Wel.nl

Minder lezen, Meer weten.

Meer huizenkijkers bij openhuizendag makelaarsorganisatie NVM

UTRECHT (ANP) - De openhuizendag van makelaarsorganisatie NVM heeft zaterdag meer belangstellenden getrokken. Bij de deelnemende huizen kwamen ongeveer 66.000 huizenzoekers over de vloer. Dat zijn er meer dan tijdens de vorige editie in maart. Toen trok de NVM Open Huizen Dag 52.000 bezoekers.

Makelaars wijzen onder meer op het zonnige weer van zaterdag. Ook stelden dit keer meer huiseigenaren hun woning open voor bezichtiging. Tussen 11.00 en 15.00 uur konden woningzoekers zonder afspraak binnenkijken bij bijna 14.500 huizen. Door de verkoopgolf van huurwoningen zijn er dit jaar ook meer koopwoningen beschikbaar gekomen. In maart van dit jaar deden er nog 8900 koopwoningen mee.

Volgens de NVM leverden de bezichtigingen soms meteen concreet resultaat op. In Rosmalen werd zaterdagmiddag direct een woning verkocht aan bezoekers, terwijl een kantoor in Apeldoorn zeker drie biedingen meldde. De hoogste gemelde opkomst was bij een woning in Arnhem. Daar telde de organisatie 66 bezoekers.


Voor Vollering had 'gouden jaar' nog wel langer mogen duren

SENCUR (ANP) - Wielrenster Demi Vollering vindt het jammer dat haar "gouden jaar" er bijna op zit na haar titelprolongatie op het Europees kampioenschap. "Ik rijd woensdag alleen nog de tijdrit en dan is het alweer voorbij. Maar ik kan niet wachten om heel volgend jaar in de regenboogtrui te rijden en dan hopelijk weer een mooi seizoen te hebben", zei de winnares van onder meer de Tour de France, Giro d'Italia en het WK van dit jaar.

Vollering veroverde bij het elfde EK de tiende Nederlandse Europese titel. "Dat is bizar. En mooi ook dat Puck (Pieterse) vandaag tweede wordt. Daar kunnen we weer heel trots op zijn. Ik hou van winnen, dat verveelt nooit. En het is niet eens alleen het winnen, het gaat mij ook om elke dag beter worden en aan jezelf werken. Dat vind ik het leukste aan dit vak", aldus de 29-jarige Zuid-Hollandse in het flashinterview.

Vollering veroverde vorige week in Montreal haar eerste wereldtitel op de weg.


VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Is kwaadwillende piloot in de cockpit te voorkomen? ‘Als iemand echt iets wil, zijn screenings niet genoeg’

Bedreigde mot strijkt massaal neer in oosten van Australië

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Gypsy Rose Blanchard’s former husband says he was ‘shocked’ by death of her ex-partner

Ryan Anderson says he reached out to Blanchard’s father to offer support after apparent overdose death of Ken Urker

The ex-husband of Gypsy Rose Blanchard has said he was “shocked” by the recent death in Louisiana of her former partner Ken Urker – and that he would be there for Blanchard and her daughter “if she needs me”.

Ryan Anderson made those remarks during an appearance on The Sarah Fraser Show podcast on Friday, providing a noteworthy reaction to the latest chapter involving Blanchard, who achieved an unusual level of celebrity after spending time imprisoned for a role in the murder of her abusive mother.

Continue reading...

MetaFilter

The past 24 hours of MetaFilter

"Entirely harmless, even if taken in considerable quantities"

Don't Cook That is a collection of 144 recipes and home remedies pulled from real cookbooks from 1831-1929. Highlights include "beer of sulfuric acid" and being placed into a whale carcass to cure rheumatism.

Mag ook al niet meer: halfnaakt in de klas zitten

Homo-acceptatie is verleden tijd. Vrouwen slaan is prima. Meisjes halfnaakt in de klas is niet goed. Tweederde van de ondervraagden vindt het prima dat er regels komen over wat leerlingen aantrekken: "Zeer korte rokjes en petten in de klas staan boven aan de lijst van kledingstukken die geweerd mogen worden. Zogeheten croptops, waardoor de buik zichtbaar is, en hoodies staan op respectievelijk de tweede en derde plaats. Ook slippers, trainingspakken en joggingbroeken worden genoemd."

Panel Inzicht heeft ook uw plaatselijke geilneef bevraagd: "Driekwart van de vrouwen wil zeer korte rokjes verbannen van school, tegenover bijna twee derde van de mannen. Van de laatste groep vindt de helft croptops te ver gaan. Maar bijna driekwart van de vrouwen vindt dat dit kledingstuk niet thuishoort in de klas."

Het onderzoek is afgenomen onder 18-plussers. Vanzelfsprekend, want waarom zou je niet 65-plussers bevragen over hoe kinderen naar school moeten? Omdat wij hoopvol zijn over zowel de tijdgeest als de jeugd, geloven we dat 18-minners hier volstrekt anders over denken. Er is hoop: "Een kwart is helemaal tegen kledingvoorschriften. Zij spreken van betutteling en vinden dat iedereen vrij moet zijn in zijn of haar kledingkeuze." Bring back geilneef.

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows

The second Anthropic-linked vulnerability known to have been exploited in the wild saw initial activity from an IP address in China targeting vulnerable hosts in the US and Japan. The vuln is a critical authentication-bypass bug in Rejetto HTTP File Server (HFS) that can lead to full admin access and remote code execution. HFS is an open source web file server that previously appeared on the US Cybersecurity and Infrastructure Security Agency’s catalog of Known Exploited Vulnerabilities in 2024. On Wednesday, researcher Zach Hanley at AI pen-testing company Horizon3 said he used Mythos to uncover a new flaw in the file server, now tracked as CVE-2026-61500. If you use Rejetto HFS, be sure to update to v3.2.1 or later, which fixes this and other security flaws. Hanley also published a video showing the steps to exploit HFS and remotely execute code on the server. By the next day, the CVE was under exploitation. “We started detecting exploitation of CVE-2026-61500 in Rejetto HFS this evening,” VulnCheck security researcher Patrick Garrity posted on LinkedIn on Thursday, adding that Hanley and team reported the bug to VulnCheck for CVE assignment. “Our canaries detected an actor in China targeting real vulnerable hosts in the US,” Garrity added. Garrity has been tracking CVEs attributed to Mythos and Project Glasswing, Anthropic’s initiative to give select partners access to the bug-hunting model, since shortly after the program was announced in April. Anthropic claims that Mythos is too powerful to release to the general public (insert evil laugh). As of Friday, Mythos and Project Glasswing have uncovered 286 CVEs, according to Garrity’s tracker, and up until Thursday only one of these bugs had been exploited in real-world attacks. The Thursday night activity originated from one IP address in China and targeted vulnerable servers in the US and Japan, Garrity told The Register. “Today we have seen four hits,” he told us on Friday. These originated from two different IP addresses in the US: 173.239.211[.]248 and 173.239.211[.]249. Both are in the same subnet, and “appear to be coming from a proxy,” Garrity added. China-linked digital intruders routinely use compromised devices as proxies to route malicious traffic and disguise the attackers’ true location, and in April a 10-country security advisory warned of China-nexus cyber operatives using proxy networks “strategically, and at scale.” In his write-up, Hanley said Horizon3 has used Mythos in its vulnerability research – and discovered “many critical vulnerabilities” – ever since the security company joined Project Glasswing in July. Mythos' mad math skillz CVE-2026-61500 highlights a couple of Mythos capabilities that make it really good at uncovering vulnerabilities, according to Hanley. Namely, Mythos excels at mathematical distillations and scientific tasks, especially those relating to computer science and operating systems. Finding this CVE “speaks to Mythos’s capabilities in understanding of mathematics, how it identified an exploitable set of cryptographic missteps, and approached solving the constraints to achieve remote code execution,” Hanley wrote. The security issue stems from how HFS authenticates users. It generates a random value with Math.random() and then passes this value to Koa, the Node.js web framework foundation for HFS. Koa uses keygrip to sign all session cookies with that random value. This means that if an “attacker can derive what the session signing key is, they can forge valid session cookies,” Hanley said. This should not be possible, assuming Math.random() uses a secure pseudo random number generator (PRNG). But V8’s Math.random() did not use a secure PRNG. Mythos discovered that the output of the xorshift128+ algorithm it used was fully reversible – and the application was leaking Math.random() outputs. The model’s analysis claimed that Z3, a Microsoft-developed, publicly available Satisfiability Modulo Theories (SMT) solver, could be used to recover the PRNG seed. Hanley notes that Horizon3’s researchers could not recall seeing an SMT solver used this way to attack a cryptographic flaw in a real application and bypass authentication. “What makes this impressive is that Mythos didn’t just flag the insecure PRNG in isolation – it simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible,” he wrote.®

Formula 1 News

Formula 1® - The Official F1® Website

How Aston Martin 'miracle' earned P12 and P14 for Bahrain GP

After a difficult season, Aston Martin finally got both cars into Q2 for the first time this year at the Bahrain Grand Prix in Malaysia.

What To Watch For in the Bahrain Grand Prix in Malaysia

Chris Medland picks out five key things to keep an eye on when the lights go out on race day at the Sepang International Circuit.