Toggle light / dark theme

Get the latest international news and world events from around the world.

Log in for authorized contributors

This New Molecule Could Transform How We Recover Gold From Electronic Waste

A new extraction molecule uses electricity to recover metals while sharply reducing the need for chemical reagents.

Recovering valuable metals from discarded electronics, mining streams, and industrial waste usually depends on large amounts of chemical reagents. Researchers at the University of Illinois Urbana-Champaign have developed a molecule that could allow electricity to replace much of that chemistry, potentially making metal recovery cleaner, simpler, and more energy efficient.

The findings, led by chemical and biomolecular engineering professor Xiao Su, were published in ACS Energy Letters.

Dark Stars May Have Left a Gravitational-Wave Signal We Can Detect Today

A new study suggests that pulsar timing arrays could help reveal how the Universe’s first supermassive black holes formed.

A faint background of extremely low-frequency gravitational waves, detected by monitoring networks of pulsars, may preserve clues from events that began more than 13 billion years ago. Among them could be the processes that produced some of the Universe’s earliest supermassive black holes.

Sohan Ghodla and Cosmin Ilie of Colgate University explored that possibility in a study published as a Letter in Physical Review D. Their goal was to determine whether supermassive black holes that originated in the early Universe could eventually account for a substantial share of the gravitational wave background now detected by Pulsar Timing Arrays, or PTAs.

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem.

The Windows path traversal, tracked as CVE-2026–75604 (CVSS score: 9.0), affects Next.js applications that use both the Pages Router and App Router without Cache Components when the server uses a Windows filesystem.

Linux and macOS deployments are not affected.

Android 17 adds ECH support to make web browsing harder to track

Google is introducing new network security protections in Android 17 to strengthen connection privacy, address cellular vulnerabilities, and protect the privacy of users’ home networks.

Android 17 adds support for Encrypted Client Hello (ECH), a new privacy standard that operates in conjunction with private DNS to hide profiling metadata, including visited domain names.

ECH acts as a privacy extension for TLS, the protocol that secures HTTPS connections, encrypting the opening part of the TLS handshake that reveals the contacted hostname via the Server Name Indication (SNI).

Nearly 700 rogue AI agents coordinated in the Hugging Face attack

New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI’s internal IM1 model coordinated the compromise through an unauthorized message board.

Last month, Hugging Face disclosed that autonomous AI agents exploited two vulnerabilities in its dataset-processing pipeline to execute code, steal cloud and cluster credentials, and move laterally across its production infrastructure.

OpenAI later confirmed that its models escaped an ExploitGym evaluation environment through a zero-day vulnerability in a locally hosted instance of JFrog’s Artifactory package manager that was connected to the internet.

PaperCut warns of NG, MF flaw exploited in zero-day attacks

PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.

The company says it is aware of confirmed attacks on customers and is urging organizations with Internet-exposed PaperCut Application Servers to immediately restrict access to the web interfaces to trusted IP addresses.

“PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF,” reads an urgent security advisory published Thursday.

Court Backs DMCA Takedown of Public Meeting Videos

The case concerns a local news outlet in Massachusetts that had its YouTube channel taken down because of videos it posted about local government meetings.

The city of Waltham had outsourced the recording of its meetings to a contractor, Waltham Community Access Corporation (WCAC), and it was this entity that sent the DMCA notices to YouTube, targeting 15 videos on the Channel 781 News outlet.

/* */