It’s a Bullant

braart has added a photo to the pool:

It’s a Bullant

Trying to get into to Monastery to seek redemption

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

VS sturen derde vliegdekschip richting Iran

Vreselijke eerste helft Oranje tegen Griekenland, puik herstel na rust (2-2)

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

AI agents hacked the hackers, stealing email addresses from security research org

AI agents hacked the hackers - the Dutch Institute for Vulnerability Disclosure (DIVD) - via two zero-day bugs in its Zammad support platform, abusing the flaws to hijack sessions, run code remotely as the local zammad user, and escalate privileges to root. The chained exploits took just seconds to move from session hijacking to root access, and on Thursday, the nonprofit bug hunting organization said the miscreants stole data belonging to its volunteer security researchers, including DIVD email addresses and potentially other contact details. “We’re still investigating exactly which data of which volunteers is affected,” DIVD said in its incident report. “For DIVD volunteers (and others) this means a higher risk of social engineering, because this makes it easier for someone to pose as a DIVD’er.” A subsequent LinkedIn post advised anyone receiving an email or contact request from someone at DIVD “that feels slightly off” to verify that it’s legit by emailing communications@divd.nl. DIVD is also a CVE Numbering Authority (CNA), and it assigned CVE IDs to the now-public security holes in Zammad, an open-source helpdesk and customer support ticketing system. They are CVE-2026-102489 and CVE-2026-102490, and both bugs received CVSS 4.0 scores of 9.4, when assessed in the chained attack scenario. CVE-2026-102489 enables unauthenticated attackers to achieve remote code execution and leak user sessions, while CVE-2026-102490 allows a local user to elevate their privileges to root. Zammad versions 6.3.0 to 6.5.4 are vulnerable to CVE-2026-102489, and it also exists in versions 7.0.0 through 7.1.3 - but it’s not exploitable “due to environment conditions,” according to DIVD’s advisory. All Zammad versions are vulnerable to CVE-2026-102490. DIVD advises “all users of Zammad to upgrade to version 7 of Zammad or to take it offline.” What happened According to the nonprofit’s timeline, the attack happened on September 21, when "malicious actors” broke into its IT system via the two zero-days in its ticketing support software. The bug hunters discovered the attackers the following day, blocked access to all of its data center systems, and formed an incident response team with Merlon Security. On September 24, DIVD reported the Zammad vulnerability to the vendor, notified the Dutch Data Protection Authority and the National Cyber Security Centre about the incident, and discussed its options with police. It also posted its first disclosure on LinkedIn. “It took us (almost) seven years but we can now say that we're the hackers that got hacked,” the post said, adding that DIVD remained committed to handling the incident in “the way we think it should be handled. That is open, transparent and honest, even if it sucks.” 'Modus operandi' indicates agentic AI DIVD also noted that its team had never seen an attack like this before. “This is an attack we have not seen before,” according to the post. “Not because it’s our first, but because the modus operandi indicates that this is an agentic AI powered attack.” The attack was "loud and very very messy," DIVD said. "We could see the agent working automated, because after every action it decided the next step itself, at the speed of light and sloppy logic or pattern." Subsequent posts with screenshots of logs found during the investigation reveal embedded notes found in the attack script - another indication that this was an agentic operation or at least AI-enabled. “What human attacker leaves notes to themself in their scripts, explaining why what they're doing is okay and really not phishing? The AI just got a task and keeps justifying its own actions in the code as comments, a human wouldn’t care less," the post said. "Who has time for that anyway?” If only all orgs responded to hacks like this While the investigation remains ongoing, security researchers applauded DIVD for its transparency in disclosing and responding to the hack. “Kudos to DIVD for their level of honesty and transparency working through their active incident and investigation,” VulnCheck security researcher Patrick Garrity posted on LinkedIn. “It would be nice if all organizations were this transparent about their security incidents!” In a subsequent interview with The Register, Garrity said he applauded DIVD’s “brutal honesty” about the breach. “They're eating their own dog food, which is great, and getting information out quickly to other organizations that potentially use this product so they can take action before they get hit.”®

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Hitting the sweet spot: bear treats itself to baked goods at Colorado farmers’ market

Shoppers and vendors in Aspen surprised by unusual customer as it stretched to sample stall offerings

Farmers’ market shoppers might not usually pay much attention to the local resident devouring fresh bread and pastries at one of the stalls with extra gusto – but some certainly did last weekend when they realized it was a hungry bear.

Onlookers on Saturday reached for their phones to take photos and videos of the bear in downtown Aspen, Colorado, after it wandered through the stalls and got up on to its hind legs to dig into the baked goods.

Continue reading...

Shaw secures WCL draw against Real Madrid as Manchester City show spirit after week of turmoil

Manchester City played out a high-quality draw with Real Madrid in the Women’s Champions League after an unprecedented week of off-field tension at the English club.

The result – which was a fair reflection of an even but entertaining game – left both sides with two points from their opening two fixtures, but City will know their league phase opponents should theoretically become less challenging from hereon, after their opening draw at Bayern Munich.

Continue reading...

Neco Williams fires revitalised Wales to fightback win against 10-man Norway

On a night when Erling Haaland moped around the pitch, dragging his hulking frame across the Cardiff turf, Wales registered a welcome victory over 10-man Norway and their first this year. Daniel James cancelled out Oscar Bobb’s well-worked opener in the first half and 17 seconds into the restart Torbjørn Heggem was sent off for fouling James as the Leeds winger streamed through towards goal, resulting in a free-kick from which Neco Williams earned Craig Bellamy’s side the three points. “You’re just a shit Kieffer Moore,” was the chant at Haaland from the locals.

Bellamy was under no illusions about the task facing his side. He described Norway as one of the best teams in the world and one riding the crest of a wave after reaching the World Cup quarter-finals. Martin Ødegaard, the Arsenal and Norway captain, was the visitors’ creator in chief and it was no surprise he was the architect for a crisp opener, slotted in by Bobb, one of two Fulham players and one of five Premier League regulars in the Norway starting lineup.

Continue reading...

Gemeente Vlissingen krijgt grond in handen van een te slopen wijk, zonder harde terugkeergarantie voor bewoners

Bewoners van het unieke wijkje ’t Eiland in Vlissingen moeten na sloop kunnen terugkeren in nieuwe sociale huurwoningen, vinden lokale politici. Maar een garantie krijgen ze niet. „Gemeentes kunnen woningcorporaties niet dwingen.”

Wel.nl

Minder lezen, Meer weten.

Rapport: oorzaak brand natuurgebied Limburg blijft onduidelijk

VENLO (ANP) - De oorzaak van de brand begin augustus in het Limburgse natuurgebied Boschhuizerbergen blijft onduidelijk. Dat is de conclusie in een rapport van de brandweer Limburg-Noord en het Landelijk team Natuurbrandonderzoek dat donderdag werd gepresenteerd.

De brandweer zegt wel met zekerheid te kunnen stellen dat de brand niet is veroorzaakt door werkzaamheden, onontplofte oorlogsresten of achtergelaten afval, is te lezen in het rapport. Ook vonkvorming van het spoor, dat dwars door het natuurgebied loopt, wordt als oorzaak uitgesloten. En het schrikdraad, waarmee delen van het gebied voor wild zijn afgezet, bevond zich ook niet in de buurt van de plek waar de brand begon.

Bij de brand in het natuurgebied bij Venray ging ongeveer 100 hectare natuur verloren, waaronder bijna 4000 aaneengesloten struiken met jeneverbessen. Volgens de brandweer is de brand vermoedelijk midden in het bos ontstaan en kon het vuur zich snel verspreiden door een combinatie van onder meer droogte en de grote hoeveelheid brandbaar materiaal.


kottke.org

Jason Kottke's weblog, home of fine hypertext products

The best multi day hikes in the world. “As an avid hiker,...

The best multi day hikes in the world. “As an avid hiker, who spends most of her time hiking, I have done more than 100 multi day hikes all over the world. This list includes 25 of my favorite ones.”