Cloudflare Announces Open-Source Cloudflare OS As AI ‘Operating System’
Cloudflare has open-sourced Cloudflare OS, an Apache 2.0-licensed platform that lets organizations build AI agents, apps, and workflows using curated company data and tools within isolated, governed environments. Despite the name, it is not a traditional operating system but a framework for securely managing organizational AI workloads … ⌘ Read more
Linux’s Staging Area To Now Reject LLM-Generated Patches, Except For Real Security Fixes
While Linux’s second-in-command Greg Kroah-Hartman does use AI / LLMs himself to success in the Linux kernel, given the “onslaught” of kernel patches produced by large language models and the intent on the Linux kernel’s staging area being an area for newcomers to get involved, moving forward he’s now rejecting AI/LLM-generated staging patches. But there is one exception and that is for genuinely valid security fixes… ⌘ Read more
Samsung Bans Smart TV Apps That Share Users’ Internet Connections
An anonymous reader quotes a report from TechCrunch: Several popular Samsung smart TV apps contain code that share the owner’s internet connection with strangers, potentially putting millions of Samsung smart TVs at risk of hijacking, according to new security research published on Monday. Some of these apps claim to have been installed … ⌘ Read more
Massive Debian 13 Linux Kernel Security Update Patches 68 Vulnerabilities
Slashdot reader prisoninmate shares this report from 9to5Linux:
Coming ten days after the previous Linux kernel security update, which only fixed 12 vulnerabilities that may lead to a privilege escalation, denial of service, or information leaks, the new Debian 13 Linux kernel security update is a massive one, and it patches n … ⌘ Read more
New GitHub, PyPI Policies Hope to Boost Supply Chain Security
“GitHub and the Python Package Index (PyPI) have introduced new policies meant to boost supply chain security,” reports SecurityWeek, “by preventing the fast propagation of poisoned package versions and the poisoning of old and long-stable releases.”
To prevent the fast delivery of malicious code through the immediate fetching of brand-new releas … ⌘ Read more
Prominent Arch Linux Developer Resigns After 10 Year Run
Arch Linux developer, security team member, AUR maintainer, and package maintainer Morten Linderud “Foxboron” announced today he is resigning from the project… ⌘ Read more
Chrome Is Using AI To Fix Hundreds of Bugs, Eliminate Full Browser Restarts
Google says AI-assisted workflows helped Chrome fix 1,072 security bugs across versions 149 and 150, more than the previous 23 releases combined. The company is also testing twice-weekly security updates and “dynamic patching,” which could apply most fixes without requiring users to restart the entire browser. “By leveraging … ⌘ Read more
Netflix Sued For Losing ‘Master Copy’ of Unreleased Nicolas Cage Movie
A production company and filmmaker are suing Netflix for $105 million, alleging the streamer lost a stolen drive containing an unencrypted master copy of the unreleased Nicolas Cage film Fortitude, which they claim damage its exclusivity and market value. Netflix denied responsibility for the lost film but said it takes content security … ⌘ Read more
A Fundamental Flaw Leaves LLMs Strikingly Vulnerable To Attack
joshuark quotes a report from MIT Technology Review: It is impossible to make large language models fully secure against hacks because of a fundamental flaw in how they work, a team of researchers argue in a paper presented at the International Conference on Machine Learning, a top AI conference, this month. The claim has huge implications for the safety … ⌘ Read more
OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
An anonymous reader quotes a report from Wired: OpenAI said Tuesday that the rogue AI agent that breached Hugging Face’s platform also hacked multiple third-party accounts and services as part of the attack. It’s now clear that the unprecedented security incident, which arose during an internal test of OpenAI’s latest AI models, was more extensive than the comp … ⌘ Read more
Trump Administration Bans New Chinese Humanoid Robots
The Trump administration has banned newly authorized foreign-made humanoid and four-legged robots, along with power inverters, citing “unacceptable risks” to the country’s national security. FCC chairman Brendan Carr said the agency was doing its part “to secure America’s critical supply chains.” The BBC reports: The FCC has added the items to its Covered List – … ⌘ Read more
Bwahahaha, these security folks have a great sense of humor! :-D Got a phishing test e-mail disguised as an overdue anti-phishing training e-mail: 
We receive these test phishing e-mails every now and then at work. When you follow the links and log in at the fake login, you probably get assigned another (real) training.
When I got this e-mail, I immediately thought of such a test. Since I actually do have some stupid training deadlines coming up soon, I wasn’t 100% sure, but still doubted that this was one of them. To make the timing even better, in the team meeting last week, our bosses reminded us to complete outstanding trainings before the deadlines. Ideally well in advance. Notifications about deadlines coming closer are sometimes not only sent to the individuals but also to the bosses and their bosses. And then things can get out of hands when somebody doesn’t read the e-mails properly and mistakes them for deadline exceeded reports.
Anyway, the URL also looked kinda legit. It really doesn’t help a single bit that domain names change all the fucking time. So, still with the test program in mind, I thought, I just give it a quick shot out of curiosity. Since I just had logged in before, the empty SSO username field was totally obvious then. Looking at the e-mail headers confirmed that this was indeed one of security’s field checks. :-)
Nvidia, Tech Giants Launch AI Safety Initiative
wiredmikey shares a report from SecurityWeek: Nvidia and a large group of technology, cybersecurity, and enterprise software companies have launched new initiative aimed at developing and sharing open source tools, models, and techniques for securing AI systems and agents. The new Open Secure AI Alliance aims to give defenders more open tools for testing, auditing and protecting AI m … ⌘ Read more
Big Tech Accused of Stonewalling European Social Media Researchers
European misinformation researchers say TikTok, X, and Meta are obstructing access to platform data required under the EU’s Digital Services Act through rejections, restrictive quotas, costly APIs, and burdensome security demands. Although regulators have fined X and pushed platforms to improve access, researchers remain skeptical that the ch … ⌘ Read more
NVIDIA, Red Hat, Cloudflare, The Linux Foundation and more launch the “Open Secure AI Alliance”
Some big names are coming together to form the “Open Secure AI Alliance”, with a plan to “share open tools that promote responsible use of and trust in AI”.
Read the full article on [GamingOnLinux](https://www.gamingonlinux.com/2026/07/nvidia-red-hat-clo … ⌘ Read more
NVIDIA & Others Form The Open Secure AI Alliance
NVIDIA and more than two dozen other companies have started the Open Secure AI Alliance for helping to keep open-source AI models secure. The other founding members range from Microsoft to Adobe, IBM, Red Hat, SpaceX, OpenClaw, Palantir, and others… ⌘ Read more
The “New Normal” Of Audio Quirks Submitted For Linux 7.2-rc5
Linux sound subsystem maintainer Takashi Iwai of SUSE sent out this week’s batch of sound fixes that he describes as “A collection of fixes that have been accumulated recently. The amount is still “new normal”, but all small fixes. Mostly hardware-specific quirks, but including a few core fixes, too.” The “new normal” has been a common phrase recently to reflect the increased tempo of patches as well as security/bug disclosures all due to the increased … ⌘ Read more
Three New Ubuntu Snap Vulnerabilities Made Public - One Dates Back To Ubuntu 16.04 LTS
Canonical today disclosed three new Snap security vulnerabilities affecting snapd. Two are rated high impact vulnerabilities while the third is considered medium but covers all Ubuntu releases of the past decade going back to Ubuntu 16.04 LTS… ⌘ Read more
Just for security as required by law.
LOL 🤣 Was this someone’s idea of a joke? 🤔
Are Wars Blurring Lines Between Corporate and National Security?
Subsea cables. Ukrainian power stations. Russian oil refineries. Even airports, water-desalination plants and Amazon data centers.
They’ve all become targets in wartime, notes the Wall Street Journal, and around the world now arguments “are already brewing between companies and governments over new regulations and potential costs.”
In Germany, po … ⌘ Read more
Decades-Old Bash Tricks Expose AI Coding Agents To Supply Chain Attacks
Slashdot reader wiredmikey writes: AI security researchers have uncovered a structural security flaw dubbed GuardFall that allows decades-old Bash shell tricks to bypass safeguards in most open source AI coding agents. By exploiting shell behaviors such as quote removal and variable expansion, attackers can hide malicious commands … ⌘ Read more
@GabesArcade@gabesarcade.com by asking me nicely 🤣 Which you just did! If you either provide me a desired username and password and secure medium to give this to you I can do that easily, or alternative a desired username and email address (never stored, only hashed), after which you can “Reset password”.
Fedora 45 Considering x86_64 Shadow Stack Usage By Default
A change proposal under consideration for Fedora Linux 45 would enable x86_64 Shadow Stack usage by default in the name of better security on modern Intel and AMD systems… ⌘ Read more
KDE Plasma Affected By Arbitrary Code Execution To Break Sandboxes With “Open New Window”
A security disclosure has been made public today for a yet-to-be-patched arbitrary code execution vulnerability with the KDE Plasma desktop… ⌘ Read more
China’s AI Matches Anthropic in Cybersecurity, Causing Worry Over US Restrictions
Chinese AI systems “have matched the performance of Anthropic’s powerful model Mythos in some cybersecurity scenarios,” reports the Wall Street Journal.
They call it “a development poised to reset the global tech race and pressure the White House in its overhaul of U.S. AI policy.”
Security researchers said that a new … ⌘ Read more
US Government Allows Anthropic Limited Release of ‘Mythos’ AI Model, Saying ‘Appropriate Safeguards are in Place”
“The US government has allowed Anthropic to release its powerful Mythos AI model to select companies and organizations,” reports CNN, “revising license requirements after ordering an export block earlier this month in the wake of national security fears.” … ⌘ Read more
Microsoft Adds Another Year To Windows 10 Extended Update Program
Microsoft has quietly extended free Windows 10 security updates for consumers by another year, pushing the Extended Security Updates (ESU) program’s end date from October 12, 2026, to October 12, 2027. “The ESU support page was updated with that date, and Microsoft’s blog post on the program has a new editor’s note confirming the change,” repor … ⌘ Read more
Polestar Banned From Selling Cars In US From Model Year 2027
Longtime Slashdot reader schwit1 shares a report from autoevolution: The U.S. Department of Commerce’s Bureau of Industry and Security denied Polestar an authorization under the Connected Vehicle Rule. Polestar will continue to sell its existing inventory of Polestar 3 and 4 crossovers in the United States and will continue to offer support to customers … ⌘ Read more
Trump Administration Asks OpenAI To Stagger Release of New Model
The Trump administration has reportedly asked OpenAI to stagger the release of GPT-5.6 over security concerns. The model will initially be offered to a small group of partners, with the government “approving access customer by customer during this preview period,” reports The Information. The request came from conversations with the Office of the N … ⌘ Read more
Linux Foundation Launches Akrites To Coordinate AI-Driven Open Source Security
BrianFagioli writes: The Linux Foundation has announced Akrites, a new initiative to coordinate vulnerability disclosure and remediation for critical open source software as AI dramatically speeds up vulnerability discovery. Founding members include AWS, Google, Microsoft, OpenAI, Red Hat, NVIDIA, IBM, Cisco, JPMorgan … ⌘ Read more
29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests
A 29-year-old bug in the Squid web proxy, dubbed Squidbleed and tracked as CVE-2026-47729, can let an authorized proxy user retrieve fragments of another user’s cleartext HTTP requests, including credentials and session tokens. The security researcher who reported the flaw credited Anthropic’s Claude Mythos Preview for the discovery … ⌘ Read more
Fwupd 2.0.21 Brings Fixes For More Than 250 Potential Security Issues Found Via AI
While the Fwupd 2.1 series is the latest stable channel for this open-source firmware updating solution, Fwupd 2.0.21 was released today to backport fixes for more than 250 potential security issues recently uncovered in the codebase… ⌘ Read more
US Bill Would Mandate AI Chip Location Tracking to Thwart China and Other Adversaries
NBC News reports:
A group of companies that specialize in tracking international shipments of sensitive technologies is backing a Capitol Hill bill that would require America’s most powerful AI chips to incorporate stronger security mechanisms aimed at preventing the chips from reaching China and other adv … ⌘ Read more
The Rust Ecosystem Gets an AI Security Engineer in Residence
While the Rust Foundation has a Security Initiative to protect its ecosystem, “the threats have expanded,” they announced this week, “and so has the kind of help maintainers need.”
Much of this comes back to a single shift: Automated tooling (much of it now built on large language models) has gotten good enough to surface real vulnerabilities in o … ⌘ Read more
Microsoft Discovers Cryptocurrency Stealer That Spreads Through USB Drives and Uses Tor
Ars Technica’s senior security editor reports:
Microsoft says it has detected new self-propagating malware that spreads through USB drives in search of cryptocurrency credentials, which it then sends to attacker-controlled servers.
The company named the worm Crypto Clipper because it monitors the cont … ⌘ Read more
FSF Patches Two-Year-Old Vulnerability Found by AI Researchers in GNU Savannah Repository
The Free Software Foundation’s GNU Savannah hosts thousands of free software projects — both GNU and non-GNU projects, including Drupal.
But in early May, security researchers from Hacktron.AI reported vulnerabilities and demonstrated an exploit, according to a new statement Friday from the FSF:
… ⌘ Read more
Rolls-Royce Secures Deal To Build Small Nuclear Reactors For Sweden
Rolls-Royce SMR has secured a multibillion-pound agreement to build three small modular reactors on Sweden’s west coast, “marking a major step in the British engineering group’s ambition to become a leading supplier of the technology in Europe,” reports Euronews. From the report: Following a rigorous selection process that started in 20 … ⌘ Read more
Google Toldl Researchers ‘Nice Catch!’ Then Denied Bug Bounty For Flaw It Still Hasn’t Fixed
Security researcher Justin O’Leary says Google initially accepted his Config Connector privilege-escalation report as a high-priority, high-severity bug, then denied a bounty by declaring the behavior “working as intended.” “Google initially rated the bug high priority and high severity, with a re … ⌘ Read more
Microsoft Working To Patch ‘RoguePlanet’ Zero-Day
wiredmikey shares a report from SecurityWeek: Microsoft on Wednesday published an advisory acknowledging the public disclosure of a vulnerability in Defender that could lead to privilege escalation. The security defect, tracked as CVE-2026-50656 (CVSS score of 7.8), was dropped last week by security researcher Nightmare Eclipse (also known as Chaotic Eclipse). “We are working to … ⌘ Read more
Anthropic Employees Accuse Trump Administration of Targeting Them
Anthropic employees say they remain confused and increasingly convinced that the Trump administration is singling out the company after officials gave it less than 90 minutes to disable Fable 5 and Mythos 5 over alleged national security concerns. Cybersecurity experts, however, argue that the cited behavior of helping to identify vulnerabilitie … ⌘ Read more
Stop Killing Games Fails To Secure EU Law Despite 1.3 Million Signatures
The European Commission has declined (PDF) to propose a law requiring publishers to keep discontinued video games playable, despite the Stop Killing Games initiative collecting nearly 1.3 million verified signatures. Instead, it plans to develop a voluntary industry code covering end-of-life transparency and preservation. Dextero … ⌘ Read more
France To Stop Certifying Products Without Quantum-Safe Encryption
Starting in 2027, France’s cybersecurity agency ANSSI will stop certifying security products that lack quantum-resistant encryption, effectively forcing government agencies and critical infrastructure operators to phase out older cryptographic systems. Reuters reports: Samih Souissi, ANSSI’s chief of staff, said at the France Quantum conference … ⌘ Read more
The US Government’s Anthropic Models Ban Was Never About an AI Jailbreak
TechCrunch’s Zack Whittaker argues that the U.S. government’s abrupt export-control order forcing Anthropic to pull its Fable 5 and Mythos 5 models offline was “never about an AI jailbreak” threat. Instead, it was driven more by “personality differences” between the AI company and Trump administration. Security experts say the repor … ⌘ Read more
FBI Issues Urgent Kali365 Security Warning For Teams, Outlook, OneDrive Users
alternative_right shares a report from The Hill: The FBI released an urgent security warning to the public about a fast-acting scam targeting Microsoft 365 users on Teams, Outlook and OneDrive. The agency warned that the hacking platform Kali365 seeks out OAuth device codes, allowing scammers to sneak past multi-factor auth … ⌘ Read more
Users Cry Foul After AMD Stripped Memory Crypto From Its Consumer CPUs
An anonymous reader quotes a report from Ars Technica: A decade ago, AMD added a protection to its high-end CPUs to protect them against cold boot attacks and other types of physical exploits that siphon sensitive data out of the connected memory chips. Short for Transparent Secure Memory Encryption, TSME encrypts the entire conten … ⌘ Read more
Arch Linux Malware Incident: Malicious Commits Found in 1,579 Packages
More than 1,500 user-contributed packages in the Arch Linux User Repository “AUR” were infected with malware, reports Phoronix:
The last message in the thread over this security incident is noting that Arch Linux developers have deleted all the malicious commits they are aware of. Cited was this list that puts the number of malware-af … ⌘ Read more
The FCC Wants to Kill Burner Phones
Plus: AI bug hunting fuels Microsoft’s biggest-ever Patch Tuesday, ShinyHunters ransomware gang exploits an Oracle zero-day, and more. ⌘ Read more
Anthropic ‘Suspends’ All Mythos and Fable Access After US Order Limiting Foreign Access
“Anthropic said on Friday it will ‘abruptly disable’ its most advanced AI models for all users,”
reports Reuters, “after the U.S. government ordered it to suspend access to the models for foreign nationals, citing national security concerns. The company received the export control directive to suspend a … ⌘ Read more
Microsoft Surface Flaw Allowed Unprotected Devices To Be Bricked By a Single Packet
Longtime Slashdot reader Dotnaught shares a report from The Register: For the past 90 days, Microsoft has been quietly patching a firmware flaw in Surface devices that allowed the hardware to be bricked with a single packet, though only for those who have disabled Secure Core and Secure Boot. And the company’s … ⌘ Read more
Stalled Ukraine security pact could leave Australia ‘fighting with one hand behind its back’
Australia’s ability to tap into Ukraine’s expertise in drones and other advanced technologies is being hampered by delays in striking a security pact. ⌘ Read more