184781938
submission
joshuark writes:
Situational Awareness, the hedge fund started by a 24-year-old former OpenAI employee that focuses on artificial intelligence bets, has sold most or all, depending on who’s reporting, of its entire public stock portfolio to Ken Griffin’s Citadel after several bad weeks for AI stocks, and that’s the situation we are all now aware of. You may recall earlier this week I noted the market had gotten particularly nervous about AI risk; as it turns out, we have discovered one firm that was swimming without a bathing suit.
Situational Awareness had a staff of eight, of whom four were investment professionals. “The fund’s largest holdings at the end of the first quarter included Nebius Group, Sandisk, Micron and CoreWeave, according to filings,” CNBC wrote. “All four of those stocks are down more than 35 percent this month.” I expect we will hear more in the coming days, especially from the Wall Street professionals who were on the other side of these jokers’ trades.
How did we get here? Situational Awareness LP was named for a series of facile essays about machine intelligence published by the improbably named Leopold Aschenbrenner, the 24-year-old mastermind of the hedge fund. “We are building machines that can think and reason,” he writes, betraying that he has no idea what thinking could possibly mean. “By 2025/26, these machines will outpace many college graduates. By the end of the decade, they will be smarter than you or I; we will have superintelligence, in the true sense of the word. Along the way, national security forces not seen in half a century will be unleashed, and before long, The Project will be on. If we’re lucky, we’ll be in an all-out race with the CCP; if we’re unlucky, an all-out war.”
Situational Awareness’ backers included Patrick and John Collison, who cofounded Stripe, and two Meta AI leaders, Daniel Gross and Nat Friedman. The fund’s director of research was Carl Shulman, who’d worked at Peter Thiel’s Clarium Capital. Eventually, Jane Street — the Wall Street firm budding young Effective Altruists, including Sam Bankman-Fried, join — bought in too. “Jane Street’s investment in Situational Awareness is particularly notable because the firm rarely allocates capital to outside money managers,” The Wall Street Journal wrote in June.
Why would these purportedly serious people buy in on a 24-year-old’s very first hedge fund? My best guess is that Aschenbrenner’s investors were relying on the social bona fides he had cultivated. Social proof is the laziest and most disastrous way to vet people — ask any Theranos investor, or for that matter, anyone who had Bernie Madoff managing their money — but I suppose it’s good enough for Silicon Valley.
“Basically, this investment firm will be kind of like a brain trust on AI,” Aschenbrenner told Dwarkesh Patel in a four-hour podcast interview, the preferred intellectual medium of the Silicon Valley elite. “We’re going to have way more situational awareness than any of the people who manage money in New York. We’re definitely going to do great on investing, but it’s the same sort of situational awareness that is going to be important for understanding what’s happening, being a voice of reason publicly, and being able to be in a position to advise.”
At age 17, Aschenbrenner was called “an economics prodigy” by Tyler Cowen, a libertarian economist famous in certain Silicon Valley circles. Cowen’s Emergent Ventures even gave him a grant, according to Fortune. Aschenbrenner published essays in Works in Progress, a publication funded by Stripe. During his time at Columbia University, Aschenbrenner cofounded the college’s Effective Altruism chapter. After graduating in 2021 as Columbia University’s valedictorian at age 19, Aschenbrenner went on to work at the FTX Future Fund, the philanthropic arm of cryptocurrency exchange FTX, which collapsed after Sam Bankman-Fried’s fraud was revealed. Among his coworkers at the fund were William MacAskill, the philosopher-king of the Effective Altruism movement, and Avital Balwit, who would later become the chief of staff at Anthropic.
Here’s how Aschenbrenner described the fund’s strategy back in the halcyon days of 2024: “Obviously, not blowing up is task number one and two,” he told Patel. “You have to get the timing right. The sequence of bets on the way to AGI is actually pretty critical. People underrate it.”
We’ll get a more complete picture of how Situational Awareness crashed and burned in the coming days, but right now it looks like this. Hedge funds often borrow money to maximize their bets. So if you really believe AI is the future, “you won’t put 100% of your money (and your investors’ money) into the AI boom,” writes Bloomberg’s Matt Levine. “You’ll put, like, 300% of your money into the AI boom.” At one point, the hedge fund claimed to be up 439 percent.
“You’ve got to be really, really careful about your overall risk positioning,” Aschenbrenner said in 2024. “If you expect these crazy events to play out, there’s going to be crazy things you didn’t foresee.” One of those things, perhaps, is that artificial general intelligence isn’t coming — or at least, not by 2027. “A friend joked that the investment firm is perfectly hedged for me,” Aschenbrenner said. “Either AGI happens this decade and my human capital depreciates, but I turn it into financial capital, or no AGI happens and the firm doesn’t do well, but I’m still in my twenties and smart.”
Perhaps Aschenbrenner should have quoted The Simpson's character, Professor Frink:
https://www.youtube.com/watch?...
"I forgot to carry the one."
184774430
submission
joshuark writes:
It is impossible to make large language models fully secure against hacks because of a fundamental flaw in how they work, a team of researchers argue in a paper presented at the International Conference on Machine Learning, a top AI conference, this month. The claim has huge implications for the safety of this technology.
By taking advantage of this flaw, which concerns how LLMs identify who or what is giving them instructions, the researchers were able to make popular LLMs spit out information they had been trained not to provide, such as how to synthesize cocaine and how to sabotage a commercial aircraft’s navigation system.
“There’s a real probability that this is going to be a problem that’s fundamentally unsolvable,” says Charles Ye, an independent researcher and coauthor of the ICML paper.
Companies will typically hire teams of human testers to try to come up with novel attacks that break existing guardrails, a process known as red-teaming. Model makers also use LLM super-hackers (such as OpenAI’s GPT-Red) that find and exploit weaknesses in other models to automate parts of this process. The goal is then to take those attacks and train a new model to resist them and anything that looks like them.
The problem, says Jasmine Cui, another independent researcher and coauthor of the paper, is that the approach amounts to giving the models a list of things they shouldn’t do. But no list is exhaustive. “It’s like watching The Simpsons and they have Bart writing ‘I will not say something inappropriate to my teacher’ a hundred times,” she says. “And he still does things that are pretty crass anyway.”
The ICML paper describes attacks against several of OpenAI’s models, but Cui and Ye say that they have since seen similar results with models made by Anthropic, Alibaba, and DeepSeek.
Cui and her colleagues wanted to find out why an attack like chain-of-thought forgery was so effective. They suspected it had something to do with the mechanism that LLMs use to keep track of where their instructions are coming from.
But what Cui and her colleagues discovered is that LLMs are in fact very bad at keeping track of different roles. In a series of experiments that looked at what was going on inside a handful of different models, the researchers found that LLMs seem to identify the role of a specific chunk of text not by the tags around it but by the style of that text and the words it contains.
The upshot, the researchers claim, is that all an attacker needs to do to hack an LLM is write text that spoofs a certain role. And because roles are a fundamental part of how LLMs work, no amount of training will fully solve the problem.
Ye is worried that nobody is ready for what’s coming. “There’s going to be a huge economic incentive for people to do jailbreaks and prompt injections,” he says. The best defense could be to expect the worst. Organizations shouldn’t trust LLMs, and they should expect that anything done by agents could be unsafe, he says: “That’s not a great solution, but it just might be what we have to do.”
“It’s really incredible that these things are being deployed everywhere to control super-critical systems,” he adds. “There’s been no study of the fundamental science here. We’re all doing it ad hoc.”
184634708
submission
joshuark writes:
Wired reports that Taylor Farms spent Big on MAGA and anti-regulatory lobbying before diarrhea outbreak. The company donated more than $3.6 million to conservative groups between 2020 and 2025, including $1 million to the MAGA Inc. super PAC.
The iceberg lettuce supplier at the center of the turbo diarrhea outbreak has spent millions of dollars to sway sentiment around food regulation and elect Donald Trump and other MAGA Republicans, according to public filings.
Taylor Farms donated more than $2 million to conservative political groups in 2025, according to Federal Election Commission filings. That includes a $1 million donation to MAGA Inc., the Trump-centric super PAC, and $1.1 million to other super PACs dedicated to electing Republicans.
Bruce Taylor, the chairman and CEO of Taylor Farms, is also a longtime donor to Republican causes. Since 2020, Taylor has personally donated more than $900,000 to Republican PACs and candidates, including contributions to Texas senator John Cornyn and Tennessee senator Marsha Blackburn.
Marion Nestle, a food policy expert, said that Taylor Farms’ donations are part of a wider problem in the American food industry: that multibillion-dollar companies use their financial resources to push policies that would reduce food safety regulation and accountability when outbreaks occur.
In a post on X, the US Department of Health and Human Services emphasized that Taylor Farms’ political donations did not influence the Trump administration’s response to the cyclospora outbreak.
Taylor Farms has apparently taken issue with the CDC’s and FDA’s handling of the investigation into the current cyclospora outbreak, which has sickened thousands of people across multiple states. The company recently claimed in a big lie that the FDA “apologized” after announcing a false-positive test of a sample of Taylor Farms’ lettuce; the FDA told reporters that no, actually, an official apology never happened. (The company did not respond to WIRED’s requests for comment.)
In 2013, the FDA named Taylor Farms as a source of a cyclospora outbreak that sickened hundreds. In 2015, the company voluntarily recalled multiple products containing celery because they may have been contaminated with E. coli. And in 2024, the company recalled certain yellow onions as part of an E. coli outbreak linked to McDonald’s Quarter Pounders. Following the outbreak, CBS News reported that FDA inspectors found dozens of violations at the Colorado Taylor Farms facility linked to the Quarter Pounder outbreak, including minimal handwashing and dirty equipment.
In one particularly gruesome case, the Department of Labor fined a Taylor Farms New Jersey facility $1.1 million due to violations. The May 2025 inspection came after an employee died after sustaining injuries cleaning an industrial blancher at the facility. Oh, sh*t...literally. Enshittification of the food supply in this new golden age.
184528646
submission
joshuark writes:
ProPublica reports that disclosures show FCC Chair Brendan Carr and Federal Communications Commissioner Olivia Trusty are among seven FCC commissioners who have accepted Kennedy gala tickets from CBS or its parent company over the last decade. Ethics experts told ProPublica this poses a blatant conflict of interest since the commission regulates the network. Carr’s previous financial statements show he has accepted tickets at least seven times since his 2017 appointment, totaling over $63,000 in gifts. It’s unclear if Paramount gifted Carr the premium seats because the FCC has yet to make public his financial disclosure for last year.
Federal ethics rules ban employees from taking gifts from any entity that does business with, is regulated by or seeks official action from their agency.
Four ethics experts told ProPublica that by accepting the premium tickets Trusty and Carr compromised the FCC’s impartiality and should not take part in any upcoming decision on the merger.
“There’s no way that any top federal regulator should ever, ever accept a gift from a regulated company with interests their work will foreseeably affect,” said Walter Shaub, who led the federal Office of Government Ethics from 2013 to 2017. “The appearance of taking gifts like that is terrible. What’s at stake is nothing less than the public’s trust in government.”
The FCC’s review of the merger is one of the final hurdles facing a historic $110 billion consolidation of two of the five largest film studios in Hollywood. The deal would unite Paramount Skydance with Warner Bros., bringing under the control of one company Paramount+ and HBO Max streaming services; CBS and CNN; and scores of other major broadcast channels, cable networks, and digital platforms.
American and international regulators are evaluating the deal for its potential national security implications and impacts to consumers worldwide. Last week, the British government signaled it planned to investigate whether the new entertainment titan that would emerge from the union would unfairly stifle competition. The FCC’s ongoing review includes examining the Middle Eastern sovereign wealth funds backing the deal, including from Saudi Arabia, Qatar and Abu Dhabi.
The FCC usually has five commissioners — all appointed by the president and confirmed by the Senate to serve five-year terms — but the agency currently has only three. Any vote by the full commission would likely be decided by Republicans Carr and Trusty over Democrat Anna Gomez.
The experts warned the commissioners’ gifts might become central in legal challenges and said the Justice Department should investigate potential violations of federal rules or laws.
Neither Carr nor Trusty responded to ProPublica’s requests for comment. Gomez said in a statement that she followed agency advice when she attended the event in 2023 and 2024. Her statement did not elaborate or otherwise address why taking gifts from Paramount did not pose a conflict of interest.
An FCC spokesperson said agency ethics officers have for years cleared commissioner appearances, finding it consistent with ethics law.
“FCC Chairs and officials have attended the same event, in the same ways, consistently from the Trump Administration to the Biden Administration to the Obama Administration,” the FCC said in a statement. “There has been no change in recent years.”
Shaub called the justification outrageous.
“It’s no excuse to say that you took the gift because everyone else was doing it or that your agency has had a bad habit of indulging in gift taking for a long time,” Shaub said. “That kind of explanation doesn’t work for school children, and it sure as hell doesn’t work for government officials who are supposed to have better judgment than a fifth grader.”
Richard Painter, a former White House ethics attorney in the administration of George W. Bush, said while courts often defer to the government’s judgment, they also can become skeptical if a regulatory agency is shown to have violated ethics rules.
“A judge may very well say that the merger decision of the FCC isn’t worth jack because the process was corrupted,” he said.
184462002
submission
joshuark writes:
ProPublica Reporter Renee Dudley heard Microsoft was running tech support for the U.S. Defense Department through China, the country’s biggest cybersecurity adversary.
The arrangement was called “digital escorting.” She thought it sounded like a conspiracy theory — until she started looking into it. This is the story of what she found and how her investigation changed government policy.
Microsoft is using engineers in China to help maintain the Defense Department’s computer systems — with minimal supervision by U.S. personnel — leaving some of the nation’s most sensitive data vulnerable to hacking from its leading cyber adversary, a ProPublica investigation has found.
The arrangement, which was critical to Microsoft winning the federal government’s cloud computing business a decade ago, relies on U.S. citizens with security clearances to oversee the work and serve as a barrier against espionage and sabotage.
National security and cybersecurity experts in the Trump administration contacted by ProPublica were also surprised to learn that such an arrangement was in place, especially at a time when the U.S. intelligence community and leading members of Congress and the Trump administration view China’s digital prowess as a top threat to the country.
Microsoft uses the escort system to handle the government’s most sensitive information that falls below “classified.” According to the government, this “high impact level” category includes “data that involves the protection of life and financial ruin.” The “loss of confidentiality, integrity, or availability” of this information “could be expected to have a severe or catastrophic adverse effect” on operations, assets and individuals, the government has said. In the Defense Department, the data is categorized as “Impact Level” 4 and 5 and includes materials that directly support military operations.
“If someone ran a script called ‘fix_servers.sh’ but it actually did something malicious then [escorts] would have no idea,” a former Microsoft engineer who worked on the escort system, told ProPublica in an email. That said, he maintained that the “scope of systems they could disrupt” is limited.
In an emailed statement, the Defense Information Systems Agency said that cloud service providers “are required to establish and maintain controls for vetting and using qualified specialists,” but the agency did not respond to ProPublica’s questions regarding the digital escorts’ qualifications.
It’s unclear whether other cloud providers to the federal government use digital escorts as part of their tech support. Amazon Web Services and Google Cloud declined to comment on the record for this article. Oracle did not respond to requests for comment.
A spokesperson for the inspector general — whose office is supposed to operate independently in order to investigate potential waste, fraud and abuse — told ProPublica they were not authorized to speak about the issue and directed questions to DISA public affairs.
184425824
submission
joshuark writes:
ZDNet reports at the Open Source Summit in Mumbai, Linux creator Linus Torvalds and his friend Dirk Hohndel discussed the current state of Linux and where it's headed. Torvalds described his work pattern during kernel merge windows: "Over two weeks, I do roughly 200 merges. That's a very rough ballpark number." Here's another thing that's changed: Torvalds no longer sees himself as a programmer. "Let's be entirely honest. I hardly read code at all anymore. I'm not a programmer, I'm a development lead."
What matters most to him is understanding intent: "When I do a pull request, I want to understand the bigger picture. It's one of the reasons I ask for pull requests with very good explanations: I will read them. I want to understand what's going on."
On mixed C/Rust code bases, he pointed out that guarantees are limited: "The guarantees that Rust give you only apply in the Rust-only parts of your code base, and wherever you interact with C code, all bets are off," with most Rust code in Linux talking to "core kernel C code" that is "much better quality because that code has been tested in every single environment."
He concluded, "There are many useful and less useful uses for AI," and "I think Godzilla is a great place to stop."
184361760
submission
joshuark writes:
The scientific journal Nature reports that a new academic 'humanizer' tool aims to personalize the tone of research papers written with an artificial intelligence program, in part by erasing apparent signs of AI usage. Some researchers praise the tool, but others are voicing concerns about a new global era of AI slop, indirect plagiarism, and IP theft.
The new humanizer is "not sophisticated," says Max Spero, chief executive of a firm in New York City that produces an AI detection platform called Pangram. In his initial tests of 'humanized' text, Pangram caught most of the AI-generated language, although not all of it. Spero says that upgraded versions of Pangram are being designed specifically to detect humanizer use.
Scientists are increasingly turning to AI systems to help them write papers, grant applications, and even peer reviews. AI assistance can be a boon, particularly for people writing in a language that is not their first, and many publishers allow some degree of AI use in preparing papers if such use is declared.
Humanizers are finding increasing favor among researchers who use AI because different AIs all "sound the same," like Donald Trump's so-called "speeches" to the American sheep, people. The tone of AI-generated text is sometimes inappropriate for academic writing. For example, the tools can exaggerate the strength of a scientific claim, he says. And most AI output has a similar style, which readers tire of, he adds.
Those preferences are likely to lead to an "explosion" of the sort of personalized AI writing, says Richard She, a biologist at Nanyang Technological University in Singapore, who says he finds AI writing "depressing. " He predicts that within two years, text run through humanizers will be indistinguishable from human-written text. "The simple reality is that there's this amazing tool, and people will use it. And because they'll use it, they'll defend it."
184238608
submission
joshuark writes:
MIT Technology review reports that Miami-based AI startup Subquadratic came out of stealth mode last month with a huge claim. It announced that it had solved a mathematical bottleneck that had been holding back large language models for almost a decade.
According to Subquadratic, it has developed a new kind of LLM, called SubQ, that is faster and cheaper and uses a lot less energy than any other model on the market. The company also claims that SubQ is able to process up to 12 times as much text at once than most other models, allowing it to carry out a range of data-heavy tasks, such as analyzing hundreds of documents or entire code bases.
The problem was that the company at first provided little evidence for its claims beyond a handful of self-published test scores. And it has yet to make SubQ widely available for people to try out themselves.
So it’s no surprise that Subquadratic’s claims were met with skepticism. Dan McAteer, an artificial intelligence engineer, captured the overall response on X: “SubQ is either the biggest breakthrough since the Transformer ... or it’s AI Theranos.”
“We expected healthy skepticism,” says Subquadratic cofounder and chief technology officer Alex Whedon. “In hindsight, releasing the third-party benchmarks alongside the initial announcement would have preempted much of the skepticism, which is why we’re taking the time to make sure any future results are fully verified before putting them out.”
SubQ won’t replace existing top models across the board, but it could offer huge increases in speed at a fraction of the typical cost for certain tasks. Subquadratic insists that in the long run, though, its breakthrough could change how LLMs are built. “We hope we’re kicking off a new age of efficiency,” says Justin Dangel, the firm’s cofounder and CEO. “We don’t think anybody will be building on transformers in a few years.”
184236252
submission
joshuark writes:
The Verge has an article about the "absolute nothing" of quantum computers. We have yet to see a quantum computer conclusively perform a single useful task. Existing machines are simply too small and error-ridden to solve commercially relevant problems.
Companies drive the hype, too. In June, Microsoft announced a new quantum computing chip named Majorana 2. It claimed the chip was a hardware advancement that accelerates its timeline to a “scalable, practical quantum computer” by 2029. But independent experts swiftly criticized the announcement. “This is complete codswallop,” Henry Legg, a physicist from the University of St. Andrews and a longtime Microsoft critic, tells The Verge.
Legg just published a paper in Nature on June 24th criticizing Microsoft’s quantum claims from a year ago — peer review takes a long time — and pointing to what he sees as major discrepancies between Microsoft’s papers and press releases. Nature included Microsoft’s rebuttal.
Researchers have made genuine progress in quantum computing — it’s just been largely incremental and too esoteric to immediately capture the public’s imagination. Proponents predict that the technology will lead to discoveries in medicine, as well as advances in materials science and machine learning. Meanwhile, many national security experts frame its development as a new Cold War competition between the US and China.
Some have imagined the quantum computer as a cyberattack tool. In 1994, computer scientist Peter Shor developed a quantum computing algorithm for factoring prime numbers that should be able to break RSA encryption, a ubiquitous family of algorithms used to secure banking and email communications. So "RSA is dead" is the repeated mantra of the quantum computing hype.
Current quantum computers like Google’s Willow are individual chips too primitive to break RSA encryption or implement drug molecule simulations. But the vision is to build scaled-up machines that can.
Similar cycles have played out several times since the technology’s beginnings. Companies announce a breakthrough; independent researchers cry hype, all while investors continue to inject money into the industry. Then investors cash out and then call it a "scam" on the public.
Henry Legg is more skeptical and thinks some have underestimated the fundamental challenges of scaling. “There’s no evidence of the scalability of any platform to the level that you would need to do useful quantum computations within a decade, or probably a couple of decades,” he says.
While researchers have made progress toward building a useful quantum computer, it’s not clear what that use should be. “It’s such a nascent technology,” says Islam. “If you ask, what is a quantum computer good for, I do not know of an application which is a sure shot.”
The Trump administration wants a useful quantum computer in two years. Are we having fun yet?
184174112
submission
joshuark writes:
Facing real competition from Digital Research's DR DOS, Microsoft secretly embedded a sabotaging mechanism known as "AARD code" into beta versions of Windows 3.1 to prevent it from running on Digital Research's competing DR DOS operating system.
This code triggered fake, alarming error messages to convince developers that DR DOS was unstable, effectively eliminating a significant market threat through fear, uncertainty, and doubt. Although the company disabled the feature in the final retail release, the California-based firm Caldera, Inc., which had acquired DR DOS assets, sued Microsoft for anti-competitive practices.
Microsoft settled the lawsuit out of court in 2000 for $280 million, a figure that remained sealed until it was unsealed in 2009. Nothing says taking ownership and responsibility than keeping it a sealed secret for a decade. Microsoft paid for being clumsy enough to write the intent down in an email. The lesson the industry took away wasn't "don't do it." It was "don't put it in writing." Something Bill Gates forgot with Epstein.
184069802
submission
joshuark writes:
Car and Driver magazine reports that a new study conducted by the New York Times shows that the increase in vehicle hood height seen over the last two and a half decades, mainly due to the rise in popularity of large SUVs and trucks, has resulted in several thousand deaths that otherwise may not have happened. The study shows that while automakers and regulators have focused on occupant safety, they have turned a blind eye to pedestrian safety, which has fallen since around 2009.
Researchers looked at four main datasets in their investigation: crash test data from the National Highway Traffic Safety Administration's (NHTSA) Crash Report Sampling System (CRSS) from 2016 to 2024; NHTSA's Fatality Analysis Reporting System (FARS); vehicle measurement data from Expert AutoStats; and vehicle registration data from S&P Global from 2002 to 2024.
The researchers concluded that the increased danger to pedestrians is caused by two main culprits.
First, large SUVs and trucks have taller hoods, raising the point of impact above most people's center of gravity and pushing them to the ground, typically hard asphalt, rather than up and onto the hood, which is designed to absorb impacts.
Second, with larger A-pillars designed to protect occupants in rollover crashes, modern cars tend to have larger blind spots than cars sold at the turn of the century (presuming the 21st century).
The shift toward vehicles with taller hoods led to roughly 3000 deaths between 2016 and 2024. This number is conservative because it does not include crashes that take place in parking lots, driveways, or private roads, which aren't part of the federal database.
The data also showed an estimated 2.8 percent increase in the odds of a pedestrian fatality for every one-inch increase in vehicle hood height. Between two different scenarios, one decreasing the hood height of every vehicle in the dataset by 3 inches, and the second using a random sampling of hood heights from 2002 across 10,000 simulated crashes, between 2624 (for scenario two) and 3077 (for scenario one) lives could have been saved from 2016 to 2024.
184043754
submission
joshuark writes:
Mars, the maker of M&M’s, will no longer manufacture blue and brown M&M’s. That’s right, the popular chocolate candy brand is doing away with two of its iconic colors, but not without good reason.The company is phasing out synthetic dyes and has plans to launch a natural version of the candy this August. Currently, the small candy-coated chocolates come in seven bright colors—red, yellow, green, blue, orange, brown, and sometimes purple. As it turns out, replicating all of these colors in the same shades using natural ingredients was harder than anticipated.
According to The Wall Street Journal, Mars had little trouble recreating the red, orange, yellow, and green M&M colors using ingredients such as turmeric and beets. Mars is moving forward with natural M&M’s in just red, green, yellow, and orange. That pack of M&M’s will never be the same. RIP li’l buddies.
Not surprising as red was once taboo for a decade. https://www.cnn.com/videos/bus...
184002396
submission
joshuark writes:
Ars Technica reports Microsoft says it has detected new self-propagating malware that spreads through USB drives in search of cryptocurrency credentials, which it then sends to attacker-controlled servers. The company named the worm Crypto Clipper because it monitors the contents of device clipboards for patterns consistent with wallet addresses or seed phrases.
“The execution of this clipper is notable because it does not depend on a traditional installer or exposed IP-based C2 infrastructure,” Microsoft said Thursday. “Instead, it deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution, turning a financially motivated stealer into a lightweight backdoor.”
“This malware family shows how lightweight, script-based stealers can deliver outsized impact when paired with anonymized communications and runtime tasking,” Microsoft said. “The combination of Tor-routed C2, clipboard targeting, screenshot capture, and remote code execution gives attackers both immediate monetization paths and continued control over compromised devices.”
Big question is "What's in your crypto wallet?"
183978134
submission
joshuark writes:
The Trump administration is U-turning on its controversial decision to dismantle a critical ocean monitoring system that provides vital information on the health of the world’s oceans, after a bipartisan backlash in Congress.
The National Science Foundation, which funds the $386 million deep-ocean system, announced it would be pulling up buoys and other underwater equipment from arrays in late May. Thursday, NSF announced it will halt these plans and convene an expert panel to “identify a sustainable path” forward. The NSF’s about-face comes amid intense backlash to its original decision. Experts feared the US was taking eyes off the oceans as they endure a period of huge change, with off-the-chart temperatures fueling devastating storms and threatening fisheries.
Ocean scientists CNN previously spoke to said ditching the monitoring system was “foolish” and “counterintuitive.”
Lawmakers on both sides of the aisle raised objections. “Dismantling the Ocean Observatories Initiative is supreme stupidity, costing taxpayers millions of dollars and destroying a vital source of climate data,” Oregon Sen. Jeff Merkley, a Democrat, wrote in a statement.
House Science Committee Ranking Member Zoe Lofgren, a Democrat from California, said the NSF’s reversal was welcome but cautioned it was not yet clear “how much damage they have already done.”
“This should have never happened,” she told CNN in a statement. “This pathetic scheme was illegal. NSF is governing via chaos and reactionary nonsense. Scientists and coastal economies that depend on this data deserve better.”
The NSF said it “remains committed to ocean sciences, to responsible stewardship of its research infrastructure and to supporting the stakeholders that depend on it.”
183660740
submission
joshuark writes:
The injured teenage survivor of a January 2025 shooting at a Nashville, Tennessee high school recently sued the manufacturer of an “AI gun detection” system that failed to detect the handgun that left two dead, including the shooter.
In 2023, the Metropolitan Nashville Public Schools (MNPS) Board approved a contract worth over $1 million to install an AI detection layer on top of its district-wide network of cameras and related security infrastructure.
The lawsuit alledges the security company Omnilert either knew or should have known that there were “significant operational limitations in its gun detection system that could result in detection failures during actual emergencies, including limitations based on camera placement, proximity of the weapon to camera sensors, camera angle, lighting, and weapon visibility.”
Omnilert cofounder Ara Bagdasarian declined an invitation to answer questions about the lawsuit. System Integrations, the other defendant in the case, which resold the Omnilert system, also did not respond to a request for comment.
MNPS spokesperson Sean Braisted said in a press conference following the January 2025 shooting that due to where the shooter was in relation to the cameras, the imagery “wasn’t close enough to get an accurate read and to activate that alarm.”
The money that MNPS spent on deploying these detection systems, he added, “could have gone to a counselor or something else to a kid in crisis. Every decision that you make is pointing away resources from something else.”