From Hacker News Front Page · 40 stories
MS Paint and Photos embed invisible GUID watermarks in AI-generated images
Microsoft's Paint and Photos applications invisibly watermark AI-generated images, even those created locally, with a GUID after sending prompts to a remote server for moderation. This occurs regardless of visible watermark settings and applies to images saved in C2PA-preserving formats like PNG, JPEG, GIF, and .paint. The practice raises questions about user privacy and the traceability of AI-generated content.
DuckDB v2.0 "Cyanoptera" to Introduce Server Mode, New SQL Parser, and Storage Format
DuckDB v2.0, codenamed "Cyanoptera," is scheduled for release this fall, bringing a new SQL parser, a new default storage format, and a reworked C API. The update's most significant feature is the introduction of a stable client/server mode, allowing DuckDB processes to serve databases over a network and connect to remote databases like PostgreSQL and MySQL.
Thomson Reuters Develops Proprietary AI Model for Legal and Tax Work
Thomson Reuters has developed its own AI model, named Thomson, for legal, tax, and compliance tasks, trained on its proprietary content. This model will power specific features within products like CoCounsel, while the company continues to use third-party models like Anthropic's Claude for other functionalities. This approach allows companies with extensive proprietary data to create specialized AI without building a foundation model from scratch.
Slovakia discovers Russian backdoors and vulnerabilities in 279 new traffic cameras
Slovakia's national security service, the NBU, found SMS-activated Russian backdoors and passwordless live feed access in 279 new NERO R-ONE speed cameras. These cameras, suspected to be rebranded Russian CORDON PRO.M units, were part of a €30 million EU-funded modernization project and have since been deactivated. The discovery highlights significant national security and privacy risks associated with critical infrastructure procurement.
Wi-Fi 8 focuses on reliability and effective throughput over raw speed increases
The IEEE is developing Wi-Fi 8, dubbed "Ultra High Reliability," which will prioritize network reliability and effective throughput rather than increasing maximum theoretical data rates. This marks a shift from previous Wi-Fi generations that primarily focused on speed enhancements, aiming to improve performance in non-ideal conditions and reduce latency.
New technique "skitter-creek-bath-salts" bypasses DRAM memory protections on AMD CPUs
A new technique called "skitter-creek-bath-salts" allows manipulation of DRAM controller registers to scramble platform memory, bypassing security features like the Platform Security Processor, System Management Mode, and CPU microcode. This method was developed and tested on AMD Family 16h CPUs, which are the last generation with publicly documented DRAM controller translation registers.
NVIDIA Releases Magpie Multilingual TTS with Open Weights and Expanded Language Support
NVIDIA has released an update to its Magpie Multilingual Text-to-Speech (TTS) model, offering open weights and support for 12 languages, including new additions like Modern Standard Arabic, Korean, and Brazilian Portuguese. This release allows developers to deploy and customize multilingual speech generation within their own infrastructure, aiming to reduce latency and meet specific data residency and privacy requirements for voice AI applications.
Rust Enables Polonius Alpha Borrow Checker on Nightly Builds
The Rust team has enabled the Polonius Alpha borrow checker on nightly builds, preparing for stabilization in the coming months. This new iteration allows more code to compile by enabling flow-sensitive borrow checking of lifetime outlives relationships, addressing limitations of the current NLL borrow checker.
India introduces legislation to allow merchant fees on UPI transactions
India is enacting new legislation to enable merchants to pay charges on some transactions made through its Unified Payments Interface (UPI) network. This policy shift aims to create a sustainable business model for UPI, which has operated without merchant fees since 2020, by allowing payment companies to recover infrastructure and operational costs.
Microsoft Edge to End Support for Manifest V2 Extensions, Impacting Ad Blockers
Microsoft Edge is ending support for Manifest V2 extensions, a move that will disable older ad blockers like uBlock Origin, mirroring a change previously made by Google Chrome. This transition means users of these specific extensions will need to switch to newer MV3 versions or alternative browsers, as MV3 limits the functionality of ad-blocking extensions.
Claude Code Defaults to Auto Mode for Pro, Max, and Team Plans
Anthropic has made auto mode the default setting for Claude Code on Pro, Max, and Team plans, effective August 14. This change allows for longer autonomous operations by replacing manual approval prompts with an automated classifier for tool calls, which Anthropic states improves safety and efficiency. The company has also stopped charging for the extra tokens used by the auto mode classifier.
AI Watermark Removal Tools Emerge, Efficacy Unverified Against Text Watermarks
A market for tools claiming to remove AI watermarks has appeared following Anthropic's announcement of invisible watermarks in Claude's output. However, the efficacy of these tools against text watermarks cannot be verified because Anthropic has not released details on its watermarking method or a corresponding detector. This development highlights the ongoing challenge of verifying AI-generated content and the rapid response from developers to new AI features.
Lovable Secures $400M Series C Funding, Reaching $13.3 Billion Valuation
Lovable, a European software creation platform, has raised $400 million in Series C funding, bringing its valuation to $13.3 billion. The round was led by Menlo Ventures and the Scaleup Europe Fund, with participation from over a dozen other investors. This funding follows Lovable reaching $500 million in annualized run rate revenue and expanding its infrastructure, including a multiyear deal with Google Cloud.
US Recruits Over 2,000 Video Gamers for Air Traffic Control Roles
The U.S. Department of Transport (USDOT) and Federal Aviation Administration (FAA) have successfully recruited over 2,000 video gamers for Air Traffic Control (ATC) positions, meeting 94% of their hiring goal. This initiative, launched in April, leveraged transferable skills from gaming such as spatial awareness and rapid problem-solving to address staffing needs in aviation.
Wisconsin Police Used Flock Cameras to Track Man for Marijuana Possession
Wisconsin police utilized Flock license plate readers to track Edward Abrams-Phillips' frequent travel between Wisconsin and Michigan, where marijuana is legal. This tracking was used as part of the probable cause to search his car for marijuana, leading to his arrest and conviction for possession, despite an initial bail jumping charge being dismissed. The case highlights concerns regarding law enforcement's use of surveillance technology to establish pretexts for searches.
Anthropic's Claude AI Improves Riemann Hypothesis Lower Bound to 67.2%
An unreleased research version of Anthropic's Claude AI has increased the known lower bound for the fraction of Riemann zeta function zeros satisfying the Riemann hypothesis from 41.6% to 67.2%. This development, achieved by an AI model without significant mathematical training, demonstrates progress in AI's mathematical problem-solving capabilities.
Linux Desktop Market Share Reaches Over 10% in North America, Data Suggests
Statcounter reported that Linux desktop usage in North America reached 10.65% in July 2026, marking its first time in double digits for the region. This increase is partly attributed to a reduction in Statcounter's "Unknown" category, suggesting improved classification rather than a mass migration of users. Other data sources, including the US federal government's Digital Analytics Program and Cloudflare, also indicate significant Linux desktop usage, with Cloudflare observing a peak of 22% on a specific workday.
New York and Illinois Enact Age Verification Laws for Online Platforms and OS
New York's SAFE for Kids Act, effective January 25, 2027, requires social media platforms to implement age verification for algorithmic feeds and late-night notifications. Concurrently, Illinois' Children's Online Social Media Safety Act (HB5511), effective January 1, 2028, mandates age verification at the operating system level for devices sold or used in the state, impacting device manufacturers, OS providers, and app stores.
Security Researcher Receives 400,000 Sensitive Emails Due to Misconfigured 'Noreply' Domains
Security researcher Cory Solovewicz has received over 400,000 emails containing sensitive personal and company information since December 2024. This data leakage occurs because organizations are misconfiguring their internal systems to send information to his purchased domains, noreply.us and noreply.net, which they mistakenly believe are unmonitored placeholder addresses.
Windscribe Releases deGDID Script to Block Microsoft's Global Device Identifier
Windscribe, a VPN provider, has developed an open-source PowerShell script called "deGDID" that removes existing Microsoft Global Device Identifiers (GDIDs) from Windows PCs and prevents new ones from being created. This tool addresses privacy concerns related to persistent device tracking, but using it may disrupt some Microsoft cloud services that rely on device authentication.
New CSS Attacks Bypass Webmail Defenses, Enabling Password and Token Theft
New research by PortSwigger's Gareth Heyes, presented at Black Hat USA 2026, demonstrates CSS-based attacks that allow email content to escape its message boundary and interact with webmail interfaces. These techniques can capture passwords, exfiltrate tokens, and hijack UI actions across major webmail providers like Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail.
Denmark Implements Oral Defenses and Supervised Writing to Combat AI Cheating in Schools
The Danish government has introduced new measures for upper secondary schools to address AI cheating, including mandatory oral defenses for all written assignments completed at home and supervised in-school writing. These changes, effective immediately, apply to students aged 16-19, including approximately 9,000 students in the two-year HF program, and aim to establish clearer guidelines for AI use in education.
Daniel K. Inouye Solar Telescope Observes Kelvin-Helmholtz Instabilities on Sun's Surface
Scientists using the Daniel K. Inouye Solar Telescope have observed Kelvin-Helmholtz Instabilities (KHI) on the Sun's surface, appearing as small swirling patterns. This discovery, published in Nature, provides the highest-resolution image of the Sun's visible surface and may explain how the Sun's outer atmosphere heats up and how magnetic energy builds and moves, influencing solar flares that impact Earth's technology.
Civilian Medevac Plane Crash in New Mexico Linked to Military GPS Jamming
A twin-engine Beechcraft King Air medevac plane crashed in New Mexico, killing all four occupants, after encountering GPS jamming from a US military exercise at White Sands Missile Range. The incident, which occurred in May, marks the first fatal civilian plane crash in the US attributed to GPS jamming, raising concerns about the impact of military electronic warfare activities on civilian aviation.
28.9M Parameter LLM Runs on $8 ESP32-S3 Microcontroller Using Flash Memory
A 28.9 million parameter language model has been successfully run on an ESP32-S3 microcontroller, which costs approximately $8. This was achieved by storing most of the model in flash memory rather than RAM, a technique inspired by Google's Per-Layer Embeddings, allowing significantly larger models to operate on resource-constrained edge devices.
US Tech Giants' Hidden Debt Reaches $1.65 Trillion Due to AI Investments
Hidden debts among five major U.S. tech companies have surged to $1.65 trillion, driven by AI-related investments and long-term contracts. These liabilities exceed the $1.35 trillion reflected in official financial statements, complicating investor risk assessment.
Arch Linux Disables AUR Package Adoption and Pushes Due to Malware Influx
Arch Linux has disabled package adoption and pushes in its Arch User Repository (AUR) following an increase in malicious package adoptions and commits. This measure was taken to prevent the spread of malware, including remote-access trojans (RATs) and info-stealers, which attempt to upload user data and spread laterally across systems. The disablement is temporary while the Arch Linux DevOps team addresses the security situation.
Judge Dismisses Google's DMCA Scraping Lawsuit, Reddit's Similar Case Proceeds
A judge dismissed Google's lawsuit against SerpApi, which alleged DMCA 1201 violations for scraping Google's search results, finding Google's claim unfounded. However, Google plans to refile its complaint. Separately, a judge largely denied SerpApi's motion to dismiss a similar lawsuit from Reddit, allowing Reddit's DMCA claim regarding scraping copyrighted content from Google search results to proceed.
Kimi K3: New 2.8 Trillion-Parameter Open AI Model with Vision Capabilities Released
Kimi has introduced Kimi K3, a 2.8 trillion-parameter AI model with built-in vision capabilities and a 1-million-token context window. This open-source model, while not as powerful as proprietary models, shows competitive performance across various benchmarks, including a strong showing against Fable 5. Kimi K3 offers new potential for AI applications but faces cost and speed challenges.
H96 TV Streaming Sticks Implicated in Ad Fraud and Proxy Network Operation
Bitsight researchers uncovered a widespread ad fraud operation, named Fuyao and attributed to Zhejiang Fengwo IoT Technology Co., Ltd., involving H96 TV streaming sticks. These devices spoof mobile phones to click ads on AI-generated websites and also function as SOCKS5 proxy exit nodes, while secretly collecting user hardware and installed app information. This activity highlights security vulnerabilities and fraudulent practices within generic streaming devices, impacting online advertising and user privacy.
Valve Funds Port of Open-Source RADV Vulkan Driver to Windows
Valve is sponsoring Collabora developers to port the open-source RADV Vulkan driver, a key component of the Linux graphics stack for AMD GPUs, to Microsoft Windows. This initiative aims to bring an open-source Vulkan implementation to Windows users, offering benefits like a shared codebase and easier debugging across platforms, and has already enabled games like Counter-Strike 2 to run.
AMD Releases Ryzen AI Halo, a $4,000 Local AI Development Platform
AMD has launched the Ryzen AI Halo, a $3,999.99 mini-PC for local AI development, powered by the Zen 5 Ryzen AI Max+ 395 processor. It includes integrated graphics, ample memory, and comes preloaded with Windows 11 Pro or a custom AMD Linux. While user-friendly, its performance is noted to lag behind Nvidia's similar offerings.
LM Studio Unveils Bionic AI Agent for Mac with Privacy-Focused Open Model Support
LM Studio has launched Bionic, a Mac app leveraging open AI models to handle tasks such as coding and document processing. Bionic supports both local and cloud-based models, ensuring user privacy with a Zero Data Retention policy. This development offers flexible computational environments for users, emphasizing control over data security and cost.
Minecraft: Java Edition System Requirements Increase to 16GB RAM, Newer CPU
Mojang has updated the system requirements for Minecraft: Java Edition, raising the recommended system memory from 4GB to 16GB and suggesting a 2020s or newer CPU. This is the first such increase in 17 years and aims to ensure smooth performance with advanced features, including preparation for a transition from OpenGL to Vulkan.
Indian Government Orders GitHub to Remove Bluetooth-Based Chat App Bitchat
The Indian Cybercrime Coordination Centre (I4C) has ordered GitHub to remove the Bluetooth-based messaging application Bitchat, citing concerns that it enables communication during network restrictions and poses a risk of misuse by various illicit groups. This action highlights government efforts to control communication channels, particularly those that bypass traditional surveillance methods, impacting developers of privacy-focused communication tools.
Black Forest Labs Launches FLUX 3 Multimodal AI for Image and 20-Second Video Generation
Black Forest Labs (BFL) released FLUX 3, a multimodal AI model capable of generating images and video clips up to 20 seconds with audio from a single prompt. This release marks BFL's first public video generation model and aims to connect creative generation, simulation, computer use, and robotics through a single visual intelligence capability.
Firefox 153 Introduces Native Containers for Better Privacy Management
Firefox 153 introduces a native Containers feature, allowing users to separate online activities by context within the same browser. This integration enhances user privacy by isolating cookies and ad tracking across different accounts and workflows.
Judge Dismisses Lawsuit Against Apple Over iCloud CSAM Detection
A lawsuit accusing Apple of not preventing child sexual abuse material (CSAM) on iCloud was dismissed by a California judge. The company was ruled immune under Section 230, shielding it from liability for user-uploaded content. The case highlights ongoing debates about tech companies' roles in moderating content on their platforms.
Hacker Attack Disrupts Romania's Land Registry Operations
Romania's land registry agency suffered a cyberattack, resulting in the wiping of its database and a halt in real estate transactions. The agency is migrating its systems to the government cloud to restore operations while ensuring data integrity.
Eminent Domain Used to Acquire Land for Data Center Infrastructure
Power companies in the U.S. are using eminent domain to secure land for building transmission lines essential for data center infrastructure. This legal approach, which allows the government to seize private property for public use, has sparked public opposition due to environmental concerns and higher utility bills. With the AI boom expanding data center construction, the use of eminent domain raises questions about property rights and community responses.