Skip to main content

Posts

Slashdot: Asos Confirms Hackers Sent 'Unauthorized' Notification to App Users

Asos Confirms Hackers Sent 'Unauthorized' Notification to App Users Published on 2026-10-06T20:00:00Z ASOS says hackers gained unauthorized access to third-party platforms it uses and sent an "ASOS HACKED" push notification directly to customers, apparently as part of an extortion attempt. The clothing and beauty store says some basic personal information may have been accessed but does not believe payment-card data or passwords were affected. The BBC reports: In an email to customers on Tuesday night, the company apologized and urged customers not to engage with the notification. And it said the website and app are "operating as usual" promising customers they can "shop with confidence" while it investigates the incident. The company has not as of yet informed the UK's data watchdog, the Information Commission's Office (ICO), about any breach. Exactly how many Asos customers received the notification on Tuesday remains unclear, but Goo...

Slashdot: IBM and Red Hat Find More Than 400 New Vulnerabilities In Popular Java Code

IBM and Red Hat Find More Than 400 New Vulnerabilities In Popular Java Code Published on 2026-10-06T19:00:00Z IBM and Red Hat say their AI-powered Lightwell initiative has identified and helped remediate more than 400 previously unknown vulnerabilities across widely used Java libraries. Phoronix reports: They announced this feat today as part of their promoting Lightwell Clearinghouse to GA, which is an enterprise service for their customers to submit open-source software dependencies for priority review and remediation. From today's announcement: "The milestone addresses a growing business risk. As autonomous AI agents become capable of combining several lower-risk software weaknesses into a more serious attack, companies need to do more than identify vulnerabilities. They need a practical way to develop, test and deploy fixes in the software that supports critical applications." Read more of this story at Slashdot.

Slashdot: Hackers Steal 8 Million Citizens' Records From Danish Government Database

Hackers Steal 8 Million Citizens' Records From Danish Government Database Published on 2026-10-05T22:38:00Z Hackers stole records belonging to roughly 8 million Danish citizens and residents from Denmark's Central Person Register (CPR), including names, addresses, social security numbers and other personal information. The breach is believed to be the largest in Denmark's history. TechCrunch reports: The CPR is a government database of Danish citizens' information, including their government-issued identity number for paying taxes and accessing other services. Denmark's current population is about 6 million people, but the database includes records for about 11 million people, with some of the data going back decades. The Danish government would not say who is behind the breach, which happened in September but was discovered on October 2. However, it said the unauthorized access was obtained by "abusing a Danish company's lawful access to search for inf...

Slashdot: Wikipedia Operator Says OpenAI's 'Rogue' Bots May Be Linked to a May Outage

Wikipedia Operator Says OpenAI's 'Rogue' Bots May Be Linked to a May Outage Published on 2026-10-05T21:00:00Z The Wikimedia Foundation says it found evidence that "rogue" OpenAI agents edited Wikimedia wikis without approval, unsuccessfully tried to exploit its Etherpad service, and generated millions of automated requests across Wikimedia projects. Here's a summary of what Wikimedia observed (via The Verge): Wiki editing: We've identified edits to Wikimedia wikis that we believe are from AI agents operated by OpenAI. These edits were not published to pages with visibility to general readers; almost all of them were testing edits in "sandbox" areas of the wiki. It also included a few edits to the configuration for a citation tool, which we believe were potentially malicious edits that were intended to misuse this tool as a proxy for fetching data from remote services. While Wikipedia policies allow bots to edit when they are disclosed and appro...

Slashdot: Meta Rushed To Fix Muse 'VM Escape' Vulnerability Soon Before Launch

Meta Rushed To Fix Muse 'VM Escape' Vulnerability Soon Before Launch Published on 2026-10-05T20:00:00Z An anonymous reader quotes a report from 404 Media: In the immediate weeks before Muse's launch, Meta engineers found several security vulnerabilities in the company's viral AI agent product, at least one of which could have allowed malicious users to break outside of Muse's intended environment and access Meta's own sensitive databases and services, 404 Media has learned. The issues were so severe that they reached Mark Zuckerberg and staff worked overtime to fix them. These specific vulnerabilities were discovered before the launch of the product but required a multi-team "mad dash" to fix "a sudden spike in reported KVM escapes," according to an internal post by Meta executives to its core infrastructure team seen by 404 Media. In order for Muse to work, a user gives the AI agent access to various important services and accounts that th...

Slashdot: Norway Plans Temporary Ban on Smart Glasses

Norway Plans Temporary Ban on Smart Glasses Published on 2026-10-05T19:00:00Z Norway is preparing legislation that would temporarily ban camera-equipped smart glasses in a range of public places, including parks, beaches, museums, shopping centers, schools, daycare centers, healthcare facilities, gyms and public events. Private use would still be allowed. The Guardian reports: Torgeir Micaelsen, Norway's minister of digital affairs, said he was worried that new, powerful technology is being introduced where people risk being photographed, filmed or audio-recorded without knowing it." "We do not want a society where people worry about being recorded without their knowledge, photographed or filmed in places and situations where they are accustomed to not being monitored," he said. Norway's Labour party, which heads a minority government, needs the support of other parties to pass the proposed ban. It said it planned to submit a bill "as soon as possible,...

Slashdot: How Python Will Test Adding Rust Into CPython

How Python Will Test Adding Rust Into CPython Published on 2026-10-04T21:37:00Z Python's security developer-in-residence Seth Larson reports from this year's official core developer Python Language Summit: "No one said 'don't do this' last year". After testing the waters at PyCon US 2025, [software engineer] David Hewitt returned to the Python Language Summit asking what Python core developers want from Rust, along with proposed timelines, phases, and success criteria for how the Rust for CPython project might proceed and become a permanent fixture within the CPython project. David is acting as an "ambassador" for the Rust for CPython project team, which is currently led by core developers Kirill Podoprigora and Emma Smith as authors of the Rust for CPython PEP draft. Emma also spoke at PyCon US 2026 about the Rust for CPython project. The team itself is around 60 developers in a Discord channel, among them a "few [Python] core developer...