o

Brian May Hospitalized

Brian May was admitted to a hospital earlier this week  ...for a torn butt. The guitarist/astrophysicist injured himself while gardening, which is a bit reminiscent of the line from the movie This Is Spinal Tap in which one drummer's death is attributed to a "bizarre gardening accident." May is expected to recover, but it may take some time.  

Writing on Instagram, the Queen guitarist said: “I managed to rip my gluteus maximus to shreds in a moment of overenthusiastic gardening. So suddenly I find myself in a hospital getting scanned to find out exactly how much I’ve actually damaged myself. Turns out I did a thorough job – this is a couple of days ago – and I won’t be able to walk for a while … or sleep, without a lot of assistance, because the pain is relentless.”

May is 72, and had been at his home after Queen was forced to cancel a tour due to the pandemic. Now he is recovering at home, and requests peace and quiet. -via reddit




o

Dad: “Remind me again what you will do with a degree in conservation biology?”



This video is well-enhanced by the title. Bird Guy lives up to his name as he waits for his Evening Grosbeaks to come visit. Seems like a great life, but that hoodie will need laundering often. Worth it. -via Metafilter




o

CISA Warns Patched Pulse Secure VPNs Could Still Expose Organizations to Hackers

The United States Cybersecurity and Infrastructure Security Agency (CISA) yesterday issued a fresh advisory alerting organizations to change all their Active Directory credentials as a defense against cyberattacks trying to leverage a known remote code execution (RCE) vulnerability in Pulse Secure VPN servers—even if they have already patched it. The warning comes three months after another




o

COVID-Themed Lures Target SCADA Sectors With Data Stealing Malware

A new malware campaign has been found using coronavirus-themed lures to strike government and energy sectors in Azerbaijan with remote access trojans (RAT) capable of exfiltrating sensitive documents, keystrokes, passwords, and even images from the webcam. The targeted attacks employ Microsoft Word documents as droppers to deploy a previously unknown Python-based RAT dubbed "PoetRAT" due to




o

Unpatchable 'Starbleed' Bug in FPGA Chips Exposes Critical Devices to Hackers

A newly discovered unpatchable hardware vulnerability in Xilinx programmable logic products could allow an attacker to break bitstream encryption, and clone intellectual property, change the functionality, and even implant hardware Trojans. The details of the attacks against Xilinx 7-Series and Virtex-6 Field Programmable Gate Arrays (FPGAs) have been covered in a paper titled "The




o

Researcher Discloses 4 Zero-Day Bugs in IBM's Enterprise Security Software

A cybersecurity researcher today publicly disclosed technical details and PoC for 4 unpatched zero-day vulnerabilities affecting an enterprise security software offered by IBM after the company refused to acknowledge the responsibly submitted disclosure. The affected premium product in question is IBM Data Risk Manager (IDRM) that has been designed to analyze sensitive business information




o

The Incident Response Challenge 2020 — Win $5,000 Prize!

Cybersecurity firm Cynet today announced the launch of a first of its kind challenge to enable Incident Response professionals to test their skills with 25 forensic challenges that were built by top researchers and analysts. The challenge is available on https://incident-response-challenge.com/ and is open to anyone willing to test his or her investigation skills, between April 21st and May




o

Chinese Hackers Using New iPhone Hack to Spy On Uyghur Muslims

A Chinese hacking group has been found leveraging a new exploit chain in iOS devices to install a spyware implant targeting the Uyghur Muslim minority in China's autonomous region of Xinjiang. The findings, published by digital forensics firm Volexity, reveal that the exploit — named "Insomnia" — works against iOS versions 12.3, 12.3.1, and 12.3.2 using a flaw in WebKit that was patched by




o

Zero-Day Warning: It's Possible to Hack iPhones Just by Sending Emails

Watch out Apple users! The default mailing app pre-installed on millions of iPhones and iPads has been found vulnerable to two critical flaws that attackers are exploiting in the wild, at least, from the last two years to spy on high-profile victims. The flaws could eventually let remote hackers secretly take complete control over Apple devices just by sending an email to any targeted




o

Hackers Trick 3 British Private Equity Firms Into Sending Them $1.3 Million

In a recent highly targeted BEC attack, hackers managed to trick three British private equity firms into wire-transferring a total of $1.3 million to the bank accounts fraudsters have access to — while the victimized executives thought they closed an investment deal with some startups. According to the cybersecurity firm Check Point, who shared its latest investigation with The Hacker News,




o

Malicious USB Drives Infect 35,000 Computers With Crypto-Mining Botnet

Cybersecurity researchers from ESET on Thursday said they took down a portion of a malware botnet comprising at least 35,000 compromised Windows systems that attackers were secretly using to mine Monero cryptocurrency. The botnet, named "VictoryGate," has been active since May 2019, with infections mainly reported in Latin America, particularly Peru accounting for 90% of the compromised




o

How An Image Could've Let Attackers Hack Microsoft Teams Accounts

Microsoft has patched a worm-like vulnerability in its Teams workplace video chat and collaboration platform that could have allowed attackers to take over an organization's entire roster of Teams accounts just by sending participants a malicious link to an innocent-looking image. The flaw, impacting both desktop and web versions of the app, was discovered by cybersecurity researchers at




o

Researchers Uncover Novel Way to De-anonymize Device IDs to Users' Biometrics

Researchers have uncovered a potential means to profile and track online users using a novel approach that combines device identifiers with their biometric information. The details come from a newly published research titled "Nowhere to Hide: Cross-modal Identity Leakage between Biometrics and Devices" by a group of academics from the University of Liverpool, New York University, The Chinese




o

Critical Security Patches Released for Magento, Adobe Illustrator and Bridge

It's not 'Patch Tuesday,' but software giant Adobe today released emergency updates for three of its widely used products that patch dozens of newly discovered critical vulnerabilities. The list of affected software includes Adobe Illustrator, Adobe Bridge, and Magento e-commerce platform, containing a total of 35 vulnerabilities where each one of them is affected with multiple critical




o

Critical Bugs Found in 3 Popular e-Learning Plugins for WordPress Sites

Security researchers are sounding the alarm over newly discovered vulnerabilities in some popular online learning management system (LMS) plugins that various organizations and universities use to offer online training courses through their WordPress-based websites. According to the Check Point Research Team, the three WordPress plugins in question — LearnPress, LearnDash, and LifterLMS —




o

Cato SDP: Cloud-Scale and Global Remote Access Solution Review

The Scouts acknowledged the necessity to "Be Prepared" over 100 years (!) ago; the industry should have, as well. Yet COVID-19 took businesses – more like the entire world – by surprise. Very few were prepared for the explosion of remote access, and the challenge of instantly shifting an entire organization to work from anywhere. Cato Networks shared its increase in remote access usage post




o

New Android Malware Steals Banking Passwords, Private Data and Keystrokes

A new type of mobile banking malware has been discovered abusing Android's accessibility features to exfiltrate sensitive data from financial applications, read user SMS messages, and hijack SMS-based two-factor authentication codes. Called "EventBot" by Cybereason researchers, the malware is capable of targeting over 200 different financial apps, including banking, money transfer services,




o

Targeted Phishing Attacks Successfully Hacked Top Executives At 150+ Companies

In the last few months, multiple groups of attackers successfully compromised corporate email accounts of at least 156 high-ranking officers at various firms based in Germany, the UK, Netherlands, Hong Kong, and Singapore. Dubbed 'PerSwaysion,' the newly spotted cyberattack campaign leveraged Microsoft file-sharing services—including Sway, SharePoint, and OneNote—to launch highly targeted




o

Critical SaltStack RCE Bug (CVSS Score 10) Affects Thousands of Data Centers

Two severe security flaws have been discovered in the open-source SaltStack Salt configuration framework that could allow an adversary to execute arbitrary code on remote servers deployed in data centers and cloud environments. The vulnerabilities were identified by F-Secure researchers earlier this March and disclosed on Thursday, a day after SaltStack released a patch (version 3000.2)




o

Hackers Breach LineageOS, Ghost, DigiCert Servers Using SaltStack Vulnerability

Days after cybersecurity researchers sounded the alarm over two critical vulnerabilities in the SaltStack configuration framework, a hacking campaign has already begun exploiting the flaws to breach servers of LineageOS, Ghost, and DigiCert. Tracked as CVE-2020-11651 and CVE-2020-11652, the disclosed flaws could allow an adversary to execute arbitrary code on remote servers deployed in data




o

New Malware Jumps Air-Gapped Devices by Turning Power-Supplies into Speakers

Cybersecurity researcher Mordechai Guri from Israel's Ben Gurion University of the Negev recently demonstrated a new kind of malware that could be used to covertly steal highly sensitive data from air-gapped and audio-gapped systems using a novel acoustic quirk in power supply units that come with modern computing devices. Dubbed 'POWER-SUPPLaY,' the latest research builds on a series of




o

Change This Browser Setting to Stop Xiaomi from Spying On Your Incognito Activities

If you own a Xiaomi smartphone or have installed the Mi browser app on any of your other brand Android device, you should enable a newly introduced privacy setting immediately to prevent the company from spying on your online activities. The smartphone maker has begun rolling out an update to its Mi Browser/Mi Browser Pro (v12.1.4) and Mint Browser (v3.4.3) after concerns were raised over its




o

Warning: Citrix ShareFile Flaw Could Let Attackers Steal Corporate Secrets

Since the past few weeks, software giant Citrix has privately been rolling out a critical software update to its enterprise customers that patches multiple security vulnerabilities affecting Citrix ShareFile content collaboration platform. The security advisory—about which The Hacker News learned from Dimitri van de Giessen, an ethical hacker and system engineer—is scheduled to be available




o

Download: 'Coronavirus Cyber Security for Management' Template for CISOs

The Coronavirus crisis introduces critical operational challenges to business continuity, placing high stress on organizations' management. As a result, CIOs and CISOs face a double challenge on the cyber risk front – apart from the new risks that the mass transfer of employees working remotely brings, capturing the management mindshare for further investments in security becomes harder than




o

Facebook Launches 'Discover,' A Secure Proxy to Browse the Internet for Free

More than six years after Facebook launched its ambitious Free Basics program to bring the Internet to the masses, the social network is back at it again with a new zero-rating initiative called Discover. The service, available as a mobile web and Android app, allows users to browse the Internet using free daily data caps. Facebook Discover is currently being tested in Peru in partnership




o

This Asia-Pacific Cyber Espionage Campaign Went Undetected for 5 Years

An advanced group of Chinese hackers has recently been spotted to be behind a sustained cyber espionage campaign targeting government entities in Australia, Indonesia, Philippines, Vietnam, Thailand, Myanmar, and Brunei—which went undetected for at least five years and is still an ongoing threat. The group, named 'Naikon APT,' once known as one of the most active APTs in Asia until 2015,




o

DigitalOcean Data Leak Incident Exposed Some of Its Customers Data

DigitalOcean, one of the biggest modern web hosting platforms, recently hit with a concerning data leak incident that exposed some of its customers' data to unknown and unauthorized third parties. Though the hosting company has not yet publicly released a statement, it did has started warning affected customers of the scope of the breach via an email. According to the breach notification




o

Control Or Creativity?

The post Control Or Creativity? appeared first on Fiction Notes.

Who’s in control of the publishing process? Once the contract is signed, does the author have any say in what happens to the story? Traditional contracts specify that the publishing company will publish as they see fit. In other words, control is given to the publisher by the contract. One criticism of indie authors is Continue Reading

The post Control Or Creativity? appeared first on Fiction Notes.




o

When Will a Self-Published Book Win a Major Book Award?

The post When Will a Self-Published Book Win a Major Book Award? appeared first on Fiction Notes.

Dear Librarians who serve on one of the ALA Youth Media Awards committees (Newbery, Caldecott, Coretta Scott King, Michael L. Printz, Schneider Family, Alex, Mildred L. Batchelder, Odyssey, Pura Belpré, Robert F. Siebert, Excellence in Early Learning Digital Media, Stonewall, Theodor Seuss Geisel, William C. Morris, YALSA Award for Excellence in Nonfiction for Young Adults, Continue Reading

The post When Will a Self-Published Book Win a Major Book Award? appeared first on Fiction Notes.




o

Prenez soin de vous + Take care of your French with a dozen more words

A gift from our guest: dried cyclamen, a ballet of expressive flowers! Today's Expression: Prenez soin de vous : take care of yourself (plural: yourselves) Audio file: Click here to listen to today's phrase in French and English A DAY IN A FRENCH LIFE by Kristi Espinasse Someone close to us, someone young and strong, had an accident--une chute while alone at home-- followed by a trip to ER for some points! The emotional and physical scars are there, but our bien-aimé is here with us now and will stay in time to recover from the choc. Today's short entry is a reminder to you and me to continue to check in with those who are living alone. Which of our friends are on their own? Which family members? Which colleagues? Have you seen the post lady lately? Big, strong, young? Grand, fort, jeune? Don't forget to check on these ones! Check on everyone. Self-check. Vérifie! I am off to check on our guest, who somehow managed--between the ER and here--to pack a bunch of goodies for us to share at the table: gingembre, poireaux, citrons, oranges--les agrumes--which have since been added to soup and put into a simple cake....

          




o

Our mystery guest + le cafoutche = The "everything room" in France

Up till now, the best part of our cafoutche was the view. More about a few sweet and savory projects in today's missive. Thank you for reading and sharing this post with a friend! Today's Word: cafoutche : storage room, cupboard AUDIO FILE: click here to listen to the following quote in French Cafoutche: De l’occitan cafoucho synonyme de cahute. A Marseille il désigne un petit placard où l’on met de tout et de rien. Peut désigner la cave, aussi bien qu’une petite pièce fermée ou un débarras. Cafoutche: from Occitan cafoucho synonymous with hut. In Marseille this designates a small closet where you put everything and nothing. May refer to the cellar, as well as a small closed room or storage room. --www.lasardineduport.fr A DAY IN A FRENCH LIFE by Kristi Espinasse Not only is our guest on the mend, she is mending! Helping, that is, to fix everything from a punctual petit creux to our unruly store room--insisting all the while, ça fait du bien de travailler. What a positive way to look at work--as something that makes us feel better! I know this is true with my writing which I often put off to a later date,...

          




o

Pâte Brisée : Jêrôme's 4-ingredient wine-based shortcrust pastry is easy, versatile, delicious for savory quiche or sweet, delectable pie!

I can tell you--after seeing them in the bathroom mirror this morning--this shortcrust pastry recipe will give you les poignées d'amour. That's French for "love handles." Même pas peur? Not even scared? Good! Read on and discover a truly delicious and versatile pâte brisée. I should know...I've tested 10 of them in the past week--ever since you asked for the recipe! Today's Word: la pâte brisée : shortcrust pastry, a rich dough for making pie crust Audio: Listen to the words pâte brisée in this soundfile En cuisine, la pâte brisée est une pâte servant de base aux tartes salées ou sucrées. La pâte brisée désigne généralement une pâte composée principalement de farine et de matière grasse sans sucre. In cooking, shortcrust pastry is a dough used as a base for savory or sweet pies. Shortcrust pastry generally refers to a dough composed mainly of flour and fat, without sugar. Jérôme's Pâte Brisée: 4-ingredient Shortcrust Pastry (makes one large or two small tarts!) Ingredients... 2 cups flour 2 teaspoons baking powder 1/2 cup white wine 1/2 cup sunflower oil Note: ordinary white wine is all you need. Leftover wine will work as long as it hasn't turned to vinegar. For...




o

Here’s Why Americans Need a Basic Income During the Coronavirus Outbreak

Dramatic action is needed now to blunt the immediate pain of vulnerable workers.




o

Trump Uses Coronavirus to Spread Racism

There is nothing like a global pandemic to unleash the forces of racism in society. Trump is now routinely calling the novel coronavirus strain “the Chinese virus.”




o

17 Years Later: The Consequences of Invading Iraq

While the world is consumed with the terrifying coronavirus pandemic, on March 19 the Trump administration will be marking the 17th anniversary of the U.S. invasion of Iraq by ramping up the conflict there. After an Iran-aligned militia allegedly struck a U.S. base near Baghdad on March 11, the U.S. military carried out retaliatory strikes against five […]




o

Elections May Have to Change During the Coronavirus Outbreak. Here’s How.

As the novel coronavirus spreads through the U.S. during presidential primaries, election and government officials are scrambling to figure out how to allow voters to cast their ballots safely ― or postpone primaries altogether. Managing in-person voting during an unprecedented pandemic has forced authorities to overcome new virus-related hurdles: providing sufficient cleaning supplies to polling […]




o

These Are the 51 GOP Senators Who Just Voted Against Expanding Paid Sick Leave to Protect Americans

Republican senators on Wednesday teamed up to kill an amendment introduced by Democratic Sen. Patty Murray that would have expanded paid sick leave to millions of U.S. workers left out of a bipartisan coronavirus relief package. Every Republican present for the vote, 51 in total, voted against the amendment while every Senate Democrat voted in favor. […]




o

The Dem Primary is Over, and We Need Bernie Sanders to Lead on Health Care From the Senate

On Tuesday, I cast a joyless vote for the very much politically doomed Vermont Sen. Bernie Sanders in the Illinois primary, in an elementary school where hushed whispers and fearful glances had replaced the normal din of an election day. There was no one standing just outside the perimeter hustling me to vote for this […]




o

Not Giving Up on Happiness: Care of the Self and Well-Being in a Plague Year

The specter of plague haunts our world, and it brings with it not only the ghouls of disease and death but vast economic and social uncertainty of a sort only the most elderly among us remembers (the Great Depression and World War II). My father is 90 and when I called him a child of […]




o

If Trump Declares Martial Law Due to Coronavirus, Can He Suspend the Election?

Following the criticism that he has mismanaged the nation’s response to the coronavirus epidemic, Trump has declared himself a “wartime president.”  If martial law is next, what will happen to the November election?




o

Senator Dumped Up to $1.7 Million of Stock After Reassuring Public About Coronavirus Preparedness

Soon after he offered public assurances that the government was ready to battle the coronavirus, the powerful chairman of the Senate Intelligence Committee, Richard Burr, sold off a significant percentage of his stocks, unloading between $628,000 and $1.72 million of his holdings on Feb. 13 in 33 separate transactions. As the head of the intelligence […]




o

Imagining A New World on the Other Side of the Pandemic

At The Nation, Atossa Araxia Abrahamian has a provocative piece that imagines how future historians may come to write the story of the Covid-19 pandemic. The speculative history takes the form of a “best-case” scenario that serves as both a challenge and a salve, an inspirational fantasy to help balance out the more easily imagined […]




o

ABOUT ALL THOSE FIRST-TIME GUN BUYERS

We’ve had several cycles of so-called “panic buying” of firearms and ammunition in the last twenty years.  There was Y2K, when credible authorities warned us that the ticking of the clocks into the Year 2000 would blast all of the Read more




o

WHO WAS THAT MASKED MAN?

Well, depending when and where you saw him, it might have been…me. When this whole thing started, we were told that people wearing bandannas and even N95 masks in public were fools: “Don’t you idiots know that just cloth won’t Read more




o

“YOU WANT AMMO WITH THAT?”

“…and while we’re at it, would you like to super-size your order? We can give you a five-hundred or thousand-round case instead of just that fifty-round box…” Yes, brothers and sisters, the Covid-19 crisis has led us to…drive-through gun sales. Read more




o

A MODEL FOR GUN CLUBS

Kevin Howard is the president of the Enfield Outing Club. (No, they’re not dedicated to shooting British military rifles; they’re located in picturesque Enfield, New Hampshire.) He recently sent out a notice to members of the gun club, explaining why Read more




o

RETURNING TO NORMALCY?

When the question is economy versus public health – literally, “Your money or your life” – the answer should be pretty obvious.  That said, though, the profound economic consequences threaten more than quality of life, depending on the progress of Read more




o

PLUS CA CHANGE, PLUS CA MEME CHOSE

Some things change: I never thought I’d see the day when I would walk into a gun shop wearing a mask and not be taken at gunpoint. Some things remain the same: The Land O’ Lakes people eradicated the Native Read more




o

APPRECIATING THOSE ON THE FRONT LINES

Reader Joe Wolking passed along a poem I’d like to share with you. It speaks to law enforcement officers, by extension offers homage also to firefighter/paramedics and all those on the medical front during the current crisis: Freedom: By Joe Read more




o

Baller Move: Five Year Old Pulled Over En Route To Buy Lambo

By Isaac Cabe  Published: May 06th, 2020