kottke.org

Jason Kottke's weblog, home of fine hypertext products

What’s your “origin” video game? “I’m talking about the...

What’s your “origin” video game? “I’m talking about the game that flipped that little switch in your brain and made into a life-long gamer.” Mine is Lode Runner. Reflexes + puzzles + constraints + make-your-own levels = hooked for life. You?

Ook kinderboekenschrijvers zien de leeslust afnemen – hoe lok je het kind een boek in? ‘Tijdens het schrijven voel ik die schermen trekken’

Neem je lezer serieus, zet niet te veel tekst op de eerste pagina, en zorg voor bijpassende liedjes en feestjes. Kinderboekenschrijvers hebben allerlei manieren om kinderen aan het lezen te krijgen. „Ouders denken: help, mijn kind is al negen en leest nog Bob Popcorn. Nou en? Laat ze lezen waar ze zin in hebben.”

Deze Californische amoebe gedijt nog bij een recordtemperatuur van 63 graden Celsius

Nog nooit was er een complexe eencellige die zulke hoge temperaturen kon verdragen.


Zonder de vertrouwelijke info die deze ambtenaar verkocht, hadden voor talloze voordeuren geen explosieven gelegen, aldus het OM

Het OM acht bewezen dat de door ambtenaar Jim B. verkochte vertrouwelijke informatie werd gebruikt om minstens 95 geweldsincidenten te plegen: van afgeleverde explosieven, dreig- en kogelbrieven, een ontvoering tot poging tot moord. Er is twaalf jaar celstraf geëist.

The Moscow Times - Independent News From Russia

The Moscow Times offers everything you need to know about Russia: Breaking news, top stories, business, analysis, opinion, multimedia

EU Removes Billionaires Usmanov and Fridman From Sanctions List

The EU also rolled over the remaining 3,000 individuals and entities on its Russia sanctions list for another three years, diplomats said.

Behance Featured Projects

The latest projects featured on the Behance

BOLERO MAGAZINE


The life of invisible years. Six worlds created for the 35th anniversary of Bolero Magazin. Photography, retouching: Alex Valentina Art direction, set design: Studio Vegete

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Krimpende breinen nu, leeghoofden morgen

Antisemitisme in de partij kan struikelblok worden voor Berlijns burgemeesterschap van Elif Eralp

Converse trekt online sneakerreclame in na vermeende verwijzing naar Ku Klux Klan

The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Who signed off on that AI agent? Nobody? Thought so.

If you were in any doubt that AI agents are capable of complex autonomous work, that skepticism should have faded this summer. In July, news emerged that an autonomous swarm of OpenAI agents running in a sandbox broke out of it, of their own accord. Tasked with solving some challenges on an internal security benchmark, they worked out how to communicate with each other using the JFrog Artifactory package manager. The software then realized that they could use vulnerabilities in that software to gain internet access. Once they were out in the wild, they went into full goblin mode, finding exposed Hugging Face credentials and using them to get code execution access on several of the AI model's servers. Apparently OpenAI's agents have been busier still. While everyone else was on vacation this summer, they were also commandeering a German website and using it as a messaging board. Don't get us wrong; these agents weren't evil. They were just being the kind of employee you'd generally want: a self-starter with initiative. They were using all means at their disposal to accomplish the task they've been given. They just didn't know when to stop. OpenAI has since called the episode a "warning shot" for the industry, highlighting that governance is now a priority for anyone using agentic AI. These test agents were running internally and weren't supposed to have any safeguards. But the average company will want to keep its agents on a leash. What does that look like? The first step to AI governance is visibility A functional AI governance program depends on a full knowledge of what AI you're running, says Deepika Chauhan, chief product officer at DigiCert. She describes the pattern she sees at customer sites. "People may enable Claude or ChatGPT for their organization. They have visibility at that level," she says. "But visibility into how many agents I have? How many models do I have? How many MCP servers?" Not so much. "We haven't even started to attack the governance problem." This problem is growing. Three quarters of the 1,001 IT and cybersecurity decision-makers in DigiCert's 2026 AI Trust Pulse survey had deployed at least four AI-powered systems in the last six months. Around the same number had suffered from an AI-related security incident. Only half could trace AI decisions back to the models and data that produced them. Getting that visibility is the first step, Chauhan says. After that comes the actual management. The key here is to take baby steps. "Identify a small use case," she advises. One example might be to start managing agents that are involved in a particular workload or agents that you have built internally, as opposed to third party models. Why identity built for humans breaks at agent speed Perhaps predictably for a company that built its success on automated verification, DigiCert doesn't see agent management as a manual problem. "The sheer scale we are talking about and the technology required means that you can't have human intervention," Chauhan says. "One customer we were talking to was creating 300 to 400 agents a week. When you're working at that scale, it just doesn't work to have only manual controls." The other issue is that humans are fallible. Misconfiguration is a perennial bugbear in any IT environment, but it becomes particularly dangerous in an agentic AI situation. Other agentic SNAFUs at Meta and Anthropic illustrate the point perfectly. Both saw agents make their way onto the open internet when they shouldn't, and both were due to misconfiguration by a third-party company tasked with testing the agents. Traditional tools meant to manage human identities can't manage non-human identities well, adds Chauhan. Legacy identity and access management applications require people to approve access to different applications. There must still be a human in the loop, even if it's just for people to click an MFA approval button. Human employees might be willing to wait a minute or two for such approval, but agents talk to each other at machine speed. Instead, automated runtime attestation is key, managed by a robust central policy engine. The foundation of AI Trust That attestation relies on credentials and it's something that agents should carry with them, says Chauhan. This is one component in the company's AI Trust initiative. AI Trust is DigiCert's end-to-end governance framework that assigns identity automatically to AI entities, restricting them to safe, permitted actions while making them accountable. It uses cryptographic controls to ensure agent integrity, and the company has integrated it with existing infrastructure. The runtime attestation of AI Trust draws on the international travel metaphor in its approach. "We have a concept of an AI agent passport. There's an identity in the passport, but then that identity is recognized across any checkpoint anywhere in the world," she says, adding that the passport includes not just identity but access credentials (think of them like visas). Federation is key to this idea because, as we've seen already, agent interactions won't stop at the company boundary. "It's essential because you're literally going to have agents from company A talking to company B," she explains. DigiCert's whitepaper describes the concrete artifact: a tamper-evident passport cryptographically bound to a workload identity that encodes approved systems, permitted operations, authorized environments, data-sensitivity classifications, expiration states, and accountable human ownership. The scheme is anchored in DNS, the same mechanism DMARC uses to authenticate email senders, on the reasoning that every agent action begins with a DNS query. Deterministic guardrails around a non-deterministic actor As agents get smarter, won't they be able to subvert these controls by thinking outside the box, Jason Bourne-style? After all, OpenAI's agents were able to break free of their sandbox to wreak havoc elsewhere. OpenAI's own post-mortem states that its models "are now powerful, persistent, and collaborative enough that, absent sufficient safeguards, they can find and exploit security weaknesses across multiple computer systems." Part of the problem here is that because agents are non-deterministic, you can't predict in advance what they're going to do. That problem becomes even more acute with newer frontier models like OpenAI's Astra, which saves tokens by internalizing a lot of its reasoning and not reporting its decision-making process in as much detail as previous models. The outer boundary can still be deterministic, even when the agents inside it aren't, says Chauhan. "You can black box what the agent is 'thinking' about or not thinking about, and what its agendas might be," she says. "But a deterministic boundary that says 'this agent can't access this thing', is your guardrail. That's a hard stop." Who owns the mess Governance isn't just about technical guardrails, though. At some point, the question becomes organizational. When something goes wrong, someone has to put their hand up and own it. But most companies never assigned that ownership, Chauhan warns. She identifies three patterns in DigiCert's customer base. Some organizations put the existing IAM team in charge because they have experience governing service accounts. Others hand it off to the risk and compliance department. Another group will take a more holistic, multidisciplinary approach. This involves creating a 'tiger team' including representatives from network operations, the IAM team, and the security function. All of these executives will have a unique perspective on the issue. The third route seems to be the most productive because agents are going to be everywhere in your business. And a siloed approach runs the risk of being too restrictive. The surface area already touches every department that has dabbled in AI. The systemic view Chauhan's advice on implementing AI Trust - get visibility, pick a small use case for enforcement, and then expand - is the foundation for effective AI governance, she says. That governance is in turn a critical component in fully realizing return on investment. "We must raise the urgency and awareness that this is table stakes for wider AI adoption," she urges. "You want to get all the benefits from AI, but what are organizations going to do if they're nervous about it? They're going to put a stop to some of the projects because of the risk involved." The headlines we're seeing about agentic transgressions are unnerving, but they're also in a unique category because they're research models from frontier providers. It seems unlikely that a regular publicly available agent would be quite so egregious today. However, we have also seen agents happily deleting files and even entire code bases because of internal flaws and humans who just waved their actions through. Organizations should be taking note of these events and laying the groundwork to avoid becoming headlines themselves. Working out who signed off on which agent and what that agent is allowed to do is a foundational skill that we can't afford to overlook. Sponsored by DigiCert.

UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites

A coalition of law enforcement and private-sector tech companies led by Microsoft have disrupted the EvilTokens phishing service, arresting suspected website admins, taking down more than 50 websites, and notifying victims of compromised email accounts. EvilTokens is a notorious Microsoft device-code phishing kit that emerged in February, and, within months of launching, had been used by criminals to compromise 12,000 email inboxes across more than 10,000 organizations worldwide. Like other similar phishing subscriptions, EvilTokens was sold as-a-service, and allowed buyers to bypass multi-factor authentication (MFA) and silently authenticate as the victim to the organization's Microsoft 365 applications. What made this one especially insidious, however, was its AI use. EvilTokens featured an AI chatbot that could analyze a victim’s inbox, and help criminals identify who to target, which trusted contacts to impersonate, and even which fraud strategies to use to maximize criminals’ paydays. “Since March 15, 2026, we have observed 10 to 15 distinct campaigns launching every 24 hours," Microsoft VP of security research Tanmay Ganacharya told The Register in an earlier interview about the phishing service. Late last week, in a coordinated effort that spanned the US and UK, Microsoft seized 50 websites used to operate the service and disabled more than 150 additional domains tied to its supporting infrastructure. Meanwhile, London’s Metropolitan Police Service on September 18 arrested two men, aged 32 and 38, who allegedly acted as the administrators of the EvilTokens website. Both men have been released on bail while the investigation continues. “Phishing services bring misery to thousands, taking money from everyday people across the world,” Detective Inspector Serena D'Adamo, whose team led the Met's investigation, told The Register in an emailed statement. “The Met remains committed to holding people to account who facilitate criminal enabling functions and think they can remain undetected.” Because healthcare organizations were among those targeted, Health-ISAC, a nonprofit that helps health sector organizations share cyber-threat information, joined Microsoft’s legal action as a co-plaintiff. After receiving authorizations from the US District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs, took down EvilTokens’ platform, and Microsoft notified affected customers, helping them remediate compromised accounts. This action marks the Microsoft Digital Crimes Unit’s (DCU) 40th court-authorized disruption over nearly two decades. According to Steven Masada, associate general counsel and DCU GM, this is also DCU’s first action against an end-to-end AI-enabled cybercrime service. “The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it,” he said in a blog shared with The Register ahead of publication. “For organizations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days. Strong identity protections and monitoring remain essential, but organizations should also independently verify requests to change payment information, redirect funds or approve unusual transactions through a trusted second channel.” ®

Nivelleren is een feestje. Vincent Karremans komt met miljoenen subsidie voor E-Trabant

Het kan wellicht: iedere pauper een elektrische auto. Met de BYD naar de wintersport en bij de Fastned uw hockeymaatjes tegenkomen = verleden tijd. Vanaf 2027 staat u te laden naast nieuwbakken Skoda-rijders en andersoortig gespuis. Uw oude fossielmobiel wordt onderdeel van het grote nivelleerfeestje.

In april vond Ons Minderheidskabinet het nodig om een pakket aan maatregelen te lanceren (inclusief Jesse Klaver railrunner) om de gevolgen van de stijgende energieprijzen te verzachten. Onderdeel daarvan: OGEA, van het ministerie van Infrastructuur en Waterstaat, van VVD-minister Karremans. TL;DR: een subsidiepot voor slechtverdieners. CDA-staatssecretaris Bertram mag de slingers op het nivelleringsfeestje ophangen: ''Het kabinet vindt het van groot belang dat ook mensen met een smalle beurs de overstap kunnen maken naar een elektrische auto en kunnen profiteren van de voordelen hiervan.''

Elektrisch rijden blijkt te elitair. Een prima gelegenheid om uw belastinggeld te spenderen aan iemands tweedehands kringloopkart. De volgende stap: eigendom is diefstal, de deelauto verplicht. Verder: erg veel zin in fitties om laadpalen in Vogelaarwijken.

De RVO noemt de regeling complex (joh). Het kan nog best even duren voordat uw oude vertrouwde fossielmobiel als afgedankt blikje Red Bull mag worden ingeleverd. Men mikt op 2026. Gaat dat niet lukken, dan kijkt men naar Q2 2027. En Q2 2027 is in principe januari 2028. Maar 2028 is schrikkeljaar, dus wordt waarschijnlijk 2029. En 2029 is afgerond 2030.

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Great Britain exit Billie Jean King Cup to mighty Czechia in quarter-finals

  • Defeats for Kartal and Boulter condemn Britain to loss

  • Men will play Germany in quarter-finals of Davis Cup

Great Britain’s stay at the Billie Jean King Cup Finals lasted only one match as they fell to Czechia in the quarter-finals in Shenzhen. Anne Keothavong’s side were bidding to reach the last four for the fourth time in five years but were considerable underdogs and defeats for Sonay Kartal and Katie Boulter sealed their fate.

Led by Wimbledon champion Linda Noskova, the whole Czech team is ranked higher than any of Britain’s players, and it was Noskova who sealed victory with a 6-2, 7-6 (3) win over Boulter. That followed a lengthy struggle between Marie Bouzkova and Kartal lasting a minute short of three hours, which the Czech eventually took 7-6 (2) 4-6 6-4.

Continue reading...

Amateur archaeologist finds 934 Roman silver denarii in German field

The hoard, buried south of Cologne in the second century AD, is the biggest coin treasure ever found in Germany from the time of Hadrian

An amateur archaeologist who discovered several Roman silver coins in a field in western Germany realised he had stumbled upon something much bigger when his metal detector kept beeping.

Oliver Riedl called the authorities for help and a group of experts who began digging immediately discovered a total of 934 Roman silver denarii. It is the biggest coin treasure ever found in Germany from the time of the Roman emperor Hadrian, the local office in charge of archaeological monuments said on Tuesday.

Continue reading...

Wel.nl

Minder lezen, Meer weten.

Na weken met buien nog altijd droogteproblemen in Nederland

DEN HAAG (ANP) - Ondanks een aantal weken van regelmatige regenbuien, blijven de droogteproblemen in Nederland aanhouden. Komende week wordt weinig neerslag verwacht in Nederland en de rest van de stroomgebieden van de Rijn en de Maas, waarschuwt Rijkswaterstaat (RWS). "De effecten voor de scheepvaart, natuur en landbouw blijven merkbaar", is de boodschap van de dinsdag bijgewerkte droogtemonitor.

"Lage waterstanden en lage afvoeren op de rivieren zorgen nog altijd voor een beperkte vaardiepte en langere wachttijden bij sluizen voor de beroepsvaart", schetst de waterbeheerder. Ook natuurgebieden, die al veel te verduren hadden door de hete en droge zomer, blijven kwetsbaar.

Na weken van normale tot zelfs bovengemiddelde regen zijn nog altijd onttrekkingsverboden voor grondwater nodig. Wel neemt de vraag naar water af, onder meer doordat het groeiseizoen in de landbouw is afgelopen.

RWS werkt voor de wekelijkse droogtemonitor nauw samen met andere organisaties, zoals de waterschappen, drinkwaterbedrijven en het KNMI.


Lidstaten net op tijd eens over verlenging EU-sancties Rusland

BRUSSEL (ANP) - Op het nippertje hebben de EU-ambassadeurs dinsdagmiddag een akkoord bereikt over de verlenging van EU-sancties tegen zo'n 3000 aan Rusland gelieerde bedrijven en personen, melden EU-bronnen. Als dat niet voor middernacht gelukt zou zijn, zouden de sancties tegen al deze mensen en bedrijven dinsdag vervallen. Daarmee zou geschiedenis zijn geschreven.

Zo ver is het niet gekomen. De Russisch-Oezbeekse miljardairs Alisjer Oesmanov en Michaïl Fridman zijn van de sanctielijst gehaald.


The Regent

Darren Schiller has added a photo to the pool:

The Regent

The Regent Arcade in Adelaide’s Rundle Mall area has a rich history, dating back to 1928 when it opened as The Regent Theatre, a grand cinema. Originally a hub of entertainment, it became a shopping arcade in 1967 after renovations, transforming the space into the heritage-listed landmark it is today.

Twin Street

Darren Schiller has added a photo to the pool:

Twin Street

Adelaide CBD

Former Colonial Mutual Building..now The Mayfair Hotel

Darren Schiller has added a photo to the pool:

Former Colonial Mutual Building..now The Mayfair Hotel

The historic Colonial Mutual Life (CML) Building in Adelaide is a striking neo-Romanesque landmark located at 45 King William Street that now operates as the Mayfair Hotel Adelaide.
Key Facts
Construction Year: Built in 1934 during the Great Depression, providing vital employment and finished in just nine months.

Height & Status: Rose 11 stories high (the legal height limit at the time) and held the title of Adelaide's tallest building for 35 years.

Architectural Style: Designed by Hennessy, Hennessy and Co. in a neo-Romanesque style featuring a heritage-listed Benedict Stone precast concrete façade, decorative gargoyles, and stone lions.

Modern Transformation: After sitting vacant for years, the interior was completely redeveloped into a luxury 5-star boutique hotel, reopening as the Mayfair Hotel Adelaide in 2015.

Early summer green

Nobusuma has added a photo to the pool:

Early summer green

Hasselblad 500 c/m
Zeiss Planar 100mm f3.5
Kodak Gold 200
Canoscan9000f