Wireless Networking

DEF CON Crowd Suspected In Fake-Hotspot Attack On Delta Flight (arstechnica.com) 29

An anonymous reader quotes a report from Ars Technica: On Monday, passengers aboard Delta flight 591 going from Las Vegas to Atlanta allegedly spoofed the onboard Wi-Fi, raising the attention of federal law enforcement. The incident came one day after the DEF CON security conference concluded in Las Vegas, and was first described on social media accounts that follow publicly available air-to-ground messages, known as ACARS.

According to the "ACARS Drama" account, a message was sent by pilots from the plane stated: "NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL." A description of the incident posted to Reddit further stated that these passengers created a fake hotspot ("Delta WiFi Fast"), with a phishing landing page "designed to harvest passengers' personal credentials."

This technique, sometimes known as an "evil twin" attack, has been long-known to the IT security community. It involves setting up a fake Wi-Fi network and then capturing login credentials and other data.
"One initial finding is an unauthorized WiFi network, which was not provided, operated, or supplied by Delta, was present onboard the aircraft for a short time during the flight," said a Delta spokesperson. Delta further noted that the flight's safety was "never in question and no aircraft operating systems were affected," and that no emergency was declared.

Ars notes that the "actual onboard Wi-Fi was disabled for 30 minutes."
Cellphones

Google Unveils Pixel 11 Lineup (techcrunch.com) 31

At its Made by Google 2026 event today, Google unveiled a slew of new devices, headlined by the Pixel 11, Pixel 11 Pro, and Pixel 11 Pro Fold. Here's a breakdown of the company's latest smartphones, provided by TechCrunch: Pixel 11: The standard Pixel 11 gets a redesigned camera bar that is thinner than the one on the previous generation. Google says the new camera bar is more than 40% thinner and now uses an all-glass surface that stretches across the width of the phone. Google is also increasing the base storage to 256GB, doubling the previous starting capacity. The starting price for the new model is set at $899, reflecting a $100 increase compared to the Pixel 10. This price hike comes with the decision to drop the 128GB storage option. Plus, the ongoing RAM supply shortage plays a part in this increase.

Pixel 11 Pro and Pro XL: Google is making durability a bigger part of the Pro lineup. The company says the Pixel 11 Pro and Pixel 11 Pro XL have improved drop resistance and a new anti-scratch display coating that provides more than twice the scratch resistance of the Pixel 10 Pro models. The Pixel 11 Pro starts at $1,099, compared to $999 for the Pixel 10 Pro.

Pixel 11 Pro Fold: Google says the new foldable is nearly 10% lighter and almost 1mm thinner than the Pixel 10 Pro Fold. It also has slimmer bezels, a 48-megapixel main camera, and 30x Super Zoom. The company is also building on the IP68 water and dust resistance introduced with the Pixel 10 Pro Fold. The Pixel 11 Pro Fold uses a glass-fiber composite back cover designed to better withstand cracking, while a redesigned hinge offers additional protection for the inner display. Google says the changes make the model three times more durable than its predecessor.
There were also several new Gemini-powered features unveiled at the event. Google is expanding "Live Transcribe" to support American Sign Language, using the Pixel Camera to translate signing into text in real time. A new voice-input feature called "Rambler" is designed to understand natural, unstructured speech, including filler words and run-on sentences. Google is also integrating "Circle to Search" more directly into the Pixel Camera for identifying objects, translating text, and asking questions about what users see.
Cellphones

France Bans Unsolicited Telemarking Calls (lemonde.fr) 64

Starting today, unsolicited telemarking calls are banned in France unless consumers explicitly consent to them. Companies that violate the law can face fines of up to 375,000 euros per call, though existing customers can still be contacted with related offers. Le Monde reports: The government says the law is a response to years of consumer complaints. Authorities estimate that about three-quarters of people in France receive at least one unsolicited sales call every week, and many receive more. In 2024, 11 consumer organizations issued a joint call for a ban, denouncing "relentless harassment of consumers through countless unwanted telemarketing calls to both landlines and mobile phones -- an intrusion that has become a regular part of their daily lives."

Now, "businesses are prohibited from contacting consumers without their prior consent," said Alice Vilcot, chief of staff at the Directorate-General for Competition, Consumer Affairs and Prevention of Fraud. "That consent can be withdrawn at any time." [...] Previously in France, people who wanted to avoid marketing calls had to register their number with a government-run service, but consumer groups said some call centers ignored the list. Vilcot noted that an Ireland-based company was fined 6 million euros ($6.9 million) last year for violating France's previous telemarketing rules by calling people on the no-call list.

Encryption

Slashdot Reader Builds a Photo-Verification App for iPhones (nerds.xyz) 53

Long-time Slashdot reader BrianFagioli is announcing that he's released a new iPhone app that creates a cryptographic witness for photos without uploading the original image. The app hashes the file, signs the hash using a dedicated identity stored in Apple Keychain, and publishes the witness to Nostr relays while keeping the photo inside the app unless the user chooses to export it.

Rather than trying to determine whether a scene was genuine, the app — named Veridenz — answers a narrower question, by verifying whether a photo file matches the one that was originally witnessed. Users do not need a Nostr account because the app creates its own signing identity, keeping private documentation separate from a public Nostr profile.

"The developer does not collect any data from this app," says its page in Apple's iPhone store. The app's tagline is "Capture. Prove. Verify."
Cellphones

The Days of Walking Into a T-Mobile Store May Be Numbered (androidauthority.com) 93

A leaked roadmap suggests T-Mobile plans to make its T-Life app the primary way customers manage their accounts by the end of 2026, "gradually moving one feature at a time into the app" and away from physical stores, reports Android Authority. That includes upgrades, new-line activations, and eventually new-account sign-ups. From the report: According to an image shared by a Reddit user, the carrier has mapped out the next phase of its app-first strategy. This clearly shows that the T-Life app is set to become the primary way customers manage nearly every aspect of their account by the end of 2026. The roadmap suggests T-Mobile isn't flipping the switch overnight. Instead, it's gradually moving one feature at a time into the app. The concierge experience has already made that transition, while phone upgrade transactions are currently being shifted over. Next on the list is support for adding new lines, followed by what appears to be the biggest change yet.

By the fourth quarter of 2026, the roadmap indicates that all new customer accounts will be handled entirely through T-Life. So, many of the tasks that traditionally required a trip to a T-Mobile store could soon be completed from your phone instead. [...] The roadmap also reinforces a direction T-Mobile has been moving toward for quite some time: making T-Life the center of the customer experience. If the timeline holds, the app may soon become a requirement for managing your account.

Privacy

Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch (itnews.com.au) 31

A Russia-linked group tracked as Midnight Blizzard has compromised hotel and conference Wi-Fi portals worldwide, redirecting guests to phishing pages and fake software updates that steal credentials, session tokens, and other sensitive data. Microsoft says the campaign, dubbed CaptiveCrunch, "targets traveling employees generally rather than a particular sector," reports iTNews. From the report: Midnight Blizzard, tracked internally by Microsoft under its earlier codename NOBELIUM, is attributed by the US and UK governments to Russia's SVR (Sluzhba Vneshney Razvedki) foreign intelligence service. Microsoft's technical analysis said compromises occurred in "several countries" without naming them, and it did not give a total number of affected venues, organisations or individuals.

A related investigation published earlier in July by security firm ReliaQuest, and which Microsoft cited in its report, found compromised captive portal gateways across multiple United States cities as well as in India and Saudi Arabia, mostly at hotels. ReliaQuest said the traffic it observed came from organizations across financial services, professional services, legal, health care, energy and retail, suggesting the campaign targets traveling employees generally rather than a particular sector.

[...] Where attackers gained a foothold, Microsoft said they deployed two main tools: CornFlake, a Windows remote access trojan (RAT) written in Go capable of keylogging, screenshot and webcam capture, audio surveillance and credential and session token theft. They would also drop ChocoShell, an in-memory PowerShell infostealer targeting browser cookies, saved passwords, Microsoft 365 single sign-on (SSO) tokens and wi-fi credentials. Microsoft also said it has seen indications the attackers might be targeting Android devices with similar prompts urging victims to download and install an APK file.

Iphone

Apple Retires iPhone Upgrade Program For Klarna-Backed Leases (macrumors.com) 38

Apple has replaced its iPhone Upgrade Program with Apple Upgrade, a Klarna-backed U.S. leasing service covering most iPhones, iPads, Macs, and Apple Watches. MacRumors reports: Apple Upgrade has lower base prices than the iPhone Upgrade Program, with iPhones available starting at $17.99 per month and the Apple Watch available starting at $11.99 per month. Macs can be leased starting at $24.99 per month, and iPads start at $11.99 per month. AppleCare+ is optional and not included in the lease price, with customers also able to opt for AppleCare One. There are 12-month and 24-month leasing options for the iPhone and Apple Watch, along with 24-month and 36-month leasing options for the Mac and iPad. Lease cost varies based on device, and is lower with a device trade-in that's applied on a monthly basis. [...]

When leasing an iPhone, customers are required to choose a plan from AT&T, Verizon, or T-Mobile, and prepaid plans are not eligible. iPhones need to be leased with a carrier plan, but the iPhones are unlocked so customers can switch carriers if desired. MVNOs like Mint Mobile or Visible are not supported. At the end of the leasing period, customers can choose to return the device and exit the program, pay off the remaining amount owed on the device with a one-time payment and keep it, or return it and upgrade to a new device with a new lease.

The payoff amount is the difference between what was paid during the leasing period and the retail price of the device, minus any remaining trade-in credits. Klarna is not charging a fee for the leasing program, so an iPhone that's $1,099 can be leased and then purchased for $1,099 with no extra cost beyond taxes. As with trade-ins, Apple will send a pre-labeled and prepaid shipping box for device returns or upgrades. If you don't opt to pay the purchase fee at the end of the leasing program, you will not own the device and must return it.
Last week, after Bloomberg reported on Apple's upcoming leasing program, 9to5Mac uncovered code in the iOS 27 beta suggesting the company was developing a system that could restrict leased iPhones when customers fall behind on payments. Apple has now told The Verge that the new "Restricted Mode" will not be activated in response to a missed lease payment. What the new system is actually meant for remains unclear.
The Almighty Buck

Apple Partners With Klarna To Offer iPhones, Macs On a Subscription Basis (computerworld.com) 62

Apple is reportedly launching a Klarna financing deal that will let U.S. customers spread the cost of devices over up to three years, pushing the company closer to a hardware-as-a-service model. "The only thing you don't get under the new arrangement is AppleCare, for which you'll allegedly need to pay extra," notes Computerworld. From the report: The introduction of the scheme gives consumers a way to purchase the company's popular high-end devices when they are introduced -- no doubt,at higher cost -- this fall. [...] A combination of changed customer habits and external threat means the stars are now aligned for hardware-as-a-service models. "Reframing a device as a low monthly payment protects that [upgrade] cadence and allows Apple to start marketing their products as device-as-a-service to consumers, which no other vendor was ever able to do," [IDC analyst Francisco Jeronimo] wrote to me.

There is a one-more-thing aspect to this: the products are effectively being leased, a new approach that will give Apple a stronger grip on EOL devices, helping it grab more of them for refurbishment, resale, and recycling. Over time, this will give the company a much stronger grip on the lucrative second-user market that exists around Apple equipment, even while for almost every consumer product we find the life we want is something we can rent, but probably can't afford to own.

The other solid reason to take a partnership approach is risk management. Apple had intended to develop its own buy-now, pay-later scheme via Apple Pay Later, but abandoned that plan as it became riskier with rising bank rates. "Also, by backing the program with Klarna rather than reviving the in-house subscription plan it shelved in 2024, Apple captures the demand upside without taking the credit risk onto its own balance sheet," Jeronimo said.
"Apple Upgrade lands at precisely the moment Apple needs it," Jeronimo wrote in a note seen by Computerworld. "Having just pushed Mac and iPad prices up on the back of the memory shortage, with iPhone increases widely expected in September -- as well as the new iPhone foldable expected at $2,500 -- Apple's real risk is that rising prices even further can impact the upgrade cycle."
Cellphones

Samsung Galaxy Z Fold 8 Announced to Compete With Future iPhone Fold (mashable.com) 16

At a Galaxy Unpacked event in London today, Samsung unveiled a new foldable smartphone designed to compete with the still-unannounced iPhone Fold. Called the Galaxy Z Fold 8, it features a wider 4:3 form factor with a 7.6-inch inner AMOLED display, Snapdragon 8 Elite Gen 5 for Galaxy chip, up to 16GB of RAM and 1TB of storage. "The inner display has enough extra real estate for multi-tasking and entertainment," reports Mashable, which got a chance to try the new foldable ahead of the event. "And if you're worried about a crease in the middle of the display, don't be. We got up close with the device, and the crease fully disappears when the display is activated." From the report: As stated above, the main distinguishing factor of the new Z Fold 8 is its wider 4:3 proportions compared to the Z Fold 8 Ultra. If the latter is a book-style foldable, the former can almost be called a tablet-style foldable, instead. We think the wide screen will serve even better for reading books or multi-tasking with several apps open at once.

Also, at 201g, Samsung is really emphasizing how light the device is. The company is calling it the "world's lightest fold ever." And while the device may be light, its no lightweight. Samsung's newest foldable features Flex Titanium technology, which makes the Galaxy Z Fold 8 more durable. Speaking of durability, it also boasts Samsung's advantage hinge technology, Armor Flexhinge.

The Z Fold 8 feels like a solid middle point between the premium Z Fold 8 Ultra and the comparatively affordable Z Flip 8. All three phones use the same chip, but the Z Fold 8's 4,800mAh battery is smaller than that of the Z Fold 8 Ultra. However, the Z Fold 8 does have an option for 16GB RAM and 1TB of storage, similar to the Ultra.

Cellphones

US Police Now Armed With Israeli Spy Vans Simulating Mobile Phone Towers (cybernews.com) 172

Longtime Slashdot reader schwit1 quotes an X post by Josh Walkos, author of the Substack We the Free: If you thought Flock was bad check out Falconet. Falconet from Israeli company Cognyte serves as a cell tower simulator that intercepts cell phone data from all devices within range. Police mount these systems in Tahoes so the vehicles can collect information while driving through areas without any direct interaction with targets. This mobile approach generates ongoing records of phone locations and communications for everyone nearby rather than only suspects, which creates comprehensive movement profiles and bypasses traditional warrant requirements under the Fourth Amendment.

Cognyte sells the technology directly to U.S. agencies, as shown by the Texas Department of Public Safety purchase of four Tahoes where over three point eight million dollars went to the interception equipment. Adoption spreads through routine vehicle procurement with little external review of how the collected data is stored or shared. Once active the systems permit warrantless collection of private cell phone data across entire communities during normal patrols, which enables potential misuse and leaves individuals with no effective way to discover or contest the surveillance.

Android

OnePlus Will Continue Software Updates After US and Europe Exit (9to5google.com) 15

OnePlus has confirmed that it will exit the North American and European markets, consolidating its operations under parent company Oppo. Existing customers will continue to receive "software updates, security patches, and applicable support," but OxygenOS will be replaced by Oppo's ColorOS. 9to5Google reports: As a part of its shutdown in global regions, OnePlus has confirmed that its flavor of Android, OxygenOS, is going away. Instead, all active OnePlus devices will be moving over to Oppo's ColorOS starting with their Android 17 updates. This includes in India, where OnePlus is adamant it will continue operations -- reliable reporting disagrees.

OnePlus explains: "As part of an operational adjustment to our software strategy, following the official release of ColorOS 17, users globally with existing OnePlus devices that fall within the eligible upgrade scope will have the option to voluntarily update to the latest ColorOS. This enables us to streamline software development, accelerate update delivery, improve software quality, and make better use of our shared engineering and R&D capabilities."

[...] OnePlus will continue "maintenance support" for OxygenOS versions on older models not included in the Android 17 update scope, but newer devices will likely need to make the switch to ColorOS for all forms of continued support. OnePlus does explain that rollback versions to OxygenOS will be available for those who prefer the prior experience: "OnePlus devices will be able to choose whether to update to the latest ColorOS system. Older models that are not included in the update scope will also continue to receive version maintenance support. If users update to ColorOS, they will be able to roll back to OxygenOS. The specific rollback versions available will be subject to future official announcements."

Security

Iran Abused Mobile Networks' Vulnerabilities To Locate US Military In Middle East (techcrunch.com) 147

An anonymous reader quotes a report from TechCrunch: The Iranian government abused well-known vulnerabilities in the global telecoms infrastructure to locate U.S. military personnel in the build-up to the Iran War, as well as in the early days of the conflict, according to Financial Times. The Iranian government exploited Signaling System 7, or SS7, a set of protocols for 2G and 3G networks that has long been the backbone of how cellular networks connect to each other to route subscribers' calls and texts around the world, the newspaper reported, citing research by the Mobile Surveillance Monitor, as well as anonymous government officials with knowledge of the spy campaign.

Intelligence agencies have long abused SS7 to track cellphones abroad, which is what happened in this campaign. Using this technique, Iran was reportedly able to locate U.S. military forces stationed in military bases as well as hotels in Iraq, Bahrain, and other countries in the Middle East, which allowed the regime to strike them. These attacks resulted in several injuries. Apart from SS7, Iran also abused advertising technology used to serve tailored ads to cellphone users, another well-known surveillance technique that relies on everyday technology.

Cellphones

OnePlus Is Reportedly Shutting Down In the US, Europe (9to5google.com) 65

OnePlus will reportedly announce this week that it is shutting down its brand in the U.S. and Europe, following months of signs that parent company Oppo was winding down the brand's global presence. India and China are reportedly unaffected, but it's unclear whether Oppo will replace the brand directly in those markets. The move also raises questions about future support for existing OnePlus users. 9to5Google reports: WinFuture reports that OnePlus is gearing up for an official withdrawal from the U.S. and European markets, with the announcement due in the "coming days" this week. Closed-door press conferences have apparently happened, with no details shared on the exact reason OnePlus as a brand is shutting down in these markets. India and China are, as far as this report claims, not affected. The report, citing "well-informed sources," notes that this OnePlus announcement will come amid "fundamental changes" to Oppo's strategy, but the big point here is the global death of OnePlus.
Security

US Government Warns That Russia State Hackers Are Coming After Your Router (arstechnica.com) 76

CISA and allied governments are warning users to secure their routers as Russian state-backed hackers continue compromising the devices and turning them into proxy nodes to disguise attacks against critical infrastructure. The advisory urges users to disable outdated SNMP versions, use strong passwords, update firmware, and turn off unnecessary router services to reduce the risk of being swept into these botnets. Ars Technica reports: "Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks," the Cybersecurity and Infrastructure Security Agency said Monday. The hacking groups are tracked under various names, including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra. The advisory was co-issued by governments from around the world, including Australia, Denmark, New Zealand, and the UK.

The primary means of compromise the agency warned about was hackers scanning IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default authentication credentials. These scans are run by the very sorts of router botnets the actors are trying to enroll the targeted device in. By sending malicious traffic from spoofed addresses, the hackers can use the SNMP agent on poorly configured routers to run malware. SNMP allows users to collect and organize information about managed networking devices or to modify that information to change device behavior.

With control of a device, the hackers then use it as an exit node when probing or attacking targets in the communications, defense, energy, financial services, and government sectors. By funneling the malicious traffic through a benign-appearing device on a trustworthy IP address, the attackers are able to lower the chances of getting blocked by firewalls and other security defenses. Monday's advisory made no mention of identical operations carried out in recent years by China. So-called residential proxies are also a go-to tool used by financially motivated criminal hackers to obscure their true IP address. In many cases, these sorts of proxies are made up of millions of streaming devices that are sold with preloaded malware.

Cellphones

Parents' Phone Addiction Affects Bond With Kids, New Study Finds (bloomberg.com) 52

An anonymous reader quotes a report from Bloomberg: Parents' attachment to screens and smartphones can have negative, long-lasting developmental and psychological effects on their children, according to new research. Caregivers who mismanage their devices can both exacerbate "insecure attachment" and make healthy relationships more anxious and avoidant for children, according to the findings, which were published last month in Frontiers in Psychology, a peer-reviewed journal. The study, which surveyed 600 minors in the US from 12 to 17 years old, found that kids reported feeling marginalized or neglected by parents glued to their screens. "A child with insecure attachment may lack confidence or display a lower sense of self; demonstrate difficulty with interpersonal relationships and intimacy; and possess an unwillingness to take risks necessary to achieve success," reports Bloomberg, citing one of the study's researchers.

This type of behavior has become normalized: 2024 Pew data found that nearly half of U.S. teens say their parents are at least sometimes distracted by phones during interactions. "When parents were asked about their own behavior, far fewer said this was an issue," the report adds. "Still, earlier Pew data from 2020 found most parents feel their phones can interfere with quality family time, with 68% reporting being 'at least sometimes' distracted by them.

Slashdot Top Deals