❌

Normal view

There are new articles available, click to refresh the page.
Yesterday β€” 12 September 2026Main stream

3 great Paramount+ thrillers to watch this weekend (September 11-13)

12 September 2026 at 18:30

Things have been a little quiet on Paramount+ lately, unless you've been deep in cover-ops land with Lioness or eagerly awaiting some renewed Harrigan madness with the coming of season two of MobLand on September 18. But on the movie side of things, things are slow, which is a perfect time for a thriller to wake you up.

Before yesterdayMain stream

AppleCare One Family Covers Six People for $49.99 a Month

11 September 2026 at 15:30

AppleCare One Family covers eligible devices for up to six people at $49.99 monthly. Compare its benefits, claim limits and potential savings.

The post AppleCare One Family Covers Six People for $49.99 a Month appeared first on TechRepublic.

AppleCare One Family Covers Six People for $49.99 a Month

11 September 2026 at 15:30

AppleCare One Family covers eligible devices for up to six people at $49.99 monthly. Compare its benefits, claim limits and potential savings.

The post AppleCare One Family Covers Six People for $49.99 a Month appeared first on TechRepublic.

This Week in Security: It’s Patch Tuesday Again, TVs Spying, Supply Chain Worms Return, Prolonged Hack Impacts, Stolen IDs

11 September 2026 at 10:00

Several times this summer, Microsoft’s Patch Tuesday, the monthly roundup of major security patches for Microsoft products, has included record-breaking numbers of security fixes. The August 2026 patch set actually seemed to catch up. Was this a sign of the bug apocalypse lessening? Ha, nope!

Brian Krebs at Krebs On Security once again brings his excellent roundup of Patch Tuesday events, with this months patch set absolutely crushing previous numbers with nearly 1,000 security fixes.

Two of the fixes are for zero-day vulnerabilities under active exploitation in the wild, both allowing privilege escalation on Windows. Privilege escalation bugs turn general vulnerabilities in applications and games into full administrator access to gain persistence and deploy ransomware, and generally make any vulnerability significantly worse.

Krebs also calls out a CVSS 9.8 (so close to a perfect 10!) vulnerability that allows remote code execution in the Windows shell with no user interaction and no authentication, a remotely exploitable DNS bug present since Windows Server 2012 and Windows 10 which will likely see exploitation in the wild soon, and over a hundred other bugs are ranked β€œCritical”.

How the sheer volume of vulnerabilities in this patch will fit with recent Microsoft recommendations that companies should apply the patches immediately remains to be seen. (Likely: not very well, depending on what new behavior and issues the fixes cause!)

Is Your LG TV Spying on You?

Gamers Nexus continues their trend of high-quality investigation, and they have posted another tremendous multi-hour investigatory video. This time Gamers Nexus focuses on the ecosystem of LG televisions and monitors.

It shouldn’t likely surprise many here that β€œsmart” devices are usually more to the benefit of advertisers than consumers. Similarly, it shouldn’t be a surprise that a β€œsmart” device harvests user data to sell to advertises. What may be surprising is the degree to which LG devices appear to collect data, how much data is sent even when collection is turned off, and how overt executives at the company are, with multiple executives making statements in pitches to advertisers that LG β€œowns the glass”, β€œowns the living room”, and is designed to correlate devices, inhabitants of the environment, and viewing habits so that ads can be served to the TV and mobile devices in the same room simultaneously.

With tracking enabled, the smart TV captures telemetry of what applications are used, as well as continually capturing the video displayed and reporting fingerprints to LG servers and ad partners. The screen content is tracked not only for TV, but for the HDMI inputs, including if the TV is used as a PC monitor. If voice control is enabled, the TV also records audio and analyzes it. The TV also continually scans the local network and nearby Wi-Fi networks, reporting all the devices it finds on the local network, including host name, MAC address, and sometimes software running depending on the MDNS advertisements. Near-by Wi-Fi networks are sufficient for very precise geolocation, so LG effectively knows the location of every customer, as well.

Gamers Nexus makes the point that while the invasive ad tech is gross, it’s mostly limited if the user does not agree to the end-user license agreement – but the infrastructure required to enable it is riddled with security flaws, both discovered and likely additional undiscovered issues. A smart TV is basically a computer, usually running either some flavor of Android or Linux, with the attendant flexibility, power, and problems. A vulnerability in the TV operating system or its apps can provide a route into your internal network. (Not that this required an exploit: LG was called out earlier this summer because 42% of apps on the official app store contained residential proxy systems to sell your home Internet connection.) But it can also access any of the attached hardware, like the microphone.

Gamers Nexus demonstrates that a LG TV can be exploited to gain local root, and from there, it can record audio from attached devices – even when the primary microphone is muted. Gamers Nexus also discovered that muting the microphone on some models does not disconnect or disable the microphone, it simply sets the gain levels extremely low; recording is still possible, and with amplification, audio is still recoverable.

Spy tech and ad tech goes hand in hand; it will be interesting to see if LG responds by at least hardening the security on the devices, or if another company finds traction in selling modern televisions and monitors without the β€œsmart” advertising.

Shai-Halud NPM Worm Returns

Aikido.dev reports that after 111 days, the Shai-Halud worm returned to the NPM repository.

Shai-Halud was one of several worms hitting package repositories in the Spring of 2026, installing backdoors, stealing cryptocurrency wallets, and taking every login credential and authentication token it could find before infecting every package the tokens linked to. Since then, infections have remained quiet, and repositories like NPM have stated that they now scan every package as it is uploaded.

Charlie Erkisen at Aikido.dev observed that on September 7, 2026, four additional packages uploaded to NPM were infected with Shai-Halud; not a variant of the worm, but the original code, matching the known public signatures. Whatever scanning is in place in the NPM repository didn’t filter them, and if an exact match for a known, major worm isn’t caught by the infrastructure, it’s unclear how a new threat would be.

Boston Scientific Hack Continues

The apparent ransomware attack against Boston Scientific continues to have impacts, with Boston Scientific filing a report with the SEC that the attack is expected to have an impact on the company earnings.

Boston Scientific makes medical devices, like pacemakers, stents, and monitoring equipment. It has not yet been publicly disclosed what happened, or if customer data was compromised, but the SEC filing confirms that unauthorized access on β€œcertain systems” causing an outage. After several weeks of outages, the company reports that it is able to ship almost at capacity, and that the sterilization facilities for medical devices are online. While there is no estimate provided for full recovery, efforts are ongoing.

Commerce Sites Vulnerable

Adobe released a security bulletin that the Adobe Commerce and Magento platforms are under active exploitation from CVE-2026-75650, a flaw in the template engine.

These platforms power tens of thousands of commerce sites, and vulnerabilities in them are usually used to steal payment data or serve malware to customers during the checkout process. Previously this year, Magento patched another vulnerability which allowed uploading executable files to any store, and indications are that the current vulnerability has been exploited in the wild since early September 2026.

The current vulnerability allows implantation of PHP code by injecting custom styles into a query, which is then executed when Magento generates a failure email and renders the template. The attackers then download and install a control binary written in Rust which masquerades as a kernel thread task, which then monitors the store and collects payment data.

The vulnerability was publicly known and used for several days before Adobe made official statements of a fix being available, leaving any store running on Magento vulnerable with no official fixes, but as of writing this, Adobe has published patches and an advisory.

Microsoft to Block Unpatched Servers

Microsoft plans to block emails to to the cloud-hosted Exchange Online from unpatched on-premises Exchange servers.

Apparently the urge to self-host Microsoft Exchange is coupled with antipathy about actually patching it, to such a significant level that Microsoft is taking the steps to detect incoming mail from servers that have not patched since October 2025. While Microsoft updates rarely apply with zero problems, nearly a year is more than enough time to have tested and deployed a security fix.

β€œThis update released nearly a year ago, and all organizations should have updated to it”: so say we all.

Hackers Pose as Recruiters

Government-backed groups in Iran have been posing as recruiters trying to infect targets with malware.

The group, designated β€œNimbus Manticore”, is known to develop custom malware and remote access tools (RATs), and typically target specific individuals via spear-phishing attacks. The latest malware from the group is cross-platform and can infect Windows, macOS, and Linux, installing services to run websocket-based remote access tunnels, SSH tunnels, and a command-and-control client that allows live control of the infected device.

The group contacts targets posing as recruiters, but first the target must solve a coding challenge contained in a zip file. The zip contains a trojaned Node.js project which infects the victim system when compiled, deploying the remote access tools and setting up persistence to relaunch them if disabled. Multiple variants have already been spotted, generally targeting different countries, predominately Egypt, Afghanistan, and Ethiopia.

The latest version of the malware package also looks for settings and data from major security vendors like Symantec, CrowdStrike, and SentinelOne, as well as the contents of directories related to Google and Microsoft services.

The fake recruiting method has also been used by other groups in Iran and North Korea. Remember: any project with a build script can execute any commands as part of the build, and most IDE project files also allow embedding custom plugins and commands into the project. Triggering a compile on a project is the same as running arbitrary commands!

150 Million US Drivers Licenses Stolen

As many outlets are now reporting, a major ID validation company was compromised, leading to the theft of scans and data of 150 million US drivers licenses.

IDScan provides drivers license and identification card scanning services used by car rental companies, bars and dispensaries, hotels, concert venues, and a multitude of other businesses. If you’ve ever had to hand your ID over for validation, there’s a high chance you’ve interacted with IDScan or a similar company.

Evidence points to IDScan being compromised for at least a year, with full scans of licenses continually exfiltrated. The scans include everything visible on a typical license or ID card, including name, license identification number, ID photo, and home address, but also the date that it was scanned in. The collection even includes additional scans of the ID in ultraviolet and infrared to catch any watermarks. With 150 million entries, the data set contains everyone from the security researcher Brian Krebs who broke the story, to government officials like Pete Hegseth.

The data has been available for sale, individually or in bulk, although with the recent press coverage the site claiming to sell the data has gone offline for now. Before disappearing, the site claimed that all data was exfiltrated into their own databases, which means it’s still available somewhere, and shutting them out of the IDScan service won’t protect data already stolen.

Many aspects of this echo the scanned ID data stolen from validation services used by Discord and other online services: almost like scanning unchangeable government IDs is a bad plan?

American Meteor Society Knocked Offline

It’s all fun and games until they come for the geek hobbies. The American Meteor Society Fireball tracking program is was knocked offline, seemingly from a ransomware attack. Fortunately it looks like as of writing this, the admins were able to restore a backup and the site is online again.

Raiders star Ashton Jeanty backs Nukleus, a tech platform for athletes and their advisors

11 September 2026 at 09:11
Las Vegas Raiders running back Ashton Jeanty, an investor in Nukleus and a spokesperson for the platform. (Nukleus Photo / Ben Miller)

Hector Rivas spent a decade building ThriftBooks into one of the country’s largest used-book sellers, before an unlikely second act: co-founding a sports agency representing NFL players.

That career change led him to the problem behind his newest startup, and to the Las Vegas Raiders running back who just invested in it.

Nukleus founder and CEO Hector Rivas. (LinkedIn Photo)

Nukleus, based in Issaquah, Wash., is building what Rivas calls an operating system for the business of sports. The idea is a single workspace for everyone in an athlete’s orbit: agent, lawyer, CPA, financial advisor, marketing team, and others. It lets them all work from the same contracts, deadlines and records, rather than each keeping a separate pile of emails and spreadsheets.

The idea came out of Rivas’s years at Disruptive Sports, the agency he co-founded in 2020 and left earlier this year.

Ashton Jeanty, who signed a four-year, $35.9 million rookie contract with the Raiders in 2025, has taken equity in the company and signed on to serve as its public face.

Nukleus has also named four strategic investors: Mat McBride, Microsoft’s executive vice president and CFO for commercial products and infrastructure; WaFd Bank President and CEO Brent Beardall; investor Skyler Nelson, previously of Vulcan Capital and its successor firm Cercano; and Dr. Brett Kindle of the Andrews Institute in Gulf Breeze, Fla.

The company has a team of 12 based out of its Issaquah office, plus a supporting engineering team in India. Most of the team is engineering.

Other executives include CTO Eric Ahlstrom, previously at Microsoft, Unity, Oracle and ESPN; chief creative officer Ben Miller, a former creative director at the University of Washington and CAA Sports; and CFO Matt Porter, who worked with Rivas at ThriftBooks, EcoGoodz and Disruptive.

Nukleus closed a pre-seed round from friends and family in 2025 and is raising again now. Rivas declined to disclose the amount raised by the company so far.

From books to football: Rivas was ThriftBooks’ first CEO, running the used-book seller for about a decade after it launched in 2003. Based in the Seattle area, the company grew during his tenure from a storage unit in Kirkland, Wash., to 10 distribution facilities in 10 states, by his account.

He went on to found EcoGoodz, a used-goods and overstock brokerage, and in 2020 co-founded Disruptive Sports Agency with agent Henry Organ.

Rivas, an NFLPA-certified contract advisor, worked the business side of the agency. He left earlier this year to build Nukleus full time.

The years inside the agency are what produced the idea.

Everyone in a player’s orbit was working off β€œtheir own version of the truth,” Rivas explained via email: the agent, the lawyer, the CPA, the financial advisor, the marketing team. The athlete, he said, β€œwas the one absorbing the cost of that disconnect,” in slower decisions and deals that fell through the cracks.

The pitch in Las Vegas: Jeanty and Rivas knew each other from Rivas’s years at the sports agency, and Rivas said the running back had been tracking what he was building.

β€œBecause Ashton and I already knew each other, and he’d been aware of what I was building, the conversation came together naturally,” Rivas said.

He flew to Las Vegas to walk Jeanty through the model, the team, and where the company was headed. Rivas said Jeanty’s equity reflects both money invested and his role promoting the platform.

In a statement, Jeanty described the job of running his own career.

β€œComing into the NFL, you become a CEO, directing a team of agents, advisors, and marketers, whether you’re ready or not,” he said. β€œNukleus is what finally gets them all on the same page, so I can actually run that team the way it should be run. That’s why I invested in it.”

Where things stand: The product is in a free beta with about 30 users, including athletes, agents, agencies, lawyers and marketing staff. Nukleus plans to charge $99 per user per month for a starter plan and $249 for a full-featured one, with custom enterprise pricing. Athletes join free.

Alongside contract storage, deadline tracking and a shared workspace, the company is building AI tools meant to answer questions about contract terms and league rules.

Others are working similar territory. Agent Live 360 sells software built specifically for sports agents, and Opendorse, which says it works with more than 1,000 sports agents, offers tools to negotiate, approve and track deals. Nukleus says it differs from narrower tools by serving everyone in an athlete’s orbit.

The bigger bet: The company is looking well past a single app.

β€œLong-term, I don’t see this as a tool athletes use, I see it as the infrastructure the entire business of sports runs on,” Rivas said. β€œEvery athlete becomes the center of their own connected team, and every professional working with them, across every sport, at every level, operates on one shared system instead of a hundred disconnected ones.”

How to Make Your Christmas Cactus Bloom

10 September 2026 at 19:30

The Christmas cactus is a rainforest plant that’s easy to grow at home in indirect sunlight and well-draining potting medium. Did you know that you can encourage it to bloom every holiday season with a few simple steps to mimic the natural dormancy process? Read on for instructions, and get set for a profusion of flowers.

The post How to Make Your Christmas Cactus Bloom appeared first on Gardener's Path.

6 must-watch shows to stream before the 2026 Emmys

10 September 2026 at 18:30

Television’s highest honors will be awarded to several shows at the 2026 Primetime Emmys. HBO led the field with 122 total nominations, including nominations at the Creative Arts Emmy Awards, followed by Netflix (111) and Apple TV (89). These three services will be searching for Emmy glory in several of the major categories, including drama series, comedy series, and limited or anthology series.

Europe will go it alone on Venus mission after NASA yanks radar instrument

10 September 2026 at 15:09

The European Space Agency is moving "full steam ahead" with development of a robotic mission to Venus after NASA officials determined they were unlikely to fulfill a commitment to provide a US-built radar instrument for the spacecraft, the mission's project scientist said.

The European orbiter, named Envision, will map the Venusian surface at 10 times higher resolution than the last radar mission sent to Venus by NASA in the 1990s. The planet is enshrouded in a blanket of thick clouds of sulfuric acid, rendering its mysterious surface unseen by optical cameras in orbit. Radar is the most effective way to penetrate the clouds of Venus to reveal the terrain below, and scientists will use Envision to look for signs of active volcanism.

NASA and ESA signed a memorandum of understanding in 2024 outlining their partnership on Envision. NASA agreed to supply a US-made synthetic aperture radar instrument, Envision's primary means of mapping the surface of Venus, along with providing tracking and communications support through NASA's Deep Space Network. In exchange, ESA would include US researchers on Envision's science team. Europe would build the Envision spacecraft and the rest of its science instruments and provide the launch on an Ariane 6 rocket.

Read full article

Comments

Β© ESA/Paris Observatory/VR2Planets

4 Best Wear OS Smartwatches for 2026

10 September 2026 at 06:49

Pixel Watch 5 leads overall, while Galaxy Watch9, OnePlus Watch 3, and Galaxy Watch Ultra2 offer better fits for Samsung users, battery life, or outdoor use.

The post 4 Best Wear OS Smartwatches for 2026 appeared first on TechRepublic.

4 Best Wear OS Smartwatches for 2026

10 September 2026 at 06:49

Pixel Watch 5 leads overall, while Galaxy Watch9, OnePlus Watch 3, and Galaxy Watch Ultra2 offer better fits for Samsung users, battery life, or outdoor use.

The post 4 Best Wear OS Smartwatches for 2026 appeared first on TechRepublic.

Poland unveils a new jet-powered strike drone

10 September 2026 at 10:49
Polish defense manufacturer WB Group has unveiled Gladius 2, a new loitering munition built for a reduced radar and heat signature and powered by a turbojet engine for a fast run into the target area. The company also refers to the weapon as Warmate 30, tying it to WB Group’s existing Warmate family of strike […]

Poland orders Turkish surveillance systems for its scout vehicles

9 September 2026 at 03:59
Turkish defense company ASELSAN has signed a new export contract to supply Poland with 24 more sets of its ARSUS reconnaissance and surveillance systems, the company announced September 8 at the MSPO defense exhibition in Kielce, Poland. ASELSAN signed the deal with Polish manufacturer AMZ Kutno for use by the Polish Armed Forces. Deliveries are […]

The universal language of space is... Star Trek? Mais oui.

8 September 2026 at 16:20

Sixty years after television audiences first tuned in to see the voyages of the Starship Enterprise, an astronaut on board the International Space Station has paid tribute to Star Trek by flying the badge of the franchise's latest fictional captain.

Expedition 75 flight engineer Sophie Adenot with European Space Agency (ESA) donned the Delta badge originally worn by actor Anson Mount for a video recorded from aboard the space station. Mount portrays Christoper Pike in the Paramount+ streaming series Star Trek: Strange New Worlds. Paramount and ESA both released the clip on their Instagram feeds.

"For 60 years, Star Trek has brought us stories of friendship and exploration. I'm wearing Captain Pike's badge aboard the ISS in celebration of continuing the real world work of science and exploration," said Adenot. "For me, exploration and science are about curiosity and cooperation daring to go a little farther together, learning from what we discover and build, and turning that knowledge into a better future for everyone."

Read full article

Comments

Β© ESA

❌
❌