Someone Snuck Into a Cellebrite Microsoft Teams Call and Leaked Phone Unlocking Details An anonymous reader quotes a report from 404 Media: Someone recently managed to get on a Microsoft Teams call with representatives from phone hacking company Cellebrite, and then leaked a screenshot of the company's capabilities against many Google Pixel phones, according to a forum post about the leak and 404 Media's review of the material. The leak follows others obtained and verified by 404 Media over the last 18 months. Those leaks impacted both Cellebrite and its competitor Grayshift, now owned by Magnet Forensics. Both companies constantly hunt for techniques to unlock phones law enforcement have physical access to. "You can Teams meeting with them. They tell everything. Still cannot extract esim on Pixel. Ask anything," a user called rogueFed wrote on the GrapheneOS forum on Wednesday, speaking about what they learned about Cellebrite capabilities. GrapheneOS is a security- and privacy-focused Android-based operating system. rogueFed then posted two screenshots of the Microsoft Teams call. The first was a Cellebrite Support Matrix, which lays out whether the company's tech can, or can't, unlock certain phones and under what conditions. The second screenshot was of a Cellebrite employee. According to another of rogueFed's posts, the meeting took place in October. The meeting appears to have been a sales call. The employee is a "pre sales expert," according to a profile available online. The Support Matrix is focused on modern Google Pixel devices, including the Pixel 9 series. The screenshot does not include details on the Pixel 10, which is Google's latest device. It discusses Cellebrite's capabilities regarding 'before first unlock', or BFU, when a piece of phone unlocking tech tries to open a device before someone has typed in the phone's passcode for the first time since being turned on. It also shows Cellebrite's capabilities against after first unlock, or AFU, devices. The Support Matrix also shows Cellebrite's capabilities against Pixel devices running GrapheneOS, with some differences between phones running that operating system and stock Android. Cellebrite does support, for example, Pixel 9 devices BFU. Meanwhile the screenshot indicates Cellebrite cannot unlock Pixel 9 devices running GrapheneOS BFU. In their forum post, rogueFed wrote that the "meeting focused specific on GrapheneOS bypass capability." They added "very fresh info more coming." <a href="http://twitter.com/home?status=Someone+Snuck+Into+a+Cellebrite+Microsoft+Teams+Call+and+Leaked+Phone+Unlocking+Details%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F25%2F10%2F31%2F0028256%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter" rel="nofollow"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a> <a href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F25%2F10%2F31%2F0028256%2Fsomeone-snuck-into-a-cellebrite-microsoft-teams-call-and-leaked-phone-unlocking-details%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook" rel="nofollow"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a> at Slashdot.
Mathematical Proof Debunks the Idea That the Universe Is a Computer Simulation alternative_right shares a report from Phys.org: Today's cutting-edge theory -- quantum gravity -- suggests that even space and time aren't fundamental. They emerge from something deeper: pure information. This information exists in what physicists call a Platonic realm -- a mathematical foundation more real than the physical universe we experience. It's from this realm that space and time themselves emerge. "The fundamental laws of physics cannot be contained within space and time, because they generate them. It has long been hoped, however, that a truly fundamental theory of everything could eventually describe all physical phenomena through computations grounded in these laws. Yet we have demonstrated that this is not possible. A complete and consistent description of reality requires something deeper -- a form of understanding known as non-algorithmic understanding." "We have demonstrated that it is impossible to describe all aspects of physical reality using a computational theory of quantum gravity," says Dr. Faizal. "Therefore, no physically complete and consistent theory of everything can be derived from computation alone. Rather, it requires a non-algorithmic understanding, which is more fundamental than the computational laws of quantum gravity and therefore more fundamental than spacetime itself." "Drawing on mathematical theorems related to incompleteness and indefinability, we demonstrate that a fully consistent and complete description of reality cannot be achieved through computation alone," explains Dr. Mir Faizal, Adjunct Professor with UBC Okanagan's Irving K. Barber Faculty of Science. "It requires non-algorithmic understanding, which by definition is beyond algorithmic computation and therefore cannot be simulated. Hence, this universe cannot be a simulation." The findings have been published in the Journal of Holography Applications in Physics. <a href="http://twitter.com/home?status=Mathematical+Proof+Debunks+the+Idea+That+the+Universe+Is+a+Computer+Simulation%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F25%2F10%2F30%2F2232258%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter" rel="nofollow"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a> <a href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F25%2F10%2F30%2F2232258%2Fmathematical-proof-debunks-the-idea-that-the-universe-is-a-computer-simulation%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook" rel="nofollow"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a> at Slashdot.
Google Shows Off Prototype Android XR Glasses From Extended Magic Leap Deal Google and Magic Leap have extended their partnership for another three years to develop Android XR glasses. They also showed off a new prototype concept that combines Google's Raxium microLED light engine with Magic Leap's AR optics, resulting in a lightweight, stylish pair of glasses that blends real-world vision with multimodal AI. 9to5Google reports: As noted by Android Central, a press release shared by Magic Leap adds some further technical details. This includes mentioning that Google's "Raxium microLED light engine" integrates with Magic Leap's tech to bring "digital content seamlessly into the world." As pictured above, the "display" portion of the lens is visible at some angles, but it's largely impossible to see. Magic Leap and Google will show an AI glasses prototype at FII that will serve as a prototype and reference design for the Android XR ecosystem. The demo shows how Magic Leap's technology, integrated with Google's Raxium microLED light engine, brings digital content seamlessly into the world. The prototypes worn on stage illustrate how comfortable, stylish smart eyewear is possible and the video showed the potential for users to stay present in the real world while tapping into the knowledge and functionality of multimodal AI. During the presentation, text on the nearby screens suggests that Magic Leap is mainly working with Google on the technology here, rather than bringing its own glasses to market. Magic Leap further hints at this in its press release, calling itself "an AR ecosystem partner" focused on "supporting global technology leaders that want to enter the AR market and accelerate the production of AR glasses." <a href="http://twitter.com/home?status=Google+Shows+Off+Prototype+Android+XR+Glasses+From+Extended+Magic+Leap+Deal%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F25%2F10%2F31%2F0021217%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter" rel="nofollow"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a> <a href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F25%2F10%2F31%2F0021217%2Fgoogle-shows-off-prototype-android-xr-glasses-from-extended-magic-leap-deal%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook" rel="nofollow"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a> at Slashdot.
AI 'Cheating' App Founder Says Engineers Can't Make Good, Viral Content and That's Why Their Startups Flop AI "cheating" app Cluely's CEO and cofounder, Chungin "Roy" Lee, said most startups flop because their products don't get seen. From a report: "Engineers just cannot make good content," Lee said during a Wednesday interview at TechCrunch Disrupt 2025 "There's a bunch of shallow replicas, but I challenge you to find one video you think is like, 'Yo, this is as tough as Cluely,'" he told TechCrunch. Every startup needs to focus more on distribution. And most startups flop because they fail to get seen, even if they have product-market fit, Lee said. Cluely launched earlier this year as a tool to help software engineers cheat on their job interviews, among other use cases. The startup earlier this year posted a tongue-in-cheek video of Lee trying to use Cluely to impress a woman on a date, which went viral. <a href="http://twitter.com/home?status=AI+'Cheating'+App+Founder+Says+Engineers+Can't+Make+Good%2C+Viral+Content+and+That's+Why+Their+Startups+Flop%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F25%2F10%2F30%2F1942215%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter" rel="nofollow"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a> <a href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F25%2F10%2F30%2F1942215%2Fai-cheating-app-founder-says-engineers-cant-make-good-viral-content-and-thats-why-their-startups-flop%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook" rel="nofollow"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a> at Slashdot.
Zuckerberg Getting Ready To Dump More AI Content To Social Feeds Meta CEO Mark Zuckerberg is getting ready to dump even more AI-generated posts into your social feeds. From a report: During an earnings call on Wednesday, Zuckerberg said the company will "add yet another huge corpus of content" to its recommendations system as AI "makes it easier to create and remix" work that gets shared online. "Social media has gone through two eras so far," Zuckerberg said. "First was when all content was from friends, family, and accounts that you followed directly. The second was when we added all of the Creator content." Though Zuckerberg stops short of calling AI the third era of social media, it's clear that the technology will be heavily involved in what comes next. Zuckerberg said that recommendation systems that "deeply understand" AI-generated posts and "show you the right content" will become "increasingly valuable." The company has already begun embedding AI tools across its apps and is now experimenting with dedicated AI social apps, too. <a href="http://twitter.com/home?status=Zuckerberg+Getting+Ready+To+Dump+More+AI+Content+To+Social+Feeds%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F25%2F10%2F30%2F1913228%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter" rel="nofollow"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a> <a href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F25%2F10%2F30%2F1913228%2Fzuckerberg-getting-ready-to-dump-more-ai-content-to-social-feeds%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook" rel="nofollow"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a> at Slashdot.
Dictionary.com 'Devastated' Paid Users By Abruptly Deleting Saved Word Lists Dictionary.com abruptly deleted all user accounts and saved word lists from its premium apps without notice or refunds, leaving long-time logophiles "devastated." "The company deleted all accounts, as well as the only ways to use Dictionary.com without seeing ads -- even if you previously paid for an ad-free experience," reports Ars Technica. From the report: Dictionary.com offers a free dictionary through its website and free Android and iOS apps. It used to offer paid-for mobile apps, called Dictionary.com Pro, that let users set up accounts, use the app without ads, and enabled other features (like grammar tips and science and rhyming dictionaries) that are gone now. Dictionary.com's premium apps also let people download an offline dictionary (its free apps used to let you buy a downloadable dictionary as a one-time purchase), but offline the dictionaries aren't available anymore. About a year ago, claims of Dictionary.com's apps being buggy surfaced online. We also found at least one person claiming that they were unable to buy an ad-free upgrade at that time. Reports of Dictionary.com accounts being deleted and the apps not working as expected, and with much of its content removed, started appearing online about two months ago. Users reported being unable to log in and access premium features, like saved words. Soon after, Dictionary.com's premium apps were removed from Google Play and Apple's App Store. The premium version was available for download for $6 as recently as March 23, per the Internet Archive's Wayback Machine. <a href="http://twitter.com/home?status=Dictionary.com+'Devastated'+Paid+Users+By+Abruptly+Deleting+Saved+Word+Lists%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F25%2F07%2F17%2F2329217%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter" rel="nofollow"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a> <a href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F25%2F07%2F17%2F2329217%2Fdictionarycom-devastated-paid-users-by-abruptly-deleting-saved-word-lists%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook" rel="nofollow"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a> at Slashdot.
As AI Kills Search Traffic, Google Launches Offerwall To Boost Publisher Revenue An anonymous reader quotes a report from TechCrunch: Google's AI search features are killing traffic to publishers, so now the company is proposing a possible solution. On Thursday, the tech giant officially launched Offerwall, a new tool that allows publishers to generate revenue beyond the more traffic-dependent options, like ads. Offerwall lets publishers give their sites' readers a variety of ways to access their content, including through options like micropayments, taking surveys, watching ads, and more. In addition, Google says that publishers can add their own options to the Offerwall, like signing up for newsletters. The new feature is available for free in Google Ad Manager after earlier tests with 1,000 publishers that spanned over a year. While no broad case studies were shared, India's Sakal Media Group implemented Google Ad Manager's Offerwall feature and saw a 20% revenue boost and up to 2 million more impressions in three months. Overall, publishers testing Offerwall experienced an average 9% revenue lift, with some seeing between 5% and 15%. <a href="http://twitter.com/home?status=As+AI+Kills+Search+Traffic%2C+Google+Launches+Offerwall+To+Boost+Publisher+Revenue%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F25%2F06%2F26%2F2046234%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter" rel="nofollow"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a> <a href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F25%2F06%2F26%2F2046234%2Fas-ai-kills-search-traffic-google-launches-offerwall-to-boost-publisher-revenue%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook" rel="nofollow"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a> at Slashdot.
Microsoft Uses AI To Find Flaws In GRUB2, U-Boot, Barebox Bootloaders Slashdot reader zlives shared this report from BleepingComputer: Microsoft used its AI-powered Security Copilot to discover 20 previously unknown vulnerabilities in the GRUB2, U-Boot, and Barebox open-source bootloaders. GRUB2 (GRand Unified Bootloader) is the default boot loader for most Linux distributions, including Ubuntu, while U-Boot and Barebox are commonly used in embedded and IoT devices. Microsoft discovered eleven vulnerabilities in GRUB2, including integer and buffer overflows in filesystem parsers, command flaws, and a side-channel in cryptographic comparison. Additionally, 9 buffer overflows in parsing SquashFS, EXT4, CramFS, JFFS2, and symlinks were discovered in U-Boot and Barebox, which require physical access to exploit. The newly discovered flaws impact devices relying on UEFI Secure Boot, and if the right conditions are met, attackers can bypass security protections to execute arbitrary code on the device. While exploiting these flaws would likely need local access to devices, previous bootkit attacks like BlackLotus achieved this through malware infections. Miccrosoft titled its blog post "Analyzing open-source bootloaders: Finding vulnerabilities faster with AI." (And they do note that Micxrosoft disclosed the discovered vulnerabilities to the GRUB2, U-boot, and Barebox maintainers and "worked with the GRUB2 maintainers to contribute fixes... GRUB2 maintainers released security updates on February 18, 2025, and both the U-boot and Barebox maintainers released updates on February 19, 2025.") They add that performing their initial research, using Security Copilot "saved our team approximately a week's worth of time," Microsoft writes, "that would have otherwise been spent manually reviewing the content." Through a series of prompts, we identified and refined security issues, ultimately uncovering an exploitable integer overflow vulnerability. Copilot also assisted in finding similar patterns in other files, ensuring comprehensive coverage and validation of our findings... As AI continues to emerge as a key tool in the cybersecurity community, Microsoft emphasizes the importance of vendors and researchers maintaining their focus on information sharing. This approach ensures that AI's advantages in rapid vulnerability discovery, remediation, and accelerated security operations can effectively counter malicious actors' attempts to use AI to scale common attack tactics, techniques, and procedures (TTPs). This week Google also announced Sec-Gemini v1, "a new experimental AI model focused on advancing cybersecurity AI frontiers." <a href="http://twitter.com/home?status=Microsoft+Uses+AI+To+Find+Flaws+In+GRUB2%2C+U-Boot%2C+Barebox+Bootloaders%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F25%2F04%2F05%2F0250250%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter" rel="nofollow"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a> <a href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F25%2F04%2F05%2F0250250%2Fmicrosoft-uses-ai-to-find-flaws-in-grub2-u-boot-barebox-bootloaders%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook" rel="nofollow"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a> at Slashdot.
YouTube Warns Creators an AI-Generated Video of Its CEO is Being Used For Phishing Scams An anonymous reader shares a report: YouTube is warning creators about a new phishing scam that attempts to lure victims using an AI-generated video of its CEO Neal Mohan. The fake video has been shared privately with users and claims YouTube is making changes to its monetization policy in an attempt to steal their credentials, according to an announcement on Tuesday. "YouTube and its employees will never attempt to contact you or share information through a private video," YouTube says. "If a video is shared privately with you claiming to be from YouTube, the video is a phishing scam." In recent weeks, there have been reports floating around Reddit about scams similar to the one described by YouTube. <a href="http://twitter.com/home?status=YouTube+Warns+Creators+an+AI-Generated+Video+of+Its+CEO+is+Being+Used+For+Phishing+Scams%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F25%2F03%2F04%2F220243%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter" rel="nofollow"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a> <a href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F25%2F03%2F04%2F220243%2Fyoutube-warns-creators-an-ai-generated-video-of-its-ceo-is-being-used-for-phishing-scams%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook" rel="nofollow"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a> at Slashdot.
Mozilla Revises Firefox's Terms of Use, Clarifies That They Don't Own Your Data "We need a license to allow us to make some of the basic functionality of Firefox possible," Mozilla explained Wednesday in a clarification a recent Terms of Use update. "Without it, we couldn't use information typed into Firefox, for example. It does NOT give us ownership of your data or a right to use it for anything other than what is described in the Privacy Notice." But Friday they went further, and revised those new Terms of Use "to more clearly reflect the limited scope of how Mozilla interacts with user data," according to a Mozilla blog post. More details from the Verge: The particular language that drew criticism was: "When you upload or input information through Firefox, you hereby grant us a nonexclusive, royalty-free, worldwide license to use that information to help you navigate, experience, and interact with online content as you indicate with your use of Firefox." That language has been removed. Now, the language in the terms says: "You give Mozilla the rights necessary to operate Firefox. This includes processing your data as we describe in the Firefox Privacy Notice. It also includes a nonexclusive, royalty-free, worldwide license for the purpose of doing as you request with the content you input in Firefox. This does not give Mozilla any ownership in that content...." Friday's post additionally provides some context about why the company has "stepped away from making blanket claims that 'We never sell your data.'" Mozilla says that "in some places, the LEGAL definition of 'sale of data' is broad and evolving," and that "the competing interpretations of do-not-sell requirements does leave many businesses uncertain about their exact obligations and whether or not they're considered to be 'selling data.'" Mozilla says that "there are a number of places where we collect and share some data with our partners" so that Firefox can be "commercially viable," but it adds that it spells those out in its privacy notice and works to strip data of potentially identifying information or share it in aggregate. <a href="http://twitter.com/home?status=Mozilla+Revises+Firefox's+Terms+of+Use%2C+Clarifies+That+They+Don't+Own+Your+Data%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F25%2F03%2F01%2F2111254%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter" rel="nofollow"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a> <a href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F25%2F03%2F01%2F2111254%2Fmozilla-revises-firefoxs-terms-of-use-clarifies-that-they-dont-own-your-data%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook" rel="nofollow"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a> at Slashdot.