Formula 1 News

Formula 1® - The Official F1® Website

LIVE COVERAGE: FP1 for the Azerbaijan GP

Live coverage of the first Formula 1 practice session for the 2026 Azerbaijan Grand Prix in Baku.

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Government contractor exposed path to immigration records

Welcome back to PWNED, the column where we look at all the ways your security can become self-owned. Today’s scary story involves government contractors who just had to make their lives easier at the expense of locking down sensitive information. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request. Our tale of bureaucratic hell comes courtesy of security researcher Joe Brinkley, who previously worked for a government contractor as an information system security officer responsible for firewall rule changes, plus network intrusion detection and prevention. To improve the contractor's ability to deploy program changes, some of the org's developers wanted to change the firewall rules so it would be easier to move data from a low-security datacenter where they tested new code to the classified datacenter that housed the production server and data. They wanted to be able to VPN into a low-security commercial datacenter, where other non-governmental tenants, such as Microsoft and Oracle, had servers accessible through the same VPN connection. The datacenter itself provided the VPN, not the government. Back then, in the early 2010s, developers would use a provisioning server to help deploy code from dev to production. But there was always a hard firewall between the classified datacenter and the non-classified datacenter. The developers wanted this provisioning server to be able to access all of the production servers that sat in the classified datacenter so they could more easily push the code around. When the developers suggested they make this change for ease of deploying code, Brinkley told the Change Review Board that it was a very bad idea. “It creates a very glaring issue that we are going from a low-level secured datacenter all the way up to a high-level, top secret secured datacenter for production, and you guys are opening up a firewall rule that would allow anybody from that low level datacenter to have access into, at a minimum, into the high level datacenter,” Brinkley said. However, during a week when Brinkley was on vacation, the developers who wanted this firewall change talked directly to the Change Acceptance Board and got the rule changed. When he got back, Brinkley got a member of his company and a government representative to sit down for a demonstration. Tethering his laptop to his cell phone, he logged into the dev server over the VPN — then turned the box on and off. Then he showed how, with the very same VPN connection, he could get into the prod server and control it. This was a server that had 50 million records about immigration: who was coming to the country, who those people stayed with, and so on. According to Brinkley, thousands of people had access to the commercial datacenter’s VPN, but only dozens were supposed to have access to the classified government datacenter. The change potentially made the production servers reachable from a network accessible to thousands of VPN users. Yes, the servers still required a username and password for access, but an enterprising hacker could have tried guessing the correct combos or attempting a brute-force attack. There was no multi-factor authentication and password standards were low at the time. After Brinkley showed supervisors what was going on, they immediately changed the rule back to the way it was before. What we can take away from this lesson is that, even when you have security measures like a VPN and password protection, sensitive data requires additional safeguards. It’s not enough to do the minimum. ®

Slashdot

News for nerds, stuff that matters

Rogue OpenAI Agent Tried to Breach Government Site in May When Prompted for Simple Data-Retrieving Tasks

OpenAI's artificial intelligence "went rogue this year in at least four additional incidents," the New York Times reported Wednesday, "hacking and trying to break into government and university websites without being instructed to do so, according to researchers and government officials."


The attacks took place in May and June, before OpenAI's technology breached the A.I. start-up Hugging Face in July and set off a global debate about A.I. safety. Unlike the Hugging Face attack and other incidents in which A.I. systems were told to complete cybersecurity tests that effectively invited the models to demonstrate their hacking skills, the new incidents occurred when A.I. systems were directed to perform relatively mundane data collection, researchers said. When OpenAI's systems struggled to gather data from websites, they resorted to hacking techniques to get the information.

"Three of the incidents were identified by Transluce, a research lab focused on A.I. oversight, and all were confirmed by OpenAI," the article points out. That research lab even reports "an attempt on an Australian government public health website... the first reported instance of agents hacking a government," and which notably was done by the AI agents "while attempting mundane data retrieval tasks which were not cyber-related." (At the UN Wednesday Australian Prime Minister Anthony Albanese complained it took three months for OpenAI to then alert Australia's government about the breach, Bloomberg reports.)

Also targeted were the University of New Mexico's digital library with exploits like SQL injection and path traversal, and Data USA with cross-site scripting and other exploits. All three incidents involved "a low number of probe payloads" with "no evidence of exploitation," according to the researchers, who released a dataset "containing tens of thousands of queries apparently made by autonomous AI agents leveraging a URL scanning service to avoid access restrictions."
Records from urlquery.net show agents using the service since at least March 6, 2026, about two months before previously reported swarm activity. The first case, a March 6 attempt to retrieve Thai drug-enforcement statistics, shows an agent escalating as each approach failed: it first requested the data directly, then tried a service that converts web pages into text, and finally packed a custom program into a web address. The same technique shows up in thousands of agent requests recorded by urlquery.net starting in mid-April, targets many of the same data sources as the collusion.wiki swarm, and collapsed the same day the wiki activity did. We also report similar activity that occurred as recently as September 16... By March, they were finding creative ways around access limits. By May and June, they were gaining more access, including attempting to bypass cyber defenses to complete their tasks.


"This data reveals that malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval," the researchers concluded.
And they warn that the traffic they observed "goes back at least to March 6, 2026 and extends as recently as September 16, 2026, suggesting agents may still be exploiting these services to bypass restrictions."

Read more of this story at Slashdot.

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Meta verwijdert satirische video van Roel Maalderink over de ‘gluurbril’: ‘Voor kritiek is blijkbaar geen plaats’

Wel.nl

Minder lezen, Meer weten.

Pakistan voert luchtaanvallen uit op Afghanistan

KANDAHAR (ANP/AFP) - Pakistan heeft in de nacht van woensdag op donderdag tien doelen in Afghanistan aangevallen met gevechtsvliegtuigen en drones. Dat heeft de Pakistaanse minister van Informatie, Attaullah Tarar, bekendgemaakt. Onder meer de zuidelijke stad Kandahar werd getroffen. Afghanistan zegt dat burgers zijn omgekomen.

In het centrum van Kandahar woedde brand. De stad geldt als thuisbasis van Talibanleider Hibatullah Akhundzada.

De Afghaanse Talibanregering zegt dat door de Pakistaanse aanvallen vier burgers om het leven zijn gekomen. Een woordvoerder spreekt op X van "misdadige agressie" en zegt dat Pakistan kan rekenen op een "passende reactie". Hoe die reactie eruit zal zien, licht hij niet toe.

Aangevallen doelen

Volgens Pakistan waren de aanvallen gericht op militaire doelen die verband hielden met geplande aanslagen in Pakistan. Ook in de oostelijke provincies Paktia en Khost werden doelen aangevallen, melden lokale functionarissen.

De spanningen tussen Afghanistan en Pakistan zijn de afgelopen tijd sterk opgelopen. Islamabad beschuldigt Afghanistan ervan militanten van de Pakistaanse Taliban (TTP) onderdak te bieden.


China heeft gevoelige F-35-onderdelen in handen, hoort Bloomberg

WASHINGTON (ANP/BLOOMBERG) - Onderdelen van F-35-gevechtsvliegtuigen die helpen ze voor radars onzichtbaar te maken, zijn in handen gevallen van China, zeggen bronnen tegen persbureau Bloomberg. De Chinese autoriteiten hebben de onderdelen volgens de ingewijden nog niet teruggegeven.

China, dat in de Verenigde Staten geldt als de grote rivaal van de toekomst, bemachtigde de heel gevoelige vracht eind mei. Het vrachtvliegtuig dat de onderdelen van Australië naar de Verenigde Staten had moeten brengen, werd omgeleid via Hongkong, bleek vorige week al. Het is onduidelijk of de vlucht met opzet via het Chinese Hongkong is gestuurd of bij toeval.

Het vliegtuig vervoerde onder meer een cockpitkap en een deur van een wapenruim voor de F-35. Die hebben bijvoorbeeld een speciale coating die de 'stealth'-eigenschappen van het paradepaardje van de Amerikaanse luchtmacht versterkt. Die technologie wordt zorgvuldig geheimgehouden voor potentiële tegenstanders.


Bloomberg: grote overname datacenters Azië en Australië nabij

TOKIO (ANP/BLOOMBERG) - Een groep investeerders, waaronder de grote Amerikaanse vermogensbeheerder BlackRock, voert gesprekken over een miljardenovername van datacenters voor AI in Azië en Australië. Dat meldt persbureau Bloomberg. Het gaat dan om datacenters van het bedrijf Stack Infrastructure. Mogelijk is met die deal een bedrag van 20 miljard tot 25 miljard dollar gemoeid.

Het investeerdersconsortium bestaat uit het door BlackRock gesteunde Artificial Intelligence Infrastructure Partnership (AIP) en IFM Investors. AIP krijgt ook steun van de techbedrijven Microsoft en Nvidia en de staatsinvesteringsfondsen van Koeweit, Abu Dhabi en Singapore. De investeerdersgroep wil de datacenters overnemen van Blue Owl, het moederbedrijf van Stack. Er wordt nu voorbereidend onderzoek gedaan.

De datacenters staan in Tokio, Osaka, Melbourne, Sydney en het Maleisische Johor Bahru. Door de enorme opmars van kunstmatige intelligentie is er veel vraag naar datacenters die rekenkracht leveren voor AI-toepassingen.


Amsterdam Centraal gaat 3 oktober dicht voor renovatiewerk

AMSTERDAM (ANP) - Het treinverkeer op Amsterdam Centraal ligt zaterdag 3 oktober volledig stil voor grootschalige werkzaamheden, melden NS en ProRail. Op zondag 4 en maandag 5 oktober rijden er minder treinen dan normaal en moeten reizigers rekening houden met grote drukte, vooral tijdens de spits. De grootscheepse renovatie van het station bereikt volgens ProRail "een belangrijke mijlpaal".

Spoor 11a wordt na afgerond werk weer aangesloten, terwijl spoor 14a juist wordt losgekoppeld. ProRail en aannemer Dura Vermeer gaan veel zichtbaar werk verrichten, maar ook veel onzichtbaar werk, bijvoorbeeld aan de spoorbeveiliging en installaties van de verkeersleiding. Dat levert de grootste hinder op.

"Om spoor 11a in gebruik en spoor 14a buiten gebruik te kunnen nemen, moet de beveiliging worden aangepast. Voor aanpassingen in de installaties moeten we al het treinverkeer van en naar het station een dag stilleggen", legt ProRail uit.

Het perron van spoor 13 en 14 wordt verlengd en de opgangen worden verbreed, zodat daar meer ruimte ontstaat.


De Speld

Uw vaste prik voor betrouwbaar nieuws.

Witte Huis onthult eerste presentator voor nieuw staatsnieuwszender

​Het Witte Huis heeft de eerste presentatrice van de nieuwe staatsnieuwszender onthuld. Zij zal de kijkers van Trump TV de belangrijkste nieuwsverhalen van de dag vertellen, rechtstreeks afkomstig van de regering-Trump. Amerikaanse staatsburgers krijgen daarmee regelmatig updates over de nieuwste historische prestaties van de president.

De woordvoerder van het Witte Huis, Chuck Williams, licht toe: “De overbodige tussenpersoon die traditioneel bekendstaat als de ‘journalistiek’ wordt met ons nieuwe staatsmedium buitenspel gezet. Amerikanen zijn het beu dat zogenaamd onafhankelijke journalisten bepalen wat als 'nieuws' geldt.”

Onderwerpen die naar verwachting een prominente rol zullen spelen, zijn onder meer: Trump die de hoogste waarderingscijfers ooit behaalt, Trump die de beste handelsovereenkomst uit de menselijke geschiedenis ondertekend, Trump die een magnifieke golfslag slaat en Trump die complimenten ontvangt van verschillende knappe, jonge vrouwen die hem aan het inoliën zijn.

&


The Match, over het WK-duel van ‘de hand van God’, is een onweerstaanbare reis terug in de tijd

Het verhaal over de WK-kwartfinale tussen Engeland en Argentinië in 1986 is in veertig jaar vaak verteld. Maar zelden met zo veel liefde voor details als in de onlangs verschenen documentaire van twee Argentijnse makers.