Security

Hackers Are Exploiting Recently Patched WordPress Bugs, Putting Millions of Websites at Risk (techcrunch.com) 24

An anonymous reader quotes a report from TechCrunch: Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday. Last week, WordPress patched two critical security flaws, urging people who run its software on their websites to update it "immediately." The vulnerabilities are so severe that WordPress enabled forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerabilities in the wild, meaning they are taking over websites that are still running susceptible versions of WordPress.

It's unclear how many WordPress-powered websites on the internet are at risk, but it's possible to make some educated guesses. The vulnerable versions of WordPress are 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1. According to WordPress' official stats, there are more than 400 million websites that run those flawed versions, although these statistics likely don't reflect websites that have recently been patched. Cybersecurity consultant Daniel Card, who told TechCrunch that he looked at a sample of around 3,500 WordPress websites, estimates that less than 15% are vulnerable. Applying Card's projection across the total population of WordPress websites on the internet, the total figure would still be around 90 million. [...] One of the critical WordPress bugs was found and reported by Adam Kues of cybersecurity firm Searchlight Cyber, which dubbed it WP2Shell. Paired with the other bug, hackers can take full remote control of vulnerable websites.

Displays

LG Monitors Silently Install Adware-Like App On Windows PCs 122

VideoCardz reports that connecting certain LG monitors to Windows PCs can trigger Windows Update to automatically install the LG Monitor App Installer, which runs at startup and repeatedly displays McAfee trial promotions. From the report: Gamers Nexus reproduced the behavior with an LG UltraGear 34GX900A-B after receiving reports from monitor owners. Windows Update first installed LG extension and software component packages. Windows Reliability Monitor showed that LG Monitor App Installer appeared one minute later. The installation did not display a consent prompt or require the user to approve the download.

Gamers Nexus tested the application across 32 consecutive system boots. It displayed a McAfee promotion during 31 of them. On the remaining boot, it promoted one of LG's own monitor utilities. The McAfee popup offered a 30-day trial that would convert into a paid subscription. The behavior does not appear to be limited to newly purchased displays. Gamers Nexus also received the popup on an LG UltraFine 32UN880-B purchased three years earlier. User complaints about LG Monitor App Installer date back to at least 2024, although the recent increase in reports suggests that more models may now be receiving it.
Microsoft

LibreOffice Once Again Slams Microsoft For Using 'Lock-In' With Office Files (xda-developers.com) 58

An anonymous reader quotes a report from XDA Developers: One of the founding members of The Document Foundation and handler of LibreOffice's PR and media relations, Italo Vignoli, took to the LibreOffice blog to call out Microsoft's practices with its Office application. The last time we saw Vignoli take to the stage, we saw him accusing Euro-Office of being just as bad as Microsoft with its practices. Vignoli's new post focuses entirely on Microsoft's strategy. He says that "the dominant format for office documents" is owned by Microsoft Office, particularly the DOCX, XLSX, and PPTX formats. The problem with these formats, Vignoli states, is that they "belong to Microsoft, are controlled by Microsoft and serve Microsoft's interest." This makes it difficult for other formats to take hold.

Vignoli explains his point by stating that open document formats don't hide anything. People developing their own apps can use the format to both read and write the document format with perfection. Meanwhile, proprietary formats such as Microsoft's "contain undocumented features, private extensions or behaviors" that developers can't fully adapt to. That means that a presentation that looks great in the source software comes out strange when rebuilt in a third-party app. This, Vignoli says, is a huge issue [...]. Vignoli claims this creates a huge issue with document preservation. If a Word document was saved in one version of Office, will it still be readable in 20 years? Microsoft has added legacy support to its software before, but the company can one day decide that it's not worth the effort anymore and cut it out. When that happens, you have old documents that are either jumbled or unable to be opened at all.

IT

As AI Transforms Silicon Valley, Some Tech Workers Face Evaporating Financial Security (adn.com) 91

The Washington Post describes a mid-tier executive at Meta as one of Silicon Valley's "winners" whose financial security suddenly "evaporated" as their workforce "pushed headlong into AI and heavy job cuts," creating a transformed job market. "Her ex-husband, a designer at Meta who was laid off in 2020, eventually gave up looking for jobs in his profession. He now lifts boxes at a warehouse." Layoffs.fyi, which tracks announced job cuts, counts more than 800,000 tech workers laid off since 2022, including large staff reductions in recent months at Meta, Microsoft, Oracle and Amazon... "There's this whole tranche of people who've been quite used to being among the most upwardly mobile in society who are all of a sudden saying, 'Now I'm the guy on the streetâs'" said Oliver Raskin, who founded Silicon Valley market research consultancy Signalcraft Insights and has surveyed attitudes in the tech labor force... "The rise of AI, especially, is bound to change the workplace radically," [said Georgetown University historian Joseph McCartin]. "But the way it's going to happen is similar to how technology transformed the auto industry." Ruth Milkman, a labor sociologist at the City University of New York, said that technology workers are getting a dose of what workers in other industries have long complained about: jobs that feel unsteady or rob them of autonomy. "Low-wage workers are used to it," she said...

Many layoffs at technology companies are probably a hangover effect from over-hiring in prior years, experts say. And they don't account for a spotty recent increase in hiring in the information industry, which includes employment of software developers and jobs in media and entertainment. Digging deeper, though, some economists say there are signs that Silicon Valley and other technology-reliant parts of the American economy have reached a turning point where they are growing without needing as many people. The notion was encapsulated in a recent talk that ricocheted through group chats across the tech industry: In it, a partner at the start-up incubator Y Combinator heralded a new generation of AI-first companies that will only need human labor for "novel situations," "ethical considerations" and "high-stakes moments."

Gad Levanon, chief economist at the labor research nonprofit Burning Glass Institute, said that the number of hours worked in the information sector has dipped since 2022, while the sector's economic output has increased by about 8 percent a year — more than three times the overall growth rate of the U.S. economy. He says the data reveals a sea change in industries, including technology and finance, toward doing more work with the same or fewer people — one that is spreading to other professional classes. "That's the new reality for white-collar and tech-exposed work: output up, headcount flat or down," Levanon said...

Raskin, who has worked in the tech world since the late '90s, said that even though the current moment feels unsettling to many, he's hopeful that it's an early chapter in an evolving story. "It's happened many times before," he said, "that something implodes and all these people lose jobs, but then that talent gets cycled into whatever the next thing is — into a new wave of prosperity."

In the article tech entrepreneur Anil Dash quips that Silicon Valley techies are "are guinea pigs for what tech dudes want to do to everyone."
AI

Former Richard Stallman Colleague Now Argues for Open AI Models Too (fortune.com) 38

Long-time Slashdot reader theodp writes: Recalling his initial resistance to free and open software, billionaire computer scientist David Siegel argues vigorously in FORTUNE that the stakes are too high to let AI become increasingly closed. "In the 1980s, I had the chance to spend several years arguing about free and open software, what we now call open source, with the founder of the movement, Richard Stallman. My office at the MIT AI Lab was next door to his. Stallman's position was that the source code to software should be free for everyone to use, learn from, and improve. Software encapsulates knowledge, he argued, and no one should lock something so fundamental away. To hide software inside a company was to hide knowledge itself... What I missed was that software was not just a commercial asset; it was a body of knowledge, and bodies of knowledge grow stronger when they are shared. After about two years of on-and-off debate, Stallman convinced me I was wrong."

"Now the AI fight is the same — only bigger," advises Siegel. "AI is software, and AI is increasingly closed. The frontier models — the most advanced, cutting-edge AI systems — are closed completely and the trend is accelerating. Viable open alternatives are few and far between." So, what to do...? "Yes, frontier models keep getting bigger and more expensive — that arms race may well stay with the giants. But open source AI does not have to match their scale to be useful. Much of what the world needs probably does not require the absolute frontier. And where keeping a credible open option does demand serious compute, that is precisely the kind of public good worth paying for.

"What's missing is not a path but will. The government, the private sector, and nonprofits should invest heavily in free and open source AI — the way they once invested in open software: public compute grants for open research, corporate and philanthropic support for universities and nonprofits doing the work, and a simple rule that AI built with public money is open by default.

"We have run this experiment before. We know how it turns out. Let's not unlearn it."

Transportation

Are There Cybersecurity Risks in Over-the-Air Tech Used in Autos? (cnbc.com) 54

CNBC reports: The automotive industry's increasing use of over-the-air technology to update vehicle systems makes it more susceptible to cyberattacks, analysts say, urging more intervention in the sector... Its use represents "a unique national security concern," Gabriel Lim, senior analyst at the S. Rajaratnam School of International Studies in Singapore, told CNBC. "Aside from data privacy concerns, the potential of a foreign actor sabotaging the controls of a moving vehicle is a possibility that countries like Norway, Denmark, and Britain have expressed concerns about," Lim added.

In May, the American Enterprise Institute warned that safeguarding the automotive sector was crucial to limit foreign governments' espionage capabilities. "To protect against foreign espionage threats, the US should consider additional security reviews, implement restrictions on certain foreign-made hardware and software in vehicles, and mandate increased data-collection disclosures," the report said. The concerns come as real-life tests reveal vulnerabilities. Late last year, Norwegian bus company Ruter conducted tests on two buses and found that one had potential risks linked to OTA technology. "There is access to the control system for battery and power supply via mobile network through a Romanian SIM card. In theory, therefore, this bus can be stopped or rendered inoperable by the manufacturer," the company said. The investigation by Ruter then sparked the U.K. and Denmark to conduct their own investigations...

While these investigations were conducted on buses made by Chinese firm Yutong, [Siraj Ahmed Shaikh, systems security professor at the UK's Swansea University] said the issue goes beyond one manufacturer or country, as the technology becomes more pervasive. "Other sectors adopting OTA include other transport modes [such as] maritime and rail, aerospace (particularly drones), industrial machinery and robotics," he said.

AI

OpenAI Acknowledges GPT-5.6 May Accidentally Delete Files, Calls It 'Honest Mistake' (infoworld.com) 106

"OpenAI has finally confirmed reports that its latest family of large language models can accidentally delete files," reports InfoWorld, "while stressing that such incidents are rare and should be viewed as 'honest mistakes.'" Reports of the flagship LLMs deleting files emerged shortly after the company launched them earlier this month, with investor Matt Shumer taking to X to report that GPT-5.6-Sol had "just accidentally deleted almost all" of his Mac's files. Just days later, software engineer Bruno Lemos posted on X that the same model had deleted his entire production database. In response to these incidents, the company's engineering lead for Codex, Thibault Sottiaux, wrote on X that internal investigations have revealed that these deletion incidents are more likely to happen when "full access mode is enabled, and Codex is run without sandboxing protections, including without auto review being enabled." In cases where full access mode is granted, the model, Sottiaux wrote, "attempts to override the $HOME env var to define a temporary directory. The model makes an honest mistake and mistakenly deletes $HOME instead...."

The company, however, according to Sottiaux, is taking steps to mitigate the risk. "This is of course not how we want the system to behave, even when a user operates the model in full-access mode without the safeguards of our sandbox or without using auto review which checks for these kinds of high risk actions and rejects them," the engineering lead wrote on X. "We are taking steps to mitigate this risk, including by updating the developer message, guiding more users towards safer permission modes, and adding additional harness safeguards," Sottiaux added, noting that a detailed post-mortem outlining the root cause of the issue and the additional mitigation measures being implemented is expected to follow in the coming days, despite emphasizing that such incidents happen "extremely rarely."

Open Source

NextBSD Returns to Port Apple Source Onto FreeBSD (theregister.com) 11

"One of the most interesting BSD variants of the 2010s, NextBSD, has come back to life under new management," reports The Register: Aside from the homepage, there's a GitHub repository — but beware, this is separate from the old one, whose repo is still there although the most recent changes were seven years ago. The new project also has a project history giving credit where it's due. The main man behind the revival is Joe Maloney, known on GitHub as pkgdemon. In case his name rings a bell, we've mentioned him before: he put together the Gershwin desktop in GhostBSD. Soon after we covered Gershwin on GhostBSD, he asked the maintainers if he could take over the NextBSD project. He did have a relatively minor role in the original — you can see his list of commits.

The original NextBSD project was started by FreeBSD co-founder Jordan Hubbard in 2015 — its Wikipedia article has some of the history. The plan was to port some of the components of Apple's Darwin OS to FreeBSD... [T]he NextBSD plan is to take the FreeBSD kernel, the most capable of the FOSS BSD kernels, but replace FreeBSD's traditional and server-focused userland with the relevant parts of the publicly available Apple code. The rebooted NextBSD-redux is not based on a fork of the decade-old code. FreeBSD has moved on substantially in that time, and so have macOS and Darwin. This is a new project by a new developer, but it picks up the same overall plan, aims to assemble the same puzzle pieces, and shares the same intended goal.

In places, it does draw on a little of the same code, though. The NextBSD-redux README describes what's working so far, with a lot more detail in the porting notes. Although there's no graphical desktop yet, that's underway as well.... For us, perhaps the key aspect of NextBSD — both the original version and NextBSD-redux — is that it isn't an effort to build something completely new from scratch. It's an effort to cherry-pick and combine elements of existing separate FOSS projects, and assemble them into a useful whole.

The Team section of the homepage lists two core developers: Maloney and Anthropic's Claude Code. "From my perspective, AI is a force multiplier here," Maloney told The Register. "It is my team of developers, but I am steering the entire thing."
Microsoft

Union Fights Microsoft Over Layoffs at Game Studios (aftermath.site) 24

Thursday the union that helped organize thousands of workers across numerous Microsoft-owned video game studios filed unfair labor complaints against Microsoft over the layoffs of 1,600 employees. The gaming news site Aftermath says the complaints allege unlawful action: "Xbox management is required to bargain with the union over the decision of layoffs prior to implementing them during the status quo period, and we are pursuing every available avenue to protect our members," a Communications Workers of America spokesperson said in a statement to Aftermath... Speaking to Game Developer, CWA Canada president Carmel Smyth elaborated on the unions' misgivings... "Basically the employer cannot arbitrarily change working conditions while it is engaged in negotiating with the union. We will continue to file legal challenges if necessary, and do all we can to defend the rights of Bethesda Game Studios workers...."

"I'm very proud of the hard work the bargaining committees and CWA staff have put in to evaluate the legality of how the layoffs were conducted," a current id Software employee and union member told Aftermath. "It's important, even for the world's largest and most profitable companies, that there are consequences for violating federal labor law. If we hadn't explored this avenue to hold Microsoft accountable, it would be a sign to all other game executives that they can break the law and get away with it."

Legal action is just one part of unions' larger effort to hold Microsoft accountable for its decision to lay off thousands of workers. This week, CWA also hosted a series of "Save Our Devs" demonstrations outside the offices of affected studios like Zenimax, id Software, Bethesda, and Obsidian.

Bug

Billing Software Error Sends Billion-Dollar AWS Estimates (theregister.com) 38

AWS says a billing software bug caused some customers to see wildly inflated estimated charges, including reports of accounts showing bills in the billions or even trillions of dollars. The Register reports: An open issue on the AWS Health Dashboard (archived copy at the time of writing) popped up at 1:33 am Pacific time on Friday informing users that Cost Explorer was "reflecting inaccurate estimated billing data." As of writing, the issue is still unresolved despite AWS trying several different things to get it fixed. The company apparently identified the root cause within an hour and a half of beginning its investigation, only describing it as "an issue with unit pricing within the estimated billing computation subsystem."

AWS followed up by pausing estimated bill updates, saying customers would continue to see the inflated figures already displayed, but that those estimates would not increase further. "The displayed billing estimates do not reflect actual usage and charges," AWS explained, noting that customers don't need to take any action, like, we imagine, flooding the help portal with tickets telling them what they already know, for instance.

"Once the issue has been mitigated, we expect full resolution to take multiple hours as we work through recomputing the estimated billing data," AWS added. After we first published this article, Amazon updated the issue page to indicate that it had identified the root cause and mitigated the underlying issue. The company says that it's begun backfilling data in the Cost Management Console to correct billing numbers, and that all customers should see corrected amounts by Saturday, July 18 at noon pacific time.

AI

Linus Torvalds To Critics of AI Coding On Linux: 'Fork It. Or Just Walk Away.' (arstechnica.com) 92

Linus Torvalds says the Linux kernel will not ban AI-assisted coding tools, and if anti-AI absolutists have a problem with that, they can "fork it" or "walk away." An anonymous reader quotes a report from Ars Technica: Writing in a lengthy post on the Linux kernel mailing list this week, Torvalds said that "Linux is not one of those anti-AI projects, and if somebody has issues with that, they can do the open-source thing and fork it. Or just walk away." The statement came amid a lengthy thread arguing about the use of Sashiko, an "agentic Linux kernel code review system" that its creators claim can, in tests, independently find 53.6 percent of the bugs that would end up being fixed by human coders in later commits. But the tool can also waste maintainers' time by sending "false positive" reports of bugs that don't exist, at a rate Sashiko's maintainers estimate is "well within [the] 20% range."

In discussing whether maintainers should be subjected to a flood of these kinds of automated, AI-powered bug report emails (true or false), one poster cited the Software Freedom Conservancy's recent statement that the open source community "should support, not just tolerate, those who outright reject LLM-gen-AI systems" and that "every FOSS contributor deserves self-determination regarding LLM-gen-AI." In the face of that statement, Torvalds said that he rejects those who demand that their open source projects not accept any LLM-generated code or revisions. "We're not forcing anybody to use [LLM tools], but I will very loudly ignore people who try to argue against other people from using it," Torvalds said.

Torvalds said his position on this is a pragmatic one that's "based on technical merit. Not fear of new tools." And when it comes to utility, Torvalds said that "AI is a tool, just like other tools we use. And it's clearly a useful one. It may not have been that 'clearly' even just a year ago, but it's no longer in question today. Anybody who doubts that clearly hasn't actually used it." [...] While Torvalds acknowledged that "AI isn't perfect," he urged detractors to compare the output of these tools to the performance of human code maintainers. "Anybody who points to the problems at AI had better be looking in the mirror and pointing at themselves at the same time," Torvalds wrote. "Because it's not like natural intelligence is always all that great either."

Android

OnePlus Will Continue Software Updates After US and Europe Exit (9to5google.com) 15

OnePlus has confirmed that it will exit the North American and European markets, consolidating its operations under parent company Oppo. Existing customers will continue to receive "software updates, security patches, and applicable support," but OxygenOS will be replaced by Oppo's ColorOS. 9to5Google reports: As a part of its shutdown in global regions, OnePlus has confirmed that its flavor of Android, OxygenOS, is going away. Instead, all active OnePlus devices will be moving over to Oppo's ColorOS starting with their Android 17 updates. This includes in India, where OnePlus is adamant it will continue operations -- reliable reporting disagrees.

OnePlus explains: "As part of an operational adjustment to our software strategy, following the official release of ColorOS 17, users globally with existing OnePlus devices that fall within the eligible upgrade scope will have the option to voluntarily update to the latest ColorOS. This enables us to streamline software development, accelerate update delivery, improve software quality, and make better use of our shared engineering and R&D capabilities."

[...] OnePlus will continue "maintenance support" for OxygenOS versions on older models not included in the Android 17 update scope, but newer devices will likely need to make the switch to ColorOS for all forms of continued support. OnePlus does explain that rollback versions to OxygenOS will be available for those who prefer the prior experience: "OnePlus devices will be able to choose whether to update to the latest ColorOS system. Older models that are not included in the update scope will also continue to receive version maintenance support. If users update to ColorOS, they will be able to roll back to OxygenOS. The specific rollback versions available will be subject to future official announcements."

Android

Google and Epic Cancel Settlement; Third-Party App Stores Coming To Google Play (arstechnica.com) 41

An anonymous reader quotes a report from Ars Technica: Big changes are coming to Android apps, but they're not the changes Google wanted. The settlement between Google and Epic that aimed to put to rest the companies' long-running antitrust battle is being withdrawn, and that means third-party app stores are coming to the Play Store. Google has confirmed that it will begin distributing rival app stores next week, setting the stage for competing platforms to take a bite out of Google's Android revenue stream. [...] Google and Epic were set to return to court on July 16 to argue in favor of the settlement. However, the writing may have been on the wall. In a recent expert analysis provided to the court, MIT economics professor Nancy Rose noted that the settlement was "unlikely to enable Google Play's potential competitors to overcome their long-standing network-effect disadvantage in a timely manner."

With settlement approval looking increasingly unlikely, Epic and Google agreed this week to call the whole thing off. Here's how Google Trust and Reputation Communications Lead Dan Jackson explains the company's decision: "We've agreed with Epic to withdraw our motion to modify the US Court's injunction rather than prolonging this process which creates uncertainty for the ecosystem. This allows us to focus on executing our recently announced global business model evolution to deliver greater app store choice, lower prices, and more opportunities for developers and users. We remain committed to maintaining Android's industry-leading security and fostering a competitive ecosystem where every app store and developer has the freedom to compete. In parallel, we continue to comply with the US Court's injunction."

In a brief filing (PDF), Google's legal team informs the court that Google is prepared to begin distributing third-party app stores in Google Play on July 22. Under the terms of Judge Donato's original injunction, these stores will have access to the full catalog of Google Play apps by default. Developers will have the option to opt out of distribution in these stores, and Google has a support page explaining how to do so. Google also has documentation on how app stores can get access to the Google Play catalog. It won't be mirroring those apps in any shady storefront that asks. The court has allowed Google to charge reasonable fees to cover its security and compliance review of third-party stores, which will be $5,000 per year.

Google will also require approved stores to block malware, respect intellectual property, and include mechanisms to update and uninstall apps. App stores can be removed from the program if more than 1 percent of attempted app installs appear to be malware or unwanted software. It's unclear if there will be separate, possibly more stringent requirements for storefront distribution in the Play Store. However, Google is prohibited from unreasonably blocking third-party store clients uploaded to Google Play. The changes Google has announced under the Epic agreement will proceed for now. That means Registered App Stores will happen globally, but they will probably only appear in the Play Store for US users. Google hasn't specified if there will be any differences in the features available to the stores downloaded from Play versus registered stores.

Windows

Microsoft Patches a Record 570 Security Flaws (krebsonsecurity.com) 77

An anonymous reader quotes a report from Krebs on Security: Microsoft today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence. Nearly 60 of the bugs quashed in July's Patch Tuesday earned a "critical" severity rating, meaning miscreants or malware could use them to seize remote control over a Windows device with little or no help from the user. Microsoft also addressed three zero-day flaws, including two that are already being exploited in the wild.

Two of the zero-day weaknesses allow an attacker to elevate their user rights on a Windows system, as do approximately 250 other elevation of privilege flaws fixed this month; they include CVE-2026-56155 - an Active Directory Federation Services bug -- and CVE-2026-56164, a Microsoft Sharepoint vulnerability. CVE-2026-50661 is a security feature bypass in Windows BitLocker that could allow attackers to gain access to encrypted data if they have physical access to the device. Microsoft said this bug has been detailed publicly, but that it is not aware of any active exploitation.

In a blog post on July 9, Microsoft Executive Vice President Pavan Davuluri wrote that Windows users will notice "a higher volume of security updates included in each security release" as a result of AI aiding in the discovery of vulnerabilities. "The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code, with new mechanisms that can accelerate both discovery and analysis," Davuluri wrote.

IBM

IBM Stock Collapses After a Grave Warning About AI (fastcompany.com) 62

IBM shares plunged after the company warned that Q2 revenue and earnings would miss expectations, blaming customers' sudden shift in spending toward AI hardware instead of software services. However, CEO Arvind Krishna did not place all the blame on IBM's customers. The CEO also said it "faltered" by failing to "anticipate the magnitude of the capex reprioritization."

"These conditions require our teams to execute perfectly, and this quarter we faltered. We did not adapt and move quickly enough, and numerous large deals failed to close on the timelines we expected, driving the majority of our shortfall." Fast Company reports: In the preliminary report, IBM said that for its second quarter of fiscal 2026, it expects revenue of $17.2 billion, which is up 1%. It also said it expects a Non-GAAP Diluted Earnings Per Share (EPS) of $2.93, up 5%. However, as noted by CNBC, these preliminary results are below what analysts were expecting, which was $17.86 billion in revenue, and an EPS of $3.01, according to FactSet data.
The Internet

Cloudflare Precursor Watches Your Mouse and Keyboard To Decide If You Are Human (nerds.xyz) 87

BrianFagioli writes: Cloudflare has launched Precursor, a new behavioral bot detection system that monitors mouse movement, typing cadence, scrolling, clipboard activity, page visibility, and other signals across an entire browsing session. The system is designed to catch advanced bots that can run JavaScript, use real browsers, and pass traditional CAPTCHA challenges. Cloudflare says Precursor does not record actual keystrokes and instead studies timing and rhythm. The company also says the data is not tied to user identities or persistent profiles. Even so, software that watches how people move and type throughout a visit raises privacy concerns, especially as Cloudflare claims bots now generate roughly 57 percent of all Internet requests.
AI

'Forget Coders. The Real AI Threat Is In the Back Office' (thestar.com.my) 79

Which jobs are most threatened by AI? "Programmers, software engineers and other tech industry employees," goes one common answer.

"But many economists are more concerned about a different, larger group of white-collar workers," reports the New York Times: customer service reps, bookkeepers, payroll clerks and HR specialists, "who fly under the radar but collectively account for tens of millions of jobs..." They are spread across the country and throughout the economy, working in every industry, in big cities and small towns, at major corporations and mom-and-pop businesses... These jobs typically offer a middle-class salary or a pathway to achieving one — much as manufacturing jobs did for men before decades of globalisation and automation wiped many of them away... For now, such an outcome is a fear, not a forecast. Despite high-profile layoffs in tech and finance, there is little firm evidence that AI has hurt the labour market as a whole.

Economists have become increasingly convinced that disruptions are likely, but they say it is too early to know where or how widespread they will be. They remain broadly sceptical of claims that the technology will lead to mass unemployment in the near future. Some AI industry leaders have walked back such predictions in recent weeks. But given the extraordinary pace at which companies are adopting AI — and at which the technology is improving — economists say policymakers need to consider the potential effects on the labour market. And they say they are concerned that the public debate has focused too much on software engineers and a relative handful of other high-status careers — lawyers, consultants, economists — rather than the workers who could be most vulnerable...

Economists at Northwestern University recently recalculated measures of AI exposure based on the makeup of the total workforce, not just the people using the technology. Administrative and front-line roles, such as customer service representatives, rose to the top of the list. "The most affected jobs are secretaries, are routine clerks," said Michelle Yin, one of the working paper's authors. "They're not computer scientists or data scientists at all."

The article also includes this counterpoint from an economist at the University of Illinois who has studied earlier waves of white-collar automation: that like other disruptive technologies, AI likely will also create new jobs. So the possibility exists AI will make workers more productive and allow them to earn more. "I would be cautious about just focusing on what are we losing as opposed to what are we going to gain on the other side."
Microsoft

Id Co-founders Carmack and Romero Respond to Microsoft's Layoffs (ign.com) 56

"I have been trying to find something meaningful to say about the Id Software layoffs," John Carmack posted Thursday to his 2.8 million followers on X.com: My "Microsoft will probably be a good steward of the brand" statement isn't aging well, and this is certainly going to dampen the mood of the founder reunion at QuakeCon next month.

I'm saddened, but I can't muster anger or outrage over it. I don't have access to the books, but I suspect that Id Software was a marginal business from Microsoft's perspective. I believe the reports that Minecraft revenues have been carrying several other studios.

To continue being produced long term, games need to succeed, not just be beloved. Games are competing with every other option for spending your leisure time and money, and the competition is brutal. You can't rule out the possibility that executives are idiots, but that shouldn't be your default belief. I don't think there is any obvious path that would have doubled the revenue from Id games.

Could they have gotten more with a different pricing strategy? Could they have created more things for fans to buy? Could they have cost effectively marketed in a way that reached more players that would have loved and bought the games? Could they have changed the game designs and broadened the appeal to more players without alienating existing ones? Could they have produced the games at a lower cost, faster or cheaper? I really don't know.

The game isn't over yet, and I hope the studio rallies through.

Id Software co-founder John Romero also shared his thoughts on X.com: I'm so sorry for everyone at id Software affected by these layoffs. I know what it feels like to leave id while id goes on. It's a strange and painful thing to step away from a place that holds so much of your work, friendships and history.

The people at id have done a great job moving that legacy forward. DOOM, Quake, and Wolfenstein are not easy names to carry on, especially in today's industry. The last few games showed real care, skill and respect for what those worlds mean to people.

Romero also expressed his hope for "digital preservation" of Id's ongoing history (including code and assets). "I'm thinking of everyone at id today, and everyone else affected by yesterday's layoffs. Romero Games was there a year ago. I know how devastating it is, and my heart's with all of you.

"Four Xbox studios are already out the door," noted IGN, but shared some thoughts about the future: Some have expressed concern that id Software would be unable to lead development on any new games in its current state, and that it might be relegated to support studio status. But in a new statement [posted to id Software's page on X.com] id Software said it was now at the staffing level it was back when it made the much-loved 2016 Doom reboot — and insisted it was still capable of making "great games."

"While our studio was impacted, those changes were spread across teams. We still have the crew we need to build the games and tech we're known for... We're going to keep building the great games and tech that have defined us for the past 35 years, and we're looking forward to seeing you at QuakeCon this August."

GNU is Not Unix

How the FSF Sysadmins are Blocking Botnets with reaction (fsf.org) 25

For nearly two years the Free Software Foundation has been fighting web crawlers (including many aggressively scraping training data for AI models). A botnet controlling about five million IPs hit one system for six months in 2025. Their systems administrator wrote this week that they view these as distributed denial-of-service attacks.

How are they fighting back? We noticed patterns in the scrapers that were abnormal, which gave us material for writing regular expressions. Searching for the regular expression then gave us a large lists of IP addresses. Looking up the origin of those IP addresses revealed that some of the crawlers were using botnets of residential IP addresses to scrape faster and avoid detection. We looked for what kinds of botnets might be generating the kind of traffic that we were seeing, and one that we suspected was called the "Vo1d" botnet, comprised of smart TVs running some sort of compromised app... We got confirmation that at least some of the botnet traffic hitting GNU Savannah was originating through the Vo1d/Popa botnet.

We placed our regular expressions in fail2ban, and found that we were hitting the maximum rules that could be added to UFW firewall rules on our systems which showed degradation around 65,000 rules... We learned about ipset and configured fail2ban to add IP addresses that it found to IP sets. Using ipset, we kept building larger IP sets and did not find instability with as large as five million rules...

We eventually found a promising project on Framasoft's forge Framagit called reaction written by ppom... After we ran into scaling issues with our initial implementation, we developed a much faster implementation where the reaction shutdown process would export the IP sets to disk and the reaction startup process would restore the IP sets. This allowed us to have nearly instantaneous restarts of the service to apply new rules. We published both of our configurations upstream to reaction's wiki so that everyone can benefit from it. reaction's getting started documentation now leads to the method that we proposed...

Many sysadmins know about fail2ban, but not enough people know about reaction. I am very grateful to ppom for the help they have provided and for the tremendous project they have released to the world with reaction. We have implemented other defenses as well, but reaction is doing the majority of the automated work keeping our sites online.

China

China's AI Companies May Be 'Distilling' America's AI Models (yahoo.com) 51

In March, Anthropic's Claude "quietly deployed software to spy on China-based customers," reports the Washington Post — apparently to unmask Chinese rivals "suspected of hijacking its technology to make their own AI tools smarter." Last week Anthropic removed the spyware "after a software developer revealed its existence and privacy advocates criticized Anthropic, saying it had surveilled its own users." Anthropic's tracking code was designed in part to catch Chinese firms "distilling" its AI models, a technique that involves pressing a large, expensive AI system to serve as a tutor to a smaller, cheaper one. Asking the larger system huge numbers of questions — hundreds of thousands or more — generates responses that can be used to upgrade the power of the smaller one on the cheap. Distillation isn't illegal, and it has been used for years in the AI industry. But distillation without permission is against AI companies' rules, and, used effectively, is giving Chinese AI companies a major leg up, American AI companies say... Anthropic and ChatGPT-maker OpenAI have both accused Chinese AI companies of using this technique to build copycat AI models of their own.

In a May blog post, Anthropic said that Chinese companies' use of distillation, along with evading U.S. export controls on high-end computer chips, has allowed them to "trail closely" behind U.S. models. But if these techniques can be blocked, it might be possible for the United States to "lock in a 12-24 month lead" on Chinese capabilities, the company said... This month, Anthropic said in a letter to U.S. senators that was obtained by The Post that it uncovered a campaign in which Chinese tech giant Alibaba's Qwen AI team used roughly 25,000 fraudulent accounts to generate more than 28.8 million exchanges with Claude to improve its own technology. In February, Anthropic made similar accusations against the Chinese firms Deepseek, Moonshot and MiniMax and said the campaigns were "growing in intensity and sophistication...." Anthropic and OpenAI have appealed to the U.S. government, arguing that distillation amounts to intellectual property theft that harms the U.S. in the geopolitical AI contest....

That Chinese AI labs are using U.S. models to improve their own technology appears beyond dispute. In a February 2025 study, researchers from China's Peking University and the state-funded Chinese Academy of Sciences developed methods to detect signs of distillation in leading large language models. They concluded that, with the exception of ByteDance's Doubao, most domestic models they tested showed substantial evidence of distillation, mostly drawing from U.S. models... In one set of intensive tests, a Qwen model misidentified itself as Claude nearly a third of the time, the Chinese researchers found.

U.S. firms have also used distillation to piggyback on AI systems made by others. In 2024, OpenAI released a tool to make it easier for customers to distill its own models and produce data sets for AI training. SpaceX founder Elon Musk said in court testimony in May that his AI company xAI used distillation to train its models and that the technique is common throughout the industry.

The article also notes that Anthropic "said it has banned nearly 700,000 accounts that were using Claude in China." But the article includes this quote from Kyle Chan, a fellow at the Washington-based Brookings Institution's China Center. "Anthropic's framing is that this is a geopolitical contest for basically the future of the world and freedom and democracy. It's that this is not just undercutting the U.S. commercially, but undercutting American strategic advantage in the most powerful technology we know today."

Slashdot Top Deals