Self Portrait

Thomas Hawk posted a photo:

Self Portrait

And I Will Try and Be Kind When I Ask You to Leave

Thomas Hawk posted a photo:

And I Will Try and Be Kind When I Ask You to Leave

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Deported Milo Yiannopoulos says he is ‘ashamed’ of support for Trump

British far-right pundit breaks silence on ICE arrest and deportation and says he was ‘really, really terrified’

Milo Yiannopoulos, the British far-right commentator who was arrested last week by Immigration and Customs Enforcement (ICE) officers in Louisiana and deported to the United Kingdom, has broken his silence about the experience, saying that “for the first time I know what it feels like to be really, really terrified”.

Yiannopoulos on Tuesday appeared on Piers Morgan Uncensored, a YouTube show presented by Piers Morgan, the British broadcaster and media personality. Yiannopoulos, 41, described the experience in the US as “humiliating and disorientating”, “physically degrading” and “frightening”.

Continue reading...

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks

AI model testing organization METR has disclosed two attacks that happened earlier this year, including one in which an attacker stole an API key and spent three weeks consuming public-model credits worth about $600,000. METR (short for Model Evaluation and Threat Research) found no evidence that the attackers accessed sensitive information in either incident, and the org said it investigated both with security experts. METR researchers worked with OpenAI to investigate how its agents hacked Hugging Face, and on Monday, it disclosed two of its own security snafus. “In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits,” the nonprofit disclosed in a Monday report. “In May 2026, we observed attackers systematically probing our publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint.” From fail-open bug to model-credit theft The March incident involved a METR researcher who didn’t have access to sensitive information - including model data and credentials, as well as information about model architectures, training, and release dates. The researcher used agents running on a personal EC2 instance that was “intentionally” left publicly accessible behind Google authentication. The instance contained an API key for METR’s public models account. According to METR’s account, a “vibe-coded app” included a fail-open bug that disabled authentication, and this exposed the system to the public internet for several days. “We suspect that the attacker found the instance by looking through recently-registered websites (e.g. in certificate transparency lists) to find vibe-coded sites with high-signal keywords relating to LLMs or agents, for purposes of harvesting potentially exposed model provider API keys,” the AI research org wrote. Once the attacker found the app, they prompted an agent to reveal its model provider API key, then added an SSH key to maintain persistent access, and over the next three weeks used the stolen credentials to consume API credits on public models worth about $600,000. Luckily for METR, the unnamed model developer had given the credits to the nonprofit for free. How do you not notice the 'large illicit usage?' METR does answer the question on everyone’s mind in the report: Why its researchers didn’t notice the “large illicit usage?” There are several reasons for this. First, the model testing operation regularly runs evaluations that use a lot of tokens, and this means the organization is “very acclimated to getting lots of weird rate limit and API errors.” So the high usage didn’t look that out of the ordinary. Plus, since the tokens were free, METR didn’t accrue a large bill, and at the time there was no way to put a spending limit on keys like the one that was stolen. In response to the March incident, METR says it improved its security infrastructure, protocols, and review process, and will continue to invest in security. To this end, it also hired a security lead, and plans to add more security staff. Crims used agents to try to access frontier models The second incident happened in early May, when “METR became the target of a sustained external attack campaign.” After being “tipped off” that attackers who appeared financially motivated may have been trying to gain illicit access to frontier models, METR watched the intruders probe its publicly accessible infrastructure. They also used agents to find ways to gain initial access, including automated vulnerability discovery, credential stuffing against authentication providers, attempting OAuth token grants, scanning newly deployed services, and phishing attempts. At the same time, METR unintentionally “exposed a read-only SQL query mechanism via our public transcript viewer.” While queries were scoped to public data by default, a bug allowed access to unpublished evaluation data, and “some sensitive model data was accidentally included in this database.” However, there’s no evidence that the attacker found the exploit or accessed any non-public data, according to the model testing body. An independent bug hunter discovered the vulnerability and reported it to METR, which paid the researcher a bounty, and took the API offline. In response, METR says it now uses an isolated production environment for public-facing applications that is separate from its internal infrastructure.®

Firefox helps iPhone users bypass ads on web sites while making money showing its own ads

After several weeks of anticipation, Mozilla has started rolling out ad blocking to the iOS version of its popular browser, but you can still expect to see ads on Mozilla's own pages, including the new tab page. The org officially rolled out the new native ad blocking feature for iOS Firefox on Tuesday, moving it out of the experimental phase, while explaining that it had to rethink its desire to give users control over their web experience on iOS due to differences in architecture between it and other OSes. “Firefox already supports a strong ecosystem of ad-blocking and privacy extensions,” Mozilla explained. iOS works differently, though, as Apple forces all web browsers on iOS to use its own WebKit to render sites instead of their own preferred back end. “Bringing ad blocking to Firefox on iOS,” therefore, “meant building it directly into the browser,” Mozilla explained. Implementing ad blocking in the iOS version of Firefox meant incorporating Apple’s own WebKit Content Blockers. According to Apple’s introduction on the topic, it specifically doesn’t want app extensions to be used to block web content because of how they operate. “App extensions … are essentially little sandboxed applications that are launched on demand to extend some specific piece of functionality,” Apple notes. “JavaScript-based content blocking extensions … have significant performance drawbacks.” Apple complains that traditional ad blockers use too much energy, increase page load time, and eat up memory, all of which it wants to protect iOS users from. Apple describes WebKit Content Blocking as “describing content blocking rules in a structured format ahead-of-time, declaratively.” Apple Web Content Blockers instead live in bytecode format that executes for each resource request, modifying requests or injecting CSS changes as needed while pages are loaded. For Mozilla, that basically means dropping the EasyList filter, originally designed for the classic Adblock blocker, into a JSON file and passing it to WebKit. Easy peasy. Ad blocking in Firefox for iOS is off by default. Turning it on, if it’s available for you – it’s rolling out gradually – is as easy as opening the in-app settings menu, tapping on Browsing, and toggling the Ad Blocker field on. Mozilla told The Register in an email that it doesn't have a timeline for general release to all Firefox users on iOS, which it said will largely depend on how well the initial rollout goes. You also have to turn Remote Improvements on, as the feature allows Mozilla to push fixes and feature changes to Firefox between full releases. Toggling that on has traditionally meant you also had to allow Mozilla to collect browser telemetry, but that was changed in February when Firefox 148 was released and the two features have officially been decoupled. Once on, iOS Firefox Adblocking will take care of ad-related trackers, ads from third-party advertising networks, third-party ads served by websites, and popups/overlays. What it won’t do, however, is take care of ads on search result pages or sponsored content on Firefox’s home or new tab page – after all, you wouldn’t want Mozilla to lose those precious ad bucks, would you? Firefox iOS ad blocking also won’t eliminate ads served directly by websites, and the company warns that it still might not work in all places, which is pretty common for ad blockers. For Firefox users who want browser consistency across platforms, it’s likely a welcomed announcement, though it begs the question whether Mozilla is considering integrating its own ad blocking technology in the desktop or Android versions of its browser. Fortunately for those making ad-blocking extensions, and those who love them, Mozilla says it has no plans to expand built-in adblocking outside iOS. "We value that ecosystem and will continue to support it," Mozilla told us. ®

Colossal

The best of art, craft, and visual culture since 2010.

Playful Patterns Adorn Ashley Percival’s Collections of Creatures

Playful Patterns Adorn Ashley Percival’s Collections of Creatures

In Ashley Percival’s world, a leopard can, in fact, change its spots. The Cornwall-based illustrator is behind a fanciful menagerie in which poodles, rotund birds, and boot-wearing insects try on a vast array of vibrant costumes. Using a mix of colored pencil, pen, paint, and digital tools, he dreams up cheeky patterns and palettes for common animals, presenting collections of the same species in endlessly alluring grids.

Percival recently spent three months in Spain and France immersed in nature, which inspired his latest flocks of birds. “I don’t think about the colors I use. It’s all free flow. I sometimes look at an animal once to get an idea and then draw from my imagination,” he tells Colossal.

In addition to his personal projects, Percival frequently collaborates with brands like Ikea and Gucci, among others. Follow his work on Instagram and purchase prints on Etsy.

an illustration by ashley percival of a collection of poodles made of colorful patterns
an illustration by ashley percival of a collection of owls made of colorful patterns
an illustration by ashley percival of a colorful patterned butterfly
an illustration by ashley percival of a collection of poodles made of colorful patterns
an illustration by ashley percival of a colorful patterned cat in front of mushrooms
an illustration by ashley percival of a collection of insects made of colorful patterns
an illustration by ashley percival of a colorful patterned cat in front of blue flowers
an illustration by ashley percival of three owls made of colorful patterns

Do stories and artists like this matter to you? Become a Colossal Member today and support independent arts publishing for as little as $7 per month. The article Playful Patterns Adorn Ashley Percival’s Collections of Creatures appeared first on Colossal.

kottke.org

Jason Kottke's weblog, home of fine hypertext products

2 Odysseus 2 Ithaca: Emily Wilson is completely...

2 Odysseus 2 Ithaca: Emily Wilson is completely retranslating The Odyssey. “It’s a complete retranslation. It’s not a revision of the old version.” This is the exact opposite of resting on one’s laurels.

Wel.nl

Minder lezen, Meer weten.

Zelensky waarschuwt luchtvaart dat Russisch luchtruim onveilig is

KYIV (ANP/AFP) - De Oekraïense president Volodymyr Zelensky heeft luchtvaartmaatschappijen en passagiers gewaarschuwd dat het Russische luchtruim "totaal onveilig" is zolang de oorlog voortduurt. Volgens hem is dat geen dreigement, maar een vaststelling.

"Oekraïne bedreigt geen enkel civiel luchtvaartuig", zei hij in zijn dagelijkse toespraak. "Er zullen in het Russische luchtruim gewoon drones vliegen op een schaal waarmee rekening moet worden gehouden."

Oekraïne en Rusland hebben de afgelopen weken hun luchtaanvallen opgevoerd. Zelensky zegt niet te willen dat dat ten koste gaat van burgerlevens. "Daarom waarschuwen we onze partners: de veilige dagen in de Russische lucht zijn voorbij."

In 2014 werd in het oosten van Oekraïne het passagiersvliegtuig MH17 uit de lucht geschoten. Daarbij kwamen 298 mensen om, onder wie 196 Nederlanders. Rusland is door het Europees Hof voor de Rechten van de Mens (EHRM) aangewezen als verantwoordelijke voor die ramp.


Europese gasprijs op hoogste niveau sinds 2023

AMSTERDAM (ANP/BLOOMBERG) - De Europese gasprijs is tot het hoogste niveau sinds 2023 gestegen. Op energiemarkten reageren handelaren op de toegenomen spanningen tussen Iran en de Verenigde Staten. Nieuwe gevechten hebben een einde gemaakt aan de hoop op een snelle opening van de Straat van Hormuz, een zeestraat die erg belangrijk is voor de wereldhandel in energie.

Termijncontracten van een maand voor de levering van een megawattuur aan gas stegen op de Nederlandse virtuele handelsplaats TTF rond 21.30 uur zo'n 6 procent tot 74 euro. Deze gasprijs geldt als maatstaf voor de aardgasprijzen in Europa.

De VS meldden dinsdag aanvallen op Iraanse doelen. Dat was volgens de Amerikaanse strijdkrachten een reactie op Iraanse aanvallen op schepen in de Straat van Hormuz. De blokkade van die zeestraat door Iran heeft al sinds het begin van de Iranoorlog grote invloed op de gasprijs, omdat Golfstaten er ook veel vloeibaar gemaakt aardgas door vervoeren.


thexiffy

Last.fm last recent tracks from thexiffy.

Vive La Fête - Petite Putain

Vive La Fête