The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Jess Cartner-Morley on fashion: forget delicate chains – this summer, make your jewellery big and bold

Fashion is getting braver with accessories again, so lean into it by embracing loud earrings and chunky pendants

This summer, I want jewellery that makes some noise. Real noise – earrings that swish, bangles that clatter – and visual noise as well. Stuff to wear when you want to be seen and heard. The total opposite, in other words, of the jewellery most of us have been wearing lately. Charming, delicate jewellery has become the default. Two necklaces of different lengths on fine chains. One has a heart pendant, the other an initial or a birth stone, am I right? Maybe a curated earlobe of tastefully small mismatched diamond hoops.

There is absolutely nothing wrong with this look. It is really nice. In fact, this is exactly the problem.

Continue reading...

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

LegacyHive: 'Bone-shattering' zero-day from Microsoft's serial tormentor not the haymaker that was promised

Microsoft’s worst nightmare - a prolific zero-day vulnerability hunter who calls themselves Nightmare Eclipse - published yet another zero-day on Tuesday, a vulnerability allowing attackers to mount user hives, including partial exploit code. Suspected of being a disgruntled former Microsoft engineer, based on the sophistication of their prior vulnerabilities, NightmareEclipse came good on their promise to release another zero-day on July 14. Whether it lives up to the promised “bone-shattering” standard touted in June is up for debate, however. Called “LegacyHive,” the proof of concept (PoC) code for the zero-day local privilege escalation (LPE) vulnerability targets Windows’ user hives - the section of the Windows Registry that stores a user's specific desktop settings, application preferences, and environment configurations. The code exploits a weakness in profsvc, the Windows User Profile Service, and the way in which it loads hives. If exploited correctly it could grant regular users privileged read-write access to target other users' hives. Matei Badanoiu, lead security researcher at Pentest-Tools.com, said that while the exploit could prove useful for attackers who had already gained a foothold in a target environment, it falls short of providing a fuller system compromise. “What caught my attention is the difference between what the public proof of concept actually demonstrates and what a full compromise would require,” he told The Register. “LegacyHive is a local privilege escalation in the Windows User Profile Service. It abuses arbitrary registry hive loading, so a standard user can mount another user’s hive, including an administrator’s, into their own classes root. “For an attacker who already has a foothold, that is a genuinely useful primitive. Bundling it with credential access and persistence into ‘full compromise’ is more of an ambition than the released code.” The LegacyHive publication differs from some of NightmareEclipse’s earlier drops in that the PoC code is stripped back in an effort to prevent widespread exploitation. According to the bug hunter, there is more than one way of exploiting the profsvc flaw. The public PoC requires additional user credentials for it to work, and is limited to the usrclass.dat hive. NightmareEclipse said the original PoC, which differs from the one they published, does not require additional user credentials to exploit the bug, and it works beyond the usrclass.dat hive, “but you would need some brain cells to make the PoC do it.” This represents a divergence from NightmareEclipse’s previous approaches. As Badanoiu pointed out to us, some of NightmareEclipse’s earlier drops, such as BlueHammer and RedSun, went from PoC to widespread exploitation within days. LegacyHive, however, comes without a fully working PoC and a CVE identifier. Regardless, security experts told The Register that cyber practitioners should respond promptly since capable attackers could probably build a reliable exploit, despite the gaps left in the PoC by NightmareEclipse. “Threat intelligence teams are advised to act with some urgency here,” said Dray Agha, senior manager of security operations at Huntress. “Huntress observed NightmareEclipse's prior LPE and defence evasion tools rapidly deployed threat actors and ransomware groups shortly after publication. “Given this history, we’d expect that capable actors will reverse-engineer the missing components of the LegacyHive PoC to build fully weaponized versions in short order.” The timing NightmareEclipse may have changed their approach to releasing full working PoCs to the public, perhaps a reflection of Microsoft’s suggestion of preparing legal action against the bug hunter, but the nuisance timing of the vulnerability disclosures remains. They dropped the details for LegacyHive shortly after Microsoft released its monthly Patch Tuesday updates, which contained an unprecedented 622 fixes. Agha said timing the disclosure in this way maximizes the exposure window before a patch can be developed, causing more trouble for Microsoft. The Register asked the Windows-maker about LegacyHive and whether it was planning to release a fix before August’s patches, but it did not immediately respond. NightmareEclipse claims their latest zero-day works against Windows machines that are fully patched according to July’s fixes. Microsoft previously issued a quiet remedy for one of NightmareEclipse’s earlier zero-days, RoguePlanet, last week, although the company did not go into any details about what the mitigation entailed. ®

Nog veel onzekerheid rondom halftime show WK: overtreedt de FIFA de eigen voetbalregels?

Voor het eerst in de geschiedenis van het WK voetbal zal er tijdens de finale een halftime show plaatsvinden.

Wat ik heb geleerd van zes jaar columns schrijven

Anders dan in Turkije zit het in Nederland wel goed met de vrijheid van meningsuiting. Maar deze vrijheid komt niet zonder verantwoordelijkheid, schrijft Aylin Bilic. Dit is haar laatste column voor NRC.

Break the Cycle

Darren Schiller has added a photo to the pool:

Break the Cycle

Young Street, Parkside, South Australia

Fences to Mend

Darren Schiller has added a photo to the pool:

Fences to Mend

Young Street, Parkside, South Australia

Fixer Upper

Darren Schiller has added a photo to the pool:

Fixer Upper

Young Street, Parkside, South Australia

NASA’s Webb Discovers Hidden Planet in Famous Star System

James Webb Space Telescope posted a photo:

NASA’s Webb Discovers Hidden Planet in Famous Star System

Wake up, babe! There’s a new planet around Beta Pictoris!

Webb spotted a new giant planet hiding in one of the most studied planetary systems in our galaxy. Beta Pictoris is a young nearby star, with two known planets, one of them (“b”) being one of the first exoplanets ever directly imaged. The new planet (“d”) was discovered not by identifying a bright point of light - but by detecting its unique atmospheric chemical fingerprint.

Beta Pic d is likely twice the mass of Jupiter, and the smallest of the three known giant planets in this system. It orbits at a distance of about 30 astronomical units, putting it somewhere around where Neptune is located in our own system.

Astronomers found Beta Pic d while studying the atmosphere of Beta Pic b with Webb’s Near-Infrared Spectrograph. NIRSpec has a special mode (using something called an Integral Field Unit) that returns not only spectral data but spatial data. This can give us an image of the object being studied and also allow us to map motion. An unexpected blob was spotted in the IFU imaging - with the distinctive signature of carbon monoxide. Astronomers were able to figure out the object’s speed, position, and alignment with the debris disk of the star, making it clear that this object was orbiting Beta Pic and not just something in the background.

Why wasn’t this found sooner? Beta Pic’s debris disk is really bright and scatters light from the star, making it hard to tell planets from other structures. Webb effectively ignored the dust and was able to hone in on the signature of the planet.

The researchers plan to continue analyzing Webb's observations to better determine the planet's temperature, atmospheric composition, and orbit, providing an even more detailed view of one of astronomy's most iconic planetary systems.

Read more: science.nasa.gov/missions/webb/nasas-webb-discovers-hidde...

Artist Concept Credit: Illustration: NASA, ESA, CSA, STScI, Ralf Crawford (STScI)

Image Description: Artist's concept of the Beta Pictoris planetary system. One edge of a smooth, dusty disk that looks like cloud wisps extends across the upper third of the image at an angle from 9 o’clock to 2 o’clock. Just below that, in the left third of the image, the star glows white and is small. Just to the left of the star there is a tiny white dot, planet Beta Pictoris c. To the right of the star, about twice the distance between Beta Pictoris c and the star is another bright dot, representing planet Beta Pictoris b. A third planet, Beta Pictoris d is larger than the other two, and appears in the right third of the illustration. The planet has subtle orange cloud bands, and the side facing the star is illuminated. Below this planet, the other wispy edge of the dusty disk that circles the star crosses the bottom right corner of the illustration below Beta Pictoris d from 4 o’clock to 7 o’clock. The black background of space is speckled with distant stars. The words "Artist's Concept" appears at the lower left corner.

Syrische asielzoeker mishandelt vrouwen in Harderwijk, is niet langer welkom in Harderwijk

Kijk zo werken OPLOSSINGEN in Nederland. Een negentienjarige Syriër mishandelt drie personen, onder wie twee vrouwen, in Harderwijk. Knakker zit in het azc Harderwijk dat al dicht had moeten zijn maar niet dicht kan, omdat de VVD de poort van Pamperpark Nederland wagenwijd open laat staan. De gemeente heeft nu kei-hard ingegrepen tegen die agressyriër: meneer heeft een 'locatieverbod' gekregen. "Hij is niet meer welkom in het azc in Harderwijk." Zo zijn ze in Harderwijk mooi van 'm af en hebben ze elders in Nederland last van deze lul. Wij stempelen 'm af: PROBLEM SOLVED!

De Speld

Uw vaste prik voor betrouwbaar nieuws.

Trump dreigt Noord-Atlantische Oceaan af te sluiten als NAVO niet helpt bij Iran

​Een week na de NAVO-top in Ankara haalt de Amerikaanse president Donald Trump opnieuw hard uit: als de NAVO niet zal helpen bij de oorlog met Iran, dreigt hij de Noord-Atlantische Oceaan af te sluiten.

“Als je goed kijkt, zie je dat er tussen de NAVO-landen en de Verenigde Staten een cruciale doorgang ligt van zo’n 76 miljoen vierkante kilometer”, schrijft Trump op TruthSocial. “De spatader van de wereldeconomie.”

Trump geeft aan dat als de NAVO de Verenigde Staten niet snel steunt bij aanvallen op Iran, hij zich genoodzaakt voelt om deze tactisch gelegen oceaan af te sluiten. “Ieder schip dat deze doorgang zal nemen, zal worden geblokkeerd. De Noord-Atlantische Oceaan is binnenkort volledig dicht.”

Trump overweegt nog wel enkele schepen door te laten, in ruil voor een tol van 20 procent van alle vervoerde lading.

&