Connect with us

Tech

Vietnam arrests suspects behind HiAnime anime piracy service

Published

on

HiAnime

​Vietnamese authorities have arrested and are prosecuting seven suspects believed to have run HiAnime, the largest anime piracy streaming service before its shutdown in June.

HiAnime provided access to a massive library of English-subbed and dubbed anime without subscription fees, attracting several hundred million visitors each month and temporarily surpassing legal streaming platforms like Disney+ and Crunchyroll in web traffic between late 2024 and 2025.

It was launched on the Zoro.to domain, rebranded to Aniwatch (and switched to Aniwatch.to) in July 2023, and again in March 2024 as HiAnime/H!Anime (using the HiAnime.to domain).

image

After becoming massively popular, HiAnime was also placed on the European Commission’s Counterfeit and Piracy Watch List and the United States Trade Representative’s (USTR) Notorious Markets list.

The seven defendants have been charged with infringing copyright and related rights and with money laundering, with four of them detained and the other three placed under house arrest.

Advertisement

They have been accused of creating more than 100 websites to upload over 26,000 pirated anime films, generating approximately $12.85 million in illegal advertising revenue between 2020 and April 2026.

​The Alliance for Creativity and Entertainment (ACE), a coalition of over 50 media and entertainment companies, including the world’s largest film studios and television networks, focused on shuttering illegal streaming services, confirmed the law enforcement action on Thursday and thanked U.S. authorities for their support throughout a multi-year investigation that led to the suspects’ arrests.

HiAnime defendants
HiAnime defendants (Vietnam’s Ministry of Public Security)

​”ACE applauds the actions of Vietnam’s Ministry of Public Security (MPS), in particular C03, the Economic Crimes Investigation Department, and A05, the Department of Cybersecurity and High-Tech Crime Prevention, in arresting and prosecuting seven operators believed to be behind Hianime and related piracy services,” said the Alliance for Creativity and Entertainment on Thursday.

“ACE would also like to thank its partners, Homeland Security Investigations and the U.S. Department of Justice, for their continued support in this multi-year investigation and action. ACE looks forward to continuing to support the MPS and its relevant agencies, and to working even more closely with them on future actions against piracy services.”

Earlier this year, in March, ACE also announced the shutdown of AnimePlay, another major anime streaming platform that hosted more than 60 terabytes of anime TV shows and movies and had over 5 million registered users.

Advertisement

The anti-piracy coalition dismantled AnimePlay by taking all infrastructure offline, including its hosting servers and web domains.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

NASA’s Swift rescue slips to late August as LINK battles its spin

Published

on

SCIENCE

Engineers make progress in stabilizing mission but push back the rendezvous date

Katalyst Space has confirmed that problems with its LINK spacecraft have delayed its attempt to rescue NASA’s Swift observatory, with rendezvous now targeted for the end of August.

Katalyst disclosed the delay in an update on the spinning spacecraft. Engineers used a thruster to cut LINK’s rotation rate from 9 degrees per second to approximately 4 degrees per second, with further burns planned.

Advertisement

Katalyst and NASA are also developing a new attitude controller suited to the spacecraft’s reduced capabilities. Engineers are determining which systems remain usable and testing their plans in a simulator before trying them on the vehicle in orbit.

The trouble has pushed the targeted rendezvous to the end of August. LINK is supposed to sidle up to Swift, survey it, grapple the observatory, and carry it to a higher orbit. For now, however, Katalyst says: “We’re focused on stabilizing the spacecraft and restoring core system functionality.” Any rendezvous attempt depends on that work succeeding.

LINK launched earlier this month, less than a year after NASA awarded Katalyst Space the contract for a rescue mission. The spacecraft encountered problems during commissioning before going into a spin over the weekend. Earlier this week, Katalyst reported that two of the three reaction wheels, used to control LINK’s attitude, were inoperable, but the team was working to stabilize the vehicle using its electric propulsion thrusters.

Time is running short. Swift is expected to enter the Earth’s atmosphere in the coming months. The observatory has enjoyed a prodigiously long life and far exceeded its primary mission, but its orbit is decaying and it cannot raise itself. LINK’s success could add years to Swift’s operational lifetime.

Advertisement

In January, almost all of NASA’s models predicted that Swift would re-enter by the summer of 2026. Most science operations were paused in February to buy more time. More recent predictions indicate that it could dip below 300 km, the altitude beneath which raising its orbit becomes more difficult, around November.

Katalyst must now stabilize LINK, secure NASA’s approval for its revised plans, and reach Swift before the observatory sinks too low for a practical rescue. ®

Source link

Advertisement
Continue Reading

Tech

What 20 Million Bans Reveal About The Stress On Wikipedia’s Volunteers

Published

on

from the moderating-in-public dept

This article is republished from The Conversation under a Creative Commons license. Read the original article.

This year, Wikipedia is celebrating 25 years as the Internet’s encyclopedia that anyone can edit. In its first decade, the quirky experiment for passionate nerds exploded in popularity. It became a ubiquitous information resource and a homework helper for schoolkids, much to the dismay of skeptical teachers.

In its second decade, amid the public’s growing dissatisfaction with the mangling of facts in popular discourse, it took on a new role as information infrastructure, helping categorize and validate information worldwide. Wired magazine deemed it “the last best place on the internet.” The hope was that the volunteer project could serve as the antidote for misinformation. Platforms from Facebook and Twitter to Alexa and YouTube began embedding Wikipedia material to ensure that users had context for what they read or saw.

That role has become more acute in recent years. Artificial intelligence developers have relied deeply on Wikipedia to train the large language models behind popular chatbots, which weight clean, reasonably reliable information sources more heavily than the rest of the web. Chatbots and AI-powered search engines have intensified Wikipedia’s significance, even as they siphon its readers by answering questions directly, with fewer people going to the source site itself.

Advertisement

But as Wikipedia’s importance – and size – has grown, the size of the volunteer corps that maintains it has not, and the number of volunteer administrators, a key moderation role, has shrunk.

I’m a researcher who studies social media platforms. I analyzed two decades of the site’s moderation records to understand the effect of these conditions. I found changes in behavior that appear to prioritize content quality while weakening the project’s ability to recruit and retain new volunteers.

Under pressure

As Wikipedia has become more prominent, its resistance to top-down control has made it a target for people who have political or financial power. There is frequent news about takedown demands and censorship abroadinvestigations and threats to its nonprofit status in the U.S., and, outside the U.S., volunteers have been arrested and imprisoned.

The Wikipedia community is also sensitive to its rising importance, but not in the way you might think. Contributors are keenly aware of political rhetoric that takes aim at their project or threatens volunteers. But the chief effect on volunteers has been a sense of heightened obligation to their global readership, which has gradually increased quality standards.

Advertisement

As a longtime volunteer myself, I’m often taken by the community’s perseverance and the people’s desire, above all, to get on with their work of summarizing the world’s knowledge.

The English language Wikipedia has maintained a reasonably steady number of contributors since 2010 – about 40,000 – yet its size and importance have grown. In 2006, it contained 1 million articles; in May 2025, it passed 7 million. A new issue is an influx of low-quality content generated by large language models.

The steady decrease in administrators is especially concerning. Administrators are a subset of trusted users, elected by the community at large, who are given powers such as the ability to delete articles or block users from editing. Unlike moderators at for-profit platforms, Wikipedia cannot simply hire more administrators. There are slightly more than 800, down from almost 1,800 in 2011, and they’re not all active.

So Wikipedia’s role has grown, but it is held together by a relatively small, shrinking community of unpaid volunteers. To keep up, the community in general and administrators in particular have had to raise their efficiency, making trade-offs between maintaining open participation and raising article quality. These trends and their costs are well documented. They are clearly visible in one of the basic administrator routines: blocking.

Advertisement

Shown the door

Blocking is when an administrator determines that a user is so detrimental to the project that they must be prevented from making any further edits. The blocked user can still read Wikipedia, but cannot change it.

Unlike the opaque moderation systems at the large internet platforms that I normally study as a researcher, such as YouTube or TikTok, nearly every administrative action on Wikipedia is recorded in a public log. I used these logs for a study analyzing all 20 million blocks made on the English language Wikipedia over the past two decades. I looked for patterns in frequency, duration and reasons for a block. I also assessed whether those patterns corresponded to the growing trade-offs between openness and quality.

I found that the frequency of blocks has risen sharply in recent years due to administrators using bots to preemptively block proxies. Proxies are services such as virtual private networks, or VPNs, that people use to conceal their identity, often to facilitate abuse or manipulation on Wikipedia. One of these bots, ST47ProxyBot, was so active that it accounted for the most blocks in the site’s history. Preemptive proxy blocking likely prevents damage, but it can also occasionally stop good-faith contributors. Given the increasing popularity of AI agents and their disruptive potential, this practice is likely to continue to expand.

I then removed proxy blocks from the analysis so I could focus on humans who were blocked and why. In the early years, administrators made the majority of blocks for vandalism: intentionally bad or nonsensical edits. That has shrunk to about a quarter of all blocks today. Blocks have risen for promotional editing and for sockpuppetry — when one person creates multiple accounts to manipulate content. These shifts speak to Wikipedia’s increased prominence as a target for influence.

Advertisement

Signs of stress

What I found most interesting was administrators’ greater use of generalized reasons for blocking, such as “disruption.” Wikipedia defines disruption as “a pattern of editing that disrupts progress toward improving an article or building the encyclopedia.” But citing this can mean nearly anything seen as counterproductive. The trend is partly explained by “disruption” being in a list of boilerplate rationales that administrators can choose from instead of entering a customized reason.

But it’s also the kind of trend I would expect to see in a labor force stretching to keep up. Administrators don’t act arbitrarily, and their actions are publicly logged and closely scrutinized. A loss of trust leads to an administrator losing their position. But to be effective, general explanations for blocks rely on shared understandings that new users may not have. Research on blocked users shows that when a sanction feels vague or unfair, volunteers are more likely to walk away – or dig their heels in – rather than reform. Good for efficiency; bad for bringing new users into the fold.

Blocks are also lasting longer on average. That, together with preemptive blocking and generalized rationales, suggests that the volunteer community is increasingly prioritizing prevention, efficiency and content quality over efforts to rehabilitate new users.

And the work is not spread evenly among the roughly 800 administrators: For many years, the most active 10% of administrators have made about 80% of the blocks. That high number dropped to 37% in 2024, largely due to changed activity by a single prolific administrator.

Advertisement

Bearing the cost

Wikipedia’s openness is part of how its volunteer community grew in the first place. Now that Wikipedia has become infrastructure, that community is rationing openness to preserve quality for readers. If Cory Doctorow’s zeitgeist-capturing idea of platform “enshittification” is fundamentally about ruining the experience of end users for the sake of the shareholders, Wikipedia is attempting something like the opposite. The end-user experience is being preserved, and the people behind the scenes are bearing the cost.

Wikipedia has adapted remarkably well in its evolution from early web experiment to one of the most important global sources of information. The open question, for a resource that so many humans – and now machines – rely on, is how long the volunteer system can keep enduring the cost.

Ryan McGrady is Senior Research Fellow at the Initiative for Digital Public Infrastructure, UMass Amherst

Filed Under: bans, content moderation, moderation, wikipedia, wikis

Companies: wikimedia foundation, wikipedia

Advertisement

Source link

Continue Reading

Tech

Bad updates, broken cables and blackouts – Cloudflare reveals some of the wildest reasons behind Internet downtime across the world

Published

on


  • Cloudflare summary logs a typhoon, two earthquakes, power failures, and thirteen government exam shutdowns
  • It also identified a fiber cut, drone damage to an AWS region, and a botched DNSSEC key rollover
  • The report’s sharpest finding is that Tanzania’s accidental power blackout looked almost identical in the data to its deliberate election-day shutdown in 2025

Cloudflare has published its latest account of what recently knocked chunks of the Internet offline, and the list reads like a catalogue of everything that can go wrong at once: a typhoon, two earthquakes a minute apart, a national power failure, ten government shutdowns timed to school exams, a fiber cut, drone damage to a cloud region, and a routine cryptographic key update that briefly made every .de website in the world unreachable.

Drawn from traffic telemetry on Cloudflare Radar, it is a useful reminder that the systems most people treat as a utility are held together by a surprisingly small number of things.

Source link

Continue Reading

Tech

Grand Jury Witness: Reflecting Pool Was Already Damaged Before Arrested Man Touched It

Published

on

from the yet-another-vindictive-prosecution dept

Donald Trump swore he could turn the Lincoln Memorial Reflecting Pool into something he could use to bask in his own reflected glory. Instead, it turned out to be everything we expect from Trump: braggadocio followed by abject failure.

Trump hired some guys he used to do some stuff to his personal pool(s) back in the day. It was a no-bid contract — one that was immediately extolled by Trump as Great Stuff. According to Trump, his personal cabana boys could get the job done right, on time, and under budget.

None of that happened. His boys took to the pool repair, doing their level best to behave like government contractors. Trump then did a Glory Roll across the unfinished sealant with his motorcade to show off for the boys back at the White House. A week or so later, the pool was refilled. For a brief moment, it showed off the “American flag blue” Trump thought was missing from the original fixture. Then it turned into a blend of algae and peeling sealant.

Instead of pulling out his receipts and asking his pool boys whether this reflecting pool refurb was still under warranty, Trump claimed the floating chunks of blue sealant bobbing around in the green muck was the work of vandals. And, of course, he had political appointees willing to press this point on his behalf. Jeanine Pirro — the US Attorney for the District of Columbia — got right on it, arresting former Olympic canoeist David Hearn on felony vandalism charges.

Advertisement

Pirro alleged Hearn had damaged “two square feet of sealant.” Well, it takes $1,000 to make vandalism charges a federal felony. While this damage estimate is subject to federal no-bid contract markup, taking someone down for doing two square feet of damage is insane, especially when Trump is still out there claiming vandals cut a 150-350 foot gash into the pool sealant.

Trump also promised there was proof of his wild allegations — something that would presumably show up as the DOJ attempted to turn vandalism arrests into federal indictments.

Well, the DOJ managed to secure an indictment against David Hearn. And it managed to do this despite its own witness stating the pool was already fucked before Hearn decided to put his hands on end results of this damage:

A key grand jury witness in a case against a former Olympic canoeist accused of tampering with the Lincoln Memorial Reflecting Pool testified that the area was already damaged and would have required repairs regardless, lawyers said in a court filing Monday.

[…]

Advertisement

The witness, who is not identified, was the only person who testified about damages, and said that the property had already been damaged before, authorities say, Hearn stuck his hands in the water, according to Hearn’s team.

Now, for those of you unaware of how grand jury proceedings work (and especially for those MAGA folks who like to show up and be deliberately ignorant), we’ll break this down quickly. A grand jury is not like a regular jury. Its sole purpose is to decide whether or not the government has enough evidence to support an indictment. The accused person is not there, nor are they represented by the lawyers. This is completely non-adversarial. And YET, the government’s witness testified to the grand jury that the pool was already damaged before the accused even arrived on the scene of the alleged crime.

What’s absolutely wild is that the DOJ still got its indictment despite this damning testimony from its own witness. Welcome to Trump Town, I guess. But we’ll see how long this indictment lasts. Hearn’s legal reps have filed a motion demanding copies of grand jury documents because it’s pretty fucking clear some bullshit must have been pulled to get Hearn indicted even though a government witness testified that the pool was already in shambles.

Lawyers for David Hearn, a 67-year-old who represented the United States at three Olympic Games, submitted a court filing seeking access to transcripts of the grand jury testimony as well as the instructions given to the panel that ultimately indicted Hearn, claiming that there were “irregularities” in the proceedings that led to the indictment. 

[…]

Advertisement

In the filing, Hearn’s legal team suggests that the jury was not “properly instructed” on the crime Hearn stands accused of, noting specifically that felony destruction of property requires the perpetrator to have caused $1,000 or more of damage. The attorneys pointed to the testimony of the federal government’s own witness, an official from the National Park Service, who suggested that the pool was damaged long before Hearn interacted with the pool and that repairs were already being sought.

The full filing [PDF] by Hearn’s legal team is embedded below. It’s worth a read. And I certainly hope the judge grants this motion because if it contains the sort of stuff these accusations suggest it the documents might contain, this won’t be the first time the Trump administration has been caught cheating even though the process already allows the government to put its prosecutorial thumb on the scales.

Filed Under: asshats, david hearn, dc, department of interior, donald trump, jeanine pirro, reflecting pool, trump administration

Advertisement

Source link

Continue Reading

Tech

Cheffy’s E.G.O.R. is Basically an Egg Machine With Ambition

Published

on

Cheffy E.G.O.R. Egg Machine Robot
Morning routines often fall apart around a single stubborn task. Eggs demand attention right when attention feels scarcest. Crack one wrong and shell fragments appear. Leave the pan a second too long and yolks firm up past preference. Busy households skip the whole thing more often than they admit.



Cheffy, a small company based in San Francisco, created E.G.O.R. to make your life easier in the kitchen. The name stands for Efficient Gastronomic Operational Robot, however some early accounts simply referred to it as Egg Go On Robot, which is acceptable. The gadget just sits on your counter and solves the egg problem, allowing you to continue with your day.

Sale


Hamilton Beach Dual Breakfast Sandwich Maker with Egg Cooker Rings & Timer
  • THE PERFECT GIFT: Whether it’s a birthday, a White Elephant party, or Father’s Day, the Breakfast Sandwich Maker makes a fantastic gift for all…
  • MAKE 1 OR 2 SANDWICHES. Cook one or two sandwiches at once with this dual breakfast sandwich maker. It’s great for couples, kids and extra guests.
  • QUICK, EASY AND READY TO EAT IN 5 MINUTES: This sandwich maker lets you easily create a breakfast, lunch or dinner sandwich in 5 minutes or less…

Simply add whole chicken eggs into the chamber. Choose one of the seven egg styles from the little display, which includes three small buttons. Sunny side up keeps the yolks fluid and the whites perfectly set. Over easy, medium, and hard all have a finishing lid that allows the top to steam cook without any flipping. Soft, medium, and hard boiled varieties are placed in different trays for you. There’s also a crack only setting, in case you need to break eggs into a bowl or batter. It can hold two eggs in the frying pan and six in the boiling tray, from peewee to giant.

Advertisement

Cheffy E.G.O.R. Egg Machine Robot
The patent-pending technology cracks each egg with ease. The contents fall into the pan or pot, while the shells go into a little compartment inside that you can discard later. You do not need to be concerned about seeming foolish. You can also simply put all of the elements that come into contact with food in the dishwasher, and there’s even a keep-warm function that keeps the eggs at serving temperature even if you’re running late.


T.O.A.S.T.R., an optional toaster, syncs with the egg cooker, allowing you to cook both items at the same time. You can put in thick slices of bread, bagels, or waffles, and it’s automatic, so you won’t have to jump when it raises or lowers the toast. Consistent browning and a crumb tray complete the toaster operations. Both machines have the same eggshell-white finish. The E.G.O.R. unit measures about 7.5 inches broad, 16 inches long, and 12 inches tall, weighing around 8 pounds. It uses between 500 and 1000 watts, depending on the setting.

Cheffy E.G.O.R. Egg Machine Robot
The founder, Arjun Mehta, described the whole thing as a response to how difficult it can be for people to get by on a daily basis, particularly when it comes to simply running a family. Early supporters were parents attempting to get their kids out the door on time and people who struggle with fine motor activities. On Kickstarter, you could get the egg unit alone for anywhere from $199 (early bird discount) to $299, with the toaster costing between $349 and $499. Those backers hope to receive the egg unit in late 2026. After the campaign, they want to sell the egg unit for approximately $400.

Source link

Advertisement
Continue Reading

Tech

The Man Who Understood Risk: Robert N. Charette retires.

Published

on

When I started at Spectrum 25 years ago, a senior editor suggested that I find a “rabbi,” by which he meant someone who could mentor me in how EEs approach problems and evaluate potential solutions.

I didn’t find one right away. Then in 2005 we decided to do a special report, focusing on the challenges of enterprise software development. I suggested we invite IEEE Life Senior Member Robert N. Charette, a self-described risk ecologist, prolific book author, and leading authority on risk management and software engineering, to explore in our pages the myriad reasons software projects fail. His seminal article “Why Software Fails” is still read in university engineering classes today.

Older white man with a white beard and glasses. IEEE Life Senior Member Robert N. Charette is one of IEEE Spectrum’s most prolific authors.Robert N. Charette

It was, as they say, the beginning of a beautiful friendship. I had found my rabbi, one who shared my love of writing. We settled into a rhythm that would last more than 20 years, talking on Friday mornings about a range of topics including the growing ubiquity of software in our lives.

So when I became Spectrum’s website editor in 2007, he was the first contributor I tapped to start a regular blog (remember those?). The Risk Factor was born and over the course of more than 10 years and 1,750 posts, Bob chronicled hundreds of software debacles, culminating in “Lessons From a Decade of IT Failures,” which won a Jesse H. Neal Award for Best Infographics in 2016. Ironically, yet predictably, those infographics were created in a software package that is no longer supported and thus are lost to the bits of time.

Advertisement

Blue heron with a fish in its beak. “I like the expression on the fish just before it’s going to be swallowed by the heron.”Robert N. Charette

Bob, however, was not a one-trick pony. In between his full-time job running his two management consultancies and raising a future biochemist and a future civil engineer, his daughters Maura and Megan, he also wrote many deeply reported and insightful articles. These include last year’s “The Doctor Will See Your Electronic Health Record Now,” the eye-opening 12-part series and e-book The EV Transition Explained, and my personal favorite “Automated to Death,” about the deadly consequences of the automation paradox as manifested by the cyberphysical systems that pilot planes, trains, and automobiles.

Juvenile bald eagle over water, yellow talons extended as it prepares to snag a fish. “The young bald eagle I photographed in September 2024 had bands that I could read which identified it as a female born in May 2024, near Lexington Park, St. Mary’s County, Maryland, about 65 miles away from where I live.”Robert N. Charette

His main goal all along has been to make software visible, as he told me one Friday in July. “Software is all around us, but we don’t recognize it at all,” he said. “I really wanted my stories to help people better understand complex software systems. You can’t see software, you can’t touch it, you can’t taste it. You may feel the consequences of software failure, but you never see the reason itself.”

When he told me that he was hanging up his hat as a contributing editor to focus on nature photography and to write a handful of fictional trilogies, including one entitled “The STEM Murders” featuring an engineer-turned-detective and his rabbi, I asked him which of his Spectrum articles had the biggest impact.

Humming bird feeding from a long red flower. “The hummingbird I caught with the yellow of a road curb behind it.”Robert N. Charette

He singled out the 2013 feature “The STEM Crisis Is a Myth.” “Spectrum gave me a platform to question the assumption that we needed more STEM graduates. Until then, people didn’t really realize how much of the STEM crisis was a mythology that was perpetuated by employers and the academic community and was foisted on the IEEE community,” he said.

Advertisement

Charette made a career of questioning assumptions. The best way to mitigate risk, he told me as our Friday chat drew to a close, is to be careful making assumptions in the first place. “My main risk maxim is assumptions made are risks accepted.”

From Your Site Articles

Related Articles Around the Web

Source link

Advertisement
Continue Reading

Tech

Rails patches critical Active Storage flaw with RCE potential

Published

on

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE).

Rails is a popular open-source web application framework written in Ruby for building websites and web apps. It uses the built-in Rails component Active Storage for handling file uploads and attachments.

Rails maintainers published an advisory about the CVE-2026-66066 flaw, which received a critical severity rating.

image

Active Storage may also generate image thumbnails from uploaded media using image processing libraries such as libvips or ImageMagick.

According to the security bulletin, CVE-2026-66066 is exploitable when libvips is used, allowing an attacker to upload a specially crafted image to a vulnerable application and read arbitrary files on the server.

Advertisement

Another prerequisite for the attack is that the server needs to allow image uploads from untrusted users.

If these requirements are met, an attacker may access app files, including the process environment, which typically contains ‘secret_key_base’ and credentials for databases, cloud storage, and other services.

CVE-2026-66066 impacts Active Storage before 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1.

Rails 6.x is only affected if Active Storage has been configured outside its defaults.

Advertisement

The Rails team recommends upgrading to libvips 8.13 or later and rotating the ‘secret_key_base’ (the Rails master key), database credentials, Active Storage service credentials, and any other secrets accessible to the application process.

For systems running libvips 8.13 or later, administrators can temporarily disable the vulnerable functionality by setting the VIPS_BLOCK_UNTRUSTED environment variable or calling Vips.block_untrusted(true) when using ruby-vips 2.2.1 or newer.

There is no workaround available for apps that use libvips before 8.13.

ImageMagick users are not affected by this vector. However, libvips is the default processor in the official Rails Docker images, and also Debian and Ubuntu setups.

Advertisement

The Rails team said it has intentionally withheld technical details for the vulnerability to reduce the risk of exploitation before users have time to apply the updates.

Full technical details were initially scheduled to be disclosed on August 28 on the Rails forums.

However, because public proof-of-concept (PoC) exploits became available very quickly, the maintainers decided to publish the full details as well as forensic investigation tooling.

The vulnerability was discovered and responsibly reported to the Rails team by researchers from Ethiack and GMO Flatt Security Inc.

Advertisement

Security firm Akamai has also published a warning about CVE-2026-66066, naming the attack chain “KindaRails2Shell,” and warning about its RCE potential.

“With the secret_key_base compromised, the attacker holds the master cryptographic key to the application,” explains Akamai.

“They can forge session cookies, sign global IDs, and manipulate serialized data, which directly translates into full RCE on the underlying server.”

Akamai says it coordinated with Ethiack before public disclosure to prepare protections for customers, and has now released web application firewall (WAF) protections.

Advertisement

Ethiack noted that a WAF might buy admins some time, but attackers using AI tooling should be able to reconstruct the attack chain based on the patch diffs.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Advertisement
Continue Reading

Tech

Commercialization And Innovation | Hackaday

Published

on

The last year or two has seen relatively affordable multi-material printers hit the market, and the question that [Tom Nardi] and I were kicking around when he was writing up the 2025 year-in-review article was what it was going to mean for our folks. I don’t think he got it wrong per se, but his heading for that section “Grandma is 3D-Printing in Color” only tells half the story.

He did get that part right, though. We’ve certainly seen a flourishing of multi-material designs out there that take advantage of the availability of (usually) four colors. The ability to print in color has given life to the purely decorative models, of course. Think full-color Pokemon desktop toys, for instance. But even functional prints have benefited from contrasting color labels printed right into the box, not to even mention the multi-material supports that pull off easier and cleaner than ever before.

Since most of these multi-filament machines are pretty much locked down as far as hardware tinkering goes, our sights were firmly locked on what the end-user would do with the new capability. But we overlooked the third axis of 3D printering: the software hackers. And it’s precisely in this area of slicer and path-planning that we’ve seen some of the coolest developments this year. Why? Because people have the hardware in their hands that they need to test out the algorithms.

Advertisement

FullSpectrum and the more recent ImageMap are two techniques to get the missing in-between colors out of a four-filament printer, and in particular ImageMap tries to get the job done faster, and with fewer purges. We are amazed to see two different approaches to color blending popping up in just a few months of each other, and we have no doubt that work on this is going to continue.

At the end of the day, this really is just “put new tools in the hands of creative hackers, and they’ll find new ways to use them”, so we shouldn’t have been surprised at all. But if this is what comes out of the commercialization of the multi-material printer, what’s going to come when some of the more esoteric machine designs go mainstream? We can’t wait to find out!

Source link

Advertisement
Continue Reading

Tech

These Android Phones Are Losing YouTube App Access In 2026

Published

on





Some Android users have been perfectly fine coasting on Android 6.0 Marshmallow for over a decade now. But all that came to an end in July 2026 when Google dropped an important layer of support for these aging Android smartphones. The official minimum operating system required for Google Play services is now Android 7.0 Nougat. The most immediate and noticeable side-effect of that is that the YouTube app isn’t going to work for those of you running Android 6.0 anymore.

To be clear, affected phones aren’t going to suddenly stop turning on or lose all of their data. Instead, 6.0 users will slowly start seeing compatibility issues. Expect more and more apps to go the way of YouTube and hit you with similar alerts, as well. You’ll see it when you open the YouTube app. Instead of working normally as it should, the app will display a prompt telling you to “Switch to YouTube” and directing you to its mobile site through your phone’s browser.

Because Google Play services power many of the key features Android apps depend on behind the scenes (like account authentication, notifications, location services, security protections, and communication between apps), it’s not unreasonable to call it the beginning of the end for these 6.0 smartphones losing support in 2026.

Advertisement

What to do if your phone is impacted

It’s worth reiterating that Google won’t be remotely disabling these devices. You can still watch YouTube on your phone, too, even if the app won’t work. You just have to watch through the web version, like what the prompt says. You can also use this same browser-based approach for other Google services if app compatibility gets worse in the weeks or months ahead. For example, if the Gmail app stops working, you can try the mobile version of the site.

All that running around and jumping through hoops can get old fast, of course. If you don’t feel like dealing with it anymore, you can always upgrade to a newer phone. Before you do that, it’s worth checking to make absolutely certain you don’t have a software update waiting for you. If that’s the case, you might be in the clear after all. Just go to Settings, then System, followed by Software Updates, and see if there’s an official upgrade to Android 7.0 or later there. If you’re out of luck there, Google says current Android smartphones from Google and Samsung will receive up to seven years of software updates. Upgrading from a device stuck on 6.0 would definitely be a smart move to future-proof your YouTube (and other Google Play services) access.

Advertisement



Source link

Advertisement
Continue Reading

Tech

Amazon spent $1.8 million on a failed AI project, and didn’t notice the overrun for five months

Published

on

In a nutshell: Amazon’s growing use of AI across its operations is starting to expose a practical problem: the technology can become expensive quickly, and in some cases, no one notices until the bill is already high. Internal discussions reviewed by the Financial Times show that several AI-driven projects at the company have run over budget, sometimes by a wide margin.

In one case, Amazon spent $1.8 million on a project that used Anthropic’s Claude Sonnet model to match author information with product listings. The system ultimately failed, and spending exceeded the original budget by 860%. The issue went undetected for five months.

Engineers say the problem isn’t limited to one project. As more teams shift from traditional software to AI models, routine mistakes are becoming far more costly. Tasks that once required minimal computing resources now depend on systems that charge based on usage, often measured in tokens. When those systems are misconfigured or left unchecked, costs can climb quickly.

During a recent internal meeting, senior engineers described these errors as “catastrophically expensive,” noting that similar mistakes in conventional systems were “trivially cheap.” The difference comes down to how AI workloads are priced and executed. Instead of predictable infrastructure costs, teams are now dealing with variable expenses that depend on how often models are called and how they are used.

Advertisement

Other projects have run into similar issues. One effort to build a financial auditing tool generated about $541,000 in unexpected costs. Another project aimed at improving delivery speeds in Amazon’s logistics network incurred $134,000 in additional spending, and it took more than two weeks to catch the problem.

According to people familiar with the situation, engineers are now working on safeguards to prevent similar incidents from happening again. These include automated controls to limit how AI systems are used and improved real-time spending tracking.

Part of the challenge is visibility. “It’s difficult to figure out how much anything [AI related] costs,” one senior Amazon employee told the Financial Times. Unlike traditional software systems, where costs are easier to estimate, AI introduces more moving parts. Model calls, prompt chains, and autonomous agents can all drive usage in ways that are difficult to track until after the fact.

Amazon, for its part, says the company is still in a learning phase. “As with any new technology, we’re experimenting, learning and improving how we use it, including how we drive cost efficiencies,” the company said in an internal presentation.

Advertisement

It also pushed back on the idea that these incidents reflect broader problems, adding that “Cherry-picking small, isolated examples where teams are learning from one another and portraying them as business as usual doesn’t reflect how teams across Amazon are using AI.”

Still, the examples point to a broader shift happening across the tech industry. As companies move away from fixed pricing models and toward usage-based billing, AI costs are becoming harder to predict. Systems that rely on autonomous agents can generate large volumes of activity, sometimes far beyond what teams initially expect.

Amazon has already encountered related issues elsewhere. Earlier this year, AWS experienced outages tied to errors from AI coding tools. In response, the company limited what those tools were allowed to do rather than giving them full access. It has also stepped back from internal efforts to encourage heavy AI usage after costs began to rise.

For a company of Amazon’s size, the financial impact of these overruns is relatively small. The business generates more than $180 billion in revenue each quarter and is expected to spend heavily on AI infrastructure this year. But the incidents highlight a more fundamental issue: managing AI costs requires a different approach than managing traditional software.

Advertisement

Source link

Continue Reading

Trending

Copyright © 2025