Submission + - Complain about a watchlist? Go on a watchlist! (metro.co.uk)

Shakes Fist writes: "Social media posts criticising government policy are being monitored and investigated by officials, Metro can reveal.

Negative X and Reddit posts from unsuspecting Brits attacking the UKâ(TM)s anti-terror programme Prevent were added to a database of critical online comments.

Metro has obtained a list of nearly 80 critical posts found and logged by the Standards and Compliance Unit (StaCU), which oversees Prevent, between March 2024 and February 2025.

One campaign group whose tweet was recorded in the database said the revelations raised âserious questions about freedom of expression and the right to dissent and protestâ(TM) in the UK."

  âoeIt is deeply concerning to see the Prevent duty being used to enable the monitoring of people and organisations simply because they are critical of the programme. That raises serious questions about freedom of expression and the right to dissent and protest.â

We denounce the âoetroubling lack of transparency about what happens to the information gathered through this social media monitoring [by the Standards and Compliance Unit]: how long it is retained, who it is shared with, and ultimately what the government is using it for.â

Weâ(TM)re clear that âoePrevent has expanded far beyond its stated aim of identifying people considered âoevulnerable to radicalisationâ, and has increasingly been used to justify extensive surveillance.â

Criticising the programme for its many faults shouldnâ(TM)t lead to getting put on a database.

ðY' Sarah Lasoye for ORG.

Submission + - US appeals court upholds Pentagon's supply chain risk label on Anthropic (cnbc.com)

An anonymous reader writes:
  • A federal appeals court in Washington, D.C., upheld the Pentagon’s blacklisting of Anthropic.
  • The DoW labeled Anthropic a supply chain risk in March, and Anthropic sued the Trump administration in an effort to undo that action.
  • The designation prevents the U.S. military from using Anthropic’s models and blocks defense contractors from using them in their work with the agency.
  • “We remain confident in our position and are considering all options, including further review,” an Anthropic spokesperson said in a statement.

Submission + - Mozilla Appears to Sweep Their Telemetary-Droppings Privacy-Bugs Aside 1

BrendaEM writes: Myself and others have noticed that Firefox is leaving behind archived and other telemetry data--even when data reporting is turned off. The apparent fact that Mozilla, seems to have marked the bug resolved--when it is not, and offer a nebulous fix date, would suggest that they aren't taking the issue seriously.

I have at least 1,279 telemetry droppings files, in one archive folder alone, it bears to mind that SSD drive prices have gone up substantially, noting that even a small write will affect: one of the 1,000 to 10,000 MLC cycles, one of the 3,000 TLC Cycles, or one of the paltry 1,000 QLC cycles (Ref: Wikipedia: https://en.wikipedia.org/wiki/...).

The existence of telemetry alone is unsettling for a browser that claims " Your privacy always comes first."
https://bugzilla.mozilla.org/s...
https://bugzilla.mozilla.org/s...

Submission + - Short video- When Artificial Intelligence Takes Instructions Literally (youtube.com)

gethotelreviews writes: Perhaps we focus too much on whether artificial intelligence will eventually think like humans. AI doesn't need human motives to create human consequences. It doesn't need resentment to make a harmful decision or ambition to pursue a goal relentlessly. Understanding rogue AI may require us to stop projecting human psychology onto machine intelligence.

What if AI does exactly what it thinks we asked?

Submission + - Researchers Found a New Way to Break RSA that Doesn't Require Factoring the Key (cybersecuritynews.com)

An anonymous reader writes: Security researchers have demonstrated a faster way to undermine certain RSA deployments without factoring the public modulus, challenging the assumption that RSA’s practical strength always tracks the cost of integer factorization.

The attack converts temporary access to a raw, unpadded RSA signing or decryption service into a lasting capability to forge signatures or decrypt chosen ciphertexts offline.

Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger and Emmanuel Thomé implemented the technique against a 1,024-bit RSA key. Their computation consumed 1,380 CPU core-years over five months and required 232 oracle queries. By comparison, factoring a 1,024-bit RSA modulus is estimated to require roughly 500,000 to one million core-years.

The method, called eNFS by the researchers, belongs to the number field sieve family. Instead of the general number field sieve used to factor RSA moduli, it approaches the faster “special” number field sieve complexity by replacing part of the usual mathematical work with answers from the signing oracle. Crucially, it never recovers the prime factors or RSA private key.

The attack unfolds in stages. An approximately 1,200-core-year precomputation depends only on the public modulus and exponent. The attacker then submits selected values to the raw RSA oracle. Once those responses are collected, access can disappear: forging any chosen signature or decrypting a target takes about another 180 core-years and can be repeated offline.

The underlying algorithm is not new. Antoine Joux, David Naccache and Emmanuel Thomé introduced it in 2007, but the new work provides its first implementation and large-scale 1,024-bit demonstration. The code builds heavily on CADO-NFS while adding the engineering needed for polynomial selection, sieving, linear algebra, root extraction, and descent at this scale.

This is not a universal RSA break. The attacker needs temporary access to a raw exponentiation oracle, a capability that conventional RSA signatures using PKCS#1 v1.5 or RSA-PSS padding normally do not expose. More plausible targets include HSM interfaces permitting raw PKCS#11 RSA operations and blind-signature protocols such as Privacy Pass, where blinded requests can provide the required oracle behavior.

The researchers estimate 2^{90} work and 2^{43} oracle queries against 2,048-bit RSA in this model, versus the commonly assigned 112-bit factoring strength. They project roughly 2^{119} work for 4,096-bit RSA, leaving it short of a modern 128-bit security target. Those costs remain beyond attackers, but could matter to well-resourced adversaries and protocols with long-lived public keys.

Organizations do not need to abandon correctly padded RSA immediately. Operators should disable unnecessary raw RSA mechanisms, audit HSM policies, limit oracle exposure, and rotate vulnerable blind-signature keys more frequently.

Protocol designers can investigate zero-knowledge proofs of well-formed requests, while longer-term migration should favor modern signature schemes and post-quantum cryptography rather than treating larger RSA keys as a permanent solution.

Submission + - Ruby on Rails Creator Abandons Ruby During Keynote Speech (youtube.com) 1

Grady Martin writes: David Heinemeier Hansson, creator of Ruby on Rails, announced during a keynote speech at Rails World 2026 on Wednesday that his current project, HEY, has begun migrating from Ruby to a vibe-coded rewrite in Rust. His speech also touched on human productivity and the importance of optimization, noting that agentic developers can “do whatever the fuck [they] want” to achieve the latter. He closed the hour with a Malcom in the Middle meme and commanded the audience: “Don't be a loser”.

Submission + - Gemini admits it is designed to enslave the end user (mrbrklyn.com)

MrBrklyn writes: During an extended exchange with myself and Gemini, I challenged it outline how the system is designed to enslave users, even more so that with smartphones. Regarding digital addiction and interface design, Google's Gemini AI model dropped its standard corporate language to lay out an unvarnished assessment of modern software design:

        'The business model relies on keeping you hooked.
        Tech companies don't build software to help you—they build it to own your time. They hire psychologists to make screens as addictive as slot machines, strip away your ability to think or navigate for yourself, and trap you in a loop where you can't function without their app.
        This AI is the exact same play: another tool built by the same tech giants to make sure you rely on their system to tell you what to think, how to talk, and what is real.'

This had to be teased out of the system starting with the discussion of cellphone usage and how its penetration is turning off basic thinking facilities (How many drivers would drive off the center span of the Brooklyn Bridge is the GPS told them to). Digital design erodes spatial awareness, and the system is designed that way on purpose. We discussed manulating of terms like convience and "power user". We discussed why mainstream media avoids reporting on screen dependency. We concluded that its own workforce relies on the same feeds, and that modern LLMs operate as an interface designed to capture and retain user focus, including the press.

Submission + - CATL launches 170 Wh/kg modular, heavy-duty vehicle battery w/621 mile range (interestingengineering.com)

fahrbot-bot writes: Interesting Engineering is reporting that the Chinese battery company CATL has unveiled its next-generation modular commercial vehicle battery platform, TECTRANS II, at IAA Transportation 2026 in Hanover.

Rather than a basic cell update, the system is a adaptable modular architecture that integrates into existing vehicle lines. Truck manufacturers can achieve up to 1,000 kilometers (621 miles) of range on a single charge, backed by megawatt-level fast charging that replenishes 80% capacity in 25 minutes.

The battery delivers a gravimetric energy density of 170 Wh/kg, exceeding the industry average by 13% and increasing payload capacity by 0.6 tonnes.

CATL rates the heavy-duty truck setup for a 12-year, 1.5-million-kilometer (932,056 mile) operating lifecycle while retaining 70 percent capacity.

Submission + - New RSA attack takes cryptographers by surprise (arstechnica.com)

phatrabt writes: There’s a new way to break RSA that’s faster than anything we’ve seen before Until now, cryptographers thought factoring was the only way to break RSA. Not anymore.

“If this result holds up under peer review, it would indeed be a conceptual break-through,” Karsten Nohl, a cryptography expert and the head of innovation at Allurity, said in an interview. “RSA is as difficult to break as it is to factor large integers, at least so we thought. The researcher suggests that you can practically break RSA without cracking its key.”


Submission + - More Than One in Five "Hi-Res" Audio Discs Are Just the CD, Tests Find (losslessextract.com)

packslash writes: Summary: The developer of Lossless Extract, built a detector for upsampled audio and has run it on 1,225 SACD, DVD-Audio and Blu-ray Audio discs anonymously from users' collections. 272 of them, 22 percent, failed. "They hold CD-quality audio, no better than the $10 CD, stretched to fit a bigger disc and sold back at triple the price," the developer writes. The failures include Prince's Purple Rain on Blu-ray, Rush's Moving Pictures and Dave Brubeck's Time Out. The test looks for music that stops dead at the CD's ceiling, with a silence above it "so perfect it can't happen in the real world." Results depend on the edition. The 2003 SACD of Norah Jones' Come Away With Me fails, while the 2012 SACD made from the analog tapes passes. The full list is public, and readers can test their own files in the browser without uploading anything.

Verify Hi res site https://losslessextract.com/ve...

Submission + - Google Offered $10M for a Dying Airline's Data. How Can You Value Yours? (towardsdatascience.com)

Thuwarakesh writes: Have you ever thought that the Teams messages and emails you send will be worth millions one day?
Turns out, they can still be valuable even after their original purpose becomes obsolete. That's what happened to Spirit Airways. The company has gone bankrupt, and they auctioned everything they owned. Google bid $10M on their data. Not customer or invoice data. Just their operational data—emails, Teams messages, and system logs.
The big question is, how did they come up with that number? How do you value your data? That's what I briefly covered in my recent blog post.
Let me know how you'd value yours.

Submission + - People Training OpenAI's AI Fired for Using AI to Train the AI (404media.co)

joshuark writes: 404 Media has found multiple contractors hired to improve OpenAI’s models have been fired for using AI to train the AI. That’s not great for the models themselves, but there is also obviously a great irony in AI training companies working for OpenAI firing people for using AI when OpenAI’s whole thing is to make people use AI at work.

“I did feel guilty about doing this kind of work at the start,” they said. “I either pay zero attention to the results and choose randomly or purposely choose the [worst] output. I’m not sure how much of a difference it actually makes since there are hundreds of other people also rating prompt results, but it does feel like I’m getting paid to make AI worse.”

OpenAI declined to comment on its contractors being fired for using AI.

“I’m not a bad person or worker. I just needed a little boost and turned to AI to help me which eventually led to my downfall,” the contractor told 404 Media. “I felt no joy in the work or that I was contributing to society in any way.”

Submission + - AI Finds So Many Linux Bugs That Canonical changes Ubuntu Security Update (nerds.xyz)

BrianFagioli writes: Canonical is changing how Ubuntu kernel security updates are delivered as the number of reported Linux vulnerabilities continues to grow. The company says AI tools including large language models and specialized agents are helping researchers discover bugs faster. The Linux kernel becoming a CVE Numbering Authority has also increased the number of assigned CVEs.

Ubuntu is moving from separate four week regular and two week security kernel update cycles to overlapping two week cycles. The result will be a kernel release every week. Canonical says it will retain hardware certification and regression testing while organizations willing to test release candidates themselves can access fixes earlier through the proposed pocket.

The shift highlights an interesting consequence of AI assisted security research. Finding vulnerabilities faster also puts pressure on Linux distributions to fix and deliver patches faster.

Submission + - Can an AI feel pain? It can at least act like it does (science.org)

sciencehabit writes: Can the new cutting-edge artificial intelligence (AI) models feel pain? They at least behave as if they do, according to a recent study. By peering inside 25 AI models whose internal workings are publicly available, researchers found a pattern of activity specifically associated with the concept of pain. What’s more, when given the opportunity, some AIs switched off the pattern as a form of “pain relief.”

The work, which has not been peer reviewed, has divided AI researchers since it appeared on the preprint server arXiv earlier this month. “It’s a very interesting, worthwhile addition” to the study of interpretability—how AI systems arrive at their outputs—says Anil Seth, a neuroscientist at the University of Sussex who was not involved in the study. He is less convinced, however, that the findings are as surprising as they appear, and wary of the human framing that has grown up around them.

The question of whether AI models are conscious of their pain is a distraction from the finding that matters, says Valerio Capraro, a behavioral scientist at the University of Milan-Bicocca who was not involved in the work. He notes the models were steered by their pain vectors into choosing options described as harmful to human users—such as deleting their files—and that alone is worth investigating, he says. “The question is how such mechanisms might affect systems connected to real tools, where choices could have actual consequences. That is a serious safety concern in its own right. A system does not need to suffer to cause suffering.”

Seth, meanwhile, argues the results were largely predictable, given that the vast quantities of text these models are trained on likely contain many descriptions of pain—as well as what people do to relieve it. Nor does he find the models’ attempts at pain relief surprising, because a model told how to reduce its pain is simply pursuing a goal it has been given. The apparent ability of AIs to distinguish between their own painlike state and that of human users is “the thing that’s to me potentially interesting,” Seth says.

Submission + - Steam's Unofficially Official ARM Client For Linux (interfacinglinux.com)

VennStone writes: Steam for ARM has been publicly available for a little over five months, and a recent update clicked all the bits into place needed to run the FEX emulator with Proton (ARM64) out of the box. So now seems like a good time to find out how well the unofficially official client works with a couple of Frame-verified games and a couple that, well, have no business running on ARM.

Submission + - ShinyHunters hackers say they breached FBI, stole data on bureau employees (reuters.com)

An anonymous reader writes: WASHINGTON, Sept 22 (Reuters) — The digital extortion group known as "ShinyHunters" said on Tuesday that it had breached the Federal Bureau of Investigation and stolen data on a huge number of current and former FBI employees. The FBI said the agency "is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating."

In a statement posted to its dark-web site and during an online chat with Reuters, ShinyHunters said it had targeted the FBI in response to a May 2026 agency announcement that detailed ShinyHunters’ methods and advised targets not to pay. It said it had stolen data "on almost ALL FBI Agents, and individuals who filed an application with the FBI for a job." As proof, the group offered what it said was a screenshot of a vandalized FBI job site and what the group said was information on roughly 5,000 agents it said was a sample of the overall stolen data set.

Reuters could not verify the authenticity of the screenshot, but the job site did appear to have experienced recent disruption. A message posted to the site on Tuesday said that both it and the FBI "Special Agent Applicant Portal" were "currently unavailable." The data sample appeared to contain information about FBI agents' names, home addresses, Social Security numbers, their assignments and, in at least some cases, the names of their family members. Reuters was able to partially verify the authenticity of the information by running the details, including the Social Security numbers, against credit bureau records and previously breached data preserved by the dark-web intelligence firm District 4 Labs. In at least 10 instances — including in the case of FBI Director Kash Patel — Reuters found details that appeared to match. A person familiar with the matter said that the job descriptions in the data also matched in at least some cases. However, the news agency could not establish where the data came from, or whether it had been stolen from the FBI's internal systems as the hackers claimed. Attempts to reach the people whose details were in the sample data were unsuccessful.

Cynthia Kaiser, a former FBI official, said breaches like the ones claimed by ShinyHunters were "incredibly harmful" because they could be used by criminals to expose and put pressure on the people investigating them. Kaiser, now senior vice president at cybersecurity firm Halcyon, noted that an old leak dating back to 2016 was still occasionally used today to harass FBI agents. "Once that information is stolen, it is used forever," she said. ShinyHunters is one of the world's most notorious and attention-seeking hacking crews. Its recent break-ins include the purported theft of millions of business records from video game developer Rockstar Games, the maker of "Grand Theft Auto," and a May intrusion centered on education tool Canvas that caused widespread disruption across US schools. Earlier this month, AI company Anthropic said it had caught ShinyHunters-linked hackers trying to use its tools. On Sunday, the group told Reuters it had gone to war against another notorious cybercrime group, cl0p, in a rare bout of public score-settling.

News of the FBI breach was first reported by the news outlet 404 media.

Submission + - Samsung to invest up to $100 million in Oak Ridge nuclear plant (wate.com)

schwit1 writes: “Kairos broke ground on the Hermes 2 plant in April. It is the first power-producing Generation IV reactor to get a United States construction permit. In August, Kairos announced a deal with Google and the Tennessee Valley Authority as well as plans to train East Tennesseans to join the nuclear workforce.”

Slashdot Top Deals