Slashdot

News for nerds, stuff that matters

AliExpress Hit With Record $625 Million Fine After Failing To Make EU-Ordered Fixes

The European Commission has fined AliExpress more than $625 million, the largest penalty yet under the Digital Services Act, after finding that the marketplace failed to "diligently assess and mitigate risks relating to the sale of illegal, unsafe, or counterfeit products on its e-commerce platform." EU officials said flagged products repeatedly reappeared, sellers could evade safeguards, and AliExpress's recommendation and ad systems helped amplify dangerous goods. Ars Technica reports: For shady sellers, the risks of detection appeared low. The e-commerce site's mandatory brand authorization system was also ineffective and understaffed, the EC found, and AliExpress did not penalize traders for selling illegal products as its policy claims it would. Making things worse, AliExpress "inadequately assessed how its recommender and advertising systems exacerbate the spread of illegal products," the EC said. So rather than remove illegal products, AliExpress was recommending them to consumers and helping to maximize exposure. Talking to the press, the European Union's tech chief, Henna Virkkunen, noted that one in five Europeans shop monthly at retail sites like AliExpress, Temu, and Shein.

AliExpress also relied on a single quantitative metric to gauge how effectively its systems were working to weed out illegal products. And that metric did not properly measure the extent of the harm. EC testing found that "a high volume of illegal products" -- including unsafe toys and dangerous cosmetics -- "continued to circulate despite AliExpress' moderation efforts." In June 2025, AliExpress was ordered to bring its platform into compliance with the DSA but failed to make the necessary changes, the EC said. The fine was calculated to be proportionate to the nature of the violations, which the EC considered "particularly serious infringements," and to penalize AliExpress's delayed interventions to mitigate flagged risks.

[...] AliExpress told Ars it was "surprised" by the "disproportionate" fine. AliExpress said it plans to appeal the decision, claiming the EC ignored its "sound risk management framework and the significant, proactive enhancements we have made." The massive online retailer noted that its EU market is substantially smaller than its China market and said that it invests "substantial resources in risk assessment and mitigation, product safety and consumer protection" and "has been and continues to be committed to meeting our obligations to consumers."

Read more of this story at Slashdot.

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Attackers pummel critical WordPress vuln to create all sorts of mischief

If you use WordPress, patch now. Just hours after fixes came out, attackers have begun exploiting two bugs that, when chained together, allow pre-authentication remote code execution (RCE). And security researchers tell us there’s a very good chance the miscreants had an AI assist. “Once the vulnerabilities were publicly disclosed, reproducing them with the help of frontier AI models was only a matter of time and tokens,” Jake Knott, watchTowr principal security researcher, told The Register. “WatchTowr was able to trivially reproduce CVE-2026-63030 within minutes of disclosure, and the second CVE-2026-60137 with some additional effort.” WordPress released patches for both CVEs late Friday, but by Saturday it was game over. “By the early hours of Saturday morning, successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public,” Knott said. “From our vantage point across a global client base, we are seeing widespread impact of this vulnerability across organizations of every size and every vertical.” Here are the details about both security holes, and what went down since WordPress revealed and fixed them on Friday. CVE-2026-60137 is a moderate-severity SQL injection issue, and CVE-2026-63030 is a critical REST API batch-route confusion bug. “A route confusion flaw causes the arrays containing the sub-requests, validation results, and matched handlers to become misaligned,” Hacktron researchers explained. This causes WordPress to become confused about which requests have been properly validated and thus treat all requests as trusted, including those that it should block. Individually, the bugs are difficult to exploit. But when chained together, they can wreak havoc on any organization using a vulnerable WordPress version because they allow unauthenticated RCE. WordPress 6.9 is affected by both vulnerabilities, and version 6.9.5 contains fixes for both, while WordPress 6.8 is only affected by the SQL injection flaw, and version 6.8.6 fixes it. Additionally, WordPress 7.1 Beta 1 is also vulnerable. Version 7.1 Beta 2 fixes both CVEs. Versions of WordPress prior to 6.8 are not affected. John Blackbourn, one of the WordPress core developers, recommended affected users “update your sites immediately.” Because of the flaws’ severity, the WordPress security team “enabled forced updates via the auto-update system for sites running affected versions,” he added. The content management system credited Searchlight Cyber researcher Adam Kues with finding and reporting CVE-2026-63030, and in a subsequent Friday advisory, Kues dubbed the bug wp2shell. “The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins,” Kues said, adding that his security shop released a free wp2shell checker to determine if your instance is vulnerable. Security firm PatchStack reported exploitation of both CVEs as of Friday night, but didn’t provide details about the attacks. VulnCheck’s research team, which also began researching the patches on Friday, verified more than two dozen unique proof-of-concept exploits targeting WP2Shell as of Sunday. “After public exploit code was released, attackers began spraying the internet indiscriminately, hitting anything reachable and trying to get lucky,” Knott told us. “Our honeypots recorded tens of thousands of exploitation attempts, and more than 100 backdoor accounts created by different threat actors using variations of public tooling.” After creating these backdoor admin accounts, watchTowr observed attackers deploying fake WordPress plugins to achieve RCE, exfiltrate credentials or secrets, or download additional tooling to further compromise the system, he added. “In one case, we watched a threat actor repeatedly attempt to pull down Overlord RAT, a Golang-based remote access trojan.” Any orgs that waited until Monday to patch are likely already compromised, Knott warned. “Defenders need to inspect their WordPress instances for new administrator accounts, malicious plugins, or other suspicious files, regardless of whether they’ve patched,” he said.®

osanpo_1970

gnsk has added a photo to the pool:

osanpo_1970

Tsubosaka temple, Nara, Japan 壺阪寺、奈良県

Mr Mikage (ミスター御影) has added a photo to the pool:

Tsubosaka temple, Nara, Japan 壺阪寺、奈良県

kottke.org

Jason Kottke's weblog, home of fine hypertext products

Goofy Oversized Wicker Costumes

Artist Lewis Prosser describes himself on Instagram as an “absurdist basket-maker”. His costumes for a project called Making Merrie reflect that self-description.

Making Merrie explores the material culture of folk theatre. Inspired by mummers’ plays and masked traditions along the Wales/England border, Making Merrie combines craft, performance, and language to reflect on cultural heritage and exchange.

Mummers’ plays are traditional folk performances with roots over 500 years old, often tied to Christmas and New Year. Full of humour and spontaneous revelry, these plays were staged in streets, homes, or pubs by amateur troupes, telling simple stories of combat, death, and miraculous revival. Unlike the religious Mystery Plays, mummers’ plays are secular, carnivalesque, and performed for community fun.

The project features large-scale wicker costumes, handcrafted using regional willow basketry techniques, highlighting basketry as an essential human skill we’re at risk of forgetting—a skill that, if lost, means losing part of what it is to be human.

(via colossal)

Tags: art · Lewis Prosser

Wel.nl

Minder lezen, Meer weten.

VS kondigen historische invoerheffingen op Canadese producten aan

WASHINGTON (ANP/RTR/AFP) - De Verenigde Staten gaan een invoerheffing van 50 procent opleggen op verschillende Canadese producten. Dat meldt het Witte Huis maandag.

De Amerikaanse president Donald Trump heeft daartoe een decreet ondertekend als reactie op de "discriminerende behandeling" door Canada van Amerikaanse auto's, alcohol en zuivelproducten.

Deze nieuwe invoerheffingen, die over een maand van kracht moeten worden, zullen van toepassing zijn op uiteenlopende producten zoals wijn, ijshockeysticks en cement. Ook producten die in het kader van de Noord-Amerikaanse Vrijhandelsovereenkomst de VS binnenkomen, vallen hieronder.

De heffingen worden opgelegd op grond van artikel 338 van de Tariff Act uit 1930, dat de president de bevoegdheid geeft om invoerrechten van maximaal 50 procent op te leggen aan landen waarvan wordt aangenomen dat zij de Amerikaanse handel discrimineren. Deze bepaling is nog nooit eerder gebruikt om invoerrechten op te leggen.


MetaFilter

The past 24 hours of MetaFilter

The curious case of disappearing polymorphs

A well-known example of the disappearing polymorph is the HIV/Aids drug ritonavir, developed by Abbott Laboratories, which gained approval in 1996. Two years later a more stable, less soluble crystalline form (form II) began appearing in manufactured batches, replacing the original form I and rendering the capsules ineffective.

More sources: Derek Lowe (one of many previous) discusses the"unintentional crystalline seed" hypothesis: that a tiny amount of an previously undiscovered crystal form of ritonavir infected the chemical synthesis (and all of the machinery and factory and duct work) associated with the first discovered and more useful form. This "infection" of the new crystal made it almost impossible to create the old form anymore. Disappearing Polymorphs(PDF) The original paper on disappearing polymorphs. Disappearing Polymorphs Revisited

Tsubosaka temple, Nara, Japan 壺阪寺、奈良県

Mr Mikage (ミスター御影) posted a photo:

Tsubosaka temple, Nara, Japan 壺阪寺、奈良県

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Nicaragua’s president says country will not hold any more elections

Daniel Ortega, the 80-year-old authoritarian leader, says move will ‘build a wall’ against the opposition

Nicaragua’s long-serving president, Daniel Ortega, has said the country will hold no further elections to prevent the opposition from coming to power.

The 80-year-old authoritarian leader, who has been in office since 2007, also said he would work with the congress he controls to pass new laws that would “build a wall” against the opposition.

Continue reading...

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Trump zet handelsoorlog met Canada voort en gaat importheffing verhogen naar 50 procent