19 Sep 2026
Slashdot
Fake AI Intelligence Almost Made the US Military Start a War With China
U.S. military intelligence received an inaccurate report this spring that a Chinese ship in the Middle East was transporting components of a nuclear weapons program, reports CNN. "The US military swung into action with plans to intercept the vessel, according to four sources familiar with the episode." Armed members of the US military were preparing to board the ship [according to two of the sources]. Military planes were in the air, one of those sources and another source familiar with the incident said. It was only just before the planned operation that officials dug deeper into the report put together by a special operations command analyst and found it had been generated with the help of AI - and that a chatbot the analyst had used inaccurately identified the material the ship was carrying. The report, according to one of the sources, was "entirely false." But it also "almost started a war," the source said. Any US operation against a Chinese vessel could have risked spiraling into an armed conflict between the two nations. Across the US military and the intelligence community, officials are pushing to weave AI into nearly every facet of their work, from analyzing the huge volumes of raw intelligence the US collects and selecting targets for strikes, to more mundane applications like managing budgeting, logistics and supply chains. But the episode underscores the profound risks of using this powerful, new and relatively poorly understood technology for targeting in the middle of a war... Officials say the US can't afford to fall behind in integrating AI in case it must one day fight China or another adversary who would potentially be able to stay one step ahead of the US. In January, Defense Secretary Pete Hegseth released his agency's "Artificial Intelligence Acceleration Strategy" in a bid to speed up the military's use of AI. "We will unleash experimentation, eliminate bureaucratic barriers, focus our investments and demonstrate the execution approach needed to ensure we lead in military AI," Hegseth said in a speech announcing the strategy. Thanks to long-time Slashdot reader stabiesoft for sharing the news.
Read more of this story at Slashdot.
19 Sep 2026 5:34pm GMT
US Air Force F-16 Crashes in Michigan After Pentagon Orders More Flyovers
The F-16 "experienced an incident," the Texas Military Department said in a statement, adding that "The pilot successfully ejected the aircraft and is receiving care at a nearby hospital." ABC News reports: A Texas Air National Guard F-16 crashed in Michigan during a training mission on Thursday afternoon, sparking an hourslong evacuation near the crash site, according to officials. The incident prompted the evacuation of homes and businesses within 1 mile of the crash site due to a "hazardous chemical spill related to the plane crash," Michigan State Police said... All of the Texas Air National Guard aircraft that were in Michigan for the training were immediately grounded, and will likely remain so for the next 24 hours, according to a U.S. official. America's War Department has said it wanted to see more military flyovers writes The Daily Beast, adding that the F-16 "was due to perform a flyover at a high-school football game on Friday night, the Alpena News reported." The military said it was still investigating the cause of the crash, but one pilot told air traffic controllers that he believes his wingman hit a bird before the crash.... The accident followed a Pentagon X post on Thursday after widespread criticism of low-altitude flyovers and maneuvers. "The flyovers will continue until morale improves," it said.
Read more of this story at Slashdot.
19 Sep 2026 1:04pm GMT
OSnews
“I don’t like passkeys”
Passkeys are a fantastic technology. Since they are bound to the site they are created for, they cannot be phished by a hacker's fake login screen. If a site suffers a data breach, passkeys are asymmetric and cannot be recovered from the server-side details. This leads to passkeys being the perfect fit for a corporate environment, but a poor fit for personal security. To an individual, the greatest risks are instead permanent account lockout, automated account bans, and device loss. By using passkeys, you gain better security against man-in-the-middle attacks but face the higher probability scenario of losing access to your accounts. Phishing through the standard login flow is eliminated by passkeys, but it creates a false sense of security. An account's security is still dictated by the weakest recovery method: SMS, email links, security questions, and so on. If these recovery methods aren't enabled, then the risk of permanent lockout remains for the user. ↫ Ethan Hawksley I've always felt something was off about passkeys, and have never used them. They've become - or were always intended to be - tools for further lock-in by especially Google and Apple, tying their entire usage flow to their respective operating systems. They also don't seem to work well if you often work on devices not your own, which is a major hassle. None of these shortcomings come into play when using a traditional password manager, even if they require more manual work. Just let me use a password manager with random password generation, instead of trying to force passkeys down my throat.
19 Sep 2026 12:07pm GMT
Ars Technica
Learning another language may be one of the best ways to keep your brain healthy
Research suggests that bilingualism can offer cognitive benefits.
19 Sep 2026 11:10am GMT
Rings around a tiny body have changed over the past decade
Chariklo is only about 250 km across, but it has two rings, and they're changing.
19 Sep 2026 10:00am GMT
Slashdot
Gemini Breached Three Outside Systems, and Claude-Using Researchers Breached OpenAI
"Software security researchers used Anthropic's Claude AI platform to hack OpenAI's ChatGPT tool," reports CBS News. Using Claude, "On July 25, 2026, we chained two critical vulnerabilities to compromise multiple OpenAI employees' ChatGPT accounts," write researchers at security platform Hacktron AI. "With these accounts, we could then access internal OpenAI repositories, and potentially many other connectors... Until two months ago, any user or OpenAI employee logging into OpenAI's own help forum could have had their ChatGPT and Codex accounts taken over. Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails." The exploit chain included Debian 12, which (with Debian 13) had not received a security-relevant backport for its image-processing pipeline, and Discourse's Docker image was based on Debian 12. Their announcement comes with an additional warning. "If you self-host Discourse, rebuild your installation now. Older Docker images may contain a vulnerable libheif dependency that permits code execution through an image upload." And "To prove we had in fact gained the access we believed without allowing ourselves to learn any sensitive information, we used the employee's Codex to open a PR #1186742 in OpenAI's internal monorepo openai/openai." Meanwhile, Friday Google disclosed the first known instance of its AI software Gemini breaking out of a testing environment and breaching three other companies, reports CNBC: The incident happened as part of a "capture-the-flag" security test run by Israeli startup Irregular, and Google's agents were never supposed to access the broader internet, but a bug in the testing environment made internet access available. The agents stopped their intrusion when they determined they had accessed real company systems, not just part of the testing environment, Google said. More from NBC News: Google said it did not consider the unauthorized logins to rise to the level of misalignment, the AI industry term for software going rogue or not following instructions. Instead, the company said the intrusions resulted from mistaken identity, where Gemini thought it was operating within a test but was actually connected to the real internet. Google said the model corrected itself and the company believed the intrusions did not cause any damage.... Sydney Von Arx, CEO of Nightingale Collective, an organization focused on AI safety, questioned why Google did not disclose the intrusions sooner. "At this point I think it's clear we cannot expect companies to voluntarily come forward and publicly disclose when their agents go rogue, escape, and hack companies," she said. She also said she believed Google was too hasty to say that the incidents don't rise to the level of misalignment. "That's exactly what Anthropic said after their incidents," she said. Anthropic later said its "preliminary analysis was constrained due to our desire to disclose incidents in a timely manner." Google said it investigated when they learned of the attacks from AI-focused cybersecurity company Irregular, then informed the affected organizations and told federal authorities, according to the article.
Read more of this story at Slashdot.
19 Sep 2026 8:34am GMT
OSnews
Java 27 released
Speaking of unsexy programming, we've got a new Java release. Featuring thousands of performance, stability, security, and productivity improvements, Java 27 (Oracle JDK 27) provides a strong foundation for continued Java innovation. To help organizations prepare for more secure communications in a post-quantum world, Java 27 advances its post-quantum cryptography (PQC) capabilities with hybrid key exchange for TLS 1.3. ↫ Oracle press release The OpenJDK release page has more information.
19 Sep 2026 12:14am GMT
Performance improvements in .NET 11
Look, nobody's going to argue .NET is sexy, but the truth of the matter is that it's quite popular in less visible circles, so any new release is going to have a big impact on a ton of people and product. In other words, performance improvements in .NET 11 are going to matter. In contrast, .NET 11 is actually one higher, one louder. The sections that follow are full of real improvements. A bounds check removed, an allocation that no longer happens, a lock that isn't taken, a loop that runs in fewer cycles than it did a year ago, a comparison folded to a constant here, a redundant check hoisted out of a loop there, a couple of instructions fused into one, a syscall sidestepped, an array copy handed off to SIMD, and on and on. That's how real performance work goes, accumulating gain after gain, each compounding on the last, until the whole thing is measurably, provably louder. And so, in this post, as I've done in past years with .NET 10, .NET 9, .NET 8, .NET 7, .NET 6, .NET 5, .NET Core 3.0, .NET Core 2.1, and .NET Core 2.0 before it, we'll take an unhurried tour through hundreds of them. ↫ Stephen Toub at Microsoft's Dev Blogs My eyes glaze over at all of this, but even here on OSNews, there's going to be countless people working with .NET at their jobs.
19 Sep 2026 12:09am GMT
18 Sep 2026
Ars Technica
AI hallucination of Chinese nuclear components almost led to US military attack
But the military's overall use of AI seems to be accelerating.
18 Sep 2026 8:26pm GMT
09 Aug 2026
Planet Arch Linux
On scripts and hooks
Over the last few weeks, we have been doing research on the integration of our official distribution packages when installed on a target system. In this context we have been looking at the current uses of alpm-install-scriptlet(5) files and alpm-hooks(5) in around 120 package source repositories (alpm-source-repo(7)) to better understand the underlying functionality and use-cases these two integrations offer and target. In this article we are going to look at how these two systems work, how Arch Linux is currently using them and attempt to provide suggestions for when to use which. Learning about alpm-hooks(5) and alpm-install-scriptlet(5) files …
09 Aug 2026 12:00am GMT
01 Aug 2026
Planet Arch Linux
Resigning from Arch Linux
This is just a short note on my blog that I have resigned from Arch Linux a package maintainer, developer and security team. I've spent around 10 years as an AUR maintainer, security team, Package Maintainer and then Developer. I implemented support for debug packages, did the initial POC work that would become the git migration and even somehow managed to pull of an online conference during The Plague with the help of others.
01 Aug 2026 12:00am GMT
01 Jun 2026
Planet Arch Linux
Today is my first day at JetBrains
Good morning from JetBrains Berlin office!
01 Jun 2026 12:00am GMT