21 Sep 2026
Slashdot
Australia Considers Smart Glasses Ban in Government Workplaces, While 70 People Sue Meta Over Unknowing Data Collection
"Australia is considering barring the use of camera-equipped smart glasses in government workplaces..." reports Reuters, "in what it said could be the first ban of its kind." But meanwhile "more than 70 people who bought, used or were recorded with Meta's smart glasses have sued the social media giant," reports the Los Angeles Times, "claiming their intimate and sensitive images were exposed to workers abroad who are paid to review and label photos and videos." The contractors in Kenya work for companies that help train Meta's artificial intelligence, according to a proposed class-action lawsuit amended in late August. The smart glasses users, some in California, allege the gadget captured footage of themselves and family members undressing, going to the bathroom, having sex and entering passwords. In some cases, the people said they weren't aware the camera-equipped glasses were recording. One California user, referred to as PL18 in the lawsuit, alleges his glasses were unknowingly recording after he placed the smart glasses on the bathroom counter. "He noticed that at times photos of his family members using the bathroom and bathing began appearing in his gallery - footage no one in his household intended to take," the lawsuit said.... The 230-page lawsuit, filed in a federal court in Northern California, accuses Meta of fraud and false advertising, along with violating other consumer protection laws in various states. Tina Wolfson, one of the lawyers representing the plaintiffs, said the case also centers on Meta's surveillance of people's lives without their consent and the exploitation of their image and likeness. "People who bought these glasses and thought that they were cool gadgets weren't aware that every time they activated AI, video was sent to train Meta's AI," said Wolfson, a principal at law firm Ahdoot & Wolfson in Burbank. Meta disagrees with the allegations and intends to fight them. "If you use Meta AI, we may review that data to help improve our products and people's experiences - this works the same way as many other companies. We take steps to filter this data to help remove identifying information and to protect people's privacy," a Meta spokesperson said in a statement... The lawsuit alleges people wearing the smart glasses were unwittingly transmitting data to Meta whenever they used Meta AI by saying "Hey Meta," or sometimes accidentally when adjusting the glasses. "Every activation of the AI features, intentional or accidental, captures video and audio that is transmitted to Meta's servers, routed overseas, and reviewed by low-paid human workers who watch, label, and embed these moments into Meta's AI models," the lawsuit said... The lawsuit also seeks to block Meta from deploying biometric tools through its glasses. The company has been exploring a controversial feature called "NameTag" that would allow people to identify others... A separate lawsuit, filed in September in a federal court in Illinois, alleges Meta has been using images of people's faces uploaded to their public Facebook and Instagram accounts to train AI that powers NameTag and other AI tools.
Read more of this story at Slashdot.
21 Sep 2026 10:04am GMT
North Korean Hackers Posed as Recruiters. They Infected 30,000 Devices Worldwide
"I would like to verify your technical abilities, so please download the specified file and complete the assigned task..." Fake job listings aimed at software developers and IT professionals led to 30,000 infected devices in over 100 countries - and 7,000 compromised cryptocurrency wallets, leading to over $10 million (USD) transferred to North Korea. Inc. reports: The hacks occurred from December 2025 through July 2026, according to a joint cybersecurity advisory issued Friday by Japanese, Australian, German, and U.S. authorities, including the Federal Bureau of Investigation and the Defense Department's Cyber Crime Center... The group reportedly has been active since 2023, carrying out both financially motivated attacks and cyberespionage... The hackers lure job seekers through social media, online job platforms, gig-work sites and freelance marketplaces. WaterPlum asks responders to take part in virtual technical interviews or complete coding assignments. The attackers then instruct targets to download and run malicious files, sometimes under the guise of completing an assignment or troubleshooting a problem with videoconferencing software. Once the group gains access to a device or network, it uses malware to steal information, including browser passwords, screenshots, files, and cryptocurrency-wallet data. An infected computer can also provide an avenue into the network of the target's employer, opening the door to intellectual-property theft and espionage, authorities said. The operation overlaps with a separate scheme in which North Korean nationals conceal their identities and locations to obtain remote IT work with companies abroad, officials said. The malicious files are "hosted on multiple online collaboration software developer platforms and code repositories," the advisory points out, and includes malicious Node Package Manager (NPM) packages.." Stolen ID images can also be used by North Korean IT workers to impersonate victims to obtain contracts and receive payment in foreign currency, but "The actors can also use stolen sensitive information for extortion." In one case, a North Korean IT worker "extorted a company over payment and published its proprietary source code online. In another case, an IT Worker hired for website maintenance defaced the hiring company's website and rendered the site inaccessible." The advisory provides clues for employers. It warns these malicious IT workers "tend to favor payment in cryptocurrency, and they may request that remuneration be sent to an account in another person's name." During interviews they'd sometimes used Al face-swapping software, then claimed network issues and disabled their video. And "On holidays celebrated in North Korea, the actors played games and watched soccer videos instead of conducting their usual malicious activities."
Read more of this story at Slashdot.
21 Sep 2026 5:34am GMT
Lawsuit Says Anthropic, OpenAI, SpaceXAI And Google Made Illegal Agreement On AI Slowdown
Tom's Hardware reports: Four plaintiffs subscribed to ChatGPT, Claude, Grok, or Gemini filed a proposed class-action lawsuit alleging that the developers of these AI models violated antitrust laws when they agreed to slow AI development. According to the Associated Press, the lawsuit argues that this agreement would "reduce the value consumers get for paid AI subscriptions" and that this coordination started in July 2026 after the leading AI labs signed a statement admitting there is "intense competitive pressure not to unilaterally slow" development. The plaintiffs recognize the need for AI development to slow for the sake of safety, but they say that Anthropic founder Dario Amodei's cooperation proposal is a "shortcut" that "substitutes collective restraint for individual accountability." Attorney Nick Rowley, the lead counsel for the plaintiffs, says, "AI will quickly spin out of human control and could kill us all if we allow AI safety and protocol ... to be controlled by private self-serving agreements between the world's most powerful 'for profit' technology companies." "Representatives for Anthropic, OpenAI, Google and SpaceXAI did not immediately respond..." reports the Associated Press: The coordination largely took place on Sept. 12, the lawsuit argues, when Anthropic CEO Dario Amodei published an essay urging for industrywide cooperation on decelerating advancements in favor of enhanced safety measures. That same day, OpenAI CEO Sam Altman, SpaceXAI CEO Elon Musk and Google DeepMind's co-founder and chair Demis Hassabis each publicly responded to Amodei's proposals in agreement. But the lawsuit also alleges that the coordination began to take shape months earlier. It points to a statement from July 2026 that high-ranking employees from several of the leading AI labs signed that acknowledged the "intense competitive pressure not to unilaterally slow" development. That statement called on the government to support a global effort to slow automated AI development. Sam Altman even specificially said "we do not believe we need to wait for an antitrust exemption or legislation to begin the work of providing this confidence," notes Tom's Hardware. However, the Trump administration shot down this idea... Chinese state media also criticized this announcement, saying that the call to put the brakes on AI development is nothing but a response to Chinese competition, especially as Amodei's essay explicitly mentioned the desire to slow China's progress and widen the U.S.'s gap over Beijing
Read more of this story at Slashdot.
21 Sep 2026 1:04am GMT
20 Sep 2026
Ars Technica
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
Google's threat intelligence group said it had a mole inside TeamPCP's inner circle.
20 Sep 2026 11:07am GMT
Don't call it an SUV: The Ferrari Purosangue review
Unlike previous Ferrari four-seaters, this one is better for humans than cargo.
20 Sep 2026 10:00am GMT
T. rex teeth indicate it ran as warm as an elephant
Isotope ratios provide a hint that the giants were actively managing temperatures.
20 Sep 2026 9:00am GMT
19 Sep 2026
OSnews
“I don’t like passkeys”
Passkeys are a fantastic technology. Since they are bound to the site they are created for, they cannot be phished by a hacker's fake login screen. If a site suffers a data breach, passkeys are asymmetric and cannot be recovered from the server-side details. This leads to passkeys being the perfect fit for a corporate environment, but a poor fit for personal security. To an individual, the greatest risks are instead permanent account lockout, automated account bans, and device loss. By using passkeys, you gain better security against man-in-the-middle attacks but face the higher probability scenario of losing access to your accounts. Phishing through the standard login flow is eliminated by passkeys, but it creates a false sense of security. An account's security is still dictated by the weakest recovery method: SMS, email links, security questions, and so on. If these recovery methods aren't enabled, then the risk of permanent lockout remains for the user. ↫ Ethan Hawksley I've always felt something was off about passkeys, and have never used them. They've become - or were always intended to be - tools for further lock-in by especially Google and Apple, tying their entire usage flow to their respective operating systems. They also don't seem to work well if you often work on devices not your own, which is a major hassle. None of these shortcomings come into play when using a traditional password manager, even if they require more manual work. Just let me use a password manager with random password generation, instead of trying to force passkeys down my throat.
19 Sep 2026 12:07pm GMT
Java 27 released
Speaking of unsexy programming, we've got a new Java release. Featuring thousands of performance, stability, security, and productivity improvements, Java 27 (Oracle JDK 27) provides a strong foundation for continued Java innovation. To help organizations prepare for more secure communications in a post-quantum world, Java 27 advances its post-quantum cryptography (PQC) capabilities with hybrid key exchange for TLS 1.3. ↫ Oracle press release The OpenJDK release page has more information.
19 Sep 2026 12:14am GMT
Performance improvements in .NET 11
Look, nobody's going to argue .NET is sexy, but the truth of the matter is that it's quite popular in less visible circles, so any new release is going to have a big impact on a ton of people and product. In other words, performance improvements in .NET 11 are going to matter. In contrast, .NET 11 is actually one higher, one louder. The sections that follow are full of real improvements. A bounds check removed, an allocation that no longer happens, a lock that isn't taken, a loop that runs in fewer cycles than it did a year ago, a comparison folded to a constant here, a redundant check hoisted out of a loop there, a couple of instructions fused into one, a syscall sidestepped, an array copy handed off to SIMD, and on and on. That's how real performance work goes, accumulating gain after gain, each compounding on the last, until the whole thing is measurably, provably louder. And so, in this post, as I've done in past years with .NET 10, .NET 9, .NET 8, .NET 7, .NET 6, .NET 5, .NET Core 3.0, .NET Core 2.1, and .NET Core 2.0 before it, we'll take an unhurried tour through hundreds of them. ↫ Stephen Toub at Microsoft's Dev Blogs My eyes glaze over at all of this, but even here on OSNews, there's going to be countless people working with .NET at their jobs.
19 Sep 2026 12:09am GMT
09 Aug 2026
Planet Arch Linux
On scripts and hooks
Over the last few weeks, we have been doing research on the integration of our official distribution packages when installed on a target system. In this context we have been looking at the current uses of alpm-install-scriptlet(5) files and alpm-hooks(5) in around 120 package source repositories (alpm-source-repo(7)) to better understand the underlying functionality and use-cases these two integrations offer and target. In this article we are going to look at how these two systems work, how Arch Linux is currently using them and attempt to provide suggestions for when to use which. Learning about alpm-hooks(5) and alpm-install-scriptlet(5) files …
09 Aug 2026 12:00am GMT
01 Aug 2026
Planet Arch Linux
Resigning from Arch Linux
This is just a short note on my blog that I have resigned from Arch Linux a package maintainer, developer and security team. I've spent around 10 years as an AUR maintainer, security team, Package Maintainer and then Developer. I implemented support for debug packages, did the initial POC work that would become the git migration and even somehow managed to pull of an online conference during The Plague with the help of others.
01 Aug 2026 12:00am GMT
01 Jun 2026
Planet Arch Linux
Today is my first day at JetBrains
Good morning from JetBrains Berlin office!
01 Jun 2026 12:00am GMT