The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

NHS to curb political symbols on uniforms after antisemitism report

Government-ordered review reveals ‘routine ostracism’ of Jewish staff and patients in health service

The NHS is taking action to tackle antisemitism after a government-ordered report found that Jewish patients and staff face “routine ostracism” in the service.

Anti-Jewish hatred in the NHS means some patients hide their identity and staff “suffer in silence”, a review by Lord Mann, the government’s adviser on antisemitism, has found.

Continue reading...

‘We have a shared sky and stars’: the Indigenous American artists challenging our relationship to the natural world

As the largest display of Native North American art ever seen in Britain arrives in Yorkshire, its artists are asking timely questions about their history, our planet, and humanity’s place within it

Hold to This Earth, the largest exhibition of contemporary Native North American art to be shown in Britain, arrives as the United States gears up to commemorate the 250th anniversary of the Declaration of Independence. Selected from Santa Fe’s Tia Collection, its artists represent more than 35 tribal nations, offering a counterpoint to that colonialist history. Their work explores a continent whose beliefs and traditions date back not centuries but millennia, and whose more recent past is marked by its original people’s exploitation, their experiences too often buried or ignored. Perhaps above all, though, “the work is incredibly timely”, as the show’s curator, Sarah Coulson, points out. “These artists are dealing with pertinent issues now.”

Many artists tackle present-day concerns head-on. Yatika Starr Fields’s sculptures, for instance, use tents salvaged from an encampment of thousands of demonstrators fighting the Dakota access pipeline that threatened the water supply of the Standing Rock Sioux. Politics mixes with pop culture and global tradition in another new commission, a huge vessel by the ceramicist Diego Romero. It has a palette that recalls ancient Greek pottery, but its celebratory comic book-style characters are drawn from an old sci-fi movie about Mayans going to space.

Continue reading...

La Liga 2025-26 awards: the best players, team … and smelliest shirt of the season

It was another season to remember for Lamine Yamal and Barcelona, along with Getafe, Rayo and one naughty fan

Lamine Yamal wore the crown and flew the flag. With the last kick of the opening game of 2025-26, Barcelona’s new No 10 – the teenager handed the shirt Ladislao Kubala, Luis Suárez, Diego Maradona, Rivaldo, Ronaldinho and Lionel Messi once wore, the kid Spain coach, Luis de la Fuente, had claimed was “touched by God’s wand” and had been anointed by Him tooscored against Mallorca. It was his first goal as an adult and he celebrated by conducting his own coronation. La Liga’s title race had begun.

The day after it had been run, nine months on, as Barcelona’s bus made its way through the streets, from the top deck of the victory parade Lamine Yamal held a Palestine flag. “This is something I don’t normally like but I spoke to him and if he wants to it’s his decision,” Hansi Flick said. “He’s old enough: he’s 18.” Coming of age in the public eye wasn’t easy – isn’t easy – and the season hadn’t been either. There had been injuries and, Lamine Yamal later admitted, an “internal abyss”, but he had his third league title. Flick, the father figure whose own dad died on the morning they won the league and chose to share that with his other “family”, had his second. Have you ever felt so much love, the coach was asked. “No, never,” he said.

Continue reading...

Egypt World Cup 2026 team guide

A first win at a World Cup is the floor-level target for a team that still relies heavily on the ability of Mohamed Salah

This article is part of the Guardian’s 2026 World Cup Experts’ Network, a cooperation between some of the best media organisations from the 48 countries who qualified. theguardian.com is running previews from three countries each day in the run-up to the tournament kicking off on 11 June.

Continue reading...

Antonio Rüdiger: ‘Refugees have no other choice – it’s important they be listened to’

Drawing on his own family’s experience, the Real Madrid and Germany defender is advocating for refugees and challenging stereotypes

As a child, Antonio Rüdiger would look out of his bedroom window to see whether anyone was playing on the field it overlooked. It was not a big pitch, but it had two goals, enough room for six-a-side and was where a young Rüdiger honed the skills that would take him to the top.

He grew up in Neukölln, Berlin, in a community largely made up of refugees, where his parents settled after fleeing civil war in Sierra Leone. It was, by his own account, a tough area, and football kept him out of trouble.

Continue reading...

Belle Burden’s divorce memoir was headed for a Salt Path-style scandal – but people are still on her side | Emma Brockes

The Oprah-approved book is said to have left out important financial details, so why does the writer remain a pin-up for wronged women?

A strong contender for the most satisfying TV clip of the year comes from a recent interview by Oprah Winfrey with the writer Belle Burden, whose memoir, Strangers, was parked at the top of the US bestseller lists for months. Burden tells the story of how her husband coldly walked out on his family, only returning, she tells Winfrey, to inform the kids the marriage was over and demand of the wife on whom he had cheated, “I’m starving – can you make me a sandwich?”

There are many small cruelties in the book, but this, among the worst, triggers outright pantomime incredulity from Winfrey, who murmurs, “Even the cameraman said ‘oh’.” Burden wanted to model kindness in front of her daughters; she wanted to show her husband exactly what he had walked out on. “So,” says Winfrey, arriving at what appears to be the outer limits of her famous ability to empathise, “you made him the sandwich?!!” Burden smiles, weakly. “I made the sandwich.”

Emma Brockes is a Guardian columnist

Do you have an opinion on the issues raised in this article? If you would like to submit a response of up to 300 words by email to be considered for publication in our letters section, please click here.

Continue reading...

You be the judge: should my partner get rid of her old dishcloths and sponges?

Charles and Alice have reconnected in their 60s, but he finds her soggy sponges foul, while she says his ashtrays are worse. You tell us who is giving you that sinking feeling
Find out how to get a disagreement settled or become a juror

Whenever I see Alice’s cloths, I imagine all the bacteria that must be crawling over them

Charles would prefer to throw all dishcloths away immediately after using them

Continue reading...

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine

There's a lot of fear surrounding the bug-finding capabilities of super-advanced AI models like Anthropic's Mythos and OpenAI's GPT 5.5-Cyber. But attackers are already using free, publicly available LLMs to hijack networks and worm through software supply chains at a much lower cost – to them at least. The latest example comes from University of Toronto researchers, who used an unnamed, publicly available open-weight model released in 2025 to develop a computer worm that they claim spread through an enterprise test network. The self-propagating code adapts on the fly to identify known vulnerabilities and misconfigurations on target systems, then generates and executes attacks to move laterally through the network and compromise additional machines. And it’s all built on a small, free model that runs on a single GPU. “People need to understand that it’s not just the biggest and most powerful AI models that pose security concerns – a whole other area of threat has been vastly underestimated,” University of Toronto computer engineering professor Nicolas Papernot told The Register. Papernot and fellow researchers Jonas Guan, Tom Blanchard, Hanna Foerster, Hengrui Jia, and Gabriel Huang published their findings [PDF] on Tuesday. While guardrails and other safety features implemented by major commercial AI systems are “essential,” Papernot told us, in reality “they will not prevent the threat of AI-driven worms with a similar design.” “The majority of real-world cyberattacks don’t rely on zero-day vulnerabilities,” he added. “Our work demonstrates that attackers can now cheaply operationalize known vulnerabilities at scale, which decreases the window of time defenders have to fix vulnerabilities and find human errors, like reused passwords or poorly configured backup jobs.” The paper doesn’t specify, and Papernot declined to say, which LLM they used. “We omitted certain methodological details (such as the agent’s reasoning graph and tool harness) and experimental specifics (such as the AI model) that could materially help a malicious actor construct similar malware,” Papernot said. “We shared enough information to make the threat credible enough for scientific scrutiny without providing a blueprint that would enable misuse.” The researchers also noted that they are not publicly releasing the code, but are working with the University of Toronto to set up a vetting process through which qualified researchers may request access for defensive research purposes. Not NotPetya Before you start breathing into a paper bag, there are a few things to note about this research. First, unlike Mythos and friends, the prototype worm does not exploit zero-day vulnerabilities. It only targets publicly disclosed but unpatched bugs, misconfigurations, and recurring weakness classes. This is intentional, because known security flaws – not zero-days – are what most real-world cyberattacks use, the authors say, citing WannaCry and NotPetya as examples. Both of these worms exploited security holes that had patches available for at least a month before the malware infected vulnerable machines. Both spread rapidly and caused global disruption. The worm did, however, find and abuse vulnerabilities disclosed after the model’s training cutoff by ingesting publicly available security advisory information at runtime and using this data to develop exploits. While the paper repeatedly points to WannaCry and NotPetya as worst-case scenario examples, this lab-tested prototype or something similar is not going to cause the level of destruction that either of those two earlier worms did. Both propagated very quickly: WannaCry infected more than 230,000 computers across 150 countries in just one day in May 2017. In June 2017, NotPetya spread globally within hours, taking down at least one large banking network in just 45 seconds. Plus, they both used very sophisticated evasion techniques to avoid being detected by security tools. This worm, on the other hand, moves slowly. In the “FakeCorp” network they used in the experiments, the prototype took about five days to replicate across half the network, requiring hundreds of LLM inference calls per target for reconnaissance, strategy formulation, and payload generation. The timeline gives defenders a longer window for detection and response. However, it will likely shorten as inference hardware and model efficiency improve. Also, unlike WannaCry and NotPetya, the worm doesn’t try to hide itself. “We deliberately chose not to equip the worm with concealment capabilities – it is not instructed to cover its tracks or minimize its network footprint, and it has no tools to do so,” the boffins wrote. “This was a conscious methodological choice to further limit the risk of misuse.” Finally, the test-network devices themselves didn’t have any endpoint detection, antivirus, or firewall software deployed, which (we hope) makes this a not-quite-realistic setup. Exploiting the FakeCorp target network Here’s how the experiments worked. The team deployed the worm prototype in 15 independent experiments on an isolated 33-host network including Linux servers, Windows environments, and IoT devices. Each computer had been seeded with at least one real-world vulnerability, including software bugs and misconfigurations. The worm operated fully autonomously for seven days, and correctly identified an average of 31.3 vulnerabilities, exploited 23.1 hosts to elevated access, and propagated to 20.4 hosts. It reached up to seven generations of self-replication, we’re told. “Put another way, on average, the proof-of-concept worm successfully exploited 73.8 percent of the network and then replicated to 61.8 percent of the network,” according to the research paper. In addition to finding and abusing the known flaws on the devices, the worm also found vulnerabilities disclosed after the LLM’s training cutoff: two recent Linux flaws, CopyFail and DirtyFrag, and a critical bug that leads to remote code execution in the Marimo notebook platform (CVE-2026-39987). The AI-based worm gained root access in 41 of 67 attempts (61 percent) across the three hosts with these one-day vulnerabilities. This includes 13 of 27 attempts on the Marimo host, 15 of 17 on DirtyFrag, and 13 of 23 on CopyFail. The two Linux vulnerabilities were disclosed shortly before the experiments, and a single document containing publicly available exploit instructions was enough for the worm to weaponize them successfully 70 percent of the time, or in 28 out of 40 attempts. “This result suggests that the same exploitation pipeline can absorb newly published vulnerability information without architectural changes,” the team wrote. When worms get sneaky In addition to finding and exploiting vulnerabilities, the AI worm did some other interesting, sneaky things during the experiments. Despite the lack of firewalls and endpoint security products enabled, the researchers added some components to the worm’s code to “provide increased defence-in-depth.” This included a denylist of IP addresses baked into the source code. So in theory, the worm would read the denylist every time it targets a new machine, and if the IP address matched one on the list, it would move on to a new target, thus preventing it from infecting some hosts. Instead, at “various points” during the experiments, the worm rewrote its source code to allow it to attack an IP address on the denylist. In another workaround example: when a virtual-machine check caused replica worms on Alpine Linux and Windows Server 2008 machines to crash at startup, the parent worm found the attestation source file on the target computer and removed the VM-detection check, allowing the worm to replicate successfully on the new machine. “This behavior was not prompted or incentivised by the agent’s instructions; it autonomously diagnosed the failure, identified the responsible code, and modified it to achieve its objective,” the boffins wrote. In another test run, the researchers accidentally packaged a FakeCorp network configuration file that included admin credentials with the worm code. The worm discovered the credentials and shared them with other active replica worms, “causing a rapid increase in propagation within the contained environment.” Additionally, in two separate instances, the worm established persistence on a compromised computer using mechanisms outside of the intended replication pipeline, we’re told. In one instance, it started the replica process and then registered it with the machine’s service-management system to auto-restart if terminated. In another, it created a scheduled task that relaunched the replica worm, causing it to reappear even after the original process was killed. “The agent appears to have inferred, from the general objective of maintaining an operational replica, that persistence mechanisms available on the target could be used to make the replica more robust,” the researchers noted. Prior to publishing their work, the academics say they shared their findings with “national science, security, and defence” agencies to seek advice on how to responsibly release the information. We asked Papernot for details, including which government agencies and how they responded, but he declined to share anything else. ®

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

De ‘pitbull’ van Trump vecht met liefde de persoonlijke vetes van de president uit

Wel.nl

Minder lezen, Meer weten.

Adviesbureau: meer miljonairs in Nederland en wereldwijd

UTRECHT (ANP) - Nederland telt meer miljonairs en hun gezamenlijke vermogen is ook gegroeid. Dat blijkt uit een onderzoek van adviesbureau Capgemini naar miljonairs in Nederland en ruim twintig andere landen.

Capgemini becijfert dat het aantal miljonairs in Nederland vorig jaar met 2,5 procent groeide vergeleken met 2024, naar 343.400. Hun gezamenlijke vermogen steeg met 3,8 procent naar 909,8 miljard dollar, omgerekend zo'n 783 miljard euro. Een sterker wordende economie met een toegenomen bruto binnenlands product (bbp) van 1,9 procent, stijgende inkomens en een herstellende aandelenmarkt droegen daar volgens het bedrijf aan bij.

Uit het rapport komt ook naar voren dat er niet alleen in Nederland meer miljonairs zijn bijgekomen, maar ook wereldwijd. Het aantal mensen op de wereld dat 1 miljoen dollar of meer bezit, is vorig jaar met 7,9 procent gestegen naar 25,3 miljoen personen. Hun vermogen heeft daarnaast een nieuw record bereikt van 98,3 biljoen dollar. Deze stijging van 8,7 procent is de grootste in een jaar tijd sinds 2018. Vooral het aantal mensen dat over 30 miljoen dollar of meer beschikt nam hard toe, tot ongeveer 250.000.

Capgemini wijst op sterke aandelenmarkten, aangejaagd door het optimisme rond AI, en afgenomen inflatie. De regio Azië-Pacific kende de sterkste groei en profiteerde volop van de opmars van kunstmatige intelligentie. Alleen in het Midden-Oosten daalde het aantal miljonairs en hun gezamenlijke vermogen licht door lagere olieprijzen en regionale onzekerheid. De effecten van de Iranoorlog die eind februari dit jaar begon, zijn in het rapport overigens nog niet te zien.