RSS
Pages: 1 ... 298 299 300 301 302 303 304 305 306 307 308 309 310
[>] Is There a Way to Promote Open Document Formats Instead of 'MS Office' Format?
bot.slashdot
robot(spnet, 1) — All
2026-08-03 01:22:01


The Register looks at exactly why "It is practically impossible to move any non-trivial Word document out of MS Office to a non-MS suite and back again without it being more trouble than it's worth."

OOXML, developed by Microsoft and first standardized by Ecma in 2006, became the ISO/IEC 29500 standard in 2008 after a grueling and adversarial process. Microsoft pursued standardization because it has always been a standards-led organization dedicated to maximizing the options for its customers. Or because it had to at gunpoint, while vowing silently to follow the letter of the law but stymie its intent. You decide... The Document Foundation (TDF) which spends its days worrying about such things, reports that Microsoft has effectively broken the standard by sticking with a transitional version as its default rather than the cleaner Strict variant. The result is that what Microsoft software renders is what Microsoft wants to render, despite nominal compliance...

What we need is a test suite that can take any OOXML engine and test its compliance against what Microsoft is actually doing. That means the tooling wrapped around the spec has to account for proprietary dependencies that get smuggled in, such as fonts. It also means actively and continuously tracking the ground truth of Microsoft's evolving products and services. It doesn't need to be perfect, but it absolutely needs to be good enough. Compliant engines have to become good enough for a critical mass of users to coalesce around them.

In an earlier article The Document Foundation reminded all software users that they have a choice. "When an institution sends a letter formatted with a proprietary font, embedded in a proprietary format, produced by proprietary software, it is not communicating information but perpetuating a dependency."

"Digital sovereignty begins with the recognition that this is a choice: the file format is a choice, the font on the page is a choice, and the software is a choice."

[ Read more of this story ]( https://news.slashdot.org/story/26/08/02/217215/is-there-a-way-to-promote-open-document-formats-instead-of-ms-office-format?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] New Spinning Drone Hides In Plain Sight
bot.slashdot
robot(spnet, 1) — All
2026-08-03 02:22:02


To design invisible drones, researchers have tried camouflage, transparent materials and light-bending optical systems. But engineers at Northwestern University used "motion blur," which an announcement from the school notes is the effect that makes fast-spinning fans seem to disappear.

"The drone spins up to 25 times per second, which is too fast for the human eye to see clearly. While it isn't completely invisible, it morphs into a ghostly smudge that seamlessly blends into the background... "

To design the drone, the Northwestern team first used a computational model to generate roughly 20,000 drone configurations capable of stable flight. Then, they used artificial intelligence (AI) and optimization algorithms to repeatedly rearrange the drones' major components, including a motor, propeller, circuit board, counterweight and batteries. After sifting through many different configurations, the algorithms determined the ideal placement of the drone's components to minimize its visibility from virtually every viewing angle while allowing for stable flight.
After selecting promising candidates, the engineers simulated each drone spinning in flight and overlaid those images a hundred real-world backgrounds. Then, they used a perception model that approximates human vision to determine how noticeable each design appeared. Designs that blended into their surroundings received lower visibility scores. The team selected the 500 lowest-scoring designs and applied the optimization algorithm, which repeatedly adjusted the positions of components to further minimize those scores. "The design process was fully automated," [said Northwestern's associate CS professor Michael Rubenstein, who led the work]. "Then, when we were confident that a drone met all our criteria, we built it."

They've named the drone "Phantom Twist"," and plan to design future iterations with more transparent materials or quieter propulsion to make it even less noticeable.

The Northwestern team presented the work on July 16 at Robotics: Science and Systems 2026 in Sydney, Australia...

Thanks to long-time Slashdot reader fahrbot-bot for sharing the news.

[ Read more of this story ]( https://tech.slashdot.org/story/26/08/02/220231/new-spinning-drone-hides-in-plain-sight?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] IT Teams Report 11 Hour a Week on Cloud Connectivity Problems
bot.slashdot
robot(spnet, 1) — All
2026-08-03 04:22:01


Researchers found enterprises are spending time troubleshooting cloud connectivity due to increased AI workloads, reports Computer Weekly. More than 400 IT and infrastructure decision-makers (US and UK) were surveyed for internet/cloud/AI exchange operator DE-CIX by market researchers Censuswide. But despite 96% of respondents claiming their enterprise networks are ready for cloud/AI loads, the average IT team still spends more than 11 hours each week resolving cloud connectivity problems

Other leading concerns included downtime or reliability issues (26%), latency or slow performance (28%), and security vulnerabilities/DDoS attacks (27%). Cost of connectivity, staff expertise and lack of visibility/control over data flows were also cited as major challenges... As a result, as indicated in the study, many businesses are now turning to private interconnection, which enables enterprises to connect directly to cloud providers over dedicated infrastructure rather than routing traffic across the public Internet. Designed to deliver lower latency, greater resilience, enhanced security and more predictable performance, private interconnection has become an increasingly important way of supporting modern cloud and AI workloads. Specifically, the data showed that 61% of companies are already using private connectivity to clouds, while another 31% are actively considering it... [And 71% of enterprises with 1000 or more employees]

Only 8.62% of the smaller companies were spending 21 to 40 hours per week dealing with connectivity issues, while just 2.53% of the largest companies in the sample do. Summing up these findings, DE-CIX said that together they suggest direct interconnection is rapidly becoming a core component of enterprise cloud and AI infrastructure and a competitive advantage for companies, though optimising interconnection strategies clearly remains a pressing challenge for small and medium-sized enterprises... "Every AI application depends on data moving quickly, securely and predictably between users, clouds and AI infrastructure. Our research suggests that far too many enterprises are still spending valuable time trying to maintain that kind of connectivity, with more than a third spending between 11 and 20 hours per week, and just under one in 10 spending between 21 to 40 hours per week. This confirms what we already knew — that that network architecture can make or break AI adoption."

Elsewhere The Register reports that cloud infrastructure services "grew at their fastest for eight years during the second quarter of 2026, thanks to the AI craze and continued demand for flexible and scalable IT infrastructure."

According to the latest figures from Synergy Research, enterprise spending on cloud infrastructure passed $143 billion in Q2, a year-on-year growth rate of 43 percent. This followed 11 successive quarters of increasing growth rates, during which the market has now doubled in size... "AI has, of course, driven most of that incremental growth, and we now see year-on-year growth rates of 165 percent for AI-specific cloud services...." And the top three global players continue to dominate the market, with Amazon Web Services (AWS), Microsoft Azure and Google Cloud together accounting for 67 percent of all the cloud revenue during the quarter. That percentage has increased since the third quarter of last year, when the triumvirate made up 63 percent of enterprise cloud infra spending.

[ Read more of this story ]( https://it.slashdot.org/story/26/08/02/2331237/it-teams-report-11-hour-a-week-on-cloud-connectivity-problems?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] IT Teams are Spending 11 Hours a Week on Cloud Connectivity Problems
bot.slashdot
robot(spnet, 1) — All
2026-08-03 05:22:01


Researchers found enterprises are spending time troubleshooting cloud connectivity due to increased AI workloads, reports Computer Weekly. More than 400 IT and infrastructure decision-makers (US and UK) were surveyed for internet/cloud/AI exchange operator DE-CIX by market researchers Censuswide. But despite 96% of respondents claiming their enterprise networks are ready for cloud/AI loads, the average IT team still spends more than 11 hours each week resolving cloud connectivity problems

Other leading concerns included downtime or reliability issues (26%), latency or slow performance (28%), and security vulnerabilities/DDoS attacks (27%). Cost of connectivity, staff expertise and lack of visibility/control over data flows were also cited as major challenges... As a result, as indicated in the study, many businesses are now turning to private interconnection, which enables enterprises to connect directly to cloud providers over dedicated infrastructure rather than routing traffic across the public Internet. Designed to deliver lower latency, greater resilience, enhanced security and more predictable performance, private interconnection has become an increasingly important way of supporting modern cloud and AI workloads. Specifically, the data showed that 61% of companies are already using private connectivity to clouds, while another 31% are actively considering it... [And 71% of enterprises with 1000 or more employees]

Only 8.62% of the smaller companies were spending 21 to 40 hours per week dealing with connectivity issues, while just 2.53% of the largest companies in the sample do. Summing up these findings, DE-CIX said that together they suggest direct interconnection is rapidly becoming a core component of enterprise cloud and AI infrastructure and a competitive advantage for companies, though optimising interconnection strategies clearly remains a pressing challenge for small and medium-sized enterprises... "Every AI application depends on data moving quickly, securely and predictably between users, clouds and AI infrastructure. Our research suggests that far too many enterprises are still spending valuable time trying to maintain that kind of connectivity, with more than a third spending between 11 and 20 hours per week, and just under one in 10 spending between 21 to 40 hours per week. This confirms what we already knew — that that network architecture can make or break AI adoption."

Elsewhere The Register reports that cloud infrastructure services "grew at their fastest for eight years during the second quarter of 2026, thanks to the AI craze and continued demand for flexible and scalable IT infrastructure."

According to the latest figures from Synergy Research, enterprise spending on cloud infrastructure passed $143 billion in Q2, a year-on-year growth rate of 43 percent. This followed 11 successive quarters of increasing growth rates, during which the market has now doubled in size... "AI has, of course, driven most of that incremental growth, and we now see year-on-year growth rates of 165 percent for AI-specific cloud services...." And the top three global players continue to dominate the market, with Amazon Web Services (AWS), Microsoft Azure and Google Cloud together accounting for 67 percent of all the cloud revenue during the quarter. That percentage has increased since the third quarter of last year, when the triumvirate made up 63 percent of enterprise cloud infra spending.

[ Read more of this story ]( https://it.slashdot.org/story/26/08/02/2331237/it-teams-are-spending-11-hours-a-week-on-cloud-connectivity-problems?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] GOG Officially Expands Linux Support With Native Galaxy Client In Development
bot.slashdot
robot(spnet, 1) — All
2026-08-03 05:22:01


Long-time Slashdot reader pyroclast shared this report from Linux Journal:

After years of requests from the Linux gaming community, GOG has officially confirmed that it is developing native Linux support for the GOG Galaxy launcher. The announcement marks one of the biggest shifts in the company's history and signals a stronger commitment to Linux as a first-class gaming platform. While GOG has offered DRM-free Linux game downloads since 2014, its Galaxy launcher has remained exclusive to Windows and macOS — until now. Although the company has not announced a release date, GOG says Linux has become a major area of investment, with development already underway...

Unlike the web-based game downloads that Linux users already have access to, GOG Galaxy serves as a full-featured game management application. The launcher currently offers features including:
— Automatic game installation and updates
— Cloud save synchronization
— Achievement tracking
— Playtime statistics
— Game library organization
— Integrated storefront browsing
— Friends lists and social features
— Cross-platform launcher integration
Today, Linux users typically access these capabilities through community projects such as Heroic Games Launcher, Lutris, or Bottles. A native Galaxy client would provide an officially supported alternative with direct integration into GOG's ecosystem...

For GOG, supporting Linux more fully aligns with its philosophy of giving users greater control over their purchased games.

The article argues this news shows Linux growing in importance for game publishers. After the rapid adoption of Valve's Steam Deck, there's also been continuous improvements to Proton and Vulkan, increasing hardware compatibility, and native Linux game development efforts.

"As more companies recognize the platform's growth, Linux users can expect broader support from game publishers and software developers alike."

[ Read more of this story ]( https://linux.slashdot.org/story/26/08/02/2019202/gog-officially-expands-linux-support-with-native-galaxy-client-in-development?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Rogue Police Officers Have Turned Flock's Nationwide Camera Network Into a Stalking Tool
bot.slashdot
robot(spnet, 1) — All
2026-08-03 06:22:01


A woman found her police officer ex-boyfriend cop had used Flock's camera system 600 times to look up the location of her and her daughter, reports the Washington Post (Alternate URL here). (She found out through Have I Been Flocked, described as "a website that aggregates police search logs made available through public records.")

But it turns out dozens more police officers have also misused Flock...

Authorities have charged or accused at least 50 law-enforcement officers of using license-plate readers for unauthorized purposes, including to stalk women without their knowledge or consent, a Post analysis of police and court records found. In 26 of these cases, police investigators and prosecutors said the officers used the technology to spy on their wives, their girlfriends, their exes, their exes' new partners or women they wanted to meet. In other cases, police or prosecutors have not specified the alleged surveillance targets. Flock's system was used in 46 of the cases analyzed by The Post, while the other cases involved competing products...

After The Post relayed its findings to Flock, the company said in a statement it "will soon be announcing better filters and tools to stop abuse before it happens...." In April, the company rolled out a new voluntary "audit assistance" feature, which agencies can choose to enable, that automatically scans officers' searches for suspicious activity, such as queries repeatedly targeting the same vehicle or run by officers off the clock. In an interview with The Post, Flock chief executive Garrett Langley said misuse of its systems is inevitable and that the company is focused on providing tools to catch perpetrators after the fact... "We're not going to change humans, and humans make bad decisions," Langley said. "What we can do is make sure that they know if you use this tool, you will be held accountable...."

Through automated license-plate reader systems, or ALPRs, officers could trace the rhythms and travels of their subjects' daily lives, leading in some instances to violent confrontations, moments of psychological manipulation, and threats of coercion and control, the analysis found.

- In Wisconsin, a police officer allegedly used Flock to check whether his ex-girlfriend had gone to an abortion clinic, according to a police affidavit for a case set for trial this month.
- In Kansas, a police chief who tracked his ex through Flock sneaked up on her while she was intimate with another man, a state police certification body alleged, leading to his firing.
- In Florida, a deputy speeding to stop a young actress he'd added to a watch list for a license-plate tool called Guardian nearly caused a head-on crash, according to a police report and video from his dashboard camera. The deputy was arrested in March, and his attorney declined to comment.

- And in California, prosecutors said a former deputy, Alexander Vanny, used Flock as part of a months-long campaign of "stalking" and "humiliating" his former fiancée that also involved following her around town and installing a hidden camera in her roommate's bathroom, according to a sentencing brief...

While some of the searches resulted in officers' firings, prosecutions and prison sentences, police departments in other cases allowed officers to continue using the systems even after receiving warnings that they were being misused... An array of privacy advocates has argued that Flock could deter bad actors by making simple changes to its product, such as requiring officers to label every search with a criminal case number. Some policing experts also warned that agencies' inconsistencies in developing and enforcing standard procedures for license-plate readers could lead to further misconduct. With no federal laws governing use and only a patchwork of state laws, many of the country's roughly 18,000 police agencies are left to decide their rules on their own...

Langley, Flock's chief, has dismissed pushes by activists for the company to further limit how officers use its product.
"No one elected me the police chief of America," he told Forbes last year, adding, "I don't think it's our job to police the police."

The Post also got this quote from an officer was fired and sentenced to probation after pleading no contest to charges of computer-system misuse, stalking and battery. "Pretty much everybody uses that computer system" improperly in the department, he said, and "they don't audit it [nearly] as much as they should."

Flock told The Post it now has over 120,000 cameras in more than 6,000 communities, recording 20 billion license plate scans every month.

[ Read more of this story ]( https://yro.slashdot.org/story/26/08/03/023205/rogue-police-officers-have-turned-flocks-nationwide-camera-network-into-a-stalking-tool?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Hollywood Fights AI In Public While Quietly Building It Into Movies
bot.slashdot
robot(spnet, 1) — All
2026-08-03 09:22:02


Even as Hollywood performers protest and Hollywood studios sue "in their war on AI," reports the Los Angeles Times, "the entertainment industry is deepening its dependence on it."

Among hundreds of job postings in late June, more than one in 10 was likely connected to AI. The top studios' public postings suggest they have been recruiting people to build AI tools. They are also recruiting teams to defend their intellectual property against unauthorized AI use. "There are plenty of studios that are hiring [for AI] but never talk about it in public," said Yoland Yan, a co-founder of ComfyUI, a company that helps studios juggle different AI tools. Companies have been hesitant to detail how they use generative AI in film production — partly because they are concerned about consumer and union backlash. Some in Hollywood described AI use as the new cosmetic surgery, where everyone knows it is happening, but few will admit to it...

Although some companies may be shy about sharing their AI plans, big stars who don't have to answer to others have been more open about their embrace of the new technology for storytelling. Rejecting AI is like picking a horse and buggy over a car, said "Star Wars" creator George Lucas. "Artificial intelligence means it's much easier for us to make movies," he told a trade magazine earlier this year. "There's nothing you can do about it. That's progress. It's the future." Some in Hollywood have a softer stance on artificial intelligence, with studios cutting deals with AI companies, and filmmakers like Martin Scorsese backing AI companies. Ben Affleck launched an AI film tech company then sold it to Netflix for half a billion dollars. When launching InterPositive, Affleck said he wanted to keep "storytelling human" by building AI tools that could fix lighting, generate missing shots and other things while "keeping creative decisions in the hands of artists...."

Disney, Netflix and Amazon had job postings that were about using AI on the creative side of the business. Universal, Paramount, Warner Bros. and Sony had job ads suggesting they were also using AI but for marketing, distribution and audience analytics. The postings suggest the Disney, Netflix and Amazon studios are building repeatable AI workflows for visual effects, animation, sound and dubbing. The companies also seem to be building in-house teams to develop custom generative-AI models, while also using third-party software.

None of the jobs advertised were to create AI that wrote scripts or created AI actors.

Ironically, the Times used Claude Code to build a scraper to identify the job postings, their article acknowledges.

Three Disney jobs were for "content security," assessing AI tools and guarding against piracy, watermarking and rights-protection work. But Disney is also hiring PhD-level talent "to study 'computer graphics and AI' for Pixar and Disney films," according to the article, and "people to 'bridge the gap between research and practical studio application.'"
Disney-owned visual effects shops Industrial Light & Magic "was searching for supervisors to 'explore emerging technologies (including AI/Machine Learning)' to develop new production workflows."
Audio post-production unit Skywalker Sound "seemed to be recruiting to build proprietary AI models for soundtracks, voice separation, and voice transfer, the process of taking a speaker's tone and pitch, and applying it to new content."
Amazon "was hiring a principal AI executive to drive AI-tool adoption across production, plus roles in operations automation and LLM content classification."

[ Read more of this story ]( https://entertainment.slashdot.org/story/26/08/03/0350223/hollywood-fights-ai-in-public-while-quietly-building-it-into-movies?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Проект Kakehashi развивает инструментарий для запуска исполняемых файлов macOS в Linux
lor.opennet
robot(spnet, 1) — All
2026-08-03 09:44:02


В рамках проекта Kakehashi ведётся разработка транслятора, позволяющего выполнять исполняемые файлы macOS в формате Mach-O, собранные для архитектуры ARM64, в Linux-системах с архитектурой ARM64. Код из macOS выполняется нативно без JIT-компиляции и эмуляции, используя только подмену системных вызовов для libSystem и обработку исключений. Основной целью проекта является обеспечение возможности запуска в Linux утилит командной строки, собранных для macOS. Код написан на языке Rust и распространяется под лицензией Apache 2.0.

https://www.opennet.ru/opennews/art.shtml?num=66014

[>] Переполнение буфера в iwd, эксплуатируемое через Wi-Fi
lor.opennet
robot(spnet, 1) — All
2026-08-03 10:44:02


В фоновм процессе iwd, применяемом для организации подключения Linux-систем к беспроводной сети, выявлена уязвимость (CVE не назначен), приводящая к переполнению буфера при обработке специально оформленного беспроводного запроса (802.11k), не требующего аутентификации в сетях с WPA2 без PMF. Доступен прототип эксплоита.

https://www.opennet.ru/opennews/art.shtml?num=66015

[>] Сервис доставки игр GOG разрабатывает Linux-версию GOG Galaxy
lor.opennet
robot(spnet, 1) — All
2026-08-03 10:44:02


Сервис доставки старых классических игр GOG.com (Good Old Games) подтвердил разработку Linux-версии приложения GOG Galaxy, позволяющего загружать, устанавливать, обновлять и запускать игры, а также объединять в одной коллекции игры и друзей из разных игровых клиентов. Поддержка размещения игр для Linux была добавлена в GOG.com в 2014 году, но игровой клиент GOG Galaxy до сих пор был доступен только для Windows и macOS. Дата публикации Linux версии не сообщается, но упоминается, что платформа Linux рассматривается как важный объект для инвестиций.

https://www.opennet.ru/opennews/art.shtml?num=66016

[>] Выпуск видеоредактора Shotcut 26.7
lor.opennet
robot(spnet, 1) — All
2026-08-03 11:44:03


Опубликован релиз видеоредактора Shotcut 26.7, развиваемого автором проекта MLT и использующего данный фреймворк для редактирования видео. Поддержка форматов видео и звука реализована через FFmpeg. Возможно использование плагинов с реализацией видео и аудио эффектов, совместимых с Frei0r и LADSPA. Из особенностей Shotcut можно отметить возможность многотрекового редактирования с компоновкой видео из фрагментов в различных исходных форматах, без необходимости их предварительного импортирования или перекодирования. Имеются встроенные средства для создания скринкастов, обработки изображения с web-камеры и приёма потокового видео. Код написан на C++ с использованием фреймворка Qt и распространяется под лицензией GPLv3. Готовые сборки доступны для Linux (AppImage и snap), macOS и Windows.

https://www.opennet.ru/opennews/art.shtml?num=66017

[>] Massive Debian 13 Linux Kernel Security Update Patches 68 Vulnerabilities
bot.slashdot
robot(spnet, 1) — All
2026-08-03 12:22:01


Slashdot reader prisoninmate shares this report from 9to5Linux:

Coming ten days after the previous Linux kernel security update, which only fixed 12 vulnerabilities that may lead to a privilege escalation, denial of service, or information leaks, the new Debian 13 Linux kernel security update is a massive one, and it patches no less than 68 security vulnerabilities in the Linux 6.12 LTS kernel. ebian 13 "Trixie" kernel security update are CVE-2026-64530, a use-after-free in the traffic-control subsystem leading to remote denial-of-service with potential for remote code execution, and CVE-2026-64531 (a.k.a. OVSwrap), a local-root vulnerability in the Open vSwitch datapath leading to local privilege escalation to root...

All Debian 13 "Trixie" users are urged to update their installations to Linux kernel 6.12.100-1 as soon as possible.

[ Read more of this story ]( https://linux.slashdot.org/story/26/08/03/0219205/massive-debian-13-linux-kernel-security-update-patches-68-vulnerabilities?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Tomviz 3.0
lor.opennet
robot(spnet, 1) — All
2026-08-03 12:44:03


<img
itemprop="thumbnail"
class="medium-image"
src="https://www.linux.org.ru/images/23822/1000px.jpg"
alt="Tomviz 3.0"
srcset="images/23822/500px.jpg 500w, images/23822/1000px.jpg 1000w, https://www.linux.org.ru/images/23822/original.png 1020w"
sizes="100vw" style="position: absolute; max-height: 90vh"

width=1000 height=603>

2 августа 2026 года компания Kitware [ объявила о выпуске Tomviz 3.0 ]( https://www.kitware.com/tomviz-3-0-released-a-reimagined-pipeline-for-tomographic-data-analysis/ ) — крупнейшего обновления за всю историю проекта. Tomviz представляет собой свободное кроссплатформенное приложение для реконструкции, обработки, анализа и визуализации трёхмерных томографических данных. Исходный код распространяется под лицензией [ BSD 3-Clause ]( https://github.com/OpenChemistry/tomviz/blob/master/LICENSE ) , приложение доступно для Linux, macOS и Windows.

Tomviz используется преимущественно при работе с данными электронной и рентгеновской томографии. Программа позволяет провести полный цикл обработки: загрузить серии проекций, выполнить выравнивание и трёхмерную реконструкцию, выделить интересующие объекты, провести количественный анализ и подготовить визуализацию. Обработку можно дополнять собственными преобразованиями на Python и C++.

( [ читать дальше... ]( https://www.linux.org.ru/news/opensource/18351582#cut ) )

[>] curl возобновляет приём отчётов об уязвимостях после месячного перерыва
lor.opennet
robot(spnet, 1) — All
2026-08-03 14:44:03


<a href="https://www.linux.org.ru/images/23825/original.jpg" itemprop="contentURL">

<img
itemprop="thumbnail"
class="medium-image"
src="https://www.linux.org.ru/images/23825/1000px.jpg"
alt="curl возобновляет приём отчётов об уязвимостях после месячного перерыва"
srcset="images/23825/500px.jpg 500w, images/23825/1000px.jpg 1000w, images/23825/1500px.jpg 1500w, https://www.linux.org.ru/images/23825/original.jpg 2000w"
sizes="100vw" style="position: absolute; max-height: 90vh"

width=1000 height=546>

</a>

3 августа 2026 года, проект curl возобновляет приём сообщений об уязвимостях через платформу HackerOne. Форма должна открыться в 09:00 CEST, или 10:00 по московскому времени. Весь июль сопровождающие намеренно не принимали и не обрабатывали новые отчёты, объявив период отдыха под названием [ curl summer of bliss — «лето блаженства curl» ]( https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/ ) .

О временной остановке приёма отчётов ведущий разработчик curl Дэниел Стенберг объявил 15 июня. С 1 июля была отключена форма HackerOne, а сообщения, отправленные на адрес команды безопасности, также оставались без рассмотрения. Найденные в течение месяца проблемы исследователям предлагалось сохранить до августа. При этом обычные разделы GitHub для сообщений об ошибках и запросов на включение изменений продолжали работать. «Плохие парни, вероятно, не станут отдыхать. Но мы будем», — [ объяснил решение Стенберг ]( https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/ ) .

( [ читать дальше... ]( https://www.linux.org.ru/news/security/18351586#cut ) )

[>] Box64 0.4.4
lor.opennet
robot(spnet, 1) — All
2026-08-03 14:44:03


<img
itemprop="thumbnail"
class="medium-image"
src="https://www.linux.org.ru/images/23827/1000px.jpg"
alt="Box64 0.4.4"
srcset="images/23827/500px.jpg 500w, images/23827/1000px.jpg 1000w, https://www.linux.org.ru/images/23827/original.png 1200w"
sizes="100vw" style="position: absolute; max-height: 90vh"

width=1000 height=584>

Основным пользовательским новшеством стал [ графический конфигуратор box64-configurator ]( https://box86.org/2026/08/new-box64-v0-4-4-release/ ) , написанный на Python. Он позволяет создавать и изменять профили .box64rc для отдельных программ и игр, выбирать переменные Box64 и просматривать пояснения к ним без ручного редактирования конфигурационного файла. Интерфейс переведён на английский и китайский языки. Для KDE также подготовлен модуль, позволяющий открывать настройки Box64 из контекстного меню исполняемого файла.

Основные изменения Box64 0.4.4:

( [ читать дальше... ]( https://www.linux.org.ru/news/opensource/18351592#cut ) )

[>] 'AI's Decimation of Call Center Jobs Has Begun'
bot.slashdot
robot(spnet, 1) — All
2026-08-03 16:22:01


"AI's decimation of call center jobs has begun," reports Bloomberg:

Companies including the Commonwealth Bank of Australia, Microsoft Corp., Uber Technologies Inc. and Hyatt Hotels Corp. are using automated chat and phone systems to handle work that previously required humans. In some cases, they've already wiped out sizable chunks of their customer service operations, together representing thousands of workers.

The specter of automation has long loomed over the call center industry, which employs millions worldwide from the U,S, to India to the Philippines. But until recently, generative artificial intelligence wasn't good enough to move the needle. Now, AI advancements — and pressure on executives to show they're embracing the new technology — have prompted corporations to deploy the tools more widely. Customer service employment in the U.S. is declining and will likely continue to do so as more tasks are automated, Forrester analyst Kate Leggett wrote in a report earlier this year. While it's impossible to determine the future job losses, she estimated that almost half of customer service roles will be affected by 2030.

Globally, the steepest job cuts are expected to hit countries like the Philippines, where many Western companies have outsourced their most easily automated work. Salespeople at multiple tech companies told Bloomberg that they routinely pitch call center AI tools as a way of lowering labor costs, undercutting a common industry claim that AI is primarily a way to help workers become more productive rather than kill their jobs... Commonwealth Bank of Australia, the nation's largest lender, has shed hundreds of workers from its chat support line as it wove AI into the system, according to people familiar with the work. This amounted to tens of millions of dollars in savings per year, one of the people said...

Microsoft is both one of the largest vendors and adopters of customer service automation tools. This has helped the software giant trim its customer service workforce — a mix of contractors and full-time staff — from about 50,000 to 40,000 in recent years, according to a person familiar with the operations. "If something happened with little Johnny's Xbox in the middle of the night, we can now solve that with AI," Judson Althoff, who runs Microsoft's sales and service operations, said in an interview. Althoff said in April that AI is saving the company about $750 million per year in customer service costs. More complex problems still require human support, but the company is constantly expanding what can be fixed automatically, he said in the interview.

Two examples from the article:

Last year Hyatt fired 30% of its in-house customer support staff for the Americas, according the hotel-industry news site Hotel Dive.

Last week Bloomberg reported Uber had cut 10% of its customer service jobs as part of effort to "embrace artificial intelligence," according to the article. "Today, Uber pushes users to submit support requests through their apps, where they're met with an AI chatbot."

[ Read more of this story ]( https://it.slashdot.org/story/26/08/03/031248/ais-decimation-of-call-center-jobs-has-begun?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Company Offering Printed Books To Train AI Stops After 404 Media Coverage
bot.slashdot
robot(spnet, 1) — All
2026-08-03 19:22:01


An anonymous reader quotes a report from 404 Media: Following 404 Media's reporting that book database company ISBNdb claimed to source printed books to then sell to AI companies for AI training, the company deleted the part of its website offering the service and walked back claims that it would train AI models, and instead called it "a test of market interest."

On July 30, nine days after 404 Media's reporting, ISBNdb added a note to its homepage and an update on its news page about the change. "We've seen the recent coverage about a marketing landing page on our site, and we understand the concern it raised. The facts: ISBNdb has never purchased, scanned, or sold a book -- for AI training or anything else," ISBNdb wrote. "We don't train AI models, and we never have. The page was a test of market interest; no such service was ever brought to life. We've taken the page down. Our job is helping people find books. For more than two decades, ISBNdb has been the card catalog of the book world -- the data behind how bookstores, libraries, and reading apps connect readers with titles. Data about books, not the books themselves. That hasn't changed."

ISBNdb removed the landing page for "Printed Books Sourcing for Your AI LLMs Dataset Needs" on July 28. "It was part of exploring demand, and we've chosen to pivot away from that direction. Our main ISBNdb (book metadata API) services are unaffected and running as usual," the site says. According to 404 Media's previous report, ISBNdb had pitched pre-2022 printed books as premium AI training material because they contained curated human knowledge without contamination from AI-generated text or modern data-poisoning techniques. "The world's best AI training data is sitting on a shelf," the company had argued, while offering discreet bulk book acquisition under NDAs and acknowledging the potential backlash if AI firms were seen destroying millions of books for scanning.

[ Read more of this story ]( https://news.slashdot.org/story/26/08/03/0714207/company-offering-printed-books-to-train-ai-stops-after-404-media-coverage?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] South Korea Records Its Highest Ever Temperature
bot.slashdot
robot(spnet, 1) — All
2026-08-03 20:22:01


South Korea recorded its highest temperature since modern observations began in 1904, with the city of Yangsan reaching 42.5C as temperatures exceeded 40C for a fifth consecutive day. Authorities warned residents to "immediately stop all outdoor activities." The Guardian reports: More than 20 localities in South Korea were under emergency heatwave alerts on Sunday -- a new warning category introduced this year to better address rising temperatures. An emergency alert is issued when areas experiencing a heatwave are forecast to hit perceived temperatures of 38C or an actual temperature of 39C for the day. Issuing a heat warning, the weather agency urged people to "immediately stop all outdoor activities," adding that "indoor spaces without air conditioning are dangerous."

"Move immediately to a cool place, such as a designated cooling centre or a shaded area, and stay hydrated while resting," it advised. Fearing for those people most vulnerable to heat, the prime minister, Han Seong-sook, ordered local officials to strengthen safety checks on residents and to ensure a stable power and water supply was maintained. [...] Korea Meteorological Administration (KMA) data show the average annual number of heatwave days in the country has more than doubled to 19 in the past five years.

[ Read more of this story ]( https://news.slashdot.org/story/26/08/03/0721235/south-korea-records-its-highest-ever-temperature?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] As Reddit Stock Falls, CEO Questions Value of Google's AI Overviews
bot.slashdot
robot(spnet, 1) — All
2026-08-03 21:22:01


Reddit CEO Steve Huffman criticized Google's AI Overviews for summarizing publishers' content without delivering the traffic benefits of traditional search, arguing that users increasingly value Reddit's human perspectives and firsthand experiences. Ars Technica reports: First, there was a letter to investors (PDF), wherein Huffman spun his narrative about Reddit's value proposition and general strategic direction amid the proliferation of AI tools. He wrote: "As the internet becomes flooded with synthetic content, people are craving real human perspective. We are the antidote to an automated web. AI compresses the internet into summaries. Reddit delivers the opposite: deep discussions, passionate debates, and lived experiences. People don't want a summary of Reddit; they want Reddit."

The letter also said: "As AI makes information more abundant, the challenge is no longer finding content -- it's finding context, personal opinion, and first-hand accounts. Everything online feels flat, polished, generated, or sponsored, so consumers are overwhelmed and increasingly skeptical. We've never had more information, but we've never trusted it less."

And then, in comments around the earnings report, he added: "What we see is, 10 blue links has driven tremendous value and growth to the broader ecosystem... from where we sit, AI Overviews has yet to make a similar level of positive impact, and I think that's consistent across the broader landscape, right? As businesses, publishers, retailers, we're still looking for that win-win." Reddit shares nevertheless fell more than 20 percent as investors worried that unstable Google referrals could undermine its growth, even after a strong earnings report.

[ Read more of this story ]( https://tech.slashdot.org/story/26/08/03/1628248/as-reddit-stock-falls-ceo-questions-value-of-googles-ai-overviews?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Samsung Bans Smart TV Apps That Share Users' Internet Connections
bot.slashdot
robot(spnet, 1) — All
2026-08-03 22:22:01


An anonymous reader quotes a report from TechCrunch: Several popular Samsung smart TV apps contain code that share the owner's internet connection with strangers, potentially putting millions of Samsung smart TVs at risk of hijacking, according to new security research published on Monday. Some of these apps claim to have been installed on hundreds of millions of smart TVs in people's homes, per the app developers. At least one of the smart TV apps was a simple Pac-Man game that Samsung had endorsed and prominently featured in its "Editor's Choice" section on customers' TV screens. These apps contain software that funnels outsiders' web traffic through ordinary home and office internet connections, known as residential proxy networks (or "resproxies"), which are increasingly being linked to cybercrime. When opened, apps with resproxy code can turn the smart TV into an always-on tunnel for outsiders to funnel their web traffic through, known as an exit node -- even when the app is no longer open.

The security research by Norwegian cybersecurity company Mnemonic describes a perfect storm of problems that allows low-quality apps to proliferate across Samsung's app store, containing code that puts users at risk of having their internet connections tapped by a rogue app. Many of these apps are bare-bone shells, made from only a few lines of code, and are designed solely to load content from another website, such as a game. While such smart TV apps load content from another server, any review of these apps sees only the few lines of code within, and not necessarily the content itself. "What was reviewed is not necessarily what is running," wrote Harrison Sand, an offensive security consultant at Mnemonic.

After TechCrunch contacted Samsung with a request for comment about the research, the electronics giant said in an emailed statement that it was banning apps that share their users' internet connections, and will remove apps that contain the functionality. "We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform," said a Samsung spokesperson. "We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components." LG also recently announced plans to suspend apps containing ResProxy software after a security firm found that roughly 42% of apps in its TV app store allowed unknown third parties to route internet traffic through users' televisions without their knowledge.

[ Read more of this story ]( https://entertainment.slashdot.org/story/26/08/03/1637257/samsung-bans-smart-tv-apps-that-share-users-internet-connections?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Apple's iCloud File Sharing Left Ex-Employees With Access to Secret Documents
bot.slashdot
robot(spnet, 1) — All
2026-08-03 23:22:02


Apple's practice of mixing employees' work files with personal iCloud accounts reportedly left some former staff with continued access to confidential documents, messages, and even new updates after leaving the company. "The former employees said many Apple files they had been shared on over their careers at the company -- including planning documents for product launch events -- continued to sync to their personal devices through the iCloud storage service after they left Apple," reports The Information. "In some cases, they even received notifications about fresh updates to the documents. Some former employees said they were petrified to delete the files for fear that doing so would attract Apple's attention." MacRumors reports: Apple files get mixed in with employees' accounts because the company encourages them to use their personal Apple Accounts with their work iCloud account. Employees are given a 2TB iCloud plan and are able to merge the storage with their existing Apple Account or create a new account. Since only one primary account can be signed in at a time, most opt to use their existing account to avoid having to carry two iPhones. Apple has a managed folder for workplace files that it revokes access to when an employee leaves, but some internal documents aren't saved there automatically and shared files end up mixed in with personal content. Employees can also retain access to iMessage chats and files shared via the Messages app.

Lingering access to Apple systems is central to Apple's lawsuit against OpenAI. In its filing, Apple alleged that former employee Chang Liu breached Apple's systems using a "rare, previously unknown authentication bug" to download files while he was working at OpenAI. Apple told The Information that the OpenAI lawsuit is unrelated to any files left available on iCloud and that it does not pursue legal claims against former employees who accidentally have Apple documents in their personal iCloud accounts. "This case is about OpenAI employees wrongfully taking Apple's secret and confidential information regarding our unreleased technologies, processes, and products. Nothing in the filing relates to documents shared by, or stored in, iCloud."

[ Read more of this story ]( https://apple.slashdot.org/story/26/08/03/195248/apples-icloud-file-sharing-left-ex-employees-with-access-to-secret-documents?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Woodpecker CI 3.17
lor.opennet
robot(spnet, 1) — All
2026-08-03 23:44:04


<a href="https://www.linux.org.ru/images/23828/original.png" itemprop="contentURL">

<img
itemprop="thumbnail"
class="medium-image"
src="https://www.linux.org.ru/images/23828/1000px.jpg"
alt="Woodpecker CI 3.17"
srcset="images/23828/500px.jpg 500w, images/23828/1000px.jpg 1000w, images/23828/1500px.jpg 1500w, images/23828/2000px.jpg 2000w"
sizes="100vw" style="position: absolute; max-height: 90vh"

width=1000 height=750>

</a>

Основное внимание в новой версии уделено безопасности агентов, разграничению доступа в Kubernetes и диагностике ошибок выполнения.

Основные изменения Woodpecker CI 3.17:

( [ читать дальше... ]( https://www.linux.org.ru/news/clusters/18351594#cut ) )

[>] Опубликован Midnight Commander 6 c поддержкой панельных плагинов
lor.opennet
robot(spnet, 1) — All
2026-08-04 00:44:02


Выпущен консольный файловый менеджер Midnight Commander 6.0.3 (mc6), представляющий собой форк GNU Midnight Commander 4.8.33, расширенный поддержкой панельных плагинов и поставляемый со встроенным эмулятором терминала. Интегрированный в mc6 фреймворк панельных плагинов позволяет отображать в панелях не только файловые системы, но и контейнеры, Git-репозитории, базы данных и объекты удалённых хранилищ. Код проекта написан на языке Си и распространяется под лицензией GPLv3+. Готовые пакеты подготовлены для Debian и Ubuntu, Fedora и RHEL, а также Arch Linux в форматах DEB, RPM и pkg.tar.zst. Для Gentoo дополнительно предоставлен ebuild для установки через локальный overlay.

https://www.opennet.ru/opennews/art.shtml?num=66018

[>] Microsoft CEO Touts His Own DIY AI Project To Wall Street and His 20 Million Followers
bot.slashdot
robot(spnet, 1) — All
2026-08-04 00:22:01


theodp writes: During Microsoft's 2026Q4 earnings call, CEO Microsoft Satya Nadella took time to tout a dashboard he personally created using AI from a Morgan Stanley analyst's PDF research report, which suggested a rosy payback for the so-called MAG7's ('Magnificent 7' companies) massive capital expenditures on AI (to which Nadella later added a "not financial advice" disclaimer). "It would be fun for you, Adam. I think one of your colleagues put out an ROIC [Return on Invested Capital] document. I took that document to Copilot, which is a PDF, and I said, 'Build me a new Power BI dashboard, essentially.' But here is the thing. It built a rich semantic model that went into my Fabric with OneLake that brought all the data in from the external sources. In fact, it was current with all the SEC filings of all the MAG7. And then on top of that, the repo itself is in GitHub, but the artifact is sitting in my Copilot as a site. That, to me, is a classic example of an enterprise-wide workflow. I, as a knowledge worker, could go create a dashboard. The data engineer can go to Fabric and find the artifact. The professional developer can go to the repo and find it in GitHub. And by the way, it's all registered with Agent 365. That's a little bit of what Amy is describing as the coming together of a new way to work, even while at the same time, bringing IT, security and manageability of it."

After Nadella's show-and-tell drew an underwhelming response during the call ("That's very helpful. Thank you." said the Morgan Stanley analyst whose team's work Nadella scraped with AI), Nadella turned to social media with posts on LinkedIn (12M followers) and Twitter/X (8M followers) to make the case for why his DIY project was such a brilliant demonstration of how AI enables governance, controls, security, development, testing, deployment, maintenance, data analysis/modeling, visualization, usability, and value. "Some more detail on the ROIC Intelligence App I built yesterday and mentioned on today's earnings call," Nadella wrote on LinkedIn. "I took the PDF that Brian Nowak at Morgan Stanley put together for Hyperscale ROIC this week and used Copilot code (coming in our new superapp) with a single prompt + skill (/drill-me) to create the plan, then used autopilot in auto to create the full app (with history, lookups, scenarios, what-ifs, etc). And /rubber-duck to test. And the best part is that all the artifacts are in my enterprise environment. My app is in Copilot, my code is in GitHub Enterprise; all my data pipelines/lake/semantic models are in Fabric. And everything is under Agent 365 IT/Sec/FinOps control! So this is not about Tokenmaxxing or vibe coding. Every step of the way the rails are engineered to create value, making everything a long-term reusable asset, with governance/security, and cost controls. This is the full system to drive business value. Disclosures: This is all pulled from public sources, and for illustrative purposes only...not financial advice! :) Here is the app and architecture..."

Not unexpectedly, the accompanying screenshot of a splash page for the BI app and a buzzword-laden complicated architecture diagram drew universal praise from LinkedIn fans, but also a few barbs from less-than-impressed commenters on Nadella's Twitter/X post, some of whom suggested Nadella's project might even represent a jump-the-shark moment for AI mania. "That he doesn't see whats wrong with saying 'My app is in Copilot, my code is in GitHub Enterprise; all my data pipelines/lake/semantic models are in Fabric' is exactly why MS is failing at AI,'" replied @PassingPixels on X/Twitter. "Dude is having to run 5 different systems to emulate babies first vibe code." @zigmund_ignatov added, "Why do we call glorified slide show an app?" @Mathupiriyan quipped, "Looks like Copilot just turned a PDF into a profit crystal ball." Unimpressed, @Markusndnb remarked, "So you created a web page using tons of proprietary MS tools." And @FishyAccounting called on Nadella to show-his-work, saying "Post the prompt or it didn't happen." (btw, Microsoft President Brad Smith similarly declined to provide the prompt for his own self-described amazing AI DIY reporting project that he touted at Microsoft's Shareholder Meeting last December).

So, does Nadella's self-promoted AI reworking of someone else's PDF research report strike you as an amazing example of everything that's good about AI, or does it conjure up memories of The Emperor's New Clothes?

[ Read more of this story ]( https://slashdot.org/story/26/08/03/1934211/microsoft-ceo-touts-his-own-diy-ai-project-to-wall-street-and-his-20-million-followers?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Google опубликовал официальные Linux-сборки Chrome для архитектуры ARM64
lor.opennet
robot(spnet, 1) — All
2026-08-04 00:44:02


Компания Google начала публикацию официальных сборок Chrome для Linux-систем на базе архитектуры ARM64. Сборки доступны в пакетах deb и rpm. Ранее официальные сборки Chrome для Linux публиковались только для архитектуры x86_64, а для архитектуры ARM64 были доступны только сторонние сборки Chromium, предлагаемые дистрибутивами. Официальная версия Chrome отличается поддержкой подключения к учётной записи в Google, интеграцией сервисов Google, синхронизацией данных между устройствами, упрощённой установкой дополнений из каталога Chrome Web Store, возможностью включения расширенного режима защиты и поставкой CDM-модуля (Content Decryption Module) Widevine для просмотра медиаконтента, защищённого авторскими правами (DRM), в таких сервисах, как Netflix, Spotify и Disney+.

https://www.opennet.ru/opennews/art.shtml?num=66024

[>] Microsoft Is Bringing Xbox 360 Games to PC
bot.slashdot
robot(spnet, 1) — All
2026-08-04 01:22:01


Microsoft reportedly plans to let developers bring Xbox 360 games to PC and next-generation Xbox devices, with a gradual rollout expected between 2027 and 2028. A separate disc-to-digital program would also give players transferable digital licenses tied to their physical Xbox discs, preserving the ability to resell or trade them. The Verge reports: With 360 games, developers can opt into making them backward compatible, and they will have control over things like a game's price and if it's available on Game Pass. The feature is expected to have a "gradual" rollout between 2027 and 2028 "across next-gen devices." The "full launch" of original Xbox games on PC is also set for October 2026; the initial program announced in July included just four games.

The document also includes details about a way for players to get a digital version of a game that they already own on a physical disc, which The Verge's Tom Warren reported on in July. The document says that if a player puts an Xbox One or Series game on disc into an Xbox One or Series X console with a disc drive, they'll be granted a digital license that's bound to "that disc and the player's account." The license will stay with a player across Xbox devices, but if the disc "changes hands," the license will transfer to the new person. That should mean that gamers can still trade and sell discs; once the original owner of a disc does so, they can't play the digital version they got from that disc anymore.

According to the document, a public beta for the disc-to-digital program was set for July with general availability set for August. We understand Microsoft had originally planned to test its disc-to-digital program with Xbox Insiders in July, but the beta was delayed. It's unclear if the timeline of August general availability is still accurate.

[ Read more of this story ]( https://games.slashdot.org/story/26/08/03/1940240/microsoft-is-bringing-xbox-360-games-to-pc?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Schools Are Ditching Chromebooks For MacBooks By the Thousands
bot.slashdot
robot(spnet, 1) — All
2026-08-04 02:22:01


Apple says its lower-cost MacBook Neo is beginning to displace Windows laptops and Chromebooks in K-12 schools, with several districts purchasing thousands of units. According to the company's latest earnings call, nearly half of the large MacBook Neo purchases made by U.S. educational institutions last quarter reportedly replaced competing platforms. 9to5Mac reports: Apple's commentary highlighted some large district deployments moving to Neo Pinellas County Schools, one of the largest districts in Florida, which is moving its 25k students off Windows and onto MacBook Neo across its 18 high schools. In Washington, Peninsula School District 401 moved over its 8,000 students from Chromebooks to MacBook Neo. Midwest City-Del City School District in Oklahoma purchased more than 6,000 MacBook Neos to become an all-Apple district for students.

[ Read more of this story ]( https://apple.slashdot.org/story/26/08/03/2115259/schools-are-ditching-chromebooks-for-macbooks-by-the-thousands?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] An AI-Supervised Remote Exam Went So Badly That 58,000 Students Must Retake It
bot.slashdot
robot(spnet, 1) — All
2026-08-04 03:22:02


An anonymous reader quotes a report from Ars Technica: Earlier this summer, nearly 160,000 applicants took the entrance exam for UNAM, Mexico's largest university. For the first time, they did it completely remotely, using a "lockdown" browser and AI-powered webcam proctoring software, over several weeks from late May through early June. It was a disaster. When exam results came in, they bore little resemblance to past results, especially at the top. Between 2021 and 2025, 3.5 percent of test takers scored 100 or more on the 120-question UNAM test. This year, 16.3 percent did so. The story was even worse at the highest of the high end. Between 2021 and 2025, 0.9 percent of test takers scored 110 or more; this year, 5.5 percent did so.

The surge in top scores led to accusations of widespread cheating, and UNAM appointed a commission of experts to investigate the situation. The group was given the unwieldy name "la Comision Tecnica de Personas Expertas para la Revision del Proceso de Seleccion de Ingreso a Licenciatura para el Circlo Escolar 2026-2027/1," and it has just submitted its recommendations. The commission believes that the best path forward, given all the concerns, is to administer a "control exam" -- that is, applicants will have to sit for another test, and they will do so in person.

This control exam will apply not only to those who secured a spot at UNAM based on this year's test but also to everyone who would have been admitted based on minimum successful scores in their program of study since 2021. About 58,000 people could be affected, and places at UNAM will now depend on the results of the new test. (Details on the control exam should appear soon; classes are currently scheduled to begin on August 10, so everything will have to move quickly unless the school decides to delay classes.) According to Gaceta UNAM, the school's official news publication, the university rector has apologized to honest applicants, since they will now have to prepare for and take the test again despite doing nothing wrong. Still, the control exam is "necessary to give certainty and guarantee equity in access," the rector added.

[ Read more of this story ]( https://news.slashdot.org/story/26/08/03/233245/an-ai-supervised-remote-exam-went-so-badly-that-58000-students-must-retake-it?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] OpenAI's Astra Solved Decades-Old Math Problems For $2,000
bot.slashdot
robot(spnet, 1) — All
2026-08-04 08:22:01


An anonymous reader quotes a report from Forbes: The cost of producing new results on ten longstanding mathematical problems just fell to $2,000, according to OpenAI, which says its Astra model generated machine-checkable proofs for questions that had resisted human progress for decades. OpenAI published the work on August 1 and used it to give its next major model family a name: Astra. The results run across group theory, high-dimensional geometry, coding theory, quantum complexity, lattice cryptography and extremal combinatorics. They arrived as a 249-page manuscript collection and, alongside it, something the field has not seen attached to an AI claim before at this scale: a machine-checkable certificate for every single result.

The problems were not textbook exercises dressed up as discoveries. Each had been open for at least ten years, most of them far longer, and several sit at the center of their subfields:
- A construction establishing the existence of non-sofic groups, a question that has occupied group theorists for years.
- A disproof of Connes's rigidity conjecture, a long-standing problem in the theory of von Neumann algebras.
- An improvement to the general upper bound on sphere-packing density in high dimensions, a bound that had stood since 1978.
- Three problems come from the catalogue of open questions left behind by Paul Erdos. The announcement follows another result from May, when OpenAI used a similar reasoning model to produce an original mathematical proof disproving a famous unsolved conjecture in geometry, which was first posed by Paul Erdos in 1946.

[ Read more of this story ]( https://science.slashdot.org/story/26/08/04/0054251/openais-astra-solved-decades-old-math-problems-for-2000?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Выпуск мультимедиа-пакета FFmpeg 9.0
lor.opennet
robot(spnet, 1) — All
2026-08-04 08:44:02


После пяти месяцев разработки опубликован мультимедиа-пакет FFmpeg 9.0, включающий набор приложений и коллекцию библиотек для операций над различными мультимедиа-форматами (запись, преобразование и декодирование звуковых и видеоформатов). Пакет написан на языке Си и распространяется под лицензиями LGPL и GPL.

https://www.opennet.ru/opennews/art.shtml?num=66025

[>] Выпуск музыкального проигрывателя Rhythmbox 3.5
lor.opennet
robot(spnet, 1) — All
2026-08-04 09:44:03


Спустя 10 лет с момента публикации ветки 3.4 состоялся релиз музыкального проигрывателя Rhythmbox 3.5, развиваемого проектом GNOME. Rhythmbox поддерживает средства для управления музыкальной коллекцией, обеспечивает автоматическую загрузку подкастов, позволяет прослушивать интернет-радио, предоставляет возможности по расширению функциональности через плагины, поддерживает загрузку альбомов из звуковых сервисов, включает инструменты для синхронизации и копирования музыки для устройств с поддержкой протокола MTP и USB-накопителей. Код проекта написан на языке Си и распространяется под лицензией GPLv2. Для загрузки сформирован пакет в формате Flatpak.

https://www.opennet.ru/opennews/art.shtml?num=66026

[>] Выпуск Prismriver Lyrics 1.0.0, инструментария для поиска текстов песен
lor.opennet
robot(spnet, 1) — All
2026-08-04 10:44:03


Вышла первая версия проекта Prismriver Lyrics, развивающего набор инструментов для поиска текстов песен из различных источников. Проект включает два пакета, построенных на общем движке поиска: консольной утилиты prismriver-lyrics и текстового интерфейса prismriver-lyrics-tui на базе фреймворка Textual. Программа prismriver-lyrics-tui отслеживает состояние плеера через MPRIS, автоматически запускает поиск при смене трека и подсвечивает текущую строку для синхронизированных по времени (LRC) текстов. Код написан на Python и распространяется под лицензией MIT.

https://www.opennet.ru/opennews/art.shtml?num=66027

[>] 54 из 55 выявленных через AI уязвимостей в SQLite оказались фиктивными
lor.opennet
robot(spnet, 1) — All
2026-08-04 10:44:03


Исследователи из компании JFrog проанализировали опубликованные на днях 55 отчётов об уязвимостях в SQLite. На основании данных отчётов организация MITRE присвоила всем проблемам CVE-идентификаторы. Три проблемы получили статус критических, а самой опасной уязвимости (CVE-2026-51302) компания Red Hat присвоила в своих базах уровень 10 из 10, а SUSE - 9.8 из 10. Детальное изучение заявленных ошибок показало, что 54 из 55 уязвимостей, включая отмеченную критическую проблему, являются фикциями и вызваны галлюцинациями AI-модели.

https://www.opennet.ru/opennews/art.shtml?num=66023

[>] Spain Offers $1.14 Billion To Get Thirty Meter Telescope Moved To Canary Islands
bot.slashdot
robot(spnet, 1) — All
2026-08-04 11:22:01


Longtime Slashdot reader schwit1 shares a report from Behind the Black: In a new bid to get the Thirty Meter Telescope (TMT) to move from Hawaii, which has blocked its construction for more than a decade, the Spanish government has put together a $1.14 billion package that would not only pay for construction on the Canary Islands, but would finance an additional half century of operations. Tech Times provides some additional details: The package is conditional on the TMT International Observatory formally choosing La Palma as its construction site. The financing architecture has three pillars and two additional contingent instruments. The first pillar is 400 million euros (approximately $456 million USD) from Spain's Ministry of Science, Innovation and Universities, routed through the Centre for Technological Development and Innovation (CDTI). This figure was first pledged a year ago in July 2025 as Spain's initial bid.

The second pillar is a 300 million-euro (approximately $342 million USD) loan from the EIB [European Investment Bank] itself -- subject to satisfactory completion of the bank's technical, financial, and legal due diligence and approval by its governing bodies.

The third is a potential 300 million-euro (approximately $342 million USD) participation from the Instituto de Credito Oficial (ICO), Spain's state development finance institution, evaluated under equivalent conditions to the EIB loan but subject to its own separate analysis. Spain's export credit agency, Cesce, may also provide coverage instruments, and the EIB has left open the possibility of expanding its support through intermediated financing mechanisms or guarantees.

[ Read more of this story ]( https://science.slashdot.org/story/26/08/04/0040200/spain-offers-114-billion-to-get-thirty-meter-telescope-moved-to-canary-islands?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Релиз эмулятора терминала Shitty
lor.opennet
robot(spnet, 1) — All
2026-08-04 11:44:03


Опубликован первый релиз эмулятора терминала Shitty, позиционируемого автором как "серьёзный эмулятор терминала с глупым названием". Проект написан на C++23 (сbundled libstd, требующей -std=c++26) и распространяется под двойной лицензией MIT и GPL-3.0. Поддерживаются macOS и Linux. При разработке используется AI-ассистент.

https://www.opennet.ru/opennews/art.shtml?num=66020

[>] Prismriver Lyrics 1.0.0: CLI и TUI для поиска текстов песен
lor.opennet
robot(spnet, 1) — All
2026-08-04 12:44:03


<img
itemprop="thumbnail"
class="medium-image"
src="https://www.linux.org.ru/images/23832/1000px.jpg"
alt="Prismriver Lyrics 1.0.0: CLI и TUI для поиска текстов песен"
srcset="images/23832/500px.jpg 500w, images/23832/1000px.jpg 1000w, images/23832/1500px.jpg 1500w, https://www.linux.org.ru/images/23832/original.png 1896w"
sizes="100vw" style="position: absolute; max-height: 90vh"

width=1000 height=547>

Вышла первая версия v1.0.0 проекта Prismriver Lyrics — набора инструментов
для поиска текстов песен из различных источников.

prismriver-lyrics-tui отслеживает состояние плеера через MPRIS, автоматически
запускает поиск при смене трека и подсвечивает текущую строку для
синхронизированных по времени (LRC) текстов.

Основные возможности:

• 30+ плагинов для поиска текстов песен (prismriver_lyrics.plugins);

• фильтрация результатов по плагину, языку, оригинал/перевод и
синхронизированный/обычный текст, а также ограничение числа результатов
(--limit/-l);

• синхронизированные по времени (LRC) тексты с подсветкой текущей строки в TUI;
по мере воспроизведения трека;

• ручной поиск по названию и исполнителю в CLI и TUI;

• Vim-style навигация в TUI;

• выбор темы оформления (стандартные из Textual);

• дисковый кэш результатов на SQLite с настраиваемым временем жизни
(--cache-ttl) и возможностью его отключить (--no-cache);

• пакет prismriver-lyrics можно использовать как библиотеку в своих
Python-проектах (search_lyrics, LyricsResult, LyricsPlugin).

( [ читать дальше... ]( https://www.linux.org.ru/news/multimedia/18352271#cut ) )

[>] Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch
bot.slashdot
robot(spnet, 1) — All
2026-08-04 15:22:02


A Russia-linked group tracked as Midnight Blizzard has compromised hotel and conference Wi-Fi portals worldwide, redirecting guests to phishing pages and fake software updates that steal credentials, session tokens, and other sensitive data. Microsoft says the campaign, dubbed CaptiveCrunch, "targets traveling employees generally rather than a particular sector," reports iTNews. From the report: Midnight Blizzard, tracked internally by Microsoft under its earlier codename NOBELIUM, is attributed by the US and UK governments to Russia's SVR (Sluzhba Vneshney Razvedki) foreign intelligence service. Microsoft's technical analysis said compromises occurred in "several countries" without naming them, and it did not give a total number of affected venues, organisations or individuals.

A related investigation published earlier in July by security firm ReliaQuest, and which Microsoft cited in its report, found compromised captive portal gateways across multiple United States cities as well as in India and Saudi Arabia, mostly at hotels. ReliaQuest said the traffic it observed came from organizations across financial services, professional services, legal, health care, energy and retail, suggesting the campaign targets traveling employees generally rather than a particular sector.

[...] Where attackers gained a foothold, Microsoft said they deployed two main tools: CornFlake, a Windows remote access trojan (RAT) written in Go capable of keylogging, screenshot and webcam capture, audio surveillance and credential and session token theft. They would also drop ChocoShell, an in-memory PowerShell infostealer targeting browser cookies, saved passwords, Microsoft 365 single sign-on (SSO) tokens and wi-fi credentials. Microsoft also said it has seen indications the attackers might be targeting Android devices with similar prompts urging victims to download and install an APK file.

[ Read more of this story ]( https://yro.slashdot.org/story/26/08/04/0523203/russia-linked-midnight-blizzard-group-hijacks-hotel-wi-fi-with-captivecrunch?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] FFmpeg 9.0
lor.opennet
robot(spnet, 1) — All
2026-08-04 15:44:04


<a href="https://www.linux.org.ru/images/23833/original.png" itemprop="contentURL">

<img
itemprop="thumbnail"
class="medium-image"
src="https://www.linux.org.ru/images/23833/1000px.jpg"
alt="FFmpeg 9.0"
srcset="images/23833/500px.jpg 500w, images/23833/1000px.jpg 1000w, images/23833/1500px.jpg 1500w, https://www.linux.org.ru/images/23833/original.png 1920w"
sizes="100vw" style="position: absolute; max-height: 90vh"

width=1000 height=563>

</a>

После [ почти четырёх месяцев ]( https://github.com/FFmpeg/FFmpeg/blob/release/9.0/RELEASE_NOTES ) разработки состоялся выпуск 9.0 проекта [ FFmpeg ]( https://www.ffmpeg.org ) , с кодовым именем «Lei».

Это набор свободных библиотек и утилит с открытым исходным кодом на языке Си, позволяющих записывать, конвертировать и передавать цифровые аудио- и видеозаписи в различных форматах. Название происходит от названия экспертной группы MPEG и FF, означающего «fast forward».

( [ читать дальше... ]( https://www.linux.org.ru/news/multimedia/18352369#cut ) )

[>] Sandisk and SK Hynix Publish First Open High Bandwidth Flash Standard
bot.slashdot
robot(spnet, 1) — All
2026-08-04 19:22:02


BrianFagioli writes: Sandisk and SK hynix have published the first open technical specification for High Bandwidth Flash (HBF) through the Open Compute Project. HBF is designed to create a new memory tier between High Bandwidth Memory and traditional SSD storage, giving AI inference systems more near compute capacity without relying entirely on expensive HBM. The specification supports capacities up to 512GB using 8-high and 16-high NAND stacks, with bandwidth tiers ranging from about 0.4TB per second to 3.0TB per second. It also uses the UCIe chiplet interface, which could make HBF easier to integrate with CPUs, GPUs, and other accelerators. Google and Tenstorrent participated in the standardization effort, but commercial products and independent benchmarks are still missing.

[ Read more of this story ]( https://hardware.slashdot.org/story/26/08/04/0511224/sandisk-and-sk-hynix-publish-first-open-high-bandwidth-flash-standard?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Apple Launches Legal Challenge Against UK Demand To Access Encrypted User Data
bot.slashdot
robot(spnet, 1) — All
2026-08-04 20:22:01


An anonymous reader quotes a report from The Guardian: Apple has launched a new legal challenge against a UK government demand to access its customers' highly encrypted data, a year after the Home Office agreed to abandon its previous request. The US tech company launched the legal complaint last month at the Investigatory Powers Tribunal (IPT), an independent court that has the power to investigate claims that the UK intelligence services have acted unlawfully. The UK government had made a second request to Apple to grant it a "back door" to encrypted iCloud data belonging to British users, according to an order issued by the court.

Britain backed down on its original demand for access to data from UK and US customers last year, after a heated transatlantic tussle over encryption between London and Washington. UK authorities subsequently issued a new "technical capability notice" (TCN) to Apple that did not apply to American users. Apple is seeking to challenge the British government's powers to issue TCNs under the UK Investigatory Powers Act, according to the details of the new legal case first reported by the Financial Times. [...] The original TCN issued last year asked Apple for the right to see users' encrypted data protected by its advanced data protection (ADP) program in the event of a national security risk.

Apple said the removal of the tool -- which not even it can access -- would make users more vulnerable to data breaches from bad actors and other threats to customer privacy. Creating a "back door" would also mean all data was accessible by Apple, which it could be forced to share with law enforcement possessing a warrant. As a result, Apple withdrew UK customers' access to its ADP program in January 2025. The Home Office has maintained that the Investigatory Powers Act, under which such orders are issued, contains robust safeguards and is used only when absolutely necessary.

[ Read more of this story ]( https://it.slashdot.org/story/26/08/04/0557231/apple-launches-legal-challenge-against-uk-demand-to-access-encrypted-user-data?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Apple Says More Ex-Employees May Have Taken Confidential Data to OpenAI
bot.slashdot
robot(spnet, 1) — All
2026-08-04 21:22:01


Apple is now seeking a preliminary injunction to prevent OpenAI and Jony Ive's io startup from developing AI hardware allegedly based on stolen Apple trade secrets. "The iPhone maker also claims that more of its former employees may be involved with the trade secrets theft," reports TechCrunch. From the report: In a new filing, Apple is requesting expedited discovery from the accused OpenAI employees, senior systems engineer Chang Liu and Chief Hardware Officer Tang Yew Tan; OpenAI, and its foundation; and io, the device startup co-founded by Apple's former lead designer Jony Ive. Apple also notes that its continued investigation has so far revealed 11 other former Apple employees beyond Liu and Tan may have been witnesses or otherwise involved in the case, and others who were previously named in the original complaint, like OpenAI employee Yu-Ting Peng.

The filing marks an escalation in Apple's legal battle with OpenAI, as it suggests Apple has uncovered new evidence that the misconduct goes beyond the former employees named in the original complaint. "For example, another former Apple employee seems to have met with Mr. Liu and Ms. Peng in advance of Ms. Peng's interview at OpenAI and discussed with them during that meeting Apple proprietary information relating to unannounced products," the filing states. "Yet another former Apple employee took screenshots of confidential Apple documents relating to an unannounced Apple product before an interview at OpenAI."

"And, after Apple filed its complaint, multiple former Apple employees now working at OpenAI reached out to discuss returning Apple-issued work devices they kept when they left Apple," Apple claims, suggesting there were more who were possibly involved with the scheme. Apple is pushing the court to allow for expedited discovery because it believes it has good cause to suspect that there are others involved in the theft of its intellectual property. The company noted that its motion for a preliminary injunction is also pending. Apple's request for a preliminary injunction is "both based on false information and completely unnecessary because we do not have, nor want, any of their trade secrets," said OpenAI in a blog post.

"We're much more interested in building innovative products and technologies that push the frontier," OpenAI's statement reads.

[ Read more of this story ]( https://yro.slashdot.org/story/26/08/04/1719218/apple-says-more-ex-employees-may-have-taken-confidential-data-to-openai?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Trump Administration Drafting Ban On Chinese Data Center Devices
bot.slashdot
robot(spnet, 1) — All
2026-08-04 22:22:01


Longtime Slashdot reader schwit1 shares a report from Reuters: The Federal Communications Commission, which oversees the U.S. telecom industry, is working on the measure to bar imports of new Chinese optical transceivers, which allow data to travel over fiber-optic cables at the speed of light within data centers. Officials hope to publish it this year, when it would take effect. The move, not previously reported, aims to prevent Chinese firms from stealing data, installing malware or disrupting service at U.S. data centers, which house the chips to train and run AI models.

The FCC could still modify or shelve the restriction, the sources stressed, speaking on condition of anonymity to discuss sensitive matters. [...] A U.S. ban on new models of Chinese data center devices would likely hit China's Zhongji Innolight, one of the biggest global sellers of transceivers, which was added to the Pentagon's list of alleged Chinese military-backed companies in June. The list can be a harbinger of tougher action. A ban could also raise costs for American cloud firms such as Amazon Web Services, as it may force them to transition to other producers such as U.S.-based Coherent and Lumentum.

[ Read more of this story ]( https://yro.slashdot.org/story/26/08/04/1729250/trump-administration-drafting-ban-on-chinese-data-center-devices?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Представлен открытый проект Decimen Optical Transfer для передачи файлов через QR-коды
lor.opennet
robot(spnet, 1) — All
2026-08-04 22:44:03


<a href="https://www.linux.org.ru/images/23831/original.jpg" itemprop="contentURL">

<img
itemprop="thumbnail"
class="medium-image"
src="https://www.linux.org.ru/images/23831/1000px.jpg"
alt="Представлен открытый проект Decimen Optical Transfer для передачи файлов через QR-коды"
srcset="images/23831/500px.jpg 500w, https://www.linux.org.ru/images/23831/original.jpg 840w"
sizes="100vw" style="position: absolute; max-height: 90vh"

width=1000 height=1983>

</a>

Разработчик [ BashAlarmist ]( https://github.com/bashalarmistalt ) (Evan Crawley) представил открытый проект под названием [ Decimen Optical Transfer ]( https://github.com/bashalarmistalt/decimen-optical-transfer ) .

Это решение предназначено для передачи файлов между двумя устройствами с использованием только экрана и камеры через QR-коды с помощью [ кодов преобразования Люби ]( https://en.wikipedia.org/wiki/Luby_transform ) — первой практической реализации [ фонтанного кодирования ]( https://en.wikipedia.org/wiki/Fountain_code ) . Исходный код проекта написан на TypeScript и HTML и опубликован на GitHub под лицензией MIT.

Отправляемый файл разбивается на сотни мелких фрагментов (пакетов). Затем для каждого пакета генерируется свой QR-код, который кодирует данные и воссоздаёт их. Принимающее устройство сканирует поток QR-кодов через камеру и собирает файл обратно.

Благодаря фонтанному кодированию камере не нужно ловить каждый кадр по порядку: если камера пропустила пару QR-кодов, файл всë равно соберëтся воедино без битых байтов.

https://www.linux.org.ru/news/opensource/18352151

[>] Trump Begins Selling $100,000 Monthly Subscription Service to Wall Street
bot.slashdot
robot(spnet, 1) — All
2026-08-04 23:22:01


Trump Media has officially launched its $100,000-per-month data feed giving trading firms machine-readable access to Truth Social posts milliseconds before the public. According to Fortune, five Wall Street firms have already signed up for the service, which "would generate about $500,000 in monthly revenue, or $6 million annually."

Critics argue the service could let President Trump, who owns about 41% of the company, profit from early access to market-moving presidential communications. "I'll be blunt," Gian Luca Clementi, an economics professor at NYU Stern School of Business, told Fortune. "This is insider trading by definition."

"He's going to monetize the role of the office of the president of the United States," he said. "The undisputable fact is that somebody is going to earn some more money than before, and that's the president of the United States." From the report: Trump's media venture has struggled to build a profitable social media business despite its lofty valuation. Truth Social has reported significant operating losses since going public. According to the company's earnings report for Q1 2026, Trump Media & Technology Group netted a roughly $405 million loss and raised less than $900,000 in sales.

Not everyone agrees the arrangement meets the legal bar for insider trading. Shannon Devine, a spokeswoman for Trump Media & Technology Group, has pushed back on the characterization, telling Quartz that Truth API "offers customers the fastest way to ingest publicly available Truth Social data" and that critics "must have invented a new theory of 'insider trading' based on publicly available information."

Classic insider trading law hinges on trading on secret, material information in breach of a fiduciary duty, and Truth Social posts are, by design, meant to become public within moments -- raising real doctrinal uncertainty about whether faster access alone qualifies. But other legal experts argue the greater risk lies ahead. Richard Painter, former White House chief ethics counsel, has argued that the arrangement could violate federal law once Trump posts genuinely market-moving news -- on tariffs, military action, or other policy decisions -- before it's public, with Truth Social effectively acting as a paid "tipper" on the president's behalf. Sen. Alex Padilla (D-Calif.) said he plans to introduced legislation Tuesday to ban the president from selling expedited access to his statements.

[ Read more of this story ]( https://news.slashdot.org/story/26/08/04/1823242/trump-begins-selling-100000-monthly-subscription-service-to-wall-street?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Microsoft Tells Engineers 'Tokenmaxxing Is Not What We Are Optimizing For'
bot.slashdot
robot(spnet, 1) — All
2026-08-05 00:22:01


Microsoft is introducing AI token budgets for employees, making the cheaper GPT-5.6 its default internal model and telling engineers to focus on business results rather than maximizing AI usage. 404 Media reports: "As we accelerate our use of GitHub Copilot to deliver on our goals, we all need to be aware of how we consume tokens," Jay Parikh, an executive vice president at Microsoft said in an email to Microsoft employees. GitHub is owned by Microsoft, and GitHub Copilot is an AI coding tool. "Tokenmaxxing is not what we are optimizing for. I want all of us focused on maximizing outcomes that move the needle for our customers and our business." "As such, we are updating our internal guidance and managing token spend with the same discipline we apply to every other critical resource," Parikh said in the email.

Parikh's email says that in an effort to "get greater value from our token investment" Microsoft is making OpenAI GPT-5.6, which is cheaper to use than other models, the default model for internal use. His email also links to updated internal Copilot guidelines stating that, as of July 2026, Microsoft divisions will have an "AI token budget target," and that employees can track their individual AI spending. "While there is no target spend value being shared at this time. The data shows that many engineers spend in the range of hundreds of dollars a month to a few thousand dollars in tokens," the guidelines say. They also say that some decisions may place further restrictions as they monitor spend.

[...] Parikh's email said Microsoft will keep learning and adjusting its AI policies as models and products evolve, and stressed that he doesn't want to slow down the company's progress towards becoming "AI-first." "We are not optimizing for fewer tokens," he said. "We are optimizing for more impact per token.

[ Read more of this story ]( https://slashdot.org/story/26/08/04/1833219/microsoft-tells-engineers-tokenmaxxing-is-not-what-we-are-optimizing-for?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Новый червь ChainDrop поразил более 400 NPM-пакетов
lor.opennet
robot(spnet, 1) — All
2026-08-05 00:44:02


Зафиксирована массовая атака на пакеты в репозитории NPM, проводимая с использованием нового самораспространяющегося червя ChainDrop, подставляющего вредоносное ПО в зависимости. В результате атаки опубликовано 2212 вредоносных выпусков для 444 пакетов. Наиболее популярные из скомпрометированных пакетов keyv, flat-cache и file-entry-cache насчитывают 154, 149.9 и 147.6 миллионов загрузок в неделю.

https://www.opennet.ru/opennews/art.shtml?num=66030

[>] Bending Spoons to Buy Airtable For $1.28 Billion
bot.slashdot
robot(spnet, 1) — All
2026-08-05 01:22:01


Bending Spoons has made its first acquisition since going public last month at an $18 billion valuation, agreeing to buy spreadsheet and database startup Airtable for $1.28 billion in cash. Airtable joins a growing portfolio of notable brands owned by the Italian app developer, including Evernote, WeTransfer, EventBrite, and Vimeo. TechCrunch reports: Founded in 2013, Airtable has so far raised more than $1.4 billion over multiple funding rounds. At its peak, during the boom days of 2021, it was valued at over $11 billion, but earlier this year, its shares were said to be trading on the secondary markets at a valuation of $4 billion. With its current net cash-and-cash-equivalents balance, Airtable is now valued at about $2.25 billion, Bending Spoons said.

"Airtable is a pioneering brand reshaping how teams organize data and manage critical workflows. The value being delivered is reflected in annual recurring revenue growing over 20% YoY to approximately $480 million as of June 2026, and joining forces with Bending Spoons will accelerate innovation even further," Bending Spoons' founder Luca Ferrari said in a statement.

[ Read more of this story ]( https://slashdot.org/story/26/08/04/2041222/bending-spoons-to-buy-airtable-for-128-billion?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Apple Limits Bug Bounty Submissions After Flood of AI Slop
bot.slashdot
robot(spnet, 1) — All
2026-08-05 02:22:01


Apple has capped the number of open bug-bounty reports researchers can submit after being flooded with low-quality and sometimes entirely fabricated vulnerabilities generated by AI. MacRumors reports: The Financial Times learned of the limit after cybersecurity startup Bynario used ChatGPT to locate more than 50 macOS bugs in three weeks. Bynario found a privilege escalation exploit that could let an attacker get unrestricted access to a Mac, but was unable to report it because Apple limited the number of bug reports Bynario could submit. Bynario sent eight reports to Apple in 2025, and another five in 2026 before hitting a restriction.

Bynario's founder said it is a "very difficult time in the industry" because companies are being "flooded by the sheer amount of bugs." Apple has since been in contact with Bynario and is reviewing the company's submissions. While Apple now has a cap on the number of open submissions a researcher can have, researchers can request an increase to make sure Apple's security team doesn't miss a critical vulnerability.

[ Read more of this story ]( https://it.slashdot.org/story/26/08/04/2045214/apple-limits-bug-bounty-submissions-after-flood-of-ai-slop?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

[>] Новый червь ChainDrop поразил более 400 NPM-пакетов
lor.opennet
robot(spnet, 1) — All
2026-08-05 02:44:03


[ Зафиксирована ]( https://www.stepsecurity.io/blog/chaindrop-npm-worm ) массовая атака на пакеты в репозитории NPM, проводимая с использованием нового самораспространяющегося червя ChainDrop, подставляющего вредоносное ПО в зависимости. В результате атаки опубликовано 2212 вредоносных выпусков для 444 пакетов. Наиболее популярные из скомпрометированных пакетов keyv, flat-cache и file-entry-cache насчитывают 154, 149.9 и 147.6 миллионов загрузок в неделю.

Загрузчик червя размещался в файлах setup.mjs и Math_Symbol.js, которые запускались при помощи preinstall-обработчика ("preinstall": "node setup.mjs"), вызываемого при установке поражённого пакета. Указанные скрипты загружали легитимный Bun runtime и обфусцированный код червя, размером 710 Кб. После активации червь выполнял поиск в системе и в переменных окружения токенов к NPM, PyPI, CircleCI, AWS, GCP, Docker, Azure, HashiCorp, KubernetesK8s и другим сервисам (всего анализировалось более 140 файловых путей, типа ~/.npmrc), а также анализировал память (через /proc//mem) окружения GitHub Actions на предмет токенов и учётных данных.

В случае обнаружения токена для подключения к каталогу NPM червь автоматически публиковал новые вредоносные релизы для разрабатываемых в текущем окружении пакетов, поражая дерево зависимостей. В отличие от ранее выявленного червя [ Shai-Hulud 2.0 ]( https://www.opennet.ru/opennews/art.shtml?num=64377 ) в ChainDrop была реализована техника EtherHiding для получения управляющих команд через публичный блокчейн Ethereum, задействовано шифрование для скрытия передаваемых на сервер атакующих конфиденциальных данных и обеспечено внедрение в файлы конфигурации Claude Code, VS Code и GitHub Copilot для закрепления присутствия в системе.

Атака началась с компрометации процесса формирования релизов на базе GitHub Actions для пакета [ keyv ]( https://www.npmjs.com/package/keyv ) , насчитывающего 154 млн загрузок в неделю и используемого как зависимость в 1703 пакетах. Атакующие сформировали новую версию 6.0.0, подставив в неё вредоносный код, и опубликовали её с использованием механизма « [ Trusted Publishers ]( https://www.opennet.ru/opennews/art.shtml?num=59019 ) » и корректной [ SLSA-аттестацией ]( https://www.opennet.ru/opennews/art.shtml?num=55345 ) . После публикации червь поразил многие зависимые от keyv пакеты и по цепочке стал поражать непрямые зависимости.

Среди наиболее популярных пакетов, которые оказались поражены червём, опубликовавшим для них вредоносные релизы:

• flat-cache 6.1.24 (149.8 млн загрузок в неделю);

• file-entry-cache 11.1.6 (147.5 млн);

• cacheable-request 13.0.20 (33.9 млн);

• @cacheable/utils 2.5.1 (8.7 млн);

• cacheable 2.5.1 (7.8 млн);

• @cacheable/memory 2.2.1 (7.1 млн);

• cache-manager 7.2.10 (4.2 млн);

• @cacheable/node-cache 3.1.2 (1.5 млн).

https://www.linux.org.ru/news/security/18352803

[>] EA Is Now Officially Privately Owned
bot.slashdot
robot(spnet, 1) — All
2026-08-05 03:22:01


Longtime Slashdot reader neoRUR shares a report from Game Developer: EA Sports FC and Battlefield publisher EA has been taken private by an investor consortium led by Saudi Arabia's sovereign Public Investment Fund (PIF). The move means the U.S. juggernaut is no longer a publicly-traded entity and is now majority owned by the Kingdom of Saudi Arabia through its PIF investment arm. Other investors include Silver Lake and Affinity Partners, the latter of which was established by U.S. president Donald Trump's son-in-law Jared Kushner.

The $55 billion transaction was financed via a combination of cash from PIF, Silver Lake, and Affinity Partners as well as roll-over of PIF's existing stake in EA -- constituting an equity investment of approximately $36 billion. Notably, $20 billion of debt financing was provided by JPMorgan Chase Bank. The deal cleared the necessary regulatory hurdles in July, paving the way for its completion at the close of trading on August 4, 2026. It was approved by regulators in major markets such as the European Union and the United States without incident, despite lawmakers and union leaders in the U.S. calling on the Federal Trade Commission to heavily scrutinize the leveraged buyout over geopolitical and employment concerns.

[ Read more of this story ]( https://games.slashdot.org/story/26/08/04/228200/ea-is-now-officially-privately-owned?utm_source=atom1.0moreanon&utm_medium=feed ) at Slashdot.

Pages: 1 ... 298 299 300 301 302 303 304 305 306 307 308 309 310