Slashdot

News for nerds, stuff that matters

Microsoft and Nvidia Unveil Surface Laptop Ultra For $2,599

At a press event today, Microsoft unveiled the new Surface Laptop Ultra featuring an NVIDIA RTX Spark platform with a Blackwell-based GPU capable of up to one petaflop of AI compute. The laptop supports up to 128GB of unified memory for running models as large as 120 billion parameters locally, while also adding a 15-inch mini-LED display, expanded ports, upgraded cooling, and support for hundreds of AAA games. It's available for pre-order today starting at $2,599. Neowin reports: To keep the device's temperature under control, Microsoft has also developed a new cooling system that offers up to 2.5 times the thermal capacity of the 15-inch Surface Laptop 7th Edition. The Surface Laptop Ultra comes with a 15-inch PixelSense Ultra mini-LED touchscreen with a 3:2 aspect ratio, a pixel density of 262 PPI, and peak HDR brightness of up to 2,000 nits.

Despite its beefy specs, the Surface Laptop Ultra measures less than 18mm thick and weighs under 4.5 pounds (around 2kg). The laptop will be available in Platinum and Nightfall finishes. Microsoft has also increased the size of the precision haptic touchpad by more than 30% compared to the Surface Laptop 7th Edition for improved haptic input. The Surface Laptop Ultra includes a broader selection of ports, featuring USB-C, USB-A, HDMI, a 3.5mm headphone jack, and a full-size SD card reader. It also features the world's first built-in USB-C magnetic charging.

Read more of this story at Slashdot.

Formula 1 News

Formula 1® - The Official F1® Website

Our early Bet Builder for the Singapore Grand Prix

Our expert betting writers have picked a four-leg Bet Builder for the Marina Bay night race, including a podium finish and top-six finish selections.

Juice

I need to push some updates to the remote sensing instruments, which are there to measure the surface and definitely not do anything else.

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Browser-in-browser attacks use fake Meta Muse Ad lure to steal credentials

A phishing campaign targeting advertising managers by impersonating Gemini, Claude, ChatGPT, Perplexity, and Manus to steal credentials and multi-factor authentication (MFA) codes has added a fake Muse Ads product to its lure lineup – just eight days after Meta launched its personal AI agent. Meta announced Muse on September 8, and by September 17, a very convincing website – museads.ai – for a product called Muse Ads that promised to help advertisers reach buyers and run sponsored placements popped up online. “The operators already had the platform, so adapting it to a new brand can take minutes,” Oleg Zaytsev, lead security researcher at Island, told The Register. “The striking part is how quickly they turned a timely announcement into a credible reason for someone to act. The same platform could then be repackaged around other familiar tasks, from connecting a business tool to claiming a refund or applying for a job.” The security startup spotted the Muse Ads webpage, and upon digging into the scam uncovered that just the page was new. “Its code, from the sign-in forms to the fake browser window, came from a wider operation that had already run fake ad products for Gemini, Claude, ChatGPT, Perplexity, and Manus,” Zaytsev and fellow Island researcher Ofek Ronen wrote in a blog post published Tuesday. All of these products served as lures for browser-in-the-browner (BitB) attacks designed to trick agency staff, media buyers, and manager-account administrators into handing over their advertising account credentials – along with stored payment methods and client accounts – to digital thieves. “For victims, the potential cost is loss of access to an advertising account, unauthorized ad spend, and exposure of linked client accounts,” Zaytsev told The Register. How the scam works BitB is a clever phishing technique originally detailed by a researcher called mr.d0x in 2022. It involves building a fake login window directly inside a legitimate one. The fake window looks like the real thing, featuring an address bar, title, and URL, but it's just an overlay to steal users’ credentials. According to Zaytsev, this one has likely proved very lucrative for its criminal operators, with hundreds of victim submissions to the platform, and activity still ongoing. “From one frontend alone, we observed submissions involving roughly 200 distinct email addresses over about a month,” he told us. “The operators used the same platform across many similar sites, so we estimate the campaign-wide volume is substantially higher.” Each phony ad product has its own page, with ChatGPT promising users a Monday Google Ads brief, Gemini offering manager account and linked-client support, Claude an advertising portal, Perplexity pitching campaign planning and spend audits, and Manus providing a private Meta integration. Each fake product page also has a “connect” button. When the victim clicks “connect,” it opens the browser-in-browser overlay, with a fake address bar showing accounts.google.com, or an Okta tenant to gain the victim’s trust. The real browser, however, stays on the phishing domain and steals credentials when the victim types them in. A human operator running the campaign sees each submission and chooses what the victim sees and is prompted to do. This includes asking for another password, requesting an SMS or Okta authenticator code to bypass MFA, showing a Google approval code or Okta push request, or displaying a QR code. The platform supports Google, Meta, TikTok, and Okta workflows, and the browser overlay adapts to whatever the victim runs: Window, macOS, iOS, ot Android, and even mimics Safari’s URL pill, Chrome’s custom tabs, and a dark mode. And while the researchers told us they haven’t identified the people operating the kit or found a name under which it’s sold, the operators did expose older source code through misconfigured public GitHub repositories that connected this to a campaign to a larger operation. In addition to the AI ad pages, this operation also used fake refund claims and job recruitment sites as lures with separate builds for Adidas, Google Careers, Robert Half, Tesla, and Louis Vuitton. All of these pages run on one Next.js and Socket.IO stack. Many of the pages also used Vercel frontends with Railway or Render services behind them for state and commands. “A new brand or polished page doesn’t necessarily mean a new attack. Operators can change the lure quickly, but the workflow still has to move someone onto a site they control, collect credentials, and steer them through authentication,” Zaytsev said. “Security teams should maintain a continuous baseline of trusted domains, check the real browser address, and connect similar behavior across different sites,” he added. “Attackers can generate a convincing website quickly; building the domain history and reputation of a legitimate service is much harder. AI can help defenders keep pace with AI-generated websites, especially as they become more convincing and appear more quickly.”. ®

Fröttmaning

Peter Kernwein posted a photo:

Fröttmaning

Fröttmaning

Peter Kernwein posted a photo:

Fröttmaning

Fröttmaning

Peter Kernwein posted a photo:

Fröttmaning

Fröttmaning

Peter Kernwein posted a photo:

Fröttmaning

Fröttmaning

Peter Kernwein posted a photo:

Fröttmaning

Rijnmond - Nieuws

Het laatste nieuws van vandaag over Rotterdam, Feyenoord, het verkeer en het weer in de regio Rijnmond

Van der Valk transformeert iconisch kantoorpand tot modern hotel

Het voormalige kantoorgebouw van Rijkswaterstaat aan de Maasboulevard in Rotterdam staat een nieuwe toekomst te wachten. Het pand uit 1988 wordt omgebouwd tot modern Van der Valk-hotel. De werkzaamheden zijn in volle gang en op de buitenkant is al een halve toekan te zien. Hoe gaat het hotel er uiteindelijk uitzien?