Iphone

Hardware Mod Showcases an iPhone SE 3 in the Body of a Windows Phone (9to5mac.com) 26

A tech enthusiast has successfully transplanted the internal components of an iPhone SE 3 into the body of a Nokia Lumia 1020 Windows Phone, according to a post on Reddit's r/hackintosh forum. The modification preserves all key functions of the iPhone SE 3, including its 12-megapixel camera, 5G capabilities, and Touch ID sensor, which has been relocated to the back of the device. The project retains the Lumia 1020's distinctive design while upgrading its outdated microUSB port to Apple's Lightning connector.

The creator adapted the Lumia's original camera shutter button to work as a secondary volume control that can trigger photos in the iPhone's camera app. The only significant feature lost in the conversion was the headphone jack.
AI

Ask Slashdot: What Would It Take For You to Trust an AI? (win.tue.nl) 179

Long-time Slashdot reader shanen has been testing AI clients. (They report that China's DeepSeek "turned out to be extremely good at explaining why I should not trust it. Every computer security problem I ever thought of or heard about and some more besides.")

Then they wondered if there's also government censorship: It's like the accountant who gets asked what 2 plus 2 is. After locking the doors and shading all the windows, the accountant whispers in your ear: "What do you want it to be...?" So let me start with some questions about DeepSeek in particular. Have you run it locally and compared the responses with the website's responses? My hypothesis is that your mileage should differ...

It's well established that DeepSeek doesn't want to talk about many "political" topics. Is that based on a distorted model of the world? Or is the censorship implemented in the query interface after the model was trained? My hypothesis is that it must have been trained with lots of data because the cost of removing all of the bad stuff would have been prohibitive... Unless perhaps another AI filtered the data first?

But their real question is: what would it take to trust an AI? "Trust" can mean different things, including data-collection policies. ("I bet most of you trust Amazon and Amazon's secret AIs more than you should..." shanen suggests.) Can you use an AI system without worrying about its data-retention policies?

And they also ask how many Slashdot readers have read Ken Thompson's "Reflections on Trusting Trust", which raises the question of whether you can ever trust code you didn't create yourself. So is there any way an AI system can assure you its answers are accurate and trustworthy, and that it's safe to use? Share your own thoughts and experiences in the comments.

What would it take for you to trust an AI?
Hardware

PassMark Sees the First Yearly Drop In Average CPU Performance In Its 20 Years (tomshardware.com) 54

For the first time since 2004, PassMark's global CPU benchmark data shows a decline in average processor performance, with laptop CPUs dropping 3.4% and desktop CPUs falling 0.5% year-over-year. Tom's Hardware reports: We see the biggest drop in laptop CPU performance results. PassMark recorded an average result of 14,632 across 101,316 samples last year. But, in 2025, the average score sat at an average of 14,130 points between 25,541 samples, decreasing the average score by 3.4%. The average desktop PC result in 2024 netted 26,436 points for 186,053 samples. But for 2025, the average score currently sits at 26,311 points for over 47,810 samples -- a 0.5% drop from last year. While that drop is small, we should only see a continued progression of faster performance.

[...] Passmark itself mused on X (formerly Twitter) that it could be that people are switching to more affordable machines that deliver lower power and performance. Or maybe Windows 11 is depressing performance scores versus Windows 10, especially as people transition to it with the upcoming demise of the latter. We've certainly seen plenty of examples of reduced performance in gaming with some of the newer versions of Windows 11, particularly as Intel and AMD struggled to upstream needed updates into the OS. [...] PassMark also muses that bloatware could contribute to the sudden decline in performance, but that seems like a longshot.

Chrome

Google Chrome May Soon Use 'AI' To Replace Compromised Passwords (arstechnica.com) 46

Google's Chrome browser might soon get a useful security upgrade: detecting passwords used in data breaches and then generating and storing a better replacement. From a report: Google's preliminary copy suggests it's an "AI innovation," though exactly how is unclear.

Noted software digger Leopeva64 on X found a new offering in the AI settings of a very early build of Chrome. The option, "Automated password Change" (so, early stages -- as to not yet get a copyedit), is described as, "When Chrome finds one of your passwords in a data breach, it can offer to change your password for you when you sign in."

Chrome already has a feature that warns users if the passwords they enter have been identified in a breach and will prompt them to change it. As noted by Windows Report, the change is that now Google will offer to change it for you on the spot rather than simply prompting you to handle that elsewhere. The password is automatically saved in Google's Password Manager and "is encrypted and never seen by anyone," the settings page claims.

The Internet

The Enshittification Hall of Shame 249

In 2022, writer and activist Cory Doctorow coined the term "enshittification" to describe the gradual deterioration of a service or product. The term's prevalence has increased to the point that it was the National Dictionary of Australia's word of the year last year. The editors at Ars Technica, having "covered a lot of things that have been enshittified," decided to highlight some of the worst examples the've come across. Here's a summary of each thing mentioned in their report: Smart TVs: Evolved into data-collecting billboards, prioritizing advertising and user tracking over user experience and privacy. Features like convenient input buttons are sacrificed for pushing ads and webOS apps. "This is all likely to get worse as TV companies target software, tracking, and ad sales as ways to monetize customers after their TV purchases -- even at the cost of customer convenience and privacy," writes Scharon Harding. "When budget brands like Roku are selling TV sets at a loss, you know something's up."

Google's Voice Assistant (e.g., Nest Hubs): Functionality has degraded over time, with previously working features becoming unreliable. Users report frequent misunderstandings and unresponsiveness. "I'm fine just saying it now: Google Assistant is worse now than it was soon after it started," writes Kevin Purdy. "Even if Google is turning its entire supertanker toward AI now, it's not clear why 'Start my morning routine,' 'Turn on the garage lights,' and 'Set an alarm for 8 pm' had to suffer."

Portable Document Format (PDF): While initially useful for cross-platform document sharing and preserving formatting, PDFs have become bloated and problematic. Copying text, especially from academic journals, is often garbled or impossible. "Apple, which had given the PDF a reprieve, has now killed its main selling point," writes John Timmer. "Because Apple has added OCR to the MacOS image display system, I can get more reliable results by screenshotting the PDF and then copying the text out of that. This is the true mark of its enshittification: I now wish the journals would just give me a giant PNG."

Televised Sports (specifically cycling and Formula 1): Streaming services have consolidated, leading to significantly increased costs for viewers. Previously affordable and comprehensive options have been replaced by expensive bundles across multiple platforms. "Formula 1 racing has largely gone behind paywalls, and viewership is down significantly over the last 15 years," writes Eric Berger. "Major US sports such as professional and college football had largely been exempt, but even that is now changing, with NFL games being shown on Peacock, Amazon Prime, and Netflix. None of this helps viewers. It enshittifies the experience for us in the name of corporate greed."

Google Search: AI overviews often bury relevant search results under lengthy, sometimes inaccurate AI-generated content. This makes finding specific information, especially primary source documents, more difficult. "Google, like many big tech companies, expects AI to revolutionize search and is seemingly intent on ignoring any criticism of that idea," writes Ashley Belanger.

Email AI Tools (e.g., Gemini in Gmail): Intrusive and difficult to disable, these tools offer questionable value due to their potential for factual inaccuracies. Users report being unable to fully opt-out. "Gmail won't take no for an answer," writes Dan Goodin. "It keeps asking me if I want to use Google's Gemini AI tool to summarize emails or draft responses. As the disclaimer at the bottom of the Gemini tool indicates, I can't count on the output being factual, so no, I definitely don't want it."

Windows: While many complaints about Windows 11 originated with Windows 10, the newer version continues the trend of unwanted features, forced updates, and telemetry data collection. Bugs and performance issues also plague the operating system. "... it sure is easy to resent Windows 11 these days, between the well-documented annoyances, the constant drumbeat of AI stuff (some of it gated to pricey new PCs), and a batch of weird bugs that mostly seem to be related to the under-the-hood overhauls in October's Windows 11 24H2 update," writes Andrew Cunningham. "That list includes broken updates for some users, inoperable scanners, and a few unplayable games. With every release, the list of things you need to do to get rid of and turn off the most annoying stuff gets a little longer."

Web Discourse: The rapid spread of memes, trends, and corporate jargon on social media has led to a homogenization of online communication, making it difficult to distinguish original content and creating a sense of constant noise. "[T]he enshittifcation of social media, particularly due to its speed and virality, has led to millions vying for their moment in the sun, and all I see is a constant glare that makes everything look indistinguishable," writes Jacob May. "No wonder some companies think AI is the future."
Windows

Microsoft's Windows 10 Extended Security Updates Will Start at $61 per PC for Businesses 70

Microsoft will charge commercial customers $61 per device in the first year to continue receiving Windows 10 security updates after support ends, The Register wrote in a PSA note Wednesday, citing text, with costs doubling each subsequent year for up to three years.

Organizations can't skip initial years to save money, as the updates are cumulative. Some users may avoid fees if they connect Windows 10 endpoints to Windows 365 Cloud PCs. The program also covers Windows 10 virtual machines running on Windows 365 or Azure Virtual Desktop for three years with an active Windows 365 subscription.
Windows

Microsoft Quietly Makes It Harder To Install Windows 11 on Old PCs Ahead of Windows 10's End of Support (xda-developers.com) 138

Microsoft has intensified efforts to block unsupported Windows 11 installations, removing documentation about bypassing system requirements and flagging third-party workaround tools as potential malware. The move comes as Windows 10 approaches end of support in October 2025, when users must either continue without updates, upgrade to Windows 11, or purchase new hardware compatible with Windows 11's TPM 2.0 requirement.

Microsoft Defender now identifies Flyby11, a popular tool for installing Windows 11 on incompatible devices, as "PUA:Win32/Patcher." Users are also reporting that unsupported Windows 11 installations are already facing restrictions, with some machines unable to receive major updates. Microsoft has also removed text from its "Ways to install Windows 11" page that had provided instructions for bypassing TPM 2.0 requirements through registry key modifications. The removed section included technical details for users who acknowledged and accepted the risks of installing Windows 11 on unsupported hardware.
Graphics

Microsoft Paint Gets a Copilot Button For Gen AI Features (pcworld.com) 26

A new update is being rolled out to Windows 11 insiders (Build 26120.3073) that introduces a Copilot button in Microsoft Paint. PCWorld reports: Clicking the Copilot button will expand a drop-down menu with all the generative AI features: Cocreator and Image Creator (AI art based on what you've drawn or text prompts), Generative Erase (AI removal of unwanted stuff from images), and Remove Background. Note that these generative AI features have been in Microsoft Paint for some time, but this quick-access Copilot button is a nice time-saver and productivity booster if you use them a lot.
Windows

After 'Copilot Price Hike' for Microsoft 365, It's Ending Its Free VPN (windowscentral.com) 81

In 2023, Microsoft began including a free VPN feature in its "Microsoft Defender" security app for all Microsoft 365 subscribers ("Personal" and "Family"). Originally Microsoft had "called it a privacy protection feature," writes the blog Windows Central, "designed to let you access sensitive data on the web via a VPN tunnel." But.... Unfortunately, Microsoft has now announced that it's killing the feature later this month, only a couple of years after it first debuted...

To add insult to injury, this announcement comes just days after Microsoft increased subscription prices across the board. Both Personal and Family subscriptions went up by three dollars a month, which the company says is the first price hike Microsoft 365 has seen in over a decade. The increased price does now include Microsoft 365 Copilot, which adds AI features to Word, PowerPoint, Excel, and others.

However, it also comes with the removal of the free VPN in Microsoft Defender, which I've found to be much more useful so far.

Displays

The 25-Year Success Story of SereneScreen (pcgamer.com) 24

A recent video from retro tech YouTuber Clint "LGR" Basinger takes a deep dive into the history of the SereneScreen Marine Aquarium, exploring how former Air Force pilot Jim Sachs transformed a lackluster Windows 95 screensaver into a 25-year digital phenomenon. PC Gamer reports: The story centers on Jim Sachs, a man with one of those "they don't make this type of guy anymore" life stories so common to '80s and '90s computing, one Sachs recounted to the website AmigaLove back in 2020. After a six-year career in the US Air Force flying C-141 Starlifters, Sachs taught himself programming and digital art and began creating games for Commodore 64 and Amiga computers. From his first game, Saucer Attack, to later efforts like Defender of the Crown or his large portfolio of promotional and commissioned pieces, Sach's pixel art remains gorgeous and impressive to this day, and he seems to be a bit of a legend among Commodore enthusiasts.

It's with this background in games and digital art that Sachs looked at Microsoft's simple aquarium-themed screensaver for Windows 95 and 98 and thought he could do better. "Microsoft had an aquarium that they gave away with Windows where it was just bitmaps of fish being dragged across the screen," Sachs told the Matt Chat podcast back in 2015. "And they had that for like, three or four years. And I thought, I've given them enough time, I'm taking them to market. I'm gonna do something which will just blow that away."

Using reference photographs of real aquariums -- Sachs thanked a specific pet shop that's still around in an early version of his website" -- Sachs created the 3D art by hand and programmed the screensaver in C++, releasing the initial version in July 2000. Even looking at it all these years later, the first iteration of the SereneScreen Marine Aquarium is pretty gorgeous, and it has the added charm of being such a distinctly Y2K, nostalgic throwback.

The standalone screensaver sold well, but then things came full circle with Microsoft licensing a version of the Marine Aquarium for the Windows XP Plus Pack and later standard releases of the OS. Since that time, the Marine Aquarium has continued to see new releases, and a section on the SereneScreen website keeps track of its various appearances in the background of movies and TV shows like Law and Order. Over on the SereneScreen website, you can purchase a real time, 3D-accelerated version of the Marine Aquarium for Mac, iOS, Android, and the original Windows. Echoing the Windows XP deal, Roku actually licensed this 3.0 version for its TVs, bringing it to a new generation of users.

The Internet

NordVPN Says Its New Protocol Can Circumvent VPN Blockers (gizmodo.com) 26

NordVPN has introduced NordWhisper, a new protocol designed to bypass VPN blocks in restrictive countries like Russia and India by making VPN traffic appear like regular internet activity. Gizmodo reports: NordVPN claims to have found a way to make traffic from its service look normal, though admits that it may not always work perfectly. It also says the NordWhisper protocol may introduce more latency. The protocol is rolling out first to users on Windows, Linux, and Android. Support for other platforms will come in the future.
Science

Microplastics Found In the Brains of Mice Within Hours of Consumption (phys.org) 44

A team of biologists have found that it takes microplastics consumed by mice just a few hours to reach their brains. "Wondering if the plastic in their brains was causing any impairment, the researchers tested several of the mice and found that many of them experienced memory loss, reductions in motor skills and lower endurance," reports Phys.Org. From the report: In this new effort, the research team sought to learn more about the medical impact of a mammal consuming different sizes of microplastics. The experiments consisted of feeding test mice water with different sized bits of fluorescent plastic in it, from micro to nano. They then tracked the progress of the plastic bits to see where they wound up in the bodies of the mice.

Knowing that the plastic would make its way from the digestive tract into the bloodstream, the researchers used two-photon microscopy to capture imagery of it inside blood vessels. Also, suspecting that the tiniest bits would make it into their brains, the team installed tiny windows in their skulls, allowing them to track the movement of the plastic in their brains.

In studying the imagery they created, the researchers were able to watch as the plastics made their way around the mice's bodies, eventually reaching their brains. They also noted that the plastic bits tended to get backed up, like cars in a traffic jam at different points. In taking a closer look at some of the backups in the brain, the researchers found that the plastic bits had been captured by immune cells, which led to even more backups.
The findings have been published in the journal Science Advances.
AI

Bad Week for Unoccupied Waymo Cars: One Hit in Fatal Collision, One Vandalized by Mob (nbcbayarea.com) 69

For the first time in America, an empty self-driving car has been involved in a fatal collision. But it was "hit from behind by a speeding car that was going about 98 miles per hour," a local news site reports, citing comments from Waymo. ("Two other victims were taken to the hospital with life-threatening injuries. A dog also died in the crash, according to the San Francisco Fire Department.")

Waymo's self-driving car "is not being blamed," notes NBC Bay Area. Instead the Waymo car was one of six vehicles "struck when a fast-moving vehicle slammed into a line of cars stopped at a traffic light..." The National Highway Traffic Safety Administration requires self-driving car companies, like Waymo, to report each time their vehicles are involved in an accident, regardless of whether the autonomous vehicle was at fault. According to NHTSA, which began collecting such data in July 2021, Waymo's driverless vehicles have been involved in about 30 different collisions resulting in some type of injury. Waymo, however, has noted that nearly all those crashes, like Sunday's collision, were the fault of other cars driven by humans. While NHTSA's crash data doesn't note whether self-driving vehicles may have been to blame, Waymo has previously noted that it only expects to pay out insurance liability claims for two previous collisions involving its driverless vehicles that resulted in injuries.

In December, Waymo touted the findings of its latest safety analysis, which determined its fleet of driverless cars continue to outperform human drivers across major safety metrics. The report, authored by Waymo and its partners at the Swiss Reinsurance Company, reviewed insurance claim data to explore how often human drivers and autonomous vehicles are found to be liable in car collisions. According to the study, Waymo's self-driving vehicles faced about 90% fewer insurance claims relating to property damage and bodily injuries compared to human drivers... The company's fleet of autonomous vehicles have traveled more than 33 million miles and have provided more than five million rides across San Francisco, Los Angeles, Phoenix and Austin...

In California, there are more than 30 companies currently permitted by the DMV to test driverless cars on the open road. While most are still required to have safety drivers sitting in the front seat who can take over when needed, Waymo remains the only fleet of robotaxis in California to move past the state's testing phase to, now, regularly offer paid rides to passengers.

Their article adds that while Sunday's collision marks the first fatal crash involving a driverless car, "it was nearly seven years ago when another autonomous vehicle was involved in a deadly collision with a pedestrian in Tempe, Arizona, though that self-driving car had a human safety driver behind the wheel. The accident, which occurred in March 2018, involved an autonomous car from Uber, which sold off its self-driving division two years later to a competitor."

In other news, an unoccupied Waymo vehicle was attacked by a mob in Los Angeles last night, according to local news reports. "Video footage of the incident appears to show the vehicle being stripped of its door, windows shattered, and its Jaguar emblems removed. The license plate was also damaged, and the extent of the vandalism required the vehicle to be towed from the scene."

The Los Angeles Times reminds its readers that "Last year, a crowd in San Francisco's Chinatown surrounded a Waymo car, vandalized it and then set it ablaze..."
AI

'Copilot' Price Hike for Microsoft 365 Called 'Total Disaster' with Overwhelmingly Negative Response (zdnet.com) 129

ZDNET's senior editor sees an "overwhelmingly negative" response to Microsoft's surprise price hike for the 84 million paying subscribers to its Microsoft 365 software suite. Attempting the first price hike in more than 12 years, "they made it a 30% price increase" — going from $10 a month to $13 a month — "and blamed it all on artificial intelligence." Bad idea. Why? Because...

No one wants to pay for AI...

If you ask Copilot in Word to write something for you, the results will be about what you'd expect from an enthusiastic summer intern. You might fare better if you ask Copilot to turn a folder full of photos into a PowerPoint presentation. But is that task really such a challenge...?

The announcement was bungled, too... I learned about the new price thanks to a pop-up message on my Android phone... It could be worse, I suppose. Just ask the French and Spanish subscribers who got a similar pop-up message telling them their price had gone from €10 a month to €13,000. (Those pesky decimals.) Oh, and I've lost count of the number of people who were baffled and angry that Microsoft had forcibly installed the Copilot app on their devices. It was just a rebranding of the old Microsoft 365 app with the new name and logo, but in my case it was days later before I received yet another pop-up message telling me about the change...

[T]hey turned the feature on for everyone and gave Word users a well-hidden checkbox that reads Enable Copilot. The feature is on by default, so you have to clear the checkbox to make it go away. As for the other Office apps? "Uh, we'll get around to giving you a button to turn it off next month. Maybe." Seriously, the support page that explains where you can find that box in Word says, "We're working on adding the Enable Copilot checkbox to Excel, OneNote, and PowerPoint on Windows devices and to Excel and PowerPoint on Mac devices. That is tentatively scheduled to happen in February 2025." Until the Enable Copilot button is available, you can't disable Copilot.

ZDNET's senior editor concludes it's a naked grab for cash, adding "I could plug the numbers into Excel and tell you about it, but let's have Copilot explain instead."

Prompt: If I have 84 million subscribers who pay me $10 a month, and I increase their monthly fee by $3 a month each, how much extra revenue will I make each year?

Copilot describes the calculation, concluding with "You would make an additional $3.024 billion per year from this fee increase." Copilot then posts two emojis — a bag of money, and a stock chart with the line going up.
Wine

Wine 10.0 Released (betanews.com) 34

BrianFagioli shares a report from BetaNews: The Wine team has officially released Wine 10.0, marking a full year of extensive development with over 6,000 changes. This stable release introduces major updates designed to enhance performance, compatibility, and visual experience when running Windows applications on Linux and other non-Windows platforms. Here's a list of the new changes and features:

- Full ARM64EC Support: Now on par with ARM64, allowing the creation of hybrid ARM64X modules blending ARM64EC and ARM64 code in a single binary.
- 64-bit x86 Emulation: Leverages ARM64EC to run internal processes natively, reducing the need for resource-intensive emulation.
- High-DPI Scaling Overhaul: Automatic adjustments for non-DPI-aware applications on high-resolution displays with customizable compatibility flags.
- Vulkan Improvements: Support for Vulkan child window rendering under X11 and compatibility with Vulkan 1.4.303.
- Direct3D Updates: Fixed-function pipeline for legacy Direct3D versions and introduced Dynamic Vulkan extensions to reduce stuttering.
- Experimental FFmpeg Backend: Better multimedia playback for applications with complex media pipelines.
- New Display Configuration Tool: Allows inspection and modification of settings, including virtual desktop resolutions.
- Wayland Graphics Driver: Enabled by default on Linux, with support for OpenGL and improved popup window placement (X11 takes precedence unless disabled).
- Input Device Improvements: Enhanced touchscreen support for X11 and expanded Bluetooth functionality.
- Internationalization Enhancements: Updated Unicode character tables and timezone data for better global compatibility.
- Upgraded Libraries: Includes FluidSynth, LibPng, and Vkd3d, alongside new developer tools like the Clang Static Analyzer and improved ARM64 support for C++ exceptions.

You can download Wine 10.0 and learn more about the release here.
Games

EA's Origin App For PC Gaming Will Shut Down In April 17

EA's Origin PC client will be shut down on April 17, 2025, as Microsoft ends support for 32-bit software. "Anyone still using Origin will need to swap over to the EA app before that date," adds Engadget. From the report: For those PC players who have not migrated over to the EA app, the company has an FAQ explaining the latest system requirements. The EA app runs on 64-bit architecture, and requires a machine using Windows 10 or Windows 11. [...] If you're simply downloading the EA app on a current machine, players won't need to re-download their games. And if you have cloud saves enabled, all of your data should transfer without any additional steps.

However, it's always a good idea to have physical backups with this type of transition, especially since not all games support cloud saves, and those titles will need to have saved game data manually transferred. Mods also may not automatically make the switch, and EA recommends players check with mod creators about transferring to the EA app.
Google

Google Upgrades Open Source Vulnerability Scanning Tool with SCA Scanning Library (googleblog.com) 2

In 2022 Google released a tool to easily scan for vulnerabilities in dependencies named OSV-Scanner. "Together with the open source community, we've continued to build this tool, adding remediation features," according to Google's security blog, "as well as expanding ecosystem support to 11 programming languages and 20 package manager formats... Users looking for an out-of-the-box vulnerability scanning CLI tool should check out OSV-Scanner, which already provides comprehensive language package scanning capabilities..."

Thursday they also announced an extensible library for "software composition analysis" scanning (as well as file-system scanning) named OSV-SCALIBR (Open Source Vulnerability — Software Composition Analysis LIBRary). The new library "combines Google's internal vulnerability management expertise into one scanning library with significant new capabilities such as:
  • Software composition analysis for installed packages, standalone binaries, as well as source code
  • OSes package scanning on Linux (COS, Debian, Ubuntu, RHEL, and much more), Windows, and Mac
  • Artifact and lockfile scanning in major language ecosystems (Go, Java, Javascript, Python, Ruby, and much more)
  • Vulnerability scanning tools such as weak credential detectors for Linux, Windows, and Mac
  • Software Bill of Materials (SBOM) generation in SPDX and CycloneDX, the two most popular document formats
  • Optimization for on-host scanning of resource constrained environments where performance and low resource consumption is critical

"OSV-SCALIBR is now the primary software composition analysis engine used within Google for live hosts, code repos, and containers. It's been used and tested extensively across many different products and internal tools to help generate SBOMs, find vulnerabilities, and help protect our users' data at Google scale. We offer OSV-SCALIBR primarily as an open source Go library today, and we're working on adding its new capabilities into OSV-Scanner as the primary CLI interface."


Microsoft

Microsoft Begins Forcing Windows 24H2 Updates on PCs (pcworld.com) 106

Microsoft began mandatory rollouts of the Windows 11 2024 Update (24H2) for eligible devices running Home and Pro editions, the company announced on its Windows 11 issues page. The update, which Microsoft describes as a "full code swap," requires longer installation times, with users reporting processes exceeding an hour.

While users can briefly postpone the installation, the company is now pushing updates to mainstream users not managed by IT departments. The 24H2 update introduces USB4's 80Gbps support, Bluetooth LE Audio for hearing aids, and enhanced Energy Saver controls.
Microsoft

Microsoft Patches Windows To Eliminate Secure Boot Bypass Threat (arstechnica.com) 39

Microsoft has patched a Windows vulnerability that allowed attackers to bypass Secure Boot, a critical defense against firmware infections, the company said. The flaw, tracked as CVE-2024-7344, affected Windows devices for at least seven months. Security researcher Martin Smolar discovered the vulnerability in a signed UEFI application within system recovery software from seven vendors, including Howyar.

The application, reloader.efi, circumvented standard security checks through a custom PE loader. Administrative attackers could exploit the vulnerability to install malicious firmware that persists even after disk reformatting. Microsoft revoked the application's digital signature, though the vulnerability's impact on Linux systems remains unclear.

Slashdot Top Deals