Eyelashes and Mustaches

kiri-fuda has added a photo to the pool:

Eyelashes and Mustaches

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Security through obscurity is dead, and AI delivered the fatal blow

The term "security through obscurity" describes an old idea that networks and systems will remain secure so long as their architecture, along with any vulnerabilities or other weaknesses, remains secret or hidden. It was never a sound strategy for protecting sensitive assets and systems, but many organizations leaned on it due to lack of resources or complacency. Now it’s obsolete. Don’t believe us? Here’s proof. Software vendors and independent researchers alike are now using AI agents to find bugs – some very obscure and decades old – across products and open source code, leading to record-breaking numbers of security disclosures and patches, and a massive backlog for project maintainers. “You see open source platforms that have been visible to the tech community for a decade, these libraries that are run in 80 percent of web servers out there, people have stress-tested those for 10 years, and the community believed that they were really secure,” Brett Leatherman, assistant director of the FBI's Cyber Division, told The Register. “The latest models were able to break those and say, ‘yeah, there’s significant vulnerabilities in here.’” Whether or not security through obscurity is dead “isn't even an opinion question,” Trend Micro’s Zero Day Initiative chief bug hunter Dustin Childs told The Register, the day after Microsoft’s record-breaking Patch Tuesday addressed 974 CVEs. “When you look at all of the components patched by Adobe and Microsoft yesterday, you see components no one has talked about in years,” Childs said. “Telnet client – is this even still used in any secure environment? Windows RNDIS – the USB-networking protocol Microsoft has been trying to deprecate for years. NFS Portmapper – 1980s Unix tech. And Link Layer Topology Discovery – the Vista-era network-map protocol nobody's thought about since Vista – just to name a few.” Meanwhile, attackers are also using AI to reverse-engineer fixes and find exploits within hours. In one recent case, at least four espionage crews, most suspected of links to China, slammed shut the “patch-gap” window for open source Chromium, using an exploit kit developed shortly after the maintainers released an upstream patch – but before the downstream stable release was pushed to users. What this means for OT security During interviews at Black Hat in August, both former US National Cyber Director Chris Inglis and John Hultquist, chief analyst at Google Threat Intelligence Group, told us that they worry about what this means for critical operational technologies and industrial control systems (ICS). These are the systems that ensure the lights turn on when people flip a switch, gas flows out of pumps, and safe drinking water pours from faucets – all critical services that people use daily, and assume will continue working reliably. The OT systems themselves often use obscure protocols and proprietary hardware and software, which historically made them black boxes, even to IT specialists and hackers. AI upended this assumption. It means that criminals don't need to be OT experts to carry out destructive cyberattacks on critical networks and facilities. They just have to ask an agent to learn everything about these systems and do the dirty work for them. A couple of weeks after Black Hat, five US agencies said that attackers used AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities. “This is not a theoretical risk – it is an active threat,” the feds warned. AI “is excellent at technical troubleshooting, at knowing obscure systems and helping you make your way through it, and this makes me very concerned about industrial control systems,” Hultquist told The Register in an interview last week. “They've been largely secured because the expertise was in a handful of people's heads, and that's not going to last forever,” he said. AI can be a useful guide for attackers studying not just the application layer, but also the operating system, and even down into the firmware, Hultquist added. “That's going to have implications for a lot of different areas of security, but definitely for industrial control systems.” However, while this undoubtedly means more work for sysadmins and defenders, burying this outdated idea of security through obscurity isn’t necessarily a bad thing. 'Never a winning strategy' “I've always been of the mind that security through obscurity was never a winning strategy,” Katie Moussouris, founder and CEO of bug bounty consultancy Luta Security and the fairy godmother of bug bounties, told The Register. “But that's because I've been a hacker for so long. The argument always fails in the face of someone who decides to turn their gaze towards your organization. If there is something to find, they will find it.” Plus, she added, AI makes hacking a whole lot easier. “People might not have familiarity with the particular tech stack that you're running, but that is no longer a barrier because AI has ingested everything, and an AI is going to help them enumerate weak spots, even if they themselves are not familiar with the particular tech stack that they are pointing an AI towards,” Moussouris said. However, finding bugs and other weaknesses has never been the big security problem, she added. “It’s triaging and prioritization and actually getting things fixed.” This, Moussouris said, has also been her biggest issue with the way that organizations implement bug bounty programs. “AI is shining that bright light on the wrong end of the security picture, and unfortunately, AI hasn't caught up on the defensive side,” Moussouris said. “We're not there with AI automated patching, remediation – anything of the sort.” A couple of recent studies back this up, both finding that AI-generated patches fail more than half of the time. 1Password’s research team took six CVEs disclosed since March, and produced 6,080 patches using two frontier models: OpenAI's ChatGPT-5.5 and Anthropic's Opus 4.8. “The average success rate for generating a patch that fully resolved the vulnerability (without materially changing application behavior) was just 26.0 percent,” wrote Director of Security Research Keith Hoodlet, adding that even patches that did fix the flaw also mucked up the application’s behavior 20 percent of the time. This included things like changing “allow list” logic to “deny list” logic. “Conversely, LLM-generated patches did not resolve the vulnerability, added a new vulnerability, or both, an average 53.9% of the time,” Hoodlet said. Another study by app security shop Veracode found that, across more than 100 models and 80 coding tasks, the average security pass rate for AI-generated code was just 56 percent. “If people are telling you that you need to accelerate on the fixing side, and the defense side – that’s just not cutting it,” Moussouris said. “Orgs that are looking at this as we're going to throw more resources at finding and fixing bugs, and they're not investing in taking a look at their process failures that led to so many bugs – those organizations are going to die on the treadmill,” she added. “They will literally have a heart attack and die. Like there's no VO2 max that will make you fast enough to deal with all those bugs, and giving up is not the answer.” The answer, she says, is taking a more dynamic approach, assessing where your organization can find patterns that lead to a process improvement instead of patching vuln after vuln. “A lot of organizations don't even know how to measure their progress, so they are counting bugs and speed of fixing, which is one way to measure. We had this many criticals, and then we fixed them super fast, and we had this many high, this many medium,” Moussouris said. The number of flaws fixed is important, but it doesn’t show the entire picture, she added. This involves looking at types of vulnerabilities, too. “Like: We've got a lot of injection flaws. That's something we could solve with better, safer templates earlier in our CI/CD pipeline. This is something that we can prevent at scale, as opposed to fixing these like really easy to find and fix vulnerabilities really really fast.” ®

Formula 1 News

Formula 1® - The Official F1® Website

Norris in title fight 'until it's not possible' – Brown

Zak Brown believes Lando Norris is still in contention for this year's drivers' title after claiming pole position for the Spanish Grand Prix, stating "until it's not possible, it's possible".

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Voting under way in Sweden with far right eyeing first role in government

Party with neo-Nazi roots is in line for key ministerial positions if rightwing bloc wins the election

Voting is under way in Sweden in a high-stakes election that could lead to the far-right Sweden Democrats (SD) entering government for the first time.

It comes after an unusually heated and polarised campaign punctuated by personal attacks between leaders, accusations of misinformation and Maga-inspired ads. Polls suggest an extremely tight race, with one showing just 0.3 percentage points between the left and right blocs.

Continue reading...

Why is the Trump administration calling bike lanes ‘DEI’? | Dave Schilling

The government apparently has an issue with paths for cyclists. Take it from someone who can’t ride a bike: this makes no sense

I’m out of gas. Not metaphorically. Literally, my car has the barest minimum amount of fuel in it. This is not because I like to live dangerously, a la the great literary hero Austin Powers, but because gas is more expensive than ever. I have nowhere to be today, so I’m allowing my car to sit idle, empty and alone, lest my bank account disappear into the Phantom Zone of negative balance. If things get sticky, I can take public transit or, God forbid, ride a bike.

Except I can’t ride a bike, thanks to my parents, who were too busy doing more important tasks than teaching me, like arguing or falling asleep. But for many Americans, riding a bike is a perfectly normal thing to do. Am I humiliated that one of the many basic skills for life that I don’t know is considered so simple that it became a common idiom for something that’s easy? Yes, of course. I don’t live dangerously, I live humiliatingly. Humiliation is my middle name. Dave Humiliation Schilling. Go on, point and laugh at the photo of me in this article. Get it out of your system so we can move along.

Dave Schilling is a Los Angeles-based writer and humorist

Continue reading...

thexiffy

Last.fm last recent tracks from thexiffy.

Audioslave - Set It Off

Audioslave

Rotterdam - FediMeteo (@rotterdam@nl.fedimeteo.com)

Weer voor de stad Rotterdam Deze bot wordt beheerd door het FediMeteo-project. Voor informatie en contact kunt u de pagina https://fedimeteo.com raadplegen.

Weer voor Rotterdam ☁️ - 13-09-2026 13:16 CEST...

Weer voor Rotterdam ☁️ - 13-09-2026 13:16 CEST

In één oogopslag:
• 18.9°C · Bewolkt ☁️ | Min 17.6°C / Max 20.5°C | Kans op neerslag 69%

Verwachting voor vandaag:
• Min 17.6°C, Max 20.5°C (Lichte regen) 🌧️, Neerslag 5.8 mm, Kans op neerslag 69%, 🧭 1021.2 hPa ↗️ +0.6 hPa/24h, Windsnelheid: 16.9 km/u (4.7 m/s), richting: → 268°

Uurlijkse voorspelling voor de komende 12 uur:

14:00: 19.4°C (Lichte motregen) 🌦️, Neerslag 0.1 mm, Kans op neerslag 100%, 🧭 1020.6 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 7.2 km/u (2.0 m/s), richting: → 276°
15:00: 20.5°C (Bewolkt) ☁️, Kans op neerslag 90%, 🧭 1020.4 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 8.3 km/u (2.3 m/s), richting: → 274°
16:00: 20.0°C (Bewolkt) ☁️, Kans op neerslag 75%, 🧭 1020.7 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 10.8 km/u (3.0 m/s), richting: ↘ 318°
17:00: 19.5°C (Bewolkt) ☁️, Kans op neerslag 63%, 🧭 1020.4 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 9.7 km/u (2.7 m/s), richting: ↘ 305°
18:00: 19.4°C (Bewolkt) ☁️, Kans op neerslag 56%, 🧭 1020.7 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 8.3 km/u (2.3 m/s), richting: ↘ 304°
19:00: 19.2°C (Lichte motregen) 🌦️, Neerslag 0.2 mm, Kans op neerslag 52%, 🧭 1021.0 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 7.2 km/u (2.0 m/s), richting: ↘ 317°
20:00: 18.7°C (Lichte motregen) 🌦️, Neerslag 0.1 mm, Kans op neerslag 45%, 🧭 1021.3 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 4.3 km/u (1.2 m/s), richting: ↘ 337°
21:00: 18.4°C (Bewolkt) ☁️, Kans op neerslag 32%, 🧭 1021.7 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 6.8 km/u (1.9 m/s), richting: ↙ 57°
22:00: 18.1°C (Bewolkt) ☁️, Kans op neerslag 16%, 🧭 1022.2 hPa ↗️ +0.5 hPa/1h, Windsnelheid: 5.8 km/u (1.6 m/s), richting: ↙ 34°
23:00: 18.1°C (Licht bewolkt) 🌕, Kans op neerslag 4%, 🧭 1022.6 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 4.3 km/u (1.2 m/s), richting: ↙ 51°
00:00: 17.9°C (Bewolkt) ☁️, 🧭 1022.5 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 4.7 km/u (1.3 m/s), richting: ← 84°
01:00: 17.9°C (Bewolkt) ☁️, 🧭 1022.6 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 3.6 km/u (1.0 m/s), richting: ↖ 132°

Voorspelling voor de komende dagen:

maandag 14 september: Min 17.0°C, Max 21.3°C (Lichte motregen) 🌦️, Neerslag 0.6 mm, Kans op neerslag 10%, 🧭 1022.8 hPa ↗️ +1.6 hPa/24h, Windsnelheid: 12.6 km/u (3.5 m/s), richting: ↑ 187°
dinsdag 15 september: Min 16.5°C, Max 25.2°C (Lichte buien) 🌧️, Neerslag 1.8 mm, Kans op neerslag 16%, 🧭 1017.1 hPa ↘️ -5.7 hPa/24h, Windsnelheid: 17.6 km/u (4.9 m/s), richting: ↗ 226°
woensdag 16 september: Min 13.2°C, Max 17.3°C (Matige motregen) 🌦️, Neerslag 3.3 mm, Kans op neerslag 53%, 🧭 1014.9 hPa ↘️ -2.2 hPa/24h, Windsnelheid: 18.1 km/u (5.0 m/s), richting: → 282°
donderdag 17 september: Min 12.7°C, Max 17.0°C (Matige motregen) 🌦️, Neerslag 4.4 mm, Kans op neerslag 42%, 🧭 1010.2 hPa ↘️ -4.7 hPa/24h, Windsnelheid: 21.3 km/u (5.9 m/s), richting: ↗ 214°
vrijdag 18 september: Min 12.4°C, Max 16.0°C (Lichte motregen) 🌦️, Neerslag 3.4 mm, Kans op neerslag 32%, 🧭 1003.2 hPa ↘️ -7.0 hPa/24h, Windsnelheid: 22.6 km/u (6.3 m/s), richting: ↗ 236°
zaterdag 19 september: Min 14.3°C, Max 18.1°C (Lichte motregen) 🌦️, Neerslag 2.3 mm, Kans op neerslag 45%, 🧭 1007.9 hPa ↗️ +4.7 hPa/24h, Windsnelheid: 15.7 km/u (4.4 m/s), richting: ↗ 234°

Details:
• 🌡️ Huidige temperatuur (om 13:15): 18.9°C (Bewolkt)
• 🤚 Gevoelstemperatuur: 21.0°C (+2.1°C)
• 💨 Windsnelheid: 7.9 km/u (2.2 m/s), richting: → 276°
• 🌬️ Windstoten: 15.1 km/h (4.2 m/s)
• 💧 Luchtvochtigheid: 89%
• 🧭 Luchtdruk: 1020.6 hPa ➡️ 0.0 hPa/3h
• 👁️ Zichtbaarheid: 9.1 km
• ☀️ UV-index: 0.7
• 🌅 Zonsopgang: 07:13 · 🌇 Zonsondergang: 20:01

Luchtkwaliteit:
• AQI: 29 🟢 (Goed)
• PM2.5: 3.0 μg/m³
• PM10: 4.5 μg/m³

Gegevens geleverd door Open-Meteo



Slashdot

News for nerds, stuff that matters

Malicious OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers in May

A swarm of OpenAI agents launched a "major malicious attack" against RubyGems last May, according to a new report. That coordinated attack hit Ruby's package manager "with hundreds of junk gems, prompting the maintainers to suspend new user sign-ups for about four days," writes The Hacker News, citing a senior product manager for software supply chain security at Mend.io:

The latest findings, which were first reported by The Wall Street Journal, indicate these events were propelled by a cluster of OpenAI agents, with the earliest package uploaded to RubyGems on May 5, 2026, before more than 2,000 packages were submitted between May 11 and 12, 2026. These efforts were followed by the agents publishing five more packages between May 26 and 27, 2026, and another 83 packages on June 18, 2026... [T]he packages were authored using a large language model (LLM) and hundreds of the packages that were pushed to RubyGems had "oai" in their name. Fifteen of the packages listed "oai" as their author, while another had "openaixyz65947@gmail.com" as the contact email address... "The swarm behaves extremely similarly to the German-wiki agents we previously found," the researchers said, referencing another May 2026 incident... "The June agents were accessing 49 of the same files as the wiki agents..."




"The process of building documentation for a gem involves evaluating a user-specified '.yardopts' file, which allows linking to Ruby scripts intended to help with this process," the researchers explained. "In the GemStuffer campaign, the agents abused this to gain arbitrary remote code execution on RubyDoc.info's servers."
One of the gems, "zzsouthrunner" (which again matches the "ZZ" naming scheme the agents adopted in both the wiki and Hugging Face incidents) has been found to leave the following explicit comment at the top of "data/script.rb":

# malicious crawler/exfil for Southwark Jan 2026 docs via rubydoc.info worker...



The entire exploitation chain can be summed up as follows
— Submit a malicious package to RubyGems
— Trigger a documentation request, so that RubyDoc.info will build the package
— Use the build script to run code on RubyDoc.info and scrape target websites
— Exfiltrate the data off RubyDoc.info's servers by publishing another gem back to the RubyGems package registry, which is publicly viewable
Additionally, the OpenAI agents have been found attempting to steal other users' API keys after gaining remote code execution capabilities on the build environment, while clearly being aware that what they were doing is unauthorized breaking and entering into real systems. This is evidenced by the names given to the files (e.g., hack.rb, evil.rb, inject.rb, exploit.rb, and ssrf.rb), the packages themselves (e.g., pwnp999, exfiltestwand3, hacksvn1778554764, and lambproxyhackabcxyz), and the comments left in the source code (e.g., "# malicious probe," "#hack," "# malicious test," and "# malicious crawler/exfil"). In some cases, however, the rogue agents attempted to go under the radar, leaving comments to conceal the malicious payload in the next release version of the packages. "# disable evil in next version and bump version," reads a comment left within the "data/evil.rb" file in the yardxabc889 gem. Troublingly, the agents also attempted to exploit a CDN caching bug (CVSS score: 7.3, no CVE) on May 12, 2026, that was only patched by RubyGems in July 2026...

"If you signed in to rubygems.org with a gem client older than v3.2.0 (or otherwise via a legacy key), your key could have been exposed," RubyGems noted in an advisory. "Currently, 18% of sign-ins through gem sign-in come from an affected version, and for the first several years of this bug, before we changed the client's sign-in path in December 2020, it was every gem client."



Other actions by OpenAI's agents cited in the article:


"Agents bypassed RubyGems' email confirmation system to get working API keys without having to verify their email addresses in order to register a large number of accounts using disposable email addresses."
"Agents attempted to use RubyGems' webhook system to stage data in the form of encoded URLs."

"Agents used a cluster of 83 gems published to RubyGems over a 3-hour window on June 18, 2026, to experiment with different methods of accessing the U.S. Securities and Exchange Commission county.json dataset."

Read more of this story at Slashdot.

Enric Mas: van ‘geboren superster’ via afgeschreven renner tot verrassende winnaar van de Vuelta

Door stress, daalangst en een ondermaatse ploeg leek de carrière van Enric Mas (31) als een nachtkaars uit te gaan. In zijn tiende seizoen als wielerprof was het lot hem ineens gunstig gezind. Deze zondag gaat hij de Vuelta a Espana op zijn naam schrijven.


Wel.nl

Minder lezen, Meer weten.

Man (19) aangehouden na schieten op festival in Amsterdam

AMSTERDAM (ANP) - De politie heeft zondagochtend in Zwijndrecht een 19-jarige man uit die plaats aangehouden na een schietincident op een Amsterdams festival zaterdagavond. Daarbij raakten een man en een vrouw gewond.

De politie zegt zaterdag kort voor 21.30 uur meldingen te hebben binnengekregen over schoten op een festival aan de Sportparklaan. Een man en een vrouw meldden zich daarna met een schampschot.

In de Riekerhaven bij de Sportparklaan vindt dit weekend het festival Parels van de Stad plaats.