Sci-Fi

As 'Disclosure Day' Premieres, Steven Spielberg Says He Believes Aliens Really Have Visited Earth (rollingstone.com) 102

Steven Spielberg grants that his 1977 UFO film Close Encounters was "speculative," writes the Associated Press, but "Disclosure Day, he insists, is the real deal." "It's my first film that will be considered science fiction that I do not consider to be science fiction," Spielberg said in a recent interview. "It's much more reflective of the world as it is evolving and discoveries that are being made as we speak." Spielberg, at 79, is trying to revive and reconsider the alien wonder that's long lingered in his mind, from "E.T." to "War of the Worlds." "Disclosure Day," Spielberg's first summer movie in a decade, is already being hailed as one of his best in years. But this time, Spielberg is testing whether he can conjure some of his trademark movie magic less with imagination than with conviction. "I've been a believer since I made 'Close Encounters' 50 years ago," Spielberg says. "But I would always say: Until I've seen a UAP or a UFO with my own eyes, I'm not going to categorically state that life from out there has come here. But I've changed that," he adds. "I'm now willing to change my mind because of the circumstantial evidence which is overwhelming..."

Spielberg, having long followed reports of alleged alien encounters, was inspired by the 2023 House Subcommittee on National Security hearing on UAPs: Unidentified Anomalous Phenomena. Among the witnesses was whistleblower and former Air Force intelligence officer David Grusch, who testified that the government concealed a program investigating UAPs. The Pentagon then denied it... Those 2023 testimonies and others so fueled Spielberg that he produced a 50-page treatment on what would become "Disclosure Day." During the writing process with Koepp, he texted him more notes, he says, "than I've ever sent to anyone in my life."

"There was a period in there where I believe he re-read the script every single day for a year," Koepp says. "We'd be in different time zones and I would wake up to 30 or 35 texts from his most current reading of the script. When the leader of the project has that level of commitment, it tends to bring along everyone. You up your game."

The article calls it "a grand bookend for one of the most cosmically-minded moviemakers of our time." But the man who filmed some of the world's first summer blockbusters also shared his thoughts on the future of movies. "Even though the numbers are still not pre-COVID level numbers for any films being released now, it's more robust than it has been for many years. The audience gives me belief that people still want to congregate in a dark space in the company of strangers to share an experience of a film made by storytellers. And that gives me faith to continue making films."

Rolling Stone wrote that "There's a lot to love in Disclosure Day." Though they also offer this pithy summary of its plot. "Remember when Steven Spielberg digitally replaced the guns in the hands of government agents for the 20th anniversary of E.T., then expressed regret about the decision? Imagine that he not only restored the weapons but crafted an entire two-and-a-half-hour feature around that one sequence as a mea culpa. That's Disclosure Day." The filmmaker may be staging a pulpy campaign with this sci-fi throwback, but he sincerely seems to believe the truth is out there — and will set us free... [W]hile the quality of his output can vary wildly when you look at the big picture of his career, there's still a baseline of love — for filmmaking, for storytelling through images, for giving people an experience that pushes emotional buttons and taps adrenal glands — that gives his work a sense of vitality and displays the sensibility of an artist at work...

There's also a weird full-circle feel to it, and not just because he's returning to the fertile ground of Close Encounters and his other science fiction spectacles. You can see traces of everything from Duel to Minority Report show up, to the point where this almost doubles as a career retrospective in miniature... Yes, Spielberg does believe that we are not the only game running in the cosmos. But he also believes that our better angels have not left the building, and that movies still have the power to communally blow minds and open hearts.

The Associated Press calls it "a grand bookend for one of the most cosmically-minded moviemakers of our time" and "a distant answer to the final notes of Close Encounters."
AI

Will Meta's $14 Billion Bet on AI Ever Pay Off? (cnbc.com) 65

"A year after spending over $14 billion to bring in Alexandr Wang and a group of his top Scale AI engineers to revamp its artificial intelligence efforts, Meta is at least back on the map in AI," reports CNBC, "though it's still far behind OpenAI, Anthropic and Google in the market." Wang's big accomplishment was the delivery of the Muse Spark AI model in April, marking Meta's first jump into proprietary foundation models and away from a strict adherence to open source, or open weight as it's more commonly called in AI... "Meta needs to provide more proof points of both adoption and commercialization," said Ralph Schackart, an analyst at William Blair who recommends buying the stock. "Investors are looking for Meta to monetize a new AI-first product, beyond the substantial positive impact AI is having on enhancing the advertising models." Wall Street, at least so far, is unimpressed. Meta's stock is down 18% over the past 12 months, the worst performer in the megacap group, along with Microsoft, which has its own challenges in AI. That's even after Meta reported 33% revenue growth in the first quarter, the fastest rate of expansion for any period since 2021.

For Meta, the problem started with what some industry experts called, in hindsight at least, a strategic blunder. The company jumped into AI with its Llama family of models, offering an open-source approach that allowed developers to freely tinker, while the other big model makers charged for access. In April of last year, Meta's release of Llama 4 fell flat, failing to captivate developers and leading Zuckerberg to reconsider his company's approach to AI development... Since the release of Muse Spark, Meta has unveiled new AI and business-related subscription plans as part of an effort to expand its business beyond online ads. Historically, it hasn't worked. Meta still counts on ads for 98% of revenue. Schackart said he wants to see "tangible evidence of a growing list of new, AI-first products created by Muse Spark, even if monetization lags." He said that's "what investors are looking for."

No matter how good Wang's model may be, Zuckerberg has a high hill to climb with developers coming off the Llama debacle. "I think the AI community largely ignores Meta at this point," said Rob May, CEO of the startup Neurometric, which works in the realm of token engineering.... Krish Subramanian, the CEO of consulting firm KOI AI and former product head at IBM Consulting, said developers are more excited about Google's AI models than what Meta is offering. The appeal of Llama was that it specifically targeted developers wanting open-weight alternative models, while with Muse Spark, Meta has made little effort in that direction, he said. "The lack of developer trust will come back to hit them if they don't focus on third-party developers," Subramanian said, noting that it took years for Microsoft to regain trust from open-source coders during the early days of Azure. "To just focus on a walled-garden kind of an ecosystem and ad revenue as the main source of income, they probably will never become the big player," he said.

A Meta spokesperson pointed to Wang's recent comments about the company's continued support for the open-source ecosystem, and said Meta still plans to offer outside developers access to Muse Spark's underlying technology via an API, as it previously announced. "We're already testing with some early partners, and look forward to releasing it this month," the spokesperson said.

"That Zuckerberg's metaverse and virtual reality ambitions have generated over $80 billion in total losses since late 2020 makes the AI pitch a tougher sell," the article points out, citing this observation from Howard Yu, business professor at Switzerland's International Institute for Management Development.

"He's running out of the space for his credibility to last," Yu said. "I think the virtual reality foray may have burned up a lot of his goodwill in front of investors."
AMD

Vintage AMD R600 Graphics Driver Sees Code Cleanups Thanks To GitHub Copilot (phoronix.com) 25

Phoronix reports: The AMD R600 Gallium3D driver saw 59 commits [last] Sunday to Mesa 26.2. Making this code restructuring and code cleaning all the more notable is that the improvements to this old AMD Radeon graphics driver was done in part by GitHub Copilot.

Gert Wollny has been among the few open-source developers left working on the AMD R600g driver that covers from the Radeon HD 2000 series through Radeon HD 6000 series graphics cards... [T]he old open-source GPU driver support is being assisted by AI long after the upstream vendor has stopped working on this driver — the Radeon HD 2000 "R600" series launched in 2007.

AI

How America's Energy Department is Building a National Platform for Doing Science with AI (acm.org) 33

America's Energy Department "wants to build a single national platform for doing science with AI," reports Communications of the ACM: It is called the Genesis Mission, and the idea is to connect the country's 17 national laboratories, their supercomputers, scientific datasets, and a growing layer of AI models and agents into one system researchers can access. The DOE has taken to calling it 'a national operating system for science.' That means treating compute, data, and AI models the way the country treats power lines and highways, as shared national plumbing everyone else builds on top of.

If it works, Genesis will change how scientific work gets organized, checked, and scaled, with AI helping run the whole pipeline from hypothesis to simulation to experiment and back. The pitch is that this is better understood as infrastructure policy than as another research program. Genesis is now moving from announcement into execution. President Trump signed the executive order launching it in November 2025. This past February, the DOE published 26 science and technology challenges for the program, and in March it opened a $294-million call for research teams in fields like nuclear energy, quantum information science, semiconductors, and biotechnology.

The program is also beginning to reach beyond U.S. borders. In June 2026, Japan moved to become Genesis's first international partner. The two governments plan to invest a combined $1 billion over five years, with Japan contributing $500 million toward joint work in quantum technology, nuclear fusion, and biotechnology. The stated goal is staying ahead of China in the fields where AI is advancing fastest. The open question is whether a federated platform this big can actually work, or whether it ends up as one more expensive coordination exercise.

Books

How Author Dave Eggers Avoids Smartphones, Internet Access, and Flock Cameras (sfgate.com) 45

A few weeks ago on a bike ride "inspiration struck" for Dave Eggers, reports SFGate... Without a pen and paper handy, he was stuck texting the idea to himself. The problem? Eggers doesn't own a smartphone. "It takes 20 minutes to write a sentence," Eggers said... It's a funny predicament for Eggers, given that he's arguably the city's biggest proponent of the written word... Now age 56, Eggers' latest book is called "Contrapposto"...

On writing days, Eggers bikes to his sailboat docked near the Golden Gate Bridge. He writes using a hefty 1998 Mac that has never been connected to the internet. On the boat, he keeps "banker's hours," working 9 to 5 without any meetings or interruptions except for the occasional wildlife visit. "You're there with the cormorants and the occasional porpoise and sea lions and seals, and when you want to take a break, you walk around and you're in the thick of it, one of the most beautiful spots on Earth," he said. "Especially coming from the Midwest, it never gets old."

Given Eggers' decidedly low-tech existence, it's not surprising that the current state of San Francisco gives him pause, but there's a streak of hope that underlies his concerns. He abhors the growing surveillance technology that's gripping the city, refusing to get into Ubers that use recording devices, but he feels a well-written ballot measure about Flock cameras could potentially save our dwindling privacy. ChatGPT's effects on the art of writing are demoralizing, but he welcomes that teachers are re-embracing pencil and paper, with cursive making a big comeback. The wave of artificial intelligence ads blanketing bus stops imploring companies to stop hiring humans are so over the top, they'd sound cliché if he were to include them in one of his dystopian tech industry novels like "The Circle" or "The Every," but tech philanthropy has helped many of his projects flourish.

Case in point, Art + Water, a new art space scheduled to open next year on Pier 29 funded largely by art world donations... Co-founded with the artist JD Beltran, the space is slated to operate as an old-school apprenticeship system, hosting 10 artists in residence mentoring 20 students, all free of charge... The ultimate goal is to break down the financial barriers that keep students from pursuing art.

Thanks to Slashdot reader destinyland for sharing the article.
Power

GM Updates 250,000 EVs with Vehicle-to-Grid Firmware, Announces Grid-Scale Sodium-Ion Batteries (fortune.com) 91

"Battery breakthroughs will lessen AI's demand on the electricity grid," argues The Washington Post's editoral board, arguing that GM's latest moves "offer a fresh reminder that resource constraints can be solved by innovation."

Or As Fortune put it, "America's electric grid is buckling under extreme weather, aging infrastructure, and an AI build-out that is quietly rewriting U.S. power demand — and General Motors wants to turn that crisis into a business." They describe GM's plan as offering itself "as a distributed utility in disguise... stitching together hundreds of thousands of battery-powered cars, new grid-scale storage, and a unified charging platform into what amounts to a virtual fleet of power plants." The bet puts GM on a collision course with Ford's newly branded Ford Energy unit as both Detroit rivals race to repurpose underused EV capacity for a more urgent problem: keeping the lights on in the AI era. GM's case rests on three planks. The first is its existing fleet. GM says more than 250,000 of its EVs on U.S. roads can already charge bidirectionally — pulling electricity from the grid and sending it back. "Every evening, a quiet transformation occurs across the American landscape," GM Energy vice president Wade Sheffer writes in an open letter to utilities and regulators, describing the EVs sitting in driveways as "a massive opportunity to aggregate energy storage capacity."

A firmware update is rolling out to customers with GM Energy's vehicle-to-home hardware, converting those systems into full vehicle-to-grid assets with no new hardware and turning home backup systems into grid resources when utilities need them. GM is piloting the idea in Michigan with DTE Energy at 30 employee homes, and has sketched a 2030 vision with Pacific Gas & Electric in which more than 52,000 GM EVs help balance the grid out of a projected 130,000 vehicles in the area.

GM is also "seeking partnerships with utility companies nationwide to assist in offering such vehicle-to-grid services for customers," reports CNBC, noting it's one of two moves "meant to address concerns about rising energy costs amid an artificial intelligence boom."

Forbes reports that GM's second goal "is to leapfrog the dominant battery cell tech used for energy storage packs right now" — right past the LFP (lithium-iron phosphate) stage, "which is dominated by China." Sodium batteries are cheaper to use than LFP because they don't need an additional cooling system. They also have a 20-year usable life and are made from materials that can be sourced from within the U.S., the company said at a briefing in San Francisco on Tuesday. "Sodium-ion actually is the better chemistry for that application. And when I say sodium-ion is better, I mean GM's version of sodium-ion," Kurt Kelty, GM's battery chief and a long-time Tesla battery executive, told Forbes. He said GM is seeing great results from its prototypes, even at scorching temperatures of 55 Celsius (131 Fahrenheit).
"Sodium-ion-powered energy storage systems have the potential to operate without active cooling and with much less system complexity," Kurt Kelty, GM's vice president of battery and sustainability, said Tuesday in a blog post. "In large energy storage systems, that matters." Not having to cool the battery cells could lead to lower upfront costs as well as operating costs, the automaker said.

TechCrunch reports on GM's big new partnership with energy-storage startup Peak Energy to develop GM's sodium-ion battery chemistry for grid-scale deployments: GM wouldn't share with TechCrunch how much money it is investing in this energy-storage effort. But we do know the company has committed $900 million to commercialize new battery chemistries, an investment that includes a new battery-development center. .. The first GM cells are expected to enter trial production at the company's Battery Cell Development Center in 2028.
"Our next-generation sodium-ion cell development will drive energy density higher," promises GM's blog post, arguing they're extending the company's battery expertise and technical infrastructure "into the electrical grid itself. If we get this right, we will not just build better batteries. We will help create a more resilient, more affordable and more flexible energy future... Every improvement we make strengthens the development stack that supports both EVs and energy storage."

"The message: GM isn't just selling cars into a stressed grid; it's supplying the batteries to stabilize it," argues Fortune.

And GM also announced they're augmenting their apps with an "Energy Pass" offering "seamless access to Tesla Supercharger, IONNA, Electrify America, and soon, ChargePoint and EVgo networks." Their goal is to simplify the charging experience with an app "that covers nearly 70% of all DC fast chargers in the United States, plus many Level 2 chargers, all through one app."
Security

Microsoft Surface Flaw Allowed Unprotected Devices To Be Bricked By a Single Packet 21

Longtime Slashdot reader Dotnaught shares a report from The Register: For the past 90 days, Microsoft has been quietly patching a firmware flaw in Surface devices that allowed the hardware to be bricked with a single packet, though only for those who have disabled Secure Core and Secure Boot. And the company's Copilot AI software inadvertently helped identify the faulty firmware.

According to Jack Darcy, a security researcher based in Australia, his instance of Microsoft Copilot stumbled across the bug after being asked to adjust the screen backlighting on a Surface device. The Copilot-conjured Python script ended up rendering the researcher's laptop inoperable by overwriting the embedded controller firmware. "Copilot autonomously created and executed four progressively aggressive Python scripts during a probe for backlight control values that sent raw SSAM ioctl commands (SSAM_CDEV_REQUEST = 0xC028A501) directly to the SAM microcontroller through the SAM software path," Darcy explained to The Register.

[...] "We appreciate the work of Jack Darcy and The Register for reporting this issue under a coordinated vulnerability disclosure," a Microsoft spokesperson said in a statement. "Our investigation found that a deprecated UEFI interface could trigger a boot loop on some devices. To trigger this loop, the user must have administrator privileges and have already disabled the Secure Boot security feature. We have released updates to address the issue for most impacted devices."

That means managed devices are not at risk. But those using Linux, or Windows users who have disabled Secure Core and Secure Boot for gaming, or who use custom Windows drivers, or who have USB boot enabled, may still be vulnerable if their systems haven't received the update. We're uncertain about the range of Surface devices affected. Our source said it appears to be all of them (Surface Laptops 3-6, Surface Book 1-3) except for Surface Go models. ARM variants, however, have not been tested.
The report notes that Microsoft is planning to move the Surface stack to a more secure architecture based on Rust code.

"Our most recent Surface for Business hardware features a major architectural shift in terms of improved reliability and security that spans our embedded controller, UEFI, but also some of our drivers," said David Abzarian, chief architect for Microsoft Surface. "We're investing in the most secure foundation for a PC by building our embedded controller firmware from the ground up in Rust (as part of leveraging and contributing to the Open Device Partnership (ODP)) in addition to a rewrite of the UEFI DXE Core in Rust; these projects are known as Secure EC and Project Patina respectively."

"We're also not only shipping some of our drivers written in Rust, but also helping co-develop the framework Windows Drivers in Rust (WDR) to help enable a broad set of partners in the Windows ecosystem to capitalize on these benefits. I will also note that all of these efforts are open-source promoting one of our key security principles around transparency."
EU

Infineon to Open German Chip Fab as Part of EU Sovereignty Push (bloomberg.com) 28

Infineon is set to open a $5.8 billion power-chip fab in Dresden on July 2, backed by about $1.1 billion in EU Chips Act subsidies. The plant will make power semiconductors for AI data centers and could eventually add up to $5.8 billion in annual revenue as demand for AI infrastructure strains global electricity systems. Bloomberg reports: Infineon, traditionally a chipmaker for the automotive industry, has increasingly benefited from soaring demand for power chips used in AI data centers, which will be produced at the new facility. "The AI data centers currently being built and planned around the world will consume twice as much electricity in 2030 as they do today," [said Chief Operating Officer Alexander Gorski]. "That's as much as the entire Federal Republic of Germany."

Chip production at the Dresden fab will be scaled over time depending on demand, potentially adding as much as 5 billion euros in revenue per year, Gorski said, declining to comment on when full capacity will be reached. The company has invested around 2 billion euros on construction and the remaining amount will be spent over time to add more machines to the fab, he added.

The new facility is "a key catalyst," Bank of America analysts including Didier Scemama wrote in a note last week. Demand from Al customers is materially above Infineon's current capacity, they said, adding the imbalance could improve in the 2027 and 2028 financial years. The analysts raised their Al power revenue forecast for the company by 500 million euros to 4.5 billion euros for 2028.

Infineon expects data center-related revenue to rise from around 1.5 billion euros in fiscal 2026 -- roughly 10% of sales -- to 2.5 billion euros in 2027, it said last month. The hundreds of billions of dollars being invested in AI are driving the rapid expansion of data center capabilities around the world. Infineon doesn't produce advanced AI chips, like those designed by Nvidia. But the power semiconductors it plans to produce in Dresden are still needed for AI infrastructure.

Open Source

Euro-Office 1.0 Arrives To Open-Source Infighting: 'Compatibility Is Not Sovereignty' (zdnet.com) 81

An anonymous reader quotes a report from ZDNet: If digital sovereignty is important to you, and it certainly is in the European Union (EU), then you'll be pleased to know that EuroOffice, a new open-source browser-based office suite alternative to Microsoft 365 and Google Workspace, has officially reached its first stable release. A coalition of EU-based companies, including Nextcloud, Ionos, and other Euro-Stack participants, is positioning Euro-Office as a cornerstone of European digital sovereignty. However, The Document Foundation (TDF), LibreOffice's steward, accuses the project of reinforcing Microsoft's document lock-in, which TDF argues isn't friendly to open standards.

Setting aside the open-source politics for the moment, here's what Euro-Office brings you. The release went live on June 9. It is, however, not a stand-alone office suite. As the software's backers explain in a FAQ, "Euro-Office is more of an integration component. It merely handles document editing itself. Storage, as well as navigation, permissions, and sharing logic, have to be offered by a platform it is integrated in, like Proton Docs, Nextcloud Hub, or OpenProject." So, while you can install Euro-Office on your own Linux server, you'll need to integrate it yourself. If you're not a Linux expert, however, don't give up hope. Some companies have already released packaged, ready-to-install Euro-Office stacks, including Nextcloud Hub 26 Spring, Ionos' Nextcloud Workspace, and Office.eu. These initial deployments are web-based rather than standalone desktop suites.

The goal, organizers say, is to give European organizations a way to host their office suite on EU infrastructure under EU law, while maintaining an experience familiar to Microsoft Office users. Specifically, Euro-Office is meant to be "a solution for editing documents, spreadsheets, and presentations, developed as a true sovereign community collaboration of over a dozen different organizations."
TDF's main objection is that Euro-Office's decision to default to Microsoft's OOXML format undercuts its claims of European digital sovereignty, since OOXML remains closely tied to Microsoft Office behavior and control. "Compatibility is not sovereignty," TDF warned, saying a European-branded suite that saves files in OOXML by default "is de facto an ally of Microsoft in its content lock-in strategy."
Science

Humans Prefer To Walk Anticlockwise, Scientists Find (theguardian.com) 156

fjo3 shares a report from The Guardian: Tests reveal that when people are ambling about, they have a natural tendency to turn to the left and walk in an anticlockwise direction. "If you simply ask someone to start walking, whether they are wandering around a museum, a supermarket, or even an empty room, it is surprisingly likely that they will drift counterclockwise," said Dr Inaki Echeverria Huarte at University of Navarra in Spain.

As with many critical discoveries in science, the revelation owes a debt to serendipity. During the pandemic, the researchers ran experiments to see how many people could share a space while keeping a safe distance. On reviewing the video, they noticed that crowds overwhelmingly walked in an anticlockwise direction. The surprise set in motion an entire research project. The scientists conducted a series of experiments in which individual pedestrians or small crowds roamed around enclosed spaces. Time and again, the researchers observed the tendency to walk in an anticlockwise direction.

Suspecting that cultural norms might play a role, the team joined forces with Dr Claudio Feliciani at the University of Tokyo. He found the same results in Japan. The finding held when the researchers accounted for people being right-handed, right-footed and right-eye dominant, and was seen in both male and female walkers. The only difference they spotted was a more pronounced bias in children. "Each of us carries a small personal bias to turn slightly to one side, and when many people share a space, those tiny biases add up into a net counterclockwise rotation," said Echeverria Huarte.
Researchers think the tendency may be tied to biomechanics: people are not perfectly symmetrical, and the way the brain processes sensory information and coordinates muscles may gently tip walkers toward one side. Right-side dominance may also play a role, especially in running, where anticlockwise movement puts more internal force on the right side of the body and may feel more natural to right-leg-dominant athletes.

"We have tested several ideas and the bias stubbornly keeps showing up, so the exact mechanism is still an open question," said Echeverria Huarte.

The findings have been published in Nature Communications.
Security

Microsoft Defender 'RoguePlanet' Zero-Day Grants SYSTEM Privileges (bleepingcomputer.com) 35

A researcher using the name Nightmare Eclipse has released a new Microsoft Defender zero-day exploit called "RoguePlanet," which reportedly works on fully patched Windows 10 and 11 systems and can spawn a command prompt with SYSTEM privileges through a Defender race condition. The release came just hours after Microsoft fixed two previously disclosed flaws during its latest monthly Patch Tuesday drop -- its largest Patch Tuesday release ever. BleepingComputer reports: The researcher shared a proof-of-concept exploit on Tuesday afternoon in a self-hosted Git repository after saying that GitHub and GitLab repositories hosting their exploits had previously been removed by Microsoft. "The exploit is a race condition, so it's a hit or miss. I have managed to get a 100% success rate on some machines while it struggled to work on others," Nightmare Eclipse wrote in the repository.

[...] Cybersecurity firm ThreatLocker told BleepingComputer that they successfully reproduced the flaw in their testing and confirmed the exploit worked against fully patched Windows 11 systems with KB5094126 installed, and shared a video demonstrating it. "Our initial analysis confirms that the RoguePlanet exploit is viable and performs as described. Organizations using application allowlisting can prevent the exploit from executing, providing an effective layer of protection against this attack," Danny Jenkins, CEO of ThreatLocker, told BleepingComputer.

According to Nightmare Eclipse, RoguePlanet was originally developed as a remote code execution vulnerability that exploited Microsoft Defender's handling of files hosted on remote SMB shares. "In initial development, it was confirmed that this vulnerability was a remote code execution," the researcher explained in a blog post. "It required an attacker to coerce a victim to open a .vhd(x) in a remote SMB server, succesful exploitation resulted in defender overwriting its own files and obviously the end outcome was an RCE."

The researcher says another attack scenario could lead to remote code execution simply by coercing a victim into opening an SMB share if symlink evaluation settings were enabled. However, the researcher claims Microsoft silently hardened Defender in mid-May by patching "mpengine!SysIO*" API, which blocked junction attacks. "Rewriting RoguePlanet to make it functional again drained my soul and I couldn't complete the other scenarios and for now it remains unclear if RoguePlanet is limited to LPE or there is some sort of way to turn it into an RCE," the researcher wrote.

EU

EU Orders Meta To Open WhatsApp To Rival AI Chatbots 39

The European Commission has ordered Meta to temporarily restore free WhatsApp Business API access for rival AI chatbots while it investigates whether Meta's ban on third-party assistants abuses its dominant position. Meta says it will appeal, calling the move "regulatory overreach" that would let major AI companies use a paid WhatsApp product for free. The BBC reports: The EU said it began its investigation, in December 2025, after Meta banned third-party general-purpose AI assistants from the WhatsApp for Business API. It said that appeared to be an abuse of Meta's dominant position in European markets. So, as an interim measure as its investigation continues, it has given Meta five working days to re-instate access for third-party general-purpose AI assistants to the WhatsApp for Business API under the same terms and conditions that were in place previously.

"In rapidly evolving markets, competition can be lost long before a final decision is adopted," said Teresa Ribera, the Commission's executive vice-president for clean, just and competitive transition. "This is why these interim measures will remain in place for the duration of the investigation." She added the decision "preserved choice for citizens across Europe on the AI assistants they want to use with WhatsApp, without that decision being made for them." The Commission said if Meta failed to comply with its interim decision it could be fined up to 10% up of its total turnover.
"The European Commission has decided that OpenAI and some of the largest companies in the world can use the paid-for WhatsApp Business product for free," it said in a statement.

"This is regulatory overreach subsidized by the many European companies that pay. We will appeal."
Privacy

Meta Deletes Face-Recognition System From Its Smart Glasses App (wired.com) 27

Last Thursday, Wired reported that Meta had quietly embedded an unreleased facial recognition system called NameTag into software installed on millions of phones. In a follow-up report, Wired says the tech giant has now removed the face-recognition-related code, while saying "no final decision" has been made about whether the feature will launch. From the report: On Thursday, WIRED reported that Meta had quietly integrated substantial portions of the NameTag system into the Meta AI app. Though never publicly enabled, the feature was designed to convert faces captured by the glasses into unique biometric signatures, commonly known as faceprints, and compare them against a database of faceprints stored on the user's device. WIRED also found that faces the system failed to recognize were cropped, indexed, and stored locally for future processing.

NameTag first surfaced in February, when The New York Times, citing internal Meta documents, reported that the company was developing face recognition for its smart glasses and weighing a launch as soon as this year. One memo reportedly described releasing it during a "dynamic political environment," when privacy and civil liberties advocates would be distracted. Last week, WIRED reported that much of NameTag's machinery was already built into the Meta AI app, downloaded by millions of users, as early as January, even as Meta publicly said it had made no final decision about face recognition. After WIRED's report, Stone dismissed the findings, writing that the company couldn't answer questions about how the system would work because "the feature does not exist." Andrew Bosworth, Meta's chief technology officer, called the reporting "incredibly misleading" and "absolutely dishonest."

[...] The newly released version of Meta AI removes nearly all traces of the feature Meta said did not yet exist. Gone is the face-recognition software itself, along with the code that ran the NameTag recognition process and the "Person recognized" alert the app would have shown if someone were identified. The update also strips out a folder where the app would have stored the cropped images and biometric signatures of faces it captured but could not identify. [...] A few fragments of the NameTag system remain in the version of latest Meta AI, including an internal debug menu label and a dormant link meant to open a recognized person's profile. The leftover code points to parts of the system that are no longer there.

Programming

Ruby Fights Supply-Chain Attacks With Filter Offering 'Cooldown' Before Installing New Packages (rubygems.org) 24

Most supply-chain attacks using Ruby's package hosting site "exploit a narrow window," according to a new blog post form Ruby core maintainer Hiroshi Shibata.

So its packaging-managing Bundler tool now offers a filter that blocks new version until it's been public "for at least N days. Releases too new to have been scrutinized are passed over in favor of ones that have aged past the window." The feature was designed in the open, drawing on how other ecosystems approach the same problem. It is opt-in, and complements rather than replaces existing defenses like mandatory 2FA and trusted publishing... Cooldown is unset by default, so a project without it keeps resolving to the newest versions.... Passing 0 disables cooldown for the run...

Cooldown is most useful as one part of the wider security investment happening on rubygems.org. The registry now validates gem contents at push time and checks logins against Have I Been Pwned so that compromised passwords cannot be reused, work described in Protecting rubygems.org from the outside in. A dedicated team is running AI-assisted vulnerability scanning against the most critical gems, backed by Alpha Omega and Anthropic, and the direction of all of this is tracked on a public roadmap. Trusted publishing and mandatory 2FA already raise the bar for who can push a release in the first place.

EU

EU's Tech Sovereignty Package Includes 9+ Pages on Open Source, Says Open Source Initiative (opensource.org) 18

Friday the Open Source Initiative welcomed the EU's new tech sovereignty package, noting that "over a third of the 29-page document is devoted to Open Source."

The nonprofit OSI — maintainers of the Open Source definition — submitted their official feedback in February, and notes that "many" of their key requests were addressed, "as well as some exciting new announcements!" One of the biggest barriers to Open Source adoption has been public procurement. Too often, tenders have been designed around proprietary solutions, ignoring the benefits of Open Source and locking public institutions into closed ecosystems. The OSI called for procurement rules that prioritize interoperability, reusability, and vendor independence. The package takes a major step forward in this area. The EU pledges to make the public sector an anchor consumer for Open Source solutions. The Commission plans to reform procurement rules to remove barriers for Open Source, provide better guidance to EU countries on procurement criteria to avoid excluding Open Source, and uphold the "public money, public code" principle when procuring software development. Both proposals align with the OSI's feedback. The next critical step is the EU's public procurement law reform. The OSI will continue advocating to ensure these pledges translate into action.

Beyond procurement, the OSI highlighted challenges faced by Open Source communities in Europe, particularly difficulties accessing investment and expertise to commercialize and scale projects. The Commission has responded by committing to ensure Open Source companies are considered for funding under the European Competitiveness Fund (ECF). It also plans to create "Open Source business accelerators" that will offer mentorship, training, legal and licensing consulting, and business development support, including marketing. Additionally, the Commission will work to raise industry awareness of Open Source solutions by leveraging the EU's existing business support networks. These measures directly address the OSI's concerns and could significantly boost the Open Source ecosystem in Europe...

[I]n our feedback, we called for the continuation of the Next Generation Internet (NGI) initiative that has funded many Open Source projects, and for the creation of a European Sovereign Tech Fund to fund ongoing maintenance and features development to meet the EU's needs. We also highlighted the need to mainstream Open Source in other funding opportunities (like the €100bn+ Horizon Europe programme). The Commission's strategy addresses these requests. The NGI will be scaled up under the new name "Open Internet Stack." A new Open Source Maintenance Instrument will fund the "maintenance and security upkeep of essential components." The Commission will also create a list of critical and security-relevant Open Source dependencies to inform funding decisions and promote Open Source solutions as the default approach in Horizon Europe funding.

Friday's announcement from the Open Source Initiative notes that the EU is already leading by example in Open Source adoption. It applauds the EU for "deploying a Matrix-based communications system and the openDesk collaboration environment internally, trialing an alternative operating system to replace Windows, which is currently widely used in EU institutions, and expanding its presence on the Fediverse, with Commissioners and key departments already joining the EU's Mastodon server.'
Open Source

Ladybird Browser Stops Accepting Public Pull Requests (ladybird.org) 25

The Ladybird browser isn't opposed to AI coding tools, but it's just brought a new change to their code-contributing policies.

February 23: "Ladybird adopts Rust, with help from AI." Our first target was LibJS , Ladybirdâ(TM)s JavaScript engine... I used Claude Code and Codex for the translation. This was human-directed, not autonomous code generation. I decided what to port, in what order, and what the Rust code should look like. It was hundreds of small prompts, steering the agents where things needed to go... The requirement from the start was byte-for-byte identical output from both pipelines. The result was about 25,000 lines of Rust, and the entire port took about two weeks. The same work would have taken me multiple months to do by hand.
June 5 (Friday): We will no longer accept public pull requests... A pull request no longer tells us as much as it used to about the person submitting it. A substantial patch used to imply substantial effort, and that effort was a reasonable proxy for good faith. That assumption no longer holds....

We have already seen patient, well-resourced campaigns in open source to earn maintainer trust and abuse it. What has changed is how much faster and cheaper it has become to produce work that looks like a serious contribution... Whether code was typed by hand is beside the point. What matters is who is responsible for it once it enters the browser. Ladybird is becoming a browser for real users. The people introducing changes to it must be the people who decide those changes belong in the project, and who will answer for the consequences.

As part of this change, we will close all currently open public pull requests. We are grateful for the work people put into them, but keeping the existing queue open would keep that contribution path open in practice. There is no perfect time to make this change, so we are making it now. Going forward, pull requests will only be available to project maintainers. There will not be a separate process for submitting patches by other means. We do not want to create a shadow contribution system through issues, comments, email, or forks...

Outside involvement still matters: clear bug reports, reductions, website testing, standards discussion, design discussion, security reports, and technical feedback all help move the project forward. This is the right change for Ladybird now. We are preparing to ship a browser to real users, and our development process has to match that responsibility.

Social Networks

Teen Social Media Bans Risk Strengthening Big Tech's Dominance, Warns Bluesky Exec (cnbc.com) 38

Bluesky's chief operating officer believes teen social media bans "risk entrenching Big Tech's dominance," reports CNBC: Rose Wang, Bluesky's chief operating officer, told CNBC on the sidelines of SXSW in London on Wednesday that the smaller open-source platform isn't opposed to regulation but that smaller players in the industry should be protected. "I support the protection and the safety of youth... The question that we have then is at what cost? Because essentially what I'm scared of is in the long term, we're headed to a world where there's about three to five platforms, and extreme heavy regulation of those platforms...

"Basically the whole compliance teams of these platforms are 10 times the size of our entire team," Wang said. "So, basically, we're living in a world where it's almost impossible for smaller entrants to come in and build healthier spaces."

The article notes Bluesky had grown to 43 million users as of March, "which is still only around 10% of X's estimated 450 million users. Bluesky has struggled to maintain popularity, and by the end of October last year, it had reportedly seen a 40% drop in daily mobile active users over the past 12 months."
Communications

The US Military Quietly Turned GPS Into a Global 'Numbers Station,' Evidence Suggests (404media.co) 49

A security researcher says evidence suggests the U.S. military has been using an obscure GPS message field for nearly 20 years to broadcast encrypted key-distribution data, effectively turning GPS satellites into a global "numbers station." The hidden-looking 176-bit messages appear tied to the Pentagon's Over-the-Air Distribution system for remotely updating cryptographic keys, meaning ordinary GPS receivers may have been receiving the traffic all along without anyone outside the military noticing. The findings have been detailed by Steven Murdoch, an information security expert, in a new article in Inside GNSS. 404 Media reports: [...] From the beginning, he suspected that the subframe field contained encrypted transmissions because the data was so random. "Random data is actually very unusual to get in nature," Murdoch said. "If you see it, either it's been carefully designed to be random -- but then, why is someone sending out random data? -- or it's encrypted data. I thought encrypted data is by far the most likely explanation." He returned to the subframe on and off over the years, and solicited guesses about its content on Stack Exchange in 2023. Ahmed Kamruddin, a master's student at UCL, developed the project further in 2025. Then, this year, Murdoch put the last pieces of the puzzle together over several weeks by analyzing open archive Global Navigation Satellite System (GNSS) recordings collected since 2007 and kept by GFZ Helmholtz Centre for Geosciences.

This dataset included more than 12 million observations of Subframe 4, Page 17, yielding 3,994 unique 176-bit messages. Within this corpus, Murdoch pinpointed key-repeating "sentinels" including a pattern that appeared in February 2010 and was broadcast on and off across dozens of satellites for more than a decade. Murdoch discovered that this particular sentinel was transmitted by all 31 operational satellites within a window of a few hours on May 26, 2011, potentially heralding the activation of a new operational system. He confirmed that this timeline coincided with the rollout of the military's Over-the-Air Distribution (OTAD) and the Over-the-Air Rekeying (OTAR) by cross-referencing declassified documents, including a 2015 presentation about the dates of the operation.

"There was a perfect match between the timeline and that presentation and the change points that were automatically identified from the data," Murdoch said. "That was the smoking gun that made me think: This is what it's for." These automated systems replaced the cumbersome manual distribution of cryptographic keying material, allowing military GPS receivers around the world to be rekeyed remotely through satellite broadcasts rather than through onsite procedures. For the next 11 years, this expansive rekeying operation was overlooked in public GPS data. In 2022, the system entered a new phase, according to Murdoch's analysis. The shift was characterized by a slowing in the message rotation rate. Later, in December 2023, broadcasts carrying a distinctive "TEXT" prefix emerged then gradually spread across the constellation.

Murdoch isn't sure what explains the recent transition, though it could be a possible modernization of the infrastructure or the introduction of a new protocol. But to him, the bigger takeaway is that the signals were always available for anyone willing to take a closer look, a discovery that suggests that there could be more revelations hidden for the cryptographically curious among us. "Every receiver in the world decodes Subframe 4, Page 17," Murdoch said in his new article. "Almost none of them have ever looked at it. The lesson generalizes: There is more to learn from the bytes already arriving at our antennas than from the bytes we wish were specified differently. The data are publicly available. The signal is overhead, twice a day, every day."

The Almighty Buck

GOV.UK Goes Dutch On Payments As It Dumps Stripe (theregister.com) 10

The UK's Government Digital Service is replacing Stripe with Dutch payments provider Adyen for many GOV.UK Pay transactions, including local authorities, police forces, and armed forces units. The three-year deal covers about 1,000 services and is meant to make payments more flexible while keeping the user experience largely unchanged. The Register reports: According to the tender notice published in February 2025, the contract covers around 17 percent of payments made through GOV.UK Pay but more than 70 percent of its organizations and includes the only option allowing users to start taking payments within one working day. At that point the contract had an estimated maximum value of £49 million, although with no guarantees over volume.

In a blogpost about the contract award on 2 June, GDS said it will migrate around 1,000 services to the new supplier. "We will make migration as straightforward as possible while complying with Know Your Customer legislation that protects everyone from fraud," wrote Alan Maddrell, senior content designer for the service. "Most importantly, there will be no discernible difference for paying users and no loss in functionality."

He added that the change of supplier will help introduce new options including pay by bank, which transfers money directly between bank accounts using open banking services and avoids the need to type in card details. GDS will continue to use WorldPay to process payments for central government, linked organizations and NHS bodies.

Open Source

BSA Lashes Out At Mandatory Open-Source Licensing (bsa.org) 87

Longtime Slashdot reader Elektroschock writes: The American Business Software Alliance (BSA) does not consider mandatory open-source licensing to be an appropriate indicator of sovereignty. This is among the "pointed messages" they sent to the French government consultation (closed) today. "What protects Europe is the ability to govern, audit, and mitigate risk, not where a company files its corporate papers," said Thomas Boue of BSA. "Criteria of this kind raise costs, reduce access to best-in-class security solutions, and risk conflicting with the EU's international trade commitments."

Slashdot Top Deals