Hackers are in the midst of a massive theft of cryptocurrency from supposedly secure offline hardware wallets, according to blockchain security firms monitoring the heists.
At least a dozen different hackers are said to be targeting Bitcoin owners who use the hardware crypto wallet Coldcard, made by Coinkite. At this point, it’s unclear who is behind the digital robberies, and it appears like there’s more than one group of hackers, according to Galaxy Research.
As of Tuesday, the research firm said the hackers have stolen around $130 million.
What makes the ongoing hacks against Coldcard wallet owners particularly interesting is that the point of using a product like Coldcard is that it’s supposed to be, at least in theory, one of the safer ways to store their cryptocurrency.
Bitcoin owners can store the secret key or seed phrase — essentially a password — to their cryptocurrency in a Coldcard wallet, a device that is not connected to the internet. With this system, Bitcoins are still on the blockchain, like all Bitcoins, but are protected by a password that lives exclusively offline.
[…]
hackers figured out that there was a flaw in how Coldcard wallets generated users’ seed phrases, which were predictable, according to security researchers at Block. Once they figured out the flaw, hackers simply needed to brute-force and generate the victims’ seed phrases.
[…]
In an advisory published on Thursday and updated on Saturday, Coinkite alerted users of the flaw, urged them to update their devices, and then “migrate” to a new seed phrase.
Qantas completed what is believed to be the longest-ever commercial flight when its Airbus jet landed in Toulouse on Tuesday after a flight from Melbourne lasting 24 hours and 24 minutes.
[…]
Qantas completed what is believed to be the longest-ever commercial flight when its Airbus jet landed in Toulouse on Tuesday after a flight from Melbourne lasting 24 hours and 24 minutes.
The flight, which triggered a surge in online tracking, is part of the airline’s Project Sunrise in which it plans to use a new A350 jet to fly nonstop from Australia to London.
The specially adapted A350-1000ULR airliner is due to debut with the Australian carrier’s nonstop Sydney-London route from 2027. Airbus has been conducting a two-month test campaign on the aircraft since June.
Airbus said the aircraft, which boasts a extra fuel tank, remained in the air for 24 hours and 24 minutes, covering 23,075km (14,338 miles) in a route over the Pacific and Atlantic oceans without stopping, before landing at the plane’s factory in Toulouse in south-west France.
[…]
Qantas completed what is believed to be the longest-ever commercial flight when its Airbus jet landed in Toulouse on Tuesday after a flight from Melbourne lasting 24 hours and 24 minutes.
The flight, which triggered a surge in online tracking, is part of the airline’s Project Sunrise in which it plans to use a new A350 jet to fly nonstop from Australia to London.
The specially adapted A350-1000ULR airliner is due to debut with the Australian carrier’s nonstop Sydney-London route from 2027. Airbus has been conducting a two-month test campaign on the aircraft since June.
Airbus said the aircraft, which boasts a extra fuel tank, remained in the air for 24 hours and 24 minutes, covering 23,075km (14,338 miles) in a route over the Pacific and Atlantic oceans without stopping, before landing at the plane’s factory in Toulouse in south-west France.
[…]
Flight-tracking provider Flightradar24 said the trip was the second-most-tracked flight ever on its channels – behind a 2022 flight carrying Queen Elizabeth II’s coffin – with more than 3.6 million people following its progress northwards via Canada.
Qantas has ordered 12 modified A350-1000ULR aircraft, designed to connect Australia’s east coast with London and New York in about 20 hours.
The services aim to turn what was once a five-day journey on the “Kangaroo Route” to London into a single flight lasting 19 to 21 hours, depending on routing and winds.
[…] Proofpoint says the cyber group it tracks as TA488, or “Laundry Bear,” began exploiting CVE-2026-42897, a cross-site scripting flaw in the Outlook Web Access (OWA) component of on-premises Exchange Server, a day before researchers and government agencies exposed the group’s abuse of a zero-day in Zimbra Collaboration Suite.
Unlike conventional phishing attacks, this one doesn’t depend on persuading the victim to follow a link or download a file. If a target opens the booby-trapped message in OWA, the browser executes attacker-controlled JavaScript inside the victim’s authenticated mail session. Exchange Online is not affected.
According to Proofpoint, TA488 abused the OWA flaw to target government organizations in the US and Europe, along with telecommunications, financial services, hospitality, and aerospace companies. The researchers said the unusually broad campaign may have been intended to hide among the background noise of everyday email traffic rather than the tightly focused operations more commonly associated with espionage groups.
[…]
Proofpoint believes TA488 may actually have been exploiting the flaw as a zero-day, citing attacker infrastructure that dates back to March, roughly two months before Microsoft’s out-of-band patch. If accurate, that would suggest the campaign was underway well before defenders knew there was a vulnerability to fix.
Weather happens in the boundary layer, the atmosphere from ground level to a few thousand metres, but this can be difficult to study in detail: weather stations are too low, and aircraft are expensive. Instrumented weather balloons are the traditional solution, and thousands are released every day. But these are at the mercy of the wind and use irreplaceable helium.
Drones offer an alternative and the US company Meteomatics has taken the idea further with Meteobase, a base station on the ground with a drone that can be launched and recovered automatically. It carries out a pre-programmed flight, gathering data at different altitudes, then returns to recharge and download data which the Meteobase sends to researchers.
The base is highly weather resistant and keeps the drone at a comfortable temperature. It can send out one data-gathering mission a day, or multiple flights to monitor fog, icing, an advancing weather front, or other fast-changing conditions. Such a setup could potentially replace labour-intensive and expensive balloon launches.
Weather balloons carrying instruments have been in regular use since the 1930s. They have become part of popular culture, partly because they sometimes get mistaken for UFOs, or are used as a throwaway “explanation” for UFO sightings. Future flying saucer spotters may be equally well entertained by weather drones bearing flashing lights.
Earlier this week, a collection of popular ASMR YouTubers discovered their accounts were simultaneously terminated. With no prior warning or the usual strikes, YouTubers such as Slight Sounds, RoseASMR and Its_Bunnii were removed. YouTube informed the accounts that they broke “sexual content” policies, but it’s already sparked up skepticism. While the line between intimacy and eros has always been contentious in ASMR circles, the sudden condemnation of decade-plus projects raises obvious double standards on what’s ultimately allowed on the platform.
[…]
Autonomous sensory meridian response, better known as ASMR, is a phenomenon where individuals experience a physical, blissful feeling triggered by certain auditory stimuli, such as tapping, scratching or kind voices. Though the science is still out on what causes it, many compare it to better documented neurological phenomena such as synesthesia.
[…]
There are accounts who tiptoe the line, which video platforms usually reward, but many of the banned accounts were relatively chaste in their uploads, paling to your average 2002 music video. It’s raised suspicions on why they were targeted.
[…]
The mass terminations have left these performers distressed, confused and angry, especially as YouTube says they have no intention of reversing the decision. It’s the latest chapter in what seems like a wider campaign of scrubbing all queer and erotic material online. As payment processors clutch their pearls, and platforms like Patreon, Steam and Itch.io scrub their hands raw, media from major commercial entertainment remains unaffected, and the scope of online speech worsens in real time.
By exploiting the quirks of human vision, Northwestern University engineers have designed a drone that nearly disappears right before the eyes.
For years, researchers have tried to design invisible drones and robots using camouflage, transparent materials or light-bending optical systems. But the Northwestern team instead used a concept called “motion blur” — the same effect that makes fast-spinning fans and propellers seem to disappear.
Called the “Phantom Twist,” the drone spins up to 25 times per second, which is too fast for the human eye to see clearly. While it isn’t completely invisible, it morphs into a ghostly smudge that seamlessly blends into the background. The work eventually could lead to drones that monitor wildlife, survey the environment and inspect infrastructure with less visual disruption.
“Most efforts to hide drones focus on making them look like their surroundings,” said Northwestern’s Michael Rubenstein, who led the work. “Instead, we asked whether we could design the drone itself around the way humans perceive motion. This idea of low visibility through persistent motion is something few people have explored.”
[…]
Whether monitoring nesting birds, surveying wetlands or inspecting aging infrastructure, drones often alter natural behavior simply because people or animals notice them. The disruption can cause wildlife to scatter and people to behave differently. A drone that’s harder to see, on the other hand, could perform the same tasks while blending into its surroundings.
[…]
“For a typical quadrotor drone, the propellers are spinning, but the robot is stationary,” Rubenstein said. “So, you still see its body. For our drone, the whole thing is rotating, so there are no stationary parts.”
To design the drone, the Northwestern team, led by Michael Rubenstein, first used a computational model to generate roughly 20,000 drone configurations capable of stable flight. Then, they used AI and optimization algorithms to repeatedly rearrange the drones’ major components, including a motor, propeller, circuit board, counterweight and batteries.
Searching for the unseen
To design the drone, the Northwestern team first used a computational model to generate roughly 20,000 drone configurations capable of stable flight. Then, they used artificial intelligence (AI) and optimization algorithms to repeatedly rearrange the drones’ major components, including a motor, propeller, circuit board, counterweight and batteries.
After sifting through many different configurations, the algorithms determined the ideal placement of the drone’s components to minimize its visibility from virtually every viewing angle while allowing for stable flight.
After selecting promising candidates, the engineers simulated each drone spinning in flight and overlaid those images a hundred real-world backgrounds. Then, they used a perception model that approximates human vision to determine how noticeable each design appeared. Designs that blended into their surroundings received lower visibility scores. The team selected the 500 lowest-scoring designs and applied the optimization algorithm, which repeatedly adjusted the positions of components to further minimize those scores.
“The design process was fully automated,” Rubenstein said. “Then, when we were confident that a drone met all our criteria, we built it.”
[…]
The new drone still has several limitations, the researchers noted. The propeller makes audible noise, and the drone’s wires and support rods are still somewhat visible. Rubenstein said his team plans to design future iterations with more transparent materials or quieter propulsion to make the Phantom Twist even less noticeable.
The digital wallet will only run on IOS and official Android. No idea how it is possible in these days of digital sovereignty, that the EU has made depedency on US OS software a requirement.
EUDI wallet collaborator recently confirmed that hardware attestation will be required [1]
Hardware attestation in this context means that the government server issuing the digital credential to the wallet wants proof that the keys being used are generated in secure hardware and on approved systems and not say an emulator or virtual machine, namely for security reasons.
This capability does not exist in a reliable way on desktops / laptops except some specific cases depending on the vendor, and in fact there’s no desktop version in the works.
No Linux system will work with this because there is no hardware signature to be validated on the government server, nor will your personalized Arch Linux install be in the list of approved systems even if it had a signature chaining back from the TPM.
Android ROMs are not technically to rule out since Play Integrity, which will be used for this attestation, is based on the Android hardware attestation API, which works on third-party ROMs like GrapheneOS, but they would need to allow the signature which has not happened for now. If you create a custom build, it won’t work though even the official version is approved.
The article fails to mention that this total surveillance mechanism has been thrown out three times before being adopted by a huge minority vote using parliamentary trickery. These Soviet and Stasi blanket spying on it’s own citizens were supposed to be what European countries stood against after WWII. These EU politicians have become the baddies.
EU countries have adopted a temporary regime allowing messaging services to voluntarily detect child sexual abuse material until 2028. End-to-end encrypted apps like WhatsApp and Signal remain exempt.
European governments have confirmed a temporary regime allowing messaging services to voluntarily deploy measures to detect suspected child sexual abuse material (CSAM), preserving a carve-out for end-to-end encrypted messages previously introduced by MEPs.
On Wednesday, EU ambassadors approved the written procedure for the temporary framework, derogating from the bloc’s rules on the privacy of electronic communications to combat the spread of the illegal content.
Written procedures are normally employed for relatively non-controversial files and allow member states to give their voting preference without a formal meeting. On Thursday, the file was confirmed as adopted with 25 governments in favour; only one voted against while another abstained.
In other words, the member states confirmed the text as it passed in the European Parliament earlier this month, including a last-minute amendment removing end-to-end encrypted messaging services such as WhatsApp and Signal from its scope.
The temporary measure has proved controversial, with privacy advocates, who have branded it “chat control,” warning of a dangerous precedent for scanning people’s private messages.
The European Parliament voted against prolonging the measure in March, and it duly lapsed in April. However, European Parliament President Roberta Metsola put the file back on the table at the request of the European People’s Party.
As a result, earlier this month the European Parliament voted to extend the temporary regime until 3 April 2028, even as EU policymakers continue negotiating a permanent solution that would introduce binding rules rather than voluntary measures.
In a last-minute move, centre-left lawmakers introduced a significant amendment excluding end-to-end encryption from the scope, a manoeuvre that privacy-minded lawmakers hoped would push member states to reject the text altogether.
“A clear majority wanted to limit the scope to known CSAM and include targeted measures,” Birgit Sippel (Germany/Socialists & Democrats), the MEP leadingthe file, said after parliament adopted the move. “However, due to procedural constraints requiring a qualified majority for amendments to be adopted, we were only able to highlight the crucial protection of end-to-end encryption.”
Last week, the European Commission delivered a favourable opinion on the parliamentary amendments, prompting member states to adopt the file without further negotiation with MEPs.
Despite the exclusion of end-to-end encrypted messaging services from the scope of the derogation, several MEPs are still critical of its content.
“Any scanning of the content of private communications must be limited to specific suspects,” MEP Ignazio Marino (Greens/EFA/Italy) told Euronews. His group voted to reject the temporary regime’s prolongation outright; it was joined by radical left and far-right parties to assemble a total of 276 lawmakers against the provisional scheme.
Other political groups split during the vote, signalling internal disagreement on the issue. In particular, the centre-left Socialists & Democrats were mostly in favour of the extension, but rapporteur Sippel was among the 20 MEPs voting against it.
Sceptic lawmakers argue that child protection should not be pursued at the expense of EU citizens’ privacy and by violating the right to secret communications.
“No child is helped by a law that will be annulled by the Court of Justice,” Marino said.
So Sony a few days ago and now Xbox. Cloud is so much fun!
An extended Xbox outage yesterday hit every part of the service, preventing players from accessing their digital games. It was the latest bleak reminder of how little control you have over the gaming ecosystem you invest hundreds of dollars in. Microsoft has now swung into damage control mode to try to explain what happened and how it plans to improve things ahead of the full launch of Halo: Campaign Evolved today.
[…]
So what exactly was the cause of the latest network outage? Van Vliet blamed a licensing service that Xbox relies on to authenticate game permissions which belongs to a different part of Microsoft. “This caused some sign-in scenarios to fail, and it caused many scenarios that require an entitlement check to also fail, such as listing out your Full Library and launching games that you own,” he explained. “It also affected several of our publishing and store partners who depend on those same systems which is why some of you saw issues in specific games and not others.”
Authorities have long warned organizations not to pay ransoms, and fresh figures underline why: handing over the money doesn’t mean the crooks leave you alone.
Proofpoint survey data suggests that 58 percent of affected UK organizations paid a ransom. Worse, 22 percent of those who pay get extorted again anyway.
The UK broadly tracks the global picture: 54 percent of victim organizations paid, though the rate swings sharply by region, from just 19 percent in Japan to 93 percent in the US.
Cybersecurity biz Proofpoint, which published the data on Wednesday, attributes the regional variation to “a combination of regulatory environment, recovery capability, insurance incentive structures, and cultural norms around negotiation.”
“But the core finding holds everywhere: ransomware creates enough pressure that a significant share of organizations in each of the surveyed markets choose to pay.”
UK organizations that paid fared somewhat better than the 37 percent global average for repeat extortion. Still, the core lesson stands: paying doesn’t reverse an attack. You can’t trust a criminal’s word. It just restarts a negotiation where the attacker holds every card, including the data, decryption keys, and the threat of publishing what they’ve stolen.
Operation Cronos, law enforcement’s LockBit takedown, provided hard proof of what had long been suspected: cybercriminals often retain victim data even after being paid.
At least 2.2 million vehicles fitted with dealer-installed KARR and SWDS security systems are vulnerable to nearby Bluetooth attacks that can unlock doors or prevent a stopped vehicle from starting, according to researchers at the University of California San Diego.
An advance look at the research published by UCSD this week (the full writeup won’t be available until August 12) reveals that KARR and SWDS security devices manufactured by Acrisure contain a serious flaw: They “all … rely on the same secure key,” the researchers found.
What that means, according to the researchers, is that anyone who knows the key, has a device with a Bluetooth connection, and can get within five yards of an affected vehicle can unlock it, make the horn honk, flash the headlights, or even prevent it from starting.
“Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors,” Jerry Yu, coauthor on the research and UCSD compsci graduate, said in the release.
KARR/SWDS devices are installed by dealerships. Along with providing key fob-like functions, they also serve as an antitheft device, allowing dealers and buyers to track cars with the devices installed in the case of theft.
According to UCSD, the devices are typically sold as a paid upgrade at dealerships around the US.
Alibaba’s reign as the worst offender under the European Union’s Digital Markets Act (DMA) lasted just four days, after the European Commission yesterday fined Google €890 million for breaches of the law –€340 million more than the Chinese e-commerce company will pay.
Europe even fined Google twice – once for treating its own services more favorably in search rankings and the second time for failing to properly inform users of its “Play” app store.
The search infractions attracted a fine of €460 million ($523.5m/£393m) and the Play offenses will cost the Chocolate Factory €430 million ($490m/£367.5m).
In US dollars, the fines total $1.013 billion – or one quarter of one percent of the $402 billion in revenue that Google’s parent company Alphabet won in its last full financial year. The Big G’s net income was $132 billion in the same year, making these fines less than one percent of its profits.
Yes, that is a huge massive problem for cloud services. They tend to go down.
PlayStation’s online services, including the PlayStation Store and some game servers, have been down for at least the last eight hours. Gamers who are still very upset about Sony’s planned demise of game discs aren’t letting this outage slide.
On DownDetector, thousands of users reported early on Friday that PlayStation Network seemed to be experiencing issues. PlayStation’s status page still says the PlayStation Store is on the fritz. While Gizmodo was still able to access some PlayStation Network services, including the store, we spent nearly five minutes trying to join a match in Battlefield 6 before receiving an “Unknown Error” report, so your mileage may vary. Judging by the number of less-than-pleased posts you find on X, some users are evidently still out of luck.
[…]
As for the cause for the outage, that’s still up in the air. Amazon resolved an AWS outage Friday morning, but that seemingly hasn’t fixed PlayStation Network. The outage is further exacerbated by Sony’s love affair with hardware DRM (digital rights management). Users require an internet connection in order to install a PS5 disc drive. PlayStation games purchased on the PlayStation Store also use DRM, and they require an internet connection to confirm a game’s license.
While some service disruptions are inevitable, this latest outage comes at a bad moment for Sony’s standing among gamers. The company said it was going to do away with any new game discs starting in 2028, effectively confirming that future consoles won’t have an optical drive to play current-gen or future games.
Europol and its partners’ investigators flagged 4,340 “horrific” URLs for removal over several weeks in June and July as part of an ongoing crackdown on The Com (short for community), a loosely knit network of online groups whose young members participate in a range of illicit activities. These range from hacking, swatting, and digital extortion to real-life shootings, stabbings, and other physical violence.
Europol’s recent Referral Action Days, aimed at disrupting The Com’s online ecosystem and stopping the spread of its propaganda, is part of the larger Project Compass operation. Project Compass began in 2025, and its partner law-enforcement agencies span the US, UK, and EU member states.
Investigators from Belgium, Finland, Hungary, Ireland, Luxembourg, the Netherlands, Portugal, Spain, and Sweden participated in the Referral Action Days during June and July.
Various groups linked to The Com post content online to recruit members and groom young victims using social media, gaming platforms, and messaging apps.
“The more extreme and harmful the content a user or group can produce or extort, the higher their status within the online community,” according to Europol. “These acts are often livestreamed on social media platforms, where online bystanders cheer them on, and later saved and disseminated.”
The URLs flagged for removal during this latest push to disrupt The Com’s recruiting activities included “violent videos and images depicting self-harm, suicide, child sexual abuse material (CSAM), animal cruelty, and violent attacks,” the international cops said.
This, the European cops say, includes so-called blood walls, which are paintings made with blood that display the extorter’s alias and group affiliation, and cut-signs, where the victims are forced to carve the extorter’s name into their bodies.
It also includes videos of street attacks and arson, plus manuals on how to commit these violent attacks, along with instructions on grooming and extorting vulnerable minors, and conducting doxxing and swatting.
Europol says its European Counter Terrorism Centre has received “hundreds” of requests from member states and others over the past two years to help investigate crimes linked to The Com. It describes the online network as a “global threat, particularly concerning minors as both victims and perpetrators.”
Last year, both the UK and US issued similar warnings about a subset of The Com that recruits children and teens for contract shootings, kidnappings, and other real-life violent crimes. In July 2025, the FBI said that In Real Life (IRL) Com had become increasingly brazen in its swat-for-hire and violence-as-a-service solicitations.
The FBI’s alert followed a similar notice from the UK National Crime Agency about a “deeply concerning” trend of The Com recruiting teenage boys to commit a range of criminal acts, from cyber fraud and ransomware to child sexual abuse.®
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV.
[…]
On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps. Spur found more than 42 percent of apps available for download on LG smart TVs include SDKs that turn one’s television in a proxy node indefinitely, and that more than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components.
Responding to questions about Spur’s research, LG Senior Vice President John Taylor told KrebsOnSecurity the company was working with app developers to remove the residential proxy option from their apps on the webOS platform. Developers that fail to comply, he said, will find their apps suspended.
[…]
App makers looking for ways to monetize their creations can turn to residential proxy providers, which pay developers to include SDKs that turn the user’s device into a residential proxy node that is rented to paying customers. In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and file utilities.
[…]
Spur’s report found the residential proxy network Bright Data accounted for a majority of proxy SDKs across both Samsung and LG smart TVs. In a statement shared with KrebsOnSecurity, Bright Data said its network is built on consent and responsibility and operates by LG and Samsung terms.
[…]
Spur argues the problem is not that residential proxy networks exist, but rather that they are being embedded at scale in devices that most consumers do not think of as computers and are not equipped to audit.
“A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight,” Spur’s Trevor Sutter wrote. “The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors.”
LG’s announcement that it is culling residential proxy SDKs from its app store is welcome news, but the company recently came under fire for another questionable partnership: Pimping McAfee security products via software drivers included in its high-end LCD monitors.
Earlier this week, the Youtube channel Gamers Nexus showed that certain LG LCD monitors will automatically install an app that promotes paid McAfee antivirus subscriptions, and that the app arrives through Windows Update without an approval prompt.
Drivers of cars from the Volkswagen Group using alternative Android versions like GrapheneOS, LineageOS, or /e/OS have been unable to use the VW app for some time. This means they can neither check their vehicle’s remaining range from their phone, schedule service appointments, nor control charging and air conditioning. The car manufacturer has made changes to the app’s backend that only allow devices with Google’s pre-installed Play Services. When asked by heise online, VW stated that affected users should not expect a timely reopening. “However, they are looking into it.”
No Play Services, no VW app
As Volkswagen explains to heise online, the blocking of custom ROMs is related to a restructuring of the software architecture. To use the app on Android devices, Google’s Play Integrity API (formerly known as SafetyNet) is required, which is only available on Android devices with Google’s Play Services.
[…]
Google’s Integrity interface is sharply criticized by GrapheneOS and others. GrapheneOS recently wrote on X about the Integrity API, stating that Google misleads companies regarding the functions of the Play Integrity API. The interface “doesn’t genuinely enforce having a secure device or legitimate app, it only pretends to. It leaves huge security holes open. It enforces Google’s business interests and bans having a reasonably secure device with GrapheneOS”
[…]
Hyundai and Kia with GrapheneOS Support
While VW is locking out users with custom ROMs, Hyundai shows that vehicle apps can also be used with alternative Android versions. The myHyundai app also supports GrapheneOS.
Of course, this thing could be used to push other, non customer, satellites into a different orbit, or just smash them about a bit in Robot Wars style.
A two-armed space robot blasted off on a private salvage operation Tuesday to slap life-extending jetpacks on old satellites running low on fuel thousands of miles up.
It’s the second satellite-saving mission to launch this month, all part of a growing, money-saving effort to keep spacecraft running as long as possible. Another company’s three-armed spacecraft rocketed into orbit on July 3 to boost NASA’s Swift Observatory so it doesn’t crash to Earth this fall.
Launched by SpaceX, Northrop Grumman’s mission robotic vehicle—dubbed MRV—and its jetpacks will spend the next year angling into the proper orbit 22,300 miles (36,000 kilometers) above Earth. Hundreds of satellites orbit at this so-called geosynchronous orbit, where they match the speed of Earth’s rotation and keep to the same part of the sky for continuous coverage.
Once in place by mid-2027, the minivan-sized spacecraft will use its 10-foot (9-meter) arms to attach a jetpack to an aging communication satellite. Then it will zip off to two more satellites in need.
For its debut flight, the spacecraft was accompanied by three electric-propelled jetpacks that peeled away separately following liftoff. Like the MRV, the jetpacks will use their own xenon gas thrusters to get to the desired orbit. Once in place, the jetpacks will wait for the robot to grab them, one at a time, and plug them into their designated satellites.
Each jetpack—the size of a washing machine—will provide the necessary oomph for an out-of-gas satellite to keep operating for several more years instead of retiring. If it works, it will be a boon for satellite operators SES of Luxembourg and Optus of Australia, saving them millions of dollars in replacement costs.
This is Northrop Grumman’s latest foray into the satellite-servicing business. In 2019 and again in 2020, the company launched a pair of spacecraft that latched onto faltering communication satellites and steered them, providing extra years of life.
Northrop Grumman designed its new robotic helpers to be even more resourceful. The company envisions future versions repairing and relocating live satellites, and even latching onto dead ones for removal from highly trafficked orbits. The company is collaborating with the U.S. Naval Research Laboratory and the Defense Advanced Research Projects Agency.
A data breach at AI music generator platform Suno exposed more than 55 million user accounts, according to Troy Hunt’s Have I Been Pwned service, which ingested the files.
The dump consisted mostly of email addresses, although phone numbers were also included where users had signed up with them instead, HIBP said.
Tens of thousands of Stripe records further revealed data such as names, physical addresses, purchase amounts, as well as partial credit card data, such as card type, expiry date, and the last four digits of the card number.
The breakdown from Have I Been Pwned puts a figure on the scale of Suno’s data breach for the first time since the news of the slip-up broke last week.
The individual who claimed responsibility for breaching Suno also supplied source code apparently dating from 2023 and 2024 that they said showed the company scraping millions of songs and lyrics from services including YouTube Music, Deezer, and Genius to train its AI.
Suno has acknowledged training its AI on music available on the open internet, while arguing that doing so constitutes fair use.
A little while ago it turned out that the US DOJ and FBI managed to track down a ransomware syndicate using a unique PC based identifier called the Global Device Identifier (GDID) (Windows 11 Identifier Code Used to Arrest 19-Year-Old Over Alleged Ransomware Spree) that Microsoft gave them. This code should have anyone who requires anonymity (journalists, homosexuals, protesters, people of the wrong ethnicity, people who like porn sites, or people who just think nobody has any right to snoop on what they are doing) really really worried as it means that MS can track you across your browsing habits, no matter what technology you are using to cover your tracks. In the meantime, people have been finding out what it exactly is and how to change it:
Listed below is true, but missing some information. Regardless of being logged in with a MSA you WILL have a GDID. I didn’t realize this at the time of posting but I looked into it. CDP has an anonymous device path that is used if no MSA has been connected. The underlying system is still factually correct just missing a few things.
GDID is a real telemetry item. It shows up in the U.S. federal criminal complaint (United States v. Peter Stokes, N.D. Ill., July 2026) as Global Device Identifier g:6755467234350028.
It is a Microsoft Account “Device PUID”. A 64 bit Passport Unique ID assigned to a Windows installation when it registers with a Microsoft Account, written in the device graph as g:<decimal>.
The claims are wrong. It is not “128 bit” and not “generated from serial numbers.” The court record itself says a reinstall produces a new GDID, which rules out it being derived from hardware serials like your GPU.
The stack, bottom to top:wlidsvc (Microsoft Account service) provisions the device with login.live.com and gets back a device PUID -> stores it in the registry -> the Connected Devices Platform (cdp.dll / CDPSvc) reads it and registers it into the Device Directory Service (DDS) graph -> Delivery Optimization reports it as the documented UCDOStatus.GlobalDeviceId.
All of it was reproduced on a live Windows 11 (26200) machine with public symbols. You can find your own GDID in one registry read (§7).
And if you want to change your GDID you can use GDID-Changer for Windows 10/11
Script that regenerates GDID assigned to your windows installation. It works by removing existing sessions and forcing new device registration. Resulting in issuance of new GDID by Microsoft servers. This script initiates exactly the same device registration process that occurs after a fresh Windows installation.
Requires an internet connection and administrator permissions. A new GDID is usually issued instantly, but script needs around 30–90 seconds to complete the job.
And this is why we seperate the courts from politics.
In a major victory for digital rights and common sense, the Court of Justice of the European Union (CJEU) has officially categorized Virtual Private Networks (VPNs) as “lawful technical tools” while establishing new boundaries for online copyright disputes.
The landmark judgment — handed down in July 2026 — stems from a complex legal battle over the online publication of Anne Frank’s historical manuscripts. At its core, the case forced Europe’s top judges to answer a highly technical question: if a publisher actively tries to block visitors from a specific country, are they still breaking the law if a user sneaks past the digital border using circumvention software?
According to the CJEU, the answer is no. As long as a website employs “state-of-the-art” geo-blocking technology, the publisher cannot be held liable for copyright infringement simply because a determined reader decides to fire up the best VPN to bypass the restrictions.
The ruling sets a massive precedent. It confirms that copyright holders cannot point to the mere existence of VPNs to claim a website’s security measures are completely ineffective.
More importantly for privacy advocates, the court firmly pushed back against the demonization of privacy software, cementing the legitimate status of VPN providers across the European Union.
This is only possible due to the Age Verification clampdown – every internet user has to prove their age, and their identity. This allows the government to unmask anonymous users. Sure, there are cases in which this is a great idea. Unfortunately there are plenty of cases where anonymous speech is hugely important, such as if you don’t want to be prosecuted for your sexuality, ideology, race or want to discuss how to free yourself from a far right controlling government. This has nothing to do with child safety and this immediate shift using the new possibilities shows that it’s all about control.
Premier Jacinta Allan announced on Sunday that her government will hand the Victorian Civil and Administrative Tribunal the power to issue “demasking orders,” forcing social media companies to reveal the identity of anonymous users accused of online vilification.
VCAT is the body Victorians deal with over rental bonds, planning permits, and faulty dishwashers. It is now being asked the question of who gets to speak without their legal name attached to it.
[…]
“We’re introducing nation-leading laws to keep AI and tech companies accountable, protect our kids & unmask anonymous online hate,”
[…]
On 15 April 2026, a new harm-based protection commenced, which means a complainant no longer has to show that anyone was incited to do anything. Harm is enough, and harm is assessed after the fact by people who were not there.
[…]
A demasking order forces a platform to reveal the identity of anonymous users “accused of online vilification.” Not found liable. Not adjudicated. Accused.
Anyone who has ever run an anonymous account knows what that changes. Once a name is out, it stays out. The order cannot be recalled, the employer cannot unlearn it, and the person who filed the complaint does not need to win anything for the exposure to be permanent. The remedy arrives before the finding does.
That asymmetry is where the chilling effect on speech is relevant.
A Victorian who wants to criticize a religious institution, or a religious practice, or a government policy on immigration, now has to price in the possibility that a tribunal will tell the world who they are.
France said Friday it was blocking access to the online prediction market Polymarket, as punters continued to make bets despite a ban already in place.
The national gaming authority ANJ said Friday that Polymarket’s webpage would be blocked on French territory, which adds to a November 2024 ban on financial transactions to the site.
Polymarket is one of a number of online prediction markets which allow people to bet on the outcome of future events.
The ANJ said the site’s continued availability – where betting odds on different events are updated in real time – constituted advertising.
“Advertising, by any means whatsoever, in favour of an unauthorised betting or gambling site is a criminal offence,” the ANJ said, and noted the fines could reach €100,000 ($114,000).
The regulator said that despite the ban on transactions from French accounts, visits from French internet addresses to Polymarket’s site have been rising, hitting 578,751 last month.
The betting markets have caused a number of problems.
France’s weather agency Meteo-France filed a complaint in April after one of its weather probes was hacked in order to fix bets on Polymarket.
A US soldier is facing federal charges for using classified information to bet on online prediction markets related to the US operation in January to capture former Venezuelan president Nicolas Maduro. He allegedly made more than $400,000.
The White House said Thursday a teleprompter operator had been suspended over allegations he placed bets with a prediction market on the content of US President Donald Trump‘s speeches.
France is one of a number of European countries that restrict or block access to online prediction markets such as Germany, Italy and Spain, according to the ANJ.
How smart should a smart TV be? According to LG‘s latest TV terms and conditions, the answer is “not quite smart enough to comply with wiretapping laws”, because that’s now your responsibility if LG captures the voice of a guest in your house through its AI voice services. Though the situation with LG monitors appears to be even more dramatic.
As Gamers Nexus reports, some LG monitors appear to be installing adware on Windows PCs without asking for permission: in addition to the LG Monitor App Installer, they also install McAfee Scam Detector.
LG’s own app requires full access to all system resources, which potentially includes all your online activity, logins, hardware, location and more — while McAfee has a long history of being installed on devices as ‘bloatware’, and people are not reacting positively to suddenly finding it on their PC.
[…]
The bit that’s causing consternation regarding smart TVs is part 6(d) of the new LG Electronics terms of service, headed Voice Recognition and Privacy Compliance. As Notebookcheck‘s Hannes Brecher notes, the section states that it’s your responsibility “to obtain all necessary consents from any third parties whose voices may be captured by the Product and to notify household members and guests that their voices may be captured and processed, in compliance with applicable wiretapping, eavesdropping, and privacy laws.”
There are three ways around that. One, you can turn off all microphone-based features. Some people won’t mind that, but they can be useful — especially asking it for settings you don’t know how to find.
Two, you can avoid installing the latest software — but that means you won’t get any security updates, which are important (to protect your privacy, ironically, among other things).
Or you can disable your TV’s connection to the internet so it can’t send information back, but that obviously makes it less useful, and will also disable the voice controls anyway.
What is ‘adversarial clothing’ I hear you ask? Well it’s a relatively new term used to describe garments (clothes) which are designed to confuse facial recognition systems.
Models wearing Urban Privacy T-shirts. Photograph: Urban PrivacyCAP_ABLE, one of the startups at the forefront of this, describes itself as a fashion design studio that develops products at the intersection of ethics and technology.
Rachele Didero, oe of the founders of Cap_able, said interest in her brand had rocketed in the last few years. She said “When I started doing this in 2018, people thought I was designing masks to rob banks. But now these concerns are no longer niche. New generations are increasingly afraid of AI and concerned for their privacy. Those wearing these products are the vanguard. The mainstream is quickly coming up behind them, helped by the fact that bigger companies will see the potential for profit and will push the trend into the popular, public domain, changing the way we dress on a large scale.”
Designers say that as well as offering a degree of protection from surveillance, their clothes make a powerful fashion statement about the importance of privacy
The UK National Newspaper, the Guardian wrote recently“As facial recognition technology is rolled out across Britain’s public spaces, a new generation of designers say privacy could be the next big fashion trend”.
Nick Tidball, co-founder of the clothing brand Vollebak, another company producing ‘adversarial clothing’ was quoted as saying “Anti-surveillance feelings are so widespread that all it would take is for a single celebrity to wear one of these garments, currently popular in the countercultural fashion world, to a high-profile event for it to take off”.
Another startup involved, Urban Privacy says that you can outsmart face recognition with the FACEPTION knitwear collection and blind night vision cameras with the URBANGHOST LED coat – both billed as “stylish protection for your privacy in the digital age”.
Urban Privacy say that their Manifesto Collection is legal to wear and enforces the GDPR laws protecting EU citizens’ privacy and human rights.
This aught to end well. If it’s a Boeing, I’m not going!
Boeing will be allowed to take responsibility for certifying all of its 737 Max and 787 planes starting next week, the Federal Aviation Administration said Friday.
The FAA said that after months of review the agency decided that Boeing’s final safety checks on its planes are good enough to ensure they are airworthy.
Since September, Boeing and the agency had been taking weekly turns performing the safety checks that are required before aircraft are cleared for delivery and declared safe to fly. The FAA said Friday that the plane maker and government inspectors were both issuing similar findings as they issued airworthiness certificates.
Federal regulators took full control over 737 Max approvals in 2019, after the second of two crashes that were later blamed on a new software system Boeing developed for the aircraft. The FAA ended the company’s right to self-certify 787 Dreamliners in 2022, citing ongoing production quality issues.
“Safety drives everything we do, and this step forward is only possible because we are confident it can be done safely,” FAA Administrator Bryan Bedford said.
Government inspectors will continue to oversee Boeing’s factories, but Bedford said they will now be able to focus more on finding and addressing potential defects earlier in the manufacturing process. The plane maker said it will continue working to improve safety.
“Boeing will continue to work under the oversight of the FAA in building safe, high-quality commercial airplanes that comply with all airworthiness certification requirements,” Boeing said in a statement.
Over the past year the FAA has also been easing the monthly production limits it imposed on Boeing’s 737 Max jets after a panel flew off one of those planes operated by Alaska Airlines midflight in January 2024. That limit has gradually increased from 38 per month to reach 47 per month this summer.