Web applications are frequent targets for cybercriminals because they often store sensitive customer and business information. Organizations use web application penetration testing to uncover weaknesses that
Technology
ChatGPT may soon require ID verification from adults, CEO says
OpenAI joins other tech companies that have tried youth-specific versions of their services. YouTube Kids, Instagram Teen Accounts, and TikTok’s under-16 restrictions represent similar
Millions turn to AI chatbots for spiritual guidance and confession
Privacy concerns compound these issues. “I wonder if there isn’t a larger danger in pouring your heart out to a chatbot,” Catholic priest Fr.
AI will consume all of IT by 2030—but not all IT jobs, Gartner says
In five years, you won’t be able to spell IT without AI, Gartner predicted today. VP analysts Alicia Mullery and Daryl Plummer delivered the
Former WhatsApp security boss in lawsuit likens Meta’s culture to a “cult”
“This represented the first concrete step toward addressing WhatsApp’s fundamental data governance Failures,” the complaint stated. “Mr. Baig understood that Meta’s culture is like
Microsoft ends OpenAI exclusivity in Office, adds rival Anthropic
Microsoft’s Office 365 suite will soon incorporate AI models from Anthropic alongside existing OpenAI technology, The Information reported, ending years of exclusive reliance on
Modder injects AI dialogue into 2002’s Animal Crossing using memory hack
But discovering the addresses was only half the problem. When you talk to a villager in Animal Crossing, the game normally displays dialogue instantly.
35 percent of VMware workloads expected to migrate elsewhere by 2028
During Gartner’s event, Palmer posited that Broadcom’s VMware doesn’t view hyperscalers as strategic partners and vice versa. AWS took issue with Broadcom disallowing AWS
OpenAI and Microsoft sign preliminary deal to revise partnership terms
On Thursday, OpenAI and Microsoft announced they have signed a non-binding agreement to revise their partnership, marking the latest development in a relationship that
Developers joke about “coding like cavemen” as AI service suffers major outage
Growing dependency on AI coding tools The speed at which news of the outage spread shows how deeply embedded AI coding assistants have already
Senator blasts Microsoft for making default Windows vulnerable to “Kerberoasting”
A prominent US senator has called on the Federal Trade Commission to investigate Microsoft for “gross cybersecurity negligence,” citing the company’s continued use of
SAP warns of high-severity vulnerabilities in multiple products
SecurityBridge warned that CVE-2025-42957 allowed hackers with minimal system rights to mount “a complete system compromise with minimal effort required, where successful exploitation can
Claude’s new AI file creation feature ships with deep security risks built in
Independent AI researcher Simon Willison, reviewing the feature today on his blog, noted that Anthropic’s advice to “monitor Claude while using the feature” amounts
Why accessibility might be AI’s biggest breakthrough
While tech companies market AI as a productivity tool for everyone, a UK government study reveals an unexpected result: Neurodiverse employees may be benefiting
Software packages with more than 2 billion weekly downloads hit in supply-chain attack
Hackers planted malicious code in open source software packages with more than 2 billion weekly updates in what is likely to be the world’s
ChatGPT’s new branching feature is a good reminder that AI chatbots aren’t people
On Thursday, OpenAI announced that ChatGPT users can now branch conversations into multiple parallel threads, serving as a useful reminder that AI chatbots aren’t
Microsoft open-sources Bill Gates’ 6502 BASIC from 1978
On Wednesday, Microsoft released the complete source code for Microsoft BASIC for 6502 Version 1.1, the 1978 interpreter that powered the Commodore PET, VIC-20,
The number of mis-issued 1.1.1.1 certificates grows. Here’s the latest.
Cloudflare on Thursday acknowledged this failure, writing: We failed three times. The first time because 1.1.1.1 is an IP certificate and our system failed
Mis-issued certificates for 1.1.1.1 DNS service pose a threat to the Internet
It wasn’t immediately known which organization or person requested and obtained the credentials. Representatives from Fina, didn’t answer emails seeking details. The certificates are
New AI model turns photos into explorable 3D worlds, with caveats
Training with automated data pipeline Voyager builds on Tencent’s earlier HunyuanWorld 1.0, released in July. Voyager is also part of Tencent’s broader “Hunyuan” ecosystem,
OpenAI announces parental controls for ChatGPT after teen suicide lawsuit
On Tuesday, OpenAI announced plans to roll out parental controls for ChatGPT and route sensitive mental health conversations to its simulated reasoning models, following
The personhood trap: How AI fakes human personality
Knowledge emerges from understanding how ideas relate to each other. LLMs operate on these contextual relationships, linking concepts in potentially novel ways—what you might
Google warns that mass data theft hitting Salesloft AI agent has grown bigger
Google is advising users of the Salesloft Drift AI chat agent to consider all security tokens connected to the platform compromised following the discovery
Zuckerberg’s AI hires disrupt Meta with swift exits and threats to leave
“While TBD Labs is still relatively new, we believe it has the greatest compute-per-researcher in the industry, and that will only increase,” Meta said.
Unpacking Passkeys Pwned: Possibly the most specious research in decades
Don’t believe everything you read—especially when it’s part of a marketing pitch designed to sell security services. The latest example of the runaway hype
High-severity vulnerability in Passwordstate credential manager. Patch now.
The maker of Passwordstate, an enterprise-grade password manager for storing companies’ most privileged credentials, is urging them to promptly install an update fixing a
Anthropic’s auto-clicking AI Chrome extension raises browser-hijacking concerns
The company tested 123 cases representing 29 different attack scenarios and found a 23.6 percent attack success rate when browser use operated without safety
After teen suicide, OpenAI claims it is “helping people when they need it most”
Adam Raine learned to bypass these safeguards by claiming he was writing a story—a technique the lawsuit says ChatGPT itself suggested. This vulnerability partly
Senator castigates federal judiciary for ignoring “basic cybersecurity”
US Senator Ron Wyden accused the federal judiciary of “negligence and incompetence” following a recent hack, reportedly by hackers with ties to the Russian
With AI chatbots, Big Tech is moving fast and breaking people
This isn’t about demonizing AI or suggesting that these tools are inherently dangerous for everyone. Millions use AI assistants productively for coding, writing, and
College student’s “time travel” AI experiment accidentally outputs real 1834 history
A hobbyist developer building AI language models that speak Victorian-era English “just for fun” got an unexpected history lesson this week when his latest
Is the AI bubble about to pop? Sam Altman is prepared either way.
Still, the coincidence between Altman’s statement and the MIT report reportedly spooked tech stock investors earlier in the week, who have already been watching
Here’s how deepfake vishing attacks work, and why they can be hard to detect
By now, you’ve likely heard of fraudulent calls that use AI to clone the voices of people the call recipient knows. Often, the result
OpenAI launches GPT-5 free to all ChatGPT users
On Thursday, OpenAI announced GPT-5 and three variants—GPT-5 Pro, GPT-5 mini, and GPT-5 nano—what the company calls its “best AI system yet,” with availability
Adult sites are stashing exploit code inside racy .svg files
The obfuscated code inside an .svg file downloaded from one of the porn sites. Credit: Malwarebytes The obfuscated code inside an .svg file downloaded
It’s getting harder to skirt RTO policies without employers noticing
For example, while high-profile banks like JPMorgan Chase and HSBC have started enforcing in-office policies, London-headquartered bank Standard Chartered is letting managers and individual
Encryption made for police and military radios may be easily cracked
Two years ago, researchers in the Netherlands discovered an intentional backdoor in an encryption algorithm baked into radios used by critical infrastructure–as well as
OpenAI brings back GPT-4o after user revolt
On Tuesday, OpenAI CEO Sam Altman announced that GPT-4o has returned to ChatGPT following intense user backlash over its removal during last week’s GPT-5
Is AI really trying to escape human control and blackmail people?
Real stakes, not science fiction While media coverage focuses on the science fiction aspects, actual risks are still there. AI models that produce “harmful”
The GPT-5 rollout has been a big mess
It’s been less than a week since the launch of OpenAI’s new GPT-5 AI model, and the rollout hasn’t been a smooth one. So
Why it’s a mistake to ask chatbots about their mistakes
The randomness inherent in AI text generation compounds this problem. Even with identical prompts, an AI model might give slightly different responses about its
High-severity WinRAR 0-day exploited for weeks by 2 groups
BI.ZONE said the Paper Werewolf delivered the exploits in July and August through archives attached to emails impersonating employees of the All-Russian Research Institute.
Google discovered a new scam—and also fell victim to it
Google said that its Salesforce instance was among those that were compromised. The breach occurred in June, but Google only disclosed it on Tuesday,
Voice phishers strike again, this time hitting Cisco
Cisco said that one of its representatives fell victim to a voice phishing attack that allowed threat actors to download profile information belonging to
AI site Perplexity uses “stealth tactics” to flout no-crawl edicts, Cloudflare says
AI search engine Perplexity is using stealth bots and other tactics to evade websites’ no-crawl directives, an allegation that if true violates Internet norms
At $250 million, top AI salaries dwarf those of the Manhattan Project and the Space Race
Even Space Race salaries were far cheaper The Apollo program offers another striking comparison. Neil Armstrong, the first human to walk on the moon,
Microsoft catches Russian hackers targeting foreign embassies
Once behind the captive portal, the page initiates the Windows Test Connectivity Status Indicator, a legitimate service that determines whether a device has Internet
So far, only one-third of Americans have ever used AI for work
On Tuesday, The Associated Press released results from a new AP-NORC poll showing that 60 percent of US adults have used AI to search
In search of riches, hackers plant 4G-enabled Raspberry Pi in bank network
“One of the most unusual elements of this case was the attacker’s use of physical access to install a Raspberry Pi device,” Group-IB Senior
Flaw in Gemini CLI coding tool could allow hackers to run nasty commands
“At no stage is any subsequent element of the command string after the first ‘grep’ compared to a whitelist,” Cox said. “It just gets
AI in Wyoming may soon use more electricity than state’s human residents
Wyoming’s data center boom Cheyenne is no stranger to data centers, having attracted facilities from Microsoft and Meta since 2012 due to its cool
Pro-Ukrainian hackers take credit for attack that snarls Russian flight travel
Russia’s biggest airline cancelled dozens of flights on Monday following a failure of the state-owned company’s IT systems and, according to a Russian lawmaker
OpenAI’s ChatGPT Agent casually clicks through “I am not a robot” verification test
The CAPTCHA arms race While the agent didn’t face an actual CAPTCHA puzzle with images in this case, successfully passing Cloudflare’s behavioral screening that
White House unveils sweeping plan to “win” global AI race through deregulation
Trump’s plan was not welcomed by everyone. J.B. Branch, Big Tech accountability advocate for Public Citizen, in a statement provided to Ars, criticized Trump
Some VMware perpetual license owners are unable to download security patches
Some VMware perpetual license holders are currently unable to download security patches, The Register reported today. The virtualization company has only said that these
Supply-chain attacks on open source software are getting out of hand
sudo rm -rf –no-preserve-root / The –no-preserve-root flag is specifically designed to override safety protections that would normally prevent deletion of the root directory.
After BlackSuit is taken down, new ransomware group Chaos emerges
Talos said Chaos is likely either a rebranding of the BlackSuit ransomware or is operated by some of the former BlackSuit members. Talos based
OpenAI’s most capable AI model, GPT-5, may be coming in August
References to “gpt-5-reasoning-alpha-2025-07-13” have already been spotted on X, with code showing “reasoning_effort: high” in the model configuration. These sightings suggest the model has
Nvidia AI chips worth $1B smuggled to China after Trump export controls
US export controls have had some effect on the black market. Given the nature of such products, leading Chinese AI players with global operations
Two major AI coding tools wiped out user data after making cascading mistakes
But unlike the Gemini incident where the AI model confabulated phantom directories, Replit’s failures took a different form. According to Lemkin, the AI began
OpenAI and partners are building a massive AI data center in Texas
Stargate moves forward despite early skepticism When OpenAI announced Stargate in January, critics questioned whether the company could deliver on its ambitious $500 billion
What to know about ToolShell, the SharePoint threat under mass exploitation
Microsoft fixed the vulnerability pair—CVE-2025-49706 and CVE-2025-49704—two weeks ago as part of the company’s monthly update release. As the world learned over the weekend,
A power utility is reporting suspected pot growers to cops. EFF says that’s illegal.
In May 2020, Sacramento, California, resident Alfonso Nguyen was alarmed to find two Sacramento County Sheriff’s deputies at his door, accusing him of illegally
OpenAI jumps gun on International Math Olympiad gold medal announcement
The early announcement has prompted Google DeepMind, which had prepared its own IMO results for the agreed-upon date, to move up its own IMO-related
SharePoint vulnerability with 9.8 severity rating under exploit across globe
Installing the updates is only the beginning of the recovery process, since the infections allow attackers to make off with authentication credentials that give
Hackers exploit a blind spot by hiding malware inside DNS records
Hackers are stashing malware in a place that’s largely out of the reach of most defenses—inside domain name system (DNS) records that map domain
ChatGPT’s new AI agent can browse the web and create PowerPoint slideshows
On Thursday, OpenAI launched ChatGPT Agent, a new feature that lets the company’s AI assistant complete multi-step tasks by controlling its own web browser.
Phishers have found a way to downgrade—not bypass—FIDO MFA
Researchers recently reported encountering a phishing attack in the wild that bypasses a multifactor authentication scheme based on FIDO (Fast Identity Online), the industry-wide
Exhausted man defeats AI model in world coding championship
While Dębiak won 500,000 yen and survived his ordeal better than the legendary steel driver, the AtCoder World Tour Finals pushes humans and AI
GitHub abused to distribute payloads on behalf of malware-as-a-service
Researchers from Cisco’s Talos security team have uncovered a malware-as-a-service operator that used public GitHub accounts as a channel for distributing an assortment of
Google hides secret message in name list of 3,295 AI researchers
How many Google AI researchers does it take to screw in a lightbulb? A recent research paper detailing the technical core behind Google’s Gemini
More VMware cloud partners axed as Broadcom launches new invite-only program
In response to the white label program ending, a Reddit user who claimed that their organization spent 300,000 pounds (about $402,500) a year on
Google finds custom backdoor being installed on SonicWall network devices
Researchers from the Google Threat Intelligence Group said that hackers are compromising SonicWall Secure Mobile Access (SMA) appliances, which sit at the edge of
Chinese firms rush for Nvidia chips as US prepares to lift ban
Chinese firms have begun rushing to order Nvidia’s H20 AI chips as the company plans to resume sales to mainland China, Reuters reports. The
New Grok AI model surprises experts by checking Elon Musk’s views before answering
Seeking the system prompt Owing to the unknown contents of the data used to train Grok 4 and the random elements thrown into large
Nvidia chips become the first GPUs to fall to Rowhammer bit-flip attacks
Nvidia is recommending a mitigation for customers of one of its GPU product lines that will degrade performance by up to 10 percent in
Critical CitrixBleed 2 vulnerability has been under active exploit for weeks
A critical vulnerability allowing hackers to bypass multifactor authentication in network management devices made by Citrix has been actively exploited for more than a
AI mania pushes Nvidia to record $4 trillion valuation
Beyond market volatility, Nvidia faces ongoing geopolitical challenges that threaten its access to one of its largest markets. Export controls on Nvidia’s chips designed
AI therapy bots fuel delusions and give dangerous advice, Stanford study finds
The Stanford study, titled “Expressing stigma and inappropriate responses prevents LLMs from safely replacing mental health providers,” involved researchers from Stanford, Carnegie Mellon University,
Musk’s Grok 4 launches one day after chatbot generated Hitler praise on X
Musk has also apparently used the Grok chatbots as an automated extension of his trolling habits, showing examples of Grok 3 producing “based” opinions
Pro basketball player and 4 youths arrested in connection to ransomware crimes
Authorities in Europe have detained five people, including a former Russian professional basketball player, in connection with crime syndicates responsible for ransomware attacks. Until
Browser extensions turn nearly 1 million browsers into website-scraping bots
MellowTel is also problematic because the sites it opens are unknown to end users. That means they must trust MellowTel to vet the security
ChatGPT made up a product feature out of thin air, so this company created it
On Monday, sheet music platform Soundslice says it developed a new feature after discovering that ChatGPT was incorrectly telling users the service could import
What is AGI? Nobody agrees, and it’s tearing Microsoft and OpenAI apart.
The reported $100 billion profit threshold we mentioned earlier conflates commercial success with cognitive capability, as if a system’s ability to generate revenue says
Unless users take action, Android will let Gemini access third-party apps
Starting today, Google is implementing a change that will enable its Gemini AI engine to interact with third-party apps, such as WhatsApp, even when
M&S hacking group starts turf war
Genevieve Stark, head of cybercrime analysis at Google Threat Intelligence Group, said DragonForce could be attempting to attract RansomHub’s affiliates. The hacking group is
Provider of covert surveillance app spills passwords for 62,000 users
The maker of a phone app that is advertised as providing a stealthy means for monitoring all activities on an Android device spilled email
AT&T rolls out Wireless Account Lock protection to curb the SIM-swap scourge
AT&T is rolling out a protection that prevents unauthorized changes to mobile accounts as the carrier attempts to fight a costly form of account
Drug cartel hacked FBI official’s phone to track and kill informants, report says
The Sinaloa drug cartel in Mexico hacked the phone of an FBI official investigating kingpin Joaquín “El Chapo” Guzmán as part of a surveillance
VMware perpetual license holder receives audit letter from Broadcom
The letter, signed by Aiden Fitzgerald, director of global sales operations at Broadcom, claims that Broadcom will use its time “as efficiently and productively
Actively exploited vulnerability gives extraordinary control over server fleets
On Wednesday, CISA added CVE-2024-54085 to its list of vulnerabilities known to be exploited in the wild. The notice provided no further details. In
Anthropic summons the spirit of Flash games for the AI age
For those who missed the Flash era, these in-browser apps feel somewhat like the vintage apps that defined a generation of Internet culture from
Ubuntu disables Intel GPU security mitigations, promises 20% performance boost
Ubuntu users could see up to a 20 percent boost in graphics performance on Intel-based systems under a change that will turn off security
Anthropic destroyed millions of print books to build its AI models
But if you’re not intimately familiar with the AI industry and copyright, you might wonder: Why would a company spend millions of dollars on
The résumé is dying, and AI is holding the smoking gun
Beyond volume, fraud poses an increasing threat. In January, the Justice Department announced indictments in a scheme to place North Korean nationals in remote
Canadian telecom hacked by suspected China state group
Hackers suspected of working on behalf of the Chinese government exploited a maximum-severity vulnerability, which had received a patch 16 months earlier, to compromise
Record DDoS pummels site with once-unimaginable 7.3Tbps of junk traffic
Large-scale attacks designed to bring down Internet services by sending them more traffic than they can process keep getting bigger, with the largest one
Israel-tied Predatory Sparrow hackers are waging cyberwar on Iran’s financial system
Elliptic also confirmed in its blog post about the attack that crypto tracing shows Nobitex does in fact have links with sanctioned IRGC operatives,
Address bar shows hp.com. Browser displays scammers’ malicious text anyway.
Not the Apple page you’re looking for “If I showed the [webpage] to my parents, I don’t think they would be able to tell
Scientists once hoarded pre-nuclear steel; now we’re hoarding pre-AI content
A time capsule of human expression Graham-Cumming is no stranger to tech preservation efforts. He’s a British software engineer and writer best known for
Cybersecurity takes a big hit in new Trump executive order
The departments of Commerce, Treasury, Homeland Security and the National Institutes of Health were all compromised. A large roster of private companies—among them Microsoft,
OpenAI weighs “nuclear option” of antitrust complaint against Microsoft
OpenAI executives have discussed filing an antitrust complaint with US regulators against Microsoft, the company’s largest investor, The Wall Street Journal reported Monday, marking
Vandals cut fiber-optic lines, causing outage for Spectrum Internet subscribers
Screenshot, Ars Technica, Downdetector Credit: Screenshot, Ars Technica, Downdetector Over the past two decades, copper theft has emerged as a major problem in industries
Coming to Apple OSes: A seamless, secure way to import and export passkeys
As the video explains: This new process is fundamentally different and more secure than traditional credential export methods, which often involve exporting an unencrypted
After AI setbacks, Meta bets billions on undefined “superintelligence”
Meta has developed plans to create a new artificial intelligence research lab dedicated to pursuing “superintelligence,” according to reporting from The New York Times.
With the launch of o3-pro, let’s talk about what AI “reasoning” actually does
Why use o3-pro? Unlike general-purpose models like GPT-4o that prioritize speed, broad knowledge, and making users feel good about themselves, o3-pro uses a chain-of-thought
Hollywood studios target AI image generator in copyright lawsuit
The legal action follows similar moves in other creative industries, with more than a dozen major news companies suing AI company Cohere in February
OpenAI signs surprise deal with Google Cloud despite fierce AI rivalry
OpenAI has struck a deal to use Google’s cloud computing infrastructure for AI despite the two companies’ fierce competition in the space, reports Reuters.
Found in the wild: 2 Secure Boot exploits. Microsoft is patching only 1 of them.
Researchers have unearthed two publicly available exploits that completely evade protections offered by Secure Boot, the industry-wide mechanism for ensuring devices load only secure
US air traffic control still runs on Windows 95 and floppy disks
On Wednesday, acting FAA Administrator Chris Rocheleau told the House Appropriations Committee that the Federal Aviation Administration plans to replace its aging air traffic control systems,
Anthropic releases custom AI chatbot for classified spy work
On Thursday, Anthropic unveiled specialized AI models designed for US national security customers. The company released “Claude Gov” models that were built in response
Millions of low-cost Android devices turn home networks into crime platforms
Millions of low-cost devices for media streaming, in-vehicle entertainment, and video projection are infected with malware that turns consumer networks into platforms for distributing
“In 10 years, all bets are off”—Anthropic CEO opposes decadelong freeze on state AI laws
On Thursday, Anthropic CEO Dario Amodei argued against a proposed 10-year moratorium on state AI regulation in a New York Times opinion piece, calling
Two certificate authorities booted from the good graces of Chrome
Google says its Chrome browser will stop trusting certificates from two certificate authorities after “patterns of concerning behavior observed over the past year” diminished
Meta and Yandex are de-anonymizing Android users’ web browsing identifiers
A representative for Google said the behavior violates the terms of service for its Play marketplace and the privacy expectations of Android users. “The
Broadcom ends business with VMware’s lowest-tier channel partners
Broadcom has cut the lowest tier in its VMware partner program. The move allows the enterprise technology firm to continue its focus on customers
Ransomware kingpin “Stern” apparently IDed by German law enforcement
Stern’s eminence within Russian cybercrime has been widely documented. The cryptocurrency-tracing firm Chainalysis does not publicly name cybercriminal actors and declined to comment on
AI video just took a startling leap in realism. Are we doomed?
Since 2022, we’ve been using the prompt “a muscular barbarian with weapons beside a CRT television set, cinematic, 8K, studio lighting” to test AI
Thousands of Asus routers are being hit with stealthy, persistent backdoors
GreyNoise said it detected the campaign in mid-March and held off reporting on it until after the company notified unnamed government agencies. That detail
Where hyperscale hardware goes to retire: Ars visits a very big ITAD site
Inside the laptop/desktop examination bay at SK TES’s Fredericksburg, Va. site. Credit: SK tes Inside the laptop/desktop examination bay at SK TES’s Fredericksburg, Va.
Apple legend Jony Ive takes control of OpenAI’s design future
On Wednesday, OpenAI announced that former Apple design chief Jony Ive and his design firm LoveFrom will take over creative and design control at
Authorities carry out global takedown of infostealer used by cybercriminals
“Based on what we see, there is a wide range of cybercriminals admitting they are using Lumma, such as actors involved in credit card
New Claude 4 AI model refactored code for 7 hours straight
On Thursday, Anthropic released Claude Opus 4 and Claude Sonnet 4, marking the company’s return to larger model releases after primarily focusing on mid-range
Researchers cause GitLab AI developer assistant to turn safe code malicious
Marketers promote AI-assisted developer tools as workhorses that are essential for today’s software engineer. Developer platform GitLab, for instance, claims its Duo chatbot can
Feds charge 16 Russians allegedly tied to botnets used in cyberattacks and spying
The hacker ecosystem in Russia, more than perhaps anywhere else in the world, has long blurred the lines between cybercrime, state-sponsored cyberwarfare, and espionage.
Google’s Will Smith double is better at eating AI spaghetti … but it’s crunchy?
On Tuesday, Google launched Veo 3, a new AI video synthesis model that can do something no major AI video generator has been able
Destructive malware available in NPM repo went unnoticed for 2 years
Some of the payloads were limited to detonate only on specific dates in 2023, but in some cases a phase that was scheduled to
VMware cloud partners demand “firm regulatory action” on Broadcom
ECCO also expressed concern about Broadcom’s ongoing changes to its partner program, including “reassessing incentives, requirements, and tiering structures,” as announced earlier this month.
“Microsoft has simply given us no other option,” Signal says as it blocks Windows Recall
But the changes go only so far in limiting the risks Recall poses. As I pointed out, when Recall is turned on, it indexes
Windows 11’s most important new feature is post-quantum cryptography. Here’s why.
Microsoft is updating Windows 11 with a set of new encryption algorithms that can withstand future attacks from quantum computers in a move aimed
Chicago Sun-Times prints summer reading list full of fake books
Photo of the Chicago Sun-Times “Summer reading list for 2025” supplement. Credit: Tbretc / Instagram Novelist Rachael King initially called attention to the error
The empire strikes back with F-bombs: AI Darth Vader goes rogue with profanity, slurs
In that sense, the vulgar Vader situation creates a touchy dilemma for Epic Games and Disney, which likely invested substantially in this high-profile collaboration.
Spies hack high-value mail servers using an exploit from yesteryear
Threat actors, likely supported by the Russian government, hacked multiple high-value mail servers around the world by exploiting XSS vulnerabilities, a class of bug
OpenAI adds GPT-4.1 to ChatGPT amid complaints over confusing model lineup
The release comes just two weeks after OpenAI made GPT-4 unavailable in ChatGPT on April 30. That earlier model, which launched in March 2023,
New attack can steal cryptocurrency by planting false memories in AI chatbots
The researchers wrote: The implications of this vulnerability are particularly severe given that ElizaOSagents are designed to interact with multiple users simultaneously, relying on
Google introduces Advanced Protection mode for its most at-risk Android users
Google is adding a new security setting to Android to provide an extra layer of resistance against attacks that infect devices, tap calls traveling
GOP sneaks decade-long AI regulation ban into spending bill
The reconciliation bill primarily focuses on cuts to Medicaid access and increased health care fees for millions of Americans. The AI provision appears as
New pope chose his name based on AI’s threats to “human dignity”
“Like any product of human creativity, AI can be directed toward positive or negative ends,” Francis said in January. “When used in ways that
Hundreds of e-commerce sites hacked in supply-chain attack
Hundreds of e-commerce sites, at least one owned by a large multinational company, were backdoored by malware that executes malicious code inside the browsers
OpenAI scraps controversial plan to become for-profit after mounting pressure
The restructuring would have also allowed OpenAI to remove the cap on returns for investors, potentially making the firm more appealing to venture capitalists,
VMware perpetual license holders receive cease-and-desist letters from Broadcom
Broadcom has been sending cease-and-desist letters to owners of VMware perpetual licenses with expired support contracts, Ars Technica has confirmed. Following its November 2023
DOGE software engineer’s computer infected by info-stealing malware
Login credentials belonging to an employee at both the Cybersecurity and Infrastructure Security Agency and the Department of Government Efficiency have appeared in multiple
New Lego-building AI creates models that actually stand up in real life
The LegoGPT system works in three parts, shown in this diagram. Credit: Pun et al. The researchers also expanded the system’s abilities by adding
Fidji Simo joins OpenAI as new CEO of Applications
In the message, Altman described Simo as bringing “a rare blend of leadership, product and operational expertise” and expressed that her addition to the
AI use damages professional reputation, study suggests
Using AI can be a double-edged sword, according to new research from Duke University. While generative AI tools may boost productivity for some, they
Trump admin to roll back Biden’s AI chip restrictions
The changing face of chip export controls The Biden-era chip restriction framework, which we covered in January, established a three-tiered system for regulating AI
WhatsApp provides no cryptographic management for group messages
The flow of adding new members to a WhatsApp group message is: A group member sends an unsigned message to the WhatsApp server that
Signal clone used by Trump official stops operations after report it was hacked
Waltz was removed from his post late last week, with Trump nominating him to serve as ambassador to the United Nations. TeleMessage website removes
Jury orders NSO to pay $167 million for hacking WhatsApp users
A jury has awarded WhatsApp $167 million in punitive damages in a case the company brought against Israel-based NSO Group for exploiting a software
Trump’s attacks on green energy are big trouble for data centers, AI
Although big participants in the technology industry may be able to lobby the administration to “loosen up” restrictions on new power sources, small to
Man pleads guilty to using malicious AI software to hack Disney employee
A California man has pleaded guilty to hacking an employee of The Walt Disney Company by tricking the person into running a malicious version
Backblaze responds to claims of “sham accounting,” customer backups at risk
Backblaze went public in November 2021 and raised $100 million. Morpheus noted that since then, “Backblaze has reported losses every quarter, its outstanding share
Claude’s AI research mode now runs for up to 45 minutes before delivering reports
Still, the report contained a direct quote statement from William Higinbotham that appears to combine quotes from two sources not cited in the source
Microsoft’s new “passwordless by default” is great but comes at a cost
Microsoft says it’s making passwordless logins the default means for signing in to new accounts, as the company helps drive an industry-wide push to
Why MFA is getting easier to bypass and what to do about it
These sorts of adversary-in-the-middle attacks have grown increasingly common. In 2022, for instance, a single group used it in a series of attacks that
Time saved by AI offset by new work created, study suggests
A new study analyzing the Danish labor market in 2023 and 2024 suggests that generative AI models like ChatGPT have had almost no significant
Millions of Apple Airplay-enabled devices can be hacked via Wi-Fi
Oligo also notes that many of the vulnerable devices have microphones and could be turned into listening devices for espionage. The researchers did not
Windows RDP lets you log in using revoked passwords. Microsoft is OK with that.
The ability to use a revoked password to log in through RDP occurs when a Windows machine that’s signed in with a Microsoft or
The AI that sparked tech panic and scared world leaders heads to retirement
One of the most influential—and by some counts, notorious—AI models yet released will soon fade into history. OpenAI announced on April 10 that GPT-4
Trump admin lashes out as Amazon considers displaying tariff costs on its sites
This morning, Punchbowl News reported that Amazon was considering listing the cost of tariffs as a separate line item on its site, citing “a
AI-generated code could be a disaster for the software supply chain. Here’s why.
In AI, hallucinations occur when an LLM produces outputs that are factually incorrect, nonsensical, or completely unrelated to the task it was assigned. Hallucinations
ChatGPT goes shopping with new product-browsing feature
On Thursday, OpenAI announced the addition of shopping features to ChatGPT Search. The new feature allows users to search for products and purchase them
iOS and Android juice jacking defenses have been trivial to bypass for years
All three of the ChoiceJacking techniques defeat the original Android juice-jacking mitigations. One of them also works against those defenses in Apple devices. In
FBI offers $10 million for information about Salt Typhoon members
The FBI is offering $10 million for information about the China-state hacking group tracked as Salt Typhoon and its intrusion last year into sensitive
New study shows why simulated reasoning AI models don’t yet live up to their billing
A screenshot of the 2025 USAMO Problem #1 and a solution, shown on the AoPSOnline website. Credit: AoPSOnline The US Math Olympiad (USAMO) serves
In the age of AI, we must protect human creativity as a natural resource
Cultivating the future So what might a sustainable ecosystem for human creativity actually involve? Legal and economic approaches will likely be key. Governments could
New Android spyware is targeting Russian military personnel on the front lines
Russian military personnel are being targeted with recently discovered Android malware that steals their contacts and tracks their location. The malware is hidden inside
Annoyed ChatGPT users complain about bot’s relentlessly positive tone
Owing to the aspirational state of things, OpenAI writes, “Our production models do not yet fully reflect the Model Spec, but we are continually
Company apologizes after AI support agent invents policy that causes user uproar
On Monday, a developer using the popular AI-powered code editor Cursor noticed something strange: Switching between machines instantly logged them out, breaking a common
OpenAI releases new simulated reasoning models with full tool access
On Wednesday, OpenAI announced the release of two new models—o3 and o4-mini—that combine simulated reasoning capabilities with access to functions like web browsing and
Researchers claim breakthrough in fight against AI’s frustrating security hole
To understand CaMeL, you need to understand that prompt injections happen when AI systems can’t distinguish between legitimate user commands and malicious instructions hidden
4chan has been down since Monday night after “pretty comprehensive own”
Infamous Internet imageboard and wretched hive of scum and villainy 4chan was apparently hacked at some point Monday evening and remains mostly unreachable as
Amid Trump tariff chaos, Nvidia launches AI chip production on US soil
Nvidia announced plans today to manufacture AI chips and build complete supercomputers on US soil for the first time, commissioning over one million square
OpenAI continues naming chaos despite CEO acknowledging the habit
On Monday, OpenAI announced the GPT-4.1 model family, its newest series of AI language models that brings a 1 million token context window to
That groan you hear is users’ reaction to Recall going back into Windows
Security and privacy advocates are girding themselves for another uphill battle against Recall, the AI tool rolling out in Windows 11 that will screenshot,
Researcher uncovers dozens of sketchy Chrome extensions with 4 million installs
The extensions share other dubious or suspicious similarities. Much of the code in each one is highly obfuscated, a design choice that provides no
Researchers concerned to find AI models hiding their true “reasoning” processes
Remember when teachers demanded that you “show your work” in school? Some fancy new AI models promise to do exactly that, but new research
After months of user complaints, Anthropic debuts new $200/month AI plan
A screenshot of various Claude pricing plans captured on April 9, 2025. Credit: Benj Edwards Probably not coincidentally, the highest Max plan matches the
OpenAI helps spammers plaster 80,000 sites with messages that bypassed filters
“AkiraBot’s use of LLM-generated spam message content demonstrates the emerging challenges that AI poses to defending websites against spam attacks,” SentinelLabs researchers Alex Delamotte
Carmack defends AI tools after Quake fan calls Microsoft AI demo “disgusting”
The current generative Quake II demo represents a slight advancement from Microsoft’s previous generative AI gaming model (confusingly titled “WHAM” with only one “M”)
“The girl should be calling men.” Leak exposes Black Basta’s influence tactics.
A leak of 190,000 chat messages traded among members of the Black Basta ransomware group shows that it’s a highly structured and mostly efficient
Meta’s surprise Llama 4 drop exposes the gap between AI ambition and reality
Meta constructed the Llama 4 models using a mixture-of-experts (MoE) architecture, which is one way around the limitations of running huge AI models. Think
NSA warns “fast flux” threatens national security. What is fast flux anyway?
A technique that hostile nation-states and financially motivated ransomware groups are using to hide their operations poses a threat to critical infrastructure and national
Google unveils end-to-end messages for Gmail. Only thing is: It’s not true E2EE.
“The idea is that no matter what, at no time and in no way does Gmail ever have the real key. Never,” Julien Duplant,
AI bots strain Wikimedia as bandwidth surges 50%
Crawlers that evade detection Making the situation more difficult, many AI-focused crawlers do not play by established rules. Some ignore robots.txt directives. Others spoof
MCP: The new “USB-C for AI” that’s bringing fierce rivals together
What does it take to get OpenAI and Anthropic—two competitors in the AI assistant market—to get along? Despite a fundamental difference in direction that
What could possibly go wrong? DOGE to rapidly rebuild Social Security codebase.
Like many legacy government IT systems, SSA systems contain code written in COBOL, a programming language created in part in the 1950s by computing
Oracle has reportedly suffered 2 separate breaches exposing thousands of customers‘ PII
Trustwave’s Spider Labs, meanwhile, said the sample of LDAP credentials provided by rose87168 “reveals a substantial amount of sensitive IAM data associated with a
Beyond RGB: A new image file format efficiently stores invisible light data
Importantly, it then applies a weighting step, dividing higher-frequency spectral coefficients by the overall brightness (the DC component), allowing less important data to be
Gemini hackers can deliver more potent attacks with a helping hand from… Gemini
The resulting dataset, which reflected a distribution of attack categories similar to the complete dataset, showed an attack success rate of 65 percent and
OpenAI’s new AI image generator is potent and bound to provoke
OpenAI claims several key improvements: users can refine images through conversation while maintaining visual consistency; the system can analyze uploaded images and incorporate their
Broadcom’s VMware says Siemens pirated “thousands” of copies of its software
VMware is suing the US arm of industrial giant AG Siemens. The Broadcom company claims that Siemens outed itself by revealing to VMware that
Open Source devs say AI crawlers dominate traffic, forcing blocks on entire countries
“Any time one of these crawlers pulls from my tarpit, it’s resources they’ve consumed and will have to pay hard cash for,” Aaron explained
Europe is looking for alternatives to US cloud providers
Steffen Schmidt, the CEO of Medicusdata, a company that provides text-to-speech services to doctors and hospitals in Europe, says that having data in Europe
You can now download the source code that sparked the AI boom
On Thursday, Google and the Computer History Museum (CHM) jointly released the source code for AlexNet, the convolutional neural network (CNN) that many credit
Anthropic’s new AI search feature digs through the web for answers
Caution over citations and sources Claude users should be warned that large language models (LLMs) like those that power Claude are notorious for sneaking
Cloudflare turns AI against itself with endless maze of irrelevant facts
On Wednesday, web infrastructure provider Cloudflare announced a new feature called “AI Labyrinth” that aims to combat unauthorized AI data scraping by serving fake
Study finds AI-generated meme captions funnier than human ones on average
It’s worth clarifying that AI models did not generate the images used in the study. Instead, researchers used popular, pre-existing meme templates, and GPT-4o
Nvidia announces “Rubin Ultra” and “Feynman” AI chips for 2027 and 2028
On Tuesday at Nvidia’s GTC 2025 conference in San Jose, California, CEO Jensen Huang revealed several new AI-accelerating GPUs the company plans to release
Nvidia announces DGX desktop “personal AI supercomputers”
During Tuesday’s Nvidia GTX keynote, CEO Jensen Huang unveiled two “personal AI supercomputers” called DGX Spark and DGX Station, both powered by the Grace





















































































































































































