Forgot your password?
typodupeerror

Submission + - Massive Debian 13 Linux Kernel Security Update Patches 68 Vulnerabilities (9to5linux.com)

prisoninmate writes: Linux blog 9to5Linux reports: "The new Debian 13 Linux kernel security update is a massive one, and it patches no less than 68 security vulnerabilities in the Linux 6.12 LTS kernel. Most of these security vulnerabilities are smaller, individually scoped fixes, ranging from use-after-free and out-of-bounds access to NULL-pointer bugs across networking, storage, and filesystem drivers. Nonetheless, these may lead to a privilege escalation, denial of service, or information leaks.

The most severe vulnerabilities patched in the new Debian 13 “Trixie” kernel security update are CVE-2026-64530, a use-after-free in the traffic-control subsystem leading to remote denial-of-service with potential for remote code execution, and CVE-2026-64531 (a.k.a. OVSwrap), a local-root vulnerability in the Open vSwitch datapath leading to local privilege escalation to root.

CVE-2026-64532 and CVE-2026-64533 are a pair of NTFS3 bugs that could lead to denial-of-service with potential memory corruption or information leak triggered by mounting a crafted NTFS filesystem, and CVE-2026-64534 and CVE-2026-64535 are two flaws in the NVMe-over-TCP target that may lead to denial-of-service."

Submission + - FBI gets voter's IP address in new fraud probe tactic (axios.com)

alternative_right writes: The Trump administration has a new tactic for trying to isolate cases of alleged voter fraud â" digging into the IP addresses of those who went online to register to vote.

The FBI recently obtained the IP address of someone who registered online in South Carolina, according to documents first shared with Axios.

Submission + - China wants physical buttons on cars instead of touchscreens (autobuzz.my)

cantle2000 writes: The Chinese Government has mandated physical buttons on Chinese built cars instead of using touchscreens, from July 1st 2027. Essential functions such as the demister, defogger, power windows, lighting,and gear shifting will be button controlled instead of touchscreen controlled.

Comment I have this wild idea (Score 1) 111

Make autonomous bots for forest strip-cleaning. Or hell, make it a game.

Give random people a joystick to a drone forest-clearing machine and tell them if they help clear firebreak lanes in the boreal forest, they will get paid.

Implement some basic "rails" controls so they can't cause havoc by bumping into other machines doing the same thing, etc and I can practically guarantee folks will sign on for this. Have someone organize things a bit and publish goals and a leaderboard.

Look at what random people have done in e.g. Minecraft for no real gain at all. If you can channel that kind of energy, the problem will sort itself.

Submission + - UK Politician vows to hold a referendum over the status of Pluto. (countbinface.com) 1

sometimesblue writes: A potential MP in the hotly contested forthcoming by-election in the town of Clacton-On-Sea has just published his manifesto. Along with many local issues such as restoring the local pier and tourist economy, he also intends to hold a public referendum on the status of Pluto as a planet. It is refreshing to see UK politicians taking an interesting in science and astronomy again.

Submission + - LibreOffice Once Again Slams Microsoft For Using 'Lock-In' With Office Files (xda-developers.com)

An anonymous reader writes: One of the founding members of The Document Foundation and handler of LibreOffice's PR and media relations, Italo Vignoli, took to the LibreOffice blog to call out Microsoft's practices with its Office application. The last time we saw Vignoli take to the stage, we saw him accusing Euro-Office of being just as bad as Microsoft with its practices. Vignoli's new post focuses entirely on Microsoft's strategy. He says that "the dominant format for office documents" is owned by Microsoft Office, particularly the DOCX, XLSX, and PPTX formats. The problem with these formats, Vignoli states, is that they "belong to Microsoft, are controlled by Microsoft and serve Microsoft’s interest." This makes it difficult for other formats to take hold.

Vignoli explains his point by stating that open document formats don't hide anything. People developing their own apps can use the format to both read and write the document format with perfection. Meanwhile, proprietary formats such as Microsoft's "contain undocumented features, private extensions or behaviours" that developers can't fully adapt to. That means that a presentation that looks great in the source software comes out strange when rebuilt in a third-party app. This, Vignoli says, is a huge issue [...]. Vignoli claims this creates a huge issue with document preservation. If a Word document was saved in one version of Office, will it still be readable in 20 years? Microsoft has added legacy support to its software before, but the company can one day decide that it's not worth the effort anymore and cut it out. When that happens, you have old documents that are either jumbled or unable to be opened at all.

Submission + - Steve Wozniak's foundation partners with RealDoll maker to make teacherbots (nysfocus.com) 1

Hentes writes: Apple cofounder Steve Wozniak's foundation is partnering with Realbotix, best known for their RealDoll brand artificial companions, to deploy AI powered robotic tutors in classrooms. The doll will serve as a sort of artificial teacher's assistant, helping students that get stuck, or generating lessons. Students will be assigned an ID code, allowing the robot to provide personalized mentoring.

The female robot, named Sally, will have a “lifelike appearance” with silicone skin and long brown hair, Kiguel said in an interview with New York Focus. It will be stationary in a seated position but have a wide range of upper-body movements and facial expressions.


Submission + - AI Executives Add Personal Security as Backlash Turns Violent (aiweekly.co)

fjo3 writes: In April, someone threw a Molotov cocktail at Sam Altman's San Francisco home, and within days a second attack put gunfire into the property. The Wall Street Journal reports that AI executives are hardening personal security as opposition to the industry moves from online posts into the physical world.

Prosecutors say Daniel Moreno-Gama, the 20-year-old accused in the first attack, traveled from Texas to San Francisco intending to kill Altman, and had writings on him about AI's purported risk to humanity. He faces two counts of attempted murder and attempted arson in California state court. Two more suspects were later arrested in connection with the second incident. Around the same time, The Information described Silicon Valley leaning into a new breed of bodyguards for AI leadership.

The pressure isn't only on the people at the top. According to the Data Center Watch Q1 2026 report, organized opposition groups roughly doubled from 396 at the end of last year to 833 by the end of March, spanning 49 states, and opponents blocked or delayed at least 75 projects worth about $130 billion in a single quarter. That is a very different problem from a viral tweet. It is permits denied, votes lost, sites relocated.

Submission + - How Microsoft's "Little Workaround" Created a Major Pentagon Threat (propublica.org)

joshuark writes: ProPublica Reporter Renee Dudley heard Microsoft was running tech support for the U.S. Defense Department through China, the country’s biggest cybersecurity adversary.

The arrangement was called “digital escorting.” She thought it sounded like a conspiracy theory — until she started looking into it. This is the story of what she found and how her investigation changed government policy.

Microsoft is using engineers in China to help maintain the Defense Department’s computer systems — with minimal supervision by U.S. personnel — leaving some of the nation’s most sensitive data vulnerable to hacking from its leading cyber adversary, a ProPublica investigation has found.

The arrangement, which was critical to Microsoft winning the federal government’s cloud computing business a decade ago, relies on U.S. citizens with security clearances to oversee the work and serve as a barrier against espionage and sabotage.

National security and cybersecurity experts in the Trump administration contacted by ProPublica were also surprised to learn that such an arrangement was in place, especially at a time when the U.S. intelligence community and leading members of Congress and the Trump administration view China’s digital prowess as a top threat to the country.

Microsoft uses the escort system to handle the government’s most sensitive information that falls below “classified.” According to the government, this “high impact level” category includes “data that involves the protection of life and financial ruin.” The “loss of confidentiality, integrity, or availability” of this information “could be expected to have a severe or catastrophic adverse effect” on operations, assets and individuals, the government has said. In the Defense Department, the data is categorized as “Impact Level” 4 and 5 and includes materials that directly support military operations.

“If someone ran a script called ‘fix_servers.sh’ but it actually did something malicious then [escorts] would have no idea,” a former Microsoft engineer who worked on the escort system, told ProPublica in an email. That said, he maintained that the “scope of systems they could disrupt” is limited.

In an emailed statement, the Defense Information Systems Agency said that cloud service providers “are required to establish and maintain controls for vetting and using qualified specialists,” but the agency did not respond to ProPublica’s questions regarding the digital escorts’ qualifications.

It’s unclear whether other cloud providers to the federal government use digital escorts as part of their tech support. Amazon Web Services and Google Cloud declined to comment on the record for this article. Oracle did not respond to requests for comment.

A spokesperson for the inspector general — whose office is supposed to operate independently in order to investigate potential waste, fraud and abuse — told ProPublica they were not authorized to speak about the issue and directed questions to DISA public affairs.

Submission + - Cloudflare, Netlify and Vercel with new toys for phishers and threat actors (cloudflare.com)

D,Petkow writes: Web Bros’ Latest Genius Move: Drop a Zip, Ship Malware

Cloudflare, Vercel, and Netlify have all launched their own “Drop” services: upload a zip, get a live site instantly on their edge networks.
Authentication and abuse protection? That’s for later. Right now it’s pure vibes.

This is peak industry brain rot. In a world already drowning in phishing, malware, and scam sites, these platforms just rolled out the easiest, fastest way for bad actors to host malicious content.
Drag-and-drop phishing kits on workers.dev, instant fake login pages on Vercel, malware droppers on Netlify — all live in seconds with zero friction.

No real verification. No serious upfront checks. Just “move fast and let the internet clean up our mess."
The hopium these web bros are smoking must be nuclear grade quality. They’ve spent years building trust in their platforms, only to turn them into free malware CDNs for anyone with a zip file.This isn’t democratizing the web.
This is handing phishers and scammers the keys with a smile.
Brilliant strategy, truly.

Nota bene — apparently real world bad actors beat red teams in abusing those new "services".

Slow clap

Apparently all the web bros are drinking the same hopium-flavored cool aid, where no phishers, c2s, implants and bad actors exist whatsoever.
https://cloudflare.com/drop/
Same concept from vercel and netlify
https://vercel.com/drop
https://app.netlify.com/drop

https://x.com/JCyberSec_/statu...

Try a DAP.LIVE or URLSCAN.IO query to see abuse and workers.dev (and pages.dev and r2.dev for that matter) — for each valid deployment, there are hundreds of confirmed fraud scams.
Nice statistics, which will only get worse now.
Good job.

Slashdot Top Deals

"Plan to throw one away. You will anyway." - Fred Brooks, "The Mythical Man Month"

Working...