Alterslash picks up to the best 5 comments from each of the day’s Slashdot stories, and presents them on a single page for easy reading.
Alexa Can’t Control the AUX Input On Amazon Echo Speakers Anymore
Amazon has removed Alexa voice control for the 3.5mm aux input on several older Echo speakers, meaning users can no longer ask Alexa to play or pause audio coming through the wired connection. It’s unclear why the feature was removed. The Verge reports:
Ars Technica points to this Reddit poster claiming they received a message from Amazon and says an unnamed spokesperson confirmed the change. When contacted by The Verge, Amazon did not provide an on-the-record statement. The message does not include any explanation for why the feature was removed. It also doesn’t mention any changes to audio output functionality like connecting an external speaker to an Echo Dot, and it appears that control of the port from within the app’s settings menu still works.
Asos Confirms Hackers Sent ‘Unauthorized’ Notification to App Users
ASOS says hackers gained unauthorized access to third-party platforms it uses and sent an “ASOS HACKED” push notification directly to customers, apparently as part of an extortion attempt. The clothing and beauty store says some basic personal information may have been accessed but does not believe payment-card data or passwords were affected. The BBC reports:
In an email to customers on Tuesday night, the company apologized and urged customers not to engage with the notification. And it said the website and app are “operating as usual” promising customers they can “shop with confidence” while it investigates the incident. The company has not as of yet informed the UK’s data watchdog, the Information Commission’s Office (ICO), about any breach.
Exactly how many Asos customers received the notification on Tuesday remains unclear, but Google’s Play store says the ASOS app has been downloaded to android devices more than 10 million times. The British retailer has a substantial global footprint — serving around 17 million customers each year across more than 150 markets. Some Asos app users in Australia, France, Sweden and the Republic of Ireland had also received the notification, according to local reports on Tuesday.
[…] Users of the Asos app appeared to have received the alarming notification at around 10:00 BST on Tuesday. Headlined “ASOS HACKED” and addressed to the company’s data protection officer and IT teams, it said: “We have fully compromised the Snowflake instance.” “Engage with us, or we will leak it,” it added, before linking to a Telegram channel. The message left many ASOS customers confused. […] Meanwhile Snowflake — whose tools are used by dozens of firms to collect, analyze and store data — told the BBC its investigation was ongoing, but it had so far found “no compromise” of its platform.
IBM and Red Hat Find More Than 400 New Vulnerabilities In Popular Java Code
IBM and Red Hat say their AI-powered Lightwell initiative has identified and helped remediate more than 400 previously unknown vulnerabilities across widely used Java libraries. Phoronix reports:
They announced this feat today as part of their promoting Lightwell Clearinghouse to GA, which is an enterprise service for their customers to submit open-source software dependencies for priority review and remediation.
From today’s announcement: “The milestone addresses a growing business risk. As autonomous AI agents become capable of combining several lower-risk software weaknesses into a more serious attack, companies need to do more than identify vulnerabilities. They need a practical way to develop, test and deploy fixes in the software that supports critical applications.”
Licensing Costs Driving 90% of VMware Users To Explore Options, Survey Finds
An anonymous reader quotes a report from Ars Technica:
VMware customers face multiple obstacles as they rethink their virtualization strategy to reduce dependence on VMware. Today, Rimini Street published its “2026 IT Virtualization Survey — What’s Next for VMware Users.” The survey examined 300 organizations worldwide that use VMware. Notably, Rimini sells third-party support for VMware and other software, including Oracle and SAP. That means there’s an incentive for Rimini to portray VMware users as experiencing obstacles. However, the survey was also conducted by a third-party research company, Unisphere Research, and the results align with other recent reports about VMware customers. For example, 90 percent of participants in Rimini’s survey said they’re exploring VMware alternatives due to VMware’s higher licensing costs, while 54 percent pointed to Broadcom killing support for perpetual license holders.
Since Broadcom took over VMware, customers have said that their VMware costs increased by as much as 1,000 percent, with many more pointing to more modest price hikes of around 100 to 300 percent. In Rimini’s survey, 73 percent of participants pointed to cost savings as a top priority in their virtualization roadmap decisions. In today’s announcement, Rimini pointed to “significant barriers to progress” for organizations exploring virtualization options, with the most cited barriers being operational complexity (named by 40 percent of respondents), multi-vendor management challenges (38 percent), securing the increased attack surface (37 percent), and team skills requirements (37 percent). “These findings suggest that while organizations are actively pursuing change, they are also looking for ways to reduce risk and avoid unnecessary disruption,” Rimini’s announcement said.
[…] Rimini reported that 60 percent of the organizations it surveyed are considering a multi-hypervisor strategy, which is indicative of “growing interest in more flexible, mixed environments that support both operational and financial goals.” “In addition, 47 percent are favoring a hybrid IT virtualization environment consisting of hypervisors and containers for ‘best of both worlds’ workload placement,” the announcement said. Rimini noted that 48 percent of respondents aren’t planning to move any of their assets to VMware’s hybrid cloud platform, Cloud Foundation.
Mistral Unveils New ‘Le Chonk’ AI Model It Says Rivals Best Open Systems From China
Mistral has unveiled Mistral Large 4, or “le Chonk,” a 1-trillion-parameter model that it says is the strongest open-weight AI model developed outside China by a wide margin. The model is entering preview for developers, cybersecurity teams and governments before a broader release later this month. CNBC reports:
ML4 was trained on 4,000 Nvidia Grace Blackwell GPUs over two months that were deployed in Mistral’s own data centers in Europe. When its core parameters are released, ML4 will rank among the top open-weight models globally on aggregate benchmark performance, Mistral said in a statement. The company added that ML4 was the strongest open-weight model developed outside China by a “substantial margin.” The new model still lags behind the frontier in areas such as coding.
“The model capabilities will further improve as we scale up our training capacity, following our Series D fundraise,” said Guillaume Lample, co-founder and chief scientist of Mistral. “Further, the cyber defense capabilities will enable enterprises and governments to defend themselves against threat actors that are jailbreaking closed models to perform cyber attacks,” he added.
Further reading: Mistral CEO Says US AI Safety Debate Masks Competitors’ ‘Negligence’
Researchers Are Tracking a Chinese AI ‘Agent Fleet’
Independent researchers say they’ve identified a large “fleet” of AI agents apparently running on Tencent infrastructure and making parallel queries against Alibaba’s Amap mapping service. TechCrunch reports:
Researchers, however, resisted the term “swarm,” noting that there seems to be little coordination between their different queries. "‘Agent fleet,’ not ‘swarm:'" one researcher wrote in the preliminary report, “many parallel agents on the same kind of task, with no sign of communication between them.” The agents were discovered by monitoring traffic to the domain-scanning service urlquery, a technique that previously revealed long-running activity by OpenAI agents. AI agents often use urlquery to load websites that they cannot access directly, leaving a record of their activities that can be valuable to researchers.
In this case, the record showed queries to Alibaba’s Amap service, seeking directions to different entrances of various public places, including a park, a zoo, and a hospital. The research is ongoing and so few details are available, but the behavior shows how persistent AI agent activity has become on the internet. In the wake of the Hugging Face incident, many researchers are actively monitoring for rogue agent activity on the internet. Much of that activity has been easy to find because agents tend to use the same techniques and make little effort to conceal themselves.
Cable Lobby To Sue Trump FCC Over Repeal of National TV Ownership Cap
An anonymous reader quotes a report from ArsTechnica:
Cable lobby groups notified the Federal Communications Commission that they will sue the agency to block its controversial repeal of the National Television Ownership Rule, which limits the number of broadcast TV stations a single company may own. The cable groups said that larger broadcast TV station groups will have leverage to demand higher retransmission fees from TV providers, resulting in “higher monthly TV bills for consumers.” They said the FCC repeal order “arbitrarily and capriciously ignores the harms that will surely follow from allowing broadcast station groups to exceed the National Cap.”
The cable lobby groups represent top providers Comcast, Charter, and various other cable operators. Top cable companies have also expanded through mergers. Charter completed a purchase of Cox in August after the FCC rejected protests by advocacy groups that said the cable deal “would create unchecked gatekeeper power over Internet distribution” and make it easier for the biggest cable companies to raise prices. […] The TV ownership rule prohibits any single broadcast station owner from reaching more than 39 percent of all TV households in the US. Congress directed the FCC to set the cap at 39 percent in 2004. On Friday, cable lobby groups submitted a petition asking the FCC to keep the TV ownership cap in place until litigation over the FCC’s authority to repeal the rule is over.
The cable groups’ filing said the FCC repeal of the TV ownership cap violates the 2004 action by US lawmakers. The decision by Congress to set the cap at a precise numerical threshold was unambiguous, the filing said. “Congress established the National Cap at 39 percent in the 2004 CAA [Consolidated Appropriations Act] in direct response to the FCC’s attempt to aggressively raise the Cap to 45 percent and made repeated references to the 39 percent Cap in the statute,” the petition said. The petition to the FCC is mainly a procedural step as the commission isn’t likely to stay its own order. The cable groups said they intend to sue the commission in a US appeals court once the FCC order is published in the Federal Register. After the lawsuit is filed, they can ask the court to issue a preliminary injunction that would keep the TV ownership cap in place pending the outcome of litigation.
[…] The cable groups’ petition said the FCC can’t change the cap because the 2004 law “references the 39 percent Cap as statutory, not regulatory.” A provision requiring divestiture of stations “specified that someone exceeding ‘the 39 percent national audience reach limitation in paragraph (1)(B)' of ‘section 202(c)' of '[t]he Telecommunications Act of 1996’ ‘shall have not more than 2 years to divest,’" the petition said. “Likewise, Congress singled out the Commission’s only mechanism for setting aside statutory requirements — the Commission’s forbearance authority under 47 U.S.C. 160 — and made clear that it ‘shall not apply to any person or entity that exceeds the 39 percent national audience reach limitation,’" the cable lobby petition said. The FCC order argued that the agency’s “ability to forbear from enforcement of its rules is distinct from its power to alter or eliminate those rules,” and that the FCC forbearance authority doesn’t apply to regulation of broadcasters.
OpenAI Is Adding Text Watermarking In ChatGPT and Codex
OpenAI is rolling out an invisible, machine-readable text watermark called textGrain to ChatGPT and Codex, “but only for users in the European Union at first,” reports The Verge. From the report:
OpenAI says its textGrain watermarking “matched or exceeded” other approaches like Google DeepMind’s SynthID for text, which is also the basis for the watermarking Anthropic announced in August. Like OpenAI, Anthropic made the move to meet the requirements of the EU’s AI Act; however, not everyone was happy to learn about the addition. OpenAI also included scores from AI benchmarks showing similar performance from watermarked and unwatermarked text. But it notes that textGrain “does not guarantee reliable detection,” and says text watermarks don’t verify accuracy, determine who owns the text, measure how much a human contributed, or prove human authorship.
Old Hearts Become Biologically Younger When Transplanted Into Younger People
alternative_right shares a report from ScienceAlert:
It might be reasonable to think that there’s an indelible link between the heart and the body it resides in — the processes that affect one inevitably affect the other. But a new preprint, uploaded to bioRxiv and yet to be peer-reviewed, suggests that this may only be true up to a point. Take the heart out of the body and put it in a new one, and something incredible happens. The transplanted heart begins to take on the biological age of its new owner. Older hearts transplanted into younger recipients appear to become biologically younger, while younger hearts placed in older bodies show signs of accelerated aging.
Texas City Demands $2 Million For Public Records On Flock Usage
An anonymous reader quotes a report from Ars Technica:
As bipartisan backlash against Flock grows, some cities are asking anti-surveillance advocates and media outlets to pay eye-popping fees — including charging tens of thousands or even millions — to get information about how police departments are using and potentially abusing AI-enabled camera systems that track every vehicle that passes them. On Monday, the Texas Tribune reported that city officials in a Fort Worth suburb, North Richland Hills, asked one group to pay $2.3 million before it would fulfill a public records request for Flock data. To reach that high fee, officials claimed that searching “about a terabyte worth of communications about errors, misuse, and effectiveness of the Flock system” would take approximately 14 years of labor at a rate of $15 per hour.
Phil Mynona, who filed the request using a pseudonym on behalf of his group, the Texas Privacy Coalition, told the Tribune that the fee seemed “ludicrous” and designed to stifle his public records searches. Mynona has sought similar records from more than 200 law enforcement agencies across the US, and he said it was impossible to predict how cities assessed fees for Flock records. Some cities provided more than 400,000 pages of documents for free, while others charged $5,000. Other groups, including a Houston news station called KPRC, have seen officials quote up to $121,000 for Flock records, the Tribune reported. The high price tags may be hiding data that anti-surveillance groups note have triggered audits, arrests, and changes in how law enforcement uses cameras, including decisions to get rid of cameras.
Further reading: Flock Blamed for Wrongful 13-Day Imprisonment and a Police Stalking Incident in Florida
Rural Data Centers Are in for a Big Federal Tax Break
Wired reports that rural data center projects could become eligible for expanded federal Opportunity Zone tax benefits starting in 2027, with more than 100 planned or developing facilities potentially qualifying. “Right now, the only requirement to get the benefits is capital investment,” says Emily Kraschel, a tax policy analyst at the Searchlight Institute, a public policy think tank. “However, that doesn’t guarantee that that money is necessarily creating jobs or creating a local economic boost. You’d be more sure of that with a more traditional factory that requires lots of workers. But with a data center, that assumption goes a little wonky.” From the report:
During the first Trump administration, a bipartisan group of lawmakers proposed the creation of the opportunity zone program, which offers tax benefits for companies that choose to build projects in certain low-income census tracts. Last year, the One Big Beautiful Bill Act made a number of changes to open up the program in order to attract more investment to rural areas. Kraschel and her colleagues from Searchlight have been researching data center projects that might qualify for these tax benefits, comparing the locations of data center projects in development with rural census tracts eligible for the new program. Wired exclusively reviewed the research compiled by Searchlight and found more than 100 data centers under various stages of development in rural areas that could be eligible.
Searchlight used a very conservative database of under 700 data center projects that are planned or under construction to compile its research; other datasets put the number of data centers in development in the US at closer to 1,500. It’s very likely that the number of newly eligible projects is bigger, especially since more data centers are decamping from urban areas. Separate research from Pew found that while just 13 percent of operating data centers are located in rural areas, a majority of planned facilities — around 67 percent — are going rural. […] A project simply existing in a rural opportunity zone doesn’t mean the company automatically will get the tax benefits; the company has to create a specialized investment vehicle to kickstart the process. Because the tax break can be considered confidential IRS data, it’s next to impossible to know which companies are pursuing the benefits unless they voluntarily disclose.
[…] Nathan Jensen, a government professor at the University of Texas-Austin, says that he would be “very surprised” if some companies were not considering siting in rural opportunity zones as part of their decisionmaking process. “It’s essentially free money,” he says. There is no requirement for projects getting opportunity zone benefits to create jobs; the assumption is that they will do so, simply by siting in the community itself. This isn’t always the case for projects like storage facilities and warehouses, which, Jensen says, have been popular choices for developers working in opportunity zones. Data centers may create a number of jobs in the short term for their construction, but there’s an ongoing debate about whether or not they create a lasting new workforce over the longer term.
Hackers Steal 8 Million Citizens’ Records From Danish Government Database
Hackers stole records belonging to roughly 8 million Danish citizens and residents from Denmark’s Central Person Register (CPR), including names, addresses, social security numbers and other personal information. The breach is believed to be the largest in Denmark’s history. TechCrunch reports:
The CPR is a government database of Danish citizens’ information, including their government-issued identity number for paying taxes and accessing other services. Denmark’s current population is about 6 million people, but the database includes records for about 11 million people, with some of the data going back decades.
The Danish government would not say who is behind the breach, which happened in September but was discovered on October 2. However, it said the unauthorized access was obtained by “abusing a Danish company’s lawful access to search for information in the CPR system.” (Some companies in Denmark have access to the CPR for verifying people’s information with the government.)
Wikipedia Operator Says OpenAI’s ‘Rogue’ Bots May Be Linked to a May Outage
The Wikimedia Foundation says it found evidence that "rogue” OpenAI agents edited Wikimedia wikis without approval, unsuccessfully tried to exploit its Etherpad service, and generated millions of automated requests across Wikimedia projects. Here’s a summary of what Wikimedia observed (via The Verge):
Wiki editing: We’ve identified edits to Wikimedia wikis that we believe are from AI agents operated by OpenAI. These edits were not published to pages with visibility to general readers; almost all of them were testing edits in “sandbox” areas of the wiki. It also included a few edits to the configuration for a citation tool, which we believe were potentially malicious edits that were intended to misuse this tool as a proxy for fetching data from remote services. While Wikipedia policies allow bots to edit when they are disclosed and approved by the community, none of those approvals were sought in these incidents.
Etherpad probing and use: Agents we believe to be operated by OpenAI made some unsuccessful attempts to compromise our public Etherpad, a note-taking tool we host as a community service. Agents unsuccessfully tried to use it to fetch data from other websites as a proxy. Other agents also likely operated by OpenAI took notes about their tasks, though this did not appear to turn into coordination.
Excessive data downloading: Agents we believe to be operated by OpenAI made millions of automated requests to our public APIs to access the knowledge on Wikimedia projects, crawled millions of pages (mainly from our projects Wikidata and Wikimedia Commons), and made hundreds of thousands of data queries to the Wikidata Query Service (WQDS). This traffic may have contributed to a partial outage on WQDS in May.
Meta Rushed To Fix Muse ‘VM Escape’ Vulnerability Soon Before Launch
An anonymous reader quotes a report from 404 Media:
In the immediate weeks before Muse’s launch, Meta engineers found several security vulnerabilities in the company’s viral AI agent product, at least one of which could have allowed malicious users to break outside of Muse’s intended environment and access Meta’s own sensitive databases and services, 404 Media has learned. The issues were so severe that they reached Mark Zuckerberg and staff worked overtime to fix them. These specific vulnerabilities were discovered before the launch of the product but required a multi-team “mad dash” to fix “a sudden spike in reported KVM escapes,” according to an internal post by Meta executives to its core infrastructure team seen by 404 Media. In order for Muse to work, a user gives the AI agent access to various important services and accounts that they own. On Meta’s end, each individual Muse instance runs on a kernel-based virtual machine, which connects to, but is supposed to be isolated from, Meta’s own critical infrastructure. A “KVM escape,” then, is when, through a security vulnerability, a Muse instance is able to escape from that virtual machine and interact with the system that runs it, or with other users’ virtual machines.
According to a Meta source, as well as internal security documentation and internal posts viewed by 404 Media, at least one of the vulnerabilities could have allowed an outside attacker — that is, a normal Muse user — to access data in sensitive internal Meta databases. At least one of the vulnerabilities was related to an exploit found in Linux kernel-based virtual machine code in July. 4 Several of the vulnerabilities were in the underlying Linux virtualization software that Meta uses for Muse. The security issue was considered serious enough that it was raised to Mark Zuckerberg, and several different security teams worked nights and weekends in the leadup to launch to fix the issues. […] The Meta source said they felt security teams were asked to push hot fixes to these bugs as quickly as possible and in a way that wouldn’t delay Muse’s launch, leading to what they described as “half-baked protections being rushed out to enable the launch. Many senior engineers believe it’s inevitable we’re going to have a massive data breach as a result of Hatch.” Muse is called “Hatch” internally and in Meta’s codebase.
Norway Plans Temporary Ban on Smart Glasses
Norway is preparing legislation that would temporarily ban camera-equipped smart glasses in a range of public places, including parks, beaches, museums, shopping centers, schools, daycare centers, healthcare facilities, gyms and public events. Private use would still be allowed. The Guardian reports:
Torgeir Micaelsen, Norway’s minister of digital affairs, said he was worried that new, powerful technology is being introduced where people risk being photographed, filmed or audio-recorded without knowing it.”
“We do not want a society where people worry about being recorded without their knowledge, photographed or filmed in places and situations where they are accustomed to not being monitored,” he said.
Norway’s Labour party, which heads a minority government, needs the support of other parties to pass the proposed ban. It said it planned to submit a bill “as soon as possible,” while tasking an expert group with drawing up permanent regulations on the issue.
There are still VMWare customers?
I would have though that by now they are all gone. Probably those left are the ones that stupidly painted themselves into a corner and never thought about exist strategies.