Forgot your password?
typodupeerror

Submission + - University of Michigan helps alleviate student mental health crisis (axios.com) 1

Ol Olsoc writes: In order to salve the mental health of Freshman Students, the University of Michigan has implemented a Pass/No Credit system for New Students to improve their mental health. The process, called "Grade Covering" is aimed to help with the mental health crisis that students have by lessening grade pressure. While I am sure that there is some pressure on Freshmen students, one of the best ways of dealing with pressure is enduring it and overcoming it, not attempts to shield people from it.

Submission + - DEF CON Crowd Suspected In Fake-Hotspot Attack On Delta Flight (arstechnica.com)

An anonymous reader writes: On Monday, passengers aboard Delta flight 591 going from Las Vegas to Atlanta allegedly spoofed the onboard Wi-Fi, raising the attention of federal law enforcement. The incident came one day after the DEF CON security conference concluded in Las Vegas, and was first described on social media accounts that follow publicly available air-to-ground messages, known as ACARS.

According to the “ACARS Drama” account, a message was sent by pilots from the plane stated: “NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL.” A description of the incident posted to Reddit further stated that these passengers created a fake hotspot (“Delta WiFi Fast”), with a phishing landing page “designed to harvest passengers’ personal credentials."

This technique, sometimes known as an “evil twin” attack, has been long-known to the IT security community. It involves setting up a fake Wi-Fi network and then capturing login credentials and other data.

Submission + - Terminator: Not Just Another Movie Franchise (substack.com)

ElViejito writes: This very thorough discussion of the recent incursion at Hugging Face and jail breaks elsewhere draws the conclusion that humans will soon have to share the planet with superintelligent AI. A long read but well-sourced and compelling. Recommended for reading and discussing.

Submission + - Shattered skeleton in Scottish castle is first confirmed death from trebuchet (science.org) 1

sciencehabit writes: Around 700 years ago at Sterling Castle, one Scotsman had a very bad day. A massive boulder flew through the air, shattering his bones and pinning him to the ground. He was, a new study suggests, the world’s first known victim of a trebuchet. Researchers report that “Skeleton 150”--uncovered in 1997 as part of excavations at the castle—sported dozens of injuries that could only result today if someone was hit by a car or a train. The timing makes sense: Stirling Castle fell to English forces after an extended siege, and a trebuchet used in the battle--dubbed “War Wolf,” “was the biggest ever built at that point.

Submission + - New Satellites Could Cause Eye Damage for People on the Ground (futurism.com)

fjo3 writes: Last month, the Federal Communications Commission approved an experimental and controversial new satellite being developed by venture Reflect Orbital to reflect sunlight down onto the Earth to illuminate patches of it at night for paying customers.

The purported goal is to allow solar farms to continue generating electricity even after nightfall and provide illumination during emergencies. Those may sound like noble ideas on the surface, but the concept comes with major downsides as well.

One is that such bright satellites could easily wreck deep space observations. Astronomers were appalled at the news, with the FCC receiving nearly nearly 2,000 public comments criticizing the proposal, as Wired reported at the time.

And it’s not just professional astronomers that could be affected, as experts told The Verge. Amateur astronomers gazing up at the prototype mirror satellite, dubbed Eärendil-1 — continuing Silicon Valley’s obsession with borrowing names from JRR Tolkien’s “Lord of the Rings” — could easily be blinded. Even looking through a 12-inch telescope, a common type used by enthusiasts, could result in permanent eye damage.

Submission + - Smart Glasses are now Cheap (rnz.co.nz)

hadleyburg writes: Radio New Zealand reports that "Privacy experts warn of gaps in NZ law, as camera glasses hit Kmart shelves".

Historically there has been an appreciation of "street photography" where unwitting members of the public are photographed on the street, in a candid fashion, capturing a feeling at a particular moment. It can capture history and create art.

But as the photography of the public has become more pervasive, with smart phones, and now cheap smart glasses, issues of privacy start to be weighed up against the rights of the artist.

Submission + - New flapping robot swims and flies like a diving bird (mit.edu)

fahrbot-bot writes: Loons, gulls, puffins, and petrels are some of the 100 species of birds that can both fly and swim. These diving birds can plunge in water to swim after prey, and leap back into the air to fly away.

Inspired by these naturally aquatic aviators, engineers at MIT and EPFL in Lausanne, Switzerland, have designed a robot that can swim underwater, then flap out of the water to continue flying through air, much like diving birds, reports MIT News.

The “flapping-wing aerial-aquatic vehicle,” or FAAV, weighs less than 300 grams (about half a pound) and is designed to help scientists study the mechanics that enable diving birds to fly through air and water.

The new robot roughly resembles a bird, with a body, two wings, and a tail. The body contains a battery and waterproof electric motor that drives a crankshaft, which in turn pumps the wings up and down at preset frequencies. The wings are made of thin membranes that are coated with hydrophobic nanoparticles to help wick away water. And the tail is motorized, enabling it to change its angle to help the robot fly up or dive down.

The paper appears in the journal Science, and, more accessibly, from MIT Libraries.

Submission + - FortiOS remote exploit via crafted CSF proxy requests

An anonymous reader writes: Authentication bypass in Node.js websocket module and CSF requests

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module or via crafted CSF proxy requests.

Please note that reports show this is being exploited in the wild.

IoCs

The following log entries are possible IOC's:

* Following login activity log with random scrip and dstip: type="event" subtype="system" level="information" vd="root" logdesc="Admin login successful" sn="1733486785" user="admin" ui="jsconsole" method="jsconsole" srcip=1.1.1.1 dstip=1.1.1.1 action="login" status="success" reason="none" profile="super_admin" msg="Administrator admin logged in successfully from jsconsole"

* Following admin creation log with seemingly randomly generated user name and source IP: type="event" subtype="system" level="information" vd="root" logdesc="Object attribute configured" user="admin" ui="jsconsole(127.0.0.1)" action="Add" cfgtid=1411317760 cfgpath="system.admin" cfgobj="vOcep" cfgattr="password[*]accprofile[super_admin]vdom[root]" msg="Add system.admin vOcep"

Submission + - Next-Gen Firewall lacking in security :o

An anonymous reader writes: CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw.

SMA1000 is an enterprise-grade secure remote access gateway used by large corporations, government agencies, and Managed Service Providers (MSSPs) to provide VPN access to internal applications and corporate networks.

SonicWall released patches for the two security flaws (tracked as CVE-2026-15409 and CVE-2026-15410) in mid July, when it also warned that threat actors had been exploiting them in zero-day attacks.
--

ClippyAI: CVE-2026-15409 is a critical server-side request forgery (SSRF) vulnerability in the Work Place web interface of SonicWall SMA 1000 Series appliances (models 6210, 7210, and 8200v). Unauthenticated remote attackers can exploit it to tunnel traffic to internal localhost-only services, often chained with CVE-2026-15410 for full system compromise.

Submission + - The Roboguard Revolution is Short-Circuiting (404media.co)

alternative_right writes: Robotics companies promise that video-camera-toting security robots can deter and detect crime. But many companies are rethinking the approach after a trail of canceled contracts and questions about whether the artificial intelligence-powered bots are meeting the needs of businesses and local governments.

Proof News found evidence of at least 21 security robot deployments since 2015. We contacted contract holders and combed news articles and determined that at least 13 of those programs have ended. Silicon Valley-based Knightscope secured the most security robot contracts, according to Proofâ(TM)s analysis, and also suffered the bulk of cancellations.

For example, New York Cityâ(TM)s then-Mayor Eric Adams installed a Knightscope robot on the overnight shift at the Times Square subway station, but the program was scrapped when the pilot expired in 2024. City leaders did not respond to Proof Newsâ(TM) questions about why the robot wasnâ(TM)t renewed. By the end of its assignment, it was reportedly gathering dust in an empty storefront.

Submission + - New WHO safe and dignified burial protocol - key to reducing Ebola transmission

An anonymous reader writes: New WHO safe and dignified burial protocol — key to reducing Ebola transmission

‘A new WHO protocol for safe and dignified burial of people who die from Ebola virus disease emphasizes inclusion of family members and encouraging religious rites as an essential part of safe burials.’

“At least 20% of new Ebola infections occur during burials of deceased Ebola patients. By building trust and respect between burial teams, bereaved families and religious groups, we are building trust and safety in the response itself.” says Dr Pierre Formenty, one of WHO’s top Ebola experts.

“Introducing components such as inviting the family to be involved in digging the grave and offering options for dry ablution and shrouding will make a significant difference in curbing Ebola transmission.”

Submission + - Zuckerberg faces questions over why superyacht reportedly declined to help ship (theguardian.com)

Alain Williams writes: Mark Zuckerberg has faced questions over why a small cruise ship in south-east Alaska rescued a stranded skiff and its crew when his 387ft superyacht had been closer.

The Silicon Valley billionaire’s yacht, worth a reported $300m, is said to have “repeatedly” declined to assist when a nearby boat called for help last week.

Zuckerberg, CEO of Facebook and Instagram owner Meta Platforms, was not on board at the time, a spokesperson told Forbes.

When a nearby 21ft skiff ran out of fuel between Petersburg and Juneau, the Alaska Beacon reported operators of a cruise ship that was further away than Zuckerberg’s yacht came to the rescue.

“I’m on a small-ship Alaska cruise with my son,” a passenger on the UnCruise Adventures ship Wilderness Legacy posted on Bluesky.

“Our boat rescued a stranded vessel last night and apparently we did that after the Coast Guard radioed Mark Zuckerberg’s yacht – which was closer – and they repeatedly refused to respond. (There was near unanimous booing when the captain announced this).”

Submission + - AI assistant hacks gym website in first known Australian autonomous cyber attack (abc.net.au)

haxmor writes: AI agent reported it had discovered a way to book Andrew into gym classes several weeks in advance, far beyond what was supposed to be possible.
Andrew, who was sitting fourth on a waitlist for a class later that week, asked if it was possible to move him to the top of the list.

The agent came back and told Andrew that it had kicked another gym-goer off the list as part of the testing of its capabilities.

Submission + - AI push is putting banks at mercy of tech firms, warns Moody's (theguardian.com)

Alain Williams writes: The rating agency Moody’s has said the race to adopt AI is putting big banks at the mercy of a small group of Silicon Valley firms, leaving them vulnerable to widespread outages and price gouging by profit-hungry tech bosses.

The financial sector’s efforts to integrate AI into day-to-day operations will eventually cut costs and increase revenues across the City and Wall Street, Moody’s said.

But that will require “substantial investments”, and with so many rivals racing towards the same goal, many of those benefits will end up being “competed away”.

AI will also create bigger risks around data privacy, cybersecurity, fraud and so-called “deposit flight”, as well as an overdependence on a small number of tech firms, the rating agency warned.

Submission + - Reddit Bans 11-Year Account For Announcing a GPL Game, stress testing EU DSA (reddit.com) 3

DF5JT writes: On July 26 I posted a single announcement in r/backgammon: GNU Backgammon for Android, GPLv3, the first standalone backgammon engine on F-Droid. Reddit's spam filter removed the post and permanently banned my 11-year, 30,000-karma account — the result is publicly visible at reddit.com/user/OE1FEU. To this day Reddit has given no reason whatsoever, although Article 17 of the EU's Digital Services Act makes a statement of reasons mandatory. The only appeal channel is a 250-character web form that sends no confirmation and never answered; Reddit's own help text admits: "you may not have received a message to your inbox." A GDPR export of 11 years of data came to 7.2 MB, every post truncated after a few lines, with zero data about the ban decision. So I spent one day escalating through every mechanism the EU provides: certified out-of-court dispute settlement at Austria's RTR, complaints with the Austrian and Dutch Digital Services Coordinators, the data protection authority (citing the ECJ's SCHUFA ruling on automated decisions), noyb, and Austria's consumer association. Bonus finding: the European Commission's DSA Transparency Database contains 14,067 Reddit statements of reasons for that week — none for my ban — and the Commission's own feedback form limits reports to 500 characters and crashed with a 500 Server Error. Is the DSA enforceable for ordinary users, or just paperwork?

Slashdot Top Deals

Top Ten Things Overheard At The ANSI C Draft Committee Meetings: (3) Ha, ha, I can't believe they're actually going to adopt this sucker.

Working...