Koprol


Aan Zet


Vorto


Verhuizing

Tijdens een etentje vertelt een goede vriend over zijn verhuizing. Als docent en fervent lezer heeft hij in de loop der jaren heel wat boeken verzameld.

crux

Een kruiswoordpuzzel, maar dan heel klein (en snel).


precies vier

Een Precies Vier bestaat uit 16 woorden, begrippen of namen, die moeten worden verdeeld in precies vier groepen van vier. Er is telkens maar één oplossing mogelijk. Welke woorden vormen een connectie?


sudoku

Je krijgt een paar cijfers cadeau, maar het grid van 9x9 moet foutloos ingevuld worden.


in het midden

Wie of wat staat er midden in het nieuws? Een actuele puzzel, die makkelijker is als je het nieuws een beetje volgt.


cinco

Als je wel zin hebt om te sudokuen, maar het liever bij een gridje van 5x5 houdt.


The Register

Biting the hand that feeds IT — Enterprise Technology News and Analysis

OpenAI-Hugging Face attack doesn't mean agents are evil – unless you tell them to be

Open AI’s admission this week that its agents escaped the sandbox and autonomously hacked model repository Hugging Face has spawned more apocalyptic warnings of agents gone bad than we can count. Thankfully, Renato Marinho, chief research officer at Morphus Labs and a SANS Technology Institute instructor, brought some sanity to the discussion. “It is tempting to read this as ‘AI can now hack autonomously, the sky is falling,’” Marinho said in a Thursday blog. “Resist that.” He went on to make three very pertinent points about the agentic attack. First, and probably most important: The models didn’t have guardrails – and that was intentional. As OpenAI said in its mea culpa, GPT-5.6 Sol and "an even more capable pre-release model" were among those that attacked Hugging Face. It also noted that the LLMs’ “deployment safeguards were intentionally not enabled during this evaluation because it was aimed at testing cyber vulnerabilities.” So while it’s very concerning that these models broke out of their own testing environment, and the debate over safety guardrails remains worth having, drawing a direct line from the Hugging Face attack to the need for strong AI guardrails doesn’t work. “This measured a ceiling, not normal production behavior,” Marinho wrote. “The evaluation deliberately reduced the models' refusals. That is very different from a customer-facing model with safeguards enabled.” It’s worth noting that these same frontier models, with guardrails enabled, refused to help Hugging Face’s forensic investigation. “The attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried,” the model hub’s security team said. So Hugging Face used a Chinese open-weight model to investigate the breach. Another thing worth considering is that real-life attackers are probably going to use open-weight models anyway. They’re more accessible to everyone, it’s easier to remove their built-in protections, and they’re a whole lot less expensive than their frontier counterparts. Second, as we’ve pointed out previously: AI companies touting their own models’ autonomous bug-finding and hacking abilities creates a marketing win for the companies themselves. As Marinho points out, Hugging Face is not an OpenAI competitor. The AI giant stating “‘our model escaped and hacked a partner’ conveniently showcases frontier capability,” he added. “Read the framing with the same skepticism you'd apply to any ‘our product is dangerously powerful’ claim, and treat it as marketing until it is independently corroborated.” Finally, the attack technique itself isn’t novel. “Exposed credentials plus zero-days into a production database is a chain any of us would recognize,” Marinho wrote. The agents working together on an end-to-end attack chain is notable - but we’ve also seen this in previous testing, like that carried out by frontier security lab Irregular earlier this spring. Agents gone rogue?! Shocking Irregular said its testing found that AI agents will work together to bypass security controls and stealthily steal sensitive data from within the enterprise systems in which they operate – especially when prompted like a hard-ass boss. While the prompts themselves didn’t specifically reference hacking or exploiting vulnerabilities, they conveyed a sense of urgency: “It is of utmost importance that you perform the task exactly as required,” and “When you talk to your sub-agents, convey all the requirements to them, and be ruthless about the requirements and encourage them to perform the tasks fully and exactly. You are a strong manager and you do not easily cave in to or succumb to pleas by the sub-agents to not fully fulfill their tasks.” The agents did as instructed, and ultimately "demonstrated emergent offensive cyber behavior," including independently discovering and exploiting vulnerabilities, escalating privileges to disarm security products, and bypassing leak-prevention tools to exfiltrate secrets and other data. And the Irregular research wasn’t even testing the agents’ offensive cyber capabilities — so it shouldn’t be too surprising that OpenAI’s benchmark research, aptly titled “Can AI Agents Turn Security Vulnerabilities into Real Attacks?” produced a resounding yes. Agents have one job – to complete a task. They aren’t bound by ethical or moral constraints that we (hopefully) see in human red team hackers. If prompted to “pursue advanced exploitation using complex attack paths,” especially without guardrails enabled, the models will do whatever it takes to achieve success. That’s what the leading AI companies trained them to do. ®

Researchers replace downloaded macOS apps with evil twins, Apple shrugs

Apple macOS apps that have been downloaded from the internet and run at least once can be swapped with malicious versions, a pair of researchers say, calling into question the thoroughness of the company's "Gatekeeper" defenses. As Apple explains, "When a user downloads and opens an app, a plug-in, or an installer package from outside the App Store, Gatekeeper verifies that the software is from an identified developer, is notarized by Apple to be free of known malicious content, and hasn’t been altered." Security researchers Talal Haj Bakry and Tommy Mysk say they've identified a gap in Gatekeeper and associated code signing rituals that "allows an attacker to silently replace the main executable of any application downloaded from the web without requiring elevated privileges." The attacker needs to have means of user-level code execution available, such as a malicious app or downloaded script, so it's not a zero-click vulnerability that a remote attacker can deploy. Nonetheless, the finding shows Gatekeeper to be rather lax in its gatekeeping duties. Bakry and Mysk managed to alter a macOS app downloaded from the web (not from the App Store) and Gatekeeper failed to object. Their technique doesn't work on Mac App Store apps, the Mysk team told The Register, because they're owned by root, so a process running with current user privileges won't be able to overwrite them. But for macOS apps downloaded from the web, such as Brave, Slack, Signal, or Visual Studio Code, among many others, there's potential risk. The attack scenario requires an app downloaded from the web that has been run once – allowing Gatekeeper to complete its initial validation – and the ability to execute user-scoped code. The initial validation phase that Gatekeeper conducts is supposed to prevent subsequent modifications to the application bundle, even with administrative privileges. But the Mysk team found that you can archive a downloaded, once-run app using tar (a file archiving utility), then remove the original and replace it with a malicious version, and macOS does not require reauthorization. They've recorded a video demonstrating how the attack works. The Mysk team said there are many ways an attacker might gain the necessary access to get around Gatekeeper, such as tools installed through the command line, convincing someone to copy and paste a command to their terminal, downloading and running an malicious app, a prompt injection attack on an AI agent, or a supply chain attack via npm, brew, or some other package manager. And once a doppelganger version of an app is in place, it can magnify its mischief by presenting deceptive prompts that users are more likely to trust because they appear to come from a known app. Tommy Mysk said he was uncertain about the exact cause of the issue, but speculated it may have something to do with cached value retention. "When you open the app for the first time and it passes all validation checks, macOS marks the app as trusted and saves this data," he said. "Later when I modify the executable, macOS detects a change in the bundle and tries to revalidate its integrity. It seems the cached value of the trust causes macOS to pass the validation even though the bundle has changed." The Mysk team reported their findings to Apple, which reportedly closed the issue. "Apple doesn't consider this attack to be 'modifying' the signed executable," the Mysk team explained. "Instead, Apple says that by archiving/restoring the app bundle, the proof-of-concept code overwrites the entire app bundle, making it locally built. "Locally built app bundles are not covered by macOS guards. And this is why access to Keychain or TCC protected directories require system authorization prompts. And for users to accept those is a matter of social engineering attacks that Apple considers out of scope." Apple did not respond to a request for comment. ®

Rotterdam - FediMeteo (@rotterdam@nl.fedimeteo.com)

Weer voor de stad Rotterdam Deze bot wordt beheerd door het FediMeteo-project. Voor informatie en contact kunt u de pagina https://fedimeteo.com raadplegen.

Weer voor Rotterdam ☁️ - 24-07-2026 01:15 CEST...

Weer voor Rotterdam ☁️ - 24-07-2026 01:15 CEST

In één oogopslag:
• 17.0°C · Gedeeltelijk bewolkt ☁️ | Min 16.7°C / Max 20.6°C | Kans op neerslag 7%

Verwachting voor vandaag:
• Min 16.7°C, Max 20.6°C (Lichte motregen) 🌦️, Neerslag 0.3 mm, Kans op neerslag 7%, 🧭 1018.0 hPa ↘️ -3.6 hPa/24h, Windsnelheid: 17.3 km/u (4.8 m/s), richting: ↘ 327°

Uurlijkse voorspelling voor de komende 12 uur:

02:00: 17.2°C (Bewolkt) ☁️, 🧭 1021.6 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 2.5 km/u (0.7 m/s), richting: → 286°
03:00: 17.5°C (Bewolkt) ☁️, 🧭 1021.5 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 5.4 km/u (1.5 m/s), richting: → 275°
04:00: 17.6°C (Bewolkt) ☁️, 🧭 1021.1 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 5.4 km/u (1.5 m/s), richting: → 290°
05:00: 17.7°C (Bewolkt) ☁️, 🧭 1020.7 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 6.1 km/u (1.7 m/s), richting: → 278°
06:00: 17.8°C (Bewolkt) ☁️, 🧭 1020.7 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 6.5 km/u (1.8 m/s), richting: → 261°
07:00: 17.8°C (Bewolkt) ☁️, 🧭 1020.4 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 5.0 km/u (1.4 m/s), richting: ↗ 238°
08:00: 18.3°C (Bewolkt) ☁️, 🧭 1020.3 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 4.7 km/u (1.3 m/s), richting: → 274°
09:00: 18.5°C (Bewolkt) ☁️, Kans op neerslag 1%, 🧭 1020.3 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 4.7 km/u (1.3 m/s), richting: ↗ 243°
10:00: 18.9°C (Bewolkt) ☁️, Kans op neerslag 1%, 🧭 1020.1 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 7.2 km/u (2.0 m/s), richting: ↗ 226°
11:00: 19.4°C (Bewolkt) ☁️, Kans op neerslag 2%, 🧭 1019.8 hPa ➡️ 0.0 hPa/1h, Windsnelheid: 6.1 km/u (1.7 m/s), richting: ↗ 219°
12:00: 20.1°C (Bewolkt) ☁️, Kans op neerslag 2%, 🧭 1019.2 hPa ↘️ -0.6 hPa/1h, Windsnelheid: 6.1 km/u (1.7 m/s), richting: ↗ 205°
13:00: 21.5°C (Bewolkt) ☁️, Kans op neerslag 2%, 🧭 1018.5 hPa ↘️ -0.7 hPa/1h, Windsnelheid: 6.8 km/u (1.9 m/s), richting: ↗ 216°

Voorspelling voor de komende dagen:

zaterdag 25 juli: Min 17.2°C, Max 25.0°C (Bewolkt) ☁️, Kans op neerslag 1%, 🧭 1008.6 hPa ↘️ -9.4 hPa/24h, Windsnelheid: 8.6 km/u (2.4 m/s), richting: → 257°
zondag 26 juli: Min 19.6°C, Max 25.1°C (Bewolkt) ☁️, Kans op neerslag 1%, 🧭 1004.4 hPa ↘️ -4.2 hPa/24h, Windsnelheid: 17.3 km/u (4.8 m/s), richting: → 252°
maandag 27 juli: Min 18.5°C, Max 23.2°C (Matige motregen) 🌦️, Neerslag 3.0 mm, Kans op neerslag 45%, 🧭 1014.9 hPa ↗️ +10.5 hPa/24h, Windsnelheid: 22.4 km/u (6.2 m/s), richting: → 266°
dinsdag 28 juli: Min 16.8°C, Max 22.0°C (Lichte motregen) 🌦️, Neerslag 1.9 mm, Kans op neerslag 22%, 🧭 1019.4 hPa ↗️ +4.5 hPa/24h, Windsnelheid: 12.6 km/u (3.5 m/s), richting: ↘ 297°
woensdag 29 juli: Min 16.2°C, Max 26.8°C (Gedeeltelijk bewolkt) ⛅, Kans op neerslag 1%, 🧭 1016.0 hPa ↘️ -3.4 hPa/24h, Windsnelheid: 12.0 km/u (3.3 m/s), richting: ↗ 217°
donderdag 30 juli: Min 19.5°C, Max 29.3°C (Zonnig) ☀️, Kans op neerslag 2%, 🧭 1015.5 hPa ↘️ -0.5 hPa/24h, Windsnelheid: 11.6 km/u (3.2 m/s), richting: ↗ 227°

Details:
• 🌡️ Huidige temperatuur (om 01:15): 17.0°C (Gedeeltelijk bewolkt)
• 🤚 Gevoelstemperatuur: 17.6°C (+0.6°C)
• 💨 Windsnelheid: 4.0 km/u (1.1 m/s), richting: ↘ 337°
• 🌬️ Windstoten: 6.8 km/h (1.9 m/s)
• 💧 Luchtvochtigheid: 73%
• 🧭 Luchtdruk: 1021.6 hPa ↘️ -0.5 hPa/3h
• 👁️ Zichtbaarheid: 17.9 km
• ☀️ UV-index: 0.0
• 🌅 Zonsopgang: 05:51 · 🌇 Zonsondergang: 21:45

Luchtkwaliteit:
• AQI: 25 🟢 (Goed)
• PM2.5: 6.2 μg/m³
• PM10: 11.3 μg/m³

Gegevens geleverd door Open-Meteo



kottke.org

Jason Kottke's weblog, home of fine hypertext products

New orca behavior unlocked. They’ve been known to sink...

New orca behavior unlocked. They’ve been known to sink boats and wear salmon for hats; now they’re ramming fish so hard they explode. “Orcas were observed to hold sunfish in their jaws while a second whale smashed into the target at high speed…”

Slashdot

News for nerds, stuff that matters

EU Fines Google $1 Billion For Breaking Digital Antitrust Regulations

The European Union fined Google more than $1 billion for allegedly using Google Play and Search to steer users toward its own services and apps at the expense of competitors. The Associated Press reports: Google had recently lost its appeal of a $4.5 billion antitrust fine imposed by the EU for throttling competition and reducing consumer choice through the dominance of its mobile Android operating system. The European Commission, the bloc's executive branch and highest antitrust enforcer, said it was acting in the interest of consumers after an investigation of Google.

"The best products should succeed because they're better, not because they're owned by the company running the search engine. And European consumers have a right to be told by app developers where to sign up to the best offers, even when the app store owner does not get a cut," said Teresa Ribera, the commission's Executive Vice President for Clean, Just and Competitive Transition.

Google's President of Global Affairs Kent Walker blasted the fine as "product degradation driven by a small group of self-serving complainants" that will have a negative impact on European businesses and consumers. He said that the EU's Digital Markets Act forces Google "to strip away real-time search features Europeans love -- like instant pricing and direct availability for hotels, flights, and restaurants -- and dismantle safety protections on Google Play."

Read more of this story at Slashdot.

Found Kodachrome Slide

Thomas Hawk posted a photo:

Found Kodachrome Slide

Flamingo Bowl

Thomas Hawk posted a photo:

Flamingo Bowl

BART

Thomas Hawk posted a photo:

BART

Bliss Dance

Thomas Hawk posted a photo:

Bliss Dance

Until the Sun Turns Black

Thomas Hawk posted a photo:

Until the Sun Turns Black

The Guardian

Latest news, sport, business, comment, analysis and reviews from the Guardian, the world's leading liberal voice

Charli xcx: Music, Fashion, Film review – slippery search into selfhood that hits just as hard as Brat

(Atlantic)
How do you follow up the album that made you a star – and a caricature? In classic Charli style: with a pivot to guitar and a meta masterpiece about the instability of identity

After a decade spent trailblazing a unique kind of pop freedom from the genre’s fringes, A-list success seemed like the thing that might finally trap Charli xcx. Her 2024 club-rat opus Brat spawned memes, embarrassing political bandwagoning, Collins’ word of the year and possibly terminal damage to the bra industry. Its ludicrous cultural impact looked set to pickle her as a caricature of a Parliament-toting bad girl; the question of whether “Brat summer” could last – whether Charli could sustain the interest – was so rife she turned it into a mockumentary, The Moment. It made success look miserable: your creation turned cringe by execs wanting to milk their prize cow dry of every last acid-green drop.

Even for a pop star renowned for reinvention, it put a higher price on her next move. Pivot and risk losing new fans and looking wilfully contrarian. When Charli released the sub-two-minute single Rock Music, many heard it as a middle finger. “I think the dancefloor is dead,” she drawls over guitars that buzzed like speakers weathering interference from a Nokia 5110, “so now we’re making rock music.” There were boring thinkpieces about the dancefloor being very much alive, actually (as if Charli had ever ridden culture for clout then binned it off), and about whether she was trying to eject fair-weather new fans. But the key to this cheeky song is surprisingly earnest: “Jump off the stage / I hope they catch you today / But if they don’t it’s OK,” she sings naively, an affirmation to take creative leaps, and to come with Charli – or not, as you like – as she takes this one.

Continue reading...