VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Bedreigde mot strijkt massaal neer in oosten van Australië

Na sterk Nederlands ploegenspel wint Demi Vollering na het WK ook het EK

Vollering soleert week na wereldtitel naar tweede EK-goud op rij

Mag ook al niet meer: halfnaakt in de klas zitten

Homo-acceptatie is verleden tijd. Vrouwen slaan is prima. Meisjes halfnaakt in de klas is niet goed. Tweederde van de ondervraagden vindt het prima dat er regels komen over wat leerlingen aantrekken: "Zeer korte rokjes en petten in de klas staan boven aan de lijst van kledingstukken die geweerd mogen worden. Zogeheten croptops, waardoor de buik zichtbaar is, en hoodies staan op respectievelijk de tweede en derde plaats. Ook slippers, trainingspakken en joggingbroeken worden genoemd."

Panel Inzicht heeft ook uw plaatselijke geilneef bevraagd: "Driekwart van de vrouwen wil zeer korte rokjes verbannen van school, tegenover bijna twee derde van de mannen. Van de laatste groep vindt de helft croptops te ver gaan. Maar bijna driekwart van de vrouwen vindt dat dit kledingstuk niet thuishoort in de klas."

Het onderzoek is afgenomen onder 18-plussers. Vanzelfsprekend, want waarom zou je niet 65-plussers bevragen over hoe kinderen naar school moeten? Omdat wij hoopvol zijn over zowel de tijdgeest als de jeugd, geloven we dat 18-minners hier volstrekt anders over denken. Er is hoop: "Een kwart is helemaal tegen kledingvoorschriften. Zij spreken van betutteling en vinden dat iedereen vrij moet zijn in zijn of haar kledingkeuze." Bring back geilneef.

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows

The second Anthropic-linked vulnerability known to have been exploited in the wild saw initial activity from an IP address in China targeting vulnerable hosts in the US and Japan. The vuln is a critical authentication-bypass bug in Rejetto HTTP File Server (HFS) that can lead to full admin access and remote code execution. HFS is an open source web file server that previously appeared on the US Cybersecurity and Infrastructure Security Agency’s catalog of Known Exploited Vulnerabilities in 2024. On Wednesday, researcher Zach Hanley at AI pen-testing company Horizon3 said he used Mythos to uncover a new flaw in the file server, now tracked as CVE-2026-61500. If you use Rejetto HFS, be sure to update to v3.2.1 or later, which fixes this and other security flaws. Hanley also published a video showing the steps to exploit HFS and remotely execute code on the server. By the next day, the CVE was under exploitation. “We started detecting exploitation of CVE-2026-61500 in Rejetto HFS this evening,” VulnCheck security researcher Patrick Garrity posted on LinkedIn on Thursday, adding that Hanley and team reported the bug to VulnCheck for CVE assignment. “Our canaries detected an actor in China targeting real vulnerable hosts in the US,” Garrity added. Garrity has been tracking CVEs attributed to Mythos and Project Glasswing, Anthropic’s initiative to give select partners access to the bug-hunting model, since shortly after the program was announced in April. Anthropic claims that Mythos is too powerful to release to the general public (insert evil laugh). As of Friday, Mythos and Project Glasswing have uncovered 286 CVEs, according to Garrity’s tracker, and up until Thursday only one of these bugs had been exploited in real-world attacks. The Thursday night activity originated from one IP address in China and targeted vulnerable servers in the US and Japan, Garrity told The Register. “Today we have seen four hits,” he told us on Friday. These originated from two different IP addresses in the US: 173.239.211[.]248 and 173.239.211[.]249. Both are in the same subnet, and “appear to be coming from a proxy,” Garrity added. China-linked digital intruders routinely use compromised devices as proxies to route malicious traffic and disguise the attackers’ true location, and in April a 10-country security advisory warned of China-nexus cyber operatives using proxy networks “strategically, and at scale.” In his write-up, Hanley said Horizon3 has used Mythos in its vulnerability research – and discovered “many critical vulnerabilities” – ever since the security company joined Project Glasswing in July. Mythos' mad math skillz CVE-2026-61500 highlights a couple of Mythos capabilities that make it really good at uncovering vulnerabilities, according to Hanley. Namely, Mythos excels at mathematical distillations and scientific tasks, especially those relating to computer science and operating systems. Finding this CVE “speaks to Mythos’s capabilities in understanding of mathematics, how it identified an exploitable set of cryptographic missteps, and approached solving the constraints to achieve remote code execution,” Hanley wrote. The security issue stems from how HFS authenticates users. It generates a random value with Math.random() and then passes this value to Koa, the Node.js web framework foundation for HFS. Koa uses keygrip to sign all session cookies with that random value. This means that if an “attacker can derive what the session signing key is, they can forge valid session cookies,” Hanley said. This should not be possible, assuming Math.random() uses a secure pseudo random number generator (PRNG). But V8’s Math.random() did not use a secure PRNG. Mythos discovered that the output of the xorshift128+ algorithm it used was fully reversible – and the application was leaking Math.random() outputs. The model’s analysis claimed that Z3, a Microsoft-developed, publicly available Satisfiability Modulo Theories (SMT) solver, could be used to recover the PRNG seed. Hanley notes that Horizon3’s researchers could not recall seeing an SMT solver used this way to attack a cryptographic flaw in a real application and bypass authentication. “What makes this impressive is that Mythos didn’t just flag the insecure PRNG in isolation – it simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible,” he wrote.®

Formula 1 News

Formula 1® - The Official F1® Website

How Aston Martin 'miracle' earned P12 and P14 for Bahrain GP

After a difficult season, Aston Martin finally got both cars into Q2 for the first time this year at the Bahrain Grand Prix in Malaysia.

What To Watch For in the Bahrain Grand Prix in Malaysia

Chris Medland picks out five key things to keep an eye on when the lights go out on race day at the Sepang International Circuit.

What the teams said – Qualifying in Malaysia

The drivers and teams report back on all the action from final practice and Qualifying for the 2026 Bahrain Grand Prix in Malaysia at the Sepang International Circuit.

What are the tyre strategy options for the Bahrain GP in Malaysia?

Matt Youson takes a look at the different pit stop and tyre options that are available to the teams on race day at the Sepang International Circuit.

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Croatia v England: Nations League football – live

Here’s how Nations League A Group 3 stands going into today’s round of matches. Spain host Czechia later this evening. Once it all comes down, the top two will qualify for the quarter-finals next March.

1. Spain P2 GD+4 Pts 6
2. England P2 GD+1 Pts 3

3. Croatia P2 GD-2 Pts 3
4. Czechia P2 GD-3 Pts 0

Continue reading...

Women given free cycling shorts to prevent upskirting on Oktoberfest amusement ride

Investigation revealed thousands of voyeuristic videos taken on Munich beer festival’s Teufelsrad or Devil’s Wheel

Women have been given free cycling shorts to prevent upskirting on a famous amusement ride at the Oktoberfest in Munich, after an investigation revealed tens of thousands of voyeuristic videos circulating online.

The Teufelsrad or Devil’s Wheel, which rapidly spins around while people try to sit on it for as long as they can, is one of the beer festival’s oldest rides. But many of the videos discovered by German journalists focus on women whose traditional dirndl dresses have ridden up, often showing their underwear.

Continue reading...

MetaFilter

The past 24 hours of MetaFilter

Body Alchemy

Loren Rex Cameron was a pioneering transmasculine photographer whose photography book Body Alchemy has been inspiring since its publication in 1996. In an article in The Believer, Sandy Ernest Allen delves into Cameron's archive to find the man behind the photos and what happened at the end of his life (CW: suicide.)

in the process, he also uncovers that Loren Rex Cameron's aunt was Marjorie Cameron, the occult artist who was married to Jack Parsons, giving new meaning to the alchemy in his book title. And his trans sister, who moved to San Francisco from Arkansas before him, was a member of the Cockettes and appeared in films including Tricia's Wedding, Elevator Girls in Bondage, and Jodorowsky's Holy Mountain. For more, see writer Allen's BlueSky thread (viewable only by those with BlueSky accounts)

Rijnmond - Nieuws

Het laatste nieuws van vandaag over Rotterdam, Feyenoord, het verkeer en het weer in de regio Rijnmond

36 woningen en horeca: na ruim vijftien jaar wordt er eindelijk gebouwd op dit lege terrein

Al in 2012 gingen de oude panden naast het Papendrechtse gemeentehuis tegen de vlakte. Sinds die tijd deed het terrein vooral dienst als uitbreiding van het marktplein. Toch werd er altijd gesproken over de nieuwe invulling van het gebied en inmiddels is het zover: begin 2027 begint de bouw van een nieuw appartementencomplex.

Man op step gewond na botsing met auto

Een man op een step en een auto zijn zaterdagmiddag in Kinderdijk tegen elkaar gebotst. Het ongeluk gebeurde rond 13:00 op het fietspad langs de Molenstraat. De man op de step raakte gewond en is meegenomen naar het ziekenhuis, meldt een 112-correspondent.

Wel.nl

Minder lezen, Meer weten.

Vollering soleert week na wereldtitel naar tweede EK-goud op rij

SENCUR (ANP) - Wielrenster Demi Vollering is voor het tweede jaar op rij Europees kampioene op de weg geworden. De kersverse wereldkampioene reed in het zonnige Slovenië op de laatste beklimming van de Možjanca weg en soleerde de laatste 15 kilometer naar de finish in Šenčur. Landgenote Puck Pieterse won de sprint om het zilver van de achtervolgende groep, voor de Zwitserse Marlen Reusser.

Vollering (29) reed haar eerste wedstrijd in de regenboogtrui, die ze een week geleden veroverde in het Canadese Montreal. Lang kon de Zuid-Hollandse daar niet van nagenieten met de voorbereiding op het EK op het programma. Nederland kwam in Slovenië met dezelfde ploeg aan de start als vorige week, met daarbij alleen Lorena Wiebes als extra helpster. Met de Poolse Kasia Niewiadoma, de Italiaanse Elisa Longo Borghini en Reusser deed ook de rest van de top 4 van het WK mee.

De eerste 90 kilometer na de start in hoofdstad Ljubljana was vlak. De Belgische Margot Vanpachtenbeke en Carina Schrempf uit Oostenrijk kregen een kleine voorsprong van het peloton, dat werd aangevoerd door Nederland.

Finale

De finale bestond uit twee rondes van ruim 20 kilometer met daarin de pittige beklimming van de MoĹľjanca over 2 kilometer Ă  ruim 10 procent. Op die eerste beklimming toonde Reusser zich nog de sterkste, maar de groep met favorieten bleef bij elkaar, al had Vollerings knecht Puck Pieterse het moeilijk.

Bij de tweede beklimming loste Pieterse juist iedereen behalve Vollering en Niewiadoma. Daarop plaatste Vollering een versnelling die haar alleen aan kop van de wedstrijd bracht. Bij de finish stak ze haar armen in de lucht en gebaarde ze naar haar regenboogtrui. Pieterse was vlak daarachter duidelijk de snelste in de sprint, waaraan Niewiadoma door een val niet meer kon meedoen.

Eerdere zeges

Het is de tiende Nederlandse Europese titel in elf edities. Alleen Wiebes won het EK eerder twee keer (2022 en 2024). Vollering is de eerste die haar titel prolongeert.

Vollering domineert dit wielerseizoen met zeges in onder meer de Tour de France, Giro d'Italia, Luik-Bastenaken-Luik, de Ronde van Vlaanderen en vorige week haar eerste wereldtitel.


Found Slide -- Ira Richolson Collection

Thomas Hawk posted a photo:

Found Slide -- Ira Richolson Collection

I am starting to tell the story about the Ira Richolson collection more here: x.com/thomashawk/status/2106395467127148611

Fog Lifting

Darren Schiller has added a photo to the pool:

Fog Lifting

Sun breaks through morning fog, Adelaide CBD

Gawler Chambers

Darren Schiller has added a photo to the pool:

Gawler Chambers

Main entrance to a grand building now abandoned and decaying

Fog Over Parliament House

Darren Schiller has added a photo to the pool:

Fog Over Parliament House

Fog over the South Australian Parliament House, North Terrace, Adelaide CBD

Scots Church

Darren Schiller has added a photo to the pool:

Scots Church

Scots Church is a Uniting church on the southwest corner of North Terrace and Pulteney Street in Adelaide, the capital city of South Australia. Founded by the Free Church of Scotland, the stone church was one of the early churches built in the new city in 1850, built as the Chalmers Church.