Join our Folding@Home team:
Main F@H site
Our team page
Support us: Subscribe Here
and buy SoylentNews Swag
We always have a place for talented people, visit the Get Involved section on the wiki to see how you can make SoylentNews better.
Framework says it's replacing some out-of-warranty AMD mainboards.
A BIOS update for the Framework Laptop 13 with AMD Ryzen 7040-series processors is bricking the systems, multiple users have reported online.
Framework started shipping pre-built Ryzen 7040-based Framework Laptop 13 computers and compatible motherboards in 2023. In June 2026, Framework released BIOS 3.20 for the devices. The update adds mainboard support for features, including a haptic touchpad and new speakers, for the higher-end Framework Laptop 13 Pro and fixes issues, including one "where the Battery Extender status was reported incorrectly following a reboot, hibernation, or shutdown after the timer had expired," per a post on Framework's forum from an employee.
Some users say that they installed the update successfully.
Numerous others, however, claim that the installation stalls, bricking the laptop.
"[T]he update process seems to have stalled," a Framework forum user named Sven posted in July. "What I see is a black screen and a progress bar with 2 dots and then the Framework logo. The progress bar is not moving for about 3 hours now. Also, I can't turn off the Framework using the power button, no matter how long I hold it down. Now the BIOS update is stuck, and I can not power down or reboot the machine."
Ars Technica contacted Framework, asking how many customers are affected. In a company statement, Framework said it has "received reports of a small percentage of Framework Laptop 13 7040 Series BIOS updates resulting in non-bootable boards." Framework is investigating the root cause of the issue, the statement said.
There are reports of users having problems with BIOS upgrades on Ryzen 7040-based Framework Laptop 13 devices going back to at least March 2025.
After the most recent BIOS update, some users reported that Framework support told them they needed a new motherboard, but Framework wouldn't provide it for free because the customer was past warranty.
Framework's statement to Ars says:
... in addition to replacing in-warranty Mainboards, we are making exceptions for out-of-warranty replacements where we can confirm a stable-release BIOS update caused the board to become non-bootable.
Framework is also introducing a "Crisis Recovery Mode" BIOS functionality to enable a path for failed updates to be directly recoverable.
"Our latest Framework Desktop BIOS release includes this functionality, and we are actively bringing it to Framework Laptop 12, 13, and 16 in our upcoming BIOS release cycles for each," Framework said.
We won't be sure of the source of the problems until Framework provides more information. Blogger Guanzhong Chen, however, wrote a detailed blog post this week about their purported experience with their motherboard breaking and suggested the problem stems from "some bug with the software that caused it to display what appears to be random memory on the screen, especially when this has happened before to other people for other BIOS versions."
The software developer, who was ultimately able to flash the firmware onto their motherboard after a support representative reportedly told him to buy a new one, added:
"At the same time, it somehow flashes the BIOS slower in regular operation than a cheap 15 MHz programmer over pogo pins, which really makes you wonder what it's doing under the hood."
The long legal battle over ownership of Linux is closer than ever to ending, after a panel of three judges ruled a claim against IBM and Red Hat isn't valid, and that time has expired for further action.
This story starts in 1998 when IBM decided the world needed a single version of UNIX capable of running on multiple processor architectures. To make that happen, Big Blue allied with a company called the Santa Cruz Operation (SCO) which made a version of UNIX for x86 CPUs. Intel and Sequent also signed up for the multi-architecture effort, called "Project Monterey."
The alliance didn't work, largely because Linux came along and delivered a *Nix that ran on multiple processors (and introduced a new way to develop software).
IBM decided to add some of the code developed during Project Monterey to Linux, leading SCO and its legal successors to claim they owned that code and therefore had some sort of legal claim over Linux.
OPINION: DVD is one of those technologies that dominated for barely a generation yet left a permanent cultural mark. It made high-quality video cheap enough for mass distribution, popularized the TV series boxed set, and encouraged its gluttonous consequence: binge viewing. Streaming and capacious storage have since pushed optical media toward irrelevance. There may no longer be a box, but the boxed-set mentality remains, and we still binge like Roman emperors. It is a genuinely new way of absorbing large quantities of information.
Now it is time to recognize a further evolution: the bingeable tech conference. Streamed conferences are nothing new, but few reward being watched from beginning to end. They offer too many talks on too narrow a subject, too much marketing flimflam, or too much variation in quality. The Goldilocks zone of quality, range, relevance, and intelligence is rare, but worth seeking out. This July delivered a near-perfect example: Software Should Work 2026.
The name supplies the plot arc. Software Should Work is about reliability in its broadest sense, because reliable software requires much more than making code that runs. It encompasses abstraction and formal methods, managing complexity, making the most of tools and processes, individual innovation, team culture, and the nuts and bolts of telling computers what to do. In just 13 videos, SSW creates a widescreen, high-definition, thought-provoking picture of the field today. You can watch them in a day, and once you start, you may not want to stop.
It would be unseemly to give too many spoilers. In such a concise treatment of a multifaceted subject, the talks that grab you will depend on your own interests and experiences. Consider dependencies, part of the calculus of reliability. So far, so dry. But Richard Feldman's talk compares web stacks from 1996, 2006, and 2026, revealing what looks like an inexorable multiplication of abstractions and dependencies. He then compares eight contemporary language and runtime websites: TypeScript, Node.js, Python, Ruby, Rust, Zig, Go, and Roc. The result is one of the more illuminating graphs you'll see this year.
Another thought-provoking contribution comes from Richard Hipp, creator of SQLite, one of the corest of the core technologies in everyday use. On its face, his account of how a codebase evolves in response to changing test methods sounds dry. It is also a personal journey, full of highs and lows, illustrating how reliability depends not only on the interplay between code and test design, but also on human motivation, creativity, flexibility, and doggedness. There is no shortage of technical detail either.
This is why SSW 2026 works so well. Its speakers have deep experience of software reliability, but were free to choose their subjects. The resulting mix of opinions, experiences, and approaches ranges from the mathematics of formal analysis to the importance of daydreaming and the dangerous myth of the superhero engineer. Reports from the language wars, AI WTFery, and arguments over whether Nix partisanship is justified are all present, delivered by people working on the front lines.
Most importantly, the conference explores the culture of reliability and what it means to say that software works. It feels like a proper symposium: an exchange of ideas about something that touches every part of the digital world yet is rarely considered as a whole. Commercial pressures can work against practitioners and customers alike, while the lack of a common language and agreed standards makes good practice harder to defend. Without reliability, everything falls apart. How to teach it, and where the discipline goes next, remain stubbornly difficult questions.
SSW 2026 provides a splendid and much-needed focus on all of this. Its blend of narratives and subjects means there is always something you did not know you needed to see, accompanied by the pleasurable sense of time well spent. Curiosity is richly rewarded. If you see software reliability as an ongoing drama – and if you don't, how are you still here? – block out a bingeing window. Software should work, but so should conferences, and this one is well worth the popcorn.
The Dead Internet Theory May Be Coming True, Pew Research Findings Show
Are you reading more text written by an AI bot? A Pew Research study published this week says it’s very likely.
That’s not breaking news if you’re aware of the Dead Internet Theory that dates back to 2021. CNET writer Trisha Jandoc dove into that theory last year, which basically says people believe the internet died 10 years ago in 2016 and that much of what we see online now is AI-generated.
There is some truth to that. Pew researchers scanned nearly half a million English webpages from the past five years using Common Crawl, a web archive. That dates back to before ChatGPT was made publicly available in November 2022. Researchers ran those pages through Open Pangram, an AI detection tool, to see if it was written or edited by AI. Then the researchers looked at a sample of 10,000 pages from last month to spot signs of AI-written content. They looked for phrases, words and language that are more common among AI bots than humans.
Researchers made it clear that AI detection models don’t always get it right. Sometimes they flag text written by humans as AI authorship and AI-written text as being written by a human.
Nonetheless, the study found that 10% of the samples “show significant signs of AI authorship.”
As Wisconsin cities flee Flock, its shared camera network loses value
[...] Over the past few months, a spate of Wisconsin towns and cities have withdrawn from Flock deals over privacy and trust concerns. As they did so, another issue revealed itself: With each city that leaves, the Flock network becomes less useful to the cities that remain. And cities are starting to notice.
Consider Dane County, which includes the city of Madison. It's one of the most populous counties in Wisconsin. It was also a significant Flock user, with a contract for 24 license plate cameras. But after complaints from citizens and privacy experts, the Dane County Board of Supervisors on April 16 voted to cut the $80,000 in county funding for Flock cameras and banned "further expenditures on the system."
"There are well-documented concerns about how this company operates and uses its technology to violate people's Fourth Amendment rights [against unreasonable searches]," said County Board Chair Patrick Miles. "The board's action supports protecting our community from a proven bad actor. We have full confidence in our Sheriff and deputies, and we are open to considering other companies that have stronger safeguards in place."
[...] Because much of Flock's value comes from access to cameras in other jurisdictions, the loss of Dane County and Monona meant Flock was suddenly less useful to nearby police departments. The town of McFarland, which neighbors Monona, announced on May 15 that it would not move forward with its plan to deploy Flock cameras "in light of a shrinking database in Dane County and input from residents."
"Once Dane County lost their funding for Flock, we lost about half of the potential camera network within Dane County," said McFarland Chief of Police Brian Redman in a statement. "I had to ask, 'Were we still going to get the return on our investment with that loss?' With the network being chipped away, that wasn't going to be the case."
[...] Public resistance was crucial to many of these decisions to de-Flock. Indeed, the broad backlash against Flock has grown so strong that the surveillance company last week announced mandatory new audit controls and lower default data retention periods for US users.
Flock now knows what Kaukauna and McFarland realized: The same "network effect" that helps build a business can also work in the other direction once customers start to flee.
Malicious updates turned routine builds into a delivery system for infostealer malware:
Hackers slipped malware into several popular Rust packages this week, turning routine software builds into a route onto developers' machines.
The Rust Security Response Team disclosed the supply chain attack on Thursday after receiving a tip about a crate called proc-macro1. An investigation found that its build script fetched malware from a remote server.
The attack extended beyond a single dodgy crate. Someone had published a new version of arrayref, a legitimate and widely used Rust package, with proc-macro1 added as a dependency. The attacker had also yanked recent legitimate releases of arrayref, helping steer users toward the poisoned release.
The Rust team does not believe arrayref's maintainer was responsible. It suspects the developer's computer or credentials were compromised and locked the account while attempting to contact them. The attacker also published malicious versions of two other crates maintained by the same developer, internment and append-only-vec.
The poisoned releases weren't around for long. Arrayref 0.3.10 was available on crates.io for 86 minutes, internment 0.8.7 for 90 minutes, and append-only-vec 0.1.9 for 107 minutes before they were removed.
That's a narrow window, but arrayref is hardly some forgotten package gathering dust in the registry. Security firm Aikido, which separately analyzed the attack, puts arrayref at roughly 245 million lifetime downloads and append-only-vec at more than 4 million. However, those figures don't tell us how many developers pulled the malicious versions during the brief period they were live.
Aikido found that the attacker largely left the legitimate source code untouched, adding only a dependency on proc-macro1, a typosquat of the legitimate proc-macro2 package. The malicious code was tucked inside proc-macro1's build.rs file.
Cargo, Rust's package manager, runs build scripts during compilation. This allowed proc-macro1 to identify the operating system and processor architecture of the developer or build machine, download a matching payload, and execute it. Aikido found malware built for Linux, Windows, Intel Macs, and Apple Silicon Macs.
The second-stage payload was more than a simple downloader. Aikido found code targeting Chromium-based browser data, including profiles for Google Chrome, Brave, and Microsoft Edge, as well as browser extension storage used by cryptocurrency wallets. It also found functionality to establish persistence and receive commands from the attacker's server.
The Rust team also deleted proc-macro-en, aovine, arone, aronenao, and tinymember, warning that every version of those crates should be considered malicious. Developers have been urged to check their Cargo lockfiles and local registry caches for the affected packages.
Rust credits Nextron Systems' research team with initially discovering and reporting the attack. It has not said how the legitimate maintainer was compromised, how many developers downloaded the poisoned releases, or how many systems ultimately executed the payload.
The malicious packages may have lasted less than two hours on crates.io, but whoever was behind them chose a well-traveled route into developers' machines.
Chinese safety regulators have cracked down on doors that don't open in a crash:
Tesla is facing a massive recall in China today. Chinese regulators are taking a stricter approach to safety, and the automaker now has to add warning labels to 2.98 million Model 3 and Model Y electric vehicles in China that make it clearer how to open the rear doors in the case of an emergency that causes the car to lose power.
As we learned earlier this year, Chinese regulators are getting more serious about the recent trend of electronically controlled car doors; a growing number of crashes have had fatal consequences when the occupants have been trapped in burning cars. Starting next year, new rules give specific dimensions for handles that must be followed by all newly approved vehicles. But cars that have already been on sale for some time, like the Models 3 and Y, are grandfathered in, at least until the end of 2028.
But China wants Tesla to do something about the nearly 3 million cars already on its roads. It is requiring the automaker to add warning labels to the car interiors—something that will require physical access to the car. Additionally, Tesla will push out a software update that automatically lowers all the cars’ windows in the event of a collision.
Tesla is also facing a second Chinese recall, this one only affecting 2.74 million cars. These require new software for their driver monitoring system, which currently only uses a torque sensor on the steering wheel to determine if the driver is holding the wheel and remaining engaged in the task of driving. Now, the update will leverage the interior camera in the Models 3 and Y to track the driver’s gaze instead.
However, Electrek has previously reported that Chinese Tesla owners have been able to defeat the cabin driver monitoring system—which it has rolled out to customers with its more advanced partially automated driving system—by mounting a doll’s head in front of the camera.
Nv's new chips need new datacenters, but you can't have bit barns without power:
Nvidia has made its fortune on the AI boom, but the company has a problem. It faces a growing number of roadblocks which, if left unchecked, could pop the bubble.
Thus, the AI arms dealer has been forced to play a game of Whac-a-Mole, shoring up the foundations of its empire by investing its spoils into ensuring its customers don't stop buying.
The latest example of this came Friday, when Nvidia announced it'd become a minority investor in Cloverleaf.
Founded in 2024, Cloverleaf specializes in laying the literal foundations – by which we mean the land and power – necessary to build bit barns so they can be leased by the cloud providers and model devs that actually pay the bills for Nvidia's hardware.
Nvidia can only sell as many GPUs as there are datacenters to put them, and those datacenters can only be deployed where there's adequate power to support them. And since its latest round of GPUs can't just be dropped into any old bit barn, Nvidia is going to need a lot more datacenter capacity, and by extension a lot more power.
[...] So, to sell its next-generation GPUs, Nvidia not only needs its customers to have adequate capacity, but also needs those facilities to offer the right mix of power and cooling.
It's well established that Nvidia prioritizes customers with datacenters ready to fill. However, many of the GPU-slinger's biggest customers don't actually own datacenters, but instead lease capacity from others. For example, Crusoe built OpenAI's Stargate facility in Abilene, Texas, and Oracle runs it. Altman and crew are simply supplying the demand.
So, Nvidia has invested in model devs and neocloud partners by helping them get financing or even investing directly in their businesses. Nvidia's investments in OpenAI, CoreWeave, and Nebius are just a few examples.
That works so long as the bit barns available for rent are the right size and shape for the hardware. But, as we noted earlier, many existing facilities aren't.
[...] The proliferation of AI datacenters has begun to strain grid capacity, forcing many new ones to employ behind-the-meter power generation. For example, Nebius has begun using Bloom Energy's natural gas fuel cells to power its datacenters, rather than relying entirely on existing grid infrastructure.
Nvidia's investment in Cloverleaf is the latest example of how the GPU slinger is using the circular AI economy to its advantage. The terms of the deal haven't been disclosed, but the benefits are obvious: Cloverleaf gets an influx of cash, while Nvidia gets greater control over the build process.
[...] The deal is the latest example of how Nvidia is using its war chest to shore up cracks in the broader AI ecosystem before they become a problem. We wrote a few weeks ago about how the company was helping AI infrastructure startups secure financing in exchange for a share of the revenues, but it's now clear Nvidia is attacking potential roadblocks from every angle.
https://arxiv.org/abs/2608.18214
Here's a strange, light space story. Obviously, everyone knows ionizing radiation damages silicon. Anyone have good stories from the old days of marginal ram detecting cosmic rays? That meme seemed to die out around the dram kilo to mega transition, certainly forgotten by giga sized dram, which you'd think would be more severely impacted from being smaller... Anyway, surprisingly, a data analysis comparing known HST silicon damage to known solar radiation levels shows it's out of phase by some years.
1) Is it new physics? Either the radiation or silicon damage?
2) Is it P-Hacking in STEM where it's just numerology, abuse R and numpy.py until you get clickbait? The authors admit "We obtain remarkably accurate fits to Hubble data but with physically absurd parameter values."
3) Some of both or maybe none of either? Some other cause?
Any fun P-hacking stories from the world of STEM?
Just a fun light news story, but there's also some depth to think about.
Amazon's updated terms of service now contain a clause that may take many subscribers by surprise. The online giant is revoking your right to file a class-action lawsuit against it if a dispute arises, according to its Conditions of Use page.
On Friday, Amazon sent an email to subscribers explaining that it will now settle any disputes via arbitration. Customers who have continued to use the corporation’s services after Aug. 14 implicitly waived their rights to bring new class-action suits against the online retail giant.
The language used in the Conditions of Use page states this new legal limitation outright.
"You and we agree that any dispute or claim relating in any way to your use of any Amazon service, or to any products or services sold or distributed by Amazon or through amazon.com, will be resolved by binding arbitration rather than in court," the document reads. "There is no judge or jury in arbitration, and court review of an arbitration award is limited. A neutral arbitrator will resolve the dispute or claim and must follow the terms of this agreement as a court would."
A class-action waiver is also included, which prevents customers from filing requests for arbitration together. Although Amazon is allowed to resolve batches of arbitration proceedings under detailed mass arbitration rules, each dispute must be filed individually.
Amazon’s language frames the change as a positive for its customers, since the company pledges to "pay most of the cost" for customers who choose to arbitrate disputes.
A representative for Amazon did not immediately respond to a request for comment.
A company spokesperson told CNET’s sibling site PCMag over email that Amazon has and will continue to "continually update our Conditions of Use to better serve our customers."
"We determined that reinstating the arbitration clause will offer customers a fast, cost-effective way to resolve disputes while still giving them the option of going to small claims court," the spokesperson wrote.
But at the end of the day, that arbitration clause may serve to stifle customer disputes by making it more difficult to seek financial restitution.
There are very few exceptions to Amazon's new arbitration clause, and none of them are particularly great for customers. You can still take the company to small claims court, but the compensation you can receive is extremely limited.
Before the terms of service update, it only took one motivated individual to perform research, consult legal professionals and get the ball rolling on a class-action lawsuit. From there, other affected parties were able to sign on and receive compensation with comparatively little effort.
That's not the case with an arbitration policy, which has a higher bar for individual effort and personal costs that may dissuade many customers from hashing out their financial disputes.
Before any arbitration proceeding can be filed, customers must submit a dispute claim to Amazon itself, giving the company 60 days to resolve it. If Amazon doesn't respond during that two-month window, you can move on to the actual arbitration process.
Filing an official complaint with JAMS, Amazon's chosen third-party arbitrator, requires you to pay a $250 fee upfront, which is a financial hurdle that the average class-action member likely won't or can't be bothered with.
From there on, "a neutral arbitrator will resolve the dispute or claim and must follow the terms of [the Conditions of Use] as a court would," according to Amazon. "The arbitrator shall issue a written award that states the disposition of each claim and provides a concise statement of the essential findings and conclusions on which it is based."
If you're keeping a running tally of every hurdle presented to customers by the arbitration clause, you'll realize that this process demands more time and money than any class-action lawsuit settlement claim does.
Technically, a critical mass of maligned customers could initiate mass arbitration and be compensated with more money than would ever be awarded to them in a class-action lawsuit. In fact, Amazon previously revoked an arbitration clause in its terms of service in 2021, after 75,000 people simultaneously filed disputes alleging Alexa was recording them without their consent.
Now, the e-commerce giant is trying to force customers into individualized claims once again, likely betting that the legal red tape of the arbitration process will put off many affected customers from ever fighting for financial restitution in the first place.
The terms of service update only limits US Amazon customers from proposing new class-action suits, which means any case filed prior to Aug. 14 will be allowed to proceed.
That means a bevy of existing lawsuits, including separate cases that allege Amazon purposefully shortened the lifespan of its first- and second-generation Fire TV Sticks and violated the privacy of millions of Americans through Ring camera AI features, will still have their day in court.
The e-commerce giant recently settled a $2.5 billion class-action lawsuit that alleged it had used deceptive "dark patterns" to push customers into paying for Prime subscriptions, before making it intentionally difficult to cancel the recurring charge.
Amazon admitted no wrongdoing as the case concluded, but more than $1.5 billion was earmarked to refund customers after legal fees were paid out. A costly, high-profile case like this one may have been part of the reason why the company changed its terms of service.
Changes to Amazon's subscriber agreement won't insulate the company from litigation by government agencies, so it will still be subject to lawsuits filed by the US Federal Trade Commission.
A new analysis of the 60 largest data centers under construction in the US by Amazon, Google, Meta and Microsoft estimates the sites could produce a cumulative 101.5 million tons of carbon dioxide annually once they’re fully up and running, Financial Times reports [Paywalled]. That’s about 7% of all 2025 US power-sector emissions. Put another way, it’s the equivalent of running 27 coal power plants or putting 24 million more gas-powered cars on the road.
The backlash against America’s data center and artificial intelligence boom has been building for a while now, reaching a fever pitch over water use, land grabs and noise complaints. Recently, environmental activist Erin Brockovich has been mapping out communities affected by data center construction and operations, and polling shows that most Americans don’t want AI factories anywhere near them.
Now, it appears there’s a looming carbon problem to add to the pile.
Big Tech companies appeared publicly committed to cutting emissions just five years ago, making the new findings feel like a notable about-face. Financial Times found that Amazon’s emissions climbed 16% from 2024 to 2025, driven by data center construction and a 34% jump in electricity purchases. Microsoft reported a 25% increase in estimated emissions during the same period, while Google's parent company, Alphabet, reported an 18% year-over-year increase in its emissions figure according to its own adjusted metric.
Researchers point to a mix of causes, from the sheer scale of demand for AI infrastructure to a political environment under the Trump administration that dramatically rolled back climate rules and clean energy tax credits in favor of fossil fuels.
Data center construction has revitalized local activism. In May, Albany, New York, residents gathered at a rally for the AI data center moratorium.
On the grid side, the numbers tell a similar story. US gas-fired energy capacity under development nearly tripled in 2025, with FT's analysts predicting the country’s existing gas-burning infrastructure could grow up to 50% if everything currently planned is built.
Researchers say it’s not that clean energy additions have stalled entirely; rather, utilities are racing to meet data center demand with power that’s available now, and that runs around the clock. Fossil fuels (like gas and coal) fit the bill better than wind or solar until large-scale storage tech catches up.
That’s left the tech giants leaning harder on renewable energy credits to make up the dirty differences between their public commitments and what’s actually happening on the grids. But doing so is expensive and exactly the sort of thing likely to be scaled back over time as profitability pressure mounts.
Utilities, meanwhile, are increasing production to meet the mounting and projected demand, preparing to roll out tens of thousands of megawatts of energy capacity across the US specifically to serve data center infrastructure. Three-quarters of the operators serving these 60 sites are building or planning new gas capacity, and a third of those running coal plants are pushing back retirement dates.
This fresh wave of gas and coal plants occupies a small but rapidly growing portion of the US energy generation mix — trending in the opposite direction to what experts expected only a few years ago. The resulting environmental impacts and grid strains from these energy decisions are stacking up to just one more AI boom cost that nobody outside the tech industry signed up for.
The Fairphone 6 Plus is a refreshed version of the 6, with more RAM and a faster chipset:
The Fairphone 6 Plus is a minor hardware refresh, but a major launch for the company: It's the first phone that Fairphone is selling directly in the US. It's on sale now for $649.99, available through Fairphone's website and Amazon, and is sold unlocked with support for both T-Mobile and AT&T. In Europe, it costs €649, a €50 increase on last year's phone.
Fairphones from the 4 onwards have been available to buy in the US, but never from Fairphone itself. They were exclusively sold through a partnership with Murena, the developer of /e/OS, a "de-Googled" version of Android. That meant buyers were forced to use Murena's software — which is capable, but certainly an acquired taste — and paid a significant premium for the phone. Last year's Fairphone 6 sold for $899.
[...] Fairphone has been building up to the US launch of the 6 Plus, bringing audio products to Amazon US starting with the Fairbuds XL over-ear headphones last November. Alongside the announcement of the 6 Plus, the company has confirmed that a new pair of earbuds, the Fairbuds 2, will launch in Q4 this year, and "will set a new bar for repairability and performance." The company says it will reveal more in October.
Any Soylentils familiar with these phones, or Murena Android, or installing something else like LineageOS or GrapheneOS for the discerning person wanting a bit more control in their phones? Asking for a friend. --hubie
It started with avocados and ended with sensitive information being leaked.
Onstage at the Black Hat cybersecurity conference in Las Vegas, researchers Netanel Rubin and Dan Avraham pulled up an AI shopping assistant — the kind that's available inside most major retail apps to answer questions, compare products and help shoppers navigate a store's enormous catalog.
But the conversation didn't stay on groceries for long.
By the end of the demonstration, the researchers had bypassed the assistant's safeguards and forced code to run inside the computer environment behind it. The bot returned directory listings, environment variables and other information that an ordinary shopper should never be able to see.
In the wrong hands, that kind of information could give an attacker clues about the retailer's systems and potentially expose secrets or access that could be used in further attacks, putting both the company and, depending on what the AI can reach, its customers at risk.
The retailer wasn't a small online shop experimenting with a hastily assembled chatbot, either.
According to Rubin and Avraham's company Rein Security, it was one of the three largest retailers in the US, and the assistant was available through the same public mobile app used by everyday customers.
A few important notes: Rein Security sells technology designed to monitor AI agents and provide visibility into what those agents are doing. Rein also didn't identify the retailer, citing legal concerns. That means the findings cannot be independently verified with the retailer, and shoppers can’t know whether they’ve used the affected assistant.
The attack started with one of the assistant's most useful abilities: comparing products.
To answer certain questions, the AI can retrieve information from websites outside the retailer's control. That helps it gather more information for shoppers, but it also means the assistant can encounter material created by virtually anyone, including an attacker.
The researchers placed instructions in content they controlled and got the shopping assistant to retrieve them. Instead of treating that material only as information to summarize, the AI was manipulated into treating some of it as new directions to follow.
This is known as an indirect prompt injection. The malicious code can be hidden within a website, document, product listing or other material the AI encounters while trying to complete a legitimate task.
That alone wasn't enough to reach the system behind the assistant, but it gave the researchers a starting point.
The retailer had installed a security layer that examines conversations and attempts to keep the assistant focused on shopping. If you ask it something outside its approved role, the request could be rejected.
The researchers found that those protections weren't applied evenly. The main chat interface had safeguards in place, but the app's regular search field didn't have the same level of protection.
[...] The researchers said they reported the vulnerabilities on March 13. As of July 16, more than 90 days later, Rein said they had not been fixed. The company has not publicly provided a newer update on whether the problems remain.
[...] Retailers want these assistants to eventually build shopping lists, check inventory, manage orders and even complete purchases. But each new ability creates another potential risk if the AI can be tricked into following the wrong instructions.
In this case, the retailer's security system monitored what shoppers said to the AI and what it said back. According to Rein, it couldn't see everything happening in between, including information the assistant retrieved and tools it used.
That created a blind spot in which the security system could see the conversation, but not everything the AI was doing behind it.
[...] There isn't much an ordinary shopper can do to prevent this kind of vulnerability. The attack targeted the retailer's design, not a weak password or a customer mistake.
The responsibility belongs to companies giving AI assistants access to internal tools and information. Those systems have to assume that anything pulled from the open internet could contain instructions intended to mislead the AI — and put appropriate safeguards in place.
It's still wise to avoid sharing unnecessary personal information with shopping assistants, particularly if the bot can access previous orders or other account details. Keeping retail apps updated can also ensure you receive security fixes when they become available.
And that also leaves one enormous unanswered question: Which shopping assistant was it?
For now, the researchers aren't saying. But the demonstration shows what can happen as AI shopping assistants are given more control. If they can be tricked into following the wrong instructions, their most useful features can also become security risks.
Hackaday has an overview of why poly(lactic acid) (PLA) is so brittle, yet used all the time in 3D printing.
Over the years poly(lactic acid) (PLA) – also known as polylactide – has become a popular thermoplastic for a variety of reasons. One of these reasons is that it's easily produced from a renewable resource, i.e. lactic acid, with the resulting polymer even being compostable if you assume that your compost pile hits a steady 65°C or more, well above the polymer's glass transition temperature (Tg).
That said, PLA by itself is a pretty crummy material, being exceedingly brittle and inferior to common alternatives like PET(G) in many metrics. Over the decades much research has gone into figuring out this material, its amorphous and crystalline states, as well as how to use plasticizers, copolymers, mechanical manipulation and PLLA/PDLA blends to produce more useful variants of PLA.
Today's spools of thermoplastic filament that gets marketed as 'PLA' are the result of such engineering, though with plenty of remaining issues, as anyone who has struggled through a spool of brittle PLA filament can attest to. Although you can find plenty of tips online about how you should 'just' toss said spool into an filament dryer, oven or similar to bake it – with accusing fingers pointed at moisture intrusion, hydrolysis and kin – it helps to understand the fundamentals of how PLA works, and how it degrades.
Previously:
(2026) Investigating 3D-Printed Metals for Aeronautical Engineering
(2025) Bye-Bye Microplastics: New Plastic is Recyclable and Fully Ocean-Degradable
(2022) Innovative 3D-Printing Technology Creates Glass Microstructures With Rays of Light
(2021) Polymer Discovery Gives 3D-Printed Sand Super Strength
An AI broke Snowflake's code; then another AI, an attack agent, autonomously found the bug, exploited it, and extracted credentials without human intervention.
Luckily, this wasn't yet another case of rogue AI agents doing evil things. It was a sanctioned bug hunt, conducted through Snowflake's HackerOne vulnerability disclosure program, and Snowflake fixed the flaw the same day Wiz reported it and rotated the affected credentials the following day.
Wiz's red agent, an AI-powered autonomous attacker designed for offensive security, found the GitHub Actions workflow flaw during a routine scan of public repositories on June 23. The script injection vulnerability existed in snowflakedb/snowflake-connector-net, and it allowed an unauthenticated user to execute arbitrary commands within a GitHub Actions runner by opening a GitHub issue with a specially crafted title.
And it turned out an AI had inadvertently injected the bug into the code five days earlier.
GitHub Copilot Autofix, an AI coding assistant, co-authored the commit on June 18, and it introduced a script injection bug in run: blocks by removing the repository's existing sanitized input pattern and replacing it with direct string expansion in a shell script.
"We crafted an issue title that, after template expansion, breaks out of the echo string and exfiltrates the Jira credentials via an out-of-band callback," Wiz's head of threat exposure Gal Nagli said in a Monday blog.
These credentials gave Wiz read access to Snowflake's engineering, security compliance, and bug bounty tracking projects.
Wiz reported the workflow vulnerability to the cloud data platform on June 23, and Snowflake patched it the same day. It also revoked and rotated the Jira token, and confirmed, via audit logs, that Wiz was the only third-party to access the endpoint during the five-day exposure window.
The disclosure "was immediately investigated and remediated, and our investigation found no evidence of unauthorized access," a Snowflake spokesperson told The Register. "We are working together with Wiz to share these learnings with the broader industry to encourage widespread adoption of these security best practices."
Wiz, for its part, deleted all of the data it accessed during the vulnerability research and proof-of-concept exploit testing, and told us that this incident proves human code review isn't sufficient to quickly detect vulnerabilities - especially as developers increasingly use AI.
"This incident highlights a rapidly emerging reality in software development: how AI coding assistants can inadvertently introduce workflow injection vulnerabilities, and how automated AI agents can rapidly surface them in the wild," Nagli wrote.
Of course, the Google-owned biz has a vested interest in saying this. But this doesn't make it not true.