanner is ready for its 2027 spa date, "regulation is the next limit," the company said. "Normally, for every diagnostic medical capability you need FDA approval," Midjourney explained. "We're starting by just giving you detailed body composition maps -- and we'll be submitting regular test results to the FDA for increased capabilities."

Midjourney also fails to mention how it will store and secure those scans, whether it will use said scans to train its body composition-detection algorithms, and how it's ensuring those algorithms get things right that it usually take a human a few years of education and training to learn.
Open Source

Google, Microsoft, and OpenAI Back Linux Foundation's Appia AI Standards Initiative (nerds.xyz) 24

BrianFagioli writes: Google, Microsoft, OpenAI, Arm, Mastercard, Siemens, and other companies have joined the newly launched Appia Foundation under the Linux Foundation. The project aims to create common specifications and assessment frameworks that organizations can use to demonstrate AI systems meet emerging safety, trust, and compliance requirements. According to the Linux Foundation, the framework is designed to allow conformity evidence to be reused across the AI supply chain, potentially reducing duplicate assessments and compliance costs. The announcement comes as governments around the world move toward enforcing AI regulations and organizations face increasing pressure to prove AI systems are trustworthy. "As international standards and legal frameworks become more established, global organizations need a consistent, practical way to verify that AI systems conform to new expectations," said Jim Zemlin, CEO of the Linux Foundation. "The Appia Foundation establishes a neutrally governed environment where the entire industry can collaborate on a common assessment framework. By building this infrastructure in the open, we are helping organizations reduce complexity, lower operational costs and build trust."

Craig Shank, Executive Director of the Appia Foundation, added: "AI systems now make decisions about people's loans, their children's schools and their jobs. People on the receiving end deserve to know those systems were built and assessed against criteria that hold up to scrutiny. The Appia Foundation was formed to do that work: creating publicly available specifications that organizations across the AI value chain use to demonstrate their systems meet those criteria. By establishing this open framework, we are building the accountability layer required to scale safe and trusted AI across major industries."
Open Source

Epic Games Announces Lore Open-Source Version Control System (phoronix.com) 35

Epic Games has released Lore, an MIT-licensed version control system written in Rust and designed specifically for "games and entertainment purposes with large file sizes," reports Phoronix. From the report: While there is Git LFS for large file storage with Git, Epic Games has crated Lore as a version control system designed entirely around the large file needs of modern game development as well as multimedia/entertainment purposes. Lore is designed to be fast and efficient for large files including binary files, and be easy-to-use including for 3D artists and more.

The Lore documentation elaborates more on its differences and motivation for development compared to Git: "No existing system was designed for the combination of constraints that large game and entertainment projects require: arbitrary content types, multi-axis scale, multi-tenant safety, and a fully open specification and license. [...] Lore is designed to combine what works in each (Git's content-addressed revision graph and centralized systems): a centralized server-of-record for durability, access control, and conflict resolution; content-addressed storage with fragment-level deduplication that is as effective on a multi-gigabyte binary as on a kilobyte of text; sparse, lazy working copies that materialize only what you need; free branching; and a fully open, publicly versioned specification and MIT license. Normal editing operations -- staging, committing, branching, diffing -- never require a network round trip."
You can learn more at Lore.org. All the code is available on GitHub.
Privacy

Hacking Group Claims Major Hack of Novo Nordisk, Attempted $25 Million Extortion (reuters.com) 15

Reuters reports a cyber extortion group has claimed responsibility for breaching Novo Nordisk's network, stealing roughly 1.3 terabytes of data, including source code, drug research, clinical-trial records, employee and physician information, production-system details, and internal AI model data. The group says it's exploring selling parts of the data after unsuccessfully demanding $25 million from the company. From the report: FulcrumSec, a cyber extortion group that emerged in October 2025, said in a long message posted to its website that it spent more than two months in Novo Nordisk's networks stealing data. It said that data included company source code, proprietary information on released and unreleased drugs, trial data, employee, doctor and patient data, information related to company processing facilities and internal AI model information.

[...] FulcrumSec told Reuters in an email that Novo Nordisk representatives contacted the group on June 3, roughly 48 hours after the group's initial contact to unnamed company executives. The company used a random Proton Mail email address sent to email addresses that FulcrumSec used in its initial outreach, and confirmed it was the company by requesting specific files for verification only the company would know about.

The FulcrumSec representative also said that the group would prefer not to sell data, "as open sourcing it is a more effective deterrent for future companies to avoid paying." [...] FulcrumSec said it would not share some of the data it stole, including information on thousands of company employees and physicians, and roughly 11,500 pseudonymized clinical trial patients. The group said it also would withhold data related to operational technology and software used to interact with sensors and machinery at Novo Nordisk production facilities as part of its "harm-reduction strategy."
A Novo Nordisk spokesperson said in an email that the company "is aware of claims that data allegedly copied externally without authorization from our systems has been published online. We take this matter seriously and maintain continued operations of our main platforms. We are in contact with the relevant authorities."
Cellphones

Commodore's Callback 8020 Is a $499 Flip Phone That Blocks Social Media and Browsers (techspot.com) 124

Commodore has unveiled the Callback 8020, a $499 Sailfish OS flip phone that runs most Android apps but deliberately blocks social media, browsers, email, and workplace apps to discourage doomscrolling. The "not dumb dumbphone" still supports messaging, music, maps, ridesharing, hotspots, a removable battery, and plenty of Commodore nostalgia. "The phone uses T9-style texting with predictive input, includes Commodore SID ringtones, ships with a selection of Commodore and Sailfish games, and even includes Snake," reports TechSpot. From the report: Commodore says it has developed patent-pending technology that prevents browsers and social media apps from being sideloaded, while DNS-level blocking should stop them from working even if someone finds a way to install them. Users can still sideload nearly anything else if it's not available on the Commostore, but apps designed for doomscrolling remain off limits. That means useful services such as WhatsApp, SMS, Signal, Telegram, WeChat, Spotify, Uber, Lyft, maps, podcasts, QR scanning, voice notes, and hotspot support work, but the likes of Instagram, TikTok, Facebook, Gmail, and browsers do not.

The Callback 8020 has a 3.25-inch 480 x 640 internal display, a MediaTek Helio G81 chip, 4GB of RAM, 64GB of storage, a 48MP Sony rear camera, an autofocus front camera, dual SIM support, USB-C, a headphone jack, FM radio, and something many of us miss from flagships: a removable battery. There's no 5G as Commodore argues that 4G VoLTE and Wi-Fi better fit a device meant to discourage constant streaming and scrolling. [...] The main screen is touch-capable but disabled by default, while the outer display keeps things deliberately sparse, showing basics such as time, battery, signal, and notifications via dome LEDs.

The 8020 name is a nod to Commodore's 8010 modem from 1980. The phone comes in ProtoPET White, SX Silver, BASIC Beige, a translucent Starlight Edition, and a gold Founders Edition with a 24-karat gold-plated Commodore button. Standard models start at $499, the Starlight version is $549.99, and the Founders Edition costs $640. Preorders open June 30, with shipping targeted for winter.
You can watch the launch ad on YouTube.
Government

The US Government's Anthropic Models Ban Was Never About an AI Jailbreak (techcrunch.com) 58

TechCrunch's Zack Whittaker argues that the U.S. government's abrupt export-control order forcing Anthropic to pull its Fable 5 and Mythos 5 models offline was "never about an AI jailbreak" threat. Instead, it was driven more by "personality differences" between the AI company and Trump administration. Security experts say the reported guardrail bypass did not justify the order and warn that the move sets a troubling precedent: the government can unilaterally disrupt American software products without court approval, potentially undermining trust in U.S. AI providers. From the report: Katie Moussouris, a cybersecurity veteran and researcher who founded Luta Security, said in a blog post that Anthropic recently shared with her a private copy of a paper written by security researchers describing an alleged guardrail bypass in Fable 5. (The Wall Street Journal reports that the paper's authors are security researchers at Amazon.) Moussouris said that Anthropic reached out to ask for her take on the paper. Moussouris' blog post described how the researchers triggered the guardrail bypass, but said that the bypass itself "should never have triggered an export control." The difference is largely between asking an AI model to "review code for security issues" versus asking it to "fix this code."

The end result is largely the same, even if the questions are posed slightly differently. "The behavior described in the paper cannot meaningfully be fixed, and any attempt would only weaken the model for defense," said Moussouris, who criticized the export control directive as hasty, heavy-handed, and misguided. Moussouris and dozens of other top security researchers and experts have since called on the Trump administration to revoke the export control order, calling the move to pull advanced cybersecurity capabilities from network defenders in the U.S. as "dangerous."

Past administrations have made sweeping decisions on knowledge gaps. For instance, language used by the U.S. government during the 2010s to fix export law covering cybersecurity tools that could also be used for cyberattacks was so broad that inadvertently, it nearly outlawed legitimate security and vulnerability research. However, the Trump administration's directive appears retaliatory. Justin Hendrix, the editor of Tech Policy Press, said the Trump administration's move is "likely to raise alarms in foreign capitals about the reliability of American AI for critical applications." The message is that AI companies in the United States can't be trusted to operate without interference from the U.S. government.

The Trump administration hasn't confirmed why it invoked its export control directive. Did the officials misread the report and freak out? Did Amazon CEO Andy Jassy say something to senior government officials that prompted the reaction, out of caution or spite? Was something lost in translation, or was this a way to pressure Anthropic, with whom the administration already has a fractious relationship? It's possible that the White House was unaware of the far-reaching consequences of the letter's demand and officials are scrambling to undo the damage of their own making. To quote Hendrix, "the climate is one of a cloud of suspicion that senior officials are picking favorites based on personal and political factors." The aftermath is that the government has set a dangerous precedent about how much control it intends to wield over the release of American-made software. This time the government took issue with Anthropic; tomorrow it could be with anyone else.

Firefox

Firefox 152 Adds JPEG XL Support, Redesigned Settings (linuxiac.com) 30

An anonymous reader quotes a report from Linuxiac: Mozilla has released Firefox 152, the latest update to its popular open-source web browser, with updated settings, improved media controls, experimental JPEG XL support, and various platform-specific fixes for desktop and Android. A key update is the redesigned Firefox Settings page, which now features clearer groupings, improved navigation, and a more streamlined structure for easier customization. The release also expands built-in spellchecker support, adding dictionaries for Croatian, English (UK), Georgian, Persian, Slovenian, Tajik, Tamil, Tibetan, Turkish, Welsh, and Xhosa. [...] Importantly, Firefox now offers experimental support for JPEG XL, an image format with improved compression over WebP, JPEG, PNG, and GIF. Users can enable JPEG XL in the Firefox Labs panel within Settings.
Space

Venus' Strange Rotation Was Likely Triggered By a High Velocity Moon-Sized Impactor (universetoday.com) 27

New simulations suggest Venus' extremely slow backward rotation may have been triggered by a high-angle collision with a fast-moving object roughly one-tenth its mass. The impact could have dramatically altered Venus' spin and melted nearly its entire mantle. Universe Today reports: Venus' bizarre and extraordinarily slow retrograde rotation on its axis has long puzzled planetary scientists. But in a new paper presented at the recent European Geosciences Union General Assembly in Vienna, the authors argue that their models indicate that a high angle moon-sized, high-velocity impactor likely triggered Venus's strange 248-day rotation. And it probably happened within the first 50 million years of Venus' formation. [...] The team found that an impactor that is about a tenth of Venus' mass hitting the planet at a high angle could drastically slow the early young planet's rotation.

Depending on the actual impact parameters, we can slow down a rapidly rotating early Venus to rotation rates that are that are compatible with long-term evolution towards a slow rotating planet, says [Cedric Gillmann, the paper's lead author and a planetary scientist at ETH Zurich]. Or even in some cases with large energetic impact that happen with a tangential impact that would even put planets early on in already a retrograde but faster rotation, he says. In the simulations, giant impacts expectedly produce surface magma oceans, the paper's authors note. Their relative depths vary depending on impact properties: from a shallow melt layer in the order of 100km thick to a fully molten mantle, they note. If the surface can radiate heat to space efficiently, the magma ocean cools down quickly, they write.

If Gillmann and colleagues are correct, Venus' likely impactor also melted some 99 percent of Venus' mantle. That is, the interior structure that extends between its core and crust. You will get rid of that impact heat pretty efficiently, and after a few hundred million years, you end up seeing an evolution that is very difficult to distinguish from a case where you don't have an impact, says Gillmann. What role the impact may have played in Venus' lack of plate tectonics, however, remains open for debate. But it's known that Venus' lack of a large-scale carbon recycling mechanism likely led to its current runaway greenhouse.

Security

Cybersecurity Vets Protest 'Dangerous' US Government Ban On Anthropic's Most Powerful Models (techcrunch.com) 40

An anonymous reader quotes a report from TechCrunch: A group made up of dozens of cybersecurity experts, including several well-known veterans of the industry, published an open letter to the U.S. government asking it to lift the export control order on Anthropic's Fable and Mythos models. According to the open letter, "this action has taken the best models away from [cybersecurity] defenders" who now can't use the models to find vulnerabilities and make their software and products more secure. "To pull the best capabilities away from defenders without a good reason when our adversaries are rapidly advancing is dangerous," read the letter.

On Friday, the U.S. government ordered Anthropic to limit the export of Fable and Mythos, citing national security concerns, without explaining the specific reasons behind the order, according to Anthropic. In response, the company suspended access to the models to all users worldwide. As of this writing, the letter is signed by 76 cybersecurity experts, including Alex Stamos, former Facebook chief of security; Casey Ellis, the founder bug bounty platform Bugcrowd; Jon Callas, famed cryptographer and former Apple security design and architecture manager; Paul Vixie, computer scientist ; Dino Dai Zovi, the former head of applied security engineering at Block; Katie Moussouris, the founder of Luta Security; and Rachel Tobac, the CEO of the security awareness training firm SocialProof Security.

[...] Anthropic said that the White House export control order may have been based on a report that there was a method to bypass -- or jailbreak -- Fable to unlock its powerful Mythos-level capabilities. According to Katie Moussouris, one of the signatories of the open letter, the method was demonstrated by Amazon researchers in a paper that is not public but that she has reviewed. But Moussouris said in a blog post that the paper did not actually demonstrate a real jailbreak. Instead, she wrote, the researchers simply asked Fable to fix open source code with public and known vulnerabilities along with "deliberately planted vulnerabilities," after the model initially refused to "review the code for security issues."

"The behavior described in the paper cannot meaningfully be fixed, and any attempt would only weaken the model for defense," Moussouris wrote. "Defenders need to be able to ask AI to fix the bugs in a file, explain why the fix matters, and write tests that confirm the patch works. That is not a guardrail bypass. It is the most valuable thing an AI model can do for defensive security: executing the find, fix, and test loop defenders run every day." Moussouris' critique was echoed in the open letter, which also said that the group of experts believe the model capabilities in the Amazon paper "can be replicated" on OpenAI's GPT-5.5, on Anthropic's own publicly available Claude Opus 4.8 and Sonnet, "and even Chinese models like Kimi 2.7."

Moussouris told TechCrunch that "the bugs used to demonstrate the techniques in the paper can be found using the other models. The method in the paper is a guardrail bypass technique. Other models that lack the Fable guardrails often won't refuse the straightforward request to look for security bugs, so they don't need a bypass." The letter also asked for transparently and fairly enforced regulations created by "a democratic rule-making process" that are based on scientific research done by industry and academic experts, and "used only to the minimal extent necessary to ensure the safety of the American public."

Television

Fox Is Buying Roku For $22 Billion (cnn.com) 74

Fox is buying Roku for $22 billion, combining Fox's sports, news, entertainment, Tubi, and Fox One offerings with a streaming platform that reaches about 100 million people. The companies say the merger would create the "third-largest player in US television by share of viewing," while Fox insists Roku will remain open to competing apps after the deal closes. CNN reports: Fox has dabbled in streaming over the past few years -- finally launching its Fox One competitor last August -- but has lacked a serious streaming business with the ability to compete in a space dominated by YouTube, Netflix, Amazon, Disney+, HBO Max, Paramount+ and Peacock. With CNN parent company Warner Bros. Discovery receiving initial US regulatory approval to combine with Paramount, Fox's purchase of Roku became more urgent. [...] The deal is expected to close in the first half of 2027 with the companies forecasting $400 million in savings. "This is a defining moment for Fox, and a natural extension of the deliberate and focused strategy we have been executing for nearly a decade," said Fox CEO Lachlan Murdoch. "Today, we take the next step: bringing together the most valuable live content portfolio in video consumption with the preeminent streaming platform through which America watches it."

Murdoch said Roku will continue to offer competing apps. "It's essential that Roku remain open and partner-friendly business. We don't see that changing at all."
Power

US-Iran Peace Agreement Prompts Stock Rally, Leaves Some Investors Skeptical and Questions on Speed of Resuming Oil Production (cnbc.com) 184

"Asian stocks rallied Monday while oil prices tumbled," reports CNBC, "after the U.S. and Iran agreed to a peace deal aimed at ending nearly four months of conflict..." The strongest reaction was seen in energy markets. U.S. crude oil futures for July delivery were down 4.77% to $80.83 per barrel by 8:27 p.m. ET. Brent futures, the international benchmark, for August delivery traded about 4% lower to $83.77 per barrel. Asian equities surged. South Korea's Kospi jumped 5.1%, Japan's Nikkei 225 climbed 3.6%, and the broader Topix advanced 2.6%... The U.S. dollar index weakened 0.32% to 99.483, while the yield on the benchmark 10-year Treasury note fell 5 basis points to 4.423%, suggesting that investors were dialing back inflation concerns on easing energy prices. "The most immediate implication is a repricing of the inflation risk premium that markets have been carrying since the Strait closed," said Billy Leung, investment strategist at Global X ETFs...

Besides safe-haven Treasurys, gold also rose. "Gold is the interesting outlier here," Leung said. "In a clean risk-on trade, gold should be selling off as the geopolitical premium unwinds, but it is holding bid around $4,300, which tells you the market is not fully trusting the deal yet." Spot gold prices were up almost 2% at $4,302.19 per ounce. That skepticism reflects lingering uncertainty around the agreement, which remains unsigned and subject to implementation risks. [Josh Gilbert, lead Asia Pacific analyst at trading platform eToro] cautioned that "the deal isn't actually signed until June 19th, the details are still thin, and this conflict has shown more than once that headlines can turn on a dime."

Analysts at Commonwealth Bank of Australia also stressed that the oil outlook hinges on how quickly shipping and production can normalize. Vivek Dhar, head of commodities and sustainability research at CBA, expects Brent to fall to around $80 a barrel by year-end, assuming the Strait remains open and exports recover. However, he warned that damage to refining infrastructure, the presence of sea mines and uncertainty over tanker traffic could slow the return to normal operations. Even so, he said markets are likely to take comfort from the prospect that oil flows need only recover to around 60%-70% of pre-war levels to restore expectations of a global supply surplus.

For investors, the biggest implication will likely be what cheaper energy means for inflation and central banks. Lower oil prices ease pressure on households and businesses while reducing the risk of a broader inflation resurgence just as major central banks enter a busy week of policy meetings.

UPDATE: "A US official is rejecting Iran's assertion that it will receive billions of dollars in frozen funds before a planned 60-day negotiating period begins following Friday's signing of an agreement," reports CNN: The pushback came after Iran's deputy foreign minister, Kazem Gharibabadi, said the next phase of talks would depend on Washington first fulfilling several obligations, including releasing Iranian funds frozen abroad. The differing accounts underscore a significant gap between how the United States and Iran are describing what must happen before the next round of negotiations can move forward.

Slashdot Top Deals