Stories
Slash Boxes
Comments

SoylentNews is people

Log In

Log In

Create Account  |  Retrieve Password


Site News

Join our Folding@Home team:
Main F@H site
Our team page


Funding Goal
For 6-month period:
2022-07-01 to 2022-12-31
(All amounts are estimated)
Base Goal:
$3500.00

Currently:
$438.92

12.5%

Covers transactions:
2022-07-02 10:17:28 ..
2022-10-05 12:33:58 UTC
(SPIDs: [1838..1866])
Last Update:
2022-10-05 14:04:11 UTC --fnord666

Support us: Subscribe Here
and buy SoylentNews Swag


We always have a place for talented people, visit the Get Involved section on the wiki to see how you can make SoylentNews better.

When was the last time you compiled an operating system kernel?

  • This morning---I live on the unstable nightly build!
  • Every time a major release comes out
  • Whenever my distro does it for me
  • Last century
  • That one time when I was in college and I was experimenting
  • Never
  • What's a kernel?
  • Other (describe in the comments)

[ Results | Polls ]
Comments:12 | Votes:48

posted by janrinok on Wednesday July 22, @06:57AM   Printer-friendly

How a Gang of Thieves Pulled Off a Multimillion-Dollar Data Center Heist - New York Times Magazine

The world's most valuable assets are stored on rows of servers in giant, anonymous buildings. And they can be stolen.

Ellis claims in "The Art of Robbery," a self-published memoir written after his release from prison, he eventually learned that Ray had been contacted by a consultant employed by "some influential bankers from America." The bankers "were involved in prime mortgages" and had "circumnavigated" certain regulations. Damning evidence of these circumnavigations could be found in banking files held in the King's Cross area in a giant building known as a data center.

This data center was operated by the business division of Verizon, which had inherited the facility, and about 20 other data centers, through a recent series of corporate mergers. Among the corporations that rented server space from Verizon were various major financial institutions, including one of the world's largest banks.

Ellis's assignment was to break into the data center and steal around 80 servers that hosted the incriminating files. Ellis usually worked with a crew of four other professional thieves, but none of them knew much about computers. For this job, he concluded, he would have to smuggle in four computer technicians who could disable the servers without destroying the data they held. Ray also insisted that another man affiliated with his client join the operation. To break 80 servers out, Ellis would have to break 10 people in.

[...] Terry Ellis, for his part, can't imagine that the Verizon job will be the last great data center heist. "Nothing is infallible," he says. "You can get around everything. And human fallibility trumps any technology. You can have the best security in the world, but if you have a group of determined criminals who have prepared to go to extraordinary lengths, they're going to get in."

All it takes is a person with the determination, and intelligence, of Terry Ellis. And a dog as big as Buster.


Original Submission

posted by janrinok on Wednesday July 22, @02:12AM   Printer-friendly

https://www.odditycentral.com/funny/doctors-document-rare-case-of-dropped-head-syndrome-caused-by-drug-use.html

Doctors at Iran's Isfahan University of Medicine recently documented the case of a 23-year-old male whose head dropped to a 90-degree angle because his neck muscles could no longer support it.

Cervical Kyphospholiosis (CKS), aka "Dropped Head Syndrome," is a serious medical condition characterized by weakness in the neck extensor muscles, which renders them unable to support the weight of the head. It is usually associated with various neuromuscular conditions, including mitochondrial myopathy, congenital myopathy, motor neuron disease, or anatomical abnormalities. such as an unusually large head, but doctors at an Iranian university recently reported a previously undocumented case of CKS caused by years of substance abuse.

The 23-year-old unnamed patient was described as "hailing from a socioeconomically disadvantaged background," with "a significant medical history of major depressive disorder and substance abuse, including addiction to heroin, opium, and amphetamines." Doctors at the Isfahan University of Medicine wrote that "after every episode of amphetamine use, the patient consistently maintained a fixed kyphotic neck position for extended periods, leading to a progressive alteration in his cervical alignment."

Cranial nerve testing yielded normal results, as did muscle strength and autonomic function tests, but a CT scan revealed a severe kyphoscoliosis deformity affecting the patient's C3, C4, and C5 vertebrae. After assessing the severity of his condition, doctors opted for a three-stage surgical solution to remove the deformed bone and realign his neck in a proper position. Luckily, the operation was a success, and the patient was able to walk with a special collar a day later and was discharged after three days.

Doctors reported that the 23-year-old patient had tried various traditional and herbal remedies, but none had alleviated his symptoms, so he eventually sought medical attention. Following the surgery, he had several psychiatric consultations, and he was able to give up drugs. A 1‐year follow‐up revealed satisfactory improvement in alignment and correction in the position of the cervical spine.

"We discovered that drug abuse contributed to the uncommon development of severe complicated cervical kyphosis," the Iranian doctors wrote in their case report. "The drug does not have a direct effect on musculoskeletal changes. Instead, there is an indirect effect: When the patient uses the drug, they remain in a certain position for a long time, and over months, this results in musculoskeletal changes that lead to kyphoscoliosis."

The previously undocumented connection between severe substance abuse and dropped head syndrome has been given the name "intoxicated syndrome".


Original Submission

posted by janrinok on Tuesday July 21, @09:24PM   Printer-friendly

The Shocking Secrets of Madison Square Garden's Surveillance Machine

If this information is well known, then I am sorry for posting it:

Famously vengeful Knicks owner Jim Dolan has long spied on people at his iconic arenas. WIRED goes deep inside the operation that allegedly tracked a trans woman, lawyers, protesters, and more.

New Yorkers have known for a long time that going to a game or concert at the Garden meant surrendering some privacy. That, as you watched the show, the Garden in a real sense watched you. Since 2018, there have been reports of the venue deploying face-recognition technology in what critics believe are increasingly intrusive ways. Owner James Dolan has watch lists of basketball fans who have dared criticize his management. He keeps a close eye on his other venues too, including Radio City Music Hall and the Sphere in Las Vegas. Last March, Dolan's security team blocked a graphic designer from seeing a concert; the designer, years earlier, had printed and sold a half-dozen T-shirts reading "Ban Dolan." He has locked out whole firms' worth of lawyers, even keeping out a mom who was trying to take her 9-year-old Girl Scout to a Christmas show at Radio City Music Hall; the mom's coworker had pissed him off.

But the true extent of Dolan's panopticon has only been caught in glimpses. A 2025 lawsuit by a former member of the MSG security team lifted the veil, just a bit. We started our own digging into the Garden's operations. We discovered that Dolan's security teams obsessively tracked Nina Richards, a trans woman, over a two-year period, monitoring her movements through the venue down to the second. (WIRED is using a pseudonym in this article out of respect for her privacy.) Dolan's biometric surveillance is so extensive that a New York City police officer's photo was added to a face-recognition database, and a child triggered an alert at one of Dolan's properties. According to that lawsuit and our sources, Dolan's head of corporate security takes such an expansive view of his mission that his employees will functionally cosplay as cops—patrolling the neighborhood, snooping on protesters if they happen to be in the area. You don't have to enter a Dolan venue to be under his watch.


Original Submission

posted by janrinok on Tuesday July 21, @04:41PM   Printer-friendly

https://www.theregister.com/paas-and-iaas/2026/07/16/airbus-migrating-70-critical-apps-from-aws-to-frances-scaleway-amid-digital-sovereignty-push/5272373

Airbus is migrating its most critical applications for sensitive workloads from AWS to French cloud provider Scaleway's under a drive to increase digital sovereignty. 

As exclusively revealed by The Register in December, the European-based aerospace manufacturer, said it needed to guarantee the data remained "under European control" and was launching a tender at the start of 2026. 

Catherine Jestin, head of digital at Airbus, told us on Thursday: "The selection of Scaleway is a combination of a very strong technical answer and a very strong commercial offer making it competitive compared to hyperscalers' public cloud offerings. In addition, Scaleway is committed to involving Airbus in the definition of its future product roadmap."

"The objective is to host Airbus's most critical applications (those required for the Minimum Viable Company). This represents 900 applications and we will start with 70 of them today hosted on AWS." 

Applications being sent to Scaleway include ERP, manufacturing execution systems, CRM, and product lifecycle management. Finding a cloud provider to host its most sensitive applications for defense and industrial workloads was not a certainty when the process began, Airbus told us last year, because European cloud providers do not have the scale of their US rivals. 

Jestin said Airbus will continue to work with AWS. Skywise, a platform that aggregates and analyzes aviation data, and Case Management Assistant for customers' technical queries will continue to be hosted by AWS. 

In a statement, she said: "By integrating a trusted, high performance, cloud environment that keeps our critical data assets shielded from foreign extraterritorial laws, we are ensuring that our digital infrastructure keeps pace with our aerospace innovation, while maintaining control and resilience of our industrial operations." 

Since President Donald Trump came to power for a second term, his antagonistic approach to allies - some of them now former allies - has created economic and geopolitical tensions between the US and Europe

This has heightened concern about the US Cloud Act, which allows the American government to request data held in overseas datacenters owned by US businesses, and only served to reinforce calls for digital sovereignty. 

Reacting to the movement in Europe, AWS, Microsoft and Google have all worked to convince customers they can provide digitally sovereign services, although a Microsoft exec previously admitted in a French court - under oath - that he could not guarantee digital sovereignty

Airbus continues to work with both Microsoft and Google's productivity suites though this latest move with Scaleway exemplifies the broader pattern across the trading bloc: to become more self sufficient and less reliant on US big tech. 

Jestin told us the aerospace corp will also still use US providers, including Salesforce, Coupa and Workday.

"We do not intend to move away from all non European solutions; we balance our choices based on the criticality of the data. 


Original Submission

posted by janrinok on Tuesday July 21, @11:45AM   Printer-friendly

Deep-sea life has a secret food source scientists never expected https://www.sciencedaily.com/releases/2026/07/260711010127.htm

Scientists have uncovered an unexpected source of food in the deep ocean that could change how researchers understand both marine ecosystems and Earth's carbon cycle. A new study from the University of Southern Denmark (SDU) suggests that deep ocean microbes are not living in such a nutrient-starved environment after all.

The research found that tiny sinking particles known as marine snow release dissolved carbon and nitrogen as they descend into the deep sea. Those leaked nutrients become an immediate food source for microbes living in the surrounding seawater. Marine snow is made up of tiny clumps of dead algae, microbes, and other organic material drifting through the ocean. According to the study, once these particles reach depths of about 2 to 6 kilometers, the enormous hydrostatic pressure begins forcing dissolved organic matter out of them.

"The pressure acts almost like a giant juicer," says first author of the study, biologist and Associate Professor Peter Stief from research centers Nordcee and Danish Center for Hadal Research, "It squeezes dissolved organic compounds out of the particles, and microbes can use them immediately."

The findings were published in Science Advances in the paper, "Hydrostatic pressure induces strong leakage of dissolved organic matter from 'marine snow' particles."

The researchers estimate that sinking marine snow can lose as much as 50% of its original carbon and between 58% and 63% of its original nitrogen during its descent through the deep ocean.

The results also have important implications for Earth's carbon cycle.

Scientists have long assumed that much of the carbon carried by marine snow eventually becomes buried in deep ocean sediments. However, if large amounts of carbon leak out before the particles reach the seafloor, less carbon may be permanently stored in sediments than previously believed. Instead, much of that dissolved carbon remains suspended in deep ocean waters, where it can stay for hundreds or even thousands of years before gradually returning to the surface ocean and eventually the atmosphere. Carbon that does become buried in seafloor sediments, by contrast, can remain locked away for millions of years, accumulating over vast stretches of time. Much of the oil and natural gas extracted today formed through this long-term burial process.

"This process affects how much carbon the ocean can store and for how long," says Peter Stief, "It's relevant for understanding climate processes and for improving future models."

To investigate the process, the researchers recreated marine snow in the laboratory using diatoms, microscopic algae that naturally clump together as they sink through the ocean.

The team placed these artificial particles inside specially designed rotating pressure tanks that kept the marine snow suspended instead of allowing it to settle. This setup allowed the researchers to measure how much carbon and nitrogen escaped under conditions similar to those found in the deep ocean.

Their experiments showed that up to half of a particle's carbon content leaked out while sinking. Most of the released material consisted of proteins and carbohydrates that free-living deep ocean microbes can readily consume.

The leaked nutrients quickly fueled microbial growth. Within just two days, bacterial abundance increased 30-fold, while respiration rates rose dramatically. These results indicate that dissolved organic matter released from marine snow provides a rapid and valuable energy source for microbes living at great depths.

The researchers also observed the same leakage pattern across multiple species of diatoms, suggesting that this mechanism is likely widespread throughout the world's oceans.

The next phase of the research will move from the laboratory to the open ocean. The team plans to search for molecular fingerprints of this process in both surface and deep waters during a future expedition to the Arctic aboard the German research vessel Polarstern. Detecting those signatures in nature would help confirm that the pressure driven leakage observed in the laboratory is occurring throughout the deep ocean.

Journal Reference: Jack J. Middelburg. The ocean's biological carbon pump under pressure. Science Advances, 2026; 12 (6) DOI: 10.1126/sciadv.aef3182


Original Submission

posted by hubie on Tuesday July 21, @07:59AM   Printer-friendly

Eating large amounts of chili peppers may raise the risk of esophageal cancer, but scientists say the evidence is not yet strong enough to prove a direct cause:

Could eating lots of chili peppers affect your cancer risk? Scientists have been debating that question for years, and the answer remains far from simple. While chili peppers contain compounds that have shown anti inflammatory and even anticancer effects in laboratory experiments, some human studies have linked very high consumption to a greater risk of certain cancers of the digestive tract.

A large review published in Frontiers in Nutrition examined the available evidence and found that people who consumed the most chili peppers were more likely to develop certain gastrointestinal cancers, especially esophageal cancer. At the same time, researchers emphasized that the evidence does not prove chili peppers cause cancer and that more rigorous studies are still needed.

[...] Chili peppers are eaten every day by billions of people and are an essential ingredient in cuisines across Asia, Latin America, Africa, and many other parts of the world. Their signature heat comes from capsaicin, a natural compound that activates heat and pain sensing nerve receptors.

Capsaicin has attracted considerable scientific interest. Laboratory studies have suggested it may reduce inflammation, influence metabolism, and even kill certain cancer cells under specific conditions. However, other experiments have found that under different circumstances it could promote tumor growth or contribute to tissue irritation. That conflicting evidence has made its overall effect on cancer difficult to pin down.

To better understand the relationship, researchers combined data from 14 observational studies involving more than 11,000 participants, including over 5,000 people diagnosed with gastrointestinal cancers.

Compared with people who consumed the least chili peppers, those with the highest intake were about 64% more likely to develop gastrointestinal cancers overall.

The strongest association involved esophageal cancer. People in the highest consumption group were nearly three times more likely to develop this cancer than those in the lowest intake group.

[...] Based on their findings, the researchers concluded that the evidence "suggest that chili pepper is a risk factor for certain GI cancers (e.g., EC)."

[...] Although these findings may sound concerning, they should be interpreted with caution.

Every study included in the review was observational. That means the researchers could identify associations, but they could not determine whether chili peppers themselves caused the higher cancer risk. Other factors, such as smoking, alcohol consumption, socioeconomic differences, infections, or overall dietary patterns, could also contribute.

Since the review was published, broader analyses have continued to paint a mixed picture. An umbrella review examining multiple systematic reviews concluded that spicy foods and capsaicin appear to have both potential health benefits and possible risks, depending on the disease being studied, the amount consumed, and the population involved. Some evidence links spicy food to lower risks of cardiovascular disease and premature death, while studies of digestive cancers remain inconsistent.

Journal Reference: Changchang Chen, Man Zhang, Xutong Zheng, Hongjuan Lang. Association between chili pepper consumption and risk of gastrointestinal-tract cancers: A meta-analysis. Frontiers in Nutrition, 2022; 9 DOI: 10.3389/fnut.2022.935865


Original Submission

posted by hubie on Tuesday July 21, @03:15AM   Printer-friendly

European authorities dismantled the VPN service in May following a yearslong investigation:

In May, European authorities dismantled First VPN, also known as 1VPNS, and arrested Rashevskyi, who is based in Dnipro, Ukraine, to culminate an investigation that began in 2021. 

Europol, the EU's law enforcement agency, said that First VPN was well publicized on Russian-language cybercrime forums as a service offering anonymous payments, hidden infrastructure and services "designed specifically for criminal use."

The agency also said the VPN service helped cybercriminals hide their identities while carrying out ransomware attacks and data theft, and that it appeared "in almost every major cybercrime investigation supported by Europol in recent years."

[...] Under the sanctions enacted this week, the Department of the Treasury will prohibit all transactions by people in the US involving property owned by Rashevskyi or Silayev. The department also said any of their property that is in the country or in possession of anyone in the country must be reported to the department. Financial institutions and others are prohibited from "engaging in certain transactions or activities" involving Rashevskyi or Silayev.

"The ultimate goal of sanctions is not to punish, but to bring about a positive change in behavior," the department said in the statement.

When used legally and ethically, a VPN is an invaluable tool for consumers seeking online privacy. The safest and most effective VPNs -- CNET advises against using free ones -- will not log or record your data, meaning that no one can see your internet activity. VPNs also mask your physical location by using a unique IP address, making it look as though you're in a different country than the one you're in. Many people use VPNs to watch online content that is geo-restricted from their actual country of residence.

But, as CNET's Attila Tomaschek writes, "total anonymity" is impossible, even with the best VPNs. They can help achieve some privacy, but so much of our data is accessible that a VPN can never give you "an all-encompassing invisibility cloak on the internet," he says.

[...] Ransomware criminals have used infrastructure obtained from First VPN to attack US businesses, financial services companies, hospitals and municipal governments, according to the Department of the Treasury.

Silayev, a Belarusian national, supplied encryption and obfuscation services to ransomware operators targeting US and allied entities, the Department of the Treasury said. These cryptors make malware look like harmless files, fooling the computer systems of companies and other institutions.


Original Submission

posted by hubie on Monday July 20, @10:27PM   Printer-friendly

New Debian versions hit FOSSland in the form of 13.6 and 12.15:

This week brings two point releases for both Debian 13 - aka "Trixie" - and Debian 12 - "Bookworm," the latter now shuffling off into long-term support. 

Debian 13.6 and Debian 12.15 are just the latest point releases of Trixie and Bookworm, but Debian 12.15 is also significant in another way: it marks the end of regular support for Debian 12, which is being handed over to the LTS team. That reduced level of support is scheduled to last until mid-2028.

That means Debian 12.15 is the last point release of Debian 12. There won't be a Debian 12.16. In turn, that means mainstream support for Debian on 32-bit x86 is over. (Debian 13 does still support some 32-bit Arm CPUs via the armhf port.)

As we warned you in 2023, to run Debian 13 on x86, you require a 64-bit CPU. It supports 32-bit packages and libraries, so you can run 32-bit programs fine – but if you want to install Trixie on a 32-bit CPU, then you need to compile your own kernel. That's not impossible: as we reported in late 2025, WindowMaker Live 13.2 does this, and so does antiX Linux, which we last looked at in March.

The new releases both have two significant changes worth knowing about.

The fwupd firmware-update tool from the Linux Vendor Firmware Service has been updated to version 2.0.20. As the Arch wiki describes, fwupd can only update the system firmware if your machine boots in UEFI mode (that is, not legacy BIOS boot.) However, that's useful, as it can update UEFI machines' secure-boot signing certificates and database too – and as Red Hat warned last month, Microsoft's original 2011 secure-boot certificates just expired.

If you don't use secure boot, that doesn't matter, but if you do and your boxes haven't rebooted in a while, you might have problems. Don't panic: problems aren't likely, but if you do have some, disabling secure boot will work around it. Either way, it's worth updating those certificates. The Debian Wiki has more info, and Linux Weekly News has a full rundown on the problem.


Original Submission

posted by hubie on Monday July 20, @05:43PM   Printer-friendly

This project uses a clever hashing trick to fit over half a million blocked domains into just 4MB of flash memory:

Firmware Uses Only Around 50KB Of RAM And Can Answer Blocked Lookups In 10 Milliseconds

How cheap can you build a hardware-based ad-blocking DNS filter? "Free," if you're willing to salvage some used hardware that's being thrown away. What if you aren't so lucky? In the era of the RAMageddon, even a Raspberry Pi will cost you a couple hundred bucks. But you know, you don't even need something that powerful. In fact, you can use a $5 microcontroller to build a fully functional ad-blocking filter with over 500,000 domains blocked and around 10ms latency.

We know that's possible because Egyptian full-stack developer ZedAxis (@M-Abozaid on GitHub) has already built one. Using an ESP32-C3 "SuperMini" board, he's created a backup DNS for his home network that still provides ad blocking. His primary router is a Pi-hole, which is a Raspberry Pi running specialized software to manage DHCP addressing and DNS resolution with integrated ad-blocking. The SuperMini serves as a backup when the Pi-Hole is rebooting or otherwise unavailable.

Instead, the ESP32-C3 used by ZedAxis has just 400KB of RAM, and 4MB of flash memory. With these limited specifications, he wasn't able to store a plaintext blocklist of any real size; it's simply too much data. So, he did what any enterprising hacker would do: he started hashing the data to reduce its size. Using 40-bit FNV-1a hashes, because 32-bit would give too many collisions and 64-bit wastes too much space, he can store some 537,000 domains in the flash memory of the device.

Of course, this isn't meant to replace a proper Pi-hole or AdGuard Home installation. The ESP32 project has a rudimentary dashboard, but it doesn't provide detailed per-client statistics, historical query logs, or all the knobs and dials that make those platforms attractive. Instead, it's designed as a tiny insurance policy. It sits quietly on the network, sips only a few dozen milliamps of power, and if the primary DNS server disappears for a reboot or a power outage, clients still get filtered DNS responses instead of falling back to whatever resolver the router happens to have configured.

I have no idea whether projects like this will ever become common. Probably not, because most people who want network-wide ad blocking will still buy a Raspberry Pi, a used mini PC, or run AdGuard Home in a virtual machine. Still, it's refreshing to see somebody look at a $5 microcontroller with 400KB of RAM and decide, "Sure, that'll do."


Original Submission

posted by hubie on Monday July 20, @12:55PM   Printer-friendly
from the laugh-and-the-shrewdness-laughs-with-you dept.

Great apes may have been laughing with a similar rhythm to modern humans for over 15 million years:

Great apes may have been laughing with a similar rhythm to modern humans for over 15 million years, a University of Warwick study reveals, providing an unexpected clue to how human speech evolved.

All living great apes - chimpanzees, bonobos, gorillas, and orangutans - laugh. But until now, it has been unclear how our laughter may have changed over millions of years of evolution, and how it might relate to the evolution of our speech.

In a new Communications Biology study, Warwick researchers analysed laughter recordings from four orangutans, two gorillas, three bonobos, four chimpanzees, and four humans. Across 140 laughter sequences, they found the same pattern: all species produce laughter with evenly spaced rhythmic intervals between successive sounds.

The researchers propose this basic rhythmic laughing structure was already present in a shared common ancestor 15 million years ago and has remained remarkably conserved with all living great apes and humans still showing the same underlying pattern in their laughter.

[...] However, while the basic rhythm stayed constant between species, the researchers did find that human laughter has become faster, more variable, and has gained sophisticated context-dependent control over time.

Of the great apes, humans alone have the ability to control when and how they laugh depending on context: an uncontrollable laugh when tickled differs sharply from a polite laugh in a meeting, a nervous laugh after a mistake, or the infectious laughter that spreads through a group of friends. The same underlying rhythm, shaped by conscious control to communicate different emotions and intentions.

The findings of this study suggest that throughout great ape evolution, our ancestors gradually developed greater control over the timing of their vocalisations, including laughter – showing a fundamental building block of speech.

Submitted from ScienceDaily

Journal Reference: De Gregorio, C., Davila-Ross, M. & Lameira, A.R. Rhythm and timing in laughter reveal that human vocal plasticity falls on a hominid continuum. Commun Biol 9, 824 (2026). https://doi.org/10.1038/s42003-026-10499-z


Original Submission

posted by hubie on Monday July 20, @08:12AM   Printer-friendly

'Operation Muck And Load' Has Published 700 Malicious Modules Since January:

Supply-chain security firm Socket has published research findings describing a Go module that posed as a DNS and subdomain scanner while acting as a first-stage Windows malware loader. The firm then traced it to a network of 222 GitHub repositories across 190 accounts. The module published its first version on January 24 this year and has since accumulated more than 1,200 versions, over 700 of them malicious. Socket tracks the campaign as "Operation Muck and Load" and reported the module to the Go security team, which blocked it from the Go module proxy.

[...] The module's main.go launches a hidden PowerShell command that downloads content from muckcoding.com, decodes it with certutil, and runs the result with execution-policy bypass. Socket describes the decoded script as a multi-layer loader using Base64 encoding and XOR decryption, with a Turkish-language comment in one layer that translates to "run directly, no other step is needed."

Rather than hardcoding a payload URL, the resolver retrieves text from public platforms, searches it for the marker string "LastW," then decrypts the trailing blob with a hardcoded key to recover the actual download location. Primary dead drops include Pastebin and a paste service called Rlim, with fallbacks across YouTube, Instagram, Telegram, Google Docs, and GitCode. If defenders remove one paste or block the final archive URL, the actor can update the resolver content without touching the first-stage loader.

The resolved URL points to a password-protected 7-Zip archive hosted as a GitHub release asset. The loader extracts it into a directory named to resemble a legitimate Microsoft Photos install and launches Microsoft.exe from that path with a hidden window. Decoded payload stages map to AsyncRAT, Quasar, and Remcos-style RAT detections alongside infostealer behavior.

Socket confirmed at least 14 unique malware files across the analyzed set, including Trojan loaders and downloaders, Vidar infostealer, dropper and spyware payloads, and XMRig-related Monero cryptominers. One Loader.exe appeared byte-identically across four separate repositories.

Lure themes span MetaMask and Trust Wallet integrations, seed-phrase utilities, Binance and PayPal automation, Telegram and Discord bots, and game cheats for PUBG, Valorant, and Escape from Tarkov. One PUBG repository, nrevv1lad/Pubg-DESYNC-Menu, presented itself as an external cheat with an installation guide while hosting a Vidar-linked Loader.exe in its source tree.

Socket assesses with high confidence that Operation Muck and Load belongs to the same cluster that Sophos documented in June last year. Sophos researchers Matt Wixey and Andrew O'Donnell traced 141 GitHub repositories, 133 of them backdoored, to the same ischhfd83@rambler.ru address. Sophos also identified "Muck" as one of the actor's aliases, a label now embedded in the muckcoding.com and muckdeveloper.com domains.

Neither GitHub nor the Go team has commented beyond the proxy block.


Original Submission

posted by hubie on Monday July 20, @03:24AM   Printer-friendly

The Coldest "Stars" in the Galaxy Might Actually Be Alien Megastructures:

Ever since physicist Freeman Dyson first proposed the concept in 1960, the "Dyson sphere" has been the holy grail of techno-signature hunters. A highly advanced civilization could build a "sphere" (or, in our more modern understanding, a "swarm" of smaller components) around their host star to harvest its entire energy output. We know, in theory at least, that such a swarm could exist - but what would it actually look like if we were able to observe one? A new paper available in pre-print on arXiv, and soon to be published in Universe from Amirnezam Amiri of the University of Arkansas digs into that question - and in the process discloses the types of stars that are the most likely to find them around.

Perhaps unsurprisingly, one of those types is a Red Dwarf. The most abundant type of stars in the Milky Way, they burn through their nuclear fuel incredibly slowly making them extremely long lived. With estimated lives in the trillions of years - far longer than the current lifetime of the universe - they are also relatively small compared to our own Sun. A Dyson swarm could be built around 0.05 to 0.3 AU away from its surface, with relatively low cost of material.

White dwarfs are arguably even better for material costs, and represent the second type of star that it's worth tracking. These are compact, dead remnants of stars like our Sun, which have shrunk down to have incredibly small radii - around 1% of their original star. In this scenario, a Dyson swarm could be built just a few million kilometers away from the surface of the star, alleviating much of the engineering challenge of build a supermassive structure around a larger star. They also radiate energy steadily for billions of years, essentially creating an effective long-lived power source.

But what would stars surrounded by such megastructures actually look like? Astronomers typically use a tool called the Hertzsprung-Russell (H-R) diagram to classify stars based on their temperature and luminosity. However, since a Dyson sphere would block all of a star's natural light, it would completely change where on the diagram it would fall. Energy can neither be created nor destroyed, so the sphere itself would have to emit the exact same amount of radiation away from itself as the star is putting into it. It just does it in the form of heat, or infrared light instead. So a Dyson sphere can really be thought of as a shell that absorbs a star's light, does something useful with that energy, and then emits it as heat.

[...] But the key take away is how much further on the right the star would go. A typical red dwarf, which inhabits the lower right hand corner of a H-R diagram, has a surface temperature of around 3000K degrees. A Dyson sphere surrounding a star would have a temperature down to 50K - two orders of magnitude lower. There are no natural stars in this area, making any such object highly interesting as a potential Dyson swarm candidate.

[...] Since infrared is the specialty of the James Webb Space Telescope, it is well placed to monitor for these kinds of structures. But even older telescopes like WISE are being actively used to search for them. In May 2024, a paper highlighting work from Project Hephaistos identified seven strong Dyson sphere candidates (all red dwarfs) out of a catalogue of 5 million stars. One was eliminated as a possible source, as there was a supermassive black hole aligned perfectly in the background around the star, explaining the anomalous readings. But that still leaves five more potential candidates that are worth some closer observation. This new paper will add another tool to astronomers' understanding of what to search for to one day find one of these elusive technosignatures.

Submitted from ScienceDaily

arXiv link: https://arxiv.org/abs/2602.23270


Original Submission

posted by janrinok on Sunday July 19, @09:53PM   Printer-friendly
from the There-are-no-Easter-Eggs-in-this-program dept.

The 27th Debian Conference is in Santa Fe, Argentina, Monday July 20th to Saturday July 25th 2026. Some of the planned talks:

  • Free as in Burned Out: who really pays for Open Source Software
  • Is it even possible to build a truly universal system installer?
  • Debian in Disaster + Security Incidents
  • You Too Can Fix That Bug on That Weird Architecture
  • Debian in the Classroom - Episode III: The Students Strike Back (with code)

DebConf is the annual conference for Debian contributors and users interested in improving Debian. Previous Debian conferences have featured speakers and attendees from all around the world. The last DebConf, DebConf25, took place in Brest, France and was attended by 443 participants from 51 countries.


Original Submission

posted by janrinok on Sunday July 19, @05:08PM   Printer-friendly

https://ludic.mataroa.blog/blog/ai-mania-is-eviscerating-global-decision-making/

Are companies actually seeing massive productivity gains from their AI adoption? Does any of this sordid affair make sense?

This should be an easy question, but it is surprisingly hard to get a straight answer to it. Executives that tell the press that their company has gone insane will quickly find themselves removed from their positions. Employees who are honest will find themselves fired in short-order, or "randomly" selected for a round of layoffs. In fact, it is in the interests of almost every actor in the space – boards, executives, employees, vendors, consultants – to obfuscate and misrepresent the success rate of AI projects. Many publicly traded companies are putting out announcements about their AI productivity gains when I know for a fact that the businesses have done nothing other than purchase Copilot licenses and declare victory.

Yet we need to know if these projects are panning out – if the total focus on AI as a core tenet of business strategy is succeeding at a reasonable rate, then a discussion about the relative risk and reward is warranted.


Original Submission

posted by janrinok on Sunday July 19, @12:23PM   Printer-friendly
from the sky-is-falling dept.

Under Helsinki, there is a network of over 5,500 bomb shelters capable of sheltering nearly a million people in the event of a nuclear attack or Russian invasion. The shelters are equipped with autonomous systems and are used in peacetime as sports complexes:

Finland has built an underground network beneath Helsinki capable of sheltering nearly one million people. Let that sink in. Nearly one million people. This is not a handful of bomb shelters scattered throughout the city, but rather an underground city stretching beneath the capital, consisting of more than 5,500 reinforced shelters connected by tunnels carved directly into solid granite. They can be converted from civilian use into military-grade protection in as little as 72 hours.

Engineered to withstand explosions, chemical attacks, biological threats, radiation, and the collapse of the world above. The shelters contain independent power systems, water supplies, communications networks, hospitals, sanitation, filtration systems, and enough infrastructure to sustain life if the surface becomes uninhabitable. During peacetime, they function as swimming pools, hockey arenas, churches, sports centers, parking garages, and shopping facilities.

[...] Finland is not building these shelters because of some passing political disagreement with Moscow. The country shares an 830-mile border with Russia and has never forgotten the Winter War. Unlike much of Europe, Finland never embraced the fantasy that major wars had become impossible. While politicians across Europe dismantled civil defense, reduced their militaries, and diverted spending toward every fashionable political cause imaginable, Finland kept digging.

Today, nearly 4.8 million shelter spaces exist for a nation of just 5.6 million people. Very few countries on Earth have anything remotely comparable. That means Finland has spent generations preparing to keep the overwhelming majority of its population alive during the unthinkable. Governments do not invest on that scale because they expect peace.


Original Submission