Toggle light / dark theme

Get the latest international news and world events from around the world.

Log in for authorized contributors

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Security researchers have disclosed new “Plug and Pwn” attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges.

The research, presented at DEF CON 34 by security researchers Alejandro Hernando and Borja Martínez, exploits how Windows automatically identifies new connected hardware, locates matching driver packages, and installs vendor software as the NT AUTHORITY\SYSTEM account.

By using software to emulate USB devices, the researchers found they could force Windows to install signed vendor packages containing exploitable components or weaknesses that can be abused to gain SYSTEM privileges.

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026–68820) to target defense-sector companies as part of the Operation Dream Job campaign.

Microsoft addressed the flaw in this month’s Patch Tuesday security updates, marking it as actively exploited in the wild. Researchers found that the Lazarus threat group has been leveraging it since early July.

Microsoft says that the vulnerability is a “use-after-free in Windows Ancillary Function Driver for WinSock (AFD.sys)” that allows an attacker to increase their local privileges.

Android malware combo takes out loans and relays victims’ credit cards

A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal card data and send it to attackers in real time.

In an incident investigated by the cybersecurity company Group-IB, a fraudster impersonated a bank employee and called the victim under the pretense of a problem with their payment card.

During the call, the threat actor instructed the victim to sideload the SpyNote RAT disguised as a legitimate app and grant it Accessibility Service permissions, giving the attacker remote access to the Android device.

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attempts to exploit a critical vulnerability (CVE-2026–71362) in Adobe’s Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts.

The flaw is described as an incorrect authorization vulnerability that could be leveraged to “gain elevated access to sensitive resources” without authentication and is one of the seven issues that Adobe addressed in a security update yesterday.

Although the software vendor states in the advisory that it is not aware of exploits in the wild for any of the fixed flaws, eCommerce security company Sansec says that its Shield web application firewall (WAF) is already blocking CVE-2026–71362 exploitation attempts.

Animaquina: Controlling Industrial Robots Inside Blender

It started pretty organically. Early on, I was rigging robots and experimenting with Blender’s Python API through lots of small prototypes and little experiments. When I began my Doctor of Design, I unified all of those ideas into a single interactive robotics environment. I emphasize interactive because that’s where Blender really changed the game.

Animaquina has been used across multiple research labs, but it’s also been used on real built projects. The Dancing Columns project with Joseph Choma, exhibited at the Phase Gallery in Miami Beach, was entirely fabricated with Animaquina. More recently, a six-meter-tall column by artist Edouard Duval-Carrié, currently on display at the Venice Biennale, was produced using it for both the robotic 3D printing and robotic milling.


We spoke to Luis Pacheco about the story behind Animaquina, from early experiments rigging robots with Blender’s Python API to its real-world applications and how Geometry Nodes became the technical core of the project.

Astronomers discover a new kind of cosmic object — a black hole ‘star’

Have you heard of the inexplicable little red dots which were found in images from the early universe?

This article may explain them — _____________

The object was lurking in the constellation of Cetus, the Whale, billions of light years from Earth. It is thought to have formed 660m years after the big bang, astronomers’ leading theory as to how the universe began.

Measurements of the exotic body found that while it resembles an immense star, it releases 100bn times more energy than any known star can produce. The energy output is far closer to that observed from black holes than stars.

“We have found a new type of astrophysical object, a black hole star,” said Dr Rohan Naidu at the Kavli Institute for Astrophysics and Space Research, part of the Massachusetts Institute of Technology.

It “shines with the energy typically associated with black holes, but at the same time bears signatures classically associated with stars”, he added.”


Seagate: AI Runs On Disks Nobody Else Wants To Make (NASDAQ: STX)

Seagate Technology (<a href=“https://seekingalpha.com/symbol/STX#source=section%3Amain_content%7Cbutton%3Abody_link” “=”” title=“Seagate Technology Holdings plc”>STX) spent two decades teaching investors to sell every rally, which is why a 700% run into record margins still gets treated as a cycle to fade. But most of this commentary is missing one key fact, and that is the fact that Seagate is no longer a commodity drive maker riding an upturn, but rather, one half of a supply-disciplined duopoly selling allocated capacity on multi-year contracts. Seagate is compounding areal density while the market still prices boom-and-bust unit economics as the primary story. This, along with a new perspective on the flash-replacement argument and the cascading effects of the HAMR cost curve, leads me to rate STX a buy with 15–20% upside as I see the company continuing to impress investors with a renewed profit mix and valuation as we head into future quarters.

Seagate reports earnings around one core franchise following the exit of legacy consumer lines, listed below:

Mass-capacity storage (the substantial majority of revenue): nearline hard drives for cloud and hyperscale data centers, built on the HAMR-based Mozaic platform (30TB+ drives today, 44TB ramping, ~50TB targeted for late 2027 qualification), plus VIA and enterprise drives.

AI can now edit DNA and create deepfake viruses

The Screening Breakdown: The world’s primary defense against synthetic bioweapons is sequence matching. When a lab orders DNA, automated software checks the order against a “blocklist” of dangerous pathogens (like Smallpox or Anthrax).


AI is moving beyond text, images, and code. Now it’s learning to read and write — shall we say program — DNA.

In this episode of NEXT, John Koetsier talks with Eric Nguyen, co-founder and CEO of Radical Numerics, about the rapidly emerging world of biological AI.

Nguyen and his team helped create Evo and Evo 2, generative foundation models for DNA, and are now working toward what they call “general biological intelligence”: AI systems capable of understanding biology across DNA, gene expression, methylation, proteins, and other biological signals.

The potential upside is enormous.

/* */