The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Stretch, be gentle and build flexibility: expert tips on doing the splits

Doing a split may look impressive, but experts caution it should not be done without practice and it may not be for everyone

On Love Island USA’s recent eighth season, contestant Kenzie Annis quickly distinguished herself with her ability to perform the splits, abruptly deploying the maneuver in fits of both delight and rage.

Seeing the splits on TV shows such as Love Island and RuPaul’s Drag Race can make people “want to take on that challenge and to push themselves to new heights”, said Ramoni Overton, a yoga instructor and YouTuber based in Los Angeles.

Continue reading...

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Philips to replace bricked Hue Bridge Pro devices

Philips is replacing Hue Bridge Pro devices after a software update left several units bricked with no way for users to restore them. Rumblings began in forums in June after a seemingly innocuous update left users, quite literally, in the dark. After a few weeks attempting to resolve the issues, Philips has thrown in the towel and said it will replace affected devices. A spokesperson told The Register, "We have identified a firmware issue affecting a limited number of Philips Hue Bridge Pro devices under a very specific software update scenario. Our data shows that fewer than 100 devices have been impacted." As for the problem itself, "The issue can occur when a Bridge Pro with automatic software updates disabled has remained on an older software version for an extended period, and a software update is then manually installed under a specific set of conditions. "In affected cases, the Bridge Pro can become inoperable and display a red LED, resulting in a loss of connectivity with the Philips Hue app and connected devices." The spokesperson told us that affected users should contact the company's customer support: "All Bridge Pro devices confirmed to have been impacted by this specific issue will be replaced free of charge, regardless of warranty status." Which is great, except that if you have to set up a network of lights and devices again from scratch, that's a substantial amount of work. Backing up a configuration isn't an option at the moment. The Hue Bridge Pro is a hub for the Philips Hue lighting system. It can support more than 150 lights and over 50 accessories. According to Philips, "Equipped with a new chip capable of running complex algorithms and AI-powered features, it's faster and stronger than ever." Except, it appears, when Philips emits an update that bricks some of them. The incident highlights the risks associated with smart homes and their devices. Support could be abruptly pulled, the device's origin might not be what you expect, or, as in the case of the Philips Hue Bridge Pro, a firmware update could leave a device hopelessly bricked. Philips should be commended for its replacement plan, particularly when a device is out of warranty, although questions remain about its validation and qualification procedures. As for the device itself, Philips released an update on Monday to address the issue (where devices haven't been bricked) and urged users to enable automatic updates to receive the firmware update as it rolls out. ®

EU and UK officially blame Russian spies for cyberattack on Poland's power grid

The UK and EU are demanding urgent action from critical infrastructure organizations after formally attributing the December 2025 cyberattack on Poland's power grid to Russia's Federal Security Service. The Foreign, Commonwealth & Development Office (FCDO) described the attack, carried out by the FSB's Centre 16 division, as "another example of the Russian state's irresponsible attempts to sow chaos across Europe." Milosz Motyka, Poland's energy minister, confirmed the attack on the country's power grid in January. He said experts suspected that whoever was behind it attempted to disrupt communication between renewable hardware and power distribution operators. The attack was ultimately unsuccessful, but suspicion quickly fell on Russia. Attackers tried to deploy the destructive DynoWiper malware, a move typically associated with Russian state-backed operations. Mandiant previously tied the 2023 blackouts in Ukraine to Sandworm's deployment of CaddyWiper malware, while the NCSC and its allies fingered the same military intelligence unit for the 2022 WhisperGate wiper attacks at the start of Russia's invasion. As The Register reported at the time, the FCDO said the attack in Poland could have left half a million Poles without power in midwinter – a cyberattack with potentially lethal consequences. We asked the NCSC to provide more information about what evidence allowed it to attribute the Poland energy attack to Russia's FSB, but it declined to comment on operational matters. Time to act The UK NCSC co-authored a technical advisory, published Monday, which highlights the latest developments in Russia's tradecraft, urging those most at risk to apply the recommended mitigations. It said organizations in the following sectors are most at risk from Centre 16 cyberattacks: communications, defense industrial base, energy, financial services, government services and facilities (especially organizations at the state and local level), and healthcare and public health. The headline mitigation recommended by the intelligence agencies is to disable SNMPv1 and SNMPv2, opting instead for SNMPv3 with authPriv, which comes with strong authentication and data encryption, and to disable Cisco Smart Install on all devices. Centre 16's common tactics involve scanning for devices that respond with SNMPv1/2. These support default or easily guessed community strings, which are commonly abused to gain access to network devices such as routers – a technique the NCSC and others issued separate warnings about in April. Attackers can abuse SNMP access to obtain device configuration data and transfer it to a server under their control, which can later facilitate persistent access. Although SNMP scanning is the principal tactic described, the advisory also covers the exploitation of Cisco devices, including those with Smart Install enabled. Defenders examining the document will notice overlapping tactics, techniques, and procedures (TTPs) between Centre 16 and other Russia-aligned threat groups, the intelligence partners wrote. Jonathon Ellison, director of national resilience at the NCSC, said: "The NCSC, alongside our international partners, have repeatedly exposed the advanced tools and coordinated campaigns of Russian cyber actors who persistently seek to exploit any vulnerability they encounter. "Today's joint advisory provides decisive, actionable directions from the global security community that network defenders should implement to protect against Russian Intelligence operations and secure the UK's critical infrastructure. "I'd strongly encourage all organisations, especially those entrusted with UK critical networks, to adopt these recommended measures immediately, thereby reducing the risk of compromise." Fresh sanctions The UK and EU have each added an array of Russian individuals and entities to their sanctions lists, including GRU officials, cybercriminals, and hacktivists. Members of pro-Kremlin outlet Rybar also makes an appearance, owing to its false narratives about Ukraine and alleged interference with European elections. The most high-profile designations concern Vyacheslav Stafeyev, Ivan Senin, and Ivan Kasyanenko – three GRU leaders accused of orchestrating cyber and hybrid operations. They also allegedly worked with cybercriminals and a company called IMPULS with a view to recruit cybersecurity specialists from universities and academies across Russia. UK Foreign Secretary Yvette Cooper said: "These sanctions strike at the core of the cybercriminal networks propping up the Russian state's aggression, and the UK and EU are sending a clear message that Russia cannot hide behind its use of these proxy groups.  "From directing criminals to targeting businesses, and striking Poland's energy grid in the depths of winter, the Russian state is sinking to new lows in its attempts to undermine European security. "Together with our partners, Britain will continue to call out this behaviour, bolster our resilience and respond to the hybrid threat posed by the Russian state. This will not deter us from supporting Ukraine." Sanctions were also imposed against three individuals accused of being operators of Lumma Stealer, one of the major infostealer malware strains that play a significant role in the cybercrime economy. National Crime Agency data suggests that in the UK alone, at least 2,100 victims were identified as infected over six months. The UK confirmed that the Russian state has used Lumma Stealer to gather stolen credentials and launch cyberespionage operations against global targets. The 24 sanctions unveiled on Monday add to the 3,400-plus individuals and entities that have been designated for their roles in supporting Russia's war efforts. Don't forget those cameras The coordinated international warnings and sanctions come days after Dutch authorities issued their own alert about Russian espionage units targeting internet-connected cameras to gather intelligence about military logistics routes. Its separate advisory warned that at least one Russian intelligence unit carries out operations targeting the Netherlands and other NATO members, using IP camera footage to track military logistics routes and the transport of materiel, and to map infrastructure such as bridges and roads. Dutch intelligence services added that Russia uses image recognition software to detect military vehicles, transport routes, shipments to Ukraine, and locations of Ukrainian soldiers. The advisory went on to say that Dutch intelligence suggests Russia's use of compromised IP cameras and their imagery has systematically increased recently and become a normal part of its tradecraft. It said abusing default passwords was the most common way in which Russian spies were gaining access to the cameras, although the most recent security updates were rarely applied, opening up vulnerabilities to exploit when using guessable passwords doesn't work. ®

The Moscow Times - Independent News From Russia

The Moscow Times offers everything you need to know about Russia: Breaking news, top stories, business, analysis, opinion, multimedia

Russia Summons German Ambassador, Accuses Berlin of Supporting Ukrainian Attacks

The Russian Foreign Ministry also criticized Germany's stance toward third countries' relations with Russia, including Russia-China ties.

In the North Caucasus, a Constitutional Reform Reopens Centuries-Old Wounds

Civil society actors in Kabardino-Balkaria and members of the Circassian diaspora believe the changes would further erode the republic’s autonomy.

VEILIGHEIDSRISICOGEBIED rond aanmeldcentrum Ter Apel

Jeetjemineetje, u raadt nooit waar het een totale bende is. Juist, bij het COA-aanmeldcentrum in Ter Apel, waar alles wat VLUCHT VOOR OORLOG EN GEWELD ons land binnenstroomt. Dat wisten we natuurlijk al lang en dat wist bijvoorbeeld ook het Rode Kruis, voor wie de agressieve sfeer (afkomstig van: 'een groepje mannen') zo akelig werd dat ze de benen namen. Zelfs de poeslieve reporters van de NOS werd het aardig heet onder de voeten dus dan kun je spreken van een aanzienlijk probleem. Het land aanmeldcentrum is druk voller dan vol en alles wat niet naar binnen kan zorgt buiten voor totale mayhem, dus neemt het kabinet nu een extra maatregel in de vorm van een veiligheidsrisicogebied. Asielzoekers worden voor het aanmeldcentrum preventief gefouilleerd en vervolgens worden ze teruggestuurd naar een ander pand gebracht om hun aanmelding af te wachten. Als ze binnen eenmaal overlast veroorzaken moeten ze permanent buiten blijven. Poeh poeh. Probleem opgelost verplaatst!

Social

Vijf plekken om deze zomer te bezoeken met de trein

Nog op zoek naar een inspiratie voor je stedentrip? NRC vroeg tips aan locals voor bestemmingen die binnen een dag met de trein te bereiken zijn.


Herschrijft Meloni de Italiaanse kieswet om aan de macht te blijven? ‘Ze zet in op winst of verlies, en niks daar tussenin’

Volgens de Italiaanse oppositie wil premier Giorgia Meloni het kiesstelsel aanpassen omdat ze bang is anders de volgende verkiezingen te verliezen. De premier zelf zegt dat het haar louter te doen is om stabiel bestuur.

Nederland roept Russische ambassadeur op het matje om cyberaanvallen

Nederland en andere Europese landen beschuldigen Rusland ervan dat het met cyberaanvallen overheidsnetwerken en kritieke infrastructuur heeft binnengedrongen en gesaboteerd. Eerder maandag ontboden ook Frankrijk, Duitsland en het Verenigd Koninkrijk hun Russische ambassadeurs om de kwestie.

kottke.org

Jason Kottke's weblog, home of fine hypertext products

A list of the new foods on offer at the Minnesota State...

A list of the new foods on offer at the Minnesota State Fair this year. They’re all some variation of “jerked pork rolled in butter & sugar, deep fried in dill pickle batter, and served with a side of cheese curd mayo”; I’d happily try any of them.