Mysterious circular structure spotted near Area 51 sparks theories of UFO landing site
A strange circular formation just miles from the highly classified Area 51 base has fueled speculations that it could be a secret UFO landing site.
Son of American boxing legend Sugar Ray Leonard 'arrested trying to break into his father's house after violating restraining order'
The report claims that Daniel Ray Leonard, 25, left the property in the back of a police car after 'violating a restraining order'. He is the youngest son of the boxing icon, and his fourth child overall.
Hayden Panettiere reveals 'deeply uncomfortable' dynamic with Connie Britton on Nashville set: 'My billing had gone way up'
The 36-year-old Golden Globe winner confessed she was never meant to be the star of the ABC musical drama, which aired for six seasons spanning 2012-2018
Google Publishes Exploit Code Threatening Millions of Chromium Users
An anonymous reader quotes a report from Ars Technica: Google on Wednesday published exploit code for an unfixed vulnerability in its Chromium browser codebase that threatens millions of people using Chrome, Microsoft Edge, and virtually all other Chromium-based browsers. The proof-of-concept code exploits the Browser Fetch programming interface, a standard that allows long videos and other large files to be downloaded in the background. An attacker can use the exploit to create a connection for monitoring some aspects of a user's browser usage and as a proxy for viewing sites and launching denial-of-service attacks. Depending on the browser, the connections either reopen or remain open even after it or the device running it has rebooted.
The unfixed vulnerability can be exploited by any website a user visits. In effect, a compromise amounts to a limited backdoor that makes a device part of a limited botnet. The capabilities are limited to the same things a browser can do, such as visit malicious sites, provide anonymous proxy browsing by others, enable proxied DDoS attacks, and monitor user activity. Nonetheless, the exploit could allow an attacker to wrangle thousands, possibly millions, of devices into a network. Once a separate vulnerability becomes available, the attacker could use it to then compromise all those devices.
"The dangerous part here is that you can just have a lot of different browsers together that you can in the future run something on that you figure out," said Lyra Rebane, the independent researcher who discovered the vulnerability and privately reported it to Google in late 2022 in an interview. He said using the exploit code Google prematurely published would be "pretty easy," although scaling it to wrangle large numbers of devices into a single network would require more work. In the thread of Rebane's disclosure to Google, two developers said in separate responses that it was a "serious vulnerability." Its severity was rated S1, the second-highest classification.
Since its reporting 29 months ago, the vulnerability remained unknown except to Chromium developers. Then on Wednesday morning, it was published to the Chromium bug tracker. Rebane initially assumed the vulnerability was finally fixed. Shortly thereafter, he learned that, in fact, it remained unpatched. While Google removed the post, it remains available on archival sites, along with the exploit code. Google representatives didn't immediately respond to an email asking how and why it published the vulnerability and if or when a fix would become available. The exploit works by abusing Chromium's Browser Fetch API to open a service worker that remains persistently active. A malicious website can trigger it through JavaScript, creating a connection that can be used "for monitoring some aspects of a user's browser usage and as a proxy for viewing sites and launching denial-of-service attacks," reports Ars.
Depending on the browser, those connections "either reopen or remain open even after it or the device running it has rebooted," effectively turning the device into part of a "limited botnet."
Read more of this story at Slashdot.
QUENTIN LETTS: Wes Streeting's big speech was 19 minutes of platitudes and soggy cliches. There wasn't one killer phrase
In the centre, looking a little plumper and more important than the rest, sat Wes. Our would-be PM had come to make his big resignation speech.
Southampton LOSE appeal against EFL for Championship play-off final expulsion and next season points deduction despite hiring lawyer used by Man City - with Middlesbrough confirmed as Hull's Wembley rivals
Southampton have lost their appeal against the EFL, with Middlesbrough now officially confirmed as Hull City's opponents in Sunday's Championship play-off final.
BOB SEELY: Breathtaking stupidity! We shut down our own oil industry - then give money to an enemy waging war on a close ally
If you want an example of the reckless foolishness of the Net Zero madness foisted upon Britain, look no further than Labour's decision to ease sanctions on Russia's murderous regime.
Supermodel Izabel Goulart deemed 'unrecognizable' by shocked fans after debuting bizarre new look
She's one of the most successful international supermodels of the past 20 years, but some fans had trouble recognizing Izabel Goulart at the Cannes Film Festival earlier this week.
Adorable beagle howls for the first time after he and 1,500 other dogs were freed from Wisconsin scientific testing facility
Eagle, one of the hundreds of beagles rescued from a testing facility in Wisconsin, let out an adorable howl for the first time since he gained his freedom.
Their incestuous romance shocked America… now mother who refused to end relationship with her own SON has sunk to an astonishing new low
A decade ago, Monica Mares and her biological son Caleb Peterson stunned America when they revealed they had fallen 'in love' after reconnecting on Facebook.
RHEL 10.2 Released With New AI Command Line Assistance
Red Hat has released RHEL 10.2 and 9.8 with new AI-assisted command-line tools. The releases also add updated developer toolchains such as Go 1.26, LLVM 21, Rust 1.92, Python 3.14, and PHP 8.4. Phoronix reports: Red Hat Enterprise Linux has introduced the goose command for power users. Goose is an optional CLI AI assistance with model context protocol (MCP) integration. There is also improved visual output via color output enhancements. As for their rationale with the new AI integration: "The business value: Faster problem resolution, and a quicker path for new administrators to become proficient. This translates into higher developer productivity and accelerated project timelines."
Read more of this story at Slashdot.
London bus driver, 64, dies 'after being attacked while working': Man, 32, is charged
Police were called just after midnight on Monday to reports that an incident had occurred on Battersea Bridge.
On-the-run 'dine and dash' ex-lawyer has fled abroad and posted pictures of herself enjoying a daytrip to Disneyland Paris
Serial dine-and-dash ex-lawyer Kerry Stevens, 40, has fled abroad and has been brazenly posting photos of herself enjoying a day trip to Disneyland - despite being wanted by police.
Even Claude agrees: hole in its sandbox was real and dangerous
Another day, another AI bug silently fixed with no CVE and no public disclosure
Three sisters who died in sea off Brighton beach are named for first time: Father pays emotional tribute to his daughters as police continue probe into their deaths
The tragic discovery was made by rescuers early last Wednesday morning following reports of someone in the water at 5.45am.
Sienna Miller shows off her bruises and gun mishaps on the set of Jack Ryan after admitting she 'threw herself' at best friend Emily Blunt's husband John Krasinski to land role
The actress, 44, returned to work just three weeks after the birth of her second child with partner Oli Green to promote her role in the thriller, which follows up on the TV series of the same name.
Top secret government files reveal astonishing UFO encounter with 13 fighter jets for first time
Hundreds of never-before-seen UFO encounters have been released to the public after decades of legal fighting and top-secret classification.
Intel's CEO reveals early hiring challenges as bankruptcy concerns deterred top talent
Recovering chipmaker looks beyond 14A to 10A and 7A process nodes in foundry comeback bid
GitHub's Internal Repos Breached Via Employee's Use of Malicious VS Code Extension
Longtime Slashdot reader Himmy32 writes: GitHub has announced on X that their internal repositories have been breached through a compromised VS Code Extension on an employee's workstation. Bleeping Computer reported that the attack is linked to TeamPCP who have been in the news for a recent campaign affecting Checkmarx, Trivy, SAP, TanStack, and Bitwarden. The group appears to be attempting to sell the stolen code on cybercrime forums. "Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately," the company said. "Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker's current claims of ~3,800 repositories are directionally consistent with our investigation so far."
Although the investigation remains ongoing, GitHub says it has "no evidence of impact to customer information stored outside of GitHub's internal repositories." The company has also not said whether it's in contact with the hackers or if it's received a ransom demand.
Read more of this story at Slashdot.
Party time! Charles and Camilla round off their visit to Northern Ireland with a garden party at Hillsborough Castle
Their Majesties gathered at the historic venue to meet guests from the nation's voluntary and charitable sectors who have had lasting impacts on their community.