Wel.nl

Minder lezen, Meer weten.

Na aardbeving 49 meldingen van schade, waarvan 16 uit gebied

GRONINGEN (ANP) - Na de aardbeving van vrijdagochtend bij het Groningse dorp Zandeweer hebben 49 mensen schade doorgegeven. Daarvan kwamen er zestien uit het gebied rond het epicentrum, waar de trilling schade zou kunnen hebben veroorzaakt, meldt het Instituut Mijnbouwschade Groningen. Bij twee meldingen ging het om een situatie die "mogelijk acuut onveilig" was.

Het instituut houdt er rekening mee dat er woningeigenaren zijn die nieuwe schade hebben gemeld terwijl hun schade eerder al definitief was afgehandeld. Zij krijgen bericht van het instituut.

De aardbeving van vrijdag was de zwaarste sinds maart. Toen was er een trilling van 3,0 in de buurt van Assen. Toen kwamen er ongeveer 2000 schademeldingen.


Jetten wil steun voor totale begroting, dus geen 'cherrypicking'

DEN HAAG (ANP) - Het is de bedoeling dat de totale miljoenennota brede steun krijgt in de Tweede Kamer, zei Rob Jetten vrijdag in zijn wekelijkse persconferentie. Hij wil dus geen "cherrypicking", waarbij partijen de ene begroting wel steunen en de andere niet. "Veel dingen hangen met elkaar samen, en dan kom je elkaar ook snel in de weg te zitten."

In de debatten over de begrotingen van individuele ministeries die de Tweede Kamer na Prinsjesdag voert, zullen partijen ook nog voorstellen doen met geld te schuiven, verwacht Jetten. "De discussie die we nu hebben, gaat vooral over begrotingen heen: hoe verdeel je de totale pot met geld, waar zet je je prioriteiten?"

Een vraag die deze week veel in Den Haag klonk, is wanneer het kabinet het brede akkoord rond wil hebben. "Wij doen er alles aan om dat voor Prinsjesdag voor elkaar te krijgen", zei Jetten daarover, maar hij sloot ook niet uit dat het later wordt. "Het budgetrecht ligt uiteindelijk bij de Tweede Kamer."


Rijnmond - Nieuws

Het laatste nieuws van vandaag over Rotterdam, Feyenoord, het verkeer en het weer in de regio Rijnmond

Deze spin kan je vaker gaan tegenkomen in je huis: 'Zou ze lekker laten zitten'

Wie zijn koffer uitpakt of tent na de vakantie opruimt kan er zomaar een tegenkomen: de 'valse' wolfspin. Het beestje komt oorspronkelijk uit Zuid-Europa, maar is vanwege het warmere klimaat steeds vaker hier te vinden. "Het is inmiddels een vaste bewoner van Rotterdam", zegt stadsecoloog André de Baerdemaeker. Wij vroegen hem hoe het ervoor staat met het spinnetje.

Op het nieuwe album van Anthony Hopkins is de grens tussen suikerzoete sentimentaliteit en prettige melancholie nogal dun

De samenstelling van Anthony Hopkins’ nieuwe album lijkt op een ouderwetse filmvoorstelling en zit vol weemoed en nostalgie. Cellist Astrig Siranossian zingt op haar cello en bij Julia Holter komt er altijd en overal wel iets moois langs waaien.

Japan Tokyo Asakusa BW

wazo3 has added a photo to the pool:

Japan Tokyo Asakusa BW

All Tourists

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Home Office could be blocked from deporting trafficking victims to Albania

Many males are returned even if they have been trafficked but Home Office must now consider new legal guidance

The Home Office could be blocked from deporting many young male trafficking victims to Albania after a major court ruling.

Thousands of Albanian males have been identified as potential trafficking victims in the UK in recent years. Many are sent back to their country even if they are potential or confirmed victims of trafficking, as the Home Office contends they will be safe there.

Continue reading...

De Speld

Uw vaste prik voor betrouwbaar nieuws.

Veehouders strijden voor betere wereld voor héél hun familie

​Veehouders zijn als beroepsgroep tegenwoordig vaak de klos in het publieke debat. Veehouders zouden zorgen voor meer emissie van broeikasgassen, boerenprotesten zouden soms tot ongelukken leiden op snelwegen, bestuurders en politici worden geïntimideerd. Toch is dit geen faire weergave, vinden veel boeren: “Wij strijden voor een betere wereld voor álle leden van ons gezin”, zegt boer Henkel.

“De stallen, de kippen, de uitstoot, de ontbossing in Brazilië: we doen het zodat onze oudste zoon op een dag dit bedrijf kan overnemen en op zijn beurt hard kan werken voor de hele familie.”

&


Formula 1 News

Formula 1® - The Official F1® Website

Albon and Sainz explain why they have kept faith in Williams

With Alex Albon and Carlos Sainz recently confirmed to remain at Williams into 2027, both drivers have explained the thinking behind their decision to stay ahead of the Dutch Grand Prix.

LIVE COVERAGE: All the action from FP1 at Zandvoort

Live coverage of Friday's first practice session for the 2026 Dutch Grand Prix.

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

$10K phishing kit claims it can plant rogue passkeys for persistent access to pwned accounts

A phishing kit for sale on Russian-language cybercrime forums claims it can enroll attacker-controlled passkeys on compromised accounts, providing persistent access after passwords are changed. Advertised at around $10,000 for the base package, with additional modules sold separately, iAuthFlow v2 aims to solve a common problem for attackers: being locked out after the victim detects the compromise. Defenders would ordinarily revoke session tokens and rotate credentials. Those measures remain necessary, but may not be sufficient if the attacker has enrolled a passkey on the compromised account. According to Abnormal Security, which examined the kit's documentation and demonstration videos, the technique uses a browser-in-the-middle (BitM) model involving two separate browser environments. In a BitM attack, the victim appears to complete the login on their own device, while the attacker's infrastructure relays the interaction through a separate browser session. The victim sees a phishing page impersonating the targeted service. The iAuthFlow v2 demos focused on Google, but the seller advertises packages for iCloud, LinkedIn, and Microsoft too. The victim enters their account details into the phishing page, while iAuthFlow v2 operates a separate browser on the attacker's server. It sends the victim's input to Google and relays Google's prompts back to the victim. The process repeats until the authentication flow is complete. Once authentication is complete, iAuthFlow v2 controls an authenticated browser session and uses it to enroll an attacker-controlled passkey, Abnormal says. That credential can remain valid after the victim changes their password. Rather than sending the victim to their Gmail inbox after authentication, iAuthFlow v2 displays a brief loading screen reading: "Verification, Processing." Meanwhile, the toolkit works behind the scenes to register a passkey to an attacker-controlled device. "During that pause, the seller's demonstration shows the passkey module opening the target's Google passkey settings through the authenticated browser and requesting a new credential," Abnormal said. "Google may require further identity verification before allowing the change. In the recorded run, the toolkit log indicates that the passkey was created six seconds after authentication." It is unclear where the private key associated with the attacker's passkey is stored. Abnormal hypothesized that the kit may use a Chromium-based virtual authenticator capable of completing WebAuthn registration without storing the private key on the victim's device. However, because the researchers did not buy and test the kit, they could not confirm its storage mechanism – or independently verify the seller's broader claims. Whatever the storage mechanism, organizations should look for newly registered passkeys when investigating an account compromise. Responders should also hunt for other post-compromise changes, including rogue passkeys, OAuth grants, recovery methods, Gmail filters, and forwarding rules. "Response and recovery cannot end with a password reset or session revocation," said Abnormal. "Organizations must also examine what changed after authentication – especially newly enrolled credentials, recovery methods, OAuth grants, and mailbox settings – and remove anything the attacker left behind. "As toolkits like iAuthFlow v2 expand their post-authentication capabilities, effective response increasingly depends on treating account restoration as a comprehensive investigation, not a simple reset." Passkeys are routinely heralded as the future of account security. Designed to resist phishing, they can replace passwords and more vulnerable forms of MFA. Registering a passkey does not make an account bulletproof. Attackers can instead target fallback login methods, active sessions, account recovery processes, and other weaknesses surrounding the credential. Stealing session cookies, often through infostealer malware, can grant access to an authenticated session without triggering a passkey prompt. Another route is device code phishing, although it depends on the organization permitting the underlying OAuth device flow – something generally discouraged unless operationally necessary. ®