Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror

Submission + - Microsoft "mitigates" Windows LNK flaw exploited as zero-day (bleepingcomputer.com)

joshuark writes: Microsoft has silently "mitigated" a high-severity Windows LNK vulnerability exploited by multiple state-backed and cybercrime hacking groups in zero-day attacks.

Tracked as CVE-2025-9491, this security flaw allows attackers to hide malicious commands within Windows LNK files, which can be used to deploy malware and gain persistence on compromised devices. However, the attacks require user interaction to succeed, as they involve tricking potential victims into opening malicious Windows Shell Link (.lnk) files. Thus some element of social engineering, and user technically naive and gullibility such as thinking Windows is secure is required.

As Trend Micro threat analysts discovered in March 2025, the CVE-2025-9491 was already being widely exploited by 11 state-sponsored groups and cybercrime gangs, including Evil Corp, Bitter, APT37, APT43 (also known as Kimsuky), Mustang Panda, SideWinder, RedHotel, Konni, and others.

Microsoft told BleepingComputer in March that it would "consider addressing" this zero-day flaw, even though it didn't "meet the bar for immediate servicing."

ACROS Security CEO and 0patch co-founder Mitja Kolsek found, Microsoft has silently changed LNK files in the November updates in an apparent effort to mitigate the CVE-2025-9491 flaw. After installing last month's updates, users can now see all characters in the Target field when opening the Properties of LNK files, not just the first 260.

A Microsoft spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today to confirm if this change is an attempt to mitigate the vulnerability. As the movie the Ninth Gate stated: "silentium est aurum"

Submission + - Meta buried 'causal' evidence of social media harm (reuters.com)

joshuark writes: In a 2020 research project code-named “Project Mercury,” Meta scientists worked with survey firm Nielsen to gauge the effect of “deactivating” Facebook, according to Meta documents obtained via discovery. To the company’s disappointment, “people who stopped using Facebook for a week reported lower feelings of depression, anxiety, loneliness and social comparison,” internal documents said.

Rather than publishing those findings or pursuing additional research, the filing states, Meta called off further work and internally declared that the negative study findings were tainted by the “existing media narrative” around the company. Despite Meta’s own work documenting a causal link between its products and negative mental health effects, the filing alleges, Meta told Congress that it had no ability to quantify whether its products were harmful to teenage girls.

The allegation of Meta burying evidence of social media harms is just one of many in a filing by Motley Rice, a law firm suing Meta. Broadly, the plaintiffs argue the companies have intentionally hidden the internally recognized risks of their products from users, parents and teachers.

Meta spokesman Andy Stone said the study was stopped because its methodology was flawed and that it worked diligently to improve the safety of its products. “The full record will show that for over a decade, we have listened to parents, researched issues that matter most, and made real changes to protect teens,” he said.

"We strongly disagree with these allegations, which rely on cherry-picked quotes and misinformed opinions,” Stone said.
The underlying Meta documents cited in the filing are not public, and Meta has filed a motion to strike the documents. Stone said the objection was to the over-broad nature of what plaintiffs are seeking to unseal, not unsealing in its entirety.
A hearing regarding the filing is set for January 26 in Northern California District Court.

Submission + - Meta wants to get into the electricity trading business (yahoo.com)

joshuark writes: Meta is looking to get into the business of trading electricity to accelerate the construction of new power plants needed to provide energy for its data centers.

Meta are asking for federal approval to trade power. According to Meta, this will allow it to make long-term commitments to buy electricity from new plants, while mitigating the risk by having the ability to resell some of that power on wholesale power markets.

Meta’s head of global energy, Urvi Parekh, states that power plant developers “want to know that the consumers of power are willing to put skin in the game.” “Without Meta taking a more active voice in the need to expand the amount of power that’s on the system, it’s not happening as quickly as we would like,” Parekh said.

Two Stupid Dogs captured the moment in the 1990s: https://www.youtube.com/watch?...

Comment C. Montgomery Burns... (Score 1) 117

C. Montgomery Burns tried this idea...

https://www.youtube.com/watch?...

And I agree with Waylon Smithers, "Owls will deafen us with incessant hooting..." Woodsy the Owl will become our greatest nemesis...

https://www.youtube.com/watch?... the new "dirty bird" without the sun. The new golden age, of darkness looms overhead...

JoshK.

Submission + - DHS head reportedly authorized purchase of planes that airline didn't own (theguardian.com)

joshuark writes: DHS head reportedly authorized purchase of 10 engineless Spirit Airlines planes that airline didn’t own– and that the aircraft lacked engines. The bizarre anecdote was contained in a Wall Street Journal report released on Friday, which recounted how Noem and Corey Lewandowski – who managed Donald Trump’s first winning presidential campaign – had recently arranged to buy 10 Boeing 737 aircraft from Spirit Airlines. People familiar with the situation told the paper that the two intended to use the jets to expand deportation flights – and for personal travel.

Complicating matters further, Spirit, which filed for bankruptcy protection for the second time, in August, did not own the jets and their engines would have had to be bought separately. Meanwhile, Democrats on the House appropriations committee said in October that during this fall’s record-long government shutdown, the DHS had already acquired two Gulfstream jets for $200m.

“It has come to our attention that, in the midst of a government shutdown, the United States Coast Guard entered into a sole source contract with Gulfstream Aerospace Corporation to procure two new G700 luxury jets to support travel for you and the deputy secretary, at a cost to the taxpayer of $200m,” Democratic representatives Rosa DeLauro and Lauren Underwood wrote in a letter to the DHS.

The American taxpayer's dollars at work for truth, freedom, justice, and the American $$$ way.

Submission + - Target Mandates Worker Smiles, Friendliness to Boost Sales in "Forced Joy" (bloomberg.com) 2

joshuark writes: The Minneapolis-based retailer has a new directive for store employees: If a shopper comes within 10 feet of you, then make sure you smile, make eye contact and greet or wave. If they come closer — within four feet — ask whether they need help or how their day is going, according to new guidance confirmed by Bloomberg News. This is part of the Forced Joy trend.

The new initiative — dubbed the 10-4 program internally — is among Target’s latest efforts to make its stores more welcoming and reverse its extended streak of weak sales. “Heading into the holiday, we’re making adjustments and implementing new ways to increase connection during the most important time of the year,” Chief Stores Officer Adrienne Costanzo said in a statement to Bloomberg News.

Target, which is set to report quarterly earnings later this month, recently cut 1,800 corporate roles to remove complexities and move faster. The company’s shares are down more than 30% year-to-date, compared to a 14% gain for the S&P 500. The retailer’s cheap chic allure has faded and customers have complained on social media about bare shelves and long lines.
Target has made trumped-up enthusiasm an expectation. Bugs Bunny said it best... https://www.youtube.com/watch?...

Comment When something... (Score 1) 35

When something is banned, or made forbidden for the young, then the younger generation want it more.

The classic law of opposites, say its good for you, kids loathe it, say don't do kids want to do it. Thus Denmark is going to create a surge of interest in social media for the 15-year old and under demographic.

When Dungeons and Dragons was forbidden in high school in the 1980s, suddenly all the kids wanted to play. :)

Example...

https://www.youtube.com/watch?...

JoshK.

Comment I am using... (Score 3, Informative) 44

I am using more non-Mac apps, like Adobe Acrobat Reader instead of Preview, as the rounded corners or PDF documents are like fingernails across a chalkboard for me visually.

I prefer documents to have sharp, right angle corners. The rounded corners are akin to some "safety" feature so I don't get a paper cut...and then sue Apple.

JoshK.

Submission + - Mark Zuckerberg Opened an Illegal School at His Palo Alto Compound. His Neighbor (wired.com)

joshuark writes: Mark Zuckerberg opend an unlicensed school named after the Zuckerbergs’ pet chicken, but it tipped neighbors over the edge the Wired magazine story reports. The school may have been operating as early as 2021 without a permit to operate in the city of Palo Alto. As many as 30 students might have enrolled, according to observations from neighbors.

Over time, neighbors became fed up with what they argued was the city’s lack of action, particularly with respect to the school. Some believed that the delay was because of preferential treatment to the Zuckerbergs. “We find it quite remarkable that you are working so hard to meet the needs of a single billionaire family while keeping the rest of the neighborhood in the dark,” reads one email sent to the city’s Planning and Development Services Department in February. “Just as you have not earned our trust, this property owner has broken many promises over the years, and any solution which depends on good faith behavioral changes from them is a failure from the beginning.”

In order for the Zuckerbergs to run a private school on their land, which is in a residential zone, they need a “conditional use” permit from the city. However, based on the documents WIRED obtained, and Palo Alto’s public database of planning applications, the Zuckerbergs do not appear to have ever applied for or received this permit.

Most of the Zuckerbergs’ neighbors did not respond to WIRED’s request for comment. However, the ones that did clearly indicated that they would not be forgetting the Bicken Ben saga, or the past decade of disruption, anytime soon.

Comment Wasn't the last "new" new thing... (Score 1) 92

Wasn't the last "new" new thing, 3-d printing supposed to be the next industrial revolution, only at home? The industry returning to the cottage, and all that delightful utopian futurism? The return of manufacturing, only at a personal level.

A home person could 3-d print an engine support bracket flange for their Saturn automobile, Or a new pot handle for their Sunbeam electric kettle, or a valve knob for your Bernz-O-matic cigarette lighter, all from your home. ???

JoshK.

Slashdot Top Deals

We're here to give you a computer, not a religion. - attributed to Bob Pariseau, at the introduction of the Amiga

Working...