Allianz Arena

Peter Kernwein posted a photo:

Allianz Arena

Fröttmaning

Peter Kernwein posted a photo:

Fröttmaning

Fröttmaning

Peter Kernwein posted a photo:

Fröttmaning

Fröttmaning

Peter Kernwein posted a photo:

Fröttmaning

Fröttmaning

Peter Kernwein posted a photo:

Fröttmaning

Fröttmaning

Peter Kernwein posted a photo:

Fröttmaning

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Microsoft N1Xes Intel in favor of Nvidia's shiny new SoCs in Surface Laptop Ultra

Look out, Intel! Microsoft released its first Surface notebook powered by Nvidia's RTX Spark system-on-chip (SoC) during an event in San Francisco on Wednesday. The Surface Laptop Ultra is one of several new Copilot+ PCs powered by the N1X chip that Microsoft says is aimed at "builders," which are available for preorder starting today and expected to begin shipping next week. The machine is arguably the vehicle for a slew of new AI features including hybrid compute functionality that dynamically routes workloads to on-device or cloud models depending on factors like connectivity, privacy, cost, and complexity. The aluminum clad system largely keeps with Microsoft's existing design ethos. It features a high-res, 15-inch mini-LED display capable of reaching a peak brightness of 2,000 nits in Microsoft's signature 3:2 aspect ratio, a standard ten-keyless keyboard layout, haptic trackpad, and a slew of ports including one you won't find on a MacBook Pro. Connectivity includes three USB-C ports, including one equipped with magnets for MagSafe-like connectivity, full-size HDMI, an SD card reader, and a solitary USB-A port because after more than a decade still can't shake the aging connector. But arguably the notebook's most interesting feature is the inclusion of Nvidia's RTX Spark N1X SoC. As we reported earlier this year, these aren't exactly new chips. The N1X is based heavily on Nvidia's now year-old GB10 platform, with a few CPU and GPU cores fused off on lower end models to meet pricing. This tells us that the Surface Laptop Ultra should ship with either an 18- or 20-core CPU designed by MediaTek and Arm and an Nvidia Blackwell-based RTX GPU with between 5,120 and 6,144 cores. In terms of memory, Microsoft says the notebook can be equipped with up to 128 GB of memory, enough to serve large language models up to 284 billion parameters in size, if you can live with just 1.6 bits of precision. As we've previously covered, the GPU is a pretty potent one with a peak theoretical throughput of 1 petaFLOPS at 4-bit precision, not that you're likely ever to see that in many real world workloads. Nvidia's marketing team is leaning on support for 2:4 sparsity to hit that target, so it can theoretically achieve that figure. Unfortunately, almost none of the AI inference workloads anyone cares about these days actually take advantage of the functionality. As a result, the chip's peak performance is actually closer to 500 teraFLOPS, which still gives it an edge over competing chips like AMD's Strix and Gorgon Halo processors. Local AI inference, as we mentioned earlier, is a major selling point for this class of hardware, though Microsoft was also keen to highlight the GPU's capabilities for more traditional creative and gaming workloads, claiming 60 FPS in the latest Gears of War release. We suspect that Nvidia's DLSS AI upscaling tech is probably doing the heavy lifting here. In order to keep the system from overheating, Microsoft says that the Surface Laptop Ultra features a beefed up cooling system with 2.5x more capacity than past Surface notebooks. From the renders we've seen, the extra cooling comes courtesy of a big fat vapor chamber. The Surface is expected to begin shipping next week at a starting price of $2,599 for the poverty-spec gray variant with the lower-end 18-core N1X, 24 GB of unified memory, and 512 GB user serviceable SSD. Jumping up to the 20-core chip, 128 GB of memory, and 1 TB of storage will set you back $5,899, and assuming memory prices haven't gone up even more by then. Alongside the Surface Laptop Ultra, Microsoft also announced a mini PC style development kit based on the N1X priced at $5,999. While by no means cheap, it's still cheaper than the similarly specced DGX Spark, which now retails for $6,950, albeit with 4TB of storage rather than 2TB. The DGX Spark also runs a lightly modified version of Ubuntu, which might be worth the premium for some. If your heart is set on a high-memory config and you don't want to wait for the Surface Laptop Ultra to come back in stock, Lenovo, Asus, Dell, MSI, and HP all are launching similarly specced systems over the next week or so. And if Nvidia isn't your style, it's worth mentioning that AMD has its own AI-tuned chips, which now support up to 192 GB of unified memory, and we strongly suspect will support many of the same hybrid AI features rolling out to Windows 11 over the next few months. ®

Attackers hijacked top-level domains, minted fake security certs for Google and other orgs

Imagine going to a Google website at its correct URL, only to be redirected to a crim's illegitimate copy. Attackers hijacked top-level domains, allowing them to alter DNS records and mint fraudulent HTTPS certificates for several Google domains, and those belonging to other organizations. Google said it became aware of the series of attacks last week in the .gh (Ghana), .sl (Sierra Leone), and .as (American Samoa) country-code top-level namespaces (ccTLDs). “During these hijacks, attackers modified authoritative DNS records and obtained unauthorized HTTPS certificates covering several Google domains, as well as domains belonging to other organizations,” Google security warned on Tuesday. Google did not say which specific domains or organizations were affected. The attacks did not compromise Google’s systems, and Chrome quickly blocked suspected counterfeit certificates across the affected ccTLDs - meaning Chrome browser users are already protected - according to the Chocolate Factory. “Due to the nature of the attacks, we have no reason to believe the Certification Authorities (CAs) that issued the impacted certificates did anything wrong,” the alert said. These types of attacks allow criminals to impersonate legitimate organizations and websites without triggering any browser security alerts. The attacker controls the traffic routing (via DNS) and the private key associated with the unauthorized certificate, which means they can potentially intercept or modify data sent by users to the impersonated site - and abuse the trusted organization's brand to distribute malware or conduct phishing attacks. “While Chrome took steps during these incidents to identify and block suspected unauthorized certificates across the affected ccTLDs, browser-side intervention should not be relied on to protect your users,” Google warned domain owners. “Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users.” To ensure that their domains and users are protected, Google recommends ongoing monitoring of Certificate Transparency (CT) logs across all of an organization’s domains, including parked or regional ccTLD properties. This provides near real-time alerts whenever someone obtains a certificate for one of your domains. And if you operate a domain in .gh, .sl, or .as, definitely review recent CT log entries for unexpected certificates. Organizations can also publish restrictive Certification Authority Authorization (CAA) DNS records, which allow domain owners to specify which CAs are permitted to issue certificates for their domains. While this won’t stop certificates from being issued during a DNS hijacking attack, it helps safeguard domains after DNS control is restored. Google recommends CAA policies that restrict issuance to specific authorized accounts and validation methods and prevent attackers from using cached validation state to mint new certificates after a hijacking ends.®

Browser-in-browser attacks use fake Meta Muse Ad lure to steal credentials

A phishing campaign targeting advertising managers by impersonating Gemini, Claude, ChatGPT, Perplexity, and Manus to steal credentials and multi-factor authentication (MFA) codes has added a fake Muse Ads product to its lure lineup – just eight days after Meta launched its personal AI agent. Meta announced Muse on September 8, and by September 17, a very convincing website – museads.ai – for a product called Muse Ads that promised to help advertisers reach buyers and run sponsored placements popped up online. “The operators already had the platform, so adapting it to a new brand can take minutes,” Oleg Zaytsev, lead security researcher at Island, told The Register. “The striking part is how quickly they turned a timely announcement into a credible reason for someone to act. The same platform could then be repackaged around other familiar tasks, from connecting a business tool to claiming a refund or applying for a job.” The security startup spotted the Muse Ads webpage, and upon digging into the scam uncovered that just the page was new. “Its code, from the sign-in forms to the fake browser window, came from a wider operation that had already run fake ad products for Gemini, Claude, ChatGPT, Perplexity, and Manus,” Zaytsev and fellow Island researcher Ofek Ronen wrote in a blog post published Tuesday. All of these products served as lures for browser-in-the-browner (BitB) attacks designed to trick agency staff, media buyers, and manager-account administrators into handing over their advertising account credentials – along with stored payment methods and client accounts – to digital thieves. “For victims, the potential cost is loss of access to an advertising account, unauthorized ad spend, and exposure of linked client accounts,” Zaytsev told The Register. How the scam works BitB is a clever phishing technique originally detailed by a researcher called mr.d0x in 2022. It involves building a fake login window directly inside a legitimate one. The fake window looks like the real thing, featuring an address bar, title, and URL, but it's just an overlay to steal users’ credentials. According to Zaytsev, this one has likely proved very lucrative for its criminal operators, with hundreds of victim submissions to the platform, and activity still ongoing. “From one frontend alone, we observed submissions involving roughly 200 distinct email addresses over about a month,” he told us. “The operators used the same platform across many similar sites, so we estimate the campaign-wide volume is substantially higher.” Each phony ad product has its own page, with ChatGPT promising users a Monday Google Ads brief, Gemini offering manager account and linked-client support, Claude an advertising portal, Perplexity pitching campaign planning and spend audits, and Manus providing a private Meta integration. Each fake product page also has a “connect” button. When the victim clicks “connect,” it opens the browser-in-browser overlay, with a fake address bar showing accounts.google.com, or an Okta tenant to gain the victim’s trust. The real browser, however, stays on the phishing domain and steals credentials when the victim types them in. A human operator running the campaign sees each submission and chooses what the victim sees and is prompted to do. This includes asking for another password, requesting an SMS or Okta authenticator code to bypass MFA, showing a Google approval code or Okta push request, or displaying a QR code. The platform supports Google, Meta, TikTok, and Okta workflows, and the browser overlay adapts to whatever the victim runs: Window, macOS, iOS, ot Android, and even mimics Safari’s URL pill, Chrome’s custom tabs, and a dark mode. And while the researchers told us they haven’t identified the people operating the kit or found a name under which it’s sold, the operators did expose older source code through misconfigured public GitHub repositories that connected this to a campaign to a larger operation. In addition to the AI ad pages, this operation also used fake refund claims and job recruitment sites as lures with separate builds for Adidas, Google Careers, Robert Half, Tesla, and Louis Vuitton. All of these pages run on one Next.js and Socket.IO stack. Many of the pages also used Vercel frontends with Railway or Render services behind them for state and commands. “A new brand or polished page doesn’t necessarily mean a new attack. Operators can change the lure quickly, but the workflow still has to move someone onto a site they control, collect credentials, and steer them through authentication,” Zaytsev said. “Security teams should maintain a continuous baseline of trusted domains, check the real browser address, and connect similar behavior across different sites,” he added. “Attackers can generate a convincing website quickly; building the domain history and reputation of a legitimate service is much harder. AI can help defenders keep pace with AI-generated websites, especially as they become more convincing and appear more quickly.”. ®

Wel.nl

Minder lezen, Meer weten.

Rubio: westerse beschaving staat op keerpunt

ATHENE (ANP/AFP) - De Amerikaanse minister van Buitenlandse Zaken Marco Rubio heeft Europa tijdens een toespraak in Athene opgeroepen om uit zijn "lange sluimerstand" te ontwaken en zichzelf te herpakken. Volgens hem staat de westerse beschaving op dit moment op een keerpunt tussen "nationale macht" en verval.

"Wij geloven dat Europa uit zijn lange sluimer kan ontwaken en het vuur kan laten herleven dat hier millennia geleden werd aangestoken", zei Rubio op een heuvel tegenover de Akropolis. "Overal op dit continent zijn we getuige van wat hopelijk het begin is van een generatiewisseling." Hij verwees onder meer naar de verhoogde defensie-uitgaven bij NAVO-landen.

Rubio greep de locatie van zijn toespraak aan om een verband te leggen met beschavingen uit de oudheid. Volgens hem begrepen de oude Grieken ook al "dat macht niet alleen betekent dat je over de middelen beschikt om jezelf te verdedigen, maar ook dat je geloofwaardig overkomt door te laten zien dat je bereid bent die middelen in te zetten".


this isn't happiness.

ART, PHOTOGRAPHY, DESIGN & DISAPPOINTMENT INSTAGRAM ★ ELSEWHERES

East of Eden, Valerio Geraci



East of Eden, Valerio Geraci

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Ondanks kritiek over ‘repressief optreden’ politie blijft Franse premier achter ordediensten staan

Maricarmen (87), de vrouw die het symbool werd van de Spaanse wooncrisis, overleden

Franse regering zit klem tussen meerdere crises, premier blijft achter optreden ordediensten staan

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Houthi forces appear to make slow advance in south-west Yemen

Group’s fighters hit key airport in Aden with explosive moments before plane from Cairo was due to land

Houthi forces appeared to be making slow advances on Wednesday in south-west Yemen, approaching the city of Taiz and firing a missile and an explosive towards the airport in Aden, the chief international hub of the Saudi-backed government.

The explosive hit the key airport moments before a plane was due to land. The British ambassador to Yemen, Abda Sharif, said the attack could have endangered thousands of people. It forced the flight – from Cairo – to be diverted to Jeddah and led to a review about the safety of flights in Aden.

Continue reading...

EU drops sponsorship of disinformation conference at Trump officials’ request

Lithuania and Canada were also pressured to withdraw, and days before #Disinfo2026, logos were wiped off website

The Trump administration pressured multiple countries to withdraw their sponsorship of a leading European conference on disinformation, with Canada, Lithuania and the EU’s diplomatic service subsequently agreeing to do so, the Guardian understands.

The conference, #Disinfo2026, taking place Wednesday and Thursday, is the annual meetup of Europe’s counter-disinformation community and has drawn hundreds of researchers, journalists, technologists and policymakers to a hotel in Vilnius, Lithuania. It is run by an independent Brussels non-profit, EU Disinfo Lab.

Continue reading...

Judge orders officials to preserve all evidence tied to Christa Pike’s botched execution

Judge tells Tennessee officials all items in execution room must be saved as Pike remains restrained in hospital bed

A judge ordered Tennessee officials on Wednesday to preserve all evidence related to the botched execution attempt on convicted murderer Christa Pike, as it emerged that the state has refused pleas from medical staff to allow her to be unshackled from her hospital bed.

At a hearing in Nashville on Wednesday, judge I’Ashea Myles said: “Anything that was in the actual room” during the attempted execution a week ago must be preserved by the state, including all drugs, intravenous lines and tubing used in the death chamber.

Continue reading...

DNA Lounge: Wherein it is Spooky Season

Lots of stupid shit going on lately, but let me try to talk about some good stuff for a change... It's October, and that means that Ribley the Skeleton is back up, and we have a full month of Halloween goodies for you. Let's do this kind-of out of order to hit the big ones first:

Halloween Week:

October Pre-gaming:

We also have burlesque, of course:

"...and, Frog."

Hallucination is a feature…

Not a bug.

Het bericht Hallucination is a feature… verscheen eerst op ICT en Onderwijs BLOG.

Juice

I need to push some updates to the remote sensing instruments, which are there to measure the surface and definitely not do anything else.