Toggle light / dark theme

Get the latest international news and world events from around the world.

Log in for authorized contributors

Measuring electron pulses for future compact ultra-bright X-ray sources

In a step toward making ultra-bright X-ray sources more widely available, an international collaboration led by the University of Michigan—with experiments at the U.K.’s Central Laser Facility—has mapped key aspects of electron pulses that can go on to generate laser-like X-ray pulses.

These X-ray pulses have the potential to advance chemistry, biology, and physics by enabling researchers to measure the way molecules behave in great detail. The technique may also be useful in clinical medicine for imaging soft tissues and organs.

Because the pulses are so short, quadrillionths of a second (femtoseconds) long, they can take snapshots of chemical reactions, revealing the choreography of atoms and molecules, including larger biomolecules such as proteins. These studies are valuable for both basic research, down to quantum mechanics, and applications of chemistry such as drug discovery.

1,500-Year-Old Mystery Solved: Scientists Rewrite the Origins of the World’s First Pandemic

USF and FAU researchers identify bacterium behind 1,500-year-old pandemic mystery. For the first time, scientists have obtained direct genomic evidence of the bacterium responsible for the Plague of Justinian, the earliest known pandemic in recorded history. The outbreak, which struck the Eastern

Dark Matter “Wind” May Finally Be Detectable With New Superconducting Tech

Physicists have created a novel detector capable of probing dark matter particles at unprecedentedly low masses. About 80 percent of the universe’s mass is believed to be dark matter, yet the makeup and organization of its particles remain largely unknown, leaving physicists with fundamental ques

Microsoft Fixes 80 Flaws — Including SMB PrivEsc and Azure CVSS 10.0 Bugs

Microsoft on Tuesday addressed a set of 80 security flaws in its software, including one vulnerability that has been disclosed as publicly known at the time of release.

Of the 80 vulnerabilities, eight are rated Critical and 72 are rated Important in severity. None of the shortcomings has been exploited in the wild as a zero-day. Like last month, 38 of the disclosed flaws are related to privilege escalation, followed by remote code execution (22), information disclosure (14), and denial-of-service.

“For the third time this year, Microsoft patched more elevation of privilege vulnerabilities than remote code execution flaws,” Satnam Narang, senior staff research engineer at Tenable, said. “Nearly 50% (47.5%) of all bugs this month are privilege escalation vulnerabilities.”

DDoS defender targeted in 1.5 Bpps denial-of-service attack

A DDoS mitigation service provider in Europe was targeted in a massive distributed denial-of-service attack that reached 1.5 billion packets per second.

The attack originated from thousands of IoTs and MikroTik routers, and it was mitigated by FastNetMon, a company that offers protection against service disruptions.

“The attack reached 1.5 billion packets per second (1.5 Gpps) — one of the largest packet-rate floods publicly disclosed,” FastNetMon says in a press release.

Microsoft waives fees for Windows devs publishing to Microsoft Store

Microsoft announced that, starting today, individual Windows developers will no longer have to pay for publishing their applications on the Microsoft Store.

The company said that developers can now submit Win32 (including. NET WPF and WinForms), UWP, PWA,.NET MAUI, or Electron apps to the Microsoft Store without paying any registration fees.

Redmond will also handle each app’s hosting and signing, eliminating the need for developers to pay for these services.

Hackers left empty-handed after massive NPM supply-chain attack

The largest supply-chain compromise in the history of the NPM ecosystem has impacted roughly 10% of all cloud environments, but the attacker made little profit off it.

The attack occurred earlier this week after maintainer Josh Junon (qix) fell for a password reset phishing lure and compromised multiple highly popular NPM packages, among them chalk and degub-js, that cumulatively have more than 2.6 billion weekly downloads.

After gaining access to Junon’s account, the attackers pushed malicious updates with a malicious module that stole cryptocurrency by redirecting transactions to the threat actor.

/* */