Toggle light / dark theme

Get the latest international news and world events from around the world.

Log in for authorized contributors

How Gravity from Entropy theory connects the second law of thermodynamics with the emergence of cosmic structure

A new study by Queen Mary University of London mathematician Professor Ginestra Bianconi proposes a new perspective on one of the deepest questions in modern physics: How can the universe become increasingly structured and complex while still obeying the second law of thermodynamics?

Einstein famously stated that “The second law of thermodynamics occupies a unique position among the laws of Nature,” reflecting his conviction that it is among the most fundamental principles of physics and unlikely to be overthrown. The second law states that the total entropy of an isolated system tends to increase over time, a principle often associated with the growth of disorder.

This presents a long-standing puzzle in cosmology. The early universe is generally believed to have existed in a low-entropy state and to evolve toward states of higher entropy. Yet over cosmic history, the universe has also given rise to increasingly complex structures, including galaxies, stars, planets and ultimately life itself. Reconciling the emergence of such ordered structures with the relentless increase of entropy remains an open challenge.

A scheme to verify gates of a quantum computer without examining devices

Quantum computers, systems that process information using the principles of quantum mechanics, could solve some problems that cannot be tackled by the classical computers currently used worldwide. Despite their potential, verifying that these computers are working correctly and can reliably perform computations remains challenging.

Shubhayan Sarkar, a researcher at the University of Gdansk, recently introduced a new scheme for certifying that quantum chips (unitary gates) in a quantum computer are operating correctly without relying on assumptions about their internal components. This scheme, introduced in a paper published in Physical Review Letters, uses an approach referred to as almost device-independent (DI) certification.

“Consider the computer you are using right now,” Sarkar told Phys.org. “If it provides the answer to a mathematical problem, how do you know that the computation is correct? In practice, we rarely verify every calculation ourselves.

Mythos Didn’t Break Your Security Program. Your Exposure Window Could

The industry spent the initial months after Anthropic’s April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain valid. Yet they all stop short of addressing the single metric that determines whether any of those vulnerabilities actually lead to a breach: the exposure window.

The exposure window — the gap between the moment a vulnerability becomes exploitable and the moment your team fixes it — is the time an attacker has to do actual damage. That window is currently open far too wide. In 2025, the average eCrime breakout time dropped to 29 minutes. Even PCI DSS — the strictest compliance framework in the industry — allows 30 days to remediate a critical vulnerability. That’s a 1,000-to-1 gap between how fast attackers move and how fast organizations are expected to respond. And the stick propping this exposure window open? Mobilization — the ownership, remediation, and organizational complexity that lowers response times and raises risk.

In this article, I’ll walk through why the exposure window is now the metric that matters most, what keeps it open, and how AI-driven discovery is forcing proactive security teams to adopt the speed-based metrics that SOC teams have used for years.

New 7Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

26.02 subtracts the bytes already written and bails out if that running total ever exceeds the buffer. The same flawed length handling appears unchanged in 7-Zip source back to at least version 21.07 (2021), though neither ZDI nor 7-Zip has said which releases are actually exploitable.

CVE-2026–14266 is the latest in a run of memory-safety bugs in 7-Zip’s archive handlers. On April 27, version 26.01 fixed a batch of them, including the higher-scored CVE-2026–48095, an NTFS-handler heap-write overflow that GitHub Security Lab detailed on May 22 with a working proof-of-concept. The XZ flaw is the quieter of the two so far, and 26.02 rolls up every one of these fixes, so one update covers them all.

So update to 7-Zip 26.02 or later on every machine that opens archives from outside. Updating is a manual install from the official site, so set-and-forget machines will not pick it up on their own. Any product that ships a vulnerable copy of 7-Zip’s XZ decoder needs its own vendor fix.

/* */