The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

Microsoft catches hackers exploiting Zimbra bug before disclosure

Attackers were poking at a critical Zimbra mail server bug weeks before it was publicly disclosed, and then moved on to steal credentials, raid mailboxes, and take deeper control of compromised systems. Microsoft Threat Intelligence said it tracked exploitation of CVE-2026-73570, an unauthenticated command injection vulnerability in Zimbra Collaboration Suite that gives attackers a potentially easy route into exposed mail servers. No stolen password or unfortunate employee clicking a dodgy link is required. An attacker can send a specially crafted email to a vulnerable internet-facing server and potentially run commands, though Redmond notes the flaw affects only servers running Zimbra's optional SNMP monitoring package with notifications enabled. Zimbra fixed the flaw in version 10.1.20 on July 20, but CVE-2026-73570 wasn't publicly disclosed until August 13. Between July 28 and August 7, Redmond spotted two different scanning tools probing the same part of Zimbra later used in attacks. At first, the activity appears to have focused on finding vulnerable servers and testing the flaw. The attackers used a collection of common network utilities to make vulnerable systems call back to infrastructure they controlled, confirming they could execute commands. Once they found servers that played ball, things got messier. Microsoft's investigation found attackers deploying web shells and reverse shells, escalating their privileges, installing tools for persistent remote access, and running malicious code directly in memory. Some even tidied up after themselves. Microsoft said attackers temporarily changed permissions on public directories to plant web shells, then restored the original settings afterward in an apparent attempt to make their meddling harder to spot. The intruders also explored the wider Zimbra environments they landed in, identifying other mail servers and looking for trusted connections they could use to move between them. In some cases, existing SSH relationships between Zimbra systems gave them a route to neighboring servers. On at least one compromised machine, attackers turned their initial foothold into root access. They then set things up to keep running commands with the highest privileges without needing a password. Mailboxes were, unsurprisingly, also on the shopping list. Microsoft said attackers hunted for Zimbra credentials and authentication secrets that could potentially be used to access user accounts. One malicious tool it uncovered was built specifically to extract service account credentials and pull mailbox information from Zimbra's databases. In another incident, attackers bundled recent mailbox backups into an archive and tried to ship the haul to Azure Blob Storage using Microsoft's own AzCopy utility. Microsoft said it couldn't confirm from the evidence available whether the transfer actually succeeded. The company saw affected organizations across multiple regions and industries, with the attacks ranging from automated exploitation to more deliberate hands-on-keyboard activity. It hasn't attributed the activity to a particular crew. Admins running versions earlier than Zimbra 10.1.20 should update to 10.1.20 or later, while those unable to patch can reduce their exposure by removing the optional SNMP package or disabling SNMP notifications. Attackers, meanwhile, appear to have gotten there early, with Microsoft spotting probes for the flaw more than two weeks before it was publicly disclosed. ®

Wel.nl

Minder lezen, Meer weten.

Bizar: meer dan de helft van de Nederlandse jongeren rijdt zonder rijbewijs

Zonder rijbewijs achter het stuur. Voor sommige jongeren lijkt het misschien een onschuldig avontuur, maar de gevolgen kunnen enorm zijn. Een paar weken geleden werd een 13-jarige jongen aangehouden die met de auto van zijn ouders de weg op ging en meerdere keren in de berm belandde. Uit een nieuwe flitspeiling van TeamAlert onder jongeren tussen de 12 en 25 jaar blijkt dat dit geen losstaand incident is: jongeren doen dit vaker.

Meerderheid jongeren zonder rijbewijs rijdt wel eens auto

Autorijden zonder rijbewijsbezit komt veelvuldig voor onder jongeren. De respondenten in dit onderzoek geven aan dat zowel zijzelf als hun vrienden het doen. Bijna 6 op de 10 jongeren zonder rijbewijs hebben zelf achter het stuur gezeten. Vaak is dit niet eenmalig, bijna een kwart van de jongeren doet het zelfs vaker dan 10 keer. Daarnaast hebben 8 op de 10 jongeren minstens één vriend zonder rijbewijs die ooit heeft autogereden. Het blijkt dus de sociale norm te zijn om voor het behalen van het rijbewijs al (meerdere keren) te hebben autogereden.

Medeweten ouders

Het rijden zonder het rijbewijs gebeurt vaak met medeweten van ouders. In bijna 40% van de gevallen mochten jongeren de auto van hun ouders gebruiken. Bij nog eens 23% wisten ouders vooraf al dat hun kind zonder rijbewijs ging rijden en gaven ze daar toestemming voor. Maar in 27% van de gevallen waren ouders hier helemaal niet van op de hoogte. Dat is joyriden: het gebruiken van andermans voertuig zonder medeweten van de eigenaar. Joyriden is strafbaar volgens de Wegenverkeerswet. Ook met toestemming van de eigenaar is rijden zonder rijbewijs natuurlijk verboden in Nederland.

Lage pakkans kan herhaling in de hand werken

De jongeren schatten de kans om gepakt te worden voor rijden zonder rijbewijs laag in. Zes op de tien jongeren denken dat de kans op een aanhouding klein of heel klein is. Een lage ervaren pakkans kan eraan bijdragen dat jongeren het risico en de gevaren van rijden zonder rijbewijs onderschatten en het gedrag blijven herhalen.

Plezier, gemak en oefenen belangrijkste redenen

Plezier is de meest genoemde reden om zonder rijbewijs te rijden: de helft van de jongeren die dit doet, noemt dit als reden. Ook gemak of praktische redenen spelen een belangrijke rol (38%), om bijvoorbeeld even snel boodschappen te doen. Een deel van de jongeren rijdt zonder rijbewijs om ervaring op te doen voor de rijopleiding. Van de jongeren die zonder rijbewijs hebben gereden, geeft 21% aan dit te doen om te oefenen.

Veilige alternatieven voor oefenen

Uit de flitspeiling blijkt dat jongeren behoefte hebben aan mogelijkheden om op jonge leeftijd ervaring op te doen met autorijden. Jongeren noemen onder meer oefenrijlessen op jongere leeftijd en virtuele verkeerstrainingen als alternatief voor zelfstandig oefenen met rijden zonder rijbewijs.

“Uit de peiling blijkt dat jongeren al meerdere keren achter het stuur zitten voordat ze hun rijbewijs hebben gehaald. Dat vinden wij zorgelijk omdat dit risico’s in het verkeer met zich meebrengt,” zegt Sophie Pulles, gedragsonderzoeker bij TeamAlert. “Maar we zien ook dat een deel van de jongeren vooral ervaring wil opdoen. Daar moeten we oog voor hebben en veilige alternatieven voor kunnen bieden.” Met het programma 2toDrive kunnen jongeren vanaf 16,5 jaar starten met rijlessen en vanaf hun 17e hun rijbewijs halen. Hierna kunnen ze onder begeleiding van een ervaren rijder zelf achter het stuur stappen.


The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Rick Ross arrested on domestic battery and strangulation charges

The rapper was arrested in Miami Beach on Thursday, days after an ex-girlfriend accused him of physical abuse

Rick Ross has been arrested on domestic violence charges in Miami Beach, according to local police.

The rapper was booked at Turner Guilford Knight correctional center at 6.10am local time on Thursday and faces one felony count of battery by strangulation as well as a misdemeanor count of battery.

Continue reading...

Finnish PM says suspected break-ins at MPs’ homes could be work of foreign power

Police investigating reports of politicians’ homes being broken into in last year with nothing being stolen

The Finnish prime minister, Petteri Orpo, has said a foreign power could be responsible for a series of suspected break-ins at the homes of several members of parliament.

Police said on Thursday they were investigating multiple reports of MPs’ homes being broken into in the Helsinki area in the last year in which nothing was stolen but subtle signs of breaking and entering were left.

Continue reading...

VK: Voorpagina

Volkskrant.nl biedt het laatste nieuws, opinie en achtergronden

Lezers kiezen hun favoriete 150 woorden van Paulien Cornelisse

We hebben ons als twee pinguïns naast een gletsjer van boeken geschaard. Dat is prima, ik zou het meteen weer doen

Toshijiro (Nenjiro) Inagaki - Yasaka PagOda. #ShinHanga #WoodblockPrint #Ukiyoe #JapaneseArt

Original Mastodon Post

Toshijiro (Nenjiro) Inagaki - Yasaka PagOda.
#ShinHanga #WoodblockPrint #Ukiyoe #JapaneseArt

404 Media

404 Media is an independent media company founded by technology journalists Jason Koebler, Emanuel Maiberg, Samantha Cole, and Joseph Cox.

'Everything but censorship'

'Everything but censorship'

Student journalists meet the moment, as we’ve seen most recently this week. As the Cornell University sexual abuse case highlights the importance of student journalism, public records reveal how schools try to censor on-campus news outlets. Claire Woodcock talked to students and legal experts about how censorship from above impacts their work. “One of the biggest things we’ve certainly found with censors over the years is they want to be called everything but a censor,” one expert said. “What they’re doing is everything but censorship.” 

'Everything but censorship'
Staff of The Alestle. Photo via Marie McMullan.

How Schools and Universities Try to Censor Student Journalists

Student journalists, their advisors, and legal advocates say colleagues and administrators are attempting to undermine student reporting on Jeffrey Epstein, Gaza, and other issues that public institutions would rather not have their reputations connected to.

Public records obtained by 404 Media show administrators taking meetings with parents and alumni when they take issue with student reporting and asking advisors to compromise their professional ethics. They also show escalating tensions between student newsroom staff and administrators, prompting more legal aid requests to advocacy groups. 

This comes as student journalists at The Cornell Daily Sun earned recognition for breaking the “Cornell Seven” story regarding the lawsuit filed in New York’s trial court last month by a Jane Doe accusing current and former Cornell University students of drugging and sexual abuse. The student journalists told The Cut this week that a vague university and campus police statement from nearly two years ago prompted more questions than answers. Such is the basis for most accountability journalism on college campuses. 

The cases we reviewed involved the phase of the reporting process that comes later, where a factual dispute the newsroom has defended or a complaint where the person doesn’t bother to explain what is allegedly wrong with the students’ reporting. 

Read the full story here.

MORE FROM 404 

Look at my lawyer dawg. A New Mexico attorney used ChatGPT to generate briefs that included completely made-up witnesses and testimony while representing a man accused of shooting his wife. When the judges caught him, the lawyer blamed it on his own “stupidity.” I'll say.

Love 2 see “community safety” and cameras in the same sentence. The USPS is putting cameras in mail carrier trucks to “continuously scan roads and signs, map roadways and sidewalks, and improve ‘community safety.’” 

Big tech props up big abuse. The most prominent hosts of non-consensual, AI-generated imagery are supported by some of the biggest web infrastructure providers in the world, getting their hosting, email, advertising, and content management systems from these companies, a new study found. It examines how providers like Cloudflare, Google, Proton, Namecheap, and WordPress help non-consensual imagery sites thrive.  

“Absolute game changer.” A company that makes phone hacking devices claims to have found a way to freeze iPhones in a state that lets cops more easily access sensitive data inside them, according to a video obtained by 404 Media. It’s nice to have our pal Lorenzo Franceschi-Bicchierai on the site! 

People (effective altruists) are being extremely normal about “torturing” (quotes heavily emphasized) an LLM. I don’t think I can sum this situation up in less than 800 words, so just read about the AI Saw torture chamber here.

AROUND THE WEB 

Today in incredible PR pitches in my inbox: “Motorbunny Jack was already a handheld, thrusting sex machine controlled through Fluffer for remote and interactive play. Now, a new Battery Upgrade Kit lets JACK go cordless while still delivering 65–210 adjustable strokes per minute.” Yes, that’s right, they’re doing hot swappable battery packs for the Hole Driller 5000. I mean, just look at the recoil on this thing (NSFW link!).

Later this month, Netflix is releasing a six-episode miniseries called The New Stanford Prison Experiment. Every day Black Mirror gets surpassed in new and exciting ways. 

The Greensboro Police Department did the one thing you do not do: Invoke the wrath of Swifties.

'Everything but censorship'

ICYMI, the White House can’t spell “United States.”

So sorry to link to an Amazon product but unfortunately I love my Kindle. I put off buying a new one for years because I didn’t want to give up the model with page-turn buttons on the sides, because tapping the screen to turn a page sucks for multiple reasons. Apparently there’s a new case that sells my beloved buttons back to me for $80. UGH.

The Interim Computer Museum is restoring Galaxy Game, which was first installed at Stanford’s Tresidder Union in September 1971. The entire blog, if you haven’t seen it and have a few minutes to peruse, is full of very cool old stuff.

We are cursed to forever reinvent Foursquare.

'Everything but censorship'

And finally, the thing that almost made me go back to bed this morning: This story about the piss drinking community’s use of AI by Futurism. One of the greatest one-line ledes I’ve seen in a while: “Pee drinkers are absolutely obsessed with AI.” Has anyone checked on the grandson pee guy lately? 

That’s enough for today. See ya tomorrow for the weekly roundup. 


Colossal

The best of art, craft, and visual culture since 2010.

World of WearableArt’s ‘GLO!’ Is a Celebration of Culture, Nature, and Whimsy

World of WearableArt’s ‘GLO!’ Is a Celebration of Culture, Nature, and Whimsy

Avant-garde style, technology, and performance converge in a fantastical, joyous competition every year in New Zealand. World of WearableArt is a vibrant multimedia competition established in 1987, which continues to invite entrants from around the world to sew and sculpt their most ambitious garments. Whimsical and technically impressive, many of the works call upon cultural traditions, while others tap into nature, futurism, and the chimerical.

This year’s show is titled GLO!, with Kayla Christensen of New Zealand taking the top prize for her work “Sacred Nightfall,” a spectacularly noble, draped floral garment that nods to Indigenous ceremonial cloaks. Additional standouts include the enigmatic “Enchantress” by Ashish Dhaka and an iridescent insect by Katherine Bertram, among many others. Performances of GLO! continue through October 4 at TBS Arena in Wellington. See more on the program’s site.

an elaborate handmade garment with blue flowers and a huge cape-like feature, worn by a performer on a stage with projections of blue flowers in the background
Kayla Christensen, (New Zealand), “Sacred Nightfall”
an elaborate, avant-garde, geometric outfit with a large, minimal mask totally shielding the face and a wide, angular skirt
Glenda Hape (Ngāti Pūkeko, New Zealand), “Te Whare Eke Nei”
an elaborate garment being performed on stage in the form of an insect
Katherine Bertram More (New Zealand), “More”
an elaborate garment being performed on stage in the form of a very long-armed, cylindrical, abstract figure with a disk-like head
Ashish Dhaka (India), “Enchantress”
three elaborate outfits worn by dancers on a stage
Zhiqian Li (China), “Hen”
an elegant, avant-garde, handmade garment with draping, lacy, mushroom cap-like forms on the head and around the body
Lisa Newsome (New Zealand), “Platinum”
two people in a duo costume-garment, one with telephones on her top and the other in an elaborate petticoat-type outfit, talking on one of the phones
Deborah H Carter and Ariel Biagini (United States), Ringing Off the Hook”
an elaborate handmade gown being demonstrated on stage, with elements that look like giant, geometrically folded candy wrappers
Vasemaca Tavola and Czarina Wilson (New Zealand), “MOTHER VAKA”
an elaborate handmade gown with details of black and white swans
Shing Hei (Hong Kong Design Institute, Hong Kong), “My Ugly Duckling”

Do stories and artists like this matter to you? Become a Colossal Member today and support independent arts publishing for as little as $7 per month. The article World of WearableArt’s ‘GLO!’ Is a Celebration of Culture, Nature, and Whimsy appeared first on Colossal.

VIDEO. Plofkraak Zwitserland waarbij 'Nederlander' zwaargewond raakt, schreeuwt als speenvarken

Social

Prachtig en duister videobeeld van de plofkraak in Zwitserland waarbij 'een Nederlander' zwaargewond is geraakt. Z'n twee handlangers lieten 'm achter voor de wouten en gingen er na de gigaknal als een haas vandoor. Nu spreken wij hier nauwelijks Nederkaans, maar op beelden is wel te horen dat hij schreeuwt als een speenvarken. Wat we denken te horen NA DE KLIK, maar u mag uiteraard meefilosoferen in de comments!

Maak de zinnen af & win een magnetron

"Wachten... wachten! Wacht, wacht wacht."

"Geven! Geven!"

Rotje: BIEM

"Pak de tas pak de tas pak de tas."

Auto: toet toet toet!

"Die ... gaat kankerhard man kankermongool!"

"Aaaargh"

"... die deur open he!"

"He kom mee a sahbi!"

"Maak die kankerdeur open!"

"... kankermongool!"

Auto: vroem

Politie: tatu


The Moscow Times - Independent News From Russia

The Moscow Times offers everything you need to know about Russia: Breaking news, top stories, business, analysis, opinion, multimedia

Kremlin Regrets U.S. Still Links Economic Ties to Peace in Ukraine

The comments come after special envoy Kirill Dmitriev was in the U.S. for talks this week.

Rijnmond - Nieuws

Het laatste nieuws van vandaag over Rotterdam, Feyenoord, het verkeer en het weer in de regio Rijnmond

Geen referendum over betaald parkeren in Rotterdam, wel een motie van wantrouwen tegen wethouder

Er komt in Rotterdam geen referendum over het betaald parkeren. Het verzoek daarvoor kwam van Leefbaar Rotterdam maar werd donderdagmiddag weggestemd. Bij een tweede debat later op de dag liepen de gemoederen soms hoog op, er werd zelfs een motie van wantrouwen ingediend tegen verantwoordelijk wethouder Chantal Zeegers (D66).

Politiek blokkeert referendum over betaald parkeren in Rotterdam

Er komt in Rotterdam geen referendum over het betaald parkeren. Het verzoek voor zo’n volksraadpleging kwam van Leefbaar Rotterdam, maar de gemeenteraad stemde halverwege de middag het verzoek weg. Niet alleen de coalitiepartijen waren tegen, ook de Partij voor de Dieren en de ChristenUnie willen geen referendum.

Tennessee voert dit jaar geen doodstraffen meer uit na mislukte executie van 50-jarige vrouw

Amerikaanse staten hebben, mede door een boycot van Europese farmaceutische bedrijven, grote moeite aan de middelen te komen voor voltrekking van de doodstraf. In Tennessee ging een executie woensdag helemaal mis.

Een cipier is áltijd alert, ook buiten de muren van de gevangenis. ‘Ik word er doodvermoeid van’

Meer verantwoordelijkheid, meer werk, met mínder mensen. Dat is al jaren de realiteit voor gevangenbewaarders. Naast nieuwe versoberingen leidt de gewelddadige dood van een collega in Amsterdam tot ontsteltenis. „Ik zie de agressie richting collega’s en mij toenemen.”

Formula 1 News

Formula 1® - The Official F1® Website

Norris explains apology to Colapinto over Baku comments

Lando Norris has shared a further insight into his apology to Franco Colapinto over his post-race comments at the Azerbaijan Grand Prix.

All the stories that got the Malaysia paddock talking

Lawrence Barretto delves into the biggest talking points from media day ahead of the Bahrain Grand Prix.

Best value early bets for the Bahrain Grand Prix

We've assessed the latest betting markets and selected our pick of early bets offering the best value at the Sepang International Circuit.

Northwest entrance

DirtyGlassEye has added a photo to the pool:

Northwest entrance

I know it's cruel to once again keep my recent Tokyo shots behind closed gates, trust me, there are reasons behind it. You will see them eventually I promise.
This is one of the more well known angles to shoot Wakayama Castle from, in fact it was my first heads up this place even existed. But as is the normal theme with this entire trip, I knew the entire thing wouldn't properly span across the sakura season, we would either be too early or eventually be too late, and I fell into the former. It took a long time for ANY sakura to appear in my compositions en masse whatsoever. Regardless I took the composition with what it offered anyways. Maybe I could probably pass this off as a Winter shot.
This castle is hard to make a buck off of, in the 19 months since this trip, I've only posted on it 3 other times, and all but 1 of them have been more filler then anything else. Shooting a small castle on a hill is harder to make interesting then it seems. It really needed that sakura man.
So what I did do in editing is keep temp up on the path below and keeping clarity up on the castle. I turned up the saturation on the sky and toned its brightness down in more subtle amounts than normal. That's about it.
Now that it's October, I'd like to remind people coming back that I'm trying a multi-week span of related posts for the holiday season (even created a new album for it), so just keep an eye out, it will start VERY soon.

Getting the Words Wrong

Thomas Hawk posted a photo:

Getting the Words Wrong