Security updates have been issued by AlmaLinux (.NET 8.0, .NET 9.0, cockpit, firefox, flatpak, httpd, kernel, and kernel-rt), Debian (kernel, kitty, lemonldap-ng, nagios4, python-flask-httpauth, and roundcube), Fedora (CImg, gmic, haveged, jpegxl, kernel, libpng, mapserver, mingw-qt6-qtsvg, openbao, perl-Sereal, perl-Sereal-Decoder, perl-Sereal-Encoder, and podofo), Mageia (bind, graphicsmagick, microcode, nginx, packages, perl-Catalyst-Plugin-Authentication, perl-HTTP-Daemon, perl-IO-Compress, and thunderbird(-l10n)), SUSE (alloy, apache2, beets, bubblewrap, cups, docker-stable, ffmpeg-4, ffmpeg-7, firefox, google-osconfig-agent, patterns-glibc-hwcaps, podman, samba, thunderbird, trivy, xdg-desktop-portal, and xz), and Ubuntu (apache2, libreoffice, multipart, openjdk-17, openjdk-17-crac, openjdk-21, openjdk-21-crac, openjdk-25, openjdk-25-crac, openjdk-26, openjdk-8, openjdk-lts, php8.1, php8.3, php8.4, php8.5, pyopenssl, python-pip, qtsvg-opensource-src, sed, and vim).
A senior CIA official, David Rush, was arrested after investigators found more than $40 million in gold bars and about $2 million in cash at his Virginia home. According to the New York Times, "The only charge lodged against David Rush is that he inflated his academic credentials and obtained military leave pay worth tens of thousands of dollars." From the report: The court papers describe Mr. Rush as a "former senior executive service-level employee at a United States government agency." People familiar with the investigation say he until very recently held a senior position at the C.I.A. In a joint statement, the C.I.A. and F.B.I. said the arrest occurred on May 19, after the agency alerted the bureau. "After a C.I.A. internal investigation identified potential violations of the law, C.I.A. Director John Ratcliffe referred the information to the F.B.I. for a law enforcement investigation," the statement said.
From last November to March, the court papers say, Mr. Rush asked for, and received, "a significant quantity of foreign currency and tens of millions of dollars in gold bars for work-related expenses." When the C.I.A. conducted a review of where the gold and currency were stashed, the agency was "unable to locate the gold bars or significant amounts of the foreign currency," according to court papers.
On May 18, F.B.I. agents searched Mr. Rush's home and found "approximately 303 gold bars, each of which weighed approximately one kilogram," according to an affidavit. Based on the price of gold, the affidavit said, the estimated value of the gold exceeded $40 million. Investigators also seized nearly three dozen luxury watches, many of them Rolexes. The court papers do not indicate why Mr. Rush appears to have kept so much gold, and $2 million in U.S. currency, in his home, or what work project would have required him to amass such wealth.
Read more of this story at Slashdot.
NASA has outlined a three-phase plan to build a lunar base at the moon's south pole. The first phase, from 2026 to 2029, will focus on robotic missions, landers, rovers, reactors, satellites, and Blue Origin's Blue Moon Mark 1 Endurance test. Later phases will add habitats, power systems, communications, cargo logistics, and rotating crews. Wired reports: According to a recent press conference, phase one will be particularly active: at least 25 missions and 21 surface landings. Without detailing specific dates, the agency said that over the next three years it will send rovers, including manned models for future mobility, drones, surface reactors, new-generation satellites, and payloads to prepare the ground.
One of the first key missions will be the test of the Blue Moon Mark 1 Endurance module in fall 2026. Its purpose is to evaluate conditions for a controlled descent and validate navigation and positioning technology. It will not carry astronauts. If the mission is successful, Blue Origin plans a manned version around 2028, possibly with Blue Moon Mark 2. Moon Base II and III missions are also part of the program's 2026 startup. One will send rovers and payloads to evaluate more complex rover operations; the other will carry scientific instruments to study the behavior of materials and systems under extreme lunar conditions.
Phase two, starting in 2029, marks the beginning of semipermanent infrastructure assembly and first occupancy operations. NASA plans to install advanced energy systems, including surface reactors, initial habitat elements, and more robust communication networks. Up to 60 tons of cargo will be delivered in 24 missions during this period.
Phase three is for scale-up. The infrastructure in place will be strengthened and expanded to form durable centers with constant turnover of personnel. NASA envisions a lunar south pole with habitable modules, reliable power systems, logistics networks for cargo and crew transportation, and the shipment of about 38 tons of cargo annually for maintenance and expansion. "Every mission, crewed and uncrewed, will be a learning opportunity as we return to the lunar surface, build the infrastructure to stay, and master the skills required to live and operate in one of the most demanding and dangerous environments imaginable," said administrator Jared Isaacman in a NASA statement. "We will go for the science, for all we stand to gain from an economic and technological perspective, for the innovations that will make life better here on Earth, and to prepare for where we will inevitably go next."
Read more of this story at Slashdot.
Illinois lawmakers on Wednesday passed a landmark AI safety bill (SB 315) that would require major AI companies to publish safety plans, submit annual third-party testing reports, report serious incidents quickly, and protect whistleblowers who flag emerging risks. OpenAI and Anthropic supported the bill, which could make Illinois a testing ground for state-level AI governance as federal regulation remains stalled. Ars Technica reports: To force companies to be more transparent about rapid developments, Illinois would likely rely on "the Big Four accounting and auditing firms -- Deloitte, EY, KPMG, and PwC -- to audit their safety practices," [said Scott Wisor, a policy director at a nonprofit called Secure AI Project, which supported the bill]. The required independent audits will likely frustrate Trump, who has tried and failed to stop states from implementing AI safety laws as Congress stalls on passing any legislation.
For Trump, the priority has been to promote AI industry interests, but he began considering expanding federal government safety testing after Anthropic's Mythos was released and the AI firm limited access due to safety concerns. Whether or not governments at any level are prepared to protect society from the most catastrophic AI risks remains a major concern for critics who wonder how and when governments will intervene. After inside sources started leaking the details of Trump's AI safety testing plans, critics warned that even the federal government may lack the necessary expertise to audit frontier AI models. And it seems the same criticism extends to independent auditors that Illinois may rely on but industry insiders suggest some AI firms may not entirely trust.
Adam Kovacevich is CEO of Chamber of Progress, a trade group that opposed SB 315 and counts Google and Apple among its members. He told Wired that Illinois' requirements "would force companies to expose sensitive systems to untested auditors in a regulatory regime that's all liability and no standards." Governor J.B. Pritzker confirmed his intent to sign, proclaiming that "Illinois is leading the nation in holding Big Tech accountable."
"I look forward to signing SB 315 and working with the legislature so that AI, when used, is used responsibly," Pritzker said.
Steve Wimmer, a senior policy and technical advisor for the Transparency Coalition, said his group considers the law to be "one of the most important pieces of legislation in 2026."
Read more of this story at Slashdot.
Valve's Steam Deck has sold out again despite a steep price increase that pushed the 1TB OLED model as high as $949 -- about $300 above its original price. "Even with the $300 price bump, the Steam Deck sold out after less than 24 hours back in stock," reports IGN's Jacqueline Thomas. "I don't know how many units Valve was able to stock into its store, but it does seem like Valve spent a couple weeks building up its stock before putting the handheld back on its store." IGN reports: Over the last couple weeks, Valve has been receiving plenty of "game console" shipments from China. At first, I thought this was a sign that the company was getting ready to finally release the Steam Machine, but it looks like at least a portion of these shipments â" if not all of them -- were Steam Deck restocks. That's a lot of Steam Decks to sell through at these inflated prices, but it's also possible that Valve is just staggering its stock so that its delivery infrastructure isn't overwhelmed.
Now its just a question of when the Steam Deck will come back in stock. Before yesterday, the Deck was sold out for months. At the time, it was the most affordable way to get into PC gaming, especially in the face of the RAM crisis. That's no longer true, but it looks like the Steam Deck's popularity is enough to make it sell out regardless. Maybe the higher price will at least help Valve keep it in stock for people who still want to buy it, no matter the cost. Earlier this week, Valve announced a price increase of more than 40% for two of its Steam Deck models, citing "rising memory and storage costs."
The price changes, according to Valve, reflect "the current state of component costs and other global logistical challenges across the industry as a whole."
"The 512GB tier of its OLED handheld gaming PC -- the newer model with an upgraded display -- will now cost $789, an increase of 43%," notes the BBC. "The larger 1TB model will cost $949, an increase of 46%."
Read more of this story at Slashdot.
IBM and Red Hat are committing $5 billion to a new initiative called "Project Lightwell," which aims to secure open-source software supply chains with AI-assisted vulnerability discovery, triage, patch validation, and upstream maintenance. Longtime Slashdot reader wiggles shares a press release from IBM: IBM and Red Hat today announced Project Lightwell, a $5 billion commitment backed by new frontier AI capabilities and a global force of more than 20,000 engineers to help enterprises secure open source software. Together, these investments establish a new model for enterprise use of open source software, from upstream development through production environments.
Project Lightwell will establish a trusted enterprise clearinghouse combined with a global force of engineers to identify and fix vulnerabilities at scale. The clearinghouse will serve as a security coordination layer, using advanced AI capabilities to validate and test fixes across an unprecedented volume of open source code. These capabilities will be offered through commercial subscriptions, allowing enterprises to integrate secure patches directly into their existing software supply chains with enterprise-grade validation and lifecycle management.
IBM and Red Hat have already begun collaborating with a select group of early adopters on Project Lightwell, including Bank of America, BNY, Citi, Goldman Sachs, JPMorganChase, Mastercard, Morgan Stanley, Royal Bank of Canada, State Street, Visa and Wells Fargo. The real-world insights from these initial deployments will actively shape how vulnerabilities are identified, validated, and remediated at scale across complex software supply chains.
Read more of this story at Slashdot.
An anonymous reader quotes a report from CNBC: Federal prosecutors charged a Google employee with fraud on Wednesday, alleging that he made $1.2 million off of bets using insider information on Polymarket. Prosecutors claim that Michele Spagnuolo, a staff information security engineer at Google, used confidential information to place trades correctly betting that singer d4vd would be Google's most searched person in 2025. Spagnuolo has been charged with money laundering, commodities fraud and wire fraud. The complaint, filed in the Southern District of New York, was unsealed on Wednesday.
Spagnuolo was arrested Wednesday morning in New York, ABC reported. "Spagnuolo had access to Google's internal data systems, including a particular Google internal software tool that provided him access to confidential, nonpublic Year in Search data," the prosecutors said in their complaint. Some observers of the Polymarket platform flagged the user "AlphaRaccoon" back in December for suspicious trades on the most searched person contracts. The complaint Wednesday said that Spagnuolo was the person behind that account. "Google officially and publicly announced its Year in Search 2025 results on or about December 4, 2025. Soon after it did so, Spagnuolo's AlphaRaccoon account, profited approximately $1.2 million on his Google Year in Search 2025-related bets," the complaint said.
[...] Spagnuolo is also facing a civil case from the Commodity Futures Trading Commission, where he's charged with insider trading. The complaint detailed that Spagnuolo correctly predicted the outcomes of a slew of other search markets, including contracts like "Will Zohran Mamdani rank in the Top 5 most searched" and "Will Squid Game be the #1 searched TV show." "Spagnuolo misappropriated the material Confidential Information by knowingly or recklessly using it to trade the 2025 Year in Search List Contracts in breach of his duties of trust and confidentiality," the CFTC complaint alleged.
Read more of this story at Slashdot.