The Earth Has But One Moon

Thomas Hawk posted a photo:

The Earth Has But One Moon

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

UK chancellor urged to remove £100k childcare ‘cliff edge’ prompting parents to cut work hours

Critics say threshold pushes higher-paid staff to cut back on work and often mothers to stop working to avoid losing entitlement

John Healey has been urged to fix the £100,000 childcare “cliff edge”, that means some higher-paid employees cut back on work to avoid losing their entitlement.

Since the latest expansion of taxpayer-funded childcare in 2024, families with young children in which both parents earn less than £100,000 a year can be entitled to 30 hours a week of care - or none at all, if one of them cross that threshold.

Continue reading...

Wel.nl

Minder lezen, Meer weten.

Rus Chatsjanov naar halve finale US Open na opgave Blockx

NEW YORK (ANP) - Tennisser Karen Chatsjanov heeft voor de tweede keer in zijn loopbaan de halve finale van de US Open bereikt. De 30-jarige Rus versloeg in New York de Belg Alexander Blockx, die in de derde set opgaf wegens een blessure. Chatsjanov stond op dat moment twee sets voor: 6-2 7-5 3-2.

Chatsjanov stond eerder in 2022 in de halve finale. Toen moest hij de zege laten aan de Noor Casper Ruud. Ook op de Australian Open haalde hij een keer de halve finale, dat was in 2023. Op deze US Open schakelde Chatsjanov de als derde geplaatste Canadees Félix Auger-Aliassime uit.

Chatsjanov neemt het in de halve finale op tegen de winnaar van de partij tussen de als eerste geplaatste Duitser Alexander Zverev en Botic van de Zandschulp.


Lichaam te water geraakte man Amsterdam gevonden

AMSTERDAM (ANP) - Een 47-jarige man uit Amsterdam is woensdag overleden nadat hij van een plezierjacht viel op het IJ. Na een grote zoekactie met duikers is het lichaam van de man gevonden, bevestigt de Veiligheidsregio Amsterdam-Amstelland na berichtgeving door Het Parool. De krant meldt dat de politie uitgaat van een noodlottig ongeval.

De man viel op het Buiten-IJ tussen de Schellingwouderbrug en de Oranjesluizen over boord vanaf een plezierjacht. Hoe hij precies te water raakte is niet bekend.

Sinds woensdagmiddag werd er door meerdere hulpdiensten naar het slachtoffer gezocht. Onder meer boten van de Koninklijke Nederlandse Redding Maatschappij (KNRM) en de brandweer zochten mee. Ook waren er veel politieagenten, brandweerlieden en ambulances aanwezig.

Na een uur werd de inzet van reddingsdiensten minder, omdat de kans dat het slachtoffer daarna in leven zou zijn, zeer klein was. Vervolgens werd er met onder meer duikers en sonarboten door de politie verder gezocht, waarna het lichaam van de man werd aangetroffen.


A28-brug weer volledig geopend, herstelwerkzaamheden afgerond

NIJKERK (ANP) - Het verkeer kan beide kanten van de Hardenbergerbrug weer gebruiken, meldt Rijkswaterstaat. Eerder ging de brug waar de A28 overheen loopt al in de richting van Utrecht open, maar nu is ook de richting Zwolle vrijgegeven.

Sinds maandag is Rijkswaterstaat bezig met herstelwerkzaamheden aan de brug bij Nijkerk. De wegbeheerder constateerde toen dat het niet veilig was om nog over dat stuk van de snelweg te rijden. Er was zand en grind weggespoeld rond de pijlers van de brug. Rijkswaterstaat heeft onder meer de pijlers weer opgevuld met zand.


Cosmos Update - No Man's Sky

Original Mastodon Post

No Man's Sky Cosmos: nomanssky.com/cosmos-update/

Discussion: news.ycombinator.com/item?id=4

@mattblaze Yes. Here are some more:

Original Mastodon Post

@mattblaze Yes. Here are some more:

kottke.org

Jason Kottke's weblog, home of fine hypertext products

Vintage Eastern European Matchbox Labels (1950-1980s)

Over on Flickr, Jane McDevitt maintains a huge collection of 20th century matchbox label art from Eastern Europe, over 4000 photos in all. Some of the labels are available as prints. They did a book too, but it’s sold out. It was really difficult to narrow these down to some of my favorites, but I managed.

P.S. I wrote this whole post and then discovered that I’d written about this collection before. But I picked different labels so it’s all good.

Tags: art · illustration · Jane McDevitt

this isn't happiness.

ART, PHOTOGRAPHY, DESIGN & DISAPPOINTMENT INSTAGRAM ★ ELSEWHERES

The deep water is unmerciful, Elizabeth Shull

The deep water is unmerciful, Elizabeth Shull

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits

At least four espionage groups, most with suspected links to China, are using a new exploit kit that chains two Chromium-based browser flaws and one Microsoft Windows bug to break into organizations' networks in the US and Southeast Asia. Mark Kelly, a threat researcher at email security shop Proofpoint, told The Register that the researchers don't know exactly who was targeted, nor how, and so far the damage appears limited. “In terms of organizations targeted, we saw fewer than 20 organizations globally targeted across the activity highlighted," he said. "However, the true number is almost certainly higher than this.” Proofpoint’s threat hunters spotted the new kit, which they named BlueMoon, and said its first observed use started on August 28. This is when a Beijing-backed crew they track as TA412, also known as Violet Typhoon and APT31, used BlueMoon to “repeatedly” target non-governmental organizations (NGOs), mining companies, and physical commodity trading firms in the US. TA412 is a cyberespionage group linked by US authorities to China's Ministry of State Security (MSS), and American prosecutors previously charged seven alleged members with conspiracy to commit computer intrusions and wire fraud, alleging they broke into computer networks, email accounts, and cloud storage belonging to numerous critical infrastructure organizations, companies, and individuals. Just days after Proofpoint documented the late-August activity, “several other espionage-motivated clusters began using BlueMoon, the majority of which have a suspected China nexus,” Kelly and fellow researchers Greg Lesnewich, Konstantin Klinger, Saher Naumaan, Julia Paluch, David Galazin, and Stuart Del Caliz said on Wednesday, noting that there may be other, non-China-nexus attackers using the exploit kit as well. “BlueMoon was developed and deployed rapidly, and shared across multiple threat actors within days,” Kelly told The Register. “This may reflect a reduced cost and barrier to entry for this class of capability, which has historically been rare and high value, as AI agents increasingly enable threat actor exploit development. That is particularly true for open-source codebases such as Chromium, where publicly accessible upstream patches create a ‘patch-gap’ window for rapid reverse engineering and exploit development ahead of downstream stable releases.” A Google spokesperson declined to comment beyond what Proofpoint wrote. Microsoft patched the Windows bug (CVE-2026-85880) on Tuesday, and a spokesperson reiterated that customers who applied that patch are protected. BlueMoon attack chain The kit chains together three vulnerabilities. The first is a V8 type confusion (CVE-2026-85046) flaw that allows remote code execution and affects all Chromium-based browsers, including Google Chrome and Microsoft Edge. Google patched this bug in Chrome on September 3, and at the time warned that it “is aware that an exploit for CVE-2026-85046 exists in the wild.” Microsoft published a security advisory saying it fixed the flaw in Edge Stable version 152.0.4191.62 on September 2. The second is a Chrome V8 sandbox escape. This one also affected all Chromium-based browsers. It does not have a CVE because Google doesn’t issue them for sandbox escapes. Finally, the third bug is a privilege escalation vulnerability in Windows Advanced Local Procedure Call (CVE-2026-85880) that Microsoft patched on Tuesday, as noted above. Redmond also warned that this flaw had been exploited as a zero-day prior to the security update. The Proofpoint researchers also note that both V8 vulnerabilities are what’s called "patch-gap" zero-days at the time of the observed activity. This means they were known and fixed in upstream Chromium source code – a change containing the fix for CVE-2026-85046 was committed on August 7. But they remained unpatched in the latest stable releases of Chrome and Chromium-based browsers available to the public for weeks. “It is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain,” the researchers note. From phishing to browser surveillance The attacks start with a phishing email that tricks victims into clicking on an actor-controlled URL. This triggers the two V8 bugs to allow remote code execution and escape the browser sandbox. The attack chain then exploits the Windows bug to download multiple payloads including browser-surveillance malware, credential-stealing backdoors, and others, depending on the group using the exploit kit. TA412’s first campaign, which began on August 28, used a range of lures. Some of the emails purported to come from university students interested in internships at the targeted organizations, and some were more target-specific exchanges, intended to build trust with the individual before ultimately sending a malicious link via email. In these instances, the exploit chain “ultimately downloaded and ran a loader executable on the infected host, which then installed a malicious browser extension disguised as Google Gemini on the victim's Chromium-based browser,” the team wrote. This browser extension, which Proofpoint tracks as GemStone, allowed the Beijing spies to issue commands through a command-and-control (C&C) channel, steal cookies and other sensitive data, take screenshots, and inject a keylogger into a browser tab. The malware also contains a keyword monitor, which injects an attacker-specified keyword list into the top frame of each page, scans the HTML body for these keywords, and triggers a screenshot if it finds any. A few days later, beginning on September 2, a second China-aligned spy crew that Proofpoint tracks under the temporary group designator UNK_LateNight used BlueMoon to target multiple US aerospace companies. The phishing emails used request-for-quotation lures specific to defense industry organizations, and included links to attacker-controlled domains spoofing a variety of US aerospace companies. These websites also served the BlueMoon exploit kit and ultimately loaded a backdoor called ShadowPad, which has been shared among multiple China-aligned groups since 2019. Around this same time, on September 2, another suspected espionage group that Proofpoint tracks as UNK_DoubleCheck targeted a Vietnamese manufacturing firm with messages sent from a compromised Southeast Asian government email address. The fourth campaign began a day later, and involved suspected China-linked spy crew UNK_QuietRacket using BlueMoon to target government, consulting, and financial-sector organizations in Indonesia and Singapore. These phishing emails used lures related to Indonesian conferences, such as the Indo Startup Expo and Forum 2026 and the World Conference on Creative Economy (WCCE 2026). Proofpoint warns that BlueMoon will likely be used by both cyberspies and financially motivated attackers. “The broader dynamic revealed by this activity - rapid exploit development that leverages the open source patch-gap – is likely to recur beyond BlueMoon as this development model becomes accessible,” the team wrote. ®