AI

Linux Kernel Team Publishes 432 CVEs In Two Days 48

Ancient Slashdot reader alanw shares a post from the OSS Security mailing list, where sysadmin Jan Schaumann wonders what to do after the Linux kernel cranked out 432 CVEs in a little over 24 hours: "I understand the position that CVEs were always a flawed way to track or prioritize security changes... But this onslaught really shows it's not feasible to attempt to prioritize individual kernel changes. I'm not sure what to do here going forward." The Register reports: The nixCraft team speculated on social media that AI bug reports are a likely reason for all those kernel CVEs, which wouldn't be without precedent - Linus Torvalds himself said in May that the Linux kernel security mailing list had become "almost entirely unmanageable" due to AI-assisted bug hunting. Nonetheless, Torvalds has described AI as a useful tool for Linux development while still noting it can be a drag for maintainers, both from a workload standpoint and the fact "it keeps finding embarrassing bugs." [...]

Unfortunately for Linux sysadmins, the position in which they find themselves in this current mess isn't one that's readily solved. CVEs might be a messy way to track and prioritize security updates, especially when hundreds of them are published over a short period, but without something better, it falls to IT and security teams to determine which vulnerabilities affect their systems and which kernel updates they need to deploy.
Senior kernel maintainer Greg Kroah-Hartman replied to Jan's post, pushing back on the idea that the kernel's CVE volume is uniquely unmanageable. The kernel isn't special, he argues -- companies everywhere are finally realizing they need to re-evaluate how they update all of their systems and devices, something that's traditionally been "woefully ignored."

On the "just always update" approach, Greg says that's precisely what the kernel community endorses: "This is what the kernel developer community recommends and supports. If you want support from us, do this." Can't manage it yourself? Pay a company for support, or "just use Debian or Yocto as their security practices are amazing." He points to Android as proof the approach scales, calling it "the largest deployment of software in the world" -- billions of devices kept updated "with one very-overworked developer guiding it all."

As for reviewing every CVE individually, he notes this can be largely automated by intersecting the files a CVE touches with the files you actually build, which typically trims the relevant set "down to about 10% of the overall total" -- the approach enterprise distros already take for their customers. Panic-mode selective patching gets a blunt "Good luck with that!" -- regulations like the EU's Cyber Resilience Act are set to legislate that habit away ("rightfully so," in his view), and "your insurance company might wish to have a talk with you as well."

Greg also warns the flood isn't over: "The number of llm-found issues is only on the rise right now, it's going to be a very long 18 months at the least to dig ourselves out of this mess, and people had BETTER be updating their systems all along the way if they expect to be secure in any way." As for the 432-CVE burst itself, he explains it was simply him catching up on a weeks-old, publicly visible review queue over the weekend -- delayed by "a perfect storm of 6 weeks straight of conferences and vacations" -- so it shouldn't have come as a surprise to anyone watching the public git repo.
The Almighty Buck

The Galaxy Card Is Samsung's Answer To the Apple Card (wired.com) 24

An anonymous reader quotes a report from Wired: Nearly seven years after Apple debuted the Apple Card, Samsung is following the iPhone maker's footsteps with the Galaxy Card, aiming for its own slice of the credit card market. The announcement comes two days before Samsung's second Galaxy Unpacked event of the year, where it's expected to showcase new smartwatches and folding smartphones. The Galaxy Card is issued by Barclays on the Visa network; the Apple Card, originally issued by Goldman Sachs but now transitioning to Chase, is on the MasterCard network. There is a physical card -- it's not made of titanium but recycled steel.

The virtual card will be provisioned to a user's Samsung Wallet account. With no annual fee, Samsung says cardmembers can earn 5 percent cash rewards on all in-store or online purchases made directly from Samsung in the US, 3 percent cash rewards on purchases made with the Galaxy Card using Samsung Wallet, 2 percent cash rewards on streaming service subscriptions, and 1 percent cash rewards on everything else with the physical card. The cash rewards can be redeemed as a statement credit or transferred to a checking or savings account. The annual percentage rate (APR) varies by cardmember, but the card has no foreign transaction fees. Other perks include a 20 percent discount on Samsung's VIP Advantage membership, which offers extended device protection, specialized support, and exclusive deals, and $200 in cash rewards after spending $2,000 in the first 90 days.

Applications open up on July 22. The Samsung Wallet app is only available on Samsung smartphones and watches, so what happens if a consumer switches to a different smartphone brand? The company says Galaxy Card is not limited to Samsung device owners and that anyone can use the physical card, but you lose the key perks; the card can be managed through a BarclaysUS.com online portal. (Similarly, if an iPhone owner switches to Android, their physical Apple Card will still work, but they lose access to the Apple Wallet app and the 3 percent daily cash perk on Apple purchases; there's a web portal to manage the account.)

Programming

Rust Will Help Linux Succeed and Makes Coding Fun, Says Greg Kroah-Hartman (zdnet.com) 121

ZDNet reports on June's Open Source Summit India 2026 in Mumbai, where Linux stable kernel maintainer Greg Kroah-Hartman gave a talk titled "Rust and Linux: How the Rust Language is Going to Help Linux Succeed." Kroah-Hartman said in his keynote that "the [Linux] kernel is moving toward Rust. Git is moving toward Rust. Lots of projects are starting to move toward Rust."

He didn't always feel that way. Kroah-Hartman added, "A number of years ago, when a friend of mine said, 'Ah, you got to try this new language. It's called Rust.' I was like, 'What? No, C is great.' His friend continued, "'No, no, no! It makes programming fun again.' I'm like, 'Nah, programming is fun in C.' He was right. I should have done it then. Rust is actually fun. It makes programming fun. It takes a lot of stuff away from having to worry about the compiler, which can fix a lot of your problems for you, and it makes code a little bit better."

So, Kroah-Hartman has moved from being a Rust skeptic to one of its strongest champions inside the kernel. He now regards Rust as a permanent part of Linux, not an experiment. His case is straightforward: Rust's ownership and type system can eliminate most of the "stupid little tiny things" that dominate kernel Common Vulnerabilities and Exposures (CVEs), while making life easier for overworked maintainers. "Rust," in short, "makes my life so much easier...." In India, he said Linux sees "about 13 CVEs a day" and has been running at "almost nine changes an hour" for a decade or more. Most of those vulnerabilities, he argued, are not exotic attacks but simple C mistakes — unchecked pointers, forgotten unlocks, and sloppy cleanup paths: "This is what we're fixing 13 times a day. Small, trivial, little bugs like this all the time.... I've seen every CVE the kernel has done in the past 25 years. I think 80% would be gone, just because they would be caught by Rust." The remaining 20% are the logic bugs he'd prefer to focus on...."

Moreover, Rust is becoming the default for new work in key subsystems. "New drivers for some subsystems are only going to be accepted in Rust...." he said. Binder, the Android IPC mechanism at the heart of billions of devices, now has parallel C and Rust implementations in the kernel. The C version "will go away soon," leaving the Rust version "as the bedrock of all Android devices going forward."

EU

EU Forces Google To Share Search Data, Open Android To Rivals 51

The EU is imposing new rules requiring Google to share anonymized search data and open up Android to rival AI companies. "Thanks to these measures, we hope to see emerging alternatives to Google Search and Google's AI services, such as Gemini, and that users in the EU can enjoy greater choice of services," Henna Virkkunen, an executive vice president at the European Commission overseeing tech, said. The Associated Press reports: In issuing the two new rules, the commission said it found that AI agents not made by Google were unable to function on Android phones at the same level as Google's Gemini. Google must now allow voice-activation of these alternative AI agents and enable them to run background tasks like booking restaurants via third-party apps. By January 2027, Google must also begin sharing anonymized search data with some rivals. The commission said the move is meant to level the playing field since Google controls a vast trove of user data that no competitor can match. Google argues the measures could weaken privacy and security by exposing user searches and reducing safeguards around third-party AI assistants. "Europeans' private searches would be exposed to unfamiliar companies, without adequate anonymization of the data and without user knowledge or consent," said Kent Walker, president of global affairs for Google and Alphabet. "This would weaken citizens' privacy, risk business trade secrets, and endanger national security."
Android

OnePlus Will Continue Software Updates After US and Europe Exit (9to5google.com) 15

OnePlus has confirmed that it will exit the North American and European markets, consolidating its operations under parent company Oppo. Existing customers will continue to receive "software updates, security patches, and applicable support," but OxygenOS will be replaced by Oppo's ColorOS. 9to5Google reports: As a part of its shutdown in global regions, OnePlus has confirmed that its flavor of Android, OxygenOS, is going away. Instead, all active OnePlus devices will be moving over to Oppo's ColorOS starting with their Android 17 updates. This includes in India, where OnePlus is adamant it will continue operations -- reliable reporting disagrees.

OnePlus explains: "As part of an operational adjustment to our software strategy, following the official release of ColorOS 17, users globally with existing OnePlus devices that fall within the eligible upgrade scope will have the option to voluntarily update to the latest ColorOS. This enables us to streamline software development, accelerate update delivery, improve software quality, and make better use of our shared engineering and R&D capabilities."

[...] OnePlus will continue "maintenance support" for OxygenOS versions on older models not included in the Android 17 update scope, but newer devices will likely need to make the switch to ColorOS for all forms of continued support. OnePlus does explain that rollback versions to OxygenOS will be available for those who prefer the prior experience: "OnePlus devices will be able to choose whether to update to the latest ColorOS system. Older models that are not included in the update scope will also continue to receive version maintenance support. If users update to ColorOS, they will be able to roll back to OxygenOS. The specific rollback versions available will be subject to future official announcements."

Android

Google and Epic Cancel Settlement; Third-Party App Stores Coming To Google Play (arstechnica.com) 41

An anonymous reader quotes a report from Ars Technica: Big changes are coming to Android apps, but they're not the changes Google wanted. The settlement between Google and Epic that aimed to put to rest the companies' long-running antitrust battle is being withdrawn, and that means third-party app stores are coming to the Play Store. Google has confirmed that it will begin distributing rival app stores next week, setting the stage for competing platforms to take a bite out of Google's Android revenue stream. [...] Google and Epic were set to return to court on July 16 to argue in favor of the settlement. However, the writing may have been on the wall. In a recent expert analysis provided to the court, MIT economics professor Nancy Rose noted that the settlement was "unlikely to enable Google Play's potential competitors to overcome their long-standing network-effect disadvantage in a timely manner."

With settlement approval looking increasingly unlikely, Epic and Google agreed this week to call the whole thing off. Here's how Google Trust and Reputation Communications Lead Dan Jackson explains the company's decision: "We've agreed with Epic to withdraw our motion to modify the US Court's injunction rather than prolonging this process which creates uncertainty for the ecosystem. This allows us to focus on executing our recently announced global business model evolution to deliver greater app store choice, lower prices, and more opportunities for developers and users. We remain committed to maintaining Android's industry-leading security and fostering a competitive ecosystem where every app store and developer has the freedom to compete. In parallel, we continue to comply with the US Court's injunction."

In a brief filing (PDF), Google's legal team informs the court that Google is prepared to begin distributing third-party app stores in Google Play on July 22. Under the terms of Judge Donato's original injunction, these stores will have access to the full catalog of Google Play apps by default. Developers will have the option to opt out of distribution in these stores, and Google has a support page explaining how to do so. Google also has documentation on how app stores can get access to the Google Play catalog. It won't be mirroring those apps in any shady storefront that asks. The court has allowed Google to charge reasonable fees to cover its security and compliance review of third-party stores, which will be $5,000 per year.

Google will also require approved stores to block malware, respect intellectual property, and include mechanisms to update and uninstall apps. App stores can be removed from the program if more than 1 percent of attempted app installs appear to be malware or unwanted software. It's unclear if there will be separate, possibly more stringent requirements for storefront distribution in the Play Store. However, Google is prohibited from unreasonably blocking third-party store clients uploaded to Google Play. The changes Google has announced under the Epic agreement will proceed for now. That means Registered App Stores will happen globally, but they will probably only appear in the Play Store for US users. Google hasn't specified if there will be any differences in the features available to the stores downloaded from Play versus registered stores.

Youtube

DuckDuckGo's Browser Now Blocks Most YouTube Ads (nerds.xyz) 81

Nerds.xyz reports: DuckDuckGo just gave its browser a feature that a lot of people have been waiting for. The privacy-focused browser can now block most video ads on YouTube, letting users watch videos without sitting through the pre-roll and mid-roll interruptions that have become part of everyday life on the platform. The feature is already enabled by default for iPhone, Windows, and Mac users running the latest version of the browser. Android users can turn it on manually... with DuckDuckGo planning to enable it by default in a future update...

To make it work, DuckDuckGo relies on the same community-maintained filter lists used by uBlock Origin, along with some of its own compatibility rules. The company says you might notice a bit of extra buffering before a video starts, but once playback begins, most ads should be gone.

Slashdot reader BrianFagioli argues that the feature raises questions about how creators are compensated when ad revenue is bypassed.
AI

Small AI Models Gain Traction Around the World 104

locater16 shares a report from IEEE Spectrum: One morning in 2019, Adebayo Alonge was in a Cape Town hotel room, preparing to demonstrate his startup's AI answer to a serious problem in African health care: counterfeit medication, which kills thousands of people across the continent every year. The RxScanner is a handheld spectrometer that scans a pill with infrared light, then sends the item's molecular profile to an AI model equipped with a pharmaceutical database. In seconds, the AI identifies the medication from its molecular profile -- or reports that it's phony.

Pharmacies were using the system in more than a dozen countries, including Ghana, Kenya, Myanmar, and Alonge's native Nigeria. But that morning in South Africa, it didn't work. "I was shocked," Alonge says... So Alonge immediately asked his engineers to shrink the AI model down to a smaller, low-power, unconnected version that could run entirely on his Android phone. They produced it 2 hours later, and that saved the demo. More importantly, the work birthed a new version of his device, which can authenticate a pill in places without broadband, computers, or even reliable electricity. It also turned Alonge into an advocate for this kind of "small AI."
"The article goes on to detail other immediately useful 'small' AI applications without any subscription or billion dollar data centers needed," writes locator16. For example, Bala Murugan and colleagues at Vellore Institute of Technology in India developed a drone-based system that photographs cashew plants and identifies disease-indicating splotches on the plants. The key advantage is that all processing happens on the drone itself, so farmers do not need a computer, broadband connection, or cloud server access.

In a Uruguayan vineyard, researchers developed small-AI systems to identify ant infestations. The article doesn't go deep into the deployment details, but it presents this as another example of a narrow, localized model trained to recognize a specific agricultural threat. Small AI has also been used to detect the presence of malaria-carrying mosquitoes in multiple countries. This is especially useful in regions where public-health teams may lack reliable network access or expensive lab infrastructure, but still need fast, local detection.

In parts of Brazil without access to more complex medical equipment, researchers have used small AI to run electrocardiograms from an Arduino device. The article also describes Marcelo Jose Rovai's work on a TinyML model that generates electrocardiograms in a patient simulator lab. Rovai also describes a newer experiment using an Arduino UNO Q with a Qualcomm chipset. The device runs a language model locally, collects sensor data, and analyzes it to detect tiny pools of water where mosquitoes might breed -- while using only about 3 watts of power.
AI

Short Story Accused of Being AI-written Goes on to Win Contest's First Prize (theguardian.com) 55

"A story widely accused on social media of being written using AI has gone on to win the overall Commonwealth short story prize," reports the Guardian.

In mid-May the story had been selected as a regional winner, but with critics on X and Bluesky "claiming it showed 'obvious markers' of AI use." In the wake of the controversy, the Commonwealth Foundation conducted a review of the regional winners, which it said involved looking at drafts, time-stamped documents and notes. "We are satisfied with the testimonies of our writers and their confirmation that AI was not used in their writing," said foundation director-general Razmi Farook... Judging chair Louise Doughty described Nazir's piece as "an original, poetic and deeply moving story...." In a film released by the Commonwealth Foundation on Tuesday, Nazir... adds that he wrote six or seven drafts of his prize-winning story, and also speaks about his use of speech-to-text software, explaining that he could only see three or four lines of text on his phone screen at any one time, so he would perfect each line before moving on, which is how his story ended up being "highly polished"...

Initial social media reactions to the Commonwealth Foundation's announcement of Nazir's win were negative, with one X user writing: "immensely disappointing and disheartening. it feels like they wanted to stick to their guns after the entire GenAI uproar. I might think twice now before submitting my stories here". After Nazir was announced as the regional winner in May, some social media users reported running his story through AI-detection software. "Pangram flags at 100% but also, come on, if you know you know", said Wharton professor Ethan Mollick. However, the reliability of AI-detection software has been called into question.

In a statement to the Guardian, Farook said that "rather than surrender our judgment to AI-detection software, we asked our winners to show their working drafts, outlines, the evidence of an artistic journey. That software, it must be said, is not infallible: it returns inconsistent verdicts and, in doing so, corrodes the very trust on which a prize depends."

"When the machine's default voice is the metropolitan one, the writer who does not fit the expected mould is the first to fall under suspicion," she added. "The more startling her gift, the more her unfamiliar brilliance unsettles, the more readily she is accused of being a machine. A young writer in Kingston or Kolkata, in Kuala Lumpur or Kigali, must now prove not only her talent but her very humanity."

Nazir's story beat 7,806 other stories, the video points out (adding that their prize "demonstrates that in a world increasingly driven by algorithms, the human voice still matters.")

The Guardian notes that the winning story "includes multiple 'not x, but y' constructions and lists of three, which some consider to be signs of AI use," and that critics also drew attention to particular lines like "Sun on galvanise is a cruel instrument" and "Marsha lived two bends down."

In a new interview with the Times of India Nazir says "Now I'm frightened about publishing new work because the attacks haven't stopped." Q: Which passages attracted the most criticism, and why do you think they were misunderstood?

Nazir: People criticised a line where I wrote: 'She had the kind of walking that made benches become men.' That's magical realism. Think Salman Rushdie or Gabriel Garcia Marquez. It's a literary technique. In my story, the character 'Zoongie' believes she is so beautiful that even when no men are around, she imagines the benches becoming men who admire her. It exists only in her imagination. People interpreted it literally. There was another line about light reflecting from a sink. That came directly from my childhood. Our kitchen faced east, and my mother liked to keep everything spotless. We used to polish the sink, and when the morning sun hit it, it glittered brightly. People claimed that the image must have been AI-generated. But it's from my lived experience...

I've lived with diabetes for 62 years, which has damaged the nerves in my fingers and feet, and I'm currently undergoing chemotherapy. That's why I began using speech-to-text on my Android phone... I hope this episode leads to a better understanding of the difference between assistive technology and AI-generated writing...

Q: Many acclaimed writers like Ursula K Le Guin, Mary Shelley, and JRR Tolkien have also been falsely flagged by AI detectors. Where does this leave writers?

Nazir: What these AI detectors are saying is that if a piece of writing is too polished, it must have been written by AI. I refuse to accept that. AI was trained on human writing. Large language models, to me, are tools, much like a word processor. They don't replace the human spirit behind creative writing. Ask an AI to write a prize-winning story on its own and see what it produces. You still need human imagination and judgment to create literature.

Nazir added, "What I don't understand is why people continue to question the judges' decision."
GNU is Not Unix

FSF Shares Update on 'LibrePhone' and New Automated Site Monitoring Tool (fsf.org) 20

At the end of 2025, the FSF launched LibrePhone project, which is working to "better understand and reverse-engineer the nonfree blobs used by a great majority of (if not all) system on a chip designs available today." The FSF's summer newsletter shares this update: We started with researching the proprietary files in Android phones supported by the Lineage project, an Android-based volunteer-led mobile phone operating system with much free software already in it. Our current, primary focus is on the radio blobs that control WiFi, Bluetooth, NFC, and cellular communications.

The software freedom issues with mobile computing have been around for a long time, with the most challenging issue being the baseband/modem firmware that relies heavily on proprietary software. This creates a technical and legal maze that is nearly impossible to break free from, but that doesn't mean we should ever stop working to create free systems. It certainly doesn't mean we shouldn't liberate the software that we know can be free software. Now, half a year into this project, lead developer Rob Savoye has extracted firmware from over 200 Lineage install packages, processed 85GB of files, and imported the results of these analyses into a PostgreSQL database for cross-device comparison... [M]uch of the software and blobs we need to work through are shared across multiple devices; this means even greater strides for mobile phone freedom...

As insurmountable as it may seem at times, every blob we manage to free up will be progress. The FSF has proven time and time again that it can bring the free software philosophy to life, not just by advocating for it, but by making it so.

The bulletin also describes how waves of botnets from "aggressive LLM scrapers, vulnerability scanners, poorly optimized CI/CD servers" inspired the FSF to create a new free-as-in-freedom automated monitoring tool: In our efforts to combat the botnets, we optimized several detection rules to ban abusive behavior. We found the upper limit of fail2ban and replaced it with reaction, an efficient alternative with our configuration that uses ipset. We also split several monolithic machines into many separate machines so that when a web service is overwhelmed the other functions of the service do not go down with it... We found quite a few ways to respond to and prevent botnet attacks, but still faced a significant related challenge: communicating when a website or service is down...

Uptime Kuma is a human-readable, automated monitoring addition to our systems... You can check out our recently-launched self-hosted Uptime Kuma instance at https://status.fsf.org/. When you see the page, you will also likely say, "Wow! The FSF and GNU sure do run a ton of services!" and you would be right... If you maintain websites and services, and are looking for a simple way to communicate publicly with your users, consider using Uptime Kuma or another free software solution instead of choosing a proprietary monitoring solution."

There's also an article on the state of free-as-in-freedom videogame console emulators.
Cellphones

OnePlus Is Quietly Steering Customers Toward OPPO Products (androidauthority.com) 32

OnePlus is directing customers in some European markets toward OPPO devices, with its German website presenting OPPO as the natural upgrade path for existing users. The regional handoff adds to "months of speculation that the smartphone brand is slowly being folded into its parent company," reports Android Authority. From the report: The banner, seen on OnePlus' German website, tells visitors seeking "the experience you trust" that OPPO offers the same speed, performance, and compatibility that OnePlus users have come to expect. It hosts devices ranging from earbuds and tablets to OPPO's latest foldables, with each button taking users straight to OPPO's website. Particularly revealing is the wording. Instead of pushing future OnePlus hardware, the company focuses on the fact that OPPO's products are built on the hardware and software that users already know, while promising seamless compatibility with current OnePlus devices. In other words, if you're up for your next upgrade, OnePlus seems to be saying OPPO has what you're looking for right now.

Reports in the past several months have said OnePlus has been scaling back operations in several global markets. Previous restructuring reportedly included cutting headcount, a more focused regional strategy, and greater dependence on OPPO's infrastructure. The two brands have been sharing engineering resources, software development, and supply chains for years now, particularly as OxygenOS and ColorOS have begun to look more and more alike.

Interestingly, the change appears to be regional. OPPO already has a retail footprint in Germany, so the handoff is fairly straightforward. In the United States, however, things are very different, where OPPO does not officially sell smartphones. That means American OnePlus customers aren't getting the same messaging, mostly because there isn't an OPPO lineup waiting to step in.

AI

SpaceX Reportedly Has an AI Device Prototype 24

According to the Wall Street Journal, SpaceX showed investors an early prototype of a slim, "handset-like" AI device running a proprietary operating system and integrating xAI technology. Elon Musk, however, denied the report, calling it "utterly false." TechCrunch reports: SpaceX, alongside sister company Tesla, does have the manufacturing expertise to pull off mass-producing a bunch of AI devices -- not to mention access to the chips needed to power any on-device compute. SpaceX has also signaled that it's keen to expand into wireless, with Starlink Mobile as a potential competitor to Verizon and AT&T. One analyst even went as far as to speculate that T-Mobile or AT&T would make fine acquisition targets for the rocket builder, though such a purchase would, undoubtedly, be pricey.

It's also not clear if SpaceX is just throwing spaghetti at the wall or if it will attempt to really mass-produce and market such a device. But one thing that seems clearer is that if OpenAI is doing it, Musk would, perhaps, want to try to do it better. [...]

Like OpenAI, SpaceX's prototype is reportedly designed to run on a proprietary operating system and integrate technology from xAI, Musk's AI company that SpaceX acquired earlier this year. This would prevent these new devices from being trapped inside another company's platforms (like Google's Android). But the intent also appears to be to create something new, with native AI interfaces. That said, the graveyard is crowded with the unsuccessful launches of AI devices from companies like Humane and Rabbit. A company wanting to sell an AI device does not equate to consumers wanting to buy such a thing. Yet.
Piracy

Amazon Blames Piracy Apps With Malware For Killing New Fire Stick Sideloading (arstechnica.com) 32

Amazon says it is ending sideloading on new Fire Sticks because "apps that facilitate piracy, and other apps, can carry malware," adding that there is "a good amount of evidence" that sideloaded apps may contain unwanted code or behavior. However, the company did not provide specific examples of Fire Stick users being harmed. Ars Technica reports: Amazon has released two Fire Stick models that use its proprietary, Linux-based operating system, Vega OS. Previous Fire Sticks ran Fire OS, which is an Android fork based on the Android Open Source Project. One of the biggest differences between Vega OS and Fire OS is that the former doesn't support sideloading. [...] In a recent interview, Or Goren, editor-in-chief of Cord Busters, a UK-based streaming news outlet, noted the negative reaction to Vega being a closed OS. [Aidan Marcuss, VP of Fire TV, advertising, and Appstore] responded, per the publication, by saying that Vega OS was Amazon's opportunity to "innovate and deliver more capabilities, even on the least expensive devices."

He also said that making a platform around security and privacy was "sort of utmost in my mind." The statement is somewhat ironic, considering Vega OS blocks custom launchers and other third-party apps that helped users avoid Amazon tracking and ads. Goren asked whether Amazon had evidence that sideloaded devices caused users harm. "Apps that facilitate piracy, and other apps, can carry malware," Marcuss responded. Marcuss also said that there is "a good amount of evidence that apps can carry unwanted code and behavior on them when they're sideloaded."

Marcuss didn't provide specific examples of Fire Stick users being hurt by sideloaded apps. There are some potential examples, though. In 2025, Amazon claimed to blacklist (which blocked the apps from being sideloaded to Fire Sticks) four video streaming apps for malicious behavior. At the time, AFTVnews reported that two of the apps served as residential proxy providers and were considered riskware, and that the other two had APK files that were flagged by virus-scanning tools. Safari and Chrome also flagged one of the apps' official websites, the publication reported. And in 2018, a botnet that infected Android devices with cryptocurrency-mining malware appeared on some Fire Sticks, per discussion on XDA Forums. That said, Amazon also has a history of disabling apps that let users circumnavigate its home screen that Fire devices, including Fire Sticks and Fire TVs, have increasingly used for ads.
Worth noting: developers can continue sideloading apps onto Vega OS devices if they register them with Amazon.
Google

Google Starts Lowering Play Store Fees, Making Good On Epic Games Settlement (arstechnica.com) 6

An anonymous reader quotes a report from Ars Technica: Google spent the last few years locked in a legal grudge match with Epic Games, which claimed that Google's stewardship of the Play Store was anticompetitive. Now, the companies are thick as thieves, and Google is beginning to implement app store changes as agreed in its settlement with Epic. The lower developer fees and new payment options that Google promised are rolling out in select markets this month before expanding. [...] Starting on June 30, developers in Europe, the UK, and the US will have access to the new fee structure. This system will split the commission into two components: billing and service fees.

The biggest win for small developers is the new flat 10 percent service fee for the first $1 million in earnings every year. Above that, the rate for various transaction types may reach 25 percent on existing installs. Apps installed after June 30 will top out at 20 percent. Developers will finally be allowed to send users outside the Play Store to complete a transaction, too. Google says they can design a choice screen "in accordance with our UX guidelines" to direct users to these external options. Devs pay the standard service fee on these purchases, but they'll avoid the billing fee. All transactions that run through Google's Play Store platform add a 5 percent billing fee -- even the base rate for publishers earning less than $1 million. Google notes that the billing fee is set at 5 percent in the initial markets, but it could be different in other regions.
Google will expand the new fee structure globally through September 2027, while also offering reduced fees through updated developer programs.

Although the changes may let developers retain more revenue, Google will continue controlling Android distribution and collecting a share of sales as it works toward allowing certified third-party app stores to operate more like the Play Store.
Cellphones

2,000 Retired Google Pixel Phones Get a Second Life As a Private Cloud (theregister.com) 27

UC San Diego researchers are working with Google to build a private cloud from 2,000 retired Pixel Fold motherboards, demonstrating how discarded smartphones could provide useful, low-cost computing capacity. "The full smartphone cluster is expected to launch this fall," reports The Register. "Depending on how well the initial phase goes, we're told the cluster could grow even larger." From the report Once the phone's motherboards have been extracted from their shells, the researchers say that the chips hiding within remain more than potent enough to be useful for a variety of tasks. In many cases, the single-threaded performance of these chips is as good as, if not better than, what you'd find from a many-cored datacenter chip. The Pixel Fold smartphones, which will form the basis of the cluster, are powered by a Google Tensor G2 processor with two 2.85 GHz Cortex-X1, two 2.35 GHz Cortex-A78 and four 1.80 GHz Cortex-A55 Arm cores, a Mali-G710 MP7 GPU, and 12 GB of system memory. Early benchmarking using the SPEC suite suggests that 25-50 phones should deliver performance similar to that of a conventional server.

The major challenge, instead, is distributing workloads across multiple devices, each of which has a handful of cores of one or more varieties, and most have 8-12 GB of memory. UCSD researchers are approaching this challenge from a couple of different angles. The first is by targeting applications that can easily fit within a single device. The second is using Kubernetes to orchestrate container deployments across clusters of 25-50 phones. For this to work, the devices first need to be flashed with a Linux operating system suitable for the job. While Android makes for a great handheld experience, it is not intended for server duty. In the blog post, researchers note that Android includes functionality intended to stop rogue applications from chewing up excessive amounts of memory and draining your battery. In server context, these safety mechanisms are no longer necessary.

[Ryan Kastner, an associate professor of computer science at UCSD] told us this was by no means an easy task, but the team has made steady progress toward getting Linux running smoothly on these devices, including support for the phone's onboard GPUs. Access to some functionality, like the chip's integrated tensor processing unit, remains elusive. Clustering these devices will require networking the phones together. Normally these devices would connect over cellular or Wi-Fi, but at this scale, this not only isn't practical, but also has implications for security, he explained. Instead, the team will employ PCBs that both supply power and break out wired Ethernet networking.

The researchers suggest that many EdTech, grading, and research workloads commonly run by universities in the cloud are small enough to run on the cluster without issue. "The vast majority of these applications are within the capabilities of a single smartphone to host, with the standard grading backend running on small cloud instances," a blog post detailing the planned deployment reads. "Early experiments show that even a moderately-sized cluster of 20 phones is capable of supporting peak submission rates for a 75+ student class."

Android

Android 17 Drops For Pixel Phones and Watch (phonearena.com) 27

Google has begun rolling out Android 17, the June Pixel Feature Drop, and Wear OS 7 simultaneously across supported Pixel phones and watches. Highlights include floating app bubbles, improved foldable multitasking and gaming, tighter location and contact permissions, stronger lost-device protections, new Pixel AI tools, and up to 10% better Pixel Watch battery life. PhoneArena reports: Pixel owners are the clear winners, since everything here reaches Pixel first and a lot of it goes back to the Pixel 6. Fold owners get the most toys, with the Bubble Bar and foldable gaming mode built for the big screen. Watch wearers get the quietly important upgrade. Better battery and Live Updates make an everyday wearable easier to rely on, especially if you keep it on overnight. Google's latest Pixel Drop combines several AI-powered tools with a broader slate of Android 17 upgrades. Pixel owners gain Lyria 3 for generating music from text or images, Gemini Omni for creating custom video clips, enhanced call translation and screening, AirDrop-compatible Quick Share, expanded Magic Cue support, and conversational photo editing.

Android 17 builds on those additions with floating app Bubbles, selfie-camera Screen Reactions, and a split-screen gaming mode for foldables, while also strengthening privacy and security with more granular location and contact permissions, improved lost-device protection, tighter PIN-guessing limits, and enhanced threat detection.

Other additions include expanded parental controls, separate assistant volume and app memory settings, and an option to hide app names for greater privacy.

You can read more about everything new in Android 17 in Google's blog post.
Cellphones

Commodore's Callback 8020 Is a $499 Flip Phone That Blocks Social Media and Browsers (techspot.com) 124

Commodore has unveiled the Callback 8020, a $499 Sailfish OS flip phone that runs most Android apps but deliberately blocks social media, browsers, email, and workplace apps to discourage doomscrolling. The "not dumb dumbphone" still supports messaging, music, maps, ridesharing, hotspots, a removable battery, and plenty of Commodore nostalgia. "The phone uses T9-style texting with predictive input, includes Commodore SID ringtones, ships with a selection of Commodore and Sailfish games, and even includes Snake," reports TechSpot. From the report: Commodore says it has developed patent-pending technology that prevents browsers and social media apps from being sideloaded, while DNS-level blocking should stop them from working even if someone finds a way to install them. Users can still sideload nearly anything else if it's not available on the Commostore, but apps designed for doomscrolling remain off limits. That means useful services such as WhatsApp, SMS, Signal, Telegram, WeChat, Spotify, Uber, Lyft, maps, podcasts, QR scanning, voice notes, and hotspot support work, but the likes of Instagram, TikTok, Facebook, Gmail, and browsers do not.

The Callback 8020 has a 3.25-inch 480 x 640 internal display, a MediaTek Helio G81 chip, 4GB of RAM, 64GB of storage, a 48MP Sony rear camera, an autofocus front camera, dual SIM support, USB-C, a headphone jack, FM radio, and something many of us miss from flagships: a removable battery. There's no 5G as Commodore argues that 4G VoLTE and Wi-Fi better fit a device meant to discourage constant streaming and scrolling. [...] The main screen is touch-capable but disabled by default, while the outer display keeps things deliberately sparse, showing basics such as time, battery, signal, and notifications via dome LEDs.

The 8020 name is a nod to Commodore's 8010 modem from 1980. The phone comes in ProtoPET White, SX Silver, BASIC Beige, a translucent Starlight Edition, and a gold Founders Edition with a 24-karat gold-plated Commodore button. Standard models start at $499, the Starlight version is $549.99, and the Founders Edition costs $640. Preorders open June 30, with shipping targeted for winter.
You can watch the launch ad on YouTube.
Firefox

Firefox 152 Adds JPEG XL Support, Redesigned Settings (linuxiac.com) 30

An anonymous reader quotes a report from Linuxiac: Mozilla has released Firefox 152, the latest update to its popular open-source web browser, with updated settings, improved media controls, experimental JPEG XL support, and various platform-specific fixes for desktop and Android. A key update is the redesigned Firefox Settings page, which now features clearer groupings, improved navigation, and a more streamlined structure for easier customization. The release also expands built-in spellchecker support, adding dictionaries for Croatian, English (UK), Georgian, Persian, Slovenian, Tajik, Tamil, Tibetan, Turkish, Welsh, and Xhosa. [...] Importantly, Firefox now offers experimental support for JPEG XL, an image format with improved compression over WebP, JPEG, PNG, and GIF. Users can enable JPEG XL in the Firefox Labs panel within Settings.
The Courts

Google Sues Chinese Cybercrime Operation That Used Gemini AI To Send Scam Texts (techcrunch.com) 10

An anonymous reader quotes a report from TechCrunch: Google is suing to dismantle the infrastructure behind an alleged massive AI-powered cybercrime operation. On Friday, the tech giant announced a lawsuit against an alleged Chinese cybercrime network called Outsider Enterprise, which Google says uses AI in its campaigns to send scam text messages impersonating Google and other brands to steal passwords and credit card numbers.

Outsider Enterprise has financially scammed "hundreds of thousands of victims" with losses "estimated in the millions." The group deployed 9,000 fake websites, 1 million fraudulent web domains, and 2.5 million texts sent to Android users in a two-week period, according to Google. "55,000 spam texts were flagged by Android users in just two weeks this past May -- that's more than two text spam complaints a minute," Google said.

Google said it uses "AI-powered tools to fight AI-powered scams", which enable the company to detect scams and alert users of suspicious calls and text messages, leading to the interception of more than 10 billion scam messages a month. The company said it has been collaborating with AT&T, T-Mobile, and Verizon to block the scam text messages and said it is coordinating with the FBI, which is taking unspecified law enforcement actions.

Power

New Power Banks Released By BMX With Safer Semi-Solid-State Batteries (androidauthority.com) 29

From Android Authority: Singapore-based BMX has announced that its SolidSafe magnetic power bank lineup, first showcased at CES 2026, is now available for purchase through its website and Amazon US, with prices starting at $59. What sets these power banks apart is their use of semi-solid-state batteries. Traditional lithium-ion and lithium-polymer batteries rely on liquid electrolytes to move energy between electrodes. Semi-solid-state batteries significantly reduce the amount of flammable liquid inside the cell, improving thermal stability and lowering the risk of overheating, swelling, or fire...

BMX says the power banks are designed to remain stable under extreme conditions and show greater resistance to physical damage and thermal stress than conventional battery packs. The company has also launched the SolidSafe Air, a 5,000mAh magnetic power bank that it claims is the world's thinnest semi-solid-state Qi2 power bank... BMX is positioning the device as a travel-friendly alternative for users who want added safety and the convenience of a magnetic battery pack without the bulk.

Thanks to long-time Slashdot reader destinyland for sharing the article.

Slashdot Top Deals