The Almighty Buck

AliExpress Hit With Record $625 Million Fine After Failing To Make EU-Ordered Fixes (arstechnica.com) 88

The European Commission has fined AliExpress more than $625 million, the largest penalty yet under the Digital Services Act, after finding that the marketplace failed to "diligently assess and mitigate risks relating to the sale of illegal, unsafe, or counterfeit products on its e-commerce platform." EU officials said flagged products repeatedly reappeared, sellers could evade safeguards, and AliExpress's recommendation and ad systems helped amplify dangerous goods. Ars Technica reports: For shady sellers, the risks of detection appeared low. The e-commerce site's mandatory brand authorization system was also ineffective and understaffed, the EC found, and AliExpress did not penalize traders for selling illegal products as its policy claims it would. Making things worse, AliExpress "inadequately assessed how its recommender and advertising systems exacerbate the spread of illegal products," the EC said. So rather than remove illegal products, AliExpress was recommending them to consumers and helping to maximize exposure. Talking to the press, the European Union's tech chief, Henna Virkkunen, noted that one in five Europeans shop monthly at retail sites like AliExpress, Temu, and Shein.

AliExpress also relied on a single quantitative metric to gauge how effectively its systems were working to weed out illegal products. And that metric did not properly measure the extent of the harm. EC testing found that "a high volume of illegal products" -- including unsafe toys and dangerous cosmetics -- "continued to circulate despite AliExpress' moderation efforts." In June 2025, AliExpress was ordered to bring its platform into compliance with the DSA but failed to make the necessary changes, the EC said. The fine was calculated to be proportionate to the nature of the violations, which the EC considered "particularly serious infringements," and to penalize AliExpress's delayed interventions to mitigate flagged risks.

[...] AliExpress told Ars it was "surprised" by the "disproportionate" fine. AliExpress said it plans to appeal the decision, claiming the EC ignored its "sound risk management framework and the significant, proactive enhancements we have made." The massive online retailer noted that its EU market is substantially smaller than its China market and said that it invests "substantial resources in risk assessment and mitigation, product safety and consumer protection" and "has been and continues to be committed to meeting our obligations to consumers."

Security

Hacker Wipes Romania's Entire Land Registry Database (cybernews.com) 52

A hacker reportedly wiped Romania's entire land registry database after a failed extortion attempt, halting property transactions across the country and preventing notaries from issuing land extracts, authenticating sales, or registering mortgages. "On the dark web, the hacker also boasted to have begun backup copies of stolen data in an attempt to prevent it from being restored," reports Cybernews. "However, Romanian officials have managed to at least restore the ANCPI's website and post a message saying they were rebuilding the agency's entire network from scratch. It appears that the agency has an offline copy of the wiped data." From the report: First, the hacker breached Romania's cadastre agency, the National Agency for Cadastre and Real Estate Advertising (ANCPI), posting on a hacking forum: "[RO] Thy arss shall be spanked, Romania! [ANCPI]." "In addition to the data of Romanian citizens, from various databases collected through ANCPI networks, there is also a copy of the GitLab servers containing the source code of all their systems, such as Eterra, RENNS, as well as a version of my little ransomware program," the announcement continued.

"The official government website announced a shutdown of IT systems due to 'technical problems,' but this is a bit of an understatement. An offer of assistance was made, but without insistence or pressure." Indeed, the ANCPI initially claimed technical issues but had to admit it was facing a cyberattack. Today, no one can really access the institution's systems. And since the extortion didn't work, the hacker -- who seems to have entered the database using valid credentials -- deleted all data they had stolen, including internal documents, employee credentials, and, of course, land registry data.

EU

France Orders ISPs to Block Access to Polymarket (engadget.com) 19

France's regulatory authority for licensed gambling/betting games "announced this week that it ordered ISPs to block access to Polymarket," reports Engadget. Anyone caught advertising an unauthorized betting site "could be fined up to 100,000 euros, or around $114,000." (The article notes this follows a previous regulatory action from November placing a geoblock on financial transactions from French residents on Polymarket's site.)

In May Spain blocked access to Polymarket and Kalshi while it launched a gambling license investigation.
Security

Iran Abused Mobile Networks' Vulnerabilities To Locate US Military In Middle East (techcrunch.com) 147

An anonymous reader quotes a report from TechCrunch: The Iranian government abused well-known vulnerabilities in the global telecoms infrastructure to locate U.S. military personnel in the build-up to the Iran War, as well as in the early days of the conflict, according to Financial Times. The Iranian government exploited Signaling System 7, or SS7, a set of protocols for 2G and 3G networks that has long been the backbone of how cellular networks connect to each other to route subscribers' calls and texts around the world, the newspaper reported, citing research by the Mobile Surveillance Monitor, as well as anonymous government officials with knowledge of the spy campaign.

Intelligence agencies have long abused SS7 to track cellphones abroad, which is what happened in this campaign. Using this technique, Iran was reportedly able to locate U.S. military forces stationed in military bases as well as hotels in Iraq, Bahrain, and other countries in the Middle East, which allowed the regime to strike them. These attacks resulted in several injuries. Apart from SS7, Iran also abused advertising technology used to serve tailored ads to cellphone users, another well-known surveillance technique that relies on everyday technology.

Youtube

DuckDuckGo's Browser Now Blocks Most YouTube Ads (nerds.xyz) 81

Nerds.xyz reports: DuckDuckGo just gave its browser a feature that a lot of people have been waiting for. The privacy-focused browser can now block most video ads on YouTube, letting users watch videos without sitting through the pre-roll and mid-roll interruptions that have become part of everyday life on the platform. The feature is already enabled by default for iPhone, Windows, and Mac users running the latest version of the browser. Android users can turn it on manually... with DuckDuckGo planning to enable it by default in a future update...

To make it work, DuckDuckGo relies on the same community-maintained filter lists used by uBlock Origin, along with some of its own compatibility rules. The company says you might notice a bit of extra buffering before a video starts, but once playback begins, most ads should be gone.

Slashdot reader BrianFagioli argues that the feature raises questions about how creators are compensated when ad revenue is bypassed.
Facebook

Meta Says US States Seek $1.4 Trillion In Penalties In August's Youth Safety Trial (yahoo.com) 39

Meta "said in a court filing on Monday that four states were seeking $1.4 trillion in penalties," reports Reuters, "over accusations the company designed its Facebook and Instagram platforms to addict young users and misled the public about their safety." Meta put forward the figure in its response to the attorneys general's filings on how penalties should be calculated if the states prevailed at trial. The number, which has not previously been disclosed and is close to Meta's market capitalization of around $1.5 trillion, comes ahead of an August trial in Oakland, California, over the claims brought by California, Colorado, Kentucky and New Jersey against the company. Meta said the amount was unsupported by the evidence. "A sanction of that size has no analog in the history of consumer protection enforcement," the company said in the filing. "The plaintiffs' outlandish calculations have no basis in fact or law," the company said in a statement, adding that it would continue to defend itself against the states' demands.

A spokesperson for California Attorney General Rob Bonta said in a statement the lawsuit "alleges Meta has prioritized profits over the safety of kids and fueled the mental health crisis we see impacting a generation of American children. The California Department of Justice looks forward to holding Meta fully accountable at trial in August...."

Meta has denied the allegations, saying the attorneys general have no evidence it misled consumers about its platforms' alleged addictiveness because "social media addiction" is not an established psychiatric condition, and therefore statements that its platforms were not addictive could not be false... Last month, [U.S. District Judge] Rogers rejected Meta's bid to cancel the trial, saying there remained factual disputes over whether its social media platforms were addictive, whether Meta falsely denied it designed them that way, and whether it "partially" directed the platforms at children.

"A further 14 states have brought claims under their own laws, which will be heard at a separate trial in February..."

Thanks to Slashdot reader Sparkatron for sharing the article.
Piracy

Amazon Blames Piracy Apps With Malware For Killing New Fire Stick Sideloading (arstechnica.com) 32

Amazon says it is ending sideloading on new Fire Sticks because "apps that facilitate piracy, and other apps, can carry malware," adding that there is "a good amount of evidence" that sideloaded apps may contain unwanted code or behavior. However, the company did not provide specific examples of Fire Stick users being harmed. Ars Technica reports: Amazon has released two Fire Stick models that use its proprietary, Linux-based operating system, Vega OS. Previous Fire Sticks ran Fire OS, which is an Android fork based on the Android Open Source Project. One of the biggest differences between Vega OS and Fire OS is that the former doesn't support sideloading. [...] In a recent interview, Or Goren, editor-in-chief of Cord Busters, a UK-based streaming news outlet, noted the negative reaction to Vega being a closed OS. [Aidan Marcuss, VP of Fire TV, advertising, and Appstore] responded, per the publication, by saying that Vega OS was Amazon's opportunity to "innovate and deliver more capabilities, even on the least expensive devices."

He also said that making a platform around security and privacy was "sort of utmost in my mind." The statement is somewhat ironic, considering Vega OS blocks custom launchers and other third-party apps that helped users avoid Amazon tracking and ads. Goren asked whether Amazon had evidence that sideloaded devices caused users harm. "Apps that facilitate piracy, and other apps, can carry malware," Marcuss responded. Marcuss also said that there is "a good amount of evidence that apps can carry unwanted code and behavior on them when they're sideloaded."

Marcuss didn't provide specific examples of Fire Stick users being hurt by sideloaded apps. There are some potential examples, though. In 2025, Amazon claimed to blacklist (which blocked the apps from being sideloaded to Fire Sticks) four video streaming apps for malicious behavior. At the time, AFTVnews reported that two of the apps served as residential proxy providers and were considered riskware, and that the other two had APK files that were flagged by virus-scanning tools. Safari and Chrome also flagged one of the apps' official websites, the publication reported. And in 2018, a botnet that infected Android devices with cryptocurrency-mining malware appeared on some Fire Sticks, per discussion on XDA Forums. That said, Amazon also has a history of disabling apps that let users circumnavigate its home screen that Fire devices, including Fire Sticks and Fire TVs, have increasingly used for ads.
Worth noting: developers can continue sideloading apps onto Vega OS devices if they register them with Amazon.
United States

US Agency Cancels Contract For Warrantless Tracking of Mobile Devices (apnews.com) 18

America's Bureau of Alcohol, Tobacco, Firearms and Explosives has "canceled its contract for a surveillance tool that enables warrantless tracking of mobile devices," reports the Associated Press.

They note the move comes "after lawmakers, a prosecutor and a judge raised concerns about the legality of the tool in criminal investigations." ATF, the federal agency responsible for enforcing the nation's gun laws, told The Associated Press that it discontinued what it called a "pilot" program using a tool called Webloc after Rep. Michael Cloud, a Republican from Texas, and Sen. Ron Wyden, a Democrat from Oregon, expressed reservations about the agency's use of bulk commercial location data. Webloc, which is made by a vendor called Penlink, sources data from consumer apps and advertising networks, which collect the location of mobile devices from consumers who download apps or browse the web...

The U.S. Supreme Court ruled in 2018 that police needed a warrant to obtain historic movement data from cellphone companies on a criminal suspect. But it has never addressed the growing practice of commercially acquired data.

Other users of Webloc include the U.S. military and U.S. Immigration and Customs Enforcement but also local law enforcement agencies such as police in places like Elk Grove, Calif. and Durham, N.C. The technology has also expanded around the world, with the national police in El Salvador and Hungarian intelligence agencies as customers, according to a report from earlier this year from Citizen Lab, a group of researchers at the University of Toronto who investigate digital threats to civil society.

The article notes that other U.S. law enforcement agencies continue to buy commercial geolocation data, "including the FBI and the Department of Homeland Security."
Businesses

Walmart, In Biggest Deal In Two Years, Buys Advertising Tech Firm Vibe.co (adexchanger.com) 11

Walmart is acquiring self-serve connected-TV ad platform Vibe.co for a reported $1.4 billion, adding it to an advertising ecosystem that already includes smart-TV maker Vizio. AdExchanger reports: On Tuesday, Walmart announced that it is buying Vibe.co, the French self-serve ad platform that specializes in helping small brands buy streaming commercials with similar ease and precision as they get from search and social. Vibe has been vying for a bigger share of the ad dollars moving to connected TV, especially in the US, as evidenced by the company's ubiquitous billboards in major cities including New York and San Francisco. Now, Vibe joins Walmart Connect's commerce ecosystem alongside the smart TV maker Vizio. And Vibe's tech is poised to help unify Walmart's growing CTV footprint with the closed-loop attribution provided by its retail sales data.

[...] Together, Walmart and Vibe.co strive to "build the best ecosystem for the performance TV market," Vibe CEO and Co-Founder Arthur Querou told AdExchanger. Performance CTV has a high ceiling for growth. The performance budgets dedicated for streaming platforms are still small potatoes compared to search and social, Querou said. Only one-quarter of CTV ad campaigns have lower-funnel objectives, and that number has been static for years, according to data from Advertiser Perceptions. Now that Walmart owns both Vibe and Vizio, advertisers should have an easier time tying streaming campaigns to shopper data. That promise stands to win Walmart more marketing dollars earmarked for retail media and streaming behemoths -- including Amazon.

Walmart is especially interested in attracting more small- and medium-sized businesses (SMBs) who lack the tools, budgets or teams to invest in streaming TV, a Walmart spokesperson told AdExchanger. Other ad platforms, including MNTN and Magnite, have likewise targeted SMB advertisers as a source for continued growth in the CTV market. By adding Vibe.co, Walmart can court SMBs with the pitch that its new self-serve tools will make it easier for them to execute CTV campaigns. Plus, SMBs tend to prioritize performance campaigns, since they are under more pressure to justify tighter ad budgets and thus have to be more selective about which platforms they advertise on. And Walmart is better positioned than most platforms to prove its ads drove performance thanks to its retail data foundation.

Social Networks

Polymarket Paid Dozens to Post Videos of Themselves 'Winning' With Fake Bets (msn.com) 34

In January a college student posted a video showing him winning $100,000 on Polymarket — one of 145 that appeared to show bets adding up to almost $410,000, reports the Wall Street Journal. "But none of those bets were real."

Instead its creator was "one of dozens of mostly college-age creators Polymarket paid to film themselves making fake trades and sometimes scoring fake wins," the Journal reports, citing interviews with the creators an an analysis of more than 1,100 of their videos: Polymarket built near-perfect copies of its website, then instructed creators to make simulated trades on those dummy sites and hide that they were being paid by Polymarket. To get the videos to go viral, Polymarket has recruited a social-media army to copy and re-post creators' footage. Though the New York-based company has been banned from offering its primary crypto platform in the U.S. since 2022, the social-media creators are paid to specifically target U.S. users, who can still access the site with a virtual private network...

Polymarket hired and worked closely with a marketing contractor to promote the site. In a message reviewed by the Journal, that contractor told its social-media army to repost content made by 10 Polymarket creators in particular... These creators didn't initially identify themselves as paid by Polymarket, although one offered a $20 bonus code in his social-media bio... The company instructed creators not to disclose they are paid, according to creators who have worked with the company. They said the pay often added up to $2,000 to $3,000 a month...

A handful of videos the Journal reviewed also contained short glimpses of URLs indicating the sites were test environments for Polymarket engineers... Creators said they send the finished videos to Polymarket for review. If a video isn't engaging enough, or if it bears obvious signs of being faked, Polymarket will ask for the videos to be reshot, the creators said... Polymarket sends creators bullet-point guidance on what to say, according to creators who have worked with the company and a recruiting website... Polymarket's viral clipping campaign racked up more than 140 million views on TikTok, YouTube and Instagram, according to the analytics provider Tubular...

Internal materials show that Polymarket and Virality promote videos showing how easy it is to conduct insider trades on the platform. Polymarket has paid clippers to promote at least 19 videos discussing opportunities to use inside information or other tactics to manipulate markets.

America's advertising laws "require people who are paid to endorse a product to disclose their ties," the article notes, "although there is some gray area about what's permitted." (After the Journal's investigation, the creators started adding "@polymarket partner" to their bios, the article points out._ And when asked for a comment, Polymarket "said it plans to conduct a comprehensive audit of active promotional content."
AI

Will Meta's $14 Billion Bet on AI Ever Pay Off? (cnbc.com) 65

"A year after spending over $14 billion to bring in Alexandr Wang and a group of his top Scale AI engineers to revamp its artificial intelligence efforts, Meta is at least back on the map in AI," reports CNBC, "though it's still far behind OpenAI, Anthropic and Google in the market." Wang's big accomplishment was the delivery of the Muse Spark AI model in April, marking Meta's first jump into proprietary foundation models and away from a strict adherence to open source, or open weight as it's more commonly called in AI... "Meta needs to provide more proof points of both adoption and commercialization," said Ralph Schackart, an analyst at William Blair who recommends buying the stock. "Investors are looking for Meta to monetize a new AI-first product, beyond the substantial positive impact AI is having on enhancing the advertising models." Wall Street, at least so far, is unimpressed. Meta's stock is down 18% over the past 12 months, the worst performer in the megacap group, along with Microsoft, which has its own challenges in AI. That's even after Meta reported 33% revenue growth in the first quarter, the fastest rate of expansion for any period since 2021.

For Meta, the problem started with what some industry experts called, in hindsight at least, a strategic blunder. The company jumped into AI with its Llama family of models, offering an open-source approach that allowed developers to freely tinker, while the other big model makers charged for access. In April of last year, Meta's release of Llama 4 fell flat, failing to captivate developers and leading Zuckerberg to reconsider his company's approach to AI development... Since the release of Muse Spark, Meta has unveiled new AI and business-related subscription plans as part of an effort to expand its business beyond online ads. Historically, it hasn't worked. Meta still counts on ads for 98% of revenue. Schackart said he wants to see "tangible evidence of a growing list of new, AI-first products created by Muse Spark, even if monetization lags." He said that's "what investors are looking for."

No matter how good Wang's model may be, Zuckerberg has a high hill to climb with developers coming off the Llama debacle. "I think the AI community largely ignores Meta at this point," said Rob May, CEO of the startup Neurometric, which works in the realm of token engineering.... Krish Subramanian, the CEO of consulting firm KOI AI and former product head at IBM Consulting, said developers are more excited about Google's AI models than what Meta is offering. The appeal of Llama was that it specifically targeted developers wanting open-weight alternative models, while with Muse Spark, Meta has made little effort in that direction, he said. "The lack of developer trust will come back to hit them if they don't focus on third-party developers," Subramanian said, noting that it took years for Microsoft to regain trust from open-source coders during the early days of Azure. "To just focus on a walled-garden kind of an ecosystem and ad revenue as the main source of income, they probably will never become the big player," he said.

A Meta spokesperson pointed to Wang's recent comments about the company's continued support for the open-source ecosystem, and said Meta still plans to offer outside developers access to Muse Spark's underlying technology via an API, as it previously announced. "We're already testing with some early partners, and look forward to releasing it this month," the spokesperson said.

"That Zuckerberg's metaverse and virtual reality ambitions have generated over $80 billion in total losses since late 2020 makes the AI pitch a tougher sell," the article points out, citing this observation from Howard Yu, business professor at Switzerland's International Institute for Management Development.

"He's running out of the space for his credibility to last," Yu said. "I think the virtual reality foray may have burned up a lot of his goodwill in front of investors."
Facebook

Black Market Tinkerers on Facebook Marketplace Offer to Hide 'Recording Lights' on Meta Smartglasses (thenewthings.com) 98

People are disabling the "recording light" on Meta's Ray-Ban smartglasses — "by my count, thousands of people," says tech journalist Joanna Stern in a new video report: STERN: "They're hiring people on Facebook Marketplace to drill out the light for as much as $100. According to our reporting, folks are offering this service in at least 30 states — despite Meta's attempts to stop it... In most states, we found multiple listings. In the New York and New Jersey area alone there were 23 listings."
Stern watched a man in New Jersey disable and then conceal the light with a drill and dental probe in a New Jersey garage (a skill he learned watching YouTube and TikTok videos). He said the same day he'd already been contacted by eight more interested customers, and Stern also found at least 10 other people willing to do the same thing, just in New Jersey. "But what we found is they're all over the country."

Meta sold 7 million smartglasses in 2025, but a Meta spokesperson insisted to the videomaker that a "majority" of their smartglasses owners aren't blocking the recording light. And furthermore, they added "We aggressively target anyone advertising tampering tools, have removed thousands of violating ads and Marketplace listings for these services, and pursue legal action when appropriate." (The reporter acknowledges "many" of the Marketplace ads disappeared after they brought them to Meta's attention — and Meta also said they were working with other retailers and sellers to take down listings for smartglasses-tampering parts.)

The reporter also heard from one journalist who said they'd used it so they could record the activities of federal immigration agents without being targeted. "Others told me they just don't want people asking questions when they're recording." (There's video of one young man saying "It's already difficult enough to film in public. I don't want to have a blinking light on my face.")

Tampering with smartglasses isn't illegal — though it is against Meta's Terms of Service, and could void your warranty. But a lawyer in the report says recording others without consent may be illegal, depending on a wide range of "jurisdictional nuances" like whether you live in an all-party consent state or a one-party consent state. "This seems to be our new reality," the report concludes: "more cameras, more microphones everywhere, and less certainty about who and what is recording." (Tech blogger John Gruber offered this assessment. "Using a Meta platform to find people to hack a Meta device so you can surreptitiously record strangers. So perfectly Meta.")

Stern's report points out that "People are trying to fight back. Apps have popped up that use Bluetooth to scan for nearby camera glasses." (In the video one app-maker wonders why Meta isn't offering the same service themselves. "There are technical solutions to these problems.")

Ironically, when I watched the report on YouTube, it was preceded by... an ad for Meta's Ray-Ban AI smartglasses.
Social Networks

Reddit Ads Impersonate BBC and The Guardian to Push Fake AI Investment Schemes (bitdefender.com) 34

A "growing wave" of Reddit's "promoted posts" are sending U.S. and European audiences to money-stealing scams that impersonate major news organizations including the BBC, the Financial Times, and The Guardian, according to new findings from Bitdefender Labs.

"Domains are short-lived and rapidly rotated to evade detection," they write, noting that the impersonating sites apparently even use language "to falsely imply that the investment platform had been reviewed, approved, or vetted" by the legitimate site they're impersonating: The campaign promotes fake AI-powered investment platforms such as Wencoin STX, Warrior Coin AI, and Nevo Coin, using fabricated celebrity endorsements, cloned news websites, fake interviews, and invented financial success stories to lure victims into depositing money. Researchers Andrea Olariu and Emanuel Puscasu have identified multiple promoted Reddit posts masquerading as legitimate financial or breaking news stories.

Some ads claimed that:

— NVIDIA and OpenAI were "creating the future"
— Heathrow police discovered hundreds of thousands of pounds in cash
— Governments and banks were allegedly trying to "hide" a revolutionary AI investment platform
— European regulators were "silencing" articles about AI trading systems

Some Reddit ads delivered in video format, including what appeared to be a deepfake BBC news segment featuring a news anchor presenting fabricated financial headlines... Examples observed by researchers included:

— Fake BBC pages discussing "$20 billion conversations" tied to AI investments
— Fraudulent Financial Times articles about Heathrow airport cash seizures
— Fake Guardian stories claiming governments were trying to suppress coverage of Wencoin STX or Nevo Coin

The pages featured fabricated interviews, fake profit screenshots, manipulated banking documents, false testimonials, and even fictional journalists or business editors designed to make the scam look legitimate. In many cases, the content sought to create a sense of exclusivity or conspiracy, suggesting that banks, regulators, or governments were trying to suppress public access to the investment platform...

Our researchers found that after users clicked links embedded within the fake Guardian articles, they were redirected to a registration form allegedly used to create a "Nevo Coin" investment account. The form requested personal contact information, including the victim's name, email address, and phone number. To increase pressure and encourage immediate action, the page warned that registration availability was limited, claiming that once all spots were filled, new user registrations would be suspended.

And in the final stage, they're asked to deposit money...
Advertising

Pentagon Says US Military Personnel Targeted Using Commercial Location Data (msn.com) 42

U.S. forces deployed to war zones "have been targeted using commercially available location data," reports Reuters, citing "reports fielded by military officials."

Reuters calls it "an illustration of how the global surveillance economy is shaping the battlefield." In a letter shared with Reuters by U.S. Senator Ron Wyden, an Oregon Democrat, U.S. Central Command said it had "received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in theater." The message, sent on April 14, offered no further specifics, but Centcom's area of responsibility includes the Gulf, where U.S. forces are facing off against the Iranian military over the Strait of Hormuz.
The disclosure was the first official confirmation that U.S. forces had been targeted in an active war zone, Wyden and a bipartisan group of legislators said in a letter sent on Thursday to the Pentagon. "Commercial location data can be used to identify where U.S. troops congregate and their pattern of life, which can be exploited by adversaries to target attacks such as missiles, drones, and roadside bombs, as well as for counterintelligence purposes," the letter warned.

Wyden said in a statement that it was time to "start treating the adtech industry as a national security threat."

"The letter from U.S. lawmakers to the Pentagon said that, given what military officials know about the trade in location data, they should have acted faster to protect their personnel," the artiles adds, "for example by disabling the unique advertising ID attached to military-issued devices, automatically turning off location sharing on smartphones in the field, and steering staff away from Google's Chrome web browser toward more privacy-focused alternatives."

Thanks to Slashdot reader JoeyRox for sharing the article.
The Almighty Buck

Meta To Start Testing AI Subscription Services 52

Meta will begin testing paid subscriptions for its Meta AI app and website, with a $7.99/month Meta One Plus plan and a more capable $19.99/month Meta One Premium plan offering. The test will start next month in Singapore, Guatemala, and Bolivia as Meta looks for AI revenue beyond advertising while continuing to offer a free tier. CNBC reports: Naomi Gleit, the head of product at Meta, revealed the subscription testing in an Instagram video, announcing that the plans "give people who use Meta AI more to work with, more capacity, bigger, more complex requests, and more room to create for businesses and creators."

Meta One Plus will cost $7.99 a month and the Meta One Premium plan will cost $19.99 a month, the company confirmed. The more expensive version offers users additional computing capacity to produce more comprehensive responses and other advanced features. The company will continue to provide a free version of the app and site.

"We're offering premium tools that allow you to enhance presence, supercharge content, automate tasks, and protect your brand," Gleit said in the post. "We're also thinking about how to bring this all together in a way that makes sense."
Advertising

Social Media Sites Got Information from Ad Trackers on US State Health Insurance Sites (gizmodo.com) 29

All 20 of America's state-run healthcare marketplace sites "include advertising trackers that share information with Big Tech companies," reports Gizmodo, citing a report from Bloomberg: Per the report, seven million Americans bought their health insurance through state exchanges in 2026, and many of them may have had personal information shared with companies, including Meta, TikTok, Snap, Google, Nextdoor, and LinkedIn, among others. Some of the data collected and shared with those companies included ZIP codes, a person's sex and citizenship status, and race.

In addition to potentially sensitive biographical details about a person, the trackers also may reveal additional details about their life based on the sites they visit. For instance, Bloomberg found trackers on Medicaid-related web pages in Rhode Island, which could reveal information about a person's financial status and need for assistance. In Maryland, a Spanish-language page titled "Good News for Noncitizen Pregnant Marylanders" and a page designed to help DACA recipients navigate their healthcare options were found to be transmitting data to Big Tech firms...

Per Bloomberg, several states have already removed some trackers from their exchange websites following the report.

Thanks to Slashdot reader JoeyRox for sharing the news.
Security

The Canvas Hack Is a New Kind of Ransomware Debacle (wired.com) 43

Wired describes the recent Canvas breach as an unusually disruptive ransomware-style extortion incident because one attack on Instructure's learning platform temporarily paralyzed thousands of schools during finals and end-of-year assignments. The hackers using the "ShinyHunters" name claim more than 8,800 schools were affected, while Instructure says exposed data included names, email addresses, student ID numbers, and platform messages. From the report: Higher education has long been a target of ransomware gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States. The widely used digital learning platform Canvas was put into "maintenance mode" on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker "ShinyHunters." Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.

Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture. In a running incident update log that began on May 1, Steve Proud, Instructure's chief information security officer, said that the company had "recently experienced a cybersecurity incident perpetrated by a criminal threat actor." He added on May 2 that "the information involved" for "users at affected institutions" included names, email addresses, student ID numbers, and messages exchanged by users on the platform.

The situation was ultimately marked as "Resolved" on Wednesday, with Proud writing that "Canvas is fully operational, and we are not seeing any ongoing unauthorized activity." At midday on Thursday, though, the Instructure status page registered an "issue" where "some users are having difficulties logging into Student ePortfolios." Within a few hours, the company had added another status update: "Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode." Late Thursday evening, the company said that Canvas was available again "for most users."

TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools' Canvas portals by injecting an HTML file to display their own message on the schools' Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach. The message from attackers "urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12 -- or else risk their data being leaked," The Crimson reported. "It is unclear what information tied to Harvard affiliates was included in the alleged breach."

The Courts

Apple Agrees To Pay iPhone Owners $250 Million For Not Delivering AI Siri 37

Apple has agreed to a proposed $250 million settlement over claims that it misled iPhone buyers about the availability of Apple Intelligence and its upgraded Siri features. The settlement would cover U.S. buyers of the iPhone 16 lineup and iPhone 15 Pro models between June 10, 2024, and March 29, 2025. The Verge reports: The settlement will resolve a 2025 lawsuit, alleging Apple's advertisements created a "clear and reasonable consumer expectation" that Apple Intelligence features would be available with the launch of the iPhone 16. The lawsuit claimed Apple's products "offered a significantly limited or entirely absent version of Apple Intelligence, misleading consumers about its actual utility and performance."

Apple brought certain AI-powered features to the iPhone 16 weeks after its release, and delayed the launch of its more personalized Siri, which is now expected to arrive later this year. Last April, the National Advertising Division recommended that Apple "discontinue or modify" its "available now" claim for Apple Intelligence. Apple also pulled an iPhone 16 ad showing actor Bella Ramsey using the AI-upgraded Siri.
Movies

Sony Boss Urges Theaters To Stop 30 Minutes of Trailers and Ads Before Movies (variety.com) 152

Sony Pictures chief Tom Rothman urged theater owners to cut down the roughly 30 minutes of trailers and ads before movies. "Get off the ad crack," Rothman told the audience at CinemaCon this week. "Get rid of the endless advertising and substantially shorten the long pre-shows." Variety reports: He noted that frequent moviegoers now show up a half hour late to avoid all the spots (something that reserved seating has made easier than ever before). Rothman said that means many people "don't even see the trailers," which results in "enticements gone to waste." Rothman predicted that the 2026 box office, which has already benefitted from hits like "Super Mario Galaxy Movie" and "Project Hail Mary," will rebound in a big way. But he acknowledged that attendance still trails pre-pandemic levels.

Rothman has been a vociferous defender of the big screen, pushing studios to embrace longer windows so that movies will stay in cinemas longer. That was a theme that Rothman returned to at CinemaCon, pressing exhibitors to hold strong and agree not to show movies that quickly appear on streaming services or on-demand platforms. "Enforce longer windows," Rothman said. "Yes, even if that means you cannot play every film."

In addition to stumping for exhibition, Rothman has practically begged Hollywood to invest in new stories along with all the franchise fare. In a recent New York Times op-ed, for instance, Rothman, the longest-serving studio chief, wrote, "For all the success of films driven by existing intellectual property, originality is essential to movies. Neither movie theaters nor the art form itself can survive without at least some originality. After all, you can't make a sequel to nothing."

The Internet

Audit Finds Google, Microsoft, and Meta Still Tracking Users After Opt-Out (404media.co) 48

alternative_right shares a report from 404 Media: An independent privacy audit of Microsoft, Meta, and Google web traffic in California found that the companies may be violating state regulations and racking up billions in fines. According to the audit from privacy search engine webXray, 55 percent of the sites it checked set ad cookies in a user's browser even if they opted out of tracking. Each company disputed or took issue with the research, with Google saying it was based on a "fundamental misunderstanding" of how its product works.

The webXray California Privacy Audit viewed web traffic on more than 7,000 popular websites in California in the month of March and found that most tech companies ignore when a user asks to opt-out of cookie tracking. California has stringent and well defined privacy legislation thanks to its California Consumer Privacy Act (CCPA) which allows users to, among other things, opt out of the sale of their personal information. There's a system called Global Privacy Control (GPC), which includes a browser extension that indicates to a website when a user wants to opt out of tracking.

According to the webXray audit, Google failed to let users opt out 87 percent of the time. "Google's failure to honor the GPC opt-out signal is easy to find in network traffic. When a browser using GPC connects to Google's servers it encodes the opt-out signal by sending the code 'sec-gpc: 1.' This means Google should not return cookies," the audit said. "However, when Google's server responds to the network request with the opt-out it explicitly responds with a command to create an advertising cookie named IDE using the 'set-cookie' command. This non-compliance is easy to spot, hiding in plain sight."

The audit said that Microsoft fails to opt out users in the same way and has a failure rate of 50 percent in the web traffic webXray viewed. Meta's failure rate was 69 percent and a bit more comprehensive. "Meta instructs publishers to install the following tracking code on their websites. The code contains no check for globally standard opt-out signals -- it loads unconditionally, fires a tracking event, and sets a cookie regardless of the consumer's privacy preferences," the audit said. It showed a copy of Meta's tracking data which contains no GPC check at all.

Slashdot Top Deals