Shared posts

13 Apr 23:05

Wikipedia Community Votes To Stop Accepting Cryptocurrency Donations

by msmash
waspleg writes: More than 200 long-time Wikipedia editors have requested that the Wikimedia Foundation stop accepting cryptocurrency donations. The foundation received crypto donations worth about $130,000 in the most recent fiscal year -- less than 0.1 percent of the foundation's revenue, which topped $150 million last year. In her proposal for the Wikimedia Foundation, GorillaWarfare added that 'Bitcoin and Ethereum are the two most highly used cryptocurrencies, and are both proof-of-work, using an enormous amount of energy.' According to one widely cited estimate, the bitcoin network consumes around 200 TWh of energy per year. That's about as much energy as is consumed by 70 million people in Thailand. And it works out to around 2,000 kWh per bitcoin transaction. Bitcoin defenders countered that bitcoin's energy usage is driven by its mining process, which consumes about the same amount of energy regardless of the number of transactions. So accepting any given bitcoin donation won't necessarily lead to more carbon emissions. But cryptocurrency critics argued that Wikimedia's de facto endorsement of cryptocurrencies may help to push up their price. And the more expensive bitcoin is, the more energy miners will devote to creating new ones. If the foundation complies with the community's request, it wouldn't be the first organization to stop using cryptocurrencies due to environmental concerns. Earlier this month, the Mozilla Foundation announced it would stop accepting cryptocurrencies that use the energy-intensive proof-of-work consensus process. These include bitcoin and ether -- though the latter is expected to convert to a proof-of-stake model in the future.

Read more of this story at Slashdot.

13 Apr 20:23

Bill Murray's Climactic Kingpin Scene Involved Over 1,000 People

by Travis Yates

As is the story with many quirky Hollywood comedies, the 1996 bowling comedy "Kingpin" from Peter and Bobby Farrelly (collectively known as The Farrelly Brothers) was a box office bomb that developed a cult following. The film follows washed-up former bowling prodigy Roy Munson (Woody Harrelson) who lost his hand shortly after his pro debut, and his rival, the eccentric, wild-haired Ernie "Big Ern" McCracken.

The Farrelly Brothers were on a roll after their 1994 debut film "Dumb & Dumber," but they came up short in their sophomore effort. Though "Kingpin" grossed just $25 million worldwide according to Box Office Mojo, it certainly has its merits. The cult comedy certainly gave us one of Bill Murray's most peculiar and memorable roles.

When Murray's character "Big Ern" McCracken finally vanquishes the plucky Roy Munson, he'd do so while filmed in front of 1,000 people. The scene itself, not to mention getting Murray to do it, was a lucky strike for the filmmaking duo.

Bill Murray Bowled A Turkey

The final tournament of "Kingpin" takes place at the National Bowling Center in Reno, Nevada. A challenge of the shoot was filling the building with extras for a full day, and keeping them convincingly engaged in the action. According to Fast Company, the film crew used raffles and had Bill Murray go into the stands to meet people to keep extras interested in the shoot. 

Then, bowling magic happened from an unlikely source, eliciting an organic response from a tired audience. Bobby Farrelly explains:

"But when we got to the final part and Bill had to get three strikes in a row, I figured it could take 10 to 15 rolls. It's gonna take a while for him to get three strikes. But I explained the situation to the audience: 'It's the last frame, he needs a turkey here. And so on the first one, you guys clap big, and then the second one, you clap bigger, and on the third one, you explode because he needs all three.' Of course, Bill gets up there, first one, strike. Everybody goes nuts. Second one, strike, the place goes crazy. Third one, strike. Three in a row. They were really blown away. Like, Bill just threw three strikes in a row when he had to and they erupted. It was not fake at all."

Murray's turkey (the bowling term for three strikes in a row) wasn't the only unplanned brilliance that day. The original script had "Big Ern" celebrating with no dialogue. Murray, known for his improvisation skills, took matters into his own hands and did something right up his alley: Instead of celebrating in silence as he was surrounded by fans and reporters, Murray improvised the absurd line that made it into the film, "I can do anything I want ... finally, Big Ern is above the law!"

Such a lightning-in-a-bottle moment likely wouldn't have happened without Murray's involvement -- something else that happened by chance.

They Weren't Sure Murray Would Show Up

The decision to cast Randy Quaid as Ishmael opposite Woody Harrelson paid off in more ways than one: without Quaid, Murray wouldn't have been in "Kingpin." 

After The Farrelly Brothers struggled to cast the part of "Big Ern" McCracken, it was Quaid who suggested Bill Murray. The casting process was very informal. Quaid called Murray and the next day he told the brothers that Murray wanted in on the project. They didn't even have Murray's contact information, just the promise from Quaid that he'd be there. The filmmakers had their doubts up until the day of the shoot. Peter Farrelly said:

"And then we were three weeks into production by the time Bill came along. So we had this fear that he wouldn't show up but sure enough, seven o'clock on the day he was supposed to arrive, we were shooting that night, he suddenly just comes walking in."

Murray's portrayal of "Big Ern" McCracken led to some of the most memorable moments in the entire film, both in and out of the bowling alley.

While "Kingpin" might have been a financial disaster at the box office, it has aged well over the years, so much so that a reported sequel is in the works. There's no word as of now if Murray will return, or if he's kept his bowling skills sharp, though it's hard to imagine "Kingpin" without "Big Ern."

Read this next: 20 Underrated Comedy Movies You Need To Watch

The post Bill Murray's Climactic Kingpin Scene Involved Over 1,000 People appeared first on /Film.

13 Apr 20:20

No Man’s Sky update turns the space game into Firefly

by Chris J Capel
No Man’s Sky update turns the space game into Firefly

The new No Man's Sky Outlaws update has arrived, bringing with it a load of new features to let players become a dashing intergalactic smuggler - and turning a great space game into the ultimate Firefly space pirate game.

The No Man's Sky patch 3.85 is out now, and it's the biggest update the PC game has had since either Sentinel or when Hello Games turned it into Dune last Halloween. No Man's Sky now has outlaw systems with shady deals and opportunities for piracy, including smuggling across star systems just like Han Solo or Mal Reynolds. If it goes wrong, however, expect the Sentinels to blow you out of the sky.

Space combat has also been rebalanced, along with an overhaul of various explosion effects to really enhance the Star Wars feel. You can now dogfight on the surface of planets, too, and create your own squadron of pilots to fly or fight with you at any time - and you can even upgrade, customise, and train your various wingmen. Players can now own up to nine starships, and upgrade them with bigger cargo holds to, well, hold more cargo.

RELATED LINKS: No Man's Sky multiplayer, No Man's Sky update, No Man's Sky VR
13 Apr 20:20

How to Fix Cracks in Your Driveway Without Paying a Professional

by Becca Lewis

After the winter months of rain, snow, ice, and frost, your driveway might not be looking its best—especially now that spring has sprung, and the weeds are further highlighting all its newly formed cracks. Repairing cracks in your driveway is important to keep them from getting larger, eventually requiring repaving or…

Read more...

13 Apr 20:19

Matt's Flights can help you travel like you've always wanted to and at a fair price

by Boing Boing's Shop

We thank our sponsor for making this content possible; it is not written by the editorial staff nor does it necessarily reflect its views.

It's safe to say that most people have the itch to use their vacation time to do exactly that, go on vacation. — Read the rest

13 Apr 20:16

The 7 Best Retro Gaming Consoles You Can Buy

by Christian Cawley

Looking for some retro gaming action, but don't have an old games console? No need to worry: all the big games console companies of the past are producing new, compact versions of their classic games systems.

13 Apr 20:15

AMD Radeon RX 6950 XT Custom Models Are Just As Expensive As NVIDIA’s RTX 3090 Ti In Early Listings, Priced at $2400 US

by Hassan Mujtaba

AMD Radeon RX 6950 XT Custom Models Are Just As Expensive As NVIDIA's RTX 3090 Ti In Early Listings, Priced at $2400 US

AMD's soon-to-be-released Radeon RX 6950 XT flagship graphics card is going to be an expensive graphics card if early listings are to go by. The card, which will be part of the RDNA 2 refresh GPU lineup, has been listed by an Australian retailer with pricing similar to NVIDIA's RTX 3090 Ti cards.

AMD Radeon RX 6950 XT Graphics Card Is As Expensive As NVIDIA RTX 3090 Ti In Early Listings WIth Pricing of Up To $2400 US

The AMD Radeon RX 6950 XT graphics cards are expected to be announced soon and we are now seeing retailers listing them down. Gigabyte seems to be working on its own custom model, the RX 6950 XTGaming OC which has been listed for $3241.54 AUD or just slightly above $2400 USD. This pricing is very close to custom models of the GeForce RTX 3090 Ti graphics card and a $1200-$1000 AUD difference between the custom RX 6900 XT models listed by the same retailer. Now since this is a preliminary listing, we will definitely be seeing much lower pricing as the new card gets close to street launch but for now, expect similar prices.

  • gbt-6950xt
  • gbt-3090ti-6950xt

Gigabyte Radeon RX 6950 XT is just as expensive as custom RTX 3090 Ti graphics cards. (Image Credits: Videocardz)

That's not all, Videocardz (Via Momomo_US) was able to obtain the full list of Gigabyte's Radeon RX 6x50 XT custom graphics cards that will be launching on the 10th of May. The lineup was submitted to the EEC and the full list can be seen in the table below:

Gigabyte RX 6x50XT Graphics Cards
Segment RX 6950XT RX 6750XT RX 6650XT
AORUS GV-R695XTAORUSX WB-16GD GV-R675XTAORUS E-12GD N/A
GAMING GV-R695XTGAMING OC-16GD GV-R675XTGAMING OC-12GD GV-R665XTGAMING OC-8GD
GV-R695XTGAMING-16GD GV-R675XTGAMING-12GD GV-R665XTGAMING-8GD
EAGLE N/A N/A GV-R665XTEAGLE OC-8GD
N/A N/A GV-R665XTEAGLE-8GD

AMD Radeon RX 6000 XT RDNA 2 Graphics Card Refresh

The AMD Navi 21, Navi 22, & Navi 33 GPUs are the ones that will be refreshed for the upcoming Radeon RX 6X50 XT lineup. The AMD Navi 21 GPU currently powers the Radeon RX 6900 XT, RX 6800 XT & RX 6800 while the Navi 22 GPU powers the RX 6700 XT and the Navi 23 GPU powers the RX 6600 XT & 6600 on the desktop platform. The graphics cards will be featuring 18 Gbps memory along with certain clock enhancements.

  • h0bade777c8a740518929f7ac41ebd71d4
  • hadf48c760eef4ae5a7883d271ea396bbb
  • hd3944b1a44f24a1fbd103b095a20e5dbz

From the previous rumor, we came to know that these cards would also feature 18 Gbps GDDR6 memory dies. Currently, all cards except the upcoming RX 6500 XT & the flagship RX 6900 XT LC, feature 16 Gbps memory dies. The bump to 18 Gbps might offer higher bandwidth and increase performance by 2-5% but that doesn't indicate a huge difference with the refreshed series. There are obviously going to be some process enhancements incorporated in the new RDNA 2 refresh GPUs since we've heard rumors of the RX 6950 XT clocking over 2.5 GHz.

AMD's Radeon RX 6950 XT, RX 6750 XT, RX 6650 XT Launching on 20th April, Expected To Get Midnight Black Reference Variants 2

It would've been worthwhile if AMD gave its existing desktop GPUs the 6nm treatment & managed to get more performance efficiency out of them but that clearly isn't happening. It looks like this soft refresh will feature both reference 'midnight black' and custom model designs.

There would also be a small price difference and the TGP numbers are expected to go up slightly with the addition of the faster memory chips. These GPUs will likely compete with Intel's high-end ARC Alchemist GPUs that are launching in a few months while the Radeon RX 6950 XT flagship is clearly aimed at NVIDIA's RTX 3090 Ti graphics card which is one power-hungry insanity.

The following table shows all the RDNA 2 graphics cards that AMD is currently offering:

AMD Radeon RX 6000 'RDNA 2' Desktop Graphics Card Lineup:

Graphics Card Name GPU Codename Process Node Compute Units / Cores Memory Capacity / Bus Memory Clock TGP Price (MSRP) Launch
Radeon RX 6950 XT Navi 21 XTXH? 7nm 80 / 5120 16 GB / 256-bit 18 Gbps 300W? $999 US? April 2022
Radeon RX 6900 XT LC Navi 21 XTXH 7nm 80 / 5120 16 GB / 256-bit 18 Gbps 330W $1199 US July 2021
Radeon RX 6900 XTX Navi 21 XTXH 7nm 80 / 5120 16 GB / 256-bit 16 Gbps 300W $999 US October 2020
Radeon RX 6900 XT Navi 21 XTX 7nm 80 / 5120 16 GB / 256-bit 16 Gbps 300W $999 US October 2020
Radeon RX 6800 XT Navi 21 XT 7nm 72 / 4608 16 GB / 256-bit 16 Gbps 300W $649 US October 2020
Radeon RX 6800 Navi 21 XL 7nm 60 / 3840 16 GB / 256-bit 16 Gbps 250W $579 US October 2020
Radeon RX 6750 XT Navi 22 XT? 7nm 40 / 2560 12 GB / 192-bit 18 Gbps 230W? $479 US? April 2022
Radeon RX 6700 XT Navi 22 XT 7nm 40 / 2560 12 GB / 192-bit 16 Gbps 230W $479 US March 2021
Radeon RX 6650 XT Navi 23 XT? 7nm 32 / 2048 8 GB / 128-bit 18 Gbps 160W? $379 US? April 2022
Radeon RX 6600 XT Navi 23 XT 7nm 32 / 2048 8 GB / 128-bit 16 Gbps 160W $379 US July 2021
Radeon RX 6600 Navi 23 XL 7nm 28 / 1792 8 GB / 128-bit 14 Gbps 132W $329 US October 2021
Radeon RX 6500 XT Navi 24 XT 6nm 16 / 1024 4 GB / 64-bit 16 Gbps 107W $199 US January 2022
Radeon RX 6500 Navi 24 XL 6nm 12 / 768? 4 GB / 64-bit 16 Gbps? TBD $149 US? April 2022
Radeon RX 6400 Navi 24 XL 6nm 12 / 768 4 GB / 64-bit 16 Gbps 53W $139 US? January 2022
Are you looking forward to the RDNA 2 Refreshed graphics cards from AMD?
  • Yes
  • No
Poll Options are limited because JavaScript is disabled in your browser.

The post AMD Radeon RX 6950 XT Custom Models Are Just As Expensive As NVIDIA’s RTX 3090 Ti In Early Listings, Priced at $2400 US by Hassan Mujtaba appeared first on Wccftech.

13 Apr 20:14

Dismantling ZLoader: How malicious ads led to disabled security tools and ransomware

by Paul Oliveria

As announced today, Microsoft took action against the ZLoader trojan by working with telecommunications providers around the world to disrupt key ZLoader infrastructure. We used our research into this threat to enrich our protection technologies and ensure this infrastructure could no longer be leveraged by operators to distribute the trojan or activate deployed payloads like ransomware. Moreover, we are sharing this intelligence to emphasize the importance of collaboration throughout the larger security community. Below, we will detail the various aspects for identifying a ZLoader campaign.

Derived from the Zeus banking trojan first discovered in 2007, ZLoader is a malware family notable for its ability to evolve and change from campaign to campaign, having undergone much development since its inception. ZLoader has remained relevant as attackers’ tool of choice by including defense evasion capabilities, like disabling security and antivirus tools, and selling access-as-a-service to other affiliate groups, such as ransomware operators. Its capabilities include capturing screenshots, collecting cookies, stealing credentials and banking data, performing reconnaissance, launching persistence mechanisms, misusing legitimate security tools, and providing remote access to attackers.

ZLoader campaign operators evolved the malware from a basic banking trojan to a more sophisticated piece of malware capable of monetizing compromised devices by selling access to other affiliate groups. By leveraging and misusing legitimate tools like Cobalt Strike and Splashtop, affiliates gain hands-on-keyboard access to affected devices, which can be further misused for other malicious activities like credential theft or downloading additional payloads, including ransomware. ZLoader has previously been linked to ransomware infections such as Ryuk, DarkSide, and BlackMatter.

ZLoader attacks have affected nations around the world, with the majority targeting the US, China, western Europe, and Japan. Due to the modular nature of some of ZLoader’s capabilities and its constant shifts in techniques, different ZLoader campaigns may look nothing alike. Previous campaigns have been fairly simple, with the malware delivered via malicious Office macros attached to emails and then used to deploy modules for capabilities. Other, more recent campaigns are notably complex–injecting malicious code into legitimate processes, disabling antivirus solutions, and ultimately culminating in ransomware.

World map with circles of varying sizes located in several countries regions to indicate the threat's impact.
Figure 1. Heat map of nations affected by ZLoader attacks

ZLoader operators have also updated their methodology to frequently deliver the malware through targeted malicious Google Ads. The use of ad fraud is a stealthy way to target end users as it bypasses typical security solutions that can be found in email and surfaces itself in normal browser activities instead.

Microsoft Defender for Endpoint detects malicious behaviors related to this campaign. Enabling cloud protection and automatic sample submission for Microsoft Defender Antivirus aids users and organizations in remaining protected on new and emerging threats. Moreover, standardizing the use of the Microsoft Edge browser across all corporate devices and enabling Microsoft Defender SmartScreen protection blocks malicious sites, such as those connected to ZLoader campaigns. 

In this blog post, we characterize the various methods by which a ZLoader campaign might be identified, along with detailing detection and mitigation information that can help users reduce the impact of this threat.

ZLoader attack chains

ZLoader is a malware variant that has evolved over the years and is used for multiple objectives, meaning that two campaigns which both use ZLoader may appear completely different. For example, an individual who has experience responding to a ZLoader campaign that originated from email and dropped the payload via a malicious Office macro, may be shocked at the complexity of a second ZLoader campaign that uses numerous malicious files for reconnaissance and antivirus tampering, before finally dropping the actual malware payload.

The following diagram identifies the most common ways the ZLoader trojan has been observed moving through the delivery, installation, payload, malware activity, and follow-on activity phases of an attack. This diagram is high-level and may not depict every step or file dropped in some of ZLoader’s more complex campaigns.

Diagram comprising of arrows and icons illustrating the flow of a ZLoader attack in the following stages: delivery, installation, payload, malware activity, and follow-on activities.
Figure 2. ZLoader attack flow diagram

Delivery

ZLoader malware has been observed being delivered in multiple ways. Two of the most prominent methods include malicious search engine ads and malicious emails.

Malicious advertisement delivery

In more recent campaigns, ZLoader has shifted away from using email as a means of delivery and instead used malicious ads on search engines such as Google to trick users into visiting malicious sites.

Each wave of these campaigns impersonated a specific company or product, such as Java, Zoom, TeamViewer, and Discord. For the delivery stage of the attack, the actors would purchase Google Ads for key terms associated with those products, such as “zoom videoconference.” Users who performed Google searches for those terms during a specific time would be presented with an advertisement that led to the form grabbing malicious domains.

In each instance of this campaign, the actors would compromise legitimate domains that appeared to be owned by individuals or small businesses, such as personal blogs. They would then set up subdomains on them that were associated with the product they were impersonating during that time. The product-specific subdomain was the second subdomain on the domain, while the first subdomain was an extremely long set of words. For example:

  • zoomdownload[.]linkforbusinessandpersonalusersofourserviceinseptember[.]jumpingonwater[.]com
  • zoomonline[.]forusersinourservicewithbusinessandpersonalcustomers[.]fineanddandiwithrandi[.]com
  • zoomdownload[.]onlinestartserviceforyourworkstudymeeting[.]indyflat-tax[.]com
  • zoomdownloadlink[.]zoomdownload[.]onlinesoftwareforpersonalandbusinessusersinseptember[.]lifeintrainingpodcast[.]com
  • teamviewerdownload[.]fastserviceworkonlinelinkjoininaugustseptermber[.]greenlinefood[.]net
  • teamviewerdownload[.]directserviceforonlinepersonalandbusinessusersofourservice[.]wahatalrabeeh[.]co
  • teamviewerstart[.]linkforpersonalandbusinessusersinourservicestartnow[.]ellisclinic[.]com

In at least one instance of this activity, the compromised webpage was set up to appear as though it was associated with the company Get VoIP, a legitimate service that provides comparisons between various VoIP providers. The attackers did not compromise the GetVoIP website or service, rather, they designed the webpage to impersonate the real GetVoIP site.

Screenshot of a spoofed website landing page.
Figure 3. The compromised domain designed to look like the GetVoIP website

From these compromised domains, the users will attempt to download the product being impersonated, which redirects them to an attacker-owned domain. These domains also pretend to be associated with the legitimate product being impersonated, and frequently use the .site TLD.

One example of the chain of redirected domains associated with this activity is:

  1. https://adservice.google[.]com, redirects to:
  2. zoomdownload.linkforbusinessandpersonalusersofourserviceinseptember.jumpingonwater[.]com, redirects to:
  3. zoomvideo[.]site

The ZLoader operators have tended to use REG.RU, LLC as the registrar for these final .site domains. Additionally, many of the domains used within a single campaign have the registrant contact email in common with each other, making it easy to pivot and find other potentially related domains.

The final website in this chain downloads the initial malicious .msi file.

Email delivery

As with many other malware variants, prior ZLoader campaigns have also been known to use malicious emails to deliver Office documents containing malicious macros that download the payload. The ZLoader operators do not have a preferred method of delivering these Office documents and have been observed using both links and attachments in various campaigns. Some observed means by which a ZLoader email was associated with a malicious document include:

  • Attached macro-enabled Microsoft Office document 
  • Attached Excel 4.0 document that contained Hidden Sheets and Very Hidden Sheets to host macros 
  • Attached PDF with link to a macro-enabled Office document 
  • Attached ZIP file that contained a macro-enabled Office document or executable
  • Link to a Google Docs page with links to a macro-enabled Office document

The emails have used a variety of lures, which typically convey a sense of urgency. Some of the campaigns used lures based on currents events at the time of the campaign, such COVID-19, or generic lures, such as overdue invoice payments and fake resumes or CVs. Additionally, most of these emails have been sent from consumer email services—notably AOL.com. There have also been campaigns that used domains that are associated with the lure theme; for example, some emails were sent from a COVID-themed sender domain.

Screenshot of an invoice-themed email message with an XLS file attachment.
Figure 4. A screenshot of a sample email associated with the ZLoader campaign posing as a request for an overdue invoice.

Regardless of how the operator chooses to deliver the Office document, once the user opens it, they are prompted to enable macros to view the content. In various known cases, the malicious macros either directly started to download subsequent payloads or they dropped a VBS file that in turn performed the download.

In general, a connection was made to a compromised WordPress instance hosting the PHP code used by the ZLoader kit. At this stage, the ZLoader payload was downloaded as a DLL masquerading as an HTML file that is then launched using rundll32.exe.  

Installation

Less complex ZLoader campaigns go straight from the delivery phase to dropping the malicious payload. In more complex ZLoader campaigns, the next phase of the attack shifts to using a legitimate process such as msiexec.exe to download several additional files, including many non-malicious .dll files that are legitimate pieces of whatever software is being impersonated at the time. A malicious .bat file is hidden in those .dll files.

In several instances, these files were added to a folder pretending to be associated with legitimate software, such as Oracle Java or Brave Browser, using the following pattern as an example: C:\Program Files (x86)\Sun Technology Network\Oracle Java SE\[malicious file].

The .bat file launches PowerShell to reach out to a download domain to drop the ZLoader payload. Examples of these domains include:

  • quickbooks[.]pw
  • sweepcakesoffers[.]com
  • Datalystoy[.]com
  • Teamworks455[.]com
  • Clouds222[.]com

In some campaigns, the attackers used a script to run various discovery commands prior to downloading the ZLoader payload, including:

  • ipconfig /all
  • net config workstation
  • net view /all
  • net view /all /domain
  • nltest /domain_trusts
  • nltest /domain_trusts /all_trusts

Payload

Once the ZLoader payload is on the device, it may drop various modules that provide it with additional functionality, such as: 

  • Capturing screenshots 
  • Collecting cookies 
  • Stealing banking passwords 
  • Providing VNC access to attackers 

Operators can choose which of these modules to deliver based on how the malware is configured. In most campaigns, the module files are dropped in subfolders in the AppData folder. Although operators are free to give the subfolders and files arbitrary names, the names Microsoft researchers have actually observed exhibit two patterns:

  • Sets of characters that appear random 
  • Concatenated dictionary words 

In several campaigns, attackers opted not to use these modules and instead used the payload to download an additional malicious file. This file was launched and then called back out to the same download domain that the ZLoader payload was downloaded from, to download a PowerShell script. The downloaded script checked if the device was workgroup- or domain-connected. The PowerShell script then reached out to the command and control (C2) domain and downloaded two malicious files—typically an .exe and a .dll. The script used regsvr32.exe to launch the DLL and run a command to time out for 200 seconds. After this, cmd.exe was used to launch an additional malicious file, which downloads a VBS file that is loaded by wscript.

Screenshot of a script
Figure 5. Script used for workgroup-joined devices
Screenshot of a script
Figure 6. Script used for domain-joined devices

These files were used to tamper with security solutions and to grant attackers hands-on-keyboard access.

Browser credential theft

One of the main functionalities of ZLoader malware is to steal online credentials targeting banks and financial institutions, as well as other credentials, via client-side web injection and form grabbing attacks. Web injection allows the attacker to alter content of the websites displayed to the victim, while form grabbing captures credentials from the browser windows. To accomplish those actions, the malware implements an Adversary-in-the-browser (AiTB) attack. 

ZLoader’s main process, msiexec.exe, spawns several threads running at the same time to perform different tasks. Each of these threads communicate with one another using shared data stored in the global memory, system registry, and encrypted files. Threads are spawned that execute functions to install a fake certificate and run a local proxy, while another thread is injected and executed inside the loaded browser process, which is responsible for redirecting traffic via proxy.

A thread runs to traverse the list of running processes and inject codes to target browser processes discovered. ZLoader targets the following browser processes:

  • iexplore.exe
  • firefox.exe
  • chrome.exe
  • msedge.exe (Microsoft Edge)

The hook API TranslateMessage is the key malware functionality that performs the form grabbing, keylogging, and screenshotting of users’ desktops. 

For the target browser processes, the following APIs are hooked for tracking, redirecting network activities, and controlling the certificate verification. The ZwDeviceIoControlFile hooks allow HTTP/HTTPs responses containing web pages codes from the target to be redirected to the proxy server to be modified. Moreover, any certificate will be tagged as valid. 

  • ntdll.dll – ZwDeviceIoControlFile
  • crypt32.dll – CertGetCertificateChain, CertVerifyCertificateChainPolicy

Another thread is responsible for checking instructions and configurations from the C2 servers every 10 minutes. Included in the configuration are the list of target banks, financial institutions, and online companies, and the instruction on how to perform the web injection.

One of ZLoader’s targets is the Microsoft online sign-in page at https://login.microsoftonline[.]com. Several of Microsoft’s main websites, such as office[.]com, redirect users to this Microsoft online page when they try to sign into their Microsoft account. When users load their favorite web browser, such as Microsoft Edge, then visit and try to sign into their Microsoft account, ZLoader will match the URL to the list of targets. In this case it will match to the first one above and perform the web injection by inserting malicious JavaScript codes after the string “</head>” and then rendering to the browser application.

Partial screenshot of a web page with a Microsoft sign-in screen. A red circle in the address bar highlights the URL.
Figure 7. A screenshot of the fake Microsoft sign-in screen

The codes injected will insert fake web controls and/or additional JavaScript codes that are responsible for capturing the credentials such as usernames, passwords, and others. This captured information is encrypted and sent to the main bot and then to the C2 server. With these stolen credentials, the ZLoader operators can potentially gain access to users’ Microsoft online account to perform further illicit activities. As the malicious activities occurred in the background, even “tech savvy” users may not be aware that their browser was tampered with, and credentials were stolen.

Defense evasion

ZLoader has used various methods of defense evasion, focused on attempting to appear more legitimate or by disabling security tools. In multiple campaigns associated with malicious ads, the ZLoader operators would sign malicious files used in their attack chain. Signing these files is intended to make them appear to be legitimate, non-malicious files used by real software, rather than malicious files used by malware.

The first method ZLoader has used to sign files is by creating fictitious companies. In certain campaigns, the .msi files that are installed on the device after the user visits a malicious ad are signed by a fictitious company created by the operator for the purpose of the campaign. The malware operators created multiple fraudulent companies, such as Flyintellect Inc, and Datalyst Oy, in several campaigns. Due to the way .msi files are designed, the registry keys that are added by this activity later in the attack chain are also published by the same company name.

Another method operators have used to evade detection is a set of techniques that utilize validly-signed files to hide malicious scripts through vulnerabilities like CVE-2020-1599, CVE-2013-3900, and CVE-2012-0151.

ZLoader operators have also attempted to perform defense evasion by disabling security tools. In many instances, ZLoader will drop a file, frequently a .bat file, that then uses PowerShell to turn off and alter security settings, such as excluding all .dll and .exe files and regsvr32.exe from being scanned.

Screenshot of PowerShell commands.
Figure 8. Some examples of PowerShell commands run during this phase of the attack

Persistence

ZLoader has used various persistence methods across separate campaigns. The first method observed by Microsoft Security Researchers involves the ZLoader DLL using rundll32.exe to register itself. In other documented cases, it also creates the following persistence mechanisms for itself or its modules: 

  • Registry entries under HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run 
  • Files in the Startup folder 

In more recent campaigns, the attackers maliciously used Atera, a legitimate remote monitoring software. While Atera was not compromised, attackers leveraged its built-in Splashtop Remote Access capabilities to achieve persistence on the compromised device.

Objectives

After establishing persistence, the campaign operators behind ZLoader infections monetize their access to domain-joined devices by selling access-as-a-service to other groups, including ransomware affiliates. These groups can then use this access for their own goals, including installations of Cobalt Strike, which enables hands-on keyboard activities by the actors.

In one instance, the VBS downloaded a batch script which connected to a Cobalt Strike C2 via a DLL beacon dropped on the device by PowerShell. It was launched via rundll32.exe, with the known Cobalt Strike flag StartW. Reconnaissance queries were then run on domain-joined devices, performing actions such as searching for all domain trusts on the network.

With the use of Cobalt Strike and Splashtop, attackers have hands-on-keyboard access to affected devices that can be leveraged for subsequent objectives, including credential theft or deployment of additional payloads such as ransomware.

In the past, ZLoader has been tied to ransomware infections such as Ryuk. We’ve also seen ZLoader operators provide access to ELBRUS actors who deployed DarkSide ransomware (earlier in 2021). Those that were more recently observed had been deploying BlackMatter ransomware. Given such history, the Cobalt Strike payloads might indicate pre-ransomware activities that prefigure a real threat of ransomware attacks.

Defending against ZLoader attacks

The take down effort against ZLoader is just one of the ways in which Microsoft provides real-world protection against threats. This action will result in protection for a wide range of organizations around the world from malware, affiliates with hands-on-keyboard access, and additional payloads delivered via ZLoader’s infrastructure.

Like many modern malware variants, getting ZLoader onto a device is oftentimes just the first step in what ends up being a larger attack. The trojan further exemplifies the trend of common malware increasingly harboring more dangerous threats, a pattern also observed in other platforms. ZLoader operators frequently monetize access from infections by selling it to other affiliate groups, who then use the purchased access to carry out their own malicious objectives. Affiliates may further misuse legitimate tools like Cobalt Strike or Splashtop to gain full hands-on-keyboard access to target devices, enabling attackers to perform additional discovery, find high-value targets on the network, move laterally, and drop additional payloads, such as ransomware variants.

The best advice for preventing ZLoader infections is to simply avoid downloading attachments contained in emails from unknown senders as well as clicking on sponsored ads and links in search engine results, instead opting for unsponsored results from verified, trusted sources. Good credential hygiene, network segmentation, and similar best practices increase the “cost” to attackers, helping disrupt their activities before they reach their target.

Defenders can take the following mitigation steps to defend against this threat:

  • Encourage users to use Microsoft Edge and other web browsers that support Microsoft Defender SmartScreen, which identifies and blocks malicious websites, including phishing sites, scam sites, and sites that contain exploits and host malware. SmartScreen removes the reputation information for the certificates leveraged during these attacks. Binaries signed with those certificates will trigger a warning about an “unrecognized app.”
  • Use Windows Defender Application Control, AppLocker, or other application control technologies to prevent end users from running unapproved software on their computers.
  • Run the latest version of your operating systems and applications. Deploy the latest security updates as soon as they become available.
  • Use only official, trustworthy websites and direct download links.

ZLoader’s prevalence in the threat landscape demands comprehensive protection capable of detecting and stopping this malware, its components, and other similar threats at every stage of the attack chain. Microsoft Defender for Endpoint provides next-generation protection that reinforces network security perimeters and incorporates antimalware capabilities to catch emerging threats, including ZLoader, Cobalt Strike, additional payloads such as ransomware, and subsequent attacker behaviors. Moreover, our endpoint detection and response (EDR) capabilities detect ZLoader’s malicious files, behaviors, domain connections, and other related events before and after execution.

Defenders can further apply the following mitigations to reduce the environmental attack surface and mitigate the impact of this threat and its payloads:

  • Configure Microsoft Defender for Office 365 to recheck links on click. Safe Links provides URL scanning and rewriting of inbound email messages in mail flow, and time-of-click verification of URLs and links in email messages and other locations. Safe Links scanning occurs in addition to the regular anti-spam and anti-malware protection in inbound email messages in Exchange Online Protection (EOP). Safe Links scanning can help protect your organization from malicious links that are used in phishing and other attacks.
  • Configure Microsoft Defender for Office 365 to detonate file attachments via Safe Attachments. Safe Attachments provides an additional layer of protection for email attachments by verifying a file in a virtual environment prior to delivering to the inbox.
  • Check your Office 365 antispam policy and your mail flow rules for allowed senders, domains and IP addresses. Apply extra caution when using these settings to bypass antispam filters, even if the allowed sender addresses are associated with trusted organizations—Office 365 will honor these settings and can let potentially harmful messages pass through. Review system overrides in threat explorer to determine why attack messages have reached recipient mailboxes.
  • Configure Exchange Online to enable zero-hour auto purge (ZAP) in response to newly acquired threat intelligence. ZAP retroactively detects and neutralizes malicious phishing, spam, or malware messages that have already been delivered to mailboxes.
  • Turn on network protection to block connections to malicious domains and IP addresses.
  • Turn on tamper protection features to prevent attackers from stopping security services.
  • Turn on cloud-delivered protection and automatic sample submission on Microsoft Defender Antivirus. These capabilities use artificial intelligence and machine learning to quickly identify and stop new and unknown threats.
  • Turn on the following attack surface reduction rules to block or audit activity associated with this threat:
    • Block executable files from running unless they meet a prevalence, age, or trusted list criterion
    • Block all Office applications from creating child processes
    • Block Office applications from creating executable content
    • Block executable content from email client and webmail
    • Block Office applications from injecting code into other processes
    • Block credential stealing from the Windows local security authority subsystem (lsass.exe)
    • Block process creations originating from PsExec and WMI commands
    • Use advanced protection against ransomware
    • Block JavaScript or VBScript from launching downloaded executable content
    • Block execution of potentially obfuscated scripts

Appendix

Microsoft 365 Defender detections

Microsoft Defender Antivirus

Microsoft Defender Antivirus detects threat components as the following malware:

Shared malware and generic detections

Microsoft Defender Antivirus incorporates next-generation antivirus capabilities, including machine learning and behavioral detection. This can result in overlapping detections, particularly of first-seen components and polymorphic variants. The detection names are listed here for reference, but related alerts are not actively monitored.

Instances of Cobalt Strike use can be detected as the following:

  • Bynoco – Cobalt Strike
  • Atosev – Cobalt Strike
  • Cosipor – Cobalt Strike

Microsoft Defender for Endpoint EDR

Alerts with the following titles in the security center can indicate threat activity on your network:

  • Suspicious behavior associated with ZLoader
  • File associated with ZLoader
  • Connection to a domain associated with ZLoader

The following alerts might also indicate activity associated with this threat. However, unrelated threat activity can trigger these alerts.

  • Microsoft Defender Antivirus protection turned off
  • Suspicious Microsoft Defender Antivirus exclusion
  • ZLoader’ malware was detected
  • Suspicious behavior by cmd.exe was observed
  • Suspicious PowerShell command line
  • Suspicious Remote System Discovery
  • Suspicious Domain Trust Discovery

Microsoft Defender for Office 365

Signals from Microsoft Defender for Office 365 inform Microsoft 365 Defender, which correlates cross-domain threat intelligence to deliver coordinated defense, that ZLoader has been detected when a document is delivered via email when detonation is enabled. These alerts, however, can also be triggered by unrelated threat activity.

  • A potentially malicious URL click was detected
  • Email messages containing malicious file removed after delivery​
  • Email messages containing malicious URL removed after delivery​
  • Email messages containing malware removed after delivery
  • Email messages removed after delivery​
  • Malware campaign detected after delivery
  • Malware campaign detected and blocked
  • Malware not zapped because ZAP is disabled

Hunting queries

Microsoft 365 Defender

To locate possible exploitation activity, run the following queries:

ZLoader alert activity

Surface devices with ZLoader alerts and related malicious activity.

// Get any devices with ZLoader related Alert Activity
let DeviceAlerts = AlertInfo
| where Title in~('Suspicious behavior associated with ZLoader',
'File associated with ZLoader',
'Connection to a domain associated with ZLoader')
// Join in evidence information
| join AlertEvidence on AlertId
| where DeviceId != ""
| summarize by DeviceId, Title;
// Get additional alert activity for each device
AlertEvidence
| where DeviceId in(DeviceAlerts)
// Add additional info
| join kind=leftouter AlertInfo on AlertId
| summarize DeviceAlerts = make_set(Title), AlertIDs = make_set(AlertId) by DeviceId, bin(Timestamp, 1d)

MSHTA-loading DLLs

Look for instances of MSHTA loading suspicious DLL files.

DeviceProcessEvents
| where not(FileName has_any("certutil", "certutil32")) and FileName endswith ".exe" and ProcessVersionInfoFileDescription =~ "certutil.exe"
| where not(FolderPath has_any("installer", "program files"))

Suspicious registry keys

Look for registry keys created by the fraudulent, attacker-created companies used in this campaign.

DeviceRegistryEvents
| where RegistryValueData in('Flyintellect Inc.', 'Datalyst ou')

Malicious .bat file created in fake Oracle Java SE folder path

Look for .bat files created in the Oracle Java SE file path associated with this activity.

DeviceFileEvents
| where FileName endswith '.bat'
    and FolderPath has @'Program Files (x86)\Sun Technology Network\Oracle Java SE'

Tim.exe payload delivery

Look for the Tim.exe payload being downloaded onto an affected device.

DeviceNetworkEvents
| where InitiatingProcessFileName =~ 'powershell.exe'
    and InitiatingProcessCommandLine has('Invoke-WebRequest') and InitiatingProcessCommandLine endswith '-OutFile tim.EXE'

The post Dismantling ZLoader: How malicious ads led to disabled security tools and ransomware appeared first on Microsoft Security Blog.

13 Apr 20:09

These Things Are Bringing Down the Value of Your Home

by Sarah Showfety

If you’re a homeowner, you’ve no doubt checked out your home’s estimated value on Zillow a time or two (or sixty). And while that dollar amount can paint a general picture of your home’s worth based on its square footage, number of bedrooms, tax records, and recent homes sales in your area, it can’t account for the…

Read more...

13 Apr 19:48

Marlon Brando's Demands On Island Of Dr Moreau Sent Production Spiraling Out Of Control

by Lee Adams

Despite its reputation as one of the most notorious flops of the '90s, "The Island of Dr. Moreau" almost passes as a watchable movie. It's nicely shot, the makeup effects are terrific, and on a surface level, it appears to be a standard Hollywood sci-fi horror. But then, right from the opening scene, something seems very off. 

The first clue is the voice over from David Thewlis, parachuted in at the last moment to play the lead. With his flat Lancashire accent jibing badly against the glossy photography, it feels like a skit parodying Hollywood voice overs. That's just for fun, because as the film unfolds, that bad feeling radiates off the screen. Everyone in the principal cast, with the possible exception of Marlon Brando, looks like they're hating every second of it, and the tension is palpable.

It's difficult to enjoy "Moreau" in a "so-bad-it's-good" sense, because while it is competently made at times, the atmosphere is rank. It made me feel like when I accidentally walked in on my parents fighting as a kid. No wonder it stank out theaters and made its original director, Richard Stanley, vanish for 25 years.

The troubled shoot, so wonderfully detailed in the documentary "Lost Soul: The Doomed Journey of Richard Stanley's The Island of Dr. Moreau," is legendary — an ill-starred collision of three eccentric talents at very different stages in their careers. The first was Stanley, a young director of "esoteric witchiness" (according to the doc) who was nevertheless regarded as the next big thing after his first two low-budget cult items, "Hardware" and "Dust Devil." Then came Val Kilmer at the peak of his career after "Batman Forever," and screen legend Marlon Brando, reputed for his often difficult and disruptive behavior on set. It was a potent mix that turned out to be a recipe for disaster.

So What Happens In The Island Of Dr. Moreau Again?

After his plane crashes in the Java Sea, U.N. negotiator Edward Douglas (Thewlis) is rescued by a passing ship, where he receives medical attention from Dr. Montgomery (Kilmer). Montgomery is heading home to the mysterious Moreau island, where he persuades Douglas to also disembark.

Put up as a guest in the main house in Moreau's compound, Douglas is warned not to go wandering about and locked in his room at night. This only spurs Douglas to break out and have a nose around. He enters a lab and is horrified to see a strange creature giving birth to a child, delivered by bestial human hybrids. Hey, at least they look like they scrubbed up.

The creatures spot him and he does a runner, crashing through the jungle and bumping into Aissa, Dr. Moreau's daughter (Fairuza Balk). She takes him to a Mutant Village, where the Sayer of the Law (Ron Perlman) preaches human-like qualities such as restraint and discipline. Moreau rolls up and uses a remote control to pacify the hybrids with radio controlled implants under their skin. Douglas is still frightened but Moreau manages to calm him down with a mad scientist exposition speech.

A partially eaten rabbit is discovered, outraging the other creatures as eating another's flesh is forbidden. The blame falls on Lo-Mai, a leopard hybrid, who is shot dead at the following day's trial in retribution. His corpse is cremated and his implant is revealed to the other creatures, who are in no mood to take Moreau's orders any longer.

Richard Stanley was fascinated with the source novel from H.G. Wells since his childhood, and he began writing his own screen version after the success of "Dust Devil." After four years in development, he got the green light on his dream project. Despite Stanley's evident talent, it was a massive step up from low-budget indie features to a big Hollywood production with major stars. If only he could get the right people onboard...

Marlon Brando And A Warlock's Intervention

Although Stanley wrote the part of Dr. Moreau with Jurgen Prochnow in mind, one of the first people approached for the role was Marlon Brando. The actor quickly accepted, still fascinated by the character of Colonel Kurtz he played in "Apocalypse Now" and intrigued by the parallels between Kurtz and Dr. Moreau.

Back in the 19th century, H.G. Wells was incensed when his friend Joseph Conrad published "Heart of Darkness," feeling that he ripped off his enigmatic main character. Conrad defended his book, claiming that Kurtz was based on British explorer Henry Morton Stanley, who was Richard Stanley's great grandfather.

New Line offered the film to Roman Polanski instead. Stanley was furious, demanding to speak with Brando and delving into the dark arts (according to "Lost Soul"):

"Knowing that the odds were stacked against me, I resorted to witchcraft. At that point in time, I was friendly with this warlock chappie in England, Dr. Edward James Featherstone, commonly known as Skip. So Skip had been shown to demonstrate his ability to fix things, to do invisible mending before, so I said, "My God, Skip, you've got to help me! You've got to save my movie!" At the exact time I went into the meeting [with Brando] on the other side of the world, Skip convened his coven, cut his arm, and drew a sigil..."

Whether Skip's magic worked or it was simply that Brando, himself an unusual character, unexpectedly connected with Stanley over the subject at hand, we will never know. But suddenly Polanski was out again and Stanley back in, with Brando refusing to make the movie without him.

It must have seemed like a blessing at the time for the younger director, although he undoubtedly knew that working with Brando presented its own unique challenges. As it turned out, Stanley never even got to direct him in a scene.

The Cast Comes Together, But Disaster Strikes

With Brando good to go, it was time to find a big box office star for the lead role of Edward Douglas. Bruce Willis initially signed on, with James Woods coming in for the Montgomery part. Then came the first in a long series of misfortunes: Willis entered divorce proceedings with Demi Moore and couldn't leave the country, so he was out.

Val Kilmer took his place, but when Stanley flew to Tokyo to finalize the details, the actor decided he was too busy in the wake of "Batman Forever" to play the part and demanded 40% less shooting time on the film. Fearful that the studio might pull the plug if he also lost Kilmer, Stanley devised a work around. Kilmer would take the smaller role of Montgomery instead, meaning Woods was also out. Rob Morrow, then hot from a role on "Quiz Show," replaced Kilmer in the Douglas part. 

In pre-production, a remote location in Queensland, Australia was chosen to represent Moreau's island and Stan Winston's effects team busied themselves live-casting extras for the animal hybrids, including Nelson de la Rosa, one of the smallest men on earth and a huge star in his native Dominican Republic.

Then it all started falling apart. Brando's daughter, Cheyenne, took her own life shortly before filming began, and it wasn't clear when the actor would arrive for the shoot, if at all. Stanley's PA was bitten by a poisonous spider and Skip the Warlock, whose day job was a bio-chemist, was accidentally irradiated by one of his experiments, causing his bones to crumble. According to Stanley, all the things Skip fixed with his magic came undone during his time in hospital, including Stanley's movie.

Stanley's mother's house in Ireland was struck by lightning and, when he started shooting around Brando's absence, a fierce hurricane blew in and washed away some of the sets. With the production put on hold and Thewlis replacing Morrow at the last second, Stanley was fired after just three days. All of this is covered in the "Lost Soul" documentary. 

Brando Finally Arrives

Richard Stanley's dismissal caused bad feeling on set, especially with Fairuza Balk, who was so upset that she threatened to quit and got someone to drive her to Sydney, around 2,400km from the movie's "base camp" in Cairns. Nobody looks like they are enjoying themselves in "Moreau," and she looks visibly unhappy in her scenes.

John Frankenheimer, an old-school director who was the polar opposite of Stanley, was brought in to salvage the picture. He had a reputation for managing big egos, but his brash ways immediately upset many of the cast and crew. Some suspected that making a monster movie wasn't really Frankenheimer's thing but, like everyone else, "Lost City" confirms that he wanted to work with Brando.

Brando was still a no-show, and nobody really knew where he was. Finally, a week after he was due on set, the enigmatic actor arrived and made an immediate impression. In his first scene, he imperiously arrives on the back of a truck, wrapped in white cloth and plastered in crudely applied makeup, wearing huge shades. Brando decided to do his own makeup, including dentures to give himself an overbite, and adopted a vague British accent for the role.

Brando's performance is so bizarre that it's very easy to make fun of it, but we should also give the guy a little benefit of the doubt since it was so soon after his daughter's tragic death. But if the production of "The Island of Dr. Moreau" was troubled before he arrived, things were about to get a whole lot weirder now he was on set.

Brando Starts Making Crazy Demands

Marlon Brando had a history of disruptive behavior, wild ideas, and outlandish demands throughout his career. He didn't bother reading the script, and instead he relied on his assistant to relay his lines to him via radio, reportedly causing confusion when he picked up the police wavelength and started repeating emergency calls (via Far Out). Brando and Kilmer took a disliking to each other and embarked on a battle of egos, each refusing to leave their trailer until the other did.

Already under time pressure and worried about further delays, the crew put up with Brando's demands just to get something on film. So when he wanted peacock feathers for his grand entrance, an assistant hurried out and plucked a few right off a live peacock's butt (via "Lost Soul"). When he decided he wanted an ice bucket hat to keep him cool, he got that too.

Brando also wanted to change the script, inventing his own plot points and deciding that he didn't want his character to die (via FX Guide). Later, he suggested to Frankenheimer that they shut down production for a few months so they could re-write the script, working in a twist revealing that Dr. Moreau was a dolphin all along.

Most disruptively, Brando became instantly smitten with de la Rosa, the diminutive extra originally cast in a minor background role. Brando wanted him as his sidekick in all his scenes, despite la Rosa's lack of English or acting experience. On top of that, he wanted his new pal dressed the same, which later provided inspiration for Mini-Me in the "Austin Powers" trilogy (via Entertainment Weekly).

Some suspected that Brando was acting strange just to mess with the director and his bosses, while Kilmer looks like he's on a sour-faced mission to try out-weirding the maestro. In a few scenes, Kilmer almost succeeds, although his quirks seem to come from a place of genuine spite. Meanwhile, Brando's ad-hoc contributions least brighten the film up, making it a singular mess — a work of inadvertent camp directed through gritted teeth by the veteran helmer Frankenheimer.

Aftermath, And A Glimpse Of What Might Have Been

Richard Stanley, with his interest in witchcraft, could surely be forgiven for thinking that malign forces were swirling around his doomed film, and his part of the "Moreau" story didn't end after he was fired. The studio paid his full fee to keep him quiet and instructed crew members to take him to the airport, but he never got on his flight out of Australia. Instead, he camped out in the forest near the production and got crew members to sneak him back on set disguised as a human-dog hybrid. He is visible in the background of some scenes (via "Lost Soul"). Stanley said:

"I had the privileged position of being able to see what was going on, but at the same time the rather nightmarish position of discovering that I was now one of the beast people... that I had completed a full arc from creative figure to a dog."

After the disaster of "Moreau," Brando continued his slide into irrelevance and still never made another good film before he passed away in 2004. Kilmer certainly kept himself busy, but he never again reached his previous level of fame, making mostly bad movies for the next 25 years with a few notable exceptions. Meanwhile, Stanley, who walked away from filmmaking after his dream project was taken away from him, made an unlikely comeback with "Color Out of Space," where he showed exactly what he could do adapting a classic piece of sci-fi horror literature with an eccentric actor (Nicolas Cage) in the lead role. 

H.P. Lovecraft, Richard Stanley, and Nicolas Cage were an inspired mix, with the latter giving one of his best performances of recent years. The film gave us a tantalizing indication of what Stanley might have achieved with H.G. Wells and Marlon Brando — if the studio just had the courage to stick with him.

Read this next: Sci-Fi Box Office Bombs That Deserve A Second Chance

The post Marlon Brando's Demands on Island of Dr Moreau Sent Production Spiraling Out of Control appeared first on /Film.

13 Apr 19:47

How The X-Files Created A Fan-Favorite Character Out Of Thin Air

by Christian Gainey

The Cigarette Smoking Man, or CSM, as loyal X-philes call him, first appeared in the pilot episode of "The X-Files," hanging out in the corner of an FBI office, casting a lingering, authoritative gaze over a young Agent Scully. Without a word, we all instinctively knew there was something up with that guy, and none of it was good.

William B. Davis is the Canadian actor behind the smoke of CSM. Originally, he was hired to do exactly what you see him do in the premiere episode, which is creep in a corner and make us ask questions that would never get an official answer. He was so good at this that the show's creator, Chris Carter, decided to make him more than a background mystery.

By the end of the series, CSM would evolve from a shady, silent figure in a smoke-filled corner to the main villain of the series.

A Background Mystery

Davis' first appearance on "The X-Files" shows him lingering in the background, which has led some to believe that he was originally cast as an extra, and quickly bumped up to a cast member after nailing the role. While this is a great story, it isn't true. From the first episode, CSM was always an official character in the world of the show, standing in as a silent reminder of the looming conspiracy Mulder and Scully constantly had to fight.

Frank Spotnitz, a co-executive producer on the show, spoke with The Palm Beach Post about how Davis silently brought CSM to life, explaining:

"The character [was] very simply written and William [was] called upon to carry a lot of the weight of the character. He is utterly convincing. Even before he had words, he had looks where you could see his mind processing what he was watching and you could see there was intelligence behind his eyes."

Through Davis' brilliant portrayal, we know that CSM's intelligence is dangerous. He's the kind of guy that knows things that would break the rest of us and he isn't above using his knowledge to do just that. The show's creators figured if this man could bring all that to the character without speaking, why not give him lines and see what he does with them? And, that's exactly what they did.

The Big Bad

CSM's voice is first heard in a season 1 episode titled "Tooms." A.D. Skinner asks him if he believes Mulder and Scully's latest case report about an immortal, liver-eating, contortionist serial killer, and he replies, "Of course I do." Not groundbreaking dialogue, but it was a huge moment for fans of the show, because the enigma of the ever-present smoking man now had a voice. Throughout the series, his lines grew much more interesting, and the character became downright chilling.

You might think the mystery surrounding this shadowy man would slowly dissipate when he finally begins to speak, but you're clearly not an "X-Files" fan if you believe that. Like the official explanations that are given for the weird events in the series, The Cigarette Smoking Man is full of disinformation and outright lies. And, If he ever told us the truth, there is no way we would ever believe it.

CSM used his newfound voice to make a lot of claims in the series, including he's Mulder's father, he impregnated Scully, and he assassinated JFK, but who really knows? The only thing you can be certain of in the world of "The X-Files" is that nothing is for certain, not even the morality of The Cigarette Smoking Man.

Davis told The Palm Beach Post he is certain "90 percent of the audience hates the character," but he thinks CSM doesn't deserve it. He believes there are noble intentions behind his sketchy actions, saying:

"He's protecting the public from information they would not be able to process successfully. He's trying to keep society from becoming chaotic."

David thinks of his character as a father figure, shielding humanity from harsh truths that would drive us mad. Like most "X-Files" fans, I will forever pitch my tent in the "Smoking Man is a bad guy" camp, but who am I to argue with the man who made me love to hate him?

Read this next: The 15 Best Horror TV Shows Of All Time

The post How The X-Files Created a Fan-Favorite Character Out of Thin Air appeared first on /Film.

13 Apr 16:31

No Man's Sky Outlaws update lets you be spacepirates

by Alice O'Connor

Hello Games today launched yet another huge free No Man's Sky update, raising the skull 'n' crossbones with the Outlaws update. It focuses on three main things: being a pirate and doing naughty things; reworking and prettifying spaceship combat; and recruiting and training a squadron of NPC pilots to fly alongside you. But oh, there's so much more. Get a glimpse in the new trailer, below.

Read more

13 Apr 10:54

AMD Ryzen 7 5800X3D gaming CPU shines in early reviews

by Samuel Willetts
AMD Ryzen 7 5800X3D gaming CPU shines in early reviews

AMD Ryzen 7 5800X3D reviews have hit the internet well before next week’s launch, giving us our first in-depth look at team red’s new Zen 3 chip boasting 3D V-Cache technology. Both TechPowerUp and XanxoGaming have put team red's potentially best gaming CPU through numerous gaming PC benchmarks, and it seems the chip can handily hold its own against the likes of Intel Core i9-12900KS.

Paired with an Nvidia GeForce RTX 3080, TechPowerUp found that the AMD Ryzen 7 5800X3D "reaches parity with Alder Lake" processors such as the Intel Core i9-12900KS in gaming performance. Unfortunately, team red's CPU seemed to fall behind in Cinebench R23 as well as other more production-oriented applications compared to its 12th Gen competition.

XanxoGaming's findings echo these sentiments, saying "most games will see ties comparing Ryzen 7 5800X3D versus 12900K" but it believes Intel could have an edge when using DDR5 gaming RAM. However, as XanxoGaming highlights, "DDR5 still has a high premium", so the new AMD chip could be the better value buy in the short-term, especially for those who already invested in the AM4 platform.

RELATED LINKS: Zen 4 CPUs - everything we know, RDNA 3 GPUs - everything we know, Best gaming CPU
13 Apr 10:53

5 Reasons Why Unraid Is the Ultimate Home NAS Solution

by Yusuf Limalia

Unraid is one of the operating systems used by some of the biggest names in the tech YouTube industry, such as MKBHD and LinusTechTips. But what makes it so unique?

13 Apr 08:00

Ghost of Tsushima Director’s Cut Update 2.18 Rolled Out; No Additional Updates Currently Planned

by Aernout van de Velde

Ghost of Tsushima Director’s Cut update 2.18

Sony and Sucker Punch Productions have rolled out Ghost of Tsushima Director's Cut Update 2.18, addressing some single-player issues and packing various improvements and changes to standalone Legends mode.

The latest patch for Sony's hit title updates the game to version 2.018 on PlayStation 5, and version 2.18 on PlayStation 4. In addition to item changes in the game's Legends multiplayer mode, the new update focuses on bug fixes and improvements. For Ghost of Tsushima's singleplayer mode, this new update addresses some dialogue and cutscene issues and increases the amount of held Silk inventory of the New Game + merchant.

As mentioned by Sucker Punch, the team currently isn't working on any additional patches for the game, but they will monitor player feedback.

"While we aren’t actively working on any additional patches at the moment, we will continue to monitor feedback on the community-run Gotlegends subreddit and messages sent to @SuckerPunchProd on Twitter for any high-priority bugs or issues that emerge", the developer writes. "We want to say a huge THANK YOU to the entire community for the incredible amount of support and feedback we’ve gotten since launch. When Legends launched in October 2020, we never expected to have such an active community more than a year and a half later, and we could not be more thankful to everyone who has been with us on this journey!"

You'll find the official release notes down below:

Ghost of Tsushima Director's Cut Update 2.18 Release Notes

Legends

  • Fixed a bug where a teammate’s health could momentarily dip below zero, counting as a “death” in Custom Mode and Raid Trials that occasionally prevented the Hidden Heart cosmetic from unlocking
  • Added a PS4 Save Import button to Legends standalone builds (Transfer PS4 console Save). Be sure to click “Yes” on the Legends import prompt
  • Shared Wounds no longer breaks Assassin out of the Vanish skill
  • Added a new Fill Party goal, Custom Mode - Perfect Completion. This will allow people looking to earn the Hidden Heart cosmetic to search for matches separately from those looking for a different Custom Mode experience
  • Item adjustments:
    • All Legendary Katanas gain Stance Master perks by default, including on stances unlocked via perks. If you already have a Stance Master perk unlocked, it will be free to reroll to a new perk
    • Legendary Charms can now roll perks and properties previously limited to class exclusive charms, if the Legendary Charm is bound to the specified class.
    • Significantly lowered resolve gains of Black Powder Bombs
    • Skipping Stone Bow no longer generates extra resolve from the ricochet arrows
    • Added Munitions perk to Caltrops and Demon Seeds
    • Reduced the drop rate of Black Powder Bombs, Flash Bombs, Fire Arrows and Piercing Arrows dropped from the Munitions perk
    • Melee Resolve Gain property maximum value increased to 25%
    • Fire Damage property maximum value increased to 20%
    • Assassinate From Above Damage property maximum value increased to 50%
    • Samurai skill Deep Strikes increased to +25% Melee damage
  • Fixed bug where Black Powder Bombs did not count for some Mastery Challenges
  • Fixed a bug where Silver and Gold Survival missions showed incorrect mission modifiers
  • Fixed a bug in Survival where a Ghost dying in the brief period after the final wave, but before the scoreboard caused some missing rewards
  • Fixed a very rare bug where the Legends tutorial was impossible to complete

Single-player

  • Increased Silk inventory held by New Game Plus merchant
  • Fixed dialogue and cutscene issues in single-player

The post Ghost of Tsushima Director’s Cut Update 2.18 Rolled Out; No Additional Updates Currently Planned by Aernout van de Velde appeared first on Wccftech.

13 Apr 07:55

GWJ Conference Call 809

by Amoebic

Elden Ring (PC), Norco (PC), Weird West, FORWARD: Escape the Fold (PC), Beyond All Reason (PC), Age of Empires 4: Festival of Ages (PC).

13 Apr 07:44

Watch How Everything Everywhere All At Once Turned A Fanny Pack Into A Deadly Weapon

by Ben F. Silverio

After breaking into the entertainment industry in the 1980s with seminal films of the decade "Indiana Jones and the Temple of Doom" and "The Goonies," Ke Huy Quan worked as an actor for a few years, then completely disappeared from our screens. Now, following a hiatus that lasted around 20 years, he has finally returned to theaters nationwide in "Everything Everywhere All At Once" with great adulation.

In the sophomore feature from the filmmaking duo of Daniel Kwan and Daniel Scheinert AKA Daniels, Quan plays the timid and well-meaning Waymond Wang. However, he also plays Waymond's multiversal counterparts, which include a suave Old Hollywood variant, a young version of himself before immigrating to America, and a resourceful Jackie Chan-esque warrior. But it's that last one that really turns the weirdness and wildness of the movie up to eleven before fully verse-jumping from parallel universe to parallel universe. And in a new video, the writing-directing duo dissects the unexpectedly badass scene where it all begins.

This Is How I Fight

In a New York Times YouTube video series called "Anatomy of a Scene," the Daniels break down the first big action sequence of their new film, which features Quan's Alpha Waymond taking down a number of security guards in an IRS office with his fanny pack. This scene takes place just after his wife, Evelyn (played by the legendary Michelle Yeoh), assaults their auditor, Diedre (played by another legend, Jamie Lee Curtis), because of Alpha Waymond's warnings and finds divorce papers from her Waymond. As the filmmakers say in the video, it's almost like each character thinks they're in a different genre until the movie decidedly heads in a more action-oriented direction.

Two things stand out immediately from the filmmakers' commentary. First, I love that they address the stereotype of Asian dads wearing fanny packs, then decide to flip that on its head for a memorable kickoff to a movie that features a number of adrenaline-filled, action-packed, and absolutely absurd fight scenes. I have distinct memories of my own dad's red and navy blue fanny pack that would eventually get passed on to me to hold my Tamagotchi, Pokemon cards, and Spice Girl lollipops. (I can neither confirm nor deny that those were actually the contents of my fanny pack, but based on when I wore it, that's probably a good educated guess.)

The second revelatory detail from this video is that the 50-year-old Quan did most of his own stunts during this scene. The editing throughout "Everything Everywhere All At Once" is pretty flawless, so I had a hard time knowing for sure when we were looking at a stuntman and when it was the actor. But after getting confirmation that Indy's former sidekick got to show off the fact that his moves have exceeded those of the fedora-favoring archeologist, that just made this moment all the more impressive.

But above all, I love that Ke Huy Quan is back in action and finally getting his flowers for paving the way for Asian and Asian American representation in Hollywood. He's truly a pioneer in the business and I can't wait to continue flying the flag of the Ke Huy Quan-naissance as he continues to land more roles in the coming years.

Read this next: 20 Movies About Time Travel Ranked Worst To Best

The post Watch How Everything Everywhere All At Once Turned a Fanny Pack into a Deadly Weapon appeared first on /Film.

13 Apr 07:41

The Flight Attendant Season 2 Review: Kaley Cuoco Shines In An Enticing, But Uneven Attempt To Recapture Previous Heights

by Jeremy Mathai

When HBO Max first launched in May of 2020, the range of original shows available on the new, upstart streaming service was limited to a mere handful. Within six months, however, "The Flight Attendant" came out of nowhere to announce itself as one of the most thoroughly entertaining new originals of any streaming service at the time.

Developed by Steve Yockey, based on a novel of the same title by Chris Bohjalian, and led by a genuinely engrossing performance by star Kaley Cuoco (who seemed to relish the chance to prove what she's capable of once freed from the shackles of a lowest common denominator sitcom), the series told the hilarious and thrilling tale of a charismatic flight attendant with a penchant for ending international flights with drunken one night stands ... only to wake up one morning and find herself caught up in a far bigger conspiracy than she ever bargained for. Even while encouraging binge-watches with its rapid-fire pacing and soap-opera-like plot twists, the writing team also managed to balance out the vicarious nature of the globetrotting plot with an impressively serious-minded exploration into the darkest depths of casual narcissism, abuse, and alcohol addiction.

When the series received the green light for a second season after an emotionally satisfying conclusion, even the show's most ardent fans had to wonder how exactly the premise would lend itself to continued adventures. This is a story about Cassie Bowden, after all, one of the most shamelessly messy, yet impossibly endearing new characters you'll ever meet, and whose biggest source of drama came from ending up entirely out of her depth in life-or-death situations ripped straight from an airport novel. Turning her into a CIA asset at the end of season 1, even after carving such a self-destructive swath through everyone she encountered, threatened to strain credulity.

Thankfully, the first 6 episodes made available (out of 8 total) in season 2 refuse to get hung up on how the world's unlikeliest hero somehow encounters multiple major murder mysteries in the span of a little over a year, instead assuming (correctly) that viewers are already invested in our favorite disaster of a human being, no matter how outsized her circumstances. Even more encouragingly, the main storyline finds plenty of time and space in between car bombings, home invasions, and assassins to recommit to some of the most nuanced, empathetic depictions of addiction recovery (and relapse) currently airing on TV.

Yet however much this season of "The Flight Attendant" tries its hardest to avoid falling prey to the dreaded sophomore slump, the combination of a thinly sketched premise and some egregiously overstuffed plotting threaten to ground this thriller before it ever takes flight.

Now Where Were We...?

Season 2 begins over a year after the events of the first, with Cassie relocated to Los Angeles and about to celebrate the milestone of her first full year of sobriety. As succinctly explained in the opening minutes to her Alcoholics Anonymous support group, she has a new boyfriend named Marco (Santiago Cabrera), "picked up a new part-time job" working as a secret CIA asset in between international flights, and certainly appears as healthy and independent as we've ever seen her. Although looks can be deceiving, it doesn't take long at all for the new season to kick things off in earnest and shuttle Cassie into a new overseas assignment in Germany.

Unfortunately, this is also the first warning sign that "The Flight Attendant" may be struggling to recreate the largely unqualified joys of its first season.

The inciting action involves Cassie impulsively getting "a little too involved with your marks," as her new CIA handler Benjamin Berry (Mo McRae) warns her before the trip. This comes back to bite her when she closely shadows a secretive "courier," whom she was ordered to merely observe from a distance. After voyeuristically spying on his risqué late-night rendezvous with a mysterious blonde woman (complete with a back tattoo suspiciously similar to Cassie's own) and noting their telltale exchange of mysterious documents, Cassie attempts to get a closer look as her mark gets into his car ... only to end up far too close for comfort when a car bomb explosion kills her suspect, triggering Cassie's underlying PTSD and leaving her with a debilitating case of tinnitus (and a serious craving for a drink or 5) that leads her to spiral throughout the rest of the season.

Much like the first time she found herself in similar circumstances, the profoundly rattled Cassie initially attempts to hold herself together without telling anyone what she witnessed or how close she came to dying — not even Benjamin, who initially takes her at her word that she was nowhere near the scene of the crime. The biggest difference, however, is that she must try to do so without the vice of alcohol and its numbing effects.

Here, the writing team behind the series (made up of credited writers such as Yockey, Elizabeth Benjamin, Jess Meyer, Louisa Levy, Ryan Jennifer Jones, Natalie Chaidaz, Haruna Lee, Liz Segal, Ian Weinreich, and Kristin Layne Tucker) reveal their greatest recurring strength: allowing a character like Cassie the dignity of making her own choices and, more importantly, her own mistakes. Additionally, her struggles with maintaining sobriety are never treated cleanly or linearly, grounding the series in authenticity. For all the various directions the season eventually takes Cassie, viewers will likely find that the potential of one personal slip-up (or, on the other end of the spectrum, one seemingly minor victory) carries far more weight than any amount of espionage drama ever could.

Clipped Wings

Ultimately, none of the second season's plot mechanics ever feel as instantly engaging as Cassie waking up in bed with a dead Alex Sokolov (Michael Huisman) at the opening of the first season, plunging our protagonist into a terrifying world she hardly even knew existed. In fact, "The Flight Attendant" seems to forget about the dead body this time around and focuses much more on the murderous blonde who certainly seems to be trying to impersonate and frame Cassie herself. Where the physical threat of violence by the unstoppable assassin Miranda Croft (Michelle Gomez) helped set viewers up for the last-minute twist involving Sokolov's real murderer, Colin Woodell's "Feliks" (actually an unhinged hitman named Buckley Ware), season 2 sees fit to keep Cassie occupied with investigating various red herrings, none of whom are particularly interesting. Worse, we wind up indulging in another extended detour involving a loose thread from season 1 — Cassie's now on-the-lam friend Megan Brisco (Rosie Perez), still trapped in one of the show's most baffling subplots.

In place of the repeated hallucinations of her dead lover that brought back Huisman in hilarious and sometimes disturbing fashion, season 2 appropriately reflects the new ongoing conflict by forcing our manic and frazzled protagonist to confront several versions of herself: young Cassie as an alcoholic teen (a returning Audrey Grace Marshall), fun partygoing Cassie in a similarly dazzling gold dress that she wore as a functioning alcoholic in season 1, a cynical and defeatist Cassie, and even a far more buttoned-up and mature reflection of Cassie, pointing to a possible future where she has seemingly every facet of her life in order. Needless to say, Cuoco has a total blast acting against herself in these heightened and introspective hallucinations.

But not even these frequent interludes into her headspace can help overcome a central mystery that should be far more compelling than it actually is. The slow-paced and lumbering plotting saps the first few episodes of any energy and momentum. And then there are all those new faces: Cassie's AA sponsor Brenda (Shohreh Aghdashloo), clingy and maladjusted recovering alcoholic Jenny (Jessie Ennis), fellow flight attendant Grace (Mae Martin), the mysterious Diaz couple who may be more than meets the eye (Joseph Julian Soria and Callie Hernandez), CIA handler Benjamin, his boss Dot (Cheryl Hines), and more. The struggle to balance this batch of new supporting characters, along with creating enough time and space for the many key returning characters, eventually takes its toll.

Flying High

That's not to say that this season of "The Flight Attendant" is entirely without its charms, however.

Outside of Cuoco's stellar work, much of the season's redeeming qualities come from its deep bench of recurring characters. The increased focus on Cassie's best friend Ani (Zosia Mamet, expressive and watchable as always) and her relationship with Max (Deniz Akdeniz) does wonders for the moments where we step away from Cassie's self-combusting life, neatly paralleling many of the same insecurities Cassie is experiencing with her own boyfriend. Though relegated to a slightly smaller role this time around, the continued presence of Griffin Matthews' Shane (Cassie's fellow flight-attendant-turned-CIA-agent, in one of last season's more dubious twists) at least helps liven up the proceedings, particularly during the aforementioned plot detour when he and Cassie are both forced to put on deceptive fronts while knowing each is lying to the other. And in an admirable continuation of Cassie's fraught family situation, the arrival of her brother Davey (T.R. Knight) and his attempts to help heal the rift between Cassie and their mother Lisa (Sharon Stone) serves as one of the stand-out episodes of the entire season, by far.

Elsewhere, more technically-minded fans can rest assured that the show's knack for flashy split-screen transitions has been preserved, visually setting "The Flight Attendant" apart from the crowd and helping to set the fun, glitzy, and breathless tone. An impressive "oner" sequence (or at least the appearance of a single-shot take, as various scenes were likely digitally stitched together with some nifty transitions) opens the third episode of the season, subtly building up tension to a boiling point during one particularly dramatic moment. We even get a few split diopter shots thrown in for good measure, largely keeping the focus on Cassie in the background and crystal clear shots of all-too-tempting alcohol in the foreground. The haziness in-between only emphasizes the internal struggle between what Cassie needs versus what she so desperately wants, with the various directors of photography (Cort Fey, Anthony Hardwick, and Jay Feather) using the camera to literalize similar feelings that we see play out in tandem with her many hallucinations.

Overall, season 2 of "The Flight Attendant" doesn't quite match the soaring heights of its inaugural season. But when the series remembers to treat its enticing spy missions as merely exaggerated extensions of Cassie's own personal flaws, rather than the end-all and be-all, viewers will find themselves reminded of why they decided to board this breezy and seductive flight in the first place.

Read this next: The 15 Best Anthology TV Series Ranked

The post The Flight Attendant Season 2 Review: Kaley Cuoco Shines In An Enticing, But Uneven Attempt To Recapture Previous Heights appeared first on /Film.

13 Apr 07:40

Russian Doll Season 2 Review: Unstacking Generational Trauma Once More, With Feeling

by Danielle Ryan

The first season of "Russian Doll" was a riff on trauma therapy using a time loop, forcing its two protagonists to relive their pain in order to overcome it. Season 2 digs deeper, interrogating generational trauma through time travel. Our two heroes, Nadia (Natasha Lyonne) and Alan (Charlie Barnett), accidentally discover the ability to time-travel using a New York City landmark, and it forces them to reconcile more than just their own pasts. 

The second season takes place four years after the events of season 1, with Nadia looking forward to (and dreading) her 40th birthday. Then, one day, she accidentally stumbles through the time portal into her distant past. The experience makes her think that she has unfinished business in the past that could possibly help her have a better present (oh wow, there's that trauma therapy allegory again), so she tells Alan about it and starts traveling in time even more in order to unravel the mystery of her history. What follows is an examination of generational trauma and how we pass down old wounds from parent to child. If the first season taught Nadia and Alan how to forgive themselves, season 2 gives them the empathy to forgive the people who impacted them most. 

Nadia's surrogate mother figure, Ruth (Elizabeth Ashley), is a trauma therapist, and she tells Nadia during one episode, "Trauma is a topographical map written on the child, and it takes a lifetime to read." Through the use of time travel, Nadia, and to a lesser extent, Alan, are given the opportunity to understand the origins of their trauma and how it shaped them. It's a season that welcomes repeat viewings, as the time travel and its effects are a bit more confusing than the time loop, but every tiny detail provides clues toward the season's ultimate message. 

If all of this sounds vague, that's because "Russian Doll" is always best viewed knowing as little about it as possible beforehand. It's weird and shocking and deeply emotionally resonant, with a punk rock, experimental ethos that makes it feel like something truly fresh. 

Trauma! What A Concept!

Trauma, and how we deal with it, is having a big pop culture moment. While those who study and practice trauma-informed pedagogy could easily argue that everything is about trauma, "Russian Doll" is one of the few pieces of art to tackle it head-on, while also using science fiction allegory to force the viewer to confront even more challenging concepts. Nadia's arc in season 2 is incredible, moving her across time and geography to better understand herself and the people who love her. Unfortunately, Alan's arc isn't fleshed out enough, ending with more questions about his past than answers, which ultimately makes his inclusion feel tacked on. It's a shame, too, because there are ideas about identity and sexuality that could have done well with more exploration. 

Stylistically, "Russian Doll" season 2 is a perfect follow-up to season 1, expanding on psychedelic imagery, carefully selected needle drops, and even more bizarre experiences. Lyonne was the sole creative in charge of this season, with co-creators Amy Poehler and Leslye Headland wrapped up in other projects, and their absence is noticeable. Lyonne's stylistic choices are bold and exciting, and she does a great job with direction, but Alan's rushed side-story and a messy ending provide clues to Poehler and Headland's previous contributions. The season is excellent, but it's hard not to feel like there should be just a little bit more

The whole cast is great, though "Schitt's Creek" star Annie Murphy and season 1 alum Greta Lee both steal every scene they're in. Lee delivers some absolutely insane lines with casual cool as Maxine, who threw the repeating birthday party in season 1, and she provides some much-needed levity during some of the season's darker (and weirder) moments. 

Season 2 does some incredible things when it comes to examining generational trauma and its impact on individual lives, but Alan's short shrift keeps it from being a perfect follow-up to the mind-blowing first season. With only seven episodes at around 30 minutes each, "Russian Doll" season 2 never overstays its welcome or becomes too navel-gazey, but maybe one or two more episodes would have made it feel complete. Headland has said the creative team has plans for multiple seasons, so hopefully the unanswered questions at the end of season 2 are meant to leave us wanting more in anticipation of season 3. As it stands, however, "Russian Doll" season 2 is messy and complicated, but ultimately emotionally enlightening — just like the trauma therapy it represents.

/Film Rating: 7 out of 10

Read this next: The 15 Best Anthology TV Series Ranked

The post Russian Doll Season 2 Review: Unstacking Generational Trauma Once More, With Feeling appeared first on /Film.

13 Apr 01:03

Autonomous Robots Used In Hundreds of Hospitals At Risk of Remote Hijacks

by BeauHD
An anonymous reader quotes a report from TechCrunch: [R]esearchers are now finding vulnerabilities in newer hospital technologies that weren't as ubiquitous a decade ago. Enter autonomous hospital robots, the supposed-to-be-friendly self-controlled digital workhorses that can transport medications, bed linens, food, medications and laboratory specimens across a hospital campus. These robots, such as the ones built by robot maker Aethon, are equipped with the space to transport critical goods and security access to enter restricted parts of the hospital and ride elevators, all while cutting labor costs. But researchers at Cynerio, a cybersecurity startup focused on securing hospital and healthcare systems, discovered a set of five never-before-seen vulnerabilities in Aethon robots, which they say allowed malicious hackers to remotely hijack and control these autonomous robots -- and in some cases over the internet. The five vulnerabilities, which Cynerio collectively call JekyllBot:5, aren't with the robots themselves but with the base servers that are used to communicate with and control the robots that traverse the hallways of the hospitals and hotels. The bugs range from allowing hackers to create new users with high-level access in order to then log in and remotely control the robots and access restricted areas, snoop on patients or guests using the robot's in-built cameras, or otherwise cause mayhem. Asher Brass, the lead researcher on the Aethon vulnerabilities, warned that the flaws required a "very low skill set for exploitation." Cynerio said the base servers have a web interface that could be accessed from inside the hospital's network, allowing "guest" users to view real-time robot camera feeds and their upcoming schedules and tasks for the day without needing a password. But although the robots' functionality were protected by an "admin" account, the researchers said the vulnerabilities in the web interface could have allowed a hacker to interact with the robots without needing an admin password to log in. One of the five bugs, the researchers said, exposed robots to remote control using a joystick-style controller in the web interface, while exploiting another one of the bugs to interact with door locks, call and ride elevators, and open and close medication drawers. "The bugs were fixed in a batch of software and firmware updates released by Aethon, after Cynerio alerted the company to the issues," notes TechCrunch. "Aethon is said to have restricted internet-exposed servers to isolate the robots from potential remote attacks, and fixed other web-related vulnerabilities that affected the base station."

Read more of this story at Slashdot.

13 Apr 00:03

Jurassic Park Had A Surprisingly Simple Solution To Self-Driving Cars

by Ryan Scott

The term "movie magic" is thrown around an awful lot, but if there is a director out there who truly encapsulates that phrase, it is most likely Steven Spielberg, the man behind "Jaws" and "E.T." But one of his finest hours in terms of crafting true blue movie magic is 1993's "Jurassic Park," which brought dinosaurs to life on the big screen in a way that nobody ever imagined possible before that moment. The dinosaurs, though, were just one element of that cinematic magic at play, as a great deal of innovation was needed to make it feel like this prehistoric amusement park was real. One such example is the self-driving cars that guide guests around the park. This was, especially in 1993, a pretty amazing concept. The John Hammond character says he spared no expense, and it needed to look that way on film.

As for the cars themselves, they were crafted from a 1993 Ford Explorer, and the model's inclusion in "Jurassic Park" helped make the vehicle famous. But how is it that Spielberg and the filmmakers made it look like these cars were driving themselves? Actor Joseph Mazzello, who plays Tim Murphy in the movie shed some light on that mystery, and the answer is kind of amazing.

People Were Still Driving The Cars

Mazzello participated in a lengthy Q&A with IGN about the movie in April of 2020 and answered all manner of questions, providing insight into the making of "Jurassic Park" where and when he could. In responding to a question about scenes that were filmed that didn't end up in the final edit, Mazzello made a pretty interesting reveal about the self-driving cars we see in the park itself.

"There was an idea that, when the cars are driving themselves later in the movie, that we were going to be going over this land bridge ... Those cars were supposed to be 'driving themselves,' well in reality there's a guy in the trunk of the car with a little TV screen, you know, smaller than my iPad that I'm on right now, and he's hunched down on his side like this driving the Jeep, driving the cars, and that's how they're being driven. They're being driven by people in the cars in the trunk. And so when my dad saw that land bridge with, like, it's death on either side, there's no barriers, he was just like, 'We're not doing this one.' Like, no way no how."

That's right. These cars weren't self-driving in any way, shape, or form. As Mazzello tells it, there was someone hidden in the back of the car actually driving it, making it appear as though it was maneuvering effortlessly down a track. On one hand, it's deceptively simple to just have someone drive the car, but the logistical effort in getting a person to drive the car from the back as described is something else entirely. Again, movie magic. It's hard to imagine any viewers would have ever imagined that to be the case when watching the film.

Just One Example Of Innovation In Jurassic Park

This is but just one of many, many examples of innovation employed by Spielberg and the team behind "Jurassic Park," including effects wizard Stan Winston. First and foremost, the film employed a groundbreaking combination of animatronic dinosaurs and never-before-seen amounts of CGI to bring the beasts to life on screen. Because the film was so successful both in execution and at the box office, CGI became the standard for Hollywood films in the years to follow. For better or worse, the vast majority of movies these days lean heavily on computer-generated effects as opposed to doing everything practically.

There are also many other small elements of movie magic at play. One of the iconic bits of imagery in the film is the rippling in the water glass just ahead of the T-rex breakout sequence. Amazingly enough, the ripple in the water was made by a guitar string, with someone plucking one underneath the car to make it happen. Yet, we feel as though it is the distant weight of a T-rex foot in the finished product. Every little detail revealed about this movie all these years later helps to shed light on why it truly is one of the greatest blockbusters ever made.

Read this next: The 15 Best Submarine Movies Ranked

The post Jurassic Park Had A Surprisingly Simple Solution To Self-Driving Cars appeared first on /Film.

13 Apr 00:02

Six Of Gilbert Gottfried's Most Hilarious Moments

by Witney Seibold

Gilbert Gottfried has passed away at the age of 67, leaving behind a legacy of utter filth, intense depravity, and sick humor that we will all desperately and tragically miss. While Gottfried's highest-profile role as an actor likely came from voicing the animated parrot Iago in the G-rated 1992 film "Aladdin," anyone who bothered to delve into his stand-up career would discover some pretty blue humor. Gottfried was often deliberately politically incorrect, telling some of the most tasteless jokes imaginable on stage to the shock and horror — and delight — of his audiences. 

Gottfried's onstage persona was that of a brash, shrieking a**hole who doesn't seem to realize how caustic and shrill he is. Like a drunken borsht-belt comedian who long ago lost his ability to adhere to decorum, Gottfried would wail obscenities at his audience, and then whip out a punchline that was somehow even darker than the setup. Example: In his 2005 stand-up special "Dirty Jokes," Gottfried tells a joke about a doctor breaking bad news to a husband that his wife has been horribly mutilated in a car accident. The doctor describes the damage in explicit terms, and the listening husband is horrified to learn how much work he'll have to put into keeping his wife comfortable. When the husband breaks down, the doctor nudges him and says "Nah, I'm just f**kin' with ya. She's dead." 

The boldness. 

Here are some wonderful highlights of Gottfried's shocking/hilarious comedy career:

A Million Ways To Die In The West

Seth McFarlane's 2014 Western spoof "A Million Ways to Die in the West" is a sprawling, slightly-too-long homage to films like "Blazing Saddles" and "The Villain." In it, Gottfried has a cameo as, of all people, President Abraham Lincoln (well, not really). The concept of Gottfried playing Lincoln is funny enough — the stentorian speaker adopting Gottfried's stage persona is comedy unto itself. Then Gottfried got to inspire a group of students by declaring that he was "so f**king rich, I can have all the licorice I want!"

It's only about 30 seconds of screen time, but it's a lovely 30 seconds. 

McFarlane and Gottfried had worked together in the past, as Gottfried voiced a couple random bits on "Family Guy," including this horse.

Fifty Shades Of Grey

When E.L. James' landmark pornographic novel "Fifty Shades of Grey" was topping (heh) the Bestseller charts, many critics emerged to talk about the book's odd use of language, citing James' common flipping back and forth between intense sexual detail and golly-gee adolescent expletives. The phrase "my inner goddess" was used repeatedly. Of course, the prose was not the reason most people bought "Fifty Shades of Grey," preferring the zesty depiction of posh sadomasochistic sexual encounters. 

College Humor wisely thought to put James' words into Gottfried's mouth, and the comedian screaming about his inner goddess and his own vagina will crack the strongest visage. The reactions of the women listening to the audiobook are priceless. 

Jerry The Bellybutton Elf

John Kricfalusi, the creator of "The Ren & Stimpy Show" was notoriously fired from his own series because he constantly butted heads with the network's standards and practices, argued with producers, and was unable to make the show on a studio timetable. The show continued for several years without John K.'s direct input (John K. would struggle to make cartoons for years, and was eventually ousted for his habit of grooming teenage girls). It was in 1994 that Gottfried appeared on the show as, rather surreally, a character named Jerry the Bellybutton Elf. 

In "Jerry the Bellybutton Elf," Stimpy (Billy West), an animated version of Larry Fine, would become weirdly obsessed with his own navel to the point of climbing inside of it. While inside his own bellybutton, Stimpy would meet the title character (voiced by Gottfried), a miniature, lint-draped cyclops that immediately turned Stimpy into his slave. When Stimpy presents Jerry with a meal of lint loaf (?), Jerry has one of the most vocal and unusual freakouts in a show full of them. Gottfried didn't just employ his well-known voice, but pushed it to 11, shrieking at the top of his lungs and mutating into a giant murderous porkchop. What a class act. 

Mr. Mxyzptlk

Another notable animated villain voiced by Gottfried was one of Superman's more notorious foes: Mr. Mxyzptlk (pronounced "mix-yes-spit-lick"). In 1996's "Superman: The Animated Series," Gottfried played the impish trickster god as a creature let loose from the funny papers, easily able to decipher Clark Kent's secret identity and eager to defeat him in battle. Luckily for Clark, Mr. Mxyzptlk can be defeated — very much like Rumpelstiltskin — by saying his name aloud and magically banishing him back to his home dimension. He cannot return for a few weeks. Each time he does, the rules of his banishment get all the more complicated, until he has to write down his name backwards, twice. Superman finds a way. 

Superman is a superhero fantasy character, of course, but Mr. Mxyzsplk brought an additional note of comedic chaos to the proceedings. He didn't play by superhero rules. He was more of a nuisance than a villain. 

"Superman: The Animated Series" was made with a younger audience in mind, so Gottfried was not permitted to let loose with a fusillade of obscenities in Superman's face (although that would have been welcome). As such, when the villain was tricked, Gottfried only muttered, "Well, shoot my monkey." It's the funniest and dirtiest piece of non-obscenity you'll find in a superhero show.

The 1991 Emmys

"If masturbation's a crime, I should be on death row." 

Gottfried's propensity for tasteless gags got him in trouble more than once, perhaps most notably for his appearance at the 1991 Emmy awards. The show was broadcast after actor Paul Reubens had been arrested for indecent exposure, and Gottfried was not one to take the high road. His act was two straight minutes of onanism jokes before presenting the award for Best Writing on a Variety Show (the winner being the writers of the 63rd Academy Awards). 

The gags were dirty, yes, and they were made at Reubens' expense, but he was careful to turn the joke back on himself, and, really, they are downright innocuous compared to some of the filth that would become a regular installment in stand-up comedy a generation hence. Regardless, Gottfried's masturbation jokes got him blacklisted from future Emmy shows, and Fox issued an apology. Only viewers on the east coast saw Gottfried's bit. His monologue was cut entirely for the west coast. Although he was not in the public's good graces for a span, Gottfried continued to work. 

Gottfried would get in trouble again in 2011 for tweeting tasteless jokes about the tsunami in Japan. This lost Gottfried a job voicing the duck mascot for the insurance company Aflac. Gottfried knew where the line was because, very occasionally, he crossed it. We can take comfort in the fact that, by all accounts, Gottfried was a kind and decent human being off stage.

The Aristocrats

In 2005, Penn Jillette and Paul Provenza made a low-fi, notable documentary film about a dirty secret in the comedy world, and a very, very dirty joke. In it, many comedians are interviewed about their relationship to shock humor, how filthy one should be permitted to be on stage, and an industry secret that let them all blow off steam. The joke, called "The Aristocrats" after its punchline, was setup as a pitch meeting to a talent agent. The performer describes to the agent that he and his family were to go on stage and perform a series of sexual and/or scatological acts that would make the Marquis de Sade blush. It wasn't really meant to be conventionally funny, necessarily, becoming a contest to see who could gross-out whom. It was a "joke" that comedians told to one another. 

While Gottfried appears in "The Aristocrats" to tell the joke to the camera, the filmmakers also recount a time when Gottfried used the joke to a weirdly cathartic effect. During the Comedy Central roast of Hugh Hefner in 2001, Gottfried made a few tasteless gags about 9/11. The audience actively booed him. Too soon. Not only did Gottfried win the audience back, but he won them over. Gottfried broke the comedians' code and told The Aristocrats joke on stage to the chagrin and surprise of the comedians around him. Rob Schneider is seen literally falling out of his chair.

The filmmakers explain how that level of unexpected filth was a healing moment. 

A Few Zingers

For good measure, here are a few Gottfried zingers to remember him by: 

A man comes home to his wife and says, "Honey pack your bags I just won the lottery!" She says, "What should I pack?" He says, "I don't care just pack and get the f*** out!"
The pressure to being a comedian is being funny, but I've given that up, so there is no pressure whatsoever.
A man goes to the doctor for a check, and the doctor examines him and says "I've got bad news, you've got cancer and Alzheimer's." The man goes "Thank god I don't have cancer."

And of course, the classic: 

I'm known for my slightly inappropriate remarks. 

Rest in peace, Mr. Gottfried.

Read this next: The 10 Best Comedies Of The Last 10 Years

The post Six of Gilbert Gottfried's Most Hilarious Moments appeared first on /Film.

12 Apr 22:05

Why Gilbert Gottfried Was One Of The Best Are You Afraid Of The Dark Villains

by BJ Colangelo

The 1990s were the perfect time to be a kid who liked all things scary. Thanks to shows like "Goosebumps," "Eerie, Indiana," "AAAHH!!! Real Monsters," "The Addams Family," "Mona the Vampire," "The Real Ghostbusters," and "Tales from the Crypt Keeper," youth-friendly horror shows were plentiful. It feels unfair to pit the abundance of quality programming against one another, but if any show served as the king of the castle, the distinction belonged to Nickelodeon's "Are You Afraid of the Dark?" The horror anthology series centered on the members of "The Midnight Society," a group of teenagers who gather each week in a clearing in the woods to share original horror stories around a campfire. The episode includes a dramatization of each story, acting like the child-friendly version of "The Twilight Zone."

"Are You Afraid of the Dark" is home to some of the strongest presentations of kindertrauma, like The Ghastly Grinner, The Crimson Clown, Zeebo the Clown, the Dead Man's Float, and a gaggle of ghosts, goblins, and other monsters. Every once in a while, the show would introduce a human character to give us the creeps and in "The Tale of Station 109.1," Gilbert Gottfried's Roy twisted his iconic voice into nightmare fuel for kids everywhere.

Eat Your Heart Out, Miss Argentina

In "The Tale of Station 109.1," a death-obsessed kid named Chris Leary (Zachary Carlin) gets more than he bargained for when his brother Jamie (Ryan Gosling, no really) lets Chris check out a hearse he's working on at his job. Jamie powers up the battery of the hearse, which cues into radio station 109.1 "for the dimensionally challenged." A DJ with an odd accent informs listeners that sometimes when people die, they miss their chance to cross into the afterlife and may need special assistance. As long as you follow his voice, he'll help you find the way "home." The voice is, of course, Gilbert Gottfried, putting on a kind-hearted and soothing voice to help lost souls make it beyond the mortal coil. Chris tracks down the address of the radio station and comes face to face with the voice, a radio DJ named Roy who talks like, well, Gilbert Gottfried when he's not on air. He's a lot like Miss Argentina in "Beetlejuice," except he's the one processing whether or not your soul is going to cross over to a heaven-like eternity, or torturous pain in proverbial Hell.

Gottfried's voice is typically played for laughs, but not on "Are You Afraid of the Dark." His shrill, loud, screeching voice is meant to strike fear in the heart of young Chris Leary. Unfortunately, Roy believes Chris is dead and needs to make it to the other side, ignoring his pleas that he's just a kid with plenty of time left. Gottfried screams in this kid's face, and the voice '90s kids grew up associating with Iago from "Aladdin" immediately transformed into something horrifying. He reprimands Chris for knocking on his window, and after assigning him a number to cross over, the camera zooms into Gottfried's face on a dutch angle as he lets out a maniacal laugh.

Subverting A Familiar Voice

What makes Gottfried's performance in this episode so memorable, is the subversion of associating his memorable voice with something worthy of fright. We witness his character seamlessly flip between the calm and gentle voice on the radio to a shrieking harbinger of death. His character is responsible for organizing lost souls' transition from our world into the next, and he mistakenly assigns Chris as another dead person needing to cross over. Throughout the episode, we see elderly people dragged away by terrifying ghosts in black cloaks as they shriek "You've made a mistake!" before being taken to the afterlife. Knowing that Chris almost shared the same fate, we can't help but wonder how many other mistakes Roy has made over the years. How many confused old people did he send to the nether realm?

Most of the human characters in "Are You Afraid of the Dark" leaned heavily into the camp nature of the show, but despite Gottfried's natural comedic charm, his character is genuinely unsettling. Despite being the most popular horror shows of the 1990s, the low-budget series seldom had known actors appear in the episodes. A handful of the Canadian child actors featured throughout have gone on to have successful careers, but Gottfried was one of the most recognizable performers to ever appear on "AYAOTD," which only added to the terror. For many of us '90s kids, this episode was the first time we saw the face of Gilbert Gottfried and implanted a tiny seed of fear in our subconscious that awakens each time we hear his voice cutting through the air.

Read this next: The 15 Best Horror TV Shows Of All Time

The post Why Gilbert Gottfried Was One of the Best Are You Afraid Of The Dark Villains appeared first on /Film.

12 Apr 22:05

Gilbert Gottfried Was Known For Being Loud And Raunchy, But He Was Also Very Sweet And Kind

by Danielle Ryan

It's somewhat common for comedians to have differences between their onstage persona and their real personalities, but few had differences as vast as Gilbert Gottfried's. The actor and comedian was best known for his loud, growling way of talking and his love of vulgarity. Much of Gottfried's humor was based on shocking people, and he would say just about anything to get a laugh, even especially if it was rude, crude, or lewd. Despite being as obnoxious as humanly possible onstage, he was beloved in the comedy world as a rather shy, sweet man who would rather ride the bus than take a private jet. His loudness and intensely offensive jokes were all part of the schtick, a character he built around himself as a way to make people laugh. 

The personal dichotomy of Gilbert Gottfried is nothing short of incredible. In his private life, he was a soft-spoken husband and father of two, but in his public life, he was the voice of Iago the parrot in Disney's "Aladdin," one of the most recognizable voices in all of pop culture, and the man behind what is potentially the dirtiest version of "The Aristocrats" joke ever told. While many will honor his passing by replaying some of his favorite roast routines or stand-up bits, they should also remember the man behind it all -- a man who was much more complex than his public persona let on.

The Softer Side Of One Of Comedy's Most Boisterous

The best way to truly understand the controversial but caring comedian is to check out the 2017 documentary "Gilbert," directed by Neil Berkeley ("Harmontown"). The documentary gives unprecedented access to Gottfried and his family, including his wife and two children. It doesn't shy away from the fact that sometimes his boundary-pushing style of comedy went too far, and the film helps paint a more complete portrait of the man who made us all laugh so much. It's difficult for some to reconcile the two sides of Gottfried, who made the kinds of jokes that aren't repeatable except in very specific company, but he was ultimately just trying to make people laugh, not hurt anyone. Comedy is hard. Provocative comedy can be even harder, because in order to test the limits, sometimes you have to overstep so the next generation knows what not to do. Gottfried took those risks and became especially beloved among other comedians as someone who could always bring the room to a riotous uproar. Laughter is medicine, after all, and his was some of the strongest. 

When he wasn't making people gasp with jokes that obliterated the boundaries of good taste, Gottfried still spent his time trying to make people happy. In the 2016 documentary "Life, Animated," he surprises one very special fan, Owen Suskind, by dropping in and re-enacting scenes from "Aladdin." Suskind has autism and became non-verbal as a child, but his parents were able to inspire him to communicate through Disney movies. One of his favorites was "Aladdin," and he lit up every time he heard Gottfried as Iago, the villainous parrot. In the clip, Gottfried and Suskind share a lovely moment, surrounded by other fans with autism who appreciate the uniquely-voiced performer. 

We, as humans, are complicated, messy creatures. Gottfried was as messy as could be on stage in a way that was almost cathartic to watch and laugh at. He said the worst things possible and gave us permission to laugh at all of the awful in the world, but he did it out of a kind of love for all of the other messy, complicated creatures out there. Rest in peace, you filthy, hilarious man. You will be sorely missed. 

Read this next: The 35 Best Documentaries You Can Watch On Netflix Right Now (March 2022)

The post Gilbert Gottfried Was Known for Being Loud and Raunchy, But He Was Also Very Sweet and Kind appeared first on /Film.

12 Apr 22:05

T-Mobile Secretly Bought Its Customer Data From Hackers To Stop Leak. It Failed

by BeauHD
An anonymous reader quotes a report from Motherboard: Last year, T-Mobile confirmed it was breached after hackers offered to sell the personal data of 30 million of its customers for 6 bitcoin worth around $270,000 at the time. According to court documents unsealed today and reviewed by Motherboard, a third-party hired by T-Mobile tried to pay the hackers for exclusive access to that data and limit it from leaking more widely. The plan ultimately failed, and the criminals continued to sell the data despite the third-party giving them a total of $200,000. But the news unearths some of the controversial tactics that might be used by companies as they respond to data breaches, either to mitigate the leak of stolen information or in an attempt to identify who has breached their networks. On Tuesday, the Department of Justice unsealed an indictment against Diogo Santos Coelho, who it alleges is the administrator of a popular hacking site called RaidForums. Law enforcement also uploaded a banner to the RaidForums site announcing they had taken over its domain. Coelho was arrested in the United Kingdom in March. Included in the affidavit in support of request for his extradition to the United States is a section describing a particular set of data that was advertised on RaidForums in August. [...] The document does not name the victim company, instead referring to it as Company 3, but says another post confirmed that the data belonging to "a major telecommunications company and wireless network operator that provides services in the United States. The document goes on to say that this company "hired a third-party to purchase exclusive access to the database to prevent it being sold to criminals." An employee of this third-party posed as a potential buyer and used the RaidForums' administrator's middleman service to buy a sample of the data for $50,000 in Bitcoin, the document reads. That employee then purchased the entire database for around $150,000, with the caveat that SubVirt would delete their copy of the data, it adds. The purpose of the deletion would be that this undercover customer would be the only one with a copy of the stolen information, greatly limiting the chance of it leaking out further. That's not what happened. The document says that "it appears the co-conspirators continued to attempt to sell the databases after the third-party's purchase." Company 3, the unnamed telecommunications firm that hired this third-party, was T-Mobile, according to Motherboard's review of the timeline and information included in the court records. The third-party that paid cybercriminals $200,000 may have been Mandiant, though the security company has yet to confirm with Motherboard. In March, Mandiant announced it was being acquired by Google.

Read more of this story at Slashdot.

12 Apr 19:56

Hubble Confirms Giant Comet With 85-Mile-Wide 'Dirty Snowball' Nucleus - CNET

by Amanda Kooser
Goodness gracious great ball of ice and dust. It's the largest comet nucleus ever discovered.
12 Apr 19:55

'Black Carbon' Threat To Arctic as Sea Routes Open Up With Global Heating

by msmash
As climate crisis allows new maritime routes to be used, sooty shipping emissions accelerates ice melt and risk to ecosystems. From a report: In February last year, a Russian gas tanker, Christophe de Margerie, made history by navigating the icy waters of the northern sea route in mid-winter. The pioneering voyage, from Jiangsu in China to a remote Arctic port in Siberia, was heralded as the start of a new era that could reshape global shipping routes -- cutting travel times between Europe and Asia by more than a third. It has been made possible by the climate crisis. Shrinking polar ice has allowed shipping traffic in the Arctic to rise 25% between 2013 and 2019 and the growth is expected to continue. But Arctic shipping is not only made possible by the climate crisis, it is adding to it too. More ships mean a rise in exhaust fumes, which is accelerating ice melt in this sensitive region due to a complex phenomenon involving "black carbon," an air pollutant formed by the incomplete combustion of fossil fuels. When black carbon, or soot, lands on snow and ice, it dramatically speeds up melting. Dark snow and ice, by absorbing more energy, melts far faster than heat-reflecting white snow, creating a vicious circle of faster warming. Environmentalists warn that the Arctic, which is warming four times faster than the global average, has seen an 85% rise in black carbon from ships between 2015 and 2019, mainly because of the increase in oil tankers and bulk carriers. The particles, which exacerbate respiratory and cardiovascular illness in towns, are short-term but potent climate agents: they represent more than 20% of carbon dioxide equivalent emissions from ships, according to one estimate.

Read more of this story at Slashdot.

12 Apr 18:22

Microsoft’s Halo: MCC update should support Steam Deck, but the exact opposite happened

by Richard Devine

As the Steam Deck gets out into more hands there are more and more eager gamers trying to play their vast libraries on the handheld. The list of verified and officially playable titles is already over 2,000 and going up by the day, a monumental achievement for Valve and its Proton special sauce. There is still a stumbling block, though; anti-cheat software. And that’s the tale of the tape when it comes to Steam Deck and general Linux support for Microsoft’s Halo: The Master Chief Collection (MCC).

Halo: MCC uses Epic’s Easy Anti Cheat (EAC) on its multiplayer, and until now that has been a roadblock for anyone trying to play through Proton. Even though EAC was updated pre-Steam Deck launch to support Linux. So when a huge update arrived on April 11 that brought with it the necessary fixes for EAC on Linux, Steam Deck owners immediately had a reason for celebration. Or perhaps just to be hopeful. Alas, as the intrepid team at GamingonLinux found, that hope was short-lived.

The frustrating thing is not that EAC hasn’t enabled multiplayer support at last — though that is still frustrating — it’s that what once worked now seems not to. It hasn’t been officially announced that Microsoft was intending to start supporting the Steam Deck and Linux with this update, but still. Considering EAC has to be enabled by the developer, it’s hard to believe it was an accident.

Halo: MCC single player has been working pretty well on Linux for some time, and while I haven’t personally played it on Steam Deck yet, I have enjoyed some super happy Spartan fun time on my Linux desktop PC. And it was really good, arguably more stable through Proton than I’d experienced through Windows. Fortunately, the Linux community rarely accepts defeat, and for those who at least want to play the single-player games, there’s a fix that can be applied.

Hopefully, this is intended as support for multiplayer on Steam Deck, especially with the added PC/console crossplay support introduced in the same update. But how quickly it might get sorted out is anyone’s guess. Soon, though, please!

via GamingonLinux

The post Microsoft’s Halo: MCC update should support Steam Deck, but the exact opposite happened appeared first on xda-developers.

12 Apr 18:21

You Can Scramble Eggs in a Pot of Simmering Water

by Claire Lower

A wise man once said, “Eggs are nature’s cooking school in a shell, a pathway to teaching yourself everything you need to know to become a passable home cook.” With this one (cheap, ubiquitous) food, you can learn at least five different cooking methods (fry, poach, boil, scramble, bake), and get familiar with fats,…

Read more...

12 Apr 18:19

Notes on BitLocker and the TPM and the pre-boot password or PIN

by Raymond Chen

I had an older system that had BitLocker configured with a pre-boot password because it didn’t have a Trusted Platform Module (TPM). I later discovered that the system did indeed have a TPM, but it was disabled by default, which is why BitLocker couldn’t find it.

Here’s how I converted the system from a pre-boot password to TPM-managed protection.

Step 1: Enable the TPM chip in the BIOS.

This will vary from manufacturer to manufacturer. The tricky part is that some BIOS menus don’t refer to the TPM as a TPM. They call it an “Embedded Security Device” or a “Security Chip”. You want to Enable the TPM / Embedded Security Device.

You also want to enable OS Management of Embedded Security Device if you have that option.

This web site walks you through the BIOS of many major manufacturers.

Step 2: Let Windows take control of the TPM.

From an elevated command prompt, type tpm.msc to run the TPM console snap-in. Over on the right-hand side, there will be an option called “Prepare TPM for use”. If prompted, reboot the system back into the BIOS, so that the BIOS can verify that you really want to let Windows use the TPM.

After convincing the BIOS to let Windows manage the TPM, you can switch over to letting the TPM manage your BitLocker volume.

Step 3: Enable TPM management of BitLocker.

From an elevated command prompt:

manage-bde -protectors -add C: -tpm

This tells BitLocker to allow the TPM to protect access to the volume.

Doing this might regenerate the recovery key, so do a

manage-bde -protectors -get C:

to get the new Numerical Password. The ID is a bunch of letters, digits, and dashes inside curly braces. This lets you remember which volume the password is for. The password is the sequence of six-digit blocks separated by dashes. Save both the ID and password in a safe place.

Step 4: Remove the old password.

manage-bde -protectors -delete C: -t Password

This last step is what stymied me. I had set up the TPM to unlock the volume, but I still kept getting prompted for the password. That’s because the password protector was still there, and the system insisted on using it.

Delete the password protector, leaving just the TPM protector. That lets the TPM take over as the source of unlocking the system volume at boot.

As an extra check, run

manage-bde -protectors -get C:

and look for interactive protectors like Password, TPMAndPIN, or TPMAndPinAndStartupKey. If present, delete them. (But don’t delete TPM or Numeric Password!)

Bonus chatter: Sometimes, the TPM doesn’t play friendly, and I have to enter my 48-digit BitLocker key (ugh). I don’t know why this happens.

The post Notes on BitLocker and the TPM and the pre-boot password or PIN appeared first on The Old New Thing.