Forgot your password?
typodupeerror

Submission + - Arch Linux's AUR Sees More Than 400 Packages Compromised With Malware. (phoronix.com)

couchslug writes: Michael Larabel reports:

"The Arch Linux User Repository "AUR" was hit by a large-scale malware campaign this week with more than 400 of these user-supplied packages being compromised.

Since yesterday Arch Linux maintainers have been working to reset/delete all of the malicious content and banning affected accounts. Over 400 packages are believed impacted by this latest malware campaign for Arch Linux's AUR. Again, to be completely clear, this just is affecting AUR packages and not the official Arch Linux packages. "

Submission + - WAPO sued, reader accuses it of using 'surveillance pricing' to gouge readers (the-independent.com)

schwit1 writes: Chelsea Bink thought she was buying a subscription. The lawsuit says she was also feeding a pricing machine. From the Independent:

A Washington Post reader has sued the Jeff Bezos-owned newspaper, accusing it of spying on its own subscribers to jack up their subscription prices.

Chelsea Blink’s class action complaint alleges that The Post began "covertly harvesting" data from its subscribers' phones, computers and tablets after the billionaire Amazon founder bought it for $250 million in 2013.

The Post then aggregated and analyzed the "deeply personal information" to "weaponize" it and maximize profits, according to the 28-page lawsuit filed in Superior Court in Washington, D.C.

"The more loyal a reader became, the more data The Post could gather to estimate how much more that person might tolerate paying at renewal," the court filing says. "Rather than rewarding loyalty, The Post’s system converted Subscribers’ engagement into leverage against them. Longtime Subscribers would end up paying more than new customers simply because the company knew more about them."

Blink's lawsuit, first reported by Mediaite, accuses The Post of violating local consumer protection law through its alleged "unfair and deceptive acts."


Submission + - Microsoft Surface firmware left embedded controller unprotected (theregister.com)

Dotnaught writes: For the past 90 days, Microsoft has been quietly patching a firmware flaw in Surface devices that allowed the hardware to be bricked with a single packet, though only for those who have disabled Secure Core and Secure Boot.

And the company's Copilot AI software inadvertently helped identify the faulty firmware. Asked by a security researcher to adjust the backlighting on a Surface laptop, the AI sprayed the embedded controller with data and bricked his device.

Submission + - Usenet is back! (sort of] (newsgrouper.org) 1

An anonymous reader writes: Newsgrouper is a free web-based interface for reading and posting to Usenet discussion groups (text only, no binaries). Hosted at newsgrouper.org, it allows users to access Usenet newsgroups through a simple browser interface — no dedicated newsreader software or Usenet provider subscription needed

Key features:

Read and post to Usenet newsgroups via the web
Text-only — no binary (file) groups supported
Guest access available for browsing; account required for posting

It was built as a personal project and shared on Reddit and Hacker News in late 2024/early 2025, with the goal of making Usenet's remaining worthwhile discussion corners (like comp.lang.* groups) more accessible

Submission + - Shutterstock is embracing AI slop and calling it creativity (nerds.xyz)

BrianFagioli writes: Shutterstock has unveiled what it calls a âoehuman-led, AI-poweredâ creative platform that combines its library of contributor-created content with AI image generation, AI editing, conversational search, prompt enhancement, and automated model selection tools. The company says the goal is to help creators move from idea to finished work faster while maintaining commercial licensing protections and contributor royalty payments.

Critics may see the announcement differently. While Shutterstock repeatedly emphasizes human creativity, much of the platformâ(TM)s future appears centered on AI-generated and AI-modified content. The move highlights a growing tension across the creative industry as companies race to embrace artificial intelligence while creators worry that the internet is becoming increasingly flooded with what many have come to call âoeAI slop.â

Submission + - Euro-Office 1.0 Arrives To Open-Source Infighting (zdnet.com)

An anonymous reader writes: If digital sovereignty is important to you, and it certainly is in the European Union (EU), then you'll be pleased to know that EuroOffice, a new open-source browserbased office suite alternative to Microsoft 365 and Google Workspace, has officially reached its first stable release. A coalition of EU-based companies, including Nextcloud, Ionos, and other Euro-Stack participants, is positioning Euro-Office as a cornerstone of European digital sovereignty. However, The Document Foundation (TDF), LibreOffice's steward, accuses the project of reinforcing Microsoft's document lock-in, which TDF argues isn't friendly to open standards.

Setting aside the open-source politics for the moment, here's what Euro-Office brings you. The release went live on June 9. It is, however, not a stand-alone office suite. As the software's backers explain in a FAQ, "Euro-Office is more of an integration component. It merely handles document editing itself. Storage, as well as navigation, permissions, and sharing logic, have to be offered by a platform it is integrated in, like Proton Docs, Nextcloud Hub, or OpenProject." So, while you can install Euro-Office on your own Linux server, you'll need to integrate it yourself. If you're not a Linux expert, however, don't give up hope. Some companies have already released packaged, ready-to-install Euro-Office stacks, including Nextcloud Hub 26 Spring, Ionos' Nextcloud Workspace, and Office.eu. These initial deployments are web-based rather than standalone desktop suites.

The goal, organizers say, is to give European organizations a way to host their office suite on EU infrastructure under EU law, while maintaining an experience familiar to Microsoft Office users. Specifically, Euro-Office is meant to be "a solution for editing documents, spreadsheets, and presentations, developed as a true sovereign community collaboration of over a dozen different organizations."

Submission + - Germany makes landmark decision on Google's AI Overviews (the-decoder.com)

Morpeth writes: A German court made clear distinction between Google simply returning search results which point to websites they did not generate/control/own, versus the information provided by Google's AI Overviews, which the court deems as content they are creating, and hence liable for.

"A German court has ruled that Google is directly liable for what its AI search overviews say. Previous case law shielding search engine operators from liability doesn't apply to AI overviews..."

"Google's AI overviews work nothing like traditional search results, the court argues. The AI rewrites and judges results "in its own words and according to its own structure," the ruling says. "

"The court also examined existing rulings from Germany's Federal Court of Justice (BGH), which gave traditional search engines and autocomplete limited liability. The BGH had argued that search engine operators were only liable as indirect infringers because they merely made third-party content findable. A proactive duty to check results would threaten how search engines work.

The Munich court found that this reasoning doesn't apply to AI overviews. A regular search engine just points to outside websites. But AI overviews generate "independent, new, and substantive statements"

Submission + - Facial Recognition Falsely Identifies Florida Man as a Child Abductor (reason.com)

fjo3 writes: Police arrested a man in Florida for attempted child abduction in a town he had never visited, and the only evidence linking him to the crime was an AI facial recognition hit. Represented by the American Civil Liberties Union (ACLU), he is now suing the officers and agencies who put him through it.

Submission + - HP: Hackers Are Turning Legitimate Remote Access Tools Into Backdoors (nerds.xyz)

BrianFagioli writes: HP is warning that hackers are increasingly abusing legitimate remote access tools such as LogMeIn and ScreenConnect instead of relying solely on traditional malware. According to the companyâ(TM)s latest Wolf Security Threat Insights Report, attackers have used tax-themed phishing emails, fake software updates, and bogus app downloads to trick users into installing authentic remote access software that ultimately gives cybercriminals persistent control over their PCs. Because the software is legitimate and digitally signed, the activity can blend in with normal IT operations and avoid raising suspicion.

The report also highlights a growing number of attacks involving fake cryptocurrency wallet recovery tools, AI-assisted âoevibe-codedâ malware, and ClickFix campaigns that disguise malware as audio files behind realistic CAPTCHA prompts. HP says email remains the top malware delivery method, accounting for 57 percent of threats observed during the first quarter of 2026. The company argues that modern attackers are increasingly hiding behind trusted software, familiar workflows, and convincing social engineering rather than obviously malicious programs. What do you think about attackers abusing legitimate tools instead of creating their own malware? Is user education enough, or do operating systems need stronger protections against this sort of abuse?

Submission + - College Students Are Rapidly Losing the Ability to Read (futurism.com)

schwit1 writes: In a new essay for The Chronicle Higher Education , university-level literature and writing instructor Tyler Jagt recalls how not a single one of his students could get through an assigned 20-page article, something that he had read "without complaint" as an undergraduate a decade ago.

One student confessed that the reason they didn't finish was that they kept losing track of what the paper was about. And there's no doubt that they're not alone.

Jagt cites the 2024 National Assessment of Educational Progress reading assessment results released last year. It showed that 12th grade reading scores were at the lowest level since the assessment began in 1992. Nearly a third of those 12th graders scored below the assessment's "basic" level in reading, meaning they likely "cannot draw general conclusions based on concepts presented explicitly in a text." Younger children aren't better off: a recent report from the Annie E. Casey Foundation found that 70 percent of fourth graders, or around two million kids, can't read at a proficient level.

"What I am seeing in my classroom is no longer a hunch," Jagt writes. "There is a measurable, generational collapse in sustained reading and writing, and the academy is responding to it with improvisation and exhaustion rather than the structural overhaul it requires."

Pupils arriving unable to read is an increasingly common complaint from college-level educators amid the explosion of generative AI. Many students treat AI as a genuine learning tool — perhaps to summarize a lengthy article they can't understand, for example — becoming reliant on its speedy responses to race through coursework.

More flagrantly detrimental to learning, plenty more use the tech to generate entire essays and solve math problems — or, in a word, cheat. That many universities have partnered with tech companies to provide students with access to their shiny AI models has only served to rubber stamp and accelerate the tech's adoption in the classroom, marooning individual instructors to figure out how to work around AI on their own.

Comment Europe is free to rearm and STAY armed. (Score 0) 154

Feasting on the sugar teat of US military welfare has consequences like voluntary national weakness. Europe is amply wealthy enough to afford rearmament (and free to cut spending wasted on anything which does not benefit European security).

Trump did the EU an unwitting favor. So did Putin. What it does with that teachable moment is a matter of choice.

Submission + - FCC Wants to Kill Burner Phones By Forcing Telecoms to Get All Customers' IDs (404media.co)

An anonymous reader writes: The Federal Communications Commission (FCC) wants to make it effectively impossible for people to buy what many call burner phones — a phone not explicitly linked to your identity at the point of purchase — which would impact privacy-conscious people, to domestic abuse survivors, to journalists, and many more. The FCC plans to do this by legally forcing the country’s telecoms to store a wealth of personal information about essentially all phone customers, including a government issued identification number and their physical address, alarming privacy advocates and civil rights activists who compare the measures to those from authoritarian countries where it can be difficult to buy a mobile phone plan without giving up your identity.

The proposed change would drastically shake up how people obtain phone plans in the U.S., and have all sorts of privacy and cybersecurity knock-on effects. The FCC is proposing the data collection partly as a way to combat scammers, with telecoms being required to collect other information on business and foreign customers like the intended use case of their bulk phone plan purchase and their IP address. But the changes would mean telecoms collect data on all new and renewing customers, and the FCC provides a long list of other things that the collected data could help authorities with.

In a synopsis of the proposed changes, the FCC writes, “Specifically, we seek comment on requiring originating providers to, at a minimum, obtain and retain the name, physical address, government issued identification number, and an alternate telephone number of any new and renewing customer before granting access to its services.” The goal of collecting this data, the FCC writes, is to deter some scammers from getting onto a telecom network in the first place, and so “enforcers will be better able to identify the scammers when they do.” The FCC compares the changes to the sort of data collected by banks to prevent money laundering.

One section stresses that the newly collected data would help “law enforcement to more easily identify callers that use the network to perpetuate crimes by ensuring that voice providers have accurate and complete customer information.” It goes on to ask if the data would help identify people buying and selling illicit goods; the investigation of “fraud, espionage, or influence operations that undermine national security”, and “address abuse in text messaging networks.” “Criminals continue to leverage the anonymity provided by phone calls and texts to defraud Americans and exploit communications networks to further other crimes,” one section reads.

Slashdot Top Deals

Experiments must be reproducible; they should all fail in the same way.

Working...