Submission + - Canadian grocery giant Loblaws advertises, in the sky (thestar.com)
A large LED aerial drone display appeared over Toronto’s skies late Thursday night promoting Loblaw’s [a major Canadian grocery retailer] health services app in an advertisement that the city says they were not made fully aware of.
Videos and photos posted online show a large-scale drone advertisement for President’s Choice Health that sparked a heated discussion online about the use of airspace for promotional material.
In an email to the [Toronto] Star, a City of Toronto spokesperson said that while they approved the rental of Fort York National Historic Site for a third-party drone operator, they didn’t know that Loblaw would be behind the display.
The City was not informed of the client associated with the display and is updating its booking requirements to add disclosure of this information as a requirement for future bookings,
said spokesperson Nichole Jankowski.
The advertisement could be seen from multiple vantage points downtown with several phrases urging viewers to ask the Loblaw-owned platform medical questions. Some of the questions on display included “Can melatonin lose its effect? Is that third coffee keeping me up?” and “Do I really need 8 hours of sleep?” The sleep-related questions are followed with a QR code.
Commenters in threads on Reddit and posts on X, where videos of the ads surfaced, criticized the company’s use of airspace, including a tweet that calls for this sort of advertising to be banned. Loblaw confirmed the advertisement in an emailed statement to the Star.
The drone show was intentionally short and carefully considered to minimize brightness and disruption. All appropriate permissions were obtained for the show, including airspace approval secured through NAV CANADA and ground space approval secured through Fort York.
reads the retail company’s statement. According to their website, Loblaw used the ad to launch their health app:
Torontonians along the waterfront can look to the skyline at approximately 11 p.m. ET on September 10, as a series of health-related questions appear overhead during a 15-minute aerial display,
reads a release from Loblaw Companies Limited. Prior to Thursday evening, the Fort York landing page on the city’s website posted that a display would be happening.
In order to stage a drone show, such as the one on Thursday evening, organizers have to apply for an SFOC-RPAS — a permit for flying a drone at an advertised event — with Transport Canada. The federal agency, who has jurisdiction over the airspace, said that they issued an SFOC-RPAS for the event, but would not provide any more information about the applicant due to “privacy requirements.”
Submission + - Vulnerability giving attackers full control on Mac is under active exploitation (arstechnica.com)
“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the Netherlands National Cyber Security Centrum warned earlier this week. “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”
The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the “state management,” which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause.
A video of the exploit in action can be found here. Details of CVE-2026-65400 became public at last week’s Black Hat security conference. Apple said last week that CVE-2026-65400 “may” allow an attacker without credentials to gain access to a Mac. It’s unclear why Apple hedged, but softening language is common among most tech developers when disclosing vulnerabilities.
As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting. Security practitioners generally advise Mac users to keep the port closed even when using screen sharing and to instead connect over a VPN or through SSH tunneling. The alternatives require actions that aren’t within the capabilities of most users.
The safest practice is to block screen sharing, enable it only when screen sharing is needed, and to turn the feature off once a session has ended. Screen sharing can be turned on or off by accessing System Settings > General > Sharing and toggling the switch for Screen Sharing. Of course, installing last week’s security update is also a must. Sharing is not caring.
Comment Credible (Score 5, Informative) 69
Submission + - Of Course They Booed
And perhaps it’s a little ironic that this graduating class, a group that we've been told time and time again has spent the last four years using ChatGPT to cheat their way through college, would display such sour sentiment towards "AI." But as most commencement speakers seem duty-bound to repeat, graduation marks the entry into adulthood; it is "the beginning of your life"; "the future is now" – that sort of thing. And just these students are now officially adults, they’re being told a very different story: that there really is no future. There are no jobs. And whatever thing they might have learned to do or learned to love in college, whatever career they might have believed they were preparing for, "AI" is going to destroy all of that. No wonder they boo.
But the growing pushback against "AI," and the growing pushback against ed-tech more generally, is not simply a rejection of technology. These efforts are, as Astra Taylor and Saul Levin recently argued in The Guardian, a rejection of the profoundly anti-democratic practices that have pushed technologies into all aspects of our lives without our consent and often in the face of our outright opposition. These technologies have been marketed to us as solutions to all sorts of social problems — and have done so, in no small part, by bypassing and undermining the very public sphere in which debate and discussion can take place: schools, libraries, the arts, the media. The adoption of education technology, "AI" or otherwise, has been anti-democratic in practices both big and small. Despite all the talk of progressive education and ed-tech, it has been experienced as something else entirely. Throughout the country for the past few decades Gates (via the Gates Foundation), other billionaire philanthropists, and giant companies have shaped education funding and policy through a combination of technology and testing.
At one point, perhaps, people were willing to welcome devices into schools, into the classroom. They believed the stories, not just that "this is the future," but that future meant something better for everyone. “Access” signaled equality. But as the tech billionaires have embraced authoritarianism and inequality, and as their apocalyptic rhetoric about not just the "end of work," but quite literally the end of the world grows louder and louder — all while they amass more wealth than anyone in history — it is quite apparent that their promises about the future do not include us. Their vision of future does not make any space or allowance for our children to choose their own futures.
Submission + - More Than Half Of What Americans Eat Is Ultra-Processed (studyfinds.com) 2
More than half of calories eaten by American adults come from ultra-processed foods, industrial products containing few or no real whole-food ingredients and made with additives that keep them cheap, shelf-stable, and highly appealing. For kids, that figure climbs even higher. A recent study found that of 651 baby and toddler food products sold in the eight largest grocery stores in North Carolina, 71% were classified as ultra-processed.
Submission + - Two-thirds of babies watch screens — some for eight hours a day (thetimes.com)
Nearly a third of newborns were found to be watching screens for more than three hours a day, while almost 20 per cent of infants of four to 11 months used screens for more than an hour a day.
The report comes after the government issued guidance that children under two do not use screens at all, apart from communal activities such as video-calling relatives.
Submission + - Rectal cancer deaths rising rapidly among millennials (nbcnews.com) 2
If the trend continues, rectal cancer deaths will exceed the number of colon cancer deaths — already the nation’s No. 1 cause of cancer death in people under age 50 — by 2035.
Submission + - Maryland Becomes First State To Pass Bill Banning 'Surveillance Pricing' (denver7.com)
Submission + - Palantir posts Bond villain manifesto on X
Submission + - the highest-paying jobs have the worst scores (fortune.com)
While the overall weighted exposure was 4.9, Karpathy’s data also showed that professions earning more than $100,000 a year had the worst average score (6.7), while the those earning less than $35,000 had the lowest exposure (3.4).
Submission + - Moria creator Robert Koeneke passed away (wikipedia.org)
Comment Re:Starkly (Score 1) 58
Submission + - How One Company Survived a Ransomware Attack Without Paying the Ransom (esecurityplanet.com)
Tony Mendoza, Senior Director of Enterprise Business Solutions at Spectra Logic, laid out the details of the attack at the annual Fujifilm Recording Media USA Conference in San Diego late last month, as reported by eSecurity Planet.
“We unplugged systems, as the virus was spreading faster than we could investigate,” Mendoza told conference attendees. “As we didn’t have a comprehensive cybersecurity plan in place, the attack brought the entire business to its knees.”
To make matters worse, backups were also corrupted, but with the help of recovery specialist Ankura, uncorrupted snapshots and tape backups helped the company get back online in days, although full recovery took a month.
“We were able to restore everything and paid nothing,” said Mendoza. “Other than a few files, all data was recovered.”
The attack, which started from a successful phishing attempt, "took us almost a month to fully recover and get over the ransomware pain," said Mendoza.
Submission + - Judge Orders Twitter To Unmask FBI Impersonator Who Set Off Seth Rich Conspiracy (npr.org)
The ruling could lead to the identification of the person behind the Twitter name @whyspertech. Through that account, the user allegedly provided forged FBI materials to Fox News. The documents falsely linked Rich's killing to the WikiLeaks hack of Democratic Party emails in the lead-up to the 2016 election.
While Twitter fought to keep the user's identity secret, U.S. Magistrate Judge Donna Ryu in Oakland, Calif., ordered on Tuesday that the tech company must turn over the information to attorneys representing Rich's family in a defamation suit by Oct. 20.
It is the latest twist in a years-long saga over a conspiracy theory that rocked Washington, caused a grieving family a great deal of pain and set off multiple legal battles.