Connect with us
DAPA Banner

Tech

Man gets 30 months for selling thousands of hacked DraftKings accounts

Published

on

Hacker

23-year-old Kamerin Stokes of Memphis, Tennessee, was sentenced to 30 months in prison for selling access to tens of thousands of hacked DraftKings accounts.

According to court documents, the accounts were hijacked by Nathan Austad (aka Snoopy) with the help of Joseph Garrison (a third accomplice charged in May 2023) in a massive November 2022 credential-stuffing attack that compromised nearly 68,000 DraftKings accounts.

U.S. prosecutors said Austad and Garrison used a list of credentials stolen in multiple breaches to hack into DraftKings accounts, then sold access to others who stole around $635,000 from roughly 1,600 compromised accounts.

Wiz

While they made over $2.1 million selling some of these hijacked DraftKings accounts (as well as FanDuel and Chick-fil-A accounts) through their own “shops,” they also sold many in bulk to Stokes (also known online as TheMFNPlug), who resold them through his own “shop.” 

One month later, the sports betting giant said it had to refund hundreds of thousands of dollars stolen from hacked accounts, after all available funds were withdrawn following the addition of a new payment method and a $5 deposit to verify its validity.

Advertisement
DraftKings
DraftKings “cash-out” instructions (BleepingComputer)

​After being arrested, pleading guilty, and released while awaiting trial, Stokes reopened his shop with a new “fraud is fun” tagline and continued selling access to compromised accounts for various retailers.

Prosecutors said he also admitted “he had been running these types of shops for three years” and that he relaunched the shop because he needed money to pay his attorney.

“Kamerin Stokes victimized thousands of users of an online betting website though [sic] a cyberattack,” U.S. Attorney Jay Clayton noted in a Thursday press release.

“After pleading guilty to federal crimes, Stokes audaciously reopened his criminal business, marketed using the tagline’ fraud is fun,’ and said that he opened the new Shop in part because ‘gotta pay my attorneys,’ referring to his prosecution in this case.”

After reopening his website, Stokes was again remanded into federal custody after being arrested for violating the conditions of his pretrial release.

Advertisement

In addition to 30 months in prison, Stokes was given 3 years of supervised release and ordered to pay $1,327,061 in restitution and $125,965.53 in forfeiture.

AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

6 Highly-Rated Kitchen Appliances On Amazon That Are Not Ninja Products

Published

on





We may receive a commission on purchases made from links.

Ninja has a chokehold on the small kitchen appliance category, and for good reason. It’s innovative and delivers quality that consumers trust. Ninja has earned the hype. But it’s not the end-all, be-all brand when it comes to stocking your kitchen, especially if you prefer to shop on Amazon.

Whether you’re air frying dinner for the family or making frozen treats for dessert, there are other highly-rated brands and products on Amazon that can do the job well, and often at a lower price. Appliances that don’t have the Ninja brand stamped on the front can still outperform your expectations. This collection of highly rated kitchen appliances on Amazon that are not Ninja products deserves just as much attention as the Ninja products you likely already know and love. Or in some cases, maybe more. If you’re ready to upgrade your kitchen without defaulting to the usual suspects, let’s shake things up a bit.

Advertisement

CASABREWS CM5418 Espresso Machine

Many people see home espresso machines as unnecessary luxuries. But if you treat your morning coffee as a survival tool, you know that an espresso machine holds just as much value as any other coffeemaker. That extra pop of caffeine in your drink means you can skip the pricey coffee shop on your commute and get the morning buzz you need to get moving.

Advertisement

Ninja’s espresso machine is far from your only option. The Casabrews espresso machine offers form and function in a single package. It can punch out a shot of espresso quickly and cleanly, and even steam and froth your milk on the same device. Stainless steel works well in any kitchen, and a small, narrow footprint means it doesn’t take up as much counter space as your typical coffee machine. Plus, you get to make your drink exactly how you want it, every time. The Casabrews espresso machine is $139.99 on Amazon. It has earned an average 4.4-star rating across more than 7,000 user reviews on Amazon, with users consistently mentioning simplicity, quality, and value for the money. By comparison, SharkNinja’s espresso and coffee barista systems start at $279.99.

Advertisement

Cuisinart Ice Cream Maker

Making ice cream at home feels like more effort than it’s worth until you find a decent ice cream maker. Then it makes perfect sense, especially since you can control the ingredients. One option that makes the process easy and worthwhile is the Cuisinart Ice Cream Maker. It does most of the heavy lifting to make limited-ingredient ice cream, sorbet, and yogurt. Making these treats at home means you can control what goes into them, resulting in healthier options.

The Cuisinart ice cream maker has earned an average 4.6-star rating across more than 18,000 user reviews. It says it can turn your raw ingredients into a ready-to-eat dessert in under 30 minutes. The container is big enough to make up to two quarts at a time. Ninja offers a similar appliance, called the Creami. It compares to the Cuisinart in size and function, but Ninja Creami ice cream makers start at $199.99, almost $100 more than the Cuisinart.

Advertisement

BKPPM Slushie Maker

A slushie maker sounds like one of those cool kitchen gadgets you’re excited to buy, use a few times, and then forget you have it. That may be true for some slushie machines, but the ones that make the process easy and delicious are less likely to become cabinet clutter. The good thing about the BKPPM Slushie Maker on Amazon is that you don’t need special mixes or learn lots of steps to use it. You can add your favorite juice, wine, or even soda, then let the machine work its magic.

The Ninja Slushi offers a similar experience. It comes with multiple preset modes for one-touch operation and can make a variety of drinks, including slushies, milkshakes, frappes, and spiked drinks. Neither machine requires ice, and both promote dishwasher-safe parts for easy cleanup. One of the most notable differences is price: The Ninja version starts at $349.99 and goes up from there, while the BKPPM Slushie Maker on Amazon retails for $269.99. The BKPPM Slushie Maker has also earned an average 4.4-star rating over more than 1,000 customer reviews.

Advertisement

Cosori Air Fryer

Air fryers get a lot of attention from home chefs. There’s a good reason for that: they’re among the most versatile and most recommended small kitchen appliances you can get. Air fryers let you get crispy, fried-style food without drenching it in oil first. There are tons of air fryers on the market right now, including Ninja’s popular Crispi line of glass air fryers. But if you’re not looking to shell out $179.99 or more for one, you might want to check out the Cosori Air Fryer on Amazon.

The Cosori retails for $119.99 (regular price) and has an impressive 4.8-star rating over more than 15,000 reviews. Customers consistently mention the cooking performance, ease of cleaning, quality, and noise level of this air fryer. Ultimately, a good air fryer should cook your food evenly, keep it crisp, and do both quickly and easily. The Cosori checks all of these boxes, according to its users. It can reach temperatures of up to 450 degrees Fahrenheit and runs at a fairly quiet 53 decibels. The basket types are the biggest difference (along with price), but if you’re not picky about what your food actually cooks in, the Cosori might make a great alternative.

Advertisement

Nutribullet Blender System

The only thing better than a good blender is a whole blending system. While a blender covers the basics, a full blending system changes how often you actually use it. A single powerful base comes with multiple blending blades and attachments, including a drink pitcher, food processor, and single-serve containers for on-the-go drinks or small batches of soups. You need different containers and blades for different jobs, and a solid kitchen system can do them all.

Advertisement

Ninja offers a line of kitchen blending systems, but so do plenty of other kitchen brands. One comparable example is the Nutribullet Triple Prep System on Amazon. It includes a mix of full-size and single-serve containers, along with a food processor container and various accessories. The smart base recognizes each container when you attach it, and you can choose from several pre-programmed settings to get ideal blends for specific ingredients. The Nutribullet system has garnered a 4.5-star rating across more than 700 reviews. Pricewise, the Nutribullet system retails on Amazon for $219.99, which is also the starting price for Ninja’s lineup.

Advertisement

Hamilton Beach Countertop Grill

Getting a good sear indoors usually comes with tradeoffs. Indoor countertop grills can be a bit smoky. Heat might be uneven, and results don’t often compare to those of a real grill. Still, countertop grills are becoming more popular since they don’t require a dedicated space outdoors and don’t take up much room to begin with. In the classic Ninja style, the brand offers several models to choose from, starting at $149.99. But one option from Hamilton Beach can help you save money without compromising on quality.

Hamilton Beach’s Electric Indoor Searing Grill is compact and simple to use. There’s one temperature control switch, a drip tray, and not much else. Since it’s made for indoors, you can enjoy your favorite grilled foods year-round in any type of weather. Even better, the Hamilton Beach option is listed at $98.57 on Amazon, significantly less than Ninja’s cheapest indoor grill. More than 31,000 customers have rated the Hamilton Beach indoor grill, resulting in a 4.5-star rating. Users say it’s easy to clean, and its performance compares to that of an outdoor grill.

Advertisement

How We Chose These Top-Rated Appliances on Amazon

The title gives away most of the requirements. We’re looking for items that fall under the kitchen appliance category and are available for sale on Amazon. Also, they have to be from a brand other than Ninja, which also includes the Shark name. We focused our search on the kitchen appliances that Ninja offers, then found a comparable brand and product that users seem to love. As the title suggests, they need to be highly rated. That means hundreds of four-star and five-star reviews with similar themes in quality, value, function, and usefulness. In other words, are most people happy with their purchase?

Only kitchen appliances that meet all of the above made it to the list. There are tons of great kitchen appliances out there that can comfortably compete with Ninja. This list focuses on just six of those options.

Advertisement



Source link

Continue Reading

Tech

Nevada Police Can Now Track Cellphones Without a Warrant

Published

on

“Nevada quietly signed an agreement earlier this year with a company that collects location data from cellphones, allowing police to track a device virtually in real time,” reports the Associated Press. “All without a warrant.”

The software from Fog Data Science, adopted this January in Nevada through a Department of Public Safety contract, pulls information from smartphone apps in order to let state investigators identify the location of mobile devices. The state is allowed more than 250 queries a month using the tool, which allows officers to track a device’s location over long stretches of time and enables them to see what Fog calls “patterns of life,” according to company documents from 2022. It can help them deduce where and when people work and live, with whom they associate and what places they visit, according to privacy experts… Traditionally, police must obtain a warrant from a judge to access cellphone location information — a process that can take days or weeks. And while cellphone users may be aware that they are sharing their location through apps such as Google Maps, critics say few are aware that such information can make its way to police…

Other agencies in Nevada have been known to use technology similar to Fog. In 2013, Las Vegas Metropolitan Police Department acquired something known as a cell-site simulator that mimics cellphone towers and can sweep up signals from entire areas to track individuals, with some models capable of intercepting texts and calls. Police have not released detailed information about the technology since then.

“Police in other states have said the technology (and its low price tag) has helped expand investigatory capacity,” the article adds.

But it also points out that Fog Data Science has a web page letting individuals opt out of all their data sets.

Source link

Advertisement
Continue Reading

Tech

I tested the Ultion Nuki 2025: the most well-rounded smart lock in the UK for ultimate peace of mind

Published

on

Why you can trust TechRadar


We spend hours testing every product or service we review, so you can be sure you’re buying the best. Find out more about how we test.

Ultion Nuki 2025: one-minute review

The Ultion Nuki 2025 is what happens when a smart lock starts behaving like a complete security product.

At a glance, it’s doing the same job as 2023’s Ultion Nuki Plus: pairing Brisant Secure’s Ultion 3 Star PLUS cylinder and UK-specific door furniture with Nuki’s Smart Lock Pro and platform. In practice, though, this version looks more cohesive, feels quicker to respond and is better aligned with how people actually use a front door every day.

Advertisement

Ultion Nuki smart lock installed on exterior of door

(Image credit: Future)

Just as importantly, there are sensible fallbacks everywhere. You can still use a physical key, operate it manually from inside, and include a biometric keypad or keyfob if you want different ways in.

Source link

Continue Reading

Tech

Equinix’s Peter Lantry on powering Ireland sustainably

Published

on

The latest episode of The Leaders’ Room podcast season four features Peter Lantry, managing director of Equinix Ireland. This series is created in partnership with IDA Ireland.

Once again in season four of The Leaders’ Room podcast, we get to know the leaders of some of the most influential multinationals in tech, life sciences and innovation, as well as getting insights into their leadership styles and the high-tech trends they see coming down the line.

In this latest episode, we speak to Peter Lantry, managing director of Equinix Ireland, about the intersection of energy, digital infrastructure and sustainability – and about what Ireland’s digital future could look like if we get the balance right. It’s a wide-ranging and eye-opening conversation about the global data centre giant that sits at the heart of Ireland’s digital ecosystem, and about a man whose career trajectory is decidedly well-matched to the task at hand.

Advertisement

Equinix is the world’s leading co-location retail data centre provider – something Lantry describes, cleverly, as akin to being a “digital airport”, connecting networks, cloud platforms, content providers and enterprises across more than 280 data centres in 35 countries. It works with major players from Nvidia and AWS to Google, as well as with smaller retail clients.

In Ireland, while Equinix has been here 10 years, many of the data centres it now owns, like those of Telecity, have been operating since 1998. The Irish operations have grown significantly since, most recently with the acquisition of two BT data centres and a new Blanchardstown facility, DB7X, now under construction.

What strikes you listening to Lantry is the sheer scale of what Equinix does – more than half a million direct connections between businesses globally, and more than 90pc of all internet traffic in the world flowing through their data centres. The subsea cables that connect Ireland to the rest of the world terminate in Dublin, most of them into an Equinix data centre.

The energy and sustainability conversation is where this episode really catches the imagination. Lantry and his team are doing genuinely pioneering things at Equinix Ireland – hydrogen fuel cells already operating at one of their Dublin sites, solar canopies going in, and an innovative grid solution planned working with the IDA, EirGrid and ESB Networks.

Advertisement

Lantry believes Ireland has a real opportunity, with its ambition to have 22GW of renewable power connecting to the grid by 2030. The question, he says, isn’t whether Ireland can become a leading sustainability hub, but whether we have the collective will to all work together and make it happen.

His vision of data centres that can flex dynamically with the grid – stepping in to support it when needed, rather than adding to its burden – is a compelling one. If we export our data and digital services rather than our electricity, he argues, we could generate perhaps 10 times the value for the Irish economy, so it is crucial, he believes, that we get our digital infrastructure right.

Lantry’s career trajectory means it’s easy to see why Equinix came calling. Starting as a civil and structural engineer with Arup, moving into management science and then consultancy with PwC and IBM, followed by 17 formative years with EirGrid – where he was connecting data centre customers, wind farms and working on the design and implementation of the Irish single electricity market. This was followed by a spell as managing director of Hitachi Energy, where he grew their global data centre business from €350m to €750m in a single year.

It is a CV that makes you understand why his Equinix colleagues remarked, with some amusement, that he was “fairly unique” when the energy crunch hit. He brings something genuinely rare to the role – a deep, practical understanding of both utilities and digital infrastructure, earned over several decades.

Advertisement

On leadership, Lantry talks about Level 5 leadership, referencing James Collins’ book ‘Good to Great’ – leading by example, listening deeply, supporting others and removing the barriers that stop teams from delivering. What comes through clearly is his sense of purpose: the utility-like nature of what Equinix does, connecting everyone and everything in a sustainable way, gives the whole team something genuinely meaningful to rally behind, he says.

I found his emphasis on being fully present in every conversation particularly striking – that good leadership means making the people you are talking with feel truly heard and understood. He describes himself as something of a translator, someone who has spent a career connecting the dots between brilliant people with different expertise and different drivers. Perhaps that instinct was shaped early he says. Lantry grew up moving between countries with his parents – the Netherlands, England, France, Colombia, and back to Ireland – learning to navigate different cultures and ways of engaging. Whatever its roots, it is clearly central to how he leads today.

We’re grateful to all our interviewees again this season, for taking the time out of busy schedules to come into the studio and share their insights and their intelligence with us. And a big thanks as ever to our partners IDA Ireland who make this series possible.

The Leaders’ Room podcast is released fortnightly and can be found by searching for ‘The Leaders’ Room’ wherever you get your podcasts. For those who prefer their audio with visuals, filmed versions of the podcast interviews are all available here on SiliconRepublic.com.

Advertisement

Check out The Leaders’ Room podcast for in-depth insights from some of Ireland’s top leaders. Listen now on Spotify, on Apple or wherever you get your podcasts.

Source link

Advertisement
Continue Reading

Tech

Slack chats and internal data from failed startups are finding a second life in AI training

Published

on


What was once considered operational residue is now being packaged, scrubbed, and sold to AI developers seeking richer training environments. The shift reflects a broader evolution in how advanced AI models are built. Early large language models drew heavily from news archives, Wikipedia, and forums. Now, newer systems, particularly agentic…
Read Entire Article
Source link

Continue Reading

Tech

Apple account change alerts abused to send phishing emails

Published

on

Apple logo

Apple account change notifications are being abused to send fake iPhone purchase phishing scams within legitimate emails sent from Apple’s servers, increasing legitimacy and potentially allowing them to bypass spam filters.

A reader shared an email with BleepingComputer that appeared to be a standard Apple security notification that stated their account information had been updated.

However, embedded within the message was a phishing lure claiming that an $899 iPhone purchase had been made via PayPal, along with a phone number to call to cancel the transaction.

Wiz

“Dear User 899 USD iPhone Purchase Via Pay-Pal To Cancel 18023530761,” reads the Apple account phishing email.

“The following changes to your Apple Account, hxfedna24005@icloud.com, were made on April 14, 2026 at 7:01:40 PM GMT:”

Advertisement

“Shipping Information”

Callback phishing email abusing Apple Account change notifications
Callback phishing email abusing Apple Account change notifications
Source: BleepingComputer

These emails are designed to trick recipients into thinking their accounts were used for fraudulent purchases and scare them into calling the scammer’s “support” number.

When calling the number, scammers typically try to convince victims that their accounts have been compromised and may instruct them to install remote access software or provide financial information.

In previous callback phishing campaigns, this remote access has been used to steal funds from bank accounts, deploy malware, or steal data.

Abusing Apple account notifications

While the phishing lure is not new, the campaign illustrates how threat actors continue to evolve their tactics by exploiting legitimate website features to conduct attacks.

Advertisement

The phishing email was sent from Apple’s infrastructure using the address appleid@id.apple.com and passed SPF, DKIM, and DMARC authentication checks, indicating it was a legitimate email from Apple.


dkim=pass header.d=id.apple.com header.i=@id.apple.com header.b=o3ICBLWN
spf=pass (spf.icloud.com: domain of uatdsasadmin@email.apple.com designates 17.111.110.47 as permitted sender) smtp.mailfrom=uatdsasadmin@email.apple.com

Further analysis of the email headers shows that the message originated from Apple mail infrastructure and was not spoofed.


Initial server: rn2-txn-msbadger01107.apple.com
Outbound relay: outbound.mr.icloud.com
IP address: 17.111.110.47 (Apple-owned)

To conduct the attack, the threat actor creates an Apple ID and inserts the phishing message into the account’s personal information fields, splitting the text across the first and last name fields.

BleepingComputer was able to replicate this behavior by creating a test Apple account and adding similar callback phishing language to the first and last name fields. This is because each field cannot contain the entire scam message.

Advertisement
Replication attack by changing Apple account name fields
Replication attack by changing Apple account name fields
Source: BleepingComputer

To trigger the Apple account profile change notification, the attacker modifies the account’s shipping information, which causes Apple to send a security alert notifying the user of the change.

Because Apple includes the user-supplied first and last name fields within these notifications, the phishing message is embedded directly into the email and delivered as part of a legitimate alert.

While the target of the attacks received the message, the email was initially sent to an iCloud email address associated with the attacker’s account. This email address is also included in the notification email, making the email look more concerning and potentially leading someone to believe the account was hacked.

Header analysis shows that the original recipient differs from the final delivery address, indicating that the attacker is likely using a mailing list to distribute the emails to multiple targets.

This campaign is similar to a previous phishing campaign that abused iCloud Calendar invites to send fake purchase notifications through Apple’s servers.

Advertisement

As a general rule, users should treat unexpected account alerts claiming purchases or urging them to call support numbers with caution, especially if they did not initiate any recent changes or if they contain unusual email addresses.

BleepingComputer contacted Apple on Friday about this campaign, but did not receive a response, and the abuse is still possible.

AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

Source link

Advertisement
Continue Reading

Tech

Best Meta Glasses (2026): Ray-Ban, Oakley, AR

Published

on

Every time I’ve written about Meta’s AI-enabled glasses, I invariably get asked these questions: Why do you even want these? Why do you want smart glasses that can play music or misidentify native flora in a weirdly cheery voice? I am a lifelong Ray-Ban Wayfarer wearer, and I’m also WIRED’s resident Meta wearer. I grab a pair of Meta glasses whenever I leave the house because I like being able to use one device instead of two or three on a walk. With Meta glasses, I can wear sunglasses and workout headphones in one!

Meta sold more than 7 million pairs in 2025. Take a look at any major outdoor or sporting event, and you’ll see more than a few people wearing these to record snippets for Instagram or TikTok. Meta’s partnership with EssilorLuxottica has made smart glasses accessible, stylish, and useful and is undoubtedly the reason why Google, and now Apple, are trying to horn in on the market. After the notable flop that is the Apple Vision Pro, Apple is recalibrating its face-wearable strategy, moving away from augmented reality (AR) toward simpler, display-less, and hopefully good-looking glasses.

That’s not to say that you shouldn’t be careful how you use these glasses. Meta doesn’t have the greatest track record on privacy, and the company has continued to push forward with policies that are questionable at best. Even if you’re not concerned that face recognition will allow Meta to target immigrants or enable stalkers to find their victims, at the very least, people really do not like the idea that you could start recording them at any moment.

Probably the biggest hurdle to wearing Meta glasses is that even doing so seems like a gross violation of the social contract. After all, these are Mark Zuckerberg’s “pervert glasses.” When I pop these on my head, I’ve had friends (and my spouse) recoil and say, “I have apps to warn me away from people like you.” The best part, though, is that Oakley and Ray-Ban already make really great sunglasses. Even if the battery runs out or you don’t use Meta AI at all, these are stellar at shading your eyes from the sun.

Advertisement

Anyway, if you decide to try them, here’s what you should get. If you do chicken out, check out our buying guides to the Best Smart Glasses or the Best Workout Headphones for more.

Table of Contents

Best Overall

  • Photograph: Boone Ashworth

Ray-Ban

Meta Glasses (Gen 2)

Advertisement

Last year, Meta upgraded the original Meta Ray-Ban Wayfarers that became a smash hit. These are Meta’s entry-level glasses, and they come in a variety of lens styles. You can order them with clear lenses, prescription lenses, transition lenses, or the OG sunglass lenses, as well as in a variety of fits, including standard, large, or high-bridge frames. Improvements to this generation include an upgrade to a 12-MP camera and up to eight hours of battery life; writer Boone Ashworth’s testing clocked in at five to six hours.

Source link

Continue Reading

Tech

DIY UPS Keeps Home Assistant Running

Published

on

If you put a bunch of computers in charge of your house, it’s generally desirable to ensure their up-time is as close to 100% as possible. An uninterruptible power supply can help in this regard. To that end, that’s why [Bill Collis] whipped one up for his Home Assistant setup.

[Bill]’s UPS is charged with one job—keeping the Home Assistant Green hub and an Xfinity XB7 cable modem online when the grid goes dark. The construction is relatively straightforward. When the grid is up, everything is powered via a Mean Well AC-DC 12 V power supply, while the power is also used to charge a 12.8 V 10 Ah lithium iron phosphate battery pack. When the grid goes out, the system switches over to running the attached hardware on pure battery power. A Victron BatteryProtect is used to automatically disconnect the load if the battery voltage drops too low. Meanwhile, a Shelly Plus Uni module is used to monitor battery voltage and system status, integrated right into Home Assistant itself.

If you want to keep the basics of your smart home going at all times, something like this is a pretty simple way to go.  We’ve featured some other great UPS builds in the past, too. If you’re whipping up your own hardware to keep your home or lab alive in the dark of night, don’t hesitate to notify the tipsline.

Advertisement

Source link

Advertisement
Continue Reading

Tech

NIST to stop rating non-priority flaws due to volume increase

Published

on

NIST to stop rating non-priority flaws due to volume increase

The National Institute of Standards and Technology will stop assigning severity scores to lower-priority vulnerabilities due to the growing workload from rising submission volumes.

Starting April 15, the service will only analyze and provide additional details (e.g., severity rating, product lists) for security issues that meet specific criteria related to the risk they pose.

The National Vulnerability Database (NVD) will still list all submitted vulnerabilities, but those considered low priority will have a severity rating only from the CVE Numbering Authority (CNA) that evaluated and submitted it.

Wiz

In an announcement this week, the non-regulatory federal agency said it will only provide additional details for vulnerabilities that meet one of the following criteria:

  • are in CISA’s Known Exploited Vulnerabilities (KEV) catalog
  • affect the U.S. federal government software
  • involve critical software as per Executive Order 14028

NIST explained that the decision was driven by the large number of submissions, which grew by 263% recently and continued to accelerate in 2026. The organization enriched 42,000 CVEs in 2025, but it can no longer keep up with the increasing volume.

NIST NVD is a public, centralized database of known software and hardware vulnerabilities, which also provides additional descriptions and analyses on top of the unique identifiers (CVE IDs) assigned by CNAs, such as vendors and the not-for-profit The MITRE Corporation.

Advertisement

The point of enriching vulnerability details is to make CVE entries usable for risk management, including assigning severity scores, identifying affected product versions, classifying weaknesses, and providing links to advisories, patches, or related research.

NIST NVD is used universally by security researchers, software vendors, government agencies, IT professionals, journalists, and regular users seeking more information about a specific security issue.

“All submitted CVEs will still be added to the NVD. However, those that do not meet the criteria above will be categorized as “Not Scheduled,” explains NIST.

“This will allow us to focus on CVEs with the greatest potential for widespread impact. While CVEs that do not meet these criteria may have a significant impact on affected systems, they generally do not present the same level of systemic risk as those in the prioritized categories.”

Advertisement

NIST admits that the new rules allow some potentially high-impact CVE slip through. For this reason, the agency accepts enrichment requests for “any lowest priority CVEs” via email messages at ‘nvd@nist.gov.’

The lack of enrichment or notable delays was noticeable since 2024, but the organization has now formally declared that it will focus on the most important entries.

AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

Source link

Advertisement
Continue Reading

Tech

Building A Rim-Driven Jet Engine

Published

on

Rim-driven thrusters turn the normal propeller-motor arrangement inside out; rather than mounting the motor at the center of the propeller, they use a large hollow motor, with the blades attached to the inside of the rotor. They’re mostly used in ship propellers, though there have been some suggestions to use them in electric aircraft. [Integza], always looking for new and unusual ways to create propulsion, took this idea and made it into a jet engine.

Rather than using an electric motor, the fan in this design is propelled by miniature rocket nozzles along the edge. The fan levitates on a layer of high-pressure gas between the fan rim and the housing. To prevent too much pressurized gas from escaping, the fan and housing needed to fit together closely, but with minimal friction. A prototype made out of acrylic and resin and powered by compressed air proved that the idea worked, but [Integza] wanted to make to this a combustion-powered engine.

The full engine would be similar to a rocket engine, with the fan being the nozzle. The combustion chamber was built out of a brass fitting, and it burned propane in compressed air. The fan and housing were CNC-milled out of aluminium and brass, respectively. They worked well when powered with compressed air, but seized up when connected to the combustion chamber — the fan was thermally expanding and jamming in the housing. Progressively rounding down the edges of the fan failed to solve this, and a hole melted in the fan during one test. [Integza] machined a new fan, which he anodized to increase its heat resistance.

To keep it from overheating, he sprayed water into the combustion chamber, creating steam and cooling the exhaust stream to a manageable temperature. The engine did work, though we do wonder whether the fan actually increases its thrust over that of the base rocket engine.

Advertisement

This isn’t the first unconventional jet engine [Integza]’s built, nor the first which tries to amplify the thrust produced by a rocket engine.

Thanks to [Keith Olson] for the tip!

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025