MoreRSS

site iconArs TechnicaModify

A website offering in-depth news, reviews, and guides on technology, science, and more, known for its technical expertise and insightful analysis.
Please copy the RSS to your reader, or quickly subscribe to:

Inoreader Feedly Follow Feedbin Local Reader

Rss preview of Blog of Ars Technica

Critical Copilot vulnerability allowed hackers to seal 2FA code from users

2026-06-16 19:15:46

Last Tuesday, Microsoft patched a vulnerability it rated as max critical in its M365 Copilot AI platform. On Monday, the researchers who discovered the vulnerability and reported it to Microsoft revealed how their proof-of-concept exploit could retrieve 2FA codes and other sensitive data from emails accessible to Copilot.

Microsoft and other LLM providers have been unable to prevent their products from complying with malicious requests to reveal data. The root cause: AI bots are unable to distinguish between instructions provided by users and those snuck into third-party content the models are summarizing, drafting responses to, or using to perform other actions on behalf of the user. With no way to secure this crucial boundary, Microsoft and its peers are left to erect complicated and ad hoc guardrails designed to rein in the consequences of this incurable gullibility.

Jumping over guardrails

One guardrail built into Copilot and most other LLMs prevents them from submitting web forms, sending emails, and taking similar actions that can be used to exfiltrate data from the user. To work around this, LLM hackers turned to markup language, which, among other things, allows users to add formatting elements such as headings, lists, and links to text without the need for HTML tags. Another workaround is to wrap sensitive data inside HTML tags such as <img> and <form>. In either case, a web request showing the data hits the attacker’s web server, where the secret information is captured in logs.

Read full article

Comments

Commodore’s newest gadget is a flip phone that blocks social media and browsers

2026-06-16 17:00:51

The next gadget to bear the storied Commodore branding will be a flip phone.

The name behind the bestselling desktop PC in history came back about a year ago. Christian “Peri Fractic” Simpson, best known for running the Retro Recipes (now known as Retro Recipes x Commodore) YouTube channel, acquired the Commodore Corporation and "100 percent of the original and official trademarks that defined the Commodore name since 1983,” per a July 2025 press release. Simpson said the price was “in the low seven figures.” Since the acquisition, the brand released the Commodore 64 Ultimate and the Commodore 64X PC, a mini PC housed in a chassis that resembles the Commodore 64.

Today, the new Commodore announced a new device in a dated design: a flip phone.

Read full article

Comments

Key mission for Europe's commercial space enterprise scrubbed again

2026-06-16 07:40:38

Isar Aerospace still commands top position among a new generation of European rocket startups, but the company's efforts to launch a critical test flight of its Spectrum rocket continue to encounter roadblocks.

The latest delay came Monday, when Isar scrubbed a launch attempt after "detecting off nominal behavior in the vehicle's fluid systems," according to a social media post. "The teams are analyzing the new data to isolate the root cause."

The two-stage, 92-foot-tall (28-meter) Spectrum rocket was awaiting liftoff from Andøya Spaceport in northern Norway. It was the fourth time in five months that Isar Aerospace, headquartered near Munich, Germany, had reached a target launch date for the second test flight of the Spectrum launch vehicle.

Read full article

Comments

Heart protection from COVID shots remains amid updates, study finds

2026-06-16 05:04:26

Although most Americans have eschewed seasonal COVID-19 vaccines, the updated shots continue to show significant protection against cardiovascular disease, especially for those over age 75 and those with underlying medical conditions. That's according to a new study that pulled data from more than 1 million patients in a US Department of Veterans Affairs (VA) health system.

The finding builds on previous data showing that the vaccines significantly lower the risk of COVID-19-associated cardiovascular risks, particularly heart attacks and strokes. But it wasn't a given that the benefit would hold up over time—as the virus evolved, the vaccines were updated, population-level immunity increased from previous infection and vaccination, and risk of severe outcomes fell.

The new study, published in JAMA Internal Medicine, found that the 2024–2025 COVID-19 vaccine continued to protect against COVID-19-associated "major adverse cardiovascular events" (MACE), which include cardiovascular death, heart attack, stroke, and hospitalization for heart failure.

Read full article

Comments

UK to ban social media for kids under 16, may impose overnight curfews

2026-06-16 04:14:04

The UK government announced today that it will ban social media for all kids under the age of 16 in rules expected to take effect in spring 2027. The ban will apply to platforms including Snapchat, TikTok, YouTube, Instagram, Facebook, and X.

"We’re going further than any country in the world by banning social media for under-16s and putting wider protections in place to give kids their childhood back," Prime Minister Keir Starmer said in the announcement.

In addition to the ban on social media, Starmer's government said it will impose "world-leading blocks on harmful functions such as livestreaming and stranger communication with children for under-16s... Restrictions on these functionalities will also be on by default for 16- and 17-year-olds to prevent a cliff-edge at 16." The livestreaming and stranger-contact rules would apply to a range of services, such as online gaming.

Read full article

Comments

Chipmaker Nvidia seeks to raise over $25B in first bond deal since 2021

2026-06-16 03:07:02

Chipmaker Nvidia is planning to sell $25 billion of investment-grade debt in the US on Monday, its first bond sale in five years, in a test of investor appetite for further exposure to the AI sector.

In a marquee seven-part bond offering, the company will issue a wide range of maturities from two years to 30 years, according to a term sheet seen by the FT.

The issuance was upsized from $20 billion after receiving more than $85 billion in orders by early afternoon in New York, according to people familiar with the deal.

Read full article

Comments