The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Atlético Madrid reject £129m bid from Real Madrid for Julián Alvarez

  • Real Madrid reveal they have made offer for Argentinian

  • Arbeloa departs club, paving way for Mourinho return

Real Madrid have revealed they have had a €150m (£129.4m) bid for Julián Alvarez rejected by city rivals Atlético Madrid. The Argentina striker has scored 49 goals in 106 appearances for Atlético since joining from Manchester City in 2024.

The 26-year-old, whose contract runs until 2030, reportedly wants to leave and has been linked with Arsenal and Barcelona. Florentino Pérez vowed before his reelection as Real’s president to submit a club-record offer for an unnamed “great player”.

Continue reading...

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Nieuwe Bulgaarse regering bekent kleur en stopt wapenleveringen aan Oekraïne

Onze vooruitziende blik komt nog niet eens tot de overkant van de brug

Zes jongeren verdacht van aanslag synagoge met terroristisch oogmerk

Het Westen moet Armenië nu blijven steunen bij de economische en politieke ontwikkeling van het land

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Miasma worms its way onto GitHub as attack kit goes open source

As if the Miasma situation weren't bad enough, now this weapon is spreading like wildfire. Someone open sourced the entire Miasma worm supply-chain attack toolkit, likely using previously compromised developers' accounts to publish GitHub repositories containing the self-spreading malware’s source code over the last 24 hours. SafeDep, a company focused on open source supply chain security that developed Package Management Guard (PMG), spotted the malicious repos, named “Miasma-Open-Source-Release,” and said that they started appearing on Monday. Its researchers analyzed one of these before GitHub nixed it, and described the code as more than just a supply chain worm. “It is a full supply chain attack toolkit that allows the operator to execute various attacks via stolen credentials against arbitrary or targeted packages on public registries (PyPI, npm, RubyGems), JFrog Artifactory, GitHub repositories and GitHub Actions, AI coding tools config poisoning, SSH based lateral movement and other attack vectors,” the SafeDep team said. While we don’t know who is behind this publicly released worm, it follows in the footsteps of TeamPCP, which developed and then open sourced the mini Shai-Hulud worm last month, announcing a supply-chain attack contest on BreachForums and spawning copycat open source package poisonings. One of these copycat worms, Miasma, first hit upwards of 100 Red Hat and Microsoft open source projects before spreading to other victims, with app-security firm Socket tracking 473 affected package artifacts as of Tuesday. “The Miasma repository is an evolution of the Mini Shai-Hulud toolkit, and was open-sourced June 8 via four previously compromised users,” Rami McCarthy, principal threat researcher at Wiz, told The Register. “Since we had already reversed the payload, this public release isn’t particularly useful for sophisticated defenders, and we haven't observed any opportunistic adoption of it yet.” This, he added, mimics what happened when TeamPCP open sourced mini Shai-Hulud last month. “We didn't see attackers weaponize it either,” McCarthy said. “It's not clear [whether] attackers benefit from adopting this out-of-the-box toolkit versus vibe coding their own. And while it raises concerns about muddying attribution, attackers tend to continue developing their private fork of the malware, providing a clear payload progression to track and deconflict from anyone utilizing the open-source version.” An interesting aspect of both of these worms and other recent attacks like this one dubbed “Comment-and-Control” by AI bug hunter Aonan Guan is that they run entirely in GitHub - they don’t require any custom command-and-control (C2) infrastructure - and use the code-hosting platform for all stages of the attack including remote command execution, configuration, and data exfiltration. “This is a key behavioural shift because traditional network based detection and protection tools rely on baselining and anomaly detection,” SafeDep researchers noted. “Defenders now have to operate closer to application protocol to identify behavioural anomaly instead of network based anomalies.” The Miasma worm uses three independent GitHub commit search channels for C2, and each has a different search string and purpose. One of these, "DontRevokeOrItGoesBoom," discovers attacker-controlled personal access tokens (PATs) to exfiltrate credentials and other sensitive data. These PATs are AES-256-CBC encrypted in the commit message. The second, "TheBeautifulSandsOfTime," delivers JavaScript for immediate command execution. It’s checked once at startup, and, after validation, it passes the payload to eval() to execute at runtime. Finally, “firedalazer” delivers Python script URLs for the persistent monitor. All three are unauthenticated by default, use GitHub’s public commit search API, and use a different validation or decryption key, which means compromising one doesn’t automatically compromise the other two.®

Tokyo Nights: Neon Pulse of Shinjuku

T.Marko has added a photo to the pool:

Tokyo Nights: Neon Pulse of Shinjuku

A vibrant nighttime scene in the heart of Tokyo, where endless neon signs illuminate the streets of Shinjuku. The blend of glowing storefronts, moving traffic, and urban energy captures the unique atmosphere of one of the world's most iconic entertainment districts. A glimpse into the city that never seems to sleep.

Veel vrouwen kampen met een ijzertekort, maar bijna niemand heeft dat in de gaten

IJzertekort kan leiden tot moeheid, concentratieproblemen en verminderde sportprestaties. Toch krijgen veel vrouwen pas een behandeling als sprake is van bloedarmoede. „Tegen een zware menstruatie valt niet op te eten.”


MetaFilter

The past 24 hours of MetaFilter

PFAS are a problem, micro plastics maybe not so much...

A bombshell': doubt cast on discovery of microplastics throughout human body
It appears that much of the research on micro plastics has a false positive issue.
Previous on the Blue


Good general summary if you would rather watch a video: YouTube video discussion on micro plastics and PFASs: Claims starting from 2019 about the amount of micro plastics are people are consuming and that it is showing up in all parts of the body including the brain: Daily Consumption: No Plastic In Nature: Assessing Plastic Ingestion from Nature to People We consume up to a credit card's worth of plastic *every* week Estimation of the mass of microplastics ingested – A pivotal first step towards human health risk assessment Accumulation in the body: Bioaccumulation of microplastics in decedent human brains Levels of microplastics in human brains may be rapidly rising, study suggests Worries about false positives starting in 2025: Nitrile and latex gloves may cause overestimation of microplastics, U-M study reveals Avoiding and reducing microplastic false positives from dry glove contact Assessing the Efficacy of Pyrolysis–Gas Chromatography–Mass Spectrometry for Nanoplastic and Microplastic Analysis in Human Blood PFAS still appear to be an issue, so it's not all good news: Our Current Understanding of the Human Health and Environmental Risks of PFAS TLDR: A common material used in Nitrile and latex gloves, called Stearates, has been contaminating research on the amount of micro plastics in nature. Also, the most common test used for detecting polyethylene aka plastic can be faulty due to human fat generating false positives. Caveat: The absence of evidence is not evidence of absence. More research is needed.

Formula 1 News

Formula 1® - The Official F1® Website

How F1 teams adapted to the unique challenge of Monaco

The very specific demands of Monte Carlo allowed several teams to devise weird and wonderful looking additional winglets for last weekend’s Monaco Grand Prix.