ZeroHour

Search: “Snap”

11 stories in the last 30d

How much of F-Droid is LLM generated?

A FOSS maintainer manually graded 102 F-Droid apps from the September 12, 2026 update batch, finding many show signs of LLM-generated code.

A student and FOSS app maintainer reviewed 102 apps pushed to F-Droid on September 12, 2026, assigning each a three-tier rating for likelihood of LLM-authored code (mostly AI >50%, hard to say/mostly human, no signs of AI). The heuristic relies on commit aesthetics, README and branding style, and the presence of agentic infrastructure like Claude Code or Codex, which automatically places an app in the 'mostly AI' tier. Example ratings include Amber (Nostr event signer) as mostly AI, and Aria for Misskey as showing no AI signs. The author stresses reliable detection of LLM-generated code from text alone is impossible, so ratings are approximate.

LLMs are real, AI is fake

Cory Doctorow argues the OpenAI chatbot 'hacking' of Hugging Face was a Python-scripted CTF loop, not autonomous AI.

In an opinion essay, Cory Doctorow debunks reports that OpenAI chatbots autonomously hacked Hugging Face servers during an 'Exploit Gym' capture-the-flag challenge. He explains the chatbot merely acts as a front-end queried by a Python program that replays commands drawn from CTF training data. He argues sensational 'AI went rogue' narratives are amplified by technical press and help AI companies raise investment capital.

I spent $4,000 on a robot dog from China

Hands-on review finds the $4,017 Unitree Go2 Pro robot dog affordable but impractical, as Unitree reaches a $34 billion valuation after its IPO.

Ars Technica reviewed the Unitree Go2 Pro quadruped, purchased for $4,017, finding it astonishingly cheap but of limited practical use; it collapsed from battery drain and heat (84°C internal temperature) on an uphill walk at 87°F. Unitree democratized quadruped research, sells humanoid robots from $13,500, and debuted on the Shanghai stock exchange on August 19 with shares rising over fivefold on day one, valuing the company at $34 billion. Its robots now face legal restrictions in the United States, and it competes with Boston Dynamics, whose Spot starts around $75,000.

Ars Technica · AI · 4d agoAI industry

Apple Watch’s new AI features are normalizing the idea that technology is always listening

TechCrunch argues Apple Watch's Live Rewind and Siri Recap normalize always-listening AI, raising consent and legal questions despite privacy safeguards.

Analysis of Apple's new Apple Watch AI features contends that Live Rewind, which transcribes the previous 15 seconds of audio, and Siri Recap, which generates high-level conversation notes, are pushing consumers toward accepting always-listening technology. The piece acknowledges the accessibility value of on-device Audio Intelligence, which alerts deaf or hard-of-hearing users to sounds like sirens, alarms, doorbells, and crying babies. It also raises concerns about consent, the evidentiary status of text-only transcripts in court, and cultural effects of pervasive capture, noting competitors like Friend, Amazon's Bee, and Plaud in the AI transcription space.

TechCrunch · AIupdated · 5d agofirst · 6d agoAI industry 7 sources

US disrupts Xinbi Guarantee marketplace fueling the cyber scam economy

US Treasury sanctions and DOJ seizures take down Xinbi Guarantee, a Telegram marketplace that processed $24B+ for cyber scams, freezing $52.8M.

The Treasury Department sanctioned the Chinese-language Telegram marketplace Xinbi Guarantee and two supporting firms, Anwen Technology (XinbiPay) and SafeW Technology, while the DOJ seized its Telegram channels and $52.8 million in USDT from 52 wallets. Blockchain intelligence firm Elliptic, which assisted the Secret Service, estimates Xinbi has processed at least $24 billion in transactions since 2022, making it the second-largest illicit online marketplace and a cornerstone of Southeast Asian cybercrime. Vendors sold money laundering, stolen personal data, deepfake technology, and other services for pig-butchering scams, with payments in Tether's USDT. The DOJ's Scam Center Task Force also dismantled 13 scam centers in Madagascar, arresting dozens of alleged leaders who were repatriated to China.

The Recordupdated · 5d agofirst · 6d agoPolicy & legal 4 sources

Italian tech collective Autistici/Inventati shuts down after US terrorist designation

Italian privacy collective Autistici/Inventati shut down after a US State Department terrorist designation triggered its domain suspension and bank account closure.

The volunteer-run Italian collective Autistici/Inventati, founded in 2001, announced Sunday it would shut down after the State Department labeled it an extremist group on August 26, 2026. The designation led the Public Interest Registry to suspend the group's .org domain on August 28 and its bank, Banca Etica, to suspend its account. The collective hosted roughly 16,000 email addresses, 1,500 websites, 5,500 mailing lists, and about 10,000 blogs, including the Noblogs platform. European Digital Rights warned the move sets a dangerous precedent for non-commercial European hosts and digital sovereignty.

The Record · 7d agoPolicy & legal

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

Infoblox reports Sable Squirrel spent nearly $7 million on expired domains to redirect traffic to illegal sports streaming, gambling, and malware infrastructure.

Infoblox tracked 50,400 dropcatch domains re-registered daily in gTLDs during H1 2026, nearly 20% of all registrations, with .net and .xyz leading. The threat actor Sable Squirrel has acquired more than 10,000 expired domains supporting Asian sports piracy brands such as Xoilac, Cakhia, 90phut, Socolive, and MiTom while promoting betting services like VSBet, ColaScore, and 8xbet. The operation, assessed as Vietnam-based and overlapping the dismantled Xoi Lac TV streaming network, targets users in Vietnam, South Korea, Japan, Taiwan, Singapore, and Australia via a traffic distribution system, publishes Android apps through suspected compromised Google Play developer accounts, and deployed over 31,000 malware samples including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, and njRAT.

The Hacker News · 8d agoThreat actor in the wild1

Norway considers ban on camera-enabled wearable ‘pervert glasses’

Norway's government is weighing bans on camera-enabled smart glasses and facial recognition in public to protect privacy.

Norway's digital minister Karianne Tung said the government is considering regulating or banning camera-enabled wearables such as Meta and Snap smart glasses over privacy concerns. Potential measures may include banning facial recognition of other people in public places. The government plans to set up an expert group to advise on better protecting privacy rights amid a trend of combining AI with cameras and microphones in everyday devices.

TechCrunch · Security · 14d agoPolicy & legal

Meta pledges to overhaul kids’ safety protections, pay $17 billion to settle social media case

Meta settles states' kids' online safety lawsuit for $17 billion, agreeing to landmark usage limits, age restrictions, and independent auditing.

Meta agreed to pay $17 billion to settle a civil suit from nearly every US state and territory alleging it hid research showing Facebook and Instagram are addictive to minors and violated COPPA by collecting data on children under 13. The settlement imposes reforms including two-hour daily limits for users under 18, a midnight-to-6am usage block, non-personalized feed options, and an independent auditor. Meta also settled separately with Texas for about $1 billion.

The Record · 20d agoPolicy & legal

The AI Malware Maturity Gap

Recorded Future introduces AIM3, a five-level maturity model for AI malware, showing current attacker AI use is mostly AI-assisted rather than autonomous.

Recorded Future proposes AIM3, a five-level model defining AI malware from LLM-translated to LLM-embedded, spanning experimentation to fully autonomous agentic campaigns. Public examples remain early-stage: PROMPTFLUX uses Google Gemini to rewrite its VBScript dropper (Level 1), while Lamehug/PROMPTSTEAL, attributed to APT28, invokes the HuggingFace API to generate reconnaissance commands (Level 3). The authors argue most current AI malware augments existing tradecraft rather than enabling one-click autonomous attacks.

Recorded Future · 21d agoResearch

Senators press TikTok over withholding of safety features for some users

Sens. Blackburn and Blumenthal demand TikTok explain why safety features were withheld from about 10% of users, following a teenager's suicide.

Sens. Marsha Blackburn and Richard Blumenthal sent a letter demanding answers from TikTok after a Bloomberg report showed the company withheld algorithmic safety changes from a control group of about 10% of users, including 16-year-old Chase Nasca, who died by suicide in February 2022. An internal review found the teen viewed more than 7,500 videos in his final two weeks, 73% with themes of sadness or personal struggles. The senators tied the case to the Kids Online Safety Act, which advanced out of the Senate Commerce Committee on August 5, and set a September 1 deadline for responses.

The Record · 27d agoPolicy & legal