News

Denmark Says Russia Was Behind Two 'Destructive and Disruptive' Cyberattacks (theguardian.com) 56

The Danish government has accused Russia of being behind two "destructive and disruptive" cyberattacks in what it describes as "very clear evidence" of a hybrid war. From a report: The Danish Defence Intelligence Service (DDIS) announced on Thursday that Moscow was behind a cyberattack on a Danish water utility in 2024 and a series of distributed denial-of-service (DDoS) attacks on Danish websites in the lead-up to the municipal and regional council elections in November.

The first, it said, was carried out by the pro-Russian group known as Z-Pentest and the second by NoName057(16), which has links to the Russian state. "The Russian state uses both groups as instruments of its hybrid war against the west," DDIS said in a statement. "The aim is to create insecurity in the targeted countries and to punish those that support Ukraine. Russia's cyber operations form part of a broader influence campaign intended to undermine western support for Ukraine." It added: "The DDIS assesses that the Danish elections were used as a platform to attract public attention -- a pattern that has been observed in several other European elections."

Businesses

Trump's Social Media Business Is Merging With a Nuclear Fusion Company 74

Tony Isaac shares a report from CNN: President Donald Trump's social media and crypto company is making a huge bet on a far different industry -- nuclear fusion, a potentially lucrative albeit commercially unproven energy technology that could help power a suddenly electricity-starved economy. Trump Media and Technology Group Thursday announced a surprise merger with TAE Technologies, in an all-stock deal valued at more than $6 billion that would create one of the first publicly traded fusion companies. News of the deal shares of Trump Media (DJT) 35% higher in early trading Thursday.

After the deal closes, shareholders of Trump Media and TAE would own about 50% of the combined entity. The combined companies plan to begin construction as soon as next year of the world's first fusion reaction that could produce electricity on utility scale, rather than just in laboratory settings. The combination with TMTG could give TAE political clout. But it could also make it more politically controversial, particularly if it looks to receive any kind of federal government support, such as grants, low-interest loans or permitting approvals.

It could also give TAE access to capital that it needs. Under terms of the deal, TMTG would provide $300 million in cash for TAE's plans. But that is likely a fraction of the cash available from some of TAE's current investors, such as Google parent company Alphabet, as well as its bevy of private equity investors. But that $300 million is only a fraction of the money that TAE needs, or expects to be able to access, once it has become a public company with this deal. Staying a private company, even with deep pocketed investors, is no longer sufficient TAE CEO Michl Binderbauer told CNN Thursday.
"It's a multi-billion dollar undertaking," said Binderbauer. "The velocity you can get the capital is differentiating. If I raise $2 billion over five years I can't built the plant sufficiently fast." He said the company has raised about $1.3 billion over the course of its 25-year history.
Privacy

Mass Hacking of IP Cameras Leave Koreans Feeling Vulnerable in Homes, Businesses (joins.com) 17

Hackers breached approximately 120,000 IP cameras across South Korea and allegedly sold footage captured from private homes, gynecology offices, breastfeeding rooms and massage parlors to an overseas pornography website, prompting an interagency government task force to announce sweeping reforms on December 7.

Police believe one suspect alone hacked 63,000 cameras and produced 545 videos that netted him 35 million won ($24,000) in cryptocurrency; a second suspect, operating independently, compromised 70,000 devices and earned 18 million won from 648 videos. The footage accounted for 62% of all content on the website, which maintains a dedicated "Korean" category. A government survey found that only 59% of installation companies consistently carried out mandatory security measures such as changing default passwords. Lawmakers are now pursuing legislation requiring security-certified IP cameras in sensitive facilities.
China

How China Built Its 'Manhattan Project' To Rival the West in AI Chips (reuters.com) 171

Chinese scientists have built a working prototype of an extreme ultraviolet lithography machine in a high-security Shenzhen laboratory, a development that represents exactly what Washington has spent years and multiple rounds of export controls trying to prevent: China's path toward semiconductor independence and an end to the West's monopoly on the technology that powers AI, smartphones and advanced weapons systems.

The prototype, completed in early 2025 by former ASML engineers who reverse-engineered the Dutch company's machines, is operational and generating EUV light, though it has not yet produced working chips. The effort is part of a six-year secret government initiative that sources described to Reuters as China's version of the Manhattan Project.

Huawei is coordinating thousands of engineers across companies and state research institutes, and recruits are working under false identities inside secure facilities. The Chinese government is targeting 2028 for producing working chips, though sources say 2030 is more realistic -- still years earlier than the decade analysts had predicted it would take China to match the West.
China

Another Starship Clone Pops Up In China (arstechnica.com) 54

Longtime Slashdot reader schwit1 shares a report from Ars Technica: Every other week, it seems, a new Chinese launch company pops up with a rocket design and a plan to reach orbit within a few years. For a long time, the majority of these companies revealed designs that looked a lot like SpaceX's Falcon 9 rocket. The first of these copy cats, the medium-lift Zhuque-3 rocket built by LandSpace, launched earlier this month. Its primary mission was nominal, but the Zhuque-3 rocket failed its landing attempt, which is understandable for a first flight. Doubtless there will be more Chinese Falcon 9-like rockets making their debut in the near future. However, over the last year, there has been a distinct change in announcements from China when it comes to new launch technology. Just as SpaceX is seeking to transition from its workhorse Falcon 9 rocket -- which has now been flying for a decade and a half -- to the fully reusable Starship design, so too are Chinese companies modifying their visions.

The trend began with the Chinese government. In November 2024 the government announced a significant shift in the design of its super-heavy lift rocket, the Long March 9. Instead of the previous design, a fully expendable rocket with three stages and solid rocket boosters strapped to the sides, the country's state-owned rocket maker revealed a vehicle that mimicked SpaceX's fully reusable Starship. Around the same time, a Chinese launch firm named Cosmoleap announced plans to develop a fully reusable "Leap" rocket within the next few years. An animated video that accompanied the funding announcement indicated that the company seeks to emulate the tower catch-with-chopsticks methodology that SpaceX has successfully employed.

But wait, there's more. In June a company called Astronstone said it too was developing a stainless steel, methane-fueled rocket that would also use a chopstick-style system for first stage recovery. Astronstone didn't even pretend to not copy SpaceX, saying it was "fully aligning its technical approach with Elon Musk's SpaceX." And then, on Friday, the state-aligned China.com reported that a company called "Beijing Leading Rocket Technology" took things a step further. It has named its vehicle "Starship-1," adding that the new rocket will have enhancements from AI and is billed as a "fully reusable AI rocket."

Government

Senate Confirms Billionaire Entrepreneur Jared Isaacman As New NASA Chief (politico.com) 69

Longtime Slashdot reader schwit1 shares a report from Politico: The Senate on Wednesday approved Jared Isaacman for the top job at NASA -- an unprecedented comeback after President Donald Trump yanked his nomination this spring. Senators confirmed the billionaire private astronaut in a 67-30 vote. Trump renominated Isaacman for NASA administrator in November, after pulling his original nomination in May. He cited Isaacman's relationship with SpaceX CEO Elon Musk, with whom Trump had just had a falling out, as the rationale for his decision. Isaacman's surprise rebound followed months of political jockeying and help from high-profile figures in Trump's orbit. [...] Isaacman garnered backing from lawmakers during his hearing by confirming his support for NASA's Artemis moon-landing mission, a key prerogative for Capitol Hill. He also committed to instilling urgency at the space agency, citing China's space ambitions.
Government

FCC Chair Suggests Agency Isn't Independent, Word Cut From Mission Statement (axios.com) 110

FCC Chairman Brendan Carr said in his Wednesday Senate testimony that the agency he governs "is not an independent agency, formally speaking." Axios: During his testimony, the word "independent" was removed from the FCC's mission statement on its website. The extraordinary statement speaks to a broader trend of regulatory agencies losing power to the executive branch during the Trump era. Last week, the Supreme Court appeared poised to allow President Trump to fire members of the Federal Trade Commission during oral arguments over the issue.

Sen. Ben Ray LujÃn (D-N.M.) began the line of questioning, citing the FCC's website, which said the agency was independent as of Wednesday morning. By Wednesday afternoon, the FCC's mission statement no longer said it was independent. Chairman Carr would not respond directly to questions about whether he believed the president was his boss. He would not answer whether it's appropriate if the president were to pressure him to go after media companies. He suggested the president has the power to fire him and other FCC commissioners.

Science

How We Ingest Plastic Chemicals While Consuming Food (washingtonpost.com) 67

A comprehensive database built by scientists in Switzerland and Norway has catalogued 16,000 chemicals linked to plastic materials, and the findings paint a troubling picture of what Americans are actually eating when they prepare food in their kitchens. Of those 16,000 chemicals, more than 5,400 are considered hazardous to human health by government and industry standards, while just 161 are classified as not hazardous. The remaining 10,700-plus chemicals simply don't have enough data to determine their safety.

The chemicals enter food through multiple pathways. Black plastic utensils and trays often contain brominated flame retardants because they're made from recycled electronic waste. Nonstick pans and compostable plates frequently contain PFAS. One California study found phthalates in three-quarters of tested foods, and a Consumer Reports analysis last year detected BPA or similar chemicals in 79% of foods tested. According to CDC data, more than 90% of Americans have measurable levels of these chemicals in their bodies. A 10-fold increase in maternal levels of brominated flame retardants is associated with a 3.7-point IQ drop in children.
The Almighty Buck

Uber and DoorDash Try To Halt NYC Law That Encourages Tipping (nytimes.com) 208

An anonymous reader quotes a report from the New York Times: Two of the largest food-delivery app companies have made a last-ditch effort to overturn tipping laws in New York City that go into effect in January just as its next mayor, who has been highly critical of the companies and the app industry, takes office. Tips to delivery workers have plummeted since some food-delivery apps switched to showing the tipping option only after a purchase had been completed; that change came after New York City established the country's first minimum pay-rate for the workers in 2023. The new laws will require the apps to suggest a minimum tip of 10 percent at checkout, though customers can contribute more or less, or nothing at all.

Two of the app companies, DoorDash and Uber, filed a joint federal lawsuit in the Southern District of New York late last week targeting the City Council legislation, arguing that the new rules violated the First Amendment by requiring them to "speak a government-mandated message" and exceeded the Council's authority. Although tipping will be optional under the law, the companies wrote in the suit that a "mandated pre-delivery 10 percent tip suggestion" would cause customers to use the app less because they were suffering from "tipping fatigue." "Lessened engagement would result in fewer orders," the suit said.

Privacy

Breach At South Korea's Equivalent of Amazon Exposed Data of Almost Every Adult (wsj.com) 32

An anonymous reader quotes a report from the Wall Street Journal: The alleged perpetrator had improper access to virtually every South Korean adult's personal information: names, phone numbers and even the keycode to enter residential buildings. It was one of the biggest data breaches of recent years and it has sent the company it targeted -- Coupang, South Korea's equivalent of Amazon -- reeling, generating lawsuits, government investigation and calls to toughen penalties against such leaks. The leak went undetected for nearly five months, hitting Coupang's radar on Nov. 18 only after a customer flagged suspicious activity.

At first, Coupang, which was founded by a Korean-American entrepreneur, said it had experienced a data "exposure" affecting roughly 4,500 customer accounts. But within days, the e-commerce firm revised the figure: The leak exposed up to roughly 34 million user accounts in South Korea -- a sum representing more than 90% of the country's working-age population. Coupang started calling the incident a "leak" after Korean regulators took issue with the company's prior word choice. "The Whole Nation Is a Victim," read one local news headline.

An investigation has found that the alleged perpetrator had once worked in South Korea as a software developer for authentication systems at Coupang, which is known for its blockbuster U.S. initial public offering a few years ago. The suspected leaker is believed to be a Chinese national who has moved back to China and is now on the lam, South Korean officials say. They haven't named the person. Even after leaving the firm roughly a year ago, the suspect secretly held on to an internal authentication key that granted him unfettered access to the personal information of Coupang users, South Korean authorities and lawmakers say. The infiltration, using overseas servers, started on June 24. By using the login credentials, the suspect was able to appear as if he were still a Coupang employee when accessing the company's systems.

Advertising

Meta Tolerates Rampant Ad Fraud From China To Safeguard Billions In Revenue (reuters.com) 54

A Reuters investigation found that Meta knowingly tolerated large volumes of scam and illegal ads from China worth billions in revenue. Reuters reports: Though China's authoritarian government bans use of Meta social media by its citizens, Beijing lets Chinese companies advertise to foreign consumers on the globe-spanning platforms. As a result, Meta's advertising business was thriving in China, ultimately reaching over $18 billion in annual sales in 2024, more than a tenth of the company's global revenue. But Meta calculated that about 19% of that money -- more than $3 billion -- was coming from ads for scams, illegal gambling, pornography and other banned content, according to internal Meta documents reviewed by Reuters.

The documents are part of a cache of previously unreported material generated over the past four years by teams including Meta's finance, lobbying, engineering and safety divisions. The cache reveals Meta's efforts over that period to understand the scale of abuse on its platforms and the company's reluctance to introduce fixes that could undermine its business and revenues. The documents show that Meta believed China was the country of origin of roughly a quarter of all ads for scams and banned products on Meta's platforms worldwide. Victims ranged from shoppers in Taiwan who purchased bogus health supplements to investors in the United States and Canada who were swindled out of their savings. "We need to make significant investment to reduce growing harm," Meta staffers warned in an internal April 2024 presentation to leaders of its safety operations.

To that end, Meta created an anti-fraud team that went beyond previous efforts to monitor scams and other banned activity from China. Using a variety of stepped-up enforcement tools, it slashed the problematic ads by about half during the second half of 2024 -- from 19% to 9% of the total advertising revenue coming from China. Then Meta Chief Executive Mark Zuckerberg weighed in. "As a result of Integrity Strategy pivot and follow-up from Zuck," a late 2024 document notes, the China ads-enforcement team was "asked to pause" its work. Reuters was unable to learn the specifics of the CEO's involvement or what the so-called "Integrity Strategy pivot" entailed. But after Zuckerberg's input, the documents show, Meta disbanded its China-focused anti-scam team. It also lifted a freeze it had introduced on granting new Chinese ad agencies access to its platforms. One document shows that Meta shelved yet other anti-scam measures that internal tests had indicated would be effective. The document didn't detail the specifics of those measures.

Meta took these steps even as an outside consultant it hired produced research that warned "Meta's own behavior and policies" were fostering systemic corruption in the Chinese market for ads targeting users in other countries, additional documents show. The upshot: Within a few months of Meta's brief crackdown, a new crop of Chinese advertising agencies was flooding Facebook and Instagram with prohibited ads. By mid-2025, banned ads climbed back to about 16% of Meta's China revenue. Rob Leathern, who was a senior director of product management at Facebook until 2020 and is no longer at the company, said the scale of predatory advertising revealed in the documents represents a major breakdown in consumer protections at the social media giant. "The levels that you're talking about are not defensible," he said of the percentage of abusive ads. "I don't know how anyone could think this is okay."

Canada

Mark Carney Criticised For Using British Spellings In Canadian Documents (theguardian.com) 121

An anonymous reader quotes a report from the Guardian: Mark Carney says that amid a fundamental shift to the nature of globalization, his government will catalyze the growth in both the public and private sector. But Canadian linguists say that's a problem. Language experts have called out the Canadian prime minister's growing "utilization" of British spellings in key documents -- including the recent federal budget and a press release issued following a meeting with Donald Trump.

Carney, who served as the governor of the bank of England for seven years, appears to have run afoul of Canadian linguistic norms, returning to his home country with a penchant for using 's' instead of 'z'- a hallmark of British spellings. In an open letter (PDF) chastising the prime minister, six linguists have asked his office, the Canadian government and parliament to stick to Canadian English spelling, "which is the spelling they consistently used from the 1970s to 2025." They warned that if governments start to use other systems for spelling, "this could lead to confusion about which spelling is Canadian."

Canadian English is a source of immense pride for the nation's pedants. But the country's distinct and somewhat arbitrary spelling reflects the legacy of how Canada was colonized. "Canadian English evolved through Loyalist settlement after the American Revolutionary War, subsequent waves of English, Scottish, Welsh and Irish immigration, and from European and global contexts," the letter says, with the current accepted spellings of words reflecting "global influences and cultures from around the world represented in our population, as well as containing words and phrases from Indigenous languages." The linguists pointed out that Canada's distinct style of spelling was widespread in media and government documents, with this deliberate decision reflecting a desire to preserve a vital element of the country's "national history, identity and pride."

Transportation

Volkswagen To End Production At German Plant, a First In Company History (nytimes.com) 43

An anonymous reader quotes a report from the New York Times: The last vehicle will roll off the assembly line at Volkswagen's plant in Dresden, Germany, on Tuesday, marking the first time in the automaker's 88-year history that it has closed a plant in its home country. Volkswagen warned of potential production cuts last year, as it faced shaky demand in Europe and China, its biggest market, as well as higher tariffs that have crimped sales in the United States.

After 24 years of vehicle production, the Dresden plant will be converted into a research hub focused on technologies like artificial intelligence, robotics and chip design. Volkswagen will team up with the government of the state of Saxony and the Dresden University of Technology on the project at the plant, known as the Transparent Factory because of its glass walls. "We did not take the decision to end vehicle production at the Transparent Factory after more than 20 years lightly," Thomas Schafer, chief executive of the Volkswagen brand, said in a statement. "From an economic perspective, however, it was absolutely necessary."

Television

Texas Sues TV Makers For Taking Screenshots of What People Watch (bleepingcomputer.com) 80

mprindle writes: The Texas Attorney General sued five major television manufacturers, accusing them of illegally collecting their users' data by secretly recording what they watch using Automated Content Recognition (ACR) technology.

The lawsuits target Sony, Samsung, LG, and China-based companies Hisense and TCL Technology Group Corporation. Attorney General Ken Paxton's office also highlighted "serious concerns" about the two Chinese companies being required to follow China's National Security Law, which could give the Chinese government access to U.S. consumers' data.

According to complaints filed this Monday in Texas state courts, the TV makers can allegedly use ACR technology to capture screenshots of television displays every 500 milliseconds, monitor the users' viewing activity in real time, and send this information back to the companies' servers without the users' knowledge or consent.

Businesses

McKinsey Plots Thousands of Job Cuts in Slowdown for Consulting Industry (bloomberg.com) 26

McKinsey, the consulting giant that has spent a century advising companies on how to cut costs and restructure operations, is now turning that advice inward as it plans to eliminate thousands of jobs across its non-client-facing departments over the next 18 to 24 months.

The firm's leadership has discussed a roughly 10% headcount reduction in support functions, according to Bloomberg. McKinsey's revenue has hovered around $15 billion to $16 billion for the past five years after a decade of rapid expansion that saw employee count climb from 17,000 in 2012 to 45,000 by 2022. The headcount has since slid to about 40,000.

The cuts come as consulting firms face cost-conscious clients, Trump administration pressure on government consulting spending, and reduced payments from Saudi Arabia, which had been paying McKinsey at least $500 million annually in the decade up to 2024. McKinsey cut about 1,400 jobs in 2023 under a plan internally labeled Project Magnolia, and axed 200 global tech positions last month. The firm still plans to hire consultants even as it shrinks support staff.
Security

China, Iran Are Having a Field Day With React2Shell, Google Warns (theregister.com) 30

A critical React vulnerability (CVE-2025-55182) is being actively exploited at scale by Chinese, Iranian, North Korean, and criminal groups to gain remote code execution, deploy backdoors, and mine crypto. The Register reports: React maintainers disclosed the critical bug on December 3, and exploitation began almost immediately. According to Amazon's threat intel team, Chinese government crews, including Earth Lamia and Jackpot Panda, started battering the security hole within hours of its disclosure. Palo Alto Networks' Unit 42 responders have put the victim count at more than 50 organizations across multiple sectors, with attackers from North Korea also abusing the flaw.

Google, in a late Friday report, said at least five other suspected PRC spy groups also exploited React2Shell, along with criminals who deployed XMRig for illicit cryptocurrency mining, and "Iran-nexus actors," although the report doesn't provide any additional details about who the Iran-linked groups are and what they are doing after exploitation. "GTIG has also observed numerous discussions regarding CVE-2025-55182 in underground forums, including threads in which threat actors have shared links to scanning tools, proof-of-concept (PoC) code, and their experiences using these tools," the researchers wrote.

The Internet

Cloudflare Reveals How Bots and Governments Reshaped the Internet in 2025 (nerds.xyz) 23

Cloudflare's sixth annual Year in Review report describes an internet increasingly shaped by two forces: automated traffic and government intervention, as global connectivity grew 19% year over year in 2025.

Google's web crawler now dominates automated traffic, dwarfing other AI and indexing bots to become the single largest source of bot activity on the web. Nearly half of all major internet disruptions globally were linked to government actions, and civil society and non-profit organizations became the most attacked sector for the first time.

Post-quantum encryption crossed a significant threshold, now protecting 52% of human internet traffic observed by Cloudflare. The company also recorded more than 25 record-breaking DDoS attacks throughout the year.
United States

US Tech Force Aims To Recruit 1,000 Technologists (nextgov.com) 53

The Trump administration announced Monday the United States Tech Force, a new program to recruit around 1,000 technologists for two-year government stints starting as soon as March -- less than a year after dismantling several federal technology teams and driving thousands of tech workers out of their jobs.

The program will primarily recruit early-career software engineers and data scientists, paying between $150,000 and $200,000 annually. About 20 companies have signed on to participate, including Palantir, Meta, Oracle and Elon Musk's xAI. Some engineering managers will be allowed to take leaves of absence from their private-sector employers to join the program without divesting their stock holdings.

The initiative follows the March closure of 18F, General Services Administration's internal tech consultancy, and the shuttering of the Social Security Administration's Office of Transformation in February. The IRS had lost over 2,000 tech workers by June.
News

How Did the CIA Lose a Nuclear Device? (nytimes.com) 73

Sixty years after a team of American and Indian climbers abandoned a plutonium-powered generator on the slopes of Nanda Devi, one of the world's most forbidding Himalayan peaks, the U.S. government still refuses to acknowledge that the mission ever happened. The device, a SNAP-19C portable generator containing plutonium isotopes including Pu-239 -- the same material used in the Nagasaki bomb -- was left behind in October 1965 when a sudden blizzard forced climbers to retreat from Camp Four, just below the summit.

The mission originated from a cocktail party conversation between General Curtis LeMay and National Geographic photographer Barry Bishop, who had summited Everest in 1963. China had just detonated its first atomic bomb in October 1964, and the CIA wanted to intercept radio signals from Chinese missile tests by placing an unmanned listening station atop the Himalayas. Barry Bishop recruited elite American climbers and coordinated with Indian intelligence to haul surveillance equipment up the mountain.

Captain M.S. Kohli, the Indian naval officer commanding the mission, ordered climbers to secure the equipment and descend when the blizzard struck. Jim McCarthy, the last surviving American climber, recalled warning Kohli he was making a mistake. "You can't leave plutonium by a glacier feeding into the Ganges!" he recalled. "Do you know how many people depend on the Ganges?" When teams returned in spring 1966, the entire ice ledge where the gear had been stashed was gone -- sheared off by an avalanche. Search missions in 1967 and 1968 found nothing.

The device remains buried somewhere in the glaciers that feed tributaries of the Ganges River.
Social Networks

Like Australia, Denmark Plans to Severely Restrict Social Media Use for Teenagers (apnews.com) 92

"As Australia began enforcing a world-first social media ban for children under 16 years old this week, Denmark is planning to follow its lead," reports the Associated Press, "and severely restrict social media access for young people." The Danish government announced last month that it had secured an agreement by three governing coalition and two opposition parties in parliament to ban access to social media for anyone under the age of 15. Such a measure would be the most sweeping step yet by a European Union nation to limit use of social media among teens and children.

The Danish government's plans could become law as soon as mid-2026. The proposed measure would give some parents the right to let their children access social media from age 13, local media reported, but the ministry has not yet fully shared the plans... [A] new "digital evidence" app, announced by the Digital Affairs Ministry last month and expected to launch next spring, will likely form the backbone of the Danish plans. The app will display an age certificate to ensure users comply with social media age limits, the ministry said.

The article also notes Malaysia "is expected to ban social media accounts for people under the age of 16 starting at the beginning of next year, and Norway is also taking steps to restrict social media access for children and teens.

"China — which manufacturers many of the world's digital devices — has set limits on online gaming time and smartphone time for kids."

Slashdot Top Deals