Toggle light / dark theme

A container of oil and water separated by a thin skin of magnetized particles has intrigued a team of chemical engineers by taking on an unexpected ‘Grecian urn’ shape upon agitation.

“I thought ‘what is this thing?’,” graduate student Anthony Raykh from the University of Massachusetts Amherst recalled, after doing what all chemistry students love to do, mixing materials with intriguing properties just to see what would happen.

“So, I walked up and down the halls of the Polymer Science and Engineering Department, knocking on my professors’ doors, asking them if they knew what was going on.”

In 2021, the Office of the Director of National Intelligence (ODNI) released a report detailing recently declassified information on Unidentified Aerial Phenomena (UAP).

Since then, the Department of Defense has released annual reports on UAP through the All-domain Anomaly Resolution Office (AARO). Nevertheless, there is still a lack of publicly available scientific data.

To address this, a new study led by the Harvard-Smithsonian Center for Astrophysics (CfA) and the Galileo Project proposes an All-Sky Infrared Camera (Dalek) to search for potential indications of extraterrestrial spacecraft.

As websites incorporate more third-party tracking technologies, robust CSRF attack prevention becomes paramount. This case study illustrates how a misconfigured third-party vendor exposed CSRF tokens on a major retailer’s website, highlighting the risks of inadequate third-party security.

The Problem

A misconfiguration allowed a third-party pixel used by a major online retailer to access CSRF tokens and authentication tokens, which, as we noted, are critical security elements for preventing unauthorized actions. This exposure transmitted the tokens to remote third-party servers, creating a significant vulnerability that risked potential data breaches.

Sensata Technologies (known as Sensata) has suffered a ransomware attack last weekend that encrypted parts of the company network and disrupted operations.

In an 8-K filing to the U.S. Securities and Exchange Commission (SEC), Sensata says that the attack occurred on Sunday, April 6, and involved data theft, too.

“The incident has temporarily impacted Sensata’s operations, including shipping, receiving, manufacturing production, and various other support functions,” reads the notification.

Hackers started exploiting a high-severity flaw that allows bypassing authentication in the OttoKit (formerly SureTriggers) plugin for WordPress just hours after public disclosure.

Users are strongly recommended to upgrade to the latest version of OttoKit/SureTriggers, currently 1.0.79, released at the beginning of the month.

The OttoKit WordPress plugin allows users to connect plugins and external tools like WooCommerce, Mailchimp, and Google Sheets, automate tasks like sending emails and adding users, or updating CRMs without code. Statistics show that the product is active on 100,000 websites.

Microsoft has released an out-of-band Office update to fix a known issue that caused Word, Excel, and Outlook to crash after installing the KB5002700 security update for Office 2016.

The company acknowledged these problems following user reports on social media that Office apps no longer open after applying the April 2025 security updates.

“We’re experiencing an issue on Windows 10 with Office 2016 where Word and Excel no longer open,” one impacted Office user said.