Wel.nl

Minder lezen, Meer weten.

Jihadisten voeren nieuwe aanvallen uit in Mali

BAMAKO (ANP/AFP) - Jihadisten hebben op meerdere plekken in Mali aanvallen uitgevoerd, meldt de Malinese krijgsmacht. Aanvallen werden onder meer gemeld in noordelijke steden en een gevangenis in Kenieroba, vlak bij de hoofdstad van het Afrikaanse land.

De Azawad Liberation Front (FLA) zegt betrokken te zijn bij de aanvallen. De rebellengroep bestaat voor een groot deel uit Toeareg, een etnische groep die onafhankelijkheid wil in het noorden van Mali.

Sinds de staatsgrepen in 2020 en 2021 wordt Mali bestuurd door een militair regime, dat beloofde het land veiliger te maken. De afgelopen tijd heeft de junta nauwer contact gezocht met de Amerikaanse regering, die eventueel wil samenwerken op het gebied van veiligheid en de mogelijkheden voor mijnbouw wil onderzoeken.

Volgens persbureau Reuters wordt er onder meer gevochten in Anefis, waar zich Russische militairen zouden bevinden.


The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Labour should win next election under Burnham after work already done, Starmer says

Prime minister holds no ‘personal animosity’ toward likely successor and stresses he has a platform to build on

Keir Starmer has said Labour “should go on to win the next election” under his likely successor, Andy Burnham, based on what the prime minister had already achieved.

In his first interview since he announced he would stand down, Starmer also said he held no “personal animosity” toward Burnham, who is expected to succeed him.

Continue reading...

Australia v Ireland: Nations Championship rugby union international – live

  • Updates as the Wallabies welcome Ireland to Sydney

  • Kick-off time is 8.10pm AEST/11.10am IST and BST

  • Any thoughts? Get in touch with an email

Really keen to see how the midfield battle plays out.

Len Ikitau is one of the elite ballers in the game and Stuart McClosky was the best centre of the Six Nations (imo).

Continue reading...

America is destroying itself. It’s no surprise | Stephen Marche

Scholars will somedy wonder how the richest country in history chose to throw it all away. But the crisis has been there since the beginning

The 250th anniversary of the Declaration of Independence has arrived at a moment of some embarrassment for the Republic. The United States of America, established to overthrow a mad king, has elected, 250 years later, a mad king of its very own. America is setting itself on fire at its birthday party. It always had a dramatic streak.

In 30 or 40 years, scholars of history, if they exist, will want to know how the richest country in history, with the world’s most powerful alliance network, and a scientific and research capacity fuelled by the talent of the world, chose to throw it all away.

Continue reading...

‘I filled a white ceramic bowl and carefully placed the fish inside’: Rashid Sheriff’s best phone picture

The Indian photographer dunked his iPhone underwater to get this shot of his pet

Rashid Sheriff’s fascination with photography and drawing originated in his school days, though “due to various limitations and circumstances, I couldn’t pursue those interests”, he says.

For the past 18 years, Sheriff, who is from Kerala, in south-west India, has been working in Qatar as an auto electrician. Smartphones, however, have allowed him to return to his passions once again.

Continue reading...

This is how we do it: ‘I fell in love with my lover’s husband – and now we’re a trio’

Jonathan met Sadie when she was dating his wife. Now the two women share him – but he insists that they are the ones in control

How do you do it? Share the story of your sex life, anonymously

When he suggested we stop seeing each other because he developed feelings for me, I told him: ‘This is too special to give up’

Continue reading...

England get hostile welcome on arrival at Mexico City hotel for World Cup showdown

  • Hundreds of fans greet the players, with many booing

  • Increased security outside after Ecuador team disturbed

England received a hostile welcome as they arrived at their Mexico City hotel for Sunday’s World Cup last-16 tie against Mexico.

England had been hoping to keep their location undisclosed after Mexico supporters used loud speakers, horns and motorcycles to try to disturb the sleep of Ecuador’s players before their last-32 tie, which the co-hosts won 2-0 on Wednesday night.

Continue reading...

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Confidential computing's core trust mechanism is broken. The fix may not exist

Vendors are trying to position "confidential computing" as the technical backbone of Europe's sovereign cloud ambitions. But new research shows that a security protocol used to prove cryptographic trust in the system may have a fundamental architectural flaw. Confidential computing rests on a mechanism called remote attestation, in which a server cryptographically proves to a client that it is running inside a genuine, unmodified Trusted Execution Environment (TEE) before any sensitive data changes hands. Intel's product pages promise TDX will "add safeguards to data sovereignty and governance." Google Cloud describes its confidential computing infrastructure as offering "full, auditable control over access to customer data." In May, The Register reported that the chip beneath the chip, the management engines running below the operating system on Intel and AMD silicon, falls outside what European sovereignty frameworks like SecNumCloud actually assess. That left an open question about the layer above the silicon: the protocol meant to prove the chip itself can be trusted. New, independently verified research answers it, and the answer is not reassuring. A protocol that promises more than it proves Muhammad Usama Sardar, a researcher at TU Dresden, has spent the past two years formally verifying whether that protocol, known as attested TLS, actually does what it claims. Using ProVerif, a tool for the symbolic security analysis of protocols, he and his co-authors discovered that it largely does not. Their recent paper, Identity Crisis in Confidential Computing, published with co-authors Mariam Moustafa and Tuomas Aura and presented at the AsiaCCS 2026 conference, found diversion attacks against two state-of-the-art attested TLS protocols. A connection intended for one server can be silently redirected to a different, compromised machine running identical software, anywhere in the world, without the client ever knowing. The intended server has done nothing wrong. The attacker simply exploits the fact that the protocol checks the software's integrity, not its location. The most recent paper, Intra-handshake.fail, published with co-authors Viacheslav Dubeyko and Jean-Marie Jacquet and accepted for ESORICS 2026, goes further. It examines what the industry calls intra-handshake attestation, where evidence is generated during the TLS handshake itself, and tests seven different ways of cryptographically binding that evidence to the underlying connection. None of them prevent relay attacks, in which a client verifies the evidence of a genuine, trustworthy AI agent or server but ends up encrypting its traffic to an entirely different, malicious one. The starting assumption in all of this is that the hardware itself can be trusted. "In confidential computing, you have to trust the hardware manufacturer anyway," Sardar told The Register. "There is absolutely no way around this." With that root of trust accepted, he argues, the protocol layer was supposed to provide everything else. His research shows it provides far less than assumed. Three levels of trust The researchers formalise the problem as three increasingly strict levels of cryptographic binding between the attestation evidence and the actual TLS connection it is meant to vouch for. The weakest, level one, ties evidence only to the very first key exchange in the handshake, the Diffie-Hellman step, where client and server agree on a shared secret before either side has proven who they are. Level two ties it to the client's handshake traffic key, covering everything up to the server's identity confirmation. Level three, the strongest and the one that matters most in practice, ties evidence to the application traffic key itself, the key actually used to encrypt the sensitive data a client sends once the connection is live. Sardar's extensive analysis in ProVerif focused on intra-handshake attestation; post-handshake attestation fell outside its scope. Three of the seven binding mechanisms examined achieve level one. The rest fail even that baseline. His team's own proposed mitigation, a cryptographic binder built from the TLS handshake secret combined with the server's public key, formally achieves level two. Level three, the paper concludes, "may not be possible" within intra-handshake attestation as currently architected, without breaking properties of TLS 1.3 that the protocol was never designed to give up. In plain terms: the best fix available today proves a client is talking to the right machine at the start of a handshake. It cannot prove that the data sent minutes later is still going to that same machine. Production systems, not laboratory proofs of concept The vulnerability is not confined to academic models. Sardar's team formally analysed four real-world implementations of intra-handshake attestation: Meta's Private Processing system for WhatsApp, Edgeless Systems' Contrast, the open-source Cocos AI platform, and a proof-of-concept maintained by the Confidential Computing Consortium's (CCC) Attestation Special Interest Group. The first three of the four are running in production today. The attacks apply to every version of Cocos AI between 0.4.0 and 0.8.2. The class of flaw itself is not new. Sardar's team notes the attacks are subtle enough to have gone undiscovered for years before formal analysis caught them. The responsible disclosure resulted in CVE-2026-33697, rated 7.5 on the Common Vulnerability Scoring System, high severity. For comparison, the researchers note in their paper that BadRAM, the 2024 memory aliasing attack against AMD's SEV-SNP that made headlines in its own right, scored 5.3. The CCC Attestation SIG's repository lists CVE-2026-33697 as the highest-scoring vulnerability among a cluster of recent confidential computing flaws, ahead of Fabricked (5.9), BreakFAST (5.9) and Staleus (4.0). The working group and the IETF's TLS working group have both formally acknowledged the relay attacks. "As implemented today, attested TLS is not mature yet," Sardar told The Register. "We are investigating further, and we are confident there are more issues yet to be discovered." What makes the finding more pointed is who missed it first. Meta commissioned an extensive security review of its WhatsApp implementation from Trail of Bits, a well-regarded security firm, before Sardar's team examined it. That review did not detect the relay attack. It is methodology, not incompetence, that explains the gap. The ESORICS paper records that Sardar's team contacted Trail of Bits directly, who confirmed no formal methods were used in their review process. Formal verification tools like ProVerif check a protocol exhaustively against every scenario a defined threat model allows. A manual audit, however thorough, samples. A subtle flaw in how evidence is bound to a connection can slip past a sampled review and still be provably broken under exhaustive formal analysis. The Attestation Special Interest Group of the CCC, which governs the adopted proof-of-concept project Sardar tested, found its own system vulnerable to the same relay attacks. A repository nobody would create The vulnerability itself had already been through a lengthy, orderly disclosure process. Sardar's team flagged it to Cocos AI in October 2025, the vendor acknowledged it two months later, and the CVE was published in March 2026. What happened next was different. On 14 June, Sardar wrote to the chairs of the CCC's Attestation Special Interest Group requesting a new public GitHub repository, named relay-attacks-in-intra-handshake, so his formal analysis artefacts for the relay attacks could be released under an Apache 2.0 licence, for use by researchers and the standardization community. He referenced an existing, adopted project under the same group's governance, the kind of administrative step that, on paper, should take minutes. Three days later, on 17 June, he sent a reminder. The following day, a second, noting the artefact link was needed for the paper's final version. On 24 June, ten days after the original request, he wrote again, this time without the diplomatic padding: "I do not see a good reason for such a delay, since the requested repo is part of an adopted project and creation of a new repo is not such a time-consuming task." The new repository still did not exist. The CCC's Attestation Special Interest Group is made up of representatives from the hardware and cloud vendors whose products the research concerns. That fact requires no embellishment. A working group populated by the companies whose attestation implementations were just shown to be vulnerable to relay attacks did not act, for over a week and across three written reminders, on a request to publish proof of that vulnerability. Since no repository had been created before the paper's final version went to the publisher, Sardar published the artefacts anyway, but inside an existing CCC-affiliated repository rather than the dedicated one he had asked for. He told The Register the repository had originally been built for an unrelated project: "Since the monopoly [of vendor-dominated working groups over this infrastructure] continues, we have released the artifacts to inform the community and for researchers to analyse it independently." The CVE stands regardless, credited and public. The delay changes nothing about the underlying mathematics. BSI reaches the same verdict None of this requires taking Sardar's interpretation on faith. A world away from the IETF mailing lists, Germany's Federal Office for Information Security (BSI) arrived at a closely related conclusion through its own, entirely separate channel. Carina Hilt, deputy press spokesperson at BSI, was asked directly about confidential computing's role in digital sovereignty. She told The Register the technology functions as "a defense-in-depth component," strengthening tenant isolation and protecting confidentiality and integrity, but not availability. Crucially, she added that "dependencies on other services, such as identity and key management etc., are also not mitigated by CC." That is, in other words, an institutional echo of exactly the gap Sardar's protocol analysis exposes: confidential computing's guarantees stop well short of guaranteeing who actually controls the keys and the identity infrastructure a deployment depends on. Pressed further on vendor marketing claims, BSI did not soften its position. "The vendors' positioning on CC might give too much weight to its technical capabilities," the spokesperson told The Register. "CC alone cannot satisfy the requirements for digital sovereignty." What the chipmakers say Mikael Moreau, Intel's France Communication Manager, was asked specifically about the attestation infrastructure underpinning its TDX confidential computing technology, and whether Intel's own role in that infrastructure constitutes a dependency. He said the company does "not consider its attestation infrastructure to be a limitation to sovereignty guarantees," arguing that any reliance on Intel's silicon and certificate root of trust is "bounded." Intel is not in the customer's workload data path, does not receive customer plaintext through attestation, and the operational trust decision can be delegated to an independent verifier or retained by the customer. That is a carefully constructed, technically defensible answer. It explains the architecture, not the law. Intel was asked whether its attestation infrastructure poses a sovereignty risk under RISAA, the 2024 US law that can compel hardware manufacturers to cooperate with secret intelligence orders. That question went unanswered. Google did not respond to a request for comment for this article. Acknowledged everywhere except the sales pitch Sardar's findings prompted four different institutional responses. The IETF's Secure Evidence and Attestation Transport (SEAT) working group, formed after a group including Sardar successfully argued for it at a Birds of a Feather session at IETF 123 in Madrid in July 2025, wrote his correlation properties directly into its charter as an explicit, mandatory requirement for any new specification work. That is a standards body doing exactly what it should, building formal verification into the process rather than bolting it on afterwards. The IETF's TLS working group formally acknowledged the same attacks, without adopting a binding requirement of its own. The CCC's inaction over ten days meant Sardar published the evidence himself, without the working group's help. None of that reached the sales conversation. Intel and Google continue to market confidential computing as proof of sovereign, verified protection. Asked directly about the infrastructure underpinning that claim, Intel's answer stopped short of the legal question at its centre. Google did not answer at all. For European CIOs and procurement officers, this raises a question beyond the one usually asked. It is no longer only which company owns the cloud or which government can compel which hardware manufacturer. It is whether the cryptographic handshake meant to prove a workload is running where it claims to be running can be trusted at all. The level that timing rules out Sardar's own mitigation reaches level two. Level three, the one that actually matters to a customer trying to verify their workload is still protected once data starts flowing, may not be achievable at all within the current architecture of intra-handshake attestation, where evidence is generated during the handshake itself. The timing is the problem. Level three requires binding the evidence to the key that encrypts the actual application data, but by the time that key exists, the evidence has already been sent, unless the TLS protocol itself is significantly changed. Post-handshake attestation waits until after that point, when the key is already there to bind against. "We believe post-handshake attestation alone can achieve level three binding," Sardar told The Register, warning that newer proposals combining both approaches add unnecessary complexity without adding security. His recommendation to the IETF's TLS working group is blunt: developers should abandon intra-handshake attestation altogether. ®

404 Media

404 Media is an independent media company founded by technology journalists Jason Koebler, Emanuel Maiberg, Samantha Cole, and Joseph Cox.

SOLVED: The Case of the Missing Megalodon

SOLVED: The Case of the Missing Megalodon

Welcome back to the Abstract! Here are the studies this week that glimpsed a bygone world, caught an 80-foot fish, outshone the stars, and declared scientific independence.

First, a mysterious group of extinct human relatives were probably not as advanced as once thought, a finding that sheds light on their possible lineage. Then: a gem from the paleontological lost-and-found, megaconstellations versus stellar constellations, and oh-say-can-you-see 250 years of American science history?

As always, for more of my work, check out my book First Contact: The Story of Our Obsession with Aliens, or subscribe to my personal newsletter the BeX Files

I do not doubt their hearts, just the reach of their arms

Veatch, E. Grace et al. ‘Taphonomic analysis at Liang Bua reveals the behavioral and technological capabilities of Homo floresiensis.” Science Advances.

A long time ago on a lush tropical island, a population of “hobbits” ventured into a cave to scavenge the kills of dragons. This is not a Tolkien tale—it’s the upshot of a new study about the short-statured human relative Homo floresiensis, which lived for more than a million years on the Indonesian island of Flores alongside Komodo dragons.

Colloquially known as hobbits for their short 3.5-foot stature, H. floresiensis arrived on Flores about 1.27 million years ago and vanished around the same time as the arrival of modern humans some 50,000 years ago. 

The hobbits have inspired much debate over their possible ancestry and whether they were capable of making fires or hunting big game, based on the discovery of charred and butchered bones of the extinct proboscidean (elephant relative) Stegodon in the expansive Liang Bua cave, which also contains many hobbit remains.

Now, researchers have cast doubt on the hobbits as hunters and fire-wielders, suggesting instead that they likely scavenged Stegodon carcasses that had already been killed by Komodo dragons. Though the hobbits left marks on the bones with butchering tools, the team concluded that they consumed the flesh raw. The charred remains, meanwhile, were likely left by late-arriving modern humans.

SOLVED: The Case of the Missing Megalodon
A facial reconstruction of Homo floresiensis. Image: Cicero Moraes et al

“Komodo dragons likely had primary access to these remains leaving behind only low-utility elements for H. floresiensis to scavenge,” said researchers led by E. Grace Veatch of the National Museum of Natural History, Smithsonian Institution. The team added that the bodily proportions of the hobbits are “unconducive for running and throwing that would make the act of hunting large game (in the traditional sense) quite difficult.” 

I guess these people have never seen Merry Brandybuck help take down the Witch-king of Angmar. In all seriousness, the study has implications for unraveling the mysterious lineage of these hobbits, as it may mean they descended from hominins that never achieved fire making or big-game hunting. 

The team noted that the elephant relatives may have been attracted to Liang Bua not just to “seek relief from heat and/or for sources of water, salt, and minerals” but as “a place to mourn deceased individuals.” Grieving proboscideans, halflings, and venomous dragons? It’s enough to make one a Middle Earth truther.

In other news…

SOLVED: The case of the missing megalodon

Shimada, Kenshu et al. Rediscovery of the associated gigantic vertebrae of the extinct megatooth shark, Otodus megalodon, from the Upper Miocene Gram Formation in Denmark, and comments on its paleobiological significance and the maximum possible size of the species” Palaeontologia Electronica. 

Ever misplace an important item like a wallet, or heirloom, or the backbone of an extinct giant shark? We’ve all been there. But scientists have good news on the latter front: a long-lost vertebrae of a Megalodon—the biggest shark in history and star of The Meg—has been rediscovered after it went missing in 1989 during a move between facilities.  

SOLVED: The Case of the Missing Megalodon
Dr. Mette Elstrup holding a 10.8-million-year-old vertebral fossil specimen of the extinct megatooth shark, Otodus megalodon, from the Gram Formation of Denmark featured in the new study, and a reconstructed O. megalodon jaw model in the background. Image: Museum of Southern Jutland, Denmark

“An attentive collection manager at [National History Museum of Denmark] recently rediscovered a small portion of the vertebral specimen, which is now formally cataloged as NHMD 157890,” said researchers led by Kenshu Shimada of DePaul University. “We report on the rediscovery of the specimen, which was thought to be lost.”

The resurfacing of NHMD 157890, which belonged to a Megalodon that lived nearly 11 million years ago, confirms that this animal could have grown as large as 80 feet, perhaps even bigger. 

The fossil measures nine inches across, making it “the largest shark vertebral specimen known to date, and quite possibly even the largest non-tetrapod vertebrae ever recorded.”

Once again, a killer shark has arrived just before the Fourth of July weekend. We’re lucky that, unlike the shark from Jaws, this Meg is very dead.

They can’t take the sky from you…oh wait nvm

Hainaut, O. R. “Large or bright satellite constellations Effects on observations, including background sky brightness.” Astronomy & Astrophysics.

The age of the Megalodon is over. The time of the megaconstellation has come. Space is rapidly becoming populated by these immense satellite networks, prompting astronomers to raise alarms about their impact on our view of the night sky. 

In a new study, a scientist warns that current plans to launch upward of 1.7 million satellites in the near future would “have a devastating impact on astronomical observations” because satellites “photo-bomb” images and also produce light pollution and radio interference. 

Of particular concern are extremely bright objects, such as the large orbital data centers proposed by SpaceX or the mirror-like satellites proposed by the startup Reflect Orbital, which aims to provide sunlight to Earth at nighttime. 

“A large constellation such as SpaceX’s Orbital Data Center…would place thousands of satellites above naked-eye visibility—comparable to the number of natural stars visible in a dark sky,” Hainaut said. “Reflect Orbital would produce more than 100 Venus-bright satellites by 2030 and over 1,000 by 2035…In light-polluted regions, one could effectively see only artificial satellites at night.”

“Beyond astronomy, they raise concerns about orbital crowding, space debris, and atmospheric pollution from launches and re-entries,” he added. What’s more, these megaconstellations also get in the way of traditional skywatching, a cross-cultural practice that dates back tens of thousands of years. Without regulatory measures on this infrastructure, the night sky that we’ve gazed upon for countless generations may have vanished within our lifetimes.  

The semiquin-science-tennial

Wellerstein, Alex et al. “American science at 250.” Science.

Cookouts. Fireworks. And 250 years of wild, spectacular, and frequently ill-advised science. If you’re looking for some Fourth of July brainfood, check out this week’s special issue of Science which reflects on America’s scientific legacy on this semiquincentennial.

“The scholars writing here do not shy away from grappling with paradoxes in US science history, confronting the complexities of six notable moments: the Manhattan Project, the unrecognized contributions of enslaved people to early agricultural knowledge, the rise of Silicon Valley, the advent of biotechnology, the eugenics movement, and the space program,” said Valerie Thompson, the books and culture editor of Science

“In doing so, they invite science lovers, critics, and everyone in between to contemplate the past and future of the US scientific enterprise and related questions about democracy, representation, and state support for research.”

Happy contemplating! See you next week.


Behance Featured Projects

The latest projects featured on the Behance

CareDx Illustration System


For CareDX, a California-based biotechnology and precision medicine company leading the field of transplant care, we developed a flexible illustration system based on continuous line drawings. Commissioned by Mucho and created together with our friends and talented partners at Familia, the system translates the brand's commitment to transplant care into a warm, human and consistent visual language.