11 Aug 2026
Slashdot
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices On a Call
An anonymous reader quotes a report from Wired: As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets' devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim. Researchers from the digital defense firm A Security say thebugwas discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports -- Windows, macOS, Linux, iOS, and Android. The vulnerabilities were specifically in the protocol used to facilitate real-time annotation during screen sharing. The researchers say that their AI bug hunting systems specifically delved into this component because, like human bug hunters, they have been trained that convoluted and obscure functions often contain overlooked vulnerabilities. This is particularly true with proprietary, closed-source software. An established company like Zoom presumably does extensive code review and vetting on all components and functions, but without the benefit of public, open review, esoteric yet complex features like annotation are more likely to contain mistakes. The bugs are now patched, with Zoom issuing both server and client-side fixes-or patches for both Zoom's own servers and the applications that run on customer devices. But the researchers emphasize that it was alarming to contemplate bugs that could have been exploited to take over a target device simply by getting someone onto a Zoom call. "What is interesting for us and what we believe is dangerous is the democratization of these capabilities -- the barrier to entry is dropping rapidly," A Security cofounder Omer Gull told WIRED ahead of the disclosure. "Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don't see it as a threat."
Read more of this story at Slashdot.
11 Aug 2026 8:00pm GMT
Spotify Will Label 'AI Persona' Profiles, Exclude Their Music From Recommendations
Spotify will begin labeling AI-generated artist identities with "AI Persona" badges and exclude their music from editorial, algorithmic, and personalized recommendations unless users explicitly follow them. The company says the designation applies to whether an artist profile represents a real person, not whether AI was used to make the music, and will allow appeals for mislabeling. TechCrunch reports: While Spotify will allow artists to identify themselves as AI Personas, the company says it won't rely on self-disclosure alone. It will also review artist profiles and identify those where the artist's name and imagery appear to represent photorealistic AI-generated identities. Spotify said it will begin its review with profiles that have met pre-defined audience thresholds to ensure the more listened-to artists are covered first. Once labeled, the AI Persona badges will appear on the artist's profile in the banner and the About section, in Search, and on track rows across playlists. By default, Spotify won't include AI Personas in its editorial or algorithmic recommendations, nor will it add AI Personas' music to users' personalized recommendations -- unless they happen to follow an AI Persona. Only users can choose to follow an artist, so it's an explicit signal that the user wants to hear more music from that person or group. Spotify wrote in its announcement that, "while we believe all artists have creative choice in determining how they present themselves, Spotify's programming is focused on elevating music from authentic artists building careers in music." "Although there's a broad spectrum in how artists use AI as a creative tool, the question of whether a profile represents an actual human is one where Spotify can help make a clear determination. This badge is about the artist's public identity, not about how the music was made," the company said.
Read more of this story at Slashdot.
11 Aug 2026 7:00pm GMT
Paramount Considers Leaving California Amid Antitrust Suit
Paramount CEO David Ellison is threatening to begin moving the studio out of California on October 1 if state Attorney General Rob Bonta refuses to enter settlement talks over the proposed Paramount-Warner Bros. Discovery merger. The company would reportedly move its Los Angeles headquarters first and shift most studio jobs out of the state over five years, with Georgia, Texas, and Tennessee under consideration. Variety reports: Ellison's threat to relocate Paramount in retaliation for California's Bonta leading the charge to kill the WBD deal -- a move that would include much of its studio operations, over time -- was first reported by industry newsletter Puck. In response, Bonta called Ellison's planned exit from the state an "attempt to blackmail the state into letting an illegal deal through." "Paramount has lost the plot as it continues to lose in court," the attorney general wrote in a post on X. "It didn't work the first time -- on the eve of our July lawsuit -- and it won't work this time." Bonta has not publicly said what concessions from Paramount-WBD he would consider acceptable enough to take the lawsuit off the table. But the Democratic attorney general has said any remedies would need to be "structural" (i.e., divestments) rather than "behavioral" (e.g., imposing certain production quotas). Oct. 1 is when Paramount will begin accruing a "ticking fee" payable to Warner Bros. Discovery shareholders of $7 million per day. The trial in the state AGs' lawsuit is scheduled to start March 2, 2027, roughly five months after that, so Paramount would be on the hook to pay around $1.2 billion to WBD shareholders by the time the trial is scheduled to conclude. (Paramount's ticking-fee payments to WBD are not due until the deal closes.) At the Aug. 5 meeting on Paramount's lot, Ellison told his 12-member senior executive team he expects Paramount to prevail in the antitrust case against the states. However, he also said that if Bonta balks at talks, Paramount will start packing up and moving out of the Golden State in less than two months.
Read more of this story at Slashdot.
11 Aug 2026 6:00pm GMT
10 Aug 2026
Ars Technica
Ars Live: Ross Scott discusses the Stop Killing Games movement
Our discussion takes place live on August 11 at 3 pm ET.
10 Aug 2026 10:23pm GMT
With new open models, Meta pitches another reboot of its struggling AI strategy
Meta has been trailing competitors. Zuckerberg thinks he's found a way forward.
10 Aug 2026 10:13pm GMT
Trump signs bonkers order that cuts vaccines, promotes ones that don't exist
Trump falsely claimed the MMR vaccine is "quite lethal" and linked shots to autism.
10 Aug 2026 9:42pm GMT
OSnews
Cookies are not needed for fingerprinting and tracking
Cookies are ancient technology, and in no way necessary of even particularly desirable to track you. Modern fingerprinting doesn't need them at all. A live demonstration of everything a website learns about you before you click anything with no cookies. It reads you during the connection and in the first two seconds of JavaScript, then narrates what it found back to you in plain English, as if a stranger were describing you out loud. The argument isn't "look how creepy this site is." It's: the site you visit after this one can do all of it too, and won't tell you. ↫ Kuber Mehta Also note, as the demonstration does, that if some of the things it determines about you are wrong, that doesn't really matter. In fact, it may actually make fingerprinting and tracking you easier; as long as fingerprinting consistently gets the same things wrong in the same way, it becomes a valuable part of the fingerprint, like a small scar obscuring part of your real thumb's fingerprint. Online tracking of people should be illegal.
10 Aug 2026 9:11pm GMT
First version of Word for Windows ported to modern 64bit Windows
Back in 2014, Microsoft released the source code to the first Windows version of Word, version 1.1a. Now, Justin Marshall has ported this code to modern versions of Windows, so you can run it as if it were any other modern application. This project is a fully working native Windows x64 port of Microsoft Word for Windows 1.1a, whose historical codename was Opus. It builds the original Word source and resources together with modern replacements for the 16-bit assembly, segmented-memory, and Win16 platform boundaries. The result is the original Word application and user experience running as a 64-bit Windows executable. This is not an emulator or a reimplementation using a modern editor control. ↫ Justin Marshall Neat endeavour.
10 Aug 2026 1:18pm GMT
Idol Mahjong Final Romance: a slideshow disguised as a video game
Top supplier of great articles Nicole Branagan is at it again. We're back into the strip mahjong games today, here going back to 1991. Video System is a company that's probably best known in retro-gaming circles for Aero Fighters/Sonic Wings, but mahjong games (usually branded Idol Mahjong) were one of their bigger moneymakers. And there's something interesting going on here- Idol Mahjong Final Romance 2-R-4 Special re-releases the final three games in the series, which all also got contemporary console releases, but the first game in the series has never been seen outside of its original arcade launch. Why? ↫ Nicole Branagan Look, you're not going to get something like this from anyone else.
10 Aug 2026 1:09pm GMT
09 Aug 2026
Planet Arch Linux
On scripts and hooks
Over the last few weeks, we have been doing research on the integration of our official distribution packages when installed on a target system. In this context we have been looking at the current uses of alpm-install-scriptlet(5) files and alpm-hooks(5) in around 120 package source repositories (alpm-source-repo(7)) to better understand the underlying functionality and use-cases these two integrations offer and target. In this article we are going to look at how these two systems work, how Arch Linux is currently using them and attempt to provide suggestions for when to use which. Learning about alpm-hooks(5) and alpm-install-scriptlet(5) files …
09 Aug 2026 12:00am GMT
01 Aug 2026
Planet Arch Linux
Resigning from Arch Linux
This is just a short note on my blog that I have resigned from Arch Linux a package maintainer, developer and security team. I've spent around 10 years as an AUR maintainer, security team, Package Maintainer and then Developer. I implemented support for debug packages, did the initial POC work that would become the git migration and even somehow managed to pull of an online conference during The Plague with the help of others.
01 Aug 2026 12:00am GMT
01 Jun 2026
Planet Arch Linux
Today is my first day at JetBrains
Good morning from JetBrains Berlin office!
01 Jun 2026 12:00am GMT