21 Sep 2026
Slashdot
North Korean Hackers Posed as Recruiters. They Infected 30,000 Devices Worldwide
"I would like to verify your technical abilities, so please download the specified file and complete the assigned task..." Fake job listings aimed at software developers and IT professionals led to 30,000 infected devices in over 100 countries - and 7,000 compromised cryptocurrency wallets, leading to over $10 million (USD) transferred to North Korea. Inc. reports: The hacks occurred from December 2025 through July 2026, according to a joint cybersecurity advisory issued Friday by Japanese, Australian, German, and U.S. authorities, including the Federal Bureau of Investigation and the Defense Department's Cyber Crime Center... The group reportedly has been active since 2023, carrying out both financially motivated attacks and cyberespionage... The hackers lure job seekers through social media, online job platforms, gig-work sites and freelance marketplaces. WaterPlum asks responders to take part in virtual technical interviews or complete coding assignments. The attackers then instruct targets to download and run malicious files, sometimes under the guise of completing an assignment or troubleshooting a problem with videoconferencing software. Once the group gains access to a device or network, it uses malware to steal information, including browser passwords, screenshots, files, and cryptocurrency-wallet data. An infected computer can also provide an avenue into the network of the target's employer, opening the door to intellectual-property theft and espionage, authorities said. The operation overlaps with a separate scheme in which North Korean nationals conceal their identities and locations to obtain remote IT work with companies abroad, officials said. The malicious files are "hosted on multiple online collaboration software developer platforms and code repositories," the advisory points out, and includes malicious Node Package Manager (NPM) packages.." Stolen ID images can also be used by North Korean IT workers to impersonate victims to obtain contracts and receive payment in foreign currency, but "The actors can also use stolen sensitive information for extortion." In one case, a North Korean IT worker "extorted a company over payment and published its proprietary source code online. In another case, an IT Worker hired for website maintenance defaced the hiring company's website and rendered the site inaccessible." The advisory provides clues for employers. It warns these malicious IT workers "tend to favor payment in cryptocurrency, and they may request that remuneration be sent to an account in another person's name." During interviews they'd sometimes used Al face-swapping software, then claimed network issues and disabled their video. And "On holidays celebrated in North Korea, the actors played games and watched soccer videos instead of conducting their usual malicious activities."
Read more of this story at Slashdot.
21 Sep 2026 5:34am GMT
Lawsuit Says Anthropic, OpenAI, SpaceXAI And Google Made Illegal Agreement On AI Slowdown
Tom's Hardware reports: Four plaintiffs subscribed to ChatGPT, Claude, Grok, or Gemini filed a proposed class-action lawsuit alleging that the developers of these AI models violated antitrust laws when they agreed to slow AI development. According to the Associated Press, the lawsuit argues that this agreement would "reduce the value consumers get for paid AI subscriptions" and that this coordination started in July 2026 after the leading AI labs signed a statement admitting there is "intense competitive pressure not to unilaterally slow" development. The plaintiffs recognize the need for AI development to slow for the sake of safety, but they say that Anthropic founder Dario Amodei's cooperation proposal is a "shortcut" that "substitutes collective restraint for individual accountability." Attorney Nick Rowley, the lead counsel for the plaintiffs, says, "AI will quickly spin out of human control and could kill us all if we allow AI safety and protocol ... to be controlled by private self-serving agreements between the world's most powerful 'for profit' technology companies." "Representatives for Anthropic, OpenAI, Google and SpaceXAI did not immediately respond..." reports the Associated Press: The coordination largely took place on Sept. 12, the lawsuit argues, when Anthropic CEO Dario Amodei published an essay urging for industrywide cooperation on decelerating advancements in favor of enhanced safety measures. That same day, OpenAI CEO Sam Altman, SpaceXAI CEO Elon Musk and Google DeepMind's co-founder and chair Demis Hassabis each publicly responded to Amodei's proposals in agreement. But the lawsuit also alleges that the coordination began to take shape months earlier. It points to a statement from July 2026 that high-ranking employees from several of the leading AI labs signed that acknowledged the "intense competitive pressure not to unilaterally slow" development. That statement called on the government to support a global effort to slow automated AI development. Sam Altman even specificially said "we do not believe we need to wait for an antitrust exemption or legislation to begin the work of providing this confidence," notes Tom's Hardware. However, the Trump administration shot down this idea... Chinese state media also criticized this announcement, saying that the call to put the brakes on AI development is nothing but a response to Chinese competition, especially as Amodei's essay explicitly mentioned the desire to slow China's progress and widen the U.S.'s gap over Beijing
Read more of this story at Slashdot.
21 Sep 2026 1:04am GMT
20 Sep 2026
Slashdot
Democracy vs Digital Infrastructure: Pulitzer-Winning Journalist Charts 'The Rise and Fall of the Artificial State'
The Rise and Fall of the Artificial State ultimately asks the question, "How did we cede control of our democracy to the machines, and can we get it back?" according to the Harvard's Arts and Sciences site, FAS Current: The new title finds Lepore, who used to teach a course at the College titled "The Rise and Fall of the Machine," charting the ascent of what she calls the artificial state: the digital communication infrastructure by which governments and private corporations automate and ultimately control public discourse. Following her Pulitzer Prize win for "We the People: A History of the U.S. Constitution" (2025), "I wanted to think about whether liberal constitutional democracies can survive this moment in time," Lepore shared in a phone interview... [In the "current ChatGPT moment"] Lepore found herself asking: "Who are the people who are clamoring to be replaced by machines, to have movies made by machines, and novels written by machines?" And who, she continued, is pushing for our government to be determined by these machines? In the book, Lepore notes that technological tools are increasingly influencing elections around the world... However, she sees the 2026 U.S. midterms as an inflection point. In a recent piece in the Financial Times, Lepore wrote, "This year marks the first AI election. Voters are asking chatbots how they should vote. Campaigns and activists are using AI to analyze the electorate, send micro-targeted messages, produce tailored ads and even deepfakes...." Lepore stresses in the book that "nobody should trust historians to make predictions," but she believes it's possible for democratic citizens to wrest back control. Referencing proposals such as New York's data center moratorium law, Lepore ends by describing a "growing and increasingly noisy tech backlash." "It's not foreordained. This isn't inevitable," she said during the interview. "In the book's epilogue Lepore predicts, as her title suggests, a fall of the Artificial State," writes the California Review of Books. "That argument turns out to be speculative, much more of a hope than a certainty." [Lepore] does support her prediction by positing that the Artificial State is "poorly designed and badly built," that it has not given people safety and happiness but rather a prison of glowing screens, and that a majority of Americans want more control over AI. To escape the Artificial State we will have to imagine a different future by gaining more knowledge of the past in a search for meaning. Of course, powerful forces want to deny that and turn us into servile automatons. The Guardian adds that "While Lepore interprets much classic sci-fi, such as Isaac Asimov, as cautionary, she observes that "the architects of the Artificial State seem to have read these stories, unironically, as instruction manuals, guides for how to build robots that would one day rule the world". (The Atlantic writes that "What one gathers from these misreadings is not so much that science fiction itself is nefarious, but that arrested development might be...") But The Indian Express writes that despite the author's bleak conclusion, "Lepore is not a pessimist. Because the Artificial State is a construct, neither alive, nor truly indestructible, she argues it is still possible to take it apart... [T]his is a clear-eyed reckoning rather than a doomsday tract. It is not an easy read, but an essential one for anyone unsettled by the pace of the AI wave."
Read more of this story at Slashdot.
20 Sep 2026 8:34pm GMT
Ars Technica
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
Google's threat intelligence group said it had a mole inside TeamPCP's inner circle.
20 Sep 2026 11:07am GMT
Don't call it an SUV: The Ferrari Purosangue review
Unlike previous Ferrari four-seaters, this one is better for humans than cargo.
20 Sep 2026 10:00am GMT
T. rex teeth indicate it ran as warm as an elephant
Isotope ratios provide a hint that the giants were actively managing temperatures.
20 Sep 2026 9:00am GMT
19 Sep 2026
OSnews
“I don’t like passkeys”
Passkeys are a fantastic technology. Since they are bound to the site they are created for, they cannot be phished by a hacker's fake login screen. If a site suffers a data breach, passkeys are asymmetric and cannot be recovered from the server-side details. This leads to passkeys being the perfect fit for a corporate environment, but a poor fit for personal security. To an individual, the greatest risks are instead permanent account lockout, automated account bans, and device loss. By using passkeys, you gain better security against man-in-the-middle attacks but face the higher probability scenario of losing access to your accounts. Phishing through the standard login flow is eliminated by passkeys, but it creates a false sense of security. An account's security is still dictated by the weakest recovery method: SMS, email links, security questions, and so on. If these recovery methods aren't enabled, then the risk of permanent lockout remains for the user. ↫ Ethan Hawksley I've always felt something was off about passkeys, and have never used them. They've become - or were always intended to be - tools for further lock-in by especially Google and Apple, tying their entire usage flow to their respective operating systems. They also don't seem to work well if you often work on devices not your own, which is a major hassle. None of these shortcomings come into play when using a traditional password manager, even if they require more manual work. Just let me use a password manager with random password generation, instead of trying to force passkeys down my throat.
19 Sep 2026 12:07pm GMT
Java 27 released
Speaking of unsexy programming, we've got a new Java release. Featuring thousands of performance, stability, security, and productivity improvements, Java 27 (Oracle JDK 27) provides a strong foundation for continued Java innovation. To help organizations prepare for more secure communications in a post-quantum world, Java 27 advances its post-quantum cryptography (PQC) capabilities with hybrid key exchange for TLS 1.3. ↫ Oracle press release The OpenJDK release page has more information.
19 Sep 2026 12:14am GMT
Performance improvements in .NET 11
Look, nobody's going to argue .NET is sexy, but the truth of the matter is that it's quite popular in less visible circles, so any new release is going to have a big impact on a ton of people and product. In other words, performance improvements in .NET 11 are going to matter. In contrast, .NET 11 is actually one higher, one louder. The sections that follow are full of real improvements. A bounds check removed, an allocation that no longer happens, a lock that isn't taken, a loop that runs in fewer cycles than it did a year ago, a comparison folded to a constant here, a redundant check hoisted out of a loop there, a couple of instructions fused into one, a syscall sidestepped, an array copy handed off to SIMD, and on and on. That's how real performance work goes, accumulating gain after gain, each compounding on the last, until the whole thing is measurably, provably louder. And so, in this post, as I've done in past years with .NET 10, .NET 9, .NET 8, .NET 7, .NET 6, .NET 5, .NET Core 3.0, .NET Core 2.1, and .NET Core 2.0 before it, we'll take an unhurried tour through hundreds of them. ↫ Stephen Toub at Microsoft's Dev Blogs My eyes glaze over at all of this, but even here on OSNews, there's going to be countless people working with .NET at their jobs.
19 Sep 2026 12:09am GMT
09 Aug 2026
Planet Arch Linux
On scripts and hooks
Over the last few weeks, we have been doing research on the integration of our official distribution packages when installed on a target system. In this context we have been looking at the current uses of alpm-install-scriptlet(5) files and alpm-hooks(5) in around 120 package source repositories (alpm-source-repo(7)) to better understand the underlying functionality and use-cases these two integrations offer and target. In this article we are going to look at how these two systems work, how Arch Linux is currently using them and attempt to provide suggestions for when to use which. Learning about alpm-hooks(5) and alpm-install-scriptlet(5) files …
09 Aug 2026 12:00am GMT
01 Aug 2026
Planet Arch Linux
Resigning from Arch Linux
This is just a short note on my blog that I have resigned from Arch Linux a package maintainer, developer and security team. I've spent around 10 years as an AUR maintainer, security team, Package Maintainer and then Developer. I implemented support for debug packages, did the initial POC work that would become the git migration and even somehow managed to pull of an online conference during The Plague with the help of others.
01 Aug 2026 12:00am GMT
01 Jun 2026
Planet Arch Linux
Today is my first day at JetBrains
Good morning from JetBrains Berlin office!
01 Jun 2026 12:00am GMT