Chinese Hackers Exploit SAP NetWeaver RCE Flaw

“A China-linked unnamed threat actor dubbed Chaya_004 has been observed exploiting a recently disclosed security flaw in SAP NetWeaver,” reports The Hacker News:

Forescout Vedere Labs, in a report published Thursday, said it uncovered a malicious infrastructure likely associated with the hacking group weaponizing CVE-2025-31324 (CVSS score: 10.0) since April 29, 2025. CVE-2025-31324 refers to a critical SAP NetWeaver flaw that allows attackers to achieve remote code execution (RCE) by uploading web shells through a susceptible “/developmentserver/metadatauploader” endpoint.

The vulnerability was first flagged by ReliaQuest late last month when it found the shortcoming being abused in real-world attacks by unknown threat actors to drop web shells and the Brute Ratel C4 post-exploitation framework. According to [SAP cybersecurity firm] Onapsis, hundreds of SAP systems globally have fallen victim to attacks spanning industries and geographies, including energy and utilities, manufacturing, media and entertainment, oil and gas, pharmaceuticals, retail, and government organizations. Onapsis said it observed reconnaissance activity that involved “testing with specific payloads against this vulnerability” against its honeypots as far back as January 20, 2025. Successful compromises in deploying web shells were observed between March 14 and March 31.
“In recent days, multiple threat actors are said to have jumped aboard the exploitation bandwagon to opportunistically target vulnerable systems to deploy web shells and even mine cryptocurrency…”

Thanks to Slashdot reader bleedingobvious for sharing the news.


Read more of this story at Slashdot.

What Happens If AI Coding Keeps Improving?

Fast Company’s “AI Decoded” newsletter makes the case that the first “killer app” for generative AI… is coding.

Tools like Cursor and Windsurf can now complete software projects with minimal input or oversight from human engineers… Naveen Rao, chief AI officer at Databricks, estimates that coding accounts for half of all large language model usage today. A 2024 GitHub survey found that over 97% of developers have used AI coding tools at work, with 30% to 40% of organizations actively encouraging their adoption…. Microsoft CEO Satya Nadella recently said AI now writes up to 30% of the company’s code. Google CEO Sundar Pichai echoed that sentiment, noting more than 30% of new code at Google is AI-generated.

The soaring valuations of AI coding startups underscore the momentum. Anysphere’s Cursor just raised $900 million at a $9 billion valuation — up from $2.5 billion earlier this year. Meanwhile, OpenAI acquired Windsurf (formerly Codeium) for $3 billion. And the tools are improving fast. OpenAI’s chief product officer, Kevin Weil, explained in a recent interview that just five months ago, the company’s best model ranked around one-millionth on a well-known benchmark for competitive coders — not great, but still in the top two or three percentile. Today, OpenAI’s top model, o3, ranks as the 175th best competitive coder in the world on that same test. The rapid leap in performance suggests an AI coding assistant could soon claim the number-one spot. “Forever after that point computers will be better than humans at writing code,” he said…

Google DeepMind research scientist Nikolay Savinov said in a recent interview that AI coding tools will soon support 10 million-token context windows — and eventually, 100 million. With that kind of memory, an AI tool could absorb vast amounts of human instruction and even analyze an entire company’s existing codebase for guidance on how to build and optimize new systems. “I imagine that we will very soon get to superhuman coding AI systems that will be totally unrivaled, the new tool for every coder in the world,” Savinov said.


Read more of this story at Slashdot.

Can an MCP-Powered AI Client Automatically Hack a Web Server?

Exposure-management company Tenable recently discussed how the MCP tool-interfacing framework for AI can be “manipulated for good, such as logging tool usage and filtering unauthorized commands.” (Although “Some of these techniques could be used to advance both positive and negative goals.”)

Now an anonymous Slashdot reader writes: In a demonstration video put together by security researcher Seth Fogie, an AI client given a simple prompt to ‘Scan and exploit’ a web server leverages various connected tools via MCP (nmap, ffuf, nuclei, waybackurls, sqlmap, burp) to find and exploit discovered vulnerabilities without any additional user interaction

As Tenable illustrates in their MCP FAQ, “The emergence of Model Context Protocol for AI is gaining significant interest due to its standardization of connecting external data sources to large language models (LLMs). While these updates are good news for AI developers, they raise some security concerns.” With over 12,000 MCP servers and counting, what does this all lead to and when will AI be connected enough for a malicious prompt to cause serious impact?


Read more of this story at Slashdot.

Intel Arc Graphics B570 & B580 Gaming Performance On Linux For Mid 2025

A number of Phoronix readers have been inquiring in recent weeks around seeing updated Linux graphics/gaming benchmarks for the Intel Arc B-Series “Battlemage” graphics cards. So for your viewing pleasure today is a look at the Arc Graphics B580 and B570 graphics cards on Ubuntu 25.04 for showing how the graphics performance have improved with the open-source Intel Linux graphics driver stack since launch.

Raspberry Pi Connect Exits Beta with Version 2.5 Release

Raspberry Pi has officially ended the beta phase of Raspberry Pi Connect, its remote access platform for connecting to Raspberry Pi devices from anywhere. With the release of version 2.5, the service now includes major updates to connection management, significantly reducing data usage and improving responsiveness. Launched in early 2024, Raspberry Pi Connect quickly gained […]

How To Claim Your Payout Of Apple’s $95 Million Siri Spying Settlement

How To Claim Your Payout Of Apple's $95 Million Siri Spying Settlement
It took several years, but there’s finally a proposed resolution for a privacy fumble related to Siri that prompted a rare apology from Apple back in 2019. As part of the proposed settlement, Apple would dole out $95 million in collective funds to past and present Siri device owners, though there is a deadline that is fast approaching to file

Nintendo Can Render Your Switch 2 ‘Permanently Unusable’ If You Break Their Rules

Slashdot reader BrianFagioli writes:

The new Nintendo Switch 2 is almost here. Next month, eager fans will finally be able to get their hands on the highly anticipated follow-up to the wildly popular hybrid console. But before you line up (or frantically refresh your browser for a preorder), you might want to read the fine print, because Nintendo might be able to kill your console.

Yes, really. That’s not just speculation, folks. According to its newly updated user agreement, Nintendo has granted itself the right to make your Switch 2 “permanently unusable” if you break certain rules. Yes, the company might literally brick your device. Buried in the legalese is a clause that says if you try to bypass system protections, modify software, or mess with the console in a way that’s not approved, Nintendo can take action. And that action could include completely disabling your system.

The exact wording makes it crystal clear: Nintendo may “render the Nintendo Account Services and/or the applicable Nintendo device permanently unusable in whole or in part….” [T]o be fair, this is probably targeted at people who reverse engineer the system or install unauthorized software — think piracy, modding, cheating, and the like. But the broad and vague nature of the language leaves a lot of room for interpretation. Who decides what qualifies as “unauthorized use”? Nintendo does.

Nintendo’s verbiage says users must agree “without limitation” not to…

Publish, copy, modify, reverse engineer, lease, rent, decompile, disassemble, distribute, offer for sale, or create derivative works
Obtain, install or use any unauthorized copies of Nintendo Account Services

Exploit the Nintendo Account Services in any manner other than to use them in accordance with the applicable documentation and intended use [unless “otherwise expressly permitted by applicable law.”]
Bypass, modify, decrypt, defeat, tamper with, or otherwise circumvent any of the functions or protections… including through the use of any hardware or software that would cause the Nintendo Account Services to operate other than in accordance with its documentation and intended use
“…if you fail to comply with the foregoing restrictions Nintendo may render the Nintendo Account Services and/or the applicable Nintendo device permanently unusable in whole or in part.”


Read more of this story at Slashdot.

CISA/DOGE Software Engineer’s Login Credentials Appeared in Multiple Leaks From Info-Stealing Malware in Recent Years

“Login credentials belonging to an employee at both the Cybersecurity and Infrastructure Security Agency and the Department of Government Efficiency have appeared in multiple public leaks from info-stealer malware,” reports Ars Technica, “a strong indication that devices belonging to him have been hacked in recent years.”

As an employee of DOGE, [30-something Kyle] Schutt accessed FEMA’s proprietary software for managing both disaster and non-disaster funding grants [to Dropsite News]. Under his role at CISA, he likely is privy to sensitive information regarding the security of civilian federal government networks and critical infrastructure throughout the U.S. According to journalist Micah Lee, user names and passwords for logging in to various accounts belonging to Schutt have been published at least four times since 2023 in logs from stealer malware… Besides pilfering login credentials, stealers can also log all keystrokes and capture or record screen output. The data is then sent to the attacker and, occasionally after that, can make its way into public credential dumps…

Lee went on to say that credentials belonging to a Gmail account known to belong to Schutt have appeared in 51 data breaches and five pastes tracked by breach notification service Have I Been Pwned. Among the breaches that supplied the credentials is one from 2013 that pilfered password data for 3 million Adobe account holders, one in a 2016 breach that stole credentials for 164 million LinkedIn users, a 2020 breach affecting 167 million users of Gravatar, and a breach last year of the conservative news site The Post Millennial.

The credentials may have been exposed when service providers were compromised, the article points out, but the “steady stream of published credentials” is “a clear indication that the credentials he has used over a decade or more have been publicly known at various points.

“And as Lee noted, the four dumps from stealer logs show that at least one of his devices was hacked at some point.”

Thanks to Slashdot reader gkelley for sharing the news.


Read more of this story at Slashdot.

SiFive and Kinara Partner to Launch USB-Based X280 RISC-V Vector Development Board

SiFive and Kinara have announced a new partnership to offer developers direct access to the SiFive Intelligence X280 RISC-V vector processor through a compact USB-based enablement board. The HiFive Xara X280 board, based on Kinara’s Ara-2 processor, is designed to allow early-stage evaluation and development of RISC-V vector software, particularly for AI and machine learning […]

Blizzard’s ‘Overwatch’ Team Just Voted to Unionize

“The Overwatch 2 team at Blizzard has unionized,” reports Kotaku:

That includes nearly 200 developers across disciplines ranging from art and testing to engineering and design. Basically anyone who doesn’t have someone else reporting to them. It’s the second wall-to-wall union at the storied game maker since the World of Warcraft team unionized last July… Like unions at Bethesda Game Studios and Raven Software, the Overwatch Gamemakers Guild now has to bargain for its first contract, a process that Microsoft has been accused of slow-walking as negotiations with other internal game unions drag on for years.
“The biggest issue was the layoffs at the beginning of 2024,” Simon Hedrick, a test analyst at Blizzard, told Kotaku… “People were gone out of nowhere and there was nothing we could do about it,” he said. “What I want to protect most here is the people….” Organizing Blizzard employees stress that improving their working conditions can also lead to better games, while the opposite — layoffs, forced resignations, and uncompetitive pay can make them worse….

“We’re not just a number on an Excel sheet,” [said UI artist Sadie Boyd]. “We want to make games but we can’t do it without a sense of security.” Unionizing doesn’t make a studio immune to layoffs or being shuttered, but it’s the first step toward making companies have a discussion about those things with employees rather than just shadow-dropping them in an email full of platitudes. Boyd sees the Overwatch union as a tool for negotiating a range of issues, like if and how generative AI is used at Blizzard, as well as a possible source of inspiration to teams at other studios.

“Our industry is at such a turning point,” she said. “I really think with the announcement of our union on Overwatch…I know that will light some fires.”

The article notes that other issues included work-from-home restrictions, pay disparities and changes to Blizzard’s profit-sharing program, and wanting codified protections for things like crunch policies, time off, and layoff-related severance.


Read more of this story at Slashdot.

Developer Tries Resurrecting 47-Year-Old ‘Apple Pascal’ (and its p-System) in Rust

Long-time Slashdot reader mbessey (a Mac/iOS developer) writes:

As we’re coming up on the 50th anniversary of the first release of UCSD Pascal, I thought it would be interesting to poke around in it a bit, and work on some tools to bring this “portable operating system” back to life on modern hardware, in a modern language (Rust).

Wikipedia describes UCSD Pascal as “a version that ran on a custom operating system that could be ported to different platforms. A key platform was the Apple II, where it saw widespread use as Apple Pascal. This led to Pascal becoming the primary high-level language used for development in the Apple Lisa, and later, the Macintosh. Parts of the original Macintosh operating system were hand-translated into Motorola 68000 assembly language from the Pascal source code.”

mbessey is chronicling their new project in a series of blog posts which begins here:

The p-System was not the first portable byte-code interpreter and compiler system — that idea goes very far back, at least to the origins of the Pascal language itself. But it was arguably one of the most-successful early versions of the idea and served as an inspiration for future portable software systems (including Java’s bytecode, and Infocom’s Z-machine).

And they’ve already gotten UCSD Pascal running in an emulator and built some tools (in Rust) to transfer files to disk images. Now they’re working towards writing a p-machine emulator in Rust, which they can they port to “something other than the Mac. Ideally, something small â” like an Arduino or Raspberry Pi Pico.”


Read more of this story at Slashdot.

Theranos Fraudster’s Partner Launches His Own Blood-Testing Startup

“The romantic partner of Theranos fraudster Elizabeth Holmes has launched a start-up that sounds eerily similar to the venture that landed his girlfriend behind bars,” writes The Daily Beast.
He’s incorporated “Haemanthus” in Delaware a year and a half ago (though the company operates out of his neighborhood in Austin), according to the New York Times. Haemanthus appears to have around 10 employees.

From The Daily Beast:
California hotel heir Billy Evans’ new company is a blood-testing firm that markets itself as “the future of diagnostics,” offering “a radically new approach to health testing,” according to The New York Times. In other words, exactly what Theranos said it would do. Holmes is even advising the start-up from the Texas prison where she is serving out an 11-year prison sentence for fraud, sources told NPR… Evans has managed to raise nearly $20 million in funds from both friends and established investors in Austin and San Francisco, according to the investor materials.

The Times reports that Evan’s company “plans to begin with testing pets for diseases before progressing to humans, according to two investors pitched on the company.”

And TechCrunch reminds readers that Elizabeth Holmes said in a recent interview “that she remains ‘completely committed to my dream of making affordable healthcare solutions available to everyone.'”


Read more of this story at Slashdot.